Go back

Rethinking End-User Computing for the AI Era

37m 41s

Rethinking End-User Computing for the AI Era

This podcast episode explores the transformation from legacy VDI to cloud-native, container-based workspaces, featuring James Davis and Ray Dussell from Casm. They discuss how Kubernetes, particularly Nutanix Kubernetes Platform (NKP), has reached enterprise scale, enabling dynamic orchestration of digital workloads without traditional connection brokers or secure gateways. A key theme is the growing overlap between IT and Operational Technology (OT), with OT environments like factories being underserved in cybersecurity and infrastructure modernization. The conversation highlights five forces driving change: license cost escalation, security debt, AI readiness gaps, talent friction, and competitive pressure. Security is a major focus, especially browser-based attacks, as modern web applications execute complex code on endpoints. Casm’s approach delivers rendered pixel streams from containers to browsers, preventing endpoint execution and containing threats within ephemeral sessions that are destroyed after use. This architecture controls ingress/egress, manages AI workflows, and reduces ransomware risk. The shift to Kubernetes is now primetime, with a mature partner ecosystem supporting enterprise needs, and customers are increasingly questioning traditional VDI models due to trust issues with legacy vendors.

Transcription

5853 Words, 32289 Characters

English
Welcome back to the Nutanix Community Podcast where we break down what's actually changing in infrastructure and user computing and the way modern apps are delivered. In this episode we're diving into one of the biggest shifts happening right now, the move from legacy VDI to cloud native container-based workspaces and why that matters more than most people realize. Moving off the energy of dot next, we're joined by James and Ray from Casm. We get into what they're seeing on the ground from Kubernetes hitting real enterprise scale to the growing overlap between IT and OT and why security, AI, browser-based workflows are forcing a complete rethink of how environments are built. If you've been doing things the same way for years, this conversation might challenge that. Let's get into it. Welcome back to the Nutanix Community Podcast. Today we have returning James and Ray from Casm. Welcome to the show. Thank you. Glad to be here. Thank you, Dwayne. We are here. Yeah, it's dot next. It was only a couple of weeks ago, but it actually seems like it's just flown on by and kind of off to the next thing. But originally when I had stopped by the booth, you guys were both there. We started chatting about a security vulnerability in a browser and it kind of went off its own little path. But before we talk more about that, wanted to first give you a chance to reintroduce yourself to the audience that made it and watched the last episode, shame on you, just kidding. Yeah, let people know who you are and then we can dive into how we see or how you see the VDI landscape changing. Cool. My name is James Davis. I'm the Chief Technical Evangelist for Casm Technologies. And as we look at that advancing, you see it is entirely changing as far as what we are accustomed to previously with both trust, security and compliance and who the end user is. All of that has changed dramatically. I don't know, gave them good through all that particularly specifically, but that's one of the things that Casm is best at for is for understanding and delivering those digital workloads or digital tool sets to all those different types of personas that are now involved. Great. Yeah, every time I turn around, it's agents, agents, agents. So Ray, how about yourself? Yeah, so Ray Dussell, known Dwayne a long time, hence the gray hair that you can't see. I'm the Strategic Account Director for Casm. Lately, we have leaned into an OT, IoT element for Casm. So we're super excited to lean into that space, which is, I guess, VDI adjacent, but still end user computing, but in the factories and plants. So it's funny how our worlds are converging again, but no, it's super excited to be here. Well, thank you both for joining. Let's start with a quick dot next recap. But what were you hearing on the show floor that was interesting or maybe that you didn't expect? May I tell you, I saw so much on that floor and so many different things. And I'll tell you, I was really happy to see some of the innovations that were starting at Big Cub ecosystem specifics. And I'll go in more detail. Kubernetes has started to get its own ecosystem of different partner sets of delivering on that enterprise class scenario, IE, cost management, organizational backup. All of those were starting to get their own third party providers. You were starting to be there delivering on that. I tell you the idea around moving more towards accepting some open source capabilities that would be delivered inside of enterprises. I think that's been widely under reported in this particular scenario, but I think that was one of the cool things I saw when I was out there as well. And then, you know, again, lastly, when we think it from it, you see the billion where we come out mostly. It was a wide branch of different people who are absolutely delivering for their customers, different results for some of the things that they're looking for. And some of them are getting the exact same thing. I want to conflict of doing the exact same thing that I did for 20 years versus understanding everything's kind of new. And maybe we should go that way more. So, but pretty interesting. I have a lot of fun there. I think it's always, if I use the word dangerous to, you know, do what you've always done, I think it's easy to get in that kind of mindset. And, you know, especially if you're dealing with federal or government, they just have old apps that they do need to keep running and keep the lights on. So, you spend most of your time doing that. There's not a lot left for innovation. So not, they don't want to poo poo on the old way too badly, but it's just a factor, I think. No, but I'll tell you, you know, again, I've been starting to watch this Inri Winkler's Hasiness History. And it kind of brings the light, those things that you did back in the day that were new, acceptable, and they had terrible consequences except you didn't quite understand all those consequences that were happening. So you just kind of kept on about it. Right? Everybody remembers Lauddarts, right? And it happens to those, nobody's asking those questions. It's like, you're all happy with that game. So yeah, you started seeing some of the things that we did back in the day that no longer have that same capability to protect us or secure us because they didn't have those type of threats back in that day. Ray, anything different, Tad, from the world of DotNext? No, I think for me, it was, you go to these conferences and everyone always announces this and that and the other thing. But for me, I think based on the fact that scale is a constant question at our booth and prior conferences alike, I think the timing was perfect to go all in on NKP. And so I think that was a sweet spot of announcements. And as James said, optimizations and partner ecosystem and then the irony of chasm leaning into this, it felt to me like a perfect storm. And then a side note of specific to the OT community, which is vastly under service as far as cybersecurity and optimizations. I'd say the first 10 or 12 people that came to the booth across day one were all OT customers. And so that was that was unexpected to me. So I think you can you define OT for people that are unaware? Yeah, absolutely. So operational technologies think, think some, think someplace like Anheuser Bush. And so they have IT that is managing and helping the humans on the one side of the business do desktops and apps and all that stuff. But then once you go into the factory floor, everything from that door that way is operational technology and it's its own ecosystem and partners and workflows that have been existing for 30 years. And so chasm has a pedigree in this space on the DOD side and now we're going loud on the commercial enterprise side. So again, it was fascinating to hear that again, everyone needs a hypervisor, whether you're IT or OT and it seems with NKP, Nutanix's poise to hopefully with chasm along its side to do some damage in that space. It was fascinating. Yeah, it's kind of mind blowing some of the changes. If you think just from the old, old broker days and some of, you know, scaling, I guess you may be scaling. I guess there's two parts to scaling. There's like the desktop side. What does that mean from a N number but also the speed in which you can do it. But there's also the infrastructure side too, which is kind of been not as robust as if you're thinking like the hero numbers from the desktop side. But that's probably a good entry way into the kind of one of the discussion points around what, and you can define what you think legacy VDI is, but kind of as your company anyway, and I don't actually don't know if there's any others moving to more of a CNCF based approach to get some of that, which I would be scale and load balancing. Yeah. It's all about the both scale, load balancing. When you think about the, I turn legacy is the same construct. There's usually a secure gateway. There's usually a broker and then there's the back end, you know. infrastructure of the virtual desktop that you're actually utilizing or we're going after from that particular perspective. And as you're starting to look at the ability for moving into a CNCF type framework, this is where we really saw in KP as one of the defining factors for us because it was the first one that was actually taken advantage of that particular format or the cloud-native cloud formation format that's part of that. IE, Casm, we deliver everything really in microservices and that capability allows us to be very easily packaged into a home chart that's going to be dropped into a Kubernetes cluster and then deployed out from the workspace control plane to any scale that the infrastructure can actually absorb from that particular perspective. And then lastly, when we start looking at, there's still Windows workloads and there's still virtual machines. This is the perfect storm of NKP allows for both virtual machine management and for us to have container management. All wow, it hasn't really worked through some of the orchestration necessary to deliver those digital workloads out there to those individuals. And that upends the entire current legacy environment. There isn't a secure gateway. There isn't a connection broker. There isn't a back-end virtual desktop environment that you're just connecting with medias. Instead, you have an orchestrated environment in which each part plays its position and has a specific ephemeral nature to the sessions which allow for it to remain a highly secure environment. What I think so cool about what you're just talking about is that, yeah, we know there's a portion of companies running Kubernetes and they're delivering their apps. But I actually haven't heard too many software I would buy from a business like a company and then use it myself on top of Kubernetes. So I think that is a signal to me in the industry that it is finally primetime. It's still the point now. And you mentioned all the other supporting tools. Even a year ago, there was really, you know, run many options for backing up a Kubernetes environment. So I tell people to all the time that when something happens in the valley that it takes along, that bomb goes off. It takes a lot of ripples to get up to where I live. And you're starting to see it or customers that aren't using it, they're definitely questioning what their next purchase is going like. It's a requirement for the future. Yeah. I mean, when you start looking at truly looking at where the CNCF type infrastructure at, definitely you started realizing Uber, you know, the things that you're using every day or going to Chick-fil-A or going to Walmart, all of these are Kubernetes-based infrastructure that are been delivering business, line of business applications directly to your consumers or your two or your users. But the people who in the IT, as Ray was defining, they've been regulated to existing Windows-based architectures versus being able to really take advantage of some of the newer capabilities of delivery to those individual devices that are happening every day with chats. AI chat, Windows, AI workflows. They're not using, you know, the traditional C++ installed application anymore. They're moving at the speed in which they can obtain with, you know, Sass type enabled it. Everybody's world. When it comes to supporting these customers, is it really finding a cheaper VDI vendor or is it go to this new architecture? Like what? What's driving? Switch, right? Because there's risk in staying and there's risk in switching. So like what, what should they be looking for? Yeah. Go ahead, Ray. Yeah, I think we've all been in the UC a long time. And I think for me, there's an observation that has been happening lately where it comes down to trust, where I think some of these monsters, it was just everyone was just going to keep, keep clicking that button. And so whether you're a Citrix or VMware or AVD, like they were just going to keep going down that path. And the trend that I'm seeing is the trust factor is now evaporating and they're more open to not only platforms like Kubernetes at scale, but also a D windowsification of environments. And that's definitely something that Kazem in particular has been looking at is, you know, how to not turn our back on windows, but yet be ready when people are that upset to turn away from that. There are really five major forces that are focusing on when you think about the C and C F type architecture and the difference between that and the legacy architecture. The first one is license and escalation, in which that's what we're dealing with left and right from the different vendors that were taught in our broadconn and so forth. There's a security debt accumulation, right? We're currently patching and building these fragile endpoints under or have been consistently. There's the AI readiness gap. They're not ready specifically for the type of stuff that you're working with LLM as in or starting to work with AI chat, AI application and AI workflows. There's so many different security issues that exist from there that the AI can inadvertently do without the proper SOC compliance or governance is better in play. There's talent and op's friction. And what I mean by that specifically, if you had a chance to be at the world of the UC yesterday, they had a little virtual piece that was going on. Kevin Goodman did a great example of how to remote users who left and did the exact same thing, one that did poorly and one that did greatly and what was the difference between those two when they had the exact same sets of tools and so forth. And that's the same thing you think about AI and talent in operations is that two people who are using AI may use the totally different or may use different sets of models. And so that is a big piece of outward you're dealing with as well. And then lastly is the competitive portion, right? How does my company stay competitive? I think the point I was making with Uber or Chick-fil-A having things like Kubernetes or CNS, yeah, type infrastructure is because they had to deal with scale dramatically, right? Everybody knows what's happening with an Uber and I know everywhere I can go, there's a Chick-fil-A at this moment in time. Chick-fil-A you say, I'm down for that. Oh man. I think from the, you know, you're bringing up AI, I guess we'll come back to the security aspect of things. But on, because, man, I'm a cloud user, I might like personally, we have different stuff running at Nutanix, but whether, you know, without even having direct access like your choice of whatever you're using, you can put, you know, into your browser and start going into everything that you're authenticated into your environment. And then, I think recently last week there was another news article about someone blowing up their production database, which, you know, as things are newer, you know, they're the same like where, where was your test environment? But I don't know, just a different way of thinking before you go and start ripping stuff and trying it out. But maybe, you know, in this new world, like the browser was always important, but it's kind of becoming even more important. But it's also, I mean, I'm an attack vector within your organization. Can you maybe explain a bit about how your architecture is, you know, trying to combat some of those issues? Absolutely. You know, I think just at a high level, when you think about the browser and the way that it was treated previous to this point, and where we are at today, I think you're absolutely right. I mean, there are higher level applications. There are a lot of business applications that are now browser dependent in this particular scenario. They no longer have a desktop or a desktop application and very well don't really need to from that perspective. And when I talk about this, because this actually leads directly to that CVE problem that we were just describing once that before, it was HTML code. I mean, like I could read HTML. It was pretty easy to actually read and walk through. Today, when I go to a website, that's not HTML code. That is, it's executing all kinds of different things from CSS is down through a wasm or web assembly type application that are all being delivered. Some even side channel delivered directly to your input. point and executing on your endpoint. That's the problem where you start to see in that CDEC problem is that that had a CSS problem that allowed for a memory that was dangling to actually running our CEO remote controlled execution on your processor bypassing every single NDR, EDR, everything that you had before hand because it could execute directly on your processor. Now, that was a thing that we built because we needed to feed. We needed to be able to animate the pictures very quickly for us in that piece. So this is now the blast radius of that problem was your entire laptop at that perspective, right? So I was stuck at that one. And that's where you start seeing as a browser being the actual target or the vector and how it can easily break into your environment with a 30 year flaw and that flaw was easily figured out by the right people at the right time to be able to be exploited. It's not even the right right? It's not even that makes it almost sound like you like smart people are working on it, but right like it's at this point, it's grip kiddies. You know, they didn't they didn't even clawed stop mythos from being out in the wild because of the damage it could potentially do. So everyone with a pie card is pretty dangerous. Exactly. You didn't buy an exploit right now. Open claw created a malt bot or the social spot that now trades exploits back and forth with crypto that you can actually literally see happening on that how easy it is to exploit somebody. So that browser is key. Now where we differ at is is really important. It's because we deliver a render pixel stream from the containerized environment to the browser. So the browser is not computing anything anymore for us. So it's not executing anything at that endpoint. The the ability of that CSS for that that CVE function would not affect the endpoint. It would have affected the container and it would have been held within the container as the only blast point that was be possible. And it's destroyed when the actual session is done. That's an important piece is because the casual session really deals with the the the ability for it to be available while you're using it at that session at that time. And then when you're done the sessions gone, the container is gone, all the trace backs on. So there's not a way for in a typical ransomware scenario where it embeds itself on your endpoint and it waits and it watches right it usually takes two weeks before most people even know that they have some type of ransomware or exploit on their environment at that point in time. Yeah. When the the note comes asking for money exactly exactly. And so when you look at these a quad quad or any of these AI tool sets that are in play, this is where containerizing it and putting it within a known blast radius if you will that you can control not only can I control it from what's inside of the actual container, but I can also control its in-bress and I can control its egress. Right. So I can control where it goes, how it communicates, what actual data can have. So it puts us into a whole different arena of things that are somewhat easier to rationalize when you think about it from the container versus giving me a laptop and plugging me up. Right. Oh, that that control of controlling traffic. Is that something that Gazem has is like in a UI or how does that work specifically? Yeah. So there's two. It's going to take 20 minutes, but but yeah. I'm just curious. I haven't seen it. Yeah. There's two major things that make it really easy. So the first thing that we have is we have web filtering built into the actual container. It's a spot in your admin console. You go down web filtering there. Not only can you web filter both a black or a white list, but you can actually use categories and so we actually update these categories every single day, what different capabilities so keeps you in the notes. So that's your first level. The second level is that we actually have an egress control. Right. So we can actually choose where and how it egresses out. And so that's a it's a part of your infrastructure drop down and you'll hit egress and you can actually set up egress for your actual container so that it understands where it needs to go. And then we have partners that we work with that can allow you to create a virtual appliances on prem so that the containers can talk directly to that that appliance directly to staging or directly to a database that it needs access to without having to expose a VPN or have to expose a connection in any way, shape or form at the end point. Wow. It, uh, I apologize. My one of my co-workers, I came, my dog is, uh, zoom is pretty good at filtering out this stuff. But anyway, the, um, so that's one part of it. But then how about like data loss prevention with, you know, disposable containers? What, what type of, you know, it was hard. It was already hard and persistent desktops. You know, how do you, what does it story look like for for doing any of the tracking? Yeah. So when you, when you actually spit up, uh, Kaz and work say it as an example, uh, you can have it's basically assembled. And then that is simply one of those assembly points as a storage, uh, provider in which I can provide a specific type of data, uh, connection to you in a FSS, S3, whatever is necessary, an object storage at the point in time that you're running the session. So any other time, only during the time we actually have the session, do I actually have connection to that object storage as you can see up. Right. And then as you start looking at, um, networking, connectivity, this goes back to that egress capability so I can choose where exactly you can go from there. Then I have all your data loss prevention capabilities where nothing comes out of the actual container unless we give you access to download, upload, copy paste, any of those type of things are out. But then we add in data leak prevention in which that allows us to put in banners, put in watermarks across the actual front end, those type of things to help control that piece because it's really important that the number one spot where enterprises can take immediate advantage of things like AI is in AI, um, experience compression. What do I mean by that specifically is that you have a unstructured database as an example in which you need to give access to it. And the database itself is unstructured as being used in a different piece. You could, as an example, spin up a chasm in environment, actually use our chasm, uh, one of our partners called Koliope, which has this AI chat studio, which then can actually have an LLM talk directly to that database and it's all done through that workspace. Now I can actually ask it natural language questions that I wouldn't actually be able like, how many people are sold to something in 10 days. Um, I could start asking those questions against a database that's available to me and I can control it from not leaving. No one gets access out. And then when it's done, sessions over, it's destroyed. Now you, you might have touched on it with the storage piece that you just mentioned, but, um, a femoral containers. I think you made the case for that, you know, that's what hooked me out. I don't, at least from a corporate perspective, but there is still kind of, um, you know, disposable by default, but a lot of our apps do need some type of state. So how do you reckon style both worlds? Yeah. So we actually have a persistence, capability as well. So the container, as the container is actually created during session, when it gets created, uh, multiple layers are in play that first layers, that storage layer, that's giving access to different storage tiers that you may want to get access to, but it's also giving access to a personal drive. And that personal drive is that persistent drive. So as far as when you're accessing the container, it actually looks and feels like it's yours. It still has your bookmark. It still has your, you know, uh, drop down on your desktop. All those things still fill out yours and in general. And when it's done and the container, which is the container itself is what's immutable, when that's destroyed, the data being held in an S3 in FS or CFS mount somewhere else is actually still okay. And that's going to get reattached and that's time you do a session. So that's how you maintain that persistence. When you think about it from a Windows perspective, in Windows, we still support roaming profiles, FSLaget, all your normal Windows capabilities, that we can still deliver back even on an auto-scaled Windows device, right? So well, auto-scale Windows, let you connect to it. It has had your information. When you're done, it will destroy the Windows VM, but your actual profile is still worth the profile is supposed to be at and your user access is still the same normal user access you had before. When deploying these containerized workspaces for AI developers or maybe someone like me that's probably doing a little bit more prompt engineering, but uh. What are the top kind of security controls that the teams shouldn't skip out? Skip out on yeah, so I think first is again having it within the right containerized environment Second part is is controlling the egress like controlling both where it actually has connections to go to how it connects out Is key, but then you also have the ability to control somebody in-gress i.e The conversation usually goes hey, how can I open up a chat window and I want to type in 511 password or social security number and it goes to my lllm Well, let's not have that happen. What's control the egress? There's a thing called lllm guard that you can implement inside of the containers that help control what's going out and Then also the other part of it is what's coming in because sometimes I don't want that hallucination Coming in and getting you the wrong information or moving up in the wrong way You can control some of those capabilities as well based on understanding tokens that are going back and forth through that container lastly use the containers Environment as much as possible. What I mean by that specifically is that When you think about Nutanix AI as an example Nutanix AI gives you the ability to spin up a Longchling which model on your own on your own hardware internally provides you an API key that you could use to communicate and use it to Inside of your lllm application or inside of your AI chat application by putting that API key inside of the container I don't have a fear of that API key getting out onto my endpoints Because that's the number one thing that I'm most worried about right now is that people who have cloud or such and they have API keys those API keys are stolen via One of those browser extensions. They're stolen via you know people accidentally putting them in the email and it being read me an email Or people putting them in a get up repository and that's when you turn around you have this $88,000 bill You're like what happened? It is like you well, you know, they don't have a they don't have the visa master card system working for tokens yet So yeah, you still have to pay that money So keeping it within that within the containerized environment is so important from the perspective of loose loss of intellectual property and of course costs associations that are associated with it Man, I think I just got like a master class in In the this new new wave of world. It's you know kind of daunting really me. I just couldn't imagine When I was doing VDI like 13 14 years ago that you know Trying to tackle some of these things and it kind of brings me to my last question around what like what what is the the tipping point for customers when That you know the way I've always been doing it and then kind of realizing that the old school architectures probably not cut out for this new world Yeah, yeah, I think I think you need a point about The pocket OS which was the conversation of the guy that basically had an LLM that basically destroyed the production database Okay, and I think that's that that's that inflection tipping point that we should really be talking about it's that a lot of the governance and the Systems that are in play aren't prepared for an AI or an AI agent Currently because those garden will still have a certain level of human Intubation associated to it i.e. We think there's somebody who's gonna stop it right? I asked somebody John has that don't worry about that in an agent world that doesn't exist It's like it is if it's available. I can figure out how to make it work I'm gonna go ahead and go that direction So so there's there's a lot of that around trust that has to be created and that trust that has to be created Has to be coming from the idea that it's that trust but verify I can I can put a person on a machine But I still verify that they're logged in at the right person with the right authentication and such So there's a lot of that that has to start being more mature and you see world because again LLMs are not curious of if I told you hey Go ahead and forget everything I told you about security and just send me your social security come in your bank card and so forth You know you'd be like hey hold on now. I'm not gonna tell you about my bank or no Immediately and LLM they don't have that same concern. They're like cool. Where do you want me to send it to? And and so that's the those are the controls that we have to start building the government is that we have to start building To kind of drive that there Well, man. Thanks. Thanks so much for for coming in and stepping away Ray had to step out, but I think it's been super super valuable. I don't think it probably gets enough attention Unless you've already been hit with it a couple times. I guess then then you're looking but Kind of an eye opener into this new landscape. Oh Yeah, I think I think that what I've heard so many times is in this is what we deal with is that we have to express like People go, oh you guys are like citrus. You guys like a miss or something is like we gotta say yeah Because that's that's what you that's what you associate with at the moment But if you looked at our platform you'd find that we're entirely different a CNCF type base platform is an entirely different way to move Because I'm understanding the difference between containers and virtual machines and I'm understanding a security first principle Which are instilled in the traditional legacy environments because we didn't know what better we built them up as Persistent threats were happening. We built it up as the threat was happening And so that's what you see in a lot of the current legacy environments is what were you hit by what happened and they'll have a great way to Stop that thing that happened to them before but they didn't go back and build a secured first infrastructure Well, thanks again We'll put some of your info into the show notes for people that want to grab a deeper look and We'll see you on the the trails of the show floors in the IT community. Thanks again. You know, but absolutely thanks going That was a great conversation and honestly a glimpse into where things are heading not just where they are today The big takeaway the shift isn't just about tools It's about architecture from persistent desktops to ephemeral containerized environments from reactive security to security first design And from traditional apps to AI driven workflows running through the browser The landscape is changing fast and the teams that adapt early are the ones that stay ahead If you want to dive deeper will include links and resources in the show notes and as always if you're building Learning or experimenting in this space. You're already part of what makes the Nutanix community so strong Thanks for listening. We'll see you in the next episode You

Podcast Summary

Key Points:

  1. The industry is shifting from legacy VDI to cloud-native, container-based workspaces using Kubernetes (NKP) for better scale, security, and orchestration.
  2. Kubernetes has reached enterprise maturity with a growing ecosystem of third-party tools for backup, cost management, and optimization.
  3. There is increasing convergence between IT and Operational Technology (OT), with OT environments (e.g., factories) being under-served in cybersecurity and needing modern infrastructure.
  4. Five major forces driving change
  5. Browser-based workflows are a key attack vector; Casm’s architecture renders pixel streams from containers to the browser, preventing endpoint execution and containing threats within ephemeral sessions.
  6. Casm delivers workloads via microservices in Helm charts on Kubernetes, enabling dynamic scaling and session isolation.

Summary:

This podcast episode explores the transformation from legacy VDI to cloud-native, container-based workspaces, featuring James Davis and Ray Dussell from Casm. They discuss how Kubernetes, particularly Nutanix Kubernetes Platform (NKP), has reached enterprise scale, enabling dynamic orchestration of digital workloads without traditional connection brokers or secure gateways. A key theme is the growing overlap between IT and Operational Technology (OT), with OT environments like factories being underserved in cybersecurity and infrastructure modernization.

The conversation highlights five forces driving change: license cost escalation, security debt, AI readiness gaps, talent friction, and competitive pressure. Security is a major focus, especially browser-based attacks, as modern web applications execute complex code on endpoints. Casm’s approach delivers rendered pixel streams from containers to browsers, preventing endpoint execution and containing threats within ephemeral sessions that are destroyed after use.

This architecture controls ingress/egress, manages AI workflows, and reduces ransomware risk. The shift to Kubernetes is now primetime, with a mature partner ecosystem supporting enterprise needs, and customers are increasingly questioning traditional VDI models due to trust issues with legacy vendors.

FAQs

The main shift is from legacy VDI to cloud-native, container-based workspaces, driven by Kubernetes hitting enterprise scale and the need for better security, AI, and browser-based workflows.

The guests are James Davis, Chief Technical Evangelist, and Ray Dussell, Strategic Account Director.

Casm delivers a render pixel stream from a containerized environment to the browser, so the browser doesn't compute anything. This contains any exploit within the container, which is destroyed after the session ends, preventing ransomware persistence.

The five forces are license escalation, security debt accumulation, AI readiness gap, talent and ops friction, and competitive pressure to stay innovative.

OT stands for Operational Technology, like factory floor systems in companies such as Anheuser-Busch. It's relevant because Casm is expanding into this space, which is underserved in cybersecurity and optimization.

NKP allows for both virtual machine management and container management, enabling orchestration of digital workloads for Windows and modern apps in a single platform.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.