Techstrong TV October 14, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. We've got trouble with Tribbles. I mean, tariffs.
Again, you're watching Textron Gang. Hey everyone, it's Alan Shimmel and welcome to our Tuesday of edition of the Techron Gang. Got a Cracker Jack gang line up here for you to talk about as usual, three interesting topics.
Um, let me introduce you to our gang. We've got the one and only Steven FoST. Sanjeev Sharma, and still licking his wounds over his Yankees.
Mike Ard. Gentlemen, welcome to Textron Gang Giants. Beat the Eagles.
That's all I gotta say. I'm good for the year. Yes, the Giants did beat the Eagles.
The Giants did beat the Eagles. All right, guys. It, it, it's the weak is off to as usual to another exciting week.
Um, today we're gonna kick off talking about, it looks like we're back to, what is it, a hundred percent tariffs or 145% tariffs or something. A Thousand percent tariffs. I don't know.
It's taco tariffs anyway, but Mike, what's going on? Yeah, it's kind of, uh, back to square one is your, is a good way to describe it. I mean, I think originally this whole conversation got started again because the Chinese decided that they were gonna restrict access to some of the rare earth metals.
And then we responded by saying, well, we're gonna start ta tariffs up on everything again and add it to that. We're gonna restrict access to AI software. Now, some of this just seems to be, to me at least, that the Chinese are trying to remind us that no matter how much we make semiconductors in the US they're, they still got us because they got all those metals that we need.
And of course, you can find those metals almost anywhere these days, but you still gotta set up the process for, uh, mining them. And that might take a few years. And I think they understand that maybe a little bit better than some of our folks in Washington.
At the same time, I'm not entirely clear how this whole AI software threat works. 'cause if the most of that software is open source, I'm pretty sure they can just get access it to from anywhere they want. But Alan, what's your take on what's going on here?
You don't really want to know, do you? Um, You know, it, it's interesting. I I just feel like, uh, bill Murray and Groundhog Day, you know, we keep waking up every, you know, every couple weeks, month or two to the same thing here, Mike, I think you hit it on, right.
I don't know if they're metals, but let's call 'em rare earths, right? These rare earths right now China seems to have a stranglehold on supply. We have, to your point, Mike Othered, uh, potential supplies have been located some right here within the USA, but we're probably a few years out from mining that commercially China's using this as a, as a a, a club, right?
To, to force what they feel are unfair trade practices being hoisted upon them. And when they do that, we respond by, you know, the, what seems to be the only thing we know how to do, which is ratcheting up tariffs, which then is just like saying, okay, we're gonna close our markets to that. And here's the important thing, Mike, I think you didn't, what you said, maybe confuse people.
Tariffs are on incoming export taxes are on outgoing. And so I think, if I'm not mistaken, this is about incoming tariffs, not export license fees. And if I'm wrong, I apologize.
So then you gotta ask yourself self, what, what exactly are we taring free deep seek, which as you said, is open source, a hundred percent of zero, still zero. Mm-hmm. So, you know, as usual, makes a lot of noise spins up us and, and at the end of the day, it's Taco Tuesday.
It seemed that Taco Tuesday riled up the markets considerably over the last few days. So Yeah, because they just see it's a hundred percent tariffs and, you know, and it's about the rare Earths and all of these things. But I, I just don't know how much teeth this has and if it'll even if, if history is any guide here, it, it's just, you know, strutting and showing just your feathers because you're a big c**k.
I, I, I think it's a, it, it goes back to that con it was a very interesting conversation. If you go back to when President Zelinsky was at the White House, right? The question being asked as we have all the cards, right?
And he, I think the question being asked here is who already has all the cards in this scenario or has the higher cards in this scenario, United States versus China versus the rest of the world? And as we saw, at some point, the tariffs as it is, incoming tax doesn't really impact the exporter. They just go find another market.
These are fungible markets, right? And, you know, look what happened with Nvidia, again, if I understood it correctly, we were putting a 15% export tax on NVIDIA chips and China then just said, instead of have contributing to that tax, we just ban Nvidia chips altogether. Who got hurt?
An American company called Nvidia. Right? They're now suddenly not viable in the chi in the, in the second largest or economy in the world.
So, uh, it's, it's a interesting situation, right? Also, as you said earlier on, uh, Mike, what is AI software? Are we talking about agent force in Salesforce?
Is that now restricted, or is it deep seek coming the other way, which is open source anyway? Well, you know, I, I think the tariffs extend on goods beyond these tech products, right? And, and so I mean, the, the, the problem you have is, you know, it's the boyer cry wolf.
And you can only do this for so long. I, I think what we've seen is the rest of the world, not just the Chinese, the rest of the world saying, look, if you're gonna play these games, you're, we, we need reliable business partners and markets. And they start just leaving you out of the conversation, right?
And, and then you become irrelevant to a good chunk of the market. And, you know, and, and there are people here who say, well, that's okay because we're the biggest economy in the world. They all have to come through us.
Well, no, they don't. Not for certain things, right? Talk to our soybean farmers, talk to our meat producers.
If I can jump in on the soybean, uh, thing, that's an Ohio thing as well. I mean, we got a lot of soybean farmers here. Um, they're certainly feeling a pinch.
Um, I think there's a little bit of a, uh, even some, uh, Trump remorse happening among the deep red rural parts of Ohio where they're realizing that they won't be able to, um, export and, and, and for them, you know, it's funny. They say the same thing that, you know, wall Street traders and investment bankers say, essentially, it doesn't really matter what the rules are, as long as the rules are consistent and predictable, and they can work around them. The the problem is that if you're a farmer and you're trying to decide what to plant, that's a year ahead or multi-year ahead planning process, and there's a lot of money riding on that.
They take on loans, they plant, they tell, they pick, you know, they harvest and, and then they have to, you know, go to market with these things. You can't upset the board game during that process, or a lot of people are gonna be hurt. And, and in many ways, as you say, Alan, it's, it's the same with, with many of these other things.
I mean, the New York Times this morning was reporting that, uh, Trump is already backing down on his China tariff plans. And, um, and it, and it just was Friday that he announced these things. So how is someone supposed to plan around that?
How is someone supposed to deal with this? I guess the only plan that you can make is uncertainty, which is why the price of gold and Bitcoin just keeps going up. Because I guess people are trying to think about other hedges.
And as you say too, there are other markets for these things. Um, there are other suppliers for soybeans, and there are other markets for Chinese electric cars and rare earths. And, and, and you know, if you, we will look at what happened with the ai, uh, hardware market.
If you completely slammed the door, then, um, other suppliers are gonna emerge. And that's what's happening in China right now. As we're seeing the emergence of domestic Chinese manufacturers of, um, GPUs and also really incredible promising, uh, chip fab capabilities in China that would not have emerged probably if it hadn't been for these, um, tariffs and embargoes.
And that, that may be the ultimate backfire is I feel like there's, there is a playbook somewhere. Because, you know, this whole thing went down with the, uh, announcement from China and then within like, what, half a day to a day, Trump starts pulling AI software out of thin air. I doubt that.
I think somebody has, there's no way He's never even heard of that. You know? So somewhere somebody's written some sort of tit for tat response playbook somewhere.
I think they call it Project 25. Yeah. You think it's a, you think it's in project 2025?
I missed That. I think part of that whole thing is to, you know, go ultra isolationist, close up the walls, rebuild the wall of China, except in reverse. And, uh, so yeah, So, so Is this SA It's not main American.
G*******t. It's no good. All right.
So this is USA 1920s economic policy. Is that where we're going? Yeah.
You remember what happened in 29? Yeah. Remember that scene in Ferris Bueller where the teacher is boring all the students?
Do you know what he was talking about when he was bo boring all the students? Wasn't it the tariff Hartley? It was the crude holly tariff act.
Har, right? The tariff. Yeah.
That's the thing. If only Ferris Bueller had paid more attention instead of cutting class, maybe we would all be in better shape. That's an interesting, that's an interesting proposition right there, Steven.
Yep. Is that, is that, I thought it was Biff that we were blaming, but it's really Ferris Bueller. It's Really Ferris.
I, I blame Ferris Bueller for everything. And it was a crime, what he did to that car. Alright, we'll, We'll we'll see, you know, today's Tuesday.
Check back with me on Friday and we'll see where this is. Mm-hmm. Um, I, I, I've given this one enough of my oxygen in time.
My life's too valuable. Let's move on. We'll take a break, come back and let's talk about some, this is interesting.
ITSM in the news, ITSM platform Wars, you're watching texture and game. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions, your home life included, that work your protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back in, in another segment that also has a certain amount of tit for tat kinda, um, mojo. So now Salesforce says that they are in the ITSM business and they finally launched their agentic ITSM platform. And of course, this comes shortly after ServiceNow, which owns about half of the market share.
In ITSM said that they were moving into the CRM space. There are other companies in this space that includes B-M-C-I-B-M, Atlassian, but it does feel like there's a good old fashion war going on in the ITSM space. So, Sanjeev, what's your take on what's going on here?
You know, this is, uh, very interesting to see, you know, back when DevOps started, maybe a decade or so ago, people said, oh, will we need ITSM? Right? Will we need, or will it be developers ruling the world?
And you'll be able to push the big green button and things will deploy and they'll run autonomously everywhere. But in the past decade, all we've seen is that while the speed of, uh, writing software and developing code and deploying code has improved, managing what's running in production, the ops side of DevOps has pretty much remained the same. Right?
In my, in, you know, I wrote the original demos for Dummies back in like 2013 or 2014, right? The original one. It was like this, this thin, because we didn't have much matter to talk about.
You could download it for free from IBM's website. And one of the things I talked about there was, there's a impetus mismatch about how software is developed and how operations is run. And that's what devs was supposed to solve, where it's unsolved problems, still most IC MDBs have garbage in them because of the lack of automation.
People are tried solutions like, oh, we'll put everything on the blockchain. Sure, that just makes change immutable. But if you are, if you don't have any idea what's actually running in production, right?
Uh, you still will put garbage on the blockchain. So that doesn't solve the problem. It is very interesting to see all these companies still fighting it out, but does any one of them truly have a solution which has solved these problems, these challenges which companies face?
I don't know. Every large company I talk to, every large company I worked for has a major problem of they don't really know what's running in production. When something breaks, you're relying on human knowledge to say, oh, this breaks at this time under these circumstances, we know what the problem is.
Let's go bounce that server. Let's go, you know, uh, roll back these changes. Will, will, I hope.
I mean, Salesforce has, you know, massive, uh, you know, credibility in the market. They have a massive presence. Well, so does service.
No, I think those are the two big dogs in this fight. So it's fun to see how they will duke it out. And I think in the end, the good news about having fierce competition is, uh, the customer benefits from it because we will, they will try to out outplay each other.
The new variable, of course, this time around is, is ai, the AI agents, can we truly make infrastructure autonomous? Can we make it self-healing? Something we've been promising in the industry for, for decades now.
Uh, but I think with AI agents, we have finally headed in that direction. But let's see, it's gonna be fun. It is, it is.
Well, depends where you're sitting. If you're in the middle of it, it may not be fun, but sitting where we are, it, it's fun. So a couple things.
Number one, does this mean Salesforce is really just not a CRM anymore? Um, you know, they've been saying that for a long time. But, but here's the other thing.
Every gener this, every generation or so, there's an opportunity where it seems we throw all the cards up in the air and let's see where it lands this time, right? And, and AI is this generation's, let's throw the cards in the air and see where it lands this time. Because basically it, it allows us to change the rules and, and do these things.
So you have a CRM company that wants to do ITSM, you have an ITSM company that wants to do CRM. You have ERP companies that want to be agent platforms, right? Because that's always what they were designed for.
Anyway, they'll tell you. And, and, and so the, the battle lines are are in flux, right? And it's not just service, uh, ServiceNow and, and Salesforce though, they're, they're two of, let's call them today's darlings, right?
They're two powerhouse companies of the existing power infrastructure. But I'm telling you, look, for companies like SAP to be getting in here, and of course IBM and you know, your traditional Oracle, and, and these guys, you know, you love the smell of fresh meat in the morning, and there's fresh, there's the smell of fresh meat out here. And the, and these guys are not these guys.
They're not guys. These, these players, old, new, established, they're all very established. Because make no mistake, this is not a little guy's game.
There's not a startups game. It is a big boy game and right, but they're going war. I don't just look at this, just look at this a little bit differently, and maybe Steven, I'd love to get your opinion on this, but, you know, the people who buy CRM in an organization are not the same people buying the ITSM platform in that organization.
So just because Salesforce showed up and said, I've got an ITSM platform does not follow that. Everybody who buys ITSM cares. So, you know, how do they actually do something here that the people who buy ITSM are gonna care about?
Well, and I, I think that that's, that's exactly right. In fact, I would go even further and say that, um, you know, if you are a very strong, if you're very well known in one area of it, that can actually hamper the acceptance of your, of you in another area of it. I mean, look at IBM in DevOps, for example.
I mean, IBM is undoubtedly one of the leaders in the DevOps software and open source software especially. Thanks now that they've got HashiCorp and Red Hat, and yet I think if you ask the average, you know IT person about IBM, they wouldn't go to Linux and open source and DevOps. They would start talking about mainframe or something, which is like completely ridiculous.
It's the same with Salesforce. You know what I mean? Salesforce frankly has egg on its face.
It has a reputation of being a difficult product to implement, a difficult product to get value from. And if you go to an IT crowd and say, Hey, um, you know, Salesforce has got a product in this ITSM space, I, I think a lot of the IT managers might immediately, um, discount it because of their history with Salesforce. On the flip side, if you go to a business person and you start talking about Oracle or something, I mean, they're, it's the same thing.
They're gonna say, Oracle, we've been trying to mess with their stuff for years. You know, it hasn't given us the, you know, it's, it's all nuts and bolts and whatever over here. You know, we need a, a partner, we need a service.
Now that kind, you know, I mean, we need a sales force. So these things, it's, it's a Mars and Venus problem, and we've been seeing this for a long time in IT where you've got companies that, uh, they know how to talk to one market, and then they think that they're gonna be taken credibly in another market. I mean, you know, go to go to Security Boulevard and see what they think of, you know, data protection companies in the security space.
It's the same thing. They're, they're using some of the right words, but it's like they're speaking a different language. It's like Portuguese and Spanish or something, right?
I mean, they, like, they, they're just, it's a real hard bridge to cross. But one thing I do wanna say is, what a relief to be talking about. Not ai, But we aren't talking about ai.
Oh, You had to ruin it. In fact, Sanjeev, I wanted to ask you this question. Since you wrote the original book.
Um, some people are saying that this is, you know, the rise of ai, this is a bullwinkle moment in the DevOps landscape, and this time for sure, we're gonna unify all this dev and ops stuff, and this is our moment in the sun. What do you say? Yeah, I, well, first of all, I, as somebody who's been advocating this for over a year, I hope that is true, right?
But I've seen this movie too many times before and being disappointed every time to say, is this really the answer? I hope it is. But at the end of the day, you know, the, the proof will be in the pudding at the right.
I think there are some very interesting solutions coming up in the market, right? Where truly with agents, we can do things, and with ai we can do things which humans could not do, given the scale and the complexity, just being able to analyze what's there. You know, think of how many companies that have startups have come in the last decade who said, we will go spread out these agents or crawlers in your infrastructure, and they'll discover everything that is there, and we will able to repair things before they break before or predict you when, when an outage will happen.
None of them really served, you know, delivered what they promised. I'm just hoping that this is true this time so that people can, like, like me can say we were right 10 years ago, but, uh, I'm not going to be holding my breath. I'm going to be hoping it's true.
No, I, I do wanna go back to this cross setting, you know, conversation we were talking about. And sorry if I'm mis messing you with your flow, Mike, and not moving on to ai, but I think some, one of these, one of the challenges I've seen as being a buyer in, you know, I've worked for two fortune hundred companies in the last few years and was on the buying side. We seem to discount when it comes working with purchasing organizations of a large company.
We seem to discount the, the, the power. A large company like a ServiceNow or a Salesforce or a Microsoft and IBM bring to the table through their enterprise license agreements and the ability to bundle software and literally squeeze everybody else outta the market. That's the play, that's the power, kind of the, the, the nuclear weapon.
Something like Salesforce brings to the table. That's what they did with Slack, right? They're like, Hey, it's in the package, right?
It's in the bundle. That's what Microsoft does all the time. Why do we all have teams despite us not liking teams and preferring Slack?
Every company has teams because it's a part of the bundle. That's the selling, the b the conversation when it comes to the CFO and the buyers at the budget holders, they go, if I can buy ITSM from Salesforce and we're gonna save me X dollars, maybe I should force my engineering teams to look at it. I think that's the part we are missing, and that's the nuclear weapons, so to speak.
Uh, these, these, these companies have. That's why to me, it's very interesting when somebody who's already getting millions of dollars, right? Dreamforce, you can go and see who all comes to Dreamforce, right?
These are people carrying hundreds of millions, if not billion dollar budgets. If they're going to say, I can now remove another vendor, I can save this many million dollars by buying ITSM from Salesforce. It's going to change the conversation.
Agreed. Mike, what, what Bullwinkle moment other than the three of us here, the four of us, how many people raise your hand if you know what a Bullwinkle moment is out there. Us.
That's what I thought. The rest of you not. So I'm doing my romper room thing and I see Little George and that.
It's, it's, it's, it's one of the great classic cartoons of all time, man. And, and more relevant today than ever. Alright.
Should we say a Lucy and football moment? Would that be more relevant to the youngins? Yeah, yeah, yeah.
To the younguns. Anyway, You have to give the young ones office, you know, uh, analogies from the office or from, yeah, yeah. Something, something a little more, we gotta get more relevant.
Oh, well look, that's your homework for today. Go ask your AI what a bow winkle moment is. Hey, next week everybody's gonna be using that phrase promise.
Absolutely. And you heard it here first, but, but Sanjeev, you're right. That, that, that is the power of the big stick, right?
You bundle it in. Microsoft did it, right? IBM does it.
Uh, they all did. This is what big companies do. And, and it'll be interesting.
And, you know, um, I, I do think you now it's one thing to say, well, I'm throwing out Joe Little company because it's coming with my big company. But when you start getting turf wars between ServiceNow and, and Salesforce and Salesforce and SAP and SAP and IBM and IBM and Oracle, you know, that makes those procurement shops spin. It's mutually assured destruction, right?
Yeah. A little bit. 'cause they all have big giant enterprise license Grid.
Well, until, until the battle lines will be redrawn, right? Mm-hmm. I think this a, a agent AI thing, as I said, is throwing the cards up in the air and giving everybody a chance to, to claim new turf.
So I'll say like the sharks and the jets, you know, what we referring To? Un un un un until the, that's a one guy gets fed up and goes and gets some other tools and just slides them in the back door, right? Absolutely.
Well, you know what? Here's the other thing I've learned, seeing these kind of turf wars erupt over the years, there's always one or two new guys who slip in and this is their chance, right? com bubble burst and I thought out Vista search was the way to go, this company come called Google snuck in among excited home in Alta Vista and all that.
Uh, there, there is, right? It's an, there is an opportunity, not widespread, but for a new, a new, uh, Mm-hmm. You know, giant to emerge.
You mean Alta Vista originally created by, I believe, digital Equipment Corp. You thought that was gonna be the answer? No.
I loved Alta Vista search. I, I'll be very honest with you, I liked it a lot. Next, he's going to say his Facebook profile is still open.
Yeah, It is. All right, let's take a break. We'll find out what happens.
You know, it, Hey, it SMS relevant again, that's great. ILE four is here. Um, let's come back and talk a little bit about unstructured data.
Is it in crisis? You're watching Textron Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techstrong Group. Hey, folks, we're back in.
There's an interesting article over on Tech Techstrong it talking about, um, whether or not we have a silent crisis around the amount of unstructured data we've been collecting all this time. And some folks estimate it's 30% of the IT budget, and a lot of that data is well useless and pointless, and we should get rid of it. But Steven, you've been around this whole data management issue forever in storage.
And so let me ask you, you know, A, is this a crisis? And B, how do we get rid of all this crappy data? Not only is this a crisis, this is a perennial crisis.
This is, this is a crisis longer running than one piece. Sorry, I had to put in a, a modern reference here. I mean, um, this crisis has been going on so long, uh, and we've been talking about it so long.
I could, I could probably find an old PowerPoint Microsoft 98 document from a presentation at Storage Decisions in 2001 that says exactly the same things as our article says today with even the same customers. Here's what's going on. Um, just to be very, very clear to the listeners, so unstructured data, I, I'm sorry, I get passionate.
This is my area. I'm MR. Storage.
Unstructured data is basically data that's not in a database, but it's also, and this is important, it's data that is not well described. So there can be, in my opinion, data outside of a database that is structured. In fact, I, I have seen, uh, incredible file systems, uh, that are incredibly structured and well described with metadata.
Um, I have seen, and, and, you know, searchable, categorized all that. I would consider those structured data, not even semi-structured, but structured. But if you look at data companies, essentially, um, you know, it's in their nature.
You know, if your background is in SQL or now, uh, no SQL databases, anything that's not in a database is unstructured. Lemme tell you, a lot of things in databases are pretty unstructured too. But, uh, point is most businesses have huge amounts of unstructured data.
The, the article that we, uh, just recently published, um, about this topic over at, um, at Textron, uh, it talks about many examples in many industries. And, and they're actually really good examples because I think people often jump to, oh, it's the nas, it's the, the, it's, it's Mike's and Alan's files on the file server. That's the problem.
No, no, no, no. It's the, like millions of medical images. It's the thousands of pages of scanned documents for every patient, or it is all the geophysical data that's been constructed, you know, built up over these years.
And it's not always in a na it can be on all sorts of things. Now, the opportunity here is to structure that data or to mine that data for value. And that's what a lot of companies are doing right now.
You know, we, I was at click Connect earlier this year, and they've got a lot of capabilities to structure unstructured data. Um, our article, we mentioned cloudent as a company that's really leaning into this. Um, you know, I've certainly heard a similar story from Microsoft, uh, talking about pulling data into the cloud from Amazon, uh, web services about pulling data up from Google.
Uh, for me, uh, I hate to do this, but I'm gonna do it. One of the most exciting things that's happening in the world of unstructured data, yes, it's ai because AI is actually really good at looking at files and extracting structure from those files. In fact, I get more use of chat GPT as a data structuring assistant than I do as chat GPT as a write my homework assistant.
Essentially, I will routinely throw articles or data sets or spreadsheets or, you know, CSV files or, or just plain images at chat GPT and say, describe this in JSON. I need to know, you know, a list of of faces, a list of animals, a list of, um, you know, background objects. Uh, you know, I need to know which companies are mentioned in this article about unstructured data.
I need to know, um, you know, which, uh, you know, I need a summary of all of the, um, different vendors that are mentioned in this spreadsheet. AI is really good at that. And the best, uh, answer to unstructured data that I've ever seen is essentially building data structuring systems that leverage LLMs to pull information metadata out of these and, and surface that and make it more useful in the future.
Whether that means moving it off the file system into cloud storage, or building metadata systems and searchable indexes around them or whatever it means, this is really an opportunity that I've never seen before, and it's something that I could get really excited about. And, and frankly, it won't burn down the rainforest with, uh, chatbots that are telling us to kill ourselves. It'll, in fact, help us to use more useful, uh, get more use outta the data we already have.
Sanjeev, after three plus decades has Steven's moment Finally come. Yeah, say Yes, please Say yes. First of all, first of all, I hope so, right?
As a former executive from Dell, I don't, I don't want anybody deleting any storage sitting on Dell hardware, right? So, uh, uh, any Pfizer, they're sitting on Dell storage, please keep them there. In fact, keep them growing, right?
Uh, but I, I think, Stephen, your stuff, spot on, right? The challenge has been, I mean, I'm, I was at IBM during the big data. I know, remember big data where everybody was buying these, creating these data lakes and data warehouses, and it turned into data swamps and data, you know, backyards, right?
And the problem was exactly that. You dump data, which you don't know anything about, it's got some label on it and obscure label with somebody put by, you know, a human put on it. Uh, or it was put on by a machine which was not intelligent, couldn't look and analyze the way today you can.
Uh, I think we finally have the opportunity to say all this data in our data lakes, or data warehouses or data, whatever, its storage or secondary storage, is it even useful? Because the first, that's the first thing you wanna find out, right? Most people do not delete the data because they think one day they'll be able to get value of it, right?
I remember working, uh, with a company which was at that point, 104 years old, and they had every transaction they had ever made stored, and was that needed? It was not regulatory required, it was not a part of their history, but they felt one day we can mine, and I'm scratching my head going, you want to mine the buying practices of a teenager 104 years ago? Even that teenager isn't alive anymore.
What are you going to get out of it? But, you know, that was the hope. But I think that hope can result because AI agents, right?
Stephen rightfully said, are really good at looking at unstructured data, large amounts of data, and extracting, you know, some labels out of it, right? It could be as simply as just properly tagging all of it, and it can finally be useful. Alan, do We have a data hoarding problem?
Is that, I was just gonna say that really what this really comes down to is hoarding. Hoarding, right? I'm keeping, and, and look, I'm guilty.
I'm as guilty as the next person, right? You know, because maybe someone will need to look at my tax returns from 2003. Um, you know, I, I go through this on my own, like personal drives and stuff.
I, I, now, on the other hand, you know, my, my Google photos probably, I'm ashamed to tell you how many photos are in there, um, but I know I'm going to need that one. I wanna see when my, you know, I remember when my kid was four and I want to see what he looked like that, right? Or what did I do during this?
At, on this day through the years, it's a giant hoarding issue, and we definitely have it and work in, in, you know, in business, because you never know what you think you're going to need. Or actually, you know what you think you're going to need, you just never need it. Or you don't know where it is.
It's buried, right? Yeah. Mm-hmm.
And they reverse is also true. Alan, I'd like, I love to ask you the question. How many photos in your Google Drive actually duplicates or duplicates?
Oh, there's ti so I do dedupe, but what I found is Google Photos, this is another discussion. Google Photos will take three photos that are similar, but not exact and, and make them dupes. And so I get upset with that.
But, But we, we have that problem in the business also, that there is large te petabyte scale, te definitely hundreds of terabyte scale data, which is duplicate. Mm-hmm. Because they duplicate for some reason.
Yeah. To work on it and never deleted the duplicate either, even though that reason to keep that copy isn't there anymore, Right? How many times do you see a file name with the one, number one after it, or two or three?
Yeah, those are the ones you should be getting rid of. But Maybe, maybe, but who's to say that it's actually a duplicate? And I'll tell you if another thing I, um, in, in an interim in my career, I advised, uh, general counsel at public companies on data retention policies.
And it was funny because when I first walked into their office, they would inevitably say, delete, delete, delete. Get rid of this old data. It's a risk to the company.
It's costing us money, delete it. But once I explained to them the fungibility of data and the fact that, uh, this email that you are going to delete is actually stored on the email server of your client as well, and they will produce that in court, even if you can't, suddenly the tune changed. And the answer was, save, save, save.
So I have, um, a bunch of self-proclaimed storage laws that I've named after myself, because that's the kind of narcissist I am. Uh, one of them is that essentially, uh, the capacity of storage, uh, your next storage purchase is going to be, uh, twice the size of all the storage purchases you've made before. And another one is that, uh, your use of storage will expand to, uh, take up all the storage available.
Um, don't delete things, never delete things. Just keep hacking it away. My blog is called Pack Rat, by the way.
I should point that out. Uh, just keep it, just keep it all. So you hear, you hear it from a hoarder here, okay.
And try to categorize it and try To structure it. You know what, hi, my name is Steven. I'm a hoarder.
I'm a Hoarder. Listen to me ho. Anyway, hey, that's a great way to end this show.
We're about out of time. It brings me joy. Look, if it brings you joy, do it.
Storage is cheaper enough. Uh, that's what I keep hearing. Steven Sanjeev, Mike, thanks so much for joining.
Thanks. You out here for watching and participating in this, uh, mental Health Day here as we explored various topics. As usual, we have a full text drunk TV lineup immediately following.
Steven, you've got a field day this week, don't you? That's right. Um, I'm gonna be in Vegas.
Uh, we are meeting with, uh, NetApp, speaking of storage. Uh, I'll be meeting with NetApp, uh, at NetApp Insight in Vegas. And we are gonna be live, uh, streaming on, uh, tech Strong as well as Tech Field Day on Thursday.
Uh, it's actually not live, live. We're recording it on Wednesday and we're gonna stream it on Thursday. Uh, but, uh, with all the news coming outta there, so in terms of this data, uh, processing the metadata, the ai, uh, use of data, all that, that's what NetApp's gonna be talking about.
So that'll be Thursday. Fantastic. And I would just like to note that no data was harmed during the making of this particular That we know of.
And Stephen, please, please ask Jack GP to tell you who Marie Kondo is. I, I'm not going to, it, it doesn't bring me joint. All right.
I, I will mention that we are going to be live at what was known formerly the artist is formerly known as, or the conference formerly known as Quais Security Conference. It's now Qualys Rock On Risk Operation Conference, and, uh, risk Operation Co. So Rock On.
We will be streaming live from Rock on on Wednesday and Thursday as well. So busy, busy stuff on Techstrong TV and Tech Field Day. Stay tuned for it.
Stay tuned for Tech TV right now. Text on TV right now. Until then, I'm Alan Shimmel.
I'm out. We're Actually gonna be talking about MCP. And if you went and watched Tron over the weekend, you may have been one of only eight people that did.
However, we're not talking about the master control program. This time we're talking about something different. Model, context, protocol.
Welcome to the Security Boulevard podcast, a cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube Channel, tech Strong tv, and all of your favorite podcast platforms.
Before we jump into today's episode, let's meet the panel starting with my friend Alan. Alan, welcome back, Tom. Thank you.
You know, this is my first, uh, appearance on the New Security Boulevard podcast. We, of course, we've been podcasting around the Security Boulevard name since we launched it. Uh, I'm Alan Shimmel.
I'm the founder, CEO of Techstrong Group. com, as well as Techstrong tv, and all of its various frontiers on the, on the rich media landscape. Um, beyond that, though, I've been in security for about 30 years and started several companies, co-founded several companies in the, we used to call it InfoSec Space before it was cyber.
And, uh, it, it's a passion of mine, so I'm happy to be here. Thanks, Tom. Well, we're happy to have you here, Alan, as well as our special guest for this episode.
Mr. Scott Roon. Scott, tell everybody who you are.
Hey, Tom and Alan, great to be with you both. I'm Scott Roon. I am a happy and grateful, uh, serial Tech Field Day delegate.
Looking forward to a couple events coming up in the next few weeks. I am a co-founder of the Network Automation Forum, um, and I'm the co-founder and CEO of my consulting company, solutional, where we help people rationalize AI adoption and kind of cut through the hype, Right? And of course, I'm Tom Hollingsworth, event lead for Security Field Day and other exciting events within the Tech Field Day business unit at Futurum Group, and one of Alan's coworkers.
I did wanna call out that it is, uh, gonna be National Dessert Day. So, uh, hopefully you guys are having a sweet treat while you're listening to us. Um, and hopefully it has real sugar in it 'cause it's also National Real Sugar Day.
Who knew that? Um, well, the sugar, sugar people did. Uh, but I wanna talk about a topic today that's actually kind of sweet and that has to do with ai, but hold on, hold on.
Before you race to the comments to tell me that we're talking about AI again, we're actually gonna be talking about MCP. And if you went and watched Tron over the weekend, you may have been one of only eight people that did. However, we're not talking about the master control program.
This time we're talking about something different model context protocol. It's the hot new topic this year that has really driven adoption of a lot of different ag agentic AI components, but of course the Security Boulevard. So, you know what we're gonna talk about, we're gonna talk about the security aspects of it, and Scott, you kind of jumped in with both feet on this, uh, topic.
So maybe you could kind of introduce to the folks out there. What is it about MCP that makes everybody want to use it, and why is it the security parts of it are starting to maybe keep you up at night? Well, to, to give kudos, right?
MC P's been with us for 11 months, you know, at the time of this recording. It's really just kind of hit, hit the street, um, very quickly. I, I'm a networker who has done a lot of network security stuff in my life.
And to see yet another product come out so quickly, you know, that wasn't governed by let's just say very long processes and, um, other, um, standards bodies. It's, it's pretty amazing to see it. It, um, but it is reflective of this typical, um, product life cycle where step one is get it to work.
Step two is find a way to manage it and then, you know, sometime later, step 179, secure it, right? So there's like, let's make the packets go, um, and then we'll figure out how to secure all this later. Um, I have been pleasantly surprised with like the integration of OAuth into MCP already.
That's a great step and, you know, makes me hopeful in the first, you know, year of its lifetime here. But you know, miles to go before we sleep on this. So it's very interesting that you talk about this idea that we need to make it work first and we need to fix it, secure it later.
I've heard this before, and Alan's the one who actually brought this up when we were kind of talking about it pre-show, uh, Alan, this feels a whole lot like APIs to me. Is that what it kind of feels like to you? Well, there is a resemblance, but, you know, invent it, make it run, worry about security later.
That's pretty much standard operating procedure in it for the 35 years I've been here. Um, you know, it, it's always the caboose on that train and it's kind of the afterthought, Tom, I gotta just one personal pet peeve of mine, I gotta throw out there. I hate all of these made up holidays and days.
I don't know if hallmark's behind it or what, but it, it's, it, I think it's been the bane of it. It, it's what led us down a slippery slope. So I don't care about National Sweet Day, sugar Day or any of those days, but back to security, this is a typical IT innovation.
Wow, we got the greatest thing here since sliced bread. Let's go out, run as fast as we can and get as much as we can. And in this age of ai, time is condensed so things are happening faster, quicker, speedier, more velocity.
And then, you know, someone says, but well, but wait, but wait, what, what about the security? Scott? I would, I would pause posit that zero auth wasn't put in for security, was put in to make it easy to log in in these things.
Sure, yeah. You there? That that is certainly an element to it.
I'm gonna take a small win here where I can, but I I totally hear you. Yeah, I mean, Tom, back, back to your point though, yes, this, to me, this was very analogous to the whole API security thing because you know, what we're really talking about with these MCP servers and, and you're right, Scott, I, you know, I thought it came out around last January, so I have 10 months, but maybe it was 11 in, in 10 or 11 months. It has become the defacto standard for how agents talk with agents and other agents with, you know, within your enterprise.
Now there is a competing standards sort of competing called A to a, which is the, under the auspices of the Linux Foundation. And maybe that'll have better security, I don't know. But quickly, this is the defacto standard for agent to agent communication.
And, you know, God bless the age of AI in, in, in 10 or 11 months, this thing is like, it's like it's been around forever. And, and, and we had the same thing three or four years ago. You know, someone came up with the, the API economy and, and, and its studies were done that a majority of the traffic going over the net over the internet was API to API traffic web, web to web kind of thing.
And all of a sudden someone said, you know, the most important attack surface left in security APIs. We need to, we need to know what APIs we have, what their configurations are, what their security posture is. And until we have that, we're, we have a blind spot to a majority of the traffic on the internet.
Scott, you're you're in the space, you know, you've heard, you've heard the stories. Yeah, I think so. I couldn't agree with you more.
Right? Um, and some of the work we've done in network automation forum, uh, we put up a blog post a few months ago, that's just a collection of community comments, not necessarily on API security, but API quality and usability. And we definitely caught a thread of, you know, there's a lot of inconsistent, you know, publishing of API specs people, you know, getting half functionality, three quarters functionality, and that being a suppressor to actually driving automation for network and security equipment.
So there's room to improve there for sure. Maybe that's more of an issue in the network element world where they're trying to be more API forward and move away from, you know, the CLI addiction, that so many of us, especially Tom still have, sorry, Tom. Um, you know, but there's, there's gotta be room for improvement there, you know, from a security and functionality and consistency perspective.
So let me offer this, because I think you're both right, that sometimes it feels like the security that we get with these rapidly developing protocols is more happenstance than it is by design. You know, uh, you know, Alan, you, you brought up the fact that, you know, using authentication mechanisms that just happen to be secure to ease, user login may have had a serendipitous benefit. What about, you know, using HTTPS calls for APIs?
Like, I'm sure that that wasn't top of mind for them originally. Like, oh yeah, you know, we'll just do this or we'll do that. Oh, hey, it just so happens that we've secured this communications channel by default years ago because everybody on the internet did.
And when you look at the way that a lot, especially things like electron apps that are basically just web browser wrappers anyway, um, we've, we've arrived at a state of security that is maybe a little bit harder to configure on the back end to begin with, but ultimately is more secure in the long run because the fundamentals of what we've done have changed so significantly. Do You, do you feel like that Go ahead. No, no, go ahead.
Finish your thought, Tom. I I, I was just gonna say, do, do you feel like that the people kind of behind the scenes that have been working diligently to do this have done more to bring the state of security forward than those people that are living on the bleeding edge? Yeah.
So I, I will tell you the, the, the, the, the big issue in API I security is most organizations didn't even know what APIs they had open, what APIs and what APIs were talking to, which APIs. And you can't defend something you don't even know you have, right? Yes.
The communication, you know, via H-C-T-P-S protocol and, and, and, and in transit is great, but if you don't know what you have and where it's going, it's good to know that at least while it's going, it's encrypted. But you still gotta, I would, you still have a fundamental issue. Um, that, that being said, though, funny thing happened with API security.
There was a whole cottage in more than a cottage industry. There was a whole bevy of API security companies that came forward. The big one was called no Name.
And then there was another one that got, I believe, bought by Red Hat. And then there was, there was a half a dozen of these, uh, trace traceable io ai, excuse me, traceable AI was another part of Harness. Now, as often happens in technology, and Tom and Scott, you've probably both seen this became tomorrow's feature.
Sure. And so, API security, including API discovery, API communication encryption, API configuration has now been subsumed into some of these, you know, platforms that, that we, that we have around security. You know, it's, it's funny.
I'm sorry, finish your thought. Oh, No, that I, that was my thought. So, um, I've had the real honor of doing some work, um, associated with DARPA through something called the Embedded Art Entrepreneur Initiative where, you know, DARPA works with lots of startups in the security space and other technologies that come up with really interesting piles of tech.
Um, I won't call 'em products, right? But they come up with fundamental artifacts and pieces of functionality, and they need help figuring out, should this be a standalone product? Should this be a feature on somebody else's platform?
Or you're too late with this. It's already, it already exists as a product or a feature on another platform. Um, but it's been amazing to see those elemental, you know, uh, I, I did some really interesting work on, um, IM um, issues and graph theory with a particular company.
And so try to figure out, um, does this belong somewhere? Turns out Wiz already had that covered. Um, but, uh, yeah, the integration piece is really important here.
You know, many companies come along with pieces of fundamental technology and how well they're integrated into bigger platforms, bigger products matters, um, and, you know, we see it, we see it in the, um, network automation space. Like there's really cooperative, um, open working together between lots of different technology providers. Um, how well you do those integrations really matters on how secure it is in the long run and what ease of use looks like.
Yeah. Let me, and I don't mean to scare anyone out here though, but let me frame the, the real problem we're dealing with though, right? APIs and APIs talking, the APIs were great.
I think as we sit here now, on the dawn of the AI age, or in the early days of this AI era, it almo the automation that API to API gives us almost seems quaint because it was automation without autonomy. As we enter agentic ai and what does agentic AI really mean? It means we're gonna have autonomous agents who aren't just doing a task.
They're creating, they're, they're completing missions, multitask missions autonomously, and in order to do so, they need to speak to each other because each one of these agents are in their own multitask autonomous mission. If we don't secure these things, the, the, the threshold for chaos, right? The, the, the potential, you know, what could go wrong here is, is unlike anything we've dealt with, right?
I'm not gonna go Y 2K on you, but you know what I mean. This is, if we don't, this may be a case where we can't wait for the proverbial stuff to hit the fan before someone says, oh, we should really think about security here. We've gotta get in front.
Yeah, I couldn't agree with you more. And there's this whole body of work around, okay, what do agents need before we even think about trusting them to operate autonomously? Um, they're gonna need identities.
Just like people have identities. We're gonna need to be able to control access to other resources based on their as assigned identity. Um, the, they're gonna be able to start firing off 5G calls at some point, right?
So I've gotta watch how that filters down into not just my network, but you know, specific pieces of the network. Um, you know, does, does every, does every, uh, agent need to have its own, you know, virtual sim or eim, um, to watch it as, uh, we make calls. I, I agree that this is a huge body of work that needs to be addressed.
I also see attenuation, see what I did there with the 5G comment, um, or friction, um, against allowing autonomy to happen too quickly. Like I think there's a huge process that vendors and system integrators need to go through to get enterprise IT shops comfortable with autonomous operation. Some are, you know, very few are more eager than others, but paying attention to what does it look like to develop trust in autonomous systems is gonna be a huge gate to adoption in just about any organization.
Scott, you're talking like the security guy. So let me ask this question because I'm sure. Someone in the comments is already thinking about it.
Yes, there is this hesitance from the IT departments to move too fast, right? Because we've seen what happens when someone rolls out an automated autonomous system that makes decisions. Either they don't like it because they feel like they're cut out of loop or worse, it makes one mistake that then it gets amplified.
Right? Is the, is the speed aspect of it coming from the IT departments, or is it coming from the decision makers above that who said, well, I was told by Sam Altman that this thing will just run my, my company for me, and I don't need to think about it, but why is it taking so long for this to happen? You guys promised that this was gonna be done already while everybody else behind them is like, whoa, whoa, whoa, whoa.
Wait a minute. We're not quite there yet. I've already laid off the people I was replacing with.
Exactly. There you go. There you go.
Yeah. Yeah. No.
So let, let me give you an interesting factoid. I heard at a conference recently, I think it was 60% of CIOs are asking for bigger budgets for it, because they're being pressured by their boards to do more with ai. Yep.
And in order to do more with ai, they need to spend more on ai. And so they need to increase their budgets. Uh, so Tom, that's your answer in my mind.
I, I, I, I believe that that's real. I haven't seen that statistic, but that totally matches conversations I've been having. Right.
And if you think about budgets moving from actual personnel costs to paying for tokens for agents to run, like that's a real shift. I think we're gonna see over the next few budget cycles, um, that's directly follows that trend. Um, I had something really important to say there, and I've, I've dropped it.
Tom, do you wanna take it? Well, let, let, can I, I, I gotta talk, Tom, your point about people willing to trust autonomous. So I had an interesting thing happen to me on Saturday morning.
I had to go up to visit a, a relative in a hospital up about two hours from the house. And I, I took my wife's car. You don't usually drive it.
And I got on the highway 95 and this nice agent's voice came on and said, oh, we detect you're in a location, not a location or a whatever highway, and you could use the, uh, assist plus driving, just press the button on your steering wheel. I press the button on my steering wheel. Now, I've used cruise control.
We've probably all used cruise cruise control before, right? It takes a little getting used to, but it's, this is not, this was full on driving my car. Sure.
So, I will tell you that for the first 15 minutes, my heart rate was probably around 180. And, and I, I wasn't touching the steering wheel, but I had my hands right over. 'cause I'm waiting for something go wrong.
And I could go like this. And that took me maybe 10 or 15 minutes and I, I kind of loosened my hands up a little bit. My heart rate went down a little bit, wound up with, you know, my hands on my lap over here.
But it was so g*****n strict, excuse my language, it was so god damn stressful. Then I realized I'm better off shutting it off because I was too stressed out. Hmm.
You know, waiting for calamity to strike. I think there is that. However, over time, I think people get used to it.
And I think that's what we're gonna see here. Yeah, I agree. And to your point, I think that there's, there's something you brought up there, like when people get used to the idea of it running, it disappears into the background, right?
Like, they know that occasionally they might have to touch the steering wheel or, or something like that. But there are also videos out there of what happens when the system fails. I think one of the ones was, uh, it actually was a, a major national news article where at a self-driving vehicle would not stop at a railroad crossing because it's not something it recognized and it didn't know that it was supposed to stop there.
Those are the kinds of exceptions to the rule that people focus on when they're talking about these things. Well, what happens if it uses the wrong OS on the upgrade? What happens if it does this?
And, and they're ignoring 95% of the things that work most of the time. Yeah. My calendar program might accidentally schedule me for a call at two in the morning instead of two in the afternoon once every nine months.
It's the rest of the time that it just works, that I'm just oblivious to. So is that part of the problem we're running into here is that people are just oblivious to the fact that we are securing these things, that we are trying our hardest to prevent them from becoming problematic. You know, something as simple, Alan, you brought up is like being able to steal data as quickly as possible rate limits, right?
Like, I can't pull more than a thousand requests from this particular device per minute. Sure. Not a problem for a human, not a problem for a well-written script.
A problem for somebody who's trying to dump as much data as possible before they get discovered and, and ejected. Like, are we, do we need to start thinking about security in a different way to make it seamless so that people just assume that everything works? Well, I so your comment, Tom brought me back to what I forgot a few minutes ago, and I'll just say this is all representative of a good and necessary tension between the innovators and the implementers.
Right? And I think the innovation, um, around MCP and so many other things that we've seen has been awesome. And that's great.
And we need people who are on the bleeding edge, hacking their way through the jungle and creating a path for others to follow eventually. Um, and it's the responsibility of the, the people who are procuring, implementing, and operating the tech to say, whoa, whoa, whoa, Whoa, whoa. Let's make sure this is hardened for my use cases that I've kicked the tire sufficiently to make sure I can have a trust in it.
And even if it's not full blown autonomous operation on day one, I've got something in place where I can start and I can map out a plan to say, what does building trust in this system look like? I, I think we're always gonna have those two, you know, things engaged in that tension. On one hand, it kind of is what it is.
On the other hand, I think it's good. And iron sharpens iron in this case. Yeah, I would agree.
Well, here, here's the other thing though, guys. And I, I, I told this story before. I'm doing a podcast for Network World about, I guess it's gotta be around 2010.
So 15, 16 years ago, and I had the CEO of at the time of MongoDB, right? And Couchbase two of the, at even then, two of the biggest, what we called NoSQL databases of its time. And I, yeah.
And back then there was a lot of discussion, you know, that they, the security in these things was non-existent. And I remember asking them both, I said, gentlemen, a lot of people say no, SQL stands for no security. What's the deal with security in your products?
And they both agreed and said this out loud. I couldn't believe they said it out loud. We will put in more security when our customers demand more security and as much as security people, and Scott, I'm, I'm one too.
We sit here and think security's the most important thing in the world. How could you roll something out without security? If customers who are running and have established MCP as the, as the de facto standard are not saying, what about the security?
Right? Can't blame the, the producers, the developers for not doing more about security. And that that's the, that's, you know, the world we live in.
Well, it's, it's a fair point. And, and I'll turn it into, you know, the, the last RFP that you read, right? There's a security requirement section in there, most likely, but it's not the first section.
It's usually buried below. Right. Um, because there is, you know, we're worried about that.
Make the packets go make the product work first. Is it gonna fit the business need that I need to drive in my enterprise? Um, and Oh yeah, by the way, um, can you show me it secure?
You know that it's not the primary thought. No. I mean, this was a big thing.
com in 20 14, 20 13, and then within a year or two, DevSecOps really showed its head and a there a lot of the DevOps people, they both, you don't need devs, you don't need SEC in the middle of dev and ops. DevOps has security built in. There's no such thing as DevSecOps.
It's just a marketing term. And I, I was one of them, I'll admit. Um, but I came to the realization that you did need dev sec ops.
You did need to put security in the middle because you needed people, both security people and non-security people to recognize that security was important and it had to be part of the equation. Yeah. And I, maybe we need MCSP Level contact security protocol.
Yeah. You know, something with security right in the middle, because that's what it's gonna take for us to make security, if not front and center, at least you know where it belongs. Well, I will, I will take that and like, I remain basically hopeful on all of this.
And I would say, what if we could have this more unified view of what's in our sims, what's happening from a securities perspective? What's happening from a network observability and streaming telemetry perspective? What if I could even pull stats on, you know, what's happening with my compute platform and different application performance?
I think LLMs provide a unique opportunity to provide an integrated view of what's happening across those domains. And I'd love to start a movement with you all right now to push our vendors to say, why not give me a unified view across my whole IT ops? You know, doesn't doesn't mean those silos go away.
There is specific expertise that's needed in security, in networking, in application performance, but if I can create this shim layer or this umbrella that brings it all together, I think that could be really powerful. Yes, we can. Tom, you were gonna say something?
I agree, Scott. Um, you're just gonna need to upgrade to the enterprise plus AI license for the tool. Um, that's gonna be eye wateringly expensive while I build it, and then everything's gonna be rosy.
But I, nice, nice. I believe you. I go back to something that, that I is kind of one of my favorite points to bring up here.
And that's the idea that security that works well is not good because nobody knows that it's there. Um, and all you have to do to figure that out is try to drive onto any military base in the world. Sure you have a government id, you are, you know, you are supposed to be there and they're still gonna check it.
Uh, you know, think about, uh, the, the old RSA tokens, which are now apps on our phones or something as simple as a pass key, which is something I know that Alan loves, um, is there's still a popup, right? Hey, confirm that you wanna log into this website using this pass key. That little tiny bit of friction proves that the security is there.
You know, it's as simple as like having a little dialogue box popping up saying, we're auto, we're automatically logging you in with your credentials because you configured SSO you're awesome. Like when we, when we let people know that, right? Like I, I, there's a story of IBM because I used to be an IBM or I was an intern there, and the road that went around the plant in Rochester, Minnesota was used as a shortcut by everybody in the, the community to get to Home Depot a little bit faster.
And if you are familiar with any legal precedent in the United States, you know what an easement is? Where if I have unfettered access to a road for more than one year, then I am, uh, then that is now a public road and I can't do anything about it. So every year for one day a year, IBM would close, uh, the checkpoints at the front of the building, which were never otherwise closed in check IDs for people going through to make sure they were IBM employees.
Uh, their stated goal was to, um, make sure that they didn't create an easement on that road. But the secondary goal was to remind people that there is a security aspect here. Even if it's not alter very present now at the facility itself, you still had to use a badge to get in.
This was in 2001. It's like, you know, you had to swipe your badge and, you know, you had to, the doors were all locked and everything. Um, I will say that after I left and everything happened at the end of the year in nine 11, those checkpoints closed and everybody getting onto the facility had to check in for, I think it was two years before they would start allowing people to go through without having to show their id.
Like we, we have to make sure that people understand that there is security in the system, otherwise either A, they're not gonna care or worse in my mind, they'll just assume that it's there. And then you'll, you'll see the breach notification, like, why were you storing all the tasks that passwords in plain text in an Excel file? That's bad.
What I'm deleting now, Uh, gentlemen, any final thoughts on this topic? I, I, I, I wish we had an hour and a half to talk about MCP and APIs and AI and everything, but, uh, I think this is definitely a fodder for another episode. For another episode.
Well, I would, I would say I am really interested in what AI tools can do to help us think about new security architectures, more holistic security architectures. I think there's really interesting, um, promise there as well. So another, another follow up episode, Tom?
Absolutely. Alan, I, I would say this to, to wrap the bow around this one. Yes.
In 11 short months, it's become the de facto standard. As I sit here today, though, don't ask me if it's gonna be the standard next year. 'cause you don't know this stuff is happening so quickly.
Yep. We don't know if something a better, a better mousetrap comes down the park, the road here and, and MCP. What?
Well, that, that's archaic, right? So let's not get, you know, we don't have to pull the emergency brake quite yet. Secondly, it is only been 11 months.
Security does, especially holistic, organically kind of embedded security takes time. We're not at the end of the game here. We're, we're, we're at the, maybe the end of the beginning if that, and there's still plenty of time to get security right with MCP.
Well said, sir. Um, I, I want to ask, you know, you two are both very busy, uh, folks, but I'm sure that you have a lot of great stuff going on. Uh, Alan, what are some cool things you've got coming up that people should be checking out?
Well, I am on Techstrong Gang four or five days a week, uh, every morning from nine 30 till I guess 10 15. So, and we talk a lot about all this stuff there. I, um, I will be, actually, I'm not sure when this podcast will, will actually air, but I'll be at the Qualys Rock, uh, uh, rock Con, uh, risk Operations conference this week.
I'll be a Cube Con in November. Right? We'll be broadcasting live from there.
And I mean, you could, you know, I I publish about 20 articles a week on the various techstrong sites, so you could follow me there, but I'm, I'm usually not hard to fight. Scott, what have you got coming up that people should pay attention to? So, for Network Automation Forum, we have our next event coming up in November the 17th through the 21st in Austin, Texas.
Um, we're always looking for more automation of security content. Um, so the agenda's closed for this one, but keep it in mind for, uh, for future events. There's a, that adjacency between the network and network security.
I'm very personally interested in seeing how that goes together. I will, um, see you all at the upcoming AI Field Day and the next networking field day in, uh, coming up in late October and then November. Um, and I'm always driving interesting conversations on network operations and IT operations on the Total Network Operations podcast.
So give it a listen. Absolutely. And don't forget that for Tech Field Day, we have an exciting month going on.
Uh, Steven is actually gonna be at, uh, tech, uh, tech Field Day Extra at Net Insight this week. Uh, next week we have Cloud Field Day week after that we have AI Field Day, the week after that we have Networking Field Day. com and check out the calendar, uh, because we're gonna be busy and we definitely want you to take part in it too.
Thank you very much for listening to this episode of the Security Boulevard podcast. If you enjoyed this conversation, we would love it if you would subscribe on YouTube or in your favorite podcast application of choice. So you don't miss an episode.
I'm a fan of Overcast, but whatever you want to use is great with us. We'd also love it if you'd leave us a rating and a review, because that does help the show grow and help us find new audiences. com and the FU Room group.
com. The Techstrong TV website. Or if you are a fan of watching us on tv, use the Techstrong TV app.
It's available on Apple tv, Roku, and any other smart device. Don't forget that we are also on social media. Uh, you can follow us on or Twitter on LinkedIn.
Just look for security BLVD for more content. Thank you very much for tuning in. We'll see you all next week.
Hey, everyone, we're back here for another text drug TV interview. I've been doing a lot of these lately and I'm happy to see me. I think primarily 'cause there's so much going on in the world, you know, in our world anyway, around AI and agentic AI and security in ai and testing in AI and cloud native in ai, but everything is, and ai.
Let me introduce you to my next guest. His name is Anthony Dero. Dero Anthony is the dis, a distinguished engineer, uh, AI strategy BMC software.
That's an impressive title. Anthony, welcome to Textron tv. Nice to meet you.
Thank you, Alan. Thanks for having me today. It's pleasure to have you on, Anthony.
Well, let's sort of just give people a little bit about your journey, your story, how you wound up here today. You know, distinguished engineer, they don't hand those out like lollipops. Um, talk to us about your, your, your journey.
Yeah. Well, my journey goes away back. I've been, um, in this industry for over 30 years now.
Um, it's hard to imagine it goes by so fast. And I have to say, you know, working with BMC software, focusing in on our, you know, mainframe product experiences 30 years ago or so, when I first took my, uh, I first, I got my first job, I should say. I remember people telling me why you gotta work for a company that does mainframe engineering.
Uh, mainframes are going away, but here we are, 30 years, mainframe going stronger than ever. And my journey has always been in the, uh, mainframe space, uh, my, my entire career. And I love every second of it.
Look at the platform is second to none when it comes to technology. Uh, and, and the capabilities of the platform, which really, um, really motivated me way back in the day to, uh, come on board with BMC. Uh, that was about 28 years ago or so.
Really? Wow. Yeah, absolutely.
I started off as a, as a, as an engineer. And over the years, worked my way all the way up to, uh, distinguished engineer. Um, as you know, BMC software has a wide portfolio of, uh, solutions from the dev, uh, DevOps space, AIOps, SecOps, DataOps security, a whole spectrum of solutions.
And over the years I've been, uh, fortunate enough to be the architect for many solutions across, uh, the portfolio and of late, uh, the last two years hyperfocused on, uh, bringing ai, generative AI to our solutions, looking across our entire, uh, portfolio. So that's what I've been working on for the last couple of years, is this whole AI focus and our strategy and vision, uh, on how we want to execute on that from, uh, from the customer perspective as well as from the technology and what we need to do be doing from the architecture and the technology perspective with ai. I love it.
What a, that's a what a great story. 28 years. I can't imagine.
Oh, yeah, yeah. It's great though. I, I, I'll be honest with you, in the, in the same timeframe, 28, 30 years, I've only, I, well, I've been with three or four companies in all that time, right?
Um, but you know, most people hop around every 18 months these days. So it's, it's a little different. Um, you know, the, you, you say, oh, 30 years ago people were saying how you, you're gonna work on a dinosaur, right?
And here's this dinosaur still, still out there kicking butt. Um, but you never thought you'd be working on AI strategy on the mainframe, did you? No, not, no.
Just even a few years back, you know, you, you never imagined, you know, what the opportunities were, but when, uh, the landscape exploded, when generative AI came onto the scene, yeah, my brain just lit up, uh, from, from just in general, just being a technologist and geek, if you will. But, you know, being so in tune to the business and the things that we were doing, and really in tune to our customers and our customers' needs. And that was always very motivating for me throughout my entire career with BMC was the, the great things that we would do and deliver for our customers.
That's always been very highly motivated, uh, behind that customer success. So when AI came onto the scene, I really personally looked at it as a challenge. Meaning you always see these cool technologies when they come about always on the other platforms, right?
You see it in the cloud space, you see it in the distributed space, right? Well, you in the mobile space, you always see it on the other platforms. And I immediately just locked in on this technology and just saw the potential immediately and what it can do for our customers, right?
It always starts with our customers. So from the customers back down to our technology, and I just went for it, and I'm like, this is the, you know, all these opportunities are there. We could start doing great things with this technology and making the mainframe just like the other platforms or in the game, just like the other platforms.
And it's just been, uh, you know, pedal to the metal from that point forward, uh, with our solutions, and then working with our strategists, working with our executives, working with our customers, and formulating our AI journey, uh, up to date. Absolutely. Absolutely.
And you know, I'm, I'm not surprised to see the mainframe community embracing ai. You know, Anthony, you said something, we're technologists, this kind of stuff, geeks, geeks the heck out of us, right? And I, I think that's why there's been so much progress focus on, on, uh, AI within it, maybe more than in the rest of the economy, because I think we are the people who get jazzed up about this stuff.
This is a, this is like waking up every day to Christmas, right? And there's a new, there's a shiny new toy there to play with Every day. Yes.
Yep. But I, I, I want to, so, you know, BMC is already rolling out, uh, AI agents AI workflows for mainframe users. I, I saw an in, uh, not an interview, a, uh, a report, a survey report, I think it was this week.
Um, and it was, it was almost counterintuitive like crazy. 90%. This isn't just mainframe, everyone, 90% of developers are using ai, some form or another, either generating the code, testing code, what, what have you, 90 90%, yeah.
Nine outta 10 dentists use Crest and nine outta 10 developers using ai. 40% don't trust it. 65% thinks it think that it introduces instability into the code base.
Mm-hmm. Somehow that doesn't add up. Right?
But because if 90% are using it, that means a hell of a lot of these people are using it even though they don't trust it. And even though they think it may introduce instability into the code base. Now, does that mean, you know, is full speed ahead damn, the torpedoes?
Or does it mean, hey, we're building trust, trust is earned trust. Yes, ab, absolutely. So first thing, you know, kudos to the entire development community.
It is, it was that group that embraced the technology that has p played a major role in accelerating that technology to where we see it today, right? Because it was embraced. Now, as a developer back in the day, I have concerns with, when it comes to AI and the development experience, et cetera.
And what I mean by that is, we all should be looking at the AI capabilities in the, in the development community space, in the DevX space as an augmentation tool to our existing skills, to our existing self developers who are really leaning on the, um, the, the AI to get them through their day or get them through their tasks and blindly taking what the AI is generating for them, et cetera. That's where the problems come in. There's gotta be a level of trust established between you and the ai, and even to some degree, the AI back to you because you're prompting it.
You're driving the ai, that's an art. The best developers moving forward are gonna recognize that the AI is there to make them better. It's, it's a cape that they're gonna put on.
It's a tool that's gonna make them more efficient, more effective, and to get them through their day faster and better. But they still have to have the core skills and knowledge to understand what the AI is bringing into them, and to validate those results they're getting back from the ai. You know, a a dangerous thing I hear developers talk about all the time is, oh, I use the AI and the code.
It, it just, it, the code works. That's not good enough, right? We all know there are multiple ways of solving problems and coding up something.
You wanna make sure that you're still coding and putting software to together the best way possible. Not just because the AI generated some code for you and you're just gonna drop it in and use it. You still gotta use your skills and your abilities to see is this good code?
Is this, is this production level code? You still gotta put all the right security checks in place. You've gotta, you still gotta check all your code for vulnerabilities that could be introduced into your system.
So it's not a substitute for bad design, it's not a substitute, you know, making you lazy by any means, actually. You have to be more focused and more diligent when working with ai. 'cause if you do it correctly and you put the right checks and balances in and guardrails, it could really accelerate, uh, what you're trying to do.
I agree. I agree with you. I, I'm also reminded though that look, trust is something that's earned.
And, and you do it in small steps, right? So there, there's a process there of, of, of adoption and adoption curve, if you will. And I think we're all in our own adoption curve and our own trust curve, if you want to call it that.
And, you know, I I, I was a skeptic. I, I'll admit it, right? I was doubting Thomas and, uh, you know, over the last couple months, it's, it's really won me over, you know, and, and, and what it's capable of.
Um, I wanna explore something else, right? One thing about AI is it made hardware sexy again, right? Anthony?
For, for the, for the last 20 years. You, it was all generic hardware. Yeah.
I had a server. You were running a X 86 thing, or, or you know, maybe arm came in and that kind of stuff. It was really, the mainframe was the only sort of, you know, unique proprietary hardware like that.
Even some of the supercomputers were just daisy chain Linux devices, right? Yes. And, um, but now all of a sudden, GPUs and, and the other, you know, kinds of, of chips specialized silicon asics and stuff are, are, are playing a big role in outside this world here.
It's a $4 trillion market cap, right? For Nvidia for this reason. What, how, how we, we, we can we run LLMs on the mainframe?
We, we don't have the, you know, there's not GPUs in there per se, but how nimble is the mainframe for that kind of stuff. Yeah. Yeah.
So I'm gonna address this in multiple ways and perspectives. Go ahead. So one of the first things, you know, you talk about the mainframe, mainframe hardware, but obviously we got GPUs.
You can procure your own AI box, right? And throw your own GPUs in it. You could go to a cloud-based service and procure, um, um, a service up there with, with GPUs.
So one of the first things we looked at, uh, with our solution is we want to make sure we give our customers the ultimate flexibility on how to deploy our AI solution. Not lock it into one cloud vendor or one type of technology from the architecture, from the ground up, whatever our customers want. So if they want to install it in the cloud, they can, they wanna put it on some on-prem VM ser, uh, uh, VM service.
They can. Now, let's talk about the mainframe. Very exciting.
The Z 17 and the spire processors, that is where is what it's gonna bring the whole generative AI support that's coming out. You know, with, with our solutions and our, um, BMC portfolio, customers are gonna be able to utilize that hardware. They're gonna be able to take our solution, deploy it on, on, on Z 17, and utilize those capabilities.
We're really excited about that. It, again, it just makes the mainframe sexy. It makes the mainframe.
Now, for the people that are not in the mainframe space, they still really have this perception. It's a dinosaur, a green screen dinosaur. And when I sit down and have these conversations of what the capabilities are on the mainframe and all the modern things that you could do on it, that you could do on other platforms, they sit there with their eyes wide open, like almost in disbelief.
I'm like, no, it's not the tape to the, the reel to reel with all the flashy lights. So when I start talking to them about the capability of the Z 17 and the spire processors and what we're gonna be doing with our solution on the mainframe, it, it's getting people's a attention. The, the, the stigma, if you will, of the dinosaur is going away, especially as we usher in a whole new generation of main framers to our great platform.
As the older folks start to retire out, AI is gonna play such a critical role in the mainframe adoption. All of a sudden, folks coming outta colleges and universities, the mainframe looks attractive to them, right? I could use my modern programming languages, I could use my modern technologies.
Like it's got an incredible AI hardware backbone for me to run my solutions on the mainframe. So it's now, it's starting to really gain traction in attracting that next generation to the mainframe. Because to, you mentioned earlier, the mainframe is becoming sexy again.
Absolutely. It's, it's an interesting point there. Um, you know, in in, when I talk to mainframe folks or even, you know, cloud non mainframe folks, one of the things they always talk about is, well, you either gotta know cold ball, or we gotta try to update these apps right?
Into a, a more modern language. Not that cobalt's not modern, I guess, but that, that again, is like a tailor made task, right? Could you imagine taking a COBOL program, giving it to the LLM and or to the ai, excuse me, and, and saying, Hey, you know, convert this to take your pick, uh, whatever you'd like today, Java, or, or whatever.
Um, it, it, it, I mean, yeah. We'll keep a human in the loop. Of course.
Yeah. But I mean, the, the should never hear again that we're unable to move these apps or modernize these apps. Yes, Yes, yes.
I think modern modernize is a better way to word it. Right? And, you know, what AI is gonna allow us to do is not do these all encompassing, monolithic conversions from, you know, call ball to Java or to whatever AI assisting us in this journey.
Now, we can be very systematic and very selective on Surgical code. We want to keep on the mainframe. 'cause the mainframe is the best platform to run this type of code.
But then the AI can also help us understand what code could, could be refactored out and run on a less expensive platform or convert to Java, so it takes advantage of the zip processors and things of that nature, right? So now we could be very selective and use AI to help us refactor the code base selectively. And I think that's a great opportunity because we real, to really take the entire call ball program or workload off the mainframe may not be realistic.
It could be No, but it, but it, No, but I, I'll give you, excuse me. Excuse me, Anthony, I'll give you one better why we, we may have the greatest bonanza of COBAL programming that we've ever seen, because there's no reason why ai AI can't generate COBOL Code. That's absolutely right.
Absolutely right. I mean, don't get me wrong. I believe in a few short years ahead, AI is obviously gonna get to a point where it is gonna write better software than some developers out there.
It's gonna evolve. It's like any other, Oh, I, I, I don't think it's a few years. I, I think it's much, much shorter than that.
Yeah. You know, I, I, uh, you look at like, like Claude code is coming out with now the code, it's writing Amazing. Absolutely amazing.
And it gets better. And, and it's trainable. Yes.
I mean, I, I, I still believe you're gonna need a human in the loop. Absolutely. A hundred percent.
But I mean, think about the ability, Hey, I want a new program for my mainframe. Write me a program for my mainframe in COBAL that does this, this, that, and this. Yes.
And it has to do that. And you have to use, log into this and, and, you know, you, it's almost like a fantasy. It is, You know, here, and here's what I, I really like about this approach, and I've, I've been experimenting with this, is it's not about just generating the code.
I point AI to my code base. It un it understands my style. It, it Learns it.
Yeah. How I structure code, it understands, you know, my flow and my, you know, my logic flow. And then I also augment the capability with just some of my own personal best practices and things that I do day in and day out when I create software, right.
For prototypes and, and whatnot these days. So they don't allow me to work in production code anymore. So I got my own, uh, you know, environment to do my, my experiments, but my AI is learning with me.
So now what I'm asking it to generate code or refactor, it's not doing it in this generic type of way. It's actually No, it's doing it an Anthony's style Styles, Anthony's style, Anthony's approach. And now the recommendations that it's making to me in code complete or refactor, it's extremely close to what I would do myself in that regard.
So this is where, from the development perspective, back in the day, or back a few years back, we had this notion of paired programming where you and I would sit mm-hmm. Like side by side, literally working on a problem. Yeah, yeah, Yeah.
I've Uhhuh I think that the AI is my paired program, right? We're we're in this together, Together. And you know what, I, I have a very similar workflow writing now, it writes in my voice.
Yes. It knows my style. I've updated, I've uploaded a whole bunch of my stuff, and it knows, and, and it blows me away, honestly.
It blows me away because I can't tell if that's what I wrote or, you know, um, it, it, it's crazy and it's coming. But, you know, that's more, that's a lot of generative AI stuff. Yes.
The the, the agents bring it a whole level of autonomy to it. Yes. That's the power.
And, and that's, that's really powerful right now, just go out and do it. Right. And again, we'll keep a human in the loop, make sure it doesn't run crazy.
Yeah. But just go out and do it. It's an amazing time to be alive here and doing this, man.
I, I, I feel you are, you know, jazzed about it. I think we're all jazzed about it. I, I, it's, it's, so some of the, uh, the architects I work with at BMC that kind of laugh and snicker at me from time to time, because I look at this vision of agents and agentic ai, I talk about them as like, I'm talking about people, right?
Yeah. And at the end of the day, agents to me are digital workers. They work 24 by seven turning and burning through whatever use cases that we have with AI as their intelligence engine, right?
And that could be a hybrid AI approach, right? These agents could be using machine learning models, they could be using a generative ai, they could be using different, combining these techniques together, right? And some hybrid AI type type model.
But what I really like about these agents is for all the great that generative AI technology is, and we're all using it in our day-to-day lives, and now it's in, in the enterprise still, fundamentally, the technology is a, is a passive technology, right? Yeah. Chat, GP GT sits there idle, um, you know, uh, anthropic, Claude sits there idle, they all sit there idle.
And so you and I have a, a, a, a, an action that we wanna take. We wanna do some research, we want go investigate something. And we, we go to, we go to the experience and we start a con a chat conversation that serves a purpose, right?
But that's a reactive model. That alone is not enough when it comes to enterprise software. So how do we move from having AI sitting idle, waiting for you to interact with it, or waiting for you to inter, uh, to trigger like a co-pilot experience, like right click on some code and say code, you know, explain this code to me, or whatever it is, it's still a response.
Uh, re a reactive model. Now with agents, we're shifting from reactive to proactive where we get these agents working independently and working as a team on very complex multi-step IT type problems. And they're just working, working their way through it and surfacing all kinds of great insights, whatnot.
But now, this is where trust really comes to the surface. When you start working with agents and agents working on complex IT problems, how do you establish trust? Well, you mentioned it a a bunch of times.
Well, we're not gonna just have the ai ai you just run off and start doing things on, on, on its own, right? We still keep the human in the loop until the human is comfortable with the results that it's getting from AI to say, Hey, you know what? Next time you do encounter this scenario, you know, hit the checkbox that says, you know, I authorize you to go off and run the script to, to deal with whatever that issue is that was detected.
We will get there. But for now, we want to keep the human in the loop when it comes to ai. But it's transparency, it's transparent.
AI is what I like to, you know, talk to our customers and our teams about, we need to have optics into the AI agents to understand how these agents came about making the decision that they're surfacing to you. Our agents and a solution need to be fully auditable. You need to have observability into these agents so that you can understand its thinking as it observing the, the environment and the data that it's working with, and it's concluding on what to do.
You need to see those, um, those reasons or those choices and why it's making those choices. So you have to build these agent systems with that level of transparency. It's that transparency that's gonna lead to trust, and it's the trust that's gonna lead to full autonomy at some point with agents in the enterprise.
I love it. Anthony, we're about outta time, man. I want to thank you for coming on here, talking to us today about this.
Keep up the great work. Let's come back soon. I want, actually, before we go, for people who want to, you know, dial in to what BMC software is doing in around AI and agent ai, AI strategy within the bigger, you know, BMC website.
Is there a section for this or it's kind of put throughout? Uh, no. We do, we do have a dedicated, uh, location out on our, uh, BMC website, which talks about our AI and our vision strategy and the things that we're, we're doing.
com and do a search on, you know, AI or uh, um, or AI solutions, you, you, you'll, you'll get a hit and you'll be able to go to that page. Or you could reach out to me on LinkedIn, find my profile out there, connect, and I would be more than happy to, uh, share those resources with you. All right, man, Anthony, we'll have you back on soon.
Thank you so much for sharing with us. Keep it up. Thank you so much.
Appreciate it. Alrighty. Anthony Dero, distinguished engineer, AI strategy BMC software.
We're gonna take a break. We'll be back. Hello and welcome to the latest edition of the Techstrong that AI Leadership Insight series.
Today we're with Mira Lid, hard Kna Prasad, who's president and CTO for engineering over at Salesforce. And we're talking about agen AI and the rise of it in the enterprise. Mk, welcome to the show.
Thank you, Mike. Great to be here. Uh, and good, good morning, good evening to everybody listening.
I think at this point, everybody's generally familiar with the concept of an AI agent, but that's not quite the same thing as understanding of how to build, deploy, maintain, and secure these things at scale. So where are we on this journey right now and what are folks gonna need to know about building the agent AI enterprise? Wow, that's, that's a big question.
So what, maybe we should parse it down, right? What is an agent enterprise, an agentic enterprise, really where we envision agents and humans working side by side, right? To like, solve complex problems.
Now, the problems could be, Hey, how do I get more people to buy my product? Or the problem could be I have a product and there's a lot of issues with it, and how do I make it easier for them to solve it? Or simply just background processes where you want workflows to be solved for your employees and, uh, HR representatives and so on.
So there are like different aspects, sort of for an agentic enterprise now, but the key thing in all of this is you could break it down into a few things. One is you certainly need the right AI foundations pv. When we say AI foundation, that starts with data and APIs.
You need to extra, have all your data to be able to go make the decisions. You need to have access to the APIs to go take the actions on it. And then you need a good sort of planner system, the agentic system, if you may, which can then orchestrate all of these data and actions and then surrounding it, you need to create that agentic enterprise.
You need all the tools around it to make it easy for you to then observe, create those agents, observe what the agents are doing, and talk to different agents, orchestrate across all of them. And then finally, you also need like an underlying, uh, security and metadata that brings it all together so that you don't want the agents, you want rather, you want the agents saying the right things to the right people and not, uh, not like leaking your sensitive information to customers or employees and so on. So that really forms what we call as a bedrock of an agentic enterprise.
And of all this, of course, you need to make sure your employees or your customers, this agent take thing, is able to go reach them in all the channels of their choice, be it slack for your employees, whether it's your web, SMS, WhatsApp, whatever it may be. It should be able to go answer in all of those channels as well. So that's kind of how we are looking at it as an agent enterprise.
It's a sort of a multi-part system with a foundation of data APIs with a strong planner that augments with the tooling system, the observe, observe, uh, observability and analytics around it, the governance on top of it, and of course the security and metadata around it. How will I govern all of that? Because as I look at this issue, each of these AI agents will be trained on handling a specific task or a set of tasks, right?
They will probably work in concert with each other, but at some point I need to understand what they're doing and I may even need another AI agent to validate what the first one did. That's a good point, right? Uh, in fact, even before we go to multi-agent, this is a problem.
We mean for a single agent, which is an agent is answering a lot of questions, how do you know it's doing the right thing? And so part of what we call as Judge LLMs that we have, uh, so if you use, uh, our thing called the testing centers, we call it our agent for studio, it allows you to go create tests or evals if you may. And then we have a judge, LLM that's running on the site to see if the agent actually answered in the right way.
Uh, and if it didn't, we, it might either replan or at least tell you the tests are failed and so on. So I, it's definitely, uh, an important thing because it's non-deterministic, right? It's a non-deterministic output.
We're gonna be getting. So to your sort of question around how do we really do the governance, I think there is two levels of governance here. One is there's a governance at the data layer, which you call as a data governance, making sure the right agent is giving, getting the right data so that it can actually go answer the questions correctly.
And that starts with an AI based classification, uh, and then tagging around it and making sure the agent is running in the context of the that particular user or that particular action. And so it has access to the right data. That's number one.
Again, it's structured or unstructured data shouldn't matter. We need that strong data governance layer. Then when you go up to the level of cross Asian communication, you wanna make sure there is governance there as well.
And if you go back to the worlds of APIs, we had done that before, right? With API governance, making sure who has access to what APIs, a p, Salesforce, and so on. And the same thing we are trying to bring, uh, in, in the world of multi-agent, what we call this the MuleSoft agent fabric, where you can actually add the similar governance across agents to know, okay, which agents can talk to what agents, how, who should orchestrate what, uh, and putting the throttles, right throttles and security, uh, things there as well.
Mm-hmm. How will agents negotiate with each other? We humans negotiate all the time when we wanna, uh, have something accomplished, right?
I'll do something new. You do something for me. Right?
Some agents may even have competing agendas and priorities. So how will they negotiate with each other and come up with some sort of resolution, or are they just gonna call us for an answer? Good question.
I think certainly it starts again with a few things, right? One is, uh, things like MCP and eight two, A eight, two A in particular, the protocol's evolving, but it's giving us a good foundation. Just like, uh, you had the Rams and other kind of standards before.
You now have the emerging protocols that's allowing for things like basic communications. It's like, okay, which agent, what can I call? What are the error conditions to handle all of those things?
But you asked a very important question, which is negotiation. How can agents negotiate with each other, uh, just like humans do? Uh, it, it would be few things in my opinion where it'll, it's, it's really one, first of all, we need to have the right context pass between the agents.
That's like crucial, right? If this agent has a lot of context and the context doesn't go to the other agent, it's gonna just make up its own thing. That's number one.
Uh, and then, so that's part of the thing that we are working on to make sure cross agent communication includes a lot of the context passing either through sort of what we have is through profiles and other things or through the protocol itself. But that's the second thing around this as well. In a typical enterprise setup where you have very clear agent's, mark, you may have this agent doing your workflow process.
I mean, for your sort of workday like thing, this agent might be doing your sales and everything else. There's less negotiation going on. It's more around figuring out the right agents to call for your particular work.
Uh, and that's where a planner comes in handy. Um, and you can, you need to make some of these things deterministic as well because you want to make sure there are very set of steps you had to follow, okay, you need to do an order first before you can go close the quote and so on. Uh, and so we have the mechanism sort of built into say, how can I bring in a sense of determinism in this non-deterministic orchestration?
The second aspect is when you get into the negotiation is where you have a plethora of agents available. Maybe it's like a supplier dealer like model where you have multiple agents running and you may wanna actually negotiate with the agents of which agent is actually going to answer my task, and then maybe give it the, give it the job to do. com, if you remember, we had all the B2B, uh, at that time it were agents, but you had all of these companies and protocols pop up for cross company negotiations to happen.
I think we'll end up creating more of these protocols with these, uh, agent exchanges, if you may, where agents can advertise what they're wanting to do. And then as an Uber agent, you can go pass the information to all the agents to say, which one will get me a better deal. Um, and I think the more interesting things also is as we are learning, uh, this is all a learning for all of us that agents can lie to.
So then we need to figure out, okay, how do we figure out is this agent really gonna tell the truth or not? And I think this is kind of where we can go back to some of our older, uh, things in terms of grabbing the data, its outputs, doing trends, doing predictive sort of scoring to say, if this agent is like really the last time it said yes, uh, it didn't really, right? Like the action really didn't happen.
And so we'll probably evolve all those methods as well. And that's kinda why the observability is kind of critical in this whole thing. Like observability and also closing the chain, if you may.
Uh, in the human case, we did that before, right? When you actually sign up with a, let's say a dealer, they don't deliver that is there recorded in your CRM or other systems and you can figure out, okay, this person is unreliable and then maybe we won't give the next deal to them. We will leave all certain systems like that for agent Dick thinks as well, Right?
I think those are employees are usually our relatives, so that's why we know not to trust them. Right? True, true.
Um, I'm trying to figure out though, how loosely or tightly coupled are agents and LLMs gonna be? Am I gonna have a scenario where I'm gonna have an AI agent that will invoke different LLMs based on the task and it will, uh, shop the LLMs as it were? Or am I gonna have a scenario where there's gonna be, I don't know, four uh, agents that are all capable of doing the same task and one might do it better or less expensively than another and they'll compete for the privilege?
That's a great point. I think my, my, the way I'm seeing happen is that I think we are finding that certain LLMs are better for certain tasks. We've seen that, right?
And so agents that are specializing in certain tasks is gonna go optimized for that LLM because it's easier to say, oh, I'll just switch LLMs. But really the results are very different. We have to go make sure the same prompts will get you different answers across the LLMs and so on.
So my, what I'm seeing happen in my gut field tells me we'll end up specializing agents based on the lms and then that way they'll compete to say, okay, this LLM has all this functionality, means cheaper. Maybe it doesn't give you everything. Whereas this LLM gives you more functionality, but it's more expensive and you'll have fine tuned agents, which may cost more.
Okay. This agent might give you the best answer possible for your core writing scenario. It may cost you more.
This LLM may be good enough for simple code writing that you may not care, right? Uh, so I think that's probably where we will evolve. But I think an LLM switching, uh, things at an action level, yes, but at a planner level, it's very hard, uh, because you gotta fine tune it to make sure it works for that particular LLM.
Certainly at an action level, yes, it can say, okay, this action can be done by Claude, this action can be done by open ai. This action can be done by Gemini. That's possible.
But dynamically flipping at a planet level, I think it's a little more farfetched. Uh, we will end up more with specialized agents, is my gut feel. Hmm.
All these agents will need to be integrated. Does that require some sort of new dedicated platform to achieve that? Or are we just gonna extend our existing integration platforms that we're already using the access data and APIs, and it's just really a matter of making sure that the right data shows up at the right place at the right time.
That's right. I think my, what we will end up happening is expanding this. So think about, think about this, right?
Every agent, just like every human needs the right data. And what is the data? It's all about your customers.
Whether it's your sales data, who I talked to, who I didn't talk to, who came on your website, or it's service data. Like, okay, what cases I've had and did I solve your problem or not? Or early on in the pipe, it's your marketing funnel to say, okay, which person, uh, that I should be targeting or not, right?
And so all that information is critical. So I know it's the same Mike who came to my website, didn't purchase or made a purchase, didn't like put it in their cart, et cetera, or had the sales call, had the service incident unhappy or happy. All of those things is really what forms the context for what you think about a customer is.
And then you have the memory as an agent to like all the conversations you might have had had with the agents. And this is an important distinction between agent a human because you may talk to different humans, it really depends on what the human then types into your Cr m mother to know. What's the context of what's a conversation you had?
And most of us don't want to type in everything, whereas agents can actually preserve all that history very easily across agents too. So bringing those two together with your profile, with your memory of the agent, they think you can really understand what the customer is doing with your business. That I think is a very profound thing.
And I think that's kind of where we, as I think as Salesforce, feel very proud that we have probably some of the best data on there to be able to go represent. And so it's an extension, if you may, of the platform that used to serve humans to be able to go serve agents. And part of this is also connecting to the rest of the enterprise, which is why I said APIs and other connectivity kind of critical to be able to go take actions, um, onto the different enterprise, uh, scenarios.
So those two is going to be an extension of what we've already done for humans into the agent era. But there is gonna be new things coming in and new things coming in is where I, like I said, we need different planners. We need more, uh, determinism within non-determinism.
What do I mean by that? Like, if you just give questions that people are asking to an LLM, we found there's a lot of issues. Meaning if you give more than eight instructions to an LLM, it starts hallucinating.
Or if you give more than a hundred topics to an LLM, it won't work. It doesn't know what to do. So, uh, you may wanna have that determinist team to say, okay, somebody should have given you order ID before we can actually go call this method.
Or if somebody is like an important VIP customer, make sure you don't keep bugging them with more questions. Go straight to the human escalation as the case may be. All of these needs a little bit of determinism, and that's kind of where some of of these innovations are happening, where we can bring in determinism within the non-deterministic sort of LLM sphere, but grounded in the right context and memory so that you can actually give the right answers.
Mm-hmm. We start to hear the phrase context engineering more and more. And it seems to me that this is what that art form is.
It's getting that data, which is, and the context that's wrapped around that data, right? And giving the metadata to the right place so that there's enough of that information Yeah. For the AI agent to come up with some sort of reasonable output.
But on the other end of it too, I think maybe you don't want to give it too much data because then you wind up getting a lot of extraneous output. So That's right. Is there an art to this thing?
It's a very good question, and I'll give the example with our own, um, customer success story, right? 5 million questions from customers have been answered by our agent, and it looks simple like, Joe, just feed all the documents to it, you'll answer. Uh, but this is kind of where the context engineering becomes important, because we did that same thing too.
First we just said, okay, let's give it all the documents. Turns out we found something interesting, which is you need to constantly also look at what is happening with your agent. What are people asking?
And is the agent answering correctly? Like it started off first, I'll give one simple example where somebody asked us to compare our agents with a competitor's agents, and the agent actually answered it, right? Like saying, oh yeah, we can do this, we can do that.
Uh, the other competitor can't do this. And so on. We were like, oh, no, that we should not be doing it.
And so we put a rule that said, Hey, don't, uh, don't talk anything about, uh, other companies. Sounds simple, except next week we found out people are asking, saying, Hey, how do I integrate your agent or your system Salesforce with another customer, like another company like X, Y, Z. The system said, sorry, I cannot talk about it.
Right? And we're like, no, no, no, no. That's an important one to actually support.
So then you have to fine tune the instruction to say, you know what? You should be talking about integrations with other companies, but don't try to answer competitive kind of questions, right? Things like that.
It's just one simple example, but, uh, it's a powerful thing to kind of say that you need to be looking at what your agent is doing and evolve. The evolve can be you need to fine tune the instructions or fine tune your data, because a lot of times it could be missing data. They're asking a question, you don't know the answer to it, that's where you go add more sources, or it may not be answering it correctly.
You go fine tune the instructions to it. And that's kinda where we are. We have added a lot of tools, including Tableau sort of tools, et cetera, to go analyze it across all of your agents to say, okay, what are the topics it's answering correctly or not answering correctly?
Uh, and what the remedies that you can do, um, at a fine grain level. So that is really what context engineering. Context engineering is really about, like making sure your rag is right, uh, making sure pipelines are right, making sure your in instructions are correct to answer the right thing, and also making sure you're bringing all that right data together.
Like you said, not garbage data, but all the right data together, structured and unstructured, uh, for the agents to work correctly. Hmm. Most battle plans are excellent until first contact with the enemy.
So I'm gonna give you this scenario and see how it plays out. So Salesforce widely used by salespeople, and they will use that to come up with offers and things like that, that they will send out to folks. But on the other end grid, won't there be a purchasing platform somewhere that has AI agents that will be acting on behalf of the buyers, and the two of these sets of AI agents are gonna somehow or other come together in in some external ether somewhere and mm-hmm.
Do what to each other? Well, 'cause isn't there a chance they'll just cancel each other out? Wow.
But in some ways, if you really step back and think if the AI agents act just like humans, their goal should be to go maximize, right? To maximize whatever they're built for. Whether as a customer, you're trying to go talk and get your tasks done on the other side, trying to maximize the dollar potential from from that other side, I feel we will evolve on that one.
When you have these AI agents, they will all be goal-based AI agents. And we have seen that already. Like if you look at our SDR agent, by the way, we now run SDR agents on our website.
They're actually pretty good now. Their, their goal is like, how do you make sure the customer will set up a meeting, uh, or the customer will actually go to your property and go buy it? Uh, I mean, go go to the, uh, uh, digital online store and go buy it.
And what we are seeing is pretty fascinating already. Like these are, um, prospects that we would've never had, nobody would've picked up the phone to call them because these are like long tail prospect that just visit our website. But now letting our agents, because the goal is to go do this thing, it's able to actually talk to them, convince them, can they do the same?
Now you're correct. On the other side, you might actually start to, to get agents right, instead of humans, in which case I, my, the thing that it'll evolve is the both will start negotiating understanding. And actually we've seen some, uh, recent, I think, uh, there was some recent things where when both sides understood those agents actually downshifted from talking English to their own language super fast too.
Uh, maybe we'll get that too. Say, Hey, you know what? I know what you're doing.
I, you know what you're doing, where do this, but I think in the end, I would say it still comes back to the goals that the agents are trained to. Uh, and they will go evolve and be flexible, and they'll also be, all the ambient data will be available for them as well to be able to make the right calls. Um, I think that's kinda where we will end up with, And, and all the code will be written in Assembler because they'll figure out that that's the most Exactly.
And maybe each will try to hack the other, who knows. Um, when you put all that together, what is your best advice to folks? Because I think everybody's out there trying to experiment with various things and, and, but getting that over the goal line into something that feels like it, I can run it in production, feels like it's a, it's a maybe a right little heavier lift than there ready for, but what do we do to get there?
Yeah, great question. See, that's why if you look at the MIT study that came out right where 95% of the agent, uh, AI agent thinks fail, because I think people are just looking at demos and saying, oh, I just so throw some things and things will just work. Uh, that's great for a demo.
But then when you get into real life practice, you need to have the solid foundation. Uh, and like I said earlier, the three foundations are one, it starts with making sure you know what data you need first. Start with the scenario.
I think that's the most important thing. Don't try to boil all the ocean. Start with the scenario.
Scenario could be something simple. It could be for your employees, your service, your sales, whatever it may be. Um, once you know that, then figure out what data you need to go accomplish the task, what APIs or, um, agents or APIs that you need access to, to go make that task and then create that agent with the right planning, with the right instructions to say what to do.
But that's just step one. The step two is make sure once you put that agent in pilot or in in beta or or even production, start monitoring it with all the right tools, with the observe observability so that you can keep fine tuning it. It's an art.
Um, and then once you have that success, then it's easy for you to build upon it and then go create the next scenario and the third scenario and so on. Uh, never assume that just because you've created one agent, it's all fine. I think, I think it, that is the part where I think people will, people are missing their thing to say, you need to continuously observe it and fine tune it, uh, as you learn from it.
All right, folks, you heard it here. Hey, has that great AI leader, Benjamin Franklin once said, you know, failing the plan is planning to fail. Still true in the age of ai.
Yeah, that's great. Thanks for being on the show. Thanks, Mike.
That's great. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series.
You can find this episode and others on our website. We invite you to check all those out. Until then, we'll see you next time.
Every company lives in fear of a ransomware attack, whether they've suffered one or not. And this is even more critical in the era of ai. This episode of the Tech Field Day podcast looks forward to Commvault Shift in November with a discussion of the importance of data protection to AI applications with Tim Zonca from Commvault and Frequent Field Day delegate, Gina Rosenthal.
Listen in and learn about the connection between data, data protection and ai. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the tech field, a delegate community, and is often recorded in association with one of our events.
This episode in particular, is recorded in association with Commvault Shift, which we will be attending in just a few weeks. Tech Field Day is part of the Futurum Group, and this podcast is published on our sister company site Techstrong tv. This episode, we're looking forward to Commvault Shift, which is November 19th, and we're talking about the importance of data protection to ai.
Yes, ai, it's 2025, everything is about ai, but we've found that there's an interesting connection between AI strategies and data protection strategies. Before we get started with that conversation though, let's meet who's on the panel today. Hi, I'm Gina Rosenthal.
I am a fractional product marketing manager. I help lots of companies including data protection companies with their, um, product marketing. And I'm Tim Zaka.
I'm the Vice President of Portfolio Marketing here at Commvault. And glad to be here with you today, Steven. Thanks for having me.
Yeah, it's great to have you. Uh, as you mentioned, I'm Steven. Uh, I am the, uh, halftime host of the Tech Field Day podcast, and, uh, have been running tech field day events for 15 years.
Over that time, I've actually attended quite a few Commvault, uh, events, and we've had Commvault join us as well at our tech field day events. And one of the things that comes across whenever we talk to folks from Commvault is the importance of data protection, I guess surprise, you know, I mean, that's, you know, what you do, but it's also something I think that is really, uh, in your hearts because you're a company that spends your time talking to companies who either fear data loss or have suffered data loss, and you're trying to help them avoid that catastrophe now that it's 2025 and AI is on everyone's lips and everyone is trying to figure out how to roll out a successful AI strategy. Tim, I wonder if you can start off by just sort of drawing the connection between AI applications and data protection needs.
I actually think you just nailed a, a big part of that connection, Steven, is you had said something along the lines of e everyone, you know, focused on kinda ransomware, staying resilient, uh, kind of frankly like the hygiene of what great looks like to just maintain a continuous business and fight through an attack. Now, while organizations are doing that and putting these best practices in place, they still most still have a long way to go. And you have this meteor of AI coming crashing into that set of projects, practices, and initiatives.
So I think one big connection point is as organizations are trying to improve their resilience, their recovery practices to fight through just kind of maybe good old, uh, cyber crimes now, it's just gotten that much more daunting as AI stacks look different, as AI data is distributed everywhere, as there's questions of accountability and ownership, and now add just attacks that could, uh, in the threat surface that's widened and different through ai. And I think that's the big connection point, because the so what across all of it, it doesn't matter if it's a, you know, maybe a more traditional looking attack or something that's come through ai, you know, poisoning, or even just, frankly, an outage due to the newness of it, the business needs to be back up and running. And so having a resilient, strong resilience practice is, I think that the connection point between the two.
I Love that word resilience because I think that's really true. A a couple of things that really stuck with me is it's definitely, you know, AI introduces all of this new ways to attack organizations. I think one of the most interesting ones is that the people sending the ransomware out are using AI to create their, their campaigns.
So one of the things we've lost is the, the as just users, individuals that, you know, on the, on taking all the training and looking out for the phishing, you've lost the ability of saying, oh, that's definitely not proper English, that I don't think this is really from that person. You've now got the ability, the, the people have the ability to, to train on an individual's voice and how they write and how they talk and send you a phishing email that looks super, super, um, real hard to explain. And then I love that point about resilience, because you're gonna make mistakes because this is all new to everybody.
So you're gonna lose data, you're gonna dump something you should, and you need to be able to roll back. So it's, it's really important to think about that. Yeah, and I think you, you mentioned a good point, Gina, which is, it's, I think maybe it's just like we as technologists, it's easy to geek out on the more sophisticated attacks or, or maybe newer ones, you know, prompt injection or just adversarial attacks, or maybe it's, uh, where the bad guys are using AI to do, you know, polymorphic attacks where the signature's changing and it's hard to detect, but I think like just making spam that much or, and, or phishing rather, you know, that much better.
Um, it's super dangerous. And, and I think that, you know, when you can have these attacks that are just actually logins, not, not these really like well-crafted, uh, uh, you know, initial kind of entry points, um, yeah, that, that's, that, I think that's really dangerous. Yeah, we've been seeing that here, um, where the, i, I don't wanna say sophistication because that's really not the right word.
'cause it's not any more sophisticated than it used to be. It's just, as Gina said, it's more convincing. And so we're starting to get, I mean, we, we're all businesses, we all get ransomware, uh, attacks, or at least openings, uh, you know, phishing and, um, social engineering openings all the time.
But I've noticed that they really have changed. Uh, they used to be pretty clunky. They used to have poor English, poor integration, you know, sometimes it was like, dear, you know, last name, you know, that kind of thing.
Now it's really not like that. And it's pretty obvious to me that, that it's generative ai, especially with, you know, text chatbots that's enabling, uh, customization and personalization at scale, at least to some extent. Now, obviously, as, as Gina points out, sometimes they're still a little nonsensical, but, um, it takes a human to recognize that.
And I'm concerned that these, um, you know, the AI technology, on the one hand, it opens, uh, doors to creating more, uh, credible attacks. But on the other hand, of course, we also have to think about the ways that agentic AI applications are opening the doors for those attacks to be more successful. So maybe we can get to that second point a little bit later.
But I mean, first, um, you know, has the prevalence of ransomware increased or does it just seem like it has 'cause it, it seems like we're hearing about it constantly and is it the fault of AI that these things are, are more credible and that's what makes people, uh, uh, more susceptible to them? I mean, I, I think at least what I see as I, as I talk with, with our customers around the world, I think I, I've seen, I would say most data at least suggests yes, ransomware is becoming more prevalent. I've seen enough to say, well, you know, it's about the same or even, you know, a slight decline.
But I think the punchline is, um, that it's gotten that much more effective and, and, and common, and I think dangerous. I think it's, and, and this, it's talking to the two of you, this is cliche to say like, it's become such a massive business that I don't really, I think it's a distraction to think about, like, has it gotten, you know, more prevalent or the same or less, like it's a, or a just a staggering, uh, danger and, and a costly one. I mean, it, it, it, you know, it impacts business from a cost perspective.
You know, we've all read, uh, you know, or, or even some of us, like work directly with, you know, healthcare organizations where, you know, it's patients that, that they're, they're working with, it's government institutions trying to serve their citizens that are impacted by this sort of thing. So it's, it's, it's like a massive business. And I think to me, that's the, the biggest one.
So regardless, like what the trend is, it's, there's no future where it's going away or, or, you know, diminishing to any kind of significant degree. And I think, Steven, you're right, it's just, it's, it's getting smarter, I think the iterations with which, um, kinda adversarial, uh, or, or just kind of either hackers or usually it's, you know, organizations can just put out a text like it's a business. Um, I think that's the part that is the most just daunting and challenging.
It's just moving so fast. And I think AI allows them to do it that much more adeptly. And I think you can have people who are, you know, even organizations that are pretty good, all of a sudden get really great and they tend to be able to move faster anyway.
And so to now have a set of tools that allows them to, um, you know, often outpace the people that they're trying to, um, get leverage against and, and hold for a ransom. I, I think that's the daunting, the, the most daunting thing. I think that's the way to look at it too.
This is not like the hackers and the hoodies, like the whole crazy way they display hackers, it's businesses, it's, it's a business and it's nation states doing it as well. So the, that the money that they can't get other ways, they're able to get it from ransom. So they're definitely using every tool they can to number one, build the tools.
And they're using, they're using generative AI to write the code, and they're using, they're using it to market. They're using all the tools we use to make sure people hear about the products. They're like, we're gonna make our product really awesome, and we're gonna make sure you hear about it and use it whether you like it or not.
So it, it's not, you know, like script kitties, like we used to always think this is literally well organized businesses that want to be well funded, and it's really easy for them to get funded because of the nature of ransomware if they don't have protection. Yeah, that's, that's a really interesting point. Like Tim said, I mean, this is, these, these are basically businesses now, uh, they're illegal businesses, but they're businesses.
And so by, uh, whether they're funded by nation states or funded by ransomware payments, they have a huge amount of power, huge amount of money. Um, they've got this incredible technology in their hands. I mean, Jeannie, you know, as you say, a lot of them are using, uh, generative AI to write code as well as to, to write text.
Um, you know, we have a whole new world now of, uh, very, very convincing generated video and audio. Uh, I know that we've all heard, uh, stories of, you know, ransomware attacks that, uh, appear to be legitimate employees on a zoom call and things like that. I mean, this stuff is just wild.
And, and I think that basically, you know, we have to move on from this idea that somehow we're gonna squash this before it happens, and we have to move to the idea of what do we do when it happens? Because I just don't think we can stuff this genie into the bottle. There's too much money at stake.
It's not going back. You have to protect yourself and have a way to recover. You have to, it's gonna happen.
Yeah. And I think the whole notion of yeah, like stuffing the genie in the bottle, I, I think the thing that, kind of back to your, one of your original questions, Steven, is just, you know, that the connection of AI and the impact that it's having on, on resilience is not only like, we can't stuff the genie in the back, in the bottle, but the, the pace of change that AI is bringing is so dramatic. At least it's the fastest and most impactful thing I've seen in, in my tech career.
I mean, there's, there are analogs to I think the cloud world. I, I see things like, you know, remember in the early days before, like the, um, kinda shared responsibility model was really something that was wholeheartedly, you know, articulated, understood, practiced, and it's kind of who owns which piece of it. I mean, I think it's a similar thing here in this, this AI world, and it's, it's moving so fast that is org.
Every organization that I've talked to recently is doing something there, and many of 'em are doing real stuff, but they're like, Hey, look, I was talking to a CISO the other day. He is like, we use Zendesk for these sorts of things, and, you know, we understand how to make that resilient, but they're using, you know, what about the supply chain of what they're using? Where does our accountability go?
How far does it reach into the LLMs and the, the way that they're, they're training stuff, and where does that line stop? And I think there's a, a whole set of questions around those kinds of practices that are being entertained now, don't have clear answers, and the pace is moving so fast that it's, you know, I think, you know, people are, are trying to keep up, but it, I think that's the part that's, it's not, it's like the genius outta the bottle and watch out because, you know, it's coming really quickly at you. I think that's a really interesting point too, because, um, PE businesses wanna move ahead and it's obvious that AI is the next round of, of innovation for computer science.
So they want to move ahead, but everything's coming so fast. Everything all at once, right? How do you, can you, you still have to maintain that data center hygiene and keep everything protected and, and do that side of the business and, and how do you do that protection and, and how do you know where to go?
Where do you put your funds to actually do more than what you've been doing and, and, and use AI to get you to the next level? Yeah. And I think to me, that that's the biggest tension that I see with the customers that, that I'm working with in that k to your point, Gina, that some of the, the practices that they're putting in place to protect their data, um, even basic ones, things like, you know, air gapping with immutable and indelible copies of your, of your critical data.
Things like, um, some sort of practices, processes, technology for identifying clean points to, you know, to recover too. You know, Steven, as we were kind of prepping for this, you know, just talking about like, Hey, how far do you, you roll back certain sets of data? Like, so having a process around what that looks like.
Things like, are you class, you know, discovering and classifying your data? You can't, do you, and and I think basics like that are still being implemented, let alone more advanced technologies or, or capabilities like, Hey, I wanna use the cloud to burst into isolated clean rooms for forensics or something like that. Just the basics are still being put in place, at least broadly.
And, and now just this rapid progression of ai. The, the, to me, the heartening thing though is the organizations that I am, I am, that I'm, that I've been working with, is just, they're, um, kind of delightfully a bit more progressive than I would've thought on, you know, who's involved or how many applic, you know, kind of AI driven applications they have in production. And even when they're, they're moving forward with almost like this blind urgency, uh, and kind of prioritizing learning and, and growth over kind of the guardrails.
They, uh, I feel like at least some of the proper guardrails are starting to get it put in place. And the ones that aren't, they know what they are. Like Gina, to your point, they're like, yeah, we know that the right hygiene looks like this for our established workloads and, you know, but we're three months out on that for this project, or six months out.
So, uh, maybe it's the eternal optimist in me, but I, I at least feel like people know what they should be doing soon for those workloads. Yeah. It's not all doom and gloom too, that's the thing.
So, I mean, AI is also a very powerful tool for data classification and for, you know, detecting, uh, attacks as well. And I think that that's all something, I think that, that gets lost sometimes. 'cause we are very scared of ransomware attacks.
I mean, I, I am, you know, as a business person, uh, I am as a professional worried about what the impact of these things are. But there is some reason to be optimistic that companies are, you know, kind of getting their act together in terms of data classification, in terms of implementing, uh, good strategies around data protection and that that the tools are advancing as well. I mean, one of the coolest things out there, and, and it's funny because it's not really a new idea, but it found new impetus, is this idea that you can have, uh, almost real time data protection.
And you have that kind of virtual dial where you can sort of go back and say, well, the ransom attack happened here, so I want my data set to go back to right before that. And there again, I don't want it to sound too much like an ad for Commvault products, 'cause I know that you guys have stuff that does that. But you know, that's a pretty powerful tool and something that has finally found some currency in here.
And the same is true as you point out of tools that allow you to, um, organize and classify and categorize data to replicate data to different locations, to burst between locations. A lot of this has been something that we in the industry have been building to for a long time, but here it is, and it's actually important, more important than ever when you're talking about these data-driven Applications. Yeah, I I think you bring up like a, one of the kind of current hot topics, I'd say in a lot of discussions with our customers at least, that are, that kind of are, uh, running their applications regardless if they're like AI driven or not, but on the AI sort of like maybe typical underpinning, so some of the larger, you know, uh, like data structures like, uh, you know, S3 or, or something like that in that, um, there's this combination that I think technology has gotten great at helping provide, which is not only being able to recover at just ridiculously massive scale and doing it really fast, but then Steven, you kind of suggest these, like what we, what we call like micro recoveries.
It's just these like kind of near real time. They're, you know, they push out, especially in cloud native apps, they're, you know, as, as, as updates are being pushed out and all of a sudden something gets corrupted or, or clobbered to being able to just have these kind of micro recoveries. I think spanning that gamut is, is I think, a key new requirement for resilience.
And so, you know, you, uh, appreciate you kind of giving a nod to us, but, you know, I'm biased kinda working for Commvault. You're right. Like we have some of our, our capabilities that we have there are just really well suited to cover that, that broad swath of recovery from just the super massive, you know, billions of objects in, you know, record time to these kind of micro recoveries where you're just kind of backtracking to some subset of your, your data state too, to a form point in time.
And again, in close to real time. To me, it seems like this, this whole period seems more to me, like when Linux came out, that's, that's when I experienced this much disruption. So with you saying that, Tim, one of the things, we're talking a lot about the production applications, but when things are in development, it seems like having that resilience to roll back exactly where you need is important too.
Especially with ai, when you've got so much time that you're spending on, um, doing some of, especially the inference training or, or whatever you may be doing in your organization, and having several people going at copies of the same data at one time, it seems like there's a great need to, um, to have a place to roll back to. So those experiments don't take longer than they need to. I think that's a good par, like kinda a good parallel or like the, you know, the, the way you mentioned Linux, I think the trend that, that I see is that I, no, I don't wanna diminish the importance of kind of on-prem disaster recovery or like, you know, kind of disaster recovery with traditional or operational recovery with traditional packaged applications.
But it's largely a solved problem, like in, in an on-prem world, you know, most, most customers I talk to, like if it's not, and it's pretty much real time or near, like they're flipping over from one site to another. Like they just got that lick, they, they're doing testing. It's, it's a really rigorous, well-established process that's not true in the cloud.
This operational outages are still an unsolved problem. Um, so, you know, they have cyber and operational recoveries to kind of deal with, and I think you're spot on is that this, this notion of, you know, in development, like, whoa, we just, we just updated a whole bunch of stuff. You know, it, it might be they're pushing out a, you know, new build of, some of the services might even just be new, you know, or infrastructure updates.
And like, we need, we need to rewind that part. Like something didn't go right there and it, and it's not a, an attack necessarily, it's, it's just a, some, you know, something doesn't match what they expected. And that's, I think that's a still like a largely unsolved problem in the cloud.
And I think that comes back to, I keep, I always just have been using, like this meteor analogy is as people get that hygiene in place, you know, then like, here comes AI to just, you know, put the additional pressure on. And I think that's the, just the massive strain that, that I see within the conversations we have with our customer base. Yeah.
I'm interested in hearing more about sort of what the real world looks like out there. I know that you guys are talking to customers all the time. I've run into those customers, uh, you know, ad events, um, certainly at Commvault shift.
Um, what are they saying is the real world of that sort of interplay between AI and data protection? I think there's a couple things. I think, um, on the fir like it's, it's almost like two sides of a coin is where I spend most of my time talking with our customers.
On the one side of it is, how do we make, you know, these new AI stacks, the new data, you know, formats and things like that, how do we make that resilient? And so this may be things like, you know, it's iceberg or, you know, S3 tables or, you know, Postgres with vector support, you know, so they, they wanna make sure that the, the, um, kind of data stores are something that they can protect in it and have adhere to their, the policies that they have in place for governance, resilience, for all their established workloads. So I think that's one of the places where AI intersects and it's where they look to Commvault to help them protect that data that's ma being made ready for ai.
And then the AI generated data. That's, that's kind of coming out of that. The other side of the coin is how do I use AI to be better at the resilience practices that I put in place?
And Steven, you already kind of alluded to some of this, which is, you know, using ai, I mean, it's great at pattern of recognition, right? So like, uh, what about things like anomalies and, you know, detecting those and threat hunting and, you know, helping people find, uh, we use it as part of our platform for our customers to, to help identify these clean points, to recover to, or to help, uh, see malicious activities that are otherwise really hard to detect if you're, you know, a human trying to, to compare this sort of stuff. For sure.
So I think the, you know, on the one side it's, um, making your data and your, especially your ai, you know, ready data resilient, and then the auto or, you know, the AI generated data making that resilient. And then the other side is just using AI to improve your, um, efficacy of your resilience practices. How does that strike you, Gina?
Again, you're kind of coming from the, uh, customer perspective as well, and from the, the world of, of, of, I guess, uh, tech skepticism generally. Um, does this, does this ring a bell for you? No, I think it's good.
I think it's been happening for a long time, though, um, within, uh, I think you guys have had some machine learning, right? For a long time and, you know, and so, uh, that's helped that this is not it, it's not a new practice, you know, and it's not something new that people have been thinking about. They've been trying to figure out, okay, this seems like if we use machine learning on this, we could get it to go really fast.
Um, and I think it is very true. I think the other thing is you, the people that are doing security and people that are doing, um, the operational piece, which is usually data protection, I think those teams are probably melting into each other a little bit. And I think there's not a lot of people doing it for the amount of a meteor coming at them and smashing them with AI driven ransomware.
So, um, you know, we already know that knocking on the door and getting in is the har is one of the hardest things for the ransomware companies. I'm just gonna call 'em that they're using AI to get better at it, but once they get in, it's really, really hard to detect it unless you've got these tools set up watching for it, even if you're been in the business 30 years. Because I mean, I remember being assisted men and having little scripts that I would run every morning just to see, and I'd have things set up and we could see when things were happening, but, uh, you know, it's a horrible feeling to know somebody's dropped a root kit on your, one of your systems and you've been wa watching for it for, you know, years.
So, um, yeah, you have to have, you have to fight fire with fire, and it's not like fire, you know, it's not like it was 20 years ago. It's, it's, it's all evolved and it's very, you've got companies trying to infect you and hold your, your data for ransom. So, and they're using AI to get there, so you've got to use fire with fire, I think.
Yep. Well said. And I think that that's exactly what we're hearing from some of these leading companies.
I mean, when we are at events, uh, with Tech Field Day, um, one of the things that I'm always listening for when companies start talking about, oh, AI is in our product, you know, the thing I'm always listening for is what are you actually doing with it that's productive? And I love it when I hear companies talk about how they're using, you know, generative AI to monitor, um, you know, massive quantities of data to find anomalies and patterns in that data when they're using AI to, uh, classify and organize and tag data when they're using AI to, as Gina is saying, fight fire with fire. Um, I think that that's great.
Um, if, if their answer is, yeah, we've got a little, uh, chat bot down on the corner that can talk to you, well, that's, uh, I don't wanna say it's bad, but it's a little less great use of this technology because, you know, it has a lot of potential and it has a lot of use cases. And, um, we can have, you know, small specific models that do specific things. And of course, we also have to think about this rise of agentic AI and giving AI applications autonomy and a chain of thought process.
Uh, by the way, quick plug, that's what we're talking about on this season of utilizing Tech, which, uh, will have just launched. Uh, that's our, our other tech field, a podcast. Uh, we're talking about AI and, um, I think that that really is going to be opening up a whole other can of worms, uh, good worms and bad worms.
So I, I guess to, to sum up Tim, um, tell us a little bit more about the state of the industry and the state of Commvault and what we could expect at Commvault shift here, uh, in November. So I think, uh, I think it'll come back to some of the points we talked, uh, about earlier, which is I think from a, the state of the industry perspective is the impact that AI is having on, you know, the market. And surely our customer base is not only massive, just, but moving at an unprecedented rate.
And so, um, what you should expect it shift is, um, uh, a, a a broad set of, um, you know, presentations, topics, discussions, demonstrations. We have a, a great both, um, for those who are joining in person in New York, um, November, um, uh, uh, 11th through 13th is we have a set of, you know, breakout sessions, um, all will have, you know, demonstrations of some of these technologies. And then we have a virtual track, and the topics are going to be around as organizations, um, scale their success with ai, how does Commvault help them bring those workloads, kind of protect those with the sorts of governance, uh, control policy monitoring and enforcement that they have, uh, come to get great at, uh, for the all their established workloads.
And then on the other side, how does Commvault help them use AI to be great at their resilience operations? I think that sounds really exciting. I think it's a really important message and, um, I know with the demos and stuff, you're gonna show people how to do it, so that's always the best.
Yeah, Gina, absolutely. I'm, I'm with you. I can't wait to see what, uh, Convault has in store at shift.
And, um, definitely we'll be continuing to follow this here on the Tech Field Day podcast, as well as on our utilizing tech podcast. So thank you both for joining us for this episode of the Tech Field Day podcast, focused on the connection and interplay between AI and data protection. Before we go, uh, where can we continue this conversation?
Uh, Gina, Uh, the best place for me is probably LinkedIn, um, and you can search for Gina Rosenthal, and you'll find me. I'd love to talk to you. Excellent.
And, uh, Tim, uh, where can we continue this conversation with you? Same thing. I'm Tim Zonca, uh, on LinkedIn.
You could find me there if you wanted to DM me, but also, uh, for those of us that wanna hear more, uh, get some hands-on experience, see some of what we talked about live, either join us in New York City, November 11th through 13th at our shift event, or do it online and you can, uh, join straight from your desk with good cup of coffee and see the same sorts of things. So thanks Steven, and good to get, get a chance to talk to you, Gina. Yeah, absolutely.
And we'll be, uh, covering shift on the tech field day channels, uh, YouTube, our social media, and of course on LinkedIn, where you'll find me as Steven FoST. Also, as I mentioned, uh, we have just launched our next season of utilizing Tech, which is focused on ag Agentic ai and features, uh, friend of the podcast, Frederick Van Herrin and Guy Courier as co-hosts. We've also just launched another podcast that's gonna be relevant to this audience, uh, security Boulevard, which is in concert with our sister website, security Boulevard.
Uh, there you'll find, uh, familiar faces, Tom Hollingsworth, uh, Mitch Ashley, along with, uh, folks, uh, like, uh, Fernando Montenegro and Alan Shimmel talking, uh, data security. So check those out in your favorite podcast feed. Thank you very much for listening to this episode of the Tech Field Day podcast.
If you enjoyed this discussion, please do subscribe. You'll find us on YouTube as well as in your favorite podcast application. I use Overcast.
So, uh, don't miss an episode. Also, please consider giving us a rating in a nice review. We love to hear from you.
This podcast is brought to you by Commvault. This episode is, uh, as well as Tech Field Day Home of IT experts from across the enterprise, which is part of the RUM Group. com/podcast.
You'll also find us on Techstrong TV and in our over the top applications. Thank you very much, uh, for listening, and we will catch you next week. Alright, uh, uh, alright, so what I'll do is basically, uh, through demos show what Gideon and Scott just talked through, right?
So, uh, what you're looking at here is the unified console. I think if you recall the first slide that Gideon showed you, uh, he showed you how in the defender console, this is the defender console, we have brought together everything that a SOC practitioner needs, right? If you all remember days of civil chairs where we used to have multiple portals that a security analyst, whether you were trying to understand an email incident or looking at a malware event, or trying to figure out what was happening in your identity space on trying to connect that to, you know, what might be happening in your cloud infrastructure.
What we have done is basically brought all those different consoles into one place. So this is the one place, if you're in the micro ecosystem, this is a one place stop shop for you if you're a security practitioner to take care of, whether you're looking at, you know, identities, your endpoints, you know, events that might be generated inside your, uh, even environment. And then being able to connect that to your SaaS applications, your cloud infrastructure, you know, everything from configuring policies, uh, security policies for these different workloads or being then be able to do security investigation and response.
So it's truly a cross domain, uh, offering. And the reason we are doing that is because, you know, as Gideon Ventures and you know, attackers think in graphs, if they're not really attacking just your endpoint or just your email or just your cloud infrastructure, they are gonna attack any part of your infrastructure, of your digital estate and pivot into it, or from one, from one node to another node till they can get to your crown jewels and, you know, either ransom view or extort you or steal information that they're after. So with that in mind, you're really invested in what is our XT R offering, brought all these different domains together.
So now you can do cross domain both protection on the pre breach side, and then do investigation respond hunts across all these domains. The first thing I wanna show you in this is, you know, our exposure management capability, and this is the first place that graph starts to show up. So one of the questions that, uh, I believe Romeo you were asking was, you know, uh, why is this?
Like, once you understand the connections between all the assets in the, in the environment, graphs can help us quickly prioritize, you know, what is the first vulnerability I need to patch? So this is expose through our exposure manager module inside defender. And so over here what I'm gonna look at is there's an, there's an, um, internet exposed, uh, uh, container, but that has an attack part that takes to, um, a storage account that is storing critical, uh, data that I'm using for AI training, right?
So because I have this underlying graph, so this graph is powered, uh, by the central graph that Gideon showed you. So that graph becomes a fundamental data structure in the platform that is now powering different security outcomes. In this case, I am doing essentially a posture assessment and I figured out there's an internet exposed container that can lead to a possible breach.
So if I, so, uh, so the action here, uh, it would be, it kind of clearly describes what the tax story is and then gives me a recommendation of, you know, what I need to do, which is basically, you know, I, you know, put this behind a firewall, you know, put this behind a bastion access so you're not having directly exposed containers to the internet. Alright, so that was the case where it's, you know, pre breach, hopefully, you know, the, as as customers we focus on, you know, good hygiene, we reduced, uh, overprivileged, uh, exposed nodes, we patch our servers on time, we reduce access so that our environments are locked down. Uh, but we know that, you know, sometimes there'll be vulnerabilities, there'll be zero days and, and you know, things will get in.
And that's where, as a SOC analyst, you need to be able to quickly look at what's happening in environment, be able to quickly prioritize them and be able to do investigation and responsibilities. So what you're looking at here is the unified incident queue. Um, and this can, this will show you incidents both from Microsoft specific, uh, detection services, but also from third party capabilities that, you know, I think, uh, somebody was talking about opt, et cetera.
Like you could have detections on data that was brought into Sentinel, say from Okta or AWS or, you know, CrowdStrike, and then those incidents will show up here. Uh, one thing that, um, Scott referenced was, hey, we can actually, we're not only looking at, you know, one incident at a time. Uh, we can correlate alerts from different parts of your, uh, environment and stitch that into an incident.
Like, so what does it mean is, you know, one of the challenges SOC teams have had for a long time is, you know, alert noise or alert fatigue. And the reason for that was, you know, we would fire alerts, uh, or different systems would fire alerts at a point level, and you could not connect them together to get to an end-to-end story. So what incidents, uh, capability and Defender and Central do is we look at events and alerts that are happening maybe at different points in time across different systems and be able to correlate them into one Uber story.
So as a SOC analyst, you know exactly what's going on, so you can prioritize your investigation and response. So if I was double clicking to one of these incidents, this is what it would look like. So there are three alerts that are fired in this case in the Azure environment.
And again, using a part of the graph, I've stitched them into a story so I can know exactly what's happening, you know, which IP address was used to log into which user account, and then subsequently what, what other things happen. And the other thing that we have now done is basically added this notion of a blast radius. So I can quickly see, you know, if this person was to get compromised, where would the attacker go next?
So if this, uh, this will render in a second, and that then helps me prioritize this is the blast radius capability that, uh, uh, uh, that gian talked about. So I can now see that, you know, if this user was to get compromised as an attack pod that goes into, uh, this virtual machine in Azure, and if this is critical, then I can now use that information to prioritize the response steps that I wanna take. Uh, quick question.
How do you determine, like I am, I am, I'm sure users who have 52 have access to more than one machine and one container, Right? How do you calculate what the blast rate is for this event is right in the context of here, you just show me two. Yeah, right.
So in this, yeah, actually, so in this demo, this is a demo environment. Obviously, you know, this demo, uh, this person only had two, but imagine they had more, right? So behind the sea, what's happening on, at the technical level is, you know, uh, as assets are changing the environment, you know, we are computing the relationships between this user and any other asset.
So for example, we are looking at the permission set that they might have an entra. So, so will the incident view show me two or will the instance the, the two assets I have access to, or will the, the blast radius view show me 5,000? So, so excellent question.
So we will show you, I mean, there's two parts. So the system can calculate 5,000. We will take a subset of that and show you in the graph and, but we'll let you expand, right?
So this is about, you know, managing the real estate. So you focus on the first n hops first, but then from there you can expand and get to 5,000 System. How do you choose which ones?
5,000? Yeah. How do you choose which ones you show me?
We look at the number of hops, so we are looking at few things. We're looking at, you know, what are the paths to critical assets? One of the things you can do in defender is tag your critical assets, right?
Some will be system defined. For example, a domain admin is a critical asset, right? A subscription owner is a critical asset.
An M 365 global admin is a critical asset. So anything that leads to an escalation path to those critical assets, you know, those would be automatically shown. And then if your, if your, if, if your blast radius goes beyond N Hops, then we will basically, you know, I think we use seven hops to say, okay, what are the parts from this user up to seven?
And then from there we will, you can, you can re-expand and so we can get to the fullness of your, um, of your graph. Okay. I'm just confused about like the, the, the, the, the demo environment is, is very limited in that.
Like, I don't get the view of, of what it looks like in real life, what, What it look like. Yeah, I like, uh, uh, uh, act Akron, that feedback. Uh, I'll see if you can find like a more complex demo and send it offline.
Thank You as well. Iik, if I may ask the question? Yeah.
What's the bare minimum work? Um, an enterprise needs to undertake to leverage, uh, this cap graph capability? Yeah.
So if they turn on, um, es essentially, you know, the Sentinel Lake and graph capabilities, like basically it's, it's literally one click in the portal, right? So, you know, uh, they'll get a banner, I think in, uh, in, in the portal. They just click on that.
Once, once the underlying lake and the graph engines un enabled, then these, these features start to light up, right? Um, there's obviously a, a, a boot up time because we need to, you know, assess the environment for the first, uh, day, uh, look at, you know, all your assets and activity and start stitching to the graph. But once that is done, then then this, this, these capabilities light up in different capabilities in the book.
Okay. Thank you. Alright.
Great questions folks. Alright, so I have a, Yeah, go ahead. Sorry, just sort of related to that, I, I have a somewhat tongue in cheek question.
Um, the, the graph showing the potential blast radius and, and sort of the incident, I think I asked this question on a previous, uh, Microsoft security briefing. So it can show me like, this is an incident that has happened, it shows me after the fact. You can also sort of show me this is what I predict is likely to occur.
Yes. Yeah. Yes.
Can, can that, uh, that's quite useful for an analyst perspective. Can it kind of generate a report that you can then provide to the executive, for example, to explain to them what happens when they say that they accept the risk, uh, so that I can keep that in a draw for the, uh, for when the investigators come from the regulator or, or something else after the incident does actually occur. Um, yeah, that I'm, I'm thinking of this.
It, it could be a very useful way to actually motivate, um, spend and budget to actually fix some of these issues. Excellent feedback. Excellent question.
So this example that I showed you before was exactly that. So this is before a breach has happened. This is just pointing out what, where the risk in your environment are, right?
And then you can export this, you could save this. And so at any point if later on in the, in the organization life cycle, this, this service was to get compromised and it was because this was exposed to the internet, you can go back and show the audit report to say, Hey, you know, this was flat previously, you know, for whatever reason the business group accepted the risk. Uh, and now look, you know, it's part of an incident.
So yes, this, this, that information that exists in the system and can be exported out. Yeah, it's, it's sort of a variation of what you've got there, I think, for the attack story. So being able to surface that like a hybrid between that and the prioritization for like incident break fix, yeah.
Um, that would be quite useful as a way particularly just to accelerate the report of like, I need to generate a summary of here is what the, the work plan that we would like to have for the next quarter in, in language that is easier for non-specialists to understand at the moment that, that actually is quite challenging to do. Uh, and, and as you say here is like, particularly when there's a lot going on, showing it in a prioritization way that is easy for non-specialists to understand, yes. That can then be attached to a budget line item would be rainy and handy.
Yeah. Excellent feedback there. And in fact, you know, I don't have that in the demo today, but, you know, one of the things you can do is because this, this graph and, and the capabilities of accessing graph will be exposed to the MCT server, you can now have, imagine an AI is basically going through all of this and generating a, you know, very simplified, prioritized report for the business groups to say, Hey, this is what happens when you choose not to say, patch this device or change the configuration on the storage account, or, you know, reduce the access on this, uh, on this user.
Uh, and that, and, and explain what the impact could be if, if any of those were exploited. Yeah, I, I'm a little bit sensitive to the, uh, to the potential for generating like something which is a bit wrong or, or slightly misleading from LNS because a lot of this is quite templated and, and fairly standardized. So I'm hoping that that variation would be fairly low.
But it would be great to have, uh, just like the standard summary thing of like, what we have for this is what the incident means, or this is what the risk, uh, what the risk means for our environment. Having that to be quite a reliable thing. Just be partly because that means that there's less for me to have to go through and then manually check and go and look into the data myself to make sure that I'm actually not misleading the board.
Um, 'cause if I pre, if I present that sort of thing in board papers, uh, I, I will do that precisely once, uh, before I will be, uh, finding somewhere else to, uh, try this again. No e excellent feedback. I, I think all the building blocks exist, uh, in the product, uh, and that, that report generation can easily be built in AED format so that you are, you know, very prescriptive, very precise in terms of the risk and what happens when you accept or, you know, choose not to fix the risk.
Yeah. And if it could, like, if you can link into some pricing information of somehow and just have that to start, like pre-fill in or just get you started on budgeting. Yeah.
Like you can, That would be amazing. Yeah. Great, great, great discussion.
I would love to have continue that, that, uh, I have a question as well, um, uh, context wise. So, um, my thoughts were just triggered by you just initially is, is putting in context into our environment. So I'm assuming there's a way I could say, these are the critical assets, therefore I wanna prioritize them above the same asset.
That's not a critical asset as well as, here's a recommendation, this is your risk. You've had x amount of incidents that took this exact path already. Is there any context setting there as well?
Is that, do you get what I'm asking? Um, if you may repeat the, the first part again. So yes, we can tag all critical assets, right?
And that helps you prioritize, right? So, uh, like which vulnerability or misconfiguration or oversharing you need to fix first, right? And I think in this example, we are showing you choke points, right?
So these resources are things through which multiple attack parts are going to these critical targets, right? So that helps you prioritize your, uh, your response. And then if you have seen one of those being, I, I guess your question was if you've seen one of those being played out in a previous incident, then you use that information to prioritize your subsequent Yeah.
Like, like, 'cause I, I can give examples to senior leadership and say, you know, this is a huge risk, and they can still say, I accept that risk, but if I've got a easy to generate reso, um, report that says you've accepted that risk X amount of times that have led to this amount of incidents. Yeah. Um, great.
Again, great feedback. You don't have that out of the box, but again, the APIs and the data in the system, uh, in the platform exists. And, you know, that would be a great tool that somebody can build on top of this to kind of do that, you know, basically a backward audit and say how many times have the risk that you have accepted, led to a, uh, uh, to an incident.
Uh, and then, you know, from there you come up with some sort of a cost metric or a, you know, uh, uh, that kind of a decision framework for that. Uh, I think that would be great tool to, and i's talk to this. All right, so let me, uh, move forward in the demo flow here.
Um, so one of the things that we let any, uh, any soc team do, they have hunting teams, you know, people wanna be able to get into the data, and this is where, you know, the, the data lake and some of the capabil data lake starts to show up further. So what you're seeing here is advance hunting thing. This is a capabil defender and Central have had for, uh, many years.
So here you're querying essentially the analytics tier. Um, so this is where you would have your 30 days data. In this case, I'm looking for, you know, a, a possible spray attempt or an unusual sign in event in my, in my environment and see, you know, where different, uh, login events have been, um, uh, happening from, right?
So, again, you know, all the different tables, uh, uh, that you get from either defender or sentinel are available here, and you can use gusto. Gusto is, uh, a very popular query language in the micro ecosystem. Um, you know, uh, uh, it, it enables you to do very fast searches on top of, uh, various data so you can quickly hunt and pivot for, uh, enormous activities in your environment.
Uh, the new thing that I was showing was, this is new. The s capability, uh, that we report to is now you can also use graphs to start doing your hunt. So there's a bunch of predefined scenarios you can look at, you know, what are the parts that take to say a key vault or to a, uh, user access sensor data?
And then you get to this graph view, and from there can start assessing, well, this is a key vault, uh, but we find that, you know, Laura has access to this. So, so the, the, the, the question you can gonna ask is, what happens if, and let's assume Laura doesn't have MFA setup or is not using, you know, uh, um, uh, password authentication. So if Laura was to get compromised, then, you know, the attacker would get access to the key vault, and from there they would get access to whatever the, the access that this key vault was, was enabling, right?
So you can start doing, uh, i, I call it posture hunting, right? So typically hunting has been in the, you know, once a breach is happening, you're trying to find where the attacker is and where are they going next. But with this, you can now do posture hunting to basically start exploring where do you have exposed nodes, where do you have overprivileged access, et cetera.
And then use that to drive further hygiene in your organization To pick on the, what I mentioned before, uh, looks very clean in a demo data set like you have here. What does this look like in production? Because a lot more people than Laura have access to, uh, likely have access to that resource.
So what kind of preemptive, uh, optimization are you able to do to help me and my team focus on people that needs to be focused on? Yeah. Um, farro, uh, excellent question.
So, so few things, let we just kind of talk to what's happening behind the scene, right? So, uh, behind the scene, we have the lake where all the data is, uh, uh, is being organized, right? That is being used to put these, these graphs that's being loaded into a scale out graph engine.
And from where this experiences are being, so, right. So we obviously wanna look at the, the practitioner we wanna focus on, you know, how many hops they're looking at at one time so they can really focus their investigation and analysis time. So we control that by the number of hops that we render at a time.
Uh, we really focus on critical assets and, you know, parts that are leading to critical assets. But then you have the opportunity then expand the graph and get into diff different parts of the, uh, of the visualizations. And this allows us to make sure that experience is fluid enough, why allowing you to get to even complex portions in terms of the total size of the data you that you wanna load into your experience.
Perfect. Thanks. Alright.
So, um, so, so we talked about, you know, uh, our unified console, we showed you the exposure management, we showed you investigations and hunting. Uh, I think there was a question earlier saying, okay, you know, are you really about the Microsoft ecosystem or can you get broader, right? And this is where the connectors that Scott and Gideon referred to, uh, comes into pictures.
So we have, uh, uh, you know, over 350 different connectors. In this case, I think there was a question about, Hey, what happens if you bring in Okta? So we have connectors for Okta, we have connectors for SAP, you know, we have Okta for A-W-S-G-C-P, Zscaler CrowdStrike.
So we truly support, uh, hybrid environment, right? We do understand like security is a team sport and customers will use, you know, different security tools. So we have made sure that all of that data can be brought into Sentinel, and not just the data.
Uh, we will of course make sure that data gets normalized. There was a question earlier about normalization. That data gets normalized, and then you can do detections and investigation response.
So everything I showed you with respects to doing exposure management or doing incident correlation or doing advanced hunting, it works on data from all of these, uh, uh, different data providers, uh, as well. Uh, uh, so one of the things that, uh, I think there was a question earlier about sys logs and network logs and, you know, what happens in terms of, Hey, I don't wanna, you know, necessarily bring all of that into my analytics here 'cause I don't really find them, uh, they are high volume or can be possibly low fidelity. So the, one of the other things that you can do in this experience is you have a new table management experience.
And in this demo, I'm showing you AWS Cloud trail, but this could have been your SIS logs as well. You can click on manage tables. And what I have done is basically said, look, all of that data, I want to go into the data lake and I wanted to retain for five years, right?
So it's as simple as that. You know, you don't have to set up any, uh, your DIY infrastructure, you know, or set up anything else, say in Azure or in AWS. It's literally one click for a security, uh, or a SOC architect to decide the layout of what, where they wanna send the data, right?
So, um, uh, if, if they wanted us to send it to analytics tier, that works as well. And as Scott mentioned, anything that goes, genetics automatically gets mirrored to the lake. So Lake is always your kind of the full copy of all the data.
And, uh, as there was a discussion on, on pricing. So the way that data lakes architected is it, it decouples from an architecture perspective, and that's why I like to use the word modern lake. Um, it is separate storage and separate compute pricing, right?
So you can really store high volume data at scale at really low cost. You know, we also pass on compress, we compress the data and we pass on the, say, savings to the customer as well. So Lake really becomes a great place for you to, you know, park all your security data.
Um, I have been in the securities domain for, you know, 10 plus years. I was, you know, uh, running Microsoft's MDR services, uh, before, uh, stepping into this, uh, this team. And the challenge that all security teams have is this un this tension of how much data should I store and how much budget do I have?
And the vision for this offering is we, we solve that false choice, right? All security teams should be able to store all the data, right? And then only when they need, you know, hopefully they never need it, but when they need, the data is ready to be analyzed in multiple ways that enables them the security outcomes that they, that they want to achieve.
I had a quick question. I wonder if, um, there is a possibility to take a look at maybe compliance from a perspective of, let's say P-C-I-D-S-S, um, in storing the data for a year, you have to store it for a d for a year. Can you apply that to, um, a setting or configuration where it automatically identifies those devices and then configures this to store the data in the data lake for a year?
Wow, omi, brilliant idea. Um, you know, great feedback. We don't have that obviously right now, but, uh, you know, just, just amazing, amazing feedback.
I'm sure there's a way to script this and, uh, you know, like, you know, CAD your devices and save a part of like a, a, a specific kind of processing and make sure those logs are okay. We showed you the connector. So the fun part of the lake is, you know, you can actually analyze it in multiple ways, right?
So when you, when you choose the connector and send that data to the lake, right? What we are doing is we are storing the data in an open format. Um, it's, uh, we store it in Delta parque format.
And what that allows us to do is basically run different kinds of analysis engine on top of one copy of data, right? And that goes back to, you know, why this is, you know, from, from an architecture perspective, a great choice. And again, this is borrowed from what, uh, you know, other products in Microsoft, like Microsoft Fabric, et cetera, are doing, right?
So this is kind of the modern lake, uh, design point. Uh, so, uh, one, one of the things that we can now do on top of the data is imagine you are in, in an incident response or a forensic scenario, or you're trying to do a retro hunt that needs to go back, say a year back, right? So maybe, uh, you know, your local government or the CS a has pushed out an advisory, you know, maybe it's, it's about a nation state actor, but you're going back a year to hunt for that.
Uh, and now that is just built in inside, inside the sentinel, uh, data Lake Explorer. So you can just come, uh, it's the same query that I ran before, but that was running for 30 days, uh, in the analytics queue. Now I can run that, uh, you know, going back 365 days and run that in the lake, right?
So, very easy for, you know, security teams to start driving insights from the lake. Now, when you're doing, uh, analysis of a large volumes of data, sometimes you wanna be able to convert them into jobs. Uh, so the lake now supports view viewing you to be able to do batch analysis on top of the data as well.
So you can basically with one click convert that query into a job, and then that can be scheduled. So you can run it, you know, every hour or every night and do aggregations on the data in the lake. And any insights you find, you know, you can promote that, uh, back to your hot tier.
A great example of that would be retro threat intelligence hunting, right? So every day a new, um, TI feed like maybe an I uh, IP address, a domain A URL is being brought into your environment, and you need to match that, you know, going back, say, six months, one year, depending on, you know, whatever your regulatory requirements are, right? So doing that now becomes super easy.
You can just schedule a job every night. You take all the TI data. So I think Gideon showed you that ti data's in the lake as well.
You take that, you scan it against all your logs, you know, and then, you know, any hits that you find, you can then promote that into the analytics tier that then becomes part of your regular SOC incident correlation hunting experiences. Okay? So, um, I love costo, Costo is great, you know, but sometimes you need, you know, more horsepower.
And this is where, you know, uh, on the same data in the lake, you know, we have enabled big data analytics again, out of the box, right? And to enable that, what we have done is basically released a new Microsoft Central extension, uh, that pairs very well, uh, with, you know, GitHub's copilot, uh, extension. So let me pretty show you what that looks like, um, for customers.
So what I've done here is install the Microsoft Sentinels vs code extension, right? You can go into the, um, into the GitHub, uh, extension gallery, download this, install it. Pretty straightforward.
Once you've done that, all you need to do is basically log in into, um, into your, uh, security account. And from there, you know, you get to access the same tables that you were seeing, um, in the portal. So it's literally, you know, one copy of data that now you have enabled multiple ways to access it.
Uh, so what I've done in this, this view is this is literally a, a spark python notebook, uh, that is connecting to the lake, right? And doing a deep analysis on past attempts in my organization going back over a year, right? In this case, it has found all the users that has been targeted, you know, that is sprayed at.
And so that's where, you know, risk is possibly floating out, uh, in my environment, right? And again, these notebooks can be scheduled as a job as well. Uh, so in terms of, you know, uh, I think there was a question, uh, earlier about what kind of analytics you can do on the lake.
Uh, I would say, you know a lot, right? You can run KL jobs, or, uh, sorry, Fernando, I see this question coming. No, I'm, I'm very, yeah, I'm, I'm the one who asked, uh, where does this run?
Yeah. So when we provision the, the central data lake, the entire compute of that is provisioned internally. So it's a fully SaaS offering.
All you're doing is logging into sentinel, you're connecting to the compute environment. So you can select the kernel here if, uh, let me load. So all these are kernels that are available to you out of the box, uh, again, running inside your tenant that we have provision in the backend for you.
And once you select the kernel, then when you hit run, it'll run in your managed compute environment. So a really, this Is managed compute. This, this is not like running on some, on some poor laptop just because No, no, this is managed compute.
You know, you can choose between a small cluster or a large cluster, and depending on your job that you can do. And this is, you know, full, full Python spice box. So you get to get all the libraries you can do.
Uh, if you're sophisticated, soft teams with data science backgrounds, you can do ML training, you can train your own model, you know, do your more, your own anomaly detections, full power of data analysis now made easily available to every security analyst. And I assume that this, uh, that this compute farms are CPU only. They're not GPU enabled yet.
Currently they're CPU only. Okay, thank you. Yeah.
Alright. So, um, this is a part that I get super excited about is, uh, because this IST in VS code, you also can wire up the GitHub copilot, right? And in GitHub copilot, you can wire up the M CCP servers for Sentinel.
So selected the CP servers for Sentinel. com/cp. Uh, and you can find it in the documentation.
And once you do that, now you can start asking it fun questions, right? So, um, I use the word vibe hunting or vibe investigation. I'm not sure if it'll catch up or not.
But essentially what I'm doing here is, you know, I just ask a simple question, right? You know, maybe I'm a SOC analyst, I don't quite know what data exists in my lake. I'm gonna ask a question saying, Hey, I'm investigating an incident related to password spray.
Tell me what tables are relevant, right? Um, so the AI will connect to the lake, it'll do a semantic search. So this is where the vector search capabilities start to show up.
Uh, and it'll find basically what tables are relevant for me, and actually tell me, you know, why these are the relevant tables and what are relevant fields for me, right? So, very easy way to start exploring, or a new way to start exploring, you know, instead of just looking at tables and the schemas in the old way, you can now also start asking questions as to what data exists in my lake and start, uh, you know, start building an education strategy from there. Alright?
So once, once I've done that, uh, let me then ask you the question saying, okay, let me find signing failures in the last 24 hours, right? So, and, and you summarize. So in this case, it'll connect to a different MCP tool.
In this case, it's connecting to, you know, uh, uh, a query tool. So it'll, it'll create the query. It'll run the query, and then essentially start finding, you know, uh, what were the failures and were there any anomalous events, uh, that we're seeing?
So it's already started to find, hey, there's a password per indicator related to these, these specific IP addresses, et cetera, right? Again, very easy way for, uh, you know, you to do, you know, vibe, investigation, vibe, hunt, start, start using the power of the lake to start exploring the data, uh, with the CP two. Uh, but sometimes as, as I was showing earlier, I wanna do a long range data analysis over here, right?
So in this case, I'm asking the AI to connect to the lake, generate an Jupyter Notebook file, and generate the Python code to do this full analysis, right? So now I have, I, I did some quick queries, explore the data, but now I'm asking AI to essentially generate, you know, my Python code. And, and as we all know, like one thing AI is really good at these days is generating code.
So we are leveraging that for security operations and analysis as well. And so it goes ahead and does that. And, and so essentially, I was cheating a bit when I showed you this notebook.
This notebook was entirely generated, uh, by, uh, by the GitHub copilot, uh, agent mode. And it is now able to essentially generate the code, do the analysis by easily understanding the data in the lake, and now allowing me to find insights that otherwise I would've had to spend a lot of time, uh, you know, you know, set up the infrastructure, generate this notebook, do this analysis, and now all of this becomes really part of, uh, you know, I did this, uh, uh, on my own. And I know I'm not a native Python developer.
It took me about couple of hours to be able to connect to the lake, do this analysis and finance insights, uh, in this environment. Let me pause if there's any questions on what I've showed so far. Yeah, no, I think judge, I, it's just that, uh, the vibe coding and, and, and yeah, we're, we're still navigating that one.
Let's leave it at that. Yeah, we still, uh, but, uh, I, I, yeah, like, uh, uh, uh, if I may, you know, um, uh, I, I, my previous job, I was a developer on the PowerShell team. Uh, I hope, you know, people in this audience know what PowerShell is.
And my learning from that journey was like before PowerShell, you know, IT, operations in Windows used to be click offs, right? You would go to, uh, MMC console and, you know, you know, load up, uh, a snap in and, you know, you would click around and, and do stuff and PowerShell opened up and revolutionize how, as an IT persona you could upskill yourself and create more value for your organizations through automation, right? Uh, I see, like what I've showed you so far, you know, and, you know, obviously you're still learning what will happen in this, uh, AI era, but I believe there's opportunity for everybody in the SOC team to use these modern tools to upskill themselves and create more value for themselves.
We know that every security team is struggling with, you know, uh, uh, talented people and hiring and all of that. And one way to, you know, address that, uh, that, uh, challenges, you know, use these modern tools to empower everybody to do more and create more value for their security. Uh, teams mostly agree.
Yeah. Alright, so, um, switching back. Um, so one of the things that we, uh, that GI talked about was, uh, security copilot.
Um, so, uh, as part of security copilot that we announced on nine 30, um, there's a whole bunch of agents that are now available with security copilot, again, you know, agents both from Microsoft themselves, but also from our rich partners, um, you know, around the globe that is now available that you can now install directly, uh, into a security cloud environment and start, you know, using the data in the lake and other analytics engines that we have provided to, you know, find interesting, uh, security outcomes. com, that is now live and, you know, a great set of solutions from, you know, partners like Illumio are not part of this offering. So, you know, customers can go to the store, acquire their agents and solutions, install it on top of the platform, and when they install it on the platform, it comes with, you know, I, I use the word composer app.
It'll have their agent, it'll have their notebook, it'll have the connector that is bringing the lumion sites on top. And then, you know, uh, doing data analysis and then being able to, you know, generate agent insights on top of that. Alright, so that was my, uh, kind of plan demo.
Uh, I walked you through essentially everything that Vivian and Scott were talking through. We showed you how we have evolved. Uh, we have brought together all our, uh, you know, sock products into one console.
You know, it in integrates deeply with Sentinel. Uh, from there it layers into the lake. And then Lake enables you to do deep, deep analysis, how we have used graph to light up different security outcomes in different places, you know, across pre breach and post-breach, and how we have enabled, uh, you know, AI capabilities to enable, you know, security analysts and agents to derive more insights from the security data.
So, uh, slightly challenging question, given this is, this is all based in Azure, is that correct? The backend infrastructure for, you know, all these services is running Azure? Yes.
Yeah. So for, if, if it's quite good, which parts of it look like they are, um, for some organizations they are somewhat reluctant, uh, to put some of their data in the cloud. Um, are, is there a way to connect some of this capability to a data lake that isn't in Azure?
Can I, can I plug this into other data sources that I perhaps run on self-hosted infrastructure, Uh, not today, um, but, you know, would love to, you know, explore and understand, you know, what those setups are, if this is a regulated scenario, et cetera. Um, so we do have like not specific to this products, like we have, uh, you know, offerings of our cloud capabilities for specific, you know, uh, entities, et cetera. And so the ask is, Hey, can this be put in a box and made available to those specific entities?
Then, um, that is definitely a possibility. But, you know, as what I've demoed so far, it currently is running on Azure. Yeah.
And, um, I mean, I'm aware that you do have some, um, some high security, um, presences in, in various nations because there are certain government agencies, for example, that prefer to keep their, uh, their data away from the general public. Um, but it does. So there, there is essentially a requirement that if you want to take advantage of this, you do need to ingest your data into a cloud system somewhere.
How you architect that and how you actually, um, uh, your comfort level for that, where that data is going, um, is something that you will need to, to go through. Yeah. And I, there I can see there are some advantages for things like, for example, rag, um, where I can have highly sensitive data sources that I can keep separate, but I can expose them to some of this analysis capability through kind of an arm's length Yeah.
Um, way of doing things. So it, if there are some of those capabilities, that's something I'd be interested in learning more about later. But if, um, it doesn't sound like you wrap Out, there are some capabilities that we are thinking internally or I'm not, uh, you know, allowed to share at this, uh, uh, at this time.
Sure. I'm, I'm sure it's, this is a question that has come up at least once I, I doubt I'm the first person to ask it. Yeah.
Uh, stay tuned and I'm sure we'll, you know, share some, some updates shortly. Okay. Alright.
Um, I mean, that's all I had in terms of demos. I'm happy to take, you know, more questions. Um, Anyone?
Sorry, I, I was fiddling with the, with the, the, the audio button here. Uh, I'd love to understand, like, you've been, you've been evolving the, the, the, the product for a while now. I'd love to understand, what can you share about early experiences or early versions of something that were changed based on design partner alpha customer, beta customer type of input?
Like, what has been surprising you about how you thought people were going to deploy this versus how they actually deployed this from your early customers? Yeah, I think, um, uh, few things that, you know, pop to, to the top is, um, a lot of, uh, enterprises are multinational enterprises are multi-tenant organizations. So, you know, uh, uh, as, as an early version of product, you design it for a single tenant, very quickly realize that, you know, not all data is necessarily in one region.
It might be spread out in like, and then you, you need to do, uh, access control differently. You need to do data residency differently. So for, for a data product, like, uh, like for a platform like ours, making sure we understand, you know, requirements for, you know, customs in different regions and let them manage them, enforce policies on that was, was one good learning, and we have made sure it's part of our product.
Yeah, it ties into, uh, Justin's question just now as well. So, yes. Uh, yes.
Uh, anything else? One, go ahead. Yeah, anything else?
And particularly on the, on ever organizations made, like, one of the things I'm poking at if our organizations are actually thinking about more agentic workloads, so anything have popped up there? Yeah, so, so couple of, uh, so, uh, one thing is like, you know, um, uh, as, uh, giv showed earlier, you know, central as a product is, is very successful. We have 25,000 customers worldwide, uh, and we support a range of customers.
We support everybody from, you know, you know, customers in the large Fortune 500 bucket all the way to, you know, uh, you know, uh, mid-size customers and everything, uh, in middle. And so we, we are seeing different customers use this platform for different scenarios. So the first use case really is I think somebody, uh, initially asked with respect to, Hey, how can I optimize the cost of what I need to bring in to manage my sim?
Right? So the first use case is, you know, there's log data sets, you know, maybe assists logs, maybe your network logs, you know, that you necessarily don't analyze on a daily basis. You now have an easy way to park that in the lake, but it's still available for, uh, for rich analysis out of the box, right?
So that is, uh, one use case I'm seeing from, from customers, right? And this was in fact, uh, Gideon referred to the, uh, case study from Nationwide. That's what they, one of the use cases was like, Hey, we remove the false choice of, you know, what to store versus what to pay by enabling them to store that.
So that's one use case. Then we have some customers, um, who are heavy data science, uh, based SOC teams, right? So they take all the data in the lake and they, they have developed their, you know, Python notebooks.
They're doing ML training on the data, they're doing anomaly detection, and they're essentially doing those, essentially those insights on top of the lake as canal jobs to find things that are otherwise high to find, like, for example, retro ti hunting or being able to do to beacon detection. Uh, these, these are really hard problems to do, um, if you were just storing 30 days of data, right? So that's, that's other cost of customers, uh, that we are, uh, seeing.
Uh, then on the, on the AI front, we have both partners and customers who are now building copilot agents, um, that connects to Sentinel, you know, quickly finds insights to complete a very core portion of their workflow. So these are the three core use cases that we are seeing early customers, uh, latch onto. That was gonna be my next question also, um, around AI agents that are able to resolve some of the, um, alerts or vulnerabilities that are found from a specific path.
Sorry, uh, uh, Rumi, if you may, uh, um, repeat or elaborate again? Uh, sure, Sure. Um, so say we've looked at a specific path that has, um, that has been identified as a risk, is there a possibility to build, I know I've seen, um, SOC agents built to resolve certain things, but is there a way to build a SOC agent that can resolve some of these, um, alerts that have been identified via a path?
Uh, yes. It's, it's, it's totally possible, right? So, um, um, uh, so far what I've seen is, you know, people are a little careful of letting an agent, you know, take an action, like, for example, quarantine a device or, uh, reset a password.
But technically it's, it's all possible for, so you can, you know, for example, you found a vulnerability, uh, in a device, can they go ahead and ask, uh, NQ agent to say, for example, go patch it technically, you know, those are possible parts, uh, but we, again, being careful to make sure how we expand into letting, you know, AI take actions in the environment. So, so like, uh, I would say start with read, triage, analyze, uh, and then graduate to act. Absolutely.
Um, uh, Again, as I just gonna make your systems more, more robust. Yeah. Yeah.
I was just curious around that. Thank you for that. Uh, so is that used in the queries that, that are kind of AI driven to actually set those guardrails to keep it from hallucinating?
Yeah. So, um, in the backend system, you know, when you, when we generate the query, we do have, you know, a bunch of checks and verify that is happening, um, to make sure we scope down what is being returned so that it, it, it doesn't hallucinate, right? Like, uh, this is an industry-wide challenge, right?
And as we all adopt ai, we have to, you know, continuously keep finding, you know, uh, techniques that, you know, reduces, uh, the, the rate of hallucination. So the accuracy of the responses keeps improving. Uh, but, you know, as, as we've all learned, like dealing with the systems, we have to always keep in mind that, you know, it can sometimes not be accurate.
And so we have to continuously either tune the input, tune the prompts, you know, uh, give it the right context, make sure that the, uh, that the, that the data that it's, it's is reasoning over is accurate enough. So that doesn't, you know, make up stuff and, you know, uh, fill with wrong information. Hey everyone, we've got trouble with Tribbles.
