All episodes

Jeff Finn, CEO of Zvelo

Apple Podcasts Spotify SoundCloud

In this episode:

Jeff Finn, CEO of Zvelo is our feature interview this week. News from: Xcel, CyberGRX, Carbon Black, CA, LogRhythm, Ping Identity, Apple, Zayo, Webroot, Red Canary, SendGrid, Coalfire, ThreatX, PasswordPing, WellTok and a lot more!

Denver loves their… soccer?

You all have strange Google searches; topped by soccer(?!) and a rapper I’ve never heard of. Xcel is going to be zero carbon by 2050. Security companies are all over the top 100 places to work in Colorado. Apple, the Big Four and Zayo are all growing their presences in town. Webroot is certfiable. Red Canary straights up the end point space. SendGrid makes steps in email security, Coalfire talks Kubernetes security, and Ping does the same for API security. Finally, several local security companies are SC Awards Finalists for 2019.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10784 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 96 for the week of December 17th. Alex, we are just about there.

We are just about there. And I think by there you mean our Christmas holiday. Our Christmas holiday. We at Colorado Equal Security are going to take a little bit of a break and not release a podcast through the end of the year so we can spend time with family and really not with you people. Yes, we're tired of all of you.

Goodbye. So get out. We'll see you next year. I think we're really just tired of 2018. We're ready to move on to next year.

We are looking forward Um, 2019 is, you know, it's going to be the best year yet. A banner year. Banner year. Banner year. We're ready for it.

And so we're going to recharge our batteries and get ready. Sounds great. Um, before we do that, why don't we go ahead and just have this episode since we're already here? Oh, hey, let's do that. Um, you know, and we do have some other announcements.

Uh, we have a Slack channel. So if you like talking with, uh, 700 of the greatest security professionals in the Colorado area, you should join that Slack channel and join the conversation. And one of the coolest things is, I don't know if you saw it yet, we have a new person who joined us just yesterday. Oh, who is the, the Attorney General Office's attorney responsible for cybersecurity, Daniel. And I'm sorry, Daniel, I don't remember your last name off the top of my head, but he's joined the channel.

So if you want to talk about cybercrimes or commit or confess to something, Slack is probably not the place to do it. Do we need to create a channel for that? Confessions? Confessions. True Confessions channel on Slack.

I like it. We also have a mailing list if you want to get the show notes delivered into your inbox every week. You can go out to colorado-security.com, sign up for that, and you'll start getting the mail— the show notes delivered to you each week. And we know you love listening, but the easiest way to do that is to subscribe so this just shows up in your favorite podcast player. And then when you do that, it would be great if you rated us to show everyone how great a podcast this is.

And if you do like us, I would love it if you would, uh, go out to our Patreon, give campaign, which is an opportunity for you to donate some money to support the show, help us pay for the, the hard costs of doing this. We would love it if you would go out there and consider any level of donation at all. And a huge thanks to those who are already donating each month. We appreciate it, keeps us going. And really, it's a big motivation factor for us.

And if you're not up for giving us a financial contribution, which is perfectly fine too, we'd appreciate you telling a friend, letting them know how great the podcast is and that they should listen too. Awesome. We appreciate all those folks who help support us. Let's jump into the news. First, we have a list of the top Google searches for Colorado, and they are strange.

They are a little strange. I'm, I'm actually a little shocked by this. So number 1, I guess not a huge surprise. Number 1 was the World Cup. So, you know, World Cup is a big global event that happened this past summer.

So I guess it's not horribly surprising that that would be up there at number 1. But number 2 is— and I can't see the name right now, but I remember that It was a rapper who I have never heard of. His name is Mac Miller. Is this someone you know? I know the name, but I don't know that I'm a fan.

So number 2, number 3, and number 5 are all related to celebrities who died this year. Number 3 was Anthony Bourdain. Number 5 was Kate Spade, who's a designer. Do you remember what number 4 on the list was? Number 4 was actually the, the sports one.

So that was actually the Colorado Avalanche. You know, of all of the sports teams in Colorado to search for on Google, I— the Avalanche would not have been my choice, but I guess everybody already knows how to find the Broncos and the Rockies and the Nuggets, and maybe they just were a little bit lost about where to find the Avalanche. Well, I guess I will say I'm proud of you guys that none of your top 5 things were, were dirty. So congratulations to all of you out there for, for doing fewer dirty searches, or at least not doing all the same dirty searches. So it didn't make the list.

That's right. Next, we have an article from Xcel Energy. They pledged to be carbon-free by 2050. So Robb, what does that mean? So I, I actually listened to a podcast this week where the president of the Colorado Xcel company talked about this pledge and what that means.

It's really neat. They're basically saying that they're going to make sure all of the energy that they produce by 2050 has a carbon-zero impact on the organization, on the environment. So it's not necessarily that there's no natural gas or coal that's a part of the mix at all, but that it's offset by things like carbon— what's the word for it— carbon return processes. One of my favorite things about hearing about this was that they actually went through what is the cost of each different type of energy that they produce at this point. So it costs about $0.04 per kilowatt hour for them to purchase natural gas energy.

It costs about $0.027 per kilowatt hour for them to do coal energy. But then they get into the renewable stuff Wind costs about 1.5 cents. That's for all of the new wind that they acquire at this point. Now, anything new that they get costs less, and the older stuff was actually up to about 4 cents per kilowatt-hour. Solar costs them somewhere between 2.5 and 3 cents per kilowatt-hour to purchase.

So if you think those are actually cheaper than we just mentioned for the non-renewable, she mentioned that there's a subsidy from the federal government that, that brings those costs down. But even without the subsidy, it's really quite competitive with with what they get for the non-renewable stuff. So she's, you know, she was expecting that, you know, over those next couple of decades, the technology is going to bring down the cost of solar and wind to make it so it doesn't make a lot of sense to go with something else. That is pretty cool. And I know, Robb, you know, you and I are doing our part.

