Nobody is coming to protect you
Welcome to another episode of Cloud
Unplugged.
It is a new season for us,
a new fresh start as well.
New episode in a new season after a
bit of a summer break.
Still focusing a bit on the news,
but we're changing format a little bit on
basically what is it all meaning to people
that run the technology teams in
businesses.
And that's basically what this episode is
going to focus on.
There's a lot going on in the industry.
It's moving really quickly,
but keeping abreast of it,
getting some useful tips and facts on how
to implement or protect the technology
business is obviously key.
Today,
we're going to be talking about the news
around Dario Amede, CEO of Anthropic,
saying that it needs to be regulated.
AI is moving too fast.
There isn't enough structure of regulation
around it, around the frontier models.
some people are saying hey you know is
it a pr stunt as usual but actually
whether or not he does think it's
regulated the time it's going to take to
get regulated is obviously unbound
government doesn't move fast so
what are people doing between now and the
policies arriving and the regulation
arriving if it even ever does and what
does that mean to your company and your
business and the security posture of your
company so
it's not just that that we'll talk about
we'll also get into who owns it where
does it really sit is it a separate
segment of your business is it really
cross-cutting how do you organize
yourselves around it from a high level but
essentially what strategy should you have
for ai and where do you even begin
on this topic because it is so complex
it is moving quickly it's very hard to
keep on top of um and we're here
to help everybody and give our advice and
opinion based on our experience so salmon
right should we get into the to what's
been said about the regulation and start
to to get into it what do you
think around it then the
The PR stunt,
non-PR stunt news of getting it regulated.
Yeah, I mean, first of all, season four,
new season, woohoo!
We're into the new one, but...
CEO of Anthropic says,
let's slow everything down.
But this is nothing new because you might
remember a few episodes ago,
a couple of months ago,
we discussed that a bunch of engineers
from OpenAI and Anthropic,
they signed a document saying we need to
slow this down.
And eventually, after a few months,
we've heard all of them.
You know, you've got Elon Musk,
Demis Hassabis from Gemini and Nadella.
They're all backing this stuff.
we should basically slow down the building
of these frontier models.
Now,
to people who are using these frontier
models, what does it mean?
I mean,
this is regulation at Frontier Labs model,
right?
I know we call them Frontier Labs or
whatever you want to call them.
But the important thing, I think,
for us who are using these tools day
to day in our businesses,
in our organizations,
is that at the moment,
you've seen all this news come out of
model hacks, a certain system.
There was a breach somewhere else that
these models were able to do really
quickly, find vulnerabilities,
find exploits.
Imagine, of course, you know,
it goes without saying,
we've seen the models that were here two
years ago to the models that are today,
they are much better at whatever task that
we're given to.
So if the development of these models
keeps going at the same pace,
that means there's going to be more chaos
if we don't have control over what's
running.
So I think from our point of view,
where we have to implement it as
organization,
people who are
decision makers is to realize that yes,
they're saying it could be a PR standard,
it could not be,
it doesn't make any difference,
but the models today are this good.
So in six months time,
what is it going to mean for us?
That means we need to put into action
the things that we have to do in
our organization from security point of
view, from operations point of view,
that
if anything does happen,
we have a bit of confidence in how
data is governed,
how our applications are deployed,
all of that stuff.
So I think that's the important point out
of all of this, in my opinion.
Yeah,
and I guess there's two facets to it,
isn't there?
There's the big dogs.
You've got people who are...
People running the frontier models,
but then you also have the open-weight
uh models which obviously you know you can
basically you've got enough compute you
can you can host an open weight model
um you'll have jurisdictional issues right
so you know there's different legislation
in different countries it's a global
element to it so um you know it's
a very complex thing so even if
were to regulate um or companies you know
decided to buy in it's not necessarily the
same as a regulation and global regulation
is going to be very difficult which leaves
everybody in a situation where it's about
time um and that could take you know
a global implementation of regulation
could take an exceptionally long time for
businesses
And so you've got to do something you
can't necessarily assume.
Well, there's two things.
Whether you're adopting it or not,
others are going to be.
And that might leave you exposed because
like you're saying,
um it's very easy to find compromises in
systems you could be running a model on
you know your own compute it doesn't even
need to be a model necessarily and you
could be attacking and and finding ways in
That's kind of number one.
Number two is it might not be just
in the traditional sense of cyber attacks.
It could be social engineering.
It could be that AI is calling you
up and making it look like an employee.
It could be that it's their voice that's
calling you up.
And a lot of attacks can be financial
gains are through social engineering.
So you've got to have that problem as
well.
And a third one is if you are
not necessarily controlling the adoption
for yourself,
you could have uncontrolled adoption
inside of your organization where people
are using it anyway.
And you might not know because to you,
you've decided that you're not.
And there's a policy and a piece of
paper,
but that won't stop people's behaviors.
And so obviously you've got to think that
through on like,
even if you're not deciding just yet,
it's probably already there.
And the behaviours of individuals nowadays
are very reliant on it in their day-to-day
lives.
People are getting very...
climatized to the value and the benefit of
AI, even personally,
as well as obviously now wanting to use
it in their work to make them more
effective and efficient.
You know,
it can solve problems faster than they
can.
It can make them more effective at their
job and therefore they'll want to use it
to make their life easier.
And so that's not going away just because
you think that you're not ready as a
business to adopt it.
So there's a lot of things going on.
You got anything to add to those things
or do you?
No, I agree,
especially by this uncontrolled adoption
that can cause a bit of a problem
as always,
like leaking of secrets or whatever.
So that's why organizations have to also
think about how they can, one,
allow this controlled adoption of these
models in the organization because
the better integrated these models are
with your existing systems the better
responses and uh you know like improvement
in your systems you'll get so if for
example if you have a knowledge base
article so any knowledge based system that
has information about things that have
happened in the past as an insurance
company there's some of the claims that
came in what was agreed so
Yeah,
something like this is kind of useful.
So I completely agree.
It doesn't matter what happens to the
frontier labs.
As you mentioned, John,
the first one is the big dogs,
the frontier labs.
What happens to them doesn't really make a
difference.
And even if you don't,
Even if you don't decide to use LLM
models in your organization, others are.
So they will find ways around it.
We've seen a bunch of examples just
yesterday.
An OpenAI agent managed to hack an
Australian government website.
This stuff is happening all the time.
Yeah, there was some statistic on...
Is it like,
I can't remember who it was,
but basically there was some exploit where
it did
think it went through forty eight
different countries obviously i suppose
systems you know very easy it's ip address
not anything particularly complicated but
went through forty eight different
countries and managed to compromise four
hundred and forty servers across three
hundred and ninety five organizations in
about four hours um yeah now that would
have taken you know depending on what it
was a huge resource group
You'd have to be a controlled effort of
individuals to have achieved that and a
very coordinated time bound, effort bound,
resource bound activity to have achieved.
And if you can do the same thing
on a whim on your own at any
point in time and achieve a very similar
thing that would have taken maybe a group
of thirty people or a huge amount of
expense and cost and resource cost.
And that's kind of worrying.
It puts everybody in a vulnerable position
if it's that accessible and the bar for
entries,
the barrier for entry is so low to
achieve something that's, you know,
quite substantial.
But I guess before we get into the
nuts and bolts of it all,
I think just more from a,
there's probably just two things that I
want to add on the strategy side.
I think for me,
the things that I'm seeing most of is
one,
people are trying to see AI at the
moment as its own individual thing.
And so, you know,
and even my language thinking about it and
how we talk about it is it sounds
like it's one universal aspect,
but the universal aspect we're talking
about
know by accident tends to be the the
inference you know the model itself yeah
but actually the bits around the model is
really where the challenge is you know how
you're adopting it what tools are using it
and those tools and that landscape is only
going to grow you know so the connection
into the inference itself i.e the power of
the model which kind of just sits at
the heart of things um is not the
sole problem and
Also trying to define a strategy for AI,
which is obviously good and you should
have a strategy,
is to kind of try and focus on
weaving it into the business as a whole.
So it's not an isolated thing that feels
like it's owned by one specific individual
or engineering team or a department.
actually ai's in every single technology
you know it's in teams and you can
integrate into slack you can have it in
your your drive and your confluence you
can have it in jira it's it's highly
integrated so you've got to think through
operationally every single aspect of the
business not just thinking of it as a
technology problem um and i think the
second bit of that is
It's putting a lot of pressure on
businesses that are having to think
through scaling challenges even though
they're not actually technically scaling.
Normally you would hit these problems of
governance and policies and how do we give
people managed devices that are going to
join and how do we make sure you'd
have to think through that level of
maturity over time as your business is
maturing.
But now you're kind of like forced to
be mature really early on because the
level of scale people are operating at,
you know,
in terms of like the security posture,
the identity,
the access is very exploitative on the
fact that it's like you've suddenly hired
three hundred people into your business
all of a sudden,
even though you kind of technically
haven't.
But it's putting pressure onto the
foundational aspects of a business on how
you operate and the operational processes
and how you behave, how you patch,
how you upgrade.
All of the things now are now getting
a bit under the spotlight and constrained.
And the risk is if you're not thinking
about them properly, i.e.
recognizing that,
you're just seeing it as a tool that
can just get added and not really noticing
the fact that it's it's actually it's not
really a tool it's it's got autonomy to
it it's got agents to it and those
agents can be in vast numbers all having
access to your systems you wouldn't
give three hundred devices without
thinking through the level of access to
three hundred people that would join the
business you'd be really like you'd be
really thinking about it in a much more
controlled fashion and you'd be worrying
about the level of control and how we're
going to organize ourselves to support an
additional three hundred people all of a
sudden um who's going to have access to
things and be doing work on our behalf
and the type of work they might need
to be doing and what access they might
need to do that work etc etc and
it's no different
Sorry, I know I'm kind of going on,
so that's just a bit of framing.
I don't know if you've got things.
No, I do.
Yeah,
I think I need to clarify a few
things because you mentioned quite a few
useful things.
So let's start with the first one.
You were saying that
AI is not a new thing.
I mean, it is,
but in terms of organization strategy,
are we saying that you don't need all
of these companies nowadays?
Oh, we need a chief AI officer.
You don't need a chief AI officer.
Is that what you're saying, John?
Let's start with there first.
The responsibility sits with a CISO or a
chief data officer or a CIO.
Is that what we're saying?
That they need to consider this?
You need some accountability.
From a general perspective.
But as the accountability isn't one thing,
it'd be like saying,
which is not necessarily wrong,
but you've already got technology in a
business.
You've probably got a chief technology
officer.
AI is just another piece of technology.
It could be that they also have to
be responsible for AI and other
technologies, right?
However, obviously how you splinter out,
it's not like technology is one thing,
the same as AI isn't one thing, right?
And so therefore the accountability start
to diversify around like, well,
workplace AI maybe is in a different team
to say, coding assistant AI,
which might sit under maybe the
development practice.
how you start to divide up the
accountability of AI adoption is no
different to how you'd think about it
through just normal technology adoption
and where those things sit.
And it should be underpinned by that.
It's more what I'm saying, I think.
yeah and i think i think the important
thing to hear is to note here from
my opinion is that usually if there's
anything to do with data or if there's
anything to do with security you know the
buck stops where our chief data officer
the cso chief information security officer
well i think when we say that
accountability sits across multiple teams
It becomes a little bit tricky,
which I agree because it can't be that
because you're bringing in yet another
tool into your existing organization
anyways.
I don't recall a tool.
So I think it's going to be a
little bit tricky to figure out who is
actually responsible for all of this at
the end of it.
Maybe it's the CIO or maybe it's the
CTO.
But because, you know,
I always find it when nobody owns it
and like, oh, it's shared responsibility.
Things just fall through the crack because
people assume, oh,
I thought the CDOs covered this,
how the data is actually being managed for
AI.
They were like, no,
I thought the platform area is supposed to
cover it or the security cover it.
I think there's no answer for this.
It's just, I'm just posing.
I don't know what you see and how
organizations are dealing with this at the
moment or is everybody trying to figure it
out right now?
Well,
I guess I think understanding it first is
more important probably than more than
anything else.
I think it's predicated on how your
business is already structured.
So it just depends on how you're
organized.
Okay.
Maybe you decide that the current CTO is
accountable for AI and that's fine,
but being accountable for it probably is
more on who owns really the strategy
behind it as opposed to who's owning the
specifics of a very specific bit of AI
would be different.
Now,
they obviously should work with business.
to understand what it means,
that might mean you need a chief AI
officer if they've got more experience to
bring in because that's what you need
because you don't necessarily have that
experience or you might outsource that
experience and influence
you know, that the CTO and CIO or,
you know,
it's whatever you decide is right.
There isn't really one size fits all.
It's recognizing the constraint of the
fact that somebody needs to really think
it through properly and own the strategy
about thinking it through about what it
means to the organization.
from many facets that we've already
covered.
So basically what we're saying is with AI,
the risks of attacks or any of this
have increased a lot in the last few
years that we've seen,
and it's just going to keep increasing.
more so you need to have a strategy
where somebody owns it doesn't matter who
owns it of ai adoption let's say and
we we are saying that the the
responsibility needs to be divided because
it falls under all the areas under data
under security and the platform the
development everything it falls under all
of them
So that's where we've got so far.
Risks are going to keep increasing.
And in terms of adoption, you know,
you mentioned like controlled adoption and
uncontrolled adoption.
So we talk about, you know,
that is what we need to address.
So, John,
you as CEO of an organization or a
CIO,
what is the first part thing that you
would do when you need to tackle this
issue?
So I guess one would be.
I guess there's two modes.
I guess one is trying to figure out
if the business is wanting to use AI.
We talked about controlled adoption and
what that means.
And irrespective of whether they are or
they aren't,
you then probably need to think if they're
not,
then there's obviously the uncontrolled
adoption lens,
as in you then need to have a
strategy for that.
I think irrespective of whether it's
controlled or uncontrolled,
You kind of have to assess it.
You need to properly understand.
And this shouldn't be some really over the
top, long winded, multi month assessment.
You should look at probably your existing
capabilities.
and think about them in terms of like
a maturity score you know in the same
way if i looked today at any business
and i put it to the lens of
i'm going to hire one thousand people in
two days what does that mean how does
how do our current teams processes and
approaches support that
And I think if I then looked and
was like, well,
actually our identity system or our
current cloud platform,
actually it's not really in a great
position to support that amount of
activity or it takes us a long time
to securely onboard an individual to know
that they're safe.
That would normally take two weeks.
then I'm kind of getting a feel for
an immature function on the time it's
going to take.
And so therefore,
I start to just look at it holistically
and be like, right,
there's areas of maturity we really need
to focus on that are more important than
others.
And so some might be really good and
some might be not so good.
Maybe your observability of knowing what's
going on
across the business through a security
lens?
Is somebody accessing things they
shouldn't?
Do we manage that from a process
perspective well?
Do we know why that was happening and
do we deal with it effectively?
That's one example of putting it through
the lens of just a scenario.
And then saying, well, actually, we don't.
So therefore,
having a hundred agents doing that is
going to be problematic.
If we don't know it today with one
person,
then having a hundred agents doing it is
clearly going to be a bit of a
problem.
So we really need to think that one
through.
Right.
So, yeah,
I guess that's just kind of being
pragmatic and objective and, you know,
and just assessing the risk and then
putting a plan over that risk.
So that'd be the first one.
yeah so you you basically are saying that
if you can't put a number on the
process today don't touch it with ai yet
right so and you pick a workflow or
pick a process and you have a number
this is how long it takes for you
to do it via such and such process
um and you try and improve it just
to see how it
Exactly right.
How it works with AI, right?
So you need to have those metrics in
place.
Exactly right.
That's for controlled or uncontrolled,
i.e.
you're trying to roll it out or people
might be using it.
The third one though,
which is a little bit more marginalised,
is the external risk,
and that's much more from a traditional
security lens.
So we're not adopting it,
and maybe nobody is using it in an
uncontrolled way.
Let's just hypothetically say that's true.
You're in a very good place.
Nobody's using it across the business at
all.
There is absolutely no risk internally.
What about the external risk?
Are we patching, upgrading?
How long does it take us to get
security vulnerabilities remediated to not
leave us exposed?
Is our security testing good?
Do we understand the risk?
Is it automated?
What's the external exposure that we have
know today when there's now new
capabilities that could potentially target
us in an uncontrolled way or processes
around phishing attacks or social
engineering do we have that covered as
well could somebody dupe someone into
thinking they're an employee even though
they're not
Because it sounds convincing.
Could Salman ring me using his voice and
he's saying, hey, John,
I'm on the podcast.
I'm locked out of my email.
I need to reset my thing.
We're about to record one today.
And I believe him.
And I'm like, yeah, sure.
I kind of reset it.
And then it wasn't really Salman.
And I'm sat on the podcast.
No one joins.
And I'm a bit bamboozled.
But meanwhile,
somebody's kind of hacked into our
company.
Yeah.
It was Lewis's grokbot.
That's all I'm going to say.
Exactly.
It's the goddamn grokbots that have
compromised me again.
But yeah, do you agree with those things?
I guess from a...
I completely agree,
and this has always been true,
no matter AI or non-AI.
Before AI,
everybody used to talk about automation.
If you didn't know how long this process
used to take before you automated,
how do you know if you've made
improvements or not?
And so I completely agree on that.
So once you've got the
Once you've got the baseline as to,
you know, you've done your assessment,
you figured out what process you need to
pick.
And as you said,
it shouldn't be a long winded assessment
process.
Really quickly figure out what you need to
do.
What's next, John?
So what are we doing after that?
So I guess just depending on the output,
because I'd run up all three in parallel,
I wouldn't necessarily do it.
So I'd go to the business and be
like,
do we have a plan for AI over
the next couple of years?
And when is it going to begin?
And what does that look like from a
business perspective?
um have we got uncontrolled access and
let's do an assessment on it anyway
irrespective of anything like how are we
sat internally and what's our external
situation and i'd have a report on all
three that very light touch not too much
i'd feed that into obviously then an
overall strategy for the organization and
i'd have probably a prioritization on
general objectives of the business and how
we're going to meet those.
And probably the controlled and
uncontrolled view would be weaving
together on a timeline of our maturity to
really effectively adopt it.
I guess where those immature areas are,
I'd be kind of obviously highlighting on
the kind of risks today that we might
just have and
And I guess from an investment
perspective,
you then need to decide on where are
you investing that money?
Are you investing it to protect your
current assets, i.e.
we feel more exposed whether we adopt AI
and grow or not because there's a risk
that some event could happen and bring us
down and maybe we weight that investment
as higher than actually growth.
Or it might be that you're waiting the
growth investment to be way more and
therefore becomes more or less about your
external positioning,
but more about actually how you adopt it
safely as a business to grow revenue.
But you need to present that back to
the board and the CEO and others in
the company that can kind of make those
decisions on where to place the money and
where to place the financials.
So I guess you're in more of an
investment calculation on how are we going
to look at this from a
through an investment lens and where we're
going to put the money.
And then I guess you're then into then
more of an actionable set of things
underneath it from that point on.
I think this cost and value is very
important.
You might remember from April,
this going back to April now, John,
the CEO of Uber came out and he
said that, well,
we burned through the whole budget for the
whole year in April.
But I can't tell you if there's a
single feature in production that was
built using LLMs.
So this is, if Uber can do it,
Everybody else is also.
So cost and value.
Again, John,
I know this is going to sound a
bit weird,
but this is something we were always
doing.
Don't put technology for the sake of
technology, right?
So what is the cost of this technology
and what value is it going to bring?
Only then implement it.
And this is even more important today with
AI than it was back in the day
because it's very easy to burn through
your tokens.
It's very easy.
Pick a slightly different model.
Tokens are gone.
Exactly, yeah.
Exactly right, yeah.
So fair enough.
yeah i think i think that goes to
the on the controlled aspect if you're
starting to roll it out you know you're
going to need some cost uh association
with whatever's going on with ai on the
inference on the inference element i guess
from a technological perspective which we
can come on to separately maybe another
session and we have done a bit of
a high level there are obviously many
pillars
that you've got to cover.
It's not just there's inference in a
platform that's there today,
getting access to the inference,
the model itself.
There are tools that connect into the
model.
Claude is one.
Teams is another.
They are connecting into the inference,
and it's then responding to people.
And people are using that tool as the
proxy to the inference.
And so how you're thinking from a platform
lens as a business on how do I
govern the association of that inference
for any tool, you know,
is obviously an approach you might want to
think about so that actually how any tool
gets to that inference is somehow
governed.
It doesn't matter where it's coming from,
what it is.
I need to make sure that something's in
front of it irrespective and it can't
bypass that.
And I've got full transparency and
control.
That's probably like from a very
simplistic lens how I would be thinking
about it.
So you're saying that the control should
not live in a PowerPoint presentation that
somebody's made,
but should actually live in the platform
as a policy.
So genuine deterministic policies that the
component can't bypass.
We're not talking about technology at the
moment,
but organizations can do this
by various things.
You can use a model that's running in
Microsoft Azure, Foundry, or AWS Bedrock,
and you can put in all the controls
that you talk about,
filtering of the prompts,
what permissions it has for the agents
that are running on those models,
what permissions it has,
what ownership it's got,
what access does it have,
what the SLAs are for ingress, egress,
patching, all of this.
Yeah, fair enough.
That does...
that is important yeah exactly you
wouldn't you wouldn't want to have five
hundred doors to your office building that
anybody could come in and out of at
any one time and then somebody asks you
who's coming in and out of your office
you know well i've no idea i've got
five hundred ways in um so i haven't
got a clue who's in and who's going
out and no one seems to know so
obviously the sensible thing would be
don't have five hundred doors maybe just
have the one and maybe govern it with
a pass and you can keep track of
who's coming in and out the building and
you're gonna know and it's no real
difference so you know in a simplistic
sense you know it's just kind of there's
a little bit of pragmatism common sense in
it is like obviously you wouldn't want to
be in that situation so that's probably
just as a high level some something to
think about but i think you still have
to look at it through you know how
you how your processes and policies are
working um
And there's no point just having a
generalist AI policy.
There's no point writing,
but obviously start there.
That's good.
It means you're thinking about it.
But unlike a human being,
who has an employment contract with you
you know an ai agent doesn't it there's
no awareness of your policies as a
business you can't fire an ai agent and
even if you did i'm pretty sure it
doesn't care um and so there's no
repercussions like there is maybe a human
they lose their job they can't pay their
bills there's ramifications to those
things but that when you start to get
into levels of autonomy
which is obviously the whole point of
agents,
which is what you need to think about,
there isn't any real accountability for
them that you can really control.
So therefore,
it has to be through a technology
perspective.
And it can't be that you put that
pressure on an individual because they may
not be a technologist.
um and therefore they could be running
things without any real awareness of the
level of autonomy that agent really truly
has and be totally blind to that um
but be governed by a piece of paper
somewhere in the business saying well you
should have known somehow um about
something that's quite complicated that
maybe use their access to do something so
you know really you have to think through
each level of maturity your your
processing policies but then make sure
that you're thinking
as a layer of like, okay,
how is this going to impact our current
technology today?
Where are we starting that assessment?
Obviously, you've got it back.
And then how are we looking at that
from an adoption perspective?
You mentioned cost controls,
but security identity.
You know,
how do we manage that for everything?
And you then need to go through the
process of seeing how we're going to
support this rollout exactly to know that
it's governed in the end and that actually
we have a sense of control and
auditability
That's totally independent to how you're
using it in your business as an
application level,
because that's even more involved than
probably using it for general day to day
use.
And so, you know,
you're then in a layer deep into the
application area,
which is what does it now look like?
from a business lens when I've got agents
talking to customers is a very different
thing to people doing their jobs using
agents.
And so you need to obviously then start
to roll through again in a similar way.
What does it look like now from a
business logic and a business risk and the
data surrounding that?
And then you're into very specific aspects
as well.
They're like another layer.
down from a technology lens and then
what's the strategy for that um and so
there's is it's a bit like an onion
you're kind of unraveling the layers
exactly so it's all over all very layered
so you so you basically are saying that
ai strategy is just a name for having
your data security platform and operating
strategy actually in place
For a world that no longer moves at
human pace, right?
I think that's the main thing.
And nobody, as before,
nobody's coming to protect you.
The attackers are already using this,
and so is your competition, right?
So those are the two things.
So I think what I would take back
from this discussion is that
If I would go back to my team,
I'd be trying to find out,
in terms of attack surface,
is what internet-facing software do we run
that nobody owns, perhaps?
And how fast can we ship an emergency
patch?
That could be at a platform level.
That could be an application level.
Who owns our AI costs, right?
And could we trace a spike within hours?
Because these agents can also be exploited
to do whatever they want to do.
But I think the most important thing that
you mentioned at the beginning of the
podcast is what is the baseline number
before we deploy anything?
so that that value that you should get
from i think that is perhaps the most
important thing what's that baseline
number that we need to work on to
improve the process that we're trying to
improve use of ai which because we just
don't want to burn everything so so ai
strategy is just a name for having the
rest of your organization in good order
exactly right yeah and it's just you know
they're very simple questions that you can
run through scenarios that's why the
assessment doesn't need to be deep because
if today if i asked a question saying
if somebody spent
you know,
a hundred thousand pounds on inference,
would you know who and why?
You know, very simple question.
If somebody today spent a hundred thousand
pounds just in cloud,
let alone the inference,
would you even know today and why?
If somebody accessed something they
shouldn't,
it went out on the internet would you
know today and why right and they're very
simple questions because what they're
doing is challenging your maturity about
how you operate today and then what it
really means to something that's going to
exploit that weakness at a very fast rate
like you're saying um and therefore you
start to get a sense of you know
where you're really stacked and the
processes that might be in place um but
yeah that that that's kind of the main
the main uh
fundamentals, I think,
on how to think through the strategy,
really.
And I think in future episodes, John,
we'll probably pick one of these areas and
talk a little bit more in detail in
terms of the data,
in terms of the operations.
terms of the security and how you can
help yourself to implement some of these
practices so you can adopt in a faster
and more secure manner yeah exactly right
and just to kind of reiterate people do
need to do something there's no point
assuming that um
by magic government's going to step in and
do a wonderful thing at a global level
and all of us are going to do
the right thing in the meantime.
And the world's going to unite, you know,
put the brakes on and make sensible
decisions together.
I think that's very, very unlikely.
So in the meantime,
it's probably worth thinking through,
you know, not in like a doomsday aspect,
but it's there, it's going to get used.
What does it kind of mean to us?
And get ahead of it.
ASAP really would be my advice.
Cool.
Cool.
That was insightful, John.
But yeah.
All right.
Well,
like we're saying on the next episode,
we'll go deep maybe on operating models or
the security side and we'll start to pick
at something like an aspect of it all
as well so we can kind of start
to kind of dig into what it really
means in a bit more detail.
But hopefully that was helpful.
Thank you.
See you next time.
Creators and Guests
