TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.
Summary
The episode opens with Scott Robon presenting a stark reality: 49,000 CVEs were published last year, averaging over 130 new vulnerabilities daily, yet network teams haven't grown proportionally. Rekha Shenoy (CEO) and Irfan Kimji (Field CTO) of Backbox explain why this creates a crisis specifically for network infrastructure teams, which face unique challenges compared to traditional endpoint patching.
They highlight that network infrastructure is the most actively compromised component because it's easier to exploit than servers, yet patching network devices is exponentially more complex than deploying patches to Windows or Linux systems. The diversity of vendors, device types, and operating system variants makes standardized patching impossible. They present concrete examples: a large financial institution calculated it would need 23 additional full-time employees just to maintain vulnerability compliance across 23,000 network devices, while another customer was spending $8 million annually on manual configuration changes—two per day on every switch.
The speakers explain that the real work begins when vulnerability reports land on network engineers' desks, requiring them to spend hours rationalizing whether vulnerabilities apply to their environment, identifying workarounds, checking patch versions, and determining mitigation strategies—all before any actual patching occurs. This prevents network engineers from doing strategic work and has led to a "smart intern" approach where AI assists with information gathering and analysis rather than autonomous decision-making.
Regarding traditional tools and automation approaches, they note that many organizations have attempted Python scripting solutions, with one customer requiring 80,000 lines of code to handle device variety—an approach that only works if your team wants to become coders. They position Backbox as offering a low-to-no-code alternative that allows network engineers to build automations using vendor documentation and configuration language they already understand, rather than requiring new programming skills.
A critical theme throughout is responsible AI use. Both speakers emphasize that network engineers fear autonomous self-healing systems that make changes without human verification, as this creates accountability gaps and alert fatigue. Instead, they advocate for AI that provides dispositioned information, accurate cross-vendor vulnerability analysis, and recommended automations that humans must test and approve before deployment. They stress the importance of AI transparency, using trusted sources rather than allowing hallucinations, and focusing on business outcomes rather than AI as a buzzword.
The speakers also discuss the convergence of traditionally opposing viewpoints: those who rejected AI entirely and those demanding full AI implementation both responded positively when the focus shifted from "AI" to "solving your specific operational challenges." They emphasize that multi-team collaboration—security, infrastructure, operations, finance, and business working together—is essential, as attackers target the business holistically, not infrastructure silos.
The episode concludes with optimism about emerging tools that can correlate network flows, security information, and application performance across traditionally siloed systems, potentially enabling more holistic threat detection and response than was previously possible.
About this episode
Last year, 49,000 CVEs were published, more than 130 new vulnerabilities every day. So what actually happens with all of those CVEs in your network infrastructure? In this sponsored episode, Rekha Shenoy and Irfahn Khimji of BackBox join Scott Robohn to discuss why the math of manual network operations no longer works, where traditional tools<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/total-network-operations/tno071-the-network-team-is-drowning-is-ai-the-life-raft-sponsored/" title="ReadTNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)">... Read more »</a>
Key Insights
- Network infrastructure is the most actively compromised component in enterprise environments because it's easier to exploit than application servers, yet receives far less patching attention than endpoints
- A major financial institution with 23,000 network devices calculated they needed 23 additional full-time employees just to maintain vulnerability compliance, highlighting the fundamental math problem of manual operations
- Network engineers spend the majority of vulnerability management time on information gathering and rationalization (determining what applies to their environment) rather than actual patching, before any remediation work begins
- Experienced network engineers often avoid learning programming languages for automation, so solutions requiring 80,000 lines of custom Python code only work if organizations can dedicate entire teams to code development and maintenance
- Network operations teams fear autonomous AI systems that perform self-healing without human approval because they create accountability gaps and generate alert fatigue without providing clear ownership of decisions
- Organizations show positive response to AI-powered solutions when the conversation focuses on solving specific business outcomes (reducing headcount, costs, or security risk) rather than leading with AI as the mechanism
- Vendor documentation for vulnerability remediation is formatted inconsistently across manufacturers (Cisco, Fortinet, Juniper), requiring manual hours to normalize data and determine appropriate responses
- Cross-organizational silos between security, infrastructure, operations, and finance prevent unified defense against attackers who target business objectives holistically rather than single technical domains
Topics
Transcript
. Welcome to Total Network Operations. Our mission is simple, to bring out great ideas in modern NetOps and networking. I'm your friendly neighborhood podcast host, Scott Robon. Today, I have the great pleasure of welcoming Rekha Shenoy and Irfan Kimji of Backbox. I'm going to ask them to introduce themselves in a second, but let me just give some setup for today's conversation, some context. So last year, 49,000 CVEs were published. That's more than 130 new vulnerabilities every day. Do you feel overwhelmed? I feel overwhelmed by these numbers. Did your team grow by 130 people? I don't think so. So how are all these CVEs getting addressed in your network infrastructure? Well, today, Rekha and Irfan will…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
HN840: How to Make a Technology Buying Decision
Sean Morgan, a research director at Deloro Group, discusses how technology buying decisions should extend beyond engineering specifications to include business alignment, ROI calculations, and understanding total cost of ownership. Engineers must shift from viewing IT as a cost center to positioning it as a business enabler by connecting technical decisions to revenue impact and organizational objectives.
IPB207: Flying Blind: Monitoring Might Not See IPv6
The IPv6 Buzz hosts discuss critical gaps in IPv6 monitoring across enterprise networks, highlighting that many monitoring platforms lack IPv6 awareness, vendor parity, and advanced analytical capabilities. They emphasize that while basic IPv6 data ingestion has improved, sophisticated features like cross-protocol event correlation, extension header analysis, and device identity tracking remain significant industry challenges.
N4N063: Link Layer Discovery Protocol
Link Layer Discovery Protocol (LLDP) is a standardized Layer 2 protocol that enables network devices to announce information about themselves to directly connected neighbors, facilitating network topology discovery and device identification in multi-vendor environments. The protocol uses Ethernet frames with special multicast destination MAC addresses to ensure frames don't propagate beyond immediate neighbors, and includes mandatory TLVs (Type-Length-Values) like chassis ID, port ID, and TTL alongside optional ones for extended information.
TCG083: Superintelligence for Everyone: Who Actually Holds the Power?
Three technology experts discuss Mark Zuckerberg's manifesto on distributed superintelligence, examining whether his promises of universal access and individual empowerment align with infrastructure realities. They conclude that while decentralized AI is theoretically safer than centralized control, the manifesto fails to account for human complexity, existing inequalities, and the enormous capital requirements that will likely concentrate power rather than distribute it.
NAN130: Network Automation Forum: From Simple Survey to Global Community
Network Automation Forum co-founders Scott Robon and Chris Grunman discuss how their community grew from a simple survey about network automation adoption into a global series of conferences with 600+ attendees across multiple continents. They emphasize maintaining the organization's vendor-neutral, practitioner-led ethos while managing rapid growth and evolving industry trends like MCPs and AI agents.