Jan 2, 2019 · 29m · a16z

a16z Podcast | The Cloud and The Public Sector

Teresa Carlson · 21m spoken Sonal Chokshi · 6m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, Teresa Carlson, Vice President of Worldwide Public Sector at AWS, discusses how cloud computing transformed public sector operations, compliance frameworks, and global innovation. She details the evolution from legacy security models to FedRAMP, cultural shifts toward agile government, international innovation centers, and hybrid cloud architectures.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The host holds 23.6% of the talking time here. How this is scored →

The host as informed peer 4.1 Guest teaching 3.9 Guest disagreement 0.4 The host pushing back 2.0
05100:0010:0020:003:25–5:56 · The host as informed peer 3/10 Defining Cloud Computing and Establishing FedRAMP Standards Sonal sets up the conversation by noting the mistake organizations make when translating paper-based processes directly into digital systems. Teresa explains the early government pushback on security and how AWS worked with NIST, OMB, and GSA to replace FISMA with FedRAMP.5:56–8:24 · The host as informed peer 3/10 Cultural Shifts and Modern Government Innovation Teams Sonal synthesizes the guest's points by highlighting how the procurement model flipped from needing to justify cloud use to having to justify why cloud cannot be used. Teresa details cultural hurdles and internal SWAT teams like 18F and UK's GDS.8:24–12:41 · The host as informed peer 5/10 Global Cloud Expansion, Entrepreneurship, and Innovation Centers Sonal demonstrates strong subject expertise by articulating a theoretical framework on why top-down or bottom-up innovation clusters fail without supportive regulatory conditions and cloud education. Teresa agrees and outlines public-private innovation hubs in Busan and Bahrain.12:41–17:07 · The host as informed peer 5/10 Data Sovereignty, Cloud Balkanization, and Global Policy Sonal pushes past Teresa's generalized response that 'the world is a small place' by directly raising cloud balkanization, geography, and data sovereignty concerns. Teresa acknowledges that while commercial firms care less, foreign governments actively navigate sovereign policy hurdles.17:07–21:04 · The host as informed peer 4/10 Compliance Tiers, Architecture Flexibility, and Cybersecurity Standards Sonal probes whether AWS offers varying spectrums of compliance tiers for lower-risk entities. Teresa educates the host on AWS's global architecture, explaining that security controls deployed in one region are inherited fleet-wide rather than custom-built.21:04–23:47 · The host as informed peer 3/10 Government Realizations and Shifting Focus to Results Sonal asks whether government clients are genuinely innovating or simply relieved of basic IT plumbing, noting how novel it is for public agencies to focus on delivered results. Teresa clarifies that while many legacy agencies start by fixing infrastructure, rapid prototyping unlocks genuine innovation.23:47–29:51 · The host as informed peer 6/10 Public vs. Private Cloud Definitions and Hybrid Cloud Transition Sonal forcefully challenges the concept of 'hybrid cloud', suggesting it may be a corporate cop-out or buzzword for delaying cloud adoption rather than a true architecture. Teresa counters that large enterprise and public sector entities running critical missions like Homeland Security cannot simply pull the band-aid off overnight.3:25–5:56 · Guest teaching 4/10 Defining Cloud Computing and Establishing FedRAMP Standards Sonal sets up the conversation by noting the mistake organizations make when translating paper-based processes directly into digital systems. Teresa explains the early government pushback on security and how AWS worked with NIST, OMB, and GSA to replace FISMA with FedRAMP.5:56–8:24 · Guest teaching 4/10 Cultural Shifts and Modern Government Innovation Teams Sonal synthesizes the guest's points by highlighting how the procurement model flipped from needing to justify cloud use to having to justify why cloud cannot be used. Teresa details cultural hurdles and internal SWAT teams like 18F and UK's GDS.8:24–12:41 · Guest teaching 3/10 Global Cloud Expansion, Entrepreneurship, and Innovation Centers Sonal demonstrates strong subject expertise by articulating a theoretical framework on why top-down or bottom-up innovation clusters fail without supportive regulatory conditions and cloud education. Teresa agrees and outlines public-private innovation hubs in Busan and Bahrain.12:41–17:07 · Guest teaching 4/10 Data Sovereignty, Cloud Balkanization, and Global Policy Sonal pushes past Teresa's generalized response that 'the world is a small place' by directly raising cloud balkanization, geography, and data sovereignty concerns. Teresa acknowledges that while commercial firms care less, foreign governments actively navigate sovereign policy hurdles.17:07–21:04 · Guest teaching 4/10 Compliance Tiers, Architecture Flexibility, and Cybersecurity Standards Sonal probes whether AWS offers varying spectrums of compliance tiers for lower-risk entities. Teresa educates the host on AWS's global architecture, explaining that security controls deployed in one region are inherited fleet-wide rather than custom-built.21:04–23:47 · Guest teaching 3/10 Government Realizations and Shifting Focus to Results Sonal asks whether government clients are genuinely innovating or simply relieved of basic IT plumbing, noting how novel it is for public agencies to focus on delivered results. Teresa clarifies that while many legacy agencies start by fixing infrastructure, rapid prototyping unlocks genuine innovation.23:47–29:51 · Guest teaching 5/10 Public vs. Private Cloud Definitions and Hybrid Cloud Transition Sonal forcefully challenges the concept of 'hybrid cloud', suggesting it may be a corporate cop-out or buzzword for delaying cloud adoption rather than a true architecture. Teresa counters that large enterprise and public sector entities running critical missions like Homeland Security cannot simply pull the band-aid off overnight.3:25–5:56 · Guest disagreement 0/10 Defining Cloud Computing and Establishing FedRAMP Standards Sonal sets up the conversation by noting the mistake organizations make when translating paper-based processes directly into digital systems. Teresa explains the early government pushback on security and how AWS worked with NIST, OMB, and GSA to replace FISMA with FedRAMP.5:56–8:24 · Guest disagreement 0/10 Cultural Shifts and Modern Government Innovation Teams Sonal synthesizes the guest's points by highlighting how the procurement model flipped from needing to justify cloud use to having to justify why cloud cannot be used. Teresa details cultural hurdles and internal SWAT teams like 18F and UK's GDS.8:24–12:41 · Guest disagreement 0/10 Global Cloud Expansion, Entrepreneurship, and Innovation Centers Sonal demonstrates strong subject expertise by articulating a theoretical framework on why top-down or bottom-up innovation clusters fail without supportive regulatory conditions and cloud education. Teresa agrees and outlines public-private innovation hubs in Busan and Bahrain.12:41–17:07 · Guest disagreement 1/10 Data Sovereignty, Cloud Balkanization, and Global Policy Sonal pushes past Teresa's generalized response that 'the world is a small place' by directly raising cloud balkanization, geography, and data sovereignty concerns. Teresa acknowledges that while commercial firms care less, foreign governments actively navigate sovereign policy hurdles.17:07–21:04 · Guest disagreement 0/10 Compliance Tiers, Architecture Flexibility, and Cybersecurity Standards Sonal probes whether AWS offers varying spectrums of compliance tiers for lower-risk entities. Teresa educates the host on AWS's global architecture, explaining that security controls deployed in one region are inherited fleet-wide rather than custom-built.21:04–23:47 · Guest disagreement 0/10 Government Realizations and Shifting Focus to Results Sonal asks whether government clients are genuinely innovating or simply relieved of basic IT plumbing, noting how novel it is for public agencies to focus on delivered results. Teresa clarifies that while many legacy agencies start by fixing infrastructure, rapid prototyping unlocks genuine innovation.23:47–29:51 · Guest disagreement 2/10 Public vs. Private Cloud Definitions and Hybrid Cloud Transition Sonal forcefully challenges the concept of 'hybrid cloud', suggesting it may be a corporate cop-out or buzzword for delaying cloud adoption rather than a true architecture. Teresa counters that large enterprise and public sector entities running critical missions like Homeland Security cannot simply pull the band-aid off overnight.3:25–5:56 · The host pushing back 0/10 Defining Cloud Computing and Establishing FedRAMP Standards Sonal sets up the conversation by noting the mistake organizations make when translating paper-based processes directly into digital systems. Teresa explains the early government pushback on security and how AWS worked with NIST, OMB, and GSA to replace FISMA with FedRAMP.5:56–8:24 · The host pushing back 0/10 Cultural Shifts and Modern Government Innovation Teams Sonal synthesizes the guest's points by highlighting how the procurement model flipped from needing to justify cloud use to having to justify why cloud cannot be used. Teresa details cultural hurdles and internal SWAT teams like 18F and UK's GDS.8:24–12:41 · The host pushing back 0/10 Global Cloud Expansion, Entrepreneurship, and Innovation Centers Sonal demonstrates strong subject expertise by articulating a theoretical framework on why top-down or bottom-up innovation clusters fail without supportive regulatory conditions and cloud education. Teresa agrees and outlines public-private innovation hubs in Busan and Bahrain.12:41–17:07 · The host pushing back 4/10 Data Sovereignty, Cloud Balkanization, and Global Policy Sonal pushes past Teresa's generalized response that 'the world is a small place' by directly raising cloud balkanization, geography, and data sovereignty concerns. Teresa acknowledges that while commercial firms care less, foreign governments actively navigate sovereign policy hurdles.17:07–21:04 · The host pushing back 2/10 Compliance Tiers, Architecture Flexibility, and Cybersecurity Standards Sonal probes whether AWS offers varying spectrums of compliance tiers for lower-risk entities. Teresa educates the host on AWS's global architecture, explaining that security controls deployed in one region are inherited fleet-wide rather than custom-built.21:04–23:47 · The host pushing back 3/10 Government Realizations and Shifting Focus to Results Sonal asks whether government clients are genuinely innovating or simply relieved of basic IT plumbing, noting how novel it is for public agencies to focus on delivered results. Teresa clarifies that while many legacy agencies start by fixing infrastructure, rapid prototyping unlocks genuine innovation.23:47–29:51 · The host pushing back 5/10 Public vs. Private Cloud Definitions and Hybrid Cloud Transition Sonal forcefully challenges the concept of 'hybrid cloud', suggesting it may be a corporate cop-out or buzzword for delaying cloud adoption rather than a true architecture. Teresa counters that large enterprise and public sector entities running critical missions like Homeland Security cannot simply pull the band-aid off overnight.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 32% · guest 68%0:00 · the host 32% · guest 68%3:00 · the host 20.3% · guest 79.7%3:00 · the host 20.3% · guest 79.7%6:00 · the host 25.9% · guest 74.1%6:00 · the host 25.9% · guest 74.1%9:00 · the host 23.9% · guest 76.1%9:00 · the host 23.9% · guest 76.1%12:00 · the host 13.9% · guest 86.1%12:00 · the host 13.9% · guest 86.1%15:00 · the host 29.1% · guest 70.9%15:00 · the host 29.1% · guest 70.9%18:00 · the host 11% · guest 89%18:00 · the host 11% · guest 89%21:00 · the host 33.2% · guest 66.8%21:00 · the host 33.2% · guest 66.8%24:00 · the host 24.8% · guest 75.2%24:00 · the host 24.8% · guest 75.2%27:00 · the host 21.9% · guest 78.1%27:00 · the host 21.9% · guest 78.1%
Sharpest disagreement ▶ 27:37 Rejection of host's 'pulling the band-aid off' framing on hybrid cloud

Teresa firmly rejects Sonal's premise that hybrid cloud is a delay tactic, emphasizing that critical agency workloads like Homeland Security or Veterans Affairs cannot simply turn off legacy systems without careful hybrid transition.

Hardest push from the host ▶ 12:41 Refusal to accept that global public sector cloud adoption is seamless

When Teresa suggests the world is a small place where global cloud operations run similarly, Sonal refuses the premise and directly challenges her on data sovereignty and cloud balkanization.

Biggest teaching moment ▶ 17:44 Explaining global fleet security inheritance vs custom builds

Teresa corrects Sonal's assumption about AWS creating custom compliance packages by explaining how global multi-tenant fleet inheritance works automatically across regions.

The host holds their own ▶ 11:13 Synthesizing framework on top-down vs bottom-up innovation clusters

Sonal takes control of the conversation by laying out a clear, authoritative framework on why top-down government projects and bottom-up communities both fail without supportive policies and cloud education.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Defining Cloud Computing and Establishing FedRAMP Standards 3400 Sonal sets up the conversation by noting the mistake organizations make when translating paper-based processes directly into digital systems. Teresa explains the early government pushback on security and how AWS worked with NIST, OMB, and GSA to replace FISMA with FedRAMP.
Cultural Shifts and Modern Government Innovation Teams 3400 Sonal synthesizes the guest's points by highlighting how the procurement model flipped from needing to justify cloud use to having to justify why cloud cannot be used. Teresa details cultural hurdles and internal SWAT teams like 18F and UK's GDS.
Global Cloud Expansion, Entrepreneurship, and Innovation Centers 5300 Sonal demonstrates strong subject expertise by articulating a theoretical framework on why top-down or bottom-up innovation clusters fail without supportive regulatory conditions and cloud education. Teresa agrees and outlines public-private innovation hubs in Busan and Bahrain.
Data Sovereignty, Cloud Balkanization, and Global Policy 5414 Sonal pushes past Teresa's generalized response that 'the world is a small place' by directly raising cloud balkanization, geography, and data sovereignty concerns. Teresa acknowledges that while commercial firms care less, foreign governments actively navigate sovereign policy hurdles.
Compliance Tiers, Architecture Flexibility, and Cybersecurity Standards 4402 Sonal probes whether AWS offers varying spectrums of compliance tiers for lower-risk entities. Teresa educates the host on AWS's global architecture, explaining that security controls deployed in one region are inherited fleet-wide rather than custom-built.
Government Realizations and Shifting Focus to Results 3303 Sonal asks whether government clients are genuinely innovating or simply relieved of basic IT plumbing, noting how novel it is for public agencies to focus on delivered results. Teresa clarifies that while many legacy agencies start by fixing infrastructure, rapid prototyping unlocks genuine innovation.
Public vs. Private Cloud Definitions and Hybrid Cloud Transition 6525 Sonal forcefully challenges the concept of 'hybrid cloud', suggesting it may be a corporate cop-out or buzzword for delaying cloud adoption rather than a true architecture. Teresa counters that large enterprise and public sector entities running critical missions like Homeland Security cannot simply pull the band-aid off overnight.

Statements from this episode (11)

Assertion Partly supported
U.S. government FISMA compliance was an outdated paper-based standard
“They had sort of an outdated security and compliance model called FISMA, which was a paper-based model, which was a law, a mandate for how they looked at security and compliance, and then they moved to this model for cloud called FedRAMP, and FedRAMP is really…”
Teresa Carlson Jan 2, 2019 ▶ 2:19
Insight
Paper-based security compliance is outdated immediately upon printing
“The minute you print it out, it's outdated. You want to look at security and compliance in a continuous manner, right? You want, that's automation, the mechanisms of doing that, and that's what cloud is.”
Teresa Carlson Jan 2, 2019 ▶ 2:59
Disclosure
AWS Public Sector scaled slower than expected, requiring hands-on customer guidance
“Once we got in the door, we felt maybe the customers would scale faster than they actually did. Now, fast forward five and a half years, I'm very pleased with where our customers have gone, but I think we probably didn't realize how much sort of work we would …”
Teresa Carlson Jan 2, 2019 ▶ 5:56
Assertion Supported
UK government mandated a 'why not cloud' requirement for tech procurements
“Liam Maxwell, who's the CTO of the UK government, sort of started the same kind of trend in the UK where he said, we are spending way too much money on tech and not getting the benefits. They've created their own digital service, and they're starting to put al…”
Teresa Carlson Jan 2, 2019 ▶ 7:45
Insight
Middle East startups need business mentoring more than technical support
“The Middle East, I think, is a really good example of what we had to do there was a little bit different. We actually had to create a model for mentoring in terms of business mentoring, because they have some businesses that are really start-uppy there, but we…”
Teresa Carlson Jan 2, 2019 ▶ 11:58
Assertion Not checkable as stated
Middle East commercial companies rely on US and Ireland AWS regions
“We find, believe it or not companies in the Middle East are using our regions here in Northern Virginia or a region in Ireland.”
Teresa Carlson Jan 2, 2019 ▶ 13:16
Prediction Not checkable as stated
Regional blocs like the Nordics and GCC will share cloud infrastructure
“Well, we believe that certain groups of countries will probably come together and say, yeah, we'll use this cloud. So if you think about the Nordics as an example, The Benilects, or you think about the GCC countries.”
Teresa Carlson Jan 2, 2019 ▶ 14:00
Insight
Excessive government compliance standards lock startups out of innovation
“Because we do worry sometimes that if you put too many standards in place, it stagnates both innovation and you're not allowing startup companies to get into that innovative cycle because it sheds them out because their costs get so high on trying to meet a”
Teresa Carlson Jan 2, 2019 ▶ 16:27
Assertion Partly supported
AWS global regions automatically inherit newly launched compliance controls
“When we create a security and compliance control, if we launch it in one region, the others inherit it.”
Teresa Carlson Jan 2, 2019 ▶ 17:53
Assertion Supported
AWS built the U.S. Intelligence Community cloud using standard commercial architecture
“The intelligence community is a cloud that we built. It's exactly like any cloud that we built around the world. It's just on their own network. So by sense, it's their own private cloud, but it is just like any other AWS region. It's just on a different netwo…”
Teresa Carlson Jan 2, 2019 ▶ 25:28
Prediction Not checkable as stated
The hybrid cloud model will remain prevalent for a long time
“Well, in terms of the hybrid cloud model, we believe that's around for a long time, because customers, you know, they're not going to transition overnight, and they need to be able to take advantage of what they built over the years.”
Teresa Carlson Jan 2, 2019 ▶ 26:53
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.