Techstrong TV - February 16, 2026
This Techstrong TV episode opens with host Alan Shimel welcoming Brian Dawson, director of product management for Linux at CIQ. Dawson traces CIQ's roots from founder Greg Kurtzer's work on CentOS and high performance computing for national labs to the creation of Rocky Linux, and lays out CIQ's thesis that general-purpose Linux takes significant engineering hours to tune for workloads such as security, container hosts and AI, so CIQ builds workload-specific variants that close most of that gap.
The security discussion moves from compliance checklists like SELinux, DISA STIG and NIST 800-171 to what Dawson calls proactive hardening: assuming attackers will get in and stopping them at the OS layer, because vulnerabilities across the open source ecosystem outpace typical remediation windows. He uses the BPFDoor malware behind the SK Telecom breach, which sat undetected in the kernel for five years, to show how the Linux Kernel Runtime Guard built into Rocky Linux from CIQ Hardened is meant to protect against unknown vulnerabilities and zero days.
Security leaders evaluating enterprise Linux get a concise case for hardening first. This page covers CIQ's segment, which opens the episode; the recording continues with unrelated Techstrong TV interviews.
Key takeaways
- CIQ founder Greg Kurtzer co-founded CentOS and started Rocky Linux within a week of CentOS being moved upstream as a testing bed.
- CIQ's thesis is that workload-specific Linux variants should close about 80 percent of the tuning gap, leaving teams to finish the bespoke 20 percent.
- Typical applications use around 200 open source components, with roughly 40 new vulnerabilities discovered daily and remediation taking 47 to more than 100 days.
- Proactive hardening means assuming attackers will get in and building protection into the OS layer rather than waiting for alerts and patching after the fact.
- BPFDoor hid in SK Telecom's kernel for five years; Dawson argues the Linux Kernel Runtime Guard in RLC Pro Hardened would have stopped it.
- The SK Telecom breach is estimated to have cost between 610 million and close to 900 million dollars for a single incident.
Questions this video answers
What does CIQ mean by proactive hardening in Rocky Linux?
Brian Dawson describes proactive hardening as going beyond compliance configuration such as SELinux and OpenSCAP playbooks to build protection into the OS itself. Instead of waiting for alerts and then patching, the foundational layer is designed to stop an attacker who gets in, covering CVEs that have not yet been identified or disclosed.
How would Rocky Linux from CIQ Hardened have helped against BPFDoor?
BPFDoor was a kernel-resident backdoor that stayed hidden in SK Telecom's systems for five years, inspecting packet traffic and activating when needed. Dawson says CIQ's testing indicates the Linux Kernel Runtime Guard, built into Rocky Linux from CIQ Hardened by Solar Designer, would likely have prevented the compromise, which cost an estimated 610 to 900 million dollars.
How did CIQ and Rocky Linux get started?
CIQ founder and CEO Greg Kurtzer co-founded CentOS and built HPC infrastructure for national labs, creating open source tools such as Apptainer and Warewulf along the way. When CentOS was shut down and moved upstream, he proposed a new project within a week, and the community named it Rocky after one of his late co-founders.
About this video
Broadcast on February 16, 2026. Securing Enterprise Linux: Brian Dawson of CIQ joins host Alan Shimel to explain how Rocky Linux is helping organizations strengthen security, compliance and infrastructure resilience. The full Techstrong TV episode carries several further interviews on other subjects, which are not covered here.
This video is part of the RLC Pro Hardened playlist. Browse every CIQ video by product and topic.
Transcript
Hey everyone, welcome to back here to Techstrong TV. You know, as I was saying before in the green room before we got on here versus the green wall that I use behind us in the studio, Brian Dawson has been doing videos on Techstrong. I think before there was a Techstrong, it was still just devops.com. >> And I'm happy to have him back. He's worn a lot of hats over the year. He'll tell you all about it. Well, let's welcome my friend Brian Dawson to Techstrong back to Techstrong TV. Brian, it's good to see you. How are you, man? >> Allan, good to see you as well.
Looking good. It's It's been a bit, but uh but yeah, always to see it. Like we go back to the early days of of uh DevOps um DevOps.com been great um to see Techstrong grow to what it is today. >> I mean, it's 12 years 12 years ago. >> Actually, next month it'll be 12 years. So crazy. Well, I want to be you when I grow up, Alan. I was gonna say you've done a great job. >> You don't want to be me. You be be the best Brian Dawson you can, and that'll be enough for this world, my friend. >> Okay, >> Bryant, give people, you know, I I said you've been around and and we know each other a long time, but give people a sense of kind of your career arc and kind of things you've done.
>> Yeah, I would love to share because I think it's it's somewhat been atypical, but I have a lot of pride in it. Um so you know I frankly uh started my career uh deciding I wanted to become a computer programmer so that I can uh build video games. I was able to be uh one of the first 100 people at Sony uh PlayStation or Sony Computer Entertainment of America. And uh and um you know that gave me um a great chance to learn about how you enable smart developers and smart teams to deliver technology literally from start to finish. I had the benefit of then uh moving forward and uh building out our tools and technology program for Sony Worldwide Studios um which led me to open source uh and developer tooling.
And then from there most of my career has been focused on kind of that underlying um substrate um that enables technology delivery um but then also with a particular focus on on open-source inner source reuse um and you know how do we efficiently sort of um capture the power of community to help us deliver software uh better faster and uh now we'll talk about more secure. >> Excellent. Love it. So, as I think people see under your name here on the screen, you're the director of product management for Linux at CIQ. Tell us well let's start with tell us about CIQ. There might be people out here who are not familiar with them and then tell us about you know what your role is here now with this title.
View full transcriptHide full transcript
>> Okay. Great. Great. And actually I'll segue from before. I saw a a fantastic fit or opportunity to come um join um CIQ cuz CIQ uh is not only uh built on open source and I'll tell that history in a minute. Uh they are focused on on emerging and leading edge technology starting with an HPC background and now sort of reframing and and revolutionizing Linux. So when I had an opportunity to come here uh about a year ago um I jumped on. And now to tell you a bit about CIQ, really cool story. Uh, so our CEO and founder, Greg Kurtzer, who I know you've had conversations with, is one of the co-founders of CentOS Linux.
Uh, which for those that don't know, eventually went under Red Hat. Um, and while he was, uh, prior to and while he was founding Linux, uh, he was building out performant compute infrastructure, uh, for high performance computing for our national labs. you know, the systems that power uh our cancer research, our simulations, our our weapons armory um and really what a lot of people are trying to adopt with AI um today.
Um after building that out and um delivering some I think really impactful open source technologies like like Apptainer uh uh Warewulf um uh he founded CIQ and CIQ has a focus on delivering modern infrastructure for the gener for the generation of AI or the AI generation and you know we believe that um both with um building widely adopted um um um open-source platforms like Linux as well as being able to scale high performance computing uh in real production environments that we're we're in a situation where we have the skills, knowledge and experience um to build the modern infrastructure that people need for the next age of compute.
Now there's another interesting story as we get um to Linux where I think we'll drill in. Um you know IBM bought CentOS. Um, CentOS was really kind of uh the developers real. It allowed you to learn uh enterprise Linux. It allowed you to deploy enterprise Linux in your dev and test environments without um high cost. Um eventually CentOS was sort of shut down and move upstream as Linux as sort of its testing bed. Um so developers lost their their their dev stage environment, their testing ground, learning ground. I think within a week of that happening, um Greg uh went to uh the channels and said, "Hey, um let's start a new CentOS." Immediately people responded.
They named it Rocky and owed to one of his co-founders who was no longer with us. Uh and uh and so that's CIQ and that brings me here with CIQ um today. Um I I will add as to kind of uh lean in one of the thesis we have here at CIQ is that uh while Linux is widely adopted uh general purpose Linux um takes significant full-time engineer hours risk and iteration to tune for purpose workloads like security like container hosts like AI and uh we believe it's our responsibility and contribution to the industry and the Linux community to sort of build workload specific variants that close out at least 80% of that gap.
Um, so that people just have to finish off the bespoke 20%. >> You know, it's funny. Uh, 199899 I'm helping build a company, an early ASP called Interlant. We went public in I think 2000. Um and and we learned that lesson in the ASP world. >> Interesting. >> 25 years ago that >> the ASP world application service provider. Yeah. And uh in that out of the box complex applications at best can do 80%. >> Right. >> You you always need to fine-tune the 20%. >> Yeah. >> And it here we are 25 years later hasn't changed. >> The same thing. Yeah. I mean, even in SAS, right?
Sales >> SAS is the same thing. Yeah. Yeah. You think you're just going to log in and you're good to go, >> right? >> What do you think all those Salesforce consultants are doing? But, you know, all you know, all that aside, Brian, Rocky Linux has made a name for itself as a secure, a hardened kernel, if you will, a hardened Linux OS. Um, and in today's world, you know, where the attack surface is multiplying, you know, every day with AI and now all of that that that it brings, what a what a good time to have a hardening, you know, a really hardened OS here and a and a not only just the OS itself, but the the packages, the whole process around it that you can, >> you know, have something you trust Um, you probably saw this week Claude Opus 4.6 came out.
>> Within a couple days, it found 600 vulnerabilities in open source code >> for decades, right? Some existed for decades. Yes. >> If that's not enough to scare your pants off, what is, right? I mean, >> it's enough to keep you up at night and and just I imagine that makes a good, >> you know, it's a good reason to take a look at Rocky. >> Yeah. Yeah. Well, and you know to to tell you a bit about our relationship to Rocky to to set the stage is so um Rocky is downstream of RE. It is uh free and open source run by uh the Rocky Enterprise Software Foundation or RSF >> and um >> what that does is that gives sort of enterprise Linux um stability and base security that people can access for free, right?
Replaces Centas. Um now what what we found is that um still to take that and harden it and for many people harden means compliant. It means I I configure SE Linux. I um I run some open scap uh playbooks like disastig or uh or NIST 800-171 acronym soup right to kind of harden my system to be compliant and pass audits. All right. Um so we did realize that people need help with that cuz that in itself yes is important and takes a lot of time right but as you said Allan um I think the statistic is uh uh most uh software applications use something like 200 open source components um there are roughly uh estimates of uh you know in the area of 40 new um um vulnerabilities be being discovered across the whole open source ecosystem.
system every day. Um, and the time to remediate those takes anywhere from 47 days to 100 plus days. In some cases, like for some of our fenthro entities, you never patch or remediate those, right? So, now we enter the discussion of proactive hardening, right? We take Rocky, we give you your compliance check box, but but your Claude Opus story is a perfect example. There are CVEes that haven't been that will be CVEEs that have not been identified or or exposed yet. How do you protect yourself against those? Right? And that is it right there. Right? In a world where you know there's a clawed opus every day, >> right?
>> Or someone's and and it's not just the good guys that are going to use it. You know, thank God it's the good guys that found these 600 vulnerabilities, but the bad guys are using it, too. Yeah. Well, >> and they'd be better. >> Yeah. And I well so um I hadn't looked at the latest uh 5.3 codeex yet but I was just reading news that open AAI as uh uh safety commission in California I believe it is feels they may be in violation of AI safety laws because they are the first ones to publicly release a model that has a high level risk because it is good enough that it can be easily used by bad actors to exploit systems.
So on that note, I just saw a flash come across my screen earlier that Anthropic announced something about that anthrop that Claude can be used for heinous crimes or something to that nature, which sounds similar to what you're talking about. >> Yeah. Yeah. >> And um look, they probably all can, Brian. I mean, you know, this is But when did people ever stop for security? It's full speed ahead here and the securityurities we're gonna have to play catchup as we always do. >> Yeah. And I think you know what you highlight um and I'm just preparing a couple of uh sort of things numbers I want to site but you highlight a key thing about um uh what is sweeping over technology especially in this AI age right is the technology sector and the technology space at this point is dictated by speed.
who can move the fastest, right? But what we are not necessarily doing and have not figured out is um how can we move faster and identifying security threats, protecting ourselves against those um um so we can stay ahead of the bad guys, right? So, how do we balance this fact that we have this wide attack surface, the attack rate is increasing at astounding rates? We're being told we need to ship yesterday. So, we don't have the privilege to sit down and button down all of the hatches. Well, you know what we believe um uh we you need to do is you need to practice what we call proactive hardening.
We no longer can um deploy a system and then sit and wait for alerts to bomb us and tell us that there's a potential risk. go out, evaluate that risk, analyze where it lives across our infrastructure, and then stop everything to go patch it, right? Um, what we need to be able to do is know that when we install this foundational piece of our infrastructure, that thing that lays beneath beneath um um our hardware, our compute, and the rest of our workloads, we need some level of assurance or protection that if somebody gets in, they're going to be stopped. And so that's what we're building with Rocky Linux uh from CIQ Harden.
This could have been a um uh I honestly say Al All and us having known as each other for a while. Uh I think this is going to turn out to be one of my prouder moments of my career being able to be part of the team that delivered this. >> You know what? We're going to come back to this day sometime in the future hopefully. >> Yes, >> Brian. And you'll say, "Hey, I told you I did. I would." And I did. >> Right. >> So, I I hope that happens. You know what? We're we're running a little low on time, but for people who want to get more information about CIQ, maybe even information about Rocky, I realize, you know, it's different, but where where can we send people to get smarter, Brian?
Oh, please send them to ciq.com. Um, and uh and uh you know, everybody go take a look at our resources and blogs in particular around some key vulnerabilities and how they're mitigated. uh if you're interested in rocking Linux from CIQ hardened and ensuring that you are protected against unknown vulnerabilities in zero days um or you just need to become compliant um uh reach out hit the contact us uh and and let's have a conversation. I I do Allan before I get the hook I want to call out as an example here there's a number of vulnerabilities one that recently in 2025 I think it hit around uh April May of last year was publicly disclosed is something called BPF door and many of us in the sector probably heard about the SK Telecom brief breach um there was a vulnerability that lived in SK Telecom's systems for 5 years undetected.
Where that thing lived and stayed resident was in the kernel and it was able to sort of activate when needed for BPF door, inspect that P packet traffic um and take actions. Um we did some investigations, we did some tests. I have them running on my system now. And this is a case where if uh five years ago SK Telecom had installed the Linux kernel runtime guard that our own solar designer builds into Rocky Lance from CIQ hardened, chances are they never would have been affected by uh BPF Door. And and just to drive home the importance of that, not only was a bunch of personally identifiable information compromised, um estimates for what that cost was for Estee Telecom are somewhere between $610 million and close to $900 million um just for that single breach alone.
>> So So there's value here. >> Agreed. Agreed. Brian, hey man, it's great to have you back on here. come back and visit us again soon. Keep us posted. Okay. >> Okay. Thank you, Alan. It's great to see you again. >> Great to see you. Brian Dawson, director of product management Linux at CIQ talking about you. If you're looking for real hardened systems, especially hard and rocky Linux system, ciq.com. Brian, we'll see you soon. That's it for Techstrong TV.
Built for scale. Chosen by the world’s best.
2.75M+
Rocky Linux instances
Being used world wide
90%
Of fortune 100 companies
Use CIQ supported technologies
250k
Avg. monthly downloads
Rocky Linux
9
Enterprise products
Spanning the kernel to the orchestrator
Have questions about your infrastructure?
Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.
