All episodes

Fred Kneip, CEO & founder of CyberGRX

Apple Podcasts Spotify SoundCloud

In this episode:

Fred Kneip, CEO and founder of CyberGRX, is our feature guest this week. News from: CTA, iFly, SendGrid, First Data, the Denver Post, Ping Identity, LogRhythm, Optiv and a lot more!

CISO finalists are out, and it's a familiar bunch!

The Apex Awards CISO of the year finalists are out, and it's three friends of the show. iFly is helping support STEM in our schools. SendGrid is getting ready to IPO, and soon. Sadly, First Data further reduces their footprint in Denver. The Denver Post tells us how to get smart about MFA. Ping's founder tells us about the future of identity. And LogRhythm and Optiv give some guidance for your security program.

Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

This week, Fred Kneip (CEO and founder) sat down with Robb to tell the story of starting and ramping up CyberGRX. CyberGRX is one of the hottest startups in security, was recently named at Denver Gazelle, and looks to have a very bright future. Fred talks about his career at Bridgewater Associates, working for Ray Dalio, where the idea for CyberGRX came from, and a whole lot more.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

  • N/A

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11533 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for October 30th, 2017. Alex, how you doing?

I'm good. How are you, Robb? Doing good. I was out in London this last week, as you know. Uh, the, the jet lag is kind of over me now.

I'm, I'm back to normal. I think I'm ready to go to work this week. I was thinking about starting to talk to you with a British accent, but my British accent is so bad that, you know, people would have thought I was Australian or something like that. Well, you did— you drove on the left side of the road on the way over here. Yeah, exactly.

So that's good enough. I still made it. All right, let's— why don't we go ahead and jump into the news? Before we do, just a reminder, once you sign up for our news— our mailing list, excuse me— sign up for our mailing list if you're, uh, if you haven't already. You can get the show notes delivered into your inbox every Sunday when we release the show, and you'll get to see what we're going to talk about before we talk about it.

Nice. The first story we have today, iFLY, which is the indoor skydiving place in Park Meadows, they now have a STEM program for K through 12 kids. So you can go and skydive and learn about science. It's a pretty cool way to learn about science, right? Physics and math and all the stuff you need in order to fly.

Aerodynamics. Yeah, pretty cool. So they do a program with lots of local schools and they've been bringing a lot of different folks through there. I think they said thousands of kids over the last few years, getting them the free diving and kind of a little lesson to go along with it. Yeah, good to see that that's expanding.

STEM education, I think we all know is important. And they specifically mentioned that they're targeting women and girls to try and help get more women involved with STEM. Absolutely good stuff. Next story this week, it's actually a couple different articles have been written about this this week. SendGrid, which is a local technology company that offers email as a service on the web, is gonna go IPO, it looks like, by the end of this year.

Yeah, I think that's pretty exciting. They noted in there that, you know, SendGrid, who came through Techstars, is gonna be one of the first to IPO from that program. Yeah. So I think that that's big news for the tech community here and for the startup community. I think as we've discussed in the past, you know, to keep that ecosystem going, you need to have these companies that eventually exit and the people can take their money and go do new companies.

Right. So, so this is only the second software company in the Denver area who will IPO since the dot-com boom. So really, it's been a long time without a lot. Rally Software was the other one who IPO'd in 2013, ended up getting sold to CA in 2015. So this would be big news and certainly, you know, good luck to those guys and Dave Campbell, the CISO over there.

Hopefully this goes really well and you guys are really happy with it. Next, not as happy a story. First Data announced that they are cutting 200 jobs at their Greenwich Village office. Yeah, this is, this is a big bummer. First Data is one of the big payment companies in the nation, really in the world.

Denver had been their headquarters from 2001 to 2009. Headquarters moved to Atlanta. And as of 2009, they had about, about 1,500 employees here in Colorado. And I think with this 100 people who are leaving, they're going to be down to very few left here, you know, less than 100, I believe. Yeah, I think they're essentially not going to have a presence in Denver any longer, which is too bad.

Yeah, it is too bad. Certainly a lot of good folks have worked through there over the years. And hopefully, hopefully those folks, anyone who loses a job will quickly find another one. I guess the good news is there's a lot of tech jobs in the area and any of those technologists should have have an easy time landing somewhere softly. Very true.

So also, the CISO of the Year finalists were announced for the CTA APEX Awards. Yeah, so that's great. We can finally talk about who those people are. The CISO of the Year will be given out at the APEX Awards on the 8th, Wednesday the 8th. If you haven't got your tickets yet, it's not too late.

There's a link in the show notes. But it's actually 3 of the friends of the show who are finalists. Sam Masiello, who was the CISO at TeleTech and was nominated for his work at TeleTech. Sam is, of course, now over at Gates Corp. Oh, go ahead. He was so good that he was able to get a, you know, an even better job at Gates, right?

So that's why you become a finalist. So Sam was one of our early interviews on the show. John Everson, the CISO for Dish Networks and Sling, he's one of the finalists, and John was also an interview on the show. And then the third finalist is Matt Shufeldt. Matt is the CISO of Cognizant Health, formerly known as Trizetto, here in Denver.

And Matt's actually our feature interview next week on the show. So Really, 3 great guys. Looking forward to hearing, you know, who ends up winning. So we'll definitely cover that news right after the awards ceremony, but make it to the show if you can. Yeah, it'll be great.

I think both of us will be there. Yep. So next, there was a story in the Denver Post by Tamara Chuang about using 2-factor authentication when you don't have access to a smartphone app or other things like that. Yeah, this is— it's just neat to see this get really kind of in the mainstream. Tamara, who writes for Denver Post about technology, really makes it approachable for non-technical people to understand how do you do multi-factor.

And the question that prompts her article is, hey, I think 2-factor is a good idea, but I don't always have my computer and my phone with me. Is there some way, some way I can do this without having to have 2 devices? So she goes into it in detail, and I think this is a good read for anyone out here who, who might need to explain to your, your mother or, you know, one of your friends how to do these kind of things and maybe use this as a resource going forward. I think it also highlights the fact that while 2-factor authentication is awesome, that everybody should be using it, there is still some barrier of entry to using it on the users. So, you know, you do have to have some other way to verify your identity, and that is going to be a hurdle that some people don't necessarily want to go over.

Yeah, for sure.

Next, next interview— excuse me, next story is an interview with Andre Durand, the CEO and founder of Ping. Where he— it's a— so the link goes to a story that has a video embedded with the whole interview, uh, really talking about what is the future of identity. I just pulled out 2 key points from the article here. Andre's contention is that mobile phones will become the ultimate identity identification device for everyone. You know, this is assumption that people are going to be carrying their phone and the phone can tell you where, you know, where Robb is.

Is Robb awake? Is Robb asleep? All kinds of information about Robb that, that helps you going forward to identify, is this really him making a request? You know, I think that that's, um, it's great insight. It reminds me a little bit of the, the keynote that he gave at Rocky Mountain Information Security Conference this year.

Yeah. Um, but also, I don't think he's looking far enough into the future to when we're going to have those, you know, chips implanted in our brains so we don't even have to carry our phones with us. Yeah, it's not that, it's not that far off, is it? Uh, then the second thing he mentions is just the identity management systems are going to become a lot more fluid and adaptive. So it's not a binary, yes, this is Alex, let him in to everything Alex knows, or no, we're not sure this is Alex.

It's, hey, we're pretty sure this is Alex, so give him the most stuff, but we're not sure enough that we're gonna give him the most sensitive information. And kind of operating on a spectrum of risk versus access and risk versus monitoring is where the future of identity is going, and I think something that we're not that far off from. Yeah, pretty cool. So next, LogRhythm had a blog this week on Uh, entitled Using Honey Credentials to Make Pivoting Detectable. So this was talking about using, uh, what they're calling honey credentials.

So essentially fake login credentials, password hashes, that kind of stuff that you can inject into memory and, you know, inject other places in your network so that when an attacker potentially finds them and tries to use them, you're going to start seeing alarms and can detect that possible pivoting throughout your environment. I, I like to think of it as just putting tripwires everywhere in the environment. I think that this is a super low-tech, super low-cost, highly effective way of knowing have you been owned, right? Putting these types of tripwires throughout your environment, it's not going to stop someone from breaking in, it's not going to stop someone from getting access to your systems, but it does stop them from hanging out in your systems for 6 months before you find out that they're there and before you can react to it. Exactly.

Faster detection meets— means lower impact from breaches. Yep. Next story, Optiv Security has released a new service around GDPR, which is the European Union's General Data Protection requirements, regulation, requirements. Regulation. Regulation.

GDPR. It's an R. It's an R. So this is really an offering they have around walking companies through compliance with GDPR, helping make sure you're hitting all of the boxes you need to. It's nice to see a local company kind of helping get that offering out there, hopefully in time. You know, it's— if you haven't started yet, you need to get started right away. But it looks like Optiv can help you through that process if you need to.

I like the fact that they were very regimented about it too. It wasn't just, oh yeah, yeah, we know GDPR and, you know, we can help you do that stuff. They lay out everything that they can do and all the steps and everything. I thought that was really cool. And then finally, our own Robb Reck is going to be on 9 News on Monday morning.

Yeah, I get to talk to Gary Shapiro, who's the main anchor for the 9News morning show, talking about cybersecurity. It's kind of the end of National Cybersecurity Awareness Month, and that's what the topic is. And I will do my best to at least mention Colorado Equal Security on there. And of course, we'll get the link to that once it's posted on the web, and we'll put it in next week's show notes. So is this gonna be live on 9News, Robb, if people wanna watch?

I think it's supposed to be live, yeah, 8:50 AM. We think probably Channel 20, which does their 9 news at 8 o'clock. Yeah, because I believe it at that time on Channel 9 is the Today Show. And yeah, you know, that would be pretty cool for you to be on the Today Show, but I don't think you're gonna be on the Today Show. They've made it very clear to me that I, I could be preempted for, for real news.

And if you guys saw the news, the Mueller investigation says there's— Mueller, they have— they now have some arrest warrants. So there might be real news tomorrow morning. So who knows, right? All right, why don't we go ahead and jump over to trivia? So this week we did have a successful answer to our trivia question.

Yay! And we did not ask the winner if we could give his name out. So I will not give out your name, sir. But congratulations. And thank you to Andre Durant— or excuse me, Andre Gaeta.

Once again, Andre has personally sponsored our trivia contest and has purchased a lovely shirt for our winner. So don't bury the lead though, Robb. We got to tell people what the actual answer was, right? Well, we got to tell them what the question was first, right? So what was the name of the role or job that was created to protect gold and other valuables in Colorado and other railroads when the U.S.

Marshals forces were insufficient in the 1800s? So the answer was the Pinkertons. The Pinkertons— what I— that's where I remember hearing from some Old West movies. Yep. People kind of speaking of the Pinkertons, a little bit afraid of them.

Right, right, exactly. Yeah. Yep. Private security force. Good stuff.

All right, go ahead. So this week's trivia question, we are going to go with our other sort. So we're talking about stuff on the podcast. So you'll have to go back and make sure that you've listened to some of our previous podcasts. Name 2 of the podcast guest hosts.

So as you know, from time to time, I am not here or Robb is not here and we invite guest hosts in. So if you can name 2 of those, then you will be our trivia winner for this week. Should we tell them how many there are total? Just leave it at that? No, no, you just gotta get 2.

All right, all right, good enough. Let's go ahead and go over to events. As a reminder, we do have a calendar of events on the website. You can go see what's going on next week, next month, all the way out into January at this point. There's not a ton of events the next 2 weeks, but there are a ton of big events.

The events that we do have are quite impressive. Uh, so first, uh, the first and second is Secure World Denver. Um, I will be teaching a class there. Um, Robb also will be there, uh, kicking off the, the conference. I get to introduce, uh, Dr. Ponemon, Larry Ponemon, who's going to be doing the opening keynote.

And, uh, hopefully if you guys are there, come say hi and ask us for a Colorado Equal Security sticker or something like that, and we'll be happy to hook you up. And there are also, as we mentioned last week or potentially the week before. There are a whole lot of local folks that are speaking at SecureWorld. It was last week. Yeah.

NCC has their Governor's Cyber Symposium this week. That's the 1st through the 3rd. Last week we talked about it. If you haven't signed up yet, it's not too late. A lot of big names going to be there, including General Petraeus, the governor himself, and a lot of interesting folks.

On the 6th, DENSEC is having their South meetup. And once again, make sure you follow them on Twitter to find out exactly where they're going to be, what table at what restaurant. Go talk to some interesting security folks. On the 7th, SecureSet has their Hacking 101 workshop on AppSec. On the 8th, Cloud Security Alliance is doing a CCSK training.

This is the day before their fall summit, but it's a for-pay training that goes along with that. Is Muhammad doing that training? Yeah, Muhammad is doing it. You got it. Awesome.

Also on the 8th, we talked about this earlier, the CTA is doing the APEX Awards. Come see who was the CISO of the year. Come say hi to Alex and I there. On the 9th, ISSA Denver is doing a GDPR training, and we have Pete Lindstrom coming in to do that, right? Yep.

IDG analyst is going to be in town. It's a really strong, strong guy. Pete is fantastic and going to be doing some really good training. Looking forward to that. On the 9th is the CSA Colorado Fall Summit.

This is the CSA's big annual conference. It's up in Broomfield or Westminster, up really far north somewhere up there. Um, so the Great White North. It looks like a really good— some really good content though. Hopefully you guys can make it.

And I think that is all we have for, uh, events this week. Jump into jobs. Move to jobs. Uh, first, uh, GE is looking for an IT cybersecurity engineer. Pearson, the education company, is hiring a cloud security engineer focused on identity and access.

Fast Enterprises is looking for an information security analyst. Progressive AS is hiring a senior information security auditor. I'm guessing AS is auto insurance. It's not. So I actually looked it up.

It looks like it's a staffing company or a staff company. It's not Progressive Insurance. Yeah. Okay. Interesting.

Cigna is looking for a cyber threat responder and malware analyst. That one looks like fun. Yeah. CHI is hiring a cybersecurity engineer 3. Which is, as you would expect, 3 times as good as a normal cybersecurity engineer.

Splunk is looking for a professional services security consultant. So if you know Splunk and want to help other people with their Splunk instances. And the last one, my favorite, the FBI is hiring for special agents right now. And of course, a special agent at this point gets to do a lot of cybersecurity work. And that's really one of the key skill sets they're looking for.

Another key skill set is you have to be able to run really quickly, do lots of push-ups and be willing to shoot people past their physical security. And of course, be willing to shoot people. Yeah. Yeah. Well, that is it.

End of the newscast. We have for our feature interview this week, Fred Kneipp, the CEO and founder of CyberGRX. We've talked about them on the show for the last 9 months. One of the big up-and-comers in Denver, the gazelle, as named by the CTA recently. So get to hear a little bit about how it came to be and where they're planning to go.

Awesome. Should be a good interview. All right. Well, Alex, have a good one. We'll talk to you next week.

Thanks, Robb. Hi, this is Chris Martinez, CISO at Digital Globe. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

This is Robb Reck, and I am today sitting in the new headquarters for CyberGRX in downtown Denver. I'm sitting with the CEO and founder, Fred— is it Kneipp? Kneipp. Fred, thank you so much for having me. Thanks for taking some time out this afternoon to talk.

I'm going to start with the first question of the day. What would you say is the most important lesson that your father taught you? Most important lesson my father taught me.

That's interesting. I think it's an interesting, applicable in many ways life. It was know what you don't know. And it was a recognize that you can be really good at some things, but you can't be great at everything, and appreciate that and find those who do. That's awesome.

It's also similar to Rumsfeld, right? The known unknown. No one out there could ever actually say it the way Rumsfeld did. Yeah, that's pretty great. Well, so I don't know, were you— you probably weren't there for the keynote at RMISC.

Cal Fussman kicked us off this year, and in his He's an interviewer for Esquire Magazine, and his point to us was like, start conversations by getting a little bit more personal and intimate, and it kind of changes the whole texture of the conversation. So that's my secret for why I just asked you that question. All right. So you are doing some really cool stuff here at CyberGRX. I'd like to go further back though and understand what's your background?

How did you first get into security? I know you actually ran security programs for a while, but Let's go back even further. How did you get into technology, and how'd you end up doing what you've been doing? Sure, it's actually a pretty unorthodox path to getting to a cybersecurity company. My background is actually mostly in finance and investing.

So I worked at a few private equity funds back in the kind of 2000s range, realized that I was being charged with running companies and didn't know what I was doing, so I went back to business school. Ended up spending 7 years at McKinsey after that, helping large multinational companies with growth strategy, acquisition strategy, and such. Yeah. And was pulled over to a unique hedge fund called Bridgewater Associates. The Bridgewater approach was take subject matter experts and pair them with quality managers, and synthetically, that's what you need to run different areas.

So I was the manager counterpart to a an SEC prosecutor. The 2 of us ran the compliance department at Bridgewater. And so that was my introduction into just the, um, this whole realm. Um, I did that for about a year, and then I was charged with running the security department, uh, for about 2 and a half years after that, and where I had a CISO, a head of staff security, head of physical security, all with deep content knowledge. One was the former CISO at, I think, UBS.

The other was the the former head of counterterrorism for the FBI, was our head of staff security. And so it was, you know, highly qualified individuals. My job was synthesizing across all that content to a cohesive strategy, and what should we do to build this thing out. That's a pretty big change though, right? Mergers and acquisitions to really running the security.

How do you make that kind of a transition? It's more kind of logical breakdown of the problem and then communication around that. Okay, what are the things that are driving this? What's the issue we're actually facing? How do you articulate that?

And then what's the fact base that's influencing that on the path forward? And then, you know, you can apply that universally. That's kind of the McKinsey model, is you get smart people who get just thrown into wherever. You have generalists there, you know, a healthcare study, and then you move to an automotive, and then to a finance company. And so it's just the same kind of problem-solving breakdown.

So that's what I was doing at Bridgewater. So you were at Bridgewater for how long? 4 years. All right, and something exciting happened near the end, I assume. No, no, it was actually, interestingly, I was one of the more tenured people there, even though there was 1,500 people.

At 4 years, the turnover is pretty great. It's a unique place, and Ray Dalio, the founder, just came out with a book about his principles, which I think is getting a lot of press. He was on the Tim Ferriss Show, I think. If folks haven't ever heard him, that interview with Tim Ferriss is really amazing, and total transparency is really the message. Right.

Which I, which I believe that's what drew me in. And the, you know, the core tenets of Bridgewater that Ray has really pushed are, you know, radical truth, radical transparency, which was basically, you know, in terms of communication, don't hold back and don't allow it to be colored with, you know, trying to cushion the blow. Give it to people straight. And that's how you'll help them grow. It can be difficult.

It can be painful. But that's, you know, if you think about if you play sports, You know, if you had a batting coach, you know, they don't come over and say, hey, nice swing, let's try another one. They're like, okay, spread your legs further, keep your eye on the ball, etc. It's the same kind of thing with business. It's okay, Fred, you know, that presentation didn't resonate at all.

Here's why. You didn't do this, this, and this. And then it's a little bit deeper of why didn't you do that? Did you not think you needed to? Did you not know it, etc.?

So it forces you to really think about your strengths and weaknesses, which is, which was really helpful for me. But as my A former colleague there just said it was like, I'm glad I went, I'm glad I left. So it's a— it was, it was a time for me to go. Um, and when I was thinking about leaving, I got connected to, um, Jay Leake, who was at the time the CISO at Blackstone. And, uh, he and I were just talking about potential business opportunities.

I was looking to start a business. I was excited to just go and do something and, and build something meaningful for me. And he had mentioned the idea of this third-party risk concept. And how that was a real problem for Blackstone and its portfolio. And we kind of sketched out, here's what this could look like.

So I wish I could take credit for the idea. It's really Jay's. Yeah. But we kind of built that out together. So before we move all the way on, I just want to ask about the radical transparency.

Do you— was it good or bad or both? Both. And how much of that have you taken with you? You know, it's a great question. It's, um, it's, it's a fantastic concept, and it It really brought me in, and the people who I worked closely with believed honestly in it.

And the problem is, for it to truly work, you need to eliminate the humanity in people and the kind of emotional element. If I can operate with pure, direct, logical interaction with you, then it works. The Bridgewater approach works perfectly. But, you know, people have wants, desires, ego, emotion in it. You have to account for it, and that's why I don't believe it fully works there.

Yeah. The other element that is, um, is interesting is it's, um, it can be used to kind of influence arguments. And, and so it's a, um, for those who have a better grasp of the way it operates. And so it's, um, you know, it was harder, and I kind of lost my, my faith in that over time. I've pulled a lot of, um, foundational components into the culture we've built here at CyberGRX, but it's with a recognition that you can't be all the way to the extreme.

You have to recognize some level of the human. But at the same time, if we haven't built cultural norms around that radical transparency, radical truth, then if I just am radically honest with you, it's gonna be perceived very negatively, right? It's gonna really hurt feelings. If we haven't set expectations that that's normal. So do you mind just talking about a little bit of how you think about that?

Well, sure. I mean, so as we, you know, built from the first employee here, it's a very open, direct interview process of this is how we want to operate and be ready for that, and that we think that's going to be right, and we expect you to both take it and also to give it. Like, you need to engage and you can't just hold back. And if, you know, I have employees coming in here telling me, Fred, that wasn't dumbest thing I saw in a long time. I was like, you know what, great, I'm glad you told me that because I need to hear that.

And it's, you know, I make mistakes left and right. If people aren't comfortable saying that, that doesn't, you know, then we'll go off on the wrong path, right? And just like the same, if I see that, if I see things, I'm gonna raise it. The, the right way to do it though is, it's like one of my favorite quotes is St. Francis of Assisi, which is to try to understand versus be understood. Which is, okay, if someone feels that way, someone sees something differently, Why?

Where's their— what's their logic? Where's their reasoning? Do they see something that you don't see? And either you're gonna help educate them or they're gonna help educate you. And so that's, that's our culture here.

It's not for everyone. And it's, you know, if you're looking for that kind of, you know, simple, you know, everything's happy-go-lucky place, that's not the right thing here. But we believe that interaction is the right way to have— to really help build, I think, a stellar product. That's great. And So you just quoted the— I think it's called the Prayer of Saint Francis.

I'm not Catholic, but it's, uh, it's really cool. And those listening might want to look it up. I think it's one of the cooler, like, uh, way— I think it's one way to look at how to go about life, right? Not to spend more time trying to think about how to understand and how to, how to, how to help other people versus trying to get helped. It's funny, I was at a talk with Pete Coors last night, and one of the things he said is, you know, God gave us 2 ears and 1 mouth, you know, you should use them in that proportion.

It's a similar, you know, along the same lines. Great. Just stepping back and thinking about it. When we spend so much of our time trying to convince— it's interesting, even to read it in kind of sales things, it's like, oh, don't go in there trying to pitch your product. You have to understand the problem.

You have to understand— same thing here is, okay, don't try and convince people of what you see. Understand why they see something differently, and is there a nugget in there that you might have missed otherwise? Yeah, well, let's, let's go ahead and go forward. You met with Jay, Jay Lee from Blackstone. You started talking about what this idea could be, and then what happened?

Yeah, so it's, um, I mean, the simple idea for CyberDirex is, is third-party risk management. Basically, how do you efficiently assess or understand the risks that exist outside of your boundaries of your company? So the best example example I can give you is, you know, Apple designs the iPhone and they have very good security. They've protected their walls pretty well. They have all the right stuff internally, but they take those, you know, highly classified plans and they send them over to Foxconn for them to build the phone.

So how do they know Foxconn has the same protections in place versus a hacker saying, okay, I'm not going after Apple, that's protected, but I can go pick it up here or in transit or whatever it is. And so how do you collaborate? And so people's environments today know, they outsource HR, they outsource legal, they outsource manufacturing, and, or, you know, Salesforce type thing. And so how do you keep your head around that ecosystem? What happens today is just convoluted and a waste.

The specific example for Blackstone, so Jay had responsibilities as the CISO at Blackstone. He was charged with securing Blackstone, but then also helping build the security programs across across their 120 portfolio companies. And that meant either placing a CISO or helping them, you know, build out the program, identifying areas of focus. One thing that kept coming up was third party. Like, we don't have much of a program, we're not doing much, we're concerned about it, et cetera.

He did a quick poll and found that of their companies, 90 of them were using the same, I'll say, business process outsourcing company, and of those 90, 50 of them were sending people on-site do a validated assessment of that control set every year. Like, okay, that's a colossal waste of time and energy. Why do that? He said, why don't I do that once at Blackstone, do one high-quality assessment of the program, and then share it across not just the 50 but all 90? And so now they've all got access to that.

He reached out to the CISO at that company and basically said, hey, we're thinking about coming really in-depth once a year versus 50 visits. And they're like, that sounds fine. And, and that, that was the origin of this concept. Yeah, and so that's our whole model is we'll go in, we'll do a high-quality assessment of a company, we'll house that data centrally and allow it to be used multiple times, and then that access is available as they update that assessment. So it's kind of a real-time— you can watch versus a once a year, once every 2 years, once every 3 years.

It's I have live access to fresh, up-to-date information on what their program looks like. The So, you know, we're not the first people to think of something like this. You know, there are, you know, processes, I think BITS came out with something, Shared Assessments is known out there, the SIG, which, you know, I'm sure most people probably listening to this podcast have come across at some point in their life. Moody's tried to do something here, S&P tried to do something here. There was a long list of, you know, I guess efforts in this front.

So we went and actually spoke to most people who were involved in each of these people, the kind of the founding team at Shared Assessments, or people who helped build some of the products in healthcare that are working in this fund, etc., and said, okay, where did you struggle? Why aren't these taking off? What's the— and learned from that. It's a long conversation, but kind of a variety of key things, a lot of which was that a lot of the burden and pain was put on the third party or the vendor. It was like, you're charged with paying for a certification of some kind, etc., and then people come and say, that's great, now do my questionnaire as well.

And it's like, what am I— you know, it's painful. Yeah, so you're going to do a SOC 2, or you're going to do an ISO 27001 certification, and that's going to get a small percentage of what this big bank asked. Correct. And so, why did I just spend $50,000 to get this certification, and these guys are still asking for this, even though they're telling me I need to be certified? As well.

And so, and a variety of other factors. So what we ended up doing is saying instead of the approaches that have been taken before, the other, you know, the SIG was really derived from, you know, a bunch of banks got together and said, okay, put all of our questionnaires together, we aggregate them, and by definition if you answer all these questions, you've now answered all of our questionnaires. But that was this huge unwieldy mess. I think it was about 1,500 questions. Yeah, and then it's been culled massively.

The first one was over 3,600, I believe. And so it was huge. And so, you know, that's struggled and it's not in the flow that would make sense. So what we did is said, okay, let's take some, you know, a few well-regarded risk practitioners and let's build an assessment based on how they think about risk. And so what Jay and I did is we built a team of, we call them design partners, and these were people that were kind of leaders in their field, forward-thinking, building the most mature programs out there, and wanted to walk through with them and say, guys, how do we collaboratively build the right answer to this?

And so the ask of them was, you know, you need to have obviously the funds to build a program on that front, you have to be mature, forward-thinking, and then you need to be willing to kind of collaborate versus a lot of people say, great, I'm happy to do this as long as it's my assessment. You had to be able to put that aside. And so we brought people like Jim Ralph at Aetna and Roland Claudier at ADP, Paul Wood at Bloomberg, obviously Jay or Shree Ramaraju at MassMutual. And we went through and spent, you know, weeks upon weeks at each of their locations, said, walk me through your program. How do you think about risk?

How do you, you know, collect information? How do you score it? How do you evaluate it? How do you track it over time? How do you report on it, etc.?

We then mapped that to kind of a standard framework that was derived from our head of products, Pat Gorman, who was the CISO at Bank of America. And so, and we mapped that to much more to how an organization is structured. So it's a, you know, it's close to NIST, but it's more, okay, this is how he built his organization at B of A. We then tested that with our design partners, like, oh, this is much more aligned. What that led us to is ability to delegate out portions very easily versus, oh, there's a question here, a question there, a question there.

And so we built this out, we sat down with each of our design partners, then we brought them together and said, 4 of you want to go this way, 2 of you go this way, we're going to put this thing in the middle. So instead of 27 questions across all this, we're going to ask these 3. Do we all agree that that gets to the meat of what we're trying to do? And they did, and we got there. So now we said, okay, we have a risk-based approach approach to collecting information that's as concise as possible that still gets the information that you need.

And that's how we built our questionnaire. And that took a long time, and— but it's, you know, we're pretty excited about where it came out in that we now have a data set that's easy to populate, that solves the needs for some of the best programs out there, and then allows us to use that as a scalable way to go and build that out across, you know, a broader reach. One thing that we learned through that process is collecting and housing the data is one thing, but what people are really looking for is a means to then act upon that. What do I do? And so what we did is 2 things.

One is we structured our assessment to be purely structured content. So instead of a description of, tell me about your incident response program, and as a long paragraph describing all that. It's very— it's, you know, incident response program has 6 different categories. Which of these do you do? Walk me through kind of level of coverage here, here, and here.

This percentage, this percentage. And so it— what it is is a data set on the backend which is very sortable, manipulable, etc., and allows us to actually map it against known breaches and kill chains for those breaches to say, okay, if I look in your industry, the most common type of attack is like this, and it goes after these top controls so I can help prioritize what makes sense or what controls are most relevant. And so what you've done is you've now moved a job that was a morass of, you know, countless different Excel files and stuff being sent around to a centralized dataset that can be sorted, manipulated appropriately, and prioritized so people can take action upon it. So, you know, I know you don't want to hear the whole thing about the product. No, no, that's great.

That— I think that sets expectations for what we're talking about I think from my conversations with you guys previously, there's a couple different levels, right? So what you just described is somewhat of a direct replacement for the security questionnaire that comes in and fill out. That's right. I call it a self-attestation around these questions, but don't you guys have another level that's kind of a validated interview as well? We do, and it's exactly right.

So recognizing that people have different tiers of experience exposure, right? It's, you know, as you think about, uh, for Ping, there's certain suppliers you say, okay, these guys, critical access, critical information, we allow them on site, we give them credentials, whatever it happens to be. That's our Tier 1 group, all the way down to a Tier 3, which is where, you know, it's someone who, you know, may have some level of risk, but I've deprioritized it. They may have limited access, whatever it happens. And so we've structured our assessment of that.

So you're right, we have for that lowest tier is a self-attestation. It very easily— it's going to— slightly abridged version of the assessment, but very easy to accomplish, very, you know, cost-effective. And then you go up to our Tier 1 where we actually send people on site to validate the controls, to confirm that when they say they have this phishing policy in place, that it actually is there, that we'll look at a screenshot of a firewall configuration, whatever it happens to be. And so that, that will be our full the full detail there. So that gives you the confidence to know that this data has been validated and vetted, and it is a high degree of accuracy there for, you know, the risks that are the highest for you.

And the business model, like, for the enterprises who want to have— who want to review their vendors, they're paying you guys a prorated amount of money for the assessment, so they're not paying for a full assessment because Help me understand how that works for them. Well, so we, I mean, our model makes sense when we sell an assessment multiple times. Yeah. And so our job is to kind of get the right companies into the database and then drive multiple orders from that. If we do a single assessment of a company and it's only purchased by one customer, we lose money.

Okay. We don't cover the cost of our process. But if we sell it 50 times, it works well for us. Yeah. You know, and we expect, you know, when I go to a company, we expect the average across the court.

Some of them will be, you know, like ADP or Salesforce that we believe will sell quite a few of, and then others will be some bespoke law firm that they use that we may be the only one, they may be the only one ordering on that. And so across the portfolio, we will make money. Some will lose money on and some will make money on. So is the cost the same? Correct.

You don't, you don't say we're gonna, you're gonna pay less for Salesforce and more for the bespoke law firm? Yeah, it costs the same for the tier regardless of the company, and so it allows the practitioner to then say, you know, I'm spending money based on risk. Yeah, so it sounds to me like there's really a network effect for both sides that's really important here. In order for you to go get new enterprises, you really have to have the vendors who are willing to either have already been through the assessment, so not only are you saving them money, you're also saving them time, right? You already have the assessment you can hand them today.

That's a huge value add. And then on the other side, for the vendors, you know, if you come walk up to, you know, that bespoke law firm, they're like, well, why would I let you guys do that until I have, you know, oh, now, you know, I had 60 different customers who were gonna ask to do assessments, and I can just do one and it goes away. So how do you, that to me seems like the big hill for you to climb. How do you get around that network effect And how do you build the momentum? It's a self-reinforcing thing, right?

The more companies we have, the more attractive it is to the customers. The more customers we have, the more attractive it is to the vendors. It drives that way. The way we built it out is we started with our design partners, and these are large organizations who then, you know, started with our initial orders, and they were able to reach out, and they're influential, big enough companies that people said, great, I'll do that. And what we found though is a lot of the companies who will do an assessment for them will then say, hey, I'd like to share this assessment with other people proactively.

They'll reach out, those companies will say yes, and those companies now say, oh, that's interesting, can I use this for other? And so it kind of perpetuates in that way. Yeah. But no, it's, you know, we're in the process of seeding that now. We really just came to market in kind of April of this year, so it's still 6 months in.

Yeah, still pretty early. And, you know, we're building it up and And it's, it's pretty exciting. What we found pretty interesting is, you know, we did expect a bit of resistance, as you were talking about, for the companies coming onto the platform. And part of the way we tried to address that, learning from our early research, was one, it costs nothing. So to be a company coming onto the platform, you come on, you're assessed by CyberGRX.

It's the cost of your time to go through that process. But what you get on that is the ability to share that proactively with any of your customers, as well as you can consume that assessment. You have an independent risk assessment that's available to you and updated based on our scoring methodology as you update your program, which you can do at your discretion. Yeah. And so you have tools.

We have several people who are using it to report to their board. They're saying, okay, this is a— this CyberGX assessment is showing you what my program looks like over time. Yeah, that's interesting. And we, we did, you know, you get the learnings of a startup, and that, you know, the first time we were sending out an email saying, welcome to CyberDirect, this is going to be great, and we were getting kind of a 10% response rate. So, like, okay, that's a problem.

We found, you know, then when we reach out to these new vendors coming onto the platform and spend sometimes 10 minutes, sometimes more on the phone, we're now— we just did a measure the other day— we're at just between 3% and 4% turn us down. So, you know, the vast majority say, I get it, I want to do it, and that ranges from people like Salesforce and Iron Mountain all the way down to the small law firms we talked about. Okay, well, that's great. I'd like to maybe shift a little bit from talking about the solution to talking a little bit about the sausage-making of building a company. Sure.

You know, how'd you go from the idea to, like, you know, you guys are now making lists of fastest-growing companies, and you guys are a gazelle in Denver Startup Week this week. So how— what did that process look like from the idea to where you are right now? Yeah, it's complete mayhem, but it's, um, It's fun. What's neat about starting a company and finding the right people early on is you're doing it, you know, you by definition have quit a well-paying job and all these other things, and so you're doing it because you're excited about it. You have that passion, and that's what's really fun.

You're going to make a ton of mistakes, and you make these crazy assumptions and such, but what's neat is you're sitting there, you know, and we were in the kitchen of one of my the early employee's house for, you know, weeks on end because we didn't have any place to go, and just powering through, and sometimes literally all through the night without even realizing it. And so it's fun. The other thing you have to recognize, and I think we did a— we were lucky in our involvement with our design partners, is so many people will start companies with, I have this really cool idea, I'm gonna build it all out, and now we'll bring it to the market, and they don't— they maybe don't want that. They don't see it. What we're able to do is we identified a real problem.

Like, Jay had this real issue with Blackstone. I knew it firsthand from my time at Bridgewater. Like, we— oh my god, it was a mess trying to do third-party risk there. And so we knew there was a market demand, and that was really helpful to know that you're tapping into something that can really influence others. To your question, I mean, it really— it's, you know, it's kind of oversaid.

It's all about the people you bring together. And it's, it's kind of, can you work together? Are you excited about this? Um, do you have that passion to pull it together? Because you're gonna, you're gonna be hit left and right on a variety of things.

Um, and you can celebrate the successes together, but then also kind of hunker down together. And then, and then recognizing when you don't have what you need and what, you know, when you need to bring in more or when you might have missed something. And that's, you know, oftentimes harder than it looks. Uh, you didn't start in Denver, right? That's correct.

Where'd you start? We started in Westport, Connecticut, because that's where I was living at the time. That's the original headquarters. We say we— was it just you or was there other employees? So I, I was the first employee, and then, uh, you know, a few weeks later we added a few others.

But in Connecticut? So we were fully distributed and we started in Connecticut. Okay. I was in Connecticut. So it was your basement at the headquarters, or was there an office?

It was, it was the office and then the third floor of our house. Okay. Yeah. And so yeah, that was, um, But, uh, no, so at the time, you know, we had about 5 people originally, and it was myself in Connecticut, someone in Phoenix, someone in DC, uh, someone in Kansas City, and someone in Florida. Okay, uh, you got the, you got the continental US covered.

Yeah, good coverage in that sense. Um, and, uh, but we knew, you know, I knew from trying to recruit people to Bridgewater, uh, particularly in the cybersecurity space You know, people didn't want to be there. It's too far out of New York, etc. So, we weren't going to start this there. And so, we looked around, and one of my earliest co-founders was, you know, he'd worked at Booz Allen before, and they'd done an analysis on where pockets of cybersecurity talent would be growing over the next decade.

And it was a few years dated, but it still was pretty relevant. And, you know, obviously, it was the coast. Um, you know, Boston, New York, DC, a little bit here in Nashville, I think, and Raleigh-Durham, etc. And then obviously California, little pocket, and Portland and Salt Lake City. And then 2 big other options were San Antonio-Austin and Denver-Boulder.

Yeah, those 2 stood out. And you overlay kind of cost of living and quality of life, and we kind of took the coasts off. I spent my whole life on the East Coast, so And so we looked at Austin. I went down there and toured around and met some people there. And then we came out to Denver and it was a no-brainer.

Yeah. So it's kind of a running joke on the podcast. It's every list of cities has Denver and Austin right next to each other. We are, we are twins. I'm glad I just didn't disappoint.

Yeah. Well done for that. So when did you guys move to Denver? When did you move to Denver? August of last year.

Okay. So just a little over a year ago. Just over a year ago. And you spent 6 months. Maybe that's even 8 months in kind of stealth mode developing a platform?

More or less, yeah. And really laying out, the biggest thing was actually just starting with our questionnaire. What are we going to ask and how are we going to interpret that information? When you're working through with 6 different strong-willed organizations and then getting them, trying to bring, you probably know this as well, trying to bring 5 or 6 CISOs in a room and trying to get them all to agree on a way to assess a company was, took a lot of work. They all have unique and usually pretty good reasons for the unique way that they do things, right?

Right. And that's a challenge for sure. So you guys got some, I think I've seen it, some pretty big news about funding you guys have received. Is there anything you can share around who's backing you guys and really what that's for? Yeah, sure, no, that's public.

So we, you know, the original, So obviously with Jay, Blackstone was our seed, like our first money, and we raised a Series A kind of the beginning of 2016. And 2016 or 2017? In 2016. Okay. And, and so we raised, and that was, you know, Blackstone.

We brought in some of the dedicated cybersecurity investment firms like 1011 Ventures and Allegiance Capital, and then we had all of our— the majority of our design partners invested. So MassMutual Ventures, Aetna Ventures, Bloomberg Ventures. We also had Google Ventures invest and a few others. And then a couple, you know, smaller investors like Mike McConnell, former head of the NSA, or Art Coviello from RSA, etc., kind of put personal capital. Yeah.

And so that was, you know, we had a pretty broad field because we wanted to, you know, get ideas and get interested and get some people who are fans, right? And so, I know it's good They've been great partners, and it's been fun because you get just a wealth of ideas, and they've been— it's a really helpful board to have helping us then. We raised additional capital in April of this year, and that was led by Bassettmore Ventures, and then actually every single one of our previous investors kind of trued up. Can you say how much you've raised, or how much this— We've raised a total of $29 million. $29 million, okay.

$29 million, and you guys, how many employees you got right now? We're about 55. 55 employees, so you're growing quickly from an employee headcount perspective. How's the top line, how's revenue going? It's good, it's good.

I mean, it's, you know, this year, you know, we're holding back on telling you the exact numbers, but it's, you know, it's growing exponential. Yeah, well, good for you. So for those people, one of the reasons I really love to talk to to the founders of local companies. Number one, I think we all want to hear your story and know the unique things going on, you know, the security automation orchestration play that no one knew was in Denver. It's a fun story, and hearing that this really, it's a big, you have a big vision, right?

A single platform where we can get the security posture for every vendor worth knowing, right? That's a place you can go get it at your fingertips, on demand, for a reasonable cost. That's— I love that. I love the vision of what you're doing. But one of the reasons I'd like to get you on here, in addition to hearing what you're doing, is also for folks who you may want to hire in the area.

So what kind of positions might you be looking to hire in Denver, and what kind of folks would you like to apply for those? Oh sure. We are, you know, it's really right now about just constantly delivering more of the features on our platform. So we're looking for engineers, front-end, back-end, Primarily frontend, actually, and as well as product managers, product owners come into that area. We're also building up a sales team too, and so on that front, you know, our— the core of this has really been a lot focused on the product development.

We have a very large analytics team that's built a lot of our backend models. These are the math PhDs and NSA guys who are kind of getting out to see the light for the first time in a while. And it's been neat to see what they've developed, and we've got an assessment team pretty well built, but now we're really scaling up our engineering team. So those are the areas of focus right now. We've hired, I think, 5 engineers in the last 2 months, and so we look to probably hire another 5 to 10 by the end of the year.

That's great. What particular languages or skill sets or experience are you looking for for engineering? So Justin, our VP of Engineering, will yell at me for not knowing all all these to put out there. No worries. But it's, yeah, so now you're stretching.

If you think about my background, I'm not a coder, and I don't even want to dare put something out there that's wrong. So what's the ideal customer profile look like for you? Is it, I mean, obviously everyone wants to sell into large enterprises, but is it just large enterprises? Do you see a play in other places as well? Yeah, no, it's actually, it's not necessarily large enterprises.

The reason is the, I'd say more, kind of the lower end of large enterprise, and it depends on how people define, you know, where those are. The thing for us is someone who has, you know, never built a third-party risk program, our platform is actually great for them to start that out. That being said, they typically haven't prioritized it, and it's an uphill, you know, sell for them to just, you know, dive full into this. And then the other end of the spectrum, the people who've built a whole program around this already, and they have a whole 100 people who are touring the country doing assessments, et cetera. It's an infrastructure that's already in place, and we're asking them to kind of rip it out.

It's harder. So, JP Morgan right now is spending tens of millions of dollars on third-party cyber risk alone, and they have a huge team in place that we're not even talking to them. But in between, these are Fortune 500-type companies who have 1 or 2 people and are saying, okay, I just did 50 assessments last year, I need to do 400 next year to try and keep pace. Literally, they don't know how to do it, and we fit that perfectly. I can think of a lot of companies in town, many companies in town, and you all know who I'm talking to, who use a spreadsheet to track, you know, the top vendors for them.

And let's say they have 200 vendors that they're tracking, and 30 of them make the the category of being worth evaluating, and they send a spreadsheet out to those 30 people, and then they manually themselves, or maybe they have an analyst review that spreadsheet when it comes back in, and maybe they do 3 or 4 onsite visits because that's a really high-risk one. That kind of a vendor customer, is that big enough, you think, that works for you guys at Scale? No, this, I mean, our solution to me is that that's the exact, exact need right there. It's because you're basically saying, okay, well, we'll help you when we have— I haven't gone into the details on this, but in the front end, we have a tool to help you basically determine the inherent risk of your portfolio. Of those 40, which are the ones that you really want to pay the most attention to?

And that would map to our Tier 1, 2, and 3 offerings. And you can select how you choose, but it's a way to help think through that. And then once you do the— once the assessment comes in, based on how you use that vendor, we'll have a couple questions up front. The data is tailored to the use case that's relevant for you, gives you actionable information, and you can use the platform to actually connect back and request remediation or monitoring and such on those fronts. What's also pretty cool is for a company like that is, you know, I'll give you something for us, right?

So we're a small startup here and we use AWS, and so, you know, they're a critical supplier for us. Yeah. And so we reached out to them, you know, for fun, actually, and said, hey, we need you to fill out a CyberGRX, and they said, that's cute. But as we talked to them and they understood the power of the platform, they've now come onto the platform. One of the big reasons is they're saying, you know, we're proud of our security, we want to share that with everyone, but, you know, we don't have the time to respond to the 100,000 companies that are on the platform.

But with CyberGRX, for us to authorize access is just a click of a button. So you guys coming on Now we have a robust, secure, third-party risk management platform with data on Salesforce and AWS, because they were brought on by Aetna or others. That's a compelling case, yeah. So, I think that's a great story, and I think hopefully we left enough info out there for folks who are looking at revamping a third-party risk program this year to maybe give you guys a call. And I want to change topics on you now and just talk about You know, you've been here for a little over a year in Denver.

What's it— what's your experience been like getting into the community? You know, I want to hear the good and the bad of it. Talk to me so far about what Denver has been like from a, from a business leader and a security business leader perspective. Yeah, I gotta tell you, it's, um, it's been great. What's, what's neat about it is it's, it's that kind of Goldilocks size of it's big enough that there's a real security community, and it's small enough that people are, they know each other and they're trying to help.

And so I found, you know, within a few months, you know, I'm reaching out and I'm having breakfast or lunch with, you know, CEOs like Scott or Brian at Red Canary, or Andre, or other. And so, you know, I just had lunch last week with Andy from LogRhythm, and it's a, sure, let's talk to each other, let's help, let's share the problem, and it's a, let's figure out how to help build the community. You know, we recognize there's— that we all benefit from working together, and it's really been helpful in just bouncing some ideas off of them as well as talking about what we can do to, to support the community at large. How do we get more, you know, people focused in building, you know, cybersecurity majors in school or building programs like SecureSet, which has been a boon for us because the people coming out of there are kind of very well trained to what we're trying to do. Yeah.

As well as You know, and trying to also bring in additional investment to try and drive more security companies around here. So it's been really exciting to do that, and I feel that sense of collaboration. And maybe it's because no one is in our space, but it's been fun on that front. And, you know, it's this— you get the East Coaster in me coming in— when we are looking to move out here, we made the decision to move to Colorado, we were connected to a friend of my parents' son, you know, so random person we never met before. And we were talking to him about the houses we were looking at on Zillow to determine where to go.

And he's like, oh, well, just tell me where you're going, I'll drive by and take a look at it. And, you know, the New Yorker in me was like, all right, what's this guy up to? What's this crap? No, what's this game he's got going on? There's something up here.

But it was generally like, oh sure, yeah, I want to do it. And I ended up leaving my car at his house for a month because, you know, we, you know, we were shipping stuff out there. But that, that same ethos carries over in the security community in spades. It's like, how can I help? What can I do for you?

And I got to tell you, coming, you know, from the East Coast, it's a wonderful feeling. I really enjoy it. Well, that's great. Uh, you know, we're, we're doing good here on time. We have 40 minutes in.

Any final stuff you want to talk about, uh, you want to send out to the community, or any, any words of wisdom you want to leave us with? No, I'm not sure I got much wisdom, but it's, uh, no, look, uh, we're excited to be here. We're looking to really build, uh, the community here. We came to Colorado for, for a reason. We think the, the talent is here.

We think it's a great place to build a company, and we have large growth aspirations. So, yeah, you know, if there are people interested in, in security in particular and building out a product, we think it's going to be, you know, pretty revolutionary. Would love to talk to you. And, uh, obviously for companies listening as well, we'd love to talk to you as well. Awesome.

Well, appreciate it. Hopefully we can maybe check in with you next year and hear about the next iteration of success for you guys and keep on top of what you guys keep doing. Does that sound good? That sounds great. All right, thanks a lot, Fred.

Appreciate your time. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes