Erik Bradley, Chief Strategist and Director of Research at Enterprise Technology Research, joins theCUBE Research’s Dave Vellante and Jon Oltsik at the RSAC 2025 Conference to analyze takeaways from this year’s keynote themes. Their discussion draws on Enterprise Technology Research’s annual cybersecurity survey and real-time insights from the show floor.
Bradley shares how AI agents are reshaping security posture management and driving major changes in how teams operate. He also points to growing vendor consolidation as organizations look to streamline tools across the cybersecurity stack.
The conversation emphasizes the importance of high-quality, accessible data in powering effective defense strategies. Bradley, Vellante and Oltsik explore how enterprises are adapting to the pace of innovation while navigating new market pressures.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
RSAC Conference 2025. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For RSAC Conference 2025
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for RSAC Conference 2025.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
RSAC Conference 2025. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to RSAC Conference 2025
Please sign in with LinkedIn to continue to RSAC Conference 2025. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Security DataANGLE with Erik Bradley
Erik Bradley, chief strategist and director of research at Enterprise Technology Research, joins theCUBE Research’s Dave Vellante and Jon Oltsik at the RSAC 2025 Conference to analyze takeaways from this year’s keynote themes. Their discussion draws on Enterprise Technology Research’s annual cybersecurity survey and real-time insights from the show floor.
Bradley shares how AI agents are reshaping security posture management and driving major changes in how teams operate. He also points to growing vendor consolidation as organizations look to streamline tools across the cybersecurity stack.
The conversation emphasizes the importance of high-quality, accessible data in powering effective defense strategies. Bradley, Vellante and Oltsik explore how enterprises are adapting to the pace of innovation while navigating new market pressures.
Chief Strategist, Director of ResearchEnterprise Technology Research
Jon Oltsik
Principal Analyst in ResidencetheCUBE Research
Erik Bradley, Chief Strategist and Director of Research at Enterprise Technology Research, joins theCUBE Research’s Dave Vellante and Jon Oltsik at the RSAC 2025 Conference to analyze takeaways from this year’s keynote themes. Their discussion draws on Enterprise Technology Research’s annual cybersecurity survey and real-time insights from the show floor.
Bradley shares how AI agents are reshaping security posture management and driving major changes in how teams operate. He also points to growing vendor consolidation as organizations look to streamlin...Read more
>> Hey everybody. Welcome back to RSAC 2025. You're watching The Cubes, day three live wall to wall coverage. My name is Dave VoLTE. I'm here with John Ick. John Furry is also here as, as is Jackie McGuire, the whole cube team. Eric Bradley is in the house. Eric and I did a breaking analysis looking at etr, latest annual state of cybersecurity survey. Eric, welcome. Thank >> You very much, Dave. See you. Very nice to meet you as well. Nice to >> Meet you. We flew out here together. I, I walked back in our, in, in the plane and I saw you had this stack of data. It was awesome. You, I mean, every single company here in this industry, you've got the data angle, so we're gonna get into that. But you've had an opportunity to meet with a number of folks here. You were, last night, you had some dinner with some Wall Street types. You've been meeting a lot of the vendors, chit chatting with the practitioners, ss John, what are you seeing? What's the big trends? >> You know, I, I think it wasn't a surprise, but it without a doubt, this is the, everything all agentic all the time type of week we're seeing here right now. Whether it's from the practitioners trying to figure out how it's gonna be used and utilized, or the vendors going ahead and rolling it out. I mean, CrowdStrike's done what three AI agents this week, Sentinel One, trying to keep pace with an agent. Even the Netskope rolling out A-A-D-P-S-M agent. So it's really been agentic all day, I think is what we're hearing right now. And there's some data. We can talk about that in a minute. The other theme I'm, I'm talking about also is just everything. SPM, it's a time right now where I think you're trying to encompass a security posture management across all angles, whether it's network, cloud, application. So those teams seem to be the two big things to me. But I'm, I'm curious, what have you seen? >> I've seen the same thing. I, I see a lot of activity on the data side and on the identity side as well. And then I've looked at security operations for a long time. That's a market that's completely in transition. Every layer of the stack is in play. >> You know, it's interesting. So on these agents, what we're seeing a lot is they're actually trying to roll out a SOC analyst, right? They're talking about, okay, I'm gonna, I'm gonna report the threat. I'm going to flag it up. These are the jobs that a traditional SOC analyst would do. So it's like the agents are trying to address that SOC analyst fatigue. It's really interesting. Yeah. >> Layer one, SOC analyst, or level one, I'm sorry, level one SOC analyst, that's a junior person. They're doing triaging of alerts. That is an agentic AI absolute role. >> Yep. And I think that's a smart place to start because it's something that's needed. It's necessary. Not only is there fatigue, but there's a shortage of actual hiring. So it's the right way to address it. And >> Correct me if I'm wrong, but this is there reliable data that you can actually trust? Because I, I always see AgTech, when I hear a gentech, I'm like, okay, what's the data? You know, start, let's start there. What access to data? Well, if you're talking >> About the person rolling it out, right? That's gonna be based on what's CrowdStrike, the telemetry that they're collecting. So you have to trust your vendor that the data's going to be valuable enough and, and intelligent enough to act on. But >> I have to believe John and Eric, that there's a spectrum of data quality, you know, by each platform. Sure. And so who's got the best data? I mean, I would think if you've got the best data, it's gonna at least accelerate your agentic strategy. >> Yes. But if you've got Splunk, if you've got Google Security Ops, you've already kind of decided that, Dave, you've looked at the logs, you've looked at the fields in the logs, and you want to get them, and of course an agent, AI agent is gonna be able to crunch those numbers faster than your son, my son, our daughters, who would be the junior person. >> I love, I, I love to squint through the marketing and try to get to the, to the fact. So you've got, I just, just in this topic, you know, George Kurtz, it's CrowdStrike. We got, we got the agent, and that's where the action happens. The network, the bad guys just, you know, that's the highway. They just traverse the highway and then, you know, all the, all the really bad stuff happens at the end point. And so our agent is key. I asked G two what at, at Cisco hut. He thought about that. He goes, yeah, it's always easy when you're on the other side and you're not in the middle of the network to say, oh, that stuff doesn't matter. But we have, it's not an, it's not an either or, it's an and and we have this great >> Telemetry and what about BYOD bring your own devices and you don't have enterprise browsers half the time the way you're accessing the application. Not everything has an agent. So endpoint isn't the only thing. There's a big, there's a big threat gap. >> And then you've got Palo Alto that >> Has to be addressed in other areas. >> And the Palo Altos saying, well, we got the best data. 'cause we have, you know, with this, we've consolidated it all. We got access to best, the best data. And you've got, you know, this company and that company saying, oh yeah, we, we've got great data too. So what's the truth? I gotta believe that, that everybody, everybody's probably partly correct, but there's still some missing pieces out there. What, what's your take on that? >> All of the companies you just talked about do have good data, but they don't have all the data. Absolutely. There's, and there's, to your point about posture management, there's more data being created every day and gathering that data through the right APIs, having access to the APIs. That's the challenge. And so, yes, they all have good data, but no one, absolutely no one has complete data. >> So let's get into the data. So as it relates to AI spend, of course, you know, looking at the, the survey that you guys have here, I mean, everybody's planning to spend on a AI tools, or they already have, I mean, we're talking about, it's actually a little bit down >> From last year. Yeah, that was what I was gonna >> Bring up was kind of interesting. So what do you make of >> That? So last year, I think there was not fatigue, there was still excitement. So people were planning to spend in the future at a higher level. And don't get me wrong, we're not talking about a huge drop here. But we did see on a trend line, lower expectation of forward spend in AI and security even more. So, the data, I think was interesting when we asked specifically about how many ai a, AI agents have you already specifically rolled out in security, only 3% have said they've already done it across the entire portfolio. >> Yeah. The, the answer was yes, fully implemented. Yeah. Across multiple systems. That was 3%, right? Partially was 15%. Currently testing 9%. So not insignificant, and not yet, but we're thinking about it was nearly 20%. And then 34% said not yet, but considering it, so only 16% were said no plans, and then 5% not sure. So you got, you know, good 80% roughly saying, yeah, we're going in that >> Direction. And I hate the baseball term, but we've heard it a million times over the last three months. We're in the second inning, maybe the beginning, the top of the third inning. But I think this data's kind of showing that people still believe it. But the spending last year, the intent to spend last year was higher than it is this year. I think there's a little bit of a stop, wait and see. Let's do our due diligence before we go ahead and rush in. Now, the last point on that AI series that we pulled that thread in the state of security, was when we asked people, is this the future? Okay, maybe you're not rolling it out now, but is this the future? It was almost unanimous. Everyone said, yes, agent AI and security is the future of security. But >> Look, but look at this. Have you hired new talent specifically for ai, LLM enabled security systems? This is where the data's interesting. 'cause it's somewhat, you know, the answers are somewhat contradictory. If that's the case, then you'd think they'd be hiring. Now maybe they can't hire, but here we have no, you know, the the percent that said no went up from 41% to 53%. We have no plans to hire new AI talent. And No, but we have plans went down from 42 to 35. Yes. We already have went down from 17 to 12. So either they, they're not putting where their money, where their mouth is, or they can't find the talent. It's probably a combination of both. >> I want to hear your take on it, but I'm gonna, I view that data differently. Oh, if the vendors are rolling out a good quality agent AI feature, they don't need to hire, then why would I hire? Yeah, that's supposed to be the higher, >> I think there's a interesting, I think there's bifurcation there. If you're a large enterprise, you are probably doing this development yourself. True. Because you've got lots of different vendors, you've got proprietary data. You may, may even have sensitive data or even confidential data. Whereas if you are, I agree with you, if you're a smaller organization, I can't do this. It's gonna be really hard to find people with security and AI development skills, and therefore I'm gonna rely on the, the vendors themselves. >> And that's a great point, because this question doesn't awkwardly define, are we talking about in building it yourself or managing it, right. So there's really no way to determine that. So that's a great point. >> And, and you know, maybe their, the organizations are putting their AI hiring talent elsewhere, not necessarily in security. Right? Because actually I think in, in, in, >> I don't think maybe, I think that's true. Yeah. And they're putting it in, in any kind of a business, right. Driving revenue, driving efficiency. >> And, and, and you know, when we talk about agents, I always end up talking about knowledge graphs. And the security industry has always been a pretty big user and adopter of knowledge graphs more so than the traditional, you know, mainstream enterprise apps. Because, you know, knowledge graphs are great, they're expressive, but to actually query them, you gotta go back 15 years and do unnatural acts up until recently. But anyway, I wanna come back to posture management. So there's some interesting data in here. When, when you ask where's the budget increasing? It's cloud security, multi-cloud, LLM protection, ransomware protection, and then, you know, it's not, you know, it's in the middle vulnerability assessment and management. But when you asked about what the, what the priorities are. Yeah. Posture management or what, what I think you they term vulnerability management. Yeah. Went through the roof. I, I want to sort of set this up with something that NRO said at our round tab table at Palo Alto Ignite. You, you saw what I wrote and you commented, thank you for doing that, and brought in your broader practitioner community. But basically said, ah, everybody calls it posture management and they think that fixes everything. That's not the case. And of course, his, his comment there was in response to a bunch of analysts asking him about Wiz, right? And, and the impact of Google, right? And, and so he, we know Wiz for a period of time anyway, was, you know, hurting Palo Alto's business. Maybe they've stemmed the tide. I think, John, you said that, but let's, let's bring it back to posture management. What's your, what's your take on what you're seeing out there? You know, is it, is it as important as everybody said, of course it's important, but is it, you know, as important as it, the whizzes of the world sort of seem to be projecting? And is it, is it, is it maybe, is there posture management washing going on? >> Yeah, this is one I could go on all day on. The first thing is our terminology is off. So vulnerability management, exposure management, yes. Posture management are all basically the same thing. Yep. Sure. And we're carving up terminology and confusing the market. So that's the first thing. The second thing is hybrid. IT is moving so quickly and it's so specialized that you need these specialized posture management tools for cloud, for identity, for data. Now that gives the, the practitioner in that space better visibility into what they're doing. But somehow I have to aggregate that data for risk management purposes. So both of those things are happening. But in terms of SPM, it's generally in a particular domain that you need that specialization. Yep. >> Completely agree. And I think I agree also that this week, where I'm seeing it most is on data. So the data security posture management side and identity and the call out netscope, they rolled out A-D-S-P-M, which is, you know, I don't want to use the word platformization, but let's talk about a consolidation of the vendor stack, right? This is an underlying theme in security. So as you see these people that, you know, they were CSB first, now they're rolling out DSPM, I've seen some identity access management people roll out some posture management on one, I'll call out one password, been around for 21 years, still private. But man, they have some really great technology. I was really impressed with what they've been rolling out. So it seems as if all of these vendors recognize that there's a platformization push as a strategy, but they can't do it in just their core space. You know, CrowdStrike's doing it as fast as anybody is. And Palo of course, also, they made that acquisition and protect ai. But yeah, I agree with you that the terminology is really what's morphing here. All of it. All a CSO cares about at the end of the day, is your vulnerability management. That's where everything starts. >> Yeah. And I would just, one, one other point is, yeah, sure. It's one thing to identify a vulnerability, it's another thing to fix it. Yes. And so these spms are closer to the people who fix, right. Those vulnerabilities. Whereas the reporting is to the people who have to understand overall risk. So >> NSH was using this term, and I hadn't heard it a lot, I'm sure security people hear it all the time, but this peace time versus wartime security. So the peace time would be my, my PO posture management. Is that right? And, and the wartime would be remediation. Is that how we should think about it? Or what is it meant by those terms? >> I don't know. Or is >> That just marketing >> Bs I think it's his terminology. 'cause to me you're always at war or you're always anticipating war. But I do think he means the preparation, the prevention angle and the risk management angle versus the boots on the ground. There's something we don't know. There's something suspicious. What is it? Do we need to respond quickly? >> I always viewed that as security hygiene versus actionable response, is how I always viewed it. But yeah, again, there's no way for us to know exactly what he meant by that statement. The truth is though, you have to do both at all times. Whether you, whether you're in peace time, award time, they're both priorities. >> I'm the, I'm the non-security guy in the room. I'm like the generalist and all these, there's like 10 or 12 security guys and it was me and Matt Eastwood from IDC. He's not a security guy either, but all the other security analysts were like, oh yeah, wartime peace time. So I'm like, all right, I'm not gonna ask the stupid questions. It's >> A great sound bite. >> Yeah. So I wanna come back to, you know, platformization, maybe we shouldn't be using that term. 'cause it really is a Palo Alto marketing term. Yes. So we should, you know, call that out. But it basically refers to, you know, this sort of consolidation play. George Kurtz, I was listening to something he was saying at one of the financial conferences. He was saying, look, it used to be best of breed product versus best, best suite. Now it's best of breed versus the best platform. They have a different strategy around platform. They'll connect in with Okta and Zscaler and other endpoint, I mean other identity and, and, and cloud players. Whereas Palo basically saying, no, we're platformization is, is we are the platform. And so last year we basically, you know, exposed the, the king has no clothes and said no customers are reducing the number of vendors in their, in their tools, number of tools in their, in their stack. This year was a little different. We're starting to see some early evidence that tools creep is slowing is what we published. Eric, the percent that said they were gonna increase went from 51% down to 40%. And they said percent that said stay the same, went from 37 to 48. So, and and the number decreased, stayed the same. Yes. 9%. Right. So we're not making really any progress there. Although there's early evidence that maybe the tools creep is slowing. And then, you know, later on the cash Aurora declared the end of, of best of breed, and of course a recency bias with my little round table with him. And so you had this big decline and we're moving from to a best of breed approach, you know, where we select the best vendor in each cybersecurity. So it went from 35% to 18 to percent, but as you pointed out, you guys added a bunch of extra questions. Right? Right. And so it's, it's maybe not as definitive as we thought, but the question remains, you know, is that consolidation? What Palo Cal's, platformization, how real is it? How practical is it? And where is it happening? >> Well, we've talked about this. So first of all, best of breed. The end of best of breed. One thing I've learned as an analyst, one absolute lesson is never, ever, ever say a category is dead is dead. Because you'll be wrong. We remember when we said the mainframe is dead, tape, Tape is dead. Yeah. I'm showing my age. Platformization for these big guys is about share of wallet. It's, I want to be one of the major consumers of your budget. I, but I know I'll never get it. You have to message to, I want the whole thing but you'll never get it. Platformization makes a ton of sense in the small, the SMB market where it's either a platform or a service provider. Yes. If I'm a large enterprise, I have one of everything. In fact, I heard that from A-A-C-I-S-O. He said, it's not like I'm replacing one thing for another. I have have 10 things and I have to rationalize that first before I move up. So absolutely CISO's job is to rationalize their security stack at the same time as look at new needs. And so that's happening. I think that's reflected in the data. >> Yeah. From a business perspective, large organizations have m and a, they have rollups, they have multiple divisions. They're not centralized, they're across globes. There's no way that we're ever gonna see a consolidation on one platform. But real quickly on the data, I think it's a touch more telling than it was last year. Yeah, there's a possible inflection point here for two particular reasons. Yes. The number of decreased state consistent 9%, there's no doubt the number that stayed the same was a big, big jump. So they're not expanding anymore. The thing that's not in that slide, but when you cut to ours, 'cause all of our data can be cut by industry size, the larger you scale up the enterprise, the more it jumps. So that's 9% across all 500 respondents, which was up for 300 last year. By the way, we increased the end. However, global 2016% said they're decreasing. So >> Wait, you're saying that the very large companies, there's >> More are trying to, there's more evidence Find find and this, >> But broadly at the global 2000, I mean you're saying not as much or there's more no more. There's evidence. Yes. >> But that's all respondents. When you go to just large, it creeps up. When you go to Global 2000, it creeps up even more. >> So it appears there's, it appears there's proportionality. >> Yes. Yes. But I think we need to change a narrative. And you're a hundred percent right. This isn't about, you're gonna be one provider. That's never gonna happen. There's no CSO that's ever gonna allow that. You are saying which is accurate. You're just trying to take a little bit more of that share. So there's somewhere else I can consolidate redundant vendors. I'm going to do it. And remember our large macro spending data. Yeah, yeah. For those people that said they're decreasing spend, we immediately ask 'em, okay, how are you gonna decrease spend? And one of the number one raises is always we're gonna try to re, you know, consolidate redundant vendors. That's what they're looking for. They don't want redundancy. >> So Yeah. And one more point, I'm sorry Dave. No, please. But I go back to, companies had multiple firewalls a few years ago. They had Checkpoint, they had Palo Alto, they had Cisco. And so they decided let's pick one across our global enterprise. 'cause we get, we get better prices, we have better skills, we can reuse rules that goes on all the time. And that's reflected in the data, especially with large organization. That doesn't mean for a second that I'm going to one platform. >> So Nikesh Aurora also makes the statement many times that, you know, no independent cybersecurity company has more than like single digit market share. And maybe they got seven or 8%, whatever. It's, and he says no cybersecurity vendor or no company has share, Microsoft has a Yeah, double digit share m Oh yeah. So let's, let's take them outta the mix. Like we often have to do Sure. To just talk about everybody else. And so I gotta say, Aurora's got cas, he said 40% is his sort of target. And so Zs, Carava and I were at that Ignite. We did a little breaking analysis afterwards and I said, okay, what would be an indicator that that the so-called platformization is actually happening? And Zia said if they get to 15% market share, then I'll, that would be to me an indicator. And I'm like, so I want to ask you guys, what do you think about that? Is that an indicator if they can get to 15% market share? Or do they need, you know, 20, 30 cash is 40% for us to clear that platform? I thought you begin on that one happening. >> Well, the first thing is, I don't know anyone who's tracking the market share of platform vendors because that assumes we have a solid definition of platforms. And I don't think we do. Yeah, >> Sorry to to interrupt. Okay. But he's, he's talking about overall share of, of wallet in, in the overall market. If the market's 200 billion we're, you know, whatever. So >> Yeah. And well then in that sense, I do agree. Yeah, because, well Palo Alto has that opportunity. CrowdStrike has that opportunity and there are a few other vendors. Few others. It's certainly Microsoft and I can't discount Microsoft 'cause I think they're doing good things. Yeah, I think that's true. But it takes a lot to consolidate and ripping and replacing. I don't think that's gonna happen easily. People have budgets, for instance, if you have Splunk and, and you say to your staff, well we're thinking replacing Splunk, they've built their career. >> Yeah. They're gonna go in, why quit? >> I'm learning Splunk. So do you wanna sacrifice that? So there's a lot that goes into it. I think fundamentally from a, I dunno market share perspective, he's right. But I think if you go under the covers, it would be very difficult. >> Well, again, I think I liked the way Z has thought about it. It's like, okay, how do we measure it as analysts? Okay. Yeah. And so 15%, 15% would be, you know, interesting. And then at that point we'd have to parse through, okay, how much of that market share gain is platformization versus just them selling other stuff. You know, so thoughts on that. >> You know, it's also, they have very much a a, an acquisition strategy. So it's like, okay, if you're getting more share just by acquiring things, I'm not really sure that's their definition of platformization either. Right. For me, a platformization is that you land and expand because you're so good with your other offerings that it gets adopted. And I'm not necessarily sure if that's what we're seeing right now. That's, >> That's a really good point. Yeah. Cisco went from almost zero market share to pretty significant when they bought Splunk. >> Yeah. And Palo's doing the same. Exactly. >> One of the things you wrote on your RSAC preview was, what is the Wiz acquisition? Tell us about this industry. It's a, it was a $32 billion acquisition up from I think the original 24 billion, you know, Wiz Israeli company say, oh we're gonna do an IPO. They hardly ever do. And so that was kind of interesting. Google buys Mandiant, a lot of people said, ah, that's kind of a head scratcher. But now with Wiz, maybe it makes some more sense. We'll see if the deal goes through. But what in your guys' view does that tell us about what's going on with m and a, with posture management, with Google, with the hyperscalers, with the industry broadly Pick one. >> Well, I'll start with the data and then maybe you can do the industry analysis. Sure. Wiz is the highest net score across all of our information security sector. There's no one higher. And >> The net score is a, a measure of spending momentum. Yes. Right. >> Wow. It is by far the highest. However, when you look at our measure of provision or presence in our survey samples, so we do about 2000 a quarter of it end users, IT experts. So their provision's very low, but their overall spending trajectory is extremely high. Another thing that I found interesting with them is when I ran a correlation analysis between them and the three major hyperscalers, their lowest correlation was with Google AWS actually had a much stronger correlation. So people that are increasing or adopting spend with AWS we're much more likely to use it. So it seemed interesting to me that like the, the Google Wiz alignment was the one that ended up happening there. Listen, you cannot deny how good Wiz is from an efficacy standpoint. They are really interesting, really innovative, great company. We'll just wait and see now if Google could speak enterprise, 'cause it's never really something they've been able to do at the very, very large enterprise level. And we'll see if they can, they're certainly trying, there's no doubt about that. >> Good points all, and I think a couple things. So one is Google Cloud security, they want it to be a bundled security solution like Microsoft, and they achieve that. Second is that they've got really good momentum with Google security operations, the old Chronicle. So now they can extend that to the cloud and they have good momentum and good synergies there. And then if you look at Microsoft's security base, it's heavily tied to micro to Microsoft assets, especially Azure. Yes. And so now they can tie security to Google Cloud. So all of that makes them, and, and this really makes them a, a, a dominant player in security overnight. >> But does it make them a player for people that aren't already heavily invested in GCP Cloud, whether it's for BigQuery or their data, like I don't see them winning net new movers, right? Is someone gonna move from their infrastructure stack and they, they're stacked there to go to Google and then now all of a sudden the cloud security is wrapped in? Or is this really just about enhancing their base that they already have? >> I think it's more enhancing their base. But remember that a lot of large companies will have AWS, they'll have Google, theyll have Azure, and so maybe this skews them there. Right? I think this is good for the public sector, very much so where they can really push this into the public sector. And I think longer term maybe they can drive security revenue specifically or, or independent of GCP. Right? I, >> I'll also add to that, that remember Google's got a 50 this year. Google, our estimates are Google will do $54 billion in their entire cloud business. Half of that will >> Be not chump change. >> It's not chump change. And, and, but everybody, you know, craps on Google, ah, they're distant number three. That's a 50. How many $54 billion companies are there in tech. Half of that for the first time ever, we think half of that will be Google Cloud platform, which is growing significantly faster than their overall cloud business. So my point is that will drag along business. That is a huge tailwind for them. I also wanna point out just one little nuance in the data. You said Wiz is the number one actually Microsoft, right. Which is just astounding. I mean, John, >> I didn't say they were number one. I said, I said AWS was better aligned because Oh no, generally Microsoft is generally, we kind of keep 'em outta the picture. They're so ubiquitous, but, but >> I'm talking about net score. Oh, okay. So net score, Microsoft actually has a slightly higher net score in your data than Wiz, which is, but, but Microsoft is off the charts in terms of penetration. Yes. So here's Microsoft. You, you >> Can't even see it on chart. >> And there's Wiz right behind them on the, on the, on the net score, which is essentially a measure of the net percent of >> Customers. I thought we were excluding Microsoft, but since you >> Bring it up. Oh, fair enough. Right. They >> Are not only that, but are product granularity surveys, like sort of our magic quadrant, but it's not magic. We, they're leading in almost every category. It, it doesn't matter if it's identity or where they are, they are a top leader every time. >> I mean you can see the, the, the players with Momentum, Microsoft Wiz Grafana, interesting. ZScaler's always been pretty high close to that magic 40%. Mark >> Rubrik net scope >> Point, which was a, a backup company Trans transformed into a security company. Very high Netscope, CloudFlare, HashiCorp Darktrace, Google actually, you know, pretty significant. You know what's interesting is, is AWS doesn't show up on this because AWS doesn't really try to monetize security the same way that Microsoft does. Right? It's built in. So there's a lot of room for the ecosystem to play in the AWS sandbox. But Will, will the, will the Wiz acquisition, you know, change that posture? Or is it because Google and Microsoft have sort of upped the stack applications business? It's, it's, it's, it's more likely that they're, you know, gonna monetize their security. Do you guys have thoughts on that? >> Well, I think the other vendors will try to fill that void with Amazon. Yeah. And I don't see, I don't see Amazon now making an acquisition. Yeah. They try to facilitate security. They don't try to own security. Agreed. Right. But I, I think that they'll look around for other players and that may open up the market for someone we're not even talking about. But >> It makes them a great platform for ecosystem partners because they're not going head >> To head. Oh yeah. Always has by the way. They've always been the more open of those two and >> They use that to a strategic advantage. Yeah. >> Yep. And I think they will in security as well. Yeah. Two names that I actually, I had written out the, the names I wanted to talk about on that, just two others that really look good right now. Also, SailPoint and Fortinet are, are performing decently well in that net score as well. So just really interesting space for me. The identity access space. Interesting. >> Yeah. Fortinet, it's >> Such a competitive area right now in that entire identity access management. It's, it's gonna be interesting. >> Okta is right up there. >> I've never seen it more active. >> It's unbelievable right now. >> Everyone kicked that can down the road for years. >> Well it's interesting, again, you look at the data and what ETR is, they have like a, a, a red sort of gray, green, red, yellow, green, almost. If you think about, oh sorry, green, yellow, red, green being, you know, high elevated net scores, you know, gray kind of in the middle and then red, you know, not so great. Look at all the green in here. There's just tons of green. If you were to go into like storage or you know, consulting or servers, >> Particularly consulting right now, >> There's no green really >> Bad right now. There's >> No green, there's like zero green, it's all red. And so this just, it underscores the, the dynamism in this marketplace. And so, alright guys. Hey, great segment. Thank you so much for your insights. >> Eric Jones always >> For having you on. Eric, it's a pleasure having you on. >> And just real quickly guys, we're about to launch a Google whiz drill down survey. Oh, awesome. So we're gonna go ahead and find out, we're gonna segmentate their actual Google customers and just Wizz customers and see how their sentiment changes. So if you, and we're gonna go take a look similar to what we did when Cisco first bought Splunk. Very cool. And just kind of see what that reaction is and kind of compare and contrast the reaction. So love to see it. I'll have that out for a couple of weeks for you guys and I'll follow up et >> Tr.ai. You can download the, the, the summary of the latest annual cybersecurity analysis and survey. Check it out. Etr ai. Eric, thank you John. Thank you very much. >> Thank you guys. It's really nice. Meet >> Keep right there everybody. This is Dave Volante, John er, John ick, Jack McGuire and the entire cube team. Hold on guys, let me let, let me exit first entire cube team. Keep it right there. We'll be back right after this short break. We're excited here. Day three, right back. Sorry David. It's all good. >> Sorry.