All episodes

Brad Feld

Apple Podcasts Spotify SoundCloud

In this episode:

Brad Feld is the feature interview this week. Brad is managing partner for Foundry Group, and co-founder of Techstars. News from Amazon, ID Watchdog, Sphero, Optiv, Ping Identity, and Swimlane.

Alex will never be lonely again

The summer is in full swing, though the Denver weather hasn't quite been convinced to get with the program. Tech hiring is up in Denver in 2017, a Denver identity theft company gets acquired for a big price tag, Optiv and Ping have some big announcements this week, Swimlane gives a nice tutorial on what security automation is (and why you need). Finally, a local toy maker has spun off a personal robot company; Alex will never be lonely again.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Brad Feld, co-founder at Techstars and managing partner at Foundry Group, has brought Boulder, and all of Colorado, into the Venture Capital world. Robb was lucky enough to have the opportunity to sit with Brad to discuss how he ended up in Boulder, what accomplishment Brad is most proud of, and where he sees technology (and security) going in the future. 

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11653 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 21 for the week of June 26th, 2017. Alex, how's your weekend been?

You know, it's been pretty good, Robb. Yesterday, the family and I, we went tubing on the South Platte River for a little bit. Water is still very cold, as you might imagine, but it was a good time. Good time had by all. Is that something you guys do regularly, or is this a random?

We've done it a few times. We're close enough to a good spot to get in that it's not hard to do the logistics, so it's pretty fun. That's great. How about you? We got back from Chicago.

I was out there for PING's big industry event. Cloud Identity Summit. I was out there for the week, just kind of recuperating. Uh, out there we got to see all the sights, right? Hadn't spent a lot of time in Chicago.

We went to Sears Tower, which is now called the Willis Center. Interesting fact that was dropped on me about the Sears Tower slash Willis Center, you know that after 9/11 they rebuilt the, the memorial there. Uh, was it called One Liberty Place or something? Oh, One World Place, right where the World Trade Center was. Uh, they built it to be taller than the Sears Tower, to be the tallest building in the Uh, in North America.

And when they got about 15 levels from the top, they realized they were running out of money, so they stopped building about 150 feet below where they were aiming for, and they built that super tall 400-foot spire on it. Yeah, that, that brought the total length with the building plus the spire to, uh, 1,776 feet. So, but the Sears Tower people still say they're the tallest building in North America because they They've never counted an antenna as being part of a building before. So they're still, the way they put it was, if you wanna go to the highest floor on any building in North America and look out a window from the highest spot, you have to do it at the Sears Tower. So that reminds me of a story.

I don't wanna get too far down a rabbit hole, but I have family that owns a lighting maintenance company in Chicago. And my uncle worked for them one summer and he actually had the opportunity to change some of the light bulbs at the top of those antennas, uh, at the top of the, the Sears Tower. So pretty scary. And your uncle's still with us today? He's still with us today.

Well, that's, that's good. It sounds like it went pretty well then. Yeah. All right, let's dive into the news. Before we jump into the stories, just a reminder for those listening, we do have a mailing list.

If you guys want to have this, these stories and these show notes sent into your inbox once a week, go to colorado-security.com, sign up for the mailing list, and we'll get you added. So first story this week, we're going to follow up with what we talked about last week. Amazon brought their Prime Now, their 2-hour shipping to Denver, and the Denver Post did a review of the service and kind of talked about how it went. They had 4 lessons learned and we thought we'd share those with you guys. Yeah.

So one of those is that it's not actually offered in very many places at this point. So a lot of the zip codes that they tried, you couldn't find the, the 2-hour shipping, including my house. It looks like Centennial. So they mentioned you have to spend $20 or more in order to get this service. It's not with anything, and it's kind of divided up in between items from Amazon and items from their grocery store partners.

Either one, $20 on either, but not a combination of the two. Also that there is tipping involved. So it's included by default, but not mandatory. So you don't have to tip somebody. And you can actually choose not to tip after the person has come and treated you rudely, or you can add more tip afterwards.

So that's kind of nice. And then finally, it says it's 2 hours, but it looks like they're actually going to give you a 2-hour window, which may actually be 2 to 4 hours from now. Still same day, but not quite within 2 hours as though we were thinking originally. Yeah, it sounds like they don't have a whole lot of capacity yet. So it may be that to get it within 2 hours, you have to plan in advance a little bit.

Otherwise, those windows will fill up. So next, Sphero. They're a toymaker in Boulder. They have spun off an entire new personal robot company. Alex, how do you feel about that?

I've always wanted a personal robot. Who doesn't want a personal robot? You know, I need Rosie to come clean my house. And Alex will never be lonely again. Ouch.

It is interesting, though. Sphero seems to be a pretty cool company. It's, it's cool to see them doing well. Obviously, again, not security related, but Robots are always a cool thing. Next on the list, we have an article about hiring expected to increase in IT in Denver in the second half of 2017.

That's always good. We like to have people being hired. That's just based on feedback from CIOs in the area who are looking to ramp up hiring. Yeah, it doesn't seem like it's going to be a gigantic increase in hiring, but still an increase. Well, good thing, because there's no one to hire, so you never increase too much.

ID Watchdog, they're a Denver-based identity theft company who I hadn't actually heard of before, but right there in the middle of downtown, they were just acquired for $63 million. That's a good chunk of change. They were, uh, purchased by Equifax. So I think most people have heard of Equifax credit company. So congratulations to that team.

Yeah. So next on the list, we had an announcement from Optiv. They had an announcement that they have 2 new services in their IAM division. So they're doing more identity and access management services. Those were the first, they call Identity-Centric Security Workshop.

So if you want to have them come out and talk to you about how it is that you use identity as a primary component of your security program, they've got that set up as a service now. And then also a secondary service with, with Ping and Netscope for an integrated security solution around that. So it looks like they're ramping up their game in terms of consulting around IAM. Yeah, and I think the timing on that press release probably was to coordinate with Ping's big conference last week. There was a number of Ping press releases last week in coordination with that.

We'll just go through a couple of those real quick. Number one, we talked about this a month or so ago when they mentioned it was coming, but they have now officially released this integration with Microsoft Active Directory in Azure where Ping has a service that can be added into the Azure AD to allow access into the on-premise applications. So generally Azure AD only allows you to get single sign-on into cloud applications and other O365 systems. This allows you to extend that back into your corporate network to your legacy systems that aren't in the cloud. I, I think that's a really cool solution.

Um, for one, you would think that's something that would be provided by default, so since it isn't, having that ability is pretty cool. Uh, I also like the fact that, uh, the first 20 applications are free. So if you're a small company, um, or if you just want to get your feet wet, uh, you can use that without having to make a purchase. And I would guess for all your SMBs, 20 is probably going to get you either all the way there or real close to all the way there. So So it is a nice solution for a lot of companies.

Second announcement that I thought was worth mentioning was Ping has added a pretty cool new feature to their PingID, their MFA, multi-factor authentication product. Basically, they've added an SDK where you can embed this functionality into your own product, into your own in-house corporate branded system, or really do a lot of interesting stuff with it. So you can have your product kick off an MFA requirement to a user at any point you want. So, you know, if you have online banking, someone goes to, to go transfer more than, you know, $2,500, all of it all of a sudden kicks off an MFA requirement through our, through that system. And it can be branded with your banking name on it or whatever you want.

So that's kind of a neat new feature. That is a neat feature. Uh, next on the list, uh, there's a blog by Swimlane this week called What Is Security Automation and Do You Need It? I think, uh, the answer is yes, probably everyone needs some of it. Um, but it's a nice little primer on, you know, really on what security automation is and workflows and how you can utilize those.

And, you know, obviously they're a workflow and security automation company, obviously how you can use their product to implement those things. But I think with, you know, skill shortages and, uh, you know, trying to make everything more efficient, you know, security automation is definitely something that, uh, that people should be looking into. And it's good to see more from the local automation company Swimlane up in, is it Louisville? Up there somewhere near Boulder. Good for them on making this, and we'll try and keep talking about what they're doing up there going forward.

Last bit of news this week, we want to just say congratulations to Randall Frietzsche. Randall is taking over as the Chief Information Security Officer at Denver Health here in downtown Denver. Yeah, awesome. Congratulations. You know, we've talked to Drew Labbo on the show a couple times, and Drew was the CISO there previously.

Randall's going to be taking his, his place there. Randall has served for quite a while at CHI in a variety of roles there. Um, so, you know, staying here in Denver, staying in the healthcare area, uh, should be a good fit. Yeah, great. Congratulations there and good luck.

So let's go ahead and move over to the events for the week. Uh, just as a reminder, on the website colorado-security.com, we do have an entire calendar filled with all the events coming up. It's actually filled out through just about November at this point. Um, so go ahead and take a look and, and you get scheduled on what you want to go to in the future. So the first event on the 27th, uh, ISSA Denver Women in Security, uh, SIG is having their, um, quarterly meeting.

So that's at a new location, uh, the Denver Field House, which I think is off Federal. Is that— yeah, that's right. Yep. Um, so that should be fun. I, I haven't looked at the numbers recently, but before I went to Chicago, they were doing really well.

On the 28th and 29th of this week, the Cybersecurity World Conference, that's by Misty. They're coming to Denver for the first time. Yeah, that could be interesting. Um, also on the 29th, uh, Avanta is having their annual CXO Executive Summit. So that's for CIOs and CISOs.

Um, there's going to be some good content there. That's down at the, uh, the Hyatt in the Tech Center. On the 29th, SecureSet has a cybersecurity career trends event. At their new location in downtown Denver, right across from the ballpark on Blake Street. And I believe that is also in conjunction with an open house that they are having to celebrate that new location.

You got it. And then on the 3rd of July, we have the new group on here, Denver, called DenSec or Denver CitySec. They have their meetups twice a month. They have one scheduled on Monday, the 3rd of July. I'm a little— I'm not sure if they're going to actually have it on the 3rd or they'll cancel because it's the day before the 4th of July.

We'll try and clarify before next week and definitely update on the website when we confirm it. Yeah, and they've gotten a little bit more organized. Don't they have a website now, Robb? So you should be able to find that information on our website. All right, that sounds good.

So let's go to the jobs. We have a few different jobs we're talking about this week. First one, Optiv in their Office of the CISO is hiring an executive director on executive solutions. Dish Network is looking for a senior security engineer. And I did drop a note over to John Everson, who we've interviewed on the show, and he's the CISO at Dish.

I asked him what he's looking for here. It sounds like there's a little bit of flexibility that they're looking for someone who's got good depth in either software development, so application security area, or network security. So if you have a good strength in either of those 2, this could be a good role for you. Premier Members Credit Union, they're looking for an information security analyst. Western Union is hiring an IT project manager focused on information security.

BP, or British Petroleum, is looking for a security architect. And that's, that's interesting to see. We talked several months back about the fact that BP was moving their North American headquarters to Denver. So it's good to see that they're hiring security people. So is BP kind of like with KFC or, or EY that they got rid of the actual names?

Yeah, I don't know. That's a good question. Is it still— it may have been after the catastrophe with the spill that they Let's just get rid of that whole name. Yeah, well, you probably don't want the petroleum part in your actual name anymore. That could be.

West Corporation is hiring a Senior Divisional Information Security Risk Analyst, which clearly wins the longest title award for this week. It's always nice to have 6 words in your job title. Yeah. And there's this company called Ping Identity. Don't know them very much, but they're looking for a GRC analyst.

Yeah, and this position will continue to be beaten into you guys until it's filled. So just looking for someone to help us with our controls, with our compliance with ISO and SOC 2. So if this is something you're either experienced with or would like to get to know more about, go ahead and apply on the website. You can drop me a note if you have any questions. And I think that's all we have for this week.

All right, well, sounds good. We'll talk to you next week and we'll be celebrating the 4th of July at that point. Awesome. Thanks, Robb.

Hi, this is Chad Payne, Executive Director of IT Operations for Kraken Sports and Entertainment. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. All right, welcome to Colorado Equals Security. This is Robb, and I have the unique pleasure today of getting to sit with Brad Feld. Brad is a Managing Director for Foundry Group, and he's a co-founder for Techstars here in Denver, and it looks like you're on about 22 other boards if your LinkedIn is to be believed.

I try really hard not to count. Well, so I did the counting for you there. So just to start off, I'd love to hear, you know, start off the interview by telling me something from your career you're most proud of. What is something that you've done that you think has made the biggest difference and you'd like to share with the group? Well, I think of all the different companies that we've been involved in, The one I'm most proud of is Techstars, which itself was a startup in 2007.

So in 2007, David Cohen and David Brown, who are the co-CEOs, Jared Polis, who's now our congressman who just announced that he's running for governor, and I funded the first Techstars program that David Cohen ran. And, you know, 10 years later, the impact of Techstars globally is, is pretty remarkable, not only in the accelerator programs that Techstars runs, which are now 30 around the world. So about 300 companies a year go through Techstars program and get funded by Techstars, but also organizations like Startup Weekend, which Techstars acquired a couple of years ago, which was actually started also in Boulder in 2007 by a guy named Andrew Hyde, who was working very very early on in that early, early Techstars activity. And, you know, in the growth of Startup Weekend, it got acquired by another nonprofit, and then scaled way up. Today, I think we have probably about 20 Startup Weekends happening somewhere in the world every weekend.

So what's the Startup Weekend? It's a 54-hour simulation of entrepreneurship. And so the idea behind it is that on a Friday, a bunch of people who want to work on startups or are in startups or are thinking about, you know, what does this entrepreneurship thing mean, get together, and over the course of Friday, Saturday, and Sunday, you know, they form teams, they start up some companies, they actually do the origin work of starting up a company, not just the technical piece of it, but often the business side of it, a little bit of what the product's going to be, doing some product-market fit activity, and then on Sunday everybody shows off what what they've done, and typically there's one company that is the highlight. The goal is not necessarily to start companies, but to get people involved in their startup community around the activity of starting companies and actually work on things together rather than just talk about it. Although some very interesting companies have come out of Startup Weekend.

So one that I'm on the board of, it's based in Seattle called Rover, came out of one of the Seattle Startup Weekends, was started by a guy named Greg Gottesman, who's, uh, now runs a thing called Pioneer Square Labs, uh, which we're investors in, but previously was a partner at Madrona Venture Partners. And today Rover is extremely fast-growing, uh, dog walking business and dog sitting business that, you know, if you have a dog, you probably are familiar with Rover. If you don't have a dog, you may not have ever heard of them. And you might say, gee, that seems like kind of a trivial business, but in fact it's a profoundly interesting and very, very large business because of the dynamics of, you know, how we think about— is it the gig economy come to dog walking? There's some of that, but there's also a fair amount of activity around, uh, both sides of the problem, which is it's, it's not purely a transactional relationship.

Um, you know, there's a lot of things that a company like Rover can do to help both the dog owner and the dog sitter and be in the middle between those 2 activities. So You know, it's, it's, but it is a marketplace business, and it's a marketplace that has both real-time elements to it as well as reservation-based elements to it, which are essential if you think about how marketplaces work. Understanding how those fit together matter. But, you know, in this startup weekend that Greg was part of up in Seattle, he's like, I got a dog and I don't want to bring it to a kennel, and it's a total pain in the ass to figure out what to do with it when I go away. There must be some way to create a marketplace So, and from there comes a business.

So the, you know, as I hear you talk about what you guys have accomplished with Techstars over the last decade or so, it sounds to me like you're reducing the barrier to entry for people to go from ideation and, you know, a desire to create a business to success. Is that— I think that's part of what Techstars has done. We have a very, very broad belief in this idea of democratization of entrepreneurship, that you can start companies anywhere in the world. Um, you know, there has been a very, very broad and significant trend that's been going on for the last 10 or 15 years, which is that the cost of starting up a high-growth business, uh, has continued to decrease. Um, you know, this is not to say that it's easier necessarily to build a successful business, but the barriers to getting started, both from a financial perspective as well as an information perspective, uh, have gone down quite a bit.

And I'd say the other side of it has also shifted, which is that the idea of starting a startup or becoming part of or joining a startup at the early stages is no longer as strange to a lot of people as it used to be. You know, the idea of working for 25 years at the same, you know, large company and then getting a pension and retiring is, is not a modality that a lot of people are thinking about these days. Or as I shouldn't say a lot, it's not as many. There's a growing percentage of folks who are looking at a different way to to do things, right? So I'm guessing that in 2006, 2007, you didn't just roll over and say, now it's time for me to go do startups.

How did you get into the VC/startup business? I started my first company when I was in college in 1987. I had a partner, another person who lives in Boulder, a guy named Dave Jilk, and I created a company. It was very, very aptly named after my father. It was called Feld Technologies.

And we built a business that we bootstrapped. We never raised any money and sold it in 1993, so 7 years later, to a public company for a couple million bucks. We built a software consulting company, so it was back in the late '80s, early '90s when PCs were just starting to be networked. So there was no— I mean, there was an internet, but there was no commercial internet. There still wasn't, for For people who are old and can remember client-server computing, there wasn't client-server computing.

You literally had PCs on desktops that were connected together sometimes by a Novell network, and maybe the data was shared on the server of that Novell network, but all of the software was running locally, and it was just literally a data store for whatever was happening. And we wrote lots of software in different languages. Ones that old people may remember, like Clarion was one of our languages that we wrote and DataFlex was another. Of course, we did some work with dBASE and Paradox. And when I sold that company, I sold it to a public company that was growing very, very quickly.

They bought about 40 companies in 3 years. We were the 8th.

In that public company, I very quickly ended up in a role where I was working on the deal team helping them evaluate companies they were buying. So I learned a lot about— I'd never done an acquisition before my company was acquired, so I learned a lot about how to evaluate companies for acquisition from both a financial and a business and a technical perspective. I also started making angel investments with my own money at that time. So between 1994 and '96, I made about 40 angel investments, about one a month. In mostly internet startups, so $25,000 to $50,000 type checks.

And there were some companies that people may remember from that timeframe included a— the first one I did was a company called NetGenesis, which was one of the early web analytics companies. They ended up going public in 1999. Another one was a company called Critical Path, which was one of the first, or maybe the first, email hosting business. So you could have a commercial email address, um, you know, with your .com or whatever your company was named, but they hosted it for you. Um, and, you know, ISPs were doing this, but they weren't necessarily giving you your own domain name.

Yeah. Or you could— it was kind of a hacky thing. It wasn't easy. They did this at scale for companies. Um, that company also went public and was very, very successful.

Another early investment of mine was in a company called Harmonix, which I was an investor in 1994 and in 2005. So they were an overnight success, only took them a decade. In 2005, they released Guitar Hero. Yeah. And, you know, that was an extraordinarily successful video game.

And they got bought by MTV for— Viacom for originally what was $175 million. And by the time the earnout was settled and there was a lot a lot of struggle and litigation around that. 7 years later, the payout was closer to about $700 million. Oh my goodness. So very, very significant business.

There's a fun twist with Harmonix is that Viacom decided at some point they wanted out of that business, so they sold it back to the founders, Alex and Aron. Um, and we then subsequently at Foundry Group invested in it. And today they're working on the next generation of, of music and rhythm-based video games using VR and, and, you know, Oculus and other types of technologies. So I saw that on your LinkedIn. So you're on the board for them now, 23 years later?

20-some years later, I'm on the board again. So that's how I get started. I mean, I made a bunch of these investments. Um, my wife Amy and I moved to Boulder in 1995 from Boston where we'd been living. She was from Alaska and I was from Dallas, so Boston, New England wasn't home for us.

We moved out to Boulder randomly, and, you know, I continued travel and invest on the East Coast and the West Coast, but I started to do things in '96 and '97 here locally. And in '97, I ended up accidentally co-founding a venture capital firm that was originally an offspring from SoftBank, which evolved into a firm called Mobius Venture Capital, which we ended up raising a bunch of money in the late '90s through a couple of funds. We had one very successful fund. We had We had one fund that was a complete disaster. My partner, Jason Mendelson, and I at Foundry are still managing the last 2 of the Mobius funds, which still have lots of companies in them.

And, you know, all of a sudden, I was a partner in a venture fund doing, instead of writing $25,000 and $50,000 checks, I was writing $1 million to $10 million checks. Yeah. So, I mean, that's an interesting road to go from a little bit of your own money on the side full-time, you know, big funds you've been managing. Uh, is— does the dynamic of how you make decisions, has that changed as the, the dollar amounts go up? Well, yes and no.

So we started Foundry Group in 2007, and that's the fund that, um, I'm currently a partner in. Um, the— in 2007, it was myself, Jason, Seth Levine, and Ryan McIntyre. And Seth and I had worked together at Mobius since about 2000, and Jason, Ryan, and I had also worked together at Mobius, although they had been based in California, so they moved to Boulder from California to start Foundry.

When we started Foundry, we changed— or we came up with a strategy that I would like to say was roughly 180 degrees from Mobius's strategy. So I like to say that people either emulate their parents or they react to their parents. And in this case, we were opposites of many, many things that we did at Mobius. One of the challenges at Mobius was that we didn't have a particularly clear strategy. So, we defined one.

The other is, or another is, that we thought really hard about what we were going to invest in and how we were going to invest in companies. When I was investing as an angel investor, I was really only focused on 2 things when I invested. In the company. I literally paid attention to, did I care about the product, and did I want to be partners with the founders? That was it.

Yeah. And if the answer to either of those was no, I didn't invest. If the answer to both of them was yes, I wrote a $25,000 to $50,000 check. In the arc of Mobius, we created all kinds of different rules for how we were going to invest and, you know, evaluate companies. And we had— we even had like a scorecard at some point, and each partner We were 10 partners at the peak.

We each allocated points to every company in the different categories. It was fucking stupid. And we sort of went through this, and, you know, when you reflect on it, what you realize is that there's not much critical thinking going on, right? You're using some process to drive your critical thinking, or to mask your critical thinking. To mask the fact that it's really qualitative and try to make it look quantitative.

That's right. And so, when we started Foundry, we said, we're going to have a set of themes. Themes. If the company's not in the theme, doesn't matter how amazing the entrepreneur is, we're not investing in it. Just doesn't matter.

If it's in a theme and it's in the US, because we decided we would only invest in the US, and it hasn't raised more than $5 million— we like to describe ourselves as early-stage investors, but we don't have to be the first money in a company. Okay. And when we started in 2007, we actually hit that threshold, was $3 million. It drifted up to 5 because we realized we were doing investments in companies that had 3.5 or 4. Like, it was— they were still very early stage.

They really weren't any different because companies had started to raise more money in that first seed round. Um, if you'd raised less than $5 million and you fit through a theme and you're in the US, then we focused on 3 things. Number one, uh, did we have affinity for the product? So very similar to my— did I like the product when I was investing as an angel? We don't have to be daily users of the product, but we have to care about the product.

And we've now invested in so many things we don't give a shit about in the past that we just don't wanna do it anymore. Like, we don't wanna be an investor in a company who we don't care about the product. The second piece was, are the founders obsessed about what they're doing? And I use the word obsession and obsessed instead of passionate, 'cause passion is totally easy to fake. It's really easy for somebody to be passionate about something, something, it's extremely hard to fake obsession, especially over multiple interactions.

What does obsession look like? Well, it varies because people have very different personalities, but the best way for me to describe it to somebody is if you were put on the planet to do this thing, obsession will come through. If you weren't put on the planet to do this thing, it will be clear that you're not obsessed about it. Okay. And, um, again, very qualitative judgment.

I'm sure we're wrong sometimes. We think somebody's obsessed about something and they're not, or we don't think they're obsessed about it and they are. Like, it's not that we have a perfect filter, but I think it's a very directionally powerful one. Um, and oh, by the way, each of us touches each company separately. Yeah.

So we're not influencing each other's critical thinking. So things like that are hard to hide. Obsession is hard to hide if you have multiple personalities interacting with you. Um, or I should say lack of obsession is hard to hide. And then the last do the founders want to be partners with us as much as we want to be partners with the founders?

So those are really our 3 criteria. Now, we know the themes extremely well. We know the markets very, very well. So we don't have to do analysis of what's your total available market, what's your technology differentiation, because we're limiting ourselves to a set of areas, themes that we know well. We can spend all of our time on that other stuff.

So what are the themes, at least currently? Sure. So, um, I'll I'll give a couple of examples. If you're interested, foundrygroup.com/themes has them all listed. Our themes tend to be very abstract, and they tend to have a— we like to believe that they have a 30-year forward time horizon.

So it's an area that we can be investing in for a very, very long time going forward. Examples of themes would include human-computer interaction. So the premise that the way that humans and computers interact with each other is going to radically change. If you think about how we interact with computers today, even if you go back 10 or 20 years, it's totally different today than it was 10 or 20 years ago. Imagine how much different it's going to be 30 years from now.

Another theme we invest in is a theme called protocol. And these are companies that have built businesses around the technology protocol. And they don't have to be formalized protocols, you know, IETF protocols. They can be. They don't have to be.

An example of some that are would be SendGrid, which is a local company that we're investors in here, that's built a very significant business around email. Returnpath's another one that's built a very significant business around SMTP. Ping, where you work, SAML is a core protocol. So, like, that notion of a protocol is key. Interactivity, bridging between other technologies.

Yeah. And so, we understand how to build companies around those technologies protocols, because we've been doing that for a long time. Another theme is a theme we call glue, which is really a cousin of protocol. And glue is software that helps machines communicate and interact with other machines. So it's that software layer between machines.

Gnip, which was a local company that Twitter bought, is a great example of glue. What Twitter was, or what Gnip was, is Ping spelled backwards. Was essentially a reverse ping server. Every time a tweet happened, Gnip had access to Twitter's firehose, and then there were a whole bunch of companies on the other side that bought access to those tweets. But they didn't buy the firehose, they bought access to a filtered set of it based on what their filter rules were.

The alerts, basically, they wanted. Whatever they wanted, whether it was a company or, you know, it could be very complicated, right? Geo plus a bunch of keywords plus a time range plus— Imagine use cases, right? Someone's tweeting about, you know, this technology and I want to sell to those people. That's right.

You can get really— I mean, the vast majority of companies doing social media monitoring or anything around social media at some point had some kind of relationship with Gnip, which now of course is part of Twitter. I talked about Rover earlier. That's in our marketplace theme. But a key part of our marketplace theme is that you have to have an asset that expires on both sides of the marketplace. So we like to We call it Remnant Asset Management, because one of my partners' initials are R-A-M, so, you know, we tease him about that.

But essentially, you know, the buyer demand has to expire over some time period, and the supplier capability has to expire over some time period. So, the trick is, if only one side of those expires, it's not interesting to us. If both sides expire, they have to expire not in concert with each other. Like, this will work until Friday and then it stops working. That doesn't really work for us if both sides are like that.

The reason— excuse me— Rover's so particularly interesting is, um, the periodicity of when you need your dog to be sat varies dramatically. It could be something you know months in advance because you're going on vacation, and it could be something that you find out in the morning because you have to go on a trip somewhere. Yeah. And the other side of it, in terms of, uh, the, the dog sitters, is very dynamic because most dog sitters have a limit of 1 or 2 dogs that they can see, that they'll sit at any given time. Yeah.

And they also have life gets in the way. So when you wake up and you realize you need a dog sitter, it's not that you can just call your normal dog sitter that day and say, hey, can you do this today? So hence the need for the marketplace. So the— and there are things that wouldn't be interesting would be somewhere where we have a constant demand, like the manufacturer who just makes an unending supply of these things. Correct.

Or, or, or a supply that never expires. So, um, you know, physical goods on one side of the marketplace where the physical goods literally never expire. Now you can do some things in the marketplace to try to make them look like they expire, right? You know, the razor blades, or the deal's off by this point if you haven't done something. But that's artificial because if it doesn't get bought, that supply just shows back up later in the marketplace.

Gotcha. So these are the kinds of ways we talk about our themes. And in some ways, we use our themes to say no to lots of stuff. Our goal is to try to say no within 60 seconds to anything that we're not going to be an investor in. Yeah.

So we don't waste the founder's time. So we don't spend a bunch of time on things that we're not going to be investors in. But they really help us, again, feel comfortable that we're actually applying critical thinking to what we're doing because we know big parts of what we're doing already. Yeah. Versus we're on this constant quest for learning something new about a new industry or new technology, etc.

So do the partners— do you guys divide up the themes and you become experts on— We all work on all of them together. Okay. And so do you guys get together? How do you do learning about— because there's a lot of change in all of these things, right? How do you learn about it?

I think it varies. It's certainly not groupthink, but we're all trying to be experts at the same level, and we all have different temperaments about different things. So, for example, you know, one of us could be very quantitative and very focused on the quantitative data. Another one of us might be much more focused on product. You know, somebody else might be much more focused on, you know, the legal issues surrounding the way a particular marketplace works.

Right. So we have different you know, different things that turn us on as individuals in terms of areas that we have more expertise. But we try to— because we're a small partnership, we try to communicate that stuff continually so we learn. Yeah. And, you know, it's not that you want to have specialization where you're constantly doing the same thing over and over again.

You want to learn something, and then you want to spread that learning and continue to create scenarios where you can keep learning as the businesses evolve. So we are, you know, a security show, so I'd love to hear a little about your take on the security industry. What kind of— do you guys look to invest in security? Does it fit into any of those categories for you? Yeah, I would say in general, we don't think about security in the same way we don't think about AI, or the same way we don't think about, you know, it's too broad, VR, AR, right?

You know, we're cutting differently. I mean, if you wind the clock back to the beginning of computers, there's an awful lot of things that either are trendy in moments of time or are sort of very broad categories that apply for a long period of time but are changing constantly. One that people can relate to from the last 20 years is video. If you think about video and the dynamics around video on the internet and how that's impacted the world today, right? In 2017, you know, the notion of watching something on your laptop versus, you know, even in 1997 how people were talking about video and the importance of video— or forget about your laptop, let's talk about your iPhone.

Yeah, right. You know, the idea of watching video on a cell phone in 1997 was nonsensical. So, but if you said we're going to invest in video, you're investing at multiple points in time on very, very evolving technology curves. I think we categorize security in the same way. And so as a result, there are going to be some companies in the world of security that are interesting to us, but they're tend— they're going to tend to have a very specific set of characteristics.

One that we are investors in that we find very interesting is a company called Distil Networks, which essentially creates a barrier barrier for any sort of automated bots hitting your website. Now, there's a bunch of other things that it can do besides just keep bots out of your site. And an example would be that most analytics about websites don't do a good job of filtering out all that traffic. So most analytics are inflated. Yeah.

And, you know, if you're just showing your analytics for ego purposes, you're kind of happy. But if you're trying to do any kind of A/B testing with those analytics, you end up with data that may or may not be right. So we view Distil as a company sort of touching on in 2 different ways our glue and our protocol themes, right? There's a protocol element to it because of all the stuff around bots and what that looks like, but there's also a glue component to it in the context of how machines and machines interact, where it's really sitting at that machine machine layer. Yeah, um, you know, you can probably squint and put most security, uh, companies into our glue theme, uh, in the same way that there's an awful lot of ad tech companies that you could put into our glue theme.

What we ended up doing with ad tech is we don't like to be ad tech investors. We don't invest in ad networks. There's not sort of the broad interest. We're again machine-to-machine layer there. And so what we ended up doing was we created a theme we called Adhesive, which was glue for ad tech.

And, you know, could you imagine that we would do something in the context of security around that? Possibly. But my guess is we'll continue to pick off every couple of years, you know, a super compelling problem in the security world that looks like it's attacking a vector that we can relate to, the same way we did with Distil. Well, I'll give a shout out to Chris Nelson, who's the senior director of security over there. He's the one who made the introduction, so I appreciate that.

So as you're looking to invest in another company, do you do any level of security due diligence on them? Do you care where a company's security practices are? Yeah, at the stage that we invest, typically we don't because we're such early investors.

I would say that as companies scale up, that security dynamic becomes much more important. And I think we're a pretty good resource for introducing them to, you know, the founders and the CEO to companies that can be really helpful and impactful on their security practices.

You know, we do things across our portfolio periodically. I think about 18 months ago, we hosted a security summit where about 150 to 200 people came that were, you know, DevOps and CIOs and CTOs and senior whatevers in companies that cared about different approaches to security. And I think we're pretty clear, I mean, with most startups, their security practices, especially the non-technical security practices at the beginning, are very insecure. Many companies have pretty good security in terms of their technical systems, but you walk around their office and you see passwords passwords written down on pieces of paper, right? You know, just the human security side of it, um, uh, in a lot of cases is weak.

You know, as companies scale up, like, you know, you, you look at their doors and you realize that they don't have any sort of— nobody has badges and key codes. I mean, nothing that's sort of standard security practices. You start to worry about, you know, your data assets in a meaningful way. Now, most of these companies, not all, but many of them have another layer of security health because they're on AWS or, you know, Google Cloud, but then they don't realize what they actually have protection for and what they don't. Because, you know, you can say, well, I'm on AWS, I don't have to think about security.

Well, that's bullshit. Like, there's an awful lot of things you better think about if you're on AWS. But, you know, at that beginning of the companies, they're not really ready to deal with that stuff. And it's generally the way I think of it. I'd love to hear your take.

Is we're going through a process of de-risking a company, with the biggest risk being that they don't have a market-viable product. We're going to spend as much time as we can validating our assumptions about the product, and that security risk, you know, it's a good-sized risk, but it's much smaller than the risk of the company failing to survive. That's right. The security risk becomes much more of an issue as the company starts to look like you actually have something that's going to work. Interestingly, many companies, and I think it's true across the whole industry, spend an enormous amount of their time, you know, one step behind the curve, right?

So you decide security is a priority, you start doing what you need to do, and you're sort of fighting a battle on 2 fronts. One front is just catch up from the stuff you haven't done yet as your business is growing really quickly, and the other front is deal with all the new, you know, threats and potential for threats that are coming in that are new to the way people are thinking about it. And, you know, as companies become critical pieces of infrastructure, especially in our current world where your infrastructure can be, what your product as a company can be critical infrastructure for a whole bunch of other companies, all of that stuff starts to get built into the product. And I would say the best companies in our world are the ones that have integrated their security practices directly into their product development path and then have a separate layer of security for sort of the organizational security dynamics. Yeah.

And, you know, one of the contrasts, the tension between we're de-risking product and organizational value and then having to— and then building in security later is hard, right? And I just wonder if you guys— do you guys give any thought to that? That yes, it's lower risk now, but it's going to be a whole lot more work to rework later on to build things in, or is that just— it just doesn't make sense because the risk is— No, I think it's a reasonable thing to be worried about all the time. It's a continuous challenge of constrained resources, right? It doesn't matter how well-funded a company is, it's still got constraints.

And so you're constantly making these trade-offs as you're deciding where you're going to allocate dollars and time as you're building up your business. The constraint allocation model is never perfect. Right, so you're always out of balance, and it doesn't matter whether you're out of balance on product or sales or marketing or security or operations or finance. Like, you're always trying to, you know, trying to define what the next level is and get things in balance at that next level as best you can. By the time you get everything that's looking like it's approximately in balance, something's way out of balance again.

Yeah. And so, you know, the company that never pays any attention to anything security-related is one that's going to have a lot of pain. The one that spends all their time paying attention to that is not going to get a product that's viable into the market. Yeah. So it's, it's kind of a balance.

Yeah. Um, last comment on it is there's just so many hygienic things you can do around security, um, that are, are easy to implement, uh, relatively low cost, but modest friction. And, you know, I bitch about it all the time. Like, every time I have to open up Google Authenticator, I'm annoyed. But it's actually good, right?

Every time I have to open up my password manager to get a password, it's kind of like, ugh, again, I'm like on a site that's not automatically integrated with my password manager, you know. But in fact, I, you know, I— when I step back from it, I'm like, yeah, actually it's a good thing. Those, those are the things that are high value, low, low cost. Yeah, they're, you know, they're incrementally more annoying for me. It'd be a lot better if like, you know, my computer recognized my fingerprint printer.

If you had a single sign-on product. If I had a single sign-on product. Totally, there were some seamlessly across everything. Yeah, of course, that'd be awesome. So, let me change topics on you.

So, what do you consider success in an investment? How do you walk away and say, yes, that was, that was a good one? Well, success in, in our world as a venture capitalist is defined really, really simply. Our investors give us a box of money, and our job is to give them back a bigger box full of more money. On the whole fund?

On the whole fund. That's it. And as long as we do that in a way that's legal, they don't really care how we spend our time to do that because that's defined as success. So the quantitative definition of success is quite easy. You know, we have a range of— this is for the fund— we have a range of outcomes for companies ranging from we lose all our investments, so we get zero.

At the other end of the spectrum, you know, we've had— been fortunate to have a number of companies in our, in our, uh, experience be worth 100 times their money or more. 100 times? Wow. And, you know, if you have a company that, that, uh, gets bought, uh, 2 years in for 3 times your money, you know, is that a disappointment or is that a success? Our view is it's a success because it's a cumulative add, right?

We tend to have a pretty long-term view in terms of the companies. Um, you know, the Harmonix example is one, although we have had one big exit, you know, 20-something years later. We have other companies that we've been investors in for, you know, 10, 15. I think the longest board I've been serving on continuously is 17 years. So it's not that we have to be out of an investment in 2 or 3 years.

In fact, you know, typically 5 to 7, sometimes pushing 10 years, is much more of a normative zone.

And I think from, again, mathematical perspective, you know, it's a multiple of return on our cash. From a non-financial perspective, I feel like even if you win— whether you win or lose from a financial return, if you have experienced something that's meaningful, if you have worked hard together, if you've, you know, generated jobs, if you've done good things for customers, even if in the end it's not a financial success, that people comported themselves in a way that was, you know, positive, and you grew and you learned with the ups and downs of creating a company. I view that as success. Yeah. So I'm separating like the definition of success as an entrepreneur and success of a long arc of this from raw financial success.

Yeah. And for me, some of my favorite people to work with, uh, are people that, you know, we had a success, a failure, and now we're trying get, right? Because you have that deep relationship, you know each other, you don't have to figure out each other again for the first time. And it's part of the community we've tried to create around Techstars, around Foundry Group, which is, you know, sure, there are people who behave in ways that are disappointing. I'm sure we behave in ways that are disappointing to entrepreneurs.

So it's not that there's this utopian view of it, but if you own your mistakes, if you learn from your mistakes, if you, you know, acknowledge your weaknesses and try to grow through them, you know, you can build a very powerful long-term relationship that transcends an individual company independent of the financial outcome of that company. Now what you're saying is a little more touchy-feely than I expect to hear from a VC generally, right? Is that typical? Are you speaking in a typical language, or is that kind of a different— I'm speaking from the perspective of Foundry Group. Yeah, and that's great.

And I'd say, you know, I'd say that value system is, is embedded within Techstars as well. Um, I, I'll let the world judge whether that's a normative, uh, value system or not, and I'll also let the world judge whether or not we're consistent with that value system. I mean, we screw up and we make mistakes, and I'm sure there are plenty of people that felt like in the moment where we could have been touchy-feely, we weren't. Um, sure. But I think that our value system is one that, you know, we're playing a very long game, and we know that in playing a very long game, you have lots of ups and downs, and, you know, trust and respect and commitment is really key.

And introspection is incredibly valuable. Like, the VC who never makes a mistake is an idiot because she makes mistakes a lot. The entrepreneur who never makes mistakes is in total denial. Denial because every entrepreneur I've ever met makes lots of mistakes. The company that was just from beginning to end a success, complete bullshit.

There's this crazy ups and downs along the way. Yeah. So, you know, how, how you approach it, um, uh, you know, when they stick you in the ground at the end of the journey, uh, you know, well, people may not care anyway at the end of the journey what happens, but, uh, on that journey, I think the way that you I should say precisely, the way that we think you can build the maximum value, the way that we can return a much bigger box full of more money, is to behave in as internally consistent a way we can with a long-term view. That's great. I do want to ask you one more kind of somewhat technical-ish question about the finances.

I've heard other folks talk about with a fund, you know, say they have 10 companies, they expect 6 to fail, 3 to come back, 2 to 5x and one to come back 20x. Do you think that way, or do you just have that kind of a distribution in your models? It's not, it's not for a forward-looking distribution. We do look at it going backward. Sure.

And mostly to learn a lot. On our early-stage funds, we've, we've now raised a fund in 2007, '10, '13, and '16. So we raised 4 of them. They're all the same size, $225 $25 million. Each of them has about 30 investments in it.

And when we look at our 2007 fund, um, uh, 75% of the investments were not successful. Okay. Uh, how do you define successful? More than 1 times their money. Okay.

8 of the companies will end up being meaningful successes. Yeah. And that particular fund, the 2007 fund, is, I don't know the absolute rankings, but one of the most successful funds of 2007. Okay. In terms of performance.

That's with 75% not making anything meaningful. Yeah. One of the things that we did realize, oh, by the way, that's, sorry, not number of companies, that's the dollar, 75% of the capital. Okay.

In the 2010 fund, we actually have same kind of scale, but now we're at a place where less than 50% of the capital will be— have been wasted. And— or wasted is the wrong word, but turned into zero. And part of that is because we were able to identify and cut off things that weren't working earlier and allocate more of that money to the companies that were working. But we also have, in that fund, we'll probably have in the end 15 of the 30 companies will have been meaningfully successful. So a higher ratio of success.

When we make an investment, every single company we ever invest in, we think is going to be a success. We wouldn't invest if we didn't think it would be a meaningful success. So it's about how you calibrate from that point forward. I think it's very easy and cliché-ish for VC funds to sort of use a mathematical, you know, one, the thing that you see going around is a power law, right? One company is gonna generate all the returns and it's a power law very, very quickly.

You know, the number 2 company is an order of magnitude less powerful. The next is an order of magnitude. By the time you get to the 4th or 5th company in the portfolio, it doesn't matter. That's not really been our experience. And our experience is that you can have multiple companies in a fund that have really meaningful impact on the fund performance.

I do have a couple more questions. I know we don't have a lot more time. Sure, go for it. What is— there's— I'm sure there's somebody listening right here who really wants Foundry Group to fund them or Techstars to take them in. If they get the chance to talk to you, to pitch to you, what should they say?

How should they come prepared? Well, 2 things. I'm easy to reach, so you don't have to come pitch to me, and that's probably not gonna be the first time we interact. So send me an email, bradadfeld.com, and I'm happy to go back and forth. Yeah.

Start with the punchline is kind of my advice always. Right. I, you know, I live a life of being during the day overscheduled. I try to do my own creative work, uh, you know, in the morning and at the end of the day, you know. But throughout the day— and, you know, that's mostly writing— throughout the day, uh, it's meeting, meeting, meeting, meeting.

And so the more we can get to the point, the more we can focus on what's actually on your mind, the better. Yeah. Again, whether in an email or face-to-face.

Do your homework. Know what we like. You don't have to know what I like socially. I mean, lots of people walk in the door and say, I know you like to run marathons. I did a marathon.

I mean, that's human connection. That's fine. There's nothing wrong with that. But know our investments. Know what we've invested in.

Know what our past is. 20, 30 years ago, it was really hard to get that kind of information on people. Today, it's really easy. Read the last 4 or 5 blog posts that I'd written just so you know what's current in my mind. Look at the last couple of investments that we've talked about.

You don't have to come in here with, you know, sort of a shtick where it feels like you're playing back all these things to me so that I know that you've done this, but use it to sort of calibrate your approach. And then the last is, Don't be secretive.

You know, it's— I think security is also a particularly interesting industry because, you know, people have like, well, I've sort of figured out how to do this thing that nobody else knows how to do, so I don't want to tell anybody how to do it in case somebody steals it from me. Like sort of the natural paranoia that then gets amplified by the fact that you're in an industry that has paranoid elements anyway. Come in pretty clearly with what you're you're willing to say. Don't tell me anything you're uncomfortable talking about, but lead with real substance. Don't, don't sort of ease into the substance.

Start with the punchline, right? Start with the punchline. Yeah. Okay. Why Boulder?

Why you guys in Boulder? When I turned 28, I sold my first company. And again, Amy, my wife, was from Alaska. She grew up in Fairbanks and I grew up in Dallas, and we both went to school in Boston. I started a company in Boston.

At 28, I told Amy, by the time I'm 30, we'll be out of Boston because it wasn't home. We didn't have any idea where we'd go. And we traveled a lot and we knew lots of places in the US. And 6 months before— I'm sorry, 2 months before I turned 30, she told me that she was moving to Boulder and I could come with her. We were married.

I knew one person in Boulder, so we just moved out here. We rented a place in Pine Brook Hills. We actually flew out one weekend, rented a place in Pine Brook Hills, flew back to Boston, you know, ordered a moving truck, you know, reserved a moving truck, and then, you know, shipped all our shit out here. And, and then we got in our car 2 weeks later and drove out, and our friends were like, where the fuck did they go? Like, I mean, it wasn't like everybody been hearing us bitch about Boston for a long time.

We just can't. And our view was, if we don't like it, we'll just try someplace else. But we'd been to Boulder, and, you know, we both like Colorado a lot for for various reasons. And, uh, and that was 21 years ago. I mean, 6 months in, we were like, this is home, we love it here.

But I didn't come here originally to work. I came here based around something I tell people over and over again, is find the place you want to live and then build your life around that place. Find the person you want to live with or be with and build your life around that person. Yeah, don't build your life around a job. I think so many people get sort of stuck in this building their life around a job and where that job takes them.

And, you know, or this sort of view of, well, if I want to be successful, I have to look like that over there. Do that, you know, come back to the phrase critical thinking, right? Do your own work, do your own, you know, radical inquiry. Look at yourself and decide what you like. And if you don't know what you like— most of us don't when we're in our mid-20s— like, use that time to explore what it is that you like so that— I mean, I'm 51 now, and I'll tell you that the last 21 years in Boulder have been incredible.

Yeah. And because I found the place I wanted to live. And, you know, is everything about Boulder awesome? No. Is everything about my life awesome?

No. You know, does everything work? No. That's okay, right? That's, that's the nature of how life works.

Am I in an environment that I want to be in? Absolutely. Am I, am I with a partner who I want to be with for the rest of my life? Yes, absolutely. Absolutely, like, that's a great— Yeah, that's a great story.

And really, it seems to me like, you know, you took the city that you're moving to and you brought in, you know, tech investment. You brought in acceleration, right? That's from you choosing to live here. And I assume, you know, found partners along the way to help accelerate that. But would we have a Foundry Group and a Techstars here in Boulder if Brad Feld's wife didn't say, let's move here, and it was in '93?

Well, '95, but I don't know. There's lots of parallel universes, right?

I hope I'm humble enough to believe that while I've had impact on Boulder, I'm not the reason something exists. And I'd much rather focus on having impact and continuing, continuing to have impact than get sort of stuck in the other side of that, which is its validation for, you know, for me or for something else. Um, I, you know, I describe Techstars as being, you know, the, the thing that makes me most proud of all the business things I've been involved in. Um, I think about sort of the ancillary to that is just a number of people, especially in Boulder and Denver now, who have real leaders in the startup communities of Boulder and Denver. And, you know, the amount of time that I spend as a leader specifically in Boulder these days of the startup community is much less than I did 10 years ago.

And it's not because I'm not interested, it's because there's so many more people who are providing leadership, right? And 10 years ago, I wasn't the only leader. 20 years ago, I wasn't the only leader, right? But the, the thing that is so nice to reflect on is to see that blossom rather than— and blossom in sort of this messy, chaotic network, rather than be king at the top of the hill. I have, you know, I never have had and I have no interest in the king at the top of the hill model.

My interest is in this extremely networked, very broadly distributed model. What I love to kind of point out here is this opportunity for others who can see the example of what you did and say, hey, I'm not going to go fit into a mold of you know, I have to go to Silicon Valley to be part of a VC community. Just take your passion and be where you want to be and just go build it. And don't be afraid of failure, as that's just the first step to getting there. That's— anyway, I hope that's what people see when they see what you did.

I hope so too. I think it's well said. Any final thoughts for the security community here in town? Keep doing great shit and keep keeping the bad guys out. All right, Brad, appreciate your time.

Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes