Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to the May 1st edition of the Colorado Equals Security Podcast. We're doing the newscast here, and this is Robb Reck with Alex. How you doing, Alex?
Hey, Robb, how's it going? Doing all right. What, can you believe we're in May? Uh, it doesn't look like May outside, that's for sure. We, we got— we definitely got a late storm this year and kind of reminded us, don't turn your sprinklers on until May, right?
I had mine on and then I had to drain, drain them. And yeah, lots of fun stuff. But I think we probably got, I don't know, close to a foot of snow at my house. Yeah, we, we had around the same amount. It just didn't stick to the cement very much, so it didn't have to do any shoveling.
Exactly. It's not very often that you get a foot of snow and don't have to shovel. Yeah. I like that. You know, I guess we're officially a third of the way through the year.
It's kind of hard to believe. It is hard to believe. It's also, you know, Cinco de Mayo this week. Fun stuff. Which is also my son and my wife's half birthday.
Oh, nice. Fun stuff. So have you accomplished a third of the things you wanted to get done in 2017? Oh, of course. Most definitely.
You? Well, you know, I hadn't really given it a lot of thought, but I think things are going fairly well. We're, what, 13 episodes into the podcast now? And that's pretty good. Work's going pretty well.
We're on track. So I think 2017's been pretty good so far. Hopefully the second half of the year slows down a little bit, though. It's going too fast. Yep, for sure.
All right, let's dive into the news for this week. Top article this week, Denver is the number 1 best place to live. Yeah, and this is, you know, a lot of times we get these lists and it's from a, I'll say, a less than reputable place, so something you've never heard of before. But this is from U.S. News and World Report, so that's, you know, a fairly big name. Yeah, it was a good article, pretty short, but Denver number 1, which is cool.
Also Colorado Springs was number 5. Yeah, so Colorado, and obviously a destination place to go, and Lots of jobs, lots of quality of living is great here. Number 2 on the list was Austin once again. So we see Austin on just about every list here with Denver. It's kind of interesting.
Yeah. Number 3 was Fayetteville, Arkansas. So that was maybe not expected. Not expected. Yeah.
I have a friend that lives down in Arkansas and he said it's nicer than you would think. Yeah. All right. So number 2 story we want to talk about this week is Oracle. Oracle is opening up a startup and innovation center here in Denver.
Yeah, so, um, obviously Oracle, very big company. Um, I've been at very large companies before, slow and methodical, hard to, to get innovation done, not necessarily new ideas coming forth. So I think they're trying to, to get some, um, some startup mentality as part of the company in little pockets. Yeah, so a few different focuses, right? They mentioned they're going to work on virtual reality, artificial intelligence, Internet of Things, and cybersecurity as focuses for this internal startup.
Yeah, and it's really cool to see that, that cybersecurity is one of those areas. Yeah, so hopefully, you know, maybe this gives someone a chance who wants to do startup entrepreneurial type work but maybe doesn't want to do it in as high a risk environment as going and starting their own company. So interesting stuff. Hopefully we'll have some jobs coming up soon we can talk about on this. Yeah, that would be pretty cool.
So, uh, 3rd on the list, um, my favorite burrito restaurant, Chipotle, uh, suffered a payment card breach. Not a whole lot of details around what exactly happened, but it looked like it was through late March and April that they had some credit card numbers stolen. You know, 4 years ago, this would've been massive news, right? Having a payment card breach for a national retailer. But now we're pretty expect— we come to expect it.
And I don't think that a lot of questions pop up out of this. I guess the big news here is, Chipotle has just a terrible year, right? And this kind of piles on to their, their very bad year. A whole lot of bad luck and bad decisions from them. Still good burritos, though.
But yeah, I mean, we'll have to see if more details come out about, you know, number of cards and things like that. I haven't seen any of that information yet. But anyway, Chipotle is a, is a Colorado company, so definitely relevant to the news here in the industry and in Colorado. And speaking of Colorado companies who maybe had not the best week, Webroot had a had a little bit of a misfire this week. Their antivirus started identifying some critical Windows system files as being malicious.
Yeah, you know, you don't hear about that a lot anymore, but I think pretty much every major antivirus company has had this happen to them at one point. Um, you know, all the big players— Symantec, McAfee, all those, those sorts of things— all of a sudden you hear, oh yeah, hey, we— none of our computers work because the antivirus, you know, took out LSASS or something like that. Yeah, it's a fairly common thing. It's certainly embarrassing when it happens though. And, you know, this one generated a huge amount of media and coverage.
For what looks like, from what I've heard, it took about 15 minutes for them to fix it. Something like that. That's what I saw, somewhere around that. But I mean, even with that short amount of time, with the speed that clients check in these days, and especially You know, Webroot being, I think, more a cloud-based, you know, antivirus, they do a lot of that processing that way. I think it's even more, even more critical for them.
Yeah. Anyway, I guess the good news is they responded quickly. They, they put out a press release kind of addressing what happened and being pretty transparent about it. So hopefully, you know, minimal damage for Webroot. Yeah, I haven't seen how easy it was to recover from this.
But you know, like on the client side, but hopefully everyone is back up and working. Um, so next, another local security company, LogRhythm, was, uh, named in as a leader in this year's Forrester Wave for security intelligence. Yeah. And so for the security analytics platform— oh, security analytics. Yes, very important.
So, uh, for those not familiar, Forrester is one of the big analyst companies along with Gartner. Know, Gartner does their Magic Quadrant, um, to show who leaders are, and Forrester does the Wave. So similar but slightly different format. Um, so I think LogRhythm was up there in leaders with, um, IBM, RSA, and Splunk. Yep.
So good for them. Yeah, congratulations to LogRhythm on that. That's a great recognition. Yep, great product. Uh, ProtectWise, another— the other, uh, security analytics company here and security operations company in Denver.
They've announced a bring your own intelligence feature for their platform. Yeah, so I think more and more getting good security intelligence into platforms like this, you know, whether it's just simply, you know, blacklist, whitelist kind of things, or, you know, more detailed intelligence features is important. And many of these things come with out-of-the-box intelligence feeds and, you know, other standards that they use. But, you know, they've announced now that they'll accept— I don't want to say any, but, um, you know, other intelligence feeds that you can add into their product. And I wonder if that's just external or if you can do internal feeds as well to, uh, to start to get enriched from what's happening in your environment.
Yeah, that's a good question. Interesting stuff. Uh, you know, obviously what this really allows them to do is have a broader Um, range of what they can support and give you insight into. So, so good for ProjectWise there. Yeah, good stuff.
And then, uh, next we had an announcement from SecureSet. This isn't actually a press release or anything like that, but, um, you know, we've talked about SecureSet a lot. You know, they have sort of 2 pieces, one being the education piece and one being the accelerator piece. And so they are now accepting applications for their accelerator. So if you're a startup in the cybersecurity area and you want to be part of their accelerator, you should go ahead and apply to that.
Yeah. And, you know, they are headquartered here in Denver and there is a requirement for some portion of onsite, you know, living here in Denver. But they are talking to companies from all around the country, bringing people in for, you know, just for the few weeks that they have to be here. And then folks can do remote for, for some of the rest of it. Well, and I think with our, you know, gigantic global audience on this podcast, we should be able to attract lots of startups to SecureSet.
So anyway, if you guys are interested in getting some, some resources to help with your startup, I think that's a pretty good place to look. Uh, so yeah, I also wanted to give a recap on the Women in Security event that happened about 2 weeks ago. And I was out last week with, with the flu. Um, but, but when we had the Women in Security event, really went well. It was actually at the SecureSet, um, office there in RiNo, River North area in Denver.
And it was, it was just a really neat event. Thanks a lot to Sarah Avery and the rest of the, the group there. Who helped put this event on. There was over 100 women there just really getting to know each other, networking, socializing. It was a little bit strange to be, you know, the guy in the room there as, you know, as a representation for ISSA.
I tried to get out of there as soon as I could after kicking the event off, but really you could feel the powerful energy in the room and the people who really were— who needed an event like this. And hopefully, you know, this is the start of a real movement versus just a one-time event. Yeah, and I've spoken to a few women that were there, and I've gotten really good feedback from them. They really enjoyed the event. So I think it's great that this got kicked off.
Obviously, it was very large in terms of the amount of people that were there. And also, I think we had what, 125 people register? Yeah, that's where we cut it off. And there were nearly that many that attended. So that's always a great sign too.
And so the next event is, is tentatively scheduled for June 29th. It's not up on the website yet, but I think that— I think it's pretty much a go, June 29th. So if you want to mark it on your calendar, uh, we'll of course— we'll be letting you guys know as we get closer when it's available for registration. But looking forward to that. Uh, speaking of events, this week there are 2 events here happening in town.
SecureSet has an event on the 2nd, which is Tuesday evening, with around application security, kind of an introduction to AppSec. And then on May the 4th, of course, Star Wars references on May the 4th. May the 4th be with you. This is Colorado Technology Professionals, The Future of Technology: Dark Side versus Light Side. So it looks sort of like a panel discussion with some folks on the light side and dark side of security.
Our friend Chris Roberts is going to be on there, and Chris is one of the interviews that we have coming up I think next week, maybe he's the feature interview on the podcast. So try and make it out this week and come listen to us next week if you want to get to know more about Chris's background. Of course, those are the only 2 events this week. But the week following, it is the culmination of the, the announcements that we've had every week since the start of the podcast. So May 9th through 11th is the Rocky Mountain Information Security Conference.
It's too late to get signed up. Um, there's great numbers registration. We, we expect we're going to beat, you know, top 1,000 people there in attendance this year. And then there's a lot of stuff going on around the conference. You know, we've mentioned BSides every, every week as well, and BSides happens the 12th and 13th.
But there's, there's all kinds of events happening in the evenings, Tuesday night, Wednesday night, Thursday night around the conference as vendors are all coming into town. A lot of good stuff to get to do. I've seen several happy hours or, or other sort of events like that. So if you're Is there whiskey tasting? Yeah.
If you're, if you're the, you know, one or two people that aren't coming to RMISC, you can still come downtown in the evening and go to a happy hour or something else that's being put on. Yeah. So definitely looking forward to that. You know, make sure you're there Tuesday night at RMISC for Jeremiah Grossman's kickoff. Jeremiah, one of the, you know, one of the real founders and, you know, initiators of the AppSec movement out there, is going to talk to us about, you know, where security is now and where we need to be going.
And then that's, that's just going to lead us off into a great conference. So hopefully you guys will be there, uh, week after this. It's going to be great. You have to be there. Uh, so that's it for the upcoming events.
Uh, let's move on to jobs. So first on the list, uh, Spectrum. They're looking for a senior manager of network security ops. And so Spectrum is, um, I believe the, the new name for, for Charter, for one of the, the pieces of Charter. Yeah, I know they're associated.
I didn't know it was, it was maybe a rebranded portion, whatever. But yeah, telecommunication, right? Yep. And then Vail Resorts is hiring an enterprise program manager. This reports to Ian Buxton, who's the senior director of risk and security there.
And from conversations with Ian, it looks like this is, is like a program, almost product manager, like really a change agent working with the business to understand what their needs are and help them work with security and get security integrated. That sounds like fun. So next, uh, Deloitte is hiring a CASB manager. Cloud access security broker. Exactly.
So, um, if CASB obviously is one of the sort of emerging technologies around cloud and security, so if you're interested in that and want to be more, more involved in cloud security, this sounds like it could be a good opportunity. I assume, you know, focusing on Netscope, SkyHigh, you know, our own local managed methods company here that that all do. There's a lot of CASB out there, but those are probably the big, the big ones worth talking about right now. The City and County of Denver is hiring an identity management associate. I assume that this is working for Steve Corey.
I don't know that. Yeah, I believe so. In that, that general area, the— I put this one on here this week because, you know, last week and this week we're seeing lots and lots of jobs around identity. So definitely a good space to be in. Or move towards.
Thank you. Yeah. So Proofpoint, they're an email security company that, you know, works with, you know, basically filtering inbound and outbound messages for spam and then for DLP on the way out. They're looking to hire a senior major accounts manager. Yeah.
And Proofpoint, they're actually— they're not located here, but I thought that was interesting that they're hiring that type of position for Denver. I think they're a California-based company. Yeah. Next, Xcel Energy, senior security analyst. So if you want to get into the utility industry, definitely would be fun.
We've had a couple of jobs from them in the past. DU, University of Denver, is hiring an adjunct faculty cybersecurity. Kind of an interesting idea, right? If you're interested in getting out there and starting a professor career, this is a good opportunity. If I wasn't so busy, I'd probably look at doing this myself.
Yeah. And that's— it's in the School of Engineering and Computer Science. So this looks like an undergrad position, whereas I've seen adjunct positions for them before where it's in the graduate programs, you know, for the working adult kind of programs. DCP Midstream, oil and gas company here in town, they're looking for an IT Security Analyst 5. Well, that's pretty good.
Yes. So that must be an awesome job. Are you sure it's not just a V? Well, it could be. IT security analyst V. Yeah, I don't know.
Anyway, so interesting stuff. Do you know DCP Midstream? You know, I don't know if I know folks over there or not anymore. Anyway, oil and gas, obviously one of the staple industries here in Denver and lots of opportunities once you get in that industry to move around. Exactly.
And then last on the list, Cisco, you may have heard of them. They are hiring a team lead for incident response. And they actually had a couple positions open. I think that they had a lower-level incident response position open, but seems like they're beefing up their incident response team and they're trying to do it here in Denver. So do they have an office in town?
Do you know? They do. They have an office in the Tech Center. Really? I think it's off Dry Creek on the east side of 25.
Oh, all right. Yeah, somewhere over there. Anyway, well, that's the end of the, the job postings for this week. Um, any other news you wanted to go into? Uh, I don't think anything for me.
You know, once again, we're one week away from Rocky Mountain Information Security Conference, so if you haven't registered, you better. Sounds good. All right, well, stick around. We're gonna have the feature interview with Cody Cornell. Cody is the, the founder and CEO of Swimlane, a local security company here in Denver that does security automation for response to alerts and all kinds of good stuff.
Sit around and learn about him. Uh, really interesting background. He did not come from your, your typical entrepreneur background. He's a security operations center guy, right? He sat in a SOC and did security operations and said, hey, I can think of a better way to do this and made a company to do it.
So stick around and learn about that. Very interesting stuff. Definitely really cool. All right, you guys have a good one. We'll talk to you next week.
This is Mike Benjamin, a big fan of Colorado Security. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
All right, this is Robb Reck, and I have the fortune today of being in the Swimlane headquarters up in Louisville, Colorado, and I have the luck to get to sit down with their founder, Cody. Cody, why don't you just go introduce yourself and just tell us a little bit about who you are personally? Yeah, Cody Cornell. I'm the co-founder and CEO at Swimlane. I myself have been in the security space for, you know, 10 going on 15 years, I guess.
Lots of different capacities, but mostly around security operations. Sure. I've had the good fortune of, you know, working in the federal space as well as the commercial space, mostly enterprise, and, you know, helping build and deploy SOCs, the technology that goes with, you know, helping manage and, you know, protect organizations basically, you know, be it SIM or endpoint or whatever it might be. And, you know, started a consulting company in 2010, and that ended up evolving into what is now Swimlane. Yeah.
So, so earlier, uh, before we got going here recording, you mentioned that you were in the Coast Guard. Let's go ahead and back up, right? So talk— let's talk about how you, you know, you went from being in the Coast Guard. You mentioned you were in, um, you were in Seattle and Petaluma, and I think you said Baltimore. Yeah, that's correct.
Yep. Um, and so what happened after that? Yeah, so I mean, I grew up in rural Montana, eastern Montana, with a huge desire to see the coast and live in the city. So the military was a very fast track to see the coast. So I joined the Coast Guard, you know, obviously went through boot camp, but I was stationed in actually an icebreaker in Seattle, went through ACE school down in Petaluma outside of San Francisco.
An icebreaker, does that mean you're in a boat that went through like sheets of ice on the water and like Tell me about— I don't know much about this. Yeah, so, uh, there, there's, you know, the Coast Guard only has, was it 3 Polar-class icebreakers? I think only 2 of them are still left in operation. But, uh, yeah, the Polar Star. We— so we went from Seattle all the way down past Australia to Antarctica into McMurdo Station there, breaking through, you know, 20-plus feet of ice.
Um, I was just an engineer, so I mean, literally just worked in the engine room. So, uh, not a very glamorous role, but, uh, it was exciting. It was— so are you breaking ice just because there's ice there? Is this why we climb— same reason we climb Everest, or is it let boats come in behind you. Exactly.
So, um, you know, Coast Guard breaks a channel in for, uh, like the fueling as well as, uh, resupply. So is this for like the Antarctica project? Yep. Yeah. So McMurdo Station is a big— I believe it's a National Science Foundation base.
There's people there. I believe you're around. Yeah. Uh, but they go in in the summer, uh, most years and, you know, basically break that channel in so they can bring— and they do science on the way, but they, they break that channel in to do resupply. That's great.
Okay. Yeah. So yeah, I just got to learn something super interesting right there. Yeah. So yeah, it was, it was good for me, right?
I got to see— I expected to go around the world kind kind of, you know, as the equator is the belt, ended up going around the world, kind of pole to pole, ended up actually going north of Alaska as well. So, but yeah, and then after that went to A-school for electronics, got stationed out in Baltimore. That's really kind of where my, my IT career kind of kicked off, you know, taking classes at the community college at night, uh, doing Linux and Solaris administration while I was in the Coast Guard. That was kind of the, you know, uh, the beginning of what was— ends up being my, my IT career. Okay, so you— how do you got— after you got out of the service, what was, uh, what was next for you?
Sounds like IT. Yeah, so actually while I was even in the service, I had a part-time job, uh, you know, working in the, the DC metro area, uh, working for one of the defense contractors, you know, doing, you know, started out doing help desk work, uh, ended up doing Unix administration, uh, you know, big storage and imaging systems and things like that, uh, so sharing imagery between different agencies and things like that. And then, uh, I got into security kind of right away after that, so system hardening and then become part of what was the big, you know, kind of DoD programs for vulnerability management, vulnerability remediation, and host-based intrusion prevention, more commonly known as SCCVI, SCRI, and HBSS. So we basically ran those programs for DISA as contractors from a technical perspective, helping them, you know, build, deploy, manage, document, test all of those different technologies as it relates to deploying them to all the different branches of the service. Very interesting.
Okay. So that was kind of a crash course in security for myself. You know, I didn't have a whole lot of security expertise before that, but, you know, got to work with product vendors, got to work with the federal government, learned a lot about, you know, security hardening and requirements and all the fun things that come along with deploying, you know, tech at enterprise scale. Yeah. Okay, so fast forward, what'd you do next?
So after that, I spent time working for— down in Fort Huachuca in Arizona doing pen testing around comm systems, voice over IP. And then after that, I started working at American Express. Oh yeah, Phoenix? Yep, in Phoenix. You know, it was a really good kind of change for me moving from kind of the more federally-centric, military-centric type of, you know, security environments to a very corporate financial services-centric situation.
So worked there, helped deploy big, you know, host-based intrusion prevention deployments, helped, you know, with some of the initial iterations of the SOC that they were putting together and kind of transitioning from their current state to their future state. And then after that, I worked for IBM Global Business Services, so helping build SOCs for components of the DHS, as well as helping them kind of build their federal data center offering, which I'm not certain, but I think it's called Smart Cloud for Government now. So is that— that's all FedRAMP? Yeah, they're FedRAMP certified now. They did all that work.
I won't take any credit for the FedRAMP work they got done, but yeah, I believe they have a FedRAMP certification now and they offer cloud services as well as managed security services for the federal government out of their Boulder office here. I think it's also multiple other locations. And so did IBM bring you to Colorado? Yeah, so I left American Express and IBM was my first engagement here in Colorado. Since I left and went out to the East Coast to start my own company and then come back to Arizona and then back to Colorado.
So, all right, so, so I won't skip around. So you were at IBM, what was next? You said next was going east? Yeah, I went east. That's when we started Phoenix Data Security, which was a consulting company that I started before Swimlane, and that was basically providing, you know, security operations consulting and security engineering consulting to federal government and commercial organizations.
So basically giving them guidance on how to set up their operational procedures, optimization, that kind of work? Yeah, building the programs, right? So, you know, if it was data loss prevention or security operations or, you know, some of the first iterations around threat intelligence, you know, how do you staff for it? What are the procedures? What technologies do you use?
How do you build it as a program more than, you know, how do you deploy the tech or how do you write the process? How do you kind of— how do you build it out as a program? And what year did you start Phoenix? That was in 2010. And how long did you run there?
So I was— we actually spun Swimlane out of Phoenix Data Security. So we actually started building it as part of that organization. We formally spun it out in 2014. And then, are you still associated with Phoenix? Does it still exist?
Yeah, so the same co-founders that founded Phoenix Data Security also founded Swimlane. So we kind of divided and conquered. Brian Kaffenbaum, the other co-founder of both organizations, now runs Phoenix Data Security full-time, and I've been at the helm of Swimlane. So is Phoenix like a going concern that's, you know, still operational on the East Coast? And okay, yeah, they're headquartered out of Phoenix now.
Yeah, ironically enough. Um, uh, but yeah, they continue to grow, they continue to service both commercial and federal customers. And, you know, that's, that's another thing that I'm happy to see continue to move forward. And, you know, Brian's doing a really good job of, you know, moving that organization forward and expanding its service offerings. And they're a great partner to Swimlane, so they offer services around the product that we have.
So 2010, you guys started Phoenix. In 2014, or somewhere before 2014, you identified this need for Swimlane for it. And I'll quickly summarize, for, you know, an automation, an automated response capability, and you thought there's a product there that we could work on. How did you go from identifying a problem in a services company to deciding you were going to create a product company to address that problem? Yeah, I mean, the inception of the idea actually happened well before even Phoenix Data Security.
Brian and I actually met working at American Express in Phoenix back, you know, well before 2010. So, you know, when we were there, we were doing host-based intrusion prevention. We were also looking at a lot of other endpoint technologies that they were, you know, they were deploying. And from an operations perspective, a centralized management perspective, it was already something that we'd started discussing at that point. When we were working in some of Phoenix Data Security, we competed with really large, well-established organizations, and we looked at taking that concept and some of the things that we already started working on around automation, around particular technologies, and continuing to formalize that into a product as a differentiator.
When you go head-to-head with very well-established vendors, you have to have really good differentiators, and that was the first concepts around what we wanted from Swimlane was to take the work that we'd already started, you know, probably back in 2008 and 2009, and drive it forward into a formalized product. So you had the idea, and I assume that you started doing some, you know, off-the-side-of-your-desk work on trying to turn this into, you know, an offering. Or maybe I shouldn't assume. How did you go from concept there to, hey, we're actually gonna have a whole separate company that's dedicated to this? Yeah, we started building, you know, kind of components for existing products, you know, all the way back in 2009, 2010.
And really just after having all those individual components, we started looking at ways of centralizing, centrally managing them. And as we started kind of evolving that concept, we realized that, you know, there's, there's a need for the ability to do automation around the things that people normally do from an operational you know, from a security ops perspective. So we started putting together requirements, trying to understand, you know, what the product would look like. At the point then, we didn't have the money in order to hire dedicated software developers, so we got some work done from contractors on some of the stuff that we were doing, but then really, you know, kind of went full bore in, you know, 2013 in building that out. So am I correct in hearing from that that neither of you, neither of you as founders are really developers actually creating the product?
Themselves? No, I mean, Brian and I have a lot of experience with, you know, dozens of different security technologies, but we knew that if we wanted to do this and do it successfully, that we would hire, you know, software developers from the beginning. Yeah, you know, when we started going down the path of we're gonna build a product, then we hired software developers to do that, and we self-funded that out of that organization. So interesting to me, you know, where— how did you make the decision that this product wouldn't— would be its own separate company rather than, you know, one company that has a product arm and a services arm. Yeah, I mean, if you, you know, as— and it's been a trial by fire for me as a founder.
I, you know, I haven't done this before, so I'm learning as I go here. But there's one thing, as you go out and try to learn to raise money, or you look at partners, is that, you know, the metrics associated with the success of a services company versus a product company are very different, right? If you, you know, if you're generating revenues from services as a product company, it's a huge red flag for VCs. And for angel investors and things like that. So having a wholly separated organization allowed us to run it as a product company without any ambiguity.
So when we talked to people about the metrics, how our revenue was growing, there wasn't questions around, well, your revenue's growing, is that services? Or did you win a services contract and you're hoping to sell the product? All the things that were happening inside of Swimlane were very product-centric. It was software licensing, it was services around the product. And generally, you know, in the industry, a product company with an annual recurring revenue model is the ideal, right?
That's where you get the best multiples if you ever sell, or, you know, if you take on investment, that's where, that's kind of where it is you can really make the biggest difference too, right? It scales a lot more easily and a lot more widely than services do, so that makes sense. All right, so you moved from back east to Phoenix, I assume, before you started Swimlane, is that right? Yeah, we actually moved Phoenix State Security from the East Coast, from the DC metro area to Phoenix, and had the concepts for Swimlane along with that. We started really kind of, at that point, we had the money we could invest in building the product.
Up until then, it was just conceptual. How did you get the money? Venture capital? No, proceeds from our services company. Revenue, gotcha.
Yep. That's great, bootstrapped. Yeah, so we bootstrapped for the first 2 and a half years. We didn't raise any outside capital until December of last year. Okay.
So we brought on our first, you know, sets of customers, obviously our first round of hiring, first product launch. All those things come out of, you know, kind of a bootstrap start. Yeah, I mean, getting an enterprise product off the ground is, it's not for the faint of heart, and not for the cash-strapped. I mean, there is a— an investment has to happen, uh, if you want to sell an enterprise product. Uh, and we naively thought we could do it, and, you know, we ended up, you know, successfully doing it, but, uh, there was a lot of lessons learned along the way.
So you might not do it the exact same next time? Uh, in hindsight, I don't— I don't— in hindsight, I realized how crazy of an idea it was to go and do it without having backing. So you're thinking next time you'd go get venture backing earlier on? Well, I don't know that I'd have, you know, if I, you know, when I do this again, there's an opportunity to, but I think there's a lot to be said for getting product-market fit, finding initial customers, really understanding what you're trying to accomplish before you go out and, you know, try to ask other people for money. I think if you've done it in the past, you're gonna have a lot more success.
I know there's lots of people out there that have done this many, many times. Serial entrepreneurs, yeah. And they can do that. A lot of respect for folks that have the credibility to raise money without a product or a customer or any revenue. But I also think there's things that are learned that are valuable when you go into those conversations about doing it without any outside funding.
You could probably make an argument the other way too. So what brought you to Denver? Why are you in Colorado? For us, we were looking at hiring. I really like Phoenix.
They have a great tech community, but they don't have as strong a security community. Community as the Denver metro area. And in all honesty, and hopefully you don't take this the wrong way, we look at organizations like Ping and Logarithm and those folks that hopefully will go public soon, which creates a really good opportunity for recruiting. So we kind of looked at— it's the truth. That was what the big— That hurts a little bit.
Well, it was the biggest driver for us, right? I mean, if you're trying to recruit and you're trying to keep your costs at a particular level, you could go to the Bay, you could go to Boston, You know, but going to Denver where potentially there's literally hundreds of employees that are potentially available over the next 24 months, depending on the outcomes for ours. So here's how I look at it. We've created an ecosystem in Colorado where there's great security talent and there's a good, there's a lot of security jobs and there's lots of opportunities for companies and people to find the right fit. That's, I do think of it that way.
I think it's a really strong thing. But you don't need to recruit any of my people. Oh yeah, no, absolutely. I wouldn't do it on purpose. No, I mean, I think it's absolutely true.
I mean, organizations that know how to build and scale at those different phases of an organization's life are invaluable, right? I mean, it's in, you know, I myself was a security analyst for many years. It's one thing to be a practitioner inside of an organization and be successful there. It's another thing to kind of take that understanding and apply it to how you grow a business and how that relates to marketing and go-to-market and sales and all those things. And some people transition through that really well, but generally you have a lot more success recruiting those people if they've been through that process before.
I totally agree. The people who get you from being a 20-person company to being a 150-person company are not the same people that you— that want to take you from being a 150-person to 2,000-person. It's really a different mindset, and people don't love both usually, right? So it makes a lot of sense. Yep.
So, you know, we've kind of alluded to it and kind of beat around the bush, but why don't you just kind of give me the, you know, the elevator pitch? What, what is Swimlane? What do you do? What problem do you solve? Yeah, I mean, Swimlane is really focused on, you know, the bottleneck that most organizations have from an operations perspective.
I mean, we have, you know, billions of dollars that are invested in detection and prevention technology, huge investments being made in threat intelligence, and all of those are driving our ability to detect and prevent things. But what it's still doing is generating a lot of alarms a lot of tasks, a lot of work for people from an operational perspective. Yeah, so, you know, as you look at how operations functions, there's an opportunity to take a lot of these high-volume tasks and apply automation to them and to track and manage it and, and to, you know, be able to, you know, provide metrics on how that's happening. So that's really what Swimlane is designed to do, is to take all the human effort that is happening from an ops perspective, be it SIEM alarms or phishing use cases or vulnerability management reports, reports and take the work off of, you know, the administrative work off the hands of the analyst and get that work done, you know, in real time at machine speed with lots of consistency. And, you know, allow organizations to scale.
They can handle more alarms, more alerts per analyst, or if you're a managed service provider, handle more customers. So I'd love to— I think I'll understand a little bit better as we dive into a couple of examples. So could you give me an example, you know, maybe something like a virus notification on the network. What might you guys do to help simplify that kind of a response? Yeah, I mean, I think, you know, sample, you know, a piece of malware on an endpoint.
You know, you get those alarms every day. You can see them coming from a bunch of different vectors, but, you know, as you get in a malware alarm as an analyst, you know, what are the 10 things that you're going to do, right? You're probably going to do some level of host forensics. What processes are running on that host? What's the registry look like?
I'm gonna take that information from my downstream detection capability and bounce it off third-party threat intelligence capabilities to say, hey, are there other processes I may be able to look for that are associated with this? Are there other— what are the other indicators of compromise that this threat actor might use if you have any type of threat actor information? And then leverage that information back into your environment to do search for other compromised hosts, what C2 addresses they might connect to, So all these things are things that analysts know they should be doing and are really doing right now via a bunch of different web portals, command line prompt, and copy and pasting, right? So it sounds like what, what you might do is, number one, we hope that an organization has matured their response processes far enough to have a checklist or an SOP that this is what we do when we, when we get a virus definition, right? And then you take if I'm getting this right, you take all of those discrete tasks and see how much you can automate to, to provide the feedback of the— of what they would get from that, and they can make a decision with the data rather than have to do all the work themselves to get it.
Does that sound about right? Yeah, I mean, the data aggregation and collection is part of the process. Um, you know, implementing— if you have existing standard procedures, I mean, that helps. Um, you can tailor Swimlane to meet your existing processes, or we can provide you with some basic, you know, it actually becomes fairly comprehensive use cases and workflows for different use cases that you might have. So yeah, I mean, the idea is that that's training somebody to do that, understanding how the environment works, where to go look for that information, having permissions into each one of those tools, knowing how to run the queries against each one of those datasets to get the information back that I want, copying and placing it into tickets, sending out an email notification.
That's all, you know, kind of high volume but not really terribly complex. Yeah, if you have those guidelines, and that's really where Swimlane streamlines that, we do that automatically. There's still an opportunity for that human component where you need them to make decisions and provide input, but there's not a, you know, if it's fully automatable based on the data sets you're receiving, you can run full automation against that. I like it. That it's— it sounds like you're— not only do you, do you help me get better scale, you also get more consistency this way.
I, I would get nervous that, you know, it's the same as always, it's really hard to automate everything, right? Right. And how do you, you know, deal with the variables that, that are just going to change based on the incident? Yeah, obviously you just kind of take it as it comes, but any, any overall guidance for how do you deal with the fact that that one virus situation might not be like the next one, that there is gonna be variants in between them, that generally we have a human just to see it and parse it and deal with it? Any general high-level guidance on that?
Yeah, I mean, I think the way that Swimlane's designed is to help kind of basically augment or replicate how analysts make decisions, right? So I mean, it's the same question we ask when you get an alarm, right? What is the severity of this alarm? If you ask the analyst that, they're gonna give you 5 or 6 different data points they're probably gonna tell you about. So, you know, what's the source?
Do I know this source is bad? What was the attack vector? What, you know, what point in the kill chain are they in? Is this just early or is it late? You know, what system is it affecting?
Is it revenue generating? Does it have confidential information? Like, all of those things go into that decision to say, is this important or not? And you can actually model that out in Swimlane. So as you're getting these different alarms and you can actually look at all these, you know, an analyst goes and looks somewhere for this information.
They don't know every revenue-generating server in the back of their mind. They have a spreadsheet they check, they go look at CMDB, they have some point of reference in which they go and make, you know, look a piece of information up in order to move this task forward. And that's really what Swimlane does. Yeah, you know, if you have to go look at DHCP logs or go look at a DNS entry or or look at Active Directory in order to make this decision, Swimlane will go do that for you. So, I mean, once again, what I really like here is it's going to force you to define what's, what's important and what's not.
You just, you just came up with a dozen examples of questions one might ask that maybe we're asking, but maybe we haven't formally documented as being part of the criteria, right? In order for Swimlane to be effective, we're going to have to document those. We're going to have to think through. And, and hopefully we go get buy-in from other people that, yeah, this formula makes sense, so that when you get an alert, um, there's cred— there's credibility to that alert, right? Because, hey, we, we agreed as a team that these are the things that are important to us as a company.
I really like that. Um, so this sounds, this sounds good. This makes sense. How do you, how do you define success when you go into a customer? You know, someone bought off on this whole thing, you know, we sales pitch and I said, yeah, I want to implement that.
You're going to walk in the door and what kind of value are you going to deliver, you know, 90 days in, 1 year in? How do you think about that? Yeah, and that's actually a really interesting thing about Swimlane versus— and other products in our space— versus your standard detection and prevention, you know, products that are sold is that a lot of time what you're talking about when you're selling a prevention technology is, you know, like kind of a qualitative protection of the brand and, you know, maybe what might be, you know, the cost associated if you were breached. The thing that's interesting about doing automation around operations is there's a tangible value to saving people time. So, you know, even inside of Swimlane, we actually track every time we do an action on your behalf, we track how much time that saves you, and you can actually, you know, tailor that.
So if sending an email takes you 3 minutes, if doing a threat intel query takes you 45 seconds, if it takes you 2 minutes to look up, you know, a user in your identity management system. All of those are, you know, those are things that you would normally have to do by hand that we can quantify, and then you can assign a dollar value to it. What is the average salary of your security analyst? Yeah. And all of a sudden, when you're doing thousands and thousands of things for people in an hour that they would normally have to do by hand, the metrics become very, very compelling.
You know, I'm offsetting, you know, the number of FTEs I have to hire to run my SOC. Reducing the amount of OpEx I have to spend on staff in order to run my managed service. I'm doing more, you know, then there's the qualitative stuff around maturity and, you know, comprehensive capabilities and, you know, all the things that come along with, you know, getting better at your job, but there is a tangible dollar savings. Yeah, that's great. And do you make that— did I hear you say you're displaying that?
Is that in the portal? How's that work? Yeah, it's right in the portal. You can, you know, so So you have basically where you define all of your different, what we call workflow items. These are the actions that we're doing on your behalf.
You can tailor it to however much time you think it's saving you and how much money it would actually, and then it aggregates up and you can see a rolling utility. And part of it is a marketing, you know, renewals and all that fun stuff, absolutely. But when people are trying to talk to their management, because doing automation is important, I need real-time response, I need consistency, I need, you know, I need to do these things, it's best for the business, but you're trying to quantify that from a business use case, and you can actually take them dollars. Over this last 45-day POC, we saved $80 grand. I mean, that really helps.
Or we got $80 grand worth of value that maybe we wouldn't have done those things because we didn't have the time, right? Much more practical, right? And for me, you know, I'm probably not able to get everything done I want to, So you guys are going to get it done consistently, and rather than me hiring a person, I'm able to get this thing to do that person's job. I love it. And generally, as security leaders, we're pretty bad at translating security tools into dollars, and you're making it easy for us.
So I highly commend you guys for doing that. That's really neat. Yeah, it's honestly self-serving, but I think it is— I think showing tangible value is is something that's rare in the security space, which is nice. And it's also tailorable, so obviously if it wasn't, then we would obviously be able to drive that cost way up. But the customers, they configure that for themselves, and they come back to us and say, hey, we saved $40,000 this month.
And that goes a long ways in saying this is definitely worth the licensing we're paying for. Yeah, right. I think it's really neat. What's your— where'd the name come from, Totalane? For me, it was basically about responsibility.
So I mean, if you've ever been in a SOC, You have people that do great jobs, you have people that kind of maybe don't do such a great job, and having things that, you know, that's in your swim lane, that's your responsibility, um, was just kind of— it's process diagram, right? Process diagram where you have different individuals and different columns and their swim lane shows everything they're supposed to do, and you're basically automating everything in the SOC swim lane. Yep, exactly. And, you know, in true startup fashion, it's easy to spell. Uh, we bought the domain for like $117.
Congratulations. And, uh, you know, and, you know, it's not so specific that we can't do anything else. Yeah, no, I actually, I really like the name. I mentioned to my wife I was coming up here to talk to you, and she started guessing what you did. She didn't get anywhere near it, but it was fun anyway.
And she'll be listening. Hi, Kristen.
You guys, are you guys a software or SaaS? We are a software platform, so generally it's deployed on-prem. We do have customers that deploy plan to the cloud. Managed service though, or not? No, we don't manage it.
We have partners that provide it. Is it Phoenix Data? No, we actually have other partners that are huge. So we have managed service customers that are leveraging Swimlane to manage their dozens of customers they have. We have a couple others that are coming on board.
But yeah, I mean, for them, if you look at the business model for a managed service provider, OpEx is one of their biggest costs. So how do I manage more customers with less people? Automation is obviously a a really good way for them to do that. So for them, they're implementing automation as a mechanism to drive competitive advantage for themselves, keep their costs down. But, you know, they do that because now they're centralizing a lot of the different tools into one spot.
I'll never say that Swimlane will be your single pane of glass. Someone's been trying to sell me a single pane of glass my entire career. You got a lot of single panes of glass. Yeah, a lot of single panes of glass out there. But the idea is that, you know, it's one thing to be able to manage a process from a PDF through 12 different tools, my SIEM, my endpoint, my threat intelligence, all these different things.
It's another thing to train somebody how to use a single product to walk through a process. Yeah. And I think, you know, it starts, you know, again, consistency, but also driving down the, the skill set, the specific, very niche skill set that's required to hire into those roles. Yeah. And the speed at which you can ramp them people up to be valuable inside your organization.
Uh, so I'm gonna, I'm gonna ask you a couple more here. Um, what is, what does Can you give me an example? I mean, you probably can't give the name. If you can give the name, great, but if you can't, no big deal. Give me an example of a customer who has implemented you successfully, like you're really happy with that, and what does it look like for them?
How does it change their business? Yeah, so I mean, we have a Fortune customer that deployed the product. You know, they have multiple kind of sub-organizations inside of their entity, and they're responsible for delivering, you know, SOC services across all those organizations. And distributing the work, tracking what's going on, for them, you know, was really burdensome, right? It's highly manual.
So for them, they're actually the customer that's saving between $40,000 and $50,000 a month through their deployment, through implementing automation around, you know, notification to the downstream customers, aggregating threat intelligence, collecting information from their managed service provider, you know, and that for them, that, you know, that was, you know, they converted off a competing product. You know, very quickly and implemented in the course of a few months, started saving lots and lots of money. And for them, it's more to your point, is they're doing things that they wish they were doing before, they didn't have the resources to do. Sure. So, so you and I talked about this, was it a few weeks ago when we got on the phone?
Who do you, who do you consider to be the right person, the ideal customer? Are you looking, is it enterprise size? Is it mid-market? Who's listening right now who you think is the right person give you a call, where should they be? Yeah, I mean, I think there's kind of a broader skill shift that's happening in, uh, you know, the security ops space, more from system administration and networking and managing, uh, network administration, more to like your DevOps and, you know, type of function.
So I think organizations that have kind of embraced that, they, you know, I know all the things that I want to do, I know I'm not getting to them, but I'm willing to put in a little bit of effort to kind of tie them all together. To see a broader value. Automate all the things, right? Automate all the things, yeah. If that's what your ops people are saying.
Yeah, or if you're just, you know, if you have an appetite to do more with less. You know, some organizations say, oh, I don't have my processes down, and I don't think that that's really a, that should keep you from doing this. I mean, once you centralize it, you can report on it, you understand what you're spending your time on, there's an opportunity to more tactically go after what's gonna provide you the most value. I think an organization that's invested in monitoring, that sees value in responding in a timely fashion, and knows they want to mature the consistency and delivery and scalability of their people in their operations are great candidates for orchestration automation. If you don't mind, I want to kind of change the topic a little bit to talk just about running a company and a little bit about that side of things.
You referenced it earlier, and I think in the first episode of the podcast, I reported on it. You guys took a round of funding late last year. Was it, was it $4 million? Uh, yeah, we, we, uh, we've taken a total— so that we announced all of our funding to date, so it was a total of $6 million of funding. Uh, at that time we had, uh, taken on an additional $3 million in equity.
Um, and how— tell me about that. Like, how did you— you've never done before in your career at all, right? No. Raising— I mean, fundraising is— that's a full-time job for something. It is for a lot of CEOs.
It is a— yeah, no, yeah, it absolutely Absolutely. So I've talked to over 100 VCs and angel groups and, you know, high net worth individuals before I raised money. And the piece of advice that I got really early in this process was you'll end up raising money from somebody you know. And that was actually the circumstances that for us. We ended up raising from an individual who was previously a customer that ended up, you know, being our investor.
And, you know, for us that's been really great. I mean, he's been a great addition to our board and provides a lot of value. Value to us. So, so tell me about your board. That was gonna be the next question for me.
What's that look like? Yeah, so we have a 3-person board, uh, myself, the other co-founder, and our investor. Yeah. Um, and you know, that's really how it works. You know, obviously raised our money in December, so, uh, we've, you know, had one board meeting to date and, you know, still kind of trying to figure out exactly how we want that cadence to work.
But, um, it's good. I mean, it's worked out really well, and you know, we're kind of excited about what that has, you know, enabled us do in our space. Obviously, there's a lot of money being invested into the orchestration space. There's a lot of competitors coming into the market, a lot of people marketing kind of collaterally into the space, and as, you know, not being the big guy in the room, that's always nerve-wracking. But on the flip side, you know, we got started early.
We built a product that was for, you know, kind of by analysts for analysts, so we compete really well. And, you know, I think the kind of the success of all of our competitors is actually helping us out because of all the marketing and awareness that's happening around us as well. Yeah. So when you think of bringing a person on your board, obviously it's kind of a given generally when, when you take funding that, that will often come along with a board seat. But what is it you're— what is it you want to get out of a board member?
You know, obviously there's, there's money in that case, but more broadly, if you know, if you, if you are, if you're looking to enlarge your board, what would the purpose of it be? I'd love to hear how you think about that. Yeah, I mean, I think for— you're crazy not to look at it, you know, from an enablement perspective. You know, how does this person help you solve the challenges that you have, and not just now, but you know you're gonna have as you continue to execute against your plan? Yeah.
So, you know, if it's, you know, go-to-market strategic partnerships, or recruiting, or future fundraising, or— I mean, there's just a whole litany of things that in and to themselves are huge hurdles that you're gonna have to be able to overcome, you know, in any given year, and finding people that can actually, you know, tell you how they've done that, they have the network to help you get that done, is invaluable. I mean, that's, you know, every one of those things, from recruiting to go-to-market to finding new customers to building out your executive management team to product management, all of those individually are terribly hard jobs. Getting help getting those things done and done well, avoiding the common, you know, pitfalls that you don't know if you haven't done it yourself before will save you time, money, hair, everything. So yeah, I have no hair, for the record. I have zero hair.
This is an audio-only podcast, so you can have as much hair as you want for the sake of this podcast. Yeah, uh, that's— are you thinking, is 3 where you want to be for now? Do you have plans to expand your board? Um, I think right now it works out really well for us. Um, it gives us you know, there's enough people to help, but not too many people that it's hard to get consensus.
I think, you know, to your point, if you continue to raise money over time, that usually comes with board seats. You know, there's obviously a kind of a delta between a strategic advisory board versus, you know, your formal corporate board. You know, I think there's kind of ways to balance that out. But, you know, I think in all honesty, the people that really, really can help you are few and far between, and they're there's a really big demand for their time, they don't want to be on your strategic board, they want to be on your board. And I think if you have somebody of that caliber that can contribute at that level, having them on your board is valuable.
So, but it's always, you know, you're also negotiating what rights they have and how that impacts the existing people and team. So it's definitely not sunshine and rainbows all the way around. So, you know, you've been running a company, I think you said you were not this year, CEO for Phoenix Data Systems. Brian is, right? But you've been running a company with him for 7 years now, basically.
What are some lessons you've learned out of that? Maybe, I'd love to hear something that you're really proud of figuring out, and maybe some relatively big failure you've had over those years. Yeah, I mean, I think starting a company with somebody is, it's a big deal. You know, people always say it's a marriage, and I think it's kind of thrown out there as cliché and, you know, just kind of a cheeky statement. But in all honesty, if you really mean it and you plan on building something of value, the person that you're building it with, you better trust as much as your spouse.
And, you know, because they, they will see all of your good sides and all of your bad sides, and they will have a huge influence over what you're doing. So going into battle with somebody that you genuinely trust, uh, and in almost every asset of your life, because things come up. I mean, family things come up that they have to bail you out of, right? And you are in it together financially and emotionally and things like that. So making sure that you're working— and that doesn't just start with your co-founder, it's, you know, who you bring on your board and who you hire early, right?
I mean, there's— if you, if you don't— we're not working with people that are just as damn excited as you are it's just gonna be frustrating for you, 'cause you've put everything you got into it. So as soon as you find, you know, somebody's not doing that with you, it's really, really hard. So I think some of the pitfalls, you know, for us, I think we took a bite of the elephant, like the whole elephant, right at the beginning. You know, building an enterprise product from scratch for enterprise customers with no outside money and not having done it, doing it before, way too ambitious. In all honesty, it was too ambitious.
Start with something that you can show value and traction on, that has potential, but doesn't require the multi-year lift of getting an enterprise product off the ground. I think there's opportunities to scale there. I think there's people that can do it from the beginning, but they also probably can raise money from the beginning. If you're gonna do this for the first time, pick something small you can get a lot of volume and traction on, traction on, that you can show value on, that has the potential to be much, much bigger, as opposed to starting with the big thing. Yeah, that's something that I, in hindsight, wish I would have done differently.
Okay, a couple questions about the community. Number one, for those who are currently leading security programs or maybe running a SOC, other than go buy Swimlane, what's the piece of advice you could give them to do better at their jobs? You know, and I touched on it earlier, if you are not experiencing the shift in skill set, go hire a developer for your SOC. Not teach a developer to— don't teach a security person to be a developer, but go hire a developer for your security team. I think the value that you'll drive out of having that skill set inside of your team is just totally immense and worth the investment.
Regardless if you have an orchestration platform in your portfolio of tools. Someone who can see a problem and go create a solution to that problem. Somebody knows what it means to take information, manage it, pipe it from one place to another, normalize it. It's just this— it's really hard as a— you know, I don't have development skills, and doing that was always something that we wanted to accomplish in some of the organizations that I was in. And I wish I'd have had that resource, and I see people that have it and have invested in it, and success that they drive out of that is just immense.
The other thing that we see a lot of people trying to do is start getting more value out of the investment that you've made in the existing things that you have. And as a vendor, this just sounds terribly hypocritical, but there's so many things that you could be doing with just the base infrastructure components of your operating system and network devices and open-source intelligence resources. Know, your, you know, FSI, you know, different ISACs that are available. There's just so much that you can be doing without spending another nickel on another technology. Amen.
And we have 2 vendors in the room here, so I genuinely believe that that's, you know, something that I think people can do and save themselves a lot of money. I love shiny things, don't get me wrong, but, you know, I think a back-to-basics approach is still very, very important. I couldn't agree more, and I And I had another interview recently where basically I think takeaway is if you can go get rid of a third of your tools, you'll probably be better off for it, right? The more focus you can give on fewer things, fewer high-value, the critical things you can spend your time on and become the expert on, probably the better your security's gonna be and the less money you spend, I think, Dan, too. I know it's not glamorous, but system hardening and vulnerability management and good user provisioning and deprovisioning and just all the hygiene things that— they're not glamorous.
But time and time again, it's proven that those are the things that create a really good foundation for you to go out and do analytics and threat intelligence and orchestration and all of these things. If you're not successful there, then all these other things are nice to have, but they're not going to provide as much value as they potentially could. You sound like someone who's read a lot of Stigs in your career. I have spent way, way too much time with the Stig. Okay, one more question for you.
What advice do you have for those who are looking to break into security, maybe a career changer or someone who's just come out of school? I think it's, you know, from an economic perspective, it's a great thing to do. Obviously, we talk about negative unemployment in the space. Even through the recession, I think people with skills would receive multiple offers in a given week. If you're looking to make a career change and get into cybersecurity, the nice thing is that there's a lot of resources that are available.
You can self-teach yourself a lot. Obviously, there's value in certifications and formal education and things like that. But in order to get into this space, there's a lot of opportunity to be self-taught, and there's also a strong community of security people that, and you know, that are self-taught, and they don't— you don't have to have that formal training. You don't have to have that certification. If you can prove that you have the knowledge and the willingness to, you know, contribute and, you know, for the success of the organization, there's opportunity for you, and the career progression is very, very fast.
Sure. So I mean, there's, there's just a lot of opportunity right now, and there's people trying to help you out. I mean, there's lots of programs available at the federal level, at the state level. Uh, you know, hell, I think there's vendors that are doing enablement that allows people to get into space just because there's such a shortage of people available. Yeah.
And here just in Colorado, we have like the Colorado Springs ISSA chapter does Security+ trainings for free, or $40 I think it is. And they'll do CISSP trainings for $120 for like an 8-week course. There's all kinds of ways to get your feet wet there. What about for Swimlane? Are you guys hiring?
You looking for any? Yeah, we're hiring kind of across the board. Software development, field operations, which is basically deployment and delivery of Swimlane, marketing and sales. We're actually doing some summer internships, so we're hiring folks in all the different departments for summer internships. So yeah, hiring all around.
Go to swimlane.com, or do you have an email we should— people should send? Yeah, go to swimlane.com, check out the careers page. We list all the different roles that we have available. So yeah, lots of stuff going on. And then obviously partners, right?
So we're always, you know, we're actually, you know, working on a partnership with Ping right now, you know, with some joint customers that we have. But, you know, would love to continue to expand our integration footprint locally as well. So I mean, we're an orchestration platform. Integration is our bread and butter. Yeah, so, you know, the more that we can add, the more opportunities we have to build use cases and value for our partners is great.
If you have systems that don't intercommunicate and aren't standards compliant, you guys are gonna have a hard time working with them. So it's probably a lot of incentive to make sure we're all talking to each other. Yeah, I mean, obviously integration happens really easy when you have, you know, robust APIs, right, good documentation. But, you know, not all products have that. And, you know, with Instantland, we've built a lot of— we haven't run into a technology we haven't been able to integrate.
Oh, nice. So, I mean, we can connect lots of different ways. Obviously, we love, you know, good APIs, right? Drivers, right? But that doesn't mean that there isn't opportunities to work with technologies that don't have that currently.
Yeah, it is becoming table stakes though as a vendor, much like the early 2000s where you had to have the web UI versus a fat client. Robust APIs is becoming very, very prominent in RFIs and RFPs. And I can, and I can just, you know, echo that from the ping side too. API support is bigger and bigger expectation for customers. Well, it's been, it's really been a pleasure.
This has been a fun story, you know, and hopefully, you know, for those who hadn't heard of you guys, now we can share the story of Swimlane and what you guys do and support you guys in the community. Anything, any final things you want to share with the community before we sign off? No, I'm just, you know, I'm probably not the networker I should be. I really like the community here. Um, you know, we've, you know, thankfully have a lot of folks we've hired from locally, so we're just, you know, starting to get a little bit more kind of brand recognition on the hiring front.
But, you know, always happy to, to engage with folks. Uh, we're pretty accessible. Yeah. Um, you know, let us know how we can help and be involved. So sounds great, and we're going to get you, you guys talking at an ISSA event sometime soon, and we'll, uh, we'll, we'll get that all figured out and sent out to everybody.
All right, well, Cody, once again, thanks for your time. All right, thanks, Robb.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember Colorado equals security.