All episodes

Cam Williams, Founder & CTO at OverWatchID

Apple Podcasts Spotify SoundCloud

In this episode:

Cam Williams, Founder & CTO at OverWatchID is our guest this week. News from: Google, Xactly, Gates, Red Canary, LogRhythm and a lot more!

Colorado = Security is always a bull market

Google is hiring in Colorado (Xactly too). In the blockchain Colorado trusts. Time to mentor. Gates IPO went pretty well. Red Canary's founder hits Forbes. A blog from LogRhythm. And a spotlight on our friend Gail Coury.

Come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10353 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Rob Rack and Alex Wood.

Been going along, it doesn't get less strange. The grip of the terror as it freezes the age. The blossoming crisis, oh, it breaks.

Whoa, Robb! Hey, what are you doing? Well, I was kind of feeling my jam. I just decided to let the theme song go this week, Alex. That's not what we do, Robb.

There's a set time for the intro. Yeah, you know, honestly, full disclosure, I wanted everyone to know that this— the rest of the song, it's not quite as good as the part that we normally let you play. I think it's just that you're in vacation mode, Robb, and I think you're just— your mind's not here. It could be that my mind is on a beach somewhere sipping margaritas while you enjoy shoveling your driveway. Yeah, well, hopefully not, but maybe a little bit.

Maybe a little bit. But that is the Agrarians playing The Language of Blame, which, as I mentioned, has a great intro and a great exit. A little mediocre on the singing. So Back to sort of regularly scheduled. Welcome to Colorado Equals Security.

This is the newscast for episode 54 for the week of February 12th, right? Yes, right. That sounds right. We're a couple days early here recording this week. Uh, we, we have a huge number of big stories to go through this week.

Yes, but we've actually decided to go through, go through some not as exciting stories instead because the good ones are a little too exciting. Number one, Google, right? Google. Yeah. So Google has announced that they are hiring thousands in 9 states, and some of those are going to be in Colorado.

Apparently they already have a decent number of employees here, but they could be hiring as many as, you know, 1,000-plus people here in Google in the future. Yeah. And their office is up in the Boulder area. So maybe us Denver folks, that's why we don't realize that there are already so many Google people here. But that's good.

Good news. And if Google hiring people here wasn't enough to excite you, well, we've got some news. Yeah, so the Silicon Valley software firm Xactly is expanding in Denver. So I believe that their offices are downtown on Larimer Square. I think they already have 150 or so people here, and they say they could have as many as 400 to 500 more folks get hired here in the next couple years.

They didn't give exactly the timeframe about when that were was going to happen. But, you know, it'll get there. It'll get there. So when you think about cybersecurity problems for our state, if you had to— if I had to ask you to give me one word for what technology solution do you think could really solve our problems, what would you tell me? You know what?

The first thing that comes to my mind? Blockchain. Blockchain. Yeah. Oh, jinx.

It's got to be blockchain. It's got to be blockchain. Well, if you haven't heard, there is a new law proposed out there about having our State of Colorado CISO Debbi Blyth, and I assume her whole team, look into how they can use blockchain and other encryption to improve security. Yeah, so there was a bill introduced in the Senate that essentially it's trying, it has good intentions, right? We're trying to increase the security of data at the state, Uh, and also, um, I think they sort of threw in there, uh, you know, uh, recreational marijuana transaction as well.

Um, but you know, they sort of, I think a little bit went off the rails and also threw in blockchain that, hey, let's, let's use blockchain to do this. So the ideas are great. I, I am of course being a little ironic here. I think it's, it's a little silly to expect blockchain to be, you know, it's a technology, it's not a solution. Um, and, and there's this quote in here from one of the politicians, uh, House representative from Colorado Springs.

And he says, that's the exciting part about this. There's hundreds, if not thousands of use cases for this. It's a transformative technology. We don't know what it's going to do, but we know it's very powerful. Yes, very powerful.

He literally has no idea what it's going to do. And neither do we. Right. And we had a conversation about this on the Slack channel in the last week or so. Right.

That blockchain sounds like a cool thing, but are there any actual implemented use cases where it's helping with security at any of our companies. I mean, and even beyond that, even if we think blockchain is going to save the world, I don't think putting any particular type of technology into a law is a good idea, right? So this is sort of like saying, hey, you know what, Debbi Blyth needs to investigate Windows NT and has to use Windows NT to, to secure our state government. To be fair, they do say or another distributed ledger technology, and there's not— there's a few others out there, but blockchain is the number one. So, okay, so that's saying we have to use Windows NT or another Windows operating system.

There you go. You know, a little bit better. It's a little— it's a little limiting. Yeah, sure. I agree with you.

There's obviously a need to get better across the board and And if there's a place where we can utilize blockchain for, I guess, really transparency and getting trust in a decentralized system, that's great. But that's just not, not the way to do security. Let's figure out the stuff that we want to do and then figure out a way to secure it as opposed to telling somebody how to do something because it's secure. Yeah. And of course, throw in the pot industry.

It just— well, hey, because we're in Colorado, right? We care about pot. New topic. New topic. So this, the next article I think actually was fairly interesting.

It was about mentoring. So this is really just talking about, are you ready to be a mentor? And, you know, I have been a mentor, I've been a mentee. I think mentorship is, is a great experience, but there are some key points that this article talks about that you really need to be able to think about if you want to be a good mentor or even a good mentee. Yeah.

Um, you know, first, are you willing to make the time to do it? Uh, some people think, okay, well, this sounds like a great idea, but then you don't invest the time and it just doesn't work. Right. Um, the second one was, are you able to be honest about your experiences? A lot of times, um, people are not interested in giving the actual truth.

You want to, you know, maybe sugarcoat it a little bit, and that's not going to help you get any better, right? So you really need to be honest. And then also, are you comfortable with difficult conversations? If you're a mentor, oftentimes you're going to have to tell your mentee some serious things that they might not want to hear. Hey, you know, I want to be— I want to be king of the world.

Okay, hold on there. You don't quite have the makeup to be king of the world, so let's think about something else. Yeah, that's great feedback. I know that this was a big topic at the Women in Security meeting last week. The, the report back from it where they were talking about mentorship and really this kind of level above mentorship, they called it sponsorship, where you're, you know, you're not just there to help someone get better, but really to help promote them within an organization or help them find that next thing.

Another, another cool thing that I loved, the concept of partnering with someone less junior in their career that you can help move up the ranks. Know, assuming of course that it's a good fit, but being that guide for them. Yeah, that's a great point too. So next article, Gates. We talked about that Gates had an IPO.

This article just really talks about how it ended up going. They made— I'm gonna call it an even billion— an even billion dollars on this transaction. Several hundred million, I will say. $799 million. The headline rounds it up to $800 million.

I think we can just call it a billion. This was sort of— I think they ended up at $19 a share for their IPO price, which is sort of right in the middle of their range. Yeah. So I'm sure they could have done better, but this is great, great news for them, especially considering how bad the stock market's been the last week or so. They're still hovering right around their IPO price, so they're doing better than most of the market right now.

Exactly. Next, there was an article in Forbes this week interviewing Brian Beyer of Red Canary. Yeah, Brian's the CEO over there. We've had him on the show already. Brian's just talking about, you know, where we are in terms of the skills shortage and how we can get good at responding to more events by leveraging something like Red Canary.

Yeah, great to see Brian, especially in Forbes. I mean, that's a big deal. That's not some little podunk publication. Yeah, it's just neat that he was able to make it into Forbes. It's pretty cool stuff.

Next story is LogRhythm giving some more detail on that intelligence. Last week we talked about their integration with WebRoots threat intelligence into the SIEM. If you remember, that's the news we got directly from New Zealand about the 2 Colorado companies. This week they go into some more detail on how you do integration. So if you are a LogRhythm customer or considering it and you want to get that intelligence into your, into your SIEM, I think you read this article to learn some more.

Yeah. So this is the actual logarithm release on the, on this. So it did come out in New Zealand first and now it has finally caught up to the US. Yeah. Uh, and finally in the news this week, um, in the February issue of the ISSA Journal, uh, Gail Corey is, is featured.

So last year in 2017, she was a part of the ISSA Honor Roll, which is the highest honor that you can get. So congratulations again to Gail. And this is a profile of her and I'm sure that they'll have other profiles of Honor Roll members or honorees in the future. Very cool. Uh, congratulations to Gail.

And thanks to Steve for letting us know about this being in the Journal this month. We hadn't seen it yet. We hadn't got our hard copies in the mail yet. Exactly. So as a reminder, we do ask you guys to go out and do a rate on the show, subscribe to the show, get it in your inbox every week.

We also have the Slack channel I already mentioned. There's a link in the show notes. There's a link on the main side of our website to join Slack. We've got, call it, 290 people in the Slack channel now. Very vibrant conversations.

It is humming. Yeah, it's been really good. Also sign up for our mailing list, and then let's move on to trivia. Yep. So trivia this week, actually for last week, was what Colorado statute prohibits computer or cybercrime?

And we got a couple answers. Our number one, our first answer actually came from Debbi Blyth, the CISO for the state of Colorado. She recused herself. I don't know why she did that, because maybe she thinks You know, she has it all memorized. It's not fair.

Yeah. But we did get an answer really actually just right after that from Phil Wong. Congratulations to Phil. And of course, Alex, you know, I'm sure you want to say what that statute is. You know, it's Colorado Revised Statute 18-5.5-101, of course.

Yeah. I mean, we all knew that. I've got that memorized. So congratulations to Phil. And of course, thank you to Andre Gaeta.

Andre is our sponsor for these every week. He has sent off a lovely gift over to Phil. Yep. And this week, our trivia question is, which former podcast guest boxed against Julio Cesar Chavez? Wow.

So do we have a professional boxer on the show? I don't remember a professional boxer. Interesting. Yeah. Was it you, Robb?

Did you box him? I'm not a guest. Yes. I mean, I did. I did box him.

You know, when, you know, because He was old by then and he still kicked my behind. All right, so info@colorado-security.com with the answer. First answer, correct answer in wins the trivia question. So get that in as soon as you can. All right, jump over to events.

As a reminder, we do have a calendar of events on the website. It is a packed house for the next couple of months. So go ahead and take a look out there and plan out your stuff going into the future. I'm gonna go first 'cause I think this is so cool. There is an event in the Netherland Library.

I believe it's fair to say This is the biggest security event to ever hit Nederland. Definitely the Nederland Library. Yeah, it is a cybersecurity for the individual training. Cool stuff. And that's happening on the 13th, on Tuesday.

So if you are really anywhere in Colorado, it's probably worth the drive to Nederland to experience number one, the event at the library, and number two, go check out their hand-carved animals on the carousel in the middle of town. Sweet. Also, on the 13th and 14th, ISSA Denver is having their February chapter meetings. On the 15th, SecureSet has their career conversations with Chris Roberts. That's Thursday the 15th.

Also on the 15th, DENSEC has their North meetup. The 3rd of our 4 items on the 15th is ISACA having their February meeting, which is around active defense. Why duck when you can hit back? I like duck.

Finally, on the 15th, OWASP Boulder, they're having Automating Offensive and Defensive Cyber Ops with John Grigg. So this is actually the first time that we've got OWASP Boulder on our calendar. So going forward, we'll plan to get all their events on here. We just didn't have the sync up with that previously. Yeah, I mean, I think a lot of times the Boulder and Denver ones are the same.

Good to see that they're branching out. Yeah. The following week on the 17th, ISSA Colorado Springs is having a mini seminar. On the 20th, CSA is having their February meeting. And Colorado Springs ISSA is having their February meetings on the 20th and 21st.

That's the dinner on the 20th and the lunch on the 21st. On the 21st, ISSA Denver is having a happy hour. And that's actually sold out. So you can get on a waitlist, but I don't think you're probably going to get on. Just go show up anyway.

Maybe don't do that. And also on the 21st, CTA has their Day at the Capitol. This is an opportunity to get to learn what's going on in the Capitol with our legislature, all that good stuff. Let's talk about some of the events a little bit further out. There's a couple coming up.

We have SnowFROCK, which is scheduled for the 8th of March. Great lineup. Registration is up. Go out there if you want to take a look at who the keynotes are, all the good events going on. It's a good opportunity to get to meet and talk about application security stuff.

And then of course, uh, May 8th, 9th, and 10th is the Rocky Mountain Information Security Conference. Um, as we are recording this, uh, we are about to close the call for papers. So we're gonna be getting that lineup set here pretty quick. Uh, we also have pretty much confirmed all of the pre-conference sessions. So we are gonna have that, uh, updated on the website here shortly and Registration for attendees is open.

So if you want to go ahead and register, it is available to go do that now. Early bird's open till March 7th, I believe. That sounds correct. Yeah, I think it's March 7th. So you have a few weeks left to get early bird pricing.

I will say we have had the best response to our CFP we've ever had. We were going to have to let go of somewhere in the ballpark of 80% of the submissions. So we're going to have really high quality content this year. We're excited about it. And hopefully you will be too.

One other event I wanted to highlight is the Sea Level at Mile High event that's happening on the 15th of March. This has not normally been a security event, but this year, you know, we've been working with the, the president and some of the organizers from the CTA to get the security community more involved. So we're going to have CISOs up on the stage, and we're really trying to get that Colorado equal security community plugged in with the larger Colorado tech community. So we hope you guys can make it. And of course, you would know about all these events if you went out to the website and checked out our event calendar.

So you should definitely go do that. We update it pretty frequently. If you're planning an event, check there first so you don't overlap with somebody. And if you're interested in finding out what's going on, go ahead and check that out. Jump over to jobs first.

Holland and Hart is hiring an information security officer. Nice. Next, BP is looking for a security architect. Arrow Electronics is also hiring a security architect, but this one is focused on applications. It's really an AppSec type of an architect position.

QEP Resources, where I used to work, is looking for an IT security analyst. That's working with our friend Dave McGuire over there. Yep. Red Sky Solutions is hiring a senior systems engineer. They are a reseller who focus on reselling security solutions, so it'd be a fun place to get your technical, uh, your, your technical chops up to industry stuff.

And that is a Denver job, but could also be based in Utah if you so desire. Sure. Burwood Group is looking for a senior network security consultant. Kivu is hiring a couple positions. They're hiring an associate director and an analyst.

And these positions are both— it's consulting gig and they're located here in Denver. But I think you're going to be traveling a little bit if you do either of those. SecureSet is looking for a vice president of educational products and programming. We've talked— exciting. We've talked about SecureSet a number of times on the show.

But just as a reminder, they are the local cybersecurity boot camp where they do these, you know, 6-month crash courses to learn how to get into security. This would be a great opportunity to, to really help create those programs. It looks like Optiv is hiring a director of content strategy, and CyberGRX is hiring a content strategy— content marketing manager. So if you know what security marketing should look like, you got a couple different opportunities here. Maybe you can play each company off the other one, get the best opportunity.

There you go. Yeah, good job. Yeah, uh, so I think that's it for news, right? That is it. I think that's it for the newscast.

Yeah, so we do have our feature interview this week with Cam Williams. Yeah, so I've known Cam for a long time. We used to work together back in the day at IBM, and he has now started his own company in the identity and access management space. So we, uh, we delve into that, talk about what they're doing. Uh, some exciting stuff.

All right, well, thanks, Alex. We'll talk to you in a week. Thanks, Robb. This is Steve Corey at the City and County of Denver. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

This is Alex Wood, and I am here with Cam Williams, who is the co-founder and CTO of OverWatchID. Hi, how's it going, Cam? Good, how are you? Good morning. Good morning.

Yeah, um, so we obviously, we go a ways back. Do. I've known you, man, basically since sort of my beginning in technology when we both worked at IBM. That's right, a long time ago. Back in the good old days, you were doing, you know, hosting work and sort of infrastructure network stuff on that side, and I was on the security side.

That's right. Yep. Kind of stayed in touch over the years. Yeah. But I think kind of to start, why don't you give everybody kind of a background on on where you came from, stuff that you've had go on in your career, just to kind of bring everybody up to the speed of where you are today.

Yeah, like I said, or like you said, I started out here in Colorado at IBM. Prior to that, I was working for MCI in the government division, so working for some 3-letter acronyms and so on, and then moved out here to Boulder after the WorldCom debacle, if you will. And moved out here with IBM and with eBusiness Hosting and did network security as well. And then went to— I left in '04, went to a company called Vertella, and I started the security group of Vertella, built that up, managed services, some managed security services, a lot of reselling back into IBM. So IBM was about 60 or so percent of our business, was white labeling our managed network services and managed security services I remember back then it was sort of the managed VPN service.

That was one of the things that sticks out to me for Vertela. Yep, we started out doing managed VPN with IBM, so a lot of backend connectivity to the hosting environments and so on, and then branched out into doing managed firewall, managed intrusion prevention, and other countermeasure management. So a lot of— in the GTS, so Global Technology Services. So outsourced engagements with like KPMG or BP and other things like that. So I left in— so Vertella got acquired by NTT end of 2013.

I went to Juniper for a little bit, Juniper Networks, and worked in their security business unit, worked on SSL VPN technology as well as the JDDS, which is the DDoS platform there, and another platform called Argon Secure. Of mothballed, but it was a FireEye sandboxing competitor, if you will. Sweet. Then came back to Colorado with InteliSecure. So I was VP of Engineering over at InteliSecure for almost 2 years and worked on a privileged access management system for the operations group over there, application monitoring system, built out a pen test system as well.

And then jumped ship and started Overwatch with my business partner Andy. So in November of 2016, so over a year ago. Yep. So, so it's kind of funny, you are not the first former IBM person that I know that we've interviewed on this show. Yeah, right.

Why? It's interesting and more curious to me, why do you think that, that so many people that came out of there have been so successful? You know what, it was when we were at IBM, when you and I were there, it was just, it felt like a, like, like you could do, like you get your hands on anything. Yeah, like I started, my background was network engineering. I did a little bit of security at MCI with FAA and DOD and some other, some other acronyms and stuff like that.

But like, you know, like PIX firewalls, like back then it was, that's the only security platform that was out, right? And then when I got over to IBM, it was literally like I started in the networking group, moved into the security group for e-business, and was doing breach mitigation for, you know, large banks and, you know, oil companies and large retailers and things like that. So it was a great place to learn and get your hands dirty if you wanted to. Like, if you wanted to try something else or get into something new, and pretty much the sky was the limit. So yeah, I mean, one of the things that I always remember too is there was always somebody you could find that had knowledge that you could acquire, right?

Yeah, absolutely. So it wasn't a very collaborative environment. I feel like a lot of times you're a smaller company or something like that, you've got to, you know, reach out to a consultant or somebody like that to maybe get that sort of in-depth knowledge that you need. And there was always, you know, it was trouble finding some people sometimes. Yeah.

But once you found them, yeah, there was gonna be somebody there that you could get the knowledge from and help you learn. Yeah, absolutely. Absolutely. I think, you know, The fact that we were working on, it wasn't just like working in an enterprise where you're, this is your company and you work on this one thing. I would go from Target.com to WAMU.com to BankOne.com and work on those different .com environments and they were completely different.

They're kind of similar but different equipment, different technologies and such in play. So it was really a great environment to to cut my teeth in. So yeah, and one of the other things that I remember too is, uh, do you remember the IBM Swap Shop? Oh yeah, I mean, that was like, it wasn't only knowledge, but it's, you know, they had this, uh, you know, this marketplace essentially where there was essentially secondhand kind of hardware and stuff like that, right? So it's, hey, um, my business can't afford to, um, to buy a brand new server or a brand new firewall or whatever it is, you know, somebody on some engagement somewhere is no longer using this and they're essentially putting it up for swap.

Yeah. You know, you could go out there and grab all this kind of stuff to, you know, just to play around with. You know, sometimes you'd have to take on whatever cost was left with that, but sometimes it was free, right? It's just you had to have someone, you know, go pick it up or whatever, right? I always thought that was awesome too.

That and the brown bag sessions with the different teams. So you could, like, if you wanted to learn like database administration, you'd go and work with the the DBA guys and do a brown bag session that they were hosting, which is pretty cool. So there's lots of that going on as well. It was a great environment. Yeah, so going from a company that's several hundred thousand people, yeah, now you're the co-founder of a startup.

Yeah. What's that been like? You know, it's a great experience. Yeah, I went from, you know, I guess when I started at Vertello and I built the security group there, I was kind of like building a startup within a startup. So I had a little bit of experience, you know, and know what to expect with the slings and arrows of starting your own business and working out of coffee shops at first and, you know, acquiring a team and, you know, eventually, you know, getting to an alpha product or a minimum viable product and so on.

It's been— I mean, it's exactly what I want to do and I can't be happier with what what we have going on right now. So, so, so what was it that made you make the jump? Was it— did you see a product? Yeah. Was it, you know, you wanted to work for yourself?

Yeah. A little bit of all that stuff? A little bit of all that. I mean, I think, you know, access management's near and dear to my heart. You know, I built and managed access management systems at Vertella.

You know, we had security engineers, and as you know, security engineers are hard to retain, especially when you have a you know, 400+ clients, how do you, you know, how do you manage credentials in a safe way and not have them walk out the door every time you have to, you know, one of your engineers leaves the organization? So, um, that was the prime— my primary concern back, back at Vertella. And then as I went to Juniper and working on SAML on the SSL VPN platform, and, and, you know, just kind of— I just kept on having that, you know, get— getting back to the roots of my, you know, I want to fix this identity problem. I, I did, I did some breach mitigation as well after I left IBM. You know, I built, I built, I did the— built the security, uh, platform for BP and worked on, uh, you know, the BP, uh, uh, dot-com environment during the oil spill and restore that.

A couple of our ex-IBM buddies were over there as well, yeah, uh, working on that and did some other breach mitigation and all All the while seeing that, you know, the credential compromise was the primary breach vector for those major breaches that I'd had my hands on. And so I just, you know, interested to solve that problem. And then when I was at my last gig at Intel Secure, where I was able to go ahead and build out, you know, kind of a version 1 PAM system, really got me, uh, seeing and having, having gone around the country and, and met with, uh, companies like Epic and MD Anderson and other companies that had deployed existing countermeasures for privileged access management and, and some other, you know, and CASB and things like that, and seeing some of the problems with their deployments like fractional or partial deployments for, for other vendors that shall remain nameless. I saw My background also being heavy in automation and using orchestration automation technologies, I saw an area to solve a problem. That's really where Overwatch came to fruition, I guess.

Yeah, so let's jump into that part of it because we haven't really talked about what it is that you guys do. Sure. So what is it really that— you mentioned identity management, privileged access management— what is it really that the problem that you you guys are trying to solve? Yeah, I think we see identity security as one of the biggest breach vectors, or the identity breach vector is the biggest breach vector according to Verizon Data Breach Report and other areas. We saw some, or I saw some significant problems in the market that were destined to be solved by my company.

So, one of the problems that we we saw was, you know, there were large enterprises spending, you know, millions and millions of dollars on security countermeasures for identity security, and they're still getting breached anyway. And what our concept is, hey, you need to, you know, the whole zero trust model and so on of solving, you know, how do you secure an environment assuming that there's malware on your— in your environment or malware on your endpoint and so on? How do you operate safely within that. There's, there's 3 tenets to that— still endpoint, perimeter— but also there's a whole security niche for solving the zero trust model or creating a, creating a, a platform for zero trust. Uh, and, and that's— we, with multi-factor authentication and cloud access security brokering and privilege access management and, and, uh, and single, you know, federation and so on, coupling all those together and a multi-vendor solution has seemed to be a problem for a lot of our clients, and our kind of vision of combining all those into one platform, making it easy to deploy, is really what we set out to do.

And then use automation as much as possible to auto-deploy so that you can get as quickly an ROI as possible. Yeah, so I mean, it sounds like to me that the The big draw here is sort of single platform, right? Yeah. So, I mean, there obviously are other CASB solutions or other identity management solutions, other PAM, PIM, whatever you want to call it. Yeah, PIM, PAM solutions.

Any acronym you want to use. Yeah, so it sounds like for you guys that driver is maybe not only making great products in those areas, but making it all together. Yeah, I think, you know, was an early adopter of, uh, you know, Palo Alto, and, you know, I saw, I saw definitely a great advantage to using— so what Palo Alto did with, with combining, um, technologies onto one perimeter security technologies like intrusion prevention and URL filtering and firewalling and that application identification, all, and putting all that into one platform, making it easy to deploy, uh, I think, you know, that really was another motivation of ours, like, hey, you know, let's just not make a better PAM solution, or let's not make a better CASB solution. Let's make a solution that does all these things. They're really identity security, and they really all need to work together.

So yeah, having a converged solution was— we set out to build a converged solution day one. And then converged sometimes has a bad name to it, I guess. Converged without being less feature-rich, right? Our goal also was Hey, you know, a lot of our competitors, you know, they'll sell you a Windows broker and then they'll sell you another license for RDP sessions and they'll sell you another thing for web session brokering and so on. And these are each licenses they'll sell you.

You know, our vision was, hey, you need— PAM is, you know, RDP shell and web connections. With all of the auditing that you need on top of that and integrated with, you know, ITSMs and for governance and so on. All of that we call PAM, not just piecemeal. And that's— we wanted to include feature-rich capabilities out of the box. So that was another goal of ours we set out to deploy.

Yeah, yeah. And you mentioned automation also, which is something that makes me feel good because not just in the identity space, but any sort of solution that you buy, you see it demoed, you hear about it, you see somebody, oh yeah, this is a piece of cake, it's gonna, you pull it out of the box, it's ready to go, but then you get into it and it's gonna take you 6 months and thousands of man-hours or whatever it is to actually get this working. That's right. That you guys attacked that part of it and how is it that automation plays into that? Yeah, that's, you know, my background is heavy in automation.

I did a lot of automation at Vertella before leaving to go to Juniper and using things like CloudStack 1.0 and other, you know, this is back in 2009, 2010 when pre-Ansible and pre-Chef and pre-Puppet, but, you know, using orchestration, I'm an old guy, I call it orchestration, but DevOps if you will, DevOps technology like Like, and using that to auto-configure. So for Privileged Access Management, for instance, the reason why it takes so long to deploy is that you have to touch every single endpoint. You literally have to log into every server, configure it to work with that, that, that PAM system, log in every router, switch, firewall, so on. And, you know, our goal was to solve that, that problem, that instead of having to manually do that, you know, we built automation to reach out and do that. In minutes, not months.

So, and that's, that's one of our pieces. Another piece is we, we do, uh, we use the same, um, automation technology to do credential management. So how we use credentials in our vault and how we add credentials to target systems and enroll those, those credentials, we use the same technology to do that. And it actually becomes more secure because we're not requiring like a domain admin cred or a directory-based admin credential to manage credentials and enroll them and so on, which is another problem that we wanted to solve. We see that as a, you know, an actual security issue, right?

And there's lots of, uh, literature on the, on the, on the internet that would show that, that, that, that actually creates a breach vector in and of itself. So we wanted to avoid that. So our architecture, having, you know, seen other solutions and, and looking at some of the problems that were in place, you know, automation being one of them and then security efficacy being another, that we were really— we really wanted to set out to solve those 2 problems out of the gate. Yeah, and you bring up something that I have seen a lot lately is, you know, it used to be, you know, all these systems had localized accounts and everybody thought, oh, this is horrible, we got to do all this password management. Um, you know, we don't want to do this.

Hey, why don't we use a directory service, right? And of course, 90% of the, um, the people out there use Active Directory. Um, hey, you know, look, we can do, uh, centralized credential management. Um, we can do, you know, Group Policy, all these things that seem great about Active Directory, right? Um, but now the way I see it is those are great, but it also enables so many problems.

Yeah, so that's right. Um, you know, now you have all these privileged accounts that if someone gets a hold of them, um, then now you have essentially the keys to the kingdom. Yeah. Um, so, you know, I see this being sort of preached more and more, like, you know, Active Directory is actually a big problem. It is.

Um, you know, you can also, you know, if you get inside a network, hey, you can use Active Directory legitimately, not even having to have access privilege, to essentially look up everything that's in the domain. You can find your whole attack surface. So, um, I mean, maybe if you just talk a little bit about, you know, uh, how you guys see that Active Directory security, um, you know, how do you see that happening? Yeah, we really see like directory-based credentials or Active Directory and LDAP and, uh, direct— we call them directory-based credentials— is, is definitely an ease of use thing. It definitely makes you— it's easier to manage your your user environment with directory-based credentials, but it also, you know, causes some significant security issues like you said.

So if you, if you're able to breach that or obtain that credential, you can legitimately move throughout the environment without, uh, with, with, with, you know, laterally move from system to system to system as long as you have that credential has access to that system. So, um, one of the things that we do, and that's just not, not only for you know, internal, uh, lateral movement, but also, you know, things like SAML, right? SAML, we— SAML and, and federation, single sign-on federation to cloud applications, you're still using a directory-based credential. If you can obtain that directory-based credential, um, because if you're federating using SAML to cloud applications, that allows— once that credential is breached, it allows for lateral movement between cloud applications as well. Um, so one of the things that we set out to do with our platform is, you know, solve that problem.

Now we support credential-based or directory-based credentials. All of our clients, you know, there's a crawl, walk, run, right, with when they set up our solution. All of our clients want to start with, hey, we already have directory-based credentials, everybody's got an admin, you know, CWilliams and CWilliams-A for the admin account and so on. So we support that, but we do it in a more secure way. We don't use— again, we don't use domain admin credentials to manage our credentials.

That's the first thing we don't do. And then number 2, we actually have a conversation with our clients about, hey, look, you know, the whole concept of local credentials had a bad name to it because you couldn't manage them. If you weren't— you had to manually manage local credentials on all your systems, right? And that was a problem forever and ever. When we were back at IBM and so on, everybody said, you know, local credentials are bad, don't do that.

But, and the reason why is there wasn't an effective way to manage those. Using our orchestration technology, our automation technology, we were able to add, change, delete, remove, detect new credentials and so on, on target systems. And because we can do that on not only, you know, servers and firewalls, but we can also do that with cloud applications as well. Well. So we can create local credentials that are local personas for users, track those, roll those iteratively, so one-time use even if we wanted to.

We see that as more— a more effective way to manage credentials for privileged access management instead of using a directory-based credential that again gives you the keys to the kingdom if you're able to spear phishing and obtain that credential. And that instead of one key for 10,000 locks, that's 10,000 keys for 10,000 locks. So it's a concept for there. So nice. Um, so obviously, uh, you know, your preference would be that, that folks come in and use your, your services for, for these types of things, but are there sort of general recommendations that, that you would give people even if they weren't using, um, Overwatch?

Yeah, I think as, as part of, you know, improving their security. Yeah. In terms of authentication and Yeah, we play well with others. So I mean, to be clear, our platform does these 4 things but can work well with other MFA technologies, other federation technologies, and so on. We partner— we're partnering with some of those companies as well.

But in any case, you know, I think an effective identity security strategy starts with, you know, managing privileged access management and then adding multi-factor authentication in wherever you you can to eliminate, uh, you know, credentials period and having rolling credentials and pseudo-credentials and so on. Um, I also think that having an effective cloud application security, uh, capability, so securing Salesforce and securing not just the, the people, the sales folks that are using Salesforce, but also securing the people that actually have admin-level access to Salesforce or or admin-level access to ADP, like the people in human resources. Those are again high-value targets. It's not just the people in the IT group, but it's also the people that have admin-level access to ADP or Workday, admin-level access to Salesforce and so on. So sales operations people as well, those people are also high-value targets because of the data that they have access to and the capability of add, change, delete that they that they have within their quiver as well.

So, I think not just securing, hey, are all my servers effectively covered with my PAM solution, but how am I securing ADP? So, I think that's an effect, having an effective strategy for those types of things is important. And then using governance, and governance is not only, so using even like change management, everybody has an ITSM, typically every enterprise has an ITSM deployed. Using that ITSM to enforce, uh, change management, for instance, not just on routers, switches, firewalls, and servers and so on, but also using that same technology to enforce change on, again, ADP or Salesforce or AWS or Azure. Those— that's another area that not a lot of people put a lot of thought to, and I think that's an important area that takes your every— you're extending your your perimeter into the cloud by using cloud applications, you still need to secure those properly as well.

Right. In order to secure those, would you say use built-in tools that those platforms have? Are you thinking about configuration settings, security settings, that sort of stuff, or do you think it needs to go beyond that too? Are there other tools that you need to put in place? Yeah, I think being able to secure, again, The users of those tools, they're the biggest breach factor for even those tools, right?

Using the same security countermeasures that are in place for Salesforce and ServiceNow, a lot of those have the capability to say, hey, I wanna look at only, like front-end ACLs, right? Where you can say, I only wanna source this from, say, my perimeter subnets from PulteGroup or whatever. Using those, the security capabilities of that cloud application, but also using your own systems to secure your users accessing them and accessing them safely, uh, is another— there's kind of 2 vectors there. So yeah, absolutely use what, what the tools have in place, you know, find, make sure you, make sure you are using those as opposed to just, you know, turning on those services and focusing on what they provide. Also look into what, what actual security countermeasures they have in place as well and being able to use those effectively.

One of the things that I've seen too is obviously there's this growing CASB market. People have wanted to extend their security controls into cloud applications. I kind of want to go down 2 paths here, but one of those is I feel like you build these things because they didn't have the security capabilities already natively in these clouds, right? But like, the only way that you can effectively use these tools is by those cloud services having APIs and other things that you can tie into, right? That's right.

Yep. So, uh, how is it that you can effectively add those additional controls to, to cloud services if, you know, say they don't have a robust, uh, API system that you could use? Yeah, things like that. So we look at, uh, so we look at at cloud applications just the same way as we look at it like a Palo Alto firewall. It's a web UI, right?

It's a web user interface. So we secure access to, and we secure users, users using those cloud applications the same way we secure like an IT person logging into a Palo Alto firewall or F5 load balancer with a web user interface. It really just is a different vector to us. So using the same things like credential obfuscation credential rolling, full audit control, so key logging and mouse click auditing and screen capture and replay for cloud applications. So for Salesforce or AWS, we use the same controls that we have in place for web user interfaces through our PAM engine for our CASB solution as well.

And that's really how we look at it. So using— additionally using APIs to know what's going on in that cloud application application, like what's being uploaded, downloaded during that same session, token, making sure that there's no session hijacking going on as well. Those are all kind of key services for our CASB solution. Again, we just look at it as another web user interface. It really is, you know, as opposed to, oh, this is a cloud app and it's somehow completely different than the stuff we have internal to our organization.

Does that make sense? Yeah, yeah, that makes sense. The other part of that is that as I've seen CASB as a sort of product develop, right, it seems more and more like it is not a true product. Like, it is really just a set of features, right? It really is, yeah.

Stuff that you, that you think that should already exist in cloud applications but just doesn't, right? Yep. And my thought has always been that CASB is not going to stay around for very long. Yeah. And I think you're— you've— the first shoe in my mind kind of dropped, uh, I guess, what is last week when, um, when McAfee, um, bought SkyHigh, right?

Right. So, so now I'm sure they'll keep it as a standalone product, but eventually it's going to be, you know, one more just add-on to like the McAfee platform or something like that. Yeah. Where do you see the CASB space going in the long run? You know, so Gartner and Forrester are all If you look at all the market guides for CASB and PAM and so on, they all say that these technologies are going to converge.

I think they're destined to converge, just like next-gen firewalls converged perimeter security. I think there's actually— if you look at other vendors in the market, they're already moving that way. There's federation companies that are adding MFA and adding some other more inside-the-perimeter security countermeasures for identity security. I think I, I absolutely agree with you. We, we see CASB as really just PAM by another vector.

It's really just a web user interface that's not— that doesn't sit within your organization, it sits outside of your organization. Um, but we see the, the same— this— the same— we use the same technology to secure that connection that we use for securing, again, an internal connection. We see that as all identity security, right? This is really just a feature, additional features of identity security. I think I would agree with you.

I think there's definitely— so CASB specifically, if you look at their 50 or 60 different— the 50 or 60 vendors in the market, you'll see 50 or 60 different feature sets, right? Right. There's not a lot of feature parity between one vendor to another in the CASB field. So it's almost, you know, we talking to Gartner and talking to Forrester and and seeing, okay, well, here's what they call CASB, and trying to meet that niche is a challenge for a lot of companies. We look at it as, again, it's going to converge, and let's just call it all identity security.

That's why— that's kind of our idea of converged platform.

So, yeah, I think that 2 years from now, you may not hear that term anymore. Anymore. Right. But who knows? Who knows indeed.

So I'm gonna switch gears a little bit and focus more on you. Okay. So, all right. Yeah. So why don't you tell us a little bit more about you?

What is it, what stuff that makes you tick and that you do when you're not building Overwatch? Yeah, I do a lot of running. I do a lot of running and a a lot of trail running and Ironmans. I do a fair amount of Ironman competitions and so on, and then playing with my daughter. Those are my 2 main things that make me happy is kiddo and running.

So like full 140-whatever Ironmans? Yeah, I've done 3 full Ironmans and I'm just branched into trying— I'm starting to do trail running. So I've been, I've been doing some like Ragnar relays and trail runs like that, but I just signed up for my first 50-miler and was training for that. Actually got injured back in October, so I'm still dealing with recovering from an injury, but I'll be back on the horse here in a little bit and hit some. So I had a 50-miler planned for January, but I think I'm pushing that out till March or April at this point.

Get back on the horse a little bit. So yeah, I actually— there was a race, not that I'm running it or would even think about running it, but I think it was in Utah not too long ago. It was like a 300-miler or something. Yeah, wow. That's— and there was a woman actually here, I think she lives in Golden, yeah, that won the whole thing.

It was like— and maybe I'm overstating, I don't remember the exact mileage, but she she did it in like 58 hours or something. That's crazy. She slept, you know, 20 minutes here and there in 58 hours. Yeah, I just thought it was incredible. That's nuts.

Yeah, I started doing Ironman. I started doing like sprint Olympic distance triathlons after I moved out here. I started like around 2005, and it was one of those things. I was like, I'll never do a full Ironman. Then I did a full Ironman, and then I had friends that were doing ultramarathons and I said the same thing, I'll never do an ultramarathon, and then I signed up for one.

So it's kind of addictive, I guess, once you start training like that and seeing how far you can push yourself. So is that what drives you to do those, just seeing how far you can push yourself? Yeah, I really like— it's a really great sense of accomplishment, right? I mean, Ironman's a long day and it's a huge challenge. It's a very long day.

Yeah, it's a very long day. It's a huge challenge. You know, the trail running has really got— I've really, like, about the last 2 years, I put a lot of time and effort into trail running, and I've gotten away from that sense of accomplishment to more of just that love of scenery and the love of the backcountry in Colorado. It's just, you know, running the Continental Divide is just— it's overwhelming how beautiful it is sometimes. So I think that's really where I've kind of gravitated more to.

These days, I don't know if I'm done with Ironman completely, but I think that's really where I'm focusing now is trail running. And I can take my kiddo with me. I've got a jogger and a lot of trails like up in Staunton and so on, they're wide enough that you can actually take joggers on and things like that. So I really like taking my daughter with me as well. Yeah, that's awesome.

Yeah, so it's the beauty of Colorado is really opens up once you get on the trail. Well, I have a great admiration for you for doing that because I am not a runner. So thinking about those distances is well beyond me. Yeah, well, it's a lot of fun. Thanks.

I love to do it, so for sure. Yeah. So we're getting close to time here. Is there anything else that you wanted to talk about that we haven't touched on? No, I think, you know, I very appreciate the time.

Obviously, you know, have a near and dear place in my heart for the Colorado security community and, you know, really appreciate you offering to have us on the show. And that actually triggers one more thing that I wanted to talk about that I almost forgot about. You guys were part of the initial SecureSet accelerator class. That's right. Which is now— the accelerator is now called Darkfield.

Yeah, that's right. So I wonder if you just talk a little bit about that process and how that worked and part of being an accelerator. Yeah, I think there's a selection process. There's the accelerators, there's other accelerators like Techstars in Boulder and so on. But SecureSet, which is now Darkfield, is solely focused on security companies, which I thought was really helpful for us.

It wasn't just jumping into an accelerator that had people doing other widgets and things like that. It was literally people within the security community within Colorado, as well as outside of Colorado. A couple of the other cohort members were from Philadelphia even, so there were folks flying in to be a part of that first cohort or that first class. It was really valuable. I thought I knew a lot of the folks in the Colorado security community, and it opened my eyes that I really hadn't.

There's lots of people that I had yet to meet and so on, so that was really helpful. We had lots of help with investor activities, and as a startup, you kind of think you know what you're doing, and then you stumble a little bit here and there, and you find that you need to go a different direction, or you need to do things, approach things a little bit differently. And having that, so having mentors come in from other companies that had other mentors from, say, like Scott Chasin from ProtectWise, and some other folks that have been there, done that, and kind of giving us, looking over our shoulder and helping us out with certain things and giving us some direction and so on was really helpful. Dave Odom and Alex Kralin, you know, they have immense experience within the industry. They have great contacts from investors as well as even mentors and clients as well.

So having, you know, having clients come in and take a look at our product in its early stages and getting good feedback and so on was really helpful. You know, a lot of leadership activities as well. So how, you know, co-founders and how You know, once you start getting into the nitty-gritty of business and, you know, kind of go at each other's throats a little bit and so on. So having, having to be able to, or having kind of leadership classes on how to deal with that and kind of stay in your swim lane. And, you know, your CEO does this and you're doing that and so on.

So it was really, all of those things were really helpful. I would highly suggest that if there's other, you know, security startups that they should reach out to Darkfield, Alex Kreilein and Dave Odom, if they're interested in learning more about that. I think it's very valuable time and it's time well spent for sure. Yeah, and we love SecureSet and those guys. And just for clarification for people, SecureSet used to be 2 pieces.

There was the education component and the startup component or the accelerator component. That's right. And now they've they've split those. So there still is SecureSet, which is the education component, and then there's Darkfield, which is the accelerator component. Yeah, we had Alex on early, um, one of our early-on interviews as part of the podcast.

Oh, you did? Okay. You know, we love those guys. And, uh, yeah, I think, you know, I highly recommend both of them. I think a lot of the folks that are coming out of the SecureSet Academy, the education arm, you know, they're coming out, you know, very well armed, very well suited to jump right into security engineering positions and so on.

So I think, you know, I think the world of both sides of that, that SecureSet Accelerator and Academy, now Darkfield for the accelerator part. So yeah, and on your part about not knowing as many people as you thought in the community, yeah, I've had that experience too with, you know, with the podcast and everything else. You know, Robb and I went into this thinking, hey, you know, we know a lot of people, let's try and bigger bring them together, but as we've gone through the process, it's like, man, there are still so many people that we don't know. Yeah, right. It's surprising how extensive the Colorado security community is.

It really just, you know, starting at IBM and knowing all these people that kind of branched out from there, it's really interesting to see where they're at these days and then bumping into new people as well at Trace3 and GTRI and all over the place. So it's been really helpful from SecureSet aspect or the accelerator aspect to meet all those, to have those people and be able to meet those people and branch out, not just, you know, from ISSA events and so on, but, but, you know, through mentor meetups and things like that. So awesome, Cam. It's been a great conversation. Yeah, thanks, Alex, so much.

Thanks for coming and talking. Any final thoughts before we get out of here? Appreciate it. Merry Christmas. Hope you have a nice Nice holiday season.

So yeah, you as well. Awesome. And this has been Colorado Equals Security, and we are signing off till next week. Thanks. Thanks.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes