Episode 319 ·

Ismael Peinado - CTO at Toptal

Today we are talking to Ismael Peinado, the CTO at Toptal.  And we discuss how Toptal is putting quality at the forefront of everything they do, why the current approach to cyber security is in need of a serious update, and the current limitations of artificial intelligence.

All of this, right here, right now, on the Modern CTO Podcast!

Check them out now at Toptal.com!

About Ismael:

As Toptal's Chief Technology Officer, Ismael leads the company's engineering organization, driving process and culture to ensure top quality delivery from our team of world-class engineers. Ismael was formerly the CEO and Co-Founder of Blue4, a distributed media system used in the aerospace and entertainment industries. He leverages over twenty years’ experience in providing commercial, operational, and technical leadership for B2B, B2C, and government organizations from early-stage startup to large-high growth market leaders. Ismael has a BE and BS in Industrial Engineering from the Universidad de Málaga.

About Toptal:

Toptal is a network of the world's top talent in business, design, and technology that enables companies to scale their teams, on demand. With $200+ million in annual revenue and over 40% year-over-year growth, Toptal is the largest fully distributed workforce in the world.

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Ismael, the CTO at Toptal, and we discuss how Toptal is putting quality at the forefront of everything they do, why the current approach to cybersecurity is in need of a serious update, and the current limitations of artificial intelligence. All of this right here, right now on the Modern CTO Podcast.

(Ismael at 00:00:24) Here we go.

(Joel Beasley at 00:00:25) This is the Modern CTO Podcast. So where are you calling in from?

(Ismael at 00:00:38) I'm from Bulgaria. I'm right now in Sofia.

(Joel Beasley at 00:00:41) Nice. Is that where you were raised or where were you born at?

(Ismael at 00:00:45) No, there's quite a long story, but short, I've been living half of my life in Spain. I'm from Spain, from Malaga. But I have been living in the U.S., in Tampa, in Florida for some time, in Switzerland, in Holland, in Romania. And the last eight years I've been here in Bulgaria.

(Joel Beasley at 00:01:09) That's pretty cool. I live about an hour south of Tampa.

(Ismael at 00:01:13) Nice. Naples or somewhere like that?

(Joel Beasley at 00:01:16) Yeah, in between Tampa and Naples. It's a town called Bradenton.

(Ismael at 00:01:21) I know Bradenton.

(Joel Beasley at 00:01:22) Yeah, that's where we are.

(Ismael at 00:01:24) Yep, yep. Nice.

(Joel Beasley at 00:01:26) So what was technology like growing up?

(Ismael at 00:01:30) Oh, well, I'm old-fashioned, so to speak. So I started back with computers when I was 14, something like that, at the era where we had 14K baud modems and when Internet was not even a thing. So, yeah, I come from a long time, even before the Internet was a thing. I was into things like phreaking, messing with telephones and electronics. Yeah, I was much into that. But probably that's why I chose security to be my thing when the whole computer and Internet thing started a long time ago.

(Joel Beasley at 00:02:14) Yeah, I saw—yeah, we'll make sure it's a long time ago. I saw that you were in reverse engineering. Typically, that's like code word for security talk.

(Ismael at 00:02:25) Code word? It's not a code word. It's the real security.

(Joel Beasley at 00:02:29) I'm sorry. So what type of cool learnings did you get when you were younger in security?

(Ismael at 00:02:37) Oh, wow. You have to think that we're talking—oh my god—we're talking now twenty-five, more than twenty-five, probably twenty-six, twenty-seven years ago. So the greatest—I still consider that the greatest part of my life in terms of learning new skills, right? The thing is, at the time, security was not even a thing. So when I started doing reverse engineering, I started by changing the dialogues in a game, something very lame at the time. But at the time, there was no protection, no security. Security was not even a thing. So it was like an empty field where you could learn new things every day. So it was amazing. So I got to learn the very first things around security. So of course, at the time, the people who worked into security, when we got into it, we were kind of the elite. Although by today's standards, when you think about it, we didn't know that much. But at the time, you could hack into everything. You could reverse the protection of almost everything because security was not even a thing at the time. So, yeah, we learned a lot of stuff. And even if you look, for example, some of the findings that I had even later on, by today's standards, in Wikipedia you can find my name too. I'm proud of that. But by today's standards, they're very simplistic, right? So we always have that in mind when we speak about security, how security changed over the years so much. But yeah, learning—amazing. Learning the assembler or how things work, how the code works, that's something you really don't do today. You don't go so low level because it's too much time.

(Joel Beasley at 00:04:29) Yeah. I got into security—one of the old—my dad was teaching me. He was an electrical engineer and programmer. And he was teaching me to do small tasks. And then from there, I was curious. We got the second computer at the house, right? That was a big deal. So there was an upstairs and downstairs. And my sisters were using the second computer. And I was like, I wonder if I can get in there and see what they're doing, you know, because it's my own network. And so I figured out how to do that through some research. And then I was thinking, well, what if it's just a computer outside of my home network? Let's see if I could do that. So my brother was in college.

(Ismael at 00:05:05) Watch out.

(Joel Beasley at 00:05:09) Yeah. And this is—it's a long time ago. And so then I ended up accessing my brother's computer. And then I was just curious because you're right. At the beginning, it was very easy. There was very little security out there. And it was almost more of an exploration, like, this shouldn't be possible. This is possible.

(Ismael at 00:05:29) Yeah, it was so cool. Actually, I remember what triggered me to work into more of the hacking part of it, because reverse engineering—it was cool to reverse engineer games, and I got to change the behavior of games. MS-DOS games at the time. I mean, very basic stuff. But the thing that triggered me more into the, let's call it, hacking side is my father realized that when I was, I don't know, 15 years old, I was spending way too much time with the computer, way too much. I mean, twenty-four/seven. And he challenged me and he put a password on the computer, which at the time, the only way to put a password was to put a BIOS password, a CMOS password, which at the time was considered like, wow, this is the best thing ever. So I got into cracking that password. At the time, I didn't crack it properly. I didn't get the password from the BIOS. But from the time my father allowed me to use the computer, I made the first phishing scam of history. I put a fake prompt to ask him to change the password. I did that in MS-DOS, and he fell for it. I was so proud. And my father too, by the way. He said, wow, impressive. And that got me thinking too. Okay, this is interesting, right? I should explore this side. That's what got me into the other side of reverse engineering.

(Joel Beasley at 00:07:01) I like that. I thought you were gonna go with—back in the day on some of the earlier Windows computers, I'm really stretching my memory here. But if you forgot—there was one exploit where if you forgot like a CMOS password, you could open the computer up and actually like short something out and reset it.

(Ismael at 00:07:20) Yes. Yeah, I think that only worked with Phoenix BIOS. Can't remember. It was a very long time ago. But yeah, that was later in the game. At the time in which I did that, MS-DOS was the only available operating system. But yeah, it's true. Later in the game, there were even tools that allowed you to recover the password—

(Joel Beasley at 00:07:41) Oh, yeah.

(Ismael at 00:07:41) —from the BIOS like that. That's more boring. Yeah.

(Joel Beasley at 00:07:45) Yeah. We'll change the topic. So what was your first legitimate job after all of your upbringing?

(Ismael at 00:07:54) Legitimate. I like how you put it. So this is the interesting thing, right? That although I have been in security my whole life, I never really took off in a security job. I even tried to open a security company. Didn't work out. So my first real job—I was just putting, I don't know how you call it in English, we put the limitations in parking spots. So that was my first job. But my first IT job, it was as a developer. Doing websites. We called it, I think it was called Professional Web, something like that at the time. Nice domain if I should keep it. But that was the thing—twenty, twenty-five years ago, there was not a lot of jobs in security, if at all. And the thing that I started was web developer, which, I mean, twenty-five years ago, you actually didn't get paid very well. Today, you're a web developer, you're a king. But yes, I started as a developer. I didn't really like it because, of course, my developing skills were more into creating tools for security. But later, I moved mostly into the sys administration part, which is more aligned with security, which is my training.

(Joel Beasley at 00:09:12) Nice. Nice. And then now you're at Toptal. And by the way, I've been a customer of Toptal a couple times, and I've built teams in Toptal and run projects in there. And so when I heard that you were coming on the show, I was really excited.

(Ismael at 00:09:26) That's so cool.

(Joel Beasley at 00:09:28) How did you get involved at Toptal?

(Ismael at 00:09:33) That's a nice story, but I will keep it short because people say I speak too much. So I was the VP of Global Operations for a company, and one of the recruiters pinged me and said, "Hey, Ismael, how would you like to be an engineering manager for Toptal?" And I thought, well, I'm the VP of Global Operations. I mean, showing my ego, I said, how can you ask me to become an engineering manager? That's like two steps down. Well, he said, listen up. I will tell you. He told me the whole thing, and he got me mildly interested, right? Like, okay, let's bite. Let's give it a try. But then I met the team. And when I met some of the teammates, I think it was Bozhidar, Alexander, Deyan—I was starting to think, okay, wow. These people, they have got some impressive level. So maybe it's not such a step down. It is, right, when you think about it in terms of role. But as a company, I was quite impressed. Like, how did you get such these cute people? But then I met Taso, and that was for me the trigger. When I met Taso, he was so passionate about our platform, about what—or our, now it's our—but what Toptal was, that I thought, man, I gotta try it. I gotta give it a try and join Toptal. And I recently even told my girlfriend when she asked me that was the best decision of my life, the best decision of my life. And I made some very good decisions that changed my life in terms of how happy I feel in this company, how it fits my personality and what I want to do. Long story short, that's how I got to join Toptal.

(Joel Beasley at 00:11:25) Yeah. Feel free to talk, man. We can hang out. We can tell long stories, whatever you want. This is all about just us sharing. Well, for people who are listening that don't know what Toptal is, can you give the overview of what the company does?

(Ismael at 00:11:38) Yeah, sure. In essence, and to keep it simple, right? Toptal allows freelancers, right, to find the best jobs in the world. Now the kind of freelancers that we get in Toptal is what we say is like the 3%. So the job of Toptal is to find the best engineers, the product managers, the best freelancers in the world. Just get the best ones and match them with the best, most interesting projects in the world. So we are in that area where we look for the highest quality kind of freelancers and the highest quality projects, which makes everything around top-tier. It was one of the things that really caught my attention, right? It's not just all freelancers with all projects. Toptal is focused on the best of the best. But in essence, it's that simple, right? You're a freelancer. You have some great skills, and you want to find the most interesting and well-paid jobs, Toptal is your place.

(Joel Beasley at 00:12:40) Yeah. No, I'll tell you this much. Like, when I did this big project and it was somewhat related to the government, so I had a nice, you know, check that I could build a team out. And I thought, all right, let's try. That was my first time trying Toptal. And I put together this team and it was like just the most brilliant people. Like, you go in and—correct me if I'm wrong because it's probably been about five or six years since I've done it—but I went in, talked with the account manager, told him about the type of job. They hand-selected some candidates. I ran some interviews. You know, they talked to me about budget and timeline and all of that. And then I just met with some great people and brought them into the team. I brought like an iOS engineer who had previously worked at Apple. I brought like a person that was like a backend API person, designer. I brought like a whole group of people together and we built something that was really great. And it was just—it was like really fantastic people on demand.

(Ismael at 00:13:37) But, you know, what is maybe something it's a thing that not many people realize, right? That me, I have been a developer, and I had companies where I hired people. If I had Toptal twenty years ago, man, oh my, my companies would have been so much more successful because the amount of people that I had to hire, the hits and misses, the training that goes with that, and then you can miss the deadlines. That's what caught my attention of Toptal, right? Like, oh, maybe this idea is great. Like, if I have to get people for a project that I know right away they are brilliant, man, it's a blessing. So obviously, that's why Toptal is doing so well, right? The concept on itself is pretty great.

(Joel Beasley at 00:14:29) Yeah. I wanna share with you. I failed the entrance exam like ten years ago when I first found out about it. So I found out about it because I was, you know, I was a software developer for seventeen years. And so I was like, oh, this is cool. Let me take this entrance exam because it was like top three percent and it was an entrance exam. And I took it and it was discussing concepts that were concepts you would probably understand if you had a computer science degree, right? And I had specifically focused all of my experience on like business-related logic, like building B2B software systems, like large-scale systems. So when these mathematical problems came up, I was like, oh, you know, I have no idea how to do that. And I could go spend a bunch of time learning it, but I was just more interested in—not working there. I was more interested to see if I could pass the test. And that was actually really useful to me because it led me to another piece of content that I read online that was written for software developers that said "The 10"—it was like the ten concepts you missed out on because you don't have a traditional computer science degree, like for self-taught people who've just been writing code. And so I got to learn about a lot of different areas that I didn't even know existed in the college. So you guys—me failing that test actually caused me to learn, and I was very grateful for it.

(Ismael at 00:15:57) Pretty cool. Pretty cool. Yeah. I also found myself in with that thought lately because I started my career as an assembler developer, which today is a very rare thing, and then I developed into C++. And after C, well, C first, then C++, and then PHP. And the PHP side was almost inherited of my work on C++. But I never really got serious training, serious coaching, or serious learning around the PHP development. Now when I go back to some of my teammates and I look at their programming skills, wow. Wow. That is impressive how things have evolved and the concepts that they manage. So, yeah, I mean, that's the thing, right, that when you're starting in something, like, even in security or even as a developer or engineering, as self-taught, you miss some concepts that later on can be super helpful and can allow you to write much better code, faster, more reliable, and so on and so on.

(Joel Beasley at 00:17:07) Oh, for sure. Higher quality code?

(Ismael at 00:17:10) Yeah. For sure. For sure. But, yeah, it happens to all of us.

(Joel Beasley at 00:17:15) What is it like—oh, yeah. I fail all the time. It's how I succeed. I just have to fail a lot, right? And never give up. And then eventually things work out, right? So I read a lot about, you know, the company, and I kept seeing this recurring theme about quality. Like, you guys mention quality all the time. What is it like—is that a core culture item? How does that play into your company?

(Ismael at 00:17:43) That is one of the core elements. I mean, everything goes around quality, and it comes all the way from even Taso himself. So we never cut on quality. Never ever. And that's kind of the first principle, and everything goes around that.

(Ismail at 00:18:02) So when we build, and I gave an example—this is, I made a presentation once for All Hands, and the presentation was around hackathons. Right? For those who don't know, hackathons are just two, three days of fun activities for the team where they build proof of concepts, applications, but it's just a fun exercise.

(Ismail at 00:18:22) So presenting one of the hackathons, on my team, I have to acknowledge that they created a game, a Toptal internal game. It's like a memory game—you switch the picture of people, you need to remember. But they went and they matched the pictures with the standards of quality that we have for our application, that the pictures need to have an edge on them, the exact DPI that the pictures need to have, the exact quality. And it was a game.

(Ismail at 00:18:51) An internal game for us, but still you see that they went all the way to meet all the quality standards because it's in our culture. Right? It's how we do it. But I was so impressed because in a game, you expect to see just the pictures. I mean, just quickly, fast.

(Ismail at 00:19:09) No. They use all the quality standards that we have for publications. Right? When we go public and we make presentations, they went and applied that in the game. So that gives you an idea that, yeah, quality is super important, and it goes with the company culture, which means that when we do releases, for example, we always need to release in quality.

(Ismail at 00:19:36) There is no negotiation around that.

(Joel Beasley at 00:19:39) I love it. For me, I always wondered before I got into business really as, like, a life choice. Right? I would see all the different car companies out there, the vehicle companies. And I would think to myself, what's the difference in the person that's starting the company to be the Bentley or the Ferrari versus the one that's starting to be, like, the lowest priced car you could possibly purchase?

(Joel Beasley at 00:20:05) And for me, it's like, if you're going to start a company, why wouldn't you start the Ferrari? Why wouldn't you start the Bentley? Like, why would you start anything else?

(Ismail at 00:20:16) That is an awesome question. There is a reason. Right? Actually, when you are inside, you see this difficult. Right?

(Ismail at 00:20:25) Because releasing in quality means a lot more quality checks, a lot more time and money spent, and not many companies want to do this balance. Right? Many companies say, okay, why should I spend so much money in quality when I can release it earlier, get more money, and patch along the way? But, yeah, it's—let's do the example you made. If you want to make a Bentley, you already made that decision. Right? I'm not going to cut corners. I'm going to build the Bentley, but it is difficult because to reach to that point, they need to get the right people, the right process in place, the right mentality. That's why Bentley, for example, is a good example because the Bentleys are very nice.

(Ismail at 00:21:08) Or Bugattis.

(Joel Beasley at 00:21:09) There you go.

(Ismail at 00:21:10) They are so special. Right? You feel it. You see them. If you get the pleasure to drive them or to touch them, you see that there was a lot of time invested in them.

(Ismail at 00:21:22) That is not something that just came like that. But it has to be, yeah, a decision. Right? And say, okay, this is what I'm going to make. I'm going to go all the way for it.

(Joel Beasley at 00:21:31) And then it's, like you said, getting the right people together. So our startup is about maybe 15 people big, and it's taken three years to get the right core team. Right? But we were at our event—we had a quarterly get-together a few weeks ago. And I said, this is the winning team. We're, like, there. And, I mean, probably 30, 40 people coming through the company for us to really figure out. First, I had to get good at finding what those people look like.

(Joel Beasley at 00:22:05) I knew what they looked like in engineering, but understanding what they looked like in these other roles that I didn't have experience with was pretty tough, like in sales. But after figuring all of it out and getting this right group of people together, I completely understand when I was hearing in some of my earlier interviews talking to some of these great leaders like you, and they would discuss the importance of, you know, principles and then the importance of hiring really, really great people. And because when you do those things, when you have good principles and you hire great people, it's like a garden. Like, beautiful things will start to emerge.

(Ismail at 00:22:42) That's an amazing comparison. And to be honest, that has been always kind of the struggle in many of the companies that I work with. I mean, when I started—now when I look back and I look how I created the teams—you have to understand that sometimes you have constraints. At least this is what I want to think about my past experiences. Right?

(Ismail at 00:23:03) That sometimes even from pressure in other companies, they say, hey, I need to hire fast. You give up a little bit and say, okay, yeah, maybe it's not the right culture fit, but it's going to do the job.

(Ismail at 00:23:16) One thing which I truly appreciate when I joined Toptal—at least, this is when I spoke with Taso, he told me that right away on the last interview. But when I joined Toptal, it's super clear: don't look for anything else. Look for the best fit for the culture. It has to be the best people you can find, period.

(Ismail at 00:23:39) And having that possibility and not having any constraint, man, I'm so grateful. I'm super grateful of that, and it's probably why I am so happy and my team is so happy. Because you get to find the right people, the people who you like to work with, that they understand each other. We are a real team. And, yeah, unfortunately, in my past experience, as you said, I have to fail multiple times until realizing that maybe that's the way.

(Ismail at 00:24:09) Maybe being a Bugatti is the way—is the way that you want to be, is the way you enjoy life. That sounds—being a Bugatti. Being a Bugatti. Sounds correct. It's okay.

(Joel Beasley at 00:24:21) It works. It works. I get exactly what you're saying. It makes your life so much easier when you have great people on your team.

(Ismail at 00:24:31) Oh, I cannot tell that enough. That's why when it was, like, three weeks ago, my girlfriend asked me, like, hey—because she knows I'm super active, and I like to try new things. So, oh, you have been now three years at Toptal, and you don't mention anything about trying other companies. And I told her, no way.

(Ismail at 00:24:51) Say, I wake up in the morning, and I want to come to—well, come to work. Come online to work, speak with my people, see what we can do to improve, what we can do to make us better. I really, really enjoy it. So I will not give up that for anything. It's like having, I don't know, the Barcelona football team, right, when they were at their peak.

(Ismail at 00:25:15) You have a great team. You have great leaders. You enjoy playing. It's fantastic, man. I love it.

(Joel Beasley at 00:25:24) Yeah. I mean, you sound like you love it. You look like you love it. You got me excited about it. People are probably wondering how they join Toptal.

(Joel Beasley at 00:25:33) How do you do your recruitment?

(Ismail at 00:25:36) So the first part to understand about Toptal, right, is that we have a core team, which is—well, is part of my team, and engineering is part of the core team, which we work on Toptal platform, the finance, the Toptal company. And then we have what is the Toptal talent side, right, which is the freelancer that we match with projects. So you want to become a freelancer, you can go to our site, you can apply to be a freelancer, and it's an automatic process. It will guide you beautifully. To be part of the core team is a whole different monster, so to speak.

(Ismail at 00:26:10) Right? To be part of the core team, we have even stronger requirements because now you need to also be a fit for my specific team, which we are a fit. So what we do is we have multiple ways of sourcing. We go on LinkedIn. We open posts.

(Ismail at 00:26:27) We have our own careers page at Toptal. And, yeah, the process is very straightforward. Right? If you are an engineer, you've got some technical interviews, but then you get to meet the team, cultural interview, and you get to meet me and try to convince you to join our amazing team. But, yes, it's pretty standard.

(Ismail at 00:26:49) Obviously, the interview process is heavy because we look for the best of the best. But the best of the best are those that fit our culture, which is the most important.

(Joel Beasley at 00:27:01) It's interesting because it's hard to turn into words, but when you meet somebody and you start interacting with them, you can tell so much about how they'll fit on your team and within your culture.

(Ismail at 00:27:14) Absolutely. Absolutely. Actually, this is a good example. Just last week, one of my directors came to me and showed me—oh, I want to show you—he did a recording of an interview. Just one interview.

(Ismail at 00:27:28) Just meeting the guy. I said, look at this guy. And I saw the interview, and I saw, and I knew it. I told him, say, yeah, you scared him. He didn't do at the time—he didn't have the technical interview, so I didn't know how technically good he was. But I knew, and my guy told me the same. He said, he's great. So he told me the first ten minutes of watching the interview to say, yeah, he's actually joining.

(Ismail at 00:27:55) You could feel it. It's difficult, as you say, it's difficult to say with words, but you could see the personality, the openness, the friendliness, how easy it was, my guys speaking with him, how they understood each other. Absolutely, 100% agree with you. And we do that a lot, by the way. We review each other's interviews sometimes to see other kinds of candidates, and you see that immediately.

(Ismail at 00:28:21) When someone is a fit, you say, this is the guy.

(Joel Beasley at 00:28:25) It's like we're advanced AI. We don't know how it works exactly. We have a good idea of the principles of how it works, but it works.

(Ismail at 00:28:37) Advanced AI. Yeah. Like that. This is what we are. Right?

(Ismail at 00:28:44) This is fun.

(Joel Beasley at 00:28:45) Well, they're storing data inside of DNA now. Have you heard about this?

(Ismail at 00:28:50) Yeah. I read about it. Oh, man. If I could live 200 more years, I just ask for that.

(Joel Beasley at 00:28:58) All right. That's a fair ask.

(Ismail at 00:28:59) Two hundred more. Because I want to see what is going to be there in the future. Right? Especially, there's a couple of things that interest me. What is going to be the future of medicine?

(Ismail at 00:29:12) Right? When they start to be able to manipulate or use the DNA, not for evil, not for good, not to create the clones and stuff. It's going to—I think it's going to be amazing, and I would like to see the results of all that. As in terms of technology. Right?

(Ismail at 00:29:28) When you see how fast we are evolving today, man, in 200 years, how will it be? Right? This is a small ask. This is all I ask.

(Joel Beasley at 00:29:39) I have a project I want to run. And, all right, so you know the famous, I guess, I don't know if it's a drawing or it's a categorization where it shows us going from single-cell organisms all the way through all the different DNA evolutions of plant or animal life, different styles, ultimately ending up in human. I want to feed samples of all those DNAs into an AI, and I want to give it a forward progression on that. I want to see what we're going to look like in the future.

(Joel Beasley at 00:30:09) It seems possible. Right? I mean, we definitely have to get more advanced with our DNA understanding. But, I mean, if we can see the entire history of DNA up into humans and trace that line all the way back, there's no reason why we shouldn't be able to look forward a little bit.

(Ismail at 00:30:27) That's an interesting concept. I used to watch a lot of videos around that, around evolution and what triggered the change in evolution and so on. So I don't have the best understanding of it. It's just a YouTuber understanding of it. But that's super interesting because in theory, it could be—in theory, if you could emulate or try to simulate those potential changes in the DNA and what will be coming after that, maybe we don't want to see.

(Joel Beasley at 00:30:59) I don't know. I kind of want to see. I think we're in the, like, the very early ages of manipulating biology. I think we're in very, very—we're like in the Stone Ages of manipulating biology. We're just getting computers.

(Joel Beasley at 00:31:13) What computers can model is going to increase. I think quantum computing is going to help a lot with biological rendering. So I'm excited because I see a day, like, in the future movies where we have, like, wings, right? Like, why not? Why can't we genetically engineer some wings and put them on our bodies and fly around?

(Ismail at 00:31:36) It could be. That sounds definitely interesting.

(Joel Beasley at 00:31:41) Is that too far for you? That's too far-fetched. Okay. We won't do the wings. No wings for you.

(Ismail at 00:31:48) Come on. I want wings, but I don't know. I was—yeah, I would think. Right?

(Ismail at 00:31:55) Based on the movies I watch and the limited information I have, I would think that I will hope that we are mostly moving into the brain part of it, right, into how to get more out of our brain, how to understand more things. Why I say that is because if you look at it in the last, I don't know, 20 years, most of our development, honestly, as humans, as our race of humans, is more on the brain side. It's understanding how to use computing and how to create AI. I haven't seen a lot of development in terms of our physical qualities. If so, probably to the opposite.

(Ismail at 00:32:37) I don't know. When you think about it, we have so much technology. I would have expected someone to invent—someone, I don't know, to make me prettier.

(Joel Beasley at 00:32:47) That's impossible. You're maximum pretty. Yeah. You can't get prettier. That's it.

(Joel Beasley at 00:32:55) You've reached your limit.

(Ismail at 00:32:56) Yes. I don't know. Yep. That's my theory. Right?

(Ismail at 00:33:01) That if we're going to evolve, I would expect to evolve more on the brain part of it than, you know, physical superpowers.

(Joel Beasley at 00:33:09) Yeah. You know, I thought that when I was researching Neuralink, I saw that they program in Ruby. They were hiring some Ruby developers, which is where my background is in. And I was thinking, what—how cool would the job have to be for me to, like, not do the podcast? And I was like, if Elon Musk called me up and said, hey, I want you to run the Neuralink App Store, like version one of—eventually, you'll be able to, you know, have communication and chat apps through neural interfaces and all of that, but we want you to build the App Store.

(Joel Beasley at 00:33:42) I thought about it and ultimately, I'd have to turn down Elon. And the reason is because I like talking about so many different topics. And this job, like with this podcast, is the only way I can just talk about everything. I'm just such a nerd. I want to know what's going on.

(Joel Beasley at 00:34:02) Like, I've actually been talking to some of the people that are designing these advanced machines in biology that will help us do things like, you know, print organs and create cells and do all of this stuff. There's—and, you know, people storing the data in the DNA, I got to talk to that person. And just all of these different technologies, so I would have to turn down Elon. But first, I would tell him maybe so I could have some lunch with him.

(Ismail at 00:34:30) Climb there. Yeah. So—

(Joel Beasley at 00:34:33) You've been thinking about the future of medicine. You've been thinking about AI. What's going on with AI at Toptal or AI in the recruitment industry?

(Ismail at 00:34:43) Well, we are using some of it. The problem is that AI currently has limited application. I even remember—well, limited functionality. I remember that we use AI, for example—AI, a preliminary version of AI, something like that. When we try to match freelancer with job, for example, we use kind of a learning system.

(Ismail at 00:35:10) We have an entire team dedicated to that. It's pretty cool because think about it. Right? We need to learn how to—I'm simplifying this a lot, by the way, to make it easier to understand for everyone who is hearing. So we need to make sure that we can automate as many things as possible to allow the business to span as fast as possible.

(Ismail at 00:35:32) So we need to learn how to find the best jobs for freelancers, for example. And this is not so easy because you cannot just say, oh, this guy knows Ruby, by the way—the entire team pronounce Ruby, wink wink. Did you want to choose a different job? Here we are.

(Ismail at 00:35:51) But no. This kind of AI model is very interesting because it allows us to learn, right, when you try to map people and offer people jobs. Let's say you're a freelancer, right? And we need to show you some jobs.

(Ismail at 00:36:04) Okay? Again, I'm simplifying this. We need to make sure that we show you the jobs which are gonna be interesting for you. Now interesting is not something that you can use binary program and say, interesting, yes or no? You need to learn.

(Ismail at 00:36:19) Right? You need to learn from your background, from your skill set, from all the jobs that you took. And I don't want to share much information because I don't know to what degree I can see all classified information. But it's like that, right? You need to learn and you need to make a system in which what we show you is of your interest and learn from it. So this is kind of a basic kind of AI. But in the past, I used even myself, I was part of it. I was part of a project which we worked with Mastercard. It was an AI to find fraud, for example.

(Ismail at 00:37:00) And that was also super interesting, but that is where we hit some of the limitations, right? And how difficult is to emulate the human mind, the human brain is incredibly challenging because the power of AI is on the trial and error, right? It's on the learning process.

(Ismail at 00:37:22) That once they learn what they, once the AI learns, it's super efficient. But until it learns, that's the most difficult part. It's feeding that information, categorizing information, creating the branch of decision making. So, yeah, in essence, I'm quite into it. I like it a lot, but there is some limitations of their application. You can't just apply that to everything. But yes, in Toptal, we have a really great use case, and I hope that in the future, we can even expand it even more. That would be so cool.

(Joel Beasley at 00:37:56) Nice. What about, has there been any sort, I mean, it sounds like a pretty standard use case for AI, right? Matching these preferences and figuring it out.

(Ismail at 00:38:05) Yeah.

(Joel Beasley at 00:38:05) Are there any ethical considerations there or no?

(Ismail at 00:38:09) In our case, not so many because at the end of the day, this is most like automation, right? You could consider this like helping, what we help is helping the matchers, helping their job. Why? Because we're making the selection available for you, in theory, right, more suited to your preferences.

(Ismail at 00:38:29) So it's not like we're invading you or trying to clone your personality or anything like that. But this is, by the way, something very similar to what some ad companies are doing. And that's a little bit less, well, a little bit less ethical, right? Ads company grab this information from everywhere, like cookies and tracking mechanism, to profit from it.

(Ismail at 00:38:57) So it's not really in your benefit. They do it just to sell you and profit from the app. What we do is this for your own benefit, right? If you want to find a job, you want to be able to see or limit your search to the jobs that have the best chance to get you.

(Ismail at 00:39:12) Right? For example, if we run our AI against you, if it works properly, it should show you talking shows, podcasts around technology. And so that's the idea, right, that the AI is trying to help you, whereas in other cases, outside of Toptal, if you say, it's called for evil.

(Joel Beasley at 00:39:35) Yeah. Yeah. There's definite, when I started learning about what some of the more advanced ad agencies were doing with profiles at scale, I was kind of blown away. You're exactly right. They're creating these profiles and now, you'll even see inside of, inside of Safari on iOS.

(Joel Beasley at 00:39:54) I don't know if you have an iPhone or not, but there was this new pop up that, like, Safari allowed you to disable, like, cross site sharing of data. I can't remember the exact words.

(Ismail at 00:40:06) Oh my god. We're getting into a dangerous topic because it's a topic I can speak a lot. One of the projects that we did long time ago, and it was related to AI, and it was a super cool project. We were using all this data because there, this data value, like the data which is collected, is available, right? You need to just pay for it. There is providers who give this data around you. So we did a project in which it was for security purposes, right, in which we collected all this data around you, and we created an AI. Again, I feel bad calling AI because there is some AI projects which were a lot much more complex than ours. But it was that.

(Ismail at 00:40:54) We used it to try to find the kind of passwords that you will use and the kind of, well, no. Not actually password. We called dictionaries. And dictionaries, we collect a series of words, which are gonna be more probably you will be more inclined to use. And that was scary, man.

(Ismail at 00:41:15) That was scary because collecting all this data, this data usage of what site do you visit, what things do you like. Do you like horses? Do you like cars? If you like cars, then the data dictionaries were a lot more concise, which is the problem, right?

(Ismail at 00:41:33) The problem is, you try to, and I can go into the power of security, which is a whole different topic. But when you try to hack a password, you cannot go the brute force way. You need to shrink the kind of words, the kind of words that you can use to the bare minimum so you can then apply a minimum set of rules in order to crack those passwords. So using that data, we were super successful, incredibly successful on limiting the range of the words in the dictionary and increase the success of cracking the passwords for research purposes. Let me add the notice.

(Ismail at 00:42:14) But that's one example on how this data that you mentioned, that cookies and so on and so on, it can be used for evil. You just need either to pay for it or this data is already available on the dark web on the back side. So you can grab it and use it for multiple purposes, including that, right? Including just compromising your security.

(Joel Beasley at 00:42:40) Oh, man. You know a lot about security. I read in your profile you have a unique and possibly controversial approach to security. Can you explain that?

(Ismail at 00:42:54) So the main problem with security today, right, is that I don't want to go on a rant, but I'm gonna rant. And the problem with security today, honestly, is that it's all based on movies. And it's crazy. It's all based on movies.

(Ismail at 00:43:14) If you look at all the security certifications, even security policies around, for example, the maximum power password length policy, 12 characters with the exclamation points, and that is bullshit. And I will tell you why. Because all this is based on the perpetuating image of hacker, which doesn't exist today, which is the old fashioned hacker, which I was part of 25 years ago, is a hacker who will spend weeks, months of his time trying to get that, right? The reason why that doesn't, they exist, but the reason why that's not a target for today's security is because high skilled hackers are developers.

(Ismail at 00:44:00) They're making a ton of money as developers. If you go to Bulgaria, the highest paid people by 20 times are developers, more than doctors, lawyers, politicians, football players, actors. So you might think that those hackers of 25 years ago, they don't wanna risk it. They have very nice lives. They can make good money.

(Ismail at 00:44:25) They can put their money in crypto, make even more money. And today, we have very strict laws, so they are not gonna risk it. So where I'm going is that today's security is still focused on that old thought that the threat is this guy, this super skilled guy who is gonna get you. Well, let me tell you something. If one of these super skilled guys want to leave their job and wants to get you, he is going to get you.

(Ismail at 00:44:53) It doesn't matter. Skilled hackers, if they can spend the time, which they won't, they will get you. The problem today is that the security has changed so much and is so different that we don't acknowledge it. What is the problem of today's security? And I will go to the controversial part right away.

(Ismail at 00:45:13) It's that the threats of today, as you see script kiddies sitting in some poorer countries or country with low income, they don't care about you as a company. They run whatever script they found on the Internet across millions of computers. They don't have any skills. They just want the money. They just want some Bitcoins that you can give them because of some ransomware.

(Ismail at 00:45:39) That's the biggest threat. Stop thinking about, oh, my password should be 12 characters long. That's the worst you should do today. Because today, just to give an example, where is that coming from, the 12 characters passwords? That comes from 20 years ago in which we, hackers, used to brute force passwords.

(Ismail at 00:46:03) We can't do that anymore. You can't. You try to brute force Gmail. Good luck. Good luck if you get two tries.

(Ismail at 00:46:12) They're around 20 billion. So that's not possible anymore. So the problem that we have is because we are still based, security certifications, same. They teach you firewalls and all kind of bullshit.

(Ismail at 00:46:28) You need to learn two things today. One, the biggest threat that you have right now in your computer is email. Email is the worst security or worst attack vector that you have right now, and you cannot get rid of it. So if today you ask me, Ismail, if you were to be a hacker and you were to hack me, how would you do it? You might imagine that I would say, oh, I will go and find a buffer overflow in your application.

(Ismail at 00:46:57) No. I don't have the time for that. I will craft a beautiful email, which will look much better than any other phishing scams, and you will click on it. It will take me half an hour. That's how I'll do it.

(Ismail at 00:47:12) So we need to acknowledge that. We need to acknowledge that the long passwords, and this is the controversial part, this is what we're teaching people. You should have a very long password with many characters. That's the worst. The way security works today is what you need to tell them is use a fairly easy password to remember.

(Ismail at 00:47:34) I mean, it can have numbers and it can, but not too long. Eight characters is enough, way enough. You have second factor authentication. That's all you need to know. Turn on second factor authentication to everything you own, turn off email, you are fine.

(Ismail at 00:47:53) But the problem is that because there is a lot of business around the certifications, we have bank regulators. Have you seen PCI DSS? Oh my god. It's so obsolete. It doesn't work.

(Joel Beasley at 00:48:09) I know.

(Ismail at 00:48:10) So that's how hackers succeed today because we're teaching them things which give us the fake impression of security. I have a long password. Great. No. Not great.

(Ismail at 00:48:22) Long password will cause you to forget it. Having to use the password, remember a password, retrieve a or reset feature, first danger because an email with a link may make you think, oh, yes. Let's reset the password. First problem, just forget about that. Just focus on second factor authentication.

(Ismail at 00:48:43) If you tell me, you might have second factor authentication. Do you want to hack me? Hell no. I'm gonna spend my time. I'm gonna look for another victim who doesn't have second factor authentication.

(Ismail at 00:48:55) It's simple as that. Most of the problems with security today, if not all of them, is that mentality. The mentality that we have these very skilled hackers in the movies that they pull a laptop out of the backpack, and they can hack you in a minute. Never was true anyway. That they tell you that this is our threat.

(Ismail at 00:49:16) It's not. It's not a threat. It's ransomware, phishing scams. Move on.

(Joel Beasley at 00:49:24) I saw the, when people started doing the thing where they expire your passwords or make you change them every 30 days for a system, immediately, I was doing a project. So I was going into an office and one of our softwares had started doing that. And overnight, you saw a million stickies go on everyone's computer monitor because because they're being forced to change from the passwords they know, they can't remember it, so they write it down and stick it to the computer.

(Ismail at 00:49:53) I'm gonna tell you something which is secret.

(Joel Beasley at 00:49:55) Okay. Yes.

(Ismail at 00:49:57) It's because it's too old. Yeah. But back in the time, well, it was not so long ago. 10 years ago, I had a research forum where I teach people security and so on. It's closed down already.

(Ismail at 00:50:12) Don't ask me why. And one of my guys developed an application, and the application was grab the password from the reflection on the glasses. And it's a true thing. From the reflection on the glasses, we catch so many stickies with the password in the monitor, in the laptop, and I don't need to go so far away. I use this program with my sister-in-law, you call it?

(Ismail at 00:50:42) With the sister of my girlfriend. I use this with her, and I saw, my girlfriend said she has her password and the credit card number on a sticker on her laptop. And she did. Yeah. She did.

(Ismail at 00:50:58) So this is so stupid. But, yeah, I told you that we're gonna rant because my the thing I feel bad is that so many people are still driven to do these certifications, security certifications. They come out of them and they say, amazing. I know how a level three switch can be hacked. No one is gonna hack you. No one is gonna hack your switch.

(Ismail at 00:51:25) Forget about it. Just think about your email. Try to completely disable email in your company, like we do, and learn data recovery process, learn how the real security works today, which is completely different. I can tell you later on if you want how I protect my laptop, by the way.

(Joel Beasley at 00:51:45) No. Tell me now. How do you protect your laptop?

(Ismail at 00:51:48) So this is another of those concept, you know, I worked for a bank for a long time and had such fights with the regulators, which they're giving us instructions how to protect our laptops with all these kind of devices, RSA tokens, and bullshit. The best way, the most secure way to protect your laptop, and I'm gonna go to the Linux browser. Windows, by the way, I'm using Windows right now to show you that you can use Windows securely. But the principle is the following. That's the principle.

(Ismail at 00:52:23) Right? I can take my laptop right now as it is, throw it on the street, give it or give it to someone else. None of my data is gonna be compromised. None of it. Why?

(Ismail at 00:52:36) Best simple principle. There is zero data on my laptop. Zero. No documents. No passwords.

(Ismail at 00:52:45) Absolutely nothing. Nothing. So it's beautiful because if I lose my laptop, I can start to work on a new laptop right away. How do I do that? It's very simple.

(Ismail at 00:52:57) I use cloud services, right? Everything, all of my documents are stored in the cloud. Authentication. Guess what?

(Ismail at 00:53:05) Second factor authentication. I've even a third factor, which is a key. It's a hardware key, which is what I use to log in laptops, which are not mine, etcetera etcetera. But the principle is that use everything on the cloud. It doesn't matter all these security resources that tell you, oh, but your data is never safe.

(Ismail at 00:53:26) Bullshit. Go cloud. Store everything. Use a known provider. Google, Microsoft, you cannot go wrong. Store everything there, make sure every service is there.

(Ismail at 00:53:40) All my data is in the cloud. So why don't I worry about viruses and so on? First, because I know how to use my laptop. For example, when I'm in Windows, which I am because when I use Zoom, it doesn't play very well when I do presentations in Windows, whatever. It's the driver of the graphic cards that drive me crazy.

(Ismail at 00:54:00) But I'm in Windows. I'm telling you, I don't wanna get any viruses, any ransomware. And if I do, which never happened to me because I work with those, so I know how to handle them, I don't care. I don't care. My laptop can turn it off today, and it's just a plain Windows installation with nothing, or even my name on it.

(Ismail at 00:54:22) If I go to Linux, it's the same. My Linux installation is a live installation. So I have this key that goes inside of the laptop. It's a live installation. I work with it.

(Ismail at 00:54:33) When I finish, take it out. It's gone. There is no data. This is not so difficult. Everyone can do this already.

(Ismail at 00:54:44) Everyone, except, of course, there is some data editors and specialized applications, but 90% of the people can do that. They just don't want to. They feel lazy just to switch everything to cloud, not installing Microsoft Office. But yes, you can. You can use Office 365, Google Suite, store everything on the cloud so you can, and I've done this.

(Ismail at 00:55:11) I've done this in a demonstration to one of my guys and in a presentation here in Sofia. I thought my laptop, it's a giveaway. Do whatever you want with it. It's empty. It's really empty.

(Ismail at 00:55:24) So that's the first step, because if you think in those terms, you're going to start to think immediately on, oh, what about authentication? Oh, if I should not have any data, we should store the data. You automatically will get in the mindset on how to protect yourself against the most important threats, not about this hacker with yellow glasses and a laptop on his backpack.

(Joel Beasley at 00:55:51) What's the craziest cyberattack that you've ever seen?

(Ismail at 00:55:54) Whoa. I've seen many, way too many. I can tell you the most recent one. And it's crazy because it literally shows you this, right? Because the old-fashioned attacks were super clever, to be honest. Super, super clever. And we even had competitions and we have fights again. Some of us in the past tend to be who was the best hacker. But recently, even in Toptal, we had a recent attack, and it was a denial-of-service attack. Didn't affect Toptal because we are very well protected. But it doesn't matter. Even if we are not perfectly protected, it's the lesson learned, right? So all of a sudden, it was a month ago, we started receiving this massive, massive denial-of-service attack. I mean, millions and millions of requests per second. And just, of course, we started to see immediately a service to pick up, and our CDNs started to issue warnings. So, so far normal. It happens, unfortunately, quite frequently. But we have business protections. We have a CDN, like everyone should, since today's CDNs are free. As crazy as it sounds, you can find free CDNs, and the best CDNs are free, but they protect you from that. Now the problem with this is that, this is unbelievable, the hacker, the attacker, contacted us. And so casually came and said, "Oh, I know that you're having an attack. If you want it to stop, you can pay me." I mean, this is exactly what I meant. Today's mentality of hackers is that skill zero. They just find the fastest way to harm you. And he can say, "Yeah, if you want to stop it, you need to pay me." And our answer was, "No, please continue. This is free test for us." But he's doing, and I told my entire team, that's why you need to think about security from a different perspective. I told the guys, "Don't ask him to stop. What he's doing is illegal. You cannot do that." But for us, it's free testing. It's testing those old systems work as expected. Thanks to that, we found our caching mechanism wasn't optimal. We found a way that we could cache better the pages. So today, thanks to this attack, we have a faster service with less load because we found our cache mechanism could have improved. But this brings to mind, right, that although the attack on itself is very serious, I mean, this happened to a company who is not prepared, you're going to be down for maybe weeks until you figure it out, because setting up a CDN to avoid these attacks is not easy. You need to also configure your servers. We were prepared for that. But that can damage your company pretty bad. And this is just some dumb yo-yo sitting in Ukraine, punching some codes. Not necessarily in Ukraine. This case, he was in Ukraine. It was so stupid. He sent an email to me, of all the people. He sent an email to me. What did I do? I traced back the email. So I know who he was. I didn't do anything. It was free for us. It was doing a testing for us. But again, it tells you, right, the mentality today of hackers is just quick money. I want quick money. He was using Tor to protect the in sense for from the attack. And that's what they're looking for. So it's crazy in the regard that it's so simple. Anyone can do it. Anyone can bring a business down for days, for sure. And there's nothing you can do, by the way. If you are not prepared for it, you will just suffer. And there is the typical thing that we speak, right? And this kind of the mentality that we don't negotiate with terrorists. It comes from there. As a business, if that happens to you, you might think, "Oh, he was asking for," I think it was like a thousand dollars. He was asking for nothing. I mean, that's not worth it if you get caught. That's what I was asking. But for some business, I might think, "Okay, it's worth it, right? Because I'm going to lose so many thousands or millions in some business. Bless you the money." No. Learn from it. This is what I mean. Didn't affect us. But still, even if it would have been successful, my reaction would have been the same. Let it continue. You need to learn from it. So this is, I mean, the most recent, not the craziest. But, yeah, in terms of craziest, I have a whole catalog.

(Joel Beasley at 01:01:05) Well, as we start to wrap up, I want a couple pieces of leadership insight from you. So I'm curious, what are you learning right now as a leader?

(Ismail at 01:01:16) I don't know if I'm going to be able to say this short.

(Joel Beasley at 01:01:20) Take your time.

(Ismail at 01:01:23) That's super interesting because when we're applying, again, in Toptal, Toptal is very special because we are remote. We don't have per se working time or working hours, and we have all kind of different things from other companies. But one of the things that I found out to be extremely effective for us is what I call my framework, which is the guidance versus the direction. So what we do at Toptal and what is being very successful at the moment is providing guidance, but never direction. Now this is the equivalent, I make this analogy all the time. Most companies, 99% of the companies, I'm going to use an analogy, which is crossing the road, crossing, if you want to teach your kids crossing the road to the zebra walk or whatever it's called, the crosswalk. So in today's world, all the companies do the following. It's a process-wide approach, which is if they are very young kids, you take them by the hand. Common sense. And as they grow, you display them the rules. Looking left, right, you can extend the rules. As they grow more, you keep extending the rules. This is a process-wide framework. Why is using 99% of the companies? Because it's very efficient. There is no question about it, right? And why many parents use this, same reason. It's super efficient. You don't have the time to wait for the cars 20 days to explain your kids how this works. Now the difference in the framework, how we apply, how I apply it at Toptal is the following. This is quite cool. It has pros and cons. Instead of building a process-wide framework, instead of telling you the rules, I stop and I say, "Okay, instead of telling you the rules, I'm going to explain you the psychology behind the drivers behind the wheel, the traffic rules. What happens when there is weather conditions?" So I explain everything around what is the traffic around, even at the time of peak hours, what happened with the drivers. They are in a rush. Maybe they don't pay attention. I explain all that, which is what I say guidance. So when you decide to cross the road, you don't need process and policies. You don't need to tell me, tell you how. You know. Now getting out of the analogy, the advantage with this approach is that you, well, the constraint of this approach is that you can only do it with fairly mature people. You cannot do it with kids, right? They're crossing the road. You need to have the best of the best. Checked. We have this at Toptal. But there's a huge advantage with it, is that accountability, which is a misused word in, you will find a lot of LinkedIn articles about accountability. I hate the word, but it has a meaning for it, which is if you build a process-wide framework and they cross the road and fail, who is accountable for that? You're the company because you create the rules. You cannot go back and blame the employees because they fail crossing the road because you missed one policy or you missed one process. Now the beauty of my framework, and the hypothetical disadvantage, of course, that's a huge one, is that because you explain everything around how traffic works, they know the cost of crossing the road. So they're already accountable in their mind. So they're going to make the best decision, but it's going to be their decision. They are going to be the ones who are going to decide when to cross the road. That is super powerful because it opens learning, creativity. That is the most important part, and this is one of the things I learned the most in my career at Toptal, which is you need to allow people to learn. You need to allow people to be creative, especially in engineering. Believe it or not, engineering is about creativity. To have these people happy, they need to be creative. The way to allow that is to show them the path and tell them the things they want to find along the path, but still they make the decision, but they know the shortcomings. They know the issues. Now the how this work in practice, if you ask me, because we have too much analogy at the moment, is that to make this work, you need to spend countless hours of coaching. So if you join Toptal, you join my team today, the first thing you will see is that coaching, coaching, coaching. Education, education. Your leader is going to be helping you, teaching you, sharing his knowledge with you nonstop. You can say a very disadvantage. The reason why this is not applied in pretty much any company is very easy. It's very costly. Very, very costly. Because you need to spend all the time, and you need to have the right amount of people. But linking back to one of your first questions, Toptal doesn't cut on quality. So costly is a factor, but doesn't matter because we want quality at the end. And it's not just quality of output, quality of work, quality of life too. How to achieve that? I mean, I'm very high level, right? I'm trying to keep it short. Is that, yes, I'm going to be with my kid waiting for the cars to close. Yes. That's the answer. I'm going to spend the time to explain my kid everything around crossing the road. Everything. The more, the better. Because the more you explain, when something goes wrong, the more they will understand what happened. You speak to that. I mean, that works also in engineering easily, right? You make a value, you make a mistake. You learn from me not because I'm going to go, "Oh, what did you do?" You're going to learn from me because you know. You know why you did that mistake. You made a mistake because you were rushing up, because you had too much in your mind. You have too many meetings. That is what we are fostering. So to answer the question, the biggest thing I learned is that the framework that will allow you to grow the more and be the most happy at your work is a guidance-based framework. It comes with a cost, so it's not easy or feasible to implement in all the companies.

(Joel Beasley at 01:08:12) I like it. You could probably start small too with, like, if you're at a larger company with a lot of process, with trying this out on one of your best employees, right? Giving them some more guidance over direction, and then you can get a little buy-in and slowly expand it.

(Ismail at 01:08:28) That's the thing, right? The problem with those frameworks is that it needs to be embedded in the culture. Because otherwise, just picture, right? I use the analogy because it's so great. I think it's great. It's because if you are waiting in line to cross the road, cars are going to pile up, right? And when the cars start to pile up, they start to beep and they start to add pressure, and pressure is not good. And that's the problem with the framework that in order to implement it, you need that leverage. You need that in the culture. You need to make sure that everyone is on board of. It has a cost. So it's not so easy. I tried to implement this in previous companies because one day I will tell you the story of my life, why I have this personality. It comes from failure. But I always knew there was something wrong with my framework in one of my previous companies, and I always thought it was that. I always thought that I'm providing too much direction. I'm telling them what to do instead of giving them a space. But my framework never worked. It never really worked. My favorite, it was failed. And I never found the reason why it failed until very recently, which is that, is that implementing it is not for everyone. Probably, you're right. I mean, someone else maybe has a better way to implement it. But I did it wrong because I tried to implement it like, "Hey, I know this is right. Cars, wait in line. Trust me." But it doesn't work in practice with many companies, right? Many companies say, "No, no, no, no, no. Cars should go on. Cross the road. You will have time too for coaching. This is next quarter, maybe." And that's the problem that if you feel very strong about it, will maybe create problems. But lesson learned, as you said, failing is what brought me to make this framework how it is today, which is quite cool. It's very cool.

(Joel Beasley at 01:10:31) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.