Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 36 for the week of December 9th, 2017. I have a new co-host with me today.
This is my friend Andre Gaeta. Andre and I have known each other for a few years as he's worked at a couple different security companies. Andre, why don't you tell the listeners who you are? Yeah, thanks, Robb. My name is Andre Gaeta.
I've been here in Denver for 20 years, and I've been doing security now for about 13 of those. Experience spans log management, SIEM, application security. Currently, I'm with an organization called Insight Engines headquartered out of San Francisco. So clearly, you, you killed and ate Alex to take his place on the show, right? Yeah, I did, I did.
Yeah. So, for real, Alex is actually just out of town this weekend, so we thought we'd have a friend join in and co-host for us. Why don't we go ahead and jump into the news, and we can talk a little bit more about what you're doing and what you're gonna help us do a little bit later in the show. Starting off this week, we have a bit of sad news to start the show. AOL has announced the end of the AOL Instant Messenger application.
It is sad, Robb. You know, I remember using AOL Instant Messenger for a real Short and long time, I guess, relatively speaking. But what's amazing about this, other messengers have come and gone in shorter lifespans. Yeah. So, so MSN Messenger, right, they had a lifespan of 18 years, and Yahoo's Messenger had a lifespan of 15 years, and AOL's Messenger ran the gamut for 20 years.
20 years. I remember vividly, I was the perfect age to become an AOL Instant Messenger fan. It was, you know, high school and I guess mostly college, and then my As a young adult, all of my friends, we used it for chatting. I haven't probably used it for a decade, maybe more, but I still feel a little bit nostalgic when I hear it's gonna go away. Yeah, no, nostalgic for sure.
And I just wonder, like, how? With so many messaging apps like WhatsApp and Communicator, like, how'd they do it for 20 years? And well, so that's amazing. And it's probably, you know, half of the audience listening is like, what's an AOL Instant Messenger? You know, for those of you who don't know what it is, you know, you're not missing out on much.
All right, so next on the news, all of the Colorado legislators sent a note to Jeff Bezos basically saying we want Amazon HQ2 here in Colorado. That's interesting. I'm on the fence on this one, and I'm gonna challenge you, and I'm gonna challenge the community. I think it's great that, you know, for us to become, uh, the, the, the center for technology here in the US and, and obviously security, uh, being top of mind for us. Um, what's, what's the impact, right, to the overall community?
Yeah. As we start thinking about 50,000 people, one of the things that crosses my mind is, uh, there's a force multiplier. And for each one of those people, they have families and then the infrastructure to support them. Right, in terms of other big box stores and smaller retailers. Great opportunity for Colorado, but are we really ready for that?
Yeah, I mean, I moved here, it's been 2001, so 16, almost 17 years now, and the, the traffic going into the mountains when I got here was reasonable, right? I was willing to drive to the mountains even, even during the middle of the weekend. And now I just have no interest in making that drive up 70. It's just so painful. And if you talk about adding another couple hundred thousand people to support this company.
Yeah, it's going to get a lot worse. Our infrastructure has to be ready to, to do it. That said, I think it's a challenge that Colorado is up for. We have to come up with the, the right solutions for these problems, but we have, we have to grow intelligently. Hopefully the fact that all of our legislators are advocating for this means that they've given it some thought and that they're ready to do it.
That, that's all I can say is hopefully they're ready to go. Yeah, yeah, absolutely. Me too. Let's go ahead and jump into the next article here. Uh, an e-commerce software company, ChannelAdvisor, is expanding here into Colorado, into Denver.
Yeah, again, right here we are in a situation where companies are moving to Colorado. Uh, down here in the Tech Center, we saw Charles Schwab open up a very big facility recently. Kaiser Permanente opened up a big facility here in the Tech Center. And now you have ChannelAdvisor. And here's a company, right, it's, it's 16 years old.
Um, if you look at the, the financials of this company, right, They've grown from 31% from 2010 to 2016, right, with revenues of $113 million. What a great opportunity for, right, Colorado to get more technology companies here and more security opportunities here. I don't think that all of the legislators wrote them a letter asking them to come. Maybe not. Maybe they did.
But I do have a couple of interesting things pulled out of the article. They have— they're headquartered in North Carolina. But they already have offices in Seattle, United Kingdom, Ireland, Germany, Brazil, Australia, China, and Spain. So we're adding a pretty cool— being added to a pretty cool list of stuff they're doing. And it looks like just a couple of years ago that they were really known as a company that sold into small and mid-sized businesses, and over the last 2 years they've really been looking how to get into enterprises directly.
So interesting interesting business that's really expanding and, you know, coming into Colorado is kind of fun to get to learn who they are. Absolutely. So the next one in the news, I read this one and I scratched my head a little bit. Colorado accountants are building bots and collecting big data. Yeah, that seemed unusual to me.
Yeah. What does that mean? Right. So a couple of interesting things from this. One of the stories we saw was that these public accounting firms are being asked to do things other than just look at the books.
For example, that their customers are asking them to look through social media and see how is the customer being referenced in social media and what does their social media profile look like. Another story, another kind of interesting quote from the article, KPMG is partnering with 9 different colleges around the country to offer a Master's of Accounting in Data Analytics. So this is not your mom's, you know, bookkeeping auditing here, right? No, no, it's no longer debits and credits, right, and audits. It's completely transforming that industry, which is interesting and exciting.
Yeah, pretty cool stuff. So it's interesting it's happening here in Colorado. They also mentioned EKS&H, which is, I think it's Denver's biggest accounting firm, and they're in the article as well. So take a look at that. Next, one of the, I think actually probably the most interesting article of the week, it's a map showing the most well-funded cybersecurity startups from each state.
Did you take a look at this, Andre? I did take a look at this, and there's a couple interesting things in I'll recommend the listening audience, if you haven't seen this image, you can go find it on LinkedIn or you can pull it up. It's in the show notes. In the show notes, perfect, yeah. So a couple of interesting things on here.
As it relates to Colorado, right, we rank really, really well when you look at the other states that are on here like New York in terms of count. New York's only got 3 organizations listed, whereas we have 4. The other interesting note on this is Florida, right? Um, you know, Florida has 3 organizations in the security startup world. You know, you expect California, right, to, to be on that list, and then you combine Maryland and Virginia, and you kind of expect that.
And when you look at Colorado being ranked up there in the top 6, yeah, that's exciting. Yeah, it's pretty cool stuff. They— you mentioned, um, Florida being a little surprising on the list. Washington is on the list, which might not be surprising if you think about, you know, Richmond and Amazon being there. But what's surprising is it was the bottom of the list.
Yeah, they weren't any higher than— they weren't as high as I would have expected. Yeah. I mean, you've got big companies. You mentioned Amazon, but let's not forget Microsoft is there. Yeah, there's a giant talent pool in Washington.
They weren't nearly as high on the list as I would expect a state like Washington to be. Yeah. So for Colorado, we've got, what, 4 companies on the list? There's Ping and LogRhythm, Webroot and ProtectWise. Yeah.
Is that right? Yeah. Interesting. Interesting. I don't— you don't see Optiv.
Maybe Optiv doesn't make the list because they're a reseller instead of a product company. I'm not sure. But generally, you'd expect them to be on any list that talks about big Colorado security companies. Yeah. And we have other ones that, you know, have been on the show before, companies like Red Canary and Swimlane, right?
This list for us is bigger and growing. And yeah, that's exciting for all of us. Those companies didn't make this map because they didn't have enough revenue. I think the cutoff was like $50 million or something, or $80 million, something like that. But really interesting stuff.
All right.
We have just a bit of news that the Inglewood computer systems— so the city of Inglewood, their computer systems were all ransomwared last week. That kind of came out of nowhere, right? Obviously, expect— you expect to have some level of that happening, but maybe not all of your systems at once. No, no, that seems— that seems like a lot. And I think it's a stark reminder to all of us, right?
The city of Inglewood. Um, right, there's, there's a lot of big companies here. There's a lot of SMB companies here. Uh, it's a city organization, and what we're seeing is that nobody's safe at any point in time. It's, it's, it's incredible.
Yep. Moving to the next story that I, I, I found, uh, we have an industry veteran in, uh, Thad Duper appointed as CEO of Secure64, uh, and that's exciting news. Yeah, so Secure64, we've mentioned on the show a few different times. Uh, we actually Uh, we're planning to interview the previous CEO and we'll see if we can still talk to him. I'd love— but I'd love to get to know Thad as well.
Secure64 does secure DNS services. And Andre, we were talking before the show, secure DNS is— is that a little important or a lot important? I, I would describe it as critically important. And it's interesting when you start thinking about CIS controls and, and NIST frameworks and ISO, yeah, nowhere in there does it say you know, the importance of DNS, right? But, but from a risk perspective to every enterprise, you tell me, right, if there's a zero-day vulnerability that comes out in DNS, what's the implications?
It's massively impactful, right? And if you can't, you can't get to anything, uh, we just use DNS as a— there's an expectation that DNS is going to work everywhere. It's not just from the experience of typing in a web, a website URL into a, you are into a browser, it's it's really the, the underlying things in those systems that all need each other to work, and it's using DNS almost all the way across the board. So big impact, big impact. So that's got a big job.
He comes from a great background— Teradata, Menlo Ventures. He's got a big job, and, and we're excited to see what he can do there. Yeah. Uh, so next story, Conversant, who we've talked about on the show a few times. They do ethics and compliance training in organizations.
They had their big industry conference here in Denver last week. There's a couple of nice stories about, about Conversant that came out of that, you know, kind of some PR generated around the events. Say that the net of it is they're having a lot of success right now, and 2017 has been a really good year for them. Apparently, for some reason, companies are starting to think about ethics and compliance more this year than previously. Well, right, I almost want to sigh right here for a second because I just Top of mind, and we spoke about this earlier, but you think about things like Wells Fargo, right?
I don't want to pick on Wells, right? I use them for my mortgage, right? They had something really bad happen, right? And that's part of the ethics compliance training is, you know, not opening up accounts that people didn't agree to open, right? Right.
Or in the case recently in the news, the jury's still out, we're not condemning anybody, but when you look at the executives of Equifax, who, who sold stock prior to notification being distributed to the public about the incident that happened there. Ethics is becoming critically important to every organization, and, um, you know, boy, it just feels like in this day and time, uh, sometimes they're just being lost. Yeah, like the Equifax one you mentioned, it may or may not be an unethical thing that happened. Maybe the people who traded didn't know, but there's the perception of an ethical problem there, right? Yes.
And the, the general counsel who approved the trade, you'd like to think that person would take a minute to think about what are the— what's the perception going to be if I approve this trade between when we found out about a breach and when the public found out, right? And that's a great point to note out, right? The, the gavel hasn't swung on whether or not something inappropriate happened, but externally the optics on this thing I think make everyone pause for a moment and scratch their heads. Like, hmm. Yeah, yeah.
All right, uh, so one more story. One more story, let's do it. So there's a blog on Ping Identity, um, the definition of security leadership, and it really basically kind of giving what Ping's example is around what makes for a good CISO. And I'd say this is a direct response to some of the criticism that came out on the web around the, the CISO at Equifax. Who had her educational background was not computer science, it was music, right?
And there was some attacks against her as a part of that. So this is a response to that. Yeah, I thought Patrick's comments were spot on. I mean, I really agreed with a lot of the things he said in there, you know, focusing specifically around understanding the business that you're in is an important role for the CISO, right? And in addition, right, you know, having those relationships internally with the organization.
I thought those are 2 key things that were called out by Patrick in that blog. The other thing that Patrick didn't talk about, which I feel is really important, is around this notion of community outreach. I mean, it is Cybersecurity Awareness Month, and being able to engage with the community for awareness is an important role for security leaders at every organization, right? It's incumbent upon us to ensure that folks that who maybe aren't in security are aware. Um, but as far as that blog goes, I thought it was great and spot on.
Yeah, yeah, it's interesting talking about the community outreach. As you know, and probably many of the listeners know, I've been very involved in the Colorado security community for, for a number of years. I have in the last maybe 2 years started trying to move away from talking to security professionals about security to talking to other professionals about security, talking to business leaders, and And the level of results I get from that is so great. It's such a positive thing. Anytime I can go talk to, um, you know, Colorado Technology Association or Denver Startup Week, or, or like there's like little groups of CFOs that get together in town and they want to have someone come talk about security.
Anytime I can get involved in those groups, it's such a bigger impact, and, and I really enjoy getting to do that. Yeah, and, and you're great at doing it, and that's the art of the pivot. And, you know, The encouragement is to all the listeners out there is to do the same, right? Broaden the awareness beyond security professionals. I think generally, right, security professionals get it.
It's the other folks that we need to start doing awareness and community outreach with. Well, great. That's the end of the news. A couple of housekeeping items. Number one, we do have a mailing list.
If you guys are not currently signed up to get our show notes every week, Sign up, give us your email address. You'll have the show notes and the link to the show in your inbox every Sunday afternoon after we publish it. And now, as I said, some housekeeping. We're gonna add a new segment to the show, and that's one of the reasons we brought in Andre today. Andre came up with this idea maybe 3 or 4 weeks ago to start adding a trivia question to the show, and he offered to personally sponsor the first person to respond to the trivia question with the right answer.
Is going to get an item from the Colorado Equal Security store valued up to $25. So Andre, I'm going to let you ask the first question. If you guys have the right answer, send a note to info@colorado-security.com, and, uh, we'll get the first one to get the right answer in, we'll, we'll get the prize. So Andre, you want to go ahead and ask our question? Yeah, yeah, there's a lot, there's a lot of great items out in the store, so, you know, take your time, but don't take too much time because I expect the responses to come back quick.
The trivia questions that will come will come in a different variety each time. They may be business-related, they may not. But for the first question in the inaugural— Can we just say no Googling it? Can you please not ruin it, people out there? I'm not saying that you— Andre's trying to make questions that are hard to Google, but don't Google it.
You know, let's have a little bit of fun with this whole thing. Yeah, and I tried to Google-proof it. I asked the question and then I tried to Google it myself to see if that question would show up. And I think I did a good job, but knowing the propensity for reverse engineering, maybe the group out there will find a way to get this. So the question for this week, week 1, and trivia is, what role did Mount Blodgett play in the history of Colorado?
Yeah, what— so Blodgett is one of the peaks here locally, and we're gonna find out. Awesome question. And then we'll look forward to hearing next week. I look forward to hearing the answers. Good stuff.
All right, let's go ahead and jump over to the events. As a reminder, we do have a calendar of events on the website at colorado-security.com. We can go see what's coming up in the next couple weeks, but we do like to talk through those, uh, those highest, uh, those things happening in the next 2 weeks. So this week on the 10th of October, the October OWASP meeting is doing a joint meeting with the SANS DevOps Summit. So the SANS, uh, organization has their DevOps conference here in town, and this is a joint meeting between those 2 groups.
ISSA is doing its monthly chapter meetings on the 10th and the 11th in Boulder and Denver respectively.
Gretchen is giving a talk on finding the business value of cyber, and that looks really, really interesting. So if you have the ability to get to the ISSA meeting this week, please do. Good stuff. And that'll be Tuesday night in Boulder— excuse me, Tuesday noon in Boulder, Tuesday night downtown Wednesday noon in the Tech Center. On the 12th of October, we have the ISACA October meeting, and on the 17th, we have the CSA October chapter meeting.
On the 17th as well, there's a, a training, a couple-hour-long training called Becoming a Threat Hunter. This was sent over to me by the folks at Carbon Black. It is a free event, a couple hours learning how you can start doing threat hunting in your organization without a whole bunch of additional tools or cost. That's great stuff. On the 18th and 19th, the ISSA COS October chapter meetings are taking place.
Yeah, so Colorado Springs, they, they do their event on the Tuesday night and then, and also the Wednesday afternoon. And then on the 19th as well, we have the Denver ISSA is putting together a special interest group on the government interest. Basically, if you're part in the government or pseudo-government organizations, this would be a great place for you to get plugged in and get to meet other folks doing security in Denver around government. And on the 19th, SecureSet doing its Cybersecurity Expert Series, and that's Chris Roberts who's going to be talking in this one. Chris is formerly, you know, the founder of OWL.
Now he's with, um, Accalvio. I think I said that right. And he'll be talking about his story. And then the final event over the next couple weeks is DenSec. They're doing their North Meetup on the 19th.
Just as a reminder, this is a real laid-back event with, with some, um, some of the more highly technical folks getting together. They meet up and say where they're going to go on Twitter. You got to follow on Twitter to know which, which restaurant and what table to go to, but a good time to get to meet some, some new folks. And there is other notable upcoming events on November 1st and 2nd. I know we're getting a little bit out there, but as calendars fill up and, and plans start to be made, um, the, uh, SecureWorld Denver is coming to that.
And if you go on the website and start checking out the agenda, there's some really, really cool activities taking place. So Larry Ponemon is doing the keynote of Ponemon Institute. There's a fantastic women in security panel that's got Cheryl Rose on it, Lucia from Polycom, and Mary Haynes from Charter. Definitely worth checking out. Randall Frietzsche is giving a talk on maturity in third-party risk.
If you haven't heard him talk about that before, I strongly recommend you go there and check that out. Awesome. Thanks for calling that out. A couple other events that are coming up a little further in the future. And we, we try and, you know, generally talk about the next 2 weeks, but then we go out in the future for those events that you're going to need to block stuff on your calendar for.
The 1st through the 3rd is NCC's Governor's Cyber Symposium. This is a chance to get to meet Governor Hickenlooper, all kinds of bigwigs in the, in the Colorado and national security scene. Something to take a look at there. Looking a little bit further out, On the 8th of November, there's the CTA's Apex Awards. We do have finalists for CISO of the Year, and those will be coming out to you in the next week or so.
But hopefully you guys can make it and see who will be named the Colorado CISO of the Year this year.
All right, why don't we go ahead and jump over to jobs now? First job open this, this week is at Douglas County. They're hiring a senior cybersecurity analyst, and I got to talk with the hiring manager on this. He's really looking for someone who, who's interested in coming up behind him to be a leader in the organization. So someone who's maybe got a little bit of experience and looking to get more and really wants to take on leadership going forward.
Next up is First Information Technology Consulting. They're looking for a process control domain administrator. So I don't know this company and I don't understand what this job is. So why don't we just move along without talking about it? Okay.
All right. If someone looks into it, let us know what that exactly means, please. Pearson is hiring a cloud security engineer on risk and compliance. Yeah. And, you know, take a moment if you have a chance and look up Pearson.
It's a, it's a dual-listed company. It's listed on the London Exchange as well as on the New York Stock Exchange. But they are an American depository company. And what's interesting about that is that their stock trades for $629 on the London Exchange. In the States, it's around $8 or $9.
But for folks that want international business experience opportunities, a company like Pearson presents multinational opportunities for you. Yeah, and they have a really nice large security program, and they've— they're building out a lot of positions here in Colorado. So you'd be part of a growing team getting to do some pretty cool stuff. They have about 20,000 employees worldwide, I think, and, and their office in Colorado is over at Streets of Southglenn at like University and Arapaho area. General Dynamics is hiring a security operations center analyst.
Western Union is looking for an information security analyst. I want to pause on Western Union for a minute. Not only do they have a great leadership team there, but they're also in the process of moving their offices from the South Tech Center up to Bellevue. But Western Union's got some pretty cool mobile applications. If you haven't checked out Western Union's mobile apps in the app stores, do.
I think we generally think of PayPal and Venmo and other things. They're doing a great job doing this digital transformation. They're really a modern company, and maybe that's not always the perception of Western Union given their very long history. Yeah, but great company. Go check those guys out.
Yeah, and you get to be at a sweet new headquarters, brand new, right by the train station at Bellevue too. I think it's literally attached to the train station. Cognizant is hiring a cybersecurity incident response and investigations— well, there's a word missing here— manager, analyst, something. Well, again, Cognizant provides anybody who wants international experience great opportunities. Another company that's had headquarters out of Teaneck, New Jersey, but also headquartered out of India.
And if someone's looking to grow their career and have multinational experience, go check out Cognizant. Swimlane, who we've talked about on the show numerous times, is hiring a security solutions engineer. Yeah, and Swimlane was just in the Colorado Startup Week just a week or two ago, and I know you participated in that. Cody Cornell is doing a great job building that organization. Fantastic location up north.
If you're looking to be in the vendor space, in the startup space, go check out the guys at Swimlane. And then finally, PwC is hiring a cybersecurity manager, and I assume this is really focused on their security solutions delivery, and you get to work with external customers who want you help them build their own security practices. That's great. All right. Well, that's it for the news here this week.
We're going to throw it over to the feature interview for this week. I sat down with Dave DeFore. Dave is the VP of Cybersecurity and Engineering at Webroot. Webroot, one of the big 4 security companies in town off the 36 Turnpike. Yeah.
Yeah. Webroot's a great company. Go and listen to the interview and I think you'll find a lot of interesting facts in it. All right, Andre, thanks once again. Thanks for joining us this week, and thanks for sponsoring our trivia competition.
We're looking forward to seeing how that goes. Yeah, my pleasure, and thank you. All right, have a good one.
This is Michael Stephan, Privacy Security Officer for Connect for Health Colorado. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is, uh, the feature interview, and today I get to sit with Dave DeFour, who is the VP of Engineering and Cybersecurity at Webroot. Dave, I've known you for, what, 2 or 3 years, and, and you've got to do some pretty interesting stuff at Webroot over the years. When I met you, uh, a few years ago, you were really at the early edge of getting into the IoT and what is this going to mean and how are we going to start to secure IoT environments. It sounds like things have changed quite a bit in the last year or so since we really caught up.
Why don't you just, you know, as a starting point, tell us what do you do for Webroot and where is your focus right now? Okay, great. Thank you for having me, Robb. So I've been with Webroot for just over 4 years. Spent a lot of time initially doing work with large OEM device manufacturers.
A lot of people, if you've heard of Webroot, you immediately jump to antivirus and things like that, but one of our largest businesses is embedding threat intelligence in network appliances from folks like Cisco, F5, Palo Alto, Aruba. And so I spent the first 2 years really working with those manufacturers, helping to integrate solutions. And we do a ton of machine learning. We've been doing that for 10 years now, taking that information, delivering it into appliances. So again, that was really out the gate what I did.
And then were you on the product side or the relationship channel side? Which side were you? Yeah, that's a great question. When I started, the discussion between the CTO and the VP of OEM sales was, where does Dave live? I landed on the sales side as a role.
I guess the thing that would be most equivalent would be think sales engineer, but my role was more specific to sitting with the engineers on the appliance company side and help them accelerate development. I did a lot of hands-on development with those manufacturers in an effort to improve sales and get them ramped up quicker. Because, you know, with an OEM appliance, you can see, you know, a year to 18 months once a contract's signed before you see a product out the door. And the goal is to accelerate that as quickly as possible by helping their engineers, you know, with development efforts and things like that. Yeah.
And then Moved out of that. So when did you join Webroot and do that? That was July 19th, 2013. 2013, okay. Did that through 2015, and then I spent a year trying to figure out IoT with Webroot.
We built some prototypes with some folks from CU, some endpoint-type prototypes that did some basic IoT work. I'm a little bit, um, not a fan of the term IoT. I think it's kind of a marketing positioning piece. Yeah. Um, in that embedded device, you like embedded device?
I like embedded device much better. Um, because we're old. Fair enough. I'm an old curmudgeon, I think they would say. How do you feel about cyber?
Do you like cyber? Cyber is— I don't like the cybers. Oh my gosh, that's hilarious. But so IoT, the problem is it turned into, that year turned into going to conferences, speaking, talking to people about, you know, people coming up with ideas on how they were gonna secure the IoT and offerings they had. And I kind of ended up after that year with the metaphor of it's kind of like going to a sporting goods like trade show and somebody showing up saying that they could build the perfect safety equipment for a baseball player, a football player, a basketball player, and a soccer player, and a hockey player, and it's the same piece of equipment.
It's just not possible. I think we have to look with IoT devices, we have to look at verticals. Is it something that lives in an industrial appliance? Does it have a radio on it? Can we update it?
Is it not updated? You know, you have to spend a lot of time thinking about that, and they kind of fall into multiple— a few basic categories of high resource availability where I can do a lot with it. It has memory, it has CPU cycles, and then you have the kind of the ones that fall in between where maybe there's not a lot of resources, but I can still update them and tweak them if need be from a security perspective. And there's the ones that once they're burnt, they're going out and they're gonna sit there for 30 years on a telephone pole and And whatever security flaws they have going out the door, that's what they have. Yeah.
Um, and so, you know, a lot of people are trying to build monitoring solutions. I think right now that's probably not a bad idea to try to monitor at the network layer, but I don't see— I am not, you know, this is an opinion— I don't see how people make money building endpoint solutions to protect IoT devices. I think they've got to do that work in the, in the at the network layer. The platform? Correct.
So it's interesting. I had never really heard someone talk about IoT the way you just did in terms of saying you can't call it a group of things, just like you can't, you know, your example of trying to have protective equipment for sporting equipment. And I feel like it's the same thing we have with security. You know, call myself a security guy, it's not right, right? You're going to be good at some subset of security and probably only really good at one or two things.
And similarly, IoT things, you know, an embedded, you know, light bulb is completely different than something out, you know, that's at an oil rig in the middle of the ocean that we call an IoT device. And trying to treat them similarly just doesn't make any sense. I could not agree more. Embedded light bulb, it's all about commodity pricing and, and, and making sure that everything is repeatable versus these high-cost devices sitting in a rig where you have the ability to put more elaborate, expensive equipment into it and really embed security there. So I like the way you're talking about it.
It makes a lot of sense to me. Well, and just to underscore what you just said is a big deal. No one would ever hire me to do your job because I would be terrible at it. I'm not good at understanding how to manage the risk of an organization, ensuring that we have proper security protocols in place. I'm good at building stuff from the ground up in an engineering perspective that fits into needs that we see in an industry.
And my point in saying that is we have vastly different backgrounds, vastly different knowledge, but if we were standing next to each other, people would say those are the security guys. Yep, exactly. And it's just we're different. And that is a problem we have that we lump security into this one thing and we lump IoT into this one thing. When it doesn't do us any favors when you need to apply different approaches to different IoT devices and different thought processes for different security areas, right?
That, you know, compliance is a totally different thought process than embedding security into the application SDLC, right? And I think from— for IoT, I have the luxury of saying we're not going to write code that protects those devices from where I sit, but from where you sit, you don't have the luxury of telling your executives, we're not going to protect our company from these IoT devices you just brought in. So it's, it's an interesting perspective. Like, I have challenges in my world, people trying to hack equipment, and I've got to figure out ways around protecting that, um, from, from a delivery perspective. But, but you do not have the luxury of ignoring these devices that are out there, man.
You've got to figure out how you're securing or mitigating risk in those instances. So I'm gonna move us forward. You spent a year looking into IoT, and what do you come out of there saying? This isn't the place we want to go right now? So I would say at Webroot, in my personal view, right now it's not something that's equitable.
It's a lot of fun. There's fun things to do in that space. You see things being hacked all the time. So if you're kind of a hobbyist and Hopefully no one above me— my boss lives in San Diego, so hopefully they won't hear this— but I would do what I do for free. I literally love what I do.
And I think it's a fun space to be in, but I don't know how people monetize it. So I don't know how companies can come up and sustain themselves in the IoT space alone. So to your point, right now we're looking at network anomaly detection. Scanning and managing network traffic and analyzing that through modeling that we're building to try to find that anomalous behavior in networks rather than looking at the individual devices and trying to create endpoint solutions for each one. Yeah, so, you know, it's fast forward a little bit.
You, your role has changed. You know, you were doing IoT stuff and then, you know, what came next? What do you, what have you been doing since then? So for the last year, I've really focused and doubled down on getting our solutions to market, moved forward better in terms of the technology behind them, making sure we're putting teams together that are both able to execute heavily on, on the low-level development that needs to occur, along with making sure we're getting things out more reliably. Um, that, that's really where I've been focused for the last year.
And then probably 10% of all that energy is also what do we need to be doing next to make sure we have things in the pipeline that will meet the needs of our, our customers moving forward. And so on that end, it's all about developing like anti-exploit solutions, things that can monitor processes that are running on an operating system, trying to determine if the behavior of that process looks malicious. And it's easy to monitor processes kind of at the OS level, in the kernel. What's hard is filtering out false positives because there are programs that look malicious but are doing legitimate work. So we're spending a lot of time in that space right now.
Yeah. So that's some pretty fun stuff you're working on, and you guys have had quite a bit of change over the last, I don't know, several months. Um, obviously some, some really cool stuff going on. I know you hired a CISO just a few months ago, Gary Aislip, who, who is, uh, came from this— Have you met him? Oh yeah, several times.
In fact, I had dinner with him recently. He's a good guy. A good guy. Uh, lives in San Diego, but he's coming to, yeah, to Colorado on a regular basis. Um, and I know you, you guys recently had your, your CEO, uh, retire, resign.
I'm not sure He retired. So our CEO, um, Dick Williams, um, 8 years I believe he was the CEO. Yeah. Um, amazing guy. Moved us from, you know, um, the, the kind of the legacy, uh, software we had, which was good at the time.
But he, he came on, um, we made a few acquisitions that really accelerated the company forward. We owned all our own tech. He really just really let us forward in a direction that has been great for Webroot. And he decided he wanted to, you know, kind of give up the reins. He's still heavily involved.
I mean, he— I think he's only been officially retired for a week, but you still see him around the office. And we have a brand new CEO, Mike Potts, who even though he has a home in Naples, Florida, and luckily wasn't too heavily affected by the hurricane, has just been all in on coming up to speed on the company. People are pretty pumped about him being there. So we're kind of fortunate that Dick's still going to be on the board, so he's going to be involved. So we're kind of in a wonderful sweet spot right now where we have a, a new CEO with some, some new ideas, wanting to really drive things forward, with, with Dick still being there, um, to, to help, you know, make sure we're, we're, we're staying the course where we need to.
So it's pretty— everybody feels really good right now at the company. And you guys just made an acquisition of a security training company? We did, yeah. So, so for a lot of folks, we spend a lot of time with MSPs and SMBs, and so we're catering a lot of solutions. So talk to me about the MSP relationship.
So MSPs, MSPs are managed service providers, if you're not familiar, and those are the people that handle all the small to medium businesses out there. Obviously, there's a few a few that handle large enterprises, but think the, the IT guy that you call, or guy or gal that you call when, when your computer isn't running, you're having some problems with small businesses, use these companies because they don't have an internal IT team or not enough internal IT support. They work with these companies to get their— absolutely. So we've, we've spent, I think, the last year and a half to 2 years heavily focused on the MSP market. Um, we've integrated into several RMMs, which are tools that MSPs use to manage their customers' environments.
And so, um, we, we have a very significant footprint in that MSP market, substantial. We're the people to catch. Um, and so we're, um, really becoming the de facto security provider in those businesses, um, in terms of both, uh, endpoint security, network layer security with like DNS solutions, Um, and so training was the next step in that, in that, um, direction, which surprised me. You know, I'm, I'm sitting here on the engineering side and, and thinking about making a new solution. Exactly.
And people are like, you know, we, we need to do training. Yeah. And, and I guess that— real quick aside, we— in, in anybody who's ever heard me speak, I always tell the story. It's, it's my one like grandpa's gonna tell the story again. Um, in, in 1988, I joined the US Air Force, and a 17-year-old Dave Dufour is in Biloxi, Mississippi after basic training.
He's at Keesler Air Force Base getting his— starting his technical training, and the first thing they teach us is that the most common way for someone to break into a computer system is to social engineer your username and password, like calling you and saying, hey, I'm support and I need your username and password. Showing up and saying, hey, I'm with support, or things of that nature. 1988. Yeah. Here we are, 2017, 29 years later.
The number one way of someone getting into a computer system is by social engineering a username and password. Yeah. Phishing is a massive, massive problem. And that's— phishing is obviously, I think everyone knows this, but just in case, is when you receive emails that have links or appear to be from a bank or lead you to a website that looks like a bank site or some other, and they're trying to solicit your username and password. And so that being the number one problem and has been for 29 years, probably longer, training is the one way to really improve that because it's a human problem.
Yeah. It's not a computer problem. So Webroot went out, looked for a company, and next month we will release integrated with our DNS solutions and our endpoint solutions, a training solution. And you have the ability to do training courses, but I think our approach and the way we think that'll be a differentiator is we can deliver training at the point of the issue. So if someone installs malware, we catch it, we can trigger a training.
Really? To say, hey, why did you— here's what malware is and here's why it just got installed on your computer. Here's what you need to know. That's interesting. Or if someone navigates to— we have a real-time phishing solution, so if someone actually navigates to a phishing site and we detect that, we could trigger a phishing training and explain what that is and kind of teach them.
And the thought is maybe by triggering that training at the point of the event rather than making it something where you have to go outside and attend a course, or you have to, at, you know, at lunch take a course. If we can maybe get that training rolling when the event occurs, maybe it'll be more effective. It's more timely, more impactful. People are going to pay more attention. The idea is right.
It sounds difficult, right? Because what you really want is you want when they make the wrong decision, that's when you want to deliver the training. Exactly right. But if you knew that they were making the wrong decision, you wouldn't let you wouldn't let them make it. And so, but, and to your point, that, that's— we feel like we're in a pretty good spot because we can tell if somebody clicked something and they've just pulled up a phishing site.
Yeah. And we should warn them, don't go there, it's a phishing site, and watch this video because, yeah, Robb, your CISO, is mad at you now and wants you to watch this video. Yeah. And, and I tell you, if you can keep the videos under 2 minutes, that's good advice. You don't want to, you don't want to— that's the way to do it, man.
Anything under 2 minutes is a whole lot easier. That's great. So what's the, what's the big picture for Webroot? What do you think, you know, you're 2017, you've got obviously a huge install base in commercial and enterprise systems for AV, you've got your MSP relationships, you got threat intelligence OEM, you've got security awareness training. There's a lot of interesting pieces, you know, where do you see this going in, you know, 2 to 5 years, whatever you're thinking for your timeline?
What does it look like? So we started as an AV company, been around 20 years. Threat intelligence, have been heavily involved in that for the last 10 years. I think we stay focused on our threat intelligence because that model has worked, served us really well as a vertical that most people don't know about, where we're working with those appliance folks. So we'll focus, we'll keep that focus there.
We have a massive consumer following. It pays all the bills. It's a great, great product. We love our consumer folks, and, and we never want to get out of that business because we have such a great relationship with our consumer people, or the consumers out there. Um, and then I think where we're really trying to focus growth is that, um, small to medium business and the MSP offerings, and just try to grow that because MSPs are growing.
I was frankly shocked. I, in the 2000s, I had a small business that paid my mortgage while I did other things, um, that, that was an MSP. And, um, I wasn't very good at it. I only had maybe 50, 60 seats under management, but it paid the bills. Um, and, and I'm surprised at how huge that industry has come.
Yeah. And it's becoming much more common for small businesses to say, hey, I need someone to take care of this. They're gonna— I just pay them a monthly fee, I'm done, and it's, and it's over with. And as that grows, we're really gonna focus on being part of that. Yeah, that's great.
So I'm gonna totally change gears on you and, and go way back before you got to Webroot. You've been there for 5 years, so you know some of the history. About 20-year-old company. Yeah, this year is 20 years. 20-year-old company founded— where would it start?
Boulder, 1997. And, and where— how did that happen? What do you know? I honestly don't know that history, and, and shame on me. I know, um, a few folks started it.
One of the original products was Spy Sweeper, and they were— oh yeah, Spy Sweeper. Yes, that was— yeah, that is a Webroot product. And they were licensing for that first 10 years, um, before they started investigating bringing in Dick, um, and, and a new management team. They, they spent a lot of time, um, uh, focused on Spy Sweeper and some other utilities, but most of that technology was licensed. So those, those first several years, they did a great job, um, growing a company, um, uh, building a pretty good solution and a very good following.
And yeah, I have to say that, that first phase of the company is, is why we have such a good consumer following today, because they really built a strong, uh, solution, but more importantly, a strong support infrastructure that really helped the consumer and really helped people. And so if you don't use Webroot, you might not have heard of us, but if you do, we have— people are passionate about it because of that support that we offer. And so that early, you know, first decade or so really, you know, set the groundwork for how the company acted and performed. And then the fear was after those first 10 years or so, not owning our own tech, having licensed all all of that, it became very important and aware that we needed to figure out how to get our own technology and, and be self-sufficient in that aspect. And then we're 100% self-sufficient today.
So, so you guys, I'm just thinking '97, I think that makes you the oldest of the, the local, at least the big companies here in town. Probably so. Optiv is like 2001, Ping's 2002, 2003, Logarithm's 2003. I don't think there's anyone who who was back into the '90s other than you guys? I don't know of anyone.
Yeah, that's, that's pretty cool. And you guys, obviously you have a nice big, uh, well, your name's on the side of a nice big building on 36th. Yes. And that's head— that's corporate headquarters. So that is Broomfield.
Broomfield. Yep. Um, so corporate headquarters in Broomfield, we're somewhere floating around 600 people total. But, um, yeah, and they're not all in Denver, right? Well, that's the 600 people and We have the corporate headquarters in Broomfield.
We have an office in San Diego where we spend— do most of our machine learning. We have a great relationship with the San Diego supercomputer facility out there. So, the universities in San Diego, we spend a lot of time with there. We have an office in the Bay Area in San Jose. Then we have an office in Dublin, Ireland, an office in Darby.
Sales offices, dev offices? Just to run down the list. Dublin is focused on threat, and then there's some sales folks there, but that's really— we have a lot of threat analysts. We have threat analysts here in Broomfield. We have folks in Derby, which— where's that?
Derby's in the Midlands in the UK. So when I say I'm going to London, I don't bother saying Derby. I say London. But Derby is, you know, a couple hours north of London. We have a very large development team there focused on endpoint solutions, backend infrastructure, structure.
It's a great place to visit, by the way, if you've never been to Derby, England. It's beautiful.
Linz, Austria, we have a development team there that we've had for quite some time, and again, that's an engineering shop. So kind of Derby and Linz are both engineering shops. Sydney, Australia is mostly sales. We have some support folks there and analysts. We have an office in Japan where, again, mostly sales focused on APAC.
We got offices everywhere for 600 people. Yeah, it's really— that's actually really similar to the Ping layout. Is this— did this go through acquisition that you get the Derby and the Austria office acquisition? So interesting question. San Jose or San Diego was our BrightCloud threat intelligence arm where we have our like kind of machine learning center of excellence.
That was an acquisition for the BrightCloud solutions. Derby was a technical acquisition for their endpoint. They had actually developed a cloud-based agent that we, you know, have grown from, but it's the super lightweight, super fast scanning agent that came out of Derby. Austria was— we just found a group of really smart people that knew security that happened to be working together, and so we brought them on board. Oh, interesting.
Just hired a big group of friends. We literally did. That is actually exactly what happened. Yeah. Um, and then, uh, but we've had Australia and Japan for a very long time just because, because of support and 24 hours.
It's— we like to have that, that spread of across the globe so we're covered. And so you guys are a private company? Yes, we are. Yes. Are you venture-backed?
We are venture-backed. Um, and I don't know, they don't let me talk about how much something costs and they don't let me in on that. I'd like— I'm joking, but I, I forgot the name of the VCs. But yeah, sure. Very strong VC backing.
The beautiful thing is we're very profitable. Um, we, we've been profitable for quite some time. Don't want to go into specific numbers, but we're a super solid, stable, growing company. And, and that's pretty uncommon in security area right now because there's so many startups. But, but I guess when you— the only way you're around for 20 years is to actually have a good solid business model that works.
Yeah. Um, and we're fortunate to have enough money to fund, you know, like science projects and stuff like that to find new tech. So I'll change this topic. For those who might be interested in working at Webroot, you know, in the Boulder-Broomfield area, what kind of jobs are you guys looking to hire up there? Uh, start— we'll start there.
What kind of jobs are you guys hiring? So, uh, think any— first, not me, let's think regular corporation. We need marketing folks, we need sales folks, we need finance people. I mean, we need those fundamental, you know, folks that can run a business, and that's very important. And check our website if you're looking for a position with a very, you know, long-in-the-tooth, well, you know, best-of-breed company.
Great company to work for. Now let's talk security.
Love Colorado. I think there's a lot to offer here, but I would say we do struggle a little bit finding folks in the Colorado area specifically for the type of security development we need. Threat researchers are almost born, they're not bred. They have to have an intrinsic curiosity on how things work. So if you're of that nature, you know, you should contact us.
But from a programming perspective, we need tons of kernel-level developers, which You have a bunch of people who maybe aren't interested in programming, but then you get the bubble of programmers, then it's an even smaller subset of folks who really want to develop at that kernel level, who understand process hooking. If you don't even know what I'm talking about, that's a trick. So, things at that level are really critical for us. And then machine learning. I mean, we love data scientists, machine learning, modeling, and and, you know, that kind of ilk.
We are always looking for that. And then the one thing that we never really talk about because we kind of take it for granted is we spend a ton of money with Amazon. We use them a lot for their infrastructure. And one thing that makes us different, like 10 years ago machine learning wasn't that, it was pretty uncommon, but it's become more and more common You know, everybody talks about it. But what we're good at, and that we don't talk a lot about, is anybody can kind of go download some machine learning models offline or online, tweak those and run them and train up some things.
That's great. The trick is scaling that to be able to provide a service to people. It's a very hard thing to scale machine modeling and analysis. So one thing we do a lot and need more of are people who understand how to scale cloud infrastructures. Rapidly and be able to change quickly because we have cloud services across North America, South America, and in Europe.
And so we spend a lot of time, money, and energy on cloud infrastructure, and it's a big deal. Hmm, that's great. Which isn't even a security thing. It's more of a backend, you know, technology thing, but we need those cloud— with a huge security impact. Correct.
It goes back earlier to the comment, you know, what is a security person? If I'm going to hire a person to do my cloud security, I'm not going to go look for a security guy. I'm going to go look for a cloud person. Exactly. That's what it means to be a good security person, is to be really good at the technology you're securing.
And so anyway, as I'm looking for those folks, I want to know someone who understands, you know, VPC security groups, all of the AWS configurations, not someone who's managed firewalls. Right, for 20 years. And I would also, to the listeners, if you're a kernel developer, think security, because a lot of kernel developers don't have security background because they may have been building drivers or things like that.
There are security knowledge people, and at a large company, you don't need a ton of those. What you do need a ton of are kernel developers who can then work with those security folks to, to take the snippets of code they wrote to say, hey, this is what I'm seeing in this kind of process, and turn it into something that's robust and deliverable. So I guess if I'm somebody trying to break into the security industry and I'm a kernel developer, I make that pitch to people because kernel developers are— kernel space is that low-level operating system space. For your listeners, application space is where you're building application programs people use, user interfaces. Those kernel developers are really critical in security, and if they don't realize that, they should, because security companies are looking for kernel developers everywhere.
Well, that's great. Well, so any kernel developers out there or anyone who knows one— exactly, exactly. Is it— there's a referral fee, I assume? Robb, you'll get the fee. No, not me, not me.
For whoever's listening, you refer your people and we'll get a referral fee over to you. Well, cool. Talk to me about your personally— what do you think is gonna be the most interesting thing coming up in the next you know, year to 2 years that maybe we're not talking about yet? Yeah, we've been talking about machine learning and AI, and maybe we got a little bit ahead of AI, but machine learning is certainly making an impact at this point. Where do you see things going in the next couple years?
What should we be thinking about? Um, so a couple of things that I try to talk about. I feel like we're gonna get back to some basics on security. One of the biggest things that I see happening, whenever I see a big explosion of some— something spreading, it's the most— the more mundane something is, the more important it is to security. And the 2 biggest things you can do to protect yourself have nothing to do with security, and they're patching systems if you can and making sure you have actionable backups.
And so I guess what I'm saying with that is I— there's all this stuff that tells you data is being exfiltrated or, you know, that's analyzing your network. And I think people are going to start getting back to, well, if I focus on the basics first, yeah, I'm probably going to be covered most of the time. Now, I also think that that's one end of the spectrum. I think there's becoming, like with Equifax and things like that, you know, I guarantee you they had stuff in place, they had audits and everything to say they were well secured and well protected. I think there'll be a renewed focus on what does that mean?
What does it mean that we're protected? Are we compliant? And, you know, you and I always talked about compliance does not equal security, but how do we get those tied together better so that you in a CISO role are able to more effectively communicate with the executives to get what you need to not just be compliant but to also ensure you have the security tools you need. So, I think some of the noise is going to go away, if I can summarize, and we'll get back to some basics on, you know, I don't need a SOC with 50 people in it to tell me that somebody from China is pulling down data. I need to just make sure that's not happening.
Yeah, I really especially appreciate your comments about um, you know, the, the basics. And you gave a couple of good examples of basics with patching and, uh, backups. Um, and, and, you know, let's say that's, that's level 2. Level 3— level 7 is where we're focusing on, you know, we want to see the data exfiltration, we want to see these indicators of compromise that happened because we didn't do level 2. And I'd go even a step further back to like level 1 below those 2 and say you need to know your environment.
You have, you have to understand your asset inventory and your configuration management. You can't patch your Tomcat version if you don't realize you're running Tomcat over there, you know what I mean? Right. And, and those— we're really bad at that, organization or industry-wide. It is, it is something that's really hard and people really struggle to do.
If you, if you, if you start by buying the blinky box all the way at level 7 and you didn't do all the stuff, you know, below it, uh, maybe you didn't get the blinky box in the right place. And you don't even know it. And it's also setting up that vigilance that once you're at level 7, are you still looking at 1, 2, and 3? Yeah, because that is constantly changing. Yeah, and those are the most important places to be looking because, you know, if you know you have Tomcat and then all of a sudden you hear there's a Tomcat, you know, exploit, then maybe you didn't protect against it, but you know you need to go look and make sure you're covered rather than having something that's monitoring, like you say, at that level 7.
7. Yeah, it's, it's, it's basics. And I think we're gonna start seeing a re— people are going to realize, yes, there's a lot of stuff out there. We're maturing. As you know, it's the Wild West right now.
But I think we'll get back to some really fundamental things that, that, that help the industry. Well, you're— I love your optimism. That's fantastic. I hope you're right, because those, those fundamental things is, is the only way to be successful. That's exactly right.
Cool. Well, you know, I guess I was going to finish this up, but I want to ask you a couple questions about Colorado. How long have you lived here in Colorado? I have lived in Colorado— now we're going to get the grumpy old man part here. So I've lived in Colorado for 21 years.
Awesome. '96, July 29th, 1996, I moved here. And why? Why haven't you left? I have not left because I like the outdoors.
I used to like the lack of people, but there are a lot more people here now, and the grumpy old man in me would wishes, uh, they would go away. So you're not— so you're not hoping that we get Amazon's second headquarters? I truly— I, I, you know what, it'd be good for the industry and good for the economy, so I, I would grudgingly have to say yes because I don't want to be a guy that— that guy who didn't want to. But man, we used to— like, you used to be able to drive up 70 in the summer on a Saturday and not have a traffic jam. It would be kind of bad on ski days.
Now you can't go up the mountain Yeah, any day of the week without there being traffic. It's miserable. They gotta solve that problem. How much— what's the economic impact of people like me never driving into the mountains? I think that's a great question.
It's got to be significant. Well, and a part of me feels like we'll have this security thing cracked before they figure out how to fix that traffic problem. Yeah. All right, well, I'll ask you, you know, final question. Anything you want to share with the community before we, before we call it a day?
Um, I guess not. Well, look, Colorado So let's talk about Colorado real quick from a security perspective. Yeah, it's really nice that you and Alex have this, this podcast. It's helping to, to really like congeal the, the security community we have here. There's some folks in the Springs, they do a good job.
My— I fear they're a little bit DOD focused, you know, and I think that doesn't necessarily, um, uh, grow the, the, you know, the startup industry in terms of security. But I think groups like this give people a place to come and talk and listen, and, and it's, it's really good that you're doing these things. You and Alex are really kind of pushing. You've always done this ever since I met you. You've been pushing like with ISSA, and, and, and you really care about Colorado.
So I guess I'm not trying to just suck up here. I actually mean this. Like, this is a great forum, and I hope people listen and pay attention. And I guess I would challenge you because I'm busy and I travel I would challenge you to maybe have events or grow your, your group here so we can maybe start getting together, show up, talk to each other face to face, so we start having a lot more, um, uh, community in, in the Colorado security, um, community. Yeah, it's, it's been an interesting thing to see how, how diverse this community is.
You know, we have— you mentioned ISSA, which obviously I've been involved with for years, but there's so many other groups, you know, this the Cloud Security Alliance and OWASP and ISC² started meeting and SecureSet, who seems like they've been having 3 meetings a week for the last 6 months. All kinds of interesting stuff going on and just trying to understand the different perspective and where everyone fits. And really that's kind of the mission that Alex and I have taken on is to communicate what these different groups are and help spread the love and then show all the interesting stuff that's happening. How many security companies would you guess there are in the Denver area? Just guess.
You know, there's— we talked about it. 20, 30 maybe? Yeah, there's well over 30, and it seems like every week I find another one. Yep. You know, and they just keep popping up, and I just met one this last week.
Oh man, I'm not going to try and get the name because I don't remember it off top of my head, but we're gonna have them added to the website soon with yet another company that's making a product here in Colorado. And even a guy who was as involved as I was just didn't know about all these companies. So that's been really neat and a chance to start to raise awareness of them. What we really need, and we had a Denver Startup Week panel recently talking with some founders, what we really need is to have a couple of really nice exits, you know, have LogRhythm and Webroot and ProtectWise go out for, you know, $1 billion, $2 billion. Which brings in capital, you know, right?
So that for the next generation of startups, and then the people, you know, maybe the Webroot employees don't want to hear, but the people who were there for the startup part to make their equity, they leave, they go to the next generation of companies, and we build an ecosystem that, you know, kind of helps continue going. So that's what, you know, we're all rooting for. You know, Webroot's talking about— excuse me, uh, LogRhythm's talking about an IPO. ProtectWise certainly looks like they're likely to go down that path at some point. Ping, you know, we've had one exit and hopefully another exit in the next couple years.
Hopefully these companies do that and really help the whole community continue moving and developing, bringing that capital. And again, knowing you, Robb, we should not underestimate the need for people who— I mean, I tweeted today about a research study on social community and stuff like that, and most of us security folks, we're quite happy sitting in our home you know, tapping away on computers, myself included. You're really good at getting us all together and talking to each other. So we need platforms like this. So, and I agree with you, if there's a big explosion, you know, in terms of getting somebody, you know, getting funded or going IPO, that will help.
But if we're not all communicating and developing that community, it, it won't grow. So, so again, this is a good thing you're doing. Well, thanks, Dave. I appreciate it. We'll hopefully check in with you next year and hear what's going on at Webroot.
That'd be great. That'd be awesome. All right, thanks a lot. All right, thank you.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.