RIFF Edition 6: Field Notes 2026
In this RIFF Edition, Navroop and Matt react to Field Notes, ArmorText’s first annual user conference, held at the Classic Car Club in Manhattan under one rule — no vendor pitches, including from the vendor hosting it. From a keynote delivered by someone who has lived the failure mode ArmorText usually has to describe hypothetically, to three customer integrations that collapsed the barrier to entry, to a student project that became the most-requested follow-up of the event, the throughline is consistent: we planned a conference, and the room turned it into a roadmap.
- Field Notes 2026: A User Conference That Banned Vendor Pitches — Including Ours Field Notes 2026 — ArmorText’s first annual user conference, Manhattan Classic Car Club (May 2026)
- Communicare aut Perire: Compromised Comms Are the Overlooked Threat Arc Field Notes 2026 — Jon Schlegel (CSO, CLEAR), keynote
- Pilot Flying J: Start Simple — an Hour’s Work From the Back Seat of a Rental Car Field Notes 2026 — Zach Randall (Pilot Flying J), “soar”
- LS Power: You Don’t Know Your Alerting Is Lost Until You Replace It Field Notes 2026 — JD Barosh (LS Power)
- Hoosier Energy: Stalled by Hand, Shipped in Days With AI — the Lesson Was Validation, Not Magic Field Notes 2026 — Dan LaCour (Hoosier Energy REC) Splunk — UCC framework/generator (the reference documentation that unblocked the build)
- Project Grimace: The Skunkworks Project That Two Customers Told Us to Turn Into a Product Field Notes 2026 — Team Grimace (Gonzaga University senior design project) MITRE ATT&CK — Enterprise technique reference CISA — COUNTER database (countermeasures and eviction strategies)
- Identity Verification: When Your Identity Infrastructure Is the Attack Surface, Verification Has to Happen Outside of It Field Notes 2026 — Navroop Mitter (ArmorText) and Jon Schlegel (CLEAR)
- The Watcher Problem: Running OT Honeypots for Each Other — From Panel to Project Field Notes 2026 — Panel: Brad Stephenson (Southern Company), Tim Chase (Manufacturing-ISAC), Zach Randall (Pilot Flying J), Matthew B. Welling (Holland & Knight); moderated by Navroop Mitter (ArmorText)
- The Secure Gateway Library: The Roadmap Ends by Handing Itself to the Community ArmorText — Secure Gateway Library, announced at Field Notes, live for customers
Navroop Mitter:
[00.00.07.21–00.00.28.15]
Welcome back to the Lock and Key Lounge RIFF Edition, the format where Matt and I react to what’s happening in the world of secure communications and cyber resilience. I’m Navroop Mitter, founder and CEO of ArmorText. Matt’s in his home office outside of DC, and I’m in mine, enjoying Argentina’s most recent win against England in the World Cup semifinals. That’s right.
Navroop:
[00.00.28.21–00.00.45.23]
Today we’re gonna be doing something a little bit different. We’re reacting to something we did ourselves. Back in late May, we hosted Field Notes, ArmorText’s first annual user conference at the Manhattan Classic Car Club. Fair warning this episode is about our own event, so we’re holding ourselves to the same ground rule we gave the room that day.
Navroop:
[00.00.46.00–00.00.58.17]
Patterns, not pitches. What our customers built? What surprised us? And because this event refused to stay in May what it set in motion, that’s what we’re going to be focusing on. And with that Matt take it away. Yeah.
Matt Calligan:
[00.00.58.17–00.01.21.21]
So this was our first annual. So I guess you call it our inaugural Field Notes. And you know, the reason I love this idea is because it came actually from client conversations. We were, you know, six months back in October last year, I waNavroop:s talking to a couple guys about just some integrations. They wrote themselves, and we were doing a quick little webinar about it.
Matt:
[00.01.21.22–00.01.43.07]
They started sharing best practices and tips, how to help each other out with coding and things like that. And I asked them if it would be helpful to create a little community for them to share this, these ideas and kind of what they were working on. They loved it. And then you talked to some clients and they thought it would be better in as a, you know, an actual event as opposed to an online kind of community.
Matt:
[00.01.43.07–00.02.13.02]
So we created this invite only strictly client content only. So there was no vendor pitching. There was no standard conference booths or anything like that. Even the vendor us hosting it. So for everyone who wasn’t in the room there, what were we trying to build? And I mean, it was a live room. Did they cooperate?
Navroop:
[00.02.13.04–00.02.42.11]
Yeah. I mean, look like you mentioned, right? This was born out of our customers telling us they wanted a form in which they could exchange best practices in which they could help each other and tell each other about the different integrations they were building. And so not only did they cooperate at the end of it, everyone actually contributed the code they had built directly into a library that we’re going to be able to give away to our other customers, so that when they’re building integrations on top of ArmorText, they benefit from what’s already been built by everyone else.
Navroop:
[00.02.42.11–00.03.08.19]
and we’ll be talking a little bit more about that later. But, you know, to me, what was really special about all this then was this was ground truth from teams who stayed operational directly from one to the other, or rather to everyone else in the room. Right. There was no pitching. It was really candid. Customers took to the stage and they were sharing stories about, you know, the fact that internal messaging can’t be considered secure in an active incident.
Navroop:
[00.03.08.20–00.03.40.10]
This is the kind of thing that would sound like FUD if it came from us, but from them it was their ground. Truth and reality. Having lived through multiple incidents where ArmorText was a key part of what kept them going. Right. And the turnout is also what surprised me, right? Not only was it the folks in the room cooperating, but we were able to use the cinema room at the Classic Car Club and then broadcast to a last second set of online attendees across North America and even in Europe.
Navroop:
[00.03.40.11–00.04.03.13]
You know, it’s something we only decided to light up the day before. Heck, you know, two days before I was even trying to figure out what the production team at the Classic Car Club, this was even possible. And actually, in the moment of that very morning, you know, it almost didn’t happen, right? It turns out we didn’t have access to the Wi-Fi because the Wi-Fi wasn’t strong enough in the in the control room.
Navroop:
[00.04.03.13–00.04.16.19]
And so we had to send our EA to Best Buy to go pick up an Ethernet. But because she had heard her need, she just wasn’t getting there fast enough. And then one of the young ladies at the car club said, hey, listen, I’m a track star. I can run there. I’ll be right back. Well.
Matt:
[00.04.16.19–00.04.19.14]
She went to the Apple Store. That wasn’t even the Best Buy, right?
Navroop:
[00.04.19.19–00.04.44.06]
She read straight to Apple and picked up exactly what we needed. And that’s what got us moving. Right. So this is resilience for the company’s live stream. It was saved by a hardware store run. It was kind of ironic and fun. It was the one thing we hadn’t planned contingency before. We had everything else saw for minus an Ethernet adapter, because who who the heck still uses Ethernet in 2026?
Navroop:
[00.04.44.08–00.05.16.20]
But you know, with that said, yeah, it was it was great. A lot of cooperation. It was kind of a modified Chatham House Rule, but that was a feature not really constrained, right? People spoke freely in the room. We then worked with the presenters to get special permission to air parts of their commentary, with the rule being that any of the Q&A in the room, neither the questions asked nor the answers delivered to those questions would ever be a part of what was shared, but that key portions of the presentation cells would become shareable, right?
Navroop:
[00.05.16.21–00.05.22.06]
And so we model the information sharing discipline that the product also helps serve.
Matt:
[00.05.22.07–00.05.45.17]
Right. Right. And that kind of took on the impromptu emcee there. One of the things that it was a great problem to have, but I was I was getting a little annoyed that I couldn’t yell louder. But when we would take quick breaks between the events, the energy like people would spill out into that little, you know, ante room there I would be yelling over, you know, trying to scream over all the conversations to get people to go back in.
Matt:
[00.05.45.19–00.06.18.20]
So we had a fantastic sort of, you know, co-mingling of all these different sectors and different roles inside of cyber. And we had, you know, electricity and oil and gas, we had some private equity. Gosh. I mean, there was some law firms, there was even some regulators and some ISAC folks. So it was just from my perspective, it was really cool to watch each of, you know, each of these participants kind of compare notes with each other, even asking questions outside of, you know, the standard presentation format.
Matt:
[00.06.18.21–00.06.47.15]
And, well, the day opened with someone actually who’s lived the failure mode. We I honestly have described hypothetically, for most scenarios that I know of, this would move us to the, I guess, our second topic, which is our, you know, our flagship Latin, which is Communicare aut perire — how did you say it, Communicare aut perire? Is that— am I getting that right?
Navroop:
[00.06.47.18–00.07.04.20]
You know, I am definitely not the Latin expert here. I actually went to google.com and typed it in and sit here, say this out loud for me. So I think it was Communicare aut perire, but I’m not sure. And so for any of you listening, if you went to Catholic school and took classes in Latin, help Matt and I out.
Matt:
[00.07.04.21–00.07.05.23]
And blame us hard.
Navroop:
[00.07.06.00–00.07.31.16]
Yeah, blame us hard. But also teach us how to pronounce our own new catchphrase that we used for Jon’s keynote. And with that, you know, Jon Schlegel, you know, he’s now the CISO— sorry, the CSO of CLEAR. He’s a former Navy cryptologist, has been a CISO previously, but is now the CSO of CLEAR. He opened the day with a with a keynote that was actually titled Communicare aut perire, right.
Navroop:
[00.07.31.21–00.07.49.17]
Which is communicate or perish in English. For those of you who don’t speak Latin like I don’t, you had Matt, who was obviously the emcee, and Matt, I know you had a lot of observations coming out of the keynote in that room. I saw you just like lighting up and looking up and just glowing every time Jon would say things.
Navroop:
[00.07.49.17–00.07.54.15]
I took my notes. That right. All the reactions in your face. And so I actually am going to turn this one over to you first.
Matt:
[00.07.54.16–00.08.21.13]
Well, it’s it, you know, like you said, or maybe it was one of us has said this so far, but it’s we talk about a lot of hypotheticals on our side of the House. It’s well, this could happen. Or we have seen this happen. Listening to Jon spell this out, the connection that really clicked for me for the first time ever is, is how the ironically, the private sector is finally catching up to how military has, you know, truths that military is known forever.
Matt:
[00.08.21.13–00.08.51.14]
And that’s what makes that’s why, you know, really successful cyber practitioners have this military background. They know what it’s like to operate in, you know, in, in this contested environment where you have an adversary actively trying to sabotage you. Right? I mean, he framed this up around the compromise communications channels that are most overlooked. And it was kind of this theme that pulled through it, you know, pulled through the whole presentation.
Matt:
[00.08.51.16–00.09.25.12]
You know, it. It’s the thing that really turns a bad day into into one that’s often unrecoverable. One of the really key points he made was with these sort of AI accelerated attacks out of band operational resilience. It’s no longer a future problem. It’s not something that you can kick the can on its right now. And that keynote really planted what that identity verification session later on, you know, sort of expanded on in the afternoon when when he unpacked that.
Navroop:
[00.09.25.14–00.09.51.18]
Yeah. It’s kind of interesting, right? It was surreal hearing our own arguments handed back to us, but from someone else’s scars. Right? I mean, look, I’ve certainly got my own war stories, having been around when communications were breached and you knew an adversary was listening in to your response and remediation, your eviction efforts. But Jon’s war stories are from a reality where the stakes were just about as high as I can frankly get.
Navroop:
[00.09.51.19–00.10.29.10]
Right? It’s actually military and national security impact. There’s an intelligence component to this. But like some of our customers that day, Jon surprised us with evidence you’d never really see in the headlines. Right? There were stories that were being shared that were off the record, but there was concrete proof that secure out-of-band collaboration, both has been needed in DoD and intelligence areas where they could rely on having the unclassified or classified networks that JWICS where they would move, they really had to go beyond the networks that they knew were being listened to by an adversary.
Navroop:
[00.10.29.10–00.10.46.11]
And potentially you never know, even maybe, that have been compromised as well. Right? You know, he talked about that, but then also why he was so surprised or what he was surprised by in the fact that the private sector was still playing catch up on this. Right. This is something we had seen in the private sector for years.
Navroop:
[00.10.46.12–00.11.07.03]
It wasn’t necessarily just hypothetical, but there were only so many public stories that we were allowed to share from our experiences. Yet Jon was able to share something that was just so invaluable, something that happened many years ago. So it’s not a security issue today, but it you know, these were he was able to allude to real scenarios, not just possibilities.
Navroop:
[00.11.07.05–00.11.10.23]
These were his actual memories from those moments. Right.
Matt:
[00.11.11.00–00.11.40.08]
Well, we took that from really the highest stakes imaginable, you know, in military lives are on the line really to very relatable ones, which was kind of interesting. So we went from, you know, these, these massive military sized operational lessons to small teams just trying to get their, their weekends back. So following Jon, we actually had three separate presentations, three teams from three completely different starting points and three different clients.
Matt:
[00.11.40.08–00.12.03.16]
We had Pilot Flying J, the travel center, we had Hoosier, the power grid operator, and then we had LS Power — or I’m sorry, LS Power was the power grid operator, Hoosier. That was the G&T on the cooperative side. But they despite all of their various unrelated starting points, they really had this shared discovery. And that was the barrier to entry collapsing.
Navroop:
[00.12.03.18–00.12.32.18]
Yeah. I mean look this was really amazing, right? To hear all these stories in the room, the integrations really added value. And I think this was best captured in actually Zach’s talk. Right. So Zach is talking about the, you know, this telemetry, these these alerts that are coming off the store and that he’s feeding into ArmorText. And, you know, the summary of his talk is really what really just I think summarizes everything, right.
Navroop:
[00.12.32.19–00.12.53.15]
It was quality of life improved in under an hour. And, you know, that was just such an amazing thing. Right? His talk was about starting simple, but the real story wasn’t the architecture, right? It was. Well, I mean, it was everything else, right? It’s how they were able to do so little to gain such tremendous value and what they’ve been doing with it since.
Matt:
[00.12.53.16–00.13.24.06]
Yeah. Well, he, he had I mean, it was they didn’t even have 24 over seven coverage. It was it was rotating on call analysts taking taking coverage because the SOC wasn’t even, you know, covering those weekend hours. And so I mean, for, for those folks like himself who are handling those alerts, it was a quality of life issue as far as having to monitor this thing all the time because of the volume of alerts and having to screen through it and everything like that, or it like, I love how he said this.
Matt:
[00.13.24.07–00.13.41.19]
It was in an hour, right? They were he was in the back seat of a taxi or a rental car, and his CSO turned to his boss. Zach’s boss was like, hey, where are we on this thing that we just bought? And his boss looked at Zach and said, well, yeah, Zach, where are we? So Zach literally built this thing and integrated it in an hour.
Matt:
[00.13.41.21–00.14.05.04]
And that’s the actual barrier to entry story, right? For the wider sort of application, being able to move the alerts out of email for him didn’t just reduce noise, right? It was using email infrastructure for the alerting not only buries the lead, so to speak, just from a you know, we all look at our inboxes, we know what those look like.
Navroop:
[00.14.05.04–00.14.08.21]
But what was he talking about? 4 or 5, 9000 unread emails.
Matt:
[00.14.08.23–00.14.10.23]
Hundreds and hundreds. Yeah.
Navroop:
[00.14.11.01–00.14.16.08]
My hundreds of thousands of my phone at the same time. I would never see that alert in all those I get in a day.
Matt:
[00.14.16.09–00.14.33.16]
And you get all the spam on top of it. So you’re trying to monitor all this, and on top of that, it’s also where, you know, the adversaries are most likely to try to find where these alerts are being going, you know, being delivered anyways. And so you’re risking actually tipping your hand mid incident. And you know, he said this himself.
Matt:
[00.14.33.21–00.14.51.12]
They shouldn’t get to read your playbook. You know while you’re executing it. my it really hit me because I’ve never been in his seat right. I’ve never been an analyst trying to watch these alerts and manage them and have that responsibility. But his comment about, you know, his what was it his almost like he put that at the top of the slide.
Matt:
[00.14.51.12–00.15.17.20]
Ruined date night with the sound of an ArmorText alert. Right? He was tongue in cheek, but that was, you know, that in a good and bad way. That’s the that’s the benefits, you know, the blessing in disguise. You get that alert and you know, it’s something you’ve got to take care of, even if it’s 7:00 on a Saturday, which, I mean, that was that was just, you know, his transparency and honesty was kind of refreshing on that one.
Navroop:
[00.15.17.22–00.15.37.19]
Yeah. But it also allowed him to, you know, in talking to it seems like it allowed him to also worry less. Right? So yes, he didn’t go as off, but he knows that’s the one thing he has to pay attention to. It doesn’t constantly be looking at every single possible thing on his phone. Then determine is this now the alert that I have to go run in to help save the day because of.
Navroop:
[00.15.37.20–00.16.06.11]
Right? It’s kind of interesting how common email is still our alerting channel, but when you think about the most high sensitivity, most valuable alerts, especially if they’re going to be context enriched, it, it’s kind of it’s almost the worst possible mechanism in which to deliver those alerts. Right. And so the fact that they were able to do some context enrichment as well, deliver the high value alerting into a channel that the adversary can’t read, but also immediately triage for the analysts.
Navroop:
[00.16.06.11–00.16.27.04]
Exactly what was worth paying attention to was just amazing to see. And the fact that it can be done in an hour really means you can start simple and get. Frankly, any of our customers could actually benefit from this. Start really simple, get on the ramp and then see what people want to see after that. Right? Yeah. This is a very simple, easy starting point that everyone can benefit from.
Navroop:
[00.16.27.04–00.16.43.23]
And actually his code is available for anyone else who wants to look at it as a sample as they write their own integrations. Right. And that’s again, one of the most powerful parts of the day. You know, I think that actually takes me to one of the other talks. And I actually think we’re going out of order here now on talks.
Navroop:
[00.16.43.23–00.17.04.21]
But this is one of the ones that I really enjoyed. It was from JD over at LS Power. Right? JD couldn’t be in the room and it was one of those last second can’t fly out guys. Not sure what we can do. And then suddenly he was like, you know what, I’m committed to making this happen. So he actually prerecorded his video just in case he wouldn’t be able to dial in effectively.
Navroop:
[00.17.04.21–00.17.26.03]
Because like I said, we weren’t sure if we were gonna be able to broadcast around until about 48 hours prior. And then it was only the day before we were released. The link. So he prerecorded his entire presentation, gave that to Matt, probably spoke a little bit faster than he normally would have had he been presenting live. So his video was about about half the total length that I had expected, but it got through everything.
Navroop:
[00.17.26.05–00.17.40.18]
But he was so committed that he actually did dial in live, just in case there was additional Q&A. And not just it speaks volumes to the commitment that our customers had to wanting to share their experiences here. I mean, this was just amazing. I had an expected I had expected the I’m not gonna be able to make it.
Navroop:
[00.17.40.19–00.17.52.05]
Sorry, guys. Right. One more item off the agenda and it was the opposite. We ended up having more in the agenda that was planned. We could have frankly used a little bit of breathing room and instead JD, you know, recorded his entire.
Matt:
[00.17.52.06–00.17.52.11]
Team.
Navroop:
[00.17.52.11–00.18.03.16]
Through presentation and his entire take on things and then dialed in just in case of live Q&A. I mean, it doesn’t get better than that, right? But why don’t you actually tell us a little bit more? What did LS Power actually find?
Matt:
[00.18.03.18–00.18.41.04]
Yeah. I mean, you know, he’s not expecting this, but a big shout out to JD for actually coming through in a pinch on that one. I mean, the, the reality that they were facing as he was kind of walking me through it, I’ve never I’ve never heard him describe it. Soup to nuts like that. I mean he sort of, you know, alluded to a little bit in some of our previous conversations, but it was it was really it was it was very impactful to hear him kind of described it before and after where, you know, they have this sort of alerting solution that it was actually missing messages.
Matt:
[00.18.41.04–00.19.01.11]
Things weren’t coming through. The scariest failure mode there is because you’re not even getting it right. You don’t even know you’re not getting these things coming through. And then after actually routing and these are OT alerts, which was interesting. Like most most people know it for the IT side of the house. This was this was one of our earliest dedicated OT deployments.
Matt:
[00.19.01.11–00.19.30.21]
But these OT alerts were going into their SolarWinds right through through our gateway and able to give them more context and reduce costs by multiples according to what he said. So for the on call responders protecting that grid, their little part of the grid there, they couldn’t miss an alert. Right. that’s not an inconvenience. This is this is part of the actual reliability that, you know, and energy companies are tasked with by regulators and by the people who are paying them.
Navroop:
[00.19.30.22–00.19.50.22]
So that’s the crazy part. They didn’t know the alerting was lost until they replaced it. Right. That’s when they finally realized what they had been missing. So. Thankfully, nothing had gone so wrong before, but had it. And it had been one of the alerts that just hadn’t come through. It would have been a heck of a lot more than just an inconvenience.
Matt:
[00.19.50.23–00.19.53.01]
Right? exactly.
Navroop:
[00.19.53.06–00.20.29.20]
Yeah. I mean, I think this was so interesting, right? Because like Matt said, so often we end up talking to our customers about cyber or IT resilience and outer brand communications or preparedness during incidents. But this was OT resonance, right? It’s you know, why that silent loss and alerting pipelines for grid operators, you know, is so important. We found you know, we found that our customers were suddenly telling us, say, hey, there’s this other use case that you really need to be focused on, because for us, these notifications that much more critical than they are for our IT brethren.
Navroop:
[00.20.29.20–00.20.47.02]
And yet so many of us on the side of the House can’t actually get appropriate alerting. And even the solutions we did have to potentially get them out of the OT environment where that’s hard enough. We’re dropping things, or they couldn’t be context enriched because the channels in which they were going to deliver the alert wasn’t secure enough.
Navroop:
[00.20.47.02–00.21.11.19]
And so we were losing time even when we did get a critical alert. So if it did come through, it wasn’t always. And then we did get it. We didn’t necessarily context right away. We’d have to spend time getting into those things. And again, this is just one of those integrations that I think is actually incredibly valuable to our customers in manufacturing, in, in electricity, in, in oil and gas, potentially even in pharma and healthcare.
Navroop:
[00.21.11.21–00.21.17.04]
I’m not sure our banking customers would necessarily need the OT side of the house, but even they might. For all I know.
Matt:
[00.21.17.08–00.21.18.22]
They got ATMs.
Navroop:
[00.21.19.00–00.21.46.05]
Fair enough. There are ATMs and that is an OT, potentially an OT source of information. Yeah, I didn’t thought about that one, but it was kind of interesting again, to have our customers tell us no. We look at your Tier and Protect model that you guys have. What communications are so sensitive that they deserve this higher security, higher sensitivity channel on which to communicate, to have both the alert or the telemetry dropped off, but then the conversation about it take place.
Navroop:
[00.21.46.06–00.22.09.03]
But oh, by the way, we’ve got our own understanding of that. And here’s something else that also falls above that Tier and Protect line that you guys have drawn. And so we’re going to start there for our integration. And so again it’s amazing to see our customers tell us how and why they need this technology in place. I just I learned so much like you Matt and JD’s JD described this.
Navroop:
[00.22.09.03–00.22.27.08]
I think I was actually overseas taking a meeting, I think possibly in Italy that day when we first got on the phone with JD to talk about doing this presentation and, and I thought I knew what he was going to talk about, and then he actually just put it all end to end. And I realized I actually had no clue as to what he was going to say until he got up there.
Navroop:
[00.22.27.08–00.22.50.00]
And that was just amazing to hear the whole story. So that I think takes us to one of the other presentations. Right. So, you know, Dan LaCour described himself as a Splunk admin, designer and integrator and AI wrangler. You know, I’m just gonna let you tell his story, right? I mean, this is kind of, again, a just an interesting one.
Navroop:
[00.22.50.05–00.23.04.01]
He he did things a bit differently. And because of the way he did it and because of where he started and from what because of what he found. We’re like, you have to come share this story. And he was absolutely thrilled to do so. So why don’t you tell us what he actually did?
Matt:
[00.23.04.02–00.23.36.01]
So he he works at Hoosier, which is a G&T, or generation and transmission, inside of the cooperative subsector. And they wanted a native Splunk add-on so that it was directly pushing alerts, you know, delivering search results, even even rendering PDFs into specific ArmorText conversations for their member cooperatives, because they had to make sure those data streams did not cross because each one was a little different for their members.
Matt:
[00.23.36.03–00.24.05.20]
He was building it by hand, and that actually stalled with the right local reference documentation and some AI. He actually shipped a full-featured integration within days, which really was a I don’t know, it was surprising to see, but I mean, it speaks to his level of skill. I mean, it was he basically kind of vibe coded with Claude, and I think he mentioned Opus, Sonnet, and Haiku just to kind of match, you know, the complexity of what, what was running.
Matt:
[00.24.05.20–00.24.29.03]
But the, you know, the lesson at the end wasn’t really the AI magic thing that everybody talks about. It was, you know, his maintaining that visibility and validation and the discipline to make sure that, you know, what was produced actually came through was, you know, test driven, spec and plan driven, everything like that before anything could ship.
Matt:
[00.24.29.03–00.25.00.06]
And so he really applied the rigor after the fact that you can only, you know, humans can only apply that level of rigor to something like that. So how do you, you know, validate AI code? It’s the question that every team, you know, was thinking in that room and what we’re all living with. And he he walked through that that rigorous process, the discipline you need to take to actually build something that then, you know, was able to, to work directly from Splunk into into our gateway.
Matt:
[00.25.00.08–00.25.02.14]
My, my favorite part was what’s that? Well, I.
Navroop:
[00.25.02.14–00.25.27.02]
Was just saying, but wasn’t the biggest lesson he found was that it was almost what it really came down to was having the right documentation to put into the AI, so it knew exactly what to go build. I mean, it’s not like he had been trying and struggling for a while. Once he had the right documentation set though, both for our gateway as well as for Splunk, I think the UCC generator, I think it was called.
Navroop:
[00.25.27.03–00.25.32.09]
Yeah, that’s what enabled the AI to suddenly develop to spec.
Matt:
[00.25.32.10–00.25.53.15]
Yeah, yeah. Well, I mean, my favorite part was that he he announced that he was actually allowing us to add it to our library, kind of opening open sourcing it, which was super cool to him because a lot of I know a lot of folks in that room and elsewhere are looking for something similar to that. So really happy to, to see that presentation.
Navroop:
[00.25.53.17–00.26.14.13]
Yeah, I mean, this was a lot of fun. You know, it’s kind of interesting. We one of the things that Dan did talk about though, was not being able to just immediately trust the machine or at least questioning it and wanting to, you know, test the outputs that came out and that kind of paired with one of the other projects of the day where this is actually an interesting one.
Navroop:
[00.26.14.13–00.26.37.15]
This is near and dear to my heart. These are a bunch of students who are at Gonzaga University. They actually all just graduated, so it was part of their senior design project. Two of them had worked with me the prior semester, so the last semester of their junior year, they proposed turning this CTI triaging and prioritization alerting system that they were building out into their senior design project.
Navroop:
[00.26.37.15–00.27.01.21]
They found two more of their classmates or colleagues at the university who were also seniors and would be graduating, roped them in and turned it into a really large project, which was kind of interesting, right? This became something that not just our customers could extend, but something that other people were thinking about wrapping an entire product around in some ways.
Navroop:
[00.27.01.22–00.27.04.03]
Right. And that was kind of an interesting one for me.
Matt:
[00.27.04.06–00.27.48.14]
Yeah. The Team Grimace was certainly sort of out of left field. You know, I kind of I called it our skunkworks project. But yeah, I mean, it was, it was it was fun to watch. My takeaway is that watching three Gonzaga, you know, computer science grads, guys who have never probably presented in front of a room, ever standing in front of, you know, CISOs of, you know, Fortune 1000 or Fortune 500 companies and present this sort of automated CTI pipeline to these folks and actually field questions and it really like that was the sleeper, you know, event that somehow became the talk that every follow up conversation came about.
Matt:
[00.27.48.16–00.27.58.09]
I know you were part of some of those conversations. I, you know, be an emcee. I was kind of, you know, just bouncing around the room, but from from the conversations you were hearing. what actually happened there? Yeah.
Navroop:
[00.27.58.09–00.28.26.07]
So it was interesting. We I mean, this was always designed to be just a proof of what could be done and delivered into ArmorText conversations, mapping, you know, specific threat intelligence that would be a value to a particular customer or set of parties, potentially by a single analyst who might be looking at hundreds of different companies but wants to help them all out and build some sort of CTI that’s scoped specifically to them.
Navroop:
[00.28.26.09–00.28.46.14]
It was just intended to be something like a demonstration of capability. The assumption had always been that others would build their own thing. Right. But as the students presented, you know, it was kind of interesting. I had customers immediately asking me, hey, so like, when is this going GA? Or hey, can we get this feature built in which would allow us to use this every single day at such and such?
Navroop:
[00.28.46.14–00.29.03.20]
Isaac or hey, we’re going to have a set of analysts over here who are going to be helping our collection of 20 or 30 or 40 goes, and we want to make sure that the appropriate CTI that’s been triaged is delivered to each one of them. But we want this analyst to set up and maintain that for each of them collectively.
Navroop:
[00.29.03.20–00.29.26.18]
It’s like those are all wonderful ideas, some of which we actually did design for upfront. But what was most interesting to hear was that one of the actually not just one, come to think of that, two, two of the customers that had seen the presentation later remarked to me in fall conversations that we had actually been looking at something that was going to be our CTI feed.
Navroop:
[00.29.26.19–00.29.46.00]
That was where we were to bring in. We were getting ready to procure, and we decided to hold off because when you asked us for feedback, we thought you were headed in the right direction and that potentially because it’s already integrated, it might be of more value. What was most interesting than hear from them was that, hey, we’ll contribute more to the roadmap because we think you should invest further and actually turns into a GA product.
Navroop:
[00.29.46.00–00.30.02.14]
But oh, by the way, if you do decide to GA this, we think this already adds as much value as those other products, if not more. And we’d already suspended procurement just to see what you came up with just in case. So our vote is turn this into a real product. And so you know what they built, right?
Navroop:
[00.30.02.15–00.30.33.17]
Was CTI triaging TTP extraction and then the delivery of actionable playbooks. Right. They would extract the TTPs, look for countermeasures based on CISA’s COUNTER database, pull together an eviction plan from that countermeasure. So our version controlled delivered straight into the channel. So you see end to end. So if you’re saying, hey, wait a minute, I am seeing this or these IOCs are showing up, you’ve already got some countermeasures being delivered to you.
Navroop:
[00.30.33.19–00.30.53.13]
What was really cool, though, was that something that we had introduced in, I guess, that junior year, second semester class project when two of the students were working, was this idea of an SQS — a Summarization Quality Score, basically getting the AI to tell on itself if and when it had hallucinated, or even when it had done a bad job.
Navroop:
[00.30.53.13–00.31.31.10]
That was something that, again, everyone’s been asking about, not necessarily because they want to go build a product, but because where they’re developing AI based, you know, either triaging or summarization or anything else they’re doing, they want to apply that same concept. And it’s and it’s pretty simple, right? it’s basically you have the AI go back and check against the check the summary against certain extracted details, and have to do grep and look up through those details to make sure that what it is now saying as a part of the summary or what was extracted and actually matches things in the source, and if and when it doesn’t, immediately, you know, giving you a score
Navroop:
[00.31.31.11–00.31.51.12]
that indicates that, hey, this particular component of what I’m presenting to you is less reliable or these parts are still reliable, but this is not right. So you might have an overall score of 70%, but it might be that, hey, it’s really the title and the subtitle of the information that’s really problematic, but everything else is trustable.
Navroop:
[00.31.51.12–00.32.17.21]
And then you can make a decision on what to do or actually title is totally trustable subtitles trustable. Heck, even the IOC’s are trust. Well, but everything else that was extracted or summarized is complete bunk. Do not trust us. Take it with a grain of salt. Right? And so just as concepts, when we’re sharing those concepts, I ended up having farm conversations with engineers at multiple other, you know, companies who are looking to develop their own integrations on top of ArmorText.
Navroop:
[00.32.17.23–00.32.38.08]
And they’re looking at using kind of that same weighted Summarization Quality Score to catch hallucinations and possibly even the same kind of Admiralty scoring for source reliability that the students come up with in their own projects. And that helps answers the can I trust a machine? alongside Dan’s tests that he came up with when he was live coding.
Navroop:
[00.32.38.08–00.32.58.11]
So it was just a lot of fun to see my students get so much praise and actually kind of be the surprise hit of the conference, right? Because that wasn’t expected. And now we’ve got a whole new roadmap of things to potentially consider for a product. We’ve already got some preliminary LOIs, which is kind of an interesting thing too.
Navroop:
[00.32.58.12–00.33.14.23]
So I know, Matt, you’re going to be going out there with Mark now to solicit some additional feedback. And sometime over the next 6 to 8 weeks, we’re going to go/no-go decision based on what potential design partners say and what the roadmap ends up looking like.
Matt:
[00.33.15.00–00.33.43.10]
Yeah. Well, I mean, it really says a lot about where the community is versus where the, you know, the solution design is with, you know, the fact that the most requested follow up and most engaged was, you know, from this student project and it, you know, to your point, it really it really opens up an interesting opportunity for people to who want in on, you know, the design of something like this.
Matt:
[00.33.43.11–00.34.05.17]
Right. This is, this is the moment to raise your hand, jump in. But I mean, yeah, that it was it was like we had to we actually had to tell people to stop asking questions. There was so much kind of interest in, you know, what else could be added to it. The other session that really refused to stay inside this time slot was actually the one about the identities, right?
Matt:
[00.34.05.18–00.34.27.14]
The who you’re actually talking to in these kinds of moments. Session five was Jon again, Jon with CLEAR. It was an out of band identity verification really was what he was talking about more in depth. And you were on the stage for this one with Jon Schlegel. And actually, it was the title of your closing slide, really that said it all.
Matt:
[00.34.27.14–00.34.38.09]
It’s like when your identity infrastructure is the attack surface, you know, the verification, the identity has to happen outside of that. So take me through that piece a little bit.
Navroop:
[00.34.38.11–00.35.03.13]
Yeah. I mean, in a lot of ways your IdP is only as trustworthy as your adversary allows it to be. For those of you who saw a previous tabletop guides that we had introduced, there’s a kind of a scenario to inject in one of them that talks about the weaponization of the IdP or the SSL systems, right? They can be compromised, they can be brought down, they can simply be suffering from outage, or they can be actively weaponized.
Navroop:
[00.35.03.13–00.35.26.01]
And by weaponized, I mean, you know, they can easily be used to grant your adversary or to deliver to them additional access to get a hold of all the communications that have taken place, as well as a whole bunch of other stuff you’re doing about remediation and response efforts and eviction. Or they can be used to suddenly deny you access to all the tools and communications protocols you need to coordinate your response.
Navroop:
[00.35.26.01–00.35.48.00]
So if everything you rely upon is tied to your IdP, then you’re potentially SOL, right. And so this is something we’ve been talking about for a while. It’s why we keep saying that the rules of zero trust actually do invert during a crisis. It’s why out of end coms and ArmorTexts are not tied to your IdP and so well.
Navroop:
[00.35.48.01–00.36.17.07]
With that said, there’s an interesting deepfake arms race that’s taking place, right? It’s the uncomfortable part of the slide that one of the sides were presenting was actually this detection column. Right. It’s the here are the fraudsters favorites among the consumer grade tooling that anyone has access to today that allows you to produce video and voice capabilities that the deepfake detectors, frankly, aren’t necessarily able to really detect.
Navroop:
[00.36.17.08–00.36.44.16]
Right. One of the things we quoted was a study that was, I believe, performed by the Australian intelligence and SKU out of South Korea. It’s one of the universities out there. They realized that of the major deepfake detectors, zero of 16 could reliably identify deepfake in the wild. Wow. There’s that article in nature as well, right? About how often humans could reliably detect a, you know, a deepfake voice.
Navroop:
[00.36.44.16–00.36.52.10]
And it was maybe 60%. And that was a couple of years ago when that analysis was done. And so here in 2026, it’s probably gotten a lot better.
Matt:
[00.36.52.10–00.36.53.22]
Even worse or better, however.
Navroop:
[00.36.53.23–00.37.10.12]
Yeah, right. Worth or better, depending how you look at it. But one of the other points we were looking at was, and that was when people were asked to do this when they weren’t under duress. So if you think about the stress of an incident or you know what your entire team is going to be experiencing, you know, I know Matt really well.
Navroop:
[00.37.10.13–00.37.32.00]
Matt and I are on the phone every day. I can’t think of a single day in the last, I don’t know, 6 or 7 years now where Matt and I haven’t spoken at least once, right, say for maybe the occasional weekend. And even then I think we speak sometimes, under duress. What I reliably be able to know for certain that this was Matt and actually Matt Calligan, and not a deepfake of Matt Calligan.
Navroop:
[00.37.32.02–00.37.52.19]
I don’t know, I’ve got some doubts, and I have that doubt only because I’ve seen the data and I know what it looks like. I’d like to think I could catch everything, but I actually think we need better than that, right? And so one of the things that we have talked about for some time, that one of our customers actually drove us to, again, this is customer driven, right?
Navroop:
[00.37.52.23–00.38.21.05]
One of our telecom customers brought CLEAR and us together and said, hey, we’ve got this out-of-band communications technology that we have used now through what, six, seven, eight, nine nation state attacks. It has allowed us to communicate securely throughout. We’ve got this identity verification technology that we initially used for workforce enablement, things like password resets, but actually, frankly, initially identity binding when they were rolling out there so they could go passwordless.
Navroop:
[00.38.21.07–00.38.43.22]
And as a result of that, you know, we think there’s something here. We want this identity verification to somehow be something that can be used both day to day as part of onboarding for the accounts we know need to be an architect, but also then in a crisis to again be used to do verification potentially, of folks who are already onboarded, but especially of any new parties that are coming to the table.
Navroop:
[00.38.43.23–00.39.08.13]
Right. If our incident response retainer firm or the digital forensics team or the insurance carrier or legal or law enforcement or whoever is saying, hey, here’s a list of the five, six, seven, nine people are sending to you, how do you actually know that the person showing up and registering for your out of band comes to suddenly help with your remediation and eviction efforts is indeed the person who was supposed to be showing up to that manifest, right?
Navroop:
[00.39.08.14–00.39.28.15]
How do you know that they are identified to be a real person, the person that you want in the room and not the adversary themselves, right. And so with this kind of technology, Jon shared something about the hundreds of different telemetry data points that they can collect around that identity verification, not just the fact that you can identify the person.
Navroop:
[00.39.28.16–00.39.49.23]
Right? It’s not just a pass fail, but with this additional telemetry that they can actually deliver straight into one of three different channels in ArmorText for you. Is it, you know, pass without any notes. Is it a pass with some sort of flag saying, hey, pass. But here’s an oddity, or is it a failure? And then you can figure out how to determine what to do next about each of those categories.
Navroop:
[00.39.49.23–00.40.09.18]
But that pass with flags category is kind of an interesting one, right? Most people think of it passed. That’s good enough. But the example that Jon and I were talking about was, well, let’s say Matt has completely passed his identity verification, but the telemetry data shows that how he passed is actually of interest here. He’s passed, but it’s from a Huawei device.
Navroop:
[00.40.09.18–00.40.37.06]
It’s what Matt is a US citizen living in the United States working for us, supposedly on Sunday morning at home, in his home office, in his home in Northern Virginia, right outside of DC. Why is there a moon in the selfie that he just took? Why did he pass from a Huawei device which were not allowed to have here or be getting from and why does why do all of these details not match that he passed?
Navroop:
[00.40.37.07–00.40.54.23]
Yes. But is there something worth investigating? Oh, wait. Match their own legitimate business trip. Devices locked. You grab the first thing he could and it’s, you know, totally legitimate. And a human loop decision maker is able to ascertain that and say, you know what? We’re going to bump up your access in ArmorText from provisional to full access or.
Navroop:
[00.40.55.01–00.41.15.21]
Wait a minute, this is suspicious. We’re going to investigate further. In the meantime, we leave them in a provisional state, or we just go ahead and suspend his access or remove his access entirely. For right now, this is the kind of thing that inserts the humans back in the loop where they belong, especially during a crisis, to make those kind of hard decisions where a pass fail isn’t enough by itself.
Navroop:
[00.41.15.23–00.41.40.05]
One of the most interesting things, though, about this particular integration, though, was actually, you know, when it was coming together. Initially, we were about to take the stage at an internal conference, bringing all of our companies together, and we realized that the client really wanted to switch to a different gateway technology, right? Rather than having quote unquote, the on-premises gateway as we would normally deliver it.
Navroop:
[00.41.40.06–00.41.58.02]
They certainly asked if it was possible to do this as an AWS Lambda-based gateway. And, you know, this just speaks to kind of the quality of the amazing team we’ve got here and why. I’ve loved working with all of them for so many years. Our CTO and our engineering team said, you know what? We got this inside of 48 hours.
Navroop:
[00.41.58.02–00.42.17.14]
They delivered a brand new Lambda-based Secure Gateway that hadn’t yet existed and is now a core part of our offering that anyone can take advantage of and multiple folks referencing. Actually, I’d rather switch to that than the on-premises. And so we’re going to see some migrations coming up here. And it’s just that’s what a real partnership should look like.
Navroop:
[00.42.17.15–00.42.47.13]
Right. And so it was just was amazing. Right. This is verification without manual effort with liveness plus a biometric audit trail across enrollments. You had IdP-independent verification and it’s telemetry data that’s being delivered out-of-band and then encrypted to the right parties so they can make the decisions they actually need to make in a crisis. It’s I was blown away by how all three of the companies can be able to deliver that.
Navroop:
[00.42.47.15–00.43.04.03]
And now what we’re seeing is our customers are saying, hey, we potentially want to do exactly this with other IdV providers. And so we’re now talking to other IdV providers and working with our customers to figure out who else needs to be integrated in the same way. But we’ve got to jumpstart in a lot of thinking about how to do it.
Navroop:
[00.43.04.03–00.43.13.19]
And so again, this is one of those ones where, Matt, I think we’re probably going to ask for more design partners. If this is something that’s of interest to you, then come to us. We would love to get your feedback.
Matt:
[00.43.13.20–00.43.40.04]
Yeah. Well, in any organization in these kinds of moments of crisis, whatever it is, you know, they’re going to be onboarding external responders of various kinds or third party council of, you know, you know, all of these critical roles externally under pressure, they’re going to see the same kind of identity gap as they’re going through it. And just kind of, you know, cross their fingers and hope everything goes okay.
Matt:
[00.43.40.04–00.44.19.17]
But that pattern is something that can extend beyond that crisis mode, those incident response scenarios to lots of even day to day use cases, large vendor transfers and fed wires, password resets from people who are on network, you know, instructions for funds transfers, any of these kinds of high value, high risk workflows where where the identity of the person receiving it one way or the other has to be has to be legitimate, which that actually brings us to the session, that end of the day, which, you know, the day really didn’t stop there, kind of kept going after that.
Matt:
[00.44.19.17–00.44.52.23]
But the final panel propose something that doesn’t even exist right now. Right? It talked about organizations running OT honeypot and then sharing what they detect, not just with, you know, with their guys in the team next to them in the office, but across, you know, industry, across their their organizational boundaries to other organizations that share similar interests but securely and, and, you know, in almost real time.
Matt:
[00.44.53.01–00.45.16.07]
And if you moderated this so and I actually was dealing with some some logistics of setting up for the after event. So I didn’t even sit in on this. So what I would actually, I’d love for to hear the case you made, because I haven’t even even watched your video yet, unfortunately. So walk through what happened there as far as kind of unpacking that concept.
Navroop:
[00.45.16.11–00.45.38.04]
Yeah, I mean, look, this kind of started because we had been talking to one of our other customers about an OT honeypot that they wanted to build and put up. What was interesting when they shared the design of their honeypot was that it was based on it was based on an architecture for sector entirely differently from their own right.
Navroop:
[00.45.38.06–00.46.01.11]
This OT honeypot they were putting up would not be representative of any of the OT that they’re actually running themselves, but rather a completely different type of utility. Right. So non non sector appropriate OT honeypot. And their thought process was it might be interesting to just collect some information and then share that with others. And what we realized at the time was that OT honeypot telemetry sharing could be a value.
Navroop:
[00.46.01.12–00.46.18.23]
One of the challenges that we had heard about was that a lot of times, legal would actually stand in the way of organizations putting up an OT honeypot that very much resembled their own organization. And as a result, this was always something that was a little harder than they would like. And so we just pulled a panel together.
Navroop:
[00.46.19.00–00.46.47.08]
Right? And we called a few friends, some who we knew were just going to be attending in the audience, others who were already going to be speaking otherwise. And frankly, in the case of one someone who’s actually helping sponsor the event, right, you know, shout out to Matthew B. Welling from Holland & Knight was our sponsor for the day and especially for this final panel when I got permission to use his name tonight, he specifically requested that I referred how ruggedly handsome he is and that also he’s a caffeine addict.
Navroop:
[00.46.47.08–00.46.49.12]
I’m not quite sure why those two things had to be mentioned.
Matt:
[00.46.49.12–00.46.55.22]
I think the extra caffeine makes the ruggedness. He’s just hands on what he does. Just he’s luckily handsome and then the caffeine makes it rugged. Yeah.
Navroop:
[00.46.55.23–00.46.59.10]
Is that what it is? He just kind of looks. Max. You drink it up, monster. And then.
Matt:
[00.46.59.11–00.47.01.01]
Frayed at the edges. Yeah.
Navroop:
[00.47.01.02–00.47.24.15]
Yeah, exactly. I think I’m going to try that next. But, you know, we pulled him together. We had our friend Tim Chase from the Manufacturing-ISAC, which is a part of the GRF. Zach Randall from Pilot Flying J came back out as well. And then Brad Stephenson from Southern Company joined as well too. And what we did was just ask a series of questions about whether or not OT honeypots had value to them individually.
Navroop:
[00.47.24.16–00.48.02.22]
Would there be value in exchanging information? What had some of the impediments been? Why had legal potentially been a challenge? Why had the other eye not already picked up on this potentially. And what we did is we just got some answers out there and started asking them if we’d work through these, would this be beneficial? And so one of the things that we talked about on stage was getting, you know, a member of sector A to operate a honeypot that was really best resembling an organization in sector B, and then I think sector B, you know, someone there, one pot that best represents someone in sector C or D or E or some other sector
Navroop:
[00.48.02.22–00.48.39.01]
and then just kind of spreading them out that way. And it was later at the, you know, the after hours happy are we having, we were having after the event that one of our other former customers, CSO, who has now moved on to greener pastures, who came up and said, hey, I actually think you could accomplish what you want, but keep it within sector as well by actually getting the companies to effectively, either directly or indirectly allow for a comparison of what the honeypot would be that would most resemble them, and then figure out what would be most distant from them.
Navroop:
[00.48.39.01–00.48.58.19]
And then having, you know, kind of this exchange of, I will allow the one who’s most distant from me to run the honeypot that would collect value or collect information would be valuable for me, and then I will subscribe to that information. While that, you know, I run a honeypot for someone else that is quite distant from me as well, and I’ll collect something that might be a value for them.
Navroop:
[00.48.58.20–00.49.15.18]
Right? So kind of this round robin of distance from your own architecture, someone else runs it for you, and then you run it for someone else who you’re most distant from as well to, and then allowing different people to subscribe to that. And, you know, this is, again, one of those things that it’s kicked off so many different conversations after the fact.
Navroop:
[00.49.15.18–00.49.42.12]
We had some of our friends in the B or I suddenly chairman and say, hey, wait a minute, I got other OT experts here for you to meet. As we’ve started to talk to them, the kind of the this idea is just blossomed. One of the folks in the room is again a former customer, but someone who has now gone to work in PE, and she pointed out that, hey, she actually is an adjunct professor and works with a professor at NYU who focuses on OT honeypot.
Navroop:
[00.49.42.12–00.49.58.21]
And so she looped him in, immediately ended up extending my trip by a couple days just to stay back in New York, go meet up with him on a Saturday morning. And we’ve continued that conversation since. To what’s coming out of this is there is a real desire for this kind of OT honeypot telemetry sharing to take place.
Navroop:
[00.49.58.21–00.50.20.22]
And some of the challenges with doing it were what’s the transport mechanism for it? How do we create the appropriate distance? What are the right kind of legal entities, or what are the kind of sharing agreements that need to happen, but also that if you do this within sector and keep it there, there’s still the possibility of standing up something that sits above the sector.
Navroop:
[00.50.20.22–00.50.42.17]
Specific networks are created for OT telemetry sharing or to telemetry sharing to do the kind of meta analysis at that upper tier, that upper level. Right. So where you’ve up level to do this meta analysis and then distribute back down to each of those, you know, within sector OT telemetry that works, additional analysis that they wouldn’t get from just their own sector.
Navroop:
[00.50.42.18–00.51.03.03]
Right. And so with that, you know, there’s no explicit commitments from anyone. We’re not going to be naming who’s going to be coming in later this year, but we are probably going to pull together a meeting and get, you know, one day dedicated session going to further explore this. And if this is something that you’re really interested in, we’d love to have you be a part of it.
Navroop:
[00.51.03.04–00.51.23.04]
You know, the email is lounge@ArmorText.com., and someone from the team. Likely either Matt, myself, or Nancy will immediately chat with you and figure out how we get you involved, and you come into the one day session. We’ll we’re going to figure out what we do with what we do next with that. Right? Because there were no hard decisions. It was just proposing something, throwing it out there and seeing if it was a value.
Navroop:
[00.51.23.04–00.51.26.17]
And, you know, the reaction told us everything.
Matt:
[00.51.26.20–00.51.56.19]
Well, and it was it is an issue that has long been it’s not ignored, but the, the segmentation and almost isolation that has been, you know, part of the way OT environments protect themselves, you know, over history from, you know, cyber intrusion and things like that. That isolation has also slowed innovation and sort of contributed to this reticence to, to, you know, mess with something that, you know, it’s not broke, don’t fix it.
Matt:
[00.51.56.19–00.52.20.02]
You know, we don’t need to fix it. But it has also created scenarios like this one that we’ve kind of almost stumbled into, just with the help of our clients, where there are real needs that need to be addressed, that require a new way of approaching something that actually could bring in some new kinds of technology, as long as it meets the sniff test.
Matt:
[00.52.20.03–00.52.42.02]
Right. And that’s the point of bringing on these kind of creating this consortium of OT specialists to, you know, to, you know, pound on this question to really to really kick the tires on it to make sure that, you know, we’re covering all the bases because trust is going to be that critical piece to win over the confidence of those OT engineers that do this every day.
Matt:
[00.52.42.04–00.53.01.05]
Before we close this out, there’s one more question, because after this, after the panel we wrapped up, everybody kind of moved over to the lounge. They’re upstairs, which kind of is the theme of the question. And it is important, right? We it was our first annual Field Notes. It was on the books.
Navroop:
[00.53.01.09–00.53.01.21]
And this.
Matt:
[00.53.01.21–00.53.21.09]
Was that. Yeah. Yeah. You know, this is our name is what it is for a reason. We, you know, there was there was some very stressful moments. We, you know, the entire event was saved by by a lady who could run really quick to the Apple Store, you know, 20 minutes after the start time, we had more sessions than we planned on.
Matt:
[00.53.21.09–00.53.39.11]
We have things that kick things off immediately. As far as, you know, new new innovations, features, capabilities. But then we headed upstairs right to that off the record, as we called it there at the car club. So for you. What was what was the libation of choice that you actually reached for there as soon as you got to that?
Matt:
[00.53.39.12–00.53.43.04]
That bar was in the back. It wasn’t it wasn’t too hard to get to, though.
Navroop:
[00.53.43.06–00.54.05.12]
Yeah, it wouldn’t be the Lock and Key Lounge if we weren’t talking about libations. Absolutely. I have been told by the folks at the Manhattan Classic Car Club that we polished off an entire bottle of Eagle Rare. Apparently that is what I was buying both myself and everyone. And because we know the bartenders are so well, their pours were quite heavy.
Navroop:
[00.54.05.13–00.54.11.17]
And so we finished at least one bottle of Eagle Rare and actually met. What about you? Because you were with me.
Matt:
[00.54.11.17–00.54.19.03]
So I showed up a little later. Yeah. I was still handing out tchotchkes, the challenge coins and things.
Navroop:
[00.54.19.08–00.54.22.00]
Now, master of ceremonies, what were you going.
Matt:
[00.54.22.01–00.54.48.12]
To say? So I walked up after everything was in full swing, and there was actually two gentlemen that were members that had nothing to do with the event itself. They just I think they owned cars and they were just, you know, kind of catching up after the fact they were drinking. What was it? It was Angel’s Envy. Rye and I had I had a few conversations with Rob Lee over at Dragos, and he’s a huge fan of Angel’s Envy Rye.
Matt:
[00.54.48.13–00.55.03.14]
So when I heard that, I just mentioned that I had been trying to, you know, look to get it. Both of them got me a drink of it. And then I continued to drink that the rest of the night. So I was actually quite happy with, with their choice and recommendations and that in that setting.
Navroop:
[00.55.03.18–00.55.05.02]
It all comes back to the lounge.
Matt:
[00.55.05.05–00.55.34.11]
All comes back. All right, well, before we sign off here, a few quick things from the day itself that we think should be like the takeaways, the secure gateway library, we announced at Field Notes is going live for our customers. And these are going to be almost entirely customer contributed integrations, reference patterns and architectures so teams can adopt what their peers have already proven out.
Matt:
[00.55.34.13–00.55.59.12]
If you look at the gateway roadmap, we shared that very last stop in 2027, says community driven development. And the roadmap literally ends by handing itself over to the community, which is, you know, apropos since it’s the community that started this. If you listen to this episode, you know, the that is the whole story of the day and why the entire conference itself exists.
Matt:
[00.55.59.14–00.56.18.06]
Session video snippets are now going out live. We’ve already started that. We’re going to be posting these on LinkedIn. Obviously at ArmorText. You can go watch, you know, all the people we’ve been talking about because none of them were us. Well, except for and you listen to them themselves, listen to hear it in their words, hear it in their in their story.
Matt:
[00.56.18.08–00.56.44.10]
And with that, this episode of the Lock and Key Lounge RIFF Edition has come to an end. If Field Notes sounded like your kind of room, I mean, who wouldn’t? You’re running OT honeypots, and that last segment made your ears perk up or you’re looking for, you know, a CTI automation platform that maybe a little bit more geared towards your industry instead of, you know, marketing.
Matt:
[00.56.44.12–00.57.00.03]
Hit us up at lounge@ArmorText.com.. And find all our RIFF and regular episodes at ArmorText.com/podcast, Spotify, or Apple. Until then, stay curious, stay resilient, do good work.