Build Versus Buy: The Risk of Vibe Coding Your Security Stack with Andrew Dutton - Ep 238
Andrew Dutton is the Regional Cybersecurity Architect for Sumitomo Chemical America, part of a global chemical manufacturing organization with roots stretching back more than 400 years, from copper mining in Japan to fertilizer production to the diversified chemical business that exists today. The company employs roughly 30,000 people worldwide, and Andrew's region also serves as its global center of excellence for cybersecurity. Andrew, himself an Army veteran, brings both a technical architect's precision and genuine appreciation for how the company operates. He joins the show to lay out a vision he has spent years developing for an AI operations layer, a way to get plain language answers about an organization's entire security posture instead of digging through disconnected tools, and to talk candidly about where the industry is already there and where real risk remains.
Here’s a glimpse of what you’ll learn:
- How Andrew's AI operations layer concept would let a CEO get a real, honest answer to are we secure
- Why Andrew says showing someone a raw count of 100,000 vulnerabilities is worse than useless
- How a real threat actor actively targeting chemical manufacturers shows proactive AI defense in practice
- Why Andrew calls traditional email gateways obsolete compared to modern AI powered alternatives
- The build versus buy risk Andrew sees in constructing an AI security stack without the right expertise
- Why Andrew believes the real barrier to good decisions is a decline in critical thinking, not the technology
- Andrew's take on how AI could reshape careers and the outdated idea of job security tied to one employer
In this episode…
Andrew opens by describing a concept he has developed for years, an AI operations layer sitting on top of every tool in the security stack with read only access, connecting inventory systems, EDR platforms, and CMDBs that often disagree with each other into one place a security leader can question in plain language. He walks through a concrete example: asking which servers aren't running EDR sounds simple, but reconciling an inventory system against an EDR platform against a CMDB that all define server ownership differently is exactly the tedious work an AI layer should absorb. He argues this layer should prioritize problems, telling a team the specific top ten things to fix rather than dumping a raw vulnerability count with no actionable meaning. From there he describes a proactive use case: asking which threat actor is currently targeting chemical manufacturers most aggressively, learning the specific technique that group uses, checking whether current defenses actually stop it, and kicking off a purple team exercise to verify the answer rather than trusting the tool's word for it.
The conversation moves into how mature this vision already is, and Andrew is blunt that machine learning built directly into security products, tools like Darktrace and ThreatLocker that catch abnormal behavior or block unauthorized actions outright regardless of how an attacker got in, is no longer the future but table stakes today. He connects this to the MGM breach, arguing behavioral AI would have flagged a brand new admin account performing wildly unusual actions long before a human analyst noticed, and he is equally direct that traditional email gateways are obsolete, pointing to how Proofpoint acquired specialized players like Tessian to bolt AI powered behavioral analysis onto legacy filtering that can no longer keep pace with attacks arriving through legitimate services like DocuSign. He is also candid about the real risk of building these systems in house without the right expertise, describing how easy it is to vibe code an impressive prototype without understanding what it is doing underneath, burning through token costs on the wrong model, and comparing the temptation to the early rush to the cloud that left organizations with runaway bills.
The back half broadens into how AI reshapes work and opportunity. Andrew argues the biggest barrier isn't the technology but a decline in critical thinking, and that organizations need people who can analyze a problem within its full business context rather than accepting whatever an AI tool outputs at face value. He shares a grounded perspective on job security as something that no longer comes from loyalty to one employer, describing his volunteer work helping high school students in rural Tennessee see paths beyond the local plant, and arguing that financial stability and a strong personal skill set matter more than tenure. He closes on an optimistic note about where AI could take society, from reducing domestic violence through in-home monitoring to enabling small, highly leveraged companies built by a handful of people, while acknowledging some of the hardest human problems are unlikely to be solved by technology alone.
Resources mentioned in this episode
CyberLynx Website
Andrew Dutton on LinkedIn
Sumitomo Chemicals Americas Website
Darktrace Website
Abnormal AI Website
Sponsor for this episode...
This episode is brought to you by CyberLynx.
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.
Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.
Check out previous episodes:
The Security Sidecar: Wrapping Code in Real Time Defense with Aby Rao - Ep 237
Doing More With Less: A Department of Three Punching at Twenty with Tony Bryson - Ep 236
The Age of Human Judgment, Not the Age of AI, With Benny Zhang - Ep 235
Transcript:
Cyber Business Podcast
Andrew Dutton,
Regional Cybersecurity Architect
Sumitomo Chemical Group Companies of the Americas
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Andrew Dutton, Regional Cybersecurity Architect at Sumitomo Chemical Group Companies of the Americas. Andrew, welcome to the show.
Andrew Dutton: Hey, thanks. Thanks for having me.
Matthew Connor: Thanks for coming on. Before we get too far in, a quick word from our sponsors.
Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. That's cyberlynx.com.
Matthew Connor: And now, back to our show. Andrew, for those who aren't familiar, can you tell us about Sumitomo Chemical Group Companies of the Americas and your role there as Regional Cybersecurity Architect?
Andrew Dutton: Sure, I don't really like talking about myself, but I'll tell you that being a regional architect is an interesting area. Sumitomo Chemical is a very large chemical manufacturing organization. Sumitomo itself is actually over four hundred years old, it started as copper mines in Japan, but then they found out they were basically destroying the environment, and from that they started creating fertilizer, and that became what is today's Sumitomo Chemical. You'll probably hear the name Sumitomo elsewhere too, Sumitomo tires, Sumitomo Mitsui banking. So anyway, we're Sumitomo Chemical, we're about thirty thousand people worldwide, but I sit in the Americas region, and we're also the center of excellence for cybersecurity for the rest of the world. It's really unique, I love working for a Japanese company that really cares about the environment. So yeah, that's kind of what I do.
Matthew Connor: That's awesome. It's funny, because when I was in the Army I was in Tokyo for three years, I was stationed there, and it's just such a cool culture, the customer service is just so different than the US, and the way they approach business, which is funny, because the way they approach business was taught by us, when MacArthur came into Tokyo and started figuring out how to rebuild the economy we'd just destroyed, he brought in a bunch of business leaders and they kind of rolled out the US model. But the Japanese took it and really ran with it and perfected it, and man, on the customer service side, the way they treat employees, the way they look after them, just incredible, they really set such a high bar.
Andrew Dutton: Yeah, absolutely, man. I love working for them. So yeah, I really enjoy it in the architectural field, understanding what we're trying to do and how to fit that within the organization. Yeah, that's pretty much it, man.
Matthew Connor: Well, let me ask you, this is really cool, because in the modern day we live in with AI and cybersecurity, I don't think you can separate the two, I think they're linked now, some people will disagree with me. I think the future of cybersecurity is a hundred percent AI-driven, you've got to fight fire with fire, the bad guys are using AI to find zero-day exploits and attack at machine speed, so how do you keep up? I don't think traditional tools can do it, traditional filtering, relying on patches being perfect and that being safe, I think we're past that now. And I'm curious, you're in quite the spot for exactly this, what's your take? Am I batshit crazy, or am I in the right ballpark? What's your take?
Andrew Dutton: Oh man, you've just opened up a can of worms, my friend. I've been working on this project for a couple years now, getting to fruition, and I'll tell you what I think, right, I'd probably tell three or four vendors a week the same thing. You've got all these vendors in the space, whether it's SIEM, SOAR, AI SOC, right, and they're all doing the same thing. But what you're talking about is this AI-enabled operations layer at the very top.
Matthew Connor: Okay, dive as deep as you want, let's go, we got no rules.
Andrew Dutton: Let's do it. So what this thing is going to do, I kind of explain it as, it's the AI in the elevator with the CEO that's answering the question, are we secure? Because we're never going to be a hundred percent secure, but this is basically an AI layer that's answering questions. So to go back to what you were just talking about, we still need those layers underneath doing the things, but we need to put this AI layer on top of it to work with those tools more efficiently. And let me tell you what this AI operations area is going to do for us, and then we can talk about why it doesn't happen today and what the challenges are. So what it's going to do is do basic things and answer basic questions at the core. I talked about "am I secure," let's talk about the integrations. You're going to integrate into your EDRs, your NDRs, your email security, your SIEM, whatever it is you have in your security stack, your entire stack needs to be integrated into this AI operational stack, read-only, and we can talk about why that is later. In that aspect, when I want to know something about my security stack, I'll ask the question in natural language. An easy example is, what servers don't run my EDR? You'd think that's an easy question, right? Well, if you're running an EDR, it only necessarily knows what systems it knows about. So if you have an inventory system, you have to get from the inventory system what servers you have, and maybe your CMDB has different servers that aren't part of your inventory system. So you've got to collect all that data together and match it up to your back end. This is very common, where you'll see something say, hey, this server doesn't run EDR. Oh, absolutely it does, I see the service running right now. That service is not connecting to our EDR service correctly, maybe said a little differently, but at the end of the day it's the same thing, it's not running our EDR processes right, our profiles have become stale or fallen off or whatever the reason is it's not working correctly. So, can I answer, are my security tools configured correctly, are they working correctly, are they on the things I want them to be on? So that's kind of a basic highlight, we can get really into the weeds, but that's one piece of it. The next piece is, if it isn't right, how do I fix it? Vulnerability data, patching, it's one thing to tell me I have a hundred thousand vulnerabilities, don't ever tell me that, I'm not going to show that to anybody, it means nothing to me. What you can tell me is, I think the top ten things you should fix are these things, and by the way, this is why I think they're broken, this is where you should start, and these are the things you should think about to fix them. The next level to that is, it should help me investigate stuff. Maybe my SIEM doesn't have certain data in it, maybe I outsource my SIEM, maybe I'm not really that level-one SOC analyst, but I want to be able to say, oh, I've got this thing happening, what does it mean, who did this and at what time, and how do I gather up this different data into one place? And that's more reactive, but then that falls onto things we could do proactively. Let me ask a question, I'm a chemical manufacturing organization, who's attacking the most chemical manufacturing organizations in the United States this month? Oh, that's, whether it's Scattered Spider, APT43, whatever it is. Oh, that's interesting, so Scattered Spider, how do they attack people? Oh, they use this MITRE ATT&CK technique. Oh, interesting, am I defending against that technique? Let's check it out. And then pivoting into, now create a pen test that'll go to my pen-test tool and pen test me, because I don't want to believe you, I want to test that thing to see if it's really stopping it and my defenses are correct, and if not, how can I fix the defenses for that? And that really comes to that whole purple-team idea, you hear about continuous pen testing or continuous defenses, purple teaming is, I want to be able to stress-test my environment whenever I want, ad nauseam, whatever's the latest thing, I want to be able to react and proactively look for things, and react to those things within this environment. And then not only that, I want it to assemble my stuff, my thoughts, and produce some sort of output I can work with, so that everyone we're working with is on the same page. So if you do an IR investigation, you have this output, and you need to make sure that this is consistent, but not only that, I want certain output going to the C-level, certain output going to the legal team, certain output going to the infrastructure team. At the end of the day, it's the things we do today, it's just going to be done faster.
Matthew Connor: Well, I couldn't agree more with all of that, but I think we're already starting to see benefits beyond just implementing that AI at the top level, for the read-only management piece. I think where we are and where we're going, you see it in tools like Darktrace, where you've got AI, specifically more machine learning, built into the security product, whether it's email, network, or MDR, now you've got AI looking for, wait a second, this is abnormal, whether it's an email, or an application doing something weird, or there's weird traffic on the network, it doesn't matter how the bad guy got in. And I think this is the future of cybersecurity, that it's awesome when we're able to use natural language to speak to AI and see all of our stuff, just as you described. It's so cool, it's so fantastic, it makes our job so much more enjoyable that we're not in there with the wrenches and the tools doing everything, but now we get to think more strategically, and the outputs are spectacular. But I think the real huge benefit comes when we've got AI in those tools, and we're no longer using traditional tools, but AI tools that are looking for the abnormalities, the strange behavior. Because we've seen far too many times in the past where threat actors have been living inside networks for weeks, often months, before they were ever captured or detected, because they exploited something we didn't know was exploitable, and traditional tools don't alert you to that. Even though it may have been sitting in the SOC, and you could have seen it in the SIEM if you'd searched, maybe, possibly, it's much better to have those AI tools immediately catch it. And the cool part, I think we would have seen it with something like the MGM attack, where it was brilliant social engineering, but you'd still have AI, that's a perfect use case for AI to be like, hey wait, day-one admin, and this guy's running around the place changing things, hold up, I'm stopping this, because this is such abnormal behavior. Phenomenal, that's where I get excited when we see stuff like that, I think that gives us a glimpse of the future, today, and where we're headed. And when you combine all of that, AI or machine learning working in your network, your endpoints, your email, and even securing your AI agents, monitoring your agents to be like, whoa, hold up, why is Jane or Jimmy putting proprietary information into this model, we said don't do that, please stop them. I think AI to secure our AI, and AI to secure our endpoints and our users, I think that's the future.
Andrew Dutton: Yeah, I don't know if it's the future, I think it's today. Honestly, I think, good point, the tools, what's the term, it's table stakes, if your tool doesn't have it, I'm not buying it. And to go back a little bit and explain it, in the past, DLP, regex, we're looking for a pattern, that's no longer, don't even talk to me about DLP because I hate it, but we're to the point, and like you said, machine learning's been around for a long time, just generative AI on top of it and being able to do that, I think those are table stakes today.
Matthew Connor: Agree.
Andrew Dutton: Where was I going with this, I was saying something about, oh, about behavior, right, you're totally right, spot on, you've got to look at overall behavior. So let's think about this, so-and-so is an admin, the domain admin, and they run a script, but they might run that script once a year, so maybe that gets flagged, or maybe instead of getting flagged, it actually gets stopped. You mentioned Darktrace, one of the products I like is ThreatLocker, they're sort of allow-listing, and they have this thing where you can get to the point of blocking the administrator from doing it, and then they put in like, oh, I'm about to run the script, I'm doing this, okay, you put in some additional factor of authentication, anything you could do. There is a caveat to that though, we have to make sure we're not stopping business. So I think that's one of the things sometimes traditional practitioners don't realize, first of all, it's not our job to secure the company, our job is to explain to the people, the executives, the risk and what they could do. They might decide not to mitigate that risk, they might decide to buy cyber insurance and be okay with that, we don't need EDR because we don't want our developers dealing with it, as long as you're explaining those risks. But being able to work with the business to maybe create some speed bumps, so maybe the executives agree, we don't need to be running at seventy miles an hour, let's put a speed bump in, we're going to go twenty-five miles an hour, that's a lot different. It's that whole "know" versus "no" thing, right? Because at the bottom layer, remember I said something about not trusting AI, there's a lot of people who don't trust cybersecurity professionals in their own companies, because of the way we portray ourselves, how we present data, we tend to be in the weeds, and you mentioned you were in the Army, I was also in the Army, we had all these acronyms for everything, and you go into a room with all these acronyms and people are looking at you like, you're an idiot, man. So being able to understand your audience and realizing how you can tell stories and work with people and say, dude, we're in the same boat, it's just that maybe I'm loading the shells into an artillery piece and you're the one pulling the trigger, but if I don't load the shells, you can't pull the trigger, and if I load the shells and you don't pull the trigger, I load another one.
Matthew Connor: Yeah, yeah, but no, I totally agree with you, I disagree with what you're saying, that it's the future, I think it's already here, I think it's table stakes, I think any products people will be buying will have a natural language component.
Andrew Dutton: And I believe the other reason that's important is we want to bring knowledge, because knowledge is power. So I want to bring knowledge to Matthew, the server infrastructure person, I don't want to be on this high pedestal like, I'm not sure you might not, no, dude, come on, let's talk about this, let me show you some things. The other day I was explaining TCP/IP, because sometimes when you go up in certain verticals, you just don't get some basic information along the way, and I'm kind of an old guy, we had to do things manually back in the day. So no, I would disagree with you, I think it's already here and it's already table stakes.
Matthew Connor: You know what, I totally agree, and I was hedging because a lot of people are, they're not AI-averse, but they're a little gun-shy, a little intimidated, a little scared, and they see it coming. But I completely agree, it is here in products now, it is the present and the future. I don't understand why anybody, and man, I'm going to get a lot of grief for this one, but I don't understand why anybody's still using a traditional email gateway, it's garbage, and now I've just annoyed a whole lot of people, but it is, in comparison to some of the more modern AI-powered email security products like Darktrace, like Abnormal Security, it's pure garbage. You've trained people to get so used to going through the trash for what they want, filtering out stuff that was legitimate, filtering out stuff that isn't, it makes it worthless and gives us a false sense of security. All you're doing is putting on these old filters, it's so archaic, and now I've alienated a ton of people, they're all mad at me, fine, so be it. But that is so arcane, it's ten years too old now, and at the speed things are going, I just don't understand it, other than the fact that people are so used to it and don't want to pull it out and put something else in. I just don't get it. Email, that's such a great example, it affects everybody, it's a gateway into the organization, it's a weak point, the end users are right there using it, so it gives you access to the weakest link in the organization, and yet we're using old-school methods to try to secure it. We are figuratively bringing a knife to an AI gunfight, and it's no contest. You take a look at things like those DocuSign scams, great example, who's falling for that, right, but how do you filter it out, you can't filter out DocuSign, people get it, it's legitimate. So when they leverage a legitimate platform, the filters can't do it, so then you're training Joe and Jane in accounting on what, that's not their job, they're accountants, we're the cybersecurity people, it's our job to do it. And people are like, oh, that's crap, but you'd say, don't they need to be trained? We just, traditionally, haven't had the tools to be able to properly do our job so the end user could just do their job, and so we're so used to saying, no, we have to train them, you've got to train them. No, we didn't want to, we had to. But I think the day's coming where we don't have to, and people are going to disagree with me on that one, but I think when we've properly done our job, and AI gives us the power to do it, the end user will no longer have to worry about, can I click on this, is this a bad email, is somebody going to get mad at me, am I going to do something wrong? No, what arrives in your inbox will be clear, and if it isn't, when you click on it, something else will catch it, and we've got you, you do your job, we'll do ours, I think that's how it should be.
Andrew Dutton: Yeah, I think your hypothesis is already playing out. Think about Proofpoint, they bought, I think it was Tessian, right? So let's just talk about Microsoft 365, Microsoft has their front end, and it's okay, but do we need to catch everything? Microsoft will probably throw out eighty percent of the junk, so let's go behind an API or some other way to look at those messages that come to your mailbox, and then, like you said, use machine learning and AI to really understand the behavior. And this is part of, we believe this is a bad thing, because again, why do you need to search through millions of things coming in, because you've got this front end doing a half-hearted job, you're already paying for it. This is going to back-end, a person in my family recently, their company, I'm not saying the switch email provider, they know who they are, they switched, and she explained to me how she gets a digest now. Then she says, but if I want spam out of my digest, I have to justify why I want the spam released. I'm like, what, it's just spam, you know what I mean, like, we shouldn't be making it hard for our users, we should just do it. Kind of what you're talking about is, let's just get rid of the risk. We can't now, the bad thing is we don't have infinite budgets, right? I mentioned, when I was talking about this AI SOC platform, I'm talking about adding to your budget, which is always hard, I always talk to vendors like, hey, what can you replace, which I have budget for, but constantly adding twenty-five percent to your budget every year probably isn't happening, especially in the manufacturing world.
Matthew Connor: You know, you said something, well, I've got an interesting take on that one too. I think there are so many great products we can replace traditional products with, swap those out without really much of a budget increase, or even a decrease, not much of a change there. So if we've swapped out all of our email security, our endpoints, our network security, and now that's doing it, I think that while you work towards getting that budget for the management piece, can't you really leverage Claude to be that manager with you, in that read-only way, to say, hey, look, here's what's happening. Like SentinelOne, for instance, I think their Purple AI, I love where they're going with things, and CrowdStrike does it as well, where you've got your natural language, hey, here's what we found, here's what's going on. It's movement in the right direction, but it's not quite there yet, it's too early. So often you take what Purple AI spits out and drop that into Claude, or your LLM of choice, and it's like, oh, here's the deal, and it really refines that. So I think leveraging agents, LLMs like Claude, is a great way to do that in the interim. I mean, if you've already got that, you're spending your hundred bucks a month to have Claude, could you not do most of the management stuff you want until you get the budget? It's not the perfect solution, because it's not all feeding in there, but you can give it read access to all of those things and say, hey, every day I want you to go through, you're going to be my chief of staff on this, I want you to go through, take a look at things, let's analyze, are we set up right? Could you not do that with Claude in the interim, easily? It doesn't just have to be Claude.
Andrew Dutton: You should be, boy, we're really getting into the weeds now, man. Let me say this, you remember that AI operations thing we just talked about, that doesn't exist today, people do pieces of it, there are reasons why it doesn't exist, and I get we can go into the weeds on that, but I told this to somebody yesterday, I said, I can vibe code this today, I could do this exact thing today. The problem is it goes back to traditional build versus buy. So what's the risk of the build, for me, number one, and again, it's not me, it's the organization. The build is number one, I'm not the best data scientist or builder there is, right, just because you can vibe code something doesn't mean you understand what it's doing. So if I don't, I run a lot of risk, not putting the right security around it and all those things, I run the risk of doing it incorrectly and using the wrong models, because you should be using a multi-model approach. The idea is, if I asked a question, what time is it, I shouldn't be using Claude Fable 5 to do that, because I'm paying whatever cents per token, maybe I use some free version, there are different levels here. If I don't know how to code that correctly, I'm going to just go crazy on my token charges. And let's think about what we're seeing today, people are moving back into the data center for this exact reason, I don't necessarily need all these subscriptions, I can run those things in my data center for significantly cheaper, run those on, what is it, DIY NUC boxes and Mac minis, dude, we're to the point where, again, if you don't know what you're doing, you can mess it up. I harken it back to the cloud, like, cloud's the best thing, and people are like, boom, I moved to the cloud, and then you go to the first meeting with the CFO and he goes, why have you spent sixteen billion dollars? Well, I don't know why we went to the cloud. So cool. And so there's a lot of problems with people running with scissors, and we're doing a lot of talking about AI, but we were very smart in saying we're not going to build anything unless we flesh out the use case, and we did that, we fleshed out some use cases and realized we don't have the datasets for it. So if we'd just been throwing money into AI trying to build this thing, we would have wasted so much money, because it's really a data issue, it's a data project, it's about getting the right sensors and the different things, there's just a lot of shiny objects out there, man, to sort through.
Matthew Connor: Well, it's true. And the interesting part is, we're at such early days, we're now September 2026, and it's less than four years since OpenAI's ChatGPT came out, so we're under four years. And I think the progress we've seen in the last six months has been absolutely spectacular, because now you look at how even Claude or Grok are building the guardrails and the safeguards in from the get-go, and they're focused on that, and as you do stuff, it's constantly reminding and focusing on that, which, going back to your running-with-scissors point, was not what was happening over the last one, two, three, four years, we were running with scissors to go as fast as we could, and security, safety, guardrails, and governance would have to catch up. How do we catch up with them, you're sprinting, and the governance folks are, they're not fast movers, especially our national government, you can see the states are way ahead of them, because we just, well, last week we started talking more about it, I think there are some executive orders around it, but really we're behind the times. And, not to get on my high horse, but why don't we work with other countries around the world, why don't we all agree on these things, why does the EU have this thing, why are we so much against it, you know what I'm saying?
Andrew Dutton: I do, and sadly, I think the reality is, you take a look at Silicon Valley, because that's kind of ground zero, the mentality of entrepreneurship and fail-fast is unique throughout the world, and it grows from there. The US, our whole economy is built around that entrepreneurial spirit, and then as you move to Europe, it's completely different, their focus is on the individual and the collective, theirs is on individual privacy and security and the collective good, whereas ours is on how do we build economic and industrial power. So we're at odds with them fundamentally, and when it comes to regulations and security, and then you throw in the military aspect, it's like, hold up, I'm not sure how much we really want to be working with the rest of the world on this, because I'd much rather, from our perspective, we want to get there first and kind of dominate, it's always been our thing, we don't know how to be second, we're not good at it, we think we know better. And that's, clearly, I think it's debatable these days, we used to, I'm going to scratch that, let's just move on, we can get ourselves in all kinds of trouble there. But I think it's a real challenge, and it would be great, and I'm an AI optimist, I think ultimately AI will bring us all together as a world. There are some huge problems, fundamentally, there are religious factions that have been fighting for hundreds, if not thousands, of years, and AI is not going to solve that, that's a people problem I don't know how we solve. But most of the other problems, economic, biologic, you name it, so many problems are going to be solved that I think it'll bring us together economically as a whole, it's going to bring up the entire world population, we're going to be wealthier, happier, assuming it doesn't decide we're a virus and wipe us out, which I don't think it will. You're basically talking about a renaissance, where we'll be able to go back and learn music and paint and become more human. I tell this to my kids, different people, my kids, I'm like, I don't think I'm going to live in a home when I'm older, because I think the home's going to come to you, I'm going to have this robot, if you've ever watched the movie Robot & Frank, you're going to have this robot, the robot's going to make sure you got cooked for, make sure you're fed, they'll call the doctor, hell, they'll probably stitch you up right there when you're old, and we won't have as much of a traditional old folks' home.
Matthew Connor: We're getting there, and I'm glad you're an optimist, because I'm also an optimist. There are a lot of people out there in the media, and companies, that are throwing out this FUD, and all it is, is bam, bam, bam, just to get investment money, and they're lying, it's just kind of what we're going into now. Can I pivot, what are we going to lose, what do we have to worry about here? Cybersecurity barrier to entry, right, when these things are doing all the job of the level ones, the level twos, and level threes, how do we make sure we get people into the workforce to understand cybersecurity, because we're going to age out the people who had to do it manually?
Andrew Dutton: How do we, I think another thing is, not just in cybersecurity, but critical thinking is an issue in the world today, how do we bring back critical thinking, because being able to analyze a problem is super important, because of what you said, we're going to have all this data, but you still have to analyze it within your context, within your company, within your world, to understand if it's the right thing to do. And I think we're starting to get to the point where we're just teaching to the test, instead of bringing out that kind of thing, because there are some core functionalities, core learned abilities, that I think are going to start really being missed.
Matthew Connor: I completely agree. And I think there's a couple of things, on the robot front, I like thinking about how much that's going to improve things, like think about domestic violence, right now a huge problem nobody really likes talking about. However, with a robot in the home, who's hitting who? Nobody's hitting anybody, murder rates are going to go down, domestic violence is going to basically be nowhere in that future where robots are everywhere. You're not going to have people breaking into your home and doing bad things, why, because good luck getting past the robot, that's not happening. So I think that's a really cool future we're headed towards, and I think that's just amazing. And then when we start thinking about where AI takes us in terms of jobs in the interim, because hopefully we're ten, twenty, thirty, forty years from that AGI super-intelligence, it's not coming next year, don't listen to those guys.
Andrew Dutton: Totally.
Matthew Connor: And it'd be really, because where we are with generative AI right now, I think, is phenomenal, and what I think we have to focus on is, right now, if you look at the news, it can be scary, because let's just take software engineers, for instance, it becomes really scary, that's a tough marketplace now, very competitive. So I think the top fifty percent, really the top twenty-five percent, probably don't have anything to worry about, the new ones coming in, when you're the best of the best, you're going to be fine. It's the bottom twenty-five, the bottom fifty in the middle, that are really going to struggle, they're going to have a harder time getting jobs. But the reality is, what does that do for those jobs, when it becomes a better job? At the same time, we're going to see so many more smaller companies rising up and doing things, and people are going to have to be more entrepreneurial, and be like, you know what, I'm going to start this company, we're going to run this thing. And there's going to be more of that, because larger organizations are going to hire fewer software engineers, because they don't need them, because they're going to be working so much better and faster. And there's only so much, even if you were to double the size of the number of software engineers you have at, let's say, Google, it makes no sense, what are they going to do with twice as many? If that made sense they would do it, it's not because we have a shortage, and for a while we did, but now we don't, and we especially aren't going to in the future, because the AI coder is so much better. So going back to your critical thinking point, we need people who can understand the business, understand the process of writing secure code, engineering, architecting it, and making sure it gets implemented properly, and not relying on pure vibing it, it needs to be well made, and how do you do that professionally, with professionals who understand the entire process, and can leverage the great abilities of AI. But I think in terms of jobs, that gets pushed down and spread out over more, smaller businesses. We're going to see, we've already seen a one-person, hundred-million-dollar company, and we're going to see a handful of people making a billion-dollar company because of AI. So when you see a bunch of these, that's what we're going to see, and that creates so much value, so much that builds the entire economy. So I think people are going to have to start looking at being more entrepreneurial, joining smaller companies, more startups, and that's tough, because people go to school so they can get a good job so they can have stability, but I think that's a false sense of stability. I think for people, because at any point you can be fired from your job, so you have to have this financial stability, your own war chest of money, to be able to move from one job to the other, so it's a false sense of security anyway, and I think we need to educate people that it doesn't exist, your security is your personal savings and investments, and what you put aside, and the skills and abilities you bring to an organization. So now you can do that startup, because you've engineered your life to be able to do that, and you understand it's basically the same risk, it's just, are we going to be sprinting, or do I want to go to this big company where we can cruise? And I don't think you're going to be able to cruise along in a big company anymore, I think they're going to get meaner, leaner, and faster because of AI, and the people who are just coasting along, I think they're gone. I think that's what happens anyway, that's a lot, but that's my take.
Andrew Dutton: Yeah, man, so much cool stuff, we could talk for hours here. And it goes back to something you said, you're seeing that today, whereas the large gateway email companies, all of a sudden there are all these entrepreneurial companies doing it differently. The battleship is hard to turn, but the little PT boat is easy to steer down the river. But I think also, in the United States, we're a little unique in the fear, because one of the things, I'll just give you an example, healthcare, a hundred percent, how hard it is, how much it costs you for healthcare to start your own company, people are scared. And I think there are some basic, human things that aren't helping us become that thing, or, education, I live in a rural part of Tennessee, and I was involved with something they call Promise Keepers, where we go and help kids who are graduating high school. You might not know this, but in Tennessee you get two years of college for free, but most people aren't going to college, they're just going down to the local plant, because hey, they'll give you twenty-five dollars an hour to start, because they're not being taught, we're failing to teach our children, our kids and young youth, what they should be striving for.
Matthew Connor: Yeah, that goes back to social problems.
Andrew Dutton: Yeah.
Matthew Connor: Well then, and that's fun, that's interesting, because I think the convergence of AI and humans, it's a social problem, and our challenge is, how do we engineer our culture, our government, our country, to utilize this new technology in a way that benefits people, and our old method of every person for themselves when it comes to healthcare and everything, it doesn't work, it doesn't work in the new future, if you take that to the extreme, there'll be five multi-trillionaires and everybody else impoverished with their hands out taking whatever the government gives them, and I don't think that's the right solution for anyone. And fortunately I hope that's a long way off, and if the runway from where we are now to that AGI level is twenty or thirty years, imagine if all these kids coming out of school, the number of five- or ten-person companies making a billion dollars, imagine that's thousands of them now, thousands of billionaires, the amount of money they've created. So if we can get the kids to that level of, this is our future, and they start doing that over the next ten, twenty years, that's going to bring up everybody, except, going back to Tennessee and those places where we're failing kids, if we continue to fail them and they don't go out and see that, and they're working in the plant, that's tough, because that's a dead end. Yes, we need people to work in plants, obviously, but only for how many more years until the robots are doing it?
Andrew Dutton: Yeah. Or that's probably not your only path, like, what else have you thought about doing? But you're basically talking about creating this middle class, which we did after World War Two, and then since the late seventies we've eroded it, you could look at the data, we're not bringing the power to the people, we really need to bring that power, knowledge is power, power to the people. Now you've got it, though, even with your free version of ChatGPT, or Gemini, or Grok, you have godlike power when it comes to knowledge, compared to any other time in history. Having Google was awesome, and now this just blows Google away. And so we're democratizing it in a way, by giving that out for free and making it so accessible, that now what we have to do is get people to where, hey, talk to this genius you've got right there, and say, how do I, whatever, dream big, dream small, dream outside of the plant, outside of your town, tell me how do I get out of my hometown, how do I make a lot of money, how can I do this?
Matthew Connor: Yeah, or maybe, again, I wouldn't say how to make a lot of money, I'd say, you need to be happy, that's the first thing, what's going to make you happy? I always say I love this job, and it's true, I love this industry and everything, but there've been parts of my life and work where I just wasn't happy, and I was like, this isn't worth it, it's not worth it to me, number one is yourself, number two your family, number three, your company should... I'm sorry, but it's not my company, I do my job, I'm paid to do a job, and I do my job pretty well, I think.
Andrew Dutton: But yeah, man, these are some great things, that's such a great, well-balanced Gen Z perspective you have on work there.
Matthew Connor: But it's so accurate and true, right, I think, this is true, we could go on and on forever, but you look at the baby boomers and Gen Xers, and there's this "work is life" kind of perspective, like, yeah, I get it, that's how you take care of yourself and your family, that's very personal, and you spend most of your waking hours doing that, so that's really important, and then you want to have purpose and meaning, so you attach that to your job, and it makes perfect sense. However, the kids coming up see it all much more clearly, like, guys, that's a little messed up, what you're doing right there, you're giving your life to that company and they don't care about you. And you're like, oh well, that is true, it's hard to refute that, even though they're nice about it, at the end of the day, if it's not your company, it's not your company, you're a cog in somebody else's machine, which is fine, just don't lie to yourself about it, be really clear about it. And I love that the kids coming up are so clear about this, and they're like, look, I can use that to my advantage, I'm not going to let them use me to their advantage, and I think that's the healthy way to go about it.
Andrew Dutton: And just a snippet of that would be, I talked to some other professionals, and I'm like, dude, why don't you go to the conference, or why aren't you getting a certificate? My company doesn't, dude, you need to get a new job. Because if your company's not investing in you, or at least saying, hey, you want to go to this conference, we'll pay for the conference pass, and we'll give you whatever, but we're not going to pay for it, okay, I can kind of get that. But if they're not doing that at all, they're just not investing in you, they're just not. And sometimes that's the manager above you, the leader above you, who's trying to look good for the CFO. There are terrible leaders out there, oh my god, man, we could talk about that for a long time, because it might not be the company, it's the leadership that's in charge, or the leadership above them, there's so many things in that. But look out for yourself, and hopefully you're going to be passionate about what you do.
Matthew Connor: Words of wisdom, Andrew, I cannot thank you enough, this has been an absolute blast, I loved having you on, I think we covered some of my favorite topics, it's so interesting and fun. But before we go, can you tell everybody where they can find out more about you and more about Sumitomo Chemical Group Companies of the Americas?
Andrew Dutton: Oh, well, for me, it's just LinkedIn, hit me up, Andrew Dutton, I believe it's linkedin.com/in/awdutton, because I've been on there so long. I posted something today, I don't try to, I just try to get things out that I find interesting. There are some folks I like to follow, like Gary Marcus, and a few others. And for Sumitomo, you're probably not going to be looking this up, because you're probably not in the market for a truckload of chemicals, but if you are, you can find us online, that's where we're at.
Matthew Connor: That's awesome, Andrew, what a blast, thanks again for coming on, until next time, buddy.
Andrew Dutton: All right, thanks, peace.
Matthew Connor: Thanks.







