This event has ended. Infotech IGNITE Washington D.C. is no longer accepting registrations.

Conference

Infotech IGNITE Washington D.C.

Part of Info-Tech Research Group's regional IGNITE conference series, bringing IT leadership research and peer discussion to Washington, D.C.

Recapping Infotech IGNITE Washington D.C. 2026

BlueCat was in Washington, D.C. to talk about where AI helps network operations today. Scott Penney, our VP of Product Management, kept it practical: AI is only as useful as the context it has. Pair DDI data (what the network should look like) with observability data (what it actually does), and AI can find root cause fast.

Three things AI can do for your network today

Enrich security alerts

Turn a bare IP address into a device, a location, a user, and a recent history, with a recommended response for your SIEM.

icon used for an eye

Make load balancing context-aware

Look past simple health checks and steer users to the best-performing region when latency climbs.

Catch configuration drift

Compare intended and actual network state, explain what drifted, and recommend the fix.

Diagnose and recommend, with humans in control

AI is probabilistic, so BlueCat’s focus is root cause and recommendations. Operators decide what to change.

Shrinking the “mean time to innocence”

When a hundred people join an outage bridge call and everyone blames DNS, correlated DNS and network data can show quickly that it isn’t DNS, so the team can move on to the real cause.

BlueCat in Infotech IGNITE Washington DC

Our team spent two days at the booth, where we demonstrated these use cases live. They run on LiveAssist, BlueCat’s agentic AI layer on Horizon, our SaaS platform. Customer data stays on the customer’s network, and you can start with a single product line.

Attendees asked sharp questions about where the platform runs, regional availability, data residency, and network versus security focus. Scott’s answer: network operations first, with security detection layered on top. One attendee noted their SD-WAN already reroutes traffic on its own, which Scott called a great example of a system with the right data to fix itself.

If you caught Scott’s talk or stopped by, thank you. If you missed us, reach out to BlueCat or request a demo.

Snapshots from IGNITE Washington DC

Frequently asked questions

Talk title: “AI for NetOps That Actually Works“

Speaker: Scott Penney, VP of Product Management, BlueCat Networks

Event: Infotech IGNITE Washington DC

Language: English ·

Scott Penney (0:00): All right, here we go. All right, howdy everybody, how you doing this morning? So far so good. So far so good, surviving. Yeah, so you’re in the right place, right? So this presentation, you know, I wanted to mix it up a little bit, talk about something sort of interesting, so I decided to talk about AI because I know nobody else is going to talk about that at this conference. And I’ve been told that like if the presentation goes badly, I can just say like network operations and jazz hands, AI. That was my guidance. That was George’s guidance. So good morning everybody. I’m Scott Penney. I’m a VP of Product Management at BlueCat Networks. Has anybody actually heard about BlueCat Networks? Probably not.

Audience (0:43): You’re just like, I had— well, yeah, we talked to you. You’re all like, I have to choose some session. This one seems like the least offensive. So just very, very high level. So BlueCat Networks, we’re a software company. We’ve been around about 22 years now, I think at this point. 21, 22 years. We specialize in network software. Very niche. sorts of network software. So anybody heard of DDI?

Audience (1:02): Yes.

Scott Penney (1:03): He has. Okay, so DDI is an acronym of acronyms. So it’s DNS, DHCP, IP address management. So it’s kind of core foundational configuration information about your network and some core services like DNS that help your clients connect to applications. So we’ve been doing that for a very long time. A couple years ago, we acquired a company called LiveAction. I don’t know if any of you have heard that name before, but they were more of a network observability company. So network observability in this context means we can watch traffic on your network, we can get flow information from your network infrastructure, we can do packet capture, we can maybe spot some security events based on the packets that are flowing over the wire.

Audience (1:39): Okay.

Scott Penney (1:40): So the idea behind us acquiring the company was, you know, we think that there’s a bigger story, a bigger opportunity here that AI actually really does unlock. Like in all seriousness, AI, there’s a lot of hype-ium, I like to call it, about AI. But, you know, there are certain use cases where AI can actually be really, effective and very practical in the network, and we think this is one of them. And the reason why we think that is kind of based around this. So what this is, we did some research with a third party and we said, okay, where, where are your apps? Where are your workloads that your customers are using, right? And we all know that, like, they all used to be here in data centers, and you guys have heard the story before, but like, that’s no longer the case. So not only are applications now sometimes in SaaS, sometimes they’re in a cloud provider, sometimes in a colo facility, wherever. But also core services are moving outside of those data centers and they’re moving to those locations to better service the clients that are out there.

