Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 45 for the week of December 11th. Alex, how are you doing this morning?
Robb, did you have a little bit of a seizure there or something? What's going on? Everything okay? Well, try something new, you know, we try and try and boost the ratings and get the Nielsen share higher. Is that how ratings work?
Something like that. Something like that. Well, good stuff. How's your week been? You know, it's been good.
Had a company Christmas deal this week. It was good times. We had a gift exchange. Oh, I walked away with an Oregon Trail card game. I honestly wanted it.
I stole it from somebody. It was really cool. So now you can die of dysentery. I have already died of dysentery several times this week. Good stuff.
Well, we're just a couple of weeks away from the holiday break. We're gonna, we're gonna still have our, our podcast through the holidays, but it'll be a little bit different, right? We'll have some, some unique stuff for folks coming up through there. There was nothing interesting in the news this week. So let's see if we can make non-news a little bit interesting for folks, all right?
I wouldn't say that there was nothing, but there was, you know, definitely not a banner week for news. First, as always, make sure to sign up for our mailing list. Go to the website colorado-security.com, sign up at the bottom there, and we'll keep you informed of things that are going on. And also, we'd love to have you on our Colorado Equals Security Slack channel. So check that out too.
So it's been— it's really picked up in the last couple weeks. A lot of good conversations going there. There's job conversations, event conversations, recommendations for security companies you might want to work with. And some of us are planning a kind of an informal lunch on the 18th. You got to come to the Slack channel to figure out the details on that.
Sounds good. So first on the list this week, it was announced that CHI is going to merge with Dignity Health. Yeah, Catholic Health Initiatives, which is one of the largest companies here in Colorado with a very large security program led by Cheryl Rose. They're going to be merging with California-based Dignity Health to form, I think they said, one of the biggest faith-based healthcare systems in the country. Yeah, it's exciting, but also a little bit disappointing.
You know, I read that the headquarters is going to move— well, I mean, CHI here— to Chicago. So we're, I think, going to lose the headquarters of a fairly major company, which is no good. Yeah, hopefully they keep the security stuff here and it doesn't impact our friends to the negative. Exactly. Another piece of news, local company news, you know, so Glassdoor is the big, you know, company review.
There's lots of information about companies. They have their best companies to work for list, and 3 Colorado companies made the list. Fast Enterprises, which is a local company here in the Centennial Tech Center area. SendGrid IPO'd just a couple weeks ago with the CISO Dave Campbell, a friend of ours over there. And the last one was Madwire, which I don't know, but it looks like it's a marketing company helping Folks there, they're mad.
They're mad. They're very mad. Next on the list, there was an article on the NCC. So this was in the National Cybersecurity Center. Yes.
Sorry, sorry. This was in the Pueblo Chieftain. Some NCC folks out were doing some presentations this week. And I think the highlight of this article was a quote that was in there. And they said, cyber is the new dirt.
Everything in the future is going to be built on it. So if anyone ever tells you that your job is not sexy, just pull out this quote because cyber is, is the new dirt. Exactly. We don't need to attribute that quote. I don't think he wants that.
Uh, next there is an organization called ENISA, uh, which is a European organization, and they made some recommendations for IoT security. Yeah. So go ahead. Sorry. You might think, Why are we doing an article about a European organization?
So Mike Glenn, who is with CableLabs here in town, he helped put together the report that this article is based on. Yeah, so I got— had a chance to look through the report. I haven't read every word of it, but if you're doing any implementation of IoT security, if you're putting stuff in your organization or you're help creating it, this report has a lot of great information. And one of my favorite parts of it is it has a really thorough threat model, goes through what kinds of threats impact what kind of IoT devices, and then they have a list of countermeasures that you could look at that'll help mitigate those threats. So really, you know, kind of hold your hand through the process.
If this is something you're new to, might want to take a look at IoT security here. Yeah, it sounds like that at some point this might become part of a European standard. So next we had a— there's an article that's a spotlight on Brett Fund. Brett is the founder and CEO over at SecureSet Academy. And this really kind of just talks about his personal life and background, which is especially interesting since we have him coming up on the show in the next couple of weeks.
That is awesome. Next, Webroot. Surprise, surprise, 15th consecutive quarter of double-digit growth. And I just have to do a shout out to Alex here. When I, when I quizzed him how many quarters would it be, he actually got it right, right off the bat.
Yeah, I keep tabs on Webroot and their growth. So if this ever stops, I assume something apocalyptic is going on. Yes, Webroot, please keep going. We need to have your quarterly double-digit growth. But yeah, double-digit growth every quarter for over almost 4 years now.
That's pretty good stuff. Next, another piece of news that doesn't surprise us, but it's great news. LogRhythm has made the leaders section of the Gartner Magic Quadrant for SIEM yet again. Yes, congratulations to LogRhythm. And interestingly, I don't know if you've taken a look, but the person who I would say was the leader over the last decade has actually dropped out of leaders.
So ArcSight is no longer up in the upper right corner. Wow, I hadn't looked at that yet, but that is— I don't want to say it's surprising, but it's sort of the, I guess, end of an era, right? Yeah, it sure is. So the other 2 up in the upper right were IBM and Splunk. Sweet.
So next we have a blog post from Red Canary talking about their Atomic Red Team testing. This is called Catching the Dragon by the Tail. Basically in this blog post, they walk through some research that was done by FireEye, and then they take the report, looked through it, figured out, you know, some of the IOCs and other things, what the threat actor was doing, and then they used those to make tests as part of their framework and then develop detections on how to detect those threats. So pretty cool. Yeah, I mean, I think that what they're doing with the Atomic Framework is fantastic.
You know, it's really not-for-profit, it's something they're doing for the community. And in fact, we're talking about having them come and do a a course around this for RMISC next year, right? Yeah, we're working through the, the details at this point, but we expect to have them there. So that'll be pretty cool if you want to learn more about using the Atomic Framework. And as a security leader, I'm super interested in anything that helps me better get assurance that my controls are working, and that's really where this thing goes.
Exactly. Okay, so that's it for news. Um, just as a reminder, you know, go ahead and go out to iTunes, go to Google Play, do a review for us, say nice things. That helps people get to find us. That'd be great, especially if they're searching for the word Colorado.
We should pop up pretty close to the top of the list if we have lots of good reviews. Moving over to trivia for this week. So last week's question was, what is the least expensive item in the Colorado Equal Security Store? And we had a winner. Douglas Holland properly answered.
There was actually 2 things tied. It's the— Trick question, trick question. Yeah, absolutely. But it's a bumper sticker and a car magnet. And so congratulations to Douglas and thank you to Andre Gaeta for sponsoring our trivia each week.
So Douglas gets to pick something from the store up to $25 value to have shipped directly to him. I'd also like to note that both of those items were $3.99. So if you want to buy something from the Colorado Equal Security Store, there is a very low bar to entry. Fair enough. Am I reading our next one?
I think you are, Robb. So this week we get to do something a little bit different for trivia. Rather than a simple question, it's really more of a choose your own adventure where your choice only one right answer. So here, here, I want you to imagine that you are in the mountains. You're in the mountains in Colorado.
I can see the scene. Yeah. You need to build a permanent shelter. You're going to be here a while. So you, you're going to select stones as your building material, uh, based on, based on a couple of core principles.
You want a shelter that's stable and secure, and you want to make sure you're building security in at the beginning, right? You don't want to bolt it on after the fact. So You have a choice of sedimentary rocks. You can choose between gypsum, granite, and basalt. So those are not just the names of towns in Colorado.
Those are actually the rocks that grow there. Yeah, grow. So you need to choose the rock that offers the best structural integrity. So you define that by which rock is the densest. It's going to provide security versus wind, rain, and all the other elements.
So which rock do you choose? Which is the densest rock there? Wow, that was a long question, Robb, and I'm glad you set the stage. So I'm sure someone will be able to figure that out, but we look forward to hearing all of the potential answers to that. Email us at info@colorado-security.com with your answer.
With that, event news. Yes. So we have events through the end of this year and then a lot of stuff popping up in February and January and February right now. So let's go ahead and go through the rest of this year. Yeah, if you wanted to know what those events are, you could check out our event calendar at colorado-security.com.
But if you want us to read them to you, we'll do that as well. So first on the list, on the 13th, CTA is doing one of their 101 series, sort of an introduction to CTA. And on Thursday of this week, the 14th, is the annual ISACA ISSA joint meeting. It's going to be at Comedy Works South. This is always a good time to get to meet a really large group of folks in the area and have a couple of good speakers and have some fun socializing as well.
Also, CTA on the 14th is doing their annual legislative outlook. So this is meeting with legislators and other government officials to find out what's coming up on the legislative roadmap. So then the last event we have on the calendar for this year is CitySec. They're meeting up north on the 21st. I assume they're still meeting.
It's still on the calendar. If those guys want to confirm and reach out, that'd be awesome. But they did meet last week, so I assume they're still going. Yeah. Of course, once we are into the new year, we have a couple big events.
We started mentioning those last week. The first one of those is SnowFROC, and that is the annual OWASP conference happening on March 8th. And the second, of course, is the Rocky Mountain Information Security Conference, which is happening on the 8th, 9th, and 10th of May. And those keynotes are going to be announced very soon, I hope. I know we have some of them signed, and I don't know, I haven't got the okay to start saying names yet.
We're getting close. Getting close. All right, let's go ahead and jump over to jobs. There's a couple of, well, a few really interesting jobs this week. Starting off with one of them, Charles Schwab is hiring a managing director of threat management and intelligence.
Wow, you get to manage Charles Schwab's intelligence. Yeah, well, Charles Schwab, you know, talk to Chuck, he knows what he's doing, right? But managing directors there are pretty high. You know, this is a really large security organization, and this is definitely a leadership position there at one of the bigger security companies here in town. Trustwave is hiring a supervisor for their security operations center.
MBL Technologies is hiring an information systems security officer. This looks like it's on the, on the government side. Deloitte is hiring an information security risk and governance analyst. Dell is hiring an InfoSec analyst focusing on security operations here in Denver. Wow.
Cobiz Financial is hiring information security risk analyst. And so this one, this next one might be my favorite on this week. CU, University of Colorado, is hiring an assistant professor of information systems. You need to have some security chops to do this job. Nice.
One that I think is also cool, TD Ameritrade is hiring an associate counsel for privacy. And then finally, Xactly is hiring a senior director of IT who is responsible for security. Xactly. Exactly. Yeah.
All right, with that, that takes us to the end of the news. We have our feature interview this week with JD Sherry. JD is a local— he's a Colorado guy who's been kind of a security entrepreneur, starting up his own companies, being the CEO of another company, and now Chief Revenue Officer at a startup. Yeah, pretty cool. All right, with that, we'll throw it over.
Thanks, Alex. Have a great week. Thanks, Robb. Hi, this is Christine Vanderpool, Deputy CISO for Kaiser Permanente. Welcome to Colorado equals security.
For Colorado security professionals by security professionals.
All right, this is Robb Reck, and I'm here for a feature interview with JD Sherry, the Chief Revenue Officer for Remediant. JD, I've got to know you over the last couple of years, and, and I've— what I've got to see is that you have a really interesting background, and as a security leader, both from the leadership side of the business and from the security knowledge side, have a lot to share. So what I want to do do is just kind of start off the interview by understanding how you got to be where you are, obviously doing some really fun stuff with fun companies. Let's back up, right? How did you get into the industry in the first place?
Thanks for having me here, Robb. Certainly, uh, love the show. I'm, I'm new, uh, to listening to the podcast. I think what you guys are doing are great as far as, uh, raising awareness in general for— oh, thank you— Colorado security. So thanks for, thanks for that.
So yeah, um, Been an interesting journey with the career for sure. I've been in Colorado for about 5 years now, relocated from Kansas City with my wife and 3 kids. But really what brought me to Colorado in general, I think, was this sense— and I'm a little bit late to the game, I think a lot of people before me have realized that Colorado is absolutely fantastic and tremendous technology, and I would even say an influx of really great cybersecurity companies that are starting to grow. Out of the Front Range, really from Fort Collins all the way down to Colorado Springs for that matter. So, um, really came here with an opportunity with Trend Micro.
So I was at Trend Micro for nearly 4 years, heavily focused on cloud security and virtualization security. So I would say circa 2006, I started to really get into cloud. Yeah, when I was head of technology for a company called NIC, which is in Kansas City, but does 20-some of the 50-state websites. So colorado.gov, for example, is a wholly owned subsidiary of a company called NIC, and ran technology for them for nearly 7 years and really started to see this shift to cloud. When you say ran technology, what does that mean you did there?
So application development, infrastructure, huge elements of security, including PCI, compliance, Level 1 compliance. NIC was really an interesting company, publicly traded. They really had a phenomenal business model that was focused on, as state taxpayers, reducing our cost to deploy really great e-government services. So, for example, as citizens of Colorado, we maybe go online and renew our tags, you know, maybe getting hunting and fishing license or register a new company with the Secretary of State, that's done by efficient government. And this company NIC created a model that was of no charge to state taxpayers.
The only transaction cost associated with that is what you and I would do to do that transaction online. So, you know, with that, you would imagine an infrastructure across all 50 states, some federal government work as well, that would need to be very resilient, robust, dynamic, highly segmented from shared services perspective. So that was my major charter there from a corporate technology perspective, is to really drive application development innovation. So mobile was another big piece, but security really became front and center there. So you were at NIC in Kansas City doing this 2006 timeframe, and take us forward from there.
Yeah, so really became focused on deploying virtualization there and evolved really a couple of different generations of data centers to get to what I would call hybrid cloud capability. And from there, really became focused on what Trend Micro was doing as a customer. So I was one of the first 150 customers that was using their platform that was embedding security, typically anti-malware capability, but since then, you know, really expanded their suite into the hypervisor with VMware. As, as you know, VMware was and still is the major hypervisor player out there with, with regard to private cloud and hybrid cloud, and really thought Trend was doing some really great things. So as I evolved out of NIC, I started to get more of a passion for going to a high technology company or a security manufacturer.
So crossing from a government service provider into cybersecurity was really intriguing to me. And that afforded me an opportunity to really step into a global role and allowed me to relocate really anywhere that was close to a major international airport. So I've got family in Colorado, not so much in Kansas City, and we were excited to look to move out to here. So that's really what brought me to the Denver area was the opportunity with Trend Micro where I traveled pretty much the globe, focused on cloud virtualization. What was your job for Trend Micro?
Yeah, so part evangelist, part product development as far as soliciting feedback from all the clients that I would go on site and talk with. So, and then as everybody mostly is, I was in sales from that standpoint too. So did you carry a number for Trend? Yeah, on the government side I did early days, and then from there was part of a larger corporate number that fundamentally was trying to drive US sales, right? Trend is a major player really all over the globe, primarily in Asia, and that's where it's headquartered, headquartered in Tokyo.
The emphasis was trying to get US, North America in general, to grow, you know, their share of marketplace versus the Semantics, the McAfees, those folks. Trend had been number 3. They were trying to drive their visibility here. So, so you at NIC were a technologist, you know, helping build technology and support technology, and you made a move to quite a different position, really, like you said, with a number, with, you know, really externally facing. How do you make that move?
What was that like? So that's a pretty significant move. I'm sure all the chief information security officers and even the CIOs that are listening to your podcast know that we're all salespeople. Yeah, I mean, when we have to go and position our priorities in front of our executive leadership, and in some cases, like I know you do, Robb, you go in front of the board around what you need for your budget and, and mapping that to the strategic objectives of the business, you have to be a salesperson from that perspective. So that was always something that I really enjoyed.
I think I was fairly successful at a space especially taking very complex things, you know, like next-generation compute, next-generation data center cloud, trying to get people to get their arms around that and invest in that. And so from there, I had a little bit of a taste of the sales perspective and then just started to realize that I could go out and maybe be successful doing that for a manufacturer. That's great. So at Trend, you were doing that position for how long? I was with them 3 and a half years, nearly 4 years, the global role pretty significantly for a little over 2 and a half for the most part.
And, you know, loved my experience there primarily because I got to see a transformation with traditional data centers and where people were going, not only with virtualization, but, you know, one of my passions now is cloud, and that was a big role for me as I kind of evolved out of trend into some of the other opportunities that we can talk about is cloud was, and to me, is the future. In fact, I'm getting ready to do a talk in Nashville in a couple of weeks to talk about go big in the cloud or get owned, right, or get pwned. So for the most part, I think organizations are there, they're going to move there, and having that ability to understand the security dynamic of it is going to be paramount because, you know, Gartner, their research indicates that I think by 2020, 95% of the breaches in the cloud will be the client's issue. Could be due to a misconfiguration, could be due to the fact that they don't understand shared responsibility. These are all things that I think, you know, we're getting our arms around as IT and security professionals as far as how we need to properly plan for that.
But I do think that the business is outpacing us, and that's a good thing. This disruption, this transformation, this digitization of what we're doing with our business models now really is creating a tremendous amount of economic growth, really for small and medium-sized businesses as well as large enterprises. And I think that shift fascinates me, and I think we have to be very diligent about how we consume cloud-based services from a security perspective because it's like running downhill. You get going real fast, the wind blows through your hair— not so much my hair anymore— but you can get out in front of you, your skis can get out in front of you, and then you can trip and fall. I think that's what's happening with the businesses.
They're driving the innovation, they're consuming cloud. IT and security in many cases are playing catch-up, and I think that's going to cause some breaches due to the fact that maybe the proper planning in the design lifecycle didn't— I mean, we've already seen a massive number of those, right? All the S3 buckets on Amazon that are, you know, that are improperly locked down, causing breaches. And I'm not gonna go through the whole list, but lots of different organizations, you know, AWS keys being exposed that people use to do bad stuff. I, you know, you say Gartner estimates that it'll be 95% in the future, but what is it now?
Is it not? Seems like it's usually the— Yeah, I mean, a lot of people I talk to say, well, that number's low. Yeah. You know, because they're like, what's the 5% gonna be the cloud service provider's fault, you know? Yeah, it seems a little low.
Okay. Yeah. So, sorry, go ahead. Yeah, so, you know, coming back full circle to the career, the cloud kind of being a huge passion and a theme for me as far as a subject matter expertise, taking those experiences of moving workloads to the cloud, looking at how AWS, Amazon Web Services, is transforming, how Microsoft Azure is transforming, and being able to then figure out the right security architecture associated with that. So to not slow the business down, but to make sure that you put the right wrapper around it so they can actually speed up, but do it with the right risk mitigation protocols.
So looked at a lot of different opportunities in the startup world. So I had worked at a startup way back when in Boston in the dot-com era, late '90s, early 2000s, and I caught the bad end of the dot-com era essentially. But I really enjoyed my time there. So I've worked in pretty much small companies to very, very large companies like Honeywell, for example, and I really loved that startup feel. So I talked to several companies that were focused on cybersecurity, looking at new leaders to help kind of drive their business, whether it was on the strategy side, the sales side, technology side, right?
I've kind of served in all those different kinds of roles and took an opportunity with a company out of Santa Clara called Cavern that was focused again on security compliance for hybrid clouds and took a swing at my first CEO position there. Yeah, you know, a very, very exciting opportunity for me in a space that um, you know, continues to still be white-hot security and compliance for, for really hybrid cloud. And, uh, real great opportunity to go dive into the Bay Area, run, you know, my own company, learn the venture capital side, uh, learn, um, some of the dynamics of having a foreign invest— foreign investor, which was also very, um, humbling and, and intuitive for me to kind of pick up on certain things and Really loved it. So I was there for a better part of a year, um, and, uh, you know, fundamentally realized that I had a, a lot to learn on that front, right? And, uh, both on what, what my role was, what a proper board is, what an investor's role is, and, um, decided to, to move on from that potential opportunity.
And, and that's what brought me to a local company which we all know in the area, uh, Optiv security and have a tremendous amount of respect for the leadership at Optiv. I got to know them pretty well from my days at Trend Micro. Obviously, Trend was a partner at Optiv, as are a gazillion other, you know, manufacturers, right? They are the behemoth in the industry, and I had a chance to talk with the leadership there and figure out if there was an opportunity to help them grow the company because of their you know, their recent acquisition of Fishnet over the years in Kansas City, an injection of private equity money with Blackstone, and really attack the cloud security space in earnest as they were trying to evolve their strategy there from a lot of on-premise activity into what really was a hybrid cloud component. So, worked there for almost a year and a half, driving the, the cloud security.
What was your role there? Yep, so, uh, I was the general manager of our cloud security business. So really getting an understanding and a baseline of what we were doing well today, maybe where we had gaps, trying to fill those gaps not only with the proverbial people, process, and technology, but also from a strategy perspective. Um, I think the shift to hybrid cloud for our customers there at Optiv was significant, and I'm sure you see that in your business every day on the identity side. And, you know, we really valued the voice of the customer.
I mean, that customer base is significant, it's massive. They have a lot of different tools in the tool belt, for lack of a better term, and they really needed guidance on what are the right tools that they can really migrate to the cloud? What are the ones that are going to scale with them, not only from a people perspective, but also a cost and a budget perspective? How do I budget for this shift to the cloud? And how do I get my arms around people that are already in the cloud in the business today that maybe I don't know about that?
So that's what my role was there at Optiv and working with all the other different lines of business to tie together If you think about the macro component of cloud security, it touches identity, it touches incident response, right? It touches threat intelligence, it touches infrastructure management significantly. So that was one thing that we were really focused on across the different businesses is to get more cohesive and present a better view for our clients around cloud. So were you creating relationships with with vendors? Were you working on professional services engagements?
Were you working on white papers? Like, what— where did your work fall along the— It was, it was all across the board. Yeah. In fact, um, you know, if you look at that, we had a research arm, uh, and, and our good friend, you know, Raf Los, that was focused on driving vision around the research side of things with cloud security. So we, we came out with several white papers and research documents that were, you know, interviewing clients, doing focus groups.
So that was one segment of how we were trying to get thought leadership out to the masses. The other piece around the technology partnerships was, was huge. You know, you have a lot of legacy vendors that were evolving their product roadmaps, and they want to understand what features are the clients going to want, right? What's driving that? And then you had the startups, you know, that prior to my, you know, coming to Optiv, I was a partner of Optiv in my Cavern days, right?
So those folks are maybe pushing the envelope of new innovative disruptive approaches that maybe fit into a larger ecosystem. So dealing with the partners and the vendors was also a big significant piece. And then the last piece I would say was the services side. The consulting side. And, you know, coming at it from a cloud security-centric viewpoint versus just a cloud viewpoint, because I bet you, you can talk to many of your colleagues in the area here, even across the states, that would say most of the consultants would like to come in and sell you a cloud strategy.
And very rarely does that include a lot of meat in potatoes, or substance for lack of a better term, um, around the security aspects of it, including the regulatory concerns, the compliance concerns, and, and how you bring that all together. And oh, by the way, how do I do that with the existing skill sets? And I really want to spend some time talking with you around the skill shortage that we continue to hear. It's going to be exacerbated in some cases with cloud, and in other ways it's going to be abstracted away. So, you know, when you think about that, they really needed to understand what is my resource, my people resource gap, yeah, for consuming cloud.
And I do want to talk about skill set. Before we jump over there, I want to ask you about the vendor side. You made the point earlier that, you know, basically everyone needs to go big in the cloud. I don't disagree with that, but one of the negatives about that is every vendor claims feels like they need to make a claim about being a cloud provider and, and how my legacy, you know, network appliance is perfect in the cloud, right? And I'd love to hear you just talk about that and how you look at, you know, what's the right partner for a cloud deployment between those, you know, mature legacy network type vendors and the, the new SaaS providers who maybe aren't proven out, maybe don't have the back end, and somewhere along the spectrum there's probably a good fit.
Yeah, um, without a doubt. I think it— a lot of this comes down to R&D. Um, not only depending on some of the publicly traded companies, you can actually get in and look at kind of where their R&D spend is on a, on a macro level, but then can you, can you run the trail back? And I would even say go back to 2005 2006, did they start talking about cloud then, right? Think about it.
Amazon, that's when Amazon popped up. It's greater than 10 years old now. So what cybersecurity companies were out there starting to talk about cloud then? Because then, you know, they were probably starting to roadmap their technology stack to start investing into an R&D in those areas, knowing that the market probably wasn't there. But betting that it was going to be there down the road.
And I think if you look at it now, that marketplace is massive. I mean, there's a reason why Amazon's looking to build a second headquarters, and I would say Amazon Web Services is a significant part of why they're looking to do that. So that piece has been pretty telling, but as far as the blending of R&D and marketing. It is amazing. I think you bring up a very good point.
We go to all the trade shows every year, whether it's RSA or Black Hat, and you're starting to see more of a cloud moniker embedded in the cybersecurity scene. And I think, you know, maybe the 80/20 rule where 80% of the legacy vendors are trying to come up with a cloud story, but is that 6 months? Is that 12 months? Or is that more like 5 years? Yeah, the ones that have been talking about this for 5 years have invested in evolving their platforms or not just creating bolt-on capabilities to what they're doing.
And I think that's where performance really struggles. I think that's where maybe security gaps can come in. Yeah, is if they don't engineer it to be cloud-centric from, from the get-go, right? Are there, are there any vendors that you're willing to give a thumbs up to? In terms of ones who you think are doing really good stuff in the cloud, either legacy or new generation?
Yeah, so I think, you know, if I look at where cloud access is, and, you know, I think we all know, and I believe personally, and even in my new role in a new company, that, you know, identity is the new perimeter, right? So if you think about extending identity out into the cloud, you have to know who has access to what, right? So I was a big proponent of the cloud access security broker space, right? And there's some really good folks that got out 4 or 5 years ago and started to innovate in there. So I was always a big fan of the Netskope capability, and I know they're part of the Identity Defined Security Alliance, right, where they get where the puck's going when it comes to identity and cloud and who has access to what, right?
Yeah. So that's a big piece. I would say the next generation firewall companies are starting to see they have to go quickly to the cloud because they're starting to see pieces of services being rolled out that are more security-centric now from AWS and Azure. And, you know, it's— they have to start creating barriers to entry on that. Can they?
Uh, I, I think they can because, you know, I think even AWS would be frank, um, in saying it's kind of like Microsoft used to say, you know, we're going to let the partners innovate on the security side. That's just to say that's changed too, right? I mean, I think they, they know security is a lever and it's a big one to be effective going forward in order to grow business. So, I think the legacy firewall companies have the technology innovation and the mindset of how packets need to work, right? How security needs to be embedded, what services can they fan out with, and they're taking that now to the cloud.
I think they're late. I really do. I think they're pretty late on that front. You know, that, that's just going off of what, um, I saw clients kind of saying, well, what do you mean I can put a firewall in the cloud? Yeah, you need to put a firewall in the cloud.
Amazon isn't just going to take care of it. You know, AWS is not just going to take everything— care of everything the way you used to do it with segmentation in your on-premise networks. So, um, I think they're starting to realize that they've had to put play catch-up pretty significantly on that. And you might argue that public numbers are starting to reflect that shift in cloud and market dynamics are kind of— And it's just gonna get more and more over time. Yeah.
Well, let's move on. So you left Optiv earlier this year, right? Would you mind talking about why you left and then where you went? Yeah, so really loved the team, Getting to work with all the different practice areas within Optiv was pretty special for me. I hadn't been part of a large consulting organization, and obviously Optiv was moving heavily to a services and consulting dynamic model to really give clients additional value, really putting the V in VAR there, because I think if they could buy equipment, they could buy consulting, objective consulting, right?
Um, from, uh, you know, a trusted vendor and do that from a procurement vehicle that made a lot of sense to them where they could get buying economies of scale. It's really what they were asking for, for the most part. So working with the identity practice, the incident response team, our MSP, our SOC, tying that cloud story all together with them so they could be more embedded with their client as they start the journey really kind of a fascinating thing for me. Um, in learning more, um, through the dynamic, you know, obviously the transition in the end of, uh, first part of this year, um, with KKR then buying the— it's a private equity firm— private equity bought the majority stake in Optiv. Yep, correct.
Yep, correct. And, you know, that's all— that's February timeframe, I think it was. Yes, yes. Um, and, you know, looking at that as an opportunity potentially to transition the stuff that we had kind of ginned up. I like to kind of be a starter on things, quite frankly, um, and, you know, once things get kind of legs and, and get going, I'd like to move on to the next challenge.
And that was a big thing. I think it was good timing for me, uh, you know, been there almost a year and a half, worked with the team to kind of get the, the core dynamic of the strategy, looking at different areas where we needed to invest and kind of lay that plan out. And the opportunity I had with Remediant was a relationship I had with these guys for a couple of years. So this was not a foreign company to me. I had watched their growth and helped advise them out of stealth mode around privileged access and really was blown away at an approach that, quite frankly, is interesting around the legacy aspect.
Talk about legacy technologies. The privileged access space, which, you know, I think is a great complement and a subset to the IAM space in general, but pretty, pretty focused and laser-focused with certain companies out there that I think have been using password vaulting as the approach to try to solve these access problems with stolen administrator credentials. And I mean, it blows my mind that here we are are with technologies that were developed in the late '90s. The number one problem according to Verizon's breach report last year, of all the breaches that happened, I think almost 2,000 breaches, over 80% were using stolen credentials to steal the data. That's a problem.
That's a legacy problem. That's not threat intelligence. That's not security automation and orchestration. That's a problem that, that's not being addressed. And, you know, it To me, I think a lot of that is due to the complexity of the legacy approach with vaulting solutions, primarily with our friends on the infrastructure side that just want to do their job.
They want to be able to get services up, they want to maintain services, and they don't want security and compliance to hinder them from doing their job. So these guys, our co-founders Tim Keeler and Paul Lanzi, took a crazy approach to disrupting this market and saying, well, you can do it that way, but why not do it in a much more scalable and easier way for your infrastructure teams to roll out? And that was through their experience through breach response, quite honestly, in some of the biotech jobs that they had held and then subsequently consulted in, where nation-state actors were stealing admin credentials, maintaining persistence in that environment for well over 100 days, and moving laterally with those credentials, even where password vaults were deployed, and they're like, this is, this is asinine. A new approach has to be done, and that's what we're doing at Remedia. So what's the new approach?
The new approach really comes at it with scale around an agentless approach where there's a, you know, a thought where, in my opinion, if the number one attack vector is admin credentials being stolen to move laterally, coupling that with continuous monitoring. Because if you look at the SANS Top 20 Controls, right, the top 4 focus on hardware and software management, configuration management, vulnerability management. And all of those, it's best practice and recommended that you do that continuously. Because if you don't do those 4, you're gonna miss something, therefore somebody's gonna find a way into your environment. You know what the 5th one is?
Privileged access. Okay, okay. So why wouldn't you want to monitor the service accounts, uh, the user accounts that are being used and stolen through phishing. That's 90% of the time. I'll phish you, Robb, I'll steal your admin credentials, and I'll maintain a foothold in your environment, and I'll just walk the environment because you've had a lot of access provisioned over time.
And even people that aren't admins or aren't CISOs of an innovative, you know, identity company have a lot of access in the environment that have crown jewels or PII or sensitive data to it, they don't even know they have access to it. So an attacker takes those credentials and just walks. So we're wanting to focus on a way where you can monitor that in real time, okay, all day, every day, those accounts and the service accounts to watch where privileged accesses have been spun out to different environments, whether it's workstations or servers, and make it, you know, a vital effort to watch that all the time, and then also feed that data back into your governance structure from an identity management standpoint, right? So that feeds how, what groups, you know, what rights are being provisioned, and that comes in tandem. And then the last piece is continuous protection at scale.
So again, without an agent, nobody wants to deploy another software component to their devices, workstations or servers, and cloud as well, to be able to do that where I can lock down access and really go to a zero-trust model. Okay, you know, I think my friend John Kindervag, who's now at Palo Alto and was at Forrester, created the zero-trust model. You have to do that for identity as well. So why not lock down machines at scale and say, hey, you can't get into that whether you've stolen credentials or not unless you go through a multi-factor protocol and elevate your administrator rights if you indeed do have access to that. If you do that, and you lock down and do just-in-time administration, you shut down lateral movement without question to an asset when you put it in a Zero Trust Protect mode like that, again without an agent and at scale.
And then, you know, in summary, I think the, the orchestration piece is huge. So have a robust API where you tie into programs like incident response, like insider threat, like user behavior analytics. If you can't have a platform tie in all that you're going to be in trouble. So that's really the disruptive approach. And then the last thing I would say is, um, we don't care how many administrators you run through it.
So I think where we've seen traditional legacy approaches come up short is they don't license the true scope of the organization that they need. So therefore, the reduced investment causes workarounds to traditional vaulting technologies. We say cover everything monitor everything, and then I don't care how many third parties, internal people you run through that particular just-in-time administration piece. Yeah, you're going to be able to scale that way from a total cost of ownership. So if folks want to know more, how should they reach out to Remediant or to you?
Yeah, so remediant.com is a great way. You can schedule a demo there. You know, we've got a really great approach to this that is not just small, medium-sized businesses or large enterprise. Everybody should be doing privileged access, quite frankly. It's not just a big company problem.
So, you know, the other thing I would say is too, being able to quickly assess your environment without a lot of consulting hours associated with it, without a lot of time spent away from your normal job, is critical. And I think that's where a lot of people get scared around privileged access is it's going to take me 6 months to roll out. So therefore they table that, they put it, you know, they put it on the back burner, but that risk there of not doing privileged access is huge. So remediate.com, schedule a demo including a free privileged access assessment that takes really a couple hours and really a non-privileged account to do it. You don't even need a privileged account to completely discern where your access is, and we're able to showcase that for clients pretty quickly.
Cool. So what I wanted to segue into is just understanding your move, you know, personally to being a Chief Revenue Officer, you know, basically the head of the sales organization there. That's, that's yet another kind of change for you, right? So we talked about that, how'd that come about and why and all that. Yeah, absolutely.
So, you know, if you kind of replay where I've been, um, from, you know, a practitioner, uh, to running a, you know, large technology group, application software, infrastructure security. If you look at then that transition to the manufacturing side, doing a couple of stints at a large, you know, multi-billion dollar manufacturer at Trend Micro to a small manufacturer and a cybersecurity startup with Cavern. The one thing I felt like I didn't have, and I did sales in both of those environments, the one thing I felt like I didn't have was understanding the reseller or the value-added reseller space. So my time with Optiv was very enlightening on a number of fronts, not only cross-practice, but looking at the manufacturer side from the reseller lens. And that was the area of my career I felt like I didn't have enough knowledge in.
So that was very helpful for me to understand what I would call the complete lifecycle of buyer to understanding manufacturer to understanding reseller. Seller and consultant. And then I think that coupled with the fact that, um, you know, moving into a, you know, a sales lead role for a startup where it's primarily technology founders, right? So, um, you have, uh, the, the need to fill out the leadership team with somebody with sales and marketing experience, but yet somebody that's walked the shoes of the client, right? I've been in the roles of of a CIO and I've been in the roles of a CISO, I know their budget concerns.
I know how they like to work with vendors because I was on that side of the table. I know, you know, how they like to consume services. So for me, jumping into the head of sales, marketing, channel development, professional services, that's really— people often go, what is a chief revenue officer? It's really all of that tied into how do we make money, what feeds that, and how do we create strategy to, to enable the growth of the company, right? So, you know, we've got a clear goal where we want to focus on, um, tripling the company in the next 2 years and then doubling the company the next 3 years, uh, after that, essentially.
Yeah. And, um, I think we'll, I think we'll hit it. And from my perspective, this, um, this space is pretty simple to have a conversation about. Uh, you know, privileged access, that's not complicated. You either know how to do it or you don't.
Yeah. And I think it's an easier conversation from a sales perspective to have with you if I'm, if I'm calling on you, Robb, versus, hey, what kind of threat intelligence feeds do you have? Or how do you bring together— not that these aren't important, I just think there's so much complexity in these larger conversations that you see at the large trade conferences that I think people are being distracted. And all my point from a sales and marketing perspective with, you know, being Chief Revenue Officer at Remediant is let's get back to really the basics because I think we've gotten away from that. The breaches aren't going away because of that, that the data and the evidence is there.
So let's put a strategy together where we don't get caught on the side, you know, caught up on the shiny object syndrome. And we're focusing on really the top 20 controls that we know we all need to do as security practitioners. So I don't doubt that you can sell the product. To me, the interesting challenge here has got to be building a team, right? You're going to be building a security— or excuse me, a sales organization and a marketing and professional services.
And those sound like challenges that are probably, you know, people spend their whole careers learning how to do that well. Um, that— I assume that's got to be a big part of the challenge for you and, and hopefully. Yeah, so, you know, I, I think, you know, that's a great question. Over probably the last 10 years, um, you know, I've been able to meet a lot of really cool people across the globe, not, not just in Kansas, not just in Colorado, but across the globe of, you know, smart technology people like you that get the business side of it to really great salespeople that I learned a tremendous amount of the things to do and to not do on the sales side. And then an area where I'm, I'm not as strong is on the marketing side, and being able to meet those people that can do lead gen, demand gen, and use social to really extend the outreach and lower your cost of customer acquisition, I've learned a lot from from that.
Um, so that network is, is there. I value every one of my, my contacts, whether they're on LinkedIn or they're in my phone. It doesn't really matter. Um, being able to, to have that as a knowledge base of, hey, what would you do in this situation? Or I've got a gap or a role that I needed, you know, need filled there.
If they don't want to take it— and a lot of people are excited to figure out where we're going in this space, so I've got a lot of interest in the company, which fantastic. Sales, marketing, engineering, all of that. But, you know, more importantly is having them be able to go, you know what, I, I probably can't fill that, but I know 2 or 3 other people that probably can help you out there. That's really the power of the network that, um, I've really enjoyed growing really over the last 10 years for sure. All right, well, I'm gonna— I am gonna take another left turn here.
Um, you, you brought up the whole talent question partway through this conversation, and there's a little bit of debate out there whether people— I've heard some folks say they don't think there is a talent shortage. I personally think there is a pretty significant talent shortage. I guess I'll throw it out to you. Where do you think we are in terms of talent and the big issues we have around finding the right people to do these security jobs? Yeah, I mean, you know, at these conferences, whether it's facilitating panels, speaking engagements, or just consuming content from the thought leaders in the industry, and those typically are coming from Chief Information Security Officers, right?
Um, it's, it's definitely a wide array of people that you go, wow, your experience— I don't care what your degree background is, and I think there's been a lot of debate on that recently in social media and in the news and all of that. Um, to me, it's really, um, what has your experience been in, in your role? Um, and, you know, are you, are you focused on the key things that truly improve the maturity of a security organization? And I think, you know, there's probably 20% that are pretty, pretty good, and I think that are spot on, that have that title of Chief Information Security Officer. And I think there's a lot of other folks that have maybe been put in that role, maybe haven't had that experience, and, and I think And I've been there before.
We, we tend to get in over our heads on certain things, and I'll admit it, right? Is that the Peter Principle? Yeah, promoted to the point of incompetence. Yeah, that's right. But that's, but that's a part of the immaturity of our profession as well, right?
We, we all of a sudden we have no security departments. So call it 1990s and no security departments. Uh, you know, 2000s, hey, we need to create a security department. Who can do it? Well, that guy's run our firewalls.
That's the only security tool we have. So he becomes the first security guy. When you look to hire your first security manager, where do you look? Well, you look at the security guys, so it's your firewall guys. When you want to hire a CISO, where do you look?
Well, you look at your security managers. And it just— there's no other way that we get here other than hiring people who did the closest job. It gets us to these people who probably aren't the best fit for a CISO job. We're the first generation of CISOs right now, and we all came from a background that maybe isn't isn't ideal for being a CISO. I, I don't think it's about educational background as much as attitude and aptitude and what really what you're good at.
Being good at a CLI, you know, programming firewall rules is not the same thing that makes you good selling to a board of directors, right? Yeah, no, no doubt. And I, I think that's, that's where the biggest gap is. And, you know, we were just out at the Security Advisor Alliance Summit here in Denver, and it was very refreshing to me to see, you know, 80-some people in that room not talking about firewalls, not talking even about compliance frameworks, which I know a lot of times CISOs get saddled with because they're the ones that have to keep the lights on. A little bit of compliance and GDPR.
A little bit of GDPR. Yeah, absolutely. That's true. But, you know, focused on how to build better teams. Yeah.
Right. And I think Um, even the rest of the executive leadership team outside of the CISO should be looking to figure out how they can help enable the CISO in some of the areas where they need to grow and, and they need to evolve their career. Um, and that's leadership training like we saw there and other, other summits that will let them grow outside of the business so they can go to the board and, and talk. Because I was just talking the other day with a, with a colleague, and it's like You know, we outlined some things for the most recent board meeting because obviously very topical things with, uh, with Experian and all the ransomware that's going on. If the CISO hasn't been at least at 2 board meetings in the last couple quarters, I'm sure they're going to be at the next 2 because of, of the challenges out there that are front and center.
But it's, it's putting together a strategic package of why they need to pay attention, meaning the board and the business, and why they need to invest that I think historically has been a big struggle. And I know I've learned a lot by going in front of boards, but if you're going in front of boards, uh, you know, for the kind of for the first time, you have to speak a completely different language to them. And it really is one of, of risk, um, not so much compliance. You know, compliance feeds into risk, but really what is the operational risk to the business if we don't do things, um, and how much can it impact us, right? Yeah, that's great.
Um, so any, any other thoughts on like how we get— how we fix this skills shortage that we have? You know, what do we do to go from where we are today to a place where we're happier with the— Yeah, I mean, I'd love to see more advanced degree programs out there because, as you mentioned, that wasn't a component. I would even say, you know, application developers are still lagging around security within their degree, 4-year degree programs, of how to really write secure code, which is a big component of what's going on out there. But seeing, you know, DU evolve their cybersecurity program, and, you know, I've guest lectured at the CU School of Business in their cyber risk program, you know, having more thought leaders— and I'd love to talk to you about potentially doing that someday too— going out and talking about our experiences and sharing that, and then providing resources to them of where they can go to become better educated. Strong internship programs.
Let's get, let's get the, the college students in, in our companies and learning about cyber early days. Because I just had one of my sales development representatives who had never really even done technology sales before completely immerse them in cybersecurity sales. And, you know, he sold recruiting services before, but that is what I'm talking about. I'm becoming smarter about how we sell how we consume and how we deliver cybersecurity services, we have to start scaling that out. And I think there's just gonna be a tremendous amount of opportunity for people that give back to the community and that are ready to go and say, hey, that's a good degree program for me, or that's a good internship, or, you know, an evolution of where I can evolve my career.
I think it's just gonna be fantastic for their mind, their creativity. I mean, you have to be an abstract thinker, so I think creative arts folks and even music and theater folks, quite honestly. If they have that abstract thinking, they can get in and they can start figuring out how to solve these abstract problems that I think we have in cybersecurity. I'd say there's a place for everyone in security. It's an awfully big tent.
It doesn't matter what your skill set is, but from highly technical, getting into the code to write secure code, to getting into incident response, social engineering, compliance, training, any— anywhere along that whole spectrum, everyone fits, right? So if someone— I think we just need to show those paths to more people, show them that the, the— here's the destination you can get to that's going to be a good job in security, and here's how you go from where you are today as a CIS major or a music major. You know, either way, there's a, there's a path for you, and let's, let's help them find it. I think we could— if we can show them how to do it, we'll get a lot more folks. Yeah, without a doubt.
I mean, I, I think what I'd like to see have happen— and my numbers might be somewhat skewed— but I think we had an influx of attorneys back in the day where everybody wanted to go and become an attorney. I think we need to create that kind of a culture, not only from, uh, you know, job skills, fulfillment, uh, salary, you know, economics of it, to where people go Hey, this is important. This is not just a matter of a company's cybersecurity and risk profile, but it all feeds into national security. Yeah, think about that, because really we all factor into national security components as well. And I think if people can get behind, you know, earning a good wage, you know, being challenged in their job, I think they can see a much larger picture around, you know, national security as well.
I think you're right. Well, we're over 45 minutes now. Any final questions, comments, thoughts you wanted to throw out here for the listeners? I don't think so. You know, from my perspective, it's great to be in the Colorado cybersecurity community.
I'm gonna continue to get more involved. I haven't been able to be, as we've talked before, in the last 5 years, be situated here. Yeah, but that's changing. I'm becoming much more involved. They're not gonna make you move out to California?
No, no. So we are headquartered in San Francisco, that's true, but we'd love to get a, you know, a larger sales office here in the Colorado Boulder area. Well, if you're looking to hire people in Colorado, send me the job description, we'll get it on the show, we'll send— we'll get you some candidates sent over. Perfect. All right, that sounds great.
Thanks a lot. This is good. We're looking forward to hearing more about how it goes over there at Remediant, and we'll check in with you next year. Awesome. Thanks.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.