All episodes

Patrick Walsh

Apple Podcasts Spotify SoundCloud

In this episode:

Patrick Walsh, CEO of IronCore Labs is our feature guest. Plus bad news from root9B and DirectDefense, and good news from InteliSecure, Optiv, Target, Oracle, Denver Startup Week, and WebRoot.

Will root9B be around for next quarter's Cybersecurity 500 list?

"Welcome to the world’s largest pay-for-play data exfiltration botnet." That's what Colorado's own DirectDefense said about Carbon Black this week. And root9B, the public security company in Colorado Springs that's topped the Cybersecurity 500 list for the last 6 quarters, is in dire straits. Creditors are planning to auction their assets on August 31st. More routine stories include: Three Colorado security companies made the Inc 5000, Target brings next-day delivery to Denver, Gail Coury and ISSA COS get recognized, there WILL be a Cybersecurity Panel at Denver Startup Week, WebRoot makes an acquisition, and a chance for you to help out students at Red Rocks Community College.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Patrick Walsh is the founder and CEO of Boulder-based IronCorp Labs. They just made it through the TechStars program and tells tales of the experience. Patrick has had a great career, and shares his learnings along the way.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11566 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 29, the week of August 21st. Alex, uh, how you doing this weekend?

I'm doing well. How about you, Robb? I'm doing great. Now, you probably haven't heard this, but there's actually some kind of solar phenomenon going on tomorrow. I've heard it's going to be a little dark.

It has something to do with the lack of security that's going to overwhelm the Sun and blot out light to the planet. Interestingly enough, though, you know, obviously, we've all heard about the solar eclipse. It's every— what's happened 38 years ago, most recently.

Everyone's going to be driving up to Wyoming to go get the best view of this and all that. But what is it that the temperature is supposed to go down by, like 25 degrees? Yes, something crazy like that. Supposed to be mass chaos, dogs and cats living together, end of days, end of days stuff. So that's pretty good.

All right, let's go ahead and jump into the news for this week. Before we start, you know, I can see you're wearing your Colorado Equal Security t-shirt today. I am. It's my regular Sunday attire. I love it.

We've got a beautiful web store link on the website. You should go check it out and buy some Colorado Equal Security swag. Wear it yourself, give it to your friends. You know, we've got all kinds of different things. Put it on your kids, slap it on your car, sticker on your kid's head, t-shirt on your car, yeah.

All right, diving into the news. We talked about BP coming into town. We mentioned that they're moving their North America headquarters to Denver, and we also mentioned a few weeks ago that they're, they're hiring in town. And it looks like they're actually hiring about 200 people in their new Denver headquarters. Yeah, pretty cool.

Um, at least one of those jobs is a security job. Um, I believe we talked about it once, maybe a while back, or, or a similar job, but it's a, uh, a security architect job that they're looking for. And we're going to talk about that, I think, at the, uh, the end of the show as well. Yeah, I actually put that in the, in the show notes as well. Target is extending, is expanding their next-day delivery into Denver.

So we talked about Amazon doing their 2-hour delivery. Target has a similar program. Where you can, if you buy enough, I think it's $25, they'll deliver to your house the next day for $5. Yeah, it looked like you'd fill up a box with a certain amount of weight of stuff and they'll deliver it to your house the next day. Pretty cool.

Yeah, up to 45 pounds of merchandise, basically a cart-sized box, and have it delivered for $5. So the Inc. 5000 list, which is a list of fastest-growing companies, came out and there were 113 Colorado companies on there, including some security companies, Direct Defense, InteliSecure, and Optiv. Yeah. So pretty cool to see those companies growing. We will talk more about Direct Defense in just a moment.

But before we do, we had some, some sad news this week. Well, look what potentially looks like sad news. Well, either way, it's not great news. Route 9B, who we've mentioned just about every week on this show, kind of out of nowhere as far as I'm concerned, is there. They have their assets scheduled to be auctioned this week.

Yeah, so it looked like this is more a business-related matter. They had been expanding, I think, pretty aggressively over the last couple of years, and it sounds like the revenues that they were trying to generate did not match up with the amount that they were spending to expand. Yeah, they are a public company, so all this information is publicly available. Their annual revenues were only something in like the $6 to $7 million range, and they had, I think it said 150, 158, somewhere at 150 employees, which is a ton of employees for that kind of revenue. If you're talking about US-based employees, it's just the math just doesn't work.

So it makes sense. They've been expanding very aggressively, hiring very aggressively without necessarily having the revenue to match for it. We've tried to reach out to them a couple times to get them on the show. Maybe this explains why they haven't had the time to respond to an email. But anyway, nonetheless, sad news, especially for all those who have jobs there at Route 9B.

You know, hopefully all works out and someone swoops in and either gives them funding or they get acquired by a benevolent owner. Yeah, much better than just auctioning off assets. And then all those folks are out of work. So yeah, definitely sad news there. So next on the list, as Robb alluded to, Direct Defense has been in the, in the news.

There's been a dustup between them and Carbon Black. So Direct Defense asserted that there's an architectural flaw in Carbon Black. Essentially allowing people to— I don't know, what was the quote, Robb? Well, the quote is, welcome to the world's largest pay-for-play data exfiltration botnet. That was how they referred to Carbon Black.

Yeah, so basically a feature of Carbon Black is that you can upload files to VirusTotal, I believe, potentially some other sources where you'll— those files will be examined against, you you know, known bad things. And when it gets uploaded there, it generally stays there. So if there's sensitive information in whatever it is that you're uploading, you've now essentially given away your sensitive information to see if it's bad. Well, so there's a, there's kind of a good news, bad news here on this for Direct Defense. The good news is for them, previous to this, I didn't even know they were a Colorado company.

They're in the Tech Center, I think it's at Englewood. And now everyone knows who they are. Bad news is I think that they'd have unethical and illogical and just basically terrible business practices at this point. They go out there and they, they pretend that Carbon Black is a data exfiltration botnet. That's a direct quote.

Um, when what we're talking about is a non-default option in Carbon Black where if you try to turn it on, an alert pops up and tells you if you send these things to VirusTotal, they will be available on VirusTotal. Like, they're, they're educating their, their users as you do it. Uh, the expectation here that, number one, they didn't reach out to Carbon Black ahead of time, so they didn't follow responsible disclosure steps here. And then when they were confronted with it, they didn't, they didn't back off at all. They stayed, oh, absolutely, this is an architectural problem that they did, and we needed to raise awareness of this, versus really doing it the responsible way.

So anyway, I, I couldn't have much less respect for the way they handled this. Of course, if they want to get on the show and talk to us, be happy to. But I can't, I can't see a real logical reason for doing it this way. Well, I guess as they say, all press is good press. Who knows if that's true, but we're definitely talking about Direct Defense.

We are talking about them for the first time. Snowmass Village, move on to the next bit of news. Snowmass Village was hit by a phishing attack. And I think it was actually last month that cost them about $60,000. There's not a lot of details in the article about specifically what kind of email it was.

It It looks like it somehow was related to them sending some construction costs out, and maybe someone knew there was a construction project and, and had sent a phishing email. But anyway, there's an impact to the city there. They did have cybersecurity insurance, so versus the $60,000 outlay, they're only going to have to pay about $5,000 of that. Yeah, based on the article and sort of reading between the lines, it looked kind of like a business email compromise. Someone got tricked to send money to the wrong place.

You know, the FBI has been talking about this a lot lately, multi-billion-dollar scams going on around that, lots and lots of losses for business email compromise or email account compromise. So sad for Snowmass Village, but it sounds like they're going to make it through. Gail Curry has been named to the ISSA Honor Roll, which is a great honor for her. This is sort of like a lifetime achievement award that ISSA gives. So Gail was, uh, Gail is the CISO for Oracle Cloud and Gail and her husband Steve were on our show.

Was it week 3? I think really, really early on. Um, absolutely. She's a great leader here in town. Big congratulations to Gail for being recognized.

She's done a lot of work internationally as well as locally here. Um, she's been on the Women in Security International group. She's been on the CISO Advisory Group internationally, and I'm sure she's done a bunch of stuff that I don't know about in addition to that. Yeah, yeah. Congratulations to Gail.

Also, the ISSA Colorado Springs chapter has been named Chapter of the Year for large chapters. So congratulations to them. Good work down there. Congratulations to Colleen. We also had Colleen, who's the president down there, on the show a few months ago.

Congratulations on being recognized there, guys. So we talked in the past, it was a few months ago, we were talking about Denver Startup Week and proposing a panel around Denver security startups and having those, the founders of those companies come together. Well, uh, good news is we've officially been added to the schedule. Um, so if you're interested in coming and hearing from the startup, the founders for ProtectWise, and, um, and I'm gonna, I'm gonna blank on Red Canary, a couple others that we have slated to do that, you can come on Wednesday, September 27th at 11 AM. It's part of the Bootstrap I don't know what you call it, track.

Um, but anyway, that's, that's good news and looking forward. I'll be moderating that, so, you know, there'll be a few, uh, a few jokes and probably a few, uh, references to Colorado Equal Security thrown in there. Of course. Um, so Webroot made an acquisition this week. They, uh, they purchased the company SecureCast, which is based out of Oregon.

Um, the headline bills to fix the securities industry's weakest link, humans. So SecureCast seems to be a, you know, a PhishMe or a Wombat or one of those where they do training materials as well as, you know, phishing exercises and things like that to make sure that people know more about cybersecurity and are less likely to get tricked. It's kind of an interesting add-on for Webroot. You know, they've for a long time been one of the leaders in consumer endpoint AV, you know, security. They've added on threat intelligence, I think pretty successfully, but this doesn't really align directly with either of those.

This seems like kind of a new area for them to be branching off into. Kind of curious how it fits their strategy from the big picture. Yeah, maybe we can get a Webroot person on the, on the show and talk strategy. Yeah, it'd be interesting to know. I know that they've also been focusing pretty heavy on IoT security.

At least that's what Dave DeFore has been focusing on. Yeah, for sure. So I don't know if they've productized that either. Interesting stuff going on over there. Finally, from the news perspective, Red Rocks— we talked about Red Rocks Community College having won second place in a National Science Foundation competition a while back for having created a cybersecurity lab.

I had the chance to meet with 2 of the guys, actually the 2 main guys who had put the lab together and gone through the process with that this last week. Really interesting guys, Bruno and John. Thanks for taking the time to kind of tell me what you guys are doing there. They've created this— it's really just a hands-on way for students at Red Rocks to learn security. In a, in a better way than, you know, reading a book.

What the, the net of it from my perspective was is they really could use community help to get hardware for this lab. They've only got a couple of different switches. Of course it's old stuff. They've got a couple servers. They could really use support from the community to, to equip that lab.

So I asked them for a list of what they could use, and I'll just read out what they need. And if you guys have any extra hardware that you guys can donate, it would be fantastic. Um, so they're looking for servers, they're looking for storage, um, uh, any SAN, any NAS storage in addition to, to actual hard drives itself, switches, routers, firewalls. You know, if you have any, any commercial stuff, that would be awesome— Cisco, Juniper, Palo Alto, whatever you've got— any security appliances, um, cloud service credits. So if you guys have the ability to help out with them getting some access into to AWS, Azure, Google Compute, you know, even Rackspace, whatever you guys have access to would be fantastic to help them get that, you know, broader coverage.

And I'd say if you are with a security company and you are listening to this and your company wants to donate stuff, you know, if you are a Palo Alto or a Cisco or something like that, I'm sure that they would love to have direct donations from the company as well, not get sort of the secondhand stuff that the— that most of our listeners might be able to donate, but rather something that's even newer. Yeah, and I've also, I gave them some suggestions about some free stuff out there, and I specifically mentioned local, you know, LogRhythm's NetMon freemium is a good thing for them to start looking into, but any of the local companies who can help them out, that'd be fantastic. So that's the news, but we did want to mention some less trafficked pages on our website, so stuff that is great resources out there that we don't necessarily talk about as much, but we have, you know, 2 big pages: the companies pages, which is, you know, Colorado-based security companies. It's not an exhaustive list, but it's still a pretty darn big list. And our local organizations page, so that's, uh, groups like ISSA and Cloud Security Alliance and ISACA and other groups like that that are around town that you can go to network and learn with.

Yeah, so there's, there's somewhere in the ballpark of 30 different companies on this Colorado security companies page. And for each of these companies, we have a nice, you know, short description, maybe one paragraph saying what do they do. And then we have links to their corporate head page, their press releases, and their jobs that they have available. So if you want to just learn quickly about what the Colorado security ecosystem looks like, that's a good place to take a look. So let's jump into events.

Also on the website is our event calendar. So if you want to know what's going on around town, check out the events page on colorado-security.com. The first event that we have on the list is from CTA. They are doing their CTA 101 on the 22nd of August. This is just sort of understanding what CTA is and what they do.

On the next day, the 23rd, uh, the Cloud Security Alliance has their August chapter meeting. That's going to be in the evening on the 23rd. Appreciate, you know, they've, uh, they've moved their schedule just a little bit and it looks like they're not going to be conflicting with ISSA going forward. So if you're downtown, you can go to both. Going forward, it looks like.

Um, SecureSet is putting on an event, Securing Your Digital Health Company, on the 23rd of August. Uh, I know Drew Labbo is participating in that, um, as well as one of the startups that's in the accelerator, accelerator over there, Dash, who's trying to automate some HIPAA compliance. Nice. On the 25th, SecureSet is also doing a hackathon, which we talked about a little bit last week. Uh, on the 29th, CTA is doing a SIP and Connect Sounds like drinking and networking.

It's probably not the kind of networking that most of our folks are doing, right? That's true. Probably no network cables involved. SecureSet on the, on the 30th is doing a Hacking 101 Girl Develop It workshop. Go girl.

You go girl. And then on the 30th and 31st of August, the ISSA Colorado Springs chapter is doing one of their really big events for the year. This is the 7th Annual Cybersecurity Training and Technology Forum. This is obviously down in Colorado Springs, a big conference that they have going on, 2 full days worth of stuff. If you're an ISSA Denver chapter member, I believe that you can get free admission.

Obviously, if you're a Colorado Springs chapter member, I'm sure that you get the same, but they're going to have some, some good content down there. So if you're interested, go check that out. I know, speaking of the good content, they do have Gail Corey, who's going to be doing one of their keynotes, and they have John Harbaugh, who's the Chief Operating Officer for Route 9B, scheduled to give a keynote. It'll be interesting to see if he'll be able to be there. That's— yeah, I think that's the same day that their auction is scheduled.

So if that goes forward, I'm guessing he won't be able to make that. And then they have Brett Kelsey, who's the Chief Technology Strategist for the Americas for McAfee. And then Dale Maryrose, who is the mayor— excuse me, Major General of the US Air Force and the president of the Maryrose Group. At this point, he's a retired general. Gotcha.

And then the final event that we have coming up in the next 2 weeks, National Cybersecurity Center is putting on a first responder cyber exercise on the 31st. So this is getting first responders more up to speed on cybersecurity. I will actually be giving a talk, a short talk on the NIST Cybersecurity Framework there. So, and that's in the Tech Center, it's not in the Springs, right? Yeah.

And so if you are a first responder, then go ahead and check that out. Could be interesting for you. Cool. All right, let's go ahead and jump over to jobs. As a reminder, we do have links to all of these jobs in the show notes.

We don't put them directly on the website because they change so quickly, so you got to go to the show notes and find, find these jobs. Um, MarkWest Energy is hiring an enterprise security architect. This is, this is reporting to Rock Lambros. Rock is our friend over there, and, and we sent him a note and asked him, well, what are you looking for here? So he's looking for someone who has experience in securing operational technology.

So for those who aren't aware, there's, you know, the information technology, and operational technology is more the, uh, the, the real life, the physical stuff. So, you know, the computers that, that make gas plants work and so forth. Um, it's looking for someone who's, who's worked in an OT, an operational technology environment, using SCADA networks and are not afraid to get hands-on with security tools— firewalls, IDS, SIEM, etc. Experience with the convergence of IT and OT is definitely a plus. Sounds like fun.

Uh, next, Frontier Airlines is looking for a senior network security engineer. Assured— excuse me, Assured Information Security is hiring an advising computer engineer. So AIS, Shared Information Systems, is where Jacob Torrey works. So I've got to know those guys over the years. They do really interesting stuff, very cutting-edge technology.

They're, they're doing good research. They're turning that into actionable, practical, practical stuff. Good place to work if you're looking to kind of use your brain and do some, some more advanced stuff. Yeah, if you read the job description, it sounded like they're doing some really cool stuff based on that. Uh, next, Kaiser Permanente, um, they actually had a few job postings this week, but the one that I put in here was this analyst cyber risk defense.

So if you're looking to be in security operations, they— looks like they need some folks for their security operations center. CU Denver is hiring an instructor in information systems. This is a neat opportunity, get to go learn, get to teach the next generation. I assume that having some hands-on security experience would be a good thing, but I haven't looked too much at this job. Yeah, and actually, it could be multiple areas, but one of those areas was cybersecurity.

So if you wanted to teach general IT, you could as well, but this is sort of a graduate-level position. Navigant, they had a number of jobs this week as well, but they're looking for a senior consultant of information security and forensics, legal technology solutions. Interesting, so they're looking for someone to do incident response and stuff like that. Essentially, yeah, so Navigant has a big incident response practice, So that looks like they're hiring some folks for that. Westech is hiring a robotic network security engineer.

You know, I didn't look too deeply at this job post, but the title alone got me. If you're doing robot security, then you're pretty cool. Well, are you sure that they're not just looking for someone who's cyborg, that is a robot? Maybe they're looking for a robot who can do security. They're looking for a robotic engineer.

That's interesting. And then finally, Deloitte is looking for a senior data protection security analyst. So if you want to work for a big accounting firm on their security side, take a look at that. Awesome. Well, that takes us to the end of the jobs, the end of the podcast, I think.

Well, the end of the newscast, that is. We're about to throw it over to the interview. This week I sat with Patrick Walsh, who's the CEO and founder of Ironcore Labs. Ironcore Labs, the short snippet description of what they do is they do encryption as a service much the same way that SendGrid or Twilio are services that you can call with your product. They allow you to outsource your encryption and really keep it so that the SaaS provider doesn't have access to the keys.

They just got through Techstars as a Techstars company. We talked with Brad Feld, who's the founder of Techstars, a month or so ago. So I got to ask Patrick a lot of questions about what was it like to go through Techstars, what was the value add, was it worth it, all those interesting facts, and he shared quite a bit. I look forward to hearing it. All right.

If we— if the world doesn't end as part of the eclipse, then we'll talk to you all next week. All right, guys, have a great week. Hello, this is Sean Murray. I am a director on the International Board of Directors for ISSA, and I am a principal scientist at Northrop Grumman Corporation working in Colorado Springs. This is Colorado Equals Security for Colorado security professionals by Colorado Security professionals.

All right, this is Robb Reck with the Colorado Equal Security Podcast. I'm sitting in my office today with a new friend, Patrick Walsh, who is the CEO and co-founder for Ironcore Labs. Patrick, you and I hadn't met until, what, 5 minutes ago? Yeah. So looking forward to understanding, you know, first question, what is an iron core?

The abs I wish I had. They're there, they're just underneath the— underneath the— ultimately, Ironcore is It's a company that's focused on fixing security from within the application. I think that's the major underserved problem in security in general, is that almost all of the attention goes to the areas outside of the application, to the network perimeter, and we're focused on fixing it from inside. So you could think of us like a Twilio or a SendGrid for application developers who need to add security into their application. Yeah, I'm looking forward to understanding more about that.

Hey, let's back up a little bit first. It sounds like you've been doing security or working in the security industry for a while. How did you get into security and what was your start? Well, security is probably really responsible for why I got into computers in the first place. And so to me, breaking things is always a little more interesting, maybe.

And so as a teenager, I definitely jumped in on the hacking stuff and was extremely interested in how to break things back in the day, before the internet. So started before the internet, uh, phone stuff then, or— so yeah, bulletin boards. Um, I, uh, I managed to get— I don't know if I should tell this story, but I managed to get onto a, uh, a Warez site back in the day, which is— was you'd have to, you know, have a phone number and have someone vouch for you, and you dial in, and then there would be software you could download so you could play with, uh, software that you couldn't otherwise afford. And, um, on that site there was a bit of software that was the bulletin board software, was the source code for Wildcat BBS back in the day. And one of my first things that I ever did was to play with that source code and then upload it to that site and other various sites.

And then before long I could pretty much dial into any bulletin boards. You backdoored the software, right? Interesting. Where were you located back in California? What part?

Northern California. I grew up in San Francisco. I'm from Redwood City. Oh, nice. A neighbor down the peninsula from you.

Cool. Very cool. How'd you get to Colorado? If I'm being honest, I chased a girl. Me too.

Did it work out? It did work out. She's my wife. There we go. We're 2 for 2 here.

Yeah, absolutely. Yeah, I came by way of Boston. So as most of you, at the time I came to Colorado, which was 2004, I was coming from Boston. Yeah. And so you've been married for a decade plus then?

Yeah. Yeah, I guess. Yeah. 12 years now. Congratulations.

Thanks. That's great. So you chased a girl out here and did you have a job? I didn't. I didn't.

I figured that out after I got here. Yeah. Good for you. What did you come out here and do? I got a job with a company called eSoft, which was a Colorado company that did unified threat management boxes for small businesses.

So They basically pulled together antivirus and anti-spam and intrusion prevention stuff into a little turnkey box that was moderately successful. They were basically the first ones to break into that category, but unfortunately got eclipsed by Fortinet and SonicWall and kind of always struggled in their shadow ever since. So I was there through, uh, in my tenure there, which was a number of years, I worked my way up to CTO. And, um, in that time we started taking, instead of like packaging other people's software, we started building our own. So we built, um, an antivirus lab.

We basically took ClamAV and we, we had some folks overseas who worked on signatures and we added a bunch of plugins to that to enhance its detection capabilities. Um, we did, uh, our own anti-spam. We did web filtering. We built an automated web categorization system, and that would look first for threats. We had like, I don't know, 6 different categories of threats.

Um, and we had like— by the time I left, I think we had a total of 63 categories. So it was kind of everything. So we were just categorizing the web. Um, that was pretty cool, and that spun out into its own company, um, yeah, around the time that ESOF sold. What company was that?

Is that someone still around? It is. Zvelo. They're a Denver company, and they're still kicking around doing— selling web filtering. Um, yeah, is that V-E-L-L?

It's Z-V-E-L-O. Z-V-E-L-O. All right, so, so what— when did ESOF end up getting sold? It sold to private equity in, uh, 2010, and then later to Untangle. Okay.

And when did you— when did you— I left in 2010. Okay. Yeah. So I went to— I went from there to a company called RightNow Technologies, which did enterprise cloud software, and, and had a pretty good ride with them. I headed up a $40 million a year product division on the engineering side, and we sold to Oracle for $1.5 billion in the end.

Well, that sounds like a pretty, pretty happy ending. Was. Yeah. Yeah, that was a nice ride. And when was that?

Uh, Oracle, um, 2012. Okay. And I was there from 2012 to 2015. Oh really? You said you were an Oracle guy for until a couple years ago.

3 years is the period that you ride out. Yeah. Okay, got it, got it. That's, that's how long it had to be. Uh, and then I have nothing bad to say about Oracle.

2-year, you know, you've had 2 years. And when did you Is that when you started Ironcore Labs? Mm-hmm, yep. And let's talk about that. Where'd that come from and what are you doing and who are you doing it with, I guess?

Yeah, it was the chief architect of our division is the guy who co-founded, of our division at Oracle, which was some 400 developers. He and I spent a lot of time architecting and working out how to build more secure cloud software. And we started to realize that we were building on top of foundations that weren't as good as we thought they could be. And that, you know, ultimately, if you were going to build enterprise software, if you're going to start a modern foundation for enterprise cloud software, that it should really start with encryption. And you should be encrypting all the data by default and not just the occasional field and not just— instead of encrypting it like with one key for all the data, instead moving to a level where the encryption complements the permission system such that literally only people who are permissioned to be able to access data can unlock it.

And as we started to think about how we might want to build our next enterprise system, we started to realize that, you know, the security layer itself was a product. And that brought me back to security. So I'm trying to figure out how you implement that. How do you operationalize this? This concept.

So tell me about it. What do you guys do and how do you help people build more secure apps? So, you know, our— I'll take it from a solution perspective. So the solution that we're offering is something we call customer-controlled data. More commonly, people know of this as customer-managed keys.

So a lot of especially large enterprises today are very hesitant to move to the cloud. And that's— if you look at spending in 2016, 75% of of application spending was on on-premise software, on-premises software, 25% in cloud services. So that even though it feels like everything's moving to the cloud, if you look at the dollars, the vast majority is still trapped on-premises. And why is that? It's because of privacy and security.

And the idea of customer-managed keys is that the data is encrypted, the data is stored in the cloud, but the customer controls the decryption keys so at any time they could cut off even the vendor's access to it. They can manage who gets access. And in practice, that sounds awesome, but in practice it's often not that great. It's like one key for all the data, every request requires a callback to the enterprise. That's how Box implemented it, for example.

In our world, we handle everything— the key management, everything— in a zero-trust system so that as a developer You drop in this SDK and then, you know, before you save a piece of data to wherever, to your database if you want to or ours, before you save a piece of data, you make a call that encrypts the data and shares it with whoever makes sense to share it with. And before— after you've retrieved it, before you use the data, you make a call to our SDK to decrypt it. And if your— if the current user's private key is able to decrypt it, then they get access, and if it's not, then there's a backstop. So what ends up happening in a system like this is, one, the vendor may or may not be trusted. They could be zero trust.

We, Ironcore, are always zero trust. It's PKI, so everyone has their own key, and we can revoke that access at any time and have a system of provable security, which means that we know for for sure who is able to unlock that data and which keys are able to unlock that data. So it's kind of a cool system. It drops in pretty easily to an application. Most people would use it specifically for sensitive data like, you know, personally identifiable information or financial or health records or things like that.

Yeah. Really almost anything that requires— So how does someone integrate it with an existing application? So it's a code-level integration. So we're like, you know, I think I said this earlier, but you can think of us like a SendGrid or Twilio. We're an online service.

All the key management, all the public key management stuff is done by our servers. And it requires a few lines of code. So depending on the complexity of the application and how many touchpoints there are, when you encrypt the data, any endpoint or user that needs to be able to access that data will have to be permissioned to do so and will have to have a key and will have to have client-side code, which could be on a server, by the way, but, you know, in that case, the server is a client of the data that can call our SDK and decrypt it. And where are you guys as a company right now? Is this product in production right now?

It's in pilot. So we're working with a select set of customers right now piloting it, and we should be launching, you know, stay tuned. What does in pilot mean? Have you got folks who are actually using it in their production systems at this point? In staging environments.

Okay. And what's your timing for— you want to share that timing for when you're hoping to unveil it and have it ready to go? I would say look for it later this year. All right. So I heard from you through Alex Krylan over at SecureSet.

So why don't you tell me, how are you involved with those guys? Um, yeah, you know, we're not heavily involved. They're really great in the community in terms of hosting events, and so we see them there all the time. Huge fans of SecuraSet. We're supporters of theirs, and, uh, um, you know, and just know them through the community.

Sure. Um, all right, well, let's talk about where— what problems do you think you guys are going to go look to solve? What are the ideal, um, target customers that that you guys are gonna be able to work with, you think? So those kind of mid-sized to large cloud application providers who are selling to, or trying to sell into, the enterprise. Yeah.

That's our sweet spot for our market. So, you know, an ideal customer for us would be Dropbox, or Slack, or someone like that. Where, for example, Slack, right, they lose frequently to HipChat for on-prem, which has an on-prem kind of competitor. And we would argue that a big reason for that is because of the security and privacy concerns. If they were to be able to— if they were to give their customers control of their data such that it was always locked, Slack was still able to do what they need to do.

So for example, they could have one-time decryption access to each message so they could expand the link, they can make a change, whatever, and save it. But the persistently stored data then could only be accessed by authorized users and not by Slack. And in that scenario, for example, if someone came with a warrant to talk to, to say, hey, we want company X's, and let's say, I don't know, Ford is their customer, and we want Ford's, you know, chat records. Right. Well, they, you know, Slack would have to be like, we don't have access to them.

Right. Go to Ford. That's the type of thing that we could enable for a company like that. Right. That's great.

So I think we have a pretty good understanding about what you guys, you know, problems you solve. I'd love to just hear your entrepreneur story. You know, this is— sounds like this is your first time starting, starting a company. This is my second. This is my second startup as a company, as a CEO.

What was the other one? My first company was called DynaQ, and I started that in college, um, and, uh, in '98. And so we pegged my age for you there. Um, and, uh, we did, you know, what at the time we called expert systems. You'd call it artificial intelligence or something like that these days.

And we had a generic system that we used initially. We had a bunch of customers in the, uh, um, environmental space doing things like, uh, checking to see if environmental designs met energy efficiency standards and things like that. And, uh, and we moved into a customer service space, and we're doing reasonably well there. We were a profitable company and having trouble raising financing back in those days in 2000 era when we— when people with ideas were getting huge valuations, we were getting valuations based on our revenue.

And long story short, there were probably many things we could have done to avoid this fate, but when the dot-com bubble burst, it wiped us out pretty, pretty hard. We had a sales pipeline that we didn't really fully understand had dried up until— I wish we had reacted more aggressively sooner in that scenario. Does that mean just cutting costs, basically, when you say— Pivoting. I mean, I think, you know, so we were selling into customer support, and our value proposition was, hey, look, you can make your level 1 people as good at solving problems as your level 3 people. We can, we can train it on what the level 3 people are doing, and we can bring that to the level 1 people so you can more cheaply and more quickly resolve customer problems.

That was effectively what, what we were doing there. But the technology that we built could have been applied in a lot of different ways. We went there because we found customers there. And when, when dot-com, when the crash was happening, customer support departments got pinched really hard, like the big tech companies. Um, we had a couple, like, very large enterprises that we were pretty advanced with, and, like, our contacts, the head of customer support, people like that, were getting laid off.

They were significantly cutting their department. We're like, we could— we can make you more efficient, this is still going to be good. But the fact is, there was no money for anything. Like, so even if it would have saved them money, it didn't matter, right? They were in crisis mode.

And, and I think that's the thing that— I think there's probably several things, but That's what, when I think back, I think we didn't react soon enough. We should have switched into some other application for our technology. So 2001, was that when you guys shuttered the business, I assume? Or 2002? More or less.

2002 is when we had to let everyone go. I kind of tried to keep it going a little bit on the side for a while. We tried to pivot when, you know, with not much money in the bank on that while I did consulting. I think it was officially shuttered in '03. Okay, so, you know, call it 12, 13 years between, you know, the end of your first business and when you decided to spin up another one.

What are the lessons you took from working for small, medium, large enterprises in the interim that you think is helping you do better here with Ironcore? Yeah, I was really deliberate about that. I always knew I wanted to start a company again. Yeah. Always had lots of ideas.

It was always the guy who's running hackathons in the organization and stuff like that. And, um, to me, it's just everywhere I look there's opportunity. And one of the things I wanted to do was with my next company, I wanted to make sure that whatever we were doing there, it was mission-based. It was something where we're going to make, make the world a better place. Um, and I spent a lot of time thinking about like, how do we fix— how do we solve the world's, you know, water problems or these other problems that we see.

And I'm a software guy, and a lot of those problems don't directly impact me. So I found it really challenging to come up with good business ideas around some of those things. But security is something I know really well. You know, I've spent a lot of time on a lot of different sides of that, a lot of different angles. And consequently, that's sort of what I come back to.

And when I think about security, I think, oh God, it's such a noisy market. There's so many products, and they all kind of sound alike because everyone makes the same marketing claims. But then when I look at it from the engineering manager standpoint, it's like, wow, there's nothing. Hmm. You know, there's, there's, there's a, you know, what do you use if you want to do encryption, for example?

OpenSSL? Are you crazy? Like, the world— and forget just encryption, just in general, building secure applications, starting with a secure foundation to me is a wildly underserved area, and applications to my— you know, everything comes back to applications. When there's a hack, something's somewhere, whether it's a misconfiguration or anything else, it goes back to that. So I feel pretty strongly that there's this huge opportunity, and it's a way to make the world better.

You know, you look at IoT, like, are you kidding me? People are just connecting stuff to the internet without a second thought, right? You know, if they were building on on top of something where they didn't have to think about it or understand it as well, we'd be in a better place. Build better frameworks, build better tools, make it easier to do it right. So that's the vision, right?

What about the implementation? Did you guys go get funding for this? How are you standing up a company? Yeah, well, we recently graduated from the Techstars Boulder program. Okay.

And we closed, we announced in May that we closed our seed round. Uh, got a bunch of money, um, to pursue the vision and, and go after it. Yeah. So I had the chance to, to sit with Brad Feld at one of these interviews a month or two ago. Yeah.

Uh, learned a little bit about Techstars. Why don't you— I'd love to hear more about that from, from your perspective as someone who's went through the program. And, you know, what are the value— what's the value for you going through it? And, um, yeah, go start there, I guess. You know, when, when we went into the program, we were not sure if it was right for us, to be honest with you.

I mean, you know, they ask, they want a chunk of the company, right? Um, you know, a lot of what they give you is— I think, I think there's a big difference between, uh, we're sort of more mature entrepreneurs, we've been around the block a little bit, you know, and so there's a big question about how much are we going to get out of it. That, that anyway was our thought process going in, and, and we ended up thinking, gosh, we really want to understand what, for example, SendGrid did right and what they did wrong. We want to avoid going down the blind alleys of things that don't work, especially in selling to developers. Yeah.

Um, and so, uh, and, and also, you know, we discount— so there were several things we discounted in thinking about it. Um, one of the things was kind of the doors that it opens. So I had this sort of, oh, I don't know, maybe it's almost egotistical opinion that I could, I could pretty much, you know, get a meeting with just about anyone, especially like within Colorado. Um, and so I discounted that, but, but it's, it was really interesting going through the program. First of all, it's like top-notch, and they do an incredible job.

They do a fantastic job of matching you with people who are like uniquely qualified to help you, who've been in your shoes, who have incredible advice. And, and where you might be able to get introduced to them beforehand, meeting meeting them through the program, there's something about that where they just really lean in. So there were even a couple people who I met before, and meeting before, they, you know, be like, oh, you know, that's what you're doing sounds really interesting, you know, let me know if I can help or whatever, right? In, in the Techstars framework, meeting them there, there's this real lean-in thing where it's like, and I have 3 ideas on ways I can help you, and I, you know, I'd be happy to go off and go make some introductions. You know, they're coming up with those ideas, they're leaning in and helping they have expectations on them that they are here to help you succeed, right?

Right. Versus just somebody who you run across. And that's amazingly powerful. And the whole give-first thing, Brad Feld and the Techstars group and these folks, this idea that, um, it's not that you're being altruistic necessarily, it's that you're, uh, you know, that you go in and you give and you'll get back in return for having done that if you, if you contribute well. And, and setting people up to do it that way It's hugely powerful because, so when my first company, you know, we were constantly under siege, I feel like, from service providers and other people who were, you know, or just like business consultants and people, and they'd be like, oh, we'll help you, you know, it's just, you know, $250 an hour or whatever, we'd love to help you, or— and I see this too because, so RightNow Technologies was headquartered in Bozeman, Montana, And, and my co-founder is in Bozeman, and as is about half of our team.

And, um, I love Bozeman. They're— it's turning into sort of a new entrepreneurial hotbed, especially kind of post-right now days. Um, but I don't think they have the, the give first— not— it's not pervasive about this kind of give first attitude. So I can, I can really like draw direct comparisons between Bozeman and Boulder and You know, the idea of, oh, we'd love to help you, give us some equity and we'll help you, versus I'm going to help you, and I know that if I do a good job, something will come out of it. It's really, it's really powerful.

They've done an amazing job of creating an ecosystem, and it's really grounded and centered around that kind of Techstars and Foundry Group nucleus. So could you kind of just summarize what does the program look like? And, you know, you get accepted, or actually go back before that, right? What's the application process look like? And, you know, all the way through the end.

Um, so the application process, oh, you know, some online form you fill out. They, they put a big emphasis on a couple of videos. There's a product demo video and a founder video. They're, they're really short. I think it's, I want to say, 2 minutes max for each of those.

Yeah. Um, and there's some dark magic that happens somewhere else. Uh, if you get past the first cut, then you go and you have I, I forget, like a 15, 10 minute maybe, some short meeting to just talk about your story with, with, uh, usually the managing director of the program. At least this is my experience. And then if you get— if, if you pass that hurdle, then you come in to like this boardroom panel where you have, I think, 3 minutes in which I want to say it's 1.5 minutes to give a pitch, and they give you like 8 points they want you to hit, like where are you at for traction and fundraising?

And like, you know, what's your, uh, value proposition? Like a bunch of stuff that you're supposed to hit in some really tiny, uh, time frame. Maybe it was 3 minutes and then 3 minutes for questions. That was it. It was 3 minutes to give, to hit all these points, and 3 minutes for questions.

Plenty of time then. Yeah. So yeah, right, double what I said. Uh, and then, you know, and then if you're in, then it becomes this sort of negotiation where they're like, okay, great, we'd love to you in there, here's all this paperwork where you sign stuff away. And it is a negotiation process through the paperwork?

I think most of the time it isn't. In our case, there were one or two things that we— so there's two parts in terms of the paperwork. One is the joining the program, and there's $20,000 for 6% basically, and the program, right? Okay. And then separately, there's a convertible note that you get offered automatically.

And that— and those terms in particular were difficult for us because they wouldn't have worked because we had, uh, um, other things going on that basically the terms more or less conflicted with. So, okay, I think, you know, they'll talk to you if you need to talk to them about stuff. Um, and so then, you know, for us, it's the, the program started in the end of January, um, and it's a 3-month super intense My co-founder moved down here for that 3 months. A lot of folks were from other countries, other locations, and they moved to Boulder for this period of time. And you basically, um, you know, plan to be in that office like 9 AM to midnight most of that program.

It's, it's super intense. I, I went home for brief family time for like an hour and a half between kind of 5 and 7 or so, and, and then would come back. And they— and it's like, it's a little bit of an executive MBA, it's a little bit of personalized assistance, it's a lot of pushing on you, introducing you to people, opening doors for customers, investors, um, and, uh, basically lighting up. Are you sitting in classrooms with a bunch of other people who made— who are, who are in the program as well, or, or individually, or what? In part.

I mean, the bulk of the time you're sitting at a desk in a big kind of— well, it, it varies, it's kind of the space, but in a big, um, I don't know, open space. So you're, you're working and, and in meetings because, um, you're generating lots of introductions and meetings. Uh, but there was classroom time too. The classroom time is— a lot of it is more workshop than classroom. So there's, there's some lecture, but a fair bit of like, you know, grab your Sharpies and Post-its and Let's, like, think about your— so here's the framework we're going to give you for a way to look at your company and to think about, I don't know, whether it's a value proposition design or a Kanban exercise or whatever the heck it is, right?

So they work on different levels of running a business and keeping it on track, goal setting, all the way through sort of frameworks for talking to customers and getting set up with that and advice on how to raise money. Yeah. So I found it— so, you know, like going in, I was a little skeptical. Coming out, I found it to be like a no-brainer. Um, I think it was an incredibly good program.

And, you know, are they on your board of directors? How— obviously they have, you said, 6% of the company. So are they, are they advising? Are they just a resource you can reach out to at this point, or is there really no interaction now, or No, so they definitely stay, you know, they're invested in the company in different ways. They want to help the company, all of their portfolios succeed, and they will do.

There's sort of 4 founders who've gone through the program. There's a community to reach out to and talk to kind of through forums and different things. Your managing director from your program stays in touch and asks how you're doing. They do ongoing education and calls and introductions, and it continues. It's just less intense.

Yeah, the intensity drops way off after demo day. Well, that sounds like a pretty good thing. Now you don't have, you know, what was it, 15 hours a day of staying on top of that stuff? Yeah. Um, so what— so you got— what, you were done in, uh, March, April time frame?

Is that what you said? Um, April. April. So what's— what have you been doing for the last few months then? Uh, well, we closed a round of money and we are, uh, you know, aggressively making that product kind of, uh, um, ready for production.

What are you doing with the money? People. I mean, personnel is, is far and away the, the biggest amount in launch. What kind of people? What are you— developers?

Yeah, predominantly engineers. Yeah, we're, you know, we're, we're an engineer— we're, we're definitely an engineering organization, right? Our customers, at least our users, are developers. Yeah, you know, who, who the actual buyer is, it varies, but, but we're selling into applications And so, um, we're, uh, we're, you know, strongly biased towards heavily technical people in our company. So do you have— what about sales?

Are you working on— are you working on getting sales folks in there? As a matter of fact, so, uh, um, you know, I'm, I'm kind of the, the chief and lone salesperson right now, but, uh, we are hiring right now. We expect to bring someone on board in August. Okay. And you— and how many folks do you have total right now?

7. Just interesting to think about, like, ratios and over time, you know, right now very heavily dev-focused, and I assume over time you get sales and marketing-focused as you look to, to get the word out. Yeah, you know, it's, uh, we, we definitely hire people who can wear multiple hats and have diverse skill sets right now. I think that's the, to my, in my opinion as an entrepreneur, the kind of the smartest thing you can do is to not get people who are narrow and niche, and you try and get people who, so for example, every one of our developers are speakers at conferences and go to conferences and do talks and did before hiring them and continue to apply abstracts. They can write and do blog postings and things like that.

So every developer for you has to be social as well? That's a challenge. Not going forward forever, but certainly for the early hires, yeah. Yeah, those are hard to find. It definitely gets tough to scale that, I think.

I used to go to all the conferences and ask them, ask them if they can write as well. So what do you think, you know, you mentioned sometime by the end of this year you're hoping to be ready to go. Public launch, yeah. Public launch, yeah? Are you in AWS?

Is that where you're running everything? So we're actually doing Google Compute at present, and, you know, one cool perk, there's a bunch of perks with doing the Texturize thing, you know, and among them is IBM and and Google and Amazon all give you, you know, a fairly large check under some time limit to go use their services for free. We chose Google Compute in part because a lot of the Amazon systems don't BAAs. So in other words, they can't— they're not able to give you something that certifies the security of those to pass on to your customers. For HIPAA, the requirements around HIPAA for that.

HIPAA or other kinds of compliance. Yeah, and so, you know, some Amazon systems do, it's just sort of hit and miss, right? So if you're a health startup and you're using AWS Lambda, you've probably gotta go back and rethink that. And so with Google, all of their services have BAAs, so we don't have to stop and think about and check it. And so it's not that they're, I think that they're necessarily more secure, more secure or less secure, one thing or another, but it makes our life a little bit easier for where we see— Yeah, just meet your requirements a little better.

Interesting. I haven't talked to a lot of folks who have deployed on GCE. Definitely interested to hear your take. Good. Well, so far so good, right?

We haven't tried it out with big production loads yet, but find the tools pretty easy to work with. Maybe a little bit easier than Amazon. Obviously, I delegate that stuff, so I'm probably not your best person to give a close analysis. But, you know, my— there is another company, one of the ones who offers free time, who I may or may not have mentioned, and we did spin something up for that, and it took the better part of a day to get the machine running, and then we forgot and left it running, and And it turned out it had crashed all by itself running absolutely nothing on it, literally just spinning up a blank machine. That was not Amazon or Google, it was another one, but we had a— there was someone we had a bad— oh, what the hell, we had a bad experience with Azure.

So we were a little bit surprised by that. Yeah, interesting. So what's the, you know, obviously we're a few months away from general release. If someone's interested in knowing more about what you do, Hey, maybe they think there's a good fit in their SaaS product. What would you suggest at this point?

So go to ironcorelabs.com, no spaces or dashes, just ironcorelabs.com. And there's a couple signups you have an option for there. One is if you'd like to be, you know, get on the beta waitlist, sign up for that. Or if you'd like the email list, do that. You can also, you know, If you have questions and you'd like to talk to someone about it specifically, if you think customer-controlled data, our take on customer-managed keys, which, you know, we didn't get into this, but our approach doesn't require calling back to the enterprise every time a piece of data is accessed, but you can— it has the same benefits, in fact better benefits around the enterprise customer being able to control their data.

You know, if that's of interest, then you can also reach out to me. Directly at patrick.walsh@ironcorelabs.com. I'll go ahead and put your email in the show notes if that's okay. Yeah, maybe obfuscate it for the bots. So, you know, one of the things that I, as you're talking about this, that I can't help but think about is the GDPR requirements around privacy that are coming out and the power that this would hopefully give some customers of SaaS providers around, controlling where their data goes and having that confidence that even if, God forbid, my SaaS provider synced data outside of the EU inappropriately, that it would be unintelligible, right?

And maybe, have you thought about that? Is that an angle that you're looking at? Yeah, so we're very interested in GDPR for a couple reasons. So the first one is the CASB industry, the cloud access security broker guys, they do a kind of the inverse of our model in some ways. So we're selling to, let's say for example, Dropbox as someone who we'd love to sell to, right?

And Dropbox, with our stuff, in a way you could think of it like they're integrating a CASB directly into their service, right? They don't have to lose the ability, they don't become a dumb application storage provider, they can still, they can be permissioned to do things, but the customer has that control. And if instead you move the the encryption point to, well, in our case, the encryption happens at the point of data use, but if you move that to a CASB box, the Dropbox becomes just sort of dumb storage, right?

But that industry has done some really interesting things around, for example, in Germany, if the CASB device is in Germany and if all the PII of German citizens go through it, then for example, the data gets encrypted before leaving the country and the keys to decrypt it don't leave country. In that scenario, it's considered okay for data locality. So, I don't know how this looks for all the countries, but Germany is definitely a stickler on this stuff and they kind of allow that as a way around it. And so, not exactly GDPR, but on the data locality side, it makes a big difference. There's another piece of this.

There's a bunch of pieces of this, but one of them is right to be forgotten. Right. And the interesting thing to me about right to be forgotten is the security industry is jumping up and down about GDPR, but you almost don't hear about right to be forgotten. Well, it's part of GDPR, but it's embedded in it from the standpoint of what security companies are doing to help people meet GDPR. Oh, I got you.

Yeah, yeah, yeah. I got you. Yeah. And, and in our world, we have a really neat way to deal with right to be forgotten because the trouble The reason it's hard is because data gets replicated all over the place. And so you get, you get a piece of data, you get, let's say, I don't know, a customer's and user's address or something, right?

And it goes into one system, it gets duplicated to another system, and then it goes to backup systems somewhere else. And oh, by the way, if any of those aren't in, you know, in-country, it's a problem. And, and oh, by the way, if that user comes in and says, I want you to delete my data, you have to go track it all down, including out of backups. Now what, what if those backups are in like tapes or zip, like how are you going to deal with that? Forget it.

You basically, you basically apply for an exception and say it's too hard for us to actually forget people. And, and that seems to be the going plan for a lot of companies. And, um, with us, the interesting thing is you could actually use what we've built to encrypt in such a way that the data, wherever it goes, is encrypted. And you can, you can revoke access to the company later, which is the same thing as forgetting, because now the company can't unlock that data wherever it lives. So you can very, very effectively, by deleting the keys, essentially forget someone, right?

And we can do that on a per-user basis because we don't have like one key for everything stuff. We do basically more like row-level encryption. And so for right to be forgotten, we have a a pretty interesting solution. Well, that's a great story. Yeah, yeah, I'm looking forward to seeing more when you guys are, are ready to, ready to go primetime with it.

Cool. Um, well, cool. I, I think I learned a lot of cool stuff. Uh, you know, one thing I like to ask our guests is, you know, your, your take on the Colorado community. You know, you've been here for over a decade now.

What was it, 13 years or so? You know, what do you like here? What do we need to get better at? What do you think? You know, it's been interesting because I've been part of the security community at least on and off over that time, and I feel like in the last couple years it's really— that's really taking off.

You know, companies like LogRhythm, Ping, SecureSet, really, really helping to solidify that. Webroot's been here for forever, and I feel like there's a bit of a center of, especially for security jobs in general, coming here. So it's pretty exciting. Um, you know, personally, I love this area, just like having nothing to do with that. Um, I, I feel like to, to me, balance is everything, right?

Within work, within, you know, within your company, you have to have balance between rigidity and chaos, right? Everything is balanced. And, and, and in work, actually, since you have Brad Feldon, he has a way of calling this— instead of calling it work-life balance, he says work-life harmony, which I I love that term because it doesn't mean there's equal proportions. It means that it's the right proportion for you. And here in Colorado, it's like, man, it's just always sunny.

There's always outdoor stuff to do. It's just people are happy. People are— when I lived in Boston, and I have a lot of great friends and family out there, but people don't smile at you, not strangers, never. Right?

There's a— here, you know, people are just really open and friendly. I think that pervades into the business culture too, right? I think that's part of the helpfulness. And I don't know if that's because people are more active or what, but I think it's an awesome place. Let's keep it going though, right?

Yeah. Hell yeah. Absolutely. All right, well, anything else you want to say before we let it go?

No. You know, if people are interested, please reach out. We'd love to talk to you and And, you know, thanks for, thanks for doing the show. All right, Patrick, thanks for joining us. All right, take care.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes