
Sign up to save your podcasts
Or


Tom and Camille are switching things up this week! They’re diving into their own conversation about security in product development and support. Listen in to discover Tom and Camille’s insights on threat models, read teams, bug bounties, the role of PSIRT vs. PRT, no-harm testing, SDL, issue mitigation, and more.
They also discuss how to think about the potential uses for products in the design phase, baking checks on attacks or vulnerabilities into your SDL process, why not to rely on external researchers, and communicating security fixes to customers—just to name a few things! Don’t miss out on this insightful conversation.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
What are human factors, and how do they impact cybersecurity? Camille’s joined today by Margaret Cunningham, PhD in Applied Experimental Psychology, to discuss the intersection of human factors and cybersecurity. Margaret’s also the behavioral scientist subject matter expert at Forcepoint’s X-Labs, which develops scalable and human-centric security solutions. In other words, she’s the go-to expert on this topic!
Tune in to learn from Margaret about the intent of human factors practitioners, where the fields of human factors and cybersecurity intersect, the questions guiding human factors practitioners, why people break the rules, how human factors can be used to improve training, how you measure a person, and more.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
If there is an issue with product security, who responds to it? That would be a PSIRT, or Product Security Incident Response Team! Tom and Camille talk with Pete Allor, Director for Red Hat Product Security, about PSIRTs and the incident response framework. It’s a discussion all business executives won’t want to miss!
The three cover what a PSIRT is and why you need one, the dangers of falling into a technical trap when addressing product vulnerabilities or problems, evaluating risk and scoring vulnerability, why incident response requires organization-wide coordination and communications, the Incident Response Services framework, the role of transparency, and more.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Everyone’s talking about artificial intelligence, but what is it exactly? Tune in for the first episode of our series What That Means, hosted by our own Camille and joined by leading experts in the tech world. Today, Camille’s joined by Rita Wouhaybi, Principal Engineer for Industrial Solutions in the IoT group at Intel, to explain everything you need to know about artificial intelligence, or AI.
Listen in to learn about the Turing Test and how we measure intelligence in a computer or machine, explainable AI/biases in learning, the questions we should be asking as consumers and/or implementors of AI, decided which AI techniques to use and how to use them, confidence levels of AI, why AI is not going to solve all our problems, and what AI competition is doing for the industry.
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
We have exciting news… Launching next week is our companion podcast to Cyber Security Inside—What That Means! Every episode, Camille will focus on one topic or term related to what we’re covering over here at Cyber Security Inside. She’ll chat with top technical experts in the industry and get the definitions directly from those who are defining them. It’s really the best way to learn about all sorts of topics, including AI, blockchain, sustainable computing, human factors, gaming, and much more!
In our first ever episode of What That Means — the Cliff’s Notes companion to the Cybersecurity Inside podcast — Camille is tasking Rita Wouhaybi, principal engineer for industrial solutions in the IoT group at Intel, with defining artificial intelligence in under three minutes.
(Spoiler: she nails it.)
Plus, Camille and Rita cover:
- The Turing Test + how we measure intelligence in a computer or machine
- Explainable AI/Biases in learning
- The questions we should be asking as consumers and/or implementors of AI
- Deciding what AI techniques to use and what to use them for
- The confidence levels of AI
- The one thing to keep in mind about AI
- Why AI is not going to solve all our problems
- What AI competition is doing for the industry
Check it out!
Here are some key take-aways
Some interesting quotes from today’s episode:
“It’s based on some cognitive ideas, where you see information, or actually you see more like data, raw data, and you distill information out of it. And as humans, as well as animals, we do that all the time. So it’s the idea of creating a computer program that is capable of doing it.”
“I would even argue that to a large extent, when you have a child growing in a biased environment, that child will be biased as a child. And it’s going to take them to go out of that environment and expand their horizon — either through reading or experiencing other individuals — to widen that scope and get rid of that bias and reexamine it. And I think that could happen in AI, too.”
“AI is never 100% sure. The trick is, where is your tolerance? Do you want AI to make sure that if it sees something bad, to tell you about it, with the assumption that some of those might actually be good? Or the opposite? Which one matters more? So, if you are a medical doctor, would you rather have an AI that says, ‘Oh, I think this one has lung cancer’ higher and ask for further testing, or miss a few lung cancer diagnoses? Where do you want that error to wiggle? Do you want it to wiggle on crying wolf? Or do you want it to be very conservative and miss some diagnoses? Those are very important questions.”
We live in a digital world, but humans are at the heart of it all! So, how does this affect our approach to cybersecurity? Tom and Camille are joined by Alan Ross, Fellow and Chief Architect at Forcepoint, to address the question—Is it safer to open up our system and monitor everything closely in a secured manner, or is it fundamentally safer to lock everything down? Alan brings his industry insight to the conversation as the three discuss indicators of behavior, time-series anomaly detection, privacy concerns, insider threats, who’s getting cyber security right, using data to inform models, and even what Alan’s learning from CrossFit about human-centric approaches! Understanding human behaviors is key to protecting and mitigating security vulnerabilities, and modern companies simply can’t afford to slack on this approach.
Tune in to learn more!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
On today's show our guest is Bob O'Donnell. Bob is President and Founder and Chief Analyst at TECHnalysis Research. He's widely regarded as an expert in the technology market research field and his original research and advice is used by executives and large technology firms all over the world.
I'd like to introduce my co-host Camille Morhardt. So hi, Camille, how are you doing today?
Camille Morhardt: Hey Tom. I'm doing great.
Tom Garrison: So what's on your mind today?
Camille Morhardt: Well, I know this sounds like a big topic. I was going to say artificial intelligence and compute.
Tom Garrison: Wow.
Camille Morhardt: But I wanted to start with something a little bit smaller: end devices. So when I think about the evolution of AI, the smartphone, particularly, with its built-in camera kind of gave deep learning such a boost. And then when I think about when I know what I'm going to do, and I need to sit down and get something done, I still go to my PC.
So, what I'm wondering is when I think of the development of AI, it's kind of through the smartphone as this end device. And then of course, servers on the backend for centralized learning models. And then when I think about the future, I tend to think IOT, preventive, maintenance and exciting things like that. But what about this basic workhorse that is the PC? What's happening with respect to artificial intelligence and the PC
Tom Garrison: Yeah, there's a lot to unpack there. In general, there's some pretty cool things about AI. Some of them sound boring, but they're, they're actually pretty game-changing and one of them sort of boring sounding ones is using AI to basically guess what you're about to do on the PC.
So if, for example, you're working away in Microsoft Word, and you've been going at it for a while typing, and then you pause for a moment and you start to move the mouse up, chances are you're, you're either going to be clicking on Save, or you're going to be clicking on Print or something like that. And using AI based on your, the things that you do--without even thinking about it--you can use AI to guess what you're about to do, and then make those actions something that's basically one click away or something that's just right there on the screen.
And it's kind of invisible to the user, but it gets us out of having to remember “which dropdown box do I have to click on this and then that.” And you know, like if in Excel, I don't know how many times in Excel I have tried to find the dang “wrap text,” little check box. Those are all things where AI can watch your behavior over time and learn your behavior and then sort of present the things that you're likely to do in a very easy to find mechanism.
Camille Morhardt: Okay. So you're talking about, you know, basic sort of workload, help my life get better kind of a thing. So what about on the security front? Is there anything that we're seeing there?
Tom Garrison: Yeah. So the first one was just one sort of simple example. And then on the AI side for security what's being looked at now is around using AI to see is the machine operating in a way that it doesn't normally operate. So knowing enough about the way you use your device, to be able to say, “huh, now I, the PC, and operating in a way I don't normally operate” and flagging that. Doing that in a way that doesn't induce a lot of false positives (or obviously false negatives too) but false positives are a real problem for security, because if you are sort of Chicken Little, and you're always raising your hand saying, “Oh, there's a problem! Oh, there's a problem!,” then pretty soon people start ignoring you.
And so the, the promise of AI is to be able to do that and see these anomalous behaviors that you should flag.
Camille Morhardt: I would like to learn a little bit more about that and find out what other people in the industry are seeing.
Tom Garrison: Yeah. I think that's probably a great podcast right there. What, what do you say we narrow in on that topic?
Camille Morhardt: Yeah, I like it.
Tom Garrison: All right, let's go for it.
Okay on today's show our guest is Bob O'Donnell. Bob is President and Founder and Chief Analyst at TECHnalysis Research. He’s widely regarded as an expert in the technology market research field and his original research and advice is used by executives and large technology firms all over the world.
So Bob, you are the perfect guest for us today. So thank you and welcome to the show.
Bob O’Donnell: Thanks for having me.
Tom Garrison: So our topic today is around Artificial Intelligence. And I wonder if you could just spend a moment and talk a little bit about your background and this topic around AI.
Bob O’Donnell: Sure. So I have been a tech industry analyst for a little over 20 years. And prior to that, I was in the music technology business--so writing and reading and playing with musical equipment (because I'm a musician for fun, as well). But so I've been following tech industry trends for a long time. And as we've seen the evolution of computing, we've seen the development of more sophisticated software tools along with more sophisticated silicon and those worlds kind of really coming together in a very interesting way with Artificial Intelligence. The idea being that you could start to see the ability to do things above and beyond what basic software would allow and enable, and then unique means of solving problems and then silicon being designed to accelerate that, cause it turns out not all, everything would just be accelerated by a CPU.
But long story short is as I've tracked these trends in devices and core technologies and software in the cloud, AI has all of a sudden become this huge issue. And I've done some independent research studies on it, I did a survey of AI use in the enterprise. I've done research on AI and consumer applications gaming and so it's just an area that I've looked at quite closely, because there's so much interest in fascination with it.
Of course there's so many different variations on it between machine learning and the different flavors of AI. And it gets very confusing very quickly, certainly, but at the end of the day, it's about being able to extend some of the core, basic types of software tools that we've created in ways that we may not have thought of before. And it's also a way, frankly, from another perspective, it's a way to make sense of data in a manner with which we haven't thought about it before.
So it's a combination of how do you create these algorithms? how do you interpret this data? and how do you put that all together into something that goes above and beyond what we've traditionally done? And it's a fascinating field, obviously, that has lots of implications all over the place.
Tom Garrison: Yeah, no, this is, this is a great, and, and I wonder through the research that you've done--and I understand you've got a white paper coming out as well--for the listeners here, what are some of the key sort of “ahas” or takeaways from your research?
Bob O’Donnell: Initially all the excitement, frankly, and all the action in AI was happening on smartphones, right? It was all about smartphones. A lot of it was we heard about computational photography, the ability to enhance image quality and do, uh, very clever processing in ways above and beyond what you could do with the traditional Photoshop filter types of things. And then we saw audio processing, as well, as some other things. But the PC was a little late to the game.
And now what we're starting to see--and what my research is on--is about AI usage on PCs. We're starting to see PCs be part of the equation. We're seeing a lot of adoption of AI in various PC applications. 90% of PC developers that we surveyed are working on some sort of AI machine learning or deep learning type of effort--either by integrating into a function within their application or building entirely new applications based on that. So that's huge, right? That's a huge amount of focus being placed there.
And at the same time, we've also seen of course, a lot of effort around both companies like Intel, as well as NVIDIA and others to build algorithms and software development kits that can leverage that and to build acceleration into some of the chips that they're creating. So, I mean, everybody is really focused on trying to bring some of that magic that we saw with smartphones a couple of years back to the PC, because there's a lot of interesting applications, especially nowadays when we're all using our PCs a heck of a lot more.
Camille Morhardt: Hey Bob, what is kind of one of the major use cases that people are actually doing with AI on a PC?
Bob O’Donnell: There's a number of things. So we are seeing some of the same kinds of things we saw in smartphones. We're seeing some of the filters, you know, for image filtering and audio filtering, especially now with video conferencing, noise reduction in the background is a huge deal, right? Because we've all had dogs and kids and, you know, loud noises happening in the background.
The other thing we've seen, actually, is workflow automation, processes totally radically different kind of thing, but using tools to leverage how data workflows are happening or process workflows. All those kinds of tools that are run on PCs are also changing.Also a lot on security and threat protection. We're seeing more and more automated tools to look for security threats.
You know, a lot of what AI does at a simplistic level is it Looks for patterns, right? You teach it a bunch of patterns--a lot of these AI algorithms--and then from that, it can determine other patterns. That's a classic, deep learning application. It was initially, you know, it was show 50 pictures of, uh, of, of dogs and then show some more pictures that they haven't been trained on and decide if it's a dog or not. Well, take that a million times further, here's a signature or here's an application that's functioning in an unusual way on a PC,
could that potentially be a security threat? And so you'll see a lot of AI based tools around security and threat protection also being used.
Camille Morhardt: Who's owning those models, then? If we're doing AI on the PC and looking for threat protection, in particular, I guess maybe, you know, is that the IT department who's owning the takeaways from that? or are there managed service providers that are collecting that?
Bob O’Donnell: I think we're seeing all of the above. Obviously in a lot of corporate environments, and even in our extended corporate view of the world with a work from home, IT shops will install, obviously, a number of security tools--there's the traditional MacAfee, Symantec types of things. There's obviously what Microsoft has done with Defender. But there's more advanced other technologies we've seen from Cylance and some of these other companies--some of whom have been purchased by some of the big PC vendors.
But there's a number of tools being deployed, sometimes by corporate IT, sometimes by individuals because, you know, the boundaries between personal and work of course have completely been obliterated during the pandemic. And so you have people working on personal PCs and they're installing those kinds of tools there. But you also, in fact, have service providers, uh, who are involved with this at a corporate level. You've got people who provide a managed security type services that are watching what goes in and out, past the firewall. Again, things are very different now because whereas everything used to be behind the firewall, now, literally everything is outside the firewall and that's changed the dynamic of what the things you have to look for, the types of threats.
So there's all kinds of services being offered from a variety of vendors. You're seeing it as well in network equipment, from the large networking companies. So folks who are in charge of the network at many organizations as a part of IT they might be monitoring. Um, so it's being approached and attacked on many different levels with AI being applied to almost all of these different security applications.
Tom Garrison: So do you see Bob then that the AI is basically just being integrated into many of the sort of existing products that are out there? And it just makes their products better?
Bob O’Donnell: It is. It's a good question, Tom. And yeah, I mean the bottom line is a lot of what's happening is not necessarily that the entire-- I mentioned that some people are trying to do entirely new apps with AI. But the vast majority of what's happening is they're taking a function or two, and they're integrating AI into that. Or they're building a couple of special new features and capabilities leveraging AI models or deep learning or what have you. So that's typically the way that we're seeing, developers on the PC, as well as other platforms do that, right? We saw the same thing on smartphones. There were always photo apps and camera apps on smartphones, but they just got a little bit smarter through the integration of some of these technologies.
And frankly, in the case of smartphones, Qualcomm had a bunch of software development kits and APIs and things like that, along with Android and the two worked together to create a suite of tools that developers could use. Now, we're seeing the same thing with Intel doing that with OpenVINO on the PC side, as well as Microsoft. So there's a lot of efforts. And then of course there's, you know, and then special instructions being integrated into the latest generation of CPU's again from Intel as well as from AMD. So lots of different parties working together to bring AI more to the mainstream.
Tom Garrison: We're certainly doing a lot of work in the hardware side, making sure that our platforms are, uh, highly performant doing AI type workloads. I wonder, from your perspective, is there anything that really has caught your imagination? Cause I'm envisioning now our listeners are listening to this podcast saying how is AI gonna impact my business?
Bob O’Donnell: Well, I think it's going to happen across a number of areas. Sort of a big picture one is around analytics. You know, we've talked about analytics and big data in the corporate world for, I dunno, 10, 15 years. It seems like forever. And the reality is that a lot of the initial analytics efforts, frankly, were not very successful. They were trying to dive into big chunks of data and try and discover patterns and, and they really weren't particularly successful in doing so.
The beauty of AI is you're unleashing algorithms onto these huge datasets and they are finding more success. So I think anything that involves traditional analytics types of applications, where you're searching for patterns in data--and that can happen across any industry and we're seeing that all kinds of places. We're also happening, see it happening in IOT tape type applications. If it's in manufacturing, you know, predictive analytics where you can not only be, you know, searching for data, but you can see patterns start to emerge of sensor data that might make you say, ”Oh, I think that piece of equipment is going to fail. We've got to deal with that.”
We're starting to see that as well on PCs, right? I mean, it was back from the old days of smart hard drives, right, where you have these sort of basic tools built into the hard drive, they would try and be able to warn you, “Hey, I think we're in trouble here.” Now we've got the same kinds of things happening on other components, right?--whether it be memory or other elements of a PC. So we're seeing those, that predictive analytics happening.
The other big area, frankly, than I think most people are starting to see is in basic office productivity. So now, for example, if you use your, either Office 365 or G Suite, or is now Google calls it Google Workspaces, you've got these tools, the editing applications that give you content recommendations, right? They'll say, “Hey, not only is it a spell checker, it's a grammar checker. Now it's even a content type of checker. Here's some suggested content for you.” One of the things I love in PowerPoint is a feature called Designer and Designer is an AI powered function that will create layouts for you. If you don't have your own in-house art department who designs all your slides, you've got to create your own. And even if you have a preset template that a lot of companies have, you still want to jazz it up and create some varieties and do some cool things with images. And the beauty of Designer is it can take some images and come up with some suggested layouts that look awesome and require very little effort on your part.
We're seeing things like the ability in video conferencing applications to track someone if someone's walking around, uh, or they're swaying, the camera can track the person and keep them centered in the frame. Uh, so all kinds of subtle-- and that we've also seen things like, you know, A little creepy, but you know, they raise your eyes up so it makes you look like you're actually looking at the person instead of looking down. Cause you know, a lot of times your camera's above your screen, so you really looking up, but sometimes you're looking down at the people you're talking to. And so it's a little weird. So it literally just tweaks the position of where your eyeballs are looking to make it feel like someone's actually looking at you as they're talking to them in a Zoom call.
So like I said, all kinds of different real world applications that I think pretty much everyone has started to see and there's creeping their way into the mainstream.
Camille Morhardt: Okay. So you've used the word “creepy” and “creeping” a couple of times. So I'm going to run with that just a little bit. What are we worried at all about privacy when we've got all of this kinds of tracking and voice, and now content suggestions? I won't even go there?
Bob O’Donnell: Yes. Look, people are a little worried about it, right? Analytics, one of the, one of the analytics that people are doing is personal analytics, as in it's tracking everything I do and then making suggestions on what I want, right? We've seen this with advertising. We see this with all kinds of things and so yes, there is obviously some concern with that.
The beauty of what's happening is we are now getting the intelligence and the compute power to do what's called Inferencing, locally. So, you know, the idea you've got training and inference when it comes to AI training is when you take a whole bunch of data and you create these algorithms by essentially training it what to look for, what to think of that's classic machine and deep learning types of algorithms. Then you apply those and you do inference by taking input and comparing it essentially to the algorithm and figuring it out.
Now in the past, you used to have to do that inference in the cloud, meaning everything you did had to be sent to the cloud, to someone else's data center and the data was processed there. By doing it locally--even though that sounds like sort of an arbitrary distinction--it's huge because it means all of a sudden, all of that inference work looking at my own data or your own data who's ever owned data happens on the local device. So all of a sudden that means my data isn't necessarily being shared out to the entire world and that makes a big difference to people, as well. They want the benefits of smart suggestions and content suggestions, all this kind of stuff. But, you know, they don't necessarily want their entire life out there, for the world to analyze. That's what I'm referring to there. But it's an excellent question and something that we do have to be aware of whenever it comes to AI.
Camille Morhardt: So just to clarify, you're saying, for example, if we're going to work on removing background noise in my audio on a video call, you can make a suggested edit to the algorithm and then send that back to the model, as opposed to sending, say, my raw audio file, which would include the specifics of my conversation?
Bob O’Donnell: That's exactly right. And so, first of all, they can do the analysis of that audio file, locally. But what they can also do is they can maybe come across a variation that occurred in your particular situation or someone else's particular situation, upload that data, in turn, refine the algorithm, and then that algorithm in turn gets re-downloaded onto your system. So it's a constantly iterating type of process. That's the ideal. We're not always, we're not quite there yet in all cases, but that's the concept is that you can get the benefits of AI, you can even get the benefits of an upgraded algorithm, without having to share too much of your own personal data.
Tom Garrison: We're starting a new segment. So you're the very first one of a brand new segment that we're doing in our podcast now. And it's basically what have you learned lately that you want to share with the podcast? Something cool, interesting. Could be something related to technology or it could be something in entertainment or something else you found intriguing and, I think, maybe our listeners might learn something from it as a result.
Bob O’Donnell: Well, I have two things and they're radically different, but I'm going to throw them out there anyway. So recently one of my personal musical heroes passed away and that was Eddie Van Halen. I discovered Van Halen--I'm showing my age here--but at a young age and he has always been an amazing rockstar and just such an icon to me. An interesting factoid that came out after his death that I never knew is that he was part Indonesian. He was actually part Asian. And he actually suffered a great deal of bigotry for being Asian. I never ever knew that. So that was an interesting little factoid, about Eddie van Halen,
The other thing, and it's again, totally unrelated, one of the things I've been doing with a little extra time during the pandemic is I-- I'm a car guy and I have a few car Lego sets and I've discovered that there are lighting sets. You can put lights into your Legos. And so you can turn on the lights on your legos. It's super cool. It's a totally nerdy geeky thing that not everybody's going to appreciate, but if you're into stuff like that, there are lighting sets.
Super cool!,
Tom Garrison: I, you know, I, I didn't know either of those two, but, uh, the Lego one that is a, that is intriguing. (laughs) Camille, any, uh, items you want to add?
Camille Morhardt: Okay, well, what I learned this last week, probably anybody who spends time by the ocean already knows, but, uh, I learned that the best time to boogie board is not exactly at low tide, which I had previously thought, but it's right after low tide when all the water is pushing you on shore, as opposed to dragging you out with that rip.
Bob O’Donnell: That would be an important thing to learn! (laughs)
Camille Morhardt: (laughs) Trial and error.
Bob O’Donnell: What about you Tom?
Tom Garrison: I am going to go into the world of entertainment. I'm always a big fan of these shows that I can just binge watch. And my son turned me on to a new show called “The Boys.” And let me just first tell everybody out there, do not watch this show with kids around. It is completely, completely inappropriate for kids. But it's a world where there are superheroes, but they're self-interested superheroes. They're not like the Superman or Batman that we grew up with that are all about the public good. These people are in it for themselves. And, anyway, it's, uh, it's a fascinating to me. It was a fascinating kind of re-think about the whole superhero genre thing.
I think it's very well done. There's two full seasons. Now you can get on it. But anyway, Bob, thank you again for taking the time stopping by, sharing what you know about AI. It was really interesting. And I appreciate your time.
Bob O’Donnell: Well, thanks, Tom. And thanks Camille, thank you so much for having me. I really enjoyed the conversation.
Tom Garrison: All right. And for all of our listeners, we look forward to sharing with you the next podcast, which will come out in two more weeks and we'll see you then
Subscribe and stay tuned for the next episode of Cyber Security Inside. Follow at @tommgarrison on Twitter to continue the conversation. Thank you for listening. .
In this episode of Cyber Security Inside, we explore what you need to know about Confidential Computing to protect your data. Our guest, technology analyst Jack Gold shares his insights on protecting your data--at rest, in transit, or in the cloud.
Tom Garrison: Hello, and welcome to the Cyber Security Inside podcast. In this podcast, we aim to dig into important aspects of Cyber Security, which can often be highly complex and intimidating and break them down to make them more understandable. We aim to avoid jargon and instead use plain language for thought provoking discussions. Every two weeks, a new podcast will air. We invite you to reach out to us with your questions and ideas for future podcast topics.
I'd like to introduce my cohost, Camille Morhardt Technical Assistant, and Chief of Staff at Intel's Product Assurance and Security Division. She's a Co-Director of Intel's Compute Lifecycle Assurance, an industry initiative to increase supply chain transparency. Camille's conducted hundreds of interviews with leaders in technology and engineering, including many in the C suite of the Fortune 500.
Hi, Camille, how are you doing today?
Camille Morhardt: Doing well. It's autumn., beautiful time of year in Portland.
Tom Garrison: It is. It's gorgeous outside. So I'm wondering, what would you like to discuss today?
Camille Morhardt: Well, Tom, I remember when people used to be afraid to put their data on the public cloud and it seemed like we had to make some sort of a trade off, right. Either I'm going to keep my data on my personal device, or if I'm an enterprise on-prem maintain complete control over it and know that I'm secure. Or I'm going to go with the convenience and the economy of scale, putting it on the public cloud and I'm going to worry about how safe it is.
And today increasingly I would, I would even say with COVID, I'm hearing more and more consumers and enterprises actually comfortable moving their data to the public cloud.
So I'm wondering first, what are the reasons today that people are interested in moving their data to the public cloud setting security side for a moment. And second from a security perspective, did something change that's making people more comfortable now or what should I be aware of if I'm considering moving data to the public cloud?
Tom Garrison: This is a deep topic for a fall day. So let's just think about this on a consumer use case and then we'll talk about corporate in a second. On the consumer use case, it's kind of interesting, cause I remember even myself years ago where we were talking about things like, you know, family pictures, wedding pictures, pick kids' pictures, and would I, or any of my colleagues ever consider putting a hundred percent of those pictures in the cloud exclusively. And without exception, everyone said no. And I think back then it was a sense of control.
You know, my sense now is that people are more comfortable with the idea that these cloud providers really know what they're doing and the chances that they would lose your photos or whatever is much, much lower than you would screw up your device or your device would die at home and you would lose your pictures.
Camille Morhardt: Right. You essentially have IT in the cloud, whereas at your house, you're your own IT.
Tom Garrison: Exactly, but then now you get to commercial. And with commercial, there's more complexities, right? You get the cost angle because if you're going to pay somebody else to do this, there's always going to be a cost to it. And can the other people manage your data in a lower cost fashion than you can do it yourself? And then there is this sticky issue of trust. Do I trust the data will be safe, especially for enterprises where the data is sort of the crown jewels of the company?
Camille Morhardt: But let's say that I want to be able to do that in a way that I can maintain either my privacy or my IP. You know, we had talked previously about not wanting to share and usage patterns of our compute devices, right. But if there were a way that my personal data could be protected and I could perhaps set the parameters for, to use or its disposal, um, and then there were a way for a company let's say a machine learning algorithm or something to come sit on my device, or maybe in the cloud where my data is also stored and run and do some learnings on that data while still maintaining protection of my privacy. I might actually be interested in that.
Tom Garrison: Yeah, I think most people would. That's sort of the Holy Grail when it comes to confidential computing in the cloud, where you can protect data from any unintended intended use. And so making sure it's secure and that hackers can't get to it or other applications can't misuse that data in some way. That's the value proposition behind confidential computing.
Camille Morhardt: And then there's this one other conundrum I’m thinking about it a little bit, which is, I know that a lot of enterprises are moving towards some services in the public cloud, like email say for their employees; part of the reason is they don't have to worry about the limited infrastructure that may be multiple concurrent VPNs is allowing it. Now it's just bandwidth directly from the employee to the public cloud.
On the converse, don't we still have to worry about as we're moving more and more to internet of things, just exactly that same concern: getting data from a thing to the public cloud is now posing a bandwidth constraint or a latency problem that wouldn't have been there otherwise, if I were processing onsite.
Tom Garrison: Sure, you're absolutely right. That is the sort of perennial challenge when it comes to huge data. Yeah. I think that's the episode for today. So I think we've got it. You good with that?
Camille: I’m great.
Tom Garrison: All right, let's go for it.
Our guest today is Jack Gold. Jack is Founder and Principal Analyst at J Gold Associates, LLC. And has a wealth of experience and expertise in the computer and electronics industries. He conducts analytical market research and advises numerous clients on many aspects of enterprise systems, including business analysis, strategic planning, architecture, product evaluation and selection as well as enterprise application strategy. So is perfect guest for us today.
I’m trying to think back, Jack, how long you and I have known each other and our best guess was about 15 years we've worked together.
Jack Gold: Yeah, Tom. I think it's been that long. Of course we're all six years old when we started so it's not much of a problem.
Tom Garrison: That's right. Oh boy. Yeah, it was pre-gray hair, I know that for me. We're here really wanting to talk about the concept of being able to create enclaves within the hardware that are safer relative to the rest of the system so you can do confidential code execution and other things inside these enclaves as well as the more broad topic about confidential computing.
So I wonder Jack, if we just start with, you know, environmental scan on confidential computing, like where do you see it playing a larger role, an outsized role in terms of the kinds of users or usages around SGX and confidential computing?
Jack Gold: Yeah. Tom, confidential computing is one of those terms that kind of means different things to different people. When we're talking about data--data about you and I, or corporate data or financial data--generally, when we talk about that data being safe because it's encrypted. And that's true. It is encrypted. It's encrypted at rest. When it's in a database it's encrypted while it's traveling over network. But generally speaking, once that data starts being processed, it's no longer encrypted.
So it's available--if you can get into the processor--you can see that data essentially in the clear. Confidential computing, to me, means two kind of circles if you're looking at a Venn diagram, right?--the two circles we were just talking about encrypted data at rest, encrypted data as it's traveling over network, but the third circle needs to be safe, data being processed. And we need to be able to, to assure that well, that data might be somehow in the clear while it’s in your computer. If I have access to your computer or access to your app, or it's just a bad app, that I don't all of a sudden have access to what was encrypted data that's not right out in the open and I could make use of. So confidential computing is really all of that.
Tom Garrison: That's interesting. And do you see particular users or, or industries that are embracing the concept of confidential computing more so than others or do you see this as kind of a broad appealing capability?
Jack Gold: The appeal of confidential computing really is across industries. It's everywhere. When you think about what gets processed in a company that isn't confidential anymore; my social security number, my driver's license number that I give to somebody, healthcare provider has all my medical details, that's worth a lot of money to people.
So we're kind of talking about servers and data centers and clouds just now, but also at the front end think about all the data that we have on our PCs and even our smartphones. So it's a broad concept that really needs to fit in the entire life cycle of computing, not just in one area.
Camille Morhardt: Is this something that we worry about for just on-prem or you described, you're talking about public cloud concerns? Do consumers need to be concerned, as well?
Jack Gold: Oh, absolutely. There's absolutely a need to have this in the cloud. Look, in most cloud environments, data that's running in an app is being shared on the same piece of hardware via virtual machine has probably tens, dozens, hundreds of other applications running on that same machine. And if there's no way to segment out those virtual machines to protect them from one another, if I have a bad app running, somehow I get it to run in, pick your favorite cloud, can it get access to an adjacent virtual machine and get the data out of that machine that has of great value?
So when we talk about confidential computing, we're talking about individual computers, whether it's a personal computer or whether it's a server in a corporation, but we're also talking about public cloud and private cloud as well.
Camille Morhardt: So basically, anybody--enterprise or consumer--who's storing any kind of a data on a public cloud or a hybrid is using a hybrid cloud environment, needs to consider what the public cloud provider is doing with respect to this protecting data, as you say, while it's being processed.
Jack Gold: Yes. Look, people want data about you and me. They can get real value out of that and sell it for a lot of money. So if I don't have a way of protecting that, there's a lot that people already know about me, but there's a lot more that they could garner. So I need to be aware of where my data resides. If it's in the cloud, or if it's in Google cloud, AWS, Azure, how do I know that that data is safe?
And if I'm an enterprise that has access to that data and that data gets compromised, I'm going to feel the pain in a number of ways. First of all, there are a lot of regulations against disclosing data. Look at what's going on in Europe with the privacy laws there compared to the U.S. There's some real fines going on.
Secondly, if there is a data breach, IBM and the Ponemon Institute, did a study showing that in the U S a typical enterprise data breach cost that company over $8 million to mitigate. That's pretty significant amount of money to have to put out because of having a compute system that isn't completely protective of the data,
Tom Garrison: You know, in preparation for this podcast today, you sent over a couple of your reports and I read through them and I just pulled out a couple of data points that I thought were fascinating and they came from the Verizon Security Report. But it said 39%t of companies have reported in 2020 that they were breached and up 6% from the year prior. But even more interesting was these behavioral, all aspects around security. 62% admitted that they sacrifice security due to expediency; 52% sacrificed due to convenience; and 46% admitted to sacrificing security because of profitability.
Jack Gold: Yeah, Tom, I think the real issue with security in general is that it's hard to do it's complex. And if you're in a hurry and you need to get something out there, you're going to put it out there and probably bypass some of the best-in class security measures that you should be doing simply because of expediency.
Especially because of COVID, companies needed to roll out 20,000 desktops in two days or a week, you bypass a lot of stuff to keep your company running. But even beyond that, even other companies that had the time perhaps to do it right, haven't really done it right. And the reason is because typically large companies can have two, three, 400 different security products running in their networks and in their data centers. How do you possibly manage all that stuff? The industry has made it really hard for companies to do security well.
Camille Morhardt: So I guess just to get really simple, if I'm IT, what am I looking for to see if the hardware is protected?
Jack Gold: So if you're IT, what you really want to know is whether the hardware that I'm working on has a vaulted area. It's called different things by different vendors--SGX with Intel, Trust Zone on Arm, it's other things with other guys. But what you really want to know is whether that's available, whether that vault is even built in.
The second thing you want to know is, is the operating system interacting with it? Does Windows know that that vaulted system is there and is it working to make sure that anything it's executing in Windows is actually running in that vault rather than running in main memory, un-encrypted.
It's a little harder when you're running in the cloud because you don't actually own the hardware. You're using somebody else’s hardware—you’re using Amazon's hardware or Google's hardware. And so you have to rely on them to tell you whether that's there or not. How many people are actually asking for that right now, I would guess are probably a pretty small number. We have to raise the awareness that that's even available. And then have those companies know that knowing that it's available, ask for it by name.
Tom Garrison: Having this be something that is on their radar to ask for is something that would be a value for, for the listeners here.
Jack Gold: If you're not asking for it, you're putting your company at risk. It's really that simple.
Camille Morhardt: Hey, Jack, you're described like this Venn diagram of the three different places that data is right--at rest, in transit, or in process being processed. Why is it that we don't already have everything covered?
Jack Gold: That's a great question. And the holdup has been that if you don't do it right, it really hurts it a lot. And so adding hardware that builds that protected vault, that enclave, that area where no one can get in--where bad apps aren't able to penetrate side channels, aren't able to get in--means, that you've got an area within the chip that is really kind of its own processing area. And so it has to have, has to be able to get data in and get data out and process at the same speed as the rest of the chip. That's a hardware problem. That's also a microcode problem. It's a software problem. And so it's complicated.
In the past, I think a lot of people have tried to do this. TPM chips were a great example. The reason they never really took hold is because there were separate chips. They had to go over a bus. They had to go over an interconnect. And the performance hit that you took, the latency on processing that data was, was pretty large. And so if you're, if you were just processing a couple of chunks of data, it's no big deal. If you're processing a big Oracle database, it's a big deal. I think we're getting better at it. And so I think you'll see it in a lot more chips and the impact on processing will be relatively minor.
Camille Morhardt: Are you saying you're going to ultimately see all of the applications that are running while they're being processed in essentially a vault or an enclave? Or are we always going to be selective about what is running in the enclave?
Jack Gold: Honestly, it will depend on how good a job you do at creating the hardware and how good a job do you do at the OS level. Until we get to that point, there probably will be some selection of, “do I run it in the vault or do I not run it in the vault?” based on the performance that I need.
Tom Garrison: Right. So what other opportunities do you see within the next say year or two, you would recommend sort of best practices or something along the lines of, of what we're talking about here with, you know, hardened security. Are there any other things that the listeners here should take away advice that you give them?
Jack Gold: Yeah. I think there are a few things you need to think about. Number one is you need to look at the entire compute chain. You need to look at it, not just from the hardware side, but also the OS and the application side. I want to go talk to SAP or, or Oracle, or Salesforce or whoever your primary vendor is. I want to go talk to them about the fact that I understand that there are now, there is now a possibility of running in a protected, vaulted, confidential computing environment. What are you doing to support that? Do you support it today? And if you don't support it today, when will you? and how do I get my applications into that vaulted environment?
The second thing I would say that you need to think about, people often have servers in place for five, seven, eight, 10 years. But those aren't the ones that are running the, you know, the heavy duty databases. Those are the email servers that kind of filtered down through the channel from high end to low end, as they got older. And people just kind of ignore them, getting new servers these days are not that expensive. And so if you're really going to run stuff on-prem, you really need to be thinking about how you're going to bring up a confidential computing environment on-prem.
If you're running it in the cloud, you need to ask your cloud provider, whether they support it. And eventually, longer term, what all companies should be thinking about is having these kinds of confidential computing, vaulted systems, trusted execution environments on every piece of hardware from smartphones, through PCs, through servers and into the cloud. Cause ultimately, that's the only way you can get maximum protection.
Tom Garrison: So I'd like to transition to one of these fun things that we do with all the guests. It has to do with our favorite virus, called COVID-19 now. What have you either come to love after having to go through this whole sort of working-from-home--work changes and personal changes--that you love? and, or something that you absolutely just cannot wait to get rid of?
Jack Gold: Great question. So look, it's nice to be able to work from home. It's nice to be able to get up in the morning, commute about 12 feet and get to my desk--whether I had my pajamas on haven't had my coffee yet, didn't call my hair, no one knows. Now the downside of course, is that it also means that I'm sitting at my computer potentially sitting at my computer at midnight because I just thought of something I needed to do and I might as well do it now. So the balance is kind of gone. My dog does remind me every once in a while that I'm home and that he needs attention. So that's probably okay. It gets me up and walking around.
Honestly, the part that I'm really getting unhappy about is the number of Zoom meetings (laughs) it's getting to be I'm Zoomed out. Look, it's just not the same as you and I sitting in a room face-to-face over a cup of coffee and. So I've, I've actually just for the most part, I just turned my camera off and just kind of do my thing (laughs)
Tom Garrison: Nice. You know, it did, it did occur to me. You mentioned your dog. Imagine how neurotic our pets going to be when we finally do all go back to work? Furniture is going to get torn up, the carpet is going to get ripped up, you know, Lord knows what else is going to happen (laughs). So I think there's a business opportunity there about whether it's dog daycare or whatever it's going to be, but we have some pretty pampered dogs that are going to have a rough reentry when we finally go back to work.
Jack Gold: Absolutely. I agree with you. And you know, the one nice statistic about it is that if you look at shelters, shelters are for the most part are out of pets because so many people are adopting them, which is actually wonderful. I mean, I for one--kind of a commercial message here--cause our, our guy is, uh, adopted from a shelter. So that's the good news. My fear of Tom on the negative side is that when people go back to work, they start bringing those pets back to shelters. And I sure hope that doesn't happen.
Tom Garrison: Yup, agreed. Well, Hey Jack, thank you very much for spending time with us. I know it's been a great conversation and, I think there was a lot of really good insight that was included in what you shared with us. So thank you for your time and for all of our listeners, we will catch you again and a couple of weeks.
Subscribe and stay tuned for the next episode of cyber security inside. Follow @tommgarrison on Twitter. To continue the conversation. Thank you for listening.
In this episode of Cyber Security Inside we'll learn how Lenovo is strengthening the supply chain to further protect its customers by introducing smarter end-to-end security through new services. Our guest is Rebecca Achariyakosol, Executive Director, PC Services Global Marketing at Lenovo.
Tom Garrison: Hello, and welcome to the Cyber Security Inside podcast. In this podcast, we aim to dig into important aspects of cyber security, which can often be highly complex and intimidating and break them down to make them more understandable. We aim to avoid jargon and instead use plain language for thought provoking discussions.
Every two weeks, a new podcast will air. We invite you to reach out to us with your questions and ideas for future podcast topics.
I'd like to introduce my cohost, Camille Morhardt Technical Assistant, and Chief of Staff at Intel's Product Assurance and Security Division. She's a co-director of Intel's Compute Lifecycle Assurance, an industry initiative to increase supply chain transparency.
Camille's conducted hundreds of interviews with leaders in technology and engineering, including many in the C suite of the Fortune 500.
Tom Garrison: Hi, Camille. How are you doing today?
Camille Morhardt: Surf's up! I'm doing well, Tom.
Tom Garrison: (laughs) Nice. That's right. You're at the beach. The benefits of being able to record anywhere in the world. Camille what's on your mind today for today's Security Matters segment?
Camille Morhardt: Well, Tom, I've been thinking about trust. And I've decided that trust is something that you can't actually offer. It's only something that can be bestowed upon you. So given that, what elements go into trust? Is that the same when we're talking about a company or we're talking about a relationship? And you know, what kind of actions could a company or government, say, take to increase your chances of trusting them since it's something you can only bestow upon them?
Tom Garrison: Interesting. So trust, I guess you can decide to inherently trust somebody, but ultimately it's something that you either are adding to the trust or you're taking away from the trust based on your actions.
Camille Morhardt: Yeah. And you don't get to decide whether somebody trusts you or not. You can only offer, I would submit actions, some sort of an action, like being upfront about your intentions or your mistakes potentially would increase trust, say in a romantic relationship.
Now, how does that translate when you're talking about the government? Do I trust the government or a company? How do I know whether I trust a company?
Tom Garrison: Yeah, that's a, it's a good topic. So let's say let's stick with companies. So how do companies increase trust?
Camille Morhardt: Well, I think one of the main ways the company can increase trust is to tell you honestly what they're doing. And I think that one way to do that when proxy, I would say almost for trust, is transparency. A bit of a buzzword these days, but that gives you visibility, not just visibility, but actually a complete view into what's happening. Transparency, everything from the, your intentions, which I think in most public companies are maximizing profit. There may be additional intentions or motives. And then after that, how are you going about producing your product?
Tom Garrison: You know, it occurs to me that there's a lot about products in general, that we don't know really much at all. We know who we bought it from. We hopefully we trust that company that they're doing the right things, but there's a lot of yeah of information that could be made available to the customer, the end customer about the devices that they're buying today.
Camille Morhardt: Yeah, is it my business? Do I just get to put trust into a company? Um, and that's good enough. I believe the company, they have a big name. They've got a good brand, you know, do I really, do I have some sort of a right to know more than that? I can buy from whoever I want.
Tom Garrison: Yeah, I think, I think you do. I mean, you know, maybe there's a debate to be had here, but I, I think as the customer, you have the right to any information that is going to have an impact on you the customer moving forward. And that might be things like, you know, maybe a more detailed understanding of what goes into the products that you're buying. And, based on that knowledge, you, you have a better understanding of what risks are involved from a security standpoint.
I think you have rights to any information that has to do with the way you're using the product. I don't think you necessarily have rights to the vendor, whoever you chose to buy it from. They've aggregated all the data about all of their customers. I don't think you as a customer have rights to that, but I do think that if you bought 10,000 of something, you have the rights to the aggregated 10,000 that you own.
Camille Morhardt: So do I have a right to know exactly what's in those devices that I own. I mean, if there's sub-vendors that are traded out, uh, we have, now we're using it as a screw from a different company now. Do I need to be burdened with that information?
Tom Garrison: Well, first I think there's a question of how much value do you get from what screw they use. But if you were to say instead, maybe the line is intelligent devices, things that are running software within maybe your PC or within your server, within your IOT device, for a couple of different reasons.
Let me just share sort of my view. If there ever turns out to be a security problem down the road with one of those devices, then you want to be able to know about it right away as soon as possible. And so if you already know what are these subcomponents in your device, then you should be able to aggregate your entire installed base of PCs or servers or whatever, and say very quickly, “I just saw about this vulnerability about this component. Do I have that component anywhere in my infrastructure?” Yes or no. There's a huge value in having that.
If you have to wait for your system provider to tell you that there was an issue you might've lost two months, three months, six months down the road.
Camille Morhardt: That's seems like bringing some alarms. That seems like a tremendous amount of collaboration which may exist in some industries. I think we have pretty good forward and backward traceability in the food industry in certain parts of the world to protect against bacteria and trace that. But is that level of traceability really necessary, you know, in a pair of running shoes? Maybe it is in a car or in the food that I eat, but are you adding or demanding unnecessary costs in even for the service of understanding, whether I have something, a problem with the thing that I'm using right now.
Tom Garrison: So, I think this is an episode. I think we could narrow it down to platforms. So say PCs and servers and our T devices. And I think this discussion is what we should cover today in today's podcast.
Camille Morhardt: I like it. Yup. Sounds good.
Tom Garrison: Let's go for it.
INTERVIEW
Tom Garrison: In today's discussion we'll learn how Lenovo is strengthening the supply chain to further protect its customers by introducing smarter end-to-end security through new services. I'm pleased to introduce our guest Rebecca Achariyakosol Executive Director, Global Marketing, responsible for product marketing and sales enablement for Lenovo IDG services.
Rebecca, please take a moment and tell us a little about your role at Lenovo.
Rebecca Achariyakosol: Sure. Hi, Tom. Thanks for the introduction and the opportunity to speak with you today. I've been working scene for Lenovo for almost three years now, and I am responsible for services, product development, marketing, and enablement for our IDG business.
So IDG stands for Intelligent Device Group, and that includes all of our laptops, desktops, workstations, and any of our mobility devices like tablets and phones. I don't create products. My job is to build solutions that can solve customer problems.
Tom Garrison: Well, that sounds interesting. Um, can we maybe just jump right into it and talk about some of the new services that Lenovo has introduced?
Rebecca Achariyakosol: So the supply chain is really an area that traditionally has presented some vulnerabilities that can be exploited. The window after devices leave the manufacturer before they reach the end user, that really creates an opening for someone to tamper with the PC. They can remove or replace components and it's really hard to detect that that's happened.
So Lenovo is directly addressing this problem within the security supply chain, with two services that we call Transparent Supply Chain and Trusted Device Setup. With these two services changes not only to the hardware, but also to the software can easily be detected.
Tom Garrison: Interesting. So maybe let's start with Transparent Supply Chain. Can you talk more about what Transparent Supply Chain is and how it works?
Rebecca Achariyakosol: Sure, absolutely. So Transparent Supply Chain is exclusively available for PCs with select Intel platforms. And it allows us to detect any hardware changes that were made between the factory and the customer. So it enables the visibility and the traceability of the hardware components so that customers can be confident that the system and hardware is exactly as it left the factory. So what they receive is exactly what was shipped.
Tom Garrison: Okay, so that makes sense. And, and you also mentioned Trusted Device Setup. What does that do?
Rebecca Achariyakosol: So that's kind of the other half of the equation. So Trusted Device Set up. It's a preload verification process. We seal the software at the point of manufacturing, so that any tampering attempts that occur after it's been sealed can be detected and prevented. So it's the second half -- Trusted Device Setup gives you the software security pieces from the software perspective and the Transparent Supply Chain is the hardware half.
Camille Morhardt: Hey, so Rebecca, I'm curious, transparency doesn't actually prevent a problem, right? It just, it just allows people to understand if a problem has occurred. So why do you guys value transparency just to back it up. Why are you pursuing it? How is that important?
Rebecca Achariyakosol: We have our Trusted Supplier Program and that's where we thoroughly vet our vendor and we do audits and inspections and things with our vendors to make sure that there's nothing in the supply chain up to the factory. But we also wanted to further expand how we've used security and provide an additional level for kind of end-to-end protection.
So Transparent Supply Chain and Trusted Device Setup, they kind of extend that past the factory through the entire supply chain, to the customer. And with these, we can make sure that the devices are truly what they should be receiving and they don't have any kind of security, risks or concerns because something's been tampered with.
Camille Morhardt: Sometimes as an industry, we tend to throw technology at the problem and forget to adjust processes or training to add the human element and intercept problems or potential problems that way. How are you guys balancing that risk?
Rebecca Achariyakosol: The pieces that we have with our Trusted Supplier Program, you know, that's kind of a little bit more of the, the people element side where we verify with process and, and people in such that, you know, anything coming into our factory we have more control of that and so we can put those pieces in place. But we really don't have any control once it leaves our factory, right? It's really up to how the customer is consuming that product, what route to markets, who they're using and in partnership to help with different pieces of and provisioning, et cetera. And so that's where we really have to lean on the technology piece.
Tom Garrison: I think that's an interesting point that the technology almost serves as a backstop so that you can try to put all the people processes in place, but ultimately the, the last check is the, is the hardware and the, and the services you put on top of that.
I wonder if you can maybe just expand a little bit on the fact now people are working from home and workforces in general are more distributed than ever. How does that play into your offerings here?
Rebecca Achariyakosol: In a recent study conducted by the security firm Barracuda Networks, 46% of surveyed global businesses said that they've encountered at least one cyber security scare since shifting to this more remote working model with COVID--and in the first quarter of this year. So that's pretty staggering. Almost half of these companies. And that's due in large part to the security risks that these remote workers pose. Right? So, you know, these services, it makes it easier, more secure to send devices directly from the factory to the employee, which is more what companies are moving to.
They don't have the luxury of that coming into the office and being touched by their IT person. So this makes it easier and more secure to send those devices directly from the factory to that end user employee. And they can still have the confidence that it hasn't been tampered with.
So this helps increase productivity, it reduces downtime, you get their end users up and running more quickly. And in some cases it really improves the efficiency for the customer's internal IT staff. So, we see this as maybe a continuing trend.
Camille Morhardt: Yeah. Hey Rebecca, do you think we're going to go back?
Rebecca Achariyakosol: Most of the companies that we've talked to, a good majority of them do see this aas somewhat of a permanent shift. Of course some workers are going to go back to a more traditional office, it's not going to be everybody working from home.
But this had already been a little bit of a trend, um, where you'd had a more distributed workforce. And I think, you know, this has just become an opportunity, it's accelerated sort of, some of those timelines. It’s become an opportunity for customers in companies to implement a more distributed workforce a little more quickly.
So I don't think it's going to go completely back. So that's why things like these technologies are going to remain important.
Tom Garrison: Now you can ship devices instead of going through sort of an IT cage to do the provisioning and so forth. You can just ship directly to the user themself.
I wonder if you could talk a little bit about how you, as an IT shop, how you roll out systems with integrity.
Rebecca Achariyakosol: So there's different pieces that you have to go through to make sure that an end user can just receive a box and get up and running. There's lots of technologies that we could kind of talk about, in the provisioning space, that allow customers to be able to get onto their networks seamlessly and very quickly and access all the things that they need.
So, we've kind of been on this journey to turn an employee like a laptop into a cell phone experience, right? So you get your new cell phone and it'll log in. They know who you are. You can be pulled down with our apps and things you need, you don't need somebody to get you up and running. This is very similar. And so there's, there's lots of technologies in that space.
And then of course, like I said, there's the security pieces, which is a huge part of it. So it's, you know, we were talking about Transparent Supply Chain and Trusted Device Setup and how that plays into it to make sure everything is trustworthy as it gets there. But then there's just kind of the monitoring, patching, all those other types of elements that our customers have to think about as well. And, and we're happy to help them with those pieces too.
Tom Garrison: I wonder if you could speak a little bit about The customers in this space and what customers are interested in Transparent Supply Chain and Trusted Device Setup?
Rebecca Achariyakosol: I mean, honestly, any company that wants to protect their devices through the supply chain can benefit from these services, right? It's also companies that want to drive higher levels of automation in IT Like we were just talking about and they need a mechanism to ensure that what the end user's receiving it hasn't been tampered with.
But additionally, specifically, you know, IT and government accounts are particular in who could be interested in those due to, you know, they're obviously highly IP sensitive nature of the work they do and the information that they handle.
Tom Garrison: Yeah. Can you talk more maybe about those classes of accounts--the highly sensitive IT accounts and government accounts?
Rebecca Achariyakosol: Sure. There are emerging standards within IT and government that they're attempting to meet, right? So these types of organizations, they typically require better visible visibility into how and where and with what their computer products are. Belts. The data is valuable for asset tracking and patching when vulnerabilities are disclosed.
So it's really about them needing to be sure that everything on their system is secure and that there's nothing been put on there that can help somebody steal or leak out their information.
Tom Garrison: I'd like to transition now a little bit into the future and pick your brain a little bit, Rebecca, if you don't mind. So what do you think are the major shifts and in the next year or two?
Rebecca Achariyakosol: I think that the narratives of today, they're really going to continue forward. I mean, even before COVID-19, we'd seen customers interested in moving to a more modern IT solution and which includes, you know, security pieces. And this was to facilitate them moving to a more distributed workforce and then also to help free up their iIT staff.
So these are things that we've been talking about to customers for a while. And I think all COVID is really done is it's accelerated that timeline. Um, and increasingly companies are reporting that even post COVID-19, as we talked about before, or the move will be to have more employees remote. So you're not going, we just see this big shift where everybody's going back into the office. So, it's not going to be business as usual and, and companies are going to continue to invest in modern IT security offerings to facilitate this new normal.
I really think the next year or two, as you asked, it's gonna be more of what we're seeing today. Customers are putting stop fixes in place, you know, because COVID happens so quickly, but now they're going to be focused on really streamlining those processes and preparing to have the more distributed workforce.
Tom Garrison: Yeah. I've, I've said to people that have asked me similar questions, that the thing that COVID has done is it changed people's perception about how productive people could be working remotely. Cause it wasn't that long ago where people assumed that if you were working remotely, you weren't as productive as you are in the office. And I think being forced to work remotely, like we all have, we've been able to change that perception pretty significantly. And so going back to the way it used to be, I think is a, is a fantasy. I don't think it's going to happen.
Rebecca Achariyakosol: I've been a big work from home proponent and you can be very productive and there is a lot of benefits to it. So I agree with you. I think it has changed the way people are viewing it. Those that haven't had that opportunity, the world in the business world is, is going to be very different when we come off the other side.
Tom Garrison: I'm going to change gears just a little bit here and maybe have a little bit of fun. I wonder if you could maybe share with us, what's one thing that you've changed to accommodate COVID-19.
Rebecca Achariyakosol: Certainly I'm not on the road. Like I was before, you know, excitement today is defined as a walking in my neighborhood and maybe picking up some takeout. Um, but I've really enjoyed having this time to be home with my family. We've had a lot of changes.
We're very much into martial arts and doing our classes via Zoom. They've recently started having some outdoor classes at the gym. So there's, you know, absolutely nothing like being outside in a hundred degree heat with a mass on exercising. (laughs) But you know, it is a chance at least to see some people. Um, and my, my oldest son, uh, every night he ends his prayers by praying COVID goes away, so he can go to his favorite sushi restaurant. Um, you know, he's really focused on all the important,
Tom Garrison: and then there's always takeout sushi, you know, don't, don't, uh, that short.
Rebecca Achariyakosol: We have done that twice now. And although, you know, I have to explain to my son that sushi is not the cheapest meal to do. Um, but he really always that experience where, you know, you, you try things and so if you like something you can continue to kind of order the different pieces that you like. Right. Versus, you know, he's got to think upfront of everything we might want to have from the restaurant. Um, but yes, we're absolutely have done on some special occasions some takeout, sushi.
Camille Morhardt: That sounds like a flexible supply chain.
Rebecca Achariyakosol: (laughs) Exactly. Absolutely. He definitely is always that flexible supply chain at a sushi restaurant. You just can't replicate that at home. I guess I could try and hide some of what we brought all and bring it out to them little by little. (laughs)
Tom Garrison: Great. Well, Rebecca, it's been nice to get to know you and thanks for coming in today and talking about. Lenovo's service offerings around Transparent Supply Chain and Trusted Device Setup.
I think it was educational for people to understand what's possible and, and the kinds of protections now that can be built into the platform directly. So thanks for coming in.
Rebecca Achariyakosol: Well, thank you for the opportunity. It was a pleasure to get to know you as well.
Tom Garrison: That's a wrap. Thank you so much for listening. I'll see you next time.
Subscribe and stay tuned for the next episode of cyber security inside. Follow @tommgarrison on Twitter to continue the conversation. Thank you for listening.
From the publisher's feed