Rethinking the Endpoint – IGEL Spotlight on Technology
If most of your applications no longer run on the endpoint, why are you still managing and securing it as though they do?
Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this Spotlight on Technology episode I'm joined by James Millington, Healthcare Field CTO for EMEA at IGEL, with more than 25 years' experience across virtual desktops, endpoint security and healthcare technology.
The way we use endpoints has changed repeatedly. Computing moved from centralised mainframes to PCs, back towards virtual desktops and then into SaaS and cloud services. Hybrid working accelerated that shift again, while rising hardware costs, Windows upgrades and increasingly distributed workforces are forcing organisations to reconsider what they actually need sitting on a user's device.
Jim and James look at why the endpoint may be due another rethink. They discuss the security and cost implications of maintaining traditional operating systems, how immutable endpoints change the approach to endpoint protection and what happens as AI creates another generation of applications and risks for security teams to control.
Three key talking points:
- Do we still need Windows at the endpoint? As applications move into SaaS, VDI and the cloud, the role of the endpoint is changing. We look at whether organisations still need a full traditional operating system on every device and what alternatives become possible when workloads run somewhere else.
- Moving from detection to prevention Endpoint security has traditionally relied heavily on detecting problems and responding to them. Discover how reducing what can run or change on an endpoint alters that model and removes attack surfaces before they need to be monitored.
- The endpoint problem AI could make worse Shadow AI gives employees another way to introduce software and move information beyond organisational controls. We discuss how controlling what can execute locally could become increasingly important as AI workloads start moving from centralised services onto endpoints.
If you're reviewing your endpoint strategy, facing another expensive hardware refresh or considering how AI changes what employees should be allowed to run locally, this conversation is for you.
On rethinking the endpoint:
“Really, what are my users accessing and where are they accessing it? And is it time to rethink that endpoint?”
James Millington
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
In this episode, we covered the following topics:
- The Cycle of Centralised Computing From mainframes and PCs to VDI, SaaS and cloud services, computing keeps moving between the endpoint and the data centre. Explore why that cycle matters to today's endpoint strategy.
- Why VDI Never Really Went Away VDI has moved in and out of fashion for decades. Find out why healthcare remained a strong use case and how remote and hybrid working changed the conversation again.
- Rethinking the Windows Endpoint If applications and data increasingly live elsewhere, does every employee still need a conventional Windows environment? We discuss what organisations should consider.
- The Cost of Hardware Refreshes Rising hardware costs and Windows upgrade requirements are putting endpoint budgets under pressure. Discover why extending device life is becoming more attractive.
- Security by Design Explore how an immutable operating system changes endpoint security by restricting what can be altered or installed rather than relying solely on detecting problems afterwards.
- Protecting Data in Distributed Healthcare Healthcare is moving closer to patients, creating more distributed endpoints. We discuss why keeping sensitive information off those devices can reduce the consequences of loss or theft.
- Moving Beyond BYOD Some organisations are reconsidering bring your own device programmes. Find out why greater control and standardisation are coming back into the conversation.
- Controlling Shadow AI As employees experiment with AI applications, organisations need to decide what can run locally. We explore how endpoint controls can limit unauthorised workloads.
- AI Comes Back to the Endpoint AI started heavily centralised but cost and performance are driving some workloads towards local devices. Discover what this latest shift could mean for endpoint security.
Resources Mentioned
Microsoft Azure Virtual Desktop
HIPAA and Cloud Computing Guidance
Connect with your host James Rees
Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.
If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
LinkedIn: Razorthorn Security
YouTube: Razorthorn Security
TikTok: Razorwire Podcast
Instagram: Razorwire Podcast
Twitter: @RazorThornLTD
All rights reserved. © Razorthorn Security LTD 2025
Transcript
So, in order to discuss this wonderful area of security and technology, to a certain extent, that has definitely evolved over time, and we've kind of come full circle in it, I have one of the best people to come and speak to us from one of the best companies who represent this space at the moment. James Millington from IGEL. Now, James, do you want to tell everybody out there a little bit about yourself, a little bit about your background, who you are, that kind of thing?
James Millington [:Thanks, Jim, and thanks for having me onto the show. So yeah, James Millington. I am the healthcare field CTO for EMEA for IGEL. I have been in and around the virtual desktop and security space for about the last 26 years, spent a decade at Citrix, spent 8 years at VMware, 4 years at Improvata, very closely tied to the healthcare workflows and how care providers access patient information at the point of care, making sure they can get the access and information they need. And then I have been at iGel for almost the last 3 years running product marketing and now into the healthcare field CTO role.
Jim [:Fantastic. Welcome, welcome to the channel. So being a bit of an old-timer, and dare I say it, you've, you've seen a few of the technological shifts that we've gone through in the last sort of 20, 30 years. There's a long history of kind of virtualization and secure desktops and the way things have gone. I mean, it all started very much with kind of mainframes and terminals back in the day. You know, you'd have your mainframe, which was the size of a football field somewhere, you know, and quite quickly, people realised that sending somebody in to sort of play around with the mainframe in the actual room was rather problematic. So they created these thin clients to be able to access that particular technology. And I mean, this is before my time, so this was a long time ago.
Jim [:But then the PC came along and started to change everything. You know, we started to get Windows, and then shortly afterwards, we got Linux. And we started to see that a lot of technology was being installed. And I had to do this back in the day on the actual machines themselves. And when I worked in reinsurance in my early days, I'd used to have to install massive databases on individual machines, and it would take literally an hour and a half per database, and they were huge as well. But, you know, it became a bit of a problem with endpoint and security because each of these machines had their own operating systems. There was no central way of managing them. It was certainly good fun.
Jim [:I mean, I take it that was your entry into technology back in the day as well?
James Millington [:Yeah, I mean, I suppose actually I started my career in antivirus, which back in 1996 was a fun space to be when it really was kids in their bedrooms and trying to work out what was the identity of the Dark Avenger. And then I went to work for for Citrix in 2000.
Jim [:Citrix, yeah, yeah, I remember them. They were, they were the first real ones, weren't they? They were, they came along and it, I mean, it took the world by storm.
James Millington [:Yeah, they, they kind of invented the, the whole multi-win concept. I mean, it was based off OS/2 to begin with, um, but then worked with Microsoft, did the whole, uh, multi-win licenced, uh, code to Microsoft, which, uh, was essentially the basis of terminal services. And then the technology and the use cases grew from there. And I'll almost certainly come back to healthcare a number of times during this conversation because around virtual desktops, it's frankly the best use case for virtual desktops and application virtualization that I've seen. The epic EMR/EPR solution was a huge piece of client software. And they and Citrix worked out very early on that actually virtualizing the Epic application, centralising it, taking it away from all the clinical endpoints where it was really difficult to go and update it locally, putting all of this inside a Citrix and terminal server type session, updating the huge piece of client software once in the data centre and having everybody securely access it remotely was a much more efficient way of care providers being able to access the software and the IT guys being able to distribute it and secure it. So that was a great use case, and we still see VDI and app virtualization used throughout healthcare. You know, Cerner, now Oracle, is— that was always distributed by Citrix, Epic.
James Millington [:But we're seeing the shift now to web-based applications. But it's still that fundamental theory of don't put all the patient information on the endpoint. keep it secure in the data centre. That's that fundamental premise of all of this.
Jim [:That's— I mean, I totally agree. I mean, back in the day when Citrix first came out, everybody wanted it, and it was everywhere, you know, and it was fantastic because, as you say, you could have a standard template, you know, people would log into the standard template, you know, it was easier to maintain than the millions of different endpoints where you had AV all over those endpoints. And if somebody misconfigured something. I mean, you gotta remember, you know, to those of you who are sort of slightly younger, we had a lot less tooling back then to be able to manage our endpoints. It was done in a very haphazard way. I mean, the tooling available now to be able to do it is eminently better than it was back then. I mean, you know, and it was little things like having to go out, you know, you'd have different departments with different setups as well, you know, and quite often you'd have to go out. And I remember ghosting machines, you know, with specific builds for those specific departments.
Jim [:And when Citrix came along, you know, it was easy. We just kind of built another template, gave them access to the template, boom, they'd just log into it, do their work. It was a bit clunky in the early days, but then as our kind of comms got better and the speed of our comms got better, we were able to apply it to people who were working remotely as well, you know, I mean, now it just seems normal, but you've got to remember back then our comms wasn't quite as fast as it is now.
James Millington [:Yeah, that was always the limiting factor. It was on that connection from the endpoint. And so you're right, when it was dial-up modems, that was a lot more difficult to try and deliver that desktop experience to a remote user. Much more of a challenge. And, you know, that central connection is still somewhat of a challenge in certain use cases. And there's always the execs that they get on planes, trains, and automobiles, and having that connectivity can be a challenge. VDI was never a one-size-fits-all. It depends on the use case, it depends on the user, and you have to look at the realistic requirements and see where it will fit.
James Millington [:But without a doubt, I mean, everything, everybody needs an internet connection now.
Jim [:Yeah.
James Millington [:And everybody needs a well-performing internet connection, which certainly improves the range of use cases that you can use application desktop virtualization and deliver those benefits with it.
Jim [:As big as Citrix was back in the day, and I mean, it was a time where everybody really had desktops. It was only like the executives that had the laptops who could like travel back and forth. But then everybody started getting laptops, you know, technology got cheaper. So you ended up with everybody going back to these endpoints. Citrix was still there, it was still quite popular in certain use cases, like with healthcare, and especially journalists, for instance, you know, out in the field, that kind of stuff. And it seemed to be that the VDI just kind of died off a tad because laptops were just so cheap and powerful.
James Millington [:Yeah, it's true. And it's that, it's this constant— I mean, I remember Mark Templeton, who was the the CEO of Citrix back in the day. Many of his keynotes at the annual events would show the— first of all, we centralised everything with the mainframe, like you said, and then we distributed everything to the endpoint, and then we centralised everything again, and then we distributed it again, and then we centralised over and over and over again. If you look at the conversation that's happening with AI and where AI is running today, It's all centralised and now we're talking about, well, the high cost of the token. So can we decentralise it and start running it on the endpoint? Over and over again, we go through this cycle. So yeah, it did exactly that. And there was the whole conversation around GPUs and—
Jim [:Yeah.
James Millington [:Well, if we put expensive GPUs into VDI and then we can use them for high-powered workstations, and then everybody realised that putting GPUs into servers was actually really, really expensive. And you've got all the endpoints with all of this processing power. And so both VMware and Citrix spent a lot of time writing the clients so that the software could make use of the local GPUs. And yeah, it's in, out, in, out. That's pretty much the way that we've developed.
Jim [:It's like Ouroboros swallowing its own tail. You know, everything goes in a cycle because when we had that laptop revolution, we then suddenly got virtualization. You know, and my 15 racks of servers suddenly became like 2, you know, which really changed everything. And virtualization of that estate, it kind of brought VDI back to a certain extent. As you say, it kept going in and out again. And then we had SaaS that suddenly changed everything as well. You know, all of a sudden, everybody's using SaaS, everybody's moving their solutions out. Fast forward to these days, I think the subscription model has become such a pain in the You know what, because now everyone's gone to that kind of model.
Jim [:But, you know, there was that beautiful piece of time where the laptops were cheap enough that you could just, you know, one broke, you just replaced it. You could send one out, they just, you know, put the client on there, they log into the client and boom, they had the desktop back. You know, there was no problems and there was all kinds of different ways you could handle it. Virtualization started to make technology significantly cheap. I remember, along with a lot of others, trying to pull out an old ProLite Exchange server, and it took 4 of us to pull the thing out. And God help you if it landed on your foot, that was it. You know, the technology advanced, everything started to centralise, and we could run 15 servers on just one piece of kit, you know.
James Millington [:Yeah, VMware transformed the data centre.
Jim [:It did. It did. And that was kind of the same for many, many years. Then COVID happened. All of a sudden, everybody got sent back home. It was a very dark time. And virtualized desktops were suddenly back on the scene of people talking because you couldn't get kit, in some cases, out to people fast enough. You needed your users to be able to, or your employees rather, we call them users back in the day, but employees working again.
Jim [:And we suddenly saw a dramatic change and rise. You know, comms companies, for instance, had a fantastic time during that period upgrading everybody's comms and what have you to be able to cope with it. And centralization just sped up along with the SaaS side of things because people just needed to be able to do the work that they were doing. Is that fair to say?
James Millington [:Yeah, in the kind of the VDI groups, for years there had been the running joke of the year of VDI, which I think Brian Madden coined that. Yes, this year will be the year of VDI where everybody acknowledges the benefits and sees the benefits of centralising all your information, securing your data, managing those Windows VMs centrally and securing them. This will be the year. And then— Suddenly COVID happened and it really was the year of VDI. Everybody sent people down to Currys to go and buy whatever they had. And if you've ever tried to buy anything at Currys, that in itself takes a while. So trying to get them, and then how do you manage this? How do you secure it? Back to the, what was it, you know, the AV discussion, which by this point has changed unrecognizably to what it was in 1998. But yeah, how do you secure all this information? How do you manage what is now a completely random set of endpoints?
Jim [:Yeah.
James Millington [:It's not as if everybody even had a single model from a single vendor with a nice Windows profile that would secure it and lock it. There was random endpoints. So yeah, VDI became very quickly a way to be able to securely deliver the data to users anywhere. And the whole high hybrid model then that followed on where you didn't know where the user could be. So again, providing a consistent way for them to access information securely in a time where the bad guys are dominating the headlines with whichever breach has happened this week. And again, patient information being that thing that you can't get back if Bad guy steals your money, a lot of the time the credit card companies will refund that or will work with you on it. If it's your health information that goes out there and the bad guy's trying to blackmail you to pay money for your personal health information, or it's going on the web, you cannot get that back. There is no coming back from that.
Jim [:The amount of attacks when I think the malicious actors realised that people were kind of pretty much jury-rigging their IT together in order to to cater for a time period where, as you said, you know, you couldn't get laptops out fast enough. And even then, where did you send them to get them centrally built so they could work? And if they didn't work, then how would you like support that? And it turned out that, as you say, VDI really came back and it was like, right, we're going to have to do this because they're running on their home technical kit. So the, you know, the home routers, which we can't secure, we don't know what they're doing. We don't know anything about them. You know, every— let's be honest, the main market routers are not exactly as secure as they sometimes let themselves known to be. It's just not possible. I mean, PCI DSS was also another big turning point, I think, for secure desktopping as well, because especially in that time period, because your call centre agents could be anywhere. And of course, PCI is very, very specific about your environment and your scope and all the rest of it.
Jim [:And as a QSA myself, You know, I was just sitting there looking at it, thinking, Jesus, how's this gonna work? You know?
James Millington [:Right.
Jim [:We need to be able to build our secure endpoints. And of course, there was all this, there's been this kind of low-grade hum up until that year where we weren't allowed to go into the office, is probably the best way to describe it. Everybody wanted to bring your own devices. They didn't wanna have the machine from their organisation. And the other thing is, The organisation started realising as well, we can reduce some of our spend on our technology. We don't have to send laptops out now. We just give them a port to be able to access and then access their desktop.
James Millington [:Yeah, that's a really interesting discussion. We're actually just seeing the tail end of that whole BYOD movement, where in some of the big financial companies that we work with, They're looking at that and going, hang on, why are we doing this? Why are we trying to manage all of this vast estate of, again, mixed— we're not doing that anymore. And they're shutting down all the BYO programmes and just giving a standard secure endpoint out to anybody that needs it. So it's interesting that you bring that up because it's like I said, we've just seen that tail end of it.
Jim [:There's a whole new set of revolutions that we're seeing. I mean, you mentioned hybrid working. You know, we're seeing a lot more fractional roles. You know, we're now moving into a time, you know, let's move towards the more modern time period. We've talked a lot about history. We've got all this kind of AI revolution going on. It's moving so fast now, we can't deal with it. And the knock-on effect that I think a lot of organisations are starting to feel the pain with is the fact that, my God, laptop prices, any kind of computer prices have been jacked up times 2.
Jim [:So trying to look after your estate, if you have breakages or whatever, it can get really, really expensive. And I think, you know, again, hybrid workers as well. You've got fractional people. I know people who operate out the Caribbean, very lucky people. They work in various different places around the world. They don't tend to go into the office anymore. And, you know, we are being driven towards a more VDI sort of world, um, and we have been for some time. I think there's been a bit of resistance But I think the thing that's really clinched it is just the cost of replacing laptops.
Jim [:I was looking at a few for us the other day, and I nearly spat my coffee over the monitor. It was so bloody expensive.
James Millington [:Yeah, it's not a good time to be refreshing your hardware. And there's a lot of organisations out there that a year ago, looking at the Windows 10, Windows 11 refresh said, I don't have the hardware budget to do the whole refresh of hardware, and I'm going to pay the extra year for the long-term support for Windows 10, thinking they'll get budget and they'll do it this year. You come to this year and now the cost—
Jim [:It's worse.
James Millington [:The cost for the support has doubled. And the cost of the hardware has doubled. And a lot of organisations are in a very tricky situation. And it's not just VDI anymore. A lot of organisations have moved Windows applications into the data centre, and rightly so, for all the good reasons of VDI. But so many organisations now have moved to SaaS applications, so they've left Windows— some, it's like I said, it's never one size fits all. But we're seeing a certain set of users that will be just using SaaS, which there's still an analogy there to the VDI days and the app virtualization days of the workloads not running on the endpoint, the workloads running somewhere else. So you can rethink what you need at the client in order to access those resources.
James Millington [:So the reason I came to IGEL was that I had— I was working for an Israeli cybersecurity startup. in the OT security space. They were about 6 years old at the time, born in the cloud. They didn't have a single Windows application, no VDI, no DaaS, no Windows application, everything SaaS applications from Salesforce through Jira, Adobe Cloud, everything was SaaS-based. And I had a good friend of mine that was working at IGEL at the time and said, hey, come talk to IGEL. And at the time I was like, well, VDI thin clients, I don't know if I want to go back there. And then I looked at what this organisation was doing and thought, oh, hang on, this could be an IGEL endpoint that's securely accessing all of these SaaS applications. And they will get all of the benefits of IGEL of make your hardware last twice as long.
James Millington [:You don't need a security stack on here because it's secure by design. It's cheaper, it's more secure. Hang on, this, this could be really interesting. And that's why I came. And that's what we're seeing in a lot of organisations. The number of conversations we have with, with customers or potential customers where they're looking at their, their VDI environment and there's been a lot of changes recently and pricing changes and they're saying, well, hang on, we've got 60% of our users who only access the VDI desktop to launch a browser. Could they just do that directly from the IGEL endpoint? And the answer is yes, absolutely. It's fundamentally, if you're not running your Windows workloads at your endpoint for whatever reason, you've moved off Windows or you've put Windows in the data centre, you don't need to run Windows at the endpoint.
James Millington [:It's an expensive way, and particularly with, like I said, the cost now of updating the endpoint hardware. I think it's really a time for organisations to take a close look at what they're actually doing from the endpoint and whether there is a better way than just relying on the old way of doing an endpoint operating system.
Jim [:You make some really good points there. And it is something that weirdly enough I've been noticing as well. And I want to go back to the operating system side of things just briefly. I'm seeing a massive rebellion now with people in general, the public, businesses, organisations, government institutions about running Windows 11 at all. You know, it's such a terribly bloated operating system. There's so many security vulnerabilities and problems, and they've done some real howlers with patching recently. It's reached a point where You know, the Microsoft licencing is— I don't even really understand how it works half the time. And a lot of people are starting to look at other options.
Jim [:They want to go to kind of like Linux, for instance, on the desktop, but they still want to be able to access some of the solutions that they need to access securely and so on and so forth. And I think that we're migrating back again to that central point that IGEL provides so brilliantly that is secure by design because it's based off Linux, isn't it?
James Millington [:Yeah, yeah, fundamentally, which scares people. Oh, hang on, isn't that really technical and the user interface doesn't make any sense and I have to be able to command line drive everything? No, not anymore.
Jim [:No.
James Millington [:There's essentially a Start window in the bottom left. There's a task tray that has all of your icons for your Bluetooth and your monitor and your sound. it looks like an environment that you are used to using.
Jim [:Yeah, absolutely. And you're not tied down with the, you know, Windows 11 bloating the hell and killing your machines. You know, you can have that Linux desktop and you just access IGEL. You know, the other good thing with IGEL, and I will point this out, and I have to get clarification on this one because I haven't checked this one. I myself moved over to Linux Mint. I had enough of Windows 11. It just, my laptop was blue screening or black screening all the time. So I thought, no, I'm going to give Linux Mint a go.
Jim [:And I moved over to Linux Mint. And I had wonderful issues with the fact that I had to use everything through a browser because, you know, Teams and everything. But on IGEL, you actually have got it work. You've got Office working, haven't you?
James Millington [:Yeah. So this is one of the areas—
Jim [:I have to ask how.
James Millington [:It's one of the areas that we've spent a lot of time and is really one of the differentiators is the different types of workloads that you can run at the endpoint. We're a huge Microsoft partner and we work very, very closely with them and we're not anti-Windows at all. We just, you know, it should be run in the data centre, Windows 365 on AVD, on Citrix, on Omnisur. But at the endpoint, you still need to give users choice in the types of workloads that they're using. So when it comes to Office and G Suite and similar applications, Microsoft created something called a progressive web app, which is part kind of a local install and client, but mostly connecting off to the Office 365 applications. So as a user just on a desktop, if you don't want to have, or your organisation has said we're not going to provide VDI or DaaS, you can still have that native feeling Office 365. And I know it's not like for like, but it is going to, it's going to continue to get better and better. But we also have, you know, we work very closely.
James Millington [:We have something called Nigel Ready. programme, which is our partner. We partner with the likes of Palo Alto and Zscaler and CrowdStrike. There are 120 organisations that are in this programme to provide things like— with Zscaler, we provide the Zscaler Client Connector. If you're using a SASE environment to protect all of your upstream infrastructure, we can give you the native client developed with Zscaler that's going to put you directly into that SASE environment to give you secure application access. And one of the things that we bring here, or one of our beliefs, is if you move to SASE as a way of essentially removing your enterprise footprint from the internet, reduce— getting rid of all of the VPNs and just having the single point of access in. That's fine if you've got a single point of access, but the trouble with Windows at the endpoint is you have to secure it. You have to put in a very expensive security stack.
James Millington [:It is a 64-gig operating system versus a 1.5-gig operating system, which IGEL is. So to your point of, you know, you've got to patch that. Gartner put out a paper in February talked about utilising Workspace Immutable Secure Endpoints, or WISE, as they called it, which I wish they hadn't used WISE as the acronym. If you've been around the VDI world for a while, you'd know why. In their research, they said at any point, 1 in 5 Windows endpoints has drifted out of compliance. So at any point, 20% of your Windows endpoints aren't compliant to the security stack that you've put on there.
Jim [:Mm-hmm.
James Millington [:If you utilise an IGEL endpoint, first, it's much, much smaller to patch. And yes, you will still have to patch, but it's much smaller. It's much quicker to get that patch down to the environment because the IGEL OS is only a fraction of the size and is only doing what it needs to get the user access to the resources, it's much, much smaller, which means that hardware can last twice as long. We have customers that are using 10-year-old hardware. Now, I wouldn't recommend that for doing Teams and Zoom calls, but for certain use cases, it can still be supported. So to your point on the chip shortage, the costs that are really impacting organisations and having to move budget from modernization to other business projects, to just keeping the lights on at the endpoint. There's a real benefit again in looking at, could we be doing something differently? Really, what are my users accessing and where are they accessing it? And is it time to rethink that endpoint?
Jim [:No, absolutely. I mean, you also get the other side of the fence as well when it comes to things like data residency, you know, centralization of you know, app management and so on and so forth. You know, somebody steals the localised desktop, well, that's great. You know, there's— at the moment, if they steal a desktop, then if you're really unlucky and people really haven't secured themselves, they just access it and grab hold of whatever data has been pulled off of OneDrive. Whereas, you know, with something like IGEL, you just can't get in. You won't be able to get into that solution.
James Millington [:Yeah, it's a critical part in healthcare.
Jim [:There's a lot of theft in healthcare.
James Millington [:A lot of Yeah, and the way that healthcare is now organising, so in the UK with the NHS England 10-year plan, that is distributing healthcare, i.e., making it easy for patients to access a point of care, to be able to physically go in and make it easy for them to be able to go and visit a nurse or a doctor. So we've seen this play out in the US since about 2009. And again, that was very distributed healthcare.
Jim [:Right.
James Millington [:So move a lot of the contact points out the hospital and in the shopping centres set up clinics. So when people are out and about, it's easy for them to be able to get a taxi and go see a care provider. Well, in the UK, we're seeing that as well. And that's fantastic, making healthcare more accessible. But that means in today's digitised healthcare, you've got to put workstations, endpoints, infrastructure into these distributed locations in order for the care providers to be able to access the information. And as you say, that leads to higher chance of these laptops being lost and stolen, and you cannot have healthcare information on.
Jim [:Absolutely.
James Millington [:In the US with the HIPAA compliance, if you have a breach that impacts more than 500 patients, you have to publicly disclose that information. So if somebody has a laptop stolen and it's a Windows laptop, you have to do a full forensic investigation as to whether the care provider downloaded information onto that endpoint. With IGEL, you cannot do that. There is no local data persistence. So laptop gets stolen, there is no forensic analysis that needs to be done. It is simply there was no patient information there. Let's move on. So as we see this distribution of healthcare, as we see this get it closer to the patient, then again, rethinking the endpoint is beneficial, not only in terms of it's better for your security, it's better for your confidentiality, it's better for your manageability, it's better for your budget.
James Millington [:So this is why we're seeing a lot of organisations that are now looking at moving to an IGEL environment.
Jim [:Well, I think it's going to get a hell of a lot more more popular going forward. I mean, you know, again, I'm springing this one on you, but I was, I was thinking, you know, in the lead-up to this over the last couple of days about other aspects of, of IGEL that could be really, really beneficial for the world of tomorrow. The world of tomorrow! Which is the fact that we're, we're getting, we're seeing more and more people seeing, uh, breaches and problems with kind of AI agents, shadow AI, and that kind of stuff. the local sort of endpoint, and people pushing out data where they shouldn't do via, you know, their connections through to whatever large language model solution that they're favouring at that time. You know, with IGEL, for instance, I'm guessing that's now a situation where, obviously, you know, it's not running locally, nobody can access, you know, stuff that they shouldn't be able to access. And I can see there being, a significant shift towards that kind of solution and the kind of solution that IGEL is performing. Is that fair to say, or am I talking complete horse shit?
James Millington [:No, you're right on. I mean, the whole Shadow AI, we have 3 fundamental components. We have the OS itself, the immutable operating system. We have that management console, UMS, and we have an app portal. So the app portal has applications from all of these partners. And what means is that the IT admin has full control over the endpoint by default. There's only workloads from the app portal that can be pushed down, managed by the administrator through the UMS down to the endpoint. So it's tried and tested secure workloads.
James Millington [:So the shadow AI of users trying to install whichever local application or even LLM it goes away. Users just cannot do it. And we're working with, so we have, for example, we have the Ollama AI model in the app portal that organisations can put down to the IGEL endpoint. So the admin has control over the AI engine that is gonna be run at the endpoint. And we're continuing to work with the AI vendors as Again, this is where we're seeing this. Everything's gonna run centrally, all the models. No, it's too expensive. Let's have them work at the endpoint.
James Millington [:So there's still a lot of work happening. You saw with OpenAI, they created the Codex model to install at the endpoint. Then they've kind of merged Codex and Chat as now one chat client. Claude, of course, with Claude Code and Claude Work. So there's still a lot changing.
Jim [:Yeah.
James Millington [:around this, but it's conversations that we are having with them to enable organisations to run AI workloads, but with this guardrail of securing the execution environment at the endpoint by default with what we term a preventative security model, so that where the model is running is in a secure space. So yeah, you were right on.
Jim [:Always nice to know. Um, but I mean, you know, I, I think it's— I think this kind of solution is going to be rather critical going forward. I mean, for a while now I've been seeing that we need to change our defence in depth, and we need to change it rather dramatically. Um, you know, there's certain things out there that are starting to happen. I mean, gone are the days where you can sling on a bit of EDR, hope it all goes well, you know, bit of email security. We're starting to see, like, just— I mean, let's talk about, you know, one particular aspect, obviously nothing to do with IGEL, but, you know, deepfakes. You know, no one's looking at deepfakes at the moment. Um, nobody's— we've had situations where entire boards of directors have been deepfaked and convinced an actual finance director to part with, what was it, £25 million? You know, this is signalling, and I think, you know, again, dare I say it, as young as you are.
James Millington [:Thank you.
Jim [:We've seen technological change, and with technological change comes the inevitable need for revisiting security and defence in depth. Back in the day, you know, you and I were the AV people. We wandered around and made sure AV was on the machines, and we had a— I mean, you know, even in the early days, we had a very simple central server, or not even at all, and we would look at the results of what was going on. Well, things have moved on now. You know, AI is a problem. Data residency is a problem. Uh, sovereign AI is another one entirely. I've got a whole podcast full of that.
Jim [:And one of the things that I think, along with deepfake detection and kernel-level security, much better kernel-level security, is the need for something like iGel, because it's the only way you're going to be able to you know, in many cases, especially with a very hybrid and diversely sort of like allocated workforce, be able to provide adequate levels of security into the organisation that you can control. You know, there's an old terminology in security, you know, trust is good, but control is better. And now that we can't really trust what's going on at the endpoint, we have to start looking at more controlling factors. Is that fair to say? I mean, we're in the last couple of minutes of our interactions, which I have enjoyed. So, you know, please feel free, your final thoughts on where things are going. Am I talking rubbish or?
James Millington [:No, I think this is fundamental to our approach, which is that the model of monitor, detect, remediate is not working. And you just have to look at the headlines and it's costing organisations millions, if not billions of dollars. Our approach is prevention rather than fixing after, after the fact. So it is removing a lot of the attack surfaces that are used by the bad guys. It's removing the, the mutable aspects. You know, Windows was designed over 30, 40 years to be whatever somebody needed it to be. Whether that is the platform for your mum to have the video conference with you, to whoever it is that's designing the latest AI engine and model and everything in between, which is all good. But that model of having the operating system be able to be changed to suit what the user needs is opening up all of these attack surfaces to the bad guys.
James Millington [:So where you don't need that, That's where the IGEL preventative security model removes those attack surfaces that just aren't necessary for the way that end users are accessing their applications. Let's put in something that is secure by design, this immutable approach, as Gartner calls it, and let's look at how the users actually are accessing their applications and provide them with an infrastructure that's going to give them the best user experience while removing a lot of the security headaches and reducing the cost. The costs. So yeah, that's where we work with organisations. And when we have this discussion over what they're actually doing, it becomes a very clear answer for how they can move forward and remove a lot of the challenges.
Jim [:I agree. I think it's the way forward. And, you know, to all of you guys out there who are sitting there thinking, oh, you know, what do I do with all of this? Where do I go from here? Seriously consider iGel. you know, and have a look at what they're doing. It's really, really good. I was really impressed, hence why they're on the Spotlight on Technology here. James, if people want to find out a little bit more about IGEL, where do they go? If they want to contact you, how do they contact you? Obviously, I don't want you to give out your email address because you'll get spammed to buggery, but—
James Millington [:Certainly take a look at the, you know, it's the obvious things. It's the IGEL website. Every year. In February, we'll be doing our big user conference in Miami. It has all of the major end-user compute players. It's really become the industry EUC event. So take a look at that. On the website, we've got all of the sessions from the last event that we had in Miami in April.
James Millington [:So not too old. You can see all of the the conference event there. So yeah, go take a look and certainly reach out to us through the website for any more information. I'm sure you can find me on LinkedIn. I'm sure it won't be too difficult to find me if you want to.
Jim [:Fantastic. And to all of you guys out there, guys and gals out there who have been supporting the channel, I mean, you know, we're over 1.1, 1.2 million views now. Thank you ever so much for your support. Please feel free to click that subscribe button though. So few people these days click that subscribe button, but it means a lot to us and, you know, it helps us with the algorithm, which is going through changes. Again, like and subscribe as well. It really, really helps. And if you do want us to talk about this, maybe you want to get us to get James back in to talk about something specific around some of the challenges that you guys are facing that you think iGel might be able to help out with, Just get in touch with us.
Jim [:Uh, there's multiple ways to do it, you know how, and we'll try to get that sorted. But for the moment, this is the, the end of our time together, James. Thank you ever so much for coming and having a chat with us. It's, it's good to talk about the old time and talk about where we're going, because as I said, it's all about the serpent chasing its, you know, eating its own tail. It just comes around again and again and again.
James Millington [:It does. Thanks, Jim. Honour and a pleasure. Thank you.
Jim [:And to all of you out there, have a great time. Speak to you again soon.
James Millington [:Thank you.