Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 26, the week of July 31st. I'm here with Alex in the studio, the exclusive studio in Centennial, Colorado.
Alex, since we last saw each other, we've traveled multiple states. What have you been up to in the last week? Yeah, so, well, I guess I was in Las Vegas the last time when we recorded. So now I'm not in Las Vegas anymore. Thankfully, I enjoy Las Vegas, but only for short bursts.
Prior to that, I think I mentioned maybe on the last one, I was in Oregon for a little bit, had a good time there. Yeah. And how about you? I know you were traveling a little for work. Yeah, I went from Vegas to Boston.
I was there for a few days. Been home for a couple of days. And then actually last night went with my son to Wyoming. We went to Frontier Days in Cheyenne, ended up driving back to Fort Collins to spend the night, though. So it's been fun.
A lot of miles on the road the last couple of weeks. There have been a couple of other states that I've been into. Intoxication, undress, other things like that. There's a lot of details here this week. Well, let's go ahead and dive into the news.
Speaking of all this travel, Denver has recently just come down with another international direct flight. There's going to be another flight coming into London. And that's in addition to a few flights recently added, including Panama, Zurich, and Tokyo. Yeah, I thought the Tokyo one was pretty interesting. I saw that a week ago or so.
The London one, I think, is a pretty good one too. I believe it's a seasonal flight, a summer flight for folks taking vacations. But it's cool to see that people are interested in coming here in the summer. As well, not just, you know, winter ski flights. Yeah.
For me, it's exciting to have more opportunities where we can get directly. One of the big inhibitors for international travel is, you know, it just takes so long to get over to Asia, to get to, you know, anywhere in Africa, Middle East. And it's nice to have more and more options to get there right away. Well, I think we're pretty spoiled anymore in the US with so many direct flights everywhere. I do my best to only take direct flights.
So next on the list, Denver Startup Week has opened registration for 2017. You know, we talk a lot about security startups, but there are lots of other startups in, in Colorado, in the Denver area as well. And Startup Week here is a pretty big event. As a reminder, we had submitted a Colorado security founders session for Startup Week, and we were waitlisted for that. Possibly we'll be accepted.
If so, we'll let you guys know. Otherwise, you probably won't hear about it again. CH2M Hill— excuse me, CH2M is in talks to be acquired. That's the largest private company in Colorado, and they're actually being talked about being acquired by one of their competitors. Yeah, that's good for them, I suppose.
Being employee-owned, you know, I got to think, hey, you know, why you want to sell and go back and work for the man again? But, you know, maybe everybody needs to make a couple extra bucks. And it's kind of one of the neat things about CH2M is it's majority owned by the active employees who are working there. So pretty neat. Next, ColdFire had a blog talking about AWS certifications and going through an explanation of what they are and how it is to best achieve those.
And I think that's something that should be of interest for a lot of people as AWS becomes more and more part of everyone's everyday work experience. Yeah, if you're interested in learning more about the public cloud craze and getting that on your resume, this would be a good place to start.
Swimlane is actually, just recently let us know that they are being, they are part of an Ernst Young cybersecurity center that they're setting up in, was it, I think it was Dallas, Texas. The neat thing here though is Ernst Young is investing in this as a place to do research, try out new technologies, and give their companies, excuse me, Ernst Young's customers access to new technologies, and that's where Swimlane comes in. They were on a list with only, I think it was 5 other companies that you can try out there at their Cybersecurity Center. Lots of synergies involved there at the Cybersecurity Center and many other buzzwords as well. Yeah, the press release was written a little buzzwordy, but the meat of it's pretty interesting.
So congratulations to Swimlane for being part of that. And we also saw on the list that LogRhythm is another one of the technologies that's It's going to be used there. Yeah. Pretty cool. Next, ProtectWise and Ixia announce an integration partnership.
Um, you know, we've talked about ProtectWise before on the show. They do, uh, I don't know the best way to describe it. It's sort of like a network, network flight recorder or some, you know, uh, network traffic analysis. They used to call it the network DVR. You could record your activity and then it looks through the activity in your network for suspicious stuff and tries to boil it down to the really actionable stuff for your SOC analysts to look at.
And Ixia, you know, I think of them as doing network taps and other things like that, sort of like a Gigamon or other things like that. But the product that they have as well looks to be a lot like a CASB, and it works in both public and private clouds. And the integration that they're talking about allows the folks that use that, that Ixia platform to integrate it directly into ProtectWise. So I thought that was pretty cool. You know, if you're using this sort of CASB-like solution from Ixia, you can now just automatically integrate a security product right into it.
From the reading, it looked like it's probably a really strong play in a private cloud. In a public cloud, you're always limited by what are the APIs available, what do the public cloud providers allow you to do, but either way, it's a good step in terms of getting visibility across your organization. Definitely. The next one is that Ping Identity won the 2017 CODIE Awards, and Alex, you and I hadn't heard of this before, but the SIIA gives these awards out for really online content type activities. And for IAM this year, Ping Identity was the winner.
Yeah, and SIIA sounded like a trade group for information software. So it's pretty cool to see that an organization outside of security is recognizing Ping for the work that they're doing. Yeah, and one of the big things that Ping's proud about there was that it's all voted by people in the industry. It's a peer award, not some small committee that does the voting there. Right.
Uh, InteliSecure put out a press release this week. Uh, they now have opened enrollment for the 2018 Critical Data Protection Benchmark Survey that they're running. So this is targeted at information security and risk professionals. So if you happen to be one of those, which I'm guessing you probably are, you should go out and take a look and take the survey. Yeah, and InteliSecure is the company that we're actually doing an interview with today.
We have their CEO Steven Drew and CTO Jeremy Wittkop on the interview today. So hopefully as you guys, as you listen, maybe you can be filling out the survey. Final thing is we mentioned it last week, but as a reminder, the, the CISO of the Year Award is available, is up right now. We're looking for nominations for that. It's, it's open till August 14th, and they're really looking for someone who has helped their business succeed by how they run their security program.
Yeah, this of course is part of the CTA's APEX Awards. Again, this is the first year for CISO of the Year, so we want to get a lot of good nominations in there, have a good pool of people to select from, show them that it's really worthwhile to have this award. Yeah, so, so go ahead, if you guys work for a good CISO or you happen to know one, let's go ahead and get those nominations rolling in there. Next, we'll go into events. As a reminder, we do have a calendar of events, and you can take a look at that to see what's coming up here over the next few months.
We're filled out into November at this point. So you don't have to be surprised by these things every time you listen to the podcast. So first on the list, CTA is doing their tech tour the 31st through the 4th of August. And we talked about that a little bit last week. They're going to a number of different cities in Colorado sort of to do technology tours.
Colorado Springs, Pueblo, Durango, Montrose, Gunnison, and Boulder. And that's really the only thing happening this week. It's a relatively light week, but as we look to next week, On the 8th of August, we have a— DENSEC has their meetup. I think that's the South one on the 8th. ISSA Denver has their August monthly meetings on the 8th and the 9th, standard locations and times.
Michael Stephan is doing a talk about privacy for information security professionals. I think that should be an interesting topic and one that is probably good for everyone. I think most of us InfoSec folks could use more focus on privacy. And Michael is the, the head of security for Connect for Health Colorado, which is the Colorado-based healthcare exchange as a part of the Affordable Health Act. Um, on the 10th of August, SecureSet has an expert series.
They've got Clark Hobby, uh, with Miranda and open source. Uh, on the 10th also, uh, the NCC is doing their cybersecurity oversight training in Colorado Springs. So this is the board-level training for folks to get boards up to speed on cybersecurity. And then on the 11th of August, SecureSet in Colorado Springs is doing an open house. So they're showing off their new digs down there in the Springs.
Awesome. And that's all we have for upcoming events. So let's move over into the jobs. Coalfire is hiring a Director of Technical Services, and there was actually a lot of different opportunities at Coalfire. That was just one of the ones I picked out.
I've got to imagine as big as they're getting, they're going to have a lot of opportunities. The NCC is looking for a cybersecurity strategic planning program manager in Colorado Springs. Radware is hiring a cloud regional sales manager. So if you want to sell Radware, they're mostly known for their distributed denial of service protections, but they do other web service or web security stuff as well. There's an opportunity for you.
Booz Allen is looking for a multi-intelligence collaboration specialist. Junior. I don't know if you're able to do multi-intelligence at junior level. That's a, that's a tough ask. Uh, AT&T is hiring a Cybersecurity Consultant III and focused on payment card industry.
Uh, Accenture, whoa, is looking for a Federal Cyber Hunter Remote++. I, I think that this is Accenture Federal, and I think that Accenture Federal is looking for a Cyber Hunter. I see. Which is— I see that apparently someone's finally gonna to find what the cyber is, and hopefully whoever they hire here can, can get on the show and tell us what's going on. When you find the cyber and you've trapped it, I would like to see it.
Uh, General Dynamics is hiring a cybersecurity software development lead. I'll take this last one. Uh, and Ping Identity is hiring a couple— actually, a couple this week I want to talk about. We have a security compliance analyst, and then we're also hiring a, uh, an intro— an introductory level, um, product security engineer. So that's a junior level somebody who knows Java development and wants to help us, you know, build security into the SDLC at Ping.
I'm glad you're looking for a junior level somebody because you wouldn't want to hire a junior level nobody.
Well, with that joke, I think we have, uh, we have worn out our welcome here. Yeah. All right, Alex, I think that's it for this week. Anything else? Uh, that's it for me.
Thanks, Rob. One more thing we'll say, uh, if you, if you do listen, if you enjoy it, go out and sign up for our mailing list. We are on our website. Give your email. Every week you'll get the summary of the show notes for that week.
And it wouldn't hurt our feelings if you wanted to rate us on the iTunes Store or Google Play Store. Yeah, and, you know, we love that people listen through SoundCloud. I know that that's super convenient, but we would also love it if you subscribe so that you automatically download the show through whatever your favorite podcast app is. So with that, thanks everybody, and we'll talk to you next week.
This is David Mackey, Director of Cyber Defense with General Motors. You are listening to Colorado Equal Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is Robb Reck, and I am at the InteliSecure headquarters in the Denver Tech Center, and I'm sitting with their CEO Steven Drew and CTO Jeremy Wittkop. Hey guys, thanks for joining the show. Hey, good afternoon. Thanks for having us.
Thanks for having us. All right, so we get to talk to kind of the new guard. Steven's been at the company for just about a year. Yeah, actually about a year on the nose now. Yeah, and Jeremy, you're a longtime InteliSecure employee.
Yeah, about 6 years now. Yeah, well, that's pretty good in this space, right? Yeah, for the startup, and you know, obviously a lot of change over the years. So for those who don't know, let's talk about the name. Those who don't know, you know, InteliSecure has not always been InteliSecure.
Could maybe one of you guys give some background? How did we get here? What do you guys do? Used to be. Yeah, absolutely.
So we were started under the name BEW Global. The 3 founders of our company, it was their initials, essentially their last names. It was Blomquist, Egebrecht, and Werden, a German guy. He didn't stick around long, but they kept his initial. Actually, when we had some private equity funding, they decided that we sounded more like a law firm than a security company, and we needed to change our name to be more reflective of what we do.
And at that time, we were calling our managed services department InteliSecure Managed Services, so they decided to elevate that service line name to our company name. Was that like 3 years ago or 2 years ago? Remember? Uh, 2015-ish. 14.
14. What's that? Okay, 14. 3 years. Yeah, at least they didn't make you put fire in it or didn't have to put source secure or fire secure.
All right, so that's, that's good. Uh, so yeah, I remember the rebranding effort you went through. Uh, so let's start, start off. So I've known you guys— we, before we started recording, talked a little bit about my history. I've known you guys, I've known you guys as the DLP guys for quite a So how did that come to be?
And do you think of yourselves as a DLP guy still? Am I right? Yeah, so we started around the idea that not all information is created equal and some information is more important than other information. That really gravitated us towards this new and emerging technology in 2002 that was known as DLP. Our 2 founders were very different.
One was a technologist, Chuck Lundquist, had been around you know, delivering Wi-Fi to rural areas and those kinds of things for quite some time. And Rob Eggebrecht was more of an ISO 27000 business process consultant type. Those 2 got together around this idea of a technology that could be business-centric, that could identify certain pieces of information from other pieces of information, apply specific protections on an information-centric basis. So that's how the company started, and that's what— we started around DLP. As things have evolved, and especially as things are evolving now in the security space, there's a lot of opportunities to protect information in different ways.
We feel strongly that the foundational element of all of those programs is still the ability to distinguish commodity information from very important information. We're talking about things like the data protection elements of CASB, things like rights management and encryption that goes with the information, and whatever else comes next from a data protection perspective. So we look at ourselves more as a company that provides comprehensive services around data protection than a DLP company. But DLP still is a foundational element of those programs. I want to drill in a lot more into DLP and what it looks like in the new world where, you know, we're not so data center-centric.
I want to dive into that a little more, but I'd love to get some more history of the company. Originally you guys were Castle Rock, right? And I think you moved up to the Denver Tech Center area. That's right. What was it, like 2010, 2012, something like that?
Yeah, probably 2012. It was an interesting journey, so, and I can tell you more about how I ended up in this little company in Castle Rock when I ended up there a little later. But yeah, we started in a glorified dentist's office in Colorado. Actually was an old dentist's office. Castle Rock, Colorado.
It wasn't glorified, was it? It became a dentist's office after we left. And, you know, it was interesting because we underwent a lot of different changes and cultural challenges associated with just moving. Because when we first moved, we were growing very quickly at the same time. So we've got a space here, and by the time the ink on the lease was dry, we'd outgrown it.
So we had to bifurcate the company into the sales and the operations teams. Oh really? The sales team was up in DTC and operations team was in Castle Rock, so you can imagine how that got out of control quickly. And then when we bought more space, we bought space for the size of the company then, and then we grew before the ink dried, so we stayed in the old space and the new space. So we had 2 floors, right?
And so in this building here? Yeah, yeah. So we were on the 2nd floor and the 8th floor, and then, and then we ended up all on the 12th floor for a very short time, and then we wanted to take additional space on the floor below us, but then that got sold. So we— now we're on the 12th and the 9th floor. So we've never really been in one spot.
Yeah, but it's an interesting dynamic. But yeah, all high-class problems driven by growth, right? That's awesome. Right. So size of the company now, where are we at in terms of employees or whatever you want to share?
Yeah, so we're about 175 employees. We have the location— the 2 primary locations are here in Denver at the tech center and then in Basingstoke in the UK, and they're just west of London. We have SOX in both locations now. And the Basingstoke location was through acquisition that was completed back in 2015. We had acquired a business there by the name of Pentura that brought to the table not only penetration testing professional services, but also managed services.
At the time, they were the number one, as I believe it was, if I recall correctly, they were the number one partner in the UK with Symantec on DLP services. So, it was a natural fit for us from that perspective. And you guys, what do you have in each of those offices? Is that just kind of operations? And I've seen some salespeople out there.
Actually, we have sales forces in both locations. So there's, there's kind of a little bit of all of it, if you will. So it's about 50 folks out there, about 125 folks here. Oh, so everyone's in an office. You don't have a lot of— No, we actually— so our sales force is out in the markets that they're going after along with our sales support, sales engineers.
We have a lot of our pen testers, as you can imagine, they don't need to be— Wherever they want to be. That's kind of wherever they want to be, that type of thing. Wherever the extradition laws are weakest. Yes, and wherever there's a copious amount of hoodies.
Yes. Well, that's great. So as you guys have grown obviously pretty well over the years, and I know you've added some capabilities. You started off really core on CAP, which I'll let you guys talk about CAP and DLP, and then you've added some other services as well. I know, I think ISO was the next one you added, is that right?
Or is that not the next one? Does that number change? Yeah, so ISO was always kind of part of the message just because of Rob's background and the capability to deliver it. We had another guy by the name of Ryan Coleman who was leading our consulting effort, which was— he came from the pharma space and very much ISO-centric in terms of the way he built programs. So a lot of the programs that we built around technologies were somewhat ISO-based in terms of taking the best practices from ISO and applying those to the technologies we supported.
From a technology perspective, we started with DLP and Then we kind of went into web and email gateways because, you know, as people who are familiar with DLP are familiar with, web and email gateways are an integral component. But we found that a lot of our clients weren't managing them well enough to make DLP integrate well with them. So they basically— we basically said, hey, you guys need to get these things doing all these different things in order for DLP to integrate the way that it can. And they said, well, why don't you do it, right? So that's essentially how we got into that space.
Over the long term, we got pulled into the SIEM managed services business by our DLP clients that basically said to us, We like your approach to security. We want a similar approach to SIEM, right? Most of the SIEM providers that we've talked to want to boil the ocean. You guys understand what our critical data assets are, where they are, what are the things that may get attacked, and we want you to watch those things for us. So we've kind of spread out a little bit.
I think we're continuing to go through, I'd say, an ongoing exercise with the people around this table and others in terms of what is our core value proposition, what still fits, what doesn't fit anymore, what new stuff may fit we didn't yesterday kind of thing. And I think, I think that process is ongoing. Yeah. So, and, you know, I would say that the thing that brought me here to the company now a little over a year ago was that very focused, business-centric approach. So, you know, my background is coming from SecureWorks and being focused on sort of the broader network and network level, and we pushed into the endpoint But what I liked about this opportunity as it presented itself was focusing on the thing that really matters to the business, which is the critical data asset, right?
The thing that a board member or an executive should be able to look you in the eye without hesitation and say, these are the vital few things that if they left my organization, either by malice or otherwise, could cause me the most damage from a security, reputational, regulatory, or just from a competitive standpoint, because IP theft is a big issue now for our clients. And so that's, for me, what really resonated here was the ability to come in and focus on this spot in the security problem in a way that doesn't try to spend a dollar to protect a nickel. And not, as Jeremy has said, not try to boil the ocean. So our services are really around the lifecycle of the most critical data assets for organizations. And I think when you talk about CAP, the Critical Asset Protection Program in place, it's, it's all about building the program and not just trying to install point products in places that if they don't truly integrate, they don't deliver on the intended outcome that was sought in the first place.
I love the approach, I really do. You guys have talked at RMISC several times over the years about critical asset protection. I think we've even had you guys at an ISSA Denver meeting once or twice over the years.
The concept is fantastic. The challenge has got to be, and I'd love to hear you comment on this, that the industry doesn't think this way, right? You're trying to convert customers as you're in a process and you're competing against, you know, the Solutionaries and the SecureWorks and the Optives who do managed SIEM, and they're just you know, let me put one more line on my spreadsheet and compare you guys against that. How do you do that? Right.
So you don't— you're right. You don't— as you guys, CISOs, don't call industry analysts and ask about how do I protect my critical assets. You call and ask about the Magic Quadrant for X, Y, or Z product, right? So, and that's really where we're going from a messaging standpoint to try to link the overarching programmatic message with the underlying solutions, because therein lies the problem that I think CISOs are facing is that they are trying to solve a bigger problem, but connecting the individual pieces together. I think we've done a lot of work on it just this week.
Jeremy, you want to talk about it? Yeah, I think just from a personal perspective, for me, I'm not in this just to get you to write me a check. I'm in this to make the world a safer place to do business, share information, to capitalize on ideas. That's what really brought me here in the first place. And so we've spent most of our history educating the marketplace on the types of questions that they should be asking and the ways in which they should build a security program.
So when we talk about this approach, There is a lot of educating people to a different way of thinking, but I do think there's an evolution in the security space that's coming, or I would say is already kind of here, and that as the spend goes up from the business people, the business people are asking and demanding in some cases information on what they're spending their money on and what that return is going to be. And it's really hard to do that with the way that most people sell security solutions and security programs. But if you can define what those critical data assets are and you can value those data assets and you can define what the risk is against them and the way that you're going to mitigate that risk, you can start to put together— if you spend X dollars, you're going to get Y return. And it's a lot harder to do that if you're doing it in the way that the traditional security solutions are sold. Yeah.
When, when I first heard that you guys added SIEM into your portfolio, I didn't think it was a good thing. Full disclosure, I thought you guys are really good at one thing, and you're world-class, the best in the world at one thing, and you're adding an extraordinarily hard thing into your portfolio, right? And something that I have very infrequently seen executed well. I think outsourcing SIM management is really, really tough. Is it?
Now, as you described to me the way you look at it, it actually starts to make a lot more sense. We're not really, a DLP company, we're not a SIEM company, we're a critical asset company, and what are the different controls you want to have around that? I like the way you're talking about this, but when you have incoming sales leads, or, you know, that's not what they're coming after, right? So do you have a process for how you kind of reeducate them? Yeah, the majority of our SIEM clients have some exposure to us before they come to us for SIEM, so we're not included in most SIEM RFPs.
We're just, we're just not gonna be there. Some of our clients end up being sim only, but it's because they heard about us from someone else. So most of our clients that come to us for sim come to us with the understanding that what we provide for sim is fundamentally different than what most people would provide for sim. Yeah, and so I think that does help. I was kind of of the same opinion as you when I was running the SOC.
I thought I was finally getting my feet under me, and I grew from a team of 3 to a team of 30 within about 12 months. And, you know, I'm finally feeling a little bit comfortable with what we had and the structure we had. And Rob said, we're managing SIM now. And I'm like, thanks, I really appreciate that, right? So it was certainly the same struggle.
We've challenged this several times about whether it still makes sense. And we've even evolved our SIM programs quite a bit so that when people see our presentation on SIM, it doesn't look like everyone else's. It's based on this idea that there are foundational use cases that everybody should take into account, and that's your due diligence essentially. We put that in place for everyone, and then there are unique use cases for your organization that really centers around CAP. And then after that, it's all about building playbooks and response, which we're going to help you facilitate by being experts in technology, but we can't do for you, right?
And then the last, last phase, if you ever want to get there, is deception technologies, which I'm not going to manage for you, but it's built on a foundation of really good response practices if you're going to use those well. And so that's kind of our vision, which is let us help you get to where you want to go. Rather than just saying I need to have a SIEM because everyone else does and I need somebody to manage it because I don't want to deal with it. It's very— it seems like everyone gets a SIEM because they have to or for a compliance perspective, and if you say what's the actual deliverable, that's pretty tough. Yeah, you know, delivering a lot of alerts, that's kind of the actual deliverable, but business value is a little bit more typical.
So CAP, right? Critical Access Protection. Critical Asset Protection System. Yeah, so 2 Ps. CAP.
Oh yeah. Yeah, and the interesting thing about CAP, I think now is probably a good time to mention it, is we've really been thinking about what is the evolution of CAP. Yeah. Right? So CAP was introduced in 2012.
It's a fantastic idea. It was Rob Eggebrecht and Brian Coleman sitting in a room coming up with what is it that we're really trying to accomplish with these technologies and how do we make our message less technocentric and more business process centric and help people understand very quickly that what they're trying to do is protect information and not deploy technology. So that, that was fantastic. The idea of CAP as it existed in 2012, to your point about the fact that perimeter is changing, data centers are changing, all that stuff, CAP has to evolve, right, with the business, with the information, and it needs to evolve. So our ideas on CAP now are almost taking a— CAP is the foundation, but building on top of that foundation almost like chapters if you will, of a book that say, all right, now we have the foundational elements that allow us to distinguish what's critical from what's commodity and identify that.
Now what do we do next? And then sometimes that next step is structure, and that structure comes in the form of data classification programs that are built on top of that foundation of DLP. And then a lot of times the next thing is now we need to cover it throughout our span of control, which isn't the traditional data center, it's all the services we subscribe to. Then we can layer on a CASB chapter of CAP that goes on top of the foundation and the structure that we've built. And then finally, what about once we share it outside of our organization?
If it's really sensitive, we have to put it to use, right? It's something that needs to be shared and used, but at the same time, we don't want to relinquish control to a third party that can then share it with whoever they want to without some kind of control. So there's these emerging things around information-centric encryption from Symantec or rights management through Azure Information Protection that we're now trying to layer in with CAP. And then the underlying technologies in each stage, whether it be DLP, data classification, CASB, or these rights management things, we're ticking and tying all these things back and integrating all those things into a single program that we can manage for our clients. So CASB is— has a noble mission, right?
I think CASB is trying to do a really good thing, but its job is maybe impossible, or at least it's so incredibly difficult that I haven't seen it pulled off super well. And not that there's no value there, but that you don't get the coverage you get from a data center-centric, you know, if I have a perimeter and everything has to go through my perimeter to get out, well, I can require that I'm able to see everything, right? When you get to the CASB aspect, many of the service providers don't give the APIs you need in order to get access. You have to know which service providers you're even using in order to have it be real valuable. What's personal?
What's company. How do you— do you guys start to have a way forward to start getting security in the new world? Yeah, absolutely. So I look at CASB a little bit differently. I don't look at it as a self-contained security solution that's going to give you everything that you need to secure information in the cloud.
I look at it as a point of presence, almost like a web gateway in the data-centric world. I even look at it as— I tell people all the time, to me, a CASB is a purpose-built built web gateway hosted in the cloud. So it's a web gateway focused on cloud, and then when you can take your data protection program and you can expand it as a point of presence inside of the CASB, you can take your visibility and compliance programs and expand it as a point of presence inside of the CASB, but the CASB doesn't govern everything. And then the other thing about CASBs is they're multimodal, so you have to, you have to be able to understand what those modes are, understand what they give you, and then understand who you're doing business with And long-term what I think is going to happen is more and more requirements with respect to am I going to go Azure or am I going to go AWS or am I going to go Rackspace are going to have to do with, well, what can I hook into through that API? And I think that API is going to become one of the many competitive points for a lot of those cloud products.
And I think we're already seeing that. So when we look at CASBs that can do forward proxying and can do, you know, log integration and can do API calls and can do reverse proxies, now we're starting to get a semblance of comprehensive protection to those cloud-based And the other piece that you said, some of those modes work for both personal and corporate-owned apps, which really only gives you visibility into what's going where. But some of those modes only work for corporate apps. So you can do a differential analysis of what I'm seeing from the forward proxy versus what I'm seeing from the API or the reverse proxy that I know is corporate sanctioned. And I can start to do that analysis even inside the CASB itself to say what is the personal stuff and what is the corporate business stuff and what information is going to each.
And then we can start to put that against DLP policy and enforce some controls. When you look at CASB as a critical control for someone, do you require agents installed? Do you think that that's a requirement? There's so many ways to skin that cat. I think so you can do— it really depends on what else you're doing, right?
A lot of people are doing like a Zscaler in the cloud or something similar for web gateway, and in which case I can just chain that proxy to CASB. And if you've got everybody going through your web gateway, then if it's going to a specific specific destination that's a cloud service, then I can send it through CASB. That's easy. I don't have to do anything to your endpoint. Because you already got the agent there for Zscaler.
Other approaches, so Symantec has now bought Blue Coat, which acquired Elastica, which is the leading CASB. If you go down that route, the CASB agent is being tucked into the SEP agent. So if you happen to have AV, then you can route through CASB in the future if you want to, and also their WSS service for non-cloud web services. So there's a lot of different things that are starting to happen in terms of collapsing endpoints down. But I can do proxy chaining.
I can do endpoint redirection. I can do PAC files that I host on my website or my SharePoint site. Or, you know, if you want to get real crazy out wherever Office 365 is, I can host it out on SharePoint. Anytime you can connect to your email, you can connect and grab that PAC file. So there's some different ways that we can route traffic.
But I think the biggest piece of it is for corporate-owned apps, I don't need to route the traffic. I can connect through an API or I can reverse proxy it, which means it doesn't matter where I connect from, I can monitor that. So that gives you some control. If I say that my sensitive information or above, if I'm looking at a classification scheme, can only go to a corporate-owned app and I'm going to monitor on a reverse proxy basis that that can only be downloaded to a corporate-owned asset, then I'm starting to— I call it span of control, but it's the new millennium perimeter, right? I'm starting to enforce my span of control around all the different services that I consume as well as the assets that I own and I can build some at least semblance of fences around that.
So what's the, what's the vision for, you know, we're in mid-2017 right now, you know, 2018, 2019, 2020, where does, where does InteliSecure go over the next couple years? Yeah, so I think that you will see us to continue to grow organically and then opportunistically, inorganically, on services that complement what we do through that critical data lifecycle. All right, so, and actually, we're in our mid-year strategic operating rhythm starts. We've got an offsite coming up here in July where we're going to take a look at what we've seen evolve from the market perspective, what the market needs, the capabilities that we currently have, and how we can extend on those to continue, especially in these areas such as cloud. And, you know, I'm hearing a lot of pain from CISOs on just what you just said, is the promise is there, but we're not quite sure how to implement it.
And that's where a partnership with someone that can bring a program in that is not necessarily tied to at the hip from one technology or another to help solve for those things. So I think that you'll see that. We're— I'm determined, I think you picked on that in the beginning, right, I'm determined that we're not going to be a generalist. Had plenty of opportunities for us to go down that path, and we felt the tug to do that. Will you manage my this?
Will you manage my that? Man, if it doesn't fit into the specialty that we're trying to do, which is around the vital few critical data elements in an organization, then we're not going to do it. We're going to stay focused on what we're great at and what we can be the best in the world at. So, you know, there's other technologies you know, the, like, the Vormetric-type database monitoring that obviously gets right into your critical assets, right? But that's pretty different than anything we've talked about thus far.
Is that kind of the same area you guys are thinking about? Yeah, you're talking kind of the DCAP space? Yeah, sure. Yeah, it's definitely something that we've been looking at and taking a hard look at. When CASB first became a thing, we had a choice to make between DCAP and CASB.
What we found was that more and more of an organization's structured data is being hosted in the cloud. So we can get a lot of that protection from the CASB side. And I think the other thing is, of the things that are still on-premise, depending on who you believe, roughly 80% is unstructured at this point. So there are still databases that exist on-premise, but if you think about all the HR management systems, you think about the CRMs, you think about even things like Epic are being hosted now. If we can do the cloud bit right, I think we're going to get at most of the structured data that's important for an organization that's also exposed.
And that's where they're most likely to want to bring in third parties to help I think for us, too, you'll see us— so we've had a lot of success in the large enterprise as well. So we're looking now at offerings as we're starting to see the adoption and the need for critical data protection programs sort of downmarket, midmarket, if you will. Organizations that maybe traditionally haven't had a requirement or, you know, the loss has not been there for them to have to focus, now it's starting to happen for them too. So, you know, again, either through organic or inorganic means, bringing capabilities that would allow us to expand to those markets as well. What's your— you guys are venture capital owned, is that right?
That's right. What does your investors want? What do they want you guys to do? Yeah, so I think they— I think we're well aligned around continuing the growth around what we do best. And, you know, I actually have a long history with Frontier Capital going all the way back to the days of Luric and through SecureWorks.
So they have a long-term view. So their urgency is not to get out. They have obviously experience having been exposed to both Luric and SecureWorks, and they understand that this problem that we are solving is not going away. If anything, it's getting more complex, and the market drivers are there for, you know, a long-term outcome for them. So, no urgency, you know, honestly, you get calls all the time, but we have no urgency to do any sort of transaction or anything like that.
So, this is about a long-term value creation around solving a critical business problem. And if we focus on that every day like we're doing, then the rest will take care of itself. Yeah. So you guys have roughly 125 people here in Denver. I guess occasionally you have to hire people.
Yeah. Is that fair to say? More than occasionally. Yeah. It's, it's one of those, you know, challenges that everyone in this space faces right now is finding talent.
But being in Denver is a good place for us. And I think we're— it's, it's really cool, the mission that we're on, which is again protecting the vital few. We We stand up every month at our monthly town halls and actually celebrate the big wins for the month. And we have a Golden Nugget program. It's a reward program that's sort of playing off the mining theme in the Rockies.
But it's for the teams that find the coolest kills, if you will, for our clients. That it's actually the clients get to determine how they are rewarded for that, that find. Just last month we celebrated where our team saw that— I forget how many thousands of this, of these records were in the process of being leaked on very publicly well-known people that would have caused this client a lot of damage, both reputationally and a direct cost perspective. And we're able to stand up in front of the entire company and say, look at what coolness that we did here. We have that same story around protecting intellectual property and being able to show that the work, the meaningful work that these folks are doing on a daily basis is combating theft of the trade secrets that when taken overseas to a competitor means jobs leaving and the threat to livelihood.
So that's, that's, you know, as I talk to people about what's cool about working here, it's about being on the good side of that fight. Right? And then being able to, much like clients that work with us can show the ROI, it's because the difference that our people are making on a daily basis is so clear on the things that they're stopping around the most critical data is having a material impact to our clients. It's one reason why our churn rate is so low from a client perspective. It's just, it's because we deliver value every day.
So what, what kind of positions are you guys hiring for here? Yeah, so we have, generally speaking, yeah, generally speaking, we have the Security Operations Center. We're always hiring from that perspective. So anyone that has security talent from, you know, really from the senior all the way down, we'd love to see your resume and find out where you could fit because we're always looking for A-players to join this team to push us forward. Yeah, I think the other thing that I'd like to get the message while we have the forum is that What we do is not just— you don't need an information security degree to be valuable to us or to our clients.
A lot of times business degrees or people who have a project management background or people who have been involved in criminal justice and law enforcement, those types of people can make a difference for us as well because we have both engineering positions, which are your traditional InfoSec type roles. We also have analyst positions that we need a broader perspective. We need— and I think it's a big passion of mine, I'm sure Steven's— diversity in this space is very important to us, largely because it's a diverse workforce that is making decisions every day with critical data assets, and being able to monitor from a variety of perspectives and then be able to make analytic decisions from a variety of perspectives, I think, is important to our long-term growth as well. So when you talk about diversity though, It sounds like you're maybe talking about more than gender and racial diversity, background from a professional and training perspective, all of those things. Yeah, I think, I think it's no secret that there's not enough women in cybersecurity.
It's something that I think we need to address as, as an overall discipline. And I think in terms of racial diversity, that's, that's a thing as well. And I also think that backgrounds and cultural diversity is awesome for us to get multiple perspectives. Because the truth of the matter is, what we're really doing, the real value that we can provide to clients, is qualitative analysis. That's, that's what machines and algorithms to this point can't really replicate, is the human experience and looking through the lens of your experience and saying, why would somebody do this thing that they did?
Does this appear to be something that they did on accident? Are they doing it on purpose? Is this a larger pattern of behavior that I should be looking for? And making those decisions well are historically what lead to our biggest golden nugget finds. Yeah, we love to, love to stay around here.
So we're gonna automate the noise reduction because I want to put the gray matter on the things that matter because that's where the real ROI is for businesses. So in terms of folks who might want to come get a job here, it sounds like from entry-level up to the senior-level folks, and you guys have training programs? Absolutely. We, first thing we look for is passion, right? We want someone that will walk in the door and clearly has a hunger to be a part of something that's meaningful, that has a hunger to learn.
And if you have those 2 things, that probably means you're a go-getter, and we have the ecosystem here in place that will feed that passion, that will feed that desire to learn, and we've got career tracks that will take you in a great direction no matter what background you come from. Yeah, I think one of the things I tell people that are talking about possibly wanting to work here, when I came here I couldn't spell DLP right. I have a diverse background, which we kind of got into before we started recording, but, but, and some of it's security related and some of it's not, but none of it is related to information protection. But I had a passion and a desire to be able to protect our way of life as a country, which comes down to, in a intellectual property protection. Long and the short of it, it's just cheaper to do business other places.
You do business here because you can keep your ideas safe and you can capitalize on those ideas and information. And I, I also wanted to be able to help organizations that were being harmed when they couldn't necessarily help themselves, right? And coming from government contracting and the military space, you wouldn't generally define those folks as us, whereas there's a lot of organizations that just are unprepared to deal with the threats that they face. To be able to help them solve one of those major problems was a major thing that drove me here, but it was the company that gave me the education and the experience that I needed to be actually good at this thing, right? So I, myself and several others around this building, would tell us how much we owe you.
That's great. So you talked about the security operations folks you need. Any other positions that you're generally hiring for that we should keep an eye out for?
Scott, are you hiring?
We— I think positions come up from time to time. I think that there's, you know, types of things you'll see come out, maybe more marketing folks that we may need, business development folks we may need, we may need more project managers at some point, consultants, implementation engineers, software development folks. These are all roles that we fill inside the organization. They kind of come up from time to time. Then your traditional stuff like HR leadership, things like, you know, finance and those kinds of positions.
As we continue to grow, we'll have more need for that kind of stuff. Yeah, when you're growing north of 30%, all of those positions come open from time to time. So we want to see your resume and get you in our database. Great. You know what, I want to go back to earlier technologies.
One thing I was thinking about when you were talking, do you guys Did you guys ever play around in the— was it UBA, end-user behavior analytics? Glad you asked. So one of the things that we're kind of challenging and thinking about right now is— so LogRhythm, a big partner of ours, fellow Colorado company, makes a lot of sense. No matter what we do from a SIEM perspective, we always see LogRhythm as being a key partner, and they get into the UEBA stuff as well as the SIEM stuff. We started to think about what are we really providing from a SIEM perspective, and that's still ongoing, but I think everything's on the table.
Things like Splunk are on the table, things like Exabeam and Fortiscale are on the table from a true UEBA perspective to kind of diversify that offering. So maybe we have one traditional SIEM, one kind of Splunk type of offering, and one UEBA offering to give clients a diversity of choice so long as all those things fit into our mission and as far as that part of our business. I think those are all things we're thinking about. I think the user and any behavioral analytics idea is fascinating. The execution is very, very difficult, and a lot of the companies that are leading in that space are leading either on the endpoint side or the network side, and it's very difficult to truly paint that entire picture without having both of those things converge.
So I don't know if that happens via acquisition or via partnership, but it's something I'm keeping an eye on in order to get comprehensive solution that I think I could put into place. Well, I'm gonna push back a little bit on you and say I think the network side is not the way to put anything anymore. Because I think it's— I think we delude ourselves when we think we're getting visibility at the network due to the remote nature of workforces. And if the better we can do at pushing things to either the laptop or the resource that they're accessing, either way, that's the better off we are. Yeah.
And that's a challenge. It's a big challenge. Yeah. When I talk network, I'm talking stuff like Darktrace. I'm not talking stuff like security analytics.
And that's more towards the resource side, like how do I get closer to the cloud or where is the information? Because the problem with endpoint is there's still very few technologies that extend to the mobile device space, and there's an increasing amount of calculations and transmissions that are being initiated from mobile devices. So I have to, to your point, be close to the source of the data, which traditionally we say things like network, but yeah, you're right. It's, it's how do I get closer to the source of the data so it doesn't matter what device I access it from and whether or not it has an agent on it. The other thing that we're fighting is agent proliferation and, and the need for clients to be able to say, well, I want to cap how many endpoint agents are running on my machines.
And then the other side of the coin is, truthfully, if I want to write an endpoint agent that covers all the operating systems in a traditional enterprise environment, it's a lot of agents I've got to be good at iOS, I've got to be good at Android, I've got to cover Windows Phone for some reason. I might still be developing for BlackBerry OS X, right? I might be on Mac, Windows, Linux, Unix, right? We're talking about a lot of different things, and it's very difficult to be effective at developing software for all those platforms. So I think that's where we get into this space of why CASB and endpoint are both kind of necessary together.
That's the point I'm trying to make in the UEBA space. I don't see a lot of technologies that do well at the source of the information, whether that be the cloud, on-premise, or otherwise, and do well at the endpoint. And I still— I haven't run across a lot of technologies that I feel like do a good job both on the desktop laptop space and on the mobile device space and then can correlate that information together to a single user identity. It's definitely a challenge. The big push that I've seen— you guys, I'm sure you guys have heard of Zero Trust Network networking.
And I don't know if you guys heard about Google's Beyond Corp white papers they've written. It's one of my very favorite things is that the way that they have implemented zero trust and, you know, pushed— they basically pushed everything to the endpoint or the resource, and they no longer have trust based on the network you're connecting from, right? Your corporate network is no more trusted than anything else. And obviously Google has all kinds of resources that the rest of us don't have, and able to do some really cool stuff. But that's the way I'm thinking about how do we push, how do we push away from this perimeter that we know doesn't work but we still use it because that's what we've done for our whole careers, and more into the stuff that in the future can work.
But you're right, the technology is not necessarily there to make it easy for us yet. Yeah, I think, I think you're right though. I mean, I don't— so we do pen testing as a core part of our business, especially since we acquired Intura in 2015. 2015, I know enough of those guys to know that I should not trust a laptop that connects from my network any more than I would trust a laptop that connects from any other network in the world. It's just not a real thing.
So I think that's, that's a very good approach. To me, I like to wrap protections around the information everywhere it exists, and then we can start to do some really cool things. When we get down that path of what we're talking about, and most clients aren't ready for that yet, But when we can have encryption that requires decryption every time you open the file, we can do some really interesting things. Now we can see who's accessing the file, where they're accessing it from, how many times they've opened it. If we ever want to stop it, we can turn it off and they can't access the file anymore.
We can even do even cooler things, like we can say now you have to do 2-factor authentication to open this document, right? Whereas this document, you just have to enter— you just have to be authenticated in some way. And I'd say even cooler yet would be based on a risk score based on the user's behavior and the system they're connecting from and a whole bunch of signals that you're pulling into this risk engine to say, okay, now it's going to be 2-factor, or now it's— no, now we go even a step further and we're going to have to, whatever the next factor for us is, a peer who has to say yes or whatever. I think it aligns really closely with what you guys are doing with critical asset protection. It's just hard right now.
It's hard. There's no vendor you go partner with to fix the problem. Well, it is hard, and it's adaptive security, and we're starting to get there. But I think the key that we're hitting upon is in the new world where the perimeter isn't really a perimeter, how do you define your perimeter or your protections? And if the perimeter has always been all of the places that my information exists, then why not put a perimeter around the information rather than trying to map everywhere the information may flow and then build a perimeter that includes space, right?
Because they're bouncing off of satellites. So our perimeter really is the whole world and then outer space. And so the way I've thought of it is we're protecting the applications that have the sensitive applications, and you're going a step more granular to saying the data in the application, which, you know, the more granular your perimeter is, the more effective it is and the more difficult it is, generally speaking, right? Yeah, and it is difficult, but I think I think the problem is that— and Steven's kind of talked about this concept of focus and this idea of protecting what matters most is a core idea for us. And it is hard, but that's why we're telling you, you don't have to protect every piece of data in your environment.
You have to pick which piece of data you're going to apply this special protection to. You're going to focus on that, because the truth of the matter is everyone has more information than is vital or necessary or could be harmful. And making sure that we can protect the information that matters with a special level of protection, and then everything else just has a base level of protection, I think is the way forward in this new world that we're living in. That sounds right. Well, I, you know, we're coming to the end of our time here.
I'll ask you guys, anything, final words you want to talk about TeleSecure, personally, the Denver community? What do you guys want to talk about? Well, so, you know, You know, I've been here now spending most of my weeks in the Denver community for going on a year, and I can say it's been a fantastic experience. So the people that I've met, it's a really great place to live and work. The talent that we've been able to bring in the door here in the Denver office has been awesome.
And, you know, I think that, you know, what a better place to work where you can look out your window and see the Colorado Rockies. And on top of that, hey, even though the Broncos The Broncos kind of, you know, came off the Super Bowl win and then had a down season. The Rockies baseball team have kind of stepped up. So out of nowhere. Yeah, right.
So from a life experience, it's been fantastic. And yeah, it's, you know, everything we talk about from a business perspective, it just remains true. It's a great environment for us to be in here in the Denver perspective, Denver location. That our focus on the things that matter is— and really trying to move businesses off of the paralysis of trying to do everything and focusing on the things that matter and getting their organizations moving forward. And then being able to show the clear return on their efforts by just focusing on the smallest.
Pareto, right? The small vital few have the most impact. And partnering with organizations over the last year has been really fun to see that progress. So, Jeremy? I'd just say that I'm not a Colorado native, but I've spent my whole life trying to get here.
When I got an opportunity to join this small company in Castle Rock, I have to be honest, I didn't know it was going to grow as fast as it did, but it was the best decision I've ever made in my life. Yeah, and I can tell you, from being from Atlanta, the humidity out here at this time of year beats the heck out of Atlanta. You're lucky to be here in the summer. That's right. Well, all right guys, I appreciate your time.
We'll look forward— maybe we can get together in a year or so and check where you are and how things have changed, and you can, you know, give us all the new news. Absolutely. We'll keep an eye on your press releases and your blog, and we'll share what— Thank you, Rob. All right guys, thank you.
Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.