Audience (2:32): Right.

Scott Penney (2:33): So DNS, for example, the thing that translates like a hostname like google.com to an IP address that a device can actually reach, that always, everywhere, every company, that used to be in the data center.

Audience (2:44): Right.

Scott Penney (2:44): ‘Cause that was just the logical place to put it. But now when your clients are out in AWS or they’re out roaming users Sometimes it makes sense to push those services out for better performance, you know, better granularity of data that you can collect from those, and so on and so forth. So the core challenge of this, this though, and you guys probably feel this more than we do as a software vendor, is now I have all this stuff in all these different locations that I got to manage, and it’s all different, right? Like when I have a service running in Google Cloud, it’s different than when it’s running in my cold office And all of these things give out data. They all emit data that’s interesting to a network operations team, but it’s all different. Sometimes I get a no-tell alert, sometimes I can get a piece of flow information, sometimes I can get a packet capture, sometimes I get a DNS query log. And it’s kind of like, okay, as a network operator, like, I don’t know, I mean, like, I can’t understand all of it all the time and be on top of it. So I need a, I need a sidekick, and that’s really where the AI story starts to come in. So does this kind of resonate with you guys? Make sense? You know, big complex networks, nobody actually really knows what all is going on in every location at every given time. So that’s kind of our starting point. That’s our problem statement. Now one of the things that we’ve all probably learned using AI just for like building presentations and stuff or whatever you do with it is you have to provide context to everything. Otherwise, you know, like you’ll draw the wrong conclusions. Like if you have one set of data, you’re trying to track down a problem, so you got a network issue. And say you’ve got like firewall logs, right? You can look at those firewall logs and you can ask AI like, hey, what’s going on here? And it’ll say, oh, well, we’re blocking this traffic.

Audience (4:21): Okay, why?

Scott Penney (4:24): Well, there was a rule change yesterday and all of a sudden this stuff’s getting blocked. You’re like, okay, but what is the traffic? Like, where is it trying to go? What is it trying to do? Who’s the end user that’s trying to access this? It doesn’t have that context, right? It just the firewall data. And so if you really want to be effective as a network operations team and be able to respond to these kinds of issues quickly, you need all of the context, right? You need to feed all of that into the AI so that it can say, oh, I understand it now. You know, Mario is sitting in this location, he’s trying to use this application, it’s going across this network segment, and this particular firewall had a rule change that’s different from the one that went into these other firewalls, and that’s why this is happening. Context matters, right? The problem is we’re all still siloed, and silos are the enemy of context, right? Because in that scenario, when I was trying to figure out why Mario can’t get to his app, like, the security team had bits of that context, the network operations team had bits of context, the DNS team had bits of context, and if that thing was in AWS, the DevOps team might have had some context, right? And you guys are all fairly senior, so like, of course this never happens in any organizations you’ve been a part of, but sometimes the network team and the security team don’t talk all that well, right? And sometimes the tools aren’t accessible to each other because of licensing issues or, you know, just sort of proprietary ownership issues, right? So if I don’t have all of the context because of silos, I can’t be effective as a network operations team. Does that make sense? All right.

Audience (5:56): Okay.

Scott Penney (5:56): So the point of all of this really is that with this dataset, because we’re talking about a bunch of different kinds of information from different systems, this is the kind of thing that AI is actually really good at, right? AI is not great at making funny pictures for me to put in presentations, which I didn’t inflict on you this time, but I usually do for internal meetings. But it’s really good at taking a whole bunch of information and getting context from that information and figuring out what’s going on. with that data, right? Whether that’s analyzing— I spent the morning with Claude analyzing sort of sales performance for the products that I own and like, you know, how are we doing when we’re competing against this company and this company and this company? And it does a really great job of that. It also does a great job taking all this network data and figuring out what’s going on because there is a lot of knowledge in these models that can help figure out the cause and effect of network changes and network issues and things like that. One thing though that you always have to keep in mind with these tools is is that AI is probabilistic, right? You can ask AI, give the AI the same data, ask it the same question a couple times, and you’ll get slightly different answers, right? So at this point in this journey, one of the things that we’re not doing as part of our AI is allowing people to make changes to the network, right? Because we’ll get there, we promise, but like, yeah, you might— he might come to the wrong conclusion if you just tell him to go fix the problem. problem, he might draw the wrong conclusion from the data once and, you know, wipe out a firewall, right? And nobody wants that. So you do have to be a little bit careful in this space, but by and large, what we’ve seen with our customers that have been using this platform, it’s really good at digging in and finding root cause and correlating data and saying, hey, this is what happened, this is why this happened, you know, this is what you should do to fix it, right? And that’s kind of the baseline, right? So helpful? Sound helpful? That probably is helpful to your network teams. Okay, great. Now, what kind of data are we actually talking about? And I don’t know if you guys are like deep low-level techie people that still like to, you know, pay attention to all the details, so I’m not going to spend too much time on this, but the BlueCat portfolio, that traditional DDI management system and then the observability system, this is kind of what you get. And I’m going to go through a couple of examples of how this data actually hangs together and helps you be more effective. So we can get raw packet capture, right? We can have always-on packet capture. Every little bit of information that goes across your network, we can record, we can analyze that, we can look for issues, things like that. Flow data, which is really performance data, like, okay, I’ve got 2 data centers and I’ve got a cloud and I’ve got, you know, this colo. What are the network links? What applications are using those links? Where’s the performance bottlenecks? You know, I get all of that information, even down to an end user where I can say, you know, I’m just going to keep picking on you, Mario. Sorry you sat there. Love it. It’s just what happens. I’m here for it. You know, Mario is doing this. Here are the applications Mario’s using, here’s the performance he’s getting, here’s where he’s getting that data, right? So you get all of that. Network topology alerts, if we see something in that data that doesn’t look right or, you know, we’re getting congestion, we can send an alert to the system, right? On the core services side, the management side, this stuff’s really important because this is what the network administrator thinks the network looks like.

Audience (8:58): Okay.

Scott Penney (8:59): So this is, okay, here’s my DNS zones, here’s my DHCP settings, here’s, you You know, the clients that are on my network. Here’s where I distributed my networks. This one’s in Cleveland and this one’s in New York City and this one’s in DC. So this is like my as-designed, you know, sort of thing. This is my as-actually-exists.

Audience (9:14): Right.

Scott Penney (9:16): Okay, so we have access to all of this data. Okay, so what do we do with it? Like, you know, what are some of the use cases? And I promise you, these are all things that we can do today. So if you come by the booth later, hopefully, Chris Eckert will be able to demo all these things unless he’s having trouble. But these are all things that actually work today. So let’s start with a really basic one. I’ve only got 3 of these. I’m not gonna kill you with slides. But let’s just say there’s something on your network fires an alert.

Audience (9:44): Mm-hmm.

Scott Penney (9:44): Says, okay, something’s going on. Let’s pretend it’s a security thing, like we saw, you know, some packets flowing on the network that, you know, have an attack signature for something. Maybe it’s doing a port scan. scan on a server or something like that. Something’s bad. So some system, and it doesn’t have to be our system, it can be any system that, you know, finds these sorts of things, says, hey, something’s going on, right? Like, like this device is doing something bad. Here’s what we think it’s doing. But in that context, again, context matters. All we have at that point is this IP address did this thing, we think. Okay? And if you’re a security person— any security people here?

Audience (10:18): Yeah.

Scott Penney (10:18): Oh, good. So as a security person, you’re just like, okay, great, you gave me an IP address and you said that I think something’s wrong. Like, what do I gotta do now? Right, so the first thing you need to do is you have to say, okay, what is that thing? Right, like, let me— help me identify that device. So this is in the IP address management system, some of it, some of it’s elsewhere, config.db, whatever. But it’s like, okay, great, this is a device. Okay, I see now that this is a laptop, it’s in the network that’s associated with New Jersey or Jersey City, and if I have a good IPAM system, And I can say that Mario has logged into this device most recently. And I can even get some more context and say, you know, show me all the leases that Mario has had in the last week. So I’ve got this IP address that’s misbehaving, but what other IP addresses has Mario had over the last week? Okay. So I get some context from that. Now I know a little bit more about what might be going on. That’s the IP history. That’s the IP history, sorry, I skipped ahead of that one. Then I can go to maybe a DNS tool and say, okay, show me all the DNS activity from that client or any other IP that Mario has been on for the last 7 days. Show me what he’s doing. Okay, there’s some internal queries, there’s some external queries. That external query maybe looks a little bit hinky, like I don’t know what that domain is. Okay, well, you know, we’ll see. Now give me the traffic data. Like how much bandwidth was Mario using before? What’s he doing now? What devices on the internal network is he connecting to normally and which ones has he been connecting to connected to in the last 2 hours before this alert fired. You get all that information and you can get a whole bunch of other information. So you can get information from a CMDB, an ITSM system, you know, whatever else. And now I’ve got the full context. Maybe not the full, full context, but I’ve got a heck of a lot more context than I had before. And now the AI can actually say, okay, based on all of this, here’s what it looks like. It looks like Mario went to a malware site. You know, here’s the DNS query. Here’s the timestamp, and then after that timestamp, this was the traffic pattern that we observed. And by the way, here are 5 other devices on the network that seem to have the same traffic pattern, right? So here’s what we think you should do— quarantine this device, whatever, whatever your security response is, right? And we can deliver that to other solutions to actually take advantage of, right? Send it to a SIEM or whatever you want. And so the security team is now primed with more information and a better, you know, sort of, you know, here’s where you should be thinking, go solve the problem. So does that all make sense? Right? We’ve bridged all those silos, we’ve gotten all this information, we’ve actually correlated it, we’ve drawn some conclusions from it, and we’re telling you what we think you should do.

Audience (12:46): Okay.

Scott Penney (12:47): So that’s one use case. Another one that we like to talk about a lot in the world of BlueCat, in DNS there’s this technology called global server load balancing. What this is for is to basically say, look, I can get this service in 3 different locations. I can get it in North America, Europe, and Asia-Pac. And I want to make sure that if I’m in North America, I’m using the North American service, right? Because I don’t want to just get a random response from a DNS server and send you to China. You know, your latency is going to suck, whatever. So there are solutions out there like from F5 and others that, you know, you can put in rules and, you know, load balance between globally and things like that. But they lack context again, right? So what we do is we say, look, you’ve got rules. You want the North American people to actually go to the North American service. And if it’s healthy, I’m just going to say, sure, you should go to the North American service. But healthy is kind of like a ping check or like an HTTP test, right? And it comes back OK. But what if the latency on that one was 2,000 milliseconds and the length that it has to traverse to get to that service is terrible and it’s about to go down, maybe I should actually route those people to Europe, right? So being able to intelligently respond to network conditions is another thing that this AI can allow us to do because again, it can correlate that client activity with network performance and then feed a configuration change that says instead of going to North America, I’m sending it to Europe. That’s another sort of dynamic thing that we can do here. And all of these are— And the third one, the last one, and this one’s the cause of a huge number of the outages that we see as BlueCat when our customers call and, you know, whatever. It’s because of drift, configuration drift, right? It’s like, look, what’s my intent? How do I want my network to respond? Okay, great, here’s all the rules, here’s the configuration, here’s everything else, and that’s all in that system of control, right? But then what’s the reality? Like, where are the packets actually flowing? What’s actually there? You know, I’ve assigned this IP address to that New Jersey data center. Why the heck am I seeing that same IP address popping up over in Cleveland, right? I mean, like, who did something? Somebody just randomly put a device on the network that, you know, has a conflicting IP address, or maybe I configured a router wrong and put an overlapping network or subnet on there. So what’s the actual reality? And another thing that AI is quite good at is just saying, okay, here’s 2 datasets. Here’s the thing that I think is supposed to happen. Here’s what’s really happening. Tell me, reconcile this for me. Tell me what has drifted and tell me and assess those things. Say, you know what you should do here? You should make this change. You should make this change. Da da da da da.

Audience (15:23): Right?

Scott Penney (15:23): Again, we’re not going to let it actually do the changes. We’re not quite that confident that we’ll be willing to. Does that make sense?

Audience (15:29): Yes.

Scott Penney (15:31): Any feedback on these? Are these valuable things? Yeah.

Audience (15:37): Okay.

Scott Penney (15:37): Is anybody doing anything kind of like this at this point?

Audience (15:40): I mean, we do some of it through our SD-WAN solution.

Scott Penney (15:45): Sure. Yeah.

Audience (15:46): So, you know, if the performance isn’t great, it will auto-route to the best performing path.

Scott Penney (15:53): Right.

Audience (15:54): Yep.

Scott Penney (15:57): Yeah. Yeah, and that’s a great example of like it actually has the right data to fix itself, right? But if it’s something else that’s actually causing the problem, right? Yeah, you need that, you need to break down that silo. So yeah, good. Okay, so this is, I think, kind of the thing that brings it all together. And I find this quote kind of funny. Our marketing team uses this. Hey, marketing team, as you’re listening to the recorder, I think this is funny. So, you know, when I talk about BlueCat, you know, troubleshooting calls. So we have, this one’s actually a retailer.

Audience (16:27): Copper.

Scott Penney (16:28): No, this is a copper company. There’s another one that I have that’s a wire transfer company. And they always tell the story about these war rooms. And I don’t know if this resonates with you guys. Like, something happens, right? And the critical system is down. We’re losing revenue because customers can’t transfer funds. And so 100 people get on a bridge call, right? And everybody comes to the bridge call. And it’s like the networking guy and the firewall guy and everybody’s there, right? And the first thing is, you know, somebody’s like, okay, I think DNS is down, right? And it’s always DNS. It used to always be databases, then it was always storage, and now it’s always DNS. And, you know, this guy, basically his point is, you know, I was able to actually have the data from DNS and say, no, it is actually— it’s not only configured correctly, but the client is making the right query, it’s getting the right response, the network is actually flowing that traffic properly, so it’s not me. And I love the part that I love is this Everyone was relieved. No, actually just you were. Everybody else was actually like, crap, it might be me. But, you know, this is the kind of thing that you can get from this sort of system. Mean time to innocence, I think, is what this guy calls it. How long does it take me to prove that it wasn’t DNS? So I like this quote. It kind of gives you a flavor for what we do for our customers. I didn’t think about Okay, so, you know, with all of that said, right, with all of that, you know, sort of as the background, now I get into the marketing pitch, right? Which is, you know, BlueCat, we’re sort of uniquely positioned as a company that can do these things because, you know, we jumped into kind of this idea of systems of control married to systems of observability, you know, quite early, a couple years ago. Our biggest competitor actually bought a company to try to emulate this about a month or 2 ago. But, you know, we’ve already got all of these things, right? We’ve got customers that have all of these systems already deployed. We have an Agentic AI layer called Live Assist that actually sits on top of this and actually has access to all of these different datasets and can actually do these correlations, right? We can actually do this work now. You know, this is not pie in the sky, oh, it’s going to take us 5 more releases to do this, come over to our booth And Chris can show you, you know, some of the stuff that we can do. It’s actually really cool. But the whole point of this is we just want to remove the friction from a lot of what your network engineering teams and security teams and whatnot have to do, right? Like, don’t make them waste their time going to multiple systems. Even if you say, well, I have a SIEM and I dump everything in the SIEM.

Audience (18:57): Eh.

Scott Penney (18:57): Do you, right? Yeah, not everything is in your SIEM. So being able to actually reach out And get the exact information you need at the exact time is super valuable. It makes things go a lot faster.

Audience (19:07): Okay.

Scott Penney (19:11): And of course we’re positioned to solve this well because we have that foundation, we have that configuration provisioning piece of your network, and then we have that observability so that we can see actually what’s going on. We can spot those things proactively and help you out. And I promised I wouldn’t PowerPoint you to death, so I’m not going to. What do you guys think? Interesting? Any questions? Where does it live? Where does it live? That’s a really good question. So right now, because of sort of the legacy of what we do as a company, a lot of our stuff actually sits on-premises or maybe in the cloud environment or, you know, whatever, virtual machines, things like that. We have this— we have a new platform. It’s called Horizon. It’s sort of— I like to call it the connective tissue that everything can sort of sit subscribe to, right? You can link all of our solutions— not all of our solutions, but we’re getting there— you can link it up to this Horizon platform. The Agentic AI layer sits on that SaaS platform, okay? Your data stays on your network, but, you know, the MCP servers that are actually hosted up on this cloud platform can reach out, grab the data they need to do the job, cache some of it for, you know, analysis and things like that, but it doesn’t actually get stored in the cloud. Now, in the future, we’re actually going to at least an on-premises version of this. We’re trying to source the hardware. We already know what the hardware is, but, you know, a big GPU box that you can deploy on-premises if you’re, you know, a 3-letter agency or something and you gotta have this air-gapped. You know, you can throw that on-prem and you get roughly the same experience. You don’t get quite the same experience because you can’t really pack as much compute into these devices as you can in a cloud environment, but you’ll be able to do both. So yeah, good question. Thanks for that.

Audience (20:45): But operations are all in the US?

Scott Penney (20:48): No, so the way that it works, the Horizon platform is actually a multi-tenant platform. It’s kind of distributed. So we have what we call RDCs, regional data centers, that we can deploy in any cloud environment right now. And eventually we will be able to deploy them locally in a Kubernetes environment or something like that. So if you’ve got some use case where, you know, it’s got to be in this data center, we’d eventually be able to do that. But we’re starting with the cloud providers. So we can do pretty much right now, we can do anywhere AWS has a region. We’re about to add Azure and OCI as well because there are some locations like Saudi Arabia is a good one where like there’s not an AWS region yet and we have some customers in Saudi that need something local because of data sovereignty laws. And so we’re going to be doing an OCI region there. So yeah, we’re pretty flexible. And we can do single tenants too, so if people don’t want a multi-tenant kind of solution. We can build you an RDC for one, you know, for one customer and it’s completely, you know, segmented.

Audience (21:43): Do you have to buy, um, let’s say both product lines, or you can just stick to DDI protection from a security perspective?

Scott Penney (21:50): Yeah, it’s kind of one of those things like the more it’s connected to the platform, the more insight you can get. But yeah, you can, you can start with one for sure. Do you have any financial institutions Who are your largest clients? We have all of the large financial institutions are our clients. They are not using this yet, right? So, I know you work for a bank, so they’re a little hesitant yet to connect some of this infrastructure to a cloud-managed platform. That’s why they want us to do the on-premises layer. So we do have them, they are very interested in this, they’ll probably end up doing doing like the on-premises version before they trust the cloud. It’s just the way they are. You had a question? Yeah, so I think from the security perspective versus the network side, which one do you think of these 2 is the primary focus? You know, if I had to choose one right now, I would say it’s network, right? It’s just we have a lot more context that’s relevant to a network. There are some security implications, so We can detect some security instances from the packet capture. We do have threat intelligence that we can apply to DNS queries and responses, and we can detect some things like DNS tunneling and things like that, but they’re not like square-on security, you know, solution. It’s more on the network side.

Audience (23:09): What about the threat intelligence? Is that organic or are you curated?

Scott Penney (23:15): No, we’re OEMing a third party. Okay, so yeah, a very well-known one that everybody uses. So, yeah, very basic level of security for people who’ve been doing DNS firewalls for a long time. So that’s basically what we’re doing with some additional advanced detection.

Audience (23:32): And is the focus large Fortune 500 companies or the SMB market?

Scott Penney (23:41): Actually, so for the Horizon, the SaaS management platform, that’s allowing us to actually go a lot lower into the sort of mid-market and start to get people there. I would say traditionally we look at more medium to large enterprise just because your network has to get to a certain level of complexity before a lot of this makes a lot of sense to do. You know, it can be a little heavy for, you know, a small network. Another driver is people who are doing a lot of like multi-cloud kind of stuff and like, you know, trying to figure out how to move workloads from here to here to here. We have a lot of capabilities that help with that. And sometimes those tend to skew a little bit smaller just because they do thinnings and then they have to clean up the mess afterwards. All right, well, I won’t make you stay here until for another minute, so I really appreciate everybody coming. That was great. Thank you so much for the interaction.