Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. All right. Welcome to the Colorado Equals Security newscast for the week of April 3rd. This is Robb Reck.
And this is Alex Wood. And we are coming to you not live from the studio in my basement, Alex, how's your week been? You know, it was pretty good. Took a little extra time off this weekend, did some, some touring and drinking downtown on Friday with some family and friends, and then didn't have kids' athletic activities on Saturday because of weather. Yeah, the weather kind of changed things a little bit this weekend.
I was fortunate on Friday evening I got to do a volleyball tournament, and I played from about 6 o'clock till almost midnight, so 6 hours of of fun. Good way to get some sweat out and enjoy the cold weather. Sounds like you got your money's worth. I did. And yesterday got to go see the new movie Boss Baby with my 7-year-old.
Yeah. Alec Baldwin. Really? My wife was trying to convince me to go see Beauty and the Beast, and I think she's going to take the kids and I'm doing this instead. Congratulations.
Well, good. Why don't we go ahead and jump into the news? Look at what we got today. Uh, the first news story for us today is that OWL, the local security company OWL, has added a couple of advisors to their board, advisory board. Yeah, and, um, I don't know if, um, if they are still technically One World Labs or not, or if they have, you know, like KFC shortened it to just OWL.
Um, but, you know, they've been around in Denver for a long time, some ebbs and flows. They've had some personnel changes and sort of that sort of thing, but Um, you know, they are big into the, the darknet intelligence. So they have a giant database of things from the, the dark web that you can, you know, search and hopefully find intelligence from. Well, you know, their big, big story for them was it, was it last year or was even 2 years ago now when Chris Roberts, who was the founder of OWL, um, you know, he had the big airplane hacking, uh, fiasco that ended up, you know, the FBI reached out to OWL and somehow he ended up getting kind of pushed out of the company and And I think at the time they went bankrupt and a lot of the folks left at that point. I'm sure Chris appreciates us bringing that up one more time.
Well, I'm not sure Chris is listening, but hi, Chris, if so. And then, you know, I think they've reformed really as a new company. So I'm not sure how that's changed. Apparently they still have their darknet intel tool, which was, you know, a big piece of intellectual property that they had created. Yeah, I've heard the tool is very good.
I've seen a demo at one time or another, but I haven't used it personally. But that's a big area for people that are interested in trying to find intelligence about your company. Well, anyway, interesting. It's nice to see that they're recovering or rebuilding. Hopefully we'll hear more from them going in the future here.
CyberGRX. I don't think we've talked about them on the show, have we? I think just slightly. We had a couple of job posts from them in the past couple of weeks, but besides that, not a whole lot. We do have a news story this week where it's really a press release.
Looking to go live with their product. So, you know, just to kind of summarize what they do, they are a third-party risk company, and they really looked to try and change the way we do third-party risk though. So instead of, you know, customers sending questionnaires to vendors and vendors having to fill those out, or the traditional, you know, a vendor does a SOC 2 or an ISO audit and hands those certifications or those audits to customers, CyberGRX is trying to be that platform in the middle where enterprises request an assessment of a vendor. So, you know, one of Ping's customers might send one to Ping and say, hey, we want— or tell CyberGRX, hey, we want a Ping assessment. And then CyberGRX reaches out to Ping to try and get them to do the assessment for free for Ping.
It really puts the cost back on the backs of the enterprises who are doing it. So, you know, those large enterprises know, someone who, you know, large healthcare provider who has thousands of vendors, um, can have this one platform where they make their requests to get that access. And as the platform grows, it scales, and, you know, that the vendor's assessment would be available to any enterprise that wants to use it for a reasonable cost, right? And, you know, one of the traditional problems with third-party assessments is that, you know, on either end you're getting hammered with requests all the time. Either you're making requests from a lot of people, or if you know, if you're a service provider, you're getting tons and tons of requests for these assessments.
So, you know, if there's a central platform like this, you can do the assessment once and then use it over and over again, you know, share the data so that you don't have to have, you know, a team of people dedicated to filling out questionnaires and providing the due diligence back to people. So we've been in talks with their CEO to get him on the show and do a feature interview with him, have him come talk more about it. But in the meantime, I've talked to a few folks over there to understand the platform. Uh, they're— they do 3 different levels of assessment. They have the kind of the Tier 3, or the lowest, um, scrutiny, which is kind of, kind of like filling out a, a SIG Lite, you know, going through 100 questions or whatever.
I think they said 85 questions, and, and given that level of info. Then there's the Tier 2, which is a whole lot more in-depth, getting, you know, more like 1,000 questions. And then their Tier 1, which is the on-site, um, they put it as, you know, significantly more robust than a SOC 2, giving a high level of assurance of the risk of that vendor. I think it's a really great idea, and I think it could be beneficial if it catches on. Yeah, the big question is, of course, can they get critical mass to drive vendors to want to say yes and to drive enterprises to be willing to sign up?
Exactly. Yeah. Anyway, interesting stuff. And that's— their headquarters is downtown Denver. They have a lot of good folks involved.
Blackstone is a big bankroll for them, and Optiv was involved really early on with the creation of the company. The, uh, the next story we have is around the Cyber Patriot competition. Yeah, so, uh, this reminds me a bit of the, the CCDC competitions that we've talked about in the past. Um, this is, I think, aimed at a slightly younger group of people. So, yeah, um, specifically in the, the high school division, the Highlands Ranch High School has a team that has made it to the national finals, which are happening, um, Monday, Tuesday, and Wednesday this week.
So the 3rd through the 5th. So it's great. This, this week that all kids from all these high schools around the country, the top— what is it about? Looks like about top 15 or so from each division. And there's 2 divisions get to meet in D.C. and, and compete with each other.
And like you said, Highlands Ranch made the list for, for the open division, which is kind of any, any school. And then also they have a public— what do they call it— an all-service division. Yeah. Which is, you know, mostly military schools. And Colorado Springs has a school going, which is with the Colorado Springs Cadet Squadron, nicknamed Wolfpack.
I was going to let you do that one. Yeah, that's all me anyway. So congratulations to the kids from Highlands Ranch High School, which is the Falcon Transfer Protocol, FTP. That's their nickname. Nice.
Very clever. And congratulations to the kids from the Colorado Springs Cadet Squadron making it out there. Would love to hear how it goes and look forward to reporting on that next week. Yeah, and I think that's really the biggest pieces of the news we have this week, but we did want to talk a little bit about some website enhancements that we've been doing. Really, when we went live with this project, we sort of subscribed to the minimum viable product philosophy, just getting something out there.
So you may have noticed that the website wasn't the prettiest. It didn't have everything that we wanted on it, but we're growing it slowly. So we've changed the look a little bit. We've added our Twitter feed to the front page. We've changed up the, the event page a little bit, so it's now a calendar view.
Uh, we're going to continue to, to do enhancements like that. But if there are any things that you'd like to see on the website, you know, obviously send us feedback, info@colorado-security.com, and we'll, we'll get on that. Yeah, we, we also have added a few more companies to the, the Colorado Security Companies page. I think we're up at like 25 or something now. There's, there's a lot of companies here in town.
We don't have all the info for all of them. Some of them don't, you know, are— don't have a lot on their websites yet, but we're trying to give you a centralized place, uh, to come find everything. And really, what's the vision for the website is, if you want to know what's going on in Colorado security in the next week or month, you go to our events page. It's all there. If you want to understand what are the key companies in town, you go to the, the companies page, and everything should be there.
You're trying to get involved with a professional association that you want to you want to start getting, you know, volunteering with or attending, go to our organizations page and you should see them all there. Really, we're trying to give you one central place to learn what's happening here in the Colorado security community. The hub for information security in Colorado. Absolutely. And finally, we don't have a whole lot of RMISC news this week, but we did want to announce that we've filled out the CISO panel that we'll be having Thursday, I think it's 11.
Yeah, about 11 o'clock. 11 o'clock. Yeah. So I'm going to be moderating the panel. This is our 3rd year doing the Colorado CISO panel at the conference.
Exactly. Always extremely interesting.
And the folks that will be attending the panel besides myself, Robb, of course, will be on the panel. We have Sarah Griffith from Euronet. John Everson from Dishy Swing. We've got Dale Drew from Level 3 and Nancy Thompson from Datavale. Nancy Phillips.
I always do that. Congratulations, Nancy. Yes, it's been several years since Nancy's been married, but I still have to say Nancy Thompson for some reason. Yeah. Anyway, so I'm looking forward to that and looking forward to your moderation on that as well.
All right, why don't we go ahead and jump into the events? This week there's a few events happening. On the 5th at SecureSet, they have an All About Bitcoin session. Honestly, that sounds pretty interesting to me. I'd like to be able to make it.
It's the evening of the 5th, which is what, Thursday? Wednesday? Yes. I wonder if they're going to be talking about, you know, cryptocurrency in general or, you know, the concepts behind it or if it's specifically Bitcoin. But yeah, it definitely sounds interesting.
Well, I would assume, you know, and I've got to learn quite a bit about distributed trust over the last year or so at Ping. I would assume that you have— they have to give some fundamental understanding of what a distributed ledger is, distributed ledger technology is, and then they'll be able to dive into how Bitcoin does it specifically and, and with how that technology works. Uh, next on the 6th, CTA has a diversity and inclusive leadership happy hour with a panel discussion. So that's at the Um, is that at the Vail Center or is that in with the Vail Center? I think it's with the Vail Center.
Uh, well, we'll have the, the info in the events page. You guys take a look. But that is, uh, Thursday night if you want to go mingle with some folks, maybe talk about diversity and inclusion. And then on third— on Saturday, we have the second of the Colorado Springs ISSA's Security+ training seminars. So if you made it you know, to the last Saturday on the 1st, definitely make sure you go on the 8th.
And I think if you didn't get to make it to the one on the 1st, you should look to June where they have another set of 2 of these trainings coming up. Yeah, I wonder, uh, if, if we know any specific people that are at those trainings, it'd be good to get feedback for, for people that might be interested for the June one. Yeah, you know what, I'll try and reach out and figure that out because I bet— I know we have a couple folks who went down there for it. A couple other events coming up that are not in the next week that were just added to the calendar that we thought we wanna call out specifically, 'cause they're interesting and different. Number one is that CTA has a growth series, and this next session is called The Quest for Colorado's Next $1 Billion Exit.
So really, how do you build a startup that scales and grows and gets to that $1 billion exit? It's been a little while since we've had one in Colorado. And that's on the 12th of April. And then on the 13th at SecureSet, Chris Peterson, who's the CTO for LogRhythm, is gonna be talking on threat lifecycle management. So that should be interesting as well.
Yeah, Chris is not just the CTO, he's also the founder of LogRhythm, one of the 2 founders. Really interesting guy. I'd say if you have an opportunity to go listen to him, highly recommend it. And a couple other, you know, big events coming up is the Women in Security ISSA group that's going to be meeting at SecureSet on April 19th. Got to tell you, it's, it's been amazing the turnout we've already got for registration.
It's over 90 people. I think it's like 95 last I looked. A lot of folks coming. So hopefully, you know, if, if you're a woman in security or you're wondering how you can better support women in security, this would be a good time for you to, to come and get involved. RMISC, once again, registration is still open.
We still have happy hour— excuse me, early bird until April 15th. So get signed up for that. And that, of course, again, is May 9th through 11th. Thank you. BSides right after that, the 12th and the 13th.
Of, of May. Um, registration for that is open. I'm not positive, I just said that, but I'm not sure that's true. Well, it'll be on the event page here as well. Um, all right, well, oh, there's a couple others we wanted to mention, right?
Yeah, 2 added in June. Yeah, not till June, but, um, every year ISC² has an event here in Denver. Uh, they sort of travel around the country, uh, providing some, some content. So their Secure Denver is on the 16th There is a small fee, I think it's around $100 for that, but it's related to, to cloud and moving to the cloud and doing that securely. And then the other one is on June 20th.
So Optiv, they do their Enterprise Security Solutions Summit. This is, you know, working with their partners, talking about potential solutions and technologies and all that sort of thing. So I just confirmed that BSides, apparently you don't even need to register this year. Oh, really? Um, yeah, it's— there's no pre-registration if you want a free badge.
Uh, you can't— they do have a donor drive, and if you donate some money, you're guaranteed a badge. And, uh, and you can just— you can show up whenever. But if you want to come in for free, you can come in for free. And just make sure you get there early in the day, otherwise it's probably going to fill up. Very nice.
