All episodes

Matt Alderman

Apple Podcasts Spotify SoundCloud

In this episode:

Matt Alderman, is our feature guest this week. News from: Google, Coalfire, InteliSecure, CyberGRX, Ping Identity, Alchemy Security and more!

Why doesn't anyone ever impersonate me?

Someone's been impersonating a candidate for the mayor of Loveland, Google invests big in Boulder, Colorado regulators take a look at cryptocurrencies, rogue robots on the horizon, Coalfire has a new executive, InteliSecure targets midsize enterprises, CyberGRX partners with BitSight, and Ping Identity gives their take on the new iPhone's FaceID security. Can you believe we're covering all that in the same episode!?

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

This week Alex interviews Matt Alderman, product advisor extraordinaire, and former VP of Strategy for Tenable Networks. Matt talks about his history in security from independent consulting, to starting consulting services at Accuvant, to leading strategy for Tenable. Matt also shares his ideas on being a successful product manager, cool emerging product areas, product segments ripe for disruption, and what companies in Colorado are on his radar.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10700 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the newscast for episode 34 on September 25th. This is Robb Reck, and I am in the studio here with Alex Wood. Alex, how are you doing this evening? You know, I'm doing pretty well, Robb.

Spent some time down in Colorado Springs today. Drove up to the top of Pikes Peak with my folks. That was fun. Was it, was it really cold up there? It was pretty cold.

Yeah. We actually were almost all the way up and had to double back because we couldn't get to the top. And then they opened it and that because there had been a lot of snow yesterday, you know, obviously it was raining down here. It was snowing up on the top of Pikes Peak. So made it up to the top.

Pretty snowy, pretty cold, but it was fun anyway. Well, good stuff. We have an exciting week, a really full week coming up here. Security Advisor Alliance stuff we'll get into in the events I'm looking forward to. But let's go ahead and jump into the news first.

Before we do, just a reminder for folks to subscribe on iTunes or Google Play. Help us get those automatic downloads. It's good for us, good for you, we hope. Rate the app in your favorite store, in iTunes or Google Play, and give us a review. We'd appreciate that.

And let's go ahead and get into the news. So the first story we had today, up in Loveland, there was a woman impersonating a potential mayoral candidate. So this isn't a cybersecurity story, just a good old-fashioned physical security story. It's interesting, you know, she's been walking around basically, number one, it's kind of strange, she's a supporter of the candidate, and she's going around and telling people she is the candidate, but apparently she's not breaking any laws, so the cops aren't going to do anything about it. Yeah, it's, uh, it reminded me a lot of what happens in cyberspace these days.

People pretend to be other people, walk around saying things, you know, setting up Twitter accounts and whatever it might be. Um, I think we always have to remember this stuff goes back to the physical world. The physical world tends to mirror the cyber world. Yeah, absolutely. All right, so we've been talking a lot about Amazon maybe bringing a second headquarters to Denver.

Well, that's a maybe, but for sure Google has just invested a pretty huge chunk of money up in Boulder where they bought a 200,000-square-foot office complex for about $130 million. It's going to be about 2,000 employees here on this new building. Yeah. And this is, this is essentially the place where they've been building out. I think that the big difference here is that they originally, they were planning to lease the space and then decided it was probably more advantageous for them to just buy it outright instead of leasing it from a property management company.

I did note that in the article there was the ability for them to build one additional building beyond what they already have in place. So it's a good sign that, that they're financially committed to Boulder and with the potential of building out even more than they already have. So that could be another 1,000 employees up there, it looks like, from the size of the buildings. Yeah, exactly. There was an article called Cryptocurrency Draws Scrutiny in Colorado.

State's Securities Regulator Sounds a Warning. So, the regulators in Colorado are taking a look at cryptocurrency and essentially, I think more specifically at initial coin offerings, which are becoming pretty popular. So, basically, you know, as a business is starting up, instead of doing an IPO, they're doing an ICO where they're offering some sort of cryptocurrency. And depending on what, you know, what the ICO is on, you may get something for it, you may not get anything for it. But, you know, regulators are saying, well, you know, if you're getting a part of the company, then this needs to function like a security and we're going to have to regulate you.

So I will say it is different in that they're not getting a part of the company generally in an ICO. They're getting a piece of imaginary something. Exactly. That may get value over time. And that's why they've been able to kind of skate around the IPO rules in the past.

But the SEC says these ICOs are now going to be— going to have to play by SEC rules. That's going to be interesting going forward. Yeah. And I would definitely check out that article. It was pretty in-depth.

Lots of stuff in there. But it is behind a paywall, which is, which is a bummer. We ended up breaking down and paying for the Denver Business Journal subscription. So if you need some insights, send us a note at info@colorado-security.com. Next article is actually from the Colorado Springs Business Journal, which I think is the first time we've covered a story from down there.

Manufacturers prepare to battle rogue robots. This is basically the coming of all of our dystopian novels, right? Exactly. Robots coming to get us. It's an article talking about how, you know, industrial robots, just like other, you know, internet-connected devices, potentially there could be harm that comes from them.

People take over robots, either shut them down and you can't use them, use them outside the bounds of what they were originally intended for, could cause physical harm, other things like that. One of the friends of the show, Sean Murray, who is down in the Springs and on the ISSA International Board, is quoted throughout the article and definitely has some good advice for manufacturers who all too frequently are just not up to speed on their security hygiene. Yeah, I definitely want to make sure that you secure your Internet of Things devices, especially if they can cause bodily harm to people. Yeah. Next, Coalfire appoints a new CFO, Michael Chow.

I don't know Michael, but I don't know Michael either. He was the CFO at Keypoint Government Solutions previously and at Vail Resorts previous to that. So he's been around Denver a little bit. He then he also worked at Famous Brands, eBay, and KPMG. Nice, that's a good history, good for Coalfire.