I mean, tariffs. Again, you're watching Textron Gang. Hey everyone, it's Alan Shimmel and welcome to our Tuesday of edition of the Techron Gang.
Got a crackerjack gang line up here for you to talk about as usual, three interesting topics. Um, let me introduce you to our gang. We've got the one and only Stephen FoST, Sanjeev Sharma, and still licking his wounds over his Yankees.
Mike Ard. Gentlemen, welcome to Textron Gang Giants Beat the Eagles. That's all I gotta say.
I'm good for the year. Yes, the Giants did beat the Eagles. The Giants did beat the Eagles.
All right, guys, it, it, it, it's, the weak is off as usual to another exciting week. Um, today we're gonna kick off talking about, it looks like we're back to, what is it, a hundred percent tariffs or 145% percent tariffs or something A thousand percent tariffs. I don't know.
It's taco tariffs anyway, but Mike, what's going on? Yeah, it's kind of, uh, back to square one is your, is a good way to describe it. I mean, I think originally this whole conversation got started again because the Chinese decided that they were gonna restrict access to some of the rare earth metals.
And then we responded by saying, well, we're gonna start ta tariffs up on everything again and add it to that we're gonna restrict access to AI software. Now, some of this just seems to be, to me at least, that the Chinese are trying to remind us that no matter how much we make semiconductors in the US they're, they still got us because they got all those metals that we need. And of course, you can find those metals almost anywhere these days, but you still gotta set up the process for, um, mining them.
And that might take a few years. And I think they understand that maybe a little bit better than some of our folks in Washington. At the same time, I'm not entirely clear how this whole AI software threat works.
'cause if the most of that software is open source, I'm pretty sure they can just get access to from anywhere they want. But Alan, what's your take on what's going on here? You don't really want to know, do you?
Um, You know, it, it's interesting. I, I just feel like, uh, bill Murray and Groundhog Day, you know, we keep waking up every, you know, every couple weeks, month or two to the same thing here, Mike, I think you hit it on, right. I don't know if they're metals, but let's call 'em rare earths, right?
These rare earths right now China seems to have a stranglehold on supply. We have, to your point, Mike, other, uh, potential supplies have been located some right here within the USA, but we're probably a few years out from mining that commercially China's using this as a, as a a a a club, right? To, to force what they feel are unfair trade practices being hoisted upon them.
And when they do that, we respond by, you know, the, what seems to be the only thing we know how to do, which is ratcheting up tariffs, which then is just like saying, okay, we're gonna close our markets to that. And here's the important thing, Mike, I think you didn't, what you said, maybe confuse people. Tariffs are on incoming export taxes are on outgoing.
And so I think, if I'm not mistaken, this is about incoming tariffs, not export license fees. And, and if I'm wrong, I apologize. So then you gotta ask yourself, what, what exactly are we taring free deep seek, which as you said, is open source, a hundred percent of zero, still zero.
Mm-hmm. So, you know, as usual, makes a lot of noise spins up us, and, and at the end of the day, it's Taco Tuesday. It seemed that Taco Tuesday riled up the markets considerably over the last few days.
So Yeah, because they just see it's a hundred percent tariffs and, you know, and it's about the rare earths and all of these things. But I, I just don't know how much teeth this has and if it'll even if, if history is any guide here, it, it's just, you know, strutting and showing just your feathers because you're a big c**k. I, I, I think it's a, it, it goes back to that con it was a very interesting conversation.
If you go back to when President Zelinsky was at the White House, right? The question being asked as we have all the cards, right? And he, I think the question being asked here is who really has all the CO in this scenario has the higher cards in this scenario, United States versus China versus the rest of the world?
And as we saw, at some point, the tariffs as it is, incoming tax doesn't really impact the exporter. They just go find another market. These are fungible markets, right?
And, you know, look what happened with Nvidia, again, if I understood it correctly, we were putting a 15% export tax on NVIDIA chips and China then just said, instead of have contributing to that tax, we just ban Nvidia chips altogether, who got hurt? An American company called Nvidia. Right?
They're now suddenly not viable in the chi in the, in the second largest or economy in the world. So, uh, it's, it's a interesting situation, right? Also, as you said earlier on, uh, Mike, what is AI software?
Are we talking about agent force in Salesforce? Is that now restricted, or is it deep seek coming the other way, which is open source anyway? Well, you know, I, I think the tariffs extend on goods beyond these tech products, right?
And, and so I mean, the, the, the problem you have is, you know, it's the Boyle cried wolf. And you can only do this for so long. I, I think what we've seen is the rest of the world, not just the Chinese, the rest of the world saying, look, if you're gonna play these games, you're, we, we need reliable business partners in markets.
And they start just leaving you out of the conversation, right? And, and then you become irrelevant to a good chunk of the market. And, you know, and, and there are people here who say, well, that's okay because we're the biggest economy in the world.
They all have to come through us. Well, no, they don't. Not for certain things, right?
Talk to our soybean farmers, talk to our meat producers. If I can jump in on the soybean, uh, thing, that's an Ohio thing as well. I mean, we got a lot of soybean farmers here.
Um, they're certainly feeling a pinch. Um, I think there's a little bit of a, uh, even some, uh, Trump remorse happening among the deep red rural parts of Ohio where they're realizing that they won't be able to, um, export and, and, and for them, you know, it's funny, they say the same thing that, you know, wall Street traders and investment bankers say, essentially, it doesn't really matter what the rules are, as long as the rules are consistent and predictable and they can work around them. The the problem is that if you're a farmer and you're trying to decide what to plant that's a year ahead or multi-year ahead planning process, and there's a lot of money riding on that.
They take on loans, they plant, they tell, they pick, you know, they harvest and, and then they have to, you know, go to market with these things. You can't upset the board game during that process, or a lot of people are gonna be hurt. And, and in many ways, as you say, Alan, it's, it's the same with, with many of these other things.
I mean, the New York Times this morning was reporting that, uh, Trump is already backing down on his China tariff plans and, um, and it, and it just was Friday that he announced these things. So how is someone supposed to plan around that? How is someone supposed to deal with this?
I guess the only plan that you can make is uncertainty, which is why the price of gold and Bitcoin just keeps going up, because I guess people are trying to think about other hedges. And as you say too, there are other markets for these things. Um, there are other suppliers for soybeans, and there are other markets for Chinese electric cars and rare earths.
And, and, and you know, if you, we will look at what happened with the ai, uh, hardware market. If you completely slam the door, then um, other suppliers are gonna emerge. And that's what's happening in China right now as we're seeing the emergence of domestic Chinese manufacturers of, um, GPUs and also really incredible promising, uh, chip fab capabilities in China that would not have emerged probably if it hadn't been for these, um, tariffs and embargoes.
And that, that may be the ultimate backfire is I feel like there's, there is a playbook somewhere because, you know, this whole thing went down with the, uh, announcement from China and then within like, what, half a day to a day Trump starts pulling AI software out of thin air. I doubt that. I think somebody has, there's No way he's never even heard of that, you know?
Yeah. So somewhere somebody's written some sort of tit for tat response playbook somewhere, maybe Should, I think they call it project 25. Yeah.
You think it's a, you think it's in project 2025? I missed That. Yeah, I, I, I think part of that whole thing is to, you know, go ultra isolationist, close up the walls, rebuild the wall of China, except in reverse.
And, uh, so yeah, So, so is this 19? It's not being American, g*******t. It's no good.
All right. So this is USA 1920s economic policy. Is that where we're going?
Yeah. Remember what happened in 29? Mm-hmm.
Remember that scene in Ferris Bueller where the teacher is boring all the students? Do you know what he was talking about when he was bo boring all the students? Was it at the tariff?
Hartley? It was the PR Hawley tariff Act. Har, right?
The tariff har yeah, That's the thing. If only Ferris Bueller had paid more attention instead of cutting class, maybe we would all be in better shape. That's an interesting, that's an interesting proposition right there, Steven.
Yep. Is that, is that, I thought it was Biff that we were blaming, but it's really Ferris Bueller. It's really Ferris.
I, I blame Ferris Bueller for everything and it was a crime what he did to that car. Alright, We'll, we'll we'll see, you know, today's Tuesday. Check back with me on Friday and we'll see where this is.
Mm-hmm. Um, I, I, I've given this one enough of my oxygen in time. My life's too valuable.
Let's move on. We'll take a break, come back and let's talk about some, this is interesting. ITSM in the news ITSM platform Wars, you're watching text and gang, You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included at work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back in in another segment that also has a certain amount of tit for tat kinda, um, mojo.
So now Salesforce says that they are in the ITSM business and they finally launched their AG Agentic ITSM platform. And of course this comes shortly after ServiceNow, which owns about half of the market share. In ITSM said that they were moving into the CRM space.
There are other companies in this space that includes B-M-C-I-B-M, Atlassian, but it does feel like there's a good old fashioned war going on in the ITSM space. So Sanjeev, what's your take on what's going on here? You know, this is, uh, very interesting to see, you know, back when DevOps started, maybe a decade or so ago, people said, oh, will we need ITSM?
Right? Will we need or will it be developers ruling the world? And you'll be able to push the big green button and things will deploy and they'll run autonomously everywhere.
But in the past decade, all we've seen is that while the speed of, uh, writing software and developing code and deploying code has improved, managing what's running in production, the ops side of DevOps has pretty much remained the same. Right? In my, in, you know, I wrote the original demos for Dummies back in like 2013 or 2014, right?
The original one. It was like this, this thing because we didn't have much matter to talk about. You could download it for free from IBM's website.
And one of the things I talked about there was there's a impetus mismatch about how software is developed and how operations is run. And that's what devs was supposed to solve. But it's an unsolved problem.
Still. Most IC MDBs have garbage in them because of the lack of automation. People are tried solutions like, oh, we'll put everything on the blockchain.
Sure, that just makes change immutable. But if you are, if you don't have any idea what's actually running in production, right, uh, you still will put garbage on the blockchain. So that doesn't solve the problem.
It is very interesting to see all these companies still fighting it out, but does any one of them truly have a solution which has solved these problems, these challenges which companies face? I don't know. Every large company I talk to, every large company I worked for has a major problem of they don't really know what's running in production.
When something breaks, you're relying on human knowledge to say, oh, this breaks at this time under these circumstances, we know what the problem is. Let's go bounce that server. Lets go, you know, uh, roll back these changes.
Will, will, I hope. I mean, Salesforce has, you know, massive, uh, you know, credibility in the market. They have a massive presence.
Well, so does service. No, I think those are the two big dogs in this fight. So it's fun to see how they will duke it out.
And I think in the end, the good news about having fierce competition is, uh, the customer benefits from it. 'cause we will, they will try to out outplay each other. The new variable of course, this time around is, is ai, the AI agents, can we truly make infrastructure autonomous?
Can we make it self-healing? Something we've been promising in the industry for, for decades now. Uh, but I think with AI agents, we have finally headed in that direction.
But let's see, it's gonna be fun. It is, it is. Well, depends where you're sitting.
If you're in the middle of it, it may not be fun, but sitting where we are, it, it's fun. So a couple things. Number one, does this mean Salesforce is really just not a CRM anymore?
Um, you know, they've been saying that for a long time. But, but here's the other thing. Every gener there's every generation or so, there's an opportunity where it seems we throw all the cards up in the air and let's see where it lands this time, right?
And, and AI is this generation's, let's throw the cards in the air and see where it lands this time. Because basically it, it allows us to change the rules and, and do these things. So you have a CRM company that wants to do ITSM, you have an ITSM company that wants to do CRM.
You have ERP companies that want to be agent platforms, right? Because that's always what they were designed for anyway, they'll tell you. And, and, and so the, the battle lines are, are in flux, right?
And it's not just service, uh, ServiceNow and, and Salesforce, though, they're, they're two of, let's call them today's darlings, right? They're two powerhouse companies of the existing power infrastructure. But I'm telling you, look, for companies like SAP to be getting in here, and of course, IBM and, you know, your traditional Oracle, and, and these guys, you know, you love the smell of fresh meat in the morning and this fresh, there's the smell of fresh meat out here.
And the, and these guys are not these guys. They're not guys. These, these players, old, new, established, they're all very established.
Because make no mistake, this is not a little guy's game. This is not a startups game. There's a big boy game and Right, but they're going to war.
I Don't just look at this, just look at this a little bit differently, and maybe Steven, I'd love to get your opinion on this, but, you know, the people who buy CRM in an organization are not the same people buying the ITSM platform in that organization. So just because Salesforce showed up and said, I've got an IT SM platform does not follow that. Everybody who buys ITSM cares.
So, you know, how do they actually do something here that the people who buy ITSM are gonna care about? Well, and I, I think that that's, that's exactly right. In fact, fact, I would go even further and say that, um, you know, if you are a very strong, if you're very well known in one area of it, that can actually hamper the acceptance of your, of you in another area of it.
I mean, look at IBM in DevOps, for example. I mean, IBM is undoubtedly one of the leaders in the DevOps software and open source software especially. Thanks, now that they've got HashiCorp and Red Hat, and yet, I think if you ask the average, you know IT person about IBM, they wouldn't go to Linux and open source and DevOps.
They would start talking about mainframe or something, which is like completely ridiculous. It's the same with Salesforce. You know what I mean?
Salesforce frankly has egg on its face. It has a reputation of being a difficult product to implement, a difficult product to get value from. And if you go to an IT crowd and say, Hey, um, you know, Salesforce has got a product in this ITSM space, I, I think a lot of the IT managers might immediately, um, discount it because of their history with Salesforce.
On the flip side, if you go to a business person and you start talking about Oracle or something, I mean, they're, it's the same thing. They're gonna say, Oracle, we've been trying to mess with their stuff for years. You know, it hasn't given us the, you know, it's, it's all nuts and bolts and whatever over here.
You know, we need a, a partner, we need a service. Now that kind, you know, I mean, we need a Salesforce. So these things, it's, it's a Mars and Venus problem.
And we've been seeing this for a long time in it where you've got companies that, uh, they know how to talk to one market, and then they think that they're gonna be taken incredibly in another market. I mean, you know, go to go to Security Boulevard and see what they think of, you know, data protection companies in the security space. It's the same thing.
They're, they're using some of the right words, but it's like they're speaking a different language. It's like Portuguese and Spanish or something, right? I mean, they, like, they, they're just, it's a real hard bridge to cross.
But one thing I do wanna say is, what a relief to be talking about. Not ai, But we aren't talking about ai. Oh, You had to ruin it.
In fact, Sanjeev, I wanted to ask you this question. Since you wrote the original book. Um, some people are saying that this is, you know, with the rise of ai, this is a Bullwinkle moment in the DevOps landscape.
And this time for sure, we're gonna unify all this dev and ops stuff, and this is our moment in the sun. What do you say? Yeah, I, I, well, first of all, I, as somebody who's been advocating this for over a year, I hope that is true, right?
But I've seen this movie too many times before and been disappointed every time to say, is this really the answer? I hope it is. But at the end of the day, you know, the, the proof will be in the pudding at the right.
I think there are some very interesting solutions coming up in the market, right? Where truly with agents, we can do things, and with ai, we can do things which humans could not do, given the scale and the complexity, just being able to analyze what's there. You know, think of how many companies that have startups have come in the last decade who said, we will go spread out these agents or crawlers in your infrastructure, and they'll discover everything that is there, and we will able to repair things before they break or predict you when, when an outage will happen.
None of them really served, you know, delivered what they promised. I'm just hoping that this is true this time so that people can, like, like me can say we were right 10 years ago, but, uh, I'm not going to be holding my breath. I'm going to be hoping it's true.
Now, I, I do wanna go back to this cross setting, you know, conversation we were talking about. And sorry if I'm mis messing you with your flow, Mike, and not moving on to ai, but I think some, one of these, one of the challenges I've seen as being a buyer in, you know, I've worked for two fortune hundred companies in the last few years and was on the buying side. We seem to discount when it comes working with purchasing organizations of a large company.
We seem to discount the, the, the power. A large company like a ServiceNow or a Salesforce or a m and IBM bring to the table through their enterprise license agreements and the ability to bundle software and literally squeeze everybody else outta the market. That's the play, that's the power, kind of the, the, the nuclear weapon.
Something like Salesforce brings to the table. That's what they did with Slack, right? They're like, Hey, it's in the package, right?
It's in the bundle. That's what Microsoft does all the time. Why do we all have teams despite us not liking teams and preferring Slack?
Every company has teams because it's a part of the bundle. That's the selling, the, the conversation when it comes to the CFO and the buyers at the budget holders, they go, if I can buy ITSM from Salesforce and we're gonna save me X dollars, maybe I should force my engineering teams to look at it. I think that's the part we are missing, and that's the nuclear weapons, so to speak.
Uh, these, these, these companies have. That's why to me, it's very interesting when somebody who's already getting millions of dollars, right? Dreamforce, you can go and see who all comes to Dreamforce, right?
These are people carrying hundreds of millions, if not billion dollar budgets. If they're going to say, I can now remove another vendor, I can save this many million dollars by buying ITSM from Salesforce. It's going to change the conversation.
Agreed. Mike, what, what Bullwinkle moment other than the three of us here, the four of us, how many people raise your hand if you know what a Bullwinkle moment is out there. Us.
That's what I thought. The rest of you not, so I'm doing my romper room thing and I see little George in that. It's, it's, it's, it's one of the great classic cartoons of all time, man.
And, and more relevant today than ever. Alright. Should we say a Lucy and football moment?
Would that be more relevant to the youngins? Yeah, yeah, yeah. To the younguns.
Anyway, You have to give the young ones office, you know, uh, analogies from the office or from, yeah, yeah. Something, something a little more, we gotta get more relevant. Oh, let's look, that's your homework for today.
Go ask your AI what a bow winkle moment Is. Hey, next week everybody's gonna be using that phrase promise. Absolutely.
And you heard it here first, but, but Sanjeev, you're right. That, that, that is the power of the big stick, right? You bundle it in.
Microsoft did it, right? IBM does it. Uh, they all, this is what big companies do.
And, and it'll be interesting. And, you know, um, I, I do think your, now it's one thing to say, well, I'm throwing out Joe Little Company because it's coming with my big company, but when you start getting turf wars between ServiceNow and, and Salesforce and Salesforce and SAP and SAP and IBM and IBM and Oracle, you know, that makes those procurement shops spin. It's mutually assured destruction, right?
Yeah. A little bit. 'cause they all have big giant enterprise License grid.
Well, until, until the battle lines will be redrawn, right? Mm-hmm. I, I think this a agentic AI thing, as I said, is throwing the cards up in the air and giving everybody a chance to, to claim new turf.
So I'll say like the sharks and the jets, you know, what we referring To? Un un un un until the, that's a relevant one guy gets fed up and goes and gets some other tools and just slides them in the back door, right? Absolutely.
Well, you know what? Here's the other thing I've learned, seeing these kind of turf wars erupt over the years, there's always one or two new guys who slip in, and this is their chance, right? com bubble burst, and I thought Alta Vista search was the way to go.
This company come called Google snuck in among Excited Home and Alta Vista and all that. Uh, there, there is, right? It's an, there is an opportunity, not widespread, but for a new, a new, uh, mm-hmm.
You know, giant to emerge. You mean Alta Vista originally created by, I believe, digital Equipment Corp. You thought that was gonna be the answer?
No. I loved Alta Vista search. I, I'll be very honest with you, I liked it a lot.
Next, he is going to say his Facebook profile is still open. Yeah, It is. All right, let's take a break.
We'll find out what happens. You know, it, Hey, it SMS relevant again, that's great. I four is here.
Um, let's come back and talk a little bit about unstructured data. Is it in crisis? You're watching Text Gay Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
Hey, folks, we're back and there's an interesting article over on Techstrong it talking about, um, whether or not we have a silent crisis around the amount of unstructured data we've been collecting all this time. And some folks estimate it's 30% of the IT budget, and a lot of that data is well useless and pointless, and we should get rid of it. But Steven, you've been around this whole data management issue forever in storage.
And so let me ask you, you know, A, is this a crisis? And B, how do we get rid of all this crappy data? Not only is this a crisis, this is a perennial crisis.
This is, this is a crisis longer running than one piece. Sorry, I had to put in a, a modern reference here. I mean, um, this crisis has been going on so long, uh, and we've been talking about it so long.
I could, I could probably find an old PowerPoint Microsoft 98 document from a presentation at Storage Decisions in 2001 that says exactly the same things as our article says today with even the same customers. Here's what's going on. Um, just to be very, very clear to the listeners, so unstructured data, I, I'm sorry, I get passionate.
This is my area. I'm MR. Storage.
Unstructured data is basically data that's not in a database, but it's also, and this is important, it's data that is not well described. So there can be, in my opinion, data outside of a database that is structured. In fact, I, I have seen, uh, incredible file systems, uh, that are incredibly structured and well described with metadata.
Um, I have seen, and, and, you know, searchable, categorized all that. I would consider those structured data, not even semi-structured, but structured. But if you look at data companies, essentially, um, you know, it's in their nature.
You know, if your background is in SQL or now, uh, no SQL databases, anything that's not in a database is unstructured. Lemme tell you, a lot of things in databases are pretty unstructured too. But, uh, point is most businesses have huge amounts of unstructured data.
The, the article that we, uh, just recently published, um, about this topic over at, um, at Techstrong, uh, it talks about many examples in many industries. And, and they were actually really good examples because I think, think people often jump to, oh, it's the nas, it's the, the, it's, it's Mike's and Alan's files on the file server. That's the problem.
No, no, no, no. It's the, like millions of medical images. It's the thousands of pages of scanned documents for every patient, or it is all the geophysical data that's been constructed, you know, built up over these years.
And it's not always in a na it can be on all sorts of things. Now, the opportunity here is to structure that data or to mine that data for value. And that's what a lot of companies are doing right now.
You know, we, I was at Q click Connect earlier this year, and they've got a lot of capabilities to structure unstructured data. Um, our article, we mentioned cloudent as a company that's really leaning into this. Um, you know, I've certainly heard a similar story from Microsoft, uh, talking about pulling data into the cloud from Amazon, uh, web services about pulling data up from Google.
Uh, for me, uh, I hate to do this, but I'm gonna do it. One of the most exciting things that's happening in the world of unstructured data, yes, it's ai because AI is actually really good at quote, looking at files and extracting structure from those files. In fact, I get more use of chat GPT as a data structuring assistant than I do as chat GPT as a write my homework assistant.
Essentially, I will routinely throw articles or data sets or spreadsheets or, you know, CSV files or, or just plain images at chat GPT and say, describe this in JSON. I need to know, you know, a list of of faces, a list of animals, a list of, um, you know, background objects. Uh, you know, I need to know which companies are mentioned in this article about unstructured data.
I need to know, um, you know, which, uh, you know, I need a summary of all of the, um, different vendors that are mentioned in this spreadsheet. AI is really good at that. And the best, uh, answer to unstructured data that I've ever seen is essentially building data structuring systems that leverage LLMs to pull information metadata out of these and, and surface that and make it more useful in the future.
Whether that means moving it off the file system into cloud storage, or building metadata systems and searchable indexes around them or whatever it means, this is really an opportunity that I've never seen before, and it's something that I could get really excited about. And, and frankly, it won't burn down the rainforest with, uh, chatbots that are telling us to kill ourselves. It'll, in fact, help us to use more useful, uh, get more use outta the data we already have.
Sanjeev, after three plus decades has Steven's moment finally come. Yeah, Say yes, please say yes. First of all, I hope so, right?
As a former executive from Dell, I don't, I don't want anybody deleting any storage sitting on Dell hardware, right? So, uh, uh, any files they're sitting on Dell Storage, please keep them there. In fact, keep them growing, right?
Uh, but I, I think, Stephen, your stuff, spot on, right? The challenge has been, I mean, I'm, I was at IBM during the big data. I know, remember big data where everybody was buying these, creating these data lakes and data warehouses, and it turned into data swamps and data, you know, backyards, right?
And that the problem was exactly that. You dump data, which you don't know anything about, it's got some label on it, an obscured label with somebody put by, you know, a human put on it. Uh, or it was put on by a machine, which was not intelligent, couldn't look and analyze the way today you can.
Uh, I think we finally have the opportunity to say all this data in our data lakes, or data warehouses or data, whatever, it's story or secondary storage, is it even useful? 'cause the first, that's the first thing you wanna find out, right? Most people do not delete the data because they think one day they'll be able to get value of it, right?
I remember working, uh, with a company which was at that point, 104 years old, and they had every transaction they had ever made, stored, and was that needed? It was not regulatory required, it was not a part of their history, but they felt one day we can mine, and I'm scratching my head going, you want to mine the buying practices of a teenager 104 years ago? Even that teenager isn't alive anymore.
What are you going to get out of it? But, you know, that was the hope. But I think that hope can result because AI agents, right?
Stephen rightfully said, are really good at looking at unstructured data, large amounts of data, and extracting, you know, some labels out of it, right? It could be as simply as just properly tagging all of it, and it can finally be useful. Alan, do we have a data hoarding problem?
Is that, I was just gonna say that really what this really comes down to is hoarding. Hoarding, right? I'm keeping, and, and look, I'm guilty.
I'm as guilty as the next person, right? You know, because maybe someone will need to look at my tax returns from 2003. Um, you know, I, I go through this on my own, like personal drives and stuff.
I, I, now, on the other hand, you know, my, my Google photos probably, I'm ashamed to tell you how many photos are in there, um, but I know I'm going to need that one. I wanna see when my, you know, I remember when my kid was four, and I want to see what he looked like that, right? Or what did I do during this?
At, on this day through the years, it's a giant hoarding issue. And we definitely have, haven't worked in, in, you know, in business, because you never know what you think you're going need. Or actually, you know what you think you're going to need, you just never need it, Or you don't know where it is.
It's buried, right? Yeah. And the reverse is also true.
Alan, I'd like, I love to ask you the question. How many photos in your Google Drive actually duplicates or duplicates? Oh, there's, so I do dedupe, but what I found is Google Photos, this is another discussion.
Google Photos will take three photos that are similar, but not exact and, and make them dupes. And so I get upset with that. But we, we have that problem in the business also, that there is large te petabyte scale, Tera, definitely hundreds of terabyte scale data, which is duplicate.
Mm-hmm. Because they duplicated for some reason Yeah. To work on it and never deleted the duplicate either, even though that reason to keep that copy isn't there anymore, Right?
How many times do you see a file name with the one, number one after it, or two or three? Yeah, those are ones you should be getting rid of, but Maybe, maybe, but who's to say that it's actually a duplicate? And I'll tell you if another thing I, um, in, in an interim in my career, I advised, uh, general counsel at public companies on data retention policies.
And it was funny because when I first walked into their office, they would inevitably say, delete, delete, delete. Get rid of this old data. It's a risk to the company.
It's costing us money, delete it. But once I explained to them the fungibility of data and the fact that, uh, this email that you are going to delete is actually stored on the email server of your client as well, and they will produce that in court, even if you can't, suddenly the tune changed. And the answer was, save, save, save.
So I have, um, a bunch of self-proclaimed storage laws that I've named after myself, because that's the kind of narcissist I am. Uh, one of them is that essentially, uh, the capacity of storage, uh, your next storage purchase is going to be, uh, twice the size of all the storage purchases you've made before. And another one is that, uh, your use of storage will expand to, uh, take up all the storage available.
Um, don't delete things, never delete things. Just keep packing it away. My blog is called Pack Rat, by the way.
I should point that out. Uh, just keep it, just keep it all. So here, you hear it from a hoarder here first, and Try to categorize it and try To structure it.
So you know what, hi, my name is Steven. I'm a hoarder. I'm a Hoarder.
Listen to me hoard. Anyway, hey, that's a great way to end this show. We're about out of time.
It brings me joy. Look, if it brings you joy, do it. Storage is cheaper enough.
Uh, that's what I keep hearing. Steven Sanjeev, Mike, thanks so much for joining. Thanks.
You out here for watching and participating in this, uh, mental Health Day here as we explored various topics. As usual, we have a full text, drunk TV lineup immediately following. Steven, you've got a field day this week, don't you?
That's right. Um, I'm gonna be in Vegas. Uh, we are meeting with, uh, NetApp, speaking of storage.
Uh, I'll be meeting with NetApp, uh, at NetApp Insight in Vegas. And we are gonna be live, uh, streaming on, uh, tech Strong as well as Tech Field Day on Thursday. Uh, it's actually not live, live.
We're recording it on Wednesday, and we're gonna stream it on Thursday. Uh, but, uh, with all the news coming outta there, so in terms of this data, uh, processing the metadata, the ai, uh, use of data, all that, that's what NetApp's gonna be talking about. So that'll be Thursday.
Fantastic. And I, I would just like to note that no data was harmed during the making of this particular Episode that we know of. And Stephen, Please, please ask Jack GP to tell you who Marie Kondo is.
I, I'm not going to, it, it doesn't bring me join. All right. I, I will mention that we are gonna be live at what was known formally the artist, formerly known as, or the conference formerly known as Quais Security Conference.
It's now Qualys Rock On Risk Operation Conference, and, uh, risk Operation Co. So Rock On. We will be streaming live from Rock on on Wednesday and Thursday as well.
So busy, busy stuff on techron TV and Tech Field Day. Stay tuned for it. Stay tuned for Tech TV right now, tech Strong TV right now.
Until then, I'm Alan Schimmel. I'm out. We're actually gonna be talking about MCP.
And if you went and watched Tron over the weekend, you may have been one of only eight people that did. However, we're not talking about the master control program. This time we're talking about something different.
Model, context, protocol. Welcome to the Security Boulevard podcast, a cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it.
com, the Security Boulevard, YouTube Channel, tech Strong tv, and all of your favorite podcast platforms. Before we jump into today's episode, let's meet the panel starting with my friend Alan. Alan, welcome back, Tom.
Thank you. You know, this is my first, uh, appearance on the New Security Boulevard podcast. We, of course, we've been podcasting around the Security Boulevard name since we launched it.
Uh, I'm Alan Shimmel. I'm the founder, CEO of Techstrong Group. com, as well as Textron tv and all of its various frontiers on the, on the rich media landscape.
Um, beyond that, though, I've been in security for about 30 years and started several companies, co-founded several companies in the, we used to call InfoSec Space before it was cyber. And, uh, it, it's a passion of mine, so I'm happy to be here. Thanks, Tom.
Well, we're happy to have you here, Alan, as well as our special guest for this episode. Mr. Scott Roon.
Scott, tell everybody who you are. Hey, Tom and Alan, great to be with you both. I'm Scott Roon.
I am a happy and grateful, uh, serial Tech Field Day delegate. Looking forward to a couple events coming up in the next few weeks. I am a co-founder of the Network Automation Forum, um, and I'm the co-founder and CEO of my consulting company solution, where we help people rationalize AI adoption and kind of cut through the hype.
All right. And of course, I'm Tom Hollingsworth, event Lead for Security Field Day and other exciting events within the Tech Field Day business unit at Futurum Group, and one of Alan's coworkers. I did wanna call out that it is, uh, gonna be National Dessert Day.
So, uh, hopefully you guys are having a sweet treat while you're listening to us. Um, and hopefully it has real sugar in it 'cause it's also National Real Sugar Day. Who knew that?
Um, well, the sugar, sugar people did. Uh, but I wanna talk about a topic today that's actually kind of sweet and that has to do with ai, but hold on, hold on. Before you race to the comments to tell me that we're talking about ai, again, we're actually gonna be talking about MCP.
And if you went and watched Tron over the weekend, you may have been one of only eight people that did. However, we're not talking about the master control program. This time we're talking about something different model context protocol.
It's the hot new topic this year that has really driven adoption of a lot of different age agentic AI components, but of course the Security Boulevard. So, you know what we're gonna talk about, we're gonna talk about the security aspects of it, and Scott, you kind of jumped in with both feet on this, uh, topic. So I maybe you could kind of introduce to the folks out there.
What is it about MCP that makes everybody want to use it, and why is it the security parts of it are starting to maybe keep you up at night? Well, to, to give kudos, right? MC P's been with us for 11 months, you know, at the time of this recording.
It's really just kind of hit, hit the street, um, very quickly. I, I'm a networker who has done a lot of network security stuff in my life. And to see yet another product come out so quickly, you know, that wasn't governed by let's just say very long processes and, um, other, um, standards bodies.
It's, it's pretty amazing to see it. Um, but it is reflective of this typical, um, product lifecycle where step one is get it to work. Step two is find a way to manage it, and then, you know, sometime later, step 179, secure it, right?
So there's like, let's make the packets go, um, and then we'll figure out how to secure all this later. Um, I have been pleasantly surprised with like, the integration of OAuth into MCP already. That's a great, and, you know, makes me hopeful in the first, you know, year of its lifetime here, but you know, miles to go before we sleep on this.
So it's very interesting that you talk about this idea that we need to make it work first and we need to fix it, secure it later. I've heard this before, and Alan's the one who actually brought this up when we were kind of talking about it pre-show, uh, Alan, this feels a whole lot like APIs to me. Is that what it kind of feels like to you?
Well, There is a resemblance, but, you know, invent it, make it run, worry about security later. That's pretty much standard operating procedure in IT for the 35 years I've been here. Um, you know, it, it's always the caboose on that train and it's kind of the afterthought, Tom, I gotta just one personal pet peeve of mine, I gotta throw out there.
I hate all of these made up holidays and days. I don't know if hallmark's behind it or what, but it, it's, it, I think it's been the bane of it. It, it's what led us down a slippery slope.
So I don't care about National Sweet Day, sugar Day or any of those days, but back to security, this is a typical IT innovation. Wow, we got the greatest thing here since sliced bread. Let's go out, run as fast as we can and get as much as we can.
And in this age of ai, time is condensed, so things are happening faster, quicker, speedier, more velocity. And then, you know, someone says, but well, but wait, but wait, what, what about the security? Scott?
I would, I would pause it that zero auth wasn't put in for security, was put in to make it easy to log in these things. Sure, yeah. You there?
That, that is certainly an element to it. I'm gonna take a small win here where I can, but I I totally hear you. Yeah, I mean, Tom, back, back to your point though, yes, this, to me, this was very analogous to the whole API security thing because you know, what we're really talking about with these MCP servers and, and you're right, Scott, I, you know, I thought it came out around last January, so I have 10 months, but maybe it was 11 in, in 10 or 11 months.
It has become the defacto standard for how agents talk with agents and other agents with, you know, within your enterprise. Now, there is a competing standards sort of competing called A to a, which is the, under the auspices of the Linux Foundation. And maybe that'll add better security, I don't know.
But quickly, this is the defacto standard for agent to agent communication. And, you know, God bless the age of AI in, in, in 10 or 11 months, this thing is like, it, it's like it's been around forever. And, and, and we had the same thing three or four years ago.
You know, someone came up with the, the API economy and, and, and the studies were done that a majority of the traffic going over the net over the internet was API to API traffic web, web to web kind of thing. And all of a sudden someone said, you know, the most important attack surface left in security APIs. We need to, we need to know what APIs we have, what their configurations are, what their security posture is.
And until we have that, we're, we have a blind spot to a majority of the traffic on the internet. Scott, you're, you're in the space, you know, you've heard, you've heard the stories. Yeah, I think so.
I couldn't agree with you more. Right? Um, and some of the work we've done in network automation forum, uh, we put up a blog post a few months ago, that's just a collection of community comments, not necessarily on API security, but API quality and usability.
And we definitely caught a thread of, you know, there's a lot of inconsistent, you know, publishing of API specs people, you know, getting half functionality, three quarters functionality, and that being a suppressor to actually driving automation for network and security equipment. So there's room to improve there for sure. Maybe that's more of an issue in the network element world where they're trying to be more API forward and move away from, you know, the CLI addiction, that so many of us, especially Tom still have, sorry, Tom, uh, you know, but there's, there's gotta be room for improvement there, you know, from a security and functionality and consistency perspective.
So let me offer this, because I think you're both right, that sometimes it feels like the security that we get with these rapidly developing protocols is more happenstance than it is by design. You know, uh, you know, Alan, you, you brought up the fact that, you know, using authentication mechanisms that just happen to be secure to ease, user login may have had a serendipitous benefit. What about, you know, using h TTPs calls for APIs?
Like, I'm sure that that wasn't top of mind for them originally. Like, oh, yeah, you know, we'll just do this or we'll do that. Oh, hey, it just so happens that we've secured this communications channel by default years ago because everybody on the internet did.
And when you look at the way that a lot, especially things like electron apps that are basically just web browser wrappers anyway, um, we've, we've arrived at a state of security that is maybe a little bit harder to configure on the back end to begin with, but ultimately is more secure in the long run because the fundamentals of what we've done have changed so significantly. Do you you feel like that, go ahead. No, no, go ahead.
Finish your thought, Tom. I I, I was just gonna say, do, do you feel like that the people kind of behind the scenes that have been working diligently to do this have done more to bring the state of security forward than those people that are living on the bleeding edge? Yeah.
So I, I will tell you the, the, the, the, the big issue in API security is most organizations didn't even know what APIs they had open, what APIs and what APIs were talking to, which APIs. And you can't defend something you don't even know you have, right? Yes.
The communication, you know, via H-D-T-P-S protocol and, and, and in, in transit is great, but if you don't know what you have and where it's going, it's good to know that at least while it's going, it's encrypted. But you still gotta, I would probably, you still have a fundamental issue. Um, that, that being said, though, funny thing happened with API security.
There was a whole cottage more than a cottage industry. There was a whole bevy of API security companies that came forward. The big one was called no Name.
And then there was another one that got, I believe, bought by Red Hat. And then there was, there was a half a dozen of these, uh, trace traceable io ai, excuse me, traceable AI was another part of Harness. Now, as often happens in technology, and Tom and Scott, you've probably both seen this, today's product became tomorrow's feature.
Sure. And so, API security, including API discovery, API communication encryption, API configuration has now been subsumed into some of these, you know, platforms that, that we, that we have around security. You know, it's, it's funny.
I'm sorry, finish your thought. Oh, No, that I, that was my thought. So, um, I've had the real honor of doing some work, um, associated with DARPA through something called the Embedded AR Entrepreneur initiative, where, you know, DARPA works with lots of startups in the security space and other technologies that come up with really interesting piles of tech.
Um, I won't call 'em products, right? But they come up with fundamental artifacts and pieces of functionality, and they need help figuring out, should this be a standalone product? Should this be a feature on somebody else's platform?
Or you're too late with this. It's already, it already exists as a product or a feature on another platform. Um, but it's been amazing to see those elemental, you know, uh, I, I did some really interesting work on, um, IAM um, issues in graph theory with a particular company and said, try to figure out, um, does this belong somewhere?
Turns out Wiz already had that covered. Um, but, uh, yeah, the integration piece is really important here. You know, many companies come along with pieces of fundamental technology and how well they're integrated into bigger platforms, bigger products matters.
Um, and, you know, we see it, we see it in the, um, network automation space. Like there's really cooperative, um, open working together between lots of different technology providers. Um, how well you do those integrations really matters on how secure it is in the long run and what ease of use looks like.
Yeah. Let me, and I don't mean to scare anyone out here though, but let me frame the, the real problem we're dealing with though, right? APIs and APIs, talking to APIs were great.
I think as we sit here now, on the dawn of the AI age, or in the early days of this AI era, it almo the automation that API to API gives us almost seems quaint because it was automation without autonomy. As we enter agentic ai and what does agentic AI really mean? It means we're gonna have autonomous agents who aren't just doing a task.
They're creating, they're, they're completing missions, multitask missions autonomously. And in order to do so, they need to speak to each other because each one of these agents are in their own multitask or autonomous mission. If we don't secure these things, the, the, the threshold for chaos, right?
The, the, the potential, you know, what could go wrong here is, is unlike anything we've dealt with, right? I'm not gonna go Y 2K on you, but you know what I mean. This is, if we don't, this may be a case where we can't wait for the proverbial stuff to hit the fan before someone says, oh, we should really think about security here.
Well, I, we've gotta get in front. Yeah, I couldn't agree with you more. And there's this whole body of work around, okay, what do agents need before we even think about trusting them to operate autonomously?
Um, they're gonna need identities. Just like people have identities. We're gonna need to be able to control access to other resources based on their as assigned identity.
Um, the, they're gonna be able to start firing off 5G calls at some point, right? So I've gotta watch how that filters down into not just my network, but you know, specific pieces of the network. Um, you know, does, does every, does every, uh, agent need to have its own, you know, virtual sim or eim, um, to watch it as, uh, we make calls.
I, I agree that this is a huge body of work that needs to be addressed. I also see attenuation, see what I did there with the 5G comment, um, or friction, um, against allowing autonomy to happen too quickly. Like, I think there's a huge process that vendors and system integrators need to go through to get enterprise IT shops comfortable with autonomous operation.
Some are, you know, very few are more eager than others, but paying attention to what does it look like to develop trust and autonomous systems is gonna be a huge gate to adoption in just about any organization. Scott, you're talking like the security guy. So let me ask this question because I'm sure someone in the comments is already thinking about it.
Yes, there is this hesitance from the IT departments to move too fast, right? Because we've seen what happens when someone rolls out an automated autonomous system that makes decisions. Either they don't like it because they feel like they're cut out of loop, or worse, it makes one mistake that then it gets amplified, right?
Is the, is the speed aspect of it coming from the IT departments, or is it coming from the decision makers above that who said, well, I was told by Sam Altman that this thing will just run my, my company for me, and I don't need to think about it, but why is it taking so long for this to happen? You guys promised that this was gonna be done already, while everybody else behind them is like, whoa, whoa, whoa, whoa. Wait a minute.
We're not quite there yet. I've Already laid off the people I was replacing. Exactly.
There you go. Yeah, yeah. No.
So let, let me give you an interesting factoid. I heard at a conference recently, I think it was 60% of CIOs are asking for bigger budgets for it, because they're being pressured by their boards to do more with ai. Yep.
And in order to do more with ai, they need to spend more on ai. And so they need to increase their budgets. Uh, so Tom, that's your answer in my mind.
I, I, I, I believe that that's real. I haven't seen that statistic, but that totally matches conversations I've been having, right? And if you think about budgets moving from actual personnel costs to paying for tokens for agents to run, like that's a real shift.
I think we're gonna see over the next few budget cycles, um, that's directly follows that trend. Um, I had something really important to say there, and I've, I've dropped it. Tom, do you wanna take it?
Well, look, look, can I, I, I gotta talk, Tom, your point about people willing to trust autonomous. So I had an interesting thing happen to me on Saturday morning. I had to go up to visit, uh, a relative in hospital up about two hours from the house.
And I, I took my wife's car, you don't usually drive it. And I got on the highway 95, and this nice agent's voice came on and said, oh, we detect, you're in a location, not a location or a whatever highway, and you could use the, uh, assist plus driving, just press the button on your steering wheel. I pressed the button on my steering wheel.
Now I've used cruise control. We've probably all used cruise cruise control before, right? It takes a little getting used to, but it's, this is not, this was full on driving my car.
Sure. So I will tell you that for the first 15 minutes, my heart rate was probably around 180. And, and I, I wasn't touching the steering wheel, but I had my hands right over because I'm waiting for something go wrong, and I could go like this.
And that took me maybe 10 or 15 minutes, and I, I kind of loosened my hands up a little bit. My heart rate went down a little bit, wound up with, you know, my hands on my lap over here. But it was so g*****n strict, excuse my language, it was so g*****n stressful.
Then I realized I'm better off shutting it off because I was too stressed out. Hmm. You know, waiting for calamity to strike.
I think there is that, however, over time, I think people get used to it, and I think that's what we're gonna see here. Yeah. And I agree To your point.
I think that there's, there's something you brought up there, like when people get used to the idea of it running, it disappears into the background, right? Like they know that occasionally it might have to touch the steering wheel or, or something like that. But there are also videos out there of what happens when the system fails.
I think one of the ones was, uh, it actually was a, a major national news article where a self-driving vehicle would not stop at a railroad crossing because it's not something it recognized and it didn't know that it was supposed to stop there. Those are the kinds of exceptions to the rule that people focus on when they're talking about these things. Well, what happens if it uses the wrong OS on the upgrade?
What happens if it does this? And, and they're ignoring 95% of the things that work most of the time. Yeah.
My calendar program might accidentally schedule me for a call at two in the morning instead of two in the afternoon once every nine months. It's the rest of the time that it just works, that I'm just oblivious to. So is that part of the problem we're running into here is that people are just oblivious to the fact that we are securing these things, that we are trying our hardest to prevent them from becoming problematic.
You know, something as simple, Alan, you brought up is like being able to steal data as quickly as possible rate limits, right? Like, I can't pull more than a thousand requests from this particular device per minute. Sure.
Not a problem for a human, not a problem for a well-written script. A problem for somebody who's trying to dump as much data as possible before they get discovered and, and ejected. Like, are we, do we need to start thinking about security in a different way to make it seamless so that people just assume that everything works?
Well, I so your Comment, Tom brought me back to what I forgot a few minutes ago, and I'll just say this is all representative of a good and necessary tension between the innovators and the implementers, right? And I think the innovation, um, around MCP and so many other things that we've seen has been awesome, and that's great. And we need people who are on the bleeding edge, hacking their way through the jungle and creating a path for others to follow eventually.
Um, and it's the responsibility of the, the people who are procuring, implementing, and operating the tech to say, whoa, whoa, Whoa, whoa, whoa. Let's make sure this is hardened for my use cases that I've kicked the tire sufficiently to make sure I can have a trust in it. And even if it's not full blown autonomous operation on day one, I've got something in place where I can start and I can map out a plan to say, what does building trust in this system look like?
I, I think we're always gonna have those two, you know, things engaged in that tension. On one hand, it kind of is what it is. On the other hand, I think it's good.
And iron sharpens iron in this case. Yeah, I would agree. Well, here, here's the other thing though, guys.
And I, I, I've told this story before. I was doing a podcast for Network World about, I guess it's gotta be around 2010, so 15, 16 years ago, and I had the CEO of at the time of Mongo db, right? And Couchbase two of the, and even then two of the biggest, what we called no SQL databases of its time.
And I, yeah. And back then there was a lot of discussion, you know, that they, the security in these things was non-existent. And I remember asking them both, I said, gentlemen, a lot of people say no, SQL stands for no security.
What's the deal with security in your products? And they both agreed and said this out loud. I couldn't believe they said it out loud.
We will put in more security when our customers demand more security and as much as security people, and Scott, I'm, I'm one too. We sit here and think security's the most important thing in the world. How could you roll something out without security?
If customers who are running and have established MCP as the, as the de facto standard are not saying, what about the security? Right? Can't blame the, the producers, the developers for not doing more about security and that that's the, that's, you know, the world we live in.
Well, it's, it's a fair point. And, and I'll turn it into, you know, the, the last RFP that you read, right? There's a security requirement section in there, most likely, but it's not the first section.
It's usually buried below. Right? Um, because there is, you know, we're worried about that.
Make the packets go make the product work first. Is it gonna fit the business need that I need to drive in my enterprise? Um, and Oh yeah, by the way, um, can you show me?
It's secure, you know that it's not the primary thought. No. I mean, this was a big thing.
com in 20 14, 20 13, and then within a year or two, DevSecOps really showed its head and a there a lot of the DevOps people. Well, you don't need devs, you don't need SEC in the middle of DevOps. DevOps has security built in.
There's no such thing as DevSecOps. It's just a marketing term. And I, I was one of them, I'll admit.
Um, but I came to the realization that you did need DevSecOps. You did need to put security in the middle because you needed people, both security people and non-security people to recognize that security was important and it had to be part of the equation. Yeah.
And I, maybe we need MCSP Little context security protocol. Yeah. You know, something with security right in the middle, because that's what it's gonna take for us to make security, if not front and center, at least you know where it belongs.
Well, I will, I will take that and like, I remain basically hopeful on all of this. And I would say, what if we could have this more unified view of what's in our sims, what's happening from a securities perspective? What's happening from a network observability and streaming telemetry perspective?
What if I could even pull stats on, you know, what's happening with my compute platform and different application performance? I think LLMs provide a unique opportunity to provide an integrated view of what's happening across those domains. And I'd love to start a movement with you all right now to push our vendors to say, why not give me a unified view across my whole IT ops?
You know, doesn't, doesn't mean those silos go away. There is specific expertise that's needed, insecurity in networking, in application performance, but if I can create this shim layer or this umbrella that brings it all together, I think that could be really powerful. Yes, we can.
Tom, you were gonna say something? I Agree, Scott. Um, you're just gonna need to upgrade to the enterprise plus AI license for the tool.
Um, that's gonna be eye wateringly expensive while I build it, and then everything's gonna be rosy. But I, nice, nice. I believe you.
I go back to something that, that I is kind of one of my favorite points to bring up here. And that's the idea that security that works well is not good because nobody knows that it's there. Um, and all you have to do to figure that out is try to drive onto any military base in the world.
Sure you have a government id, you are, you know, you are supposed to be there and they're still gonna check it. Uh, you know, think about, uh, the, the old RSA tokens, which are now apps on our phones or something as simple as a pass key, which is something I know that Alan loves, um, is there's still a popup, right? Hey, confirm that you wanna log into this website using this pass key.
That little tiny bit of friction proves that the security is there. You know, it's as simple as like having a little dialogue box popping up saying, we're auto, we're automatically logging you in with your credentials because you configured SSO you're awesome. Like when we, when we let people know that, right?
Like I, I, there's a story of IBM because I used to be an IBM or I was an intern there, and the road that went around the plant in Rochester, Minnesota was used as a shortcut by everybody in the, the community to get to Home Depot a little bit faster. And if you are familiar with any legal precedent in the United States, you know what an easement is, where if I have unfettered access to a road for more than one year, then I am, uh, then that is now a public road and I can't do anything about it. So every year for one day a year, IBM would close, uh, the checkpoints at the front of the building, which were never otherwise closed, and check IDs for people going through to make sure they were IBM employees.
Uh, their stated goal was to, um, make sure that they didn't create an easement on that road. But the secondary goal was to remind people that there is a security aspect here, even if it's not alter very present now at the facility itself, you still had to use a badge to get in. This is in 2001.
It's like, you know, you had to swipe your badge and you know, you had to, the doors were all locked and everything. Um, I will say that after I left and everything happened at the end of the year in nine 11, those checkpoints closed and everybody getting onto the facility had to check in for, I think it was two years before they would start allowing people to go through without having to show their id. Like we, we have to make sure that people understand that there is security in the system, otherwise either A, they're not gonna care or worse in my mind, they'll just assume that it's there.
And then you'll, you'll see the breach notification, like, why were you storing all the tasks, the passwords in plain text in an Excel file? That's bad. What deleting Now, Uh, gentlemen, any final thoughts on this topic?
I I, I, I wish we had an hour and a half to talk about MCP and APIs and AI and everything, but, uh, I think this is definitely a fodder for another episode. Well, I would, I would say I am really interested in what AI tools can do to help us think about new security architectures, more holistic security architectures. I think there's really interesting, um, promise there as well.
So another, another follow up episode, Tom? Absolutely. Alan, I, I would say this to, to wrap the bow around this one.
Yes. In 11 short months, it's become the de facto standard. As I said here today though, don't ask me if it's gonna be the standard next year.
'cause you don't know this stuff is happening so quickly. Yep. We don't know if something a better, a better mousetrap comes down the park, the road here and, and MCP.
What? Well, that's archaic, right? So let's not get, you know, we don't have to pull the emergency brake quite yet.
Secondly, it has only been 11 months. Security does, especially holistic, organically kind of embedded security takes time. We're not at the end of the game here.
We're, we're, we're at the, maybe the end of the beginning if that, and there's still plenty of time to get security right with MCP. Well said, sir. Um, I, I want to ask, you know, you two are both very busy, uh, folks, but I'm sure that you have a lot of great stuff going on.
Uh, Alan, what are some cool things you've got coming up that people should be checking out? Well, I am on Textron Gang four or five days a week, uh, every morning from nine 30 till I guess 10 15. So, and we talk a lot about all this stuff there.
I, um, I will be, actually, I'm not sure when this podcast will, will actually air, but I'll be at the Qualys Rock or uh, rock con, uh, risk operations conference this week. I'll be a cube con in November. Right.
We'll be broadcasting live from there. And I mean, you could, you know, I I publish about 20 articles a week on the various Textron sites. So you could follow me there, but I'm, I'm usually not hard to fight.
Scott, what have you got coming up that people should pay attention to? So, for Network Automation Forum, we have our next event coming up in November the 17th through the 21st in Austin, Texas. Um, we're always looking for more automation of security content.
Um, so the agenda's closed for this one, but keep it in mind for, uh, for future events. There's a, that adjacency between the network and network security. I'm very personally interested in seeing how that goes together.
I will, um, see you all at the upcoming AI Field Day and the next networking field day in, uh, coming up in late October and then November. Um, and I'm always driving interesting conversations on network operations and IT operations on the Total Network Operations podcast. So give it a listen.
Absolutely. And don't forget that for Tech Field Day, we have an exciting month going on. Uh, Steven is actually gonna be at, uh, tech, uh, tech Field Day Extra at Netex Insight this week.
Uh, next week we have Cloud Field Day Week after that we have AI Field Day. The week after that, we have Networking Field Day. com and check out the calendar, uh, because we're gonna be busy and we definitely want you to take part in it too.
Thank you very much for listening to this episode of the Security Boulevard podcast. If you enjoyed this conversation, we would love it if you would subscribe on YouTube or in your favorite podcast application of choice. So you don't miss an episode.
I'm a fan of Overcast, but whatever you want to use is great with us. We'd also love it if you'd leave us a rating and a review, because that does help the show grow and help us find new audiences. com and the Futurum Group.
com, the Techstrong TV website. Or if you are a fan of watching us on tv, use the Textron TV app. It's available on Apple tv, Roku, and any other smart device.
Don't forget that we are also on social media. Uh, you can follow us on, or Twitter on LinkedIn. Just look for security BLVD for more content.
Thank you very much for tuning in. We'll see you all next week. Hey, everyone, we're back here for another text drug TV interview.
I've been doing a lot of these lately, and I'm happy to see, I think primarily 'cause there's so much going on in the world, you know, in our world anyway, around AI and agent ai and security in ai and testing in AI and cloud native in ai, but everything is, and ai. Let me introduce you to my next guest. His name is Anthony Dero.
Dero Anthony is the dis, a distinguished engineer, uh, AI strategy BMC software. That's an impressive title. Anthony, welcome to Tech Drunk tv.
Nice to meet you. Thank you, Alan. Thanks for having me today.
It's a pleasure to have you on, Anthony. Well, let's sort of just give people a little bit about your journey, your story, how you wound up here today. You know, distinguished engineer, they don't hand those out like lollipops.
Um, talk to us about your, your, your journey. Yeah. Well, my journey goes way back.
I've been, um, in this industry for over 30 years now. Um, it's hard to imagine it goes by so fast. And I have to say, you know, working with BMC software, focusing in on our, you know, mainframe product experiences 30 years ago or so, when I first took my, uh, I first, I got my first job, I should say.
I remember people telling me why you gotta work for a company that does mainframe engineering. Uh, mainframes are going away, but here we are, 30 years, mainframe going stronger than ever. And my journey has always been in the, uh, mainframe space, uh, my, my entire career.
And I love every second of it. Look at the platform is second to none when it comes to technology, uh, and, and the capabilities of the platform, which really, um, really motivated me way back in the day to, uh, come on board with BMC. Uh, that was about 28 years ago or so.
Really? Wow. Yeah, absolutely.
I started off as a, as a, as an engineer, and over the years, worked my way all the way up to, uh, distinguished engineer. Um, as you know, BMC software has a wide portfolio of, uh, solutions from the dev, uh, DevOps space, AIOps, SecOps, DataOps, security, a whole spectrum of solutions. And over the years I've been, uh, fortunate enough to be the architect for many solutions across, uh, the portfolio end of late, uh, the last two years, hyper-focused on, uh, bringing ai, generative AI to our solutions, looking across our entire, uh, portfolio.
So that's what I've been working on for the last couple of years, is this whole AI focus and, uh, strategy and vision, uh, on how we want to execute on that from, uh, from the customer perspective as well as from the technology and what we need to do be doing from the architecture and the technology perspective with ai. I love it. What a, that's a what a great story.
28 years. I can't imagine. Oh, yeah, yeah, it's great.
No, I, I, I'll be honest with you, in the, in the same timeframe, 28, 30 years, I've only, I, well, I've been with three or four companies in all that time, right? Um, but you know, most people hop around every 18 months these days. So it's, it's a little different.
Um, you know, the, you, you say, oh, 30 years ago, people were saying, how are you, you're gonna work on a dinosaur, right? And here's this dinosaur still, still out there kicking butt. Um, but you never thought you'd be working on AI strategy on the mainframe, did you?
No, not, no. Just even a few years back, you know, you, you never imagined, you know, what the opportunities were, but when, uh, the landscape exploded, when generative AI came onto the scene, yeah, my brain just lit up, uh, from, from just in general, just being a technologist and geek, if you will. But, you know, being so in tune to the business and the things that we were doing, and really in tune to our customers and our customers' needs.
And that was always very motivating for me throughout my entire career with BMC was the, the great things that we would do and deliver for our customers. That's always been very highly motivated, uh, behind that customer success. So when AI came onto the scene, I really personally looked at it as a challenge.
Meaning you always see these cool technologies when they come about always on the other platforms, right? You see it in the cloud space, you see it in the distributed space, right? Well, you in the mobile space, you always see it on the other platforms.
And I immediately just locked in on this technology and just saw the potential immediately and what it can do for our customers, right? It always starts with our customers. So from the customers back down to our technology, and I just went for it, and I'm like, this is the, you know, all these opportunities are there.
We could start doing great things with this technology and making the mainframe just like the other platforms or in the game, just like the other platforms. And it's just been, uh, you know, pedal to the metal from that point forward, uh, with our solutions, and then working with our strategists, working with our executives, working with our customers, and formulating our AI journey, uh, up to date. Absolutely.
Absolutely. And you know, I'm, I'm not surprised to see the mainframe community embracing ai. You know, Anthony, you said something, we're technologists, this kind of stuff, geeks, geeks the heck out of us, right?
And I, I think that's why there's been so much progress focus on, on, uh, AI within it, maybe more than in the rest of the economy, because I think we are the people who get jazzed up about this stuff. This a, this is like waking up every day to Christmas, right? And there's a new, there's a shiny new toy there to play with Every day.
Yes. Yep. But I, I, I wanna, so, you know, BMC is already rolling out, uh, AI agents AI workflows for mainframe users.
I, I saw an in, uh, not an interview, a, uh, a report, a survey report, I think it was this week. Um, and it was, it was almost counterintuitive like crazy. 90%.
This isn't just mainframe, it's everyone. 90% of developers are using ai, some form or another, either generating the code, testing code, what, what have you, 90 90%. Yeah.
Nine outta 10 dentists use crust and nine outta 10 developers using ai. 40% don't trust it. 65% thinks it think that it introduces instability into the code base.
Mm-hmm. Somehow that doesn't add up. Right?
But because if 90% are using it, that means a hell of a lot of these people are using it even though they don't trust it. And even though they think it may introduce instability into the code base. Now, does that mean, you know, is full speed ahead damn, the torpedoes?
Or does it mean, hey, we're building trust, trust is earned trust. Yes, ab, absolutely. So first thing, you know, kudos to the entire development community.
I is, it was that group that embraced the technology that has played a major role in accelerating that technology to where we see it today, right? 'cause it was embraced. Now, as a developer back in the day, I have concerns with, when it comes to AI and the development experience, et cetera.
And what I mean by that is, we all should be looking at the AI capabilities in the, in the development community space, in the DevX space as an augmentation tool to our existing skills, to our existing self developers who are really leaning on the, um, the, the AI to get them through their day or get them through their tasks and blindly taking what the AI is generating for them, et cetera. That's where the problems come in. There's gotta be a level of trust established between you and the ai, and even to some degree, the AI back to you because you're prompting it.
You're driving the ai, that's an art. The best developers moving forward are gonna recognize that the AI is there to make them better. It's, it's a cape that they're gonna put on.
It's a tool that's gonna make them more efficient, more effective, and to get them through their day faster and better. But they still have to have the core skills and knowledge to understand what the AI is bringing into them, and to validate those results they're getting back from the ai. You know, a a dangerous thing I hear developers talk about all the time is, oh, I use the AI and the code.
It, it just, it, the code works. That's not good enough, right? We all know there are multiple ways of solving problems and coding up something.
You wanna make sure that you're still coding and putting software to together the best way possible. Not just because the AI generated some code for you and you're just gotta drop it in and use it. You still gotta use your skills and your abilities to see is this good code?
Is this, is this production level code? You still gotta put all the right security checks in place. You've gotta, you still gotta check all your code for vulnerabilities that could be introduced into your system.
So it's not a substitute for bad design, it's not a substitute, you know, making you lazy by any means, actually. You have to be more focused and more diligent when working with ai. 'cause if you do it correctly and you put the right checks and balances in and guardrails, it could really accelerate, uh, what you're trying to do.
I agree. I agree with you. I, I'm also reminded though that look, trust is something that's earned.
And, and you do it in small steps, right? So there, there's a process there of, of, of adoption, an adoption curve, if you will. And, and I think we're all in our own adoption curve and our own trust curve, if you want to call it that.
And yeah, I, I, I was a skeptic, I'll admit it, right? I was doubting Thomas and, uh, you know, over the last couple months, it's, it's really won me over, you know, and, and, and what it's capable of. Um, I wanna explore something else, right?
One thing about AI is it made hardware sexy again, right? Anthony? For, for the, for the last 20 years, you know, it was all generic hardware.
Yeah. I had a server, you were running an X 86 thing, or, or you know, maybe arm came in and that kind of stuff. It was really, the mainframe was the only sort of, you know, unique proprietary hardware like that.
Even some of the supercomputers were just daisy chain Linux devices, right? Yes. And, um, but now all of a sudden, g and, and the other, you know, kinds of, of chips specialized silicon, asics and stuff are, are, are playing a big role in outside this world here, $4 trillion market cap, right?
For Nvidia for this reason. What, how, how we, we, we can we run LLMs on the mainframe? We, we don't have the, you know, there's not GPUs in there per se, but how nimble is the mainframe for that kind of stuff.
Yeah. Yeah. So I'm gonna address this in multiple ways and perspectives.
Scott, go ahead. So what are the first things, you know, you talk about the mainframe, mainframe hardware, but obviously we got GPUs. You can procure your own AI box, right?
And throw your own GPUs in it. You could go to a cloud-based service and procure, um, um, a service up there with, with GPUs. So one of the first things we looked at, uh, with our solution is we want to make sure we give our customers the ultimate flexibility on how to deploy our AI solution.
Not lock it into one cloud vendor or one type of technology from the architecture, from the ground up, whatever our customers want. So if they want to install it in the cloud, they can, they wanna put it on some on-prem vm, er, uh, uh, on VM service. They can.
Now, let's talk about the mainframe. Very exciting. The Z 17 and the spire processors, that is where is what it's gonna bring the whole generative AI support that's coming out.
You know, with, with our solutions and our, um, BMC portfolio, customers are gonna be able to utilize that hardware. They're gonna be able to take our solution, deploy it on, on, on Z 17, and utilize those capabilities. We're really excited about that.
It, again, it just makes the mainframe sexy. It makes the mainframe. Now, for the people that are not in the mainframe space, they still really have this perception.
It's a dinosaur, a green screen dinosaur. And when I sit down and have these conversations of what the capabilities are on the mainframe and all the modern things that you could do on it that you could do in other platforms, they sit there with their eyes wide open, like almost in disbelief. I'm like, no, it's not the tape to the, the reel to reel with all the flashy lights.
So when I start talking to them about the capability of the Z 17 and the spire processors and what we're gonna be doing with our solution on the mainframe, it, it's getting people's a attention. The, the, the stigma, if you will, of the dinosaur is going away, especially as we usher in a whole new generation of main framers to our great platform. As the older folks start to retire out, AI is gonna play such a critical role in the mainframe adoption.
All of a sudden, folks coming outta colleges and universities, the mainframe looks attractive to them, right? I could use my modern programming languages, I could use my modern technologies. Like it's got an incredible AI hardware backbone for me to run my solutions on the mainframe.
So it's a, now it's starting to really gain traction in attracting that next generation to the mainframe. Because to you what mentioned earlier, the mainframe is becoming sexy again. Absolutely.
It's, it's an interesting point there. Um, you know, and in, when I talk to mainframe folks or even, you know, cloud non mainframe folks, one of the things they always talk about is, well, you either gotta know cold ball, or we gotta try to update these apps right? Into a, a more modern language.
Not that cold ball's not modern, I guess. But that, that again, is like a tailor made task, right? Could you imagine taking a COBOL program, giving it to the LLM and or to the ai, excuse me, and, and saying, Hey, you know, convert this to take your pick, uh, whatever you'd like today, Java, or, or whatever.
Um, it, it, it, I mean, yeah. We'll keep a human in the loop. Of course.
Yeah. But I mean, the, the, we should never hear again that we're unable to move these apps or modernize these apps. Yes, Yes, yes.
I think modern modernize is a better way to word it. Right? And, you know, what AI is gonna allow us to do is not do these all encompassing, monolithic conversions from, you know, coal ball to Java or to whatever AI assisting us in this journey.
Now, we can be very systematic and very selective on surgical. We want to keep on the mainframe. 'cause the mainframe is the best platform to run this type of code.
But then the AI can also help us understand what code could, could be refactored out and run on a less expensive platform or convert to Java, so it takes advantage of the zip processors and things of that nature, right? So now we could be very selective and use AI to help us refactor the code base selectively. And I think that's a great opportunity because we real, to really take the entire call ball program or workload off the mainframe.
It may not be realistic. It could be No, but it, but No, but I'll, I'll give you, excuse me, Anthony, I'll give you one better why we, we may have the greatest bonanza of COBAL programming that we've ever seen, because there's no reason why I AI can't generate COBOL code. That's absolutely right.
Absolutely right. I mean, don't get me wrong. I believe in a few short years ahead, AI is obviously gonna get to a point where it is gonna write better software than some developers out there.
It's gonna evolve. It's like any other, oh, I, I, I don't think it's a few years. I I think it's much, much shorter than that.
Yeah. Yeah. You know, I, I, uh, you look at like, like Claude code is coming out with now the code, it's writing Amazing.
Absolutely amazing. And it gets better. And, and it's trainable.
Yes. I mean, I, I, I still believe you're gonna need a human in the loop. Absolutely.
A hundred percent. But I mean, think about the ability, Hey, I want a new program from my mainframe. Write me a program from my mainframe in COBAL that does this, this, that, and this.
Yes. And it has to do that. And you have to use, log into this and, and, you know, you, it's almost a fantasy.
It's, You know, here, and here's what I, I really like about this approach, and I've, I've been experimenting with this, is it's not about just generating the code. I point AI to my code base. It un it understands my style.
It understands, it learns it. Yep. How I structure code, it understands, you know, my flow and my, you know, my logic flow.
And then I also augment the capability with just some of my own personal best practices and things that I do day in and day out when I create software, right. For prototypes and, and whatnot these days. So they don't allow me to work in production code anymore.
So I got my own, uh, you know, environment to do my, my experiments, but my AI is learning with me. So now what I'm asking it to generate code or refactor, it's not doing it in this generic type of way. It's actually, No, it's doing it in Anthony's style Styles.
Anthony's style, Anthony's approach. And now the recommendations that it's making to me in code complete or refactor, it's extremely close to what I would do myself in that regard. So this is where, from the development perspective, back in the day, or back a few years back, we had this notion of paired programming where you and I would sit mm-hmm.
Like side by side, literally working on a problem. Yeah, yeah, yeah. I've, I, I do get the AI is my paired program, right?
We're, we're in this together. Together. And you know what, I, I have a very similar workflow writing now, it writes in my voice.
Yes. It knows my style. I've updated, I've uploaded a whole bunch of my stuff, and it knows, and, and it blows me away, honestly.
It blows me away because I can't tell if that's what I wrote or, you know, um, it, it's crazy and it's coming. But, you know, that's more, that's a lot of generative AI stuff. Yes.
The, the agenda, the agents bring it a whole level of autonomy to it. Yes. That's the power.
And, And that's, that's really powerful right now, just go out and do it. Yes. Right.
And again, we'll keep a human in the loop, make sure it doesn't run crazy. Yeah. But just go out and do it.
It's an amazing time to be alive here and doing this, right? I, I, I feel you, you know, jazzed about it. I think we're all jazzed about it.
I, I, it's, it's, so some of the, uh, the architects I work with at BMC that kind of laugh and snicker at me from time to time, because I look at this vision of agents and agentic ai, I talk about them as like, I'm talking about people, right? Yeah. And at the end of the day, agents to me are digital workers.
They work 24 by seven turning and burning through whatever use cases that we have with AI as their intelligence engine, right? And that could be a hybrid AI approach, right? These agents could be using machine learning models.
They could be using, uh, generative ai. They could be using different, combining these techniques together, right? And some hybrid AI type type model.
But what I really like about these agents is for all the great that generative AI technology is, and we're all using it in our day-to-day lives, and now it's in, in the enterprise still, fundamentally, the technology is a, is a passive technology, right? Yeah. Chat, g PT sits there idle, um, you know, uh, anthropic, Claude sits there idle, they all sit there idle.
And so you and I have a, a, a, a, an action that we want to take, we wanna do some research, we want to go investigate something, and we, we go to, we go to the experience and we start a con a chat conversation that serves a purpose, right? But that's a reactive model. That alone is not enough when it comes to enterprise software.
So how do we move from having AI sitting idle, waiting for you to interact with it, or waiting for you to inter, uh, to trigger like a copilot experience, like right click on some code and say, you know, explain this code to me, or whatever it is, it's still a response. Uh, re a reactive model. Now with agents, we're shifting from reactive to proactive, where we get these agents working independently, working as a team on very complex multi-step IT type problems.
And they're just working, working their way through it and surfacing all kinds of great insights, whatnot. But now, this is where trust really comes to the surface. When you start working with agents and agents working on complex IT problems, how do you establish trust?
Well, you mentioned it a a bunch of times. Well, we're not gonna just have the ai ai you just run off and start doing things on, on, on its own, right? We still keep the human in the loop until the human is comfortable with the results that it's getting from AI to say, Hey, you know what?
Next time you do encounter this scenario, you know, hit the checkbox that says, you know, I authorize you to go off and run the script to, to deal with whatever that issue is that was detected. We will get there. But for now, we want to keep the human in the loop when it comes to ai.
But it's transparency, it's transparent. AI is what I like to, you know, talk to our customers and our teams about, we need to have optics into the AI agents to understand how these agents came about making the decision that they're surfacing to you. Our agents and our solution need to be fully auditable.
You need to have observability into these agents so that you can understand its thinking as it's observing the, the environment and the data that it's working with, and it's concluding and what to do. You need to see those, um, those reasons or those choices and why it's making those choices. So you have to build these agent systems with that level of transparency.
It's that transparency that's gonna lead to trust, and it's the trust that's gonna lead to full autonomy at some point with agents in the enterprise. I love it. Anthony, we're about out time, man.
I wanna thank you for coming on here, talking to us today about this. Keep up the great work. Let's come back soon.
I want, actually, before we go, for people who want to, you know, dial in to what BMC software is doing in around AI and agent ai, AI strategy within the bigger, you know, BMC website. Is there a section for this or it's kind of put throughout? Uh, no.
We do, we do have a dedicated, uh, location out on our, uh, BMC website, which talks about our AI and our vision strategy and the things that we're, we're doing. com and do a search on, you know, AI or uh, um, or AI solutions, you, you, you'll, you'll get a hit and you'll be able to go to that page. Or you could reach out to me on LinkedIn, find my profile out there, connect, and I would be more than happy to, uh, share those resources with you.
All right, man, Anthony, we'll have you back on soon. Thank you so much for sharing with us. Keep it Up.
Thank you so much. Appreciate it. Alrighty.
Anthony Dero, distinguished engineer, AI strategy BMC software. We're gonna take a break. We'll be back.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. Today we're with MI lid Hard Kna Prasad, who's president and CTO for engineering over at Salesforce. And we're talking about agen AI and the rise of it in the enterprise.
Mk, welcome to the show. Thank you, Mike. Great to be here.
Uh, and good, good morning, good evening to everybody listening. I think at this point, everybody's generally familiar with the concept of an AI agent, but that's not quite the same thing as understanding of how to build, deploy, maintain, and secure these things at scale. So where are we on this journey right now, and what are folks gonna need to know about building the agent AI enterprise?
Wow, that's, that's a big question. So what, maybe we should parse it down, right? What is an agenting enterprise?
An agenting enterprise, really where we envision agents and humans working side by side, right? To like, solve complex problems. Now, the problems could be, Hey, how do I get more people to buy my product?
Or the problem could be I have a product and there's a lot of issues with it, and how do I make it easier for them to solve it? Or simply just background processes where you want workflows to be solved for your employees and, uh, HR representatives and so on. So there are like different aspects, sort of for an agentic enterprise now, but the key thing in all of this is you could break it down into a few things.
One is you certainly need the right AI foundation, pv, when we say AI foundation, that starts with data and APIs. You need to extra, have all your data to be able to go make the decisions. You need to have access to the APIs to go take the actions on it.
And then you need a good sort of planner system, the agentic system, if you may, which can then orchestrate all of these data and actions and then surrounding it, you need to create that agentic enterprise. You need all the tools around it to make it easy for you to then observe, create those agents, observe what the agents are doing, and talk to different agents, orchestrate across all of them. And then finally, you also need like an underlying, uh, security and metadata that brings it all together so that you don't want the agents, you want rather, you want the agents saying the right things to the right people and not, uh, not like leaking your sensitive information to customers or employees and so on.
So that really forms what we call as a bedrock of an take enterprise. And of all this, of course, you need to make sure your employees or your customers, this agent take thing, is able to go reach them in all the channels of their choice, be it slack for your employees, whether it's your web, SMS, WhatsApp, whatever it may be. It should be able to go answer in all of those channels as well.
So that's kind of how we are looking at it as an agent enterprise. It's a sort of a multi-part system with a foundation of data APIs with a strong planner that augments with the tooling system, the observe, observe, uh, observability and analytics around it, the governance on top of it, and of course the security and metadata around it. How will I govern all of that?
Because as I look at this issue, each of these AI agents will be trained on handling a specific task or a set of tasks, right? It will probably work in concert with each other, but at some point I need to understand what they're doing and I may even need another AI agent to validate what the first one did. That's a good point, right?
Uh, in fact, even before we go to multi-agent, this is a problem even for a single agent, which is an agent is answering a lot of questions. How do you know it's doing the right thing? And so part of what we call as Judge LLMs that we have, uh, so if you use, uh, our thing called the testing centers, we call it our agent for studio, it allows you to go create tests or evals if you may.
And then we have a judge l LM that's running on the side to see if the agent actually answered in the right way. Uh, and if it didn't, we, it might either replan or at least tell you the tests are failed and so on. So I, it's definitely, uh, an important thing because it's non-deterministic, right?
It's a non-deterministic output. We're gonna be getting. So to your sort of question around how do we really do the governance, I think there is two levels of governance here.
One is, there's a governance at the data layer, which you call as a data governance, making sure the right agent is give it, getting the right data so that it can actually go answer the questions correctly. And that starts with an AI based classification, uh, and then tagging around it and making sure the agent is running in the context of the that particular user or that particular action. And so it has access to the right data.
That's number one. Again, it's structured, unstructured data shouldn't matter. We need that strong data governance layer.
Then when you go up to the level of cross Asian communication, you wanna make sure there is governance there as well. And if you go back to the worlds of APIs, we had done that before, right? With API governance, making sure who has access to what APIs, a p, Salesforce, and so on.
And the same thing we are trying to bring, uh, in, in the world of multi-agent, what we call this the MuleSoft agent fabric, where you can actually add the similar governance across agents to know, okay, which agents can talk to what agents, how, who should orchestrate what, uh, and putting the throttles, right throttles and security, uh, things there as well. Mm-hmm. How will agents negotiate with each other?
We humans negotiate all the time when we wanna, uh, have something accomplished, right? I'll do something new. You do something for me.
Right? Some agents may even have competing agendas and priorities. So how will they negotiate with each other and come up with some sort of resolution, or are they just gonna call us for an answer?
Good question. I think certainly it starts again with a few things, right? One is, uh, things like MCP and eight two, A eight, two A in particular, the protocol's evolving, but it's giving us a good foundation.
Just like, uh, you had the Rams and other kind of standards before. You now have the emerging protocols that's allowing for things like basic communication. It's like, okay, which agent, what can I call?
What are the error conditions to handle all of those things? But you asked a very important question, which is negotiation. How can agents negotiate with each other, uh, just like humans do?
Uh, it, it would be few things, in my opinion where it'll, it's, it's really one, first of all, we need to have the right context pass between the agents. That's like crucial, right? If this agent has a lot of context and the context doesn't go to the other agent, it's gonna just make up its own thing.
That's number one. Uh, and then, so that's part of the thing that we are working on to make sure cross agent communication includes a lot of the context passing either through sort of what we have is through profiles and other things, or through the protocol itself. But that's the second thing around this as well.
In a typical enterprise setup where you have very clear agent's, mark, you might have this agent doing your workflow process. I mean, for your sort of workday like thing, this agent might be doing your sales and everything else. There's less negotiation going on.
It's more around figuring out the right agents to call for your particular work. Uh, and that's where a planner comes in handy. Um, and you can, you need to make some of these things deterministic as well because you want to make sure there are very set of steps you had to follow, okay, you need to do an order first before you can go close the quote and so on.
Uh, and so we have the mechanisms sort of built into say, how can I bring in a sense of determinism in this non-deterministic orchestration? The second aspect is when you get into the negotiation is where you have a plethora of agents available. Maybe it's like a supplier dealer like model where your multiple agents running and you may wanna actually negotiate with the agents which agent is actually going to answer my task, and then maybe give it the, give it the job to do.
com, if you remember, we had all the B2B, uh, at that time it were agents, but you had all of these companies and protocols pop up for cross company negotiations to happen. I think we'll end up creating more of these protocols with these, uh, agent exchanges, if you may, where agents can advertise what they're wanting to do. And then as an Uber agent, you can go pass information to all the agents to say, which one will get me a better deal?
Um, and I think the more interesting things also is as we are learning, uh, this is all a learning for all of us that agents can lie to. So then we need to figure out, okay, how do we figure out is this agent really gonna tell the truth or not? And I think this is kind of where we can go back to some of our older, uh, things in terms of grabbing the data, its outputs, doing trends, doing predictive sort of scoring to say, if this agent is like really the last time it said yes, uh, it didn't really, right?
Like the action really didn't happen. And so we'll probably wall all those methods as well. And that's kinda why the observability is kind of critical in this whole thing.
Like observability and also closing the chain, if you may. Uh, in the human case, we did that before, right? When you actually sign up with a, let's say a dealer, they don't deliver that is there recorded in your CRM or other systems and you can figure out, okay, this person is unreliable, and then maybe we won't give the next deal to them.
We will leave all certain systems like that for agent things as well, Right? I think those are employees are usually our relatives, so that's why we know not to trust them. Right?
True, true. Um, I'm trying to figure out though, figure out how loosely or tightly coupled are agents and LLMs gonna be? Am I gonna have a scenario where I'm gonna have an AI agent that will invoke different LLMs based on the task and it will, uh, shop the LLMs as it were?
Or am I gonna have a scenario where there's gonna be, I don't know, four, uh, agents that are all capable of doing the same task and one might do it better or less expensively than another and they'll compete for the privilege? That's a great point. I think my, my, the way I'm seeing happen is that I think we are finding that certain LLMs are better for certain tasks.
We've seen that, right? And so agents that are specializing in certain tasks is gonna go optimized for that LLM because it's easier to say, oh, I'll just switch LLMs. But really the results are very different.
We have to go make sure the same prompts will get you different answers across the LLMs and so on. So my, what I'm seeing happen and my gut field tells me will end up specializing agents based on the L lms and then that way they'll compete to say, okay, this LLM has all this functionality meets cheaper. Maybe it doesn't give you everything.
Whereas this LLM gives you more functionality, but it's more expensive and you'll have fine tuned agents, which may cost more. Okay. This agent might give you the best answer possible for your core writing scenario.
It may cost you more. This LLM may be good enough for simple code writing that you may not care, right? Uh, so I think that's probably where we will evolve.
But I think an LLM switching, uh, thinks at an action level, yes. But at a planner level is very hard, uh, because you gotta fine tune it to make sure it works for that particular LLM. Certainly at an action level, yes, it can say, okay, this action can be done by Claude, this action can be done by open ai.
This action can be done by Gemini. That's possible. But dynamically flipping at a planner level, I think it's a little more farfetched.
Uh, we will end up more with specialized agents, is my gut feel. Hmm. All these agents will need to be integrated.
Does that require some sort of new dedicated platform to achieve that? Or are we just gonna extend our existing integration platforms that we're already using to access data and APIs? And it's just really a matter of making sure that the right data shows up at the right place at the right time.
That's right. I think my, what we will end up happening is expanding this. So think about, think about this, right?
Every agent, just like every human needs the right data. And what is the data? It's all about your customers.
Whether it's your sales data, who I talked to, who I didn't talk to, who came on your website, or it's service data. Like, okay, what cases I've had and did I solve your problem or not? Or early on in the pipe, it's your marketing funnel to say, okay, which person, uh, that I should be targeting or not, right?
And so all that information is critical. So I know it's the same Mike who came to my website, didn't purchase or made a purchase, didn't like put it in their cart, et cetera, or had the sales call, had the service incident unhappy or happy. All of those things is really what forms the context for what you think about a customer is.
And then you have the memory as an agent to like all the conversations you might have had had with the agents. And this is an important distinction between an agent, a human, because you may talk to different humans, it really depends on what the human then types into your CR mothers to know. What's the context of what's the conversation you had?
And most of us don't want to type and everything, but as agents can actually preserve all that history very easily across agents too. So bringing those two together with your profile, with your memory of the agentic thing, you can really understand what the customer is doing with your business. That I think is a very profound thing.
And I think that's kind of where we, as I think as Salesforce feel very proud that we have probably some of the best data out on there to be able to go represent. And so it's an extension, if you may, of the platform that used to serve humans to be able to go serve agents. And part of this is also connecting to the rest of the enterprise, which is why I said APIs and other connectivity is kind of critical to be able to go take actions, um, onto the different enterprise, uh, scenarios.
So those two is going to be an extension of what we've already done for humans into the agent era. But there is gonna be new things coming in and new things coming in is where I, like I said, we need different planners. We need more, uh, determinism within non-determinism.
What do I mean by that? Like, if you just give questions that people are asking to an LLM, we found there's a lot of issues. Meaning if you give more than eight instructions to an LLM, it starts hallucinating.
Or if you give more than a hundred topics to an LLM, it won't work. It doesn't know what to do. So, uh, you may want to have that determinist team to say, okay, somebody should have given you an order ID before we can actually go call this method.
Or if somebody is like an important VIP customer, make sure you don't keep bugging them with more questions. Go straight to the human escalation as the case may be. All of these needs a little bit of determinism, and that's kind of where some of these innovations are happening, where we can bring in determinism within the non-deterministic sort of LLM sphere, but grounded in the right context and memory so that you can actually give the right answers.
Mm-hmm. We start to hear the phrase context engineering more and more. And it seems to me that this is what that art form is.
It's getting that data, which is, and the context that's wrapped around that data, right? And giving the metadata to the right place so that there's enough of that information Yep. For the AI agent to come up with some sort of reasonable output.
But on the other end of it too, I think maybe you don't want to give it too much data because then you wind up getting a lot of extraneous output. So That's right. Is there an art to this thing?
It's a very good question, and I'll give the example with our own, um, customer success story, right? 5 million questions from customers have been answered by our agent, and it looks simple like, Joe, just feed all the documents to it, you'll answer. Uh, but this is kind of where the context engineering becomes important, because we did that same thing too.
First we just said, okay, let's give it all the documents. Turns out we found something interesting, which is you need to constantly also look at what is happening with your agent. What are people asking?
And is the agent answering correctly? Like it started off first, I'll give one simple example where somebody asked us to compare our agents with a competitor's agents, and the agent actually answered it, right? Like saying, oh yeah, we can do this, we can do that.
Uh, the other competitor can't do this. And so on. We were like, oh, no, that we should not be doing it.
And so we put a rule that said, Hey, don't, uh, don't talk anything about, uh, other companies. Sounds simple, except next week we found out people are asking, saying, Hey, how do I integrate your agent or your system Salesforce with another customer, like another company like X, Y, Z? The system said, sorry, I cannot talk about it, right?
And be like, no, no, no, no. That's an important one to actually support. So then you had to fine tune the instruction to say, you know what, you should be talking about integrations with other companies, but don't try to answer competitive kind of questions, right?
Things like that. This is one simple example, but uh, it's a powerful thing to kind of say that you need to be looking at what your agent is doing and evolve. The evolve can be you need to fine tune the instructions or fine tune your data, because a lot of times it could be missing data.
They're asking a question, you don't know the answer to it, that's where you go add more sources or it may not be answering it correctly. You go fine tune the instructions to it. And that's kinda where we are.
We have added a lot of tools, including tableau sort of tools, et cetera, to go analyze it across all of your agents to say, okay, what are the topics it's answering correctly or not answering correctly? Uh, and what the remedies that you can do, um, at a fine-grain level. So that's is really what context engineering.
Context engineering engineering's really about, like making sure your rag is right, uh, making sure pipelines are right, making sure your in instructions are correct to answer the right thing. And also making sure you are bringing all that right data together. Like you said, not garbage data, but all the right data together, structured and unstructured, uh, for the agents to work correctly.
Mm Hmm. Most battle plans are excellent until first contact with the enemy. So I'm gonna give you this scenario and see how it plays out.
So Salesforce widely used by salespeople, and they will use that to come up with offers and things like that, that they will send out to folks. But on the other end grid, won't there be a purchasing platform somewhere that has AI agents that will be acting on behalf of the buyers, and the two of these sets of AI agents are gonna somehow or other come together in in some external ether somewhere and mm-hmm. Do what to each other won't.
'cause isn't there a chance they'll just cancel each other out? Wow. But in some ways, if you really step back and think if the AI agents act just like humans, their goal should be to go maximize, right?
To maximize whatever they're built for. Whether it as a customer, you're trying to go talk and get your tasks done on the other side, trying to maximize the dollar potential from from that other side. I feel we will evolve on that one.
When you have these AI agents, they will all be goal-based AI agents. And we have seen that already. Like if you look at our SDR agent, by the way, we now run SDR agents on our website.
They're actually pretty good now. Their, their goal is like, how do you make sure the customer will set up a meeting, uh, or the customer will actually go to your property and go buy it? Uh, I mean go go to the uh, uh, digital online store and go buy it.
And what we are seeing is pretty fascinating already. Like these are, um, prospects that we would've never had, nobody would've picked up the phone to call them because these are like long tail prospect that just visit our website, but now we're letting our agents, because the goal is to go do this thing, it's able to actually talk to them, convince them, can you do the same? Now you're correct.
On the other side, you might actually start to get agents, right, instead of humans, in which case I, my, the thing that it'll evolve is their bulls will start negotiating understanding. And actually we've seen some, uh, recent, I think, uh, there was some recent things where when both sides understood with agents actually downshifted from talking English to their own language super fast too. Uh, maybe we'll get that too.
Say, Hey, you know what? I know what you're doing. I, you know what you're doing, do this.
But I think in the end, I would say it still comes back to the goals that the agents are trained to. Uh, and they will go evolve and be flexible and they'll also be, all the ambient data will be available for them as well to be able to make the right calls. Um, I think that's kinda where we will end up with And, and all the code will be written in Assembler because they'll figure out that that's the most Exactly.
Maybe Each will try to Hack the other, who knows. Um, when you put all that together, what is your best advice to folks? 'cause I think everybody's out there trying to experiment with various things and, and, but getting that over the goal line into something that feels like it, I can run it in production, feels like it's, it's a maybe a, a little heavier lift than there ready for, but what do we do to get there?
Yeah, great question. See, that's why if you look at the MIT study that came out right where 95% of the agent, uh, AI agent thinks fail because I think people are just looking at demos and saying, oh, I'll just so throw some things and things will just work. Uh, that's great for a demo.
But then when you get into real life practice, you need to have the solid foundation. Uh, and like I said earlier, the three foundations are one, it starts with making sure you know what data you need first. Start with the scenario.
I think that's the most important thing. Don't try to boil all the ocean. Start with the scenario.
Scenario could be something simple. It could be for your employees, your service, your sales, whatever it may be. Um, once you know that, then figure out what data you need to go accomplish the task.
What APIs or um, agents or APIs that you need access to, to go make that task and then create that agent with the right planning, with the right instructions to say what to do. But that's just step one. The step two is make sure once you put that agent in pilot or in in beta or or even production, start monitoring it with all the right tools, with the observe observability so that you can keep fine tuning it.
It's an art. Um, and then once you have that success, then it's easy for you to build upon it and then go create the next scenario and the third scenario and so on. Uh, never assume that just because you've created one agent, it's all fine.
I think, I think it, that is the part where I think people will, people are missing their thing to say, you need to continuously observe it and fine tune it, uh, as you learn from it. All right, folks, you heard it here. Hey, has that great AI leader, Benjamin Franklin once said, you know, failing the plan is planning to fail.
Still true in the age of ai. Yeah, it was great. Thanks for being on the show.
Thanks, Mike. It was great. All right.
And thank you all for watching the latest episode of the techstrong AI Leadership Insight series can find this episode and others on our website. We invite you to check all those out. Until then, we'll see you next time.
Every company lives in fear of a ransomware attack, whether they've suffered one or not. And this is even more critical in the era of ai. This episode of the Tech Field Day podcast looks forward to Commvault Shift in November with a discussion of the importance of data protection to AI applications with Tim Zonca from Commvault and Frequent Field Day delegate, Gina Rosenthal.
Listen in and learn about the connection between data, data protection and ai. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events.
This episode in particular, is recorded in association with Commvault Shift, which we will be attending in just a few weeks. Tech Field Day is part of the Futurum Group, and this podcast is published on our sister company site, Textron tv. This episode, we're looking forward to Commvault Shift, which is November 19th, and we're talking about the importance of data protection to ai.
Yes, ai, it's 2025, everything is about ai, but we've found that there's an interesting connection between AI strategies and data protection strategies. Before we get started with that conversation though, let's meet who's on the panel today. Hi, I'm Gina Rosenthal.
I am a fractional product marketing manager. I help lots of companies including data protection companies with their, um, private marketing. And I'm Tim Zaka.
I'm the Vice President of Portfolio Marketing here at Commvault, and glad to be here with you today, Steven. Thanks for having me. Yeah, it's great to have you.
Uh, as you mentioned, I'm Steven. Uh, I am the, uh, halftime host of the Tech Field Day podcast, and, uh, have been running tech field day events for 15 years. Over that time, I've actually attended quite a few Commvault, uh, events, and we've had Commvault join us as well at our tech Field day events.
And one of the things that comes across whenever we talk to folks from Commvault is the importance of data protection. I guess surprise, you know, I mean, that's, you know, what you do, but it's also something I think that is really, uh, in your hearts because you're a company that spends your time talking to companies who either fear data loss or have suffered data loss, and you're trying to help them avoid that catastrophe now that it's 2025 and AI is on everyone's lips and everyone is trying to figure out how to roll out a successful AI strategy. Tim, I wonder if you can start off by just sort of drawing the connection between AI applications and data protection needs.
I actually think you just nailed a, a big part of that connection, Steven, is you had said something along the lines of e everyone, you know, focused on kinda ransomware, staying resilient, uh, kind of frankly like the hygiene of what great looks like to just maintain a continuous business and fight through an attack. Now, while organizations are doing that and putting these best practices in place, they still most still have a long way to go. And you have this meteor of AI coming crashing into that set of projects, practices, and initiatives.
So I think one big connection point is as organizations are trying to improve their resilience, their recovery practices to fight through just kind of maybe good old, uh, cyber crimes now, it's just gotten that much more daunting as AI stacks look different, as AI data is distributed everywhere, as there's questions of accountability and ownership, and now add just attacks that could, uh, in the threat surface that's widened and different through ai. And I think that's the big connection point, because the so what across all of it, it doesn't matter if it's a, you know, maybe a more traditional looking attack or something that's come through ai, you know, poisoning or even just, frankly, an outage due to the newness of it, the business needs to be back up and running. And so having a resilient, strong resilience practice is, I think the, the connection point between the two.
I love that word resilience, because I think that's really true. A a couple of things that really stuck with me is it's definitely, you know, AI introduces all of this new ways to attack organizations. I think one of the most interesting ones is that the people sending the ransomware out are using AI to create their, their campaigns.
So one of the things we've lost is the, the as just users, individuals that, you know, on the, on taking all the training and looking out for the phishing, you've lost the ability of saying, oh, that's definitely not proper English, that I don't think this is really from that person. You've now got the ability, the, the, the people have the ability to, to train on an individual's voice and how they write and how they talk and send you a phishing email that looks super, super, um, real hard to explain. And then I love that point about resilience, because you're gonna make mistakes, because this is all new to everybody.
So you're gonna lose data, you're gonna dump something you shouldn't, and you need to be able to roll back. So it's, it's really important to think about that. Yeah, and I think you, you mentioned a good point, Gina, which is, it's, I think maybe it's just like we as technologists, it's easy to geek out on the more sophisticated attacks or, or maybe newer ones, you know, prompt injection or just adversarial attacks where maybe it's, uh, where the bad guys are using AI to do, you know, polymorphic attacks where the signature's changing and it's hard to detect.
But I think like, just making spam that much, or, and, or phishing rather, you know, that much better. Um, it's super dangerous. And, and I think that, you know, when you can have these attacks that are just actually logins, not, not these really, like, well-crafted, uh, uh, you know, initial kind of entry points.
Um, yeah. That, that's, that, I think that's really dangerous. Yeah, we've been seeing that here, um, where the, i, I don't wanna say sophistication because that's really not the right word.
'cause it's not any more sophisticated than it used to be. It's just, as Gina said, it's more convincing. And so we're starting to get, uh, well, I mean, we, we're all businesses, we all get ransomware, uh, attacks, or at least openings, uh, you know, phishing and, um, social engineering openings all the time.
But I've noticed that they really have changed. Uh, they used to be pretty clunky. They used to have poor English, poor integration, you know, sometimes it was like, dear, you know, last name.
You know, that kind of thing. Now it's really not like that. And it's pretty obvious to me that, that it's generative ai, especially with, you know, text chatbots that's enabling, uh, customization and personalization at scale, at least to some extent.
Now, obviously, as, as Gina points out, sometimes they're still a little nonsensical, but, um, it takes a human to recognize that. And I'm concerned that these, um, you know, the AI technology, on the one hand, it opens, uh, doors to creating more, uh, credible attacks. But on the other hand, of course, we also have to think about the ways that agentic AI applications are opening the doors for those attacks to be more successful.
So maybe we can get to that second point a little bit later. But I mean, first, um, you know, has the prevalence of ransomware increased or does it just seem like it has because it, it seems like we're hearing about it constantly and is it the fault of AI that these things are, are more credible and that's what makes people, uh, uh, more susceptible to them? I mean, I, I think at least what I see as I, as I talk with, with our customers around the world, I think I, I've seen, I would say most data at least suggests yes, ransomware is becoming more prevalent.
I've seen enough to say, well, you know, it's about the same or even, you know, a slight decline. But I think the punchline is, um, that it's gotten that much more effective and, and in common, and I think dangerous. I think it's in, in this, it's talking to the two of you.
This is cliche to say like, it's become such a massive business that I don't really, I think it's a distraction to think about. Like, has it gotten, you know, more prevalent or the same or less, like it's a, or a just a staggering, uh, danger and, and a costly one. I mean, it, it, it, you know, it impacts business from a cost perspective.
You know, we've all read, uh, you know, or, or even some of us, like work directly with, you know, healthcare organizations where, you know, it's patients that, that they're, they're working with, it's government institutions trying to serve their citizens that are impacted by this sort of thing. So it's, it's, it's like a massive business. And I think, to me, that's the, the biggest one.
So regardless, like what the trend is, it's, there's no future where it's going away or, or, you know, diminishing to any kind of significant degree. And I think, Steven, you're right, it's just, it's, it's getting smarter, I think the iterations with which, um, kinda adversarial, uh, or, or just kind of either hackers or usually it's, you know, organizations can just put out a text like it's a business. Um, I think that's the part that is the most just daunting and challenging.
It's just moving so fast. And I think AI allows them to do it that much more adeptly. And I think you can have people who are, you know, even organizations that are pretty good, all of a sudden get really great and they tend to be able to move faster anyway.
And so to now have a set of tools that allows them to, um, you know, often outpace the people that they're trying to, um, get leverage against and, and hold for ransom. I I think that's the daunting, the, the most daunting thing. I think that's the way to look at it too.
This is not like the hackers and the hoodies, like the whole crazy way they display hackers, it's businesses, it's, it's a business and it's nation states doing it as well. So the, the, the money that they can't get other ways, they're able to get it from ransom. So they're definitely using every tool they can to number one, build the tools.
And they're using, they're using generative AI to write the code, and they're using, they're using it to market. They're using all the tools we use to make sure people hear about the products. They're like, we're gonna make our product really awesome, and we're gonna make sure you hear about it and use it whether you like it or not.
So it, it's not, you know, like script kitties, like we used to always think this is literally well organized businesses that want to be well funded, and it's really easy for them, them to get funded because of the nature of ransomware if they don't have protection. Yeah, that's, that's a really interesting point. Like Tim said, I mean, this is, these, these are basically businesses now, uh, they're illegal businesses, but they're businesses.
And so by, uh, whether they're funded by nation states or funded by ransomware payments, they have a huge amount of power, a huge amount of money. Um, they've got this incredible technology in their hands. I mean, Jeannie, you, you know, as you say, a lot of them are using, uh, generative AI to write code as well as to, to write text.
Um, you know, we have a whole new world now of, uh, very, very convincing generated video and audio. Uh, I know that we've all heard, uh, stories of, you know, ransomware attacks that, uh, appear to be legitimate employees on a zoom call and things like that. I mean, this stuff is just wild.
And I think that basically, you know, we have to move on from this idea that somehow we're gonna squash this before it happens, and we have to move to the idea of what do we do when it happens? Because I just don't think we can stuff this genie into the bottle. There's too much money at stake.
It's not going back. You have to protect yourself and have a way to recover. You have to, it's gonna happen.
Yeah. And I think the whole notion of yeah, like stuffing the genie in the bottle, I, I think the thing that, kind of back to your, one of your original questions, Steven, is just, you know, that the connection of AI and the impact that it's having on, on resilience is not only like, we can't stuff the genie in the back, in the bottle, but the, the pace of change that AI is bringing is so dramatic. I at least it's the fastest and most impactful thing I've seen in, in my tech career.
I mean, there's, there are analogs to I think the cloud world. I, I see things like, you remember in the early days before, like the, um, kinda shared responsibility model was really something that was wholeheartedly, you know, articulated, understood, practiced, and it's kind of who owns which piece. I mean, I think it's a similar thing here in this, this AI world, and it's, it's moving so fast that as org every organization that I've talked to recently is doing something there, and many of 'em are doing real stuff, but they're like, Hey, look, I was talking to a CISO the other day.
He is like, we use Zendesk for these sorts of things. And, you know, we understand how to make that resilient, but they're using, you know, what about the supply chain of what they're using? Where does our accountability go?
How far does it reach into the LLMs and the, the way that they're, they're training stuff, and where does that line stop? And I think there's a whole set of questions around those kinds of practices that are being entertained now, don't have clear answers, and the pace is moving so fast that it's, you know, I think, you know, people are, are trying to keep up, but it, I think that's the part that's, that's not, it's like the genius outta the bottle and watch out because, you know, it's coming really quickly at you. I think that's a really interesting point too, because, um, PE businesses wanna move ahead and it's obvious that AI is the next round of, of innovation for computer science.
So they want to move ahead, but everything's coming so fast. Everything all at once, right? How do you, can you, you still have to maintain that data center hygiene and keep everything protected and, and do that side of the business and, and how do you do that protection and, and how do you know where to go?
Where do you put your funds to actually do more than what you've been doing and, and, and use AI to get you to the next level? Yeah. And I think to me, that that's the biggest tension that I see with the customers that, that I'm working with in that kir, to your point, Gina, that some of the, the practices that they're putting in place to protect their data, um, even basic ones, things like, you know, air gapping with immutable and indelible copies of your, of your critical data.
Things like, um, some sort of practices, processes, technology for identifying clean points to, you know, to recover too. You know, Stephen, as we were kind of prepping for this to, you know, just talking about like, Hey, how far do you, you roll back certain sets of data? Like, so having a process around what that looks like.
Things like, are you class, you know, discovering and classifying your data? You can't do rag if you don't what your, what your data is where, you know, like, you know, and, and, um, and, and I think basics like that are still being implemented, let alone more advanced technologies or, or capabilities like, Hey, I wanna use the cloud to burst into isolated clean rooms for forensics or something like that. Just the basics are still being put in place, at least broadly.
And, and now just this rapid progression of ai. The, the, to me, the heartening thing though is thing, the organizations that I am, I am, that I'm, that I've been working with, is just, they're, um, kind of delightfully a bit more progressive than I would've thought on, you know, who's involved or how many app, you know, kind of AI driven applications they have in production. And even when they're, they're moving forward with almost like this blind urgency, uh, and kind of prioritizing learning and, and growth over kind of the guardrails.
They, uh, I feel like at least some of the proper guardrails are starting to get it put in place. And the ones that aren't, they know what they are. Like Gina Deer point, they're like, yeah, we know that the right hygiene looks like this for our established workloads and, you know, but we're three months out on that for this project, or six months out.
So, uh, maybe it's the eternal optimist in me, but I, I at least feel like people know what they should be doing soon for those workloads. Yeah. It's not all doom and gloom too, that's the thing.
So, I mean, AI is also a very powerful tool for data classification and for, you know, detecting, uh, attacks as well. And I think that that's all something, I think that, that gets lost sometimes. 'cause we're very scared of ransomware tax.
I mean, I, I am, you know, as a business person, uh, I am as a professional worried about what the impact of these things are. But there is some reason to be optimistic that companies are, you know, kind of getting their act together in terms of data classification, in terms of implementing, uh, good strategies around data protection and that that the tools are advancing as well. I mean, one of the coolest things out there, and, and it's funny because it's not really a new idea, but it found new impetus, is this idea that you can have, uh, almost real time data protection.
And you have that kind of virtual dial where you can sort of go back and say, well, the ransom attack happened here, so I want my data set to go back to right before that. And there again, I don't want it to sound too much like an ad for Commvault products, 'cause I know that you guys have stuff that does that. But you know, that's a pretty powerful tool and something that has finally found some currency in here.
And the same is true as you point out of tools that allow you to, um, organize and classify and categorize data to replicate data to different locations, to burst between locations. A lot of this has been something that we in the industry have been building to for a long time, but here it is, and it's actually important, more important than ever when you're talking about these data-driven applications. Yeah, I think you bring up like a, one of the kind of current hot topics, I'd say in a lot of discussions with our customers at least, that are, that kind of are, uh, running their applications regardless if they're like AI driven or not, but on the ai sort of like maybe typical underpinning, so some of the larger, you know, uh, like data structures like, uh, you know, S3 or, or something like that in that, um, there's this combination that I think technology has gotten great at helping provide, which is not only being able to recover at just ridiculously massive scale and doing it really fast, but then Steven, you kind of suggest these, like what we, we call like micro recoveries.
It's just these like kind of near real time. They're, you know, they push out, especially in cloud native apps, they're, you know, as, as, as updates are being pushed out and all of a sudden something gets corrupted or, or clobbered to being able to just have these kinda micro recoveries. I think spanning that gamut is, is I think, a key new requirement for resilience.
And so, you know, you, uh, I appreciate you kind of given a nod to us, but you know, I'm biased kinda working for Commvault. You're right. Like we have some of our, our capabilities that we have there are just really well suited to cover that, that broad swath of recovery from just the super massive, you know, billions of objects in, you know, record time to these kind of micro recoveries where you're just kind of backtracking to some subset of your, your data state too, to a form point in time.
And again, in close to real time. To me, it seems like this, this whole period seems more to me, like when Linux came out, that's, that's when I experienced this much disruption. So with you saying that, Tim, one of the things, we're talking a lot about the production applications, but when things are in development, it seems like having that resilience to roll back exactly where you need is important too.
Especially with ai, when you've got so much time that you're spending on, um, doing some of, especially the inference training or, or whatever you may be doing in your organization, and having several people going at copies of the same data at one time, it seems like there's a great need to, um, to have a place to roll back to. So those experiments don't take longer than they need to. I think that's a good par, like kinda a good parallel, or like the, you know, the, the way you mentioned Linux, I think the trend that, that I see is that, I know I don't wanna diminish the importance of kind of on-prem disaster recovery or like, you know, kind of disaster recovery with traditional or operational recovery with traditional packaged applications.
But it's largely a solved problem, like in, in an on-prem world, you know, most, most customers I talk to, like, if it's not, I mean, it's pretty much real time or near, like, they're flipping over from one site to another. Like they just got that lick. They, they're doing testing.
It's, it's a really rigorous, well established process that's not true in the cloud. These operational outages are still an unsolved problem. Um, so, you know, they have cyber and operational recoveries to kind of deal with, and I think you're spot on is that this, this notion of, you know, in development, like, whoa, we just, we just updated a whole bunch of stuff.
You know, it, it might be they're pushing out a, you know, new build of, some of the services might even just be new, you know, or infrastructure updates. And like, we need, we need to rewind that part. Like something didn't go right there and it, and it's not a, an attack necessarily, it's, it's just a, some, you know, something doesn't match what they expected.
And that's, I think that's a still like a largely unsolved problem in the cloud. And I think that comes back to, I keep, I always just have been using, like this meteor analogy is as people get that hygiene in place, you know, then like, here comes AI to just, you know, put the additional pressure on. And I think that's the, just the massive strain that, that I see within the conversations we have with our customer base.
Yeah. I'm interested in hearing more about sort of what the real world looks like out there. I know that you guys are talking to customers all the time.
I've run into those customers, uh, you know, at events, um, certainly at Commvault shift. Um, what are they saying is the real world of that sort of interplay between AI and data protection? I think there's a couple things.
I think, um, on the fir like it's, it's almost like two sides of a coin is where I spend most of my time talking with our customers. On the one side of it is, how do we make, you know, these new AI stacks, the new data, you know, formats and things like that, how do we make that resilient? And so this may be things like, you know, it's iceberg or, you know, S3 tables or, you know, Postgres with vector support, you know, so they, they wanna make sure that the, the, um, kind of data stores are something that they can protect and it, and have adhere to their, the policies that they have in place for governance, resilience for all their established workloads.
So I think that's one of the places where AI intersects, and it's where they look to Commvault to help them protect that data that's ma being made ready for ai. And then the AI generated data. That's, that's kind of coming out of that.
The other side of the coin is how do I use AI to be better at the resilience practices that I put in place? And Steven, you already kind of alluded to some of this, which is, you know, using ai, I mean, it's great at pattern of recognition, right? So like, uh, what about things like anomalies and, you know, detecting those and threat hunting and, you know, helping people find, um, we use it as part of our platform for our customers to, to help identify these clean points, to recover to, or to help, uh, see malicious activities that are otherwise really hard to detect if you're, you know, a human trying to, to compare this sort of stuff.
For sure. So I think, uh, you know, on the one side it's, um, making your data and your, especially your ai, you know, ready data resilient, and then the auto or, you know, the AI generated data making that resilient. And then the other side is just using AI to improve your, um, efficacy of your resilience practices.
How does that strike you, Gina? Again, you're kind of coming from the, uh, customer perspective as well, and from the, the world of, of, of, I guess, uh, tech skepticism generally. Um, does this, does this ring a bell for you?
No, I think it's, I think it's been happening for a long time, though, um, within, uh, I think you guys have had some machine learning, right? For a long time and, you know, and so, uh, that's helped that this is not, it's not a new practice, you know, and it's not something new to people have been thinking about. They've been trying to figure out, okay, this seems like if we use machine learning on this, we could get it to go really fast.
Um, and I think it is very true. I think the other thing is you, the people that are doing security and people that are doing, um, the operational piece, which is usually data protection, I think those teams are probably melting into each other a little bit. And I think there's not a lot of people doing it for the amount of a meteor coming at them and smashing them with AI driven ransomware.
So, um, you know, we already know that knocking on the door and getting in is the har is one of the hardest things for the ransomware companies. I'm just gonna call 'em that they're using AI to get better at it, but once they get in, it's really, really hard to detect it unless you've got these tools set up watching for it, even if you're been in the business 30 years. Because I mean, I remember being assistant man and having little scripts that I would run every morning just to see, and I'd have things set up and we could see when things were happening, but I, you know, it's a horrible feeling to know somebody's dropped a root kit on your, one of your systems and you've been watching for it for, you know, years.
So, um, yeah, you have to have, you have to fight fire with fire. And it's not like, you know, it's not like it was 20 years ago. It's, it's, it's all evolved and it's very, you've got companies trying to infect you and hold your, your data for ransom.
So, and they're using AI to get there, so you've got to use fire with fire, I think. Yep. Well said.
And I think that that's exactly what we're hearing from some of these leading companies. I mean, when we are at events, uh, with Tech Field Day, um, one of the things that I'm always listening for when companies start talking about, oh, AI is in our product, you know, the thing I'm always listening for is what are you actually doing with it that's productive? And I love it when I hear companies talk about how they're using, you know, generative AI to monitor, um, you know, massive quantities of data to find anomalies and patterns in that data when they're using AI to, uh, classify and organize and tag data when they're using AI to, as Gina is saying, fight fire with fire.
Um, I think that that's great. Um, if, if their answer is, yeah, we've got a little, uh, chatbot down on the corner that can talk to you, well, that's, uh, I don't wanna say it's bad, but it's a little less great use of this technology because, you know, it has a lot of potential and it has a lot of use cases. And, um, we can have, you know, small specific models that do specific things.
And of course, we also have to think about this rise of agentic AI and giving AI applications autonomy and a chain of thought process. Uh, by the way, quick plug, that's what we're talking about on this season of utilizing Tech, which, uh, will have just launched. Uh, that's our, our other tech field, a podcast.
Uh, we're talking about agent ai, and, um, I think that that really is going to be opening up a whole other can of worms, uh, good worms and bad worms. So I, I guess to, to sum up Tim, um, tell us a little bit more about the state of the industry and the state of Commvault and what we could expect at Commvault shift here, uh, in November. So I think, uh, I think it'll come back to some of the points we talked, uh, about earlier, which is I think from a, the state of the industry perspective is the impact that AI is having on, you know, the market.
And surely our customer base is not only massive, just, but moving at an unprecedented rate. And so, um, what you should expect it shift is, um, uh, a, a a broad set of, um, you know, presentations, topics, discussions, demonstrations. We have a, a great both, um, for those who are joining in person in New York, um, November, um, uh, uh, 11th through 13th is we have a set of, you know, breakout sessions, um, all will have, you know, demonstrations of some of these technologies.
And then we have a virtual track, and the topics are going to be around as organizations, um, scale their success with ai, how does Commvault help them bring those workloads, kind of protect those with the sorts of governance, uh, control policy monitoring and enforcement that they have, uh, come to get great at, uh, for the all their established workloads. And then on the other side, how does Commvault help them use AI to be great at their resilience operations? I think that sounds really exciting.
I think it's a really important message and, um, I know with the demos and stuff, you're gonna show people how to do it, so that's always the best. Yeah, Gina, absolutely. I'm, I'm with you.
I can't wait to see what, uh, Commvault has in store at shift. And, um, definitely we'll be continuing to follow this here on the tech field, a podcast as well as on our utilizing Tech podcast. So thank you both for joining us for this episode of the Tech Field Day podcast, focused on the connection and interplay between AI and data protection.
Before we go, uh, where can we continue this conversation? Uh, Gina, Uh, the best place for me is probably LinkedIn, um, and you can search for Gina Rosenthal, and you'll find me. I'd love to talk to you.
Excellent. And, uh, Tim, uh, where can we continue this conversation with you? Same thing.
I'm Tim Zonca, uh, on LinkedIn. You could find me there if you wanted to DM me, but also, uh, for those of us that wanna hear more, uh, get some hands on experience, see some of what we talked about live, either join us in New York City, November 11th through 13th at our shift event, or do it online. And you can, uh, join straight from your desk with good cup of coffee and see the same sorts of things.
So thanks Steven, and good to get, get a chance to talk to you, Gina. Yeah, absolutely. And we'll be, uh, covering shift on the tech field day channels, uh, YouTube, our social media, and of course on LinkedIn, where you'll find me as Steven FoST.
Also, as I mentioned, uh, we have just launched our next season of utilizing Tech, which is focused on a agentic AI and features, uh, friend of the podcast, Frederick Van Herrin and Guy Courier as co-hosts. We've also just launched another podcast that's gonna be relevant to this audience, uh, security Boulevard, which is in concert with our sister website, security Boulevard. Uh, there you'll find, uh, familiar faces, Tom Hollingsworth, uh, Mitch Ashley, along with, uh, folks, uh, like, uh, Fernando Montenegro and Alan Shimmel talking, uh, data security.
So check those out in your favorite podcast feed. Thank you very much for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please do subscribe.
You'll find us on YouTube as well as in your favorite podcast application. I use Overcast. So, uh, don't miss an episode.
Also, please consider giving us a rating in a nice review. We love to hear from you. This podcast is brought to you by Commvault.
This episode is, uh, as well as Tech Field Day Home of IT experts from across the enterprise, which is part of the Futureum Group. com/podcast. You'll also find us on Textron TV and in our over the top applications.
Thank you very much, uh, for listening, and we will catch you next week. All right, uh, uh, alright. So what I'll do is basically, uh, through demo show what Gideon and Scott just talked through, right?
So, uh, what you're looking at here is the unified console. I think if you recall the first slide that Gideon showed you, uh, he showed you how in the Defender console, this is a defender console. We have brought together everything that a SOC practitioner needs, right?
If we all remember days of civil chairs, where we used to have multiple portals that a security analyst, whether you were trying to understand an email incident or looking at a malware event, or trying to figure out what's was happening in your identity space on trying to connect that to, you know, what might be happening in your cloud infrastructure. What we have done is basically brought all those different consoles into one place. So this is the one place, if you're in the Microsoft ecosystem, this is a one place stop shop for you if you're a security practitioner to take care of, whether you're looking at, you know, identities, your endpoints, you know, events that might be generated inside your, uh, even environment.
And then being able to connect that to your SaaS applications, your cloud infrastructure, you know, everything from configuring policies, uh, security policies for these different workloads, or being then be able to do security investigation and response. So it's truly a cross domain, uh, offering. And the reason we are doing that is because, you know, as Gideon Ventures and you know, attackers think in graphs, if they're not really attacking just your endpoint or just your email or just your cloud infrastructure, they are gonna attack any part of your infrastructure, of your digital estate and pivot into it, or from one, from one node to another node till they can get to your crown jewels and, you know, either ransom view or extort you or steal the information that thereafter.
So with that in mind, you're really invested in what is our XDR offering, brought all these different domains together. So now you can do cross domain both protection on the pre breach side, and then do investigation respond hunts across all these domains. The first thing I wanna show you in this is, you know, our exposure management capability, and this is the first place where graph starts to show up.
So one of the questions that, uh, I believe Romeo you were asking was, you know, uh, why is this? Like, once you understand the connections between all the assets in the, in the environment, graphs can help us quickly prioritize, you know, what is the first vulnerability I need to patch? So this will expose through our exposure manager module inside defender.
And so over here, what I'm gonna look at is there's an, there's an, um, internet exposed, uh, uh, container, but that has an attack part that takes to, um, a storage account that is storing critical, uh, data that I'm using for AI training, right? So because I have this underlying graph, so this graph is powered, uh, by the central graph that Gideon showed you. So that graph becomes a fundamental data structure in the platform that is now powering different security outcomes.
In this case, I am doing essentially a posture assessment, and I figured out there's an internet exposed container that can lead to a possible breach. So if I, so, uh, so the action here, uh, it would be, it kind of clearly describes what the tax story is and then gives me a recommendation of, you know, what I need to do, which is basically, you know, I, you know, put this behind a firewall, you know, put this behind a bastion access so you're not having directly exposed containers to the internet. Alright, so that was the case where it's, you know, pre breach, hopefully, you know, the, as as customers we focus on, you know, good hygiene, we reduce, uh, overprivileged, uh, exposed nodes.
We patch our servers on time, we reduce access so that our environments are locked down. Uh, but we know that, you know, sometimes there'll be vulnerabilities, there'll be zero days and, and you know, things will get in. And that's where, as a SOC analyst, you need to be able to quickly look at what's happening in environment, be able to quickly prioritize them and be able to do investigation and response capabilities.
So what you're looking at here is the unified incident queue. Um, and this can, this will show you incidents both from Microsoft specific, uh, detection services, but also from third party capabilities that, you know, I think, uh, somebody was talking about Okta, et cetera. Like you could have detections on data that was brought into Sentinel, say from Okta or AWS or, you know, CrowdStrike, and then those incidents would show up here.
Uh, one thing that, um, Scott referenced was, Hey, we can actually, we're not only looking at, you know, one incident at a time. Uh, we can correlate alerts from different parts of your, uh, environment and stitch that into an incident. Like, so what does it mean is, you know, one of the challenges SOC teams have had for a long time is, you know, alert noise or alert fatigue.
And the reason for that was, you know, we would fire alerts, uh, or different systems would fire alerts at a point level, and you could not connect them together to get to an end-to-end story. So what incidents, uh, capability and defender and Central do is we look at events and alerts that are happening maybe at different points in time across different systems, and be able to correlate them into one Uber story. So as a SOC analyst, you know exactly what's going on, so you can prioritize your investigation and response.
So if I was double clicking to one of these incidents, this is what it would look like. So there are three alerts that are fired in this case in the Azure environment. And again, using the part of the graph, I've stitched them into a story so I can know exactly what's happening, you know, which IP address was used to log into which user account, and then subsequently what, what other things happened.
And the other thing that we have now done is basically add this notion of a blast radio. So I can quickly see, you know, if this person was to get compromised, where would the attacker go next? So if this, uh, this will render in a second, and that then helps me prioritize this is the blast release capability that, uh, uh, uh, that Gian talked about.
So I can now see that, you know, if this user was to get compromised as an attack pod that goes into, uh, this virtual machine in Azure, and if this is critical, then I can now use that information to prioritize the response steps that I wanna take. Uh, quick question, Abha, how do you determine, like I am, I am, I'm sure users who have 52 have access to more than one machine in one container, right? How do you calculate what the blast rate is for this event is right in the context of here, you just show me two.
Yeah, right. So in this, yeah, excellent. So in this demo, this is a demo environment.
Obviously, you know, this demo, uh, this person only had two, but imagine they had more, right? So behind the sea, what's happening on, at the technical level is, you know, uh, as assets are changing the environment, you know, we are computing the relationships between this user and any other asset. So for example, we are looking at the permission set that they might have on entra.
So, so will the incident view show me two or will the incident, the, the two assets I have access to, or will the, the blast radius view show me 5,000? So, so excellent question. So we will show you, I mean, there's two parts.
So the system can calculate 5,000. We will take a subset of that and show you in the graph and, but we'll let you expand, right? So this is about, you know, managing the real estate.
So you focus on the first n hops first, but then from there you can expand and get to 5,000 System. How do you choose which one? 5,000?
Yeah. How do you choose which ones you show me? We look at the number of hops, so we are looking at few things.
We're looking at, you know, what are the parts to critical assets. One of the things you can do in defender is tag your critical assets, right? Some will be system defined.
For example, a domain admin is a critical asset, right? A subscription owner is a critical asset. An M 365 global admin is a critical asset.
So anything that leads to an escalation path to those critical assets, you know, those would be automatically shown. And then if your, if your, if, if your blast radius goes beyond n hops, then we will basically, you know, I think we use seven hops to say, okay, what are the parts from this user up to seven? And then from there will you can, you can re-expand and so they can get to the fullness of your, um, of your graph.
Okay. I'm just confused about like the, the, the, the, the demo environment is, is very limited in, like, I don't get the view of, of what it looks like in real life, What, what it look like. Yeah, I, I, uh, uh, act, act on that feedback.
Uh, I'll see if you can find like a more complex demo and send it offline. Thank You. Aish, if I may ask the question?
Yeah, please. What's the bare minimum work, um, an enterprise needs to undertake to leverage, uh, this cap graph capability? Yeah, so if they turn on, um, es es essentially, you know, the Sentinel Lake and graph capabilities, like basically it's, it's literally one click in the portal, right?
So, you know, uh, they'll get a banner, I think in, uh, in, in the portal. They just click on that. Once, once the underlying lake and the grop engines are enabled, then these, these features start to light up, right?
Um, there's obviously a, a, a boot up time because we need to, you know, assess the environment for the first, uh, day, uh, look at, you know, all your assets and activity and start stitching to the graph. But once that is done, then then this, this, these capabilities slide up in different particular in the book. Okay.
Thank you. Alright, great questions folks. Alright, so I have a Yeah, go ahead.
Sorry, just a sort of related to that, I, I have a somewhat tongue in cheek question. Um, the, the graph showing the potential blast radius and, and sort of the incident, I think I asked this question on a previous, uh, Microsoft security briefing, so it can show me like, this is an incident that has happened, it shows me after the fact. You can also sort of show me this is what I predict is likely to occur.
Yes. Yeah. Yes.
Can, can that, uh, that's quite useful for an analyst perspective. Can it kind of generate a report that you can then provide to the executive, for example, to explain to them what happens when they say that they accept the risk, uh, so that I can keep that in a draw for the, uh, for when the investigators come from the regulator or, or something else after the incident does actually occur? Um, yeah, that I'm, I'm thinking of this, it, it could be a very useful way to actually motivate, um, spend and budget to actually fix some of these issues.
Excellent feedback. Excellent question. So this example that I showed you before was exactly that.
So this is before a breach has happened. This is just pointing out what, where the risks in your environment are, right? And then you can export this, you could save this.
And so at any point if later on in the, in the organization lifecycle this, this service was to get compromised and it was because this was exposed to the internet, you can go back and show the audit report to say, Hey, you know, this was flag previously, you know, for whatever reason the business group accepted the risk. Uh, and now look, you know, it's part of an incident. So yes, this, this, that information that exists in the system and can be exported out.
Yeah, it's, it's sort of a variation of what you've got there, I think, for the attack story. So being able to surface that like a hybrid between that and the prioritization for like incident break fix, yeah. Um, that would be quite useful as a way particularly just to accelerate the report of like, I need to generate a summary of here is what the, the work plan that we would like to have for the next quarter in, in language that is easier for non-specialists to understand at the moment that, that actually is quite challenging to do.
Uh, and, and it, as you say here is like, particularly when there's a lot going on, showing it in a prioritization way that is easy for non-specialists to understand, yes, that can then be attached to a budget line item would be really handy. Excellent feedback there. And in fact, you know, I don't have that in the demo today, but, you know, one of the things you can do is because this, this graph and, and the capabilities of accessing graph will be exposed to the M CT server, you can now have imagine an AI is basically going through all of this and generating a, you know, very simplified, prioritized report for the business groups to say, Hey, this is what happens when you choose not to say, patch this device or change the configuration on the storage account, or, you know, reduce the access on this, uh, on this user.
Uh, and that, and, and explain what the impact could be if any of those were exported. Yeah, I, I'm a little bit sensitive to the, uh, to the potential for generating like something which is a bit wrong or, or slightly misleading from LNS because a lot of this is quite templated and, and fairly standardized. So I'm hoping that that variation would be fairly low, but it would be great to have, uh, just like the standard summary thing of like, what we have for this is what the incident means, or this is what the risk, uh, what the risk means for our environment.
Having that to be quite a reliable thing, just be partly because that means that there's less for me to have to go through and then manually check and go and look into the data myself to make sure that I'm actually not misleading the board. Um, was if I pre, if I present that sort of thing in board papers, uh, I, I will do that precisely once, uh, before I will be, uh, finding somewhere else to, uh, try this again. No e excellent feedback.
Uh, I think all the building blocks exist, uh, in the product, uh, and that, that report generation can easily be built in a templated format so that you are, you know, very prescriptive, very precise in terms of the risk and what happens when you accept or, you know, choose not to fix the risk. Yeah. If and if it could, like if you can link into some pricing information somehow and just have that to start, like pre-fill in or just get your start or budget Yeah.
Like you can, That would be amazing. Yeah. Great, great, great discussion.
I would love to have continue that, that, uh, I have a question as well, um, uh, context wise. So, um, my thoughts were just triggered by you just initially is, is putting in context into our environment. So I'm assuming there's a way I could say, these are the critical assets, therefore I wanna prioritize them above the same asset.
That's not a critical asset as well as here's a recommendation, this is your risk. You've had x amount of incidents that took this exact path already. Is there any context setting there as well?
Is that, do you get what I'm asking? Um, if you might repeat the, the first part again. So yes, we can tag all critical assets, right?
And that helps you prioritize, right? So, uh, like which vulnerability or misconfiguration or oversharing you need to fix first, right? And I think in this example, we are showing you choke points, right?
So these resources are things through which multiple attack parts are going to these critical targets, right? So that helps you prioritize your, uh, your response. And then if you have seen one of those being ac i, I guess your question was if you have seen one of those being played out in a previous incident, then you use that information to prioritize your subsequent Yeah.
Like, like, 'cause I, I can give examples to senior leadership and say, you know, this is a huge risk, and they can still say, I accept that risk, but if I've got an easy to generate reso, um, report that says you've accepted that risk X amount of times that have led to this amount of incidents. Yeah. Um, again, great feedback.
You don't have that out of the box, but again, the APIs and the data in the system, uh, in the platform exists and, you know, that would be a great tool that somebody can build on top of this to kind of do that, you know, basically a backward audit and say how many times have the risk that you've accepted, led to a, uh, uh, to an incident. Uh, and then, you know, from there you come up with some sort of a cost metric or a, you know, uh, uh, that's kind of a decision framework for that. Uh, I think that would be great tool and let's talk to this.
All right, so let me, uh, move forward in the demo flow here. Um, uh, so one of the things that we let any, uh, any, so team do they have hunting teams, you know, people wanna be able to get into the data, and this is where, you know, the, the data lake and some of the capabilities, data lake starts to show up further. So what you're seeing here is advance on thing.
This is a KP defender and central I've had for, uh, many years. So here you are querying essentially the analytics tier. Um, so this is where you would have your 30 days data.
In this case, I'm looking for, you know, uh, a password spray attempt or an unusual sign event in my, in my environment and see, you know, where different, uh, login events have been, um, uh, happening from, right? So again, you know, all the different tables, uh, uh, that you get from either defender or sentinel are available here. And you can use Costco.
Costo is, uh, a very popular query language in the Microsoft ecosystem. Um, you know, uh, uh, it, it enables you to do very fast searches on top of, uh, various data so you can quickly hunt and pivot for, uh, enormous activities in your environment. Uh, the new thing that I was showing was this is new.
The capability, uh, that GI referred to is now you can also use graphs to start doing your hunt. So there's a bunch of predefined scenarios and look at now one of the parts that take to say a key vault or to a, a user access sensor data. And then you get to this graph view, and from there you can start assessing, well, this is a key vault, uh, but we find that, you know, Laura has access to this.
So, so the, the, the, the question you can gonna ask is, what happens if, and let's assume Laura doesn't have MFA setup or is not using, you know, uh, um, password, its authentication. So if Laura was to get compromised, then, you know, the attacker would get access to this key vault, and from there they would get access to whatever the, the access that this key vault was, was enabling, right? So you can start doing, uh, I, I call this posture hunting, right?
So typically hunting has been in the, you know, once a breach has happened, you're trying to find where the attacker is and where are they going next. But with this you cannot do posture hunting to basically start exploring where do you have exposed nodes, where do you have overprivileged access, et cetera. And then use that to drive further hygiene in your organization To pick on the, what I mentioned before, uh, looks very clean in a demo data set like you have here.
What does this look like in production? Because a lot more people than war have access to, uh, likely have access to that resource. So what kind of preemptive, uh, optimization are you able to do to help me and my team focus on people that needs to be focused on?
Yeah. Um, uh, ferdo, uh, excellent question. So, so few things, let just kind of talk what's happening behind the scenes, right?
So, uh, behind the scene we have the lake where all the data is, uh, is being organized, right? That is being used to cook these, these graphs that's being loaded into a scale out graph engine and from where these experiences are being served, right? So we obviously wanna look at the, the practitioner we wanna focus on, you know, how many hops they're looking at at one time so they can really focus their investigation and analysis time.
So we control that by the number of hops that we render at a time. Uh, we really focus on critical assets and, you know, parts that are leading to critical assets. But then you have the opportunity to expand the graph and get into diff different parts of the, uh, of the visualizations.
And this allows us to make sure that experience is fluid enough, why allowing you to get to even complex portions in terms of the total size of the data you that you wanna load into your experience. Perfect, thanks. Alright, so, um, so we talked about, you know, uh, our unified console, we showed you the exposure management, we showed you investigations and hunting.
Uh, I think there was a question earlier saying, okay, you know, are you really about the Microsoft ecosystem or can you get broader, right? And this is where the connectors that Scott and Gideon referred to, uh, comes into picture. So we have, uh, uh, you know, over 350 different connectors.
In this case, I think there was a question about, Hey, what happens if you bring in Okta? So we have connectors for Okta, we have connectors for SAP, you know, we have Okta for A-W-S-G-C-P, Zscaler CrowdStrike. So we truly support a hybrid environment, right?
We do understand like security is a team sport and customers will use, you know, different security tools. So we have made sure that all of that data can be brought into Sentinel and not just the data. Uh, we will of course make sure that data gets normalized.
There was a question earlier about normalization. That data gets normalized and then you can do detections and investigation response. So everything I showed you with respect to doing exposure management or doing incident correlation or doing advanced hunting, it works on data from all of these, uh, uh, different data providers, uh, as well.
Uh, uh, so one of the things that, uh, I think there was a question earlier about sys logs and network logs and you know, what happens in terms of, hey, I don't wanna, you know, necessarily bring all of that into my analytics here 'cause I don't really find them, uh, they are high volume or can be pro possibly low fidelity. So the, one of the other things that you can do in this experiences, you have a new table management experience. And in this demo, I'm showing you AWS cloud trail, but this could have been your s logs as well.
You can click on manage tables. And what I have done is basically said, look, all of that data, I want to go into the data lake and I wanted to retain for five years, right? So it's as simple as that.
You know, you don't have to set up any, uh, your DIY infrastructure, you know, or set up anything else, say in Azure or in AWS. It's literally one click for a security, uh, or a SOC architect to decide the layout of what, where they wanna send the data, right? So, um, uh, if, if they wanted to send it to analytics tier, that works as well.
And as Scott mentioned, anything that goes, genetics automatically gets mirrored to the lake. So Lake is always your kind of the full copy of all the data. And, uh, as there was a discussion on, on pricing.
So the way the data lakes architected is it, it decouple from an architecture perspective, and that's why I like to use the word modern lake. Um, it is separate storage and separate compute pricing, right? So you can really store high volume data at scale, at really low cost.
You know, we also pass on compress, we compress the data and we pass on the size savings to the customer as well. So Lake really becomes a great place for you to, you know, park all your security data. Um, I have been in the securities domain for, you know, 10 plus years.
I was, you know, uh, running Microsoft's MDR services, uh, before, uh, stepping into this, uh, this team. And the challenge that all security teams have is this un this tension of how much data should I store and how much budget do I have? And the vision for this offering is we, we solve that false choice, right?
All security teams should be able to store all the data, right? And then on even the need, you know, hopefully they never need it, but when they need, the data is ready to be analyzed in multiple ways. That enables them, the security outcomes that they, that they wanna achieve.
Had a quick question. I wonder if, um, there is a possibility to take a look at maybe compliance from a perspective of, let's say P-C-I-D-S-S, um, and storing the data for a year. You have to store it for a d for a year.
Can you apply that to, um, a setting or configuration where it automatically identifies those devices and then configures this to store the data in the data lake for a year? Wow, omi, brilliant idea. Um, you know, great feedback.
We don't have that obviously right now, but, uh, you know, just, just amazing, amazing feedback. I'm sure there's a way to script this and, uh, you know, like, you know, tag your devices and save a part of like a, uh, a specific kind of processing and make sure those logs are active. Okay?
We showed you the connector. So the fun part of the lake is, you know, you can actually analyze it in multiple ways, right? So when you, when you choose the connector and send that data to the lake, right?
What we are doing is we are storing the data in an open format. Um, it's, uh, we store it in Delta parque format. And what that allows us to do is basically run different kinds of analysis engine on top of one copy of data, right?
And that goes back to, you know, why this is, you know, from, from a architecture perspective, a great choice. And again, this is borrowed from what, uh, you know, other products in Microsoft, like Microsoft Fabric, et cetera, are doing, right? So this is kind of the modern lake, uh, design point.
Uh, so, uh, one, one of the things that we can now do on top of the data is imagine you are in, in an incident response or a forensic scenario, or you're trying to do a retro hunt that needs to go back, say a year back, right? So maybe, uh, you know, your local government or the CS a pushed out an advisory, you know, maybe it's, it's about a nation state actor, but you're going back a year to hunt for that. Uh, and now that is just built in inside, inside the sentinel, uh, data Lake Explorer.
So you can just come, uh, it's the same query that I ran before, but that was running for 30 days, uh, in the analytics queue. Now I can run that, uh, you know, going back 365 days and run that in the lake, right? So, very easy for, you know, security teams to start driving insights from the lake.
Now, when you're doing, uh, analysis of a large volumes of data, sometimes you wanna be able to convert them into jobs. Uh, so the lake now supports view viewing you to be able to do batch analysis on top of the data as well. So you can basically with one click convert that query into a job, and then that can be scheduled.
So you can run it, you know, every hour or every night and do aggregations on the data in the lake. And any insights you find, you know, you can promote that, uh, back to your hot tier. A great example of that would be retro threat intelligence hunting, right?
So every day a new, um, TI feed like maybe an I uh, IP address, a domain A URL is being brought into your environment, and you need to match that, you know, going back, say, six months, one year, depending on, you know, whatever your regulatory requirements are, right? So doing that now becomes super easy. You can just schedule a job every night.
You take all the PI data. So I think Gideon showed you the PI data is in the lake as well. You take that, you scan it against all your logs, you know, and then, you know, any hits that you find, you can then promote that into the analytics tier that then becomes part of your regular SOC incident.
Correlation hunting experiences. Okay? So, um, I love gusto.
Costal is great, you know, but sometimes you need, you know, more horsepower. And this is where, you know, uh, on the same data in the lake, you know, we have enabled big data analytics again, out of the box, right? And to enable that, what we have done is basically released a new Microsoft Central extension, uh, that pairs very well, uh, with, you know, GitHub's copilot, uh, extension.
So let me really show you what that looks like, um, for a customer. So what I've done here is install the Microsoft Sentinels vs code extension, right? You can go into the, um, into the GitHub, uh, extension gallery, download this, install it.
Really straightforward. Once you've done that, all you need to do is basically log in into, um, into your, uh, security account. And from there, you know, you get to access the same cables that you were seeing, um, in the portal.
So it's literally, you know, one copy of data that now you have enabled multiple ways to access it. Uh, so what I've done in this, this view is this is literally a, a spark python notebook, uh, that is connecting to the lake, right? And doing a deep analysis on pho attempts in my organization going back over a year, right?
And in this case, it has found all the users that has been targeted, you know, that is sprayed at. And so that's where, you know, risk is possibly floating out, uh, in my environment, right? And again, this notebook can be scheduled as a job as well.
Uh, so in terms of, you know, I think there was a question, uh, earlier about what kind of analytics you can do on the lake. Uh, I would say, you know a lot, right? You can run jobs or, uh, sorry, Fernando, I see this question coming.
No, I'm, I'm very, yeah, I'm, I'm one who ask, uh, where does this run? Yeah. So when we provision the, the central data lake, the entire compute of that is provisioned internally.
So it's a fully SaaS offering. All you're doing is logging into sentinel, you're connecting to the compute environment. So you can select the kernel here.
You if, uh, let me load. So all these are kernels that are available to you out of the box, uh, again, running inside your tenant that we have provision in the backend for you. And once you select the kernel, then when you hit run, it'll run in your managed compute environment.
So This is managed compute. This, this is not like running on some, on some poor laptop just because No, this is managed compute. You know, you can choose between a small cluster or a large cluster, and depending on your job that you can do.
And this is, you know, full, full Python Spice Park. So you get to get all the libraries you can do. Uh, if you're sophisticated, soft teams with data science backgrounds, you can do ML training, you can train your own model, you know, do your more, your own.
And ly detections full power of data analysis now made easily available to every security analyst. And I assume that this, uh, that this compute farms are CPU only. They're not GPU enabled yet.
Currently they're CPU only. Okay, thank you. Yeah.
Alright. So, um, this is a part that I get super excited about is, uh, because this isn't in VS code, you also can wire up the GitHub copilot, right? And in GitHub copilot, you can wire up the MCP servers for Sentinel.
So selected the MCP servers for Sentinel. com/cp. Uh, and you can find it in the documentation.
And once you do that, now you can start asking it fun questions, right? So, um, I use the word vibe hunting or vibe investigation. I'm not sure if it'll catch up or not.
But essentially what I'm doing here is, you know, I just ask a simple question, right? You know, maybe I'm a SOC analyst, I don't quite know what data exists in my lake. I'm gonna ask a question saying, Hey, I'm investigating an incident related to password spray.
Tell me what tables are relevant, right? Um, so the AI will connect to the lake, it'll do a semantic search. So this is where the vector search capabilities start to show up.
Uh, and it'll find basically what tables are relevant for me, and it'll actually tell me, you know, why these are the relevant tables and what are the relevant fields for me, right? So, very easy way to start exploring, or a new way to start exploring, you know, instead of just looking at tables in the schemas in the old way, you can now also start asking questions as to what data exists in my lake and start, uh, you know, start building an notification strategy from there. Alright?
So once, once I've done that, uh, let me then ask you the question saying, okay, let me find signing failures in the last 24 hours, right? So, and can you summarize? So in this case, it'll connect to a different MCP tool.
In this case, it's connecting to, you know, uh, uh, a query tool. So it'll, it'll create the query. It'll run the query, and then essentially start finding, you know, uh, what were the failures and were there any anomalous events, uh, that we're seeing?
So it's already started to find, hey, there's a password indicator related to these, these specific IP addresses, et cetera, right? Again, very easy way for, uh, you know, you to do, you know, vibe, investigation, vibe, hunt, start, start using the power of the lake to start exploring the data, uh, with the CP two. Uh, but sometimes as, as I was showing earlier, I wanna do a long range data analysis over here, right?
So in this case, I'm asking the AI to connect to the lake, generate an Jupyter Notebook file, and generate the piping code to do this full analysis, right? So now I have, I, I did some quick queries, explore the data, but now I'm asking AI to essentially generate, you know, my Python code. And, and as we all know, like one thing AI is really good at these days is generating code.
So we are leveraging that for security operations and analysis as well. And so it goes ahead and does that. And, and so essentially, I was cheating a bit when I showed you this notebook.
This notebook was entirely generated, uh, by, uh, by the GitHub copilot, uh, agent mode. And it is now able to essentially generate the code, do the analysis by easily understanding the data in the lake, and now allowing me to find insights that otherwise I would've had to spend a lot of time, uh, you know, you know, set up the infrastructure, generate this notebook, do this analysis, and now all of this becomes really part of, uh, you know, I did this, uh, uh, on my own and I know I'm not a native Python developer. It took me about couple of hours to be able to connect to the lake, do this analysis, and find insights, uh, in this environment.
Let me pause if there's any questions on what I've showed so far. Yeah, no, I think judge, I, it's just that the, the vibe coding and, and, and yeah, we're, we're still navigating that one. Let's leave it at that.
Yeah, we, we still that, but, uh, I, I, yeah, like, uh, uh, my, uh, if I may, you know, um, uh, I, I, my previous job, I was a developer on the power team. Uh, I hope, you know, people in this audience know what power is. And my learning from that journey was like before PowerShell, you know, IT, operations in Windows used to be click offs, right?
You would go to, uh, MMC console and, you know, you know, load up, uh, a snap in and, you know, you would click around and, and do stuff and PowerShell opened up and revolutionize how, as an IT persona you could upskill yourself and create more value for your organizations through automation, right? Uh, I see, like what I've showed you so far, you know, and, you know, obviously you're still learning what will happen in this, uh, AI era, but I believe there's opportunity for everybody in the SOC team to use these modern tools to upskill themselves and create more value for themselves. We know that every security team is struggling with, you know, uh, uh, talented people and hiring and all of that.
And one way to, you know, address that, uh, that, uh, challenge is, you know, use these modern tools to empower everybody to do more and create more value for their security. Uh, teams Mostly agree. Yeah.
Alright, so, um, switching back. Um, so one of the things that we, uh, that Gide talked about was, uh, security copilot. Um, so, uh, as part of security copilot that we announced on nine 30, um, there's a whole bunch of agents that are now available with security copilot, again, you know, agents both from Microsoft themselves, but also from our rich partners, um, you know, around the globe that is now available that you can now install directly, uh, into a security core environment and start, you know, using the data and the lake and the other analytics engines that we have provided to, you know, find interesting, uh, security outcomes.
com, that is now live and, you know, a great set of solutions from, you know, partners like Illumio are not part of this offering. So, you know, customers can go to the store, acquire their agents and solutions, install it on top of the platform, and when they install it on the platform, it comes with, you know, I, I use the word composite app. It'll have their agent, it'll have their notebook, it'll have the connector that is bringing the lum insights on top and then, you know, uh, bring data analysis and then being able to, you know, generate agent insights on top of that.
Alright, so that was my, uh, kind of planned demo. Uh, I walked you through essentially everything that Vivian and Scott were talking through. We showed you how we have evolved.
Uh, we have brought together all our, uh, you know, sock products into one console. You know, it integrates deeply with Sentinel. Uh, from there it layers into the lake.
And then Lake enables you to do deep, deep analysis, how we have used graph to light up different security outcomes in different places, you know, across pre breach and post-breach, and how we have enabled, uh, you know, AI capabilities to enable, you know, security analysts and agents to derive more insights from the security data. So, uh, slightly challenging question, given this is, this is all based in Azure, is that correct? The backend infrastructure for, you know, all these services is running Azure?
Yes. Yeah. So for, if, if it's quite good, which parts of it look like they are, um, for some organizations they are somewhat reluctant, uh, to put some of their data in the cloud.
Um, uh, is there a way to connect some of this capability to a data lake that isn't in Azure? Can I, can I plug this into other data sources that I perhaps run on self-hosted infrastructure, Uh, not today, um, but, you know, would love to, you know, explore and understand, you know, what those setups are, if this is a regulated scenario, et cetera. Um, so we do have like not specific to this products, like we have, uh, you know, offerings of our cloud capabilities for specific, you know, uh, entities, et cetera.
And so the ask is, Hey, can this be put in a box and made available to those specific entities? Then, um, that is definitely a possibility. But, you know, as what I've demoed so far, it, it currently is running on Azure.
Yeah. And, um, I mean, I'm aware that you do have some, um, some high security, um, presences in, in various nations because there are certain government agencies, for example, that prefer to keep their, uh, their data away from the general public. Um, but it does.
So there, there is essentially a requirement that if you want to take advantage of this, you do need to ingest your data into a cloud system somewhere. How you architect that and how you actually, um, your comfort level for that, where that data is going, um, is something that you'll need to, to go through. Yeah.
Um, and I, there I can see there are some advantages for things like, for example, rag, um, where I can have highly sensitive data sources that I can keep separate, but I can expose them to some of this analysis capability through kind of an arm's length Yeah. Um, way of doing things. So it, if there are some of those capabilities, that's something I'd be interested in learning more about later.
Yeah. But if doesn't sound like wrap Out, there are some capabilities that we are thinking internally or I'm not, uh, you know, allowed to share at this, uh, uh, at this time. Sure.
I'm, I'm sure it's, this is a question that has come up at least once I, I doubt I'm the first person to ask it. Yeah. Uh, stay tuned and I'm sure we'll, you know, share some, some updates shortly.
Okay. Alright. Um, I mean, that's all I had in terms of demos.
I'm happy to take, you know, more questions. Um, Anyone? Sorry, I, I was fiddling with the, with the, the, the audio button here.
Uh, I'd love to understand, like, you've been, you've been evolving the, the, the, the product for a while now. I'd love to understand, what can you share about early experiences or early versions of something that were changed based on design partner alpha customer, beta customer type of input? Like, what has been surprising you about how you thought people were going to deploy this versus how they actually deployed this from your early customers?
Yeah, I think, um, uh, few things that, you know, pop to, to the top is, um, lot of, uh, enterprises are multinational enterprises are multi-tenant organizations. So, you know, uh, uh, as, as an early version of product, you design it for a single tenant, very quickly realize that, you know, not all data is necessarily in one region. It might be spread out in like, and then you, you need to do, uh, access control differently.
You need to do data resiliency differently. So for, for a data product, like, uh, like for a platform like ours, making sure we understand, you know, requirements for, you know, customs in different regions and let them manage them, enforce policies on that was, was one good learning, and we have made sure it's part of our product. Yeah, it ties into, uh, Justin's question just now as well.
So, Yes. Uh, yes. I think one, go ahead.
Yeah, anything else? And particularly on the, on as organizations, maybe like, one of the things I'm poking at is how organizations are actually thinking about more agentic workloads. So anything has popped Up there.
Yeah, so, so couple of, uh, so, uh, one thing is like, you know, um, uh, as Gideon showed earlier, you know, product is, is very successful. We have 25,000 customers worldwide, uh, and we support a range of customers. We support everybody from, you know, you know, customers in the large Fortune 500 bucket all the way to, you know, uh, you know, uh, mid-size customers and everything, uh, in middle.
And so we, we are seeing different customers use this platform for different scenarios. So the first use case really is I think somebody, uh, initially asked with respect to, Hey, how can I optimize the cost of what I need to bring in to manage my sim? Right?
So the first use case is, you know, there's log data sets, you know, maybe assist logs, maybe your network logs, you know, that you necessarily don't analyze on a daily basis. You now have an easy way to park that in the lake, but it's still available for, uh, for rich analysis out of the box, right? So that is, uh, one use case I'm seeing from, from customers, right?
And this was in fact, uh, Gideon referred to the, uh, case study from Nationwide. That's what they, one of the use cases was like, Hey, we remove the false choice of, you know, what to store versus what to pay by enabling them to store that. So that's one use case.
Then we have some customers, um, who are heavy data science, uh, based SOC teams, right? So they take all the data in the lake and they, they have developed their, you know, Python notebooks. They're doing ML training on the data, they're doing anomaly detection, and they're essentially doing those, essentially those insights on top of the lake, asking jobs to find things that are otherwise high to find, like, for example, retro ti hunting or being able to do to beacon detection.
Uh, these, these are really hard problems to do, um, if you were just storing 30 days of data, right? So that's, that's other cost of customers, uh, that we are, uh, seeing. Uh, then on the, on the AI front, we have both partners and customers who are now building copilot agents, uh, that connects to Sentinel, you know, quickly finds insights to complete a very core portion of the workflow.
So these are the three core use cases that we are seeing early customers, uh, latch onto, That was gonna be my next question also, um, around AI agents that are able to resolve some of the, um, alerts or vulnerabilities that are found from a specific path. Sorry, uh, uh, Rumi, if you may, uh, um, repeat or elaborate again? Uh, sure, Sure.
Um, so say we've looked at a specific path that has, um, that has been identified as a risk, is there a possibility to build, I know I've seen, um, SOC agents built to resolve certain things, but is there a way to build a SOC agent that can resolve some of these, um, alerts that have been identified via a path? Uh, yes. It's, it's, it's totally possible, right?
So, um, um, uh, so far what I've seen is, you know, people are a little careful of letting an agent, you know, take an action, like, for example, quarantine a device or, uh, reset a password. But technically it's, it's all possible for, so you can, you know, for example, you found a vulnerability, uh, in a device, can they go ahead and ask, uh, inq agent to say, for example, go patch it technically, you know, those are possible parts. Uh, but we are again, being careful to make sure how we expand into letting, you know, AI take actions in the environment.
So, so like, uh, I would say start with read, triage, analyze, uh, and then graduate to act. Absolutely. Um, Uh, again, as, as gonna make your systems more, more robust.
Yeah. Yeah. I was just curious around that.
Thank you for that. Uh, so is that used in the queries that, that are kind of AI driven to actually set those guardrails to keep it from hallucinating? Yeah.
So, um, in the backend system, you know, when you, when we generate the query, we do have, you know, a bunch of checks and verifier that is happening, um, to make sure we scope down what is being returned so that it, it, it doesn't hallucinate, right? Like, uh, this is an industry-wide challenge, right? And as we all adopt ai, we have to, you know, continuously keep finding, you know, uh, techniques that, you know, reduces, uh, the, the rate of hallucination.
So the accuracy of the responses keeps improving. Uh, but, you know, as, as we've all learned, like dealing with the systems, we have to always keep in mind that, you know, it can sometimes not be accurate. And so we have to continuously either tune the input, tune the prompts, you know, uh, give it the right context, make sure that the, uh, that the, that the data that it's, it's is reasoning over is accurate enough so that it doesn't, you know, make up stuff and, you know, uh, fill with wrong information.