Video summary
The Cyber Shift Podcast Episode 2 explores a fundamental shift in how organizations approach security, moving from traditional disaster recovery focused on tangible infrastructure failures to the emerging concept of cyber resilience against distributed and hidden threats. Historically, resilience planning was built around known physical events like natural disasters or data center outages where failure points were clear and predictable. However, with the rise of sophisticated cyber incidents driven by AI, attackers can now operate at unprecedented speed and scale, making disruptions difficult to scope and impossible to predict in advance. Consequently, the industry must evolve from merely recovering lost infrastructure to establishing a "defensible recovery posture" that ensures applications and data remain uncompromised even when facing advanced malware or ransomware attacks that bypass traditional security perimeters.
As threats accelerate due to AI integration, relying solely on backups is no longer sufficient because restoring individual datasets does not guarantee the continuity of critical business services. The conversation highlights a necessary paradigm shift from a technical, data-centric approach to an enterprise-wide, business-service centric strategy. Organizations must now orchestrate recovery across heterogeneous environments involving applications, data replication, and security protocols simultaneously to meet strict Service Level Agreements (SLAs). This holistic view requires breaking down organizational silos so that every role, from the CEO to individual contributors, understands their part in maintaining resilience. The focus has shifted from achieving technical wins like replicating a database to ensuring business outcomes are protected, including reputation and customer trust, which cannot be rebuilt with goodwill alone after a breach involving personal data.
Looking toward the future of cyber resilience over the next few years, experts anticipate that operational resilience will become a key competitive differentiator rather than just an insurance policy. While AI-driven autonomous recovery tools offer significant speed advantages for routine operations, there remains a critical need for human oversight during consequential decision-making moments to prevent agentic models from acting unpredictably or causing further damage. The industry is expected to see the breakdown of departmental barriers as teams realize that resilience is not solely the responsibility of IT or security departments but an ideology embraced across the entire stack. Ultimately, while caution regarding AI adoption will persist due to recent incidents involving rogue agents, organizations must embrace these technologies cautiously yet decisively to keep pace with adversarial attacks, ensuring they transform their business operations rather than merely adding another tool to a static toolbox.
Read the full video transcript
[music]
Hello and welcome to Cyber Shift, the
podcast where we explore the shifts
changing how organizations think about
security, resilience, and business
continuity. I'm Christa Casease,
principal analyst and practice lead for
cyber security and resilience here at
the Cube Research. And we have a really
great episode for you today. We're going
to be talking about cyber resilience and
how that definition is changing these
days. Now, for decades, we've seen
resilience planning was really built
around known failures. So, things like a
natural disaster, a data center going
down, um or someone making an
operational mistake. Um in that context,
generally, you know, what failed, when
it failed, and where to begin recovery.
But today, it's far more likely that
organizations are going to um be
disrupted by a cyber incident. Um and
these and in these incidents the
disruption is distributed. It's hidden
and it's really difficult to scope. Um
and AI is only raising those stakes
further because attackers can operate
faster and at a greater scale and
enterprises are embedding AI into more
business processes. So here to dig into
all those topics with me today is Joe
D'Angelo, director of product management
for data resiliency at Infoscale. Joe,
thank you so much for joining us today.
Uh Christa, it's great to be here.
Thanks for having me.
>> Of course. Of course. And Joe, I think
you're really the perfect guest to um to
talk about this topic. Um I know in our
prep call yesterday, you were talking
about sort of, you know, your tenure at
Infoscale and how you've really been in
kind of a front row perspective to see
this shift um from again kind of these
physical attacks to these cyber attacks.
So um I wanted to first I guess kind of
just get some background context from
you, right? in terms of um traditional
cyber resilience thinking and planning
and how the cyber scenario forces a
different way of thinking.
>> Yeah, that is exactly the uh the
question that gets asked me most
frequently these days. You know, our our
historical perspective on resiliency and
disaster recovery, high availability has
been rooted very much so in this
infrastructure concept, right? Something
that you can it's tangible, you can put
your hands on it, right? It's this idea
that um you know my physical device has
suffered some sort of failure. how do I
recover from that or I've lost access to
something that again is result and it
could be a software defect but it's
something that it's tangible that's
changed right it's changed dramatically
and listen we were very much you know in
the the legacy of of of of semantic into
veraritoss into arctera and now into
infoscale with with with CSG you know we
were very much at the forefront of those
infrastructure discussions anyone who's
seen some of our old content knows that
we've done some pretty wild things with
infrastructure faults right pushing data
centers off the roof of buildings and
flooding them in hurricane simulators
and doing all those very entertaining um
but at the same time very extreme
examples. Um none of which that would
have addressed an you know an AI attack
or a cyber resiliency attack right
[gasps] so we know that that has changed
the the attack surface is growing
tremendously the uh exposure the fallout
all of that is increasing exponentially
um so must then so the response and so
much so should then the uh way that you
envision your cyber resiliency posture.
Yeah, absolutely. And I really
appreciate you kind of bringing up the
AI side of things. And to your point,
although it's not as eye-opening as
pushing a data center off of the roof of
a building, um it can be, you know,
arguably even more impactful just
because of the scale that these attacks
can operate at. Um and really just the
the interconnected nature these days of
our environment. So if one area is
penetrated, it can quickly spread, you
know, elsewhere in the environment. So I
wanted to get your perspective on that
AI view in particular and given that
these attacks can unfold in minutes or
even seconds. How does that change the
recovery equation from your perspective?
>> Yeah, that is precisely it. When things
are happening in real time, uh you have
to have a means of recovery that is
commensurate. Uh so if you you know you
can there's no horizon there's no uh
hurricane warning there's no tsunami
warning that a that a ransomware attack
or an AI attack is coming um you can
kind of see meantime between failures of
of devices and physical equipment. So
you can almost predict in some regard
that there's no prediction here. So the
only way to protect yourself is to
ensure that you have a def what we
really like to call a defensible
recovery posture. And that is um
understanding the state of your your
applications, understanding the state of
the data and being able to uh recover
those in a way that um uh is not
encumbered or in any way compromised by
an attack. Um so that means um looking
at you know your your enterprise
holistically. It's not just looking at
one application. It's not just looking
at one data set, but rather it's looking
at them together as a um sort of an
aggregate. Uh but then at the same time
being able to prove that it's not just a
uh physical infrastructure fault that
you're protecting from, but you also
want to be able to ensure that there was
known malware or known ransomware
attacks that uh uh can uh can penetrate
your environment. How do I then sort of
distance myself or separate myself from
that uh that blast radius?
>> Yeah, absolutely, Joseph. And what I
really like is that you're you're kind
of referencing the fact that um you know
backup in kind of the data itself, it's
still a very important piece of the
resilience equation. Um but really that
resilience equation today needs to be
grounded in an understanding of those
trusted business operations and
especially those critical business
services and what it takes to get those
back up and running after an attack. Um,
so can you I guess maybe talk a little
bit more about that in particular and
why just recovering the data itself is
no longer sufficient these days?
>> Yeah, I mean it's it's a combination of
things, right? First, it's the, you
know, this idea that your security
posture has to improve. Um, it used to
be that and I use this analogy um
recently and I I think it it'll it'll
resonate. Um, it used to be your
security posture was either to add, you
know, more locks to your door, maybe a
more sophisticated combination, you
know, a numerical pad, but none of that
matters if someone's just going to come
in with a battering ram and kick in your
front door where none of those security
measures are are relevant anymore. And
that's kind of what we're dealing with
here with this onset of of AI based
tools. um you know you get to this point
of quantum computing where things are
going to happen so fast that we can't
even contemplate what is going to be
needed in order to you know insulate
yourself from those types of uh of
situations. So for us the way we look at
it is is that backup and recovery is an
essential part of your uh um recovery uh
posture but it's not the only part. Uh
back recovery tends to look typically
more as a datacentric approach. Um, and
we actually want to have people start
looking at it more from an enterprise
business ccentric approach. Meaning
you're going to have to look at services
and applications and data and
replication and all these different
functions and have to be able to
orchestrate them together, but at the
same time make sure that where you're
recovering to is also going to be um,
again defensible, free from contaminants
uh, and um, able to resume your
business, you know, in a in an
appropriate time to meet your SLAs's.
>> Yeah, absolutely, Joe. And I know, you
know, you brought up kind of that that
visual of the door being, you know, kind
of, you know, beaten down, right, for
lack of a better way to put it. Um, and
I think it's so true. You know, we look
at prevention as still a critical piece
of this continuum of cyber security to
cyber resilience, but it's no longer
sufficient. And so, you really need um
the ability to operate through that
disruption these days. So can you talk
to the fact that you know practitioners
um they have less time to detect um to
understand what's happening to isolate
and recover can and they have to make
some of these high consequence decisions
very quickly so I guess can you maybe
elaborate on that a little bit
>> yeah I think that when it comes down to
it the uh investment you make in your
sort of recovery technologies and
recovery procedures um needs to be uh
needs to meet that that demand needs to
meet that SLA
So if you have say a workload that is um
critical to your business and it does
suffer some sort of cyber attack or some
sort of you know AI based threat um and
your you know backup and recovery type
solution it may take 24 to 48 hours or
however long to recover to it that's not
sufficient. So, one of the things that
we try to do is to open up a sort of the
aperture on your view into your
enterprise and say, well, you've got
your primary data, you've got backup
data, you've got application data,
you've got all these different sources
of data, and they're really not often
aware of one another. Um, how do you
create an orchestration model that can
be right sized for the different
workloads, but also doesn't
overenccumber you from an operational
standpoint? So that's where we've, you
know, we see the the the the sort of the
next phase or the next generation of of
cyber resiliency. It's being able to
look into all these different pieces and
understand uh exactly what they mean to
your business. Um and that's you know um
you know
as uh uh shown by the you know the
partnerships that we've forged and the
the different technologies that we're
investing in and the different
capabilities that that we're introducing
into our into our solutions all kind of
feed into that narrative. If I'm reading
through the lines here a little bit, you
know, you're alluding to some greater
visibility and kind of coordination that
needs to occur, you know, I imagine not
just within IT. Um, a little bit of a
leading question, but one thing we like
to do here on Cyber Shift is also talk
through some of the new decisions that
practitioners are having to make. Yeah.
>> So, I'm wondering if you can talk
through some of the biggest mind sh
mindset shifts um that you're seeing
both IT and security practitioners have
to make as they start to rethink
business continuity in their cyber
resilience.
>> At at the risk of sounding uh bougie
from an IT perspective, it's a paradigm
shift, right? And everybody everybody
loves these phrases. Um but it is and I
say that um minimally in justest uh that
when in reality what's happening here is
is that individuals whom in the past
maybe never were front and center in a
cyber resiliency conversation or perhaps
maybe were adjacent to the conversation
are now equally as important or can
contribute to the conversation as much.
So it's not just a CISO, it's not just a
CTO, it's not just an a a practitioner
from a technology standpoint, but rather
the entire organization, right? From the
individuals who are entering data entry
all the way up to the CEO all play a
significant part in your cyber
resiliency posture. And that's the
change, right? And what's important is
to break down the silos and the barriers
between those teams because if you
continue to operate independently and
you continue to operate in these silos,
you're never going to truly be able to
achieve that kind of um you know
comprehensive cyber resiliency. It's
it's still going to be very tactical um
and and may suit for smaller
organizations or organizations with much
you know um you know uh weaker SLAs's
and so on and so forth. But for most of
the customers that we work with and the
ones that we are constantly in
communication with, you know, their
demands are are are really driving a lot
of these changes.
>> Yeah, absolutely. Joe, you know, you
referenced kind of SLAs's and what we're
seeing is it's almost less about, you
know, RPO, RTO, I mean, that's an
important piece of the conversation, but
it's less about we need to recover, you
know, this particular database within a
certain amount of time. It's more about
kind of having ownership over the
business services and again really
understanding impacts to downtime and
recoverability. So it it sounds like
you're seeing that as well.
[clears throat]
>> Absolutely. In fact, I like to say that
what we are driving are business
outcomes, not, you know, not technical
achievements, right? They're they're you
can achieve technical, you know, wins by
saying, "Oh, I have this application and
it's replicated from site A to site B."
That's great, but that's not in and of
itself a cyber resiliency solution. That
is a tactical approach to one
application. If you had to ask the same
the person the same question be like,
okay, this application is protected, but
is your business protected? Is your
reputation protected? Is your enterprise
protected? Is something if something
happens to that app, is it going to, you
know, wake up the CEO? Those types of
questions now have to be asked because
these these threats are happening so
dramatically. They're happening so fast
and they're happening so widespread that
every single group is being impacted. So
it's not just it it works almost in
reverse, right? If you start with an
infrastructure solution, you're not
guaranteed to get a cyber resiliency
outcome, right? But if you start with
the cyber resiliency posture and work
your way backwards, all that
infrastructure challenges are implicitly
addressed, right? If you could pro
defend yourself against a ransomware, AI
based malware attack, you know, however
you want to combine the phrases you
want, you implicitly will be protected
from the, as I like to put it, the
fires, floods, fault lines, fatfingered
commands, all the things that we've
been, you know, concerned about. I
jokingly say that if today a data center
floods and a CTO gets the phone call,
they're probably going to be relieved.
They're like, "Wait, it's just a flood.
It's just my infrastructure. That's all
that happened. Oh, thank God. That's not
going to that's not going to affect
stock prices. That's not going to affect
our reputation, right? You know, fire in
the data center. Is it out? Is everybody
safe? Great. I'm not going to lose any
sleep over that anymore." Whereas that
that used to be like the death nail in
the coffin for a business. Now it's this
sort of like, oh jeez, [laughter] that's
not the worst that could happen to us,
right? It's not this existential threat.
>> It's so true. And you hit on two things,
Joe. I think the first is okay, they
understand specifically what happened,
when it happened, what was impacted. You
know, there's a lot of kind of really
concrete visibility there, but then also
you talk about, you know, the
reputation, right? And so there's um
when we step back and think about it,
how do we even quantify the impact of a
cyber incident? it's nearly impossible
because of all of these other factors
that go into it that have, you know,
longer term implications even beyond
just, you know, that particular business
service being taken down for a period of
time. [snorts]
>> It's um it's always going to be in the
back of someone's mind if their data and
their personal information was somehow
compromised because of a weak cyber
resiliency posture from a particular
service they use. It will always be
there. No amount of goodwill, no amount
of everything's okay will ever take that
sort of little nagging notion like if I
click enter here is my data ever going
to be safe again. Um, I don't I mean my
wife's had to replace her credit card I
don't know how many times because places
that she's reputable places are
constantly saying we had a you know we
had a cyber incident and your data was
you know and I looked and I'm like just
a month ago she's like what did you buy
for $300 on GrubHub and I'm like I did
not buy $300 worth of food on GrubHub.
I've never even used GrubHub. uh more of
a Door Dash guy. But [laughter]
uh uh but the point being is that
obviously these things happen and it
happens no matter how much you you you
act in um you know you know safe circles
these things will happen. But the point
being is that next time she goes to use
that merchant again. She's like but if
it was like a physical data center fault
there's like hey we're just having an
outage we'll be back up and running.
That that's almost acceptable right? We
can we can accept it that you know
things happen that way. Um, so yeah,
that's the change that's happening.
>> Absolutely. And so Joe, I know you
talked to kind of a cyber resilience
strategy and if you know the
organization starts there, they'll then
have a strategy for resilience of the
infrastructure. Um, for the
practitioners that are listening to
this, I'm wondering if you could maybe
just give a couple thoughts in terms of
kind of what that looks like, where
should they start?
>> Where should they start? Yeah. uh you
know for us and and you know I'm I'm
biased in the sense that I you know I
work for a company and have endorsed
this and and been an advocate for this
use case for many many years. It starts
with your applications, right? It starts
with the con that which is the the face
of your enterprise and your business out
to your customers and that is going to
be those applications and in many cases
it's not just one app but it's more of
an aggregate or tapestry of applications
you know interconnected. Um it starts
there. It's understanding those
relationships first and foremost because
when we talk about a a strong cyber
resiliency posture orchestration
couldn't be a bigger factor, right?
Being able to coordinate that recovery
is so critical because time-sensitive uh
recovery that that's you know cutting
what you can out of your your time to
recovery or your RTO that's something
everyone can control right your recovery
point objective is a little bit
different right that's very much
dependent on other pieces but being able
to take out some of those operational
overhead uh that will dramatically help
with uh with RTO um so knowing those
relationships that's that's the first
place to start um and then figuring out
how do I provide a solution that's going
to work across as wide a a a a a
cross-section of my environment. Uh help
to orchestrate as many of these
different pieces as I can. Um but at the
same time, um not discount the fact that
not every application is created equal.
You have different business objectives
and different business tier criticality.
So being able to quantify that and being
able to capture that is also critical so
that you know what that sequence would
be and what that would be. This is a
different
>> and I would say sort of quantifying that
leads me into my next question for you
Joe which is if I am a board level
executive right and I'm just thinking
about everything we're talking about
today and I had to understand only one
thing about cyber resilience and how
it's evolving what would it be from your
perspective
>> well I I've had a chance to speak to a
couple of boards in my day and I would
say that without being alarmist or
coming across as hyperbolic like AI
based threats are probably the most
consequential thing that that we will
have to face in this industry in in the
modern IT age right because it has um
accelerated so much across the board so
with that knowing that again not trying
to sound alarmist or hyperbolic I would
say that what a board needs to
understand is that cyber resiliency is
everyone's responsibility right you you
need to understand that it is not just a
product you purchase it is not just
software you install it is not just some
piece of equipment that you rack in a
data center. Cyber resiliency is an
ideology that you have to embrace up and
down the stack. It's in how you uh
advocate for you know uh you know safe
you know digital uh you know safe
digital presence. It's how you uh
operate within in terms of how you
orchestrate the different recovery
procedures. It has to deal with the uh
the uh sort of the uh uh heterogeneous
nature of so many different technologies
and how that can can in many cases
impact your your recoverability. So it's
it's everyone. It's the CEO, the CTO,
the CISO, the the the the uh all the way
down to the individual contributors all
play a in many cases a significant part
uh in cyber resiliency and how you
intend to recover.
>> It's definitely it's a team sport,
right?
>> Yeah. Yeah. Yeah. This is not golf. This
is not golf. This is this is my golf
>> for sure. So Joe, we're going to move to
um the next section here in cyershift
which we call signal or noise. Um it's a
rapidfire segment. I'm going to give you
a handful of statements and you're going
to give your reaction in the context of
this is kind of where the industry is
heading. Is it something that is kind of
just noise we don't need to pay
attention to or got it?
>> Yeah. Right. Exactly.
>> Yeah.
>> All right. So Joe, the first one is
disaster recovery is becoming
operational resilience.
>> Uh that one is uh signal. That was
absolutely signal. And the reason I say
that is because you have to embrace this
idea of not just reacting but being
proactive, right? You have to have a a
posture that uh when that disaster
happens, you kind of give a little brush
your shoulder off be like, I don't care
that happened because I know that my
resiliency posture puts me in a place
where I can recover at a moment's
notice. Uh I can in advance of things if
I need to or when the, you know, when
that strike happens, I know I've got a
defensible recovery point and I can I
can be up and running in in a moment's
notice.
All right, our second statement here is
backup alone delivers cyber resilience.
>> Uh that's definitely noise. I'm selling
that one. I'm not buying that one. Uh
backup alone uh does not address the
context of your enterprise. It looks at
uh almost like a very narrow lens of
what it is intended to recover and the
window of time in which it needs to
recover it. It does not look at your
enterprise or your business. And this is
evidenced by the fact if you look at
most backup solutions, they're now
embracing a broader orchestration
framework and narrative as well. Um
because simply having a backup copy,
there are a million products out there
that can make a copy of your data. They
can say it can be restored and super
super fast and it can be scanned if you
do this and all that. But again, that's
one data set. When you talk about
recovering your enterprise and
orchestrating across uh a heterogeneous
set of applications and services, uh
backup alone doesn't uh doesn't get it
done.
All right, our next statement. Recovery
will have to become increasingly
autonomous.
>> Uh that one I am going to also buy. Uh I
think that one is definitely signal. Um
because the ability for the human
intervention now is critical because we
have to understand how these changes are
happening. But eventually sort of this
agentic mindset is going to kind of be,
you know, taking over and we're going to
have to build towards that sort of fight
fire with fire, right? Everybody
understands that that that expression.
So the only way we're going to be able
to respond that quickly is if we have
solutions that act that quickly. Um so
yes, autonomy and autonomous type
recovery is going to be a huge part of
the future of resiliency.
>> All right. And Joe, our last statement
here, operational resilience will become
a competitive differentiator.
Oh, that is absolutely signal. Um, in I
if you as an organization are basically
uh your digital presence is your entire
presence these days, right? It used to
be that it was just something that was
there and you know you you used it and
it was more of a tool. Well, now it's
actually it represents in many cases
your entire enterprise and your your
business everything from the transaction
side of it, the service that you
deliver. Um, so yeah, it it is
absolutely critical. Um, so yeah, I'm I
am uh I'm that signal all the way for
me.
>> I definitely agree, Joe. I think it
previously maybe was this insurance
policy. Um, but now I think absolutely
as that disruption becomes inevitable,
it's it's really that differentiator.
>> Yeah, it's it's um the idea that the the
the saying that everybody has a plan
until you get punched in the mouth,
right? And then you're back on your
heels and you're like, what do I do now?
uh every single organization is going to
get punched in the mouth with an AI
based cyber threat malware attack. It is
a question of of when not if. Um so
best move is to be prepared for it now.
Build at build that into your plan your
road map your vision for how your your
enterprise is going to operate. Uh and
you'll be uh you'll be better off for it
in the long run for sure.
>> Absolutely. All right, Joe, we have just
a few minutes left here. Um, I've got a
couple of kind of closing
forward-looking questions for you. Um,
we've talked about a lot and as you
think ahead over the next 3 to 5 years,
what do you envision organizations that
are truly resilient doing that is
fundamentally different from what we're
seeing today?
>> So, this is where it starts getting into
my my my magic eightball, right? I'm I'm
turning it. I'm seeing what uh what it's
going to come back with. um where I see
us and uh the us the the royal us here
uh I see a uh a breaking down of silos.
I really think it's going to happen. I
think eventually there will be an
acknowledgement that it's not their
problem and then their problem and then
their problem. It's our problem and that
we need an our solution in order to
resolve that. Um so it's not just going
to be the backup team's job to do this
and the storage team's job to do that.
they will recognize that um there needs
to be coordination there. So that's more
of a fundamental um like ideological
change from a more of a technology
shift. I would say that we would see a
greater embracing of agentic models but
it will be cautious like with any good
technology it you know you start to see
a slow ramp. It doesn't matter what it
was it all follows the same trajectory.
The only difference here is AI may
increase how quickly we reach that
culmination. Um, but that being said,
there's still going to be some caution
there over the next few years. Um, some
cautionary tales lately, right? You hear
about these these agents that go rogue
and start deleting things because that's
what they thought was the right thing to
do. No one's going to hand over the
reigns of their entire business to a to
an agentic model until it has proven
itself in
exhaustive way. Um, but we will get
there. Um um it's just you know it will
take time like with any other you know
good advancement or good uh innovation.
>> Yeah, I agree Jo. I think there's been
some trepidation and for good reason. Um
and like you say kind of eyes wide open
wanting any AI capabilities to be very
provable with that human in the loop. Um
but at the same time, you know, I agree.
I think it's the future. it's where
we're heading and I think it's going to
be necessary to be able to close that
bottleneck that we've been talking about
in terms of keeping pace with you know
these adversarial attacks that are
AIdriven. So I guess the question is for
enterprises that are thinking about
incorporating components of AI into
their resilience strategies, do you have
maybe just at one or two um best
practices to keep in mind over the next,
you know, kind of 12 to 18 months as
organizations are trying to figure this
out?
>> Well, we have operated with a an
expression for many years at at at
Infoscale is that we like to automate
things, but we don't want things to
necessarily be automatic. And that is
the reason we say that is because at the
end of the day there are certain
recovery principles that make sense to
be done you know rapidly real time
things that you don't want to you know
step in for example one of the things
that we provide from an HA standpoint is
that we can in real time we know the
health of an application and
automatically make that application
available on another host that's a form
of autonomy that's a fair of autonomous
uh operation that being said we also
think that when something as
consequential as a disaster event would
happen. We don't want that same level of
of um of autonomy. We want we want a
human to step in. So I honestly believe
that there will always be a need for
human intervention. The things that you
want to happen quicker, the things that
you can automate and things that you can
do to you know verify the the the
recoverability of of a set of services,
absolutely those you can hand off to
some agentic model. Um, but the
decisions, right, the the very
consequential decisions, the ones that
are that are going to wake that CEO up
in the middle of the night, those are
the ones right now. Hang on to those.
Don't don't let those loose just yet.
And I think for the most part, people
will will appreciate that. Um, and the
other thing is is don't be held to
convention. I I'm I'm listen, I am I'm
definitely guilty of of things that
you're comfortable with. Get outside
your wheelhouse a little bit. do things
a little bit differently because you
never know what you might uncover in
terms of a of a method or an approach
that's going to revolutionize the way
you do business.
Yeah, ve very well said Joe and a great
lead into you know the last question
that I had for you know you paint this
picture of a lot of you know sort of
cautious trial and error and kind of
experimentation right and I definitely
agree when you think you know a year
from now say you and I sit down and have
a conversation on this topic of cyber
resilience which I certainly hope that
we do
>> what do you think we'll have learned
throughout this process
Well, we will certainly we'll break all
the records of your podcast in terms of
the amount of viewership. That's what
I'm hoping for first and foremost. But
um I think what we'll have learned is
the um
how mature or immature today's AI
agentic models are right we are going to
obviously with time get that kind of
perspective um but also I think that we
will see how quickly uh customers can
embrace or not customers but just just
the community in general the the the you
know IT community in general how quickly
they're able to embrace and improve
their position whether it's in their
software development life cycle, whether
it's in their cyber resiliency posture,
whether it's in any form of different,
you know, uh, operations and and, you
know, protocols that they must follow.
Um, I think that's really what we're
going to what we're going to learn. Um,
and the reason I say that within a year
we'll know that is because I do believe
that AI will accelerate the time to that
uh, sort of conclusion. you know with
previous technologies like even adopting
the cloud or uh you with virtualization
going back you know 15 20 years those
things were a slow burn but it was still
you reach the same conclusion right did
it transform my business um and that I
think is really what it's going to
happen are we transforming businesses or
is this just going to be another another
tool that's in the toolbox um I think
it's transforming businesses I really do
I think that's what's going to be the uh
the result of this
>> I definitely agree I think there's going
to be a lot of transformation
information. Um, and I think security
and resilience for out of necessity have
become at the forefront of that of that
transformation. So,
>> it's the vanguard. It's the vanguard for
all the IT conversations, security and
and resiliency.
>> Resilience vanguards. I love it.
>> That's that's where we're at.
>> I love it.
>> Talk about being bougie now,
>> right? [laughter]
>> Well, Joe, thank you so much for joining
CyberShift today. This has been um a
really um informative conversation, a
lot of fun um and I really appreciate
it. Thank you so much.
>> Thanks for having me, Krista. Anytime.
>> Of course, and thank you to our
audience. Um again, this has been um the
CyberShift podcast. Um I'm Christa Case,
principal analyst um here at the Cube
Research. Um and we hope you'll join us
on our on our next episode. Thank you so
much.
>> [music]