All episodes

Joe Bonnell

Apple Podcasts Spotify SoundCloud

In this episode:

Alex sits down with Joe Bonnell, CEO and Founder at Alchemy Security. News from Bad Axe Throwing, Amazon, root9B, Optiv, ManagedMethods, and Webroot.

Axes hurdling toward Denver

Not sure where to take your sweetie on your next hot date? Canadian axe-throwing may be just the thing. This week we discovered that a lot of Coloradans don't bother to go to work, Amazon robots may be coming, a big time General joins the advisory board for root9B, Optiv and ManagedMethods are recognized as leaders, and IT has moved to the Cloud, why hasn't security?

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Alex interviewed Joe Bonnell (JoBo to friends) to discuss building Alchemy Security here in town, scaring legislators, and what makes Denver's security scene great.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next Week:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13692 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 19 for the week of June 12th, 2017. This is the newscast, and I am Robb Reck.

And I am Alex Wood. And we are here to just kind of talk to you what's going on this next couple of weeks here in Denver. Alex, how's your week been? You know, it's been pretty good. It's first week of summer, so that's always nice.

First foot— well, first full week. My wife works for the school, so she is now off and everyone off is off in my family. How about you, Robb? Well, it's been pretty good. We had our— my wife and I celebrated our 15th anniversary last night.

It wasn't our anniversary day, but that was when we got the date night. And when you have kids, that's, that's what counts in terms of the anniversary. That's true. So that was fun. Did you do anything exciting?

We went out to dinner, went to a special dessert place downtown, you know, just hung around downtown a little bit, walked around, saw some freaks down there. It was good times. Nice. Yeah, sounds like fun. All right.

Well, should we dive into the news for the week? Let's do it. First thing on the, on the agenda was just to give an FYI that the CISSP training that the Colorado Springs chapter of ISSA is doing, the registration is now open. Yeah, I think that that's a great program that they have. They've built up the training down there for CISSP.

This isn't just a regurgitation of a book or something like that. It's a really good training. So I'd recommend that for folks. And the first class, it's actually, what, 5 weeks every other week? Right, exactly.

And it starts the last week of July. So go get signed up now before all the spots are taken. So the first news story that we have for this week is It's not security related, but I think it's still pretty interesting. Um, there is a, a Canadian chain that is opening a location in Colorado and, uh, it's sort of like, um, you know, throwing darts or something like that, but it's, uh, it's a chain that you go and you throw axes. So if you wanna go and, and do target practice throwing axes, then, then you've got a place to go now.

So it's a little bit like a, a gun range. Yeah. Except instead of shooting bullets, you're throwing an axe down the range, right? Yeah. So unfortunately, they weren't open in time for our anniversary date.

I think this would have been perfect. But this is pretty neat. It's called Bad Axe Throwing, I believe. Bad Axe Throwing. And it's opening August 11th in North Denver.

Yeah. So it's like 73rd and Broadway-ish. They also noted in the article that once they are open, they're going to be bringing in the professional axe throwing league. So if Uh, if you want to have continual axe throwing, you can, you know, go in there and, and join a team and, and try and become a professional axe thrower. So yeah, if you walk in there and you say, I finally found my, my calling, uh, they're gonna enable you to make this, make this for real.

So this is fun, you know, this is kind of like this escape room, something it's fun to do with your team, uh, something kind of a unique experience to go get to be a part of. I'm looking forward to giving it a try. Yeah, me too. Should be fun. All right.

Colorado is ranked the number 1 state for work from home. Do you see that? I did. So we are slightly less than number 1. We are tied with Vermont.

So we're tied for number 1. Tied with Vermont, which, you know, they're much smaller. So in terms of, you know, per capita, we're number 1. How about that? I just made that up.

But yeah, that doesn't surprise me. You know, part of the reason people like to come to Colorado is quality of life. So I think working from home goes along with that. Amazon, now interesting here, Amazon has kind of given away some metadata that leads us to believe that they're gonna be bringing in robots to help with their fulfillment in the Colorado region. Well, who doesn't like robots?

I don't know anyone. They're pretty much popular with everyone, especially the Japanese.

There's the whole, Alex is looking at me like I'm crazy. There's the whole robot sex toy Japanese thing going on over there. Okay. Okay.

And I think, you know, I was gonna say everybody likes robots until, you know, they take over the world and kill everybody. But, you know, fair enough. It only takes once. So BKD, which is an auditing firm, acquired the Denver internal audit group Paragon Consulting. And Rick's over there, right?

Yeah. So Rick Lucy, who is now going to be the ISACA chapter president, I believe worked for Paragon or works for Paragon right now. So it now works for whoever. For BKD. Yep.

So, you know, big news in the audit community here in town and something worth talking about. On the security side, we've talked about Route 9B several times. They have some big news. A big name has actually joined their advisory board. Yeah.

So General Hayden is now on the advisory board for Route 9B. It's pretty exciting to get that level of person on your advisory board. Yeah. And he was helping out cybersecurity czar under Obama or under Bush? Ooh, now you're testing me on that one.

Tough facts. Definitely, you know, one of the lead cybersecurity strategists for the entire country. And of course, Route 9B, who has some really deep roots in the defense contracting world, has got him on their board, which I'm sure is going to help them not only with their category of offerings, but probably more so with the relationships they need to expand their business. Seems like a positive relationship for everyone. So next, Optiv.

They have been ranked as the top pure-play security company on the CRN SP 500. And we all track the CRN SP 500. I have an app on my phone. It you know it beeps at me all the time telling me about the the SP 500. Yeah, I do keep the the list printed out next to the bed in my room, and Kristen and I look at that on a regular basis.

But but seriously, it what it looks like you know Alex and I did a little bit of research on this before the show. It looks like this is kind of the the channel group puts this together, and this is a list of the channel partners who are really influence makers and selling a lot of product. Yeah, and so they were— Optiv was, I think, what, number 27 overall? Yep. Which is still, I think, a pretty good number, but the number 1 in terms of security pure play.

The rest of these are network or data center or cloud providers. Yeah, and we looked through the list, and like number 1 was IBM, and Accenture is number 2. So it's all these big names you've heard of at the top of the list. It's nice to see Optiv being included there. Just shows that they are big.

So Managed Methods, we've talked about them before. They are a Boulder-based CASB company, and they won gold in the Network Products Guide review. So this one, we also looked at this list, and this was a little bit less impressive a list. We— there was a lot of names, but it's a gold, Robb. They got first place.

Second place was a company that doesn't do CASB. It's hard to tell exactly what you know, how you get on this list, if it's pay-to-play. Um, certainly it's nice to see a local company get recognized. Uh, they, you know, we didn't see them compared directly with some of the big competitors in that space. Um, but once again, like we said, they, this is kind of a little bit of share of voice that Managed Methods is getting, and it's not a bad thing.

Exactly. So Webroot, we talked about this about 3 months ago, and we could follow up now. Webroot has announced that they have now reached 13 consecutive quarters with double-digit growth. That's awesome. That is one more quarter than the last time we talked about it when it was 12 quarters of double-digit consecutive growth.

Here's hoping that in 3 months from now, we get to talk about quarter 14. Yep. In the press release for this, they note a couple new products that they have, so if you want to see those, go take a look at the link on the website. The last news for the week, it's actually a blog post by Managed Methods, and the topic is, IT has moved to the cloud. Why hasn't security?

Yeah, and I think it's, uh, it's definitely a good point. Being a security practitioner, I think we often— people often think no first. And, you know, I think a lot of that's uncertainty. We don't know the risk profile of, uh, something new that's coming along, and people just want to put on the brakes. Uh, but with the agility and scale and potentially cost savings that you can do from the cloud, uh, you know, most IT groups are either there or, you know, on their way there.

So definitely security needs to get on board. And generally in security, we let the IT group, you know, guide us into what technology direction we're going to be going. And this is an area where if your IT group hasn't yet guided you toward the cloud, you should get there before them. You have the opportunity to learn the new model for security in the cloud. It's, it's not just simply, you know, moving your controls into a different environment.

Take the time to really learn and understand how this is going to work for your company and your security strategy. And I think, you know, one of Managed Method's big points here is that, you know, they are a cloud access security broker and they can provide some of those security controls in a more cloud-native way as opposed to you trying to bolt on the, the traditional security controls that you might have into the cloud environment. Absolutely. All right, let's go ahead and talk about the events for the next 2 weeks. And you can go to our calendar on the website colorado-security.com, look at the events, and you can see not only the next couple weeks worth of events but also the next few months worth of events.

I think we're actually updated through about November right now, which is, which is how far most of these groups have gone. Yeah, so this week, and we talked about it last week, the SANS Rocky Mountain event is here in town. So that's a week-long training class. They have several different SANS classes that they're offering. I'm sure if you wanted to take one, you can still get signed up.

And although I believe that they are actually starting first thing in the morning tomorrow, so If you listen to this on Sunday night, you better get out there and get signed up fast. If you're not going to be able to make the full week worth of events, there are a couple of evening events going on alongside the conference. Go ahead and take a look at our event calendar to see the details on those. We're not going to go through all those right now, but you should be able to go to those even if you're not attending the event overall. Exactly.

And I believe those are on Tuesday and Wednesday evening. The Cloud Security Alliance has their June meeting on Tuesday, evening, and that's going to be at the DaVita campus downtown. ISSA Denver has their June meetings on the 13th and the 14th. So on the 13th is our downtown meeting, and, uh, the 13th for dinner is the downtown meeting. It's actually at DaVita as well, different, different room.

Uh, the 13th in Boulder will be the lunch meeting. Yep. And then the, the 14th, that's the Wednesday at lunch. That's the biggest meeting at the DTC campus. And at all 3 of these meetings, we're going to actually have the election where James Johnson will be, will be brought in as the president of the chapter.

And we'll be recognizing a couple of the previous people who've been on the board and kind of talking about what we've accomplished in the last couple of years. And Robb gets to change to the title of past president, and I get to change the title of nothing. I think you don't lose past president, do you? I suppose I still have that. Um, on the— also on the 14th, uh, ISACA is having their social event at, uh, Topgolf.

So you do need to be a member to participate in that. So if you like, uh, like hitting golf balls and you like auditing, you should go check that out. Uh, if you haven't been to Topgolf yet, take it— you should try and go there if you can. It's a really fun experience. You're not held accountable for your poor golf skills, right?

You just— and in fact, not being able to hit the ball far doesn't necessarily hurt you here. Also starting on the 14th is the Colorado Springs ISSA monthly meetings. There's the dinner on the 14th and then lunch on the 15th. Um, go ahead. On the 15th, uh, at SecureSet, they're doing their, uh, expert series.

Uh, Michael, uh, Boucher, Boucher, uh, Boucher, one of those probably is a Connect correct pronunciation. So that's it at SecureSet on the 15th. Also on the 15th, Colorado Cyber is doing their cybersecurity insurance event. On the 16th, ISC2 is doing their Secure Denver, which is their annual event in town. It's a full-day event, right?

I believe it is a full day. I think more like 9 to 3 or something like that. But yeah, better part of a day. On Saturday, SecureSet, which is that academy that does the boot camp for cybersecurity, they're doing an open house at their new location on Blake Street downtown. Nice.

Uh, on the 20th of June, Optiv has their Enterprise Security Summit here in Denver. Uh, this is something that, uh, that they do every year. And, uh, it was originally, I think, a Fishnet piece, and they've carried that through into the Optiv company. On the 22nd, ISSA Denver has their healthcare SIG. So if you're either a part of, of security at a healthcare organization or you're interested in getting to know more about it, that's a good opportunity.

That's going to be at Dave Buster's on the 22nd. On the 23rd, SecureSet is having a capture the flag event. We've talked about the capture the flag events that they have in the past. I'm assuming that this is at their new Blake Street location, but you might want to check the calendar for that. Yeah.

And And just as a reminder what they do, the first hour is an intro to capture the flag, so you don't have to be experienced, you don't have to be good at it. They're going to walk you through how you can participate, and that's 5 to 6. And then starting at 6 o'clock is the real full capture the flag where you'll be able to compete. Uh, and then last on the list, uh, ISSA Colorado Springs on the 24th, they are having a mini seminar So they do these periodically. I'm not sure that we have a topic yet for that mini seminar, but there's no topic.

It's about 4 hours of CPEs though, and you'll get to learn about some various security stuff. Hopefully next week we'll have more information about the topic. Awesome. And so that is the events for the week. Let's dive into jobs.

We have 2 different jobs at Digital Globe. Digital Globe, our friend Chris Martinez is the CISO over there. They're hiring a senior security— excuse me, senior cybersecurity architect. And a SOC engineering lead. So a couple of leadership roles there, high-level roles at DigitalGlobe.

Nice. Uh, so the state of Colorado has a position that is open. Uh, we heard from Debbi Blyth on this one, and, uh, to sort of loosely quote Debbie, she said this job is probably the coolest job we have here at OIT, Office of Information Technology and Security. This person will be a cyber investigator and a cyber hunter. So it sounds like a really cool opportunity to work for the state.

Yeah. And if you're interested in really having a chance to let loose and look through an environment and figure out what's going on in a very large organization and help, and help the public good at the same time, I hope you guys take a look at this for sure. Four Winds Interactive is hiring a senior information security analyst. So I looked at Four Winds. I don't know if you're familiar with them, Robb, but they make those the digital signage boards that are often like in the lobbies of hotels and things like that.

So that might be interesting to do security around those. Western Union is hiring an IT project manager focusing on InfoSec. Optiv is hiring a senior security consultant in the SIEM practice, specifically around LogRhythm. So if you are an expert in LogRhythm and want to do some consulting, there's a spot for you at Optiv. That's it.

And that's it for the posted positions. I do have one that's not posted yet that I want to get out there early. I, uh, you know, my day job, I am the CISO for Ping Identity. I am looking to hire a new GRC analyst who's going to help us with compliance, help us with our SOC 2 report on an annual basis, and help us get ISO 27001 and FedRAMP controls implemented throughout the organization. Uh, I'm not sure that you'd want to work for Robb, but, uh, if you do like that stuff, then, uh, maybe it would be a good job anyway.

Uh, and so send a note to the, you know, info@pingidentity.com. Colorado-security.com and send me, send me your information. I'll get connected with you and help you get in the process if you're interested. Awesome. So that's all of the information we have for this week.

We do have our feature interview coming up with Joe Bonnell of Alchemy Security. I had a great conversation with Joe, talked about a lot of cool stuff, including his visit to the White House. So that should be fun. So, you know, Joe Bo, as we call him, he's, uh, he's the reason I think of Besides Denver existing here in Denver, we you know he he started it about seven years ago, 2010, 2011, something like that. Did a great job getting that started.

He's handed that off now. And I also know Joe is a huge fan of music, and if anyone ever is around him and they want to they want to get the inside track, you know talk to him about music production and concerts, and that's something he's he's really into. Yeah, exactly. So listen to that coming up and have a great week. All right, see you guys.

Hi, this is Christine Vanderpool. Deputy sees over Kaiser Permanente. Welcome to Colorado Equals Security, for Colorado security professionals by security professionals.

This is Alex Wood with the Colorado Equals Security podcast, and I'm here with Joe Bunnell, CEO for Alchemy Security. Hey Joe, how's it going? Good Alex, how you doing today? I'm doing well. I'm excited for our conversation today.

You know, we go, we go back a few years working at IBM together a number of years ago. I wanted to see if you could real quick give us a history of, you know, how you started in security, your path to where you are today, and, you know, sort of interesting things that happened along the way. All right, well, my first real kind of significant IT job was with a consulting firm that worked with IBM, and I was doing some Level 2 support on PL/1 technology. It was so hard. Don't date yourself, Joe.

It was terrible, but it was a good start. It was a break into the field, right, in an interesting way. And, you know, but at the time, this was to support their publication distribution out of all of IBM. Mechanicsburg, and they had these— and all the computers up there, we weren't responsible for any of this, but all the computers up there had— they were still running on punch cards. Ooh.

And this is like '89. Wow. So— no, I'm sorry, '99. '99. So there were parts of IBM that were still very archaic, and somehow I ended up in the archaic project to get my start, and then I ended up moving over to IBM and supporting the server team, where I ultimately ended up being responsible for herding kind of all the system administrators to make sure that all the servers that they were managing were to the IBM security standard of the day, which was great.

It was a really good way to get a solid foundation on what, you know, system hardening is about, what good governance actually kind of looks like, right? So it was It was a good way to kind of break in the security field from that standpoint. And then I was walking down one of the halls one day to the cafeteria, and I don't know if you maybe even saw this, but there was this sign of this old guy with a beard, and it said, I am a hacker at IBM Global Services. And I was like, holy crap, that's a job, right? So I immediately walked right back to my cubicle and I started searching, and sure enough, there were some ethical hacking positions at the campus up in Niwot.

So I went and interviewed, and having that background, you know, it was just kind of a natural fit for me to go that direction anyway. And then they pulled me into a project that was basically kind of to just test my wings a little bit, and it turns out I'm really good at breaking things. So that's how it got started. You know, I think it's funny that, uh, my experience was almost exactly the same. You know, I mean, I came into IBM with a, you know, sort of an entry-level job.

Um, I didn't see the sign, but there was a, uh, a guy that I was working with at the time, um, and he apparently saw the sign and applied and got a job over there. I don't know if you ever worked with, uh, with Jason North. Yeah, okay. Um, but, uh, but yeah, he— we were working together and he went over and he's like— I'm like, are you going to do? He's like, oh yeah, I'm going to be a hacker.

I'm like, what? That, that's a job? You get paid for that? You can really do that? Yeah.

Um, and so that's, you know, how I ended up over in the security group at IBM too. Um, so you did that for a while? Yeah, ended up running the FCLAC. Well, at the time, um, the group that I hired into was actually called the S&I team. So you might remember back in the early thinking days of IBM, it was Well, we want to make sure that the Class A network that's fully routable from the internet is protected from this network segment where they would deploy shared resources all in the same infrastructure.

Secure network infrastructure. Yes. Yeah, so when I walked in the door, their primary concern was that, you know, any traffic from that environment couldn't get back to the 9-dot, right? And I'm like, well, aren't you guys kind of concerned about Customer A's data being visible by customer B? I'm like, oh yeah, that's probably a pretty good point.

So for us, that was really kind of the start of what we'd now describe as kind of application hacking or kind of black box testing. We weren't given a lot. We were just a part of IBM. We wanted to deploy something in the environment, and then we would be responsible for banging on it with full user credentials and then, you know, no credentials at all and see what we could get done. And so it was a really interesting dynamic time there.

It was a great, just an amazing crew that, you know, worked there at the time that, you know, I still look back with, you know, great fondness and some of the things that we were able to accomplish. And I guess kind of the feather of the cat on my cap at the, uh, in that job was we ended up, uh, being requested to, you know, test Tivoli as a framework.

And, you know, bad news, lots of work there. They were like, well, what do you know? What's the process? So I explained it to them. They're like, okay, well, what do we need to do to get it certified?

I'm like, well, you need to stand it up, and then we're gonna, you know, beat on it for a while. Okay, which parts do we need to stand up? Which parts you want to certify? All of it. Well, there's your answer.

And we ended up finding race conditions. We ended up— I mean, just really, uh, you might remember Josh Lackey. He, you know, reverse engineered the encryption, and it took him as long to convince himself he'd done it versus actually figuring it out, right? And, uh, that ended up being kind of good for lots of people's careers because it was— even though it got to be contentious with a newly acquired you know, Tivoli, uh, partnership, uh, it, uh, it, it was a big win for everybody on the team, and it really kind of, you know, helped to kind of get everybody to understand, you know, why this was so important. Because within the hack, we were able to prove that from Customer A's network, we could manage Customer B's infrastructure, which was the mission.

And so it was mission accomplished. And then they had to work through, you know, obviously a number of issues. And then, uh, so that was more or less kind of the kind of winding down my tenure at IBM. And then I got invited to go help build a security practice in Avaya, which is voice communications. And, you know, at the time IBM was riding really high, and, you know, Avaya stock I think was like at about $40 or something like that.

And, you know, all my friends and family were suggesting why I'm— why— or asking why am I jumping out of this perfectly good airplane, right? And it was a good question because, I mean, I really had that job wired, you know. I had lots of legs to go there at IBM, but I realized that this was a really good opportunity to help kind of an early-stage security practice get off the ground. And what they thought they wanted to do at the time was go build kind of, uh, you know, AT&T's version of their network security team. I forget the name at the moment, but they— INS is what it was.

So they thought they wanted to build an INS within Avaya, and it turns out that they didn't have any relationships with any of the networking people. So it was a, it was a practice that wasn't going to go anywhere very fast kind of heading that route. So I ended up kind of redirecting the focus towards towards, uh, you know, what are these— you know, we started asking questions like, what do these voice technologies do? What goes in these things? We realize that these interactive voice response systems and these nice recording systems contain all the kind of crown jewels that we think about when it comes to sensitive data, and they weren't really being addressed by the security community.

You know, it just didn't happen, right? It's like, oh, that's voice, and they just kind of put the blinders on and walk by the room. Right, but I'm sure this was either before or early days of PCI, so, you know, I'm sure you had tons and tons of credit card numbers that were getting recorded, and, you know, again, probably before HIPAA, so you had, you know, all kinds of personal health information being recorded and all this stuff, you know, potentially lots of bad news if people got in there. Yeah, and the security was like, you know, default user credentials with running PC Anywhere. There was available from, you know, just about anybody that could find the modem.

So, uh, it learned a lot about voice technologies, did that for about, I don't know, 18 months, 2 years, something like that. And then I got invited to go to CyberTrust that was in the process of building up their professional services group with Chris Calvert. So Chris gave me a call, I was like, yeah, sounds like fun. So jumped over to CyberTrust and worked there for a couple years. And, um, politically things got weird at one point, and, uh, there was kind of this desire for PS leadership at the time to kind of, you know, I guess he felt like he wasn't quite, you know, getting the, um, you know, kind of attention accolades that maybe he should have.

And I don't know what exactly happened, but there seemed to be some bad blood. And so there was this desire to just kind of peel off, you know, all the critical talent from the PS team to go start a new thing. And that didn't really resonate with me so well, so I opted to stay even though I was offered the opportunity to go and ended up continuing to have a good relationship with what later became Verizon and quit my job essentially, and hung out my own shingle and kind of went on my way. So that was the start of Alchemy? Yep.

So when did you guys start the company? January 7th, 2007. And what was your— what was your idea and your mission thinking about starting the company at that point? Well, I mean, as I mentioned, there was other people kind of starting— talking about starting their own, forming their own startups, and the and they did, I just kind of realized that, you know, if I was going to continue to do this, it really made sense to just give it a go on my own. And so the initial objective really was to build a kind of, you know, security consulting professional services practice.

And it started really just with a party of one, right? And I went and got my QSA certificates, or whatever they're calling it these days, and spent the better part of 18 months just doing that job for a while. And so fascinating, right? You know, pen testing, running ethical hacking teams, you know, there's lots of things that are interesting about that for a while, right? But after you've had your consultant break in the same system, you know, next year, similar findings, you know, it really kind of gets to be somewhat demoralizing, you know, along the way, right?

And so putting the QSA hat on for a while was just a good opportunity to see again the field from a completely different standpoint, right? So, you know, we weren't just banging into systems, we weren't— I wasn't running single sign-on, projects. I was really focused on just, you know, trying to help customers understand, well, here's where you kind of fall when it comes to— with respect to the standard. The problem with that ended up being is, like everything else I've done in this field, I got really good at it. Yeah.

And, you know, ultimately your customers aren't necessarily happy with you if you're just everywhere you look, it's just, you know, explosions are going off, right? And, uh, you know, at some point people start, you know, not being pleased with, you know, you being an effective performer in your job. So, uh, but it was really instructional in all kinds of ways. I learned a lot about, you know, when you start to look at so many different companies of different sizes, you really start to get kind of an understanding scope of just how widespread and difficult and entrenched the problems really are, right? And so it was great.

I just love that time. You know, I'm not necessarily a huge fan of the standard. I'm not a basher either. But, you know, I think, you know, that really kind of— that time in particular really started to kind of shape my thinking about security in a lot of different kinds of ways. So I know you guys Um, you know, one of the big services that you provide at Alchemy is, you know, sort of managed SIEM security operations kind of work.

Um, how did you go from, you know, from doing PCI work and penetration testing to deciding that managed SIEM and managed security operations was, was the way to go? Um, it was, uh, you know, It kind of goes back to that statement about pen testing and all that, right?

One of the things we realized is like, you know, the bigger problems in security are detection, right? I can, I can run red team exercises, I'm going to win all day, right? And that can be gratifying for a while, right? But at some point you just start to get feeling a little delusional about, you know, what your purpose is in life if all you can keep doing is succeeding. And you can only tell people their baby is ugly so many times.

Sure, yeah, the same people or different people, but it's the message being the same every time gets to be kind of an exercise in frustration, right?

So what we decided to do is about this time we started to strike up a relationship with ArcSight to provide engineers for implementation work and that sort of thing. And when I really started looking at at security monitoring and SOC and SIEM, you know, to me that represented the deep end of the pool. That's the hard part, right? And I was attracted to that, of just, you know, going from this place where it was very easy to do your job and get into that repeatability of just breaking into environments to trying to identify when these activities are occurring and helping our customers respond to them. So the more we got in transport, we ended up doing all kinds of interesting things with ArcSight.

It was a really great relationship for quite some time. We ended up, um, kind of getting in the SOC building business. So we, uh, we had a consultant, uh, Peter Shawalker, who's now over at Optiv. He, he ran the engagement for us to go build, um, Canada's central bank, the Bank of Canada SOC. So he calls me up on day one, he's like, I'm down with the guns and the gold.

This is gonna be an interesting engagement, right? And it was. And he learned a lot and we learned a lot. And, and, you know, out of that time— and so ArcSight took us into all kinds of interesting places. We had engineers that ended up flying all over the world, seeing the places that I have yet to see, which was a little frustrating in some ways because I know most of them probably needed some kind of chaperoning anyway, right?

But somebody had to hold down the fort here. So, um, you know, as time moved on, we realized that there's lots of organizations that need that kind of high-end SOC function, but they're never going to have the $1.3, $1.5 million just annual spend in labor to get there. And that's when we really realized that there was this severe need for managed SIEM on-prem because there's many organizations that like the idea of their logs remaining in their environment. You know, they don't— they, they like— they want to buy the technology, but they really don't want to have to manage and do all the heavy lifting that comes with SOC. And so that's when we realized that there was a real niche there that was going to play well to all the things that I think that make up kind of the Alchemist way of thinking.

And, uh, and that's how we ended up kind of getting into the managed SIM space in a bigger way. Nice. So what do you guys— do you feel like you bring something special to that area? Um, you know, I think I've seen a lot of different providers that, you know, can, uh, you know, either manage a SIM for you or do monitoring for you. Most of the ones that I've seen, it's, it's sort of a low-cost, hey, we want to just, we want to provide you with some basic resources essentially so that you can have this thing running, right?

You know, what's your feel on that and how do you guys sort of differentiate in that area?

So there's a lot of kind of what I would characterize as not quite commodity but not far off of it, right? Security monitoring services.

The challenge is, I think, in the field— well, we've got all these different kind of levels of buyer sophistication, right? Some buyers really savvy, really sophisticated, know kind of what they want, and they know that they need us to— that they need some help getting there, right? So we— and we continue to do that. We continue to provide SOC consulting on behalf of kind of, you know, bigger companies that still kind of aspire to build their own sock, right? Um, it, it, it's been a process of time and kind of what I describe as letting the garden reveal itself is like what, what really, what does separate us?

What makes us special? How do we justify our price points, right? And what we realized over time is as we've been building and You know, we had to pivot off of ArcSight because HP just keeps shooting bullets in the product's head, right? It's sad to see, but that's exactly kind of what's happened, right? Not just for ArcSight, but, you know, sort of everything that they touch.

Yeah, that's another story. Yeah, I mean, and we had such a great relationship there, and just to kind of watch it, you know, just go south was like one of these things that was really kind of difficult for us because we were so tied to ArcSight as a product line and had lots of close relationships with people at ArcSight. And, you know, didn't want to necessarily rock the apple cart, but we had to figure out how we start to pivot to other technologies. And about that time, we ended up meeting, uh, some people with a hosting company, actually at one of the Rocky Mountain Information Security events. So they came to our booth and asked us what we did, and we started explaining.

They're like, you're just the guys we're looking for. So we ended up striking up, and that's, that's kind of started you know, our business in the hosting space of helping hosting companies provide, you know, the basket of services that they need to be competitive in the marketplace at a price point that is kind of reasonable for those economics. And the economics of the hosting market are completely different than enterprise buyers, even though they are enterprise buyers in most instances. It's just the dynamics of monthly spend end kind of skews, you know, CFO thinking, right? So, so we ended up kind of going to kind of the other end of the pool with a product called AlienVault, which we thought was gonna do real well for us.

And just the more we worked with it, the more kind of struggles we ended up having with engineers being able to keep the product up and, you know, really not being able to be as effective as practitioners as we wanted to be. I mean, simple like group by functions where analysts could group by, you know, whatever it is that they're looking at and being able to kind of discern all that. It was an extremely manual kind of heavy labor process, and which got to be a real frustration point for the team and really started kind of affecting morale in the SOC, which is not a great place to be as a services provider. Exactly. And so we ended up kind of pivoting at that point to Splunk.

Splunk. And since then, uh, you know, the things that we like about Splunk or the things that we can do with Splunk that we couldn't do with ArcSight, couldn't do with AlienVault, really aren't going to be able to do with kind of the other competing SIEM technologies out there. And that really helped us kind of define how we do managed security services monitoring for customers, being able to of take the power of what we can do with Splunk from, uh, you know, not only from just like, here's a correlation rule fire that we need to go manage, but also being able to provide proactive hunt team analysis services. And not everybody needs proactive hunt team analysis services. Everybody wants it.

They don't want to necessarily pay for the labor spend that's associated with that. But for us, it's, it's one of the differentiators that, that, that we feel is relevant And then the other thing that, that really, that we really kind of latched on to was kind of migrating our own thinking to, you know, just like this is an event that coordinated with this event and now we got to triage it, to really adopting the ATT&CK chain as a framework. And when we did that, um, a whole bunch of awesome things just started happening, and not the least of which is when we kind of— when we started work combining our, our kill chain or attack chain thinking with Splunk, we really started coming up with a methodology that would allow us to provide extremely detailed reporting to customers about what we're doing, where we're spending time in their environments. You know, one of the, one of the challenges being a managed security services provider is that, you know, the traditional relationship is really kind of a you know, not a cool place to be, right? Right.

Like, if, if you see Alchemy calling, you know, it's probably bad news. It's probably— that's why we send out an incident response kit with every new customer, right? Just to save a little bit of the whiskey for, you know, the real deal, right? And so what we realized— and, and the other thing that we observed is, you know, it's like kind of that out of sight, out of mind thing, you know. If I don't see analysts you know, doing stuff every day because they're not in my same operating environment.

Well, what are they actually doing, right? And even when we're pointing out bad things, so it's the, you know, that relationship is kind of one of like, you know, every time they call it's really not awesome news. So how do we get better about showing them the positive aspects of, of what we're actually doing, uh, from a security monitoring standpoint? So since then we've developed some really awesome reporting in all kinds of ways that we're able to share with customers just because we got the right tools and the right technology now, and that's really codified with our thinking. So we're real excited about kind of where we're going.

Yeah, that's awesome. Having done a lot of, uh, security monitoring and SIEM work myself in the past, you know, one of the things that I've always seen is that, um, you know, a lot of the major players, you know, your Uh, your LogRhythms, your QRADARS, your ArcSights. One of the reasons that people like them is because, not that they're easy, but they have, uh, they're aimed to have some stuff out of the box. You've got, you know, built-in rules and things like that. And, you know, one of the problems that I always saw with Splunk is it's awesome if you can build stuff around it, but you're going to have to have the people to build stuff around it.

So that's not for everybody. So it's, it's interesting for me to hear from you that you know, that sort of the opposite was true for you. It's, hey, well, Splunk works for us because we have the people to build stuff around it, as opposed to some of these other vendors where, you know, you might be locked into some of the stuff that they're, they're already building and doing. So that's just sort of interesting from, from my perspective, you being a service provider, it's kind of the opposite of, uh, you know, of what someone might be doing just buying it off the street. Sure.

And, you know, for us, it, it's been a real, uh, time of enablement over the past couple years in that, you know, before, like, we'd be— we would get invited out to go share our thoughts on what should go in the next-gen product, or we've had product managers fly here and, um, you know, you share all these great ideas and then you never see them go anywhere. And some of these things are like things that we really need to make the product work. Right, just fundamental, like this thing is broken, I need to fix it, to, um, um, you know, whiz-bang kind of like things that are, are certainly— that would be nice to haves, right? And when we adopted Splunk as a framework, we spent a lot of time over the past year and a half actually kind of writing our own version of what what we, what, what we need to be effective as a SOC. And if we want a new feature, if it's a priority, you know, if it saves X minutes per analyst hour and we can quantify that, that goes right to the top of the list, right?

And so we've been able to kind of take our, you know, the, uh, you know, our own, you know, uh, better control of our own destiny in terms of like what we want to my customers versus waiting for a vendor to do it, right? Yeah, that's awesome. Yeah, so pivoting a little bit here, so I— we are— we're Facebook friends, so we, you know, I see what's going on in your life, you know, fairly regularly. And I saw not too long ago a picture of you at the gate of the White House, hmm, and I thought, wow, that's pretty interesting. Um, not every day that you see that.

Um, why don't you tell me a little bit about that and, uh, what it is, how that you, you got to go to visit the White House. Sure. And, uh, you know, sort of what led up to that, what you've been doing around that area and with the government. Okay. Uh, yeah, I think I even captioned it with, uh, meanwhile in the Hell Freezes Over Department.

It's been a little bit surreal in that regard. You know, we— there was a delegation of congressional delegates put together that came to visit other cybersecurity firms here in Denver, along with some of the other high-tech firms that represent this trade association called the Association of Competing Technologies. And, you know, I was kind of very green to this at the time. It was like, hey, we want to have 30 congressional delegates drop by the office and hear what you have to say. And I was like, it felt kind of heavy, you know, like, like, what do I, you know, and, and really fascinating at the same time, you know.

So I ended up, uh, you know, I said, sure, why not, let's just do it. What, you know, what could go wrong, right? And, uh, you know, ended up having, uh, 30 people in the room, mostly from representing House and Senate, but we had some people from Energy and Commerce and Federal Trade Commission here too. And this is— this was the time, you know, that I brought that real conversation to the table, right? Like, this is a— I took it as kind of the consultative state of the state along with summary kind of recommendations and next steps.

And it ended up going really well. It was a really dynamic conversation. It was somewhat early in the morning too, so, you know, they weren't all tired yet from going all around the city and all that. And what— and I was really able to— the thing that kind of most surprised me about it later is just how much took hold in their brains, you know, from the discussion and the stories that I shared with them. You know, not only the OPM breach but all these other things that have been happening.

And, you know, kind of sharing the perspective of, you know, we're really focused somewhat, you know, as a, as a nation, we seem to be mostly focused on these kind of, you know, um, offensive red teaming kinds of things. And our defense really sucks, right, was kind of what I told them. And, uh, so I ended up getting invited up to DC to kind of basically do not the same kind of pitch, but, you know, more working with other people to go around and talk to congressional reps about kind of issues that were relevant to the association. And, you know, one of the things that they're real interested in is 5G and getting 5G deployed. I didn't really have a, you know, dog in that hunt, so I didn't— wasn't really a point of conversation with me.

So as long as they can build security into the 5G standard, right? That's right. But this— but, you know, from what they were concerned about mostly was, you know, how do we fast-track the process of getting 5G deployed? Because we really need it. We could set aside some bandwidth for first responders instead of building their own— they're talking about building their own cell network for first responders globally, internationally.

It's like, well, that would be a significant overspend on something because we had one event, you know, in 2001 that, right, is still in our minds, right? So, um, but they had other things that were kind of relevant that they did want to talk about, you know, backdooring phones, for example. And just with all the disclosures that we've seen, you know, from, you know, agencies that are in that kind of offensive business and kind of losing their own tools, there's a very easy discussion, you know, with DHS to say, you know, the, the big boys are having trouble, you know, keeping their tools contained. What makes you think that having this kind of tool that would, you know, allow, you know, any law enforcement agent to break into a phone— what makes you think that that's going to be any more secure with however many hundreds of thousands of county networks run around this country, right? Right.

And, you know, the conversation was really kind of meant to be, this is not anti-law enforcement, this is just good, you know, OPSEC, right? And, and, you know, it was neat to see kind of DHS kind of support, you know, and appreciate that perspective. So ended up being a 2-day trip. So if first day was, you know, all male, talking to reps about, you know, these kinds of subjects. And then day 2, I ended up in FCC and DHS and in the White House.

So, which was like one of those surreal kind of like, I can't believe this is actually kind of happening moments. They're letting me in here, actually. Yeah, right, right. And on the Hill the first day, I ended up meeting with Diana DeGette Getz, one of Diana Getz's reps, was here at the event that we had here at Alchemy. And then we ended up meeting with him in DC, and he's like, man, I remember you.

He's like, you're the one that scared the hell out of all of us at 9 o'clock in the morning. I'm like, that's right. Did it work? He's like, I pull out your presentation all the time, show people. And I was like, holy crap, I can get messages through to this brain, to kind of collective brain of like, you know, people that are making policy decisions that can affect the future in ways that might actually make sense.

So, uh, that was one of those moments I was just like, wow, there's, you know, I can't just continue to be the, the jaded citizen that feels like I don't even have a voice in the way things are going, right? So we ended up meeting with an education policy advisor within the administration, and, you know, there was lots of kind of different topics that got brought up. And I really spent a lot of time thinking about what I wanted to tell people, right? I mean, I'm just doing this because I want to see better happen, right? Because right now, every year, since we've been doing this long, long time, you know, spending goes up, problems get worse.

Yep. And, uh, so what I ended up advising, uh, the White House on is like, if you really want to have, um, a leveraged spend, if you want to spend a dollar and get some kind of significant multiple back from that, what we really need to be doing is, you know, not dictating but certainly socializing that computer science programs in particular have a component of secure programming as part of the core curriculum, right? Because at the end of the day, all we're dealing with here is software vulnerabilities. Not all— I mean, there's social engineering, all other things too, right? But, you know, any of the botnet activity, any kind of offensive hacking that's taking advantage of a vulnerability in software.

And, uh, it was, it was kind of nice because everybody's like, oh, and, you know, taking notes down. And, you know, you can see that it got the gears turning, right? So, so since then, um, you know, started to try to keep a little bit of an ongoing dialogue when I see things going down that I get concerned about. And, you know, they're picking up the phone and, you know, wanting to talk. So that's awesome.

Uh, it's, it's really kind of one of these things where You know, we don't do a lot of— we don't do business, you know, government work, right? We don't maintain cleared resources. It's not a big kind of revenue path for us. But, um, you know, the ability to kind of influence people that are setting policy around this thing in ways that I think make sense are great. So I'll extend the offer to you, as I have to other people that I respect, um, you know, if you have ideas you want to share You know, I mean, and this goes to the community out there of people that I know and people that I don't, you know, if the government could do anything to make it better, actually create positive impact, what would that be?

Instead of just bitching, get off my lawn, this sucks. Yeah, never going to get any better. You know, I've been that jaded guy for a long time. And it gets tiring, you know, quite frankly, to just kind of be in that mindset of like everything's pwned, right? Which we talked about here at BSides a few years ago.

And once the disclosures came out, turned out, well, maybe everything that really matters has been pwned. To how do we— what's our forward strategy here? And it's not just going to be kind of like, well, you hacked me, so I'm going to hack you back now. Yeah. Um, have you seen any of the, the ideas that you've put forward make it through into either legislation or potential legislation?

Have you seen those ideas bubble up? Uh, we'll see. I mean, you know, it's kind of early on. Yeah. You know, um, what I have observed is the things that we were talking about, I'm reading where there's changes happening.

Right, so there was probably 50 people that went up for day 1 activities on the Hill, and then there was a subset of us that they invited kind of for day 2. So there's maybe 15 of us for day 2 talking to FCC or Trade or DHS or White House or whatnot. So, um, I— that's the other thing that really struck me is that, you know, I'm just talking about this 2 months ago and now I'm reading about it you know, and, you know, the media that, you know, this is kind of the direction it's going. So really enabling too, in terms of enlightening, in terms of like how actually things work in DC and understanding kind of maybe in some respects the, the, that there, that there are leveraged ways to start to inject ideas that might start making a difference, right? Have you also had the chance to provide any, uh, sort of close the feedback loop?

So, you know, you started the process, you said, hey, here's bad stuff that's going on, here's ideas that I have. There's been some pieces of legislation or ideas that have come out, right? Have you been able to kind of close that loop and say, hey, this one is good, this one is bad, you know, why are you thinking about this thing? You know, an example of that would be I've seen some legislation recently that's Uh, popped up around, um, you know, enabling people to do hackback and other stuff like that, which, which in my opinion is pretty misguided. Um, but, uh, I didn't know if you'd had the ability to see, oh hey, um, you know, I'm— this is one that maybe came from something that I, I proposed or is along those lines, and maybe this one isn't, right?

Being able to close that loop and give feedback. So we'll see. So I'm starting to get a little more proactive Yeah, in my knowledge sharing versus where, you know, it kind of started, which was like, we want to talk about this, what are your thoughts? But that's starting to happen too. So like yesterday, they wanted to spend some time talking about, you know, how widely adopted NIST is being discussed and talked about in small to medium enterprise, 250 or 500 employees or less.

And they're like, they said, we talked to somebody else earlier today and they're like 1 in 10 And I'm like, well, that's probably being generous because I don't hear NIST being talked about in small-medium enterprise, right? They're talking about if they've got a PCI concern, they're talking about solving that problem. If they've got HIPAA concerns, they're talking about solving that problem. But, you know, in all fairness, you know, after, you know, building my own business, you know, over the past 10 years, you know, it's, it's, it's it gets to be a little easier to kind of appreciate, quote, the other side, you know, of like you're trying to build a business that, you know, is, you know, scalable, has the right people on the team. And we've got just an amazing team here at Alchemy at this point, and that's something I've really put a lot of focus in, um, you know, getting new products to market, all the things that are employing the these 250 to 500 people.

And, you know, and I bitched about it a long time. You know, I used to, I used to say that the security problem was really an accounting issue, right? When the CFOs went to CFO school, kind of nobody taught them what the value of an information asset was, right? So them asking the question, what's the ROI of doing this? And our best answer being, well, you get to live to fight another day.

How awesome is that? It's a really— I mean, the context of ROI, I've been one of the biggest, you know, advocates for CFOs stopping to ask that question. But the reality is, is there has to be some sort of component to that, right? And I think the way we get there is we help CFOs better understand kind of like Well, if that gets hacked, this is the cost to your business, right? And, you know, and if you do nothing, well, here's kind of the trade-off, right?

And we're not— I think we're starting to get there. And I think NIST and some of these other frameworks that are more risk-based are starting to kind of scratch the, you know, kind of more the surface of it now than we've seen over kind of time. But, you know, I would challenge even the you know, the Colorado Equal Security community, you know, when did you last have a real risk assessment, right? You know, the, the real sit-down. Where are the crown jewels?

Why do they matter to you, right? What are the bad things that could happen to them? Yeah. And then I'm gonna, I'm gonna be— play scary guy for a minute and say, well, here's all the things that would happen if you lost your crown jewels, right? And really kind of putting in that context.

We've gotten so kind of, you know, it feels like the industry is just bogged down in this technical discussion, right? I've got the latest new thing, right? And everybody's focused on— one of the things I've been fortunate to become a part of is kind of mentoring and starting to provide feedback to some of the ideas that are coming through SecureSet's accelerator program. And I'm hearing some really interesting things, right? And I'm hearing some ideas like, well, you still have to remember that, you know, as an industry as a whole, we're still focused on the basic blocking and tackling.

And yeah, we could be talking about this next generation awesome, but before we get there, you know, because there's no silver bullets that we're going to find anytime soon, we still got to get past the basic blocking and tackling. And I think on that topic, and along with NIST, you know, I mean, I do a full-day training on the NIST Cybersecurity Framework, and the people that I tend to have in my class are either part of small or medium-sized businesses, and they probably have never heard of the framework before, but they know they want to do something around security, or people that know, maybe are even part of a bigger company that they're not doing enough around security. And it's— they are all focused on the technical, hey, let's put this cool whiz-bang thing in, where they really need to be starting with, you know, putting a program in place and essentially, you know, making your plan. You know, it's not the technology, it's doing the risk assessment, it's doing all these other things to figure out all the unsexy, uncool things that you need to do. And then when you can, you know, have your plan to do that, maybe you start doing those, you realize, oh hey, maybe I do need some whiz-bang technology to help me do these non-cool things.

Yeah, but it, you know, it often happens the other way around. So hey, well, let's do the whiz-bang cool technology because it's easy. I can just, you know, spend some money and put this whiz-bang technology in. Yeah, but then they never actually develop that plan. They never figure out what the actual risks are.

Yeah, yeah, yeah. And see, and you know, unfairly, I think a lot of, you know, companies run into the, well, I can get CapEx dollars all day long, but I can't get any OpEx dollars to actually make it work beyond day one. And, you know, that's, I think, something as an industry we face. And kind of interestingly enough, I'm starting to believe that— and nobody's told me this, and it's not like I've got, you know, any kind of special knowledge here— but I'm almost beginning to believe that we're gonna start seeing some changes in tax law that is more favorable for OpEx dollars versus CapEx. Because as you can see from an IT— where IT is going is it's going off of-prem.

Yep, it's going managed services, all this stuff. Colo— I mean, colo's been around for a long time. Hosting, all OpEx costs, not buying hardware and, you know, long-term software. Sure. And it makes sense, you know, from a, from a, you know, business owner standpoint, you know, being able to have predictability with your costs and being able to predict, well, as our customer growth is, is X, our technology growth is going to be Y, and being able to more effectively make, you know, cost assumptions around what that technology is going to cost us.

Has been really enabling, right? Um, you know, we're going to continue to see this just kind of price drop in the, the basic blocking of IT, uh, stuff, you know, racking, stacking gear, swapping drives, you know, those jobs are going to AWS and Azure, right? Yep. Ultimately. And which is, it's kind of interesting in some ways that, you know, we're at a spot now where I almost kind of think about it in terms of like the Microsoft— you know what, there's lots of reasons why people can kind of bitch about Microsoft, right?

One of the ways I look at Microsoft is there was this whole kind of business enablement thing that occurred because all of a sudden people were using the same technology Right, right. And the things that, you know, everybody's literally, you know, they kind of got off— was it WordPerfect at the time? And some of these other things that these early kind of office suites— yeah, there you go. You know, they're now— that as that came along, it created this huge growth in business because everybody was kind of leveraging the same technologies. They could, you know, they could share documents more freely, things could start happening more quickly.

And, and now, you know, my kids in school, they're all using Google Spreadsheet and Google Docs. And why do I have to open up this application when I could just use my browser kind of thinking, right? But what I see AWS doing is really kind of being— and Azure, you know, they're obviously— Microsoft's obviously focused on cloud too. It's like, you know, getting that kind of adoption, I think, is almost going to kind of propel us to that next place, whatever that is, right? You know, I, I hear a lot of people struggle with that move from a security perspective.

What, what's your thought on that, um, in terms of cloud maybe specifically, but also, you know, other technology trends? Do you see them, um, helping to improve and enable security? Do you see it, um, making the problem worse? What do you, what do you see in that area? I guess my short answer would be yes, right?

I mean, honestly, you know, it's like, um, there's some step backwards, steps backwards that are happening right now. I mean, companies are putting servers right on the internet without anything other than, you know, some basic security controls that come with AWS. Like, you know, we met with a company yesterday that they've got 6 kind of data center presences around the world. In some cases, they need to keep data in-country, right? They, they don't manage PII, but the applications that they develop and customers use ends up with all kinds of things in there that they don't actually know what's in there, but they know it's probably not good if it were compromised, right?

And they've got this footprint of where And they're heavily— they've heavily adopted AWS. Like, the story that was explained to me was, you know, 2011, they had, you know, big on-prem presence, and they kind of were putting their toe into AWS. And 2 years later, they were in AWS with kind of maintaining a toe in on-prem stuff. Yeah. And it really supported their business because the particular field that they're in, they see tons of spikes in volume.

They've got a customer that processes payroll, so if there's any things that are kind of related to that to come up, they need to— they see these huge spikes in volume on the 15th and the 1st, right? And with AWS, they're able to kind of spin up and spin down VMs as fast as they need to, which has really enabled that business. But right now it's sitting kind of right there. They don't have any kind of firewalls in front of it. They're just using basic controls.

And, you know, as I understand it, Amazon is focused on kind of creating a bigger suite of tools to make available to Amazon customers, but that would be an example of a step backwards. An example of a step forward, just using that same company example, is, you know, if they've got— when they migrate to like a latest release of their software, they're basically just spinning up new VMs, pointing traffic there, and spinning down old VMs. And so it gives them this kind of agility to rapidly deploy new versions of their software that's transparent to their customer. And kind of what they get along with that is if, well, if a system has been compromised and it's got malware on it, or it's just misbehaving in any way, they've got zero problem with spinning it down and, you know, and firing another instance up that's clean. So this idea of like persistence, I think, is going to get to be a lot harder with companies like that because, well, the only persistence that you can really have at that point is either, you know, you either own— you either create another server in that environment that maybe they're— if they're big enough, they don't really understand, don't know that it's there, they could be a jump point or whatever.

And if they don't have good monitoring in place, they'd never see that, right? They're not auditing their, you know, VM infrastructure. And companies like that, who's gonna look at VMs going up and down like this, you know, by time of month or, you know, big events? They actually saw— they knew when, just in the business they're in, they ended up seeing kind of advanced indicators that AWS was actually having a problem in one of their environments. So Which was really interesting, you know.

So they've got this kind of new technology, haven't adopted traditional security controls that you or I agree with would be kind of, kind of minimally viable security standards, right? Um, but on the other hand, they've got this whole new kind of proactive, you know, persistence is going to be difficult unless I've got admin credentials and nobody knows that. So, you know, it really is kind of some of both. I think they're starting to see the light. This particular organization starting to see light of why, you know, having firewalls on the front end is a good thing, and being able to get visibility between different, you know, zones within their Amazon environments for lateral movement and that sort of thing will really take hold.

But, you know, it's, it, it's just new. It's different. We need to be thinking about we need to be thinking about security in the positive ways with these new kinds of potentials and things that are just happening anyway, because they're— it's not all bad, it's not all good, it's, it's really some of both. So obviously the— this, uh, this example company has had to make some adjustments in how they do their, their operations and things. Have you, as a, a managed security operations provider, have you had to change the way that you guys do your work as these new models of technology come out?

Is it, you know, monitoring in the cloud? Is that a different paradigm for you guys? I mean, obviously there's one part of just getting the data. Sure. But the second part of, you know, is what you get— does it look different?

Are the patterns different? You know, how have you guys had to adjust to that? Well, I guess there's kind of two ways to think about that question, and it really is a good question. You know, one of the things kind of fundamentally, a core value of Alchemy has been that your logs are your logs. They should remain on your prem.

That's why— one of the reasons why we've been going with, you know, these kind of commercial off-the-shelf technologies, because customers could buy these things and we would help them maintain that, right? And there's still a lot of that thinking, you know, by many customers that they don't want to ship their logs off to an MSSP. Right? But I'm hearing much more. And so we didn't really, quote, adopt the cloud kind of cloud computing models, even though we've had hosting partners that resell our services now.

These are still kind of contained private cloud environments, so we could really wrap our brains around that and all that and be effective, and really be effective, as security monitoring practitioners in the field. Um, you know, one of the things that we've— the ways we've changed our business model has been to kind of adopt the cloud, right? So for us, we can give customer savings if we're managing kind of a bigger instance, right, with indexing clusters, you know, you know, dedicated indexes per customer but still using kind of the shared infrastructure. So our engineering costs go down so we can provide a kind of cost recovery to customers. So it shaped our thinking differently about what we— how we provide services, knowing that win, lose, or draw, no matter what I think about why I think why you're putting all that stuff in that SaaS provider is a really bad idea, my thinking is not going to change that movement from happening, right?

So we recognize that there's been just this kind of shift in thinking, particularly at the CFO level, where, you know, if I can just buy this as a service and focus on the core thing that I do, that makes a lot of sense to me. And I'm just really gonna expect my SaaS provider to have good cybersecurity hygiene, right? And there's definitely some SaaS providers out there that have some of the best security teams in the world, right? Now, from our standpoint, what we're running into is, you know, we've had to kind of rethink what How do we do security monitoring in AWS environment, particularly if we've got a customer that's got 450 servers over 6 data presences globally that's going up and going down without any kind of north-south, real north-south traffic to monitor? So, you know, we start looking more at endpoints more, and, you know, well, what do we get out of endpoint that's going to be different or new that, that we didn't before?

You know, and I know there's other kind of companies here in town very much focused on, you know, I'm gonna monitor the endpoint. And there's, I think that's a, there's certainly some relevance in thinking there, and we've addressed it in our own way with our own endpoint kind of monitoring technology, and we're just continuing to improve upon that. But I do think what we're ultimately gonna see is kind of this adoption of like, you know, some reference good reference security architecture that exists to where, you know, if you're going to deploy here, here's kind of the— yeah, you're going to need a virtual firewall in front of that, or a couple virtual firewalls for redundancy. And we're going to need, um, you're going to need endpoint monitoring because, you know, you still need that, right? It's not going away.

These requirements, particularly from a compliance standpoint, aren't going away. If anything, they're just going to get kind of more more, right? Everything's going to just continue to get to be more driven towards, you know, particularly if you're managing regulated data. You know, we might see some point where if you're a public company, you have to comply to NIST. I don't know, it's not like anybody's talking about that, but I think there's this kind of collective agreement that, you know, security monitoring is going to be a component of all these different kinds of regulations.

And, uh, you know, doing that effectively is something that, you know, we as practitioners are always trying to find the new alchemy way to make that happen, right? Awesome. Well, I think we're getting close to the end of time, um, but I wanted to, to end with a question about Colorado. So, okay, you know, we are Colorado Equals Security, um, You've, you've been a, a member of the, the community here for a long time. You've been a, a great proponent, you know, you've helped organize BSides in the past.

Um, what do you see as, um, as making the, the security community here in Colorado special? Wow, there's, there's just so many amazing people in this community. There really is, you know. And, and, you know, not living— having lived in another community for some time, it's really kind of difficult for me to compare like how it is here versus either San Fran or Dallas or Austin or other places where we've even seen B-Sides events. But, um, I am always blown away by the just massive amount of really smart people here.

And, you know, it's funny, you know, we've got the governor kind of pushing some cybersecurity initiatives and all that. And, and I think with maybe not even realizing, you know, because he's been looking further south, you know, it's kind of the hub for all that, and almost kind of missing the boat in some ways that we've just got this really massive community here. But, you know, there's so many of us, and, you know, myself over time have been on airplanes going somewhere else because, you know, just the, the nature of where Colorado is terms of, you know, number of headquarters and security buyers and all that versus the number of practitioners we have. I'm sure if we could rank it on practitioners per, you know, you know, you know, a resident in Colorado, it's got to be certainly— it would seem to me probably disproportionately high. So it's a beautiful community.

I love all the people. That I've interfaced with over time. You know, not always been easy. There's been some arm wrestling going on over time, but at the end of the day, it's just— it's, uh, it— I really appreciate being a part of this community. I just look forward to continue to doing so for, for many, many years.

Awesome. Well, thanks, Joe. I appreciate your time today. Good conversation. Uh, this has been Colorado Equal Security, and we'll talk to you again next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes