Techstrong Gang – October 10, 2024
In today’s episode, the gang discusses challenges of disaster recovery in the era of extreme climate change, the Nobel Prize committee awards two prizes for work using AI, and finally, we are in San Diego covering QSC with Qualys. Alan meets to discuss the new TruRisk management ROC (Risk Operations Center).
Transcript
Hey, everyone, don't cry for me. I'm in San Diego, not Florida, where I'm at. The Qualys QSC event will be, and I'll be, we'll be live from the gang at QSC today.
But we're also gonna talk about how all of these hurricanes are, are affecting, uh, it disaster recovery, and AI is winning Nobel Prizes, all that and more. You're watching Textron Gang. Hey everyone, good morning.
It's an Ellen Shimo from sunny San Diego, not war or, or storm Red seem to be ravaged Florida. I'm here for the Qualys QSC event, and in our C block today, I'll actually be down on our, at our Tech strong TV booth at the QSC event interviewing, uh, some folks from Qualys about what they're calling a rock a risk operation center. And, uh, we'll have more, we'll have that, but we have a lot more of our usual text on gang coverage today.
Let me introduce you to our, our gang members present for today. First of all, I'm on the West Coast with them, but there could be only one star of Silicon Valley. It's our very own John Swartz.
Hey John, how are you? Hey, Alan. Welcome to California Hope, uh, state is treating you well.
My son, by the way, lives in San Diego, so welcome. Thank you. Yeah, it's nice in San Diego.
It's nice here. Um, so John, welcome. Uh, thanks for being on today's show.
Let me introduce the rest of our gang members. Our, uh, our next gang member is from Austin, and she's in her backup map as it turns out today. Um, she's on her backup map.
It, it's our, uh, Ann Alhoa War. Did I get that one right? Am I getting closer?
You're getting, you're getting closer and a ho award. Yeah. Every day.
Every day. I find, every day I turn that dial a little more in I'm getting there. You're, it's, it's fine.
I, I appreciate the effort. It's a hola. It's, uh, my father was from Finland.
Yep. And It's, I don't even know how to pronounce it correctly. I've been corrected a hundred times saying it by my relatives.
It's okay. It's all good. But more importantly, it's great to have you here, Anne, and thank you very much.
Thank you so much. And then joining us from, you know, old hurricane news location up in North Carolina. It's our own Mark Kel resident AI guru and cloud expert marketing and so many other things.
Hey Mark, I'm glad to see you in the pink and Well, I hope everything is almost back to normal up in your neck of the woods. Yeah, and in the center of the state. We're good.
But I'll tell you, western North Carolina, there are whole towns that are gone. So, but we're doing good here in, uh, outside of Raleigh. Good, good to have you on.
And, and thanks for being here. So guys, as I mentioned up at the top of the show, our first block today deals with climate change, right. And how these intense storms and, and this one coming right now, this Milton is look like it's gonna be a monster.
Um, but how these intense storms, storms are kind of changing the equation for disaster recovery, which let's face it was a bit of a disaster. It's been, you know, there hasn't, you, you never know your disaster recovery doesn't work until you go to from a disaster. So you haven't been affected too much by recent climate change disasters.
But what do you think about, you know, how is this affecting disaster recovery? I think that it's, you know, we're seeing so many disasters, natural and manmade, that have made it imperative for organizations to have more robust data protection strategies. I think that traditional mesh methods like scheduled backups, disaster recovery plans really aren't sufficient as they once were to safeguard our data, uh, in the face of escalating threats.
So I think that if we are not protecting data as organizations, then that's gonna lead to severe consequences, um, and financial losses. So I think that this is a, is making everybody sort of rethink those plans. Yeah.
Hey, mark, what about you? Yeah, You know, it's interesting 'cause uh, you know, nothing is ever really new. And I grew up in the shadow of Three Mile Island back in those days when we had the, uh, um, the meltdown or the, the re the, the leak, everybody called it a meltdown.
But, um, uh, my former boss worked at, um, for Ross Perot at, uh, EDS, and they used flew in helicopters and pulled, pulled, uh, drives right out of the data center and flew away with them. Um, I mean, I, I think that the problem is just getting exasperated by climate change and just different things that are going on. I think there's some really upside to the technology we have for earlier response in a lot of ways.
Um, you know, Google released, uh, graph cast, I think it was called last year, and they have better forecasts. But the thing I think we really need to do is leverage this technology and this data so that we can, you know, figure out cause and effect and, you know, do the things that prevent us from having, you know, Miltons and Helenes and all these other things. Uh, I I was really, you know, growing, living here in North Carolina, I have not seen that kind of carnage in the us It's probably Katrina.
I mean, it was, it's town's wiped out. But, um, I'm very hopeful because I think it's a matter of us taking the data we have, taking the technology we have, and not just having better early warning, but start figuring out, is it cal flatulence jets data centers with AI in that are causing these problems and get a cause and effect and have a real like, preventative plan so that we're not in this situation as often as we are today. So you're, you're saying let's get at the root cause of, of, of these storms.
John, I'm sorry, go ahead. Oh, I was gonna say, what's, what's really scary to me is the, the severity of these storms are escalating. They're getting more, more and more powerful.
Yet a lot of the companies that have data recovery plans are more traditional, I think, which is a root of the story. So we have this combination of climate change intensifying the technology, perhaps not keeping pace, or not as up to date as it was before. And I'm wondering, I'll throw this out to all y'all.
I think Mark rep mentioned it like the element of ai or even something like, uh, digital twin, something that could probably help, uh, in terms of data recovery going forward, because this is gonna get worse. I, I'm afraid so in Florida and other states. So I, I'm not, I'm not one of those people who say we can't stop climate change, but I have become one of those people that say it's probably taken us, taken us 150 years of industrial pollution to get into this mess, and it's gonna take us probably at least half of that or longer to get out of that mess.
So while doing something to reverse the effects of climate change overall is worthy, and, and we absolutely have to make it a priority as a, as the human race. And, and we need our political leaders to find the will to do what needs to be done. That's a whole separate thing, specifically on how we can prepare better for disaster recovery in terms of it, I think is, is another piece of this puzzle.
com days. We helped take a company an A SP that operated data centers and managed infrastructure. And what always, what always freaked me out is, you know, back then we had tape backup and a lot of the tape backups would, uh, you know, you know, those machines with the robotic arms that would move and, um, you know, we could restore you from backup in one day, half a day, an hour, two hours.
It was all nonsense. When push came to shove and you actually had to do a, a big time restore from backup, you found out just how fragile and crappy that rest, you know, restore from backup worked. And so I don't know if we've ever really gotten disaster recovery, right.
Even before these latest effects of climate change. And so now it's only worse with, with what we have. The other thing is when we're looking to build data centers that run off the, the three mile island, I don't know, mark, if you were on our show when we discussed this, right?
Microsoft just contracted Yeah. The island to take all the output of what used to be Three Mile Island. Now they've given it a, uh, or Norwell truth kind of new name.
But, um, you know, when we're building data centers in extreme locations to take advantage of temperature or water or power output or what have you, and you combine that with, you know, the volatile climate that we have, something's gotta give. We've gotta be a lot smarter, a lot smarter about what our disaster recovery plans are, how realistic they are, and then how, how we, how we do them, right. How we implement them.
And so, you know, I think we've gotta get it's time to get real about disaster recovery is, is my kind of thought on this. You know, You know, what terrifies me though is the, the, the, the prospect of somebody winning the election who doesn't believe in climate change and dismantling segments or elements of the government, which I think is a, a possibility. Um, that to me is, is the, is more scary, as scary as the, the storms themselves.
But I'm, I, I won't go too political, but I I do think we should mention that. I I agree with you. I mean, and, and that's only one of very scary things around this election.
Yeah, I know, but Right. I mean, that, that's, I I mean that's it's lot. That's number one.
If you, if you have an administration, an official policy that climate change is not real, me is not real, that climate change is not, you know, majority manmade, how can we ever hope to deal with the root causes that Ann and Mark are referring, we're talking about here as well as, you know, getting the, the political will and national, uh, kind of direction on what disaster recovery should look like. How can we successfully do disaster recovery going forward? And, you know, yes.
Let's, you know, I I, I don't even want to get too political either, but Yeah, I know, I know. The fact that, you know, you're talking about the US economy and the US government being held by an administration that may not believe that climate change is real just takes this to a whole different level, a whole different level. Um, let me ask you this though.
You know, one of the things that I think the, the disaster recovery teams have kind of bet the farm on is the idea of redundancy, decentralization, the ability to, you know, have data spread across multiple data centers and geographies. And, you know, the idea of, hey, if this node goes down, we have re enough redundancy in our system to make up for it. You know, it's inexpensive.
It, it, it definitely adds a layer of expense to your, your IT planning. But given the realities of, of climate change today, and these storms, should every company be doing that, Everybody that wants to handle disruption in operations well, wants to do that. But, you know, it's real easy to say, yeah, I want to do that while we see hurricanes going through.
And it's really hard to do it when earnings are coming up and you're like, you know, triple redundancy at Amazon is even more than triple the cost. And so, you know, it's like anything else in life is, you know, you could have a plan for that. I think data is one of those things that even in, uh, the non, the, the thing that's more concerning is people that are non-technical and understand that they think they have backups.
Well, you know, there's a lot of people that in this story, they have backups, but they have them in a room in a locked closet next to the data center where the live data is, and maybe they have it on a server somewhere offsite. But, but yeah, it's, it's, you know, redundancy is expensive and you, you tend to be, uh, overly cautious when it's brought to light and under cautious when you have other things front of mind. Yeah.
Hey, I'm sorry, I might have dropped there for a second. Do you, do you guys hear me? Yes.
Okay. Yeah, I think it was climate change was, was a hurt in the internet for a little while, Alex. Yeah.
Well, yeah. I just can't get away from those Florida connections, but, um, but yeah, you, I mean, you know, this is a risk management equation to me, right? Yes.
The, the cost of redundancy and decentralization can be substantial. What is, what is the risk of, of a disaster, you know, taking down your IT infrastructure for a period of time. And I, I think that, you know, when we get right to the heart of it, I think that's the nitty gritty of it.
Well, and what is the, what is the risk of depending on another organization to do it for you? You know, the hosts that I have recommended for WordPress sites for a very long time is WP Engine. Mm-Hmm.
They bought into a giant, uh, spat with, uh, Matt Mellen and with the WP Foundation that's now being litigated. And, you know, I found out not through WP Engine, who I've sent a fair amount of business to, I found out through just reading the tech news that there's litigation and they're no longer going to allow WP Engine to update certain plugins and their freezing features. So, as somebody who doesn't have expertise in security and has depended on those daily backups for WP Engine, it, it just sort of reminds you you're vulnerable if you're depending, I mean, we always have local backups, but still, you know, I now can't update my site because of a spat between two powerful people.
It's just sort of, you know, it's sort of eye-opening, how you have to be careful not only how you handle your it, but you also have to be careful who you trust. Well, and that's always the case in it, right? And, and just full disclosure, we used to be a WP Engine customer we left a couple years ago for not because of this spat with the WP with the Word Press folks, but, um, it was exactly over backups and their, their technical response.
'cause we were growing to the point where we really needed a little bit more and we weren't getting it there. So, um, but in, in any event, look, this is, this is a real problem and it's not going away, right? We're not gonna slot solve climate change, not here on the Textron gang anyway.
And, um, this is what we're dealing with. So some good articles in the notes for, for us to check out. But, um, let me just say this.
Obviously the health and safety of humans is probably more important than the, the redundancy or your ability to, uh, to restore your IT infrastructure. And with the storm bearing down on, you know, central West Florida, um, you know, saving your life is, is job one. And then we'll save the backup data later.
Uh, I think that's my best advice I could give you. Let's take a break here on Text and gang. We're gonna come back and we're gonna talk a about some Nobel Prize winners.
That's something we talk about a lot on the gag. You're watching Textron gag. Welcome back to Textron Gang.
I'm John Schwartz in California. And yesterday, or actually Tuesday morning, we had a, a really monumental event, uh, researchers, Jeffrey Hinton and John Hop Fields whose work on machine learning led to the development of things like chat, GPT and other AI products. They were awarded the Nobel Prize in physics on Tuesday.
Their work was, uh, instrumental according to the Nobel Committee of Physics in laying the cornerstones for what we experienced today as artificial intelligence. Now, what I found particularly interesting in kind of draw, uh, comparisons to was Mr. Hinton, who's a professor at the University of Toronto and left Google last year after 10 years with the company because he's afraid of what AI can do.
So the very award he was getting was for a technology that he's warnings about. And it reminded me of, of Oppenheimer, uh, in a sense, someone who knows the technology as well as anyone telling us that we need to be careful how we use it. And in a sense, also, it's, it, it, I I talked to a couple of people in the last few days about this, and they not only made that comparison, but they also were looking at this idea that as we kind of move into the future, and as things start jumping and leaping with ai, that makes it all the more crucial that we think about the long-term implications.
And like in the case of like, say an iron, iron man, he's got the assistant speaking into his ear, telling him the consequences of what he's gonna do. And I think that's what Mr. Hinden is trying to do for the rest of us.
So again, history and the godfather of AI is kind of in a sense being compared to the fa father of the atom bomb on multiple tracks. Wow. Um, I thought what was really cool, I didn't realize that their research was actually inspired by the brain structure.
Um, and that was sort of what led to the advancements that they made in AI technology. And I think on a positive note, right, that the committee also focused on, you know, the impact of the discoveries and how, how it's made our machine learning system so powerful. So it wasn't all doom and gloom there, there were positive notes to it, but I think that's just sort of how it goes with ai.
There's always sort of a caveat, uh, and a warning because we're all still dipping our toes. And you, you know, the thing that's, that's really interesting about it is that, um, both of these, these guys have created these, um, research and neuro networks. And actually Hough Field was a contemporary of, uh, Richard Feynman who won the physics, um, Nobel Prize for physics, I think in 65 ish.
Yeah. So, um, you know, he's sort of a legacy, but their, their discoveries of what they did were, um, really interesting, like Hop Field is we, our last segment, we talked about data. The key thing about his, his contribution was it takes noisy data and puts order into it.
So it, it identifies patterns to reconstruct images and such. So, uh, um, is No is noisy shorthand for unstructured, Uh, it could be unstructured, but it's mainly means that there's, uh, um, there's probably more holes in the data and it fills it in using statistical analysis to predict and fill it in. You know, I just wanted to make sure we're clear here for our audience.
So there's, there's two Nobel Prize prizes that we're given out that are AI related, or maybe there's more. One, as we mentioned, is, is ai pa Pioneer Jeffrey Hinton, who won the physics prize, right? Uh, and that was with John Hop Field, but there was a second Nobel Prize in chemistry awarded today, and that went to Google DeepMind scientist, John Jumper and David Baker.
And they wanted for using AI to crack the code on almost all proteins, which, you know, protein and protein folding. And I mean, it's, it's a key to life, right? And, um, using AI on, on protein structure and, and cracking the code on that is, again, this is a great use of ai actually, if you ask me, right?
This is the kind of stuff where ai it can change our lives in terms of, you know, so many diseases, whether we're talking about Alzheimer's or, or MS or so forth, you know, how, how our bodies produce proteins and a little DNA off here and there when you got the wrong protein structure and catastrophe. That's it. Yeah.
So, you know, for all the time I sit here and badmouth AI and, and poo poo it, these are, these are amazing accomplishments, right? That are worthy. I'm sorry, again, mark.
Actually, there was a thirds scientist, so it was split in half. You're right about that. But Demi, uh, bu who is the, uh, founder of DeepMind, um, and John Jumper got half of it along with David Baker, who got the other half uhhuh.
And what they, what they did was, um, it's sort of cool 'cause I did a little bit of look of work. It looks like, um, the Google side and the DeepMind folks created the, the models that, that do, uh, protein folding, uh, analysis. And then David Baker, um, took those tools and made, made some, uh, design, uh, I guess leaps forward.
But, but the, the essence of protein folding in this context is, as we are with so much of science, we think that probably a lot of diseases caused by a failure in protein folding. And this allows you to simulate and, uh, design, uh, proteins that I as, and I'm really probably butchering this 'cause I'm a very simple minded guy, is it's, it's very simply, um, fixing the way proteins work so that we can prevent disease. So it's a huge, huge impact versus the AI that is creating fakes and writing stories and doing all sorts of others, uh, nonsense.
This is, this is the kind of stuff why I'm interested in the long-term AI prospects. Absolutely. Absolutely.
What a great use of, of the technology. Um, look, there's more Nobel Prizes to be awarded. I don't know if they'll be AI related, but certainly in a lot going on.
Um, John, anything else before we close out? This I, you're gonna see actually, I think can, I was gonna say, um, I think you're actually gonna see the influence of ai not just in, in these types of awards, but eventually in, in entertainment related awards, writing awards. I think this is just the beginning of AI contributing to heightened creativity in a certain sense and heightened discovery.
I mean, if you remember everything all at wa I forget how to say it, everything everywhere, All at once, That's the rocks in that section. And they won the Academy Award where AI generated by runway ml, and now, I, I had written last year, I'm like, I can't, I'm pretty sure that it won't be too long before we'll see a, uh, academy Award won by ai Mm-Hmm. Tools and production.
If Milli Vanilli can Win, great. Maybe special effect Emmy, You know, it's true. Anne, Talk about it was taken away later about fake, fake music and fake news.
Anyway. Well, I, I'll I I'll tell you something. Um, look, will we see AI as times person of the year?
Is it right to still call it person of the year? Is it times intelligence of the Year? Is it, you know, That's inevitable.
Yeah. You know, instead of people using AI to win the Nobel, is it someone, is it Google's AI that wins the Noble for curing some disease or something? You know, You know, it's gonna happen eventually.
Maybe there'll be a national book award that that's won that's won by, by a name. It turns out it was, it was written by ai. Yeah.
Just like anonymous, you know, that could happen. Yeah. I, I, you know, I think, look, we are in many ways in uncharted waters here, right?
And, uh, we'll, we'll have to see where that goes. All right. Let's, um, let's take a break here on, uh, on this.
And we're going to come back and I'm going to set us up for our Qualys, uh, QSC interview. You're watching Textron Gang. I'm Bonnie Schneider, sustainability contributor to the Textron Group.
I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong Research.
Hey, everyone. All right, back here on Text Strong Gang. As I mentioned at the top of the show, I am out in San Diego this week for the Qualys, uh, QSC event.
And our next segment, I I actually am gonna be on the QSC floor at our tech drunk TV booth. And I will be talking with, uh, and Naem Islam around the big news here at Qualys QSC, where Qualys is announcing what they term the rock, ROC, uh, the Rock, not, not Dwayne Johnson or anything like that, but ROCK stands for Risk Operation Center. And when you think about it, well, you're of course already have Knocks and SOCs, right?
Network Operation Centers, security Operation Center. Do we need another operation center? Is Rock, should rock be part of soc or have we gotten to the point where Rock is a standalone, uh, OC And, and we're gonna talk to the, our Friends of Qualys about it.
And here's that interview now. Hey everyone, it's Alan Shovel. We're here in San Diego at the Qualys QSC event, and I'm excited to be here.
This is probably my, I don't know, seventh or eighth QSC event in the Americas over the years. It's always a great event, a great event for learning about security and seeing what's new in the security space. Um, for those who aren't familiar, we're gonna jump into what Qualys QSC is and what some of the big news coming out here today is.
If you've been following along, we've been streaming live from QSC since yesterday, and we'll continue today following the Textron Gang with our, uh, live broadcast from here in San Diego. But for now, I want to introduce you, our two guests for this special segment on Textron Gang. Um, I'm gonna start to my far right, introduce you to Naem Islam Naem.
I hope I got that name right. Yes, you did. I went with the easy one first because I can get a little confidence.
Naem your product manager, uh, for cloud security. That's correct. Yeah.
So, um, I'm, I'm, I've been at Qualis for, uh, about a couple of years. Uh, came as a part of an acquisition in AI and, uh, which we've integrated into our, uh, total cloud, cloud security product. Um, and, um, very happy to be here.
Absolutely. And we we're gonna talk more about ai, and we have been talking about ai. Obviously everyone talks about ai, what we do more than, uh, we want even.
But, um, today we're gonna talk about enterprise true risk management. And if we're gonna talk about that, this gentleman is the guy to have here with us. It's Mayor Meyer Ari.
Yep. Thank you so much. Right?
Yeah. I'm de how are you? So talk to us a little bit about your background.
Absolutely. I've been in the cybersecurity industry for the last 20 plus years, uh, you know, fairly new at callers. Um, uh, I'm leading the, uh, you know, launch of our true risk management platform, enterprise tour risk management.
And this is really not taking the risk management strategy to the next level for call, right. Of, and I can, uh, certainly go into the details of what we really mean by a risk operation sector. Uh, but, uh, I'm re I'm VP of product management here, managing the enterprise service management of it.
Very good. And we are gonna jump into that. Before I do though, I, I realize, you know, our audience, they mean, I think most of our audience knows who pharmacists, right?
Wallace has been around. I, my background is security as well. I've been in security almost 30 years.
There was a time where one of the companies I co-founded, uh, in the vulnerability management space. We were a big Qualys competitor early 2002, 2003. Interesting.
Over the years, became very good friends with eb. And then, uh, there've been, you know, covering Qualys since I started this company 10 plus years ago. The QSC has for a long time been Qualys, uh, a platform to announce new products, give their thoughts on where the direction of the security industry is, but most importantly also to get some FaceTime one-on-one time with customers and one on many time too, right?
Correct. Um, I know this is the QSE for the Americas, but you guys do one usually in India and Asia back and, and one in Europe, Europe As well. Yeah, it's a global thing.
It's a, it's a series that we have Mm-Hmm. And it's our way to, um, two things, as you said, announce, um, new products, um, tell the industry where the company is headed, but also connect with customers. And so we also have advisory board meetings that we do strategic product partners.
Um, that's another thing to remember that we also have a very strong partner program, and we're actually in the partner pavilion right now. Yes. So this is, uh, um, you know, very important for Qualys, uh, success, but it's an opportunity for us to bring everyone together and then really interact with them, meet with them, and, um, and, and really, uh, do we do training and have many one-on-one sessions with customers.
So it's a, it's a two-way interchange. It's never one way, but it is, the one in the Americas is probably the largest. It's a, it's an, it's a, it's a it's a great event.
Yeah. You know, I was, I was recently at another user conference from a you other fairly, uh, you know, public company security and DevOps space. And it was an inter, I was talking to their CEO and he said something very interesting to me.
He said, the, the customer interaction that take place at these conferences, fuel product direction and company strategy for the next year, because this, as much as you are giving them what you are doing, they're telling you what they need done. And, and so that two-way information and, uh, sharing is as I think really the kind of the dirty little secret, if you will, about these kinds of conferences. You learn as much as you give Here.
Yeah. I think that's important because, you know, we're a customer first company. Mm-Hmm.
So learning what the customer needs, particularly getting as broad a view of that as possible is pretty critical to our success. Um, so that, that's, uh, I couldn't agree. Is there more?
Absolutely. So let, let's turn though to the big news though. And then the big story in terms of product coming out of this year's QSC Americas is the debut of the, uh, risk operation center, uh, as part of enterprise true risk management.
Schmidt, there are a lot of words in there, but how would you describe exactly what this is? Yeah. So, uh, let me set the background first.
Uh, tool sprawl in security industry is real. I, um, and the, the, the a reason for that, you know, roll back the time a decade ago, two decades ago, and infrastructure was all that organizations had to manage, you know, scan and patch then came around the software that was deployed on that infrastructure, right? And that, that they, those came with vulnerabilities as well.
Now, with the digital transformation and everything moving up into the cloud, what's happening is modern cloud architectures are bringing to life new digital assets that also need to be managed uncured. These assets can range from anything, starting from Europe know container workloads, uh, you know, identities mis, you know, uh, and dozens of new things that show up in the, um, uh, you know, cloud space. Now, uh, security industry has responded graciously by creating a specialized tooling to secure every single digital asset type.
Right? You know, there is an, We like to think, you know, anyway, right? There's A identity security solution.
There's a container security solution, right? You know, there, there, there's a AI security solution. Now, it is important to have these offerings.
However, uh, you know, when you really look at it, are they working in uni? That is what, uh, is really, uh, you know, challenging for many of, uh, organizations. Um, risk management strategies are oftentimes fragmented.
I would like to really draw an analogy with a SOC security operation center, which is a pretty well understood, uh, concept in an organization. What it does is it indeed takes threat incident data, right? By events from multiple different tools for the purpose of aggregation, correlation, enrichment, to really figure out a coordinated incident response plan.
Similar strategy does not exist today in the proactive risk management side. And that is indeed what a risk operation center is. Our strategy with the launch of enterprise tourist management offering is to really provide that, I would say cybersecurity operating system that really focuses on risk reduction programs, collecting cyber, uh, you know, security posture management information from the specialized tools that we discussed earlier, bringing it all into the same, uh, risk plane so that you can normalize them and reach them and really create a coordinated risk response as opposed to threat response.
We are really looking at the proactive side of things so that your, your vulnerabilities and misconfigurations don't get exploited in the first phase. That is what the concept of a risk operation center really is. And now it's risk operation in the cloud.
But, you know, risk doesn't exist only in the cloud, right? And so I'm imagining you're pulling, uh, data in from the agents on endpoints, threat intel, and, and, you know, all kind of the traditional things. So I'm of two minds of this stuff, right?
And as I mentioned, I've been in security a long time. I think one of the problems that security in general has suffered from is that for a very long time, especially when I first got involved in security, you know, 30 years ago, security was not always part of it, right? It was got separate.
It was, it was oftentimes part of risk. And risk management was not an IT function. Risk management, some, a lot of times came out of the CFO's line, right?
And that, and so there was this unnatural silo, unnatural wall between security, IT risk, and it, and then what happened, we realized that security had to be, it was too close to it. It had to be part of it. And so all of a sudden, the rise of the ciso and the CISO many times has their own seat at the, uh, exec table in other organizations.
The CISO used to report to A CFO now started reporting to the ccio. And a lot of, in some organizations, the CIO and CSO role merge, like into the same person, right? Um, when we went that path, though, we bifurcated security for risk.
Okay, security, you can go, go be part of it, but risk, that's still a financial decision. And so I'm wondering if what we're seeing now is the other shoe dropping, saying, Hey, you know what, risk is bound to it as well. The, the, you may make financial considerations in terms of managing your risk, but the information that you need to make those decisions live in, live in the, it, live in the cloud operation center in your, in your soc, in your not right.
And, and that really what this is, right? Are we seeing risk now move to the IT side of the house? Yep.
You know, we wouldn't have to talk about risk if, um, organizations were able to patch every vulnerability, fix every misconfiguration, right? We wouldn't have to talk about that. The, the reality on the ground is, uh, customers, our customers have to deal with 50 million, a hundred million findings, right?
And there's just no humanly possible way to fix a mark. And now you have to really have that risk dialogue to understand what is the meaningful, uh, or impact of these vulnerabilities and misconfigurations in my organization. So security data is one thing, but when you process that security data, it has to be contextualized for your organization, right?
In terms of what is the impact of a loss? Should I incur one? And that is where risk management strategy sort of blend into the security response that organizations often derive, right?
Uh, uh, you are absolutely right. These functions have sort of, um, uh, you know, shifted between multiple different teams in an organization, but with a risk operation center, what we envision is, um, you, you know, supporting three different functions to a single platform, the CE continuous threat exposure management, the CRQ, the cyber risk quantification, because, you know, what do you do with risk? You either eliminate the risk, um, the, you know, you accept the risk that I'm okay with this risk, or you actually transfer the risk, which is, you know, buying cyber insurance.
So having this comprehensive view of what that risk means from a financial impact to my organizations is really important. And that is where the cyber risk quantification comes in. And last but not the least is you really want to have an automated compliance platform that really allows you to identify, uh, uh, you know, audity or regulatory risks to the business as well.
So these are the three key pillars of a re risk operation center. Uh, and a single platform like enterprise to risk management is going to enable organizations to derive these insights from a unified Gotcha. Yeah.
I, let me add a couple of things to that. That's, uh, these actually, right? So it's a complex situation that I think we have this whole organization now involved in risk.
It used to be siloed. You had this silo of, uh, finance looking at risk as a purely business thing, and then you have it that had an operational thing to fix. With, with Rock, everything is coming together where we have a tool that can address many different issues.
But, but, but with major breaches occurring in so many organizations, everyone in the organization is now part of the security team, if you will. Um, if you look at it, some of the, we have this notion of DevSecOps. Now, the developers are now responsible.
Finance is responsible, legal is responsible. Um, there is a security team, but everyone is part of the solution. Security is Everyone's responsibility.
It wasn't that way until they, we had these large breaches and everything was breaking, you know, all hell was breaking loose, if you will. Um, so I think our, this is our attempt to bring it together, um, to put some structure in the madness and giving an organization an opportunity to think through how they can address these issues systematically throughout the organization and actually have something for every stakeholder. So it's a different view that, that I think we, we've created here.
com about 10 years ago, is I recognize that for security to be successful, we had to get the developers thinking security. We had to get the ops teams thinking security and test teams. And even, yes, the HR and the sales and the business teams everyth, And then with the cloud, you know, and agile development, because everything goes is all API driven.
There's no physical stuff that you, it, it's all really, really fast. Yes. And so the other thing that's not on your side is time.
So you don't have time to think, you don't have time to do anything. In fact, everyone is going at lightning speed. There's chaos in the organization, and there's an, there's this opportunity, if you will, for companies like us to help put some method in the madness.
But, but I think it's all very agile, the whole process. Yeah. And I wonder in some sense, I'm not a finance guy.
Well, the entire organization with all these tools have become very agile and things are going really fast, and you have to have some automated way to get your arms around the risk in real time, if you will. Yeah. Which to me screams ai.
So let me throw that back at you. How big is, how big a role does AI play in the, uh, rock, you know, true risk, uh, formula. It is really foundational because at the end of the day, what we are really looking at is, uh, aggregating risk signals from multiple different diverse tools.
Um, uh, aggregation is just the baselining. However, what you really need to do is correlate that data with threat intelligence. Um, how are these vulnerabilities and risk configurations being exploited out there in the world, right?
Are there threat actors who have actually weaponized these vulnerabilities? Uh, you know, using this information allows organizations to really surface the most meaningful risk that their teams limited number of resources that they have can actually focus on today. Finally, the business context that we talked about, it's really unique to every organization.
You know, Don, you don't have a security tool that can provide you with that data set, right? It know every organization has their own way of organizing the structure, you know, figuring out which business units these applications assets belong to. And we overlay this, uh, contextual data on top of the raw security data that, uh, you know, we pull in from multiple different tools.
So AI plays an instrumental role in stitching all of these together, because when you are really looking at, uh, millions and billions of findings and misconfigurations that need to be remediated, this is again, no humanly possible way to analyze them all. You really need to look into the AI to have, uh, if provides you recommendations of here's a plan of action that would potentially reduce your risk from here to here. Uh, that's, uh, what risk Operation Center does.
Absolutely. Hey, we're about out of time. I'm, you know, we, we, you've been talking about this yesterday.
We'll continue talking about it today. I do wanna emphasize though, this product is available now, this isn't pie in the sky, it's in ga. com, you can find out all about it.
Gentlemen, thank you for joining us on Textron Gang today, and, uh, enjoy the rest of QSC. It was a great, it's been a great show. Thank You so much for having us.
Thank You. All right. Thank you so much.
Thank You. Hope you enjoyed our tech Strong gang show today. We are gonna take a break.
We'll be streaming live the rest of the day or following in about an hour or so. Uh, here from San Diego's Qualys is QSC day two coverage. But for now, this is Alan Shovel for Textron.
Have a great day, everyone. All right. So I gotta tell you, I'm having a ton of fun out here at Qualys.
QSC there. Always put on a good event. I will mention though, Mike ards not here, but I did get to go to the Padres Dodgers game last night while I was out here as well.
And that was a great game. Six five, uh, Padre's win. And there wasn't a seat empty in that stadium.
It was crazy. Um, but look, Qualys big news is, is the, the birth of the rock, if you will. And, um, I don't know if any of you want to chime in on what you think about it or if you, you know, do we, do we need yet another operation center here?
Is, is what is a rock part of the SOC mission? I not a hundred percent sure myself, but you know, I know better than to call what Quas does. Crazy.
'cause I remember calling what they did crazy back in 2002 and three, thinking that they were gonna store other people's vulnerability data up, up, not OnPrem that we didn't call it a cloud then, but on someone else's servers, uh, with the Qualys operations center, if you will, or the Qualis network. So I don't know, mark and John, any thoughts on rocks? So I have maybe I'm, I'm that old guy saying get off my wall in these days, but back in the nineties when I, I did have, I worked for an ISP and I ran the, uh, well the knocks under me.
I feel like there, there was always a benefit for having one point of contact, whether it was power outage in the building or network outage in our network. So I think having security within the NOC framework, or, and I, I use not generically back then it was network. But let's just say I, I don't know what was the IROC or which was a Camaro in 1983 to be, I Remember the iroc.
Yeah, but I, I, I really think having, uh, you know, a digital operation center that is well integrated across your network, your, you know, all of your business had an, uh, and, and we have big call centers. I had ran about nine call centers in nine different states and we really benefited not just from the network, but having outages. You know, Phoenix got a dust storm and it blocked all the microwave digital transmission.
So all these people went offline or there was a floods in Texas and it took out something, the power or whatever. Um, I think having security as a, as an equal footing with any kind outage is good. But from a practical operations state and right now, I, I will preface that with I cause security problems.
I don't fix them anymore. Yeah. So, um, I, I am speaking a little out of turn, but I, I do think having that integrated into your overall IT operations center is, is important.
I don't know if it standalone always scares me. 'cause silos coming from the DevOps world, right, are not always, are really not a good thing in my experience. Good stuff.
Ann, John, any thoughts or, or we'll move on going once, twice, three times. Ann, you sure you were about to say something? Well, I would say just, he brought up Texas.
So of course as a Texan I have to talk about Texas 'cause that's what we do. Uh, it was just announced in the news that we are apparently not too good to join the National Grid any longer. Uh, the Department of Energy has a $360 million, uh, project basically to connect us to the US grid as we don't wanna, um, a redo of snowpocalypse.
It was a little embarrassing for us. Yeah, well I'm surprised they're taking the federal money, but that's a whole nother story. Um, anyway, but look, maybe this makes, maybe this puts risk management on par with security and, and operations and some other stuff.
We'll see. Anyway, hey, that's gonna call a wrap on this day's text. John Gang, we hope you enjoy your Thursday.
We'll be back tomorrow with the weekend, uh, wrap or the Friday, you know, heading to the weekend wrap up show. Until then, John and Mark, thanks for joining us. Thank you out there for watching us from San Diego.
This is Alan Schmo for Textron Gang. We're out.


