Skip to content

Your Security Model Is Stuck in the ’80s. AI Isn’t.

In this episode of Data Driven, Frank La Vigne talks with Richard Luna, CEO of Protected Harbor, about why security built around keeping attackers outside a network leaves organizations exposed once someone gets in. Richard explains his concern that AI-driven attacks will probe multiple weaknesses at once, and makes the case for layered defenses, network segmentation, and infrastructure designed around the applications it supports.

The conversation moves from security architecture to the people and processes that make systems dependable. Richard shares how his team plans for failures, works across technical silos, and tests vendor claims before putting equipment into production. Frank and Richard also explore the promise of AI-assisted coding, the experience junior developers need to build, and the expensive gap between a successful demo and software that holds up under real demand.

From a storage cluster that failed on its second day of testing to a deployment that collapsed under load, the episode offers practical lessons in building durable systems and teams that take responsibility for them.

Key Takeaways

• Design beyond the perimeter. Richard argues for barriers and tripwires inside the environment, with attention to how data moves between systems.

• Build around application needs. Storage performance, traffic separation, redundancy, and failure recovery should reflect the actual workload.

• Break down technical silos. Developers and infrastructure teams need each other’s knowledge to diagnose problems and implement security effectively.

• Keep human judgment in AI-assisted development. Generated code and automated tests still need experienced review and realistic load testing.

• Make accountability specific. Divide responsibilities clearly, give engineers a path to ask for help, and involve clients when they own a blocker.

• Test before trusting. Vendor assurances and a working demo do not establish how a system will behave in production.

About the Guest

Richard Luna is the CEO of Protected Harbor. His career has spanned software development, managed services, hosting, DevOps, and SaaS infrastructure engineering. In this conversation, he brings that experience to the design, operation, and security of systems that businesses depend on.

Links and Resources

Time Stamps

00:00 Why the 1980s security model falls short

01:21 Introducing Richard Luna

02:32 What SaaS infrastructure engineering means

03:53 AI threats, perimeter defenses, and information silos

05:44 Building barriers and tripwires

07:17 Application-aware infrastructure

10:27 Phased change and lessons from Toyota

11:22 Rebuilding infrastructure around the workload

13:37 Collaboration, zero trust, and asking for help

15:35 Data flow, security, and finding the root cause

18:19 Listening to clients and earning long-term trust

20:08 AI-assisted coding and the next generation of developers

21:17 Why generated tests are not enough

25:17 DevOps experience and “works on my machine”

26:58 Learning from the loss of a customer

29:02 Dividing responsibilities without losing accountability

31:56 Oversight meetings that remove obstacles

33:34 Empowering clients and engineers

35:42 Respect, culture, and learning across teams

38:06 Building a business by solving clients’ problems

42:01 Planning for failure instead of fighting fires

43:01 Stress-testing enterprise storage

47:01 A deployment failure and the cost of skipping tests

48:32 Cloud scaling and runaway costs

49:48 Closing thoughts and connecting with Richard

Subscribe to Data Driven for more conversations about data science, AI, data engineering, and the people building the systems behind them.

Transcript
Speaker:ncerned about, is that in the:Speaker:

you could hardcode getting in.

Speaker:

And maybe you were smart and used an encrypted— you had

Speaker:

encrypted passwords in a database, hopefully. Although this year

Speaker:

we had a client that had clear text passwords.

Speaker:

So then you're in, but once you're in, you could do anything. AI is not

Speaker:

going to attack one vector. It's going to attack everything all at the same time.

Speaker:

And it's going to overwhelm any defenses that are there. And so

Speaker:

we're designing strategies. For every lock, there's a key, and

Speaker:

for every key, there's a way to defeat the

Speaker:

entire process. So you look at

Speaker:

what an agentic agent can do and how it's going to attack,

Speaker:

and then you build in the barriers

Speaker:

for it. And each barrier, You have tripwires so

Speaker:

that you can stop certain traffic. And that's, that's the fun

Speaker:

part. Your security model is stuck in the '80s. AI isn't.

Speaker:

Today on Data Driven, Richard Luna explains why perimeter defenses

Speaker:

fall short and how to prepare for AI-powered attacks.

Speaker:

Welcome to the Data Driven Podcast.

Speaker:

Hello and welcome back to Data Driven, the podcast where we explore the emerging industry

Speaker:

of data science, artificial intelligence, and

Speaker:

data science and data engineering. And without

Speaker:

data engineers, none of this is all possible. However, my favorite data

Speaker:

engineer in the world is not able to make it here today. I'm going to

Speaker:

go on and on my own. And today we're talking with Richard Luna,

Speaker:

who is the CEO of Protected Harbor. Hi, Richard. And

Speaker:

we had some good times reminiscing about New York City

Speaker:

and places where I used to live and places there where he

Speaker:

lives now, I'm quite familiar with, and his love for the color

Speaker:

orange. Yes. So welcome to

Speaker:

the show. How's it going? Awesome. Awesome. I'm

Speaker:

in a postal show right now. So I'm enjoying it, talking to

Speaker:

clients. We are a SaaS infrastructure engineering company,

Speaker:

and one of our clients is here, and so we're supporting

Speaker:

them and they're referring to us. So

Speaker:

it's— that's always a good thing. Partnerships are a great

Speaker:

way to build a business. And these trade shows are always interesting because you get

Speaker:

to meet people, you get to interact with people. And it's old school.

Speaker:

It's what we— here's what I tell people. What we do, nobody

Speaker:

understands. When you say you're a SaaS infrastructure engineering company,

Speaker:

What does that mean? We see— we under— we can talk to programmers about what

Speaker:

the programmers need. We can talk to IT and talk

Speaker:

about resources, and we can build the infrastructure and make it resilient.

Speaker:

And that's in a nutshell what we do, because

Speaker:

I'm a lifelong technologist. And so I started as a programmer and had

Speaker:

3 commercial software packages, then went to—

Speaker:

became an MSP. All because customers drove

Speaker:

you to do these things. And that went

Speaker:

into a hosting business, which then led to a DevOps business,

Speaker:

which then led to SaaS infrastructure. And it's all

Speaker:

about, hey, we can't— this is a problem for the

Speaker:

company. Can you please help in this area? And can you please help in this

Speaker:

area? And it's sure. And now we're— SaaS

Speaker:

infrastructure is huge and we're dealing with that as well as, of course,

Speaker:

AI. From a customer viewpoint, I'm scared out of my

Speaker:

mind about the Hugging Face attack. It's

Speaker:

the more I've read about it and dove into it,

Speaker:

the scarier it is. Yeah. You know,

Speaker:

the fact that Hugging Face wasn't even the target. The whole idea

Speaker:

was the Engentic agents wanted to prove to the greater

Speaker:

that they could pass the test. And they weren't sure what the

Speaker:

grader would do, so they elected to go and find out

Speaker:

what Hugging Face did as the answer.

Speaker:

And what I think of is

Speaker:t of my clients still use the:Speaker:

If you're in the perimeter, if you're outside the perimeter, I'm not a big fan

Speaker:

of, hey, let's use this app and let's use that app and let's use this

Speaker:

box and let's use that box. Because

Speaker:

I'm of an age that you had to know and

Speaker:

understand how it all fits together, and information

Speaker:

silos have killed this industry and have led us—

Speaker:

led to us being completely wide open to attack.

Speaker:

Because the database administrator knows nothing of Windows

Speaker:

security, the Windows administrator knows nothing of what's possible

Speaker:

in firewall. Nobody is trying to break up the traffic to

Speaker:

make sure it's durable to attack. So I find these large

Speaker:

flat networks and it's like, gee, I wonder why this is

Speaker:

exposed or why ransomware went for all across the board.

Speaker:

You're right, yeah. Because nobody designed it that way.

Speaker:

You know, that's what I'm concerned about

Speaker:is that in the:Speaker:

getting in. And maybe you were smart and

Speaker:

used an encrypted— you had encrypted passwords in a database,

Speaker:

hopefully. Although this year we had a client that had clear

Speaker:

text passwords. So then you're in. But once you're in, you could do

Speaker:

anything. AI is not going to attack one vector. It's going to

Speaker:

attack everything all at the same time. And it's

Speaker:

going to overwhelm any defenses that are there. And so we're

Speaker:

designing strategies for every lock, there's a key, and for

Speaker:

every key, there's a way to defeat the entire

Speaker:

process. So you look at

Speaker:

what an agentic agent can do and how it's going to attack,

Speaker:

and then you build in the barriers

Speaker:

for it. And in each barrier, you have tripwires so

Speaker:

that you can stop certain traffic. And that's, that's the fun

Speaker:

part. I mean, Explaining this,

Speaker:

this to bring this full circle, to explain to a

Speaker:

customer at a trade show what is a SaaS engineering company,

Speaker:

I don't have the time to go through. They're not going to give me the

Speaker:

time standing at a trade show booth because we're a

Speaker:

long-time sell, right? You gotta listen. Oh, these people

Speaker:

really do know how to help us, and we'll help their programmers with

Speaker:

their DevOps, or we'll help an area, their IT with

Speaker:

blocking or their DNS is messed up. And all of a sudden it's like, oh,

Speaker:

these people actually know what they're doing. And once you have

Speaker:

that level of trust, then the doors are open. Yeah,

Speaker:

that's true. And I was looking at your— you can hear me, right? Yeah. Okay.

Speaker:

I wasn't sure. I had to mute while the dogs were barking. Yeah, no problem.

Speaker:

Because I saw that, you know, application-aware infrastructure, right? Like,

Speaker:

what exactly is that? AAI? Which I know has nothing to do with AI

Speaker:

per se, but I'm sure that since everything revolves around AI now, it

Speaker:

probably does. So what is application-aware infrastructure? It's about

Speaker:

using our knowledge of how the apps

Speaker:

work internally. I mean, a database app is gonna

Speaker:

have only so much, so many needs, and it's gonna need

Speaker:

storage, right? Let me net this out to the most

Speaker:

basic principles. Either it's going to be fully

Speaker:

a SaaS online, so it's going to be Ruby on Rails, or it'll

Speaker:

be a PHP

Speaker:

frontend, or some other language, right?

Speaker:

Or it'll be a .NET, and it'll be a database

Speaker:

language, or a database site, or

Speaker:

something all in between. Once you know

Speaker:

what the design was, then you can look at what is

Speaker:

the— what are the resources that are there? How durable

Speaker:

are those resources? So in the most grossest example, you

Speaker:

take a database server, so it lives and dies on

Speaker:

storage, and customers then complain because when we

Speaker:

go and look at it, the storage is sitting on a RAID 5,

Speaker:

right? And it's on really slow physical

Speaker:

drives. of course your customers are gonna have a hard time.

Speaker:

So what application-aware infrastructure is, is

Speaker:

it's aware of what the application needs to

Speaker:

fly. Right. And then designing the

Speaker:

infrastructure around it so that it can take off

Speaker:

and be durable, right? You know, separate the data, the

Speaker:

storage traffic from all the other traffic and make sure that there's redundancies

Speaker:

and build it all into the infrastructure so that

Speaker:

You don't say, well, when this fails, we'll do this. You say,

Speaker:

no, we've planned for this to fail, this to fail, this to fail.

Speaker:

When those fail, the backups will kick in, and that's what

Speaker:

you want. So like, in just the most basic example, all

Speaker:

our storage is double, double run so

Speaker:

that if one link dies, the traffic

Speaker:

without a blip keeps going. and everything running in that

Speaker:

traffic doesn't miss a heartbeat.

Speaker:

So that's what application-aware infrastructure is. It's really getting

Speaker:

their customers' applications, whether that's their physical

Speaker:

office applications they ran, whether that's their SaaS

Speaker:

applications, and this is a SaaS deployment, it's getting them to

Speaker:

be optimal, to get the performance optimal, the growth

Speaker:

optimal, and plan Well, how do we—

Speaker:

what happens in an emergency? What happens in an outage? Plan for it,

Speaker:

right? Yeah. You don't— and you do it in phased implementations. This way

Speaker:

you bring people along. You say, okay, there's these 5

Speaker:

things that need to get fixed right away because you are so at risk for

Speaker:

an attack. And then there's these 15 things we'll do

Speaker:

over the next 2 years working with you. to

Speaker:

improve performance. And it's a phased approach, right? You

Speaker:

can't just turn a key and everything will be right. You

Speaker:

could, but the budget for that would be like absurd. It's

Speaker:

not just— it's not the money, right? When you try to move all the

Speaker:

parts at the same time, yeah, you cause

Speaker:

chaos. I mean, look at— I'll tell you,

Speaker:

take this out of the data science world. Go look at Toyotas. You

Speaker:

look at everything they're selling now, it's all

Speaker:

the same engine tweaked, the same battery pack for the

Speaker:

hybrid system tweaked. The entire

Speaker:

components are exactly the same. They change the shell of the body.

Speaker:

And even there, the doors are all from the same

Speaker:

manufacturer and they use the same hinges in a slightly different

Speaker:

configuration depending on what it is. So they're

Speaker:

They've really studied how to get

Speaker:

durability because they have whittled down to a

Speaker:

certain set of vendors and a certain process that they follow,

Speaker:

and this is how they scale. We

Speaker:

can apply the same model, the same structure to IT

Speaker:

and SaaS infrastructure. That's how— I

Speaker:

mean, in a nutshell, that's what we do. It's like when we take

Speaker:

on a new customer, we have one rule. We have several rules, but one that's

Speaker:

really critical that nobody else bothers to do, we

Speaker:

rebuild everything that they have. Really?

Speaker:

Yeah, because here's the thing, a customer hires you because

Speaker:

their servers are slow. The

Speaker:

last 5 people that were there that looked at it,

Speaker:

were they stupid? No, they're not stupid. They were smart people.

Speaker:

They had a limited amount of time and a limited focus.

Speaker:

So what we did, what we look at, like, we have

Speaker:

a— there's a medical SaaS vendor that we are

Speaker:

converting 300 servers over.

Speaker:

None— we've not taken a single one from the old

Speaker:

hosting equipment to us. We have taken 100% of the data,

Speaker:

reset the data. Like, they had such a mess. They had

Speaker:

taken their web servers and jammed multiples of their clients

Speaker:

onto the same web server, which meant they never could do maintenance,

Speaker:

right? Because— and why? Because

Speaker:

programmers are great at being programmers. They know how to solve problems.

Speaker:

They do not know infrastructure and design. Wow.

Speaker:

And the people that usually— so, so when you have a new

Speaker:

program, a new either Internal program or SaaS,

Speaker:

what happens? The programmer says, this is what I need. I need some databases,

Speaker:

I need some web hosting, I need, you know, da.

Speaker:

And so IT goes, okay, that's it, here you go. And he wired—

Speaker:

they wired up and everything is fine initially. Until it's not,

Speaker:

until they either grow or something else happened in

Speaker:

the code that there was a resource that was just totally not

Speaker:

available. So I don't fault

Speaker:

clients, and this is where we have to be very careful because it's easy

Speaker:

in technology to play the blame game and to say the other person is

Speaker:

stupid. There's even a

Speaker:

tool in Git called the blame tool, right? Yeah, yeah.

Speaker:

And where does that get anybody? The problem in the end is

Speaker:

you need everybody's cooperation to do what we do. We need

Speaker:

the respect of the programmers, If it's a

Speaker:

SaaS organization, we need the respect of those programmers

Speaker:

because they are the ones who understand how the code works. We don't. We see

Speaker:

it anecdotally, right? From afar, you see traffic going

Speaker:

here, you see storage going there, so you can see

Speaker:

what the needs are, but you don't know what module is

Speaker:

doing what. And we need that sometimes

Speaker:

if, for example, you want to put in zero trust in the middle of the

Speaker:

code. Well, we need your help to do that. We can't do that

Speaker:

alone. We can apply

Speaker:

all the hooks so that we make it easy

Speaker:

for you, and that's where reciprocity builds. But if you

Speaker:

cause intellectual gates to go up, I mean, that's how

Speaker:

we get through the information silos, right, is prove

Speaker:

ourselves to each of the people, each of the

Speaker:

groups, that we actually know what we're doing and here's our mission.

Speaker:

And we're pretty stubborn. I mean, it happens. It's great that

Speaker:

we're New Yorkers because it's like, this is where we're driving to.

Speaker:

So we've got to drive. So please help get on board. We need your help.

Speaker:

And I was reading a study that said the

Speaker:

number one

Speaker:

aspect or the number one

Speaker:

I'm old, so I forget words now. The

Speaker:

number one trait— that was it— of successful people

Speaker:

is they know how to ask for help. Yeah.

Speaker:

And I thought about— I've been thinking a lot about that

Speaker:

because in technology, we are not trained or

Speaker:

taught to ask for help. That's true.

Speaker:

And the guy next to you or the woman next to you

Speaker:

could be the exact person who has the answer

Speaker:

to what you're looking for. So this now

Speaker:

full circle, I was raised in the environment

Speaker:

that every kilobyte was necessary,

Speaker:

every kilobyte of RAM was very

Speaker:

expensive, so you had to know what was going

Speaker:

on. And that love of understanding

Speaker:

how the world really works, because the patterns are there, I don't

Speaker:

care if you're talking about way back in a

Speaker:

6502 assembler or you're talking about AI

Speaker:

today and the latest GPU. The

Speaker:

patterns of how data flows is still there

Speaker:

exactly the same. The scale absolutely is different, but

Speaker:

the underlying rules of how data flows— data is like

Speaker:

water, it'll go everywhere if you don't put security guidelines and

Speaker:

walls up, it's just like water. It flows through every hose in the, in the

Speaker:

place, every wire. And so you

Speaker:

create those, those boxes. And I've got a

Speaker:

team of people that I have taught the

scientific principle:

peel the onion away until we find the root cause.

scientific principle:

Technology is not— I always, when people come and pitch me,

scientific principle:

you know, I'm the CEO of the company, so I get pitched all the time.

scientific principle:

If you approach me with buzzwords,

scientific principle:

it's not proving that you know what you're doing. It's proving you don't know what

scientific principle:

you're doing. Because if you really do know what you're doing,

scientific principle:

you know how to explain the concepts in basic words. I

scientific principle:

don't need to string a bunch of letters together to prove that I'm the

scientific principle:

smartest guy in the room. All I'm doing by doing that is pissing

scientific principle:

everybody off. So how about

scientific principle:

