James Whitehurst17:55
Yeah, I mean, I think the two biggest blind spots that we see is, first off, the developer is now keying, right? Because we're all about how do we move at a faster pace, how, you know, etc. And, you know, developers in moving fast want choice, then they want variety. Well, variety and security are a tough combination. You know, the analogy I would make is the average security kind of incident isn't, you know, spies shooting in through the skylights, it's somebody checking every window, and if you have a million windows, the likelihood that one got left unlocked is high, right? And so this real focus on variety and self-service has led to, you know, a whole set of challenges for security. And frankly, one of the reasons we keep talking about having a common one platform, having a common operating model across that, I think matters. So that's number one, it's how do you ensure the feature velocity and variety and choice that developers want, but still be able to do that in a safe, secure, reliable way. Frankly, I think the other thing is ensuring that we have tech players that have a shared sense of responsibility. In other words, it is often the case where, not SolarWinds, but many of the things you look at, each component, each vendor can argue, 'Oh, what I did is totally safe and secure.' Well, what I did is totally safe and secure. It's when you plug the things together is where the seams, you know, kind of start to show. And so I do think vendors need to step up and say, 'For my clients, I have a shared responsibility around security that goes beyond is my product safe or did I do this securely, into it's jointly responsible.' I think one of the things, the reasons IBM has such a strong position in security and, you know, kind of is often affiliated with trust, is we do go into every engagement around security first. And even if it's not components of our stack, you know, we are jointly responsible when there's a problem, and we think of it that way. And I do think we have a lot of vendors who are running saying, 'Here's my piece, here's my piece, here's my piece,' if you don't think about how those plug together to offer the holistic solution, that's where the security issues have. And we need every vendor to step up and say, 'It's not just about me and my piece, it's about all of us and how my things are getting used in a joint set of responsibilities.' I mean, the analogy would be, and which we see now, if you want to hop into politics, it's like what responsibility do social media platforms have for the content on their platforms? It's not too different. What responsibility do, you know, technology platforms have for the potential security vulnerabilities that can manifest on their platforms and the way people use them? And I think I'd argue that from an IBM perspective, for security, we're not in social media about saying security, it's like we should feel a shared sense of responsibility for people using our platform to make sure that it is inherently secure, or we work with our clients to do that. And if we don't have that shared sense, you're never going to, from a technical perspective, solve every security problem.