Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 92 for the week of November 12th. Alex, we're just about to Thanksgiving.
We're most of the way here. We're almost there. Everybody should start getting their speeches ready. All the, you know, you know, around the table somebody's gonna ask what you're thankful for. So you better, you know, start thinking of that.
Start being ready to be offended by somebody's political views. And exactly. I am choosing to opt out of family Thanksgiving this year. We're actually going for a trip over the holidays. Nice.
I am not. I'm opting out of American Thanksgiving, but I am gonna be with family. I'll be in Mexico instead. Awesome. Well, we're going on a cruise and it'll be my wife and my kids, but we won't have the extended family around.
And I think along with Thanksgiving, we wanted to note that because we are traveling, next week there will not be an episode. So you guys will have to miss us. Something to be thankful for. Exactly, exactly. One less thing to do during that busy holiday week.
Before we jump over to the content this week, we do have a little bit of housekeeping to do. As a reminder, we have a Slack channel. The Slack channel has been growing. We've seen, I think, 650-ish people a part of the community right now. This is a good place for you to come get involved, get to meet other security people in the area.
You can get the link to join on the colorado-security.com website. Come join us and be a part of the conversation. Exactly. Also on our website, colorado-security.com, you can sign up to be part of our mailing list. You will get the show notes in the email right after it is released.
So this will get all of the links to everything that we talk about on the show. So if you're interested in that, go ahead and sign up. We'd also love it if you would rate us and subscribe on your favorite podcast listening application. Subscribing means you get the podcast in your, in your queue every week to listen to us. And of course, if you rate us and say nice things about us, that means other folks will be more likely to find the show.
And if you really like us, please, please support us through Patreon. We have a Patreon campaign going to help pay for the expenses of the show. All of the money on that Patreon campaign goes right back into the podcast and other Colorado Equals security activities. And we would like to thank a new Patreon supporter, Ruble Henderson. Thanks, Ruble, for signing up.
He signed up for the $10 a month level, which gets him a shout out on the show and a free t-shirt. We really do appreciate it. He works with Mimecast over there with Andre Gaeta. So hopefully Andre nudged him and said, you know, come, come support the show. That's right.
If you're going to work here, yeah, you got to support these guys. We love it. Good stuff. And then finally, you know, if you want to support the show and you don't, you don't want to use any financial support for it, we would love it if you just go tell some coworkers, tell some friends about the show, help us find some new listeners through reach out like that. So, Robb, big news this week.
Amazon HQ2. We found out that there's probably going to be 2 HQ2s. Yeah, kind of weird, right? Yeah, I think we were all expecting, you know, they said there's going to be this new headquarters that's going to be the peer to Seattle in a different city. We're all— I think we're all thinking, you know, one city will be that peer.
But it looks like, you know, the whole time there's some, like, some language in the proposal that said they could choose to put it in multiple cities. And from the rumors, I think it was the Washington Post who posted this, that the rumors are that it's actually going to be in 2 cities and neither of them are Denver. Yeah. So the odds on now are for Crystal City, Virginia, which is right across from DC, right next to Reagan Airport and part of Queens, again, right outside of Manhattan. Yeah.
So really near near New York City and near Washington, D.C. Yep. As the, the split HQ2, HQ2A and HQ2B. I, I don't know. This whole thing's kind of weird. I, I think Amazon accomplished exactly what they wanted to.
They wanted all of the cities to, to bow down and give them a whole bunch of incentives. And they also wanted a whole bunch of publicity for this. So they've gotten both of those. And they, they, we certainly wouldn't have been talking about this if without their massive campaign. So Yeah, good for them.
Exactly. Next, speaking of Denver being fantastic, we ranked number 2 on a Millennium Boomtown from Magnify Money report. Yeah. So this report actually had a couple of different things. There was an original report that talked about boomtowns in general, and Denver ranked number 6.
And then they sort of sliced that data again, I think, and look at boomtowns for millennials. And we were number 2 on that list. So we have a lot of millennials here and they like Denver. Number 1 is San Francisco. Obviously, we're second.
And number 3, way behind us in a distant third place, is Austin, Texas. Suck it, Austin. Suck it, Austin. Very well. Some interesting other ones on the list.
Nashville made the list. Raleigh, North Carolina was number 6. Portland. Oklahoma City made the list. Kind of a surprising top 10.
I would not have guessed. I guess there are millennials in Oklahoma City. Yeah. Next, Fort Collins and Boulder are the top 2 cities in Bloomberg's Brain Concentration Index. So this is talking about cities that have concentration of business formation, education, employment services, science, technology, engineering, and mathematics.
The way I look at it is basically, are people— are smart people moving to that area or moving away from that area? And they both were at the top of the list of places that people are moving to. It was interesting. I don't know if you read the other part of the report. It actually talked about the brain drain section of it.
So I don't want to make too much fun of them. But there were a lot of different cities on that list that had lost a lot of folks, including a place just a little ways away from Silicon Valley. I actually, you know, I'm from the Bay Area and I've never heard of the Hanford-Corrigan metropolitan area, 175 miles southeast of the Silicon Valley. But it was the number one on the brain drain index. I'm surprised you haven't because it sounds like everyone is leaving there.
Yeah. There's also a city in West Virginia, which doesn't surprise me. And a couple other, you know, cities that you might recognize on the list. Kankakee, Illinois was number 2 on the brain drain. Anyway, the whole thing's a little bit interesting to me.
Exactly. Next on our news here, do you remember we talked quite a bit about this, this campaign that a bunch of Colorado tech companies put together to put signs like in the, in the subways out in San Francisco and the BART? Saying, you know, move to Colorado. It's a place for you to continue your career and a good place to live. Would you— how many, how many would you guess we've had come to Colorado as a result of that?
You know, I think that seems like a really good idea. So I'm going to say like, you know, tens of thousands. Yeah. Well, so you're absolutely right. Just multiply by zero and you're right there.
They have— they have no— not had a single person that they can tie back to this campaign who's actually moved out to Colorado. The organizers of the campaign have said that they're not too worried. This is actually— it's a long game, right? They're not. Out for short-term results.
They're thinking that it's still going to have an effect and we're going to see that effect any day now. Well, I actually think I agree with them that the whole point here is not that you put up a sign and someone's going to quit their job and move to the Bay Area immediately— excuse me, move from the Bay Area to Colorado the same day. However, you know, we have seen a lot of companies move from the Bay Area to Denver. I expect that as those companies move, as they continue to hear this good press you'll start to make some progress there. Yeah, they've only— they spent about $500,000 on marketing, so it's not like it's been a massive amount of money at this point.
They're, they're just getting our name out there. Exactly. Hopefully good things to come. Uh, next, there was an announcement this week from Zayo that they plan to separate into 2 different companies. So the— they announced plans to separate into 2 publicly traded companies, one that will focus on their core communications infrastructure and the other that will leverage that infrastructure to provide enterprise solutions.
So they're, they're, you know, tentatively calling themselves like the infrastructure co and enterprise co, you know, based on their focuses. Um, we, we don't know a lot yet. I, I do know that, you know, historically Zayo has spun out other companies, and this is something that they've done successfully. And this is not a, a sign of things going poorly. This is a way that they continue to let companies be focused on what they do best instead of having a monolithic big organization.
Yeah, it seems like, you know, part of the way that they operate, right? Which is great. You see, a lot of times companies just grow and grow and grow and have all these different pieces and parts that don't necessarily complement each other. And you have problems with culture and other things like that. So to, to have that culture where you spin out these companies once it makes sense, I think is a good one.
Yep, absolutely. Next, I think we've talked about it a few previous shows. But this past week was the CTA's Apex Awards ceremony. Uh, where there were a number of awards given away, including Colorado's CISO of the Year. So we had, uh, some nominees for that award.
Um, Debbie Blyth from the state of Colorado, James Carder from LogRhythm, and our own Robb Reck were all finalists in this award. And I am proud to announce Robb Reck was, uh, awarded with CISO of the Year. Congratulations, Robb. Thank you. I appreciate it.
It was, it was a special night. It was a lot of fun. Um, you know, James and Debbie were both at the event, and I got the opportunity to hang out with them and talk with them. And it's just a neat thing to be a part of and, um, to get to see the way security has become acknowledged in the community and up there on the stage with the CEO of the Year and the CIO of the Year. Uh, it was a, it was a really cool thing.
Um, it was great, great to see you up there. You gave a great acceptance speech, which, um, you know, not to toot your own horn or anything, but I think that we will play as part of this episode. So if you guys you know, listen after the news, you'll get to hear Robb accepting that award. And it is less than 2 minutes long. So, so keep that in mind.
We didn't go super long. I'd also like to note, last year at the award ceremony, it was the first year for the CISO of the Year Award. And not surprisingly, they put that award last. It was not last, last, they give a Lifetime Achievement Award, which is always last, but of the, the other sort of standard awards, we were last this year. We moved up and we were second to last in front of the CIO of the Year award.
So they do the individual awards toward the back. So CEO of the Year, CIO of the Year, and then like the Entrepreneur of the Year. Yeah, those are all like right bundled together. So it's a good spot to be. I'd also like to note that Swimlane was a finalist as well.
They did not win their award, but Cody Cornell, CEO of Swimlane, was sitting at my table at the awards ceremony. So— and Password Ping was also out there. Password Ping was also Also, um, breach database, uh, company that helps you compare passwords against your database of known bad passwords. Exactly. Congratulations to all the winners.
Yeah, absolutely. Moving over to some local security company news, Ping Identity had a survey that they released this week. It was a survey of about 3,000 people across the US, UK, France, and Germany. Some interesting numbers I pulled out from the survey. 78% of respondents said they would stop engaging with a brand online, and more than a third said they'd stop engaging altogether if the brand had a data breach.
So yeah, that's it. Those are big numbers. 76% are gonna stop buying from your, you know, from Amazon if Amazon is breached or right or whatever. That's a lot. Yeah.
Um, and I think that is a great sign to see that, that people are caring more about their, uh, security and their privacy. I will say though, that this was, it was a survey. So it's people's opinions, not their actions. I think, I know personally, I've seen in the past where people will say one thing and act another way. So I think it is a little bit dubious that the numbers are that high.
I think people probably want to do that, but maybe not are going to actually act that way. I would love to see some follow-up research to see if you can find any data around how people have acted after a security breach. Self-reported versus actual data. Right. That makes sense.
I can take that back. You should. Nearly half of the people said they would not sign up to use an online service recently experienced a breach. 53% said that 53% of respondents under 35 feel confident with online services security. That's compared to only 27% of people over 55.
So there's a really big gap for those, you know, under 35 and those over 55. Yeah, no, it's definitely some interesting numbers in there. Um, and I think it is things that, that people can use to show how important security and, and people's brand awareness around security is. One other thing I pulled out was that Americans are nearly twice as likely to share sensitive information with brands online than folks from the other countries, from the UK, France, and Germany. Privacy, uh, is not high on the list of priorities here.
It is not. All right, moving on. Uh, next, there was a CyberGRX blog this week. SMB Cybersecurity Series: Asset Inventory is the Foundation of Cybersecurity. I think, you know, this is something that I know you've talked a lot about, Robb, and, you know, I talk about as well.
If you look at any of the, uh, the standards and frameworks that are out there, you know, the first control they always have on the list is around asset inventory, making sure that you know what you have. And that's kind of what this blog post is talking about, how important knowing what your assets are is. And he doesn't just talk about how important it is. He also talks about how to do it, what to, what to measure, what to inventory, and how to go about doing that. So it's a really good idea, especially for an SMB or any organization that doesn't yet have a solid inventory program in place.
You should take a look at this. By the way, this blog post is written by Kevin Ford, who is the CISO over at CyberGRX. I actually don't know Kevin yet, but nice to see him contributing to the community. I also, when I was reading this, um, there's a section in the NIST cybersecurity class that I teach that reads very similar to this. So I was like, oh, did Kevin come and take my class and then write this blog?
He has not, but we obviously think the same way. That's pretty cool. So you guys have the same issues. Yeah. Uh, next there's a blog post, uh, by Webroot by Randy Abrams over there.
I'm talking about password constraints and their unintended security consequences. And what this is all about is, is talking about what it do when you apply password complexity requirements? And, and what are you doing to your, um, to the entropy, if you're familiar with that phrase, listeners? Basically, how many different options do you have to have to guess before you can get a password right? So if I say, you know, your password has to be 8 characters and one of those characters has to be a capital letter, that means that if you're guessing my password, you actually have fewer combinations to guess because you don't have to bother guessing any of the combinations that have no capital letters in it.
So they're going through talking about what are the impacts of different complexity requirements on password entropy and, and how much more difficult we can make it for hackers to guess passwords. Yeah, and I thought it was a nice blog. They actually, you know, talk through the math and give some examples of how that works. But, you know, you, you get to the bottom line, the, the bottom line really is it's better to have a longer password than a complex password. So that kind of goes along with the fairly recently announced NIST identity requirements.
So, you know, they say, hey, longer passwords don't necessarily enforce complexity. You don't necessarily have to change them as often. So just make sure that you guys have long passwords. That's going to make it— so I want to add a nuance to that. I think that what they're saying is longer password requirements are better and make better passwords, not longer.
Not— it's longer is better in terms of better than complexity in terms of requirements. But if actually when you're making your password, you probably do want to use complexity. It's just as you do the requirements that if you say it has to have one of these things, you're eliminating space for people to guess. So it does get a little bit nuanced if you're setting your own passwords. I still recommend using high complex passwords.
Just when you're setting requirements for passwords, it's— that's where it gets a little fuzzy. Yes. Yeah. You don't want to have a password that is, you know, 24 A's. You know, yeah, that you still want to make it complex.
Next, there was a ProtectWise blog this week on security predictions for 2019. Is it already the season, Alex? It is already the season. Now we're gonna have several months here of people writing prediction blogs, and then come January, we're gonna have several months of people writing blogs that are, hey, this is what happened back in 2018, right? So, but we'd never see Well, you almost never see is someone saying, let me show you my prediction blog from last year and how right I was.
Exactly. Because they're always very wrong. Yeah. So speaking of being very wrong, just, just kidding, ProtectWise folks. This is written by Gene Stevens, who I know.
Gene. Hey, Gene. And Tom Hagel over at ProtectWise. They have 9 different items on the list. I think it's probably worth going through them pretty quickly.
Yeah. First one, they are talking about publicly announced supply chain attacks will continue to climb. I can see that happening. Yeah. Number 2, the amount of incidents occurring from unknown attack services within an organization increase.
So they're talking about Internet of Things and BYOD, really seeing those attacks increase next year. Number 3, network detection and response will become much more common and integrate with endpoint detection response. I don't know if I see that or not, but, you know, ProtectWise is a company that does network detection response, so I can see where they're, if nothing else, hopeful that that will happen. They say, they say much more common. I think if they got rid of the word much, just more common, I could buy that.
It's going to be a slow process. Yep. People are getting more interested in those network analytics, though. Number 4, the SIEM will see early but serious disruption as security vendors introduce meaningful correlation capabilities and SOC automation. I could see that happening.
Yeah, that's, that's true. People will shift prioritizing cloud-delivered security solutions over traditional appliance-based products. I think we've already started to see that. Yeah, that's just a continuation of a trend. Yeah, it will continue.
Teams will prioritize security technologies that work equally well in traditional enterprises and the cloud, basically getting to that hybrid security deployment. I do agree with this, that many organizations want to move to the cloud, but you just can't move everything all at once. DevSecOps will continue to grow, moving people towards API-centric solutions. Again, I, I can't disagree with that. Yep, they're just recognizing the trends that are happening, right?
And By the way, I've been part of having to write these lists and you're like, well, yeah, most of this is simple, but we gotta put the content out there. Yep. It is true. Uh, number 8, all security concerns will increasingly be consolidated under the CSO to increase operational efficiency. So IT networks, OT environments are gonna continue to be, uh, you know, centralized into one place.
Yeah, makes sense. And then finally, talent shortages will continue to be a problem. Um, uh, not going on a limb on that one, are they? No, I, I completely agree with that one. We will continue to have these problems going forward for the near future.
Near-term future. Next, we have a blog by Automox. It's the Modern IT Manager's Tech Stack: Supporting Your End Users. So this is really going through what are the different technologies that you need to be thinking about supporting and securing. Software as a service.
So it talks about Slack. It talks about G Suite. This is a nice introduction for those who are interested in getting, you know, kind of up to date on technology. Maybe you've been sitting in a company that hasn't updated their stack in the last decade. Uh, take a look through this.
I think it's a, it's a good update for what the rest of the world is going through right now. And then finally, uh, we had a blog from Conversant this week, uh, from Patrick Quinlan, who is the CEO over there. Um, basically sort of, sort of his opinion on civic engagement since we did have Election Day this week. You know, he would give us a little story about, uh, you know, him being asked a question, uh, from from someone in the news and he didn't have a great answer for it. So this is sort of him taking the time after the fact to go back and think about what his good answer should be.
Yeah, I threw this in this week because we did just go through an election and, you know, as much as we can all get really embedded in our jobs and our day-to-day lives, it's worth taking a moment to think about how are you helping move society in the direction you want to see society go. And I think Patrick Quinlan does a good job talking, you know, not necessarily about what direction it should be, but that you should know what that direction is for you. And you should really be working toward that, that engagement process. Yeah, for sure. All right.
That's it for the news. Let's go ahead and move over to our events for the week. As a reminder, we do have a calendar of events on the website at colorado-security.com. We have a lot of good stuff going on this week, starting on the 12th, Monday the 12th. SecureSet is doing their Denver War Games, an intro to strategy and GRC.
On the 13th, CTA is doing their Craft Your Career Path event. On the 13th and 14th, ISSA Denver has their November chapter meetings. That'll be on Boulder, Denver downtown, and then DTC over those 2 days. Also on the 13th and 14th, ISSA Colorado Springs is having their November chapter meetings. On the 14th, SecureSet has another one of their Denver war games.
This one is applied cryptography. On the 14th as well, OWASP is having their November chapter meeting. We're seeing all this stuff front-loaded in November because we've got a week off for Thanksgiving. And, and this event is— it's not going to be at Dave Buster's. They're moving back to Chinook Tavern, at least for this month.
So you can go enjoy a nice beer while you're there. On the 15th, ISACA Denver has their November chapter meeting. Also on the 15th, ISC² is doing their November chapter meeting. On the 17th, Colorado Springs ISSA is doing their mini seminar. As a reminder, those are the Saturday morning event they do from about 8 a.m. to 12 p.m. You get 4 CPEs and you learn some various security cool stuff.
On the 20th, SecureSet is doing a cybersecurity career convo. Rachel Pressler with Kelly IT Services. And that is the only event of that whole week because that's Thanksgiving week. So the next thing I just throw out there is once again another reminder, we have the ISSA ISACA Holiday Bash on December 10th. This is going to be fantastic.
It's at Soil Dove, a chance for you to get to hear from one of the bigwigs over at Palo Alto Networks and network with several hundred of your closest security friends here in Denver. Should be a good time. So everybody sign up. Uh, why don't we go ahead and move over to jobs? Uh, first job on the list is a security program business analyst at Ping Identity.
This is someone working directly with me. I think of this almost as a chief of staff role for me, someone to help manage the, the tasks that we're doing across the department. If you have experience either with program management, business analysis, financial analysis, those types of roles, I would love to talk to you about it. Go ahead and send me a note and or apply on the website. Second one is another paying job, our GRC analyst focused on business continuity and incident response, if you want to help us run those programs.
Next, Iterable is looking for a software engineer for application security. ThreatX is hiring a security engineer to work in their SOC. CGI Group is looking for a senior IAM specialist/engineer. Spectrum is hiring a supervisor of network security operations. Splunk is looking for Security with Splunk.
I know it's kind of a crazy name, but that's the title, Security with Splunk. So you're working in their internal security team. Cool. NREL is hiring a cybersecurity full-stack web application developer. That's a mouthful.
Coalfire is looking for an associate security consultant in healthcare. And then finally, FINRA is hiring an examiner focused on member regulation and sales practice. So if you want to help FINRA do regulation, Some of the, some of the job is cybersecurity, but some of it is just financial regulation. Cool. It's here in Denver.
Nice. And those are our jobs for the week. Those are our jobs. That is it for, for our news for this week. Next, we do have our feature interview coming up, and I think it's Dave Dufour who we're talking to this week.
Is that right? I believe it is. Yeah, Dave Dufour is the VP of Engineering over at Webroot. He and I talked, we caught up, you know, it's been about a year since we last talked to him. Figure out what's going on over there at Webroot and what, what's changed.
Nice. Love Dave. And if you ever listen to CyberWire, you'll hear him on there as well. Yeah, he's on there all the time. Uh, and so next you can— guys can listen to my, uh, 2 minutes of my acceptance speech, and then we'll go over to the interview.
Congrats again, Robb. Well deserved. Thank you very much. Talk to you soon. Thanks, Robb.
Awesome.
So has anyone else in the room been thinking about how to secure secure or hack Sam Elliott's tie the last hour and a half?
If so, I have a job for you. Give me a call. Let's chat about it. I do, I do want to say thanks to a couple things. Number one, CTA.
It's so awesome to have a group like this in Colorado that we get to help bring the community together, help us have a common goal for raising up the tech community in Colorado. I want to say thanks to the judges and the whole committee, the volunteers who put this on. We don't get to have this without their efforts. And I also want to say thanks to James and Debbie. I got to know both Debbie and James over the last few years.
We're not competitors. We are friends. We are a community here. The security community in Colorado has become really close, and I really appreciate Debbie and James both. Great people.
Really good to be on a finalist list with you guys. I want to say thanks to my wife, Kristen. Please, can we clap for my wife?
She puts up with a lot. A lot of stuff that I do for work and for the community, and I appreciate that very much. Thanks to Ping, the company that I get to work at. An amazing company. If you guys were here last year, our founder and CEO Andre Duran got the Lifetime Achievement Award.
It's an amazing place to work, and I'm blessed to be there as well. I'm gonna just say one more, one or two more things, and I'll get down so you guys can go drink and have fun.
We all have one common vision, right, for making Colorado the best place for technology in the world, in the country, in the world. And that's— what does that mean for me? That means we bring in the best technical companies, the best tech jobs, and of course the capital to make that happen. It doesn't work without the capital. If you guys can help drive toward that vision, we can be really successful.
I see the security community as a central part of that. Hickenlooper's National Cybersecurity Center, all the stuff we've done in town is a part of driving that together. And I'd ask you guys, kind of a call to action for you, Think about ways you can be a part of that. How do you— how can you be not just someone who, who's observing sitting in this room today, but giving back? Whether it's helping teach kids to code at a school near your house or getting involved with a community association like this, whatever you can do, help us, help us move forward and drive Colorado to be the number one place for technology and selfishly for security in the country.
That's it. Thanks a lot, guys. Yeah!
Hi, I am Justin Cohen, VP of Security at MedKeeper. Welcome to Colorado Equals Security. For Colorado Security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is a feature interview today, and I have the present— the pleasure of getting Dave Dufour back on the show. Dave, it's been about a year since we last touched base. That's right. How you been?
You know, things are good. Very busy at Webroot. Security industry is doing well. Webroot's doing really well as, as we focus in on, you know, managed service providers and offerings we have for them. And then, you know, our consumer business is booming.
So I want to hear all about Webroot stuff. Why don't we worry about that? I want to hear all about it, but in the, in the short term, I want to talk a little about personal stuff. So this summer, I know you have a couple of things we want to talk about. First, you went to France with your boys this summer.
Tell me about that. Well, so every summer my boys spend some time in France. So this year I got to— I was fortunate enough to get to go with them. So we spent a couple of weeks on the beach in a small little town called Saint-Jean-Monts. French Riviera?
No, no, it's on the Atlantic. It's a little more tame than the French Riviera, but it's really great. Lots of, you know, it's calm waters, kind of like the Gulf of Mexico, if any— if anyone's been down there. It's great for windsurfing, paddleboarding, things like that. What's the temperature there?
So it can vary. It can get actually chilly. You know, you're on the north Atlantic-ish, but 60s or 70s, but all the way up in the 80s or 90s. What about the water? Water temp is great because it's wetsuits, or you're going— no, it's Gulf Stream comes down along the coast there.
It, you know, wraps up North America and then back down along Ireland, the UK, and then Europe. Yeah, so it's pretty, it's pretty nice weather. You can go in, no problem. So you mostly spent your time in the water? Yep.
Water sports? Why? Yes, that's exactly right. I mean, I'm kind of addicted to French food. So, the markets and stuff.
Spent a lot of time walking. Didn't drive a car. Literally did not drive a car for 2 weeks. We just walked everywhere. No cabs at all?
You just walked? Could have taken a cab. But no, there was no need. Everything was close enough. Yeah.
Close enough. That's pretty fun. So, nice and sunny. You know, maybe 1 or 2 days of rain. But nice and calm.
I like surfing. No waves there. So, You know, like I said, paddleboarding, things of that nature. And how old are your boys? 8 and 10.
Same, it's basically the same as mine. Yeah, so it's a fun age. Totally a fun age. Yeah, absolutely. And they, are they fluent then?
Fluent. So that was one of the fun things. Um, you know, just for your listeners, I'm divorced. My ex-wife is French, and the boys are fluent in French. So we'd go into a restaurant and, you know, it was a little bit awkward when the waiter would try to talk to me, and my French is broken.
It's passable. I think if we were in France, you'd probably be glad I was there, but the boys make fun of me. When your 8-year-old or your 10-year-old is making fun of you, and then they start talking to the waiter and you don't know what they're talking about, it's a little bit awkward, and they love it. It's good for them for independence. That is good for them.
That's fun. Well, very cool. And then you said one other thing this summer is you started, uh, skateboarding, skating again. I did. You know, I'm an avid snowboarder.
Um, I'm fortunate that Webroot has an office in San Diego. I surf out there. But when I was a kid, I was born and raised in Florida, and I'd spent my entire childhood, you know, on half pipes, things like that. And I'm pretty old, I'm 48 now, but I'm trying to get the boys interested in skateboarding as well. I have this theory that if you get good at skateboarding and you're comfortable falling, there's not many other sports that hurt as much as when you fall skateboarding.
So it kind of toughens you up a little bit. And, and that, that ended up me, um, being in the bowls here. Like Westminster has a great, uh, bowl. It's a 10 or 11-foot bowl. And there's a nice skate park in Louisville.
I don't feel good enough to be downtown Denver. That's— yeah, there's that one there on 20th Street, right? Yeah, I'm a little bit shy about going there. I'm not that good. Are they pretty good there?
They're very good there. That's, that's a great place to watch if you're into skateboarding, watch really good skaters. Yeah, there's another one over at Clement Park in Littleton. Yeah, that's, you know, Colorado— again, growing up in the '80s in Florida, there weren't skate parks. You know, you know, I was fortunate to live in a rural area where there were a lot of half pipes.
People would build half pipes. But Colorado is great for skateboarding because every town has a little skate park, little, little lip trick, you know, bowl, or, you know, bowls with 2 feet of vert, depending on what your pleasure is. Yeah, it's a nice It's nice here. So have you had any major wipeouts yet? So I have— what's funny is when I started back, you know how it is, Robb, your brain thinks you're as good as you were when you were a kid.
And so my leg muscles, my calves, my ankles, and my feet had to get— the muscle tone had to get back. So if you saw me the first few times I'm riding the pipe, I would just fall over and people would be like, what are you doing? But Nothing major, you know, I'm not trying to blast out of half pipes or anything. I'm just trying to have fun and get my kids comfortable doing it. And where are they right now?
Are they actually doing it? They're more like, we bring their scooters along and they're more still wanting to ride their scooter because it's a little bit easier on the scooter because you're actually able to control the board with your hands. Yeah, so they're a little timid still, but we'll ease them into it. We'll get them One of these days, you know, the scooters won't be there. Oops, right?
Exactly. That's exactly a good idea. I didn't thought it was a good idea. We'll see how it goes, right? All right.
Well, so if I remember correctly, when I talked to you about a year ago, you had just taken on the head of engineering role at Webroot. Does that sound right? That is, that is right. A year ago August, I was put in a position of VP of engineering. Yeah.
So I'd love to hear what you guys have been investing in over the last year, you know, since you've kind of taken that on. Where have you been putting your focus? So we've spent a lot of time just shoring up some products we had in the works over, again, over the last few years. We have a DNS solution now that you can install and use our threat intelligence. So we got that out the door.
So talk to me about that. You're saying, is it a freestanding appliance, or what does that mean? Oh, I'm sorry. So imagine there's a client on your machine and you want to control where— let me back up. MSPs.
We've really focused on MSPs. We have a great consumer business. Now we're focusing on managed service providers. And so one offering we have for them is a managed DNS solution where they're able to sell that into their customers that you point your DNS servers to our environment. You can use our threat intelligence that large device manufacturers use to manage policy and things of that nature.
So this is kind of replacing what you might get from, what is it, 4.9s and 4.1s, the other that do some filtering. Cloudflare has a DNS service that does that kind of filtering. So we like to, honestly, we like to position ourselves straight up against Umbrella. We have a client-side offering that's a Cisco offering, and so we have found very good traction going straight after those customers. So you mentioned that you guys focus on MSPs.
I want to hit that a little bit. Before we do, just kind of high level, Webroot is known for 20-whatever years ago, was it Spy Sweeper? Spy Sweeper. That was the first product, right? Correct.
And that was kind of the get rid of spyware from your machines. That's exactly right. And then now antivirus is the flagship product from a consumer perspective for you guys. And from a business perspective. And from business, and then also threat intelligence that you embed or sell into MSPs, but not to enterprises directly usually, right?
Correct. We sell, like you said, our number one product is our Webroot Secure Anywhere. It's an antivirus solution, next-gen endpoint solution we like to call it, and it lives in the consumer space really well, also in the MSP space. MSPs like things that are super lightweight, not a lot of management. They're not looking to run SOCs and things like that because their customers are budget-conscious.
So it lives in that space. And then to your other point, we have a very robust business for OEM device manufacturers. Some of our clients are Cisco, are F5, the— basically they're using your Intel embedded in their plans, in their hardware. Correct. Things like malicious IP blocking, you know, URL filtering, things of that nature.
And lots of different appliances will have that kind of stuff built in. Absolutely. A lot of people don't realize they have Webroot threat intelligence already running in their offices because we've OEM'd.
So I was trying to look right now for this article we covered on you guys a little while ago, you might remember, um, one of your press releases had a number of MSPs, and it was something like, like 13,000. That's right. Some crazy— like, so just like for context here, for those listening, MSP, these are companies that offer services to usually small and medium businesses. Um, and they were saying that there are 13,000 of those MSPs who are who are your customers? Correct.
So, so we have 13,000. It's actually over 13,000. That was our fiscal year ended in June. So that was in June, we landed around 13,000. We're trying to drive well past that this year.
And as you said, an MSP, basically a managed service provider, offers IT and security solutions to small businesses, right? And so every one of those 13,000 MSPs has some number between 1 and N customers. So we literally have hundreds of thousands of customers through these MSPs, and it's just been a great market. I'm gonna be honest, super demanding. They want personal attention.
They want— you can't give personal attention to 13,000. Well, we spend a lot of time. We have very good customer service ratings. We spend a lot of time addressing their needs. Whether it be on the phone, the larger ones have, you know, support people directly that work with them.
The smaller ones are working through automated support solutions, things like that. So you're right, we don't have 13,000 people, so every day they're not on the phone. But we do a good job, and it's been really, really successful business for us. Yeah, I did find the press release. It was the— apparently at the end of your last fiscal year, it was 12,800 And which was up from 9,400 at the previous end of year.
That's right. That's what, 30% growth? Roughly 30%, more than 30% growth, right? It's awesome. I think, and I'm kind of making this one up, but between 3 and 4 years ago, we didn't have any MSPs.
And what, again, what people liked was it's lightweight, and we get that all the time. Do not make this thing heavy. Do not make it large. Do not make it use memory or CPU heavily and make it automated. Make it do everything.
Well, that's— that is the trick, isn't it? And the big thing MSPs want over a lot of enterprises is they want automated remediation. They don't necessarily need to know everything that's happening. What they need to know is that it's working because they don't want to hire extra bodies to be security experts for every one of their customers. So it's got me definitely wondering, you know, you say if you have 13,000+ MSPs now, what's the market there?
What percentage of saturation are you at? So that we globally, because we have offices in EMEA, Japan, and EMEA is Europe, Middle East, Africa, and in the States. So globally, our research shows about 60,000 MSPs That are in our addressable market. There's probably more than that. But so we're hoping to have a third of that market in the next year or two.
Seems pretty reasonable based on where you are. It does. Another 50% growth and you're there. Correct. That's great.
I do have another press release I just pulled up from August. Looks like Digital Shadows. Basically what I'm seeing here is that they're now OEMing your threat intel into their Searchlight. Are you familiar with that? I am not familiar with that deal.
I have to admit, I was, as you and I met, I I was buried in OEM when we started. I've been out of that for a little while now. So no, I'm not familiar with that. Digital Shadows is a threat intel company. It looks like they're now using your guys' threat intelligence in addition to their own proprietary stuff, augmentation.
So pretty cool stuff. And we're honestly, we have some pride about being, and it sounds funny, a growing, very robust, healthy security company. Based in Colorado. Yeah, because there's not a lot of, a lot of out-of-Silicon Valley companies that are really strong, robust, and running this stuff. So it's— we're proud to be here.
Yeah, and you know, there's what, there's 3 or 4 or 5 of us here in Colorado that kind of hit that with, with Ping and LogRhythm. Yeah, Optiv, obviously. Yeah, they're doing great. Coalfire is another one that's different, right? They're not a product company, but they've been doing really well as a services company.
And then there's the next whole generation, a little bit smaller side with the ProtectWise and Red Canary and Swimlane and those folks. Anyway, good stuff. I do want to talk a little bit more about the mix of stuff going over there. Obviously, you started solely as the SpySweeper. You call it now ProtectAnywhere?
Webroot SecurityAnywhere. SecurityAnywhere. What's the breakdown between that consumer space and the MSP, and where do you guys want that to be in the future? So that's a great question. As an engineer, I don't necessarily care where it lands.
I just like making stuff. I think the business folks would like to see that larger MSP, small business, business be stickier— or excuse me, to be larger because it is stickier. As you know, the space you work in, it's nice to have those business customers who are loyal and dedicated to you. We have a lot of consumers, super dedicated, super loyal. We love them and we cater to them, and that is our bread and butter.
But we'd like to see a nice 50/50 mix, and we're approaching that, that right away. That way, if there's any problem in any one segment of the market, we're still feeling strong. But we, we do not pretend to forget where we came from. We were a consumer company first. We love our consumer markets.
Great relationship with Best Buy. A lot of people don't realize that. The Geek Squad, they really like Webroot in terms of a remediation tool for folks who maybe have had a problem.
I think the right mix would be a 50/50, somewhere in that area.
It's getting more into your area. Those are all business questions. Yes, yes, yes. Let's talk about your area. What kind of technology changes or new enhancements have you been really digging into, and what problems you try to solve?
So we're really focused right now moving away from like PUAs, potentially unwanted applications. Potentially unwanted applications, right? Is this bot, you know, just annoying stuff? Basically it's malware. We're— I don't want to say we have it baked.
There's always behaviors. There's new malware coming out, but we're trying to grow and look at things outside of just executable malware scripts. You know, you see a ton of not just JavaScript but PowerShell. That's exactly right. And, and so we're trying to make sure we're, we're spending a ton of time looking at scripting.
There's a lot of techniques for, for, you know, doing permission escalation and then jumping into PowerShell and triggering scripts at that point. We're also investing a ton of time in R&D around exploits, and how do we really get into blocking and preventing exploits.
Exploits are really the delivery mechanism for most attacks that maybe a nation-state does where they're really trying to get in, but we're seeing more and more exploits kind of in that consumer small business area where they're becoming cheaper to implement, and if you haven't patched the system, I can exploit something in there and deliver malware through that exploit. So talk to me about the difference between exploits and malware. It feels like in order for malware to be effective, it has to have an exploit in it. That's right. Okay, so that's, that's a great, great question, and I'm gonna completely oversimplify this.
And, and, you know, your listeners are— some of them are gonna pick me apart on this oversimplification, just Give me a pass on this. I'm trying to explain it. Hardly. Exactly. Hardly, Robb.
But so there's the actual malicious payload, and then there's a delivery mechanism. So phishing typically, but not always, is a delivery mechanism. And not the phishing where it's trying to steal your credentials, but those drive-bys where you click on a URL. But what's going on when you click on that URL and then it pops up a page? That is most of the time delivering what's called an exploit.
And that exploit can be— the simple example I like to give, which isn't as pertinent nowadays as it was 2 or 3 years ago, was Flash used to be the most exploited product on the market. So imagine that we went out to Silk Road. You and I could go for, you know, $40,000 in Bitcoin. We could buy a zero-day exploit for Flash. Legitimately, this was possible a couple of years ago.
We could still do it today, but we couldn't use Silk Road because as you know, Silk Road is gone.
The exploit, the Flash exploit, we're going to embed that into that cute little kitty cat video everybody likes to watch. What's going to happen is the exploit is taking advantage of a flaw in Flash. That lets it do something like write to a memory location it's not supposed to and then execute whatever you just wrote. And so I embed an exploit in Flash. And while this video is playing, that exploit that's embedded in this video gets triggered.
And I maybe have 32 bytes, 64 bytes that I'm able to write to in a memory location I shouldn't get to. That exploit lets me write to that location. And then the very next step lets me execute from that location. And if I can do those 2 things, I can own a computer. Escalate.
That's exactly— and go from there. So what I hear you saying is previously you guys were more focused on the payload that you deliver, and you're trying to focus more on the exploit, which it seems like would be impossible to get specific exploits because if you knew them, they wouldn't be zero days, and thus, you know, they wouldn't work. So you've got to be focusing on behavior, like types of behavior. That's exactly right. And the good news about exploits is at the end of the day, if you can think of threats in a funnel, if you can watch what's going on in certain parts of memory and certain aspects of CPU processing, you can really identify common threats that we know of today.
Doesn't mean next year or the year after somebody doesn't come out with a new way. Triggering a threat, but you can really funnel down, you know, millions of potential exploits to a dozen or two things you need to really look for. If the trick is you got to be hooking every process, you've got to be watching all memory, and that takes a lot of resource load. And you also got to worry about false positives. One of the biggest examples I like to give is if we're doing process hooking and we say, oh, we don't want any We don't want to let any process run that modifies itself in memory because exploits— that's a common exploit technique to do process hollowing in memory and insert your code and run there.
But there's, there's programs like Steam where I'm sure many of your listeners are familiar, is a gaming platform where you can download games, and they do that exact thing. So the trick with this isn't identifying malicious stuff, it's identifying the stuff that's doing things that looks malicious that aren't. Which are false positives. Yeah. So you guys are focusing on trying to get better at what behaviors look bad and using that.
Are you using it for a binary decision, or are you trying to create risk scores from that? So we're— that's— if my boss was sitting here, he would say we are absolutely trying to do risk scores. So the answer is yes. He, the CTO, wants a risk score on everything. Yeah, he's a huge proponent of machine learning, believes in it.
From the ability to identify things humans can't, and through proper modeling, you can always get risk scores. Absolutely, that's what we're trying to do. In the long run, I think what I hear is maybe the MSPs or your customers can make decisions that are risk-appropriate for them based on environment. That's exactly right. Here's the trick.
First of all, we're never going to give up looking at payloads that have already landed. I mean, that's your bread and butter to make sure, hey, if a payload gets on the system, you want to know if it's good or bad. But we're expanding into areas where we prevent payloads from landing. I mean, for example, you know, we have an anti-phishing tool, we have the malicious URL blocking in our endpoint. We try to prevent a lot of that to keep the payload off.
But if it does get on and it does get past the scanning process, then let's look at the exploit. And with all of that in mind, you want to be able to give a confidence score, and you want to be able to give sort of a reputation. And that way, depending on the business, they can turn that up or down, you know, for some fidelity depending on their risk tolerance level. Yeah. So what we're talking about sounds like based primarily on prevention.
But it could very easily turn into the detection here, right? Especially when you start talking about these risk scores and saying things like, well, we don't want to block, so we'll alert on those, which would, you know, you're a step away from that, which gets you really into like the EDR-type world, right? Are you guys— and I don't think right now you guys offer an EDR solution. We do not. Is that a direction that this could take you, or what are you thinking?
In engineering, we spend a lot of time coming up with ideas that we vet. Like, we have what's called a streaming malware product that actually looks at IP packets and scans IP packets with file attachments and attempts to make, with a machine model, determinations, basically reconstructing these packets before they're completely constructed to give you if something's malicious or not. And it works very well, believe it or not. The problem is we've created this, but the market for that is in the enterprise space. And again, Webroot has focused, I mean laser-focused, on maintaining that consumer market and then SMBs and MSPs.
We just have realized that is our sweet spot. We're not going after large enterprises. There's a lot of people in there. Large enterprises like that EDR-type technology. So to your point, do we sit around and think about it?
We do. But when we come up with new ideas from a technical perspective and we take them to product, product is always like, how do we get that into our MSP space without them adding humans to have to analyze and monitor that? Because that adds cost, because MSPs care about, you know, cost points to their customers. Yeah, that's interesting. So we as an engineering team spend time on it.
But then it gets pulled back. We've got to figure out how to plug it in the MSP market. And how do you make it, you know, simple stupid, right? Correct. It just does it.
That's exactly— it needs to be iPhone'd. I mean, the stuff's just got to work. Yeah, that's interesting. What do you see, you know, we're not gonna talk for another year on the podcast. What's good?
What are you gonna be working on the next year? What's gonna be your focus 2019? That's a great question. We're spending a lot of time honing in the exploit tools that we're building, so that's not going anywhere. Network continues to be a major R&D focus for us.
We spend a lot of time with network anomaly detection, trying to look for threats. But you guys aren't getting network telemetry, are you? We bought a company 2 years ago called FlowScape. That did network anomaly detection. And so you would feed data off your— off of device SPAN ports into listeners that we created.
We would analyze that data, and we're very successful at finding anomalies and looking at anomalous behavior in the cloud. But the product team is pushing back saying, that's great, you got to hire a human to look at it to determine if that anomaly is a malicious actor. Or if it's truly just an anomaly that can be ignored. So they've sent us back to figure out how to automate that, make it smarter. Exactly.
And so we're spending a lot of research time on that as well. And that one's fun but tricky because it's science, right? We don't exactly know when we'll be able to get to that sweet spot of, of it, it provides enough value that, that a human doesn't have to look at it. So, so we're back working on that heavily. So you're building out teams and you guys are growing.
Are you hiring any folks in Denver? So we do hire— I mean, yes, we have engineering folks we're looking for in Denver. Denver's our corporate headquarters, right? And just, just to run through the globe, we have an office in Tokyo, an office in Australia, an office in San Jose, an office in San Diego, corporate headquarters in Broomfield. An office in Dublin, Ireland, an office in Derby, UK, which is about an hour and a half north of London, and an office in Linz, Austria.
We have a lot of offices. Half of those are engineering offices. The largest office, though, is here in Colorado. This is where our biggest footprint is. In Colorado, we're always looking for sales folks, marketing folks, engineering folks.
We've got a threat research arm here, so we're looking for threat researchers. Customer support is here. I mean, anyone who's interested in the cyber industry field in general, irrespective of your background, we have lots of opportunities. Okay, what are some skill sets that you are most interested in finding? Who do you want to make sure reaches out to you?
Yeah, so we may have touched on this last year, but it's not really changed. The joke around the office is if tomorrow Ebru didn't want to be a cybersecurity company, we could basically be any big data machine learning analysis company. So we're always looking for, you know, big data folks. And by big data, I mean really big data. We have, we have, you know, dozens of products.
And one component of one of our products, the file lookup— just the file lookup, not behavior analysis, any of that, just the file lookup— we do 5 billion lookups to the cloud a day. So we're doing billions upon billions of lookups and data capture and all that, so we need big data folks, big, big, big data folks with the ability to understand and analyze data. We look for machine learning folks, that is mainly out of San Diego, but here in Colorado for sure big data, we're looking for any type of really good C++, C# folks. People with C, C++ background that have moved to C# are super desirable because there's a lot of development that is done in that C, C++ level that people who just immediately learn C# maybe don't have the depth of knowledge that we look for. So, all right, well, let's— that's enough about Webroot.
Let's talk about what else you've been up to. I know we were talking before the show that you've been getting involved with some schools in the area. I'd love to hear what you're doing and why you're talking to schools. Well, and it's convenient, you know, we're on this month with you because I've been spending a lot of time going to— recently I was at a STEM program at Centaurus High School talking to their class. They were super interested in cybersecurity.
CU, a gentleman by the name of Daniel Massey, he's a professor out there. He's, he's really spearheading trying to get all the universities in Colorado to really work together. You know, he laid it out pretty well for me. I met with him recently. He laid it out where he's like, there's, there's something like 9,000 cybersecurity jobs in Colorado.
And he said all the major schools are graduating like 8,000 people a year. So there's enough pie to go around for everyone. And so we're all kind of talking, like programs like yours where all the industry is getting together, and as the universities start getting it— Regis has a really good program as well, that was my school— it's good to see, but we've got to get a little bit more congealed where we're— I know, and what I'm working for is when I'm out at a middle school or a high school speaking, I need to be very good about finishing the discussion with, hey, if you're interested in this, go here, or, you know, CU has a program, or Regis has a program. Like, I need to— we need to have something, I think, as an industry here in Colorado where we can drive the kids to that are interested in doing the— being involved in cybersecurity. And I think, you know, as we were talking about earlier, going from, hey, go to security, to giving some actual actionable steps.
Yes. And it's, it's so, you know, if I'm a high school kid and, and I've watched Mr. Robot a few times— it's a good show. It's a great show. It's super entertaining, but it doesn't tell you how to get into security, right?
That's exactly right. And, you know, very recently I happened to be in a conversation where a student was like, do I continue with my degree degree, or do I go off and do cybersecurity and don't get a degree? And I have to say, one, I recommend that you get a degree, and here's why. Some of the best people I know that are hackers don't have degrees, but they are so few and far between, and they've done things for like the government or built a product that somebody sold, that they have a reputation to go on. That degree helps you move forward.
What kind of degree though should you be looking into? When I'm talking to middle school or high school students, you can never go wrong with mathematics. Our lead machine learning scientist, his name's Maurice, he's a particle physicist. So, so the hard mathematics, hard science classes lend themselves well. Then if you couple that with an engineering background, you really are gonna fit into the cybersecurity industry.
Now, do you need to maybe have some chops on what type of malware there is? How do you reverse engineer it? How, you know, do you know what a decompiler or disassembler is? Probably, but you can catch up on that. That's the kind of stuff we can show you if you've got a strong science background, that's really what we're looking for.
Yeah, I like that, but I do want to also throw out there that there are less technical roles too, right? That, and it can be, we can easily alienate those people who aren't math folks, but there are a lot of things that we need to do in security that just take that softer touch, the program management stuff, GRC, the security training. There's lots of skill sets, and I actually— I think I told you earlier, I was actually trying to come up with a list of all the different fields. I came up with like 26 on my little list, and probably, you know, a good quarter of those are not technical in nature. Yeah, in my, in my typical hubris way, I literally did what you just said, and I focused on engineering.
And, you know, if I look around Broomfield, Yeah, we're outnumbered, you know, 3, 4 to 1. You've got to have folks— maybe you're a business major. You know, a year ago I spoke out at CU to a business class, and they're trying to figure out how to kind of integrate some cybersecurity knowledge in a business class. So, you know, there's, there's business points. Maybe you're— you want to be a project or a product manager, you know, and you have to bring your knowledge on how to bring products to market, that's critical.
I don't know how to bring a product to market. I know how to build stuff. I know how to— but I also know how to build stuff that nobody wants to buy. Like, we need people like who are good at managing products, who are good at meeting with, you know, customers, that are super social, want to get out there and understand the industry. I mean, it's massive.
Marketing folks, sales folks, finance— we have a massive finance department. It's just anything you need to run a business, and if you have any type of little focus on cybersecurity or interest in it and you get in that business, it's a good business to be in. One more thing, CU, when I was out there recently, as I said, talking to them, they're looking to make a minor in cybersecurity for business folks, for marketing folks. That doesn't go so deep into the ones and zeros, but more gives them that policy side of stuff, or maybe the risk assessment, or how do, how do we, you know, make sure if I'm in finance, we bought the right insurance to cover any liability we may have. Like, they're really trying to build programs that are more than just in the math and science departments.
Yeah, and another thing we haven't talked about is this whole privacy movement and It's not necessarily the same as security, but it's awfully close, right? You can be forgiven for confusing the two. And this drive towards security that's going to continue to change how we do business, that's not super technical in nature, but it's critically important and a good place for folks who are looking to get involved, can get involved early. GDPR is— the ink hasn't dried yet on that. The California Consumer Privacy whatever it is, CCPAs, it goes into effect in about a year.
All these things are gonna drive more and more needs for that. And like, you can be pretty non-technical and be effective there. Well, and I would almost say you could be more effective. You know, as technical folks, we want to lock everything down irrespective of cost. And sometimes you need those people to come in and say, look, there's a cost-benefit analysis we need to do here?
Because at some point it costs too much to do something over, you know, just acknowledging that's a risk. Yeah. And us technical folks, we're kind of binary. We're gonna solve all the problems. Exactly.
And so you're right. I mean, there's a lot of work in this industry around that. So what do you see, you know, personally, what's got you excited for the next year? And I surprised you with that question. Yeah, you did.
Um, It— so to be a little snarky, one of the big things is if people stop asking about machine learning and AI, because it's everywhere and it's in everything in terms of cybersecurity. But I don't, I don't know that it needs to be central to our discussion. It's a silly— it's a way to accomplish the goal, but it's— we've taken the place of the goal by using that. That's exactly right. Like, why— if your booth says machine learning, you're missing the point, right?
Like, I don't care how you accomplish the goal, just go do it. And machine learning could be part of it or it could not be part of it. I don't care. I could not agree with you more. As long as the product does what you want, you should be satisfied if it's giving you that protection, irrespective.
Now, I know for a lot of folks it gives them a warm and fuzzy that it uses the latest technology, and that's a great discussion, but Again, if— and that's the snarky answer— if we stop talking about that and just make sure, get back to, is this product doing what I need, that would be exciting. I think you— I think talking about machine learning on a second call might make sense. How do you do this? How do I know that in the future it's gonna continue doing this, right? So that's, that's where machine learning might get interesting, because if you tell me, hey, I can stop 99% of bad things, And I say, that's great, that's what I need.
And then why— I think to myself, well, a year from now the bad things are gonna be different. And if you just hardcoded what are the current bad things in, and a year from now you don't stop any of the bad things, right? Well, that's when machine learning might be an interesting topic of conversation. It just— I hate the fact that we lead with it so much. Yeah, from a— but blockchain is gonna solve the problem.
Yeah, blockchain has got everything solved. Blockchain in your product, you're on the record here. We do not use blockchain in our product. This is going to be the headline on the podcast. It is funny how you can put blockchain in the name of something and ask 8 people, you'll get 16 different answers on what it is.
They don't know. For me, the one thing we're really starting to focus on, 4 or 5 years ago, actually 4 years ago, we contextualized all of our threat intelligence. Where we linked IP addresses with files, with URLs, with mobile apps, and we could give you reputation scores based on that cross-linking. Well, now we're beginning to collect not data that we use publicly, but you're able— for MSPs, if you're an MSP, you're able to see what— we're working on this, it's not a product yet. We're working on the ability to say this user has been doing these things and has caused these threats to occur in your network because we offer a training solution and maybe you need to train them on this or maybe you need to go do some one-on-one explaining to them to quit going to malicious websites.
But we're trying to do that contextualization down at the user level and give users a risk score. We had talked about that a little bit so that once an organization starts using our suite of products, we're able to let that MSP know, hey, you know, this person, you probably don't need to worry about them. We're never seeing problems. This person, every other day they're doing something a little bit scary. You might want to do something there.
Yeah. Well, that's great. Final words. I know I'll do these for you. You should be backing up all your stuff and patching.
Is that— that's exactly— thank you. I get it right. Back up your data, folks. There is nothing you can't recover from if you have a backup. See, I listen.
You do, and I'm very glad. So Dave is regularly a guest on the CyberWire podcast, and this is a— this is one of the drums that he beats on that podcast as well. It's the number one security thing you can do for yourself. And Robb, I mean, let's be real, if we lost all those selfies of you and we didn't— we didn't have those to look at, the world would be a lesser place. It'd be a worse place to live.
Yes. Anything else though, now that I stole your thunder, anything else you want to say to close up the podcast? No, it's— I'm— yes. Yeah. Okay, good.
I'm really excited to see what's going on in Colorado around security, and it's good to see around the world, but we live here, and I'm really excited for us to keep moving forward as a community and really start working together more and more and more, mainly to help the kids. Who are interested in getting involved from that middle school and high school level, how we help guide them, because this provides really good opportunity for them in their life. Awesome. Yeah, that's awesome. We've come a long way, and we have a long way to go still.
Yep. But there's a lot of good stuff. Yeah, but honestly, shows like this, they, they really help, Robb, and that's not lost. And don't, don't forget that, that this really helps all of us have a platform to talk about these things. Well, thanks, Dave.
Appreciate your time. We'll look forward to catching up again sometime in the future, but hopefully we'll see you around in the meantime. Great, great being here. Have a good one. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.