Techstrong TV – October 30, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Wednesday. There's no joy in Mudville tonight.
Mighty Casey is struck out, but it is football season. So let's, let's focus on football. Um, our first story, actually, today's on football.
You're watching Textron Gang. Hey everyone, it's Alan Shimmel. Happy Wednesday, as I said at the opening, no joy in Mudville.
Congratulations to the Dodgers. They certainly seem to be the better team in this route series. Um, but life goes on.
It's the middle of football season, and as they used to say in Brooklyn about them, bums just wait till next year. Uh, we're gonna switch, as I said though, over to football. Our first story today is armed football.
But first, let me introduce you to our gang today. Uh, we've got hardcore gag, you know, we're down to our court here. Let me bring them on.
First of all, you immediately switched from baseball to football, sprouting his, his University of Georgia Bulldog shirt. He's the czar of Silicon Valley, John Schwartz. Hey, John, how are you?
Hey, Alan. You know what? I, I'm holding you out.
Desperate, desperate times. Call for desperate measures. So, I dunno if you can see, There it is.
There it is. They got a chance. They're still breathing.
Hopefully they, they win. But I I, I will hold that hope against all odds, especially against the Dodgers. I would root for a wrong before I root for the Dodgers, by the way.
Anyway, True meaning of a fan, never give up. Speaking of True Fan from ground near ground zero there, well, we're a little north of Ground Zero in the Bronx. Our chief Content Officer, Mike Ard.
Hey, Mike. Hey, we're, we're, we're still holding out out here, man. Yankees, we're gonna four straight, it's been done.
We can make it, man. Okay. None of you believe AWS stats like they have on all those sports things, right?
I never believe those. Um, I think Google, Google Cloud is actually official stats. Oh, it's World Series A Ws, I think it's NFL, Google Cloud might be the MLB.
You're right. Let's move on to Denver, right? The King of Guitars, our CTO, Mitch Ashley.
Hey, Mitch, how are you? Hey, I'm doing really well. You know, if it's any solace, you know, you could be a Rockies fan, just be thankful.
Absolutely. You're in the series, boys. Yeah, that, I guess there is that.
Yeah. Looking for a silver lining, like, you know. Yeah, no, about the buffalo.
They're kicking some butt. They're doing well. Buffalo's doing well.
Yeah. Yeah. Buffalo's doing well, enjoying that.
Anyway, that's a good transition into football. Mitchell. Our first story today, our first article in our first, uh, what we're gonna cover is about the Dallas Cowboys calling an AI audible.
Is, is AI calling the plays now, John? Is, is Google Cloud calling plays? What's going on here?
Well, eventually that might happen. They might actually do, uh, game planning based on AI and tendencies of other teams and their own tendencies. So, yes, I, uh, ran into the Dallas Cowboys.
CIO is a guy named by the name of Matt Messick. And I'm gonna make the argument this guy is probably in as much pressure field job as, as the head coach of the team, who's probably gonna be gone by the end of the year. Um, Matt Messick has been the CIO for a couple of years.
And just to give a little, a little history about the Cowboys, I actually make the argument that they're successful as a tech and marketing company as they are as a sports team. I mean, they haven't been to an NFC Championship in decades, but they are the most valued team according to Forbes, I believe it's about $9 billion. And they're also a pioneer in the use of technology.
Um, dating back to, you can say arguably the sixties, late sixties, early seventies, when they were the first team really to use computers. It was Gil Brand who was called the godfather of modern drafting. He would use computers to find and evaluate players that were nowhere near the radar of other teams.
Now since then, the Cowboys have been working with people like at and t so they've helped develop this 5G network several years ago within their stadium, which is at T Stadium. They've done a lot, a lot of research. They've sent, they sell a lot of merchandise, and they do that basically through technology.
And they look at ai, interestingly enough, Jerry Jones, who's a, who's, who's a marketing genius, I will say that he is a marketing genius. Sayable gm, yes. Market marketing genius.
I see it. I was gonna say one of the worst GMs in history. But he understands the one technology where he's gone to Matt and said, I wanna learn about this.
The only technology is ai. And this sounds, does this sound familiar? Everybody in the Jones family with Jones, the team is pressuring Matt Messick to find out what they can do with AI moving forward.
They want to be the trendsetters because in terms of technology use, they really are among all the teams. The other teams send their CIOs to Frisco, Texas, where the Cowboys are headquartered to find out how they use technology. And what they want to do with AI is they want to use it not only to sell even more merchandise, but they're looking at game planning.
And yes, they are looking at endgame gambling. That is the killer app that they are really interested in. And I think the, obviously the league is interested in gambling, that's their bread and butter.
But the Cowboys see that as an incredible incentive. So anyway, I talked with him and he kind of laid out some of the plans that they're working on. They're a big Cisco user.
They use all the collaborative stuff from Cisco. Cisco just came out with some, a Jet agentic AI offering across their collaboration tools. The Cowboys are embracing it, and it's, it'll be interesting to see how it plays out, because these guys really are the premier team in terms of use technology.
I, I, dating back to my days at Barron's, I would go down there and visit them, and they were showing me the testing of 5G and a lot of this stuff they're working on. So, you know, pro sports, it's very competitive. It's, it's just competitive on the tech side, as it is on the sports side.
So are you saying That we should jump here before I go? Yeah. Mike, Are you saying that we gamblers, I guess, are gonna have to join some sort of AI network to counter this so that we can use AI to win?
Yeah. I mean, how's this playing out in your head? So one of the things that Matt, really, the re the reason why they're obsessed with the 5G network to begin with, and I remember going down there and they were testing it in downtown Dallas.
So at and t is headquartered not too far from at and t Stadium, and they were obsessed with speed in inside the stadium. So one of the things they do now is they do a lot of was That was out Davis, Just speed, baby. Yeah.
So Dal, yeah. With da, yeah, with Dallas, they're obsessed with speed and throughputs and uploading and downloading. So what they want to do is they wanna make it as fast as possible for a myriad of reasons.
But I think the one thing that they are the most obsessed with is creating this opportunity to bet on games inside The stadium, on individual plays. Not just games. Yes, yes.
Play. They play The guy in this stadium to say, third down in five, what are they gonna make it? What are the odds that he passes?
What are the odds that he runs? What are the odds they got the first down? Who's he passing to?
Who's he handing off to? And they want people to bet play by play by play. You need real low latency, high speed to be able to do.
Yes. And they want to be replacing the diamond vision with your handheld, right? You're betting, you're watching the plays, you know, you're, maybe you're watching the football game like this, right?
As much as you are the field. And I think that's actually, oh, sorry, go ahead, Mike. I think the coaches are gonna love this because instead of people screaming for their heads, they'll just say, fire the AI agent.
Well, but you need that AI because to create the, as much as you need speed for the person to be able to make their bet and get it in in time, right? It's 25 second play clock. You need that AI to make the odds in real time as well, right?
For someone to sit and calculate what are the odds of a, a throw versus a run. What are the odds I give it to this guy, not that guy. And also in that same 25 second span, right?
Given all the variables, it's third nine in four, and we're at there 40 and we're trailing by six. This screams for ai when you think about it, right? You're going to need AI to make those odds.
You all, it all makes perfect sense to me because the Cowboys have always been kind of the outlier in the NFL. Remember there was that whole ke Coke sponsorship throughout the NFL. And Jerry Jones wanted to do a deal with Pepsi.
So he was the one renegade who got his way, which led to this, this kind of like more of an open Jerry led, he was one than a renegade. He sued, Yes. Yeah.
He sued the NFL to be able to do his own thing. Now look, he is a master marketer, he's a terrible gm. He, they haven't been in the, you know, at Super Bowl and forever, but terrible gm, but a great marketer.
And, and that's why they're the, the, they have the valuation. They do, right? They're, they fancy themselves.
America's team now. So I, I'm gonna, I'm gonna give you a little, just like a quick context and I'll then I'll head back to you. So I mentioned this company, my full disclosure, my daughter worked for a startup called Venue Next.
They had an affiliation with the Vikings, the 49 ERs, and I think they worked briefly with the Cowboys. And this, this, this startup, which basically burned through its cash and, and crashed and burns. They had this kind of, let's see, about 10 years ago.
Yeah, up about six. It's 10 years ago. They had a, an app that was within the stadium.
And the whole idea is everything goes through your phone, your ticket, your parking, you order from your seats. And I tried it out, it does work. It did work fairly well.
But it was a very limited menu that, that was kind of the beginning of this. You buy merchandise and have it delivered to your seats. And, and so the Cowboys could of picked up on that and they see where all the money's going, right?
com media ops is the C-T-O-C-P-O for Caesars Entertainment. He built their online gambling and runs that, that team, um, not online gambling. They call it online gaming.
But you know, John, I'm a Caesar taking here to the Dolphins. I don't go to a lot of games, but the Dolphins app has that ability in it. Now I can order right to my seat.
I can order merchandise, my parkings in, in there and everything. Um, but let's talk about the Cowboys. How about them cowboys?
All right, so I'm a Steelers fan. I'll full disclosure, I'll say it upfront. And you're right, even before Jerry Jones, Gil Brandt was the father of bringing computers to the NFL, he computerized, digitized all of the college films so that when you looked up a player in the cowboy system, they had all the college film that you can to go scout that player and see what he's like.
There's an old story. You know, the best draft ever in the NFL best draft ever was, I believe the 1972 draft of the Pittsburgh Steelers. Yes.
Four Hall of Famers in one draft. Lynn Swan, Jack Lambert, John Stalworth, and Mike Webster, all in one draft, all Hall of Famers. The Steelers drafted John Stalworth, and I think it was the fourth round.
He was a great receiver. No one knew who he was. He went to a, a historically black college.
I, You know what, you just read my mind. I was gonna say that. That's what the cowboy, I think it was Ed too Tall Jones.
I want to say it was him, but maybe it was some, some other player. But no, Ed too tall Jones was a well-known guy. He was the first round pick Ed too tall Jones.
Okay. But the Cowboys never knew about John Stalworth because the spear and scout, and he's a hall of Famer now. He's passed away.
He knew the Cowboys were digitizing all of the Yes. Filming, going through their scouting. There were only two reels of John Stalworth playing football in college.
That Steeler Scout took 'em both and never gave him back. And no one in the NFL knew John Stalworth or had seen film Warn him. And so the Steelers just tucked it away and waited to the fourth round.
And you were gonna take this guy, John. Everyone said who? John Smore.
Now they got film on Pop Warner kids. So, you know, there's no, That's never gonna happen again. I coached Pop Warner.
We had film. There's an app called Huddle. Yes.
Yes. That's very used. You Know, I 1-year-old, very still, max is another one Review at nine.
And by the way, by the way, Alan Lynn Swan went to high school, maybe, maybe three miles from where I lived. He went to Sarah High School. Um, really?
Yes. Uh, very. Anyway, but I was gonna mention, well, She went to USC and he was a very known quantity.
Right. He is well known. He was their first round pick that year.
Right. But, you know, it's, it's, it's interesting though, the Cowboys in a sense are as well known and respected within the league. And here's the funny thing.
So this guy, Matt was saying, oh yeah, they all come and visit me. They all come to visit our, our facility to, to learn from us. And I said, oh, it's kind of like when you're successful as a coach, and I think of like the west coast offense or where Bill Walsh was in his prime teams had come very, Yes.
They would come in, Keep concepts. Concepts. I don't take umbridge with your use of the term.
Well-known and respected. Okay. I've reminded of the Godfather, part two.
Frank Panang says, your father did business with Hyman Roth. Your father made money with Hyman Roth. Your father never liked Hyman Roth.
It's the same thing. Yeah. With the Cowboys.
Yeah. Another, they're, they're, they're a hated franchise. They're like the University of Texas.
I said it. Yeah. I, I take issue with the whole, you know, America's team thing.
I think think they invented that themselves. Themselves, Of course, themselves. America's team.
Oh, more People getting jealous. What's all on job marketing? I hope my friend Michael Farham is watching this back home in Houston, by the way, because far this is for you.
I know Andy Alice and the rest of my cybersecurity football friends and George Hume out there fly, Eagles fly. Let's all jump on that bandwagon about those cowboys. Anyway, I think, you know, as a New York giant fan, I follow my ABCs.
Anybody but cowboys, cowboys, I'm not there. Oh my gosh. Um, anyway, Josh, thanks for bringing this one.
It actually is a great, it's a great story. We got off the track here, off the rails, right? You know, I have, I have all this anger and aggression because of the Yankees.
I apologize. So I'm taking it out on the Cowboys. Um, anyway, let's move on.
We'll take a break here. It's extra gang. Let me compose myself.
We're going to come back and talk about overcoming observability obstacles. All right, folks, we're gonna, well maybe be a little more serious for a minute here, but we'll see how it turns out. But, um, if you've been following the show, you know, that we've been kind of taking apart this DevOps next report that Mitch and the folks at Techstar Research put together.
And one of the things we looked at in this report was observability and This Whole category, Mitch always leaves me scratching my head a little bit because theoretically, at least observability has always been a core tenant of DevOps. And yet here it is decade later, and we're still trying to figure this thing out. So what is your assessment of where we are with observability?
The research says there's more investment in the area, but what the heck are we, is it, Well, one thing we should have studied is I, and just anecdotally, there's a lot less therapy involved in observability than there in technology and sports as we proved in the last, I think we can just send in a recording, Alan, you can skip your next session. That'll, that'll do. Anyway.
Anyway, I had to put that in there. So, you know, observability has been around for a while. You know, it started with the open telemetry and open tracing coming together and, and, and combining forces.
Um, and people talked about it as, you know, logs and alerts and traces, right? Well, much more than that. It's kind of grown up in parallel with, as DevOps has, you know, matured and expanded cloud native and microservices and containers.
And, you know, observability has also progressed in several ways. One of it is being used in multiple areas, not just in operations for it, but also in security. And another is, as the complexity's gone up, well, we need more than just the logs and alerts and traces.
We need really di visibility across all of our systems to be able to trace down a, or walk down a, a security incident or this bug that's happening in a, in an application that may be involving external services, our own apps, our own databases, maybe in the cloud, maybe on-prem, all these different locations. So it's, it's grown and is really well established, Mike. But even in our own DevOps research, I think it was about 47% so that they were using observability.
Okay, so not even half yet. Quite So there's, there's certainly more room to grow. I think the biggest thing about observability that we're, we're finding is it's not only moved and, and used in in security as well as IT ops, but we're starting to see it in test.
We're starting to see it in software development. We're even seeing applications design for telemetry that is gonna go into an observability kind of solution. Now, the real question is, are we creating more stove pipes, more, uh, silos of data and not being able to see across all that data?
Or are we sharing that data on a common platform, some kind of a, a data fabric and identifying where we share data across the dimensions or the domains of the different areas using, that's probably the next frontier. I won't, I won't claim AI is gonna solve that problem for us. I think we gotta organize the data ourselves better.
I feel like people don't distinguish enough between observability and moderating where I'm just looking at a bunch of predetermined metrics and then they call that observability. So I'm not sure that 47% number is as high as we think it is. And a lot of times a lot of the applications still aren't even instrumented yet.
'cause nobody figured out how to go back to all those legacy apps. And when we had application performance management tools, they were so expensive, we only used them for a handful applications. And to your point, we now have all these cloud native applications and things are more complex than ever.
But I feel like we're not quite catching up to that complexity. And there's still a lot of work to be done here. Someone's using, you know, Prometheus and Open Telemetry.
Yeah, open Telemetry is the second biggest open source project in the CNCF. It Is, I do, I not doubt that people are instrumenting their apps today, but I don't think that those apps will represent even 10% of the total install base of apps that are out there. Let me see if I can help you here, Mike.
How about those cowboys? How about them cowboys trend around trigger em. Lemme see if I can help you.
I think when you look at the observability conundrum, you're gotta look at it around the event horizon of deployment, right? Is that for little Carl Ganish, uh, post, yeah. Post-deployment, post-deployment observability for all intents and purposes has replaced performance management.
It has replaced a PM, what we used to call a PM and a LM and, and and management is now called observability. I don't care whether you're New Relic or Cisco's AppDynamics or, or Datadog or any of those things. They're, or Grafana, they're all about observability all the time, right?
So post-deployment, horizon observability has, is the new nomenclature, the new name for what we used to call what you refer to. But I think when we look at this 47% number of DevOps teams of DevOps people who are using observability, it goes exactly to what Mitchell said. It's pre-deployment event horizon.
So it's sort of the left of the, of the deployment horizon. And it's the testing teams, it's the classic DevOps feedback loops of taking observability data from post-deployment going through the wormhole, if you will, of the event horizon back to pre-deployment. And using that data to make my testing better, to improve my code and, and act, you know, faster, get my next releases done better faster.
So I think that's where the action in observability is pre-deployment. It did, I hope that helped you. When, When, when do I call the temporal police to prevent me from going back in time?
Is there any thoughts about that? We, we could like sign Tom Cruise up for this one, but, you know, I like work through the work wormhole thing. That was, that was kind of, we need little Owen, Owen Wilson, PAC Owen, listen to help this, this out.
I was the spacing guilt, Mitch. I, I think, I think part of the problem here has been the tools themselves up until most recently have been too complex to use. And I remember talking to somebody and explaining to 'em, and they were like, well, that sounds awesome, but I have no idea what queries to ask in the first place.
And I think with the help of ai, maybe we won't have to launch the queries Soon because the machine learning algorithm, that's true too. Also, what queries To run, I mean, you have to think of this also as a data problem because it, when I grew up writing software, right, it was like stuff goes in the logs and then when you couldn't figure out what happened, you added more log messages and you hope that that was gonna lead you to some clue of what a what might have happened or to trace down or walk down where, where an issue was. Now, now it's more about, okay, we have better tools to do aggregation of much more content, much more log and telemetry data coming from everything from security devices, networks, host servers, cloud services, our applications, the infrastructure software that we're running it on, Kubernetes, containers, everything else.
That's a massive amount of data. So in many ways that makes the problem much, much worse, Mike, to your point of like, okay, great, we've got all the data now how do I do anything with it? And just as opposed to get overwhelmed and never find anything.
And that's what, where observability is, tries to step in and do much better job of correlating tying events together and being able to walk across different systems and different, uh, devices that are emitting content. And then they actually have an app platform for building apps on top of that data. Um, I believe it was like in Splunk, I think it's Splunk development language, if I remember right.
SDL, um, to actually build apps. And it's a very, you know, popular marketplace and a lot of free apps and things like that. So people now have at least the data to operate with.
It's, to your point, what's the questions we need to ask? And then how do we build kind of better monitoring, better alerting, better whatever. I, I think observability is a poster child for ai and the full spectrum of ai, quite frankly, what we call observability today would be impossible without machine learning.
Mm-Hmm. Right. A lot of what we do with observability to this point is based upon our ability to sift through large and larger data sets, find patterns, tendencies, and, and bring those to the forefront, if you will.
Now, as you get more data and you find more patterns, you tend to bring more to the forefront and it overwhelms the ability of humans. No matter how good that UI is in your observability plot platform, whether it's Splunk or one of the others, there's so much observability being observed that it overwhelms the human. So phase two of this observability revolution is bringing generative AI or agen AI into play to, to parse and make decisions based upon the pattern recognitions and, and observability of, of the machine ai, machine learning ai.
Well, that's What I'm going with the a you know, to your point about ai, about building apps in a, you know, Splunk development language or whatever it is, is much more use of natural language query interface, right? So I'm not writing queries, I'm not writing apps. Yes, I might have those things, but No, but I'm talking about AI taking, you know, actions based upon what the machine learning shows without a human involved.
That's your agents, right? That's where you start to turn those loose, hopefully the agent one. Well, and hopefully they work.
I mean, but that's, if, if you don't think they're gonna work, let's not waste our time and effort in doing it. Right. Idea, I mean, building that's idea.
The agent is all, yeah. So, So are you saying that there'll be no software engineer to review that process because there's a saying in, Well, they'll always be a software engineer because they're gonna be able to do more valuable things with their time. Right?
But, but there's a saying that says it's one thing to be wrong, it's another thing to be wrong at scale. And if I let the agent go do something on its own, bad things are gonna happen. Sarcasm meter.
Sarcasm meter. Yeah. Yeah.
Um, but oh boy, where'd we go wrong today? It's a day. It's a day We go wrong, miss it.
This is why we try not to go just hardcore all the time because Yeah, yeah. So there's a problem with running in the red line, red line Anyway, gasket. Anyway, there is one other issue here that I would like to point out too.
And some of the engineers I've talked to are getting yelled at by their CFO for storing too much data. It's too expensive, and they're getting these bills and the CFO's like, what the hell is all this log data crap doing? You mean this?
Well, yeah. Well that's, look, we've heard this with Splunk, That's been Forever the issue, right? Times I'm vendors.
Yeah. Splunk being So, you know, that's the classic case of just course I can, doesn't mean I should. Um, and there's been, there's been a lot of takes on this.
I've seen some companies that do their analysis in real time and then purge data that they don't think they're going to need. But, you know, there's hoarders wherever we go. And, and there are some hoarders who just say, you know, I need everything.
I wanna store everything. You know, my wife's like that with our children's pre-K art projects. But, um, you know, that being said, this is why we have different tiers of storage, right?
And right. Cheaper storage versus premium storage. Um, but that is, you know, that's a constant kind of fault line that moves depending on, uh, your tolerance.
So, so we, so we can have a Halloween movie that's called, you know, the observability purge, right? We'll go from There one day a year, Right? One day a year we're allowed to purge.
I mean, it's still a big area of investment. I think about two thirds of our folks that participated in our survey said that they were doing modest or, or significant increases in their, their observability spend. So it's, and it may be just that incremental data, you know, storage, you're talking about Alan.
Uh, it may be those other uses in other areas in the SDLC too as well. Look, storage is a good business. You're gonna always gonna need it.
Just got one word for you, young man storage. Um, Not off Sticks. No.
With that, I'm just full of movie references today. Let's take a break here on our observability obstacles. We're gonna come back about a, something that's gotta actually no kidding near and dear to me.
Managing the shift or making the shift to managed security services. MSSP is a lot going on in there. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right, folks, we're back in. Yes, we're talking about managed security services and they've been around forever, but there's an argument that's starting to emerge that says, well, the bad guys are getting too smart. The attacks are too vulner, too much volume and the attacks, and we're on the cusp of ai.
And no cybersecurity team on its own can train all the models that are required. So maybe the whole thing is just gonna become a service that we consume rather than a set of products and platforms that some SecOps teams deploy. Alan, I know you've been around this space a long time as they manage security services, time has, has it come?
Yeah, so let me start off, first of all by saying, you know, this, this segment right here references two articles over on Security Boulevard. One is that NTT one of the largest MSPs in the world, uh, has tapped Palo Alto for their MXDR service. So they're basically being powered by Palo, uh, within their socks knocks and all of that.
Secondly, the good folks over in Sophos outta the uk, they bought SecureWorks, which was one of the big, one of the first big footprint SSPs that Dell bought years ago. They bought it for a little under a billion dollars, which, you know, for, for whatever reason, MSS PS never got the multiple that your true software or even some of the SaaS companies got. But that being said, Mike, let Uncle Al tell you a little story here about mss ps um, Mitchell and I started a company back in Denver, in Boulder, Colorado 2001, still secure 2001.
And we banged our head on the wall for about five, six years selling, uh, vulnerability management, IPS and, uh, network access control. And I came to the conclusion that we sucked, not just, we still secure, but the whole paradigm of how we do security sucked that there wasn't, but a handful of companies in the world that were capable. And this is back in 2006, 2007 maybe, that there were maybe 50 companies in the world that could do security by themselves that had the resources, the will, the wherewithal to do security and do it well.
And keep in mind, Alan, that was in the day of, oh, you, you passed the, the mirror nose test. Oh, you could be a security engineer. Come here.
Come here. Yeah. Admin, Network Network.
You used to work on the Cisco Switch here, you're a security guy, come security In here, you're engineer. It was, I mean, literally the, that was that big Of a bold Behind people. Absolutely.
And, and so we went to the board, it's still secure and said, Hey, we need to pivot. MSSP is the future. The people need someone to do their security, if not entirely, at least augment their security.
And I bought a security company, right, identified and we acquired a security company right down here in South Florida. I had just moved down here a few years before and uh, I be damned if I remember the name of that company now, but Steve Harris was the CEO of a very capable guy. And the idea was we were gonna do a rollup because the MSSP business was so fragmented.
There was no NTT at that point doing MSSP. SecureWorks was the only one who had, and they were based, I think they were based in Atlanta or Georgia area, but they had kind of a national footprint. Every other M-S-P-M-S-S-P was very regional.
Very regional. There were like a thousand SSPs in the US when I did my research. And we were gonna do a kind of rollup in MSPs, of course, by that we had already burned through a lot of money and still secure and we're losing money.
And the board really didn't have the appetite for another business development adventure led by me. And, um, I left still secure shortly thereafter. Uh, But if they would've followed that strategy, I wouldn't be here now.
I'd be, yes, I'd be point watch the Cowboys or Something, isn't it Protect Point, is that who we bought? Yes. Protect Point.
That was the name of the company, Mitch, you remembered. Yes. Protect Point.
And so I have been a believer in a long time that the fact of the matter is most organizations are incapable of doing a soup to nuts security ball game. They just can't, they don't have the resources. They don't have the, they don't have the will to do it.
They don't have the oomph, they don't have the software, they don't have the tools, they don't have the talent. And so I say this is, this is a trend that's been a, a long time coming, right? This has been a long time coming and good for Sophos.
'cause Sophos made some great, uh, MSSP tools, right? They had what we used to call back in the day, A UTM. Now Mitchell tried to build a better UTM with a router called Coia, and he can tell you about that tomorrow's bedtime story.
But, um, Tonight Kids, Yeah. But, but Sophos has a long history of servicing the MSSP market. Mm-Hmm.
So my question is, by borrowing SecureWorks though, do they alienate their MSSP audience? Right? A lot of, a lot of the MSS PS I talked to are sick of buying the gear themselves, and they're just as happy to resell somebody else's service under their own.
Well, so, so protect point was what we call a roll your own IT before stuff was legal in Colorado. Um, But, but, but let me ask you this. I mean, I don't disagree with your analysis, but for decades now, organizations continue to try to hire cybersecurity people, build their own platforms and manage all this stuff, and it's like beating your head against the wall and expecting a different outcome.
And yet that's what they keep doing. Well, I think there's a tipping point. There's a, there's a point where you reach where what you're trying to secure and, and operate and then manage Monitor is beyond the complexity of what a service provider can respond to.
They have to get you involved again. And you reach this point of saying, well, maybe I should just do that part of it ourselves. It made a lot of sense to outsource it when it was just resource intensive and who they could do it as well as we could.
Maybe better. Maybe they have the skills that we have. You get into bigger organizations, maybe using MSP for some of that, but you'll also probably consider doing more of it internally.
So there's this tug and pull about what part of the market is best suited for MSPs. And it does depend on the tools the MSSP is using. I I think the NTT Palo Alto story is a great example of it.
N NTTS coming and saying, we have best of breed software here. We have Palo Alto, a name, bridge and trust. I think, you know, leaning back on, you know, Mr.
Allen, good news, um, AI is gonna force the issue. I don't think your average organization can collect and update to train an AI model much less build and maintain it. So if I'm gonna fight fire with fire and everything is now a real time fight, and I need ai, I don't see how you're gonna get there without a service provider to, to deliver it for you.
No, but, but let's take Sophos or not. But you know, Sophos could build a tool that utilizes the SecureWorks data set as an LL lab Mm-Hmm. And sell you that tool or sell it to you as a service.
That's, Yeah. I think that vendors, they're becoming service providers. If you look at Sophos and where it's going, and Palo Alto Networks and all of these guys, you know, they start out with this.
We have a SaaS platform. It's an as a service security platform. And then, you know, for a few dollars extra, we'll sell you some managed services.
And, and if you need a partner to implement it, we'll send that to you. So let Uncle Ally tell you another story. This is not new in security.
I remember walking uphill to school and uphill back from school. Um, company called ISS, that was the first big security buy. IBM bought ISSI forget if it was 400 or $600 million.
And that was crazy back then for security. Who the hell would pay that much for a security company? Well, when you looked at their revenue, I think they had, I don't know, 75 or $85 million in revenue.
So it wasn't that crazy. com bubble burst. Um, but when you looked under the covers, that is S'S revenue, 40% of it, four 0% of it was services, not software.
And I would venture that every security company that's been sold ever since has a, a like amount of services tucked in underneath, whether it was pro services back then or managed services over the last 10 years. That's been the dirty little secret in the security business. Well, that's why I don't sell just product so much was sold through the channel for that reason.
Exactly. Yes. Yeah.
And, And, and, and who is still one of the largest managed security service providers out there today? IBM and then Cisco? Uh, yeah.
IBM. Absolutely. And it is the old ISS business at the core of it.
Uh, though Cisco, Cisco manages the make the deal with, I was gonna mention, uh, Cisco, speaking of Cisco, they're managing the security for our, their dreaded Dallas Cowboys. So, you know, there you Go, tech they are, they had to bring us back there. Had John Yeah.
Had to do it. And they got thing at the SSEs kicked by the 49 ERs. Sorry.
I'm sorry, go ahead. Yeah, I, I served this past weekend. They absolutely did.
And it's not the first time shades of Joe Montana to John Taylor. Oh, I know. We, I'll hold onto that.
I'll hold onto that. Thank you. Absolutely.
But Roger Staubach, that's all I got to say. Wow. Greenback Brandy.
Roger, the guy Greenback Roger. You Know what, Brad sitting, Sorry. Got Roger the dodger though.
I'll tell you, even as a Steelers fan, he scared the hell out of me. He was great. Dead.
No, look, the Landry, Tom Landry, poor Jerry jus Tom Landry classy guy. Well go. I don't know.
I bet I'm betting that the road to the Super Bowl this year is going through Detroit. That's what I gotta say, isn't It? That's A good bet right now.
Looks, But you know, we'll see what happens. But let, let's get away from football back to Security brought up just starting that. I'm sorry.
Yeah, no, but you know, but that's the truth. IBM security, huge. Cisco, secure Cisco for many, many, many, many years was the largest security vendor in the world.
They may still be, but um, especially if you consider Splunk a security company and you add their revenue to it. Mm-hmm. Yeah.
But that being said, a lot of services wrapped in there and a lot of services in their channel wrapped in there. So, you know, this is, this is Palo Alto net. Yeah.
Look at Palo Alto Networks. It's an outweigh you then it's probably 40 to 50% serviced. I, I didn't IBM do the deal with Palo Alto and I think PA doing services now or so.
Yeah, I, I believe they have some sort of alliance, but, uh, you know, and I think it's more than just your typical, uh, uh, Barney announcement. But IBM also has relationships with everybody. No, I, it was, there was something, I, I don't remember it now, but I remember covering it when it came out.
It was, it was, it was my AI and your AI are gonna meet in the cloud and we're gonna work together kind of thing. Yeah. But there was a t but then there was a quid pro quo underneath that with a RY one, pers one of them got technology, one of them got the contracts.
And I, I, Yeah, I think, I think IBM gave up Tech and Palo Alto got contracts. There you go. There you go guys.
What a, what a great core text and gag today. How we had a lot of fart. Thanks For joining us on ESPN here on Text, on Tv.
It's good. So this is, you're just trying to like harken back to the core four of the Yankees? Is that where you're going with that?
Oh wow. 96. 96.
So that's what I thought when we lost the first two games, it was gonna be like the Atlanta Braves. And we all remember Jim Laitz, Jim Laitz, pinch it running, hitting That whole run that turned that series around. But as I said, the mighty Casey has struck out, but that's okay.
Right. There's always next year in baseball. It's always next year, and there's always tomorrow on the Textron gag.
It's true. So, and you, I don't, are you gonna be on the show tomorrow? I don't think so.
'cause you know, you might have to eat some of those words. Yes. I'll tell you what, if there's, if there is a game five, I will come on and eat my words and apologize to you.
Right. I, I, but as I, as I said, when Mush made that bet, I just tore up my tickets. I it Bet.
I, I I'm looking forward to accepting your apology gracious. I think The Yankees are gonna, they're gonna salvage at least one game, at least One a safe face. Yes, they are.
Uh, you think Aaron Judge hits a home run? No. You'll strike out twice more.
Two more times. Sorry. Okay.
I'm gonna end this with, how about them cowboys? That was one of my favorite things. Michael Farham.
I hope you're watching this wherever you are. Um, but guys, hey, we've got a full text on TV following this. We've also got a great, uh, uh, virtual event we did yesterday.
com and whether they're going on live or on demand, some great sessions on there. And eventually they do make their way onto Text Strong tv. But for now, this is Alan Shimmel Mitchell, Michael, John, thanks for joining us.
You've just watched Textron Gang. This is Textron tv. Hey everyone, welcome back here to another Textron TV interview.
I'm really happy to introduce you to Shivan or Shiv. Ramji. Shi is the President of Customer Identity Cloud at Okta.
Hey, Shiv, welcome to Textron tv. Thanks for having me. I'm excited to join you guys today.
I really we're excited to have you on Shiv. Um, I mentioned you're the president of the Customer Identity Cloud at Okta, but, uh, you know, people may not know what that is, number one. We're gonna talk about that in Okta.
But before we do, Jim, give people a sense of kinda your story, your journey, if you will. Yeah. So I, uh, started out as a developer myself many, many years ago.
And one of the first things I had worked on was, uh, building a single sign-on portal. Uh, at the time I was an engineer and I was working for, uh, uh, in media research with Nielsen. I built a single sound portal for the field.
So I knew firsthand sort of what it takes to, for an engineer or developer to build identity. It's cumbersome, it's complex. And then, you know, after that journey, I sort of went on to, uh, different companies of different sizes and even different industries where we were building products that were a downstream consumer or user of identity information.
So whether it was advertising targeting, marketing, personalization, so on and so forth. Uh, and then got into cloud computing. So I was building products for developers at digital lotion.
And then after that I joined, uh, auth Zero. And, uh, I was really excited about that because I knew the problem of solving identity firsthand and the product made sense. So, joined that team, and now of course, you know, we are about over three years and, you know, we, we acquired, we got acquired into Okta, and I get to pursue the same, uh, mission now within, uh, the, uh, you know, the Octa umbrella.
Much bigger stage. Yes, absolutely. A lot more responsibilities and, and specifically with regards to the threat landscape, right?
Uh, it, it's, it's getting more complex and, um, threats are increasing at an alarming rate. So, yeah, absolutely. Uh, stakes are much higher now.
Yes, they are. They are. But you do have more resources, hopefully.
Um, shi as we were talking, our, our audience knows Okta. We've been, you know, tracking Okta here at Techstrong for many years. I think a lot of people think of, you know, single sign on identity, access control, et cetera.
You know, to me, identity and access control is sort of the, the killer app in cloud security, right? We don't worry as much about firewalls or intrusion prevention, but access control and identity is a part of that, is really our, our choke point at, you know, for, for, uh, cloud security for people maybe are not familiar with the full breadth of Okta's offerings and they are, if you don't have to take 10 minutes. But, you know, can you give us a kind of the shortened version?
'cause Okta has quite a lineup of offerings Yes. Solutions. Yeah, we absolutely do.
So hopefully everybody, audience is mostly familiar. I wouldn't assume everybody, but mostly familiar with, uh, Okta is the product that you use when you are, um, in your business or, uh, for, for work, basically. And, uh, that product essentially provides secure and seamless access for employees and contractors and business partners.
So the idea is, if you are working at a company, you're accessing SaaS applications, chances are, uh, uh, a big majority of them use Okta to access those applications securely. So that use case is all about safe and secure access for, uh, employees, you know, contractors, business partners. Then there is the other market that we're also, uh, building products for, and it's commonly known as customer identity access management, or more commonly known as Siam.
Uh, we love acronyms. So we've got an acronym for everything. Siam is, is the, is the, is the, the other market.
And there the two big use cases are we wanna provide secure and seamless access for consumer applications. So this is your typical, I'm logging into my bank, my news website, my streaming, my loyalty accounts. Um, I'm paying my mortgage, accessing insurance, anything you are as a consumer that you're using that has identity and security, we power those use cases.
The second use case is essentially, um, secure and seamless access for your business customers. So in this case, we are providing capabilities to other companies and businesses who are then providing access, uh, to their, uh, applications. Classic examples here tend to be your typical SaaS applications.
IMA, uh, up and coming AI company. They'll build, um, their access controls and login systems using our product, and then they wanna make that product available to other businesses. So that's the other use case that we, that we power.
Excellent. And you spoke a little bit about what, you know, the you've been doing, and I just wanna make sure people realize when we say customer identity cloud, they understand what that is. She, if you wouldn't mind.
Yeah. So customer INA cloud, we use that name and, and the brand really is AU zero. com.
And it's a product that's really specifically built and tailored, uh, for, uh, for developers and eng and engineers. Because in the customer identity market, in most deployments, the engineers and developers are, uh, both either the, uh, the folks who choose the technology and also deploy it, or they're definitely the, uh, the, the folks who deploy, uh, chosen technologies when it comes to the customer identity project. So our product is tailored built to solve this for developers, in essence, making it so easy for them so they can integrate authentication and authorization into their applications easily.
And they don't have to be identity experts because that's one less thing that they have to worry about, and they can really focus on innovation that matters and business differentiation that matters so they can launch their apps, uh, as fast as possible. Excellent. Now, you guys have recently expanded the au zero, uh, capabilities over at Okta and, and helping developers, DevOps folks.
Uh, why don't we, you know, talk about that. I, I think Shiv the way that it makes sense to us though is maybe, you know, what was before, what was that baseline and what did, what the new capabilities here have been put in place? Yeah, so from the very early days, uh, of the company's founding, we've been obsessing on making it easy for developers to integrate authentication so they don't have to be experts.
And I think that maybe a little bit more context behind this is today we're asking developers to build products and experiences faster. We were asking developers to do more, we're asking 'em to do it, uh, in a more cost effective way, and now we're making them responsible for security. So what we said was, what, what can we build so that we can take those, all of those burdens away?
So that's how, uh, that's kind of the philosophy of the product that we built. And we then we offer a, a very generous, free tier. So the classic example is you are a developer, you might have an idea of a product in your mind, but you're not monetizing it yet.
And, but you still want your idea to be out there for your prospective customers or existing customers to use an experience. We want to enable that, and we wanna enable that, not just from the perspective making it easy for them to integrate and use, but we also wanna give them a lot of security capabilities. So what we've done with the new plans is we've increased the number of monthly active users, uh, developers can get, uh, to 25,000.
We have also added new security features such as passwordless, uh, authentication now is available in our, uh, free plan. And we provide unlimited Okta connections and unlimited social connections so that they can, you know, um, take an I, you know, a product from idea all the way into production. Um, so they can test it out.
Now, of course, as, as it's successful and as it starts scaling, then we do have self-service and enterprise paid plans that they can sort of might, um, upgrade to over time. So I think that's really the, uh, the, the news here. And the one last thing I would talk about in the free plans is we also offer custom domains for free, uh, which tends to be a barrier.
And we, we got a lot of feedback from developers that this really allows them to fully experiment with our product and go to market and see, uh, whether their product has legs and then it allows them to, to expand on from there. Sure. So shift sometimes free isn't free, or is that always free?
Would this free offering, what are the, um, you know, is it time limited, size limited? What is the, the governance? No, we, uh, well, it, it, i it's limited by certain, uh, features.
So for example, um, we do have very specific, uh, uh, rate limitations. We have owner APIs in our features in the free plan. 'cause we don't want customers to abuse them.
So those are the, those are the gates that we have. But outside of that, in terms of most of our features, we, we make sure that our customers can experience a full breath and there is no expiration or credit or spend associated with it. Um, you can, we have customers who've been on our free tier for many, many years and they'll continue to, you know, to be there.
Fantastic. So it's free forever or free forever anyway at this point. Yes.
Now there's not a new business model, quite frankly, we've seen businesses with this Ronald Shiv. Where is the point where people should say, you know what, the free is great, but I need more. What are the, what are the dials?
So usually when, um, a custom when, uh, um, one of our customers is starting to gain real traction, so when they go above 25,000 monthly active users is when they have to upgrade to a paid plan. So that's one. Um, this is when you're building consumer experience, obviously, um, when it comes to building B2B applications, it tends to be, uh, how many different organizations you're trying to serve and how many different IDPs you're connecting to.
So that tends to be the, the, the point where they need to move to a, a paid plan. And these points are specific because they are clear indicators that a, an idea or a, or a developer pro a a product from a developer is finally gaining traction. So there is, it's a good indicator that, um, the company has some monetization in place and, uh, and once you do have a monetization in place, then it makes sense to have a paid offering and additional security capabilities and additional features.
So those are the, those are the signals we, we look for to, to, to tell us that, hey, this app is successful, so let's, uh, do a paid plan. Okay, we got a little bit of time left. Yeah, sounds great.
How do people engage? What's the on-ramp here? Where, where do they go?
What do they do? How, you know, they wanna try it? Yeah, good news.
com and you can sign up for, uh, our free product. The other way to engage with us is recently also announced auth for Gen ai. Uh, you can sign up for a wait list.
ai, you can sign up for a wait list. Uh, and we also have another product called Dev Portal. ai/dev portal and you can sign up for, uh, a wait list.
Um, there, and just so I'm not letting, uh, the audience guessing what these products are. Essentially, we believe that there's gonna be lots of agents, um, that companies are going to be experimenting with and developing. But the concern is to put these, these agents and products into production.
Uh, they need robust, um, security and they need identity capability. So what Auth four Gen AI does is it allows developers to add authentication, uh, in, uh, into applications that are incorporating Gen AI provides finer grain permissions and also allows agents to, um, uh, to have a security contract with APIs, because that's the, the, the mode of interaction. And so, um, so those are the things that we've, we've announced, uh, recently and, uh, are excited for the developer community to get engaged and, and play with the product and give us feedback.
I love it. Shiv, we're about outta time. I want to thank you for coming on here.
Hey, now that you're here and you know the address, we expect to see more of you. Keep us posted, you know, the whole world, zero. Hey, as we deal with, you know, security is being top of mind and everything else, and from our DevOps, uh, audience, this is something that's important and the fact that you guys are making this available for them to kind of build in.
'cause as you said, developers aren't security professionals. They don't want to be, but they wanna build secure applications. Correct.
Exactly. Yeah. Happy to come back.
Um, as often as we have these updates, we'll have meaningful updates here, especially with auth four, gen, ai, and other capabilities. So I'm more than happy to come back and Yeah. I'm gonna hold you to that, man.
I All Thanks Sal. Right. Pleasure to meet.
Pleasure to meet you. Ve Chief President, customer Identity Cloud Okta Here're on Tech drunk tv. We're gonna take a break.
We'll be back in a minute with some more tech drunk tv. Thanks. This is Techron tv.
Hey everyone, it's Alan Shimmel and we're back here at the Quala Security Conference. We just grabbed this gentleman off the main stage. We pulled him in here.
He was, uh, part of a panel. His name is, and I, I'm gonna try my best to get this right. Hamesh Chala.
He's CEO of a company called Mulberry. If you're not familiar with Mulberry, they are a leading cybersecurity insurance provider. Is that the right term?
I think that's very right. Yep. Very Right.
So before we go any further, I ask for people who maybe are not familiar with Mulberry. Sure. What's the website?
io. And how do you spell Mulberry? M-U-L-B-E-R-R-I.
It's Like one of that's a Y not a y, right? Exactly. Yes, you're absolutely right.
That's, I want to make sure we got that. Alright. Now that we've got that out of the way, let's jump in here.
Yep. So I've always had a belief that the cybersecurity industry, maybe five years ago Yep. Became the big stick in enforcing cyber hygiene.
Sure. Right. I, I frankly, you know, I've been in security 30 plus years Yep.
Who have, who's been able to enforce cyber security hygiene Yep. And process best practices. Well, the government tried not so great.
Yeah. In some cases they're okay, I guess, but Sure. For the most part Yeah.
I call it least common denominator security. Right? Yeah.
Because they, they tend to go low. Then you had sort of the private, like PCI Sure. Right.
Payment card industry, PCI stuff. Uh, you had nerc, ferc, which was quasi-governmental. Yeah.
You had these sort of agencies Yeah. A lot of them private Yeah. That said, Hey, this is what I need from you.
Yeah. But now we've got a genuine insurance industry. A real, this is a classic Yes.
Right. Kind of industry. Yes.
Who can, who says, look, if you want to get cyber insurance and you really need cyber insurance today to operate, this is what we need from you. Yes. And they were able to enforce this over the last five years.
Yes. You've become the enforcer. Yes.
But as we were talking off camera, all good things come to an end, right? Yes. And we're coming now to maybe the next stage.
Sure. Give me your thoughts on this. I think you summarized it very well.
I mean, let me just back up a little bit. Sure. Fundamental element of any insurance, and now you take it, cyber insurance is determination of risk.
Right. Risk determines how much premium you write, whether you decline or accept, um, or what's, and an accurate a detection of risk also helps in, you know, what's going to be my loss ratio, just like you said. Mm-Hmm.
There could be a big claim or, or you know, that, that hands and the falls from the carriers. So typically this process, what we call underwriting or determination of risk is done by asking a bunch of questions. That's been a traditional method in any insurance.
Um, plus in case of cyber, what started to happen was, well, let's go and do these external scans. Let's collect some data points from these public sources. But however, cyber is an evolving threat.
The, the metrics, the, I would say the instruments keep changing every day. So unless you're continuously monitoring or getting the data, you know, it's difficult to say, make any decision of snapshot in time, which is where we feel the more the sources of data, such as the true risk score by qualis and combined with inside outside conditions in a continuous manner, is where the insurance and protection needs to come together. Right.
And, and, and which is, and which is to your point, you know, if it doesn't, then I think you are, your loss ratios are gonna go up. You're not being able to, to accurately detect risk. Um, and, and, and that's where we feel the industry will shape towards, You know, let me, let me make an analogy to kind of mainstream insurance house.
We live in Florida, I'm from Florida. Hurricane wind insurance is impossible to get right now, but for a long time when you would apply for a wind insurance policy, just like you said, they'd send you that questionnaire. Yep.
How old is your roof? Yeah. Does it, is it free of leaks?
Yeah. Do you have storm proof windows, doors? Yeah.
Do you, uh, you know, do you have a wooden frame, cement frame? Are you building co complaint? Yeah.
And you would just answer Yes, no. Yes, no. Yes.
No. The idea being that if you lied or you didn't answer truthfully or Right. Sure.
When it came time to make a claim and they found out you were wrong. Yeah. They could deny your claim, but then litigation ensues.
Yeah. And litigation is no one's friend. Yes.
Right now, it's a very different thing when you go get insurance. Yeah. In Florida, how old is your roof?
What kind of shape is it in? Well, they send a drone. Yeah.
That flies over your house and takes pictures Yeah. Of your roof. And it's attached to your file.
Yes. You know, trust, but verify, if you will. I, yeah.
It's where is You? Just where we're going. And it's the same thing we're doing now with cyber.
Yeah. I mean, look, I mean, you said it's very, very succinctly. I mean, it's like the zero trust framework, right?
Yeah. In cyber, the only difference that I will put together is the roof. Let's say the drone takes a picture and it is cement today, but in case of cyber, it may become as fault the next day.
Yeah. And that's the problem we have. Yeah.
Right. And so, you know, like I've seen many examples wherein their premium is written to a firm. They answer those 10 questions, and as you said, somebody could lie, somebody could, you know, say the truth and we get some point of scan data, right.
And we write premium. Right. Two months down the line, that point of scan data is invalid, or even the next day That it's a point in time.
That's, but security's I always used to say with the PCI industry, right? Yeah. Do you know A PCI compliant com company was never breached because the moment they were breached, they were no longer PCI compliant.
That's true. It's the same thing. That's a great thing.
You know, it's the same thing here. Yes, yes. You didn't have any known vulnerabilities yesterday.
Yes. But today, a known vulnerability came out And, and that's where then the carriers get there. And I think you brought up another good point when we were chatting.
You know, one thing is to say, do you follow best practices? And your answer could be Yeah. Yeah, that's Right.
But the other thing is to say, are you following them every quarter? Do you have training programs in place every quarter? Because guess what?
A new employee comes in. Yeah. You followed best practices the last quarter, you get an email, which is a phishing email, clicks there gets to a ransomware.
Cyber insurance is called. Right. But we wrote the premium.
There you go. We wrote the premium based on that. Well, and, and I think that's another problem here is I think a lot of organizations say, Hey, I pay my premium.
That's why I've got insurance. Instead of saying, that's so shortsighted, because your premium's gonna be twice that next year. A hundred percent.
If You get it a hundred percent. If you don't take steps to keep best practices up to date to get new employee training in. And again, to me, this is something where the cyber insurance industry has to be the big stick.
I love it. I love how you're saying, in fact, I'm gonna borrow that in my future. You know, conversations the big stick.
And I think you're right, because that's where, otherwise what happens is, yes, oh, I have got cyber insurance, I'm protected, but guess what, it's gonna double next year, much like any other insurance. Second, what, what you're not realizing is there is reputational damage, there is other sorts of damage that you're Having Absolutely. That is not covered, Then you're not covered.
Right. Right. Uhhuh.
And so just like you said, just having feeling that cyber insurance is there, but using that as a stick. Right. And, and, and, and, well, You could use the carrot too.
If you do it, your premiums are less Oh, Love it. Right. Absolutely.
That's what we trying to, and that's classic sticking carrot. Yeah. I mean, with call now we are saying that we can, if you're a call us customer, we can offer you a discount just because we know that, that it's a carrot and, and we'll help people with good practices.
Absolutely. Right. So we are trying to give small, medium businesses an incentive.
Uh, I, I loved it. This is a good path to go down. We'll, we'll talk more about it.
I wanna ask a little question about using the twa, uh, true wrist. Do you, because again, we don't want a moment in time. I want an ongoing, is it built in or can you have it built in that if you're a, a, let's say a Mulberry customer, an Aquas customer, you get daily, weekly, quarterly updates on true risk.
Yes. I think the, the, at least a vision they have, and from what I understand is they are having a vision of being able to continuously monitor provider states. So we will build adapters to, to sort of ingest that score.
Right. No, I'm thinking, right. They, you know, one of the nice, I, I followed Qualys for many.
I've been in security 30 years. I knew Philippe very well. One of the nice things Qualys always did was have different views for different personas.
Right. I'm thinking if they don't have a cyber risk, uh, dashboard for a cyber insurer, Right. I think this is what now they're trying to do.
And which I, which I feel is absolutely the right vision. Uh, you know, they're also putting together a vision of risk, determination of risk. Yeah.
Right? Because if you look at, if I, if I sit up with my board, or if any board sits together, you, you have to talk about security. We talk about security, but at the end of the day, we talk about risk.
And risk can have six different things. There could be three C cyber risks, it could be three other risks. So they're going after the risk persona.
And then when you go after the risk persona that has a direct intersection with any underwriting that you do in insurance industry. Absolutely. Because that becomes a business.
That becomes a business Decision decision, not the security guy. Exactly. Exactly.
And the moment you talk about risk, it's not a CSO decision, it's more like a, the CCO Or a Agreed. We are having words there. Each other's, You know, that's always been a, a source of friction, right?
'cause you got the Cs, the cso who's with the CIO with it. And then you've got the risk team pill here from the CFO. And you know, the, there is that.
And so this new CRO thing that came, the, the, uh, security, the risk operations center, excuse me. ROC is I think a way that we could bridge that too. Again, by having different ones for every, for everything.
Yes. Yes. No, I, I couldn't agree more.
This is been great. One more time. Mulberry.
com. Do io. Do io.
All right. There. You got it.
We'll put it down on, well, it's gonna be on the bottom with your name and title, so we'll put it in there for you. All right. Thanks.
Pleasure, pleasure, pleasure, pleasure Meeting you. Really thank you for being here. Thank you for talking here at the QUAS event as well.
And thank you for your insights. I mean, I caught that line is a big stick Insurance company. I'll carry that big stick.
Thanks. Alright. We're live, we're live here in, uh, San Diego.
We'll be back in just a moment. Who know? com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers network. Hello and welcome to the Techstrong AI podcast.
I'm Amanda Ani, and with me today is Cindy Hausen. She is the Chief Data Strategy Officer for ThoughtSpot. How are you doing?
Great. Thanks for having me on the show, Amanda. Happy to have you here.
So can you share a little bit about ThoughtSpot and what services do you provide? Sure. So ThoughtSpot is the AI powered analytics platform for all your cloud data.
We pioneered and patented this category that Gartner would call augmented analytics that now really the rest of the world is, is trying to do it, its natural language processing and AI generated insights on business data. Wonderful. And so ThoughtSpot recently with MIT, I believe conducted a survey.
And can you share a little bit about this report? Who are you, uh, what were you analyzing and who did you survey? Yeah, I'm really excited about this survey because there's so much noise hype, we might say with generative ai.
But what we wanted to do was focus on generative AI on the data and analytics use case. So this is not generative AI for social media posts, for example, or summarizing emails. It's really on data and analytics.
So we partnered with MIT, they surveyed over a thousand executives globally across different sectors, financial services, healthcare, insurance, CPG. And the, the findings were a little surprising to me. The one, um, that most surprised me is that already two thirds of organizations are putting generative AI to work against their data and analytics platforms.
Oh wow. So what does that mean to business leaders as they look at AI and how to implement it? So the biggest thing that it means is that we really, as an industry been trying to democratize data and analytics at the point of impact for business people.
And now generative AI makes that even easier, more possible. So people don't have to learn hard to use tools or learn how to program in SQL or Python. That is part of it for the right persona.
But for business people, it's about being able to ask questions in natural language and then get an answer back that is further explained in natural language that really makes data less scary, more approachable, um, for everyone. And I believe the report mentioned about the skillset of employees. Can you share a little bit about that?
And where are we as far as skillset when it comes to generative ai? Yeah, so skillset is something that every organization really needs to work on. So now that we have made the technology easier, one thing that technology cannot solve is AI literacy and data literacy.
People need to understand the difference, for example, in sales to customers versus shipped to customers, sold to customer and shipped to customer can have a very different meaning, um, and different languages. So focusing on the business definitions, that's what I would call data literacy. And then the critical thinking, does this number look right?
Does it pass the smell test? Is the data complete? Might I have gaps in my data?
These critical thinking skills are important for every organization to embrace. And did that survey say anything about hesitation to adopt this new technology? And what is the mindset there?
Yeah, so the biggest hesitation, this is a new technology. The landscape is changing really fast. Hopefully all of your listeners are aware of hallucinations and they know the mitigation strategies, things like rag architecture, data completeness.
And that is the biggest thing. So this is also where we see differences in the platforms. The degree of trust accuracy and transparency varies greatly.
But this is really the biggest hesitation. So what I'm always happy about is when a customer will tell me they have set up a responsible AI council and they're leaning in, but they're leaning in intentionally. What I never like is when people stick their head in the sand and say, we'll just wait until this matures because that is really at their peril.
Yes, it is. It seems everybody is trying to harness the power of ai and they'll be left behind if they don't, when it could have been a, a useful tool. Yes.
And the other question I have is, um, when it comes to, uh, return on investment, what tips do you have to businesses as far as seeing where they're getting the return on investment? Yeah, and this is perhaps I would say also one of the most exciting parts of the findings from the report is that, so MIT divided this between the early adopters and those that are slow followers and those that are still taking a wait and see approach. Well, the early adopters, 12% said that they expect a 300% return on investment from making generative AI work with their data and analytics.
That's huge. And just about half estimate a at least a hundred percent or greater ROI, and that's a combination of productivity, data analyst, business user productivity, but also new revenues and improved customer loyalty. So that's the good news.
How do you get there? First off, take a baseline. What are your metrics today?
And I often think of this in terms of leading indicators and lagging indicators. So if I were to take a supply chain example, a leading indicator might be how many users do you have that can ask their own questions? How long does it take?
If it's taking you three months to build a dashboard and you can get it down to seconds, um, or even days. That's a huge productivity savings of doing more with less. Your lagging indicator will be those supply chain metrics.
So it might be, for example, on time and in full or, um, aging of accounts, receivables, stockouts, things like this. And so as you democratize data insights at the point of impact, then those lagging indicators will eventually follow. And you definitely want to be measuring both.
All right. Well, if there was one key takeaway you could leave our audience with today, what would that be? That generative AI is just a technology and enabling technology, a powerful technology.
But you do need the people and the culture to embrace this. This is a generational lifetime shift in the way of working. And I don't want people to miss out.
I want them to benefit from it. Alright, well thank you so much for coming on our show today and talking about this report. Thank you, Amanda.
Always a pleasure. Yes. And thank you to our audience as well.
Stay tuned. There's more. This is Textron tv.
Hey everybody. Mitch Ashley here in Barcelona at Atlassian, team 24 Europe. A great, great topic.
We're switching into sales and talking with, uh, Chris Moen from the head who's head of global sales, enterprise sales for, uh, Atlassian. Welcome. Thank you so much to, uh, happy to be here.
You. Yeah. And thanks for coming down to our event as well.
You bet. Hope you have enjoyed yourself this week. We Have.
We have great love participating in Atlassian events. I've been coming for a number of years, so, great. It's a lot of fun.
So you're familiar here. Yep. Good.
Well, tell us about global Head of enterprise sales. Sounds like a big job. You're, uh, Atlassian.
I tend to think of, oh, north America or Australia, but we've got a great president presence in emea. Yeah, We surely do. Uh, so currently my role indeed is global head of enterprise sales.
Uh, previously I ran our, uh, EMEA and APEC regions. So, um, I have a probably more extensive knowledge around those two markets than the AIM market. 'cause I'm still learning that one.
It's been, uh, it's been three months since I'm in this role. Uh, but yeah, you're right. If we, uh, if we look at it at sort of where the market is for Atlassian, uh, for many, many, many years, it's been a very large in Europe.
Uh, I think by now, uh, we have close to 130,000 customers in the Europe region, uh, which represents about 40% of our total customer base. If we look at, uh, sort of the spread of where we find our revenue, it's, it's quite similar. Um, which is pretty unique for, for software companies to, to have that type of presence.
And the, the way we think about it's that, uh, our original flywheel model, the way we we sort of entered into the market, uh, was really based around the strength of our product. And that strength was recognized by both European companies as well as, uh, APEC based and AMR based companies. So, um, I mean, has always been and will continue to be a very important, uh, geo for, for Atlassian.
Mm-Hmm. Truly global company, I would say. Yeah.
Well, when you're working with enterprise customers, oftentimes they are global also, so that kinda leads you wherever they are. Yeah. Uh, and I, and, and that is also one of the reasons why we've, uh, quite recently with our renewed focus on those larger organizations, let's call them enterprise customers, um, we've made sure that our, uh, own internal organization is aligned with that, right?
We wanna make sure that we have true specialization in, in how we have to work with these types of customers. And the majority of them are indeed, well, let's at least say multinational, right? Not all of them are global, but they do span across multi, uh, geos, multiple geos.
Uh, and we felt it was important to make sure that our teams and our leadership is also aligned in that way so we can serve those customers the best way possible. Um, so this is very much aligned with our strategy on where we think the biggest opportunity is for us as a business. And we made sure that our organization is, uh, is fully aligned with that.
Do you see a lot of differences between the markets between North America? em, me, uh, Eve? We're very similar.
Um, I think when we look at what we do for customers, what we solve for customers, there is a lot of similarities there, right? Um, uh, companies struggle with the same challenges. Uh, we tend to help them hopefully with the right initiatives.
And I, I, I think we, we do a good job at, um, doing that in a, in a sort of standardized fashion between the regions. One of the very, uh, uh, obvious differences obviously is that in Europe, uh, we have all these different countries. And, uh, that means companies built themselves, uh, in accordance to, uh, all these different countries.
Meaning you have one central hub, but you have all these different legal entities that often have autonomy in buying or decision making. It means that, uh, we have less of a consolidated, uh, opportunity in, in Europe and in APEC versus a R where companies tend to be a little bit more centralized. They're a big company in the us right?
Um, and they operate from one central environment. Uh, that is a, that is definitely a difference in what we see in the market. It, it's a challenge and both an opportunity for us.
'cause it also means that, um, we have more opportunities in Europe to influence multiple people that have something to say about what we do and how we can help them. Whereas in the US it's, uh, it's, it's, it's more centered around a couple of individuals. So we have to make sure we, we, we do the right thing for those, for those people.
Uh, A different sales model. It's, it's a, it's a different sales, uh, method. Indeed.
And, um, the other thing that I find interesting, uh, and this has been true for Atlassian, but also other companies that I've worked at, is that decision making, uh, seems to be different. Whereas in, in, in the Americas, the people that make the decision to potentially buy a certain technology, they tend to choose the best technology out there, right? They're always looking for competitive advantage.
You choose the best solution that could make you go fastest. Where in Europe, typically people are like, we need to find the right balance solution. So it shouldn't be too expensive.
It should do what we wanna do, but let's not go for the highest tier that we can potentially buy because we might be spending money the wrong way. So it's a different, uh, val, uh, validation process. I would say.
Different philosophy, Different philosophy. Um, yeah. So AI's the big topic.
It's one of the areas of that and data privacy, a lot of regulation, different frameworks, different requirements in, uh, eu, Americas even, you know, the, uh, localization of data where it's stored all big questions for enterprises that they have to deal with. Yeah. Um, it's very interesting actually, because you, you sort of combine those two topics, right?
AI and data privacy. It's, you would, you would think that's, oh, we're gonna start this whole thing all over again. So far what we've seen is that the hurdle that we had to take to convince customers to move from on-prem, uh, software deployments to, uh, to adopting SAS technology, right?
It was all about that. Um, and it was often was the majority of the engagement would be around security and data residency and all the things that come with that. Nowadays, when we talk about ai, you would, you would think that you would get the same questions, and we do get the questions, but the appetite from customers to just get over that to, because they're so eager to start leveraging the power of AI in their environment.
It's a different discussion. They wanna be educated. We have to do the right things, obviously, but it's not the hard discussion where we have to sort of drag them along.
It's more like, give us the right information so we can start leveraging the power of ai. So it's an interesting changing landscape. Um, I, I do feel that, and this is not Europe specific, but more globally, that the majority of people are still expecting that there will be some sort of a break or hiccup or delay.
That at some point people are like, oh, have we, have we gone? And this is not, again, this is not Atlassian specific, but more AI specific. Have we have, have we stayed within, within the sort of the borders that we set for ourself?
Or is AI now going everywhere, right? People want to wanna continue to feel that they are somewhat in control. Uh, I think that's gonna be the next big discussion that we will have with the majority of customers.
Uh, you know, in, in the sales organization, the transparency philosophy of Atlassian has to be a big plus. I would think you're very much more a threat disclosing with customers what you're doing. Yes.
Um, we've, we've always, you, you've known Atlassian for multiple years, right? I mean, we're always very big on our company values. And, uh, they've not changed and they're still the same.
And, and they are guiding principles for us on how we build our business. And I think transparency and just being upfront with certain situations, right? We have a value open company, no b******t.
Um, is also, it, it, it also translates to how we do business and how we share information, how we wanna make sure that our customers understand what we do. Uh, so yeah, we always try to share and disclose as much information as we can to make sure the customers know what they're getting into, um, and, uh, and are not confused about anything. And, and that, that works really well.
'cause especially enterprise customers, they, they might have been burned in the past by adopting technology that, um, eventually when they dug deeper, um, was a little bit different than what they had expected. Let's call it like that. Yeah.
Uh, how has the economies changed and how's that changed how you approach customers and, Um, o obviously, if we take a couple of years, all right. There was this incredibly unpredictable situation during pandemic and post pandemic, right? We saw massive growth, and then we saw a lot of challenges, let's call it decline, uh, uh, uncertainty in the market, which was, was also impacting our business.
Um, interestingly enough, the bigger organizations, they have long-term strategies, so they were a little bit more consistent than, uh, than our s and b markets, right? Our s and b markets have a very direct response to the market cooling down, meaning we hire less people, or we maybe layoff people, which has a big influence on how that market behaves. Whereas enterprises, they, they keep, they kept marching forward.
Now, certain industries obviously suffered more than others. So, um, yeah, we had to, we had to work with them, um, to figure out ways of still making progress on, on how, how they optimize the way they work, right? But the, the goal there was not necessarily to sell them the next product, the goal there was to how can we extract more value from the things that we've already purchased to make sure that it contributes to our bottom line as a business, not the Atlassian bottom line, but their bottom line to help them through those phases.
Um, I think we bounced back from that as a market. I think in Europe right now, we see certain markets that are, there is uncertainty again. Um, um, interestingly enough, one of our biggest markets in Europe, Germany, right there, there, there seems to be a lot of uncertainty in Germany right now.
It's, it's probably the next to Poland. It's the country that is closest to the, to the war, right? From a geo perspective.
So there's, there's that, there is elections in Germany, there's elections in the us right? The, the, the, there's a lot of things that are happening there. And in a big large economy like Germany, that has an effect.
So we're seeing more and more German customers raise their hand saying like, we have to, we have to strategize about how we move forward, uh, because we don't, we don't necessarily know if our budgets will remain the same. Mm-Hmm. That is part of doing business with larger organizations.
That's what we're ready for. We will have good conversations and we'll figure out a path for both of us to continue to, to move forward in a partnership. Well, and partnership's, the key word, it's not just selling product to customers, right?
That's how you lay out that strategy or match your strategy to their, so you can help 'em Yeah. Achieve that. I, if you're in sales, partnership is always a, a word that you sometimes hate and sometimes love, right?
When a chief procurement officer talks to me and wants to do a partnership, I know what he means, right? And when I try to sell some something to somebody, I call it the partnership, but it's like, I wanna sell you something. So partnership is always an interesting word, but I think the way you describe it is, is, is exactly right.
It, it needs to be a situation where, uh, together we find value in the things that we do. If the value's there, right, the value has to go both ways. If the value's there, that's a partnership.
Um, if the value goes one way, it's a partnership in one direction or the other direction. So that's my philosophy. I try to make sure that my people see it the same way.
So we are receptive for certain market conditions. We wanna have a conversation. At the end of the day, we also run a business, so, right, right.
There's a limit to what we do, but we always look for a, for a high value situation. Great. Well, it's great to get your perspective on things and, uh, nice to meet you and have likewise part of the conversation with our audience.
So thanks for joining us, Chris. All Right. Thanks so much.
Great. Good luck with the rest of the show and thanks. And the global enterprise sales role.
I'll do my best. You bet. All right, thanks.
We'll be back with our next guest. com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content, featuring breaking news, blog posts, podcasts, and more. com to learn more. com, where the world meets DevOps, This is Textron tv.
Hey guys, thanks for the throw. We're here with David Lee, who's CEO for Iveta. And we're talking about, well, just how might we apply AI to improve national security and public safety, because, well, there's no shortage of use cases, but some things might be a higher priority than others.
Dam, welcome to the show. Thanks, Mike. Thanks for having me.
I think a day doesn't go by now where somebody doesn't talk about my great new thing for ai, but, um, how do we kind of think about this for the greater good as it were? Because there are a lot of, uh, pressing issues as it relates to national security and public safety. So from your perspective, are there things that we should be more focused on than others?
Well, that's a, that's a big question there. National security. Well, from our, from our experience as, as you know, the, the company doing business in the field, we, we do business with, with municipal police agencies all the way to, um, uh, regional and national, uh, security agencies, both our domestic and international, from my experiences at all levels of, um, security or, or public safety concerns.
You know, I think what everybody's looking to satisfy is the lack of personnel and ai, or let's say technology in general, is aimed at force, multiplying the resources that these agencies currently have. That that's a start there. Now, before I even jump into what does AI do, I wanna share with you, that's our real world experience.
When we do meet in front of these people and in front of the agencies in the conference room, it's not about, the cool technology is I've only got yay amount of time. I've got yay amount of people and, and, uh, folks in the field. What can you do that, that's really the, the sincere mentality, you know, not, there's no time and, and energy.
So we gotta multiply force, multiply resources that are available. Are you seeing any particular AI technologies gain more traction than others because either A, maybe they're value is higher, or B, they're just simpler to I implement. I mean, where are we in the curve and what should we expect to see?
Definitely in the forensics, uh, utilization applications such as investigation, uh, going back after the fact, post a report, um, post an incident, uh, up to up to now, um, businesses and agencies across the world are still spending, and I'll use the word wasting way too much time in investigative work. What does that mean? Uh, sorting through docs, looking back at weeks, months of video footage and not knowing exactly where to start.
So we're talking days, days, forget about hours, just days and weeks of man hour to, uh, satisfy some of these, um, search and, and investigative work. AI has really, um, come and, and save the day. So, say, when it comes to, um, uh, investigations, how is it?
So Aveda being the, the video experts, we Aveda AI is a video search platform fastest in the world, right? I'll add, what do we do? Imagine an agency or any, uh, organization might that already has existing video surveillance cameras or video that is brought to the agency for investigation purposes.
Well, up to date, we, the officer or humans have to calm through this data and hopefully find something that matters or something that's relevant. AI technology, such as what Aveda offers, is imagine just telling the ai, I'm looking for a person in a brown polo, um, male driving a blue Honda. You could do that.
And guess what? In seconds, one or two second of that six month worth of video, you have highest probability pop up right in front of your screen. Now, you tell me that's highly impactful to today's, uh, uh, workforce for law enforcement.
We will hear a lot of concerns about, uh, preserving civil rights and all kinds of issues. How do we strike a balance between, you know, solving the issue that we don't have enough people to enforce the law to the extent that we probably should be doing, but, um, we have this concern about, you know, making sure that we don't identify the wrong people for the wrong reasons. So where's the, where's the middle grant?
Yeah, uh, very good question. And being in the video surveillance in industry for over 20 years, Mike, you can imagine the, um, uh, uh, press interviews and questions that I get pertaining privacy. So I'll answer this confidently given technology there, there's always the, um, the, uh, misconception that technology does.
The negative technology goes out and intrudes on your you and i's privacy. Um, the fact of the matter in the real world of operation, um, there's not enough resources. And really the entities that are, uh, here to support and protect us don't have the time to, to hear.
Uh, let me tell you what that means is, and I, I, I'll speak very bluntly, we all think we're so special. We all think that, uh, people love looking at us. But no, we ourselves post ourselves on Facebook and the rest of social media.
But in the public safety, uh, sector, nobody has time to see you do what you do in public. But I can tell you one thing where technology comes in and assists these, these much needed, uh, uh, support from the professionals, is that when we do need to find the bad guy, the AI or the technology comes in and assists at a much higher pace. Remember, we don't care who you were before you swipe that car before you cross the street or tossed the i, you did something bad spray painted on a bus before you did anything that, that brought attention to yourself.
What the AI's doing is say, Hey, this person looking like this at this position and time, I need to find that person. I need to find this exact criteria. Technology comes in and says, here's your highest probability, and guess what?
It still requires the officer to go and verify view, go catch, apprehend, whatever the physical requirement is, and that's the proper, um, I would say explanation or description of how the technology works. We talk technology, and by default, people think, oh my God, the technology's gonna go and in invade and intrude on our privacy technology doesn't know what to do. The technology is, is just there.
And yes, AI has automations, and it can, it can do a lot of things, um, autonomously, but granted, it's still by direction of the human and, and, and the professional sector and the official sector. From my experience engaging with all of them, it's, it's sad that they have to listen and hear about all the misconception, because nobody has time. Nobody has time to deal with that.
We barely have time to get the technology to actually function in our favor properly. So nobody has time to worry about you picking your nose, uh, uh, whatever it is that people are afraid of when it comes to privacy. Is it getting easier For various enforcement agencies to collect the data that they need?
Is there more video out there? Is there more audio? Because, um, you know, depending on what city you're in, I don't see cameras everywhere, and I don't see every one of those cameras belonging to the local police department either.
So, um, where's the data coming from? Very good question. And, um, you are correct.
Uh, pertaining more domestic United States, um, you know, people are contributing data. There's, there's cities that have what we call, uh, public private partnerships. That's when, uh, law enforcement partners with private organizations and enterprises, uh, for example, let's say a a, uh, local gas station, you know, already has cameras.
Um, and that gas station contributes to the city or law enforcement by saying, Hey, I love it. If I get a nine one one call in my area, by all means, those cameras that are pointing outward, use 'em, please. 'cause I I need you to respond properly.
You know, we, we forget that we as citizens prefer that in times of, of emergency or crisis, we want to help. And that's, that's how, let's say agencies are getting their data. Now, I tell you, nobody's combing the streets intruding on any privacy, because technically we can't.
It's more difficult than one might realize. You don't just hack somebody. Hacking is a widely used word, but it's not easy.
You know, one in a million guys know how to do that. It's, and they don't go out there and try to hack you or I, right? We're, we're not special.
So we're pretty safe. But when it comes to data, it is still contributed data. Mike, you know, these agencies are not calling out there.
Um, you know, I want your data. Gimme this, gimme that. And when we do have public cameras, you know, it's, it's, um, public works.
It's for traffic, it's for traffic counting, it's for red light, yellow light, green light. And now with technology, the good news is that seeing existing public works and traffic infrastructure can now assist law enforcement because why It's no longer just turning our lights green or red anymore, or it's not, it's no longer just hounding how many cars past the, the intersection. It can now help identify how many motorcycles, how many four wheel vehicles, how many 18 wheelers.
There's so many things that when it, when this appropriate data is collected, it helps everything from city maintenance, public works, and public safety. You know, if there's a lot of 18 wheelers going through this intersection, we need, we need special lighting, special signing so that our kids don't cross this every day or build a bridge around it. This is what I'm seeing when it comes to, um, government agencies leveraging technology.
It's, it's rarely, uh, conversations about, uh, I've got a bad guy, I need to seize them. That's, that's a given. We do that every day.
And if technology can assist, you bet it's, it's gonna make it more efficient. And again, we need force multipliers. There's not enough people out there.
Do we need clarity on what the definition of privacy really is? Because, um, you know, when I look at common law basically suggests, you know, anything that happens in your home, you're king of your castle, and that's private. But anything that happens outside your house is in the public venue, and therefore is common knowledge.
And, uh, back in the day, your neighbors knew where you were going and what you were doing. And cameras and various public places are no different. Mike, I agree with you.
A as a citizen and just as a normal dude walking around, that's what I believe. You know, that's what I believe. And, and I'll say it again.
I think we expose ourselves, uh, more on social media than would any public sector, uh, presence. You know, we, we go ahead and self expose, but I step outta my house, and if there's a street camera, there's a store camera, we walk into the mall, we go to Disneyland, come on. It's, we're caught everywhere.
But why are those things there? They're safe measures. You know, if I go in, if I go around town breaking people's property, everybody deserves, the public deserves to know that I shouldn't be doing that.
And, you know, take me off the streets, will you? That's common sense. So do you think overall we might soon see a, a decline in crime rates and, uh, terrorism and all these other things because, uh, we are gonna have more visibility into what is happening around critical infrastructure or, um, for that matter, you know, just a plain old stolen car?
I would agree with you. I, I would answer yes. You know, it's, it's the, the old, uh, form of, of I think, uh, mitigation or just caution.
You know, there's areas in the country, cities and countries that implement red light cameras. You know, we all drive without thinking, but we hit up an intersection that has a sign, you know, photo in force. I think we all kind of, you know, put, you know, to the, the 10 and two, and we kind of look around and we slow down just by that near, uh, by human nature, things will be safer because we're, we're, we're more aware.
And that's, that's really what it is. And it, before you go and snatch something at, from a store, and knowing that store has technology, that whatever you grab, um, they're gonna know and they're gonna know it's you who did it. So it's that, you know, you're gonna think twice.
That whole, uh, um, uh, reaction of just people will think twice. And being in technology for a long time, I can tell you one, one thing, something else that does happen. The more sophisticated the technology, the more sophisticated the criminals become.
You know, we humans learn just like technology. So, uh, we just, it's a catchup game. But yes, if we deploy advanced technology and we, uh, um, you and I are aware that hey, this safety measures in place, we're either gonna feel more safe or we're either gonna be, uh, uh, on watch, you know, we're gonna be more careful.
Um, so yeah, it should deter. I think that the word I'm looking for is deterrence. And that's, that's ideal when it comes to functional technology.
All right, folks, you heard it here. We can't afford to hire armies of police department personnel and all the other folks that are required to go with that. It's just not feasible.
But we can take a bite outta crime using ai. Hey, David, thanks for being on the show. Thanks, Mike, for having me, And back to you guys in the studio.
Hey, Hey everyone, and welcome to another episode of From The Source with your hosts, uh, me, Turner. And hi, I am Brian Fox, And today's, uh, fantastic topic, Brian. Uh, it's going to be about, uh, the compliance and regulation remains and what you need to know, uh, in order to survive it.
Um, Brian, though, I love your hat. Yeah. Um, so last week was all day DevOps.
Um, and they made special hats, and, uh, and I was told I had to wear it, so I figured I'd wear it here today. Um, because all the sessions are still online on demand, so you can sign up and, and go watch them. It's like 24 hours, uh, of live broadcast stuff across what, like six channels.
Like, I, I don't want to do the math on that, but there's a lot of really interesting sessions. com. You can sign up and you can watch all of them on demand.
And I actually did the math for you. It's 180 individual talks, uh, across all of those tracks. So it's, it's some of the best of the best.
And, uh, I think you and I both also get talks. You can safely skip those, but absolutely do look at the back catalog. They're really, really good.
Um, but hey, so today's theme, uh, uh, on our episode is as governments and regulatory bodies worldwide continue to tie in their focus on software security compliance has become more and more complex, uh, than ever before. So, uh, in today's episode, what we really wanted to do was do a little bit of a fly by on some of the regulation that's been passed that's about to pass, uh, across the world. And what does that, what does that mean in term results, uh, compliance?
And finally, obviously we'll talk a little bit about what we've seen, uh, organization do to actually survive this sort of tsunami of our regulation. So why don't we, uh, start off by talking about, uh, my favorite, uh, part of the world, which is where I live, uh, Europe, and talk a little bit about some of the regulation, uh, that's, uh, been passed, uh, over here. Before we set them though, regulation in EU is like super complex.
Um, there's, there are acts, there are directives, there are other sort of elements, uh, over there. So why don't we, why don't we start there? Why don't, why, why don't we define, so what does each of these mean?
And then let's, let's do a little bit of a drive by on, um, some of the, some of the ones that we recently asked. Yeah, so I'm not from Europe, so I'll try to explain it and you can, you can, uh, correct me or confirm. Um, but, uh, I, I was confused about this.
So there's two, two main things, um, that have been going on in Europe in this space. There's the Cyber Resiliency Act, and then there is a related product liability directive. And, um, I was a little bit confused on that.
I didn't really pay much attention to the fact that one's an act, one's a directive, but it was recently explained to me that, um, an act is basically a direct, um, set of legislation that basically applies to the entire European Union. You know, it is effectively a past law. And, um, a directive, however, is more like a set of principles that then the member, uh, countries, the member states have to pass their own, uh, legislation or up their, update their own legislation to comply with, you know, the spirit of what the directive is.
Um, and so I think that's important because, uh, one of them would be sort of very uniform across the union. The other one might have country by country nuances. And also it takes time, once a directive is passed, there's a timeline for which then the, the country legislatures have to do their thing, so it takes even longer to roll it out.
Is that a fair description? I, I think that's a really, really good description. I think my high school, uh, social, uh, social matters teacher would be, I'm very proud of that explanation.
So basically, I like the states, the European Union is sort of a alliance of, of, uh, all its member states. And what they basically said is, Hey, we'll meet up, uh, in, uh, Sal and Strasberg and in a bunch of other places, and essentially we'll delegate some of the legislative, uh, ways. So an act essentially is sort of a very similar thing as a federal, uh, law over in the States.
It just automatically, when when an act is passed, it applies exactly as written across all of the member states. There's sort of no room for interpretation versus a directive is really, uh, more of a, every single member state should pass a law that fulfills these criteria and check these checks, these boxes. You know, every, every country can kind of tweak the act a little bit or the directive a little bit.
They can act their own thing. Some countries have more strict regulation than others in certain elements, but roughly, uh, roughly they need to comply with the demands. And if they don't, they actually get a very stern letter from the European Commission saying, you're not in compliance.
Uh, and you should go and fix that. So, um, I guess an analogy from a US perspective would be state law versus federal law. State law might apply locally, might be tighter than federal requirements, but federal law applies uniformly, uh, no matter what.
I think that's h yeah, we Don't have, we don't have the exact equivalent of like, all the states must pass the law, except in certain cases where the federal government might say, uh, the one that comes to mind is the old, uh, speed limit law, you know, and they would say like, if you, if you didn't have a speed limit that was capped at a certain amount, we're not gonna give you as much money for the, for your roads or something like that. So it was, uh, it was not a requirement. It was, uh, choose your own, but we're not paying you if you don't do what we ask.
That's the closest I Can think of. That's a very American interpretation. I, that's where we kind of differ.
We're all like, you know what control you shall do it or otherwise that will be, there'll be storytelling off which nobody wants. So, uh, so you mentioned two things there. You mentioned the Cyber Resilience Act, uh, and you mentioned the product liability directive.
And these are pretty huge momentous, uh, momentous, uh, pieces of regulation no matter what you, no matter sort of the flavor of it because, uh, each of them have just been cleared by the commission. I believe that they're just expecting, uh, sula on the line, the president of the European a, uh, council to site on the dot line, and then it'll get published into essentially the European Journal of Regulation, which makes it, you know, set it stone. Uh, and that sort of starts an implementation starting gun, uh, starting gun for about 36 months or so.
So the CRA especially, I think is pretty monumental 'cause it really changes the way the minimum security requirements for software and a lot of other things. So why don't you give us a quick overview of, uh, kind of, kind of what's, uh, embedded in there, because there's quite a lot of history in that. Yeah, I mean, there, there's, it, it's been quite a long time actually since I read the meat of it.
Most of where my focus last year was on trying to ensure that the CRA didn't in inadvertently penalize open source or, or worse cause open source to basically withdraw from the European Union market. Um, which was, uh, a pretty significant outcome last year that could have happened. We managed to change that and, and, and it's open source is now excluded more or less from, from the CRA, but the, the, the requirements basically lay down things like, you know, honestly sensible best practices is the things you and I talk about all the time, that not shipping with known vulnerabilities that are not mitigated, you know, having bills of materials.
Um, you know, there's a, there's a whole litany of things in there, but I think the bottom line is that failure to comply can come with pretty significant penalties, um, based on your worldwide revenue up to, I believe, uh, 15 million euros for failing to comply. So it's a pretty, pretty hefty uh, uh, stick. They're gonna hit you with there, potentially, if you're not doing these sensible things, It's, it is in fact 50 million euros or 3% of your global turnover, whichever is higher.
So, Oh, it's the higher it's, right. So It's an even sharper stick. Yeah.
Right. And, and so I think that's pretty significant in terms of getting, getting organizations to fa face the, the music and, and, um, and, and do some of the, the right things. Um, and there's, there's been a lot written a lot, you know, um, a lot of thought into the CRA.
And so this one as a directive, you know, once it gets published into the, the journal, as you said, 21 days later, it starts to come into effect, the actual penalties phase in over two to three years. Um, but that clock basically starts, let's say, a couple months from now. Um, once, once it gets signed and gets published.
Um, you know, I think the, I think the product liability directive, however, might be a sleeper changer. And it may, um, may have a much more profound impact, in my opinion. 1000%.
Yeah. So, so, you know, you've heard me talk a lot about, you know, my frustration with the industry not really doing the right thing for the right reasons and, and kind of, um, you know, uh, checking the box, if you will. And then when they screw up and all of our data gets leaked, you know, the, the downside is they buy us credit monitoring.
At least that's what happens in the, in the us. You know, like That's pretty much exactly what a, yeah, yeah, that's exactly what happens here as well. You know, have a, have a one year annual subscription to this paid for service that you'll automatically get, uh, rolled into a subscription to, Right?
And, and you've got 10 of them, because 10 companies have leaked your data all over the place. It's, it's a ridiculous situation where the, the cost of failure is not high enough for organizations to invest appropriately. Right?
So that's, that's my opinion. I've spoken and written on this for, for a while, and I think it's actually happening now in Europe, right? So the product liability directive is not actually new.
There are, there is an existing, uh, EU wide PLD, uh, for many years ago. But the, the important part is it carved out digital goods. So software, other things that were digital in nature were not included in that PLD.
What the change this year is, is basically removes that exemption and provides a little bit more clarity. Um, and so basically it means, you know, software that causes harm, um, that loses data, destroys things. Um, now those organizations, um, can be sued, um, you know, like any other product, uh, failure.
And so I think that will change the, change the economics quite a bit for companies will now have to focus not only on checking the box and being compliant like the CRA requires them to do, but now they will ultimately be on the hook for the final outcome. So even if you do all those things and you still bring a, a product into market that causes harm, or leach data, or does whatever, you might be susceptible to lawsuits. Now where it gets a little bit more complicated is because the European Union only can control what's going on inside their borders.
There's this whole concept of importing software and distribution, you know, and these things make sense in the physical, uh, goods world, but it's a little bit harder to get your head around in terms of the software, who in fact is the importer and distributor may be unclear. And so I think that's going to be where some of the nuances, um, you know, the PLD also pretty clearly excludes the makers of open source, but not when somebody includes open source in a product and then sells it or distributes it, they are on the hook for that, as I believe they should be. Right?
So if you're choosing to use a thing for free, great, but you're still producing a product, you, you bear the responsibility of that. And I think ultimately that's where it's going to change some of the behaviors for the better. Yeah, I think, I think it's a, it, it's very big mental change.
'cause up to this point, um, you know, the way that the software industry and liability it's worked is we also end user agreement. There's big indemnity closes there that basically say, uh, you know, you, you agree to basically waive all of our rights. It, you know, just, just like this famous Disney Plus case, like, hey, somebody signed on a Disney plus eula, so they can't sue Disney, the corporation, uh, for any of it aspects.
Uh, allegedly. So, so, uh, you know what the names, I guess Yeah, Like the liability li like, it, it's that, it's like that it, it's a contract, right? One way know what you're talking about it.
But somebody, I, I believe his wife got injured or maybe killed at a Disney park, and they were trying to claim because they signed up for Disney plus the video stream like Two years ago, Two years prior during some trial, that they basically waived all indemnification against the company for all things. Um, I've lost track of where that is, but it's certainly, um, an, an aggressive interpretation of that law. It, yeah, and it, it, it's sort of a good example of how it actually works in software when you think about it, right?
You know, we, we signed these U list, uh, and that EULA basically always without exception, says, Hey, by the way, you get a software as is, it's up to you to maintain it. Uh, no guarantees. And you can't sue us for any losses because it's up, it's up to you.
So really what each of these laws to me, uh, kind of mean is, um, first of all just, you know, find any piece of electronics. Like I've got this wireless charging pad here, uh, that's sat at my desk. Uh, you'll actually usually find like a little stencil, like a CE stencil, uh, on each and every one of them.
And that's like, like in here, as you can kind of see on my video here. Um, that's really what they're applying to software. Now, every piece of software made available in the European Union market, regardless of where it was manufactured.
You build it in the states, you put it in, in Europe, you're gonna need this, uh, you build it in Europe, you're still gonna need this. It needs to attain per version of software a CE mark. That's, that's, that's in and itself a already a pretty interesting thing.
It's that you have to sort of self certify every single one of your releases to be compliant with those security best practices that, you know, we've, we kind of think are pretty much aligned with industry best practice anyway. But if you haven't been thinking about it now, you actually genuinely do. And what the product liability directive does is if somebody then takes your software, even if they misuse it and it causes data loss, like let's say, I don't know, they like feed all the fields really stupid stuff, and they like manage to craft the server and whatever, if that leads to data loss and you didn't certify your software up to that standard, that means that you can be sued for, I think it's limitless li uncap liability essentially in a court of law.
Like even if they misuse the product and used it wrong, but you manufactured it wrong, you're liable. And that applies in any other good, like of course, if I crash a car by speeding, and it turns out the car was mismanufactured, I'm gonna say the manufactured cord, that's like a non brainer. But extending that line of thinking now on the software is, is, is what's happening with these regulations.
And that, I think is going to be the big, uh, big sort of, uh, uh, hitter that's gonna really start making this, uh, sort of regulation sinking in. I think we've had sort of industry best practice and self-regulation for quite a many years, and cloud company is doing really well, some less so well, uh, but to have something this deep, like essentially it's all the regulators, you know, especially in New Europe, but also in the States, you guys have had passed some fairly similar laws and, uh, Jenny from C made some very similar liability sounds, uh, as well in public, uh, engagements. Yeah, but we're, we're, we're only just talking about it and only very right in circles about it.
So I'm, I'm particularly, particularly interested to see how this rolls out. Um, uh, in, in Europe, of course, it's gonna take several years. I think, um, the, uh, it's gonna take two years, or at least up to two years for the member states to pass their own version of laws.
Who knows how long those things will take to phase in if they're, if they're, if they apply, um, instantly, if there's backwards com, you know, uh, compatibility or any, you know, anything like that, that happens, um, uh, we'll, we'll remain to be seen. The other interesting part is it doesn't stop there. Uh, we were chatting before the recording, they also, the draft AI liability directive.
Um, and, um, that one is still very early. Uh, I think they were waiting to see how the PLD and some of the other things unfolded, whether they even need it for reasons I don't completely have my head around. Um, apparently they feel like they need additional liability directives on ai, which is a little per perplexing to me because AI is software and it's a product, and so therefore it seems like it would be covered by default with the new change.
But I'm sure there's some nuances there. Um, the current draft, I'm told, does not have an exclusion for anything open source. So we're kind of back to the, the starting point.
But, uh, I think the community feels pretty good that, that those exceptions will be made because it needs to be aligned with the PLD and the CRA. It wouldn't make sense for it to be more punitive around open source. Um, but, you know, uh, as with all things shifts, the battle continues.
Um, there's more coming more to figure out. And, But, and, and that's not all The, the, the bottom line for companies is, you know, if you've been in denial that nothing's gonna happen. Especially if in you, you're in the US and you feel like, yeah, Congress isn't gonna change the liability laws and the contract laws to, to, you know, preclude you from disclaiming liability in the eula, you might be right.
And also, it probably doesn't matter because Europe is, is kind of leading the way on the liability side. And basically every company is a global company these days. And that means you're gonna have to pay attention and follow these regulations.
So, you know, I think it's sort of a matter of, uh, how quickly can you turn your own organization around to be in a place where you feel like you, you are ped from both A CRA and A PLD versus how long is it gonna take to phase? In many large organizations, it may take them longer than two years to clean up their mess. Um, and so that means you're already behind the scenes, you behind behind the time.
Yes, you've got two years before the hammer comes down, but if you're not ready by then, good luck to you. So I think that's the kind of takeaway, you better get started now if you're not ready. And if 1000%, I mean, um, I mean, it's like DG PR to be honest.
Uh, you know, I think, um, it's gonna follow a very similar path. I think, uh, a lot of organizations will forget about it for a while, then they'll come back with a bang. And when the first big signs are coming out, that's really when the big, uh, sort of drive for change is gonna start happening.
Um, and I wish, you know, we're, we're actually, uh, uh, starting to run out of time for this episode, but that's not even all of the regulation that's come up recently. Like in two days time. At the point of this recording, we're going to see something called network and infrastructure directive, uh, uh, pass in the u in, in the eu.
And what that already does is take some of those requirements from the CRA and applies it vertically to some sort of more societally critical industries. You know, things like transport, energy, banking, financial markets, postal and careers, but also digital service providers, online marketplaces, search engine, social networking, uh, they called computing seem Like all of a songs, Basically all, all of the things, I mean, I, I could be reading this list, uh, forever and ever. But basically this, there's also something called the, the Digital Operational Resilience Act, or Dora, uh, uh, which has another directive that's been, um, uh, that's been passed to, uh, in past financials.
Basically what all of these are saying is there's now a minimal level of cybersecurity that's expected of you as a service provider, as a software manufacturer, as a product developer. And if you fail to demonstrate that you've done those things, you have those, uh, steps as well as the policies, as well as demonstrate that when you built the software at the time that you did all of those things, the regulators are going to come after you. I think that's the big sort of takeaway.
So if you haven't been thinking about, thinking about having some minimal level of understanding, I think now is high time. Uh, otherwise it's gonna be way, way, way too late. Yep.
I, I, I think that's exactly right. Right. Well, um, uh, uh, one of the things, uh, that you can actually do if you wanna see, uh, what you, what you should do is we've actually published a lovely little regulations up, uh, because there's so many of these, and each of them have these, uh, have these sort of superfic requirements.
So we've, uh, published this sort of very handy, uh, checklist actually, uh, that you can take a look, you know, kind of go through each of the regulations, kind of tells you a little bit about what you need to do. And on the flip side, we also have a pretty picture that kind of shows you what you need to be doing, uh, across the SDLC. So we'll put down on the show notes, go, go take a look.
There's a lot of things to be understanding there, but Brian, um, any closing thoughts, uh, part on this? I mean, it sounds like a big tsunami of our change coming our way. Yep.
Um, you know, it's, it's time to get out of the denial phase and into acceptance phase and start getting your organization ready. I mean, it's just as simple as that. I didn't have said it, uh, better than that.
And I still am jealous because they actually are ran outta my size, uh, on that cap. So I, I'm still waiting for my, so this what makes you happy. If I heard you, I, I had another one here with us.
Oh, mad well on that bombshell. We'll see you next time. Alright, bye everyone.
Welcome. Call Cloud Native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud Native now. Hey everyone, welcome to the latest episode of Marketing, art and Science. I'm CMO advisor from the Peach Group, Lisa Martin.
This is a show where we really get to sit down with CMOs weekly and understand how they're balancing the artistry and the science of marketing to convert those prospects into really vocal, loyal advocates. I'm so pleased to welcome my longtime colleague, Lynn Lucas, the CMO of Pure Storage to this episode. Lynn, it's so great to have you on the show.
Thank you for joining us, Lisa, it's great to be here. Thanks for inviting me. You have such an interesting background.
I want the audience to understand CMO of peer storage, as I mentioned, but walk me the audience through how you got there, because your, even your education is like such an interesting topic. Well, thank you. And you know, I think my story proves that you can start in one place, but then just let your passion take you where, uh, it should.
So I did start out, um, as a double E degree from uc, Berkeley, but after a summer job of coding, which I thought was my lifetime love, I realized I really wanted the interaction with people. I went, uh, back to school, heard from a, a colleague, uh, or a student one year ahead of me, and she had done this thing called technical marketing, and it just fascinated me on how I could take my technical background, but helped turn that into what does that mean to a salesperson or a seller? So, that's how I got started.
Went into, uh, the original Hewlett Packard as a technical marketing engineer, and over the course of my journey have been at multiple all B2B high tech companies, large and small. I would say the consistent theme is just building and growing businesses. I love that it's fun to do.
I always love to hear those backgrounds that are kind of zigzaggy, um, because most of them are, it's, it's really rare. I don't know about you, but it's really rare for me to meet someone in marketing as long as we've been in marketing who actually has a degree in marketing. There's always different, different backgrounds, life sciences, double E, computer science, whatnot, that this gives, I think marketers so much more, well-roundedness in terms of being able to lead marketing organizations and really impact the business.
Talk about the, the vision. You've been CMO at Pure, what, nine months or so I have. Yes.
Walk us through your vision. What does that look like? Well, for me, vision always first is grounded in the business strategy.
So, and I agree, I think marketing and marketers are more well-rounded when they come from different places. But what we want to do, and what I always, uh, ascribe to is take those first 30 to 45 days, do your listening tour, and understand the context of the business. So here at Pure, we are doing incredible things, disrupting the storage industry, the oldest, I would say legacy part of the IT stack with a platform and an as a service approach.
And so our marketing vision based on that is to really drive awareness, especially in these times with AI and cyber attacks, that your data storage platform is an advantage to you if you have the right one. And to reach those higher level buyers that today, you know, let's just be frank, they don't think about storage because they don't see the connection to the business. Yeah.
So our vision is to be that premier innovative provider of an as a service data storage platform. And Pure's been innovating in this space for many years. So it's just an honor for me to be here on this next step of the journey.
Love that. Let's talk now about the science and the art of marketing. Something that you and I have spoken about before is that we both love the fact that it's been become so scientific the last 10 years or so.
How are you leveraging, let's talk about the science piece first. How are you leveraging data science to become proactive so that you get that message out to the, the customers that, uh, why they should go pure, why it's important, especially from a cybersecurity and AI perspective? So I could talk about this forever, so you're gonna have to, to keep grounded on this.
It's one of the core reasons I went, uh, into marketing is that blend of the art and the science. And it is so great with all the tools that we have. So we have a data scientist team here at Pure that is fabulous, and we use data science in every phase of the customer journey.
So from really understanding what are the highest TAM accounts we should be targeting that are ripe for our solution, highest propensity to buy, also, when are they ready? We all know that purchases in IT are going to come over some cycle or there may be other priorities. So we're using that to really develop propensity and, uh, information for our sellers and bringing it to them.
And then we're using data science to really understand what content is resonating the most with different personas. We're selling to seven different personas, and we really wanna understand what is resonating. So that's a really brief overview, but we're very grounded in data and the metrics to inform our marketing strategy and continually adjusting.
I love that, what you just described as data scientists foundational to marketing at Pure Storage. You talked about seven different personas, and as consumers, and this blends into our business lives, we just expect the content that we're surfed up is going to be relevant, contextual, um, personalized in a non-creepy way. And we have, as marketers these tools now that allow us to do just that, to really stay ahead of the competition to differentiate.
Talk a little bit about some of some of the key top line metrics that you are delivering to your stakeholders. Yes. And, and if I can, if I can just go back one thing before we get into the metrics, I think, um, and this is the fun and exciting and super challenging part of marketing, is the tools are often there, the understanding of how to employ them and the change management within your own marketing organization, um, and change management in the c-suite.
I mean, let's be candid, right? Marketing today, I believe is we are media houses. And if you are not a media house, um, is going to be very difficult to win in your industry because to your point, it's not B2B or B2C, we're all human and we're expecting that personalized content.
Yeah. So, uh, to the metrics, right? And speaking of c-suite, you know, what do they care about?
Top line growth, top line, uh, revenue, and, you know, cost of of sale, right? So I think let's ground ourselves in what the CEO, the board, the CFO are, are looking for. And that's what, uh, we support.
I am a partner to the CRO and this is what we are driving together. What gets very interesting is the metrics down a level or a couple of clicks, and we're looking at what's the, uh, really when you start to talk about, uh, a business where you have multiple personas, you know, there's a lot of different, uh, metrics that you can start to look at. Are we reaching all of them?
Do we have enough in our database? Are they engaging? What's the effectiveness of the content?
What is the ROI, uh, overall for my campaign? These are the things that I am tasking my leaders with, really at their level, looking at that one click down from the business metrics and then their managers with how are we doing at the tactic or the channel level and continually driving efficiency and improvement. So it's a broad range of metrics.
We could probably spend a whole podcast looking at that, but I think for your listeners, really you have to ground it first in what the business cares about. Absolutely. That at the end of the day, that's what's most important is how is marketing moving those levers there, pulling on data science, pulling on the artistry, um, to really inform the brand so that ultimately those personas are given exactly what they're looking for and as close to real time as possible.
That's really kind of where the sweet spot is. Yeah. How would you, would you say, sorry.
Oh, go ahead. Go ahead. Well, I was gonna say, so we try to, you know, to combine the two topics in terms of the metrics and the data science, you know, as an example, in an existing customer, how am I demonstrating to the business that I can provide, uh, timing on when that customer's ready to buy or expand in a solution, and then the efficiency of us delivering that to the seller to shorten the sales cycle.
So those are some of the ways that we're really looking at how do we combine the metrics the business cares about with the data science that we have. How would you say the data science piece is helping to inform or evolve the pure brand? I've known Pure for a very long time.
It's always been very bold in its marketing, which I've always admired, but how, how does the, the, the science piece come in to help from a brand perspective? 'cause we think often a brand is art. Yeah.
I'm so glad you love the Pure brand. I mean, again, uh, just an iconic challenger brand. And see we're wearing the orange, uh, love.
Yep. We stand out in a sea of blue, uh, in tech. Me too.
Well, the data for the brand is critical, uh, with a platform approach and as a service, we're really reaching the VP and the C-suite who are really interested in a new approach. Like, why do I not think about this part of the IT stack in the same simple way I would a collaboration software or my CRM or my virtualization or my cloud? So that's where we're going to get those VPs and C levels interested.
We're using data science, again, to really understand for our target profile of who we believe is ripe for our solution, their readiness. And then we're measuring lift with our brand approach. We're also doing really classic things.
We've been talking about in marketing for a long time, got multiple, uh, versions of brand campaign messages running at the same time. How is the science saying, uh, folks are reacting to that? And we're really drilling into the detail.
Is that by geo? Is it by industry? Are there differences?
Is it by VP versus c-suite? So we're really baking all of that into our brand approach and, uh, being quite agile and and tuning our approach based on that. Sounds like it could get, I mean this is gonna sound silly, but very scientific, very prescriptive down to the persona level.
What's, what messages, what colors, what content is resonating with them to ultimately help them on this self journey that they're probably on before they even get to a pure rep to understand, yeah, we need to be talking to Pure Storage. This is absolutely critical for us. Yeah, that's the goal.
We are trying to really drive that awareness so that it becomes easier for our sellers to get that response, to get that engagement. I mean, as a csuite myself, I can tell you there's very few emails or phone calls that I pick up, uh, for, uh, you know, MarTech stack items in, in our part of the, uh, world. So we're really focused on that.
Are we, uh, there on that journey? No. We have so much more that we can be doing to, uh, make this really efficient and get that reaction.
And I, again, I think that is applying a lot of what maybe has traditionally been thought of as more of a a, B2C kind of a emotion. But we can use all these techniques here in B2B to really stand out, um, uh, you know, with the customer, which is our goal. Absolutely.
How has the MarTech stack that you've implemented, that Pure has been working on for a while, I suppose as well influenced and facilitated the sales alignment with marketing? Because that's something that we talk about a lot as well. It's challenging.
Um, but I think nowadays there's so much more from an observability perspective that sales can get because of the marketing science that's behind it. Yeah. You're so right on this.
So have a fantastic, uh, marketing ops team, and you hit the nail on the head. Uh, you know, I think where we often continue to forget both internal to companies and with our external customers is, um, the tech is one piece of it, but there's the change management, the education. So we have progressed quite far, uh, in the down the path of moving to buying groups, uh, which is not focused on a single lead that we would pass to sales.
But as you might imagine, uh, for most high tech B2B sales of any consequence, there's multiple people in that sale from maybe VP of IT to procurement to maybe finance, you know, folks in the IT team. Um, that's been pretty, uh, natural conversation with sellers. But then the action of how are we delivering that information?
What do they do differently? What does our SDR organization do differently? That's the area that is really critical for marketers to be hand in hand with their sales organization.
And so what it has done, and it's fantastic, is we have, um, joint meetings regularly on how we are transitioning to this. And it's really brought tighter alignment. Uh, and I will say that pure sales and marketing already had a very strong relationship, but now we're in this joint go-to-market conversation, and it's really facilitated it.
So in a way, the tech stack has facilitated us getting even tighter on how we're going to market. And that's so critical. 'cause at the end of the day, you both want to bring those customers in, convert them to loyal advocates.
Everyone's on the same page. With respect to that, I love how you really leaned into the science part of marketing. I, I think I love, like you taking complex, esoteric information and distilling it into digestible components is something that, that fascinates me about marketing something that I love and know you do as well.
But let's talk about the art piece because the sizzle the arts Oh yeah. And we talked about pure bold brand. I've, I've seen it for so many years now.
What is the art piece to you and how do you fuse or blend it or balance it with science? Yeah, and, and you have to have both, you know, because also we're, we buy as humans, we want a good story. We wanna feel good.
Yes, we wanna feel like we are, uh, doing right for our, you know, whether it be our team, our company, our customers. So, uh, it is an absolute and of the two, and certainly with brand, uh, we are leaning into the, the art and the emotion. Uh, one of the things that I, I learned, uh, back in the day is really how impactful a brand can be when it taps into that emotion.
And, you know, let's be, let's just be honest, right? You know, with all the tools that marketers have, um, and thinking about it and how much they are bombarded with all the messages from vendors, if you have a really functional brand, very kind of product spec feature out, are you really gonna break through the noise? Versus if you can pull a story, pull on a heart string, you know, can you rise above and, and grab their attention?
And so Pure, I think, has done that well over the course of its history today we're doing that. Uh, and in particular, you know, touching on a theme that is, is really emerging around the globe, which is that of sustainability. Um, and how can we solve a business problem and also help with the sustainability aspect, which, uh, may be part of the business's need, but may also just work with the, uh, the emotion of I'm helping doing good, passing it forward.
So, uh, watch for our, our newer ads that are coming out, um, on sustainability. And that's where we're really trying to tap into that emotion to bring the awareness of, of Pure's entire, uh, platform and, and the reach in what we can do. I'm so glad you brought up the emotion piece because it's critical from a differentiation perspective.
I think you hit that nail on the head with tell a story that evokes a response from me, a prospect when you talk about sustainability. A a lot of, a lot of, uh, customers I interview have sustainability requirements and initiatives within their organization such that they're only gonna be working even at the RFP level with companies like Pure who have, aren't just talking the talk about sustainability, but actually have the data to demonstrate how the technologies that they're delivering are helping organizations to meet their sustainability objectives. So I think that emotion piece that you hit on is, um, is unique to pure, um, but incredibly important.
Yeah, and, and you know, here's where, if we come back to blending a little bit of the data science, uh, you know, sustainability overall as a topic is maybe a little stronger in Europe for some obvious reasons in the us. Uh, it's there, but it is more around power and space right now. And so yes, understanding, uh, the slight differentiation and message can make a massive difference in your, your campaign, uh, and tying it, right?
We're tying it into the hot topic of the moment. And I will say, you and I talked about this, it's not just the moment, uh, ai, right? We're at the absolutely screen of this very long journey, uh, for all of us on ai.
And that has an incredible impact on power, uh, consumption in the data center. It does, it does. It almost comes full circle from that perspective.
Let's now switch to talking about emerging technologies like ai. You know, you've seen a number of big waves in technology in your time in the industry. What, where does AI wave to that point, right?
And where, but where does the AI wave fit from your perspective? 'cause we, we, we talk about this all the time with customers, with clients, with the, the mainstream media, and people have this laser focus on AI and all the investments going on and wanna see where's the ROI, we're not there yet. We're early inning.
So what do you see the AI wave compared to some of the other waves like mobility and wifi and the internet, for example? So I think you just nailed it, right? Uh, this, uh, wave is, you know, as significant as mobility and the internet, if not more, right?
Honestly, you're reading many of the same things that I am that is saying that it is much more, uh, impactful, but it certainly is as impactful and like these other waves. It, it, we are at early innings of this journey, uh, both for how our customers use it, as well as how we use it in marketing, but it is, it is not, uh, going away. And I think there's been a little bit of, you know, are, are we, is it overhyped?
And certainly that happens with these tech cycles, but, uh, it is here to stay and it's fundamentally changing everything we do. So it's a big focus, uh, both external in terms of how we help our customers be AI ready and also internal in marketing. How do you, you just said AI ready, I, I wanna, I wanna kind of pivot on that for a second.
How do you, how does prc what, what is AI ready? Because customers, you know, we go to so many technology conferences, you and I, Lynn and, and AI is part of every, pretty much every, um, theme, every keynote, every presentation. It's, it's their, so kind of the fear of AI washing and the me a lot of the messages to, to the prospects and the customers are, if you're not in AI right now, you're too late.
You're already behind. Do you think that is, um, a, a sense that customers have in terms of how can I become AI ready when everyone's telling me if I'm not in it already, I'm too late? Yeah.
Well, I would say, uh, it's, it's never too late to get started. And again, we're in early innings, and if we take a page from the past with mobility and we think about when the first Apple phone came out, and can we imagine what we can do today with our phone, the apps, and all of the things that were invented with that? Yeah.
That would be the vision I would paint for, you know, we can't even imagine where this is going. Right? Right.
com. When we talk about AI ready, we're really starting to talk to organizations about, uh, their data storage strategy, their security around it, because of the, uh, intense use of data, what kinds of use cases they might be starting to think of, and how is there infrastructure an enabler for that, uh, versus something that's holding them back. So right.
Without double clicking into it, I think that what we see right now with customer feedback is they're super interested in it. They're just starting to really think through what are the bigger use cases. We haven't hit that wave yet.
We're really working still, I think in very early days on efficiency use cases and not the fundamental transformative use cases that I know are coming to all of our industries. I agree. I I believe they're on their way as well.
I, every time I'm on Schwab network, they always ask me, where are we with ai? Is it hype? Is it, is it a, is it a bubble?
And I say, you know, a lot of, a lot of organizations are in pilot faces to understand where, what are some of the quickest wins we can get right now? And a lot of that to your point is, is around the efficiency gains. I think every CMOI talked to, just talked at one an hour ago, same thing.
They're bringing in AI in their technologies and in their marketing and delivering significant efficiency gains, which eventually will make its way to cost savings. So when those investors and, and the street is looking for, where's the ROI of the AI investments we're gonna get there. Yeah.
But as you said, it's, we're, we're in the kind of the first lap, and that's okay, but we can only imagine, or we can't really imagine what some of the great things are to come, uh, where AI can be hugely impactful. But to me, from a storage perspective, you know, they go, AI runs on data Pure helps organizations to securely store that data for as long as it needs to be there. So in a way, pure is kind of foundational to organizations being AI ready.
Well, and if I were to add, not just securely store that data, but, you know, put it in a platform approach so that you can easily transition from training to inference and also do it with the incredible efficiency of flash, which is 10 x more efficient from a power and a space than hard disk. And given everything we talked a little bit about with sustainability, that is more critical than ever because, uh, many organizations do not have the room, uh, in the data center or the electricity and the water to cool. It does not exist.
And so we wanna do our part in helping organizations be able to take advantage of this incredible technology, um, but do it in a more efficient and sustainable way. You know, what I wanna also maybe come back to is in marketing, because I think, you know, we have to look at how we are using this technology as well. So we're really, today in these early innings as well, we formed a marketing AI council, uh, or AI for marketers aim because we have to have an acronym.
Um, and getting the users, uh, some of the users in our organization, um, sharing use cases, sharing how, uh, they are applying it to the different parts of marketing, which is so exciting because it's really every department from creative to the web, to the data science team, to product marketing, can all use it. And I think we're seeing today a couple of classes of, you know, just efficiency framing of problems, uh, summarization of data or great bodies of information, and that is helping us right now, uh, make our marketers more productive, um, and get to results faster. And that's, that's what we're working on now.
So I'm super excited about what the team is doing. I imagine there's a lot of hand raisers across marketing functions, and we wanna be next. We've got a great idea for a use case where we think ai, gen AI can be a huge efficiency booster for us.
How do you stop, right? Um, uh, because I imagine everybody in marketing wants to be part of this. Well, super fortunate here at Pure, uh, very advanced.
And we have a CTO that focuses on AI for the company, uh, enterprise Chat, GPT licenses. So we are, uh, very, uh, you know, advanced in company wide in terms of using AI in the different functions. Uh, so we haven't had to stack rank so much so far using and chat GPT Enterprise Chat, GPT, uh, has been made available for us to use.
And you can do so many things with that already. Uh, and of course that's what, you know, as I would caution all is that's what keeps your data safe, right? So, uh, not using anything that, uh, would be proprietary or would go out into the public models.
And, and so right now I don't, I don't have that, uh, that constraint. And we are, that's great. Learning as fast as we can.
I have fascinating use case from our A BM Center of Excellence where they are using it to also start to personalize content, uh, yes for our one-to-one a BM approach and make that process faster. And that gets back to what we talked about, which is marketing today's really needs to deliver that personalized content. We're a media house in many ways.
And so it's one of our, our great use cases that we're exploring right now is how we can do that more efficiently. I think that's fantastic. It sounds like your approach is really methodical.
It's very strategic, it's very much aligned to the business strategy, and it sounds like customers are really finding value in that. Last question before we wrap up, 'cause I know we could keep talking, give advice to those future CMOs who are following in your footsteps. You talked about the, the breadth and the depth that you bring from a background perspective.
You're leaning into emerging technologies, you're driving marketing with the art and the science. How would you advise that the next generation of CMOs to continue learning to get to your level? Oh, well, uh, I appreciate that.
I feel that, uh, first of all, my, my biggest tip to anyone at any stage of their career is be curious, keep learning. That I think is probably the secret to career success and keeping yourself energized, keeping yourself engaged with the business. And that's been the hallmark.
I didn't start out thinking I would be a CMO, uh, or want to be a CMO. Um, it was really an extension of my curiosity about what more could I do in marketing? And over the course of my career in marketing, I've had, um, the opportunity to do many different marketing jobs.
Uh, and that's informed my, my role today. And that would be maybe my second piece of, of advice is I think it's really critical to have whether that be a more well-rounded business experience to bring to marketing or a well-rounded marketing experience. Uh, because leaders in marketing have to have a lot of perspective to bring to the table around how to align to the business strategy, CEOs, CFOs are looking for what are the insights from the market?
How are you addressing them to best, uh, create that growth at an efficient pace? Um, and also increasingly advising the organization on the communication of key corporate messages, whether that be sustainability or diversity. And so all of this, um, requires that more well-rounded approach.
And I just encourage folks to take those steps in their career to have new, new experiences and to keep learning, follow your career path that way versus set out just for a title. I couldn't agree. Marlyn, thank you so much for sharing that Great advice.
I love the whole stay curious theme. I think that gets you so far and there's so much untapped potential there. We thank you so much for sharing your wisdom, your insights, your journey with our audience.
I know they learned a ton from this, Lynn, thank you. Oh, Lisa, it's been such a pleasure. Thank you for having me on.
It's been great to talk about marketing, art, and science with you. I love it. Thank you.
We wanna thank you for tuning into this latest episode of the podcast, Pearl Lucas. I'm Lisa Martin. I'll see you next time.