Image Title

Search Results for Hall of Justice:

Yousef Khalidi, Microsoft & Dennis Hoffman, Dell Technologies | MWC Barcelona 2023


 

>> Narrator: theCUBE's live coverage is made possible by funding from Dell Technologies, creating technologies that drive human progress. (upbeat music) >> Welcome back to the Fira in Barcelona. This is Dave Vellante with David Nicholson. Lisa Martin is also here. This is day two of our coverage of MWC 23 on theCUBE. We're super excited. We're in between hall four and five. Stop by if you're here. Dennis Hoffman is here. He's the senior vice president and general manager of the Telecom systems business at Dell Technologies, and he's joined by Yousef Khalidi, who's the corporate vice president of Azure for Operators from Microsoft. Gents, Welcome. >> Thanks, Dave. >> Thank you. >> So we saw Satya in the keynote. He wired in. We saw T.K. came in. No AWS. I don't know. They're maybe not part of the show, but maybe next year they'll figure it out. >> Indeed, indeed. >> Lots of stuff happened in the Telecom, but the Azure operator distributed service is the big news, you guys got here. What's that all about? >> Oh, first of all, we changed the name. >> Oh, you did? >> You did? >> Oh, yeah. We have a real name now. It's called the Azure Operator Nexus. >> Oh, I like Nexus better than that. >> David: That's much better, much better. >> Dave: The engineers named it first time around. >> I wish, long story, but thank you for our marketing team. But seriously, not only did we rename the platform, we expanded the platform. >> Dave: Yeah. >> So it now covers the whole spectrum from the far-edge to the public cloud as well, including the near-edge as well. So essentially, it's a hybrid platform that can also run network functions. So all these operators around you, they now have a platform which combines cloud technologies with the choice where they want to run, optimized for the network. >> Okay and so, you know, we've talked about the disaggregation of the network and how you're bringing kind of engineered systems to the table. We've seen this movie before, but Dennis, there are differences, right? I mean, you didn't really have engineered systems in the 90s. You didn't have those integration points. You really didn't have the public cloud, you didn't have AI. >> Right. >> So you have all those new powers that you can tap, so give us the update from your perspective, having now spent a day and a half here. What's the vibe, what's the buzz, and what's your take on everything? >> Yeah, I think to build on what Yousef said, there's a lot going on with people still trying to figure out exactly how to architect the Telecom network of the future. They know it's got to have a lot to do with cloud. It does have some pretty significant differences, one of those being, there's definitely got to be a hybrid component because there are pieces of the Telecom network that even when modernized will not end up centralized, right? They're going to be highly distributed. I would say though, you know, we took away two things, yesterday, from all the meetings. One, people are done, I think the network operators are done, questioning technology readiness. They're now beginning to wrestle with operationalization of it all, right? So it's like, okay, it's here. I can in fact build a modern network in a very cloud native way, but I've got to figure out how to do that all. And another big part of it is the ecosystem and certainly the partnership long standing between Dell and Microsoft which we're extending into this space is part of that, making it easier on people to actually acquire, deploy, and importantly, support these new technologies. >> So a lot of the traditional carriers, like you said, they're sort of beyond the technology readiness. Jose Maria Alvarez in the keynote said there are three pillars to the future Telecom network. He said low latency, programmable networks, and then cloud and edge, kind of threw that in. You agree with that, Yousef? (Dave and Yousef speaking altogether) >> I mean, we've been for years talking about the cloud and edge. >> Yeah. >> Satya for years had the same graphic. We still have it. Today, we have expanded the graphic a bit to include the network as one, because you can have a cloud without connectivity as well but this is very, very, very, very much true. >> And so the question then, Dennis, is okay, you've got disruptors, we had Dish on yesterday. >> Oh, did you? Good. >> Yeah, yeah, and they're talking about what they're doing with, you know, ORAN and all the applications, really taking account of it. What I see is a developer friendly, you know, environment. You got the carriers talking about how they're going to charge developers for APIs. I think they've published eight APIs which is nowhere near enough. So you've got that sort of, you know, inertia and yet, you have the disruptors that are going to potentially be a catalyst to, you know, cross the chasm, if you will. So, you know, put on your strategy hat. >> Yeah. >> Dave: How do you see that playing out? >> Well, they're trying to tap into three things, the disruptors. You know, I think the thesis is, "If I get to a truly cloud native, communications network first, I ought to have greater agility so that I can launch more services and create more revenue streams. I ought to be lower cost in terms of both acquisition cost and operating cost, right, and I ought to be able to create scale between my IT organization, everything I know how to do there and my Telecom network." You know, classic, right? Better, faster, cheaper if I embrace cloud early on. And people like Dish, you know, they have a clean sheet of paper with which to do that. So innovation and rate of innovation is huge for them. >> So what would you do? We put your Clay Christensen hat on, now. What if you were at a traditional Telco who's like, complaining about- >> You're going to get me in trouble. >> Dave: Come on, come on. >> Don't do it. >> Dave: Help him out. Help him out, help him out. So if, you know, they're complaining about CapEx, they're highly regulated, right, they want net neutrality but they want to be able to sort of dial up the cost of those using the network. So what would you do? Would you try to disrupt yourself? Would you create a skunkworks? Would you kind of spin off a disruptor? That's a real dilemma for those guys. >> Well for mobile network operators, the beauty of 5G is it's the first cloud native cellular standard. So I don't know if anybody's throwing these terms around, but 5G SA is standalone, right? >> Dave: Yeah, yeah. >> So a lot of 'em, it's not a skunkworks. They're just literally saying, "I've got to have a 5G network." And some of 'em are deciding, "I'm going to stand it up all by itself." Now, that's duplicative expense in a lot of ways, but it creates isolation from the two networks. Others are saying, "No, it's got to be NSA. I've got to be able to combine 4G and 5G." And then you're into the brownfield thing. >> That's the hybrid. >> Not hybrid as in cloud, but hybrid as in, you know. >> Yeah, yeah. >> It's a converge network. >> Dave: Yeah, yeah. >> So, you know, I would say for a lot of them, they're adopting, probably rightly so, a wait and see attitude. One thing we haven't talked about and you got to get on the table, their high order bit is resilience. >> Dave: Yeah, totally. >> David: Yeah. >> Right? Can't go down. It's national, secure infrastructure, first responder. >> Indeed. >> Anytime you ask them to embrace any new technology, the first thing that they have to work through in their minds is, you know, "Is the juice worth the squeeze? Like, can I handle the risk?" >> But you're saying they're not questioning the technology. Aren't they questioning ORAN in terms of the quality of service, or are they beyond that? >> Dennis: They're questioning the timing, not the inevitability. >> Okay, so they agree that ORAN is going to be open over time. >> At some point, RAN will be cloud native, whether it's ORAN the spec, open RAN the concept, (Yousef speaking indistinctly) >> Yeah. >> Virtual RAN. But yeah, I mean I think it seems pretty evident at this point that the mainframe will give way to open systems once again. >> Dave: Yeah, yeah, yeah. >> ERAN, ecosystem RAN. >> Any RAN. (Dave laughing) >> You don't have to start with the ORAN where they're inside the house. So as you probably know, our partner AT&T started with the core. >> Dennis: They almost all have. >> And they've been on the virtualization path since 2014 and 15. And what we are working with them on is the hybrid cloud model to expand all the way, if you will, as I mentioned to the far-edge or the public cloud. So there's a way to be in the brownfield environment, yet jump on the new bandwagon of technology without necessarily taking too much risk, because you're quite right. I mean, resiliency, security, service assurance, I mean, for example, AT&T runs the first responder network for the US on their network, on our platform, and I'm personally very familiar of how high the bar is. So it's doable, but you need to go in stages, of course. >> And they've got to do that integration. >> Yes. >> They do. >> And Yousef made a great point. Like, out of the top 30 largest Telcos by CapEx outside of China, three quarters of them have virtualized their core. So the cloudification, if you will, software definition run on industry standard hardware, embraced cloud native principles, containerized apps, that's happened in the core. It's well accepted. Now it's just a ripple-down through the network which will happen as and when things are faster, better, cheaper. >> Right. >> So as implemented, what does this look like? Is it essentially what we used to loosely refer to as Azure stacked software, running with Dell optimized Telecom infrastructure together, sometimes within a BBU, out in a hybrid cloud model communicating back to Azure locations in some cases? Is that what we're looking at? >> Approximately. So you start with the near-edge, okay? So the near-edge lives in the operator's data centers, edges, whatever the case may be, built out of off the shelf hardware. Dell is our great partner there but in principle, it could be different mix and match. So once you have that true near-edge, then you can think of, "Okay, how can I make sure this environment is as uniform, same APIs, same everything, regardless what the physical location is?" And this is key, key for the network function providers and the NEPs because they need to be able to port once, run everywhere, and it's key for the operator to reduce their costs. You want to teach your workforce, your operations folks, if you will, how to manage this system one time, to automation and so forth. So, and that is actually an expansion of the Azure capabilities that people are familiar with in a public cloud, projected into different locations. And we have technology called Arc which basically models everything. >> Yeah, yeah. >> So if you have trained your IT side, you are halfway there, how to manage your new network. Even though of course the network is carrier graded, there's different gear. So yes, what you said, a lot of it is true but the actual components, whatever they might be running, are carrier grade, highly optimized, the next images and our solution is not a DIY solution, okay? I know you cater to a wide spectrum here but for us, we don't believe in the TCO. The proper TCO can be achieved by just putting stuff by yourself. We just published a report with Analysys Mason that shows that our approach will save 36 percent of the cost compared to a DIY approach. >> Dave: What percent? >> 36 percent. >> Dave: Of the cost? >> Of, compared to DIY, which is already cheaper than classical models. >> And there's a long history of fairly failed DIY, right, >> Yeah. >> That preceded this. As in the early days of public cloud, the network operators wrestled with, "Do I have to become one to survive?" >> Dave: Yeah. Right. >> So they all ended up having cloud projects and by and large, they've all dematerialized in favor of this. >> Yeah, and it's hard for them to really invest at scale. Let me give you an example. So, your biggest tier one operator, without naming anybody, okay, how many developers do they have that can build and maintain an OS image, or can keep track of container technology, or build monitoring at scale? In our company, we have literally thousands of developers doing it already for the cloud and all we're doing for the operator segment is customizing it and focusing it at the carrier grade aspects of it. But so, I don't have half a dozen exterior experts. I literally have a building of developers who can do that and I'm being literal, here. So it's a scale thing. Once you have a product that you can give to multiple people, everybody benefits. >> Dave: Yeah, and the carriers are largely, they're equipment engineers in a large setting. >> Oh, they have a tough job. I always have total respect what they do. >> Oh totally, and a lot of the work happens, you know, kind of underground and here they are. >> They are network operators. >> They don't touch. >> It's their business. >> Right, absolutely, and they're good at it. They're really good at it. That's right. You know, you think about it, we love to, you know, poke fun at the big carriers, but think about what happened during the pandemic. When they had us shift everything to remote work, >> Dennis: Yes. >> Landline traffic went through the roof. You didn't even notice. >> Yep. That's very true. >> I mean, that's the example. >> That's very true. >> However, in the future where there's innovation and it's going to be driven by developers, right, that's where the open ecosystem comes in. >> Yousef: Indeed. >> And that's the hard transition for a lot of these folks because the developers are going to win that with new workloads, new applications that we can't even think of. >> Dennis: Right. And a lot of it is because if you look at it, there's the fundamental back strategy hat back on, fundamental dynamics of the industry, forced investment, flat revenues. >> Dave: Yeah. Right. >> Very true. >> Right? Every few years, a new G comes out. "Man, I got to retool this massive thing and where I can't do towers, I'm dropping fiber or vice a versa." And meanwhile, most diversification efforts into media have failed. They've had to unwind them and resell them. There's a lot of debt in the industry. >> Yousef: Yeah. >> Dennis: And so, they're looking for that next big, adjacent revenue stream and increasingly deciding, "If I don't modernize my network, I can't get it." >> Can't do it. >> Right, and again, what I heard from some of the carriers in the keynote was, "We're going to charge for API access 'cause we have data in the network." Okay, but I feel like there's a lot more innovation beyond that that's going to come from the disruptors. >> Dennis: Oh yeah. >> Yousef: Yes. >> You know, that's going to blow that away, right? And then that may not be the right model. We'll see, you know? I mean, what would Microsoft do? They would say, "Here, here's a platform. Go develop." >> No, I'll tell you. We are actually working with CAMARA and GSMA on the whole API layer. We actually announced a service as well as (indistinct). >> Dave: Yeah, yeah, right. >> And the key there, frankly, in my opinion, are not the disruptors as in operators. It's the ISV community. You want to get developers that can write to a global set of APIs, not per Telco APIs, such that they can do the innovation. I mean, this is what we've seen in other industries, >> Absolutely. >> That I critically can think of. >> This is the way they get a slice of that pie, right? The recent history of this industry is one where 4G LTE begot the smartphone and app store era, a bevy of consumer services, and almost every single profit stream went somewhere other than the operator, right? >> Yousef: Someone else. So they're looking at this saying, "Okay, 5G is the enterprise G and there's going to be a bevy of applications that are business service related, based on 5G capability and I can't let the OTT, over the top, thing happen again." >> Right. >> They'll say that. "We cannot let this happen." >> "We can't let this happen again." >> Okay, but how do they, >> Yeah, how do they make that not happen? >> Not let it happen again? >> Eight APIs, Dave. The answer is eight APIs. No, I mean, it's this approach. They need to make it easy to work with people like Yousef and more importantly, the developer community that people like Yousef and his company have found a way to harness. And by the way, they need to be part of that developer community themselves. >> And they're not, today. They're not speaking that developer language. >> Right. >> It's hard. You know, hey. >> Dennis: Hey, what's the fastest way to sell an enterprise, a business service? Resell Azure, Teams, something, right? But that's a resale. >> Yeah, that's a resale thing. >> See, >> That's not their service. >> They also need to free their resources from all the plumbing they do and leave it to us. We are plumbers, okay? >> Dennis: We are proud plumbers. >> We are proud plumbers. I'm a plumber. I keep telling people this thing. We had the same discussion with banks and enterprises 10 years ago, by the way. Don't do the plumbing. Go add value on the top. Retool your workforce to do applications and work with ISVs to the verticals, as opposed to either reselling, which many do, or do the plumbing. You'd be surprised. Traditionally, many operators do around, "I want to plumb this thing to get this small interrupt per second." Like, who cares? >> Well, 'cause they made money on connectivity. >> Yes. >> And we've seen this before. >> And in a world without telephone poles and your cables- >> Hey, if what you have is a hammer, everything's a nail, right? And we sell connectivity services and that's what we know how to do, and that both build and sell. And if that's no longer driving a revenue stream sufficient to cover this forced investment march, not to mention Huawei rip and government initiatives to pull infrastructure out and accelerate investment, they got to find new ways. >> I mean, the regulations have been tough, right? They don't go forward and ask for permission. They really can't, right? They have to be much more careful. >> Dennis: It is tough. >> So, we don't mean to sound like it's easy for these guys. >> Dennis: No, it's not. >> But it does require a new mindset, new skillsets, and I think some of 'em are going to figure it out and then pff, the wave, and you guys are going to be riding that wave. >> We're going to try. >> Definitely. Definitely. >> As a veteran of working with both Dell and Microsoft, specifically Azure on things, I am struck by how you're very well positioned in this with Microsoft in particular. Because of Azure's history, coming out of the on-premises world that Microsoft knows so well, there's a natural affinity to the hybrid nature of Telecom. We talk about edge, we talk about hybrid, this is it, absolutely the center of it. So it seems like a- >> Yousef: Indeed. Actually, if you look at the history of Azure, from day one, and I was there from day one, we always spoke of the hybrid model. >> Yeah. >> The third point, we came from the on-premises world. >> David: Right. >> And don't get me wrong, I want people to use the public cloud, but I also know due to physics, regulation, geopolitical boundaries, there's something called on-prem, something called an edge here. I want to add something else. Remember our deal on how we are partner-centric? We're applying the same playbook, here. So, you know, for every dollar we make, so many of it's been done by the ecosystem. Same applies here. So we have announced partnerships with Ericson, Nokia, (indistinct), all the names, and of course with Dell and many others. The ecosystem has to come together and customers must retain their optionality to drum up whatever they are on. So it's the same playbook, with this. >> And enterprise technology companies are, actually, really good at, you know, decoding the customer, figuring out specific requirements, making some mistakes the first time through and then eventually getting it right. And as these trends unfold, you know, you're in a good position, I think, as are others and it's an exciting time for enterprise tech in this industry, you know? >> It really is. >> Indeed. >> Dave: Guys, thanks so much for coming on. >> Thank you. >> Dave: It's great to see you. Have a great rest of the show. >> Thank you. >> Thanks, Dave. Thank you, Dave. >> All right, keep it right there. John Furrier is live in our studio. He's breaking down all the news. Go to siliconangle.com to go to theCUBE.net. Dave Vellante, David Nicholson and Lisa Martin, we'll be right back from the theater in Barcelona, MWC 23 right after this short break. (relaxing music)

Published Date : Feb 28 2023

SUMMARY :

that drive human progress. of the Telecom systems They're maybe not part of the show, Lots of stuff happened in the Telecom, It's called the Azure Operator Nexus. Dave: The engineers you for our marketing team. from the far-edge to the disaggregation of the network What's the vibe, and certainly the So a lot of the traditional about the cloud and edge. to include the network as one, And so the question Oh, did you? cross the chasm, if you will. and I ought to be able to create scale So what would you do? So what would you do? of 5G is it's the first cloud from the two networks. but hybrid as in, you know. and you got to get on the table, It's national, secure in terms of the quality of Dennis: They're questioning the timing, is going to be open over time. to open systems once again. (Dave laughing) You don't have to start with the ORAN familiar of how high the bar is. So the cloudification, if you will, and it's key for the operator but the actual components, Of, compared to DIY, As in the early days of public cloud, dematerialized in favor of this. and focusing it at the Dave: Yeah, and the I always have total respect what they do. the work happens, you know, poke fun at the big carriers, but think You didn't even notice. and it's going to be driven And that's the hard fundamental dynamics of the industry, There's a lot of debt in the industry. and increasingly deciding, in the keynote was, to blow that away, right? on the whole API layer. And the key there, and I can't let the OTT, over "We cannot let this happen." And by the way, And they're not, today. You know, hey. to sell an enterprise, a business service? from all the plumbing they We had the same discussion Well, 'cause they made they got to find new ways. I mean, the regulations So, we don't mean to sound and you guys are going Definitely. coming out of the on-premises of the hybrid model. from the on-premises world. So it's the same playbook, with this. the first time through Dave: Guys, thanks Have a great rest of the show. Thank you, Dave. from the theater in

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
DennisPERSON

0.99+

MicrosoftORGANIZATION

0.99+

DavidPERSON

0.99+

DavePERSON

0.99+

David NicholsonPERSON

0.99+

Yousef KhalidiPERSON

0.99+

Lisa MartinPERSON

0.99+

Dave VellantePERSON

0.99+

David NicholsonPERSON

0.99+

Dennis HoffmanPERSON

0.99+

YousefPERSON

0.99+

DellORGANIZATION

0.99+

Jose Maria AlvarezPERSON

0.99+

CapExORGANIZATION

0.99+

John FurrierPERSON

0.99+

AT&TORGANIZATION

0.99+

BarcelonaLOCATION

0.99+

TelcoORGANIZATION

0.99+

Dell TechnologiesORGANIZATION

0.99+

36 percentQUANTITY

0.99+

36 percentQUANTITY

0.99+

GSMAORGANIZATION

0.99+

ChinaLOCATION

0.99+

siliconangle.comOTHER

0.99+

yesterdayDATE

0.99+

EricsonORGANIZATION

0.99+

AWSORGANIZATION

0.99+

theCUBE.netOTHER

0.99+

2014DATE

0.99+

Eight APIsQUANTITY

0.99+

next yearDATE

0.99+

NokiaORGANIZATION

0.99+

HuaweiORGANIZATION

0.99+

CAMARAORGANIZATION

0.99+

SatyaPERSON

0.99+

thousandsQUANTITY

0.99+

MWC 23EVENT

0.99+

third pointQUANTITY

0.99+

Mobile World Congress Preview 2023 | Mobile World Congress 2023


 

(electronic music) (graphics whooshing) (graphics tinkling) >> Telecommunications is well north of a trillion-dollar business globally, that provides critical services on which virtually everyone on the planet relies. Dramatic changes are occurring in the sector, and one of the most important dimensions of this change is the underlying infrastructure that powers global telecommunications networks. Telcos have been thawing out, if you will, they're frozen infrastructure, modernizing. They're opening up, they're disaggregating their infrastructure, separating, for example, the control plane from the data plane, and adopting open standards. Telco infrastructure is becoming software-defined. And leading telcos are adopting cloud native microservices to help make developers more productive, so they can respond more quickly to market changes. They're embracing technology consumption models, and selectively leveraging the cloud where it makes sense. And these changes are being driven by market forces, the root of which stem from customer demand. So from a customer's perspective, they want services, and they want them fast. Meaning, not only at high speeds, but also they want them now. Customers want the latest, the greatest, and they want these services to be reliable and stable with high quality of service levels. And they want them to be highly cost-effective. Hello and welcome to this preview of Mobile World Congress 2023. My name is Dave Vellante, and at this year's event, theCUBE has a major presence at the show made possible by Dell Technologies, and with me to unpack the trends in telco, and look ahead to MWC23 are Dennis Hoffman, he's the Senior Vice President and General Manager of Dell's telecom business, and Aaron Chaisson, who is the Vice President of Telecom and Edge Solutions Marketing at Dell Technologies, gentlemen, welcome, thanks so much for spending some time with me. >> Thank you, Dave. >> Thanks, glad to be here. >> So, Dennis, let's start with you. Telcos in recent history have been slow to deliver and to monetize new services, and a large part because their purpose-built infrastructure could been somewhat of a barrier to responding to all these market forces. In many ways, this is what makes telecoms, really this market so exciting. So from your perspective, where is the action in this space? >> Yeah, the action Dave is kind of all over the place, partly because it's an ecosystem play. I think it's been, as you point out, the disaggregation trend has been going on for a while. The opportunity's been clear, but it has taken a few years to get all of the vendors, and all of the components that make up a solution, as well as the operators themselves, to a point where we can start putting this stuff together, and actually achieving some of the promise. >> So Aaron, for those who might not be as familiar with Dell's a activities in this area, here we are just ahead of Mobile World Congress, it's the largest event for telecoms, what should people know about Dell? And what's the key message to this industry? >> Sure, yeah, I think everybody knows that there's a lot of innovation that's been happening in the industry of late. One of the major trends that we're seeing is that shift from more of a vertically-integrated technology stack, to more of a disaggregated set of solutions, and that trend has actually created a ton of innovation that's happening across the industry, or along technology vendors and providers, the telecoms themselves. And so, one of the things that Dell's really looking to do is, as Dennis talked about, is build out a really strong ecosystem of partners and vendors that we're working closely together to be able to collaborate on new technologies, new capabilities that are solving challenges that the networks are seeing today. Be able to create new solutions built on those in order to be able to bring new value to the industry. And then finally, we want to help both partners, as well as our CSP providers activate those changes, so that they can bring new solutions to market, to be able to serve their customers. And so, the key areas that we're really focusing on with our customers is, technologies to help modernize the network, to be able to capitalize on the value of open architectures, and bring price performance to what they're expecting, and availability that they're expecting today. And then also, partner with the lines of business to be able to take these new capabilities, produce new solutions, and then deliver new value to their customers. >> Great, thank you, Aaron. So Dennis, you and I, known you for a number of years. I've watched you, you're are a trend spotter. You're a strategic thinker. I love now the fact that you're running a business that you had to go out and analyze, and now you got to make it happen. So, how would you describe Dell's strategy in this market? >> Well, it's really two things. And I appreciate the comment, I'm not sure how much of a trend spotter I am, but I certainly enjoy, and I think I'm fascinated by what's going on in this industry right now. Our two main thrusts, Dave, are first round, trying to catalyze that ecosystem, be a force for pulling together a group of folks, vendors that have been flying in fairly loose formation for a couple of years, to deliver the kinds of solutions that move the needle forward, and produce the outcomes that our network operator customers can actually buy and consume, and deploy, and have them be supported. The other thing is, there's a couple of very key technology areas that need to be advanced here. This ends up being a much anticipated year in telecom. Because of the delivery of some open infrastructure solutions that have being developed for years. With the Intel Sapphire Rapids program coming to market, we've of course got some purpose-built solutions on top of that for telecommunications networks. Some expanded partnerships in the area of multi-cloud infrastructure. And so, I would say the second main thrust is, we've got to bring some intellectual property to the party. It's not just about pulling the ecosystem together. But those two things together really form the twin thrusts of our strategy. >> Okay, so as you point out, you obviously not going to go alone in this market, it's way too broad, there's so many routes to market, partnerships, obviously very, very important. So, can you share a little bit more about the ecosystem and partners, maybe give some examples of some of the key partners that you'd be highlighting or working with, maybe at Mobile World Congress, or other activities this year? >> Yeah, absolutely. As Aaron touched on, I'm a visual thinker. The way I think about this thing is a very, very vertical architecture is tipping sideways. It's becoming horizontal. And all of the layers of that horizontal architecture are really where the partnerships are at. So, let's start at the bottom, silicon. The silicon ecosystem is very much focused on this market. And producing very specific products to enable open, high performance telecom networks. That's both in the form of host processors, as well as accelerators. One layer up, of course, is the stuff that we're known for, subsystems, compute storage, the hardware infrastructure that forms the foundation for telco clouds. A layer above that, all of the cloud software layer, the virtualization and containerization software, and all of the usual suspects there, all of whom are very good partners of ours, and we're looking to expand that pretty broadly this year. And then at the top of the layer cake, all of the network functions, all of the VNF's and CNF's that were once kind of the top of proprietary stacks, that are now opening up and being delivered, as well-formed containers that can run on these clouds. So, we're focusing on all of those, if you will, product partnerships, and there is a services wrapper around all of it. The systems integration necessary to make these systems part of a carrier's network, which of course, has been running for a long time, and needs to be integrated with in a very specific way. And so, all of that, together kind of forms the ecosystem, all of those are partners, and we're really excited about being at the heart of it. >> Interesting, it's not like we've never seen this movie before, which is, it's sort of repeating itself in telco. Aaron, you heard my little intro up front about the need to modernize infrastructure, I wonder if I could touch on another major trend, which we're seeing is the cloud, and I'm talkin' about not only public, but private and hybrid cloud. The public cloud is an opportunity, but it's also a threat for telcos. Telcom providers are lookin' to the public cloud for specific use cases, you think about like bursting for an iPhone launch or whatever. But at the same time, these cloud vendors, they're sort of competing with telcos. They're providing local zones, for example, sometimes trying to do an end run on the telco connectivity services, so telecom companies, they have to find the right balance between what they own and what they rent. And I wonder if you could add some color as to what you see in the market and what Dell specifically is doing to support these trends. >> Yeah, and I think the most important thing is what we're seeing, as you said, is these aren't things that we haven't seen before. And I think that telecom is really going through their own set of cloud transformations, and so, one of the hot topics in the industry now is, what is telco cloud? And what does that look like going forward? And it's going to be, as you said, a combination of services that they offer, services that they leverage. But at the end of the day, it's going to help them modernize how they deliver telecommunication services to their customers, and then provide value added services on top of that. From a Dell perspective, we're really providing the technologies to provide the underpinnings to lay a foundation on which that network can be built, whether that's best of breed servers that are built in design for the telecom environments. Recently, we announced our Infer block program, in partnering with virtualization providers, to be able to provide engineered systems that dramatically simplify how our customers can deploy, manage, and lifecycle manage throughout day two operations, an entire cloud environment. And whether they're using Red Hat, whether they're using Wind River, or VMware, or other virtualization layers, they can deploy the right virtualization layer at the right part of their network to support the applications they're looking to drive. And Dell is looking to solve how they simplify and manage all of that, both from a hardware, as well as on management software perspective. So, this is really what Dell's doing to, again, partner with the broader technology community, to help make that telco cloud a reality. >> Aaron, let's stay here for a second, I'm interested in some of the use cases that you're going after with customers. You've got Edge infrastructure, remote work, 5G, where's security fit, what are the focus areas for Dell, and can we double click on that a little bit? >> Yeah, I mean, I think there's two main areas of telecommunication industry that we're talking to. One, we've really been talking about the sort of the network buyer, how do they modernize the core, the network Edge, the RAN capabilities to deliver traditional telecommunication services, and modernize that as they move into 5G and beyond. I think the other side of the business is, telecoms are really looking from a line of business perspective to figure out how do they monetize that network, and be able to deliver value added services to their enterprise customers on top of these new networks. So, you were just touching on a couple of things that are really critical. In the enterprise space, AI and IoT is driving a tremendous amount of innovation out there, and there's a need for being able to support and manage Edge compute at scale, be able to provide connectivity, like private mobility, and 4G and 5G, being able to support things like mobile workforces and client capabilities, to be able to access these devices that are around all of these Edge environments of the enterprises. And telecoms are seeing as that, as an opportunity for them to not only provide connectivity, but how do they extend their cloud out into these enterprise environments with compute, with connectivity, with client and connectivity resources, and even also provide protection for those environments as well. So, these are areas that Dell is historically very strong at. Being able to provide compute, be able to provide connectivity, and being able to provide data protection and client services, we are looking to work closely with lines of businesses to be able to develop solutions that they can bring to market in combination with us, to be able to serve their end user customers and their enterprises. So, those are really the two key areas, not only network buyer, but being able to enable the lines of business to go and capitalize on the services they're developing for their customers. >> I think that line of business aspect is key, I mean, the telcos have had to sit back and provide the plumbing, cost per bit goes down, data consumption going through the roof, all the over at the top guys have had the field day with the data, and the customer relationships, and now it's almost like the revenge (chuckles) of the telcos. Dennis, I wonder if we could talk about the future. What can we expect in the years ahead from Dell, if you break out the binoculars a little bit. >> Yeah, I think you hit it earlier. We've seen the movie before. This has happened in the IT data center. We went from proprietary vertical solutions to horizontal open systems. We went from client server to software-defined open hardware cloud native. And the trend is likely to be exactly that, in the telecom industry because that's what the operators want. They're not naive to what's happened in the IT data center, they all run very large data centers. And they're trying to get some of the scale economies. Some of the agility, the cost of ownership benefits for the reasons Aaron just discussed. It's clear as you point out, this industry's been really defined by the inability to stop investing, and the difficulty to monetize that investment. And I think now, everybody's looking at this 5G, and frankly, 5G plus 6G, and beyond, as the opportunity to really go get a chunk of that revenue, and Enterprise Edge is the target. >> And 5G is touching so many industries, and that kind of brings me, Aaron into Mobile World Congress. I mean, you look at the floor layout, it's amazing. You got Industry 4.0, you've got our traditional industry and telco colliding. There's public policy. So, give us a teaser to Mobile World Congress 23, what's on deck at the show from Dell? >> Yeah, we're really excited about Mobile World Congress. This, as you know, is a massive event for the industry every year. And it's really the event that the whole industry uses to kick off this coming year. So, we're going to be using this obviously to talk to our customers and our partners about what Dell's looking to do, and what we're innovating on right now, and what we're looking to partner with them around. In the front of the house, we're going to be doin', we're going to be highlighting 13 different solutions and demonstrations to be able to show our customers what we're doing today, and show them the use cases, and put into action, so they get to actually look and feel, and touch, and experience what it is that we're working around. Obviously, meetings are important, everybody knows Mobile World Congress is the place to get those meetings and kickoff for the year. So, we're going to have, we're lookin' at several hundred meetings, hundreds of meetings that we're going to be lookin' to have across the industry with our customers and partners in the broader community. And of course, we've also got technology that's going to be in a variety of different partner spaces as well. So, you can come and see us in hall three, but we're also going to have technologies, kind of spread all over the floor. And of course, there's always theCUBE. You're going to be able to see us live all four days, all day, every day. You're going to be hearing our executives, our partners, our customers, talk about what Dell is doing to innovate in the industry, and how we're looking to leverage the broader, open ecosystem to be able to transform the network, and what we're lookin' to do. So, in that space, we're going to be focusing on what we're doing from an ecosystem perspective, our infrastructure focus. We'll be talking about what we're doing to support telco cloud transformation. And then finally, as we talked about earlier, how are we helping the lines of business within our telecoms monetize the opportunity? So, these are all different things we're really excited to be focusing on, and look forward to the event next month. >> Yeah, it's going to be awesome in Barcelona at the FITA, as you say, Dell's big presence in hall three, Orange is in there, Deutsche Telecom, Intel's in hall three. VMware's there, Nokia, Vodafone, you got some great things to see there. Check that out, and of course, theCUBE, we are super excited to be collaborating with you, we got a great setup. We're in the walkway right between halls four and five, right across from the government of Catalonia, who are the host partners for the event, so there's going to be a ton of action there. Guys, can't wait to see you there, really appreciate your time today. >> Great, thanks. >> Alright, Mobile World Congress, theCUBE's coverage starts on February 27th right after the keynotes. So, first thing in the morning, east coast time, we'll be broadcasting is, Aaron said all week, Monday through Thursday in the show floor, check that out at thecube.net. siliconangle.com has all the written coverage, and go to dell.com, see what's happenin' there, have all the action from the event. Don't miss us, this is Dave Vellante, we'll see you there. (electronic music)

Published Date : Feb 13 2023

SUMMARY :

and one of the most important and to monetize new and all of the components the network, to be able to capitalize on I love now the fact that Because of the delivery of some open examples of some of the key and all of the usual suspects there, about the need to the applications they're looking to drive. I'm interested in some of the use cases the lines of business to go and capitalize I mean, the telcos have had to sit back and the difficulty to and that kind of brings me, Aaron and kickoff for the year. awesome in Barcelona at the FITA, and go to dell.com, see

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Dave VellantePERSON

0.99+

DennisPERSON

0.99+

DavePERSON

0.99+

Dave VellantePERSON

0.99+

AaronPERSON

0.99+

VodafoneORGANIZATION

0.99+

Aaron ChaissonPERSON

0.99+

Dennis HoffmanPERSON

0.99+

February 27thDATE

0.99+

DellORGANIZATION

0.99+

iPhoneCOMMERCIAL_ITEM

0.99+

OrangeORGANIZATION

0.99+

BarcelonaLOCATION

0.99+

NokiaORGANIZATION

0.99+

Mobile World CongressEVENT

0.99+

hundredsQUANTITY

0.99+

Deutsche TelecomORGANIZATION

0.99+

MondayDATE

0.99+

IntelORGANIZATION

0.99+

Dell TechnologiesORGANIZATION

0.99+

first roundQUANTITY

0.99+

two thingsQUANTITY

0.99+

ThursdayDATE

0.99+

Mobile World CongressEVENT

0.99+

next monthDATE

0.99+

TelcoORGANIZATION

0.98+

13 different solutionsQUANTITY

0.98+

todayDATE

0.98+

TelcosORGANIZATION

0.98+

thecube.net.OTHER

0.98+

bothQUANTITY

0.98+

Mobile World Congress 23EVENT

0.98+

this yearDATE

0.98+

OneQUANTITY

0.98+

One layerQUANTITY

0.98+

VMwareORGANIZATION

0.98+

both partnersQUANTITY

0.98+

Mobile World Congress 2023EVENT

0.97+

oneQUANTITY

0.97+

MWC23EVENT

0.97+

twin thrustsQUANTITY

0.97+

two key areasQUANTITY

0.96+

telcoORGANIZATION

0.95+

two main thrustsQUANTITY

0.94+

fiveQUANTITY

0.93+

second main thrustQUANTITY

0.93+

2023DATE

0.93+

EdgeTITLE

0.92+

theCUBEORGANIZATION

0.92+

a trillion-dollarQUANTITY

0.91+

TelcomORGANIZATION

0.91+

firstQUANTITY

0.91+

hall threeQUANTITY

0.9+

dell.comORGANIZATION

0.89+

Mobile Word Congress Preview 2023 | Mobile Word Congress 2023


 

(upbeat music) >> Telecommunic^ations is well north of a trillion-dollar business globally that provides critical services on which virtually everyone on the planet relies. Dramatic changes are occurring in the sector, and one of the most important dimensions of this change is the underlying infrastructure that powers global telecommunications networks. Telcos have been thawing out, if you will, their frozen infrastructure, modernizing. They're opening up. They're disaggregating their infrastructure, separating, for example, the control plane from the data plane and adopting open standards. Telco infrastructure is becoming software-defined, and leading telcos are adopting cloud-native microservices to help make developers more productive, so they can respond more quickly to market changes. They're embracing technology consumption models and selectively leveraging the cloud where it makes sense, and these changes are being driven by market forces, the root of which stem from customer demand. So from a customer's perspective, they want services, and they want them fast, meaning not only at high speeds, but also they want them now. Customers want the latest, the greatest, and they want these services to be reliable and stable with high quality of service levels, and they want them to be highly cost effective. Hello and welcome to this preview of Mobile World Congress 2023. My name is Dave Vellante and at this year's event, theCUBE has a major presence at the show, made possible by Dell Technologies, and with me, to unpack the trends in Telco and look ahead to MWC 23, Dennis Hoffman. He's the senior vice-president and general manager of Dell's telecom business and Aaron Chaisson, who is the vice-president of telecom and edge solutions marketing at Dell Technologies. Gentlemen, welcome. Thanks so much for spending some time with me. >> Thank you, Dave. >> Thanks, glad to be here. So, Dennis, let's start with you. Telcos in recent history have been slow to deliver and to monetize new services, in a large part, because their purpose-built infrastructure can been somewhat of a barrier to respondent to these market forces. In many ways, this is what makes telecoms, really, this market, so exciting. So from your perspective, where is the action in this space? >> Yeah, the action, Dave, is kind of all over the place, partly because it's an ecosystem play. You know, I think it's been, as you point out, the disaggregation trend has been going on for a while. The opportunity's been clear, but it has taken a few years to get all of the vendors and all of the components that make up a solution, as well as the operators themselves, to a point where we can start putting this stuff together and actually achieving some of the promise. >> So, Aaron, for those who might not be as familiar with Dell's a activities in this area, you know, here we are just ahead of Mobile World Congress. It's the largest event for telecoms. What should people know about Dell, and what's the key message to this industry? >> Sure, yeah, I think everybody knows that there's a lot of innovation that's been happening in the industry of late. One of the major trends that we're seeing is that shift from more of a vertically-integrated technology stack to more of a disaggregated set of solutions, and that trend has actually created a ton of innovation that's happening across the industry, well, along technology vendors and providers, the telecoms themselves, and so one of the things that Dell's really looking to do is, as Dennis talked about, is build out a really strong ecosystem of partners and vendors that we're working closely together to be able to collaborate on new technologies, new capabilities, that are solving challenges that the networks are seeing today, be able to create new solutions built on those in order to be able to bring new value to the industry and then finally, we want to help both partners as well as our CSP providers activate those changes so that they can bring new solutions to market to be able to serve their customers, and so the key areas that we're really focusing on, with our customers, is technologies to help modernize the network to be able to capitalize on the value of open architectures and bring price performance to what they're expecting and availability that they're expecting today and then also partner with the lines of business to be able to take these new capabilities, produce new solutions and then deliver new value to their customers. >> Great, thank you, Aaron. So, Dennis, I have known you for a number of years. I've watched you. You are a trend spotter, and you're a strategic thinker, and I love now the fact that you're running a business that you had to go out and analyze, and now you got got to make it happen. So how would you describe Dell's strategy in this market? >> Well, it's really two things, and I appreciate the comment. I'm not sure how much of a trend spotter I am, but I certainly enjoy, and I think I'm fascinated by what's going on in this industry right now. Our two main thrusts, Dave, are, first round, trying to catalyze that ecosystem, you know, be a force for pulling together a group of folks, vendors, that have been flying in fairly loose formation for a couple of years to deliver the kinds of solutions that move the needle forward and produce the outcomes that our network-operator customers can actually buy, and consume, and deploy, and have them be supported. The other thing is there's a couple of very key technology areas that need to be advanced here. This ends up being a much anticipated year, in telecom, because of the delivery of some open infrastructure solutions that have been being developed for years, with the Intel Sapphire Rapids program coming to market. We've of course got some purpose-built solutions on top of that for telecommunications networks, some expanded partnerships in the area of multi-cloud infrastructure, and so I would say the second main thrust is we've got to bring some intellectual property to the party. It's not just about pulling the ecosystem together, but those two things together really form the twin thrusts of our strategy. >> Okay, so as you point out, you're obviously not going to go alone in this market. It's way too broad. There's so many routes to market, partnerships, obviously, very, very important. So can you share a little bit more about the ecosystem and partners, maybe give some examples of some of the key partners that you'd be highlighting or working with, maybe at Mobile World Congress or other activities this year? >> Yeah, absolutely. You know, as Aaron touched on. I'm a visual thinker. The way I think about this thing is a very, very vertical architecture is tipping sideways. It's becoming horizontal, and all of the layers of that horizontal architecture are really where the partnerships are at. So let's start at the bottom, silicon. The silicon ecosystem is very much focused on this market and producing very specific products to enable open, high-performance telecom networks. That's both in the form of host processors as well as accelerators. One layer up, of course, is the stuff that we're known for, subsystems, compute, storage, the hardware infrastructure that forms the foundation for telco clouds. A layer above that, all of the cloud software layer, the virtualization and containerization software and all of the usual suspects there, all of whom are very good partners of ours, and we're looking to expand that pretty broadly this year, and then at the top of the layer cake, all of the network functions, all of the VNFs and CNFs that were once kind of the top of proprietary stacks that are now opening up and being delivered as well-formed containers that can run on these clouds. So, you know, we're focusing on all of those, if you will, product partnerships, and there is a services wrapper around all of it, the systems integration necessary to make these systems part of a carrier's network, which, of course, has been running for a long time and needs to be integrated with in a very specific way, and so all of that together kind of forms the ecosystem. All of those are partners, and we're really excited about being at the heart of it. >> Interesting, it's not like we've never seen this movie before, which is sort of repeating itself in telco. Aaron, you heard my little intro up front about the need to modernize infrastructure. I wonder if I could touch on, you know, another major trend which we're seeing, is the cloud, and I'm talking about, not only public, but private and hybrid cloud. The public cloud is an opportunity, but it's also a threat for telcos. You know, telecom providers are looking to the public cloud for specific use cases. You think about, like, bursting for an iPhone launch or whatever but at the same time, these cloud vendors, they're sort of competing with telcos. They're providing, you know, local zones, for example, sometimes trying to do an end run on the telco connectivity services. So telecom companies, they have to find the right balance between what they own and what they rent, and I wonder if you could add some color as to what you see in the market and what Dell, specifically, is doing to support these trends. >> Yeah, I think the most important thing is what we're seeing, as you said, is these aren't things that we haven't seen before, and I think that telecom is really going through their own set of cloud transformations, and so one of the hot topics in the industry now is what is telco cloud and what does that look like going forward? And it's going to be a, as you said, a combination of services that they offer, services that they leverage, but at the end of the day, it's going to help them modernize how they deliver telecommunication services to their customers and then provide value-added services on top of that. From a Dell perspective, you know, we're really providing the technologies to provide the underpinnings to lay a foundation on which that network can be built, whether that's best-of-breed servers that are built and designed for the telecom environments. Recently we announced our, our Infra Block program in partnering with virtualization providers to be able to provide engineered systems that dramatically simplify how our customers can deploy, manage and lifecycle-manage throughout day-two operations, an entire cloud environment, and whether they're using Red Hat, whether they're using Wind River or VMware or other virtualization layers, they can deploy the right virtualization layer at the right part of their network to support the applications they're looking to drive, and Dell is looking to solve how they simplify and manage all of that, both from a hardware as well as a management software perspective. So this is really what Dell's doing to, again, partner with the broader technology community to help make that telco cloud a reality. >> Aaron, let's stay here for a second. I'm interested in some of the use cases that you're going after with customers. You've got edge infrastructure, remote work, 5G. Where's security fit? What are the focus areas for Dell, and can we double-click on that a little bit? >> Yeah, I mean, I think there's two main areas of telecommunication industry that we're talking to. One, we've really been talking about sort of the network buyer, how do they modernize the core, the network edge, the RAN capabilities, to deliver traditional telecommunication services and modernize that as they move into 5G and beyond. I think the other side of the business is telecoms are really looking, from a line of business perspective, to figure out how do they monetize that network and be able to deliver value-added services to their enterprise customers on top of these new networks. So you were just touching on a couple of things that are really critical. You know, in the enterprise space, AI and IoT is driving a tremendous amount of innovation out there, and there's a need for being able to support and manage edge compute at scale, be able to provide connectivity, like private mobility and 4G and 5G, being able to support things like mobile workforces and client capabilities to be able to access these devices that are around all of these edge environments of the enterprises, and telecoms are seen as that, as an opportunity for them to not only provide connectivity, but how do they extend their cloud out into these enterprise environments with compute, with connectivity, with client and connectivity resources, and even also provide protection for those environments as well. So these are areas that Dell's historically very strong at, being able to provide compute, being able to provide connectivity and being able to provide data protection and client services. We are looking to work closely with lines of businesses to be able to develop solutions that they can bring to market in combination with us to be able to serve their end user customers and their enterprises. So those are really the two key areas, not only network buyer, but being able to enable the lines of business to go and capitalize on the services they're developing for their customers. >> I think that line of business aspect is key. I mean, the telcos have had to sit back and provide the plumbing. Cost per bit goes down. Data consumption going through the roof. All the way over to the top guys, you know, had the field day with the data and the customer relationships, and now it's almost like the revenge of the telcos. (chuckles) Dennis, I wonder if we could talk about the future. What can we expect in the years ahead from Dell, if you, you know, break out the binoculars a little bit? >> Yeah, I think you hit it earlier. We've seen the movie before. This has happened in the IT data center. We went from proprietary vertical solutions to horizontal open systems. We went from client server to software-defined, open-hardware, cloud-native and you know, the trend is likely to be exactly that, in the telecom industry, because that's what the operators want. They're not naive to what's happened in the IT data center. They all run very large data centers, and they're trying to get some of the scale economies, some of the agility, the cost of ownership benefits for the reasons Aaron just discussed. You know, it's clear, as you point out, this industry's been really defined by the inability to stop investing and the difficulty to monetize that investment, and I think now everybody's looking at this 5G, and, frankly, 5G plus, 6G and beyond, as the opportunity to really go get a chunk of that revenue, and enterprise edge is the target. >> And 5G is touching so many industries, and that kind of brings me here into Mobile World Congress. I mean, you look at the floor layout, it's amazing. You got industry 4.0. You've got, you know, our traditional industry and telco colliding. There's public policy. So give us a teaser to Mobile World Congress '23. What's on deck at the show for from Dell? >> Yeah, we're really excited about Mobile World Congress. This, as you know, is a massive event for the industry every year, and it's really the event that the whole industry uses to kick off this coming year. So we're going to be using this, obviously, to talk to our customers and our partners about what Dell's looking to do and what we're innovating on right now, and what we're looking to partner with them around. In the front of the house, we're going to be highlighting 13 different solutions and demonstrations to be able to show our customers what we're doing today and show them the use cases and put it into action, so they get to actually look and feel and touch and experience what it is that we're working around. Obviously, meetings are important. Everybody knows Mobile World Congress is the place to get those meetings and kick off for the year. You know, we're looking at several hundred meetings, hundreds of meetings that we're going to be looking to have across the industry with our customers and partners and the broader community, and, of course, we've also got technology that's going to be in a variety of different partner spaces as well. So you can come and see us in hall three, but we're also going to have technologies kind of spread all over the floor, and, of course, there's always theCUBE. You're going to be able to see us live all four days, all day, every day. You're going to be hearing our executives, our partners, our customers, talk about, you know, what Dell is doing to innovate in the industry and how we're looking to leverage the broader open ecosystem to be able to transform, you know, the network and what we're looking to do. So in that space, we're going to be focusing on what we're doing from an ecosystem perspective, our infrastructure focus. We'll be talking about what we're doing to support telco cloud transformation and then finally, as we talked about earlier, how are we helping the lines of business within our telecoms monetize the opportunity. So these are all different things we're really excited to be focusing on and look forward to the event next month. >> Yeah, it's going to be awesome In Barcelona at the Fira. As you say, Dell's big presence in Hall three. Orange is in there, Deutsche Telekom. Intel's in Hall three. VMware's there, Nokia, Vodafone. You got great things to see there. Check that out and of course, theCUBE, we are super excited to be collaborating with you. We got a great setup. We're in the walkway, right between halls four and five, right across from the Government of Catalonia, who are the host partners for the event. So there's going to be a ton of action there. Guys, can't wait to see you there. Really appreciate your time today. >> Great, thanks. >> All right, Mobile World Congress, theCUBE's coverage starts on February 27th, right after the keynotes. So first thing in the morning, East coast time, we'll be broadcasting, as Aaron said, all week, Monday through Thursday, on the show floor. Check that out at thecube.net. Siliconangle.com has all the written coverage, and go to dell.com, see what's happening there. Have all the action from the event. Don't miss us. This is Dave Vellante. We'll see you there. (upbeat music)

Published Date : Jan 30 2023

SUMMARY :

and one of the most important dimensions and to monetize new and all of the components It's the largest event for telecoms. the network to be able to and I love now the fact that of solutions that move the of some of the key partners and all of the layers about the need to and so one of the hot topics I'm interested in some of the use cases the lines of business to go and capitalize and now it's almost like the revenge as the opportunity to really What's on deck at the show for from Dell? and partners and the broader community, So there's going to be and go to dell.com, see

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
AaronPERSON

0.99+

DennisPERSON

0.99+

Dave VellantePERSON

0.99+

Aaron ChaissonPERSON

0.99+

DavePERSON

0.99+

Dennis HoffmanPERSON

0.99+

VodafoneORGANIZATION

0.99+

February 27thDATE

0.99+

Dell TechnologiesORGANIZATION

0.99+

BarcelonaLOCATION

0.99+

iPhoneCOMMERCIAL_ITEM

0.99+

DellORGANIZATION

0.99+

OrangeORGANIZATION

0.99+

TelcoORGANIZATION

0.99+

Mobile World CongressEVENT

0.99+

hundredsQUANTITY

0.99+

thecube.netOTHER

0.99+

ThursdayDATE

0.99+

secondQUANTITY

0.99+

NokiaORGANIZATION

0.99+

Mobile World CongressEVENT

0.99+

13 different solutionsQUANTITY

0.99+

TelcosORGANIZATION

0.99+

next monthDATE

0.99+

two key areasQUANTITY

0.99+

MondayDATE

0.98+

first roundQUANTITY

0.98+

Deutsche TelekomORGANIZATION

0.98+

two thingsQUANTITY

0.98+

todayDATE

0.98+

Government of CataloniaORGANIZATION

0.98+

Mobile Word CongressEVENT

0.97+

bothQUANTITY

0.97+

MWC 23EVENT

0.97+

Mobile World Congress 2023EVENT

0.97+

IntelORGANIZATION

0.97+

VMwareORGANIZATION

0.97+

OneQUANTITY

0.97+

this yearDATE

0.96+

oneQUANTITY

0.96+

two main areasQUANTITY

0.96+

firstQUANTITY

0.95+

both partnersQUANTITY

0.94+

twin thrustsQUANTITY

0.94+

fiveQUANTITY

0.93+

Red HatTITLE

0.93+

One layerQUANTITY

0.92+

telcoORGANIZATION

0.92+

FiraLOCATION

0.91+

a trillion-dollarQUANTITY

0.91+

theCUBEORGANIZATION

0.9+

twoQUANTITY

0.88+

hundred meetingsQUANTITY

0.86+

Mobile World Congress '23EVENT

0.83+

two main thrustsQUANTITY

0.82+

2023DATE

0.8+

Reza Honarmand & Sergio Farache, TD SYNNEX | AWS re:Invent 2022


 

(corporate electronic xylophone jingle intro) >> Good afternoon everyone. Welcome back to theCUBE's live coverage of AWS re:Invent 22 from Vegas. We're at the Venetian Expo Hall with we're hearing, north of 50,000 people. I know we've been giving you different numbers but, that's kind of what we've settled on here. Hundreds of thousands are watching online. This is a huge event. People, John Furrier, Lisa Martin are ready to be back. >> Yes, it's really great show. A lot of change going on at Amazon. They're continuing the innovation, continuing to grow. The theme this year's data security and their partner ecosystem, which is continuing to grow. Their partners are filling the gaps on solutions and, it's just a whole another, I think, partner friendly cloud. This next gen wave that's coming, it's really next segment I think speaks to, I'm looking forward to this. >> It does. We're going to be digging into that partner network. We've got two guests. One of them's an alumni, Reza Honarmand SVP Global Cloud at TD SYNNEX. Great to have you back. >> Hello. >> Sergio Farache joins us as well, the Chief Strategy Officer at TD SYNNEX. Welcome to the program. >> Thank you. Thank you for having us. >> Great to be back in person, isn't it? >> Yeah, absolutely. It's a great experience. >> Amazing. The energy here has been hot at the highest levels since we came here Monday, Monday night, which is great. Sergio, I want to start with you. Last year when you guys were on the show, Tech Data. Tech Data has been around a long time. Now your TD SYNNEX. Talk a little bit about that. What's new, that transformation? >> Yeah, that is correct. It's great to be able now to present TD Synnex as a new merger between Tech Data and Synnex Corporation. Now, we are the largest distributor basically, across the world, with more than 62 billion dollar in a business. And, Amazon is obviously a strategic partner with a hyper growth and, we has been very focused to working with them to expand that partner ecosystem across solution ISVs and service providers. There has been very nice experience combine these two company and now have the reach and a scale that enable more than 140,000 partners across the world. >> Wow. >> And, the partner's message here is changing too. The new leader, Aruba is up on stage talking about this new partner paths. A lot of changes in a good way. They're bringing people together. What's your guys take and reaction to AWS's new posture towards partners? Obviously, the ecosystem we see going to be doubling and tripling we see in size and, also the value proposition is going to be stronger too and, more money making of course. But, the new Amazon's posture with partners. What's your reaction? >> We were at Aruba just an hour ago. Fantastic. If I look at the change from when we first got here a few years ago to now, it is beyond comparison. The realization is that technology and, especially what we work with Amazon is deflationary force and, we need scale to actually drive that across all of our partners to the customers. And, I can only see that accelerating now in terms of what Amazon is doing and actually with the channel and what Aruba is doing. I think this is exactly the right direction. >> John: What's your message? >> My message is, this is now channel. This is channel and this is serious. So, partners with Amazon equals growth. >> As we've seen so much transformation in the last couple of years, Sergio, with every business having to become digital to survive, right. And then, to eventually thrive and succeed and grow and the challenging economic times that we've had. What are some of the pivots that TD Synnex has made through your partner program to meet customer needs to accelerate their transformation? >> Yeah, as you said, has been a significant transformation. I think that in the past was clear what was a technology company and what an industrial company etcetera and, those frontiers are blending right now. Then, as a consequence we has been investing in several elements. One is to really increase the capability of the partner network in a way that they can on one side provide more solution-oriented activities to those customers to drive either growth or cost optimization. The other element has been verticalization meaning, know the industry where you are playing. We have been investing in the healthcare market, of course, as a consequence of all the demand that has been generating. But, at the same time and, we recently announced the competency in the government sector where we expand drastically our capabilities around specifically the federal and non federal business. But, not only in US but, across the world with those elements. Then, I would say that it's a combination of enhancing the skill, enhancing the knowledge on the industry, and finally provide the tools through our platform to enable the partner to operate in a digital way and enable the access of ISVs to the Iotly and serving the customers end to end. >> Is that the ISV experience project that I heard about, ISV experience with SaaS companies? Is that what you're referring to? >> Yeah, ISVs is one, ISV experience is one of the components that we use but, basically what we are trying to achieve with the ISV is helping in the journey of certification. Is how you transform either a partner that is born in the cloud or a partner that is still in the on-premise side. How you transition to the cloud and enabling how you reach to the end user in a more effective way and, how we expose 140,000 partner across the multiple geographies to help those ISVs to reach more customers. >> It's great distribute, it's great distribution. It's a business model innovation. >> Sorry? >> It's a business model innovation for these ISVs. >> Absolutely. Some of the ISVs, as you can imagine, they're incumbent with us. We work with them. So, actually it's finding new ways of consuming technology but, there's thousands of them that actually do not understand how to operate with a channel. And, this is a part where we help them with the channel, build a program, coach them through the process, help them access their partners and the customers that Sergio was referring to. >> Let me ask you guys a question. Where's the growth going to come from? You mentioned ecosystem, more growth, Aruba mentioned that's where the growth is. They are serious. So, you going to deliver that keynote now. Where do you guys see your growth coming from? >> Well, to be honest, the growth is unlimited in our opinion, right? It's so many areas. >> John: The wave is still coming. Yeah, the wave is still there. When you see still the amount of platform that need to be migrated to the cloud then, we have been investing in a significant way in enable capabilities of migration programs from the on-premise to the off-premise. At the same time, we have been expanding geographically because, it's still several segments and markets we operate globally. As an example, we recently launched our public sector capability in Latin America and Europe, expanding those segments. And, in addition to that, again, how we bring more ISVs more solution oriented driven. There's many spots of growth. And, I think that Amazon message recently recognized more and more the value of, nobody have all the solutions. You need this ecosystem playing together to bring those solutions to market. >> So if I build on that. If we look at the growth in the public cloud last year, was around 40 billion dollars. We expect a similar growth level this year as well. I mentioned about deflationary force, the technology being a deflationary force. Now, everybody knows a lot of businesses out there are going under a lot of challenges. So, they have to compete, they have to have the insights, they have to be efficient, and actually, they're going to get a lot of that through the technologies that we're talking about here. The key to that is partners with the right skill sets. What we are seeing is the partners with the skill sets who can participate in that 40 billion dollar growth, take a big, big share of it. >> And you guys are providing a great service. I think, when I wrote the story on Friday that I published. One of my premise was is that, this next-gen cloud is going to lift up more ISVs which is kind of a legacy classic, independent software vendor, create new kinds of partners that have platforms or unique solutions for verticals. So, the ISV classic definition will still exist and, new customers are emerging. It's got a new dynamic developing. We're seeing people build clouds on top of the cloud, tap the ecosystem, partner distribution services. It's a whole new way to build and take something to market. What do you guys think about that? >> Yeah, I think that the beauty of our position in the market is that we are in the center of that ecosystem. Again, we have access to thousands of ISVs, thousands of hardware vendors, the hyperscalers. Then somebody need to put all those pieces together. That is our role in the market. >> John: It's a good position to be in. >> It's a good place to be. And, enabling those partners now to collaborate with all those entities to bring the solution because, the customer is not acquiring technology anymore. They're acquiring a solution to a problem now. And, that solution require multiple components. >> Last year, no, this year, I'm sorry, you guys were announced as EMEA Distributor of the Year. Congratulations on that. >> Yeah, thank you. >> Talk about that in terms of just the evolution of the partnership. >> The partnership in EMEA is now across our entire geo. The growth that we've driven across the EMEA market space is I think, the reason why we have won it, as well as the competencies that we have built. Now, you were just talking about ISVs to give you an example. There are many ISVs that sit in EMEA that want to access the US market and vice versa. So, where we sit in the middle and enable that access, the frameworks that they need to move. So, those are the kind of things that contribute to the strength in the relationship what those awards are coming from. >> Yeah, the other critical factor here is again, how we bring more capability in terms of the serve to the market to Amazon. And, that has been another component of data where that we are very thankful. Again, we has been enabling and bringing numerous new partners and numerous new end customers that now have access, support, and services including, again, the competencies that we already described but, including service oriented businesses like migration, like cost optimization of the use, et cetera, that now we through partner serve to the market. >> Reza, Sergio. I want to ask you guys a question around trust. Trust. You're a trust broker because you have a lot of services and people and companies to put together. We were just talking about the good position you're in. Trust is a big part of your relationship with your customers. You've got two sides of your business. You got one side is the supply side and you got the distribution side, and then both sides are working together. Requires a lot of trust. What's that look like inside your company? Could you just take a minute to explain, take a bit to explain what's that like, the culture of the company and that trust. >> Yeah, absolutely. And, that is why the term of Trust Advisor came to the table, right? And, and again, for more than 40 years we has been building this ecosystem. We has been driving that motion and, we have been proving to the market a consistent approach with a strong support to the two tier model. We never get in opposition to our customers and, we enable those customers in a consistent way. Then, I think that trust is something that you earn not something that you ask for. And, that is what we are doing day basis. >> Well, congratulations. It's been great chatting with you. Challenge time for the challenge >> Lisa: Challenge Time, all right guys. >> A new challenge on theCUBE, new format. We usually say... >> Yes at the end of the interview. What's the take on the show? What's the bumper sticker? So, think of it like an Instagram Reel. Thought leadership, hot take. Each of you, spend a minute, 30 seconds to share a hot take, thought leadership, what you think was going on at Amazon, why you're here, what's important. What would you say if you were going to do an Instagram Reel right now? >> Yeah, the Amazon enable a new way to do business and a new transformation of the Iotly economy. We are here in TD Synnex to expand that capability across the segments enhancing partners to reach to their goals and, in users to get those transformations. In general, we will provide what is needed and, we continue investing to continue growing the capacity across all geographies and all the type of solutions that we deliver. >> All right, Sergio, you nailed it. Reza, you're up, your hot take, your sizzle reel. >> Well, frankly, I think, Sergio nailed it. It's about covering the geos and taking the competencies and, make sure we execute consistently across all of our geos. >> All right, nailed it. Thanks so much. >> Consistent execution. Reza, Sergio, thank you so much... >> Thank you so much. for joining John and me on the program, talking about what TD SYNNEX has done since we've last seen you. What you're doing with AWS and the partner ecosystem. We really appreciate you stopping by the set >> Thank you. >> Thank you for the time. >> All right, our pleasure. For our guests and for John Furrier, I'm Lisa Martin. You're watching theCUBE, the leader at live tech coverage. (corporate electronic xylophone jingle outro)

Published Date : Dec 1 2022

SUMMARY :

We're at the Venetian Expo Hall They're continuing the Great to have you back. the Chief Strategy Officer at TD SYNNEX. Thank you for having us. It's a great experience. hot at the highest levels and now have the reach and, also the value proposition of our partners to the customers. So, partners with Amazon equals growth. in the last couple of years, Sergio, enable the partner to operate that is born in the cloud It's a business model innovation. It's a business model Some of the ISVs, as you can imagine, Where's the growth going to come from? the growth is unlimited from the on-premise to the off-premise. the public cloud last year, So, the ISV classic of our position in the market It's a good place to be. EMEA Distributor of the Year. of just the evolution of the partnership. the frameworks that they need to move. of the use, et cetera, the culture of the company and that trust. is something that you earn It's been great chatting with you. A new challenge on theCUBE, new format. at the end of the interview. that capability across the All right, Sergio, you nailed it. and taking the competencies All right, nailed it. thank you so much... and the partner ecosystem. For our guests and for John

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JohnPERSON

0.99+

Lisa MartinPERSON

0.99+

Tech DataORGANIZATION

0.99+

AmazonORGANIZATION

0.99+

Sergio FarachePERSON

0.99+

SergioPERSON

0.99+

Lisa MartinPERSON

0.99+

John FurrierPERSON

0.99+

AWSORGANIZATION

0.99+

John FurrierPERSON

0.99+

LisaPERSON

0.99+

RezaPERSON

0.99+

TD SynnexORGANIZATION

0.99+

USLOCATION

0.99+

TD SYNNEXORGANIZATION

0.99+

EuropeLOCATION

0.99+

Last yearDATE

0.99+

Tech DataORGANIZATION

0.99+

FridayDATE

0.99+

MondayDATE

0.99+

Latin AmericaLOCATION

0.99+

two sidesQUANTITY

0.99+

thousandsQUANTITY

0.99+

last yearDATE

0.99+

VegasLOCATION

0.99+

one sideQUANTITY

0.99+

more than 140,000 partnersQUANTITY

0.99+

OneQUANTITY

0.99+

Synnex CorporationORGANIZATION

0.99+

40 billion dollarQUANTITY

0.99+

Hundreds of thousandsQUANTITY

0.99+

more than 62 billion dollarQUANTITY

0.99+

two guestsQUANTITY

0.99+

both sidesQUANTITY

0.99+

EMEAORGANIZATION

0.99+

Venetian Expo HallLOCATION

0.99+

30 secondsQUANTITY

0.99+

a minuteQUANTITY

0.99+

this yearDATE

0.99+

Reza HonarmandPERSON

0.99+

more than 40 yearsQUANTITY

0.98+

oneQUANTITY

0.98+

two companyQUANTITY

0.98+

around 40 billion dollarsQUANTITY

0.98+

an hour agoDATE

0.98+

EachQUANTITY

0.97+

ArubaORGANIZATION

0.97+

Monday nightDATE

0.94+

firstQUANTITY

0.93+

InstagramORGANIZATION

0.9+

TechORGANIZATION

0.9+

ArubaLOCATION

0.89+

theCUBEORGANIZATION

0.88+

CloudORGANIZATION

0.88+

140,000 partnerQUANTITY

0.85+

InventEVENT

0.85+

22TITLE

0.84+

Reza Honarmand & Sergio Farache, TD SYNNEX | AWS re:Invent 2022


 

(upbeat music) >> Good afternoon everyone. Welcome back to The Cube's live coverage of AWS Reinvent 22 from Vegas. We're at the Venetian Expo Hall, we're hearing north of 50 000 people. I know we've been giving you different numbers but that's kind of what we've settled on here. Hundreds of thousands are watching online. This is a huge event people. John Ferrior and Lisa Martin are ready to be back. >> Yes, it's really great show. A lot of change going on at Amazon. They're continuing the innovation, continuing to grow. The theme this year's Data Security. And their partner ecosystem, which is continuing to grow. Their partners are filling the gaps on solutions. And it's just a whole nother, I think partner friendly cloud. This NextGen wave that's coming is really, the next thing segment I think speaks to that, I'm looking forward to this. >> It does. We're going to be digging into that partner network. We've got two guests, one of them is an alumni, Reza Honarmand SVP Global Cloud at TD Synnex. Great to have you back. >> Yeah. >> Sergio Farache joins us as well the Chief Strategy Officer at TD Synnex. Welcome to the program. >> Thank you. >> Thank you for having us. >> Great to be back in person, isn't it? >> Yeah absolutely. That's great experience. >> Amazing, the energy here at the highest level since we came here Monday night, which is great. Sergio, I want to start with you. Last year when you guys were on the show Tech Data. Tech Data has been around a long time now you're TD Synnex. Talk a little bit about that, what's new, that transformation? >> Yeah, that is correct. It's great to be able now to present it in Synnex as a new merger between Tech Data and Synnex Corporation. And now we are the largest distributor basically across the world with more than $62 billion in a business. And Amazon is obviously an strategic partner with a hyper growth and we have been very focused to working with them to expand that partner ecosystem across solution ISVs and service providers. That has been very nice experience combine these two company and now have the reach and skill that enable more than 140,000 partners across the world. >> Wow. >> And the partner's message here is changing too. The new leader, Ruba is up on stage talking about this new partner paths, a lot of changes in a good way. They're bringing people together. What's your guys take and reaction to AWS's new posture towards partners? Obviously the ecosystem we see going to be doubling and tripling we see in size. And also the value proposition being stronger too and more money making of course. But the new Amazon's posture with partners. What's your reaction? >> Well, (indistinct) just an hour ago. Fantastic. I mean, if I look at the change from when we first got here a few years ago to now, it is beyond comparison. The realization is that technology and especially what we work with Amazon is deflationary force and we need scale to actually drive that across all of our partners to the customers. And yeah, I can only see that accelerating now in terms of what Amazon is doing and actually with the channel and what Ruba is doing. I think this is exactly in the right direction. >> What's your message? >> My message is, this is now channel. This is channel and this is serious. So partners with Amazon equals growth. >> As we've seen so much transformation in the last couple of years, Sergio, with every business having to become digital to survive. Right and then to eventually thrive and succeed and grow in the challenging economic times that we've had. What are some of the, the pivots that TD Synnex has made through your partner program to meet customer needs to accelerate their transformation? >> Yeah, as you said, has been a significant transformation. I think that in the past was clear what was a technology company and what industrial company, et cetera and those frontiers are blending right now. Then as a consequence we have been investing in several elements. Once is to really increase the capability of the partner network in a way that they can on one side provide more solution-oriented activities to those customers to drive either growth or cost optimization. The other element has been verticalization meaning know the industry where you are playing. We have been investing in the healthcare market, of course as a consequence of all the demand that has been generating. But at the same time and we recently announced the competence in the government sector where we expand drastically our capabilities around specifically the federal, and non feral business, but not only in US but across the world with those elements. Then I would say it's a combination of enhancing the skill, enhancing the knowledge on the industry, and finally provide the tools through our platform to enable the partner to operate in a digital way and enable the access of ISVs to digitally and serving the customers end to end. >> Is that the ISV experience project that I heard about? ISV experience with SaaS companies, Is that what you're referring to? >> Yeah, ISVs is one. ISP experience is one of the components that we use, but basically what we are trying to achieve with the ISV is helping in the journey of specification. It's how you transform either a partner that is born in the cloud or a partner that is still in the, in the OnPrem side how you transition to the cloud and enabling how you reach to the end user in a more effective way. And how we expose 140,000 partner across the multiple geographies to help those ISVs to reach more customers. >> It's great distribution. I mean this is, a business model innovation. >> Sorry? >> It's a business model innovation for these ISVs. >> Absolutely. Some of the ISVs, as you can imagine they're incumbent with us. We work with them. So actually it's finding new ways of consuming technology. But there's thousands of them that actually do not understand how to operate with a channel. And this is a part where we help them with the channel, build a program. Coach them through the process, help them access the partners and the customers that Sergio was referring to. >> Let me ask you guys a question. Where's the growth going to come from? I mean you mentioned ecosystem, more growth, Ruba was mentioned that's where the growth is. They are serious. She's going to deliver that keynote now. Where do you guys see your growth coming from? >> Well, to be honest the growth is unlimited in our opinion, right. It's so many areas. >> The wave is still coming. Yeah >> The wave is still there, you know. When you see still the amount of platform that need to be immigrated to the cloud then we have been investing in a significant way in enable capabilities of migration programs from the on-premise to off premise. At the same time, we have been expanding geographically because it's still several segments and markets we operate globally. As an example we recently launched our public sector capability in Latin America and Europe, expanding those segments. And in addition to that again, how we bring more ISVs more solution oriented driven than many spots of growth. And I think that Amazon message recently recognized more and more the value of nobody have all the solutions. You need this ecosystem plan together to bring those solutions to market. >> So if I build on that. If we look at the growth in public cloud last year, was around $40 billion. We expect a similar growth level this year as well. I mentioned about deflationary force, the technology being a deflationary force. Now everybody knows a lot of businesses out there are going under a lot of challenges. So they have to compete, they have to have the insights they have to be efficient and actually they're going to get a lot of that through the technologies that we're talking about here. The key to that is partners with the right skillsets. What we are seeing is the partners with the skillsets who can participate in that $40 billion growth, take a big, big share of it. >> And you guys are providing a great service. I think when I wrote the story on Friday that I published one of my premise was, is that this Next-Gen cloud is going to lift up more ISVs which is kind of a legacy classic, independent software vendor. Create new kinds of partners that have platforms or unique solutions for verticals. So, the ISV classic definition will still exist and new customers are emerging. It's got a new dynamic developing. We're seeing people build clouds on top of the cloud tap the ecosystem, partner distribution, services. It's a whole new way to build and take something to market. What do you guys think about that? >> Yeah, I think that the beauty of our position in the market is that we are in the center of that ecosystem. Again, we have access to thousands of ISVs thousands of hardware vendors, the hyper-scalers then somebody need to put all those pieces together. That is our role in the market. >> It's a good position to be in. >> It's a good place to be. And enabling those partners now to collaborate with all those entities to bring the solution because the customer is not acquiring technology anymore. They're acquiring a solution to a problem now. And that solution require multiple components. >> Last year. No, this year, I'm sorry. You guys were announced as EMEA distributor of the, of the year. Congratulations on that. >> Yeah, thank you. Talk about that in terms of just the evolution of the partnership. >> The partnership in EMEA is now across our entire geo. The growth that we have driven across the EMEA market space, is I think the reason why we have won it. As well as the competencies that we have built. Now you were just talking about ISVs to give you an example, there are many ISVs that sit in EMEA that want to access the US market and vice versa. So where we sit in the middle and enable that access. The frameworks that they need to move. So those are the kind of things that contribute to the strengthened in the relationship and what those awards are coming from. >> Yeah. The other critical factor here is, again how we bring more capillarity in terms of the serve to the market to Amazon. And that has been another component of data that we are very thankful. Again, we has been enabling and bringing numerous new partners and numerous new end customers that now have access, support and services. Including again, the competencies that we already described but including service oriented businesses like migration, like cost optimization of the use, et cetera. That now we through partners serve to the market. >> Reza and Sergio, I want ask you guys a question around trust. Trust. You're a trust broker because you have a lot of services and people and companies to put together. We were just talking about the good position you're in. >> Trust is a big part of your relationship with your customers. You've got two sides of your business, you got one side's the supply side and you got the distribution side and then both sides are working together, requires a lot of trust. What's that look like inside your company? Can you just chip in and explain, take a bit to explain what's that like? The culture of the company and that trust. >> Yeah, absolutely. And that is why the term of trust advisor came to the table right? And again, for more than 40 years we have been building this ecosystem. We have been driving that motion and we have been proving to the market a consistent approach with a strong support to the two tier model. We never, you know get in opposition to our customers and we enable those customers in a consistent way. And I think that trust is something that you earn, not something that you ask for. And that is what we are doing day to day basis. >> Congratulations, it's been great. Great chatting with you. Challenge time? For the challenge time? >> Challenge time. >> Alright guys. >> New challenge on the Cuba new format. We usually say yes at the end of the interview. What's take on the show, what's the bumper sticker? So think of it like an Instagram reel, thought leadership, hot take. Each of you, spend a minute 30 seconds to share a hot take, thought leadership, what you think was going on at Amazon? Why you're here? What's important? What would you say if you were going to do an Instagram reel right now? >> Yeah, the Amazon enable a new way to do business and a new transformation of the digital economy. We are here TD Synnex to expand that capability across the segments. Enhancing partners to reach to their goals and in users to get those transformations. In general we will provide what is needed and we continue investing to continue growing the capacity across all geographies and all the type of solutions that we deliver. >> All right, Sergio you nailed it. Reza you're up. Your hot take your sizzle reel. >> Well, frankly I think Sergio nailed it. It's about covering the geos and taking the competencies and make sure we execute consistently across all of our geos. >> All right, nailed it. Thanks so much. >> Consistent execution. Reza, Sergio. Thank you so much for joining John and me on the program, talking about what TD Synnex has done since we've last seen you. What you're doing with AWS and the partner ecosystem. We really appreciate you stopping by this side. >> Thank you very much. Thank you for the time. >> Alright, our pleasure. For our guests and for John Furrier, I'm Lisa Martin. You're watching theCUBE, the leader at Live Tech coverage.

Published Date : Nov 30 2022

SUMMARY :

We're at the Venetian Expo Hall, I think speaks to that, Great to have you back. the Chief Strategy Officer at TD Synnex. Yeah absolutely. here at the highest level It's great to be able now Obviously the ecosystem we of our partners to the customers. This is channel and this is serious. and grow in the challenging enable the partner to operate either a partner that is born in the cloud I mean this is, a It's a business model Some of the ISVs, as you can imagine Where's the growth going to come from? the growth is unlimited The wave is still coming. the on-premise to off premise. The key to that is partners and take something to market. of our position in the market It's a good place to be. EMEA distributor of the, of the year. of just the evolution of the partnership. The frameworks that they need to move. of the use, et cetera. the good position you're in. The culture of the company and that trust. and we have been proving to the For the challenge time? New challenge on the Cuba new format. of the digital economy. All right, Sergio you nailed it. and taking the competencies All right, nailed it. John and me on the program, talking Thank you for the time. For our guests and for John

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JohnPERSON

0.99+

SergioPERSON

0.99+

AmazonORGANIZATION

0.99+

Lisa MartinPERSON

0.99+

Sergio FarachePERSON

0.99+

Lisa MartinPERSON

0.99+

John FurrierPERSON

0.99+

AWSORGANIZATION

0.99+

RezaPERSON

0.99+

$40 billionQUANTITY

0.99+

John FerriorPERSON

0.99+

TD SynnexORGANIZATION

0.99+

EMEAORGANIZATION

0.99+

oneQUANTITY

0.99+

EuropeLOCATION

0.99+

Last yearDATE

0.99+

more than $62 billionQUANTITY

0.99+

USLOCATION

0.99+

two sidesQUANTITY

0.99+

thousandsQUANTITY

0.99+

RubaPERSON

0.99+

Synnex CorporationORGANIZATION

0.99+

Monday nightDATE

0.99+

Tech DataORGANIZATION

0.99+

FridayDATE

0.99+

two guestsQUANTITY

0.99+

SynnexORGANIZATION

0.99+

more than 140,000 partnersQUANTITY

0.99+

last yearDATE

0.99+

VegasLOCATION

0.99+

around $40 billionQUANTITY

0.99+

Latin AmericaLOCATION

0.99+

both sidesQUANTITY

0.99+

this yearDATE

0.99+

Hundreds of thousandsQUANTITY

0.99+

more than 40 yearsQUANTITY

0.99+

Venetian Expo HallLOCATION

0.98+

EachQUANTITY

0.98+

Reza HonarmandPERSON

0.98+

two companyQUANTITY

0.97+

an hour agoDATE

0.97+

CubaLOCATION

0.96+

Live TechORGANIZATION

0.95+

last couple of yearsDATE

0.93+

140,000 partnerQUANTITY

0.92+

one sideQUANTITY

0.92+

InstagramORGANIZATION

0.92+

two tier modelQUANTITY

0.91+

a minute 30 secondsQUANTITY

0.9+

firstQUANTITY

0.9+

2022DATE

0.88+

few years agoDATE

0.86+

north of 50 000 peopleQUANTITY

0.81+

NextGen waveEVENT

0.76+

SVPPERSON

0.75+

thousands of ISVsQUANTITY

0.75+

Reinvent 22TITLE

0.74+

Tech DataORGANIZATION

0.72+

OnceQUANTITY

0.67+

Srinivasan Swaminatha & Brandon Carroll, TEKsystems Global Services | AWS re:Invent 2022


 

>> Good afternoon, fellow cloud nerds and welcome back to AWS Reinvent 2022. We are live here from fabulous Las Vegas, Nevada. My name is Savannah Peterson, joined by Lisa Martin. So excited to be here Lisa, it's my first reinvent. >> Is it really? >> Yeah. >> I think it's only like my fourth or fifth. >> Only your fourth or fifth. >> Only. >> You're such a pro here. >> There's some serious veterans here in attendance that have been to all 11. >> I love that. >> Yeah. Wow, go them. I know, maybe we'll be at that level sooner. >> One day we will. >> Are you enjoying the show so far? >> Absolutely, it is. I cannot believe how many people are here. We've had 70,000 and we're only seeing what's at the foundation Expo Hall, not at the other hotel. So, I can only imagine. >> I mean, there's a world outside of this. >> Yes, and there's sunlight. There's actual sunlight outside of this room. >> Nobel idea. Well, Lisa, I'm very excited to be sitting here next to you and to welcome our fabulous guests, from TEKsystems, we have Brandon and Srini. Thank you so much for being here. How is the show going for you gentlemen so far? >> It's great. Lot of new insights and the customers are going to love what AWS is releasing in this reinvent. >> There is such a community here, and I love that vibe. It's similar to what we had at Cloud Native con in Detroit. So much collaboration going on. I assume most folks know a lot about TEKsystems who are watching, but just in case they don't, Brandon, give us the pitch. >> You bet. So full stack IT solutions firm, been in business for over 40 years, 80,000 global employees, really specializing in digital transformation, enterprise modernization services. We have partners in One Strategy, which is an an acquisition we made, but a well known premier partner in the Amazon partner ecosystem, as well as One North Interactive, who is our boutique brand, creative and digital strategy firm. So together, we really feel like we can bring full end-to-end solutions for digital and modernization initiatives. >> So, I saw some notes where TEKsystems are saying organizations need experienced AWS partners that are not afraid doing the dirty work of digital transformation, who really can advise and execute. Brandon, talk to us about how TEKsystems and AWS are working together to help customers on that journey which is nebulous of digital transformation. >> So, our real hallmark is the ability to scale. We partner with AWS in a lot of different ways. In fact, we just signed our strategic collaboration agreement. So, we're in the one percenter group in the whole partner network. >> Savanna: That's a pretty casual flex there. >> Not bad. >> I love that, top 1%, that no wonder you're wearing that partner pin so proud today. (speaking indistinctly) >> But we're working all the way on the advisory and working with their pro serve organization and then transforming that into large scale mass migration services, a lot of data modernization that Srini is an absolute expert in. I'm sure he can add some context too, but it's been a great partnership for many years now. >> In the keynote, Adam spent almost 52 minutes on data, right? So, it emphasizes how organizations are ready to take data to cloud and actually make meaningful insights and help their own customers come out of it by making meaningful decisions. So, we are glad to be part of this entire ecosystem. >> I love that you quantified how many minutes. >> I know. >> Talked about it, that was impressive. There's a little bit of data driven thinking going on here. >> I think so. >> Yeah. >> Well, we can't be at an event like this without talking about data for copious amounts of time, 52 minutes, has just used this morning. >> Right, absolutely. >> But every company these days has to be a data company. There's no choice to be successful, to thrive, to survive. I mean, even to thrive and grow, if it's a grocery store or your local gas station or what? You name it, that company has to be a data company. But the challenge of the data volume, the explosion in data is huge for organizations to really try to figure out and sift through what they have, where is all of it? How do we make sense of it? How do we act on it and get insights? That's a big challenge. How is TEKsystems helping customers tackle that challenge? >> Yeah, that's a great question because that's the whole fun of handling data. You need to ensure its meaning is first understood. So, we are not just dumping data into a storage place, but rather assign a meaningful context. In today's announcement, again, the data zone was unveiled to give meaning to data. And I think those are key concrete steps that we take to our customers as well with some good blueprints, methodical ways of approaching data and ultimately gaining business insights. >> And maybe I'll add just something real quick to that. The theme we're seeing and hearing a lot about is data monetization. So, technology companies have figured it out and used techniques to personalize things and get you ads, probably that you don't want half the time. But now all industries are really looking to do that. Looking at ways to open new revenue channels, looking at ways to drive a better customer experience, a better employee experience. We've got a ton of examples of that, Big Oil and Gas leveraging like well and machine data, coming in to be more efficient when they're pumping and moving commodities around. We work a lot in the medium entertainment space and so obviously, getting targeted ads to consumers during the right periods of TV or movies or et cetera. Especially with the advert on Netflix and all your streaming videos. So, it's been really interesting but we really see the future in leveraging data as one of your biggest corporate assets. >> Brilliant. >> So, I'm just curious on the ad thing, just real quick and I'll let you go, Lisa. So, do you still fall victim to falling for the advertising even though you know it's been strategically put there for you to consume in that moment? >> Most of the time. >> I mean, I think we all do. We're all, (indistinct), you're behind the curtain so to speak. >> The Amazon Truck shows up every day at my house, which is great, right? >> Hello again >> Same. >> But I think the power of it is you are giving the customer what they're looking for. >> That's it. >> And you know... >> Exactly. We have that expectation, we want it. >> 100%. >> We know that. >> Agree. >> We don't need to buy it. But technology has made it so easy to transact. That's like when developers started going to the cloud years ago, it was just, it was a swipe. It was so simple. Brandon, talk about the changes in cloud and cloud migration that TEKsystems has seen, particularly in the last couple of years as every company was rushing to go digital because they had to. >> So several years ago, we kind of pushed away that cloud first mentality to the side and we use more of a cloud smart kind of fashion, right? Does everything need to go to the cloud? No. Do applications, data, need to go to the cloud in a way that's modern and takes advantages of what the cloud can provide and all the new services that are being released this week and ongoing. So, the other thing we're seeing is initiatives that have traditionally been in the CTO, CIO organization aren't necessarily all that successful because we're seeing a complete misalignment between business goals and IT achievements, outcomes, et cetera. You can automate things, you can move it to the cloud, but if you didn't solve a core business problem or challenge, what'd you really do? >> Yeah, just to add on that, it's all about putting data and people together. And then how we can actually ensure the workforce is equally brought up to speed on these new technologies. That has been something that we have seen tremendous improvement in the last 24 months where customers are ready to take up new challenges and the end users are ready to learn something new and not just stick onto that status quo mindset. >> Where do you guys factor in to bringing in AWS in the customer's cloud journeys? What is that partnership like? >> We always first look for where the customer is in their cloud journey path and make sure we advise them with the right next steps. And AWS having its services across the spectrum makes it even easier for us to look at what business problem they're solving and then align it according to the process and technology so that at the end of the day, we want end user adoption. We don't want to build a fancy new gadget that no one uses. >> Just because you built it doesn't mean they'll come. And I think that's the classic engineering marketing dilemma as well as balance to healthy tension. I would say between both. You mentioned Srini, you mentioned workforce just a second ago. What sort of trends are you seeing in workforce development? >> Generally speaking, there are a lot of services now that can quantify your code for errors and then make sure that the code that you're pushing into production is well tested. So what we are trying to make sure is a healthy mix of trying to solve a business problem and asking the right questions. Like today, even in the keynote, it was all about how QuickSight, for example, has additional features now that tells why something happened. And that's the kind of mindset we want our end users to adopt. Not just restricting themselves to a reactive analytics, but rather ask the question why, why did it happen? Why did my sales go down? And I think those technologies and mindset shift is happening across the workforce. >> From a workforce development standpoint, we're seeing there's not enough workforce and the core skills of data, DevOps, standard cloud type work. So, we're actually an ATP advanced training partner, one of the few within the AWS network. So, we've developed programs like our Rising Talent Program that are allowing us to bring the workforce up to the skills that are necessary in this new world. So, it's a more build versus buy strategy because we're on talents real, though it may start to wane a little bit as we change the macroeconomic outlook in 2023, but it's still there. And we still believe that building those workforce and investing in your people is the right thing to do. >> It is, and I think there's a strong alignment there with AWS and their focus on that as well. I wanted to ask you, Brandon. >> Brandon: Absolutely. >> One of the things, so our boss, John Furrier, the co CEO of theCUBE, talked with Adam Selipsky just a week or maybe 10 days ago. He always gets an exclusive interview with the CEO of AWS before reinvent, and one of the things that Adam shared with him is that customers, CEOs and CIOs are not coming to Adam, to this head of AWS to talk about technology, they want to talk about transformation. He's talking about... >> The topic this year. >> Moving away from amorphous topic of digital transformation to business transformation. Are you seeing the same thing in your customer? >> 100%, and if you're not starting at the business level, these initiatives are going to fail. We see it all the time. Again, it's about that misalignment and there's no good answer to that. But digital, I think is amorphous to some degree. We play a lot with the One North partnership that I mentioned earlier, really focusing on that strategy element because consumer dollars are shrinking via inflation, via what we're heading into, and we have to create the best experience possible. We have to create an omnichannel experience to get our products or services to market. And if we're not looking at those as our core goals and we're looking at them as IT or technology challenges, we're not looking in the right place. >> Well, and businesses aren't going to be successful if they're looking at it in those siloed organizations. Data has to be democratizing and we've spent same data democratization for so long, but really, we're seeing that it has to be moving out into the lines of business because another thing Adam shared with John Furrier is that he sees and I'm curious what your thoughts are on this, the title of data analysts going away because everybody in different functions and different lines of business within an organization are going to have to be data analysts to some degree, to use data whether it's marketing, ops, sales, finance, are you seeing the same? >> That is true. I mean, at this point, we are all in the connected world, right? Every data point is connected in some form or shape to another data point. >> Savanna: There are many data points, just sitting here, yeah. >> Absolutely, so I think if you are strategizing, data needs to be right in the center of it. And then your business problems need to be addressed with reliable data. >> No, I mean, advertising, supply chain, marketing, they're all interconnected now, and we're looking at ways to bring a lot of that siloed data into one place so we can make use to it. It goes back to that monetization element of our data. >> That's a lot about context and situational awareness. We want what we want, when we want it, even before we knew we needed it then. I think I said that right. But you know, it's always more faster, quicker and then scaling things up. You see a lot of different customers across verticals, you have an absolutely massive team. Give us a sneak peek into 2023. What does the future hold? >> 2023 is again, to today's keynote, I'm bringing it back because it was a keynote filled with vision and limitless possibilities. And that's what we see. Right now, our customers, they are no longer scared to go and take the plunge into the cloud. And as Brandon said, it's all about being smart about those decisions. So, we are very excited that together with the partnership that we recently acquired and the services and the depth, along with the horizontal domain expertise, we can actually help customers make meaningful message out of their data points. And that keeps us really excited for next year. >> Love that, Brandon, what about you? >> I think the obvious one is DevOps and a focus on optimization, financially, security, et cetera, just for the changing times. The other one is, I still think that digital is going to continue to be a big push in 2023, namely making sure that experience is at its best, whether that's employee and combating the war on talent, keeping your people or opening new revenue streams, enhancing existing revenue streams. You got to keep working on that. >> We got to keep the people happy with the machines and the systems that we are building as we all know. But it's very nice, it's been a lot of human-centric focus and a lot of customer obsession here at the show. We know it's a big thing for you all, for Amazon, for pretty much everyone who sat here. Hopefully it is in general. Hopefully there's nobody who doesn't care about their community, we're not talking to them, if that's the case, we have a new challenge on theCUBE for the show, this year as we kind of prepped you for and can call it a bumper sticker, you can call it a 30 second sizzle reel. But this is sort of your Instagram moment, your TikTok, your thought of leadership highlight. What's the most important story coming out of the show? Srini, you've been quoting the keynotes very well, so, I'm going to you first on this one. >> I think overall, it's all about owning the change. In our TEKsystems culture, it's all about striving for excellence through serving others and owning the change. And so it makes me very excited that when we get that kind of keynote resonating the same message that we invite culturally, that's a big win-win for all the companies. >> It's all about the shared vision. A lot of people with similar vision in this room right now, in this room, like it's a room, it's a massive expo center, just to be clear, I'm sure everyone can see in the background. Brandon >> I would say partnership, continuing to enhance our strategic partnership with AWS, continuing to be our customers' partners in transformation. And bringing those two things together here has been a predominance of my time this week. And we'll continue throughout the week, but we're in it together with our customers and with AWS and looking forward to the future. >> Yeah, that's a beautiful note to end on there. Brandon, Srini, thank you both so much for being here with us. Fantastic to learn from your insights and to continue to emphasize on this theme of collaboration. We look forward to the next conversation with you. Thank all of you for tuning in wherever you happen to be hanging out and watching this fabulous live stream or the replay. We are here at AWS Reinvent 2022 in wonderful sunny Las Vegas, Nevada with Lisa Martin. My name is Savannah Peterson, we are theCUBE, the leading source for high tech coverage.

Published Date : Nov 30 2022

SUMMARY :

and welcome back to AWS Reinvent 2022. So excited to be here Lisa, I think it's only in attendance that have been to all 11. at that level sooner. and we're only seeing what's I mean, there's a Yes, and there's sunlight. to be sitting here next to you are going to love what AWS is It's similar to what we had at in the Amazon partner ecosystem, that are not afraid doing the dirty work is the ability to scale. Savanna: That's a that no wonder you're wearing the way on the advisory are ready to take data to cloud I love that you Talked about it, that was impressive. Well, we can't be at an event like this I mean, even to thrive and grow, that we take to our customers as well coming in to be more efficient So, I'm just curious on the ad thing, I mean, I think we all do. is you are giving the customer We have that expectation, we want it. We don't need to buy it. that cloud first mentality to the side and the end users are ready so that at the end of the day, And I think that's the classic and asking the right questions. is the right thing to do. with AWS and their focus on that as well. and one of the things to business transformation. and there's no good answer to that. that it has to be moving out to another data point. Savanna: There are many data points, data needs to be right It goes back to that What does the future hold? 2023 is again, to today's keynote, is going to continue to and the systems that we are and owning the change. center, just to be clear, continuing to be our customers' and to continue to emphasize

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
BrandonPERSON

0.99+

AdamPERSON

0.99+

SavannaPERSON

0.99+

Lisa MartinPERSON

0.99+

AWSORGANIZATION

0.99+

Savannah PetersonPERSON

0.99+

Adam SelipskyPERSON

0.99+

SriniPERSON

0.99+

LisaPERSON

0.99+

2023DATE

0.99+

John FurrierPERSON

0.99+

70,000QUANTITY

0.99+

30 secondQUANTITY

0.99+

One North InteractiveORGANIZATION

0.99+

AmazonORGANIZATION

0.99+

52 minutesQUANTITY

0.99+

next yearDATE

0.99+

DetroitLOCATION

0.99+

fourthQUANTITY

0.99+

TEKsystems Global ServicesORGANIZATION

0.99+

100%QUANTITY

0.99+

firstQUANTITY

0.99+

over 40 yearsQUANTITY

0.99+

TEKsystemsORGANIZATION

0.99+

bothQUANTITY

0.99+

todayDATE

0.99+

One StrategyORGANIZATION

0.99+

10 days agoDATE

0.99+

Big Oil and GasORGANIZATION

0.99+

Las Vegas, NevadaLOCATION

0.99+

oneQUANTITY

0.98+

fifthQUANTITY

0.97+

two thingsQUANTITY

0.97+

Las Vegas, NevadaLOCATION

0.97+

this weekDATE

0.97+

80,000 global employeesQUANTITY

0.97+

NetflixORGANIZATION

0.97+

this yearDATE

0.97+

OneQUANTITY

0.97+

One NorthORGANIZATION

0.96+

several years agoDATE

0.95+

a weekDATE

0.94+

11QUANTITY

0.93+

1%QUANTITY

0.93+

InstagramORGANIZATION

0.91+

theCUBEORGANIZATION

0.9+

last couple of yearsDATE

0.89+

Amazon TruckORGANIZATION

0.89+

Srinivasan Swaminatha & Brandon Carroll, TEKsystems Global Services | AWS re:Invent 2022


 

>> 10, nine, eight, (clears throat) four, three. >> Good afternoon, fellow cloud nerds and welcome back to AWS Reinvent 2022. We are live here from fabulous Las Vegas, Nevada. My name is Savannah Peterson, joined by Lisa Martin. So excited to be here Lisa, it's my first reinvent. >> Is it really? >> Yeah. >> I think it's only like my fourth or fifth. >> Only your fourth or fifth. >> Only. >> You're such a pro here. >> There's some serious veterans here in attendance that have been to all 11. >> I love that. >> Yeah. Wow, go them. I know, maybe we'll be at that level sooner. >> One day we will. >> Are you enjoying the show so far? >> Absolutely, it is. I cannot believe how many people are here. We've had 70,000 and we're only seeing what's at the foundation Expo Hall, not at the other hotel. So, I can only imagine. >> I mean, there's a world outside of this. >> Yes, and there's sunlight. There's actual sunlight outside of this room. >> Nobel idea. Well, Lisa, I'm very excited to be sitting here next to you and to welcome our fabulous guests, from TEKsystems, we have Brandon and Srini. Thank you so much for being here. How is the show going for you gentlemen so far? >> It's great. Lot of new insights and the customers are going to love what AWS is releasing in this reinvent. >> There is such a community here, and I love that vibe. It's similar to what we had at Cloud Native con in Detroit. So much collaboration going on. I assume most folks know a lot about TEKsystems who are watching, but just in case they don't, Brandon, give us the pitch. >> You bet. So full stack IT solutions firm, been in business for over 40 years, 80,000 global employees, really specializing in digital transformation, enterprise modernization services. We have partners in One Strategy, which is an an acquisition we made, but a well known premier partner in the Amazon partner ecosystem, as well as One North Interactive, who is our boutique brand, creative and digital strategy firm. So together, we really feel like we can bring full end-to-end solutions for digital and modernization initiatives. >> So, I saw some notes where TEKsystems are saying organizations need experienced AWS partners that are not afraid doing the dirty work of digital transformation, who really can advise and execute. Brandon, talk to us about how TEKsystems and AWS are working together to help customers on that journey which is nebulous of digital transformation. >> So, our real hallmark is the ability to scale. We partner with AWS in a lot of different ways. In fact, we just signed our strategic collaboration agreement. So, we're in the one percenter group in the whole partner network. >> Savanna: That's a pretty casual flex there. >> Not bad. >> I love that, top 1%, that no wonder you're wearing that partner pin so proud today. (speaking indistinctly) >> But we're working all the way on the advisory and working with their pro serve organization and then transforming that into large scale mass migration services, a lot of data modernization that Srini is an absolute expert in. I'm sure he can add some context too, but it's been a great partnership for many years now. >> In the keynote, Adam spent almost 52 minutes on data, right? So, it emphasizes how organizations are ready to take data to cloud and actually make meaningful insights and help their own customers come out of it by making meaningful decisions. So, we are glad to be part of this entire ecosystem. >> I love that you quantified how many minutes. >> I know. >> Talked about it, that was impressive. There's a little bit of data driven thinking going on here. >> I think so. >> Yeah. >> Well, we can't be at an event like this without talking about data for copious amounts of time, 52 minutes, has just used this morning. >> Right, absolutely. >> But every company these days has to be a data company. There's no choice to be successful, to thrive, to survive. I mean, even to thrive and grow, if it's a grocery store or your local gas station or what? You name it, that company has to be a data company. But the challenge of the data volume, the explosion in data is huge for organizations to really try to figure out and sift through what they have, where is all of it? How do we make sense of it? How do we act on it and get insights? That's a big challenge. How is TEKsystems helping customers tackle that challenge? >> Yeah, that's a great question because that's the whole fun of handling data. You need to ensure its meaning is first understood. So, we are not just dumping data into a storage place, but rather assign a meaningful context. In today's announcement, again, the data zone was unveiled to give meaning to data. And I think those are key concrete steps that we take to our customers as well with some good blueprints, methodical ways of approaching data and ultimately gaining business insights. >> And maybe I'll add just something real quick to that. The theme we're seeing and hearing a lot about is data monetization. So, technology companies have figured it out and used techniques to personalize things and get you ads, probably that you don't want half the time. But now all industries are really looking to do that. Looking at ways to open new revenue channels, looking at ways to drive a better customer experience, a better employee experience. We've got a ton of examples of that, Big Oil and Gas leveraging like well and machine data, coming in to be more efficient when they're pumping and moving commodities around. We work a lot in the medium entertainment space and so obviously, getting targeted ads to consumers during the right periods of TV or movies or et cetera. Especially with the advert on Netflix and all your streaming videos. So, it's been really interesting but we really see the future in leveraging data as one of your biggest corporate assets. >> Brilliant. >> So, I'm just curious on the ad thing, just real quick and I'll let you go, Lisa. So, do you still fall victim to falling for the advertising even though you know it's been strategically put there for you to consume in that moment? >> Most of the time. >> I mean, I think we all do. We're all, (indistinct), you're behind the curtain so to speak. >> The Amazon Truck shows up every day at my house, which is great, right? >> Hello again >> Same. >> But I think the power of it is you are giving the customer what they're looking for. >> That's it. >> And you know... >> Exactly. We have that expectation, we want it. >> 100%. >> We know that. >> Agree. >> We don't need to buy it. But technology has made it so easy to transact. That's like when developers started going to the cloud years ago, it was just, it was a swipe. It was so simple. Brandon, talk about the changes in cloud and cloud migration that TEKsystems has seen, particularly in the last couple of years as every company was rushing to go digital because they had to. >> So several years ago, we kind of pushed away that cloud first mentality to the side and we use more of a cloud smart kind of fashion, right? Does everything need to go to the cloud? No. Do applications, data, need to go to the cloud in a way that's modern and takes advantages of what the cloud can provide and all the new services that are being released this week and ongoing. So, the other thing we're seeing is initiatives that have traditionally been in the CTO, CIO organization aren't necessarily all that successful because we're seeing a complete misalignment between business goals and IT achievements, outcomes, et cetera. You can automate things, you can move it to the cloud, but if you didn't solve a core business problem or challenge, what'd you really do? >> Yeah, just to add on that, it's all about putting data and people together. And then how we can actually ensure the workforce is equally brought up to speed on these new technologies. That has been something that we have seen tremendous improvement in the last 24 months where customers are ready to take up new challenges and the end users are ready to learn something new and not just stick onto that status quo mindset. >> Where do you guys factor in to bringing in AWS in the customer's cloud journeys? What is that partnership like? >> We always first look for where the customer is in their cloud journey path and make sure we advise them with the right next steps. And AWS having its services across the spectrum makes it even easier for us to look at what business problem they're solving and then align it according to the process and technology so that at the end of the day, we want end user adoption. We don't want to build a fancy new gadget that no one uses. >> Just because you built it doesn't mean they'll come. And I think that's the classic engineering marketing dilemma as well as balance to healthy tension. I would say between both. You mentioned Srini, you mentioned workforce just a second ago. What sort of trends are you seeing in workforce development? >> Generally speaking, there are a lot of services now that can quantify your code for errors and then make sure that the code that you're pushing into production is well tested. So what we are trying to make sure is a healthy mix of trying to solve a business problem and asking the right questions. Like today, even in the keynote, it was all about how QuickSight, for example, has additional features now that tells why something happened. And that's the kind of mindset we want our end users to adopt. Not just restricting themselves to a reactive analytics, but rather ask the question why, why did it happen? Why did my sales go down? And I think those technologies and mindset shift is happening across the workforce. >> From a workforce development standpoint, we're seeing there's not enough workforce and the core skills of data, DevOps, standard cloud type work. So, we're actually an ATP advanced training partner, one of the few within the AWS network. So, we've developed programs like our Rising Talent Program that are allowing us to bring the workforce up to the skills that are necessary in this new world. So, it's a more build versus buy strategy because we're on talents real, though it may start to wane a little bit as we change the macroeconomic outlook in 2023, but it's still there. And we still believe that building those workforce and investing in your people is the right thing to do. >> It is, and I think there's a strong alignment there with AWS and their focus on that as well. I wanted to ask you, Brandon. >> Brandon: Absolutely. >> One of the things, so our boss, John Furrier, the co CEO of theCUBE, talked with Adam Selipsky just a week or maybe 10 days ago. He always gets an exclusive interview with the CEO of AWS before reinvent, and one of the things that Adam shared with him is that customers, CEOs and CIOs are not coming to Adam, to this head of AWS to talk about technology, they want to talk about transformation. He's talking about... >> The topic this year. >> Moving away from amorphous topic of digital transformation to business transformation. Are you seeing the same thing in your customer? >> 100%, and if you're not starting at the business level, these initiatives are going to fail. We see it all the time. Again, it's about that misalignment and there's no good answer to that. But digital, I think is amorphous to some degree. We play a lot with the One North partnership that I mentioned earlier, really focusing on that strategy element because consumer dollars are shrinking via inflation, via what we're heading into, and we have to create the best experience possible. We have to create an omnichannel experience to get our products or services to market. And if we're not looking at those as our core goals and we're looking at them as IT or technology challenges, we're not looking in the right place. >> Well, and businesses aren't going to be successful if they're looking at it in those siloed organizations. Data has to be democratizing and we've spent same data democratization for so long, but really, we're seeing that it has to be moving out into the lines of business because another thing Adam shared with John Furrier is that he sees and I'm curious what your thoughts are on this, the title of data analysts going away because everybody in different functions and different lines of business within an organization are going to have to be data analysts to some degree, to use data whether it's marketing, ops, sales, finance, are you seeing the same? >> That is true. I mean, at this point, we are all in the connected world, right? Every data point is connected in some form or shape to another data point. >> Savanna: There are many data points, just sitting here, yeah. >> Absolutely, so I think if you are strategizing, data needs to be right in the center of it. And then your business problems need to be addressed with reliable data. >> No, I mean, advertising, supply chain, marketing, they're all interconnected now, and we're looking at ways to bring a lot of that siloed data into one place so we can make use to it. It goes back to that monetization element of our data. >> That's a lot about context and situational awareness. We want what we want, when we want it, even before we knew we needed it then. I think I said that right. But you know, it's always more faster, quicker and then scaling things up. You see a lot of different customers across verticals, you have an absolutely massive team. Give us a sneak peek into 2023. What does the future hold? >> 2023 is again, to today's keynote, I'm bringing it back because it was a keynote filled with vision and limitless possibilities. And that's what we see. Right now, our customers, they are no longer scared to go and take the plunge into the cloud. And as Brandon said, it's all about being smart about those decisions. So, we are very excited that together with the partnership that we recently acquired and the services and the depth, along with the horizontal domain expertise, we can actually help customers make meaningful message out of their data points. And that keeps us really excited for next year. >> Love that, Brandon, what about you? >> I think the obvious one is DevOps and a focus on optimization, financially, security, et cetera, just for the changing times. The other one is, I still think that digital is going to continue to be a big push in 2023, namely making sure that experience is at its best, whether that's employee and combating the war on talent, keeping your people or opening new revenue streams, enhancing existing revenue streams. You got to keep working on that. >> We got to keep the people happy with the machines and the systems that we are building as we all know. But it's very nice, it's been a lot of human-centric focus and a lot of customer obsession here at the show. We know it's a big thing for you all, for Amazon, for pretty much everyone who sat here. Hopefully it is in general. Hopefully there's nobody who doesn't care about their community, we're not talking to them, if that's the case, we have a new challenge on theCUBE for the show, this year as we kind of prepped you for and can call it a bumper sticker, you can call it a 30 second sizzle reel. But this is sort of your Instagram moment, your TikTok, your thought of leadership highlight. What's the most important story coming out of the show? Srini, you've been quoting the keynotes very well, so, I'm going to you first on this one. >> I think overall, it's all about owning the change. In our TEKsystems culture, it's all about striving for excellence through serving others and owning the change. And so it makes me very excited that when we get that kind of keynote resonating the same message that we invite culturally, that's a big win-win for all the companies. >> It's all about the shared vision. A lot of people with similar vision in this room right now, in this room, like it's a room, it's a massive expo center, just to be clear, I'm sure everyone can see in the background. Brandon >> I would say partnership, continuing to enhance our strategic partnership with AWS, continuing to be our customers' partners in transformation. And bringing those two things together here has been a predominance of my time this week. And we'll continue throughout the week, but we're in it together with our customers and with AWS and looking forward to the future. >> Yeah, that's a beautiful note to end on there. Brandon, Srini, thank you both so much for being here with us. Fantastic to learn from your insights and to continue to emphasize on this theme of collaboration. We look forward to the next conversation with you. Thank all of you for tuning in wherever you happen to be hanging out and watching this fabulous live stream or the replay. We are here at AWS Reinvent 2022 in wonderful sunny Las Vegas, Nevada with Lisa Martin. My name is Savannah Peterson, we are theCUBE, the leading source for high tech coverage.

Published Date : Nov 30 2022

SUMMARY :

So excited to be here Lisa, I think it's only in attendance that have been to all 11. at that level sooner. and we're only seeing what's I mean, there's a Yes, and there's sunlight. to be sitting here next to you are going to love what AWS is It's similar to what we had at in the Amazon partner ecosystem, that are not afraid doing the dirty work is the ability to scale. Savanna: That's a that no wonder you're wearing the way on the advisory are ready to take data to cloud I love that you Talked about it, that was impressive. Well, we can't be at an event like this I mean, even to thrive and grow, that we take to our customers as well coming in to be more efficient So, I'm just curious on the ad thing, I mean, I think we all do. is you are giving the customer We have that expectation, we want it. We don't need to buy it. that cloud first mentality to the side and the end users are ready so that at the end of the day, And I think that's the classic and asking the right questions. is the right thing to do. with AWS and their focus on that as well. and one of the things to business transformation. and there's no good answer to that. that it has to be moving out to another data point. Savanna: There are many data points, data needs to be right It goes back to that What does the future hold? 2023 is again, to today's keynote, is going to continue to and the systems that we are and owning the change. center, just to be clear, continuing to be our customers' and to continue to emphasize

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
BrandonPERSON

0.99+

AWSORGANIZATION

0.99+

SavannaPERSON

0.99+

AdamPERSON

0.99+

Savannah PetersonPERSON

0.99+

Adam SelipskyPERSON

0.99+

Lisa MartinPERSON

0.99+

SriniPERSON

0.99+

30 secondQUANTITY

0.99+

LisaPERSON

0.99+

John FurrierPERSON

0.99+

2023DATE

0.99+

DetroitLOCATION

0.99+

fourthQUANTITY

0.99+

AmazonORGANIZATION

0.99+

52 minutesQUANTITY

0.99+

70,000QUANTITY

0.99+

One North InteractiveORGANIZATION

0.99+

fifthQUANTITY

0.99+

100%QUANTITY

0.99+

bothQUANTITY

0.99+

Las Vegas, NevadaLOCATION

0.99+

next yearDATE

0.99+

over 40 yearsQUANTITY

0.99+

firstQUANTITY

0.99+

TEKsystems Global ServicesORGANIZATION

0.99+

TEKsystemsORGANIZATION

0.99+

One StrategyORGANIZATION

0.99+

NetflixORGANIZATION

0.99+

todayDATE

0.99+

80,000 global employeesQUANTITY

0.98+

threeQUANTITY

0.98+

Big Oil and GasORGANIZATION

0.98+

two thingsQUANTITY

0.98+

oneQUANTITY

0.98+

nineQUANTITY

0.98+

this yearDATE

0.97+

eightQUANTITY

0.97+

Srinivasan SwaminathaPERSON

0.97+

11QUANTITY

0.97+

this weekDATE

0.97+

Las Vegas, NevadaLOCATION

0.96+

10 days agoDATE

0.96+

several years agoDATE

0.95+

theCUBEORGANIZATION

0.95+

OneQUANTITY

0.95+

fourQUANTITY

0.94+

Brandon CarrollPERSON

0.9+

1%QUANTITY

0.9+

Dan Kogan, Pure Storage & Venkat Ramakrishnan, Portworx by Pure Storage | AWS re:Invent 2022


 

(upbeat music) >> Welcome back to Vegas. Lisa Martin and Dave Vellante here with theCUBE live on the Venetian Expo Hall Floor, talking all things AWS re:Invent 2022. This is the first full day of coverage. It is jam-packed here. People are back. They are ready to hear all the new innovations from AWS. Dave, how does it feel to be back yet again in Vegas? >> Yeah, Vegas. I think it's my 10th time in Vegas this year. So, whatever. >> This year alone. You must have a favorite steak restaurant then. >> There are several. The restaurants in Vegas are actually really good. >> You know? >> They are good. >> They used to be terrible. But I'll tell you. My favorite? The place that closed. >> Oh! >> Yeah, closed. In between where we are in the Wynn and the Venetian. Anyway. >> Was it CUT? >> No, I forget what the name was. >> Something else, okay. >> It was like a Greek sort of steak place. Anyway. >> Now, I'm hungry. >> We were at Pure Accelerate a couple years ago. >> Yes, we were. >> When they announced Cloud Block Store. >> That's right. >> Pure was the first- >> In Austin. >> To do that. >> Yup. >> And then they made the acquisition of Portworx which was pretty prescient given that containers have been going through the roof. >> Yeah. >> So I'm sort of excited to have these guys on and talk about that. >> We're going to unpack all of this. We've got one of our alumni back with us, Venkat Ramakrishna, VP of Product, Portworx by Pure Storage. And Dan Kogan joins us for the first time, VP of Product Management and Product Marketing, FlashArray at Pure Storage. Guys, welcome to the program. >> Thank you. >> Hey, guys. >> Dan: Thanks for having us. >> Do you have a favorite steak restaurant in Vegas? Dave said there's a lot of good choices. >> There's a lot of good steak restaurants here. >> I like SDK. >> Yeah, that's a good one. >> That's the good one. >> That's a good one. >> Which one? >> SDK. >> SDK. >> Where's that? >> It's, I think, in Cosmopolitan. >> Ooh. >> Yeah. >> Oh, yeah, yeah, yeah. >> It's pretty good, yeah. >> There's one of the Western too that's pretty. >> I'm an Herbs and Rye guy. Have you ever been there? >> No. >> No. >> Herbs and Rye is off strip, but it's fantastic. It's kind of like a locals joint. >> I have to dig through all of this great stuff today and then check that out. Talk to me. This is our first day, obviously. First main day. I want to get both of your perspectives. Dan, we'll start with you since you're closest to me. How are you finding this year's event so far? Obviously, tons of people. >> Busy. >> Busy, yeah. >> Yeah, it is. It is old times. Bigger, right? Last re:Invent I was at was 2019 right before everything shut down and it's probably half the size of this which is a different trend than I feel like most other tech conferences have gone where they've come back, but a little bit smaller. re:Invent seems to be the IT show. >> It really does. Venkat, are you finding the same? In terms of what you're experiencing so far on day one of the events? >> Yeah, I mean... There's tremendous excitement. Overall, I think it's good to be back. Very good crowd, great turnout, lot of excitement around some of the new offerings we've announced. The booth traffic has been pretty good. And just the quality of the conversations, the customer meetings, have been really good. There's very interesting use cases shaping up and customers really looking to solve real large scale problems. Yeah, it's been a phenomenal first day. >> Venkat, talk a little bit about, and then we'll get to you Dan as well, the relationship that Portworx by Pure Storage has with AWS. Maybe some joint customers. >> Yeah, so we... Definitely, we have been a partner of AWS for quite some time, right? Earlier this year, we signed what is called a strategic investment letter with AWS where we kind of put some joint effort together like to better integrate our products. Plus, kind of get in front of our customers more together and educate them on how going to how they can deploy and build vision critical apps on EKS and EKS anywhere and Outpost. So that partnership has grown a lot over the last year. We have a lot of significant mutual customer wins together both on the public cloud on EKS as well as on EKS anywhere, right? And there are some exciting use cases around Edge and Edge deployments and different levels of Edge as well with EKS anywhere. And there are pretty good wins on the Outpost as well. So that partnership I think is kind of like growing across not just... We started off with the one product line. Now our Portworx backup as a service is also available on EKS and along with the Portworx Data Services. So, it is also expanded across the product lanes as well. >> And then Dan, you want to elaborate a bit on AWS Plus Pure? >> Yeah, it's for kind of what we'll call the core Pure business or the traditional Pure business. As Dave mentioned, Cloud Block Store is kind of where things started and we're seeing that move and evolve from predominantly being a DR site and kind of story into now more and more production applications being lifted and shifted and running now natively in AWS honor storage software. And then we have a new product called Pure Fusion which is our storage as code automation product essentially. It takes you from moving and managing of individual arrays, now obfuscates a fleet level allows you to build a very cloud-like backend and consume storage as code. Very, very similar to how you do with AWS, with an EBS. That product is built in AWS. So it's a SaaS product built in AWS, really allowing you to turn your traditional Pure storage into an AWS-like experience. >> Lisa: Got it. >> What changed with Cloud Block Store? 'Cause if I recall, am I right that you basically did it on S3 originally? >> S3 is a big... It's a number of components. >> And you had a high performance EC2 instances. >> Dan: Yup, that's right. >> On top of lower cost object store. Is that still the case? >> That's still the architecture. Yeah, at least for AWS. It's a different architecture in Azure where we leverage their disc storage more. But in AWS were just based on essentially that backend. >> And then what's the experience when you go from, say, on-prem to AWS to sort of a cross cloud? >> Yeah, very, very simple. It's our replication technology built in. So our sync rep, our async rep, our active cluster technology is essentially allowing you to move the data really, really seamlessly there and then again back to Fusion, now being that kind of master control plan. You can have availability zones, running Cloud Block Store instances in AWS. You can be running your own availability zones in your data centers wherever those may happen to be, and that's kind of a unification layer across it all. >> It looks the same to the customer. >> To the customer, at the end of the day, it's... What the customer sees is the purity operating system. We have FlashArray proprietary hardware on premises. We have AWS's hardware that we run it on here. But to the customer, it's just the FlashArray. >> That's a data super cloud actually. Yeah, it's a data super cloud. >> I'd agree. >> It spans multiple clouds- >> Multiple clouds on premises. >> It extracts all the complexity of the underlying muck and the primitives and presents a common experience. >> Yeah, and it's the same APIs, same management console. >> Dave: Yeah, awesome. >> Everything's the same. >> See? It's real. It's a thing, On containers, I have a question. So we're in this environment, everybody wants to be more efficient, what's happening with containers? Is there... The intersection of containers and serverless, right? You think about all the things you have to do to run containers in VMs, configure everything, configure the memory, et cetera, and then serverless simplifies all that. I guess Knative in between or I guess Fargate. What are you seeing with customers between stateless apps, stateful apps, and how it all relates to containers? >> That's a great question, right? I think that one of the things that what we are seeing is that as people run more and more workloads in the cloud, right? There's this huge movement towards being the ability to bring these applications to run anywhere, right? Not just in one public cloud, but in the data centers and sometimes the Edge clouds. So there's a lot of portability requirements for the applications, right? I mean, yesterday morning I was having breakfast with a customer who is a big AWS customer but has to go into an on-prem air gap deployment for one of their large customers and is kind of re-platforming some other apps into containers in Kubernetes because it makes it so much easier for them to deploy. So there is no longer the debate of, is it stateless versus it stateful, it's pretty much all applications are moving to containers, right? And in that, you see people are building on Kubernetes and containers is because they wanted multicloud portability for their applications. Now the other big aspect is cost, right? You can significantly run... You know, like lower cost by running with Kubernetes and Portworx and by on the public cloud or on a private cloud, right? Because it lets you get more out of your infrastructure. You're not all provisioning your infrastructure. You are like just deploying the just-enough infrastructure for your application to run with Kubernetes and scale it dynamically as your application load scales. So, customers are better able to manage costs. >> Does serverless play in here though? Right? Because if I'm running serverless, I'm not paying for the compute the whole time. >> Yeah. >> Right? But then stateless and stateful come into play. >> Serverless has a place, but it is more for like quick event-driven decision. >> Dave: The stateless apps. >> You know, stuff that needs to happen. The serverless has a place, but majority of the applications have need compute and more compute to run because there's like a ton of processing you have to do, you're serving a whole bunch of users, you're serving up media, right? Those are not typically good serverless apps, right? The several less apps do definitely have a place. There's a whole bunch of minor code snippets or events you need to process every now and then to make some decisions. In that, yeah, you see serverless. But majority of the apps are still requiring a lot of compute and scaling the compute and scaling storage requirements at a time. >> So what Venkat was talking about is cost. That is probably our biggest tailwind from a cloud adoption standpoint. I think initially for on-premises vendors like Pure Storage or historically on-premises vendors, the move to the cloud was a concern, right? In that we're getting out the data center business, we're going all in on the cloud, what are you going to do? That's kind of why we got ahead of that with Cloud Block Store. But as customers have matured in their adoption of cloud and actually moved more applications, they're becoming much more aware of the costs. And so anywhere you can help them save money seems to drive adoption. So they see that on the Kubernetes side, on our side, just by adding in things that we do really well: Data reduction, thin provisioning, low cost snaps. Those kind of things, massive cost savings. And so it's actually brought a lot of customers who thought they weren't going to be using our storage moving forward back into the fold. >> Dave: Got it. >> So cost saving is great, huge business outcomes potentially for customers. But what are some of the barriers that you're helping customers to overcome on the storage side and also in terms of moving applications to Kubernetes? What are some of those barriers that you could help us? >> Yeah, I mean, I can answer it simply from a core FlashArray side, it's enabling migration of applications without having to refactor them entirely, right? That's Kubernetes side is when they think about changing their applications and building them, we'll call quote unquote more cloud native, but there are a lot of customers that can't or won't or just aren't doing that, but they want to run those applications in the cloud. So the movement is easier back to your data super cloud kind of comment, and then also eliminating this high cost associated with it. >> I'm kind of not a huge fan of the whole repatriation narrative. You know, you look at the numbers and it's like, "Yeah, there's something going on." But the one use case that looks like it's actually valid is, "I'm going to test in the cloud and I'm going to deploy on-prem." Now, I dunno if that's even called repatriation, but I'm looking to help the repatriation narrative because- >> Venkat: I think it's- >> But that's a real thing, right? >> Yeah, it's more than repatriation, right? It's more about the ability to run your app, right? It's not just even test, right? I mean, you're going to have different kinds of governance and compliance and regulatory requirements have to run your apps in different kinds of cloud environments, right? There are certain... Certain regions may not have all of the compliance and regulatory requirements implemented in that cloud provider, right? So when you run with Kubernetes and containers, I mean, you kind of do the transformation. So now you can take that app and run an infrastructure that allows you to deliver under those requirements as well, right? So that portability is the major driver than repatriation. >> And you would do that for latency reasons? >> For latency, yeah. >> Or data sovereign? >> Data sovereignty. >> Data sovereignty. >> Control. >> I mean, yeah. Availability of your application and data just in that region, right? >> Okay, so if the capability is not there in the cloud region, you come in and say, "Hey, we can do that on-prem or in a colo and get you what you need to comply to your EDX." >> Yeah, or potentially moves to a different cloud provider. It's just a lot more control that you're providing on customer at the end of the day. >> What's that move like? I mean, now you're moving data and everybody's going to complain about egress fees. >> Well, you shouldn't be... I think it's more of a one-time move. You're probably not going to be moving data between cloud providers regularly. But if for whatever reasons you decide that I'm going to stop running in X Cloud and I'm going to move to this cloud, what's the most seamless way to do? >> So a customer might say, "Okay, that's certification's not going to be available in this region or gov cloud or whatever for a year, I need this now." >> Yeah, or various commercial. Whatever it might be. >> "And I'm going to make the call now, one-way door, and I'm going to keep it on-prem." And then worry about it down the road. Okay, makes sense. >> Dan, I got to talk to you about the sustainability element there because it's increasingly becoming a priority for organizations in every industry where they need to work with companies that really have established sustainability programs. What are some of the factors that you talk with customers about as they have choice in all FlashArray between Pure and competitors where sustainability- >> Yeah, I mean we've leaned very heavily into that from a marketing standpoint recently because it has become so top of mind for so many customers. But at the end of the day, sustainability was built into the core of the Purity operating system in FlashArray back before it was FlashArray, right? In our early generation of products. The things that drive that sustainability of high density, high data reduction, small footprint, we needed to build that for Pure to exist as a company. And we are maybe kind of the last all-flash vendor standing that came ground up all-flash, not just the disc vendor that's refactored, right? And so that's sort of engineering from the ground up that's deeply, deeply into our software as a huge sustainability payout now. And we see that and that message is really, really resonating with customers. >> I haven't thought about that in a while. You actually are. I don't think there's any other... Nobody else made it through the knothole. And you guys hit escape velocity and then some. >> So we hit escape velocity and it hasn't slowed down, right? Earnings will be tomorrow, but the last many quarters have been pretty good. >> Yeah, we follow you pretty closely. I mean, there was one little thing in the pandemic and then boom! It's just kept cranking since, so. >> So at the end of the day though, right? We needed that level to be economically viable as a flash bender going against disc. And now that's really paying off in a sustainability equation as well because we consume so much less footprint, power cooling, all those factors. >> And there's been some headwinds with none pricing up until recently too that you've kind of blown right through. You know, you dealt with the supply issues and- >> Yeah, 'cause the overall... One, we've been, again, one of the few vendors that's been able to navigate supply really well. We've had no major delays in disruptions, but the TCO argument's real. Like at the end of the day, when you look at the cost of running on Pure, it's very, very compelling. >> Adam Selipsky made the statement, "If you're looking to tighten your belt, the cloud is the place to do it." Yeah, okay. It might be that, but... Maybe. >> Maybe, but you can... So again, we are seeing cloud customers that are traditional Pure data center customers that a few years ago said, "We're moving these applications into the cloud. You know, it's been great working with you. We love Pure. We'll have some on-prem footprint, but most of everything we're going to do is in the cloud." Those customers are coming back to us to keep running in the cloud. Because again, when you start to factor in things like thin provisioning, data reduction, those don't exist in the cloud. >> So, it's not repatriation. >> It's not repatriation. >> It's we want Pure in the cloud. >> Correct. We want your software. So that's why we built CBS, and we're seeing that come all the way through. >> There's another cost savings is on the... You know, with what we are doing with Kubernetes and containers and Portworx Data Services, right? So when we run Portworx Data Services, typically customers spend a lot of money in running the cloud managed services, right? Where there is obviously a sprawl of those, right? And then they end up spending a lot of item costs. So when we move that, like when they run their data, like when they move their databases to Portworx Data Services on Kubernetes, because of all of the other cost savings we deliver plus the licensing costs are a lot lower, we deliver 5X to 10X savings to our customers. >> Lisa: Significant. >> You know, significant savings on cloud as well. >> The operational things he's talking about, too. My Fusion engineering team is one of his largest customers from Portworx Data Services. Because we don't have DBAs on that team, it's just developers. But they need databases. They need to run those databases. We turn to PDS. >> This is why he pays my bills. >> And that's why you guys have to come back 'cause we're out of time, but I do have one final question for each of you. Same question. We'll start with you Dan, the Venkat we'll go to you. Billboard. Billboard or a bumper sticker. We'll say they're going to put a billboard on Castor Street in Mountain View near the headquarters about Pure, what does it say? >> The best container for containers. (Dave and Lisa laugh) >> Venkat, Portworx, what's your bumper sticker? >> Well, I would just have one big billboard that goes and says, "Got PX?" With the question mark, right? And let people start thinking about, "What is PX?" >> I love that. >> Dave: Got Portworx, beautiful. >> You've got a side career in marketing, I can tell. >> I think they moved him out of the engineering. >> Ah, I see. We really appreciate you joining us on the program this afternoon talking about Pure, Portworx, AWS. Really compelling stories about how you're helping customers just really make big decisions and save considerable costs. We appreciate your insights. >> Awesome. Great. Thanks for having us. >> Thanks, guys. >> Thank you. >> For our guests and for Dave Vellante, I'm Lisa Martin. You're watching theCUBE, the leader in live enterprise and emerging tech coverage. (upbeat music)

Published Date : Nov 29 2022

SUMMARY :

This is the first full day of coverage. I think it's my 10th You must have a favorite are actually really good. The place that closed. the Wynn and the Venetian. the name was. It was like a Greek a couple years ago. And then they made the to have these guys on We're going to unpack all of this. Do you have a favorite There's a lot of good There's one of the I'm an Herbs and Rye guy. It's kind of like a locals joint. I have to dig through all and it's probably half the size of this so far on day one of the events? and customers really looking to solve and then we'll get to you Dan as well, a lot over the last year. the core Pure business or the It's a number of components. And you had a high Is that still the case? That's still the architecture. and then again back to Fusion, it's just the FlashArray. Yeah, it's a data super cloud. and the primitives and Yeah, and it's the same APIs, and how it all relates to containers? and by on the public cloud I'm not paying for the But then stateless and but it is more for like and scaling the compute the move to the cloud on the storage side So the movement is easier and I'm going to deploy on-prem." So that portability is the Availability of your application and data Okay, so if the capability is not there on customer at the end of the day. and everybody's going to and I'm going to move to this cloud, not going to be available Yeah, or various commercial. and I'm going to keep it on-prem." What are some of the factors that you talk But at the end of the day, And you guys hit escape but the last many quarters Yeah, we follow you pretty closely. So at the end of the day though, right? the supply issues and- Like at the end of the day, the cloud is the place to do it." applications into the cloud. come all the way through. because of all of the other You know, significant They need to run those databases. the Venkat we'll go to you. (Dave and Lisa laugh) I can tell. out of the engineering. We really appreciate you Thanks for having us. the leader in live enterprise

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Dave VellantePERSON

0.99+

Lisa MartinPERSON

0.99+

AWSORGANIZATION

0.99+

DavePERSON

0.99+

Dan KoganPERSON

0.99+

Dave VellantePERSON

0.99+

PortworxORGANIZATION

0.99+

Venkat RamakrishnanPERSON

0.99+

VegasLOCATION

0.99+

Adam SelipskyPERSON

0.99+

Venkat RamakrishnaPERSON

0.99+

DanPERSON

0.99+

AustinLOCATION

0.99+

LisaPERSON

0.99+

yesterday morningDATE

0.99+

tomorrowDATE

0.99+

Pure StorageORGANIZATION

0.99+

Castor StreetLOCATION

0.99+

CBSORGANIZATION

0.99+

10XQUANTITY

0.99+

10th timeQUANTITY

0.99+

Portworx Data ServicesORGANIZATION

0.99+

last yearDATE

0.99+

5XQUANTITY

0.99+

bothQUANTITY

0.99+

Cloud Block StoreTITLE

0.99+

first dayQUANTITY

0.98+

Cloud Block StoreORGANIZATION

0.98+

PureORGANIZATION

0.98+

VenetianLOCATION

0.98+

todayDATE

0.98+

VenkatPERSON

0.98+

S3TITLE

0.98+

first timeQUANTITY

0.98+

this yearDATE

0.98+

pandemicEVENT

0.98+

one final questionQUANTITY

0.98+

This yearDATE

0.98+

KubernetesTITLE

0.97+

EdgeORGANIZATION

0.97+

2019DATE

0.97+

oneQUANTITY

0.97+

AzureTITLE

0.97+

Cloud Block StoreTITLE

0.97+

eachQUANTITY

0.97+

InventEVENT

0.97+

Pure AccelerateORGANIZATION

0.97+

Earlier this yearDATE

0.97+

EKSORGANIZATION

0.96+

PurityORGANIZATION

0.96+

one-timeQUANTITY

0.96+

Cloud Block StoreTITLE

0.96+

Cathie Hall, IFS | IFS Unleashed 2022


 

>>Hey guys, welcome back to the Cube's coverage of IFS Unleashed in Miami. I'm Lisa Martin. Been here half a day so far, having great conversations. It is so great to be back on the show floor and I'm getting that sentiment from the IFS execs, their customers, their partners, and the ecosystem. I'm pleased to welcome Kathy Hall as my next guest, the SVP of experience at ifs. Kathy, welcome to the program. >>Thank you. >>Love talking about the customer experience. Talk to me, but the employee experience is equally important because they're like this, but talk to me about your role as the SVP of experience and what that entails. >>Yeah, so I'm really, really fortunate at IFS to be SVP across experience. So I do a lot of work with the r and d team, but I also have a role that spans sales consulting support so I can really get involved in any part of the organization to enable us to deliver moments of service. So I'm really, really fortunate. I've got such a broad remit and really work on everything from the user experience and what the product looks like, feels like, how it interacts, how it moves, how we put our partner, the technologies in there, everything to their customer experience. So how people find it if they have to engage with support or what it's like in presales. And we are really trying to wrap that up into a total experience so that we bring all of those parts together and really productize our experience so that every customer gets a fantastic experience and the best moments of service. So yeah, it's like a short job title and it's a really kind of big role. It's fantastic. >>It is. It's very, it's very encompassing. You have so much visibility across the entire organization that impacts the customer in many different ways. I can't only imagine that having that visibility in that role really helps to create not only a great customer experience but a, a great experience for the employees. And those two things I always think of them as like this, like inextricably linked. >>Yeah, exactly. And we've done a lot over the last couple of years of really trying to make sure we've got the data so we understand both from a product point of view and a service point of view, what our users and our customers think about that moment of service. Where the friction points are, you know, what's really good and, and we can use that to coach our employees to celebrate success, to give people kudos for the fantastic work they do. And that really enables us to create a hype around the customer within, within ifs. And just last week we were celebrating CX day and we did a whole week and had our own sort of internal hashtag of CX days every day. And that was fantastic to really galvanize that spirit of those ifss, you know, Team Purple, really being at the forefront of how we deliver that, that customer experience. And it's fantastic for our customers, but it's also brilliant for our people because it's motivating and, and it empowers people to, to be able to do a great job, which is what we all want to do. >>Absolutely. Employees need to be empowered because if that's not there, then the customer experience inextricably linked will suffer. Talk to me a little bit about the evolution of the role. Has it been something that's been the, a focus of ifs? Cuz there's, you guys have so many unique differentiators for, for a company that isn't widely known, but talk to me about how that came about going, you know, what we need to be able to take to really look at the customer experience through many different lenses, take their feedback and really deliver a product experience that is seamless so that they can deliver those moments of service. >>Yeah, exactly. And I think, you know, when, when Darren took over a ceo, we've been on this really kind of passionate journey to bring service to our customers, bring value to our customers, you know, we really value is at the heart of, of everything for our customers. And, and so it's our ethos too. And so we've, we've sort of woven this value into everything that we do with that focus on the customer. So my role started off sort of more in the come in and then try and understand it from a very product point of view, but in today's kind of world products and service lines emerging things need to be unified. You know, if you go back 20 years a product was built and it got shipped out and somebody picks it up and they implemented it and then there was a support and there were sort of these walls in between, but now of course it is a cloud company and those walls don't exist anymore. >>Product features are coming out regularly. The code sort of flows through the system out to customers. The way that we service has to be different. And so we're thinking all the time, how do we get that to be a seamless process and how do we enable, for example, data within a customer system to identify opportunities to create more value for that customer using technology like AI for example, and then being able to highlight that value back. But then maybe you say to the presales person, okay, this is the precise demonstration and capability that the customer needs to see because this is what the, the system's telling us is the business case. And that then flows through to the scope and it enables us to, to deliver that value. So it's really changing the way that we think about these things and unifying together that product and that service into this kind of bigger total experience and this end to end experience. >>So we're really looking at what are all the friction points along our journeys with the customers, How does it stop them getting value? How do we prioritize that value and, and therefore how do we reimagine an end to end experience? So as that thinking's evolved, my role's also evolved from being quite product centric to being very much across the organization. And I'm lucky I come from a commercial and operational background, so I've got a vast amount of experience in delivering these types of solutions. So that's really helped as well because I'm able to see that that full end to end and, and I've got a, you know, brilliant team of people and, and it comes back to the point where we said before, the people ifs are so engaged to want to deliver value, to want to deliver the moments of service that, that it's kind of easy, you know, just got to kind of focus people in the right way and, and the s comes together. >>That's nice to hear. And that's actually the vibe and the sentiment that we're getting from this. You know, talking about the end to end experience. It's so critical because people used to tolerate fragmented experiences. We don't anymore. One of the things that went away, I think or is in massively short supply during Covid and may not come back as patience and tolerance, right? So being able to deliver that end to end experience to your customers through what you're doing internally is critical for differentiation, for competitive advantage, and of course for your customers to be successful with their customers. >>Yeah, and there's so many parts of that that you could un pick. We, we could spend hours talking about it and as consumers our expectations are huge and we carry those expectations into the workplace. And in the same way, you know, at IFS we want our team to be motivated and, you know, proud and excited about the moments of service they're delivering. Our customers want the same thing from their teams and that also means they want a system where it's easy to train, easy to use, you can pick up, it looks great, you know, it gives users love ifs and it kind of gives them a tool that helps 'em get the job done, doesn't stand in their way. So, you know, all the kind of things we think about internally and how we're measuring customer experience also translates and resonates with our customers. Everything we think about how, you know, our people need to be empowered to deliver a customer experience. That's the same messages that, you know, we hear back time and time again from our customers. So there's so many parallels and we're really able to work with our customers to kind of do both at the same time, which is fantastic. >>Talk about measurement. What are some of the key indicators of success cus success in in from an experienced lens internally and with your customers? >>Yeah, so I mean there's all the obvious ones about, you know, MPS and CSAT and customer effort score. We also put a lot of value into the qualitative feedback. So we use customer A avail, which is an IFS product to collect data on our own moments of service. And you know, the numbers are great and they tell a story, but I also get really sucked into reading the comments back from the customers and there's kind of text analytics and sentiment analytics and for me that's becoming the more powerful kind of piece of data to look at because a story conveys much more than a simple number and it's also something that goes global as well. You know, different countries score in different ways. There's different kind of, you know, there's a lot of gaming that can go on with a score. It can be quite difficult to really interpret, but a but a story and understanding the sentiment behind that customer, that's gold. And if you can put those together and have a way of on scale being able to interpret that analysis, which we can do, you know, that becomes something quite special. So for me it's about a shift to understanding more of those stories as well as keeping, you know, the kind of traditional, traditional measures across the, the learning across the journey points, >>Right? The, the value, I always think the value of the voice of the customer is probably invaluable to organizations because it's honest. >>It absolutely it's honest. And I think once you've got those stories and you've got those metrics and then you're looking at your operational metrics, so what does that mean then in terms of, you know, recur revenue and what does that mean in terms of margins and the costs? And being able to put those three things together so that you couldn't understand the levers that you've got and the, and the results of those levers, that becomes really powerful. And that's really what's driving our, our customers for, for them to deliver in their moments of service as well, which ties back into when we're working within customers and engaging with customers and looking at that value story, doing the value assessments more able to use the, the evidence from industry and previous customers and, and the data sources available to help them also project, you know, an operational efficiency here will have this c CX benefit but actually also has this value benefit >>Oh, a value back to the business. I mean a a good experience is transformative. Yeah, >>Really powerful. >>Any industry. >>Yeah. Yeah. It's, it's so powerful and you know, that really resonates with our customers and that's what they're trying to, to achieve all the time. And so when they're looking at IFS cloud in particular, they're looking at how, you know, the, the software can help them achieve those moments of service and perfect those moments of service and all the technology that comes into play that can enable people to improve those moments of service at the same time as getting those operational benefits. And that enables organizations to then invest more in the customer experience, more advocacy and, and really, you know, feels growth. There's, there's no denying that now you have to have that experience and, and at your point before the expectation from as others consumers, we won't tolerate a bad experience anymore, which is a good thing. >>It is. We, we've all had met plenty of those throughout the last two and a half years. Last question for you, you, what are some of the things that are next for experience at ifs? I know you mentioned before we went live that you started during the pandemic, so you go, go get to meet your team finally, but what are some of the things that excite you about the momentum that you guys are carrying through the rest of the second half? >>Yeah, so our focus now is really bringing the component parts together. So we have several tools across our whole experience that leverage from our IFFs cloud platform in order to deliver those moments of service to our customers. But those tools have grown up in different areas of the business because there's been a specific need in that area of the business. So tools at the pre-sale stage, tools that enable us to deliver scope, more frictionlessly tools that enable us to, to identify and capture value. The next stage is bringing those all together. So this week I announced our vision for experience and the experience hub and that really being a place where you get that thread of value throughout the whole experience where everything is tied into one place and it makes it really frictionless for our customers to get the value from ifs. >>And that's critical. You guys have north of 10,000 customers, it's only growing. Kathy, thank you so much for joining me on the program, talking about the end to end experience that IFS delivers internally and externally to its customers. We appreciate your insights. >>Thank you for having >>Me. My pleasure. For Kathy Hall, I'm Lisa Martin, you're watching The Cube live on the show floor of IFS Unleashed from Miami. Stick around. My next guest joins me in just a minute. I have been in the software and technology industry for over 12 years now, so I've had the.

Published Date : Oct 11 2022

SUMMARY :

to be back on the show floor and I'm getting that sentiment from the IFS execs, because they're like this, but talk to me about your role as the SVP of experience and part of the organization to enable us to deliver moments of service. entire organization that impacts the customer in many different ways. Where the friction points are, you know, what's really good and, but talk to me about how that came about going, you know, what we need to be able to take to really look to our customers, bring value to our customers, you know, we really value is at the heart And that then flows through to the scope and it enables us to, to deliver that value. before, the people ifs are so engaged to want to deliver value, You know, talking about the end to end experience. And in the same way, you know, at IFS we want our team to be What are some of the key indicators of success cus success And you know, the numbers are great and they tell a story, invaluable to organizations because it's honest. And being able to put those three things together so that you couldn't understand the levers Oh, a value back to the business. and really, you know, feels growth. I know you mentioned before we went live that you started during the pandemic, so you go, go get to meet your team and that really being a place where you get that thread of value throughout the whole experience thank you so much for joining me on the program, talking about the end to end experience that IFS I have been in the software and technology industry for over 12 years now, so I've had the.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
KathyPERSON

0.99+

Lisa MartinPERSON

0.99+

Cathie HallPERSON

0.99+

Kathy HallPERSON

0.99+

MiamiLOCATION

0.99+

last weekDATE

0.99+

DarrenPERSON

0.99+

second halfQUANTITY

0.99+

IFSORGANIZATION

0.99+

2022DATE

0.99+

20 yearsQUANTITY

0.99+

The CubeTITLE

0.98+

two thingsQUANTITY

0.98+

OneQUANTITY

0.98+

bothQUANTITY

0.98+

CX dayEVENT

0.97+

this weekDATE

0.96+

todayDATE

0.96+

over 12 yearsQUANTITY

0.94+

pandemicEVENT

0.93+

half a dayQUANTITY

0.93+

one placeQUANTITY

0.91+

oftwareORGANIZATION

0.91+

three thingsQUANTITY

0.89+

a whole weekQUANTITY

0.8+

IFFsORGANIZATION

0.8+

10,000 customersQUANTITY

0.73+

CX daysEVENT

0.71+

two and a half yearsQUANTITY

0.67+

IFSTITLE

0.65+

CubeORGANIZATION

0.59+

rORGANIZATION

0.58+

LastQUANTITY

0.58+

last coupleDATE

0.57+

lastDATE

0.56+

CovidPERSON

0.4+

Kate Hall Slade, dentsu & Flo Ye, dentsu | UiPath Forward5


 

>>The Cube Presents UI Path Forward five. Brought to you by UI Path. >>Welcome back to the Cube's Coverage of Forward five UI Path Customer event. This is the fourth forward that we've been at. We started in Miami, had some great events. It's all about the customer stories. Dave Valante with Dave Nicholson, Flow Yees here. She's the director of engineering and development at dsu and Kate Hall is to her right. And Kate is the director of Automation Solutions at dsu. Ladies, welcome to the Cube. Thanks so much. Thanks >>You to >>Be here. Tell us about dsu. You guys are huge company, but but give us the focus. >>Yeah, absolutely. Dentsu, it's one of the largest advertising networks out there. One of the largest in the world with over 66,000 employees and we're operating in a hundred plus countries. We're really proud to serve 95% of the Fortune 100 companies. Household names like Microsoft Factor and Gamble. If you seen the Super Bowls ads last year, Larry, Larry Davids ads for the crypto brand. That's a hilarious one for anyone who haven't seen it. So we're just really proud to be here and we really respect the creatives of our company. >>That was the best commercial, the Super Bowl by far. For sure. I, I said at the top of saying that Dave and I were talking UI pass, a cool company. You guys kinda look like cool people. You got cool jobs. Tell, tell us about your respective roles. What do you guys do? Yeah, >>Absolutely, absolutely. Well, I'm the director of engineering and automation, so what I really do is to implement the automation operating model and connecting developers across five continents together, making sure that we're delivering and deploying automation projects up to our best standards setting by the operating model. So it's a really, really great job. And when we get to see all these brilliant minds across the world >>And, And Kate, what's your role? Yeah, >>And the Automation Solutions vertical that I head up, the focus is really on converting business requirements into technical designs for flows, developers to deliver. So making sure that we are managing our pipeline, sourcing the right ideas, prioritizing them according to the business businesses objectives and making sure that we route them to the right place. So is it, does it need to be an automation first? Do we need to optimize the process? Does this make sense for citizen developers or do we need to bring in the professional resources on flow's >>Team? So you're bilingual, you speak, you're like the translator, you speak geek and wall, right? Is that fair? Okay. So take me back to the, let's, let's do a little mini case study here. How did you guys get started? I'm always interested, was this a top down? Is, is is top down required to be successful? Cuz it does feel like you can have bottom up bottoms up with rpa, but, but how did you guys get started? What was the journey like? >>Yeah, we started back in 2017, very traditional top down approach. So we delivered a couple POCs working directly with UiPath. You know, going back those five years, delivered those really highly scalable top down solutions that drove hundreds of thousands of hours of ROI for the business. However, as people kind of began to embrace automation and they learned that this is something that they could, that could help them, it's not something that they should be afraid of to take away their jobs. You know, DSU is a young company with a lot of young, young creatives. They wanna make their lives better. So we were absolutely inundated with all of these use cases of, hey I, I need a bot to do this. I need a bot to do that i's gonna save me, you know, 10 hours a week. It's gonna save my team a hundred hours a month, et cetera, et cetera. All of these smaller use cases that were gonna be hugely impactful for the individuals, their teams, even in entire department, but didn't have that scalable ROI for us to put professional development resources against it. So starting in 2020 we really introduced the citizen development program to put the power into those people's hands so that they could create their own solutions. And that was really just a snowball effect to tackle it from the bottom up as well as the top down. >>So a lot of young people, Dave, they not not threatened by robots that racing it. So >>They've grown up with the technology, they know that they can order an Uber from their phone, right? Why am I, you know, sitting here at MITs typing data from Excel into a program that might be older than some of our youngest employees. >>Yeah. Now, now the way you described it, correct me if I'm wrong, the way you described it, it sounds like there's sort of a gating function though. You're not just putting these tools in the hands of people sitting, especially creatives who are there to create. You're not saying, Oh you want things automated, here are the tools. Go ahead. Automated. We'll we, for those of you who want to learn how to use the tools, we'll have you automate that there. Did I hear that right? You're, you're sort of making decisions about what things will be developed even by citizen developers. >>Let me, Do you wanna talk to them about governance? Yeah, absolutely. >>Yeah, so I think we started out with assistant development program, obviously the huge success, right? Last year we're also here at the Cubes. We're very happy to be back again. But I think a lot, a lot had changed and we've grown a lot since last year. One, I have the joy being a part of this team. And then the other thing is that we really expanded and implemented an automation operating model that I mentioned briefly just earlier. So what that enabled us to do is to unite developers from five continents together organically and we're now able to tap into their talent at a global scale. So we are really using this operating model to grow our automation practice in a scalable and also controlled manner. Okay. What I mean by that is that these developer originally were sitting in 18 plus markets, right? There's not much communication collaboration between them. >>And then we went in and bridged them together. What happened is that originally they were only delivering projects and use cases within their region and sometimes these use cases could be very, very much, you know, small scale and not really maximizing their talent. What we are now able to do is tap into a global automation pipeline. So we connecting these highly skilled people to the pipeline elsewhere, the use cases elsewhere that might not be within their regions because one of our focus, a lot of change I mentioned, right? One thing that will never change with our team, it's used automation to elevate people's potential. Now it's really a win-win situation cuz we are connecting the use cases from different pipelines. So the business is happy cuz we are delivering these high scalable solutions. We also utilizing these developers and they're happy because their skills are being maximized and then at the same time growing our automation program. So then that way the citizen development program so that the lower complexities projects are being delivered at a local level and we are able to innovate at a local level. >>I, I have so many questions flow based on what you just said. It's blowing my mind >>Here. It's a whole cycle. >>So let me start with how do you, you know, one of the, one of the concerns I had initially with RPA, cuz just you're talking about some very narrow use cases and your goal is to expand that to realize the potential of each individual, right? But early days I saw a lot of what I call paving the cow path, taking a process that was not a great process and then automating it, right? And that was limiting the potential. So how do you guys prioritize which processes to focus on and maybe which processes should be rethought, >>Right? Exactly. A lot of time when we do automation, right, we talk about innovations and all that stuff, but innovation doesn't happen with the same people sitting in the same room doing the same thing. So what we are doing now, able to connect all these people, different developers from different groups, we really bring the diversity together. That's diversity D diverse diversity in the mindset, diversity in the skill. So what are we really able to do and we see how we tackle this problem is to, and that's a problem for a lot of business out there is the short-termism. So there's something, what we do is that we take two approaches. One, before we, you know, for example, when we used to receive a use case, right? Maybe it's for the China market involving a specific tool and we just go right into development and start coding and all that good stuff, which is great. >>But what we do with this automation framework, which we think it's a really great service for any company out there that want to grow and mature their automation practice, it's to take a step back, think about, okay, so the China market would be beneficial from this automation. Can we also look at the Philippine market? Can we also look at the Thailand market? Because we also know that they have similar processes and similar auto tools that they use. So we are really able to make our automation in a more meaningful way by scaling a project just beyond one market. Now it's impacting the entire region and benefiting people in the entire region. That is what we say, you know, putting automation for good and then that's what we talked about at dsu, Teaming without limits. And that's a, so >>By taking, we wanna make sure that we're really like taking a step back, connecting all of the dots, building the one thing the right way, the first time. Exactly. And what's really integral into being able to have that transparency, that visibility is that now we're all working on the same platform. So you know, Brian spoke to you last year about our migration into automation cloud, having everything that single pipeline in the cloud. Anybody at DSU can often join the automation community and get access to automation hub, see what's out there, submit their own ideas, use the launchpad to go and take training. Yeah. And get started on their own automation journey as a citizen developer and you know, see the different paths that are available to them from that one central space. >>So by taking us a breath, stepping back, pausing just a bit, the business impact at the tail end is much, much higher. Now you start in 2017 really before you UI path made it's big enterprise play, it acquired process gold, you know, cloud elements now most recently referenced some others. How much of what you guys are, are, are doing is platform versus kind of the initial sort of robot installation? Yeah, >>I mean platforms power people and that's what we're here to do as the global automation team. Whether it's powering the citizen developers, the professional developers, anybody who's interacting with our automations at dsu, we wanna make sure that we're connecting the docs for them on a platform basis so that developers can develop and they don't need to develop those simple use cases that could be done by a citizen developer. You know, they're super smart technical people, they wanna do the cool shit with the new stuff. They wanna branch into, you know, using AI center and doing document understanding. That's, you know, the nature of human curiosity. Citizen developers, they're thrilled that we're making an investment to upscale them, to give them a new capability so that they can automate their own work. And they don't, they, they're the process experts. They don't need to spend a month talking to us when they could spend that time taking the training, learning how to create something themselves. >>How, how much sort of use case runway when you guys step back and look at your business, do you see a limit to the use cases? I mean where are you, if you had on a spectrum of, you know, maturity, how much more opportunity is there for DSU to automate? >>There's so much I think the, you feel >>Like it's limitless? >>No, I absolutely feel like it's limitless because there one thing, it's, there's the use cases and I think it's all about connecting the talent and making sure that something we do really, you know, making sure that we deliver these use cases, invest the time in our people so we make sure our professional developers part of our team spending 10 to 20% of the time to do learning and development because only limitless if our people are getting the latest and the greatest technology and we want to invest the time and we see this as an investment in the people making sure that we deliver the promise of putting people first. And the second thing, it's also investment in our company's growth. And that's a long term goal. And overcoming just focusing on things our short term. So that is something we really focus to do. And not only the use cases we are doing what we are doing as an operating model for automation. That is also something that we really value because then this is a kind of a playbook and a success model for many companies out there to grow their automation practice. So that's another angle that we are also focusing >>On. Well that, that's a relief because you guys are both seem really cool and, and I'm sitting here thinking they don't realize they're working themselves out of a job once they get everything automated, what are they gonna do? Right? But, but so, so it sounds like it's a never ending process, but because you guys are, are such a large global organization, it seems like you might have a luxury of being able to benchmark automations from one region and then benchmark them against other regions that aren't using that automation to be able to see very, very quickly not only realize ROI really quickly from the region where it's been implemented, but to be able to compare it to almost a control. Is that, is that part of your process? Yeah, >>Absolutely. Because we are such a global brand and with the automation, automation operating model, what we are able to do, not only focusing on the talent and the people, but also focusing on the infrastructure. So for example, right, maybe there's a first use case developing in Argentina and they have never done these automation before. And when they go to their security team and asking for an Okta bypass service account and the security team Argentina, like we never heard of automation, we don't know what UiPath is, why would I give you a service account for good reason, right? They're doing their job right. But what we able to do with automation model, it's to establish trust between the developers and the security team. So now we have a set up standing infrastructure that we are ready to go whenever an automation's ready to deploy and we're able to get the set up standing infrastructure because we have the governance to make sure the quality would delivered and making sure anything that we deployed, automation that we deploy are developed and governed by the best practice. So that's how we able to kind of get this automation expand globally in a very control and scalable manner because the people that we have build a relationship with. What are >>The governors to how fast you can adopt? Is it just expertise or bandwidth of that expertise or what's the bottleneck? >>Yeah, >>If >>You wanna talk more about, >>So in terms of the pipeline, we really wanna make sure that we are taking that step back and instead of just going, let's develop, develop, develop, here are the requirements like get started and go, we've prove the value of automation at Densu. We wanna make sure we are taking that step back and observing the pipeline. And it's, it's up to us to work with the business to really establish their priorities and the priorities. It's a, it's a big global organization. There might be different priorities in APAC than there are in EM for a good reason. APAC may not be adopted on the same, you know, e r P system for example. So they might have those smaller scale ROI use cases, but that's where we wanna work with them to identify, you know, maybe this is a legitimate need, the ROI is not there, let's upscale some citizen developers so that they can start, you know, working for themselves and get those results faster for those simpler use cases. >>Does, does the funding come from the line of business or IT or a combination? I mean there are obviously budget constraints are very concerned about the macro and the recession. You guys have some global brands, you know, as, as things ebb and flow in the economy, you're competing with other budgets. But where are the budgets coming from inside of dsu? Is it the business, is it the tech >>Group? Yeah, we really consider our automation group is the cause of doing business because we are here connecting people with bridging people together and really elevating. And the reason why we structure it that way, it's people, we do automation at dsu not to reduce head count, not to, you know, not, not just those matrix number that we measure, but really it's to giving time back to the people, giving time back to our business. So then that way they can focus on their wellbeing and that way they can focus on the work-life balance, right? So that's what we say. We are forced for good and by using automation for good as one really great example. So I think because of this agenda and because DSU do prioritize people, you know, so that's why we're getting the funding, we're getting the budget and we are seeing as a cause of doing business. So then we can get these time back using innovation to make people more fulfilling and applying automation in meaningful ways. >>Kate and Flo, congratulations. Your energy is palpable and really great success, wonderful story. Really appreciate you sharing. Thank you so >>Much for having us today. >>You're very welcome. All keep it right there. Dave Nicholson and Dave Ante. We're live from UI path forward at five from Las Vegas. We're in the Venetian Consent Convention Center. Will be right back, right for the short break.

Published Date : Sep 29 2022

SUMMARY :

Brought to you by And Kate is the director You guys are huge company, but but give us the focus. we really respect the creatives of our company. What do you guys do? Well, I'm the director of engineering and automation, So making sure that we are managing our pipeline, sourcing the right ideas, up with rpa, but, but how did you guys get started? So we were absolutely inundated with all of these use cases So a lot of young people, Dave, they not not threatened by robots that racing it. Why am I, you know, sitting here at MITs typing data from Excel into to use the tools, we'll have you automate that there. Let me, Do you wanna talk to them about governance? So we are really using So we connecting these highly skilled people to I, I have so many questions flow based on what you just said. So how do you guys prioritize which processes to focus on and Maybe it's for the China market involving a specific tool and we just go right into So we are really able to So you know, of what you guys are, are, are doing is platform versus kind of the initial sort They wanna branch into, you know, using AI center and doing document understanding. And not only the use cases we are doing what On. Well that, that's a relief because you guys are both seem really cool and, and the security team Argentina, like we never heard of automation, we don't know what UiPath So in terms of the pipeline, we really wanna make sure that we are taking that step back You guys have some global brands, you know, as, as things ebb and flow in the So then we can get these time back using innovation to Thank you so We're in the Venetian Consent Convention Center.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
BrianPERSON

0.99+

DavePERSON

0.99+

Dave ValantePERSON

0.99+

Dave NicholsonPERSON

0.99+

KatePERSON

0.99+

MiamiLOCATION

0.99+

2017DATE

0.99+

LarryPERSON

0.99+

Las VegasLOCATION

0.99+

ArgentinaLOCATION

0.99+

95%QUANTITY

0.99+

2020DATE

0.99+

FloPERSON

0.99+

Last yearDATE

0.99+

Kate HallPERSON

0.99+

ExcelTITLE

0.99+

Dave AntePERSON

0.99+

Flo YePERSON

0.99+

last yearDATE

0.99+

10QUANTITY

0.99+

Larry DavidsPERSON

0.99+

DSUORGANIZATION

0.99+

Kate Hall SladePERSON

0.99+

18 plus marketsQUANTITY

0.99+

UberORGANIZATION

0.99+

UiPathORGANIZATION

0.99+

Super BowlEVENT

0.99+

ThailandLOCATION

0.99+

10 hours a weekQUANTITY

0.99+

OneQUANTITY

0.99+

APACORGANIZATION

0.99+

two approachesQUANTITY

0.99+

Venetian Consent Convention CenterLOCATION

0.99+

dentsuPERSON

0.98+

over 66,000 employeesQUANTITY

0.98+

oneQUANTITY

0.98+

dsuORGANIZATION

0.98+

DensuORGANIZATION

0.98+

todayDATE

0.98+

bothQUANTITY

0.98+

ChinaLOCATION

0.98+

Super BowlsEVENT

0.98+

second thingQUANTITY

0.98+

first timeQUANTITY

0.98+

CubesORGANIZATION

0.98+

one marketQUANTITY

0.98+

MITsORGANIZATION

0.97+

20%QUANTITY

0.97+

five yearsQUANTITY

0.96+

five continentsQUANTITY

0.96+

one regionQUANTITY

0.96+

first use caseQUANTITY

0.95+

OktaORGANIZATION

0.95+

fiveQUANTITY

0.95+

one thingQUANTITY

0.94+

Microsoft FactorORGANIZATION

0.94+

a hundred hours a monthQUANTITY

0.94+

single pipelineQUANTITY

0.93+

PhilippineLOCATION

0.92+

each individualQUANTITY

0.91+

CubeORGANIZATION

0.91+

One thingQUANTITY

0.9+

DentsuORGANIZATION

0.89+

hundred plus countriesQUANTITY

0.88+

hundreds of thousands of hoursQUANTITY

0.86+

firstQUANTITY

0.83+

fourth forwardQUANTITY

0.78+

one centralQUANTITY

0.75+

UI PathORGANIZATION

0.73+

exampleQUANTITY

0.7+

GambleORGANIZATION

0.69+

Fortune 100 companiesQUANTITY

0.67+

Horizon3.ai Signal | Horizon3.ai Partner Program Expands Internationally


 

hello I'm John Furrier with thecube and welcome to this special presentation of the cube and Horizon 3.ai they're announcing a global partner first approach expanding their successful pen testing product Net Zero you're going to hear from leading experts in their staff their CEO positioning themselves for a successful Channel distribution expansion internationally in Europe Middle East Africa and Asia Pacific in this Cube special presentation you'll hear about the expansion the expanse partner program giving Partners a unique opportunity to offer Net Zero to their customers Innovation and Pen testing is going International with Horizon 3.ai enjoy the program [Music] welcome back everyone to the cube and Horizon 3.ai special presentation I'm John Furrier host of thecube we're here with Jennifer Lee head of Channel sales at Horizon 3.ai Jennifer welcome to the cube thanks for coming on great well thank you for having me so big news around Horizon 3.aa driving Channel first commitment you guys are expanding the channel partner program to include all kinds of new rewards incentives training programs help educate you know Partners really drive more recurring Revenue certainly cloud and Cloud scale has done that you got a great product that fits into that kind of Channel model great Services you can wrap around it good stuff so let's get into it what are you guys doing what are what are you guys doing with this news why is this so important yeah for sure so um yeah we like you said we recently expanded our Channel partner program um the driving force behind it was really just um to align our like you said our Channel first commitment um and creating awareness around the importance of our partner ecosystems um so that's it's really how we go to market is is through the channel and a great International Focus I've talked with the CEO so you know about the solution and he broke down all the action on why it's important on the product side but why now on the go to market change what's the what's the why behind this big this news on the channel yeah for sure so um we are doing this now really to align our business strategy which is built on the concept of enabling our partners to create a high value high margin business on top of our platform and so um we offer a solution called node zero it provides autonomous pen testing as a service and it allows organizations to continuously verify their security posture um so we our company vision we have this tagline that states that our pen testing enables organizations to see themselves Through The Eyes of an attacker and um we use the like the attacker's perspective to identify exploitable weaknesses and vulnerabilities so we created this partner program from a perspective of the partner so the partner's perspective and we've built It Through The Eyes of our partner right so we're prioritizing really what the partner is looking for and uh will ensure like Mutual success for us yeah the partners always want to get in front of the customers and bring new stuff to them pen tests have traditionally been really expensive uh and so bringing it down in one to a service level that's one affordable and has flexibility to it allows a lot of capability so I imagine people getting excited by it so I have to ask you about the program What specifically are you guys doing can you share any details around what it means for the partners what they get what's in it for them can you just break down some of the mechanics and mechanisms or or details yeah yep um you know we're really looking to create business alignment um and like I said establish Mutual success with our partners so we've got two um two key elements that we were really focused on um that we bring to the partners so the opportunity the profit margin expansion is one of them and um a way for our partners to really differentiate themselves and stay relevant in the market so um we've restructured our discount model really um you know highlighting profitability and maximizing profitability and uh this includes our deal registration we've we've created deal registration program we've increased discount for partners who take part in our partner certification uh trainings and we've we have some other partner incentives uh that we we've created that that's going to help out there we've we put this all so we've recently Gone live with our partner portal um it's a Consolidated experience for our partners where they can access our our sales tools and we really view our partners as an extension of our sales and Technical teams and so we've extended all of our our training material that we use internally we've made it available to our partners through our partner portal um we've um I'm trying I'm thinking now back what else is in that partner portal here we've got our partner certification information so all the content that's delivered during that training can be found in the portal we've got deal registration uh um co-branded marketing materials pipeline management and so um this this portal gives our partners a One-Stop place to to go to find all that information um and then just really quickly on the second part of that that I mentioned is our technology really is um really disruptive to the market so you know like you said autonomous pen testing it's um it's still it's well it's still still relatively new topic uh for security practitioners and um it's proven to be really disruptive so um that on top of um just well recently we found an article that um that mentioned by markets and markets that reports that the global pen testing markets really expanding and so it's expected to grow to like 2.7 billion um by 2027. so the Market's there right the Market's expanding it's growing and so for our partners it's just really allows them to grow their revenue um across their customer base expand their customer base and offering this High profit margin while you know getting in early to Market on this just disruptive technology big Market a lot of opportunities to make some money people love to put more margin on on those deals especially when you can bring a great solution that everyone knows is hard to do so I think that's going to provide a lot of value is there is there a type of partner that you guys see emerging or you aligning with you mentioned the alignment with the partners I can see how that the training and the incentives are all there sounds like it's all going well is there a type of partner that's resonating the most or is there categories of partners that can take advantage of this yeah absolutely so we work with all different kinds of Partners we work with our traditional resale Partners um we've worked we're working with systems integrators we have a really strong MSP mssp program um we've got Consulting partners and the Consulting Partners especially with the ones that offer pen test services so we they use us as a as we act as a force multiplier just really offering them profit margin expansion um opportunity there we've got some technology partner partners that we really work with for co-cell opportunities and then we've got our Cloud Partners um you'd mentioned that earlier and so we are in AWS Marketplace so our ccpo partners we're part of the ISP accelerate program um so we we're doing a lot there with our Cloud partners and um of course we uh we go to market with uh distribution Partners as well gotta love the opportunity for more margin expansion every kind of partner wants to put more gross profit on their deals is there a certification involved I have to ask is there like do you get do people get certified or is it just you get trained is it self-paced training is it in person how are you guys doing the whole training certification thing because is that is that a requirement yeah absolutely so we do offer a certification program and um it's been very popular this includes a a seller's portion and an operator portion and and so um this is at no cost to our partners and um we operate both virtually it's it's law it's virtually but live it's not self-paced and we also have in person um you know sessions as well and we also can customize these to any partners that have a large group of people and we can just we can do one in person or virtual just specifically for that partner well any kind of incentive opportunities and marketing opportunities everyone loves to get the uh get the deals just kind of rolling in leads from what we can see if our early reporting this looks like a hot product price wise service level wise what incentive do you guys thinking about and and Joint marketing you mentioned co-sell earlier in pipeline so I was kind of kind of honing in on that piece sure and yes and then to follow along with our partner certification program we do incentivize our partners there if they have a certain number certified their discount increases so that's part of it we have our deal registration program that increases discount as well um and then we do have some um some partner incentives that are wrapped around meeting setting and um moving moving opportunities along to uh proof of value gotta love the education driving value I have to ask you so you've been around the industry you've seen the channel relationships out there you're seeing companies old school new school you know uh Horizon 3.ai is kind of like that new school very cloud specific a lot of Leverage with we mentioned AWS and all the clouds um why is the company so hot right now why did you join them and what's why are people attracted to this company what's the what's the attraction what's the vibe what do you what do you see and what what do you use what did you see in in this company well this is just you know like I said it's very disruptive um it's really in high demand right now and um and and just because because it's new to Market and uh a newer technology so we are we can collaborate with a manual pen tester um we can you know we can allow our customers to run their pen test um with with no specialty teams and um and and then so we and like you know like I said we can allow our partners can actually build businesses profitable businesses so we can they can use our product to increase their services revenue and um and build their business model you know around around our services what's interesting about the pen test thing is that it's very expensive and time consuming the people who do them are very talented people that could be working on really bigger things in the in absolutely customers so bringing this into the channel allows them if you look at the price Delta between a pen test and then what you guys are offering I mean that's a huge margin Gap between street price of say today's pen test and what you guys offer when you show people that they follow do they say too good to be true I mean what are some of the things that people say when you kind of show them that are they like scratch their head like come on what's the what's the catch here right so the cost savings is a huge is huge for us um and then also you know like I said working as a force multiplier with a pen testing company that offers the services and so they can they can do their their annual manual pen tests that may be required around compliance regulations and then we can we can act as the continuous verification of their security um um you know that that they can run um weekly and so it's just um you know it's just an addition to to what they're offering already and an expansion so Jennifer thanks for coming on thecube really appreciate you uh coming on sharing the insights on the channel uh what's next what can we expect from the channel group what are you thinking what's going on right so we're really looking to expand our our Channel um footprint and um very strategically uh we've got um we've got some big plans um for for Horizon 3.ai awesome well thanks for coming on really appreciate it you're watching thecube the leader in high tech Enterprise coverage [Music] [Music] hello and welcome to the Cube's special presentation with Horizon 3.ai with Raina Richter vice president of emea Europe Middle East and Africa and Asia Pacific APAC for Horizon 3 today welcome to this special Cube presentation thanks for joining us thank you for the invitation so Horizon 3 a guy driving Global expansion big international news with a partner first approach you guys are expanding internationally let's get into it you guys are driving this new expanse partner program to new heights tell us about it what are you seeing in the momentum why the expansion what's all the news about well I would say uh yeah in in international we have I would say a similar similar situation like in the US um there is a global shortage of well-educated penetration testers on the one hand side on the other side um we have a raising demand of uh network and infrastructure security and with our approach of an uh autonomous penetration testing I I believe we are totally on top of the game um especially as we have also now uh starting with an international instance that means for example if a customer in Europe is using uh our service node zero he will be connected to a node zero instance which is located inside the European Union and therefore he has doesn't have to worry about the conflict between the European the gdpr regulations versus the US Cloud act and I would say there we have a total good package for our partners that they can provide differentiators to their customers you know we've had great conversations here on thecube with the CEO and the founder of the company around the leverage of the cloud and how successful that's been for the company and honestly I can just Connect the Dots here but I'd like you to weigh in more on how that translates into the go to market here because you got great Cloud scale with with the security product you guys are having success with great leverage there I've seen a lot of success there what's the momentum on the channel partner program internationally why is it so important to you is it just the regional segmentation is it the economics why the momentum well there are it's there are multiple issues first of all there is a raising demand in penetration testing um and don't forget that uh in international we have a much higher level in number a number or percentage in SMB and mid-market customers so these customers typically most of them even didn't have a pen test done once a year so for them pen testing was just too expensive now with our offering together with our partners we can provide different uh ways how customers could get an autonomous pen testing done more than once a year with even lower costs than they had with with a traditional manual paint test so and that is because we have our uh Consulting plus package which is for typically pain testers they can go out and can do a much faster much quicker and their pain test at many customers once in after each other so they can do more pain tests on a lower more attractive price on the other side there are others what even the same ones who are providing um node zero as an mssp service so they can go after s p customers saying okay well you only have a couple of hundred uh IP addresses no worries we have the perfect package for you and then you have let's say the mid Market let's say the thousands and more employees then they might even have an annual subscription very traditional but for all of them it's all the same the customer or the service provider doesn't need a piece of Hardware they only need to install a small piece of a Docker container and that's it and that makes it so so smooth to go in and say okay Mr customer we just put in this this virtual attacker into your network and that's it and and all the rest is done and within within three clicks they are they can act like a pen tester with 20 years of experience and that's going to be very Channel friendly and partner friendly I can almost imagine so I have to ask you and thank you for calling the break calling out that breakdown and and segmentation that was good that was very helpful for me to understand but I want to follow up if you don't mind um what type of partners are you seeing the most traction with and why well I would say at the beginning typically you have the the innovators the early adapters typically Boutique size of Partners they start because they they are always looking for Innovation and those are the ones you they start in the beginning so we have a wide range of Partners having mostly even um managed by the owner of the company so uh they immediately understand okay there is the value and they can change their offering they're changing their offering in terms of penetration testing because they can do more pen tests and they can then add other ones or we have those ones who offer 10 tests services but they did not have their own pen testers so they had to go out on the open market and Source paint testing experts um to get the pen test at a particular customer done and now with node zero they're totally independent they can't go out and say okay Mr customer here's the here's the service that's it we turn it on and within an hour you're up and running totally yeah and those pen tests are usually expensive and hard to do now it's right in line with the sales delivery pretty interesting for a partner absolutely but on the other hand side we are not killing the pain testers business we do something we're providing with no tiers I would call something like the foundation work the foundational work of having an an ongoing penetration testing of the infrastructure the operating system and the pen testers by themselves they can concentrate in the future on things like application pen testing for example so those Services which we we're not touching so we're not killing the paint tester Market we're just taking away the ongoing um let's say foundation work call it that way yeah yeah that was one of my questions I was going to ask is there's a lot of interest in this autonomous pen testing one because it's expensive to do because those skills are required are in need and they're expensive so you kind of cover the entry level and the blockers that are in there I've seen people say to me this pen test becomes a blocker for getting things done so there's been a lot of interest in the autonomous pen testing and for organizations to have that posture and it's an overseas issue too because now you have that that ongoing thing so can you explain that particular benefit for an organization to have that continuously verifying an organization's posture yep certainly so I would say um typically you are you you have to do your patches you have to bring in new versions of operating systems of different Services of uh um operating systems of some components and and they are always bringing new vulnerabilities the difference here is that with node zero we are telling the customer or the partner package we're telling them which are the executable vulnerabilities because previously they might have had um a vulnerability scanner so this vulnerability scanner brought up hundreds or even thousands of cves but didn't say anything about which of them are vulnerable really executable and then you need an expert digging in one cve after the other finding out is it is it really executable yes or no and that is where you need highly paid experts which we have a shortage so with notes here now we can say okay we tell you exactly which ones are the ones you should work on because those are the ones which are executable we rank them accordingly to the risk level how easily they can be used and by a sudden and then the good thing is convert it or indifference to the traditional penetration test they don't have to wait for a year for the next pain test to find out if the fixing was effective they weren't just the next scan and say Yes closed vulnerability is gone the time is really valuable and if you're doing any devops Cloud native you're always pushing new things so pen test ongoing pen testing is actually a benefit just in general as a kind of hygiene so really really interesting solution really bring that global scale is going to be a new new coverage area for us for sure I have to ask you if you don't mind answering what particular region are you focused on or plan to Target for this next phase of growth well at this moment we are concentrating on the countries inside the European Union Plus the United Kingdom um but we are and they are of course logically I'm based into Frankfurt area that means we cover more or less the countries just around so it's like the total dark region Germany Switzerland Austria plus the Netherlands but we also already have Partners in the nordics like in Finland or in Sweden um so it's it's it it's rapidly we have Partners already in the UK and it's rapidly growing so I'm for example we are now starting with some activities in Singapore um um and also in the in the Middle East area um very important we uh depending on let's say the the way how to do business currently we try to concentrate on those countries where we can have um let's say um at least English as an accepted business language great is there any particular region you're having the most success with right now is it sounds like European Union's um kind of first wave what's them yes that's the first definitely that's the first wave and now we're also getting the uh the European instance up and running it's clearly our commitment also to the market saying okay we know there are certain dedicated uh requirements and we take care of this and and we're just launching it we're building up this one uh the instance um in the AWS uh service center here in Frankfurt also with some dedicated Hardware internet in a data center in Frankfurt where we have with the date six by the way uh the highest internet interconnection bandwidth on the planet so we have very short latency to wherever you are on on the globe that's a great that's a great call outfit benefit too I was going to ask that what are some of the benefits your partners are seeing in emea and Asia Pacific well I would say um the the benefits is for them it's clearly they can they can uh talk with customers and can offer customers penetration testing which they before and even didn't think about because it penetrates penetration testing in a traditional way was simply too expensive for them too complex the preparation time was too long um they didn't have even have the capacity uh to um to support a pain an external pain tester now with this service you can go in and say even if they Mr customer we can do a test with you in a couple of minutes within we have installed the docker container within 10 minutes we have the pen test started that's it and then we just wait and and I would say that is we'll we are we are seeing so many aha moments then now because on the partner side when they see node zero the first time working it's like this wow that is great and then they work out to customers and and show it to their typically at the beginning mostly the friendly customers like wow that's great I need that and and I would say um the feedback from the partners is that is a service where I do not have to evangelize the customer everybody understands penetration testing I don't have to say describe what it is they understand the customer understanding immediately yes penetration testing good about that I know I should do it but uh too complex too expensive now with the name is for example as an mssp service provided from one of our partners but it's getting easy yeah it's great and it's great great benefit there I mean I gotta say I'm a huge fan of what you guys are doing I like this continuous automation that's a major benefit to anyone doing devops or any kind of modern application development this is just a godsend for them this is really good and like you said the pen testers that are doing it they were kind of coming down from their expertise to kind of do things that should have been automated they get to focus on the bigger ticket items that's a really big point so we free them we free the pain testers for the higher level elements of the penetration testing segment and that is typically the application testing which is currently far away from being automated yeah and that's where the most critical workloads are and I think this is the nice balance congratulations on the international expansion of the program and thanks for coming on this special presentation really I really appreciate it thank you you're welcome okay this is thecube special presentation you know check out pen test automation International expansion Horizon 3 dot AI uh really Innovative solution in our next segment Chris Hill sector head for strategic accounts will discuss the power of Horizon 3.ai and Splunk in action you're watching the cube the leader in high tech Enterprise coverage foreign [Music] [Music] welcome back everyone to the cube and Horizon 3.ai special presentation I'm John Furrier host of thecube we're with Chris Hill sector head for strategic accounts and federal at Horizon 3.ai a great Innovative company Chris great to see you thanks for coming on thecube yeah like I said uh you know great to meet you John long time listener first time caller so excited to be here with you guys yeah we were talking before camera you had Splunk back in 2013 and I think 2012 was our first splunk.com and boy man you know talk about being in the right place at the right time now we're at another inflection point and Splunk continues to be relevant um and continuing to have that data driving Security in that interplay and your CEO former CTO of his plug as well at Horizon who's been on before really Innovative product you guys have but you know yeah don't wait for a breach to find out if you're logging the right data this is the topic of this thread Splunk is very much part of this new international expansion announcement uh with you guys tell us what are some of the challenges that you see where this is relevant for the Splunk and Horizon AI as you guys expand uh node zero out internationally yeah well so across so you know my role uh within Splunk it was uh working with our most strategic accounts and so I looked back to 2013 and I think about the sales process like working with with our small customers you know it was um it was still very siled back then like I was selling to an I.T team that was either using this for it operations um we generally would always even say yeah although we do security we weren't really designed for it we're a log management tool and we I'm sure you remember back then John we were like sort of stepping into the security space and and the public sector domain that I was in you know security was 70 of what we did when I look back to sort of uh the transformation that I was witnessing in that digital transformation um you know when I look at like 2019 to today you look at how uh the IT team and the security teams are being have been forced to break down those barriers that they used to sort of be silent away would not commute communicate one you know the security guys would be like oh this is my box I.T you're not allowed in today you can't get away with that and I think that the value that we bring to you know and of course Splunk has been a huge leader in that space and continues to do Innovation across the board but I think what we've we're seeing in the space and I was talking with Patrick Coughlin the SVP of uh security markets about this is that you know what we've been able to do with Splunk is build a purpose-built solution that allows Splunk to eat more data so Splunk itself is ulk know it's an ingest engine right the great reason people bought it was you could build these really fast dashboards and grab intelligence out of it but without data it doesn't do anything right so how do you drive and how do you bring more data in and most importantly from a customer perspective how do you bring the right data in and so if you think about what node zero and what we're doing in a horizon 3 is that sure we do pen testing but because we're an autonomous pen testing tool we do it continuously so this whole thought I'd be like oh crud like my customers oh yeah we got a pen test coming up it's gonna be six weeks the week oh yeah you know and everyone's gonna sit on their hands call me back in two months Chris we'll talk to you then right not not a real efficient way to test your environment and shoot we saw that with Uber this week right um you know and that's a case where we could have helped oh just right we could explain the Uber thing because it was a contractor just give a quick highlight of what happened so you can connect the doctor yeah no problem so um it was uh I got I think it was yeah one of those uh you know games where they would try and test an environment um and with the uh pen tester did was he kept on calling them MFA guys being like I need to reset my password we need to set my right password and eventually the um the customer service guy said okay I'm resetting it once he had reset and bypassed the multi-factor authentication he then was able to get in and get access to the building area that he was in or I think not the domain but he was able to gain access to a partial part of that Network he then paralleled over to what I would assume is like a VA VMware or some virtual machine that had notes that had all of the credentials for logging into various domains and So within minutes they had access and that's the sort of stuff that we do you know a lot of these tools like um you know you think about the cacophony of tools that are out there in a GTA architect architecture right I'm gonna get like a z-scale or I'm going to have uh octum and I have a Splunk I've been into the solar system I mean I don't mean to name names we have crowdstriker or Sentinel one in there it's just it's a cacophony of things that don't work together they weren't designed work together and so we have seen so many times in our business through our customer support and just working with customers when we do their pen tests that there will be 5 000 servers out there three are misconfigured those three misconfigurations will create the open door because remember the hacker only needs to be right once the defender needs to be right all the time and that's the challenge and so that's what I'm really passionate about what we're doing uh here at Horizon three I see this my digital transformation migration and security going on which uh we're at the tip of the spear it's why I joined sey Hall coming on this journey uh and just super excited about where the path's going and super excited about the relationship with Splunk I get into more details on some of the specifics of that but um you know well you're nailing I mean we've been doing a lot of things on super cloud and this next gen environment we're calling it next gen you're really seeing devops obviously devsecops has already won the it role has moved to the developer shift left is an indicator of that it's one of the many examples higher velocity code software supply chain you hear these things that means that it is now in the developer hands it is replaced by the new Ops data Ops teams and security where there's a lot of horizontal thinking to your point about access there's no more perimeter huge 100 right is really right on things one time you know to get in there once you're in then you can hang out move around move laterally big problem okay so we get that now the challenges for these teams as they are transitioning organizationally how do they figure out what to do okay this is the next step they already have Splunk so now they're kind of in transition while protecting for a hundred percent ratio of success so how would you look at that and describe the challenge is what do they do what is it what are the teams facing with their data and what's next what are they what are they what action do they take so let's use some vernacular that folks will know so if I think about devsecops right we both know what that means that I'm going to build security into the app it normally talks about sec devops right how am I building security around the perimeter of what's going inside my ecosystem and what are they doing and so if you think about what we're able to do with somebody like Splunk is we can pen test the entire environment from Soup To Nuts right so I'm going to test the end points through to its I'm going to look for misconfigurations I'm going to I'm going to look for um uh credential exposed credentials you know I'm going to look for anything I can in the environment again I'm going to do it at light speed and and what what we're doing for that SEC devops space is to you know did you detect that we were in your environment so did we alert Splunk or the Sim that there's someone in the environment laterally moving around did they more importantly did they log us into their environment and when do they detect that log to trigger that log did they alert on us and then finally most importantly for every CSO out there is going to be did they stop us and so that's how we we do this and I think you when speaking with um stay Hall before you know we've come up with this um boils but we call it fine fix verifying so what we do is we go in is we act as the attacker right we act in a production environment so we're not going to be we're a passive attacker but we will go in on credentialed on agents but we have to assume to have an assumed breach model which means we're going to put a Docker container in your environment and then we're going to fingerprint the environment so we're going to go out and do an asset survey now that's something that's not something that Splunk does super well you know so can Splunk see all the assets do the same assets marry up we're going to log all that data and think and then put load that into this long Sim or the smoke logging tools just to have it in Enterprise right that's an immediate future ad that they've got um and then we've got the fix so once we've completed our pen test um we are then going to generate a report and we can talk about these in a little bit later but the reports will show an executive summary the assets that we found which would be your asset Discovery aspect of that a fix report and the fixed report I think is probably the most important one it will go down and identify what we did how we did it and then how to fix that and then from that the pen tester or the organization should fix those then they go back and run another test and then they validate like a change detection environment to see hey did those fixes taste play take place and you know snehaw when he was the CTO of jsoc he shared with me a number of times about it's like man there would be 15 more items on next week's punch sheet that we didn't know about and it's and it has to do with how we you know how they were uh prioritizing the cves and whatnot because they would take all CBDs it was critical or non-critical and it's like we are able to create context in that environment that feeds better information into Splunk and whatnot that brings that brings up the efficiency for Splunk specifically the teams out there by the way the burnout thing is real I mean this whole I just finished my list and I got 15 more or whatever the list just can keeps growing how did node zero specifically help Splunk teams be more efficient like that's the question I want to get at because this seems like a very scale way for Splunk customers and teams service teams to be more so the question is how does node zero help make Splunk specifically their service teams be more efficient so so today in our early interactions we're building customers we've seen are five things um and I'll start with sort of identifying the blind spots right so kind of what I just talked about with you did we detect did we log did we alert did they stop node zero right and so I would I put that you know a more Layman's third grade term and if I was going to beat a fifth grader at this game would be we can be the sparring partner for a Splunk Enterprise customer a Splunk Essentials customer someone using Splunk soar or even just an Enterprise Splunk customer that may be a small shop with three people and just wants to know where am I exposed so by creating and generating these reports and then having um the API that actually generates the dashboard they can take all of these events that we've logged and log them in and then where that then comes in is number two is how do we prioritize those logs right so how do we create visibility to logs that that um are have critical impacts and again as I mentioned earlier not all cves are high impact regard and also not all or low right so if you daisy chain a bunch of low cves together boom I've got a mission critical AP uh CPE that needs to be fixed now such as a credential moving to an NT box that's got a text file with a bunch of passwords on it that would be very bad um and then third would be uh verifying that you have all of the hosts so one of the things that splunk's not particularly great at and they'll literate themselves they don't do asset Discovery so dude what assets do we see and what are they logging from that um and then for from um for every event that they are able to identify one of the cool things that we can do is actually create this low code no code environment so they could let you know Splunk customers can use Splunk sword to actually triage events and prioritize that event so where they're being routed within it to optimize the Sox team time to Market or time to triage any given event obviously reducing MTR and then finally I think one of the neatest things that we'll be seeing us develop is um our ability to build glass cables so behind me you'll see one of our triage events and how we build uh a Lockheed Martin kill chain on that with a glass table which is very familiar to the community we're going to have the ability and not too distant future to allow people to search observe on those iocs and if people aren't familiar with it ioc it's an instant of a compromise so that's a vector that we want to drill into and of course who's better at Drilling in the data and smoke yeah this is a critter this is an awesome Synergy there I mean I can see a Splunk customer going man this just gives me so much more capability action actionability and also real understanding and I think this is what I want to dig into if you don't mind understanding that critical impact okay is kind of where I see this coming got the data data ingest now data's data but the question is what not to log you know where are things misconfigured these are critical questions so can you talk about what it means to understand critical impact yeah so I think you know going back to the things that I just spoke about a lot of those cves where you'll see um uh low low low and then you daisy chain together and they're suddenly like oh this is high now but then your other impact of like if you're if you're a Splunk customer you know and I had it I had several of them I had one customer that you know terabytes of McAfee data being brought in and it was like all right there's a lot of other data that you probably also want to bring but they could only afford wanted to do certain data sets because that's and they didn't know how to prioritize or filter those data sets and so we provide that opportunity to say hey these are the critical ones to bring in but there's also the ones that you don't necessarily need to bring in because low cve in this case really does mean low cve like an ILO server would be one that um that's the print server uh where the uh your admin credentials are on on like a printer and so there will be credentials on that that's something that a hacker might go in to look at so although the cve on it is low is if you daisy chain with somebody that's able to get into that you might say Ah that's high and we would then potentially rank it giving our AI logic to say that's a moderate so put it on the scale and we prioritize those versus uh of all of these scanners just going to give you a bunch of CDs and good luck and translating that if I if I can and tell me if I'm wrong that kind of speaks to that whole lateral movement that's it challenge right print serve a great example looks stupid low end who's going to want to deal with the print server oh but it's connected into a critical system there's a path is that kind of what you're getting at yeah I use Daisy Chain I think that's from the community they came from uh but it's just a lateral movement it's exactly what they're doing in those low level low critical lateral movements is where the hackers are getting in right so that's the beauty thing about the uh the Uber example is that who would have thought you know I've got my monthly Factor authentication going in a human made a mistake we can't we can't not expect humans to make mistakes we're fallible right the reality is is once they were in the environment they could have protected themselves by running enough pen tests to know that they had certain uh exposed credentials that would have stopped the breach and they did not had not done that in their environment and I'm not poking yeah but it's an interesting Trend though I mean it's obvious if sometimes those low end items are also not protected well so it's easy to get at from a hacker standpoint but also the people in charge of them can be fished easily or spearfished because they're not paying attention because they don't have to no one ever told them hey be careful yeah for the community that I came from John that's exactly how they they would uh meet you at a uh an International Event um introduce themselves as a graduate student these are National actor States uh would you mind reviewing my thesis on such and such and I was at Adobe at the time that I was working on this instead of having to get the PDF they opened the PDF and whoever that customer was launches and I don't know if you remember back in like 2008 time frame there was a lot of issues around IP being by a nation state being stolen from the United States and that's exactly how they did it and John that's or LinkedIn hey I want to get a joke we want to hire you double the salary oh I'm gonna click on that for sure you know yeah right exactly yeah the one thing I would say to you is like uh when we look at like sort of you know because I think we did 10 000 pen tests last year is it's probably over that now you know we have these sort of top 10 ways that we think and find people coming into the environment the funniest thing is that only one of them is a cve related vulnerability like uh you know you guys know what they are right so it's it but it's it's like two percent of the attacks are occurring through the cves but yeah there's all that attention spent to that and very little attention spent to this pen testing side which is sort of this continuous threat you know monitoring space and and this vulnerability space where I think we play a such an important role and I'm so excited to be a part of the tip of the spear on this one yeah I'm old enough to know the movie sneakers which I loved as a you know watching that movie you know professional hackers are testing testing always testing the environment I love this I got to ask you as we kind of wrap up here Chris if you don't mind the the benefits to Professional Services from this Alliance big news Splunk and you guys work well together we see that clearly what are what other benefits do Professional Services teams see from the Splunk and Horizon 3.ai Alliance so if you're I think for from our our from both of our uh Partners uh as we bring these guys together and many of them already are the same partner right uh is that uh first off the licensing model is probably one of the key areas that we really excel at so if you're an end user you can buy uh for the Enterprise by the number of IP addresses you're using um but uh if you're a partner working with this there's solution ways that you can go in and we'll license as to msps and what that business model on msps looks like but the unique thing that we do here is this C plus license and so the Consulting plus license allows like a uh somebody a small to mid-sized to some very large uh you know Fortune 100 uh consulting firms use this uh by buying into a license called um Consulting plus where they can have unlimited uh access to as many IPS as they want but you can only run one test at a time and as you can imagine when we're going and hacking passwords and um checking hashes and decrypting hashes that can take a while so but for the right customer it's it's a perfect tool and so I I'm so excited about our ability to go to market with uh our partners so that we understand ourselves understand how not to just sell to or not tell just to sell through but we know how to sell with them as a good vendor partner I think that that's one thing that we've done a really good job building bring it into the market yeah I think also the Splunk has had great success how they've enabled uh partners and Professional Services absolutely you know the services that layer on top of Splunk are multi-fold tons of great benefits so you guys Vector right into that ride that way with friction and and the cool thing is that in you know in one of our reports which could be totally customized uh with someone else's logo we're going to generate you know so I I used to work in another organization it wasn't Splunk but we we did uh you know pen testing as for for customers and my pen testers would come on site they'd do the engagement and they would leave and then another release someone would be oh shoot we got another sector that was breached and they'd call you back you know four weeks later and so by August our entire pen testings teams would be sold out and it would be like well even in March maybe and they're like no no I gotta breach now and and and then when they do go in they go through do the pen test and they hand over a PDF and they pack on the back and say there's where your problems are you need to fix it and the reality is that what we're going to generate completely autonomously with no human interaction is we're going to go and find all the permutations of anything we found and the fix for those permutations and then once you've fixed everything you just go back and run another pen test it's you know for what people pay for one pen test they can have a tool that does that every every Pat patch on Tuesday and that's on Wednesday you know triage throughout the week green yellow red I wanted to see the colors show me green green is good right not red and one CIO doesn't want who doesn't want that dashboard right it's it's exactly it and we can help bring I think that you know I'm really excited about helping drive this with the Splunk team because they get that they understand that it's the green yellow red dashboard and and how do we help them find more green uh so that the other guys are in red yeah and get in the data and do the right thing and be efficient with how you use the data know what to look at so many things to pay attention to you know the combination of both and then go to market strategy real brilliant congratulations Chris thanks for coming on and sharing um this news with the detail around the Splunk in action around the alliance thanks for sharing John my pleasure thanks look forward to seeing you soon all right great we'll follow up and do another segment on devops and I.T and security teams as the new new Ops but and super cloud a bunch of other stuff so thanks for coming on and our next segment the CEO of horizon 3.aa will break down all the new news for us here on thecube you're watching thecube the leader in high tech Enterprise coverage [Music] yeah the partner program for us has been fantastic you know I think prior to that you know as most organizations most uh uh most Farmers most mssps might not necessarily have a a bench at all for penetration testing uh maybe they subcontract this work out or maybe they do it themselves but trying to staff that kind of position can be incredibly difficult for us this was a differentiator a a new a new partner a new partnership that allowed us to uh not only perform services for our customers but be able to provide a product by which that they can do it themselves so we work with our customers in a variety of ways some of them want more routine testing and perform this themselves but we're also a certified service provider of horizon 3 being able to perform uh penetration tests uh help review the the data provide color provide analysis for our customers in a broader sense right not necessarily the the black and white elements of you know what was uh what's critical what's high what's medium what's low what you need to fix but are there systemic issues this has allowed us to onboard new customers this has allowed us to migrate some penetration testing services to us from from competitors in the marketplace But ultimately this is occurring because the the product and the outcome are special they're unique and they're effective our customers like what they're seeing they like the routineness of it many of them you know again like doing this themselves you know being able to kind of pen test themselves parts of their networks um and the the new use cases right I'm a large organization I have eight to ten Acquisitions per year wouldn't it be great to have a tool to be able to perform a penetration test both internal and external of that acquisition before we integrate the two companies and maybe bringing on some risk it's a very effective partnership uh one that really is uh kind of taken our our Engineers our account Executives by storm um you know this this is a a partnership that's been very valuable to us [Music] a key part of the value and business model at Horizon 3 is enabling Partners to leverage node zero to make more revenue for themselves our goal is that for sixty percent of our Revenue this year will be originated by partners and that 95 of our Revenue next year will be originated by partners and so a key to that strategy is making us an integral part of your business models as a partner a key quote from one of our partners is that we enable every one of their business units to generate Revenue so let's talk about that in a little bit more detail first is that if you have a pen test Consulting business take Deloitte as an example what was six weeks of human labor at Deloitte per pen test has been cut down to four days of Labor using node zero to conduct reconnaissance find all the juicy interesting areas of the of the Enterprise that are exploitable and being able to go assess the entire organization and then all of those details get served up to the human to be able to look at understand and determine where to probe deeper so what you see in that pen test Consulting business is that node zero becomes a force multiplier where those Consulting teams were able to cover way more accounts and way more IPS within those accounts with the same or fewer consultants and so that directly leads to profit margin expansion for the Penn testing business itself because node 0 is a force multiplier the second business model here is if you're an mssp as an mssp you're already making money providing defensive cyber security operations for a large volume of customers and so what they do is they'll license node zero and use us as an upsell to their mssb business to start to deliver either continuous red teaming continuous verification or purple teaming as a service and so in that particular business model they've got an additional line of Revenue where they can increase the spend of their existing customers by bolting on node 0 as a purple team as a service offering the third business model or customer type is if you're an I.T services provider so as an I.T services provider you make money installing and configuring security products like Splunk or crowdstrike or hemio you also make money reselling those products and you also make money generating follow-on services to continue to harden your customer environments and so for them what what those it service providers will do is use us to verify that they've installed Splunk correctly improved to their customer that Splunk was installed correctly or crowdstrike was installed correctly using our results and then use our results to drive follow-on services and revenue and then finally we've got the value-added reseller which is just a straight up reseller because of how fast our sales Cycles are these vars are able to typically go from cold email to deal close in six to eight weeks at Horizon 3 at least a single sales engineer is able to run 30 to 50 pocs concurrently because our pocs are very lightweight and don't require any on-prem customization or heavy pre-sales post sales activity so as a result we're able to have a few amount of sellers driving a lot of Revenue and volume for us well the same thing applies to bars there isn't a lot of effort to sell the product or prove its value so vars are able to sell a lot more Horizon 3 node zero product without having to build up a huge specialist sales organization so what I'm going to do is talk through uh scenario three here as an I.T service provider and just how powerful node zero can be in driving additional Revenue so in here think of for every one dollar of node zero license purchased by the IT service provider to do their business it'll generate ten dollars of additional revenue for that partner so in this example kidney group uses node 0 to verify that they have installed and deployed Splunk correctly so Kitty group is a Splunk partner they they sell it services to install configure deploy and maintain Splunk and as they deploy Splunk they're going to use node 0 to attack the environment and make sure that the right logs and alerts and monitoring are being handled within the Splunk deployment so it's a way of doing QA or verifying that Splunk has been configured correctly and that's going to be internally used by kidney group to prove the quality of their services that they've just delivered then what they're going to do is they're going to show and leave behind that node zero Report with their client and that creates a resell opportunity for for kidney group to resell node 0 to their client because their client is seeing the reports and the results and saying wow this is pretty amazing and those reports can be co-branded where it's a pen testing report branded with kidney group but it says powered by Horizon three under it from there kidney group is able to take the fixed actions report that's automatically generated with every pen test through node zero and they're able to use that as the starting point for a statement of work to sell follow-on services to fix all of the problems that node zero identified fixing l11r misconfigurations fixing or patching VMware or updating credentials policies and so on so what happens is node 0 has found a bunch of problems the client often lacks the capacity to fix and so kidney group can use that lack of capacity by the client as a follow-on sales opportunity for follow-on services and finally based on the findings from node zero kidney group can look at that report and say to the customer you know customer if you bought crowdstrike you'd be able to uh prevent node Zero from attacking and succeeding in the way that it did for if you bought humano or if you bought Palo Alto networks or if you bought uh some privileged access management solution because of what node 0 was able to do with credential harvesting and attacks and so as a result kidney group is able to resell other security products within their portfolio crowdstrike Falcon humano Polito networks demisto Phantom and so on based on the gaps that were identified by node zero and that pen test and what that creates is another feedback loop where kidney group will then go use node 0 to verify that crowdstrike product has actually been installed and configured correctly and then this becomes the cycle of using node 0 to verify a deployment using that verification to drive a bunch of follow-on services and resell opportunities which then further drives more usage of the product now the way that we licensed is that it's a usage-based license licensing model so that the partner will grow their node zero Consulting plus license as they grow their business so for example if you're a kidney group then week one you've got you're going to use node zero to verify your Splunk install in week two if you have a pen testing business you're going to go off and use node zero to be a force multiplier for your pen testing uh client opportunity and then if you have an mssp business then in week three you're going to use node zero to go execute a purple team mssp offering for your clients so not necessarily a kidney group but if you're a Deloitte or ATT these larger companies and you've got multiple lines of business if you're Optive for instance you all you have to do is buy one Consulting plus license and you're going to be able to run as many pen tests as you want sequentially so now you can buy a single license and use that one license to meet your week one client commitments and then meet your week two and then meet your week three and as you grow your business you start to run multiple pen tests concurrently so in week one you've got to do a Splunk verify uh verify Splunk install and you've got to run a pen test and you've got to do a purple team opportunity you just simply expand the number of Consulting plus licenses from one license to three licenses and so now as you systematically grow your business you're able to grow your node zero capacity with you giving you predictable cogs predictable margins and once again 10x additional Revenue opportunity for that investment in the node zero Consulting plus license my name is Saint I'm the co-founder and CEO here at Horizon 3. I'm going to talk to you today about why it's important to look at your Enterprise Through The Eyes of an attacker the challenge I had when I was a CIO in banking the CTO at Splunk and serving within the Department of Defense is that I had no idea I was Secure until the bad guys had showed up am I logging the right data am I fixing the right vulnerabilities are my security tools that I've paid millions of dollars for actually working together to defend me and the answer is I don't know does my team actually know how to respond to a breach in the middle of an incident I don't know I've got to wait for the bad guys to show up and so the challenge I had was how do we proactively verify our security posture I tried a variety of techniques the first was the use of vulnerability scanners and the challenge with vulnerability scanners is being vulnerable doesn't mean you're exploitable I might have a hundred thousand findings from my scanner of which maybe five or ten can actually be exploited in my environment the other big problem with scanners is that they can't chain weaknesses together from machine to machine so if you've got a thousand machines in your environment or more what a vulnerability scanner will do is tell you you have a problem on machine one and separately a problem on machine two but what they can tell you is that an attacker could use a load from machine one plus a low from machine two to equal to critical in your environment and what attackers do in their tactics is they chain together misconfigurations dangerous product defaults harvested credentials and exploitable vulnerabilities into attack paths across different machines so to address the attack pads across different machines I tried layering in consulting-based pen testing and the issue is when you've got thousands of hosts or hundreds of thousands of hosts in your environment human-based pen testing simply doesn't scale to test an infrastructure of that size moreover when they actually do execute a pen test and you get the report oftentimes you lack the expertise within your team to quickly retest to verify that you've actually fixed the problem and so what happens is you end up with these pen test reports that are incomplete snapshots and quickly going stale and then to mitigate that problem I tried using breach and attack simulation tools and the struggle with these tools is one I had to install credentialed agents everywhere two I had to write my own custom attack scripts that I didn't have much talent for but also I had to maintain as my environment changed and then three these types of tools were not safe to run against production systems which was the the majority of my attack surface so that's why we went off to start Horizon 3. so Tony and I met when we were in Special Operations together and the challenge we wanted to solve was how do we do infrastructure security testing at scale by giving the the power of a 20-year pen testing veteran into the hands of an I.T admin a network engineer in just three clicks and the whole idea is we enable these fixers The Blue Team to be able to run node Zero Hour pen testing product to quickly find problems in their environment that blue team will then then go off and fix the issues that were found and then they can quickly rerun the attack to verify that they fixed the problem and the whole idea is delivering this without requiring custom scripts be developed without requiring credential agents be installed and without requiring the use of external third-party consulting services or Professional Services self-service pen testing to quickly Drive find fix verify there are three primary use cases that our customers use us for the first is the sock manager that uses us to verify that their security tools are actually effective to verify that they're logging the right data in Splunk or in their Sim to verify that their managed security services provider is able to quickly detect and respond to an attack and hold them accountable for their slas or that the sock understands how to quickly detect and respond and measuring and verifying that or that the variety of tools that you have in your stack most organizations have 130 plus cyber security tools none of which are designed to work together are actually working together the second primary use case is proactively hardening and verifying your systems this is when the I that it admin that network engineer they're able to run self-service pen tests to verify that their Cisco environment is installed in hardened and configured correctly or that their credential policies are set up right or that their vcenter or web sphere or kubernetes environments are actually designed to be secure and what this allows the it admins and network Engineers to do is shift from running one or two pen tests a year to 30 40 or more pen tests a month and you can actually wire those pen tests into your devops process or into your detection engineering and the change management processes to automatically trigger pen tests every time there's a change in your environment the third primary use case is for those organizations lucky enough to have their own internal red team they'll use node zero to do reconnaissance and exploitation at scale and then use the output as a starting point for the humans to step in and focus on the really hard juicy stuff that gets them on stage at Defcon and so these are the three primary use cases and what we'll do is zoom into the find fix verify Loop because what I've found in my experience is find fix verify is the future operating model for cyber security organizations and what I mean here is in the find using continuous pen testing what you want to enable is on-demand self-service pen tests you want those pen tests to find attack pads at scale spanning your on-prem infrastructure your Cloud infrastructure and your perimeter because attackers don't only state in one place they will find ways to chain together a perimeter breach a credential from your on-prem to gain access to your cloud or some other permutation and then the third part in continuous pen testing is attackers don't focus on critical vulnerabilities anymore they know we've built vulnerability Management Programs to reduce those vulnerabilities so attackers have adapted and what they do is chain together misconfigurations in your infrastructure and software and applications with dangerous product defaults with exploitable vulnerabilities and through the collection of credentials through a mix of techniques at scale once you've found those problems the next question is what do you do about it well you want to be able to prioritize fixing problems that are actually exploitable in your environment that truly matter meaning they're going to lead to domain compromise or domain user compromise or access your sensitive data the second thing you want to fix is making sure you understand what risk your crown jewels data is exposed to where is your crown jewels data is in the cloud is it on-prem has it been copied to a share drive that you weren't aware of if a domain user was compromised could they access that crown jewels data you want to be able to use the attacker's perspective to secure the critical data you have in your infrastructure and then finally as you fix these problems you want to quickly remediate and retest that you've actually fixed the issue and this fine fix verify cycle becomes that accelerator that drives purple team culture the third part here is verify and what you want to be able to do in the verify step is verify that your security tools and processes in people can effectively detect and respond to a breach you want to be able to integrate that into your detection engineering processes so that you know you're catching the right security rules or that you've deployed the right configurations you also want to make sure that your environment is adhering to the best practices around systems hardening in cyber resilience and finally you want to be able to prove your security posture over a time to your board to your leadership into your regulators so what I'll do now is zoom into each of these three steps so when we zoom in to find here's the first example using node 0 and autonomous pen testing and what an attacker will do is find a way to break through the perimeter in this example it's very easy to misconfigure kubernetes to allow an attacker to gain remote code execution into your on-prem kubernetes environment and break through the perimeter and from there what the attacker is going to do is conduct Network reconnaissance and then find ways to gain code execution on other machines in the environment and as they get code execution they start to dump credentials collect a bunch of ntlm hashes crack those hashes using open source and dark web available data as part of those attacks and then reuse those credentials to log in and laterally maneuver throughout the environment and then as they loudly maneuver they can reuse those credentials and use credential spraying techniques and so on to compromise your business email to log in as admin into your cloud and this is a very common attack and rarely is a CV actually needed to execute this attack often it's just a misconfiguration in kubernetes with a bad credential policy or password policy combined with bad practices of credential reuse across the organization here's another example of an internal pen test and this is from an actual customer they had 5 000 hosts within their environment they had EDR and uba tools installed and they initiated in an internal pen test on a single machine from that single initial access point node zero enumerated the network conducted reconnaissance and found five thousand hosts were accessible what node 0 will do under the covers is organize all of that reconnaissance data into a knowledge graph that we call the Cyber terrain map and that cyber Terrain map becomes the key data structure that we use to efficiently maneuver and attack and compromise your environment so what node zero will do is they'll try to find ways to get code execution reuse credentials and so on in this customer example they had Fortinet installed as their EDR but node 0 was still able to get code execution on a Windows machine from there it was able to successfully dump credentials including sensitive credentials from the lsas process on the Windows box and then reuse those credentials to log in as domain admin in the network and once an attacker becomes domain admin they have the keys to the kingdom they can do anything they want so what happened here well it turns out Fortinet was misconfigured on three out of 5000 machines bad automation the customer had no idea this had happened they would have had to wait for an attacker to show up to realize that it was misconfigured the second thing is well why didn't Fortinet stop the credential pivot in the lateral movement and it turned out the customer didn't buy the right modules or turn on the right services within that particular product and we see this not only with Ford in it but we see this with Trend Micro and all the other defensive tools where it's very easy to miss a checkbox in the configuration that will do things like prevent credential dumping the next story I'll tell you is attackers don't have to hack in they log in so another infrastructure pen test a typical technique attackers will take is man in the middle uh attacks that will collect hashes so in this case what an attacker will do is leverage a tool or technique called responder to collect ntlm hashes that are being passed around the network and there's a variety of reasons why these hashes are passed around and it's a pretty common misconfiguration but as an attacker collects those hashes then they start to apply techniques to crack those hashes so they'll pass the hash and from there they will use open source intelligence common password structures and patterns and other types of techniques to try to crack those hashes into clear text passwords so here node 0 automatically collected hashes it automatically passed the hashes to crack those credentials and then from there it starts to take the domain user user ID passwords that it's collected and tries to access different services and systems in your Enterprise in this case node 0 is able to successfully gain access to the Office 365 email environment because three employees didn't have MFA configured so now what happens is node 0 has a placement and access in the business email system which sets up the conditions for fraud lateral phishing and other techniques but what's especially insightful here is that 80 of the hashes that were collected in this pen test were cracked in 15 minutes or less 80 percent 26 of the user accounts had a password that followed a pretty obvious pattern first initial last initial and four random digits the other thing that was interesting is 10 percent of service accounts had their user ID the same as their password so VMware admin VMware admin web sphere admin web Square admin so on and so forth and so attackers don't have to hack in they just log in with credentials that they've collected the next story here is becoming WS AWS admin so in this example once again internal pen test node zero gets initial access it discovers 2 000 hosts are network reachable from that environment if fingerprints and organizes all of that data into a cyber Terrain map from there it it fingerprints that hpilo the integrated lights out service was running on a subset of hosts hpilo is a service that is often not instrumented or observed by security teams nor is it easy to patch as a result attackers know this and immediately go after those types of services so in this case that ILO service was exploitable and were able to get code execution on it ILO stores all the user IDs and passwords in clear text in a particular set of processes so once we gain code execution we were able to dump all of the credentials and then from there laterally maneuver to log in to the windows box next door as admin and then on that admin box we're able to gain access to the share drives and we found a credentials file saved on a share Drive from there it turned out that credentials file was the AWS admin credentials file giving us full admin authority to their AWS accounts not a single security alert was triggered in this attack because the customer wasn't observing the ILO service and every step thereafter was a valid login in the environment and so what do you do step one patch the server step two delete the credentials file from the share drive and then step three is get better instrumentation on privileged access users and login the final story I'll tell is a typical pattern that we see across the board with that combines the various techniques I've described together where an attacker is going to go off and use open source intelligence to find all of the employees that work at your company from there they're going to look up those employees on dark web breach databases and other forms of information and then use that as a starting point to password spray to compromise a domain user all it takes is one employee to reuse a breached password for their Corporate email or all it takes is a single employee to have a weak password that's easily guessable all it takes is one and once the attacker is able to gain domain user access in most shops domain user is also the local admin on their laptop and once your local admin you can dump Sam and get local admin until M hashes you can use that to reuse credentials again local admin on neighboring machines and attackers will start to rinse and repeat then eventually they're able to get to a point where they can dump lsas or by unhooking the anti-virus defeating the EDR or finding a misconfigured EDR as we've talked about earlier to compromise the domain and what's consistent is that the fundamentals are broken at these shops they have poor password policies they don't have least access privilege implemented active directory groups are too permissive where domain admin or domain user is also the local admin uh AV or EDR Solutions are misconfigured or easily unhooked and so on and what we found in 10 000 pen tests is that user Behavior analytics tools never caught us in that lateral movement in part because those tools require pristine logging data in order to work and also it becomes very difficult to find that Baseline of normal usage versus abnormal usage of credential login another interesting Insight is there were several Marquee brand name mssps that were defending our customers environment and for them it took seven hours to detect and respond to the pen test seven hours the pen test was over in less than two hours and so what you had was an egregious violation of the service level agreements that that mssp had in place and the customer was able to use us to get service credit and drive accountability of their sock and of their provider the third interesting thing is in one case it took us seven minutes to become domain admin in a bank that bank had every Gucci security tool you could buy yet in 7 minutes and 19 seconds node zero started as an unauthenticated member of the network and was able to escalate privileges through chaining and misconfigurations in lateral movement and so on to become domain admin if it's seven minutes today we should assume it'll be less than a minute a year or two from now making it very difficult for humans to be able to detect and respond to that type of Blitzkrieg attack so that's in the find it's not just about finding problems though the bulk of the effort should be what to do about it the fix and the verify so as you find those problems back to kubernetes as an example we will show you the path here is the kill chain we took to compromise that environment we'll show you the impact here is the impact or here's the the proof of exploitation that we were able to use to be able to compromise it and there's the actual command that we executed so you could copy and paste that command and compromise that cubelet yourself if you want and then the impact is we got code execution and we'll actually show you here is the impact this is a critical here's why it enabled perimeter breach affected applications will tell you the specific IPS where you've got the problem how it maps to the miter attack framework and then we'll tell you exactly how to fix it we'll also show you what this problem enabled so you can accurately prioritize why this is important or why it's not important the next part is accurate prioritization the hardest part of my job as a CIO was deciding what not to fix so if you take SMB signing not required as an example by default that CVSs score is a one out of 10. but this misconfiguration is not a cve it's a misconfig enable an attacker to gain access to 19 credentials including one domain admin two local admins and access to a ton of data because of that context this is really a 10 out of 10. you better fix this as soon as possible however of the seven occurrences that we found it's only a critical in three out of the seven and these are the three specific machines and we'll tell you the exact way to fix it and you better fix these as soon as possible for these four machines over here these didn't allow us to do anything of consequence so that because the hardest part is deciding what not to fix you can justifiably choose not to fix these four issues right now and just add them to your backlog and surge your team to fix these three as quickly as possible and then once you fix these three you don't have to re-run the entire pen test you can select these three and then one click verify and run a very narrowly scoped pen test that is only testing this specific issue and what that creates is a much faster cycle of finding and fixing problems the other part of fixing is verifying that you don't have sensitive data at risk so once we become a domain user we're able to use those domain user credentials and try to gain access to databases file shares S3 buckets git repos and so on and help you understand what sensitive data you have at risk so in this example a green checkbox means we logged in as a valid domain user we're able to get read write access on the database this is how many records we could have accessed and we don't actually look at the values in the database but we'll show you the schema so you can quickly characterize that pii data was at risk here and we'll do that for your file shares and other sources of data so now you can accurately articulate the data you have at risk and prioritize cleaning that data up especially data that will lead to a fine or a big news issue so that's the find that's the fix now we're going to talk about the verify the key part in verify is embracing and integrating with detection engineering practices so when you think about your layers of security tools you've got lots of tools in place on average 130 tools at any given customer but these tools were not designed to work together so when you run a pen test what you want to do is say did you detect us did you log us did you alert on us did you stop us and from there what you want to see is okay what are the techniques that are commonly used to defeat an environment to actually compromise if you look at the top 10 techniques we use and there's far more than just these 10 but these are the most often executed nine out of ten have nothing to do with cves it has to do with misconfigurations dangerous product defaults bad credential policies and it's how we chain those together to become a domain admin or compromise a host so what what customers will do is every single attacker command we executed is provided to you as an attackivity log so you can actually see every single attacker command we ran the time stamp it was executed the hosts it executed on and how it Maps the minor attack tactics so our customers will have are these attacker logs on one screen and then they'll go look into Splunk or exabeam or Sentinel one or crowdstrike and say did you detect us did you log us did you alert on us or not and to make that even easier if you take this example hey Splunk what logs did you see at this time on the VMware host because that's when node 0 is able to dump credentials and that allows you to identify and fix your logging blind spots to make that easier we've got app integration so this is an actual Splunk app in the Splunk App Store and what you can come is inside the Splunk console itself you can fire up the Horizon 3 node 0 app all of the pen test results are here so that you can see all of the results in one place and you don't have to jump out of the tool and what you'll show you as I skip forward is hey there's a pen test here are the critical issues that we've identified for that weaker default issue here are the exact commands we executed and then we will automatically query into Splunk all all terms on between these times on that endpoint that relate to this attack so you can now quickly within the Splunk environment itself figure out that you're missing logs or that you're appropriately catching this issue and that becomes incredibly important in that detection engineering cycle that I mentioned earlier so how do our customers end up using us they shift from running one pen test a year to 30 40 pen tests a month oftentimes wiring us into their deployment automation to automatically run pen tests the other part that they'll do is as they run more pen tests they find more issues but eventually they hit this inflection point where they're able to rapidly clean up their environment and that inflection point is because the red and the blue teams start working together in a purple team culture and now they're working together to proactively harden their environment the other thing our customers will do is run us from different perspectives they'll first start running an RFC 1918 scope to see once the attacker gained initial access in a part of the network that had wide access what could they do and then from there they'll run us within a specific Network segment okay from within that segment could the attacker break out and gain access to another segment then they'll run us from their work from home environment could they Traverse the VPN and do something damaging and once they're in could they Traverse the VPN and get into my cloud then they'll break in from the outside all of these perspectives are available to you in Horizon 3 and node zero as a single SKU and you can run as many pen tests as you want if you run a phishing campaign and find that an intern in the finance department had the worst phishing behavior you can then inject their credentials and actually show the end-to-end story of how an attacker fished gained credentials of an intern and use that to gain access to sensitive financial data so what our customers end up doing is running multiple attacks from multiple perspectives and looking at those results over time I'll leave you two things one is what is the AI in Horizon 3 AI those knowledge graphs are the heart and soul of everything that we do and we use machine learning reinforcement techniques reinforcement learning techniques Markov decision models and so on to be able to efficiently maneuver and analyze the paths in those really large graphs we also use context-based scoring to prioritize weaknesses and we're also able to drive collective intelligence across all of the operations so the more pen tests we run the smarter we get and all of that is based on our knowledge graph analytics infrastructure that we have finally I'll leave you with this was my decision criteria when I was a buyer for my security testing strategy what I cared about was coverage I wanted to be able to assess my on-prem cloud perimeter and work from home and be safe to run in production I want to be able to do that as often as I wanted I want to be able to run pen tests in hours or days not weeks or months so I could accelerate that fine fix verify loop I wanted my it admins and network Engineers with limited offensive experience to be able to run a pen test in a few clicks through a self-service experience and not have to install agent and not have to write custom scripts and finally I didn't want to get nickeled and dimed on having to buy different types of attack modules or different types of attacks I wanted a single annual subscription that allowed me to run any type of attack as often as I wanted so I could look at my Trends in directions over time so I hope you found this talk valuable uh we're easy to find and I look forward to seeing seeing you use a product and letting our results do the talking when you look at uh you know kind of the way no our pen testing algorithms work is we dynamically select uh how to compromise an environment based on what we've discovered and the goal is to become a domain admin compromise a host compromise domain users find ways to encrypt data steal sensitive data and so on but when you look at the the top 10 techniques that we ended up uh using to compromise environments the first nine have nothing to do with cves and that's the reality cves are yes a vector but less than two percent of cves are actually used in a compromise oftentimes it's some sort of credential collection credential cracking uh credential pivoting and using that to become an admin and then uh compromising environments from that point on so I'll leave this up for you to kind of read through and you'll have the slides available for you but I found it very insightful that organizations and ourselves when I was a GE included invested heavily in just standard vulnerability Management Programs when I was at DOD that's all disa cared about asking us about was our our kind of our cve posture but the attackers have adapted to not rely on cves to get in because they know that organizations are actively looking at and patching those cves and instead they're chaining together credentials from one place with misconfigurations and dangerous product defaults in another to take over an environment a concrete example is by default vcenter backups are not encrypted and so as if an attacker finds vcenter what they'll do is find the backup location and there are specific V sender MTD files where the admin credentials are parsippled in the binaries so you can actually as an attacker find the right MTD file parse out the binary and now you've got the admin credentials for the vcenter environment and now start to log in as admin there's a bad habit by signal officers and Signal practitioners in the in the Army and elsewhere where the the VM notes section of a virtual image has the password for the VM well those VM notes are not stored encrypted and attackers know this and they're able to go off and find the VMS that are unencrypted find the note section and pull out the passwords for those images and then reuse those credentials across the board so I'll pause here and uh you know Patrick love you get some some commentary on on these techniques and other things that you've seen and what we'll do in the last say 10 to 15 minutes is uh is rolled through a little bit more on what do you do about it yeah yeah no I love it I think um I think this is pretty exhaustive what I like about what you've done here is uh you know we've seen we've seen double-digit increases in the number of organizations that are reporting actual breaches year over year for the last um for the last three years and it's often we kind of in the Zeitgeist we pegged that on ransomware which of course is like incredibly important and very top of mind um but what I like about what you have here is you know we're reminding the audience that the the attack surface area the vectors the matter um you know has to be more comprehensive than just thinking about ransomware scenarios yeah right on um so let's build on this when you think about your defense in depth you've got multiple security controls that you've purchased and integrated and you've got that redundancy if a control fails but the reality is that these security tools aren't designed to work together so when you run a pen test what you want to ask yourself is did you detect node zero did you log node zero did you alert on node zero and did you stop node zero and when you think about how to do that every single attacker command executed by node zero is available in an attacker log so you can now see you know at the bottom here vcenter um exploit at that time on that IP how it aligns to minor attack what you want to be able to do is go figure out did your security tools catch this or not and that becomes very important in using the attacker's perspective to improve your defensive security controls and so the way we've tried to make this easier back to like my my my the you know I bleed Green in many ways still from my smoke background is you want to be able to and what our customers do is hey we'll look at the attacker logs on one screen and they'll look at what did Splunk see or Miss in another screen and then they'll use that to figure out what their logging blind spots are and what that where that becomes really interesting is we've actually built out an integration into Splunk where there's a Splunk app you can download off of Splunk base and you'll get all of the pen test results right there in the Splunk console and from that Splunk console you're gonna be able to see these are all the pen tests that were run these are the issues that were found um so you can look at that particular pen test here are all of the weaknesses that were identified for that particular pen test and how they categorize out for each of those weaknesses you can click on any one of them that are critical in this case and then we'll tell you for that weakness and this is where where the the punch line comes in so I'll pause the video here for that weakness these are the commands that were executed on these endpoints at this time and then we'll actually query Splunk for that um for that IP address or containing that IP and these are the source types that surface any sort of activity so what we try to do is help you as quickly and efficiently as possible identify the logging blind spots in your Splunk environment based on the attacker's perspective so as this video kind of plays through you can see it Patrick I'd love to get your thoughts um just seeing so many Splunk deployments and the effectiveness of those deployments and and how this is going to help really Elevate the effectiveness of all of your Splunk customers yeah I'm super excited about this I mean I think this these kinds of purpose-built integration snail really move the needle for our customers I mean at the end of the day when I think about the power of Splunk I think about a product I was first introduced to 12 years ago that was an on-prem piece of software you know and at the time it sold on sort of Perpetual and term licenses but one made it special was that it could it could it could eat data at a speed that nothing else that I'd have ever seen you can ingest massively scalable amounts of data uh did cool things like schema on read which facilitated that there was this language called SPL that you could nerd out about uh and you went to a conference once a year and you talked about all the cool things you were splunking right but now as we think about the next phase of our growth um we live in a heterogeneous environment where our customers have so many different tools and data sources that are ever expanding and as you look at the as you look at the role of the ciso it's mind-blowing to me the amount of sources Services apps that are coming into the ciso span of let's just call it a span of influence in the last three years uh you know we're seeing things like infrastructure service level visibility application performance monitoring stuff that just never made sense for the security team to have visibility into you um at least not at the size and scale which we're demanding today um and and that's different and this isn't this is why it's so important that we have these joint purpose-built Integrations that um really provide more prescription to our customers about how do they walk on that Journey towards maturity what does zero to one look like what does one to two look like whereas you know 10 years ago customers were happy with platforms today they want integration they want Solutions and they want to drive outcomes and I think this is a great example of how together we are stepping to the evolving nature of the market and also the ever-evolving nature of the threat landscape and what I would say is the maturing needs of the customer in that environment yeah for sure I think especially if if we all anticipate budget pressure over the next 18 months due to the economy and elsewhere while the security budgets are not going to ever I don't think they're going to get cut they're not going to grow as fast and there's a lot more pressure on organizations to extract more value from their existing Investments as well as extracting more value and more impact from their existing teams and so security Effectiveness Fierce prioritization and automation I think become the three key themes of security uh over the next 18 months so I'll do very quickly is run through a few other use cases um every host that we identified in the pen test were able to score and say this host allowed us to do something significant therefore it's it's really critical you should be increasing your logging here hey these hosts down here we couldn't really do anything as an attacker so if you do have to make trade-offs you can make some trade-offs of your logging resolution at the lower end in order to increase logging resolution on the upper end so you've got that level of of um justification for where to increase or or adjust your logging resolution another example is every host we've discovered as an attacker we Expose and you can export and we want to make sure is every host we found as an attacker is being ingested from a Splunk standpoint a big issue I had as a CIO and user of Splunk and other tools is I had no idea if there were Rogue Raspberry Pi's on the network or if a new box was installed and whether Splunk was installed on it or not so now you can quickly start to correlate what hosts did we see and how does that reconcile with what you're logging from uh finally or second to last use case here on the Splunk integration side is for every single problem we've found we give multiple options for how to fix it this becomes a great way to prioritize what fixed actions to automate in your soar platform and what we want to get to eventually is being able to automatically trigger soar actions to fix well-known problems like automatically invalidating passwords for for poor poor passwords in our credentials amongst a whole bunch of other things we could go off and do and then finally if there is a well-known kill chain or attack path one of the things I really wish I could have done when I was a Splunk customer was take this type of kill chain that actually shows a path to domain admin that I'm sincerely worried about and use it as a glass table over which I could start to layer possible indicators of compromise and now you've got a great starting point for glass tables and iocs for actual kill chains that we know are exploitable in your environment and that becomes some super cool Integrations that we've got on the roadmap between us and the Splunk security side of the house so what I'll leave with actually Patrick before I do that you know um love to get your comments and then I'll I'll kind of leave with one last slide on this wartime security mindset uh pending you know assuming there's no other questions no I love it I mean I think this kind of um it's kind of glass table's approach to how do you how do you sort of visualize these workflows and then use things like sore and orchestration and automation to operationalize them is exactly where we see all of our customers going and getting away from I think an over engineered approach to soar with where it has to be super technical heavy with you know python programmers and getting more to this visual view of workflow creation um that really demystifies the power of Automation and also democratizes it so you don't have to have these programming languages in your resume in order to start really moving the needle on workflow creation policy enforcement and ultimately driving automation coverage across more and more of the workflows that your team is seeing yeah I think that between us being able to visualize the actual kill chain or attack path with you know think of a of uh the soar Market I think going towards this no code low code um you know configurable sore versus coded sore that's going to really be a game changer in improve or giving security teams a force multiplier so what I'll leave you with is this peacetime mindset of security no longer is sustainable we really have to get out of checking the box and then waiting for the bad guys to show up to verify that security tools are are working or not and the reason why we've got to really do that quickly is there are over a thousand companies that withdrew from the Russian economy over the past uh nine months due to the Ukrainian War there you should expect every one of them to be punished by the Russians for leaving and punished from a cyber standpoint and this is no longer about financial extortion that is ransomware this is about punishing and destroying companies and you can punish any one of these companies by going after them directly or by going after their suppliers and their Distributors so suddenly your attack surface is no more no longer just your own Enterprise it's how you bring your goods to Market and it's how you get your goods created because while I may not be able to disrupt your ability to harvest fruit if I can get those trucks stuck at the border I can increase spoilage and have the same effect and what we should expect to see is this idea of cyber-enabled economic Warfare where if we issue a sanction like Banning the Russians from traveling there is a cyber-enabled counter punch which is corrupt and destroy the American Airlines database that is below the threshold of War that's not going to trigger the 82nd Airborne to be mobilized but it's going to achieve the right effect ban the sale of luxury goods disrupt the supply chain and create shortages banned Russian oil and gas attack refineries to call a 10x spike in gas prices three days before the election this is the future and therefore I think what we have to do is shift towards a wartime mindset which is don't trust your security posture verify it see yourself Through The Eyes of the attacker build that incident response muscle memory and drive better collaboration between the red and the blue teams your suppliers and Distributors and your information uh sharing organization they have in place and what's really valuable for me as a Splunk customer was when a router crashes at that moment you don't know if it's due to an I.T Administration problem or an attacker and what you want to have are different people asking different questions of the same data and you want to have that integrated triage process of an I.T lens to that problem a security lens to that problem and then from there figuring out is is this an IT workflow to execute or a security incident to execute and you want to have all of that as an integrated team integrated process integrated technology stack and this is something that I very care I cared very deeply about as both a Splunk customer and a Splunk CTO that I see time and time again across the board so Patrick I'll leave you with the last word the final three minutes here and I don't see any open questions so please take us home oh man see how you think we spent hours and hours prepping for this together that that last uh uh 40 seconds of your talk track is probably one of the things I'm most passionate about in this industry right now uh and I think nist has done some really interesting work here around building cyber resilient organizations that have that has really I think helped help the industry see that um incidents can come from adverse conditions you know stress is uh uh performance taxations in the infrastructure service or app layer and they can come from malicious compromises uh Insider threats external threat actors and the more that we look at this from the perspective of of a broader cyber resilience Mission uh in a wartime mindset uh I I think we're going to be much better off and and will you talk about with operationally minded ice hacks information sharing intelligence sharing becomes so important in these wartime uh um situations and you know we know not all ice acts are created equal but we're also seeing a lot of um more ad hoc information sharing groups popping up so look I think I think you framed it really really well I love the concept of wartime mindset and um I I like the idea of applying a cyber resilience lens like if you have one more layer on top of that bottom right cake you know I think the it lens and the security lens they roll up to this concept of cyber resilience and I think this has done some great work there for us yeah you're you're spot on and that that is app and that's gonna I think be the the next um terrain that that uh that you're gonna see vendors try to get after but that I think Splunk is best position to win okay that's a wrap for this special Cube presentation you heard all about the global expansion of horizon 3.ai's partner program for their Partners have a unique opportunity to take advantage of their node zero product uh International go to Market expansion North America channel Partnerships and just overall relationships with companies like Splunk to make things more comprehensive in this disruptive cyber security world we live in and hope you enjoyed this program all the videos are available on thecube.net as well as check out Horizon 3 dot AI for their pen test Automation and ultimately their defense system that they use for testing always the environment that you're in great Innovative product and I hope you enjoyed the program again I'm John Furrier host of the cube thanks for watching

Published Date : Sep 28 2022

SUMMARY :

that's the sort of stuff that we do you

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Patrick CoughlinPERSON

0.99+

Jennifer LeePERSON

0.99+

ChrisPERSON

0.99+

TonyPERSON

0.99+

2013DATE

0.99+

Raina RichterPERSON

0.99+

SingaporeLOCATION

0.99+

EuropeLOCATION

0.99+

PatrickPERSON

0.99+

FrankfurtLOCATION

0.99+

JohnPERSON

0.99+

20-yearQUANTITY

0.99+

hundredsQUANTITY

0.99+

AWSORGANIZATION

0.99+

20 yearsQUANTITY

0.99+

seven minutesQUANTITY

0.99+

95QUANTITY

0.99+

FordORGANIZATION

0.99+

2.7 billionQUANTITY

0.99+

MarchDATE

0.99+

FinlandLOCATION

0.99+

seven hoursQUANTITY

0.99+

sixty percentQUANTITY

0.99+

John FurrierPERSON

0.99+

SwedenLOCATION

0.99+

John FurrierPERSON

0.99+

six weeksQUANTITY

0.99+

seven hoursQUANTITY

0.99+

19 credentialsQUANTITY

0.99+

ten dollarsQUANTITY

0.99+

JenniferPERSON

0.99+

5 000 hostsQUANTITY

0.99+

Horizon 3TITLE

0.99+

WednesdayDATE

0.99+

30QUANTITY

0.99+

eightQUANTITY

0.99+

Asia PacificLOCATION

0.99+

American AirlinesORGANIZATION

0.99+

DeloitteORGANIZATION

0.99+

three licensesQUANTITY

0.99+

two companiesQUANTITY

0.99+

2019DATE

0.99+

European UnionORGANIZATION

0.99+

sixQUANTITY

0.99+

seven occurrencesQUANTITY

0.99+

70QUANTITY

0.99+

three peopleQUANTITY

0.99+

Horizon 3.aiTITLE

0.99+

ATTORGANIZATION

0.99+

Net ZeroORGANIZATION

0.99+

SplunkORGANIZATION

0.99+

UberORGANIZATION

0.99+

fiveQUANTITY

0.99+

less than two percentQUANTITY

0.99+

less than two hoursQUANTITY

0.99+

2012DATE

0.99+

UKLOCATION

0.99+

AdobeORGANIZATION

0.99+

four issuesQUANTITY

0.99+

Department of DefenseORGANIZATION

0.99+

next yearDATE

0.99+

three stepsQUANTITY

0.99+

node 0TITLE

0.99+

15 minutesQUANTITY

0.99+

hundred percentQUANTITY

0.99+

node zeroTITLE

0.99+

10xQUANTITY

0.99+

last yearDATE

0.99+

7 minutesQUANTITY

0.99+

one licenseQUANTITY

0.99+

second thingQUANTITY

0.99+

thousands of hostsQUANTITY

0.99+

five thousand hostsQUANTITY

0.99+

next weekDATE

0.99+

Chris Hill, Horizon3.ai | Horizon3.ai Partner Program Expands Internationally


 

>>Welcome back everyone to the Cube and Horizon three.ai special presentation. I'm John Furrier, host of the Cube. We with Chris Hill, Sector head for strategic accounts and federal@horizonthree.ai. Great innovative company. Chris, great to see you. Thanks for coming on the Cube. >>Yeah, like I said, you know, great to meet you John. Long time listener. First time call. So excited to be here with >>You guys. Yeah, we were talking before camera. You had Splunk back in 2013 and I think 2012 was our first splunk.com. Yep. And boy man, you know, talk about being in the right place at the right time. Now we're at another inflection point and Splunk continues to be relevant and continuing to have that data driving security and that interplay. And your ceo, former CTO of Splunk as well at Horizons Neha, who's been on before. Really innovative product you guys have, but you know, Yeah, don't wait for a brief to find out if you're locking the right data. This is the topic of this thread. Splunk is very much part of this new international expansion announcement with you guys. Tell us what are some of the challenges that you see where this is relevant for the Splunk and the Horizon AI as you guys expand Node zero out internationally? >>Yeah, well so across, so you know, my role within Splunk was working with our most strategic accounts. And so I look back to 2013 and I think about the sales process like working with, with our small customers. You know, it was, it was still very siloed back then. Like I was selling to an IT team that was either using us for IT operations. We generally would always even say, yeah, although we do security, we weren't really designed for it. We're a log management tool. And you know, we, and I'm sure you remember back then John, we were like sort of stepping into the security space and in the public sector domain that I was in, you know, security was 70% of what we did. When I look back to sort of the transformation that I was, was witnessing in that digital transformation, you know when I, you look at like 2019 to today, you look at how the IT team and the security teams are, have been forced to break down those barriers that they used to sort of be silo away, would not communicate one, you know, the security guys would be like, Oh this is my BA box it, you're not allowed in today. >>You can't get away with that. And I think that the value that we bring to, you know, and of course Splunk has been a huge leader in that space and continues to do innovation across the board. But I think what we've we're seeing in the space that I was talking with Patrick Kauflin, the SVP of security markets about this, is that, you know, what we've been able to do with Splunk is build a purpose built solution that allows Splunk to eat more data. So Splunk itself, as you well know, it's an ingest engine, right? So the great reason people bought it was you could build these really fast dashboards and grab intelligence out of it, but without data it doesn't do anything, right? So how do you drive and how do you bring more data in? And most importantly from a customer perspective, how do you bring the right data in? >>And so if you think about what node zero and what we're doing in a Horizon three is that, sure we do pen testing, but because we're an autonomous pen testing tool, we do it continuously. So this whole thought of being like, Oh, crud like my customers, Oh yeah, we got a pen test coming up, it's gonna be six weeks. The wait. Oh yeah. You know, and everyone's gonna sit on their hands, Call me back in two months, Chris, we'll talk to you then. Right? Not, not a real efficient way to test your environment and shoot, we, we saw that with Uber this week. Right? You know, and that's a case where we could have helped. >>Well just real quick, explain the Uber thing cause it was a contractor. Just give a quick highlight of what happened so you can connect the >>Dots. Yeah, no problem. So there it was, I think it was one of those, you know, games where they would try and test an environment. And what the pen tester did was he kept on calling them MFA guys being like, I need to reset my password re to set my password. And eventually the customer service guy said, Okay, I'm resetting it. Once he had reset and bypassed the multifactor authentication, he then was able to get in and get access to the domain area that he was in or the, not the domain, but he was able to gain access to a partial part of the network. He then paralleled over to what would I assume is like a VA VMware or some virtual machine that had notes that had all of the credentials for logging into various domains. And so within minutes they had access. And that's the sort of stuff that we do under, you know, a lot of these tools. >>Like not, and I'm not, you know, you think about the cacophony of tools that are out there in a CTA orchestra architecture, right? I'm gonna get like a Zscaler, I'm gonna have Okta, I'm gonna have a Splunk, I'm gonna do this sore system. I mean, I don't mean to name names, we're gonna have crowd strike or, or Sentinel one in there. It's just, it's a cacophony of things that don't work together. They weren't designed work together. And so we have seen so many times in our business through our customer support and just working with customers when we do their pen test, that there will be 5,000 servers out there. Three are misconfigured. Those three misconfigurations will create the open door. Cause remember the hacker only needs to be right once, the defender needs to be right all the time. And that's the challenge. And so that's why I'm really passionate about what we're doing here at Horizon three. I see this my digital transformation, migration and security going on, which we're at the tip of the sp, it's why I joined say Hall coming on this journey and just super excited about where the path's going and super excited about the relationship with Splunk. I get into more details on some of the specifics of that. But you know, >>I mean, well you're nailing, I mean we've been doing a lot of things around super cloud and this next gen environment, we're calling it NextGen. You're really seeing DevOps, obviously Dev SecOps has, has already won the IT role has moved to the developer shift left as an indicator of that. It's one of the many examples, higher velocity code software supply chain. You hear these things. That means that it is now in the developer hands, it is replaced by the new ops, data ops teams and security where there's a lot of horizontal thinking. To your point about access, there's no more perimeter. So >>That there is no perimeter. >>Huge. A hundred percent right, is really right on. I don't think it's one time, you know, to get in there. Once you're in, then you can hang out, move around, move laterally. Big problem. Okay, so we get that. Now, the challenges for these teams as they are transitioning organizationally, how do they figure out what to do? Okay, this is the next step. They already have Splunk, so now they're kind of in transition while protecting for a hundred percent ratio of success. So how would you look at that and describe the challenges? What do they do? What is, what are the teams facing with their data and what's next? What do they, what do they, what action do they take? >>So let's do some vernacular that folks will know. So if I think about dev sec ops, right? We both know what that means, that I'm gonna build security into the app, but no one really talks about SEC DevOps, right? How am I building security around the perimeter of what's going inside my ecosystem and what are they doing? And so if you think about what we're able to do with somebody like Splunk is we could pen test the entire environment from soup to nuts, right? So I'm gonna test the end points through to it. So I'm gonna look for misconfigurations, I'm gonna, and I'm gonna look for credential exposed credentials. You know, I'm gonna look for anything I can in the environment. Again, I'm gonna do it at at light speed. And, and what we're, what we're doing for that SEC dev space is to, you know, did you detect that we were in your environment? >>So did we alert Splunk or the SIM that there's someone in the environment laterally moving around? Did they, more importantly, did they log us into their environment? And when did they detect that log to trigger that log? Did they alert on us? And then finally, most importantly, for every CSO out there is gonna be did they stop us? And so that's how we, we, we do this in, I think you, when speaking with Stay Hall, before, you know, we've come up with this boils U Loop, but we call it fine fix verify. So what we do is we go in is we act as the attacker, right? We act in a production environment. So we're not gonna be, we're a passive attacker, but we will go in un credentialed UN agents. But we have to assume, have an assumed breach model, which means we're gonna put a Docker container in your environment and then we're going to fingerprint the environment. >>So we're gonna go out and do an asset survey. Now that's something that's not something that Splunk does super well, you know, so can Splunk see all the assets, do the same assets marry up? We're gonna log all that data and think then put load that into the Splunk sim or the smoke logging tools just to have it in enterprise, right? That's an immediate future ad that they've got. And then we've got the fix. So once we've completed our pen test, we are then gonna generate a report and we could talk about about these in a little bit later. But the reports will show an executive summary the assets that we found, which would be your asset discovery aspect of that, a fixed report. And the fixed report I think is probably the most important one. It will go down and identify what we did, how we did it, and then how to fix that. >>And then from that, the pen tester or the organization should fix those. Then they go back and run another test. And then they validate through like a change detection environment to see, hey, did those fixes taste, play take place? And you know, SNA Hall, when he was the CTO of JS o, he shared with me a number of times about, he's like, Man, there would be 15 more items on next week's punch sheet that we didn't know about. And it's, and it has to do with how we, you know, how they were prioritizing the CVEs and whatnot because they would take all CVS was critical or non-critical. And it's like we are able to create context in that environment that feeds better information into Splunk and whatnot. That >>Was a lot. That brings, that brings up the, the efficiency for Splunk specifically. The teams out there. By the way, the burnout thing is real. I mean, this whole, I just finished my list and I got 15 more or whatever the list just can, keeps, keeps growing. How did Node zero specifically help Splunk teams be more efficient? Now that's the question I want to get at, because this seems like a very scalable way for Splunk customers and teams, service teams to be more efficient. So the question is, how does Node zero help make Splunk specifically their service teams be more efficient? >>So to, so today in our early interactions with building Splunk customers, what we've seen are five things, and I'll start with sort of identifying the blind spots, right? So kind of what I just talked about with you. Did we detect, did we log, did we alert? Did they stop node zero, right? And so I would, I put that at, you know, a a a more layman's third grade term. And if I was gonna beat a fifth grader at this game would be, we can be the sparring partner for a Splunk enterprise customer, a Splunk essentials customer, someone using Splunk soar, or even just an enterprise Splunk customer that may be a small shop with three people and, and just wants to know where am I exposed. So by creating and generating these reports and then having the API that actually generates the dashboard, they can take all of these events that we've logged and log them in. >>And then where that then comes in is number two is how do we prioritize those logs, right? So how do we create visibility to logs that are, have critical impacts? And again, as I mentioned earlier, not all CVEs are high impact regard and also not all are low, right? So if you daisy chain a bunch of low CVEs together, boom, I've got a mission critical AP CVE that needs to be fixed now, such as a credential moving to an NT box that's got a text file with a bunch of passwords on it, that would be very bad. And then third would be verifying that you have all of the hosts. So one of the things that Splunk's not particularly great at, and they, they themselves, they don't do asset discovery. So do what assets do we see and what are they logging from that? And then for, from, for every event that they are able to identify the, one of the cool things that we can do is actually create this low-code, no-code environment. >>So they could let, you know, float customers can use Splunk. So to actually triage events and prioritize that events or where they're being routed within it to optimize the SOX team time to market or time to triage any given event. Obviously reducing mtr. And then finally, I think one of the neatest things that we'll be seeing us develop is our ability to build glass tables. So behind me you'll see one of our triage events and how we build a lock Lockheed Martin kill chain on that with a glass table, which is very familiar to this Splunk community. We're going to have the ability, not too distant future to allow people to search, observe on those IOCs. And if people aren't familiar with an ioc, it's an incident of compromise. So that's a vector that we want to drill into. And of course who's better at drilling in into data and Splunk. >>Yeah, this is a critical, this is awesome synergy there. I mean I can see a Splunk customer going, Man, this just gives me so much more capability. Action actionability. And also real understanding, and I think this is what I wanna dig into, if you don't mind understanding that critical impact, okay. Is kind of where I see this coming. I got the data, data ingest now data's data. But the question is what not to log, You know, where are things misconfigured? These are critical questions. So can you talk about what it means to understand critical impact? >>Yeah, so I think, you know, going back to those things that I just spoke about, a lot of those CVEs where you'll see low, low, low and then you daisy chain together and you're suddenly like, oh, this is high now. But then to your other impact of like if you're a, if you're a a Splunk customer, you know, and I had, I had several of them, I had one customer that, you know, terabytes of McAfee data being brought in and it was like, all right, there's a lot of other data that you probably also wanna bring, but they could only afford, wanted to do certain data sets because that's, and they didn't know how to prioritize or filter those data sets. And so we provide that opportunity to say, Hey, these are the critical ones to bring in. But there's also the ones that you don't necessarily need to bring in because low CVE in this case really does mean low cve. >>Like an ILO server would be one that, that's the print server where the, your admin credentials are on, on like a, a printer. And so there will be credentials on that. That's something that a hacker might go in to look at. So although the CVE on it is low, if you daisy chain was something that's able to get into that, you might say, ah, that's high. And we would then potentially rank it giving our AI logic to say that's a moderate. So put it on the scale and we prioritize though, versus a, a vulner review scanner's just gonna give you a bunch of CVEs and good luck. >>And translating that if I, if I can and tell me if I'm wrong, that kind of speaks to that whole lateral movement. That's it. Challenge, right? Print server, great example, look stupid low end, who's gonna wanna deal with the print server? Oh, but it's connected into a critical system. There's a path. Is that kind of what you're getting at? >>Yeah, I used daisy chain. I think that's from the community they came from. But it's, it's just a lateral movement. It's exactly what they're doing. And those low level, low critical lateral movements is where the hackers are getting in. Right? So that's what the beauty thing about the, the Uber example is that who would've thought, you know, I've got my multifactor authentication going in a human made a mistake. We can't, we can't not expect humans to make mistakes. Were fall, were fallible, right? Yeah. The reality is is once they were in the environment, they could have protected themselves by running enough pen tests to know that they had certain exposed credentials that would've stopped the breach. Yeah. And they did not, had not done that in their environment. And I'm not poking. Yeah, >>They put it's interesting trend though. I mean it's obvious if sometimes those low end items are also not protected well. So it's easy to get at from a hacker standpoint, but also the people in charge of them can be fished easily or spear fished because they're not paying attention. Cause they don't have to. No one ever told them, Hey, be careful of what you collect. >>Yeah. For the community that I came from, John, that's exactly how they, they would meet you at a, an international event introduce themselves as a graduate student. These are national actor states. Would you mind reviewing my thesis on such and such? And I was at Adobe at the time though I was working on this and start off, you get the pdf, they opened the PDF and whoever that customer was launches, and I don't know if you remember back in like 2002, 2008 time frame, there was a lot of issues around IP being by a nation state being stolen from the United States and that's exactly how they did it. And John, that's >>Or LinkedIn. Hey I wanna get a joke, we wanna hire you double the salary. Oh I'm gonna click on that for sure. You know? Yeah, >>Right. Exactly. Yeah. The one thing I would say to you is like when we look at like sort of, you know, cuz I think we did 10,000 pen test last year is it's probably over that now, you know, we have these sort of top 10 ways that we think then fine people coming into the environment. The funniest thing is that only one of them is a, a CVE related vulnerability. Like, you know, you guys know what they are, right? So it's it, but it's, it's like 2% of the attacks are occurring through the CVEs, but yet there's all that attention spent to that. Yeah. And very little attention spent to this pen testing side. Yeah. Which is sort of this continuous threat, you know, monitoring space and, and, and this vulnerability space where I think we play such an important role and I'm so excited to be a part of the tip of the spear on this one. >>Yeah. I'm old enough to know the movie sneakers, which I love as a, you know, watching that movie, you know, professional hackers are testing, testing, always testing the environment. I love this. I gotta ask you, as we kind of wrap up here, Chris, if you don't mind the benefits to team professional services from this alliance, big news Splunk and you guys work well together. We see that clearly. What are, what other benefits do professional services teams see from the Splunk and Horizon three AI alliance? >>So if you're a, I think for, from our, our, from both of our partners as we bring these guys together and many of them already are the same partner, right? Is that first off, the licensing model is probably one of the key areas that we really excel at. So if you're an end user, you can buy for the enterprise by the enter of IP addresses you're using. But if you're a partner working with this, there's solution ways that you can go in and we'll license as to MSPs and what that business model on our MSPs looks like. But the unique thing that we do here is this c plus license. And so the Consulting Plus license allows like a, somebody a small to midsize to some very large, you know, Fortune 100, you know, consulting firms uses by buying into a license called Consulting Plus where they can have unlimited access to as many ips as they want. >>But you can only run one test at a time. And as you can imagine when we're going and hacking passwords and checking hashes and decrypting hashes, that can take a while. So, but for the right customer, it's, it's a perfect tool. And so I I'm so excited about our ability to go to market with our partners so that we underhand to sell, understand how not to just sell too or not tell just to sell through, but we know how to sell with them as a good vendor partner. I think that that's one thing that we've done a really good job building bringing into market. >>Yeah. I think also the Splunk has had great success how they've enabled partners and professional services. Absolutely. They've, you know, the services that layer on top of Splunk are multifold tons of great benefits. So you guys vector right into that ride, that wave with >>Friction. And, and the cool thing is that in, you know, in one of our reports, which could be totally customized with someone else's logo, we're going to generate, you know, so I, I used to work at another organization, it wasn't Splunk, but we, we did, you know, pen testing as a, as a for, for customers and my pen testers would come on site, they, they do the engagement and they would leave. And then another really, someone would be, oh shoot, we got another sector that was breached and they'd call you back, you know, four weeks later. And so by August our entire pen testings teams would be sold out and it would be like, wow. And in March maybe, and they'd like, No, no, no, I gotta breach now. And, and, and then when they do go in, they go through, do the pen test and they hand over a PDF and they pat you on the back and say, there's where your problems are, you need to fix it. And the reality is, is that what we're gonna generate completely autonomously with no human interaction is we're gonna go and find all the permutations that anything we found and the fix for those permutations and then once you fixed everything, you just go back and run another pen test. Yeah. It's, you know, for what people pay for one pen test, they could have a tool that does that. Every, every pat patch on Tuesday pen test on Wednesday, you know, triage throughout the week, >>Green, yellow, red. I wanted to see colors show me green, green is good, right? Not red. >>And once CIO doesn't want, who doesn't want that dashboard, right? It's, it's, it is exactly it. And we can help bring, I think that, you know, I'm really excited about helping drive this with the Splunk team cuz they get that, they understand that it's the green, yellow, red dashboard and, and how do we help them find more green so that the other guys are >>In Yeah. And get in the data and do the right thing and be efficient with how you use the data, Know what to look at. So many things to pay attention to, you know, the combination of both and then, then go to market strategy. Real brilliant. Congratulations Chris. Thanks for coming on and sharing this news with the detail around this Splunk in action around the alliance. Thanks for sharing, >>John. My pleasure. Thanks. Look forward to seeing you soon. >>All right, great. We'll follow up and do another segment on DevOps and IT and security teams as the new new ops, but, and Super cloud, a bunch of other stuff. So thanks for coming on. And our next segment, the CEO of Verizon, three AA, will break down all the new news for us here on the cube. You're watching the cube, the leader in high tech enterprise coverage.

Published Date : Sep 27 2022

SUMMARY :

I'm John Furrier, host of the Cube. Yeah, like I said, you know, great to meet you John. And boy man, you know, talk about being in the right place at the right time. the security space and in the public sector domain that I was in, you know, security was 70% And I think that the value that we bring to, you know, And so if you think about what node zero and what we're doing in a Horizon three is that, Just give a quick highlight of what happened so you And that's the sort of stuff that we do under, you know, a lot of these tools. Like not, and I'm not, you know, you think about the cacophony of tools that are That means that it is now in the developer hands, So how would you look at that and And so if you think about what we're able to do with before, you know, we've come up with this boils U Loop, but we call it fine fix verify. you know, so can Splunk see all the assets, do the same assets marry up? And you know, SNA Hall, when he was the CTO of JS o, So the question is, And so I would, I put that at, you know, a a a more layman's third grade term. And then third would be verifying that you have all of the hosts. So they could let, you know, float customers can use Splunk. So can you talk about what Yeah, so I think, you know, going back to those things that I just spoke about, a lot of those CVEs So put it on the scale and we prioritize though, versus a, a vulner review scanner's just gonna give you a bunch of Is that kind of what you're getting at? is that who would've thought, you know, I've got my multifactor authentication going in a Hey, be careful of what you collect. time though I was working on this and start off, you get the pdf, they opened the PDF and whoever that customer was Oh I'm gonna click on that for sure. Which is sort of this continuous threat, you know, monitoring space and, services from this alliance, big news Splunk and you guys work well together. And so the Consulting Plus license allows like a, somebody a small to midsize to And as you can imagine when we're going and hacking passwords They've, you know, the services that layer on top of Splunk are multifold And, and the cool thing is that in, you know, in one of our reports, which could be totally customized I wanted to see colors show me green, green is good, And we can help bring, I think that, you know, I'm really excited about helping drive this with the Splunk team cuz So many things to pay attention to, you know, the combination of both and then, then go to market strategy. Look forward to seeing you soon. And our next segment, the CEO of Verizon,

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
ChrisPERSON

0.99+

JohnPERSON

0.99+

Patrick KauflinPERSON

0.99+

2013DATE

0.99+

70%QUANTITY

0.99+

MarchDATE

0.99+

Chris HillPERSON

0.99+

VerizonORGANIZATION

0.99+

2019DATE

0.99+

SplunkORGANIZATION

0.99+

McAfeeORGANIZATION

0.99+

John FurrierPERSON

0.99+

WednesdayDATE

0.99+

UberORGANIZATION

0.99+

six weeksQUANTITY

0.99+

last yearDATE

0.99+

AdobeORGANIZATION

0.99+

three peopleQUANTITY

0.99+

5,000 serversQUANTITY

0.99+

2008DATE

0.99+

2002DATE

0.99+

TuesdayDATE

0.99+

bothQUANTITY

0.99+

Horizons NehaORGANIZATION

0.99+

four weeks laterDATE

0.99+

LinkedInORGANIZATION

0.99+

next weekDATE

0.99+

todayDATE

0.99+

United StatesLOCATION

0.99+

oneQUANTITY

0.99+

AugustDATE

0.99+

firstQUANTITY

0.99+

2012DATE

0.99+

2%QUANTITY

0.98+

thirdQUANTITY

0.98+

one pen testQUANTITY

0.98+

one timeQUANTITY

0.98+

this weekDATE

0.98+

one testQUANTITY

0.98+

hundred percentQUANTITY

0.98+

NextGenORGANIZATION

0.98+

15 more itemsQUANTITY

0.97+

two monthsQUANTITY

0.97+

First timeQUANTITY

0.97+

five thingsQUANTITY

0.96+

SECORGANIZATION

0.96+

one customerQUANTITY

0.96+

Lockheed MartinORGANIZATION

0.96+

15 moreQUANTITY

0.95+

one thingQUANTITY

0.95+

hundred percentQUANTITY

0.95+

Snehal Antani S2 E4 Final


 

>>Hey everyone. Welcome to the Cube's presentation of the AWS startup showcase. Season two, episode four, I'm your host. Lisa Martin. This topic is cybersecurity detect and protect against threats. Very excited to welcome a Cub alumni back to the program. SNA hall, autonomy, the co-founder and CEO of horizon three joins me SNA hall. It's great to have you back in the studio. >>Likewise, thanks for the invite. >>Tell us a little bit about horizon three. What is it that you guys do you we're founded in 2019? Got a really interesting group of folks with interesting backgrounds, but talk to the audience about what it is that you guys are aiming to do. >>Sure. So maybe back to the problem we were trying to solve. So my background, I was a engineer by trade. I was a CIO at G capital CTO at Splunk and helped, helped grows scale that company and then took a break from industry to serve within the department of defense. And in every one of my jobs where I had cyber security in my responsibility, I suffered from the same problem. I had no idea I was secure or that we were fixing the right vulnerabilities or logging the right data in Splunk or that our tools and processes and people worked together well until the bad guys had showed up. And by then it was too late. And what I wanted to do was proactively verify my security posture, make sure that my security tools were actually effective, that my people knew how to respond to a breach before the bad guys were there. And so this whole idea of continuously verifying my security posture through security testing and pen testing became a, a passion project of mine for over a decade. And I, through my time in the DOD found the right group of an early people that had offensive cyber experience that had defensive cyber experience that knew how to build and ship and, and deliver software at scale. And we came together at the end of 2019 to start horizon three. >>Talk to me about the current threat landscape. We've seen so much change in flux in the last couple of years globally. We've seen, you know, the threat actors are just getting more and more sophisticated as is the different types of attacks. What are you seeing kind of horizontally across the threat landscape? >>Yeah. The biggest thing is attackers don't have to hack in using zero days. Like you see in the movies. Often they're able to just log in with valid credentials that they've collected through some mechanism. As an example, if I wanted to compromise a large organization, say United airlines, one of the things that an attacker's gonna go off and do is go to LinkedIn and find all of the employees that work at United airlines. Now you've got, say 7,000 pilots of those pilots. You're gonna figure out quickly that their use varie and passwords or their use varie@leastarefirstnamelastinitialatunited.com. Cool. Now I have 7,000 potential logins and all it takes is one of them to reuse a compromise password for their corporate email. And now you've got an initial user in the system and most likely that initial user has local admin on their laptops. And from there, an attacker can dump credentials and find a path to becoming a domain administrator. >>And what happens oftentimes is security tools. Don't detect this because it looks like valid behavior in the organization. And this is pretty common. This idea of collecting information on an organization or a topic or target using open source intelligence, using a mix of credentialed spraying and kinda low priority or low severity exploitations or misconfigurations to get in. And then from there systematically dumping credentials, reusing those credentials and finding a path towards compromise and almost less than 2% of, of CVEs are actually used in exploits. Most of the time attackers chain together misconfigurations bad product defaults. And so really the threat landscape is attackers don't hack in. They log in and organizations have to focus on getting the basics right and fundamentals right first, before they layer on some magic, easy button that is some security AI tools hoping that that's gonna save their day. And that's what we found systemically across the board. >>So you're finding that across the board, probably pan industry, that, that a lot of companies need to go back to basics. We talk about that a lot when we're talking about security, why do you think that >>Is? I think it's because one, most organizations are barely treading water. When you look at the early rapid adopters of horizon threes, pen testing, product, autonomous pen testing, the early adopters tended to be teams where the it team and the security team were the same person and they were barely treading water. And the hardest part of my job as a CIO was deciding what not to fix because the bottleneck in the security processes, the actual capacity to fix problems. And so fiercely prioritizing issues becomes really important, but the, the tools and the processes don't focus on prioritizing what's exploitable, they prioritize, you know, by some arbitrary score from some arbitrary vulnerability scanner. And so we have as a fundamental breakdown of the small group of folks with the expertise to fix problems, tend to be the most overworked and tend to have the most noise to need to sift through. So they don't even have time to get to the basics. They're just barely treading water doing their day jobs. And they're often sacrificing their nights and weekends. All of us at horizon three were practitioners at one point in our career, we've all been called in on the weekend. So that's why, what we did was fiercely focus on helping customers and users fix problems that truly matter, and allowing them to quickly retack and verify that the problems were truly fixed. >>So when it comes to today's threat landscape, what is it that organizations across the board should really be focused on? >>I think systemically what we see are bad password or credential policies, least access, privileged management type processes, not being well implemented. The domain user tends to be the local admin on the box, no ability to understand what is a valid login versus a, a malicious login. Those are some of the basics that we see systemically. And if you layer that with, it's very easy to say misconfigure vCenter, or misconfigure a piece of Cisco gear, or you're not gonna be installing monitoring and OB observa security observability tools on that. HP integrated lights out server. And so on. What you'll find is that you've got people overworked that don't have the capacity to fix. You have the fundamentals or the basics, not, not well implemented. And you have a whole bunch of blind spots in your security posture, and defenders have to be right. Every time attackers only have to be right once. And so what we have is this asymmetric fight where attackers are very likely to get in. And we see this on the news all the time. >>So, and, and nobody of course wants to be the next headline. Right? Talk to me a little bit about autonomous pen testing as a service, what you guys are delivering and what makes it unique and different than other tools that have been out there as, as you're saying that clearly have >>Gaps. Yeah. So first and foremost was the approach we took in building our product. What we set up front was our primary users should be it administrators, network, engineers, and P. And that, that it intern who in three clicks should have the power of a 20 year pen testing expert. So the whole idea was empower and enable all of the fixers to find, fix in verify their security weaknesses continuously. That was the design goal. Most other security products are designed for security people, but we already know they're they're task saturated. They've got way too many tools under the belt. So first and foremost, we wanted to empower the fixers to fix problems. That truly matter, the second part was we wanted to do that without having to install credentialed agents all over the place or writing your own custom attack scripts, or having to do a bunch of configurations and make sure that it's safe to run against production systems so that you could, you could test your entire attack surface your on-prem, your cloud, your external perimeter. >>And this is where AWS comes in to be very important, especially hybrid customers where you've got a portion of your infrastructure on AWS, a portion on-prem and you use horizon three to be able to attack your complete attack surface. So we can start on Preem and we will find, say the AWS credentials file that was mistakenly saved on a, a share drive, and then reuse that to become admin in the cloud. AWS didn't do anything wrong. The cloud team didn't do anything wrong. A developer happened to share a password or save a password file locally. That's how attackers get in. So we can start from on-prem and show how we can compromise the cloud, start from the cloud and, and, and show how we can compromise. On-prem start from the outside and break in. And we're able to show that complete attack surface at scale for hybrid customers. >>So showing that complete attack surface sort of from the eyes of the attacker, >>That's exactly right, because while blue teams or the defenders have a very specific view of their environment, you have to look at yourself through the eyes of the attacker to understand what are your blind spots? What do do they see that you don't see? And it's actually a discipline that is well entrenched within military culture. And that's also important for us as the company. We're about a third of horizon, three served in us special operations or the intelligence community with the United States, and then do OD writ large. And a lot of that red team mindset view yourself through the eyes of the attacker and this idea of training. Like you fight in building muscle memories. So you know how to react to the real incident when it occurs is just ingrained in how we operate. And we disseminate that culture through all of our customers as well. >>And, and at this point in time, it's, every business needs to assume an attacker's gonna get in >>That's right. There are way too many doors and windows in the organization. Attackers are going to get in, whether it's a single customer that reused their Netflix password for their corporate email, a patch that didn't get applied properly, or a new zero day that just gets published a piece of Cisco software that was misconfigured, you know, not by anything more than it's easy to misconfigure. These complex pieces of technology attackers are going to get in. And what we want to understand as customers is once they're in, what could they do? Could they get to my crown Jewel's data and systems? Could they borrow and prepare for a much more complicated attack down the road? If you assume breach, now you wanna understand what can they get to, how quickly can you detect that breach and what are your ways to stifle their ability to achieve their objectives. And culturally, we would need a shift from talking about how secure I am to how defensible are we. Security is kind of a state, a point in time, state of your organization, defense ability is how quickly you can adapt to the attacker to stifle their ability to achieve their objective >>As things are changing >>Constantly. That's exactly right. >>Yeah. Talk to me about a typical customer engagement. If there's, you mentioned folks treading water, obviously there's the huge cybersecurity skills gap that we've been talking about for a long time. Now that's another factor there, but when you're in customer conversations, who were you talking to? What typically are, what are they coming to you for help? >>Yeah. One big thing is you're not gonna win and, and win a customer by taking 'em out to steak dinners. Not anymore. The way we focus on, on our go to market and our sales motion is cultivating champions. At the end of the proof of concept, our internal measure of successes is that person willing to get a horizon three tattoo. And you do that, not through state dinners, not through cool swag, not through marketing, but by letting your results do the talking. Now, part of those results should not require professional services or consulting it. The whole experience should be self-service frictionless and insightful. And that really is how we've designed the product and designed the entire sales motion. So a prospect will learn or discover about us, whether it's through LinkedIn, through social, through the website, but often because one of their friends or colleagues heard about us saw our result and is advocating on our behalf. >>When we're not in the room from there, they're gonna be able to self-service just log to our product through their LinkedIn ID, their Google ID. They can engage with a salesperson if they want to, they can run a pen test right there on the spot against their home, without any interaction with a sales rep, let those results do the talking, use that as a starting point to engage in a, in a more complicated proof of value. And the whole idea is we don't charge for these. We let our results do the talking. And at the end, after they've run us to find problems they've gone off and fixed those issues. And they've rerun us to verify that what they've fixed was properly fixed, then they're hooked. And we have a hundred percent technical win rate with our prospects when they hit that fine fix verify cycle, which is awesome. And then we get the tattoo for them, at least give them the template. And then we're off to the races >>That it sounds like you're making the process more simple. There's so much complexity behind it, but allowing users to be able to actually test it out themselves in a, in a simplified way is huge. Allowing them to really focus on becoming defensible. >>That's exactly right. And you know, the value is we're all, especially now in security, there's so much hype and so much noise. There's a lot more time being spent, self discovering and researching technologies before you engage in a commercial discussion. And so what we try to do is optimize that entire buying experience around enabling people to discover and research and learn the other part, right. Remember is offensive cyber and ethical hacking. And so on is very mysterious and magical to most defenders. It's such a complicated topic with many nuance tools that they don't have the time to understand or learn. And so if you surface the complexity of all those attacker tools, you're gonna overwhelm a person that is already overwhelmed. So we needed the, the experience to be incredibly simple and, and optimize that fine fix verify aha moment. And once again, be frictionless and be insightful, >>Frictionless and insightful. Excellent. Talk to me about results. You mentioned results. We, we love talking about outcomes. When a customer goes through the, the POC POB that you talked about, what are some of the results that they see that hook them? >>Yeah. The biggest thing is what attackers do today is they will find a low from machine one, plus a low from machine two equals compromised domain. What they're doing is they're chaining together issues across multiple parts of your system or your organization to hone your environment. What attackers don't do is find a critical vulnerability and exploit that single machine it's always a chain is always, always multiple steps in the attack. And so the entire product and experience in actually our underlying tech is around attack pads. Here is the path, the attack path an attacker could have taken. You know, that node zero, our product took here is the proof of exploitation for every step along the way. So, you know, this isn't a false positive, in fact, you can copy and paste the attacker command from the product and rerun it yourself and see it for yourself. >>And then here is exactly what you have to go fix and why it's important to fix. So that path proof impact and fix action is what the entire experience is focused on. And that is the results doing the talking, because remember, these folks are already overwhelmed. They're dealing with a lot of false positives. And if you tell them you've got another critical to fix their immediate reaction is Nope. I don't believe you. This is a false positive. I've seen this plenty of times. That's not important. So you have to in your product experience in sales process and adoption process immediately cut through that defensive or that reflex and its path proof impact. Here's exactly what you fix here are the exact steps to fix it. And then you're off to the races. What I learned at Splunk was you win hearts and minds of your users through amazing experience, product experience, amazing documentation, yes, and a vibrant community of champions. Those are the three ingredients of success, and we've really made that the core of the product. So we win on our documentation. We win on the product experience and we've cultivated pretty awesome community. >>Talk to me about some of those champions. Is there a customer story that you think really articulates the value of no zero and what it is that, that you are doing? Yeah. >>I'll tell you a couple. Actually, I just gave this talk at black hat on war stories from running 10,000 pen tests. And I'll try to be gentle on the vendors that were involved here, but the reality is you gotta be honest and authentic. So a customer, a healthcare organization ran a pen test and they were using a very well known, managed security services provider as their, as their security operations team. And so they initiate the pen test and they were, they wanted to audit their response time of their MSSP. So they run the pen test and we're in and out. The whole pen test runs two hours or less. And in those two hours, the pen test compromises, the domain gets access to a bunch of sensitive data. Laterally, maneuvers rips the entire entire environment apart. It took seven hours for the MSSP to send an email notification to the it director that said, Hey, we think something's suspicious is wow. Seven hours. That's >>A long time >>We were in and out in two, seven hours for notification. And the issue with that healthcare company was they thought they had hired the right MSSP, but they had no way to audit their performance. And so we gave them the, the details and the ammunition to get services credits to hold them accountable and also have a conversation of switching to somebody else. >>That accountability is key, especially when we're talking about the, the threat landscape and how it's evolving day to day. That's >>Exactly right. Accountability of your suppliers or, or your security vendors, accountability of your people and your processes, and not having to wait for the bad guys to show up, to test your posture. That's, what's really important. Another story is interesting. This customer did everything right. It was a banking customer, large environment, and they had Ford net installed as their, as their EDR type platform. And they, they initiate us as a pen test and we're able to get code execution on one of their machines. And from there laterally maneuver to become a domain administrator, which insecurity is a really big deal. So they came back and said, this is absolutely not possible. Ford net should have stopped that from occurring. And it turned out because we showed the path and the proof and the impact Forder net was misconfigured on three machines out of 5,000. And they had no idea. Wow. So it's one of those you wanna don't trust that your tools are working. Don't trust your processes. Verify them, show me we're secure today. Show me we're secured tomorrow. And then show me again, we're secure next week, because my environment's constantly changing. And the, and the adversary always has a vote, >>Right? The, the constant change in flux is, is huge challenge for organizations, but those results clearly speak for themselves. You, you talked about the speed in terms of time, how quickly can a customer deploy your technology, identify and remedy problems in their environment. >>Yeah. You know, this fine fix verify aha moment. If you will. So traditionally a customer would have to maybe run one or two pen tests a year and then they'd go off and fix things. They have no capacity to test them cuz they don't have the internal attack expertise. So they'd wait for the next pen test and figure out that they were still exploitable. Usually this year's pen test results look identical the last years that isn't sustainable. So our customers shift from running one or two pen tests a year to 40 pen tests a month. And they're in this constant loop of finding, fixing and verifying all of the weaknesses in their infrastructure. Remember there's infrastructure, pen testing, which is what we are really good at. And then there's application level pen testing that humans are much better at solving. Okay. So we focus on the infrastructure side, especially at scale, but can you imagine so 40 pen tests a month, they run from the perimeter, the inside from a specific subnet from work from home machines, from the cloud. And they're running these pen tests from many different perspectives to understand what does the attacker see from each of these locations in their organization and how do they systemically fix those issues? And what they look at is how many critical problems were found, how quickly were they fixed? How often do they reoccur? And that third metric is important because you might fix something. But if it shows up again next week, because you've got bad automation, you're not gonna you're in a rat race. So you wanna look at that reoccurrence rate also >>The recurrence rate. What are you most excited about as obviously the threat landscape continues to evolve, but what are you most excited about for the company and what it is that you're able to help organizations across industries achieve in such tumultuous times? Yeah. You >>Know, one of the coolest things is back because I was a customer for many of these products, I, I despised threat intelligence products. I despised them because they were basically generic blog posts maybe delivered as a, as a, as a data feed to my Splunk environment or something. But they're always really generic. Like you may have a problem here. And as a result, they weren't very actionable. So one of the really cool things that we do, it's just part of the product is this concept of, of flares flares that we shoot up. And the idea is not to be, to cause angst or anxiety or panic, but rather we look at threat intelligence and then because all, all the insights we have from your pen test results, we connect those two together and say your VMware horizon instance at this IP is exploitable. You need to fix it as fast as possible or as very likely to be exploited. >>And here is the threat intelligence and in the news from CSUN elsewhere, that shows why it's important. So I think what is really cool is we're able to take together threat intelligence out in the wild combined with very precise understanding of your environment, to give you very accurate and actionable starting points for what you need to go fix or test or verify. And when we do that, what we see is almost like, imagine this ball bouncing, that is the first drop of the ball. And then that drives the first major pen test. And then they'll run all these subsequent pen tests to continue to find and fix and verify. And so what we see is this tremendous amount of AC excitement from customers that we're actually giving them accurate, detailed information to take advantage of, and we're not causing panic and we're not causing alert, fatigue as a result. >>That's incredibly important in this type of environment. Last question for you. If, if autonomous pen testing is obviously critical and has tremendous amount of potential for organizations, but it's not, it's only part of the equation. What's the larger vision. >>Yeah. You know, we are not a pen testing company and that's something we decided upfront. Pen testing is a sensor. It collects and understands a tremendous amount of data for your attack surface. So the natural next thing is to analyze the pen test results over time, to start to give you a more accurate understanding of your governance risk and compliance posture. So now what happens is we are able to allow customers to go run 40 pen tests a month. And that kind of becomes the, the initial land or flagship product. But then from there we're able to upsell or increase value to our customers and start to compete and take out companies like security scorecard or risk IQ and other companies like that, where there tended to be. I was a user of all those tools, a lot of garbage in garbage out, okay, where you can't fill out a spreadsheet and get an accurate understanding of your risk posture. You need to look at your detailed pen, test results over time and use that to accurately understand what are your hotspots, what's your recurrence rate and so on. And being able to tell that story to your auditors, to your regulators, to the board. And actually it gives you a much more accurate way to show return on investment of your security spend also, which >>Is huge. So where can customers and, and those that are interested go to learn more. >>So horizon three.ai is the website. That's a great starting point. We tend to very much rely on social channels. So LinkedIn in particular to really get our stories out there. So finding us on LinkedIn is probably the next best thing to go do. And we're always at the major trade shows and events also. >>Excellent SNA. It's been a pleasure talking to you about horizon three. What it is that you guys are doing, why and the greater vision we appreciate your insights and your time. >>Thank you, likewise. >>All right. For my guest. I'm Lisa Martin. We wanna thank you for watching the AWS startup showcase. We'll see you next time.

Published Date : Aug 19 2022

SUMMARY :

It's great to have you back in the studio. What is it that you guys do you we're founded in 2019? that my people knew how to respond to a breach before the bad guys were there. Talk to me about the current threat landscape. And now you've got an initial user in the system and And so really the threat landscape is attackers don't hack in. that, that a lot of companies need to go back to basics. And so we have as a fundamental breakdown of the small group of folks with the expertise And you have a whole bunch of blind spots in your security posture, and defenders testing as a service, what you guys are delivering and what makes it unique and different and make sure that it's safe to run against production systems so that you could, you could test your entire attack surface three to be able to attack your complete attack surface. And a lot of that red team mindset And culturally, we would need a shift from talking That's exactly right. What typically are, what are they coming to you for help? And you And at the end, after they've run us to find problems Allowing them to really focus on becoming defensible. And so if you surface the complexity of all those attacker tools, you're gonna overwhelm a POB that you talked about, what are some of the results that they see that hook them? And so the entire product and experience in actually our underlying tech is And then here is exactly what you have to go fix and why it's important to fix. Talk to me about some of those champions. And I'll try to be gentle on the vendors that were involved here, but the reality is you gotta be honest and the details and the ammunition to get services credits to hold them accountable and also to day. And from there laterally maneuver to become You, you talked about the speed And that third metric is important because you might fix something. to evolve, but what are you most excited about for the company and what it is that you're able to help organizations across And the idea is not to be, And here is the threat intelligence and in the news from CSUN elsewhere, that shows why it's important. but it's not, it's only part of the equation. And being able to tell that story to your auditors, to your regulators, to the board. So where can customers and, and those that are interested go to learn more. So LinkedIn in particular to really get our stories out there. It's been a pleasure talking to you about horizon three. We wanna thank you for watching the AWS startup showcase.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Lisa MartinPERSON

0.99+

two hoursQUANTITY

0.99+

2019DATE

0.99+

twoQUANTITY

0.99+

AWSORGANIZATION

0.99+

Seven hoursQUANTITY

0.99+

oneQUANTITY

0.99+

HPORGANIZATION

0.99+

seven hourQUANTITY

0.99+

tomorrowDATE

0.99+

next weekDATE

0.99+

LinkedInORGANIZATION

0.99+

CiscoORGANIZATION

0.99+

CSUNORGANIZATION

0.99+

20 yearQUANTITY

0.99+

NetflixORGANIZATION

0.99+

SplunkORGANIZATION

0.99+

zero daysQUANTITY

0.99+

5,000QUANTITY

0.99+

second partQUANTITY

0.99+

firstQUANTITY

0.99+

United airlinesORGANIZATION

0.99+

first dropQUANTITY

0.99+

third metricQUANTITY

0.99+

7,000 pilotsQUANTITY

0.98+

todayDATE

0.98+

this yearDATE

0.98+

Ford netORGANIZATION

0.98+

hundred percentQUANTITY

0.98+

three machinesQUANTITY

0.98+

one pointQUANTITY

0.97+

seven hoursQUANTITY

0.97+

three clicksQUANTITY

0.97+

three ingredientsQUANTITY

0.97+

single machineQUANTITY

0.97+

eachQUANTITY

0.97+

varie@leastarefirstnamelastinitialatunited.comOTHER

0.96+

end of 2019DATE

0.96+

CubORGANIZATION

0.96+

40 penQUANTITY

0.96+

DODORGANIZATION

0.96+

threeQUANTITY

0.95+

less than 2%QUANTITY

0.95+

single customerQUANTITY

0.95+

Forder netORGANIZATION

0.95+

G capital CTOORGANIZATION

0.95+

last yearsDATE

0.94+

two pen testsQUANTITY

0.94+

7,000 potential loginsQUANTITY

0.93+

Snehal AntaniPERSON

0.92+

zero dayQUANTITY

0.91+

40 pen testsQUANTITY

0.9+

horizon threeTITLE

0.89+

United StatesLOCATION

0.88+

horizonORGANIZATION

0.87+

last couple of yearsDATE

0.87+

SNA hallORGANIZATION

0.86+

a yearQUANTITY

0.86+

40 pen tests a monthQUANTITY

0.86+

machine twoQUANTITY

0.85+

10,000 pen testsQUANTITY

0.84+

over a decadeQUANTITY

0.84+

machine oneQUANTITY

0.82+

a monthQUANTITY

0.81+

CubePERSON

0.76+

episode fourOTHER

0.75+

S2COMMERCIAL_ITEM

0.74+

onceQUANTITY

0.73+

Chris Lynch, Tech Tackles Cancer


 

(bright music) >> You know, there's a lot of negative press around the technology industry these days. The tech lash is somewhat understandable, people are struggling and yet the tech industry is booming, creating incredible wealth for a relatively select group of people. I get it. But the reality is, that the technology industry has guided us through the pandemic, allowing us to work remotely, securing our employees, keeping goods and services flowing, and using data and analytics to track COVID and accelerate the development of vaccines. And many in the tech industry are passionate about giving back and applying their talents to solve real world problems. I'll give you an example. After accidents, cancer is the number one cause of death among young people. In the middle of the 20th century, the survival rate for kids with cancer was 0.0%. Today, it's above 85%. Cancer in kids is much different than in adults. The types of cancer, the diagnoses, the treatments, they vary. Different types of research are required to attack the problem. And that takes money. And one of the people here in Boston and beyond that's using his talents, his creativity, his network, and yeah, his wealth, to attack this problem, is my friend, Chris Lynch, entrepreneur, investor, and philanthropist. Chris, awesome to see ya. Welcome back to theCUBE my friend. >> Thanks, Dave. It's great to be here. >> So, listen, this personal story of yours, how'd you get into, where's the passion come from for kids with cancer? >> Dave, it's actually related to one of my startup endeavors. When you're starting, bootstrapping your company, you're typically staying at people's homes to save money. >> Sleeping on couches. Yeah. >> Yeah, yeah. Pretty much. And for the years of these startups, I've developed relationships with families all over the world, 'cause I've literally lived with them for periods of time until the companies got to points where we didn't have to do that. And there was a family in Seattle that I used to stay with, and they had a son that was a similar age to one of mine and he ultimately passed of cancer. And I stayed with the family, and I stayed with them a few times while they were going through this, and I was touched, I was inspired by their courage, how positive they were. I was thinking in my own circumstance, how could I, I would just hate the world. And in these families, I stay there, they call me Uncle Chris. And I was having dinner at the family home and I was looking at the boy, and I excused myself, went to the bathroom and I started sobbing, and he knocks on the door, comes in and says, "Uncle Chris, it's okay. My dad tells me you can do anything. Just do whatever you can so that other kids don't have what I have." You know and... >> Wow. Wow. And I can see the emotion that you're feeling right now, bringing us back to that moment. >> Well. Yeah. >> It's unbelievable. All right, so you got Tech Tackles Cancer. Is this your latest venture? I think the last one was 2018. It's coming back, took a break 'cause of COVID, and this is going to go down on the 21st at The Sinclair in Harvard Square. Bring a bunch of people in. We got a number of people who have signed up to, actually you're one of them, of course, but to sing karaoke, raise a bunch of dough, and then there's like a little contest, right? So... (he chuckles) Alex, bring up that slide. I got to show the audience who we got here. And this is, Chris, this is your competition. So, here you go. We got, Steve Duplessie, right? That's a great picture, Steve. Thanks for doing this, right. Nathan Hall, who's at Pure Storage. Steiny, Ken Steinhardt, from INFINIDAT. And you got George Hope at HPE. And Joe Lemay, who's an inventor, he's the CEO of Rocketbook. Any of these guys worry you? >> I'm going to sleep easy tonight. (Dave laughs) >> So, how did you get into rock and roll? You wrote a blog one time. You quoted Nietzsche saying that life without music would be a mistake. Rock and roll. Rock on. How'd you get into rock and what's your passion there? >> Well, I always loved rock and roll but I had someone that was staying with us who was a student at BU, and he went to his semester abroad, he went to the UK. And he came back with all this punk rock music, the Sex Pistols and all this stuff. And I heard it and it just triggered something in me. And then I didn't want to do anything but play music and try to be a musician, and my grades and everything else suffered as a result. But music's always inspired me, the creativity, the boldness. A lot of things that I think I apply to my startup life. >> How could people help? Let's say they want to get involved. I mean, obviously, they can attend the event, they donate. What should people do? They could sing? >> Yeah. So they can certainly sponsor the event. There are a number of sponsorship opportunities. They can participate. They can volunteer for the event. It is an all-volunteer organization. Every dollar that we raise goes to the charities that we've listed. And we handle everything else through a lot of arm twisting and whatnot. >> Great. So it's June 24th, sorry, June 21st, at The Sinclair, which is right in Harvard Square. So it's live band karaoke, right? >> Correct. >> I've seen some of the, we're going to share a little clip there. And so, it's a call to action to all you rock and roll technology gods out there. You know, we showed you the five folks plus Chris who were doing it, and so we're dying to see you up there again, you must be really excited about it. >> I am, I am. I'm going to be much better than last time. >> Okay. Well, so just on that note we'll close with a little taste of what's in store for June 21st. We'll see you there. ♪ Now my loneliness ♪ ♪ Is killing me now ♪ ♪ You know I still believe ♪ ♪ Midnight, midnight to six ♪ ♪ Midnight, midnight to six ♪ ♪ Midnight, midnight to six ♪ ♪ Believe in things that you don't understand ♪ ♪ then you're su... ♪ (bright music)

Published Date : Apr 13 2022

SUMMARY :

and accelerate the to one of my startup endeavors. Yeah. and he knocks on the And I can see the emotion and this is going to go down on the 21st I'm going to sleep easy tonight. So, how did you get into rock and roll? I apply to my startup life. attend the event, they donate. certainly sponsor the event. So it's live band karaoke, And so, it's a call to action to all you I'm going to be much ♪ Midnight, midnight to six ♪

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Joe LemayPERSON

0.99+

Ken SteinhardtPERSON

0.99+

Steve DuplessiePERSON

0.99+

ChrisPERSON

0.99+

Nathan HallPERSON

0.99+

DavePERSON

0.99+

SeattleLOCATION

0.99+

StevePERSON

0.99+

BostonLOCATION

0.99+

Chris LynchPERSON

0.99+

June 21stDATE

0.99+

George HopePERSON

0.99+

June 24thDATE

0.99+

SteinyPERSON

0.99+

2018DATE

0.99+

Harvard SquareLOCATION

0.99+

UKLOCATION

0.99+

AlexPERSON

0.99+

0.0%QUANTITY

0.99+

NietzschePERSON

0.99+

pandemicEVENT

0.99+

five folksQUANTITY

0.99+

TodayDATE

0.99+

HPEORGANIZATION

0.98+

oneQUANTITY

0.98+

RocketbookORGANIZATION

0.98+

above 85%QUANTITY

0.97+

Tech Tackles CancerORGANIZATION

0.96+

COVIDOTHER

0.95+

21stQUANTITY

0.94+

tonightDATE

0.94+

one timeQUANTITY

0.92+

Pure StorageORGANIZATION

0.92+

INFINIDATORGANIZATION

0.9+

MidnightDATE

0.87+

midnightDATE

0.85+

SinclairLOCATION

0.81+

endeavorsQUANTITY

0.75+

Every dollarQUANTITY

0.73+

sixDATE

0.72+

middle of the 20th centuryDATE

0.7+

CancerCOMMERCIAL_ITEM

0.66+

Sex PistolsORGANIZATION

0.6+

Tech TacklesORGANIZATION

0.58+

theCUBEORGANIZATION

0.48+

Josh Epstein, Tech Tackles Cancer


 

(upbeat music) >> On June 21st in Cambridge mass at the Sinclair in Harvard Square, Tech Tackles Cancer is back after a COVID hiatus with live band karaoke and some local tech celebrities raising money for a great cause. The Cube is a media sponsor of the event and Josh Epstein, local marketing exec and one of the events organizers is here to tell us more. Josh, good to see you, welcome. >> Good to be here, Dave. >> So tell us about this event. What's going on? What are the logistics? How's that all work? >> Yeah, we're super excited. So as you said, June 21st at the Sinclair in Harvard Square, Sinclair, if you haven't been there is just the great old school rock club. So we'll be there from 6:00 to 10:00. We will have live band karaoke. So the main event and kind of the primary fundraising approach here is that we have some celebrity technology rock gods these featured performers like Chris Lynch who was the founder of Tech Tackles Cancer, who are are raising money from basically now, up until June 21st. Then at the event, their fundraising will culminate with them singing a live song backed by a live band. And the awards will be given out to the most money raised, the best performance and the best stage presence. So it will be a lot of fun. >> So the fundraising format is I sign up to sing do the karaoke with a live band which is a little bit different. And then I raise as much dough as possible. So obviously that's competitive. >> It's competitive, I think that we ask for a minimum of $10,000 targeted for each of the fundraisers but knowing these guys, knowing guys like Chris Lynch, they don't like to lose. So the bet here is that people are going to go out, they're going to hit their network and they are going to look to kind of raise the most money. So we anticipate this to be a great event with a lot of money raised and a lot of fun. >> So we have a graphic from Alex. If you could bring that up of the people who have signed up for this already. We got Steve Duplessie, founder of of ESG, senior analyst. They sold their company to Tech Target, which is awesome. Congratulations to those guys and thank you for stepping up. George Hope, who heads partner sales for HPE, Joe Lemay of Rocketbook Nathan Hall from Pure Storage, system engineering guy and of course, Steiny, Ken Steinhardt from Infinidat. He was at EMC, he's the field CTO now. He's going to be up there singing. So of course, Chris. >> Absolutely, these are just the early entrance here. So we just started really working our networks. And obviously, I'm a Boston tech guy kind of working the storage networks, the networking networks and kind of the other folks that are around. So as we come out of stealth here in April and start really recruiting, we anticipate having probably 10 to 15 of these featured performers, really fundraising performers that we'll sing. And then we're also obviously soliciting broader donations from anyone who wants to come to the event or just give to the cause and the corporate sponsorships as well. >> All right, so you got corporate sponsorships. You can sing, you can donate you can be there just to support it. That's fantastic and the awards, how's that work? >> Yeah, so we're excited. So first off, most money raised wins an award. So we'll have a leaderboard on the website, we'll be able to kind of track who's raised what, at the event, we're going to have some celebrity judges that will be actually voting for their favorites and then have a crowdsource component as well. So we'll introduce what that mechanism is. But as people, either at the events or a watching in streamed live on LinkedIn live, we'll actually vote for their favorite performance as well as their their pick for best stage presence which we know in rock and roll is half the battle. >> Now this cause has raised a bunch of, I think last time, you guys did this, it was probably a quarter million or close to it and you support multiple causes. What causes are you supporting? >> Sure, yeah, actually I think since they founded the event several years ago they raised over $2 million. This year for this format where we're looking, we can really up our game here but this year we're supporting two really great causes that are both focused on pediatric cancer. The first is St. Batrick's that is really committed to raising funds for research to really help stamp out pediatric cancer really. The approach to researching cures and treatments to pediatric cancer is very different from regular adult cancer. So St. Batrick's does a great job of picking those research projects that really target in on those pediatric cancer causes. And then the second is one mission. And one mission really outlooks to help make pediatric cancer patients that are spending time in the hospital, making their time less stressful, less painful, less sad, less boring. And so they do a lot of fundraising and contributions targeting children's hospitals, really around the country for those pediatric cancer floors. >> Josh, amazing cause. Thanks so much for coming onto the Cube and explaining all that. >> Great, thanks David. >> All right, June 21st, go to ttcfund.org, Tech Tackles Cancer fund, ttcffund.org for more information and you can donate. We'll see you there. (soft music)

Published Date : Apr 6 2022

SUMMARY :

and one of the events organizers What are the logistics? and kind of the primary So the fundraising So the bet here is that So of course, Chris. and kind of the other That's fantastic and the at the event, we're going to or close to it and you really around the country for Thanks so much for coming onto the Cube go to ttcfund.org, Tech Tackles

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
DavidPERSON

0.99+

Steve DuplessiePERSON

0.99+

Ken SteinhardtPERSON

0.99+

Joe LemayPERSON

0.99+

George HopePERSON

0.99+

Josh EpsteinPERSON

0.99+

JoshPERSON

0.99+

SteinyPERSON

0.99+

ChrisPERSON

0.99+

Chris LynchPERSON

0.99+

June 21stDATE

0.99+

AprilDATE

0.99+

Harvard SquareLOCATION

0.99+

twoQUANTITY

0.99+

ttcfund.orgOTHER

0.99+

AlexPERSON

0.99+

10QUANTITY

0.99+

over $2 millionQUANTITY

0.99+

ESGORGANIZATION

0.99+

BostonLOCATION

0.99+

Tech Tackles CancerORGANIZATION

0.99+

ttcffund.orgOTHER

0.99+

one missionQUANTITY

0.99+

this yearDATE

0.99+

EMCORGANIZATION

0.99+

Tech TargetORGANIZATION

0.99+

DavePERSON

0.99+

several years agoDATE

0.99+

firstQUANTITY

0.99+

$10,000QUANTITY

0.99+

10:00DATE

0.99+

6:00DATE

0.99+

15QUANTITY

0.99+

Pure StorageORGANIZATION

0.98+

bothQUANTITY

0.98+

InfinidatORGANIZATION

0.98+

This yearDATE

0.98+

secondQUANTITY

0.98+

HPEORGANIZATION

0.98+

RocketbookORGANIZATION

0.98+

eachQUANTITY

0.97+

SinclairLOCATION

0.96+

CambridgeLOCATION

0.96+

Nathan HallPERSON

0.94+

LinkedInORGANIZATION

0.9+

quarter millionQUANTITY

0.9+

St. Batrick'sORGANIZATION

0.88+

Tech Tackles Cancer fundOTHER

0.88+

great causesQUANTITY

0.87+

St. BatrickORGANIZATION

0.83+

one of the eventsQUANTITY

0.78+

COVIDEVENT

0.6+

CubeORGANIZATION

0.57+

Andrea Hall & Andrew Block, Red Hat | Managing Risk In The Digital Supply Chain


 

(upbeat music) >> Okay, we're here talking about how you can better understand and manage the risks associated with the digital supply chain. How in this day and age where software comes from so many different places and sources throughout the ecosystem, how can organizations manage the risks associated with our dependence on software? And with me now are two great guests, Andrea Hall, who is a specialist solution architect and project manager for security and compliance at Red Hat. She's going to focus on public sector. And Andrew Block who's a distinguished architect at Red Hat Consulting, folks welcome. >> Welcome >> Thank you. Thanks for having us. >> You're very welcome. Andrea, let's start with you. Let's talk about regulations. What exists today that we should be aware of that organizations should be paying attention to? >> Oh sure, so the thing that comes to mind first being in the US is the presidential executive order on cybersecurity that came out a few months ago. Organizations are really paying attention to that. And in the US, it's having a ripple effect with policy, but we're also seeing policy considerations pop up in other countries, Australia and England. The supply chain is a big focus right now, of course, but we see these changes coming down the road as more and more government organizations are trying to secure their critical infrastructure. >> Is there kind of a leadership, or probably in other words, is somebody saying seeing what the UK does and say, okay, we're going to follow that template? Or is it just a variety and a mish mash with no sort of consolidation? How is that sort of playing out? >> I see a lot of organizations kind of basing their requirements on (indistinct) However, each organization has its own nuances. Each agency has its own nuances to how it wants them implemented. >> Andrew, maybe you could chime in here. What are you seeing when you talk to customers that are tuned into this issue? >> You know, as Andrea had just mentioned having that north star in terms of regulations is so fundamentally great for them because many of them especially in regulate industries, look to these regulations on how they apply their own policies. So at least it has some guidance on how to move forward because as we all know the secure software supply chain is getting news every day and how they react to it is something that I know all their leaders are asking themselves, especially those IT leaders. >> Andrea, when I talk to practitioners, sometimes they're frustrated. They understand they have to comply. They know new regulations are coming out, but sometimes it's hard for them to keep up. It would be helpful if you're sitting across the table from somebody who's frustrated and they ask you, what are your expectations? What are the trends in regulations? How do you see the current regulations evolving to specifically accommodate the digital supply chain and the security exposures and corollary requirements there? >> We see a lot of organizations struggling in the sense of trying to understand what the policy actually wants. Definitions are still a little bit vague, but implementation is also difficult because sometimes organizations will add more tools to their toolkit, adding a layer of complexity there. Really automation has to be pulled in. That's key to implementing this instead of adding more workload and more burden to your folks. It's really important for these organizations to pull stakeholders in the organization together. So the IT leaders bring together the developers, the security operations sit at the same table, talk about whether or not what needs to be implemented or what's proposed to be implemented, will affect the mission or in any way or disrupt operations. It's important for everybody to be on the same page so it doesn't slow anything down as you're trying to roll it out. >> And one of the things here is that we're seeing a lot of change with these new regulations and with a lot of organizations, any type of change is scary. And that is one area that they're looking for guidance not only in the tooling, but also how they apply it in the organization. >> I'll add on. >> Please. >> I'll add onto that and say, organizations really need to take into account the people side of things too. People need to understand what the impact is to the organization, so that they don't try to find the loopholes, they're buying into what needs to be done. They understand the why behind it. You for example, if you walk into your house, you normally close the door behind you. Security needs to be seen as that, as well, that's the culture and it's the habit. And it's ingrained in the fabric of the organization to live this way, not just implement the tools to do it. >> Right, and the number of doors you have in your infrastructure are a lot more than just a couple. Andrew mentioned sort of guidance and governments are obviously taking a more active role. I mean, sometimes I'm a cynic. I mean, the president Biden signs an executive order, but swipe of a pen doesn't really give us enough to go on. Do you think Andrea, that we're going to see new guidance from governments in the very near future? What are you expecting? >> I expect to see more conversations happening. I know that agencies who developed the policies are pulling together stakeholders and getting input. But I do see in the not too distant future, that mandates will be rolling out, yes. >> Well, so Andrew of course, Andrea, if you have a thought on this as well, but how do you see organizations dealing with adopting these new policies. >> Slowly, don't boil the ocean is one thing I tell a lot to every one of them, because a lot of these tooling, a lot of these concepts are foreign to them, brand new. How they adopt those and how they implement them, needs to be done in a very agile fashion, very slow and prescriptive. Go ahead and try to find one area of improvement and go ahead and work upon it and build upon it. Because not only does that normally make your organization more successful and secure, but also helps your organization just from a more out standpoint. One thing that you need to emphasize is that don't blame anyone. 'Cause a lot of times when you're going through this, you're reassessing your own supply chain. You might find where you could see improvements that need to be done. Don't blame things that may have occurred in the past. See how you can benefit from these lessons learned in the future. >> It's interesting you say that the blame game, I mean it used to be that failure meant you get fired and that's obviously has changed. As many have said, you know you're going to have incidents. It's how you respond to those incidents. What you learn from them. Do you have Andrew, any insights from specifically working with customers on securing their software supply chain? What can you tell us about what leading practitioners are doing today? >> They're going in and not only assessing what their software components consist of. Using tools like an SBOM, a software bill of materials, understand where all the components of their ecosystem and their lineage comes from. We're hearing almost every single day, new vulnerabilities that are being introduced in various software packages. By having that understanding of what is in your ecosystem, you can then better understand how to mitigate those concerns moving forward. >> Andrea, Andrew was just saying, one of the things is you don't just dive in. You've got to be careful. There's going to be ripple effects is what I'm inferring, but at the same time, there's a mandate to move quickly. Are there things that could accelerate the adoption of regulation or even the creation of regulations and that guidance in your view? What could accelerate this? >> As far as accelerating it goes, I think it's having those conversations proactively with the stakeholders in your organization and understanding the environment like Andrew said. Go ahead and get that baseline. And just know that whatever changes you make are maybe going to be audited down the road, because as we were moving towards this kind of third-party verification, that you're actually implementing things in order to do business with another organization. The importance of that, if organizations see that gravity to this, I think they will try to speed things up. I think that if organizations and the people in those organizations understand that why, that I talked about earlier and they understand how things like solar winds or things like the oil disruption that happened earlier this year. The personal effect to cyber events will help your organization move forward. Again, everybody's bought into the concept, everybody's working towards the same goals and they understand that why behind it. >> In addition to that, having tooling available, that makes it easy for them. You have a lot of individuals who this is all foreign, providing that base level tooling that aligns to a lot of the regulations that might be applicable within their real realm and their domain, makes it easier for them to start to complying and taking less burden off of them to be able to be successful. >> So it's a hard problem because Andrew, how do you deal with sort of the comment more tools, okay. But I look at that the Optiv map, if you've seen that. It makes your eyes cross. You've got so many tools, so much fragmentation, you're introducing new tools. Can automation help that? Is there hope for consolidation of that tools portfolio? >> Right now, this space is very emerging. It's very emerging, it's very fluid to be honest, 'cause there is actually mandates only a year or two old. But as they come over the course of time, however, I do see these types of tooling starting to consolidate where right now it seems like every vendor has a tool that tries to address this. It's being able to have the people work together, have more regulations that will come out that will allow us to start to redefine and solidify on certain tools like ISO standards. There are certain ones that I mentioned on as balance previously, there's now a ISO standard on SBOM there wasn't previously. So as more and more of these regulations come out, it makes it easier to provide that recommended set of tooling that organizations can start leveraging instead of vendor A, vendor B. >> Andrea, I said this before I was a cynic, but will give you the last word, give us some hope. I mean, obviously public policy is very important. A partnership between governments and industry, both the practitioners, the organizations that are buying these tools, as well as the technology industry got to work together in an ecosystem. Give us some hope. >> The hope I think will come from realizing that as you're doing this, as you are implementing these changes, you're in a sense trying to prevent those future incidents from happening. There's some assurance that you're doing everything that you can do here. It's a situation, it can be daunting, I'll put it that way. It can be really daunting for organizations, but just know that organizations like Red Hat are doing what we can to help you down the road. >> And really it's just continuing this whole shifting left mentality. The top of supply chain is just one component, but the introducing dev sec ops security at the beginning, that really will make the organizations become successful because this is not just a technology problem, It's a people issue as well. And being able to kind of package them all up together will help organizations as a whole. >> Yeah, so that's a really important point. You hear that term shift left. For years, people say, hey, you can't just bolt security on, as an afterthought, that's problematic. And that's the answer to that problem, right? Is shifting left meaning designing it in at the point of code, infrastructure as code, dev sec ops. That's where it starts, right? >> Exactly, being able to have security at the forefront and then have everything afterwards. Propagate from your security mindset. >> Excellent, okay, Andrea, Andrew, thanks so much for coming to the program today. >> Thank you for having us. >> Very welcome, thanks for watching. This is Dave Vellante for The Cube. Your a global leader in enterprise tech coverage. (soft music)

Published Date : Feb 15 2022

SUMMARY :

how can organizations manage the risks Thanks for having us. that organizations should that comes to mind first to how it wants them implemented. What are you seeing when and how they react to it is something What are the trends in regulations? more burden to your folks. And one of the things fabric of the organization from governments in the very near future? But I do see in the but how do you see organizations dealing that need to be done. say that the blame game, how to mitigate those of regulations and that if organizations see that gravity to this, to be able to be successful. But I look at that the Optiv have more regulations that will come out but will give you the last that you can do here. And being able to kind of And that's the answer have security at the forefront to the program today. This is Dave Vellante for The Cube.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
AndreaPERSON

0.99+

AndrewPERSON

0.99+

Andrew BlockPERSON

0.99+

Dave VellantePERSON

0.99+

Andrea HallPERSON

0.99+

Red HatORGANIZATION

0.99+

USLOCATION

0.99+

oneQUANTITY

0.99+

Red Hat ConsultingORGANIZATION

0.99+

todayDATE

0.99+

a yearQUANTITY

0.99+

EnglandLOCATION

0.98+

twoQUANTITY

0.98+

one componentQUANTITY

0.98+

AustraliaLOCATION

0.98+

bothQUANTITY

0.98+

each organizationQUANTITY

0.97+

Each agencyQUANTITY

0.97+

firstQUANTITY

0.97+

BidenPERSON

0.96+

One thingQUANTITY

0.96+

one areaQUANTITY

0.96+

two great guestsQUANTITY

0.94+

SBOMORGANIZATION

0.94+

one thingQUANTITY

0.91+

earlier this yearDATE

0.88+

few months agoDATE

0.88+

The CubeORGANIZATION

0.81+

UKORGANIZATION

0.72+

single dayQUANTITY

0.72+

yearsQUANTITY

0.72+

presidentPERSON

0.64+

coupleQUANTITY

0.63+

SBOMTITLE

0.54+

OptivORGANIZATION

0.5+

ISOTITLE

0.43+

Andrea Hall & Andrew Block, Red Hat V2


 

(upbeat music) >> Okay, we're here talking about how you can better understand and manage the risks associated with the digital supply chain. How in this day and age where software comes from so many different places and sources throughout the ecosystem, how can organizations manage the risks associated with our dependence on software? And with me now are two great guests, Andrea Hall, who is a specialist solution architect and project manager for security and compliance at Red Hat. She's going to focus on public sector. And Andrew Block who's a distinguished architect at Red Hat Consulting, folks welcome. >> Welcome >> Thank you. Thanks for having us. >> You're very welcome. Andrea, let's start with you. Let's talk about regulations. What exists today that we should be aware of that organizations should be paying attention to? >> Oh sure, so the thing that comes to mind first being in the US is the presidential executive order on cybersecurity that came out a few months ago. Organizations are really paying attention to that. And in the US, it's having a ripple effect with policy, but we're also seeing policy considerations pop up in other countries, Australia and England. The supply chain is a big focus right now, of course, but we see these changes coming down the road as more and more government organizations are trying to secure their critical infrastructure. >> Is there kind of a leadership, or probably in other words, is somebody saying seeing what the UK does and say, okay, we're going to follow that template? Or is it just a variety and a mish mash with no sort of consolidation? How is that sort of playing out? >> I see a lot of organizations kind of basing their requirements on (indistinct) However, each organization has its own nuances. Each agency has its own nuances to how it wants them implemented. >> Andrew, maybe you could chime in here. What are you seeing when you talk to customers that are tuned into this issue? >> No as Andrea had just mentioned having that north star in terms of regulations is so fundamentally great for them because many of them especially in regulate industries, look to these regulations on how they apply their own policies. So at least it has some guidance on how to move forward because as we all know the secure software supply chain is getting news every day and how they react to it is something that I know all their leaders are asking themselves, especially those IT leaders. >> Andrea, when I talk to practitioners, sometimes they're frustrated. They understand they have to comply. They know new regulations are coming out, but sometimes it's hard for them to keep up. It would be helpful if you're sitting across the table from somebody who's frustrated and they ask you, what are your expectations? What are the trends in regulations? How do you see the current regulations evolving to specifically accommodate the digital supply chain and the security exposures and corollary requirements there? >> We see a lot of organizations struggling in the sense of trying to understand what the policy actually wants. Definitions are still a little bit vague, but implementation is also difficult because sometimes organizations will add more tools to their toolkit, adding a layer of complexity there. Really automation has to be pulled in. That's key to implementing this instead of adding more workload and more burden to your folks. It's really important for these organizations to pull stakeholders in the organization together. So the IT leaders bring together the developers, the security operations sit at the same table, talk about whether or not what needs to be implemented or what's proposed to be implemented, will affect the mission or in any way or disrupt operations. It's important for everybody to be on the same page so it doesn't slow anything down as you're trying to roll it out. >> And one of the things here is that we're seeing a lot of change with these new regulations and with a lot of organizations, any type of change is scary. And that is one area that they're looking for guidance not only in the tooling, but also how they apply it in the organization. >> I'll add on. >> Please. >> I'll add onto that and say, organizations really need to take into account the people side of things too. People need to understand what the impact is to the organization, so that they don't try to find the loopholes, they're buying into what needs to be done. They understand the why behind it. You for example, if you walk into your house, you normally close the door behind you. Security needs to be seen as that, as well, that's the culture and it's the habit. And it's ingrained in the fabric of the organization to live this way, not just implement the tools to do it. >> Right, and the number of doors you have in your infrastructure are a lot more than just a couple. Andrew mentioned sort of guidance and governments are obviously taking a more active role. I mean, sometimes I'm a cynic. I mean, the president Biden signs an executive order, but swipe of a pen doesn't really give us enough to go on. Do you think Andrea, that we're going to see new guidance from governments in the very near future? What are you expecting? >> I expect to see more conversations happening. I know that agencies who developed the policies are pulling together stakeholders and getting input. But I do see in the not too distant future, that mandates will be rolling out, yes. >> Well, so Andrew of course, Andrea, if you have a thought on this as well, but how do you see organizations dealing with adopting these new policies. >> Slowly, don't boil the ocean is one thing I tell a lot to every one of them, because a lot of these tooling, a lot of these concepts are foreign to them, brand new. How they adopt those and how they implement them, needs to be done in a very agile fashion, very slow and prescriptive. Go ahead and try to find one area of improvement and go ahead and work upon it and build upon it. Because not only does that normally make your organization more successful and secure, but also helps your organization just from a more out standpoint. One thing that you need to emphasize is that don't blame anyone. 'Cause a lot of times when you're going through this, you're reassessing your own supply chain. You might find where you could see improvements that need to be done. Don't blame things that may have occurred in the past. See how you can benefit from these lessons learned in the future. >> It's interesting you say that the blame game, I mean it used to be that failure meant you get fired and that's obviously has changed. As many have said, you know you're going to have incidents. It's how you respond to those incidents. What you learn from them. Do you have Andrew, any insights from specifically working with customers on securing their software supply chain? What can you tell us about what leading practitioners are doing today? >> They're going in and not only assessing what their software components consist of. Using tools like an SBOM, a software bill of materials, understand where all the components of their ecosystem and their lineage comes from. We're hearing almost every single day, new vulnerabilities that are being introduced in various software packages. By having that understanding of what is in your ecosystem, you can then better understand how to mitigate those concerns moving forward. >> Andrea, Andrew was just saying, one of the things is you don't just dive in. You've got to be careful. There's going to be ripple effects is what I'm inferring, but at the same time, there's a mandate to move quickly. Are there things that could accelerate the adoption of regulation or even the creation of regulations and that guidance in your view? What could accelerate this? >> As far as accelerating it goes, I think it's having those conversations proactively with the stakeholders in your organization and understanding the environment like Andrew said. Go ahead and get that baseline. And just know that whatever changes you make are maybe going to be audited down the road, because as we were moving towards this kind of third-party verification, that you're actually implementing things in order to do business with another organization. The importance of that, if organizations see that gravity to this, I think they will try to speed things up. I think that if organizations and the people in those organizations understand that why, that I talked about earlier and they understand how things like solar winds or things like the oil disruption that happened earlier this year. The personal effect to cyber events will help your organization move forward. Again, everybody's bought into the concept, everybody's working towards the same goals and they understand that why behind it. >> In addition to that, having tooling available, that makes it easy for them. You have a lot of individuals who this is all foreign, providing that base level tooling that aligns to a lot of the regulations that might be applicable within their real realm and their domain, makes it easier for them to start to complying and taking less burden off of them to be able to be successful. >> So it's a hard problem because Andrew, how do you deal with sort of the comment more tools, okay. But I look at that the Optiv map, if you've seen that. It makes your eyes cross. You've got so many tools, so much fragmentation, you're introducing new tools. Can automation help that? Is there hope for consolidation of that tools portfolio? >> Right now, this space is very emerging. It's very emergent, it's very fluid to be honest, 'cause there is actually mandates only a year or two old. But as they come over the course of time, however, I do see these types of tooling starting to consolidate where right now it seems like every vendor has a tool that tries to address this. It's being able to have the people work together, have more regulations that will come out that will allow us to start to redefine and solidify on certain tools like ISO standards. There are certain ones that I mentioned on as balance previously, there's now a ISO standard on SBOM there wasn't previously. So as more and more of these regulations come out, it makes it easier to provide that recommended set of tooling that organization is leveraging instead of vendor A, vendor B. >> Andrea, I said this before I was a cynic, but will give you the last word, give us some hope. I mean, obviously public policy is very important. A partnership between governments and industry, both the practitioners, the organizations that are buying these tools, as well as the technology industry got to work together in an ecosystem. Give us some hope. >> The hope I think will come from realizing that as you're doing this, as you are implementing these changes, you're in a sense trying to prevent those future incidents from happening. There's some assurance that you're doing everything that you can do here. It's a situation, it can be daunting, I'll put it that way. It can be really daunting for organizations, but just know that organizations like Red Hat are doing what we can to help you down the road. >> And really it's just continuing this whole shifting left mentality. The top of supply chain is just one component, but the introducing dev sec ops security at the beginning, that really will make the organizations become successful because this is not just a technology problem, It's a people issue as well. And being able to kind of package them all up together will help organizations as a whole. >> Yeah, so that's a really important point. You hear that term shift left. For years, people say, hey, you can't just bolt security on, as an afterthought, that's problematic. And that's the answer to that problem, right? Is shifting left meaning designing it in at the point of code, infrastructure as code, dev sec ops. That's where it starts, right? >> Exactly, being able to have security at the forefront and then have everything afterwards. Propagate from your security mindset. >> Excellent, okay, Andrea, Andrew, thanks so much for coming to the program today. >> Thank you for having us. >> Very welcome, thanks for watching. This is Dave Vellante for The Cube. Your a global leader in enterprise tech coverage. (soft music)

Published Date : Dec 16 2021

SUMMARY :

how can organizations manage the risks Thanks for having us. that organizations should that comes to mind first to how it wants them implemented. What are you seeing when and how they react to it is something What are the trends in regulations? more burden to your folks. And one of the things fabric of the organization from governments in the very near future? But I do see in the but how do you see organizations dealing that need to be done. say that the blame game, how to mitigate those of regulations and that if organizations see that gravity to this, to be able to be successful. But I look at that the Optiv have more regulations that will come out but will give you the last that you can do here. And being able to kind of And that's the answer have security at the forefront to the program today. This is Dave Vellante for The Cube.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
AndreaPERSON

0.99+

AndrewPERSON

0.99+

Andrew BlockPERSON

0.99+

Andrea HallPERSON

0.99+

Dave VellantePERSON

0.99+

Red HatORGANIZATION

0.99+

USLOCATION

0.99+

todayDATE

0.99+

Red Hat ConsultingORGANIZATION

0.99+

EnglandLOCATION

0.98+

one componentQUANTITY

0.98+

a yearQUANTITY

0.98+

oneQUANTITY

0.98+

AustraliaLOCATION

0.98+

bothQUANTITY

0.98+

each organizationQUANTITY

0.97+

Each agencyQUANTITY

0.97+

firstQUANTITY

0.97+

BidenPERSON

0.97+

One thingQUANTITY

0.96+

two great guestsQUANTITY

0.94+

SBOMORGANIZATION

0.92+

earlier this yearDATE

0.88+

few months agoDATE

0.88+

one areaQUANTITY

0.84+

one thingQUANTITY

0.84+

single dayQUANTITY

0.78+

two oldQUANTITY

0.77+

Red Hat V2ORGANIZATION

0.75+

The CubeORGANIZATION

0.74+

UKORGANIZATION

0.72+

yearsQUANTITY

0.71+

coupleQUANTITY

0.68+

OptivORGANIZATION

0.63+

SBOMTITLE

0.59+

ISOTITLE

0.41+

starORGANIZATION

0.38+

Andrea Hall & Andrew Block, Red Hat


 

(upbeat music) >> Okay, we're here talking about how you can better understand and manage the risks associated with the digital supply chain. How in this day and age where software comes from so many different places and sources throughout the ecosystem, how can organizations manage the risks associated with our dependence on software? And with me now are two great guests, Andrea Hall, who is a specialist solution architect and project manager for security and compliance at Red Hat. She's going to focus on public sector. And Andrew Block who's a distinguished architect at Red Hat Consulting, folks welcome. >> Welcome >> Thank you. Thanks for having us. >> You're very welcome. Andrea, let's start with you. Let's talk about regulations. What exists today that we should be aware of that organizations should be paying attention to? >> Oh sure, so the thing that comes to mind first being in the US is the presidential executive order on cybersecurity that came out a few months ago. Organizations are really paying attention to that. And in the US, it's having a ripple effect with policy, but we're also seeing policy considerations pop up in other countries, Australia and England. The supply chain is a big focus right now, of course, but we see these changes coming down the road as more and more government organizations are trying to secure their critical infrastructure. >> Is there kind of a leadership, or probably in other words, is somebody saying seeing what the UK does and say, okay, we're going to follow that template? Or is it just a variety and a mish mash with no sort of consolidation? How is that sort of playing out? >> I see a lot of organizations kind of basing their requirements on (indistinct) However, each organization has its own nuances. Each agency has its own nuances to how it wants them implemented. >> Andrew, maybe you could chime in here. What are you seeing when you talk to customers that are tuned into this issue? >> No as Andrea had just mentioned having that north star in terms of regulations is so fundamentally great for them because many of them especially in regulate industries, look to these regulations on how they apply their own policies. So at least it has some guidance on how to move forward because as we all know the secure software supply chain is getting news every day and how they react to it is something that I know all their leaders are asking themselves, especially those IT leaders. >> Andrea, when I talk to practitioners, sometimes they're frustrated. They understand they have to comply. They know new regulations are coming out, but sometimes it's hard for them to keep up. It would be helpful if you're sitting across the table from somebody who's frustrated and they ask you, what are your expectations? What are the trends in regulations? How do you see the current regulations evolving to specifically accommodate the digital supply chain and the security exposures and corollary requirements there? >> We see a lot of organizations struggling in the sense of trying to understand what the policy actually wants. Definitions are still a little bit vague, but implementation is also difficult because sometimes organizations will add more tools to their toolkit, adding a layer of complexity there. Really automation has to be pulled in. That's key to implementing this instead of adding more workload and more burden to your folks. It's really important for these organizations to pull stakeholders in the organization together. So the IT leaders bring together the developers, the security operations sit at the same table, talk about whether or not what needs to be implemented or what's proposed to be implemented, will affect the mission or in any way or disrupt operations. It's important for everybody to be on the same page so it doesn't slow anything down as you're trying to roll it out. >> And one of the things here is that we're seeing a lot of change with these new regulations and with a lot of organizations, any type of change is scary. And that is one area that they're looking for guidance not only in the tooling, but also how they apply it in the organization. >> I'll add on. >> Please. >> I'll add onto that and say, organizations really need to take into account the people side of things too. People need to understand what the impact is to the organization, so that they don't try to find the loopholes, they're buying into what needs to be done. They understand the why behind it. You for example, if you walk into your house, you normally close the door behind you. Security needs to be seen as that, as well, that's the culture and it's the habit. And it's ingrained in the fabric of the organization to live this way, not just implement the tools to do it. >> Right, and the number of doors you have in your infrastructure are a lot more than just a couple. Andrew mentioned sort of guidance and governments are obviously taking a more active role. I mean, sometimes I'm a cynic. I mean, the president Biden signs an executive order, but swipe of a pen doesn't really give us enough to go on. Do you think Andrea, that we're going to see new guidance from governments in the very near future? What are you expecting? >> I expect to see more conversations happening. I know that agencies who developed the policies are pulling together stakeholders and getting input. But I do see in the not too distant future, that mandates will be rolling out, yes. >> Well, so Andrew of course, Andrea, if you have a thought on this as well, but how do you see organizations dealing with adopting these new policies. >> Slowly, don't boil the ocean is one thing I tell a lot to every one of them, because a lot of these tooling, a lot of these concepts are foreign to them, brand new. How they adopt those and how they implement them, needs to be done in a very agile fashion, very slow and prescriptive. Go ahead and try to find one area of improvement and go ahead and work upon it and build upon it. Because not only does that normally make your organization more successful and secure, but also helps your organization just from a more out standpoint. One thing that you need to emphasize is that don't blame anyone. 'Cause a lot of times when you're going through this, you're reassessing your own supply chain. You might find where you could see improvements that need to be done. Don't blame things that may have occurred in the past. See how you can benefit from these lessons learned in the future. >> It's interesting you say that the blame game, I mean it used to be that failure meant you get fired and that's obviously has changed. As many have said, you know you're going to have incidents. It's how you respond to those incidents. What you learn from them. Do you have Andrew, any insights from specifically working with customers on securing their software supply chain? What can you tell us about what leading practitioners are doing today? >> They're going in and not only assessing what their software components consist of. Using tools like an SBOM, a software bill of materials, understand where all the components of their ecosystem and their lineage comes from. We're hearing almost every single day, new vulnerabilities that are being introduced in various software packages. By having that understanding of what is in your ecosystem, you can then better understand how to mitigate those concerns moving forward. >> Andrea, Andrew was just saying, one of the things is you don't just dive in. You've got to be careful. There's going to be ripple effects is what I'm inferring, but at the same time, there's a mandate to move quickly. Are there things that could accelerate the adoption of regulation or even the creation of regulations and that guidance in your view? What could accelerate this? >> As far as accelerating it goes, I think it's having those conversations proactively with the stakeholders in your organization and understanding the environment like Andrew said. Go ahead and get that baseline. And just know that whatever changes you make are maybe going to be audited down the road, because as we were moving towards this kind of third-party verification, that you're actually implementing things in order to do business with another organization. The importance of that, if organizations see that gravity to this, I think they will try to speed things up. I think that if organizations and the people in those organizations understand that why, that I talked about earlier and they understand how things like solar winds or things like the oil disruption that happened earlier this year. The personal effect to cyber events will help your organization move forward. Again, everybody's bought into the concept, everybody's working towards the same goals and they understand that why behind it. >> In addition to that, having tooling available, that makes it easy for them. You have a lot of individuals who this is all foreign, providing that base level tooling that aligns to a lot of the regulations that might be applicable within their real realm and their domain, makes it easier for them to start to complying and taking less burden off of them to be able to be successful. >> So it's a hard problem because Andrew, how do you deal with sort of the comment more tools, okay. But I look at that the Optiv map, if you've seen that. It makes your eyes cross. You've got so many tools, so much fragmentation, you're introducing new tools. Can automation help that? Is there hope for consolidation of that tools portfolio? >> Right now, this space is very emerging. It's very emergent, it's very fluid to be honest, 'cause there is actually mandates only a year or two old. But as they come over the course of time, however, I do see these types of tooling starting to consolidate where right now it seems like every vendor has a tool that tries to address this. It's being able to have the people work together, have more regulations that will come out that will allow us to start to redefine and solidify on certain tools like ISO standards. There are certain ones that I mentioned on as balance previously, there's now a ISO standard on SBOM there wasn't previously. So as more and more of these regulations come out, it makes it easier to provide that recommended set of tooling that organization is leveraging instead of vendor A, vendor B. >> Andrea, I said this before I was a cynic, but will give you the last word, give us some hope. I mean, obviously public policy is very important. A partnership between governments and industry, both the practitioners, the organizations that are buying these tools, as well as the technology industry got to work together in an ecosystem. Give us some hope. >> The hope I think will come from realizing that as you're doing this, as you are implementing these changes, you're in a sense trying to prevent those future incidents from happening. There's some assurance that you're doing everything that you can do here. It's a situation, it can be daunting, I'll put it that way. It can be really daunting for organizations, but just know that organizations like Red Hat are doing what we can to help you down the road. >> And really it's just continuing this whole shifting left mentality. The top of supply chain is just one component, but the introducing dev sec ops security at the beginning, that really will make the organizations become successful because this is not just a technology problem, It's a people issue as well. And being able to kind of package them all up together will help organizations as a whole. >> Yeah, so that's a really important point. You hear that term shift left. For years, people say, hey, you can't just bolt security on, as an afterthought, that's problematic. And that's the answer to that problem, right? Is shifting left meaning designing it in at the point of code, infrastructure as code, dev sec ops. That's where it starts, right? >> Exactly, being able to have security at the forefront and then have everything afterwards. Propagate from your security mindset. >> Excellent, okay, Andrea, Andrew, thanks so much for coming to the program today. >> Thank you for having us. >> Very welcome, thanks for watching. This is Dave Vellante for The Cube. Your a global leader in enterprise tech coverage. (soft music)

Published Date : Dec 15 2021

SUMMARY :

how can organizations manage the risks Thanks for having us. that organizations should that comes to mind first to how it wants them implemented. What are you seeing when and how they react to it is something What are the trends in regulations? more burden to your folks. And one of the things fabric of the organization from governments in the very near future? But I do see in the but how do you see organizations dealing that need to be done. say that the blame game, how to mitigate those of regulations and that if organizations see that gravity to this, to be able to be successful. But I look at that the Optiv have more regulations that will come out but will give you the last that you can do here. And being able to kind of And that's the answer have security at the forefront to the program today. This is Dave Vellante for The Cube.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
AndreaPERSON

0.99+

AndrewPERSON

0.99+

Andrew BlockPERSON

0.99+

Andrea HallPERSON

0.99+

Dave VellantePERSON

0.99+

Red HatORGANIZATION

0.99+

USLOCATION

0.99+

todayDATE

0.99+

Red Hat ConsultingORGANIZATION

0.99+

EnglandLOCATION

0.98+

one componentQUANTITY

0.98+

a yearQUANTITY

0.98+

oneQUANTITY

0.98+

AustraliaLOCATION

0.98+

bothQUANTITY

0.98+

each organizationQUANTITY

0.97+

Each agencyQUANTITY

0.97+

firstQUANTITY

0.97+

BidenPERSON

0.97+

One thingQUANTITY

0.96+

two great guestsQUANTITY

0.94+

SBOMORGANIZATION

0.92+

earlier this yearDATE

0.88+

few months agoDATE

0.88+

one areaQUANTITY

0.84+

one thingQUANTITY

0.84+

single dayQUANTITY

0.78+

two oldQUANTITY

0.77+

The CubeORGANIZATION

0.76+

UKORGANIZATION

0.72+

yearsQUANTITY

0.71+

coupleQUANTITY

0.68+

OptivORGANIZATION

0.63+

SBOMTITLE

0.59+

ISOTITLE

0.41+

starORGANIZATION

0.38+

Ben Fischer, Red Hat


 

(upbeat music) >> Welcome to this special CUBE program. We're going to help you better understand how to manage risk by securing your digital supply chain. And we're going to first give you a high level preview of what's happening in the market. And with me, is Ben Fischer, who's Emerging Security Technology Advocate at Red Hat. Hello, Ben. Good to see you again. >> Nice to meet you, David. I'm (indistinct) >> Yeah, so let's set it up. What can people expect to hear from this program? >> So today, I'm going to start off and you're going to, we're going to have a conversation about some of the business challenges related to the software supply chain. And then the next video will be with Vincent Danen, Red Hat's VP of product security, and Luke Hinds, our security lead from the office of the CTO. And they're going to discuss more of the security aspects of the software supply chain. Thirdly, you'll (indistinct) the newcomer director of hybrid platforms, security product management. We'll dig into some of the practices and the technologies, and that will be followed up by Andrea Hall and Andrew Block. Andrea is a specialist solution architect, and Andrew is a distinguished architect, and they're going to cover some of the change in environments. There's a lot of change in environments related to the regulations and different movements in the industry and organizations. And then lastly, we'll have a video from an interview you did with Luke Hinds, discussing a software sign in tool called Sigstore and how it can improve security supply chain. >> Excellent. Thank you for that. Okay. So Ben, people hear the term software supply chain, and makes them, "Oh. That's an interesting name." But what do we mean by the term software supply chain, Ben? >> So it's a loaded term. Simply, it's the supply chain but of software. And people think, "Oh well. I just go to a store, and I buy software and it comes packaged," maybe in the old days. But these days, we've got open source software. So there's repositories and collaboration upstream where a lot of people in a community contribute to all these different pieces of the software. It's kind of like when you go to a store. You go to a store and you just see this one piece, but that store carries lots of different products. And for each of those products, they have relationships with different vendors and different distributors to gather all those products into a store. And it's pretty complex. So there's been this kind of curation of products and softwares that's kind of come about kind of like a warehouse club. So like you would trust a warehouse club to be kind of a place to reduce the amount of shopping you might have, or you can kind of go there and you trust that they have good products that you'll like, and that fulfill most of your needs for your family, and you can go there and you can kind of get most of your shopping out of one place versus having to drive all around town to go get a bunch of different products that are carried in different stores, and then having to research all those products, warehouse clubs make that experience very simple. And so there's been kind of an upsurge of organizations like Red Hat that just help simplify your choices and do that curation. And the value there is in trying to not just give you everything, but also curate and try to make sure that what you have is secure. Make sure what you have is up to date. Kind of do all these kinds of nuanced things. The software supply chain is kind of complex in that there's all these extra details you need to be kind of aware of, and it's true. You know, you could run around town and shop for every product you would like yourself, just like in a software supply chain, you could go directly and get all the pieces of software and manage them and update them and do all the work yourself. But it it's a lot of work, and it is, as the word implies, it's a chain. So it's not just one relationship. It's a whole chain of relationships. And having a trusted entity as kind of a proxy, that you could put your faith in, and knowing that they're kind of doing some of that work for you makes life a lot easier just like in the warehouse club, right? You want to kind of go one place, get all your shopping done and be satisfied. And so just like you would in traditional times. You Know, before open source came about, there was a lot of proprietary software, and you'd put your trust and faith into them, that they would satisfy all of your needs, and they service you entirely. But even proprietary software now is an open source software so it comes into the same problem. So you need to have a trusted partner basically to help you understand and give you that level of trust in the software you're buying. >> Makes sense, yeah. And Red Hat plays that critical role. >> Yeah. >> So let's explain why all of a sudden this topic of digital supply chain, software supply chain has taken center stage. Ben, what should people understand about the digital supply chain and how it impacts their respective businesses? >> Well, the digital supply chain is really, really critical, I mean, if nothing else. I mean to bring up the kind of the COVID analogy, right? Everything changed with COVID. Things just got accelerated because we realized that the old way of doing things in person and a lot of physical ways slowed things down. And so when we were trying to social distance and have space, the pressure for doing everything in a digital form, and to make it easier to, you know, order your groceries and have them delivered to your door, or, you know, do a trunk delivery of your pizza at the local pizza shop, all this became really critical. So yeah. It's just, honestly, the COVID experience really accelerated the whole need for digital transformation. I'm not trying to go there, but that was part of the supply chain because all those companies also needed to have that digital experience with all of their vendors, and it's kind of accelerated in that respect. So the supply chain in general is something that's gotten a lot of attention. I think people actually understand, maybe have an idea what the word means over the last two years with all the incidents that have happened, and kind of the power of having it in digital electronic form, really really, I think, has hit home for a lot of people. And it's critical because now, I just don't feel like the world can ever really kind of go back from that. We're all so dependent on transacting in a digital form. Our businesses rely on it. We rely on a daily checking of phones, checking websites for information, doing everything. All this is run on software, right? And it's not just software that maybe one person wrote and can maintain for the rest of their lives, and do it in a perfect form. At some point, the software, you know, almost all of it, is using different parts of software that are open source and out there and available. And the pieces that were already developed, cause there's no reason to recreate the wheel. And they just kind of pulled in all these little open source components. If they didn't make a program, it was the programming around that to kind of make that usable for their particular use case. And everyone's just gotten very, very comfortable with this model of pulling software, what we would say, from the upstream down to the downstream and consume it and utilize it themselves. It's just pervasive everywhere. It's just, you know, open source, they say, is kind of eating the world and that's kind of where it's come from. >> Right. Yeah. And this is really a major issue for folks. We're seeing all kinds of new techniques. And for example, just imagine you've got dozens or even hundreds of suppliers, and the bad guys are targeting, you know, a victim, and they might put a piece of malware in an individual, one of the suppliers, you know. They'll get in to one of the suppliers, and that's a benign piece of code, but when it gets actually through the victims', you know, the targets' firewall, things will start to self-form in ways that we've really not seen before. And so this is really a big issue. There's a lot of talk coming from policymakers. Of course, the POTUS has issued an executive order and is putting pressure on businesses and technology companies to improve their security posture. I wish it were as easy as a sort of a swipe of a pen, but what's behind these trends, Ben? >> So, oh, there's so much behind there. So I think you're alluding to something really, really, really important. So in the security world, I mean, most of the issues in the security world is due to, you know, breaches, I should say. Hacks are due to kind of unpatched vulnerabilities. So the problem with that is then the answer is, well, you should patch and patch regularly, and that's absolutely true. You should patch as much as you can where it's not causing business disruptions. But when you get into a supply chain, or a digital supply chain issue, if you have a hacker who is able to penetrate into a vendor's software, and they're able to play something that gets placed into their update mechanism and then gets pushed out to all of our customers, it can be catastrophic and it can be, it will spread very fast and all the customers that are doing the right thing normally, by doing constant updates, will get infected. This is kind of the scary thing. Obviously, it is the right thing to do. And the right thing is for those vendors to secure their environment as much as possible and do everything they can to make that as tight as possible. But also, as in anything, it's really, we're in a world now where it's not if you're going to be breached or, you know, it's going to be when. Everybody in the world, especially the United States, we've all had breaches with our confidential information exposed, right? It's kind of the world we live in. It's what we expect. So with that understanding, you know, it becomes more about how we'll react to that. You know, if your credit card number gets exposed, you just don't throw your hands up in the air. You go, "Okay. Well, I need to put a credit freeze. I need to do certain diligent actions." Same thing in the industry. You know if something happens like that, an organization needs to respond properly and fast to share with the industry what has happened to stop those updates from continuing to perpetrate and provide guidance on what they can do. And this is one of the wonderful things, I think, about the security industry, is actually the willingness and interest to share. You'd kind of think of people in the old days wanting to hide their security secrets. Hide and protect what they do to make sure that, to safeguard all their assets and safeguard the company, their data, everything. And I'm not saying that everything is exposed, but there's a more willingness to share information on threats they're seeing and collaborate on fixes, and work through very difficult issues in a collaborative way, which is, I think it's really wonderful, and it plays perfectly in my mind, kind of the open source mentality of doing things together, out in the open, across organizations. >> Right. So, I mean, again, it's, you know, the very things that, the good behavior we're supposed to be doing with patching and what everybody's advising us to do, we have to be really careful. That can actually turn around and bite you. So how should we think about trust with software? What does that even mean today, Ben? >> Well, it's becoming more important than ever before, because before, you know, there, like I'll tell you way back when I, long time ago, when I was quite young, you'd just download software. And you would share it with friends and copy it, and there was no such thing as antivirus. And everybody was fine with that, and you didn't even think of an issue. And then I remember the first antivirus or viruses came out and then you went down to your local computer software store, and they're handing out free discs as antivirus fixes for that one particular issue. So you went down and you got it and you'd patch it up. And that was that. And you didn't really have any worries beyond that. These days, you know, and that's because you trust the store, and you knew there was only one issue and nobody was, it's kind of a free environment where nobody thought that anything bad would really happen. Today though, we hear in the news constantly about cyber attacks, about breaches, about just endless numbers of things that are happening. Ransomware. There's so many different types of attacks and it's happening in so many different ways across every industry, every geography. It's everywhere, you know. It's really, in my mind, the world's largest industry, cyber crime. And that's just a scary thing and that's because it's profitable. And so, you know, when you think of it as that, as a kind of an evil industry, if you will, it puts things into a little bit of a perspective that, okay, their motives, for the most part are money, and they're trying to do this. So if that's the case, then you're just trying to create enough friction that it's just not profitable for them. And so it's not about doing everything in terms of security. It's about trying to do, you know, for the right things to mitigate the risks for organization. And so getting back to your point about trust, how do you trust the software that you're given? You know, if you download a piece of software, you should be thinking about where's the software being downloaded from? There's lots of sites. There's lots and lots of ways to get it. There's absolutely millions of different pieces of open source code that's out there. And just because you downloaded it from a site, you don't know who posted it, you don't know a lot of these issues. So it can be scary. And as an organization, you can choose to take on all or part of that risk by trying to understand which locations are safe. You can try to understand, you know, which code is safe, and which code you can basically feel comfortable that there's a level of trust. Or simply you can shift that risk over to an organization that might do some of that work for you, like kind of in any business model. Red Hat is an entity, and it focuses on open source software. So, you know, you can go out and you could download any bit of open source software that Red Hat sells, and you can run it today. There's nothing stopping you, and that's wonderful, and we're happy that you're doing that, but Red Hat plays a particular role in that. We're trying to kind of curate that software. We're trying to pick the best piece of software that we feel we can trust. We have a lot of people in those communities, working with the people who actually work on that software. We believe in the open source model, partly because not only is it collaborative and just open and transparent, but in that transparency and in that collaboration, there is review of all the code that gets submitted. So if you can go to the right upstream article repositories, and you can work with those people, you have insight into what's happening, and you can pull down the pieces and the components that you feel are best that you can package into a product that you feel can meet all the needs for your particular customers, and you can do that in a particular way. And then having that close proximity to those communities, you also have an idea when there's updates and patches and you get to work on those, and that allows you to consume those faster, and bring those to your customers faster. And so this is part of the trust element. It's a matter of do you want to do it yourself? Like, you know, warehouse club analogy? Do you want to go to 100 stores when you do a shopping list, or, you know, 20, 30 stores driving around the whole day? I don't know. I don't want to do that on my Saturday. Or, you know, do you want to go to warehouse stuff? Yeah, you might pay a little bit more. There's a premium there. You have to have that warehouse club membership, but then you kind of go to one store and maybe get 80% of your shopping done there, and that's really good. And maybe get the 20% from a couple other stores down the street, but you're done in a matter of a few hours versus the whole day. And so I would implore you, in terms of trust, you need to think about what are the critical pieces of software that you have in your organization, right? What are the critical digital processes that your organization runs? Think about them, and also not just think about what the risks are around them, but also think about beyond them, what the risks are to the people you're trusting. So whether it's Red Hat, or whether it's a particular website you might be wanting to download that open source software from, you need to think about it's a whole chain of things. So you will need to know that, okay, I have access to these things. I have this information, and I have these risks. Now, if I extend that out one degree further, then what risks are those folks are exposed to? What do they have knowledge of? And do that, and then think about it, and think about and evaluate who has the most information? Where are the risks? And think about what makes sense for the organization in terms of mitigating those risks and giving you the best ability to respond when something does happen. I think you can reduce your risk exposure with an organization that curates open source, or even closed source, but also you can also kind of reduce the blast radius, I think, because if they can get you those updates faster, respond faster than you could yourself, then that's hugely valuable too. >> Yeah. I mean, you know, to your point about it's very lucrative for the hackers. I mean, the criminal algorithm is actually pretty simple. It's all about ROI for them, which is how much value can they extract and what does it cost them to extract that in a numerator denominator? And so to the extent that you can increase the cost to the hacker, there's less value to them, and they will go look somewhere else. So question is, what are the parameters of trust in software that can potentially help organizations increase that denominator? And how do you define trustworthy software? What are the attributes? >> Yeah. So there's a lot of attributes. Yeah. I come back to kind of warehouse club analogy. When you kind of go to the warehouse club, they've kind of already pre-picked for various use cases, kind of, you know. Here's the, you know. Here's the two brands of shavers and we have it in the disposable form and the replacement blade form. And you just have a few options there. And it's you know a nice, simple selection, and you look at it and, you know, you can see the price and you know the quantity and you have certain information. And if you did want to look up more information, it's either on the package or you pull out your phone and get more information. In the open source world, you know, some things you want to look at, you want to see its transparency. So everything in open source is very transparent. If you do want to go with a closed source provider, that's fine too. But you know, you do want to have as much transparency as possible. So you want to build up a good relationship, whether it's Red Hat, open source or a closed source vendor, you want to have that relationship to get insight. And if it's closed source, it's more important because you need to go deeper into that relationship to understand what's happening behind that veiled curtain. Accountability. So, you know, whether it is software that you're getting through another organization, you want to make sure you know who in that organization is accountable. You want to know how they're going to be accountable, how they're going to respond. If it's upstream, right now, one thing that's coming through is, and they call it S bomb, software bills and material, which has details about kind of an ingredient list, if you will, of that software. And that is something that will, in the future, make it a little bit easier for everybody, but also if you're going to get software yourself directly, give you an understanding of maybe who's accountable, who actually wrote the software or made the patch, or submitted the last update to a branch. That type of information is very useful because you need, at some point, you may need to know who did this to verify if something is trustworthy, if something was intentional or not, if you see something that might be curious or, I don't know, questionable in some nature. And traceability. You want to be able to have that ability to understand all the changes that have been done in that software, right? Software is, you know, it's highly versioned. So there's constantly new features or updates or patches. And you want to be able to go through and know what's happened there. So not only for the benefit of understanding the things that have been added and the benefits that have been added to the software, but if something happened or you were trying to make sure nothing bad happened, you'd want to make sure maybe there has been no malicious submissions into that code stream as well. And so by tracing that, that's good. And then the whole auditability of it, to go back and look at the software, and having somebody understand what might have happened by kind of digging into all the records for that particular software. I'd also say risk management, because you, as an organization, you really need to know what your risks are, and you need to be able to not just do that at the macro level, but now with the software supply chain, you need to bring that down to kind of a software level and really understand, you know, if my business relies on a particular software component, like open SSL for VPN software and site-to-site networking and whatnot, I need to make sure that if anything happens to this piece of software, which is a critical component for me operating my business, what am I going to do about it? You know do I just terminate all my VPN connections and leave my rural workers stranded and, you know, disable site-to-site networking so my different sites don't have direct networking connections? You have to kind think about what are the risks and, you know, what's my plan B? How would I possibly manage things? And it feels very overwhelming when you think about the number of components. And so this is where understanding this and trying to find ways to mitigate risk and manage it and make things a little bit simpler so you can really focus on things that matter and think are important. And then incident response, which is, there's going to be something that happens sometimes to some piece of software that your organization has. So how are you going to respond? How are you going to even find out? How are you going to know that something happened? How are you monitoring for vulnerabilities in the software? How are you connecting with the upstream communities and being aware that something is happening wrong, and there's a bunch of developers scrambling to try to fix something quick because maybe there's a known (indistinct) of some software out in the wild. So having that awareness and having that ability to building to respond really is probably one of the most critical things here. >> Ben, can you give us a sense of just kind of the scope of this problem? Are there metrics you can share to kind of frame the issue for the audience? >> Yeah. So in terms of open source supply chain attacks, some type, a software vendor, actually has reports every year. And they've reported that there was a 650% increase in open source supply chain attacks in the past year. And this is on top of a 430% increase the prior year. So it's scary, but it's basically literally exploding in terms of the threats happening in the supply chain attacks. Supply chain attacks are not new, but they've become quite popular. And the power of the supply chain, as an amplifying factor, is starting to get exploited really well by the attackers these days. >> Mm-hmm. Okay. So let's kind of go to best practice. I mean, what are businesses doing about these today? These problems today? What should they be doing that maybe they're not doing? >> So with the explosion, you can understand that with the spike of these supply chain attacks, organizations are honestly, and understandably pretty caught off guard. So while organizations have been working on their cybersecurity programs for some time now, they're mostly trying to react. And by react, they're reacting with maybe not the most efficient of incident response plans yet. And these attacks are spreading like wildfire, but as an industry, you know, it's not really helping us get ahead. So, you know, it's the unfortunate place where we're at. You mentioned that there's, obviously there's some guidance from POTUS and other folks in the industry, and various efforts in the industry to work on improving the supply chain, work on improving different components that can help make things dramatically better for the industry, but they're still pretty early stage. There's still a lot of work to be done. So as far as kind of what we can be doing as an industry, obviously, you know, I'll say collaboration again, because, you know, by working together, whether it's with the government or in an upstream organization setting standards, these things are all really important. And especially within verticals, I think it's really important to kind of get together because even if you have a general standard, things can vary quite a bit within the verticals. But besides that outwardly looking action, looking inside and trying to understand, in a sense, it's kind of a simple thing. It's a business process engineering a question of, okay, what are your critical business processes? You know, what do those business processes rely upon? You know, what software components are there? And then okay, for those pieces of software, they also have different components. So even if you go to, you know, whether you go to an open source provider or a closed source provider, there are open source components. So understanding the software that you use, understanding where you get that software from, and understanding the components in those software and how those are digested, whether it's from an organization like Red Hat that's open source, or maybe a closed source provider, is really important. Developing the relationships that you have, that bi-directional trust with those organizations that are running that critical software for your organization is really important. So it's a lot more of a mapping and awareness type exercise, because from there, you can start asking a bunch of different questions. And by engaging in conversations about those questions, you're going to learn more and more and more. And that will continue to lead forward. Eventually, you'll get an understanding of, "I have these risks," and you may not necessarily know everything, but along the way, you'll start developing awareness of risks, and then you can ask yourself along the way, "Okay. As an organization, let's come together and figure out how can we- Let's look at these risks and how can we think about mitigating these right within our budget? To meet our business needs," et cetera. But it's a hard question because there's so many software out there. Our businesses are so critical on so many ways. There's so much software, and each software has so many different components. It's a pretty overbearing problem. I just not trying to scare anybody, but it's just important to just take some time and think about it and understand what you have, and be diligent about kind of walking through those business processes, and start with the most critical ones and kind of keep walking forward. And as you're mitigating them, think about, do you want to have an organization help you with these, or do you want to hire people and have them invest their time into doing the work that an outside organization might do for you? >> Right. Hey, Ben, I've taken a lot of your time. Really appreciate your insights, and really great to have you on. Thank you. >> Well, thank you for having me, Dave. Appreciate it. >> And thank you for watching the CUBE. This is Dave Vellante, and we are the leader in enterprise technology coverage. (upbeat music)

Published Date : Dec 15 2021

SUMMARY :

We're going to help you better Nice to meet you, David. What can people expect to and they're going to cover Thank you for that. It's kind of like when you go to a store. And Red Hat plays that critical role. the digital supply At some point, the software, you know, one of the suppliers, you know. to be breached or, you again, it's, you know, and that allows you to And how do you define and really understand, you know, And the power of the supply So let's kind of go to best practice. software that you use, and really great to have you on. Well, thank you for having me, Dave. And thank you for watching the CUBE.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Dave VellantePERSON

0.99+

AndrewPERSON

0.99+

Vincent DanenPERSON

0.99+

Luke HindsPERSON

0.99+

AndreaPERSON

0.99+

DavidPERSON

0.99+

Ben FischerPERSON

0.99+

DavePERSON

0.99+

80%QUANTITY

0.99+

20QUANTITY

0.99+

20%QUANTITY

0.99+

Andrew BlockPERSON

0.99+

Red HatORGANIZATION

0.99+

650%QUANTITY

0.99+

430%QUANTITY

0.99+

BenPERSON

0.99+

100 storesQUANTITY

0.99+

dozensQUANTITY

0.99+

Andrea HallPERSON

0.99+

TodayDATE

0.99+

todayDATE

0.99+

United StatesLOCATION

0.99+

two brandsQUANTITY

0.99+

one pieceQUANTITY

0.99+

30 storesQUANTITY

0.99+

one degreeQUANTITY

0.99+

SaturdayDATE

0.98+

oneQUANTITY

0.98+

eachQUANTITY

0.98+

each softwareQUANTITY

0.97+

one storeQUANTITY

0.97+

one personQUANTITY

0.97+

firstQUANTITY

0.96+

one relationshipQUANTITY

0.95+

past yearDATE

0.94+

CTOORGANIZATION

0.94+

hundreds of suppliersQUANTITY

0.93+

Red HatORGANIZATION

0.93+

one particular issueQUANTITY

0.92+

one issueQUANTITY

0.92+

first antivirusQUANTITY

0.92+

COVIDOTHER

0.9+

one placeQUANTITY

0.89+

SigstoreTITLE

0.88+

millions of different piecesQUANTITY

0.87+

POTUSPERSON

0.86+

Red HatTITLE

0.8+

ThirdlyQUANTITY

0.79+

last two yearsDATE

0.75+

prior yearDATE

0.73+

couple other storesQUANTITY

0.72+

one thingQUANTITY

0.71+

HatTITLE

0.7+

CUBETITLE

0.65+

peopleQUANTITY

0.63+

of sitesQUANTITY

0.6+

openQUANTITY

0.53+

softwareQUANTITY

0.53+

RedORGANIZATION

0.51+

lotsQUANTITY

0.5+

Pete Bernard, Microsoft | Cloud City Live 2021


 

(upbeat music) >> Thanks Adam from the studio. Dave, with the next interview, I had a great chance to sit down with Pete, from Microsoft Azure. Talk about 5G and all the advances in the innovation around Silicon and what's coming around under the hood. Obviously Microsoft big hyperscaler, top three cloud player. Let's hear from Pete my conversation and we'll come right back. (upbeat music) Well, we'll come back to the cubes coverage of Mobile World Congress 2021, we're onsite in-person and virtual. It's a hybrid event this year. It's in-person for the first time, since the winter of 2019 lots been passed, a lot's happened and theCube's got to cover it. Our next guest is Pete Bernard, senior director, Silicon and telecom at Azure edge devices, platform and services at Microsoft. Pete, thanks for coming on theCube for our remote coverage. Thanks for coming on. We'll be there live and as well as with the remote community. Thanks for coming on. >> Yeah, no, that's great to be here. I'm coming here from sunny Bellevue, Washington. I wish a wish I was going to be in Barcelona this year, but like, as you mentioned, I think the last time I was in Barcelona was 2019. So a lot has happened since then. Right? >> Well, let's get into it. First of all, we'll see you on the interwebs and the community, but let, let's get the content storyline after the number one story at mobile world. Congress is the rise of the modern developer overlay on top of this new infrastructure, 5g, what is the edge, super edge, AI edge, whatever we want to call it. It is an enabler. Okay. And it's also leveraging the assets of, of these telecom infrastructures and certainly the pandemic we've had great success, nothing crashed. It saved us. So what's your, what's your view on this? This is the big story. It's the most important story? What's your take? >> Yeah, I mean, as I mentioned, a lot has happened and there's been a lot of advancements in this area and I think, you know, the part of what's happened with the pandemic is companies have really accelerated their strategies in this area. In terms of, you know, we have tons of commercial customers that are trying to solve really difficult problems using AI and edge and, and 5g now. So the demand is tremendous and the technology has really advanced quite a bit. And you know, we're, my team is specifically focused on sort of the intersection of 5g edge and AI, and it's sort of bringing together these kinds of existing credible technology advances and it's unlocking some amazing new scenarios and business models for, for customers and partners. For sure. >> So let's get it under the hood a little bit and talk about some of the technical issues. Obviously 5g is enabling a lot of commercial benefits cloud providers like Microsoft Azure is having great edge capabilities now with, with bringing the cloud to the edge, which opens up the obvious gamers Mehta versus AI, AR VR kind of things, low latency, applications, cars, and all that good stuff, all the data coming in and then new use cases. So it's a data problem. It's a typology challenge. It's a new architecture, unpack that for us. What, where are we in this? So. >> So I mean, as you mentioned, I mean, it was kind of an infinite set of problems to be solved. And one of the things that we found was that there was actually a lot of friction out there. It's almost like so many different partners and typologies and ways to put things together. Quite often, we get with a commercial customer and they're like, look, we just need to solve this particular problem in retail or healthcare energy. And so one of the things that we introduced as part of our kind of Azure portfolio is something called Azure percept, which is an end to end system for edge AI development and deployment that now works over 5g and L PWA as well. And so a lot of what we're trying to do as a platform company is help customers and partners kind of expedite and speed that development and deployment of solutions. Because like I said, there's no shortage of demand, but they're quite complex. And as you mentioned, you could have, you know, on-prem solutions, you could have hybrid solutions that talk to on-prem hardware and then go to the cloud. You can go direct to the cloud. But the question is like, how do you put these things together in a secure way? And it get an ROI quickly out of your edge AI deployments. And that's been kind of an interesting challenge. And I think when I talked to a lot of partners, telco partners, especially Silicon partners, were all struggling with how do we expedite, expedite? Because you know, the sooner we can get people to deploy and solve their problems, obviously, you know, the sooner they're happy, the sooner we all get paid. Right? And so that's one of the things we have to be careful of is with all the new technology, how do we really sort of titrate down to, you know, what does it take to actually get things from a POC to deployment as quickly as possible? >> And one of the big things is happening is not seeing the developer ecosystem is coming hardcore into the telco cloud, whatever you want to call it. And it's interesting, you know, the word operators is used a lot, the carriers, the operators, you don't hear that in it and say, you don't say that's the operator, the operators writes it department. So you have cloud native and this operating cultures coming together, dev ops dev sec ops coming to what is a carrier grade operating model, which is like a steady build solid foundation. That's what they expect. So you kind of have this classic OT it collision. And this has been talked about in the edge. What's different though, because now you've got to move faster. You got to have a lot of it like cloud scale with automation and AI at the same time I need full Bulletproof operations. Yeah. >> And so it's, you know, we're trying to expose a consistent developer fabric, you know, to our community. I mean, Microsoft's got millions of developers around the world using lots of, lots of tool, tool chains, and frameworks. And we want to sort of harness the power of that whole developer community to bring workloads and applications onto the telco network, right. In, in environments that they're familiar with. And we're seeing also sort of, you mentioned sort of colliding worlds in the edge world. There's kind of traditional embedded developers that are building cameras and devices and gateways. And then there's a lot of data science, AI developers as well. And what we're trying to do is sort of help both communities sort of learn these skills so that, you know, you have developers that are enabled to do, you know, AI workloads and scenarios and all of the business logic around those things and develop it in an environment, whether it's cloud-based or edge based that they're familiar with. And, you know, so therefore a lot of the complexities of the teleco network itself get sort of obfuscated or abstracted for them. So the developer doesn't have to become a telco expert, right. To build a 5g based camera system for their retail stores. Right. And so that's, that's exciting when we start to merge some of these communities together. >> Yeah. So what would be your message to the operators this year? I mean, obviously the edge is not something you need to educate people on, but they are trying to figure out how to, you know, swap the engine of the airplane out at 35,000 feet, as I say, they got, they want to innovate and this year what's your message. Yeah. >> I mean, there's kind of two things going on. One is yes. I think we're, we are deeply involved helping telcos Cloudify their network and take advantage of 5g and virtualization. And, you know, we have recent acquisitions as a metal switching affirmed and hold that whole thing. So that's, that's that chunk of work that's ongoing. I think the other thing that's happening is really thinking about telcos. We're seeing as a hunger for solutions. And so telcos thinking of themselves as solution providers, not just connectivity providers and, you know, getting into that mindset of saying, we're going to come in and work with this city or this, you know, big retailer and we're going to help solve the problems for them. And we love working with partners like that, that are actually delivering solutions as opposed to pieces of technology. >> What solutions do you think Pete are showing the most promise for helping the telco industry digitally transformed? >> Well, I think on the NGI space, there's a couple of big verticals. I mean, you know, obviously places like agriculture are huge, you know, where you need a wide deployments. We're seeing a lot of areas in around retail, you know, retail environments when I would have leveraged like low latency 5g. One of the pieces of feedback we heard was a lot of retailers actually want less hardware in their physical store and they want to leverage 5g more to get back to the cloud. And then we're seeing, you know, energy sectors, you know, and mining and other kind of difficult to reach areas where you can leverage ciliary networks. So a lot of these verticals are, you know, turning onto the fact that they could get some of their conductivity and edge AI solutions combined together and do some amazing things. >> Right. You just made me think of a question while I got you. I got to ask this because you know, you've brought up 5g and back haul, you know, and people in the, in this business always know backhaul is always the problem. We all know we've been to a concert or a game where we've got multiple bars on wifi, but nothing's loading. Right. So we all know, right. We've seen that that's back haul. That's a choke point. If 5g is going to give me more back haul to essentially another exchange, how has the core of the internet evolved? Because as I started poking around and research and there's more direct connects now, there's not many exchanges. It used to be, we had my west and my east, those are now gone. I'm like, what's going on in the backbone? Does that simple? Is it better or worse? Is that still a good thing? >> Well, yeah. One of the exciting things around kind of the virtualization of what's going on with networking is that we're able to partner with telcos to sort of extend the Azure footprint to help with some of those congestion points, right? So we can, we can bring heavy edge equipment, pretty darn close to where the action is, and actually have direct connections into teleco networks to help them sort of expand their footprint, you know, even farther out to the edge and they can leverage our hyperscaler to, to do that. So that that's a benefit of one of the architectural improvements of 5G around virtualization. >> That's awesome. And I'm looking forward to following up on that great point. And I think it's, it sells a digital divide problem. That's been going on for over a decade, 15, 20 years, this digital divide. Now you got city revitalizations going on. You have, I mean, just the, just the, the digital revitalization in global communities is everywhere. And I think, I think this is going to be an influx point. That's not yet written about in the press now, but I think it's going to be very clear. So, so with all that, I got to ask you the importance of how you guys see an ecosystem for this transformation, because it used to be the telcos ruled the world, and now it's not going that way. They still have a footprint. I mean, everyone, the rising tide helps everybody, as they say, what's the importance of a strong ecosystem in order to drive this nutrient? >> Well, you know, it's definitely a team sport. It's definitely a team sport. And, and you know, Microsoft's been a big partner company for decades, and I think it's something like $8, a part of revenue for every dollar of revenue from the Microsoft generate. So we're heavily invested in our device, builder partners, our telco partners, the ISV community. And, you know, I think what we're trying to do is work with telcos to sort of bring those communities together, to solve these kinds of problems that customers are having. So yeah, it's definitely a team sport. And like I said, the new entrance with some really innovative software platforms, it's an opportunity for telcos, I think, to sort of reinvent and to kind of rethink about how they want to be more agile and more competitive. Again, this will be businesses. >> Okay, great. And have you on, I got it. I got ask you, we've talked about the most important story, obviously 5g edge in AI. I think you nailed it. You're you're in this cross hairs of probably one of the most exciting areas in the tech industry as distributed computing goes that last mile, so to speak pun intended, what, but what's, in your opinion, the most important story that not many people are talking about that should be talking about, what do you think is something that's being written about, but to talk about, but it's super important that that needs to be true. >> Well, you know, it's interesting. I mean, a lot of the marketing and talk about 5g is around phones, people talking about their speed on phones. And I think we're finally getting past the discussion of 5g on phones and talking about 5g for like more MTM communications and more, more kind of connecting really trillions of things together. And then that enabled me to is going to be a big, big deal moving forward. And I think that's, we'll start to see probably more coverage of that moving forward. We're on the inside of the industry. So we kind of know it, but I think on the outside of the industry, when people think 5g, they still think phones. And then hopefully that becomes, there's more of a story around all the other pieces being connected with 5g. >> Yeah. And I got to ask you about two quick things before we go open source, openness, interoperability, and security. What, how would you, what's your opinion on those two pillars? >> So I think security is kind of foundational for what we're we've been doing at Microsoft for a long time, whether it's Azure sphere that we're doing for end to end, you know, edge security or any of our security offerings that we have from services perspective. So we're trying to like with Azure percept, we actually build in like TPM encryption of AI models from edge to cloud, as an example of that. So security really is foundational to all of the stuff that we need to do. It cannot be something that you do later or add on it has to be designed in. And I think from an open source perspective, I mean, whether it's our, you know, stewardship of GitHub or the involvement in open source communities, you know, we're, we're totally excited about all the innovation that's happening there and you know, you got to let people participate. And in fact, one of the cool things that's been happening is the amount of developer reach in areas where maybe there isn't, you know, like we've had our build conferences and other Microsoft events. It enables everyone to participate virtually no matter where they are in the world, even if they can't get a ticket to Redmond Washington, and you can still be part of the developer community and learn online and be part of that. >> I think this whole embed developer market's going to come back in and massive volumes of new people as Silicon becomes important. And of course, I can't leave you without asking the Silicon angle question for our team. Silicon is becoming a competitive advantage for whether it's acceleration, offload and or core things, whether it's instance related or use case related, what's the future of Silicon and the telecom and cloud in general. >> For mine. Yeah. So I mean, the advances happening in the Silicon space are fantastic. Whether it's like process advances down to like five nanometers and below. So you're talking about, you know, much lower power consumption, much higher density, you know, packaging and, you know, AI acceleration built in as well as all these other, you know, containerized security things. So that's being driven by a lot by consumer markets, right? So more powerful PCs and phones. And that's also translating into the cloud and for some of the heavy infrastructure. So the leaps and bounds we're seeing even between now and the last MWC in person in 2019 in Silicon has been amazing. And that's going to unblock, you know, all kinds of workloads that could be done at the edge as well as incredible high-performance stuff to be done in the cloud. That's pretty exciting. >> Peter Love that word unblocked, because I think it's going to unblock them that big, you know, rock in the river. It's holding the water back. I think it's going to unleash creativity, innovation, computer science engineering down from Silicon to the modern application developer. Amazing opportunity. I think the edge is going to be the, an awesome area to innovate on. Thanks for coming on the cube. >> Sounds good. Thanks for having me. >> People in our senior director, silica telecom as your edge devices for platform services at Microsoft, a lot going on big cloud player, hyperscaler at the edge. This is the final area. In my opinion, that's called the accident habits going to be great innovation. It's part of the cloud cloud is creating massive change in telecom. We've got to cover here in the queue. Thanks for watching. Okay, Dave, that was a great interview with Pete Bernard, senior director, Silicon telecom, Azure edge devices, platform, and services. Microsoft's got all those long titles in the, in the thing, but Silicon is a key thing. You heard my interview wide ranging conversation, obviously with that kind of pedigree and expertise. He's pretty strong, but he, at the end there a little gym on the Silicon. Yeah. Okay. Because that is going to be a power source. You you've been reporting on this. You've been doing a lot of breaking analysis. Microsoft's a hyperscaler they're they're the second player in cloud, Amazon. Number one, Microsoft number two, Google number three, Microsoft. They didn't really say anything. They have something Amazon has got grab a ton, but big directional signal shift there. >> Well, I think it was interesting. It was a great interview by the way, and the things that struck me pizza, and they're focused on the intersection of 5g edge and AI. So AI is all about data-driven workloads. If you look at AI today, most of the AI in the enterprise is done in the cloud and it's modeling, but the future of AI is going to be inferencing at the edge in real time. That's where the real expenses today. And that's where you need new computing architectures. And you're right. I've written about this one of my last breaking analysis on AWS, a secret weapon, and that secret weapon is a new computing architecture. That's not based on traditional x86 architectures. It's based on their own design, but based on arm, because arm is higher performance, lower cost, better price, performance, and way cheaper. And so I guarantee you based on what you just said that, well, Amazon clearly has set the direction with nitro and graviton and, and, and, you know, gravitate on to Microsoft is I think following that playbook. And it's interesting that Pete has Silicon in his title and telecom and an edge they're going after that because it doesn't require new low powered architectures that are going to blow away anything we've ever seen on x86. >> Yeah. I mean, I think that's a killer point. You and I have been covering the enterprise, the old guard rack and stack the boxes. Amazon was early on that clearly winning low power, high density looks like a consumer, like feel in cloud scale, changes the game on economics. And then he also teased out if you squint, there's a lot of stuff to decode. We're going to unpack that video and write probably six or five blog posts there, but he said, 5g is going to change the direct connect. They're already doing it. Microsoft's putting that to the edge, that right in the same playbook as AWS, right on the almost right on the number, put the edge, make it powerful, direct connects connectivity. >> We've seen this before. The consumer piece is key. The consumer leads, we know this and the consumer apple is leading in things like AI and, and Tesla is leading at the edge. That's where you have to look for the innovation. That's going to trickle into the enterprise. And so in the cloud guys, I kicked the hyperscale. You and Sergeant Joe Hall talked about this at the startup showcase that we did was that the cloud guys, the hyperscalers, and a really strong position for the edge. >> I got to tell you, we are on this go to the siliconangle.com. Obviously that's our website, the cube.net. We are reporting on this. It's very nuanced point. But if you look at the cloud players, you can see the telco digital revolution telco. Dr. Is a digital revolution back to you, Adam, in the studio for more coverage, we'll be back at the desk shortly.

Published Date : Jul 7 2021

SUMMARY :

Talk about 5G and all the Yeah, no, that's great to be here. And it's also leveraging the assets of, And you know, we're, bringing the cloud to the edge, And so that's one of the things the operators, you don't and all of the business logic swap the engine of the And, you know, So a lot of these verticals are, you know, I got to ask this because you know, extend the Azure footprint to I got to ask you the importance dollar of revenue from the hairs of probably one of the a lot of the marketing and And I got to ask you about I mean, whether it's our, you know, and the telecom and cloud in And that's going to unblock, you know, Thanks for coming on the cube. Thanks for having me. This is the final area. most of the AI in the enterprise that right in the same playbook as AWS, And so in the cloud guys, in the studio for more coverage,

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
AmazonORGANIZATION

0.99+

MicrosoftORGANIZATION

0.99+

Pete BernardPERSON

0.99+

PetePERSON

0.99+

AdamPERSON

0.99+

$8QUANTITY

0.99+

DavePERSON

0.99+

BarcelonaLOCATION

0.99+

sixQUANTITY

0.99+

Pete BernardPERSON

0.99+

2019DATE

0.99+

35,000 feetQUANTITY

0.99+

AWSORGANIZATION

0.99+

TeslaORGANIZATION

0.99+

cube.netOTHER

0.99+

15QUANTITY

0.99+

siliconangle.comOTHER

0.99+

OneQUANTITY

0.99+

PeterPERSON

0.99+

GoogleORGANIZATION

0.99+

telcoORGANIZATION

0.99+

millionsQUANTITY

0.99+

appleORGANIZATION

0.98+

this yearDATE

0.98+

two pillarsQUANTITY

0.98+

five nanometersQUANTITY

0.98+

first timeQUANTITY

0.98+

second playerQUANTITY

0.98+

oneQUANTITY

0.98+

both communitiesQUANTITY

0.98+

five blog postsQUANTITY

0.97+

Redmond WashingtonLOCATION

0.97+

two thingsQUANTITY

0.97+

telcosORGANIZATION

0.97+

MWCEVENT

0.97+

FirstQUANTITY

0.97+

SiliconLOCATION

0.97+

SiliconORGANIZATION

0.96+

Joe HallPERSON

0.95+

Mobile World Congress 2021EVENT

0.95+

over a decadeQUANTITY

0.95+

pandemicEVENT

0.94+

CongressORGANIZATION

0.93+

SergeantPERSON

0.93+

sunny Bellevue, WashingtonLOCATION

0.93+

AzureTITLE

0.93+

decadesQUANTITY

0.93+

two quick thingsQUANTITY

0.93+

5gORGANIZATION

0.92+

todayDATE

0.92+

Azure perceptTITLE

0.91+

5gQUANTITY

0.91+

Silicon telecomORGANIZATION

0.91+

Breaking Analysis: Best of theCUBE on Cloud


 

>> Narrator: From theCUBE Studios in Palo Alto, in Boston bringing you data-driven insights from theCUBE and ETR. This is "Breaking Analysis" with Dave Vellante. >> The next 10 years of cloud, they're going to differ dramatically from the past decade. The early days of cloud, deployed virtualization of standard off-the-shelf components, X86 microprocessors, disk drives et cetera, to then scale out and build a large distributed system. The coming decade is going to see a much more data-centric, real-time, intelligent, call it even hyper-decentralized cloud that will comprise on-prem, hybrid, cross-cloud and edge workloads with a services layer that will obstruct the underlying complexity of the infrastructure which will also comprise much more custom and varied components. This was a key takeaway of the guests from theCUBE on Cloud, an event hosted by SiliconANGLE on theCUBE. Welcome to this week's Wikibon CUBE Insights Powered by ETR. In this episode, we'll summarize the findings of our recent event and extract the signal from our great guests with a couple of series and comments and clips from the show. CUBE on Cloud is our very first virtual editorial event. It was designed to bring together our community in an open forum. We ran the day on our 365 software platform and had a great lineup of CEOs, CIOs, data practitioners technologists. We had cloud experts, analysts and many opinion leaders all brought together in a day long series of sessions that we developed in order to unpack the future of cloud computing in the coming decade. Let me briefly frame up the conversation and then turn it over to some of our guests. First, we put forth our view of how modern cloud has evolved and where it's headed. This graphic that we're showing here, talks about the progression of cloud innovation over time. A cloud like many innovations, it started as a novelty. When AWS announced S3 in March of 2006, nobody in the vendor or user communities really even in the trade press really paid too much attention to it. Then later that year, Amazon announced EC2 and people started to think about a new model of computing. But it was largely tire kickers, bleeding-edge developers that took notice and really leaned in. Now the financial crisis of 2007 to 2009, really created what we call a cloud awakening and it put cloud on the radar of many CFOs. Shadow IT emerged within departments that wanted to take IT in bite-sized chunks and along with the CFO wanted to take it as OPEX versus CAPEX. And then I teach transformation that really took hold. We came out of the financial crisis and we've been on an 11-year cloud boom. And it doesn't look like it's going to stop anytime soon, cloud has really disrupted the on-prem model as we've reported and completely transformed IT. Ironically, the pandemic hit at the beginning of this decade, and created a mandate to go digital. And so it accelerated the industry transformation that we're highlighting here, which probably would have taken several more years to mature but overnight the forced March to digital happened. And it looks like it's here to stay. Now the next wave, we think we'll be much more about business or industry transformation. We're seeing the first glimpses of that. Holger Mueller of Constellation Research summed it up at our event very well I thought, he basically said the cloud is the big winner of COVID. Of course we know that now normally we talk about seven-year economic cycles. He said he was talking about for planning and investment cycles. Now we operate in seven-day cycles. The examples he gave where do we open or close the store? How do we pivot to support remote workers without the burden of CAPEX? And we think that the things listed on this chart are going to be front and center in the coming years, data AI, a fully digitized and intelligence stack that will support next gen disruptions in autos, manufacturing, finance, farming and virtually every industry where the system will expand to the edge. And the underlying infrastructure across physical locations will be hidden. Many issues remain, not the least of which is latency which we talked about at the event in quite some detail. So let's talk about how the Big 3 cloud players are going to participate in this next era. Well, in short, the consensus from the event was that the rich get richer. Let's take a look at some data. This chart shows our most recent estimates of IaaS and PaaS spending for the Big 3. And we're going to update this after earning season but there's a couple of points stand out. First, we want to make the point that combined the Big 3 now account for almost $80 billion of infrastructure spend last year. That $80 billion, was not all incremental (laughs) No it's caused consolidation and disruption in the on-prem data center business and within IT shops companies like Dell, HPE, IBM, Oracle many others have felt the heat and have had to respond with hybrid and cross cloud strategies. Second while it's true that Azure and GCP they appear to be growing faster than AWS. We don't know really the exact numbers, of course because only AWS provides a clean view of IaaS and passwords, Microsoft and Google. They kind of hide them all ball on their numbers which by the way, I don't blame them but they do leave breadcrumbs and clues on growth rates. And we have other means of estimating through surveys and the like, but it's undeniable Azure is closing the revenue gap on AWS. The third is that I like the fact that Azure and Google are growing faster than AWS. AWS is the only company by our estimates to grow its business sequentially last quarter. And in and of itself, that's not really enough important. What is significant is that because AWS is so large now at 45 billion, even at their slower growth rates it grows much more in absolute terms than its competitors. So we think AWS is going to keep its lead for some time. We think Microsoft and AWS will continue to lead the pack. You know, they might converge maybe it will be a 200 just race in terms of who's first who's second in terms of cloud revenue and how it's counted depending on what they count in their numbers. And Google look with its balance sheet and global network. It's going to play the long game and virtually everyone else with the exception of perhaps Alibaba is going to be secondary players on these platforms. Now this next graphic underscores that reality and kind of lays out the competitive landscape. What we're showing here is survey data from ETR of more than 1400 CIOs and IT buyers and on the vertical axis is Net Score which measures spending momentum on the horizontal axis is so-called Market Share which is a measure of pervasiveness in the data set. The key points are AWS and Microsoft look at it. They stand alone so far ahead of the pack. I mean, they really literally, it would have to fall down to lose their lead high spending velocity and large share of the market or the hallmarks of these two companies. And we don't think that's going to change anytime soon. Now, Google, even though it's far behind they have the financial strength to continue to position themselves as an alternative to AWS. And of course, an analytics specialist. So it will continue to grow, but it will be challenged. We think to catch up to the leaders. Now take a look at the hybrid zone where the field is playing. These are companies that have a large on-prem presence and have been forced to initiate a coherent cloud strategy. And of course, including multicloud. And we include Google in this so pack because they're behind and they have to take a differentiated approach relative to AWS, and maybe cozy up to some of these traditional enterprise vendors to help Google get to the enterprise. And you can see from the on-prem crowd, VMware Cloud on AWS is stands out as having some, some momentum as does Red Hat OpenShift, which is it's cloudy, but it's really sort of an ingredient it's not really broad IaaS specifically but it's a component of cloud VMware cloud which includes VCF or VMware Cloud Foundation. And even Dell's cloud. We would expect HPE with its GreenLake strategy. Its financials is shoring up, should be picking up momentum in the future in terms of what the customers of this survey consider cloud. And then of course you could see IBM and Oracle you're in the game, but they don't have the spending momentum and they don't have the CAPEX chops to compete with the hyperscalers IBM's cloud revenue actually dropped 7% last quarter. So that highlights the challenges that that company facing Oracle's cloud business is growing in the single digits. It's kind of up and down, but again underscores these two companies are really about migrating their software install basis to their captive clouds and as well for IBM, for example it's launched a financial cloud as a way to differentiate and not take AWS head-on an infrastructure as a service. The bottom line is that other than the Big 3 in Alibaba the rest of the pack will be plugging into hybridizing and cross-clouding those platforms. And there are definitely opportunities there specifically related to creating that abstraction layer that we talked about earlier and hiding that underlying complexity and importantly creating incremental value good examples, snowfallLike what snowflake is doing with its data cloud, what the data protection guys are doing. A company like Loomio is headed in that direction as are others. So, you keep an eye on that and think about where the white space is and where the value can be across-clouds. That's where the opportunity is. So let's see, what is this all going to look like? How does the cube community think it's going to unfold? Let's hear from theCUBE Guests and theCUBE on Cloud speakers and some of those highlights. Now, unfortunately we don't have time to show you clips from every speaker. We are like 10-plus hours of video content but we've tried to pull together some comments that summarize the sentiment from the community. So I'm going to have John Furrier briefly explain what theCUBE on Cloud is all about and then let the guests speak for themselves. After John, Pradeep Sindhu is going to give a nice technical overview of how the cloud was built out and what's changing in the future. I'll give you a hint it has to do with data. And then speaking of data, Mai-Lan Bukovec, who heads up AWS is storage portfolio. She'll explain how she views the coming changes in cloud and how they look at storage. Again, no surprise, it's all about data. Now, one of the themes that you'll hear from guests is the notion of a distributed cloud model. And Zhamak Deghani, he was a data architect. She'll explain her view of the future of data architectures. We also have thoughts from analysts like Zeus Karavalla and Maribel Lopez, and some comments from both Microsoft and Google to compliment AWS's view of the world. In fact, we asked JG Chirapurath from Microsoft to comment on the common narrative that Microsoft products are not best-to-breed. They put out a one dot O and then they get better, or sometimes people say, well, they're just good enough. So we'll see what his response is to that. And Paul Gillin asks, Amit Zavery of Google his thoughts on the cloud leaderboard and how Google thinks about their third-place position. Dheeraj Pandey gives his perspective on how technology has progressed and been miniaturized over time. And what's coming in the future. And then Simon Crosby gives us a framework to think about the edge as the most logical opportunity to process data not necessarily a physical place. And this was echoed by John Roese, and Chris Wolf to experience CTOs who went into some great depth on this topic. Unfortunately, I don't have the clips of those two but their comments can be found on the CTO power panel the technical edge it's called that's the segment at theCUBE on Cloud events site which we'll share the URL later. Now, the highlight reel ends with CEO Joni Klippert she talks about the changes in securing the cloud from a developer angle. And finally, we wrap up with a CIO perspective, Dan Sheehan. He provides some practical advice on building on his experience as a CIO, COO and CTO specifically how do you as a business technology leader deal with the rapid pace of change and still be able to drive business results? Okay, so let's now hear from the community please run the highlights. >> Well, I think one of the things we talked about COVID is the personal impact to me but other people as well one of the things that people are craving right now is information, factual information, truth, textures that we call it. But here this event for us Dave is our first inaugural editorial event. Rob, both Kristen Nicole the entire cube team, SiliconANGLE on theCUBE we're really trying to put together more of a cadence. We're going to do more of these events where we can put out and feature the best people in our community that have great fresh voices. You know, we do interview the big names Andy Jassy, Michael Dell, the billionaires of people making things happen, but it's often the people under them that are the real Newsmakers. >> If you look at the architecture of cloud data centers the single most important invention was scale-out. Scale-out of identical or near identical servers all connected to a standard IP ethernet network. That's the architecture. Now the building blocks of this architecture is ethernet switches which make up the network, IP ethernet switches. And then the server is all built using general purpose x86 CPU's with DRAM, with SSD, with hard drives all connected to inside the CPU. Now, the fact that you scale these server nodes as they're called out was very, very important in addressing the problem of how do you build very large scale infrastructure using general purpose compute but this architecture, Dave is a compute centric architecture. And the reason it's a compute centric architecture is if you open this, is server node. What you see is a connection to the network typically with a simple network interface card. And then you have CPU's which are in the middle of the action. Not only are the CPU's processing the application workload but they're processing all of the IO workload what we call data centric workload. And so when you connect SSDs and hard drives and GPU is everything to the CPU, as well as to the network you can now imagine that the CPU is doing two functions. It's running the applications but it's also playing traffic cop for the IO. So every IO has to go to the CPU and you're executing instructions typically in the operating system. And you're interrupting the CPU many many millions of times a second. Now general purpose CPU and the architecture of the CPU's was never designed to play traffic cop because the traffic cop function is a function that requires you to be interrupted very, very frequently. So it's critical that in this new architecture where does a lot of data, a lot of these stress traffic the percentage of workload, which is data centric has gone from maybe one to 2% to 30 to 40%. >> The path to innovation is paved by data. If you don't have data, you don't have machine learning you don't have the next generation of analytics applications that helps you chart a path forward into a world that seems to be changing every week. And so in order to have that insight in order to have that predictive forecasting that every company needs, regardless of what industry that you're in today, it all starts from data. And I think the key shift that I've seen is how customers are thinking about that data, about being instantly usable. Whereas in the past, it might've been a backup. Now it's part of a data Lake. And if you can bring that data into a data lake you can have not just analytics or machine learning or auditing applications it's really what does your application do for your business and how can it take advantage of that vast amount of shared data set in your business? >> We are actually moving towards decentralization if we think today, like if it let's move data aside if we said is the only way web would work the only way we get access to various applications on the web or pages to centralize it We would laugh at that idea. But for some reason we don't question that when it comes to data, right? So I think it's time to embrace the complexity that comes with the growth of number of sources, the proliferation of sources and consumptions models, embrace the distribution of sources of data that they're not just within one part of organization. They're not just within even bounds of organizations that are beyond the bounds of organization. And then look back and say, okay, if that's the trend of our industry in general, given the fabric of compensation and data that we put in, you know, globally in place then how the architecture and technology and organizational structure incentives need to move to embrace that complexity. And to me that requires a paradigm shift a full stack from how we organize our organizations how we organize our teams, how we put a technology in place to look at it from a decentralized angle. >> I actually think we're in the midst of the transition to what's called a distributed cloud, where if you look at modernized cloud apps today they're actually made up of services from different clouds. And also distributed edge locations. And that's going to have a pretty profound impact on the way we go vast. >> We wake up every day, worrying about our customer and worrying about the customer condition and to absolutely make sure we dealt with the best in the first attempt that we do. So when you take the plethora of products we've dealt with in Azure, be it Azure SQL be it Azure cosmos DB, Synapse, Azure Databricks, which we did in partnership with Databricks Azure machine learning. And recently when we sort of offered the world's first comprehensive data governance solution and Azure overview, I would, I would humbly submit to you that we are leading the way. >> How important are rankings within the Google cloud team or are you focused mainly more on growth and just consistency? >> No, I don't think again, I'm not worried about we are not focused on ranking or any of that stuff. Typically I think we are worried about making sure customers are satisfied and the adding more and more customers. So if you look at the volume of customers we are signing up a lot of the large deals we did doing. If you look at the announcement we've made over the last year has been tremendous momentum around that. >> The thing that is really interesting about where we have been versus where we're going is we spend a lot of time talking about virtualizing hardware and moving that around. And what does that look like? And creating that as more of a software paradigm. And the thing we're talking about now is what does cloud as an operating model look like? What is the manageability of that? What is the security of that? What, you know, we've talked a lot about containers and moving into different, DevSecOps and all those different trends that we've been talking about. Like now we're doing them. So we've only gotten to the first crank of that. And I think every technology vendor we talked to now has to address how are they are going to do a highly distributed management insecurity landscape? Like, what are they going to layer on top of that? Because it's not just about, oh, I've taken a rack of something, server storage, compute, and virtualized it. I know have to create a new operating model around it in a way we're almost redoing what the OSI stack looks like and what the software and solutions are for that. >> And the whole idea of we in every recession we make things smaller. You know, in 91 we said we're going to go away from mainframes into Unix servers. And we made the unit of compute smaller. Then in the year, 2000 windows the next bubble burst and the recession afterwards we moved from Unix servers to Wintel windows and Intel x86 and eventually Linux as well. Again, we made things smaller going from million dollar servers to $5,000 servers, shorter lib servers. And that's what we did in 2008, 2009. I said, look, we don't even need to buy servers. We can do things with virtual machines which are servers that are an incarnation in the digital world. There's nothing in the physical world that actually even lives but we made it even smaller. And now with cloud in the last three, four years and what will happen in this coming decade. They're going to make it even smaller not just in space, which is size, with functions and containers and virtual machines, but also in time. >> So I think the right way to think about edges where can you reasonably process the data? And it obviously makes sense to process data at the first opportunity you have but much data is encrypted between the original device say and the application. And so edge as a place doesn't make as much sense as edge as an opportunity to decrypt and analyze it in the care. >> When I think of Shift-left, I think of that Mobius that we all look at all of the time and how we deliver and like plan, write code, deliver software, and then manage it, monitor it, right like that entire DevOps workflow. And today, when we think about where security lives, it either is a blocker to deploying production or most commonly it lives long after code has been deployed to production. And there's a security team constantly playing catch up trying to ensure that the development team whose job is to deliver value to their customers quickly, right? Deploy as fast as we can as many great customer facing features. They're then looking at it months after software has been deployed and then hurrying and trying to assess where the bugs are and trying to get that information back to software developers so that they can fix those issues. Shifting left to me means software engineers are finding those bugs as they're writing code or in the CIC CD pipeline long before code has been deployed to production. >> During this for quite a while now, it still comes down to the people. I can get the technology to do what it needs to do as long as they have the right requirements. So that goes back to people making sure we have the partnership that goes back to leadership and the people and then the change management aspects right out of the gate, you should be worrying about how this change is going to be how it's going to affect, and then the adoption and an engagement, because adoption is critical because you can go create the best thing you think from a technology perspective. But if it doesn't get used correctly, it's not worth the investment. So I agree, what is a digital transformation or innovation? It still comes down to understand the business model and injecting and utilizing technology to grow our reduce costs, grow the business or reduce costs. >> Okay, so look, there's so much other content on theCUBE on Cloud events site we'll put the link in the description below. We have other CEOs like Kathy Southwick and Ellen Nance. We have the CIO of UI path. Daniel Dienes talks about automation in the cloud and Appenzell from Anaplan. And a plan is not her company. By the way, Dave Humphrey from Bain also talks about his $750 million investment in Nutanix. Interesting, Rachel Stevens from red monk talks about the future of software development in the cloud and CTO, Hillary Hunter talks about the cloud going vertical into financial services. And of course, John Furrier and I along with special guests like Sergeant Joe Hall share our take on key trends, data and perspectives. So right here, you see the coupon cloud. There's a URL, check it out again. We'll, we'll pop this URL in the description of the video. So there's some great content there. I want to thank everybody who participated and thank you for watching this special episode of theCUBE Insights Powered by ETR. This is Dave Vellante and I'd appreciate any feedback you might have on how we can deliver better event content for you in the future. We'll be doing a number of these and we look forward to your participation and feedback. Thank you, all right, take care, we'll see you next time. (upbeat music)

Published Date : Jan 22 2021

SUMMARY :

bringing you data-driven and kind of lays out the about COVID is the personal impact to me and GPU is everything to the Whereas in the past, it the only way we get access on the way we go vast. and to absolutely make sure we dealt and the adding more and more customers. And the thing we're talking And the whole idea and analyze it in the care. or in the CIC CD pipeline long before code I can get the technology to of software development in the cloud

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
IBMORGANIZATION

0.99+

Daniel DienesPERSON

0.99+

Zhamak DeghaniPERSON

0.99+

Dave VellantePERSON

0.99+

OracleORGANIZATION

0.99+

John RoesePERSON

0.99+

AWSORGANIZATION

0.99+

Paul GillinPERSON

0.99+

Andy JassyPERSON

0.99+

DellORGANIZATION

0.99+

MicrosoftORGANIZATION

0.99+

Rachel StevensPERSON

0.99+

Maribel LopezPERSON

0.99+

Michael DellPERSON

0.99+

$5,000QUANTITY

0.99+

Chris WolfPERSON

0.99+

2008DATE

0.99+

Joni KlippertPERSON

0.99+

seven-dayQUANTITY

0.99+

AmazonORGANIZATION

0.99+

Dan SheehanPERSON

0.99+

Pradeep SindhuPERSON

0.99+

Dheeraj PandeyPERSON

0.99+

March of 2006DATE

0.99+

RobPERSON

0.99+

Hillary HunterPERSON

0.99+

GoogleORGANIZATION

0.99+

Amit ZaveryPERSON

0.99+

Ellen NancePERSON

0.99+

JG ChirapurathPERSON

0.99+

John FurrierPERSON

0.99+

Dave HumphreyPERSON

0.99+

Simon CrosbyPERSON

0.99+

Mai-Lan BukovecPERSON

0.99+

2009DATE

0.99+

$80 billionQUANTITY

0.99+

Palo AltoLOCATION

0.99+

AlibabaORGANIZATION

0.99+

JohnPERSON

0.99+

11-yearQUANTITY

0.99+

Kristen NicolePERSON

0.99+

DatabricksORGANIZATION

0.99+

LoomioORGANIZATION

0.99+

BostonLOCATION

0.99+

10-plus hoursQUANTITY

0.99+

45 billionQUANTITY

0.99+

HPEORGANIZATION

0.99+

$750 millionQUANTITY

0.99+

7%QUANTITY

0.99+

Holger MuellerPERSON

0.99+

DavePERSON

0.99+

FirstQUANTITY

0.99+

John FurrierPERSON

0.99+

thirdQUANTITY

0.99+

two companiesQUANTITY

0.99+

SecondQUANTITY

0.99+

firstQUANTITY

0.99+

Zeus KaravallaPERSON

0.99+

last yearDATE

0.99+

Kathy SouthwickPERSON

0.99+

secondQUANTITY

0.99+

Constellation ResearchORGANIZATION

0.99+

theCube On Cloud 2021 - Kickoff


 

>>from around the globe. It's the Cube presenting Cuban cloud brought to you by silicon angle, everybody to Cuban cloud. My name is Dave Volonte, and I'll be here throughout the day with my co host, John Ferrier, who was quarantined in an undisclosed location in California. He's all good. Don't worry. Just precautionary. John, how are you doing? >>Hey, great to see you. John. Quarantine. My youngest daughter had covitz, so contact tracing. I was negative in quarantine at a friend's location. All good. >>Well, we wish you the best. Yeah, well, right. I mean, you know what's it like, John? I mean, you're away from your family. Your basically shut in, right? I mean, you go out for a walk, but you're really not in any contact with anybody. >>Correct? Yeah. I mean, basically just isolation, Um, pretty much what everyone's been kind of living on, kind of suffering through, but hopefully the vaccines are being distributed. You know, one of the things we talked about it reinvent the Amazon's cloud conference. Was the vaccine on, but just the whole workflow around that it's gonna get better. It's kind of really sucky. Here in the California area, they haven't done a good job, a lot of criticism around, how that's rolling out. And, you know, Amazon is now offering to help now that there's a new regime in the U. S. Government S o. You know, something to talk about, But certainly this has been a terrible time for Cove it and everyone in the deaths involved. But it's it's essentially pulled back the covers, if you will, on technology and you're seeing everything. Society. In fact, um, well, that's big tech MIT disinformation campaigns. All these vulnerabilities and cyber, um, accelerated digital transformation. We'll talk about a lot today, but yeah, it's totally changed the world. And I think we're in a new generation. I think this is a real inflection point, Dave. You know, modern society and the geo political impact of this is significant. You know, one of the benefits of being quarantined you'd be hanging out on these clubhouse APS, uh, late at night, listening to experts talk about what's going on, and it's interesting what's happening with with things like water and, you know, the island of Taiwan and China and U. S. Sovereignty, data, sovereignty, misinformation. So much going on to talk about. And, uh, meanwhile, companies like Mark injuries in BC firm starting a media company. What's going on? Hell freezing over. So >>we're gonna be talking about a lot of that stuff today. I mean, Cuba on cloud. It's our very first virtual editorial event we're trying to do is bring together our community. It's a it's an open forum and we're we're running the day on our 3 65 software platform. So we got a great lineup. We got CEO Seo's data Practitioners. We got a hard core technologies coming in, cloud experts, investors. We got some analysts coming in and we're creating this day long Siri's. And we've got a number of sessions that we've developed and we're gonna unpack. The future of Cloud computing in the coming decade is, John said, we're gonna talk about some of the public policy new administration. What does that mean for tech and for big tech in General? John, what can you add to that? >>Well, I think one of the things that we talked about Cove in this personal impact to me but other people as well. One of the things that people are craving right now is information factual information, truth texture that we call it. But hear this event for us, Davis, our first inaugural editorial event. Robbo, Kristen, Nicole, the entire Cube team Silicon angle, really trying to put together Morva cadence we're gonna doom or of these events where we can put out feature the best people in our community that have great fresh voices. You know, we do interview the big names Andy Jassy, Michael Dell, the billionaires with people making things happen. But it's often the people under there that are the rial newsmakers amid savory, for instance, that Google one of the most impressive technical people, he's gotta talk. He's gonna present democratization of software development in many Mawr riel people making things happen. And I think there's a communal element. We're going to do more of these. Obviously, we have, uh, no events to go to with the Cube. So we have the cube virtual software that we have been building and over years and now perfecting and we're gonna introduce that we're gonna put it to work, their dog footing it. We're gonna put that software toe work. We're gonna do a lot mawr virtual events like this Cuban cloud Cuban startup Cuban raising money. Cuban healthcare, Cuban venture capital. Always think we could do anything. Question is, what's the right story? What's the most important stories? Who's telling it and increase the aperture of the lens of the industry that we have and and expose that and fastest possible. That's what this software, you'll see more of it. So it's super exciting. We're gonna add new features like pulling people up on stage, Um, kind of bring on the clubhouse vibe and more of a community interaction with people to meet each other, and we'll roll those out. But the goal here is to just showcase it's cloud story in a way from people that are living it and providing value. So enjoy the day is gonna be chock full of presentations. We're gonna have moderated chat in these sessions, so it's an all day event so people can come in, drop out, and also that's everything's on demand immediately after the time slot. But you >>want to >>participate, come into the time slot into the cube room or breakout session. Whatever you wanna call it, it's a cube room, and the people in there chatting and having a watch party. So >>when you're in that home page when you're watching, there's a hero video there. Beneath that, there's a calendar, and you'll see that red line is that red horizontal line of vertical line is rather, it's a linear clock that will show you where we are in the day. If you click on any one of those sessions that will take you into the chat, we'll take you through those in a moment and share with you some of the guests that we have upcoming and and take you through the day what I wanted to do. John is trying to set the stage for the conversations that folks are gonna here today. And to do that, I wanna ask the guys to bring up a graphic. And I want to talk to you, John, about the progression of cloud over time and maybe go back to the beginning and review the evolution of cloud and then really talk a little bit about where we think it Z headed. So, guys, if you bring up that graphic when a W S announced s three, it was March of 2000 and six. And as you recall, John you know, nobody really. In the vendor and user community. They didn't really pay too much attention to that. And then later that year, in August, it announced E C two people really started. They started to think about a new model of computing, but they were largely, you know, chicken tires. And it was kind of bleeding edge developers that really leaned in. Um what? What were you thinking at the time? When when you saw, uh, s three e c to this retail company coming into the tech world? >>I mean, I thought it was totally crap. I'm like, this is terrible. But then at that time, I was thinking working on I was in between kind of start ups and I didn't have a lot of seed funding. And then I realized the C two was freaking awesome. But I'm like, Holy shit, this is really great because I don't need to pay a lot of cash, the Provisional Data center, or get a server. Or, you know, at that time, state of the art startup move was to buy a super micro box or some sort of power server. Um, it was well past the whole proprietary thing. But you have to assemble probably anyone with 5 to 8 grand box and go in, and we'll put a couple ghetto rack, which is basically, uh, you know, you put it into some coasting location. It's like with everybody else in the tech ghetto of hosting, still paying monthly fees and then maintaining it and provisioning that's just to get started. And then Amazon was just really easy. And then from there you just It was just awesome. I just knew Amazon would be great. They had a lot of things that they had to fix. You know, custom domains and user interface Council got better and better, but it was awesome. >>Well, what we really saw the cloud take hold from my perspective anyway, was the financial crisis in, you know, 709 It put cloud on the radar of a number of CFOs and, of course, shadow I T departments. They wanted to get stuff done and and take I t in in in, ah, pecs, bite sized chunks. So it really was. There's cloud awakening and we came out of that financial crisis, and this we're now in this 10 year plus boom um, you know, notwithstanding obviously the economic crisis with cove it. But much of it was powered by the cloud in the decade. I would say it was really about I t transformation. And it kind of ironic, if you will, because the pandemic it hits at the beginning of this decade, >>and it >>creates this mandate to go digital. So you've you've said a lot. John has pulled forward. It's accelerated this industry transformation. Everybody talks about that, but and we've highlighted it here in this graphic. It probably would have taken several more years to mature. But overnight you had this forced march to digital. And if you weren't a digital business, you were kind of out of business. And and so it's sort of here to stay. How do you see >>You >>know what this evolution and what we can expect in the coming decades? E think it's safe to say the last 10 years defined by you know, I t transformation. That's not gonna be the same in the coming years. How do you see it? >>It's interesting. I think the big tech companies are on, but I think this past election, the United States shows um, the power that technology has. And if you look at some of the main trends in the enterprise specifically around what clouds accelerating, I call the second wave of innovations coming where, um, it's different. It's not what people expect. Its edge edge computing, for instance, has talked about a lot. But industrial i o t. Is really where we've had a lot of problems lately in terms of hacks and malware and just just overall vulnerabilities, whether it's supply chain vulnerabilities, toe actual disinformation, you know, you know, vulnerabilities inside these networks s I think this network effects, it's gonna be a huge thing. I think the impact that tech will have on society and global society geopolitical things gonna be also another one. Um, I think the modern application development of how applications were written with data, you know, we always been saying this day from the beginning of the Cube data is his integral part of the development process. And I think more than ever, when you think about cloud and edge and this distributed computing paradigm, that cloud is now going next level with is the software and how it's written will be different. You gotta handle things like, where's the compute component? Is it gonna be at the edge with all the server chips, innovations that Amazon apple intel of doing, you're gonna have compute right at the edge, industrial and kind of human edge. How does that work? What's Leighton see to that? It's it really is an edge game. So to me, software has to be written holistically in a system's impact on the way. Now that's not necessarily nude in the computer science and in the tech field, it's just gonna be deployed differently. So that's a complete rewrite, in my opinion of the software applications. Which is why you're seeing Amazon Google VM Ware really pushing Cooper Netease and these service messes in the micro Services because super critical of this technology become smarter, automated, autonomous. And that's completely different paradigm in the old full stack developer, you know, kind of model. You know, the full stack developer, his ancient. There's no such thing as a full stack developer anymore, in my opinion, because it's a half a stack because the cloud takes up the other half. But no one wants to be called the half stack developer because it doesn't sound as good as Full Stack, but really Cloud has eliminated the technology complexity of what a full stack developer used to dio. Now you can manage it and do things with it, so you know, there's some work to done, but the heavy lifting but taking care of it's the top of the stack that I think is gonna be a really critical component. >>Yeah, and that that sort of automation and machine intelligence layer is really at the top of the stack. This this thing becomes ubiquitous, and we now start to build businesses and new processes on top of it. I wanna I wanna take a look at the Big Three and guys, Can we bring up the other The next graphic, which is an estimate of what the revenue looks like for the for the Big three. And John, this is I asked and past spend for the Big Three Cloud players. And it's It's an estimate that we're gonna update after earning seasons, and I wanna point a couple things out here. First is if you look at the combined revenue production of the Big Three last year, it's almost 80 billion in infrastructure spend. I mean, think about that. That Z was that incremental spend? No. It really has caused a lot of consolidation in the on Prem data center business for guys like Dell. And, you know, um, see, now, part of the LHP split up IBM Oracle. I mean, it's etcetera. They've all felt this sea change, and they had to respond to it. I think the second thing is you can see on this data. Um, it's true that azure and G C P they seem to be growing faster than a W s. We don't know the exact numbers >>because >>A W S is the only company that really provides a clean view of i s and pass. Whereas Microsoft and Google, they kind of hide the ball in their numbers. I mean, I don't blame them because they're behind, but they do leave breadcrumbs and clues about growth rates and so forth. And so we have other means of estimating, but it's it's undeniable that azure is catching up. I mean, it's still quite distance the third thing, and before I want to get your input here, John is this is nuanced. But despite the fact that Azure and Google the growing faster than a W s. You can see those growth rates. A W s I'll call this out is the only company by our estimates that grew its business sequentially last quarter. Now, in and of itself, that's not significant. But what is significant is because AWS is so large there $45 billion last year, even if the slower growth rates it's able to grow mawr and absolute terms than its competitors, who are basically flat to down sequentially by our estimates. Eso So that's something that I think is important to point out. Everybody focuses on the growth rates, but it's you gotta look at also the absolute dollars and, well, nonetheless, Microsoft in particular, they're they're closing the gap steadily, and and we should talk more about the competitive dynamics. But I'd love to get your take on on all this, John. >>Well, I mean, the clouds are gonna win right now. Big time with the one the political climate is gonna be favoring Big check. But more importantly, with just talking about covert impact and celebrating the digital transformation is gonna create a massive rising tide. It's already happening. It's happening it's happening. And again, this shift in programming, uh, models are gonna really kinda accelerating, create new great growth. So there's no doubt in my mind of all three you're gonna win big, uh, in the future, they're just different, You know, the way they're going to market position themselves, they have to be. Google has to be a little bit different than Amazon because they're smaller and they also have different capabilities, then trying to catch up. So if you're Google or Microsoft, you have to have a competitive strategy to decide. How do I wanna ride the tide If you will put the rising tide? Well, if I'm Amazon, I mean, if I'm Microsoft and Google, I'm not going to try to go frontal and try to copy Amazon because Amazon is just pounding lead of features and scale and they're different. They were, I would say, take advantage of the first mover of pure public cloud. They really awesome. It passed and I, as they've integrated in Gardner, now reports and integrated I as and passed components. So Gardner finally got their act together and said, Hey, this is really one thing. SAS is completely different animal now Microsoft Super Smart because they I think they played the right card. They have a huge installed base converted to keep office 3 65 and move sequel server and all their core jewels into the cloud as fast as possible, clarified while filling in the gaps on the product side to be cloud. So you know, as you're doing trends job, they're just it's just pedal as fast as you can. But Microsoft is really in. The strategy is just go faster trying. Keep pedaling fast, get the features, feature velocity and try to make it high quality. Google is a little bit different. They have a little power base in terms of their network of strong, and they have a lot of other big data capabilities, so they have to use those to their advantage. So there is. There is there is competitive strategy game application happening with these companies. It's not like apples, the apples, In my opinion, it never has been, and I think that's funny that people talk about it that way. >>Well, you're bringing up some great points. I want guys bring up the next graphic because a lot of things that John just said are really relevant here. And what we're showing is that's a survey. Data from E. T. R R Data partners, like 1400 plus CEOs and I T buyers and on the vertical axis is this thing called Net score, which is a measure of spending momentum. And the horizontal axis is is what's called market share. It's a measure of the pervasiveness or, you know, number of mentions in the data set. There's a couple of key points I wanna I wanna pick up on relative to what John just said. So you see A W S and Microsoft? They stand alone. I mean, they're the hyper scale er's. They're far ahead of the pack and frankly, they have fall down, toe, lose their lead. They spend a lot on Capex. They got the flywheel effects going. They got both spending velocity and large market shares, and so, but they're taking a different approach. John, you're right there living off of their SAS, the state, their software state, Andi, they're they're building that in to their cloud. So they got their sort of a captive base of Microsoft customers. So they've got that advantage. They also as we'll hear from from Microsoft today. They they're building mawr abstraction layers. Andy Jassy has said We don't wanna be in that abstraction layer business. We wanna have access to those, you know, fine grain primitives and eso at an AP level. So so we can move fast with the market. But but But so those air sort of different philosophies, John? >>Yeah. I mean, you know, people who know me know that I love Amazon. I think their product is superior at many levels on in its way that that has advantages again. They have a great sass and ecosystem. They don't really have their own SAS play, although they're trying to add some stuff on. I've been kind of critical of Microsoft in the past, but one thing I'm not critical of Microsoft, and people can get this wrong in the marketplace. Actually, in the journalism world and also in just some other analysts, Microsoft has always had large scale eso to say that Microsoft never had scale on that Amazon owned the monopoly on our franchise on scales wrong. Microsoft had scale from day one. Their business was always large scale global. They've always had infrastructure with MSN and their search and the distributive how they distribute browsers and multiple countries. Remember they had the lock on the operating system and the browser for until the government stepped in in 1997. And since 1997 Microsoft never ever not invested in infrastructure and scale. So that whole premise that they don't compete well there is wrong. And I think that chart demonstrates that there, in there in the hyper scale leadership category, hands down the question that I have. Is that there not as good and making that scale integrate in because they have that legacy cards. This is the classic innovator's dilemma. Clay Christensen, right? So I think they're doing a good job. I think their strategy sound. They're moving as fast as they can. But then you know they're not gonna come out and say We don't have the best cloud. Um, that's not a marketing strategy. Have to kind of hide in this and get better and then double down on where they're winning, which is. Clients are converting from their legacy at the speed of Microsoft, and they have a huge client base, So that's why they're stopping so high That's why they're so good. >>Well, I'm gonna I'm gonna give you a little preview. I talked to gear up your f Who's gonna come on today and you'll see I I asked him because the criticism of Microsoft is they're, you know, they're just good enough. And so I asked him, Are you better than good enough? You know, those are fighting words if you're inside of Microsoft, but so you'll you'll have to wait to see his answer. Now, if you guys, if you could bring that that graphic back up I wanted to get into the hybrid zone. You know where the field is. Always got >>some questions coming in on chat, Dave. So we'll get to those >>great Awesome. So just just real quick Here you see this hybrid zone, this the field is bunched up, and the other companies who have a large on Prem presence and have been forced to initiate some kind of coherent cloud strategy included. There is Michael Michael, multi Cloud, and Google's there, too, because they're far behind and they got to take a different approach than a W s. But as you can see, so there's some real progress here. VM ware cloud on AWS stands out, as does red hat open shift. You got VM Ware Cloud, which is a VCF Cloud Foundation, even Dell's cloud. And you'd expect HP with Green Lake to be picking up momentum in the future quarters. And you've got IBM and Oracle, which there you go with the innovator's dilemma. But there, at least in the cloud game, and we can talk about that. But so, John, you know, to your point, you've gotta have different strategies. You're you're not going to take out the big too. So you gotta play, connect your print your on Prem to your cloud, your hybrid multi cloud and try to create new opportunities and new value there. >>Yeah, I mean, I think we'll get to the question, but just that point. I think this Zeri Chen's come on the Cube many times. We're trying to get him to come on lunch today with Features startup, but he's always said on the Q B is a V C at Greylock great firm. Jerry's Cloud genius. He's been there, but he made a point many, many years ago. It's not a winner. Take all the winner. Take most, and the Big Three maybe put four or five in there. We'll take most of the markets here. But I think one of the things that people are missing and aren't talking about Dave is that there's going to be a second tier cloud, large scale model. I don't want to say tear to cloud. It's coming to sound like a sub sub cloud, but a new category of cloud on cloud, right? So meaning if you get a snowflake, did I think this is a tale? Sign to what's coming. VM Ware Cloud is a native has had huge success, mainly because Amazon is essentially enabling them to be successful. So I think is going to be a wave of a more of a channel model of indirect cloud build out where companies like the Cube, potentially for media or others, will build clouds on top of the cloud. So if Google, Microsoft and Amazon, whoever is the first one to really enable that okay, we'll do extremely well because that means you can compete with their scale and create differentiation on top. So what snowflake did is all on Amazon now. They kind of should go to azure because it's, you know, politically correct that have multiple clouds and distribution and business model shifts. But to get that kind of performance they just wrote on Amazon. So there's nothing wrong with that. Because you're getting paid is variable. It's cap ex op X nice categorization. So I think that's the way that we're watching. I think it's super valuable, I think will create some surprises in terms of who might come out of the woodwork on be a leader in a category. Well, >>your timing is perfect, John and we do have some questions in the chat. But before we get to that, I want to bring in Sargi Joe Hall, who's a contributor to to our community. Sargi. Can you hear us? All right, so we got, uh, while >>bringing in Sarpy. Let's go down from the questions. So the first question, Um, we'll still we'll get the student second. The first question. But Ronald ask, Can a vendor in 2021 exist without a hybrid cloud story? Well, story and capabilities. Yes, they could live with. They have to have a story. >>Well, And if they don't own a public cloud? No. No, they absolutely cannot. Uh hey, Sergey. How you doing, man? Good to see you. So, folks, let me let me bring in Sergeant Kohala. He's a He's a cloud architect. He's a practitioner, He's worked in as a technologist. And there's a frequent guest on on the Cube. Good to see you, my friend. Thanks for taking the time with us. >>And good to see you guys to >>us. So we were kind of riffing on the competitive landscape we got. We got so much to talk about this, like, it's a number of questions coming in. Um, but Sargi we wanna talk about you know, what's happening here in Cloud Land? Let's get right into it. I mean, what do you guys see? I mean, we got yesterday. New regime, new inaug inauguration. Do you do you expect public policy? You'll start with you Sargi to have What kind of effect do you think public policy will have on, you know, cloud generally specifically, the big tech companies, the tech lash. Is it gonna be more of the same? Or do you see a big difference coming? >>I think that there will be some changing narrative. I believe on that. is mainly, um, from the regulators side. A lot has happened in one month, right? So people, I think are losing faith in high tech in a certain way. I mean, it doesn't, uh, e think it matters with camp. You belong to left or right kind of thing. Right? But parlor getting booted out from Italy s. I think that was huge. Um, like, how do you know that if a cloud provider will not boot you out? Um, like, what is that line where you draw the line? What are the rules? I think that discussion has to take place. Another thing which has happened in the last 23 months is is the solar winds hack, right? So not us not sort acknowledging that I was Russia and then wish you watching it now, new administration might have a different sort of Boston on that. I think that's huge. I think public public private partnership in security arena will emerge this year. We have to address that. Yeah, I think it's not changing. Uh, >>economics economy >>will change gradually. You know, we're coming out off pandemic. The money is still cheap on debt will not be cheap. for long. I think m and a activity really will pick up. So those are my sort of high level, Uh, >>thank you. I wanna come back to them. And because there's a question that chat about him in a But, John, how do you see it? Do you think Amazon and Google on a slippery slope booting parlor off? I mean, how do they adjudicate between? Well, what's happening in parlor? Uh, anything could happen on clubhouse. Who knows? I mean, can you use a I to find that stuff? >>Well, that's I mean, the Amazons, right? Hiding right there bunkered in right now from that bad, bad situation. Because again, like people we said Amazon, these all three cloud players win in the current environment. Okay, Who wins with the U. S. With the way we are China, Russia, cloud players. Okay, let's face it, that's the reality. So if I wanted to reset the world stage, you know what better way than the, you know, change over the United States economy, put people out of work, make people scared, and then reset the entire global landscape and control all with cash? That's, you know, conspiracy theory. >>So you see the riches, you see the riches, get the rich, get richer. >>Yeah, well, that's well, that's that. That's kind of what's happening, right? So if you start getting into this idea that you can't actually have an app on site because the reason now I'm not gonna I don't know the particular parlor, but apparently there was a reason. But this is dangerous, right? So what? What that's gonna do is and whether it's right or wrong or not, whether political opinion is it means that they were essentially taken offline by people that weren't voted for that. Weren't that when people didn't vote for So that's not a democracy, right? So that's that's a different kind of regime. What it's also going to do is you also have this groundswell of decentralized thinking, right. So you have a whole wave of crypto and decentralized, um, cyber punks out there who want to decentralize it. So all of this stuff in January has created a huge counterculture, and I had predicted this so many times in the Cube. David counterculture is coming and and you already have this kind of counterculture between centralized and decentralized thinking and so I think the Amazon's move is dangerous at a fundamental level. Because if you can't get it, if you can't get buy domain names and you're completely blackballed by by organized players, that's a Mafia, in my opinion. So, uh, and that and it's also fuels the decentralized move because people say, Hey, if that could be done to them, it could be done to me. Just the fact that it could be done will promote a swing in the other direction. I >>mean, independent of of, you know, again, somebody said your political views. I mean Parlor would say, Hey, we're trying to clean this stuff up now. Maybe they didn't do it fast enough, but you think about how new parlor is. You think about the early days of Twitter and Facebook, so they were sort of at a disadvantage. Trying to >>have it was it was partly was what it was. It was a right wing stand up job of standing up something quick. Their security was terrible. If you look at me and Cory Quinn on be great to have him, and he did a great analysis on this, because if you look the lawsuit was just terrible. Security was just a half, asshole. >>Well, and the experience was horrible. I mean, it's not It was not a great app, but But, like you said, it was a quick stew. Hand up, you know, for an agenda. But nonetheless, you know, to start, get to your point earlier. It's like, you know, Are they gonna, you know, shut me down? If I say something that's, you know, out of line, or how do I control that? >>Yeah, I remember, like, 2019, we involved closing sort of remarks. I was there. I was saying that these companies are gonna be too big to fail. And also, they're too big for other nations to do business with. In a way, I think MNCs are running the show worldwide. They're running the government's. They are way. Have seen the proof of that in us this year. Late last year and this year, um, Twitter last night blocked Chinese Ambassador E in us. Um, from there, you know, platform last night and I was like, What? What's going on? So, like, we used to we used to say, like the Chinese company, tech companies are in bed with the Chinese government. Right. Remember that? And now and now, Actually, I think Chinese people can say the same thing about us companies. Uh, it's not a good thing. >>Well, let's >>get some question. >>Let's get some questions from the chat. Yeah. Thank you. One is on M and a subject you mentioned them in a Who do you see is possible emanate targets. I mean, I could throw a couple out there. Um, you know, some of the cdn players, maybe aka my You know, I like I like Hashi Corp. I think they're doing some really interesting things. What do you see? >>Nothing. Hashi Corp. And anybody who's doing things in the periphery is a candidate for many by the big guys, you know, by the hyper scholars and number two tier two or five hyper scholars. Right. Uh, that's why sales forces of the world and stuff like that. Um, some some companies, which I thought there will be a target, Sort of. I mean, they target they're getting too big, because off their evaluations, I think how she Corpuz one, um, >>and >>their bunch in the networking space. Uh, well, Tara, if I say the right that was acquired by at five this week, this week or last week, Actually, last week for $500 million. Um, I know they're founder. So, like I found that, Yeah, there's a lot going on on the on the network side on the anything to do with data. Uh, that those air too hard areas in the cloud arena >>data, data protection, John, any any anything you could adhere. >>And I think I mean, I think ej ej is gonna be where the gaps are. And I think m and a activity is gonna be where again, the bigger too big to fail would agree with you on that one. But we're gonna look at white Spaces and say a white space for Amazon is like a monster space for a start up. Right? So you're gonna have these huge white spaces opportunities, and I think it's gonna be an M and a opportunity big time start ups to get bought in. Given the speed on, I think you're gonna see it around databases and around some of these new service meshes and micro services. I mean, >>they there's a There's a question here, somebody's that dons asking why is Google who has the most pervasive tech infrastructure on the planet. Not at the same level of other to hyper scale is I'll give you my two cents is because it took him a long time to get their heads out of their ads. I wrote a piece of around that a while ago on they just they figured out how to learn the enterprise. I mean, John, you've made this point a number of times, but they just and I got a late start. >>Yeah, they're adding a lot of people. If you look at their who their hiring on the Google Cloud, they're adding a lot of enterprise chops in there. They realized this years ago, and we've talked to many of the top leaders, although Curry and hasn't yet sit down with us. Um, don't know what he's hiding or waiting for, but they're clearly not geared up to chicken Pete. You can see it with some some of the things that they're doing, but I mean competed the level of Amazon, but they have strength and they're playing their strength, but they definitely recognize that they didn't have the enterprise motions and people in the DNA and that David takes time people in the enterprise. It's not for the faint of heart. It's unique details that are different. You can't just, you know, swing the Google playbook and saying We're gonna home The enterprises are text grade. They knew that years ago. So I think you're going to see a good year for Google. I think you'll see a lot of change. Um, they got great people in there. On the product marketing side is Dev Solution Architects, and then the SRE model that they have perfected has been strong. And I think security is an area that they could really had a lot of value it. So, um always been a big fan of their huge network and all the intelligence they have that they could bring to bear on security. >>Yeah, I think Google's problem main problem that to actually there many, but one is that they don't They don't have the boots on the ground as compared to um, Microsoft, especially an Amazon actually had a similar problem, but they had a wide breath off their product portfolio. I always talk about feature proximity in cloud context, like if you're doing one thing. You wanna do another thing? And how do you go get that feature? Do you go to another cloud writer or it's right there where you are. So I think Amazon has the feature proximity and they also have, uh, aske Compared to Google, there's skills gravity. Larger people are trained on AWS. I think Google is trying there. So second problem Google is having is that that they're they're more focused on, I believe, um, on the data science part on their sort of skipping the cool components sort of off the cloud, if you will. The where the workloads needs, you know, basic stuff, right? That's like your compute storage and network. And that has to be well, talk through e think e think they will do good. >>Well, so later today, Paul Dillon sits down with Mids Avery of Google used to be in Oracle. He's with Google now, and he's gonna push him on on the numbers. You know, you're a distant third. Does that matter? And of course, you know, you're just a preview of it's gonna say, Well, no, we don't really pay attention to that stuff. But, John, you said something earlier that. I think Jerry Chen made this comment that, you know, Is it a winner? Take all? No, but it's a winner. Take a lot. You know the number two is going to get a big chunk of the pie. It appears that the markets big enough for three. But do you? Does Google have to really dramatically close the gap on be a much, much closer, you know, to the to the leaders in orderto to compete in this race? Or can they just kind of continue to bump along, siphon off the ad revenue? Put it out there? I mean, I >>definitely can compete. I think that's like Google's in it. Then it they're not. They're not caving, right? >>So But But I wrote I wrote recently that I thought they should even even put mawr oven emphasis on the cloud. I mean, maybe maybe they're already, you know, doubling down triple down. I just I think that is a multi trillion dollar, you know, future for the industry. And, you know, I think Google, believe it or not, could even do more. Now. Maybe there's just so much you could dio. >>There's a lot of challenges with these company, especially Google. They're in Silicon Valley. We have a big Social Justice warrior mentality. Um, there's a big debate going on the in the back channels of the tech scene here, and that is that if you want to be successful in cloud, you have to have a good edge strategy, and that involves surveillance, use of data and pushing the privacy limits. Right? So you know, Google has people within the country that will protest contract because AI is being used for war. Yet we have the most unstable geopolitical seen that I've ever witnessed in my lifetime going on right now. So, um, don't >>you think that's what happened with parlor? I mean, Rob Hope said, Hey, bar is pretty high to kick somebody off your platform. The parlor went over the line, but I would also think that a lot of the employees, whether it's Google AWS as well, said, Hey, why are we supporting you know this and so to your point about social justice, I mean, that's not something. That >>parlor was not just social justice. They were trying to throw the government. That's Rob e. I think they were in there to get selfies and being protesters. But apparently there was evidence from what I heard in some of these clubhouse, uh, private chats. Waas. There was overwhelming evidence on parlor. >>Yeah, but my point is that the employee backlash was also a factor. That's that's all I'm saying. >>Well, we have Google is your Google and you have employees to say we will boycott and walk out if you bid on that jet I contract for instance, right, But Microsoft one from maybe >>so. I mean, that's well, >>I think I think Tom Poole's making a really good point here, which is a Google is an alternative. Thio aws. The last Google cloud next that we were asked at they had is all virtual issue. But I saw a lot of I T practitioners in the audience looking around for an alternative to a W s just seeing, though, we could talk about Mano Cloud or Multi Cloud, and Andy Jassy has his his narrative around, and he's true when somebody goes multiple clouds, they put you know most of their eggs in one basket. Nonetheless, I think you know, Google's got a lot of people interested in, particularly in the analytic side, um, in in an alternative, hedging their bets eso and particularly use cases, so they should be able to do so. I guess my the bottom line here is the markets big enough to have Really? You don't have to be the Jack Welch. I gotta be number one and number two in the market. Is that the conclusion here? >>I think so. But the data gravity and the skills gravity are playing against them. Another problem, which I didn't want a couple of earlier was Google Eyes is that they have to boot out AWS wherever they go. Right? That is a huge challenge. Um, most off the most off the Fortune 2000 companies are already using AWS in one way or another. Right? So they are the multi cloud kind of player. Another one, you know, and just pure purely somebody going 200% Google Cloud. Uh, those cases are kind of pure, if you will. >>I think it's gonna be absolutely multi cloud. I think it's gonna be a time where you looked at the marketplace and you're gonna think in terms of disaster recovery, model of cloud or just fault tolerant capabilities or, you know, look at the parlor, the next parlor. Or what if Amazon wakes up one day and said, Hey, I don't like the cubes commentary on their virtual events, so shut them down. We should have a fail over to Google Cloud should Microsoft and Option. And one of people in Microsoft ecosystem wants to buy services from us. We have toe kind of co locate there. So these are all open questions that are gonna be the that will become certain pretty quickly, which is, you know, can a company diversify their computing An i t. In a way that works. And I think the momentum around Cooper Netease you're seeing as a great connective tissue between, you know, having applications work between clouds. Right? Well, directionally correct, in my opinion, because if I'm a company, why wouldn't I wanna have choice? So >>let's talk about this. The data is mixed on that. I'll share some data, meaty our data with you. About half the companies will say Yeah, we're spreading the wealth around to multiple clouds. Okay, That's one thing will come back to that. About the other half were saying, Yeah, we're predominantly mono cloud we didn't have. The resource is. But what I think going forward is that that what multi cloud really becomes. And I think John, you mentioned Snowflake before. I think that's an indicator of what what true multi cloud is going to look like. And what Snowflake is doing is they're building abstraction, layer across clouds. Ed Walsh would say, I'm standing on the shoulders of Giants, so they're basically following points of presence around the globe and building their own cloud. They call it a data cloud with a global mesh. We'll hear more about that later today, but you sign on to that cloud. So they're saying, Hey, we're gonna build value because so many of Amazon's not gonna build that abstraction layer across multi clouds, at least not in the near term. So that's a really opportunity for >>people. I mean, I don't want to sound like I'm dating myself, but you know the date ourselves, David. I remember back in the eighties, when you had open systems movement, right? The part of the whole Revolution OS I open systems interconnect model. At that time, the networking stacks for S N A. For IBM, decadent for deck we all know that was a proprietary stack and then incomes TCP I p Now os I never really happened on all seven layers, but the bottom layers standardized. Okay, that was huge. So I think if you look at a W s or some of the comments in the chat AWS is could be the s n a. Depends how you're looking at it, right? And you could say they're open. But in a way, they want more Amazon. So Amazon's not out there saying we love multi cloud. Why would they promote multi cloud? They are a one of the clouds they want. >>That's interesting, John. And then subject is a cloud architect. I mean, it's it is not trivial to make You're a data cloud. If you're snowflake, work on AWS work on Google. Work on Azure. Be seamless. I mean, certainly the marketing says that, but technically, that's not trivial. You know, there are latent see issues. Uh, you know, So that's gonna take a while to develop. What? Do your thoughts there? >>I think that multi cloud for for same workload and multi cloud for different workloads are two different things. Like we usually put multiple er in one bucket, right? So I think you're right. If you're trying to do multi cloud for the same workload, that's it. That's Ah, complex, uh, problem to solve architecturally, right. You have to have a common ap ice and common, you know, control playing, if you will. And we don't have that yet, and then we will not have that for a for at least one other couple of years. So, uh, if you if you want to do that, then you have to go to the lower, lowest common denominator in technical sort of stock, if you will. And then you're not leveraging the best of the breed technology off their from different vendors, right? I believe that's a hard problem to solve. And in another thing, is that that that I always say this? I'm always on the death side, you know, developer side, I think, uh, two deaths. Public cloud is a proxy for innovative culture. Right. So there's a catch phrase I have come up with today during shower eso. I think that is true. And then people who are companies who use the best of the breed technologies, they can attract the these developers and developers are the Mazen's off This digital sort of empires, amazingly, is happening there. Right there they are the Mazen's right. They head on the bricks. I think if you don't appeal to developers, if you don't but extensive for, like, force behind educating the market, you can't you can't >>put off. It's the same game Stepping story was seeing some check comments. Uh, guard. She's, uh, linked in friend of mine. She said, Microsoft, If you go back and look at the Microsoft early days to the developer Point they were, they made their phones with developers. They were a software company s Oh, hey, >>forget developers, developers, developers. >>You were if you were in the developer ecosystem, you were treated his gold. You were part of the family. If you were outside that world, you were competitors, and that was ruthless times back then. But they again they had. That was where it was today. Look at where the software defined businesses and starve it, saying it's all about being developer lead in this new way to program, right? So the cloud next Gen Cloud is going to look a lot like next Gen Developer and all the different tools and techniques they're gonna change. So I think, yes, this kind of developer ecosystem will be harnessed, and that's the power source. It's just gonna look different. So, >>Justin, Justin in the chat has a comment. I just want to answer the question about elastic thoughts on elastic. Um, I tell you, elastic has momentum uh, doing doing very well in the market place. Thea Elk Stack is a great alternative that people are looking thio relative to Splunk. Who people complain about the pricing. Of course it's plunks got the easy button, but it is getting increasingly expensive. The problem with elk stack is you know, it's open source. It gets complicated. You got a shard, the databases you gotta manage. It s Oh, that's what Ed Walsh's company chaos searches is all about. But elastic has some riel mo mentum in the marketplace right now. >>Yeah, you know, other things that coming on the chat understands what I was saying about the open systems is kubernetes. I always felt was that is a bad metaphor. But they're with me. That was the TCP I peep In this modern era, C t c p I p created that that the disruptor to the S N A s and the network protocols that were proprietary. So what KUBERNETES is doing is creating a connective tissue between clouds and letting the open source community fill in the gaps in the middle, where kind of way kind of probably a bad analogy. But that's where the disruption is. And if you look at what's happened since Kubernetes was put out there, what it's become kind of de facto and standard in the sense that everyone's rallying around it. Same exact thing happened with TCP was people were trashing it. It is terrible, you know it's not. Of course they were trashed because it was open. So I find that to be very interesting. >>Yeah, that's a good >>analogy. E. Thinks the R C a cable. I used the R C. A cable analogy like the VCRs. When they started, they, every VC had had their own cable, and they will work on Lee with that sort of plan of TV and the R C. A cable came and then now you can put any TV with any VCR, and the VCR industry took off. There's so many examples out there around, uh, standards And how standards can, you know, flair that fire, if you will, on dio for an industry to go sort of wild. And another trend guys I'm seeing is that from the consumer side. And let's talk a little bit on the consuming side. Um, is that the The difference wouldn't be to B and B to C is blood blurred because even the physical products are connected to the end user Like my door lock, the August door lock I didn't just put got get the door lock and forget about that. Like I I value the expedience it gives me or problems that gives me on daily basis. So I'm close to that vendor, right? So So the middle men, uh, middle people are getting removed from from the producer off the technology or the product to the consumer. Even even the sort of big grocery players they have their APs now, uh, how do you buy stuff and how it's delivered and all that stuff that experience matters in that context, I think, um, having, uh, to be able to sell to thes enterprises from the Cloud writer Breuder's. They have to have these case studies or all these sample sort off reference architectures and stuff like that. I think whoever has that mawr pushed that way, they are doing better like that. Amazon is Amazon. Because of that reason, I think they have lot off sort off use cases about on top of them. And they themselves do retail like crazy. Right? So and other things at all s. So I think that's a big trend. >>Great. Great points are being one of things. There's a question in there about from, uh, Yaden. Who says, uh, I like the developer Lead cloud movement, But what is the criticality of the executive audience when educating the marketplace? Um, this comes up a lot in some of my conversations around automation. So automation has been a big wave to automate this automate everything. And then everything is a service has become kind of kind of the the executive suite. Kind of like conversation we need to make everything is a service in our business. You seeing people move to that cloud model. Okay, so the executives think everything is a services business strategy, which it is on some level, but then, when they say Take that hill, do it. Developers. It's not that easy. And this is where a lot of our cube conversations over the past few months have been, especially during the cova with cute virtual. This has come up a lot, Dave this idea, and start being around. It's easy to say everything is a service but will implement it. It's really hard, and I think that's where the developer lead Connection is where the executive have to understand that in order to just say it and do it are two different things. That digital transformation. That's a big part of it. So I think that you're gonna see a lot of education this year around what it means to actually do that and how to implement it. >>I'd like to comment on the as a service and subject. Get your take on it. I mean, I think you're seeing, for instance, with HP Green Lake, Dell's come out with Apex. You know IBM as its utility model. These companies were basically taking a page out of what I what I would call a flawed SAS model. If you look at the SAS players, whether it's salesforce or workday, service now s a P oracle. These models are They're really They're not cloud pricing models. They're they're basically you got to commit to a term one year, two year, three year. We'll give you a discount if you commit to the longer term. But you're locked in on you. You probably pay upfront. Or maybe you pay quarterly. That's not a cloud pricing model. And that's why I mean, they're flawed. You're seeing companies like Data Dog, for example. Snowflake is another one, and they're beginning to price on a consumption basis. And that is, I think, one of the big changes that we're going to see this decade is that true cloud? You know, pay by the drink pricing model and to your point, john toe, actually implement. That is, you're gonna need a whole new layer across your company on it is quite complicated it not even to mention how you compensate salespeople, etcetera. The a p. I s of your product. I mean, it is that, but that is a big sea change that I see coming. Subject your >>thoughts. Yeah, I think like you couldn't see it. And like some things for this big tech exacts are hidden in the plain >>sight, right? >>They don't see it. They they have blind spots, like Look at that. Look at Amazon. They went from Melissa and 200 millisecond building on several s, Right, Right. And then here you are, like you're saying, pay us for the whole year. If you don't use the cloud, you lose it or will pay by month. Poor user and all that stuff like that that those a role models, I think these players will be forced to use that term pricing like poor minute or for a second, poor user. That way, I think the Salesforce moral is hybrid. They're struggling in a way. I think they're trying to bring the platform by doing, you know, acquisition after acquisition to be a platform for other people to build on top off. But they're having a little trouble there because because off there, such pricing and little closeness, if you will. And, uh, again, I'm coming, going, going back to developers like, if you are not appealing to developers who are writing the latest and greatest code and it is open enough, by the way open and open source are two different things that we all know that. So if your platform is not open enough, you will have you know, some problems in closing the deals. >>E. I want to just bring up a question on chat around from Justin didn't fitness. Who says can you touch on the vertical clouds? Has your offering this and great question Great CP announcing Retail cloud inventions IBM Athena Okay, I'm a huge on this point because I think this I'm not saying this for years. Cloud computing is about horizontal scalability and vertical specialization, and that's absolutely clear, and you see all the clouds doing it. The vertical rollouts is where the high fidelity data is, and with machine learning and AI efforts coming out, that's accelerated benefits. There you have tow, have the vertical focus. I think it's super smart that clouds will have some sort of vertical engine, if you will in the clouds and build on top of a control playing. Whether that's data or whatever, this is clearly the winning formula. If you look at all the successful kind of ai implementations, the ones that have access to the most data will get the most value. So, um if you're gonna have a data driven cloud you have tow, have this vertical feeling, Um, in terms of verticals, the data on DSO I think that's super important again, just generally is a strategy. I think Google doing a retail about a super smart because their whole pitches were not Amazon on. Some people say we're not Google, depending on where you look at. So every of these big players, they have dominance in the areas, and that's scarce. Companies and some companies will never go to Amazon for that reason. Or some people never go to Google for other reasons. I know people who are in the ad tech. This is a black and we're not. We're not going to Google. So again, it is what it is. But this idea of vertical specialization relevant in super >>forts, I want to bring to point out to sessions that are going on today on great points. I'm glad you asked that question. One is Alan. As he kicks off at 1 p.m. Eastern time in the transformation track, he's gonna talk a lot about the coming power of ecosystems and and we've talked about this a lot. That that that to compete with Amazon, Google Azure, you've gotta have some kind of specialization and vertical specialization is a good one. But of course, you see in the big Big three also get into that. But so he's talking at one o'clock and then it at 3 36 PM You know this times are strange, but e can explain that later Hillary Hunter is talking about she's the CTO IBM I B M's ah Financial Cloud, which is another really good example of specifying vertical requirements and serving. You know, an audience subject. I think you have some thoughts on this. >>Actually, I lost my thought. E >>think the other piece of that is data. I mean, to the extent that you could build an ecosystem coming back to Alan Nancy's premise around data that >>billions of dollars in >>their day there's billions of dollars and that's the title of the session. But we did the trillion dollar baby post with Jazzy and said Cloud is gonna be a trillion dollars right? >>And and the point of Alan Answer session is he's thinking from an individual firm. Forget the millions that you're gonna save shifting to the cloud on cost. There's billions in ecosystems and operating models. That's >>absolutely the business value. Now going back to my half stack full stack developer, is the business value. I've been talking about this on the clubhouses a lot this past month is for the entrepreneurs out there the the activity in the business value. That's the new the new intellectual property is the business logic, right? So if you could see innovations in how work streams and workflow is gonna be a configured differently, you have now large scale cloud specialization with data, you can move quickly and take territory. That's much different scenario than a decade ago, >>at the point I was trying to make earlier was which I know I remember, is that that having the horizontal sort of features is very important, as compared to having vertical focus. You know, you're you're more healthcare focused like you. You have that sort of needs, if you will, and you and our auto or financials and stuff like that. What Google is trying to do, I think that's it. That's a good thing. Do cook up the reference architectures, but it's a bad thing in a way that you drive drive away some developers who are most of the developers at 80 plus percent, developers are horizontal like you. Look at the look into the psyche of a developer like you move from company to company. And only few developers will say I will stay only in health care, right? So I will only stay in order or something of that, right? So they you have to have these horizontal capabilities which can be applied anywhere on then. On top >>of that, I think that's true. Sorry, but I'll take a little bit different. Take on that. I would say yes, that's true. But remember, remember the old school application developer Someone was just called in Application developer. All they did was develop applications, right? They pick the framework, they did it right? So I think we're going to see more of that is just now mawr of Under the Covers developers. You've got mawr suffer defined networking and software, defined storage servers and cloud kubernetes. And it's kind of like under the hood. But you got your, you know, classic application developer. I think you're gonna see him. A lot of that come back in a way that's like I don't care about anything else. And that's the promise of cloud infrastructure is code. So I think this both. >>Hey, I worked. >>I worked at people solved and and I still today I say into into this context, I say E r P s are the ultimate low code. No code sort of thing is right. And what the problem is, they couldn't evolve. They couldn't make it. Lightweight, right? Eso um I used to write applications with drag and drop, you know, stuff. Right? But But I was miserable as a developer. I didn't Didn't want to be in the applications division off PeopleSoft. I wanted to be on the tools division. There were two divisions in most of these big companies ASAP. Oracle. Uh, like companies that divisions right? One is the cooking up the tools. One is cooking up the applications. The basketball was always gonna go to the tooling. Hey, >>guys, I'm sorry. We're almost out of time. I always wanted to t some of the sections of the day. First of all, we got Holder Mueller coming on at lunch for a power half hour. Um, you'll you'll notice when you go back to the home page. You'll notice that calendar, that linear clock that we talked about that start times are kind of weird like, for instance, an appendix coming on at 1 24. And that's because these air prerecorded assets and rather than having a bunch of dead air, we're just streaming one to the other. So so she's gonna talk about people, process and technology. We got Kathy Southwick, whose uh, Silicon Valley CEO Dan Sheehan was the CEO of Dunkin Brands and and he was actually the c 00 So it's C A CEO connecting the dots to the business. Daniel Dienes is the CEO of you I path. He's coming on a 2:47 p.m. East Coast time one of the hottest companies, probably the fastest growing software company in history. We got a guy from Bain coming on Dave Humphrey, who invested $750 million in Nutanix. He'll explain why and then, ironically, Dheeraj Pandey stew, Minuteman. Our friend interviewed him. That's 3 35. 1 of the sessions are most excited about today is John McD agony at 403 p. M. East Coast time, she's gonna talk about how to fix broken data architectures, really forward thinking stuff. And then that's the So that's the transformation track on the future of cloud track. We start off with the Big Three Milan Thompson Bukovec. At one oclock, she runs a W s storage business. Then I mentioned gig therapy wrath at 1. 30. He runs Azure is analytics. Business is awesome. Paul Dillon then talks about, um, IDs Avery at 1 59. And then our friends to, um, talks about interview Simon Crosby. I think I think that's it. I think we're going on to our next session. All right, so keep it right there. Thanks for watching the Cuban cloud. Uh huh.

Published Date : Jan 22 2021

SUMMARY :

cloud brought to you by silicon angle, everybody I was negative in quarantine at a friend's location. I mean, you go out for a walk, but you're really not in any contact with anybody. And I think we're in a new generation. The future of Cloud computing in the coming decade is, John said, we're gonna talk about some of the public policy But the goal here is to just showcase it's Whatever you wanna call it, it's a cube room, and the people in there chatting and having a watch party. that will take you into the chat, we'll take you through those in a moment and share with you some of the guests And then from there you just It was just awesome. And it kind of ironic, if you will, because the pandemic it hits at the beginning of this decade, And if you weren't a digital business, you were kind of out of business. last 10 years defined by you know, I t transformation. And if you look at some of the main trends in the I think the second thing is you can see on this data. Everybody focuses on the growth rates, but it's you gotta look at also the absolute dollars and, So you know, as you're doing trends job, they're just it's just pedal as fast as you can. It's a measure of the pervasiveness or, you know, number of mentions in the data set. And I think that chart demonstrates that there, in there in the hyper scale leadership category, is they're, you know, they're just good enough. So we'll get to those So just just real quick Here you see this hybrid zone, this the field is bunched But I think one of the things that people are missing and aren't talking about Dave is that there's going to be a second Can you hear us? So the first question, Um, we'll still we'll get the student second. Thanks for taking the time with us. I mean, what do you guys see? I think that discussion has to take place. I think m and a activity really will pick up. I mean, can you use a I to find that stuff? So if I wanted to reset the world stage, you know what better way than the, and that and it's also fuels the decentralized move because people say, Hey, if that could be done to them, mean, independent of of, you know, again, somebody said your political views. and he did a great analysis on this, because if you look the lawsuit was just terrible. But nonetheless, you know, to start, get to your point earlier. you know, platform last night and I was like, What? you know, some of the cdn players, maybe aka my You know, I like I like Hashi Corp. for many by the big guys, you know, by the hyper scholars and if I say the right that was acquired by at five this week, And I think m and a activity is gonna be where again, the bigger too big to fail would agree with Not at the same level of other to hyper scale is I'll give you network and all the intelligence they have that they could bring to bear on security. The where the workloads needs, you know, basic stuff, right? the gap on be a much, much closer, you know, to the to the leaders in orderto I think that's like Google's in it. I just I think that is a multi trillion dollar, you know, future for the industry. So you know, Google has people within the country that will protest contract because I mean, Rob Hope said, Hey, bar is pretty high to kick somebody off your platform. I think they were in there to get selfies and being protesters. Yeah, but my point is that the employee backlash was also a factor. I think you know, Google's got a lot of people interested in, particularly in the analytic side, is that they have to boot out AWS wherever they go. I think it's gonna be a time where you looked at the marketplace and you're And I think John, you mentioned Snowflake before. I remember back in the eighties, when you had open systems movement, I mean, certainly the marketing says that, I think if you don't appeal to developers, if you don't but extensive She said, Microsoft, If you go back and look at the Microsoft So the cloud next Gen Cloud is going to look a lot like next Gen Developer You got a shard, the databases you gotta manage. And if you look at what's happened since Kubernetes was put out there, what it's become the producer off the technology or the product to the consumer. Okay, so the executives think everything is a services business strategy, You know, pay by the drink pricing model and to your point, john toe, actually implement. Yeah, I think like you couldn't see it. I think they're trying to bring the platform by doing, you know, acquisition after acquisition to be a platform the ones that have access to the most data will get the most value. I think you have some thoughts on this. Actually, I lost my thought. I mean, to the extent that you could build an ecosystem coming back to Alan Nancy's premise But we did the trillion dollar baby post with And and the point of Alan Answer session is he's thinking from an individual firm. So if you could see innovations Look at the look into the psyche of a developer like you move from company to company. And that's the promise of cloud infrastructure is code. I say E r P s are the ultimate low code. Daniel Dienes is the CEO of you I path.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
SergeyPERSON

0.99+

JohnPERSON

0.99+

CaliforniaLOCATION

0.99+

Andy JassyPERSON

0.99+

MicrosoftORGANIZATION

0.99+

AmazonORGANIZATION

0.99+

JustinPERSON

0.99+

Daniel DienesPERSON

0.99+

GoogleORGANIZATION

0.99+

John FerrierPERSON

0.99+

Dave VolontePERSON

0.99+

IBMORGANIZATION

0.99+

RonaldPERSON

0.99+

Jerry ChenPERSON

0.99+

DavidPERSON

0.99+

Ed WalshPERSON

0.99+

Michael DellPERSON

0.99+

DavePERSON

0.99+

Kathy SouthwickPERSON

0.99+

Paul DillonPERSON

0.99+

OracleORGANIZATION

0.99+

Rob HopePERSON

0.99+

DellORGANIZATION

0.99+

1997DATE

0.99+

TaraPERSON

0.99+

HPORGANIZATION

0.99+

Dan SheehanPERSON

0.99+

Simon CrosbyPERSON

0.99+

AlanPERSON

0.99+

DevOps Virtual Forum 2020 | Broadcom


 

>>From around the globe. It's the queue with digital coverage of dev ops virtual forum brought to you by Broadcom. >>Hi, Lisa Martin here covering the Broadcom dev ops virtual forum. I'm very pleased to be joined today by a cube alumni, Jeffrey Hammond, the vice president and principal analyst serving CIO is at Forester. Jeffrey. Nice to talk with you today. >>Good morning. It's good to be here. Yeah. >>So a virtual forum, great opportunity to engage with our audiences so much has changed in the last it's an understatement, right? Or it's an overstated thing, but it's an obvious, so much has changed when we think of dev ops. One of the things that we think of is speed, you know, enabling organizations to be able to better serve customers or adapt to changing markets like we're in now, speaking of the need to adapt, talk to us about what you're seeing with respect to dev ops and agile in the age of COVID, what are things looking like? >>Yeah, I think that, um, for most organizations, we're in a, uh, a period of adjustment, uh, when we initially started, it was essentially a sprint, you know, you run as hard as you can for as fast as you can for as long as you can and you just kind of power through it. And, and that's actually what, um, the folks that get hub saw in may when they ran an analysis of how developers, uh, commit times and a level of work that they were committing and how they were working, uh, in the first couple of months of COVID was, was progressing. They found that developers, at least in the Pacific time zone were actually increasing their work volume, maybe because they didn't have two hour commutes or maybe because they were stuck away in their homes, but for whatever reason, they were doing more work. >>And it's almost like, you know, if you've ever run a marathon the first mile or two in the marathon, you feel great and you just want to run and you want to power through it and you want to go hard. And if you do that by the time you get to mile 18 or 19, you're going to be gassed. It's sucking for wind. Uh, and, and that's, I think where we're starting to hit. So as we start to, um, gear our development chops out for the reality that most of us won't be returning into an office until 2021 at the earliest and many organizations will, will be fundamentally changing, uh, their remote workforce, uh, policies. We have to make sure that the agile processes that we use and the dev ops processes and tools that we use to support these teams are essentially aligned to help developers run that marathon instead of just kind of power through. >>So, um, let me give you a couple of specifics for many organizations, they have been in an environment where they will, um, tolerate Rover remote work and what I would call remote work around the edges like developers can be remote, but product managers and, um, you know, essentially scrum masters and all the administrators that are running the, uh, uh, the SCM repositories and, and the dev ops pipelines are all in the office. And it's essentially centralized work. That's not, we are anymore. We're moving from remote workers at the edge to remote workers at the center of what we do. And so one of the implications of that is that, um, we have to think about all the activities that you need to do from a dev ops perspective or from an agile perspective, they have to be remote people. One of the things I found with some of the organizations I talked to early on was there were things that administrators had to do that required them to go into the office to reboot the SCM server as an example, or to make sure that the final approvals for production, uh, were made. >>And so the code could be moved into the production environment. And so it actually was a little bit difficult because they had to get specific approval from the HR organizations to actually be allowed to go into the office in some States. And so one of the, the results of that is that while we've traditionally said, you know, tools are important, but they're not as important as culture as structure as organization as process. I think we have to rethink that a little bit because to the extent that tools enable us to be more digitally organized and to hiring, you know, achieve higher levels of digitization in our processes and be able to support the idea of remote workers in the center. They're now on an equal footing with so many of the other levers, uh, that, that, um, uh, that organizations have at their disposal. Um, I'll give you another example for years. >>We've said that the key to success with agile at the team level is cross-functional co located teams that are working together physically co located. It's the easiest way to show agile success. We can't do that anymore. We can't be physically located at least for the foreseeable future. So, you know, how do you take the low hanging fruits of an agile transformation and apply it in, in, in, in the time of COVID? Well, I think what you have to do is that you have to look at what physical co-location has enabled in the past and understand that it's not so much the fact that we're together looking at each other across the table. It's the fact that we're able to get into a shared mindspace, uh, from, um, uh, from a measurement perspective, we can have shared purpose. We can engage in high bandwidth communications. It's the spiritual aspect of that physical co-location that is actually important. So one of the biggest things that organizations need to start to ask themselves is how do we achieve spiritual colocation with our agile teams? Because we don't have the, the ease of physical co-location available to us anymore? >>Well, the spiritual co-location is such an interesting kind of provocative phrase there, but something that probably was a challenge here, we are seven, eight months in for many organizations, as you say, going from, you know, physical workspaces, co-location being able to collaborate face to face to a, a light switch flip overnight. And this undefined period of time where all we were living with with was uncertainty, how does spiritual, what do you, when you talk about spiritual co-location in terms of collaboration and processes and technology help us unpack that, and how are you seeing organizations adopted? >>Yeah, it's, it's, um, it's a great question. And, and I think it goes to the very root of how organizations are trying to transform themselves to be more agile and to embrace dev ops. Um, if you go all the way back to the, to the original, uh, agile manifesto, you know, there were four principles that were espoused individuals and interactions over processes and tools. That's still important. Individuals and interactions are at the core of software development, processes and tools that support those individual and interact. Uh, those individuals in those interactions are more important than ever working software over comprehensive documentation. Working software is still more important, but when you are trying to onboard employees and they can't come into the office and they can't do the two day training session and kind of understand how things work and they can't just holler over the cube, uh, to ask a question, you may need to invest a little bit more in documentation to help that onboarding process be successful in a remote context, uh, customer collaboration over contract negotiation. >>Absolutely still important, but employee collaboration is equally as important if you want to be spiritually, spiritually co-located. And if you want to have a shared purpose and then, um, responding to change over following a plan. I think one of the things that's happened in a lot of organizations is we have focused so much of our dev ops effort around velocity getting faster. We need to run as fast as we can like that sprinter. Okay. You know, trying to just power through it as quickly as possible. But as we shift to, to the, to the marathon way of thinking, um, velocity is still important, but agility becomes even more important. So when you have to create an application in three weeks to do track and trace for your employees, agility is more important. Um, and then just flat out velocity. Um, and so changing some of the ways that we think about dev ops practices, um, is, is important to make sure that that agility is there for one thing, you have to defer decisions as far down the chain to the team level as possible. >>So those teams have to be empowered to make decisions because you can't have a program level meeting of six or seven teams and one large hall and say, here's the lay of the land. Here's what we're going to do here are our processes. And here are our guardrails. Those teams have to make decisions much more quickly that developers are actually developing code in smaller chunks of flow. They have to be able to take two hours here or 50 minutes there and do something useful. And so the tools that support us have to become tolerant of the reality of, of, of, of how we're working. So if they work in a way that it allows the team together to take as much autonomy as they can handle, um, to, uh, allow them to communicate in a way that, that, that delivers shared purpose and allows them to adapt and master new technologies, then they're in the zone in their spiritual, they'll get spiritually connected. I hope that makes sense. >>It does. I think we all could use some of that, but, you know, you talked about in the beginning and I've, I've talked to numerous companies during the pandemic on the cube about the productivity, or rather the number of hours of work has gone way up for many roles, you know, and, and, and times that they normally late at night on the weekends. So, but it's a cultural, it's a mind shift to your point about dev ops focused on velocity, sprints, sprints, sprints, and now we have to, so that cultural shift is not an easy one for developers. And even at this folks to flip so quickly, what have you seen in terms of the velocity at which businesses are able to get more of that balance between the velocity, the sprint and the agility? >>I think, I think at the core, this really comes down to management sensitivity. Um, when everybody was in the office, you could kind of see the mental health of development teams by, by watching how they work. You know, you call it management by walking around, right. We can't do that. Managers have to, um, to, to be more aware of what their teams are doing, because they're not going to see that, that developer doing a check-in at 9:00 PM on a Friday, uh, because that's what they had to do, uh, to meet the objectives. And, um, and, and they're going to have to, to, um, to find new ways to measure engagement and also potential burnout. Um, friend of mine once had, uh, had a great metric that he called the parking lot metric. It was helpful as the parking lot at nine. And how full was it at five? >>And that gives you an indication of how engaged your developers are. Um, what's the digital equivalent equivalent to the parking lot metric in the time of COVID it's commit stats, it's commit rates. It's, um, you know, the, uh, the turn rate, uh, that we have in our code. So we have this information, we may not be collecting it, but then the next question becomes, how do we use that information? Do we use that information to say, well, this team isn't delivering as at the same level of productivity as another team, do we weaponize that data or do we use that data to identify impedances in the process? Um, why isn't a team working effectively? Is it because they have higher levels of family obligations and they've got kids that, that are at home? Um, is it because they're working with, um, you know, hardware technology, and guess what, they, it's not easy to get the hardware technology into their home office because it's in the lab at the, uh, at the corporate office, uh, or they're trying to communicate, uh, you know, halfway around the world. >>And, uh, they're communicating with a, with an office lab that is also shut down and, and, and the bandwidth just doesn't enable the, the level of high bandwidth communications. So from a dev ops perspective, managers have to get much more sensitive to the, the exhaust that the dev ops tools are throwing off, but also how they're going to use that in a constructive way to, to prevent burnout. And then they also need to, if they're not already managing or monitoring or measuring the level of developer engagement, they have, they really need to start whether that's surveys around developer satisfaction, um, whether it's, you know, more regular social events, uh, where developers can kind of just get together and drink a beer and talk about what's going on in the project, uh, and monitoring who checks in and who doesn't, uh, they have to, to, um, work harder, I think, than they ever have before. >>Well, and you mentioned burnout, and that's something that I think we've all faced in this time at varying levels and it changes. And it's a real, there's a tension in the air, regardless of where you are. There's a challenge, as you mentioned, people having, you know, coworker, their kids as coworkers and fighting for bandwidth, because everyone is forced in this situation. I'd love to get your perspective on some businesses that are, that have done this well, this adaptation, what can you share in terms of some real-world examples that might inspire the audience? >>Yeah. Uh, I'll start with, uh, stack overflow. Uh, they recently published a piece in the journal of the ACM around some of the things that they had discovered. Um, you know, first of all, just a cultural philosophy. If one person is remote, everybody is remote. And you just think that way from an executive level, um, social spaces. One of the things that they talk about doing is leaving a video conference room open at a team level all day long, and the team members, you know, we'll go on mute, you know, so that they don't have to, that they don't necessarily have to be there with somebody else listening to them. But if they have a question, they can just pop off mute really quickly and ask the question. And if anybody else knows the answer, it's kind of like being in that virtual pod. Uh, if you, uh, if you will, um, even here at Forrester, one of the things that we've done is we've invested in social ceremonies. >>We've actually moved our to our team meetings on, on my analyst team from, from once every two weeks to weekly. And we have built more time in for social Ajay socialization, just so we can see, uh, how, how, how we're doing. Um, I think Microsoft has really made some good, uh, information available in how they've managed things like the onboarding process. I think I'm Amanda silver over there mentioned that a couple of weeks ago when, uh, uh, a presentation they did that, uh, uh, Microsoft onboarded over 150,000 people since the start of COVID, if you don't have good remote onboarding processes, that's going to be a disaster. Now they're not all developers, but if you think about it, um, everything from how you do the interviewing process, uh, to how you get people, their badges, to how they get their equipment. Um, security is a, is another issue that they called out typically, uh, it security, um, the security of, of developers machines ends at, at, at the corporate desktop. >>But, you know, since we're increasingly using our own machines, our own hardware, um, security organizations kind of have to extend their security policies to cover, uh, employee devices, and that's caused them to scramble a little bit. Uh, so, so the examples are out there. It's not a lot of, like, we have to do everything completely differently, but it's a lot of subtle changes that, that have to be made. Um, I'll give you another example. Um, one of the things that, that we are seeing is that, um, more and more organizations to deal with the challenges around agility, with respect to delivering software, embracing low-code tools. In fact, uh, we see about 50% of firms are using low-code tools right now. We predict it's going to be 75% by the end of next year. So figuring out how your dev ops processes support an organization that might be using Mendix or OutSystems, or, you know, the power platform building the front end of an application, like a track and trace application really, really quickly, but then hooking it up to your backend infrastructure. Does that happen completely outside the dev ops investments that you're making and the agile processes that you're making, or do you adapt your organization? Um, our hybrid teams now teams that not just have professional developers, but also have business users that are doing some development with a low-code tool. Those are the kinds of things that we have to be, um, willing to, um, to entertain in order to shift the focus a little bit more toward the agility side, I think >>Lot of obstacles, but also a lot of opportunities for businesses to really learn, pay attention here, pivot and grow, and hopefully some good opportunities for the developers and the business folks to just get better at what they're doing and learning to embrace spiritual co-location Jeffrey, thank you so much for joining us on the program today. Very insightful conversation. >>My pleasure. It's it's, it's an important thing. Just remember if you're going to run that marathon, break it into 26, 10 minute runs, take a walk break in between each and you'll find that you'll get there. >>Digestible components, wise advice. Jeffery Hammond. Thank you so much for joining for Jeffrey I'm Lisa Martin, you're watching Broadcom's dev ops virtual forum >>From around the globe. It's the queue with digital coverage of dev ops virtual forum brought to you by Broadcom, >>Continuing our conversations here at Broadcom's dev ops virtual forum. Lisa Martin here, please. To welcome back to the program, Serge Lucio, the general manager of the enterprise software division at Broadcom. Hey, Serge. Welcome. Thank you. Good to be here. So I know you were just, uh, participating with the biz ops manifesto that just happened recently. I just had the chance to talk with Jeffrey Hammond and he unlocked this really interesting concept, but I wanted to get your thoughts on spiritual co-location as really a necessity for biz ops to succeed in this unusual time in which we're living. What are your thoughts on spiritual colocation in terms of cultural change versus adoption of technologies? >>Yeah, it's a, it's, it's quite interesting, right? When we, when we think about the major impediments for, uh, for dev ops implementation, it's all about culture, right? And swore over the last 20 years, we've been talking about silos. We'd be talking about the paradox for these teams to when it went to align in many ways, it's not so much about these teams aligning, but about being in the same car in the same books, right? It's really about fusing those teams around kind of the common purpose, a common objective. So to me, the, this, this is really about kind of changing this culture where people start to look at a kind of OKR is instead of the key objective, um, that, that drives the entire team. Now, what it means in practice is really that's, uh, we need to change a lot of behaviors, right? It's not about the Yarki, it's not about roles. It's about, you know, who can do what and when, and, uh, you know, driving a bias towards action. It also means that we need, I mean, especially in this school times, it becomes very difficult, right? To drive kind of a kind of collaboration between these teams. And so I think there there's a significant role that especially tools can play in terms of providing this complex feedback from teams to, uh, to be in that preface spiritual qualification. >>Well, and it talked about culture being, it's something that, you know, we're so used to talking about dev ops with respect to velocity, all about speed here. But of course this time everything changed so quickly, but going from the physical spaces to everybody being remote really does take it. It's very different than you can't replicate it digitally, but there are collaboration tools that can kind of really be essential to help that cultural shift. Right? >>Yeah. So 2020, we, we touch to talk about collaboration in a very mundane way. Like, of course we can use zoom. We can all get into, into the same room. But the point when I think when Jeff says spiritual, co-location, it's really about, we all share the same objective. Do we, do we have a niece who, for instance, our pipeline, right? When you talk about dev ops, probably we all started thinking about this continuous delivery pipeline that basically drives the automation, the orchestration across the team, but just thinking about a pipeline, right, at the end of the day, it's all about what is the meantime to beat back to these teams. If I'm a developer and a commit code, I don't, does it take where, you know, that code to be processed through pipeline pushy? Can I get feedback if I am a finance person who is funding a product or a project, what is my meantime to beat back? >>And so a lot of, kind of a, when we think about the pipeline, I think what's been really inspiring to me in the last year or so is that there is much more of an adoption of the Dora metrics. There is way more of a focus around value stream management. And to me, this is really when we talk about collaboration, it's really a balance. How do you provide the feedback to the different stakeholders across the life cycle in a very timely matter? And that's what we would need to get to in terms of kind of this, this notion of collaboration. It's not so much about people being in the same physical space. It's about, you know, when I checked in code, you know, to do I guess the system to automatically identify what I'm going to break. If I'm about to release some allegation, how can the system help me reduce my change pillar rates? Because it's, it's able to predict that some issue was introduced in the outpatient or work product. Um, so I think there's, there's a great role of technology and AI candidate Lynch to, to actually provide that new level of collaboration. >>So we'll get to AI in a second, but I'm curious, what are some of the, of the metrics you think that really matter right now is organizations are still in some form of transformation to this new almost 100% remote workforce. >>So I'll just say first, I'm not a big fan of metrics. Um, and the reason being that, you know, you can look at a change killer rate, right, or a lead time or cycle time. And those are, those are interesting metrics, right? The trend on metric is absolutely critical, but what's more important is you get to the root cause what is taught to you lean to that metric to degrade or improve or time. And so I'm much more interested and we, you know, fruit for Broadcom. Are we more interested in understanding what are the patterns that contribute to this? So I'll give you a very mundane example. You know, we know that cycle time is heavily influenced by, um, organizational boundaries. So, you know, we talk a lot about silos, but, uh, we we've worked with many of our customers doing value stream mapping. And oftentimes what you see is that really the boundaries of your organization creates a lot of idle time, right? So to me, it's less about the metrics. I think the door metrics are a pretty, you know, valid set metrics, but what's way more important is to understand what are the antiperspirants, what are the things that we can detect through the data that actually are affecting those metrics. And, uh, I mean, over the last 10, 20 years, we've learned a lot about kind of what are, what are the antiperspirants within our large enterprise customers. And there are plenty of them. >>What are some of the things that you're seeing now with respect to patterns that have developed over the last seven to eight months? >>So I think the two areas which clearly are evolving very quickly are on kind of the front end of the life cycle, where DevOps is more and more embracing value stream management value stream mapping. Um, and I think what's interesting is that in many ways the product is becoming the new silo. Uh, the notion of a product is very difficult by itself to actually define people are starting to recognize that a value stream is not its own little kind of Island. That in reality, when I define a product, this product, oftentimes as dependencies on our products and that in fact, you're looking at kind of a network of value streams, if you will. So, so even on that, and there is clearly kind of a new sets, if you will, of anti-patterns where products are being defined as a set of OTRs, they have interdependencies and you have have a new set of silos on the operands, uh, the Abra key movement to Israel and the SRE space where, um, I think there is a cultural clash while the dev ops side is very much embracing this notion of OTRs and value stream mapping and Belgium management. >>On the other end, you have the it operations teams. We still think business services, right? For them, they think about configure items, think about infrastructure. And so, you know, it's not uncommon to see, you know, teams where, you know, the operations team is still thinking about hundreds of thousands, tens of thousands of business services. And so the, the, there is there's this boundary where, um, I think, well, SRE is being put in place. And there's lots of thinking about what kind of metrics can be fined. I think, you know, going back to culture, I think there's a lot of cultural evolution that's still required for true operations team. >>And that's a hard thing. Cultural transformation in any industry pandemic or not is a challenging thing. You talked about, uh, AI and automation of minutes ago. How do you think those technologies can be leveraged by DevOps leaders to influence their successes and their ability to collaborate, maybe see eye to eye with the SRS? >>Yeah. Um, so th you're kind of too. So even for myself, as a leader of a, you know, 1500 people organization, there's a number of things I don't see right. On a daily basis. And, um, I think the, the, the, the technologies that we have at our disposal today from the AI are able to mind a lot of data and expose a lot of, uh, issues that's as leaders we may not be aware of. And some of the, some of these are pretty kind of easy to understand, right? We all think we're agile. And yet when you, when you start to understand, for instance, uh, what is the, what is the working progress right to during the sprint? Um, when you start to analyze the data you can detect, for instance, that maybe the teams are over committed, that there is too much work in progress. >>You can start to identify kind of, interdepencies either from a technology, from a people point of view, which were hidden, uh, you can start to understand maybe the change filler rates he's he is dragging. So I believe that there is a, there's a fundamental role to be played by the tools to, to expose again, these anti parents, to, to make these things visible to the teams, to be able to even compare teams. Right. One of the things that's, that's, uh, that's amazing is now we have access to tons of data, not just from a given customer, but across a large number of customers. And so we start to compare all of these teams kind of operate, and what's working, what's not working >>Thoughts on AI and automation as, as a facilitator of spiritual co-location. >>Yeah, absolutely. Absolutely. It's um, you know, th there's, uh, the problem we all face is the unknown, right? The, the law city, but volume variety of the data, uh, everyday we don't really necessarily completely appreciate what is the impact of our actions, right? And so, um, AI can really act as a safety net that enables us to, to understand what is the impact of our actions. Um, and so, yeah, in many ways, the ability to be informed in a timely matter to be able to interact with people on the basis of data, um, and collaborate on the data. And the actual matter, I think is, is a, is a very powerful enabler, uh, on, in that respect. I mean, I, I've seen, um, I've seen countless of times that, uh, for instance, at the SRE boundary, um, to basically show that we'll turn the quality attributes, so an incoming release, right. And exposing that to, uh, an operations person and a sorry person, and enabling that collaboration dialogue through data is a very, very powerful tool. >>Do you have any recommendations for how teams can use, you know, the SRE folks, the dev ops says can use AI and automation in the right ways to be successful rather than some ways that aren't going to be nonproductive. >>Yeah. So to me, the th there, there's a part of the question really is when, when we talk about data, there are there different ways you can use data, right? Um, so you can, you can do a lot of an analytics, predictive analytics. So I think there is a, there's a tendency, uh, to look at, let's say a, um, a specific KPI, like a, an availability KPI, or change filler rate, and to basically do a regression analysis and projecting all these things, going to happen in the future. To me, that that's, that's a, that's a bad approach. The reason why I fundamentally think it's a better approach is because we are systems. The way we develop software is, is a, is a non-leader kind of system, right? Software development is not linear nature. And so I think there's a D this is probably the worst approach is to actually focus on metrics on the other end. >>Um, if you, if you start to actually understand at a more granular level, what har, uh, which are the things which are contributing to this, right? So if you start to understand, for instance, that whenever maybe, you know, you affect a specific part of the application that translates into production issues. So we, we have, I've actually, uh, a customer who, uh, identified that, uh, over 50% of their unplanned outages were related to specific components in your architecture. And whenever these components were changed, this resulted in these plant outages. So if you start to be able to basically establish causality, right, cause an effect between kind of data across the last cycle. I think, I think this is the right way to, uh, to, to use AI. And so pharma to be, I think it's way more God could have a classification problem. What are the classes of problems that do exist and affect things as opposed to analytics, predictive, which I don't think is as powerful. >>So I mentioned in the beginning of our conversation, that just came off the biz ops manifesto. You're one of the authors of that. I want to get your thoughts on dev ops and biz ops overlapping, complimenting each other, what, from a, the biz ops perspective, what does it mean to the future of dev ops? >>Yeah, so, so it's interesting, right? If you think about DevOps, um, there's no felony document, right? Can we, we can refer to the Phoenix project. I mean, there are a set of documents which have been written, but in many ways, there's no clear definition of what dev ops is. Uh, if you go to the dev ops Institute today, you'll see that they are specific, um, trainings for instance, on value management on SRE. And so in many ways, the problem we have as an industry is that, um, there are set practices between agile dev ops, SRE Valley should management. I told, right. And we all basically talk about the same things, right. We all talk about essentially, um, accelerating in the meantime fee to feedback, but yet we don't have the common framework to talk about that. The other key thing is that we add to wait, uh, for, uh, for jeans, Jean Kim's Lascaux, um, to, uh, to really start to get into the business aspect, right? >>And for value stream mapping to start to emerge for us to start as an industry, right. It, to start to think about what is our connection with the business aspect, what's our purpose, right? And ultimately it's all about driving these business outcomes. And so to me, these ops is really about kind of, uh, putting a lens on this critical element that it's not business and it, that we in fact need to fuse business 19 that I need needs to transform itself to recognize that it's, it's this value generator, right. It's not a cost center. And so the relationship to me, it's more than BizOps provides kind of this Oliver or kind of framework, if you will. That set the context for what is the reason, uh, for it to exist. What's part of the core values and principles that it needs to embrace to, again, change from a cost center to a value center. And then we need to start to use this as a way to start to unify some of the, again, the core practices, whether it's agile, DevOps value, stream mapping SRE. Um, so, so I think over time, my hope is that we start to optimize a lot of our practices, language, um, and, uh, and cultural elements. >>Last question surgeon, the last few seconds we have here talking about this, the relation between biz ops and dev ops, um, what do you think as DevOps evolves? And as you talked to circle some of your insights, what should our audience keep their eyes on in the next six to 12 months? >>So to me, the key, the key, um, challenge for, for the industry is really around. So we were seeing a very rapid shift towards kind of, uh, product to product, right. Which we don't want to do is to recreate kind of these new silos, these hard silos. Um, so that, that's one of the big changes, uh, that I think we need to be, uh, to be really careful about, um, because it is ultimately, it is about culture. It's not about, uh, it's not about, um, kind of how we segment the work, right. And, uh, any true culture that we can overcome kind of silos. So back to, I guess, with Jeffrey's concept of, um, kind of the spiritual co-location, I think it's, it's really about that too. It's really about kind of, uh, uh, focusing on the business outcomes on kind of aligning on driving engagement across the teams, but, but not for create a, kind of a new set of silos, which instead of being vertical are going to be these horizontal products >>Crazy by surge that looking at culture as kind of a way of really, uh, uh, addressing and helping to, uh, re re reduce, replace challenges. We thank you so much for sharing your insights and your time at today's DevOps virtual forum. >>Thank you. Thanks for your time. >>I'll be right back >>From around the globe it's the cube with digital coverage of devops virtual forum brought to you by Broadcom. >>Welcome to Broadcom's DevOps virtual forum, I'm Lisa Martin, and I'm joined by another Martin, very socially distanced from me all the way coming from Birmingham, England is Glynn Martin, the head of QA transformation at BT. Glynn, it's great to have you on the program. Thank you, Lisa. I'm looking forward to it. As we said before, we went live to Martins for the person one in one segment. So this is going to be an interesting segment guys, what we're going to do is Glynn's going to give us a really kind of deep inside out view of devops from an evolution perspective. So Glynn, let's start. Transformation is at the heart of what you do. It's obviously been a very transformative year. How have the events of this year affected the >> transformation that you are still responsible for driving? Yeah. Thank you, Lisa. I mean, yeah, it has been a difficult year. >>Um, and although working for BT, which is a global telecommunications company, um, I'm relatively resilient, I suppose, as a, an industry, um, through COVID obviously still has been affected and has got its challenges. And if anything, it's actually caused us to accelerate our transformation journey. Um, you know, we had to do some great things during this time around, um, you know, in the UK for our emergency and, um, health workers give them unlimited data and for vulnerable people to support them. And that's spent that we've had to deliver changes quickly. Um, but what we want to be able to do is deliver those kinds of changes quickly, but sustainably for everything that we do, not just because there's an emergency. Um, so we were already on the kind of journey to agile, but ever more important now that we are, we are able to do those, that kind of work, do it more quickly. >>Um, and that it works because the, the implications of it not working is, can be terrible in terms of you know, we've been supporting testing centers,  new hospitals to treat COVID patients. So we need to get it right. And then therefore the coverage of what we do, the quality of what we do and how quickly we do it really has taken on a new scale and what was already a very competitive market within the telco industry within the UK. Um, you know, what I would say is that, you know, we are under pressure to deliver more value, but we have small cost challenges. We have to obviously, um, deal with the fact that, you know, COVID 19 has hit most industries kind of revenues and profits. So we've got this kind of paradox between having less costs, but having to deliver more value quicker and  to higher quality. So yeah, certainly the finances is, um, on our minds and that's why we need flexible models, cost models that allow us to kind of do growth, but we get that growth by showing that we're delivering value. Um, especially in these times when there are financial challenges on companies. So one of the things that I want to ask you about, I'm again, looking at DevOps from the inside >>Out and the evolution that you've seen, you talked about the speed of things really accelerating in this last nine months or so. When we think dev ops, we think speed. But one of the things I'd love to get your perspective on is we've talked about in a number of the segments that we've done for this event is cultural change. What are some of the things that you've seen there as, as needing to get, as you said, get things right, but done so quickly to support essential businesses, essential workers. How have you seen that cultural shift? >>Yeah, I think, you know, before test teams for themselves at this part of the software delivery cycle, um, and actually now really our customers are expecting that quality and to deliver for our customers what they want, quality has to be ingrained throughout the life cycle. Obviously, you know, there's lots of buzzwords like shift left. Um, how do we do shift left testing? Um, but for me, that's really instilling quality and given capabilities shared capabilities throughout the life cycle that drive automation, drive improvements. I always say that, you know, you're only as good as your lowest common denominator. And one thing that we were finding on our dev ops journey was that we  would be trying to do certain things quick, we had automated build, automated tests. But if we were taking a weeks to create test scripts, or we were taking weeks to manually craft data, and even then when we had taken so long to do it, that the coverage was quite poor and that led to lots of defects later on in the life cycle, or even in our production environment, we just couldn't afford to do that. >>And actually, focusing on continuous testing over the last nine to 12 months has really given us the ability to deliver quickly across the whole life cycle. And therefore actually go from doing a kind of semi agile kind of thing, where we did the user stories, we did a few of the kind of agile ceremonies, but we weren't really deploying any quicker into production because our stakeholders were scared that we didn't have the same control that we had when we had more waterfall releases. And, you know, when we didn't think of ourselves. So we've done a lot of work on every aspect, um, especially from a testing point of view, every aspect of every activity, rather than just looking at automated tests, you know, whether it is actually creating the test in the first place, whether it's doing security testing earlier in the lot and performance testing in the life cycle, et cetera. So, yeah,  it's been a real key thing that for CT, for us to drive DevOps, >>Talk to me a little bit about your team. What are some of the shifts in terms of expectations that you're experiencing and how your team interacts with the internal folks from pipeline through life cycle? >>Yeah, we've done a lot of work on this. Um, you know, there's a thing that I think people will probably call it a customer experience gap, and it reminds me of a Gilbert cartoon, where we start with the requirements here and you're almost like a Chinese whisper effects and what we deliver is completely different. So we think the testing team or the delivery teams, um, know in our teeth has done a great job. This is what it said in the acceptance criteria, but then our customers are saying, well, actually that's not working this isn't working and there's this kind of gap. Um, we had a great launch this year of agile requirements, it's one of the Broadcom tools. And that was the first time in, ever since I remember actually working within BT, I had customers saying to me, wow, you know, we want more of this. >>We want more projects to have extra requirements design on it because it allowed us to actually work with the business collaboratively. I mean, we talk about collaboration, but how do we actually, you know, do that and have something that both the business and technical people can understand. And we've actually been working with the business , using agile requirements designer to really look at what the requirements are, tease out requirements we hadn't even thought of and making sure that we've got high levels of test coverage. And what we actually deliver at the end of it, not only have we been able to generate tests more quickly, but we've got much higher test coverage and also can more smartly, using the kind of AI within the tool and then some of the other kinds of pipeline tools, actually deliver to choose the right tasks, and actually doing a risk based testing approach. So that's been a great launch this year, but just the start of many kinds of things that we're doing >>Well, what I hear in that, Glynn is a lot of positives that have come out of a very challenging situation. Talk to me about it. And I liked that perspective. This is a very challenging time for everybody in the world, but it sounds like from a collaboration perspective you're right, we talk about that a lot critical with devops. But those challenges there, you guys were able to overcome those pretty quickly. What other challenges did you face and figure out quickly enough to be able to pivot so fast? >>I mean, you talked about culture. You know, BT is like most companies  So it's very siloed. You know we're still trying to work to become closer as a company. So I think there's a lot of challenges around how would you integrate with other tools? How would you integrate with the various different technologies. And BT, we have 58 different IT stacks. That's not systems, that's stacks, all of those stacks can have hundreds of systems. And we're trying to, we've got a drive at the moment, a simplified program where we're trying to you know, reduce that number to 14 stacks. And even then there'll be complexity behind the scenes that we will be challenged more and more as we go forward. How do we actually highlight that to our users? And as an it organization, how do we make ourselves leaner, so that even when we've still got some of that legacy, and we'll never fully get rid of it and that's the kind of trade off that we have to make, how do we actually deal with that and hide that from our users and drive those programs, so we can, as I say, accelerate change,  reduce that kind of waste and that kind of legacy costs out of our business. You know, the other thing as well, I'm sure telecoms is probably no different to insurance or finance. When you take the number of products that we do, and then you combine them, the permutations are tens and hundreds of thousands of products. So we, as a business are trying to simplify, we are trying to do that in an agile way. >>And haven't tried to do agile in the proper way and really actually work at pace, really deliver value. So I think what we're looking more and more at the moment is actually  more value focused. Before we used to deliver changes sometimes into production. Someone had a great idea, or it was a great idea nine months ago or 12 months ago, but actually then we ended up deploying it and then we'd look at the users, the usage of that product or that application or whatever it is, and it's not being used for six months. So we haven't got, you know, the cost of the last 12 months. We certainly haven't gotten room for that kind of waste and, you know, for not really understanding the value of changes that we are doing. So I think that's the most important thing of the moment, it's really taking that waste out. You know, there's lots of focus on things like flow management, what bits of our process are actually taking too long. And we've started on that journey, but we've got a hell of a long way to go. But that involves looking at every aspect of the software delivery cycle. >> Going from, what 58 IT stacks down to 14 or whatever it's going to be, simplifying sounds magical to everybody. It's a big challenge. What are some of the core technology capabilities that you see really as kind of essential for enabling that with this new way that you're working? >>Yeah. I mean, I think we were started on a continuous testing journey, and I think that's just the start. I mean as I say, looking at every aspect of, you know, from a QA point of view is every aspect of what we do. And it's also looking at, you know, we've started to branch into more like AI, uh, AI ops and, you know, really the full life cycle. Um, and you know, that's just a stepping stone to, you know, I think autonomics is the way forward, right. You know, all of this kind of stuff that happens, um, you know, monitoring, uh, you know, watching the systems what's happening in production, how do we feed that back? How'd you get to a point where actually we think about change and then suddenly it's in production safely, or if it's not going to safety, it's automatically backing out. So, you know, it's a very, very long journey, but if we want to, you know, in a world where the pace is in ever-increasing and the demands for the team, and, you know, with the pressures on, at the moment where we're being asked to do things, uh, you know, more efficiently and as lean as possible, we need to be thinking about every part of the process and how we put the kind of stepping stones in place to lead us to a more automated kind of, um, you know, um, the future. >>Do you feel that that planned outcomes are starting to align with what's delivered, given this massive shift that you're experiencing? >>I think it's starting to, and I think, you know, as I say, as we look at more of a value based approach, um, and, um, you know, as I say, print, this was a kind of flow management. I think that that will become ever, uh, ever more important. So, um, I think it starting to people certainly realize that, you know, teams need to work together, you know, the kind of the cousin between business and it, especially as we go to more kind of SAS based solutions, low code solutions, you know, there's not such a gap anymore, actually, some of our business partners that expense to be much more tech savvy. Um, so I think, you know, this is what we have to kind of appreciate what is its role, how do we give the capabilities, um, become more of a centers of excellence rather than actually doing mounds amounts of work. And for me, and from a testing point of view, you know, mounds and mounds of testing, actually, how do we automate that? How do we actually generate that instead of, um, create it? I think that's the kind of challenge going forward. >>What are some, as we look forward, what are some of the things that you would like to see implemented or deployed in the next, say six to 12 months as we hopefully round a corner with this pandemic? >>Yeah, I think, um, you know, certainly for, for where we are as a company from a QA perspective, we are, um, you let's start in bits that we do well, you know, we've started creating, um, continuous delivery and DevOps pipelines. Um, there's still manual aspects of that. So, you know, certainly for me, I I've challenged my team with saying how do we do an automated journey? So if I put a requirement in JIRA or rally or wherever it is and why then click a button and, you know, with either zero touch for one such, then put that into production and have confidence that, that has been done safely and that it works and what happens if it doesn't work. So, you know, that's, that's the next, um, the next few months, that's what our concentration, um, is, is about. But it's also about decision-making, you know, how do you actually understand those value judgments? >>And I think there's lots of the things dev ops, AI ops, kind of that always ask aspects of business operations. I think it's about having the information in one place to make those kinds of decisions. How does it all try and tie it together? As I say, even still with kind of dev ops, we've still got elements within my company where we've got lots of different organizations doing some, doing similar kinds of things, but they're all kind of working in silos. So I think having AI ops as it comes more and more to the fore as we go to cloud, and that's what we need to, you know, we're still very early on in our cloud journey, you know, so we need to make sure the technologies work with cloud as well as you can have, um, legacy systems, but it's about bringing that all together and having a full, visible pipeline, um, that everybody can see and make decisions. >>You said the word confidence, which jumped out at me right away, because absolutely you've got to have be able to have confidence in what your team is delivering and how it's impacting the business and those customers. Last question then for you is how would you advise your peers in a similar situation to leverage technology automation, for example, dev ops, to be able to gain the confidence that they're making the right decisions for their business? >>I think the, the, the, the, the approach that we've taken actually is not started with technology. Um, we've actually taken a human centered design, uh, as a core principle of what we do, um, within the it part of BT. So by using human centered design, that means we talk to our customers, we understand their pain points, we map out their current processes. Um, and then when we mapped out what this process does, it also understand their aspirations as well, you know? Um, and where do they want to be in six months? You know, do they want it to be, um, more agile and, you know, or do they want to, you know, is, is this a part of their business that they want to do one better? We actually then looked at why that's not running well, and then see what, what solutions are out there. >>We've been lucky that, you know, with our partnership, with Broadcom within the payer line, lots of the tools and the PLA have directly answered some of the business's problems. But I think by having those conversations and actually engaging with the business, um, you know, especially if the business hold the purse strings, which in, in, uh, you know, in some companies include not as they do there is that kind of, you know, almost by understanding their, their pain points and then starting, this is how we can solve your problem. Um, is we've, we've tended to be much more successful than trying to impose something and say, well, here's the technology that they don't quite understand. It doesn't really understand how it kind of resonates with their problems. So I think that's the heart of it. It's really about, you know, getting, looking at the data, looking at the processes, looking at where the kind of waste is. >>And then actually then looking at the right solutions. Then, as I say, continuous testing is massive for us. We've also got a good relationship with Apple towards looking at visual AI. And actually there's a common theme through that. And I mean, AI is becoming more and more prevalent. And I know, you know, sometimes what is AI and people have kind of this semantics of, is it true AI or not, but it's certainly, you know, AI machine learning is becoming more and more prevalent in the way that we work. And it's allowing us to be much more effective, be quicker in what we do and be more accurate. And, you know, whether it's finding defects running the right tests or, um, you know, being able to anticipate problems before they're happening in a production environment. >>Well, thank you so much for giving us this sort of insight outlook at dev ops sharing the successes that you're having, taking those challenges, converting them to opportunities and forgiving folks who might be in your shoes, or maybe slightly behind advice enter. They appreciate it. We appreciate your time. >>Well, it's been an absolute pleasure, really. Thank you for inviting me. I have a extremely enjoyed it. So thank you ever so much. >>Excellent. Me too. I've learned a lot for Glenn Martin. I'm Lisa Martin. You're watching the cube >>Driving revenue today means getting better, more valuable software features into the hands of your customers. If you don't do it quickly, your competitors as well, but going faster without quality creates risks that can damage your brand destroy customer loyalty and cost millions to fix dev ops from Broadcom is a complete solution for balancing speed and risk, allowing you to accelerate the flow of value while minimizing the risk and severity of critical issues with Broadcom quality becomes integrated across the entire DevOps pipeline from planning to production, actionable insights, including our unique readiness score, provide a three 60 degree view of software quality giving you visibility into potential issues before they become disasters. Dev ops leaders can manage these risks with tools like Canary deployments tested on a small subset of users, or immediately roll back to limit the impact of defects for subsequent cycles. Dev ops from Broadcom makes innovation improvement easier with integrated planning and continuous testing tools that accelerate the flow of value product requirements are used to automatically generate tests to ensure complete quality coverage and tests are easily updated. >>As requirements change developers can perform unit testing without ever leaving their preferred environment, improving efficiency and productivity for the ultimate in shift left testing the platform also integrates virtual services and test data on demand. Eliminating two common roadblocks to fast and complete continuous testing. When software is ready for the CIC CD pipeline, only DevOps from Broadcom uses AI to prioritize the most critical and relevant tests dramatically improving feedback speed with no decrease in quality. This release is ready to go wherever you are in your DevOps journey. Broadcom helps maximize innovation velocity while managing risk. So you can deploy ideas into production faster and release with more confidence from around the globe. It's the queue with digital coverage of dev ops virtual forum brought to you by Broadcom. >>Hi guys. Welcome back. So we have discussed the current state and the near future state of dev ops and how it's going to evolve from three unique perspectives. In this last segment, we're going to open up the floor and see if we can come to a shared understanding of where dev ops needs to go in order to be successful next year. So our guests today are, you've seen them all before Jeffrey Hammond is here. The VP and principal analyst serving CIO is at Forester. We've also Serge Lucio, the GM of Broadcom's enterprise software division and Glenn Martin, the head of QA transformation at BT guys. Welcome back. Great to have you all three together >>To be here. >>All right. So we're very, we're all very socially distanced as we've talked about before. Great to have this conversation. So let's, let's start with one of the topics that we kicked off the forum with Jeff. We're going to start with you spiritual co-location that's a really interesting topic that we've we've uncovered, but how much of the challenge is truly cultural and what can we solve through technology? Jeff, we'll start with you then search then Glen Jeff, take it away. >>Yeah, I think fundamentally you can have all the technology in the world and if you don't make the right investments in the cultural practices in your development organization, you still won't be effective. Um, almost 10 years ago, I wrote a piece, um, where I did a bunch of research around what made high-performance teams, software delivery teams, high performance. And one of the things that came out as part of that was that these teams have a high level of autonomy. And that's one of the things that you see coming out of the agile manifesto. Let's take that to today where developers are on their own in their own offices. If you've got teams where the team itself had a high level of autonomy, um, and they know how to work, they can make decisions. They can move forward. They're not waiting for management to tell them what to do. >>And so what we have seen is that organizations that embraced autonomy, uh, and got their teams in the right place and their teams had the information that they needed to make the right decisions have actually been able to operate pretty well, even as they've been remote. And it's turned out to be things like, well, how do we actually push the software that we've created into production that would become the challenge is not, are we writing the right software? And that's why I think the term spiritual co-location is so important because even though we may be physically distant, we're on the same plane, we're connected from a, from, from a, a shared purpose. Um, you know, surgeon, I worked together a long, long time ago. So it's been what almost 15, 16 years since we were at the same place. And yet I would say there's probably still a certain level of spiritual co-location between us, uh, because of the shared purposes that we've had in the past and what we've seen in the industry. And that's a really powerful tool, uh, to build on. So what do tools play as part of that, to the extent that tools make information available, to build shared purpose on to the extent that they enable communication so that we can build that spiritual co-location to the extent that they reinforce the culture that we want to put in place, they can be incredibly valuable, especially when, when we don't have the luxury of physical locate physical co-location. Okay. That makes sense. >>It does. I shouldn't have introduced us. This last segment is we're all spiritually co-located or it's a surge, clearly you're still spiritually co located with jump. Talk to me about what your thoughts are about spiritual of co-location the cultural impact and how technology can move it forward. >>Yeah. So I think, well, I'm going to sound very similar to Jeff in that respect. I think, you know, it starts with kind of a shared purpose and the other understanding, Oh, individuals teams, uh, contributed to kind of a business outcome, what is our shared goal or shared vision? What's what is it we're trying to achieve collectively and keeping it kind of aligned to that? Um, and so, so it's really starts with that now, now the big challenge, always these over the last 20 years, especially in large organization, there's been specialization of roles and functions. And so we, we all that started to basically measure which we do, uh, on a daily basis using metrics, which oftentimes are completely disconnected from kind of a business outcome or purpose. We, we kind of reverted back to, okay, what is my database all the time? What is my cycle time? >>Right. And, and I think, you know, which we can do or where we really should be focused as an industry is to start to basically provide a lens or these different stakeholders to look at what they're doing in the context of kind of these business outcomes. So, um, you know, probably one of my, um, favorites experience was to actually weakness at one of a large financial institution. Um, you know, Tuesday Golder's unquote development and operations staring at the same data, right. Which was related to, you know, in calming changes, um, test execution results, you know, Coverity coverage, um, official liabilities and all the all ran. It could have a direction level links. And that's when you start to put these things in context and represent that to you in a way that these different stakeholders can, can look at from their different lens. And, uh, and it can start to basically communicate and, and understand have they joined our company to, uh, to, to that kind of common view or objective. >>And Glen, we talked a lot about transformation with you last time. What are your thoughts on spiritual colocation and the cultural part, the technology impact? >>Yeah, I mean, I agree with Jeffrey that, you know, um, the people and culture, the most important thing, actually, that's why it's really important when you're transforming to have partners who have the same vision as you, um, who, who you can work with, have the same end goal in mind. And w I've certainly found that with our, um, you know, continuing relationship with Broadcom, what it also does though, is although, you know, tools can accelerate what you're doing and can join consistency. You know, we've seen within simplify, which is BTS flagship transformation program, where we're trying to, as it can, it says simplify the number of systems stacks that we have, the number of products that we have actually at the moment, we've got different value streams within that program who have got organizational silos. We were trying to rewrite, rewrite the wheel, um, who are still doing things manually. >>So in order to try and bring that consistency, we need the right tools that actually are at an enterprise grade, which can be flexible to work with in BT, which is such a complex and very dev, uh, different environments, depending on what area of BT you're in, whether it's a consumer, whether it's a mobile area, whether it's large global or government organizations, you know, we found that we need tools that can, um, drive that consistency, but also flex to Greenfield brownfield kind of technologies as well. So it's really important that as I say, for a number of different aspects, that you have the right partner, um, to drive the right culture, I've got the same vision, but also who have the tool sets to help you accelerate. They can't do that on their own, but they can help accelerate what it is you're trying to do in it. >>And a really good example of that is we're trying to shift left, which is probably a, quite a bit of a buzz phrase in their kind of testing world at the moment. But, you know, I could talk about things like continuous delivery direct to when a ball comes tools and it has many different features to it, but very simply on its own, it allows us to give the visibility of what the teams are doing. And once we have that visibility, then we can talk to the teams, um, around, you know, could they be doing better component testing? Could they be using some virtualized services here or there? And that's not even the main purpose of continuous delivery director, but it's just a reason that tools themselves can just give greater visibility of have much more intuitive and insightful conversations with other teams and reduce those organizational silos. >>Thanks, Ben. So we'd kind of sum it up, autonomy collaboration tools that facilitate that. So let's talk now about metrics from your perspectives. What are the metrics that matter? Jeff, >>I'm going to go right back to what Glenn said about data that provides visibility that enables us to, to make decisions, um, with shared purpose. And so business value has to be one of the first things that we look at. Um, how do we assess whether we have built something that is valuable, you know, that could be sales revenue, it could be net promoter score. Uh, if you're not selling what you've built, it could even be what the level of reuse is within your organization or other teams picking up the services, uh, that you've created. Um, one of the things that I've begun to see organizations do is to align value streams with customer journeys and then to align teams with those value streams. So that's one of the ways that you get to a shared purpose, cause we're all trying to deliver around that customer journey, the value with it. >>And we're all measured on that. Um, there are flow metrics which are really important. How long does it take us to get a new feature out from the time that we conceive it to the time that we can run our first experiments with it? There are quality metrics, um, you know, some of the classics or maybe things like defect, density, or meantime to response. Um, one of my favorites came from a, um, a company called ultimate software where they looked at the ratio of defects found in production to defects found in pre production and their developers were in fact measured on that ratio. It told them that guess what quality is your job to not just the test, uh, departments, a group, the fourth level that I think is really important, uh, in, in the current, uh, situation that we're in is the level of engagement in your development organization. >>We used to joke that we measured this with the parking lot metric helpful was the parking lot at nine. And how full was it at five o'clock. I can't do that anymore since we're not physically co-located, but what you can do is you can look at how folks are delivering. You can look at your metrics in your SCM environment. You can look at, uh, the relative rates of churn. Uh, you can look at things like, well, are our developers delivering, uh, during longer periods earlier in the morning, later in the evening, are they delivering, uh, you know, on the weekends as well? Are those signs that we might be heading toward a burnout because folks are still running at sprint levels instead of marathon levels. Uh, so all of those in combination, uh, business value, uh, flow engagement in quality, I think form the backbone of any sort of, of metrics, uh, a program. >>The second thing that I think you need to look at is what are we going to do with the data and the philosophy behind the data is critical. Um, unfortunately I see organizations where they weaponize the data and that's completely the wrong way to look at it. What you need to do is you need to say, you need to say, how is this data helping us to identify the blockers? The things that aren't allowing us to provide the right context for people to do the right thing. And then what do we do to remove those blockers, uh, to make sure that we're giving these autonomous teams the context that they need to do their job, uh, in a way that creates the most value for the customers. >>Great advice stuff, Glenn, over to your metrics that matter to you that really make a big impact. And, and, and also how do you measure quality kind of following onto the advice that Jeff provided? >>That's some great advice. Actually, he talks about value. He talks about flow. Both of those things are very much on my mind at the moment. Um, but there was this, I listened to a speaker, uh, called me Kirsten a couple of months ago. It taught very much around how important flow management is and removing, you know, and using that to remove waste, to understand in terms of, you know, making software changes, um, what is it that's causing us to do it longer than we need to. So where are those areas where it takes long? So I think that's a very important thing for us. It's even more basic than that at the moment, we're on a journey from moving from kind of a waterfall to agile. Um, and the problem with moving from waterfall to agile is with waterfall, the, the business had a kind of comfort that, you know, everything was tested together and therefore it's safer. >>Um, and with agile, there's that kind of, you know, how do we make sure that, you know, if we're doing things quick and we're getting stuff out the door that we give that confidence, um, that that's ready to go, or if there's a risk that we're able to truly articulate what that risk is. So there's a bit about release confidence, um, and some of the metrics around that and how, how healthy those releases are, and actually saying, you know, we spend a lot of money, um, um, an investment setting up our teams, training our teams, are we actually seeing them deliver more quickly and are we actually seeing them deliver more value quickly? So yeah, those are the two main things for me at the moment, but I think it's also about, you know, generally bringing it all together, the dev ops, you know, we've got the kind of value ops AI ops, how do we actually bring that together to so we can make quick decisions and making sure that we are, um, delivering the biggest bang for our buck, absolutely biggest bang for the buck, surge, your thoughts. >>Yeah. So I think we all agree, right? It starts with business metrics, flow metrics. Um, these are kind of the most important metrics. And ultimately, I mean, one of the things that's very common across a highly functional teams is engagements, right? When, when you see a team that's highly functioning, that's agile, that practices DevOps every day, they are highly engaged. Um, that that's, that's definitely true. Now the, you know, back to, I think, uh, Jeff's point on weaponization of metrics. One of the key challenges we see is that, um, organizations traditionally have been kind of, uh, you know, setting up benchmarks, right? So what is a good cycle time? What is a good lead time? What is a good meantime to repair? The, the problem is that this is very contextual, right? It varies. It's going to vary quite a bit, depending on the nature of application and system. >>And so one of the things that we really need to evolve, um, as an industry is to understand that it's not so much about those flow metrics is about our, these four metrics ultimately contribute to the business metric to the business outcome. So that's one thing. The second aspect, I think that's oftentimes misunderstood is that, you know, when you have a bad cycle time or, or, or what you perceive as being a buy cycle time or better quality, the problem is oftentimes like all, do you go and explore why, right. What is the root cause of this? And I think one of the key challenges is that we tend to focus a lot of time on metrics and not on the eye type patterns, which are pretty common across the industry. Um, you know, if you look at, for instance, things like lead time, for instance, it's very common that, uh, organizational boundaries are going to be a key contributor to badly time. >>And so I think that there is, you know, the only the metrics there is, I think a lot of work that we need to do in terms of classifying, descend type patterns, um, you know, back to you, Jeff, I think you're one of the cool offers of waterscrumfall as a, as, as a key pattern, the industry or anti-spatter. Um, but waterscrumfall right is a key one, right? And you will detect that through kind of a defect arrival rates. That's where that looks like an S-curve. And so I think it's beyond kind of the, the metrics is what do you do with those metrics? >>Right? I'll tell you a search. One of the things that is really interesting to me in that space is I think those of us had been in industry for a long time. We know the anti-patterns cause we've seen them in our career maybe in multiple times. And one of the things that I think you could see tooling do is perhaps provide some notification of anti-patterns based on the telemetry that comes in. I think it would be a really interesting place to apply, uh, machine learning and reinforcement learning techniques. Um, so hopefully something that we'd see in the future with dev ops tools, because, you know, as a manager that, that, you know, may be only a 10 year veteran or 15 year veteran, you may be seeing these anti-patterns for the first time. And it would sure be nice to know what to do, uh, when they start to pop up, >>That would right. Insight, always helpful. All right, guys, I would like to get your final thoughts on this. The one thing that you believe our audience really needs to be on the lookout for and to put on our agendas for the next 12 months, Jeff will go back to you. Okay. >>I would say look for the opportunities that this disruption presents. And there are a couple that I see, first of all, uh, as we shift to remote central working, uh, we're unlocking new pools of talent, uh, we're, it's possible to implement, uh, more geographic diversity. So, so look to that as part of your strategy. Number two, look for new types of tools. We've seen a lot of interest in usage of low-code tools to very quickly develop applications. That's potentially part of a mainstream strategy as we go into 2021. Finally, make sure that you embrace this idea that you are supporting creative workers that agile and dev ops are the peanut butter and chocolate to support creative, uh, workers with algorithmic capabilities, >>Peanut butter and chocolate Glen, where do we go from there? What are, what's the one silver bullet that you think folks to be on the lookout for now? I, I certainly agree that, um, low, low code is, uh, next year. We'll see much more low code we'd already started going, moving towards a more of a SAS based world, but low code also. Um, I think as well for me, um, we've still got one foot in the kind of cow camp. Um, you know, we'll be fully trying to explore what that means going into the next year and exploiting the capabilities of cloud. But I think the last, um, the last thing for me is how do you really instill quality throughout the kind of, um, the, the life cycle, um, where, when I heard the word scrum fall, it kind of made me shut it because I know that's a problem. That's where we're at with some of our things at the moment we need to get beyond that. We need >>To be releasing, um, changes more frequently into production and actually being a bit more brave and having the confidence to actually do more testing in production and go straight to production itself. So expect to see much more of that next year. Um, yeah. Thank you. I haven't got any food analogies. Unfortunately we all need some peanut butter and chocolate. All right. It starts to take us home. That's what's that nugget you think everyone needs to have on their agendas? >>That's interesting. Right. So a couple of days ago we had kind of a latest state of the DevOps report, right? And if you read through the report, it's all about the lost city, but it's all about sweet. We still are receiving DevOps as being all about speed. And so to me, the key advice is in order to create kind of a spiritual collocation in order to foster engagement, we have to go back to what is it we're trying to do collectively. We have to go back to tie everything to the business outcome. And so for me, it's absolutely imperative for organizations to start to plot their value streams, to understand how they're delivering value into aligning everything they do from a metrics to deliver it, to flow to those metrics. And only with that, I think, are we going to be able to actually start to really start to align kind of all these roles across the organizations and drive, not just speed, but business outcomes, >>All about business outcomes. I think you guys, the three of you could write a book together. So I'll give you that as food for thought. Thank you all so much for joining me today and our guests. I think this was an incredibly valuable fruitful conversation, and we appreciate all of you taking the time to spiritually co-located with us today, guys. Thank you. Thank you, Lisa. Thank you. Thank you for Jeff Hammond serves Lucio and Glen Martin. I'm Lisa Martin. Thank you for watching the broad cops Broadcom dev ops virtual forum.

Published Date : Nov 18 2020

SUMMARY :

of dev ops virtual forum brought to you by Broadcom. Nice to talk with you today. It's good to be here. One of the things that we think of is speed, it was essentially a sprint, you know, you run as hard as you can for as fast as you can And it's almost like, you know, if you've ever run a marathon the first mile or two in the marathon, um, we have to think about all the activities that you need to do from a dev ops perspective and to hiring, you know, achieve higher levels of digitization in our processes and We've said that the key to success with agile at the team level is cross-functional organizations, as you say, going from, you know, physical workspaces, uh, agile manifesto, you know, there were four principles that were espoused individuals and interactions is important to make sure that that agility is there for one thing, you have to defer decisions So those teams have to be empowered to make decisions because you can't have a I think we all could use some of that, but, you know, you talked about in the beginning and I've, Um, when everybody was in the office, you could kind of see the And that gives you an indication of how engaged your developers are. um, whether it's, you know, more regular social events, that have done this well, this adaptation, what can you share in terms of some real-world examples that might Um, you know, first of all, since the start of COVID, if you don't have good remote onboarding processes, Those are the kinds of things that we have to be, um, willing to, um, and the business folks to just get better at what they're doing and learning to embrace It's it's, it's an important thing. Thank you so much for joining for Jeffrey I'm Lisa Martin, of dev ops virtual forum brought to you by Broadcom, I just had the chance to talk with Jeffrey Hammond and he unlocked this really interesting concept, uh, you know, driving a bias towards action. Well, and it talked about culture being, it's something that, you know, we're so used to talking about dev ops with respect does it take where, you know, that code to be processed through pipeline pushy? you know, when I checked in code, you know, to do I guess the system to automatically identify what So we'll get to AI in a second, but I'm curious, what are some of the, of the metrics you think that really matter right And so I'm much more interested and we, you know, fruit for Broadcom. are being defined as a set of OTRs, they have interdependencies and you have have a new set And so, you know, it's not uncommon to see, you know, teams where, you know, How do you think those technologies can be leveraged by DevOps leaders to influence as a leader of a, you know, 1500 people organization, there's a number of from a people point of view, which were hidden, uh, you can start to understand maybe It's um, you know, you know, the SRE folks, the dev ops says can use AI and automation in the right ways Um, so you can, you can do a lot of an analytics, predictive analytics. So if you start to understand, for instance, that whenever maybe, you know, So I mentioned in the beginning of our conversation, that just came off the biz ops manifesto. the problem we have as an industry is that, um, there are set practices between And so to me, these ops is really about kind of, uh, putting a lens on So to me, the key, the key, um, challenge for, We thank you so much for sharing your insights and your time at today's DevOps Thanks for your time. of devops virtual forum brought to you by Broadcom. Transformation is at the heart of what you do. transformation that you are still responsible for driving? you know, we had to do some great things during this time around, um, you know, in the UK for one of the things that I want to ask you about, I'm again, looking at DevOps from the inside But one of the things I'd love to get your perspective I always say that, you know, you're only as good as your lowest And, you know, What are some of the shifts in terms of expectations Um, you know, there's a thing that I think people I mean, we talk about collaboration, but how do we actually, you know, do that and have something that did you face and figure out quickly enough to be able to pivot so fast? and that's the kind of trade off that we have to make, how do we actually deal with that and hide that from So we haven't got, you know, the cost of the last 12 months. What are some of the core technology capabilities that you see really as kind demands for the team, and, you know, with the pressures on, at the moment where we're being asked to do things, And for me, and from a testing point of view, you know, mounds and mounds of testing, we are, um, you let's start in bits that we do well, you know, we've started creating, ops as it comes more and more to the fore as we go to cloud, and that's what we need to, Last question then for you is how would you advise your peers in a similar situation to You know, do they want it to be, um, more agile and, you know, or do they want to, especially if the business hold the purse strings, which in, in, uh, you know, in some companies include not as they And I know, you know, sometimes what is AI Well, thank you so much for giving us this sort of insight outlook at dev ops sharing the So thank you ever so much. I'm Lisa Martin. the entire DevOps pipeline from planning to production, actionable This release is ready to go wherever you are in your DevOps journey. Great to have you all three together We're going to start with you spiritual co-location that's a really interesting topic that we've we've And that's one of the things that you see coming out of the agile Um, you know, surgeon, I worked together a long, long time ago. Talk to me about what your thoughts are about spiritual of co-location I think, you know, it starts with kind of a shared purpose and the other understanding, that to you in a way that these different stakeholders can, can look at from their different lens. And Glen, we talked a lot about transformation with you last time. And w I've certainly found that with our, um, you know, continuing relationship with Broadcom, So it's really important that as I say, for a number of different aspects, that you have the right partner, then we can talk to the teams, um, around, you know, could they be doing better component testing? What are the metrics So that's one of the ways that you get to a shared purpose, cause we're all trying to deliver around that um, you know, some of the classics or maybe things like defect, density, or meantime to response. later in the evening, are they delivering, uh, you know, on the weekends as well? teams the context that they need to do their job, uh, in a way that creates the most value for the customers. And, and, and also how do you measure quality kind of following the business had a kind of comfort that, you know, everything was tested together and therefore it's safer. Um, and with agile, there's that kind of, you know, how do we make sure that, you know, if we're doing things quick and we're getting stuff out the door that of, uh, you know, setting up benchmarks, right? And so one of the things that we really need to evolve, um, as an industry is to understand that we need to do in terms of classifying, descend type patterns, um, you know, And one of the things that I think you could see tooling do is The one thing that you believe our audience really needs to be on the lookout for and to put and dev ops are the peanut butter and chocolate to support creative, uh, But I think the last, um, the last thing for me is how do you really instill and having the confidence to actually do more testing in production and go straight to production itself. And if you read through the report, it's all about the I think this was an incredibly valuable fruitful conversation, and we appreciate all of you

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JeffPERSON

0.99+

JeffreyPERSON

0.99+

SergePERSON

0.99+

GlenPERSON

0.99+

Lisa MartinPERSON

0.99+

Jeffrey HammondPERSON

0.99+

Serge LucioPERSON

0.99+

AppleORGANIZATION

0.99+

Jeffery HammondPERSON

0.99+

GlennPERSON

0.99+

sixQUANTITY

0.99+

26QUANTITY

0.99+

Glenn MartinPERSON

0.99+

50 minutesQUANTITY

0.99+

MicrosoftORGANIZATION

0.99+

LisaPERSON

0.99+

BroadcomORGANIZATION

0.99+

Jeff HammondPERSON

0.99+

tensQUANTITY

0.99+

six monthsQUANTITY

0.99+

2021DATE

0.99+

BenPERSON

0.99+

10 yearQUANTITY

0.99+

UKLOCATION

0.99+

two hoursQUANTITY

0.99+

15 yearQUANTITY

0.99+

sevenQUANTITY

0.99+

9:00 PMDATE

0.99+

two hourQUANTITY

0.99+

14 stacksQUANTITY

0.99+

twoQUANTITY

0.99+

next yearDATE

0.99+

GlynnPERSON

0.99+

two dayQUANTITY

0.99+

MartinPERSON

0.99+

Glynn MartinPERSON

0.99+

KirstenPERSON

0.99+

todayDATE

0.99+

SRE ValleyORGANIZATION

0.99+

five o'clockDATE

0.99+

BothQUANTITY

0.99+

2020DATE

0.99+

millionsQUANTITY

0.99+

second aspectQUANTITY

0.99+

Glen JeffPERSON

0.99+

threeQUANTITY

0.99+

14QUANTITY

0.99+

75%QUANTITY

0.99+

three weeksQUANTITY

0.99+

Amanda silverPERSON

0.99+

oneQUANTITY

0.99+

seven teamsQUANTITY

0.99+

tens of thousandsQUANTITY

0.99+

last yearDATE

0.99+

Bong Gumahad and Chris Henson V2


 

>>From around the globe. It's the queue cover >>Space and cyber security >>Symposium 2020 hosted by Cal poly. >>Hello and welcome to the space and cybersecurity symposium 2020 hosted by Cal poly and the cube I'm chilling for a, your host. We have a great session here. Space, cyber security, the department of defense perspective. We have bond Google hall, director of C four ISR directorate office of the undersecretary of defense for acquisition and sustainment for the DOD and Chris Henson, technical director space and weapons, cybersecurity solutions for the national security agency. Gentlemen, thank you for taking the time for this awesome session. Thank you, John. Thank you. So we're gonna talk about the perspective of the DOD relative to space cybersecurity, a lot, going on congestion, contention, freedom, evolution innovation. So Paul, I'd like to have you start with your opening statement on how you see the space cybersecurity perspective, Don, thanks for the intro. Really appreciate it. First, let me give my thanks to Cal poly for a convening, the space and cybersecurity symposium this year, you know, and despite the pandemic, the organization and the content delivery spreading impressive, I really foot stomping. >>What can possibly be done with a number of these virtual platforms? This has been awesome. Thanks for the opportunity. I also want to recognize my colleague, Chris Nissen from NSA was actually assigned to our staff that LSD, but he brings both policy and technical perspective in this whole area. So I think you'll, you'll find his commentary, uh, and positions on things very refreshing or for today's seminar. Now space cyber security is a pretty interesting terminology for us all. Uh, cyber security means protecting against cyber threats and it's really more than just computers here on earth, right? Uh, space is the newest war fighting domain, and cybersecurity's perhaps even more of a challenge in this domain that and others. Uh, I'm sure it'll turn journal Thompson and major journals Shaw discuss the criticality of this new dorm space force. It's the newest military service in the earlier sessions and they're at the risk of repeating what they already addressed. >>Let me start by talking about what space means to DOD and what we're doing directly from my vantage point as part of the acquisition and sustainment arm of the Pentagon. Uh, what I want to share with you today is how the current space strategy ties into the national defense strategy and supports the department's operational objectives. As the director of CFRI SAR. I have come to understand how the integration of CFRI Sarcic. Billy is a powerful asset to enhance the lethality of the joint war fighter. Secretary Lord, our boss, the sec, the undersecretary for acquisition and sustainment is diligent in her pursuit to adapt and modernize acquisition processes, to influence the strategy and to focus our efforts domain are to make our objectives a reality. I think first and foremost, we are building a more lethal force. This joint force will project low Valley and custom contested environments and across all domains through an operationally integrated and resiliency for ISR infrastructure. >>We are also called debating our alliances, deepening interoperability, which is very important in a future fight and collab, collaboratively planning with those partner with us in the fight most significantly for our work in acquisition and sustainment, we continue to optimize the department for greater performance and affordability through reform of the acquisition process. Now space is our newest war fighting domain. And while it is indeed unique, it shares many common traits with the others land, air and sea all are important to the defense of the U S in conflict. No doubt about this. They will be contested and they must be defended. One domain will not win future conflicts in a joint operation in a future fight in the future conflict. They must all succeed. I see three areas being key to a DOD strategic success in space, one, developing our whole of government approach in close partnership with the private sector and our allies to prioritizing our investments in resiliency, innovation, and adaptive operations, and third responding rapidly and effectively to leverage emerging technologies and seize opportunities to advance your strengths, partnerships and alliances. >>Let me emphasize that space is increasingly congested and tested and demanded as essential delete Valley operational effectiveness and the security of our nation. Now the commercialization of space offers a broad set of investments in satellite technology, potential opportunities to leverage those investments and pathways to develop cost efficient space architecture, where the department and the nation. It's funny, there's a new race, a race for space. If you will, between commercial companies buying for dominance of space. Now the joint staff within DOD is currently building an operational construct to employ and engage as a unified force, coordinated across all domains. We call it the joint, all domain command and control. It is the framework that is under development to allow us to conduct integrated operations in the future. The objective of Jesse too is to provide the war fighter access to the decision making information while providing mission assurance of the information and resilience of the underlying terrestrial air in space networks that support them operationally. >>six to maintain seamless integration, adaptation, and employment of our capability. To sense signal connect, transmit, process control, direct, and deliver lethal capabilities against the enemy. We gain a strategic advantage through the integration of these capabilities across all the domains, by providing balance bowel space, awareness, horse protection, and weapons controlled and deployment capabilities. Now successfully any ratings, the systems and capabilities will provide our war fighters overwhelming superiority on the battlefield environment, challenged by near peer adversaries, as well as non state actors in space. The character of its employment is changing, driven by increasing demands, not just by DOD, but by the commercial sector as well. You know, more and more, uh, we see greater use of small satellite systems to address a myriad of emerging questions, ubiquitous communications, awareness, sensor diversity, and many more. Uh, as I said before, the commercial world is pioneering high rate production of small satellites in our efforts to deploy hundreds, if not thousands of nodes space X, Darlene constellation is one example. >>Another one is Amazon's Kiper, uh, Kuyper just received FCC approval to deploy like over 3000 of these different notes. While a number of these companies continue to grow. Some have struggled. They some pointed as one web, uh, nevertheless, the appetite remains strong and DOD is taking advantage of these advances to support our missions. We are currently exploring how to better integrate the DOD activities involving small satellites under the small satellite coordinating activity, scholarly call it. We want to ensure collaboration and interoperability to maximize efficiency in acquisition and operation. When we started this activity on over a year and a half ago, we documented over 70 plus separate small, small sat programs within DOD. And now we've developed a very vibrant community of interest surrounding a small satellites. Now, part of the work we have identified nine focus areas for further development. These are common areas to all systems and by continuing to expand on these, our plan is they enable a standard of practice that can be applied across all of the domains. >>This includes lawn services, ground processing distribution, and of course, a topic of interest to the symposium space security and Chris we'll, we'll talk more about that being the Houston expert, uh, in this area. Uh, one challenge that we can definitely start working on today is workforce development. Cybersecurity's unique as it straddles STEM and security and policy, the trade craft is different. And unfortunately I've seen estimates recently, so suggesting a workforce gap in the next several years, much like the STEM fields, uh, during the next session, I am a part of a panel with precedent, Armstrong, Cal poly, and Steve Jake's the founder of the national security space association to address workforce development. But for this panel, I'll look forward to having further dialogue surrounding space, opera security with Chris and John. Thank you, John >>Bob, thank you for that whole thing, Steven. Yes. Workforce gaps. We need the new skill space is here. Thank you very much. Chris Henson, technical director of space and weapons, cybersecurity solutions for the national security agency. Your statement, >>Thank you for having me. Uh, I'm one of several technical leaders in space at the national security agency. And I'm currently on a joint duty assignment at the office of under secretary of defense for acquisition and sustainment. I work under mr. GUMA hot in the C four ISR area, but almost 63 years ago on the 4th of October, 1957, Sputnik was the first artificial satellite launched by the Soviet union in space. History was made in each of you can continue to write future space history in your careers. And just like in 1957, the U S isn't alone in space to include our close partnerships and longterm activities with organizations like the Japanese space agency, the European space agency, and, uh, the Canadian space agency, just to name a few. And when we tackle cybersecurity per space, we have to address, address the idea that the communications command and control, uh, and those mission datas will transverse networks owned and operated by a variety of partners, not only.go.mil.com.edu, et cetera. We need to have all the partners address the cyber effects of those systems because the risk excepted by one is shared by all and sharing cyber best practices, lessons learned, uh, data vulnerabilities, threat data, mitigation, mitigation procedures, all our valuable takeaways, uh, in expanding this space community, improving overall conditions for healthy environment. So thank you for having me, and I appreciate the opportunity to speak to you and your audience. And I look forward to the discussion questions. Thank you. >>Thank you, Chris. Thank you, Bob. Okay. I mean open innovation, the internet, you see plenty of examples. The theme here is partners, commercial government. It's going to take a lot of people and tech companies and technologies to make space work. So we asked my first question, Bonnie, we'll start with you is what do you see as the DOD his role in addressing cybersecurity in space? Uh, it's real, uh, it's a new frontier. Um, it's not going away. It's only going to get more innovative, more open, more contested. It seems like a lot to do there. So what's your role in addressing cyber security in space? >>I think our role is to be the leader in developing and only is it the strategy, but the, uh, the implementation plan is to ensure a full of cybersecurity. If you look at the national cyber cyber strategy, I think publishing 2018 calls for like-minded countries, industry academia, and civil society. Once you mentioned John, the support technology development, uh, digital safety policy advocacy, and research you here today, and those listening are fulfilling their strategy. When you, when you develop, enable use cyber hygiene products, as examples of capabilities, you're pushing the goal to fruition. When you know, what's on your network patron network backup, you're in encrypt your network, you're hardening and preventing cyber attacks. And we in government academia in the case of Cal poly civil networks and in commercial companies, we all benefit from doing that cyber security. Uh, and I think Chris will, we'll, we'll definitely back me up on this more than passwords encryption or pharma. It's truly a mindset and a culture of enabling missions to succeed in assured in a resilient fashion. >>Chris, you're taking reaction to, to the cybersecurity challenge involved here, >>That's it, it's starting really at the highest level of governments. We have, uh, you know, the, the recent security policy directive five that just came out just a couple of days ago, recognize all the factors of cybersecurity that need to come into play. And probably the most important outcome of that as mr said, is the leadership role and that leadership, uh, blends out very well into partnership. So partnership with industry partnership with academia partnership, with, uh, other people that are exploring space. And those partnerships lend itself very naturally to sharing cybersecurity issues, topics as we come up with best practices as we come up with mitigation strategies. And as we come up with vulnerabilities and share that information, the, uh, we're not going to go alone in space, just like we're probably not going to go alone in many other industries or areas, uh, that the DOD has to be, uh, involved in many spectrums of deploying to space. >>And that deployment involves as Mr. Guzman said, encryption authentication, knowing what's on the network, knowing the, the fabric of that network. And if nothing else, this, uh, this, uh, internet of things and work from home environment that we've, uh, partaken of these last few months has even explored and expanded that notion even more dramatically as we have people dial in from all over the different, uh, locations, well space will be that natural node that, uh, natural, uh, next network and mesh involvement that we'll have to protect and explore on not just from a terrestrial involvement, but all segments of it. Th the comm segment, the space vehicle and the ground portion, >>No bond. We talked about this in our other segment, um, around with the president of Cal poly, but the operating models of the space force and the DOD and getting space. It's a software defined world, right? So cybersecurity is a real big issue. Cause you have an operating model that's requiring software to power, these low hanging satellites. That's just an extension to the network. It's distributed computing, know what this is. If you understand what technology we do in space, it's no different, it's just a different environment. So it's software defined that just lends itself well to hacking. I mean, if I'm a hacker I'm going, Hey, why not just take out a satellite and crash it down or make the GPS do something different? I mean, it's definitely an attack vector. This is a big deal. It's not just like getting credentials that are cashed on a server. You gotta really protect, >>Right? Because in one hand it space will carry not only, uh, uh, you know, for local national security information. Uh, but the, uh, I feel like at the economic wellbeing, the financial state of allowed a lot of countries and institutions, you know, more and more John lb, they'll be using space assets to, uh, uh, to make, uh, make, make all that happen. Right. So, and if you look at the, you talk, you mentioned the attack vectors in space, you know, it's not just the computers in the ground, but if you look at the whole life cycle for satellite systems in space, you know, that the, the, the tasking that you need to do that the command, the controlling of the vehicle, the data that comes down in the ground, even when you launch the, the birds, the satellites, you know, they only need to be protected because they're all somewhat vulnerable to, uh, to hacking, uh, to cyber attacks. Especially as we grow into commercialization space, it's going to be a lot more people out there playing in this world. It's going to be a lot more companies out there. And, you know, it's hard to track, uh, uh, you know, the, the potential of, of, of foreign influences as an example, and therefore the potential of being vulnerable in terms of the cyber threat. >>Gentlemen, I like you guys said to move on to this leadership role, you mentioned that you want to be a leader. I get it. The DOD is department of defense. That's a new frontier to defend war time zone. You mentioned war time opportunity potentially, but how do you guys assist that's term hat to getting done? Because there's public and private space operations happening, um, there's security challenge. What does being a leader mean? And how does the DOD department of defense assist driving the public and private? Do you lead from a project standpoint, you lead from a funding standpoint? Is it architectural? I mean, you're talking about now a new end to end architecture. It's not just cloud it's on premise. It's in devices, it's offloaded with new AI technology and Nicks and devices. It's IOT, it's all, this is all new, this is all new. What does it mean for the DOD to be a leader and how do you assist others to get involved? And what does that mean? >>Yeah, I think, uh, the one hand, you know, DOD used to lead, uh, in terms of, uh, uh, being the only source of funding for a lot of, uh, highly developmental efforts. Uh, we're seeing a different story in space. Again, I keep going back to the commercialization of space. We're seeing a lot more players, right? So in many ways >>Ally's commercial companies are actually legally leading the R and D uh, of a lot of different technologies. So we want to take, we certainly want to take advantage of that. So from a leadership standpoint, I think we, we, Lucia can come in, you know, by partnering a lot more with, with the commercial companies, uh, in 2022, the DOD released the defense, uh, uh, space strategy as an example that highlights the threats, the challenges and opportunities the United States has faced by, by sending a example of how we, how we, uh, how we counter, uh, the threats that are out there, not just the DOD, but, but the disability and the commercial sector as well. Our current conditions are strong, but we want to use four lines of effort to meet our challenges and capitalize on our desire state space, uh, lines of effort include building a comprehensive military badges space, integrating space into a national joint and combined operations. Like I mentioned before, shaping that strategic environment and cooperating with allies, partners, and industry and other U S governmental agencies, departments, and agencies to advance the cost of space to take full advantage of what space can provide us, uh, in DOD, uh, and the nation. Chris has a domain. Now, what's your take on all that? >>That's because again, it's going to take more people, >>More diverse, potentially more security >>Halls. What's your view on it? >>Well, let's, let's look at how innovation and new technologies can help us in these areas. So, uh, and, and mentioned it a couple of topics that you hit on already. One of the areas that we can improve on is certainly in the, uh, the architecture, uh, where we look at a zero trust architecture, one of the NIST standards that's come about where it talks about the authentication, uh, the need to know a granular approach, this idea of being able to protect, not just data, but the resources and how people can get access to those, whether they're coming in through an identification, authentication Prudential, or, uh, other aspects of, uh, the, the idea of not just anybody should be able to have access to data or anybody should have access once they're on the inside of the network. So that zero trust architecture is, is one approach where we can show some leadership and guidance. >>Another area is in, uh, a topic that you touched on as well was in the software area. So some innovations are coming on very rapidly and strong in this artificial intelligence and machine learning. So if we can take this AI and ML and apply it to our software development areas, they can parse so much information very quickly. And, uh, you know, this vast array of code that's going into system nowadays, and then that frees up our human, uh, explicit talent and developers that can then look at other areas and not focus on minor bawling to Beverly fix a vulnerability. Uh, they, they can really use their unique skills and talents to come up with a better process, a better way, and let the artificial intelligence and machine learning, find those common problems, those, those unknown, hidden lines of code that, uh, get put into a software alarm Prairie, and then pull down over and over again from system to system. So I think between, uh, an architecture leadership role and employee innovation are two areas that we can show, uh, some benefits and process improvement to this whole system. >>That's a great point, Chris, and you think about just the architectural computer architecture, you know, S you know, network attached storage is an advantage software defined there. You could have flash all flash arrays for storage. You could have multiple cores on a device and this new architecture, offloads things, and it's a whole new way to gain efficiencies. I mean, you got Intel, you got Nvidia, you've got armed all the processors all built in. Um, so there's definitely been commercial best practices and benefits to a new kind of architecture that takes advantage of these new things. It's just, just efficiencies. Um, but this brings up the whole supply chain conversation. I want to get your thoughts on this, because there is talk about predatory investments and access and tactics to gain supply chain access to space systems, your thoughts. >>Yeah. It's a serious threat and not just for, uh, the U S uh, space. So supply chain, if you will, is the supply chain. And I says, you know, writ large, I think, uh, I think it's a, it's a, it's a threat that's, that's real, we're we're seeing today. I just saw an example recently, uh, involving, uh, our, I think our launch services were, there was a, uh, a foreign, uh, threat that was those trying to get into a true through with predatory investments. Uh, so, uh, it is something that we need to, uh, be aware of it it's happening, uh, and is continuing to happen. Uh, it's an easy way to gain access, to, uh, do our IP. Uh, and, uh, so it's something that we, uh, are serious about in terms of, uh, awareness and, and countering >>Chris, your thoughts. I mean, we've see, I mean, I'm an open source guy. I was seen it when I grew up in the industry in the eighties, open source became a revolution, but with that, it enabled new tactics for, um, state sponsored attacks on it that became a domain in of itself. Um, that's well-documented and people talk about that all the time in cyber. Now you have open innovation with hardware, software connected systems. This is going to bring supply chain nightmare. How do you track it all? Who's got what software and what device, where the chip come from, who made it, this is the potential is everywhere. How do you see the, these tactics, whether it's a VC firm from another country or this, that, and the other thing startup. >>Yeah. So when we see, when we see coal companies being purchased by foreign investors, and, you know, we can get blocked out of those, whether it's in the food industry, or if it's in a microchip, then that microchip could be used in a cell phone or a satellite or an automobile. So all of our industries that have these companies that are being purchased, or a large born investment influx into those, you know, that could be suspect. And we, we have to be very careful with those, uh, and, and do the tracking of those, especially when those, uh, some of those parts of mechanisms are coming from off shore. And then going again, going back to, uh, the space policy directive five, it calls out for better supply chain, resource management, the tracking, the knowing the pedigree and the, the quantitative of ability of knowing where those software libraries came from, where the parts came from and the tracking and delivery of that from an end to end system. >>And typically when we have a really large vendor, they can, they can do that really well. But when we have a subcontractor to a subcontractor, to a subcontractor, their resources may not be such that they can do that. Try tracking in mitigation for counterfeits or fraudulent materials going into our systems. So it's a very difficult challenge, and we want to ensure as best we can that as we ingest those parts, as we ingest those software libraries and technologies into the system, that, uh, before we employ them, we have to do some robust testing. And I don't want to say that the last line of defense, but that certainly is a mechanism for finding out, do the systems perform as they stated, uh, on a test bench or a flat set, whatever the case may be before we actually deploy it. And then we're relying on the output or the data that comes from that, that system that may have some corrupt or suspect parts in it. >>Great point, this federal grant, >>The problem with space systems is kind of, you know, is once you, once you launch the bird or the sunlight, uh, your access to it is, is diminished significantly, right? Unless you, you go up there and take it down. Uh, so, you know, kind of to Chris's point, we need to be able to test all the different parts of insurer that is performing as, as described there ass, I spent as specified, uh, with, with good knowledge that it's, uh, it's, uh, it's trustworthy. Uh, and, uh, so we that all on the ground before we, we take it up to launch it. >>It's funny. You want agility, you want speed and you want security, and you want reliability and risk management all aggressive, and it's a technical problem. It says it's a business model problem. I'd love to get real quick. Before we jump into some of the more workforce and gap issues on the personnel side, have you guys should just take a minute to explain quickly what's the federal view. If you had to kind of summarize the federal view of the DOD and the roll with it wants to take, so all the people out there on the commercial side or students out there who are, you know, wanting to jump in, what is the current modern federal view of space cybersecurity. >>Chris, why don't you take that on I'll follow up. Okay. Uh, I don't know that I can give you the federal view, but I can certainly give you the department of defense. That cybersecurity is extremely important. And as our vendors and our suppliers, uh, take on a very, very large and important role, one area that we're looking at improving on is a cyber certification maturity model, where we, where we look at the vendors and how they implement an employee cyber hygiene. So that guidance in and of itself shows the emphasis of cyber security that when we want to write a contract or a vendor, uh, for, for a purchase, that's going to go into a space system. We'd like to know from a third party audit capability, can that vendor, uh, protect and defend to some extent the amount that that part or piece or software system is going to have a cyber protection already built into it from that vendor, from the ground floor up before it even gets put into a larger system. >>So that shows a level of the CMMC process that we've thought about and, uh, started to employ, uh, beginning in 2021 and will be further built on in, in the out years. How, how important the DOD takes that. And other parts of the government are looking at this, in fact, other nations are looking at the CMMC model. So I think it shows a concern in very many areas, uh, not just in the department of defense that they're going to adopt an approach like this. Uh, so it shows the, the pluses and the benefits of a cybersecurity model that, uh, all can build on boggy reaction. Yeah, I'll just, uh, I'll just add to that, John, you, you, you, you asked earlier about, you know, how do we, uh, track, uh, commercial entities or, or people in the space and cyber security domains? Uh, I can tell you that, uh, at least my view of it, you know, space and cyber security are new, it's exciting, it's challenging a lot technical challenges there. So I think in >>Terms of attracting the right people, personnel to work those areas, uh, I think it's, it's not only intellectually challenging, uh, but it's important for, for the dependency that NASA States, uh, and it's important for, for, for economic security, uh, writ large for, for us as well. So I think, uh, in terms of a workforce and trying to get people interested in, in those domains, uh, I hope that they see the same thing we do in terms of, of the challenges and the opportunities it presents itself in the future. >>Awesome. I love your talk on intro track there falling. You mentioned, uh, the three key areas of DOD sec success, developing a government whole government approach to partnership with the private sector. I think that's critical and the allies prioritizing the right investments on resilience, innovation, adaptive operations, and responding to rapidly to effectively emerging technology. So you can be fast, all think are all things. I all, all those things are relevant. So given that, I want to get your thoughts on the defense space strategy in 2020, the DOD released dispense defense space, strategy, highlighting threats, and challenges and opportunities. How would you summarize those threats and those challenges and opportunities? What are the, what are those things that you're watching in the defense space area? Right. >>Well, I think, I think I saw, as I said before, of course, as well, you know, uh, or, or seeing that a space will be highly contested, uh, because it's a critical element in our, in our war fighting construct, uh, Dwayne, a future conflict, I think we need to, to win space as well. So when you, when you look at our near peer adversaries, there's a lot of efforts, uh, in trying to, to, to take that advantage away from the United States. So, so the threat is real, uh, and I think it's going to continue to evolve and grow. Uh, and the more we use space, both commercial and government, I think you're going to see a lot more when these threads some AFAs itself, uh, in, in forms of cyber, cyber attacks, or even kinetic attacks in some cases as needed. Uh, so yeah, so with the, the, the threat is need growing, uh, space is congested, as we talked about, it will continually be contested in the future as well. So we need to have, uh, like we do now in, in, in all the other domains, a way to defend it. And that's what we're working on with India, with the, how do we pilot with tech, our assets in space, and how do we make sure that the data information that traverses through space assets are trust 40, um, and, uh, and, and, and free of any, uh, uh, interference >>Chris, exciting time. I'm your, if you're in technology, um, this is crossing many lines here, tech society will war time, defense, new areas, new tech. I mean, it's security, it's intoxicating at many levels, because if you think about it, it's not one thing. It's not one thing anymore. It spans a broader spectrum, these opportunities. >>Yeah. And I, and I think that expansion is, is a natural outgrowth from, as our microprocessors and chips and technology continue to shrink smaller and smaller. You know, we, we think of our, our cell phones and our handheld devices and tablets, and so on that have just continued to, uh, get embedded in our everyday society, our everyday way of life. And that's a natural extension when we start applying those to space systems. When we think of smallsats and cube sets and the technology that's, uh, can be repurposed into, uh, a small vehicle and the cost has come down so dramatically that, you know, we, we can afford to get a rapid experiments, rapid, um, exploitations and, and different approaches in space and learn from those and repeat them very quickly and very rapidly. And that applies itself very well to an agile development process, dev sec ops, and this notion of spins and cycles and refreshing and re uh, addressing priorities very quickly so that when we do put a new technology up, that the technology is very lean and cutting edge, and hasn't been years and years in the making, but it's, uh, relevant and new, and the, uh, the cybersecurity and the vulnerabilities of that have to be addressed because of, and allow that DevSecOps process to take place so that we can look at those vulnerabilities and get that new technology and those new, new experiments and demonstrations in space and get lessons learned from them over and over again. >>Well, that brings us to the next big topic I want to spend the remainder of our time on that is workforce this next generation. If I wasn't so old, I would quit my job and I would join medially. It's so much, it's a fun, it's exciting. And it's important. And this is what I think is a key point is that cybersecurity in and of itself has got a big gap of shortage of workers, nevermind, adding space to it. So this is, uh, the intersection of space and cybersecurity. There is a workforce opportunity for this next generation, a young person to person re-skilling, this is a big deal. Bong, you have thoughts on this. It's not just STEM, it's everything. >>Yeah. It's everything, you know, uh, the opportunities would have in space it's significant and tremendous. And I think, uh, if I were young, again, as you pointed out, John, uh, you know, I'm, I'm, I'm lucky that I'm in this domain in this world and I started years ago. Uh, but it continues to be exciting, uh, lots of, lots of opportunities, you know, and when you, when you look at, uh, some of the commercial space, uh, systems that are being, being put up, uh, if you look at, I mentioned Starlink before, and, and, uh, Amazon's Kuyper constellation. These guys are talking about couple of thousand satellites in space to provide ubiquitous communications for internet globally and that sort of thing. Uh, and they're not the only ones that are out there producing capability. Uh, we're seeing a lot more commercial imagery products being developed by bike, by companies, both within the U S and, and, uh, foreign foreign elements as well. So I think it's an exciting time to be in space. Certainly lots of opportunities, there's technical challenges, uh, galore in terms of, you know, not only the overcoming the physics of space, but being able to operate, uh, flexibly, uh, in, uh, get the most you can out of the capabilities we have, uh, uh, operating up as high as being cool. I mean, everyone looks at launch. >>She gets millions of views on live streams, the on demand, reruns get millions and millions of views. Um, it's, there's a lot of things there. Um, so Chris, what specifically could you share are things that people would work on? Um, jobs skills, what are some, what's the aperture, what's it look like if you zoom out and look at all the opportunities from a scale standpoint, what's out there, >>We'll talk to the aperture, but I want to give a shout out to our space force. And I mean, their, their job is to train and equip, uh, future space and, uh, that, that space talent. And I think that's going to be a huge plus up, uh, to have, uh, uh, a space force that's dedicated to training equipping, uh, the, an acquisition and a deployment model that, uh, will benefit not just the other services, but all of our national defense and our, uh, you know, our, our strategic way of, uh, how, how this company, country, employees space, uh, altogether. So having, having a space for us, I think, as a, is a huge, uh, a huge issue. And then to get to that aperture aspect of, of what you're, what you're asking and, you know, that addresses a larger workforce. Uh, we need so many different talents in, in this area. >>Uh, we can, we can have, we can employ a variety of people, uh, from technical writers to people who write, uh, write in developed software to those who, uh, are bending metal and actually, uh, working in a hardware environment. And, uh, those that do planning and launch operations and all of those spectrums and issues of jobs, or are directly related to a workforce that can contribute to, to space. And then once that data gets to the ground and employed out to a user, whether it's a data or we're looking at, uh, from a sensor recent, uh, recent events on, uh, shipping lanes, those types of things. So space has such a wide and diverse swath that the aperture's really wide open, uh, for a variety of backgrounds. And, and those that, uh, really just want to take an opportunity, take a, take a technical degree or a degree that, uh, can apply itself to a tough problem, uh, because they certainly exist in space. And we can, we can use that mindset of problem solving, whether you come at it from a hacker mindset, an ethical, a white hat approach to testing and vulnerability exploration, or somebody who knows how to actually, um, make, uh, operations, uh, safer, better, uh, through space situation awareness. So there's a, there's a huge swath of opportunity for us >>Bon talk about the, um, the cyber security enabled environment, the use cases that are possible when you have cybersecurity in play with space systems, um, which is in and of itself, a huge range of jobs, codings supply chain. We just talked about a bunch of them. There's still more connected use cases that go beyond that, that, that are enabled by it. If you think about it, and this is what the students at Cal poly and every other college and university community college, you name it, or watching videos on YouTube, anyone with a brain can jump in. If they, if they see the future, it's an all net new space force is driving awareness, but there's a whole slew of these new use cases that I call space enabled by cybersecurity systems. Your thoughts. >>Absolutely. I, you know, I was, uh, had planned on attending the, uh, uh, the cyber challenge that's Cal poly had planned in June, of course, a pandemic, uh, uh, took care of that plan. But, but I was intrigued by, by the approach that the Cal poly was taking with, with, uh, middle school and high school kids of, of, of, of exposing him to a problem set here. You have a, a satellite that came down from space, uh, and, uh, part of the challenge was to do Porensic analysis on the debris, uh, the remaining pieces of the sound like to figure out what happened. Uh, it had a, uh, a cybersecurity connotation. It was hacked. It was attacked by, by cyber threat nation, took it down. And the beauty of having these kids kind of play with, with the remaining parts of the satellite figure out what happened. >>So I was pretty exciting. I was really looking forward to participating in that, but again, the pandemic kind of blew that up, but I, I look forward to future events like that to, to get our young people intrigued and interested in, uh, in this new field of space. Now, you know, Chris was talking earlier about opportunities, the opportunity that you talk about, you know, while I would like to have people come to the government, right. To help us out. It's not, it's not just focused on government, right? There's not lots of opportunities in commercial space. I, if you will, uh, for, for a lot of talent to, uh, uh, to have, uh, to participate in. So the challenge is a man's government and the commercial sector, John, >>I mean, you get the hardcore, you know, I want to work for the DOD. I want to work for NSA. I want to work for the government. You clearly got people who want to have that kind of mission, but for the folks out there, Chris and bong that are like, I'll do I qualify it? It's like the black box of the DOD. It's like a secret thing. You got any clearance, you've got to get all these certifications. And you've got to take all kinds of tests and background checks. And, um, is it like that? And will that continue? Cause some people might say, Hey, can I even get involved? What do I do? So I know there's some private partnerships going on with companies out there in the private sector. So this is now a new, you guys seem to be partnering and going outside the comfort zone of the old kind of tactical things. What are some of those opportunities that people could get involved that they might not know about >>PR for NSA, there's a variety of workforce, uh, initiatives that, uh, uh, for anybody from a high school work study can take advantage of to, uh, those that would like have to have internships. And those that are in a traditional academic environment, there's, uh, several NSA schools across the country that have a academic and cyber acts, uh, sites of excellence that participate in projects that are shepherded and mentored by those at NSA that can get those tough problems that don't have maybe a classified or super sensitive, uh, nature that that can be worked in and in an academia environment. So, so those are two or three examples of how somebody can break into, uh, the, uh, an intelligence organization and the, and the other agencies have those, uh, opportunities as well across the intelligence community and the, the partnership between and collaborative collaboration between private industry and the agencies and the department of defense just continue to grow over and over again. And even myself being able to take care advantage of a joint duty assignment between my home organization and the Pentagon just shows another venue of somebody that's in one organization can partner and leverage with another organization as well. So I'm an example of, of that partnering that's going on today. >>So there's some innovation, bong, non traditional pathways to find talent. What are out there? What are new, what are these new nontraditional ways >>I was going to add to what Chris was, was mentioning John? Yeah. Even within view and under the purview of our chief information officer, back in 2013, the deputy surfed dirty defense signed the, uh, what we call the DOD cyberspace workforce strategy, uh, into effect. And that included a program called the cyber information technology exchange program. It's an exchange program in which a, uh, you know, private sector employee and worked for the DOD in cyber security positions, uh, span across multiple mission critical areas. So this is one opportunity to learn, uh, you know, in inside the DOD what's happening as a private sector person, if you will, uh, going back to what we talked about, you know, kinda, uh, opportunities, uh, within the government for, for somebody who might be interested, uh, you know, you don't have to be super smart, Bork and space. Uh, there's a lot of like, like Chris pointed out, there's a lot of different areas that we need to have people down within people to do, uh, to conduct the mission space. So you don't have to be mathematician mathematician. You don't have to be an engineer to succeed in this business. I think there's plenty of opportunities for, for any types of, of talent, any type of academic disciplines that, that, that, that they're out there. >>And I think, you know, Chris is shout out to the space force is really worth calling out again, because I think to me, that's a big deal. It's a huge deal. It's going to change the face of our nation and society. So super, super important. And that's going to rise the tide. I think it's gonna create, uh, some activation, uh, for a younger generation, certainly, and kind of new opportunities, new problems to solve new threats to take on and, and move it on. So really super conversation space in cybersecurity, the department of defense perspective, Von and Chris, thank you for taking the time. I'd love you guys just to close out. We'll start with you bong. And then Chris summarize for the folks watching, whether it's a student at Cal poly or other university or someone in industry and government, what is the department of defense perspective for space cybersecurity? >>Chris, won't go and take that on. I started, thank you. Uh, cyber security applies to much more than just the launch and download of mission data or human led exploration and the planning, testing, and experiments in the lab prior to launch require that cyber protection, just as much as any other space link, ground segment, trust rail network, or user data, and any of that loss of intellectual property or proprietary data is an extremely valuable and important, and really warrants, cybersecurity safeguards in any economic espionage or data exfiltration or denied access to that data I E ransomware or some other, uh, attack that can cripple any business or government endeavor. Uh, no matter how small or large, if it's left in our economic backbone, uh, clearly depends on space and GPS is more than just a direction finding our banking needs that a T and timing from P and T or whether it says systems that protect our shipping and airline industry of whether they can navigate and go through a particular storm or not, uh, even fighting forest fires picked up by a remote sensor. >>All those space-based assets, uh, require protection from spoofing date, uh, data denial or total asset loss. An example would be if a satellite sensitive optics were intentionally pointed at the sun and damaged, or if a command, uh, to avoid collision with another space vehicle was delayed or disrupted or a ground termination command. As we just saw just a few days ago at T minus three seconds prior to liftoff, if those all don't go as planned, uh, those losses are real and can be catastrophic. So the threat to space is pervasive real and genuine, and your active work across all those platforms is a necessary and appreciated. And your work in this area is critical, uh, going forward going forward. Uh, thank you for this opportunity to speak with you and, uh, talking on this important topic. >>Thank you, Chris Henson, goodbye. >>Closing remarks. Yeah. Likewise, John, uh, again, uh, as, as Chris said, thank you for, for the opportunity to discuss this very important, uh, around space, cyber security, as well as addressing, uh, at the end there, we were talking about workforce development and the need to have, uh, people, uh, in the mix for four features. We discussed with you. We need to start that recruiting early, uh, as we're doing to address, uh, the STEM gap today, we need to apply the same thing for cybersecurity. We, we absolutely need smart, innovative people to protect both Iraq. Anomic wellbeings a nation as well as our national defense. So this is the right conversation to have at this time, John and I, again, thank you and our Cal poly hose for, or, uh, having a symposium and, and having this opportunity to have this dialogue. Thank you, >>Gentlemen. Thank you for your time and great insights. We couldn't be there in person. We're here virtual for the space and cybersecurity symposium, 2020, the Cal poly I'm Jennifer with Silicon angle and the cube, your host. Thank you for watching.

Published Date : Oct 1 2020

SUMMARY :

It's the queue cover the space and cybersecurity symposium this year, you know, and despite the pandemic, Uh, space is the newest war fighting what I want to share with you today is how the current space strategy ties into the national defense strategy and effectively to leverage emerging technologies and seize opportunities to advance your assurance of the information and resilience of the underlying terrestrial air in space networks You know, more and more, uh, we see greater use of small satellite systems to address a myriad While a number of these companies continue to grow. and Steve Jake's the founder of the national security space association to address workforce development. We need the new skill space is here. the European space agency, and, uh, the Canadian space agency, So we asked my first question, Bonnie, we'll start with you is what do you see as the DOD his role in addressing the support technology development, uh, digital safety policy advocacy, is the leadership role and that leadership, uh, blends out very well over the different, uh, locations, well space will be that natural models of the space force and the DOD and getting space. uh, uh, you know, for local national security information. to be a leader and how do you assist others to get involved? Yeah, I think, uh, the one hand, you know, Ally's commercial companies are actually legally leading the R and D uh, of a lot of different What's your view on it? So, uh, and, and mentioned it a couple of topics that you hit on already. And, uh, you know, I mean, you got Intel, you got Nvidia, And I says, you know, Now you have open innovation with hardware, delivery of that from an end to end system. into the system, that, uh, before we employ them, Uh, and, uh, so we that all on the ground before we, we take it up to launch it. on the commercial side or students out there who are, you know, wanting to jump in, So that guidance in and of itself shows the emphasis of cyber security that So that shows a level of the CMMC process that we've thought about for the dependency that NASA States, uh, and it's important for, So you can be fast, all think are all things. Uh, and the more we use space, I mean, it's security, it's intoxicating at many levels, because if you think about it, and so on that have just continued to, uh, get embedded in our everyday society, So this is, uh, the intersection of space and cybersecurity. Uh, but it continues to be exciting, uh, lots of, jobs skills, what are some, what's the aperture, what's it look like if you zoom out and look our, uh, you know, our, our strategic way of, uh, how, how this company, can apply itself to a tough problem, uh, because they certainly exist when you have cybersecurity in play with space systems, um, analysis on the debris, uh, the remaining pieces of the sound like to figure Now, you know, Chris was talking earlier about opportunities, the opportunity that you talk about, I mean, you get the hardcore, you know, I want to work for the DOD. industry and the agencies and the department of defense just continue to So there's some innovation, bong, non traditional pathways to find talent. to learn, uh, you know, in inside the DOD what's happening as a private sector And I think, you know, Chris is shout out to the space force is really worth calling out again, because I think to and experiments in the lab prior to launch require that cyber protection, So the threat to space is pervasive real So this is the right conversation to have at this time, John and I, the space and cybersecurity symposium, 2020, the Cal poly I'm Jennifer with Silicon angle and the cube,

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
ChrisPERSON

0.99+

Chris HensonPERSON

0.99+

Chris NissenPERSON

0.99+

JohnPERSON

0.99+

StevenPERSON

0.99+

BonniePERSON

0.99+

BobPERSON

0.99+

GuzmanPERSON

0.99+

2013DATE

0.99+

Steve JakePERSON

0.99+

millionsQUANTITY

0.99+

2020DATE

0.99+

DwaynePERSON

0.99+

FCCORGANIZATION

0.99+

NvidiaORGANIZATION

0.99+

JuneDATE

0.99+

PaulPERSON

0.99+

VonPERSON

0.99+

2022DATE

0.99+

hundredsQUANTITY

0.99+

AmazonORGANIZATION

0.99+

GUMAPERSON

0.99+

DODORGANIZATION

0.99+

2018DATE

0.99+

first questionQUANTITY

0.99+

PentagonORGANIZATION

0.99+

4th of October, 1957DATE

0.99+

twoQUANTITY

0.99+

NSAORGANIZATION

0.99+

1957DATE

0.99+

2021DATE

0.99+

Cal polyORGANIZATION

0.99+

JenniferPERSON

0.99+

LuciaPERSON

0.99+

U SLOCATION

0.99+

todayDATE

0.99+

FirstQUANTITY

0.99+

U SORGANIZATION

0.98+

one exampleQUANTITY

0.98+

bothQUANTITY

0.98+

eachQUANTITY

0.98+

Darlene constellationLOCATION

0.98+

first artificial satelliteQUANTITY

0.98+

one organizationQUANTITY

0.98+

over 3000QUANTITY

0.98+

DonPERSON

0.98+

IntelORGANIZATION

0.98+

StarlinkORGANIZATION

0.98+

one opportunityQUANTITY

0.98+

eightiesDATE

0.98+

firstQUANTITY

0.98+

MedTec Entrepreneurship Education at Stanford University


 

>>thank you very much for this opportunity to talk about Stamp with a bio design program, which is entrepreneurship education for the medical devices. My name is Julia Key Can. Oh, I am Japanese. I have seen the United States since two doesn't want on the more than half of my life after graduating from medical school is in the United States. I hope I can contribute to make them be reached between Japan that you were saying right I did the research in the period of medical devices with a patient all over the world today is my batteries met their country finished medication stamp of the city. Yeah, North Korea academia, but also a wrong. We in the industry sectors sometimes tried to generate new product which can generate revenue from their own research outward, it is explained by three steps. The first one is the debut river, which is the harbor Wrong research output to the idea which can be product eventually. That they are hard, though, is the best body, which is a hot Arboria. From idea to commercial for the other one is that we see which is a harder to make a martial hold up to become a big are revenue generating products for the academia that passed the heart is a critical on the essential to make a research output to the idea. Yeah, they're two different kind of squash for the developing process in the health care innovation, Why's bio and by all the farmer under the other one is medical device regarding the disciplining method is maybe in mechanical engineering. Electrical engineering on the medical under surgical by Obama is mainly chemical engineering, computer science, biology and genetics. However, very important difference off these to be the innovation process. Medic is suitable on these digital innovation and by Obama, is suitable discovery process needs. Yeah, in general transformation of medical research between the aroma academia output to the commercial product in the medical field is called bench to bed. It means from basically such to critical applications. But it is your bio on the path. Yeah, translation. Medical research for medical devices is better. Bench on back to bed, which means quicker Amit needs to bench on back to Greek application. The difference off the process is the same as the difference off the commercialization. Yeah, our goal is to innovate the newer devices for patient over the war. Yeah, yeah, there are two process to do innovation. One is technology push type of innovation. The other one is news, full type of innovation. Ignore the push stop Innovation is coming from research laboratory. It is suitable for the farm on the bios. Happy type of innovation. New, useful or used driven type of type of innovation is suitable for medical devices. Either Take this topic of innovation or useful type of innovation. It is important to have Mini's. We should think about what? It's waas Yeah, in 2001 stop for the Cube, API has started to stop with Bio Design program, which is on entrepreneurship education for medical devices. Our mission is educated on empowering helps technology, no based innovators on the reading, the transition to a barrier to remain a big innovation ecosystem. Our vision is to be a global leader in advancing Hearst technology innovation to improve lives everywhere. There are three steps in our process. Off innovation, identify invent on England. Yeah, yeah. The most important step is the cluster, which is I didn't buy. I didn't buy a well characterized needs is the Vienna off a grating vision. Most of the value off medical device development is due to Iraq Obina unmet needs. So we focused in this gated by creates the most are the mosque to find on the Civic on appropriate. Yeah, our barrels on the student Hickory World in March, disparate 19 that ideally include individual, which are background in many thing engineering on business. Yeah, how to find our needs. Small team will go to the hospital or clinic or environment to offer them the healthcare providers with naive eyes. The team focused. You look to keep all the um, it needs not technology. This method is senior CTO. It's a rocket car approach which can be applied all that design, thinking the team will generate at least 200 needs from economic needs. Next stick to identify Pace is to select the best. Amit Knees were used for different aspect, which can about it the nominees. These background current existing solutions market size on the stakeholders. Once we pick up ur madness from 200 nominees, they can move to the invention pates. Finally, they can't be the solution many people tend to invent on at the beginning base without carefree evaluating its unmet knees to result in a better tend to pouring love. Their whole idea, even amid NIS, is not what this is. Why most of the medical device innovation fail due to the lack off unmet needs. To avoid this Peter Hall, our approach is identify good needs. First on invention is the sex to generate the idea wrong. Unmet knees. We will use seven Rules off race Tony B B zero before judgment encourage wild ideas built on the ideas off. Others. Go Conte. One conversation time. Stay focused on the topic. The brainstorming is like association game. Somebody's idea can stimulate the others ideas. After generating many ideas, the next step is sleeping of idea whether use five different Dustin to embody the ideas. Intellectual property regulatory. Remember National Business Model on technology How, after this election step, we can have the best solution with system it needs, and finally team will go to the implementation pace. This place is more business oriented mothers. The strategy off business implementations on the business planning. Yeah, yeah, students want more than 50 starting up are spinning off from by design program. Let me show one example This is a case of just reputations. If patient your chest pain, most of that patient go to family doctor and trust. The first are probably Dr before the patient to General Securities. General Card, obviously for the patient Director, Geologist, Director, API geologist will make a reservation. Horta uses it. Test patient will come to the clinic people for devices in machine on his chest. Well, what? Two days? Right? That patient will visit clinic to put all the whole decency After a few days off. Analysis patient Come back to Dr to hear the result Each step in his money to pay. This is a minute, Knees. This is a rough sketch off the solutions. The product name is die. A patch on it can save about $620. Part maybe outpatient right here. >>Yeah, yeah. Life is stressful. We all depend on our heart with life source of our incredible machine. The body, however, sometimes are hard Need to check up. Perhaps you felt dizzy heart racing or know someone who has had a serious heart problem The old fashioned monitors that used to get from most doctors or bulky And you can't wear them exercising or in the shower. If appropriate for you, sudden life will provide you the eye rhythm. Zero patch to buy five inch band aid like patch would. You can apply to your chest in the comfort of your own home or in the gym. It will monitor your heart rate for up to 14 days. You never have to come into a doctor's office as you mail back. Patched us shortly after you were receiving. Easy to understand report of your heart activity, along with recommendations from a heart specialists to understand the next steps in your heart. Health sudden life bringing heart monitoring to you. >>This is from the TV broadcasting become Ah, this is a core value we can stamping on his breast. He has a connotation of the decent died. Now the company names Iris is in the public market cap off. This company is more than six billion di parts is replacing grasp all or that you see the examination. However, our main product is huge. The product lifecycle Very divisive, recent being it's. But if we can educate the human decision oil because people can build with other people beyond space and yeah, young broader stop on by design education is now runs the media single on Japan. He doesn't 15 PBS probably star visited Stamp of the diversity and Bang. He announced that Japan, by design, will runs with vampires. That problem? Yeah, Japan Barzan program has started a University of Tokyo Osaka University and we've asked corroborating with Japanese government on Japanese medical device Industry s and change it to that. Yeah, this year that it's batch off Japan better than parachute on. So far more than five. Starting up as being that's all. Thank you very much for your application.

Published Date : Sep 21 2020

SUMMARY :

is. Why most of the medical device innovation fail due to the lack off unmet The body, however, sometimes are hard Need to check up. This is from the TV broadcasting become Ah,

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
ObamaPERSON

0.99+

Peter HallPERSON

0.99+

Julia Key CanPERSON

0.99+

United StatesLOCATION

0.99+

200 nomineesQUANTITY

0.99+

MarchDATE

0.99+

Two daysQUANTITY

0.99+

Amit KneesPERSON

0.99+

2001DATE

0.99+

twoQUANTITY

0.99+

more than 50QUANTITY

0.99+

more than six billionQUANTITY

0.99+

three stepsQUANTITY

0.99+

Tony B BPERSON

0.99+

PBSORGANIZATION

0.98+

about $620QUANTITY

0.98+

JapanLOCATION

0.98+

JapaneseORGANIZATION

0.98+

FirstQUANTITY

0.98+

five inchQUANTITY

0.98+

University of Tokyo Osaka UniversityORGANIZATION

0.98+

firstQUANTITY

0.98+

EnglandLOCATION

0.98+

this yearDATE

0.97+

first oneQUANTITY

0.97+

15QUANTITY

0.96+

Each stepQUANTITY

0.96+

Zero patchQUANTITY

0.96+

Stanford UniversityORGANIZATION

0.95+

todayDATE

0.95+

JapaneseOTHER

0.95+

up to 14 daysQUANTITY

0.94+

more than fiveQUANTITY

0.93+

more than halfQUANTITY

0.93+

Stamp of the diversityTITLE

0.92+

Hickory WorldORGANIZATION

0.92+

BangTITLE

0.91+

MedTecORGANIZATION

0.89+

one exampleQUANTITY

0.88+

two processQUANTITY

0.88+

fiveQUANTITY

0.88+

seven RulesQUANTITY

0.87+

19QUANTITY

0.86+

ViennaLOCATION

0.86+

OneQUANTITY

0.86+

at least 200 needsQUANTITY

0.85+

singleQUANTITY

0.84+

One conversation timeQUANTITY

0.78+

GreekOTHER

0.76+

two different kindQUANTITY

0.76+

daysDATE

0.75+

AmitPERSON

0.74+

ContePERSON

0.73+

DesignOTHER

0.7+

oneQUANTITY

0.66+

APIORGANIZATION

0.63+

NISORGANIZATION

0.63+

SecuritiesORGANIZATION

0.61+

North KoreaLOCATION

0.6+

IrisORGANIZATION

0.59+

HortaPERSON

0.55+

PaceORGANIZATION

0.54+

JapanORGANIZATION

0.54+

zeroQUANTITY

0.52+

DustinCOMMERCIAL_ITEM

0.5+

Iraq ObinaLOCATION

0.49+

CubeORGANIZATION

0.4+

Japan BarzanOTHER

0.34+