Podcasts about cloud act

  • 141PODCASTS
  • 208EPISODES
  • 37mAVG DURATION
  • 1EPISODE EVERY OTHER WEEK
  • Sep 1, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about cloud act

Latest podcast episodes about cloud act

ChannelBuzz.ca
Frank Balonis on why Canadian partners need to start CPCSC prep now, and what CMMC taught us

ChannelBuzz.ca

Play Episode Listen Later Sep 1, 2026 25:03


Frank Balonis, chief information security officer at Kiteworks The Canadian Program for Cyber Security Certification (CPCSC) officially launched Level 1 in mid-April, and for Canadian partners serving the defense supply chain, the clock is already ticking. In this episode of In The Channel, Kiteworks chief information security officer Frank Balonis joins us  to break down what the framework covers, where it differs from its U.S. counterpart, and what lessons from the CMMC rollout mean for Canadian MSPs and MSSPs. Balonis explains that while CPCSC is closely modeled on CMMC and shares the same NIST 800-171 foundation, the two frameworks diverge on one critical point: data sovereignty. Canadian defense data must remain in Canada, and partners who understand that requirement – along with the encryption and key-control implications that come with it – have a real advantage. The bigger opportunity, Balonis argues, lies in the cross-border play. Canadian partners who have already advised clients through CMMC preparation have built the muscle memory to tackle CPCSC. Those same partners can help Canadian defense suppliers meet Level 1 self-assessment requirements now, identify the “skeletons in the closet” before third-party audits arrive, and position themselves for the Level 2 requirements expected in 2027. Unlike CMMC, which paused and relaunched as 2.0, CPCSC is already live with a shorter runway. Balonis notes that CMMC has driven roughly half of Kiteworks’ deal flow over the last 18 months, and Canadian partners who start now can avoid the scramble that caught many U.S. contractors flat-footed. His core advice for partners: start with governance, not dashboards. Understanding where client data lives, how it is protected, and being able to demonstrate that control is the real work that will differentiate advisory relationships from product pitches. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca, and your host for the show. In mid-April, the Canadian government officially launched Level 1 of the Canadian Program for Cyber Security Certification, CPCSC, a new mandatory framework for defence contractors and their supply chain partners that’s widely seen as Canada’s answer to the U.S. CMMC program. For Canadian MSPs and MSSPs, it represents a significant and time-sensitive services opportunity, but one that comes with a shorter runway and a critical data sovereignty twist that its U.S. counterpart never had to address. To understand what the framework actually covers, how it differs from CMMC, and what lessons Canadian partners can borrow from the U.S. rollout, I sat down with Frank Balonis. He’s the chief information security officer at Kiteworks, where he’s spent years working with partners and defence contractors through CMMC preparations, and now he’s turning that experience toward the Canadian market. Let’s get right into it. My chat with Frank Balonis. Frank, thanks for taking the time. I appreciate it. Frank Balonis: Glad I could be here. Robert Dutt: Before we get into the policy stuff, let’s orient the audience a little bit. Kiteworks has been around for a long time and started under a different name, Accellion, which folks may remember. But can you kind of give me the nickel tour of where you’re at and what you do as a company today? Frank Balonis: Today, Kiteworks is positioned to protect and govern data in all channels in and out of an environment, provide governance to understand who, what, and where at all times for any data leaving your environment or coming in, to ensure sensitivity requirements and things of that nature across the board. Robert Dutt: Interesting place to be in right now because with AI and regulations around it and so many other things, governance is becoming a really big word. Frank Balonis: Yes, it is. And there’s so many aspects when you take into account AI and agents and chatbots, also possibly interacting with all that data coming in and out. It’s a bigger and bigger field out there. Robert Dutt: And tell me a little about your role. It’s kind of unusual to have a CISO as a guest voice on the show. A lot of folks tend to send channel chiefs, marketing folks, product type folks. Just given the nature of this conversation, why does it make sense to have the CISO be the person driving the conversation with partners? Frank Balonis: Well, mainly because of all the frameworks and requirements around that. And my unique position here at the company has grown throughout the years as I’ve been here for over 20 years, working through the company from the very beginning. So most of my experience is working with customers and the channel, all of our partners, and ensuring a successful deployment of the product and making sure it’s doing what it needs for them and their own end users. Robert Dutt: Okay. Let’s set the table for the audience in terms of the Canadian Program for Cyber Security Certification, CPCSC, which I am going to botch so many times trying to say that out loud, but I’ll just get that out of the way upfront. Officially launched Level 1 in mid-April. It’s an ongoing process. For a partner who hasn’t been following this space closely, can you give us kind of the rough definition on what exactly it’s covering and why does it matter right now? Frank Balonis: Well, what it’s covering is – actually the bigger thing to know is it’s very much a partner framework that’s based on the U.S. CMMC platform, which revolves around government defence contractors in protecting the sensitive data and working with the defence and the government, both in Canada and the U.S. It’s actually based on the same framework as CMMC. So it’s really important to know because they’ve been seeing from up north what the U.S. has been going through for the last 18 months, and hopefully they’ll be able to take some lessons learned from that entire process. Robert Dutt: I understand there are some technical differences between the two, including the fact that Canada is using a slightly newer version of the underlying NIST standards. How close is the Canadian standard that’s rolling out to the U.S.-based CMMC that is in fact in play right now, and where does that comparison kind of break down? Frank Balonis: The biggest and first breakdown of that is it compares quite a bit, actually. It’s very – like you said, it’s just a newer version of the original that it’s based on. So it’s extremely similar. The one divergent part is the data sovereignty for Canada that is put in place. The CMMC in the U.S. is more about protecting the data. It doesn’t matter where it’s at rest, as long as it’s properly protected and governed by the controls put in place. Whereas the Canadian – and I have an issue as well with the CPCSC framework – there’s data sovereignty, which means it must remain in Canadian land and maintain that sovereignty. Robert Dutt: Who are we talking about when we say folks who are involved as Canadian defence suppliers here? The first thing that pops to mind are the big defence companies, the Lockheed Martins of the world, but there’s also a pretty big SMB world here. I guess I want to get into what does the actual supply chain look like and how that’s relevant to the MSP and MSSP community that’s listening to us. Frank Balonis: Yeah, so it applies to everyone who is doing business and processing sensitive data between their own organization and the government defence agency. So it can be the big, large – the Boeings of the world, the General Dynamics – but it is also the small SMB, even a five-person company that is doing some special design work for software, hardware, whatever it might be. They’re all tied into the same framework. Now, there’s going to be various levels. As you mentioned, Level 1 is in play right now. Level 2 will be later and so on until Level 3, very much similar to CMMC. So it varies depending on what type of data and what industry they’re in, but it affects all of them. Robert Dutt: How do those levels ramp over time? What’s the dividing line between Level 1, Level 2, Level 3? Frank Balonis: Well, Level 1 starts out with a self-assessment where an organization will have to look at the framework, the controls, and self-assess and attest to meeting those requirements. As you move into Level 2, you will have to have a third party – a C3PAO – to perform these audits. And when Level 3 comes out as it’s finalized, it is only the defence organization that can do those audits. And that’s still, as you mentioned, in progress. Robert Dutt: Okay. So it’s sort of a measure of who keeps track of it and how rigorous that attestation is. Got it. You rightly point out the really big wrinkle on the Canadian side of things: data sovereignty. It means you can’t just take Protected B data in Canada and put it on a U.S.-hosted cloud environment, make sure everything’s as locked down as it needs to be, and call it done. How big a deal is that in practice compared to what you saw with CMMC in the States? And what does it mean for partners to have to include that in their calculus and their thinking? Frank Balonis: Well, the good news is that from what I’ve seen in all the customers and partners we’ve been working with, although it’s not a hard requirement with CMMC, most of them are trying to – it makes it easier to answer that question if you know that it’s where it’s at in the U.S. and safe. So the bigger issue in Canada would be more reliant on: there are cloud services, colocation facilities, things of that nature. You can also do a hybrid as long as the data remains in Canada within your own area or within a hosted facility. Of course, there are also concerns of the CLOUD Act and issues in that manner. And that’s why you would need to ensure that you are specifically – these can be addressed with other technologies such as encryption at rest and things of that nature that would protect you from having to worry about that. Robert Dutt: That’s kind of a generally overhanging concern though. It’s not necessarily specific to this particular regulation. It’s an industry-wide thing if I’m not mistaken. Frank Balonis: 100%. I deal with this globally all the time and we work together to provide the right tooling and controls to ensure that you can meet the data sovereignty and you do not have to be concerned about the CLOUD Act. Robert Dutt: That must be a super fun challenge given the array of countries that have various regulations that are going in various directions at various times and the propensity of those to change. Frank Balonis: Yes. That’s why the important part that we always work with our customers and partners on is understanding that – making sure that the customer, the end user itself, that organization has full control of their data by controlling the keys, maintaining awareness and control of where the data is, how it’s stored. It allows them to address any framework or global requirements. Robert Dutt: So let’s take away some of the lessons if we can from CMMC and that experience. You guys have been living with CMMC since the early days of the rollout, working with defence contractors, partners through the whole experience. Looking back, what actually happened in the U.S. market when it landed and became law of the land? Did the partner community step up and help solve the problem? Was it chaos? What did we experience? Frank Balonis: Actually, a little bit of all of the above really. There was a lot of chaos. There’s still a lot of chaos, honestly. As you understand the scope and the breadth of all of the companies that are going to be in focus for both of these frameworks, there’s still a lot to be learned. But there are a number of partners and MSPs that have understood really where to lock in on what these requirements are. At the end of the day, in the U.S., for instance, the CMMC was actually just another enforcement of something that was already required of the contractors with the NIST SP 800-171. They were already required to meet those. CMMC was just a more rigid framework that has to be completed, whether it’s your own self-attestation or third party. So there’s the aspect of that. Once you understand these requirements have already existed and that the main point of this is governance and evidence to prove that you are following these controls – where the organizations focused on that, as opposed to just trying to cover everything, they succeeded in making this a successful program for a number of our customers. And I’ve seen it in how they work with other companies and vendors to do the same thing. So focusing on the governance part is where it needs to happen. Robert Dutt: Any other common threads that you saw among partners who built successful practices around CMMC, or around customers who are subject to CMMC? What did those partners do differently – technical services, different service models, a go-to-market thing, a combination of any of that? Frank Balonis: There was a lot of go-to-market. We see not only with just us as a vendor, but other partner vendors that we have working with our partners to build an entire framework to help meet the needs of CMMC. Technologies like Kiteworks and other security platforms, they can meet a majority of the controls, but there are some areas that it doesn’t make sense or it just doesn’t fit, that they can meet all the controls. So bringing all of those together and understanding the controls and staying focused on those was what drove the success that we’ve seen in putting together an entire ecosystem to properly provide the evidence and the governance over the platform and your environment. Robert Dutt: Okay. Your own data for the CMMC experience shows some pretty sobering numbers – less than half of contractors feel prepared for Level 2 and more than half still haven’t done a gap analysis. I’m curious if you think Canada is tracking along a similar way. Are there any signs that we’re better prepared because folks have been able to sit back and watch the experience in the U.S. and kind of seeing where the mines are in the minefield? Frank Balonis: Yes, I think they’re going to be in a better place as long as you learn from history and are able to move forward. As we see in the close proximity of the two countries, the fact that those two frameworks were actually purposely built off the same framework for that commonality – I’m already working with partners and customers from Canada that need to meet the CMMC requirements. So those organizations already have a leg up because they already have all of these things in place. Now they may have to make adjustments because of the sovereignty rule that we talked about earlier, but it allows them to quickly address these needs. So as long as they’ve been paying attention to the neighbours down south and enacting these things, they’ll have a leg up on where the U.S. was a few years ago with CMMC. The downside is they have a shorter runway to do it because CMMC launched and then they paused and then they launched again with CMMC 2.0 and they built through all of that. Whereas CPCSC is already live and continuing to move forward, and you have to meet requirements as soon as this summer and sooner than later you’re going to have Level 2 requirement and a Level 3 requirement, depending of course where you are and what data you’re working with. So it’s something one has to be on top of fairly quickly if one is affected or working with organizations that are. Robert Dutt: Absolutely. And a lot of the partners – one of us actually earlier working with a partner that is out of Canada to provide services for CMMC – we have these partners that understand exactly how you need to move forward in addressing these things. So as long as the partners have a very good future of being able to help their customers, as long as they’ve been paying attention, they’ll be able to help these organizations that don’t have a compliance person, they’re too small of an organization, they don’t have all of these things in place, and they are going to have to rely on these partners to help them out. I wanted to expand a little bit on what you were talking about with the kind of cross-border opportunity. You flagged it with partners who are in Canada, who today have some experience working with CMMC, they’ve built up some of the muscle memory to deal with CPCSC as it comes online. I imagine somewhere down the road in the not too distant future, by the sounds of it, we’re going to have Canadian partners who are CPCSC certified, who are therefore partially down the road to understanding and being able to solve for CMMC. How much of that – how real is that cross-border bidding opportunity and how should a partner be thinking about positioning that? Frank Balonis: I think there’s a real opportunity there because the partners up north might not have been able to be the third-party auditors for CMMC, but they could be the advisors. As long as they’re working through all of that, they could take their experience from being advisors to their customers to prepare for CMMC and convert that into the ability to actually work with auditors for the CPCSC and help implement that. Where, again, a number of our customers utilize this – since there isn’t that sovereignty requirement with CMMC and there is that natural instinct of an organization that wants to stay completely in control, they already have their data up in Canada, which means they’ve already got a framework in place to meet the CMMC requirements for the U.S. and they can easily convert that to CPCSC very, very easily. So the best advice I could give to an organization is to properly vet and find a partner that has that experience and can quickly work with you to get you up to speed because, as we mentioned, they have a much shorter runway to get there. They can’t start at the beginning. They have to find someone that’s already been doing this for a while. Robert Dutt: If I’m a Canadian MSSP or a security-focused VAR listening to this right now, I’ve got a general security practice. Maybe I’ve been doing some compliance work in regulated industries. Where do I actually start with this? What’s the first conversation I should be having with my clients and what does engagement around CPCSC or CMMC look like in practice? Frank Balonis: It really starts with understanding whether they know where their data is and how that data is being protected. That is the biggest part of all of that. Working with the partner to understand what these requirements look like, where their data is, is the first place that I would really focus on because, again, the most important part is not a dashboard but the governance and the evidence of it and making sure that you control this. Robert Dutt: What’s kind of the best practice guideline, shall we say, for timelines? I imagine because of the nature of this, it’s not the kind of thing you want to be looking at that deadline and planning to slide in right at the deadline to reach compliance. You want to have some runway to make sure that all of your assumptions along the way have been correct, shall we say? Frank Balonis: If I was an organization up in Canada right now, I’d already be looking for a partner to help. Maybe not specifically setting any kind of deadlines other than the fact that you understand certain requirements are going to be in effect this summer. So the sooner you get on this, the faster, the better. So yesterday is the time to start on this, but if you can’t start yesterday, start today. That’s the best advice I could give because there’s always going to be those skeletons in the closet of, “Oh, I forgot about this,” or “Where is that?” As you start walking through the framework with your partners and understanding the controls, you are going to uncover things that you need to address as quickly as possible. Very similar to CMMC, you will have very little room to have any kind of out-of-control controls, so to speak, any findings or nonconformities depending on what framework you’re looking at and what type of audit. The area for margin is very small. Robert Dutt: Along that note, the last one for me: Level 1 is self-assessment, which is relatively accessible, I would think. But Level 2, you’re getting third-party assessments and that clock is ticking toward April 2027. Sort of along the same lines as the last question, but what’s basically your message to the Canadian partner community about the window of opportunity that exists right now? Frank Balonis: I would, for the folks that are going to be required for Level 2, I would do the Level 1 as soon as possible for you to understand where your gaps are. And you can attest to have your controls in place, because when Level 2 comes, the more information you already have by running through your own internal audit, which is effectively what a Level 1 is, the quicker you’ll be able to close those gaps and understand what you need to do before 2027 comes up on you. I personally, we’re working on consolidating a huge number of audits into a single one, and I’m already nervous that we’re three months away and still looking at a few things to complete all of them. We’ve done all of these individually, but we’re bringing them together, and that’s where you start seeing your gaps in between different organizations, different architectures. So the sooner you understand where you are, the sooner you can close those gaps and meet the requirements for Level 2. Robert Dutt: Sound advice. I appreciate it. Thanks for taking the time to walk us through the situation as it is and the opportunity out there for partners. Frank Balonis: My pleasure. I’m glad I could do this today. Robert Dutt: There you have it. Frank Balonis from Kiteworks. I’d like to thank Frank for his time. A couple of things from that conversation that I think are worth sitting with. First, the urgency. Balonis was clear that unlike CMMC, which paused, restarted, and gave the market time to catch its breath, CPCSC is already live and moving toward Level 2 third-party assessments. If you are a Canadian partner waiting for the phone to ring, you are already behind the partners who started this work six months ago. Second, the governance point. The line that stuck with me was that the important part is not a dashboard, but the governance and the evidence of it. In a market that loves to sell tools, the real compliance opportunity is advisory: helping clients understand where their data lives, how it is protected, and being able to demonstrate that control. That is a services play, not a product play. And third, the cross-border angle. Canadian partners who built CMMC advisory muscle with U.S. clients have a head start that is actually hard to replicate. The frameworks share the same foundation, and the sovereignty requirement is a wrinkle, not a wall. The firms that can bridge both sides of the border are going to be the ones that win the long-term compliance relationships. I’d like to thank you as always for listening to the show. Follow or subscribe wherever you get your podcasts – Apple Podcasts, Spotify, YouTube, most directories. Ratings and reviews are always appreciated and always help. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

ChannelBuzz.ca
Red Hat’s Kennedy on why the swim lanes are gone – and what the partner program looks like now

