Techstrong TV September 8, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everybody. Are you feeling insecure about your Salesforce apps? You're not alone, you're watching Textron.
Hey, everybody, welcome to show. We got an awesome lineup. Once again, our friends, Mitch Ashley, Tracy Reagan, guy Courier, Jack Poller, and we're talking about all kinds of fun stuff.
And let's jump right in with Salesforce and this whole security issue, as I understand it, it's kind of complicated as following, but, um, a company called Sales Loft, which provides an integration engine and apps to plug in into Salesforce, bought something called Drift ai Drift. AI turns out had some, uh, issues with authentication and credentials, and now everybody's waking up one morning and discovered that their Salesforce platforms have been hacked. Jack, I know I grossly oversimplified that, but kind of walk us through what's happened here, and is this something we should expect more of?
Yes and yes. This is really ugly and complicated. So you Sales Loft, which is not Salesforce Sales Loft, has an app called Drift.
It's an AI chat bot that does realtime scoring of interactions, uh, to help people, uh, qualify leads this. The Salesforce Sales Loft app is connected to Salesforce through an OAuth token. And so every user of every company that implements SalesLoft Drift, gets an OAuth token to connect to their Salesforce instance.
Apparently, the sales loft drift environment was compromised. It's unclear how, whether that was phishing, phishing or, uh, another attack. But as part of that attack, the attackers got access to the OAuth tokens that Drift uses to authenticate to Salesforce, that let the attackers directly access the company's Salesforce instances to acquire and download and extract the data stored in Salesforce.
So that's sort of the attack itself. The outcome of this is being portrayed as really a SaaS issue and a supply chain issue. And it is, but there's some more fundamental security problems that we need to talk about here.
As you noted, this is really an identity issue. An identity authentication issue is the organizations were originally compromised through a phishing attack. At least that's what we believe today.
This reinforces what I've been saying for a long time now, is a lot of organizations are worried about network security and, uh, zero day attacks and those types of more exotic or more, um, let's say press worthy type things, whereas most organizations today are leaving their front door wide open with having very insecure authentication policies, not implementing F-F-M-F-A, not implementing password lists, um, and not doing adequate training. Uh, and apparently, again, like some other recent attacks, this attack was targeted at the, uh, organization's, uh, customer support arm, not the main body of the organization. And it appears that, uh, many companies are giving their customer support portals and their customers employed employees, which may often be third party contractors.
They're not giving them the same level of security attention or training. So, you know, that's, that's a big issue, right? Yeah, that's a scary, it's a kind of, when you use OAuth often, right?
We're not talking about a token theft is the worst case scenario. It really is, because I don't even know how you would implement, you know, multifactor in, uh, a workflow. Now we're talking about SalesLoft and Drift and, and, uh, and Salesforce, but this is all stuff that's automated on the back end, so that's why it's harder to to, to secure it.
But this impacts a lot of different structures. I mean, I go back to my DevOps, we, OAuth is used across DevOps pipelines. It's used in platform engineering.
It's used in medical records, transferring data across, uh, you know, from from one doctor to the next. It's, it's out there, it's used a lot, and there's no worse kind of threat than an oof token theft. And that's what it is.
It stole the token. So once it stills the token, it's good to go. It's, it's, it's a bad, bad problem.
Um, and I have no idea how we're gonna look at it and fix it across so many different industries and address these things in a timely matter. Well, and, and one of the issues, lemme just pipe in real quickly, Mike. One of the issues is that we're not treating OAuth tokens as secrets the way we do other secrets.
Any secret that you have should be stored in a hardware security module in HSM, which is essentially a write once read never device that you cannot extract the OAuth token from again. And if we do that, that goes a long way towards securing our oath off environment. It's not a, it's not a silver bullet cure, it's not the only thing we need to do, but that would really help a lot, Mitch, is this one of those teachable moments that we always look for?
Or are we just gonna ignore all this? I mean, you know, we'll, in, in a couple of months we'll be able to say to people, Hey, don't pull a sales loft, and they'll know what we mean. You mean, uh, shame on me once, shame on knew twice, or whatever the phrase is.
Right? Of course, this will happen again. I think pull me Once.
Yeah. Yeah. I don't remember the phrase.
Thanks. You, you know, it points to how vulnerable you are to, to trace's issue if you can get in and Jack too, if you can get in at the authentication step somewhere in the identity and authentication part of this. It's, it's a akin to getting the, you know, root password to a, to a server in some ways.
I mean, you've got that user's, uh, authentication or their, uh, access controls into whatever systems that they're using. And it's very common to use OAuth and, and other forms of this matter. Fact, OAuth is very, very popular today.
I think. I think it's part of, it has to be viewed more as part of the security stack, not just part of the software stack. And, you know, I think when you turn folks loose, like Jack as a security engineer saying, you know, are we properly secured?
Are we stor storing our tokens appropriately? Do we have the controls in place around this as opposed to, great, here's an API call this API, you'll get this back. Let's move on.
We're all good. Reminds me of when I was in the, um, certificate business, a business for, um, let's call 'em entertainment devices, things that are, are in your home. And people would email me back and say, I got this public.
I got this private key, and what am I supposed to do with it? I said, well throw that one away. 'cause I have to give you a different one since you sent it to me.
You know, don't, yeah. There's hygiene with this that you have to practice. Is it a teachable moment, meaning we won't happen, happen a year, happen again.
Uh, it'll happen again. And, and be, and this gets noticed because it is such a broad access and can really bring down a lot of data lot. And I don't think was a, This wasn't a user, this was an application authentication, right?
Mm-hmm. App to app. Well, it's right, it's unclear.
It may have been a, it was originally, that's why I think is it was originally a user phishing attack that got them access to the Drift environment where they were able to then get tokens. Okay? Right.
So that's why I mentioned MFA is I believe that the, and, and it's not clear because everybody's focusing on the blast radius that this impacted Salesforce and people were able to extract Salesforce stuff, but the, or the original attack apparently was compromised users. But I feel like Tracy's question is the Radius radius. Let's, let's, let's, let's, I feel like Tracy's question is perspective is is the critical one though, because, uh, there's so much focus on, on, on user access and, and, and sort of the perimeter perimeter defense, all that sort of thing.
And, and I kind of wonder where Zero trust figures into all of this, because reading, uh, about this incident, and this story wasn't directly about zero trust, but, um, it, it, it made me feel like zero trust is, I mean, we've always felt it's a bit of a misnomer, right? But more so here than, than than ever. I think it's, I'm a fan of zero trust from what I know.
It's a great concept. Um, but I think you have to keep in the back of your mind that, um, it, it, it's, it's a, it's an aspiration, not, not a reality. And, and the, and the way that I think of Tracy's question, you know, as being relevant here, is there's a lot of map access.
There's a whole supply chain of services and tools and lifecycle management and all that other sort of stuff. And if you're really doing zero trust, you're assuming that any point along the way is not tru not can't be trusted. Um, but I, I think there's so much focus on things like user access and millennial and or AI access, but not thinking in terms of those app connections.
Not as often, Mitch. I think that this is just one example of maybe hundreds of things that will happen, because it seems like the bad guys are viewing SaaS applications now as massive honeypots, and they're looking for ways to get in there. And they're not looking to break in.
They're just looking to log in. And that's very difficult to fight against, even with zero trust, because, uh, somebody may have those credentials they've stolen, and as far as I know, they're a legitimate end user. And I don't know how we combat this.
It's kind of path of least resistance, right? That's what and, and attacker is gonna take. And if going after your tokens for OAuth for an application or an end user, if it's susceptible, great, they're gonna grab that and run with it.
Especially if they see a major application like a Salesforce C-R-M-E-R-P system, whatever it might be, that they're gonna really gonna have goods in it, that they can leverage that data and sell that data. Um, I, I think, I think are we gonna see more of this? Yes.
Because we see more and more machine to machine identity and, and access. Yeah. Both a applications, Yeah.
We got M CCP to deal with now too. Pardon? Yes.
And, you know, um, we have MCP to deal with now too. That's, that just, that just exponentially grows the, That'll be fine. That won't be a problem.
No. Oh, okay. All right.
Now I feel better. Tracy, I just wanna point, I wanna point out how many, um, websites out there use SalesLoft and Drift and Salesforce there, and we used to, we had Salesforce connected in the backend. We had SalesLoft, uh, passing data.
We used Drift for our bots, and I started watching what was coming into our Salesforce account and a lot of garbage. And me being a little bit paranoid in a small company, I said, you know what? It's not, the bots are not worth the risk.
This was years ago. I'm not saying I, I had a vision that this would happen, but I, I could see the kind of phishing attacks that I was getting in my Salesforce based on, you know, who was trying to download stuff, and I could tell that they were out there, uh, trying to, to play with the bots. So I, this is not a new thing.
I don't believe it's a new thing. So maybe the, the answer to this is be careful what you decide to throw out to the general public, because in those ca all of those ins in those cases, you didn't have to log onto the Deploy hub website. You just had to interact with the Deploy hub website for the bots to come up.
And it was the bots that were, uh, and I, I believe in this case, it was the bots that, uh, the tokens were stolen from. So nobody logged in. They're just out there talking to our website and looking for forms to fill out, to try to see if they can break in.
And sometimes you gotta look at the data, right? So the difference, Tracy, when you're a small company versus a bigger company, is that in a bigger company, there's gonna be somebody whose whole job, or half of their job is implementing tools like Drift, and they're gonna be reporting on the success of Drift using metrics that'll say things like this many interactions, this many this, this many that. And so there's this kinda layer where the expert is not necessarily, is not self-evaluating in particular, I'm gonna keep my job and get promoted because I showed that our drift usage grew like this, and our efficiency went like this and all this stuff in some report.
And then someone else looking at it is just like, wow, that's great, right? That's why lead generation or demand generation organizations in big companies can throw through lots of junket sales and never get really like, ding for it. So, you know, there's this, there's this, uh, uh, issue in larger companies where this sort of vulnerability seems to need to be greater.
It would seem to me at least that as we get more bots going, we need to be wary of what they're doing. Because every time you open up those things, to Tracy's point, you're creating an avenue for phishing attacks. Is that not the case, Mitch?
Well, the, yeah, the more vectors, the more open it is to attack, no doubt. And, and if these things aren't closed down, you know, that's the more, the more it happens, I think there's more opportunity for people to learn from it, like you were asking about earlier, and people will start to be, take it more seriously. You, you would think.
But then again, there's always, you know, guy brought up the great question. What about the mid-tier? What about the small company who don't have the security resources, but are still trying to use, use mps, MCP servers or, or accessing SaaS applications?
Um, so security has gotta get easier for folks to lock these environments down, which creates opportunities for security companies. Alright? Sadly, we're gonna be talking about this issue more.
There's gonna be more of these incidents going forward, and, um, I got a bad feeling that the only way we're gonna learn about this is the hard way. But hey, everybody, at least you heard something about it here. First 'cause to be forewarned is to be forearmed.
We'll be back in a minute. Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're moving on to our next topic, which is Atlassian bought a company called The Browser Company for I think 610 million.
And the idea here, I guess is that they want access to what will be AI browser technology that they will embed inside their applications and their workflows. And Guy, when I saw this, it reminded me of an old debate that's been going on for a long time about, you know, why are we using all these consumer grade browsers inside our enterprise apps? And, uh, but we never seem to move off them, and we keep using them no matter what.
And we've had enterprise class browsers forever, and adoption rates are minimal. Um, is this gonna be, you know, the beginning of something different here, or is this just, you know, uh, somebody making a hope for 610 million? Oh, an easy question.
It's somebody making hope for 610 million. Shall we move to the next block? Wait, Wait.
Lead to witness there, Mike. Come on. So look, um, first of all, um, arc, um, I haven't used dia, which is the browser company's other, uh, browser.
I'll get to that. Arc is a really cool browser. Um, a real focus on the user experience and, um, a front end, obviously to SaaS like Atlassian produces Atlassian produces software, SaaS, um, for the developer community.
Um, uh, you, you know, it's many parts and forms. Um, and, uh, our friend and leader of this pod, um, uh, Alan Shimmel wrote a great column, uh, about the acquisition, where he made the basic point that if you are on essentially a web application SaaS company, um, which is every, every software company is now, um, why wouldn't you want to own the final mile? Uh, you would.
Um, but your point is a really good one, Mike. Um, so let me ask you a question. Why is everybody still using whatever it's Chrome.
Why is everybody still using Chrome? Let's, let's just stick to that. Why?
Well, because the machine that I got came with, you know, two choices, and so I picked one, Right? Right. And you picked the one that's the cool one, or that the one everybody knows, or the one you're familiar with, or whatever it is.
I think that the, um, the, the, as long as, um, Atlassian, let's just take Atlass as long as it Atlassian suite is gonna be available in any browser, which presumably it will be, um, otherwise we're going back to the days of Citrix where, you know, Atlassian, you have to, you know, install the, uh, their particular client reuse it. I don't think they're gonna do that. Um, are they gonna do something where the experience is so much better?
If you use Arc D. Now, DIA is a radically simplified interface that still allows you to browse, but with, uh, the use of ai, so it's like an AI chat where you get to browse, instead of having to poke around to click here, click that, do a search, and all that other sort of stuff. The AI acts like sort of an agent for you to help you do it.
This is all great, this is innovation in the user experience. It's fantastic Love. A sure is, you know, uh, built along similar lines.
Um, but 610 million for this one, one can't help but think that the whole idea is, like Alan said, to own the entire software experience and to end. I just don't see how they're gonna impose that control on the client's side just because it's an enterprise. But just because everybody says to all these developers who all have their own opinions, obviously, um, go use this every time you want to use Jira.
You know, you go open this other piece of software instead of just doing it integrated in, in Chrome like you've always done. That's where I think, um, uh, the, the questions still lie now, Atlassian very smart company, and I am, uh, a famous, at least in my own mind, for not understanding things that become clear to OB and obvious to everybody later. But that's my initial take, which is, it's, it's, it's an effort to improve the user experience, the developer experience, which is Atlassian's core, um, value proposition to the market.
But I think there's a lot of friction that they're up against here, and I'm not sure how they'd solve that. Mm-hmm. This kind of reminds me of a ca purchase back in the day.
Ca I used to, we used to say they're not superior by design. They were superior by acquisition. Mm-hmm.
Um, and Atlassian's got a big enterprise customer base, which probably, I don't know, 250,000 plus something like that. That's kind of how ca built tools that none of the rest of us would ever use. But they sold into the, specifically to the enterprise customer, the Mainframe mainframe customer specifically.
Yeah. Go on Mainframe customers. But they spread out quite, quite well into networking into DevOps for quite some time by acquiring companies, right?
And it feels like to me that they're looking at selling this into the enterprise accounts, and I bet it has some security on the back end of it that they're interested in, that they'll probably do quite well selling this into those enterprise accounts. And when you get a, when you have a giant list of customers like that, that are enterprise, you don't look at, you don't really worry about selling to the masses. You worry about selling to those enterprise customers and giving them new, new stuff to buy.
'cause you've got a book and you wanna sell everything in the book. I was actually just talking with Atlassian this morning about this and some other things. First of all, uh, Atlassian is one of those companies that has a very, very solid ethos.
You know, we talk about culture, and then there's ethos, right? You, it is a certain way. They have a definite model of how they do business, and they're not a roll up company.
You know, let's go buy a bunch of companies and roll it up and, you know, try to make them work together. They're very intentional about doing this. And their CEO Mike is, is, is pretty brilliant business person.
Now, it tends to put Atlassian on its own path compared to other companies. But I think there's, there's a way to look at this as both a offenses offense and a defensive move. I don't think it's to become the next chrome.
Maybe that's what could happen. Now, like you were saying, Mike, that's, that's a big nut to crack, right? You're gonna go after that.
Good luck. On the other hand, if you look at what's happening in the, in the AI browser space, there's many people that think that the current web browser, you know, Google's working on how do I transform from doing Google searches to doing Gemini searches? Well, there's much more layers past that or steps past that.
When you think about AI and agents and workflows, because browsers are very passive things. They, they render information to you, you do some interaction with it through JavaScript, things that are running in the browser, uh, and, and other ways, but it's pretty much a passive experience. If you're working in an environment where, um, you're orchestrating, you're, you're having work orchestrated for you.
Agents are running and doing things. You're having information put into LLMs and brought back and something else done with it. If you think about these interactive workflows, which is what rode the VO platform, the Atlassian platform is about, is taking not an AI plugged into something, but an AI platform plugged into all of the suite of applications that they have, and they've already done some nice work on this, it takes it to the next level.
So I think it's, it's one is they're not leaving their fate to the browser wars for other people to figure this out and either to win or lose based on somebody else's decisions. I think, I think they're taking the bull by the horns. And at a minimum, if that turns into radical chaos, they've got a structured good program going forward.
If you know something else or, or Google or something else, turns out, turns out to be the next best thing. Okay, great. Maybe they, you know, continue down the browser, company d that path until that.
But I think, I think it's a very strategic move. It's, it's a, um, sort of a wild card move, right? You don't think about that right off the bat.
Why would Atlassian wanna be a browser company? I don't think they think they wanna be a browser company. I think they want to be an enterprise apps company in an AI era, Tracy And productivity tool.
Yeah. Mm-hmm. Tracy, what, walk that through a little bit with me because I think Mitch may be onto something, but let's take it to the end degree, right?
What is the future UI gonna be for these applications? Is it gonna be something that is optimized specifically for AI agents rather than humans? And we just need a different interface to talk to the AI agents, which will probably be natural language or even voice soon.
So is the whole end user experience about the change? I think that what we're looking at in this particular scenario is a marriage between a browser and an IDE, right? It's, I believe it will become the next IDE for productivity in developing in an ai, uh, under an AI platform.
It may, you know, Tracy, you think about it from that per per perspective. It totally makes sense for it. Last in to go down this road.
Who owns the IDE today? Uh, Microsoft. Well, the biggest one is vs code code vs code from Microsoft, right?
Yeah. That's the thing is who owns the ID today? I mean, it's open source vs.
Code is the most widely used, but Yeah. And so is the Cliff, and then there's this whole i DP movement as well, so, right. But it is, so, so I think, uh, Mitch and Tracy, um, uh, I, I, I agree with Mike.
You're onto something here that didn't occur to me, which is, I, first of all, you know, I, I don't think anyone thought that, uh, you know, atlass is now gonna try and become the dominant browser, whatever, whatever it is, no matter how disruptive and innovative, um, ARC and DIA might be. But it's really helpful actually for them as a developer focused SaaS company to own and have a product development lifecycle and investment in a browser because of the way standards and norms are set in SaaS across everything, this gives them a foothold in that, that they didn't have before. They're more like, like knocking on the glass and looking and say, oh, can you please do this?
Can you please add this feature? Can we please add the security capability? Whatever it is here, they actually are gonna have a seat at the table because of the personnel and the history behind the browser company, as well as when you produce a freaking cool product, people wanna listen to you more.
I mean, Chrome and Chromium, I think made its name with, uh, true, truly, um, uh, breakthrough JavaScript, uh, hosting and, and, and, and capabilities. Um, and so this could be breakthrough AI capabilities, I don't know, or, or user interface or whatever. That actually makes a lot of sense to me that this is Atlassian's way of helping to have ownership in the development of SaaS broadly across the board.
Also, think about it, this also, I love your analogy, Tracy, of the IDE and meets browser, and, and I take your mention of ID is not literally, you know, BS code or something, but it's, it's taking the, the model we have of, of how we work today with AI is vastly broken because it's, we have the mode of, I'm gonna use a, a chat interface, right? Um, and we have some CLI tools for developers and things like that, but it's, it's natural language. Either spending all our time in that or taking existing applications and hanging sidecar an app, an AI functionality to be able to query your email or go look something up or whatever.
It's not integrated into the application that Log Jam's gotta break for AI to really become, um, essentially what, what we really can get the most out of ai. It's gotta be part of the applications, not, it's not an application. And so what's that user experience like?
And your, your analogy of the sort of the chocolate and the peanut butter, we get a Reese's Peanut butter cup. I think that's what they're hoping for, is the next Reese's peanut butter cup of user experience, um, in an AI workflow driven process world. Uh, and that's, it's A focus on their tooling with a focus on their tooling.
Mm-hmm. Yeah. Make sure there's another, there's another aspect to this, Jack.
There's another aspect to this as well, which is that this is not unusual for, you know, it's not an absurd dollar value for a browser, not at all, right? We've seen this with Signal, sorry, with, uh, island and some of the others. And you know, when we've talked about this in the past, I said, I don't understand why Microsoft and, uh, Google haven't looked at this and said, that's a business we can own, right?
Because they can make enterprise browsers and Secu add security to browsers pretty easily. And I think the answer is proving out to be that they're either not interested in that business or unable to in, to execute on that business. And there's a lot of other companies that are executing in this environment and are saying that the browser doesn't have to be just a passive part of the user experience.
Uh, Mitch, I think you said it renders, you know, traditionally it just renders information and I think there's, uh, people are looking at it and saying, there's an opportunity here for the browser to become more than just a passive part of the landscape. And I think that's, that's really interesting and exciting. Yeah, but I gotta, I gotta say again.
Um, so just to blend the two concepts, I agree with you, Jack, if these capabilities wind up commonly used across a lot of browsers, or in particular the Chrome browser itself, because the idea of Atlassian, um, or anyone going and saying, you're gonna get the best experience from our suite if you use this browser, that we're gonna give you a deal on it, it's gonna be this and this. We're gonna enable you and all this other sort stuff. I just need the, at the end of the day, the user's gotta go use it.
And if you're gonna restrict the user, that will cause backlash in those enterprise accounts Tracy was talking about. So you don't wanna restrict them. You wanna give them freedom of choice in user agent.
It's just, there's a lot all right of difficulty in trying to do that. So, Tracy, last question on this one, but, and feel free to call me crazy, but isn't this like a memo to the open source community? This is kind of what we need is the next generation open source AI browser that all ISVs can use as opposed to getting locked into one from, I don't know, Microsoft, Google, or Atlassian or wherever it may be.
Uh, it'll end up there, it'll end up open source. If they wanted to take it to the masses, they they would, it would end up there. I don't think that's the, that's not the play here.
Uh, I, I really do. You know, there's something about having sticky products and a company like Atlassian's gonna want sticky products and being able to build this, this browser, this AI browser that enterprises can use as a productivity tool. And as I'm seeing it, uh, kind of morphing into an IDE, uh, is different from what the open source communities usually, uh, focus on.
And remember, even though we're all open source, we're not necessarily talking to each other and trying to build broader kind of enterprise facing tools. So yes and no. Uh, I think Visual Studio, how long was it before it became open source?
You know, it was part of your subscription for a very long time. Uh, certainly Eclipse has been out there for, for quite some time, but IBM drove that trying to hold on to developers, and it did that job for them. So, no, I don't think that it's, we're gonna see this as an open source tool, not for a while.
Not until, um, enterprises love it so much that they start saying that they want an open source version. All right, folks, we'll see where this all goes. But I'm willing to bet by end of this year, we, we will see an open source project started, at least in this vein.
It may not deliver it for another year or so, but we'll see what happens. We'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers Network. Hey, folks back, and we're talking about, well, another acquisition.
1 billion. Now I'm a simple mind, Mitch, but I'm gonna start with you on this one. 1 billion still seems like a lot of money for a company that, as far as I can tell, is a feature management platform for experimentation.
I mean, uh, why, you know, we argue a lot about buy versus build, but this is going to take bye to a whole other direction. I mean, did they need this? What's your thought here?
I think it's an example of try before you buy, because open AI has been a customer stat sig, or sig stat, excuse me, my dyslexia kicking in there. Um, in, in that it's more than an ab ab capability. Um, they specialize in AI and AI models and collecting data around deploying features around different models and different capabilities in the application.
So what, what I, the way I read this is it's been beneficial for open AI to use that in their product development. They see this as a big boon to expanding the, uh, open AI co codex and their capabilities, uh, you know, things that they acquired from, you know, windsurf, the licensing deal that they have to start to build in that capability in the software that they're, they're generating through the models. So think about it that way, as, as not as a, um, I'm gonna add this and put as a feature, add this as a, I'm gonna put this into my models and my code building process that now I can also provide that directly in the code that I'm generating, and I don't have to think about, it's another product I gotta integrate.
This will be our product and, and built into how it kind of automatically works. So if you wanna turn on this kind of testing or collect this kind of user data, or go do a feature out here in this part of the, the world, great. It's really easy to do.
It's already built into the code. It's been factored, it's already instrumented. Boom, you're ready to go.
Mm-hmm. Tracy, how much of this was, uh, acquihire was hiring the people, buying the people, rather than That's what What I was gonna Say. Yeah, sorry, Tracy didn't mean to step On you.
That's a really big sign on bonus. Yeah, that's, but it's Because, because the, because the, the president of stats or the, the CEO, whatever it is now, the CTO of Oakland ai, And it was a stock Swap and, and what's, yeah, and what's, and what's, yeah. And what's really interesting, what, not only is it like hiring in new leadership or buying new leadership, but the current leadership is kind of being, you know, like if you notice that there's, there's a, there's a major organizational shift that just happened at Open ai, um, But isn't, I've seen, I think that's, that's somewhat normal as you transition from being research led to being product led, right?
The company was originally structured as a AI research organization with a whole bunch of AI researchers that were, may not have had the right skill sets to build commercial sellable product. So, so I think that Open AI doesn't know who they are. I think this is another step towards the yawning grave for open ai.
And I just like saying this because no, everybody thinks open AI is gonna be around forever, just like they thought Yahoo was gonna be around forever. It's original form. Um, because your point is exactly right, Jay, this is like them saying, actually, we're not an AI company, we're a chat company.
I think chat GPT has taken over open ai, you know, the, the, the, the, the brain cells of open ai, kinda like, you know, yeah, go ahead. Let me explore what Mitch was talking about for a minute, because when OpenAI talked about it, they said, using this to accelerate the building of their own products. However, OpenAI is also an app dev company.
Essentially, they build a framework and won't they stick this feature management platform in some sort of framework that they're establishing or showing other developers, third party developers to help them build apps. And maybe we will have a more integrated approach to building AI apps versus today in the land of DevOps. You know, we got like, what, 22 different tools that we slapped together.
Mitch, is there, is there something different gonna happen here? I think it's akin to back, I, I agree. It's part acquihire just like the Johnny Ives kind of agreement with, with OpenAI.
But going back to our prior conversation, this is about shaping the next experience of what it's like to use, if we wanna call 'em apps in an AI world, because this acquisition goes into part of, uh, OpenAI as AI's rebuilding of their product organization. So they're, they're may, maybe they don't know who they are, guy, to your point, maybe this is the sly fox saying, here's who we want to become and we need this to stay ahead of anthropic and the others. So we just don't look like a patchwork of whatever kind of capabilities of, as we acquire companies.
Um, I tend to think there's a, a strategic intent behind this in addition to acquiring talent, which is a very valid point. Um, but I think we're in a race for not the next model, but we're in the race for defining the user experience and owning what that's like and becoming the iPhone of AI experiences. Alright, cool.
Tracy, what do you think? Is there a new way of thinking about app dev? I think we're gonna see open AI have a new browser.
I would not be a bit surprised. I would not be a bit surprised. I mean, um, Because when I read that, when, when I saw the, the, the, uh, the topic come up for our B block, I was like, you know, open AI should have a better browser.
'cause it kind of sucks for chats. I could have a much more productive, uh, productive browser for this. It's a good point.
So, you know, it, it, I I do believe that this was a, a more of an acquisition of personnel than it was of technology. That doesn't mean that there, uh, oh, I just, you just lost me for a minute. But anyway, I hope you can still hear me.
That doesn't mean that the technology was bad. It just means that Didn't wanna ask Jack one final point on this. Isn't it wonderful that we're gonna have all these additional types of browsers that we need to secure and the attack surface is gonna be so much broader.
Aren't security people really thrilled about all this? Uh, I think you've nailed the bucket on the head, which is really that we're, it's expanding the attack surface. It's another tool then that we have to think about and worry about how to secure.
The flip side is theoretically the browsers will, or at least should include additional security features, right? These are targeted much more at enter, well, at least the other enterprise browsers and probably, um, whatever comes up out of, uh, OpenAI as well will be targeted enterprises much more than targeted at mass adoption. Uh, OpenAI maybe not 'cause they really are a consumer based uh, solution, but a lot of the other efforts like the Atlassian effort and the other browsers are really targeted at enterprise users.
Where to guys point, it is really forced adoption and forced security around that. So I think that helps a little bit for mass adoption. Then more browsers we have the scarier becomes from a security point of view.
All right, well folks, you're heard it here. Once again, it giveth with one hand and take it with the other. Thanks everybody for being on the show and sharing their thoughts and insights.
We wanna encourage all of you to stay tuned for the rest of the Tech strong TV lineup behind us, which is equally awesome. Until then, we'll see you guys tomorrow. Hey everyone, welcome back here to Tech Drunk tv.
Uh, my next guest is Louis Gutierrez. Louis is the director of AI at Constant Contact and let's welcome him to the show. Louis, great to have you on Tech Drunk tv.
How are you? Great. Yeah, thanks for having me on.
Alan. Excited to be here. My pleasure to have you.
Hey Louis. I'll be honest, we don't get a lot of director of AI here yet, though. I think we'll be getting more and more in the coming months and years.
But, um, give people a sense of, you know, what, what's your role as a director of ai? What, what were your qualifications? Yeah, yeah, Yeah.
Uh, you know, what's your road been like? Yeah, for sure. So, um, briefly I'll just describe what Constant Contact does.
So Constant Contact, um, provides AI enabled digital marketing tools for small and medium sized businesses. Um, so as the director of ai, which I've been at this role for about 10 or 11 months, which is relatively new for Constant Contact, we have engineers that have been here five, seven years. Um, we have some people that have been here 10 years because we're a company that's been around in the marketing space for, uh, almost 30 years now.
Uh, so it's still relatively new, but generally my role breaks up into two different parts. So one of them is ai, integration of AI into the product side, so the customer facing side. So this, um, manifests itself in content generation tools, brand analyzers, so forth.
Uh, and then the other side of it is the productivity side. Like I here at Constant Contact, we're a medium sized business, uh, and we wanna utilize and leverage AI tools to bring productivity gains efficiency to free up people to work on things that they're passionate about, um, while delegating some of the other things over to ai. So my role, um, generally falls into those two categories.
And our strategy is pretty simple here. Uh, we approach AI through a clear-eyed, uh, way. We want to, we want to make sure that we don't get caught up in the hype of adopting AI tools, um, just for the sake of the new shiny thing.
But we want to adopt AI so that it brings value so that it brings and more importantly, measurable value. And so that goes both on the productivity customer facing side and on the internal productivity side as well. Uh, and so we do that by measuring adoption, by measuring ROI, by measuring quality and so forth.
Um, so, so that's a little bit about, uh, what I do here at ai, uh, at constant contact in, in regards as AI director. So my journey, um, started off, uh, as a software engineer. I did undergrad and, and master's.
And so I worked as a software engineer for a while, and then at a certain point I decided to go back to grad school, and I was actually really interested in cybersecurity. I think you have a background, right? And some experience Yes.
In security. So I went into grad school, um, and to do my PhD and I was, you know, had an advisor. I was ready to do cybersecurity.
Uh, and then I, you know, as part of, uh, you know, PhD program, first year PhD programs, we had to attend seminars and lectures and conferences. And so I went to one and I saw somebody presents, like on an early on machine learning results, I think they were analyzing, uh, an article from the New York Times and looking for bias and topic modeling. And I remember sitting there and thinking, wow, this is really bad.
This is so bad. There's no way that this is ever gonna work. And so I, I, uh, I, I harassed like, as you do in academia, you harass and give the the speaker a hard time and ask 'em a bunch of technical questions, uh, make 'em sweat up there.
And then afterwards I went and I talked to this person and I was like, wow, this is, you know, so bad. This is, uh, you know, this is never gonna work. This is never gonna scale.
People are never gonna want to use this. Uh, and then we started chatting and talking. We went to go get coffee, and, uh, 15 years later, here I am, right?
I've dedicated my, I switched over my major, my concentration from security over to machine learning and AI found a new advisor. Uh, yeah. And I've been focusing on that since, you know, roughly around 2009, 2010.
So it's, uh, wow, it's pretty, uh, a long journey here. So He converted you, He converted me just one simple conversation, probably 30, 45 minutes. And I was Willing enough to ignite.
Yeah, for sure. It was, it was almost like, maybe this is a little bit of hindsight bias, but it was, he, he convinced me that someday I would be having a conversation like this, right? That there would be mass adoption, that these tools would be made publicly available, that they'd be easy to adopt, uh, and that, you know, we would be, uh, you know, at the forefront of technology, innovation, productivity, and changing the way that people work.
Um, not in so many words and not so specific, but that, that type of, uh, impact on, on society, I think is what he communicated with me. And, and it worked. And here I am.
AI's game was securities loss, huh? Right. But we're here, and, and, and you're right.
I mean, look, this is, you know, I, I often think this, if we took someone not from the last century, not even like from the nineties, if you just took someone from 10 years ago, 15 years ago, and them, you know, in front of a computer with chat GPT today and said, have at it, it, it would be akin to like, you know, primitives praying to a God for rain because they thought the God brought rain. You know? Um, there are some people who still do think that, but that's a whole nother story.
But anyway, you know, it's so, it's almost auto magical, right? Yeah. In, in the, and what it does here, I I was having a conversation earlier today, you know, when will we achieve super intelligence?
When we we achieve, uh, uh, uh, uh, artificial general intelligence, a GI, and I don't look, as I sit here today, I can't tell you when, or even if we may never, who knows, maybe the, you know, we top it out. But even if we stopped developing AI where we are and froze it today, there's enough here to revolutionize and disrupt industries for years to come, years to come, that that's how impactful that that is. But, you know, Louis, I've been in in tech a long time, A lot of times, you know, it's the big guys, it's the big boys who get to take advantage of this technology because there's oftentimes a high barrier of entry.
It's expensive. You need really, you know, boat, you know, crazy good skills. You know, there's something that kind of prohibits the, the every man, the small, the SMB, the mom and bob from harnessing, right?
Like, I, I remember for instance, when the web first came out, everybody should have a website. Well, where's a small company going to go get a web? Right?
They didn't have, you know, you could go hire someone, but that got expensive quick too. Um, AI seems different. It's, it's almost that the big demo desire demo, well, it, it spreads democracy, right?
Everyone, everyone could use it. You don't have to be a prompt engineer. You don't have to be a director of ai.
Talk to us what you guys are seeing at Constant Contact. You, I don't know how many customers, but you guys have to have tens of thousands of Mom and Pops and SMB businesses as customers. Yeah.
Yeah, absolutely. So you, you're absolutely right. I think there is something fundamentally different about what AI means, and I think it's even more specifically like our perspective is that there's, there's actually an, an added benefit to being a small business.
So if you look at, um, the disruption, especially as far as like job displacement is you look at the big companies, and so I've worked at big companies before, right? Where the, the, the name of the game is like, you have a problem and you throw a bunch of resources and money at it, and it gets solved, right? Um, but it's not necessarily like a long-term solution in some cases, right?
Uh, and I think, um, what these bigger companies are learning with AI is that they can have leaner teams and then enable them with AI tools so that they're, those leaner teams are, they're, they're force, they're force multiplied, right? They have a bigger impact. So they're able to do more with less.
So the interesting thing, uh, and the perspective that we take at Constant Contact is that small companies, small mom and pop shops have, have known this since the beginning. They've worked with small teams and they've made people on their teams, uh, wear multiple hats and do multiple things, right? And so the difference that's happening is here, is now they're enabled with AI tools like Constant Contact that allows them to do more with less.
So in a sense, we, we see AI as bridging that gap or like leveling the playing ground between the big companies and the smaller companies at Constant Contact internally, we use a lot of the same tools that the bigger companies use. We just, we buy licenses, like, for example, for AI system development. On the product side, it's about content generation, right?
So what we do is that we look at, uh, our goal is that we want our customers to be able, they're not marketing experts. They're, uh, real estate agents, right? They're, they have ice cream shop, they have a bakery, they're experts.
They're passionate about their business, and marketing is something that they have to do at Constant Contact. We enable them with these AI tools so that they can have the, the least amount of effort that goes into it with the maximum amount of output, right? And we do that by allowing them to generate templates, email campaigns, social media can, um, by having smaller smart input with their brand data, with their campaign history data, with their, with their online presence, we enrich that context, and then we're able to produce templates, email templates, social media posts, SMS, that is tailored to their audience, right?
Where you wouldn't ordinarily get that if you just went to chat g PT and said, you know, I have a, I'm releasing pistachio flavored ice cream this Friday. Write me an email, right? It's gonna be too general purpose.
So we able to carve out a space for our customers in the marketing space and be able to have very tailor specific marketing copy generated for them. Excellent. So, again, I've been around sometimes the road to, you know, what they say, the road to perdition is lined with the best of intentions, right?
Right, right. You're a director of ai, you're very comfortable around it. I'm using it.
We're techie people. We we're comfortable with this stuff. I think sometimes the guy owning the ice cream shop, or the flower shop or, or what have you, feels a little bit like this stuff is being forced down their throat and they're not comfortable with it.
Hmm. And so, you know, they use it if they have to, but they prefer not to. Let's say what, but like you said, I don't know if we've seen something as easy as, as wearable as AI is, what, what's been the reception from the constant contact customer base loss?
Yeah. Yeah. So we, we re um, we're coming out with a report pretty soon, um, and we're, we're noticing that essentially 48% of all the SMBs are, are using AI tools.
They're integrating them into their really, yeah. Yeah. Yeah.
And, and That's a big amount, I think like when you start to break it down. Yeah, it's a big amount, right? Yeah.
And, you know, when you start to break it down, emails and social media posts is like 37%, right? Um, so it's, it's a, it's a huge adoption, right? Um, and I think that the way that we manage it at constant context, so there's, there's a lot of, um, a lot of things you have to watch out for.
If you're, if you're out, you're out, out there and you wanna adopt AI tools, you have to think about legal legality, compliance, right? Um, ethics, right? Responsible ai, and you have to think about, um, uh, a bunch of other things that hallucinations, for example, right?
Like, how do I, how do I manage hallucinations? How do I make sure that if I'm generating some sort of marketing content, that it's relevant, that it's not just something that, uh, that the AI made up? Uh, and so like in constant contact, we do that hard work for everyone, right?
So from one of the first things that we did before we even started integrating AI into our product, as we developed an AI governance team that is a cross-functional effort, security, it, ai, team, legal, we all come together, we decide what the rules are, right? Until the day when government comes in and says, here's the rules. Like companies are left these rules.
And since we all put the customer first, bringing value to the customer, ensure that we're delivering responsible, ethical solutions for them, that's at the forefront of our air governance team. So that, that's the case hallucinations, right? A big one.
How do people pe That's the first thing that I hear from people is like, how do I know that it's just not regurgitating up some nonsense to me, right? Um, and so we do things, we add context, we add different types of mechanisms in there to reduce hallucinations. Like if you think about hallucinations, one of the problems with hallucinations is that a lot of times, one of the reasons it could come up is that the, the model might see training data and then it might see other training data that conflicts with it, and then it might just give you some noise, right?
That's one of the reasons for it. Um, so what we do is we make sure that we validate some of our results to minimize. So with any probabilistic model, generative discriminative, whatever the case is, any type of machine learning or AI model, you're going to have error associated with it's inherent, which we do our best to minimize that error, um, through several, uh, you know, uh, several functions within SI within us, and then also we monitor it as well.
So we have an observability platform that allows us to monitor it for quality. So we have different quality metrics that we can see how those metrics behave over time. If we start to notice that quality goes below over a certain threshold, then we go in there and investigate what it, um, and then we also, uh, monitor for toxicity, for quality, for all these other things to make sure that we're providing the best experience and minimizing that, that error, that threshold for error for our users.
And then, um, you know, also we do, you know, we do all of the legwork from, from legality perspective, like everything on our side goes through legal vetting to make sure that everything is ready to be used on the user's end. Excellent. So what appears to the user to just be a really easy pick it up and run with it is really pretty heavily monitored, optimized, maintained by you guys.
Yeah. We're almost outta time. I want to bring up that legality thing.
Have you guys looked into, because I don't even know what model, are you using a frontier model? Is this your own LLM is, is the data in there responsibly, harvested, I guess is a good word? You know, what, what's constant contacts take on that?
Yeah. Yeah. So, um, we, we have like a perspective where we put security and ethics first.
Like, this is, this is really obvious. Our CTO is a security guy, right? So like, you know, the first question that he has every time is like, how can we make this secure?
How secure is this? And how can we make it more secure, right? So from that aspect, we don't star, we don't store raw input, you know, prompts.
We don't store them, right? Um, so, so that's one aspect. So we never store that data, right?
It's just, it's ephemeral, right? It just, it comes in and then it disappears. Uh, and then also every, everything that we do, like when we work with third party vendors, for example, open AI or other third party vendors, we make sure that they go through a rigorous legal and procurement process to make sure that all of the i's are dotted and all the t's are crossed on that end.
Um, then when we do train, like, like for example, we have spam detection models that we train internally. Um, we're experimenting and trying to answer some questions about fine tuning models, so taking open source models and fine tuning those with our, with our own internal data as well. And so all of those then would re, would, would live behind our virtual private cloud, right?
So it's all within, in the same place where all the user data is. So it doesn't actually leave like our, our secure space as well. Um, so, so those are some of the precautions we take as well as just we do audits.
We have, like we said, we have like these observability platform, so we're always constantly looking at our data and doing manual review of our data, uh, as well as monitoring different metrics that we have to, that can give an indication on whether like the distributions of data might be changing and so forth. I love it. Yeah.
Hey Louis, we're about outta time. We've gotta wrap up. com, but is there a specific section of the website where you can get all the great AI tools and Yeah, so What I would recommend is, the best thing to do is start a free, free trial.
dot com, start a free trial and start to play with some of the tools on there, uh, and generate some prompt, like generate some emails, test it for yourself. That's the best way. One of the things that we wanna do is we want this to be very natural and organic for people.
So it should be that someone starts a trial and they're very seamlessly go in to be able to generate some emails. Love it. Hey, thanks for coming up here on Text Drug TV and talking to us.
Continued success to you and all the folks at Constant Contact. You do good work. Thanks so much.
Take care, Louis. Alrighty. Thank you.
Louis Gutierrez, director of AI for Constant Contact here on Text Drug tv. We're gonna take a break. We'll be back in a moment.
Hey guys, thanks for the throw. We're here with Chris McHenry, he is Chief Product Officer for aviatrix. And we're talking about well network traffic these days, especially in the cloud, it's getting hard to distinguish what's what, and I guess we need to find some way to figure out what the actual intent is because otherwise it all looks the same.
Chris, welcome to the show. Thank you. Thank you, Mike.
Good to, good to see you. Right? Yeah, so this is something that we're super passionate about.
It's, uh, it's been, it's been a really big problem. I'm excited to talk about it. Well, describe what the problem is because theoretically we are at least implementing all these various zero trust protocols, but if we don't have some way to understand what it is something is trying to do, it gets really hard to put a policy in front of it.
Yeah, a hundred percent. And, and I think in many cases, organizations are even a step behind that. Like zero Trust has been something that people have been working on for almost 20 years now, if you go back to kind of the origins of it, but obviously it's been a project on CISO's whiteboards for the last 10 years or so.
And, uh, it's challenging. It's challenging because in many cases we have no idea what things are doing on the network in the first place. Uh, not only do we not know what they're doing, but we don't necessarily have controls.
And cloud really, I think in many ways has completely changed the game in terms of the way that people need to think about network security, think about how they, uh, how they look at their network traffic. And ultimately, uh, the network is the thing that allows attackers to act in your environment. And, uh, they're getting really, really good at, uh, what they generally call living off the land, which is using the things that look normal.
Uh, you know, it's, it's, uh, it's obvious, you know, if you go look at many of the breaches nowadays, a lot of them start with a stolen identity, A legitimate, legitimate stolen identity stolen credential, right? And so, uh, so figuring out how we can, um, how we can mitigate some of these attacks, I I I, I do ultimately believe that the key lies in the network. Now, one of the things that's really changed when organizations move to the cloud is that, uh, your trust boundaries fundamentally change because a lot of the services that you're using used to be inside the four walls of your data center.
If you had an Oracle database as an example, it would be a physical piece of hardware that you sought on the floor that you could plug, you know, cables into. Now you're renting a database from Snowflake, you're using APIs from open AI or Bedrock or all of these different paths. Are those things that we trust?
Are they east west traffic? Are they north south traffic? Are they internet traffic?
Like, what do they look like? Right? It's, it's funda that pattern has fundamentally changed.
And so we need to start rethinking how we think about network security in the context of, in the context of workloads. And it's only gonna get crazier, uh, crazier with ai. Mm-hmm.
So, um, yeah, start starts with just, you know, people didn't understand what their workloads and their applications are doing on premises. They look fundamentally different in the cloud, their behavior characteristics, the mechanisms that you use to enforce them. And that's really what we're trying to solve here at Aviatrix with our cloud native security fabric is, is rethinking the way that network security and zero trust looks for these modern cloud workloads.
To your point, I think we don't really even know what normal looks like. So how do we identify what the issues are gonna be if we can't understand what's an anomaly? Because everything kind of looks somewhat new and different to us.
So how do we start this movement or shift? Yeah, it's a great question. Uh, I think the biggest thing that I recommend for organizations is starting with understanding where the internet is.
Like what is that trust boundary look like? Because those are the places that are gonna drive the, the strongest indicators of compromise in an organization. And one of the things that happened with cloud, and going back to that complete shift in the way that traffic patterns look inside of the cloud, is that, uh, many, many, many more of your workloads and services have dependencies on the internet.
And in many cases, organizations aren't controlling that path. So, uh, as an example, if you look at the default security posture, when you deploy a workload inside of AWS, it's completely opened outbound to the internet. If you look at, uh, you still have to make some configuration to allow to access the internet, but it's completely open by default.
Same thing with Azure, although they're shutting that down at the end of September and changing the way that they do default outbound internet access. Up until this point, you deploy a vm, immediate access to the internet. Why?
Because you have these interdependencies and they want you to use PAs services, and they were really selling to developers. But that is one of the, the key things that you see exploited by cyber criminals as well. Um, there's some amazing research, like I love my peers in this space.
Palo Alto obviously has an incredible threat research organization. There was an article that I read from unit 42 a while back talking about, you know, one of the most common techniques for data exfiltration in the cloud is that the attackers will actually spin up a VM and then they'll just start shipping the traffic out, because most customers have no control over that, that egress perimeter. So it's, uh, it that, that ends up being, you know, it's, a lot of people think about, okay, well I need segmentation.
Yes you do. I might need micro-segmentation. Yes, you probably do.
But in the cloud, we oftentimes have a bigger problem, which is we don't have control over the basic trust boundaries like the internet. And if we can add those controls, they're much higher, stronger, they're much stronger, uh, high fidelity signals of when you might be compromised, and also much more important position for control. So it actually gives us a pretty easy place to start.
We talk a lot about egress security with our cloud native security fabric. The reason that's the case is because it's so poor in so many organizations that we visit, and it's like first principle fundamentals understand what's going on to the internet. So, uh, it's different.
Cloud is different, and it's one of those, it's, uh, there's, there's a lot of opportunity for improvement. It also feels like whether we like it or not, the reality of the threat is that people aren't breaking in anymore. They're simply logging in, they're stealing the credentials, and we have no way of understanding what they're up to because they may look normal for months before they do something that they shouldn't be doing.
A hundred percent. And this actually, so it's an interesting question, right? Because the, um, I have this philosophy, and I've, I've said this in a number of interviews before, but I had this philosophy that there really are only three pillars of what I call runtime security.
And those are things that can actively stop and attack. It's not just about detecting it. You can detect it in many cases, you're already too late, right?
It's about how do you actively stop breaches? And there's a long time philosophy in cybersecurity around defense and depth, and I generally see that defense in depth falls across these three pillars. So the first one is identity, right?
It is, can you log in or not? And what do you have access to once you log in, like aaa, RAC, all of that stuff. Identity pillar number one, definitely compromisable, actually, all three of them are compromisable.
That's why you need events in depth. And the problem with the cloud is, in many cases, that's your only layer of defense. Your management network is on the internet.
You don't have good network security. You can't deploy the other, you know, endpoints everywhere. Other two pillars.
Other two pillars are endpoint security, right? Which in the cloud, you can't deploy it everywhere. You can't deploy endpoint security on a server serverless function easily, as an example.
Um, and you definitely can't deploy it on your databases, which are as a service in many cases. And then the third pillar is network security. And if you lose effective visibility and control in the network, and you lose effective visibility and control in the endpoints, then the only layer you have is identity.
And any of those layers can be compromised at any point in time. So I, I would argue that it's really less of a problem on how do I discover anomalous behavior? Because anomalies in many cases are too late.
It's actually more how do I build defense in depth from a runtime perspective. And I think the challenge of understanding what's good and bad in the cloud oftentimes has to do with you only have one perspective. You only have the perspective on the logins, on the authentications, on the behaviors of the users.
You don't have an understanding of how they're moving laterally within the network. You don't have an understanding in many cases of what they're doing on the endpoint that you don't necessarily own. And so combining those three things together really allows us to get a much better signal on what intent is, what's normal, what's abnormal.
And that's, you know, that that's really the key is we, we actually see that customers are lacking the defense in depth. And it's one of the fundamental things that's challenging to determine intent and ultimately stop attackers who look like they're good because they stole a valid set of credentials. Despite all our conversations about defense in depth, are we still overly focused on the perimeter?
I almost feel like, um, we haven't moved all that far. And, you know, we check everybody coming in through the gate, but we have no idea what they're doing once they're in town. Uh, I think it's a great question, and I would argue that, um, we shouldn't even be thinking about the perimeter anymore, right?
It's, uh, you know, again, going back to the, the concept of the traffic patterns have changed. What is east west traffic? If I'm calling a database that I don't own, that somebody else owns?
Is that east west? Is that the perimeter, right? We see a lot of people using techniques in the cloud, like private endpoints.
Um, you know, the, the concept of, Hey, I'm gonna, I'm gonna ride on the AWS backbone to get to this third party service. Well, to me, that's a backdoor outta the network. Like if, like, that's the perimeter, right?
Like the perimeter looks fundamentally different. So we need to think about, I actually think there's a blurring of, uh, of what, what that kind of traditional East west traffic and, and what, uh, perimeter traffic looks like. And we really need to be thinking about it holistically in terms of how do I protect the workloads that I own as they're communicating with other workloads that I own, and as they're communicating with workloads that I don't own.
And so, um, looking for solutions, you know, I think it's, it's, it's always important to sequence. So where are your higher, highest risk points? The perimeter is still a highest risk point.
If organizations had full control over the perimeter, then we wouldn't be talking about it anymore, but they don't. And so you definitely wanna start there. But then lateral movement, obviously it's a critical part of the kill chain and part of the Mitre attack matrix, and that's, that's that east-west movement, we need to do that as well.
And if you, if you can, you can achieve those, obviously sequencing from most important, um, you know, uh, those kind of critical control points. And then, and then getting more granular and more effective internally in your environment, we can make a huge impact on the cybersecurity posture of organizations. You mentioned this in passing, but I'd like to get into it a little bit more.
But we have soon all these AI agents, so let's imagine for a minute that we have, uh, for every one person there's 15 AI agents, each of them is gonna have an identity and some authorization to go do something. But do I have this right? If they get compromised, it's not like I'm just having data stolen.
It's like an entire process will be hijacked. Yeah. So is this, is this level of risk gonna be a lot higher?
Yeah, it definitely is, right? Like, if you think about the most common insertion point for attackers in an environment, you know, it's, it's kind of a, goes back and forth on whether it's vulnerability exploits or whether it is social engineering, right? Most of the high profile attacks you hear from, like Scattered Spider recently, they, they start with social engineering.
AI agents can be socially engineered, right? That's what prompt injection is. And so if we think about it, your workloads, which used to be highly predictable and highly deterministic, are now vulnerable to the same vulnerability that humans are in some respects, right?
With social engineering. So yes, it's a challenge. And actually I think it makes it even more important to be very, to have a very good understanding and the ability to control what data agents have access to.
Because just talking back and forth between, you know, a, a a, a customer and a client service little portal and, you know, answering questions like no big deal, right? Um, but as soon as that agent, the AI agent has access to a database or has access to even scrape things from the internet, because you could use that to send things out to the internet or has access, some of the exfiltration that we've seen with AI agents are posting code to GitHub repositories because you gave that agent access to GitHub, like that relationship, the access that the agents have to other portions of your environment. It's the same challenge that we have with humans, right?
It's when I get your credentials, what can you do? Because I socially engineered you. Now we can social engineer agents, so we need to take it a lot more seriously because of the non-deterministic nature of the agents.
So what's your best advice to folks about how to get their organization to think through all this? 'cause I think sometimes we're so busy fighting the fire that we can't think about fire prevention. Yes.
So the, I think this is an amazing question, uh, and I love your analogy around fire pre prevention, right? Because, uh, my best advice for organizations is go back to first principles, right? We talked about AI agents, you could go buy a suite of AI security tools out there, but it's like playing whack-a-mole.
Like the first principles of cybersecurity have not changed in 25 years. There are three runtime security controls, identity network endpoint, right? And if you think about even the techniques that organizations are using to defend against agent threats, they're almost all using network, actually.
They're using proxies, they're inspecting traffic, they're preventing access to systems, they're using identity as well. Um, they're using components of those core, core, core elements. And so we obviously need to be able to enable our organizations to leverage ai.
I think it's completely transformational, but you will constantly be playing whack-a-mole if you don't go look at the first principles. And that is exactly the same as fire prevention. That's why you do proactive burns, right?
Is because you don't want to be fighting fires every fire season. And so, um, and so again, you'll never get out of playing Whack-a-Mole, you'll never get out of fighting fires if at some point you don't go back and focus on first principles. It's not just about taking your vitamins, it is about thinking through, like, how, how do you, how do you prevent the illness?
Like, it, it is, it is that, again, first principle controls Mm-hmm. To that point, and we talked about AI agents being a, a cause of an issue, but is there hope for the networking and the security people with the rise of AI agents that might help them bring some of the order to the chaos and adhere to those first principles 1000%? Right.
So we are, you know, we look at AI security in two ways. Uh, from a network security perspective. We look at it as how do you secure ai, so security for ai, or how do you use AI for security?
And I do think there is an immense opportunity to actually fundamentally rethink how people implement Zero Trust with AI agents. And I will just say stay tuned on that one. 'cause we're gonna do some cool stuff in the next couple months.
All right, folks. Well, you're heard it here. One way to think about it is, the more chaotic things become, the more important it is to hold on to your principles.
Hey Chris, thanks for being on the show. Yep. Thank you, Mike.
All right. And back to you guys in the studio. Hi everyone, it's Alan Shimel.
Welcome to another episode of Control Alt Deploy. This is a, uh, control Alt Deploy is a podcast we try to do every two weeks or so here at Techstrong. And we talk about, well, it's, it's really DevOps, but it's DevSecOps, which is kind of, you can't have DevOps these days without DevSecOps.
It's about security. It's about how we're, how we're writing and deploying and running software these days. It's, it's one of my favorite shows of all the things we do on Techstrong.
It is, uh, sponsored by our friends at OpenText. So many thanks to them. But, um, it's, it's our show.
It, it's a tech strong event, a production as we say, and, uh, have a lot of our tech strong friends on this particular episode. I'm looking forward to it. Today's episode is titled Shift Left or Shield right, the Evolution of DevSecOps.
And, and that's a loaded question we're gonna have a lot of fun with. Let me introduce you to our panel members for today. If you watch Textron Gang, you've probably seen a lot of these folks on, on the gang.
So they may not be strangers. Gee, I'm gonna start with our, our friend Kate Scar, and welcome Kate, if you could give people a little bit about you Bit. Sure.
I've been, uh, part of, um, I've been doing technology since 1998, started with IBM and again, you know, cybersecurity with us, started with network security, AV and dear, I say Tivoli identity and access management, so, Ooh. Yeah, no, that Heys gonna rule the world. Thanks, Kate.
Um, joining next is our good friend, Tracy Reagan from Deploy Hub. Hey, Ellen. Hey, you know, Tivoli used to have some pretty righteous parties in Austin.
Oh, I have to say about that. And yes, I am Tracy with the Ploy Hub. Um, I do get to enjoy being on the gang, uh, on Mondays, which is a lot of fun.
I'm part of the Linux Foundation's open source security foundation, um, board governing board, as well as the Continuous Delivery Foundations board. And I'm really into open source and I'm really into fixing post-deployment vulnerabilities. Excellent.
Welcome, Chay. It's great as always to have you on. Next up, we have an analyst, gang member tech Field day, uh, delegate.
Our good friend Jack, Jack Poller. Hey, Jack. Hey, Alan.
Great to be here. Uh, I am the founder and principal analyst for Paradigm Technica. I have a long history in technology, a few more gray hairs than Kate in a few more years.
Uh, I started as an engineer, turned into a marketing person, and then an industry analyst focusing on cybersecurity. Excellent. Thank you, Jack.
And welcome is always, it's always great to have you on. Next up, I wanna introduce you to Garima ba Bal. Uh, well, I'll let Garima introduce herself.
Garima, go ahead. I'm, I am based out of AWA Canada. I'm the founder for the DevOps Community of Practice here in Canada.
I just, several chapters, I'm also the chair for the ambassador program at Condensed Delivery Foundation, written several books. And, uh, my latest book, which is coming out, is Mastering Security at Scale. So hopefully I can value add to this panel.
Oh, I'm sure you will. Garima you always bring value to every, every panel, every show we do. So thank you for all you do.
Last but not least, he's, he's the newcomer to our group here today, but we're gonna not hold that against him. Trey Island. Trey, welcome.
Introduce yourself. Uh, thank you very much. Yeah.
Um, I'm based out of Denver, Colorado. I'm a security consultant. Um, so that means I am the technical hands-on demo guy, uh, when it comes to, Hey, how do you integrate application security into your organization?
Are you ready to move to the cloud? Or do you have CICD implementation? So I kind of help with all of that.
Uh, integration with our tools for scanning the source code mobile applications, uh, open source and dynamic scanning. So guys, let's dive into it. com because of what became DevSecOps.
I thought DevOps was gonna give us a chance to do security better, to correct a lot of mistakes that I had seen, you know, in my years in security, we didn't call it DevSecOps. Truthfully, it was rugged DevOps. I remember the fights I had with people in security and the people in DevOps because there is no, there's just one DevOps, you don't need a second there.
You don't need biz in there, you don't need anything. The security people said, ah, you know, it, it should be SEC DevOps, because isn't security first always. Um, and then we, you know, this whole idea of shift left, and I was, I was so gung ho for sh shift left.
I believed in shift left from the bottom of my heart. And it, and it, you know what, over the years caught on DevSecOps became a real thing. Most of the DevOps companies considered themselves DevSecOps companies.
We shifted left and we shifted, left some more, and we even went a little further left, and some began to question, did we go too far left? Is it really working? Maybe we should shift right?
Shift up, shift down, shift everywhere. We still need better security. Kate, if you don't mind, I'm gonna ask you to kick us off here.
Yeah. Did we shift too far? Left Was shift left the right move?
You know, one of the problems that I, I, I feel like we continue to have is that it, I think originally it was a good idea to shift left because the people who were coming out of, um, school, they, we just weren't, it wasn't being taught. So we had to start somewhere in this and shifting left and trying to add security because we were being hit. I mean, I still remember, you know, the SQL injection attacks in, you know, 2003, 2004.
I mean, it, it was, it, it was taken us by surprise, right? And I think at the end of the day though, we still, you know, we became cybersecurity people became these roadblocks and to business and to the dev people. And, and we were really putting a lot on application teams when they weren't security people at the end of the day.
So I, I think we did go too far, um, to the left. And I, and I think that we didn't work together. We put a burden on them, but we didn't lift a burden and we didn't share that burden going forward.
So I think it's better that we are starting to look and, and create this culture of, let's really take a look at this because we all want, um, we all wanna do it safely. I mean, at the end of the day, you know, it, it's, we have to be better at working as a team. Yes.
The team Thing, I reemer Go ahead. The team thing, you're both, Yeah. That, that team thing is so important because, you know, it's, you know, I, I was doing software configuration management in the late nineties all through the early two thousands.
And I never even talked about security. I never even heard about it. I just thought security was something was done behind the other, the, the curtain oz was back there dealing with security, and we didn't have a discussion about it.
There wa there really wasn't any, any tooling to add to anything that we were doing that would improve security. So shifting left was, uh, a, a shock when suddenly we were told, oh, the development team and your, um, your, your SCM at the time needs to have more security in it. We were like, well, what kind, what do we need to do?
And in fact, that was the first time we started looking at, uh, what they call software de bloating now, um, to shrink what libraries we were pulling in it in a shared library environment to try to minimize the amount of libraries that we were bringing in so that we could do better security on the, on the binaries that we had. So it didn't have so many executable, uh, functions in it. So, you know, it's interesting that you say the team part.
'cause I think that's where we got caught up in the beginning and suddenly it was securities got oz, but then you're gonna have to shift it over to the, to the, the munchkins to get the work done. And we didn't know what to do. Yeah, yeah.
It really wasn't being taught. No, not at all. It was security was not taught to developers.
That's for sure. When you computers site reemer, you know, the voice of DevOps here, shift left was such an important piece of it for me. What about you?
It is still an important piece, but what I feel in today's AI era, it is shifting, uh, from a personality perspective, which is basically having more, uh, and new components of, you know, how to integrate security when you are looking at the development stack, because a lot of developers are using AI and AI native tools to kind of in, you know, build code and, you know, also develop and review and test and deploy code, right? So there are new types of security, uh, you know, is required and new, new type of security vulnerabilities are introduced in the code itself. So shift left is changing, and, uh, obviously, uh, there is a lot of upskilling required in that dimension.
And why runtime security is important. I'll put some facts on the table so that, uh, you know, we understand the urgency of it. Uh, there was a report from Checkpoint, which says that, uh, every prompt, which we do, uh, one out of 80 prompts are posing higher risk of, uh, sensitive data leakage, a hundred compromised AI models.
Uh, were deployed into hugging face platform, which is based for a lot of people who are using it. And there is dark LLM, you know, the malicious modification of AI models, for example, is happening as we speak. So if you think about this shifting left had reduced the vulnerability problem by 70%, right?
30% was still runtime security gaps, which we were finding. But now with the injection reduction of AI into various, uh, SDLC lifecycle phases, it becomes more urgent to ensure now we don't look at only runtime security, but also looking at shifting left and seeing what kind of new vulnerabilities are getting added through a AI injection. I can talk a little bit more about it, but I think from a community point of view, we are seeing a lot of these things which are, which needs upscaling.
And, uh, I mean, this is a bad news that, you know, uh, we don't have enough talent, we don't have, uh, enough education and awareness in this dimension. And where there, where the communities like this, uh, what we drive come handy and we foster that collaboration. Excellent.
Gima, excellent Jack Tre thoughts? Well, I, I may, I don't know if I'll be call it controversial, but I have a slightly different opinion, which is really embrace the power of, and rather than, or which is, I think we need both shift left and shift, right? Which, you know, defense in depth, right?
We are having different types of controls at different points in the process and in the life cycle of the application to solve different problems. Shift left is really, you know, Kate talked about it not teaching cybersecurity to, you know, early engineers, but even senior engineers who know about cybersecurity don't address cybersecurity because functionality, feature functionality and schedule is the most important things to the company, not security. And so we, that's how we measure our developers and our development life cycle, right?
So shift left is a way to introduce cybersecurity into that conversation, to bring it level of importance up so it gets addressed as quickly as possible. That doesn't necessarily make it sufficient to protect our applications. We also need security shifted, right?
To do more at runtime, to catch things that can't be caught at the early stages of the development lifecycle. Fair. Trey, you're talking to real life customers, users.
What, what's your view on this Shift? Left is very important. I think the problem, the problem resides when security then offloads their responsibilities onto the developers.
And the developers then decide what security tools they want to use because of ease of use. Not necessarily this tool is better than the other. I've seen a lot of that issues where developers then have a lot of power to dictate what security tools will be used, but they don't really have metrics of why other than, oh, this, look, this works really good in my IDE as far as easibility, but what security checks are in place.
I see a lot of that. Um, now with these AI tools, it's gonna be up to security to continue to research and understand these vulnerabilities. I think it, for me, my background was, I was a developer before I became a security analyst, before I became a security consultant.
So I'm kind of able to have a conversation at a lower level rather than just, Hey, go fix this because the report says, so that I think is a lot where there is contention between developers and security. 'cause the first thing a developer will say, okay, can you tell me why? Or do you, my, my application works like this.
Why is this a vulnerability? You can't just say, it's only in the report, go fix it. You have to go on that other level.
Um, so that's where security is gonna have to continue to do their work, their research, their efforts. And I see AI as a complimentary tool. Um, the problem I see on the development side, if it continues to go down this path, is this whole thing with open source, right?
You have something in your code that you did not create. You don't have a good understanding of it. And if you're just gonna use these AI tools to generate an application, you're not gonna have a good understanding and you're probably have a lot of loaded code for functionality you didn't even need to utilize.
So that's where organizations are gonna have to lock down what tools that they allow And let's you have insecure code. Go ahead, chase. Go.
I'm sorry. Let's talk about, Let's talk about tools for a minute. So I just spent the last week we have the at, at the CD foundation.
Kate and I are on a, a special interest group called the CICD cybersecurity, um, sig. And we have a deliverable, so I, I gave up this last week to start working on looking at tools and how they fit within the secure software development framework. And I'm not gonna say AI's out there, and it's gonna probably change the way we do things, but there are so many tools today.
I am, I was shocked by the number of open source tools that have been delivered to the industry that I know we're not, we're not using yet. Not everybody's using them or taking them serious. It it just look at the problem with generating SBOs.
Not everybody generates an SBO M1 of the core components of your secure pipeline. So we have to remember that while we have this shift left discussion, and many of these tools are on the left side of the house, there's also many that the platform engineering teams are gonna start using that are sort of squished to the middle. Yeah.
And, and many of those ones in the middle are, are actually starting to monitor what's happening in production. So maybe we've come to a place where we're shifting, um, we're shifting a, a lot of tooling into the middle that catches things as it's coming through the pipeline, if they're adding it and it's starting to monitor what's happening in production. I really was surprised by the number of open source tools and the, and the security features that these tools offer that can fit today without any ai, without any new, new tooling to solve some of these problems.
Um, and I, you know, I hope when this document gets out that people can use it as a research tool because it is shocking. I mean, I, I was thinking I'd have five or six tools per category, and I'm looking at 25, 30 tools per category, all of 'em doing something a little different and solving the problem in a different way. But they do relate specifically to the challenges that have been brought up in this, in the secure software development framework.
And it's a really good guideline to use that framework because it gives you a real, a clear indication of what your goals are, but it doesn't tell you how to solve them. So what we were trying to do is say, here are the tools that will solve these. And I was shocked, I was really shocked.
It's taken me all week to get just a few of these pages done because there's so many tools and sorting out what they do to fit that has been a challenge. So I'm hoping this helps. I really do, because we don't need to wait for AI to solve the problem.
There are tools out there that can do it today. Yeah. Yeah.
And, and I love it. I think you used a key word, um, platform engineering this idea about that, right? It does come to that middle.
It, it, it really, um, I think it's a perfect word to that encompasses, um, everything that we're talking about from the shifting left to the, you know, runtime application protection. It, it, it gives this whole more of a holistic view and I think where organizations are, are moving and it's better. Um, I do wanna address quickly, if you don't mind, uh, with Jack this defense in depth.
You know, it's something from a strategy point of view that I have seen that really isn't working. And the reason being is that it almost creates more of this whack-a-mole type of strategy where you get a, a vulnerability and you get a tool and you hit it. I think in what we are trying to work on, um, with, with Tracy, um, is more of this holistic type of picture and a strategy that is more proactive instead of like a proactive offense, more so than a strategic, um, defense, which is different when you think about it.
You know, you still need to have an offense strategy. It doesn't mean that we are going to attack. It just means that we're setting ourselves up in a position that we understand, hey, a heavy hitter is coming to, um, to hit, are we gonna be all in the infield or are we gonna go to the, you know, off field and get ready because we understand that it's coming.
We know the threats, we understand the attacks. There really isn't anything new even with I ai, there's still the same attacks. We know this.
And, and so, um, with the tools that are out there, some phenomenal tools like Tracy is saying, it's, it's, it's, it's such a beautiful time to be a part of cybersecurity. I, I, I'll, I'll tell you, I don't disagree with you at all. I highlight defense in depth more to highlight that a single tool is not a silver bullet, right?
That we are not that simply doing shift left and doing static code analysis or dynamic code analysis, whatever your shift left or combination of shift left tools is gonna give you isn't going to solve or, or provide you perfect security. Right? And I think you mentioned in the word holistic, which is right, is that we want to think about the entire gamut of everything from the very start of the project architecting security into the design, through the coding phase, through the test phase, through the deployment phase, through runtime, and then even how do you end of life the product and how do you secure, right?
Yeah. And what do you do with the data at the end? It's an entire picture and there's an entire set of problems.
And one tool or one small set of tools shifting left is not going to solve our problems. So I'd like to people to think about it as, and, and I, I appreciate the, the, the, the analogy of whack-a-mole we do in cybersecurity, spend a huge amount of time doing whack-a-mole, which is, I believe the wrong way to do it. And I think the right way to do it is say that we have seen these problems in a slightly different domain.
AI is a brand new domain, but it is still a data leak problem, right? And how do we treat data leak problems and can we, uh, uh, repurpose tools or apply the same tools as Tracy said, where you said there's hundreds and hundreds of tools. How do we use these tools to solve that problem without saying, oh, we have to wait for ai?
Yeah, I I would also like to shift this discussion to runtime security and, you know, uh, of, of course there's a majority of work which is needed to be done in terms of, you know, securing the legacy or securing the as is or status quo situation. For a lot of organizations, you know, there's a maturity curve. So a lot of organizations are already behind, right?
So the 70% of vulnerabilities, which can be found through injecting security through shift left is not already happening. So that addresses or caters to that. But if you think about runtime security and why it is becoming more and more important, and the CXOs have a shorter runway of 36 months to prove this because AI is coming, and I'll highlight three points.
LLMs, you know, you, like it or not, developers have started to use LLMs in many shapes and forms. So the LLMs are creating code, right? The second part is prompts.
So we all use prompts, right? And if you think about what tasks software engineers are accomplishing through prompts, there are many, right? So test case generation, for example, uh, has a high kind of volume where, you know, people are generating, uh, test cases through prompt engineering, right?
So, uh, the third aspect is AI agents, you know, if you like it or not, the AI agents are coming in the operation stack as well, and they're using LLMs. So for these three special components, which AI is bringing, we need a special, uh, security mindset. We need to have, you know, specialized components and security guardrails to not to inject malicious code, for example, uh, data poisoning through prompt injections.
Even AI agents, they are playing a, uh, a bigger role because a lot of autonomy and decision making is happening through AI agents. So it is more and more important that, uh, people start to invest in runtime security. I, I don't disagree at all.
I, you know what, I, I like the term shift everywhere. I, and I, it's not my term actually, I first heard it from my friend Jeff Williams from Contrast Security, right? But certainly we've gotta shift left, but we can't expect our developers to become Security Pros, right?
As Trace said, they're going to, they're going to lowest common denominate a least path of least resistance, whatever one's easier for them, whether it's good security or not, it's something, but we do need to have runtime controls. We need to remember that security doesn't end at the Deploy button, or we don't actually press a button for Deploy anymore, do we? But it doesn't end at the deploy it, that that mission continues as well.
And, and so it, I would like to see a holistic security view of, you know, throughout that the life cycle, not just of software development, but of software operations, right? Observability and security is, is something we haven't talked on here, but that needs to be part of this as well. Um, I, you know, we, security's important and no matter who you talk to, I think no one says, ah, security's not really important.
We all say it's important, but we can't just focus on the security over here or the security over there, or at this stage or that stage. Every stage needs security. And I, I think the, one of the problems with security left is we took our eye off the ball of right.
And runtime and, and these other, these other places, um, Uh, you know, being a, you know, I wanna, I wanna, I wanna disagree with that statement just for a minute. Go ahead. Because, you know, if you look at what the open SSF has done, which I work with quite often, and they talk about security all the time, there has been a quite a bit of work done on trying to create that holistic view.
That's why I'm gonna push again, if you have not read the SSDF, this is a, this is a, a reminder to do that because the goal was to create that holistic view, and there has been a ton of work on creating that holistic view. So read the SSDF because it's, that's what that is. I I will and I should.
And, and Chay and Kate, when you guys do finish this deliverable here from the, uh, CDF, I'd love to have it either on one of our tech strong properties. Let's get you both on and, and, you know, shine a light on it because it sounds interesting. Trey, October, actually we haven't October.
October, alright, I'm marking it down. Trey, I feel like we haven't heard enough from you on this. What are you, what are you making of this discussion?
No, absolutely. With runtime, right? You have no, you have an idea of how your application should run when it's under a load, when users are actually actively using your application.
But there's always that use case and sometimes it only takes one to break your application or have data leak. That's why it is important. It's not important.
It's important to have these tools, right? But it's also, why do we have these tools, observability, what are we doing with that data? Who's managing that data?
If a tool is fading, failing, what is the corrective action, right? It's all these things you just can't throw. And like, uh, Tracy was saying, there's so many tools out there.
How do we actually, um, identify the ones that are correct for our use case? There could be a tool that's gonna be great for one company, does not mean it's gonna be great for our company or our application. So that's where a lot of that research does have to come into play.
Um, and having information on the log injection, how is the host running? All of that is important of course, after the development phase. But if we can do that in every phase development static, well, static analysis, dynamic analysis, how is it running that is gonna give the holistic view, but sometimes I see is there's so much on dev teams to do almost all of that.
And they're great at developing code now you're forcing them to put another hat on, another hat on. And in my role in the past, because I'm a jack of all trades, I enjoy learning things, but I'm not ne I necessarily did not have teammates that had that same, uh, go get it mindset. And then you feel like you're ha my last name.
Like you're on an island all by yourself. Um, yeah. And, and there is that, that we need I'm sorry, go chase.
I Have one, one, I it based on what Trey just said, something came to mind what companies can do to start understanding their gaps in their shift everywhere approach is they, like we, we did in chaos engineering, we need to start doing game days where a, a fictional, uh, you know, software supply chain, CVE, that's critical or high risk is floating out there in your live environments. Watch to see how long it takes your team to re respond to it. What is your meantime to remediation?
Those are the kinds of things that organizations should start looking at. Uh, because I'm, right now it's over a hundred days, we've gotta get it down to less than 15, less than 10 would be good because it only takes 10 to exploit. But we ha we are over a hundred days folks, and that doesn't work.
So game days would be a really important, um, exercise for your team to start practicing because it means every single person in the organization from developers who have to recreate the, the new palm files all the way out to the deployments have to, that that whole, that whole cycle elastic, uh, has to be hit when there's one vulnerability that has to be fixed. Great. Hey, Jack, I'm sorry.
Go ahead, Kate. Oh, I, I was just gonna Say, I'll come, come back to Jack. Go.
So, um, so quickly, the only thing that I'll, I'll add is that, you know, it's not as bad as it was meaning, um, you know, when we used to go talk to application teams, there used to be like, you know, what are we talking about? Like, you have no, I like, and there was such a pushback. You don't see that today.
Today You actually have people who are interested and, um, who are concerned and still feeling overwhelmed by, by all the different tools that are out there. And I, and I think, um, and, and I believe the way that Tracy, you know, broke things down very easily, um, within this deliverable, I, I believe that it will help. But making it simple, I think will, will go a long way into making SAC important in ops.
Go ahead, Jack. I'm sorry, I I don't disagree. Jack, when you talk to consultant of clients, right?
Analyst service, do they take this? Do they ask, do they want a holistic approach that shift everywhere or do they focus in on a particular stop along the SDLC? I think they, right now, vendors are primarily Focused on a particular stop along the SDLC because they perceive that as a way to market and sell.
Not that that's what's really needed. And something that Kate sort of said resonated with me. Part of what I see and what I bring back to vendors is when I talk to practitioners, they complain that the security tools are built for security people, not for developers, right?
When, when I was a early on in my engineering career, I started out as a software engineer and then I went and started developing chips. And one of my mentors in the chip development space said, well, all the code you wrote for the chip will work, but you write it like a software guy, not like a hardware guy would. And it took me a long time to figure out what that meant.
And it's really you, the way people do things and operate in DevOps is a different mindset comes out. You start with different assumptions, different perceptions than you do with when you start out as a security person. And think about it as a security person, I think the security tool developers need to put themselves in the position of the practitioners and have people like Trey with them who can represent the practitioner point of view and say, this is how we really use that type of tool in our environment.
Build it for us, not build it for you. And I think that will really help build it for us, not for you. I think that's a great place where we call pull the plug on this, Jack.
It's a good, good way to end it. Build it for them, not for you. Kate, Tracy Reemer, Jack, Trey, thank you all so much for joining us.
We, we try to keep these to a half hour. We're a little over, but we're close. Many thanks to OpenText for their sponsorship of this and all they contribute, so we appreciate it.
Many thanks for you to you guys for watching. We'll be back in another two weeks with another Control alt Deploy and we might be doing some more live round tables where you can take part in them as well. So stay tuned for that.
Until then, for Control, alt Deploy and Techstrong, Ms. Allen Shemel, we're out. Welcome everybody to this special event, showcasing the VMware Cloud Foundation nine release.
This is also the first time we've run a Techstrong Field day, so, uh, really delighted to be here on Techstrong and giving you the opportunity to interact with us. The various presenters and, and various delegates throughout the day here will be with us in the chat. So please do drop down into the chat if you have any questions, just ask them straight up into that chat.
And we will, uh, endeavor to answer those questions as we go. So we're gonna kick off with a nice direct, what's new in VCF nine, and then we will head through a, a variety of slightly deeper dives into the various areas. Leading us straight into this session is Sabina Anya with the What's New in VCF nine.
Hello everybody. Thank you for joining this session. Uh, obviously we're out with VCF nine.
This will be a fantastic highlight of what's new, what you should know, how you can start playing with this fantastic platform. We have a bunch of folks here on this session today. We're gonna make it interactive.
We're gonna go through a bunch of content. We're gonna have about 30 minutes of, let's see what's new. Let's see how you can te take it for a drive.
Let's see what's changed in the past, let's say two years of Broadcom and VMware coming together to work on this. And then we're gonna have a reasonably live conversation about some of the stuff that you're gonna see as part of these slides. There are other sessions coming after this.
Make sure you check in some of them. We're gonna go far deeper than we're gonna go in the next 30 minutes, so tune in to what comes after this. My name is Sabina Anya.
I'm your senior technical product lead for VMware Cloud Foundation. Been with VMware for five years now, every time VCF. Let's have a little bit of fun today.
Cloud Foundation has been around for, I don't know, a good part of seven to eight years, and we've had vSphere for about 25 years. Don't count the years if you don't wanna look at a calendar. The fun part of this is, is that at the core of what VMware is, it's always been about virtualization, taking hardware and making the most of it, allocating the resources in the best and most efficient way.
But why stop just at virtualizing servers? So for the past 7, 8, 9 years, depending how you're counting the the age of VCF, we've basically looked at virtualizing storage, networking, and tying it into our automation and operation tooling that we've had in the past and basically creating this one platform for everything. The last version of VCF before nine oh was five two.
Up until that stage, you could still see like the seams between all these different components and it came more of a, you know, we use what you want. But ever since we kind of joined forces with Broadcom on this, one of the major shifts that we've seen and we've executed on successfully is this, it's one platform. You don't have to start trying to understand each separate product anymore.
We're delivering to you one platform, VMware Cloud Foundation, that that hosts both containers and virtual machines that has automation at the fingertips and helps you do day-to-day operations. And this can be deployed, you know, on premises in your, you know, Paris, London data center. You can put it in a partner cloud, you can work with some of our many partners to do this, or you can put it in smaller remote locations and have a smaller footprint of this.
All of this is your VCF fleet now that's supposed to deliver on your solution, your technology and your applications that you want delivered Quick, kind of what does this do for you? Why should you care? Again, we're gonna get technical in a minute, so bear with me as we go through a little bit through why should you, the what is, sorry, the why should you care part.
First of all, when you have one platform, it's a lot easier for you, for your business leaders to increase revenue quickly, changing market conditions. Your management wants you to start thinking about how to deploy ai. You wanna really reinvent your data center over the weekend, or do you wanna say, sure, we support this out of the box, we support containers out of the box, we support whatever you need next.
We probably thought of it and put it in the platform, so why not just take advantage of that? Also, because we've introduced so much intelligence in the platform, you're able to look at different issues across the different, uh, technologies, whether it's networking and storage, and combine that with, again, our automation operations platform and mitigate problems before they escalate, do some application troubleshooting. We actually have a little bit of this to show you later.
Again, downtime is just not a word that's okay anymore in 2025, it wasn't okay in 95, but there is zero tolerance today for that. So being able to minimize, to recover fast, to be secure and resilient becomes key to all of this. And last but not least, there is not one IT outfit out there that does not want to lower cost.
There is not one IT manager that suggests, Hey, you know what? We should have this year more cost and less efficiency in arfa in our it. So part of what makes a platform great is that you can look at your entire footprint.
You have that level of visibility so you can reduce waste. How many times have you not deployed oversized VMs? Because you know, nobody actually gave you any guidelines on how to do this.
And it's like nobody got fired for an oversized vm. But now you have all of this space being eaten up all over the place and your management is saying, can we do more with less? This is one of the places where working with a platform that has utilization and cost insight can help you build a report in minutes rather than days.
So what's changed? Most of us are used to doing IT infrastructure by basically managing each and every component in our IT zoo. Whether it's I'm managing my vSphere, I'm managing my whatever storage environment I have my entire data center land, so on and so forth.
We don't think of the IT environment as one continuous delivery platform. And sadly, it's also how we look at different failures across the data center. We bounce tickets around between the different teams.
However, VCF nine absolutely wants to rewrite the way we do this. And we're very adamant about it because you have the traditional sort of the bottom layer of the, the technologies that you know and love with vSphere, storage, powered by vsan, networking, powered by VCF networking that bring together, again, once you deploy VCFA, VM has everything IT needs. It has networking attached to it, it has storage attached to it, everything you could need to make your workloads run.
And then we have all these adjacent services. You can do that capacity management, I mentioned you can do configuration, you can do multi-tenancy, you can do fleet management, upgrade your entire data center kind of in one flow. But all of this is table stakes or IT AB absolutely should be table stakes at this point.
What's on, what's next? What goes on top of this? The way we consume infrastructure cannot be manually creating VLANs and clicking through screens in order to deploy VMs.
It has to be designed ones repeat every time or at least modify little by little what you need and kind of get it to that state where you can design once and deploy every time. So having something like an easy to use service catalog, having orchestration that doesn't take two years to set up, having the ability to have a content library that's easy to access, whether you're talking about infrastructure service deployment or application deployment, all of this is part of what VCF nine offers. And you can take it to the next level.
All of this is by default, VCF nine. You wanna enhance that experience? Let's do it.
Let's look at things like private ai. There's a lot of buzz in the market now about using the AI to either in pharma to analyze data faster. Again, work with all sorts of different workloads.
LLMs are definitely relevant. How can you deploy that on top of the data center? There are so many dependencies when you deploy ai.
It's becoming increasingly difficult for IT administrators to tackle all of the challenges. This is what the advanced service does for you. Other advanced services include security, ransomware, recovery load balancing, all sorts of things that you can enhance your VCF experience with.
But get the basics right And let's talk about what made VCF nine this fantastic platform that you need to know about. This is the, the crux of what's new. First of all, you get one interface to private cloud operations.
So think about one console where you can do day-to-day operations, where you can manage storage, networking, all of the things that, uh, attached to that. And then when we move into that consumption layer where we wanna define services catalogs and so on, you have one interface for that as well for all of automation. And for those of you that are familiar with Aria, that's not the experience we're offering you.
We've simplified, we've made it easier to consume. We've made it a lot easier to actually configure your flows. So it's not the VCF we used to know.
The next part is we wanted you to have feature purity when it comes to running VMs and containers to the point where you don't have to think twice about which kind of workload do I need to deploy today. We've had container support for a very long time. We have something called VKS that's part of the platform vSphere you've known and loved again for about 25 years.
So between these two, VCF nine is in this perfect place to deliver all of these out of the box without any additional add-ons or without you needing to go shopping around for additional technologies. Second, we have a, sorry, fourth item on the list. We have a lot of security built in straight into the platform.
You can enhance this with any of our add-ons. But the most important part is it is built with security in mind. It's not a bolt-on.
Every single technology in there has a security work stream attached to it that our engineers are working on and constantly refining it. It also allows you to build your own sovereign private cloud. Last one, remember how I mentioned that there is no IT leader that wants things to be expensive?
We've brought cost control front and center in the platform. It's becoming easier and easier for you to track your consumption and your cost. And I'm gonna show you how that looks like in the platform.
Just a bit of a highlight on, you know, what have we done for innovation and efficiency? We've talked with a lot of customers before and after we've launched VCF nine and some of the things that they cared about was definitely, it's great that we've delivered a platform. It's great that we've kind of removed the seams between our different technologies, but have you forgotten about your core platform?
Have you forgotten kind of to really, really innovative, bring out all of those cool features that made VMware so so incredibly sexy and no, we haven't, we've worked on our memory tiering with MVME. If you're unfamiliar with this, think about it like this. You have hot pages that need to stay in memory, your expensive memory, but you also have cold pages with low rates of access.
At which point, why are those things in your incredibly expensive memory? Why not downgrade that to something like MVME that can perfectly support the rate of access to that? That means at the end of the day, you get about 40% reduction in server TCO.
And we've done this again, across different tests, across different workloads such as databases, and we've seen that almost consistently you end up needing 40%, sorry, you reduce 40% of your server TCO. So Sabina, with that feature, um, I know we're probably gonna get a deeper dive in other sessions, but how is memory tiering different than traditional VM swap for people who are familiar with that feature? This is largely how the page allocation is being done in memory as opposed to how we've done that in traditionally.
So you're thinking about you had to allocate all of the necessary memory for, um, the different workloads and how they load this into memory. Once you have all of these have open pages and what the m VME algorithm looks at is the rate of access and the rate of open across different, sorry, the rate of load across these different pages. How hot are they?
How cold are they? And it basically shifts anything that it doesn't need or it doesn't have the above a certain threshold rate of access onto the NVME drive. So you don't need to, you don't need to provision as much.
You can run it over subscription algorithm, something that you couldn't have done before. Gotcha. Okay.
On the second feature that we wanted to bring up here is the 34% lower storage DCO with global ddu. Key part here is we know that global DDU isn't necessarily that new in the market. There's any number of other storage system that had this before.
However, VS A-N-E-S-A has brought a lot of improvements. Global DIB was just the natural next step. What's interesting about this is, and again, if you're unfamiliar with how global DIB works, we basically eliminate duplicate data across the cluster in real time.
You need fewer drives, lower power and cooling and everything that's associated with when basically you have a higher storage footprint. As a result of this removal of the duplication, uh, the duplicated data, you end up with 34% lower TCO. The switching performance is an interesting one because we don't own a hardware layer per se.
We, we have virtualized switching and raving. What's really interesting about the NSX enhanced data path is that it gives you the ability to leverage the full, um, transport pipeline that we have. So at the kernel level, once you start loading data, you need to be able to process it fast enough in order to be able to take advantage of line rate switching.
A lot of how fast we process the package becomes incredibly important because if we can't process the package fast enough from our networking perspective, it doesn't matter if we have 40 gig or a hundred gig on your networking side. So what we ended up doing here is make it a lot more efficient to pass packets through our own pipeline once they get out. Again, that's what the mercy of your switching layer.
So we ended up improving it three times, coming to near line rate for the switching environment. The next one is compared to bare metal. There's an, there's an interesting statistic here.
So we've done some ML performance benchmarks and we saw that VCF retains nearly 99% of bare metal inference performance. Now think about it like this, when you virtualize full bare metal, the tolerable amount of performance overhead is about nine to 10%. That's the general standard for this.
We managed to get it down to 1% as a result of this. So you get all the benefits of virtualization, the mobility, hint, hint, v motion, the automation, the security without sacrificing GPU throughput. And all of this, by the way, you can read, there's an entire report on it.
And the last bit that we kind of brought in the core platform is this vMotion for ai. So we've had vMotion for I think 18 years if I'm to count my years, right? The very interesting part here is that we didn't have it for VGPU.
Now if you have workloads running on Vgpu, we have this vMotion optimization in place where you can do a live vMotion, even for large AI ML jobs. This means, again, a truly zero downtime environment regardless of the workload type. That's a lot of the, what our core platform is doing.
If you're in a position to think like, okay, what can I do with VCF? Clearly this is a massive platform. Clearly there's a lot of technology in there.
How can I get started? Like, what should I look at first? We have a few basic use cases that we'd like you to look at and we've split them up in these three different, uh, pillars.
First of all, we have infrastructure modernization. Basically, if you're coming from legacy environments, what would you like to think of first? For example, maybe deploy private cloud infrastructure on premises.
Like how do you do that? Like that at day zero? How do I get started?
How do I put together a green field that doesn't take months? The second one is optimizing infrastructure and operations. Again, if you don't want to keep bouncing between your different environments to troubleshoot, to set things up, to deploy VMs and containers, how can you optimize this better?
And then there's a third step. Where do you want to extend this? Most customers have a hybrid cloud strategy.
Nobody's entirely on-prem. And what we wanna do is help you go to the edge to sovereign clouds or even in the public cloud. Application modernization means have your data center, have your private cloud, have your VCF deployment, be ready to do self-service for different cloud services and for app teams, just the, the exact same way that you deploy services in the public cloud.
Like for example, you request a VPC in the public cloud or you request a slice of storage the same way you can actually make that available in VCF nine. Are you Kubernetes ready today or you'd like to be, again, I've mentioned this a few times before. You have Kubernetes straight out of the platform, and if you wanna go private AI, that also works.
Security modernization is a key topic as well. Compliance and hardened infrastructure has been something that's been difficult for companies for a very long time. Compliance has stronger and stronger rules every year and infrastructure sprawling out every year some more.
So it's constantly a catch up game, but you also have things like ladder security, intrusion prevention and detection that you want to look at. Last but not least, ransomware recovery, one of the hottest topics in data protection. How can you do this with VCF?
Now we've kind of covered the very, very general ideas of what's new. Do we have anything we wanna talk about before we dive into the, the features? Just a quick follow ups, Sabina, real quick on, uh, on your points on the three X switching performance, will you get into that in more detail or can you point to like, how are you really measuring that?
That would be great. Uh, follow-up reading. Oh, that's been actually, that's me that's been measured on r and by essentially pushing packets through our own kernel.
So assume the number up until a certain point was 20. We basically saw that go up to three times more and three times more was actually the conservative number that our product team has ended up giving us as a result. So as you do kernel optimization, one of the things that happens is how much, how encumbered is the processing of your code as a result of, again, all the in instructions you're giving it.
So this is more of an efficiency, um, report rather than anything else. And it's very easy to test because it's essentially you put an old version of this next to the new one and that's also how they've been testing to see is it getting better by essentially fluking it. So that's great and it's a great story.
It does sound more like a kernel optimization story than actually, uh, um, uh, increase in switching performance, if I'm hearing you right. Well, it is a kernel optimization in, uh, for the switching part. So coming back to what's new for the next few slides, what we wanna talk about is, again, what's in there, what are the key features that drive a modern, secure and appli application ready platform?
And you're, you're seeing these pillars again that we just talked about a few minutes ago. There are things that we've done or features that we brought that help you do infrastructure modernization. We've completely redesigned the day zero.
How do you get VCF nine installed? Um, we've completely, we've set you up with a new VCF operations console. VCF is now multi-tenant, something that hasn't been the case before.
Next up, it's a lot easier to troubleshoot. We've introduced enhanced diagnostic routines. We've introduced proper fleet management that helps you with the different deployment scenarios that you might have and helps you upgrade quickly and loss that cost chargeback and showback that you have as part of the platform.
On the app modernization bit, you have the consumption experience, you have cloud networking with VPC consumption exactly like you have it in AWS or Azure. And then self-service catalog infrastructure as code and VKS cluster management. VKS is our VMware Kubernetes service.
It's our Kubernetes, um, deployment on top of VCF and it helps you do K cluster management on top of ECF from the security modernization perspective. Three key features here, security operations dashboard, look at a glance of what's going on in your infrastructure, the configuration, compliance and monitoring and lost the identity and certificate management. Below this, we have some of the more core features that we've talked about before.
We kind of highlighted five of them. There are many, many features. The payload is about 300 plus features wide.
Again, ma major features, not patches, not fixes. So we talk about things like native recovery with vsan to vsan data protection with deep snapshots. We talk about confidential computing as part of the core.
We talk about maximizing throughput with VCF data path enhancements, the three times that we just chatted about, uh, cost performance with memory tiering and vsan, global dtu. Quick question on the previous slide. Uh, you had a few, and I think they show up on this one.
Uh, basically a few features that, you know, there's an asterisk like they're available with an RPQ. What's driving that and do you expect them to be just available to any and all customers at, at some point, like the global, do you do confidential computing? So a lot of the features that are available with RPQ, um, are designed for like the, they're, they're ready to go.
They're absolutely customer safe. However, there are still certain things that our engineering teams are working on that we'd like to make sure that they have a smooth experience with. Like for example, they might not apply for 99% of the cases.
So we want the RPQ process essentially. You can get the feature, that's not an issue. We just wanna make sure that we track that we communicate with you, we understand where you are in the usage of this feature and we guide you towards deploying this.
So it's more of a, again, especially when it comes to data-focused features or things like confidential computing, we wanna make sure that the customer has a good experience with the feature. What happens is a feature is released with an RPQ asterisk. We go through this entire process of requesting it through our teams and then usually by the next version or something along those lines, it's being released as GA with the feedback from that, um, from the previous RPQ session.
Gotcha. Let's talk a little bit about the feature. So we talk about infrastructure modernization.
What does this cover a foster deployment with streamline operations, things like data simplicity. Again, a lot of marketing terms, but I actually want to show you what's in the box. If you're familiar with VMware Cloud Foundation from the days of five to and before, I wanted to kinda show a little bit of a timeline of where we were before and where we are now.
And you'll notice that there's a little bit of a, not necessarily an equal sign, but a growth sign of what was before the Quick Start app for VCF deployment has now become this full fledge cloud foundation installer in Nino, what was before a mixed lifecycle management has now become this performance fleet management that allows you to do really a lot of different things as part of your upgrade. The Offline depot functionality that allows you to, um, work with dark side environments that a lot of our more military type customers are asking for has also been folded into this fleet management where you have a lot of options and a lot of ways to do upgrades and download packages and so on. Then we had, uh, vsan max and V storage clusters as different offerings offerings of vsan.
Now, the way you wanna look at vsan N is a technology in VCF that powers the way you store data. You want something like very, um, dense storage, fantastic. Use that part of, of VCF and that part of VS n as part of VCF.
You want to do basic primary storage with all the functionality attached to it. Fantastic. That's, again, available to you all sorts of single sign on.
Like we've, we've introduced enter ID in the past, you're gonna see a plethora of options for a single sign on nowadays and in general for identity management. And then we've also done all sorts of migration tools in the past, like the easy adoption of virtual networking that basically allowed you to stretch an existing network from a legacy environment, from a layer two VLAN based environment into VCF and help you move the gateway over. This basically now becomes, there's now functionality to that at layer three level on top of the fact that you can turn some of these into VPCs.
All of this is basically a growth story that by VVC nine you have all of these featured, they're more matured and you're able to use them with automation operation tied to them. Talk a little bit about the installer. In the past, it used to be that we had something called a cloud builder.
You needed A-J-S-O-N file, you'd load, there was basically an entire epic journey to go from what are my requirements and where do I want to go and how can I deploy my, my um, um, my VCF in my, in my private cloud. Now this has basically become a, okay, launch this, download this as a VM and start playing with it and start ask, answering some of the prerequisites. But by the way, notice how from the beginning it asks you, do I do I want to do an offline depot?
What are my depot options? If I already have a JSO, I can go ahead with that. Do I wanna do a guided workflow instead?
So it's up to you how you want to get started. You have any number of options from the beginning and you have a very mature GUI to help you go through this. Or again, the more coded version via a JS o script, um, once landed in this, you can start by deploying either VCF or VVF.
Obviously here we're gonna cover VCF. And if this is the first time you're running this at all, you, again, you still don't have those two options of I have an existing vCenter appliance and I'd like this to become a VCF deployment or do completely v uh, greenfield and just deploy, uh, VCF from scratch. Have both options, sign in and sign out.
Sorry, opt in or opt out from certain parameters. A quick question on the installer if I can ask one. Yeah.
Um, so with the, with the ability to deploy two existing infrastructure, uh, I'm assuming there's checks to make sure that you're at a version that's supported of vSphere and vCenter and, and whatever else, what happens after that import? 0, um, is it just automated to upgrade everything that you're importing or can you stage it, you know, around whatever maintenance windows, like that's the part that I haven't really understood when I've seen this installer so far. So there, that's a two part question.
So there are prerequisites by default that once, if, especially if you pointed to an old, older or previous deployment of whatever you might have, it basically goes and it looks something like this, right? So it checks, it has any number of checklists. By the way, this has, this is a slightly older view of it.
It actually is a little bit even longer nowadays. And, sorry, that's the one I was looking for. Um, all of these pre-checks are being done to see, okay, does this work?
But even before that, in order to consider an upgrade to VCF nine, you have to be on the correct version for your vSphere, your vsan, your VCF deployment, assuming maybe you're coming from A VCF deployment. 2 as you're picking up NSX into let's say, uh, VCF environment. So you have to put in the work of basically upgrading some of these and getting to the target version.
Then what happens is an import and convert process of getting from the existing version or existing, sorry, bundle of products that you might have available and converting that into A VCF deployment, assume you start with the correct versioning. What happens next is you tell it to convert vCenter into a new VCF instance, you can point it to your NSX and VSAN setup, and then it takes them basically all three, four, whatever. If you have old ARIA deployments, that's also something we can convert and then bring it into a VCF deployment.
And, and, and the reason I ask is like all of those components and upgrades, that can be a pretty lengthy and disruptive process. And so what is the recommendation for customers who might have a rather large environment with all those management components and maybe dozens or even hundreds of ESXI hosts that also are on an, you know, three nine oh version and they validated that it's on eight oh U three, but is it going to try to upgrade every single management component that you just outlined and every single ESXI host in sequence and you just have to wait for it to complete. I'm just kind of curious there, what that looks like.
So you started with the vCenter instance upgrade itself, and I think this might be a better conversation for, uh, one of the future sessions, otherwise we can really spend 30 minutes on it. But the, um, what we advises inevitably do it in a maintenance window, the vCenter part does not, as you well know, does not create any disruption to the actual vm. However, the, the bigger the environment, the more risk the same for NSX.
If you bring in N-S-X-N-S-X manager does not necessarily disrupt traffic. Traffic continues to be forwarded, but do it in a maintenance window. So far, we haven't seen a lot of issues at this stage as we imported different vCenters in, but I don't think I'd ever recommended to do it to in full production either.
I see. Thank you for that clarification. All right.
From an existing infrastructure perspective, this is kind of how it, what you were asking, like how does it work? You point it to your vCenter server, you point it to your NSX instance. If it's not connected to one, that's fine as well.
You have two options here. You can bring one that you've already had or you can deploy a new one. And then as a result of kind of all the data that you feed it in, you go through this process of, okay, what are my pre-checks?
How does this work? Are there any unsupported? Um, uh, sorry, topologies.
So for example, when we first launched this import and convert features, we weren't supporting certain type of topologies. Those have since been resolved. 2, but this would be the point where, okay, this is the configuration that we don't know how to transfer into VCF nine.
We're gonna stop here and tell you to go either fix it, change it, or abort this migration. What happens afterwards is you took the different components, you took the different technologies. Do you want the VCF operation instance?
If this is a greenfield deployment, you probably won't have a VCF ops deployment yet. So what you wanna do is deploy a new one and attach from there. But if this is your second, your third, your fifth import, then you basically say, I've already deployed my VCF operations.
Please just attach to that. So Ken, to your question from before, if you have multiple deployments, if you have multiple vCenters, what we've worked with customers to do in the past is basically take them one by one and slowly attach them to your VCF uh, environment over time and start consolidating them. It, you don't have to do them all at the same time.
You can do it usually cluster by cluster is probably the best way to do it, but again, it's a customer decision at the end of the day. Okay, cool. For the VCF automation part, same story as for VCF operations.
You start with, you have none, you wanna deploy one. There is an interesting discussion here where if you have existing area ARIA automation deployments, what you wanna do is do a migration post-deployment at VCFA. So if you're running ARIA Automation today in production and you have existing workflows, that's gonna be a separate migration and that's not going to be part of this ingestion process.
You go through all of these steps, you've imported your existing infrastructure or deployed new, you've deployed VCFA, you've deployed VCFO, you go through all of this on a standard greenfield deployment, we're looking at about four hours for the full data center deployment. What happens next? Your VCF operations is available to you.
And that's exactly where we go next. It's just, uh, question about the migration. Yep.
Save that automation. You don't get, uh, migrated existing I automations. What about I operation For our operations?
It's, again, it's also a migration process where we can pick up some of the stuff that you have there, but you do it separately out of VCF Ops. Okay, got it. Speaking of, now that you've mentioned it, the VCF operations console is your landing spot, the mo.
So the moment you've, um, you've deployed VCF nine, this is basically your main console. It's not vCenter, it's not vSphere, it's not vsan. The whole idea is to walk away from managing these individual technologies and kind of leverage this central console for all of this.
One of the first bits that you can do is, okay, again, you have a new deployment. Let's start thinking about how we wanna do our identity provider. And remember, I I told you that in VCF F five two, we introduced support for intra id.
Now we see all of this, both modern and legacy identity providers that you can set up. So go ahead and set up how you want your users to log in and out. What else can you do straight at a glance or straight away, uh, out of your VCF operations, deployment certificate management.
And kind of to the point of what I can ask before, like how do I, how do I import different pieces of my current deployment? My many, many V centers. You'll notice here that you have different data centers and all of these have also different like, um, environments that we brought in.
0 1, 0 2, 0 3, all of these are different, different V centers that we brought in. All of these you can bring in one at a time in the end. So all of these are different pieces of infrastructure that we've imported as a result of it.
That being notice also the number of V centers available here. Coming back to the certificate management, this is also how we aggregate data across the different environments. Up until this point, there wasn't one central licensing, um, view for everything like NSX, vCenter vsan.
So if you needed to, to see whether your certificates were aligned or, um, apologies, we're gonna need to edit this one out. Um, centralized certificate management wasn't available before. And if you wanted to see your, your certificate roca rotation, your expiry dates and so on, you have to consistently log into the different platforms and kind of check when any of these are gonna expire.
What we brought in is the certificate status from the different platforms. We bring it in, we present it to you here, and you get notifications, you get auto renewal status, and you get to see like at the cross of different components, where do I have the most challenges at the moment? Where do I need to go and start thinking, okay, I need to start scheduling planning for this certificate.
Uh, lack of C certificate rotation has caused a lot of issues in a lot of environments. So having this at a glance allows for, uh, IT practitioners to just go in and go like, okay, I need to worry about this. I starting with next week or next month.
One last bit. So we've, uh, we've had an entire beta program running for about seven or eight months ahead of our launch. And this was run by customers large and small.
And one of the things that we've wanted them to test was the installer and VCF operations kind of process feedback experience. And for some of these customers, VCF was entirely new. For some of them, they were existing VCF customers.
The feedback has been overwhelmingly positive, especially coming from kind of disparate environments and so on. The fact that it's intuitive, the fact that it's, um, easy to understand kind of what should I do next? How should I import this, where does it fail, has definitely been pieces of feedback that we've gotten.
That's been a lot better than in the past. Real quick on that, Sabina, can you put any numbers against like time saved? Like what is the new installer?
You, you said about four hours for a full data center deployment. 0. So there's, there's a two part.
So strictly how long, so the process that you see here, kind of all of this, when it gets from nothing to 100%, used to be also four hours in the past. Largely a lot of this is how long it takes to deploy all of the machines there. There's maybe some efficiency, some efficiency to be gained going forward, but it's largely about setting everything up correctly.
Where it has helped quite a bit is more at this stage. So when you, when you got started in the past, the cloud builder or the Excel that we asked our customers to fill in, in order to kind of get, get started, all of that was, let's say, from a product of a different era. And definitely that used to slow down quite a bit.
The fact that it's intuitive, um, allows for kind of the IT admin and the architect to go through this pretty quickly and start playing with their, their vCenter fleets. What I can share with you from customer, uh, discussions that we had in the past is customers are less concerned about how do they, not necessarily how do they convert and how do they deploy, but more like look at it, looking at their vCenter sea of, um, deployments and thinking about how do I wanna get started? So this has become a non-issue.
The four hour deployment time is something that you let it do on its own and so on. Where the efficiency becomes is creating that normalized architecture in a discussion with a large bank. What happened was they were a result of a large amount of acquisitions.
So they had a lot of different configurations for their V centers, right? So they acquired this smaller bank and it was configured like this with this kind of a security profile and so on. So when we were discussing migration scenarios, what became very obvious is this is an opportunity to deploy from scratch.
This is an opportunity to normalize the config, secure it, make it compliant again, big bang problems. And that's what's actually been, this is an enabler of, because since here you can hook in whatever vCenter you want and bring it in. Again, you have two options.
You can bring it in with all the garbage, or you can start deploying new and kind of move your VMs onto the new platform. So from an efficiency perspective, I can't say that the installer goes all that much faster. All of the steps from going from traditional legacy infrastructure to a platform-based infrastructure, however, is an enabler.
And it takes less time, Helps, helps ensure correctness. That's like one theme that I'm hearing. And and just so you know, we're trying to get away from spreadsheets and, uh, for source of truth and network automation too.
So, Well, you're gonna like some of the features that are on the roadmap, which my, uh, networking, my, my networking team would definitely complain if I start talking about it. But you'd love some of the stuff that's coming. Um, I think it, a lot of IT infrastructure runs on Excel, especially when it comes to accounting for everything that's going on.
And this is where kind of that centralized view is supposed to help. Hope that answered your question. I know I went a little bit roundabout.
Thank you. All right. So we've gone through the identity provider.
We talked about certificates, we've talked about the overall installer feedback. This is the don't trust me, we have happy customer slide. And by the way, it's uh, VMware explorer.
You're gonna see a lot more of that 'cause we're focusing on bringing as many customers that have interacted with our environment as we can. Now let's jump on application modernization. What does this mean?
It means we wanna help you deploy, deliver, and automate. So when you have to, uh, deploy a new application, there's any number of components and IT practitioners, it, um, architects don't want to necessarily deal with trying to understand everything that a developer needs, but giving them the building blocks straight out of the box becomes a lot easier for them to kind of piece it together. Remember, the primary reason why public cloud became increasingly popular is because somewhere a frustrated developer was able to request infrastructure services a lot faster than asking their IT team and 15 different tickets.
So let's do that in the private cloud as well. Similar journey map here and five two, we have, we have infrastructure as code services. We had, uh, Kubernetes support, we had container support.
And what happened with that? 0, we've we're giving you that one consumption experience. We're giving you the VPC consumption that again, looks exactly like the public cloud.
That multi-tenant, again, so many customers for so long have asked us bring multi-tenancy into the platform. And on top of that, you also have tenant-based private chargeback and showback. So if you wanna set up, set yourself up as a service provider for the rest of your organization, that's the way to do it.
You can look at the cost of a certain tenant, you can look at the cost of an application based on the amount of resources it's using. And then you end up with things like Kubernetes as a service. The console is the the one stop shop for, again, whether you want to do service deployments or you wanna set up things like, I want a new vm, or I want a load balancer, or I want a new VPC.
Or if you wanna go even further than that and deploy applications from a catalog. All of these are out of the box. This is at a glance how this looks like in VCF nine.
And we've had customer going like, I've seen this kind of thing before. How is it different than how it was before in VCF five, for example, or in our automation. One of the interesting things in the background of this, so even if this screen seems a little bit familiar, one of the things that makes, uh, the experience different is in the past, if you wanted to create automation between, let's say for deploying a vm, you needed to tie it to what kind of image do you want, how much storage and so on.
And all of those you'd have to do manually. There wasn't a hook that you can say, okay, go pull storage, go pull this, go load this image from the content library. All of this you have to set up manually for one vm.
Now it looks a little bit more like this, where you can basically point it to the resources that you need. What kind of VM class do you want? How many nodes, what kind of, um, C-P-U-G-P-U configuration that you want?
You can point it to your content library and say, okay, go load this image. And again, the entire automation flow is set up for you. So when you publish here and you say VM service, all of this is curated by you, the IT admin, the IT architect, and you get to just choose between these and notice the versioning here.
You can upgrade these over time. Like you can give them more or less options. You can limit access, for example, to an image of red hat that you don't want your, um, your team to use anymore.
Things like that. So the major differences speaking, Scott, you were asking me before like what's, what's the delta time reduction in between the fact that you don't have to do the work anymore? In this case, I know your question was about the installer, but every time I kind of have these presentations, the question is more like, okay, what's actually changed?
What's changed is the, you can set up a VM service in a matter of minutes nowadays, same for container service as well. And on top of that, if you wanna get a sense of how much does it cost, you can also put a price estimate on top of it. You can configure your, um, your usage, how much does it cost, for example, for your memory, your storage and so on.
And it presents to you what a total cost of ownership for that app, that service, that VM container VPCs are literally a one-to-one experience compared to the pub public cloud. How can you get your slice of cloud, a piece of networking that you can use straight away? We've heard customers also wanting to use this as very, very soft tenancy.
Like you isolate certain applications or certain group of applications. You know, this piece of my biotech team wants to deploy this application, have A VPC. Some of our, uh, advanced services even allow you to do specific firewalling and threat protection within that VPC as well, or at least at the edge.
So you can prevent some of this. So you have the closest, you have security closest to the VPC ingress and egress. Again, nothing too fancy about this.
You get a bunch of information about how is it working, how is it used, and so on And on top of it, you can also do that cost management at the per VPC level, the big thing, the multi-tenancy, the benefits, I'm not even gonna start talking about them because we all know them. You can slice up your entire, uh, data center or private cloud deployment as you see fit across the different organizations. But what's even better is that you can see how it's being used.
Again, we're pulling data from the different parts of the platform. This is a little bit what the result looks like. And since I mentioned it about a hundred times ahead of this slide, the, uh, the chargeback show back and cost control looks a little bit like this.
What's interesting with the cost optimization opportunity is that you can go further than just the tech that's in, uh, the VCF platform. So you can do modeling with things like, uh, the energy that it costs you to consume for that data, for that specific VM at that stage, or data center cooling. All of these are fields that you have to manually input, but it allows you to do a full cost modeling of, okay, I deploy this.
How much does it cost me? So it's dynamic when it comes to, you know, how much CPU memory storage am I using? It's static for things like how much cooling, because that's an external source of information, but divided by the correct amount.
And then you get at least, at the very least, a general average on a perm per tenant per VPC level. And then you can publish this towards, um, either whoever the BU that's using this is or the general consumer. Speaking of, let's take a look how this actually looks like at the more tenant level.
You'll notice how much am I using from a resource perspective, but also how much will it cost me? And the general trend analysis, what IT managers found interesting about this is that it allows them to do, um, their annual planning and their annual budgeting for next year based on, okay, what have we used and what's our capacity today? Am I just running a bunch of oversized VMs or can I go ahead and, you know, increase by 20% the same way I do every time from a security modernization perspective.
This is our last chapter, just a little bit more to go through. We've done a few things as usual in five two, we've done like in-service ESXI patching, we've done a synchronous upgrades and other data protection features. What happened in nine oh is we've introduced a security operation dashboard.
It's very much powered by VCF operations and this will grow more and more with the future releases to bring more security insights into it. We've done configuration compliance and monitoring. Things like config drift come to mind, data and ransomware protection via the vsan, um, feature set.
But also, uh, through some of our advanced services application, troubleshooting and insights fits into security modernization largely because again, if something goes wrong, we wanna make sure that it's quickly resolved and nobody else can take advantage of it. The security operations looks a little bit like this at the glance. It offers you kind of what CVS are open, do I need to tackle this very quickly?
And again, they're, we're tracking CVS across the platform. The host encryption mode is the next item. User permissions, authentication.
Have there been any failures? This is fantastic for somebody like a security architect or even a CISO to kind of look, is there something going wrong at the general glance and what should I be doing about this? But the really interesting one is this config drift feature where again, you have a standard, especially for compliance reasons, you have a standard of how you want these to look like.
Have we drifted, have we had somebody that accidentally introduced a new configuration somewhere else that either should have been replicated somewhere or it should have never been there in the first place? This allows you to send alerting emails, create tickets as far as, Hey, something's happened. Are we aligned with our framework still?
Are we still compliant? Can we go ahead or is this something we should go ahead and correct? One of the last things I wanna talk about is the application insights and troubleshooting where we wanna do better with troubleshooting in general.
One of the questions that we've gotten in the past was, you know, I'm used to vSphere. I'm not a network engineer, I'm not a storage engineer. Troubleshooting isn't the easiest thing to do for me when you give me this massive platform.
Well, to kind of help with that, imagine something goes wrong in your whatever application, here's a wellness application, but it doesn't quite matter overall. We know what all the components are, we know how they're connected, we know how to reach them. So what if we help you kind of troubleshoot, say there is a drop in latency today, or sorry, an increase in latency this morning.
And we try to understand what happened here and why. Normally what you do in a more legacy environment is you start going and investigating. Somebody logs in on a switch, somebody looks on the VM of everybody plays a game of hot potato, not my fault, probably networking.
And then what you open a ticket management is still wondering what's going on. This allows you to do kind of full application mapping of what's going on in there and see, okay, it looks like we can't reach the loan balancer, the the web service, the whatever. So even if it doesn't give you the full output of what happened, it gives you the very clear, these I can't reach as of this time.
Like I'm gonna narrow for you kind of the time window when this happened. The first instance of me not being able to reach whatever it was is that time. What do we do next?
And then you can isolate and go from there and you can continue your troubleshooting without that game of hot potato by the end of the day. It shows us, okay, we have this much packet drop and these are some of the issues that we've noticed. Again, simply allowing for, uh, the IT practitioner to play around and start a lot faster troubleshooting in the right place.
With that in mind, I think this is a good overview and a good, uh, place to get started, kind of understanding VCF nine. I'm curious, are there any questions or anything you'd like to cover on top of this? 0, uh, and they maybe feel a bit overwhelmed by everything you've shown today, 'cause it's a lot of new stuff for them, what's the best place to start?
Should they just poking around operations since that's now the main point of administration for everything you've showed or certain features they should check out in particular, what do you think is this way for people to start getting value out of all this new stuff they bought? You know, it, it's great that you asked that because I think it's a, it's a common ask from a lot of our customers. Like it's, it's definitely a massive platform first.
Um, there's a lot of free certificate certifications and reading and so on. We've put a lot of materials out there. So it start by deploying this in the lab, play with it.
There's a lot of good information about how you can put together kind of your own deploy, especially if you're an existing VMware customer. Talk to your rep about how you can get a lab license and start playing with it. And from a aware perspective, VCFA and VCFO are definitely the, the right place to get started.
'cause that's the part that's gonna feel overwhelming. That's the part that's gonna expose you to your entire infrastructure. And then start replicating things that you do day by day.
Like say your day-to-day job is just managing a massive VM environment. How would that look in VCFO? How am I managing my vm?
And then once you get comfortable with things, like, what I like to do is breaking things, right? I start breaking it. Does it give me the right alert?
Does it show me where it's broken? And then play with it some more. And once you get kind of comfortable with VCF operations jumps towards VCFA and starts seeing like, can I build some of my own automation?
I have this thing with Ansible in my infrastructure. Can I easily replicate it in VCFA? I have some terraform deployment here.
Can I connect the Terraform provider into my environment, my lab environment, and play a little bit with it and see how that looks like. And basically start doing the things that feel already familiar to you from vSphere, from vCenter, from vsan, from NSX, do them in V-C-F-O-V-C-F-A start getting used to it. And then for everything you have a question for, there's a ton of documentation about Quick question about, uh, application, um, modernization perspective.
So how really can reduce the complexity from this? Yeah. Because yeah, from a platform perspective, I, um, uh, some companies are thinking about the application, the deployment, and the whole lifecycle, like, you know, the CICD pipeline and stuff like that.
Mm-hmm. How the, this can be easily integrated in, uh, into, into BCF. And I know, Oh, you've, you've brought a question that I really love.
So the nice part with VCFA is that it actually integrates with GitHub. We, we leverage something called Argo cd, and you are able to link, so you, you use GitHub as, as your source of truth and use Argo CD as essentially your broker for that. So you're able to pull your automation into your CI ICD pipeline.
So if, if you have that kind of customer, we have that level of maturity. The fun part is you can actually teach your developer teams to request infrastructure through your CI ICD pipeline. Yeah.
So say, say you want a VM and you want two petabytes of storage for some obnoxious reason, and you can only allow for something like let's say one petabyte or a hundred terabytes and things like that. The nice part is that it's not only allowing you to go and request it through that pipeline again. It'll make a call from GitHub to Argo CD to VCFA.
What happens next is what am I allowed to do here? You know, requester X has requested two petabytes of data. I'm allowed to give it about a hundred terabytes.
It provisions the a hundred of terabytes. It sends a notification saying, here's your a hundred terabytes. Great.
And as a result, you also get you the IT manage, sorry, the, uh, IT architect or vSphere admin. 9 that's missing, what do you wanna do next? So you both have that level of control that if you put your, uh, blueprint in place, um, this is all we're gonna give you.
But you also know like, hey, there's a need for more. What do you wanna do about it? And it's all part of the CICD pipeline from the developer perspective.
They don't have to open a ticket, they don't have to talk to you. They don't have to do anything. That's great.
And the other thing is that is about, uh, the integration with, uh, the brownfield scenario. So, uh, I was thinking about the integration with the enterprise, uh, software. Like, you know, you talk about the security improvement, security and also the, um, monitoring and the operation.
So sometimes you yeah, in a auto company, uh, things are be tracked by, for example, by Jira, by Atlas, and by the other software. So is there any integration, native integration or people, uh, should do this manually or with a third party tools or, you Know, best answer I can give you here is that it depends. Yeah, depending on the provider, depending on which version as in we're looking at integrating with more and more providers, I think it's really specific to what the customer has.
And with some we do. Yeah. And in some we don't.
And with some we will in the future. The idea is to have a open ecosystem where we work with our partners and make it easy to do, again, automation left to right, not just within our platform. So if it's not doing it, sorry, if it's not working now, it might be on the roadmap.
Thanks, Sabina. We're really looking forward to digging a little deeper into each of those topics. Remember that you can always connect with us in the chat here and talk with the presenters who are going to be, uh, presenting the various sessions throughout the day to day.
Next up we're gonna look at the best practices for adopting and deploying VCF nine, whether it's in a Brownfield environment or whether you are starting completely from scratch.