We both have solar panels on our roof. So yeah, we're already there. Carbon neutral. Carbon neutral. I don't get nearly enough solar to be there.

But But we do our best, right? Next, there was a list put out by Built in Colorado of the 100 best places to work in Colorado. And we do have, of those 100, 6 of them are security companies here in town. Wow. Yeah.

Number 2 on the list, CyberGRX, the third-party risk management platform that's headquartered in downtown Denver. At number 7 was Webroot. Number 10 is Carbon Black. Now, they are not a Colorado company, but they are, they do have a large presence up in the Boulder area. Number 21 was CA Computer Associates.

I've, I have never heard anyone say they liked working for CA, so I, it makes me really wonder about this list. Uh, number 38 is LogRhythm, who is, uh, obviously the SIEM company up in Boulder, and glad to see those guys made the list. And then number 52, but number 1 in our hearts, Ping Identity. And if you're interested in working for one of these companies, Ping Identity has a couple of— Hey, wait, hold on. That's not this section of the podcast.

Don't jump ahead. Segue.

Next, we have a few companies that are really growing their footprint here in the area. Apple has announced that they're going to double the employee count that they have here in Colorado. From what we could tell in the article, there's somewhere between 100 and 250 employees here currently. They expect to at least double that. So that means we'll either— I mean, we could go from 100 to 200 or we could go from 250 to 500.

Yeah, no, good stuff. This is also on the heels of Apple announcing their big, you know, it's not quite as big as Amazon, but they're sort of HQ. It's not really another big campus in Austin, 5,000 workers down there, which Colorado did not bid to try and get because the jobs did not pay enough. So suck it, Austin, with your low-paying jobs. Suck it.

The next is talking about the Big Four and why they have big presence here in Denver. All 4 of those firms have increased their presence here over the last 5 years. Yeah, so, uh, KPMG saw an 89% increase between 2013 and 2017, EY an 80% increase, Deloitte a 57% increase, and PwC a 49% increase. Um, you know, in the article, it's not surprising as Colorado grows and there are more companies and more people here the need for the services that the Big Four provide grows. So they have more people.

And finally, Zayo Group has chosen to double the size of their Denver office. So they're actually moving into the old Chipotle office. We're glad that they left because we hate them. Anyone who leaves Colorado, we hate them. That's right.

You're dead. You're dead. You're dead to me now. And I'm a big Qdoba fan, apparently. The Zayo Group is moving into Chipotle's old office and they're going to have a, what, 60,000-square-foot office there that they'll be filling into.

So that's awesome. Yeah. And it's interesting because they're, you know, previous weeks we talked about Xeo getting ready to, you know, potentially split into multiple companies. So, you know, maybe they're also, you know, planning with different space for different companies. Who knows?

Yeah. Well, one other fact here, it does say that there's 400 people working in their current office, which is 30,000 square feet. So, you know, I don't know if we can expect to move from 400 people to 800, but obviously there's some room for growth for that organization. For sure. Next, Webroot had a press release this week announcing the fact that they have reached ISO 27001 certification.

Congrats to Gary Hayslip, the CISO there, and Tram, Mike Trammell, the deputy CISO who we know. I'm sure a lot of good work went into getting that certification. Yeah, it's not an easy thing to do. Good for those guys. We have a blog post this week from Red Canary.

This is actually by their CISO talking about evaluating endpoint products in a crowded, confusing market. So Number one, totally agree with that headline. It is a tough market now to dive into. Number two, they do a really good job, or Keith does a really good job of diving into exactly how do you analyze this market? How do you kind of sort through what technologies work for you?

Yeah, this, it's a really good article. Keith lays out a nice framework to think about different areas, questions you should ask. So if you are in the market for endpoint products, you should definitely take a look at this. I will say one thing that I wish they would do is I wish they would name names. Keith did not name names in the article, and I get it.

They're, you know, they're a provider of services that work with a number of different solutions. But if you're looking for, you know, this is the product to pick, this is not the article for you, right? You know, I'm sure if you, you know, happen to run into Keith at the bar and, you know, bought him a drink, you know, he might be able to give you a little bit of insight, but not in the article. Next, SendGrid had an article this week about their their press release for their first inbox protection rate. So, uh, this is a little bit different.

You know, SendGrid is not technically a security company, they're an email service provider, but they're, they're posting what their, uh, the security of the emails that they deliver are. And they delivered 99.97 legitimate emails across their outbound email flow. Now, so 99.99 99.97% of their emails that they delivered were legitimate. Is that what you're saying? Correct.

Yes. And you may think, oh, okay, well, you know, what does that really mean? Um, on Black Friday, SendGrid processed 2.8 billion emails, and on Cyber Monday, they also processed 2.9 billion emails. So, um, even a small percentage of those emails being malicious going to people it could turn out to be a lot of emails. Yeah.

Um, so good on them for, for really thinking about, uh, securing the emails that they send out, not just passing along whatever comes through to them. Yeah, it's awesome. This is, this is the first time I've seen them release this kind of a report, and it's great that, you know, as a company that's, that really doesn't sell their service based on security, that they're starting to think about security and be more, you know, speak in that language more. So that's great. Scott Gerlach is the CISO over there.

We know him and appreciate the job Scott's doing and all the, all the team over there. Next, Coalfire has an article this week talking about the big Kubernetes vulnerability that came out. I think it was about a week and a half ago that that vulnerability came out. Yeah. And it's actually become more important over time.

Initially, it was a vulnerability that required authentication, and now there's an unauthenticated version of the vulnerability. Basically, it allows you to hop between containers, you know, with different with different, uh, security between the two. So really a challenge is something that needs to get fixed. Uh, Coalfire kind of lays out the map for how do you, um, how do you address this? How do you look in your environment to see whether you're vulnerable and what do you do if you are?

Yeah. And it's, uh, not just looking at, um, you know, it does look at it, but not just the part that, you know, upgrade, you know, part of this was, you know, it started out with older versions of Kubernetes. Um, but, you know, thinking about how to look at the risk of, uh, different containers you have and other things like that. Uh, next, uh, Ping had a blog this week about how to be proactive about your API security. So Robb, how do we be proactive about our API security?

Yeah, I mean, the first question is, do you know what APIs you've got exposed? And as much as, you know, obviously this is, you know, the critical controls list number one, know your inventory. Um, I think most companies, most security departments don't do a great job of understanding what their API infrastructure looks like. It's often something that's managed more by developers than by IT people, and maybe we don't have the same relationships there. So number one is knowing what they are.

And, you know, there are tools out there, including something that PingSells, that'll do a scan and look for your APIs, find what that footprint looks like, and then you have the ability to start looking at what normal behavior looks like. Your firewall probably doesn't have a great signature to say what does normal behavior for your API look like. You need something that's more specific to APIs to help figure that out. I also think when, you know, people think of APIs and API security, they think of the technical components, right? You know, I'm going to make sure that it's, you know, authenticated and encrypted and, you know, all that sort of stuff.

A lot of this article talks about the actual governance process around it, the non-technical means, right? Asking questions, you know, do I need this API? What should this API do? Who, you know, who should it talk to? Not necessarily, you know, the technical means of securing them.

Yeah, good stuff. Thanks. Thanks to the Ping It Block author for that. Moving on, we have the SC Awards. SC Magazine has done their, their Trust Awards for the year, which really kind of go through different products, different companies, and talk about who's, you know, who's delivering good stuff.

And a bunch of Colorado companies made the list this year. Yeah. Webroot, I think— are these finalists or these winners? Finalists, right? Webroot was finalist for Best SME Security Solution.

PasswordPing made the list for Rookie Security Company of the Year. Ping Identity for Best Identity Management Solution. LogRhythm for the Best SIEM Solution. ThreatX for Best Web App Solution. And finally, WellTalk, which is not a security vendor provider, they are an enterprise, they made the list for Best Security Team.

So that's Travis Shaxx. Yeah, awesome. He runs security over there. They made They made a finalist for the work they do internal security with WellTalk. Congrats, Travis, for being a finalist.

That's awesome. I think it's in March, early March, we're going to find out the winners. So, you know, hopefully we get a couple winners off this. I think they usually do these at RSA, if I remember right. I bet it is.

Yeah. They release the winners. That makes sense. Yeah. Okay.

That would be early March. Yeah. Well, congrats to those. And let's go ahead and move on to the Slack message of the week. Thanks to Andre Gaeta, who's been a loyal sponsor for us.

Over a year now, um, doing the— doing these fun things. Um, whoever wins Slack Message of the Week gets to have something for free from the Colorado Equal Security store. Yeah, and this week our winner is Ben Ryder. Congratulations, Ben. Uh, Ben posted an article on Friday about the Bitcoin ransom, uh, bomb threats that had been going around.

This was something that, you know, basically struck, um, not just the US. I mean, I think the whole world. A number of these were sent on Friday, including to Columbine High School. Resulted in a lockdown of a bunch of schools in Colorado, but it was— I heard stories from all over the country. So yeah, and basically what the email said is, hey, we have a bomb in your building.

There's someone there watching. If they start to see things get weird, he's gonna set the bomb off. Yep. In order to stop this from happening, give us $30,000 in Bitcoin. Sent to this address, right?

It's kind of a play on the sextortion scams that were going around for quite a while previously. From everything I've heard, there's been no payments on this. You know, you can monitor the wallets to see if anyone's paid. I was listening to CyberWire today, and I think that they said there have been $2 in Bitcoin that got sent to the addresses in there. From that same thing, you know, it made a good point that, you know, even if you send a note like this to a school and say, you have to do this by the end of today, and you have to pay us $30,000 in Bitcoin, They probably can't.

Like, right. There's no way that that's gonna happen. They might actually wholeheartedly want to give you $30,000 in Bitcoin, but have no idea how to do it. And they probably cannot, you know, they can't give you $30,000 in one day. Yeah.

The, the sad part though is for many of the places that received this, they have no choice except to follow their normal bomb threat protocol. Right. So even though you look at this and you're like, yeah, yep, 99% sure this isn't fake, they're gonna have to go through the motions of, of lockdown the school, locking down, sweeping for, for explosives, all that kind of stuff. It's very expensive. It's very expensive, so not a good thing.

Yeah, well anyway, congrats to Ben Ryder for winning the award here, and we'll get you a note on how to collect your prize. So let's move over to events. As we are getting to the holiday break, you can imagine we are getting a little bit short on the events that we have coming up, so only a couple here. As a reminder, we do have an event calendar on the website, colorado-security.com. You'll see there's only a couple things left through December, but we are pretty well populated going into January right now.

So first on the list, on the 17th, SecureSet is doing their Denver War Games Capture the Flag. And on the 19th, the Denver CitySec meeting is having their last of the year. It's going to be at the Wynkoop. They've just confirmed that location, so you can go join and drink a beer with some security folks before you take off on your holidays. Very nice.

Moving over to jobs, we have a good sampling of jobs this week. At Ping Identity, we are hiring a GRC analyst. This will be someone to help support our compliance with like SOC 2 and ISO, our vendor risk management program, business continuity, those different kind of functions. We're looking for someone with, you know, really maybe more junior level, either right out of school or maybe a year or so of experience to help work with our more senior analysts doing that. And oh, we also have one other position at Ping that we have a senior software engineer looking for someone who's got some in-depth Java development experience, helping build some of the most fun security identity products in the industry.

Very nice. Next, uh, CoBank is looking for a security manager in the Secure SDLC. So we talked about this last week, I believe, 2 weeks ago, 2 weeks ago. Um, and Robb mentioned at the time that this probably reported to Stanton Meyer over there at CoBank, and we got some feedback from him that, that this is, uh, a, an application security-ish focused, uh, looking for someone who can help them not only do internal security SDLC, but also do assessments of SaaS products that they use. Really, you know, work as kind of the AppSec guru across the department.

Good stuff. Spectrum is hiring a supervisor of network security operations. So it looks like probably if you want to be heading a team in a SOC, there's an opportunity there at Spectrum. Nice. American Medical Response is looking for a cybersecurity architect.

Great West Financial is hiring a senior security engineer. Direct Defense is looking for a senior security analyst. The US Army is looking to hire a cyber network defender. Alex, what in the world? Yeah, and I put this one in here.

I thought it was very interesting. This is actually an enlisted position. So if you want to get this job, you're going to have to enlist into the Army. But I thought, hey, you know, this might be interested— interesting for people that have kids, or someone that is maybe just getting out of school. That looked like there are a number of positions around this.

And if you're interested in going into the Army and you're interested in cybersecurity, it could be a good thing. So you have to be good at security and you have to be able to do push-ups. Yes. Or they'll get you there. Maybe.

I don't know. Maybe we'll see. Yeah, that's pretty interesting. Vail Resorts is hiring a network security engineer. Journey is looking for a senior security architect.

I mean, you know, We have a lot of puns here. Yes, we're, you know, it's, it's more than a feeling that— Yeah, you have to serve them faithfully to get this job. They will, they will welcome you with open arms. Good stuff. All right, finally, AWS, Amazon Web Services, is hiring a security engineer here in Denver.

So if you want to be part of taking over all of the rest of the jobs, you can go over to Amazon before it's too late. You know, it's probably a good idea to get in there early. Um, that way, you know, you will not be voted off the earth. I don't know. It's— yeah, you're one of the Borg early rather than late.

Right. Uh, I think that's it for the news this week. Uh, moving forward, we have a feature interview. Alex, you sat down with the president or CEO of Zillow. Zillow.

Zillow. Um, Jeff Finn. Yeah. And, uh, you know, high level, how'd that go? It was good.

We had a great conversation. Um, Many people probably do not know the name, but they are a web categorization company. So, you know, for doing web filtering, you have to have categories to do that filtering with. Since they don't hire or sell directly to consumers, you probably don't know the name, but it was an interesting conversation. Awesome.

We're looking forward to hearing about that and looking forward to talking to you guys again in January. Thanks, Robb. All right. Happy holidays. Hello, this is Jeremy Cooper-Levitt, managing director of Insurance at Charles Schwab.

This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Alex Wood, and I am here with a special interview guest today, Jeff Finn, CEO of zvelo. Hopefully I pronounced that right, Jeff. Yeah, zvelo. Yeah, zvelo.

All right, I'll try to remember to, to do it better for the rest of the interview. Thanks again, and appreciate you taking a little time today to talk with us. And thanks for your time as well. Yeah, I think, as you know, you were saying earlier that you've listened to some of the episodes. We like to get into the background of you and not just zvelo.

So I wonder if maybe we can start by you just giving a background on yourself, how it is that you came to be CEO here and what your path has been. Sure. So I've been at zvelo about 20 years.

Prior to that, I've been in tech since during college. So worked for IBM for a short while, worked with a company called Applied Communications in Omaha for a short while. We did banking software. Did a number of startups in the tech field, one of which took me to London for a couple years, lived and worked over there with cable wireless. Subsidiary, moved back here, helped take a company here in Denver public, and then came over to— at the time it was called eSoft.

We changed the name to zvelo in 2010, but joined the company 20 years ago. Nice. You guys are in the security space. I sort of like to think of it around URL categorization and things like that. Had you always been in security or had you been in other areas of technology prior to coming here?

I'd been in other areas of technology prior to coming here. In sort of the late '90s, at that point in time, we were building at ESOFTE at zvelo, we were building an all-in-one security router. So that was really my first exposure to what I'd call pure security from a vendor standpoint. We were putting together a product that we'd sell into small and medium-sized businesses that had firewall, IPS, IDS, antivirus, web filtering, spam filtering, a number of other functions all into a single box, selling it through the channel. They would then take and install that at small and medium businesses, and we made our money on the subscriptions to the services.

So we actually had built up a pretty nice business, but that's a really cutthroat business, highly dependent on the channel. Channel is really tough, and there were a number of companies that had much better funding, much deeper pockets, you know, the Ciscos of the world and so forth. Yeah, I remember some of those Cisco multifunction devices that they had back in the day. Exactly, exactly. So there were a number of companies out there.

And it was in about the 2005 timeframe where we started having some customers saying, look, we are running into some issues with your web filtering. They didn't realize we were basically licensing web filtering from companies at the time like Secure Computing, WebSense, and others, tucking under our covers, and then licensing that out to the marketplace. The problems that they were explaining to us that they were having, one was that there were more and more websites that were coming online that were what today we'd call social media sites, blog sites, where you had really diverse content across the website at the subdomain, at the page, at the full path level. Prior to that point in time, and really to a great extent prior to today, virtually every other vendor in the web categorization business is categorizing content at the domain level. So Jeff.com might be categorized as sports, but you might have all these pages within Jeff.com that have all sorts of diverse content.

We— when we started hearing about this, there were websites like MySpace.com and similar sites where somebody might have a particular page under MySpace.com that might be talking about travel, and within that same domain but on a different page or subdomain, they might be posting pornography. And companies were faced with the choice of either blocking the entire myspace.com because some of it contained porn or allowing everybody to access it within an organization knowing that some people might find some of those corner areas of MySpace or whatever the website was that had pornography on it. So one of the first things that we were hearing was, can you solve the problem of trying to categorize content at the page level? Deeper within websites. The second thing where we were starting to hear, this is again in the 2005-2006 timeframe, was people were starting to see more and more web-based malware attacks.

Early days of phishing attacks and things like that. Companies and vendors have become very proficient at blocking email protocol-based malware exploits through antivirus, through spam filtering, and so forth. But at that point in time, really nobody was really focused on what was happening online with websites. And again, those same very websites people wanted to have categorized at the page level were places where hackers were starting to put their exploits deep within those websites, then using social engineering to trick people into going to those particular pages where they were getting their payloads or where they were getting infected. So we in the 2005 timeframe saw an opportunity to try and build a better mousetrap, which was trying to do page-level content categorization and do malicious website detection.

And we spent several years working on that. Took about 3 years to develop the technology. We released our first offering in 2008. Started seeing immediate demand in the marketplace for people interested in taking our technology, integrating into their web filtering, their parental controls and so forth, so much to the point that we ended up spinning off what had been our core product at that point in time, this little UTM box that we'd been selling. So by 2010, we were at a point where we'd made a decision that we were going to focus 100% of our energies on categorizing the web, which to us meant categorizing the content and doing malicious website detection.

Protection. We changed the rebrand of the company as zvelo at that point in time, and that's what we've been doing since then. So when you came over to ESOF originally, did you come in as CEO, or were you— did you come in as a different position? No, I came in as CEO at that point in time. Yeah.

And then moving forward a little bit, you did this spin-off of your original sort of flagship product. Where did that end up going? That was acquired by firm out of Boulder who took that product line and ran with it for a couple years. Nice.

So then 2010 you guys rebrand. Where did the name come from? Good question. So coming up with a company name is a little bit like coming up with a name for a rock band. So you start eliminating all the good names already taken.

We— look for open domain names. Look for open domains, what ranks well, what has some sort of unique capabilities to it. We couldn't find any acronyms that made sense. So we started playing around with the concept of Velo, the bike, the circular, the feedback, the constant movement because one of the things that we were interested in and felt we were doing unique in the marketplace was taking a very proactive approach to categorizing the web. We weren't— it wasn't static to us.

The web was ever-changing, constantly evolving, very dynamic. So we wanted something that sort of reflected a very dynamic, very proactive name.

And to make it unique, we threw a Z on the front. So it was as simple as that. Opposite of the you know, the plumbing and the towing people that, you know, throw 3, 4, 5, 8 plumbing, right, on the front of it. Uh, you know, you put the Z on it to get you guys exactly the, the, at the end of the alphabet and the, the, the tongue recognition, right? Uh, that's cool.

So, uh, so it sounds like it's been a little bit of a unique journey and that it's the, the process is just sort of, uh, seems like sort of come to you guys, right? So it's, hey, we're doing something and people are asking us for something slightly different, you know, what are the things that you guys feel like you've done, and I think you mentioned a couple of them, that sort of make you unique? Because there's other people that do similar things in this space too, right? Yeah, there's a— when we started, there were, I'll call it, 3 800-pound gorillas and then 2 or 3 companies that were sort of the next tier down as far as suppliers in the marketplace. During the timeframe that we were actually building our product, 800-pound gorilla number 1 bought 800-pound gorilla number 3, they merged those companies.

800-pound gorilla number 2 was acquired by McAfee, who was then turned around and acquired by Intel. And so by the time we got around to actually launching our product, the market landscape had changed pretty dramatically. The couple companies that we thought were going to be our primary competitors ended up basically exiting the marketplace. Place through being acquired and losing focus, which allowed us to get a couple of anchor accounts very early on, which helped us to continue to reinvest in bringing on more engineers, getting the expertise we needed to really build this technology out.

When we made the decision in the '05-'06 timeframe, this is what we want to do. We want to Today the terminology is pivot the company. Well, we weren't smart enough to call it pivoting the company. We're going to change what we're doing. And we realized that we really didn't have the expertise we needed to be effective at categorizing the web or doing malicious website detection.

So a lot of it was lessons we learned one at a time. And over the course of several years, we realized, okay, here's what works and what doesn't work for doing content categorization. We had to become proficient in things like NLP. We had to sort of go from a blue-collar AI machine learning approach to categorizing the web to more and more advanced, more sophisticated. It meant hiring different types of scientists, different types of AI engineers, AI folks.

And all that just took time to figure out what worked, what didn't work. Same thing on malicious websites. Protection, figuring out what worked from doing static analysis, behavioral analysis, what sandbox worked, which sandboxes didn't work, which did we have to build ourselves, what feeds we could use that we could trust, which feeds don't, you know, aren't trustworthy. We're fortunate to work with a number of the leading antivirus vendors who incorporate our products, so we have sharing relationships for signatures and viruses and so forth. So all that helped contribute to us building a knowledge base on how to detect malicious sites.

And over the last couple years, that's really translated largely into how to detect phishing sites and malware distribution sites, as opposed to strictly, you know, is a site hosting a specific exploit of some type. Yeah. Yes, you mentioned having to to pivot the personnel based on the company pivot. What is the size of the company today? And are most of the people here in Colorado?

So we're a private company. We've been private since 2002. We have the company split about half here in Colorado and half in the Philippines. So what we do in the Philippines is we have our web analysts over there who create the training and the testing datasets, what we call the corpora that we use for our AI engines. So AI and machine learning algorithms are very intensive on getting data to be used for training, what they're getting right, what they're getting wrong.

And we've been in the Philippines now for over 10 years. We found it to be a very good place for finding folks that are excellent at doing the human tagging of content that we use to train our AI systems and algorithms. Nice.

The whole thing to me seems like a really big problem though, or a big undertaking. I don't know, problem is not the right word. You're essentially categorizing the entire internet, right? I mean, that's functionally what you're doing. I mean, how is it that you go about tackling such a large sort of problem?

Well, we're now— we just went live with our 3rd generation of categorization systems earlier this year. So if you roll the clock back 10 years ago and we're thinking, okay, we want to categorize the web. What can there be? There can only be a billion or so pages. So if we line up enough Filipinos, we thought we might take a crack at it.

Well, that ends up being something you obviously— I'm kind of joking. You can't scale this with humans. There aren't enough humans to categorize all the websites that are coming online every day, all the pages that are coming online. And the amount of data, the amount of content that is going live on the web every day, when you start looking at video and all the different social media pages and individual posts and blog posts and so forth or podcasts, whatever. There's no way you can scale this up using humans.

Machines are good at doing certain things over and over, whether that machine is an AI, machine learning, whatever terminology people want to use for it. They're good at doing certain things if you train them to do what you want them to do. So what we've had to become good at, better at over the last decade is how do we get humans involved in this circular loop, this feedback loop where we can use AI engineers to build an algorithm.

We use the folks we have in the Philippines to basically tag data that we use for human-supervised training of those algorithms. We process content, we look at the output, we randomly sample the output. We then use that sampled output and those verdicts that humans are looking at to further train our engine. So to put it in perspective, we have right now about 90 partners. We're strictly a 100% OEM company, so everything we do is through OEM partnerships.

Those OEM partners represent about 650 million end users who are using our product for various forms of web filtering, parental controls, DNS filtering, reputation filtering, and so forth. So we are seeing queries from that active user base on a 24-hour-a-day basis. So we're seeing traffic coming in, what we have categorized, what we don't have categorized. That is the source of the traffic. So think of it as a very large crowdsourced engine where we're getting all this data, all these URLs that need to be categorized.

So any given day, we are processing 5, 10, 20 million URLs on a given day, putting those back in our database, propagating those back out. And then as people go to new websites, new blog posts, new podcasts, new social media sites, whatever it might be, those are the source of the content we're categorizing tomorrow. So that is interesting, and I wouldn't have— sort of to my naive mind, it's you have some giant farm of servers, whether that's cloud or whatever, somewhere that's just constantly going around and looking at everywhere on the internet. But it sounds like you have a different approach where it's the places where your software essentially is being used is the place that also is doing the categorization. Is that correct?

Yeah, absolutely. Good point. So what we found early on was trying to crawl the web and guess what websites people are using didn't prove to be very effective. It didn't give us very good coverage. So what we ended up going to is what we call an active web approach, where we let our partners' users tell us what websites they're trying to get to.

That also means we need to be not just very good in terms of accuracy and coverage, we need to be very, very fast in how soon we can— how quickly we can categorize a new website. So on any given day, we have these hundreds of millions of users. Their web surfing is what drives us to go categorize the URLs they're looking at in pretty much real time. So we can categorize most websites in a matter of 1, 2, 3, 4, 5 seconds, put it back in our database. So all of our users therefore get the benefit of all the categorizations of all the traffic and all the surfing of our collective Borg, if you will, of all of our partners and users.

Yeah. So is that the approach that you've had all along? Because at some point it's a chicken and the egg problem, right? So you don't have any users, but you need the users to be able to tell you where to look to categorize things. Did you start out with a different approach?

Well, we did a little bit of crawling, taking things like the most popular million sites, 2 million sites, getting those categorized, making sure we had coverage for those. As I mentioned, we were fortunate, lucky if you will, to be able to land a couple of large anchor accounts early on that were able to work with us and help nurture us and make sure we had sufficient coverage in the markets where they were active. Now our initial plan was we want to be really good with, call it, 50 categories in our taxonomy and we want to be good at English. And we thought, okay, that will last for a while. Well, that lasted about 2 weeks and our second customer said, you know, we are active in Russia and Germany and we need 100 categories.

And our Our next customer said, well, we're in France and Japan. And so within a year, it was clear we were going to have to find a way to support basically all the languages across the world, and we were going to have to develop a very, very granular taxonomy. So now we do support for over 200 languages, and we have support for 500 categories. So within that 500 categories, you have a dozen or more malicious categories. You have about 30 suspicious, I'll call it gray category, anonymizers, Tor sites, and so forth.

And then you have over 400 topical categories, arts, alcohol, business chat, dating, all the way up to weapons and wiki at the end of the alphabet. Wow. So say I'm using a product that licenses your categorization. I go to a site that you guys haven't categorized yet, comes back to you, you guys go off and categorize it. How long does that take you guys?

You said you're fast, but how long does that take you from when essentially you find out something new to when you have a verdict on what that category should be? Good question. With our prior generation product, it would take us anywhere from 30 to 40 seconds, maybe a minute or so, because we have to go through both the content categorization looking at the content. In parallel, we're running it through our malicious detection systems to see, is that particular page clean? Is it malicious?

Is it compromised, used for phishing?

So that process in our prior generation systems would take, again, 30 seconds, 60 seconds. That wasn't fast enough. So we spent about 3 years developing a new technology we just brought online earlier this year. So those processes are now down into the second, sub-second, a few seconds at most. So people in a lot of cases can leave the connection, leave the session open while we're categorizing the content, and they can use it then to either block or allow access to whatever requested URL that their user is trying to get to.

And then do you guys have infrastructure, I'll say, sort of all over the place to handle sort of localization? And you don't want to be— if you're trying to get something done in a second, you don't want to be reaching out from the US to someplace in Sri Lanka to try and do the categorization. Right. So our partners, we have a global load-balanced, fault-tolerant, highly available network. So if people are using our cloud services, they go to the nearest available cloud.

So the folks in Asia will go to China, Japan, so forth. Folks in Europe will go to the cloud locations close to them. Many of our partners, however, can't even afford the latency involved in a cloud lookup, so they will create and take data feeds and mirror our data locally in their data centers or at their end users' data centers, particularly when you get into high-volume, massive query volume types of applications where people are doing billions or tens of billions of queries a day or they need millions of queries per second, they can't do cloud lookup. So we've created a process where they can actually store, mirror our data locally and then get data feeds to continuously update that local data cache. So likely someone that is also maybe running a cloud service on their end and they have their own local sub-cloud of your cloud.

To do that on their premise. Exactly. That's pretty cool. One of the other things that struck me earlier is when you guys made your pivot, you went from being a consumer direct or business direct kind of company to a reseller just to other companies that are providing services.

How was that transition and what kind of changes did you guys have to make? Make? You know, obviously, there's a technology piece for the product, right? But what sort of changes did you guys have to make going from sort of a— it seemed like a direct sales, you know, model in my mind, and to then being a, you know, a business-to-business, you know, service provider to other service providers? Yeah, no, another good question.

So you're right, on the technology side, we went through a series of changes from We started with VMware platforms to sort of enhance VMware platforms. So most recently we went to a SOA architecture platform. We run microservices, AI-based microservices on that. Been fortunate in that a number of our engineers were able to make that transition and develop the skills over the last decade to, to help with what we needed to do. We've complemented that by bringing in AI, data science, and so forth to help where needed.

The biggest change for us was really on the sales and marketing. So when we were selling a hardware appliance, we were channel-based. You'd go through the distributors, you'd go through resellers, and that took a completely different type of organization, a channel sales organization that almost any company in that space is going to be familiar with, where you have folks calling on distributors, you're trying to work on the pull, you're trying to work on the push, creation, you know, have folks who are doing the hand-holding with the resellers and so forth. That is a really expensive business model for companies to try and maintain. In an OEM market like what we've been in now for the last decade, it is all basically organic demand that we're creating.

We do virtually no sales and marketing, outbound sales and marketing. And fortunately, through word of mouth, we have a lot of our folks either find us by doing a simple Google search when they identify and say, we need a really highly accurate content categorization, web categorization, malicious detection. They're able to find us. Or word of mouth, somebody leaves Company A, they go to Company B and say, hey, we used to work with zvelo, loved them, fantastic responsiveness, great product, they do what they say they're going to do. And that's the way we've grown our business.

Yeah, it's pretty amazing how even, you know, even as a company of your size now that, you know, you can sort of survive without any sales and marketing. It's— I don't want to say it's funny. It's interesting, right? It's a great business model to be in, right? You don't have to worry about supporting that whole sales and marketing monster anymore.

Yeah, it's different. I mean, there's, you know, in this case, in the product we sell, the markets we serve, the partners we work with, they really— we're selling to a highly technical, very sophisticated buyer. They're not going to believe anything they read on our website or what a sales rep tells them. They're like, okay, when do you want to talk to just let us get our hands on the product, let us evaluate it. They'll go through the evaluation to determine, okay, what's the accuracy, what's the coverage, how fast you guys categorize, what's the speed of lookups, what's your language support.

They'll make all the determinations on their own. And so our product absolutely has to stand up. And so right now there's really only 2 or 3 companies in the market doing what we're doing, and fortunately we're at a point where we believe, both anecdotally and in the testing that we do, that we are superior on basically all the evaluation criteria that people are looking at these days. So if you're not, you never hear back from them. They'll do the evaluation and quite frankly, they won't call you back.

They won't even return a phone call if the product doesn't pass muster. Well, you know, that's technical people for you, right? Yeah. You said that you did this, you don't do this. Okay, I'm not talking to you anymore.

See you later. Unfortunately, we go to great lengths and this is all we do. This is 100% of our focus. You said earlier this year you released this new platform. You've got your detection times way down.

What does the future look like for you guys? Now that you've got this new platform, are you going to platform X plus 1? Are you looking at new areas? What's the future look like for zvelo? So we've— what we believe we built is really great categorization and detection engine, highly scalable, able to process massive amounts of data, deliver massive amounts of data.

So within our, what we call our core business, the categorizing the web business, we're definitely seeing very strong demand for continuous continuing to improve and enhance phishing detection. That is across the board with virtually everybody we're talking to wants better phishing. We've seen, I'll call them sort of more nichey kind of requirements. For example, earlier this year we started seeing an increase in cryptocurrency mining exploits. People wanted the ability to say, okay, can you help us detect whether or not our site's been infected, we're being used for people Bitcoin mining in the background or something.

So we'll continue to spend time improving the products we have around the web categorization. But since many of our customers are in network security where they're putting routers, UTMs, firewalls, gateways into enterprises, small business, consumers, residential, and so forth. One of the increasing things that people are starting to pay attention to is around IoT and connected device security. Starting about 2 years ago, we began working on how to use our detection capabilities and our categorization capabilities and say, hey, look, rather than categorizing a website, can we categorize a device? Can we then look at that device and tell you whether or not it's acting normally or abnormally?

So we introduced an IoT security product offering last year that provides the ability to do device profiling, device detection, device profiling, and then anomaly detection. And we can tell you whether or not the Nest thermostat is operating within the expected range of behaviors or whether or not it's now operating abnormally or it's been hacked, compromised, and potentially being used for DDoS attacks or whatever it might be. That is really interesting. I want to dig into that a little bit. So how exactly does that work then?

So theoretically, my Nest thermometer is not going to be available and accessible on the internet. Right. Not to say that that's 100% true for all Nest thermometers. So how is it that you get get access to look at those devices and do the proper polling and testing and whatever you might need to do on a device like that? So the approach we took is to deploy a piece of code onto the local router.

So it can run on any type of generally available router. It can run on a gateway. We can even build it on a Raspberry Pi for the folks who are interested. The device is then installed in a place in the network, obviously, where it's seeing all the network traffic to and from the internet. So as it gets— as that router running our code gets installed in a network, it starts looking at and detecting all the different traffic coming from devices in that local network.

And it can say, okay, here's device 1, 2, 3, 4, 5, and it starts cataloging those devices, sends the data up to our cloud where we can look at it and say, okay, here's the MAC address, here's the IP, here's the other information, and we can say that looks like a Nest thermostat. Oh, it looks like a Nest thermostat model 10. It looks like a Nest thermostat model 10 with this version of whatever else. And so we found that we can be very accurate at detecting all these devices on the network. Surprisingly to me anyway, what we found is many of our partners are saying they're sysadmins, that to them is a big win, just being able to identify what devices are on the network.

So knowing they can narrow it down from just iPhones to Jeff's iPhone or Jeff's Mac is a very important thing for them to have. So that to me was sort of a given with our offering, but that turns out to be something that is of interest to people. What we do though is once we're on that network, we're monitoring the traffic. And some devices are more verbose than others. A Nest thermostat, for example, isn't going to have a lot of connections, communications out to the internet.

A streaming video camera is going to have a tremendous amount of data that it's sending back and forth to the internet. So we can, in some cases very quickly, within a matter of minutes, other cases might take a few days, develop a profile and say that device is doing what it should be doing, it's going to the right kind of websites since our core business is telling you whether a website is a Nest thermostat-associated website, it's a compromised website, it's a malware distribution website, it's a phishing website, whatever it might be, a C2 website. So we were able to use that data and leverage it to say that Nest thermostat is compromised or suspicious, this video camera is doing what it's supposed to be doing. And we provide trust scores and we provide that to a partner, then can say, look, We're not setting the policies or implementing the policies. We'll let our partner do that within their application layer and give the sysadmin the tools as far as where they want to set blocking, filtering, segment, or segregate that device from the network.

Is this— obviously it's through the partners, but is this a service that you see them offering to businesses or to consumers? And if both, what sort of split split, if you know that. Yeah, so right now I think the biggest challenge with IoT security is just general market awareness or concern. So it's not unlike where I think the market was at in the late '90s as it related to just viruses in general. It took a couple of— a series of headline-grabbing incidents where people realized, oh man, maybe I better get some endpoint and perimeter security and do something about these viruses.

Right now, most of the devices, many of the devices are being installed in the homes. It surprises us, it surprises the people who are installing these devices in their homes how many web-connected devices are in their homes when they start adding up light bulbs, thermostats, laptops, Fitbits, wearables, you name it. And we're seeing 30, 40, 50, 60 devices in just an average little household that are connected the web. One of the challenges though is people say, well, how can this cute cuddly little device that I just plugged in and I didn't have to do anything to it and it just started working for me, that can't be a threat. We're like, well, it may not be a threat to you, but it might be being used as a threat against some other company over here on a DDoS attack or something.

It's almost like a victimless crime where the people who own the product aren't aware that it even has potential for doing sort of mischief. Even if they're aware, they don't know what to do about it. Even if they knew what to do about it, most of these IoT devices are designed in a way that they can't run an endpoint security client. So they're like, well, you want me to take this, throw these devices away, go to Home Depot and go install some more light bulbs that are going to get immediately infected 2 minutes later? So the consumer market, I think people are trying— struggling with how to monetize IoT security at this point in time.

The people that are probably closest to it are the cable companies, some of the telcos, broadband providers, ISPs, who are probably gonna sell it as like a managed service. Say, hey, for an extra $10 a month, we will manage and alert you to any sort of IoT or any web-connected threats that are in your home. Industrial is a little bit different story. There's awareness there. They're spending a lot of money on these connected devices, and they, unlike a thermostat, which is sort of a throwaway if it breaks or isn't working, you can't very well throw away a heart monitor or a dialysis machine or some of the industrial controls that are being put into factories and so forth.

That's where we're seeing probably an earlier market adoption of profiling and security around those types of devices.

It occurred to me as you were saying that, most likely, even if someone who is listening to this podcast thinks, wow, it sounds like zvelo is doing really, really cool stuff, they're one, not going to know if any of the products that they use actually use your technology. And they may not even know how to figure out if they do. Is there a way that someone could figure out if, you know, I use XYZ device at my office or at my home or whatever is using your technology on the backend? You know, you guys have a partner list or something like that that people can look at? Or do you even care?

You know, yeah, we care. So this is, you know, it's actually a very Very insightful question, comment. We talked before about one of the benefits of our sales and marketing model in that you don't really need a big sales channel to do what we're doing. Right. One of the downsides is in many cases we're the secret sauce that gets tucked inside our partners' products.

And it's sort of under penalty of death will you disclose that we are using zvelo. So we, In many cases, we can't disclose who's using us. We certainly work with our partners to create content, whether it's blogs, white papers, help them with videos and so forth to help promote the concepts and capabilities that we offer. Unfortunately, that's one part of the puzzle we haven't cracked yet. Gotcha.

I guess people will have to do some digging on their own and see if they can figure it out. Well, we're getting close to time here. This has been a great interview. Was there anything that you wanted to talk about that we haven't hit yet? No, I think this is great.

I appreciate what you guys are doing with your podcast. We were talking offline before we started here. I think what you guys have done is great. There's really— I haven't found any other place that sort of is an aggregator of all the news, commentary on the local cybersecurity seen in the, in the metro Denver area. So, you know, great job for you guys putting this together.

Awesome. Well, thank you, Jeff. I appreciate the compliment. We'll try and keep it up. And we appreciate your time too.

This has been great. I've learned a lot about you and what you guys do. So thank you for your time. And this has been Colorado Equals Security. We will talk to you next time.

Learn more about the Colorado Security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes