Techstrong TV October 7, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Ah, I love the smell of irrational exuberance. In the morning you're watching Textron Gang. Hey, good morning everyone.
Happy Tuesday. What a Tuesday. This is coming off a crazy Monday.
Yesterday, you know, I, I thought things were so overheated that we were gonna like, reach the superconductor phase pretty soon, but yesterday, I, you know, we torched it yet again even higher with, with the most recent announcement of this open AI A MD deal coming on top of Huawei News and TDK and AWS advancing their own chip business and rumors of an Intel and a MD hookup. You gotta love it when chip makers hook up, they make baby chips. I don't know.
Um, but so, so much going on, so much going on. We've got a great gang to discuss this with. Let me introduce you to our gang members.
We've got JP Morgenthal Sporting a new, a new set at his home studio, uh, chia Gun What Chaya welcome. Steven FoST, as usual from downtown Hudson, Ohio. And, uh, coming at us, I think from Barcelona today where he's a Yankee refugee.
He just couldn't stand it anymore. Mike Ard. Hey, gang guy, gang members, welcome.
Thanks for joining here. So, Mike, when half of the U-S-G-D-P is data center and, and AI related, and as the time says, we, we have a bifurcated economy, the AI economy, and the rest of the economy, are we in a bubble? What the heck is going on here?
I think we're in a small bubble, but I look at these, um, announcements from various folks, and I say, Hey, maybe rational thought is starting to prevail here, and here's how I get there. Well, maybe ad's got a little more efficient processor capability. I mean, OpenAI found them for a reason.
They're not just doing it for the heck of it, it, I'm assuming it's not just some second source supplier that they actually intend to use these chips. And there's also been advancements to your point about Huawei and, um, TDK, and everybody seems to be working on chips that are more efficient in terms of the use processing of ai. And I almost feel like we lost sight of that goal or that requirement, because every time I look at every announcement for the last two years, it always seemed to be about, well, how can we figure out how to use a bigger banner processor instead of being more efficient with what we have and what we need?
And that's why we have all these big data centers in the bubbles. But jp, am I engaging in some wishful thinking? I think that the, you know, there's just a, a, a natural inclination, still was so much room to run.
There's such a big runway on this technology. We're we're just really in infancy, right? So, you know, obviously, uh, optimization, uh, is one of the key things that has gotta take place.
There has to be, uh, some answers for the economic, um, management or, uh, profitability at some point, uh, of these platforms, which, you know, I think some attention has already been paid to. This just doesn't make sense financially unless you're looking at it from the long game perspective in which we're seeding a market, uh, with the expectation this technology will eventually become, uh, less expensive to, uh, buy and operate it. And you're building your audience now, and, and hopefully they're sticky.
Uh, you know, there, there's a lot going on with, you know, just general new market movements. And there are market makers is a, the technology is changing rapidly. You have a number of players, you know, if you remember the discussion in the beginning was Nvidia, Nvidia, Nvidia, Nvidia, Nvidia, everything was Nvidia.
Now you, you have a MD you have, uh, AWS you have even TDK, right? Uh, you have a number of players that are getting into the, um, game of providing, uh, not just GPUs, but asics around AI and AI processing. And so, uh, you know, this is just gen general build out and, and infrastructure and chip makers finding their, their place, uh, or making their way at the table, pushing their way to the table.
And so, you know, we don't, we don't even know what the outcome of this might be, right? We, if, if we, if we're seeing significant improvement at lower costs, that's gonna have a huge impact on how the market, you know, starts to, uh, move. And, and who's doing deals with who.
Like you said, OpenAI probably, you know, has communications with every chip manufacturer out there in the world. I'm sure they did a very thorough study. Why did they choose a MD?
I'm sure it was a combination of factors, but, you know, the, the point is that they did the due diligence and they chose a MD for all we know. It could have just been the fact that a M D's the only one that agreed to give them 10% state. But it's true, right?
I mean, uh, upside on the business, right? But here, if OpenAI put their weight behind a MD, what's that gonna do to Nvidia? It definitely shuffles the deck.
Sure. So for me, uh, the way I look at it in the chip market, it was nvidia. Now there are other players, which is good.
You get a better technology and speed up in terms of the timeline, the way the chips are developed. But my concern is, as in terms of usage, it's only open AI that's controlling all this chip providers who are the competitors for OpenAI to challenge that. These are the chips used for this business use case, because, uh, believe it or not, we still haven't find a good strong business use case for AI yet.
So that's something I will believe for Stephen to comment further. Yeah. Yes.
Believe it or not, we still haven't found a use case for this. Absolutely true. And, you know, the thing is, I I think that, uh, you know, to be a little bit cynical here, um, the reason they made this deal with a MD is because a MD is effectively paying them for the deal.
So for, for, for reference 160 million shares of a MD stock, which is what, um, OpenAI stands to potentially gain according to multiple milestones of delivery, is worth $33 billion. Which is effectively, um, I don't know that it's exactly the amount of money, but that's a lot of money that is going to be used then to buy a MD chips to power this, uh, approach. So essentially, this is the same game of passing around revenue in order to subsidize sales.
And, and, and, you know, in this case, it's only two players. Sometimes it's three players, sometimes it's four players. But essentially that's what we're seeing in Silicon Valley right now.
We're seeing companies passing around revenue in order to all write up, uh, massive sales that aren't actually leading to anything necessarily. Ultimately, like Chaya said, the thing that we need is productive and beneficial and financially rewarding use cases for all of this work. We are not seeing it yet.
So let me jump in here and be patient with me. I got a lot to say on this one. So first of all, Mike, there is no such thing as a little bubble.
You know, my father rest, his soul used to tell me if a Jewish person is going to eat pork, they shouldn't nibble at the corners. It's doesn't pay. Go for the meat, go for the gusto.
Let it like the juice run from your mouth because you're sinning anyway. So there is no little bubble. There's a full on, there's a full on pigs at the trout bubble of total irrational exuberance.
Steven, to your point and try you to your point, what we have here is a situation where basically the GDP, the investment in AI is roughly the size of Singapore's entire economy. The profits and output is roughly the size of Somalia's economy, right? It doesn't end up, it doesn't add up.
You look at these deals, God bless Sam Altman in OpenAI. He's not dis Nvidia. He promised them hundreds of billions of dollars in business last week.
This week he's, he got 10% of a, of a a MD. And by the way, we're not using these processors in Stargate data centers in Texas and here and there and everywhere. These are gonna be yet different data centers, I assume, in the US because everyone has to make Duche happy.
But my question is, when are we going to pinch ourselves and say, who, who are we kidding here? This is a Ponzi scheme. This is me giving it to you.
You giving it to me, me giving it back. I give it to the next guy. He trades it to this guy.
com. I went to Houston in this big building that had an e at the bottom of it. You know, the building I'm talking about?
We were in a, yep. I used to work across the street from that building at their Competitor. So, you know, that building, we were, we were stuck in a bad contract with WorldCom buying bandwidth.
Not much different than buying a and d above AI chips. And we, we, we were paying a thousand dollars a megabit. The market rate was six, 700.
They invited us down. I sat at a long table. There were like eight different Enron people around me.
Each one of them had a card that had a different division of Enron. And they told me if I sold my WorldCom bandwidth to them and a thousand dollars here a megabit, he would give it to him to give it to him, to give it to him, to give it to her, to give it to him, to give it to her, to sell it back to me at 600. How do you do that?
Arbitrage. We are the kings of arbitrage. We know what we're doing.
I walked outta there. I asked my CEO herb rebar. I said, herb, how did they do this?
He said, Alan, it beats the s**t outta me. Either they're the smartest people on earth, or they're the biggest crooks. As it turned out, they were the biggest crooks.
Mark my words. This is a Ponzi scheme. I, you know, I, when, when, in, in terms of a little bubble, when AI and data centers represent 50% of the GDP of the us when this Ponzi scheme goes south, we're, we're all getting dragged down into it.
We're all bat in the hatches put on your life jackets because this is going to, this is gonna make, this could make 1929 look like a picnic. Let, let me add something about the a MD deal that I'm really, I have to say a MD you might think that a MD is being taken advantage of here. No, no, no, no.
They're the smart ones here. Effectively what they've done is they've guaranteed that future open AI models will run on a MD hardware. They've guaranteed a market for a MD hardware and all this, and A seat at the table, Very low cross of nothing, because it's all predicated on shares and stock market valuation.
So, effectively, a MD just earned them, just bought themselves a, a seat at the table for nothing more than some theoretical stock. And that's pretty good way to enter the Ponzi scheme. Absolutely.
And a MD was always the bridesmaid and never the bride. Right? And now they, here's their wedding day.
God bless 'em. Mazel tough to a MD. But here's the next thing.
Let's go beyond the a MD open a I deal. Look, last week we had news, uh, from deep seek, right? They're coming out with an intermediate, more efficient, right?
The Chinese clearly are, are trying to play the role of the Russians in the, in the migs, right? Making a, a cheaper but effective jet fighter. They're making a cheaper, effective ai.
Huawei unveils this sink. S-I-N-Q-I don't know if it's syn or synq. Um, we mentioned TDK with their own announcement of a, of a, a chip that never loses rock paper, scissors.
That's, that's a reason to buy a chip. Okay? In case for all you rock paper scissor players out there, there's, well, The DDK thing is, is very different than that.
But yeah, there, There's a way, there is a world of difference between saying I have a design and actually building it at scale too. So that, That's another thing. But There's a piece to this that you're leaving out, which is they've created a sticky technology.
All these people who are now have made changes in their business to incorporate generative AI as a component of how they do business. Um, you can't just shut that off. So these companies, you know, when the, let's say it does quote unquote blow up, where do these people turn?
These people are gonna have to turn to doing it themselves, buying their own hardware, setting up their own data centers, uh, you know, being able to deploy and move the, their call to the commercial LLMs to local LLMs, right? If, if it should blow up. I don't see how it can blow up.
It. It's getting to that too big to fail. Too big to fail.
I think. I you just can't pull the rug out. It's like Turning electricity when you start hearing it's a new paradigm and a new, a new reality sell.
I, I don't, I don't disagree with you that there is something amiss, that it's fishy. What I'm saying is it's connected to this, you know, this par of the game that I think that people are gonna keep up. They're not gonna let it fall down.
Because if it falls down, it, it's, it's devastating beyond just the, the small market that, you know, I is creating the bubble. Well, You gotta have total faith that the people in the administration, 'cause after all, they would never let that happen. There's a guy who never declared bankruptcy.
Hold on, Chaya, let me ask you something. So, let's say that I am company A and I have an investment in an and in company B. Company B is makes a processor.
And I have no real incentive anymore to run my software more efficiently. 'cause I'm making money every time that that processor gets bought. So, um, it seems to me like the bubble will bust because there'll be more efficient software, but open OpenAI might not have the incentive to go bust that bubble anymore.
'cause they're now got money coming out of the hardware side. So I think that there's a mismatch here in terms of, um, goals and value to shareholders, Right? I, first of all, for me, it's not a bubble, it's a technology evolution.
I would say being a technologist myself, I just think the whole way of the way software are being developed over years has been changing. And because it's such a big shift, it feels like a bubble. I don't think it's a bubble, it's just that it'll get stabilized in terms of every week there's a new news that is coming up.
So there, there's gonna be a point where there'll be standards of technology and it'll stable it down. And that's when the competitors to open AI will also come in and will have players on both side. So the negotiations will be on the table.
Right now, it's open AI versus all the chip providers. That's kind of, uh, is what the game looks like to me. Um, for now, going back to the deep seek point, what Alan just made, uh, remember when, uh, deep seek came for the first time and the market crashed because people think that, oh, this, we don't need a hardware.
We can run. I played around with that technology myself. It is nowhere close to what we have with OpenAI models and the way of efficiency that yes, it's a good experimental thing.
So I don't trust that technology enough that we start using it for business use cases. So there's a lot to go in, in deep sake to gain that trust. What existing, um, generative AI models with open AI and existing chip providers are been promising at the moment?
I don't think it's generative ai. That is, is that's the, the push of this, I think it's agent ai. Yes.
Kind of. I think they both are go hand in hand on top of it. Agent AI just gives you more power, but it's equally risky also, right?
Because it, you, you have less control on in terms of the actions it's gonna perform. And, and then we, we haven't discussed AWS right? They're coming out, what is it?
The Tanium, not Tanium. Tanium three. Tanium three.
Yep. Right. You know, how long is it gonna be till Microsoft or Google do it as well?
Um, They already have them. I mean, they already have in-house Asics. Yep.
Yeah. And then, you know, Broadcom is part of this guys. Yep.
It it's all in, it's all in and, and China, you know what, I remember what you talking about. I remember saying in 2000, the company I helped take public too big. Of course, you know, if we're going to use all this technology, every company's gonna have a website, we're gonna need all this bandwidth, we're gonna need all those data centers.
And then the bubble did burst, and it took almost 8, 9, 10 years for us to recover. Back to that point, no matter how you deal it, like when did the NASDAQ go back over 20,000 or whatever it was. When did, uh, you know, when did we stop having all that dark fiber?
When was all that dark fiber actually used in the data center build outs? I'm not saying that AI is without merit or without value, but when you are turning the largest economy in the world to 50% of its GDP being data centered, you know, the old saying about putting all your eggs in a basket, you wind up with a lot of egg on your face. Right?
But if you go back to the bubble that you just referred, best of the companies did came out after that bubble. Google came out after it, Amazon came out after it, and they are the trillion dollar companies today. So We, but it took 10 years.
Yeah, but Can you, and for every, for every Google and Amazon, there were a hundred or a thousand companies that are cratered that went outta business, right? So I'm not saying there's not gonna be winners here. What I'm saying is, you know, I'll quote my, you know, bill Clinton, this is simple arithmetic.
The numbers don't add up. The numbers don't add up. There's just two, you know, it's, this is like a Bernie Madoff gone wild.
Yeah. And, and just to be clear, the bubble isn't ai. No.
The bubble is using this circular economy of investment to bolster the irrational and and excessive investment into specific AI hardware. The, you know, the rest of this stuff we're talking about, you know, deep seek, like Chi was saying, um, ag agentic, ai, asics, all of this stuff actually makes sense and I can see a market for it. The problem is that we're that there, that there's also this thing over here that's just churning through money.
And for what, Who gets fooled by this then? Because you would think that there are, uh, wall Street who gets pulled MD is up 32%. Yeah.
Yeah. So that, but you would think that the Wall Street analyst would be wise to this circular shifting of money. But they seem to be all in on it.
I, let me tell you something. Oh, God. Does the name Henry Blott mean anything to you?
Yes, he was, he was our advisor at Interline. The company I, I helped when we went public in 2000, Henry Blodgett was our advisor. He was touting us and, and taking us public at the same time.
What, what, what do you think Wall Street has clean hands here? This is, this is a made, this is, this is a made by Wall Street movie. I I think some sort of poor day trader investor gets hurt at the end of the day.
No, because they don't, because they're playing it too. A MD is up 32% today. They're day traders who made a fortune today.
And if they're smart, they'll take their money and go home. But they may think like Shire and say, well, no, this is a new, a new normal. There's a new paradigm to, yet last two weeks ago, it was Oracle.
Today, it's a MD tomorrow. It could be, I don't know, but I, I wanna, you know, do, who was it? A, a sucker and his money When I feel it's everybody's winning.
Everybody's winning. I being the shareholder of Oracle, it went up to three 40. I was happy today.
I, I have seen, woke up with the news at a MD has gone up, up, I don't mind being this in a circular economy for some more time till, till the stocks Up. I didn't mind it either. That's when I thought I had my children's college education paid off in 1999 when they were 1-year-old.
com stocks that I loved watching them go up in Yahoo and everything else. And then in 2001, it wasn't so pretty. So are you Telling everybody to short those stocks?
What are you saying Right now? I would never give investment advice. That's not me.
Yeah. You know what? I will give investment advice.
My investment advice is trust a competent professional investment manager. And don't do this yourselves. I have zero insight into my stock and, um, holdings, and I have professionals handling it.
And hopefully they will help protect me when all of, if all of this changes. How's that for investment advice? Leave it to the professionals.
There you go. Shane. Shane.
All right, Mike, I'm gonna give you the last word. I I think that this battle is just beginning. And I think we're gonna see much more efficient AI models and that will bust the bubble.
com bust go. I just think tech is gonna become more efficient, as it always does. We shall see.
All right. Hey, we're gonna take a break here on Textron Gang. Let's come back and talk about checking my notes.
Ai, you are watching Textron gang. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back.
And yes, we're talking about ai, but maybe, uh, hopefully a killer use case for it. HPE has got a whole, um, service Now and around an AI platform that they've built to come up with Section 5 0 8 compliance faster. It involves, uh, of course using their AI platform, but they built something with DataIQ and SHI as the implementation for all this.
And 5 0 8 has to do with the American Disabilities Act. And it takes a long time to comply with all these requirements. But what's interesting about all this is, this is not the only thing that maybe we could shorten the compliance window on it.
Instead of taking years to make sure that we comply with all these regulations, we could do it maybe in months, weeks, China, and maybe the whole cost of compliance comes down. And who knows, maybe politicians stop b******g about what the cost of regulations are. 'cause we can just do the right thing and do it in a way we can afford, Right?
So I like their initiative that they're treat giving compliance. The weightage in the world of ai, west feed matters and compliance and security and policies are always the way which slows down the things. But, uh, again, in the world of identity ai, how do we decide which are the right compliance policies, right?
So there has to be some rules, some intervention based on the use cases that can cover up. For example, when we talk about disabilities and compliance, what disabilities are we talking about? Who are the beneficiaries of these policies so that we can give the advice or we can give the advantage that now this is the best use case.
This is where it it's going to be used going forward. So who is setting the benchmarks here? Is it HPE setting?
It, is it the, they have done an industry analysis and they are saying, here is what, how we have done it. Maybe industry can follow the trend. So yes, compliance is a good initiative agenda, AI can help expedite the development of it.
But I am just, uh, right now more in terms of concern, in terms of what are the driving factors for this. I think if we go along here, you can start modeling it out and say, Hey, how much are we spending going to Alan's point about the GDP, how much money is spent on compliance with all these different security initiatives and every government and every state. And then you map it up around the world and there's just a boatload of money being spent on something that doesn't really add value.
I mean, it's important, but it doesn't add economic value in my mind. So I say automate this stuff as much as possible, and those are the use cases. And nobody likes doing this job and nobody wants to audit it.
Anyway. I gotta disagree with you, Mike. Mm-hmm.
Compliance is security's bastard son. Okay? And if, and really what compliance represents is lowest common denominator security, a basic floor, if you will not ceiling a floor of the minimum you should be doing in terms of best practices, security wise, and everything else.
Now, the instant case here of the HPE, automating section 5 0 8 compliance is not really the compliance. Those are not the DRS you're looking for. This is compliance.
We're making a website, uh, accessible to people, let's say, who have vision or hearing, uh, disabilities or challenges, right? And so you have all techs and, and all of the things, it's a very, it's a very well established sort of model. And, and it lends itself well, I think to an a, uh, an AI type of situation.
But when we talk about compliance, it's talking about are you masking PII are you encrypting data in transit and in rest? Are you ensuring, you know, your certificates are up to the latest things, right? G governance, risk and compliance GRC is, is, you know, I I said it in jest about the bastard son of security.
It's an integral part of the security, and it's important. I think We're looking for a re hen and stepchild. There you go.
These things are being automated today. Let's not pretend this is new. They, they just require humans to spend time developing the automation.
Like the change here is that the AI has the ability to, uh, alleviate the need or the, at least the, the amount of degree that a human needs to be involved in order to check this stuff. So you can, you have what's called the large action model, and it understands, you know, basic UI uh, interactions, right? How to press a button, what it should look like, and it, you can train it to say, this is what it, these are the factors that need to be on the screen in order for it to be compliant with 5 0 8.
And so it very simply, it, it's very simple to tell an ai, listen, here's the script of things I want you to test. Make sure it's 5 0 8 compliant. It understands what 5 0 8 compliant means, and it'll walk through the script.
And no human has to sit there like with an RPA tool, validating and putting all those steps in manually. And it does, it's a huge reduction in time. It's a huge reduction in costs.
Uh, and, and I think what Mike was saying earlier about its value, it's an important requirement. You can't sell the software to the government and certain other, you know, um, non-governmental agencies unless you are compliant. So if you wanna sell your software, this is lifeblood.
It's table stakes. Um, but you're right. It's not like it's something you can advertise and say, look, I got 5 0 8 compliance here.
Uh, you need, you know, so that makes me better. So, uh, so the fact that you can pawn that off, and it's no different than what's happening in many QA functions. Uh, a lot of the QA functions and software engineering are being handed off because, uh, again, this is not something that you can charge for, per se, uh, that quality, but you, but it's expected and, and it's now requires less human intervention to get there.
And, and I'll just say too, that this may not be, uh, so, so let's kind of refocus on this particular story here, section 5 0 8 compliance that's about complying and, and helping people with disabilities to be able to use software that may not be a big selling feature for a lot of people, but it's a life or death feature for some people. And as somebody who's active in the dis disabilities community, I can tell you that, um, having websites that are compliant with section 5 0 8 is, um, and I am not joking, is life and death to people who have visual disabilities or motor disabilities or need to use alternate input and output mechanisms. Um, you know, being able to access the social security or the disability, or the Medicaid or Medicare or local disability, uh, websites, uh, using alternative methods.
That's the whole ballgame. And not only that, but it's the whole ball game for these agencies as well. So, if you're a board of developmental disability and you're, uh, software and interfaces aren't compatible with alternative disability inputs, well then you might as well just go home.
So I'm actually really thrilled to see this. I want to, you know, give a little shout out here to the folks from kaza who are, uh, field day presenters. Their, their hearts are in the right place.
They're, they focused on this because they care about this product and this and this segment of people. And, you know, I mean, it's easy to get angry and oh, ai, all this and that, but this is a case where we're actually using AI for something useful and, you know, give 'em a pat on the back. I think this is the beginning of a much larger trend, and I think I'm really happy to see section 5 0 8.
That's great. But I think this is gonna play through just about every other compliance mandate there is out there. And this is gonna be the, that a lot of folks are gonna say, Hey, ai, AI delivered some actual value here.
Because a lot of this stuff is, consumes an inordinate amount of time. It's costly and it's expensive, and it, not that, but it's just scut work at the end of the day. Yeah, because that was your best Bogart imitation how Mike Louis, this is the start of a beautiful friendship.
There you go. Hey, we're gonna take a break here on the gang. Let's come back and we will move into our C block, which is around, wait a sec, checking notes again.
Microsoft and Security is that at Oxymoron, you are watching Textron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back in. Yes, Alan's point.
We're gonna have a little chat about Microsoft and security and well, some people love 'em and some people hate 'em, and some folks are just in between. But the latest thing outta Microsoft is that they are gonna use graph technology to make it easier to integrate all these different security tools we use. And within the security world, there's this debate going on about whether we should centralize everything on a platform and that we can get rid of our swivel chairs.
'cause we'll all have one set of integrated tools. There are others that continue to say, you cannot rely on one tool and you need to have layered defense. And Microsoft here is gonna make that easier because we're gonna use graph technologies to integrate all the tools, and we'll live in a more of a kumbaya kind of world in security is yet to be proven.
But this is the ongoing debate. And I know that Steven, you a thing coming up around, um, uh, Microsoft and an event that you're doing with Tech Field Day. So you guys are following this space pretty closely, but I don't know, what's your take on what's going on here?
I mean, I seem to see a lot more Microsoft in the security world, but you know, not everybody loves 'em. Well, Microsoft is certainly stepping up in the security world. I think that, uh, they have invested a ton of money in it.
Uh, you know, I mean, Microsoft isn't a charity. Uh, they invested a ton of money in it because I think they see a lot of opportunity in it for, uh, product sales and so on. But, uh, frankly, they are investing, they are working hard at it.
And of course there's a carrot and a stick here, as you pointed out. We also have, uh, you know, uh, Ron Wyden, uh, US Senator, uh, and Microsoft critic, uh, attacking Microsoft for delivering dangerous and insecure software and encouraging the FTC to go after them. So, uh, you know, the challenge with being Microsoft is that they, as the, you know, the makers of, you know, certainly one of the most important infrastructure components in the world, and also one of the, uh, by far the leading, um, end user computing platform in the world, they have to balance a lot.
And I don't envy them in many of these decisions. So, for example, if we look at the, uh, the, the, the specifics of the, uh, the Ron Weiden letter, they're talking about, uh, hackers exploiting of vulnerability that was kept in my in windows. 1% of traffic uses this, and if they had deprecated it, they would've blocked by extension thousands or hundreds of thousands of actual and users from using something that they never upgraded.
1%, let's, let's flip that switch. Let's, let's get rid of that vulnerability. Would you maybe, would you do that?
If, if it meant that it affected literally thousands of customers, uh, maybe you wouldn't. And that's the sort of the problem that Microsoft is facing here. Now, on the flip side, Microsoft is doing some really cool things.
They are improving their security tools. They are bringing AI to bear. Um, and as you wrote about, uh, Mike on, uh, you know, security Boulevard, they're using, uh, graph technology.
They're using ai, they're using MCP to build a more collaborative and flexible security framework. Um, as we saw in, uh, the recent article, another recent article by Jeff Bird on SE Security Boulevard, they actually have been seeing some success with these tools, uh, sniffing out some pretty clever AI generated attacks. So, you know, it's not easy to be Microsoft.
I like that they're really putting a lot of energy and effort into this. And I do, uh, look forward to hearing what they have to say on October 9th during this, uh, tech field day presentation. And I think, Stephen, what I want to add is security and fun stuff doesn't go very hand in hand when it comes to ai.
Um, I play it around with a lot of AI tools, and when I try to automate a security use case, yes, it's gonna fix one thing, but it might mess up or open up some other things. So there's a lot of risk, I would say, needs to be reviewed before anyone adopts it end to end. My question about the thing with Microsoft is why does only Microsoft specific operating systems has this so many vulnerabilities that they have to patch so many things, why they can't build a system like Linux or, you know, where the system is strong enough and you don't even need these kind of vulnerabilities to be tackled, which can, you know, played around with users' data As, as a long-term Linux administrator?
It pains me to admit this exactly, but Linux has a lot of vulnerabilities To absolutely they do. You know what, and as a person who's been in security for 25, 30 years, you know, it's hard being Microsoft because damned if you do and damned if you don't. The fact of the matter is, when you had an operating system that at one time represented 95% of the market for, uh, personal, uh, you know, for computers, not servers, desktops, laptops, et cetera, it still represents I think 80 or 75% of, of these devices you have a giant bullseye on your back.
It's not that it has necessarily more vulnerabilities to Steven's point as Linux or even Mac. It's that it's the bad guys exploit it, look for exploits there more. So they find more.
If we put the same amount of effort into Linux and Mac exploits, you probably find a similar amount of vulnerabilities. No one has a, a, uh, a, a lock on on being the most secure. They all software has vulnerabilities.
Well, and you look, I mean, even, even Apple iOS, which is by far the most locked down operating system with the most security controls of anything we've ever seen in widespread use, and there are zero days. Absolutely. And there are exploits on that platform as well.
So, you know, I don't think it's credible to say, you know, lock the door because I, I just don't think you can. I, I, I think this is why insecurity, we've moved from a prevention to a resilience model, right? Yeah.
Here's the part that I get uncomfortable with, right? So on the one hand, uh, I guess I'm just flat out conflicted. I really like what Microsoft's doing here with graph technology and some of the AI stuff and the MCP stuff, but I also look at it and I go, so let me get this straight.
You're selling software to fix the software you already sold. And so like, you know, why don't you just fix the software? Well, so, so, so Mike, I'm a, I'm glad you raised, that was the point I was about to make.
The a the story is isn't so much about their investments in security, it's how they're leveraging emerging technology to improve, uh, your, your, your security stance, your security posture, identify new, uh, potential threats that before were difficult and what they're doing. I, I don't look at it in the way you just mentioned, right? One of the issues has been this is highly analytical process.
It, it lends itself to time series data. Um, a significant quantity of data needs to be analyzed. And how do you share that data?
And, you know, typically in the past, you know, they've had to build the tools, the analytical tools into the product. Now they have a way of leveraging the, the actual, uh, underlying foundational capabilities like graph database and, uh, MCP to now share that information with a, uh, inference engine and allow the inference engine to do what it does well without having to yet add more weight into the product. So this is, you know, this is about the ecosystem growing and taking advantage of the ecosystem.
And I'm sure for a, a large number of customers who are, you know, in the security office, in the operations teams, they're saying, this is great. I now can add my sentinel data into what I'm watching in addition to, or I can now easily combine Sentinel data with my Datadog data because I now have, and, and I can allow the LLM to drive that, right? Hey, LLI can ask Natural Language Pro, tell me, is there any anomalies that you noticed in the Sentinel Stream that you didn't pick up in Datadog?
Boom. It'll actually go and ask both of those platforms for the right data and then correlate them. These are things that in the past would've taken operations team, uh, days, months to build special, you know, it would've had a cost associated.
It's now an an, you know, a simple prompt. I, I don't disagree. I think you're dead on.
So one, some, but I mean, God bless Microsoft for doing this, but I also look at it and go, well, won't a dozen other companies do the same thing and maybe do it more broadly across different products and use cases and graphs are gonna be everywhere. Maybe they will. The MCP is native to the, it is just, I, I own a pro software product.
I'm providing an MCP. It's almost like providing an integration an API interface for something for, for other people to then leverage my what my proprietary stuff. That's what the CP is.
It's about allowing ev the outside world to connect in and take advantage of my proprietary, uh, universe, right? But isn't MCP or any a table stake? I mean, everybody and his brother has one.
And wow, that's, that's pretty aggressive for something that just came out less than a year ago. Aware. It's only important to the extent that you have something that you want a, uh, LLM to automate.
Steven, we're in a new paradigm, you know, Need New normal, Which has bugs. Then we are saying that, oh, we sold your software, which has issues. Now let's buy a solution to fix your problem, because we know the one that we shipped you has a problem.
Well, that's a good business. That's a good business model. All right.
Hey, we're about outta time here, though, for today, guys. What a great gang. You know, let's, let's face it, it's a, it's a, uh, target rich environment to talk about tech news these days, but it was a great discussion.
Jp, Steven Chaya, Mike, thank you so much. Thank you for watching. As usual, we have Techstrong TV following today's show.
Enjoy your Tuesday. Uh, on behalf of the gang, Techron Tech Field Day, future urm, this is Alan Shumer. We're out, But today, we, the consumer are the enterprise.
And, and so how do we protect us going forward? Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Every episode explores a variety of topics within cybersecurity and the technologies that drive it.
com on our Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms. Before we jump into the episode, let's meet today's panel, starting with my friend Fernando. Hey, Fernando, how's it going this week?
I'm, I'm doing well, thank you. I'm experimenting with different video things here. So, hello everybody.
Fernando Montenegro. I'm VP and Practice lead for cybersecurity here at the Futurum Group, right? And, um, we, we covered different security topics as one might expect, right?
This one is really interesting. The one we have for today is really interesting, and I can't wait to get started. Uh, on that, I'll pass it over to Kate.
All right. Hi, my name is Kate Scar. I'm the chair of the CD Cybersecurity sig, also, um, cybersecurity Architect and C-I-S-S-P.
My focus is securing the full stack from pipelines to networks to emerging AI and LLM ecosystems to make innovation not just faster, but safer. Alright? And of course, I'm Tom Hollingsworth.
I'm the event lead for Security Field Day and other security related events at Tech Field Day, and that's part of the Futurum group, uh, just like Fernando and I, and I'm very happy to have Kate joining us today because it's, uh, gonna line up to be an amazing day, but it's not the most amazing thing because folks buckle up. It is officially National Taco Day, and how did it just so happen that it fell on a Tuesday? However, don't say the word taco next to the word Tuesday, because evidently there's a trademark that you have to worry about there.
So no, no, no, no, no, no. This just happens to be a Tuesday that includes tacos. That's not your thing, though.
It's also national chocolate covered pretzel day, but maybe you could have both, you know, little, little meal, little dessert, uh, geo. But the little things in life, that's what really makes it worthwhile. And we wanna talk about the little things today, because this episode is gonna be all about the internet of things.
You know, those little devices that seem to have completely taken over our lives. Uh, I, I know this for a fact because last night, uh, my wife was absolutely insistent that the heater must have kicked on at two 30 in the morning. And so I grabbed my phone and I pulled it up, and I looked down there, and I'm like, no, actually, the heat's not on.
Um, we need to investigate some other things that might be going on. Uh, but in the old days, you know, I would've had to get up. I would've had to walk downstairs.
I would've had to like, get put on my glasses and flick on a light and tap the thermostat. So obviously, iot has made my life significantly easier until someone figures out how to get on my thermostat and actually do turn on the heater when it's 90 degrees outside, because that's a thing we've heard about. And that's on the consumer side of things.
We're not talking about industrial milling machines and all of the other ridiculousness. So for this episode of Security Boulevard, it's all about IOT. Kate, you're the one that really brought up this topic, so I wanted to give you a chance to kind of open up, it's for some of the things that you've seen out there.
What is it about IOT and the intersection with security that kind of makes you lay awake at night, even if the heater's not on, Right? So it's basically how devices have just taken over our lives more so than we realize. Um, last time I really, there's over 44 billion IOT devices, and to me it's, you know, it's just like the tsunami of devices that we have, zero, almost zero cybersecurity, um, controls of, right?
Because they're so small, they're so little, and they're very, very chatty. So even if we try, have tried to bring them into, um, a security operation center into a soc, they can quickly overwhelm, um, SOC analysts because of the noise, and yet they're running, they're literally running our lives. So it's not just, um, the industrial internet of things, right?
We're not just talking about in critical infrastructure, the, the programmable logic controllers and the remote terminal terminal units, the RTUs and, and the PLCs. And, and I'm not, you know, I don't wanna get so deep into critical infrastructure, but, you know, there is this segue into the internet of things and how it connects and, and things that we don't even think about, like HVACs, you know, that's iot. Um, you know, our, our solar panels iot, and now when we think about, um, buildings and critical infrastructure and this bi-directional traffic of, um, of energy, and we're, we're not even monitoring these things.
And, and I did, um, I did a, uh, uh, like a proof of concept as I went down this path and looking at, you know, um, windmills and, and, and solar panels as an, as an example, and I am without exaggeration. Um, we put, um, we put a solar panel, like on the outside of the DMZ, and it was taken over within four and a half minutes and added to the Mariah, Mariah botnet, so the king of botnets it. And, and, and we couldn't even like, have access, meaning we actually had to send someone into the field and, and flash the, the solar panel to, to bring it back in.
Like, like it, they, they totally took it over this one solar panel. And one of the things that I thought about is the idea is that we would not have known that the solar panel was taken over because it was acting as it should have until when, until until we really needed it, right? I mean, and I, and I really started to think about how many of these devices, um, from cameras, from our, from, from our, our traffic lights to signs on the internet to, um, to, to building access controls.
I mean, think about just even, um, you know, parking meters today and, um, electric vehicle charging stations. These are all IOT devices that we have zero, zero visibility. So what do we do?
And, and, and when I really, and I don't know why I was thinking about this weekend, so talking about, you know, weekend things that, you know, we were thinking, you know, we've all been thinking about and having to deal with, but I was thinking really about our homes and how our homes have become these, you know, these small little business centers, not only from our printers, but from, you know, from the thermostat controls to our, um, to our fridge and freezer, to, you know, so I can just keep going on. And all of a sudden now, we as a consumer have to be concerned about this, you know, have to be concerned about things that we typically thought was just business related, was just enterprise related. But today, we, the consumer are the enterprise.
And, and so how do we protect us going forward, our, our pacemakers? Um, I don't have one, but if I did have one, it would be right here. Um, so our, you know, these devices, all of a sudden we've also become these walking IO OT devices, uh, from our watches to our phones, to, you know, I used to have these smart glasses that were a blast to play with.
Um, but yeah, Fernando, I mean, how's your perspective on this from, from the research side? Because I know that I, I, we hear a lot about iot, but is anybody really doing a lot of investigating into just how insecure it is? Short answer is yes, right?
But let me, like, there is so much for us to, to, to, to, like, I, I, I really excited about the topic you all. Um, uh, you may have, you may remember, uh, mark Andreesen, uh, the guy who was, he was one of the leads with Netscape, uh, sorry, Netscape navigator way back when, and now he, for, for years now, he's been a venture capitalist in, uh, Andreesen Horowitz. And back in 2011, I believe it's, he coined, he said he wrote a paper and he said something like, software is eating the world, right?
I say that because it's a, it's a quote that I use in some of my research for good reason, right? And yes, software has eaten the world, but software has eaten the world in, in two ways, right? In, uh, uh, within businesses.
It's because everything, I mean, technology drives everything, right? And, but what I, when I, when I think about IOT, I think about IOT as the physical representation of that, right? Software has eaten the world, and the vehicle through which software has eaten the world outside of data centers has been through IOT, uh, industrial control systems, uh, uh, scada take a pick on the, on, on, on the different things, right?
So it has really taken the world and random thought, right? As, as, um, uh, nothing to do with, uh, I think it's this coming Friday that, uh, there's a new, uh, uh, Tron movie coming out for those that, like the original, uh, Toronto Tron Aries is coming out and have, from what I understand, has something to do with them coming into the real world. So as we were thinking about this, like, okay, there's, there's, there's an iot reference there somewhere, but, um, but for us, uh, yes, it's, it's, it's an area that's deeply interesting.
It's an area that, uh, plays a lot where, uh, if you, if you heard me say this, uh, a few times, but I always talk about, I always like to think about the economics of things. My degree is computer science, but if I go back to school, it'll be something around those lines of economics, organizational psychology, what have you. And from an economics perspective, right?
IOT introduces several really interesting problems for us, right? So Kate, you were talking about the, the, the, the consumer side. Well, how informed is the consumer about what they need to do with their, uh, consumer level IOT devices, right?
That problem of information of how informed the consumer is, is at the heart of information as symmetry, right? Which is a, uh, an area of economics that, I think it was the Nobel Prize in 2000, I think, uh, George Kerl and, and others, that that's the, they did some research on market for lemons, right? The, the, the, the concept of market for lemons.
So it's screaming at us that this is an area of economic, uh, uh, where, where economic concepts play a part, and we've seen some initiatives over time. Uh, there is, uh, I don't know where we are now from a regulatory perspective, uh, but there have been initiatives around consumer labeling of divisive hay, but we've never really took off. And that consumer labeling is interesting, but it doesn't mean anything if the consumer is not informed, right?
So if me as a consumer buy an io buy a device, right? And, and for, uh, for this podcast, I, I, I bought a new camera, right? Uh, if I'm not aware of what the ramifications are, am I exposing myself?
And, and the thing that that comes to mind, I mean, there are so many IOT related, uh, incidents we had over time. You of course brought up the, the, the mi i botnet, right? Um, the one that that struck me was, you know, how a few years ago we had issues with, um, uh, classified information being disclosed because, uh, soldiers were using their fitness trackers in sensitive locations, and they didn't know that that thing was being uploaded.
Yeah. Right? So the, the, the, the ramifications are, uh, uh, literally worldwide, they're, I say galactic, right?
In the country we have iot, uh, outsiders. I love it. Yeah, absolutely.
Anyway, long and short of it, super interesting. Uh, but there, and, and, and I, I urge people to think about them, not only from a technology angle, but what is the economic foundation of I ot And I, I have more to talk about that, but I don't want to talk the mic too much. I, I'm glad you brought up economics, because I feel like the drive for IOT is all about the modern enterprise of brutal efficiency.
Like, like when you think about all of the things that we've been driving towards in, in, in the enterprise, especially around IT iot and it, it is about making things as efficient as possible. But in order to know exactly how efficient it is, I have to be able to measure it and, and think about all of the things that a consumer iot gives you. It gives you flexibility, right?
I can set my thermostat from my desk, I can set my oven to preheat my lunch so that it'll notify me when I'm ready, so I don't have to keep going in there to see if it's ready yet. Um, you know, crazy things like my fridge knows where the milk is, so it knows when the milk's getting low, so it can pre place an order for that. That is all about making me more efficient as a person, but in the enterprise, it's about being able to measure, like, think about a milling machine, right?
If that milling machine is down for any amount of time, that's a literal cost to the business. By monitoring that system, I can tell you how long it was down. But not only that, I can tell you when it runs most efficiently, how many people are necessary to be able to remove the work and to to, to preload it for other things, which means I can keep a better cost on my staffing and, and so on and so on and so on.
Where the intersection with security becomes a problem is one of my favorite topics. Friction. We want a certain amount of friction in security so that it's visible.
Think about the airport. Realistically speaking, most of the stuff that they do at the airport for security can very easily be automated, right? And we've seen that in other airports all over the world, right?
You just walk in, drop your stuff in a thing, walks through, and, and it's easy. The reason why they have to wave you through the reason why they have to w you or, or do a scan, is because they want you to see that there's something going on. But when you're doing that with I ot, IOT's supposed to be invisible.
So if you create friction that says, oh, well, you know, this needs to be authenticated, or the certificates on these devices need to be re um, renewed every two years, every point of friction for a thousand sensors for 10,000 sensors creates problems, and people are gonna chuck 'em out the window. And Kate, to your point about the solar panel, the reason why the Mariah botnet has been so efficient is because it's invisible. If we had done this, if we had taken over all of these cameras and routers and things like that, and then made them unavailable, uh, the relative inexpensive of that chip set means that people would've just grabbed it and threw it out and got a new one.
Whereas, you know, you can't do that with a $4 million paper press. Like you've gotta figure out how to fix that. And that's getting into the other problem that I OT is exposing is that a lot of the ways that people are choosing to put these things on the internet, so to speak, with iot, is standardizing things that historically have not been standard.
Like I can remember, there's an, there's an apocryphal story about a guy who gets hired to fix a pipeline, and he walks out and he taps a couple spots with a hammer, and then he sends a bill for $10,000, and the guy's like, I refuse to pay it. That should not be too difficult. And he goes, oh, well, I'm only charging you a thousand dollars for tapping it with a hammer.
I'm charging you 9,000, because I knew exactly where to hit it with the hammer. Like those people who were good at programming SCADA systems, who are good at programming all those programmable logic controllers, they're still necessary to do that. But the infrastructure that they overlay that rides on top of that is pretty standard, right?
It's HTTP, it is using REST APIs and things like that, which is real fun for people who know how to exploit those things. It's like, oh, you forgot to use a certificate on that. I'm gonna have a field day.
So like, is is our drive for efficiency in the business creating these problems? Because, well, if I have to make sure that I can monitor everything so that I can automate it or use AI to collect statistics from it, am I just creating a trap for myself where everything becomes real easy to kayak? I, yes, I think, you know, it, it's a, it's one of the biggest problems, right?
That, that we continue to see with iot because there's so many devices and, you know, how do we, how do we, we've already moved forward. So it's almost like everything else. Um, when we look at, when I look at LLMs and things like, like, like the, it's already out of the, you know, the, the bull's already out of the, out of the cage, and it's running around the, the, the ring there.
Um, so it is a really big huge problem that I, I, you, you asked me at the beginning, like, what keeps me up at night? This is actually something that keeps me up at night because of all the systems that we have running on this. Now, when I, when I start to think about like, well, how, how do we start to capture this and, and bring this in?
And one of the things that I had wondered and, and it crosses, you know, like a business section is predictive analytics. So do we go from, instead of looking at, um, configuration and changes in configuration, which has been very problematic, even with just computers and servers and mainframes, um, but do we start to look at the behavior of the devices? And can we, by looking at the behavior of device, understand that it has been taken over.
And so that's how I, I have started to formulate, like, if I'm going to be looking at how to, um, take hold of, of this problem. And so let's just take a camera. This, this would be a really easy example.
Um, so let's take, let's say we have a thousand cameras in a large building. And typically, um, typically we understand that cameras are gonna start working, let's say it's 7:00 AM to midnight. And so they're gonna be very, very chatty.
And so, but so, so that becomes our window of chattiness. And, but all of a sudden, this camera that is usually not on, starts to come on at 3:00 AM. So I am going to look at that as an anomaly, and I'm gonna say, okay, now is it coming on?
Because it's, it's dying. You know, the, the device is, is suddenly, you know, I'm not feeling well, and I'm coming on, I'm coming off, I'm coming on, I'm, you know, or has it come on at 3:00 AM because there's anomalous activity happening in the, in the building. And so then we start to marry the predictive part of iot, which I think is important.
But, but personally, um, to answer your question, I, I mean, I, I think we have to start looking at the behavior, um, from a cybersecurity point of view. And, um, in order to start to wrap our arms around this problem of, of, because I don't, I don't know how else we can do it from a configuration standpoint. It, it just is.
So if we have 44 billion devices, how, how do we start this? How do we, how do we secure this? I, it's a really big problem.
It is, uh, it is a very hard problem, and they use the word hard on, on very specifically on purpose. There is a phenomenal study that came out of the National Academy, so National Academy of Science, but National Academies overall, uh, called the cyber heart problems, right? These are, this is a research report that aims at, um, informing policy conversations, right?
We wrote about it in, uh, back in June, I believe. So the report came out in April, may timeframe. I wrote about it in June.
And, uh, it's really interesting because they talk about what are the, the, the kind of cyber hard problems that we have to deal with as an industry, right? Because, uh, they are not in intractable, but they are difficult to solve, and it's uncanny how many of them apply to I ot? So we have a software composition problem, right?
We, we, we are now not writing software anymore as much as we are assembling software, right? Uh, uh, we're, there is a phenomenal problem with, uh, uh, how do we define the trust of a system, right? How do we evaluate trust, right?
That's just, that's a hard problem. And then, and, and Kate, I'm latching on to the 44 billion number, you said, yes, that applies across all of those. Now, one of the things that, uh, I found like a broken record, which I know is maybe a dated reference, but I, I, I keep repeating myself because one of the things that we need to prepare ourselves for as organizations is we need to be able to be resilient, right?
Cyber resilient, if you want the term, right? We need to be able to be resilient within our overall systems in, in the face of individual failures, right? So if you have to pick on, on your 1000 cameras example, right?
I have 1000 cameras running in my environment, right? But hopefully I've architected my security, uh, environment so that tho the traffic from those 1000 cameras is on a specific vlan or is on a specific SSID or is, is somehow segmented so that even though there is a volumetric anomaly in that traffic, okay, that pops up there, uh, if they try to, oh, look, we, we took over this camera, let's FFH into whatever server we want to, uh, that boundary is going to block that, right? So yes, the camera has been taken over, yes, the camera is infected.
No, it's not bringing down the entire organization, right? We need to be able to ask practitioners continuously work towards that environment, that kind of architecture where things are self, uh, I don't, uh, I remember way back when we had the term self defending networks where we're, we're back to it, right? But we need to be able to have that kind of, uh, of segmentation inside of our environments.
And one of the areas i i I cover is, uh, sassy Figure access SE Secure Access Service Edge, right? One of the more interesting things around SS e deployments is, so it's the idea that you're now using a service, a cloud-based service to basically enforce some of that segmentation. I think that IOT devices is one of the more interesting areas for SSE, because now you can radically simplify what the, the, the connectivity needs are at the edge so that you know what the device just needs to connect to a a 5G radio or, or whatnot.
Okay, great. We're you are now protected by the SAFI service and, and that takes care of, of this kind of thing. One other thing I want to bring up back to economics is that, uh, we need to, uh, Tom, you bring up the, the, the, the milling machine versus the cameras, right?
The difference in one of them costs $4 million, the other one costs 40, right? The margins that the producers have on those divisive is radically different. So that $40 camera, right, has a tiny, tiny, tiny profit margin, right?
And you cannot, as a producer, uh, splurge too much on security because security costs money, right? Goes back to your friction point. Well, one of the more interesting things that happened, it's, this is, this is a weird one, is that from a scaling perspective, right?
And, and I, I credit, uh, Thomas Doan, he goes by Halor Flake on the socials. He had the presentation a couple of years ago where he highlighted how it's cheaper for an IOT manufacturer to buy a generic purpose chip that can do a ton of stuff. It's cheaper to buy that than to buy a more specialized chip that doesn't do it.
So now all of a sudden, that camera that perhaps, or, or that PLC that perhaps just needed a couple of controls to do it needed functionality to do five things, it now has functionality to run a full blown Linux system in there. It doesn't need to, but it's actually cheaper for the producer to build it like that. Guess what?
If you're still treating that device of, hey, it's a little PLC that can do these five or six things, and you don't realize, holy expletive, it has an actual Linux system built in, you are going to have a bad day, right? So it, it goes back to, again, I keep going back to economics, I'm sorry, right? But it's this, this thing about, uh, you, you talk about, uh, friction, there's also the friction of how expensive is it to deploy these things.
Well, I, but I think to kind of wrap up here, Fernando, it's, it's important that you bring up that, that kind of, um, aspect of it. Because one of the things we've learned over the years in security is that no matter how complicated things get, when you can take it back to the basics and understand the challenges that are forcing these decisions, you can actually get a pretty clear picture of it. You know, economics is gonna, um, force that, as I said at our security field day event a couple weeks ago, opportunity cost spare is no one, you're always gonna be making a trade off somewhere.
But more importantly, for what we're thinking about here, you know, kind of to Kate's point, sometimes all you gotta do is ask the right questions. And the questions are, can be as simple as what is doing the talking, where does it need to speak and how much talking does it need to do? Like, like we've seen that, right?
Like the, we always go back to our favorite apocryphal stories of like, the target POS hack or the, the, uh, casino fish tank thermometer hack. Does the thermometer really need to be talking to the betting system? Well, if the answer is no, and there's not a control in place to prevent that, then that's a bad security decision.
You know, if the target POS system or the HVAC system should not be talking to the POS, why are we allowing that communication? A simple deny there would have saved a whole lot of headache, and quite honestly, forced us to come up with a new story. But I think that, that the challenge there is though, that we still have to apply our old methods of thinking to technologies that assure us that we don't need to do that because this is all taken care of.
And I promise you that the first time that somebody comes to me and goes, oh, you don't need to worry about that security. We've taken care of all of that, I'm gonna double down on what I do, because one of us doesn't know what we're talking about, and my experience has told me it's not me. All right?
Uh, we're gonna go ahead and wrap it up there 'cause we're kind of at the top of the time for this. But I wanted to give our guests a chance to kind of tell us some of the cool stuff they're working on, Kate, starting with you. Uh, if people wanna go read some of the stuff that you're working on or, or see some of the projects you're involved with, where can they go to do that?
So right now, the CD Foundation has put out a, um, security guide, cybersecurity guide on how to, um, secure the software, um, the cd, the, the pipeline, the CICD pipeline. Um, I would, I say in like three easy steps. And to me though, what's more exciting about this cybersecurity guide that came out from the CD Foundation is that you truly have cybersecurity working with the DevOps people.
So to me, that has been very exciting. And, uh, yeah, you just need to go out to, um, the CICD, uh, from Linux Foundation and look at, uh, then go drill down one more to the CD Foundation and you'll see our guide. It's free, and we're so happy, um, and would love feedback.
It, you know, so please, that's the big thing. Uh, It, it's, uh, we didn't even touch on the, on the CD foundation aspects of things, right? Because it's a, it's really interesting when you consider iot that IC CI and c modern ci cd is all about the quick feedback loop, right?
How quickly can we fix something, uh, and then quickly make changes and work that, that can't be done in iot, right? I mean, if I ship a, if I ship a system that is a turnkey system, it's supposed to live for 30 years or 50 years or whatnot, i, I, I wish we had more time, Kate, perhaps we can do this again in the future. But, um, uh, so from, from, from my perspective, from from a research angle, right?
I'm, uh, I'm just wrapping up. I'm late on a report on, on software supply chain security, which again, we didn't touch in the context of, of IOT as well. I mean, bills of materials and, and, and everything, but I'm just wrapping that report up.
And then we have, um, uh, should be up by end of the month. We should have a, uh, our cybersecurity decision maker survey. That's, that I'm working on.
So we have think about 900 respondents, give or take. I'm, the data is coming in and, uh, uh, I'm a data geek at heart, right? And, uh, I'm, I'm, I'm just dying to get into the, the, the cross tabs and, and, and, and whatnot.
That should be fine. Uh, we also have our, uh, security operations, uh, signal report. So Futurum has a new report type signal, and, uh, uh, I'm, I'm working towards the, the security operations report, uh, security operations platforms report.
So that should be out early November, I think. So, yeah, it's a, it's a very busy month and, uh, uh, not as much travel. November for travel is gonna be brutal.
October for travel is not too bad. Uh, I'm, I'm happy to announce that all of the videos from Security Field Day are now posted, featuring Kate and a bunch of other great delegates. Uh, we have all of the conversations that we were able to have there up and including our, uh, enforcement round table discussion, which was kind of fascinating.
Uh, there's a lot of discussion in the industry about how we should be doing these things, and I love getting different viewpoints. Um, if you don't have hours upon hours to watch every one of the videos, make sure you head over and check out the Tech Field Day takeaways that I recorded. I picked three big points from Security Field Day that I think are something that you need to be paying attention to.
Um, it's less than 10 minutes. You can get your information and go. Uh, but we want to thank you all very much for listening to this episode of the Security Boulevard podcast.
If you enjoyed this conversation, please make sure you subscribe on YouTube or use your favorite podcast application, because that way you never miss an episode, it'll just get delivered right to you. The other thing we'd ask is if you could leave a rating and a review, because that does help the show grow. The more ratings and reviews we get, the more likely it's just to get put in front of the right people who need to be hearing.
com and the Futureum Group. com is the place to be. But don't forget, you can also head over to the Techstrong TV website or check out the Techstrong TV app.
It's available on Apple tv, Roku, and pretty much any smart device that you can watch things on. Make sure you're following Security Boulevard on X and Twitter, as well as LinkedIn. We are at security BLVD, because vowels are things you don't buy on Wheel of Fortune.
Thanks for tuning in, and we will catch you next week. Hey guys. Thanks Withrow.
We're here with Haw Ol, who's CEO of one io, and we're talking about how integration needs to evolve, especially in the age of AI, because, well, it's getting a little complex out there. Yuha, welcome to show. Thank you.
So one of the issues that we seem to see out there is, well, it's getting a lot more complex, as we noted, but historically we had a bunch of APIs, and then we got a bunch of connectors built on top of those, and we managed them through some sort of centralized platform if we were lucky. But chances are, we just kind of managed them in some sort of bespoke way that was not very efficient. You are.
How does the way we think about integration need to change as we start to deploy all these AI agents out there? It seems to be coming together at a level of scale that is mind boggling at the moment. Yeah, well, I think it's first thing, the old, old saying that goes in it, that if you build it, you have to run it.
So I think that's the first principle which leads into this, um, more like a holistic thinking of managing innovations as more like a product rather than just ad hoc project that somebody, some hero puts together, and then we hold fingers crossed that they work. Um, so that's, that's the fundamentally fundamentals kind of a mindset change that we need As part of that. Therefore, do we need to kind of build the integration platform first and figure out how to manage it before we go build all the connectors?
Well, of course, integration use cases are like various, there are different kind of indications that you, the simple, simple, simple from simple, um, um, innovations that can be kind of connector driven, let's say that you need to copy your active directory and stuff like that, which is really like simple all the way to this, uh, cross platform workflow automation that involves several parties. So of course, you have to weigh, uh, the requirements a again, against the investment investments that you do. But overall, the innovation platform is a kind of a good starting point, but it's only set of tools.
So you really need to have some operations model. You have, you need to have governance, all those things on top so that technology is not, um, enough. Mm-hmm.
We have had integration platforms for years, and they're usually managed by some internal IT team. Um, but it seems to me at least that it's not like we're integrating things every day. We do integrate a lot of things, but is this really, you know, a capability that the internal IT team should have?
Or should it just be something that feels more like a service that I just invoke as needed? Mm-hmm. Of course.
Depends what is your business? If you feel like that innovations are your core business, then of course you invest into your own capabilities. Um, at the end of the day, there's no, no sort of a way of outsourcing responsibility.
So regardless of internal IT team, doing them these things themselves or, uh, getting them as a service or something in between, there should be somebody who's responsible of this. So, um, that said, um, majority of the companies, enterprises, they have their internal team to support their business. So things that are not directly creating, um, business value should be somehow put aside or buy both not to invest into.
Yeah. Um, will this whole equation get a little more complicated? We talked about early on in the intro with the rise of AI agents, but are these not gonna be, I don't know, hundreds of thousands of endpoints that need to be integrated, not just with legacy systems, but each other?
And how is that gonna all play out in your mind? Yeah. Well, um, I, I would, I guess that the ai, um, helps us to build faster, first of all.
And then AI agents are as, as, as we see them at the moment, they are mimicking human beings. So it means that they, they still need, um, real time, reliable correct data in order to operate. That means that you need the integrations more than ever.
And then the demand is becoming so, so, so much higher because of the AI agents will be deployed, systems will be, uh, and they require more and more data. So you need to build more and more integrations, which means that you have to find ways to scale, which means that, uh, the manual way of, uh, and approach based approach that you bring in bunch of people and start building from the Strat on top of the platform is not suitable anymore. Will we also maybe, I don't know, create AI agents for the integration platforms themselves to help integrate AI agents with legacy applications?
And the AI agent will talk to one other AI agent, which will then manage the process for them? Is that possible? Well, they need something in between.
And, uh, like what you just described is it's sort of considered as a kind of API driven approach that you have APIs and interfaces. Putting AI on top of the APIs might make them little bit more, uh, you know, intelligent. But the problem is that how, what is the communication?
What, where is the communication happening then, and how do you, the translations and mappings and all these things with different data models, and how do you run the business logic on the integration? So point to point, yes, that I can see that happening, but then you need to have this, um, multi-point integration use cases. Um, it's unlikely that ai, um, agents can replace it.
They can, they can be super efficient when they get the data and can process it and send it over, but how they send it over there needs to be something in between mm-hmm. Some kind of fabric, Right? And to your point, how that gets accomplished matters, especially from a governance and security and compliance perspective.
So I can't help but wonder if the carts before the horse a little bit, and we're all excited about AI agents without thinking through exactly how these things are gonna get managed. Yeah. Well, I think we, thankfully we have one, one really good example in the, in the sort of past of it, which is DevOps.
I think same fundamentals can be applied, uh, when it comes to managing integrations, taking the DevOps culture, taking the automation, taking the monitoring, having the lifecycle approach, and that leads into better governance, clear responsibilities, accountability, um, SLAs, SLOs, all these things that are making integration look like more at the products that have some, some, you know, clear reason to exist, and they're not at some, some ad hoc stuff. So I think that DevOps principle would nicely limit it into this picture When it comes to integration. What's that one thing you currently see organizations doing that just makes you shake your head a little bit and go, folks, we should be a little bit smarter than that?
Well, we, we still try to fix, fix this scalability issue with the sort of the old way of doing things, which is, uh, today I think was today Gartner has to release the latest magic quadrant for IPAs, and you'll see the same folks there year after year, integration platform as a service. That's considered as a kind of a, some kind of a silver bullet for this. And nobody's talking about the actual requirements for these integrations.
So we are taking, um, we are enhancing the tools for developers to develop integrations. Uh, but you still need to developers, so I, what you said mentioned about the AI being on the, on the IPAs platform and helping, helping them to develop faster, make more integrations without any management model. And we all remember what happens happened when the shadow it was introduced back in the day, like suddenly you have different things outside within the organization because it's so easy.
But at the end of the day, security, governance, all those things that are super important nowadays, um, they, you need, you just need a model for them, operational model that covers them, the whole thing. From your perspective, um, how will the current platforms need to evolve, therefore, I mean, a lot of people will say, I already have an integration platform. So what becomes the impetus for them to change that out or swap that out and, and, and what's the ROI on that?
Well, I don't think it, it goes down to not only on the platform, what technologies it comes down to the understanding that innovations are, are, are sort of important part of the whole IT delivery as they, uh, are in the supply chain is a good example. Supply chain management innovation have been, have been fundamental for, for that kind of, uh, uh, concept for, for decades. And now within it, we have to wake up that we should have a similar principles, even regardless of the technology we need to invest into competencies, the model, how we run it, uh, the whole approach of, uh, really investing into important things and consider integrations as a product.
So it takes a, also, I think there's a kind of a skill, skill cap in that sense that companies are not really getting there. And it's not about ai. It's about really having the competencies and understanding what it really takes to run integrations as a, as a part of a, um, organic part of your it, IT ecosystem.
Mm-hmm. So as you look forward to this new AI slash API driven world, you know, how many APIs will organizations be managing, do you think? And, you know, are we gonna see some level of scale here that people aren't quite prepared for?
Well, I think it was some what it, MuleSoft or Salesforce, um, study about this, A number of applications that we add, uh, every year in the larger enterprise, it's hundreds of new applications will be kind of added, especially like terms of ai. So there will be a lot of interfaces, APIs, and now the question is that how do you make sure that they are, uh, they match into your security requirements, all these things. So it, it's, the scale will be, will be just like we, I think we just, we, we have just scratched the surface when it comes to a number of APIs and interfaces.
And that being said, you need a governance model. You need operational model, otherwise you're gonna be like, you're, you're sailing your ship without knowing if all the, all the hatches are latches are closed. True that.
So what's your best advice ultimately for IT folks out there as they kind of think this through and they start to, I guess, recognize the level of scale, what should they be thinking about? Hmm. Um, quite often we see when we discuss with the customers, the biggest pain is that they, they say that they have technology, they have integration capabilities when it comes to team, uh, competencies and, and things like that.
But they still have, uh, backlog of six months to getting there, which means, of course, simple answers you have to prioritize. But how do you prioritize if you don't really know what is the most business critical, um, uh, for instance, for what, what is the most bus business critical innovation for you? How do you do it?
So, um, my advice is that you really step back from technology perspective and start thinking that how do we actually deliver integration in integration at scale, which means that the operational model, how do we, how do we ensure that we are credible deli in delivery on time? All these things that are like basic stuff to any, any IT operation, but integration are integrations. Integrations are not often considered as as a product.
So people don't think them like that. So I will start with that type kind of a thinking that should be turn our thinking into more productized, standardized approach and what, what kind of investments we are willing to, to take in order to get there, which means then you have to prioritize. Alright, folks, while you heard it here, Hank, when it comes to integration, we're gonna be looking at things at a level of scale that might be mind boggling, but at the end of the day, it all comes down to the fundamentals.
But if you don't start with integration, you're gonna treat it as an afterthought. It's probably gonna go wrong. Yuha, thanks for being on the chair.
Thank you. All right. And back to you guys in the studio.
Hey everyone, welcome back here to Tech Drunk tv. My next guest is Jeff Reed. Jeff is the Chief Product Officer at Vectra ai.
Let's welcome Jeff in. Hey Jeff, how are you man? I'm well, Alan, how about yourself?
Very good, thank you. Appreciate you coming on. Um, Jeff, we're gonna talk a little, we're gonna talk a lot about fact actually, and we're gonna talk about some new solutions you guys have.
But before we do that, let's hear a little bit about you, your chief product officer. How, how'd you wind up there? How long you doing this?
Yeah, what's your background about? Yeah, so been here about a year and a half. Uh, you know, I lead engineering, product management, product marketing for Vector ai.
We'll talk more about what we do. But I got here, uh, by way of Google Cloud. Uh, and so I've kind of spent, if you look the, I call myself a plumber.
Yeah. I've been in kind of the infrastructure security land for the last 25 years. You started, started file systems and volume managers at Veritas for folks that remember back in the day.
Um, and then spent a bunch of time at Cisco, I Remember. Yeah. Yeah.
So Uhhuh, you went through there. Oh, you at Cisco too, You really, yeah, yeah. Then went to Cisco.
You Were like a nest plumber, huh? Yeah, No, exactly. Yeah.
Yeah. I never had, I mean, we did it on chips, so could kind of see I got in the chips. It's probably, you know, you know, but, uh, but yeah, so did, was it Cisco?
And, and really, you know, from there it spent a bunch of time in networking and then, you know, went into security side of Cisco for a few, for four years or so. And then, you know, look, the whole cloud thing's pretty important. Uh, so I had an opportunity to go over to Google Cloud, and that was great, great experience, and kind of did two things there.
One was in kind of the core services, Kubernetes, serverless, you know, that, that kind of space. And then, you know, when Google was looking to acquire Mandiant, uh, they wanted to bring in a, you know, security product leader. And so had the opportunity to come in there, and that was a great role.
So kind of had, you know, VP of product for all cloud security at Google Cloud, um, both from the infrastructure, identity, access management, compliance, HSMs, all that side, but also what we're doing in security operations in that world with, at that point Chronicle. Uh, and then you had, you know, it was interesting. Hitachi, who's the chat, he's the founder, CEO of Vector, reached out and I really was super interested in what Vector was doing, um, because, you know, the, what we were doing with Chronicle was really interesting at Google.
You like the economies of scale, the speed, all that was amazing. But we were still like, I think in the sim market was still kind of incumbent on the customers to do most of the, the real, like threat finding. And so what I, what I loved about Vectra was how they were doing things that were really unique in the industry around how to detect attackers using, you know, initially network side, you know, uh, you know, data, but then expanding to other places.
And so that really kind of got me jazzed about coming over to Vectra. Excellent. What a charm course of, uh, the, you know.
Yeah. I've been lucky. Yeah.
Yeah. Career. Well, you know what the, what was it Branch, Ricky, the guy from the Dodgers back in the forties or fifties said, luck is 80% or 90% respiration, 10th percent inspiration, right?
So luck comes, you know, God helps those who help themselves. Anyway, Jeff, let's turn to Vectra, right? Yeah.
It's a lot of people out here may or may not be that familiar with it. Sure. How would you describe Vectra to them?
Yeah, so it's, there's, you know, really started this idea of can we apply advanced AI techniques to what initially was network data to find attackers that had bypassed other, other, you know, security controls within an environment. And, you know, kind of came out of, you know, some breaches that you have the, the founding team had seen in customers back in, you know, the 2010s where, you know, nothing else was able to pick up their activities, but they'd left this like trail in terms of the network, uh, activities they were doing. So command and control, reconnaissance activities, lateral movement, and that side.
But I think the, the key thing that, that, the key part of the premise though was instead of doing, you know, the normal, you know, what's abnormal behavior, the things that have kind of generated so many alerts and so much noise, it's could we take a much more focused approach around what are the durable attacker behaviors? And if you think of that, like what attackers have done over the past, you know, 10 plus years, like the core pieces are the same. I need to establish some presence.
I need to have a com controlled channel. I need to figure out where I'm in the, I am in the environment. I'll probably need to move towards different parts.
And so those behaviors, those minor, uh, techniques are the things that we really try to find. But we find them using very sophisticated, you know, capabilities. So we use long short-term memory, recurrent neural networks for C two channels.
We do some really interesting clustering techniques around, you know, trying to identify, you know, where is privilege within an environment and then, you know, where are places where we see, you know, potential privilege escalation. So things like that I think is really kind of unique to the, the capability with the whole desire being, can we always find the attack behavior, but do so with as much clarity, so there's a little noise as possible. I love it.
I'm assuming the website's vector ai. It is, yes. B-E-C-T-R-A.
And, and Be clear. So one thing, like, you know, the, obviously AI is, you know, very hot topic these days. Um, you Think, You think just, just as, just as sko uh, we've been around for over 10 years, you know, these techniques were started being deployed in, you know, 20 18, 19.
So pre the big gen ai, you know, wave. Uh, so, so yeah, we, we describe ourselves as the OG of, uh, of a AI and security. Fair enough.
Very good. I I love the OG staying current here. Alright, let's, let's pivot into our topic of discuss.
It's not really a pivot, it's a continuation of what we're talking about, but Jeff Vectra AI recently announced a, uh, a new generative AI solution, uh, for AWS powered by the, the Amazon Bedrock platform, which, you know, Amazon has really, uh, put a lot into and continues. Yeah. Right?
It's a big part of their strategy there. Um, talk to us about this new, this new solution. Yeah.
So this is where your vector AI analysts and you to take a little bit of a step back, but you think, yeah, I talked about the idea of, you know, we want to drive great clarity. Like, hey, here are the small number of things that you, Mr. Customers should worry about each week within your environment.
You know, we do that in kind of these stages. So we start with the actual detections themselves, and we talked about recurrent neur networks, you know, then we have actually a triage, a agentic framework that's been around for a couple years now. And it basically is trying to find out like even if there's attacker behavior within your environment, some of those behaviors are, are actually hard to decipher from what normal, like real, you know, legitimate use.
And so it basically tries to kind of like, take that and, and reduce the number of, uh, of potential, you know, alerts and detections that we have. Then we go through a prioritization scheme. It basically says, and what that is, is a constrained optimization model that's trying to mimic what a, how an analyst, a security analyst soc analyst would prioritize all the things that hit his or her desks in a day.
Then that kind of pops out with a score. And then, and then, so the last thing that this new, this new analyst agent is really about the next step from that. So once we've prioritized anin, a host or an I or priorit as anin, a host or an identity, how can we then like make the next steps for that analyst as easy as possible?
So think about this as being able to go out and, and do all the, the kind of work around, you know, investigating that, that entity, what are the behaviors potentially reaching out to new data sources that we haven't naturally? 'cause what's nice thing about these agentic models is they have the ability to go out and read blogs of the latest attack, you know, attack techniques out there, or, you know, go to find new additional sources of data within that customer's environment and basically come back with a, a more sophisticated assessment of that entity. And do we think that this is actually a, a likely to be a malicious behavior or not?
So that's kind of the, and it does that this, and I think the, the interesting thing here is if you just throw this to a large language model and have it go, it would, uh, sometimes it would be amazing, sometimes it'll be completely wrong. Uh, and so the, I think the, a lot of the work that we've been doing is how do you not just leverage what the, the genetic generative AI capabilities have brought to bear, which is a lot of good, like fuzzy logic and like long tail reasoning, but compliment that with, hey, there's some guidelines or, you know, guardrails in terms of this type of, you know, we've seen these behaviors on this, on this host, what would the normal steps be for an, an investigation? And so this kind of mix of expert system logic plus large language models kind of combined, do we think deliver a really interesting approach.
Love it. Jeff, what about for the people out there who say, this is a great AWS solution, but I'm multi-cloud? Well, so Yeah, yeah, yeah.
So to be clear, and this one maybe I should have, should have done this earlier. My bad. Uh, we are leveraging AWS's bedrock and infrastructure to deliver this solution.
It is by no means, uh, limited in terms of the, oh, okay. Purpose area coverage, just AWS environment, since You guys are actually sort of hosting it on AWS, but it's available, However you wanna call it, on ID inter ID M 365, Azure AWS, like everywhere that we have, uh, detection coverage, so kind of our native signal generation, you can apply this analyst. Now, the one thing I, just to be clear, you right now, this is available as part of our managed detection and response service.
So you, we Right. We provide a managed service that'll, you know, basically where Vectra analysts will sit side by side with their SOC counterparts to help kind of make sure, so initially it's powering that service is, is where this analyst is coming to bear That that's available. Right now It's available right now it's, it's on, if you go to the, uh, AWS marketplace and their generative AI tool sections around security, it's one of the, you know, one of the solutions as part of that, I gotta ask you a hard question, Uhoh, bring it on.
Alright. You know, look, I spend most of my day on videos like this with people like you. Yeah.
And not just vendors, practitioners, analysts, you know, a good mix. Everyone, everyone has an AI story, everyone, as we talked about earlier, right? How much of this is not, not that I, I'm not saying it's not real.
It's obviously real. Yeah, yeah, Yeah. But how much of it is must have today versus, oh, this sounds cool, but, you know, I could live without it.
I think that comes down to the problems we're trying to solve. You know, every year we do a, a big survey of SOC practitioners and, and kinda ask them a series of questions around, you know, kind of what their, what their day-to-day life is. And, and some of the findings from the last one we did were, were amazing.
You know, like, um, you, 71% of them worry that they're gonna miss a real attack buried in a flood of alerts every week. Uh, so that to me kind of stands out. Like that's one of just new numerous findings.
But I think for the way I think about it is given the scale of people's environments and, and the thing we've seen is just the fact that it used to be simpler. We had a data center, we had a campus put some firewalls around it, you know, it was like, it was a much simpler environment to protect. Yeah, no, I get it.
You know, between, you know, everyone still has those, and they have cloud and they have SaaS. And so the, the, the complexity of their environment and, and, and you used to find, I mean, you've been in this world a long time, you know, 25 years ago you talked to someone that kind of knew everything that was going on within the IT infrastructure. That's almost impossible to find now.
Not Today. You're right. You just thought, yeah.
And so I just don't, I don't think the tools that aren't leveraging some degree of more sophistication in how they identify, triage, prioritize. I just don't think they're gonna be successful in, in really helping avoid that problem of, I'm flooded with alerts every week. I'm thinking I'm gonna miss some the thing that really matters in that flood of alerts.
And so, so to me, that's the thing. And, and really that's the foundation of why Vectra. And that's, we've 10 years ago that was That, right?
That was your reason for being to begin with. Yeah. And, and, and so I think that, you know, and we've been, we have, we have more data scientists vectra than we're working at insecurity at Google Cloud.
So, so I think that just gives you a sense for the scale of investment and the bet we've made that this stuff is really important. And it's not really ge like, the thing I wanna say is like, like generative is another technique that is very useful in some parts of this problem set, but it's not the end all be all to what we've been trying to do and what we think you need in order to be successful. And so, to me, it's a great compliment.
It's absolutely, I'm really excited about stuff. You see, you know, some of the stuff we've seen in terms of like, you know, you know, MCP servers and things like that, I think, you know, how the stock operates, I think is gonna radically change in the next five years. And, and I think that we can play a key role in that through the, the mix of technologies that we have.
Yeah. No, we, we just had this discussion on Textron gang the other day. I don't even think it's five years, I think.
Yeah. I think it might be two to three years at most. I mean, the way, the way thing, right?
Agentic AI things are snowballing so quickly Yeah. And you get this kind of compounding capability set the things you, um, so yeah, no, I, I, I was, I, I'm very confident by five years it will be totally different. Oh, Absolutely.
I, I don't disagree. 18, I think all sort of relative, right? Hundred percent.
When you look at how this whole AI thing is affecting the speed and velocity that code is being developed, I was about to say that New apps are being deployed now. You gotta manage those apps and observe 'em and all of that, and you gotta secure them. You know, it's, uh, it's the circle of life here, right?
Absolutely. On steroids. And, and so, you know, I, I think that that's what we go with.
ai is the website Yeah. For people who are interested in this particular new offering, where does it right off the front page kind of thing, Right off the front page. Yeah.
Yeah, yeah. Yeah. And you'll, you'll also see how well we did in the Magic Quadrant, uh, for first ever MQ for in DR We were really both access Es though.
Yeah. So really happy about that. Oh, Congratulations.
Strategy. Yeah. Thank you.
Good for you guys, man. Hey Jeff. Come back on and keep us posted here.
Right. World's changing real quick. We got to stay on top of it.
Sounds good, Alan, thank you so much. You're welcome. ai here on Techstrong tv.
Go check out their new, uh, gen AI solutions powered by Amazon Bed Bedrock. You're watching Techstrong tv. We'll be right back.
Hello and welcome to the latest edition of the Techstrong AI Leadership series. I'm your host, Mike er today with Brian Moore, CEO for Voxel 51. And we're talking about why a lot of these visual AI projects seem to be failing.
Brian, welcome the show. Thanks for having me, Mike. We see these use cases all the time.
I think most commonly people are seeing, uh, vision applications and everything from factory floors to cars, but a lot of the efforts underway seem to be still experimental and people are struggling. What's your assessment of what's going on here? Yeah, definitely.
So first of all, just to generalize it to all of ai, I think that's kind of the state of play in 2025. You know, we've had studies from places like Harvard Business Review sharing that something like 80 to 90% of AI initiatives within enterprises are not yet reaching production. You could call that a failure.
I would just call that kind of expected or par for the course. You know, this is new technology. There's lots of rapid innovation, there's a lot of excitement to try new things and build proof of concepts.
Unsurprisingly, uh, something that you cobble together in a few weeks or even months, is unlikely to meet the needs of the production environment that you need to deploy that into. And that's perhaps, you know, uh, most poignant in something like visual AI where we're talking about deploying, you know, robots or vehicles, uh, or automations that have to act in the physical world and deal with all the different sort of nuances, edge cases, strange scenarios that might crop up. So yeah, there's definitely a need to invest, you know, kind of the typical 80% of the time to get that last 20% of the way to production.
Uh, but the good news is that folks are aware of that, uh, and companies like ourselves are building technology to help assist, uh, you know, practitioners of visual AI address those key, uh, needs, which we can dive deeper into and get that model ready for everything that the production Yeah. The real world, uh, will throw at it. Alright, well, to your point on that maturity curve, where are we when it comes to vision ai?
Because, um, I guess there's some unique challenges there, but what are they? Yeah, so the interesting thing about visual ai, and by visual ai, I mean, anything that has to do with image or video or 3D uh, lidar radar data, um, that's an absolutely immense data source. Something like 90% of all of the bits that go through routers on the internet today are actually visual in nature.
Uh, so the vision AI challenge is at least two orders of magnitude larger than the challenge, uh, of building models that can, for example, process text, right? So it's kind of expected that it'll take some, you know, additional time and effort to get these things, uh, ready for production. Of course, the good news is that with all the investment going into accelerated computing infrastructure, you know, data centers, power r and d, all the things you hear about in the news, uh, those advancements are coming.
The, the promise of being able to feed larger scales of data into these systems, uh, is also coming. And so I would definitely expect to see continued progress on some of the kind of bulletin board vision AI use cases that everyone's familiar with, self-driving cars, humanoid robots. But maybe most, uh, exciting to us are kind of the more incremental advancements, you know, automating specific scenarios like maybe defect detection in manufacturing context, uh, or building purpose-built expert systems that can, for example, you know, uh, detect the fall, uh, of a, a human in a healthcare context, uh, or automatically, you know, process, uh, a camera feed to make a decision about whether a part is, uh, high quality or low quality.
Those kind of things, uh, are much more short term. Uh, and we're seeing those types of technologies get to production, which is very exciting for the, the vision AI field overall. Mm-hmm.
I think everybody's excited about the use cases, but it seems to me they're also running into issues around, well, what does it actually cost to run something in a production environment when you add up all the infrastructure and resources required? So do we need to be smarter about what projects we're gonna pick with an eye towards what's gonna go into production sooner than later? Yeah, I, I think it's a great call out.
So, you know, uh, one of the exciting things that's happening in the AI space is the progress of these, uh, so-called foundation models. The large models, you know, the GPTs, uh, coming from hyperscalers and, and those models are, uh, have a broad expertise of knowledge. Uh, however, large models are expensive to run.
Uh, and so what you can expect to see is those models knowledge getting distilled into smaller expert models that are more efficient, uh, at solving, you know, specific tasks. Uh, and so, you know, that's what's actually getting, uh, into production, uh, in vision AI especially, is these distilled models that are purpose-built for specific use cases that can run at a much more cost effective, uh, price point. As you kinda sort that out, who's gonna build those smaller distilled models for organizations?
Is that some data science team that they hire? Or are there specialist organizations that are emerging who are gonna basically make those things available as a service? How does this kind of manifest?
Yeah, so what we're seeing is that enterprises that, um, are having the most success and visual AI are ones that bring the development of these sort of fine tuned systems in-house. They treat, uh, their AI strategy as a core part of their company's competitive advantage. Uh, and so they want to bring as much of that development in-house as possible.
That definitely means using off the shelf models, uh, data sets and so forth, uh, to sort of, you know, turbocharge their, their development. Uh, but they see their ability to develop, uh, a high quality data set, uh, and model that's an expert in their use case, uh, as being critical to their, uh, company strategy. What are the skills that are available as it relates to this?
And I'm asking the question because, well, we're already having a hard time just finding your everyday run of the mill data scientist genius, and how many of them are actually cognizant of visual AI and, um, what does the pool of talent look like? Yeah, so for context, uh, a little bit about myself. So I have a PhD in machine learning.
Uh, voxel was founded by myself and my co-founder, Jason, actually over 10 years ago, uh, initially doing consulting, uh, in, back then it wasn't called visual ai, but rather computer vision. Uh, and so computer vision as a field has actually been around for quite a long time. In fact, even Nvidia as a company, uh, got its start and spent many decades focused on computer graphics, the kind of, you know, uh, low level computer vision, uh, algorithms that are necessary to, you know, build graphics engines, video games, so forth, right?
So there's a rich history and, and expertise in, in the, in the market that exists in computer vision. Uh, and, you know, so that's the good news. There's lots of, uh, you know, capability out there.
And then, uh, what we're seeing is that whenever there's advancements in sort of overall AI technology, uh, those models, those architectures can be deployed not only for language use cases, but also for vision use cases. And so the visual AI field definitely benefits from all of the advancements that are happening in, you know, large language models. Uh, as an example, the, the transformer architecture that Google created a couple years ago, uh, was very important both in language but also in vision.
Mm-hmm. Of course, it takes a village to kind of build these applications and there's developers involved and, um, data engineers and all kinds of folks. But, um, how do I meld them together?
I think a lot of organizations I talk to are struggling 'cause the data science folks have one culture and the developers have a different culture and they're not quite in sync with each other about how to not just build an app, but maintain it and update it. That's a great point. So, you know, historically what we've seen is that some, uh, companies have decided to kind of create separation between what they call their data team and then their model or product team, which might result in kind of a separation of duties where the data org is responsible for building data infrastructure, maybe gathering data, and then throwing it over the wall to the product teams that then make use of that data kind of a one way street type of modality.
Uh, however, you know, especially when we're talking about model failures, what we're seeing is that the ability to overcome model failures and actually get a system into production, like we were talking about earlier, that comes really from the iteration cycle, being able to understand, okay, I built a data set, I trained the first version of my model, where is it succeeding and where is it failing? And inevitably, if it has a failure, maybe an edge case or a certain type of bias that you've discovered, you need to address that, uh, through better data. It's not sort of a one way street, it's an iterative process, and you're in the best position to make that kind of, uh, action to improve your model, uh, if your data and model teams are working closely together.
So, as an example, uh, our software 51 that we deploy to enterprises, it kind of puts the data at the center of the entire development process of visual ai, allowing data teams and model teams to collaborate together in one place. And when they see a model's performance or lack thereof, that underlying data is always one click away. So with just a click of a button, a user who's trying to, you know, evaluate a model can understand, oh, I see this is why the model's performing poorly.
I can see that there's, uh, something I didn't expect about my data. A bunch of it is low light or low quality maybe, or it's having problems in the self-driving yeast case, uh, you know, understanding, you know, sort of crowded intersections and low light conditions. If I'm able to go gather more examples of those problem areas, that'll be the most effective way to improve that model's performance.
Mm-hmm. How readily accessible is that kind of data? I think, you know, you hear people talking about how all the data that's publicly available aren't even sucked up.
So do we have enough of this visual data to train the models going forward? Yeah, that's a great point. So, so that, that kind of, uh, quote, uh, is most often used about large language models, people are saying that, you know, the reason that let's say GPT five had a smaller delta than one might have hoped over G PT four, is that we've already ingested all of the data that's available on the internet.
And that's definitely not true of visual ai. Uh, like I said before, there's, you know, 90% of all of the bits that go through routers on the internet are visual in nature. Uh, and there's definitely a vast amount of untapped data in visual, uh, it's visual in nature, uh, that is yet to be fed to all of these models.
Having said that, uh, one trend that we're seeing with our customers is, you know, kind of by definition where you need to spend all of your time are on the edge cases, uh, or failure modes of a system. And those are rare, they're hard to acquire. And so companies like let's say Tesla are in a, a good position, uh, where they can, for example, trigger, uh, anytime there's a, a hard braking event in a vehicle, they can capture that scene and feed that data back to headquarters and use that to specifically address that, you know, sort of failure mode.
So being able to connect to your development process, to the products that you're putting in the real world, that's a great way to gather more data. On the other side, we're seeing, you know, synthetic data as an example. You know, we partnered with Nvidia, uh, to make their, um, neural reconstruction, uh, models available to our customers.
That's a situation where you can generate a synthetic version of a scene, and then you can play with things like, Hey, I've got this scene. Uh, what if I swapped out that FedEx truck for a UPS truck? What would happen then?
Or what if I took this sunny scene and I wanted to consider how the model would perform if it was instead snowy or rainy? Uh, you can perform those types of, you know, uh, you know, uh, synthetically generated tunings, uh, you know, uh, from a model standpoint, which obviously gives you the ability to plug those gaps that may be hard to acquire, uh, real data for now. I would say that that's kind of a, you know, uh, up and coming technology, uh, and there's definitely interesting questions to be answered about, you know, how do you evaluate how much real versus synthetic data you need, uh, to build, you know, a production ready model.
Uh, but it's definitely something that our customers are excited to, to tap into. It also seems to me the tolerance for being wrong in these apps is a lot less, shall we say, than it is in your typical, um, you know, chat GPT type of application where, you know, if the thing hallucinates on some sort of summarization, I'll notice, but, you know, if it's not the end of the world, and I'll shrug, but it feels like with the visual ones, that those applications are a little more, shall we say, mission critical. Is that fair?
Yeah. I think what you're getting out there is that, you know, and this is kind of maybe obvious with hindsight, but the key to getting these systems into production is choosing the right use cases. And to your point, the right use cases, especially early in the development cycle, are ones where the, the system or the use case can tolerate a failure.
So yeah, if you're, if the task is to summarize, uh, some content, uh, for a human to take action on, and if it's not quite right, you know, there's a human in the loop already, and so maybe it's okay, right? Uh, on the other end of the spectrum, you could see something like a self-driving car where, you know, it makes kind of intuitive sense that it needs to be, at least in order of magnitude safer than a human driver in order for us to kind of accept, uh, any sort of failures that might happen. Uh, but the good news, like I was saying before, is that in addition to the sort of, you know, bulletin board use cases for visual ai like fully self-driving or fully humanoid robots, there's a lot of, uh, smaller more sort of focused tasks like detecting defects or, you know, uh, automatically processing, you know, user imagery for insurance claims where there's a lot of summarization and sort of constrained environment tasks that can reach production level and will, you know, uh, add lots of value to us while we continue to push towards those bulletin board use cases.
Kind of similar to how everyone spends some fraction of their time talking about what a GI will look like when in reality, uh, those use cases like, you know, automating customer calls, uh, in service centers or, you know, summarizing, uh, knowledge work, uh, for enterprise. Those are the real value creation in the short term. And to your point about that, you know, everybody talks about, well, who moved my cheese and am I gonna get laid off?
But when you look at those use cases you're talking about, some of them are things that we probably would never have done in the first place, and many more of them are things that well, nobody really enjoys doing in the first place, and we typically don't do it all that well. So is that part of the thinking about where to make use of something like vision ai? Definitely.
Right. And, and just to put a point on maybe a macro trend that's happening right now and how it's impacting the visual AI space, uh, you know, we're talking a lot these days about onshoring manufacturing for various, you know, political reasons, uh, you know, so forth, which we won't go into here. But, you know, there's this sense that, well, uh, there's, there's certain tasks, sort of menial tasks in factories and so forth that maybe, you know, some fraction of US workers aren't interested in doing, or it doesn't make sense to do, uh, at sort of like human level price points.
Perfect use case for vision ai, right? We can come in and invest, uh, as we're onshoring manufacturing in building automation, uh, and they, you know, building out factories that'll put us in a, you know, uh, competitive advantage compared to, you know, even our, uh, offshore, uh, competition there. Well, let me ask you this then.
Um, is this really a separate discipline in the sense that there will be a separate ecosystem for it, or, you know, are you at all concerned that the open ais of the world and everybody else who's in that space is just gonna, you know, just add this to their portfolio of services? Yeah, so that, that's, um, kind of what I was getting at before when I was making a distinction between, you know, what a foundation model, uh, can do, uh, versus, you know, what's actually required to get that particular use case fully automated and in production. Uh, you know, there's, there's interesting conversations happening right now.
Let's take on the language side for a second around, you know, hey, if, uh, if it is true that these large language models have quote unquote PhD level knowledge in all fields, then why do I need to go to a healthcare provider? Why can't I just go to chat GPT and have it solved, you know, provide my diagnoses and provide a plan of action? While there's not, it's not just as simple as providing the knowledge.
There's expectations around, you know, quality of care and certification and so forth that come out. And for that reason, it's not gonna make sense for a single company, certainly in the short term, to provide sort of expert level guaranteed certified services and all these use cases. Uh, and I would expect the same thing to happen in vision ai.
You know, it'll make sense for vertical specific companies that deeply understand use cases and customer needs and so forth to take a technology, a general purpose technology off the shelf, and build a solution for a specific vertical. Uh, not to mention the, the, the point I mentioned earlier around how it's not cost effective to take that general purpose model and plug it in directly. That may be sufficient to build a proof of concept to show that something can be done.
But ultimately to drive margins up, costs down, you're gonna have to invest in building more expert, you know, fine tuned systems. And that clearly has to be done by a, you know, an entity that's focused on that one vertical and ready to make that commitment. All right.
Well, folks, you heard it here. There's a lot of things to be excited about in the AI era, but maybe all the cool kids are starting to hang out in the visual AI table because that's where the new and interesting applications are gonna be. Brian, thanks for being on the show.
Thanks, Mike. All right. And thank you all for watching the latest episode of The Techstrong that AI Leadership series.
You can find this episode, others on our website. We invite you to check them all out. Until then, we'll see you next time.
Ah, I love the smell of a rational exuberance in the morning you're watching Textron Gang. Hey, good morning everyone. Happy Tuesday.
What a Tuesday. This is coming off a crazy Monday. Yesterday, you know, I, I thought things were so overheated that we were gonna like reach the superconductor phase pretty soon, but yesterday, I, you know, we torched it yet again even higher with, with the most recent announcement of this open AI A MD deal coming on top of Huawei News and TDK and AWS advancing their own chip business and rumors of an Intel and a MD hookup.
You gotta love it when chip makers hook up. Do they make baby chips? I don't know.
Um, but so, so much going on, so much going on. We've got a great gang to discuss this with. Let me introduce you to our gang members.
We've got JP Morgenthal Sporting a new, a new set at his home studio, uh, Chaya Gun, gun Chaya, welcome Steven Foskett, as usual from downtown Hudson, Ohio. And, uh, coming at us, I think from Barcelona today where he's a Yankee refugee, he just couldn't stand it anymore. Mike Ard.
Hey, gang guys, gang members, welcome. Thanks for joining here. So, Mike, when half of the U-S-G-D-P is data center and, and AI related, and as the time says, we, we have a bifurcated economy, the AI economy, and the rest of the economy, are we in a bubble?
What the heck is going on here? I think we're in a small bubble, but I look at these, um, announcements from various folks and I say, Hey, maybe rational thought is starting to prevail here, and here's how I get there. Well, maybe AMD's got a little more efficient processor capability.
I mean, OpenAI found them for a reason. They're not just doing it for the heck of it, it, I'm assuming it's not just some second source supplier that they actually intend to use these chips. And there's also been advancements to your point about Huawei and, um, TDK, and everybody seems to be working on chips that are more efficient in terms of the use processing of ai.
And I almost feel like we lost sight of that goal or that requirement, because every time I look at every announcement for the last two years, it always seemed to be about, well, how can we figure out how to use a bigger banner processor instead of being more efficient with what we have and what we need? And that's why we have all these big data centers in the bubbles. But jp, am I engaging in some wishful thinking?
I think that the, you know, there's just a, a, a natural inclination, still was so much room to run. There's such a big runway on this technology. We're we're just really in infancy, right?
So, you know, obviously, uh, optimization, uh, is one of the key things that has gotta take place. There has to be, uh, some answers for the economic, um, management or, uh, profitability at some point, uh, of these platforms, which, you know, I think some attention has already been paid to. This just doesn't make sense financially unless you're looking at it from the long game perspective in which we're seeding a market, uh, with the expectation this technology will eventually become, uh, less expensive to, uh, buy and operate it.
And you're building in your audience now, and, and hopefully they're sticky. Uh, you know, there, there's a lot going on with, you know, just general new market movements. And there are market makers is a, the technology is changing rapidly.
You have a number of players, you know, if you remember the discussion in the beginning was Nvidia, Nvidia, Nvidia, Nvidia, Nvidia, everything was Nvidia. Now you, you have a MD, you have, uh, AWS you have even TDK, right? Uh, you have a number of players that are getting into the, um, game of providing, uh, not just GPUs, but asics around AI and AI processing.
And so, uh, you know, this is just gen general build out and, and infrastructure and chip makers finding their, their place, uh, or making their way at the table, pushing their way at the table. And so, you know, we don't, we don't even know what the outcome of this might be, right? We, if, if we, if we're seeing significant improvement at lower costs, that's gonna have a huge impact on how the market, you know, starts to, uh, move.
And, and who's doing deals with who. Like you said, OpenAI probably, you know, has communications with every chip manufacturer out there in the world. I'm sure they did a very thorough study.
Why did they choose a MD? I'm sure it was a combination of factors, but, you know, the, the point is that they did the due diligence and they chose a MD for all we know. It could have just been the fact that a M D's the only one who agreed to give them 10% stake.
But it's true, right? I mean, uh, upside on the business, right? But here, the, if open AI put their weight behind a MD, what's that gonna do to Nvidia?
It definitely shuffles the deck. Sure. So for me, uh, the way I look at it in the chip market, it was nvidia.
Now, there are other players, which is good. You get a better technology and speed up in terms of the timeline, the way the chips are developed. But my concern is, as in terms of usage, it's only OpenAI that's controlling all these chip providers who are the competitors for AI open to challenge that these are the chips used for this business use case, because, uh, believe it or not, we still haven't find a good strong business use case for AI yet.
So that's something I will leave for Stephen to comment further. Yeah. Yes.
Believe it or not, we still haven't found a use case for this. Absolutely true. And, you know, the thing is, I, I think that, uh, you know, to be a little bit cynical here, um, the reason they made this deal with a MD is because a MD is effectively paying them for the deal.
So for, for, for reference 160 million shares of a MD stock, which is what, um, OpenAI stands to potentially gain according to multiple milestones of delivery, is worth $33 billion. Which is effectively, um, I don't know that it's exactly the amount of money, but that's a lot of money that is going to be used then to buy a MD chips to power this, uh, approach. So essentially, this is the same game of passing around revenue in order to subsidize sales.
And, and, and, you know, in this case, it's only two players. Sometimes it's three players, sometimes it's four players. But essentially that's what we're seeing in Silicon Valley right now.
We're seeing companies passing around revenue in order to all write up, uh, massive sales that aren't actually leading to anything necessarily. Ultimately, like Chaya said, the thing that we need is productive and beneficial and financially rewarding use cases for all of this work. We are not seeing it Yet.
So let me jump in here and be patient with me. I got a lot to say on this one. So first of all, Mike, there is no such thing as a little bubble.
You know, my father rest, his soul used to tell me if a Jewish person is going to eat pork, they shouldn't nibble at the corners. It doesn't pay. Go for the meat, go for the gusto, let it like the juice run from your mouth because you're sinning anyway.
So there is no little bubble. There's a full on, there's a full on pigs at the T trout bubble of total irrational exuberance. Steven, to your point, and Charlie to your point, what we have here is a situation where basically the GDP, the investment in AI is roughly the size of Singapore's entire economy.
The profits in output is roughly the size of Somalia's economy, right? It doesn't end up, it doesn't add up. You look at these deals, God bless Sam Altman in OpenAI, he's not distant Nvidia, he promised them hundreds of billions of dollars in business last week.
This week he's, he got 10% of a, of a a MD. And by the way, we're not using these processors in Stargate data centers in Texas and here and there and everywhere. These are gonna be yet different data centers, I assume, in the US because everyone has to make Duche happy.
But my question is, when are we going to pinch ourselves and say, who, who are we kidding here? This is a Ponzi scheme. This is me giving it to you.
You giving it to me, me giving it back. I give it to the next guy. He trades it to this guy.
com. I went to Houston in this big building that had an e at the bottom of it. You know, the building I'm talking about?
We were in a, Yep. I used to work across the street from that building at their competitor. So, you know, that building, we were, we were stuck in a bad contract with WorldCom buying bandwidth.
Not much different than buying a and d about AI chips. And we, we, we were paying a thousand dollars a megabit. The market rate was six, 700.
They invited us down. I sat at a long table. There were like eight different Enron people around me.
Each one of them had a card that had a different division of Enron. And they told me if I sold my WorldCom bandwidth to them and a thousand dollars here a megabit, he would give it to him to give it to him, to give it to him, to give it to her, to give it to him, to give it to her, to sell it back to me at 600. How do you do that?
Arbitrage. We are the kings of arbitrage. We know what we're doing.
I walked outta there. I asked my CEO herb rebar. I said, herb, how did they do this?
He said, Alan, it beats the s**t outta me. Either they're the smartest people on earth, or they're the biggest crooks. As it turned out, they were the biggest crux.
Mark my words. This is a Ponzi scheme. I, you know, I, when, when, in, in terms of a little bubble, when AI and data centers represent 50% of the GDP of the us, when this Ponzi scheme goes south, we're, we're all getting dragged down into it.
We're all bating the hatches put on your life jackets because this is going to, this is gonna make, this could make 1929 look like a picnic. Let, let me add something about the a MD deal that I'm really, I have to say a MD you might think that a MD is being taken advantage of here. No, no, no, no.
They're the smart ones here. Effectively what they've done is they've guaranteed that future open AI models will run on a MD hardware. They've guaranteed a market for a MD hardware and all this.
IC The table Very low cross of nothing, because it's all predicated on shares and stock market valuation. So effectively, a MD just earned them, just bought themselves a, a seat at the table for nothing more than some theoretical stock. And that's pretty good way to enter the Ponzi scheme.
Absolutely. And a MD was always the bridesmaid and never the bride. Right?
And now they, here's their wedding day. God bless 'em. Mazel tough to a MD.
But here's the next thing. Let's go beyond the a MD open a I deal. Look, last week we had news, uh, from deep seek, right?
They're coming out with an intermediate, more efficient, right? The Chinese clearly are, are trying to play the role of the Russians in the, in the migs, right? Making a, a cheaper but effective jet fighter.
They're making a cheaper, effective ai. Huawei unveils this sink, S-I-N-Q-I don't know if it's sync or synq. Um, we mentioned TDK with their own announcement of a, of a, a, a chip that never lo loses rock paper scissors.
That's, that's a reason to buy a chip. Okay? In case for all you rock paper scissor players out there, there's, well, The DDK thing is, is very different than that.
But yeah, There's, there's a way, there is a world of difference between saying I have a design and actually building it at scale too. So that, That's another thing. I I, There's a piece to this that you're leaving out, which is they've created a sticky technology.
All these people who are now have made changes in their business to incorporate generative AI as a component of how they do business. Um, you can't just shut that off. So these companies, you know, when the, let's say it does quote unquote blow up, where do these people turn?
These people are gonna have to turn to doing it themselves, buying their own hardware, setting up their own data centers, uh, you know, being able to deploy and move the, their calls to the commercial LLMs to local LLMs, right? If, if it should blow up. I don't see how it can blow up.
It. It's getting to that too big to fail. Too big to fail, I think you just can't pull the rug out.
It's like When you start hearing it's a new paradigm and a new, a new reality sell. I, I don't, I don't disagree with you that there is something amiss, that it's fishy. What I'm saying is it's connected to this, you know, this parlor game that I think that people are gonna keep up.
They're not gonna let it fall down. Because if it falls down, it, it's, it's devastating beyond just the, the small market that you know, is, is creating the bubble. Well, You gotta have total faith at the people in the administration.
'cause after all, they would never let that happen. There's a guy who never declared bankruptcy. Hold on.
Chaya, let me ask you something. So, let's say that I am company A and I have an investment in an, in, in company B. Company B is makes a processor.
And it, I have no real incentive anymore to run my software more efficiently. 'cause I'm making money every time that that processor gets bought. So, um, it seems to me like the bubble will bust because there'll be more efficient software, but open OpenAI might not have the incentive to go bust that bubble anymore.
'cause they're now got money coming outta the hardware side. So I think that there's a mismatch here in terms of, um, goals and value to shareholders, Right? I, first of all, for me, it's not a bubble, it's a technology evolution.
I would say being a technologist myself, I just think the whole way of the way software are being developed over years has been changing. And because it's such a big shift, it feels like a bubble. I don't think it's a bubble, it's just that it'll get stabilized in terms of every week there's a new news that is coming up.
So there, there's gonna be a point where there'll be standards of technology and it'll stable it down. And that's when the competitors to open AI will also come in and will have players on both side. So the negotiations will be on the table.
Right now, it's OpenAI versus all the chip providers. That's kind of, uh, is what the game looks like to me. Um, for now, going back to the deep seek point, what Alan just made, uh, remember when, uh, deep C came for the first time and the market crashed because people think that, oh, this, we don't need a hardware.
We can run it. I played around with that technology myself. It is nowhere close to what we have with open AI models and the way of efficiency that yes, it's a good experimental thing.
So I don't trust that technology enough that we start using it for business use cases. So there's a lot to go in, in deep sake to gain that trust. What existing, um, generative AI models with open AI and existing chip providers are been promising at the moment?
I don't think it's generative ai. That is, is that's the, the push of this, I think it's agentic ai. Yes, kind of.
I think they both are go hand in hand on top of it. Agentic AI just gives you more power, but it's equally risky also, right? Because it, you, you have less control on in terms of the actions it's gonna perform.
And, and then we, we haven't discussed AWS right? They're coming out, what is it? The Tanium, not Tanium.
Tanium three. Tanium three. Yep.
Right. You know, how long is it gonna be till Microsoft or Google do it as well? Um, They already have them.
I mean, they already have in-house. Asics. Yep.
Yeah. And then, you know, Broadcom is part of this, guys, it, it's all in, it's all in and, and China, you know what, I remember what yours talking about. I remember saying in 2000, the company I helped take public too big.
Of course, you know, if we're going to use all this technology, every company's gonna have a website, we're gonna need all this bandwidth, we're gonna need all those data centers. And then the bubble did burst, and it took almost 8, 9, 10 years for us to recover. Back to that point, no matter how you deal it, like when did the NASDAQ go back over 20,000 or whatever it was.
When did, uh, you know, when did we stop having all that dark fiber? When was all that dark fiber actually used in the data center build outs? I'm not saying that AI is without merit or without value, but when you are turning the largest economy in the world to 50% of its GDP, the data center, you know, the old saying about putting all your eggs in a basket, you wind up with a lot of egg on your face.
Right? But if you go back to the bubble that you just referred, best of the companies did came out after that bubble. Google came out after it, Amazon came out after it, and they are the trillion dollar companies today.
So We, but, but it, it took 10 years. Yeah, but can You, and for every, for every Google and Amazon, there were a hundred or a thousand companies that are cratered that went outta business, right? So I'm not saying there's not gonna be winners here.
What I'm saying is, you know, I'll quote my, you know, bill Clinton, this is simple arithmetic. The numbers don't add up. The numbers don't add up.
There's just too, you know, it's, this is like a Bernie Madoff gone wild. Yeah. And, and just to be clear, the bubble isn't ai.
No. The bubble is using this circular economy of investment to bolster the irrational and and excessive investment into specific AI hardware. The, you know, the rest of this stuff we're talking about, you know, deep seek, like Chi was saying, um, agen, ai, asics, all of this stuff actually makes sense and I can see a market for it.
The problem is that we're that there, that there's also this thing over here that's just churning through money. And for what, Who gets fooled by this then? Because you would think that there are, uh, wall Street who gets fooled AMDs up 32%.
Yeah. Yeah. So that, but you would think that the Wall Street analyst would be wise to this circular shifting of money.
But they seem to be all in on it. I, let me tell you something. Oh, God.
Does the name Henry Blot mean anything to you? Yes, he was, he was our advisor at Interline. The company I, I helped when we went public in 2000, Henry Blot was our advisor.
He was touting us and, and taking us public at the same time. What, what, what do you think Wall Street has clean hands here? This is, this is a made, this is, this is a made by Wall Street movie.
I I think some sort of poor day trader investor gets hurt at the end of the day Because that No, because they don't, because they're playing it too. A MD is up 32% today. There are day traders who made a fortune today, and if they're smart, they'll take their money and go home.
But they may think like Shire and say, well, no, this is a new, a new normal. There's a new paradigm to last two weeks ago, it was Oracle. Today, it's a MD tomorrow.
It could be, I don't know. But I, I wanna, you know, who was it? A, a sucker and his money When I feel it's everybody's winning.
Everybody's winning. I being the shareholder of Oracle, it went up to three 40. I was happy today.
I, I have seen woke up with the news that a MD has gone up. I don't mind being this in a circular economy for some more time till, till the stocks Up. I didn't mind it either.
That's when I thought I had my children's college education paid off in 1999 when they were 1-year-old. com stocks that I loved watching them go up in Yahoo and everything else. And then in 2001, it wasn't so pretty.
Wasn't. So you're Telling everybody to short those stocks? What are you saying Right now?
I would never give investment advice. That's not me. Yeah.
You know what? I will give investment advice. My investment advice is trust a competent professional investment manager.
And don't do this yourselves. I have zero insight into my stock and, um, holdings, and I have professionals handling it. And hopefully they will help protect me when all of, if all of this changes.
Yeah. How's that for investment advice? Leave it to the professionals.
There you go. Sane, sane. All right, Mike, I'm gonna give you the last word.
I think That this battle is just beginning. And I think we're gonna see much more efficient AI models and that will bust the bubble. com bust go.
I just think tech is gonna become more efficient, as it always does. We shall see. All right.
Hey, we're gonna take a break here on Text and gang. Let's come back and talk about checking my notes. Ai, you are watching text and gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back. And yes, we're talking about ai, but maybe, uh, hopefully a killer use case for it.
HPE has got a whole, uh, service Now and around an AI platform that they've built to come up with Section 5 0 8 compliance faster. It involves, uh, of course using their AI platform, but they built something with DataIQ and SHI as the implementation for all this. And 5 0 8 has to do with the American Disabilities Act.
And it takes a long time to comply with all these requirements. But what's interesting about all this is, this is not the only thing that maybe we could shorten the compliance window on it. Instead of taking years to make sure that we comply with all these regulations, we could do it maybe in months, weeks, China, and maybe the whole cost of compliance comes down.
And who knows, maybe politicians stop b******g about what the cost of regulations are. 'cause we can just do the right thing and do it in a way we can afford, Right? So I like their initiative that they're treat giving compliance.
The weightage in the world of ai, west feed matters and compliance and security and policies are always the way which slows down the things. But, uh, again, in the world of agent ai, how do we decide which are the right compliance policies, right? So there has to be some rules, some intervention based on the use cases that can cover up.
For example, when we talk about disabilities and compliance, what disabilities are we talking about? Who are the beneficiaries of these policies so that we can give the advice or we can give the advantage that now this is the best use case. This is where it it's going to be used going forward.
So who is setting the benchmarks here? Is it HPE setting? It?
Is it the, they have done an industry analysis and they are saying, here's what, how we have done it. Maybe industry can follow the trend. So yes, compliance is a good initiative.
Identity AI can help expedite the development of it. But I am just, uh, right now more in terms of concern, in terms of what are the driving factors for this. I think if we go along here, you can start modeling it out and say, Hey, how much are we spending going to Alan's point about the GDP, how much money is spent on compliance with all these different security initiatives and every government and every state.
And then you map it up around the world and there's just a boatload of money being spent on something that doesn't really add value. I mean, it's important, but it doesn't add economic value in my mind. So I say automate this stuff as much as possible, and those are the use cases.
And nobody likes doing this job and nobody wants to audit it. Anyway, I gotta disagree with you, Mike. Mm-hmm.
Compliance is security's bastard son. Okay? And if, and really what compliance represents is lowest common denominator security, a basic floor, if you will not ceiling a floor of the minimum you should be doing in terms of best practices, security wise, and everything else.
Now, the instant case here of the HPE, automating section 5 0 8 compliance is not really the compliance. Those are not the droids you're looking for. This is compliance.
We're making a website, uh, accessible to people, let's say, who have vision or hearing, uh, disabilities or challenges, right? And so you have all texts and, and all of the things, it's a very, it's a very well established sort of model. And, and it lends itself well, I think to an a, uh, an AI type of situation.
But when we talk about compliance, it's talking about are you masking PII are you encrypting data in transit and in rest? Are you ensuring, you know, your certificates are up to the latest things, right? G governance, risk and compliance GRC is, is, you know, I I said it in jest about the bastard son of security.
It's an integral part of the security, and it's important. I think We're looking for rehan and stepchild. There you go.
These things are being automated today. Let's let, let's not pretend that this is new. They are, they just require humans to spend time developing the automation.
Like the change here is that the AI has the ability to, uh, alleviate the need or the, at least the, the amount of degree that a human needs to be involved in order to check this stuff. So you can, you have what's called the large action model, and it understands, you know, basic UI uh, interactions, right? How to press a button, what it should look like, and it, you can train it to say, this is what it, these are the factors that need to be on the screen in order for it to be compliant with 5 0 8.
And so it very simply, it, it's very simple to tell an ai, listen, here's the script of things I want you to test. Make sure it's 5 0 8 compliant. It understands what 5 0 8 compliant means, and it'll walk through the script.
And no human has to sit there like with an RPA tool, validating and putting all those steps in manually. And it does, it's a huge reduction in time. It's a huge reduction in costs.
Uh, and, and I think what Mike was saying earlier about its value, it's an important requirement. You can't sell the software to the government and certain other, you know, um, non-governmental agencies unless you are compliant. So if you wanna sell your software, this is lifeblood.
It's table stakes. Um, but you're right. It's not like it's something you can advertise and say, look, I got 5 0 8 compliance here.
Uh, you need, you know, so that makes me better. So, uh, so the fact that you can pawn that off, and it's no different than what's happening in many QA functions. Uh, a lot of the QA functions and software engineering are being handed off because, uh, again, this is not something that you can charge for, per se, uh, that quality, but you, but it's expected and, and it's now requires less human intervention to get there.
And, and I'll just say too, that this may not be, uh, so, so let's kind of refocus on this particular story here, section 5 0 8 compliance that's about complying and, and helping people with disabilities to be able to use software that may not be a big selling feature for a lot of people, but it's a life or death feature for some people. And as somebody who's active in the dis disabilities community, I can tell you that, um, having websites that are compliant with section 5 0 8 is, um, and I am not joking, is life and death to people who have visual disabilities or motor disabilities or need to use alternate input and output mechanisms. Um, you know, being able to access the social security or the disability, or the Medicaid or Medicare or local disability, uh, websites, uh, using alternative methods.
That's the whole ball game. And not only that, but it's the whole ball game for these agencies as well. So if you're a board of developmental disability and you're, uh, software and interfaces aren't compatible with alternative disability inputs, well then you might as well just go home.
So I'm actually really thrilled to see this. I want to, you know, give a little shout out here to the folks from kaza who are, uh, field day presenters. Their, their hearts are in the right place.
They're, they focused on this because they care about this product and this and this segment of people. And, you know, I mean, it's easy to get angry and oh, ai, all this and that, but this is a case where we're actually using AI for something useful and, you know, give 'em a pat on the back. I think this is the beginning of a much larger trend, and I think I'm really happy to see section 5 0 8.
That's great. But I think this is gonna play through just about every other compliance mandate there is out there. And this is gonna be the thing that a lot of folks are gonna say, Hey, ai, AI delivered some actual value here.
Because a lot of this stuff is, consumes an inordinate amount of time. It's costly and it's expensive, and it, not that, but it's just scut work at the end of the day. Yeah, because that was your best Bogart imitation how Mike Louie, this is the start of a beautiful friendship.
There you go. Hey, we're gonna take a break here on the gang. Let's come back and we will move into our C block, which is around, wait a sec, checking notes again.
Microsoft and Security. Is that an oxymoron? You're watching?
Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in. Yes, Alan's point.
We're gonna have a little chat about Microsoft and security and well, some people love 'em and some people hate 'em, and some folks are just in between. But the latest thing outta Microsoft is that they are gonna use graph technology to make it easier to integrate all these different security tools we use. And within the security world, there's this debate going on about whether we should centralize everything on a platform and that we can get rid of our swivel chairs.
'cause we'll all have one set of integrated tools. There are others that continue to say, you cannot rely on one tool and you need to have layered defense. And Microsoft here is gonna make that easier because we're gonna use graph technologies to integrate all the tools, and we'll live in a more of a kumbaya kind of world in security is yet to be proven.
But this is the ongoing debate, and I know that Steven, you were think coming up around, um, uh, Microsoft in an event that you're doing with Tech Field Day. So you guys are following this space pretty closely, but I don't know, what's your take on what's going on here? I mean, I seem to see a lot more Microsoft in the security world, but you know, not everybody loves them.
Well, Microsoft is certainly stepping up in the security world. I think that, uh, they have invested a ton of money in it. Uh, you know, I mean, Microsoft isn't a charity.
Uh, they invested a ton of money in it because I think they see a lot of opportunity in it for, uh, product sales and so on. But, uh, frankly, they are investing, they are working hard at it. And of course there's a carrot and a stick here, as you pointed out.
We also have, uh, you know, uh, Ron Wyden, uh, US Senator, uh, and Microsoft critic, uh, attacking Microsoft for delivering dangerous and insecure software and encouraging the FTC to go after them. So, uh, you know, the challenge with being Microsoft is that they, as the, you know, the makers of, you know, certainly one of the most important infrastructure components in the world, and also one of the, uh, by far the leading, um, end user computing platform in the world, they have to balance a lot. And I don't envy them in many of these decisions.
So for example, if we look at the, uh, the, the, the specifics of the, uh, the Ron Weiden letter, they're talking about, uh, hackers exploiting a vulnerability that was kept in my in windows. 1% of traffic uses this, and if they had deprecated it, they would've blocked by extension thousands or hundreds of thousands of actual end users from using something that they never upgraded. 1%, let's, let's flip that switch.
Let's, let's get rid of that vulnerability. Would you maybe, would you do that? If, if it meant that it affected literally thousands of customers, uh, maybe you wouldn't.
And that's the sort of the problem that Microsoft is facing here. Now, on the flip side, Microsoft is doing some really cool things. They are improving their security tools.
They are bringing AI to bear. Um, and as you wrote about, uh, Mike on, uh, you know, security Boulevard, they're using, uh, graph technology. They're using ai, they're using MCP to build a more collaborative and flexible security framework.
Um, as we saw in, uh, the recent article, another recent article by Jeff Bur on SE Security Boulevard, they actually have been seeing some success with these tools, uh, sniffing out some pretty clever AI generated attacks. So, you know, it's not easy to be Microsoft. I like that they're really putting a lot of energy and effort into this.
And I do, uh, look forward to hearing what they have to say on October 9th during this, uh, tech field day presentation. And I think, Stephen, what I want to add is security and fun stuff doesn't go very hand in hand when it comes to ai. Um, I played around with a lot of AI tools and when I try to automate a security use case, yes, it's gonna fix one thing, but it might mess up or open up some other things.
So there's a lot of risk, I would say, needs to be reviewed before anyone adopts it end to end. My question about the thing with Microsoft is why does only Microsoft specific operating systems has this so many vulnerabilities that they have to patch so many things, why they can't build a system like Linux or, you know, where the system is strong enough and you don't even need these kind of vulnerabilities to be tackled, which can, you know, play around with users' data As, as a long-term Linux administrator, it pains me to admit this exactly, but Linux has a lot of vulnerabilities To absolutely they do. You know what, and as a person who's been in security for 25, 30 years, you know, it's hard being Microsoft because damned if you do and damned if you don't.
The fact of the matter is, when you had an operating system that at one time represented 95% of the market for, uh, personal, uh, you know, for computers, not servers, desktops, laptops, et cetera, it still represents I think 80 or 75% of, of these devices, you know, a giant bullseye on your back. It's not that it has necessarily more vulnerabilities to Steven's point as Linux or even Mac. It's that it's the bad guys exploit it, look for exploits there more so they find more.
If we put the same amount of effort into Linux and Mac exploits, you probably find a similar amount of vulnerabilities. No one has a, a, uh, a, a lock on on being the most secure. They all software has vulnerabilities.
Well, and you look, I mean, even, even Apple iOS, which is by far the most locked down operating system with the most security controls of anything we've ever seen in widespread use, and there are zero days. Absolutely. Absolutely.
And there are exploits on that platform as well. So, you know, I don't think it's credible to say, you know, lock the door because I, I just don't think you can. I, I, I think this is why in security we've moved from a prevention to a resilience model, right?
Yeah. Here's the part that I get uncomfortable with, right? So on the one hand, uh, I guess I'm just flat out conflicted.
I really like what Microsoft's doing here with graph technology and some of the AI stuff and the MCP stuff, but I also look at it and I go, so let me get this straight. You're selling software to fix the software you already sold. And so like, you know, why don't you just fix the software?
Well, so, so, so Mike, I'm a, I'm glad you raised, that was the point I was about to make. The, the story is isn't so much about their investments in security, it's how they're leveraging emerging technology to improve, uh, your, your, your security stance, your security posture, identify new, uh, potential threats that before were difficult and what they're doing. Uh, I don't look at it in the way you just mentioned, right?
One of the issues has been this is highly analytical process. It, it lends itself to time series data. Um, a significant quantity of data needs to be analyzed, and how do you share that data?
And, you know, typically in the past, you know, they've had to build the tools, the analytical tools into the product. Now they have a way of leveraging the, the actual, uh, underlying foundational capabilities like graph database and, uh, MCP to now share that information with a, uh, inference engine and allow the inference engine to do what it does well without having to yet add more weight into the product. So this is, you know, this is about the ecosystem growing and taking advantage of the ecosystem.
And I'm sure for a, a large number of customers who are, you know, in the security office and the operations teams, they're saying, this is great. I now can add my sentinel data into what I'm watching in addition to, or I can now easily combine Sentinel data with my Datadog data because I now have, and, and I can allow the LLM to drive that, right? Hey, LLI can ask Natural Language Pro tell me, is there any anomalies that you notice in the Sentinel Stream that you didn't pick up in Datadog?
Boom. It'll actually go and ask both of those platforms for the right data and then correlate them. These are things that in the past would've taken operations team, uh, days, months to build special, you know, it would've had a cost associated.
It's now an and, you know, a simple prompt. I, I don't disagree. I think you're dead on, So won't some, but I mean, God bless Microsoft for doing this, but I also look at it and go, well, won't a dozen other companies do the same thing and maybe do it more broadly across different products and use cases and graphs are gonna be everywhere.
Maybe they will. The MCP is native to the, it is just, I, I own a pro software product. I'm providing an MCP.
It's almost like providing an integration an API interface for something for, for other people to then leverage my what my proprietary stuff. That's what the MCP is. It's about allowing ev the outside world to connect in and take advantage of my proprietary, uh, universe, right?
But isn't MCP or already a table stake? I mean, everybody and his brother has one. And wow, that's, that's pretty aggressive for something that just came out less than a year ago.
I'm Aware. It's only important to the extent that you have something that you want a, uh, LLM to automate. Steven, we're in a new paradigm.
You know, I know New normal, Which has bugs. Then we are saying that, oh, we sold your software, which has issues. Now let's buy a solution to fix your problem, because we know the one that we shipped you has a problem.
Well, that's a good business. That's a good business model. All right.
Hey, we're about outta time here, though, for today, guys. What a great gang. You know, let's, let's face it, it's a, it's a, uh, target rich environment to talk about tech news these days, but it was a great discussion.
Jp, Steven Chaya, Mike, thank you so much. Thank you for watching. As usual, we have Tech Drunk TV following today's show.
Enjoy your Tuesday. Uh, on behalf of the gang, Textron Tech Field Day Fu, this is Alan Shumer. We're out, But today, we, the consumer are the enterprise.
And, and so how do we protect us going forward? Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Every episode explores a variety of topics within cybersecurity and the technologies that drive it.
com on our Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms. Before we jump into the episode, let's meet today's panel, starting with my friend Fernando. Hey, Fernando, how's it going this week?
I'm, I'm doing well, thank you. I'm experimenting with different video things here. So Hello everybody.
Fernando Montenegro. I'm VP and practice lead for Cybersecurity here at the food room group, right? And, um, we, we cover different security topics as one might expect, right?
This one is really interesting. The one we have for today is really interesting and I can't wait to get started. Uh, on that, I'll pass it over to Kate.
All right. Hi, my name is Kate Scar. I'm the chair of the CD cybersecurity sig, also, um, cybersecurity architect, and C-I-S-S-P, my focus is securing the full stack from pipelines to networks, to emerging AI and LLM ecosystems to make innovation not just faster, but safer.
Alright? And of course, I'm Tom Hollingsworth. I'm the event lead for Security Field Day and other security related events at Tech Field Day, and that's part of the Futurum group.
Uh, just like Fernando and I, and I'm very happy to have Kate joining us today because it's, uh, gonna line up to be an amazing day. But it's not the most amazing thing because folks buckle up. It is officially National Taco Day.
And how did it just so happen that it fell on a Tuesday? However, don't say the word taco next to the word Tuesday, because evidently there's a trademark that you have to worry about there. So no, no, no, no, no, no.
This just happens to be a Tuesday that includes tacos. That's not your thing, though. It's also a national chocolate covered pretzel day.
But maybe you could have both, you know, little, little meal, little dessert, uh, you know, but the little things in life, that's what really makes it worthwhile. And we wanna talk about the little things today, because this episode is gonna be all about the internet of things. You know, those little devices that seem to have completely taken over our lives.
Uh, I, I know this for a fact because last night, uh, my wife was absolutely insistent that the heater must have kicked on at two 30 in the morning. And so I grabbed my phone and I pulled it up, and I looked down there, and I'm like, no, actually, the heat's not on. Um, we need to investigate some other things that might be going on.
Uh, but in the old days, you know, I would've had to get up. I would've had to walk downstairs. I would've had to like, get a put on my glasses and flick on a light and tap the thermostat.
So obviously, iot has made my life significantly easier until someone figures out how to get on my thermostat and actually do turn on the heater when it's 90 degrees outside, because that's a thing we've heard about. And that's on the consumer side of things. We're not talking about industrial milling machines and all of the other ridiculousness.
So for this episode of Security Boulevard, it's all about IOT. Kate, you're the one that really brought up this topic, so I wanted to give you a chance to kind of open up, it's for some of the things that you've seen out there. What is it about IO OT and the intersection with security that kind of makes you lay awake at night, even if the heater's not on, Right?
So it's basically how devices have just taken over our lives more so than we realized. Um, last time, I really, there's over 44 billion iot devices, and to me, it's, you know, it's just like the tsunami of devices that we have, zero, almost zero cybersecurity, um, controls of, right? Because they're so small, they're so little, and they're very, very chatty.
So even if we try, have tried to bring them into, um, a security operation center into a soc, they can quickly overwhelm, um, SOC analysts because of the noise. And yet they're running, they're literally running our lives. So it's not just, um, the industrial internet of things, right?
We're not just talking about in critical infrastructure, the, the programmable logic controllers and the remote terminal terminal units, the RTUs and, and the PLCs. And, and I'm not, you know, I don't wanna get so deep into critical infrastructure, but, you know, there is this segue into the internet of things and how it connects and, and things that we don't even think about. Like HVACs, you know, that's iot.
Um, you know, our, our solar panels iot. And now when we think about, um, buildings and critical infrastructure and this bidirectional traffic of, um, of energy, and we're, we're not even monitoring these things. And, and I did, um, I did a, a a, like a proof of concept as I went down this path and looking at, you know, um, windmills and, and, and solar panels as an, as an example, and I am without exaggeration.
Um, we put, um, we put a solar panel, like on the outside of the DMZ, and it was taken over within four and a half minutes and added to the Mariah, Mariah botnet, so the king of botnets it. And, and, and we couldn't even like, have access, meaning we actually had to send someone into the field and, and flash the, the solar panel to, to bring it back in. Like, like it, they, they totally took it over this one solar panel.
And one of the things that I thought about is the idea is that, that we would not have known that the solar panel was taken over because it was acting as it should have until when, until until we really needed it, right? I mean, and I, and I really started to think about how many of these devices, um, from cameras, from our, from, from our, our traffic lights to signs on the internet to, um, to, to building access controls. I mean, think about just even, um, you know, parking meters today and, um, electric vehicle charging stations.
These are all iot devices that we have zero, zero visibility. So what do we do? And, and, and when I really, and I don't know why I was thinking about this weekend, so talking about, you know, weekend things that, you know, we were thinking, you know, we've all been thinking about and having to deal with, but I was thinking really about our homes and how our homes have become these, you know, these small little business centers, not only from our printers, but from, you know, from the thermostat controls to our, um, to our fridge and freezer, or to, you know, so I can just keep going on.
And all of a sudden now, we as a consumer have to be concerned about this, you know, have to be concerned about things that we typically thought was just business related, was just enterprise related. But today, we, the consumer are the enterprise. And, and so how do we protect us going forward, our, our pacemakers?
Um, I don't have one, but if I did have one, it would be right here. Um, so our, you know, these devices, all of a sudden we've also become these walking IO OT devices, uh, from our watches to our phones, to, you know, I used to have these smart glasses that were a blast to play with. Um, but yeah, Fernando, I mean, how's your perspective on this from, from the research side?
Because I know that I, I, we hear a lot about iot, but is anybody really doing a lot of investigating into just how insecure it is? Short answer is yes. Right?
But let me, like, there is so much for us to, to, to, to, like, I, I, I really excited about the topic you all. Um, uh, you may have, you may remember, uh, mark Andreesen, uh, the guy who was, uh, he was one of the leads with Netscape, uh, sorry, Netscape navigator way back when, and now he's, he, for, for years now, he's been a venture capitalist in, uh, Andreesen Horowitz. And back in 2011, I believe it's, he coined, he said he wrote a paper and he said something like, software is eating the world, right?
I say that because it's a, it's a quote that I use in some of my research for good reason, right? And yes, software has eaten the world, but software has eaten the world in, in two ways, right? In, uh, uh, within businesses.
It's because everything, I mean, technology drives everything, right? And, but what I, when I, when I think about IO ot, I think about IOT as the physical representation of that, right? Software has eaten the world, and the vehicle through which software has eaten the world outside of data centers has been through IOT, uh, industrial control systems, uh, uh, scada take a pick on the, on the on, on the different things, right?
So it has really taken the world and random thought, right? As, as, um, uh, nothing to do with, uh, I think it's this coming Friday that, uh, there is a new, uh, uh, Tron movie coming out for those that, like the original, uh, Toronto Tron Aries is coming out and have, from what I understand, has something to do with them coming into the real world. So as we were thinking about this, like, okay, there's, there's, there's an iot reference there somewhere.
But, um, but for us, uh, yes, it's, it's, it's an area that's deeply interesting. It's an area that, uh, plays a lot. Or, uh, if you, if you heard me say this, uh, a few times, but I always talk about, I always like to think about the economics of things, my degree, computer science, but if I ever go back to school, it'll be something around those lines of economics, organizational psychology, what have you.
And from an economics perspective, right? Iot introduces several really interesting problems for us, right? So, Kate, you were talking about the, the, the, the consumer side.
Well, how informed is the consumer about what they need to do with their, uh, consumer level IO OT devices, right? That problem of information of how informed the consumer is, is at the heart of information as symmetry, right? Which is a, uh, an area of economics that, I think it was the Nobel Prize in 2000, I think, uh, George Ker and, and others, that that's the, they did some research on markets for lemons, right?
The, the, the, the concept of market for lemons. So it's screaming at us that this is an area of economic, uh, uh, where, where economic concepts play a part. And we've seen some initiatives over time.
Uh, there is, uh, I don't know where we are now from a regulatory perspective, uh, but there have been initiatives around consumer labeling of divisive, Hey, but we've never really took off. And that consumer labeling is interesting, but it doesn't mean anything if the consumer is not informed, right? So if me as a consumer buy an io buy a device, right?
And, and for, uh, for this podcast, I, I, I bought a new camera, right? Uh, if I'm not aware of what the ramifications are, am I exposing myself? And, and the thing that that comes to mind, I mean, there are so many ILT related, uh, incidents we've had over time.
You of course brought up the, the, the mi I botnet, right? Um, the one that that struck me was, you know, how, uh, a few years ago we had issues with, um, uh, classified information being disclosed because, uh, soldiers were using their fitness trackers in sensitive locations, and they didn't know that that thing was being uploaded. Yeah.
Right? So the, the, the, the ramifications are, uh, uh, literally worldwide there, I say galactic, right? And the, we have iot, uh, outsiders.
Yes. I love it. Yeah, absolutely.
Anyway, long and short of it, super interesting. Uh, but there, and, and, and I, I urge people to think about them, not only from a technology angle, but what is the economic foundation of iot? And I, I have more to talk about that, but I don't want to hog the mic too much.
I'm, I'm glad you brought up economics, because I feel like the drive for IOT is all about the modern enterprise of brutal efficiency. Like, like when you think about all of the things that we've been driving towards in, in a, in the enterprise, especially around IT iot, and it, it is about making things as efficient as possible. But in order to know exactly how efficient it is, I have to be able to measure it.
And, and think about all of the things that a consumer iot gives you. It gives you flexibility, right? I can set my thermostat from my desk.
I can set my oven to preheat my lunch so that it'll notify me when I'm ready, so I don't have to keep going in there to see if it's ready yet. Um, you know, crazy things, like my fridge knows where the milk is, so it knows when the milk's getting low. So it can pre place an order for that.
That is all about making me more efficient as a person. But in the enterprise, it's about being able to measure, like think about a milling machine, right? If that milling machine is down for any amount of time, that's a literal cost to the business.
By monitoring that system, I can tell you how long it was down. But not only that, I can tell you when it runs most efficiently, how many people are necessary to be able to remove the work and to, to, to preload it for other things, which means I can keep a better cost on my staffing and, and so on and so on, and so on. Where the intersection with security becomes a problem is one of my favorite topics.
Friction. We want a certain amount of friction in security so that it's visible. Think about the airport.
Realistically speaking, most of the stuff that they do at the airport for security can very easily be automated, right? And we've seen that in other, other airports all over the world, right? You just walk in, drop your stuff in a thing, walk through, and, and it's easy.
The reason why they have to wave you through, the reason why they have to w you or, or do a scan, is because they want you to see that there's something going on. But when you're doing that with I ot, IOT's supposed to be invisible. So if you create friction that says, oh, well, you know, this needs to be authenticated, or the certificates on these devices need to be re um, renewed every two years, every point of friction for a thousand sensors for 10,000 sensors creates problems, and people are gonna chuck 'em out the window.
And Kate, to your point about the solar panel, the reason why the Mariah botnet has been so efficient is because it's invisible. If we had done this, if we had taken over all of these cameras and routers and things like that, and then made them unavailable, uh, the relative inexpensive of that chip set means that people would've just grabbed it and threw it out and got a new one. Whereas, you know, you can't do that with a $4 million paper press.
Like, you've gotta figure out how to fix that. And that's getting into the other problem that iot is exposing is that a lot of the ways that people are choosing to put these things on the internet, so to speak, with IOT, is standardizing things that historically have not been standard. Like I can remember, there's an, there's an apocryphal story about a guy who gets hired to fix a pipeline, and he walks out and he taps a couple spots with a hammer, and then he sends a bill for $10,000, and the guy's like, I refuse to pay it.
That should not be too difficult. And he goes, oh, well, I'm only charging you a thousand dollars for tapping it with a hammer. I'm charging you 9,000, because I knew exactly where to hit it with the hammer.
Like, those people who were good at programming SCADA systems, who are good at programming all those programmable logic controllers, they're still necessary to do that. But the infrastructure that they overlay that rides on top of that is pretty standard, right? It's HTTP, it is using rest APIs and things like that, which is real fun for people who know how to exploit those things.
It's like, oh, you forgot to use a certificate on that. I'm gonna have a field day. So like, is, is our drive for efficiency in the business creating these problems?
Because, well, if I have to make sure that I can monitor everything so that I can automate it or use AI to collect statistics from it, am I just creating a trap for myself where everything becomes real easy to kayak? Yes. I think, you know, it, it's a, it's one of the biggest problems, right?
That, that we continue to see with iot, because there's so many devices and, you know, how do we, how do we, we've already moved forward. So it's almost like everything else, um, when we look at, when I look at LLMs and things like, like, like the, it's already out of the, you know, the, the bull's already out of the, out of the cage, and it's running around the, the ring there. Um, so it is a really big huge problem that I, I, you, you asked me at the beginning, like, what keeps me up at night?
This is actually something that keeps me up at night because of all the systems that we have running on this. Now, when I, when I start to think about like, well, how, how do we start to capture this and, and bring this in? And one of the things that I had wondered, and, and it crosses, you know, like a business section is predictive analytics.
So do we go from, instead of looking at, um, configuration and changes in configuration, which has been very problematic, even with just computers and servers and mainframes, um, but do we start to look at the behavior of the devices? And can we, by looking at the behavior of device, understand that it has been taken over. And so that's how I, I have started to formulate, like, if I'm going to be looking at how to, um, take hold of, of this problem.
And so let's just take a camera. This, this would be a really easy example. Um, so let's take, let's say we have a thousand cameras in a large building.
And typically, um, we understand that cameras are gonna start working, let's say it's 7:00 AM to midnight. And so they're gonna be very, very chatty. And so, but so, so that becomes our window of chattiness.
And, but all of a sudden, this camera that is usually not on, starts to come on at 3:00 AM starts. So I am going to look at that as an anomaly, and I'm gonna say, okay, now is it coming on? Because it's, it's dying.
You know, the, the device is, is suddenly, you know, I'm not feeling well, and I'm coming on, I'm coming off, I'm coming on, I'm, you know, or has it come out at 3:00 AM because there's anomalous activity happening in the, in the building. And so then we start to marry the predictive part of iot, which I think is important. But, but personally, um, to answer your question, I, I mean, I, I think we have to start looking at the behavior, um, from a cybersecurity point of view.
And, um, in order to start to wrap our arms around this problem of, of, because I don't, I don't know how else we can do it from a configuration standpoint. It, it just is. So if we have 44 billion devices, how do, how do we start this?
How do we, how do we secure this? I, it's a really big problem. It is, uh, it is a very hard problem, and they use the word hard on, in on, very specifically on purpose.
There is a phenomenal study that came out of the National Academy, so National Academy of Science, but National Academies overall, uh, called the cyber heart problems, right? These are, this is a research report that aims at, um, informing policy conversations, right? We wrote about it in, uh, back in June, I believe.
So the report came out in April, may timeframe. I wrote about it in June. And, uh, it's really interesting because they talk about what are the, the, the kind of cyber hard problems that we have to deal with as an industry, right?
Because, uh, they are not in intractable, but they are difficult to solve, and it's uncanny how many of them apply to iot? So we have a software composition problem, right? We, we are, we are now not writing software anymore as much as we are assembling software, right?
Uh, uh, we're, there is a phenomenal problem with, uh, uh, how do we define the trust of a system, right? How do we evaluate trust, right? That's a, that's a hard problem.
And then, and, and Kate, I'm latching on to the 44 billion number, you said, yes, that applies across all of those. Now, one of the things that, uh, I found like a broken record, which I know is maybe a dated reference, but I, I keep repeating myself because one of the things that we need to prepare ourselves for as organizations is we need to be able to be resilient, right? Cyber resilient, if you want the term, right?
We need to be able to be resilient within our overall systems in, in the face of individual failures, right? So if you have to pick on, on your 1000 cameras example, right? I have 1000 cameras running in my environment, right?
But hopefully I've architected my security, uh, environment so that tho the traffic from those 1000 cameras is on a specific vlan, or is on a specific SSID or is, is somehow segmented so that even though there is a volumetric anomaly in that traffic, okay, that pops up there, uh, if they try to, oh, look, we, we took over this camera, let's FFH into whatever server we want to, uh, that boundary is going to block that, right? So yes, the camera has been taken over, yes, the camera is infected. No, it's not bringing down the entire organization, right?
We need to be able to, as practitioners continuously work towards that environment, that kind of architecture, right? Where things are self, uh, I don't, uh, I remember way back when we had the term self defending network where we're, we're back to it, right? But we need to be able to have that kind of, uh, of segmentation inside of our environments.
And one of the areas i i I cover is, uh, SS e Secure Access Service Edge, right? One of the more interesting things around SS e deployments is, so it's the idea that you now using a service, a cloud-based service to basically enforce some of that segmentation. I think that iot devices is one of the more interesting areas for SE because now you can radically simplify what the, the, the connectivity needs are at the edge so that you know what the device just needs to connect a a 5G radio or, or whatnot.
Okay, great. We're you are now protected by the SE service and, and that takes care of, of this kind of thing. One other thing I want to bring up back to economics is that, uh, we need to, uh, Tom, you bring up the, the, the, the milling machine versus the cameras, right?
The difference in one of them costs $4 million, the other one costs 40, right? The margins that the producers have on those divisive is radically different. So that $40 camera, right, has a tiny, tiny, tiny profit margin, right?
And you cannot, as a producer, uh, splurge too much on security because security costs money, right? Goes back to your friction point. Well, one of the more interesting things that have happened, it's, this is, this is a weird one, is that from a scaling perspective, right?
And, and I, I credit, uh, Thomas Doan, he goes by Halvar Flake on the socials. He had the presentation a couple of years ago where he highlighted how it's cheaper for an IOT manufacturer to buy a generic purpose chip that can do a ton of stuff. It's cheaper to buy that than to buy a more specialized chip that doesn't do it.
So now all of a sudden, that camera that, or, or that PLC that perhaps just needed a couple of controls to do it needed functionality to do five things, it now has functionality to run a full blown Linux system in there. It doesn't need to, but it's actually cheaper for the producer to build it like that. Guess what?
If you're still treating that device as, Hey, it's a little PLC that can do this five or six things, and you don't realize, holy expletive, it has an actual Linux system built in, you are going to have a bad day, right? So it, it goes back to, again, I keep going back to economics, I'm sorry, right? But it's this, this thing about, uh, you, you talk about, uh, friction, there's also the friction of how expensive is it to deploy these things.
Well, I, but I think to kind of wrap up here, Fernando, it's, it's important that you bring up that it, that kind of, um, aspect of it. Because one of the things we've learned over the years in security is that no matter how complicated things get, when you can take it back to the basics and understand the challenges that are forcing these decisions, you can actually get a pretty clear picture of it. You know, economics is gonna, um, force that, as I said at our security field event a couple weeks ago, opportunity cost spare is no one, you're always gonna be making a trade off somewhere.
But more importantly, for what we're thinking about here, you know, kind of to Kate's point, sometimes all you gotta do is ask the right questions. And the questions are, can be as simple as what is doing the talking, where does it need to speak and how much talking does it need to do? Like, like we've seen that, right?
Like the, we always go back to our favorite apocryphal stories of like, the target POS hack or the, the, uh, casino fish tank thermometer hack. Does the thermometer really need to be talking to the betting system? Well, if the answer is no, and there's not a control in place to prevent that, then that's a bad security decision.
You know, if the target POS system or the HVAC system should not be talking to the POS, why are we allowing that communication? A simple deny there would have saved a whole lot of headache, and quite honestly, forced us to come up with a new story. But I think that, that the challenge there is though, that we still have to apply our old methods of thinking to technologies that assure us that we don't need to do that because this is all taken care of.
And I promise you that the first time that somebody comes to me and goes, oh, you don't need to worry about that security. We've taken care of all of that, I'm gonna double down on what I do, because one of us doesn't know what we're talking about, and my experience has told me it's not me. All right?
Uh, we're gonna go ahead and wrap it up there 'cause we're kind of at the top of the time for this. But I wanted to give our guests a chance to kind of tell us some of the cool stuff they're working on, Kate, starting with you. Uh, if people wanna go read some of the stuff that you're working on or, or see some of the projects you're involved with, where can they go to do that?
So Right now, the CD Foundation has put out a, um, security guide, cybersecurity guide on how to, um, secure the software, um, the cd, the, the pipeline, the CICD pipeline. Um, I with, I say in like three easy steps. And to me though, what's more exciting about this cybersecurity guide that came out from the CD Foundation is that you truly have cybersecurity working with the DevOps people.
So to me, that has been very exciting. And, uh, yeah, you just need to go out to, um, the CICD, uh, from Linux Foundation and look at, uh, then go drill down one more to the CD Foundation and you'll see our guide. It's free, and we're so happy.
Um, and we'd love feedback, you know, so please, that's a big, uh, It, it's, uh, we didn't even touch on the, on the CD foundation aspects of things, right? Because it's a, it's really interesting when you consider iot that IC CI and c modern ci cd is all about the quick feedback loop, right? How quickly can we fix something, uh, the, and then quickly make changes and work that, that can be done in iot, right?
I mean, if I ship a, if I ship a system that is a turnkey system, it's supposed to live for 30 years or 50 years or whatnot, i, I, I wish we had more time, Kate, perhaps we can do this again in the future. But, um, uh, so from, from, from my perspective, from from a research angle, right? I'm, uh, I'm just wrapping up.
I'm late on a report on, on software supply chain security, which again, we didn't touch in the context of, of IOT as well. I mean, bills of materials and, and, and everything. But, uh, I'm just wrapping that report up.
And then we have, um, uh, should be out by end of the month. We should have a, uh, our cybersecurity decision maker survey. That's, that I'm working on.
So we have think about 900 respondents, give or take. I'm, the data is coming in and, uh, uh, I'm a data geek at heart, right? And, uh, I'm, I'm, I'm just dying to get into the, the, the cross tabs and, and, and, and whatnot.
That should be fine. Uh, we also have our, uh, security operations, uh, signal report. So futurum have a new report type that room signal, and, uh, uh, I'm, I'm working towards the, the security operations report, uh, security operations platforms report.
So that should be out early November, I think. So, yeah, it's a, it's a very busy month and, uh, uh, not as much travel. November for travel is gonna be brutal.
October for travel is not too bad. Uh, I'm, I'm happy to announce that all of the videos from Security Field Day are now posted featuring Kate and a bunch of other great delegates. Uh, we have all of the conversations that we were able to have there up, including our, uh, enforcement round table discussion, which was kind of fascinating.
Uh, there's a lot of discussion in the industry about how we should be doing these things, and I love getting different viewpoints. Um, if you don't have hours upon hours to watch every one of the videos, make sure you head over and check out the Tech Field Day takeaways that I recorded. I pick three big points from Security Field Day that I think are something that you need to be paying attention to.
Um, it's less than 10 minutes. You can get your information and go. Uh, but we want to thank you all very much for listening to this episode of the Security Boulevard podcast.
If you enjoyed this conversation, please make sure you subscribe on YouTube or use your favorite podcast application, because that way you never miss an episode, it'll just get delivered right to you. The other thing we'd ask is if you could leave a rating and a review, because that does help the show grow. The more ratings and reviews we get, the more likely it's just to get put in front of the right people who need to be hearing.
com and the Futurum Group. com is the place to be. But don't forget, you can also head over to the Techstrong TV website or check out the Techstrong TV app.
It's available on Apple tv, Roku, and pretty much any smart device that you can watch things on. Make sure you're following Security Boulevard on X and Twitter as well as LinkedIn. We are at security BLVD because vowels are things you don't buy on Wheel of Fortune.
Thanks for tuning in and we will catch you next week. Hey guys. Thanks Withrow.
We're here with Haw Ol, who's CEO of one io, and we're talking about how integration needs to evolve, especially in the age of AI, because, well, it's getting a little complex out there. Haw. Welcome to show.
Thank you. So one of the issues that we seem to see out there is, well, it's getting a lot more complex, as we noted, but historically we had a bunch of APIs and then we got a bunch of connectors built on top of those, and we managed them through some sort of centralized platform if we were lucky. But chances are, we just kind of manage them in some sort of bespoke way that was not very efficient.
You are. How does the way we think about integration need to change as we start to deploy all these AI agents out there? It seems to be coming together at a level of scale that is mind boggling at the moment.
Yeah, well, I think first thing, the old all saying that goes in it, that if you build it, you have to run it. So I think that's the first principle which leads into this, um, more like a holistic thinking of managing integrations as more like a product rather than just ad hoc project that somebody, some hero puts together. And then we hope, fingers crossed that they work.
Um, so that's, that's the fundamentally fundamental kind of a mindset change that we need As part of that. Therefore, do we need to kind of build the integration platform first and figure out how to manage it before we go build all the connectors? Well, of course, integration use cases are like various, there are different kind of indications that you, the simple, simple, simple from simple, um, um, innovations that can be kind of connector driven, let's say that you need to hook up your active directory and stuff like that, which is really like simple all the way to this, uh, cross platform workflow automation that involves several parties.
So of course you have to weigh, uh, the requirements against the investment investments that you do, but overall, the integration platform is a kind of a good starting point, but it's only set of tools. So you really need to have some operations model. You have, you need to have governance, all those things on top so that technology is not, um, enough.
Mm-hmm. We have had integration platforms for years and they're usually managed by some internal IT team. Um, but it seems to me at least that it's not like we're integrating things every day.
We do integrate a lot of things, but is this really, you know, a capability that the internal IT team should have? Or should it just be something that feels more like a service that I just in vogue as needed? Mm-hmm.
Of course. Depends what is your business? If you feel like that innovations are your core business, then of course you invest into your own capabilities.
Um, at the end of the day, there's no, no sort of a way of outsourcing responsibility. So regardless of internal IT team doing them these things themselves or, uh, getting them as a service or something in between, there should be somebody with responsible of this. So, um, that said, um, majority of the companies, enterprises, they have their internal team to support their business.
So things that are not directly creating, uh, business value should be somehow put aside or buy both not to investing too. Yeah. Um, will this whole equation get a little more complicated?
We talked about early on in the intro with the rise of AI agents, but are these not gonna be, I don't know, hundreds of thousands of endpoints that need to be integrated, not just with legacy systems, but each other? And how is that gonna all play out in your mind? Yeah.
Well, um, I, I would, I guess that the ai, um, helps us to build faster, first of all. And then AI agents are as, as, as we see them at the moment, they are mimicking human beings. So it means that they, they still need, um, real time, reliable correct data in order to operate.
That means that you need the integrations more than ever. And then the demand is becoming so, so, so much higher because of the AI agents will be deployed, systems will be, uh, and they require more and more data. So you need to build more and more integrations, which means that you have to find ways to scale, which means that, uh, the manual way of, uh, an approach based approach that you bring in bunch of people and start building from the stretch on top of the platform is not suitable anymore.
Will we also maybe, I don't know, create AI agents for the integration platforms themselves to help integrate AI agents with legacy applications? And the AI agent will talk to one other AI agent, which will then manage the process for them? Is that possible?
Yeah, well, they need something in between. And uh, like what you just described is it's sort of considered as a kind of API driven approach that you have APIs and interfaces. Putting AI on top of the APIs might make them little bit more, uh, you know, intelligent.
But the problem is that how, what is the communication? What, where's the communication happening then and how do you, the translations and mappings and all these things with different data models and how do you run the business logic on the integration? So point to point, yes, that I can see that happening, but then you need to have this, um, multi-point integration use cases.
Um, it's unlikely that ai, um, agents can replace it. They can, they can be super efficient when they get the data and can process it and send it over, but how they send it over there needs to be something in between mm-hmm. Some kind of fabric, Right?
And to your point, how that gets accomplished matters, especially from a governance and security and compliance perspective. So I can't help but wonder if the cart's before the horse a little bit, and we're all excited about AI agents without thinking through exactly how these things are gonna get managed. Yeah.
Well, I think we, thankfully we have one, one really good example in the, in the sort of past of it, which is DevOps. I think same fundamentals can be applied, uh, when it comes to managing integrations, taking the DevOps s culture, taking the automation, taking the monitoring, having the lifecycle approach, and that leads into better governance, clear responsibilities, accountability, um, SLAs, SLOs, all these things that are making integrations look like more at the products that have some, some, you know, clear reason to exist and they're not, add some, some ad hoc stuff. So I think that DevOps principle put nicely into this picture When it comes to integration.
What's that one thing you currently see organizations doing that just makes you shake your head a little bit and go, folks, we should be a little bit smarter than that? Well, we, we still try to fix, fix this scalability issue with the sort of the old way of doing things, which is, uh, today, I think was today Garner just released the latest magic quadrant for IPAs, and you'll see the same folks there year after year, integration platform as service. That's considered as a kind of a, some kind of a silver bullet for this.
And nobody's talking about the actual requirements for these integration. So we are taking, um, we are enhancing the tools for developers to develop integrations, uh, but you still need the developers. So I, what you mentioned about the AI being on, on the iPad platform and helping, helping them to develop faster, make more integrations without any management model, and we all remember what happens happened when the shadow it was introduced back in the day, like suddenly you have different things outside within the organization because it's so easy.
But at the end of the day, security, governance, all those things that are super important nowadays, um, they, you need, you just need a model for the operational model that covers them, the whole thing. From your perspective, um, how will the current platforms need to evolve, therefore, I mean, a lot of people will say, I already have an integration platform. So what becomes the impetus for them to change that out or swap that out in and, and what's the ROI on that?
Well, I don't think it, it goes down to not only on the platform, what technologies it comes down to the understanding that innovations are, are, are sort of important part of the whole IT delivery as they, uh, are in the supply chain is a good example. Supply chain management innovation have been, have been fundamental for, for that kind of, uh, uh, concept for, for decades. And now within it, we have to wake up that we should have a similar principles, even regardless of the technology we need to invest into competencies, the model, how we run it, uh, the whole approach of, uh, really investing into important things and consider integrations as a product.
So it takes, uh, also, I think there's a kind of a skill, skill cap in that sense that companies are really getting there. And it's not about ai, it's about really having the competencies and understanding what it really takes to run integrations as a, as a part of a, um, organic part of your it, IT ecosystem. Mm-hmm.
So as you look forward to this new AI slash API driven world, you know, how many APIs will organizations be managing, do you think? And then, you know, are we gonna see some level of scale here that people aren't quite prepared for? Well, I think it was, um, what it, MuleSoft or Salesforce, um, study about this app, number of applications that we add, uh, every year in the larger enterprise, it's hundreds of new applications will be kind of added, especially like terms of ai.
So there will be a lot of interfaces, APIs, and now the question is that how do you make sure that they are, uh, they match into your security re requirements, all these things. So it, it's, the scale will be, will be just like we, I think we just, we, and we have just scratched the surface when it comes to a number of APIs and interfaces. And that being said, you need a governance model.
You need operational model, otherwise you're gonna be like, you are, you're sailing your ship without knowing if the, all the hatches are assets are closed. True that. So what's your best advice ultimately for IT folks out there as they kind of think this through and they start to, I guess, recognize the level of scale, what should they be thinking about?
Mm. Quite often we see when we discuss with the customers, the biggest pain is that they, they say that they have technology, they have integration capabilities when it comes to team, uh, competencies and, and things like that. But they still have a backlog of six months to getting there, which means, of course, simple answers you have to prioritize.
But how do you prioritize if you don't really know what is the most business critical, um, uh, for instance, for, but what is the most business critical innovation for you? How do you do it? So, um, my advice is that you really step back from technology perspective and start thinking that how do we actually deliver integration in integration at scale, which means that the operational model, how do we, how do we ensure that we are credible deli in delivery on time?
All these things that are like basic stuff to any, any IT operation, but integration are integrations. Integrations are not open considered as as a product. So people don't think them like that.
So I will start with that kind of a thinking that should be turn our thinking into more productized, standardized approach and what, what kind of investments we are willing to, to take in order to get there, which means then you have to prioritize. All right, folks, while you heard it here, hey, when it comes to integration, we're gonna be looking at things at a level of scale that might be mind boggling, but at the end of the day, it all comes down to the fundamentals. But if you don't start with integration, you're gonna treat it as an afterthought.
It's probably gonna go wrong. Yuha, thanks for being on the chat. Thank you.
All right. And back to you guys in the studio. Hey everyone, welcome back here to Text Drunk tv.
My next guest is Jeff Reed. Jeff is the Chief Product Officer at Vectra ai. Let's welcome Jeff in.
Hey Jeff, how are you man? I'm well, Alan, how about yourself? Very good, thank you.
Appreciate you coming on. Um, Jeff, we're gonna talk a little, we're gonna talk a lot about VRA actually, and we're gonna talk about some new solutions you guys have. But before we do that, let's hear a little bit about you, your chief product officer.
How, how'd you wind up there? How long you doing this? Yeah, what's your background about?
Yeah, so been here about a year and a half. Uh, you know, I lead engineering, product management and product marketing for Vector ai. We'll talk more about what we do, but I got here, uh, by way of Google Cloud.
Uh, and so I've kind of spent, if you look the, I call myself a plumber. Yeah. I've been in kind of the infrastructure security land for the last 25 years.
You started starting file systems and volume managers at Veritas for folks that remember back in the day. Um, and then spent a bunch of time at Cisco, I Remember. Yeah.
Yeah. So Uhhuh, you went through there. Are you At Cisco too?
You Really, yeah, yeah. I then went to Cisco. You were Like a master plumber, huh?
Yeah, no, exactly. Yeah. Yeah.
I never got, I mean, we did our own chips, so I can kind of say I got into chips, it's probably, you know, you know, but, uh, but yeah, so did, was it Cisco? And, and really, you know, from there it spent a bunch of time in networking, and then you went into security side of Cisco for a few, for four years or so, and then, you know, look, the whole cloud thing's pretty important. Uh, so I had an opportunity to go over to Google Cloud, and that was great, great experience and kind of did two things there.
One was in kind of the core services, Kubernetes, serverless, you know, that that kind of space. And then, you know, when Google was looking to acquire Mandiant, uh, they wanted to bring in a, you know, security product leader. And so had the opportunity to come in there, and that was a great role.
So kind of had, you know, VP of product for all cloud security at Google Cloud, um, both from the infrastructure, identity, access management, compliance, HSMs, all that side, but also what we're doing in security operations in that world with, at that point Chronicle. Uh, and then you had the, you know, it was interesting, Hitachi, who's the chattis, the founder, CEO of Vector, reached out and I really was super interested in what Vector was doing, um, because you, the, what we were doing with Chronicle was really interesting at Google. You like the economies of scale, the speed, all that was amazing.
But we were still like, I think in the sim market was still kind of incumbent on the customers to do most of the, the real, like threat finding. And so what I, what I loved about Vectra was how they were doing things that were really unique in the industry around how to detect attackers using, you know, initially network side, you know, uh, you know, data, but then expanding to other places. And so that really kind of got me jazzed about coming over to Vectra.
Excellent. What a charm course of, uh, the, you know. Yeah.
I've been lucky. Yeah. Yeah.
Career. Well, you know what the, what was it? Branch Rickey, the guy from the Dodgers back in the forties or fifties said, luck is 80% or 90% ation, 10th percent inspiration, right?
So luck comes, you know, God helps those who help themselves. Anyway, Jeff, let's turn to Vectra, right? Yeah.
It's a lot of people out here may or may not be that familiar with it. Sure. How would you describe Vectra to them?
Yeah, so it's, there's, you know, Vectra really started this idea of can we apply advanced AI techniques to what initially was network data to find attackers that had bypassed other, other, you know, security controls within an environment. And, you know, kind of came out of, you know, some breaches that you have the, the founding team had seen in customers back in, you know, the 2010s where, you know, nothing else was able to pick up their activities, but they'd left this like trail in terms of the network, uh, activities they were doing. So command and control, reconnaissance activities, lateral movement, and that side.
But I think the, the key thing that the, the key part of the premise though was instead of doing, you know, the normal, you know, what's abnormal behavior, the things that have kind of generated so many alerts and so much noise, it's can we take a much more focused approach around what are the durable attacker behaviors? And if you think of that, like what attackers have done over the past, you know, 10 plus years, like the core pieces are the same. I need to establish some presence.
I need to have a com control channel. I need to figure out where I'm, and the I am in the environment. I'll probably need to move towards different parts.
And so those behaviors, those minor, uh, techniques or the things that we really try to find, but we find them using in very sophisticated, you know, capabilities. So we use long short-term memory, recurrent neural networks for C two channels. We do some really interesting clustering techniques around, you know, trying to identify, you know, where is privilege within an environment and then, you know, where are places where we see, you know, potential privilege escalation.
So things like that I think is really kind of unique to the, the capability with the whole desire being, can we always find the attack behavior, but do so with as much clarity, so there's a little noise as possible. I love it. ai.
It is, yes. B-E-C-T-R-A. And, and Be clear.
So one thing, like, you know, the obviously AI is, you know, very hot topic these days. Um, You think, you Think just, just as, just a skosh, uh, Uh, We've been around for over 10 years, you know, these techniques were started being deployed in, you know, 20 18, 19. So pre the big gen ai, you know, wave.
Uh, so, so you know, we, we describe ourselves as the OG of a, of a AI and security. Fair enough. Very good.
I I love the OG staying current here. Alright, let's, let's pivot into our topic of discussion. It's not really a pivot, it's a continuation of what we're talking about, but Jeff Vectra AI recently announced a, uh, a new generative AI solution, uh, for AWS powered by the, the Amazon Bedrock platform, which, you know, Amazon has really, uh, put a lot into and continues.
Yeah, right? It's a big part of their strategy there. Um, talk to us about this new, this new solution.
Yeah, so this is our, your Vector AI analysts, and we need to take a little bit of a step back. You think you, I talked about the idea of, you know, we want to drive great clarity. Like, hey, here are the small number of things that you, Mr.
Customers should worry about each week within your environment. You know, we do that in kind of these stages. So we start with the actual detections themselves, and we talked about recurrent neur networks, you know, then we have actually a triage, a agentic framework that's been around for a couple years now.
And it basically is trying to find out like even if there's attacker behavior within your environment, some of those behaviors are, are actually hard to decipher from what normal, like real, you know, legitimate use. And so it basically tries to kind of like take that and, and reduce the number of, uh, of potential, you know, alerts and detections that we have. Then we go through a prioritization scheme basically says, and what that is, it's a constrained optimization model that's trying to mimic what a, how an analyst, a security analyst soc analyst, would prioritize all the things that hit his or her desks in a day.
And that kind of pops out with a score. And then, and then, so the last thing that this new, this new analyst agent is really about the next step from that. So once we've prioritize an ity, a host, or an I or prioritize an ity, a host or an identity, how can we then like make the next steps for that analyst as easy as possible?
So think about this as being able to go out and, and do all the, the kind of work around, you know, investigating that, that entity, what are the behaviors potentially reaching out to new data sources that we haven't naturally? 'cause that's nice about these agentic models is you, they have the ability to go out and read blogs of the latest attack, you know, attack techniques out there, or, you know, go to find new additional sources of data within that customer's environment and basically come back with a, a more sophisticated assessment of that entity. And do we think that this is actually a, a likely to be a malicious behavior or not?
So that's kind of the, and it does that this, and I think the, the interesting thing here is if you just throw this to a large language model and have it go, it would, uh, sometimes it would be amazing, sometimes it'll be completely wrong. Uh, and so the, I think the, a lot of the work that we've been doing is how do you not just leverage what the, the gen generative AI capabilities have brought to bear, which is a lot of good, like fuzzy logic and like long tail reasoning, but compliment that with, hey, there's some guidelines or, you know, guardrails in terms of this type of, you know, we've seen these behaviors on this, on this host, what would the normal steps be for an, an investigation? And so this kind of mix of expert system logic plus large language models kind of combined do we think deliver a really interesting approach.
Love it. Jeff, what about for the people out there who say, this is a great AWS solution, but I'm multi-cloud? Well, so yeah, yeah, yeah.
So to be clear, and this one maybe I should have, should have done this earlier. My bad. Uh, we are leveraging AWS as bedrock and the infrastructure to deliver this solution.
It is by no means, uh, limited in terms of the, Oh, okay. Purpose Area coverage, just AWS environment, since You guys are actually sort of hosting it on AWS but it's available Or however you wanna call it, ond, inter ID M 365, Azure, AWS, like everywhere that we have, uh, detection coverage, so kind of our native signal generation, you can apply this analyst. Now, the one thing I, just to be clear, you right now, this is available as part of our managed detection and response service.
So you, we Right, we provide a managed service that'll, you know, basically we're Vectra analysts will sit side by side with their SOC counterparts to help kind of make sure. So initially it's powering that service is, is where this analyst is coming to bear That that's available. Right now, It's available right now it's, it's on, if you go to the, uh, AWS marketplace and their generative AI tool sections around security, it's one of the, you know, one of the solutions as part of that, I gotta ask you a hard question, Uhoh, bring it on.
Alright. You know, look, I spend most of my day on videos like this with people like you and not just vendors, practitioners, analysts, you know, a good mix. Everyone, everyone has an AI story, everyone, as we talked about earlier, right?
How much of this is not, not that I, I'm not saying it's not real. It's obviously real. Yeah, yeah, yeah.
But how much of it is must have today versus, oh, this sounds cool, but you, I can live without it. I think that comes down to the problems we're trying to solve. You know, every year we do a, a big survey of soc practitioners and, and kinda ask them a series of questions around, you know, kind of what their, what their day-to-day life is, and, and some of the findings from the last one we did were, were amazing.
You know, like, um, 71% of them worry that they're gonna miss a real attack buried in a flood of alerts every week. Uh, so that to me kind of stands out. Like that's one of just new numerous findings.
But I think for the way I think about it is given the scale of people's environments and, and the thing we've seen is just the fact that it used to be simpler. We had a data center, we had a campus put some firewalls around it, you know, it was like, it was a much simpler environment to protect. Yeah, no, I get it.
You know, between, you know, everyone still has those, and they have cloud and they have SaaS, and so the, the, the complexity of their environment and, and, and you used to find, I mean, you've been in this world a long time, you know, 25 years ago, you talk to someone that kind of knew everything that was going on within the IT infrastructure. That's almost impossible to find now. Not Today.
You're right. It's just not. Yeah.
And so I just don't, I don't think the tools that aren't leveraging some degree of more sophistication in how they identify, triage, prioritize, I just don't think they're gonna be successful in, in really helping avoid that problem of, I'm flooded with alerts every week. I'm thinking I'm gonna miss some the thing that really matters in that flood of alerts. And so, so to me, that's the thing.
And, and really that's the foundation of why Vectra, that's we've 10 years ago that was Right. That was your reason for being to begin with. Yeah.
And, and, and so I think that, you know, and we've been, we have, we have more data scientists at RA than we're working at Insecurity at Google Cloud. So, so I think that just gives you a sense for the scale of investment when the bet we've made that this stuff is really important and it's not really ge like, the thing I wanna say is like, like generative is another technique that is very useful in some parts of this problem set, but it's not the end all be all to what we've been trying to do and what we think you need in order to be successful. And so, to me, it's a great compliment.
It's absolutely, I'm really excited about stuff. You see, you know, some of the stuff we've seen in terms of like, you know, you know, MCP servers and things like that, I think, you know, how the stock operates, I think is gonna radically change in the next five years. And, and I think that we can play a key role in that through the, the mix of technologies that we have.
Yeah. No, we, we just had this discussion on TechOne gang the other day. I don't even think it's five years.
I think, I think it might be two to three years at most. I, the way, the way thing, right? Agentic AI things are snowballing so quickly Yeah.
And you get this kind of compounding capability set the things you, um, so yeah, no, I, I, I was, I, I'm very confident by five years it will be totally different. Oh, Absolutely. I, I don't disagree.
18, I think also think's all sort of relative, right? When you look at how this whole AI thing is affecting the speed and velocity that code is being developed. I was about to say that, yeah.
That new apps are being deployed now. You gotta manage those apps and observe 'em and all of that, and you gotta secure them. You know, it's, uh, it's the circle of life here, right?
Absolutely. On steroids. And, and so, you know, I, I think that that's what we go with.
ai is the website Yeah. For people who are interested in this particular new offering, where does it right off the front page kind of thing. Right off the front page.
Yeah. Yeah, yeah, yeah. Yeah.
And you'll, you'll also see how well we did in the Magic Quadrant, uh, for first ever MQ for NDR, we were really both access axes. So yeah. So really happy about that.
Oh, Congratulations. Strategy. Yeah.
Thank you. Good for you guys, man. Hey Jeff, come back on and keep us posted here.
Right. World's changing real quick. We got to stay on top of it.
Sounds good, Alan, thank you so much. You're welcome. ai here on Techstrong tv.
Go check out their new, uh, gen AI solutions powered by Amazon Bed Bedrock. You're watching Techstrong tv. We'll be right back.
Hello and welcome to the latest edition to the Techstrong AI Leadership series. I'm your host, Mike Azar, today with Brian Moore, CEO for Voxel 51. And we're talking about why a lot of these visual AI projects seem to be failing.
Brian, welcome to the show. Thanks for having me, Mike. We see these use cases all the time.
I think most commonly people are seeing, uh, vision applications and everything from factory floors to cars, but a lot of the efforts underway seem to be still experimental and people are struggling. What's your assessment of what's going on here? Yeah, definitely.
So first of all, just to generalize it to all of ai, I think that's kind of the state of play in 2025. You know, we've had studies from places like Harvard Business Review sharing that something like 80 to 90% of AI initiatives within enterprises are not yet reaching production. You could call that a failure.
I would just call that kind of expected or par for the course. You know, this is new technology. There's lots of rapid innovation, there's a lot of excitement to try new things and build proof of concepts.
Unsurprisingly, uh, something that you cobble together in a few weeks or even months, is unlikely to meet the needs of the production environment that you need to deploy that into. And that's perhaps, you know, uh, most poignant in something like visual AI where we're talking about deploying, you know, robots or vehicles, uh, or automations that have to act in the physical world and deal with all the different sort of nuances, edge cases, strange scenarios that might crop up. So yeah, there's definitely a need to invest, you know, kind of the typical 80% of the time to get that last 20% of the way to production.
Uh, but the good news is that folks are aware of that, uh, and companies like ourselves are building technology to help assist, uh, you know, practitioners of visual AI address those key, uh, needs which we can dive deeper into and get that model ready for everything that the production Yeah. The real world, uh, will throw at it. Alright, well, to your point on that maturity curve, where are we when it comes to vision ai?
Because, um, I guess there's some unique challenges there, but what are they? Yeah, so the interesting thing about visual ai, and by visual ai, I mean, anything that has to do with image or video or 3D uh, lidar radar data, um, that's an absolutely immense data source. Something like 90% of all of the bits that go through routers on the internet today are actually visual in nature.
Uh, so the vision AI challenge is at least two orders of magnitude larger than the challenge, uh, of building models that can, for example, process text, right? So it's kind of expected that it'll take some, you know, additional time and effort to get these things, uh, ready for production. Of course, the good news is that with all the investment going into accelerated computing infrastructure, you know, data centers, power r and d, all the things you hear about the news, uh, those advancements are coming.
The, the promise of being able to feed larger scales of data into these systems, uh, is also coming. And so I would definitely expect to see continued progress on some of the kind of bulletin board vision AI use cases that everyone's familiar with, self-driving cars, humanoid robots. But maybe most, uh, exciting to us are kind of the more incremental advancements, you know, automating specific scenarios like maybe defect detection in manufacturing context, uh, or building purpose-built expert systems that can, for example, you know, uh, detect the fall, uh, of a, a human in a healthcare context, uh, or automatically, you know, process, uh, a camera feed to make a decision about whether a part is, uh, high quality or low quality.
Those kind of things, uh, are much more short term. Uh, and we're seeing those types of technologies get to production, which is very exciting for the, the vision AI field overall. Mm-hmm.
I think everybody's excited about the use cases, but it seems to me they're also running into issues around, well, what does it actually cost to run something in a production environment when you add up all the infrastructure and resources required? So do we need to be smarter about what projects we're gonna pick with an eye towards what's gonna go into production sooner than later? Yeah, I, I think it's a great call out.
So, you know, uh, one of the exciting thing that's happening in the AI space is the progress of these, uh, so-called foundation models. The large models, you know, the GPTs, uh, coming from hyperscalers and, and those models are, uh, have a broad expertise of knowledge. Uh, however, large models are expensive to run.
Uh, and so what you can expect to see is those models knowledge getting distilled into smaller expert models that are more efficient, uh, at solving, you know, specific tasks. Uh, and so, you know, that's what's actually getting, uh, into production, uh, in vision AI especially, is these distilled models that are purpose-built for specific use cases that can run at a much more cost effective, uh, price point. As you kind of sort that out, who's gonna build those smaller distilled models for organizations?
Is that some data science team that they hire? Or are there specialist organizations that are emerging who are gonna basically make those things available as a service? How does this kind of manifest?
Yeah, so what we're seeing is that enterprises that, um, are having the most success in visual AI are ones that bring the development of these sort of fine tuned systems in-house. They treat, uh, their AI strategy as a core part of their company's competitive advantage. Uh, and so they want to bring as much of that development in-house as possible.
That definitely means using off the shelf models, uh, data sets and so forth, uh, to sort of, you know, turbocharge their, their development. Uh, but they see their ability to develop, uh, a high quality data set, uh, and model that's an expert in their use case, uh, as being critical to their, uh, company strategy. Mm-hmm.
What are the skills that are available as it relates to this? And I'm asking the question because, well, we're already having a hard time just finding your everyday run of the mill data scientist genius, and how many of them are actually cognizant of visual AI and, um, what does the pool of talent look like? Yeah, so for context, uh, a little bit about myself.
So I have a PhD in machine learning. Uh, voxel was founded by myself and my co-founder, Jason, actually over 10 years ago, uh, initially doing consulting, uh, in, back then it wasn't called visual ai, but rather computer vision. Uh, and so computer vision as a field, it's actually been around for quite a long time.
In fact, even Nvidia as a company, uh, got its start and spent many decades focused on computer graphics, the kind of, you know, uh, low level computer vision, uh, algorithms that are necessary to, you know, build graphics engines, video games, so forth, right? So there's a rich history and, and expertise in, in the, in the market that exists in computer vision. Uh, and, you know, so that's the good news.
There's lots of, uh, you know, capability out there. And then, uh, what we're seeing is that whenever there's advancements in sort of overall AI technology, uh, those models, those architectures can be deployed not only for language use cases, but also for vision use cases. And so the visual AI field definitely benefits from all of the advancements that are happening in, you know, large language models.
Uh, as an example, the, the transformer architecture that Google created a couple years ago, uh, was very important both in language but also in vision. Mm-hmm. Of course, it takes a village to kind of build these applications and there's developers involved and, um, data engineers and all kinds of folks, but, um, how do I meld them together?
I think a lot of organizations I talk to are struggling 'cause the data science folks have one culture and the developers have a different culture and they're not quite in sync with each other about how to not just build an app, but maintain it and update it. That's a great point. So, you know, historically what we've seen is that some, uh, companies have decided to kind of create separation between what they call their data team and then their model or product team, which might result in kind of a separation of duties where the data org is responsible for building data infrastructure, maybe gathering data, and then throwing it over the wall to the product teams that then make use of that data kind of a one-way street type of modality.
Uh, however, you know, especially when we're talking about model failures, what we're seeing is that the ability to overcome model failures and actually get a system into production, like we were talking about earlier, that comes really from the iteration cycle, being able to understand, okay, I built a data set, I trained the first version of my model, where is it succeeding and where is it failing? And inevitably, if it has a failure, maybe an edge case or a certain type of bias that you've discovered, you need to address that, uh, through better data. It's not sort of a one way street, it's an iterative process, and you're in the best position to make that kind of, uh, action to improve your model, uh, if your data and model teams are working closely together.
So, as an example, uh, our software 51 that we deploy to enterprises, it kind of puts the data at the center of the entire development process of visual ai, allowing data teams and model teams to collaborate together in one place. And when they see a model's performance or lack thereof, the underlying data is always one click away. So with just a click of a button, a user who's trying to, you know, evaluate a model can understand, oh, I see this is why the model's performing poorly.
I can see that there's, uh, something I didn't expect about my data. A bunch of it is low light or low quality maybe, or it's having problems in the self-driving use case, uh, you know, understanding, you know, sort of crowded intersections and low light conditions. If I'm able to go gather more examples of those problem areas, that'll be the most effective way to improve that model's performance.
Mm-hmm. How readily accessible is that kind of data? I think, you know, you hear people talking about how all the data that's publicly available aren't even sucked up.
So do we have enough of this visual data to train the models going forward? Yeah, that's a great point. So, so that, that kind of, um, quote, uh, is most often used about large language models, people are saying that, you know, the reason that let's say GPT five had a smaller delta than one might've hoped over G PT four, is that we've already ingested all of the data that's available on the internet.
That's definitely not true. A visual ai, uh, like I said before, there's, you know, 90% of all of the bits that go through routers on the internet are visual in nature. Uh, and there's definitely a vast amount of untapped data in visual, uh, it's visual in nature, uh, that is yet to be fed to all of these models.
Having said that, uh, one trend that we're seeing with our customers is, you know, kind of by definition where you need to spend all of your time are on the edge cases, uh, or failure modes of a system. And those are rare, they're hard to acquire. And so companies like let's say Tesla are in a, a good position, uh, where they can, for example, trigger, uh, anytime there's a, a hard braking event in a vehicle, they can capture that scene and feed that data back to headquarters and use that to specifically address that, you know, sort of failure mode.
So being able to connect to your development process, to the products that you're putting in the real world, that's a great way to gather more data. On the other side, we're seeing, you know, synthetic data as an example. You know, we partnered with Nvidia, uh, to make their, um, neural reconstruction, uh, models available to our customers.
That's a situation where you can generate a synthetic version of the scene, and then you can play with things like, Hey, I've got this scene. Uh, what if I swapped out that FedEx truck for a UPS truck? What would happen then?
Or what if I took this sunny scene and I wanted to consider how the model would perform if it was instead snowy or rainy? Uh, you can perform those types of, you know, uh, you know, uh, synthetically generated tunings, uh, you know, uh, from a model standpoint, which obviously gives you the ability to plug those gaps that may be hard to acquire, uh, real data for now, I would say that that's kind of a, you know, uh, up and coming technology, uh, and there's definitely interesting questions to be answered about, you know, how do you evaluate how much real versus synthetic data you need, uh, to build, you know, a production ready model. Uh, but it's definitely something that our customers are excited to, to tap into.
It also seems to me the tolerance for being wrong in these apps is a lot less, shall we say, than it is in your typical, um, you know, chat GPT type of application where, you know, if the thing hallucinates on some sort of summarization, I'll notice, but, you know, if it's not the end of the world, and I'll shrug, but it feels like with the visual ones, that those applications are a little more, shall we say, mission critical. Is that fair? Yeah, I think what you're getting out there is that, you know, and this is kind of maybe obvious with hindsight, but the key to getting these systems into production is choosing the right use cases.
And to your point, the right use cases, especially early in the development cycle, are ones where the, the, the system or the use case can tolerate a failure. So yeah, if you're, if the task is to summarize, uh, some content, uh, for a human to take action on, and if it's not quite right, you know, there's a human in the loop already, and so maybe it's okay, right? Uh, on the other end of the spectrum, you could see something like a self-driving car where, you know, it makes kind of intuitive sense that it needs to be, at least in order of magnitude safer than a human driver in order for us to kind of accept, uh, any sort of failures that might happen.
Uh, but the good news, like I was saying before, is that in addition to the sort of, you know, bulletin board use cases for visual ai like fully self-driving or fully humanoid robots, there's a lot of, uh, smaller more sort of focused tasks like detecting defects or, you know, uh, automatically processing, you know, user imagery for insurance claims where there's a lot of summarization and sort of constrained environment tasks that can reach production level and will, you know, uh, add lots of value to us while we continue to push towards those bulletin board use cases. Kind of similar to however, everyone spends some fraction of their time talking about what a GI will look like when in reality, uh, those use cases like, you know, automating customer calls, uh, in service centers or, you know, summarizing, uh, knowledge work, uh, for enterprise, those are the real value creation in the short term. And to your point about that, you know, everybody talks about, well, who moved my cheese and am I gonna get laid off?
But when you look at those use cases you're talking about, some of them are things that we probably would never have done in the first place, and many more of them are things that well, nobody really enjoys doing in the first place, and we typically don't do it all that well. So is that part of the thinking about where do make use of something like vision ai? Definitely.
Right. And, and just to put a point on maybe a macro trend that's happening right now and how it's impacting the visual AI space, uh, you know, we're talking a lot these days about onshoring manufacturing for various, you know, political reasons, uh, you know, so forth, which we won't go into here, but, you know, there's this sense that, well, uh, there's, there's certain tasks, sort of menial tasks in factories and so forth that maybe, you know, some fraction of US workers aren't interested in doing, or it doesn't make sense to do, uh, at sort of like human level price points. Perfect use case for vision ai, right?
We can come in and invest, uh, as we're onshoring manufacturing in building automation, uh, and be, you know, building out factories that'll put us in a, you know, uh, competitive advantage compared to, you know, even our, uh, offshore, uh, competition there. Well, let me ask you this then. Um, is this really a separate discipline in the sense that there will be a separate ecosystem for it, or, you know, are you at all concerned that the open ais of the world and everybody else who's in that space is just gonna, you know, just add this to their portfolio of services?
Yeah, so that, that's, um, kind of what I was getting at before when I was making a distinction between, you know, what a foundation model, uh, can do, uh, versus, you know, what's actually required to get that particular use case fully automated and in production. Uh, you know, there's, there's interesting conversations happening right now. Let's take on the language side for a second around, you know, hey, if, uh, if it is true that these large language models have quote unquote PhD level knowledge in all fields, then why do I need to go to a healthcare provider?
Why can't I just go to chat GPT and have it solved, you know, provide my diagnoses and provide a plan of action? Well, there's not, it's not just as simple as providing the knowledge. There's expectations around, you know, quality of care and certification and so forth that come out.
And for that reason, it's not gonna make sense for a single company, certainly in the short term, to provide sort of expert level guaranteed certified services in all these use cases. Uh, and I would expect the same thing to happen in vision ai. You know, it'll make sense for vertical specific companies that deeply understand use cases and customer needs and so forth to take a technology, a general purpose technology off the shelf, and build a solution for a specific vertical.
Uh, not to mention the, the, the point I mentioned earlier around how it's not cost effective to take that general purpose model and plug it in directly. That may be sufficient to build a proof of concept or show that something can be done. But ultimately to drive margins up, costs down, you're gonna have to invest in building more expert, you know, fine tuned systems.
And that clearly has to be done by a, you know, an entity that's focused on that one vertical and ready to make that commitment. All right. Well, folks, you heard it here.
There's a lot of things to be excited about in the AI era, but maybe all the cool kids are starting to hang out in the visual AI table because that's where the new and interesting applications are gonna be. Brian, thanks for being on the show. Thanks, Mike.
All right. And thank you all for watching the latest episode of The Techstrong that AI Leadership series. You can find this episode, others on our website.
We invite you to check them all out. Until then, we'll see you next time.