Techstrong TV – September 18, 2023
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
Transcript
Hello everyone and welcome to Techstrong tv. Today's Monday, September 18th, and I hope y'all are having a wonderful day so far. I'm your host, William Willis, and in today's show, we're gonna bring you some fantastic interviews with incredible guests from around the world.
So stay tuned. First up, we will head over to Mike, where he sits down with Randall dgs, head of developer relations for sny. As Randall dives into the impact artificial intelligence is having on the developer experience and the impact that it will have on application security, then Alan will meet with Richard Bird, chief Security Officer of traceable AI to learn about traceable AI's.
Recently published State of a P I security, a global study on the reality of a p i risks survey. Alan will then speak to Yoav Landman, co-founder and C T O of J, about reinventing M mo model management and elevating software supply chain security. Next, Bonnie Schneider speaks with Olga Kova, head of Go-to Market at workspot on the growing importance of sustainability in the tech industry and the transformative role cloud technologies play in driving positive environmental impact.
Next, we'll Air Two's episodes of you with vard in the first episode, Mike interviews Armory, c e o, Jim Douglas. As Jim dives into why DevOps in the age of platform engineering isn't dying as much, it is evolving in a way that improves developer productivity. Then Mike interviews CISO Greg Notch as Greg dives into a survey conducted by the Cloud Security Alliance that finds that IT teams are repatriating a surprising number of cloud workloads back into on-premise IT environments.
And then to wrap this broadcast up, we have two episodes of AI Leadership Insights. First up, Amanda speaks with Jeremy Shapiro, founder of Bay Area Mastermind about the transformative role of ai. Then Amanda speaks with JR Sherman c e o of Rain focus about the importance of understanding real time consumer behaviors.
And that's what we have coming up for you in this episode of Techstrong tv. So without further ado, let's get the show started. Enjoy In a universe as vast and complex as the world of DevOps.
Balance is not a concept to be taken lightly. It is the life force that binds the galaxy of developments and operations uniting them in a seamless flow of power and efficiency. Or you underestimate the power of the DevOps experience virtual events, it'll not only enlighten your mind, it'll show you how to bring balance to your D ops world.
The DevOps experience will lay bear the arcane secrets of maintaining equilibrium between speed and security, automation and manual governance, freedom and compliance. Even I find their methods impressive. While you may consider P C D pipelines automated testing and container asmu tools, I see them for what they are Weapons used effectively, they can elevate your operations to unprecedented heights used poorly, and they become no more than crude machinations lasters in a world of lightsabers, even the dark side requires balance.
This is Textron tv. Hey guys, thanks for the thrill. We're here with Randall Dengs, who's head of developer relations for Sneak, and we're talking about the impact that AI is having on developers.
Randall, welcome to the show. Hey, thank you so much for having me. I'm excited to be here.
I think it's already clear that developers are using the latest generative AI capabilities, things like co-pilots to write code. The question is, is it making them more productive and in what ways? And wonder, some of it may be the inherent risks that go with that that we're not considering.
Great question. So first off, I've been writing code for about 25 years or so now, and I think the, the initial part of your question is, are large language models and their practical applications like GitHub, co-pilot chat, pc, et cetera, are they making developers more productive? I think the answer is absolutely yes across the board.
Um, speaking from personal experience, the amount of code you can write and the amount of learning you can do using some of these tools is extraordinary. I mean, previously, if you were trying to figure out how to solve a problem as an engineer, um, what you might do is you might say, okay, maybe I need to implement a, uh, a registration form on my website. You're gonna go off and Google the name of your framework plus, you know, registration or password hashing or whatever that particular thing you're trying to solve was.
You spend a while looking through some blog posts, maybe find some stack overflow questions and answers you use as reference nowadays, you can go straight to chat g p t, ask it there directly and get back some really useful resources and information. So it expedites the learning process for engineers. The same is true for writing software.
So in addition to learning about it, they can also now just output a function or a method or a class or an object, or sometimes even ready to go scripts are gonna help do exactly what they need to do. So the first part of the question is, does enhance productivity? I would say absolutely.
The second part of the question though is does it introduce additional risks? And to really understand that you have to put a few, few pieces of context together in your head. Um, the first thing to know is that regardless of how software's being created, so if I'm personally writing software and Googling things and learning through Stack Overflow and then write handcrafting the code myself, you know, some organic artisanal handcrafted software, if you will, or if you have co-pilots shooting things out or other pieces of software, at the end of the day, security is a really complex topic.
And if you're trying to build secure performance production software, you always need to have review, and you always need additional tools to make sure that the code you're shipping doesn't have additional risks in it. And the same is true for code generated from anyway. So AI is no exception here.
The biggest risk vector to ai, I would say in the development of software is that people are now churning out code a lot quicker. And when they do that, they're oftentimes either not paying as much attention to the quality of the code that they're creating, um, or maybe they're sort of blindly trusting that the code that they're getting back from these engines is really well, well written, really secure, et cetera, which is often not the case. And so the short answer is in terms of software security, you still have to follow the rigorous, you know, proven over and over again.
Systems of building software in production environments, if you want to ensure the things you're building are safe and secure and AI is no exception, Do we trust these LLMs too much? Because to your point, it seems like one of the issues is their general purpose platforms, and they were trained by essentially hoovering up all the code they could find, and the code was of varying quality. So what they generate will be randomly different at different times.
So, um, having too much faith in these platforms, Uh, I think the answer is absolutely. So Stanford did some research a while back and basically found out that people using AI tooling to create software tended to have more security vulnerabilities in their code than those who do not. And even though you can ask developers and pull them and say, Hey, do you think the quality of AI generated code is better or worse than what you're generating yourself?
A lot of people assume it's better. The reality is that due to the very nature of the way large language models work and the way they're generating text and code and all these different things, um, is it's never gonna be perfect. There's always going to be issues.
And if you think about it from how these things are built as a point of view, we'll, you'll get it right away. You know, so the way these things work is open AI or any of these large language model providers will go out onto the internet and crawl massive amounts of information. They'll download lots of questions and answers from stack overflow, lots of threads from Twitter, uh, lots of information from blogs, right?
And so they have all these examples of text. What they do from there is they take that information, they do a bit of data cleanup and sanitization on their end with human researchers, but after that, they essentially compile a statistical model and say, okay, um, given this particular, you know, chunk of text, what is the most likely next chunk of text to come after it? And the way they're generating that is by analyzing all these existing sources of information out there on the internet.
So that's how large language models work. Like if I'm talking to GitHub copilot or chatt pt and I say, please write a Python function that is going to generate a secure login page from my flask web application. It's going to be predicting that based on things that's seen online already.
Now, what's the problem with that? In theory, there's no problem if all the information online on the entire internet was always accurate, but as we both know, that's just not the case, right? Like there's tons of information on Stack Overflow where maybe it was accurate a couple years ago, but today that information has security issues in it or just isn't accurate at all.
There's always these gaps in knowledge, right? And so blindly trusting data that you get from a large language model is just a really, really bad idea. And I think more and more developers are coming around to realize this, especially when you're using, you know, static analysis tooling like sny or other companies or even open source projects out there to help vet the quality of your software.
It becomes pretty obvious after doing this for a bit that you can't blindly trust code that's written by ai. Are there different use cases where I might trust it more? So let's say I am trying to create a script for something that's running internally, and I just wanna automate some DevOps workflow versus code that might wind up in a web application that's externally faced.
Hundred percent. I mean, at the, the end of the day, it really comes down to risk factors. There's certain types of things you can do with AI where the risk of causing a a an issue that's going to impact people is extraordinarily low, right?
Like for example, I was using AI the other day to take some video files that I had locally on my computer and to strip out the metadata and change it with something else. And I essentially went to chat g pc and I asked it, Hey, please create a command line script using the F F M P command line tool that is going to do these things that I just described. So let's spa back an FFM command line for me to copy and paste into my terminal.
Now, the risk there, I would say is pretty low because first of all, I asked it a very specific question about the tool that I already know what the tool does in a vague sense, right? So I don't have to understand every single option that it's giving me back, but I have to understand the basics of it. Secondly, I'm only going to paste that one FFF m peg command line option that is sped out to me into my terminal.
And so I have a pretty good amount of confidence what it's going to do, and that if there is an issue with the, if the data or if the information I got wasn incorrect, the scope of that issue is very limited as to what, what problems it can cause. Now, this situation could be radically different. Imagine your developer working at a medical company and you're help building tooling that is going to take in patient information from a patient's, you know, uh, uh, charts and, and, and, you know, history, and then make medical recommendations for changing medications or going in for routine lab work.
If you're performing actions like that and you get incorrect information, you know, the consequences can be catastrophic. And so you really have to just, uh, put on your risk management hat whenever you're using tools like this and just think, okay, how valuable is what I'm about to do? What are the potential things that could go wrong if I do it?
And I'm really just way off base? And better yet, how do you write your questions, the scope, the types of things you're asking AI for to help you out while reducing that risk? I feel like the pace of innovation for developers as far as pacing the innovation being seen by the DevSecOps teams, are we looking at a situation where the amount of code that's being generated and the code bases are just gonna grow exponentially and then weeks and months ahead, and I don't really have the tools to cope with that, and I don't have any generative AI capabilities, or do I, what's the state of the, um, frameworks for helping me cope with all this?
There's a lot of things to consider there. I mean, let's just take it from the policy perspective for for a moment here. Um, at a lot of larger companies right now, CISOs and engineering leaders are freaking out.
And the reason they're freaking out is because they have employees, just random developers who are using tooling that they haven't approved or vetted whose information might con or whose request might contain sensitive company information. People are doing these things today, and so there's a lot of like weird things happening from a policy and enforcement perspective. Um, at, at sny, we talked to a lot of large companies with advanced security departments.
And in those cases, basically everyone agrees, Hey, developers using, using these tools already, the solution isn't to enforce, uh, restrictions on what things you're able to use. The solution is to make sure that we are extremely rigorous with our software development practices. If you're going to be building software, it's more important than ever right now to follow strict, you know, best practices for building software.
What that means for a lot of people is if you have an engineering team and you're writing software, you need to be using static analysis tools to take a look at every single piece of code you're writing, ideally, as soon as you write it and try to detect security issues early on. Um, you're very right in the sense that the innovation for outputting code is vastly, uh, surpassing the innovations for securing code in in general. However, if you're using the right tool, and you can avoid a lot of those mistakes.
Now, I'm gonna mention s sneak briefly because I work here and that's what I'm most familiar with. But the approach we take to doing this is twofold. First of all, we use large language models ourselves to show people how to actually fix a piece of software that we know has a vulnerability.
So let's say we're looking at your code mic and we say, Hey, this, this one Python file that you're writing has this big, you know, path traversal vulnerability in it. And if you allow users to actually view, view this page of your site, there's a big risk, uh, of data leakage or other things bad happening. So we can take a look at that.
Now, in the past, we were able to successfully identify that stuff by using our own symbolic AI engines. Now, these aren't large language models, these are things that are trained by actual human security analysts that are highly accurate. And these are two fundamentally different approaches to ai.
One approach is to predict what thing is gonna come next based on a lot of input, which is what large language models do. The other is that have like actual people creating and crafting rules to detect things that are very specific and niche. And so at sny we take a hybrid AI approach.
We use symbolic AI to help detect issues in code with a very high degree of accuracy. Then we use large language models to generate potential fixes. And then once we generate these potential security fixes, we then use our own symbolic AI tooling to validate that those fixes will actually solve the problem and aren't introducing new issues or new security problems.
And so it's really only through a combination of using different tooling and having different, like fundamental philosophies on securing software that you're able to deliver a single product that's going to comprehensively help in this regard. Will this something get better if we start using LLMs that are trained specifically to write better code? And we've seen some examples with that is the l l m is much narrower.
It's not a general purpose. It does one thing well. And so ultimately, might this someday get better?
So there's no doubt things are gonna get better. However, if you're still thinking about it, the fundamental problem is to have a successful L L M need a lot of data and a lot of examples. That's the only way to generate really accurate predictive texts.
Now, the problem there is software is a very niche field. All things being considered, and software is not typically written the same way. Like if you take a look at and you analyze every single book in the Library of Congress and read all the texts of those books, the English language follows a lot of straightforward rules, and you'll see a lot of the same types of things, right?
Like, you'll see similar paragraphs, similar explanations of things there. And so you can train models on English text fairly well, code's, a completely different story. Like if you go on Stack overflow and look at examples of how to properly implement a b crypt password hashing algorithm in 2023 or, or whatever the modern times are, you're gonna get back a few examples of this, but there's not a lot.
And so the fundamental amount of data you're working with is a lot less than other domains sometimes just by the very nature of the types of work we're doing. And so because of that, it's going to be a big challenge for companies like OpenAI and other large language model providers to build these comprehensive data sets to get better in these very particular niches that, that we really care about, right? And so it's definitely feasible, feasible for that to happen in the future, but I think we're still personally a long way out from having these rock solid l l m style outputs.
And again, due to the very nature of the way LLMs work, there's always going to be a need for different types of solutions there. And that's why we're heavily investing in not only the large language model stuff at sny, but also symbolic AI to make sure that the things we're actually generating are accurate, uh, production ready, safe, secure, you know, all all that stuff. So short of outright banning usage of some of these tools, what's your best advice to organizations about how to go about, uh, having this conversation with developers?
I think that if, if anything, if I've learned anything in the last, you know, 10, 15 years being in the security space, it would be you need to establish clear processes and security is something that every single person in your organization needs to think about. You know, up until a year ago before like chat c p t hit the scenes, security was already, uh, an under-resourced part of businesses. You might have one security engineer to a hundred developers at an organization, and that security engineer would be responsible for monitoring software, coordinating with software developers to make sure they're fixing things in a prompt, uh, fashion, et cetera.
Nowadays, the importance of that has multiplied, you know, a hundred x. And so the best advice I can have is if you're working in security at an organization, build a really clear, simple process for your engineers, and don't just give them a clear process that says, Hey, every time you write code, make sure you run this tool to scan the code for issues before you check things into production. Um, you need to go a step further.
You need to have security implemented at all the different parts of your software development lifecycle. Ideally, if you're writing code in i d e, you'll have a plugin, like the sneak plugin that's analyzing the code you're writing in real time and giving you security fixes and recommendations. That's the first part of it.
The second part is to instrument your continuous integration and delivery pipelines with security tooling. So that way not only is, are you looking at the code you're writing in real time, but also you're looking at the entire code base all the time in a recurring fashion to figure out are there new newly introduced security issues that you weren't aware of before? Or was there an a security issue disclosed recently that is now impacting you that no one even knew about before?
You have to have these things in an ongoing fashion, and there's no way to like short circuit that, you know. So the best advice I have for security teams, again, is build a simple process. Make sure everyone in your organization, every single developer is aware of what that is.
And then finally, you should be doing enablement for your engineering teams and showcasing to them how to actually use these tools to be productive. It, you know, the best security tooling in the world isn't going to help if no one's using it and understanding it, right? So you have to not only have the tools and have the process, but you actually have to understand it as well.
And that's, you know, the sneak advice for security teams, really. So ultimately, do you think we're making progress on DevSecOps, or is it still in the realm of sometimes I feel like, you know, the boss shows up and gives the sermon and everybody nods their head and then goes back to living their lives as they were before. I mean, anecdotally, what I've heard over the last year, just from peers in the space, is people care about security a lot more.
And I think your average developer is much more security conscious today than they were a year ago than they were 10 years ago. It's become a more and more critical part of software development, and people are just more generally aware of this in the industry, which is great. Now, in terms of tooling, like is the DevSecOps space actually getting better for users?
I would say absolutely. Uh, I think one of the biggest and most exciting things to happen in the entire security industry for the last like 30 years or so, is the advent of these LLMs becoming, uh, commercialized, if you will. The reason why is because we're getting pretty close to the point where today, you know, a lot, a lot of security tooling is focused on, first of all, identifying problems.
That's like the first thing security tools focus on, right? The second thing is on helping people fix those problems, which is what sny and other vendors do today, right? Like, we identify the issue, we show you how to fix things.
The third part though, which is quickly becoming a reality, is the ability to autonomously fix issues. This is something that has only been a dream for people ever since, you know, I've been in the space, you know, what if as a developer you could write some code, it had some security issues in it, and in real time you are getting fixes for this code delivered directly to you. Or maybe, you know, maybe right now those fixes get put into your I D E as you're writing code so you can understand what's happening maybe in the future.
Those fixes happen instantaneously, and you don't even need to look at them. We're, there's so much innovation happening in the space right now, it's a really exciting time to be in security, and I would love to tell you about a lot of these sort of interesting projects and experiments we're doing internally. Some of them are, uh, going to be announced in the future.
And so I, I don't wanna spoil the fun, but there's a lot of really exciting things happening in this space, for sure. All right, folks, you're heard in here. Things may get a little bumpy in the short term, but long term we get better with every cycle and every revision.
Hey, Randall, thanks for being on the show. Yeah, thank you so much for having me, Mike. Appreciate it.
All Right. Thanks to you guys in the studio. Hey, everyone.
Welcome back here to Tech Drunk tv. I'm happy to be joined today by Richard Byrd. Richard is the, uh, chief Security Officer, c s o over at Traceable ai, a company we've been, I think we've been following traceable since they launched.
Hey, Richard, welcome back. How are you, man? I'm doing well.
Thanks for having me back on. It's a pleasure to have you here, Richard. You know what, give, let's give start off with, with a little bit about you, give people a little bit about your, of your background, if you don't mind.
Sure. Um, I've been with Traceable for exactly a year. Um, but as I like to tell people, I'm, uh, Benjamin Button living life in reverse.
I spent, uh, 20 plus years in the corporate side, uh mm-hmm. About 17 of those in banking, uh, financial services, payments, um, 11 of those with JP Morgan Chase. So I have had, uh, a number of stops that led both to a C I O role and then, uh, on the security side, a CISO role.
And, uh, and then I made a decision about five years ago to get, uh, out of the corporate side and try and help, uh, be a voice, uh, universal translator, uh, and the solution side and help out there. And, uh, thankfully, uh, j o t Bonsal and Sanjay Nagar garage, their founders at Traceable, called me up one day and said, uh, we'd like you to join the team. And, uh, and I ended up in, uh, a p I security, which has been a blast so far.
Absolutely. And, and it, and it's funny 'cause, you know, the whole arc, if you will, of a p i security just isn't that old. And, and, No, no, not at all.
I, I think for, and for the first two, three years, I think the, the, uh, we were dealing with sort of the, the primary question of do you even know what APIs you have? 'cause you can't secure what you don't know you have. But, uh, I'm hoping, and, and we're gonna talk about a new study that you guys did.
I'm hoping we're moving beyond the, what APIs do you have to, how am I securing my APIs, but be before we do, you know, we mentioned traceable a few times for those who maybe aren't familiar, 'cause I imagine some folks in the audience are not. Why don't you give 'em a little traceable background? Sure.
It's, it's impossible to talk about traceable without talking about our roots. Um, I like to always say that, uh, we're the most unfairly advantaged startup company possibly in the world because our founders, uh, were the founders of AppDynamics. And AppDynamics basically created the entire application performance metrics space.
And, um, you know, jot Bonsal was successful with that company to the point that, uh, he sold it the day before I p o to Cisco, uh, in 2017. Took a bit of time off and then started looking at the market on where there were key problems. And he actually started two companies simultaneously Harness, which is a C I C D platform, and then traceable.
And I love the story about Traceables background because I think it speaks directly to what, uh, makes us different, um, which is, uh, the application dynamic, uh, or the app dynamic roots, right? AppD built, um, you know, an enterprise level solution that can handle massive amounts of volume, um, using trace technologies. And in using, uh, those capabilities to build, uh, traceable, it answered a really important question.
One of our engineers at one time was looking at, you know, AppD and what was going on with the customers they had and said, you know, we collect all this information about performance metrics, and we take all the security information and we kind of toss it on the floor. Do you think that security information is important? And that really became the genesis of, of traceable.
So the goal state for traceable is to use an entirely different architecture than is available out in the marketplace today to monitor, not just collect all the information about your APIs and, you know, auto discovery and cataloging and all that, but, um, really take and evaluate every a p i every single, single time it's used against a normative baseline of what the A p I is supposed to be doing. So we take that catalog and then we take all of the information from every time that a p I is used and we do comparative analytics, um, against this normative baseline. And that helps us discover, uh, you know, huge numbers of unknown vulnerabil vulnerabilities that aren't published, haven't been, uh, uh, shared in internally within research communities, or, you know, discovered by any other sources.
Um, and that capability to over these unknown vulnerabilities is incredibly important because, um, when it comes to a p I security, back to the point you just made about, um, we've only been talking about it for the last couple of years, regardless of the fact that APIs have been existent for 15 or 20, um, the bad guys are on the job training too. They're learning how to use all of these APIs and abuse them in new ways, which means that things like published vulnerabilities are functionally worthless. You, you have to be able to keep pace with how the bad actors are manipulating those APIs.
And really the only way to do that is use this comparative analysis between how an API is being used and what it was designed for. And that's what traceable excels at. Agreed.
Excellent, man. Good, good background. You know, before we jump into the study, it's, it's traceable AI is the website.
Yes. Cool. Alright, Richard, so you guys have been doing this state of a p i security report now.
This is what gonna be the second or third year? Um, so this is, uh, this is a second. In this particular case, we took a slightly different, um, direction, um, on our most recent, um, we, uh, we partnered up with Larry Ponemon and the P**n Institute, which, um, is always a great thing to do.
Um, I've, you and I have been around the block a long time. Larry's been around the block probably longer. Larry's actually down here near us.
We're in Boca Ratone. Larry's down right down here. Yeah.
Yeah. And I, I think that, um, the value of going with the PAMA Institute is kind of the, the, the depth and breadth of their experience in doing studies and analyses. Um, and, and I think that, uh, you know, even, um, you know, in Larry's case, he was, and as I was, I, I was shocked by the founding, uh, the findings in the study that we've, uh, we've developed.
And we think the most important thing about this study is, is that it doesn't rely on, you know, let's do case studies on breaches and, and hacks from the past. Um, let's talk to people in the enterprise and ask what their current state understanding is of a p i security and whether they have programs. And, you know, the percentages have come back, uh, that, that are really kind of shocking.
They indicate, and I think we can dig into this, they indicate that there's a substantial cognitive dissonance between I know I have a problem and I'm doing nothing about it. And I don't know that there are many points in cybersecurity or information security history where the gap has been as large as what this study is, is suggesting. Um, and it raises a lot of questions.
Why are people, uh, you know, slow to address this issue? Why are people slow to form up programs and, um, invoke, uh, controls to be able to address a p i security? And I think there's some indications in the study of what some of those answers might be.
Um, but really the, the, the, the, the degree of the problem, um, is to mention in this study, uh, in a way that, like I said before, it was really shocking to me. And I'm an old practitioner, um, and I don't see many things to surprise me anymore, but this study did I, I agree. So I always like to say, Hey, Richard, we we're going to get into the surprises in a second, but let's take the, the key findings, the three big key findings, if you will.
Sure. If you don't mind sharing. Yeah, absolutely.
And I don't, you know, I don't typically read off the percentages, um, you know, in rote, I don't need the percentages. Yeah. I encourage people to go out and pull down that study and take a look at themselves.
But what we, what we definitely see as kind of the three, um, you know, or so major issues that have, have been highlighted in the study is, first of all, the landscape of APIs is much bigger than anybody's really acknowledging. And, and one of the things that I found fascinating in this study is, uh, 88% of the responding companies, nearly 1700 respondents, um, across, uh, the world. Uh, 'cause there's a global study, um, 88% have more than 2,500 cloud applications.
That's a staggering number. Um, and what's interesting about all of these cloud applications is, is that they're incredibly dependent and some of 'em are exclusively dependent upon APIs in order to be able to do and provide the functionality and features that these companies need in business applications and technology applications, 2,500 applications to be exposed to that all have a p i dependencies is a massive number. Um, and that's just an average.
Um, and, and I think that, you know, the other thing that really materializes out of these, uh, out of this study is that, um, there is a universal, uh, understanding, you know, nearly, you know, in the seventies and 80%, uh, range of, of concern that APIs are a, a substantial threat and risk. Um, and you kind of couple that with how many of you are doing something about it, and it's 80 some odd percent acknowledging and 20% on doing something about it. There's that cognitive dissonance gap that, that gets me so concerned.
And then I think the other thing that really, um, you know, kind of jumps off of or out of the pages, uh, of the study is that, um, everybody is acknowledging that their a p I situation is going to get worse. Um, they're acknowledging that that APIs have created a dynamic where, um, attack surfaces are growing within their organization every day. And if we look at, you know, security frameworks, whether it's NIST or ISO or, uh, zero trust or any, there's no security framework that suggests that what you really want to have happening in the organization is your attack surface growing out of your control, right?
Your, your goal state is to du reduce your attack surface. Um, yet the survey respondents and study respondents for, for, um, the work that we've done in the state of a p I are all clearly saying that, um, this world is moving faster than we are, and that attack surface is growing exponentially. And it kind of, you know, leads you to that conclusion of why is anybody in the marketplace thinking that this particular problem is going to age well?
Um, because this problem is going to age very badly, very poorly. Um, and, and again, the numbers are simply concern, uh, confirming what we've talked about, about anecdotally for the last two or three years around a p i security problems not aging well, you're not doing anything about it. You recognize it as risk, and then frankly, your attack surface is even bigger than you thought it was.
Agreed. Agreed. Matt?
Um, you know what? I'm a half full kind of glass half full kind of guy. It, this is progress to me.
I mean, it's, look, the world's full of potholes and time bombs and Yeah. You know, but this is progress for me because I think at least we're acknowledging a, how big a, a part APIs play in our development, in our applications, right? In, in our connected world.
And b, what what some of these issues are beyond, do I have APIs? What APIs do I have? Right?
And, and, and so that's progress. Um, you mentioned, you know, you and Larry were very surprised at some things. Let, let's kinda highlight those for, if you don't mind.
Yeah. For, for the audience. I, I think I can really just boil that down to one, um, you know, key finding that all other surprises radiate off of, um, which is just this, this finding that, um, the vast majority of enterprises are doing nothing currently, um, relative to a p i security.
And in the cases when we look in the, uh, that's Not progress. That's not progress, right? Right.
But, but in the cases where we're looking in into that, um, into those findings even deeper, um, what we, what we are seeing are numbers inside of that study that suggests that a lot of enterprise security as well as enterprise business leaders strongly believe that their current state solutions are solving for a p i security. And this is a point that I find fascinating because if you look at the, the, the news cycle, if you look at the breaches, uh, that have been a p I enabled, and this is not throwing rocks at any of my, you know, brethren and sisters at, uh, any of the other solution providers and, you know, all of the security solutions that have come up in the stack. But the reality is, is that every massive, uh, a p I breach of the last two years, uh, were large enterprise customers with huge, uh, you know, customer and account volumes that were exposed or data that was exposed.
In every case, every single one of those large enterprise customers has gateways in place, has web application firewalls in place, as encryption in place is using, uh, you know, authentication protocols. And there's not this recognition that all of those different components, like if we think about authentication protocols being used for a p i security, which a lot of people say, well, if I authenticate it correctly, then everything's gonna be good downstream. Um, we have to kind of be intellectually honest with ourselves and remind ourselves that APIs, which are virtualization in this layer seven making all of this cool magic happen are dependent upon authentication technology that was created about 25 years ago.
So this, we, we have this disconnect where security architectures and security solutions, um, are, are being overlaid onto this cloud, uh, enabled world. And those technologies, like I said, I'm not throwing rocks, I'm just simply looking at outcomes and results. And when a company like T-Mobile has 37 million accounts, uh, you know, exfiltrated from their organization like that, you know, it raises questions like, okay, so why didn't securities technologies that were currently in place that are managing a p i traffic and all of that catch that the truth of it is it didn't catch it because it was still dependent upon a security architecture, um, that is based on 15 or 20 years ago.
So I do think that one of the things that, um, kind of radiates off of that, too many people not doing anything about this currently, or they think that their current state solutions will protect them in this a p i security space, um, is we're starting to see, and this is a, the glass half full, uh, kind of, uh, position. We're starting to see people understand that maybe, um, some of our most pressing challenges aren't specific to a solution like a traceable, um, but they're specific to the fact that our security architectures have not changed to reflect that the way, the way that the bad guys are actually attacking us. And, and that security architecture conversation starts to lead us in the conversations about the sufficiency of our current state solutions and whether or not we need to change those.
So I think all of that is, is very clearly, um, pointed to, right, not explicitly talked about in the study, but clearly pointed to in the, in the, um, information that we have. And Alan, I wanna come back to something that I think is so important. Like you said, you know, we, this is progress, and I agree it absolutely is progress because it matches a pattern that we know from history, and sometimes it takes the folks that have been around security for a long time to see these patterns.
Um, but there was a time in history where I could walk into a data center and ask how many firewall rules I had, and a security engineer would look at me with a blank stare and say, I don't know. Right? Or How many virtual machines do I have, say 10 years later?
I don't know. Right? How many, uh, web applications are my employees using?
I don't know. And, um, that, I don't know, phase happens perpetually in the evolution of technology. And we're beginning to come out of that, I don't know, phase The study proves this, the, I don't know, phase and into the, I better know and I better do something about knowing, and from knowing I'm gonna understand my risk dimensions and from understanding my risk dimensions, I'm going to start to take action.
So we're in that window now, that inflection point has been achieved. I think this study proves it. And I think that that's a very good thing because now we'll see, see companies and organizations begin to take this particular threat seriously.
Way to, way to put a smile on at the end of that, Richard. Um, and, and I'll tell you something else. You know, it's almost the nature of the industry that there is a lag between what's going on, sort of at the front lines, right?
Yep. And that information intel making, its way back to the architecture groups and it being, uh, reflected in new security architectures and processes and so forth. It's just the kind of the nature of the beast.
You, you wanna shorten those lines, right? You want to increase the communication, but that, but it is taking place. And as we both said, it's a good thing, Richard, you know what we didn't mention?
ai is the website for the company. Where can they get this report? Um, there's a stub for traceable, or for this report on traceable ai, you can actually go right to, um, our, our web slash page.
You'll find a link to go directly to it. Um, and anybody's able to download this report. We encourage people to do so.
We're actually broadly distributing it, uh, to agencies and organizations, um, and, you know, everybody in the industry that's willing to, uh, take it on, because I think it, I, I think it is a unique study. Um, like, like I said at the top of the conversation, I think it's a unique study because it's looking directly at the levers and the mechanisms and the decision making processes around, um, why a p i securities in its current state, and how to move forward from here. Like I said, instead of doing some kind of, you know, forensic analysis of how many dollars were lost or how many people, you know, impacted an account fraud or account takeover, those numbers are really, really important.
But that's just a scoreboard, right? People really need a playbook. And I think that the numbers that are in this study are giving indications of a playbook, um, that people can begin to form up in organizations to attack this particular issue.
Excellent. Richard. Matt, thanks for coming on, keeping us in the loop here on, on this latest study and what's going on in a p i security regards to Jody, Jody, and the entire traceable team.
Come back and keep us posted, Matt, until then, enjoy Absolutely up for it. And as always, thanks again for having me on, Adam. Thank you.
Keep doing what you're doing. Richard Byrd, chief Security Officer, traceable AI on their new traceable AI state of a p I security study. ai.
We're gonna take a break. We'll be right back here on Textron. This is Textron tv.
Hey, everyone, welcome back here to techron tv. You know, I, I spent most of this week out in San Jose for the annual Jfr Swamp Up event. And as usual, it was a great event.
You know, the folks at Swamp Up, I've said this for years, they, they've created, not at Swamp Up, but Jfr, they've created a great culture, not only of the frogs themselves who work there, but the partners, the, the, the users, the, the entire community really comes together at Swamp Up. And you can kind of feel the love. It's, it's tangible.
And, and I think it's a testament really, to the three co-founders at Jfr. Of course, you know, Shlomi, Shlomi, Beka, C E o, Fred Prince, and y Laman. Um, I'm very happy to have yv.
We, we snagged them from swamp bup here with us. Yo, of course is co-founder and c t O at Jfr. Yv, always a pleasure to have you on Techstrong.
How are you? Great. Good to be here again, Ellen, It's good to have you.
So, yobo was another fantastic event, swamp up this year. It's good to be, you know, not that totally gone, but people aren't as worried. It's in the rear view mirror.
We've got a full kind of turnout again. Um, lot of interesting discussions, a lot of interesting announcements from Jfr. If you don't mind, why don't you, I'm gonna ask a, I'm gonna put it on you.
Uh, what, what, what do you think were the big takeaways for people, you know, that they can listen to here now about, uh, was announced that, uh, swamp up this week? Yeah, so first it was a great event. Uh, I think we're out of the woods, or it feels like it's out of the woods with Covid.
So great attendance, uh, many partners, uh, many customers, and many future customers. So we made exciting announcements around, uh, the Jeffo platform as a full secure software supply chain, end-to-end software supply chain in three major areas. The one, uh, the first one is really lifecycle management.
Uh, second one is around security. We're extending our security portfolio. I'll touch around it about it, uh, in a second.
And the last one is about, uh, machine learning and the support of J Fog as a machine learning, uh, uh, supply chain platform. Uh, so maybe, maybe we should start with, uh, with, with release lifecycle, uh, management Love. So, Jeff always had, uh, binaries in mind.
And as you know, a release, uh, at the end of the day, it's a binary that's going to end up in your runtime. That's everything you care about. Like, you have the pipeline and the pipeline is significant, but it's just the vehicle to get a release to run somewhere.
Otherwise, why, why bother developer, uh, this, uh, release? And what we are introducing is, uh, with this release first approach is the ability to, to attach evidence on top of the release. So you can think about the release as a binary that leaves behind the trail of evidence.
It could be, can be security scanning, it can be approval for promotion, maybe from staging to production. It can be, uh, some something else like, uh, even a general document like, uh, maybe a code coverage document or, or something like that, that q you can attach to your release. Mm-hmm.
Uh, we already have, uh, very strong building blocks in the j o platform that are highly adopted by customers, such as release bundle, which is, um, uh, which, which is the way to, uh, basically bundle an application. And we introduced the next version of release bundle or release bundle, uh, version two, uh, with this new feature of attaching, uh, extensible metadata, signed metadata evidence on top of it, and get this lineage and get the, get this full traceability, uh, about your release, the build that created it, uh, all the artifacts that were part of it, and any external evidence, like you can go back in time and say why this release is even in production. It has a very critical security vulnerability.
And you can show the evidence and say, but look, when, when I scanned it a week ago before I put it in production, it was not a known, uh, vulnerability. Here's the manifest, the signed manifested, or the evidence that, uh, that is attached to this release and proves that, uh, this was the situation. So that's the release lifecycle management on security.
We announced a couple of, uh, exciting things about, uh, shifting left. Uh, so the first thing is that we're expanding our, uh, ID integration with sass. So, uh, source codes, uh, scanning SaaS, and, uh, uh, so, so that's, uh, the jfr approach to, to SaaS scanning, SaaS scanning.
We have our own, we devised our own, uh, mechanism, uh, of doing that, that can work across multiple files and support, uh, various, uh, uh, ecosystems. Uh, and another very big announcement that we made is, uh, is curation and catalog. This combination of, uh, a curation engine, uh, which allows any security personnel to really focus on, uh, on, um, quality control, even before quality assurance.
So if you know this term from the industry, uh, you can do quality assurance on your, on your materials that are already in the pipeline. But in order to be, uh, to save, uh, uh, a lot of time and money, you want to kind of, uh, eradicate on the external perimeter, anything that you want to bring, you don't want to bring in from the first place. And sometimes it's very intuitive, like if there's a malicious package, no way.
I want it in my organization from the get go. If there is a release that is too new, maybe it's two weeks old, so I don't want to, to be the new Guinea pig of, uh, of the software industry and get, uh, uh, hammered by, uh, faker J or Color js, if you remember those, uh, incidents, not, not so long ago. I can set a policy that say, okay, don't allow this, uh, two new release to, to get in, uh, and so on.
So this is GE curation. The nice way about it that it's seamless. You just, uh, point your artifactory at the curation engine, and you get immediately all the good research, uh, uh, and metadata that the Jeff o research team has injected into catalog.
Uh, so for instance, you can set policies, uh, which will be also expanded in the future around the security, the, the risk level of a certain project, because the number of, uh, commits or, or the, the cadence of releases and so on. So this is catalog. This is something, it's like the database that curation consults with in order to create those policies.
And when you try to download something for multifactor as a developer, Artifactory will reach out to the curation engine, make, uh, the, the question and get a thumbs up thumbs, thumbs down decision of whether this dependency is allowed. We also know how to, uh, deal with the range of, like the graph of dependencies. Uh, and as a developer, you can, you will get an email.
If you get rejected, you can start a workflow of waivers, and you can see, uh, exactly why, uh, sometimes in your ID or in your, um, C L I tools, uh, why this, uh, uh, specific download request was rejected. And this comes on top of our, uh, of our current security offering. So if there is a situation where something which is vulnerable, uh, which wasn't vulnerable at the time of request, and maybe a week later the situation changed.
So Excel and Advanced Security, we'll find out about it. So we have extra for, uh, component scanning and advanced security that is doing secret detection and, uh, zero day, uh, uh, discoveries and contextual analysis like, uh, applicability, uh, uh, analysis, um, and yeah, and infrastructure code scanning and, and all that, that, uh, goodness. Um, so that comes on top of, uh, of our current security offering.
And so I'll, I'll pause here for if you, if you have any question. Sure. I mean, there's a lot to digest there.
You know, you have, we, uh, next month, October 16th, I think is, uh, we're doing our annual virtual event DevOps experience. I think actually Shlomi May on a panel of CEOs from CloudBees and Digital AI and a few others. Um, the theme this year that we picked is we're calling it Achieving Balance in DevOps, right?
com in 2013, 14, right before even, we certainly have now seen the shift left happen. We've seen DevSecOps. I mean, from, look, just listening to you over the last few minutes, we could see how important security and software quality has become to that DevOps through the, not only to DevOps to the whole software development lifecycle, right?
Are you afraid that we we're shifting left too far, we're putting too much emphasis on security? It it, or is it, is this now balanced and it was unbalanced before? What, what are your feelings?
Yeah, it's, it's a very good question. So at the end of the day, it boils down to a question of trust. Like everything that, uh, that we're doing is around, uh, really, uh, like, uh, emphasizing the, the trust or, or, uh, um, accelerating the trust that you have in your releases.
Because everything is automated with every, uh, pipeline is automated. At the end of the day, if you cannot instill trust in the process, uh, uh, you, it, it hampers your automation. So the, the one thing that you don't want is to overload your developers with too much information, uh, and too many findings.
Or some vendors, they may consolidate different open source tools that, uh, at the end of the day, they will reflect to them many findings. Some of them may be conflicting, and some of them may not even be applicable, right? So you may get a security vulnerability, vulnerability about something that your code isn't even making a call to.
So that can be reduced. Uh, so sometimes you have a network, uh, uh, exposed vulnerability, but your dock container is not allowing any network connection. So you, you are not exposed.
So the whole idea is not just to, it's actually twofold. It's first of all to consolidate everything around, uh, one, uh, single pane of, uh, of information. Uh, otherwise you're just going to be bombarded with, uh, with more and more, uh, information.
Um, and some, some security guys like that, they, they kind of, it looks like you have multiple insurances and, and, uh, it's not necessarily a bad thing, but when it comes to the developer, it slows you down. So you want to have everything consolidated, uh, and maybe you, you want to challenge the tool that you're using from time to time by comparing it to other tools. And the other thing is that you want to have only the applicable findings.
That's even more important. You want to reduce the noise. You want to, uh, avoid this, uh, vulnerability fatigue the developers are getting.
And at the end of the day, you have a huge depth, uh, of, uh, security issues that you already are not fixing or you are just, uh, waiving them. Uh, we, we also saw these kind of situations happening. Um, so increasing the quality of results, making sure that you have, uh, everything consolidated.
Uh, sure. So Let me bring up another topic. You can't, you can't walk three steps without tripping over something with AI these days, right?
Generative AI and how it's helping. We had a hackathon, uh, here two weeks ago with John Willis and Damon Edwards, Patrick Dubas, Shannon, Lisa, a whole bunch of DevOps people operationalizing ai. And, uh, the, the, the potential to use this to help make better code, more secure code, when I say better quality, you know, it's, it's not just fiction anymore.
It's not pipe dreams. It, it, I saw for myself, it's real. I haven't seen a, I didn't see a lot in, in, in your description of new functionality, but I'm sure jfr is, is looking at this.
What kind of effect or impact is that gonna have, do you think, over the next six months, 12 months, 18 months? So we're not just looking at it, we actually announce some, uh, Yes, Big, uh, uh, announcements, uh, and features around that. Uh, but you know, Alan, the reason that people are using J Rog initially Artifactory, and now also the, the security solution, uh, is, like I said, it's trust is, is to be able to trust the releases, manage them in one place, get good access control, using the, uh, checks and base storage of Artifactory as a mean to, uh, find out about tempering and, uh, and basically have one single source of truth for all the input of your build and all the output of your, uh, well, the release, the, the final output.
Uh, AI is not different. It's just, uh, if you think about AI models, uh, so the model itself is a binary. Uh, normally it's, uh, it's a binary plus plus, uh, y plus plus because there are other, uh, Aries that surround it and are not less critical for, um, for the holistic view of the model, like the training data that you use to train the model, the artifacts like the dependencies.
Most of the models are Python packages are, are, are using Python packages. I mean, at the end of the day, it's some sort of a neural network, uh, embedded with dependencies in Python packages. So those packages may impact the, the, like, the stability in the quality of your model.
Uh, the model itself is not runnable by itself. So at the end of the day, like most cases that we see, you put some sort of a Docker container with some convention for the a p i endpoint that will invoke your prediction. And then there's the results of your model that you're using for retraining and finding out whether your predictions are still accurate or whether you need to, uh, deploy new model.
So there is a whole new workflow there, uh, that needs to be managed. And for, for the J F O customers, when we spoke with customers, their models, many times they're the crown jewel of Aries because they directly impact the, the, the, the revenues. Sometimes, you know, they're making critical business decisions based on this model, not just, uh, identifying, uh, whether something, uh, is an animal or a human being in a picture.
A lot of these models, they, they really drive the business, uh, so you need to manage them. And what, uh, what we found out is that, uh, there is, with l l m, you know, there is huge adoption of machine learning says like, uh, 90% of applications in 2027 are going to to be, uh, and I to, to embed machine learning. And I think it's real because it's very easy.
The barrier to embed it is, is very easy. Uh, but we found out that the situation is that, uh, it's very much like the early days of DevOps. Like, uh, you have the data scientists mm-hmm.
Or the, the researchers, and they work in their own small world on, on their desktop a lot of times, or maybe on, on a remote development environment, uh, in the Jupyter Notebook, uh, doing the, uh, the scientist, uh, stuff and creating the models and training them and using all those, uh, nice Python libraries. At the end of the day, they are not productive unless they get a DevOps to hold their hand and move them to production. You know what, even before moving them to production, the DevOps have to streamline the data from other systems for them in order for them to clean it up and, and train the model on it.
So they need the, the, the operational end, um, in order to, uh, create trusted workflows. And today, they, they, whenever we spoke to the customer that has machine learning for a couple of years, and we found out that a lot of customers are already using Artifactory as the, um, registry for their models because of the access control, because of the trust, 'cause of the checks and based origin and so on. There's always a develop team that, uh, uh, helps the, the, the scientist.
Sure. And what we announced, uh, is we, we said, okay, we have to, uh, we, we have to offer our customers a much better and much more mature and much more trusted solution around managing those models. Uh, so we, we did a couple of things.
First of all, we introduced a dedicated machine learning type of registry in Artifactory, we are using hugging face as the format to, to begin with. Mm-hmm. Uh, so we are, you can host hugging face compliant models, but, but what's more nice is that you can bring on all the foundation models from hugging face to your own organization, uh, and those models that can be used, sometimes they are, uh, I mean, if you take lama uh, too, it's uh, it's around 10 gig, so it can take a lot of time to download.
You don't want, uh, your organization to redownload it, uh, every time. Uh, so we bring, we, we, the, the, the models from hugging face, uh, and more other, we scan them. So we scan them for, uh, vulnerabilities.
And we found out there are, um, malicious models already in hugging using, uh, mainly Python to, uh, to allow a takeover. Uh, I mean, at the end of the day, it's like a Python library that runs something. So you can, uh, you can use that, uh, for, um, for not kosher purposes.
And the other thing Got it, is we're scanning for, uh, compliance, for license compliance. So if you're using a model which is not friendly in terms of licensing, we will also also alert you about that. And, um, and we, we, we actually see a lot of customers already using these transacation models for marketing phase, uh, retraining those models, uh, adding, uh, lower land, lower LE layers on top of the, the existing foundation models.
Uh, so that's, that's a big announcement we made around trusted, uh, modern management, uh, with ro. So yv, here's all fantastic deep information. Unfortunately, people watching this, if they were not swamp up, they missed it.
Uh, but we can't help out, but we can help them get on the ramp to, to jfr and, and to take advantage of these new things. What's the best way for them to engage and, and to maybe, you know, try out some of these new features and capabilities and everything that was announced at Swamp Up. Yeah.
So the nice thing with what we announced is that everything then we, that we announced is either, uh, ready for you to use or, uh, in, uh, in, uh, last, uh, phases. Uh, so you can, you can use it today. com and you start downloading Yeah.
The trial and, and, uh, and start experimenting yourself or reach out to us. We'll know how to give you more information if you need. Absolutely.
And we should mention that at the same time, swamp Up was going on, JFR was also, also had some folks over in DC right at a, an important cybersecurity conference there, uh, in, in conjunction with the government. com as well for, for those who are interested. But if you want to give them maybe of just a 30 seconds, what was going on there On there?
Yeah. So in, in the same spirit of, uh, of fostering software trust and trusted releases, the White House is, uh, uh, gathering again the group of experts to discuss what the next, next steps should be with securing open source software and, uh, releases in general. So, uh, our CSO Morken is there, together with one of our, uh, product, uh, uh, leaders.
Uh, we were invite you to these discussions under the, uh, open source, uh, foundation. Fantastic. Alright, we gotta pull the plug on this one.
Yo, thank you so much for coming on. I know between traveling from Israel to California and back and everything else, it's a lot. And I appreciate you taking time out to come talk with us today.
Be well, hopefully I'll see you soon again, but it was great seeing you, and it was a great swamp up. Thank you very much. Thank You.
My pleasure. All right. Yo Laman, co-founder, C t o for Jfr here on Tech Drunk tv.
We're gonna take a break. We'll be back in a minute. This is Strong tv.
Hi everyone, I'm Bonnie Schneider with Techstrong tv. Today we are talking about the critical intersection of cloud technology and sustainability. Joining us is Olga Kova, who is the head of Go-to market at Workspot, and the founder of Women in Industries Network.
With an extensive expertise in cloud technologies and a commitment to sustainability, Olga is here to share valuable insights that will help us understand the impact of cloud adoption on driving positive environmental change. Olga is a pleasure to have you here. Thank you for having me.
I'm super excited to chat with you today, Bonnie. Great. Well, can you share it with us more about your background and the work that you're doing at Work Spot and Women in Industries?
Yes, absolutely. So I've been with Work Spot for two years. Um, as I came in, I've been exploring end user computing space.
And it's an act, actually a really interesting intersection between everything that's going on in Theno technology space, what's happening in the on-prem world and the cloud world. And of course, one of my passions is how do we actually take technology, profits, revenue and impact the globe in a better way? And one of those questions that I've been asking across all of our customers is, what are you doing around sustainability?
So I think today we'll be actually sharing some interesting statistics and data from our recent customer interactions. And I'm really excited. There's, there's a lot of awareness that needs to happen on how to bridge it together, and I think you and I can, uh, achieve that today.
We'll see what we get. Yeah, I think that's a great, uh, point. And I, I just have to tell you offhand, like I've been hearing so many of the guests that I've had say that they've been hearing from their clients more and more about sustainability and how do we address this, and we're gonna get into it.
Well, first of all, I wanna talk about what do you attribute to be the driving force behind the growing importance of sustainability in the tech industry? We talked about how it's a topic of discussion, but what do you think is behind it? I think it is, uh, talked at a board level.
I think the CIOs understand the importance of putting metrics around it. So as we were doing research, we saw that 50% of CIOs are saying this will be a metric tied to their overall performance by 2025. So it is an awareness thing that's raising, I think the challenge is how do you quantify something you can't see.
Mm-hmm. And, um, I have, you know, we, we can get into a little bit more of details of what I'm seeing in the market, but I think the awareness is coming. The news are also helping us saying that the, the entire world is burning versus heating up at this point, right?
We've seen in the news that we're now in a boiling state, the ocean's boiling. So I think people are concerned, and if, if we're looking at it from corporate level, it seems like a much bigger thing, much bigger thing to attempt to address. We actually almost dumb it down to what can you do as a person today as an individual to actually impact what's happening around the world.
So we can address both and we can go into it. Yeah. I mean, um, let's first talk about cloud technologies.
Um, that is, uh, we have a lot of viewers that work in that field. So how can cloud technologies be leveraged to minimize the environmental footprint of organizations? Yeah, I think, so.
We, we partner with Google Cloud and, um, their initiative around, uh, overall, you know, sustainability is really, really strong. They're aiming to be a net zero, um, emissions platform by 20 th uh, 2030. I think the biggest part in where we are playing a role is the data centers.
Um, for us it's extremely important to having people. So what we're used to pre pandemic is you go into the office, your data center is closer to your office. If you go in there, it's super hot.
All these machines are overheating. So now that we're migrating in this, to this hybrid world, world of work, our recommendation to organizations to take a look at your data center and migrating your data center to a public cloud, from numbers perspective, let me just give you guys a number from sustainability and translate what it means in our terms that we can understand. So if you migrate your public, uh, data center to public cloud, you reduce your c o two emissions by about 59 million tons per year.
To us, it's a very large metric. What does it mean? It equates to about 22 million cars, gasoline operated cars off the road.
So that's the impact of migrating one data center to the cloud. What a great way to put that so people can visualize that. I don't think I've heard that before.
I think that's the biggest challenge, right? It's, it is important. We're seeing it all over the news.
We know it's a corporate initiative, but unless it gets down to an individual understanding of what that means, there's not much impact we can drive. I also think there's a lot more regulations in Europe versus anywhere else in the world. Um, and that's the piece that needs to come in play as well, to drive that change.
I think that cloud and cloud technologies are definitely addressing it because of how we're building technologies today, but we're not necessarily addressing what's been built in the past that's still being used by customers. So they, the the way we need to help our customers understand is if you're looking into cloud, it's not only the cost efficiencies, the speed of deployments, speed of use, user experience, it's also the fact that you're helping the world and help helping the sustainability metrics being addressed. It's interesting that you mentioned, um, you know, Europe that just July 31st, they just announced about the adoption of, um, um, in the eu of, of, of new, new regulations that are coming.
And it's only going to affect more companies as we go forward over the next, uh, four years or so. Do, do you find that, um, that some of, that the mindset is coming to the us? Some of it, but I would say it's a much bigger, longer road for us here, just because there's so many opinions on what's, what's possible and what's not.
But I do think it's a, it's really good for organizations that are global. For example, we're, we'll be discussing our customer Landis and Gear today. It's 125 year old, uh, organization that's seen it all, right?
And they're all over the world, probably everyone who has a meter in their house. I encourage any, any of the watcher go check it where it's from. Lend and Gear is the industry standard.
Who's tracking your energy consumption and how has it evolved? Right? So we had energy in our homes for as long as we know.
Uh, but how do you collect that data? How do you actually make that data available to improve your energy consumption to actually address energy needs around the world? And there, because they're a global company, they are taking advantage of the regulations set in Europe regulations they can implement in the us and they're pulling it, um, their metrics around the entire value chain.
And I think that's a set, that's a really good example of how companies can take a look at what they're doing. It's not just saying, we're sustainability aware, we're recycling. I feel like that's kind of like standard in our world now, but it's, it's the recommendation of taking the look at the entire Valley channel, what you're doing today, um, and how you can impact it from the, uh, from the sustainability angle.
Um, how would you describe the Landis and, and gear, and I don't wanna pronounce it wrong, gear's, uh, journey to achieving sustainability goals through end user computing modernization? Yeah, there's, there's a lot. So I had the pleasure, uh, to work with Steve Crawford, their IT director, um, and he's taking a look at their entire infrastructure globally and, and user experience and user computing.
And they've tried multiple technology. They've tried, tried on-prem solutions. They've tried, um, cloud solutions, but for them, when they were making a decision on which technology to use, it was actually sustainability that was driving some of the decisions behind it as well.
So when they're taking a look at the overall strategy, so whether it's design raw material components and semi-finished products, their actual production, their transporting and packaging installation of solutions, all of that is important, um, to impact their value chain and their sustainability metrics. Um, so when they were taking a look at WORKSPOT as a solution, because we're cloud native and we built in the cloud, and because we addressed the data center, um, being migrated to the cloud, that that was a big part of the decision, um, as to why they chose work spot. That makes sense.
How can other companies adopt similar strategies to achieve their environmental objectives? Yeah, I mean, we can address it from, um, you know, metrics perspective. Um, I like to talk about, you know, investment in the right technologies.
What are you, what does your entire organization use and how does that contribute to your sustainability goals? Taking a look at all your, your vendors will be the first step, um, understanding how to quantify, you know, Bonnie, you and I were talking about what is a metric, what does it mean, right? So 59 million tons of c o two emissions seems very drastic.
Does, we can't visualize it, but we can visualize it by removing 22 million cars off the road. Um, that's, that's, I think that's the metrics level of metrics we need to start using to understand and quantify it a little bit better. I think organizations like Landis and Gear is making it a company standard and everything that they do in terms of investments, solutions, internal vendors, everything is uh, uh, correlated to the metrics they're trying to drive through sustainability.
I think that's an important driver as well. Well, the partnership between workspot and industry leading providers like Google Cloud and Microsoft Azure, um, has transformed IT infrastructure. So how do you view these collaborations, um, in terms of the effort to drive innovation and elevate sustainable practices?
We do a lot together. We try to, so recently we've spent quite a bit of time educating the Google Cloud customer community. Um, we partnered together with Google Intel and Work Spot, our, you know, there's Chief Sustainability officers.
And I think this is the unique part of bridging the gap between my job at Work Spot and my women, uh, in, um, women Industries Network is being able to educate audiences of what they can impact. You know, when I was growing up, our roles were be a engineer, be a mathematician, be a doctor, but now you can be chief sustainability officer, you could be, uh, you could be anything. So it's understanding if you have passion behind it, if you know how to drive metrics, if you, uh, know how to help companies quantify, you can contribute to their efforts around the world.
And I think that, um, there's a level of interest across many organizations and corporations to get that going because of the board, uh, board level interest because of the vendor's interest. I think it's a mutual interest to drive. And in our partnership with Google Intel and Work Spot, we're trying to educate people where they can get started.
That is, that's great. Yeah, I'm, I'm, I'm super excited. There's certain things like start with the data center.
Um, minimize your waste on having a physical data center. Um, minimize your waste by having, you know, data center running 24 by seven, that's, you know, that's incredible amount of energy being put out and you don't need it running when your users are not active when they're asleep. So there's little things that companies can start thinking about, um, that they can implement on solutions they have today, uh, that can drive a major impact.
That, that's really good. I, and I'm sure there's a lot of solutions that that almost seem obvious, but if you don't know, you know, you don't know. So, uh, very helpful to hear that.
Um, can you share some of the best practices that organizations can follow, um, specifically for their IT processes, uh, to enhance environmental responsibility? Early this morning I was on a webinar with people from all over the world basically asking you this question, you know, what can we do? Because a lot of the corporations are looking to their IT departments to lead the way.
Yep. I think, um, even Gartner's and IDCs research were saying that digital solutions will play a huge role in, uh, reducing c O two emissions and getting to the net zero economy. Um, I think the very conservative estimate is 20 to 25% impact.
So the recommendation is take a look at cloud native solutions when they're built in a cloud native with cloud native architecture in mind, you are removing a big chunk of C O two emissions. So that's number one. We actually, um, with collaboration with Google and Intel, we went down a level deeper said actually, what are the five things you as an individual can do today to impact?
So your IT department can take a look at the applications, review your vendors, review your stack, but as an individual you play a huge role. So, um, I'd love to share five things we've recommend. Yeah, please, for the cloud customer community.
So number one, simple. They're all of these are very simple. This is why this is so cool and how much you can drive impact immediately.
So number one, reducing your energy consumption by just simply turning off EL electronics that are not in use. So if you go into the office or you're at home, unplugging that or turning off the lights is immediate impact. Um, when setting up your energy bill, many don't know, but you can actually request clean renewable energy.
So take a look at your energy bill at home, your IT team can take a look at the energy bill, whoever pays those bills within your organization, finance, um, take a look at it. Are you using renewable energy? You can request that from your provider watching high network bandwidth consuming, uh, content.
So that's a tough one. We all get on planes, we all travel, we are all on the beach. Everyone's streaming, right?
Everyone's streaming, but if you can download it at home and then watch it when you're away, that's also a huge contribution. So those are very small things. Number four, supporting your local farmers.
Very simple by locally grown food, uh, and uh, produced food that's supporting local economies, supporting local, uh, farming. And it doesn't require as much as much energy resources as you would on a bigger, bigger farm. And then, um, if you can, which is also a really important one is hybrid electric vehicles.
So if you, you have an ability to bike somewhere or you can invest in a electric car or just using public transportation instead of driving everywhere, take advantage of it. Um, and also is really good for resetting your stress levels, not just not just our sustainability practices. That's great.
Um, and it kind of leads into my next question. You answered half of it already, but, um, what about waste reduction? You know, if we're dealing in the IG department, there's just so much stuff here and then and people don't know what to do with it and how, what's the best way to dispose of it or repurpose it?
What would you say about that? I think that's the biggest part of what we do here at workspot. It's, you know, in our world end user computing can be done on any device.
So the biggest conversation we have is your physical PC refreshes. So every company, you know, when you join an organization, an IT organization, any organization nowadays is that you get a laptop and you of course want the new shiny thing and that's fine, that's perfect. However, typically they last two to three years at most.
That's a very kind of the, the longest term you can keep your laptop for. What Workspot provides is that you can keep that laptop and the way you provision your desktop is via cloud. So we're leveraging cloud infrastructure, the speed being able to give you the highest power machine via cloud by you just simply logging in this way you extend the lifecycle of your laptop.
We've seen that done across multiple organizations we work with. And that not only saves the budget for physical laptop refresh, but it's also giving your employees the flexibility to bring their own. It gives them flexibility to use any device.
And that's a big part about, you know, renewable energy. From a physical, you can actually feel it and see it, right? So you have your laptop by getting work spot and logging into a high powered machine, you're saving a ton of money, ton of waste for your organization.
So that's a big, big conversation we're having with all of our customers because we've shifted from just the V D I perspective, V D I has always been more of a security conversation. How do I give access to my employees in a secure manner? There are not in the office, there are not a part of the company.
There are consultants or remote engineers. Now we've shifted that to how do I actually leverage this solution to one, minimize the impact of physical devices and distribution. Two, minimize my costs and three, minimize the waste.
And that's a big part of the conversation. Oh, that's great. We have time for just one more question.
Um, and maybe if you can talk to what we're seeing for trends going forward towards the future. Yes. I think there's a lot of noise and buzz around this, right?
I think it's about being focused. What are the one or two things can we achieve? Um, I think it goes both ways for our new year resolutions as far as sustainability strategies, right?
Can we focus on one thing we can achieve in a year? So what are the trends? I would say if you were to get started today, data center migration is a big project that people undertake.
Um, implementing a full-on, you know, cloud PC strategy was versus a physical, a PC strategy is a big conversation, but taking a look at your existing vendors or taking a look at your existing solutions and making sure that they are filling your requirements of sustainability practices is extremely important. And you can do that to get started today. That sounds great.
Well thank you Olga. Like Cova head of go to market at workspot for sharing your invaluable insights. This was a really interesting conversation.
Uh, really enjoyed talking to you and I'm sure our viewers on Techstrong TV gained a lot from it. Thank you so much Bonnie. Thanks for having us.
Alright, well stay with us on Techstrong tv. We're going to have a lot more coming up. I am Bonnie Schneider, sustainability contributor to the Techron Group.
I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with the sustainability pulse meter offered exclusively from Techron Research.
This is Techron tv. Hey guys, thanks for the throw. We're here with Jim Douglas, the C E O for Armory and we're talking about DevOps, whether it's dead or whether platform engineering is just the latest incarnation thereof.
Jim, welcome to the show. Mike. Thank you very much.
Good to be back on Techron. There's all this noise in the system about platform engineering is the next great thing. And my question to you is how do you define it?
'cause some folks think it's the replacement for DevOps and others are like, well no, it's just the next iteration because well, we're all maturing Maybe the oldest thing in the world. That's how I define it. It's been around forever and I wouldn't even call it the next thing.
It's an augmentation do a sound DevOps strategy. Um, let me monologue for a second. I'll kind of back my way into it, but I'll be quick.
You know, go back before kind of electricity, you know, 20, 25 years ago, um, before the IT teams were really part of the value delivery and value capture process. You know, organizations were very stovepipe. You had developers in one hand in one org and you had operational folks that kept the computers running in another org.
And that all had to change once the IT teams had to be part of, as I said, that delivery and the value capture process, i e e-commerce. And so organizationally you started to, things change and then eventually you had to drive better communication and collaboration, build new processes and eventually start to automate those processes. And that was really the start of DevOps is how do you make that whole flow more seamless and how do you continue to optimize it?
And it continues to be the case and it will continue to be the case forever. People will come up with new names to call it or new adjuncts to DevOps. But at the end of the day, people are constantly gonna try to improve and optimize the overall software creation delivery.
And as I said, capture process platform engineering is a newer term, but there's always been terms for teams that have been building tools to help augment that process. And I think the thing that's changed and why the term platform engineering came about is these teams used to have to either completely build custom tools before the market had produced commercial tools to really, um, if you will, automate parts of that process. Or they had to supplement commercial tools with a lot of customization.
As I said, these groups have had different names forever. Heck, when I started my career in software, I was in the cadcam domain electronics automation. And we used to have to sell into these groups called CAD groups or CAD managers.
And they essentially were platform engineering teams that were building out a suite of tools for their designers. And that's what platform engineering teams do today for people that are designing applications for the cloud. I think the thing has changed since they moved from doing a lot of custom work to doing more integration and then building abstraction layers to create more efficiencies for developers is that process has changed from being a project and moved into being a product.
I saw somebody a while ago wrote that line and I'm just absolutely stealing it from 'em. Uh, because I thought it was very descriptive of kind of the sea change where today these platform teams have this ongoing product that they continue to develop and advance and really focused on building more productivity and more efficiency for developers. So think about it once again, it's just augmenting a good solid DevOps practice and good DevOps automation by creating a platform that is really gonna aid developers being more effective.
There are some folks who are a little cynical and say, this is another attempt at the revenge of centralized it. So how do we kind of strike a balance between those cherished freedoms of innovation that we have and the tooling side and some sort of adult supervision? Yeah, well I think in general all organizations kind of ebb and flow between centralization, decentralization, and the kind of technology domains are no different.
Um, I think what you find is most organizations, these platform engineering teams, um, are building best practices and trying to deliver best practices to the dev teams. But in general, the dev teams still own and are accountable for what gets deployed. And so they still have the power.
The platform teams, I said, are just ensuring that those best practices are used wherever possible and doing everything they can to do two things, ensure that reliability, um, is met in terms of the objectives for the company. And the second thing, as I said, is just improving developer experience. So yeah, there always is kind of a ebb and flow of that relationship, but the developers at the end of the day are really, as I said, accountable for the work product that their customers are actually consuming.
Um, so I, I don't see that happening. I think in most cases what we see in organizations are in the platform engineering teams offer up tooling and best practices to developers, um, as guides and once again as tools and the developers consume what works for them in different lines of businesses and big organizations. Uh, but rarely is it draconian.
I've seen very few examples where it's, it's so draconian that hey, not only are we gonna develop all the tooling, but we actually own the deployment of code. You just tell us what you want deployed, we do everything else, and vow shall never touch that part of the S D L C. That's pretty rare.
So I, I don't think we're gonna see that. Like I said, you see a little bit of ebb and flow each way, but in general, um, there's a good symbiotic balance between the two organizations and the dev teams generally since they're accountable, they've got the last say. One of the longstanding criticisms of DevOps is it doesn't scale well.
And you still hear idle folks out there saying, you know, idle scales, it may not be as agile, but at least it works reliably. DevOps folks say it's all about being quick. Is this an attempt to kind of get to the middle?
Well, I think it's a misnomer too. I, I think, and that's one of the reasons that platform engineering as people are defining it today really gets a lot more attention because a lot of focus is on kind of that last mile of automation that is necessary for DevOps to really scale. Um, it's even more important in large organizations 'cause you have way more moving parts.
The problem is there's still holes in the automation of an S D L C where there's too much kind of man in the middle in terms of critical pieces of that handoff between organizations. And that's a lot of what platform engineering's trying to address in a more systematic way, um, where they're adding in that last mile of automation that does make it scale. So that's where it really is, um, augmenting the capabilities of organizations to use DevOps effectively.
Do you think this will also lay the foundation for applying AI to DevOps? Because we see a lot of AI tools being used to write code, but the folks that are on the receiving end of that don't seem to be benefiting quite as much just yet? I, I think in two directions, absolutely.
Um, I'm a big proponent of it and I've argued with a lot of people about how soon it's gonna take hold, how big of an impact it's gonna be. You know, I think folks like GitHub are on the right path with copilot, typically you find abstraction moving two directions. One is gonna be kind of vertical, um, adding abstraction layers for developers so they can operate at a higher level of distractions, they can be more productive.
And I think you're gonna see AI as you are in the form of products like copilot, um, improve very, very quickly as more people use 'em and allow developers to work at a much higher level of abstraction than a JSON file or a AML file where they can really describe outcomes, um, rather than trying to describe in detail what they need execution to look like. So I think that we're gonna see take off pretty rapidly in the next few years. I think the other part is think more horizontal as you're deploying code.
Most of optimization, whether it's manual or through using tools to automate, is more focused on reliability and stability. That's the real vector today. And it's ensuring that whatever you deliver to customers is gonna work and work as advertised.
You don't have downtime. If you have downtime, you can remediate either automatically, instantly, or rapidly such that you preserve that customer experience. It's not the only variable people should be looking at.
Right? There's other variables as well. Um, cost is one, right?
So maybe you're willing to give up a little bit of reliability if you could drive a much better cost envelope. So I see AI kind of at that point of a lifecycle as well, where as you have more and more operational data, you can start to add more variables into the mix in terms of what you wanna optimize for. I think that's gonna be kind of the longer, uh, pulling the 10, if you will.
The immediate one. I think we're on the right path relative to adding a higher level of abstraction for developers. And I think that's gonna have a big impact.
Should I arrive one morning and tell everybody that we're doing platform engineering or should I just maybe build some better portals and let people discover these capabilities and then after a little while I can go, Hey look, no hands, we're doing platform engineering. Um, I think once again, don't get wrapped around the axle on the terminology. I, I think everybody wants to create the new wow thing.
So they gotta come up with a new term. At the end of the day, the folks in those organizations, they're focused on two things. It's developer productivity, so building a platform set that's gonna continuously add productivity.
And then the other thing is how to onboard people so they can reap the benefits of that productivity. That's one of the biggest and most kind of concentrated effort you see from all the platform engineering teams we work with is how can we improve that onboarding experience. So kind of two flavors of user experience.
One is once you're actually on the platforms and really leveraging the automation, what does that look like? Is it easy, is it intuitive? But just how do you actually address it?
So how do you get on board these platforms and really adopt 'em? Um, so I wouldn't get wrapped around the axle on the name of that org. I think more how do we continue to improve the tooling that makes up those platforms today and back on the path we run before?
How do we continue to add higher levels of abstraction So developers don't have to be down in the weeds. They can focus on what they do best is what architecture is gonna yield the best outcome and then have technology that's gonna help them implement that more effectively going forward. Speaking about not getting wrapped around the wheel, did we lose sight of developer productivity as an issue in recent years?
It seems like maybe we obsessed about a lot of DevOps metrics but maybe forgot that the developer was the reason we all exist, right? I think so a bit. If you look at Dora metrics, so you can kind of bid 'em out two directions.
One direction would be around developers where you're looking at, you know, how fast does it, you know, how fast can you be ready to commit code, what velocity can you actually push code out? Those are definitely developer centric. The other side of that coin is more operation centric, right?
How fast can you remediate issues? How often do you have issues? So I think we totally lost it, but we've been spending more focus on operational issues than developers.
But I think we are seeing that swing back and I think a lot of it once again is some of the new tooling that are coming out in the developer space that are, you know, front and center focused on that whole developer productivity. And more and more, as I said, the platform engineering teams, back to what you asked before that power struggle. Um, you only have that power struggle where they lose sight of what their job is and their focus.
Um, if they think their job is control, their greatly mistaken if they think their job is delivering value to their customers, which are developers, those are the folks that are building great organizations. And you see more and more of kind of the really elite companies, um, really understanding that more and more and more attention is getting pushed where it should be on the developers and really helping them be more effective Speaking of jobs. And no one in these days who's seen anything about AI doesn't have that thought process in their head.
Heck chat G P T could be a c e o one day, right? Um, Absolutely. I'll be chairman.
So my question then is yeah, do software engineers need to be concerned about their future? What does that look like and what role are they gonna play? Technology is always a disruptor.
It just changes kind of focus. It has since the beginning of time. It certainly has my entire career and this isn't the first technology that people thought was gonna displace humans, right?
Um, it's just a little bit more radical when you think about it 'cause you can apply all your sci-fi thinking to it about kind of what the future could look like without man in the middle. Um, the reality is it's back to what I said about 10 times now. Abstraction, abstraction, abstraction, you know, from the beginning of computer programming, we started at an assembly language because it wasn't very efficient to write ones and zeros that a computer could consume.
So we created this abstraction layer called an assembly language and we kind of kept going up in terms of abstraction layers. From a developer standpoint, this is just gonna be the next level of extraction and it's just gonna enable developers to be more productive at the end of the day. You know, people can still define the outcomes best, um, but tooling's just gonna get better at helping 'em actually implement those outcomes.
So well we see a shift. Sure. You know, you're gonna see a shift in where people are applied in that process.
But in terms of wholesale, job elimination, yeah, I don't think so. In general, certain functions absolutely. Um, but new functions will pop up.
Do you think that maybe we're on the cusp of approaching a level of innovation in terms of how quickly we can build applications and iterate on 'em, then the business can absorb. I mean, how are we gonna be on some new x some new curve that's people aren't really thinking through the implications Now? I love that question because I think that's been a challenge for a few years now.
Um, just look at kind of technology in general and how good it's got and how fast it's evolved. You know, think about Moore's laws, the underpinning to that. It used to be from a compute standpoint every three years, absolutely you would upgrade, every corporation would upgrade every PC in the building or Mac in the building.
And then that went two years. We're at a point now, if you look at things like phones where people just aren't migrating, the next new thing is fast because they're so good and software falls in the same bucket, right? Um, it is so good at what people need in terms of base functionality that just because we can go faster doesn't necessarily mean people will be prepared to consume it.
So I think that is a good question. I don't have a great answer in terms of how the shape of that curve's gonna change, but I think businesses do need to look at that, uh, because there's a cost associated with building new innovations. And if you're delivering things that people can't consume, you know, that's not a winning formula.
So don't have a great answer, but I think you're on the right path there. I think that's probably the biggest issue is how do you kind of translate that if you will, value creation into kind of value capture. Um, it's been pretty straightforward the last kind of 20 years because of deficiencies in technology and you could just make leapfrog progression in terms of the value you could actually deliver what you're leading to is that starting to slim?
Now with that said, we go through those ebbs and flows too. Um, and I think we'll see a step function probably, you know, five to 10 years from now as people really understand how to apply AI better and we're gonna be able to create a lot more value out of it versus fairly pedestrian things we're doing today. Interesting things, but fairly pedestrian.
All right folks. Well, you heard it here. It's time to buckle in because it's gonna be a wild ride for sure.
Jim. Thanks. It's funny.
One, one funny thing to tell you. I got did a Bloomberg interview probably eight years ago asking me about AI displacing jobs and like doomsday scenario that within the next two years that all developers' jobs are gonna go away and potentially, you know, assembly workers' jobs are gonna go away because of smart equipment down on factory floors. Um, so same thing I said that I'm saying now, it's gonna change the landscape of employment, uh, but it's only gonna make it better.
But people will have to get new skills, um, retooling in some cases in terms of how organizations are built. Um, but at the end of the day, it's gonna make us more effective. All right folks.
Well, you heard it here and we're gonna have to buckle in. It's gonna be a wild ride. Jim, thanks for being on the show.
A fun ride. Thanks. Appreciate it.
All right, thanks. Cheers, the studio. This is Textron tv.
Hey guys, thanks for the throw. We're here with Greg Nacho's, CSO for Expel, and we're talking about cloud repatriation and how come we're seeing more of it these days? Hey Greg, welcome to the show.
Thank you for having me. You guys did a survey with the cloud security alliance that found a number of things, but one of the more intriguing aspects is that workloads are moving back from the cloud to on-premise. What do you think is driving that?
Um, frankly, I was somewhat surprised by it. Um, the, the, i I have a background in DevOps and infrastructure and I was surprised to see the repatriation by, uh, uh, by a bunch of vendors. I think there's maybe a few things.
Uh, you know, maybe the, the promise of moving everything to the cloud hasn't been realized and folks realized that they had kind of, they were gonna have both environments for an indefinite amount of time as opposed to we're just gonna get all of our infrastructure to the cloud. Um, and that's sort of forced to rethink in terms of box. 'cause the, the cloud is more expensive in some ways.
And so the, you know, the shifting landscape of, well, if I'm gonna have both on-prem and cloud for a much longer runway than I anticipated, maybe I better do some harder thinking about which, what stuff goes where. Do you think also that covid played a factor in this? Because I think a lot of workloads went up in the cloud regardless of their attributes during, you know, at a time when we didn't have access to on-premise environments, and people are now starting to realize the cost factors and doing a little deeper dive.
I think that's true. I also think the, you know, there's the operat, like the DevOps and operational side was, well, if you're gonna have to maintain both environments, that cost is the same, and then you have security concerns. And frankly, the technology improved for getting remote employees access to on-prem such that it's not wildly different than what, than getting them access to resources in the cloud.
And so I think both of those were e you know, it, it re the cost benefit calculus changed a little bit in terms of like, well, I need to put it in the cloud because my people are remote. And I think people question that as a first principle. Do you think that on premise is more secure than the cloud or just maybe differently insecure?
And the two environments have different attributes and you need to think through what the security parameters are, depending on the workload. They're different. Um, and I think there's a tension between them.
So there's, with the cloud, you have, you've sort of have a shared responsibility model where the cloud provider provides hopefully very excellent security up to a certain layer of the infrastructure. You're not generally worried about network security the same way you are when you're running, when you're running data centers on-prem for that, you pay the premium and the tax of the cloud, the, if you're running on-prem, you're there. The, there's a lot more mature fooling for and because you have more control over the infrastructure.
But with that control comes the responsibility of managing. So it depends on like where in the stack you wanna like focus your security sho resources. So I, I, uh, I'm reticent to say more or less it's just different and what skills you need and what tools you need changed depending on which environment you're talking about.
Part of the issue seems to me it's not so much the cloud platforms as much, it is the processes we use to provision those, uh, resources. A lot of times developers with very little cybersecurity expertise are using infrastructure as code tools and surprise, surprise mistakes get made. So how secure do you think the cloud really is these days as it relates to the platform versus the processes we're using?
Well, I mean, if the valuations of CSPs and synapse are, are any indication, this is not a cottage industry, right? The, the, i I don't know that I'm willing to blame the developers because I, I think cloud introduces a different kind of complexity than they're traditionally used to. It gives them freedom, right?
They have a lot more control over the deployment of their applications, um, which is was the great promise of DevOps. But at the same time, like the tooling wasn't there to help keep them on the garden path. And so I think we've seen a whole proliferation of tooling that that sort of helps, you know, you know, build paved roads for that.
The problem is that complexity is significant. Um, take for example, a technology like Kubernetes, um, that is, you know, you could deploy on-prem, you could deploy in the cloud using this. It's, you know, it's, it's what the promise of it is.
Cloud agnosticism. However, if you run your own Kubernetes clusters, anybody who's ever tried to do that will tell you that is a a herculean effort. Um, and the benefit of doing so is dubious.
And so that's where like the promise of the tooling and the complexity introduced by cloud Native Tech actually does itself a disservice, I think is the, you know, the choices of these advanced technologies sometimes make, uh, make, make for difficult security and difficult operational outcomes. Aren't we entering a new phase? I feel like the first phase of the cloud was a lift and shift of monolithic applications into a cloud environment, otherwise known as, you know, your mess somewhere else.
But it feels like we're moving to these cloud native architectures, and so does the security paradigms that I lifted and shifted into the cloud along with those workloads service well, or do we need to rethink this whole thing? I think you, I think like every security decision it needs to be tuned to the application and the business goal that you have. Like the, you know, it needs to be tuned to the amount of risk it needs to be tuned to the type of application.
So if you wanna put up, uh, you know, sort of a low impact application that you want to quickly iterate on, go to the cloud. If you have a high security application where you wanna proliferation of controls and you want a lot more, you know, eyes on and, uh, restrictions, you, you may find value in, in deploying it on-prem, uh, I think the, the, it's a, it is not an all or nothing and it's not a one size fits all, uh, choice. And I think that was the false dichotomy of the lift and shift thing.
It was like, well, all right, we're just gonna go all to the cloud and the, you know, uh, well why some applications, and if you're just, if you have a cloud native application, this makes a lot of sense. But if you're just picking up VMs from your VMware cluster and putting them in a w ss like maybe the, you've lost controls in a lot of ways, and maybe the unit economics don't make sense, Are we gonna see workloads continue to move back and forth? I mean, it seemed like, you know, back in the good old days, workload went somewhere and it kind of just stayed there.
But are workloads dynamically moving between the cloud and on premise as we go forward? Um, I mean, that was the, so when I talked about multi-cloud in previous roles, my, my, my multi-cloud strategy was effectively on-prem and multiple cloud providers. It was, uh, the, the kind of data centers and infrastructure that I was responsible for building lend didn't lend itself to like putting everything in the cloud.
So I actually think we are gonna see workloads move back and forth, I think for business continuity reasons, I think for scaling reasons, you'll see some folks go for the cost consistency of running infrastructure on-prem, but if they have a burst of traffic, they want the ability to, to, to go from effectively CapEx to opex dollars in order to meet business needs. So I think you'll see some of that for more static non movable workloads. I think it's, there'll be the cost benefit, um, i, you know, analysis for those particular workloads.
I think what's interesting is that the businesses are choosing to pay for both, like both the skillsets required to manage both of those, the security technology stacks required to secure both. I mean, they, they're fundamentally different tooling in a lot of ways. And it's interesting to me that the, the business choice is, well, it's worth it to manage security and manage operations in both of these areas if that's cheaper than paying the cloud tax for everything.
Or they, or they, so they believe, So the survey covers a lot of ground. So what else leaped out at you in this survey as you kind of walked through it a little bit? Is there anything else that you go, wow, just didn't think I'd see that either?
I mean, I think that was the biggest surprise. Most of the rest of it was, I, like, I felt like it, it was on trend for like, you know, folks that are moving into the cloud, but now we're thinking about the financial part of it a little bit more. Um, what was, but that was that, that took me aback because I honestly didn't think we would see that pendulum swing for, for quite some time.
And so I, you know, I wonder how folks are gonna operationalize this across their business. You know, the, the, the people who are skilled at operate in cloud infrastructure might not be network engineers that can run things on prem. So how, like, how the, the blend of what your operations teams and frankly what your security teams and what tech you buy is g is gonna be the, the interesting outcome.
I think here, Of course we have a shortage of cybersecurity skills and we have an even greater shortage of people who know the cloud and cybersecurity. So how will we kind of address all this hybrid cloud computing environments with the lack of resources we currently are struggling with? Um, well, uh, there's a bunch of, I'm we're hoping for automation, right?
Like that is, that's been the, the, the great equalizer for DevOps and network operations for the years. Um, so I think you'll see some of that in security. I think you'll see outsourcing, um, I think you'll see the tooling consolidate.
You know, there's a lot of point products in the security market right now, and you'll start to see some, some platform plays start to emerge in the market. Um, certainly vendors like us will, will help customers make those journeys and help them with their workloads regardless of whether they put them on-prem or put them in the cloud. And I think, you know, or they choose to use agnostic technologies like Kubernetes, like I think that will there be demand for that?
Because hiring all of the people that you need to manage that is not a, it's not a sustainable thing for a lot of businesses. Like even if you could find the people, the cost is hot. You cannot walk down the street without somebody telling you about their great new AI thing.
Will AI in this case save us from ourselves? Um, I think, you know, there's been a lot of chatter around this I think where I net out is AI's a dual use technology like every other. Um, it, you know, it, it brings, uh, it brings, it advantages to the defender, um, and it brings significant advantages to the attackers, both.
I think in the short term, it'll bring advantages to the attacker, but in the long run, it brings more advantages to the defender. You can view more logs, you can cover more surface, you can, you can, uh, build detections and response capabilities automatically. Like there's a, there's a bunch of advantages if you're sitting on the pile of response data that, that most security teams are.
But it might be a while before the, the dream is realized, so to speak. And I think in the short term, it might favor the attackers. Right?
So what's your best advice to folks who are, you know, clearly dealing with an expanded attack surface? I mean, it's the cloud, it's on premise stuff's moving to the network edge. How do we cope?
Find vendors you can partner with. Find, um, like make sure that you're making business and risk decisions about what, what workloads you put where like it's, it's not a one size fit all. Like, carefully look at what's in this workload, what's it doing, how fast is it changing?
And then decide, you know, what security controls it requires. And then you can make better decisions about where it needs to, where it needs to live. It should be, it should be a, a, a combination of sort of a financial security and an operational decision.
That's, you gotta look at it that way. And there's plenty of vendors, um, that are out there that are, that are willing to help you. All right, folks, you heard to hear much like the workloads, the security needs to be fit for purpose.
So you need to figure out what to do when and where, based on the risk and the type of workload that's running, and also what hardware it's on. In some ways things never change. It is just, there's a lot more of these decisions to be made.
Hey Greg, thanks for being on the show. Thank you so much for having me. All right, back to you guys in the studio.
Discover the cutting edge insights of our new show, AI Times a series that explores the limitless potential of artificial intelligence sponsored by the AI Infrastructure Alliance. The AI Times is at the forefront of the AI revolution, tackling the crucial questions of how we can leverage AI for the betterment of humanity. Stay ahead of the curve as this show delves into all things surrounding ai, including trends, pressing concerns, and the positive impact AI is making around the globe AI times.
Hello, I'm Amanda Ani with techstrong ai. I'm excited to be here today with Jeremy Shapiro. He is the founder and facilitator of Bay Area Mastermind.
How are you doing today? I'm doing great, Amanda. Thanks so much for having me.
Glad to have you on our show. So the topic of the day is the transformative role of AI in the enterprise. And Jeremy, I'm gonna start with my first question, which is, how can AI serve as a tool, a support tool rather than a competitor and enhance productivity in the enterprise?
That's a great question. I think there's been a lot of headlines and conversations as of late about AI taking away jobs and AI replacing and AI is transformative. But really where I've seen firsthand with our clients and within our mastermind community, what I've seen is that AI is supporting businesses.
And especially when we're talking about some of the more creative or production related tasks within a business, AI is there to help get rid of the blank slate. So instead of someone in marketing or someone you know, in design looking and saying, gee, what should we do? You can get really helpful prompts, you can get really helpful, uh, research and insights to make that writing in that creativity side of things much easier.
AI has also historically been really helpful on the automation side, but where there's been a movement in industry over the decades to automate more, it was still always up to a person to decide, gee, what should we automate? And we're seeing AI assist more in terms of the suggesting or automatic creation of automations you might have in business. It certainly is making things more efficient across many sectors and the automation level you brought up.
But I have a question as far as when it comes to the implementation phase, what is the starting point for business leaders? Because that's a huge undertaking. So what is your Advice?
So we are lucky that so many tools have become more freely accessible, easy to access and play with, and there are some cautions around that to have. But the barrier to entry, if we look, you know, over the past five, 10 years to today, anybody can quickly get going, whether it's, you know, again on the marketing side or your software developers or your C-suite execs can jump in and start playing with AI to see some of the transformative ways it can help us out and support our team, our customers and and our business. Overall, how Do you suggest that business leaders handle some of the, um, buck back from employees that are not on board with utilizing AI just yet?
Yeah, so again, this is an area where having, having it be accessible to the team in a non-threatening way is really great, right? So you can show value more easily, you know, without tremendous cost and time investment and the way it can help out your team. So for example, we've, you know, one of our clients and mastermind members within his business had some avatar work that was being done in terms of defining your customer avatar, right?
And all of our CMOs and marketing folks know what I'm talking about there, right? The better you know who your customer is, especially if you're launching a new product line or new division, the better you can speak to that avatar. So we all have ideas of who that avatar is, and we have our preconceived notions, but leveraging AI to say, Hey, give me a counterpoint to this, right?
Tell me more about this avatar and what am I missing? And help me to challenge the avatar I've created gives you a really well-rounded perspective. And so George was able to use this to get a much better idea of what his avatar was and wasn't what was motivating, what was, you know, what the fears were, the concerns were and where the opportunities were.
And that allowed the creation of a much better, much more targeted copy than could normally be done by a marketing team or creative writer on their own. And so that's just one of the ways that AI was able to assist and support versus replace within the team. Absolutely.
So another question I have is, there are many concerns about the security of AI and the many flaws that exist currently, such as bias or hallucinations, et cetera. So how do companies address these situations and what do you think is in store for AI as far as regulations and governance? Yeah, that's a really good question.
And you know, we've seen over the past number of years a lot of vocal voices sharing about some of the controls and things we need to put into place, right? And those are reasonable, and we should be having that conversation in terms of how, what we do on a day-to-day basis. With that, we've gotta keep in mind that AI is being trained on the data put into it.
So just like anything garbage and garbage out, we need to be mindful that we don't just ship the output of whatever AI says. You know, just the other day, you, we are working with AI again in terms of content generation and research for, for some content we're writing. And so we asked the question about some, some very specific marketing stats, but also asked to cite the sources, right?
And so this was a rather simple prompt, and we got back some fantastic stats. We were, we were able to use along with really good sources from publications we know and love. And wouldn't, you know what those URLs were like all made up falsified URLs.
None of them were actually valid, but like, they looked good and they looked convincing. But until you actually peel back the layer of the onion and go back a few levels, you would think this is all great. So we've seen oftentimes output can be good, but it may not have the voice of the brand, right.
Output can be good, but it may not actually be based in fact. So really where we've seen success again in using AI not to replace, but to support is taking the content that's generated or the output, but still having people look at it and use it and fact check it and make sure it's, you know, it's on point, it's on brand and it's, it's factually correct, but it's a really good jumping off point That human element is still very important. It enterprise is not at a point yet to where they can just say, AI, go run with it.
So Exactly. What are some particular roadblocks that you have seen business leaders experience in the AI implementation phase? So again, there's so many ways we can use AI within the business.
A lot of the businesses that we work with within the Bay Area masterminds, the AI is being used from, is being used for marketing, for content creation, for research, for support. In that regard, we're talking a totally different conversation If we're, if we're saying from a technology standpoint, integrating AI within your technology, a little outta scope of what we're talking about here. So with within that context, from a roadblock standpoint, it used to be getting started was a challenge.
That roadblock is gone. Now any business can start playing with AI out of the box, but where we've seen is not knowing how to prompt or how to ask the right questions to get an answer that would be valuable. And so that's why we've seen the, the creation of all these roles for people who have knowledge of that and are able to interface and put in the right prompts to get the right data back out.
The second roadblock we've seen is assuming that whatever output comes out can just be used, right? And so it can take some massaging and some nuance. And so a roadblock that we've often seen is this assumption I could just use what comes out.
And then usually you quickly learn, well, hold on, I've gotta take the output, work with it and make sure it's on brand, it's on message, it's factually correct, and that is what we want, right? We've seen companies start to integrate AI far more into their own products for us and users just the other day, for example, using Google Slides, there's the option to have Google Slides create images and graphics to your slides, which is like a really great application of making AI accessible to an end user in a product. However, you look at, you know, what of what of the output is actually usable that you put in a slide deck.
Well, that's, that's a, a bit of a different story. And is it your own original work? Not really.
I appreciate you sharing some use cases. There are so many it seems like, and really across any sector. So if there's one key takeaway you'd like for our audience to have today, what is that when it comes to ai?
Yeah. So AI is not here to replace your team and get rid of jobs. It's here to support your team and help 'em to do a better job, right?
You can look at the, at the medical space, we're not yet at the point where we want AI completely handling everything, but to have AI spot things a human might not where a human can then check it. But we're not replacing jobs. We're allowing our humans to do a more efficient and more effective job with support that doesn't get tired and is able to spot things that we might not.
So a key takeaway, a AI is not here to replace, it's here to support. And what we're seeing at the Bay Area Mastermind with our members is that AI is helping to get rid of the blank slated paper and is here to help challenge assumptions and is here to support creativity. Absolutely.
Well, thank you so much Jeremy, for coming on our show and sharing your insights. Absolutely. Thanks for having me, Amanda.
Hello, I'm Amanda Ani with digital C X O, and I'm excited to be here today with JR Sherman. He is the c e O of Rain Focus. How are you?
Great. Thanks for having me, Amanda. Excited to be here.
Glad to have you. Can you share a little bit about Rain Focus and the services you provide? Yes, absolutely.
Uh, just briefly speaking, uh, I've been in the event industry from a services and then software perspective for 25 plus years. Uh, I believe in it, I believe this is the most powerful channel for driving relationships in B two B and B two C. So just been passionate about it forever and, uh, rain Focus really came about through all that experience because we knew we had to build a platform correctly from the ground up that could help organizations to manage their entire portfolio of events from virtual to physical large and complex, to very simple in a single platform.
And really with the objective to simplify the integration into MarTech and to create more seamless journeys for our customers customers as they interact with those brands. So, uh, rain Focus is just that. It is a top to bottom event management platform that's designed to capture all the behavioral insights, uh, from events of all types around the world and feed it into the, uh, the systems, the CDPs, the marketing tech, the c r m systems of our clients and create better customer journeys.
Great. Well, that's a good segue into our topic today, which is consumer behaviors. So why is it critical for business leaders to better understand real-time consumer behaviors online?
Yeah, I think, I think probably everyone will, will feel this. Um, there is just an ever increasing amount of signal coming in and hitting us both as a consumer and as a business buyer, business solutions buyer. Uh, the signal is increasing, it's everywhere.
And if organizations aren't kind of taking advantage of both technology and relationships to better understand me, the messages can be lost in the signal and what is actually what I'm looking for can be lost in, in that signal as well. So I just think it's very important for organizations to leverage technologies, but really to get real time insights on preferences and inclination on what, where I am in the buying cycle or decision process, because that can be the difference to capture my attention. Got it.
So how can businesses harness consumer data and ensure they have clean and updated data for effective decision making? Yeah, so the, uh, I think that's a great question, Amanda. There are so many, you know, just like we said, there's a lot of signal hitting consumers and, and business buyers out there.
There's this plethora of tech solutions, and it's ever increasing as well. Everything can be automated. There's new SaaS offerings for just about everything.
But I think, you know, I'll probably repeat this as we talk today, I'd imagine, but I just kind of always go back to the idea that we need to maintain the customer at the center of all the technology decisions that we make as organizations as opposed to the technologies function itself or the purpose of that function. So it's not just about the event that you're running or the technology that just came out that's really cool. It's about the customer.
And as we are fed all of these, you know, new opportunities to implement technology, to build relationships, I think just keeping the customer at the center of that decision process and then implementing and testing the best technologies that can provide that customer the most real time personalized content. That's, that's the key. Just keep the customer at the center and then evaluate and test technologies that, that augment that relationship.
Absolutely. So what are the potential business consequences for companies if they miss important touch points in consumer behavior? Yeah.
Um, I thought you, you might ask that, and I, I always just have this example that I think about in, in that, but I think what it, what can happen is you can actually create a detractor, right? And, and why I say that is, you know, whether it's some of the, the platforms out there that listen to you over your phone, um, or some of the AI that's out there that's just capturing random clicks. If you're making just technology, do the decision making about what my interests are without any thought behind that, um, you can really create a detractor.
And the example I use is riding in the car talking about, you know, uh, my friend's mountain bike, um, because something broke on it and I have no interest in mountain biking. Um, all of a sudden I'm getting hit with Mountain Vik ads, right? Really creates a detractor for me of those brands, right?
And they probably don't want to be, they, they would love to, you know, not bother me, but the technology that they've deployed is simply taking advantage of something out of context and applying it to me in a basically very unintelligent personalization, um, deployment. So I just think if, if you're not keeping the center, you know, the customer at the center and you're not really making smart informed technology decisions in real time, then you can almost create a detractor the exact opposite of what you would want, right? So that, that's what I would say is just that can be one of the big consequences.
Got it. So do you have some examples of businesses that digitally transform their data processes well and solve measurable results? Yeah, sure.
Um, I think, um, I'll, I'll give just a preface to that and say, you know what, look, I'm in the events industry and, and I, I, like I said, I'm passionate about it. I believe it, it's what builds and grows relationships. But, um, the, the two and a half year pandemic period that drove events to an online environment really awakened a lot of organizations and functions and organizations to the power of events themselves.
So, um, all of a sudden they realized these crazy things that took place at the Moscone Center. They were online, they said, wow, I, I get it now. Really great content is created.
Um, and then we have customers and we're matching content with customers and we're providing a captive environment to do that. Well, yes, it was online for a little bit, so digital marketers could understand it over that period, and it's moved back now to physical. Nonetheless, there is this heightened awareness of the importance of tracking customer preferences and behaviors to give better personalization in real time.
So, um, really the almost every customer we're working with is at some phase in the process of digital transformation, including the event channel. And that's both physical and virtual. There's no reason nowadays to treat physical events any different than virtual in capturing real-time behavioral insights from those, those interactions.
And I would use I b m as an excellent example. Uh, when, when we were brought into, uh, I B M, they had probably countless, uh, technology solutions being deployed around the world with their teams to execute events. Uh, those could be webinars, they could have been online or they could have been, uh, small meetings or breakfast meetings or conferences or seminar tours that were live.
Um, and the transformation that took place there was moving all of those event experiences onto the Rain focus platform so that we could create a single point of integration back to their C D P, back to their MarTech and have one data instance, we call it the global attendee. Whether that customer attends one or 50 different experiences with I B M, they're seen as one record, and that record is in constant contact, uh, with IBM's master record on that customer. That in and of itself had tremendous r o i for, you know, I B m and being able to understand preferences in real time, and then not just think of events versus digital marketing, but think of them all as assets that can be delivered at the right time for a customer in their journey.
It might be digital now that might push or, or show that there might be some great content at a physical meeting or conference. And out of that, we see that some other digital content is relevant. So transformation for us really meant merging both the entire event channel and digital marketing into a set of assets and technology that could deliver the right content to a customer in their buying cycle or their journey with your brand.
Uh, and like I said, all of our customers are at some phase of that. Um, and you know, I, I just, I think of I B M because of the vast amount, thousands and thousands of events per year mm-hmm. Is a great example of being able to take a very large volume and still achieve that goal of, of bringing all of that, that content, digital and physical together.
Absolutely. Thanks for the example. So what role does experimentation play in the d n A of businesses in the context of digital transformation?
Uh, I think it's, I think it's fantastic. I, I would, I think I said I was gonna do this, but I'll, I'll harken back to that. Um, if you're going to look into a new technology, um, a new offering, um, a new automation tool or something like ai, I think it's very important again, to check yourself for a moment and say, am I keeping my customer at the center of this decision?
And in doing so, am I going to experiment and test with the this technology as to how it improves my relationship with this customer and helps me grow it? Or am I simply racing the implemented technology because it's all the rage right now and I've gotta figure out how to get it integrated? Um, I would say that's the most powerful thing, uh, to do as you evaluate some of these things coming out and you're testing them.
Um, and we see testing and experimentation both on the digital side and on the event channel, um, frequently. And I think it's important to compartmentalize that, that testing or experimentation so that you can actually see an ab difference in what its impact and attribution is for r O I on that, as opposed to just rolling it out completely across everything. And then assuming that you have some relevant basis for R o I, so, uh, keep the customer at the center of the decision experiment in a compartmentalized fashion.
So you can really check attribution in R o I, I know we're hearing about AI a lot these days and also starting to hear a lot about VR and AR as well. Yeah, for sure. Um, this is something, you know, it, it, it is definitely not, um, something we can just compare to things in the past.
Um, I remember in the banking crash in oh 7, 0 8 and the whole event world was gonna go virtual. Um, and then we saw that again, you know, in 20 20 20 and, and through 22. But I think at the end of the day, um, when we see trends like this, and I do think AI is something much more real than AR and, and VR in the ability to help, you know, businesses that are B two C or B two B grow their relationships, AI is gonna play probably a more long-term significant role than some of those others.
But I do think it is really about being, again, keeping the customer at the center, but also kind of testing or experimenting like, like you were asking about before with those technologies. There's some great ways to, um, implement, uh, AI right now. We, we do it within the event channel.
It can be as simple as the ability to help create synopsis or summaries of content that are personalized to somebody. It can be a great way to search, you know, terabytes of video, uh, on demand sessions for relevant terms and words and create a list of relevant sessions. So it helps us with generating personalized recommendations on content.
Um, it can do moderation of chat, so there's some great ways to deploy it where you have to kind of be careful with something like AI is, is understanding, you know, personal information, protecting your ip, uh, and racing to deploy something like AI too quickly could cause a lot of damage there, right? Because there is a human aspect. AI and generative AI are based on existing content, so we have to be careful that it's not grabbing something that's already error prone or incorrect and incorporating it into a broader deployment.
So I do think there is still very much a human aspect to checking, testing and experimenting with something even like AI and VR and ar, um, I think are are very cool. Um, but you know, as much as we love to incorporate those into the event channel, um, we, we see a limited, um, impact in helping expand business relationships or grow relationships so much as it's more of a cool factor for helping generate interest at the top of the funnel, we might say. But, uh, it really is live interaction that that helps businesses and, and relationships get get established.
So, uh, always looking for cool ways to deploy VR and ar, but uh, face-to-face is, is just, I think human nature drives the need for people to see each other. Got it. So a little bit more of a technical question.
How does the infusion of contextualized data into Tech Stacks contribute to bolstering brands customer data profiles? Oh, that's, uh, I think that's something that we actually talk about with customers quite a bit, and it, it can be very eye-opening. Um, I'll give a very simple example of how I view contextualization of, of data.
Um, many times when we lay out for a customer what it means for somebody to have attended six sessions at a conference versus they opened an email, clicked on a link and downloaded a P D F white paper, um, we do it from the context of the amount of time, money and commitment spent by a customer to block out time, travel to a conference, whether it's local or flying, and then take literally hours if not days of their time and dedicate it to consuming content and networking in your captive environment. The context of that has to be applied in understanding that, um, preference or inclination for the customer versus the seconds or at most minutes spent clicking on a pop-up ad or opening an email and downloading a white paper. So contextualization many times has to do with understanding the commitment level and the engagement level required for a consumer or a customer to engage with content as opposed to just the fact that they did it or what that content was.
So, um, that's why I think it's very important as we think about engagement being a measure of interest and preferences, we have to understand what it took for the customer so it gets a higher rating or a higher score or a weight, right, for the fact that they took that time and made that journey and, and engaged that much versus clicking. So I think if we weight those, it helps us understand where in a customer journey, physical engagement or digital content are more helpful for that customer in making their buying decision. And that's that constant learning that we do, um, to understand how to make those journeys as personalized but efficient as possible for customers.
Got it. So you already touched on some technologies, but what are some emerging technologies that can help businesses simplify the collection, sorting and analysis of data sets? Uh, yeah, I'll, I'll, I'll focus on one that I think is really super important right now, and that is the C D p, right?
The customer data profile that, that organizations are evaluating, uh, from most major players, right? We've got, uh, Microsoft, Adobe, Salesforce, Oracle, they've all got CDPs. Um, and many people say, so what is this C D P?
Um, we believe that not only is the C D P critical, but being the event channel aggregator and being able to pull all event data into a single platform at Rain Focus, we believe that merging that data with A C D P can be the tipping point for really what we call omni-channel marketing. And what that means is, currently if you speak with, let's just say an enterprise B two B organization, they have a number of digital marketing tools and techniques and campaigns that they run. They have physical events and virtual events, and they have all types of engagement and web engagement and social, and in many cases, those organizations are relying on those individual tools to provide reporting data insights and attribution.
And then they're required to pull that from each of those different tools and understand which ones are maybe performing best. I would call that ability to do that, which is not easy, multi-channel marketing. That means that I'm leveraging a number of digital and physical ways to engage with customers, and I am pulling data from all of them and doing my best to, to attribute the movement of a customer through their buying journey to each of those different tactics.
What the C D P provides is a central place for all of that data to be housed and grown on an individual customer or account. So that C D P is pulling the data from all of those different campaigns and all of those different tools, digital and physical events and rain focus. If you think of us having all the event data into that C D P and the C D P helps you do a better job of exactly that.
Let's do not just attribution, but proactively understand and recommend what paths are best for a customer in their journey on a decision process. Um, so I think that is something that continues to emerge. There's a number of them out there, and depending what organizations are trying to achieve or how complex their sales and marketing campaigns are, there are different ones that might match their need.
But, um, I do think as organizations face this potential cookie list future and zero in first party data being very hard to capture, again, events, um, be they physical or virtual, uh, face-to-face will become a critical and definitely the largest source of zero in first party data. And that being the case, I think having a C D P in place allows you to take all of that data, joined with what you already know about customers and maybe learning through the digital marketing process. And again, all of this that we're talking about is just to provide more efficient, valuable customer journeys, um, to our clients' customers.
Um, C D P is something that I think everybody should probably be looking into, especially if they have complex, uh, MarTech stacks and, and campaigns. Definitely sounds like it simplifies the process and is much more efficient. So last question.
As more businesses move services online and digitally transform their operations, what are the key issues and pit pitfalls you're seeing business leaders need to be aware of? Um, I, you know, I would say Amanda, it's kind of like a summary of, of what we were talking about here because it, the ability to really understand your customers, meaning their preferences, their inclinations, and how they like to consume content from you and how they make decisions. Um, you, you really need to put them at the center of it.
And so you can't fake it, I guess is what I would say, right? You can't leave it just to some technology that you put in place and expect that technology to go learn about your customers and then make recommendations to them. There is a human process to all of this, for the same reason face-to-face events came back as fast as it did.
Um, I think human nature drives a lot of what we do in marketing and sales because it is about relationships. So behind all of the technology that you deploy or you test or experiment with, I think it's very important to put the human touch into it and to make sure that whatever you're testing or deploying is really enhancing in some way that customer's experience with your brand and maybe helping them make decisions in a more efficient process. Um, because the, the pitfalls are leaving too much to the technology, uh, and not putting the human touch behind it.
Um, it would be like just putting a whole bunch of virtual content out there, um, on demand and expecting customers to come find it and make decisions and buy your product versus all of the human touch we put behind creating experiences and personalized customer journeys. Um, it's the same. So I would say just keep the customer at the center, um, and don't depend too much on the technology to, to understand your customer's preferences.
Just kind of keep an eye on that and, uh, and help the technology create better journeys. Got it. Personalization is the key.
Yes. Well, thank you so much for coming on our show today and sharing your insights with us. My pleasure, Amanda.
It was great to be here. Thank you for, for talking with me. Thank you.
Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud Native now.
Hi again, everyone. Hope you all enjoyed today's episode of Techstrong tv. We had an amazing set of interviews with industry professionals to give you the inside scoop into the tech world.
We'll be back again on Thursday, so we hope to see you then. In the meantime though, if you want more tech strong TV content, be sure to check out some of our podcasts or download our mobile app. Thank you so much for watching and I hope you have a wonderful rest of your day.
As always, stay strong. Text strong.