Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.
Hello, this is the February 27th episode of the Colorado Equals Security Podcast. This is Robb Reck. And this is Alex Wood. All right, we're in the studio here in Centennial, Colorado, ready to dive into another fun cast. Alex, how's your week been?
You know, it's been pretty good. Still recovering from RSA. You know, that week in San Francisco, it really takes a toll. So trying to get caught up on all the stuff that I missed being out there. Yeah, getting back to the big email deluge is never any fun.
And then this week's been unique, right? We had This unbelievably warm, perfect weather for the first half of the week, and then all of a sudden, was it Thursday? Yeah. Snowpocalypse, or I guess just coldpocalypse, really. Yeah, well, I think a lot of it was the cold that we had, you know, some moisture on the ground that became ice.
I know some people had some hard times driving around. Yes. Getting home from work. Thursday night on the way home, it was, you know, I work downtown, I live in the Tech Center area. It's usually maybe a 45-minute drive after work, and it was an hour and 45 minutes, and the last 20 minutes of it I was was on Bellevue, uh, behind a couple cars that couldn't get up the hill.
Yeah, 20 minutes and I didn't move. I heard similar stories of people that were stuck behind cars on hills that were just— they were either stuck or moving backwards, which is even scarier. Yeah, yeah, it was, it was certainly no fun. And ended up— I ended up turning around and just going like the long circuitous route because I just couldn't, I couldn't take it anymore. All right, let's, let's go ahead and dive into the news for the week.
Uh, big story, you know, the— we talked about DigitalGlobe a couple times recently. Big story this last week is that they have been acquired, or they're going to be acquired. Yeah, so a Canadian company that seems to be similar in nature, they also deal in satellites, purchased DigitalGlobe. I think on the positive side from the press that I was seeing is that they plan to keep, you know, the DigitalGlobe name and the company here, but it sounds like maybe there's some synergy for the 2 companies. Right.
$2.4 billion is the price tag, at least that was reported for it. I did hear one bit of maybe not so good news was that with the acquisition, they're not gonna be purchasing their satellites from Colorado anymore, which, or at least that's the assumption. I read an article that said that. So we'll see how that goes and we'll follow it more as it seems relevant to the security world. Good stuff.
So next, Transamerica will be adding 200 employees in downtown Denver this year. Yeah, we talked about them a couple weeks ago, right? With— they had an open security director or manager position, I think. Yeah, I think it was director of digital risk or something similar to that. Yeah, it's interesting.
I think— I assume that they're based in San Francisco, being that the Transamerica building is there, right? But it's good to see that they are making a bigger presence here. From reading the article, it looked like they are consolidating some of their different offices around the country and bringing people to Denver. Well, I love it when people identify Denver as the place, right? And, you know, whether or not there's a security position immediately, you know, the more folks they have here, the more it's gonna help the security community, I'm sure.
Yeah, and, you know, with that digital director of digital risk position, you know, maybe it's a good indication that they are gonna have some more security jobs here. Yeah, good stuff. So the next couple articles, really, we've been trying to focus more on pulling data out of the local security companies. So Webroot had a threat report that they recently issued. This is their 2017 occurrence of a recurring report they do.
Alex, I know you had a chance to read it. I'll kind of pull out what I thought was maybe the most interesting thing from the report. They have the claim that for every new phishing impersonation that comes from a financial institution, so for everyone that comes from your bank or likewise another financial company, there are more than 7 that are coming from technology companies, including Facebook and Gmail and those technology accounts. Kind of the assumption for me out of that is there's a whole lot more value for the bad guys in stealing your credentials to your social media accounts and your email accounts so they can get access to those financial services companies. Yeah, and the thing that I wondered about that is, is there more value in those other accounts, which I would imagine that there is plenty of value, or is it that those other types of accounts don't offer the same level of security, or people don't have the same level of security on those accounts So, people are going for the lowest-hanging fruit.
Not everyone has turned on 2FA for their Facebook and for their Gmail, right? Right, but hopefully for your bank account and other things, you're using whatever security methods they have in place. Or even if it's not the user-facing stuff, it might be the backend fraud analytics picking up on— Right, exactly. Yeah, that makes sense. One of the other things that I noticed was that they said that they categorized 33 million unique malicious IP addresses.
But of the top 10,000 of those, only 88% showed up once. People are recycling these over and over again. It's not— I remember in the past, you do more security operations work and it's, oh, hey, well, I know this IP address. They've been— I've seen this forever as someone that's attacking us, or this has been sending spam for a long time, those sorts of things. It seems like now it's You use something once and then you discard it.
There's lots of bots or whatever else out there that you can recruit for those types of things. Makes it awfully hard to blacklist, right? For sure, yeah. Blacklisting in that environment is not going to be easy. I think it all goes to the ephemeral nature of infrastructure at a lot of places now.
As you spin up instances in Amazon or wherever else the bad guys are going to spin up their instances, they just don't need to use the same system for very long. For sure. So next on our list, ProtectWise. We've talked about these guys a couple of times. Alex, when you and I were at RSA, we were able to attend their, their evening party where they, they released— they introduced their immersive security technology.
So this, you know, for those listening who haven't had a chance to look at it yet, um, at least at their booth and at their party, they had some VR glasses to kind of get you immersed into a kind of a cityscape view of your, of your network. So rather than showing you either the traditional network diagram or just a list of systems, this is really trying to show you what your network looks like as though the different hosts were buildings and then the connections between them were roads. Really a unique way to display this data. Yeah, and I think it's an interesting concept. You know, looking— when we were at that party, I was able to look through some of those VR goggles, see what it is that it looked like.
It wasn't immediately apparent to me how useful that would be, but it is interesting to see that they're pushing the envelope, trying to go in a different direction. And of course, you know, they're really known for their interface in general, so it doesn't surprise me that they're trying to even push the envelope even farther in terms of interface. And neither of us are probably exactly the person that it's made for, right? Like, it's made for the SOC analysts who are day in, day out going through alerts and trying to find those correlations, which, you know, isn't, isn't what we do most of our time. Well, I would imagine also it's, it's gonna be somewhat generational too, you know, as you get, you know, younger and younger folks coming into those entry-level roles that are more used to this sort of an environment, whether it's VR or that sort of, you know, immersive kind of environment, that they'll take to that better than us old folks.
Yeah, fair enough. So there's a, there's a link in the show notes here to to the press release about what they've done here. If you haven't taken a look at it, I'm sure their website's got, got some, you know, kind of watered-down versions since you're not going to get the VR version there, but probably worth taking a look and learning what they're doing. Yeah, so the next thing we had on our list was about Virtual Armor. So this, I don't know that we have a whole lot of news related to them, but it was just something that came up on our radar.
You know, we've— one of the things we try and do is talk about the local security companies that we have in Denver. And, uh, Virtual Armor popped up as a company that, you know, neither of us were particularly familiar with. I don't know that I had ever heard the name before, um, but they are in fact based here in Denver. Yeah, so I, I had heard of them. I had no idea they were a Denver company.
And this, this popped up because I came across a press release of theirs, which we can get to in a minute. But before I went to the press release, I'm like, well, who are these people, right? So it looks like they're, they're a company in the, in the Centennial DTC area. Um, according to LinkedIn, it says they're less than 50 employees, uh, somewhere between 10 and 50 employees. They are a managed security services provider.
Um, they've been around since 2001, um, which is certainly quite a while to last in that, in that field. So it sounds like they're doing some pretty good stuff. Uh, they do 24/7 monitoring. They have 2 different NOCs or SOCs, one here in Colorado and one in the UK. So lots of good stuff they're doing.
What really surprised me was that they're actually a public company. They're listed on the stock exchange. Um, the Canadian Stock Exchange nonetheless. So a lot of stuff to learn. If someone from Virtual Armor hears this and wants to reach out, we'd love to, to learn some more about this, uh, this, this company that's, you know, less than 50 people but on a— it's a public company too.
Yeah, and you know, being that my office is in Centennial, they're not far down the road from me, so it'd be interesting to know some of my neighbors. Um, so the, the press release they, they issued was really just to take to broadcast that they had signed some pretty good new clients. And if I remember correctly, they had signed somewhere over $350,000 worth of new recurring revenue in the last month that they were, that they were sharing with us. So some good success for them, and hopefully they keep growing and we can learn more about them as they grow. So next, we've talked a lot about SecureSet previously on the show, and we mentioned that they were opening a new campus in Colorado Springs.
So they've, uh, put out a release that Abe Thompson is going to be named director for the, that new Colorado Springs branch. So that, yeah, we have talked about them opening that. The good news is now they have a leader for it, um, Abe, who I haven't had a chance to meet yet, but he has a background in the Navy Cyber Warfare Division. He's going to be, you know, that's a good fit, right, for the, the Springs, which is really DOD-focused, really government-focused. Having someone who comes from that background is going to be a good fit for that environment.
Hopefully a Navy guy can, uh, manage to work with all the Air Force people that are down in the Springs. I think there's a pretty good Navy presence in the Springs too, isn't there? Yeah, which is a little strange for being landlocked. Uh, so that's the end of the news. We did want to make a couple recommendations.
Um, had some folks ask me, you know, what are other podcasts that they might want to listen to, and I have 2 that I want to recommend. One, every single day on my way to work, I always listen to the SANS Internet Stormcast podcast. It's by Johannes Ulrich. It's 5 minutes per day, and he really summarizes what's the big news of the day, what, you know, what's happened in the last 24 hours that you're not going to want to have missed, basically. So if you don't have a chance to, to do anything else, make sure you spend 5 minutes listening to that per day, and you'll, you'll be up to speed.
The second recommendation I'll make is for those of you who work in or run an enterprise security program. That's Down the Security Rabbit Hole by, by Raf Loos. Raf is a friend of ours and, and has been doing this podcast really focused on CISOs and security leaders at the enterprise level for several years now. So recommend taking a look at those. Yeah, and there's actually a couple that I listen to, Robb, as well.
So I listen to it daily called The Cyber Wire, which I think is pretty good. And then I listen to the, the family of Security Weekly podcasts. So Used to be the Paul.com, but they got rid of that name. So they have a more technical Security Weekly, they have an Enterprise Security Weekly, and then if you're, you're interested in startups, they have a Startup Security Weekly also. Yeah, and I actually listen to all of those as well.
It's a lot of listening, and unfortunately I have a drive where I get to do that. So let's go ahead and move into the events coming up this week. There's just 2 events here. On the first, we have this Cyber Summit USA Denver. This is that leadership-level event that we've talked about a couple of times downtown Denver.
Yeah, this is the first time they're here, so it'll be interesting to hear feedback from people that are able to make it. I'll actually be out of town, so I won't be able to attend that event. And I have heard, I have heard good feedback from folks who are planning to go. I personally can't make it, I have a conflict, but if you do go, let us know how it was and whether you think it'd be worth going next time. And the second one, also on the 1st, is the CTA Day at the Capitol.
So again, not directly security-related, but if you want to get in front of legislators here in Colorado and talk about technology and security issues, that would be a good thing. And then a couple weeks out, we just added a new one to the list. On the 14th of March, the Cloud Security Alliance has announced their March meeting. It's gonna be a CASB overview. That's the cloud access security brokers.
The big players in that area are SkyHigh and Netscope, and there are a lot of other players as well, but I think those are the 2 leaders. From looking at the notes, the Netscope folks are going to be giving the presentation here about, about a CASB overview. And also at that meeting, they're having their board of directors elections. So if you either are involved with Cloud Security Alliance or you want to be, this is a good time to get there for sure. We'll just quickly mention a couple others.
We've talked about it a few times, but the annual OWASP conference SnowFROC is coming up on the 16th, and again, Robb is going to be speaking there. As long as I get my, my talk together by then. Uh, don't, don't tell Steve that I, I'm not quite ready yet. I think you just told Steve. Uh, and then the RMISC, you know, that's the, the 9th, 10th, and 11th of May, Rocky Mountain Information Security Conference, the big security conference in the Colorado region for the year.
Um, we are still— we're closed for, uh, CFPs, and registration should open. I think it should open this week. I'll be able to tell you guys next week for sure if it opened, but you can take a look at rmisc.org. The big ask for you guys is if you have any sponsors who you can recommend to get involved with the conference. We're always looking for sponsors.
That's how both ISSA and ISACA are able to fund a lot of the great stuff we do through the year. So send them our way if you have any sponsors who might be interested. Yeah, and of course, go to the website colorado-security.com and look at the full event calendar there. We have more than we just talked about today, so That's where we'll update things first, so keep an eye out there for any new events. And if you're planning to— if you're gonna schedule an event, anyone out there, take a look at the calendar first and maybe don't pick— exactly, maybe don't pick the 16th of March where there's, you know, 4 other events already.
And then once you've scheduled it, let us know so that we can put it on the calendar. Yeah, we don't have to go find it. Job postings. So, you know, every, every week we try and come up with 10 interesting postings we think you guys might want to— might want to look at, from leadership level to entry level. And so Starting off today here, we have Honeywell.
They're hiring an information systems security manager. I don't know much about that position. I don't know much about it either. Honeywell, they do some good stuff, so worth taking a look at. Yep.
Next on the list, RubinBrown. They are a CPA firm, I believe, but they also have a cybersecurity practice, and our friend Rob Rudloff is over there and is managing that. Yeah, Robb got brought over there 2 years ago to create the cybersecurity practice. So we sent him a note asking, hey, what's this position about, this IT Risk Services Manager that they're, they're looking for? And his feedback to me was that the ideal candidate is someone with solid experience in IT audit, um, but who's willing to lead projects and get more experience in the cybersecurity side.
So they really need someone who can do both sides, audit and security services, going forward. So if you can go both ways, go look at that job. Yeah. Clovis Oncology, they're a, they're a Boulder-based health services company, and they're looking for an IT security manager. So if you want to work with a bunch of doctors, do their security, take a look at that one.
Important stuff. Yeah. Next on the list, Ernst Young, an advisory services manager for IT and risk and assurance services. I didn't look at this post specifically, but it sounds like, you know, a consultant around some of the, the risk services that they have. So if you want to get on the advisory and consulting side, that would be a good position to look at.
And I don't know exactly where this report's up to, but we know a couple of the guys over there pretty well. Um, with Matt Reynolds and, uh, excuse me, Matt Randolph and Jason Zellmer, who are leaders there. So if you're interested in this and you have some questions about the company, we might be able to get you in touch with, with some folks who know. Uh, next, uh, Wells Fargo Application Security Champion. You know, uh, that sounds like a really interesting role to me.
Um, I assume it has something to do with fighting. You have to have defeated the other. Do the championship— do you go get to do, uh Uh, jiu-jitsu against, um, uh, uh, sorry, I'm blinking. Um, but against Jeremiah Grossman. Sorry, that would be fun.
Absolutely. Uh, but really, what my guess is, it's, it's someone who, who comes into this development teams and really helps embed security into the SDLC, which I, I, I'm a huge fan of. This is what we do at Ping. It's probably the most important thing we do at Ping, making sure that the applications are built securely. So good stuff.
I'm also sure that it involves metals. So, all right. So Visa is hiring a cybersecurity systems engineer. That's down in Highlands Ranch. I don't know much about the environment there.
Yeah, you know, I think we all know Visa and what they do. You know, I have heard from some folks that used to be there that in the security department they've had some, say, some culture issues and there have been a number of people that left. So I think that this could be a good opportunity if you want to go in and try and make a difference and help turn things around. I know that they're not just only this job, but I would imagine they're gonna be hiring a lot of other jobs as well. Next we have Kaiser Permanente, a principal security architect.
Do you know much about this one? You know, there is a cybersecurity architecture team at Kaiser, and the gentleman that leads that team is a great guy who'd be a great person to work for. So I'm not sure what this particular architect position is, but they kind of focus on different areas. Whether that's IAM or network architecture, other things like that, and they go in and do assessments of different programs and work with different teams to do architecture assessments. I think that could be something that's really interesting.
Next on the list, RTD is hiring an analyst in information systems risk. RTD, of course, the public transportation throughout Denver. We know Sherry Lee, who's the head of security over there. She's been there for about 2 years, and reached out to her to ask about this position as well. They're really looking for someone who has at least a little bit of experience and is looking to grow with the team.
So you don't have to be, you know, late in your career to consider this one. Um, look, but they would like someone who has some experience with compliance and assessments to help with, uh, like PCI, HIPAA, and NIST Cybersecurity Framework work that they're doing. Cool. Someone who's got good communication skills and really, like, like I said, they want to work downtown as a part of a small team. So next on the list, InteliSecure is looking for a platform delivery engineer.
You know, InteliSecure, they do some managed security services as well, so I'd imagine this is involved with helping to deliver those services. Yeah, they, they're— they used to be called BEW Global. They've been InteliSecure for, I think, a little bit over 2 years, and, and they are really well known for being the DLP experts. And I think they moved into SIEM a couple years ago as well. So managed DLP, managed SIEM, good opportunity.
That's also in the Tech Center area. And then the last one on the list is again for Kaiser Permanente, Cyber Risk Defense Intern. So if you're a student or someone lower on the experience level and you want to get into an internship, this sounds like a great opportunity. The Cyber Risk Defense Center, which is the security operations center for Kaiser is based here in Colorado. They've got some great folks over there, some people that have a lot of knowledge, so I'm sure you'd learn a lot.
Matt Parks, Katie Winslow are some folks that we know from local area that are down there, and I think that could be a really good opportunity for somebody. All right, well, that takes us to the end of the agenda here. We'll go ahead and move it over to our feature interview for the day. This interview was with me sitting down with Brian Beyer. Brian is the founder and CEO of Red Canary, a local security company.
So looking forward to that. Anything before we go, Alex? That's it. Thanks, Robb. Everyone have a great week.
See you next week. Hello, this is Sean Murray. I am a director on the International Board of Directors for ISSA, and I am a principal scientist at Northrop Grumman Corporation working in Colorado Springs. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security.
This is Robb Reck, and I'm here today with Brian Bayer. Brian is the founder and CEO of local security company Red Canary. Welcome, Brian. Thank you. Thanks for having me.
Absolutely. Brian, it's been a treat to get to meet you over the last— what's it been, about 2 years now, I think, since we, since we met each other at a— at the time it was called C3, right? Colorado Cybersecurity Consortium, maybe, which has now been renamed as Colorado Cyber. We met at their first event at the Governor's Mansion. Anyway, ever since then, obviously your company's been, been making some progress.
I'd love to hear if you could just talk to us a little bit about Red Canary, about yourself, and how you got here. Absolutely. So Red Canary is a managed endpoint security company. We've been around almost 3 years now, so we'll hit our 3-year anniversary in February. What we do is we make endpoint security easy for all of our customers.
So many of you and many companies may be purchasing EDR tools like a Carbon Black or CrowdStrike or others, and then you have to build the team that goes along with that. And what we've done is we've taken great security minds and people who've built security operations programs in the past and paired them with some awesome security engineers and built this program that should make it much easier and cost-effective for you to do it. So it's been a great experience and a great team we get to work with. It's one of the most fun things about coming to work. So 3 years, you know, I'd love to hear, was that 2014 or 2013 that you started?
Yep, 2014. 2014. So 2014, you had an idea. How did we get there? So 2014, we had an idea, but more importantly, we had 4 pilot customers, and those were Actually, people that one of the 3 co-founders, Keith McCammon, effectively convinced them to subscribe to Red Canary to make their security better.
And it was about that vague. We didn't know exactly what it would look like. And really what we started doing, we kind of looked like a traditional MSSP, right? We had some network monitoring tools. We had Carbon Black at the time.
We were their first technology partner. And so we had this more wide variety of services. And what we did, you know, thanks to Chris Rothi, one of our other co-founders and our CTO, he started cutting pieces off of it. And the question was really, you know, we provide this great level of detection and response, what if we took away the network sensor? Does it really make that big of a difference in terms of what we detect?
And so we started cutting more and more pieces off until we came up with this very focused and very easy-to-use solution, which is Red Canary today. So the setup process is really one of the things we're most proud of. You simply deploy the sensor across your endpoints, and from there you have effectively, you know, Fortune 100-grade endpoint security behind it. And it's really a great credit to, you know, we wouldn't be here if it wasn't for those pilot customers who said, yeah, we trust you, you're going to make a big difference. And all of them are still customers today.
So 2014, you had 4 customers. Let's go back a year, 2013. What were you doing? So 2013, I was doing cybersecurity problem solving, let's call it, for a company called Kairos. Kairos is a boutique cybersecurity firm, half in the Northern Virginia area and then half in Denver.
So a lot of the work we did supported the defense and intelligence community, really with whatever their cybersecurity needs were. And that was a follow-on or a, you know, a new company created out of a defense contractor that was really my first introduction to cybersecurity, which was the Mantec Computer Forensics and Intrusion Analysis Group back in the Northern Virginia area. So are you from Northern Virginia or where are you from? I'm not. I'm actually a Wisconsin and Michigan guy and then went to Purdue.
So very much Midwest and expected I'd go back out to DC and work for the Mantec team after college and just happened to take a trip out to Colorado, actually down to the Springs. And it was November 15th or something, and it was supposed to be a blizzard, right? Because if you're in Michigan and you go skiing, you— the only reason you come to Colorado is to go skiing in even more snow, and everybody gets stuck in the airport, right? And so it's supposed to be this blizzard area, and I came out here and it was beautiful. I was in jeans, I had the windows rolled down.
I was This is great. So I called my fiancée and said, if we're gonna move, now is probably a good time to not go to the East Coast. Yeah, we've been here almost 9 years now and haven't looked back. So did you come here and get a job, or— Yep, came here and worked for Northrop Grumman out by Buckley Air Force Base. And what year was that you came out here?
That was 2009. All right, so spent— I think I spent 4 years working on a lot of the satellite programs and the big data processing systems. Over there, which was actually a surprisingly comparable experience to what we do here. In the satellite world, you know, you have a giant data collection system, right, which is dozens of satellites that fly around and soak up data. Then you use technology to figure out what might be potentially interesting, and then you put those in front of a human analyst who says, yes, this is bad, or no, it's a false positive.
Very similar to what we do at Red Canary. The only result there, you know, in that case you generally end up with like a crater in the ground afterward as your response. Right, a little bit worse consequences maybe. Definitely a worse consequence if there's a false positive. Yeah, so Red Canary, you know, you basically sounds like you saw a big problem and you started trying to solve the big problem and realized later that you could maybe solve a smaller problem with more precision and maybe provide as much or more value.
Is that— yeah, that's a good way to think about it. I think the— one of the biggest strengths of Red Canary is we don't try and do 20 different things. We don't try and do 20 different things because it's really hard to do 20 different things exceptionally well. We really focus on solving one slice of your security problem and doing it better than anybody else could. So define for me, what is that one slice?
It really is your endpoint detection and response. So it is all of these prevention tools you have, you've put antivirus in place, you've put your network prevention tools in place, those are going to get breached, right? Something is going to get by them, and it might be something as simple as one of your users gets phished. When your prevention tools fail, you really want something behind that to be detecting those threats and allowing you respond, and that's what Red Canary does. That's the slice where we fit.
It's the backstop. Exactly. Yeah, so 2014, you had, you know, an initial 4 customers. You went from a larger MSSP looking at network and endpoint to focusing in just on endpoint. Yep, exactly.
And how did you go from those first 4 to growing? So really, if you look at all of that first year, we didn't really grow very much. It turns out from what we've learned, we kind of did the startup thing the different way or the opposite way of how it's normally done. We didn't show up in 2014 and say, we have the solution to all your problems, here's all our marketing buzzwords, come buy Red Canary, and then we'll go raise VC money and build the product later. Instead, what we did was for those 4 pilot customers, we built what is today Red Canary And then once we were confident and really believed this was the right way to solve your endpoint security problem, only then did we start going to market.
So March of 2015, we publicly launched, and from there we've grown relatively quickly since then. I think we've hit a very good time in the market where lots of people are buying EDR products and they're realizing this is very challenging to do myself, and we're the perfect fit for that. And so March 2015, you kind of had your coming-out party.
What's your growth look like? Has it been pretty steady? Has it been frustrating? Talk to me about that process. It's been relatively consistent in that so far it's been something like 200% to 300% year-over-year growth.
I mean, it's been very fast through like you want to see at an early stage. Is that by revenue? Yes, revenue, customer number, very similar. And as it's grown like that, I think one of the best things we ever did was we as the founding team, we were the first salespeople, you know, and that is for someone who's never sold a thing in their life before, you know, and being a technology person and getting to build some of the first versions of Red Canary, it was a very different experience having to come out and, you know, convince someone like you, Robb, or, you know, this is the type of thing that can make your security better, and here's why you might find value in it. You know, and so those first conversations we had with CISOs and with other people really helped us understand what value do we really provide.
Yeah, I think maybe the first conversation that you and I had that was one-on-one, we talked about how I defined the problem set, right, which was broader than what you guys solve. I was thinking of it as secure my endpoint, and that means, probably means prevention, antivirus, and it also means detection, and maybe it means forensics and all these other things. And I, while I still see, you know, I have a bigger problem, I do appreciate that you guys have narrowly defined what you do and that you're really good at just that thing. So, you know, full disclosure, I'm a Red Canary customer and been able to experience that what they're offering is really focused on making sure that they have the right resources looking at detection, right? They're not looking at other stuff.
So I appreciate that, and I think that's been pretty valuable.
Let's talk about the company right now. How many employees do you guys have at this point? So we have 28 employees right now. And we are currently sitting in the Red Canary headquarters in downtown Denver. How many— are all 28 here located in this office?
They're not. So our security analysis team is remote across the United States, as well as our technical account management team. Many work from their homes, some work from local coworking spaces. Really, especially in that area, we want the best talent and the people who can best serve our customers wherever they are. The remainder of the company, the engineering team, the leadership team, as well as the sales team and marketing team are all here in Denver.
So how many in this office? 20-ish? About 20 now. Yeah, yeah, we've gone from 4 people in this office when we first moved in and we were here every day, and it was quite lonely and awkward, to filling it up quite a bit. You're gonna have to move out of here one of these days?
Is it gonna be— someday we'll have to, or we'll have to take over another floor. Yeah. So is this your first time as a CEO? First time. Not only first-time CEO, first time in a startup.
You know, first time at a very early-stage company like this. So, you know, I do find this story of how Red Canary grew to be interesting, but I'd love to hear your personal story of, you know, becoming a leader of a company and having all these people depend on your decisions and all, you know, talk about that. I'm fascinated. So I think for me it goes back, it could go back a very long time. You know, I kind of grew up seeing, seeing a little bit of this life.
And seeing a little bit of the consequences of this life. Back in Michigan, my grandfather started a— what started as a wood trucking company, a timber trucking company, that then grew into, hey, let's own the actual land and perform forestry services, and then let's buy some stone quarries and let's ship breakwall stone, you know, down to support Hurricane Katrina and, you know, the breakwalls there, and really grew into this conglomerate of companies. Companies that both of my parents worked for. So I grew up in this, right? My first job at some probably very illegal age was, you know, working at those companies supporting the different jobs throughout there.
So I've always had, you know, exposure to the business side of things, and that's been the fun for me. Coming through Purdue, you know, and my real passion is building things, and I think a lot of the ways I've expressed that passion throughout my has been on the software side because there's nothing that's easier to build things with than software, and that's really evolved into what we do at Red Canary, right? We, we have built an exceptional product and service to serve our customers, but the bigger thing we're building here is the actual company itself, right? We're building a culture where we put our employees first and we put making our customers' security better first, and that's really one of the most exciting things about this team. Team.
And let's talk a little bit more about your leadership, you know, getting into this. Did you have any training on how to run a company? Do you have an MBA? Was your degree in business? No MBA, no degree in business other than what you learn, you know, being exposed to those companies from the beginning.
I mean, I had decent exposure through some of the coursework I had done at Purdue and, you know, a natural involvement in the business side of any company I've worked with. So how did you get— how do you feel like you've learned the skills you needed to make this kind of transition to running a company? You know, a lot of it is find the right people to learn from and then also find the right resources. You know, a lot of what I've learned, you know, for anybody who's read Inc. magazine, hands down my favorite resource ever to go open up every month and read 50 different stories of about people who've built all types of companies. And, you know, that's been— I think that's a good example of what's been pretty important for me, is that it's very easy in the tech world to think that all of the other companies out there and what you're supposed to build as a tech company is like what you see out of Silicon Valley, right?
It's— you're supposed to be the next Facebook who grows at that rate and everyone knows who you are, and the expectation is that, you know, you're going to be a unicorn as fast as possible, and that's the goal. What's really neat about the stories you learn from Inc. and from non-tech companies is that you can build awesome companies doing anything, right? I mean, the guy who runs the construction company down the road from you, his job is just as hard as mine is, right? He's solving a very different problem than I am, but the business he's building is just as important. Yeah, I, you know, we're on a podcast, so I can mention a podcast that I've been listening to lately.
NPR, it's How I Built This. Have you seen this podcast? It's really interesting. And they, for those who aren't aware of it, yeah, it's a, I think it's about 30 to 40 minute podcast where the, the host sits down with someone who built a company that you've probably heard of and just talks through how it worked. And, um, it, I find it very interesting, and I listen to the ones that, that are not as typical dot-com type stuff.
I do think there's a little bit of a challenge with any of those where you basically only hear about the successful companies, right? Absolutely. They don't sit down and interview the guy who started, you know, Pets.com. Although that'd be an awesome interview, wouldn't it? I'd love to hear about that.
I guess, so my question is, is there anything you've learned from your research in Inc. or any other conversations you've had that have been especially poignant, some advice or some guidance that you're taken to heart? Yeah, I think one of the biggest things, and it really proved itself in kind of the middle year of Red Canary, was really being careful who you take money from, right? So, to use your story, and I think a perfect way to think about it is it's almost like survivorship bias, right? Exactly. You only talk about the companies who survived, and if you're trying to get people excited about raising venture capital money, you only talk about the people who made great investments and who their partners were, and it turned out well, right?
You rarely hear about the case where you took money from the wrong person and then they fired all of the founders and forced, you know, the company to get sold to a terrible place. You don't hear about that as much. And so one of the things we were very careful about was being sure we knew if we wanted to take venture money, who we wanted to partner with, and what we were looking for, you know. So all cards on the table, we actually looked to raise money I guess, early 2015 and could not find any partner we wanted to work with. They didn't fit the Red Canary culture.
We weren't confident that they were going to agree when we said we're going to put maintaining quality above growth at all costs, you know, because that's not the typical VC way. And so, it was only when we worked with Frank from Access Venture Partners here locally and Alan from Norah Mosley Partners out of Atlanta, we found people who really believed in the same thing we believed, and that was the most important thing for us. The second thing that was great was we didn't need to raise the money, right? We had gotten to the point where we were cash flow positive, I think just on the hair of being profitable, which is kind of unheard of for an early-stage startup. And so we were in a great position where we really could decide, do we want to take outside money or do we not?
Yeah, and that was the most, the best advice I think you could ever get is if you're starting your company, don't assume you have to take VC money. Make sure it's really the right thing you want to do. So how did you fund the first year? Did you guys bring your own money to the table, or do you have an angel, or how'd you do it? So we actually took, we took Red Canary and spun it out of Kairos, and so that had $2.5 million of seed funding coming from Kairos at the beginning.
So that funded the first year and a half or whatever? Exactly. Gotcha. It funded us perfectly to the point of when we sold enough Red Canary to be cash flow positive, so then wouldn't need to anymore. That's nice.
Good timing. So it was perfect timing, and it was, it was really neat. So we're the second company that's done this. Carbon Black actually was incubated and seeded out of Kairos as well, and then ended up to take their, you know, venture capital money from Blackstone. And then so Carbon Black pre-Bit9, the— correct, the original, the original Carbon Black.
Which then, you know what, 2 years ago was acquired by Bit9, and now they rebranded Bit9 as Carbon Black, and they just confused all of us. It's hilariously confusing. Yeah, so they have a new prevention technology they bought last year, right? Are they gonna call that Carbon Black too? That is Carbon Black Defense.
Carbon Black Defense. So we have Carbon Black Protection, which is formerly known as Bit9. That's the AWL, application whitelisting. Exactly. Okay, we have Carbon Black Response, formerly known as Carbon Black, which is your EDR tool.
And then we have Carbon Black Defense, before the acquisition was Confer, which is next-gen antivirus. Got it. There you go. For everyone listening, now you understand the Carbon Black product line. So, all right, tell me a story of something that's gone really well, either for the company, a great decision you guys made, or even as you as a CEO, something you're like, wow, that I did something cool there.
I'm really proud of what happened there. So I think honestly one of the best stories of that is, you know, for anyone who's ever seen Red Canary, one of the neatest things about the portal and the actual product is that at any point when we've detected a threat, there's a big red respond button you can click. And you click that respond button and say ban this from ever running again, maybe delete the files off the system, and if they put some persistence keys in the registry, clear those out, and go execute it. And it doesn't matter if that system is down the hall or if it's over in China. When that system checks in next, those commands get run.
It was something honestly we built, I think, as an RSA demo. It was like a— it was a Beast Mode project, which is effectively our weekly hackathon and company get-together we have every quarter. And we did it and we thought it would be great for demos. But we didn't think anyone would actually use it, right? I mean, how often do you have security people who want to click 3 buttons and remediate something?
That's normally IT's job. Yeah. And it turns out like that's probably the most used feature of Red Canary. We get security audit alerts when it happens, and it happens all day, every day. I mean, it's really one of the neatest things where you think I'm going to build maybe a gimmicky feature, and it turns out to be one of the best products or parts of the product you could build.
So whose idea was it? I think it was Chris's idea. CTO? CTO, yeah. Yep, he— and it's really neat to see how Chris has developed the product over time because Chris has never held the role of a, you know, security officer or security analyst or director.
So from the beginning of Red Canary, this was really relatively new to him, right? This was Keith's problem. He was the chief security officer and an IT security director for many, many years, and to see the two of them together, you have Keith whose problem it is, and then Chris, which is a completely new perspective looking at that problem, to say, how can we solve this in the best way possible? So we don't have any of the baggage that a typical security company might have. None of us have done 20 years at McAfee.
Right. Good or bad, sure. So, you know, on the other side of that, right, that's a great feature you guys have had a lot of success on? What is something you guys did that didn't work well, either as a company or you as the CEO of the company? Yeah, I mean, one of the things was we attempted to have someone else sell Red Canary before— To resell channel?
Not even to resell, just to actually be part of the sales team before the 3 of us founders did it first. And, you know, one of the huge things we learned, you know, we outsourced some of that and some of the initial calling to another firm, and it was a disaster. I mean, it really made us very uncomfortable with how they positioned Red Canary. You know, it just didn't have the quality and the feel of someone like us who really cares about making your security better and never being, you know, a slimy salesperson or trying to jam something down your throat you don't really need. So, one of the best things we ever did was fired them and then said, we have to sell it ourselves first.
And in hindsight, I would never— I'd never be part of a company or never start a company again where the founders weren't the people who had to sell the first, let's say, 20, 30, 40 customers. So now I think you as a founder selling the product is going to change you. It's going to make you understand your customers better, and I'm sure at some point that gets back into the product and better aligns the product with the customers and the need they have, and I totally get that. But at some point, you're gonna scale, and you're gonna bring on a salesperson, and that salesperson is going to have the same potential risks that that first person you hired did. So what did you learn from the first time that made it so when you have since hired a salesperson that they are better able to address that?
I trust, I trust myself, and I think we as a leadership team trust ourselves more than we trust just the experience of someone who's sold software in the past. And what that means is we're actually going through this now, you know, we've grown the sales team pretty significantly in the last several weeks. Today is the end of week 1 of their new training, and their new training is not just, here's the process of selling at Red Canary. It is what is now 30 pages or so of straight content which says, this is the problem a security person can have, and this is how Red Canary might be able to help them. You know, because we care a lot about making sure our salespeople actually know why they're trying to help you.
You know, we don't want to be the people who show up and say, you know, forget what it was, do you know how to stop randomwares?
Randomware, yes. No kidding, you go— we just created a new thing. Did you say ransomware? I said, yeah, do you know how to stop ransomware? Right?
I mean, stuff like that, like, that's my greatest nightmare, is that that would ever happen. Yeah. And so what you have to do is you have to spend a ton of time and energy, right? Our entire leadership team did nothing for the last 2 weeks other than build and train this training material. And it's a huge commitment, but it's what you have to do if you want it done the right way.
And how are you going to measure success? Is it Is it new sales dollars, or how does success for this new sales team get measured? So, some of it obviously is new sales dollars, so it's new customers brought on board. There's also, you know, the customer satisfaction side of things. One of the metrics that's most important to us, and one of the things I care most about, is what our retention rate is.
You know, this year, when we wrapped up, I guess last year, so our fiscal year actually ends the end of this month. So, we've come to the end of this year, we had zero customers voluntarily churn. 2 of them got acquired by other larger companies. Everyone else stayed with Red Canary and renewed for the future. That's great.
And that's in, you know, industry average is maybe 90%, you know, renewal rates. I want to keep it 100% forever, right? As much as possible. And that, to me, honestly, is one of the most important numbers. The new customers number is great and everything, but if the new customer number is even if it beats our expectations, but our renewal rate and our retention rate is only 80%, that's a bad year.
Yeah, it's not good at all. I don't know if this is a common phrase, but at Ping we call it the snowball. You know, you want to build the snowball, and if the weather gets too hot and it starts to melt, your snowball shrinks. That's not a good thing, right? You want to keep it nice and cool and keep the customers happy.
Customer satisfaction, net promoter score, all that stuff. Exactly. But it's not, you know, and a lot of the reason for that is as a subscription business, like, that's a huge part of your value and your revenue over time. The most important part of it for us is I want you as a customer to go tell everyone you know, man, when you have an endpoint security problem to solve, you go talk to Red Canary. And we want to actually make your security better, right?
If you leave Red Canary, it's because we didn't do a good enough job. Yeah, so that's great. Thank you for sharing that. The struggle there initially with sales and how you guys have addressed that. What is— what's your market?
Who are you going after? Big companies, little companies? Mid-sized companies. Mid-sized? Yeah, so the place where we think we make the biggest difference is any company generally under 10,000 employees.
So they're to the point in maturity where they said, my prevention tools are not enough. So AV is not enough, even if I buy next-gen AV. You know, let's say that's 90% effective, there's still that 10% that gets by, and they want to do something to make that better. That's the ideal place for us, and it's very different actually than most security startups. Most security startups get started and they spend all their time trying to land the Fortune 100.
Yeah, that's, that's the trend. Yeah, they want the biggest logos, right? And for us, we have a couple of those customers, but the biggest difference we can make is for the smaller team, right? The smaller team has smaller budgets. They don't have the ability to hire great security people to do it themselves in this market, and that's where we can make the biggest difference.
So you guys, you know, let's say— I don't know if you're able to give these kind of, or you want to give these kind of numbers, but I'd be interested in knowing how many endpoints you monitor and how many people it takes to do it. Before I ask you, I'll tell you why. I'm just thinking, you know, as the CISO for a company, I can think about my my ratios internally. Okay, you know, if you have 1,000 endpoints, you need to have one, you know, one analyst looking at whatever, and it doesn't scale all that well. So I'd love to see how well yours scales and what those numbers look like.
Yeah, so I'll tell you what the numbers are, happy to share them, and I'll also tell you why you shouldn't use them for your own internal modeling purposes. So today we monitor over 150,000 endpoints, and we do that with roughly an 8-person security operations center. And that's in the flow, and please correct me if I'm wrong, I believe the flow is, you know, Carbon Black or whatever your EDR solution you're using is kicks out a large number of events that go into the Red Canary engine, and you guys have algorithms that tune those events into a smaller subset of potentially interesting things that go to a human, one of those 8 people to triage. Very close. So the only difference is we do detection ourselves.
So what we get from Carbon Black or any EDR product would be raw data. So it's actual completely raw data. So you're not using their eventing at all? No, we built our own. We built Red Canary before there was eventing in any of the EDR products like that.
So we just take the raw data. It gives us the chance to do things like user behavior analytics and apply some more interesting algorithms that you couldn't do on top of preprocessed data. So beyond that, spot on. So raw data comes to us, we perform detection, that then goes in front of our security operations center. That's when those analysts, they do the investigation of every event.
So the reason why I said, you know, so if you think of that ratio, you're looking at roughly 20,000 endpoints per analyst. If you built this yourself, you'd probably be able to do about 3,000 endpoints per analyst. The reason why we get these massive, you know, efficiencies of scale is because we actually built what we call the Red Canary analysis platform. So the tool that our SOC analysts work in and our team works in, it's not Carbon Black, it's not an EDR product, it's inside the own our own Red Canary platform, which is very well tuned and has all of these tools and capabilities to allow them to very effectively make decisions and allow those decisions to be something that teaches our engine. So the reason why we get better and better and more efficient is because every time an analyst makes a decision and says, no, this was a false positive, the engine learns from that so it can replicate similar behavior in the future.
Yeah. So when we deploy across, you know, any of your systems, if we see that you have a logon script that does something that looks relatively evil, right, like it runs some PowerShell commands and maps a bunch of network drives, which is exactly what an attacker would do, when our analyst looks at that and says, no, that exact command line or this variation of it, when running in this context across these systems, that's okay, the engine learns from that and says, if I see that again, as long as it's exactly the same or very similar, I don't need to show it in this context. That's great. So, yeah, from a company perspective, potential folks in Denver who might want to work for you, what kind of roles, as you guys grow, what kind of roles are you going to be looking to fill and what kind of skills are you going to be looking for? I think it's going to be the pretty typical roles across the company.
So I think the biggest focus for us right now We are building our sales team, so if you are one of the best and let's say most loved security salespeople by your customers, you know, if a CISO is going to shoot me an email and say, hey, you picked up so-and-so, they're the best person I've ever worked with, you know, that's who we want at Red Canary. That's exactly who. So the sales side is obviously a big part of what we're doing and making sure we find the right people there. The other side of things is on the engineering and the security side. So what kind of engineers?
Engineers— so our stack on the portal side is Ruby on Rails and all the associated tech with that. On the engine side of things and how that works, it's actually a custom-built stream data processing system. So if you're familiar with Apache Kafka and some of the, you know, non-Hadoop-based systems that you'd plug in beyond that, that's a lot of how our core infrastructure works. And then on the security, the security team, the analyst team, what kind of skill sets are you looking for there? You know, the interesting thing about that is there's no SANS course or any sort of training that teaches you how to be an endpoint security analyst.
So really anyone with good security background who wants to come in and learn a very deep area, that's the place to come. We're gonna put you through the Red Canary boot camp and We're going to teach you what Windows does under the covers, what OS X and Linux do under the covers, and then how the attackers use that to their advantage and how we find it. That's great. So let's talk a little more broadly about the security community in general. Excuse me, the Colorado security community in general.
There's the big, what, 4 companies in town with Optiv, LogRhythm, Webroot, and Ping Identity as kind of the big 4. And then there's the up-and-comers, yourselves and ProtectWise and Swimlane, and I don't mean to exclude anyone else. CyberGRX. CyberGRX, they're brand new, right? Brand new, came here from New York.
6 months ago or whatever. I think they're funded by Blackstone and operate out of the Optiv area. And there's more, and I'm sorry if I missed you, let me know and we'll get you included in the future. InteliSecure is a great local company that does MSSP. On, on DLP and SIEM down in the Tech Center area.
So anyway, we have a vibrant community, and I know we were just talking before the interview that you have recently joined the board for Colorado Cyber. So if you don't mind talking a little bit about that organization and what you're doing there and helping. Yeah, absolutely. So Colorado Cyber really has a, a pretty special place in my heart because when we started Red Canary, you know, Colorado Cyber Robb, was where you and I met for the first time and really, you know, one of our first chances to talk with a lot of the local Denver security community. And that was exciting, right?
It was a great place to bring together people on the security side and who are responsible for protecting their companies and then letting them work with the other people at vendors, right? Not the people who want to sell them things, but the people who actually want to understand their products and their problems and how they can work together. So I joined the board, I have a great team that we get to work with there, and our passion and what you should see from us in 2017 is a curriculum very focused on how do we explain and really learn from each other across the security ecosystem. The next event we have a great set of panelists, actually your general counsel, Lauren, is sitting on it talking about risk. That's the type of thing that I think is really important for this ecosystem is learn more about security than just what a vendor might sell you.
Learn more about how should you think about risk. What do you think it's going to take for Colorado to take that step from maybe a tier 2 security and tech player to that next step up to being the premier place in the country or in the world for both tech talent to come to and also for tech security companies to come. So I think what you just said 5 minutes ago is the starting point that we have to do over and over. You know, you just listed that Ping, LogRhythm, Webroot, and Optiv are in Denver. Yeah, I can almost guarantee you if you poll 10 people who are not in Denver— actually, poll 10 security people who might be in Denver And they don't even know those companies are all based here.
You know, one of the things that really drew me to get involved with Colorado Cyber is this understanding that we as Colorado security companies kind of suck at marketing, right? We're the typical Colorado people who are maybe a little too quiet about what we do. Nobody knows that there's great security companies that are here, and that's something I think we need to change, right? We need to, we need to make sure that if you're going to build a security team, you should do it in Denver. It's a great ecosystem.
If you're going to build a security company, do it in Denver. You know, it's great to see the CyberGRX guys come from New York City where they could have built a security company, and instead they do it in Denver. Yeah, that's awesome. Let's get some of the companies from the Bay Area to come out here. Yeah, one of— a friend of the show, Ed Fuller, who was at Kaiser Permanente, started at CyberGRX recently, and I know they're building a good team, and they're focusing on third-party risk.
And helping simplify the problem, I think, for both the vendor side and the enterprise side. So if you guys have problems in that area, it might make sense to reach out to CyberGRX on that. Yeah, if you're tired of filling out a 30-page vendor diligence form from every potential company you work with, maybe someday they'll make that problem go away, which would be a great day for both of us. Yeah, and at Ping, that's certainly something we work on quite a bit. So let's, you know, talking about where you see taking your company in the future, what's, what's, you know, 2017 look like?
What's 2018 look like? So it's a lot of growth of what we can do to support our customers. That growth obviously is going to be constrained by making sure we can always deliver good quality, but really our goal here is make our customers' security better and build one of the great security companies in Denver. You know, I'd love to be the place that people think about as the bar for quality for security companies, right? Unparalleled quality in terms of what we actually do to make your security better.
And that means you end up being a great place to work. You know, you don't have people who are frustrated working there. They get to work on great problems. And at the end of the day, they know they defend a lot of great businesses that we get to work with. Yeah, that's great.
You guys, talk to me about, you know, you mentioned in 2015 you were looking to take money and nothing worked out then. In the last, you know, almost 2 years now since then, how have you been going forward and what's your plan in the future about capital? Yeah, so, you know, just to be clear, so in 2015 we didn't raise any money. Last year in the summer of 2016, once we had become cash flow positive, we found the right partners in Access Venture Partners and Nora Mosley. So we raised the $6 million in Series A last summer.
Right. So that is, that's lots of money, money that still sits in the bank and really has allowed us to accelerate, you know, building out parts of the team that we would have done more slowly. Yeah. So is the plan to grow pretty aggressively? You know, the Burn cash like the Silicon Valley model, or are you trying to stay— No, I like cash very much.
We've burned cash before. I don't like burning cash. The plan is to grow as fast as we can while still maintaining quality, and obviously do that while being financially responsible all the time, right? I have no interest in being a company that raises money, burns it 18 months later, and then is out desperately trying to raise it Yeah, well, I think that sounds like a whole— that's a painful cycle to go through and kind of leaves you exposed there at the end of the cycles too. So what kind of guidance, you know, we're coming to the end of our time here, what kind of guidance do you have for security leaders out there?
You know, let's kind of put aside what Red Canary does, just what do you see folks like myself or, you know, other CISOs doing that we could be doing better? Just general guidance for us. I'd say the biggest general guidance, if you're not already doing it, ignore the marketing from most security companies and really hold them accountable for it. You know, I think you look at some of the— we're what, 4 weeks away from RSA? It's about to start the RSA drinking game time, right?
Who's going to have the most buzzwords? Who's going to have the carnival barkers, you know, hawking at you as you walk by? We've got to hold security companies accountable for that. Yeah, you know, it's the only way to really determine if I should partner with that company, you know. So hold your vendors accountable.
The other thing is keep focusing on improving that internal security with more than just other products, right? A lot of the people that we work with, they can make a much bigger difference improving their security by making a few IT changes than they ever could by buying more products. Keith will get a t-shirt at some point because he runs around all the time saying, better security through better IT, right? And it's spot on. It's one of the biggest differences you can make.
Yeah, I think security is built on the back of the IT department they're securing, right? If IT doesn't have repeatable processes, if they don't have an inventory control system, if they don't do change and configuration management, all of our controls kind of are for naught. Yep, exactly. That's great feedback. Any final questions, comments, something you want to tell the community?
What's the biggest thing you want to see from the security community in 2017? You know, I'm kind of a broken record for years now. I think that we don't— to echo what you were just saying, we don't so much need the newest technologies as we just need to get better at what we already do. We need to become repeatable in our processes and understand, you know, what does it mean to make changes without understanding the risk of those changes? And what does it mean when we, you know, when we bolt on security after the fact?
All these things that don't take a new tool, they don't take, you know, the greatest machine learning, AI, you know, BYOD device you can find. It just takes people really taking their job seriously and maturely. I think that that's what we most need to do across the organizations, across the community. In terms of what I'd love to see from vendors, folks who can tackle a problem and state what that problem is clearly and concisely. Anytime I talk to a vendor who— I feel like it's a little bit the snake oil.
It's, you know, good for whatever ails you is what they want to sell me. Well, you know, that's, that's not how it works. Or if a vendor approaches me and says, hey, tell me what, tell me what you're gonna work on this year and I'll tell you where it fits. You have to remember that I get, what, 1,000 of those a year. I can't— I'm not gonna respond to each of those people and tell them what I'm doing.
You know, clearly state what your value proposition is, you know, where it is, and then I can decide, does that fit in with what my schedule is this for the next year. I think that those are probably the, the biggest things for me in 2017. Good. We can start the most unsexy security company ever. Do what you were doing before, but better.
Do it better and write it down. There you go. All right, well, Brian, thank you very much for your time, and thanks for letting us come see your office. We'll look forward to catching up with you soon. You bet.
Thanks, Robb. All right, have a good one.
Learn more about the Colorado security scene at colorado-security.com. Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.