All episodes

Trent Hein, Founder of Applied Trust

Apple Podcasts Spotify SoundCloud

In this episode:

Trent Hein, founder of Applied Trust is our guest this week. News from: Toastmasters, CDOT, CenturyLink, Amazon, Juniper Unmanned, Optiv... and a lot more!

"May the wave always die in your section"

 

That's my favorite toast. I'll drink to that. Toastmasters is hiring in Douglas County. Will CDOT get to use data from our vehicles? Former Level3 boss is taking over CenturyLink earlier than expected. Denver tech jobs surging. Amazon is expending in Denver (HQ2 or not). Drones are pretty popular. Other stuff too. 

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure.

Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11243 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 61 on April 2nd, 2018. Alex, we're in Q2 of the year.

We're a quarter of the way through. It's hard to believe. I feel like the year just started, but we can definitely tell that we're in quarter 2 because it is still snowing outside. It's still snowing. Absolutely.

So we know that spring has officially started, right? The snow is very heavy and is ruining my trees. Yes. Perfect. Yes.

I don't think it's quite as bad as last year when I had a whole bunch of stuff die because of the hard freeze, but not yet. Not yet anyway. Still got time. We have more time for that. Go ahead and diving into a couple of business.

Items here. Please remember we have a Patreon campaign and a huge thank you to those Patreons who are supporting us. We do appreciate that support that helps us pay for things like hosting the podcast, our website, really just keeping things going from a podcast perspective. Yeah, and you can find more information about that on the front page of the website. We have a button there that you can go to.

So go to colorado-security.com to find that out. We also have our Slack channel, of course. So there again on the front page of the website, you can get your invite to the Slack channel. We've got over 300. I don't know if we hit 400 this week.

Pretty close, 380 or so, I think. Lots of good conversations going on in there. So come and join the fun, uh, get engaged with the other Colorado Equals Security folks. And I'd say especially if you're looking to hire someone, there's a, there's a lot of folks in there looking for jobs, especially lower level jobs. And if you're looking for a job, it's a good way to meet hiring managers.

Exactly. So let's go ahead and jump into the news. First, Toastmasters has opened their new headquarters here in Douglas County. Speech, speech. Go ahead, Alex.

Well, I, I— so I know where you can find some help with your speechmaking capabilities. But they've apparently been in California for, I think it said 93 years or 96 years or something like that. But they moved to Colorado because it's much better here. Clearly, just like you. Yeah, absolutely.

So they put their headquarters just south of 470, east of 25, over there by Hacienda, Colorado, if you know the area. And pretty cool stuff. We have an international organization headquartered right in our backyard. Lots of fun. Next item in the news, there's a bill that would allow CDOT to use technology with data from cars to start really getting tracking on the road and understanding what's happening with traffic.

Yeah, so right now, if you wanted to get that data, it would require a warrant. You know, essentially that is protected data. So that the bill would allow this kind of data to be collected on a more regular basis without having to go through that process. Now we're talking about like the, the kind of IoT sensors on the cars themselves, right? Right.

So tracking your location, you know, where you're going, other things like that. Yeah. The sort of creepy stuff. It sounds like I, Robot type stuff. Yes.

We're going to be there. And actually, one of the representatives quoted in the story who was against it mentioned, you know, people's permission. Right. So we're essentially— we would be legislating away people's privacy a little bit. Yeah.

My favorite thing here is it says CDOT and lawmakers say the technology would not pick up any identifiable information of drivers, which is probably the most false statement I've read in the last few days. I think we know that even data that does not seem to be identifiable is pretty easy to make identifiable. Listen, it's not identifiable. All I can do is see what house he started at, which business he drove to, and everywhere else he went during the day at what speeds and what times. Exactly.

I have no idea who it was though. Right. You know, it could have been anybody that got in that person's car.

So anyway, that is up for debate now. You know, if you have feelings one way or the other on this, maybe you should reach out to your representative. This is a follow-up from a story we talked about a few months ago as a part of the acquisition of Level 3 by CenturyLink. We mentioned that the CEO from Level 3, Jeff Storey, was going to become the CEO of CenturyLink in January 2019. Well, apparently he's very good at his job, and they said we just can't wait to have this guy be the CEO, and he's actually gonna be taking over this May.

Yeah, maybe it's just that the, the previous CEO decided, you know what, I'm just ready to go play golf. Yeah, so Jeff, you seem capable, I'll just leave it in your hands, see you later. Anyway, congratulations to Jeff. Obviously, it's— I think it's good for the Denver community as well to have the Denver executive be running the new company. Hopefully that means we see more expansion here in Colorado.

Exactly. Next, there is a story that tech employment in the state increased by 6,500 jobs in 2017. That's a big number. That is a big number. It sounds like a lot.

And then you look at the percentage and they say it's like a 2.3% increase of tech jobs. And I say, wow, we got a lot of tech jobs here. Yeah, exactly. Exactly. Yeah.

I think about 2.3%, that doesn't seem like that much. But I mean, year over year, I think that is a pretty big number. Yeah. So it's just tech jobs. I suspect that security is more like, you know, 20%.

It feels to me like 100%. Massive increase in security jobs here in Colorado. Next, there was a story this week about Amazon. It is not related to HQ2, even though that is in the headline, but basically saying whether or not we get the second headquarters for Amazon here in Denver, Amazon is definitely expanding here. Yeah, I know they have a lot of employees in the area already and they are going to have a central office over by Union Station where all those folks are going to be sitting together.

And we're actually— when we get to the jobs, we'll talk about one of the security jobs here in Colorado. Yeah, they noted that they have over 1,500 full-time jobs in Colorado already. That's pretty good. I wonder where that puts them in terms of like biggest employers in Colorado. Yeah, I bet it puts them on the list somewhere.

Yeah, I want to say that Arrow, who touts that they're the biggest employer, is something like 15,000. Okay. Sound right? So yeah, so that's it. Getting there.

Yeah. So if you set aside things like Denver Public Schools, which obviously they're all here, right, it'd be a little bit more interesting in terms of international companies like that. Moving on, we have a story about a drone company from Golden that raised $3.4 million. Yeah, so this is very interesting. They're doing data collection around their drones to make the drones work better.

Sounds like they have some, I don't know, interesting tech that other drone makers don't have, but unmanned flight. So the company is Juniper Unmanned. They, like I said, they are out in Golden. It just, it's neat to see this industry, which, you know, probably at first we all thought of as hobbyists doing, you know, RC and then turning, you know, going from RC into something a little bit more, you know, distance-oriented. It's really becoming an industry changer and a lot of things that you can do with a drone that you You know, would have to— you normally have a person, you know, climb on a roof to do a roof inspection after a hailstorm.

You know, how long does it take you to have that inspection? Well, if we can— if we have drones, we can do it much faster. Going out to like, you know, isolated areas and oil fields and sending a drone out there to inspect things. A lot of things you can do much more quickly with a drone. Looking out at crops in the field to see how things are growing.

So yeah, lots of good stuff there. Patrolling the border instead of putting up a massive wall. There's options, right? Hey, you know what? Let's just put guns on these things, then we'll be all good to go.

Oh, we did just get there. I, I, Robot. All right. So next, there was a story this week about the world's most infamous hacker, Kevin Mitnick, spending some time in Denver in the '90s. Yeah.

So if you guys haven't had a chance to read about him much, take a look at this article for a nice little intro. If you want to learn more, he's got a book, Ghost in the Wires, that I've read. It talks an awful lot about his time in Denver. Really interesting stuff. He is one of the most famous hackers in the world and, you know, kind of one of the early ones.

Apparently, he's, you know, per the article, been arrested only 5 times. So only 5. He learned relatively quickly. Exactly. Exactly.

You know, you spend a little time in jail and I think, you know, you figure out that's probably not where you want to be. Moving on. So there is a story out there right now about Denver undergoing some kind of computer systems, especially with their 911 and 311 systems. There is some kind of a computer issue going on that's taken down some functionality there. You can still dial into 911, but you can't text into 911, and the 311 system has been down altogether.

So we have an article in here that gives a little bit of info. Frankly, I don't think we know much about this quite yet. Obviously, the, the technologists over there are still working on it. What we have heard, you know, from the, from the article, the official statement is that it's not related to a cyber attack. It's related to some kind of other software problems.

Yeah, I have heard a little bit of scuttlebutt that some people do think that it might be related to a cyberattack. But as Robb said, official statements are that it is not. So I guess we'll hear more about that soon, hopefully. Yeah, absolutely. Last story.

You want to go ahead and Optiv us? Sure. So Optiv earned the prestigious Competitive Strategy Innovation and Leadership Award from Frost Sullivan. Yeah. And I think this is maybe the second year they've won this in a row.

I think we talked about this last year as well. There are a number of these awards that get awarded to different companies. So it's very possible that we talked about it, or it could be one of the other very similar awards that are out there. Another little piece of Optiv news is the headquarter building that they're going to be moving into has officially had the ribbon cutting, right? Yeah.

Open. It's called Optiv Tower at Gates Plaza and Chipotle Cafeteria or something like that. Yeah. So all 3 of those companies are going to be moving the bulk of their employees in there. So all 3 of the companies have their name on something.

There. There was kind of a little bit of a 3-way fight to see who was gonna get the name on the outside of the building. I guess Optiv paid the most, Gates paid the second most, and Chipotle paid the third most. That's my guess, right? This is— if I throw the word allegedly in here, we get— we're okay?

Allegedly all of these things, right? This is what I've heard. Yeah. So that's it for the news. Let's move on to our not trivia.

So as you guys may or may not remember, last week we, we took a little turn, and instead of doing our trivia questions, we are now moving to the Slack message of the week. Yeah. So Obviously, we would love to drive more activity in the Slack channel. We think it's a great community-building opportunity. Slack message of this week is from Brian Becker.

Brian is the Director of Security over at Cronki, and Brian was the breaking news source for us this week as he shared the story about Boeing who got hit by the— was it WannaCry, right? I believe so. Yeah, got hit by WannaCry, and the first reports were a little bit more sensationalist than maybe the later reports. First reports were like, hey, they're not going to be able to make jets for a while. But it looks like probably, you know, they were impacted by WannaCry, but not going to impact their production.

Yep. So congratulations to Brian. We will reach out to him. And thanks again to Andre Gaeta, who's our sponsor of the Slack Message of the Week. And Brian will be able to get something from our swag store.

Yeah, absolutely. We'll get a note out to him. Let's go ahead and move over to events. As a reminder, as always, we have an event calendar out on colorado-security.com. Go ahead and take a look at that if you want to see what's coming up over the next several months.

Also, just kind of as an aside, we have a mailing list. You can, if you want to sign up to the mailing list on the website, we'll get this thing, this show notes into your inbox every week. So the first event, which is tomorrow, April 3rd, SecureSet is doing their Hacking 101 workshop, which is intro to threat analysis. On the 6th through 8th, we have a critical infrastructure hackathon. If you're part of the critical infrastructure or you want to be, this looks like a good way for you to get some experience.

Next, ISSA Colorado Springs is doing their Security+ exam preparation seminar on the 7th. Yeah, this is a great way for you to get ready for that certification test. It's a 2-week thing. It's at the 7th and the 14th, but if you're not gonna go on the 7th, probably don't go on the 14th either. Then on the 10th and the 11th, ISSA Denver has their April meetings, and those will, as always, be Tuesday lunch in Boulder, Tuesday evening downtown Denver, and Wednesday lunch in the Tech Center.

Next, SecureSet is doing a cybersecurity career trends, Nadine Tanner from Rapid7 on the 12th of April. And then kind of looking forward a little bit further from that, later in April, I think it's the 26th, we have the Women in Security event coming up. 24th. 24th, thank you. Women in Security event coming up.

And then we have RMISC just a couple weeks after that, May 8th through 10th. A lot of good stuff going on. We've got a full slate of of pre-conference sessions and then of course of track sessions during the event itself. Alex, I know we wanted to focus on a couple of things this week about the conference. As the co-chair of the conference, what would you like to share?

So we are doing something a little bit different this year that we haven't done before. We are bringing in a vendor called Living Security and they do security awareness education through essentially escape rooms. So during the conference, we will have an area set aside where you can go through the Living Security experience. And this essentially, you'll get locked in a room, you'll have a bunch of puzzles to solve, security-related. And, you know, once you solve all of those, you'll be able to get out of the room.

That sounds a lot like a lot of fun. I've certainly done a couple of escape rooms before. This one sounds, from what I've seen, that they're really focused on security awareness and trying to drive home some reminders. It sounds like a lot of fun and it should be a good fit for the conference. Yeah.

And as part of this, we do have sign up for Living Security. Basically, they're going to run, run these every hour. So I think they can only have 10 participants per hour. So as you register for the conference, there is an area where you could sign up to do the Living Security experience. So make sure when you register to go do that.

I imagine that there will be some spots that you could get into at the conference, but we want to try and get as many people registered prior as possible. So we want as many people excited as possible, but not too many people because there's not that many spots. Exactly. Okay. Say moderately excited about this.

Okay, listeners, really excited for now. Later, maybe moderately excited. So sponsorship as well, right? I think we've— we had some great news that we've already surpassed our goal for sponsorship for the year. Yep.

So thanks. A huge thanks to the sponsors that we have for the conference. We also have some spots open still, right? And we definitely still have some spots, but we are getting shorter on those number of spots. So if you are a company that has been thinking about sponsoring, we would still love to have you, but you should probably pull the trigger pretty soon because not too long, I think we're going to be sold out.

And just as a reminder, RMISC is put on jointly by ISSA and ISACA Denver chapters. And any proceeds that come out of this, it, you know, it's for many years, it's what, this is like the 13th year, I think. Um, for many years this is a break-even or lose a little bit of money conference that, you know, became break-even. And over the years it's actually become, um, it's become cash flow positive and it takes, spends money back to the chapters. So ISSA Denver and ISACA get some money back out of the conference that they can use to increase those, those organizations.

Exactly. Everybody's nonprofit. There's no one, there's no one sitting there at the end taking this money home. It really just goes back into the community. So we appreciate any support we get for that.

Exactly. So let's move on to jobs. First in jobs this week, I will turn it over to Robb. We once again have some Ping Identity jobs. Yeah.

So one of the nice things about having a podcast is you can keep your jobs on the list every week. So we have a few jobs here at Ping. Looking for one that we just announced last week, still pretty new, a senior security analyst position. Looking for someone who's got strong Linux, web application architecture, and hopefully AWS skills along with scripting. Looking for a senior analyst for that.

Looking for an infrastructure security specialist, which is on the same team but really on the more junior level, you know, quite junior level position. Someone who we can train up on those same type of skills. And then we're also looking for a GRC analyst to work on our compliance team. Who would be doing ISO, SOC 2, GDPR type work. And this is also someone relatively junior looking for someone who can, who we can train up on those skills.

So moving on to the non-Ping jobs, Staples is looking for a Microsoft Cloud Security Consultant. Kaiser Permanente is hiring a Senior Analyst of Cyber Risk Defense. LogicWorks is looking for a Senior Cloud Security Engineer. Got a lot of senior positions this week. DISH Networks is hiring a senior security engineer.

NBCUniversal is looking for a cybersecurity vulnerability researcher. I think it's the second week that we've talked about NBCUniversal. Apparently they're, they're building out a security team here. Yeah, I saw a few other job posts from them as well. Cool.

And then this is a fun one. This is one we mentioned earlier. Amazon is hiring and it's a security transformation consultant. Of course, because it sounded so interesting, I, I spent a little bit of time looking through this one. And they're looking for, they're looking for a unicorn here, someone who's got really highly technical hands-on skills working on infrastructure and security as code, CI/CD microservices type stuff.

And then also they want you to know about compliance frameworks and, you know, have worked with NIST, ISO, PCI, those types of things. So really interesting skill set they're looking for there for sure. Next, ClickBank is looking for a cyber threat intelligence analyst. Is this clickbait? Is it?

