Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 89 for the week of October 22nd. Alex, last time we got together, you were wearing snow boots and a big parka.
Yes. Today I was freezing. Sunglasses and a Hawaiian shirt. That's right. It's, it's a beautiful day today.
Weather is great. Our winter has passed. It's already spring. Finally, we made it through that long, long cold winter. It was tough.
Yeah. Well, before we dive into the news, talk about a little bit of housekeeping. We do have a Slack channel with over 600 people, a great opportunity for you to get to meet other people who do security work here in the Denver area. We also have a mailing list if you would like to hear about what's going on with the show, get the show notes in the mail. Go ahead and sign up for that mailing list and we will get that out to you ASAP.
You can get that at colorado-security.com. We would also love it if you would subscribe and rate us on your favorite podcast viewing application, whether you're doing iTunes or Stitcher or any of those other crazy places. Libsyn or SoundCloud. SoundCloud. Also, if you really like the show and want to support us financially, we have a Patreon campaign.
It would be awesome if you signed up and helped us cover the costs that we have for the show. You are welcome to sign up for any dollar amount that you would like. But if you sign up for $10 a month or more, you will get a free t-shirt and a shout out on this show. And if you really like us, but you don't want to spend any money, that's fine too. We ask you just to go tell a friend or tell a coworker about the show and hopefully get us some new listeners.
Awesome. So, Robb, Denver is on a very prestigious list, one that I'm sure all cities would like to be on. Are we behind Austin? We are not behind Austin. All right.
We're ahead of Austin. We're moving up. Okay. And what is— what's this list? Denver is among the top 10 most rat-infested cities.
So, but we're not behind Austin. All right. So I guess the good news, if you're going to be on the top 10 most rat-infested cities, the spot to be is slot 10, which is exactly where we are. Congrats to Denver for, for only being number 10. We do have some decent company.
The number 1 most rat-infested city is Chicago. Behind that is Los Angeles, New York, D.C., San Francisco, Detroit, Philadelphia, Cleveland, and Baltimore. Yeah, good stuff. If you are looking for rats, then you've come to the right place. And this list comes from Orkin.
And I guess The Orkin man saying, you know, where are they getting the most calls for, for rat removal? Right. Speaking of getting rid of rats, I don't have a good segue here. Getting rid of things. Sears is going Chapter 11 and they're going to be closing a bunch of different stores, including a couple here in Colorado.
Yeah. Speaking of getting rid of things, Sears is getting rid of its debt. Yeah, its debt and much of its value as well. They did sell off Craftsman recently to Black Decker, so they, they don't have nearly the same number brands they used to have. There are 2 stores that are going to be closing here in Colorado, including the one at Streets of Southglenn on University, which is my Sears.
I'm disappointed to see that go away. And they're also closing one in Lakewood on Colfax. There's still going to be another 24 Sears stores and 2 Kmarts in the state. For reference, as of May, Sears had fewer than 900 stores Down from its 2012 peak of 4,000. It is a pretty big deal, huh?
It is a pretty big deal. Sears is a pretty big brand. Yeah. And, you know, they were the Amazon of 100 years ago where everyone got these, you know, the Sears Roebuck catalogs in their house and you mailed away and you could buy anything, including a house. You can buy a house out of the catalog.
Did we listen to that? Did you listen to the podcast? I listened to a podcast recently that was all about how people were buying houses that they would build themselves and their homes from Sears. Pretty cool stuff. I think I know what Sears' problem is, though.
There was a quote in the article It says the problem in Sears' case is that it is a poor retailer.
They also, you know, they also are burdened with this huge pension that they have to pay. And yes, they have some, some negatives that even if they were the best, it'd be really tough for them to compete with the likes of the new companies. So in some positive news, Bellevue Station, which is a development at Bellevue and I-25, has got a new tenant. You know, recently we heard that Western Union was moving into a building there and putting their headquarters at Bellevue Station. But now Newmont Mining is signing on to be in a different building, I believe, across the street.
So are they going to have their name on a building too? I think so. It is a separate building. So Newmont's moving up there. They're just over there at Dry Creek and 25, right?
They are over by, by Pulte, I think. Yes. Just moving up a couple exits. It sounds like one of the draws— well, a couple. One is that these are brand new buildings, you know, so you don't have to worry about remodeling the building that you're in, get to move into a new building with, you know, fancy new amenities and all that stuff.
The other thing is, which appears to be important, is that at that particular location you have a Denver address, which is important for some businesses. And there looks like they're gonna be moving in 400 to 500 employees, so a pretty good size, good size headquarters there. And this also seems to be part of the trend where suburban companies are trying to move into a little bit of a more urban kind of environment. So, you know, at Bellevue Station there's a bunch of restaurants and shops and other things that are part of the buildings there. You got a little bit, a little bit of, uh, more style and panache.
Is this the first time we've talked about Newmont? No, we've had a job or two from Newmont. Yeah, I'm sure we have. Well, speaking of companies that we talk about on the podcast sometimes, we've talked a lot about SendGrid, even though they're not a security company. They are a technology company, and they've been in the news a lot.
Well, this in the last week, you know, big news, they are being acquired. Even though SendGrid did an IPO about a year ago, they're now being acquired by Twilio. Yeah, so Twilio is, I guess I would call them a similar company, but for other services besides email. Basically, I mean, from my perspective, SendGrid is the default platform for sending out email. Twilio is the default platform for sending out texts.
That's how I've seen it used. Or phone calls, I think, also. Okay, fair enough. So Twilio is buying SendGrid. Their headquarters for Twilio is in California, but SendGrid has assured everyone that they're gonna keep their huge presence in Denver.
All of the executives are gonna stay there. It is, you know, Twilio is excited to get into the Denver tech community and certainly not looking to leave it. Yeah, and this was an all-stock transaction for about $2 billion. That's pretty good. It's a lot of money.
So congratulations to those guys. Congratulations to Scott Gerlach, who is the, the CISO over there. Scott, hopefully this is a great thing for you. For sure. Um, some not as good news.
Um, the Innovation Pavilion, which is an incubator down in, in the tech center. You know, they had hosted some meetings, I think, for ISSA in the past. But anyway, they're a place where, where you could incubate companies. They're actually closing. There was some news, I think it was probably last year, that the CEO was, was sued for some sexual assault allegations.
Yeah. So certainly a bummer to hear that that whole company is going to go out of business. It's not too surprising when one person starts and builds up a company that when that person goes down, you know, it can take a whole business with it. They're just not big enough to survive that. Yeah.
And prior to those allegations, the Innovation Pavilion had been working on some deals to try and take their model to some other cities, but it doesn't seem like that's going to happen. Yeah. So certainly, you know, sad news. Obviously, this is something I know we had ISSA meetings there a couple of times in the past. And, you know, it's just disappointing to see it go away.
With that, moving over to something we actually don't have a link for, but Alex, you know, last week, the feature interview was with Dr. Charles Lively, the head of the the IT and security programs at CSU Global Campus. I got a note this week from, from Ian Morgan. Ian is the CISO over at LenderLive, and he has gone through both the bachelor and master's program from that program. And, oh cool, and he had some really positive things to say. So, uh, just to share with you guys, you know, he, he made the comment that, um, you know, relative to other programs he's looked at, and he's taken some classes, uh, from Washington State and other folks.
He really appreciated the CSU Global Campus experience, something that was able— he was able to work with remotely, said that they, they really mirrored the industry knowledge as you might expect from like the Sean Harris CISSP type book, really relevant stuff from the security perspective. And, uh, he highly recommended the program there. So just kind of nice to get some, some recommendations. Yeah, good stuff. Uh, next, uh, Cherwell was in the news.
They are an ITSM service provider, kind of like ServiceNow, and they're based down in Colorado Springs. We actually had Vance Brown, who is the CEO of the National Cybersecurity Center, who is the founder and CEO— a former CEO, excuse me— of Cherwell on the program before. But this is just talking about how Cherwell now has a new CEO, Sam Gilliland. Sorry. Uh, who's the former CEO of Travelocity.
And so he is now, um, at Chairwell. And it looks like while they're based in Colorado Springs, they're expanding their presence in Denver. Um, so maybe some talk about them even moving their headquarters up a little farther north from Colorado Springs. The article does have some numbers in it. Uh, Chairwell has about 500 employees globally with 280 in their Springs headquarters right now.
The Denver office has about 35 employees and they're talking about tripling that. So we should expect, you know, 100-ish employees there in their downtown Denver office here coming up soon. Yeah, and Chairworld had recently gotten about $250 million in investments, with about $172 million of that coming in April from KKR. Yeah, KKR is one of the, you know, big private equity funds out there, and, uh, pretty cool stuff. So good, looking forward to seeing what happens there.
Uh, next we have an article from BizWest, uh, which is actually talking about a presentation done by our friend Josh Saunders. Josh is the senior director of Enterprise Risk Management, who— he's basically the CISO over at Otter Products up in Fort Collins. And he's talking just a lot at the, uh, annual Flood and Peterson Symposium, um, talking about security and talking about what companies need to be doing and really what individuals need to be doing to keep their own data secure. Yeah, so they, they definitely had some, uh, good takeaways in the article. Um, he mentioned some practices both for individuals and companies, including Things like using password vaults.
Funny, when we had the discussion last week about the Ping blog that said don't use password vaults. He also mentioned that you shouldn't let your browser store your password. You know, if you do have it stored in the password, it becomes a vulnerability that bad guys can pull it out or use it to log in automatically. Also, multi-factor authentication, which I think we have said many times is a wonderful thing and that you should do. And he says you should turn off your location services on your cell phone.
Um, of course, that, that's going to be for privacy and monitoring that folks might want to do about you. So interesting stuff. Yeah, so take a look at that blog. Good stuff. Next, uh, Webroot actually announced a new product this week.
They are entering the VPN space, uh, sort of the personal VPN space, and they were launching Webroot Wi-Fi Security. Yeah, so we've heard a lot of news from them in the last couple years about their enterprise offerings and their threat intelligence offerings. This is the first consumer-grade offering that I think I've seen in a while from them. So it's neat to see that they're, they're still playing in, you know, kind of what got them here, right? Yeah, I think one of the cool things is that their Wi-Fi technology— excuse me, their VPN technology, uh, leverages their, the Webroot BrightCloud threat intelligence, which is, you know, one of their big products developing that threat intelligence.
So as part of your VPN, you'll be able to stay away from bad sites. It looks like it costs $40 a year. So if you, you know, for just a couple, you know, $3 a month, you'll have this service protecting you. You know, not a, not a too high a price tag, I hope. So if anyone, uh, takes a look at that service, we'd love to hear about how it works for you.
All right, uh, next we have a blog post, uh, from Virtual Armor, another one of the local security companies here. It's recapping DerbyCon, the big DerbyCon conference. This is one of the conferences that, you know, is pretty well known nationally. It's not a huge conference, it's certainly nothing like Black Hat or RSA in terms of size, but it is really well known for having high-quality technical talks and kind of that smaller feel that you get from a regional conference like that. Yeah, one of the interesting things that I saw in there is, uh, they talked about a talk given by Apple and some more features that they've come out recently for doing code signing, which was pretty cool.
I did have one of my employees went to DerbyCon this year and really enjoyed the, the conference. I think getting hands-on and the more technical talks, he was able to see some actual exploitations and kind of learn how to do some of the more technical stuff that he hadn't done before. So it's, it's a neat opportunity for those who, who want to go see it. And of course, it would never take the place case of RMISC here in Denver, of course, but it is something else for folks to look at. And I believe DerbyCon is one of the conferences that puts their videos up online, so if you want to see all the talks, go, go check that out.
Uh, next, there was a Zavello blog this week, uh, talking about an increase in phishing scams targeting Apple ID users. Yeah, you know, I have gotten, I don't know, an email every day for the last month saying, hey, your Apple purchase just gone through, you know, check your invoice here. And they, they've really, uh, been hitting on that hard. It didn't even occur to me until I saw this article that, that it's happened, right? I just, I know I've been getting them, but I never really put it all together to say, oh yeah, it's, it's really increased.
And it really has increased for me. Uh, yeah, I would say the same, but I will say that they seem to go to my Gmail and Google is pretty good about catching those things. So I don't know that I've seen many actually hit my inbox. Um, but, but I have definitely seen them in my spam folder. So for those of you who are putting together a dossier against Alex, Gmail is the, uh, the platform to attack.
Definitely. My ProtonMail account, you'll, uh, you'll have a hard time getting me on. Well, if you really want to get me, send it to my AOL address. Uh, last article in here is not really an article, it's a kind of a news thing. ISSA International, which is the, the parent group for ISSA Denver and ISSA Colorado Springs and what do they call the Fort Collins one in Northern Colorado?
Northern Colorado. Yeah. The NOCO chapter. They, they every year they do their big annual awards presentation and the conference was this last week. Alex, I believe you were there in person, right?
I was. And there were some pretty exciting awards from a Colorado perspective. Yeah. So this year we had some Hall of Fame recipients. Gordon Lyon, Mark Weatherford, who is here in Colorado.
Congratulations, Mark. William Cheswick. Susan Landau, and Phil Zimmerman. So yeah, obviously Mark Weatherford, you know, from our area, one of only, one of only 5 people to, to make the Hall of Fame this year. And then there's an honor roll recipient.
There's only one person who made the honor roll, and it is the former president of Colorado Springs ISSA, Pat Lavery. Yeah, congratulations, Pat. Also, they awarded the chapters of the year, and they do that in several different varieties based on the size of the chapter. So The ISSA Fayetteville/Fort Bragg chapter won for Small Chapter of the Year. Oh, good for them.
The ISSA Alamo chapter won for Medium Chapter. Well, you know, maybe someday they'll get to the Big Chapter. That's right. And the winner for Large Chapter was the ISSA Denver chapter. ISSA Denver.
So congrats. If I remember correctly, 2017 Colorado Springs won the Chapter of the Year award. They did. So, you know, 2 years in a row taking down the Large Chapter of the Year here in Colorado. Yeah, I think last year Denver got sort of an unofficial runner-up.
A you know you should have won, but you didn't. Yeah, maybe call it what you'd like. But congratulations to the Denver chapter for winning this year. Great work by them. And so there there was several other awards, and we're not going to go through all of them.
But there was one other one that that I called out here, which is that Johannes Ulrich won the 2018 President's Award for Public Service. Johannes Ulrich does the Daily SANS Internet Stormcast podcast. This is just a thing he does to help the community. It's 5 minutes every single day. I listen to it on the way to work every morning, and it gives you, you know, all of the breaking news of the day.
So I don't— I never walk into the office not knowing that Heartbleed just happened or whatever the big vulnerability is. Yeah. And I think my favorite thing is that at the beginning of the podcast, he says, I'm Johannes Ulrich, and I'm coming from And it's wherever he happens to be that week teaching or whatever. And it's like, you know, I'm in Antwerp, Belgium, I'm in Thailand, I'm in Florida. He's in Jacksonville, Florida when he's home.
And then, and then that's half the time he's somewhere random the rest of the time. So I will say it's a lot of work, you know, Robb, for you and I to put together this weekly podcast. I can't imagine doing one every day without fail. Yeah, he's, he's an impressive guy and certainly worthy of winning that award. So, Johannes, we appreciate all your work in the community.
Yeah, for sure. That's it for news. Moving over to the Slack Message of the Week. First of all, we'll want to say thanks to Andre Gaeta. Andre is our, our sponsor for this segment of the show every week.
The winner of the Slack Message of the Week gets to pick something from the Colorado Equal Security store and get some swag sent right to them. So this week's message comes from JD Burke. Congratulations, JD. JD started a discussion this week by posting an article about IBM's new sock on wheels. It's a semi truck outfitted essentially as a sock that they're taking on tour, and it's painted red and it looks just like Optimus Prime.
Is that true? Yes, it is. And it transforms also. Well, we're hoping that it gets there at some point, right? Yeah.
So that's what you know. After he posted that, I said, "I am not interested in this unless it is Optimus Prime." Anyway, congratulations, JD. We're looking forward to seeing whatever swag you pick. Uh, let's go ahead and move over to our calendar of events. Before we go through the events, I want to remind you that we do have a calendar on the website at colorado-security.com where you can check out everything going on in the security and tech community here in Colorado all the way through February of next year right now.
Wow. First on the list, uh, on October 23rd, there is a GDPR meetup, Data Privacy by Design: Securing Your Employees, Customers, and Service Providers. There are four events on the 24th, so get ready. I'm just gonna bang through them. There's the Ada Lovelace Day Celebration Denver, which is a women in security event or see women in STEM science, technology, engineering, mathematics.
There's a SecureSet Capture the Flag event. Bang! ISS Colorado Springs is doing their mentorship program. Bang! And finally, ISC2 Pikes Peak that's also in the springs is doing their October chapter meeting.
Man, you bang through those. On the 25th, ISACA is having their monthly meeting in conjunction with the IIA chapter here. Internal Audit Innovation: Leveraging Technology and New Methods to Build an Internal Audit Group of the Future. Also on the 25th, this is actually a new one. There is the 2nd Annual Cyber Synergy Award, which is happening down in the— I said award.
I don't know why I said that. The 2nd Annual Cyber Synergy event that's happening down in Colorado Springs. On the 26th, the Colorado Springs Cybersecurity Group is having their Cybersecurity for Small Business Summit. Colorado Springs ISSA is doing a mini seminar on Saturday the 27th. SecureSet is doing a Hacking 101 with Microsoft PowerShell on the 29th.
The CTA, the Colorado Technology Association, is doing some Security+ training on the 29th through the 2nd of November. Cybersecurity in the Future What Every Organizational Leader Needs to Know is happening on the 30th of October, and that's put on by CSU Global Campus. On the 31st and 1st of November, we have SecureWorld Denver. I think we're both speaking at that event in some capacity. Yeah, I am teaching a class on the NIST Cybersecurity Framework.
Lots of local Denver people besides both of us going at that event as well. Also on the 1st, CTA is doing their day of service along with PMI Mile High chapter. On the 1st, ISSA Denver has their oil and gas special interest group that's going to be meeting. Also on the 1st, SecureSet is doing a Hunt Hacking 101 Intro to Wi-Fi. That sounds like a lot of fun.
Yeah. And the last event here is that on the 2nd of November, Colorado Springs is doing their First Friday Cybersecurity Social Mixer. So if you're down there and you want to get to meet some folks, this is your chance to do it. Looking ahead just slightly, on November 7th, the CTA is doing their annual Apex Awards. And of course, we mentioned this a lot last year, but again this year they're doing the CISO of the Year Awards.
So we have 3 finalists in that award category. So Debbi Blyth from the state of Colorado, James Carder from LogRhythm, and our own Robb Reck from Ping Identity are the finalists for that award. It's great competition. It should be a lot of fun. I assume, Alex, you'll be wearing a tuxedo there that night, right?
Oh, I was, I was gonna wear a bathing suit. A tuxedo t-shirt. Yes, tuxedo t-shirt. All right, let's go ahead and move over to jobs. First, Ping Identity, I am hiring a cloud security architect.
This is if you want to help build our AWS and cloud security strategy, you know, send me a note. Denver Public Schools is looking for an information security officer. I believe that this is the first of, uh, of its kind at Denver Public Schools. So you get to build the security program there. I, I had to do a lot of searching.
So, so on LinkedIn this week, the CIO had posted, we're hiring a CISO, check the website out. And I spent, I don't know, 20, 30 minutes trying to— checking the website, finding a link. I, I did find a link, so it's embedded here on the show notes if you want to apply. However, it says ISO instead of CISO, so maybe, you know, maybe it's not the right job. I'm not positive.
Uh, speaking of jobs, Great West Financial is hiring a Director of Security Strategic Initiatives, and I, I did look through this. Uh, it's going to be reporting directly to Doug Peterson, who is the CISO over there and a former boss of mine and a friend. And it's basically, I'd call this like a chief of staff type of a role doing budgeting, project management, metrics, reporting, communications, you know, kind of all of the non technical parts of this job. Nice. Educause is looking for a director of cybersecurity program.
S&P Global is hiring a cybersecurity incident response lead. Western Union is looking for a senior information security analyst in application development. And if you don't want Western Union but you want finance, Visa is hiring a cybersecurity analyst for applied cryptography. Wow. I'm surprised that that is not a senior position if it is applied cryptography.
Well, you don't have to be that good at it.
Webroot is hiring an information security analyst. Dish Network is hiring a senior security systems administrator. And Red Sky Consulting is looking for a technical recruiter. All right. Well, Alex, that takes us to the end of our news for this week.
Our feature interview coming up here is with Justin Tibbs. You know Justin a little bit, right? I do know Justin. Yeah. So I sat down with Justin a couple of weeks ago and just talked about how he got to be You know, so awesome.
The UConn Cornelius of security is what I was going to say. Yeah, I look forward to hearing it. Justin is an interesting character, so I'm sure it's a great interview. Should be fun. All right.
Well, that's it for this week, and we'll talk to you again next week, Alex. Thanks, Robb. Hi, I'm Tim O'Brien, the director of information security at Educause. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is Robb Reck, and I am sitting today with Justin Tibbs. Justin, I'm excited to talk about what you guys have built over at Red Sky and your whole career in security and all the good stuff you've done. But first, why don't you tell me a little bit about this, this security car club you've got? What was it, Binary?
Yeah, Binary Motorsports. Yeah, so yeah, so Phil Wong, you know Phil, Phil Wong and I are both kind of petrolheads, and so we wanted to combine our love of cars and InfoSec into kind of like— was it Cars and Comedians? Comedians and Cars. Yes, thank you. Jerry Seinfeld's show on Netflix.
Yes, exactly. I should watch more of that. That was Phil's kind of correlation to that, and the ability to kind of get in a car and drive, for example, initially in the mountains and have some nice curvy roads and carving time, but also still talking about InfoSec-related topics that are completely out of the office and just random, random conversation and banter. So that kind of started that, that kind of draw to create Binary Motorsports, which is just kind of a fun little kart club we created. And it started with Phil and I, and then several people from Palo Alto like Paul Lago joined in, Bo Jolly.
And so now we actually do kind of random— we'll text each other in a group chat and just say, hey, do you want to get go do Deer Creek Run or do you want to go do a track run or something like that? Then we'll all just go up and meet somewhere and actually drive around and then stop afterwards for like a smoothie or something and have a conversation about challenges or whatever it may be. It's pretty cool. It could be just everything down to something about cars or it could be, hey, I've seen some issues with these kinds of threats. So it's kind of interesting because you never know what you're going to get.
It could just be a day of we're driving in the mountains having fun or it could be a day of driving with some really cool technical talk as well. So, but it doesn't feel like work because you're kind of combining 2 passions. So what kind of fast car do you drive? So I have a couple of cars. Usually in the mountains, I, I drive a Maserati GranTurismo.
Phil drives a Z06 Corvette. And then the guys, it varies through there from BMW M4s. And I think Bo just got a new, kind of new to him Porsche, which is really, really nice, really good car. So Yeah. So if there's people listening who want to get involved, can they?
Yeah, absolutely. Yeah, it's not a limited group. It's just, just hit up Phil Wong or myself or Bo or any of those guys and just say, hey, I'd love to hang out with you guys and, and go along for a drive, or I know some cool places to go drive and conversations and things of that nature. It's open to everybody. It's completely just the more the merrier.
Let's just have fun and awesome and be, you know, kind of awesome. Yep. Well, cool. Let's, uh, let's dive in. I'd like to learn a little bit about your background.
You know, I actually don't know, where are you from, Justin? Originally, yeah, I grew up in Europe. I grew up in Germany, a little town called Nuremberg, right outside of Nuremberg. Not to be confused with Nürburgring, speaking of cars, but Nuremberg. Um, so I grew up there.
I didn't come to the US until I was 13, I think, 13 or 14. All right, uh, is when I had my first US experience. What brought you to the US? Uh, so my parents are both US citizens, just coming home. So were you over there for military then?
My dad was in the military, yeah. Okay, so you were born on a base? I was born on an Air Force base, yes. All right, yeah. And then you're still a US citizen if you're born over there?
Yes, I'm absolutely a US citizen. So you can become president. Got it, fair enough. And where did you live when you came over to the States? I stayed with my grandparents for a little while in Oklahoma, ironically.
I'd never been there. That was kind of a change from coming from anywhere in Europe to kind of southern Oklahoma which is completely just redneck as you can get. Fun though. Fun experience. Southern Oklahoma.
Kind of like Lawton area. Altus. Those areas. So the most exciting thing I think was my grandparents took me to— I forget the name of the little ice cream shop they have in Oklahoma now that I've never been to in Europe. And that was what they did.
And there was a Dunkin' Donuts drive-through, which amazed me. I'd never seen one of those. And I'm like, what is this thing? You can drive through and get a donut? So things like that were very fascinating to me.
And I remember actually the first time I came from Europe, from Germany, over to visit my grandparents with my mom, we flew into New York and I saw yellow school buses. And that was the first time I've ever seen one except for on TV. And I just looked at my mom and said, those things are real? Like, people ride those things? Because we had— you'd ride a city bus over there, and it was just much like an RTD bus.
Okay, going to school, we didn't have dedicated— so it wasn't for kids, it was, it was just everybody. Yeah, you got your backpack, jumped on the city bus, and went to where you needed to go. So it was very different for me. Yeah, but it's been cool. It's, it's— so did you go to high school there in Oklahoma?
Uh, no. So Oklahoma, I went— I only stayed there, uh, I don't know, probably 6 months. Uh, and then I went to middle school roughly in, uh, Kansas in, uh, Junction City, Kansas, Fort Riley. Okay. And then I ended up graduating high school right outside of Chicago at a school called South Central.
It's on the Indiana side. So I graduated in Indiana in cornfields. Ironically, my high school sat in a cornfield, which was also a cultural shock. Sounds kind of amazing. Yeah, it was cool because it's like literally you're driving, there's cornfields, and then there's this huge high school.
Yeah. But nothing else around it. So it was kind of a It was kind of a cool mixture of growing up with very like kind of city life and then coming to the US and kind of getting rural life and then graduating with kind of a mix of Chicago being 30 minutes away, but also being in cornfields and kind of having that kind of rural life still there. So it's, it's kind of an interesting, you know, kind of path to grow up on, I guess. Yeah.
So what'd you do after you graduated from high school? After high school, I gotta think way back here. Um, after high school, what did I do? I went to school for a little while. Went to— bounced in and out of school, ironically, different colleges here and there, and I ended up just deciding that I was going to go get Cisco certified because I thought that would be much quicker than trying to finish my comp sci undergrad at the time.
And so it ended up working out really well. So I just went through the full Cisco CCNA, CCNP courses at the time and got certified and then ended up working for lucky Martin. Getting a Cisco certification has been a pretty good strategy for 25 years. Yeah, I don't disagree. It worked out really well.
I mean, it's— and I still to this day have not finished my degree. It's funny because I go take courses here or there, and I'm kind of a professional learner because I always want to try something new. And so I'm always enrolled somewhere taking an online course these days because I don't have time to go to campus. And it's just one of those things where like Every fall I'm like, okay, let me find some weird class I want to take. I don't think I'll ever maybe finish my degree because I don't think all those classes add up to anything other than things I was interested in, but it's still fascinating.
Where are you taking classes right now? At University of Maryland, online classes there. And that was kind of a pedigree that was left over from working at Northrop Grumman, Lockheed Martin. They kind of got me to take classes there because they wanted me to finish my comp sci degree. So when you worked for Lockheed, were you out there in the DC area?
Lockheed actually took me back to Oklahoma City, believe it or not. So I worked for Lockheed Martin at the Department of Transportation, which is the FAA in Oklahoma City. That's their, I think, their first or second largest campus in the United States. If you've ever flown into Will Rogers Airport, right off to the right of the airport there is a huge— looks like a prison, and there is a prison in there, but it's a huge campus. And that's all the FAA over there.
They handle all of the payroll processing processing and stuff for DOT, amongst other things there. All the medical records for every pilot in the United States sits over there. And so I worked for Lockheed there doing security. Oh, you started doing security right off the bat, huh? Yeah.
Yep. So I was doing, at that point, I was a checkpoint firewall admin. Firewalls is all that meant, right? Firewalls back then, yeah. So you got your Cisco certification and you got a checkpoint job right off the bat.
Yeah, exactly. It was the networking team at Lockheed loved that I knew Cisco. Yeah, because everybody else interviewing were strictly Check Point guys. And so I knew Check Point well enough. I wasn't quite as good as I probably should have been for the job, but they did a lot of on-the-job training for Check Point for me because it was running on Solaris platforms back then.
And so that was new to me using Solaris, but it was good. It was a cool place to learn because at the time when I joined, we were collapsing FIDI rings into just Ethernet networks. Yeah. And so that was a cool experience back then. I know I'm dating myself talking about fitty rings, right?
But you're gonna have to explain for our listeners. Fiber distribution. I bet you lost 90% of the listeners right there. Probably. Yeah, ring technologies.
So, but that was so cool to come into, you know, collapsing those into just an Ethernet network and then going into— they were just starting to deploy like the early Cisco VoIP solutions back then. So we were getting into that where you had to have a call manager on site and you had to learn how to do all the dial pads. And so firewalls were easy. We set them up and you kind of set it and forget it because back then it was just Layer 3 ACLs, right? Are we going to allow FTP through or not?
So I got to spend a lot of my time working on really cool route switch configurations and also just kind of weird programmatic things that they would ask us to do outside of firewalls. So it was a cool place to really learn. And it was a cool environment to learn on because there were so many weird things and so many big datasets going through there at the time. One of the things that was super fascinating is, I didn't even know this until like a year after I'd been on the campus, is they had a Cray. And it was off in its own little building.
And we never had to go over there until it was one of the Cray and T4 kind of mixed systems. And it had a network card that went bad, an ATM lane card. And I had to go over and you see these bubbling water towers and you're fascinated going, This thing has water in it. What is this thing? And that was incredibly fascinating to actually say that there's a Cray supercomputer sitting on the same campus I'm sitting on.
Yeah, as a young guy, I'm like, this is, this is pretty amazing. Yeah. Yeah. And so I was like, what is this doing? Is this doing something really cool?
And they're like, you do the weather, weather with it. It's like Doppler. Yeah. I'm like, you're just processing weather patterns with this thing? Like, it's pretty complex.
It is complex. But you know, you kind of go to WarGames or something where you're like, are you doing something really cool with this? Cray is hiring a senior security architect here in town. Oh, really? Yeah, amazing.
We just covered that on the show a few weeks ago. I don't know exactly what skill set you have to have, but number one, it's working for Cray. Number two, it's a security architect job for their product security architect. Wow. So I don't know, it's got to be some super smart people doing some stuff.
Oh, that is, that is intense. I didn't even know that. That does sound really cool. It sounds like really low-level hardware type job. That's That sounds fascinating.
Sounds like a lot of fun. Yeah, absolutely. Anyway, sorry to distract you there. No worries. So how long did you work for Lockheed?
Oof, I don't even know how many years I was there. I was there for a long time. I thought that was going to be— Lockheed was going to be my career. It was a great company to work for.
Maybe 5 years. Okay. And then what happened was Cisco had come in. A couple of the Cisco engineers came in when we were starting to put in Catalyst 6500s back when those were new. And we started talking about PIX at the time and trying to get the— they were trying to get the Checkpoints out and PIX in and all the fun stuff.
PIX is the Cisco firewall to replace the Check Point firewalls. Yes, yes. I forget I have to clarify these things. And a couple of the guys just said, why don't you work at Cisco? And I said, I never really even thought about working at Cisco.
What became out of that is Northrop Grumman got wind that I was looking potentially to go to Cisco, and Northrop Grumman swooped in and said, we have some Cisco work we'd love to hire you to do. I was like, oh, interesting. Okay, well, this sounds like something different. It's a lot of travel. I'm not sitting at a desk.
I'm going to be traveling all over the world doing crazy Cisco stuff, quote, for Northrop Grumman. Instead of doing internal networking security for Lockheed, you'd be doing consulting security for Northrop Grumman's customers. Yes, exactly. So I took that job. I stayed in Oklahoma for a little while, but I traveled constantly.
I was in Alaska, just everywhere on Air Force bases and things, basically telling them how they should design and deploy various Cisco security-centric products, which was a lot of fun and an incredible learning experience to be able to see. I remember the first time I saw a Marconi switch, which I don't even know if those are still around, but at an Air Force base. And I opened the closet, an access closet, and I just said, what is this? I don't even know what this company is. Yeah.
And getting to replace those with, quote, state-of-the-art switches back then, learning things like that. But also one of the things that was really funny, and I've made some great friends from working in Northrop, we were still really good friends today, is, um, we were up in Elmendorf, Alaska— Elmendorf Air Force Base in Alaska, sorry— and they had the beginnings of the, I think it was the F/A-22. Raptor in its early prototype sitting in one of the hangars we were working in. And they had a line on the hangar floor and it said, do not cross. And, you know, logically you just say, I'm not going to cross that line.
I don't want to know what's going to happen. But one of our teammates decided that nobody was around, so he wanted to cross the line to see the engine on this plane. And it was no sooner than he had stepped over the line that he was face down with MPs and guns on the back of his head. It was the craziest thing. So we still joke about that to this day.
Espionage concerns. Yes, exactly. And we had to kind of get an explanation on why he crossed the line and why we were there and all this fun stuff. Those are kind of the fun memories that we've had from those experiences. And even this many years later when I see Steve, is his name, I still joke with him.
I'm like, you remember when you got face-planted? He's like, yeah, absolutely. But it's a great learning experience. It's led to kind of where I ended up. After Northrop, I did end up at Cisco.
I went straight from Northrop to Cisco, and on Cisco I joined what was the Worldwide Security Services Practice team, security consulting again. Yeah, they had a team called Security Posture Assessment team, which was a red team, if you will, for customers that were willing to pay the price for Cisco's red teaming. And so we would work with, you know, at the time, like Walmarts of the world type customers. Yeah, the big ones that would value the Cisco services. That were offered.
Cisco kind of ran me through the paces of pen testing. I'd always kind of been a hacker at heart, but we were traveling 300 days a year all over the place. I mean, I would be in Brazil for 3 weeks, and then I might come home for maybe a couple days, and then I would be in Portugal, or then I would go to London or somewhere, right? It was great because there were always 2 of you, so it was like traveling with your friend and you're going someplace and you're gonna break into something and you're gonna just pwn the hell out of everything, if I can say that. And it was just glorious.
You just— all you did was go blow things up. Yeah, right. And tell our customers, this is how we blew things up. And it was kind of the cool pinnacle of pen testing. Eventually that gets a little boring after like 6 years of blowing up the same things.
Yeah, exactly. So where were you living when you were working? So I moved from Cisco moved me to Colorado. Okay, so my office was based out of Englewood personally, but my team was based out of Austin and San Francisco. So Cisco wanted you here?
Yeah, Colorado. Okay. Yeah, so it's your first— that was your first time living here? That was my first time living here. Yeah, and so prior to— actually, I missed— I actually missed a tiny gap in there.
Ironically, I moved to Colorado before Cisco while I was working on Cisco contracts. Because I worked here for GTRI for about 5 weeks while I was waiting for my Cisco transition. GTRI, the contracting company basically, right? Services. Yeah, services Cisco partner.
Yeah. And so I was actually here before I started with Cisco. So I always forget because it was such a short stint there. Not that they're not relevant in their way. But yeah, so I was here and then I accepted the position Cisco, but they wanted me in Colorado for an international airport.
Okay. Because I was traveling, that was part of my job, was to be on the road so much. And so I left Cisco in 2010, if I can trust your LinkedIn. Yes, December 2010. December 2010.
I had just got back from Venezuela, I think, and I was like, I've kind of had enough of this. Yeah. So I, I left Cisco in 2010, which I never thought I would do, ironically. When I was at Cisco, and I didn't leave Cisco because I didn't like the company, ironically.
When I started at Cisco, I was like, this is the last place I'll ever be. It's great. The culture is great. I'm doing great things. The team is great.
The management structure is great. Everything about the company was great, benefits, everything. You didn't want for anything. Whatever we wanted in our lab, we had it. We had all kinds of fun testing things, multiple laptops, and it was just kind of the this cool place to be.
But like you said, you kind of get bored at a point and then you go, what's my evolution? Well, my evolution was to move to San Jose. Not really a place that I wanted to end up, quite frankly. Not really. I love to visit the Bay Area, but I don't know if that's someplace that I could just hang out and live there for.
And then there's also the evolution of getting into kind of the Cisco bureaucracy of, okay, you're gonna move into products, you're gonna move into management, what are you gonna do? And so I kind of looked at one of my good friends, Christina Harstad, was talking to me. She's like, you should really come join NetSource. And I was like, what is that? I mean, what are you even talking about?
What's a NetSource? Yeah, exactly. And so she's like, let me set up a meeting with the owners of NetSource. I know they're looking to kind of get into security, and I think you could really do great things here. And so I said, yeah, I'll kind of entertain this.
I don't even know what that means. And so she kind of started the ball rolling, quite frankly, the evolution. I met with owners, and then we kind of came to an agreement. Hey, I would leave Cisco to kind of start my own thing. Give me that time to build a security-focused company.
I don't want to call it a security company, but security-led or security-focused is kind of the way I like to lean into it because it's not strictly a security company. There's always more elements to it like data or storage arrays or things of that nature that are not pure-play security. NetSource in its core was a data center company, right? Hitachi Data Arrays, EMC, Dell type things. And so adding security to that, we would never be a security company, we'd be security-led.
Okay. And that's kind of been my focus. But you're going from being a pen tester for Cisco to, you're saying, like leading strategy for this company? That seems like a pretty significant jump. It is a huge jump.
And so some of the stuff we did at Cisco— Cisco was a great grooming company. So while my position is Cisco was basically a network consulting engineer, which is a pen tester, if you will. One of the things we did internally, we were always tasked with building new programs. For example, Cisco has a program called Deep Application Vulnerability Assessment, DAVA. They love their acronyms.
So DAVA was a program that a few of us on the SPA team came up with. Cisco at the time had 1,300, I think it was, custom homegrown apps. None of them had ever been assessed. So we didn't know what security level they had, what posture, anything. And they handled some of them very critical data.
And so we came to this conclusion we had to develop programs and policies and procedures around how to handle these apps and new apps going forward. So Cisco was really great about kind of side grooming you into different things on how to build programs, how to force you to think creatively. And I never wanted to build policies or frameworks or programs, but when you got into it, it was pretty interesting to say, okay, well, These applications are being developed by developers who have no concept of security. How am I going to get this to a secure state without, one, offending people, but two, making sure I do it the right way and in a positive way so it's reproducible and consistently reproducible? And so Cisco really forced us to think on those lines even outside of our daily tasks, like when I was building these programs.
And I think that's really helped— what's helped make that leap Because initially when Joe and Dave and the guys said, we want you to come over here, I'm like, yeah, I can build you a security program. I can build you a pen testing team. That's easy to do.
There was a lot of trial by fire with the whole, let's build out a full security-focused company. In the past, when I was a part of Secure Network Operations or SnowSoft research team, we had our own little autonomy. We had our own little company. We were a research team. We ran like a company, so there were some elements that I was used to, but that was many, many years previous.
NetSource was kind of this interesting, how am I going to build a security-led practice with what I have and what I need? It really forces you to kind of grow up. That's what I always tell some of the guys, like Phil and the guys, if you would have asked me 10 years ago would I be a CSO, I would tell you no. It was never on my radar, or even CTO for NetSource. At the time.
It was never a job directive for me. It was more so I wanted to be engineering, I wanted to flip bits, I wanted to understand how to write the latest attack vector. But then I also understood as I started NetSource that that is a great, glorious, fun job to flip bits, as I call it. It is incredibly fun, but it is not something that helps customers at the end of the day always. How can I build something that if I come to you and talk to you and you give me a problem, me talking to you about buffer overflows isn't going to solve your problem, generally speaking.
There's another pain point. There's another way to resolve it. There's multiple facets in security that we have to understand, and I think NetSource really pushed me to grow that and understand that. I spent 5 years— I think it was 5 years there. Yeah, it looks like over 5 years.
Yeah, growing that out and building it with a lot of trial and different techniques, and a lot of actually honestly talking to industry peers, quite frankly. I would talk to some of my friends like Jay Coons, for example, who runs— I forget the name of his new company, he'll kill me for that, but he ran OSVDB for the longest time, and so now that's called Vulnerability Database. I think he monetized it. I would talk to him about different strategies, and occasionally I think I had lunch with Brian Jericho. We would talk about various different things in the industry and things that annoyed us.
So you take feedback from all these different people and all these different peers and people you idolize, and you kind of just say, okay, based on what I'm finding in the industry, as well as talking to a multitude of customers who are at least being gracious enough to tell me what their problems are, maybe I can build something that will solve at least most of these things in some way. And then you kind of build a puzzle out of it, and you start putting the pieces together, which the pieces are the company, so to speak. And that's kind of how I got into it, quite frankly, of really building these out. You had 5 years to learn there. What were your biggest learnings for like, what's the recipe that worked?
And maybe it doesn't always work, but it worked there, and then you went to Red Sky. We'll talk about that, but what did you learn in those 5 years? You know, I think the biggest thing I learned if you're starting a company is that you need to make sure that everybody that you're partnered with, you're all aligned and you're all firing the same way. I call it the Death Star beam, right? Make sure that the Death Star is firing in sequence at the same time.
And it's not that you're always going to be in agreement with everything, but everybody should be at least tracking to the same goal within a company. That creates a culture, and that culture is the most important thing to a company. If you can't create a unified culture in the company because you're all aligned, you're going to have eventually some disagreements and some probably impasses. That was the biggest thing I learned outside of the obviously the pieces of growing a company and learning P&L and, and all the little financial things I never cared to but now are very fascinating to me. Being able to understand the human elements of bending and flexing as well are also— that's part of that, that firing in a single line, is realizing that you're not the center of the world.
You've got how many people working with you and for you. Everybody's important. Yeah, I think that to me has been the most critical piece to take into any company. It's amazing how little finance and budgeting is interesting until all of a sudden you care, right? Absolutely.
If it's hypothetical in a finance class somewhere, it's just— I just can't bring myself to caring about it. And then, and then when it's my budget, when it's, you know, when the bottom line matters, it's, it's really quite interesting. And that forecasting thing, it's a pretty good idea. We should get good at this. That is so very true.
And even today, to this day, day. There are certain things in finance— I get charts and I get PowerPoints sent to me on certain metrics, which we could talk about a little later with the Presidio scenario. And sometimes I just look at the charts and I gloss over unless it's really relevant to what I'm wanting to see. So it's still relevant today where I'll look at a chart and say, I'm ignoring this slide, but this slide is super important to me because I care about this, this financial piece. You're absolutely correct about that.
Well, it looks like you, you moved over to Red Sky in December 2015. That is correct. Tell me about what was the impetus for making a change and what'd you move to? Sure. After 5 years of working with the team at NetSource, we're just at a— I want to talk about differences of opinion.
That's kind of the impetus of the move.
I'm very much a creator. As Chris Barney, the CEO of Red Sky, would tell you, I'm very much about painting and making making something. And NetSource was more about a, let's just kind of keep the status quo, we'll grow a little bit, we'll do some things here or there. But it was more of a lifestyle company, and I'm more of a kind of a hypergrowth painter. I want to create things that I can deliver and not wait 5 years to do it, so to speak, and not have any pain points consistently holding me up.
And so that kind of created some frustration with me at NetSource from that perspective of, hey, how are we going to grow this company? If we're not all aligned and we're not all firing in the same beam, we're not going to grow the company the way that it should be grown. And that's okay for, for those of you that want to continue the company the way it is, but as a painter, quote, I wanted to go out and do kind of better things, so to speak. And so that's kind of what drove the impetus of me kind of just to say maybe this is— maybe I, I've kind of run my course here and maybe I need to look at the next, next elevation, so to speak. And kind of like we talked about a little bit earlier pre-podcast, but it was Chris Barney, the CEO of Red Sky, had caught me at a conference, a Palo Alto conference, and he just does— he's very persistent, he doesn't give up, you know, basically alluded to the fact that I would be working at Red Sky.
And what was his vision for you to do for Red Sky, and what was Red Sky pre-Justin and post-Justin? Sure, so Red Sky was— prior to me, actually, was more network-focused, a network and platform kind of data center network company. Similar to what NetSource was before. Similar, very similar indeed, but we were actually competing companies, in fact, in that area, and they were Brocade's number one partner in the United States for different kinds of switched lines. Chris's vision was, hey, we see this security shift.
We know we need to be able to provide security solutions to our customer without forgetting that we're also a platform and network company as well. And so we want you to kind of come and build that for us, and I'm going to give you the kind of autonomy to do that. You tell me what you need, and I'll tell you when you're crazy, right, kind of so to speak. And, uh, that's kind of what kind of drove the conversation. You know, there were some, like we discussed earlier, some more forceful points where he was a little more like, hey, in my face about some things in terms of like getting me to come over.
But inevitably, that's what drove it, the ability to to say, okay, here I have this management team at a company that wants me to join them. They're definitely open-minded to being security-led, but not a security company, so to speak. They have the drive and the ambition to continue hypergrowth or to get into hypergrowth and maintain it and have a lot of fun while you're doing it. Another big component for me with Red Sky is Chris Barney and everybody through the management team, whether it's John Jensen or Andy Olson, Kevin K, our CIO, super family committed. So Red Sky is a huge family company.
Was, um, so Chris Barney, our CEO, could tell you the name of everybody in the company. How big is the company? Um, at that time they were, they weren't that big, 20. Maybe I was 20-something, I could be off on that. But even as we get to 100 employees, Chris knows everybody, right?
And he knows them intimately. And I think that was the thing, seeing kind of that just family atmosphere, meeting the team and seeing how how much camaraderie there was, and that culture was there, that culture of let's do great things. That was the driving force for me to say, okay, I think I can align here, and I think there's so many cool teammates here that we can build something great. Yeah. Yeah.
And so you talked about, you talked about hypergrowth a couple of times. What does that mean to you? What's hypergrowth? So hypergrowth to me is when a company is sustaining over 30% year-over-year growth, at least for, for a reseller-type company, right? A little bit easier to blow those numbers out in certain product type companies.
But it's easier the first couple years. Yes, yes, yes, exactly. You can go get 100% growth at the beginning or 1,000% growth. It gets harder and harder each year as you go on. It's very true.
You know, I do, I do chuckle to myself when I see companies go, I have 5,000% growth. I'm like, that's because last year you made $500,000, right? Right. So the numbers do get skewed. Hypergrowth to me is continually doing it over a set of like 4 or 5 years, right?
Just sustaining it. And it's not sustainable forever, but if you can hold it for a long time, yeah, for 5, 6 years without, you know, organically, without investment, it's a pretty cool thing to do. And that's something we set out to do at Red Sky, and we achieved that really, really quickly by just, again, aligning the Death Star, making sure that the teams were all aligned, the culture was there, and we're all— now my newest analogy in the company is that we're all rowing the same boat. Direction in the canoe because paddles, right? So that's kind of what drove that along with our culture and just the thing with Red Sky that was really cool and is still cool today is we're engineering heavy.
So we had more engineers than we had salespeople or anything. And that was pretty unique for a reseller at the time when I first joined to be that engineering heavy and being so engineering focused. Focused. At that time, we didn't have a split post-sales, pre-sales scenario. Our engineers were both.
We were small enough that the engineer that you talked to with an account manager was probably the engineer that was also going to install your solution or do whatever it was you're looking for, which created a really cool atmosphere. It's not a sustainable model as you grow. You do have to split the teams out and have organization because that's just growth, also maturing factor of things you have to understand with business, right? But if you can do that for a while and then build that camaraderie, and then your teams are already there, they know exactly what roles they like. Certain engineers like post-sales, certain engineers like pre-sales.
It's easier when you get bigger for those teams to split apart logically and say, I'm pre-sales, I'm post-sales. That's where we grew that to. Tactically speaking, you got into the job and your goal was to build a security practice out and make this kind of change the company. How do you do that? What's step 1 through 5 look like?
Yeah, it's an interesting question. I call it moving the Titanic just slightly. I still do. I still say that today. When you take a company that has any kind of sales motion to it and that sales motion is non-security related, so mostly let's say that there's a lot of— let's, for the sake of today's technology, pure storage arrays.
They're selling a ton of pure storage. Or Nutanix or whatever it may be, and then the sales reps are making a lot of money doing it. Yeah. And then you come in and say, I need to take like 5% of your attention because I'm going to show you something cool and something we're now growing. That's a hard thing to do because a salesperson's so focused on that dollar, and you're now telling them, I'm going to take some of your runway away.
Runway, right? They have an existing pipeline. Yes. They have all the stakeholders at the customers. They know how to sell.
The old stuff, right? Exactly. So essentially what we did at that point is the first thing I did at Red Sky was to kind of get everybody together. So we had a sales kickoff, and there was something John Jensen put together which was awesome, so we could come together as a whole company and present kind of the direction where we wanted to go. And the first thing I always tell everybody on the team when we were starting something new was this is not the primary focus of the company.
Red Sky is not a security company. We will be security-led. And what that means for you is that everything that we do has security built into it. So if we're still talking about a Pure Array or Nutanix or whatever it may be, those things still have security components to them, whether it's encryption at rest, whatever it may be. We still need to understand those components.
I'm not wanting you to distract from that, but understand that these security components also play into a bigger discussion with your customers that you should be having anyways about how you're going to help them secure their infrastructure. We did some presentations on that. The easiest way to break into security for a new rep or someone who's not focused on it heavily is services, quite frankly. We launched our applied research team right off the bat, and that was our pen testing team. I think we had 2 engineers, and I was doing pen testing as well.
That's easy enough for an account team to grab ahold of and go to the customers and say, who's doing your pen testing? You want to give us a shot at it? Here's what our sample looks like. That gets the door open. Step 1, building some pen testing out that's an easy service to sell.
Right. Once they get the understanding of that, what tends to happen, at least in the 2 consecutive buildouts here, is that the account managers understand that you become more valuable to your customer base. You now are not just the guy that sells Nutanix, right? You also understand the security strategy, or you can bring in parts of the team to help your customer on a wider array of things, and you become much more valuable, right? And that's how we kind of built that out.
We started heavily with services, and easier services that are easier to pitch. They're a little more competitive, right? And so sometimes they may even become a bit of a loss leader for you because you can't go out and say, I'm demanding that you pay $30,000 a week for a pen test because I'm cooler than Company XYZ, and Company XYZ is $9,500. You're like, man, you're not gonna go anywhere. Yeah, right.
You have to be realistic, and sometimes you have to come in under that because you're new to the market. And that loss leader scenario is more about growing your team's confidence and getting them to understand we're now shifting into security-led, not security company, but security-led. And that's really what we did. We spent a lot of time— I spent a ton of time on planes with the account managers going to a lot of meetings with them, talking to them about how I would approach security discussions. And to me, it is just a discussion, having a very casual, like we are now, discussion.
It's not a scary thing. It's just, hey, let's just— what's going on, right? Be human, right? And so I spent a lot of time the first 6 months just everywhere with our account teams, and I started kind of building my plans for what engineers and consultants I could bring on board. And Phil Wong and Eileen Wells will tell you I always have this master plan.
There's a picture of us at Black Hat a few years ago of all of us together with Chris Barney before they came to Red Sky. And I knew at that point I wanted to bring both of them on. And so we have this laugh now that they're like, you always have this master plan of people that you want to work alongside. And so that's kind of what I did. I built this plan.
I went around and asked everybody who would be the most top-notch engineer that you would love. Because I didn't know everybody at Denver at the time. I'd spent so much time traveling, and I kind of built it out, quite honestly. I made a list and we just started. I went to the executive team, we'd have retreats, and we'd sit down and I'd say, this is kind of eventually what we're going to do.
It worked out splendidly well in this instance, but I think it did so because, again, the team was so driven across the board. Everybody understood that we're not a security company, we're integrating security into what we do, but we're still going to do what we do and do it well. And we're only going to focus on the things we do really well, and we're not going to try to step outside of that wheelhouse. Because that's also where you start to stumble, is if you tell a customer, yeah, I can do that, yeah, I can do that, yeah, I can do that, you start to become CDW, right? No offense to CDW, they just have a lot of products.
And then when you're a little Red Sky, a 30-person company at the time, there's no way you can scale to that, right? So you have to pick your partnerships pretty well. Looking at the growth over the last 2+ years that you've been there, almost 3 years, what are the capabilities that you've really grown into? You mentioned pen testing was a starting point. What's that turned into?
Sure. That's a good question. We grew services both on what we call post-sales side of the house, so Palo Alto-type engineering, security product engineering, as well as applied research, which is our dark arts team, which is the pen testing, code reviews, mobile assessments. So being able to disassemble iOS and work with customers on SDLC. So Applied Research matured into a team that really kind of became less pen testing, so to speak, and more about reviews.
Customers would integrate us into their SDLC to say, hey, our QA team is going to send you their code. For this quarter. Can you guys check the code out and make sure that there's no security issues that are glaring? And that's really what that team grew into. We still do a lot of what I call basic pen testing, kind of the scan and light confirmation that a vulnerability is there.
Very few customers are asking us for intense red teaming right now, so that's— it's more so about the code reviews, web apps for those guys. Applied Research broke off as well into another scenario, which was was kind of a managed services scenario. So we built out what we called managed vulnerability threat management, is where we could actually ingest customers' data, and we built an actual homegrown portal with charts and all kinds of cool remediation functions, and customers could then maintain and manage their vulnerability lifecycle with our engineering team helping them on the backend. So that kind of broke out that way, and then the product side, we decided that Palo Alto was a product we really loved, the firewalls at the time, and so we invested a lot in engineering and Palo Alto certifications, becoming their number one partner in terms of engineering capabilities and delivery capabilities because we already had engineers that could deliver Juniper, Brocade type network installs and things of that nature, and those guys were busy. But for our product side of the house, when you look at customers that needed like help with Palo Alto or Proofpoint or whatever it was, we needed to pick our partnerships there very strategically.
One, to make sure that the products that we're choosing to partner with are actually good products. Two, that we could support them without having to go to the vendor for anything. Without having to have hundreds of engineers. Yeah, absolutely. That's another challenge.
Fast-forwarding a little bit, you guys have had an ownership change, right? You want to talk about that a little at all? Yeah, we can talk about that. April 2nd of this year, we announced we were acquired by a Presidio. Presidio is not really well known in the Colorado market or the Rocky Mountain region right now.
They are a $3 billion systems integrator, if you will. I don't want to call them reseller. I think that's a disservice, but a systems integrator, engineering-heavy firm.
Predominantly, they're Cisco's 2nd or 3rd largest partner in the world right now. I think first largest unified communication partner. They are huge into the unified communication space and really delving into the security spaces now. They've had a cybersecurity practice for a while that does a lot of pen testing, compliance type stuff. Out west here, they haven't had, like you're aware of, not much of a brand or an image, and so that was kind of their go-to for us.
We were— was it in 2017? They were Palo Alto's Partner of the Year, National Partner of the Year, and we were Palo Alto's Western Partner of the Year. And so I think that kind of got them thinking at that point in time, hmm, these guys, they're a small little shop here winning Partner of the Year, there's got to be something special here. And so that started the balls rolling there, I think. And so we announced the acquisition April 2nd.
We're still, like I mentioned earlier, we're still trying to figure out the branding, what that means with the Red Sky logo or the Red Sky name itself. Right now we're called Red Sky Presidio company. And so we'll see how that plays out. We're pretty proud of our Red Sky brand. As they all found out, we were in Orlando a couple weeks ago now for their national sales meeting, sales and engineering meeting, and the Red Sky engineers all showed up in Red Sky polo shirts, backpacks, socks, belts, everything.
And the COO of Presidio just laughed. He's like, you guys in those polo shirts, man. So it's hard. You are wearing a Red Sky polo shirt right now. I am indeed.
Yeah, I've got a ton of these in my closet. Yeah, it's when you've built something, right? It's your baby and you've got so much pride in it. It's hard to let it go, especially if you know what you did. I mean, this actual design was something that I approved with Chris Barnier prior to him coming on board, the new 3 stripes, the logo.
Yeah. And so you kind of— it's hard to let that go, right? Eventually you have to because that's just what happens in an acquisition type equity event. Is eventually that gets absorbed. But we'll see what happens with the logo because they don't have the branding we do or the branding power we have out here right now.
So it'll be interesting. Yeah, it will be. Uh, and something else I saw on your LinkedIn here, it looks like you're a, uh, you're a volunteer for BSides Las Vegas. Can you talk about that involvement? Yes, so I am, um, the secretary of the board for BSides Las Vegas, some board of directors.
Um, so, and I'm also on the CFP panel. Okay. For, um, and I did that The CFP panel is a lot of fun, but man, it takes a lot of time. So each year I kind of pull myself out of that a little less and a little less unless they need me to. Last year I did CFP— sorry, I say last year.
This past summer I did CFP again for B-Sides. And that's a challenging thing. Like the board of directors is challenging, but CFP is really challenging because there's so many awesome submissions coming in and you kind of look at them and you read— there's a lot of reading obviously and a lot of categorization, and you have so many slots to fill and you have all this great content and you're like, man, how do I pick and choose? Luckily there's more than one CFP member, right? And we aggregate scores and there's a whole secondary chair that helps out with that.
But it's a super fascinating and cool thing to do. I definitely— the CFP panel is a volunteer team. You can actually reach out to B-Sides Las Vegas and volunteer to do things there, whether it's working on-site with them or CFP panel type stuff. Or if you want to be on the CFP panel, definitely reach out to me, I can help you with that. But it's, it's a fascinating thing to see all the different research that people are doing.
The hardest part, like I said, is to say, man, I don't think this fits here, but I really think it's so cool, but I don't know where I would put it in the conference. And I'm sure in the past with RMSIC, you probably had the same issues where it's like, how do you— I need to start another little track here because this is so neat. But yeah, you just can't put it all in. Yeah, absolutely. There's way too much good content.
Yeah. What do you have? Any other community involvement you want to talk about? You've been around here a while. Yeah, you know, I, I've been traveling so much with, with our acquisition and the kind of acceleration of Red Sky.
I haven't been home much, to be honest with you. That's something I've talked to Phil Wong about recently is I haven't been out to much of the OWASP stuff or any of that stuff. I always seem to be out of town when those meetings are going on. I do need to get more connected with the local teams here. I said teams, but the crew, and spend more time out at those events if I can.
If there's something you guys recommend, I definitely am open for that. All kinds of great stuff. Yeah, absolutely. The Colorado Equal Security event calendar has stuff going on. About every night of the week.
Okay, I will check it out. I've taken the hint there. There's a, you know, I don't know if you've got the DenSec meetup, you've been to that stuff. They do these, it's the, was it the 3rd Wednesday of the month? Sorry if I got that wrong, guys.
They get together at one of the bars downtown. Okay, just a great group. You'd love it. You'd love hanging out with those guys. There's no speaker, it's just a social event.
Talk to some security guys. Okay, lots of good opportunities. Yeah, absolutely. I mean, I'm definitely One of the things that I'm kind of stoked about with the acquisition is I'm going to slow my travel down about November because we're getting everything aligned now, and I've got the teams in the different geos, so I can be home a lot more and kind of build my network of people here again. So I definitely will reach out and look at that calendar to kind of jump out there outside of work stuff.
I work too much, clearly. Yeah, you've got to stop working. Well, we've had a great conversation. I want to ask you, is there anything that I should have asked you that I didn't ask?
I have no idea on that. I've kind of covered a lot of things.
No, I don't think— I can't think of anything. Well, Dustin, this is awesome. I'm looking forward to seeing what happens with Red Sky and you in the future, and we'll check in and keep tabs on what's going on. Absolutely.
Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.