All right, so that's, I think, it for events. We'll go into the jobs for this week. The focus of jobs this week, we have a few here in Denver and Boulder, but we really tried to look a little bit broader in Colorado, and we found some jobs in the Springs and some jobs up in Fort Collins and Greeley, trying to get a little bit more exposure for those of us who are not sitting right in the middle of the Denver metro area. So first on the list, LogRhythm. They have a data scientist for advanced analytics.
You know, they're, they're doing some really cool stuff around analytics and their product, so that, that could be an interesting position. Yeah, I, I— it's not a security-specific skill set, but it's going to be really contributing to the security offerings that they have at LogRhythm. So it looks like a lot of fun. Protegurity, which is a professional services company here in Denver, is hiring a solutions architect with a focus on enterprise data security. Western Union has a Senior Infosecurity Analyst.
Ball Corporation is hiring an Infosecurity Information Security Intern, and I believe that this is Ball Corp, not Ball Aerospace. Just just for clarity, we're going to move outside a little bit. So in Greeley, Flood and Peterson, they are hiring a Director of IT and Security Architecture. That sounds interesting. Pretty interesting role there up in Greeley.
I'm not sure, not sure how many of those there are up there, so it might be an interesting one for. Folks in the area. Fort Collins, at Bell Integrator, is hiring an IP networking and security team lead. Down in Colorado Springs, KForce Government Solutions, they're looking for a cybersecurity officer. And then also in the Springs, Booz Allen Hamilton has— they have a lot of jobs, maybe a couple dozen jobs in the Springs that they're hiring.
I focused on 4 here. If you look at the show notes, Uh, there's a, a junior level, a mid-level, a senior, and a manager level. So really the whole gamut of experience levels for security positions in the Springs with Booz Allen Hamilton. Yeah, and SecureSet, we've talked about them a number of times, and we also mentioned that they opened their new campus down in Colorado Springs, and so they're looking for a cybersecurity technical instructor to teach down there. Yeah, you know, I, I would assume that this is not a full-time role and Maybe Alex can send us a note.
Alex Kryline can send us a note if I'm wrong. But this is probably something that you could do in addition to your other job if you've been looking to get into instruction. This seems like a really cool opportunity. Yeah, definitely. And then finally, down in Colorado Springs, Route 9B, another company we've talked about, they're looking for a service delivery lead.
Yeah. And a good opportunity to get in with, you know, the number 1 on the Cybersecurity 500 list. Number 1. Well, that takes us to the end of the formal agenda here. I did want to mention, thanks so much to those who completed our listener survey.
Survey. We've got a lot of good data out of that, and I'll tell you what you guys said. Kind of the feedback we received was keep doing everything we're doing, don't stop doing the news or the events or the jobs, and keep doing the feature interviews and try and get some more. So we're going to try and pull in some more detail on the news in the area, some more detail on the events. That's going to probably make it run a little bit longer, so, you know, give feedback if you guys disagree, but that's what we've heard.
We also had asked the question of, do folks prefer to have the newscast and the feature interview combined into one episode, or should we separate those into 2? And the overwhelming feedback was to keep it as one. So that's how we're planning to go for now. But of course, again, if you have any other feedback, positive or negative, on the podcast, the website, anything else that we're doing, please send that to info@colorado-security.com. All right.
Well, with that, we'll call it a day. Everyone have a great week and we'll look forward to talking to you next week. Sounds good. Thanks, Robb. Right.
This is Carlin Dornbusch, CISO at Think Tank. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
All right. This is Robb Reck. I'm sitting with Scott Chasin. Scott, you know, thanks for having me in. We're in your headquarters here in downtown Denver.
Sitting in a nicely acoustic room, hopefully. So hopefully we don't get too much echo. So why don't you go ahead and introduce yourself for the listeners? Sure. I'm Scott Chasin, co-founder, CEO of ProtectWise.
ProtectWise is almost a 4-year-old security startup, if we can still say we're a startup, based in Denver. We've got 85 employees. We've raised $67 million in the last 3 years to bring a pretty disruptive platform to the market. I'm no stranger to security. This is my 4th venture in security.
So I go back to the early '90s. So let's kind of start off 4 years ago with ProtectWise here in Denver.
How did you come up with the idea for the company? Then let's talk about what that idea is. Sure, yeah.
I guess with— in my career, I should say, my DNA is all about how to deliver security as a service, how to deliver it as a utility.
My last venture, MX Logic, was quite successful in delivering email security. As a utility model. We were acquired by McAfee, and I became a CTO at McAfee for several years. That gave me an interesting perspective on just how fragmented the enterprise security architecture was.
After I left McAfee, I spent a lot of time thinking about that in terms of how can I take a utility model and start to really absorb all that point product fragmentation. I looked at that in conjunction with how the attack surface was forming and the environment that all of these threats were propagating. I looked at from a time perspective, time was kind of a missing element, meaning whether you're talking about visibility or you're talking about detection, time was something that was missing. You know, from a visibility perspective, log files and the output of all these point products were fairly myopic in terms of retention or the fidelity of the data. And I thought that we could do a better job with that.
On the detection side, you know, I thought that having security focused on real-time detection only was kind of a mistake. And again, if you add a time, temporal dimension to that, you get some really interesting lookback capabilities. So we looked at that and really I was, after I left McAfee, I spent a year trying to learn the game of golf, which didn't go that well.
Turned out that I started to feel like I was becoming irrelevant. Can I ask you one question about the MX Logic? Did you work with Sam Masiello? Yeah, of course. Yeah, so Sam's a good friend, right?
Yeah. Now currently the CISO down at TeleTech. Yep. Obviously gone very well. That's pretty cool.
It is a small world here, right? I love Sam. Yeah, I mean, Sam's a great guy and he's done amazing things in his career and When I hired Sam, he came in as a software engineer, and then we developed our SOC, and he ran our SOC, and look what he's done in his career. Good hire for sure. I'm really excited about what Sam has done and where he's going now.
Sorry about that. No, no, no, no. The little link all of a sudden. Listen, it's a small world, right? And in Denver, even smaller for security.
But growing. So to go back to the question, the concept really hit me— this might sound a little corny, but it actually, because I was grinding on it so much, it hit me in a dream. And I actually saw the product in my head and kind of built it in my head. And I woke up and the first person I called was my co-founder and CTO, Gene Stevens, who I worked with at MX Logic. And Gene is just an amazing, you know, data scale, um, you know, engineer.
And, um, I said, Gene, you know, I think I have something here. And he was at McAfee at the time. And, um, I said, I, I— what do you think of this? Do you think you can build it? He goes, I think I can build this.
And so, uh, the concept, uh, very simply, uh, was how do we build a memory for network. And that was a bold thought because it kind of— no one's ever thought of that before or expressed that before, a memory for a network. And, you know, from a security context, that does a couple of things. One, it does introduce a temporal, you know, element to how security is managed, both from a visibility perspective, right? And then also from a detection perspective.
And so That concept really became what is our platform today. So how does the idea of a memory for the network differ from a log repository? That's obviously what you'd be— Yeah, so it's the resolution of the data. So we look at it in terms of if you can record everything, not just when somebody opened a door or closed a door, which is what a log would introduce. But if you could record everything with the fidelity of full packet and you could store it for a really long period of time, that resolution is really, really powerful in a forensic response.
And so if you look at, you know, the— one of the biggest problems we have forensically is that these attacks develop over long periods of time, especially the targeted ones that are very sophisticated. And so having a retention window that could exceed or at least meet that of the breach detection window, we thought could be really, really powerful. And then the ability to search all of that data at scale, we thought could be really powerful. So, you know, part of the challenge that we saw with the existing enterprise security architecture was again this point product fragmentation where you had all these, you know, point products, maybe 50 to 100 depending on your organizational size, spitting out log files that were based off of the detection capability or the capability of those point products. And then you had the birth of the SIEM, which obviously tried to correlate all of that or glue it together so that you could have perhaps a detection engine that could feed off of those log files, or perhaps an ability to search all those log files.
We said, well, that's not enough. In a world where people say there's too much data in security, our theme is there's not enough. The reality is that the model for security within the enterprise has been this appliance-based, put it on-prem, and manage it through backhauls or centralization in your own data center. Well, that's, in our view, kind of broken. You need to have the resolution of not only full packet capture, but as much data as you can, and it needs to be searchable, and you need to have a presentation layer on top of that that can be expressed in a number of ways that creates a really efficient response.
Obviously enables proactive analysis. So we looked at all of this and we said, you know, if we can start with the network as our foundation and record everything, good and bad traffic, right? That could be, you know, our true north. You know, once we have a recording of the network on any network segment, you know, and the only way to really record that we thought would be to put it in the cloud, right? So the only way we could get a retention window that could meet or exceed that of the breach detection window was to put it in the cloud.
So we said, well, let's figure out a way to do packet capture on-premise, but compress and optimize what we see locally and stream it in near real time to this cloud platform. That way we could store it for a really long period of time. And then index it so it could be searched. But we said, aha, if those packets are coming into our cloud platform in near real time, well, why don't we run them through real-time security analytics, right? Like intrusion detection and malware detection, exfiltration detection, right?
Behavior anomaly detection. We could put machine classifiers on it. And so that's what we did. And so we built, the first thing we did was we built a very lightweight software sensor. Virtual appliance that is responsible for doing that local packet capture.
Because we knew the first problem we'd have to solve was how do we optimize, you know, all that bandwidth that we're seeing locally and compress it down so that we could stream it. And, you know, one of the first hires that we brought on from an engineering perspective was one of the contributors to the libpcap in the Linux environment. And he is still with us today. I won't name his name, but amazing architect as far as doing packet capture at scale. And we figured out a way over 2 years of stealth R&D to optimize what we see locally by up to 80% so that this kind of model could work over commodity internet.
And that's really kind of some of the secret sauce, the IP that allows this to happen. But we said, okay, well, once we get those packets to this cloud platform, what are we going to do with it? Well, let's start to provide real-time detection. And because we're storing them, let's then do something that no one's done before, which is let's go back in time, continuously. Let's leverage not only the elasticity of storage within the cloud, but the elasticity of processing power to continuously process what we have stored.
And so as new zero days come out, let's automatically go back in time and create a retrospection model to replay what was stored. So basically what you're saying is, January 1st, a bad thing happens. We had no signatures. We had no way to know that that was bad. And April 15th, You figure out this, you identify this bad thing, now you're going back through all year and you said, oh, look at that.
Yeah. 3, 4 months ago, something bad here happened. That's right. Yeah, it's a model that we actually borrowed from the International Olympic Committee. And so the IOC has been testing athletes.
They keep the urine, is that what you're telling me? Yeah, they do. So they've been testing athletes for the last decade plus for obviously performance-enhancing drugs, and when they get new signatures of masking agents they couldn't test for historically, they go back and they retest those samples. You've probably seen in the news some athletes have been disqualified from previous medals. That idea, we thought, was very valid in cybersecurity.
Again, cybersecurity is real-time today. Is this email good or bad? Is this file good or bad? Is this packet good or bad? Yet everything that has happened in security that's interesting from a threat perspective has already happened.
But yeah, I would almost already— I'd almost prefer to know about the one that happened a few months ago because they might have done a lot of stuff in the last few months, right? Well, again, going back to my previous statement, which is, you know, these attacks don't happen instantaneously. They develop over long periods of time. And the reality is, is that, you know, we don't We don't go back in time. We don't look back, but we should because we don't know, you know, today's innocuous connection, tomorrow based off of future intelligence could be malicious.
And that's something that we've seen time and time again, and it's something we thought if we created a memory for the network, we could solve that. We could create not only pervasive visibility, Um, you know, with this sensor that acts like a virtual camera that records everything, but also this different shade detection model. So there's a lot of threads here that I want to pull. Sure. Yeah.
So I'm trying to decide which one to pull first. I think, you know, the market— the market you've been going after here, the way— the way you position this, um, really sounds like a blue ocean strategy where we're trying to go into a space where people haven't really targeted previously. Yeah. You know, versus a red ocean where of course there's a feeding frenzy, lots of competitors.
But it also kind of seems like it gets into the area where Sim is playing. There's some other areas as well. As you created this company, obviously you're looking for an opportunity that you can grow and find a nice market for. How did you think about that question? Well, listen, I've been doing this a long time.
It's hard to introduce a new category and be successful if you can't displace something that's already there. I mean, especially in a marketplace like cybersecurity where you've got a gazillion vendors out there and a CISO is constantly being targeted by the vendor community with the same messaging. This was certainly part of our design process in the early days, which was we wanted a go-to-market and a model for our platform that was additive, meaning for a lean-in CISO or sophisticated organization that needed this kind of visibility, they could add it to their existing stack. But we also saw a big opportunity in displacing a legacy market. And so precisely, we developed our platform to go after kind of those legacy appliance network traffic recording solutions like RSA NetWitness and Celera, which are 15+ years old.
Um, very myopic. And, uh, you know, they, they, you know, aren't built on that modern stack, right? You've gotta, you gotta buy all that iron and you've got to manage it yourself, and it's— they're very hard to distribute. And so we said, well, that's a big market. I mean, that's a, that's a, a, a market that, you know, uh, it's $300+ million that, you know, we could disrupt with that traditional kind of cloud disruption opportunity.
And so we did that. And that's mostly enterprises in that market. That's large enterprise, right? And what we learned was fairly early, if I go back to some of the research that we did 3 years ago, was there was such a pent-up demand for visibility and that the visibility that those legacy solutions offered was not only myopic, but it was a luxury item. It was so expensive because you had to build all that big iron and the storage in the sands, right?
And so, you know, we said, well, this is, this is interesting. Now we can, we can build this as an additive solution, but we can also target it very specifically to this legacy opportunity of, you know, of a market that, that we can displace. And so we said, well, what else fits that criteria? And one of the things we did, which was geared towards our go-to-market, was we built an intrusion detection engine inside of our product. We said, IDS is kind of in that same vein.
IDS is another appliance. It refreshes every 2 to 3 years. It's not contributing a lot of value on-premise. What if we virtualize that and put it inside— Make it a feature of your product. Exactly right.
We did that, and that created another opportunity of displacement. I think it really highlights exactly what we're trying to do here, which is this is a platform play where a lot of that fragmented point product mess that the enterprise has embraced over the last 15 years in their security architecture, we see an opportunity to serve it up as a checkbox.
That's pretty much our go-to-market. From an enterprise perspective, that's what we're building. Do you guys also displace centralized log repositories, your Splunk or— You know what, we have. We have. It's not something that— we don't do log management today.
We don't have a vision for ingesting all the security ecosystem logs. Again, we have a different model. That's very different from SIEM. SIEM was, quite frankly, built because the enterprise needed to go on a console diet, right? So all those point products had their own dashboard, and there were too many dashboards.
And the idea was, well, let's just consolidate all the log files, and we'll create one dashboard, and we'll correlate the data, and we'll provide a detection capability quite possibly. On top of all of that. And so we, we looked at that and said, well, that model's broken because it's only as good as the point products that are feeding it. And so we looked at it and we said, you know what, let's again start with the memory of recording everything good and bad, and then we'll bind context to that network timeline. That's, you know, we like to say the network doesn't lie.
You know, all of your endpoints and assets communicate. That communication we capture within this memory, and we can grab context from key layers of IT infrastructure, you know, the firewall, the endpoint, the proxy, email, and bind that to this network timeline, which serves as our true north. And that is our platform, and that is a different model. It's very different from SIEM, but is a model that, you know, we think it does represent a new category because it's all it as a utility, but it's one that over time can actually lower the cost and complexity of a security architecture, which is something that not a lot of vendors are actually out there promoting today. Generally, when you get an opportunity— well, I guess a backup.
Are you focusing on SMB, enterprise? No, enterprise. Fortune 2000. Generally, does that come through an RFP process then? Depends.
We're obviously, we are a new category. We're a new way of delivering enterprise security as a utility. And so it's largely about awareness and building out the direct relationships with CISOs and practitioners in these organizations. Organizations. It's also about building a partner program and a channel ecosystem, which we're very channel-focused.
There are RFPs, and we're starting to see those more and more because some of those legacy technologies that I mentioned are— the refresh decision is upon a lot of CISOs, and what are they going to do from a forensics or from a visibility or even from a detection perspective. We are seeing those RFPs. But I would say it's kind of a healthy mix. We're getting pulled into opportunities and we're out there finding opportunities.
If it's an RFP, it's really one of those legacy products for the network recording. But if you make an opportunity, how do you position it? You're saying, hey, we need a new line item, or you're saying, hey, let's tear out these other 3 things that you might have? Either way, obviously this depends on the opportunity and the enterprise and what they're looking for. What we don't like to do is, from an RFP perspective, go into a checkbox war on features because we are different and we're not trying to be a next better version or cloud version of what we're trying to replace.
That's a message we're trying— because you We can't, you know, we are something entirely different. We're entirely different based off of the kind of visibility that we can deliver. We're entirely different based off of, you know, the detection model that we've created, based off of the presentation layer we've created, and based off how we deliver this as a service. And so, you know, all those things, you know, do represent this kind of new category. And so we're not trying to map one for one with the legacy that we're displacing.
So part of it is education too, but certainly we see, and we're seeing more and more, opportunities where they have an idea of what they want. They want deep visibility. They want that visibility to have a very long retention because they know that these attacks develop over long periods of time. They don't want it just to be sitting in the basement for the rainy day to give it to Mandiant after been breached. They actually want to use it in their workflow.
They want to use it in a detection sense that's both real-time and retrospective. We're seeing those things outlined in the wishlists. One of our biggest challenges is just unawareness. We're new. We've been on the market for a little over a year and selling the product.
We've got to get out there and make sure that this new way of delivering enterprise security is understood and it's known. And so that's kind of one of our challenges, is to solve awareness. So I'm gonna go back and pull a different thread now. Sure, yeah. You had the idea, you called Gene, I can build this.
And by the way, Gene is gonna be speaking at the Rocky Mountain Information Security Conference. Everyone come listen. Do you remember the talk? I don't know the talk. We'll get that.
I'm sure it's gonna be great because he's fantastic. Yeah, so excited to have Gene there. Um, uh, so anyway, you call him, you agree we're gonna build this. Talk about building the company, right? Let's talk about the company building aspect.
Yeah, you know, uh, so, so, so it was, you know, Gene and I, it's kind of that classic, um, you know, dot-com story, uh, of the day. 2 guys in a PowerPoint, you know, heading out to Silicon Valley. Um, however, we're a little different in Like I said, this was my 4th at-bat. So, you know, we wanted to raise a seed round that was large enough to get us through some R&D. And at this stage, we hadn't built anything.
I mean, literally, we just had kind of an architecture and a passion for what we wanted to do and a vision. And we went to Silicon Valley specifically and pitched about 6 VCs. And I would tell you, in about 4 weeks, 4 and a half weeks, we had a term sheet from 2 of them for $3 million. And that was a price round. It was a real round.
And that really started this 2-year R&D effort. Uh, and what year was that? That was 2013. Yeah, yeah, so that was April of 2013. And, you know, we, um, started to, to, uh, you know, build the business.
You know, our first kind of office was in Galvanize. Uh, it was basically we were just renting some desks there, and we pulled, uh, together some, some pretty amazing engineers very early on and attracted them with, with this vision. And, you know, continued to grow the team. And, you know, that phase is just a really special phase in any startup because, you know, once you get the funding and it's kind of like, okay, let's— how are we gonna build this thing? For me, that's a really exciting phase because you spend every moment, you know, that you're awake thinking about the construction and, you know, the promotion and, you know, even things like the logo, which, you know, for us, because we're so passionate about wanting to do something that would have a major impact in this market, um, meant a lot.
And we spent, you know, hours and hours and days and weeks on just like our logo as an example. So you can imagine what we spent on the platform itself. And the team that we were able to to bring together, I can honestly tell you, you know, the engineers, the early engineers, are the best engineers I've ever worked with. And we knew that we had some major, major, major hurdles that we had to overcome. And, you know, a lot of people that we talked to, um, you know, we, we talked to a lot of folks about what we wanted to do.
They all thought we were crazy. They were like, there's, there's no way, it's impossible. You can't record a network and stream it the cloud. Yeah, it just— the physics don't work. And, you know, we proved them wrong.
I mean, it took a little bit longer than I wanted it. You know, we thought we could actually build this platform and get it done in a year. It took 2 years. And it does seem like the physics shouldn't work. Like, that's right, it does.
I gotta— you know, I don't hold too much against them because, yeah, it doesn't seem like it'd be possible. Well, you know, and they've said that throughout time about a lot of endeavors, right? And we looked at this as something that for us was our moonshot. It was a real opportunity to prove a lot of people wrong and to fundamentally change how visibility and detection operates inside of a security architecture. Talk about— I'd like to hear about your first customer.
How'd you get a customer? First customer. Our first customer was Netflix. That's a common story, I think, isn't it? Yeah, I mean, that's a difficult customer to have as your first customer.
We got introduced to the guys at Netflix fairly early on in the design phase of our R&D effort, and we gave them a pitch. Similar to what I described to you as our idea. And they said, we absolutely love this. And obviously they're very cloud-friendly and very sophisticated. And they said, you know what, we want to watch you guys.
In fact, we want to do more than watch you guys. We want to early access test you guys. And that really started a relationship where they had a front row seat seat and to watching our development effort and to watching us kind of knock down some of these big hurdles around scale and how we're going to ingest all this data and how the sensor would work and, you know, our presentation layer and our APIs. And, you know, that, I think, visibility that we gave them in kind of just opening everything up very transparently to what we wanted to do got them really excited and got them to write a check and actually buy our solution. That was our first customer, and I can tell you that since then, we've continued to enjoy a great relationship with Netflix as one of their vendors.
They have a very sophisticated security architecture, and we're a big part of that. They speak highly of you guys, so that's pretty good.
Do you have any— I love— I always love to get the good and the bad, right? Some examples of projects you've done that have gone really well and you like to brag about, and maybe a project that didn't go so well and you've learned some lessons from. Yeah, I guess when you say project, you're talking about ventures, or you're talking about anything you've done here, really? Yeah, here at ProtectWise, or whatever. I'll let you open it You know, listen, I've been pretty lucky, I guess, in my career in being able to identify gaps in the market, convergence of technologies, and just having the luck and right market timing.
And so I've had some great successes. I mean, obviously you can't win them all. You know, I'll say that, you know, when we started with ProtectWise, we did have kind of this, this vision of a mid-market approach. We weren't quite sure that the enterprise was ready for our kind of product for a couple of reasons. One, the cloud.
There was still some bad religion to the cloud 3 years ago that largely has diminished.
We tried a mid-market approach. I think part of it was, we didn't succeed. Part of it was just kind of the timing of where we were at in our go-to-market and how we messaged the product and how we were positioning. Then also, the sophistication of a mid-market SMB is just, it's not there. It's largely a managed service approach.
I was going to actually ask that as a separate question, but I think it ties into what you just said. From what you're saying, it sounds like in order for a company to be a good fit for you guys, they probably have to have some basics in place and be a relatively mature organization. I think that's right. I think you'll find the market that we're going after, the Fortune 2000, largely fits that on a number of dimensions. However, I will say what we get high marks in, and which is just a natural benefit of our form factor, is ease of use.
And so, and that's also a key element to our vision and mission, which is to, you know, leverage that instant-on, low-friction deployment capability that our platform provides with an opportunity to leverage a very sophisticated yet easily digestible user experience to speak to the less sophisticated analyst or security team. And so we do a lot of the heavy lifting, removing a lot of the manual work, so to speak. And so, yeah, I mean, I think that those are key elements that apply to a varying degree of sophistication in the Fortune 2000. You've alluded a little bit to the presentation layer in there about how it's displayed. I'll just come out and say you guys are well known for having a beautiful user interface, and that being not the key differentiator, but certainly a big draw.
If a security leader wants to give their SOC something that they're going to want to use, this is a good example of that, right? Yeah, it means a lot to us, and I, you know, for us, it's— we saw an opportunity to evolve the presentation layer of security mainly because it's just been an afterthought for so long. You know, the dashboards that you get off of a SIEM, we thought were a joke. The status quo of most security products is either Bootstrap or something that smells like Bootstrap, you know, from a UI perspective. I think the intention is, hey, we need to make the user experience nice for our users, but security, we can just suck it up and we'll just get the data.
Give them— give me the data. Yeah, you guys have really— no, we think the data is beautiful, but we also think that, you know, the presentation layer can be beautiful, but not just beauty. We didn't want to— we didn't want to be a a bombshell. And that's what's interesting. When most people find out about ProtectWise and they see our UI, part of our challenge really is showing them the inside of what we do, because we've built our platform like a carrier would build a petabit stream-based processing engine for all this massively scaled data ingestion and indexing and all the value that comes out of that.
And that's, you know, so we have this amazing UI and presentation layer, which is designed to ultimately extend the human resource pool, right? So part of our vision is we fundamentally want to change how humans interact with security. And, you know, when you look at, you know, the evolution of the presentation layer, you know, it really started with log files, which is still kind of the status quo today. Then we hit the dashboard, which, you know, Every SIEM has pie charts and line bar graphs. And now we're kind of at the era of search, right?
And the ability to search all that data, those log files. Well, we said, well, there's got to be another rung in the evolution. Let's think about one, creating something that's beautiful and functional, that's not Bootstrap, that provides great efficiencies for searching and for forensic exploration of all this data, uh, and 2, let's come up with a vision that ultimately could immerse, you know, a new audience, a new analyst, um, into all of this data so they can actually look at the data from a different perspective. And that's really our vision. And, and when it comes down to what is ProtectWise, you know, long-term play and vision here, it's twofold.
It's we believe in the platform, platform and the ingestion and processing of all this data as a utility model and being able to absorb all that point product fragmentation like security analytics and intrusion detection. But also on the other side, it's the presentation layer and being able to extend the human resource pool to the next generation of analysts and security practitioners. It does seem like you're your presentation layer makes your platform an attractive place to move other things that you're not currently doing. And we'll leave it at that for now. I want to take a little bit of a turn here though and really talk more about you.
We've talked a lot about ProtectWise. You know, how did you get to Colorado? How did you get into security? Why don't you tell the story? Yeah, so I've been in security, uh, for a long time.
Like I said, I go back to the '90s. So my first, um, the first thing I did in security was I created a mailing list. It was called BugTrack. And it was something that grew pretty quickly. It was a concept around being able to identify vulnerabilities in software on the internet.
Obviously, we've heard the term zero-day. Well, BugTrack was the alerting service for zero-days. And it grew pretty quickly to about 30,000 security practitioners, which back in 1990 was all of them around the world.
That was an interesting experience. I was doing some consulting work as well in doing that in Texas, in Houston, and I actually got a call for from a long-distance company in Colorado Springs that was being hacked at the time. And they wanted me to come out and consult and clean up. And so I did, and that introduced me to Colorado. And I actually met John Street, who was the CEO of that long-distance company.
It was called Telephone Express. And John and I collaborated, and, you know, he convinced me to move to Colorado. And together we worked on a number of projects for about 15 years. So BugTrack morphed into Security Focus after I moved to Colorado, and then that was acquired by Symantec. And then in 1994, I co-founded USA.NET with John Street in Colorado Springs.
And that was another dream, that was another crazy idea. I had this idea of Uh, well, it's called web-based email. You've probably used it. Um, yeah, so I, I had this idea of taking a, a POP email server and building an interface for it with the Mosaic web browser, uh, which— what year are we talking about right now? '94.
Okay, that's early. Uh, which at the time hadn't been done before. Um, the end of '94. And so in, in, in '95, uh, you know, we started actively building it. And John funded it.
And, you know, that was an interesting opportunity because that was the dot-com era. And, you know, we were— interesting story there. We were a year— we launched our product a year before Hotmail came out. And we had a different business model. Our business model was we were charging $36 a year for this lifetime email address and access to this web-based email.
And obviously when Hotmail launched in July of '96, their model was offering the same product but for free. And that was the birth of the advertising internet and, you know, eyeballs. And I remember it was— there was a small trade show in San Francisco. It wasn't even an internet trade show, it was just a business expo. And we were there and we had, you know, um, you know, a 30 by 30 booth with sales guys and giveaways and all kinds of things.
And, um, you know, we're selling this $36 a year lifetime email address, web-based email product. And across the way there were 2 guys at a cardboard table, you know, uh, card table rather, uh, with 2 PCs, and they had lines of people lined up. And they would sign up and get their email. Yeah, it was Sabir Bhatia and jack racks, and it was their first day of launching Hotmail. I went over there and I looked, and it was the exact same product, you know, left-hand navigation frame, right-hand body with all your emails.
It took us about a year, but we retooled our product and offered it for free. We became the 3rd largest email infrastructure on the planet behind Hotmail and Rocketmail. The story there is Hotmail was acquired by Microsoft, Rocketmail became Yahoo, was acquired by Yahoo. And, you know, we, we raised over $100 million in venture, filed our S-1 to go public at the end of '99, which was not great timing, and the crash happened. And, and we ended up doing a private placement with JP Morgan and took about $60 million from them.
And the business kind of grew into hosting just an exchange from then on out. We also had a very large relationship with Netscape. They were an investor in the company, and we had about $30+ million on our platform, and that was all here in Colorado.
That company sold to ePerimeter Security, which is now BAE Systems, and yeah, that was a 7-year venture. I learned a lot, and that was, you know, that exposure to email is what, you know, led me to to start MXLogic in 2002. So why don't you tell the story of, you know, what was the idea for MXLogic? Yeah, so, well, you know, the idea there was quite simple. We were spending at USA.NET about $1 million a month on EMC storage gear because what I was able to see from '95 to '99, really to 2001, was the pollution of the SMTP channel of email.
And it was all spam, and the spam wave was coming really quickly. And I didn't see a clean way to kind of filter out all of that. And so we said, well, if we could harness the power of DNS, we can basically redirect a domain's MX record, their mail exchange record, to a service model, a proxy model that we create. And we could do all of the filtering and manage all of the filters for them. And so, they could very easily make a very simple change to their domain name, have the email come to us, we would filter out all the bad stuff and then forward all the good stuff to them.
And they wouldn't have to have any infrastructure on-premise. And so, that was the premise, was all about delivering email security as a utility model. Back then, we called it a managed service. That was before the cloud became the cloud, and that was another 7-year venture, and we did focus on the mid-market with that venture, and we grew it to about 45,000 business customers, and we were acquired by McAfee. I assume competing directly with Postini?
Postini and MessageLabs, that's right. We went after mid-market. Postini and MessageLabs both did large enterprise.
We kind of started by going mid-market, and then we started going up. They started enterprise and started coming down. The story there is market consolidation happened and MessageLabs was bought by Symantec and Postini by Google and MXLogic by McAfee. So why Colorado? Obviously you moved here, you said, when you had the opportunity down in the Springs.
Did you move to the Springs? Did you move to Denver? Moved to the Springs, started USA.NET in the Springs, then moved that to Denver in '99, at the end of '99. You know, why Colorado? It's a great place to live.
You know, there's been challenges in doing startups here. You know, the reality is that, you know, in the Bay, you know, you've got access to a ton of talent and a ton of venture capital. Here, not so much. It's changing. It's changing.
You know, 15 years ago, you know, I wouldn't think that, you know, here we are at ProtectWise, you know, we've raised $67 million in capital, all of it from outside of Colorado. You know, that just wasn't the case. You know, it was hard to pull in, you know, Silicon Valley, you know, VC into the state back then. A lot of that's changed, but, you know, Colorado is, the quality of life obviously And, you know, the— I think that the opportunity to seed something here initially, you want to kind of leverage that into the next deal. And, you know, when you start to— when you have success in building a team, it was just really a family.
I mean, you spend, you know, and again, we've done it multiple times now, you kind of want to take that energy and that community and leverage it into the next one if you can. So we did a lot of that along the way with MX Logic and ProtectWise here, and so that's why, I mean, we have roots here. Right. So interesting comments about the talent pool. What kind of talent are you looking for when you say to start up a new company here?
What is it you need? Well, the first thing you need is engineering engineers, right? And the amazing thing about Denver these days is you have really experienced engineers, software engineers.
They've either migrated from the Bay Area or the East Coast or places like Austin, second-tier markets, and they've moved here. Because they're a little bit more mature. They have families. Colorado is a great place to raise kids, right? The quality of life.
And so you have access to that. And so the first thing, you know, I do obviously is, you know, I look for what's the core engineering team. You know, you gotta have a team of 6 guys or gals that, you know, that not only get the vision but are willing to commit, you know, the next 5 years of their life to building it. And that's your core team. And it obviously grows over time, but the first thing you look for is engineering.
And that's the first phase, is you have your concept, you build out your prototype, and then you gotta whiteboard it all out and figure out what's the production version of that. And so that's the first thing I look for, engineers. We're at about 45 minutes right here, so I wanna be respectful of your time. Final thoughts for those listening, those who are working on either running a security program or looking for— let's start there. Folks who are running a security program, what kind of advice?
Obviously you've been around for a while doing security. You've seen what we do well, what we don't do well as a general industry. What's your advice for security leaders?
Advice for security leaders. Don't listen to the noise. There is so much noise. It's really— and that's actually, going back to ProtectWise a little bit, we've focused our marketing to be very different. We don't want to be a part of that noise.
We believe in our product so much that our sales presentations don't have any slides. It's just we're going to show you the product, right? Because that's essentially what you're buying from us is, is our platform. So don't, don't fall into the noise. And I know a lot of them are, um, are inundated with the noise.
And, and I think that leads to the next thing, which is don't be discouraged, you know, because there are teams out there like what we have here at ProtectWise that believe in a way forward, that are passionate about that. I mean, that aren't, you know, here to flip the company to Symantec or to the next big— we actually believe that— I'm not saying that can never happen, but we believe in this. I mean, we believe that there's a huge opportunity to disrupt. In fact, we talked about, at one point, we wanted to have a sign in here that said, this is not a job, this is the future. And I would say that that goes the same for for any security leader, you've got to believe that there's a way forward here.
It's not all vendor craziness and marketing hollowness. There's real tech that's being developed that solves real problems that you've got to learn to listen for and to look for. It's hard because there's so much noise. There's so much noise, but there is signal in there. I would just say lean forward a little bit and don't get discouraged.
My last question for you, for those who are looking to get involved in security, start a career there, do you have any advice for what's the right thing to go learn? What's the right thing to get started with? That's an interesting one because I'm on the side of wanting to change the skill set. Um, you know, I, I don't— you know, somebody might say a common answer would be, oh, go learn Python, or, you know, understand, you know, the shell, um, you know, play around with your terminal window on your Mac. You know, you know, for me, it's, you know, um, I, I guess my advice would be, um, there's so much to learn on the internet.
Um, you know, understand the base layer of skills that are needed. I think to be an amazing security engineer with today's toolsets, you do have to know Python, you have to know Unix, Linux, I'm sorry. You have to know networking and you have to be passionate about it, right? I mean, you got to have passion for it. It's not something that, you know, you got to have a curiosity, a desire to explore, right?
And so, you know, that's an interesting thing is the network and all the assets that we're trying to protect and the information that's on it, whether it's, you know, on the network or in the cloud or whatever. I mean, it's fascinating, you know, because of the dimensions of scale of all of this to be able to try to create a security fabric around that. Um, is an amazing challenge, but it's also an amazing thing to explore and to think about. And so if you have that and you have that desire to, to want to explore and, and, and be a puzzle solver and, and figure out how to put things together and, and, and, you know, look for, you know, I just say, you know, start with, you know, the open source community. Start with, um, understanding the, the industry in all the different layers, right?
Because at some point you gotta, you gotta figure out what you want to do in security. It's not just, you know, I want to get into cyber. It's like, what do you want to do? Do you want to be an analyst? Do you want to, you know, sell security?
Do you want to market security? Do you, do you want to be an architect? Do you want to, you know, work for, you know, a vendor or ProtectWise, right? I mean, do you want to write code? I mean, what do you want to do?
So I'd say figure that out and then, you know, go from there. But I think passion— you got to have passion. You got to dive in and make sure you have it and you can find it. That sounds right. And there is a huge menu of options for careers there, but yeah, the curiosity and the technical aptitude to do whatever it is is gonna be there.
Well, I want to just say thanks for, you know, setting aside your time to do this and letting the community in the area know more about you guys. We're gonna keep an eye on you as you guys grow. Please. We'll keep on— we'll keep talking about what you're doing. If you have any especially interesting job postings, send me a note.
We will. In the podcast. And hopefully we'll talk to you again maybe, maybe a year from now. We'll revisit with you. Absolutely.
Thanks, Robb. All right, Scott. Thanks.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.