Hey, everyone. I wanted to start by just taking a few seconds to think about where we're at at the moment.
And, I mean, you're going to hear about AI, AI agents every second of every minute of every hour of the next couple of days if you haven't already had that conversation all of yesterday. But, for me, I just reflect on the fact that, genuinely, I think everyone in this room should be probably the most excited people in technology in your organizations right now. But you should also probably be some of the most afraid, genuinely. And I'll explain what I mean by those two things in a second.
But, you know, and it's the subcontext of all of these conversations, right? We are at a point at which the decisions we make, the things we do, the choices that we're part of and, ultimately, the technology and the controls that we implement are the key to the success of all of our organizations.
And also, honestly, if I can be frank, all of us and probably our careers and the things that we might do that might be super interesting for the next whatever it might be, 12 months, 5 years, 10 years. And, you know, for me, and I think this is the kind of leadership imperative, but it's framed by three simple things.
And, you know, I think it is super simple. We've always had policies, but policies now become the bedrock and the foundation of literally everything we do. And I don't mean the old world static policies that someone wrote, no one knew what it was, no one knew what was in it. Policy now defines every single action and every single thought that we should take. And by that, I mean, you know, in our AI security policy for our organizations, which I hope we've all got and I hope we've all read, it will define what's our risk tolerance.
And I don't mean in terms of what happens at a technical layer when we implement AI in our organization, but what does our organization, what does our company think about in terms of how fast it wants to move, what it wants to do, and how the technology needs to play a critical role in that, and what's its tolerance? What's its tolerance for disruption? What's its tolerance for security incidents? Because we're moving into a world where there's a lot that's still unknown.
So for me, actually, and if you guys don't have one of these things, you should go ask, where is it? Who's writing it? And if you do have one and it defines what you're doing in terms of your AI governance, your AI strategy, please make sure that you understand exactly what's in it. Because it becomes important and it's deterministic for everything else that follows. The other thing, data.
Like, nothing works in this world without thinking about data, whether that's honestly the integrity of data, because all of that stuff we're doing in the broader ecosystem around AI, none of it's of any value. It fails pretty quickly if we don't understand the quality of data. Where is all of that data? And then obviously, how do we secure data? Everything we do is really just pivoted around data, right?
Like, data is the construct that drives everything that happens, decision making. AI doesn't function without that. So this becomes super critical for me. And then there's the third pillar. This is relevant for everyone in this room. This is why I said what I said at the start. Because there's nothing that happens when we don't understand what our tolerance is in our organization and where we're at in terms of our data security, you know, data integrity journey with our identity.
Like, it's the foundation. It's, I mean, we can call it whatever. The fabric, I think of it actually as the currency. Nothing happens. There's no transaction in the IT estate that happens without identity. We own those things. So we are at the heart of everything that's happening at this moment in time, which is why I think, you know, as we think about the transformation that's happening, we should be the most excited people probably, well, definitely in the IT estate in your organization.
But we should also consider what's the implication of the fact that we are at the forefront of literally everything that's about to happen. For me, when I think about that kind of board transition and all the changes that are happening, I'm thinking about them in terms of kind of five key areas or forces. The first one, guess what, actually, we've been here before, right?
I mean, when we all moved to the cloud, we were incredibly optimistic. We had all of this on tap processing. Everyone had access to unlimited resources. But what did we learn? We learned an important lesson that we cannot forget today because we're repeating the same pattern, which was did we have the controls?
No, we didn't. When we moved to the cloud, guess what? Costs went up two-, three-, four-fold. We didn't have all the tools that we needed to manage that environment. Our users and the business were super happy because they could spin up instances everywhere. They could do whatever they wanted, and it's the whatever they wanted without control that got us into trouble. We have to make sure that if we do nothing else, we learn that lesson and we make sure, because we can refer to it. This isn't a theoretical discussion.
We can actually refer to what we've already learned and make sure that those realistic components of enabling our AI transformation are at least thought through. People understand why we need them, and they're on our agenda, and we're starting to do stuff.
That, for me, that's the realism paradigm in terms of one of the key forces that's shaping, I think, everything that happens today. The other one, really, I think of this as sovereignty. There is no conversation, actually, I think, that doesn't start now with how well do you understand sovereignty?
Yeah, I didn't use the words AI in that at all because guess what? Before you come to what you're trying to do in terms of enabling your AI strategy, enabling the tech strategy in your organisation, if you don't understand this and you haven't thought through what that means for what you own, what you run, and what you're trying to do, then you're going to be challenged because the world is changing. We all understand the very, very volatile geopolitical implications at the moment, which have driven us to think about the decisions we make.
So maybe we were comfortable 12, 24 months ago in terms of some of the services that we consumed, where they were consumed from, who ran them, what our risk was in terms of what happens if that service gets turned off or denied to us, and all of that kind of obvious and clear stuff. But it's not something we can ignore, and I would challenge everyone in this room again, have you thought that through? Do you understand what that volatility and that kind of sovereign question means for you? Are you factoring it in to what you're doing and the decisions you're making?
I think it's super important, and I think we need to make sure that we understand what's our organisation's attitude to it, and then what does that mean for us? Visibility and blind spots.
For me, some of these are already pretty well known. We understand, and I think we've been managing things like third-party risk, because in the identity space, there was an awful lot happening in our hyper-connected ecosystem where we weren't the owners of those things anymore. But guess what?
Again, that paradigm just changed. So it's not only, and I think most organisations are still probably on their journey to solve some of those heritage or legacy risks in terms of visibility, but now, and you've heard it every second, we've got this new paradigm. We've got AI agents, and again, it's just a visibility risk.
So for me, when we think about one of the areas that is forcing us to prioritise what we do, visibility becomes a key. And then we've got this thing that we've called disinformation. So we've been on a journey where we've got to a great state when we think about our human identity landscape, and we moved people from doing the obvious stuff that we all knew was wrong, like sharing passwords. So we've made great progress in terms of the things we focused on, and actually I think our focus got quite narrow. So we started to think about very, very narrow context, but the world just changed.
And actually, guess what? We're now in a world again where attestation and provenance and context are absolutely the most important thing. AI agents require us to rethink the bigger questions, who, what, when, where, why. Like if we aren't thinking about those things, and they're very simple terms. That's not technology, it's just the key things that we need to think about now, because that is now really important as we are looking at how do we make sure that we enable and secure our enterprise.
And then, guess what? There is this new paradigm, there aren't humans anymore, there aren't just AI agents. We've got both of these things coming together, and we need to understand that context. We need to understand how does that work, what are the primary patterns of operation that we're seeing and going to see in the future. With that last point in mind, I genuinely think this is one of the most important questions that we face today. And honestly, I don't think anyone can answer this question.
In fact, I'm actually prepared to do a little challenge. So can anyone stay seated, please, in this room if you think that you know how to answer this question and you have it in control. So if you don't have this in control, stand up, please. If you don't have it in control. So all of you sitting down have it in control, yeah?
Well, could you stand up then? I want to see, is anyone still sitting down that believes that they have got this locked in? Because I'm going to come and ask you some questions later. Because I genuinely think that there are a lot of people in this room that are standing up that would like to know the answer to your question. Thank you. And here's part of the challenge. And here's some of the actions that we can start to take or the questions we can ask to start to, I think, address that pretty simple question and problem. Because we should go ask, like, does the CISO think the CIO owns it?
Does the CIO think the AI data team owns this problem? Like, literally, if you want to do one thing when you go back to your organization, go start to ask those questions. Because it will get you an insight into where we're at and it will help you frame what you need to do next. And I don't mean to scare, but do that question pretty quickly and try and do some of the things I'm going to share with you pretty quickly. Because the world doesn't stop.
In fact, the world's moving faster and faster as I talk. So I think, you know, speed is imperative. And there are a couple of things I might frame as, you know, things we should absolutely go and do tomorrow as we start to ask some of those questions. Ask yourself this.
Like, genuinely, what's your answer? Like, you might have a slightly different perspective. But for me, actually, the key is, do you have a perspective and do you have something that you've agreed on that you're going to do? That's what I think. That's what I believe should be the answer. But my challenge for everyone is, ask that question, do something, and do it tomorrow. And honestly, once you've done that one, do this one.
Like, if you don't have, like, that ownership and you haven't thought about these things in terms of where they sit in importance in your organization, then I think you've got actions to take. And they are pretty simple actions. Because to this point, actually, I've not really given you anything that you need to do that is technical and going to take you one, two, three, four months. All of these things you can literally go and do tomorrow.
So, talking about going and doing stuff tomorrow, where do we start? Let's keep this simple, right? I don't think the answer is that we could do any of those things.
So, here's where we start. We absolutely have to start with discovery. Let's not get sidetracked by, and it will become important, don't get me wrong, but as of today, and I mean as of today and as of tomorrow, there is only one thing that you need to do. Discover and observe. If you don't know what's going on, you've got, it's great, you've got an architecture, you've got a strategy, you're thinking about what you want to do in terms of run time enforcement and what's going to happen in terms of your architecture for identity and control. It's amazing.
Those things are amazing, don't get me wrong, they will be needed. You've got to start somewhere, and you've got to start somewhere quickly, and this is where you have to start.
So, if you're not doing this, you need to ask yourselves, how do I do this, and how do I do it quickly? Because, if you look to the previous slide, like, these things are out there, the challenges are out there, the opportunities are out there, but we have to start telling our organization that we are making progress in terms of understanding what's going on and therefore what we need to do next.
And, by the way, you actually, you know, there's some easy stuff in here, but there's some difficult stuff. Shadow IT. Shadow IT is a problem that we've not solved for 10, 20 years. It just came back around as one of the biggest challenges for us because, as we connect to all of those systems of record and all the things where we think we know what's going on, but we validate because generally we probably don't know what's going on, the shadow IT piece becomes even more important.
How are we getting the signals and the insight that tells us all the stuff that's happening in and around the edge that actually is probably our biggest risk and our biggest opportunity? Because, if we can't solve that problem, then, if we only know 20% certainty of what's going on, that's not good enough. We have to get to 60, 70, 80%, and we have to continue that cycle. Once we've got the discovery piece, we need to start with that ownership. We need to make sure we understand who's accountable for these systems, the development of these systems.
How do we make sure we've got those things in place? How do we make sure that we understand all of that at run time and that we can continue to check and validate those things? We talked about and I've heard conversations about real-time authorization. Those things are important, and we have to build our frameworks for how we manage in this new world at the speed at which is required because our old systems won't cut it. They don't work. They're not dynamic enough, so we have to then start to look at what does that mean and what do we need to put in place? And guess what?
I mean, actually, this is all part of a much bigger and potentially a much more interesting conversation as well because this whole AI transformation journey is about to change some stuff that I think fundamentally we've all taken for granted in this room for quite a long time. So, most organizations probably in this room, you're probably buy not build. The world just changed, by the way. Just changed. And I can't tell you what the percentage will be, but back to how your organization is trying to transform.
You might be looking at 10, 20, 30, 50% of all of your IT estate might in the next five years now be built by your own organization. Are you ready for that?
Well, guess what? Actually, AI security and identity security becomes the foundation and the bedrock of managing that transformation, and that is a transformation that's coming to every organization. It's just when. We talked about, and I just talked about the discovery piece and the importance of it, and that's where you start your journey, and it's kind of obvious, I guess, for everyone why you start there and what that means from a security perspective.
I tell you what, you just got a seat at every financial conversation in your organization, probably starting now, and if it's not starting now, I challenge you to ask your organizations what's happening because this technology, AI agents, is a great example of nondeterministic behavior. Nondeterministic behavior means, well, we can't predict what our machines are doing in terms of the activities they're performing and therefore the cost associated with it. All of our financial models potentially are at risk now next year. You might ask yourself, why should I care in this room?
You should care because as you start doing your discovery and as you start to build your systems of control, you can now go and have a conversation with the business about the key constructs that will enable them to do their forecasting accuracy for next year in a way that I guarantee you they probably don't understand that they can't. You can play a part in a completely different conversation.
If you want to be the CFO's best friend, I genuinely mean that, start that journey and start to tell them what's happening because you can explain to them what organizations are doing what, what have they got in terms of agents, and what AI platforms are they using, and what does that mean from a capacity perspective? Yes, you can't produce the models, but you can give some key input into some of the decision making. And guess what? It's not all about finances.
It is also about making sure that we understand the risk and we're starting to, whatever your risk profile was in your AI security strategy and your business risk appetite, you now become a key part of that decision making. So for me, it's pretty simple, and which is why I think you all should be so excited in this room, but also probably slightly nervous and asking yourself, what am I doing today and tomorrow? Because this is real. This is happening now. And honestly, without this, we're nowhere.
Please do not think that your strategy is going to help you if you haven't started to execute this. And I genuinely think this is true. We have to be aware that we're moving at a pace at which, if we don't have the foundations in place, everything will come crashing down pretty quickly. And we can help avoid that now, but we have to bear this in mind. We have to do this hard work and we have to start it now. And I think the where we start, the how we start is pretty simple, but honestly, there are no excuses and there can be no exceptions. Thank you very much.
Well done, Simon. I think that was really well articulated, nice and clear. You stumped our audience. They haven't got any questions. And the only question I had, you've just answered. So if you guys have got any other questions for Simon, please, I'm sure he's going to be at the booth. And otherwise, just give it up for Simon Gertsch. Thank you.