SourceForge Podcast
The SourceForge Podcast is the world's largest B2B software podcast published to over 1.5 million subscribers across all major social media and podcast platforms, and to over 667,000 subscribers on YouTube. Interviews with tech and software CEOs, leaders, and changemakers. The SourceForge Podcast by Slashdot Media gives you insight into the cutting edge of software, B2B SaaS, and trailblazing technology.
SourceForge Podcast
Unified Endpoint Management Platform: ManageEngine
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
ManageEngine provides a comprehensive suite of IT management and security solutions that help organizations monitor, manage, and protect their infrastructure, networks, endpoints, identities, and applications from a unified platform. Its broad portfolio enables IT teams to automate routine tasks, improve service delivery, strengthen cybersecurity, and maintain reliable, compliant IT operations across on-premises, cloud, and hybrid environments.
In this episode, we speak with Romanus Raymond, Director of Technology at ManageEngine, about how endpoint management has evolved from bulky, enterprise-only software into a more accessible, unified security platform. The conversation explores the growing challenge of defending a sprawling mix of devices—Windows, macOS, Linux, mobile, and remote endpoints—while attackers and AI-driven threats move faster than traditional patch cycles.
Romanus explains why “best-of-breed” point tools often create more complexity than control, and why a unified approach gives IT teams better visibility, prioritization, and remediation. The discussion also covers practical strategies for patching, including how to separate mitigation from remediation when patches aren’t yet available, how to prioritize vulnerabilities based on exposure and exploitability rather than just CVSS scores, and how to support remote workers without forcing them back onto the corporate network.
The episode closes with a look at automation, digital employee experience, and the future of proactive IT. Romanus argues that the long-term value of endpoint management isn’t just cost savings—it’s resilience, trust, and the ability to recover quickly when disruptions happen.
Follow SourceForge:
SourceForge.net - https://sourceforge.net
SourceForge LinkedIn
SourceForge X (Twitter)
SourceForge Facebook
Interested in appearing on the SourceForge Podcast? Contact us here.
The SourceForge Podcast is the world's largest B2B software podcast.
Hello, everyone, and welcome back to the Source Forge podcast. I'm your host, Bo Hamilton. All right. Now I want you to think about how many devices are connected to your company's network right now. Think of the laptops, the phones, the tablets, all spread across, you know, maybe it's your office, maybe it's the kitchen table, uh, connected to sketchy hotel Wi-Fi around the world. All those devices, every single one of them, is actually a door for potential bad actors and vulnerabilities. And if you're an IT, your job isn't really to keep the computers running anymore. It's it's defending this huge, constantly moving fleet of endpoints that attackers are poking at around the clock. And honestly, that job is uh is getting a lot harder this year. That job of defending them is has become much more difficult. Patch cycles that used to be measured in a matter of months are now racing against exploit timelines measured in hours. You've probably heard of Anthropic's Claude Mythos, the AI model that can find an exploit zero days on its own across basically every major OS and browser. Um, it's it's caused um you know some concern, some headaches, um, but it's also uh shown a light on you know where the future is is going and and um kind of the problems that are out there. So um offense, you know, um in this area is moving at really quick light speed almost, while most of the the defense um is still waiting on humans to click approve. And so, you know, you have the uh those two different timelines. Um, it's not a great matchup, right? And so that's kind of the backdrop for today's conversation. My guest is Romanus Raymond, director of technology at Manage Engine, and he works uh on endpoint management security, manage engines, unified endpoint management and security platform um that that covers all sorts of uh the possible IT um, you know, concerns and and and pillars there with patch management, software deployment, mobile device management, and increasingly working on AI-powered threat detection, um, all of which is under one roof under the endpoint management security platform. So um in this conversation, we we have a lot to cover. We'll get into how Manage Engine's mission has evolved over the last two decades, what it takes to manage Mac OS, Linux, and mobile without sort of flattening what makes each platform unique. Uh, we're gonna talk about where automation should act on its own versus you know where humans should still be in the loop and so much more. So I'm really excited to have him here for this conversation. Um, so without further ado, Romanis, welcome to the podcast. Glad you could join us.
SPEAKER_00Thanks, Phil. Thanks for the great uh intro, actually. You completely covered the portfolio. Thanks, Fallett. Very excited to be here. Yeah, looking forward.
SPEAKER_01Yeah, so um uh okay, so we've got a lot to talk about. I know it's kind of a long-winded intro, but um a lot of really interesting things to cover. And I just want to get right into it if you if you don't mind. Uh I want to focus a little bit first on Manage Engine for listeners who you know might not be familiar. Manage Engine has been doing you know IT management for over two decades now, uh, which is I would say several lifetimes in software years. Um, maybe you can take us back to the inception point, the beginning. What problem did the company originally set out to solve? And then how has that mission evolved into what it is today?
SPEAKER_00That's a great question. So I'll just start with uh what were we doing initially, right? In terms of managing managing gin was previously uh with a different name called Advantage. So by then we were doing NMS EMS, network management systems, element management systems. It's more of developer products, right? We write products for the developers so that the developers can work on the product and build products for their products. Right? It's that kind of approach. So from there it shifted to more into enterprise IT, where during that time, I'm talking about our late 1990s, 2000, right? So if there are a lot of um requirements in terms of IT management. Now, during that time, the software, what you have to buy, there are two things. You have requirements, it could be monitoring a server, or it could be monitoring uh the performance of a particular application, right? Uh it could be checking the availability of uh some network devices. So you have some uh focused requirements. But the software which you have to use for that is very huge, bulky. Only the Fortune 500 were affordable to take that because it requires expertise. They were bulky. You have to download, you have to install and have the database available, configure that database with your application, and you have a UI, and it takes days with an expert to run the application. Right now, we launched Manage Engine launched the product with a pretty much easy targets address the requirement, which is one. Two, make sure that these requirements in terms of uh bulky downloads has to be reduced. So it's a small download, one click, installation completes with all the required parameters configured, including the DB, making sure that you run the product immediately. You don't have to take weeks together to configure that and install it. And directly get into the problem what you want to fix in terms of uh discovering the assets, in terms of identifying the uh protocols and how you're going to configure all these things. So we kind of democratized the space for software for the small, mid, large. Anybody can use it with the affordable pricing and with no experts required to run the software. So, this is something that I think uh managing, apart from the uh focus area where it has to solve the problem, with this focus uh we launched. And I should say there are a couple of things which actually uh catalyst or two forces which drove the shift are basically the device that it was initially in your introduction, you were talking about Windows, Mac, Linux, mobile devices. Today we talk about IoTs, right? A lot of such things have to be managed. How do you manage? Now we have an additional question of how do you secure? And the second one is we all know the pandemic came. So the remote work shifted gear to another level of uh management and security. You don't no longer have a perimeter to manage and secure, it's more in terms of it could be anywhere, it could be any of your employees working for you, but you are supposed to manage and secure them. Now that's the uh gear shift which actually accelerated more in terms of her products. So I would say from from from uh democratizing the software till to to the level of remote work culture adoption.
SPEAKER_01Gotcha. That makes sense. Yeah, so it's it's I mean it's in the name, manage engine. You have to, it's it's this engine that's that has to manage all these different endpoints, all these different um threats, uh manage all these different tools. I mean, you don't, like you were saying, you don't uh you don't have to be uh a Fortune 500 company and have all these all these resources um and these funds. Now you can have this one platform um that has democratized access to security um and you know threat mitigation, right? Um and it's uh I you know it's a tall order trying to keep devices secure these days. There's so many threats. And obviously, you know, I think it's a testament. You're your two decades in the industry is a testament to, you know, the capability of the platform, I would say, um, having to evolve with all these different, you know, uh evolving threat landscapes, um, you know, the cloud migration period, the pandemic remote work. Now we have AI and everything, you know, in between and before that. So there's uh no shortage of things you guys had to um tackle and evolve um to mitigate. But um, okay, thanks for laying that that groundwork, that foundation. Um, before we get you know too much further, too much uh you know deeper into the product, I want to sort of like clear the air on something because I think there's a little bit of a perception gap here at the industry. In your experience, uh, what's the biggest like misconception IT leaders still have about endpoint management platforms today? Is there anything that comes to mind?
SPEAKER_00Even today, many of our enterprise customers, CISOs, uh, would ask this question, right? So um typically, what is the misconception that I have seen is basically instead of going with um uh product which can do everything, we'll take best of breed and then stack them so that you should be able to manage them better. And I think this that's going to give them better results. Now, I would strongly say that this is going to bring more uh complexity to the IT management and security. You can have one product for the Apache, right? You can have one product for doing endpoint detection and uh response, you can have one product for MDM. But from enterprise point of view, as a CISO, if you look at your tools, they are doing their jobs, but they are all siloed. You don't do not get to uh have a better visibility of what's happening across. Now, today, industry, when there is an attack, it's all connected from one vulnerability from one endpoint, from one user's click on the fishing bail, it's going to get the threat actor into your organization. And wherever you have vulnerability, it's going to move. How do they move laterally? So, unless you have better visibility in terms of what's happening, you will not be able to do a good job of managing and securing. So, in reality, if you have multiple tools, you just built a highly fragmented brittle IT stick. So, I would strongly say having a unified approach, right? Having a better visibility of all these things, unified approach gives you better control, better visibility of what's happening, where you have to focus, and where you have to have more things or energy put. I think that's where uh the misconception is happening. Best breed, stitched solutions put together, that stack is going to help you. No, that's not going to help you.
SPEAKER_01What's what's tricky about uh you know unified endpoint management is it it's you know you have macOS, you got Linux, you have uh mobile, uh you have all these different operating systems, they have their own sort of like philosophy, um, right? Apple, Apple wants things done Apple's way, Linux admins want they want full control. Mobile is sort of like its own universe. I know that like with the Apple ecosystem, they're trying to sort of bridge the gap between mobile and um iPad OS and Mac OS. Um, but the point is like you know, you have all these different sort of um uh design languages and and like just different again vectors for for for vulnerabilities. Um so how does this unified endpoint central management platform like reconcile all of that without sort of flattening what makes each platform work?
SPEAKER_00Each OS, each uh uh have their own philosophies, right? As you mentioned, Apple, you don't install agent, you have to do uh enrollment. The language itself changes, right? For Linux, it's a different approach. So we clearly understand that Apple has to be managed the way that Apple expects that to be managed. Linux is so open, so it has to be managed in that way. Mobile devices have to be done in that Windows has its own way of uh doing that. So endpoint central has a federated uh approach in terms of managing that. All right, but uh from an enterprise, from the business point of view, if you look at that, uh you want to know the inventory. You want to know what are your assets. And in my digital estate, I might have servers from different vendors, different OES, I might have uh end user computing, missions from different vendors, different operating systems, Mac, as you mentioned, mobile devices, iPads, and you also have Linux servers and Windows missions. Now, if I want to have a better view of visibility of all the assets, I should be able to talk to different uh such different verticals and get the visibility for the business. This is what and two vulnerability as far as business is concerned, it's one in the C. A vulnerability through a Mac, through a Linux or through a Windows or mobile device is going to cause the same problem to the business. It's not how I manage, how I visualize and how I am able to get that information and then do a remediation accordingly. So we have a federated approach in terms of managing, securing them, but from the business point of view, we have a unified view where everything becomes an asset for them and everything has to be secured. So we speak that language when it comes to unified, and we speak federated way of managing each individual uh vendor and their applications, OS, things like that.
SPEAKER_01Gotcha. Okay, so yeah, we're respecting the platform uh instead of like forcing, forcing everything through sort of this like window-shaped lens. Um, that's that's really what um, you know, that's what cross-platform admins I think are looking for. Um, I can see the the appeal there, and I think it's gonna resonate a lot with um the IT teams uh listening and leaders who are interested in in adopting a new security approach. I think they're gonna resonate with that. So, okay, so we've covered like the the what aspect now. Um now I want to get into the the sort of day-to-day reality for IT teams because for a lot of them, I think the job still feels like you know they're running around with a fire extinguisher trying to extinguish threats and um you know issues as they arise. Um, so let's kind of get into that reactive firefighting mode that the IT teams live in. Something breaks, maybe there's a ticket that comes in, there's there's all sorts of scrambling going on trying to solve it, fix the problem. How does endpoint central help leaders shift from that to actual like a proactive control, proactive response, especially now that everyone's you know, hybrid or uh working remotely? How do you deal with that?
SPEAKER_00There are certain things like um, say, for example, like user wants uh application for his business, right? Now, for his own uh trade inside the organization, it could be for uh AutoCAD for his uh designing, it could be some designing software for a particular designing team. Now they have to raise a ticket and the ticket has to be assigned to a technician, and the technician has to check the license and availability, and then uh either he walks in or he takes a remote control, installs, installs the license, and then configures and then closes the ticket. This is a typical flow in any organization, right? If it's not automated. Now, what happens you understand that this particular team has to have a particular designing software, not for everyone, just for that. So, what is available there? There are two kinds of approach. One, you can administratively push this to that particular person. You don't have to go there and uh do any kind of uh settings, so remotely push. Yet another approach is make sure this whole design team has a self-service portal in which this application is available. Right? When this user clicks on that, finds that application, clicks on it, it gets installed. Automatically, uh inventory is generated, a license is already taken, mapped, and the entire back-end process of having a license is proactively managed and the required application is also installed. Now, this way we proactively ensures that particular team or organization or a remote office or uh complete new businesses that you have merged with your business gets whatever they need. Instead of raising multiple tickets, you automate the process. Right? Either administratively or from the self-service point of view. So that's how the endpoint management and security uh is delivered in a better way than uh getting a ticket and doing that thing.
SPEAKER_01That's a great way to illustrate it. I appreciate the the examples there. Um it's you know, uh getting ahead of the problems um is is just that's that's gonna be way more appealing, way more of a uh of the choice that you know prospective customers and clients are gonna um want. Um and of course it's easier said than done, but it sounds like having the automations in place to to tackle and uh address some of these issues is um does a lot, speaks wonders. Um okay, so I want to uh talk about patching, right? Because uh, you know, that's the that's there's nowhere is more is more um urgent than patching, right? Um so I want to throw some numbers your way. Uh industry data has put typical enterprise patch cycles somewhere in the in the 55 to 94 day range. So basically like two to three months or so. Um meanwhile, you have attackers that are weaponizing new vulnerabilities in a matter of hours. And so you see the mix, the mismatch there. The the math doesn't work. It's not math and right. You know, a traditional patch cycle is effectively a breach timeline now because of that. So the the metric everyone's talking about now is mean time to remediate. How fast can you actually close the gap once a vulnerability drops? Uh, my question to you is is what's endpoint central's approach to getting that number down? How do you reduce that uh mean time to remediate time?
SPEAKER_00Yeah, yeah. That's that's the huge talk of the town today, right? With as you mentioned in the beginning, with Maitos and Daybreak coming in, number of uh patches, what uh you can expect. It's the velocity of patches which are going to uh burst is going to be huge. So there's going to be a tough time for the IT admins who are actually managing the security of the endpoints on the service. And you might have also seen the June months Microsoft patch. I don't know whether you have uh noticed that. This is this is the first month which has got a lot of patches, one and a lot of catches with more uh elevation, uh elevated uh remote code execution, a lot of such things are happening. Zero days. So this is going to be the new normal. That's what this prediction is happening. Um we were doing a similar uh cyberessential uh uh for the UK. So they are actually uh redefining the critical patch uh timeline from 50 days to uh 14 days, and while we were broadcasting this uh that uh webinar, some inside information came, they are going to reduce it to seven days by July. Right? So this is how industry is thinking in terms of complaints that they have to adhere. So the product is capable of doing that. Now, the product is capable of doing manual mode of uh patching, automated mode of patching, right? But what I see here is more important, the strategy. Right? When there is a zero day, you don't have to uh wait for a lot of things. You have to separate the mitigation and remediation. When you have the patch, you can immediately deploy it. When you don't have the patch, go for the mitigations where you have a scripted way of uh removing the unwanted protocols, right? Uh reducing the access to the service and reducing the exposure of the endpoints. This way, adapt a risk framework to put your patch unaware. Vulnerable machines into deeper into your network so that you protect them. At the same time, whatever has the patch, you should be able to automate them, make sure that you quickly do that. Have priorities. Two things here about so one, there are a lot of patches which are being uh released by the vendors, right? And you have to think about how many are exploited and how many are applicable to you. And you also have to think about what is the exposure of your endpoints or servers to the internet to the outside world. And the exploitability is the main thing. And I mean whether whether it is exploited, whatever uh patches you have, it is exploited to how is your exposure to the internet? Right now, calculating all these for your network is going to give you a better visibility. The tool is there to uh deploy that in a systematic way. You can you can do the critical patches, most exposed uh uh servers uh endpoints could be done in the first ring, and then you go for the other words, and then you go for the lesser critical things. The strategy has to be devised by you so that it becomes very efficient. So you address the uh exploitable exposure, uh more exposed endpoints first, and then you go with other things. So it's a strategy, and the tool is well designed for any of that strategy, which will ensure that your endpoints, your servers are actually always protected and secure.
SPEAKER_01Well, that's what I was wondering is like the prioritization. How do you prioritize all these different threats? Because right when you, I mean, you you alluded to the uh Microsoft Tuesday patch uh for earlier this month um in June, uh, which set a record for the number of patches and um uh vulnerabilities it addressed. Um and but like what looking ahead, uh constantly you always have to look ahead of what's what's coming, you know, what are the threats now? And actually, right after that uh patch Tuesday was released, um a zero day for Windows just dropped, was made uh available. So um, you know, that's just the the nature of the the industry right now. But yeah, how do you prioritize things? Every vulnerability um I know comes with a C VSS score or a vendor severity label, um, but those often don't really reflect real world risk. You know, plenty of of sort of like quote unquote critical CVEs never get exploited, while some of the less critical ones, the medium sort of uh severe ones, get get hammered um across the board. How do you help like IT teams prioritize patches based on real world risk rather than these scores or vendor severity labels alone, especially in this age of AI, you know, discovered vulnerabilities?
SPEAKER_00I mean, what bothers me, what can put my business down? So I will treat that first. So that's prioritization. Now, you cannot take the CVSS. That's one way of measuring that, right? CVSS is based on the patch released and its criticality, right? Now, EPSS is something that uh uh which talks about exploitability and uh CISA has uh KV data, right? Now, as I mentioned earlier, how do you uh you know your uh network better, you know your endpoints better. Now there are standards, there are some information available. Now, based on that, now what are the endpoints according to the EPSS score, according to the CISA KEVE, and your practical uh knowledge about what are exposed outside? Now you have to make sure that you prioritize first in the first ring of deployment, which has to be done immediately. So that way you can prioritize not based on CVSS, but based on exposure, exploitability, which in terms of EPSS or Sisaki V data, you should be able to find that. The tool will help you to just do that.
SPEAKER_01Gotcha. Okay, so so context of the exposure and and vulnerability um is it's is more important than just kind of the raw scores. Um, right. Okay, that's a good, that's good to good to know, good differentiator there. Um now, okay, all this sort of, let's say you you do you do prioritize the right things, you know, all this sort of assumes you can actually reach the endpoint. And I know in 2026 a lot of them aren't sort of sitting on the corporate network, right? So how does patching change when endpoints are remote or off-network or only just connecting intermittently? Um, because you know, the the laptop that's like sitting in, you know, that's been sitting in my uh a backpack of mine for for two weeks is actually the one you should probably be most worried about, right?
SPEAKER_00Yeah, that's that's uh really a pain now, right? Managing the work from home endpoints, end user computing, and the people who always travel, right? So as far as the product is concerned, this is designed to manage and patch anywhere, from anywhere. Right? It could be, I mean, there are organizations uh which mandate that they have to use the VPN, right? Only using the VPN because they want to ensure that uh the patches like this are happening periodically, they want to keep their endpoint secure. This is one way, and uh but we don't recommend that. So you don't have to have because most of the companies, as you mentioned, go cloud. Their applications are available on cloud, they don't have to hit the uh carpet network just to get the patch. Right? Now they are all uh uh let out to work from anywhere, but only to receive patch, you can you cannot ask them to come back to the corporate network. Now, the best way is you have to make sure that you get the status of each endpoint about patching level, and make sure that you have a staging from the from the cloud or uh on the endpoints so that the patches are downloaded and available. So whenever it is contacting, whenever it is uh reaching to the uh internet, it should be able to get that downloaded and deployed. So it's not about coming to the corporate network, it's about availability of that endpoint spread across uh work from home or remote work, they should be able to get the patches staged and then deployed to them. So you don't have to have necessarily come back to the uh corporate network to get it done.
SPEAKER_01Well, um, Romanis, uh, this is a I think a good point uh of the conversation to bring in uh the mythos discussion. Um I know we've kind of been uh alluding to it throughout. I mentioned it in the introduction, but um for for listeners who might not be aware, so in April, Anthropic published research showing its Claude Mythos model could autonomously discover and exploit zero days across basically every major OS and browser. Um now currently Mythos is is gated, only a small set of partners can touch it. I know that that is changing by the day. It's it's kind of being more broadly rolled out. Um by the time this episode publishes, maybe it'll be uh, I don't doubt it'll be fully public, but it's it's more broadly being rolled out. Um but the question is like, how should an IT leader recalibrate their endpoint strategy when you know offense, because of these tools, these AI tools like mythos moves they move at a machine speed, and and most offense uh you know strategies are still gated by human approval. Like we I mentioned earlier how there's like uh uh there's just sort of this discrepancy between like hours versus weeks of of um you know offense versus defense. So how do you just respond to that? Yeah.
SPEAKER_00So when the offense is autonomous, the defense should also be in that way, right? So it's uh it's it's going to be really tough or unpredictable as of now. Now we have the tools, but the strategy, the methodology that we use is very slow in terms of uh getting the consensus. You have to go for QA testing, you have to ensure the patches what you have deployed is not breaking uh the business application which is running, right? And uh you have to go by staging the deployment rings. Now, all those things are strategies before Mythos. You cannot have those strategies when a velocity of patches is going to flow into your uh purview, which you have to deploy to your headpoints. Now, this is where uh the the two points which we already discussed. I'm just bringing it back. So, not all with the rate of patches, the rate of uh vulnerabilities identified being identified, you cannot expect patches to be available at the same speed. The vulnerabilities are identified at the mission speed, the patches are delivered at human speed, right? So there's a difference. So if the patches are available well and good, you can go ahead and deploy it. You have the tools, you have the strategy to that. If they are not available, make sure you fall back to risk framework, mitigate by having uh reducing the uh, as I said, if the protocol is going to be uh complicated, reduce the number of protocols, number of ports, number of people accessing that. Keep it inside the uh uh network by having more firewalls to be captured. And we also talk about uh the layered approach, right? You have known vulnerabilities which you address by patching. You have unknown vulnerabilities, you don't have visibility, but when you bring visibility, you can have some remediation for that. You have unknown unknown, which I classify that category where you don't know what kind of problems are going to come. How do you remediate that? The best way to do go about that is having a detect and respond. So you I have the vulnerable server where I don't have the patch, not better scripted, mitigated way, then I'll place it inside my uh organization with multiple layers of uh uh protection and do uh detect and response. So any malicious activities, any suspicious activities, any known um IOCs, any no iOS, based on that I should be able to do that. So mitigation, detect and respond kind of approach is going to help you with that. So this is the combination of strategy that we can uh today think about that. But on in reality, only when you get into that time and see how much, what kind of uh patches are being released, what kind of wulneries are going to be treated, has to be treated, only by that the strategies can be redefined and refined better for business.
SPEAKER_01Yeah, and I think in regards to to mythos and these uh these insanely advanced AIs that are able to discover some of these zero days and exploits, I think that from what I've I've gathered, is like it's there's gonna be this big spike of vulnerabilities in zero days, and then it should sort of ideally mellow out, sort of level out after um you know uh this AI has been out there and partners have been able to kind of issue patches and or uh are actually uh discover vulnerabilities, right? Like there's only you'd think there's only so many that they can discover. So it's gonna be this big spike, and then ideally things will kind of mellow out. But um it's certainly that spike, we're in the spike phase right now, and it's certainly causing a big stir.
SPEAKER_00So to add to that, if you're having a product which are open source, because the mythos is going to go through the code and give you the vulnerabilities. It's not the without the code, it's a black box testing. So it's not going to generate so much as it could generate with the code what it is available to them. You get the difference, right? So that way, as you mentioned, it's going to be at the peak at some point and then going to below down gradually.
SPEAKER_01And and it from uh I from information I've I've heard from researchers who have used Mythos hands-on, it's really um, it really does best when it knows the full context of the situation. So like it's not like it necessarily you can just kind of plug it into your system and immediately it's gonna find all these vulnerabilities. It kind of needs to like know the full context, how how the platform works, the you know, the various code and whatnot. So I feel like there is still gonna be a little bit of a um, you know, this this learning curve for mythos, even to discover everything. If that makes sense. But um all right. So there's obviously a lot of AI promises floating around in enterprise software right now. Um, I want to get into some of the the examples, the concrete examples that maybe um will resonate with listeners. Um where uh maybe you can give me an example of something real, something that's shipping today where AI actually saves an IT admin some some serious time.
SPEAKER_00Okay. So uh taking an example, like uh in the patching itself, right? So you have uh uh application running on all your, let's say uh 5,000 endpoints, right? They're all remotely uh uh connected to the road, right? Now you you find a vulnerability found a vulnerability in one application which you use. Now you want to uninstall that, right? So you don't have a patch for that, you have to go and uninstall that. Now you can do that uh as a as a script, or you can go to the console and do it and create it as a uh as a configuration and then deploy it, it's going to take care of uh that and comes back and tells you this is one way of manual way of doing that, right? Uh but in order to do that, um if it is a specific requirement, specific way of doing that, so it needs some scripts, uh coding knowledge to be available for the uh the technicians or the application owner so that it can be deployed to the product. Right now, with the integration of AI, so uh from manage engine we call it as Zia, which is integrated to all the products. Now, you can talk to the um product seeing that I need to uninstall um this application from so many computers, and uh I want to test this before deployment, then you can you talk or give this context to that, it's going to, because of the integration of AI, this is going to understand that, create a script for you, and also understand the behavior availability of those machines. So it understands the criticality. So as soon as those machines show up in the network online, this is going to make sure that this is automatically doing the job what has to be done on priority and comes back, gives you a report that it has current status of 5,000 to how much it is reducing and when it is neutralized completely.
SPEAKER_01Yeah, I love that. That's that's crazy. Like I that's the best thing about this kind of AI era is it just use natural language, type into a uh basically a chat box, um, and then it just gets to work, right? Like you don't need necessarily all of the technical explanations. It kind of already knows the context and has some solutions. Um, obviously, the the more kind of uh technical, you know, expertise and prowess and and terms you you are you know of, like that you're able to um kind of fine-tune the the um direction it it gives you. But like it's pretty powerful, a pretty powerful tool. Thanks for sharing that with us.
SPEAKER_00So you don't have to remember the syntax, all you have to do is understand your business, understand uh the endpoints, and it also has the context of telemetry collected from each endpoint. So it has more information about the availability, about the behavior, about uh what is there in the endpoint. So your prompting is going to be uh very uh uh easy in terms of uh getting those contexts and then doing the job done.
SPEAKER_01Yeah, well, and certainly much easier than the the previous solution of having to actually, you know, know of the the the threat, tackle, like know how know the solution, and then do it yourself, basically, right? So um, yeah. All right, well, um, so I I want to uh bring up uh automation uh some more and and kind of get into that more directly. I know automation more broadly speaking is sort of uh pitched as like this this time saver, um, but I know a lot of IT leaders sort of worry about the control aspect and losing that control. Nobody wants to be the the admin kind of explaining why a bot pushed a bad patch to 10,000 machines. Um that would make for an awkward you know conversation with your boss and have a PR nightmare would just be a mess. Um, so how do you think about that uh that line in endpoint central? Where should the system act autonomously and then where should humans you know stay in the loop and have control?
SPEAKER_00All right. So I gave you an example of um uh the zero day, right? When there is a zero day, so you don't uh it is directed by your endpoints, right? And if you feel that uh there is a uh fix for that, you don't have to wait for uh the human approval because if you know the impact is going to be huge, you can quickly uh ensure that it is automatically deployed, right? Automation and more autonomous decision making in that area, right? Similarly, uh we we we hear about uh digital employee experience, right? When there is a deviation from standard, right? When uh when application is available or more complex, the end user, uh the user might be moving to a shadow IT, shadow application, which is not approved by you, but he has a right and he's installing that. When there is a configuration drift, when there's a password drift, the DEX can automatically bring it and align it to your uh compliance JS. So you don't have to deviate. Now this could be automated, this could be uh autonomous decision. But whereas in terms of uh uh rebooting the service, right? Uh think about uh things like uh you are in a hospital environment, right? And uh you have uh deploy the patch. And uh here I would suggest deploying a patch is not a problem, but doing a reboot is a challenge here. It might be uh the the consultants or the doctor's uh uh uh iPad or a laptop or a mat book machine, it might be the nurse's station, it might be the imaging machines controlled uh PC. So there it needs uh uh a consultation human in the loop because I cannot go and reboot a production environment's uh life critical, mission critical endpoints because I need a mandatory reboot for that definition. So I have to have a human in the look because it and he understands the business or uh a life better than the uh the autonomous or automated decisions. So this is how business have to, depending on their business uh uh circumstances, they have to decide on that.
SPEAKER_01So yeah, it really depends on on the the business itself and the industry you're working in. If you're in a healthcare uh setting and you're dealing with you know life or death matters, um, you know, you got to take a much more careful approach versus if you're, I don't know, uh like a department store or something like that, you know? Okay, so for enterprises running lean IT teams, um, and I would say that's most of them these days, uh, where should the focus really go? Like where should the prioritization go? Should it be for more tools, a better sort of orchestration of the tools they have, or is it uh towards delegating more to these autonomous systems?
SPEAKER_00So uh if you have a unified uh tool, so again, I'm just coming back to the uh the previous answer. Like, so you can most of the things you can orchestrate automate. So based on certain things, so you understand your business, you understand certain type of uh uh patch or certain type of tasks could be delegated automatically then, and then you have uh to take that. Uh result uh you have to see the results based on the reports. That's when you can delegate, automate. And then uh keep track of that. Not all the problems need autonomous solutions. Right. And when you go for autonomous, you have to spend a lot in terms of uh the compute, the AA you choose, the tokens that you spend, all those things. Now, what you spend and what you get out of that autonomous, it is actually uh improving your business or uh or bringing more revenue for the business. That's a trade-off questions. But I would say having a unified tool, having an autonomous orchestration, delegation, is the way to uh look at it better than designing on the autonomous systems.
SPEAKER_01Okay, well, um, on that note, I want to zoom out a little bit and kind of look at just where things are are heading because there's obviously a shift um happening in who uh endpoint management is even for. Um you mentioned earlier uh DEX, digital employee experience. There's this growing focus on that area of the um you know employee experience. Um endpoint management used to be purely an IT side concern, you know, like is the is the device secure? Is it patched? Now it's about whether the employee on that device actually can do their job well. Um two questions on this front. The first one, how does DEX digital employee experience fit into the evolution of endpoint management? And then the second part of the question is like, why is endpoint experience suddenly this leadership level concern? So you maybe we can split it up into two separate questions there. I'll let you handle the first one.
SPEAKER_00How I look at DEX, maybe this is the second part answer. How I look at Dex now is basically it is changing the way that IT has been working. As you rightly sure said, it's more reactive. It's more reactive. Only when people talk to you about uh their application is crashing, then you go ahead and uh investigate if you cannot fix that, go to the vendor, get their support, fix that. Now, Dex is changing that. So that's the reason uh the IT leaders are focusing more on that, because it's moving this one into a new regime called proactive IT, not a reactive way of managing things. Proactive IT. What I mean by that, the same example there are uh applications being used, business applications being used in your uh business, but it is behaving uh uh sluggish, it's kind of slow, right? It's not responding well. So instead of you waiting for the end users, the consumers, uh, experiencing that, coming back to you and reporting about that, the system will understand that this performance of particular application is degrading from last week to this week. And it could sense that this is because of the latest update which has happened. It is doing a correlation root cost analysis. Okay, after this, it seems to be slow and it shows the option to the end user himself because there is a solution available. Do you want me to revert to the previous version and try um this application again? And somebody says yes, and this then it reverts the uh the last patch, whatever has been done for the for that particular application. And if it is going to work normally and it takes the the confidence level of uh the solution is gaining, so it could do that, and at the same time, it's giving a report that there was a performance issue, and I was able to revert that with a known solution uh after finding the root cause analysis, and now you can report. Now, two things have been solved. One, your business point of view, people are happy working continuously. Two, you found the problem and you have to report it to the vendor who can work on that and come back to you. There's no downtime, there is no uh better experience, degraded of experience for employees. Now, after this, you can also trigger surveys to uh uh the the end users and see how they felt about the product, the new rollout of uh the the software and new policy which you have brought in, new processes which are all these things are possible. So this is becoming one of the uh the go-to tool for your uh CISOs and IT managers to get more predictive, more insights, proactive pay.
SPEAKER_01Gotcha. Okay. Thanks for um explaining that and and addressing the you know, answering the leadership level concern around um you know digital employee experience, kind of the focus there nowadays. I think just kind of relating it to how the endpoint is the the workplace now, like for remote for a remote employee, like the the laptop, the device they have is sort of the office. And so when you kind of like look at it from that lens, you kind of understand the focus on on Dex. Um now I want to ask you for the last question is is the the value um side of things. You know, cost savings are uh the easy pitch, I would say. But beyond that, what's like the long-term strategic value that endpoint central delivers to IT leadership? Like what does this look like as an investment and not an expense?
SPEAKER_00Okay, beyond costing, right? So as you mentioned, we started with simple focus on configuration management and then becomes management and management to uh secure. Now it is adding uh proactive IT next to it, autonomous, right? Now, beyond that, beyond costing, I think endpoint central or manage engines unified endpoint management security line of products delivers resilience and trust. I think that's the value that uh I want to re-emphasize, right? Uh the IT leaders basically gain confidence that their network environment can withstand disruptions, right? Now you cannot avoid uh attacks because so many we talked about uh mythos, we talked about uh uh daybreak, we talked about uh uh a lot of patches being June being an example from Microsoft, right? Now the attack surface is going to always increase. There is going to be always vulnerability, there's going to be always attacks happening from the threat actors. But one thing what the leaders wants to have is we have to have resilience. Though I am attacked, how soon I can come back to normalcy along with the data applications that is required to run the business for every endpoint. Now I think we from manage engine, we want to ensure that resilience and trust is the value that it promotes the most rather than the cost saving. We also have recently done a study with Forrester, independently done by them, which talks about 442 percentage of ROI within six months. Right? Which is one of the best in the industry. But I'm not going to, I'll not be talking about that, recommending that. The value part I want to emphasize is resilience and trust. There is going to be attack, there is going to be a breach, but how soon you are going to detect, come out of that, neutralize, come out of that, and with the business information application data, contribute, start contributing immediately to the business. That's the value I see.
SPEAKER_01Well, that's a strong note to end on. And you know, there's there's three things that are you know certain in life. I feel like it's it's death, taxes, and vulnerabilities and exploits, and and these bad actors trying to, you know, take advantage of um loopholes and uh yeah, just yeah. So uh it's it's a matter of what you're able to do to mitigate those threats. And I think uh the the solutions manage engine and the and your platform has uh put together um under this unified umbrella, I think is um very advantageous. And the value is uh definitely uh it's it definitely seems like um a high value offering uh with what you guys have. So um thank you just for for you know breaking down this this landscape and uh elaborating on some of the the tools and features and whatnot that you have built into the platform. For listeners who are curious to learn more, maybe get in contact with your team, um, is there a place you'd like to send them?
SPEAKER_00Yeah, we have the website, uh, and um you should be able to get uh competent information. If you're using the product, even if you are the product is free to sign up and uh you you can manage uh a certain number of endpoints for free. And right from the product, you have the chat. You can directly talk to one of our live agents. So any queries, any um demos, any uh any specific uh requirements or any coexistence. I already have invested in so many products. So this piece is something that I want. How do you coexist? So that's one of the biggest strategies that we have. All those things can be handled from the website or from the product itself.
SPEAKER_01Perfect. All right, we'll leave that link down below in the show notes and over on uh SourceForge.net in the article section. Um, Romanus, uh, thank you so much for all the insights you shared with us. I genuinely think this has been a great conversation, and um, I hope listeners really enjoyed this one.
SPEAKER_00Thank you so much for hiring me. It's a blessure.
SPEAKER_01Thank you all for listening to the SourceForge podcast. I'm your host, Bo Hamilton. Make sure to subscribe to stay up to date with all of our upcoming B2B software related podcasts. I will talk to you in the next one.