Yeah, it's nice to see new leadership there. InteliSecure, they've launched some new managed security services offerings this week to help midsize enterprise protect critical data. Yeah, so this is a neat one. Generally speaking, insider baseball here, most security vendors and security solutions providers are really focused on selling into the enterprise, 'cause there's just a lot more money to make selling into large enterprises. This is a neat new offering from InteliSecure, kind of bringing DLP, their, you know, their critical asset protection, which we talked about a lot a couple episodes ago, bringing that into the SMB market and really giving, you know, an affordable entry point to get control over that data as it resides in your network and as it leaves the network.

Yeah, I think that there's really a ripe opportunity for many companies in that SMB space, especially for, you know, the sort of the bigger size of SMB. Yeah. And as a reminder, InteliSecure is hiring a director of security in GRC right now, kind of their security leader role. I believe this is an up-and-coming company and someone it'd be good to hitch your wagon to. So look at, look at that and send us a note if you need an introduction over there.

CyberGRX, who we've talked about a couple times, they've partnered with Bitsight to address supply chain risks. This is interesting because this article wasn't Colorado-focused, right? This is a national article that was really hitting on one of our up-and-coming security companies here in town. And really what it does is CyberGRX is a platform that enterprises can use to have insight into the vulnerability, to the security posture of lots of different vendors of theirs. And there's other ways that can be filled in.

And they're augmenting that platform with the BitSight info, which is kind of a little bit like a credit score for a security posture of an organization. You know, one of the things that they mentioned in there was that, you know, BitSight sort of gives an external rating. They're looking at external data, whereas CyberGRX is actually doing an internal assessment. They're trying to standardize those, the questionnaires and the other ways to get that internal assessment. But now you could get the internal and external assessment.

Yeah. The other thing that I thought was interesting is CyberGRX had previously, they had a similar capability. So I'm not sure exactly what happened with that capability. I don't know if they just decided that it's easier to partner with Bitsight, who has a much, probably a much more mature practice in that area. But I think it is definitely an interesting idea for them to come together so you can have that holistic view of a potential third party.

Yeah, agreed. And then finally, Ping had a blog this week about multi-factor authentication and the security of iPhone's Face ID. So the iPhone X came out, well, it's not technically out till November, but it was announced. And one of the things that was announced on it was they were getting rid of the home button and Touch ID and instead using Face ID to do authentication. So this article talks a little bit about biometric authentication, you know, how it is that they are potentially doing it with Face ID and whether or not they think it's a good idea.

There's a lot of interesting stuff. So the guy who wrote it, David Waite, is a fantastic guy here in Denver, very, very smart security guy and knows iOS inside and out. What I hadn't realized initially right after the announcement was that as they added Face ID, they were getting rid of the ability to use Touch ID. And you might see out on the web there's a few different places that show kind of the comparison, not to say which is better, Touch ID or or Face ID or a password, but what's the difference and when would you want to use one rather than the other? And it's really clear to me that, you know, Face ID is not going to be for everyone.

It's going to be a subset of people who would rather look at it and have it, you know, that integrated use case versus touching it. And I'm going to be interested to see how popular this is. And does it, you know, does it ever take the place of Touch ID or is it going to be, hey, I'm going to buy my phone based on which one I prefer? Yeah, well, and I think one of the things that I had heard was that Apple was trying to get Touch ID to work without the dedicated home button. So if they could have gotten that to work through the screen, they would have done that.

So maybe in the iPhone 11, maybe they'll have both. So another interesting thing I thought from this, this article was that with Touch ID, there is a false positive rate of about 1 in 50,000, which sounds like a pretty small false positive rate to me. And then, but what for Face ID, it's 1 out of every million. So significantly higher assurance that they have that they're not going to have someone getting through positive or who shouldn't get through. And it's basically there's like 7 different factors that they use for this.

Anyway, really good blog post. Take a look at it if you want to learn a little bit about how that works. So that's all the news that we have before we move on to the events. Just a reminder that we have a store. So if you haven't bought your Colorado Equals Security merchandise, you should go out and check that out.

We have a link on the website. Buy t-shirts, buy, buy your kids onesies, buy some stickers for your car, whatever it might be. Go, go check it out and buy some stuff there. And we also on the website have an event calendar. And I'll tell you that every week as I go fill in the calendar, I'm amazed.

And we filled out a ton of events coming up through the end of the year, all the way out into December right now. So a lot of stuff coming up. Go ahead and sync this up with your calendar to see what it is you want to attend through the rest of the year. So first on the calendar for this week, Denver Startup Week tomorrow morning. There is a cybersecurity compliance and security panel that is, I should probably know this, it's at 9:30 or 10.

It's at 10. 10 to 11:30. We have to be there at 9:30. Robb and I are participating in this panel. So if you want to come to Startup Week and listen to us talk about security compliance for startups, you can do that.

And on the, actually all week long is SANS Rocky Mountain and fall. And that's a conference with training. I don't know if you haven't signed up yet, it's probably too late, but maybe swing by and say hi and maybe you can go next time. The 26th and 27th, the CISO Advisor Alliance is having their leadership summit. That is the Westin in Westminster.

That is a— there's a cost for that conference. And obviously it's focused on CISOs and security leaders, but I would bet if you are local and haven't signed up yet, you could probably finagle your way in. On the 27th, NCC has their Cyber Healthcare Exercise. Also on the 27th, there at Denver Startup Week is the Security Founders Panel, which Robb is moderating. Yeah, and we're going to have the founders from several different companies: ProtectWise, CyberGRX, Red Canary, Swimlane.

I feel like there might be one more, but it should be a really good time to get to meet some of the local founders here. On the 2nd of October, DENSEC has their South Meetup. That'll be at a bar. Check it out on Twitter. On October 3rd through 5th, Conversant is having their Converge 17 conference, which is a business ethics training conference.

Yep. Also on the 3rd through 5th, Vector8 has their Threat Hunting and Advanced Analytics course. That one looks really cool, technical in nature. On the 5th, ISSA Colorado Springs has a professional networking event. And then finally on the 6th, this is a new event that I just came across this week.

Coalfire has a high-trust community extension program. There's not a lot of details in the press release that mentions this, but take a look, maybe reach out to Coalfire if you want to go, and as I find more details, we'll get it on the calendar. Sounds good. Let's jump over into jobs. Do you remember, was it 3 months ago we had Matt Sharp as a co-host on the show right before he left town to go move to New York City and become the CISO for LogicWorks?

Well, Matt is back. Well, at least he's back. Sort of. Sort of, kind of. He's hiring a senior cloud security engineer here in Denver.

This position looks pretty cool. They're— it's located at the, the WeWork building over by Union Station, and it's really working heavily on AWS security and some other cool cloud DevOps-y stuff. Vertella, they are hiring a Director of Systems Security. Comcast is hiring a Security Operations Center Manager. Pegwright is hiring a Security Solutions Consultant.

Great West Financial is hiring a Principal Security Engineer. Catholic Health Initiatives is hiring an enterprise security architect. NREL, which is what, the National Renewable Energy Laboratory? They're hiring a smart homes application developer. That sounds pretty fun.

Yeah, that was not a direct security job, but they had some security mentions in the job description. So, but yeah, developing stuff for smart homes, that sounds pretty cool. Please do it well though. Veritas is hiring a DDoS security engineer. Do you know Veritas?

I don't know Veritas. I don't know Veritas either. I'm guessing that they do something around DDoS protection. Well, that or maybe data center stuff. I don't know.

Interesting. Alchemy Security, Jobo's company, is hiring a cybersecurity junior analyst intern. And then the job title with the longest title. Charles Schwab is hiring the 2018 Schwab Intern Academy vendor technology risk management intern for information security risk management. Yeah, so that's a heck of a business card.

Yes. So, you know, especially if you're young enough to be an intern, you would probably want to sign up for this so they can put those 27 words on your business card, your resume, saying that you had this position at Charles Schwab. Very cool. Well, that's the end of the jobs right here. We're gonna go over the feature interview, which is you sitting down with Matt Alderman.

Matt is a Colorado guy who right now I think is a kind of international man of mystery. Yeah, I think, you know, he's doing some advising for a couple companies, I believe including Automox, which is out of Boulder, but he also is doing his own thing, doing strategy development. He was previously with Tenable Networks, so doing their strategy there. Acuvant as well. Spent some time at Acuvant, spent some time at his own company, which did some GRC solutions.

Great talk with Matt, really interesting stuff. We talked a little bit about project or product management, a number of other things, but I like Matt a lot and it was a good interview. All right, well, that'll be it for this week. Hopefully we'll see you guys at one of the Denver Startup Week events. Otherwise, hopefully we'll hear you next week.

All right, guys, thanks, Robb.

Hey, this is James Carder, CISO at LogRhythm. This is Colorado Equals Security for Colorado security professionals by Colorado Security. Professionals.

Hey, this is Alex Wood and I am here with Matt Alderman. Matt is a longtime vet in the security industry, been around a long time. I've known Matt for, I don't know, probably 10 years, probably, yeah, just from being around Denver and, you know, coming to speak at ISSA meetings and things like that here. Matt, I guess I'll just turn it over to you for a second to introduce yourself, you know, where you've been, how you started, and what you're doing now. Yeah, thanks, Alex.

It's funny because, you know, we've known each other for a while, but I don't spend a lot of time in Colorado. Yeah, because I've worked for companies outside of Colorado on East Coast or West Coast, so it's always interesting to like connect the dots of like the local community. But yeah, so I got here in 2004. So, you know, before that I was in Ohio, in Cleveland, and I started doing security in '96 when I left nuclear power. I worked in nuclear power for a number of years and decided to leave nuclear power and started consulting.

And my first project back in '96 was antivirus. That was right around the time of SQL Slammer and everybody was, you know, freaking out about viruses. So I remember my first project was at National City Bank, which is now part of PNC, replace McAfee antivirus with Symantec, I think because they did a better job of protecting against— anyways, and that turned into then firewall work with Check Point and then Cisco. And so I consulted in Cleveland for a for a number of years in and around security compliance. I did a lot of third-party vendor management work for National City later in my career in Ohio, running their third-party vendor management program.

And that's kind of how I got to Colorado. In 2004, we had already owned land in Colorado. My wife and I and the family really loved the area, and so in '97 we bought land and we just We didn't know when we were coming. And in 2004, I was doing— I had my own consulting firm in Cleveland, and my mother-in-law retired, and she said, we're ready to go. Like, okay, so we literally— yeah, it's time to go.

And so we literally packed 2 truckloads, 2 houses on a truck, and sent it west. And my wife's like, well, what's your job going to be? I'm like, well, I'm still consulting, and I can do it remotely. I'm okay. So I just came out west and I eventually ended up merging my consulting practice into Accuvant back in '04.

And I built out their original compliance services practice back in 2004. And the vision was compliance was a driver for security. The Accuvant guys were really good at security, but somebody who understood compliance and the compliance drivers was something they thought they needed. And they thought they needed it from a services and product perspective, not necessarily to build product. And, you know, one of the things I had in the back of my mind from all the work that I had done at National City in third-party vendor management was the ability to build some sort of tool to manage the assessment process, the remediation workflows, etc., etc.

And Acuvant's like, ah, we don't know if we want to be in the product game. And literally, I think I merged everything in August of '04, when we— right after we got here. And by September, we had landed our first consulting engagement, and the customer came to us and said, I don't have enough people, can you build me a product? Right, that's great. Now do the stuff that you were talking about for doing all the remediation.

Yeah, exactly. And so within 2 months of getting in Acuvant, we started building a product that we thought we should build, but we weren't quite sure if we would ever build it. And so what ended up happening was we built out this software product internally. We called it AccuCert. And then in '06, Scott Walker and Dan Wood and the founders and I sat down.

We said we really should spin it out, not keep it as part of AccuVant. At that time, AccuVant didn't really want to be a product company. They wanted to be a reseller services company, and they still primarily are. And so we decided we'd spin it out, and that's when we spun out ControlPath here locally. And so I took a good chunk of the original team I had hired in the compliance services practice, opened an office down here in the Tech Center, and we started building out ControlPath.

And we were competing with, you know, Archer and RSAM and Agilience and all those guys at the time in the really early days of GRC. Ran that through '08 here locally, and then when AccuVant got the first private equity deal, they were our primary funding source. And so we ended up selling the business in '08 to Trustwave. It was between Qualys and Trustwave, and the decision I made was get everybody employed. So we ended up going Trustwave, and, you know, hindsight's 20/20, it was the wrong decision.

Yeah, um, I eventually— I took my engineering team and I went to Qualys, where we did a lot of work on their policy compliance module, the cloud platform enhancements to their questionnaire and PCI stuff. That was a lot of the work that we did when we went to Qualys in '09 to '12. I left there, I went to Archer, got a great opportunity to go do some strategy and work at Archer. You know, I competed with them for almost 5 and a half years in the GRC space. So to go to RSA under the Archer brand and do some stuff on the Archer team was really, really fun.

Does that product that you sold to Trustwave, does it still exist in some capacity? It exists. Or did it just die on the vine somewhere? No, the majority of it died on the vine. The broader GRC vision behind what ControlPath was built to do died.

The pieces that remained were all PCI-focused, so the report on compliance. What Trustwave really wanted the product to do was to help automate the generation of report on compliance. And so they used the questionnaire functionality and the evidence collection pieces really to build out the rock. And that, I still think, exists within their portfolio, but the rest of the stuff we did with third-party vendor management and the broader regulatory compliance stuff, I think all that got shelved. I don't think any of that exists anywhere anymore.

More. And then from Archer, I went to Tenable, where I was up until April running strategy for, for the Archer team, or for Tenable, which was kind of fun. So yeah, how was that? You know, I love— so the early days of Tenable were just fantastic. And if you think about where they were, I'll tell a story that I've told a few people when I left RSA.

And but the early days were really, really fun because Tenable was in a very interesting position. They'd only taken a— would they take a $50 million A round from Accel like in '14, '15, something like that? And they were looking to expand out the executive team and really put them on the next level of growth. You had all 3 founders, Ron Gula, Jack Hufford, Renault-Derson, all still fully in control of the company, which I thought was great. And really this desire to bring in people to go.

And so when, when the opportunity came up, I was intrigued. And so I decided to go. And when I resigned, Art Coviello called me. Art was running RSA at the time, and he said, he said, I don't want you to go. I said, I know, but I said, I gotta go.

I said, the opportunity is great. And he goes, but don't understand why Tenable. He goes, why not Qualys or Rapid7? And I said, Art, I said, I was already at Qualys, Rapid7's not asking, and I said, I think Tenable is in a very interesting spot to disrupt the VM space. They got money, they've— then they can be disruptive.

They're not public yet, they can do some stuff. And I can tell you, when I got there and late '14, we, we've really started to move some stuff in the right direction for Tenable to the point to where they are today. And what's more interesting is that Amit Yaron, who replaced Art Coviello at RSA, is now running Tenable as a CEO. And so when I saw Art last year at RSA, I said, so what do you think about that Tenable now that Amit's overrunning the ship? He goes, I I never saw it, never saw it coming.

But it, you know, the early days were just fantastic. We really made a lot of progress in the cloud platform.

Tenable has some very interesting capabilities in the VM space that the other 2 major players don't have. It really puts them in a unique position. So I had a great time there. But after some of the changes with the Series B round from Insight, changes at the board, Ron's departure, you know, Amit coming on and putting his executive team in, I didn't feel I can make the same sort of impact anymore. So that's in April when I decided to leave.

Yeah, it's time to go find something else to do. Yeah, so it seems like the common theme in all this stuff though is that you really for most of your career have been working on product. So you've had a cool idea or you've come into to a company that has a cool idea and you've really tried to work on those products and be a product manager or work on the strategy around those products. So I think that's something that most times we don't really think about in security. It's really more of a— it could be anything, a general product, but, you know, we're dealing obviously in security.

So, well, you know, what is it for you that you do as a product manager? Because I think a lot of people probably don't know And then, you know, what is it that you have seen that makes you a successful product manager? Yeah, you know, at first I didn't think I was a product manager for the longest time, right? I mean, way back in my early career when I was in nuclear power, we were writing what we called tech specs. We were basically writing PRDs back then.

We were writing the requirements to build software, but somebody else is doing the work when you're in a vendor, right? So Control Path and Qualys and RSA and Tenable. It's similar, but the roles are a little bit reversed in that you're now defining the requirements of, of what the product needs to be. And there's two— there's a couple different trains of thought about how products get developed, right? Most startups have this great idea.

Technology is really, really cool. But the question is, does it solve a problem that people are trying to solve? Does it provide value to the customer? Because what we see a lot in security, I think, is really, really cool products, but do they really solve a problem? Do they really provide value to the buyer?

And if they don't, then you could see these really great technologies just kind of fizzle out, right? And so I think the magic with product management is the tie to the value proposition, which is a tie to marketing in some respects. Right? So if you think about a traditional organization, they'll have maybe a Chief Product Officer responsible for engineering, product management, maybe product marketing. Then you have marketing responsible for corporate marketing and go-to-market and field and all this other stuff.

To do it really, really well, the two teams really have to have a good alignment. And I think that's where a lot of security companies, and maybe even technology companies in general, struggle a little bit. Is you got a really cool technology that you think is just awesome, and then marketing is trying to go out and figure out what problem that thing solves, and maybe they find a way to solve the problem differently or uniquely, but then they have to convince product to actually build it that way, right? And so there's this very interesting connection between marketing and product that have to get really, really aligned to do it well. And I've had— luckily, when I was at Archer, I spent a lot of time not only on the product strategy side but on the marketing messaging side.

So I got to learn a lot about value and how you drive value, and then how does that articulate into product roadmaps. And so a lot of the consulting work I've been doing since I left Tenable is this alignment of what's the company vision, what is your What is that message you want to take to the market? Where is your strength? Where is your, what I call, value proposition? And then align that to your roadmap of, well, how do you then develop and drive a roadmap that enhances that message to the market so that people continue to adopt and buy your technology?

And that's an interesting balance that I don't think every company has figured out yet. Yeah, and I mean, one of the other things I think that plays into it too is things like usability and other things like that that are part of the value proposition but are not necessarily directly related to the problem you're trying to solve. It's about how easy it is to use the product to solve those problems. Yeah, a lot of people think ease of use is a value. It's a feature more or less.

It helps with adoption, but just because you have a really easy-to-use interface or product doesn't mean it's still solving the problem. And it's that products are built to solve problems that customers have. And if you can't articulate that well and you can't prove to them that there's value in what you do to solve that problem, they're not going to buy. Right. That— and that is a disconnect most people don't have.

Then what you see from a product perspective is customer-focused or market-focused, right? And that's the other interesting part of technology. In a highly agile world that we are today, some product managers and chief product officers will think everything has to be vetted and validated by a customer. And I think that works really well when you're doing a B2C-type business where you're selling to consumers, where the consumer is the buyer, right? And so customer validation is very important in that particular case because they're also the buyer.

But in B2B, That's not necessarily the same because the people who are using the product may not be the ones that are actually buying the product or that you have to go get budget from. Right, exactly. Right. And so sometimes you need to do some market validation outside of the customer and really understand the trends of the market and where the market's going so that you can balance between what the customer thinks they want and what the customer— what the market is really going to require them to need in the future. And that's an interesting balance in a B2B play that also impacts product management, because you can't just be 100% focused on the customer.

Sometimes you have to be thought-leading, you have to understand those broader trends so that you're building a product that the market eventually requires. And so those are always interesting balances. Yeah, I do tend to see a disconnect a lot between the focus that are using the product, you know, mostly your technical folks, and then the, you know, your executives or other folks that are going to be the ones probably that are buying the product. Because, you know, the technical folks see, oh, this is something that's really cool, it may be able to help me in my day-to-day job, or maybe it's just cool, right? But then it's hard, it's often hard for them to articulate back to the executive folks Hey, why to buy?

Why to buy? What's the actual value that the business is going to see from this? Not just, you know, what's the value to me as an individual contributor? Right, exactly. And that's that value proposition again, right?

Because if you can't convince your CISO or CIO or whoever who's got the budget to buy it because you can't articulate the value, then it's not going to go anywhere. Anyways, right? And that's, that's why I do believe that there is a strong tie between what the product can do, feature functionality, to the value it provides to whoever is buying it. And sometimes you have to, you know, do some things a little differently with your, with your marketing campaigns or even your roadmaps to make that work. So how is it that you are getting the information that you need to, to figure out if you're really solving a problem for somebody?

Are you guys in the past, are you going out and doing, you know, interviews with customers? Are you, are you doing this sort of in a bubble where it's like, oh, I know this is going to solve a problem, let's go build it, and then, you know, you turn around and, you know, maybe it does or maybe it doesn't? So it depends on the stage of the company, right? In the early days, it's all internal. It's like, I got this great idea, I know what I want it to do, I think it solves a problem, without much customer validation, and then over time you find out it does or it doesn't, right?

In more mature companies who have been established for a while, it's easier to then go out to the customer base and validate certain things, right? And that's important because you have to keep your customer base happy from a recurring revenue renewal perspective, but you also have to go capture new customers. Prospects. So I always like to go out and talk to partners, our resale partners, MSSP partners. What are their customers asking them to do?

They were a great source of data from potential prospects because I couldn't focus 100% on customers. If I did, I'd build like a really high-scale vulnerability scanner that did zero false positive detection, but maybe didn't solve the other problems that people needed, right? So partners were a great source of that. When I was at Tenable, we had a fantastic research team, and so that team tracked hundreds. I think we were just under 300 companies that we tracked in the adjacent spaces.

So we understood our competition really, really well. We understood the competition in all the adjacency markets we may or may not want to enter and what their message, what their value proposition were. So that if we wanted to go there, we already had an idea of some of the things we were gonna have to do to compete in that market. So there were other sources besides just customer interviews, but customer interviews were an important part of what we do, what we did, and what Tenable still does to this day. But there was always a research kind of market trend and kind of prospect partner analysis that needed to be part of that, that broader vision.

Yeah, I'd like to explore that a little bit more. So you, you're obviously, you're not at Tenable anymore, you're doing some stuff on your own for the time being, um, but you, I'm sure you still have to stay on top of, uh, of the market, of trends, of, you know, uh, you know, where things are going. What are some areas that you're seeing now that are either up-and-coming areas or areas that maybe are ripe for disruption, for someone to come in and disrupt? Yeah, so there's a number of them, and, you know, my inbox is inundated every day even though I'm, you know, doing my own thing. I'm still reading, you know, a dozen articles a day of stuff that's coming in.

Markets that I like that are starting to pick up pace, I have for a while, you know, I've been a big believer that the device vulnerability is shifting to the application, so I've been a big proponent proponent of application security, the containers and microservices, these like new applications. There's a lot of interesting technology and startups coming into that space really to solve application security for the next-gen application. Applications aren't going to look like a big RPM or tarball anymore, right? They're going to be built in the cloud. They're going to be built with Docker containers, highly microservices with all this underlying API communication.

And the way you protect that's very different than the way we used to protect applications in the past. So you're going to see companies like StackRox and, and BanyanOps and others that are Twistlock, etc., continue to grow and gain some share as these new applications really take hold in the corporate environments and continue to move forward. So I really like that space, been tracking that for a long, long time. I'm a— I, I— the other space I really, really like is security orchestration and automation. Yeah, I do not think we can solve this with bodies.

I don't think there's enough cybersecurity resources to handle this stuff. You know, we still see detection times over 200 days. And we see patches that can't be applied in less than 90 days. I mean, some level of orchestration and automation is, I think, the only way we're going to be able to shrink dwell times, shrink time to respond, which we're going to need to do to fight things like WannaCry and other things. I mean, WannaCry is a perfect example, I think, right?

We knew 2 months in advance It was a critical vulnerability, but it missed most people's patching windows if you're on a 90-day patch, and so you were susceptible to that. If you could shrink that window through orchestration and automation, most companies would not have been susceptible to the WannaCry ransomware. To me, it's how do you speed up aspects of the operational side in a way. So I like the SOA space. You know, you've got Phantom, Cyber Response, and others that are doing that.

Swimlane locally. You have Automox up in Boulder that I've been doing some work with that is all on the patching and the configuration side. You know, it's just interesting. People struggle just doing basic patch management, right? So the ability to put some workflows and some automation into patching there's a huge value play there for customers.

So they're up in Boulder. I really like what they're doing. So I like that space. I think it needs more trust, right? So we have to learn to trust these systems.

We're gonna have to allow humans to kind of step into the process and do some approvals. But over time, as we build trust, the ability to auto-apply and auto-protect tech systems, I think, is the future if we're going to continue to keep up with the hackers in an environment where we don't have a lot of cybersecurity resources. So those are 2 spaces I absolutely love. Disruption-wise, there are some— I've always said the firewall market's been ripe for disruption for a long time because the perimeter is vanishing, right? Right.

As you move stuff to the cloud, what do you need a firewall to protect anymore if all your data is up in the cloud. Amazon is providing WAF and firewall services there. The firewall market to me has always been in this— is kind of at the precipice of a major disruption. We'll see when it actually happens, but as the trend to cloud and mobile continues, the perimeter just vanishes. I don't see how you need a firewall when there's no perimeter Anymore.

Anyways, the, you know, then there's other spaces, right? You see even in the vulnerability management space, you're starting to see this uptick of what's called threat and vulnerability management vendors. The guys that are taking the data from the VM vendors, putting analytics on top of it, and trying to provide some higher-level analytics and prioritization.

Could they disrupt? Maybe. I don't know. I know all the VM players are obviously looking at them like, what does that do? Um, those are some of the markets, you know, those— the markets that have been around for a while, right?

Everybody's got a firewall budget, everyone's got a VM budget. Anytime you see that, there's a potential for disruption in those markets because people are going to try to find a different or better way to address aspects of that and try to pull that TAM into their core market. So things, you know, Tanium's doing aspects of this with, you know, introducing security capabilities on their agent, right? Will they disrupt some of the core VM and configuration guys? Maybe.

ServiceNow has an interesting opportunity to disrupt from the CMDB asset inventory side to say, can they do aspects of this in a much more centralized way? I mean, there are plays out there that potentially have potential impact. The ServiceNow one or other vendors like that are really interesting to me because if they can do it right, they're already going to have the baseline of the information that you need to do this work. Because you need the asset data, right? So who's a better source of asset data than the CMDBs and ServiceNow being one of the big ones?

Ones, right, has an interesting opportunity to potentially disrupt other markets adjacent to the core asset data. Yeah, I wonder what your thought is on, um, one of the things that people keep saying is going to be a disruptor, which is, um, you know, artificial intelligence, or, um, you know, there's subsets of that, whether it's machine learning, or I, I don't know that there's really any, you know, quote broad artificial intelligence at this point, even though people keep saying that. Yeah. But is that something that really is going to be a disruptor? Is it just a marketing term?

Is it— what's your feelings on AI? Today it's a marketing term. Everybody throws it around. Anton Chervakin posted on Twitter, I think yesterday, you know, whenever I hear a vendor say AI, I have to ask them what they actually do because everybody uses the term, right? They're using AI or ML or some version of it.

So I think there's a lot of hype around artificial intelligence and machine learning and what it can do, but you're actually starting to see some companies start to use it in a way that's interesting. And where I think AI comes into play longer term in the security space is the ability to predict potential attacks, and therefore tightly coupled with security orchestration automation, the ability to actually preventatively protect a device or an application before the attack actually is available. That's where I see the future of AI in the security space, is that you see— we see a new vulnerability released and an AI model says there's a 95% probability this this is going to be an exploit, then you know that I should patch that vulnerability before I patch all the other ones because it has a high probability of exploit, right? So that's where I think AI and, and all this advanced analytics stuff can eventually come into play. How many are actually doing it in production today?

I'm not sure. Um, it's definitely a lot of marketing hype behind it, but I know there are some very good companies out there working on some really cool stuff on the predictive side, and that's where I think its best use case is for us. So back slightly, we mentioned a couple of Colorado companies, Autobox and Swimlane. You know, we have a fairly vibrant startup community here in Colorado. Are there other startups that you see, or even just— I don't even know if you want to say they're not startups anymore— any other security companies in Colorado that you see as being particularly interesting, or maybe folks that are, you know, maybe need a kick in the butt that are here in Colorado?