ChannelBuzz.ca

Play Episode Listen Later Aug 26, 2026 32:26


Kevin Kennedy, vice president of global partner ecosystem at Red Hat The channel has fundamentally changed – and for a long time, Red Hat‘s partner program hadn’t caught up. That’s the candid starting point for Kevin Kennedy, who joins In The Channel this week fresh off his appointment as Red Hat’s vice president of global partner ecosystem. Kennedy’s career spans just about every layer of the channel – direct sales at IBM and Xerox, close to a decade at Arrow Electronics, and leadership roles at VCE, Dell EMC, and TD SYNNEX before joining Red Hat in 2022. That perspective shapes how he talks about the shift from a model built on clear “swim lanes” – where resellers, services partners, and software sellers all stayed in their own lanes – to the multi-partner, collaborative engagements that define how business gets done today. “It’s really hard to even define a partner today,” Kennedy says. “We can’t go to market by ourselves any longer.” Red Hat’s program refresh responds to that reality with a bifurcated incentive structure: front-end rewards for individual sellers at the deal level, and back-end incentives for firms making deeper investments in Red Hat competencies. Kennedy is direct about what drove the change: “We were putting all of our rewards around the resell of our products. And that ship had sailed.” The conversation also covers the Broadcom/VMware disruption as a modernization opportunity rather than a rip-and-replace play, where AI realistically fits in the partner revenue picture right now, the evolving role of distribution as an ecosystem aggregator, and – for Canadian partners specifically – the growing urgency of data sovereignty as a go-to-market factor. And Kennedy offers a memorable frame for Red Hat’s long-term platform ambition: “Red Hat inside” – the idea that Red Hat increasingly underpins solutions partners build and customers buy, whether or not the name is on the box. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. My guest today is Kevin Kennedy, vice president of the global partner ecosystem at Red Hat. Kevin’s career spans just about every seat in the channel: direct sales at IBM and Xerox; the better part of a decade, on and off, at Arrow Electronics; leadership roles at VCE and Dell EMC; and then about five years running advanced solutions at Tech Data and TD SYNNEX before coming to Red Hat in 2022. That’s a resume that takes you from carrying a bag, through distribution leadership, to vendor-side ecosystem strategy. That full-channel perspective shapes how he thinks about the partner business in ways that are pretty evident in this conversation. Red Hat recently named him the permanent head of its global partner ecosystem, and the word “ecosystem” in that title is deliberate, as you’ll hear. We get into how the partner business has fundamentally shifted from the old swim-lane model to something much more collaborative and complex; what Red Hat is changing in its partner program and why; the VMware modernization opportunity; where AI realistically fits in the partner revenue story right now; and what data sovereignty means for Canadian partners specifically. Let’s get right into it, my chat with Kevin Kennedy. Robert Dutt: Kevin, thanks for taking the time. I appreciate it. Kevin Kennedy: Thanks for having me, Rob. I appreciate being here. Robert Dutt: You’ve been in so many different seats facing the channel, from starting in direct sales at IBM and Xerox, to distribution, and now, of course, the vendor side. I’m curious: when you look back at the arc of the channel, as it were, over that time, what’s the biggest way the partner business has changed since you started looking at it and watching it closely? Kevin Kennedy: That’s a great question, because there has been a significant evolution, that’s for sure. I think it starts with the definition of what a partner is. It used to be that you had very clear swim lanes. You had resellers, you had services partners, and you had people who always sold software or people who always sold hardware. Everybody had their individual lanes, and that was predominantly the way the channel made money: through the resale of all those things. If you fast-forward to today, it’s completely different. It’s really hard to even define a partner today. You can’t put them in one camp. Take a larger partner like WWT, for example. It used to be the preeminent reseller for a myriad of OEM lines. Today, that may be just a portion of its business. If you look at its total bottom-line profitability, I would say the vast majority of that comes from the services it offers and the contracts it manages for very large customers. Partners have evolved. We used to be able to go sell something individually. With the complexity that now exists in technology and the solutions that customers are demanding, we can’t go to market by ourselves any longer. We’re forced to collaborate and build relationships outside of our historical domains in order to present a customer with a holistic solution that’s going to drive the outcomes or efficiencies they demand. I think all of that dynamic is great. We talked about multi-partner engagement for decades and couldn’t get it to work because, realistically, we were all competing for the same nickel. If I went into a customer with you, likely one of us would get cut out of that deal or eventually be eased out. Today, that’s not true. We’re really dependent on each other. You bring your strengths to the table, I bring mine to the table, and those combined strengths are what the customer is going to realize. I think that’s the exciting component that’s really changed dramatically, especially over the last 10 years, and even more so over the last five. Robert Dutt: That speaks to the fact that you’re coming in as vice president of the global partner ecosystem, rather than vice president of channel sales or vice president of partner programs. I’m guessing, especially from that latter point about the co-sell and multi-partner arrangement becoming much more accepted and more of a default, that it’s a meaningful and purposeful distinction. What changes day to day when you call it an ecosystem, or when you think of it as an ecosystem, rather than a channel? Kevin Kennedy: I think your point is well made. The title and our nomenclature – ecosystem versus channel, or ecosystem versus partner – are intentional. Again, it goes back to illustrating the necessity of multiple people with varying levels of expertise in a variety of domains. All of them are required to bring a customer a solution and drive an outcome. It actually makes things more complex in some regards. From my lens, at the end of the day, what do we want to sell? We want to sell Red Hat products and our platforms into a customer. In years gone by, that might have been a much more simplistic arrangement. Our sales teams would call on a customer, represent only what we’re good at, and get that deal done. That no longer remains the case. I have to make sure we’re selling the value of Red Hat’s portfolio not just to the customer. I’ve also got to make sure the systems integrator sees how we can bring value to the solutions they’re going to represent to their customer base. I’ve got to represent the value of Red Hat to the hyperscalers – why they should care about us and how we may drive consumption in their marketplaces. I’ve got to bring value to the distributors and explain why they want to put resources around our product portfolio. I need to show them how our portfolio is going to help accelerate some of the more profitable lines they represent. On one hand, the ecosystem model illustrates the necessity for all of us to come together. On the other hand, it invites complexity from a go-to-market standpoint because everybody’s my customer. That’s traditionally been true in distribution, where a lot of my heritage comes from. We used to have the adage that we’re nobody’s customer and everybody’s customer, because I have to constantly sell the value of why we exist and why we should matter to you, and how we can help you be successful. Robert Dutt: That must make it an interesting challenge to structure programs when it’s no longer as simple as, “You are a reseller, therefore you fit in box A.” Now you’ve got to get creative with your programs and incentives in order to keep partners excited about what you’re doing, engaged with your platforms, and recognizing where you’re headed and why that might be valuable to them. Kevin Kennedy: I’ve got to construct a program with incentives that look at presales and the whole customer-management lifecycle. It’s no longer just, “We’ve got a product and a contract for that product that’s going to be sold.” Now I’ve got to think about adoption. I’ve got to think about how we make that product more pervasive through an organization. I’ve got to ensure that everything we said was going to be done when we presented the solution is actually coming to fruition, so the customer sees a return on that investment. If they don’t, I’m going to be a one-and-done. If they do, it’s going to give me an opportunity to have conversations around other things we can bring to bear that might provide similar or even better outcomes than what they did initially with us. Robert Dutt: When you did the program refresh, you said it was built around simplicity, predictability and profitability – three words that come up a lot in channel chief conversations, for obvious reasons. I don’t think those are unique to Red Hat, but along with what you’ve already touched on, what did you see or hear from partners about what they were experiencing that made those changes the priority at this time? Kevin Kennedy: That’s a good question. When I joined Red Hat, I observed that we weren’t necessarily meeting partners where they were. We were still thinking about the way things had been in years gone by. We were typically putting all of our rewards – and, by the way, they were plentiful – around the resale of our products. That ship had sailed. The ecosystem had evolved considerably, but we hadn’t necessarily evolved with it. What we tried to do, especially with the incentives we launched in January, was meet partners where they are. That means we have to bifurcate our incentive structure. We’ve got sellers at those partner organizations, and we need to make sure we’re targeting incentives on the front end, at the deal and transaction level, to get them excited about moving Red Hat products. Primarily, I look at that as a great opportunity for customer acquisition. There are a lot of places where we haven’t been, and those sellers are going to be able to introduce us to those customers. They have respected and long-tenured relationships that are going to help us land our objectives, which is to have the Red Hat portfolio consumed there. Similarly, we’ve got to make sure we’re incentivizing the firms to make the investments necessary to upskill their people and ensure they have the technical requirements and technical capabilities to deliver our solutions. We’re showing them a path from whatever managed services they currently provide in the enterprise to how they can include Red Hat as part of that. That’s going to be accretive to their service capabilities and to their profitability. We’re ensuring that we have both the front end and the back end covered. Again, we’re meeting partners where they are in the market, rather than saying that we only care about what they’re going to do for us from a product standpoint. We recognize that services are probably the most profitable component of their business. How do we translate the sale of our products into an increase in their services business, which is going to be accretive to their overall profitability? Robert Dutt: The nice part about that approach, even if you are coming from playing catch-up a little bit, is that there isn’t quite as much need to educate or incentivize partners to come around to where you’re going. You’re setting it up based on where they’re at today. Kevin Kennedy: Exactly. Recognizing that partners need a lot of hand-holding and a lot of our Red Hat engagement isn’t necessarily true. In many cases, partners have a level of sophistication that’s beyond what we would even address in a traditional enablement program. Now it’s about leveraging all those skills and competencies and translating them into what that means for Red Hat and how that accelerates adoption of our portfolio. From a partner standpoint, what does our portfolio mean to them in terms of plugging into what they’re already doing from a go-to-market standpoint? It puts more bullets in the gun when they’re talking to a customer. Robert Dutt: One of the areas of opportunity right now has to be the whole Broadcom-VMware situation, which has created a lot of disruption for partners, customers and pretty much everyone. Red Hat is obviously positioned well in that space, but capturing the opportunity through the channel is different from simply having the right technology on the shelf. How are you helping partners have that conversation with customers, especially those who are frustrated and interested in other options but aren’t necessarily ready to make the big jump? Kevin Kennedy: When the whole Broadcom situation first transpired, I think we all saw it as a generational opportunity to make a land grab. We all had varying degrees of success. And when I say “we all,” I don’t just mean Red Hat, but others that play in this space as well. Where we’ve seen a tremendous acceleration in our opportunity is by changing the conversation. When we go out with one of our partners and talk to customers about what they’re doing from a virtualization perspective, it’s no longer simply about moving off VMware onto Red Hat, for instance. It’s about modernization. It’s about making sure that the customer is prepared for its technology journey – moving from virtualization and modernizing its data centre toward the AI conversation that I’m sure we’ll get to in a moment. Red Hat and our partners can help customers on that journey and accelerate it without requiring a rip-and-replace approach or a complete transformation of their entire infrastructure. They can leverage the things they may do with us today to move off VMware and into a more modernized, virtualized, containerized and Kubernetes-based environment. That prepares them to take the next step into AI. It’s not a step back. It’s not a step sideways. It’s a step forward from their initial investment with us. Robert Dutt: It is 2026, and we’ve been talking for 12 or 13 minutes now, so I am legally required to ask an AI question at this point. You’ve been pretty straightforward in saying that virtualization, automation and hybrid cloud are still the real revenue drivers, while AI is more of a near-future opportunity. I respect that honesty, and I think it probably maps closely with what partners are telling you about where they are today. But where does that leave the partner who’s getting pressure from customers to have an AI story right now? Do you lead with the infrastructure story, or do you lead with AI and then backfill toward virtualization, automation and hybrid cloud? Kevin Kennedy: I think we lead with the hybrid modernization and automation play first, and then segue into the AI discussion. Part of what we’ve seen over the last year, especially, is the need to separate AI reality from AI hype. Everybody talks about AI, and I think the pockets of success have come from partners who are listening to customers and giving them the counsel and advice that they don’t need to boil the ocean. Let’s start with some very specific processes that the customer could look to automate by leveraging AI technology and Red Hat technology. Then the customer will be able to see an immediate win and a return on that initial investment. From there, we can see where to grow. For most customers, it’s not too different from us as consumers. We think of AI and ChatGPT, and all of these things where we’re going to be able to ask a whole bunch of questions and get smart answers back to help inform us about where to go. For a lot of customers, that’s debilitating. They don’t even know where to start. The whole thing is a massive labyrinth of issues they’re trying to sort through. Every partner that can go in and provide consultative advice – saying, “We don’t need to look at everything. Let’s start with some very direct things that you say require a lot of manual intervention or take up a lot of cycles” – can leverage AI technology to circumvent a lot of that. They can make processes that took weeks or months translate into hours or minutes. What productivity increase do you see as a result? That’s an immediate win and a return on the initial investment. I think the partners that understand what collaboration looks like in this space are also going to be successful, because AI forces us to talk to others and play well with others. Even for us, we’ve enjoyed a lot of recent announcements around collaborative partnerships with NVIDIA, Dell, Cisco and others. We’re doing these things together. It’s not because we each woke up one day and said, “I really want to build a partnership with NVIDIA,” or, “I really want to build a better partnership with Cisco.” We were forced to have those conversations because of the outcomes customers expect. We realized that while we have a really important and robust piece of the solution, it’s only a piece of the pie, and the customer wants the whole pie. How do we orchestrate and architect it together so that we collaborate and go to the customer together and say, “Here’s what we can do for you. Here’s your whole pie”? Robert Dutt: You spent years on the distribution side, as you said earlier. A lot of your career was spent there. Now you’re managing some of those same companies, or the companies they’ve become over time, as a vendor. I’m curious: has your background in distribution changed what you actually ask of distributors, or what you think vendors typically ask of distributors but either shouldn’t or should ask more of? Kevin Kennedy: I tell anybody who wants to be involved in the ecosystem that if you’ve worked in distribution, that’s your MBA of channel engagement. You learn so much because, when I was at TD, for instance, I was doing business with every major OEM in the world, each with different expectations and demands. I was running a business on basis points. Understanding how to get the greatest efficiencies in the sales model and how to reap the greatest amount of profit in order to continue investing in the business prepared me better for the ecosystem role I have today. Even when I got to Red Hat, I think the way we leveraged distribution was much more traditional. We appreciated distributors for the financial piece they brought to the equation. That continues to be a critical thing that distribution adds to technology in general: they’re a financial backbone for a lot of the investments we’re all making. But distributors were also viewed as providing logistics and operational efficiencies. While that’s still part of what they do, it’s just a small part of what they do today. I look at distributors as aggregators. We talked about how one, two, five or seven partners may touch every transaction a customer buys. There’s no better place to bring all of that together than within distribution. Distributors have developed their own great level of sophistication. They’ve got technical expertise across multiple vendor lines. They’ve made tremendous investments in AI on their own, and they have specialists who are trained, competent and capable. I’m leaning on them to do a lot of the enablement for me. When I look at how we go to market with all these different partner types – whether it’s hyperscalers, OEMs, GSIs or ISVs – I can go to distribution, which is also doing business across all those same partner types, and say, “How do we work more effectively together to develop a really cohesive go-to-market strategy?” The distributor is the aggregator. It can go to the partners we all share in common – the WWTs, CDWs, Softchoices and Mobias of the world – and say, “How can you bring all this together for us to present to these partners, so they can go talk to a customer and have a holistic solution to put in front of them?” Distributors represent that capability for me. We’re leaning in hard with distribution, certainly on the legacy and traditional things they bring to bear, but more importantly on the forward-looking investments they’re making in their own enterprises that are going to help accelerate partner adoption of our solutions. Robert Dutt: Close to home, data sovereignty is a major issue for Canadian organizations right now. Between government guidance and some muscle being put behind that, there’s a growing concern about where data resides and the whole CLOUD Act question. Do you see that showing up in partner conversations in Canada, and how does Red Hat’s story change in that context, if it does? Kevin Kennedy: It’s a prevalent and very relevant conversation today in Canada, certainly in EMEA and APAC – essentially everywhere outside of the United States. It’s forced us to re-evaluate how we’re going to market in those environments. It changes the perspective on simply talking about the hyperscalers. It changes the perspective on what a sovereign cloud looks like and who the players are. It’s introducing us to players in spaces such as telecom, where telcos are now looking more like the sovereign cloud providers of the future. How do we build a secure solution, working on a public cloud, private cloud or sovereign cloud provider, that will be required – especially in government and GOE spaces – and provide them with the opportunities they’ll need in the future? It started to emerge perhaps at the end of last year, but it’s now a massive topic of conversation with us, and I think that’s going to continue. When we talk about AI, this is going to be a big component as well. How do we protect this data, and how do we have it reside in a secure environment that’s critical to government agencies and how they operate every day? Robert Dutt: Do you see Red Hat partners as having a major untapped or under-realized opportunity right now? Kevin Kennedy: I still think virtualization is a major, major untapped market. We’re hot on the customer-acquisition trail. Traditionally, we’ve grown through established customer relationships that have been great to us over the years. We’ve made mutual investments in those relationships, and we’re certainly going to continue that. But we’ve got to find new business. I think AI is the accelerant in that. It gives us a forum for conversations around what we’ve built. Anybody who has made an investment in our core portfolio has a springboard to get to where they want to go relative to AI. The partnerships I referenced with NVIDIA, Cisco, Dell, HPE and others are great catalysts for opening discussions with customers who perhaps didn’t know Red Hat before. I sometimes think about it this way – and this is probably an oversimplified way to put it – but for years we all bought laptops that ran on Intel chips. “Intel Inside” was a great marketing ploy for a whole host of reasons. I kind of see Red Hat that way a little bit: Red Hat inside. We’re going to be the underpinning of a lot of solutions that customers are going to buy in the future. They may not even know that Red Hat is running in there, and I’m not sure that we care. We want to be that secure platform that provides mobility from the cloud to on-premises environments, with seamless motion back and forth. We want to provide the level of security that’s going to be required, whether that’s in a sovereign environment or in our current state, where data security is the utmost concern. We want to be the underpinning that allows all that stuff to run effectively and efficiently, and gives customers portability and an open concept. Whether or not the customer actually knows Red Hat is there, I’m not sure that matters that much to us from the customer lens. It matters more in terms of how we’re going to work with some of the other partner routes we’ve talked about, especially given the ecosystem discussion. Robert Dutt: I’m curious what you’d like to see partners doing more, better or differently for the benefit of Red Hat, yes, but especially for their own businesses and where the business is going. Kevin Kennedy: I want to be a catalyst for them to sell autonomously. I think OEMs have often seen themselves in an outsized role when it comes to going to market with partners. We’ve acted as though partners need us in order to deliver the solution, or need a Red Hat badge in order to get validated by the customer. Certainly, there may still be an element of that, but I’ve found that partners’ customer relationships and the trust they’ve already earned with those customers supersede our need to be necessarily involved. I’m looking at ways to pour gasoline on that fire. How can I get out of the way and let partners move at a quicker pace than they may have in the past? Certainly, we’re part of the solution. We want to make sure partners have everything necessary, whether that’s training, enablement, demo equipment, proofs of concept or executive briefing centres – whatever they need to ensure they have the utmost confidence to position a solution that contains Red Hat products in the best light with the customer. But we know partners don’t need our help to have that sales conversation. They don’t necessarily need our help to deliver the services after the sale, to do the migration or to provide managed services, because they already have that expertise. We just need to make sure they feel confident that they can incorporate us into that motion. That’s really my focus, even from an ecosystem program standpoint. I want to put the incentives in a place that accelerates all the things partners are already good at and simply includes us in that motion. Robert Dutt: It sounds from those last couple of answers that you’re quite happy being the underpinning, the foundation behind either the customer solution or the partner’s sales motion. How does that shape what you’re focused on personally and program-wise in terms of what partners can expect from you and from Red Hat over the balance of the year and beyond? Kevin Kennedy: My mantra has been to do more with less. What I mean by that is that the partners who already fit the profile I’ve been describing – those with core competencies and skills, strong market presence, tremendous customer relationships, and investments in upskilling their people with the technical and sales expertise to represent Red Hat well in the marketplace – are the partners I want to invest in to a high degree. The partners who may traditionally have just wanted to put our logo on their website and clicked through to become a partner because they wanted to resell or perform more fulfilment activities – that’s great, and I still want to welcome those partners. But those are not the partners around whom I’m going to build programs or in whom I’m going to invest heavily. They’re not the partners where I’m going to continue putting direct resources side by side with them to win in the marketplace. I want to go deeper and wider with fewer partners who have the investments and skills necessary to bring customers the outcomes and efficiencies they’re looking for. Robert Dutt: That’s a great place to leave it. Kevin, thank you very much for taking the time. Kevin Kennedy: Thank you for having me. It’s been a great time, and I appreciate the opportunity. Robert Dutt: There you have it, Kevin Kennedy from Red Hat. I’d like to thank Kevin for his time today. He’s someone who has thought seriously about how this business actually works from multiple vantage points, and that comes through. Thanks for listening as well. A couple of things I’m taking away from this one. The “Intel Inside” framing that Kevin used – the idea that Red Hat is increasingly going to be the underpinning of solutions that customers buy and partners build, without necessarily being the name on the box – is a significant strategic statement. It’s a bet that being foundational is worth more than being front and centre. It’s worth watching how that plays out for partners who are building practices around Red Hat technology, or potentially are. And the ecosystem-versus-channel distinction doesn’t come off as just a title change. When you’re talking about a single customer engagement that might bring together a cloud provider, a services integrator, a software specialist and a reseller, all at the same table, the question of how you build a program and reward structure around that is unsolved across the industry. Red Hat is working on it, but so are a lot of other people. For Canadian partners specifically, the data sovereignty conversation is one to pay attention to. Kevin was candid that it’s reshaping how Red Hat thinks about going to market outside the United States, and the Canadian regulatory environment is only going to make that more pressing over the next few years. If you found this useful, please follow or subscribe wherever you get your podcasts. We’re on Apple Podcasts, Spotify, YouTube and most major directories. Ratings and reviews are always appreciated. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.

Les Samouraïs de la Vente
#869 - Ciprian Melian, CEO de Dicte AI

Les Samouraïs de la Vente

Play Episode Listen Later Aug 14, 2026 47:19


Et si l'intelligence artificielle n'était pas obligée de compromettre vos secrets d'affaires ? --- Chaque jour, des millions de réunions stratégiques, qu'il s'agisse de comités de direction, de négociations financières ou de projets d'innovation, sont confiées à des assistants de réunion basés sur l'IA. Mais à l'heure du Cloud Act et des fuites de données, savez-vous réellement où finissent vos enregistrements vocaux et vos informations les plus sensibles ? Pour répondre à cette problématique cruciale, accueillons dans ce nouvel épisode des Samouraïs du Business un entrepreneur d'élite : Ciprian Melian, cofondateur de Dicte.ai, groupe Livdeo. Fort d'un parcours remarquable de plus de 11 ans dans le déploiement de solutions technologiques hautement sécurisées pour des institutions culturelles de renommée mondiale, de l'Europe à l'Australie, Ciprian combine une vision métier affûtée et une rigueur technique exceptionnelle. --- Son métier avec Dicte.ai ? Redéfinir l'assistance de réunion grâce à une intelligence artificielle souveraine et éthique. La plateforme capture, transcrit et analyse automatiquement les échanges vocaux pour générer instantanément des comptes-rendus structurés, des résumés clairs ou des grilles d'analyse décisionnelle. Mais sa véritable force réside dans son architecture sans compromis face aux risques de fuites : hébergement sur des serveurs physiques hautement sécurisés installés en France, pseudonymisation par défaut des données personnelles, absence de sous-traitance et intégration d'un chiffrement post-quantique inédit. Lors de cet échange passionnant, Ciprian Melian a exposé cette philosophie d'indépendance technologique et de sécurité absolue qui caractérise son entreprise : "Aujourd'hui nous avons fait le choix de maîtriser de bout en bout toute la chaîne de traitement audio. Ça veut dire qu'on ne fait pas appel à un sous-traitant." Des coulisses de la diarisation de locuteurs à l'optimisation du taux d'erreur (WER), cet épisode technique décrypte les défis d'une IA respectueuse du secret professionnel et du RGPD, plébiscitée par les ministères et les DSI les plus exigeantes.

Silicon Valley Tech And AI With Gary Fowler
Keeping Business Secrets in the Era of Cloud, AI, and Industry 4.0 with Andreas Walbrodt

Silicon Valley Tech And AI With Gary Fowler

Play Episode Listen Later Aug 11, 2026 24:34


Join Andreas Walbrodt, CEO and Co-Founder of enclaive, for an essential exploration of cybersecurity, data sovereignty, and business confidentiality in an increasingly cloud-reliant world. While enterprises have spent decades securing data at rest (in storage) and in transit (over networks), sensitive workloads remain completely unencrypted the moment they are processed in memory. As organizations rush to adopt public cloud platforms, scale Industry 4.0 smart manufacturing, and deploy proprietary AI models, this "in-use" vulnerability creates catastrophic exposure to cloud operator access, third-party subpoenas, and cyber threats. Drawing on over 30 years of enterprise IT leadership at IBM and TÜV Rheinland, Andreas explains how confidential computing closes this gap—allowing businesses to leverage hyper-scale cloud power without sacrificing sovereignty, compliance, or core intellectual property.

Bare Knuckles and Brass Tacks
Designing compute for the edge: Out of the cloud and down on the ground,

Bare Knuckles and Brass Tacks

Play Episode Listen Later Jul 27, 2026 41:59


Cloud computing solved for scale by centralizing everything into a handful of massive buildings. Edge computing is the argument that scale was never the only thing worth optimizing for.On this episode, Jeff MacMillan of Green Edge Computing Corp makes the case that sovereignty was never really about geography. It was about how many entities you'd have to strong-arm before someone gave in.The conversation moves from mining sites with unreliable wireless to a Cloud Act clause most people have never read. It lands on an uncomfortable question: when decentralizing compute means decentralizing oversight too, who ends up accountable for what happens in the box nobody's watching.The same hardware standard the U.S. military spent fifteen years refining now sits in clinics and 7-Elevens, and has implication and applications for bringing cutting edge software to the most remote areas. What does it mean when you can bring your own compute literally anywhere?Mentioned: Jevon's paradox

Omsorgspodden
Samtal från Almedalen: Julia Altenhofer

Omsorgspodden

Play Episode Listen Later Jul 19, 2026 17:00


Vad betyder egentligen AI Act, Cloud Act och nya EU-regler för svenska kommuner och regioner? Julia Altenhofer, VP Public Affairs på Evroc, hjälper oss att navigera i den föränderliga världen av digital lagstiftning, molntjänster och AI – och vad utvecklingen innebär för framtidens välfärd. Inspelat på ett loft i Visby under Almedalsveckan.

Redefining Energy
235. European Sovereign Neocloud - Jun26

Redefining Energy

Play Episode Listen Later Jun 29, 2026 32:11 Transcription Available


Gerard and Laurent welcome Michel Boutouil, co-founder and CEO of Polarise, a leading European AI infrastructure provider and NVIDIA Cloud Partner based in Berlin. After discussing about what happens outside of a datacenter, it is time to dive inside one.  Polarise is one of the few genuinely European NeoCloud companies — essentially a European counterpart to CoreWeave — specializing in GPU infrastructure for AI inference. Through its partnership with NVIDIA, Polarise designs its datacenters around the GPU rack itself, using liquid cooling from the outset rather than starting with a traditional real estate-first approach. The company has already developed AI factories in Germany, Norway and the UK.  In the conversation, we explore the growing commoditization of large language models and why the real long-term value may lie in AI factories — facilities that are fundamentally different from conventional datacenters. Given Europe's notoriously long grid-connection timelines, Polarise focuses on refurbishing brownfield sites with under 50MW of grid access instead of pursuing massive gigawatt-scale campuses. It's a pragmatic “pod” strategy: adapt to the grid's constraints rather than try to reshape the entire energy system.  We also tackle the thorny issue of digital sovereignty. With the U.S. CLOUD Act allowing U.S. authorities access to data managed by American tech companies, it is fair to ask what hyperscalers are doing with European data — and whether Europe needs its own sovereign AI infrastructure. Polarise has secured €1 billion in backing from Swiss investor SWI Stoneweg Icona, but even that is modest compared with the hyperscalers' spending power. For comparison, SpaceX has reportedly invested around $40 billion in Colossus 1 and 2 alone.  So, what does the future of the European AI ecosystem look like? Michel's answer is clear: Europe should not try to outspend China or the United States head-on. Instead, it should play to its strengths — smart execution, agility, flexibility, and the ability to learn quickly from the mistakes being made elsewhere.    “Today's show is supported by the BMW Foundation Herbert Quandt. The BMW Foundation unites leaders across sectors to develop solutions that foster an innovative economy and a future-proof society. A key focus is "Energy Transition & Climate Change," where the Foundation drives "International collaboration to accelerate the energy transition." With rising energy demands from AI and data centres, new partnerships, effective collaboration, and the exchange of science-based solutions and strategies are essential.”  

Datenschutz Plaudereien
DAT407 KI zwischen Bauchgefühl, CLOUD Act und Überforderung (David Rosenthal, Teil 2)

Datenschutz Plaudereien

Play Episode Listen Later Jun 29, 2026 30:06 Transcription Available


Spezialgast David Rosenthal und Martin Steiger diskutieren Rechtsfragen rund um die Nutzung von KI in der Schweiz. Themen im zweiten Gesprächsteil sind unter anderem die Datensicherheit, der CLOUD Act, die Bedeutung von Bauchgefühl und Emotionen, und die Überforderung der Tech-Unternehmen.

The 10Min Trader con Marco Casario
L'Europa CANCELLA Google e Microsoft: il rischio nascosto per i tuoi risparmi

The 10Min Trader con Marco Casario

Play Episode Listen Later Jun 8, 2026 14:38


L'Europa sta cercando di staccarsi dal cordone ombelicale tecnologico americano, ma il prezzo della sovranità è più alto di quanto sembri. In questo video di 12 minuti analizziamo il "Tech Sovereignty Package": dalle istituzioni che abbandonano Google e Microsoft per Qwant ed Euro-Office, fino al rischio legale del CLOUD Act sui tuoi dati personali. Ma c'è un paradosso che nessuno ti svela: mentre Bruxelles scrive leggi per l'indipendenza, i tuoi risparmi (tramite ETF come VWCE o MSCI World) stanno finanziando proprio quei giganti americani. La dipendenza digitale non è solo un tema politico, è l'architettura stessa dei tuoi investimenti. La disclosure dinamica aggiornata è disponibile qui: www.marcocasario.com/disclosure Vuoi lanciare il tuo negozio online?Vai su https://www.shopify.com/it e scopri come iniziare con Shopify in pochi minuti.

Wartungsfenster
Plaintext für alle, Ciphertext für niemanden

Wartungsfenster

Play Episode Listen Later Jun 7, 2026 60:40 Transcription Available


In dieser Folge dreht sich alles darum, wer was lesen kann – und wer nicht. Patrick bekommt eine verschlüsselte Mail von seinem Stromanbieter und kann sie nicht öffnen. Die Niederlande stellen fest, dass Microsoft Behördennamen ungeschwärzt an den US-Senat weitergegeben hat – dank CLOUD Act völlig legal, aber trotzdem eine schlechte Idee. Und die US-Cybersicherheitsbehörde CISA legt AWS-Keys, Kubernetes-Configs und Klartext-Passwörter in einem öffentlichen GitHub-Repository ab. Das Repository heißt "Private-CISA". Verschlüsselung hilft. Manchmal. Wenn man's richtig macht.

Monde Numérique - Jérôme Colombain

L'Europe relance la bataille pour sa souveraineté numérique face aux GAFAM • Le Parlement européen adopte Qwant comme moteur par défaut • L'IA affronte le droit d'auteur et Mistral monte au créneau • Anthropic relance le débat sur une pause mondiale de l'IA • SoftBank investit 75 milliards d'euros dans des data centers en France • Microsoft dévoile ses nouveaux modèles et ses agents autonomes ⭐️ Découvrez Frogans à Vivatech 2026

ZD Tech : tout comprendre en moins de 3 minutes avec ZDNet
Sous la menace d'une action en justice, l'École polytechnique annule sa migration vers Microsoft 365

ZD Tech : tout comprendre en moins de 3 minutes avec ZDNet

Play Episode Listen Later Jun 5, 2026 2:26


C'est un véritable coup de théâtre auquel vient d'assister en France le secteur de l'enseignement supérieur.Sous pression, la prestigieuse École polytechnique vient d'annuler sa migration vers Microsoft 365.Le cadre juridique se durcit sérieusementCe revirement spectaculaire est d'abord le signe que le cadre juridique se durcit sérieusement. En tentant d'imposer l'écosystème Microsoft, Polytechnique s'est heurtée de plein fouet au Code de l'éducation, qui exige de prioriser les logiciels libres.Mais surtout, en migrant vers ces outils, l'école exposait les données sensibles de la recherche française aux lois extraterritoriales américaines, notamment le fameux Cloud Act.Sous la menace d'une action en justice menée par le Conseil National du Logiciel Libre, et face à la fronde de ses propres chercheurs, la direction a dû capituler.Ce dossier dépasse largement les murs de l'écoleMais attention, ce dossier dépasse largement les murs de l'école.Car au même moment, l'autorité de protection des données autrichienne édicte que la version éducation de Microsoft 365 viole purement et simplement le RGPD, notamment en pistant les utilisateurs à des fins commerciales.Il est donc temps de sortir du déni. Les promesses d'hébergement localisé ne suffisent plus lorsque la société mère reste contrainte de livrer ses données sur simple injonction d'un juge outre-Atlantique.Quelle alternative s'offre aux décideurs ?Face à ce constat, quelle alternative s'offre aux décideurs ? Longtemps perçu comme complexe, le logiciel libre pourrait servir de levier stratégique.Le Conseil National du Logiciel Libre assure structurer une véritable filière d'accompagnement.L'objectif est d'aider les organisations à migrer vers des outils ouverts, souverains et interopérables.Hébergé par Ausha. Visitez ausha.co/politique-de-confidentialite pour plus d'informations.

Cyberhelden
Cyberhelden 75 - DigiD, residential proxies en AI die aanvallen niet magisch maakt

Cyberhelden

Play Episode Listen Later Jun 4, 2026 47:28


Ronald, Marco en Jelle zijn terug met DigiD, device-code-phishing, residential proxies en de vraag of AI cyberaanvallers echt onhoudbaar maakt. Eerst kort: Marco repareert tijdens een nachtwacht Home Assistant-data met Claude, Jelle bouwt met AI een lesdashboard, en Ronald rijdt in Kaapstad een fox hunt met antennes op de auto. Daarna DigiD. Staatssecretaris Willemijn Aerdts blokkeert de Amerikaanse overname van Solvinity door Kyndryl. Ronald legt uit waarom dit via de Wet ongewenste zeggenschap telecommunicatie loopt, waarom dat juridisch anders is dan VIFO, en waarom Nederland hiermee feitelijk zegt: Amerikaanse jurisdictie en CLOUD Act-risico's zijn voor DigiD te groot. Marco bespreekt RSI, recursive self-improvement, als nieuwe AI-hypeterm. Het idee: AI die zijn eigen training verbetert. De nuchtere conclusie blijft: losse stappen automatiseren lukt steeds beter, maar richting houden, controleren of iets klopt en echt autonoom onderzoek doen blijft lastig. Jelle pakt Kali365: phishing via Microsoft 365 device-code-flows. Het slachtoffer logt in op de echte Microsoft-site, maar autoriseert het apparaat van de aanvaller. Domeinchecken is dus niet genoeg als de context rond de login vergiftigd is. Het eerste hoofdverhaal: ASocks en residential proxies. Politie en NCSC verstoren een botnet met minstens 17 miljoen besmette apparaten, aangestuurd via ongeveer 200 servers in Nederland. Marco vat het scherp samen: het botnet is de infrastructuur, de residential proxy is het product. Aanvallers kopen verkeer vanaf normale thuisverbindingen in plaats van herkenbare datacenters of Tor-exitnodes. Daardoor lijken phishing, credential stuffing, DDoS en brute-force-pogingen op gewoon verkeer van echte gebruikers. Open vraag: zijn de apparaten echt opgeschoond, of vooral de aansturing geraakt? Jelle sluit af met Lennart Maschmeyers paper Deception and Detection. Maschmeyer stelt dat AI aanval en verdediging helpt, maar verdedigers structureel meer kunnen winnen: verdediging draait veel om detectie en patroonherkenning, aanval verderop in de kill chain om misleiding, context en gecontroleerde effecten. De drie zijn kritisch op zijn dwell-time-argument, maar herkennen de kern: je wilt geen autonome agent die in een vijandelijk netwerk creatief gaat improviseren. Tegelijk maakt AI aanvallers wel sneller als copiloot, codegenerator, parser van scanoutput en phishinghulp. Vooral lagere en middelmatige actoren kunnen daarmee sneller opschalen. *Bronnen* DigiD / Solvinity - NOS: https://nos.nl/artikel/2615885-staatssecretaris-verbiedt-amerikaanse-overname-solvinity-bedrijf-achter-digid - Wet OZT: https://wetten.overheid.nl/BWBR0045423 - Wet VIFO: https://wetten.overheid.nl/BWBR0046686 RSI - TechCrunch: https://techcrunch.com/2026/05/28/rsi-is-the-new-agi-and-its-just-as-hard-to-pin-down/ Kali365 - FBI IC3: https://www.ic3.gov/PSA/2026/PSA260521 - BleepingComputer: https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/ ASocks / residential proxies - Politie: https://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html - NCSC expertblog: https://www.ncsc.nl/expertblogs/residential-proxies-en-hun-grote-impact-op-de-digitale-veiligheid-in-nederland - NCSC nieuws: https://www.ncsc.nl/nieuws/gezamenlijke-actie-politie-en-ncsc-legt-groot-botnetwerk-plat - Security.nl: https://www.security.nl/posting/938396/Proxy-botnet+van+17+miljoen+apparaten+na+actie+politie+en+NCSC+offline?channel=rss Maschmeyer / AI - CV Maschmeyer: https://www.lennartmaschmeyer.com/CV_Lennart_Maschmeyer.pdf - Paper: https://doi.org/10.1162/isec.a.398 - M-Trends 2025: https://cloud.google.com/security/resources/m-trends

Tech Update | BNR
Europese Commissie gaat eigen techsector helpen op de cloudmarkt

Tech Update | BNR

Play Episode Listen Later Jun 1, 2026 4:41


De Europese Commissie wil de cloudmarkt aanpakken en de eigen techsector een handje helpen. Op dit moment is deze markt voor bijna tweederde in handen van bedrijven zoals Amazon, Google en Microsoft. Onder de Cloud and AI Development Act wil Eurocommissaris Henna Virkkunen, die technologie in haar portefeuille heeft, helpen door woensdag nieuwe maatregelen aan te kondigen. Dat staat in een conceptversie waar persbureau Reuters over schrijft. Rosanne Peters vertelt erover in deze Tech Update. De belangrijkste reden is Europa minder afhankelijk te maken van technologie uit de Verenigde Staten. Dat is niet alleen cruciaal voor ons concurrentievermogen, maar ook voor onze veiligheid. Er blijft een reële angst dat de VS onder hun eigen Cloud Act toegang kan krijgen tot opgeslagen data. Verder in deze Tech Update: Apple stelt release van meerdere producten uit door Siri die - opnieuw - tekort schiet See omnystudio.com/listener for privacy information.

Maxisciences

[SPONSORISÉ] Le cloud, on ne le voit pas. Pourtant, il fait tourner l'économie, connecte nos objets, héberge nos données de santé, nos secrets industriels, nos infrastructures critiques. Une infrastructure invisible... mais un choix éminemment stratégique. Anne Duboscq, directrice des affaires publiques chez OVHcloud, le résume en une phrase : la souveraineté numérique, c'est avant tout une liberté de choix. Une liberté qui se joue sur trois plans — la maîtrise des données, l'indépendance technologique, l'autonomie opérationnelle — et qui n'a rien d'abstrait quand le Cloud Act et le FISA américains permettent, en théorie, d'accéder aux données de n'importe quelle entreprise cliente d'un acteur américain, où qu'elle se trouve dans le monde. Mais comment cela se traduit-il concrètement dans une entreprise ? Vincent Charretier, ingénieur en cybersécurité et DPO chez Withings, a des réponses très concrètes à cette question. Quand on manipule des données de santé aussi sensibles que celles issues d'objets connectés, le choix de son hébergeur, de son architecture, de ses partenaires n'est plus une affaire de service informatique : c'est une décision qui engage toute l'entreprise. Dans ce deuxième épisode d'UltraViolet, nous explorons comment les entreprises peuvent reprendre la main sur leurs données et leurs infrastructures : comment définir sa stratégie cloud, arbitrer entre coût et souveraineté et se repérer parmi les qualifications et certifications existantes (SecNumCloud, ISO 27001, HDS, ISO 27701). Un échange d'autant plus utile que le marché du cloud croît de 15 % par an et qu'il devrait, dès 2030, dépasser en Europe le marché des télécoms. Cet épisode s'adresse aux dirigeants et décideurs qui veulent sortir du réflexe "c'est un sujet technique réservé à la DSI" pour comprendre pourquoi le cloud est, avant tout, un sujet stratégique. UltraViolet, c'est le rendez-vous du groupe AFNOR pour aider les entreprises à faire les bons choix et passer à l'action ! Bonne écoute !

Podcasty Aktuality.sk
SHARE: Máte v USA citlivé dáta? Zvážte ich presun domov, radí expert

Podcasty Aktuality.sk

Play Episode Listen Later May 27, 2026 35:33


Umiestnenie amerických serverov v Európe je len falošný pocit bezpečia. Neslávne známy zákon Cloud Act jasne hovorí: Ak ste americká firma, musíte vydať dáta vašej vláde, bez ohľadu na to, v ktorej časti sveta sa fyzicky nachádzajú. Európa si preto konečne začína uvedomovať obrovské riziko, ktoré prináša masívne spoliehanie sa na služby od gigantov ako Amazon, Google či Microsoft.Už to dávno nie sú len teoretické hrozby. Tlak na Dánsko ohľadom anexie Grónska či tvrdé digitálne odstrihnutie Medzinárodného trestného súdu OSN ukázali, ako rýchlo môže Európa prísť o svoju infraštruktúru, ak nevlastní jej zdrojový kód. Liekom na túto závislosť majú byť „suverénne cloudy“ a masívny prechod na open-source riešenia. O tom, prečo je aj na Slovensku potrebné budovať vlastnú digitálnu nezávislosť a ako sa reťazec Lidl stal poskytovateľom cloudu, sa v podcaste SHARE rozpráva Maroš Žofčin s riaditeľom spoločnosti dNation Martinom Pilkom.Podcast vznikol v spolupráci so spoločnosťou dNation.Pripravte sa na budúcnosť s knihou od redaktorov Živé.sk „Umelá inteligencia: Pripravte sa na budúcnosť“. Teraz ju máme aj v elektronickej verzii. Nájdete ju na obchod.aktuality.sk.TIP: https://zive.aktuality.sk/clanok/0RfdZVW/nahliadnite-do-buducnosti-vydavame-knihu-o-umelej-inteligencii/V podcaste sa dozviete aj o týchto témach:Prečo fyzické umiestnenie servera v EÚ nestačí a ako funguje sporný zákon Cloud Act.Ako v priebehu 24 hodín úplne zmizla z internetu celá digitálna identita Medzinárodného trestného súdu.Prečo je otvorený zdrojový kód kľúčom k tomu, aby ste neboli rukojemníkom poskytovateľa licencií.Ako nástroje ako Nextcloud dokážu plnohodnotne nahradiť obľúbený Office 365 či Google Disk.Ako si známy európsky supermarket vybudoval cloud pre e-shop a dnes ho predáva ako infraštruktúru.Prečo slovenskí výskumníci stavajú vlastný privátny cloud s mimoriadne citlivými dátami.Podcast SHARE pripravuje magazín Živé.sk.

ChannelBuzz.ca
Outcomes before hardware: Microserve CTO Nigel Brown on AI readiness, tokenomics, and resilience from Dell Technologies World

ChannelBuzz.ca

Play Episode Listen Later May 27, 2026 27:55


Nigel Brown, CTO of Microserve Not every voice at Dell Technologies World last week belonged to a vendor. For a partner perspective on the week’s biggest themes, In The Channel sat down with Nigel Brown, CTO of Microserve – a Burnaby, BC-based solution provider, Dell Titanium partner, and Dell’s Client Solutions Partner of the Year in Canada in consecutive years. Brown walked away from DTW with deskside agentic AI as his headline takeaway, particularly after hands-on time in a Dell lab showcasing NemoClaw – NVIDIA‘s enterprise-governance take on the OpenClaw open-source agent framework. “They’ve set it up closed by default – it can’t leave the box,” Brown says. “That’s a safety net that really opens the conversation.” That said, he’s clear-eyed about where most of his public sector and enterprise clients actually are. “Broad scope, it’s ahead. The hardware is going to follow it.” The tokenomics reality landed hard too. Brown shared a personal story about spending a hundred dollars testing Claude on a single flight – a relatable example he’s started using to frame the real cost implications of unmanaged AI usage, well before any on-premises or local inference conversation begins. On cyber resilience, Brown says he’s had to evolve his approach: “I got to be more of a jerk. I was being too nice.” His firm’s managed backup practice has seen firsthand the damage when clients – and even other MSPs – treat backup as a checkbox. When you show up after a ransomware event to find the backup server was on the same domain and hit just as hard, the conversation changes. And on Canadian data sovereignty, Brown goes beyond the standard data-residency talking points. FISA Section 702 and the CLOUD Act, he argues, represent far more serious legal exposure than most clients realize – even those who believe a Canadian cloud region is sufficient protection. The conversation also covers the AI PC refresh cycle colliding with supply chain pressure, the end-user adoption gap that’s undermining Copilot investments, and what Dell’s revised partner incentive structure signals about where the growth opportunities are. Read Full Transcript Robert Dutt: Hello and welcome to In the Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Last week, I was at Dell Technologies World in Las Vegas, Dell’s big annual customer and partner event. Over the course of the week, I had a number of conversations that I’ll be bringing here on In the Channel. Last week, we featured three Dell executives. This week, we’re bringing you some partners. Today, we start on that partner perspective, specifically from one of Canada’s top Dell partners. Nigel Brown is CTO of Microserve, a Burnaby, BC-based solution provider that has earned Titanium status with Dell and taken home Dell’s Client Solutions Partner of the Year in Canada in consecutive years. Microserve serves an enterprise and public sector-heavy client base, which means Nigel’s job is regularly about taking what gets announced on a stage in Las Vegas and translating it into something that makes sense for organizations that don’t necessarily move at conference speed. I caught up with Nigel on site at DTW last week. We covered a lot of ground – deskside agentic AI and what it’s actually going to take to make that real for customers, the very real cost of token economics, why he’s had to be, as he put it, more of a jerk about cyber resilience, and why the Canadian data sovereignty conversation is more urgent than most people realize. Let’s get right to it. My chat with Nigel Brown. Nigel, thanks for taking the time. Appreciate it. Nigel Brown: Happy to be here. Thanks for having me. Robert Dutt: So you guys are here, obviously, as a Titanium-level Dell partner, consecutive years as the Client Solutions Partner of the Year in Canada. What’s your overall read on this week? What made your ears stand up? What caught your attention? What are you taking back to both your team and to your customers when you go back to Burnaby? Nigel Brown: That’s a really good question. It’s also a big one. There’s been a lot of announcements, a lot of dialogue over the last couple of days. I’m trying to process that a little bit, assuming you were going to ask me that. I think the biggest takeaway I had – everybody’s heard of OpenClaw, everybody’s heard all the IT people are terrified of it, so it’s more, how do we get rid of it in our environments? Seeing this whole push around deskside agentic AI, especially given our market where we play a lot with clients – I actually had the opportunity, I did the lab today because I couldn’t resist seeing what it’s like. The governance and security wrapper on it totally makes sense and it’s opened my eyes. I think that’s probably the biggest. Beyond that, I would say the Dell hardware being able to run frontier models, seeing Gemini running local for sovereignty conversations – I think that’s a really good thing to see as well. Robert Dutt: Along those lines, obviously you touched on one of the big stories this week, which is deskside AI – the idea of physical infrastructure that’s at or near the customer’s desk, either in the data center or right there in the PC, that’s processing the models locally. It sounds like something that you’re interested in. I’m curious where it lands for your customers. Is it something that’s a conversation point, or is it ahead of where they are in the AI discussion at this point? Nigel Brown: I would say broad scope – I don’t want to lump all my customers into one bucket – but broad scope, it’s ahead. I don’t think you’re seeing a lot of organizations ready for it. We also deal heavily with public sector enterprise accounts, for example. We’re doing more and more in the commercial market where you’re going to see a little bit more playing and adoption within tech teams. But in ours, yeah, I’d say we’re definitely ahead right now. So it gives you a chance to get in there and pitch the idea as something new and plant those seeds. Once I get it past my IT and security folks, then that’s where it’s all going to start. If I can’t get it through mine in a good conversation, then I’m never going to be able to with our clients. Robert Dutt: But it sounds like there’s at least that – from your comments on OpenClaw, it sounds like there’s that door, that area of interest. Nigel Brown: Seeing it today under the NemoClaw and Viya umbrella – yeah, I think there’s definitely something there. They’ve set it up closed by default. It can’t leave the box. That’s what I saw in the lab today. So until you set up essentially like a firewall rule to allow it to do something, it’s a safety net that I think really opens the conversation and allows the idea of end users actually playing. Those are really early adopters anyway. And how could I integrate agentic AI into organizations? Robert Dutt: Man, how often does it come back down to governance with AI? Nigel Brown: Oh, absolutely. That’s pretty much the name of the game everywhere. And so we’re doing it well, and many are still scrambling. Robert Dutt: You touch on you guys having a lot of public sector, healthcare, education, all those kinds of verticals – not always the fastest to move on new tech. Along the lines of the previous questions, but sort of taken out a notch – how much of what the AI announcements we’ve heard this week translate directly to where your customers are at, versus how much needs to be, shall we say, adapted for the reality of your accounts? Nigel Brown: Well, you go to any of these events and it’s, “We’re behind if we’re not doing agentic AI everywhere.” Reality is, it’s just not true. I think it’s very forward-thinking – or very optimistic – to think we’re all moving that fast. It’s headed in that direction quicker and quicker. Executive tables are always the ones sitting there going, “We want it, we need it in our organizations, we’re going to get left behind.” So it’s very top of mind. But some organizations have very niche deployments – they’re figuring out the right solutions. Healthcare – I’ve seen it, they’ve done some phenomenal things in radiology and other areas. So it’s picking up. We’re dealing with one client right now that’s looking at online pharmacy and they’re looking at a huge Dell compute cluster to run AI on. So you see it, but it’s not commonplace. It’s not every organization. Certainly as you get into municipalities and things like that, it’s Copilot at best – that’s really where they’re trying to play – and their user base just isn’t adopting, not even close. Robert Dutt: So it sounds like there are at least a couple of steps that need to happen to get to the point of, A, using what’s already in place and, B, potentially looking at building out something internally – and the stuff that’s been talked about here a lot, the idea of running those AI workloads internally on the data center side. Nigel Brown: Yeah. I think it’s going to get there for sure. Right now the conversation has to be outcomes – not “I want AI.” And right now it’s so heavily, “Well, I know I need it, I don’t know what for yet.” I’ve seen it even in some peer groups – the dialogue is, “Well, we’re going to do AI, we’re going to build agents.” So, what for? And then there’s a long pause. Driving outcomes conversations is where it’s going to start, in my opinion. The hardware is going to follow it. And that really ties into, well, where are you going to run it? Do you understand token economics – or tokenomics, whatever the buzzword is right now – and that’s a really big deal. For me, getting that message out really loud and clear around the cost of tokens – I’ve done it, I’ve gotten burned. I spent a hundred bucks on a plane because I wanted to see Claude do something cool. And you’re going, wow, if I can do that in 10 minutes, think of what larger organizations will spend if they don’t find a smarter way to run it. Robert Dutt: That’s a good point – it’s not something you necessarily understand, but it’s something you can sure feel if you start to have adventures with the stuff. Nigel Brown: Well, exactly. And all it’s going to take – like I said, a lot of organizations started with Copilot under the Microsoft umbrella, because it was like an easy button. It was there for them, it was already set up. I am worried about some of those days changing, where that subscription turns into usage-based models. And we’ll see where that goes. You’re seeing it with Anthropic, you’re seeing it with Perplexity. I bounce off my limits all the time. Most of what I’m doing I can wait till tomorrow – but it’s easy to get out of control. Robert Dutt: And user computing is pretty core to what you guys do. There are a few things going on there – Windows 11 end-of-life support coming in October, the AI PC push coming from every direction at the same time. I’m curious if those two things are coming together in customer conversations as one refresh decision, or are they still separate tracks – the need to modernize for the Windows upgrade versus the need to modernize to get the most out of AI workloads? Nigel Brown: I think the end-of-support conversation and hardware refresh, honestly, is the biggest driver of the conversation that I’ve seen. And then that leads into, well, do I need an AI PC, and why, and what’s going to run on it? Everybody’s exploring and curious about it. There’s more skepticism about whether you need it now. Robert Dutt: How is that hitting along with the current fun situation with hardware constraints and prices spiking? And we’re hearing pretty directly from Jeff Clarke that, you know, telling customers, let us know what you want as early in the process as you can. I think the natural addendum to that is, make decisions knowing you might have this machine for a little bit longer than you previously expected. Nigel Brown: Totally right. So it’s very much my dialogue with our clients – it’s future-proofing. You better do it now. You don’t want to be stuck with a machine that can’t run an NPU for the next five years. So even if right now there’s skepticism about how much is going to run on it today, I think it is an important conversation to have and make sure that we’re ready for the moments where we’re really seeing workloads and inferencing running on device. You have to have that conversation now and pre-plan for it. But yeah, it’s been – especially in public sector – a hard conversation to have right now. Supply chain – we’re like a broken record. It still surprises me how many clients we talk to that haven’t seen this coming, that don’t know it’s real, or you get the ones going, “Well, I think it’s going to clear up in September, I’ll just wait till then.” Oh man. Brace for it. We’ve got to be ready. It just feels like a conversation on repeat these days – and it’s more than worth it, making sure we’re doing model selection with the future in mind. Robert Dutt: I find it’s a fun time to be a partner in that particular space. Nigel Brown: Well, you know, quote volume has quadrupled, because that same customer deal might take four different passes before they’ve made it through, especially in government. Pricing validity is a real challenge. It’s a moving target – no decision ever gets made fast. Robert Dutt: I want to talk a little about cyber resilience – another big topic here at the event. You guys run a managed backup practice, I understand, and you’re doing a lot of what vendors are asking MSPs to evolve towards. When you get into a customer environment today, what’s the most common gap between what they think their backup situation looks like and the reality of the situation? Nigel Brown: That’s an interesting question. It’s a real mixed bag. I always start with, “How confident are you in your ability to recover?” And most leaders – business leaders, outside of IT – there’s like a long pause. “Well, I don’t know.” Okay. Have you ever tested your recovery capability? No. Well, that’s where we’re going to start. And in other dialogues, they think they’ve got the backups running, but nobody’s been looking at them – they’re coming from doing it themselves, or maybe a mom-and-pop IT person taking care of it. They’re not watching, they’re not looking at tools, they’re not getting alert notifications on whether it’s keeping up and whether they’re protected. So that’s very foundational. Warning new clients – it’s just, let’s take them on that journey, do an assessment of the whole environment, make sure we’re protected. And a lot of conversations are, “Do you know that you’re not protected? Like, if you got ransomware tomorrow, there’s nothing I could do to help you, even though I’m your MSP.” That’s a scary reality. I’ve seen that have to go back to boards and make some tough decisions, find budget and solve it. They usually do – they react fast – but you’ve got to make the risk abundantly clear. Robert Dutt: That makes sense. In talking to Rob Emsley, who’s on the marketing team for the cyber resilience side at Dell, he was saying that 97% of cyber attacks now are specifically targeting backup infrastructure – because it turns out that’s where all the stuff is. Does that match what you’re seeing, and has that shift changed what you’re recommending to customers about what being protected really means for them? Nigel Brown: I wouldn’t say it’s really changed our messaging. I’d like to think we were maybe ahead of the curve in talking about storage and immutability – some of these key elements of, well, you just need it. That’s how we run our hosted service for clients that use it. And if we’re building out an architecture for another client, it’s just fundamental these days. You can’t even consider a solution that doesn’t include immutability protection, being able to spot bad things happening. But I’ve seen it – we’ve come into a disaster client where, “Hey, we got ransomware, can you help us recover?” And you go to the backup server to find out it was ransomwared too. “Do you have any tapes floating around?” It’s a tough chat to have. You see that less these days, but you definitely see the attempts – people trying to do it. And even other MSPs – I hate to say it – they’re not mature enough in how they’re protecting. They took the backup server, joined it to the domain – it’s just another device on the network. And sure enough, that’s exactly what gets hit because they didn’t plan it out. So it’s all planning and doing it right in the first place. Robert Dutt: It’s a checkbox as opposed to something that’s more firmly thought through. Given that, how do you approach it with customers? Do you come at it as, “This is something you should do, these are the reasons why, this is the potential downside” – or is it a thou-shalt kind of conversation? Nigel Brown: You know, a pile of years ago, after seeing an incident hit a new customer, I kind of resolved – I’ve got to be more of a jerk. I hate to say it. I got to be a lot tougher in my stance. I was being too nice. So yeah, in all things on this, my position is to generally take a pretty firm line. It’s all about risk, though. And to business leaders especially, that’s a term they understand. I’m not telling them, “Okay, you need this type of backup solution and it’s going to do these things.” It’s all about, how do we address the risk that you have right now? Leave it to us to figure out the details as we design the solution. Rarely do we get into the weeds of it unless it’s a larger client where we’re dealing with a large IT team that has opinions. But usually in those larger environments, there are groups that are already aligned – they know what they should be doing, maybe just haven’t done it themselves yet. The new architecture is absolutely going to include all those steps. So it’s an easier conversation to have. In some ways, it’s giving them permission if you’re coming in as a new supplier – it’s the stuff they’ve wanted to do, but haven’t really had the air cover to make the case. Robert Dutt: Yeah, you come in as that outside opinion to say, this is how it needs to be. Nigel Brown: And our job is often more of just a translator for those IT teams to their leadership – to help support the business case. Robert Dutt: I want to talk about the Modern Partner Platform and some of the partner program changes that have rolled out this week. One of the big things is obviously the revised incentive structure, with cyber resilience particularly called out as a premium rebate area. From your seat as a Titanium partner, what does the new structure tell you about where Dell sees the biggest growth opportunities for partners? Nigel Brown: Well, I think it does exactly that – it says where the growth opportunities are. And largely there was no surprise. In my opinion, when you look at it, it aligns to how we want to lead deals, it aligns with the conversations we’re already going to have. Now it’s just helping incentivize that dialogue. Nothing surprising there – I just see better alignment. Robert Dutt: Let’s play a little bit of “anything can happen here.” Vendors like Dell are starting to build agentic AI into their programs, their portals, their tools – all the stuff you guys work with every day. Where do you see the most genuine value for an organization like your own in vendors – agentifying, for want of a better word – their partner programs and tools? And the flip side: are there any potholes you’re watching out for as that rolls out? Nigel Brown: You know, the more the merrier – more tools you can bring in is great. We’re always excited to see what they come up with. But to me, the bottom line is back to outcomes. It’s about reducing friction in the sales process. What do we want our sellers to do? We want them out selling. Living in a partner portal trying to find what they need, deal registration, all of those things that can be painful – sometimes it’s just admin work taking you away from conversations with clients. Reduce friction – that’s the name of the game. Do I want to see more AI-generated marketing content? No. We can do that ourselves – one prompt, feed something in, done. To me, the more you can expose what matters to us and reduce friction, the better. It keeps us doing what we should be doing and not sitting there doing admin work. Robert Dutt: It sounds like based on that comment, what Dell and a lot of its peers are doing is already on track – because I’m sure they’re asking these exact same questions of partners around the world right now. Nigel Brown: Oh, they’ve got way smarter people than me working in these massive organizations. They know the outcomes we want to achieve. And I’m excited that we’re at a point in time where we can see some of this come to fruition. Ten years ago, this was never a reality. Robert Dutt: What’s the biggest misconception you think your customers have about what it means to be AI ready right now? Nigel Brown: I think it depends on who the conversation is centered around. If it’s C-suite leadership, it’s back to, “We want AI, I don’t know what for, I don’t know what it is, but I know I need it.” There are tough conversations to be had. AI readiness is really, is your data ready? We heard that on stage this morning. Most organizations we walk into – it turns out they’ve got no data governance. So, let’s define some of this, let’s build some process, look at the right tools. In the Microsoft lens, we do a lot around Microsoft 365 and modern workplace. Well, then it’s a Purview conversation. And they get confused – “Why are you talking about DLP and Purview? I thought we were talking about AI readiness.” That’s exactly what it’s all about. The other big one I think they’re not taking seriously enough is the end-user adoption side. I’ve seen organizations – you go into their portals and have a look with them – their adoption of Copilot, where they’ve spent a whole pile of money, is abysmal. So then the dialogue is, “What you actually need to do is get your users excited. Train them, show them the cool things.” I think we’ve been really successful doing that inside our own organization, and now that’s something we deliver to our clients as well – we need to get your teams ready and thinking differently. At a C-suite level, they’re usually surprised at the path it takes, or in some cases how long it might take to get there. “Your data is in such rough shape – you’re two years away. You need to build a foundation before you can really consume it.” Now, some of the announcements this morning – okay, that starts changing the equation. We could get there faster if we have the right infrastructure in place. Robert Dutt: For a variety of reasons, the Canadian data sovereignty question feels like it’s getting louder. And I have to imagine, especially in your public sector footprint, how are you helping customers think through AI infrastructure decisions when data residency and compliance are an increasing part of the equation? Nigel Brown: It’s a non-negotiable for most of our enterprise and public sector clients. It’s going to run on-prem. They cannot afford to run on cloud. Yes, they want the latest models, the frontier models, the cool bells and whistles as we all do. But really – I presented at a conference last year on exactly this topic, why it’s important to bring it back on-prem. Never mind the tokenomics conversation – now there’s just more ammunition. I chatted with one IT leader, a commercial client, not public sector, who was all proud of how he’d migrated everything to cloud. We were in a session where they talked through the tokenomics challenge and another reason why sovereignty matters. And you watch the look on his face go, “Wow, I’m going to have to start building a data center again. I thought I got out of that.” And he was sitting there with his CEO in the room for that conversation. Kind of a wake-up call. So my dialogue is, let’s talk through what does the Patriot Act mean? What does FISA Section 702 mean? It’s a little bit scary, and people are shocked – “I thought running in Google Cloud or AWS, running it in a Canadian location was good enough.” No. That provider has access to your data. Have you heard of the CLOUD Act? That’s nothing compared to FISA 702 – they don’t even need to ask. They can just go and get it. And that’s pretty scary. So yeah, a lot of our job now is just sharing and communicating the right things to our clients and making sure they’re aware. Robert Dutt: Aside from your efforts to bring that education – do you find that the level of general awareness is on the rise? Are we getting to more of a discussion about how to solve for this, rather than still defining the scope of the problem? Nigel Brown: I would love to say it’s more mature. The reality is no – it’s still early-stage conversations. You get anomalies. We were with some clients who are way ahead and have just deployed Azure Local on Dell infrastructure. They’re doing amazing things, moving fast. So now it’s more, “How can I partner with you to go share this message? Why you went there, why you built it this way, what are you doing about it?” But no, it’s going to be a continued push – much like the supply chain story here – these dialogues just repeat as you walk into client after client. Robert Dutt: Last one for me – along the same lines as the first question, but a slightly different lens. What’s one thing from this week that you think will genuinely change what Microserve brings to customers in the next 12 months? Nigel Brown: I come back to where we started – the whole side of agentic AI. That was not on my radar, not in a serious way. “Let’s play around with this, let’s lab it out, see where it’s getting explored.” When you see a name like Dell behind what we’re doing, that got me more excited than I would have thought. I want to pilot inside our org. And if we can start building something that works here, then absolutely – taking that to clients and saying, “Okay, look at the GB10s, look at the GB300s, let’s move up the ladder.” There’s a tangible path that gives them more value than trying to build massive solutions right out of the gate. There are quick wins there, and that’s what excites me – showing a customer how there could be a quick win if we did this right. And it ties into the last thread we were pulling on – “Okay, you’re telling me I shouldn’t have all this stuff running on public cloud, so where’s it going to run?” And you’re not talking megawatts and massive data centers here. All I want to do is automate tasks and do some of this lower-level stuff. I think that’s going to be an interesting entry point for a lot of clients – making it more accessible. Everybody’s used ChatGPT, Claude, whatever their tool of choice is, so they’re into prompting. Nobody’s really understanding Copilot or understanding agentic – it’s a big buzzword. That’s our job. We can show them a slice of the possible, mock up these use cases, and those are quick wins. Then it is something deployable at scale – you just move it from the little box to a bigger box. The more people take advantage of it and keep moving up the scale, you don’t need to go spend millions upfront to play around with something like that. It’s going to open more doors. Robert Dutt: No shortage of interesting opportunities. Good luck getting out there and chasing those, and thanks again for making the time this week. Nigel Brown: You bet. Thanks for having me.

Boekestijn en De Wijk | BNR
De machtsstrijd om AI

Boekestijn en De Wijk | BNR

Play Episode Listen Later May 23, 2026 37:07


Amerika en China zijn verwikkeld in een race om suprematie in AI en Europa bungelt weer eens achteraan. De gevolgen daarvan kunnen ingrijpend zijn. Te gast: Marietje Schaake, fellow aan het Institute for Human-Centered Artificial Intelligence aan de Universiteit van Stanford. Boek: De Machtscode Marietje Schaake schetst hoe kunstmatige intelligentie de machtsbalans tussen Verenigde Staten, China en Europa verandert en waarom Europese afhankelijkheid van Amerikaanse AI-bedrijven gevaarlijk wordt. Zij wijst op de politieke verwevenheid tussen Silicon Valley en Washington, de Cloud Act en bedrijven als Palantir, die tegelijk in Oekraïne en Gaza actie zijn. Dat alles maakt Europese digitale soevereiniteit tot een veiligheidsdossier, niet alleen een marktkwestie. Rob de Wijk en Arend Jan Boekestijn benadrukken hoe langzaam Europa beweegt in wetgeving, kapitaalmarkt en defensiesamenwerking, terwijl AI al wordt ingezet voor autonome wapensystemen. De AI Act, een Europese chipsindustrie en een echte kapitaalmarkt moeten tegelijk snelheid en bescherming bieden, maar botsen op politieke terughoudendheid. De vraag wordt hoe lang Europa nog kan vertrouwen op Amerikaanse bescherming terwijl het zelf geen AI-supermacht is. De gesprekspartners bespreken ook de acute risico's van open source intelligence, hackende AI-modellen zoals Anthropic’s Mythos en het strategische gewicht van ASML in de wereldwijde chipoorlog. Schaake ziet een groeiend verzet in de VS tegen datacenters en AI-banenverlies, en tegelijk een kans voor Europa om talent aan te trekken en een eigen democratisch AI-ecosysteem te bouwen. Wie wil begrijpen waarom AI geen gadget maar machtsinstrument is, hoort hier hoe die strijd nu al over Europese hoofden wordt uitgevochten. [Samenvatting geschreven door AI en gecontroleerd door mens] Over de Podcast Arend Jan Boekestijn en Rob de Wijk gaan onder leiding van Hugo Reitsma op zoek naar de nieuwe wereldorde. Wat betekenen oorlog, machtspolitiek en economische verschuivingen voor Europa en Nederland? In elke aflevering duiken zij in de geopolitieke actualiteit. In 2022 werd Boekestijn en De Wijk uitgeroepen tot winnaar in de categorie Nieuws & Politiek tijdens de Dutch Podcast Awards Reageren? Op X: @ajboekestijn en @robdewijk Bluesky: @hugoreitsma.bsky.social Mail: boekestijnendewijk@bnr.nl Over de makers: Arend Jan Boekestijn is een Nederlands historicus en voormalig politicus. Hij studeerde geschiedenis en politieke wetenschappen aan de Vrije Universiteit in Amsterdam. Boekestijn is voormalig Tweede Kamerlid (tot 2009). Sinds 1989 is hij verbonden aan de vakgroep geschiedenis van de Universiteit Utrecht en sinds 2016 lid van commissie Vrede en Veiligheid van AIV. Rob de Wijk studeerde eigentijdse geschiedenis en internationale betrekkingen, promoveerde op kernwapenstrategieën, werd hoogleraar in Leiden en richtte in 2007 het Den Haag Centrum voor Strategische Studies op. Hugo Reitsma studeerde rechten en politicologie. Hij werkte eerder als politiek verslaggever en vanuit verschillende conflictgebieden. Hij is auteur van het boek ‘Boekestijn en De Wijk voorspellen de toekomst’ (november 2023).See omnystudio.com/listener for privacy information.

Big Picture Medicine
#140 Should the NHS Trigger the £330M Palantir Break Clause? An Insider's Take

Big Picture Medicine

Play Episode Listen Later May 11, 2026 49:29


Tom Bartlett spent 22 years inside the NHS. For three and a half years, he led the 150-person engineering team at NHS England that built the £330M Federated Data Platform with Palantir.He a month ago and he's the only insider speaking publicly about what the platform actually does, what it costs, and whether the NHS has any credible alternative.We cover the architecture, the cost, the CLOUD Act, the BMJ exposé, the conflicts of interest at Chelsea & Westminster, and whether ministers should trigger the break clause.

Ich glaube, es hackt!
Die Spare-Ribs-Wurfaffäre im Bayerischen Hof

Ich glaube, es hackt!

Play Episode Listen Later May 5, 2026 69:31 Transcription Available


Rüdiger hat Tobis Geburtstag nicht vergessen – aber DHL schon fast. Mit vertauschten Absender- und Empfängeradressen startet Folge 121 entspannt chaotisch, bevor die beiden tief in Technik, KI und Google-Bewertungs-Intrigen eintauchen. Leserpost RailWise (iOS): Zwei Masterstudenten tracken minütlich den gesamten Fernverkehr Deutschlands – 25.000 Fahrten/Tag, Millionen Datenpunkte/Woche. Hörer Markus korrigiert Tobis Wire-Einschätzung: Der CLOUD Act greift auch bei europäischen Servern amerikanischer Betreiber. Hörer Klaus schickt zwei Links zu Signal-Angriff und Wire-CEO-Interview – kommen in die Shownotes. Kurzmeldungen WhatsApp bekommt eine eigene Backup-Cloud – endlich Plattformwechsel zwischen iOS und Android möglich. Apple ermöglicht Jahresabo-Preise bei monatlicher Zahlung im App Store. E-Ink-Fingernägel von Eye Polish (CES 2026): Farbe per App ändern – die App hat Standortdaten geleakt. KI & Tech Spielearchiv Myriad (390 TB, 6.000 $/Monat) stirbt an explodierenden Hosting-Kosten durch KI-Rechenzentren – Community spiegelt, aber Langfristigkeit fraglich. BambuLab droht OrcaSlicer-Entwickler juristisch, weil er gesperrte Druckerfunktionen per Fork wieder freigeschaltet hat. Microsoft testet 19 KI-Modelle bei Dokumentenarbeit: nach 7 Schritten 50 % der Dateien korrupt. Chrome-Extension aus Kanada zeichnet jeden Tastendruck in Google Docs auf – Lehrer können Hausaufgaben als Zeitraffer abspielen, alle fünf Investoren in der Höhle der Löwen dabei. Apple verschippt versehentlich eine interne CLAUDE.md-Datei in einem App-Update. Ex-GitHub-CEO Ned Friedman gibt seiner KI Zugriff auf Kameras, Bluttest und Tesla – sie schickt ihn Wasser trinken und ändert die Route zur Apotheke. Samsung The Frame nimmt Bilder ohne Authentifizierung von jedem Gerät im gleichen WLAN entgegen – Rüdiger hat's per Claude Code genutzt, Rick Astley im Media Markt wäre der nächste logische Schritt. Google-Bewertungen Google zeigt jetzt in Maps an, wenn ein Lokal Bewertungen löschen ließ – in 50er-Blöcken. Transparenz oder Freifahrtschein für Anwaltskanzleien, die davon leben? Plus: Spare Ribs, ein besoffener Russe im Bayerischen Hof und warum Tobi trotzdem nie eine Rezension schreibt. -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast

Crazy Wisdom
Episode #544: Privacy Is the New Counterculture

Crazy Wisdom

Play Episode Listen Later Apr 27, 2026 50:27


In this episode of the Crazy Wisdom Podcast, host Stewart Alsop sits down with Cindy Cohn, Executive Director of the Electronic Frontier Foundation (EFF), for a wide-ranging conversation covering the EFF's origins and mission, the countercultural roots of Silicon Valley, the rise of surveillance-based business models, the challenges facing open source software and open-weight AI models, the legal landscape around intellectual property and privacy law, and the growing tension between government overreach and civil liberties in the digital age. Cindy also discusses her upcoming departure from EFF after 26 years, the transition to new leadership, and her recently published book Privacy's Defender, which chronicles key legal battles she fought to protect digital privacy rights.Links mentioned:- EFF website: eff.org- Privacy's Defender book: eff.org/privacysdefenderTimestamps00:00 - Stewart introduces Cindy Cohn, EFF Executive Director, who explains the organization's mission protecting digital rights since 1990.05:00 - Cindy connects counterculture roots to early internet idealism, describing how digital communication broke down physical barriers for organizing.10:00 - Cindy reveals surveillance becoming the dominant business model surprised her, blaming corporate consolidation over naive techno-optimism.15:00 - Discussion shifts to Silicon Valley's military contractor substrate and how corporate money co-opted hacker ethos.20:00 - Open source community faces existential threat from age verification legislation while open-weight AI models emerge as critical alternative.25:00 - Cindy outlines legal frameworks like compulsory licensing and easements that could democratize access to foundational AI models.30:00 - Privacy principles around secondary data use identified as core surveillance problem, with Anthropic's domestic surveillance red line praised.35:00 - Cloud Act, Five Eyes surveillance networks, and global jurisdictional complexity examined through individual threat modeling lens.40:00 - Constitutional rights and democratic participation framed as irreplaceable bulwarks against authoritarian surveillance tendencies.45:00 - Cindy announces departure from EFF after 26 years, naming successor Nicole Ozer while planning return to courtroom litigation.Key Insights1. The Electronic Frontier Foundation was founded in 1990, before the World Wide Web existed, by Mitch Kapoor, John Perry Barlow, and John Gilmore, with early support from Steve Wozniak. Its core mission is to ensure that civil rights and freedoms follow people into the digital world, using lawyers, technologists, and activists to keep the internet on the side of users.2. The early countercultural movement of the 1960s and 70s heavily influenced the founders of the internet and EFF. Figures like Barlow believed the digital world could reduce physical barriers like race, class, and geography, allowing people to be judged by the quality of their ideas rather than the circumstances of their birth.3. The dominant surveillance business model that emerged was not inevitable. Cohn argues it resulted from deliberate policy failures, particularly the abandonment of competition law, which allowed a handful of companies to consolidate control over the entire internet and adopt 360-degree data collection as their primary revenue strategy.4. Open source communities remain active and vital but are under serious threat from legislation like age verification laws that make it practically impossible to maintain fully open tools. Cohn sees this community as essential to reclaiming public control over computation, especially in the age of AI.5. The open weights question for AI models is fundamentally different from traditional open source software because of the enormous capital required to train foundation models. Cohn suggests legal mechanisms like compulsory licensing, similar to how cover songs work in copyright law, as one possible path toward broader public access.6. A core privacy principle Cohn advocates is that data collected for one purpose must not be used for others. This single rule, if enforced, would begin dismantling the infrastructure that enables mass individual surveillance, including the AI-powered profiling she sees as the next dangerous frontier.7. Cohn is stepping down from EFF after 26 years to allow new leadership and return to litigation, which is where she believes her impact is greatest. She also wrote a book called Privacy's Defender to preserve the history of digital rights fights from the 1990s onward and to help people understand how current threats emerged so they can work to reverse them.

Monde Numérique - Jérôme Colombain

Tim Cook quitte la direction d'Apple et passe le relais à John Ternus • OpenAI dégaine un nouveau modèle d'images surpuissant • Une boutique 100 % gérée par une IA ouvre à San Francisco • La Chine impressionne avec un semi-marathon de robots humanoïdes • Google injecte de l'IA dans sa suite bureautique.⭐️ [Annonce] : découvrez Frogans : l'innovation française qui réinvente le Web===============Sommaire détaillé : ===============Apple : Tim Cook passe la main à John Ternus (03:11)C'est une page majeure qui se tourne chez Apple. Après quinze ans à la tête du groupe, Tim Cook quitte son poste de CEO et devient président exécutif, laissant les rênes à John Ternus, actuel responsable produits. Une transition en douceur pour l'entreprise valorisée près de 4 000 milliards de dollars, qui devra désormais relever les défis de l'intelligence artificielle et préparer l'après-iPhone. Au-delà du symbole, l'héritage de Tim Cook est considérable : montée en puissance des services, succès de l'Apple Watch et surtout virage stratégique vers les puces maison Apple Silicon, qui placent aujourd'hui la firme en position favorable dans la course à l'IA. Reste à savoir comment John Ternus imprimera sa marque.OpenAI muscle son jeu avec GPT-5.5 et ChatGPT Image 2.0 (05:44)OpenAI frappe fort avec GPT-5.5, nouvelle version de son grand modèle de langage, plus rapide, plus performant mais aussi plus cher, destiné aux abonnés payants et aux entreprises via API. L'objectif est clair : reprendre l'avantage face à Google et Anthropic dans une compétition devenue féroce. En parallèle, le nouveau modèle de génération d'images ChatGPT Image 2.0 impressionne par son réalisme et sa capacité à produire du texte fiable dans de nombreuses langues. Intégré à Codex pour les développeurs, il ouvre des perspectives créatives considérables… tout en soulevant des risques accrus d'usages frauduleux.DeepSeek V4 et le réveil chinois de l'IA (08:06)La Chine n'est pas en reste avec la sortie de DeepSeek V4, modèle open source décliné en version Pro et Flash, aux capacités agentiques renforcées. Depuis son irruption en 2025, DeepSeek bouscule le marché en affichant des performances comparables aux leaders américains avec des ressources optimisées. Selon le baromètre annuel de l'université Stanford, la Chine talonne désormais les États-Unis tandis que la France ne place qu'un seul modèle dans le haut du classement, signé Mistral AI. Les écarts d'investissement restent abyssaux, illustrant un décrochage européen préoccupant.Andon Market : la boutique créée par une IA (10:25)À San Francisco, sur Union Street, une petite échoppe baptisée Endowment Market intrigue : concept, bail commercial, commandes fournisseurs, site web… tout a été orchestré par une IA nommée Luna, dotée d'un budget initial de 100 000 dollars. Derrière l'expérience, la start-up Andon Labs teste une idée radicale : une intelligence artificielle peut-elle créer et gérer un commerce rentable dans le monde réel ? Si des humains assurent la vente en magasin, l'initiative pose une question vertigineuse sur l'autonomie économique des machines.Meta surveille ses employés pour entraîner ses IA (12:36)Chez Meta, un programme baptisé “Model Capability Initiative” installe des outils de suivi sur les postes de travail afin de collecter des données comportementales destinées à l'entraînement des modèles d'IA. Officiellement conçue pour améliorer les performances des systèmes, la démarche suscite des inquiétudes en interne, sur fond de licenciements. Jusqu'où peut-on aller dans la captation des données des salariés au nom de l'innovation ?Cyberattaques : l'ANTS piratée, un hacker arrêté (14:02)Nouvelle alerte en France avec le piratage de l'Agence nationale des titres sécurisés (ANTS). Un hacker affirme détenir 19 millions d'enregistrements comprenant des données d'état civil, désormais proposées à la vente sur le darknet. Une enquête est ouverte et la CNIL a été saisie. Dans le même temps, un pirate présumé de 21 ans, connu sous le pseudonyme Hexdec, a été interpellé en Vendée. Soupçonné d'être lié à plusieurs attaques majeures, il avait récemment revendiqué ses actes dans une interview, assumant agir uniquement pour l'argent.Health Data Hub : cap sur un hébergeur français (16:41)Le Health Data Hub ne sera finalement pas hébergé par Microsoft. Après polémique autour des risques liés au Cloud Act américain, le gouvernement confie l'infrastructure à Scaleway, filiale du groupe Iliad. La migration prévue fin 2026 marque un tournant stratégique vers une souveraineté numérique renforcée pour cette plateforme destinée à soutenir la recherche en santé grâce à l'IA.Google et l'entreprise agentique (43:04)À Las Vegas, lors de Cloud Next 2026, Google a présenté sa vision de “l'entreprise agentique”. Objectif : déployer des agents IA capables d'automatiser tâches répétitives, réponses à appels d'offres, analyses de données ou gestion RH. Dans Google Workspace, l'IA Gemini devient transversale et proactive, capable de synthétiser agenda, mails et documents pour assister l'utilisateur. Pour les entreprises, une marketplace d'agents et des outils de gouvernance promettent d'encadrer cette nouvelle génération d'assistants intelligents

Darn IT Podcast
Why Cybersecurity Startups Are Being Targeted? What That Means For Your Business?

Darn IT Podcast

Play Episode Listen Later Apr 22, 2026 27:08


The company you hired to protect you just got hacked. That is not a hypothetical, it is the defining threat pattern of the past 18 months. In this episode Darnley breaks down why cybersecurity vendors, including some of the most recognized names in the space, have become the highest-value targets for threat actors, how a single vendor compromise translates directly into a supply chain breach affecting hundreds or thousands of downstream clients, and what every business needs to do before signing another security contract. Featuring real-world case vendors including SolarWinds, Okta, CrowdStrike, Sisense, and the 2026 eScan compromise, plus a practical vendor vetting playbook and a hard look at why infrastructure-level privacy matters more.Listen hereClick here to send future episode recommendationSupport the showSubscribe now to Darnley's Cyber Cafe and stay informed on the latest developments in the ever-evolving digital landscape.

O Mundo Agora
Pacotes de IA expõem dilema do Brasil na disputa entre EUA e China

O Mundo Agora

Play Episode Listen Later Apr 21, 2026 4:47


Em 23 de julho de 2025, Donald Trump assinou ordem para exportar “pacotes completos” de inteligência artificial, colocando o Brasil entre destinos prioritários ao lado de Egito e Indonésia. A medida intensifica a disputa com a China por influência tecnológica global. No mesmo período, o Brasil firmou memorando com Pequim e negocia com Washington, enquanto amplia dependência de infraestrutura digital estrangeira. Thiago Aragão, analista de geopolítica O Brasil está nominalmente na lista de destinos prioritários. Ao lado do Egito e da Indonésia, o país figura entre os mercados emergentes onde a presença americana precisa ser consolidada, antes que a influência chinesa se torne irreversível. Para entender o que isso representa na prática, vale olhar o que aconteceu com o Japão. Em outubro de 2025, durante a visita de Trump a Tóquio, os dois países assinaram um “Technology Prosperity Deal”, um acordo de alinhamento em política de IA que vai muito além da compra e venda de hardware. O documento inclui compromissos sobre padrões técnicos, frameworks de governança, fluxo de dados e cooperação em segurança digital. O Japão passou a integrar estruturalmente a órbita tecnológica americana, não apenas como parceiro comercial, mas como parceiro normativo. Washington quer replicar esse modelo em escala. Leia tambémPossível uso de inteligência artificial em ataques no Oriente Médio levanta questões, diz especialista A lógica americana é clara e, num certo sentido, legítima. A China exporta tecnologia de IA num modelo que analistas descrevem como “full-stack com condições embutidas”: hardware subsidiado, software com lógica de caixa preta e frameworks de governança que replicam o modelo regulatório de Pequim. Washington entendeu que competir chip a chip não é suficiente. É preciso exportar o ecossistema inteiro e, com ele, a arquitetura normativa que o acompanha. Para o Brasil, o problema é que os dois modelos chegam com política externa no rodapé do contrato. Leia tambémNa Índia, Lula diz que IA sem regulação ameaça a democracia e aprofunda desigualdades Em 2025, o governo Lula assinou um memorando de entendimento com a China para aprofundar a colaboração em inteligência artificial. No mesmo período, Brasília avançava nas conversas com Washington sobre o programa de exportação de IA e recebia anúncios de bilhões de dólares em data centers da Microsoft, Amazon e Oracle. Do ponto de vista diplomático, é um malabarismo admirável. Do ponto de vista tecnológico, é uma contradição estrutural que vai cobrar seu preço mais cedo do que se imagina. A questão central não é quem vende o chip. É quem treinou o modelo. Os grandes sistemas de linguagem e tomada de decisão que o setor público e privado brasileiro já usa, na análise de crédito, na triagem de políticas, na recomendação de conteúdo e na gestão de contratos foram desenvolvidos majoritariamente por empresas americanas, segundo padrões americanos, com dados que refletem realidades americanas. O viés não é necessariamente malicioso. Mas é estrutural. E tende a se aprofundar na medida em que o Brasil sustenta sua infraestrutura cognitiva sobre servidores sujeitos ao CLOUD Act americano, a lei que autoriza o governo federal dos EUA a requisitar dados armazenados por provedores americanos em qualquer jurisdição do mundo, independentemente de onde o servidor esteja fisicamente localizado. Leia tambémInteligência artificial: China alerta para cenário apocalíptico ao estilo 'O Exterminador do Futuro' O próprio debate regulatório revela a ambiguidade. O Senado brasileiro tem acompanhado de perto o AI Act europeu como referência normativa para sua legislação nacional, e o projeto em discussão cria um sistema de governança de IA sob a responsabilidade da Autoridade Nacional de Proteção de Dados. Na teoria, é soberania. Na prática, o discurso regulatório aponta para autonomia, mas a implementação é operada por corporações multinacionais americanas. O Brasil faz a lei, mas quem comanda a infraestrutura sobre a qual essa lei incide são outros. Isso não é uma acusação. É uma descrição de como o poder funciona no século 21. Brasil é maior mercado de dados da América Latina A boa notícia é que o Brasil tem cartas genuínas nessa mesa. É o maior mercado de dados da América Latina, tem uma das matrizes energéticas mais limpas do mundo, o que importa imensamente para data centers, e produziu o Pix, um dos sistemas de pagamentos digitais mais sofisticados em operação no planeta. Quando Washington e Pequim disputam o Brasil como parceiro de IA, não o fazem por generosidade. É porque o país tem o que ambos precisam: escala, energia e população conectada. A dependência, se vier, será escolhida, não imposta. A pergunta que o debate público brasileiro ainda não fez com a seriedade necessária é esta: ao aceitar o pacote completo de IA americano, com seus chips, seus modelos, seus padrões de governança e suas obrigações de compliance, o que o Brasil está abrindo mão em troca? Não em termos comerciais, mas em termos de autonomia sobre decisões que, daqui a dez anos, serão tomadas por sistemas que alguém, em algum lugar, já programou.

La French Connection
Épisode 0x292 - Souveraineté numérique : Québec n'est pas maître de ses données

La French Connection

Play Episode Listen Later Apr 17, 2026 66:46


Synopsis Épisode spécial de La French Connection avec Jean-François Courteau, président et fondateur de 4DS Technologie, venu présenter son rapport sur la souveraineté des données au Québec. Patrick, Francis et Steve décortiquent avec lui les résultats d'une étude qui a fait jaser jusqu'à Radio-Canada : analyse géographique de l'hébergement Web et courriel des ministères, des 40 plus grandes villes, des 30 plus grandes entreprises et des 40 plus grandes PME du Québec. Le constat est sans équivoque : le Québec n'est pas maître de ses données. Plus de 90 % des organisations gouvernementales ont leurs courriels chez Microsoft, plus de 82 % de l'ensemble des organisations analysées ont leurs courriels filtrés ou hébergés par des entreprises américaines. Le trio revient sur le CLOUD Act américain, cette loi adoptée en 2018 qui donne aux agences fédérales le droit d'exiger les données de tout client d'une entreprise américaine, sans mandat canadien, et avec une clause bâillon qui empêche le fournisseur d'aviser son client. Jean-François explique pourquoi l'emplacement physique des serveurs ne veut rien dire si la compagnie qui les opère est soumise à une juridiction étrangère - et pourquoi la nationalité du fournisseur pèse trois fois plus lourd dans son système de pointage. Francis apporte une perspective critique : le rapport est un bon point de départ mais ne couvre pas toutes les dépendances cachées - Cloudflare, AWS, GitHub, les tenants Microsoft des clients et fournisseurs. La panne Cloudflare du 18 novembre 2025 a démontré à quel point l'économie numérique repose sur une poignée de joueurs. Patrick ramène le palmarès gênant des partis politiques québécois et canadiens : même le PQ et Québec Solidaire, ardents défenseurs de l'achat local, hébergent leurs services chez Cloudflare, Google et Microsoft. L'épisode se termine sur des pistes concrètes : l'annonce du ministre Gilles Bélanger de février 2026 qui marque un virage à 180 degrés vers le logiciel libre, l'exemple du Schleswig-Holstein en Allemagne qui économise 15 M€ par an en sortant de Microsoft 365, et l'idée d'un package “PME souveraine” basé sur Nextcloud, Postfix, Dovecot et LibreOffice pour donner aux entreprises une alternative clé en main aux géants américains. Invité Spécial Jean-François Courteau Crew Patrick Mathieu Francis Coats Steve Waterhouse Liens et ressources Rapport sur la souveraineté des données au Québec (2025) PowerOn Energy - Solutions de souveraineté numérique Le CyberPanier - Marché numérique souverain AugureAI - IA canadienne (tarification) 8x8 Video Conferencing Nextcloud Talk High Performance Backend avec Docker (Arno Welzel) Outil “Vérifier où est hébergé votre site Web” 4DS Technologie Décret 38-2019 (PCCTI) Annonce du ministre Bélanger - Politique de souveraineté numérique (février 2026) CLOUD Act - Quelle souveraineté sur les données numériques? Panne Cloudflare du 18 novembre 2025 Schleswig-Holstein sort de Microsoft 365 - 15 M€ d'économies Danemark abandonne Microsoft Office pour LibreOffice Lyon abandonne Microsoft Office 4,1 M$ par semaine envoyés à Microsoft par le Québec Nextcloud - alternative libre à Microsoft 365 Micrologic - “Projet Cirrus” LibreOffice Shamelessplug Join Discord securite.fm Hackfest iHack POLAR conference La French Connection sur YouTube Crédits Montage audio par Hackfest Communication Locaux virtuels par Streamyard

c't uplink (HD-Video)
Passwörter raus aus der US-Cloud – aber wohin? | c't uplink

c't uplink (HD-Video)

Play Episode Listen Later Mar 28, 2026


Es ist ein Interessenkonflikt. Passwortmanager vereinfachen einem das Leben, weil man mit Ihnen mehr oder weniger komfortabel für jedes (Online-)Konto ein eigenes und sicheres Passwort vergeben kann. So kann man hunderte Passwörter einsetzen, ohne ein fotografisches Gedächtnis zu besitzen. Gleichzeitig aber bietet man eine sehr attraktive Angriffsfläche, gerade Online-Passwortmanager, die die Passwörter via Server zwischen mehreren Endgeräten synchronisieren. Dieser Datenschatz erweckt auch das Interesse von Behörden. Populäre Passwortmanager – Bitwarden, LastPass, Dashlane – aus den USA kommen oder von dortigen Firmen entwickelt werden. Und US-Behörden könnten mit Verweis auf Cloud Act und Foreign Intelligence Surveillance Act (FISA) Zugriff auf die Daten verlangen. Eine aktuelle Untersuchung der ETH Zürich zeigte zudem, dass trotz Ende-zu-Ende-Verschlüsselung unter bestimmten Bedingungen Passwörter abgreifbar sein können – etwa wenn der Server manipuliert wird. https://www.heise.de/news/Schwachstellen-in-Cloud-basierten-Passwort-Managern-11179212.html Manch einer wird sich daher fragen, ob man die eigenen Passwörter nicht vielleicht in souveränere Gefilde umzieht. Welche Alternativen es gibt und wie sinnvoll die sind, diskutieren die c't-Redakteure Jan Schüßler und Niklas Dierking in der neuen Folge von c't uplink mit Moderator Keywan Tonekaboni. Jan Schüßler hat fünf Passwortmanager getestet, die entweder aus der EU stammen oder Open-Source-Community-Projekte sind – sowohl cloud-basierte Dienste als auch lokale Lösungen wie KeepassXC/KeepassDX. Niklas Dierking hat Passbolt auf einem eigenen Server installiert und ordnet die Erfahrung im Vergleich zu VaultWarden ein. Die drei c't Redakteure vergleichen Komfort, Kosten und Sicherheitskonzepte der verschiedenen Alternativen. Lösungen – etwa fehlende biometrische Entsperrung am Desktop. Außerdem gibt das Team praktische Tipps für den Umstieg von einem Passwortmanager zum anderen, erklärt Synchronisierungswege über Syncthing oder Nextcloud und warnt vor typischen Stolperfallen bei der Migration. Zu Gast im Studio: Niklas Dierking und Jan Schüßler Host: Keywan Tonekaboni Produktion: Tobias Reimer Im Newsletter c't Open Source Spotlight ordnen Keywan und Niklas aktuelle Entwicklungen rund um freie Software ein und stellen innovative Open-Source-Anwendungen vor. Jetzt anmelden und an jedem zweiten Freitag eine neue Ausgabe erhalten. https://www.heise.de/newsletter/anmeldung.html?id=ct-opensource Passwortmanager: Gute Gründe für europäische Clouds oder Self Hosting: https://www.heise.de/ratgeber/Passwortmanager-Gute-Gruende-fuer-europaeische-Clouds-oder-Self-Hosting-11172904.html Fünf Open-Source-Passwortmanager im Vergleich: https://www.heise.de/ratgeber/Fuenf-Open-Source-Passwortmanager-im-Vergleich-11172914.html Passbolt: Den europäischen Open-Source-Passwortmanager selbst hosten: https://www.heise.de/ratgeber/Passbolt-Den-europaeischen-Open-Source-Passwortmanager-selbst-hosten-11172920.html Anleitung: Von LastPass zum Passwortmanager KeePassXC wechseln: https://www.heise.de/ratgeber/Anleitung-Von-LastPass-zum-Passwortmanager-KeePassXC-wechseln-5075363.html Raspberry Pi als zentralen Backup-Server mit Syncthing einrichten - https://www.heise.de/ratgeber/Raspi-Backup-Plattformunabhaengiges-Backup-mit-Syncthing-einrichten-6111168.html - https://www.heise.de/ratgeber/Raspberry-Pi-als-zentralen-Backup-Server-mit-Syncthing-einrichten-6109494.html Anleitung: Raspberry Pi als Passwort-Server einrichten: https://www.heise.de/ratgeber/Anleitung-Raspberry-Pi-als-Passwort-Server-einrichten-6005925.html

c’t uplink
Passwörter raus aus der US-Cloud – aber wohin? | c't uplink

c’t uplink

Play Episode Listen Later Mar 28, 2026 38:49 Transcription Available


Es ist ein Interessenkonflikt. Passwortmanager vereinfachen einem das Leben, weil man mit Ihnen mehr oder weniger komfortabel für jedes (Online-)Konto ein eigenes und sicheres Passwort vergeben kann. So kann man hunderte Passwörter einsetzen, ohne ein fotografisches Gedächtnis zu besitzen. Gleichzeitig aber bietet man eine sehr attraktive Angriffsfläche, gerade Online-Passwortmanager, die die Passwörter via Server zwischen mehreren Endgeräten synchronisieren. Dieser Datenschatz erweckt auch das Interesse von Behörden. Populäre Passwortmanager – Bitwarden, LastPass, Dashlane – aus den USA kommen oder von dortigen Firmen entwickelt werden. Und US-Behörden könnten mit Verweis auf Cloud Act und Foreign Intelligence Surveillance Act (FISA) Zugriff auf die Daten verlangen. Eine aktuelle Untersuchung der ETH Zürich zeigte zudem, dass trotz Ende-zu-Ende-Verschlüsselung unter bestimmten Bedingungen Passwörter abgreifbar sein können – etwa wenn der Server manipuliert wird. Manch einer wird sich daher fragen, ob man die eigenen Passwörter nicht vielleicht in souveränere Gefilde umzieht. Welche Alternativen es gibt und wie sinnvoll die sind, diskutieren die c't-Redakteure Jan Schüßler und Niklas Dierking in der neuen Folge von c't uplink mit Moderator Keywan Tonekaboni. Jan Schüßler hat fünf Passwortmanager getestet, die entweder aus Europa stammen und/oder Open Source sind – sowohl cloud-basierte Dienste als auch lokale Lösungen wie KeepassXC/KeepassDX. Niklas Dierking hat Passbolt auf einem eigenen Server installiert und ordnet die Erfahrung im Vergleich zu VaultWarden ein. Die drei c't Redakteure vergleichen Komfort, Kosten und Sicherheitskonzepte der verschiedenen Alternativen. Außerdem gibt das Team praktische Tipps für den Umstieg von einem Passwortmanager zum anderen, erklärt Synchronisierungswege über Syncthing oder Nextcloud und warnt vor typischen Stolperfallen bei der Migration.

c't uplink (SD-Video)
Passwörter raus aus der US-Cloud – aber wohin? | c't uplink

c't uplink (SD-Video)

Play Episode Listen Later Mar 28, 2026


Es ist ein Interessenkonflikt. Passwortmanager vereinfachen einem das Leben, weil man mit Ihnen mehr oder weniger komfortabel für jedes (Online-)Konto ein eigenes und sicheres Passwort vergeben kann. So kann man hunderte Passwörter einsetzen, ohne ein fotografisches Gedächtnis zu besitzen. Gleichzeitig aber bietet man eine sehr attraktive Angriffsfläche, gerade Online-Passwortmanager, die die Passwörter via Server zwischen mehreren Endgeräten synchronisieren. Dieser Datenschatz erweckt auch das Interesse von Behörden. Populäre Passwortmanager – Bitwarden, LastPass, Dashlane – aus den USA kommen oder von dortigen Firmen entwickelt werden. Und US-Behörden könnten mit Verweis auf Cloud Act und Foreign Intelligence Surveillance Act (FISA) Zugriff auf die Daten verlangen. Eine aktuelle Untersuchung der ETH Zürich zeigte zudem, dass trotz Ende-zu-Ende-Verschlüsselung unter bestimmten Bedingungen Passwörter abgreifbar sein können – etwa wenn der Server manipuliert wird. https://www.heise.de/news/Schwachstellen-in-Cloud-basierten-Passwort-Managern-11179212.html Manch einer wird sich daher fragen, ob man die eigenen Passwörter nicht vielleicht in souveränere Gefilde umzieht. Welche Alternativen es gibt und wie sinnvoll die sind, diskutieren die c't-Redakteure Jan Schüßler und Niklas Dierking in der neuen Folge von c't uplink mit Moderator Keywan Tonekaboni. Jan Schüßler hat fünf Passwortmanager getestet, die entweder aus der EU stammen oder Open-Source-Community-Projekte sind – sowohl cloud-basierte Dienste als auch lokale Lösungen wie KeepassXC/KeepassDX. Niklas Dierking hat Passbolt auf einem eigenen Server installiert und ordnet die Erfahrung im Vergleich zu VaultWarden ein. Die drei c't Redakteure vergleichen Komfort, Kosten und Sicherheitskonzepte der verschiedenen Alternativen. Lösungen – etwa fehlende biometrische Entsperrung am Desktop. Außerdem gibt das Team praktische Tipps für den Umstieg von einem Passwortmanager zum anderen, erklärt Synchronisierungswege über Syncthing oder Nextcloud und warnt vor typischen Stolperfallen bei der Migration. Zu Gast im Studio: Niklas Dierking und Jan Schüßler Host: Keywan Tonekaboni Produktion: Tobias Reimer Im Newsletter c't Open Source Spotlight ordnen Keywan und Niklas aktuelle Entwicklungen rund um freie Software ein und stellen innovative Open-Source-Anwendungen vor. Jetzt anmelden und an jedem zweiten Freitag eine neue Ausgabe erhalten. https://www.heise.de/newsletter/anmeldung.html?id=ct-opensource Passwortmanager: Gute Gründe für europäische Clouds oder Self Hosting: https://www.heise.de/ratgeber/Passwortmanager-Gute-Gruende-fuer-europaeische-Clouds-oder-Self-Hosting-11172904.html Fünf Open-Source-Passwortmanager im Vergleich: https://www.heise.de/ratgeber/Fuenf-Open-Source-Passwortmanager-im-Vergleich-11172914.html Passbolt: Den europäischen Open-Source-Passwortmanager selbst hosten: https://www.heise.de/ratgeber/Passbolt-Den-europaeischen-Open-Source-Passwortmanager-selbst-hosten-11172920.html Anleitung: Von LastPass zum Passwortmanager KeePassXC wechseln: https://www.heise.de/ratgeber/Anleitung-Von-LastPass-zum-Passwortmanager-KeePassXC-wechseln-5075363.html Raspberry Pi als zentralen Backup-Server mit Syncthing einrichten - https://www.heise.de/ratgeber/Raspi-Backup-Plattformunabhaengiges-Backup-mit-Syncthing-einrichten-6111168.html - https://www.heise.de/ratgeber/Raspberry-Pi-als-zentralen-Backup-Server-mit-Syncthing-einrichten-6109494.html Anleitung: Raspberry Pi als Passwort-Server einrichten: https://www.heise.de/ratgeber/Anleitung-Raspberry-Pi-als-Passwort-Server-einrichten-6005925.html

Mon Carnet, l'actu numérique
Souveraineté numérique : pourquoi les entreprises canadiennes cherchent des solutions locales

Mon Carnet, l'actu numérique

Play Episode Listen Later Mar 9, 2026 17:09


Benoît Martel, président et fondateur de R2I, explique que la souveraineté numérique n'est plus un débat théorique, mais une préoccupation très concrète pour les entreprises canadiennes. Dans un contexte où le Cloud Act américain inquiète davantage, il rappelle qu'une donnée hébergée par un fournisseur américain peut rester soumise à la juridiction des États-Unis, même si elle se trouve physiquement au Canada. R2I, qui offre depuis plus d'une décennie une solution infonuagique canadienne baptisée Edwin, dit constater une forte hausse de la demande pour des services locaux, souverains et redondants, notamment de la part d'organisations qui arrivent à l'échéance de leurs contrats avec les grands hyperscalers. Benoit Martel insiste aussi sur le fait que la souveraineté numérique ne concerne pas seulement l'hébergement, mais aussi la sécurité, la conformité et la capacité de reprise en cas de crise. R2i est partenaire de Mon Carnet. Merci à R2i de soutenir la production de ce podcast.

Business of Tech
Pentagon Pressures Anthropic for AI Access; VMware Exit Costs and Compliance Risks for MSPs

Business of Tech

Play Episode Listen Later Feb 26, 2026 13:58


The episode's central development is the ongoing dispute between the U.S. Department of Defense and Anthropic regarding Pentagon demands for unrestricted access to Claude, Anthropic's AI model. According to Dave Sobel, the Pentagon has threatened to sever ties or invoke the Defense Production Act if the company does not comply, seeking capabilities that Anthropic argues may be illegal—specifically mass surveillance without warrants and autonomous weapons systems without human control. This move exposes Managed Service Providers (MSPs) serving defense contractors to unpredictable legal, operational, and compliance risks embedded in their AI workflows. The analysis highlights that a commercial AI provider's acceptable use policy now intersects directly with national security policy, and even partial vendor compliance can trigger regulatory or legal instability for dependent organizations. For MSPs, this means that building service offerings on AI infrastructures without clear fallback strategies or documented policy change clauses can lead to unmanageable risk and liability in the event of provider or legal regime shifts. Dave Sobel stresses that failing to address policy volatility as part of a managed service amounts to underwriting geopolitical risk without compensation. Other notable developments include the passage of the Small Business Artificial Intelligence Advancement Act, federal cybersecurity resource contraction as CISA operates with 38% staffing after layoffs, and heightened uncertainty around cloud infrastructure due to Microsoft's Azure Local “air-gapped” offering not wholly mitigating U.S. CLOUD Act exposure. Vendor news covered new AI-powered compliance features from Compliance Scorecard (version 10) and Beachhead Solutions (ComplianceEZ 2.0), Apple's accelerated retirement of Rosetta 2 translation technology, a Microsoft 365 Copilot DLP change, and continued fallout from VMware's acquisition by Broadcom, which has led to ongoing cost and trust challenges for cloud and infrastructure partners. The episode's clear implications for MSPs and IT providers are operational. Service catalogs and statements of work should actively address AI provider liability, dependency exit planning, and degraded federal cybersecurity support. Without scheduled and documented compatibility and risk reviews, MSPs absorb hidden exposure into their margins. Vendor stability can no longer be assumed, and proactive policy, renewal intelligence, and transparent advisory sessions are now required to avoid unplanned liability, budget crises, and damaged client trust. Four things to know today 00:00 Pentagon Threatens Anthropic Over Claude Access, Demands Autonomous Weapons Use 04:31 CISA Cuts, Azure Sovereignty Push Signal End of Federal MSP Safety Net 06:56 AI Compliance Tools Flood Market as MSPs Face Validation Gap 09:54 86% of Firms Cutting VMware Ties as Broadcom Renewal Costs Loom   This is the Business of Tech.    Supported by: Small Biz Thoughts Community

Explain IT
Data Sovereignty in a Multi Cloud World

Explain IT

Play Episode Listen Later Feb 24, 2026 37:16


"It's not just about where your data lives - it's about who should, or shouldn't, have access to it."In this episode of Softcat's Explain IT podcast, host Helen Gidney, Head of Architecture at Softcat, is joined by Sabina Anja, Chief Technologist, VMware Cloud Foundation at Broadcom, and Gary Hawkins, Chief Technologist, Hybrid Platforms at Softcat, to demystify the complexities of Data Sovereignty.As organisations face increasing regulatory pressure and the rapid adoption of AI, understanding where your data lives - and who controls it - is critical. The discussion explores how governance, the Cloud Act, and GDPR are reshaping cloud strategies across Europe, driving a renewed interest in private cloud and sovereign cloud solutions.In this episode, Helen, Sabina and Gary discuss:• Defining Data Sovereignty: Why it is not just about location, but about jurisdiction, technical control, and operational access.• The Reality of Repatriation: Analysing the shift back to on-premise or Neo cloud environments to control data, without abandoning public cloud entirely.• Modern Infrastructure: How containers, Kubernetes, and AI demands are influencing infrastructure and data design.• The Power of Platforms: Meaningful insights on using VMware Cloud Foundation 9 (VCF9) to provide a unified control plane for policy-based data sovereignty.Thanks for listening to the Explain IT podcast from Softcat.This podcast is produced by The Podcast Coach. Hosted on Acast. See acast.com/privacy for more information.

Shift: Rethinking Business
The new economics of sovereignty: AI, Capital and Canada's next advantage

Shift: Rethinking Business

Play Episode Listen Later Feb 12, 2026 33:39


In this episode of Shift, investor and innovation leader John Ruffolo offers a bold, forward‑looking take on the forces reshaping Canada's economic future and the massive opportunity ahead. From digital sovereignty and the evolving implications of the U.S. Cloud Act to strengthening industrial strategy and anchoring homegrown innovation, Ruffolo highlights why now is the moment for Canada to rethink how it builds wealth and scale its brightest ideas.Candid, optimistic, and deeply pragmatic, this conversation offers a roadmap for how Canada can seize this moment and build world‑leading companies on its own soil. A must‑listen for executives, investors, and builders shaping Canada's next chapter.

Monde Numérique - Jérôme Colombain
☕️ GRAND DEBRIEF (jan. 26) – CES, voiture autonome et indépendance numérique

Monde Numérique - Jérôme Colombain

Play Episode Listen Later Feb 1, 2026 61:37


Robots, intelligence artificielle, dépendance aux géants américains, nouvelles lois sur Internet… Le mois de janvier a concentré toutes les fractures du numérique. Dans ce Grand Débrief, on prend le temps d'analyser ce que ces signaux disent vraiment de l'avenir de la tech.Le Grand Debrief vous est proposé en partenariat avec Free ProAvec François Sorel (Tech&Co) et Bruno Guglielminetti (Mon Carnet)CES 2026 : un salon moins spectaculaire, mais plus révélateurLe Consumer Electronics Show de Las Vegas a-t-il perdu de sa magie ? Moins d'annonces grand public, moins d'objets “wahou”, mais un salon qui confirme malgré tout plusieurs tendances lourdes : automatisation, robotique, intelligence artificielle omniprésente et montée en puissance des acteurs asiatiques. Bref, un CES 2026 plus sobre mais qui reflète mieux que jamais l'état réel de l'industrie technologique mondiale.- Voitures autonomes : la réalité derrière le fantasmeLes véhicules autonomes avancent vite… mais pas toujours là où on l'imagine. Waymo, Zoox ou Uber multiplient les expérimentations de niveau 4, capables de circuler sans conducteur dans des zones bien définies. En revanche, le niveau 5, celui d'une voiture autonome partout et en toutes circonstances, n'existe toujours pas.Contrairement au discours d'Elon Musk, le FSD de Tesla reste officiellement classé niveau 2, loin des critères d'autonomie totale.- Robots humanoïdes et “IA physique” : le vrai tournantLe CES 2026 a marqué une étape importante : le passage de l'IA logicielle à l'IA incarnée. Robots humanoïdes, machines domestiques intelligentes, automatisation du monde réel… la robotique entre dans un nouveau cycle. Si l'électromécanique et l'équilibre sont désormais maîtrisés, le véritable verrou reste l'intelligence elle-même.Les modèles d'IA actuels sont-ils capables de comprendre le monde physique, ou faudra-t-il changer de paradigme, comme le défend notamment Yann LeCun ?- La Chine, puissance technologique majeureTrès visible cette année à Las Vegas, la Chine n'est plus dans l'imitation mais dans l'exécution rapide et industrielle. Robots aspirateurs, robots humanoïdes, vidéoprojecteurs, électronique grand public : les innovations chinoises s'imposent par leur qualité et leur vitesse de développement. Un basculement stratégique majeur, qui redessine la concurrence mondiale — et interroge la place de l'Europe.Dépendance à la tech américaine : le réveil européen ?Pendant que les patrons de la tech défilaient au Forum économique mondial de Davos, le Parlement européen adoptait une résolution alertant sur la dépendance numérique de l'Europe. Cloud, logiciels, systèmes d'exploitation, IA : que se passerait-il en cas de tension politique majeure avec les États-Unis ? Faut-il craindre un "kill switch" (coupure totale) ou une dégradation des services ? La question n'est plus théorique, notamment après les menaces commerciales de Donald Trump et les débats autour du Cloud Act. Alors, peut-on réellement se passer de la tech américaine… si oui, à quel prix ?Cloud souverain : solution réelle ou illusion juridique ?AWS, Google et Microsoft multiplient les annonces de clouds souverains européens, comme le projet d'AWS European Sovereign Cloud. Mais une entité juridique locale suffit-elle à garantir une indépendance réelle ? Réseaux sociaux interdits aux mineurs : la fin de la récré ?Dernier grand sujet de ce Débrief : la loi française visant à interdire les réseaux sociaux aux moins de 15 ans. Après la loi sur la protection contre les contenus pornographiques, le RGPD, le DSA ou encore le projet Chat Control, la régulation numérique s'intensifie. Sommes-nous en train d'assister à la fin de l'Internet libre tel qu'on l'a connu ou à une tentative nécessaire de protection face à l'addiction, au temps d'écran et aux effets cognitifs sur les plus jeunes ?-----------♥️ Soutien : https://mondenumerique.info/don

Paul's Security Weekly
The State of Cybersecurity Hiring, 2026 content plans, and the weekly news - ESW #441

Paul's Security Weekly

Play Episode Listen Later Jan 12, 2026 95:49


First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-441

Enterprise Security Weekly (Audio)
The State of Cybersecurity Hiring, 2026 content plans, and the weekly news - ESW #441

Enterprise Security Weekly (Audio)

Play Episode Listen Later Jan 12, 2026 95:49


First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-441

Paul's Security Weekly TV
The State of Cybersecurity Hiring, 2026 content plans, and the weekly news - ESW #441

Paul's Security Weekly TV

Play Episode Listen Later Jan 12, 2026 95:49


First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-441

Enterprise Security Weekly (Video)
The State of Cybersecurity Hiring, 2026 content plans, and the weekly news - ESW #441

Enterprise Security Weekly (Video)

Play Episode Listen Later Jan 12, 2026 95:49


First Topic - Podcast Content Plans for 2026 Every year, I like to sit down and consider what the podcast should be focusing on. Not doing so ensures every single episode will be about AI and nobody wants that. Least of all, me. If I have one more all-AI episode, my head is going to explode. With that said, most of what we talk about in this segment is AI (picard face palm.png). I think 2026 will be THE defining year for GenAI. Three years after the release of ChatGPT, I think we've hit peak GenAI hype and folks are ready for it to put up or shut up. We'll see winners grow and get acquired and losers pivot to something else. More than anything, I want to interview folks who have actually seen it work at scale, rather than just in a cool demo in a vendor sandbox. Also on the agenda for this year: The battle against infostealers and session hijacking: we didn't have a good answer in 2025. When is it coming? Will it include Macs, despite them not having a traditional TPM? The state of trust in outsourcing and third party use (Cloud, MSSPs, SaaS, contractors): 2025 was not a good year for third parties. Lots of them got breached and caused their customers a lot of pain. Also, there's the state of balkanization between the US and... the rest of the entire world. Everyone outside the US seems to be trying to derisk their companies and systems from the Cloud Act right now. Vulnerability management market disruption: there are half a dozen startups already plotting to disrupt the market, likely to come out of stealth in 2026 Future of the SOC: if it's not AI, what is it? What else??? What am I missing? What would you like to see us discuss? Please drop me a line and let me know: adrian.sanabria@cyberriskalliance.com Topic 2: The state of cybersecurity hiring This topic has been in the works for a while! Ayman had a whole podcast and book focused on all the paths people take to get into security. Jackie worked with WiSys on outlining pathways into a cybersecurity career. Whether you're already in cyber or looking for a way in, this segment crams a lot of great advice into just 15-20 minutes. Segment resources: Ayman's personal guide for getting into security https://www.wicys.org/wp-content/uploads/2025/10/WiCyS-Pathways-in-Cyber-PDF-9.24.25.pdf News Finally, in the enterprise security news, Fundings and acquisitions still strong in 2026! Santa might be done delivering gifts, but not protecting Macs! ClickFix attacks Weaponized Raspberry Pis MongoDB incidents for Christmas Top 10 Cyber attacks of 2025 US gets tough on nation state hackers? Brute force attacks on Banks An AI Vending Machine All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-441

Cyberhelden
Cyberhelden 55 - To DigiD or not to DigiD

Cyberhelden

Play Episode Listen Later Jan 1, 2026 56:12


In deze aflevering bespreken we de overname van DigiD-leverancier Solvinity door het Amerikaanse Kyndryl. Wat betekent het als een cruciale schakel in de Nederlandse digitale infrastructuur in Amerikaanse handen komt, en hoe verhouden technische maatregelen zich tot juridische verplichtingen onder de Cloud Act? Daarna duiken we in The Breachies 2025 van de Electronic Frontier Foundation, waarbij we de Mixpanel-breach gebruiken om het probleem van het surveillance capitalism ecosysteem uit te leggen. We sluiten af met een verontrustend Nederlands verhaal: een 17-jarige havo-scholier die geronseld wordt door de pro-Russische hackersgroep NoName057(16) en opgepakt wordt voor spionage. De eerste vervolging onder de nieuwe spionagewet. Bronnen Solvinity overname & DigiD - Follow the Money: https://archive.ph/20251214155809/https://www.ftm.nl/artikelen/amerikanen-hebben-straks-wel-toegang-tot-digid-ondanks-belofte-van-staats-secretaris - Computable: https://www.computable.nl/2025/11/13/verkoop-van-solvinity-aan-kyndryl-valt-slecht-bij-nederlandse-overheid/ - DigiD over Solvinity: https://www.digid.nl/solvinity/ - Solvinity/Kyndryl: https://www.solvinity.com/nl/kyndryl-nederland/ The Breachies 2025 & Mixpanel - EFF Breachies 2025: https://www.eff.org/deeplinks/2025/12/breachies-2025-worst-weirdest-most-impactful-data-breaches-year - TechCrunch Mixpanel breach: https://techcrunch.com/2025/12/02/a-data-breach-at-analytics-giant-mixpanel-leaves-a-lot-of-open-questions/ - Mixpanel statement: https://mixpanel.com/blog/sms-security-incident/ - OpenAI over Mixpanel incident: https://openai.com/index/mixpanel-incident/ Spionerende scholier & NoName057(16) - NRC hoofdartikel: https://archive.ph/oc6Jr - Operation Eastwood: https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network

Tank Talks
The Rundown 12/17/25: Microsoft's Canadian AI Gamble, Quantum Bets, & Crypto's Soccer Play

Tank Talks

Play Episode Listen Later Dec 17, 2025 22:15


In this episode of Tank Talks, Matt Cohen and John Ruffolo break down a pivotal week for Canada's innovation economy. Microsoft's $7.5 billion investment in Canadian AI and cloud infrastructure sets the stage for a deeper discussion about whether foreign hyperscalers can genuinely support Canadian data and AI sovereignty under U.S. laws like the Cloud Act.John challenges the assumption that scale equals sovereignty, arguing for a more intentional strategy built through government procurement, layered infrastructure, and selective partnerships. The episode also examines Canada's new Quantum Champions program and the funding directed toward companies Anyon Systems, Xanadu, Photonic, and Nord Quantique, questioning whether current capital levels are enough to prevent Canadian breakthroughs from moving south.Layoffs across the consulting industry surface broader shifts in knowledge work, as information becomes increasingly commoditized in the age of AI. Matt and John discuss how trust, execution, and implementation are replacing traditional advisory models as the real sources of value. The episode closes with a collision of crypto and legacy power, as stablecoin issuer Tether pursues a controlling stake in Juventus, raising new questions about regulation, asset backing, and trust.As foreign capital pours in and domestic funding lags, how much control does Canada actually retain?Microsoft's $7.5B Canadian AI Investment & the Sovereignty Question (01:04)Microsoft announces a massive investment to expand AI and cloud infrastructure in Canada. Matt and John unpack why foreign capital is welcome, but claims of “sovereign AI” raise serious concerns under the U.S. Cloud Act and data jurisdiction realities.Sovereign Compute Strategy: Procurement Over Promises (04:39)John outlines how Canada could realistically build sovereign compute capacity by breaking the stack into layers, using government procurement to back domestic players, and making intentional choices about allies, chips, and infrastructure.Canada's Quantum Champions Program: A Signal or a Solution? (07:49)The federal government commits funding to four Canadian quantum startups, including Xanadu. The discussion explores whether milestone-based funding is enough or if Canada risks losing its quantum leaders to U.S. capital markets again.Why Canadian Capital Isn't Backing Its Winners (09:04)Xanadu's SPAC decision becomes a case study in Canada's capital formation problem. John explains why strong companies still struggle to raise meaningful domestic capital and what that means for long-term value creation.Consulting Firms Face Layoffs as Demand Shifts (11:36)McKinsey and other professional services firms prepare for significant job cuts. Matt and John discuss overhiring during COVID, slowing demand, and how AI is compressing the value of information-based consulting.The End of the Traditional Consulting Pyramid (14:07)AI-driven efficiency challenges the apprenticeship model. The conversation explores why implementation and trust now matter more than slide decks and why junior-heavy consulting structures may no longer work.Forward-Deployed Engineers & New Service Models (16:17)From Palantir's FDE approach to new AI-enabled services firms, Matt highlights how execution-first models are eroding traditional consulting margins and reshaping enterprise problem-solving.Crypto Meets European Dynasties: Tether & Juventus (19:00)Tether's attempted acquisition of Juventus sparks debate around stablecoin backing, asset quality, and trust. John questions whether a treasury-backed stablecoin should ever be tied to assets like football clubs.Trust as the Core Currency of the AI Era (21:03)The episode closes with a clear takeaway: information is cheap, execution is hard, and trust is everything, from sovereign infrastructure to consulting, investing, and crypto.Connect with John Ruffolo on LinkedIn: https://ca.linkedin.com/in/joruffoloConnect with Matt Cohen on LinkedIn: https://ca.linkedin.com/in/matt-cohen1Visit the Ripple Ventures website: https://www.rippleventures.com/ This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit tanktalks.substack.com

Choses à Savoir TECH
Stocker les data en Europe ne nous protègent pas des USA ?

Choses à Savoir TECH

Play Episode Listen Later Dec 16, 2025 2:55


C'est une révélation qui risque de refroidir les ardeurs des partisans du cloud « souverain ». En Allemagne, un rapport juridique commandé par le ministère de l'Intérieur, longtemps resté confidentiel, vient d'être rendu public grâce à une demande d'accès à l'information. Et son constat est sans appel : les lois américaines permettent bel et bien aux agences de renseignement des États-Unis d'accéder à des données hébergées en Europe. Pour y voir clair, Berlin avait missionné des juristes de l'Université de Cologne. Leur question était simple, mais explosive : jusqu'où s'étend réellement le pouvoir des autorités américaines sur les données stockées hors de leur territoire ? La réponse tient en quelques textes bien connus à Washington : le Stored Communications Act, renforcé par le Cloud Act, et surtout la section 702 du Foreign Intelligence Surveillance Act, prolongée par le Congrès jusqu'en 2026 au moins. Ensemble, ces lois offrent une portée extraterritoriale massive aux services américains. Le point clé est juridique, pas géographique. Peu importe que vos données soient stockées à Francfort, Dublin ou Paris. Ce qui compte, c'est qui contrôle l'infrastructure. Si la maison mère d'un fournisseur cloud est basée aux États-Unis, elle peut être contrainte de transmettre des données, même si celles-ci sont hébergées par une filiale européenne. Et la zone grise va plus loin encore : selon les experts cités par Heise Online, même certaines entreprises européennes peuvent être concernées dès lors qu'elles entretiennent des relations commerciales substantielles avec les États-Unis. On pourrait croire que le chiffrement règle le problème. Là encore, le rapport tempère. Le droit américain impose aux entreprises de préserver l'accès aux données jugées pertinentes dans le cadre d'enquêtes potentielles. Un fournisseur cloud qui se rendrait techniquement incapable d'y accéder s'exposerait à de lourdes sanctions. Résultat : un conflit frontal entre le RGPD européen, qui limite les transferts vers des pays tiers, et l'extraterritorialité revendiquée par Washington. Le Data Privacy Framework, censé servir de pont entre les deux blocs, apparaît plus fragile que jamais.Cette situation touche directement les géants américains du cloud, mais le cas de Microsoft 365, omniprésent dans les administrations et les entreprises européennes, cristallise les inquiétudes. Certains juristes estiment qu'un usage compatible avec le RGPD reste possible, à condition de mener des évaluations d'impact très poussées. D'autres jugent cette approche illusoire. Pour des acteurs comme Nextcloud, le diagnostic est clair : audits et clauses contractuelles ne suffisent plus. L'Europe doit investir massivement dans ses propres infrastructures, miser sur l'open source et développer des technologies réellement autonomes. Car une chose est désormais évidente : héberger des données en Europe ne garantit plus leur protection. Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.

Mon Carnet, l'actu numérique
{RÉFLEXION} - Thierry Weber : souveraineté numérique et défense nationale

Mon Carnet, l'actu numérique

Play Episode Listen Later Nov 13, 2025 4:45


Thierry Weber revient sur un virage majeur en Suisse : l'armée refuse désormais de stocker ses données sensibles chez Microsoft, invoquant les risques liés à l'infonuagique soumis au droit américain. Cette décision, motivée notamment par le Cloud Act, relance un débat qui dépasse le simple choix d'un fournisseur. Thierry Weber décrit une tension croissante entre efficacité technologique et indépendance nationale, alors que plusieurs pays repensent leurs infrastructures numériques à l'heure des cyberattaques et des ingérences potentielles.

Monde Numérique - Jérôme Colombain

En ,retard sur l'intelligence artificielle, Apple miserait sur Google Gemini pour muscler son assistant Siri. La Chine bannit les puces Nvidia. Microsoft promet un Copilot localisé pour rassurer sur la confidentialité des données.Avec Bruno Guglielminetti (Mon Carnet)Apple mise sur Google pour réinventer SiriApple aurait tranché : plutôt que de tout développer en interne, la firme californienne s'apprêterait à intégrer des modèles d'intelligence artificielle développés par Google dans son assistant vocal Siri. Selon plusieurs fuites concordantes, il s'agirait du modèle Gemini, avec ses 1 200 milliards de paramètres, le tout hébergé sur les serveurs Apple pour préserver la confidentialité des données. Un choix stratégique, signe d'un certain aveu de faiblesse sur l'IA, mais aussi d'un réalisme technologique.Ce partenariat inédit pose aussi la question de la différenciation : comment Siri saura-t-il se démarquer de l'expérience Pixel, propulsée par le même moteur IA ? Réponse attendue dans les prochaines versions d'iOS.Pékin boute Nvidia hors de Chine et crée ses propres microprocesseurs IALa Chine franchit un nouveau cap dans sa stratégie d'indépendance technologique. Pékin a officiellement interdit l'usage des puces IA étrangères dans ses centres de données publics. Nvidia — jusqu'ici très présent sur le marché chinois — est directement visé.Cette décision s'inscrit dans un mouvement entamé depuis plusieurs années : après avoir été privé des technologies américaines, Huawei a réussi à rebondir avec ses propres solutions. Le pays entend désormais faire de même avec les puces IA, en s'appuyant sur des acteurs comme Cambricon, Enflame ou encore Alibaba Cloud. Même le patron de Nvidia, Jensen Huang, reconnaît : « la Chine va gagner la course à l'IA ».Microsoft Copilot veut rassurer sur la souveraineté des donnéesMicrosoft promet que, d'ici fin 2026, son assistant Copilot de Microsoft 365 traitera les requêtes localement dans 15 pays, dont la France, le Canada et l'Allemagne. Une annonce destinée à rassurer les utilisateurs face aux enjeux de souveraineté numérique.Mais dans les faits, les données resteront soumises au Cloud Act, cette loi américaine qui autorise les autorités à accéder aux serveurs des entreprises US, même à l'étranger. En France, le sujet est particulièrement sensible, et le concept de “cloud souverain” a d'ailleurs été discrètement remplacé par celui de cloud de confiance.Au Canada, un budget national tourné vers l'infonuagiqueAu Canada, le nouveau budget fédéral 2025 prévoit d'importants investissements dans l'infrastructure numérique, avec des data centers locaux et une IA “made in Canada”. Une réponse directe aux enjeux géopolitiques et à la dépendance vis-à-vis des géants technologiques américains. Pendant ce temps, en France, l'IA reste (hélas) largement absente du débat budgétaire.-----------♥️ Soutien : https://mondenumerique.info/don

Voice of the DBA
Data Sovereignty in the Cloud

Voice of the DBA

Play Episode Listen Later Aug 28, 2025 3:11


I remember the court case years ago when the US government wanted to access data in Azure that was physically stored in Ireland. I wrote lightly about this and linked to the article back in 2020. This has typically been more of a concern for the EU (and other countries) than the US, but I'm sure there are organizations in the US that use the cloud and don't want their data accessed by other countries' governments. Recently, a Microsoft executive was asked about this in the French Senate. The Microsoft response was that they  (Microsoft) cannot guarantee data sovereignty for French customers. If the US government served a warrant under the Cloud Act, a US corporation would have to turn over the data. Read the rest of Data Sovereignty in the Cloud

Monde Numérique - Jérôme Colombain

Et si, du jour au lendemain, un conflit suffisait à couper l'accès à vos données ? La souveraineté numérique, c'est la capacité d'un pays à garder le contrôle de ses infrastructures, de ses technologies et des informations qui y circulent. Un enjeu crucial pour la France et l'Europe.

M&A Science
Cross-Border M&A Strategy: Navigating Complex International Deals with Arash Attar-Rezvani

M&A Science

Play Episode Listen Later Aug 4, 2025 42:25


Arash Attar-Rezvani - M&A Partner, Skadden, Arps, Slate, Meagher & Flom LLP Arash Attar-Rezvani, M&A Partner at Skadden based in Paris, brings over two decades of cross-border M&A strategy experience to this in-depth conversation. From billion-dollar telecom deals across Latin America to luxury brand acquisitions spanning multiple jurisdictions, Arash reveals the hidden complexities that make international M&A uniquely challenging. M&A professionals will learn how to structure deals across incompatible legal systems, navigate emerging regulatory landscapes, and build the trust essential for successful cross-border transactions. Things you will learn: How to identify and manage multiple antitrust and national security clearances across jurisdictions with varying sophistication levels Why smaller transactions often require more innovation than billion-dollar deals, and how to build structures when no legal playbook exists The psychology behind cross-border deal-making and why trust trumps even the most ironclad contracts _________________ How One Small M&A Team is Closing 8 Deals This Year See how US Heart & Vascular is running faster, cleaner deals using Buyer-Led M&A™ and DealRoom. Join Kison in the live session on August 14 at 11am EST.

AWS Morning Brief
In the Bleak Theater of the Cloud: A Werner Herzog-Style Dispatch

AWS Morning Brief

Play Episode Listen Later Jul 28, 2025 16:47


AWS Morning Brief for the week of July 28th, 2025, with Corey Quinn. Links:Launching Amazon CloudWatch generative AI observability (Preview) Amazon CloudWatch adds IPv6 supportBoost cold-start recommendations with vLLM on AWS Trainium AWS Private CA now supports issuing up to 100 million certificates per CA Amazon Connect announces per-day pricing for external voice connectors Amazon RDS for Db2 adds support for group-based authorization with self-managed Active Directory Manage multi-tenant Amazon Bedrock costs using application inference profilesSimplify serverless development with console to IDE and remote debugging for AWS Lambda | AWS News Blog AWS Generative AI for Developers Professional Certificate Simplify AWS Organization Tag Policies using new wildcard statement  Security Update for Amazon Q Developer Extension for Visual Studio Code (Version #1.84) Cost Optimization Hub now supports account names in optimization opportunities Year One of Valkey: Open-Source Innovations and ElastiCache version 8.1 for Valkey - go listen to the audio version of this newsletter specifically for this item. AWS Security Incident Response: The customer's journey to accelerating the incident response lifecycle AWS Service Reference Information now supports actions for last accessed services - Five facts about how the CLOUD Act actually works | AWS Security Blog Bob's Used Books: Build a .NET Serverless Application on AWS, Part 1: Deployment and Setup Amazon EC2 now supports skipping the operating system shutdown when stopping or terminating instances New whitepaper available: AICPA SOC 2 Compliance Guide on AWS Why 2025 is the Inflection Point for AWS Cloud Migration Beyond IAM access keys: Modern authentication approaches for AWS Introducing SRA Verify – an AWS Security Reference Architecture assessment tool Supercharging Ad Creative with Amazon Bedrock and Amazon Nova: How AI is Revolutionizing Content Generation for Advertising & Marketing Use-CasesBuilding resilient multi-tenant systems with Amazon SQS fair queues How Truth For Life transformed its viewer analytics while optimizing costs

Backup Central's Restore it All
The EU Cloud Exit - Backup Strategies for Digital Sovereignty

Backup Central's Restore it All

Play Episode Listen Later Jul 7, 2025 36:58 Transcription Available


The EU cloud exit movement is reshaping how European organizations think about data storage and sovereignty. Companies across Europe are moving away from US-based cloud providers like Microsoft 365, AWS, and Google Workspace due to concerns about the Cloud Act and data privacy regulations.In this episode, Curtis and Prasanna explore the backup implications of this major shift. They discuss the challenges of replacing comprehensive platforms like Microsoft 365 with multiple EU-based providers, the complexities of bringing services back in-house, and why the 3-2-1 backup rule becomes even more critical during these transitions.Whether organizations choose local providers or decide to self-host their infrastructure, data protection remains paramount. The hosts share real-world examples of failed backup strategies, including the Rackspace Exchange disaster and OVH's data center fire, to illustrate why third-party backup solutions are necessary regardless of your hosting choice.

KZradio הקצה
Guy Bahir: Special Guests - Cloudact / The Untattoed, 30-05-25

KZradio הקצה

Play Episode Listen Later May 30, 2025 120:06


https://www.facebook.com/fingeredfloodgate https://cloudact.bandcamp.com/ https://theuntattooed.bandcamp.com/

Lage der Nation - der Politik-Podcast aus Berlin
LdN418 Staatsstreich in den USA?, Trump verhandelt mit Putin über Ukraine (Interview Claudia Major, Politikwissenschaftlerin), TV-Duell, Bundestagswahl nach neuen Regeln, Korruption in Deutschland, CLOUD Act und Datenschutz, Bürokratieabbau in der Praxi

Lage der Nation - der Politik-Podcast aus Berlin

Play Episode Listen Later Feb 13, 2025 105:58


LdN418 Staatsstreich in den USA?, Trump verhandelt mit Putin über Ukraine (Interview Claudia Major, Politikwissenschaftlerin), TV-Duell, Bundestagswahl nach neuen Regeln, Korruption in Deutschland, CLOUD Act und Datenschutz, Bürokratieabbau in der Praxis (Interview Heidrun Hausen, DELO)