All episodes

Bret Fund, CEO & Founder of SecureSet Academy

Apple Podcasts Spotify SoundCloud

In this episode:

Bret Fund, CEO & Founder of SecureSet Academy is our guest this week. News from: Amazon, Red Robin, ViaWest, SendGrid, Fast Enterprises, NCC, Red Canary, Webroot and a lot more!

HQ2 - So you're saying there's a chance!

Denver made the final 20 cities for Amazon's HQ2. Will they pick us? Do we want them to? Even if Amazon doesn't pick us, more and more retirees are. And Red Robin's going to stick around. ViaWest is now Flexential. SendGrid and Fast Enterprises are still great places to work. NCC spent a lot of money on a new roof. Plus we've got research from Red Canary and Webroot.

Come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9248 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 51, the week of January 22nd. Alex, winter has finally come.

I'm not sure if I believe it, Robb. I mean, we did get a little snow, but really, is it actually winter? I'm still wearing shorts. You are still wearing shorts. That doesn't necessarily have anything to do with the winter as much as your level of insanity.

Oh, well, that could be too. Maybe I'm just still in denial. But we do have a real storm here this week. Hopefully, you know, the drives to work are not too terrible for folks on Monday. Yeah, my kids' basketball games got canceled today, so I guess it must actually be a winter storm.

Do your kids play basketball outside in January? They do not. Inside basketball. So let's, let's go ahead and jump into the news. As a reminder, we have a mailing list.

If you guys want to get all the great stories we talk about in your inbox every Sunday afternoon, go ahead and go to colorado-security.com and sign up for the mailing list. Also, when you're there, you can look for information on our Slack channel. I think we, we were over 200 people in the Slack channel this week. So getting getting up there in terms of participation. Lots of good conversations happening in there.

So check out the link there and go ahead and join. Yeah, it's been, it's been really good. Good way to get to meet people who you maybe wouldn't have otherwise run into. Let's jump into the stories. We have a little bit of an update about the Amazon HQ2.

We've talked about this since it first came out. Denver is still on the list of Amazon finalists. Yeah, so they narrowed down the list to the top 20. And these are the ones that will go forward. We got a couple articles that we actually linked to this week.

One of them that talks about how Denver stacks up against the other folks that have submitted. So, you know, what incentives they've put out and that kind of thing. And then the other one, which just sort of gives general background and lists all the ones that are in the top 20. Yeah. And so we, we top 20 out of, I think it was 235 submissions.

Yeah, not bad. Really, you know, top 10%, top 9%. That's not bad. And in one of the articles, I think that they said someone ranked them how they saw them and they had Denver at 10. Yeah.

So it doesn't seem like we're a favorite to win this thing. No. But, you know, it's not bad. I'd say if we were on the East Coast, we'd have a really good shot of winning this. As it is being so close to Seattle, I don't think we have a great chance.

Yeah. But, you know, if Denver was on the East Coast, we'd suck like all the other people on the East Coast. Amen. Yes. You know, speaking of headquarters and moving to Denver, you hear Apple is looking at making a second headquarters as well.

Yeah. So they just put that— an article out about that this week, I think under the guise of, you know, the tax plan. Hey, we're gonna have all this extra money now. We're gonna— we're gonna make some more space somewhere in the US. So the article talks about Denver not being interested in this particular one.

So it was interesting to see the headline, you know, Obviously they're so interested in Amazon but not interested in Apple. And as I looked into why, if you read the article, you know, basically Apple is talking about bringing in a tech call center and the, the job, the pay for these jobs is quite a bit lower than the average Denver salary. And the last thing we wanted to do is bring down salaries here in Denver. Yeah, I mean, it makes sense. And honestly, from Apple's perspective, if you're going to do you know, jobs like that, you probably want to do it in a lower cost environment anyway.

You know, somewhere middle of the country, Iowa, Nebraska. I was— what I was thinking, something like that. Yeah. So Iowa might be the leader in the clubhouse. I think so.

Right off the bat. That right off the bat. Exactly. Brand new spaceship campus right in the middle of Iowa. Well, we don't know if Amazon's going to pick us and we certainly know Apple is not going to pick us.

But a lot of retiring people might want to pick Colorado. Good segue, Robb. Good segue. Yeah. So we had an article this week about Colorado moving up on the best states to retire list.

So this year we are— drum roll— number 2. Does that mean we're, we're ahead of Florida and Arizona? Uh, we— Florida is number 1. Okay, so we're not ahead of Florida. I don't think that will ever change.

Um, you know, 90-some percent of, you know, all retirees are gonna move to Florida. That's just the way it goes. Um, but yeah, good to hear that, that that were positive for folks that are retiring. And we're gonna have even, even worse traffic from, you know, all the, the old folks driving around on, you know, in their giant Cadillacs. Well, you know, God bless them.

I'm looking forward to that. And personally, I'll be in Florida. So when I get there, you won't have to worry about it. We'll have to worry about that. Speaking of people who want to stick around in Colorado, Red Robin has committed to renewing their lease for their headquarters here in Colorado.

So we've had a couple of you know, not so good news articles coming out about Red Robin recently with their, you know, not no longer expanding. And then they're laying off some folks at their corporate headquarters. But they have renewed their lease and they're going to keep their headquarters here in Denver. That's good news. It's never a good thing to lose the, the headquarters of a company.

So they're staying around. Alex, if I say the word Flexential, what does that mean? What does that make you think of? I don't know. Not good.

It's not, it's not a particularly good feeling that I have. So it doesn't immediately make you think, oh, this is the merger of Viawest and Peak 10? It does not. It does not. So I think we've talked about this in the past.

Viawest merged with another hosting company called Peak 10. In the article, they talk about how Viawest is, strangely enough, because of their name, focused on the west part of the US and Peak 10. With Peak, you'd think that they'd be west also, but they were focused more on the east. So they thought, hey, well, we need to show that we're really a national company instead of a regional company. So they changed their name and Flexential is what they chose.

Flexential is what they chose. That domain name was available. That's right. They, they went on the internet, found a, you know, a company name generator app and, you know, put in a couple of keywords and that's what came out. I love it.

They're going to get their mission statement from the Dilbert business speak generator as well. 2 Colorado companies made the Fortune's Greatest Places to Work list. Yeah, so we had an article similar to this last week, couple weeks ago maybe. So it is SendGrid and Fast Enterprises. Yeah, SendGrid is number 2 on the SMB list.

That's pretty good. You know, we're talking nationwide, number 2 for small and medium businesses. And then Fast Enterprises was number 11 for large companies. So it's good to see that Fortune reads Glassdoor and uses that as part of their research for the stuff that they post. Yeah, anytime you can get free research done for you, We should just— to be clear, I have no idea how Fortune made their list.

They probably did not steal it from Glassdoor, and I wouldn't want to have any lawyers sending me letters asking me to take it back. So to be clear, Fortune probably did really good work to come up with this list. Lots of original research there. So next, uh, we have an article from the Colorado Springs Gazette on the National Cybersecurity Center. So they have now opened and moved into their, their new digs down there I think in the past we've talked about that, how they were in a temporary space and had been remodeling another spot that they were going to move into.

So, Alex, when I moved into my house, it was about 8 years ago now. Yeah. I put a new roof on it. Yeah. I think that new roof cost me $12,000.

Yeah, it was expensive. Did you know when NCC moved into their new house, they put a new roof on it? Do you see how much that cost? They put on a new roof. I think they also, you know, put in a new air conditioning unit, maybe a couple other things, and it cost them about $8 million.

Yeah. Yeah. I put in a new furnace when I did my roof at the same time. About $17,000, I think, total. Yeah.

$8 million. I don't know. I— you guys know most of our coverage on this show is quite positive. I'm flabbergasted to see that they used $8 million on a building in Colorado Springs and have not built a program yet. For NCC.

So I, I would love to hear some explanation about how that investment of— it's taxpayer money, right? It's your money and my money to, to get this NCC going. Makes any sense to spend $8 million on a property when you don't have a program to actually run in the property? Yeah. I mean, they also talk in the article about how originally the plan was, you know, to help with incident response for companies, to You know, some other plans like that.

And they've essentially, you know, changed their roadmap and gone a different direction, you know, trying to be a think tank, trying to, you know, offer a training center, some other things like that. But again, still, I don't think that there is anything other than now a building that really exists with the National Cybersecurity Center. There's some quotes from Governor Hickenlooper and the mayor of mayor of Colorado Springs that were positive about this new direction. But I mean, I think from my perspective, it's just more of the same. It's vaporware at this point, right?

Yeah, it's really frustrating that we have, we have a leader in Governor Hickenlooper who is awesome for supporting security the way he does and getting the investment into security. And then we have this, these resources that are seemingly just going down the toilet, not providing any value anywhere. And someone's telling him, hey, this is going to build toward adding value. I don't— I think he's a very smart man, but he's trusting some people who are not giving him great advice, it feels like. If there's someone who wants to defend this and come talk to us and explain to us how value is being created, I'd love to hear it, but I just don't see it.

And we're 2+ years into it right now and apparently $8 million into it with, with yet nothing to be shown for it. Yeah. And they, they also talk about how they're trying to become self-sustaining now, and it appears that they're offering memberships, uh, to be part of the National Cybersecurity Center, uh, of various different levels for individuals and corporations. But still, you know, in the article, maybe it is somewhere, no information on what that membership actually gets you. Yeah.

You know, especially if you don't really have programming yet, I'm not sure what you're buying into if you get the membership. So yeah, I think it's just a big disappointment. Obviously, we'll keep an eye on this going forward and we'll keep asking folks about it. I did interview Andre McGregor, who's one of their board members, and he's— I think his interview is actually next week on the show. We talk about it just a little bit.

Uh, he'll give a little bit of insight, but you know, there's just not enough information yet to, to really see value being created there. And then finally in the news, we've got a couple blog posts this week. Uh, first one from Red Canary talking about credential harvesting being on the rise. Um, some good information in there. I've definitely seen a lot of this, um, as opposed to, uh, phishing and other things trying to get you infected with malware, instead trying to harvest your Office 365 or Google Apps or, you know, other credentials where they can essentially then go in harvest data, uh, start to move laterally within your network.

So turn on MFA and this whole problem is pretty well eliminated. Yep. Uh, number— the last, uh, blog post here, um, how to keep your cryptocurrency secure. And this is from Webroot and talking about, you know, if you have Bitcoin, Ethereum, whatever your cryptocurrency is, how do you stop someone from stealing it from you? It's a really easy target, right?

Someone's going to try and break into your wallet, take your money, it's gone forever. You don't get it back like you do with the bank bank. So here's some nice steps that you can use for, for keeping things secure. Exactly. And, you know, now that Bitcoin has crashed a little bit, maybe you'll be a little more safe.

But, you know, still, still a lot of value out there that you got to protect. Buy low, sell high. That's right. Get in now. Get in now.

I'm not an investment advisor. I'm not an investment advisor.

All right. So that's it for the news. Let's move on to trivia. So for last week's episode, the question that we had was, which local security company called Carbon Black the world's largest pay-for-play data exfiltration botnet? And of course, the correct answer there is Direct Defense.

Yes. And we did have a winner. Lots of correct submissions this week, but our winner was Marshall England. Congratulations to Marshall. Nice job, Marshall.

And once again, thank you to Andre Gaeta, who is our sponsor for the trivia. Without Andre, we would not have the trivia, and he's been been very faithful in rewarding our winners with a free item from the Colorado Equal Security Store each week. Yes, I have to say that he is definitely the number one purchaser from the Colorado Equal Security Store. And so our question for this week, this was actually from Andre, and it's kind of more Colorado security focused or safety focused. In regards to skiing, if a blank breaks, it interrupts a circuit which causes the system controller to immediately stop the system.

Remember, this is regarding skiing. And if this thing breaks, if blank breaks, it interrupts a circuit, which causes the system controller to immediately stop the system. Hmm. So what things in skiing have circuits, Robb? It's a great question.

It's a great question, Alex. All right. So we look forward to all of the submissions for trivia for this week. So let's talk about events. Obviously, on our website, we have our event calendar.

So you should go out there and check it. If you have events that you are putting on, please let us know. We try and get all of them on there, but we are not perfect. You know, pretty close, but not perfect. This week, first event, Lady Coders is having a Workplace Sexual Harassment: It Happens and What to Do Next event.

That's, that's on the 23rd, right? Tuesday? Yes. On Friday, we have a couple of different events. So we have Red Canary's Microbrew Tour.

That sounds really fun. It's kind of take a bus around town, go to a couple different tour breweries and drink some beers, and you get to talk to some cool people. Nice. And then SecureSet also on the 26th is doing a capture the flag. And then the next week on Tuesday the 30th, SecureSet is doing their Hacking 101 workshop with an intro to social engineering.

There's a few events that we want to talk about a couple months in the future. Actually, here coming up in February on the 21st, we have the CTA's Day at the Capitol event. This is an opportunity for you to get to learn how governments run, meet your legislature, any other good stuff like that. On March 8th, we have SnowFROC. That's the OWASP Annual Conference.

Should be a good event. Should be a good event, always is. On the 15th, a week later, is the Sea Level at Mile High event. This is the CTA's big annual fundraiser where they get, you know, 1,000+ people together, do a big networking event. This year, you know, they have their celebrities who are bid on, and we're going to have some CISOs involved with that.

So real good, hopefully, involvement for the security community with that event this year. And then of course, Rocky Mountain Information Security Conference is coming up May 8th through 10th. We are getting close to finalizing the agenda, including pre-conference workshops. We've got the keynotes locked down at this point, and then our call for papers is closing here shortly. So you should submit if you're interested in talking, and then we'll have that lineup shortly thereafter.

So I think, you know, we could at this point talk about the keynotes. They're on the website. I didn't— they are. We're free to talk about them. So our opening keynote is a man named Lane.

Oh, I'm going to forget Lane's last name. Hensley. Lane Hensley. Yes. Thank you.

Who's going to come talk to us really about how do you impact change in your organization? It's a big keynote. It's meant to be really impactful for how you go back to your work and work with the rest of your company. And then we're going to have breakouts after that where you can do some, some practice of the stuff you learned during that keynote. I think that one's gonna be really cool.

And then that's the first day as well. Closing keynote is gonna be Dan Burns, the CEO and founder of Optiv, the biggest security company here in Denver. Gonna be talking about his experience and really what he sees going forward for security in Denver. On the Thursday morning opening keynote, we have a man named Daniel Mesler. I'm a huge fan of Daniel's podcast, which is called Unsupervised Learning.

He is a security guy, but really he's a futurist. That's how I look at him. He's someone who's understanding how is AI impacting us, how are all of the consumerization of things impacting us, and where are we gonna be in 5 years, and what do you wanna do today to get ready for that? Really looking forward to that talk. Yeah, that should be good.

And then the last session of the day, we actually have another comedian, right? Phil Pelissol, Parasol? Pelissol, I believe. Pelissol, who's a local comedian who's also been on, The Last Comic Standing, and he's been on The Late Show and some other big, big-time stuff. But he's a Denver guy, and he's gonna kind of close us off after a long week of learning.

I don't think he is quite as colorful as Josh Blue. So I know there are some folks that were not quite as comfortable with, with Josh's type of comedy last year. So I think that this will be a little more family-friendly, a little more for all everyone in the audience. We did. I did go.

Not that I love Josh. He was awesome. It was, it was fun. Josh isn't for everybody. Yeah, Josh is not for everybody.

I did— I get— look up Phil on YouTube and watch some videos. Very funny guy. I'm looking forward to the show. Yeah, should be good. So I think that takes us to the end of the news for the week.

So we do have to do jobs. Oh, we do have jobs. Yep. And the first we have this week, Woodward— this is a Fort Collins job— is looking for a manager of information security. So Woodward is an aerospace company.

Oppenheimer Funds is hiring a senior network engineer. Arrow is looking for a senior security infrastructure engineer. Vail Health, which is up in Vail, Colorado, is hiring an IT security analyst. So if you want to ski and hang out in the mountains and still do security, this sounds like your opportunity. Hopefully it pays well enough so that you can actually afford to live in the mountains.

And, or maybe they have like a shack that you can get a bunk in or something. That's right. MITRE is looking for a lead cyber operations engineer. If you read the description of this job, it sounded really, really cool. But this one is in Colorado Springs.

What was cool about it? So now you're putting me on the spot, Robb. The— they talk about essentially cyber warfare and doing cyber operations. So you're, you're essentially developing tactics and tools for doing military cyber operations. And this is as a, as a contractor for the government, I assume?

Yes. Underwriter. Very cool. That's great. Um, Flatiron is hiring a cybersecurity policy and compliance analyst.

Uh, BSI, which is the British Standards Institute, is hiring an auditor for information security for ISO 27000. So if you actually want to be an ISO 27000 auditor for the company that does ISO 27000, then you can do that. And that's actually a Denver-based job. If you guys aren't aware, ISO used to be BSI. So it was the, it was the old British Standards 9001 that turned into ISO 27001.

So it all came from BSI originally. There's only a couple of different companies that can do these audits. Coalfire is another one here in Denver, but BSI is, uh, is the biggest one worldwide. Uh, and then Black Knight, who's a financial services company here in town, is hiring a senior penetration testing analyst for— yes, again, I like to add those jobs with the numerals on it, Robb. And then finally, LeaderQuest.

They are hiring a cybersecurity curriculum designer. And LeaderQuest, I believe, is headquartered here, and they are an online provider of cybersecurity education. Very cool. Yeah, very cool. I didn't know that.

I didn't know that till I found this job. Maybe we should meet those folks. I think we should probably reach out to them. All right, LeaderQuest, reach out to us too. Yep.

All right. Now that takes us to the end of the news for the week. Yes. Our feature interview this week is with Bret Fund. Bret is the CEO and one of the co-founders for SecureSet Academy here in town.

We talk about SecureSet a lot. I'm looking forward to hearing the interview. Yeah, we had Alex Kreilein, who was one of the earlier co-founders who ended up kind of spinning off and moving to their, their accelerator side. And then Bret's still doing the academy side. So we'll hear from Bret and talk about what they're doing and all the kind of fun stuff that's coming up over there.

Should be good. All right. Well, have a great week, Alex. Thanks, Robb. Hi, this is Colin Mariner, VP of Data Center Operations at HomeAdvisor.

This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Alright, good afternoon. This is Robb Reck and I am here today with the co-founder and CEO of SecureSet Academy, Bret Fund. Bret, thanks so much for finding some time to sit down with me and talk about what's going on in your world. Yeah, thank you for having me. Alright, so to start off, the first thing I want to do is talk about SecureSet.

The Academy, the Accelerator, where you're playing, and what really— what's the focus of what we're talking about today? So if you don't mind just kind of setting the context for what those things are, that'd be great. Sure. Yeah, no, um, there are a group of 5 of us back in 2015— well, actually 2014, uh, 4 of us, Alex Kryolan, John Black, and Chris Goldberg, got together and started both the Academy, the Accelerator, and then we recruited Brad Davis in 2015. We were the original group that started it As we move forward, we realized that both entities really needed their own, uh, you know, drive and management, and that's where Alex and Dave really took off on the Accelerator side, and then the rest of us continued on the Academy side.

Yeah. And then this last year, the Accelerator actually went through a rebranding exercise, and so they've been working out of the Franklin Street location where the Academy moved to the the Blake Street location right across from Coors Field. Yep. So, so for the context of today, we'll just focus on the, the Academy side of stuff. That'd be great.

And you said the, the Accelerator is now— is not Secure Site Accelerator now, it's called Darkfield, right? Right. And so we'll probably catch up with Alex Kreilein to hear what's going on there and perfect, get an update with him in the future. But for today, let's talk about the Academy. Great.

Very cool. Wonderful. Now what I want to do is just back up you know, as far back as we can and tell me, just you personally, how did you get into security? How did this crazy thing become an idea? And, and what's your background?

Sure. Yeah. Um, so I think part of this reaches all the way back to teenager, right? So when I was a teenager, this was, uh, late '80s, early '90s. So really before the internet as we know it.

So, uh, dealt more with like— so I played around with phone phreaking and the BB bulletin board systems and whatnot. So got into it there, had a couple friends, um, you know, that I associated with that, uh, you know, you know, had, uh, incidences with, um, law enforcement. Law enforcement. Yeah. Where'd you grow up?

Uh, in actually Ohio, but I moved here when I was 15, so a lot of this occurred here while I was in Colorado. Sure. In the Broomfield area, but Anyway, so it sort of dissuaded me and my friends because we were really worried about getting in trouble because we saw some of our friends get in trouble. Yeah, so walked away, went into college and focused more on the business side of things. Though I was still, you know, at the time it was PalmPilot, so I was cracking PalmPilot software.

Yeah, get around that. That's what you did in college, that way you could get it for free, right? But, you know, so I always have had an interest in security and in this space, but for you know, personal reasons, decided to go down the path of doing professional, more business stuff, and then went on to actually get a degree, my PhD in business and private equity. So went and started as a professor at CU Boulder at the business school. So, and I was a professor there for 7 years.

So while I was a professor there, I also started a venture fund there and had a team of students that worked with me from engineering to law to business. We got together, and that's actually where I met Alex. So Alex, you know, he and I became familiar through him working on the venture fund that I ran there. So I want to hear— I want to get more details here. So yeah, number one, what were you teaching as a professor at CU?

Yeah, so what I taught was class on entrepreneurship, class on private equity. And so then a second class on entrepreneurship to undergraduates. So I taught mostly in the MBA program, but I did teach an entrepreneurship class as well at the undergrad level. And then how did you create a VC? How did you create a venture fund?

Yeah, so worked with donors that actually provided some donations. So the model was we would take these donations, then we'd have a team of engineering, law, and business students get together, we'd go vet a bunch of deals, invest in those, and then as that money came back in, then we would grow the fund. So that way we could go to donors and say, you know, you can give us $100,000, we hope to make this into a bigger thing for students over time. We can give scholarships and other things and grow the money that way. So that was the, the premise.

So you had a VC without having investors who needed to get a return? Correct, yes. It was wonderful. That's a pretty good gig. It was, it was a lot of fun.

And honestly, it was so great for the students to just be able to have that experience and to be able to, you know, work to do that hands-on and actually make investment decisions versus just learning out of in a classroom. I've always been really big into immersive education where you get your hands dirty and actually do what you're saying you're going to do versus just talking about it. Yeah. And that's what we did on the fun side, right? Um, I would say like, you know, About 2, 3 years into my being a professor over at CU, I started being drawn back to the security space.

So, you know, I started doing the internet thing where you're going and you're downloading Kali Linux, you're looking at videos, you're trying to learn. And what was interesting to me is how far the field had really progressed from the early days of the pre-internet to where we were back in probably 2000, 2007, you know, 2008, um, to where things were, you know, just more advanced than where they— when I had left them. Yeah, they walked away. Um, but, and then talking with a number of people, realized that this was a big problem. And I think, you know, as we've seen, you know, uh, hacks and attacks become more prolific, right?

Um, trying to figure out the right way to solve the problem. And for me, I'm in education, I was in education at the time, and so it was like how do we solve this from an education standpoint? Yeah. Um, and then recognizing that what we do sometimes at the university level is not very immersive. It's a little bit more theoretical, academic, right?

It's academic. Yeah. So, but how do we get more hands-on opportunities for individuals who want to go into the space? Yeah. And then had been working on that and a couple different ideas, and then, um, you know, had started working on that with my brother actually, but then talking with Alex about it and then working with John and Chris, we all came together and said, man, this is, this is something that we can do.

And then like I said, Brad came on board and really we all 5 took off with the idea. Okay, so, so what year was it that you guys are, you know, said this is the idea, we're really going to go forward, we're going to do something here? 2014. Okay. Um, and then follow that, started to vet that with, uh, some investors that I knew from having ran this fund, yeah, had a number of contacts throughout the Denver-Boulder area, yeah, in the capital space, and then started to talk to them about the idea and whittled it down.

And then we basically raised money in 2015, and then that's when we started full-time operations. Yeah, so, so obviously, I mean, I could just tell from the outside and the folks I've talked to, you guys have been growing a ton. You started off with the one campus here in RiNo and that you've expanded. Can you talk to me, where are you guys currently at in terms of campuses and classes? Yeah, so we were, we had about 4,000 square feet in the Franklin, the RiNo location, and we realized we needed to grow because we were adding another program on.

We had the core program, which is more focused on engineer pen testing consulting. We were growing into this hunt analyst program, which is more, you know, threat intel analysts or information assurance analysts or even hunt analysts. So we wanted to add that program, but we didn't really have the space. So we moved to the Blake facility, and that's about 8,400 square feet. Yeah.

So that gave us more room to do that. But we have both our Denver campus there and our corporate team. Yeah. And our corporate team is growing, and so now we're looking for probably additional space so we can continue to house our operations. Yeah.

Now you have more than just Denver though, right? We do. So now we've got Colorado Springs that's online, and we actually have a really cool program down there. So we service a lot of the local population. We also have a program where we work with active-duty soldiers who are in their last 6 months of transition.

They can come to our school full-time and then roll out the other side and then we can set them up with employers and they roll right into a job once they transition out of the military. Yeah. Which is great. And then we also have our Tampa campus that is up online as well. So, we got 3 campuses right now.

Anything else in the works? Yes. We got more in the works. So, stay tuned for next year. There'll be more coming down the pike.

What does, what does the end state look like? I mean, do you imagine a campus in every major city, or is there, you know, what's your goal here? Yeah, I think the goal, um, I don't know that we need to get into every major city though, not going to preclude that, right? But I think at the moment we're really looking to get a footprint across the United States, which we hope to achieve in the next 3 years. Um, so we'll have coasts and then a couple in the middle, and then And once that, we'll probably focus more on some of the other modalities and other areas that we'll look to expand into.

So doing more with some corporations and what they're doing, as well as embedded programs with universities or others. So you told me, you mentioned earlier that one of the main reasons for doing this is that a university doesn't have the hands-on approach, but there's some other differences here as well, right? Would you just kind of talk through what does your program look like? What would a student, a potential student, look to get from this? Sure, yeah, and we really, we try to teach to the whole student in terms of what we believe in our conversations with the many corporate partners, I believe an entry-level security professional looks like.

So if we do the core program, for example, we'll cover topics around network security and system security, right? And those will include modules say in the network side, even around application security, where we'll have our students build a web app from scratch on a LAMP stack, then they'll go and attack it, then they'll harden it based on their attacking of it, then we have them attack everybody else's in the class while defending their own at the same time. So then they can learn, you know, how others think about their web app and attack it versus how they thought about it and attacked it. And then they're starting to harden that. And so, and this is just 6 weeks out of a 20-week module in the networks class that we do.

So that's just one thing that we do. 20 weeks total, is that what I just heard? 20 weeks total. We got networks, systems. We also cover cryptography and logs and detection.

Those are the more technical classes. But then we'll cover classes like governance, risk, and compliance, strategy and analysis, and threat intel, as well as security culture. And those are a little more less technical but more focused on helping them understand some of the managerial perspective and thinking about security strategically, not just security from what I have to do in my job every day. So that way when they come out, they are good technically but also understand their managers and the managers can help them. And then hopefully over time they grow up into those management capacities and can influence the field.

So you said 20 weeks. How much time commitment per week? Full-time. What's that mean? In our day program, they're usually there between 8 and 8:30, and they're done between 5 and 6 every day.

So they're full-time. Yeah, they're drinking from the fire hose. So 40 hours a week. 40 hours a week. For 20 weeks, basically.

Yep. Okay. And so most folks who do this, are they, you know, right out of high school, right out of college, career shift, career changers, right out of the military? What's your— what's the mix look like? Yeah, it is a mix.

I would say the— if we look at the average, that's 66%, right? They're probably between, you know, 26 and 40, but we have the tails as well. And so the 26 to 40, it's got to be a career changer then, right? Oftentimes career changer or early in. We'll see a lot of individuals early in tech, maybe a net admin, sysadmin, web developer, but then have always loved security.

They they want to get to security, they just don't know how. So we become a great path for them to do that. Yeah, because you can go and get certifications, but that doesn't mean that you necessarily can always put your hands on the keyboard and do things, whereas they come to us and they can do, you know, the hands-on stuff, which will help them in their job interview. So, so you— we just talked through the core, right? Yep.

Tell me about the second program, the Hunt program. What's the difference? Yeah, the difference is it's a It's less time, so it's only 12 weeks. Still full-time? Still full-time.

It's more focused on analytics, and it has unique classes, so it doesn't have cryptography, for example, but it has an expanded logs and detection, which goes deeper in incident response and forensics, whereas in core we do a little abbreviated on that. We also have a separate hunt class, which looks at more data visualization and active hunt versus passive hunt. And the idea is that on the core side, we're dealing more with the engineering types and pen tester types. The analyst side don't need to be as technical, but they need to know enough technical speak to talk with the engineers. But they're gonna be focused more on data analytics and going, hey, we see trends in this area in the network, maybe we should go investigate, or maybe we should go put some sort of a trap there, a lure there, so we can figure out what's going on.

So they're going to be more the data watchers and the analysts versus the engineers. Okay, that helps. So it sounds like, you know, from what we said earlier and what you're saying in the interview, you've had great growth. You know, how big is the class right now? So for example, we have 20-some students in our core class, and we we have 30 in our hunt class, and that's in Denver.

And then in Colorado Springs, same sort of thing, we have about 30— 27 in our core class in Colorado Springs, and I think about 15 in our hunt class in the Springs as well. So, and what's your, uh, I'm not sure how to put it, employment rate? What's the job finding rate after graduation? Well, so Today, within 6 months, we've been able to place all of our students, though I think this is going to be our largest section of classes. But the great news is we've also got a larger bench of employers.

They've been growing as well. We have one employer that is interested in hiring 10 from one of our classes. They're just— which is great. It's great to have that kind of commitment from some of the employers. As well.

I mean, there is no shortage of available jobs out there. The question is getting the people with the right skill set, right? That's exactly right. Obviously what you guys are trying to tackle. So everything you just said sounds really good.

I want to hear the hard parts, right? What have you done so far in the last 3 years that hasn't worked or has really been a challenge through this process? Yeah, well, I mean, I think it's probably similar to a lot of other people who have started companies. It's— there are some So last year at this time, you know, we had our, uh, smallest class ever. We only had 4 students for the whole company.

Yeah. So you think about that. This, this, you know, this fall we'll have, um, over 100, right? But last year at this time we didn't, and so, uh, things were a lot bleaker, right? So was that a dip after having a larger class?

Yeah. Okay. So we had our largest inaugural class and we we had probably 12, 13. Yeah. And then we went to our second, which was only 4.

Because you had some pent-up demand that you, you met. Yes, that we met. How do we find people? Yes. So that was exactly right.

So that, that was the time where, you know, at least for me personally, I had to go back to some of my investors and ask for some additional money, which was great. But then I also had to empty some of my own bank account and savings and make payroll and I mean, those are the hard times of a company, um, and it's scary, right? Because you're putting a lot on the line. At least I was personally. Um, but here we are a year later, and I think a lot of that has, uh, paid off, which is great.

Now you're lighting cigarettes with $100 bills? Well, no, I'm not saying that. No, we still have a long, long way to go, but, um, we— it's great to see the good that we're doing. Yeah. And see the model working.

At the same time. So what— you guys are obviously privately owned, is a small group of investors doing this. What is the plan to, to grow this thing up and sell, to, to build into your own big company? What are you guys thinking? Yeah, I mean, you know, for me, a lot of this is very mission-driven, right?

So you look at sort of the mission, what we're trying to do is we're trying to, you know, transform and secure the world through premier cybersecurity education, right, and training that next generation of cybersecurity professionals. And that's going to require us to do a lot and have the impact. So we're going to need the multiple campuses across the country to be able to have the impact to really try to accomplish that mission. So my point is, we have taken some private money. So what does that mean?

That means it's at some point we've got to figure out how, you know, how do you pay it back? Yeah, how do we give it back, right? How do we— and there's multiple ways of doing that. But what's great about it is our investors all to date are sold on the mission, not just on the money-making opportunity. And I think that's where largely across the organization, that's what we see.

So we're really about this to educate that next generation of cybersecurity professionals. That's step one. And then at the same time, we're— I'm very fiscally conservative, and, and as an organization, we try to do the same thing so that we, you know, we make smart moves with the money that we've been given and we're stewards of. Yeah. So, um, so one of the things you guys have been very well known for doing is having lots of community events, right?

That's— yeah, from the beginning, it seems like you've had weekly, maybe more than weekly events at your, at your campus, you know, the 2 different campuses. Talk to me about the, the, the driver behind that. And, you know, not only do you have your own, like, the, the hacking, uh, like the hacking, the CTF events, yeah, that are once a month or so, you have the, you know, bringing in industry folks to talk. Yeah, all kinds of stuff going on. What's behind that, and, and, uh, what are you guys getting out of that?

Yeah, so part of it, our community, being part of a community is really important for us. So anywhere we go, we want to be part of a community. And what, at least I think for me, what we find is that in order to find people who are interested that want to try their hand, or people that are professionals and want to give back in some way, they're all interested in being part of a community, right? And And they already are usually parts of various communities. So we just try to come in and put together events that stitch it together, right?

So we do the Hacking 101s and the Career Conversations, which are really meant for people who are looking to get into security but don't necessarily believe they can, or they want to see if they can and they want to try their hand out on it. Yeah, so those are free events. We put it on just to let people come in and try their hand. We also do the, the meetups, which are a little bit more professional. Speaker series type events.

And again, that's more just to engage and have a context of interaction for people in the security community to come together. And then the CTF— all these events we hold every month, right? The CTF is a place where you can have newbies as well as other people who have been in this industry to come and just play, right? And play in the space. And all the events are free.

They're all meant to just say hey, whether you're trying to find out about it, whether you're already in the industry, um, let's get together and talk about it. And we just want to be the gym that you don't have to feel uncomfortable walking into because, you know, everybody's already, you know, security professional and you feel out of place, right? Or, or whatever. So we want to make sure that everybody feels comfortable and has an event to come to. One of the things I thought was really neat is in your capture the flag events, you have the first hour set aside for beginners, right?

Yes, there's the beginner kind of learn how to do it, and then after the first hour is kind of the main, the main event itself. So I've never seen someone do something quite that way. I thought that's a really cool idea. And the fact that you do it every month is, is neat. It's a good commitment.

Yeah, um, it's good for them because we have a lot of people who come back month after month just because they want to see, they want to progress on the levels. And to date, we haven't had anybody go all the way through all the levels, which is great. So they have more to play. There's a lot, there's a lot to learn out there, isn't there? Yeah.

Yeah. So let's just talk about what you, you know, why Colorado? Obviously you're a CU guy, so that's part of it, but why, why Colorado? Why are you doing this here? Yeah, it's interesting because when I had originally started working on the idea, it was around an opportunity that was forming out in Utah, but then ended up not being what, what we thought was the gonna happen there.

And Colorado just has such an amazing community, so it was actually really fortunate that Utah didn't, because they don't, in my perspective, have as, as a mature community as we have here in Colorado. There's just a lot of great security companies, a lot of companies that have their security teams here that aren't necessarily security product companies, and we really do have a developed community. Whether that's ISSA or OWASP or BSides, right? There's, there's great pockets of communities here that are easy to tap into and people can learn a lot about security. Yeah, that's great.

And I appreciate you guys. You guys have not just shown up. I think to your, to your point, you guys have really added a lot to the community over the last year-ish. Thanks. Really appreciate your commitment to doing that.

For those listening who either may be thinking about getting better trained or recommending somebody else to get plugged in with you guys, how should they reach out and learn more about the Academy? Yeah, I think the easy way is just go to our website. We've got contact information there. Obviously, info@secure-set.com.

There are several of us that get that email. I'm one of them, so we're all listening, we're all active and happy to help people who are interested in moving into this direction. All right, I'm going to change it a little bit, just talk a little bit more about the community and advice for us. Your perspective is unique, doing academics and then now getting to help train the next generation of folks. What skill sets do you think security people don't have now that they need to have more of?

Current security people. That's a great question. Um, I don't know, I think a lot of the individuals that I've met in security are very talented, right? And, and oftentimes what I would say, and maybe I'll talk about it this way, as I see some of the people coming in, um, especially on the engineering side, you know, a little more development around some of the soft skills, um, is, is what we work hard on. So for example, our security culture class in our 20-week program goes the entire And part of that is just to make sure, you know, that we can— that when people get out into the field, they can communicate and persuade and talk appropriately.

Because sometimes I think being technical, you think, well, I've got the technical solution in my head, all I have to do is talk about the technical solution and the other person will understand. And we all know that's not the case. So helping bridge that gap between saying, okay, I got the solution, but how do I communicate it? How do I understand the interest of the other person to the point where I can tell them how this aligns with their needs or matches up with what they want? And communicating the problem that you're trying to solve, right?

So often, not only does the person who you're talking to not know what problem you're trying to solve, but maybe you yourself don't know exactly what the problem is. Right. We found a hammer and it's a really sweet hammer and I'm gonna swing this thing. Regardless of what it is we're trying to do. Yeah, okay, very cool.

Any guidance you'd give other than obviously getting, you know, kind of the soft skills better, aligning with the community? Anything else you want to share about, you know, what you think folks can do better to help get better at security?

I don't know, I think it's really hard to say. I think we do have a really fantastic community here, and what I've seen is a lot of individuals willing to to help and mentor. And so I think oftentimes what I see is individuals being afraid to raise their hand and ask a question or to ask for the mentoring. Because what I've seen from people like yourself and others who are willing to talk and are willing to mentor, but people aren't necessarily willing to ask, right? And so I think especially people early on in their career, they don't want to look dumb.

And I think so, you know, just that culture of it's okay to not know everything and to fail every now and again is, is going to be important to sustain here. Yeah, I like that, you know, ask for help. The, the follow-up to that I'd say is be willing to do the work when you ask for help. That a lot of times the more junior folks will come and say, hey, I could use your help, and, and then not come prepared and not, you know, not show up on time and just do those basic basic things of, you know, hold your end of the bargain and you're going to have a lot more luck with whoever it is. Well, great.

I really do appreciate your time. I'm looking forward to hearing about, you know, your next classes and whatever it is you guys are going to come up with next. Hopefully we can get together maybe like next year and— Sounds great. Update for what you're doing. Yeah.

All right, Bret. Well, thank you very much for your time. Yeah, appreciate it. Learn more about the Colorado security scene at coloradosecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security.

Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes