TechnicalDiscussion

TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)

Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.

Summary

The episode opens with Scott Robon presenting a stark reality: 49,000 CVEs were published last year, averaging over 130 new vulnerabilities daily, yet network teams haven't grown proportionally. Rekha Shenoy (CEO) and Irfan Kimji (Field CTO) of Backbox explain why this creates a crisis specifically for network infrastructure teams, which face unique challenges compared to traditional endpoint patching.

They highlight that network infrastructure is the most actively compromised component because it's easier to exploit than servers, yet patching network devices is exponentially more complex than deploying patches to Windows or Linux systems. The diversity of vendors, device types, and operating system variants makes standardized patching impossible. They present concrete examples: a large financial institution calculated it would need 23 additional full-time employees just to maintain vulnerability compliance across 23,000 network devices, while another customer was spending $8 million annually on manual configuration changes—two per day on every switch.

The speakers explain that the real work begins when vulnerability reports land on network engineers' desks, requiring them to spend hours rationalizing whether vulnerabilities apply to their environment, identifying workarounds, checking patch versions, and determining mitigation strategies—all before any actual patching occurs. This prevents network engineers from doing strategic work and has led to a "smart intern" approach where AI assists with information gathering and analysis rather than autonomous decision-making.

Regarding traditional tools and automation approaches, they note that many organizations have attempted Python scripting solutions, with one customer requiring 80,000 lines of code to handle device variety—an approach that only works if your team wants to become coders. They position Backbox as offering a low-to-no-code alternative that allows network engineers to build automations using vendor documentation and configuration language they already understand, rather than requiring new programming skills.

A critical theme throughout is responsible AI use. Both speakers emphasize that network engineers fear autonomous self-healing systems that make changes without human verification, as this creates accountability gaps and alert fatigue. Instead, they advocate for AI that provides dispositioned information, accurate cross-vendor vulnerability analysis, and recommended automations that humans must test and approve before deployment. They stress the importance of AI transparency, using trusted sources rather than allowing hallucinations, and focusing on business outcomes rather than AI as a buzzword.

The speakers also discuss the convergence of traditionally opposing viewpoints: those who rejected AI entirely and those demanding full AI implementation both responded positively when the focus shifted from "AI" to "solving your specific operational challenges." They emphasize that multi-team collaboration—security, infrastructure, operations, finance, and business working together—is essential, as attackers target the business holistically, not infrastructure silos.

The episode concludes with optimism about emerging tools that can correlate network flows, security information, and application performance across traditionally siloed systems, potentially enabling more holistic threat detection and response than was previously possible.

About this episode

Last year, 49,000 CVEs were published, more than 130 new vulnerabilities every day. So what actually happens with all of those CVEs in your network infrastructure? In this sponsored episode, Rekha Shenoy and Irfahn Khimji of BackBox join Scott Robohn to discuss why the math of manual network operations no longer works, where traditional tools<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/total-network-operations/tno071-the-network-team-is-drowning-is-ai-the-life-raft-sponsored/" title="ReadTNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)">... Read more &#187;</a>

Key Insights

  • Network infrastructure is the most actively compromised component in enterprise environments because it's easier to exploit than application servers, yet receives far less patching attention than endpoints
  • A major financial institution with 23,000 network devices calculated they needed 23 additional full-time employees just to maintain vulnerability compliance, highlighting the fundamental math problem of manual operations
  • Network engineers spend the majority of vulnerability management time on information gathering and rationalization (determining what applies to their environment) rather than actual patching, before any remediation work begins
  • Experienced network engineers often avoid learning programming languages for automation, so solutions requiring 80,000 lines of custom Python code only work if organizations can dedicate entire teams to code development and maintenance
  • Network operations teams fear autonomous AI systems that perform self-healing without human approval because they create accountability gaps and generate alert fatigue without providing clear ownership of decisions
  • Organizations show positive response to AI-powered solutions when the conversation focuses on solving specific business outcomes (reducing headcount, costs, or security risk) rather than leading with AI as the mechanism
  • Vendor documentation for vulnerability remediation is formatted inconsistently across manufacturers (Cisco, Fortinet, Juniper), requiring manual hours to normalize data and determine appropriate responses
  • Cross-organizational silos between security, infrastructure, operations, and finance prevent unified defense against attackers who target business objectives holistically rather than single technical domains

Topics

Vulnerability management at scaleNetwork infrastructure patching complexityAI-powered automation and responsible AILow-code/no-code solutions for network engineersAlert fatigue and autonomous self-healing risksCross-vendor vulnerability intelligenceNetwork operations vs. traditional endpoint managementMulti-team collaboration in security operations

Transcript

. Welcome to Total Network Operations. Our mission is simple, to bring out great ideas in modern NetOps and networking. I'm your friendly neighborhood podcast host, Scott Robon. Today, I have the great pleasure of welcoming Rekha Shenoy and Irfan Kimji of Backbox. I'm going to ask them to introduce themselves in a second, but let me just give some setup for today's conversation, some context. So last year, 49,000 CVEs were published. That's more than 130 new vulnerabilities every day. Do you feel overwhelmed? I feel overwhelmed by these numbers. Did your team grow by 130 people? I don't think so. So how are all these CVEs getting addressed in your network infrastructure? Well, today, Rekha and Irfan will…

Full transcript available for MurmurCast members

Sign Up to Access

More from The Everything Feed - All Packet Pushers Pods

Get AI summaries like this delivered to your inbox daily

Get AI summaries delivered to your inbox

MurmurCast summarizes your YouTube channels, podcasts, and newsletters into one daily email digest.