The biggest kind of shift in your thinking should be stop looking for a zero trust platform. I know that probably sounds weird, but this is exactly the right kind of mindset. Stop looking for hammer, or if you are surrounded by nails, or the other way around. I should stop looking for nails if you are carrying a hammer. You are about to solve a major architectural problem. It's not like you have an outdated tool. It doesn't work well enough. You want to throw it away and replace it with a new one. This will never happen.
If you are honestly looking for a zero trust platform, it means that you are actually thinking architecturally. You want to kind of redesign the entire way your digital business is working. And your goal is to make sure that everything works the same way. Like to follow the same policies, listens to the same risk signals, make the same decision. Or it is like broadly similar across different environments. Welcome to the Kupinger Coal Analyst Chat. I'm your host. My name is Matthias Reinhardt. I'm analyst and advisor with Kupinger Coal Analysts.
My guest today, and I will have a long intro, first of all, to welcome in my guest today is Alexey Balagansky. He is a lead analyst with Kupinger Coal Analysts.
Hi, Alexey. Hello, Matthias. Great to be back. Great to have you back. And that's, of course, because it's you. And second, because we are actually back with a topic that we started covering earlier this year in January. And we did an episode at an unusual time in our research process, because it was at the starting of the research process. And we talked about the topic, what's behind that, and that you are starting the process of doing, on the one hand, a bias compass and a leadership compass in that segment.
And at that time, we really discussed an evolution of a market that you expected, that I expected, and that we today want to verify to test drive now that the reports are finished, done and published. We want to talk again about zero trust platforms, and especially if all our expectations went out right, and ideally what a buyer should do.
So, first of all, CTP, zero trust platforms, has everything worked out the way that you did expect it then? Well, first of all, Matthias, you are right. It was kind of a new topic for us. We've never done it before. But usually when we are tackling a new topic, like we are starting from a very small pool of vendors for products, for example, because zero trust, it's like complete opposite. If anything, we have too many vendors to choose from.
And the real problem is not how many quote unquote zero trust tools you have at your disposal, but how well can they work together to form a coherent platform. It was the whole point of us having to establish very strict criteria, what a zero trust platform actually is, and then reaching out to interesting vendors.
And then, of course, we spent basically six months talking to them, listening to them, looking at their products, doing write-ups, and finally the paper is actually published today as we speak, or probably last week at the moment of you listening to our recording. So, yes, it took us six months and the results are in, and they are pretty interesting and even somewhat unexpected.
Okay, but what did we expect back in January? What was our expectation? Zero trust platforms has this P in it, it's platform, it's not product, service, tool. So it's really platform. What did we conclude in January for anyone who missed it way back then?
Right, so first of all, recapping the same statement, I lost count, I repeated how many times, zero trust is not a product, zero trust is a strategy, is a set of very basic principles on how you should organize your entire IT, if you will. And back in January, we discussed what zero trust was for over a decade, what went wrong, what went in the wrong direction, and how should we fix it, if you will. And we defined four basic requirements, what a zero trust platform should be like. It has to combine, first of all, universal access enforcement across all of your systems ideally.
Second, continuous trust evaluation, not just a single log-in check, but again, ideally, real-time, at least at every transaction. Third, intelligent segmentation of your entire infrastructure, simply because at the current scale, you cannot just create every tiny bit of a standalone system. You have to group them into logical segments, if you will. And finally, give you a unified analytics view, that's proverbial single pane of glass. I hate the term, but it's one very crucial requirement. That was our expectation set in advance.
And of course, the biggest question is, do we actually have enough solutions and enough vendors that deliver that problem? The difference today is that we can actually talk about specific results and our findings after six months of research. We rated 20 vendors against those criteria, and we covered almost 20 other vendors who, for whatever reasons, could not participate. But we still consider them important enough. So let's see whether our predictions were true. Yeah.
And the first thing that really struck me is all the capabilities that you just described are somewhere in other categories that we previously covered. But you took the twist and said, OK, let's look at it as a Zero Trust platform to cover all the four criteria that you've mentioned. So I would have expected that the usual suspects, though, the tools that are covered in SASE and SS Zero Trust network architecture, that these vendors also appear here. And they do not only appear, but they are in the upper right corner as leaders.
And that would be, usually we don't say names, but since I say a lot of names, I think this is allowed for today. That would be Microsoft, Cisco, Teleport, Broadcom, AppGate, Illumio, and all these vendors that are probably well known, but they are not where we expect them, right?
Well, yes, that's a key observation on your part, of course, Matthias. And yeah, I guess some people would not just be surprised, but probably actively push back against our findings.
Yeah, this is not what we expected. Like, where is this cable? Where is Palo Alto Networks, the biggest SASE and the TNA and VPN replacement vendors?
Well, and that's exactly our point. Zero Trust has too long been a label. And like every label, it eventually lost its sharp and specific meaning. And now it basically means anything you want it to mean. And of course, every vendor treats the definition slightly differently. This is why we have, again, outlined a very specific set of expectations from a Zero Trust platform. And unsurprisingly, at least to me, a Zero Trust platform is not the same as SASE or the TNA platform. Simply because it has to do more than that. We rated architectural depth.
And again, the most important criteria is that the platform should be able to enforce policies in a unified way across systems, across types of identities, across clouds and on-prem and endpoints and AI agents and whatnot. A platform is not just a tool. A platform is something which gives you a combination of breadth of coverage and depth of sophisticated functionality. And with that, there's also requirements in place.
Yes, the expectations of who should have emerged on top have changed. And yes, I'm not sure whether we are allowed to name every overall leader now. But some of those leaders are pretty large and respectable. And I would say even expected to be there. Some are very specific, specialized vendors which only do one or two things but exceptionally well and are able to kind of do the fabric thing. That is to collaborate with partners and other third-party providers to expand their capabilities in a way that it works on a bigger scale, on a larger coverage base and so on.
Yes, the overall leader in our finding was Microsoft. This is probably the only vendor who can deliver both massive scale, pretty wide functional coverage and, well, respectable market value. Unsurprisingly, they have emerged as the single highest rated overall leader.
Again, in the same list, we have companies which are large, like Broadcom, for example, or Cisco, and also smaller like Illumio, Netco, or even a pretty specialized companies like NetFoundry. They have all been recognized as overall leaders. Does it mean that they are equally big or equally capable or like replaceable in your next procurement decision?
No, absolutely not. This is the biggest key takeaway for you. You cannot just take a list, pick a random number, and decide on that number. You have to actually look behind labels, understand your challenges, your risks, your requirements, and find the best fitting solution. This is exactly what our research is designed to deliver.
That also goes hand in hand with the way that we apply our research and advisory to understand what is actually the key set of requirements that a customer has, and then to identify the right solution out of these obviously different types of leaders, although they are all leaders. But to go back to that, a smaller specialist that follows your idea of a platform, combining all these capabilities into a single firm fabric, a small vendor can outrank a global, sassy vendor when they are not implementing and following that platform approach.
Well, let me just give you a quick recap of what we actually do in our research. What we published today at the moment of recording this is a combination of two papers. One is the Leadership Compact. This is our flagship research format where we basically measure the functional capabilities, the rate of innovation, and the market presence of all the vendors we have reached out to and decide who can be recognized as a leader. The companion paper for this is our Buyer's Compact, which basically tells you exactly how to use the Leadership Compact to make the right decision.
It would give you the different use cases, all these types of tools or platforms, outline the key selection criteria, architectural considerations, and even give you some hints on what you should be specifically asking each vendor to understand how well they would fit your requirement. And this is exactly where we come to this major, or you can call it an unexpected twist, or very much expected realization that there is still kind of a gap between what we expect from a zero-trust platform, what they can actually be used and which use cases they can cover.
And this is why, again, there is no single solution which can do everything. And even Microsoft's solution has its limitation, even though they're probably smaller than others. But if you are only looking for a very specific use case, for example, embedding zero-trust directly into your application layer instead of infrastructure layer, or if you're specifically in a dire need of an air-gapped deployment, and unfortunately, very few vendors actually support that, or if you're specifically targeting non-human identities.
And this is another huge gap, and I think it probably was a separate discussion. So my point is, without giving you specific names, that 20 names in the report, or like nine leaders, doesn't mean that you have nine options to choose from, or 20, or even 39 if you count vendors to watch. I mean that we are giving you a guide with a list of rules how to follow it, and it's up to you to understand what is it exactly that you're looking for, and we will support you in making the right decision. You're right. If you need more information, if you have more questions, talk to us. We are happy to help.
But this is also the beauty of this tandem of these two documents, the Buyer's Compass and the Leadership Compass. One provides you with the insights into the market as detailed as you just described it.
Now, on the other hand, the Buyer's Compass gives you the right set of questions, the right mindset to deal with these vendors, and to ask the questions that are relevant to you yourself, and to make sure that you get to the proper solution. If we go back to January, even then, and maybe we were even profits way back then, because the topic even exploded even more in the meantime, we all expected that a driver for this platform approach would be AI agents, would be machine identities, would be this NHI term that everybody loves and hates. Were we right?
Well, again, there is no simple answer to this question. We were right, and I guess everybody is right in a way that, yeah, everybody is now talking about AI as if it's the coolest and the biggest thing in the world, which it probably is for a lot of use cases, but it's definitely not the only thing in the world. And unfortunately, it's not even the thing which the markets have already solved. So now that we are looking at the actual findings, and can do some calculations and derive some statistics, I can give you some observation. So absolutely, NHI and AI agentic identity are a huge driver.
This is what everybody is asking for. The question is, do we already have solutions, or do we already have enough solutions to address those requirements?
Well, this is where it becomes complicated. So 80% of the vendors we have analyzed do provide, let's put it like secrets for automated workload. Let's not use fancy terms like non-human identities, they are still operating with machine secrets. This is kind of good enough, but only 40% of those vendors can actually provide a certificate-based identity. That's the way how we usually see real identities operate. It's not just a key, it's not just a secret, it's something more than that. And usually, the industry deals with certificates, right?
But only 40% of the solutions can actually do that natively. This is something to be solved in the future, I guess. One other topic we have discussed many times, I believe, even in this podcast with some of other VC analysts, is semantic layer controls. The key word here is intent. Because whenever an agent is acting upon somebody else's request, there is always an intent handed over, along with some set of entitlements. And the biggest question is, does the current intent still justify the entitlement or not?
This is a hugely complicated topic on its own, both technology-based and from a philosophical perspective. And it is very rare to see, not even a turnkey solution for that, but even a vendor talking about it as an ordinary buyer. There's still very much work in very early progress, if you will.
Still, the problem, of course, is the long tail of both vendors and customers. They still deal with a huge amount of technical debt. We have static secrets, you have long-lived credentials, you have too many permissions issued to agents, and very little oversight over their lifecycle. This is something that has to be figured out. We already know how to do it. This is exactly what we are talking about in the buyer's compass, for example. At least how to ask the right questions to figure out whether the vendor can support your use cases.
But again, this is not something which you would get out of the box or from every solution. So I guess the biggest problem for me, it's quite pet peeve, if you will, everybody is now kind of narrowing this whole problem down to AI agent security. And it's not just security, it's much more about governance. And it's not just about AI agents, because we have so many other types of human identities. And after all, I mean, humans are still there. Even if AI is now outnumber us, we are still there.
And it's enough to have one rogue human to break your entire AI security, if the AI security is the only thing you now care about. So the marketing is still way ahead of the real architectures. And this is where, again, I have to remind you, stop looking at labels, zero trust to label. Look for capabilities, look for coverage of your specific requirements.
Of course, again, do not just think about access management or security or government or compliance, think about everything. And try to make sure that you have at least common visibility across all types of identity, not just AI. And I think especially this AI agent, AI identity topic is something where we are also still in parts are lacking standards and interoperability and just common approaches, best practices approaches to deliver there. So the maturity in that area still can grow, but what we expected at least happened.
They are dealing with that topic, but at different levels of feature completeness or maturity. But to be fair, although this is a first time leadership compass slash bias compass, this is nevertheless a mature market because we are looking at vendors who are doing that for quite a while. Where is maturity higher? Where can we say, okay, yeah, these are solutions that are made for creating zero trust security and for creating solutions in that area.
Right, right. You know, I've just recently heard a statement, a motto, if you will, which I think I very much agree with. Somebody told me access is the new identity. Orange and then you black or something like that.
And yeah, this is true because again, kind of identity on its own is of course critically important, but it's not the identity on its own that decides what you can do, what you cannot do at this specific moment, at this specific context and under the combination of very specific condition. This is where real-time access decision happen. And this is exactly where all this quote unquote zero trust platforms are focusing their developments now. Because again, this is a pretty important thing. So continuous authorization is probably like the basic foundation of it.
Like if you only do authorization once at login time, it is not zero trust. Avoid those tools like a plague. Continuous authorization is the baseline and I can report that 75% of vendors we analyzed do that already. To a different level of granularity and or sophistication, but at least they do it. And it's also important to not just kind of do the authorization, but also be able to change that authorization in real time when the signals change. And the biggest question is what kinds of signal you can even connect to your zero trust platform that do influence those policy decision.
Device posture is probably the most common one. If you're accessing some data from your laptop, does your laptop run latest version of an antivirus? Does it have all the patches? Does it have any open vulnerabilities? Is something suspicious happening from the biometric analysis point of view? Maybe it's not you in front of the keyboard, but somebody else. Or maybe it's even an AI agent impersonating them. These are kind of the device posture signal and 80% of vendors we've covered can do that, can integrate those signals. Unfortunately, the cloud signals are a much bigger gap.
Only 40% of solutions can actually do that. And it's kind of strange because again, we can discuss with all those risks in mind, like digital sovereignty and whatnot, whether it means that the most sensitive data will kind of migrate back from the cloud to on-prem or we actually have to invest much more in securing that sensitive data in the cloud now. So we have to be able to respond to cloud signal.
Again, this is kind of still a substantial gap. Oddly enough, I would call phishing-resistant authentication should be another basic requirement, a baseline feature.
It's not, it's still a differentiator. Again, kind of around 85% of solutions do support integrations with our IDPs, like Okta or Entra, but only 60% natively support phishing-resistant authentication method, like Buskeys, for example, even though this has been a standard for years and it has been pushed by multiple compliant regulations. So this has to be kept in mind as well. For more strictly regulated deployments or cryptographic isolation, for example, another gap, less than half of the platforms we've covered actually can provide that kind of isolation.
And again, kind of in the cloud, it's an absolutely key requirement for any kind of or to go somewhere, if you will. So yes, we are on a good track with some areas, like continuous authorization, but that alone is not enough. The more signals coverage you have, the better. And that's still a way to grow. But of course, there are some basic requirements, like a cryptographic isolation is something to keep in mind, especially in this pre-post-quantum era, if you will.
Well, I like that term. Pre-post-quantum is nice.
So, but yeah, this is where we actually are. So this really puts it quite well.
And again, going back to the bias compass, if you are relying on pass keys and when this is a key requirement, then 40% of the vendors covered are out more or less. So this is something that needs to be considered. So asking the right question, although they show up upper right corner, because overall they performed well, that does not mean that all of the upper right corner is suitable for you.
But going back to January, when we discussed that market segment and when we really were not knowing what will happen in the research, now that we know, we suggested or expected or suspected that there might be not a single vendor who actually implements this platform, this, we love that term, fabric approach to get to a solution that rewires capabilities as expected by a customer organization. How did that settle? How does the report settle that? Are there vendors that really have the full picture?
Well, I guess kind of their honest response to this question would be again, it depends, right? This is our default answer. As analysts, right? The problem again is, it all depends on how you initially frame your expectations about what a platform even is.
Again, I'm not sure if we are allowed to name specific names. There are vendors out there outside of this market segment who call themselves platform vendors. Could have built their entire identity around the fact that they have a huge platform of different tools. But if you actually start looking into specific capabilities, you'll find out that they actually have maybe five platforms or 10 or even more.
And they do not actually, or they are not yet fully integrated because the platform was actually a combination of a dozen of recent acquisitions and the work to kind of integrate them into a coherent suite of tools is still underway to say nothing about the real platform. This is why I think Kupingacool has been pushing this notion of a fabric instead. A fabric is on the one hand, it doesn't have to come from a single hand, right? It can be built from multiple vendor portfolios. But on the other hand, it has to be properly integrated, right?
And the question is, can you find a solution in the zero trust platform market, which is like the most fabric-like? And yeah, there are some getting close. As I mentioned, kind of Microsoft is getting there because of the sheer, right, the entire service and product portfolio. They're doing everything. They're doing endpoint security, they're doing cloud, they're doing identity management and whatnot. And they have the ability to combine all those tools in a fairly coherent platform. You also have companies like Broadcom and Cisco have a similar history.
They're just big enough to be able to offer you not just a huge portfolio of tools, but also kind of a sensible, historical, organic, integrated suite or fabric or platform built around, right? There are some smaller companies, Medco probably, one example on those.
Again, kind of, they've grown more or less organically and they have probably not as broad overall coverage, but they do have enough to give you kind of a semblance of a platform depending on your expectations. And again, kind of, if you go even a little bit deeper, if you are diving into specific use cases, you can argue that there can be an application layer, Zero Trust Platform, or intelligent micro-segmentation layer of Zero Trust Platform. Whether you should be able to call them proper platforms, again, that is debatable. This is a terminology discussion, which I am always trying to avoid.
As I said, stop looking at labels, start looking at capabilities. It's up to you as a potential customer to know what is it that you need. And we can help you answer the question, does the vendor ex-offer it or not?
But yes, kind of, we were half right. The market is not there yet, but the market is growing in the right direction. That would be our simple takeaway from that question.
Right, but that also means a change in perspective of the vendors themselves. So not just selling a product, not selling a tool, but understanding that they're providing a set of Lego bricks that can be rewired according to the requirements of individual organizations and many at the same time, but individually. I think that's also a change of perspective within the vendors. But if somebody is listening to this podcast and he came to that position and say, okay, yeah, there are the big ones, there are the smaller ones, there are the specialized ones, I need to ask the right questions.
I am the buyer, obviously the market is uneven. Where do I start now that I have your research in hand?
Obviously, everything I need is there. How do I start?
Well, I guess the biggest shift in your thinking should be stop looking for a zero-trust platform. I know that probably sounds weird, but this is exactly the right kind of mindset. Stop looking for a hammer if you are surrounded by nails, right? Or the other way around. Stop looking for nails if you're carrying a hammer. You are about to solve a major architectural problem. It's not like that you have an outdated tool, it doesn't work well enough, you want to throw it away and replace it with a new one. This will never happen.
If you are honestly looking for a zero-trust platform, it means that you are actually thinking architecturally. You want to kind of re-design the entire way your digital business is working, right? And your goal is to make sure that everything works the same way.
Like, it follows the same policies, listens to the same risk signals, makes the same decisions, or it is broadly similar across different environments. And first of all, obviously, you have to decide which environments you are even going to cover and what outcomes you want to achieve, what are your biggest risks and challenges, or what are your budget limitations and so on. So you have to define an outcome and then you have to kind of build everything around it. What do you want to achieve?
And I can totally imagine a situation where I would say, well, no, the zero-trust platform is actually not right on such a new requirement. Maybe you can do it much easier with a much more specialized solution. Hooray! The low-hanging fruit problem solved. But what should be your next step? If you already know, if you already figured out that, yes, you have a very sophisticated and heterogeneous and multi-cloud footprint, and you already have too many security and identity and risk management and whatnot tools, and you want to consolidate them, it's a completely different story, right?
Because not only you start designing a new architecture, you somehow have to deal with tons of technical debt. So you have to kind of limit your focus to a set of very specific architectural decisions and try to follow them consistently. So I guess continuous authorization is probably the foundation of that, because, again, if you don't have that, the rest is kind of pointless. This kind of continuous authorization, making each decision in real time, it's the whole point of zero-trust. If you don't have that, it's not zero-trust at all.
And again, as we figured out earlier in the age of hybrid multi-clouds and genetic identities and whatnot, any other way is a dead end. It will never work. It will never fail. It will be too dangerous. I remember one slide that I use all the time for years now, since the zero-trust hype started, where I tried to explain the basic principles of zero-trust. And this is, for me, very simple. These are a few pillars, and it starts with identity that is represented through a device that goes across a hostile network.
That then addresses a system, a service, a program, a server, a service to, in the end, get access to data. So on the one hand is the identity, and across all these journeys that they go in the end, we access data. We have not mentioned data right now. So how important is, for this platform approach, data protection? So the final pillar in this, is this part of the platform?
Well, first of all, let me address one word you said before, data, and that's, again, access. And you're absolutely right, because, again, access is the new identity.
Identity, while important, is just, again, just one of the signals, if you will. It's one of the attributes, and access decisions should be made. Other attributes in that decision are, of course, risk signals, and, of course, the data signals.
Because, again, it depends a lot on what exactly is it you are accessing. Is it sensitive customer data? Is it some kind of explosive type of intellectual property? Or is it some test data which expired 10 years ago?
That is, by the way, just one of the signals you can collect from your data. And, of course, data security, data lineage, data governance, if you will, this all feeds into all those decisions. But the final thing in every decision is actually the verdict. What do you do when you figure out if the specific actor is actually not authorized to access the specific data? Should you just deny the access? Should you step up the authentication? Should you do something with the existing entitlements? Should you block and kind of start the silence? There are so many decisions to make.
So many outcomes, if you will. And this is also something which a lot of potential customers forget about. And this is, by the way, somewhat unrelated, but my huge pet peeve is security posture management.
You know, like they usually understand that we will scan your entire environment and we will give you a list of problems. Fine, but what do I do with that list? How do I act?
Like, I mean, if you just tell me my house is on fire and I don't have a fire extinguisher, what's the point of telling me? I need to be able to act on those issues. And you're absolutely right. Kind of data protection is one of those things.
Like, how do I act? Do I mask or encrypt the data? Do I have to immediately inform government authorities that there was a data breach or is there a ransomware attack going on and I have to do something? Should I restore from backups? There are so many things to consider in this.
And yes, they all belong to the same architecture. You cannot just say, okay, we will have an identity management team responsible for zero trust and an AI team responsible for AI data and the operations team responsible for backups.
No, this just does not work anymore. I'm not saying that you have to combine them into one team.
No, but at least you have to combine them into a single platform, if you will. And the zero trust platform is a good candidate for that. Right. So we are getting close to the end. And for those who made it here, and you should, what would be your suggestions if people are hesitant to read the full BIOS compass but nevertheless, if they're willing to ask the right questions? So what are three recommendations that you would say should be in an RFP in that area? What are the top list candidates for that?
Well, I hope you're not asking me to tell specific company names or solution names, because again, that will be very different for every project. But again, if you are talking about the top considerations, and again, I can totally recommend reading the BIOS compass. It's pretty short. And it's exactly that. It's a list of considerations you have to start with. But I guess the most important points would be, well, first of all, again, I hate to repeat that, but what about non-human identities and AI agents? This is kind of important nowadays.
Even if you think that this whole AI is a fad, and it will probably burst the bubble really soon. No, no, not really. Internet wasn't a fad, and automobiles weren't a fad. They profoundly changed the way we work and existed in society, and AI will still be there, and you will still need to do it on a more consistent, secure, and compliant way. And this will probably be much more expensive than today. So it's a pretty important consideration. The second is, how do you deploy it in a composable, kind of separable manner, this whole platform?
Because on the one hand, it has to unify the entirety of your IT infrastructure. On the other hand, it has to comply with lots of regulations and performance and security considerations. So there has to be a separate control plane, a separate data plane, probably running in a completely different place, and isolated. Tons of different deployment points across very different types of systems. And somehow, they have to operate together in a consistent and uniform way to be able to translate a single policy into tons of different policy decisions.
And finally, how do you ensure that this thing kind of stays relevant in real time? Because things change, not just on a minute scale, but also on a slower scale. There will be new requirements, there will be new risks tomorrow, next month, next year. There will be regulations, there will be new types of workloads, there will be maybe even new types of identities. You have to be able to adapt. We are talking about different types of agility recently, like cryptographic agility and whatnot. I don't know if zero trust agility is even a thing, but it probably should be at least talked about.
Okay, this is the end. This was an interesting attempt to look at research before it started, which we did in January. And now it's July, and the research is out there. And looking at the developments and the experiences that you've made during this, by the way, really big amount of work, just to mention that once, that was really interesting. So for the audience, for the listeners, the important fact is both documents are out and published. So the Bias Compass for Zero Trust Platforms and the Leadership Compass for Zero Trust Platforms with their different angles are available at our website.
So of course, this is the short commercial break. These documents are there. You can get them when you are a member of Wikipedia called analysts, and you have a subscription where you can access these documents. If you have any questions around this podcast to Alexei, just leave a message below that video on YouTube, send us a message.
As usual, we are happy and willing to give answers and are interested in your perspective on that topic. So please reach out. Happy to discuss this further. But the first starting point, of course, would be, yeah, the real message, the documents. Before we close down, Alexei, final statements before we go?
Well, just to reiterate, Zero Trust is not something which you can buy and turn on or you can replace. It's first of all, an architectural decision, which depends on your specific requirements and expectations. And only then can you start looking for an existing solution that kind of fulfills your expectations. And we are here to help. Thank you very much. Thanks for your reporting, your research, for the documents, and for being my guest today. Looking forward to having you soon again.
Thank you, Alexei. Thank you. Goodbye. Bye-bye. Bye-bye.