All episodes

Andy Grolnick

Apple Podcasts Spotify SoundCloud

In this episode:

Andy Grolnick, CEO of LogRhythm, is our feature guest this week. News from: Oracle, Red Canary, Denver Startup Week, LogRhythm, ManagedMethods, Secure64 and more!

Sure it'll only take 14 minutes to get from Denver to Pueblo, but will the wifi work?

This could bring a whole new meaning to "tubing in the rockies." Oracle is laying off a lot of people, as they shift to a cloud focus, Red Canary makes a list of growing CO companies, Colorado = Security is taking over Denver Startup Week, LogRhythm integrates with Cisco, and some thought leadership pieces by ManagedMethods, and Secure64. And probably a little chatting about that Equifax thing too, while we're at it.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Andy Grolnick graces us with his presence this week. Andy is responsible for leading LogRhythm through tremendous growth. He talks about the challenges of scaling a company, why they're doing it in Colorado, and what he sees next.

Also, a couple years ago Robb's interviewed Chris Peterson, LogRhythm founder. You can check that out here: https://inforeck.wordpress.com/2014/04/21/an-interview-with-logrhythms-chris-petersen/

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9780 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 33 for the week of September 18th. Alex, this is the weekend.

How's your weekend been? You know, I spent probably 6 hours yesterday at a football field. Yeah, my kids had back-to-back games, which is fun. The positive side, I got to be on the crew that did the chains, you know, so where the first down markers are. So I get to be right up on the field.

So that was nice. On the positive side, you had a job to do. That's right. So you felt, you felt like you were really accomplishing something. That's good.

How about you, Robb? Soccer games. I was at soccer for both boys separately yesterday and Basically, you know, my weekdays are scheduled wall-to-wall meetings and my weekends are now scheduled wall-to-wall kid things. That tends to happen. We did get— Kristen and I did go out to a comedy show last night.

I was mentioning we went to see Paul Reiser from Mad About You fame. Yeah, from the '90s. It was fun. We went to Parker. There's a Parker events center down there called PACE, Parker Arts Center, something like that.

The E is probably for events. Maybe for events. Why don't we go ahead and dive into the news? Let's do it. Number one, Alex, how would you feel about being able to get from Denver to Pueblo in 14 minutes?

I don't care. I don't have any reason to go to Pueblo. No. So what Robb is alluding to is that Colorado is sort of potentially on the cutting edge. They're going to be maybe making a Hyperloop test track here.

Which I think would be cool. Some— there's a couple options. One is, I think, all the way from Fort Collins to Pueblo or something like that, and one's from like Greeley to the airport and to Vail. Yeah, anyway, out to Vail and stuff. So, so what Hyperloop is, is it's basically a tube that you'd basically install through the plains, and it allows you to have a vacuum-sealed container inside the tube that shoots along in it at like air airplane speeds.

You could travel extremely quickly for, you know, a whole lot less cost in terms of each trip. Functionally, it's like one of those little tubes at the bank where you, you know, you shove your money in there and there it goes right into the cashier. But hopefully it's a little safer and, you know, other things like that. And I think when we were talking about this earlier in the week, I said, you know, would you want to go? And you said you wouldn't want to be the first, but you'd love to go.

And I said, yes, you don't want to be the last either. Uh, absolutely. I think it sounds like a lot of fun. You know, this is years away from becoming a reality, but these are the kind of things that can move us into the, into the future from the movies, right? This is the I, Robot type, you know, getting us right to the, to the future we all have— think we've been promised by our childhood movies.

On a not so happy note, uh, Oracle announced that they're cutting 2,500 jobs in the US. Yeah, it looks like this is focused mostly on their software area, actually the former Sun-type products. So Solaris is being end-of-lifed. They're cutting a lot of support for Solaris, and they are— so it is a 2,500-job cut, but they're actually investing more than that number of jobs into their cloud teams. Yeah, so net gain, and hopefully of those jobs that they're cutting, they would maybe be giving those folks an opportunity to take a different job within the company.

You said something interesting though right before the show, that Oracle's second-largest campus is actually the one up in Broomfield here. Yeah, the former Sun campus, which is pretty cool. And it's a very big campus up there. We've had ISSA meetings up there before, um, but it's one of those things with big campuses these days. It seems like it's, it's kind of deserted that, uh, you know, folks often work from home, but you get a lot of buildings with nobody in them.

Uh, so there, there's an article in here about 12 companies in Denver that are hiring for work-from-home staff. It's kind of an interesting list of companies. Yeah, one of them that stuck out to me was Red Canary. We've talked about on the show before. They do uh, you know, managed endpoint detection and response.

And, you know, they hire a lot of their security operations folks to work remotely. Yeah, pretty cool. I also saw that Dish Networks is on there, and that one really shocked me, honestly, because, uh, the, the story about Dish is usually you have to be in the office full-time and you have to be there certain hours. And apparently they're hiring a bunch of work-from-home folks. So kind of an interesting trend.

Uh, next, we're getting close here to, uh, Denver Startup Week, and there's a couple events for Denver Startup Week that we wanted to highlight. Yeah, so Denver Startup Week is next week, right? Starts on Monday the 25th, and we have 2 different events that Colorado Equal Security is going to be a part of. On Monday, there is an event, a panel on compliance security, um, and your startup. Uh, that's going to be 10 o'clock to 11:30, I think.

Yeah, and we're both going to be speaking on that. It's, it's about essentially how startups can provide security and what things that they should do to make sure that their products are secure and that their customers feel secure. And then on Wednesday the 27th in the morning as well, there is the Security Founder Panel where we're going to have the founders from several different security companies get together. And that includes the founder from ProtectWise, founder from Red Canary, Swimlane, and CyberGRX. And then I will be moderating that panel kind of in my role here as the Colorado Equal Security host and Also probably my ping role.

Nice. Yeah. So next, there was an article in the Denver Post about Cyber Girls. So we've talked about that event a couple times in the events section. They had a nice little summary of what Cyber Girls is.

It's coming up on the 23rd, I believe. Debbi Blyth, the state CISO, is going to be speaking there. But really, it's about getting girls exposure to STEM subjects, and in this case, cybersecurity. So that they can hopefully go on to careers in those areas. This is junior high and high school age girls, is that right?

I believe so. Yeah. And it's, it's not limited to anyone who has experience in those areas. So it's, you know, if you have a daughter that is interested in that, go ahead and get them over there. This is a great opportunity not only to get some of your daughters exposed to this a little bit, but to figure out if there's a program for you to take back to your kids' schools to help help start that program up.

This is how we're gonna address the gap, right? There's no, there's no short-term fix for getting our, our job gaps filled and getting more women into security. Uh, longer term, we need to start working on, you know, getting— gotta start early. Yeah. Uh, next news, LogRhythm announced an enhancement, an integration with Cisco, and it's basically just, you know, another way that they can have a nice integration from Cisco products into the LogRhythm SIEM.

Yeah, and LogRhythm announced a few months back a partner program. I'm guessing this is part of their partner program. So now you can have better integration with the logs and information from, uh, from Cisco into LogRhythm and back and forth. Uh, Managed Methods had a blog post this week about why the architecture of your CASB matters. So it talked a little bit about making sure that you have essentially a cloud-native CASB.

Yeah, the, the point that they're making is, hey, you're going to have access— you have all your employees going out to these SaaS products like, you know, Amazon and Salesforce, they have massive scale. And as they, as they use those products more and more, the scale is going to hit harder and harder. If you have a CASB that's going through a single proxy that's not, that's not built natively scalable, you're going to run into problems as you scale and it's going to become that roadblock that stops access. So you want to make sure you're working with a CASB that does scale and is kind of a cloud-native CASB. I assume that that means that Managed Methods is a scalable cloud-native CASB, and probably one of their competitors who they didn't name in the blog post is not.

Yeah, interesting point. Yep. Next blog post, we had something from Secure64. And as a reminder, those are the guys who do secure DNS. It was actually not a blog post, it was a piece that made it into MarketWatch about what would happen if the DNS of the internet was compromised.

I really like this. Basically, he's hitting on the fact that we have a lack of diversity in our DNS implementations, and a lack of diversity makes it really easy for catastrophically bad things to happen. The article starts off alluding to the Irish Potato Famine. If you guys know your history at all, you know Ireland had potatoes everywhere throughout the country. Actually, if you travel to Ireland now, you can still see the rows of potatoes from before the Potato Famine back, you know, 100+ years ago.

And then when, when these those little critters came and killed all the potatoes, it was a massive impact to the people who lived there because they just didn't have other produce that they could use to take the place of potatoes. In the same way, the implementation of DNS bind throughout the internet is what we're all depending on. So if and when there is a massive vulnerability discovered there, it's going to have a huge implication. Yeah, exactly. Um, I think that goes also for, for other things as well.

So, you know, we're Things are changing somewhat, but, you know, Windows has been— Microsoft architecture has been largely used across, uh, many areas. And so one failure there, as we know, goes across many different industries. Yeah. So, um, next, uh, Vector8. Uh, they're a company here in town that we've talked about periodically, but they, they do a threat hunting product.

So they have a course coming up, uh, Threat Hunting and Advanced Analytics. It is October 3rd through the 5th. Saw that pop up as part of the news this week. It looks pretty interesting. It's not a cheap class.

It's nearly $4,000, but it was recommended by someone in my LinkedIn network. So I wanted to pass it along. If you're interested in threat hunting and you feel like you have a base already and want to go more advanced than that, then you should take a look at this course. It looks really cool. A couple of reminders, some logistics.

Number one, go subscribe on iTunes, go rate us on iTunes, subscribe on Google Play, rate us on Google Play. We'd love that if you could spend a few minutes doing that. We'd appreciate it. Number 2, uh, Alex is wearing his Colorado Equal Security t-shirt today. That's a reminder for me to say we have a store, and we'd love it if you guys would go out and buy some stuff.

And we get, like Alex said, I think 16 cents per, per $100 you spend there. So, uh, you know, you could really make a big difference if you have millions of dollars to spend in the store. One of these days we'll be able to get one of those postage stamps we've been looking for, Robb. Let's go ahead and dive into events now. As a reminder as well, we do have a whole calendar of events on the website.

I'll tell you, the calendar has filled up a ton coming up in the next couple of months, up through the end of basically November. There's a lot of stuff going on. So look out there now 'cause there's too much for us to get in front of very far. The first one on the list, we've mentioned a few times, the SANS Security 511. Which is being hosted at LogRhythm, starts this week.

I'm not sure if there is a sort of a walk-on capability or if you can just walk on. Just walk on. Tell them we sent you. Right. Don't tell them we sent you.

If you could just, you know, show up and register or not. But that's happening at the LogRhythm campus. That's continuous monitoring and security operations. On the 20th this week, OWASP is having their September meeting about radio frequencies and what it means to us. On the 21st, Chorus 360 is having their security symposium at Topgolf.

Also on the 21st, ISC² is having their monthly meeting with John R. Nye from CyberGenesis Tech. On the 21st, the DenverSec is having their North meetup. As a reminder, that's just a place to hang out with some cool folks at a bar, talk security, talk other stuff. Really very social, no agenda. Good thing to take a look at.

On the 23rd is the CyberTech Girls event. We talked about this a couple times earlier in the show here. And also, um, on the 25th, we talked about the compliance and security panel at Denver Startup Week that we were both going to be a part of. The whole week of the 25th, it, you know, we have Denver Startup Week going, but there's also the SANS Rocky Mountain fall conference happening. So lots of SANS training, Lots of good opportunities for you to get to meet folks through SANS.

If you have the extra budget, it's a pretty cool opportunity. On the 26th and the 27th, the CISO Advisor Alliance is having their leadership summit. I think that that's up at the Omni in Broomfield. Is that right? I know it's up north.

I'm planning to be there. It looks like it's going to be a pretty cool event. Hopefully folks can join us there. And then on the 27th, the NCC, the National Cybersecurity Center, is having their cyber healthcare exercise. That should be a pretty fun event, especially if you're involved in healthcare.

Take a look, get to meet some other folks in the industry. And then finally, also on the 27th, as Robb mentioned earlier, he is moderating the Security Founders panel at Denver Startup Week. All right, let's go ahead and jump into jobs. We have a couple of really cool jobs this week. I'm not sure how Alex found these things, but, but good job, Alex.

InteliSecure is hiring a Director of Information Security Governance, Risk, and Compliance. You know, in a lot of ways this looks like it would be running the internal security program for InteliSecure, one of the, you know, fastest growing security companies in Colorado. Seems like a really great opportunity. You heard us do an interview with the CEO and CTO from InteliSecure a month or two ago. I, I know this would be something that I'd be interested in if I were looking, so I recommend anyone who's looking for a really fun job at a fast-moving place to take a look at this.

Yeah, it sounds really cool. Uh, Pearson is looking for a Director of Global Product Information Security. PISO. PISO. That's what it says, PISO.

Yeah, so you're, uh, the product information security officer, which is cool. So it sounds like you're in charge of the security for all of their, I'm guessing, education product products since Pearson does education. Yet another really cool looking position. This is another one that I recommend folks take a look at. Probably you want to have a little bit more product side or application side, security side experience, but something worth looking at.

Ball Aerospace is hiring an Information Systems Security Officer 1. Lockheed Martin— that we got a couple jobs from them. One is a Cybersecurity Director, so it looks like a leadership position over there in cybersecurity. And the second one, which I thought was pretty cool, was a Cyber College Development Program. So if you read the job description It looks like maybe a little bit of hands-on work, but also helping to develop some education materials internally for Lockheed Martin.

So that sounds kind of fun. Very fun. The state of Colorado is hiring a criminal investigator too, focusing on cybercrime. LGS Innovations is hiring a reverse engineer too. So if you want to take apart software and malware and other things like that, that sounds like a— that sounds like really fun.

Do you know who LGS is? Do you know those guys? I have no idea. Yeah, I don't know either. Yep.

If you work for LGS Innovations and you want to tell us what you do, we'd love to hear it. I don't— not a lot of companies are hiring reverse engineers. That's true.

ViaSat is hiring a network security engineer. Yeah, and I'm pretty sure ViaSat is the people that have the, the mobile satellite systems. So it's like a trailer with a satellite on it and you, you know, drive it up someplace and you can plug in and— disaster, basically. Yeah, it could be, or like remote operations, other things like that. Anyway, that one sounds cool as well.

Deloitte is looking for a Cyber GRC Technical Architect and Senior Consultant for Archer. That's one of the longer titles we've seen. That's a 7-word title, everybody. Yes, that's pretty good. And you'd get the pleasure of working with RSA Archer.

Yeah, well, so you know your job is safe because that will never stop being a thing. Coalfire is looking to hire a project manager, and Red Sky Interactive is looking for a senior sales executive in Colorado. Pretty cool. If you want to sell security solutions here in Colorado. Exactly.

Give them a call. Well, that takes us to the end here. We have our feature interview coming up with Andy Grolnick. Andy is the CEO from LogRhythm. Got to sit down with Andy.

It was actually a couple of months ago that we sat down. We didn't want to post this one too close to the one with James Carder, who's the CISO over there. But it was actually the day, you know, that they do a— in Boulder, a raft to work day. So the idea is you're supposed to get on the river on an inner tube and tube— I guess it's tube to work, tube to work day. So I was actually there on Tube to Work Day, which is kind of like an unofficial holiday up in Boulder.

Yeah, pretty cool. Cool. Well, all right. Anything else before we let everyone go? No.

Have a good week, everybody. All right. Have a good one. Thanks, Robb.

This is Michael Glenn. I'm Vice President of Security at CableLabs. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Robb Reck, here to interview today the CEO of LogRhythm, Andy Grolnick. Andy, today I hear you took an interesting way to get to work. Could you share with me what that's about? Yeah, today is Tube to Work Day, and so it's an event that's been growing in Boulder here over the last— I think it was started in 2008 by a couple local creative guys.

And it's, uh, we, we, you know, some, several of us about 4 years ago, um, heard about it. And at the company, about 12 of us did it one year. And, and this year, about 150 employees from, from the company, um, joined in. And it's basically, you start at the mouth of the canyon, downtown Boulder, and get in an inner tube with, uh, this year it's probably 600, 700 folks and And it's kind of like bumper tubes all the way down the river, and it's just a blast. It's a great, you know, annual event, rite of summer type thing.

So did you take a swim this morning, or did you make it all the way on the tube? I turned over once.

The water is really cold. Are you wearing a wetsuit up there then? I'm not.

There are people that do. A lot of people do. There were moments today I was I was reconsidering, but made it through it. It was a sunny day, and once you got out on the water in the sun, it was nice. Well, I do want to, you know, that's great.

It's so neat that you guys are participating in that Boulder kind of new tradition. But let's set the stage. You know, LogRhythm, you guys are a sim provider. I'd say more than just a sim provider now. And I'd love to have you just summarize what LogRhythm is for anyone.

I don't know if there's anyone who doesn't know who you are, but just in case, what are you guys? Yeah, at a very high level, we call it threat lifecycle management. So, you know, our platform for customers today is really that foundation for the next-gen security operations center. And so we've been building this end-to-end platform for many years. And now, you know, power and kind of almost mission— you think of it as mission control for security operations for medium to large enterprises.

And so what we've done is gone beyond, you know, what the first generation of SIEM and log management were to incorporate things like network and endpoint forensics, security orchestration and automation, advanced UBA and security analytics all in one integrated platform. So security CISOs and security organizations don't need to have 4 or 5 different products. All those capabilities are integrated together, and as a result, you don't have kind of information overload, you don't, you know, alarm fatigue. You don't have data silos, you know, what we call swivel chair analysis. You've got all this integrated so your analytics can be much better, your workflow is much better.

You can get it from, you know, take it from, you know, early detection all the way through response and even automate that entire workflow. So I want to accomplish Thanks for the summary of the company. That's fantastic. And I want to accomplish 2 things here. Number one, I'd like to let the folks here, um, here in the community get to know you personally.

You know, who's Andy Grolnick and what have you done and why do you get to run such a cool company? And number two, maybe we can get some practical advice during this on how someone can, can make their SIEM not be, you know, a generator of alarm fatigue, as you call it, or, you know, the death by false positives, as I frequently think of it. Um, so, but let's start off by backing up. You know, I, you and I talked about before we started recording that I, I had the chance to sit down with Chris Peterson, one of the founders of the company, a few years ago, and I got to learn about the startup, the startup journey from that. And I'll actually put a link in the show notes to that article for folks who want to hear about it.

But you came in, you said 12 years ago, right? So 2005, right? If my math is right. Tell me about what happened in 2005. What, why'd you come into the company, and where were we at that point?

Yeah, so at that point, uh, the company was, uh, Chris and Phil and, and Chris's dog. And, and, and, uh, they had— those guys had bootstrapped for 2 and a half, 3 years. Uh, you know, Chris had sold his house and, and that helped fund the company. And they, they lived together and worked together and, and really in a, in a, um, you know, classic kind of boot— bootstrap way. Got a couple customers Chris and I knew each other.

I was on— we were on the same tennis team, just coincidentally in town. And so we got to know each other that way. He knew I'd been, you know, an exec and been involved in tech companies and startups. You were in the storage industry, is that right? I spent a lot of years in the storage area, companies like Iomega and Quantum.

Early in my career, I was with Hewlett-Packard up in Fort Collins. Sure. In the technical workstation area. Started here in Colorado as a product— HPUX product manager up at HP, but been in the industry for a while and had some successes. And, you know, Chris, after tennis matches, he asked me questions, you know, ideas, advice on things.

Got to know him, got to know the what they were doing, and they got a couple customers. And, you know, he and Phil asked, you know, hey, we could use some help building the company, and I think we got something here. And I looked into it, and I was at a point where actually I'd been, you know, doing a lot of them doing storage a long time. I was looking to do something different. I didn't have security domain experience at that time, and that was part of what was interesting to me.

And so it was kind of a— the more I dug into this segment, it's very dynamic, required a lot of innovation and something new to learn and get experience on. But I could leverage a lot of my background in storage and software and so on and just high-tech, building high-tech businesses. And so the more I looked into, you know, these guys have a vision that is differentiated. They're looking at things differently than the pure log management folks or the early SIEM folks at the time were, and they had a vision for a platform that was pretty interesting. And I felt like this was— we were behind as a company, but we had, you know, I think I felt like we had time because I felt this was a long-term platform versus a feature that you know, would be subsumed into a bigger platform.

Yeah. So 2005, you made the decision. Had you been a CEO of a company previous to LogRhythm? I hadn't. I'd been a general manager.

I was vice president, general manager of a large division at Iomega, kind of helped launch the Zip drive and ended up running, you know, so I had that experience but never been a CEO. Of a company of any size. And so that was a new experience for me. It was an opportunity to, you know, also build a company from the ground up, you know, and a culture and all that. So, yeah, I did my due diligence and, you know, I saw enough opportunity and jumped on board.

And so I was basically employee number 3. Yeah. And we had about $30,000 in the bank and 2 customers, and, you know, it's like, okay, what do we do next? You know, so, so it sounds like you would have had not only the, the challenge of learning kind of a new industry with security versus storage and other tech stuff, but also getting to run a company. How was that first transition for you personally?

You know, did you start focusing on the security industry first, or how do you accomplish— go after that? Yeah, you know, I think probably the, you know, what I always tell people in a, particularly in an early-stage startup, but in a startup, you know, I believe what I've learned over the years is the most precious commodity is not capital, it's actually time. And so, you know, I'd learned that along the way. So the first real decision is how to not only how do I spend my time, but how do we, you know, all, you know, and Chris and Phil have talents and capabilities beyond product and technology. And so we're all wearing multiple hats.

One of the— I would say that the, you know, the things you do, I'd been— I'd had enough experience in kind of building startups early stage to kind of know where to focus on. The harder thing for me early on Uh, was, was kind of getting to know the space and the security domain. Yeah. Um, so that was, that was, uh, that was, I would say, a bigger hurdle, you know. And so I tried to kind of balance where I was spending my time, and, and some of that I learned over time and through osmosis.

And obviously Chris was very helpful on that. Yeah, I'm just thinking through what you'd have to learn coming into a SIM company, and it's a lot, right? There's, I mean, there's all of— you have to know all of the systems you're ingesting logs from, which is kind of the gamut, you know, from the real traditional firewall AVs to web servers and, you know, domain controllers and workstations, and you're trying to learn all that. And now, of course, as CEO, you probably don't have to understand how to parse all these logs, but you You have to understand the importance of them. And what is, do you have a take on what you came out of that with?

Is there an appreciation you gained for some of this data is more useful than others? Or what kind of learnings did you have from that process? Yeah, I mean, I think that parts of my background were very helpful and relevant because on one level it is a, it's a big storage problem, you know, and it's a data management problem, you know, log management, same on one level. And so there was a lot of relevance between the storage and the software background I had, but what I had to learn is kind of all the domain uniqueness. And so, you know, it was, but it wasn't You know, over time, you know, it kind of really clicked.

I mean, it didn't take too long. Yeah. But it was certainly a ramp. Yeah. So 2005, you were employee number 3 and you started, you had $30,000 and a couple customers.

And today you have more, hopefully more than $30,000 and a whole lot more than 2 customers. Let's talk a little bit about the journey. Maybe give me the meta journey. How do we get from there to here? Yeah, I mean, today You know, we have, you know, well over 2,000 customers and over 650 employees.

It's global business. But the, you know, what we talked about early on, you know, is how do you want to kind of build the business, right? I mean, there's an approach which is raise a lot of capital and hire tons of people and move really fast. And there would have been a rational argument for us to go about it that way, given folks like ArcSight and LogLogic and QRadar had— we're further along as companies, as products, and so on.

But we decided that actually, and what I'd seen is there through my experience too, is that there's just a There's a certain pace, you know, depending on the business you're in, there's a certain pace beyond which you can't really be effective and grow effectively. So we took actually, it was a little counterintuitive, but a slower approach, more methodical, more incremental, and we would make investments in certain areas and, you know, in kind of 6 to 9 month periods. You know, measure what's going on and then kind of figure out what the next phase of investment. So I'd say those 3 to 4, the first 3 to 4 years were more like that. We raised a relatively small amount of capital, $6, $7 million, you know, in that period.

And, you know, there's a germination period for a company and a culture and You know, before you really go after the large enterprise, you've got to get the product maturity at a certain point. You've got to get to, you know, you've got to hire the types of sales, service, and support people that, you know, know how to serve those customers. So we kind of did that for a while until we felt like, okay, we're ready to kind of move to that next level and started raising more capital at that point and putting the foot on the gas in certain areas more. When would you say you, you kind of started putting your foot on the gas? What year would that be, raising the capital and ready to go more aggressively there?

Yeah, I mean, that was, that was probably, you know, 2011, 2000. Yeah, halfway. Yeah, yeah, yeah. Okay, sure. Yeah, you know, I would— about that time, I don't know, maybe I'm crazy, but is that about when all of the, your competitors got started getting picked off, or maybe it was a little bit after they all started getting picked off.

There was a lot of pure plays in the mid-2000s, and are you the only pure play that's still around from then? And maybe you count Splunk, maybe you don't, but like, you know, QRadar and ArcSight and LogLogic, they've all been picked up by larger organizations. Yeah, a lot of them. There's— yeah, I put them in like 3 buckets. There are some There were, you know, if you look at maybe the Gardner Magic Quadrant in 2008, there was a lot more players.

Some, as you say, have been picked up, acquired by large system players like HP and IBM. Others have gone out of business. They haven't stayed competitive. Which ones haven't gone out of business? I'm trying to think of which ones you've lost.