Well, so the other big one here locally is CyberGRX, who just took a Series B a month or two ago. You know, they're really trying to build out the third-party vendor management sharing aspect of what the old Shared Assessment Program tried to do. I mean, I was doing this back in 2003, 2004 at National City Bank. It's always been the nirvana that the banks and the service providers share data and really get a better way to manage risk more centrally. CyberGRX is trying to do it here in Denver.

So, I definitely watch Fred and the team and what they're doing. I think there's an opportunity there.

We've got Red Canaries down here in the Tech Center here somewhere close. They're downtown actually. Oh, they're downtown. Yeah, I don't know much about them. I mean, I've tracked them for a little bit, but I haven't seen what they've been doing lately.

There's some stuff starting to pop up out of Boulder again, so you're starting to see the community pick up. And then you've got some of the old traditionals, right? You've got Coalfire, you have LogRhythm, you have Webroot.

What are those— you know, I guess what's the future of some of those guys look like? It's always interesting, right? You know, LogRhythm's done pretty well in the SIEM market, but what's the next step for them? You know, Webroot's been really good on the consumer side. What's the next steps for them?

Coalfire PCI and and some of their strategic services. But again, you know, what's the longevity? What's the next kind of thing for them? I think it's always an interesting thing. Obviously, Optiv, based here in Denver, you know, the Acumont Fishnet stuff.

You know, I was, I was at Acumont for a number of years, and so I always tracked those guys. And, you know, there's been some interesting hires over there. You know, Dave Castagnola from RSA went over to, to run global sales for them. So kind of watching what they're going to do, you know, do they do more than just their traditional resell, some of their MSSP and their services? Are they going to do some other stuff, you know, with like Avantix and stuff?

They're, they're offering some third parties, right? They have some, yeah, some third-party risk stuff product. Yeah, in there, which is— so will they do more of that? Yeah, you know, they're always fun to watch. I feel like they're sort of in a transition period.

Trying to figure out exactly what they want to be when they grow up. They're, they're big enough that they can do stuff, right? But it's, all right, do we want to, do we want to move more towards services? Do we want to move more towards— right, do they really double down into the managed services side, right, more than they have? I mean, they've got an offering, but do they go bigger there?

Do they do more like they were doing with Avantix, which is kind of a product and a service a little bit together, but that's more on the product side for them? Or do they just stay with the traditional resale and services offering, which, you know, that to me, that business gets harder and harder to grow, right? Because, you know, you got to keep selling services and bodies and software and hardware to continue to keep that momentum. Where, you know, recurring revenue streams like managed services or even product, you know, that helps the, the monthly recurring revenue streams a little differently than a product resale. So yeah, it'll be interesting to see.

Um, are there any other local companies that people may not know of, um, that, that are worth a look? I know we mentioned Automox earlier, which is one that I've— I'm familiar with a little bit because of you mostly, uh, but I'm sure that, uh, many people probably haven't heard of. You know, we've talked about most of the other ones that we mentioned on the show. Yeah. Um, No, not off the top of my head.

Um, I'm still recovering from vacation, so I'm still trying to get back in the swing. I got, you know, we got home Wednesday, early Wednesday morning, so I'm still trying to think about who else is— I was trying to think about who's down. Dome 9 is down in the Springs, but I'm, you know, the, the corporate's there, but Some of their other stuff's, I think, out of DC or something, but I haven't seen much with them lately. I'm trying to think who else is— anybody else down in the Springs that nobody knows about? Now, most of it's up in Boulder right now that I'm seeing.

Yeah, that's— that's— the Springs has always been an interesting enigma to me too. It's, uh, you've got so much security capability down there, but it, you know, it's all government focused. It's all gov, yeah. It's Fed, gov. So you see less of the, I think, sort of the startup mentality and people coming out of it that way because it's obviously a much more controlled environment to be a government contractor as opposed to being private sector.

Right. We see the same thing out of DC, out of the Beltway too. I mean, you see a lot of those tech companies just focusing their stuff right back into the federal government. There's a ton of engineering talent there like there is down in the Springs, but it's all focused more on Fed than it is on startup and commercial stuff. Yeah, it is interesting though that, you know, you do get a lot of startups that come out of those folks in the DC area that's, I'm tired of running the government stuff, let me go do my own thing.

Yeah. Um, so I guess maybe I am a little surprised that we don't see as much of that down in Colorado Springs. Yeah, but there's good talent down there. You don't see much, uh, kind of startup stuff coming out of there. Yeah, maybe just more, uh, career government lifers down there.

They're not, not interested in taking a chance. Who knows? Maybe. Um, so, so what— I guess what's next for you? You know, you've got some, uh, it sounds like some consulting work going on.

Um, are you looking to, to get back into being in a product company? Yeah, I think so. Uh, you know, Like I said, for a long time I didn't realize I was in product management, but I am. And yeah, so I'm trying to find that next home. What's the next place to go?

The interesting thing for me is I can go a couple different directions, which is kind of the weird part for me because I've done a lot on the product strategy side, but I've also done a lot on the marketing messaging side of the house. And, you know, I'm not quite sure what that next position looks like. Is it staying on the product side, or is it kind of expanding more of my marketing side and spending more time— I enjoy being outbound. I have for a long time. I like going out and talking to people.

You know, I've done a lot of keynotes overseas at RSA Singapore and Abu Dhabi, a couple years ago in the US. So I like to get out and tell that story stories. So I like the outbound side, which is more on the marketing side of the house than it is on the product side, which is more inbound focused. But yeah, both— either one of those is kind of where I'll probably land. The question is, will it be with a local company, right?

Or will it be back to the East Coast or West Coast again, which is where the majority of the opportunities are, I think, right now for me. But Yeah, it would be nice to stay in Colorado. I just, I don't know if I'll find the next home in Colorado or not yet. Yeah, being that you, you haven't worked in-state in a long time, how much are you on the road? Are you— oh yeah, the last few years, a lot.

You know, I think it was 312,000 miles in the air last year, right? So yeah, I was covering the world for Tenable between Europe, Middle East, and Asia on multiple trips, and then back and forth between here and Baltimore. I racked up a good amount of miles last year, which doesn't— that doesn't bother me at all.

It's, you know, finding the right opportunity where that's fun to do. It was fun. You know, I enjoyed doing that kind of stuff at Tenable, and, you know, Ron really gave me the opportunity to do it. You know, when I did the first one, um, and the second one came along, I'm like, Ron, if you want to go do it, do it. He's like, no, no, no, you do it.

And I was like, okay. So I kept doing it. And yeah, that was a lot of fun building, you know, building out those messages and those stories and those keynote presentations. I enjoy doing that, um, but I also like building product because deep down inside I'm still a I'm an engineer. I'm still that techie guy deep down inside, so I like to build product too.

So it's, it's an interesting balance for me of trying to find that right fit. Yeah, for sure. So I know in addition to doing this interview today, you do, I'll say, a fair amount of other podcasts too. You've been involved with the Security Weekly crew a bit lately. What's that been like?

Uh, it's funny, you know, so Paul Asadorian used to work on my team. Yeah. So we had the— that research team, and when I got there, we kind of built out the team. And Melinda Marks, who's over at StackRox now running marketing, ran that team, and Paul worked for her. And, and so I always enjoyed going to do the tenable stuff for Paul.

And so when I left, Paul's like, I gotta get you on the show, I want to interview you on Startup Security Weekly. They asked me to co-host a couple weeks ago. I was asked to co-host last night, but I couldn't. I enjoy it because it's so much fun to interact with those guys. I mean, you've got Jack Daniel, Jeff Mann, you know, who used to be at Tenable, Paul, Michael, John Strand, and stuff.

So there's a really good core group of guys, and it's always fun to get on and like compare notes and talk about the latest stuff. Like Was that a good investment or not a good investment? So you can have these very interesting conversations with guys that are just experts in the market. We can kind of debate the market and what's good and what's bad. It gives you an outlet to share some of that stuff more openly.

So I've enjoyed that.

And Paul's a good friend, so it's always fun to be able to do something like that. Of that stuff. Yeah, I mean, most of those guys have been around for a long time. Oh yeah, lots and lots of knowledge. Uh, so I'm sure that's been fun too.

Oh yeah, yeah, it's fun. You know, when I did— when I co-hosted a few weeks back before I left on vacation, um, I, I sent, um, Michael, uh, Sarcantangelo, uh, I said, hey, by the way, here's all the news articles I think we should cover today. And I sent them to him. He goes, this is great. He goes, Paul never prepares like this.

He goes, we're gonna have fun today. And most of the stories we had kind of overlap because I track so much of the market. Yeah, every day. So, you know, I thought I was going to host last night on, on the regular Paul Security Weekly. And so I got home from vacation, I'm like, I'm writing down all the stories I want to cover, you know, because, you know, Symantec's made 2 acquisitions in the last 2 weeks, right?

I mean, they're on— they're, they're out acquiring products to fill pieces in the portfolio. And, you know, there are lots of holes to fill. Yeah. And, yeah, and, and, you know, there were a couple good interesting funding rounds in the last week. And I'm like, you know, so I see this stuff every single day come across my inbox because I do want to understand what's going on in the broader market.

So it really helps when you're on one of those shows or podcasts. You connect, you know what's going on, you're current with all the news that's going on where sometimes people in the vendor community, you know, they're so busy day-to-day building their product, they're not necessarily looking at what's going on in the rest of the industry. They don't have the time. We had the luxury at Tenable to have that team that could look broad and really track those companies. So we had a really good idea of the competition and the funding and kind of the new and upcoming technologies that we wanted to look at.

And so I haven't lost any of that. I still, even though I'm, you know, doing some side consulting and interviewing and doing others, I'm still tracking all that same stuff I was tracking before. But I find that the podcast stuff too, it helps you really make sure you understand the stories and things like that. You know, a lot of times I'll see, you know, I track a lot of news and everything else myself, but it's, you know, you'll see a headline, you'll maybe read a little bit, skim, whatever, and you're like, I think, okay, I'm not interested in that. Or whatever.

But, you know, if you're gonna actually talk about it on a show, you have to understand what you're actually talking about. You can't just have a surface-level knowledge. You have to, you know, be able to talk to it. So yeah, and you gotta understand where it fits, right? Yeah.

And you gotta dig in and do a little more research. You might read a couple articles. You might wait a day or two to figure out, you know, kind of what, what, what the analysts think about it, right? Because you want to see the— was that a good move or not a good move? Sometimes when you see the news up front, you like scratch your head.

I remember when HP bought Niara, right? I was like, why? They just, you know, divested a bunch of their security portfolio. Yeah, why Niara? Well, because they embedded it into all the Aruba stuff to do advanced behavior stuff on the wireless networks and stuff to tie into aspects of the Aruba portfolio.

But you didn't realize that until a couple days after the acquisition announcement that that's what they were planning to do with that acquisition. Position. And then it was like, oh, well, that kind of made sense. But at first, everybody was scratching their head going, why'd you buy a security company when you just divested a bunch of security stuff? Anyways, yeah, so we're getting close to running out of time here.

Um, any other topics you wanted to cover or any closing thoughts? No. If anybody's listening that needs a good product or strategy or marketing guy in Colorado, I'm here. Awesome. Well, we'll put your contact info in the, uh, in the show notes and people can get a hold of you that way.

And Matt, thanks, appreciate your time. Thank you, Alex, always a pleasure. Awesome.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes