AI, Ransomware & User Empowerment | Security Boulevard Ep. 1
The Security Boulevard Podcast brings together leading voices in cybersecurity to explore the latest threats, challenges, and innovations shaping the digital landscape.
Each episode covers key trends including:
-
The rise of AI in both defense and attacks
-
Ransomware tactics and evolving adversaries
-
Software supply chain security
-
Cloud, DevSecOps, and modern infrastructure risks
-
Real-world insights from industry experts and practitioners
Whether you’re a security professional, developer, or business leader, Security Boulevard delivers timely discussions and expert perspectives to keep you informed — and ahead of emerging risks.
🎧 Subscribe and watch every episode to stay updated on the future of security.
Transcript
We're past that they can't write down their biometrics to give to someone else. So let's improve security. Let's really step up and innovate in this industry.
Welcome to Security Boulevard, a cybersecurity podcast from The Future Room Group. Each of our episodes discuss a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms.
My name is Tom Hollingsworth. I'm the event lead for Security Field Day and other events at the Tech Field Day Group, which is a part of the Futurum Group. And we are relaunching the Security Boulevard Podcast to bring you some discussion topics about everything that's going on in the cybersecurity world.
I'd like to take a minute for my co-host to introduce themselves so that you understand the voices that you're listening to on this particular episode. Mitch, why don't you let everybody know who you are? Great.
So we're starting with the a's I'm Mitch Ashley and, and, uh, I lead the analyst practice for Software Lifecycle Engineering, which you might say, well, why is he on a security podcast? Actually, I've been in security since the late nineties and developed security products that operated in the federal government, uh, in the, uh, in the security sector. Um, but also my li my life has been about developing products, trading products for the internet, SaaS services, et cetera.
And I actually cover, uh, the software security, uh, supply chain security angle, um, working with my compadre and, and friend Fernando Montenegro. Uh, perfect segue, and then, uh, stole my thunder on, on us working together. But that's perfectly fine.
So, I'm Fernando Mogra. I lead the, the, the broader cybersecurity and resilience practice here at futu. And, uh, I've, I've, I have the gray hair that, that have been around cybersecurity for a very long time.
Right? And, um, yes, this is a, this is an opportunity to have a, a, a broader conversation on all things that are happening in terms of, uh, of technical and organizational and cultural security and whatnot. And kind of like Mitch, I'm, uh, uh, I mean, I've been around since the nineties as well.
And, uh, um, the, the differences that you don't want to see code that I write, I, I see Mitch's code. It's really good. My code, no.
Alright. And you're probably wondering, well, why is Tom hosting this podcast? Well, uh, I'm very similar to Tron.
I speak for the security users, the practitioners out there who are facing the day-to-day challenges that my distinguished colleagues here are researching and reporting on. And, uh, I've spent a lot of time over my career involved in security, uh, working with, uh, solutions and trying to make them work, which is probably why, unlike Fernando, I just don't have any hair left. And so the idea behind what we're doing here is we wanna explore some of these topics a little bit more in depth.
Let's be fair, you don't need another podcast that just recaps all of the breaches that happened this week. Um, you know, that, that first of all, that episode would be like two hours long. But more importantly, it doesn't get into the why and the how and the understanding behind all of this.
So, while there may be some news things that we bring up from time to time, we're really gonna kind of dive into topics around cybersecurity and spend, I don't know, maybe about a half an hour discussing one or two of them and giving you a better understanding so that you, you can understand how to go along with your day. Speaking of the day, one of the things that I love to do is I like to go find some of the weird wacky days, because every day of the year has something associated with it. And in case you were wondering, uh, today's National Chewing Gum Day, which I was told by our wonderful podcast producer, Corey, that if I chewed gum on this episode, that he would fire me.
So, Corey, that one's for you buddy. Uh, also it's National Hot Mold Cider Day, which I figured would've been a little bit deeper into October. But, you know, if you, if you wanna have a glass of something warm and refreshing while you listen to this podcast, go for it.
Uh, I kind of wanna start off with, with a fun topic here, because if you're listening to this, because you were subscribed to the Security Boulevard Podcast channel before, uh, you know, that it's been a, a little bit since our, uh, our last episode came out, uh, probably what about 18 months. Uh, but even before that, you know, the, the face of cybersecurity has really changed over the last, I don't know, four or five years, uh, basically since the pandemic, it feels like someone put their foot on the gas. And we haven't slowed down since.
I kind of wanna throw this to my co-host. I'm gonna start with you, Fernando. What was one of the biggest changes that you've seen over the last five years in the cybersecurity landscape?
Uh, I, listen, I, I, people, I make fun of it, but like, ai, alright, fine, I got the word out. Uh, meantime to time, to AI in this episode was what, a minute or two content wise, 30 seconds. Not even that, but, um, absolutely, it's been a change.
Uh, it's all over the place. And, um, it's one of those areas that is affecting, like, the way that we're structuring it at at ura, if we're talking about AI in, in three different buckets, if you'll, there is the AI for security. Take your typical security pro, uh, product, whatever it might be, there is a usage for AI in there somewhere, right?
Maybe it's triage, maybe it's writing better or, or finding code vulnerabilities, maybe it's data classification, whatever, right? That's the AI for security piece. There is the security for AI piece, which is block, you are doing AI within your organization at scale, uh, of some scale, or maybe it's a pilot.
Maybe you're further along. You need to secure that AI deployment. That's one.
Uh, and that's all the, Hey, let's protect against model poisoning. Let's protect against the, uh, uh, prompt injections, et cetera, et cetera, et cetera. Right?
And then the third one is, even if you don't do anything else, right? We are, one of the major changes in the past five years to bring to your question is adversaries have been using ai, right? So we've seen derive in, in, in potentially deep fakes.
Uh, we, but we've also seen, uh, the application of, of AI to shorten time from CVE to POC, uh, to, to proof of concept exploits and so on. So absolutely massive change on technology as it relates to ai. There's others, but I don't wanna ho the, the, the mic too long, Mitch.
What's up? You know, we could, we could name a lot of things. Um, I think because that's what I'm focusing on my practice, I'll bring up the, the, the convergence of security and the software organizations and thinking about software security software, supply chain security as part of the overall security of an organization.
You know, we, we live forever. We we're really good at silos and we live forever. And, you know, software developers live here and security people live over here.
They don't talk to each other. They dunno the same language. They don't even know what each other's talking about.
Well, now that, that, those things have, have started to get knocked down. And we talk a lot about open source security, we talk a lot about security of the code that we develop. We talk a lot about security of the tool chains that we use to create software, because of course, guess what's being wooded?
The new attack vector, one of the new attack vectors is that the developers and people involved in creating software themselves. So open source projects, things like that. So you already see, you know, like the, uh, the, uh, link foundation, uh, collaborating with o Open Source Security Foundation, collaborating on creating a baseline of what projects should implement for better security, et cetera.
So it, it's a topic that we now talk about. And I think more collaboration is happening. Security isn't just picking tools for developers to use, which they won't use.
And developers aren't ignoring security all the time because they've gotta ship code. I'd say those are both really good. And, and yes, we've seen that huge evolution for me.
I think the biggest one is, is empowering users to be more secure. And I, I know it kind of sounds a little trite, but if you think back to, you know, five years ago was the pandemic. Um, we have accelerated security since then.
And, and I wanna give you an example. It's actually something we discussed on a podcast last week. The idea of pass keys.
Um, the reason why that stands out to me so much is because it combines PKI, excuse me, it combines PKI with biometric authentication and inherent two factor authentication. And Mitch, to your point, like you, you talk about the fact that people are using attack vectors to get into development environments. Now, the reason why is because it's actually getting really hard to break in the front door by guessing people's passwords.
Like, you know, now I can authenticate to my login system using my phone through my face, which is inherently trusted because there is a TPM module in my phone now, and I can use all of that together to ensure that nobody's able to intercept my two-factor code or, you know, guess a seed value for a key generator. And I think about that because when you look at the way that users treat security now, compared to the way that they did it six or seven years ago, it's night and day different. Like, you know, we all joke about the, the regular anti phishing training that we all have to take, but we've at least gotten to the point now where the average person knows how to spot those kinds of attack vectors, right?
Like, they can tell that this is a sloppily written, uh, attempt to get my password or something like that. In fact, they're getting pretty sophisticated to be able to beat the average levels, uh, of notification and notice that people have. So I think that overall we've gotten better at security through tooling, through education and things like that.
I, I guess that the question that comes up though is if, if we've gotten so good at fixing all of these things that have changed in security, why are we still facing challenges? Oh, this is a good one. Uh, oh, we can go down the rabbit hole from this, uh, my, my personal take if that, I, I agree with everything you said.
The reason I, I think that we have been talking about cybersecurity in, uh, in, I'll, I'll, I'll frame it this way. Do we have the right expectations of what good cybersecurity is, right at, uh, at, and, and, and that can mean at different levels. It can mean at the individual level, what's good cybersecurity for you.
There's a level of, within your organization what's good cybersecurity for your organization. And I would argue that there's a level of society, what's good cybersecurity for society, right? And I think that we continue to have incidents the same way that we continue to have car crashes, that we continue to have airplane incidents, that we continue, god forbid, to have, uh, uh, uh, uh, people die in hospitals, right?
Uh, I think that the issue is, is the rate that we are seeing bad things, uh, worse or better than what they were before. Like, yes, we're seeing bad things, I agree. But if we're seeing bad things at, uh, we're seeing a few bad things.
But given the scale of what we're doing with technology, is it, uh, uh, is it just something that perhaps okay, overall it's gotten better. Yes, there will always be incidents that I think that's a, that's a question we haven't answered as an industry, right? I'm, I'm, and kind of like you, I'm really optimistic about how things have improved over the past few fi few years.
But yeah, we still have stuff to do. But, um, yeah, the, the, the, the, the broader point to me anyway, is that we will con if we, if we expect, uh, a very low or zero or rate of cybersecurity incidents, that's, that's, uh, that's an unfair burden on the industry. And, and that's going to set us up for failure.
I think that the biggest problem we've seen so far is that you and Mitch and I, we've all had, uh, and, and, and others, like, we've all been deploying this, but what are the expectations that our end users have of us, right? If they expect us to be perfect, oh my goodness, we're going to fail miserably. Sorry, that's a No, I, I agree with you about Number One, I agree with you about the, uh, the, the frequency of incidents matter of fact, reporting a new incident is really kind of nonsense.
That happens so frequently and people don't respond to it anymore. Who cares whether this bank had an incident or this, whatever grocery shopping chain had a one. You know, it happens every day.
It happens. So often people don't pay attention. It's not news.
What's news is somebody, somebody implementing something new that might help with it might help address it. You mentioned pasties Tom, which is a great example of that. And, and I think we're reaching, I don't think we've got, we're there yet, but we're starting to reach a level of damnit somebody has to do something about it, right?
And it may be an inconvenience for people, but it's something we have to do. Who didn't know 20 years ago that passwords were extremely insecure and it just ratcheting up the algorithm slightly to lengthen the password, require special characters and numbers and blah, blah, blah. You know, that, that, that wasn't even, you know, that wasn't even a patchwork or sticking your finger in the d**e, right?
Really? Yes, that's marginally helpful, but that's not really the problem. 'cause people can get access to those pa password using a password manager, as you mentioned, just had one password on the security field data you just had.
Um, who's got a really great browser plugin that makes it a little easier, little less, uh, cumbersome to, you know, put passwords into your system. We use pass keys now. We see things like I mentioned earlier, of software projects starting to require certain security standards before they submit 'em.
Um, there's also some discussion now around MCP model context protocol within the AI world of, we see exploits happening. It wasn't like anybody didn't know those were gonna happen. We knew there were security issues in the standard, but it got adopted quickly.
We're people are starting to respond to address that. So my point being, Tom, is I think the days of we're gonna train users and we're gonna solve the problem by having more informed and better, uh, better acting users, users are not the problem. Yes, if they write passwords down and, you know, share 'em, okay, but we're past that.
They can't, they can't write down their biometrics to give to someone else. So let's improve security. Let's really step up and innovate in this industry.
And I think you're right. The, the overall tenor of security has gotten a lot better. And to Fernando's point, uh, I think one of the reasons why we're hearing that there are more and more breaches is because we're getting better and better at finding them, right?
Like, even something as ridiculous is the SolarWinds hack. Like, we may not have caught that years ago, and this time we at least knew what to look for, and we found it relatively quickly and Mandiant was able to report on it and the, the, the, the loopholes were closed. But that's good, right?
Like, if, if we're detecting more disease, we can cure it. Even if we don't know how to cure it now, we can cure it in the future. And, and I, I know that people feel like it's a never ending drumbeat of, oh crap, here's another breach.
Here's my data. Uh, I'm, I'm sure you guys are in the same boat that I am. I have enough free credit monitoring from all these breaches that like my great grandkids will have free credit monitoring forever.
Um, but to me, I think The, the real trouble is that with our hyperconnected world, a breach has the capability of causing so much more damage. And like, you know, something as stupid as, oh, well, they were able to get access to the service account. That's a member of the backup operators group and active directory.
Oh, which by the way, has the ability to read everything in the organization. We've started having to shift our thinking and security less about keeping people out than keeping people from moving once they get in. You know, it's, it's that old mentality of, uh, there's a building on the University of Oklahoma campus that was built in the 1960s, and one of the quirky things about it is that the stairwells that go from the first floor to the fourth floor don't connect to the stairwells that go from the fourth, the fifth to the ninth floor.
And I asked somebody about that one time, I'm like, why would you do that? And they said, oh, well, when this building was built in the 1960s, there was a real chance there was gonna be a riot on campus. And so you can go into the upper floors of the building and completely locked down that floor where the interchange happens, and you can be protected.
Nobody can get up there like the sides of the building, the first floor, four, four floors look like a concrete bunker. I'm like, oh. Like, I, I guess I've never had to think about that as a security practitioner, but that's where we're at now with things like Zero Trust and, and other security paradigm shifts.
It's no longer about, oh, well, Fernando wants, he has the right password, or the VPN client he can get and do whatever he wants. Now it's like, if something were to happen to Fernando's user id, how can I create a system so that nobody can jump through all the right hoops to, I don't know, steal our research or something like that. Like, we've, we've literally started thinking about that and it, it feels like that's a huge projection into where security is gonna go A hundred percent.
And I argue that I go back to what are the expectations we're asking people to do. Um, if, like, I, I've, uh, I'm not sure if any of you play sports, right? Or if any of you have done martial arts or whatever, right?
But you can still win a fight in martial arts while taking blows, right? And as you practice in martial arts, I, I say this because I did karate for a few years, right? You, you, you, you trained to be hit, right?
And you win by Yes. You, you, you absorb that hit and, and, and you keep going, right? I think that some, I think about that a lot in the context of what we're doing, Tom, it's exactly, exactly what you said.
It's not about game over because Fernando's password has been compromised, or Fernando's token has been stolen. It's, does our organization have the necessary, uh, defense in depth and monitoring in depth and response at the right timescale to handle, Hey, Fernando's account was compromised. Oh, look, now somebody is looking at what repos Fernando have access to.
Oh, look, they've done a few commits adding a, uh, uh, adding a call to a JavaScript library that doesn't really belong here. Oh, look, that now they push this to production, right? Uh, uh, the expectation that we are going to completely avoid the problem in the first place, and we're done.
That's something that we need to change. And I think that that goes back to the, the comment I made earlier is what expectations are we training non-security professional, non-security team members or colleagues, or executive leadership, right? Uh, minor ran, one of the words that I dislike is the word ransomware, right?
I've, I've, I'm on record saying this. I think that back then, like five years ago, 10 years ago, whatever, right? If I told you that you have ransomware, or sorry if that you had malware, you would buy anti malware software.
If I told you you had spyware, what would you do? You'd buy anti spyware software. If I told you, now that you have ransomware, what do you do?
The expectation is you buy anti ransomware software. Guess what? There is no such thing.
Ransomware is actually a multi-stage extortion campaign by sophisticated actors against your organization. You cannot expect security teams to handle this by themselves. You need the cooperation of everybody else in the organization.
Sorry, again, I ran too much. But, um, but, but to your point, you're, you're absolutely right. It's about, okay, we defend the user here, but we understand what's going on along the way, and we respond along the way.
Thank you. Off the soapbox. No, I think it's a good soapbox to be on because it terminology matters, right?
Because if you talk to somebody old enough, they're like, oh, well my computer has a virus. Woo. We don't really get those anymore.
Like, like the, the, the technology for exploitation has evolved, right? And ransomware is different than a BitLocker, which is different than some kind of another malware function that is not designed to encrypt your data and steal your money, but, you know, look at something as advanced as stuxsnet. Like they didn't want money, they wanted to wreck stuff.
So I think it, you know, it's just like in the medical field, right? Like doctor, it hurts right here can be a very different thing for a lot of different stuff. And that's why doctors are very precise nurses too, and what terminology they use so that we can make the patient better.
I think, I think the attitude of the attackers has also changed. Yes, for forever we thought of the end users as being sort of the low hanging fruit to go after, right? With phishing attacks, et cetera.
And they still are. We all we are. Um, but it's also recognizing, uh, you mentioned SolarWinds, right?
If I can find, uh, attack vectors that once I'm in there, I get everywhere. Yes. It's like getting access to the directory.
If I can get somebody's, uh, system level account admin account, I can move laterally, get up, get, get access to the directory. There's other vectors like that too. If I can get into your tool chain in your software development cycle, which is what happened with SolarWinds is now I can ingest code that I wanna put into your code that gets distributed with your software out on the internet.
Um, so that, that was a bellwether event, not just 'cause it was widespread and that it got, that it affected a lot of customers. It was a well weather event to show that, oh, the software creation process is a great attack vector because if you can get in there now, you can get everywhere. Same thing for open source projects.
If I can get in embedded into an open source project, easy to do. Um, also, you know, there, there's injection attacks now with AI that, um, they started implementing libraries, open source, uh, source libraries for typical packages that might, that often get, uh, misspelled by an LLM when generating codes, suddenly you're linking to a library that you thought was the right one. But it's not 'cause it got, uh, typo squatted.
So we're, we're in a world where, where the attackers aren't just looking for the easiest way to get in, they're also looking for ways to get the farthest reach once they're there. And that's also important for us to consider. So it, it's a, it's a problem, if you will, that is changing continuously.
Well, I wanna take a minute to kind of discuss, uh, something that we've hinted around a little bit here on this episode. And that was the fact that we just got wrapped up with our security Field day event, the, the most recent one, uh, last week as of the time of this recording. Um, and it was funny because a lot of these things were discussed during the event.
Um, you know, we talked one password and they talked about the way that they're looking at doing identity management and security. And, and it's funny because like everyone knows one password as the, the password management people like they the vault and, and they actually spent more time talking about other stuff, which I thought was, you know, super fascinating. We talked to Square X, uh, they make, uh, browser plugins, which you think, oh wow, we're going back to flash, huh?
No, no, these are things that actually can prevent like, you know, uh, Wolfgang Gerlich, one of my friends was saying, you know, my biggest problem is, is that people install these, uh, you know, BHOs and things like that, that can then read the in-memory contents of your browser and be able to strip passwords and user IDs and things out of there. And I'm like, oh crap. That, that's the serious stuff that, that people are going after.
Um, you know, I I, I think that the value of having these regular events like Security Field Day is that we can continue this conversation about what it means to be secure. And, and not only that, but but hear from companies that are trying different new things. Like, uh, Nile Secure is a company that has been a part of, uh, some other events that we've done in the past, but like, they're coming in saying, Hey, we do security.
We can help secure your stuff because you don't have to worry about your network anymore. Like, we'll, we'll do all of that for you and include security functionality on top of it. You know, are you, are you gentlemen hearing anything in the industry that would make you think that, you know, people are still out there trying to solve these problems in a novel way?
Kind of to Mitch's point from earlier, it's like, you know, why am I making this tool if nobody's gonna use it kind of thing. You know, I'm gonna just jump in. Say I, I, I've participated in some tech field days, security field days.
I think, uh, Fernando has as well, what what what is super interesting about them, and I'm not just saying this is a company person, but what's super interesting about them is they aren't your standard sales pitch. They're not your demo from the field engineer, field CTO showing you what the product does. They're there talking about openly about what sort of the latest advances are, what they're working on next.
'cause they want feedback from the audience. They want feedback from the people, the delegates that are there. They want feedback from the people that are watching.
So if you want kind of the closest thing to inside information really inside, but you're not gonna get in your standard conversation of, for your sales rep and your field engineer to go find the person who can have this conversation with you about what are you doing about identity when it comes to ident to password management or a pass key management, uh, or, or device identity management. This is a great place to find it. So I would highly recommend people step in.
'cause that's the kind of thing you'll hear on Security Field Day. Yes. Commercial, yes.
Self-interest. But I really do believe that. I wouldn't say if I didn't, if I didn't believe it.
Oh, thank You. Unplug, Mitch. Yeah, I listen, I, I I think I'm on record saying, uh, like the, the amount of fanboy that I have over Tech Field Day more broadly, like, it, it really has defined my career.
Like, let's leave it at that and then, like, Tom heard this before when, when, when we were together. But yeah, I've, I've, I've been listening since the very, very early days and, and it's a phenomenal event precisely for those reasons. Mitch and, and Tom, you bring up, uh, uh, some of the areas that, uh, that presented at at at the last one.
Yeah, absolutely. We're seeing this evolution. Uh, we're seeing evolution in multiple areas.
Evolution driven by two things. We're seeing evolution driven by the fact that technology is everywhere. So for example, um, the, the browser security stuff, I wrote a report about it a couple of months ago.
One of the things about browser security that I find fascinating is that it's a phenomenal place for the kind of monitoring that you want to do. It's, it's not, it doesn't suffer from the fact that, oh, the network is now encrypted. So network detection, it's still possible, but it's more difficult, but it's not as detailed as, or, or it can be detailed, of course, but it doesn't, it, it captures events at a higher level of, um, of, uh, abstraction then EDR tooling, right?
So for example, you don't have to put together the thing, oh, look, process X, Y, Z or thread X, Y, z, red memory, location, A, B, C, right? You can have the, the, the, the browser look, oh, somebody read the password field. I'm exaggerating.
But, but so I, I find it fascinating. The other thing just to, just to mention that I mentioned two things. One is that it's, it's everywhere.
And the other is we're seeing, and this I I, I think this is highly positive. We're seeing security products and vendors and tooling and, and professionals be a little more attuned to the economics of things, right? It's almost 30 minutes into the session.
And, and I, I, the first time I mentioned, it's that the, the how do you align the incentives for what people need to do? How do you align the incentives that people get for what you want them to do? And, uh, uh, you ask about what's novel and and whatnot.
I think that as we be, we have this more sophisticated understanding of security, I think it's gonna be very positive. Awesome. Well, gentlemen, um, we're getting close to the end of our episode, but I wanted to give you both a chance to kind of let everybody know some of the cool things that you're working on.
'cause one of the, the key aspects of security that is super important is sometimes just keeping up with what's out there, right? You never know what you need to use if you don't know what people are working on. And you two have been doing an amazing job, uh, doing research, uh, writing reports, creating content.
So what are a couple of things that you've got coming up that people should be waiting for paying attention to? Go ahead, Fernando. Go for it.
I, I was gonna let you go first because I think, I think your research is, is coming up before mine in terms of publishing. Well, um, so, you know, as I mentioned, I covered the, the entire software development life cycle. So there's lots of areas of security being addressed from, you know, observability and how that's used in security, but also how that extends down below the line into the tool chain itself.
Um, one of the areas that I've spent a lot of time focusing on are the open standards around, uh, AI and LLM models. I mentioned MCP earlier. There's agent to agent, there's an agent, um, purchasing, uh, protocol.
There's also agent communication protocols. A lot of those protocols are, are early in their life cycle, meaning they aren't fully mature and they need additional security added to it, Microsoft announced at Microsoft Build that they were gonna be helping anthropic enterprise ready MCP, um, as part of their process, since they're still kind of holding onto the MCP keys, if you will, while other projects have been donated to the Linux Foundation or to CNCF and become more kind of open collaboration officially in that way. So you'll see some continuous updates for myself on that, as well as updates around software, supply chain security, um, have a report that's just gonna be coming out that is showing, and this is something I said early on, is we see the greatest innovation in AI being applied in the developer world.
That's where it software's being crafted. It's where natural inclination to adopting new technologies are what software developers love to do most do anyway. And, but we will see incrementally more and more AI show up in different products down the software development lifecycle, including security products.
And I don't go into the depth that, uh, necessarily Fernando would, but in my latest report analyst insight report, I'll be talking about where we're seeing AI show up and how it's being used or implemented in those particular product categories. Yeah, from, from my perspective, and, and I'll, I'll be brief. Uh, there's, there's two types of research that we do, right?
There's the, the, the more, okay, um, I'm gonna say timed, okay, what's the topic for this month kind of thing. I'm just wrapping up a report on software supply chain security. So Mitch's gonna get that for, for peer review very shortly, right?
Where we're touching on some of these things in some of these, these strengths, like one of, one of the areas I'm particularly curious about is where are we on, uh, software supply chain, like the difference between what do you need as a producer of software versus what do you need as a consumer of software, for example, right? And, and everything that flows from there. Software builds of material and, and, and, and on and on and on.
That's one type of report. Another one that we're working at, within, uh, Futurum, we have the, and, and, sorry, yes, it's a plug. We have the, the, the futurum signal, right?
Which is a new type of report that we're doing. So I'm working on, on a FUTURUM signal report on security operations platforms, right? I'll, uh, I'll, I'll, I'll leave you, uh, with that for now, but it's, um, it should be coming in early November.
I think that's when we're publishing. So I'm, I'm doing some of the research now on, on what does the modern security operation platform look like, right? Platforms is a huge area in, uh, buyer behavior, right?
People do tend to prefer buying these, these platforms. So what, what's in there actually anyway, that's, uh, that's research I have coming up. And then other than that, it's just hanging around the, the, the never ending stream on the socials and, and commenting where appropriate and, and so on.
I was adept and or not mentioning my signal report, which actually will probably be out at the time, be out probably when this, uh, podcast comes out. It's on the software development platforms, not developer tools, but thinking about the entire software development lifecycle and evaluating awaiting vendors, looking at it kind of holistically. And, you know, o over time we'll look at more depth in specific areas, security being and supply chain security being one component of that.
So while Fernando's looking at much more in depth on the security market as well as on software supply chain and his latest report that's coming up, kind of looking at it from a software perspective and where that fits in as well. Alright. com.
Uh, big things that I think you should check out, security Field a 14. Uh, the videos are actively being posted right now, so by the time you're listening to this episode, you should have some great, uh, information you can go over and listen to. Uh, we have a special exclusive event coming up with Microsoft Security talking all about Microsoft Sentinel.
That's gonna happen on the ninth. Uh, we also have our Tech Field Day experience with NetApp Insight. Uh, we also have episodes of the Tech Field Day podcast.
com or make sure that you're following Tech Field Day on LinkedIn, Twitter, blue Sky, Mastodon, you know, all of the regular places. I wanna thank you very much for listening to this kickoff episode of the Security Boulevard podcast. If you enjoyed this conversation, do the things right, subscribe on YouTube, uh, open up your favorite podcast application of choice so you don't miss an episode, even if it's just the audio only version.
And we'd appreciate if you'd leave us a rating and a review 'cause that helps the show grow and reach new audiences and new ears. com and the Futureum Group. com.
Text strong tv website or the Text Strong TV app, which is available on Apple tv, Roku, and other smart devices. Of course, make sure you follow Security Boulevard on Twitter X and LinkedIn at Security bvd. And, uh, there's gonna be lots more content to come there.
Thanks for tuning in and we'll see everybody next week.