Every client meeting. In fact, I've got a dinner tonight and

scientific principle:

I'm gonna ask the same question, which is,

scientific principle:

describe to me what your ideal vendor is. That's

scientific principle:

an interesting, thought-provoking question. I bet you get a lot of answers, a lot of

scientific principle:

long— not just like, you know, if you have kids, you ask, how was

scientific principle:

your day? They'll say fine, right? Right, well, yeah, especially when you're a parent.

scientific principle:

Yeah, especially when you're a parent. Fine, like, okay. It could be the worst day

scientific principle:

of your life, could be the best day of your life. You're fine.

scientific principle:

Right. And as they get older, they'll just close the

scientific principle:

door. That's right. If you see them at all. Right. If you

scientific principle:

see them at all. Yeah. And when they get into their 20s, they'll actually talk

scientific principle:

to you. Well, that's good to know. That's good to know. Oh yeah. Then

scientific principle:

they become your best friend. Right.

scientific principle:

But it takes a life. Yeah. No, it's good to have

scientific principle:

those kind of open-ended questions because that elicits

scientific principle:

the conversation. And then what that's telling me is

scientific principle:

what they need from us. And then of course I'll ask,

scientific principle:

in what areas are we not doing those things?

scientific principle:

And the answer I always want to hear is,

scientific principle:

oh no, you guys are doing— you are the poster child of

scientific principle:

our vendors. And then I know we're doing

scientific principle:

the the right thing. We're listening at the right level, we're talking at the right

scientific principle:

level, we're making things happen, and we're making a difference. Because in the day—

scientific principle:

in the end, you can get the first contract,

scientific principle:

you won't get the second contract if you don't know how to deliver. That's

scientific principle:

true. So you'll have a client for 6

scientific principle:

months. I have clients for 2 decades,

scientific principle:

right? How can I continue to

scientific principle:

provide so much support and value that they still want us

scientific principle:

to do it for 2 decades by staying relevant. Where's your business?

scientific principle:

Anyway, I went off on a tangent. No, hey, that's what we do on the

scientific principle:

show. It's kind of our thing. One of, one of our guests suggested that we

scientific principle:

eventually sponsor an off-road racer because we're always going off the track. It was—

scientific principle:

that's actually funny. And like, I, I

scientific principle:

Googled like what those look like. I'm like, that looks like That would be fun.

scientific principle:

I would totally— Yeah, it would be fun. But how does this— how does

scientific principle:

AI really change this, right? Obviously, the technology model has changed. You mentioned

scientific principle:

the old style of you have a wall, you have a fence, you have a

scientific principle:

moat, you have a castle, no one gets in your castle, right? Now you have

scientific principle:

to assume breach. That led into zero trust.

scientific principle:

How does AI change into this? Like, AI—

scientific principle:

AI is a gift and a curse. How so?

scientific principle:

It's amazing at taking code and telling you where all the holes are in your

scientific principle:

code. And it's a curse in that, why

scientific principle:

hire junior programmers? And

scientific principle:

it's also a curse because people use it, I have seen

scientific principle:

it firsthand, people use it that don't know the material.

scientific principle:

And if you use it that way, you are in trouble.

scientific principle:

Because It is— if you have to understand

scientific principle:

how it was trained, it's trained off Reddit, and there are

scientific principle:

crazy ideas on Reddit, and there are some awesome

scientific principle:

answers in Reddit, and AI can't tell the difference.

scientific principle:

No. Right? It's— so if you get one of

scientific principle:

the crazy answers, you're gonna make a fatal flaw

scientific principle:

and a fatal mistake, right? So

scientific principle:

you gotta— you use it as a tool. I worry

scientific principle:

that we're eliminating all the jobs of the entry-level programmers and

scientific principle:

coders, and that's going to kill this industry down the

scientific principle:

road. I feel like we're poisoning the pipe. We're

scientific principle:

shutting off the pipe of new talent. I don't think that's going to end well

scientific principle:

for anyone. Nope. Nope. And the other thing

scientific principle:

is, AI can be— is great, and you can give it a prompt,

scientific principle:

and that's a whole nother science that you have to get to get, but

scientific principle:

at some point, that's got to move into production.

scientific principle:

And how do you know without thorough

scientific principle:

testing? And how do you test without the knowledge

scientific principle:

of what a test is and what the purpose is? I'm not saying you can't

scientific principle:

buy a tool that says, hey, it tests, or vibe

scientific principle:

coding will tell you, oh, we tested. What does that mean? The

scientific principle:

AI vibe coded tests. Right. Yeah.

scientific principle:

It spun up a page and it turned on the page and it said the

scientific principle:

page was rendered. Big whoop. How about you

scientific principle:

multiply that 4,000 times, like as though there's

scientific principle:

4,000 people logged in? Oh, we didn't do that type of

scientific principle:

test. We don't do that. Right? So

scientific principle:

we're missing that skill set that goes from

scientific principle:

quick to market to durable. So the

scientific principle:

future is going to have a whole lot of junk code in it. But,

scientific principle:

you know, it's— having been in this industry, uh,

scientific principle:

a long time, it's just another tool, and

scientific principle:

it's great. It's really a powerful tool if used right.

scientific principle:

And, um, it's done— I've done some wonderful

scientific principle:

designs with it, and it saved me a whole lot of time.

scientific principle:

It's, it's really efficient in ideation and making it part of,

scientific principle:

like, your brainstorming loop. Give me— today on a call I was on

scientific principle:

we were struggling to come up with a kind of one-word phrase, one sentence.

scientific principle:

Perfect. It's perfect for that. And I basically said, give me 15

scientific principle:

options, right? Right. And

scientific principle:

10 of them were— 10 of them were okay, right? 5 though,

scientific principle:

and one of them was just chef's kiss, right? And

scientific principle:

I think— But you knew the material you were looking for, Frank. That's my point.

scientific principle:

You knew when you saw the chef's kiss,

scientific principle:

you could appreciate it and it matched what your vibe was.

scientific principle:

Okay, now that's something esoteric. I'm talking about

scientific principle:

also, what if it's actual code, like processing

scientific principle:

code, and it's guessing or thinks it has it

scientific principle:

right and it ran through a series of tests? What happens

scientific principle:

when that needs to go full scale?

scientific principle:

Yeah, we don't know. I mean, no one— unless you have— unless you have—

scientific principle:

one of the things that, that I remember interviewing a guy

scientific principle:

and for a job, and I liked him, he was smart and all, and I

scientific principle:

was like, the only thing he doesn't have is the scars, right?

scientific principle:

Because sometimes what they say about good judgment is often the result

scientific principle:

of bad judgment. Yeah, yeah. Something you learn far more from your

scientific principle:

failures than you do your successes. And again,

scientific principle:

not going to name the guy, but he was very difficult to work with because

scientific principle:

it was kind of like he was very smart and he was always trying to

scientific principle:

prove that he was smart, but he didn't have the scars to be like, look,

scientific principle:

I know what the general best practice is,

scientific principle:

but sometimes you have to know— sometimes you have to be bopped on the nose

scientific principle:

and get a couple of bloody noses and realize, well—

scientific principle:

100%. Sometimes the

scientific principle:

best practice isn't worth going that doing that because it's going to cause

scientific principle:

these other problems downstream. Right. And like, you know, you want

scientific principle:

to— I think you're right, you know, having those scars,

scientific principle:

they're unpleasant experiences as you go through them. But,

scientific principle:

um, going through them, that's— it's quite

scientific principle:

unpleasant, but it's what makes you a better developer. And I

scientific principle:

think if we shut off the pipe, you know, when people our age

scientific principle:

decide— well, you're, you know, you and I are, you know,

scientific principle:

I'm 10 years younger than you. Exactly right.

scientific principle:

So, you know, in 20 years from now, you and I will both be sipping

scientific principle:

Mai Tais in a beach somewhere. You know, like— I will have a

scientific principle:

keyboard in my hand. I probably will have this tablet in my hand.

scientific principle:

But like, and I actually like what I do, right? So like, I've had

scientific principle:

this conversation with retirement planners when they come like, what do you want to do

scientific principle:

when you retire? And I'm like, I kind of like what I do, you know?

scientific principle:

But when we are no

scientific principle:

longer in the workforce, like we're cutting off, you know, the

scientific principle:

generation, maybe 2 generations below us, like they'll be the last

scientific principle:

people that know what it's like to run a DevOps thing and get their

scientific principle:

you-know-what handed to them because the deployment didn't go the way

scientific principle:

we thought it would. And, you know, you've been on those deployments where it works

scientific principle:

on my machine was an actual— people said that works on my machine.

scientific principle:

Yeah. Right? Now— Oh, I've had that happen. I've

scientific principle:

had that happen in scale

scientific principle:

here. I can't imagine what that would be like. This

scientific principle:

code worked on my laptop. Why isn't it running on the

scientific principle:

4,000 servers we have? Right, right, right, right,

scientific principle:

right, right. You know, I had a miniature version of that.

scientific principle:

I had an application that had like 200 users, and I'm still in school

scientific principle:

while I'm doing this. And like, you know, I pushed an update and I was

scientific principle:

like, it blew up on half the machines. And I'm like, it worked on my

scientific principle:

machine. And like, And then my

scientific principle:

manager at the time just shot me this look of like,

scientific principle:

like Jedi mind trick. Like I could just like, all right, I won't say that

scientific principle:

again. But, um, but no, that really taught me the,

scientific principle:

the, that, that little bloody nose taught me like really

scientific principle:

anticipate that the production, pushing it into production is gonna

scientific principle:

be a process that is gonna be unpleasant. Right.

scientific principle:

You know, or at least be prepared for it. Right. It's not gonna be as

scientific principle:

simple as compile and ship. I have learned as

scientific principle:

CEO far more from my failures

scientific principle:

than I have my successes. Now, we don't lose customers,

scientific principle:

right? Most MSPs, they did— the marketing group did

scientific principle:

what's called Net Promoter Score, and most

scientific principle:

technology companies are 30 to 35, and we're 92.

scientific principle:

Oh, wow. Yeah. So we don't lose too

scientific principle:

many customers. So we lost a customer

scientific principle:

4 years ago, and I

scientific principle:

was like, how did we lose them?

scientific principle:

And studying it and looking at each

scientific principle:

layer of where we failed in

scientific principle:

listening to them, in what their needs were,

scientific principle:

We were on autopilot. We were just doing a

scientific principle:

good day, average work on a good day, except

scientific principle:

the client was shifting and we completely

scientific principle:

missed the importance of the shift to the

scientific principle:

organization. Interesting. And

scientific principle:

that not feeling heard

scientific principle:

caused that client to go elsewhere.

scientific principle:

And that caused me

scientific principle:

first soul searching, right? And then you have to say, okay,

scientific principle:

that's the first 24 hours. It's the gut punch.

scientific principle:

And then it's how can you use this to improve? How

scientific principle:

can you use this to build a better product to

scientific principle:

keep going forward? And then you keep marching because the

scientific principle:

only thing you can change is your actions today. Right. You can't go in the

scientific principle:

past, and complaining about the past does absolutely

scientific principle:

nothing. There's no value because the present is the only

scientific principle:

place that you can be. So how do we be more

scientific principle:

present for our customers so that we can keep moving forward?

scientific principle:

What was your mitigation strategy? Do you just kind of touch base with more

scientific principle:

of your customers? Mitigation strategy? I, I hired new people

scientific principle:

to do things. We now have a VCIO that visits all of our

scientific principle:

clients. I divided the responsibilities across multiple

scientific principle:

people. My CTO is now the person who does the

scientific principle:

design. Every time we get

scientific principle:

especially larger accounts, he's the one who does the deep dive and

scientific principle:

does the initial design, and that's all he does.

scientific principle:

His designs are solid. Now there's a team of people

scientific principle:

at each layer, then the directors of the groups

scientific principle:

do the execution of the design. And if they run into a

scientific principle:

problem, they have one, one person, because what I didn't

scientific principle:

want to lose was the accountability. So it's— the

scientific principle:

goal is how do you divide up the work so that you don't lose the

scientific principle:

accountability? Because we had an account once, they had to get us

scientific principle:

into a firewall. There was 25 people on the call.

scientific principle:

Wow. What does that tell me? There's no accountability. And it

scientific principle:

tells, it tells me through one action how to get on the

scientific principle:

firewall. I, my, my director, one of the

scientific principle:

directors sent me the picture of the Teams meeting and there was literally 25,

scientific principle:

and he's, and he said, what do I do with this? And I said, first

scientific principle:

you have to cooperate with everybody and get logged in. But this

scientific principle:

is telling us this is the problem that this customer has.

scientific principle:

Every decision It's 25 people.

scientific principle:

Then if it's 25 people, there's no one throat to choke. I first

scientific principle:

heard— I, um, I first heard that term when

scientific principle:

I worked for a company and, uh, the customer was, um,

scientific principle:

the Marine Corps, actually. Yeah. And, um, I

scientific principle:

forget his rank or whatever, but fairly highly placed guy. And

scientific principle:

he goes— he was telling like, I want one throat to choke.

scientific principle:

My first thought was, well, that's his industry, so to speak.

scientific principle:

But that's a great, that's a great phrase, and I'm glad it's kind of caught

scientific principle:

on, right? Yeah, yeah. And it's, in a nutshell, very,

scientific principle:

very clear as to what is going on. And so

scientific principle:

here's how you, you massage that, because you can overwhelm that one

scientific principle:

throat, right? Yeah, absolutely. If you break the tasks

scientific principle:

up and each one has a throat,

scientific principle:

You can build a chain structure that all can move

scientific principle:

simultaneously. And that's the— that's, to me, that's

scientific principle:

the music. When you get there and you can watch an organization

scientific principle:

start to pivot and actually move in a direction, that's awesome. That

scientific principle:

feels good. That's cool.

scientific principle:

How do you balance

scientific principle:

autonomous operation of these teams, like where they can operate independently,

scientific principle:

with accountability? Is it breaking it down into small tasks, or is there a more

scientific principle:

nuanced It's that

scientific principle:

plus oversight.

scientific principle:

Oversight and accountability go hand in hand.

scientific principle:

We hold a— I

scientific principle:

coined the phrase, see the field. I'm the

scientific principle:

one— my CTO runs it.

scientific principle:

Everybody in our tier 4 in our organization is the top.

scientific principle:

level of engineers. We all get in a conference room

scientific principle:

twice a week, 11 o'clock Mondays and 11 o'clock Thursdays,

scientific principle:

and I'm a fly on the wall

scientific principle:

and I'm listening. Are we following process?

scientific principle:

Are we getting into— So I, I've got one client that we

scientific principle:

have worked for 3 months, 2 and a half months, to

scientific principle:

get the generator repaired by the electrician,

scientific principle:

and this data center is exposed because

scientific principle:

they're weak on power without this generator.

scientific principle:

And we've— the Tier 4 engineer who's been assigned

scientific principle:

has done that. And I said, stop. I said, I don't want to— and

scientific principle:

I literally stopped the meeting. I said, I don't want a Tier 4 engineer

scientific principle:

worrying about an electrician. That The customer

scientific principle:

needs to own the problem. It's their electrician, it's their

scientific principle:

generator. Get the

scientific principle:

customer, the main customer contact, and tell them

scientific principle:

this project is stuck until you clear that.

scientific principle:

So that's the one throat to choke, right? Is it's now, it's now in the

scientific principle:

customer's— and what you're doing, that action is empowering. So here,

scientific principle:

so oversight. Here's what I did in that one action. I

scientific principle:

empowered the client to help in their

scientific principle:

process. I empowered my Tier 4 engineer

scientific principle:

to ask for help and to understand where

scientific principle:

we— what is the limit of our service

scientific principle:

and how we can't do everything all the time. We have to

scientific principle:

keep our eye on the ball, which is solve this problem.

scientific principle:

And I'm doing it in a

scientific principle:

large meeting, so everybody is learning from it

scientific principle:

because I'm talking about something they have direct

scientific principle:

process. They're doing the actual work at that moment. So

scientific principle:

if you're doing work at that moment, that is the most

scientific principle:

influential time to make a change. If I sit here and I

scientific principle:

said, here's the 10 principles, follow these 10 principles,

scientific principle:

you'll Somebody will say, oh, those are great principles. I don't know how to apply

scientific principle:

them, so I'll forget them in 5 minutes. But if I say

scientific principle:

something right at that moment, do it this way,

scientific principle:

give this, give this issue to the client.

scientific principle:

Right. Now the engineer is saying, oh, I thought we'd take care of our clients.

scientific principle:

We are taking care of our clients by empowering them

scientific principle:

to help themselves and to help us. help them.

scientific principle:

And then it's like, ah, okay, I get it. So we do that

scientific principle:

twice a week. It's a 30-minute meeting and it's all high

scientific principle:

level. What are the obstacles you're facing? Where are you? And

scientific principle:

then I'll, I'll call audibles and I'll say, what about this? And

scientific principle:

it's— my CTO runs it. I do color commentary.

scientific principle:

And because I want him to own the problem and

scientific principle:

That's the model. So I model for my staff how I

scientific principle:

want them to manage their people. And we have an

scientific principle:

overseas division too. Our tier 1 and 2 is

scientific principle:

overseas, and people don't leave that company

scientific principle:

either. Generally, people don't leave Harbor.

scientific principle:

They stay. I have people for 13, 15 years. Oh, wow.

scientific principle:

And it's not money. Money is important,

scientific principle:

It's culture. Culture is critical in an organization. And

scientific principle:

it's the best thing about what I do and working in technology

scientific principle:

is the people. I get a chance to grow people, right? So I

scientific principle:

had the manager, we have one accountable manager overseas.

scientific principle:

And I said to him, how come there's jobs everywhere? How come people

scientific principle:

stay here? He said, because it's the way you—

scientific principle:

this organization operates. And I said, well, give me an example. He said,

scientific principle:

when you want to talk to somebody, you never say— you never just

scientific principle:

call them and say, hey,

scientific principle:

do this. You always say, do you have a moment?

scientific principle:

He said that little thing means

scientific principle:

Respect their time. That's right. And so when the

scientific principle:

CEO is doing that, then

scientific principle:

the chiefs are doing it, and then the directors are doing it.

scientific principle:

And it's what he's telling me, what he's telegraphing to me, is it

scientific principle:

percolated all the way down to him, which

scientific principle:

says what I'm really care— what I'm really doing is making

scientific principle:

sure, does everybody Are we following our

scientific principle:

corporate values? Is everybody on board?

scientific principle:

The other thing, to digress, the other thing those meetings do

scientific principle:

is educate, because what we miss

scientific principle:

in the world we have is, again, the information silos are

scientific principle:

vertical. Right. So I'm not worried, I'm not worried, will my guys

scientific principle:

get the vertical education? I worry about the horizontal education.

scientific principle:

That's the opportunities for, for me to, to dive

scientific principle:

into the horizontal education and talk about

scientific principle:

people skills and how to deal with certain people and how to

scientific principle:

overcome obstacles. And, um,

scientific principle:

that's what I love my job. I mean, I love it. You can tell, you

scientific principle:

can tell you have a passion for this. And, you know, yeah, if you're doing

scientific principle:

something for decades, like in tech, like

scientific principle:

You have to love it, right? Oh, you have to. Yeah, yeah. No, I tell

scientific principle:

people, if you don't— I— people, oh, I really need a

scientific principle:

job. No, you need a passion. I— because the first

scientific principle:

4 clients that I got were all barter clients. Why? Because I

scientific principle:

needed somebody to teach me, right? When it was just

scientific principle:

me, I needed somebody to help teach me how

scientific principle:

to do my job. I knew how to solve the tech problems.

scientific principle:

That wasn't my job. My job was to solve their problems.

scientific principle:

And so those first 4 clients,

scientific principle:

3 of which— 2 of which I still have today.

scientific principle:

Wow. Yeah. 30 years later.

scientific principle:

Wow. So clearly you're a successful entrepreneur. Yeah, no,

scientific principle:

I'm— yeah, no, I, I have 70

scientific principle:

employees. Wow. Yeah. You know, I—

scientific principle:

my CTO, my director, director of technology,

scientific principle:

my COO, and I go to India once a year. Why?

scientific principle:

We don't— does anybody ever go? We all outsource, right?

scientific principle:

Very few people do. Yeah, I go.

scientific principle:

Why? Because, A, those are my people. I opened an Indian

scientific principle:

subsidiary. I didn't farm out to some third

scientific principle:

party where I have absolutely no control or input.

scientific principle:

I created an organization there that matches the culture

scientific principle:

of the organization here. And by

scientific principle:

doing that, I can extend the quality and take

scientific principle:

care— take better care of my clients. Right. Interesting.

scientific principle:

So you mean you, you have instilled that culture at every

scientific principle:

level? It sounds— I have to. Yeah, I have to.

scientific principle:

Have to. And you have to let

scientific principle:

people fail because, like I said, you only learn from your

scientific principle:

failures. And then I got to pick them up.

scientific principle:

And when they fail, okay, what did you— what—

scientific principle:

again, when I lost a customer, I failed. I failed.

scientific principle:

My company failed. Okay, deal with the gut punch.

scientific principle:

Be paralyzed for 24 hours. Now come back.

scientific principle:

What do we need to do? How do we fix this?

scientific principle:

So as someone who's been in the technology game for as long as you

scientific principle:

have, and you've seen all these changes, what still separates

scientific principle:

organizations that build durable systems

scientific principle:

from those that just spend their time with punching tickets and like putting

scientific principle:

fires out? Their

scientific principle:

value prop internally, their value— Culture, kind of?

scientific principle:

Yeah, their culture, their core values. Do they

scientific principle:

promote and people would promote and

scientific principle:

enhance people with passion, or do they demote

scientific principle:

people with passion? They scare people. And

scientific principle:

passion can be two— it's a curse and it's a blessing.

scientific principle:

Just like AI. It's like a lot of things, right?

scientific principle:

Just like a lot of things. Food. I mean, I used to be 300

scientific principle:

pounds, right? You know, I loved— I used to eat a pizza all

scientific principle:

by myself. It was killing me. And if I wanted to be here longer, I

scientific principle:

had to make changes. So I had to, you know,

scientific principle:

why did I eat like that? I had to deal with that.

scientific principle:

Now it's a lot easier. I mean, GLP-1s are amazing. And yeah,

scientific principle:

you know, they, uh, but I, I was doing the,

scientific principle:

the precursors, growth hormones, before that because I got the

scientific principle:

DNA of an obese person. And if I, if I

scientific principle:

don't— so

scientific principle:

I don't remember the tangent I was on, but— What

scientific principle:

separates companies that actually build durable systems and,

scientific principle:

and versus ones that just They're always putting fires

scientific principle:

out. Putting fires out tells me

scientific principle:

right off the top that they've not tested enough. Right.

scientific principle:

And they haven't thought about failure, which means they're

scientific principle:

immature, which means they're not really

scientific principle:

paying homage to wanting to be

scientific principle:

okay. Okay, that's one way to be.

scientific principle:

It's not the way to be successful in my book, and it's

scientific principle:

not the way to be long-term successful. Right. So

scientific principle:

any process, you don't say,

scientific principle:

oh, this is perfect. You say, well, what if that breaks? What if that

scientific principle:

breaks? What if that breaks? What do we do?

scientific principle:

And you can get to the laws of diminishing

scientific principle:

return where if you've got so many things, you're like, okay, this is good.

scientific principle:

Now we can put it in production and it will teach us

scientific principle:

what we need to know. Right. I mean,

scientific principle:

I, uh, we had a, a unit from a hardware

scientific principle:

vendor, big storage unit. It was

scientific principle:

up for— we— my client

scientific principle:

bought it in March. It's still not in production.

scientific principle:

They deployed it. It was a storage cluster.

scientific principle:

And I don't want to say the vendor because I don't— I'm not interested in

scientific principle:

badmouthing people.

scientific principle:

But we were on— my guys were

scientific principle:

on umpteen phone calls and meetings

scientific principle:

to get this damn thing built. And they came out with their

scientific principle:

engineers and they set it up.

scientific principle:

I'm at the point of, could we just buy 4

scientific principle:

pieces of equipment and put drives and build our own cluster? Because

scientific principle:

this is never going to work. No, let's get— we have to work with the

scientific principle:

vendor. Okay.

scientific principle:

They built it. They said it's stable and it's good. You can use it. We

scientific principle:

used it. We then said internally, we

scientific principle:

don't use anything until we run it for 7 days and bang the crap

scientific principle:

out of it. Whatever it is, sure enough, day

scientific principle:

two, it crashes.

scientific principle:

Okay. Now, if we would have taken the

scientific principle:

vendor's word for it, and we could have, right? We've been told from the

scientific principle:

vendor this is going to be good. It's still it will

scientific principle:

fully work, and we've tested it, and

scientific principle:

it's it's a company that everybody knows. This is not I'm not

scientific principle:

talking about some. Overseas

scientific principle:

fly-by-night organization. I'm talking about top-line

scientific principle:

enterprise hardware. This is like a legit enterprise

scientific principle:

company, not somebody selling it from the back of a U-Haul truck, right? Yeah, no,

scientific principle:

no, no, no, no, no, no, this is with teams and

scientific principle:

teams of people, okay? Right, right, right.

scientific principle:

I could have, as the vendor, right? It's a vendor in my client's

scientific principle:

environment. We asked for storage, they ordered the storage.

scientific principle:

Their vendor is telling us it's all good.

scientific principle:

I— there's absolutely no reason that I shouldn't be using it,

scientific principle:

except I know history.

scientific principle:

So we have a process, we

scientific principle:

test, and we don't test a little bit, we

scientific principle:

throw a whole script at it. We're gonna

scientific principle:

knock this thing on its, on its ass and see how it performs.

scientific principle:

Why? Because when we put 300 VMs on there,

scientific principle:

guess what's going to happen? It's going to be on its ass. So we'd like

scientific principle:

to know what's going to happen now rather than later. Well,

scientific principle:

it's better to know before it hits the storm. You know, this

scientific principle:

reminds me of a story, and this is one of the worst

scientific principle:

scars I have. I was

scientific principle:

working at a moderate-sized consulting company, and

scientific principle:

when I moved to Richmond. And one of the projects they had, they

scientific principle:

did this joint project with a

scientific principle:

local university. And we had

scientific principle:

purchased software from—

scientific principle:

it was a guy who was an entrepreneur who had built a beverage company. Right.

scientific principle:

And he built like a survey software to kind of go with it,

scientific principle:

like to basically do his own customer thing. And then he spun that off. I

scientific principle:

think he sold the beverage company and then spun that off to its own thing.

scientific principle:

And, you know, we grilled them with questions and the

scientific principle:

budget was so tight that they decided to cut the testing cycle.

scientific principle:

Right. And we took the vendor's word for it of how

scientific principle:

it can scale. Yeah. Yeah.

scientific principle:

Yeah. Now, as I described that,

scientific principle:

you can see, you know, the iceberg sailing straight into the

scientific principle:

Titanic. Oh yeah. Yeah. But when we— when it— I mean, we

scientific principle:

bought new servers, but— and when the servers keeled over on the

scientific principle:

first day, right, what the hell's going on?

scientific principle:

Anyway, we did some like initial kind of triaging and we found out that

scientific principle:

like it would basically—

scientific principle:

it would basically not run any kind of database

scientific principle:

queries. It would basically pull back everything and then the data was

scientific principle:

sorted from in code as

scientific principle:

opposed to having the database do it, which right there, there's a massive

scientific principle:

bottleneck, right? Got it. I mean, so—

scientific principle:

The indexing was code-based and there wasn't a true index. There was

scientific principle:

no true index. So we're picking this apart and we're like, oh my

scientific principle:

God. And that's when I learned if you can't afford to test

scientific principle:

it, you can't afford to do it, right? Testing is not

scientific principle:

optional. And Andy Leonard has a, um, has a

scientific principle:

phrase, my co-host on the show who's normally here. He goes, all software is

scientific principle:

tested, uh, but sometimes the first time it's

scientific principle:

tested is in production. You know,

scientific principle:

and, and then those never ends well.

scientific principle:

And that's the type of like judgment call. Yeah. Anytime, like ever since then,

scientific principle:this was like:scientific principle:

cringe when I think about the, the consequences of that.

scientific principle:

So now, now cycle back to your question

scientific principle:

about AI. Yeah. Somebody vibe codes and

scientific principle:

says, oh, I want to scale this. Guess what they're going

scientific principle:

to do? The same hairs in the back of my neck. I get flashbacks.

scientific principle:

No, you're right. Like, they don't know. And, and, you know, it's very easy to

scientific principle:

say, look, we'll just throw more cloud resources at it. Yeah, you can

scientific principle:

do it. And I, I thank God that, like, that

scientific principle:

happened pre-cloud because it just keeled over

scientific principle:

like these 4 new, like brand new top-of-the-line servers.

scientific principle:

If you had that in the cloud, the bill would have been astronomical because the

scientific principle:

cloud just would have thrown more stuff at it, right? It's kind of like you

scientific principle:

see that video of the guy doing with money. That's music to my ears,

scientific principle:

right? That's my business. There's my business model. There's my business model. I

scientific principle:

can give you DevOps, SaaS

scientific principle:

infrastructure engineering, for 30%

scientific principle:

less than they're charging and actually have eyes

scientific principle:

on it, not just raw anything, so that the next

scientific principle:

time your code goes nuts, we'll stop it as we're seeing

scientific principle:

the problem and hook your engineer in the place and

scientific principle:

say, hey, come on, we need help. This— look what's happening. Right, right, right. And

scientific principle:

that's a better— even if you page out the engineer at 3 in the morning,

scientific principle:

that's a better— That's a better conversation

scientific principle:

Anytime. Than a $2 million bill at the end of the month. Yeah. Yeah.

scientific principle:

Yeah. Well, awesome. I see we're at time. I really

scientific principle:

enjoyed this conversation. We'd love to have you back. Sure. It's been really fun. Where

scientific principle:

can folks find out more about you and what you're up to? Email

scientific principle:

me, richardluna@protectedharbor.com.

scientific principle:

AI isn't waiting for your security to catch up, and neither

scientific principle:

should you. Thanks again to Richard Luna for joining us.

scientific principle:

Subscribe to Data Driven, and we'll see you next time.