I mean, in the early days there was one called Hightower. I don't remember that one. There was, or they've morphed into something else like LogLogic. Right, they're not even a SIEM anymore. Not really.

I mean, they were acquired by TIBCO and we don't see them in the market at all other than as a replacement opportunity. And SenseAge. So, you know, similar. So there have been a lot of stories like that where for whatever reason they, they didn't make the right investments, didn't stay competitive. And this is a market you've got to, you know, continue to innovate.

And, and so they're not— they're either not relevant anymore, they're not in business, or, you know, but in terms of pure plays, You know, I would say Splunk is obviously serving a much broader market in IT ops where part of their business is security. So from that standpoint, they are sort of, kind of, yeah. But we're probably the only one that is just, you know, zeroed in on of any scale. I would also include AlienVault that, you know, the lower end of the market. As, as a pure play.

And, and there, there's some smaller ones. Has the barrier to entry gotten so significant that there's just no new, new companies coming in? I don't think I've seen any. I can't think of any that have come in for quite a while. I mean, Sumo Logic sort of, but more as a Splunk competitor, right?

Yeah, so you have companies like Sumo Logic and Loggly who have really been gone after trying to be flunk in the cloud, and so we don't really directly compete with them. Alert Logic, maybe? Alert Logic's been around for a while, and they're— yeah, so there's still some. They're doing pretty well, and they've got a focus in one area. Well, that's enough about non-Colorado companies.

Let's get back to LogRhythm. Yeah, so tell me one of my favorite questions. What is something that you guys have accomplished in the last 12 years that you're, you're really proud of? Something that's a big success that you'd like to share with us? You know, I, I think, uh, you know, I'd say a few things.

I, I think building, um, building a company of this scale from the ground up, um, and, and I'd say, you know, kind of building, building a business, I think, the right way, you know, building a culture that, you know, I love to come to work at every day is something to be proud of. And to build, just have the, you know, amount of talented people every day, you know, going through those phases from, you know, early days where you're doing everything to it's a totally different It's very similar. You know, the company hasn't fundamentally changed, but at this scale, you know, you're just, you know, it's a different scenario where you've got a lot of talented people that are doing a lot of great things. So that part as well, I think what's also satisfying is coming from where we did to bypass several bigger, much better-funded companies out there with lots of resources and, you know, having the right strategy and the right execution to get to the point where we are, where we're in the, you know, it's us and Splunk and IBM in the top tier of the leader's quadrant. Right.

Right. And, you know, with the cool From my perspective, one of the really cool things is you've not only done it here in Boulder, you've really focused the vast majority of your workforce here in Boulder as well. I'd love to hear from you, you know, why Boulder? Obviously when you came in as employee 3, you guys had choices. You could have said, hey, we're gonna hire talent wherever it is, or hey, we're gonna move to Silicon Valley where all the VC money is, or we're gonna move to middle of Nebraska where talent is cheaper.

Why did you end up staying here? Yeah, and so, you know, it's interesting. Chris and Phil actually started the company in 2003 in Washington, D.C. Chris had been working out there, and initially I think they felt like that they needed to be a place like that, you know, where it's kind of a hub of cybersecurity activity and so on. And then I guess after a year or so, they're dealing with the traffic, and they're both from Colorado. So both, both of them grew up here, went to school.

Phil went to CU, Chris went to CSU, and, and they said, you know, we, you know, it's really just the two of us right now. I mean, we can have this company anywhere. Why don't we go where we're from and where we want to live, right? Uh, and so they moved here, and I was, you know, like I said, I met Chris here, and we— are you a Colorado native as well? Are you— where are you from?

I You know, I grew up mostly in North Carolina but moved out here in 1988 and I've been out here ever since. I've worked for Hewlett-Packard and just love it here. Technically, I'm a native. I was actually born here. My dad was doing a residency, so I was born here and lived 6 weeks before they moved back to Houston.

So you're a native, all right. So I am a native and I love it here. You know, so one, we all just have an affinity and like it here. So we wouldn't have— it wouldn't have been a consideration to, you know, move to Nebraska or Silicon Valley. And there's got to be a little bit of pressure to move to Silicon Valley, right, at some point?

You know, I've seen that, you know, having worked for startups here and the VCs get invested here from the Valley and And there is a mentality there that you really can't build companies outside of Silicon Valley. Especially 5 years ago. I feel like it's maybe got a little better now because it's so hard to find talent out there. But man, it seems like 5 years ago— Yeah, go back to 2005, right? And so when we started raising capital, I mean, we were able to— there's obviously not as much VC and capital here.

But, you know, there's a lot of VCs in Silicon Valley who don't— just want to stay local. They don't even want to get on a plane to go to a board meeting. And so it makes it, you know, I think it, you know, just— I think there's a need for more early-stage capital here. Once you get to later stages, it's— you're strong enough because it's less of an issue. You know, you can attract capital from anywhere.

But the hard part is the early stage. And but what we felt like, you know, I've always felt like this is a great, you know, call it a tech hub. There's a great combination of, you know, people and universities and culture. And I like I actually really like the more collaborative nature of the community here. Yeah.

And I think that's an advantage. And I think that you're starting to see folks from both coasts and, you know, move to— you know, there's a lot of influx to Denver and Boulder and there's a lot of momentum. But, you know, I think you can build great companies here. And, uh, you know, your company's certainly an example of that, and, and, uh, there's plenty others. Yeah.

Well, I, I asked you for one of the, uh, big successes of things you're most proud of. I'd love to hear— I think it's really instructional whenever we can talk about something that didn't work that you tried. Is there any examples of something you guys, you know, went after, and I don't want to use the word failure, but a learning opportunity, something that, you know, you ended up moving away from during the last 12 years that you're we can learn from the logarithm tried and said, eh, that's not, maybe the industry expects us to do this and we're not gonna do it or something like that. Sure, yeah, I mean, I can give a couple examples. I mean, one from the earlier days, I'd say we didn't, this goes back to 2007, 2008, we probably should have invested in separate QA organization team earlier than we did.

So were devs basically testing their own code? Yeah, exactly. And that's pretty typical of a lot of— so trying to, you know, as I look back, I mean, that's— you're running really fast, but I think that's one of the things, that's one of the lessons, you know, I would let you know if I were to do another early-stage company, just to make sure to do that. But, you know, we— so we had a release that went out, you know, 2008, probably before it was ready. We learned from it.

We put a QA organization in place and moved on. I'd say probably the other— so that's more of just a lesson learned for earlier For other stage companies, CEOs, you're scaling. And it's always a balancing act. You know, you don't want to put in too much process and get too far ahead of yourself where you slow yourself down in all facets of business. You know, it's kind of the right things at the right time.

And sometimes you're a little early, sometimes you're a little late. But that's always kind of the art and science of it. The other thing was, you know, we went, wow, we were, this was 2008, we just finished, we had a really rapid growth year and we thought we were about to take over the world. And so we said it was time to go global and we opened an office in the UK, ready to go international. And it actually went, You know, that's not easy to do for any size.

And that actually went really well. And so a few years later, you know, we went into, we started going into some other geographies. And I guess the, you know, one of the things we've had to learn over the years, some have, expanding into international geographies, some have gone really well, some have not gone as well. And so trying to learn what are the dynamics, what's the formula for success, you know, because you can have a great business in the US and it doesn't always translate in every geography instantly, right? There's so many dynamics.

So I think Um, I think we've gotten a lot better at that and, and, you know, been more thoughtful and kind of, we know, starting to learn the, the, the, you know, what, what works best. Yeah. Yeah. Well, we are— we have another 8 minutes here. I want to ask you the, the second topic I wanted to get into, which is, you know, I, I've implemented a SIEM 4 times in my career, including LogRhythm, and I've— it's every time it's been a significant challenge for me to, you know, weed through the noise and really get value out of it.

So I'd ask you, you know, from someone who's had thousands of implementations of your product, right, what are the tips that you can give for security leaders or security administrators who are listening right now to how to get the most value from their SIEM? Yeah, yeah, I think, I think part of it is, you know, step one, what we, you know, just go through some examples of kind of what we've seen works. So step 1 is really between the customer and the vendor having a clear set of success criteria for phase 1. And actually, I would recommend companies implement in phases, not trying to boil the ocean. I think when you try to You know, a lot of companies have limited resources, budget, security challenges.

We all know that, right? So not trying to take on too much early on, really have a kind of a defined use case, a compliance project you're trying to take on, or a set of your network. So can we talk about the kind of the phases for just a second? I— the paradigm I use for SIEM, and you can tell me if this aligns with how you think of it, I really see 2 different components. There's, there's the centralized log repository where it's basically feeding data in so you guys can hold it for either, well, for forensic data or for the second component, which is security analytics.

So I'm going to run upon it. So phase 1, log repository. Phase 2, security analytics. When I think of— there's those 2 components. When I think of deploying SIEM, I basically want to go after phase 1.

I want to get all my logs into the central place immediately from day 1, but I don't have to set up any alerting on it, right? I can just say, yeah, I got every system sending logs over there, and then start applying some kind of analytic package to that data. Do you guys think of it that way, or do you say, no, no, go after just those, maybe your domain controllers or your high-risk application systems and just start deploying to those? Or how would you think about breaking up your phases? Yeah, that's really interesting because that's almost exactly how— and it's been a learning process over the years— but that's almost exactly how we work on onboarding, work with customers on onboarding them in the right way.

And so we have actually a deployment methodology that first— it's called Core plus TMF. Core is that centralized logging, get the key logs you need in for log sources for the use cases you want to do. And TMF is that Threat Management Foundations, which is the analytics on top of it. So we'll do that first part first, spend— leave some time to get more of the log sources in and then come back and work with the customer on the analytics side of things and what we call the threat management foundations. And that seems to go really well because, and there's very clear kind of objectives for each part of that phase and what's expected of us and what's expected of the customer.

And I think what where a lot of projects don't work out well is it's kind of fuzzy and undefined and you just kind of go, okay, here we go, what do you want to do?

We've gotten to a point where we kind of know what works and it's important for the customer to know what they need to do. And they really like the approach. They like the structure to it. And then, you know, you get to that point, and so in 90 days, you're actually seeing value and use out of it, and then you can build from there. So one of the struggles I've had, and it's gonna lead into a piece of advice that I'd love to hear your opinion on.

One of the struggles I've had is it's so incredibly tempting to say yes when my SIEM provider, which may be LogRhythm, says, hey, I have this set of rules that's custom-built for a PCI environment or whatever, and you can turn these rules on, and you can start, you know, turn on this suite of rules and then start turning off the ones that don't matter. It's so tempting to say, oh yeah, I'll turn on that set of rules and then I'll tune it down. But what I've experienced is if I do that, I have just lost the war. It's too much. You just went from nothing to too much data for you to manage, and now you're spending time, you're spending an enormous amount of time turning off wasted, you know, false positives versus if you go about it the opposite way and say, I'm going to have nothing turned on.

I'm going to say, what are the high-risk activities in my environment? And what might, what might the log behavior look like if those things were to happen, and turn on those things one at a time. It takes longer, it takes more work and more knowledge of your environment, but everything should be a true positive. That's, that's the advice I give, and that's, that's how I approach it at this point. I'd love to hear your take on that.

Yeah, no, I would, I would, I would, uh, I would absolutely agree. I mean, I think we've, we've seen, it gets back to that success criteria because we have a, we've got a ton of out-of-the-box modules and packages and you can turn on all kinds of rules and things like that. But really the better way to do it is clarify the success criteria and the use cases that every customer is different. What's your priority? And actually I would say also goes back to the log sources, doesn't necessarily mean just collect all your logs.

First of all, what are those use cases? Now, what are the log sources you need to deliver on those? And then turn on the analytics rules that help deliver on that or the compliance rules. It also saves you money, right? It saves you money on licensing and the size of the appliance you have to buy.

Absolutely. And then at the end of the day, You're— because otherwise you get into that information overload scenario, which doesn't benefit anyone. And so you're gonna— you can really clarify, okay, and we've seen this, right? I mean, if you— sometimes you throw all your log sources at it, and this, you know, I'm the vendor, right? We'd actually want people to buy more licensing, but The reality is if they don't need it and they just kind of overload things, they're not getting value.

And ultimately the better thing is for them to get value. So it's really, it's actually sort of the phasing comes in because if you can really just hone in on what are those success criteria, what are you trying to accomplish in phase 1, what are those use cases, go execute on that. You know, get comfortable with it, get, you know, get good at it. And, and obviously we can help along the way and then move on from there. Sure.

You know, so I'm going to wrap this up because I know you want to respect your time. We're going to get you a couple minutes late to your next meeting. Sorry about that. A couple of things real quick, though. One, we've been following your guys' news over the last, over the last 6 months or however long we've been on the podcast now.

One of the interesting stories recently, you guys talked about a contest you're doing where people can get NetMon free— is that what— NetMon freemium and talk about a problem you're solving and they can win money, right? Right. I'd just love to hear how that came about and, you know, what's the motivation behind it? Yeah, we introduced a freemium version of our network monitor, which is network forensics deep packet inspection solution that's part of our overall platform. But we felt that that would be a way to kind of, one, give back to the community and here's something of value, particularly maybe smaller customers who are not able or ready to invest in a full SIEM.

For whatever reason, but this is something that would certainly be valuable for them. But it was also a way to kind of get LogRhythm out there, get people to know LogRhythm with a freemium product, see some of the value we could provide, and maybe they want to work with us more beyond that. Is it too early to talk about the contest in terms of if you got any cool entries to it? That part of it is just— we started actually, we had a contest giving away a trip to Black Hat. So that's already in, and the next phase of it is what you're talking about, which is really a contest for people to download this freemium product and create interesting, cool use cases using the deep packet analytics rules there around network forensics.

And that's really very recently just kicked off, so we don't really know. Too early to tell, but that's going to be going on over the next few months. And yeah, anyone out there listening, just go to our website, you know, look up the Network Monitor freemium page. I'll have a link in there and download and You know, it's got all the information on it. And I will definitely keep track of when you guys post the winners and we'll get on top of that.

Yeah. The last thing I wanted to mention, we also cover job postings in the area and we talked about a number of jobs here for you guys over time. What if you want to either make a sales pitch for why people would want to go here or what kind of people you're looking for? Either way, you know, I'd love to give you a chance to do that. Yeah.

I mean, I think, you know, at various times we're always hiring in all kinds of different roles. The company's been, you know, as the company's been growing, you know, so there's always needs. You know, generally I would say at a high level, look for people who obviously have an interest in the mission of cybersecurity and helping the good guys, you know, protect their networks against cyber threats. So obviously if that's of interest to you, and then, you know what, know, there's a lot of information on our website, our careers page, on, uh, the different types of roles. But, you know, also people who want, um, you know, like, like all of us, work in a, uh, a culture, uh, that is, um, you know, work hard, have fun.

Andy is sitting in front of me wearing shorts right now, so, so this is, this is not a place where you're going to have to wear a tie every day. That's Yeah, that's right. It's not the same time. You know, it's kind of a, you know, be comfortable, you know, be yourself, work, you know, we're so— we do obviously serious work, but we don't try to take ourselves too seriously. So I think that's kind of the balance as well.

Well, we're looking forward to what you guys are doing, and I'm not going to ask you to comment on it, but we'll reach back out to you after we hear IPO news coming from you guys one of these days. It's been— that's been the gossip for, for a year or so, a couple years. Maybe we can touch base a year from now and see how things have changed and keep in contact. All right, Andy. Always great to talk to you.

Good to you too. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes