Inside Product at Cisco

5. Reimagining Cisco Security with Jeetu Patel and Peter Bailey

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 31:10

Jeetu Patel and Peter Bailey discuss the evolution of Cisco's security portfolio in the age of AI. Particularily in the context of new security models like Mythos, they discuss how Cisco is simplifying security, providing our customers with the speed and scale they need to protect their most critical assets

SPEAKER_01

Hello everyone and welcome again to Cisco's Inside Product series of conversations. I have with me Peter Bailey, who is our fearless leader in the security business, joined us. What is it? Has it been a year?

SPEAKER_00

Year and a month.

SPEAKER_01

Year and a month. Yeah. Wow, it's amazing. And joined us from Google. We're delighted to have you here. Delighted to have you on the pod. Thanks. And um uh tell us what's happening. By the way, this you might be in the hottest area at the intersection of AI and security that there is in the industry. So um take a step back and tell us what's happening in your world and security and what are customers telling you. You just came back from Germany. Just came back from Germany. You've got an enormous amount of stamina to be in Germany. Yeah, yeah.

SPEAKER_00

Have not slept in a while. That's okay. Um listen, the last 75 days have you know changed so much, and the whole security market and the problem set is getting redefined around mythos and agentic security. And you know, mythos really announced the world that the frontier models are now good enough to do the things we've been afraid they were going to do for a long time, which is to penetrate all of our defenses and penetrate applications. And you know, the world we have built to date is one for human speed and whether that's policy or a reaction or what have you, and it all needs to get rebuilt for this machine speed. And so we've been talking to customers about that a lot, how to get ready for that. I think that the thing that is coming first, the first wave is vulnerabilities. The perimeter has to be patched, uh, products have to be patched. The second wave is gonna be internal vulnerabilities. Think open source, which is a huge, huge problem as well. And then you think about how you're gonna actually improve your defenses and in the short term put up walls because we know lots of things we can do around zero trust, around segmentation, around walling off the crown jewels that can survive these attacks. Um, but everything has to get rethought along the lines of how you're gonna have comprehensive visibility, real-time policy, and enforcement everywhere. And of course, that's in our view kind of advantaged Cisco because the network is everywhere. Network can't be compromised, a host can be compromised. Uh, we have visibility everywhere, we have the opportunity for enforcement everywhere, things like the smart switch, putting a firewall on a campus switch, all the things we're working on or have announced. This is about distributed enforcement everywhere so that we can protect at the edge, protect at the core, because you're gonna need all those protection points to be able to fend off AI-based attacks. And ultimately to safely use AI in the organization as well. And so this is what we've been talking to our customers about, and it's obviously um, you know, gonna be, I think, what we're talking about for the next you know 12 months, if not longer.

SPEAKER_01

And so given that you're gonna see a fair amount of kind of acceleration of attacks from agents um and from adversaries that are gonna actually use agents to go penetrate environments that they otherwise could have not penetrated quite as easily. I think there's gonna be a massive democratization of um um, you know, kind of hackers getting into environments that could be nation states, that could be individual actors that are threat actors. Um and you talked about the fact that you need to have visibility everywhere which you can get through the network. Walk through um for us on what we are building and how has that because you've you've done a few things which are very remarkable to you and the team. One of them is we used to have a firewall estate that was pretty dated a few years ago. I think you've completely refreshed it. We've got a full new lineup of products in the firewall. We've actually that business is growing very healthily now. Yep. Yep. You've got secure access, which now you have, you know, uh an enormous amount of user base at this point in time within a very compressed amount of time. Yep. Um what what are you seeing in the momentum as far as adoption of these technologies? What feedback are customers giving you, and what are the things that you feel like, hey, you're in. Here's what surprised me about Cisco, both on the positive as well as on the negative.

SPEAKER_00

Yeah. So so let me kind of touch the product uh evolution. And so it's you know, the the traditional on-ramps we talk about are firewall, right? Our zero trust, our identity, right? And and network detection response and email security. And, you know, we spent the last year plus really dialing in on what we think we can be the best in the world at, where we can lead, right? And really have focused in on network security, focused in on zero trust, and obviously identity is a substrate, and I'll come back to that. Um, and obviously, you know, network detection response, I would add to that as well. But but ultimately, you know, you take a real big step back. I think everything we do can be categorized as either visibility, policy, or enforcement. You got Splunk really as a visibility layer across the organization and your entire state. We have policy models all over the place, right? And you got it in the network, you got it in security and everywhere. And our opportunity and superpowers to create a singular policy plane that can talk to everything else. And so that as a security professional or a network professional, you can create policy and enforce it everywhere, which across a very diverse environment, a large environment, uh is very challenging today. And so when we think about whether it's ICE and security group tags, right, and doing segmentation in the campus, we think about the Nexus smart switch and doing segmentation in the data center, we think about firewalls, we think about workloads, right? The ability to problem solve with policy, and then having this broad landscape for enforcement. And again, that's really a superpower. So the things we are working on and talking about is how do we think about that more holistically? How do we think about not just a firewall as a hardware appliance sitting in a in the center of a network, but how do we think about sensors and enforcements and decomposing that and putting that everywhere? And so you've seen that start to happen with HyperShield, which is on the smart switch now. You're gonna see more of that at the workload level. You're gonna see more of that embedded in our switch infrastructure as well. So it's really taking what are kind of these historical on-ramps and starting to decompose them to some extent, but push them into the network, push them out to the edges and distribute those, because we know that data volumes are gonna be enormous. And just putting a bigger firewall is not the answer, right? You're not gonna get a TEDx more capacity firewall. You're gonna have to have distributed security.

SPEAKER_01

And so migrating So is the big architectural shift in security just hyper-distributed security?

SPEAKER_00

It's it's hyper-distributed, and it's having a real-time view of your environment so that you can have the visibility and the policy and enforcement when we think when we think about AI. And so to have that, you have to have identity. You have to have identity aware. The network has to be aware of identity, everything has to have an identity, has to be a cryptographic credential that's ephemeral in nature, adjust in time. All those things we talk about is the way we're gonna secure this environment such that we can safely use AI, we know what should talk to what, what should not talk to what, have pattern recognition. And so, you know, I talked to my team about, you know, again, I kind of try to simplify it because it's complicated, you know, visibility policy and enforcement, and that's kind of been our world for a long time. But then we did these verticals of firewall and email and network detection response and CNAP and identity, and they all have elements of visibility policy and enforcement. But between them all are gaps. The data planes aren't merged together, and between them all is where AI is going to operate. So we have to have more holistic views, breadth and depth, and the ability to build a knowledge graph in the background that can look across that and see there's those real-time interactions such that you can put intelligence and policy on top of it. And that's that is what we are building, that's what we need to build to really enable the safe use of AI.

SPEAKER_01

And so um what happens with let's assume that agents are gonna be everywhere. And agents are gonna be um, you know, rather multiplicative in their pattern of usage of infrastructure as well. And you're gonna have thousands of agents per human uh over time. Um the biggest challenge that you have right now is this notion of trusted delegation to an agent is really, really hard to do. And right now the difference between trusted delegation and simple delegation is the difference between like you know, market leadership and complete bankruptcy and abject failure. What is uh what what is your team doing to really help with agent security, agent trust, um, and uh guardrails for agents so that they can operate in a way that you want them to operate and not in different ways that you that that surprise you in in ways that could really be business-ending for your company.

SPEAKER_00

Yeah. So you said a really important word there, which is trust. And again, we we need to think about identity as sort of the the new trust layer. And the extent that the network is aware of that, you've got a trust anchor in the network, you've got a trust anchor in identity, and that's gonna be super important going forward. So when we think about building, you know, the ability to use agents safely, and you think about the examples you gave, like a tightly bound agent, right? They can do one thing, right? And that that feels like something we could sort of authenticate it, monitor it, and it's only allowed to do that one thing. It has policy controls around it, so it can't do anything else. Maybe it lives actually in a container, lives in a sandbox environment, right? I think we we we have solutions that can deal with that today, and that's really built into how we think about discovering and authenticating and authorize an agent on the network. Then you go to the other end of the spectrum like open cloud. And you know, why have we not seen dramatic usage of open cloud? Why are they sitting on your desktop side computer? It's because they have broad capability. And so for broad capability, you really need not just the ability to see the behavior and take action. You have to do that at machine speed. And ultimately, you're gonna have to be able to write policy and enforce policy at machine speed, which means using an LLM to watch an LLM ultimately, right? And so where we are as an industry is still wanting a deterministic step in there, whether it's policy or in changing policy and not leaving it all up to an LM watching an LLM. And so that's that's that next step. And so our team has built what I would sort of say is is the steps to, like I said, discover authenticate, authorize, and monitor behavior and take action. But today those are still at human speed. They're not yet at machine speed, and that's where we're gonna have to get to to really enable broad use of these broadly capable AI agents across the network.

SPEAKER_01

So I'm a customer. I have a pretty broad, sprawled out of state. I've got some um different security vendors in the market because on average there's 3,500 vendors in the market. On average, people have 50 to 70 of them. Um I hear from Cisco that hey, it's it's uh important to make sure that you have a um co-designed, full stack, integrated platform. Um what can I do with you without actually going out and extracting everything out of my organization? Because I don't have time to go take everything out all at once.

SPEAKER_00

Yeah, so so we gotta meet the customer where they are, right? Like you said, these are big estates, big investments, very complicated. And while the perfect world, everything's standardized and uh heterogeneous or homogeneous rather, it's it's not.

SPEAKER_01

And by the way, share also why the customer should care about working with Cisco in the first place as well as you go through this.

SPEAKER_00

Yeah. So so when we approach a customer, um, we are trying to think about how we can bring obviously our products to bear and wrap it around the customer, but then allow them to still work within their current environment. So I'll give you an example. So, you know, firewall, right? We've got northbound perimeter firewalls, you have zone firewalls, you have firewalls you're putting in switches and workloads. And the thing I said early on is the key is there is policy. Policy is the platform. And so we have built a policy engine as an example that can write policy and push it down not just our firewalls, but third-party firewalls as well. So give the customer an opportunity for policy integration. And so I think working with Cisco is working with a company that's open, that you know, works in an ecosystem, that is used to working in an ecosystem, and you can create simplification while still not having rip and replace everything. And obviously, over time we we think our products are better. We want you to kind of continue to add those in the world, but that's an example of how we are approaching it.

SPEAKER_01

Why would I come to your firewall versus going to someone else's? Give me what why your firewall is better.

SPEAKER_00

Absolutely. So we are doing things that we think are unique to us, right? We have built very unique ML models. We built the Eve encrypted visibility engine to look at encrypted traffic. We were able to detect things on the network that others are not able to detect. And we've seen that in performance reviews again and again. But what I would say is that again, the power, I believe, is gonna be in this policy unification, the policy plane, because that's the intelligence layer. And so you want to build simplification under your strategy. You want to build the ability to have an intelligent leader. Because over time, as you know, some point that's gonna be AI that's driving that. And so to do that, you have to unify the substrate, the data, and unify a platform there that you can actually put AI on top to drive policy. And that's that's really what we're building.

SPEAKER_01

We are at this point in time extremely AI forward in the sense that we've got an entire stack of agent security. We we launched AI defense. We were the first to launch AI defense like, I don't know, two years ago. Um and and that that essentially has been a tremendous kind of area where customers have interest saying, hey, I I have these models, they're unpredictable, they're non-deterministic, but you can go out and validate these models, you can then dynamically enforce guardrails. Um baking security into the network, making sure that you've got the right level of efficacy because of the breadth of the product, and ensuring that your AI forward do those um generally do you agree with those, or are you you think that there's anything fundamental that I'm leaving out?

SPEAKER_00

No, no, no. I mean, you took it beyond firewall and hit some really important points. And the thing I would add that you didn't say is that now with cloud control, yeah, having this all brought together, right? And so having unification of management, of data planes, control planes, is gonna allow us to also drive different outcomes in the future, easier outcomes in the future, too. And so the thing I'm also hearing from customers is as you know, that was by far the biggest thing we announced at Cisco Live US was really Cisco is is finally serious about this. They've taken the steps, they reorganized the business a couple years ago to do this, but they're now seeing that things are coming together. And I had partners and customers say to me, like, we get it. We get it now, we're we're back in. You know, we we understand the value of that. And and so I think I think those all of the things you said and and the platform reality that we're we're uh introducing now is are are all very powerful messages.

SPEAKER_01

Aaron Powell Yeah. And so what do you worry about the most with our customers as as they work with us? So so Cisco is not always known, even though we are one of the largest security vendors, not everyone fully processes all the advantages. If you have an opportunity to talk to our customers, what would you say to them and how they should be thinking about it?

SPEAKER_00

Yeah. So I think as you said, like we have probably one of the best kept secrets in the industry, right? We have Talos, the 500-person Threat Intel that sees as much as anybody. I I, as you know, in my background, I've been in a couple of big shops that have done that kind of work, some of the best in the world. And talk about your background real quickly. So before Google was with Mandi, and before that with FireEye, um, and so have had a chance to see a lot of things at scale, a lot of things from a threat intel and an instant response perspective. And so have a sense for or kind of what that looks like. And the talus team is excellent, right? And the talus team is writing those MLMs for our firewalls, et cetera, right? And so what when I I want to educate customers, you know, first of all, understand their needs, understand how we can help them, right? Especially in this moment, everyone is so worried about mythos and what's going to come next. And there are many things we can do to help them. I mean, even someone who just owns ice but is not using it to the extent it can be used to segment their network, that is a very valid defense against an I-based attack, right? And so for me, it it's an education. And so when you ask what I'm worried about, it's I want to make sure customers understand what we can do for them and what we can do because they own the network, because they're already a customer of ours, how they can even create better outcomes, also leveraging our security products, and how those are becoming very integrated into that fabric, as you said. I just don't think that message has gotten out there enough yet. As you said, we've been on a journey, but I think we're feeling very, very good where we're at. And frankly, uh the Mythos moment has given us an opportunity to go talk about that.

SPEAKER_01

I will say that the progress that you and the team have made in the course of the past two years in most of the new and refreshed products that we have in the market has been nothing short of extraordinary. So congratulations on that. Let's let's switch gears to, you know, um agent security.

SPEAKER_00

Yeah.

SPEAKER_01

One of the things that you'll see with agents is like I love your framework that you've laid out, which is hey, we gotta protect these agents from the world, we gotta protect the world from agents, and we gotta make sure that we're operating at machine speed and scale. Yep. Explain that a little bit and talk to us about what you've built on agent security. Because you just launched something at Cisco Live on Agent Security.

SPEAKER_00

Yeah, yeah, we launched the agent security app that gives you a view on everything that's happening in your network effectively, right? So so yeah, the three paradigms, right, is you know, protect agents from the world, protect the world from agents in detection response at machine speed. And so in the first example, protecting the agents from the world, you know, we're using these models, we're building uh apps with these models. These models can be poisoned, these models can be jailbroken. Uh, you know, we want to understand um, you know, the the provenance of these models, we want to understand you know, every interaction with the model because you know these agents you might be building are also reading our emails or interacting with websites. They might be getting malicious content coming back to them. And so you have to put protections around them so they are not impacted negatively themselves to keep this all this safe, right? And so when we think about protecting um uh the agents from the world, it it's that. It's also you can have a compromise in your in your data center, and a workload can be compromised. And that workload, you know, if the workload is compromised, your agent's compromised, right? And that workload might be talking to another workload, right? And so this is kind of coming back to things like segmentation become important in the data center. So so all of that needs to be understood in the context of where agents can go and how they can be impacted. And so to your point, we've built fantastic capabilities with the iDefense, now with segmentation with a smart switch. And so we have some very strong solutions there to help protect agents that our customers are building.

SPEAKER_01

So basically, what you're doing over there is saying if there's an effort from an external party to go out and do a prompt injection attack, data poisoning attack, uh, any kind of efforts to go out and alter a behavior of the agent.

SPEAKER_00

Trevor Burrus, Jr.: We're gonna scan everything it does, we're gonna red team it, we're gonna we're gonna make sure that that the prompts and responses we're getting out of the model are what we expect.

SPEAKER_01

Aaron Ross Powell And you will algorithmically validate that the agent's working the way that you wanted to work. That's right. Um and if um so so that's the first thing is protecting the agent from the world. Aaron Ross Powell What ha what what is this whole notion of protecting the world from agents?

SPEAKER_00

Aaron Powell Yeah, so a few aspects of this. We talked about sort of the mythos stuff, which is really kind of getting at the same issue. We didn't talk a lot about zero trust, right? So zero trust you know kind of began as this idea of a way to provide access onto a network, right? Almost like a network-based solution. Least privileged access. Well, yeah, and in some cases just access, but yes, but we're going towards least privilege, right? And you know, connecting to apps, connecting to whatever a user is trying to get to. So we use that same paradigm now for agents, right? And we want to think about true zero trust, assume that as a malicious agent, and have the ability to quarantine, to enforce policy, et cetera. And so to do that, we've got to create an extension of our current zero trust, as is what we've done. We introduced also back at RSA is the ability to discover, authenticate, authorize an agent. And then at Cisco Live US, now the ability also to enforce policy based upon what the agent is actually doing, right? And so we think about, um, and I'm gonna come back to identity in a second here as well, because identity is is, again, still a fundamental piece of the fabric here because I want to know what the agent's talking to. I want to know every data source, every workload, you know, I want to get that information also from the network because we want to be able to have that visibility so we ultimately can uh impose and impose policy and enforcement. And so zero trust and the whole zero trust platform is designed to do that.

SPEAKER_01

So would it be fair to say on the identity side that the goal that we have is to make sure that we can be the provider of not just identity for the human, but identity for machines and services and agents.

SPEAKER_00

Yes.

SPEAKER_01

And once we have that identity, we will be able to make sure that we can assess the behavior of that identity. Detect for anomalies, and then do something to make sure that you can actually put the right guardrails.

SPEAKER_00

Trevor Burrus, Jr. And one step further is I want the infrastructure to be aware of identity, I want the network to be aware of identity, I want to be able to enforce lower in the stack, right? I don't want this just up at the apple chair.

SPEAKER_01

So what's the real world example of that?

SPEAKER_00

So the real world example is like, for example, we have security group tags today, right? This is a way we've been we've been delivering a segmentation on our networks for, I gosh, 15 years now.

SPEAKER_01

Aaron Powell And so just for the folks that are not completely familiar, so security group tags do what?

SPEAKER_00

I can I can tag a group of users, and and and those users can only go to a certain part of the network effectively, associate my segmentation with who that group of users is, could be a group of machines, what have you, right? So um, you know, and and down operating layer two, layer three, right? You're down in the network, right? So we have spiffy IDs up here, up top, right, which is a new rich way to kind of think about identity, right? So spiffy ID is going to give you information about what the thing is, you know, what it ought to be doing, et cetera. You can have a lot of rich metadata in there. How do I get that data down to segmentation? How do I extend SGTs to also be a participator in enforcing identity so that if I do have AI on the network that's not credentialed, maybe doesn't have a rich SPIFI ID, or it has one that expired an hour ago, or it's not supposed to be in this part of the network, how can I also invoke the network to help in protecting me? And that's really a a place that Cisco can play, right? Where we actually can bring the infrastructure and the network to bear to help as well.

SPEAKER_01

What question do you think customers aren't either asking or aren't preparing themselves appropriately for in this day and age? Like what worries you the most and what questions are they not asking?

SPEAKER_00

Yeah, so listen, it's hard to get past mythos right now because for those of us have been in cyber.

SPEAKER_01

But everyone's asking about mythos.

SPEAKER_00

They are, but at the same time, I mean, uh unfortunately, like there's been a lot of press that kind of says, hey, maybe it's all marketing, maybe it's not real. Everywhere I go, I say it's real. It's the real deal. We're dealing with vulnerabilities and we should spend some time with this. Like what I'm also saying to customers is like, listen, not only do you need to patch your own products, you may need to rewrite them. If you have legacy products with fragile code and patching itself is going to create probably instability. You may have quality issues your customers aren't going to be able to deal with, right? I in my personal belief is we're going to end up rewriting most of the software out there because in most cases, that's going to result in far fewer vul vulnerabilities, uh, software that's frankly simpler, um, you know, kind of collapsing some of these legacy architectures and putting pieces together, and that's gonna create better outcomes and take a whole class of security problems off the table. You know, have they actually protected the crown jewels? Have they gone beyond that? You know, you know, can can prod our engineers over here talk to the sales team over here, right? Like what actually protections are in place? And hygiene becomes a really important issue. And again, so much of what we do, we've put some incredible products and technology out of the years, and I think our customers probably use 20% of their capability, right? And in this moment, you want to turn stuff on. You're right, you want to upgrade your infrastructure if it can't handle some of these uh capabilities, but you want to actually start using these capabilities and build on top of that. And so that is kind of the moment we're in right now, and I think that's gonna be the next several months of our lives. I guess one other thing I'll say is that there's gonna be a tidal wave around open source vulnerabilities. And that's another area that we're trying to put people's attention to because everyone's got a bunch of legacy apps they built on open source and open source libraries that they've used. Massive vulnerabilities there because guess why? It's it's source code that AI can read and they can munge and find the vulnerabilities. And so we've got to do a lot of work there too. So putting attention to that. And we actually have capabilities there too with our HyperShield agent that can actually put shields down and protect that. And so we are working to make sure that we're putting up layered defenses, right? Defense in depth with and for our customers, because you're gonna need that to handle all these different scenarios.

SPEAKER_01

So here's what I'm gonna I want to talk about Live Protect for a second. Yep. Live Protect is a product that we introduced, and I'm just gonna explain it and then give give give me the next level of color on the detail. Um when you announce a vulnerability, uh, it typically takes about 45 days to patch the vulnerability, but your exploit can happen within a matter of minutes. So you've got this exposure kind of window. And the reason it takes so long to patch is you have to bring your systems down, and usually people can do it a couple of times a year, and so it's very, very hard to do. Patching is hard. And so we needed to have some mechanism where organizations can have an interim um mechanism while the patch is still being applied or n or being prepared to be applied for them to stay safe and secure. That's right. And so Life Protect built this kind of compensating control, and you can actually stack multiple compensating controls together to the tune of up to 20, and that'll only go up over time. Yep. Um, that allow you to go out and basically put a shield in front of a vulnerability so it can't do things that can put your business in harm's way. That's right. Um provide what this what is your vision on what this can do over time in the next um six, twelve, eighteen months? Yeah.

SPEAKER_00

So so Live Protect, you know, is there's technology under the hood, but really it's a program. It's a shielding program, right? And and much like in the old days, we might write snort rules or other things for our firewalls, I think this is going to turn into um a sort of ongoing valuable content we can give to our customers to help protect their infrastructure, right? And so, you know, you've kind of taken us through exactly what's happening, which is we're we're pushing an agent down to the product. Um, all of our products run some version of Linux, and so it's it's a it's a uh it's an agent that sits on the Linux kernel, and we're able to see different attack types and vulnerabilities, understand those, and write a shield to block that process call or whatever it might be, right? And to your point, based upon the memory, the system, and the compute, they can handle 10, 20, more, what have you, right? And we're scaling that. And we don't want this to replace patching, right? Patching, and again, the other thing we're talking to customers about is the patching operational model has to change. Yeah. We have to get more in this kind of CI CD pipeline mode where you know it's not every day, but it man, it can't be every six months. It can't be every six months. And so there's probably some tooling there needed as well. But ultimately, patching needs to be something we are at least for the next 12 to 18 months gonna have to get a lot better at. But but even then, we can buy you time, right? And to your point, you know, the the from um vulnerability to exploit, I mean, it was like three years as of like two years ago, like the time.

unknown

Yeah.

SPEAKER_00

You would see these things kind of show up. And if someone really put their work into it, it actually could happen in months, but on average it was like three years, right? And to your point, we've collapsed down to not just hours, but minutes. And so, you know, if the attacker is finding that vulnerability first, we're in a negative territory, right, where we don't even know what's happening, right? We're getting zero days, we're getting attacked. And of course, with Mythos, you know, if you do nothing, you're gonna see a raft of zero days, right? Because you know, these models, this class of models can go find those vulnerabilities. And so live protect is a critical defensive measure to protect vulnerable systems very quickly until such time you can apply a patch. And so the idea is that we would put a shield out and a patch out at the same time, right? And so you, if you can't apply the patch, great, go apply the patch. If not, we can provide shielding for you, right? And so that's our live protect for our Cisco products, effectively. And the second piece then is the thing that we're we are working on now is how can we help that from for open source. Right. And again, many of our large customers, as I mentioned, have thousands of the open source applications. Some of them are old, not patchable. So how do you also protect those? Well, there's compensating controls or segmentation, there's WAF rules, you know, things you do with the firewall, but also shielding. And so we think of offering the customer a range of compensating controls that they can use to protect themselves, with shielding being the newest tool in the tools tool bag. And again, to your point about the futures, I think that this is something that is not a six-month thing. I think this is a long-term way to protect applications on the network. And I think it's going to be something that, by the way, it's our Talos team that's working to build these tools, the same guys that build the snort rules, the ML models, and all of that, working in close conjunction with our technology teams. And so uh very powerful program and something we're rolling out as fast as we can. That's awesome.

SPEAKER_01

Um what questions that I didn't that I did not ask you that you wish I had so that you can convey it to customers?

SPEAKER_00

You know, I think I think the rate of innovation, right? Um, you've been pushing on all of us, right, to adopt these tools. And I'm very proud of our organization kind of being on the front lines of of leading AI-based development, and that's allowed us to really innovate much, much faster. And so I think the the ability to react to what we're seeing in the world right now, the ability to build new products quickly and get to market quickly is going to help us be a better partner to our customers. Yeah. Right. And we think that we can be an incredibly strategic partner to them because we're we own the network, because we're in the infrastructure layer, because we can tie security into that, that we can be an incredibly important partner to our customers, especially now in this AI era where the controls need to be rethought. We have to think about stopping these things much earlier in the process. By the time it hits the sock, it's too late, right? And so that means embedding controls down on the fabric of the network. And someday in the silicon too.

SPEAKER_01

Yep, yep. Um I just want to let your team know, and you know, that I think you folks are doing a fantastic job. Thank you. And keep uh keep doing it. Um the reality is is the mission is so uh timely and it's so important for the world to make sure that as we have this massive upsurge of AI, that we remain safe as a species, and we remain um, you know, that that there's not unintended consequences that can happen that can really threaten um uh the safety and security of humanity. And I think you're you and your team are doing a fantastic job with that. Thank you again, and I'm sure we'll have many, many more conversations like these to keep sharing the new innovation that we have in the payload coming up.

SPEAKER_00

Well, thanks to my team who's does all the work. They're the ones who deserve the credit, so thank you very much.

SPEAKER_01

You and I are both overhead, man. Yes, we're overhead, that's right. So uh you're a great overhead to have. So uh delighted to have you on the team.

SPEAKER_00

Thank you, appreciate it, appreciate it. Take care. Thank you.