It might be. I don't know. I hope not. And then finally, Bank of America is hiring a senior information security officer. So hopefully, you know, you're probably running security for one of their business units over there.

Exactly. And that one actually could be located in multiple places, Denver being one of them. Awesome. Well, that is it for the week's news here. We do, of course, as always, have a feature interview we'll be going over to.

This week I sat down with Trent Hein. Trent was the one of the founders for Applied Trust. If you guys know, over the years, Applied Trust was a professional services organization in the Boulder area. They got bought, I don't know, 4 years ago by, um, by ViaWest. And then just recently, ViaWest was bought by Peak 10, right?

Yeah. Um, and, and that's now turned into a new company, the name of which we don't remember. It was a bad name, but I don't remember what the name was. I remember making fun of the name, but I don't remember what it was either. Um, anyway, looking forward to hearing from Trent on here, uh, and we'll talk to you guys next week.

Thanks, Robb. Hi, this is Merlin Nameth, Business Information Security Officer at the Reed Group. This is Colorado Equal Security, for Colorado security professionals, by Colorado security professionals.

This is Robb Reck with Colorado Equal Security, and I am here today with Trent Hein. Trent, as we get started here, I want to know what brought your great-grandfather to Colorado. Uh, they came here as blacksmiths. Um, they, uh, he, he was a blacksmith and it was the frontier, you know, the early 1900s, and there was demand. And so he set up shop and, um, eventually was the blacksmith in Lafayette, of course, where there was a lot of mining going on at that point.

So the Lafayette blacksmith, and I assume that's making mining equipment mostly at that point then? Oh, everything from fixing wagons to fixing heavy equipment, you know, whatever, you know, you need a blacksmith, you need a blacksmith. Yeah, so number one, I don't know what my great-grandfather did professionally. I know where he lived. He lived in Nebraska, but I don't know what he did.

So it's cool that you know what your great-grandfather did. So if you don't know any of the other questions, I get it. Do you know, like, did your family stay in Lafayette? Did your grandfather follow in his footsteps? Talk to me through this.

This is interesting to me. Yeah, so my grandfather grew up in Lafayette, and actually, and this is just unfathomable to me. Um, he eventually went to the University of Colorado for electrical engineering, and he would walk from Lafayette to the Boulder downtown campus, uh, to go to school, which I can't imagine how long that would even take on foot. Yeah, that is, that is really painful. Do you know what he was, what he was majoring in?

What was it? So he majored in electrical engineering, and then my father also majored in electrical engineering at CU. And the story there is, you know, they had lab books of, you know, when they did testing of big motors or whatever. Yeah. And when my dad was a student there, he found his dad's notes in the lab notebooks, which is really cool.

That's amazing. So, so you are— if I'm getting it right, if your great-grandfather's first generation, then that makes you fourth generation Colorado native. And did you guys all— you said you told me earlier you live in Boulder. Have you guys lived up there in that Lafayette, Boulder, northern area for the whole time? I grew up in Arvada, but I personally have lived in Boulder the last 30 years and absolutely love it.

It's a great place. That's very cool. Well, so I guess we should probably talk about who you are and why we're talking other than this awesome Colorado history. Random Colorado history, yeah. So Trent Hein, you are— what I know you as is the founder of Applied Trust, which is a Colorado-born security services firm.

Yep, that fair description? That's a great description. Um, but I bet you did something before that, so would you mind kind of backing us up and telling me how did you— obviously you said you grew up in Arvada, you've been a local guy. What did you do? You went to high school and then what?

Uh, I went to the University of Colorado and got a degree in computer science, and, uh, actually 2018 will be my 30th year in cybersecurity, which makes me feel super old. Yeah, that's pretty good. But, uh, the reason I say that is I was a student at CU and I worked as administrator for the College of Engineering on November 3rd, 1988, which of course is the famous date of the Robert Morris Jr. worm, really the first internet worm. And that sparked my interest and started a lifetime of casing vulnerabilities and ways to avoid them. Yeah.

And so you— talk to me about how did you get— you go from getting this interest in the worm and moving from there and actually getting to professionally going after this? So at the time, my advisor was Dr. Abby Nemeth at CU, and she had a whole crew of system administrators and really was known worldwide as kind of the grandmother of system administration. And so we did projects with her, consulting projects with her out of the university. We built the computer science building at Princeton, built the network there. That started a passion for, hey, I like to help solve— people solve problems.

And then when I graduated in 1991, I started a consulting company with a buddy, Exor. And Exor grew from 2 to 550 people. Holy smokes. It went through a couple rounds of acquisition in the 1999-2000 era. And in fact, there are folks that I hired at Exor that still work for its current owner, which is FICO, the credit score people.

Holy smokes. Yeah, so that's kind of crazy. And then I left Exor in 2001 and started Applied Trust. So you— did I get the date right? You started Exor in '91 or '81?

'91. '91. Okay, '91. So 10 years, 550 employees. Is that— that's It was crazy.

Now, this was also the crazy internet dot-com boom, lots of e-commerce. I got to do lots of great projects in the e-commerce and early security space. And then in 2001, Ned McLean and I started Applied Trust, focused solely on security, which was just fantastic at the time. It was a good time to start a security company, I will say that. 2001, okay.

So what was the idea when you started up? What were you doing? We were very focused on getting enterprise to understand the need for security as a discipline, right? So this is before the era— 2001 is really before the era of CISOs. It's really before the era of security really being a clearly defined discipline.

People, some people laughed at us. They're like, yeah, you'll never be able to run a company just focused on security. Of course, now that sounds ridiculous. But in 2001, this most large enterprise had just started to think about it. And so we worked on everything from, you know, policy frameworks to, you know, how do we detect intrusions, and with very crude tools, right?

We didn't have the beautiful commercial platforms that are out there today. Yeah. So do you maybe tell me about some of those early engagements and and how you go from walking in and maybe they say, I don't even know why I need you, to delivering value? Yeah, you know, this, and the sad part of it is, and I think this is still true today, is there's really 2 types of clients. There's clients who don't know they've had a breach, and clients who have had a breach and are suddenly very interested in getting help.

And that space still today is very driven by, when you look at inbound leads, is very driven by, hey, we need help. And oftentimes it's a friend referring a friend where someone accidentally discloses 100,000 credit cards, they're in tears, panicking, they call a buddy and say, what do I do? The buddy's like, you need help, go hire a professional, which is definitely the right answer, right? And it's, I'm not saying go hire Applied Trust. I am saying if you have a large breach, you need to go get professional help because you want to make sure that evidence is handled in a way that it could be eventually turned over to law enforcement, that you don't destroy evidence in the process, that type of thing.

And so you pick up a lot of clients that way, but then it really boils down to understanding where sensitive data is in the environment and how do we protect it. And that sounds simple. You're like, oh, well, of course, that's super obvious, Trent. Well, unfortunately, a lot of organizations can't identify what sensitive data they even house and where it is, right? Is it in a spreadsheet on someone's laptop?

Is it in some server in the closet? Is it in some third-party SaaS provider that marketing contracted with that no one even knew about? Even knowing where the data is is often a challenge. Yeah. So I am interested in the business side just a little bit, and of course I want to talk about security too, but when you chose to open up this new business, was it, you know, you said you had a co-founder.

I'm sorry, what was his name? Ned McClain. Ned McClain. When you and Mr. McClain opened the business, did you guys, just the two of you, are the business development and the delivery arm, or did you have folks you were working with, or how did you go there? At least the first 6 months, it was the two of us.

We did sales, we did marketing, we did engagements, everything, outreach, everything. You have to, right, when you're bootstrapping a business. I mean, this is one of the things that I often struggle with, is that the perception, at least in Boulder, often is, is that the only way to start a business is you have some type of venture capital, you know, some big cash infusion, and you know, they come with all these resources that help you with XYZ and K, and that's absolutely a valid way to start a business.

We didn't start XOR that way, and we didn't start Apply Trust that way. We completely bootstrapped it, you know, 2 of us working in front of a whiteboard figuring out what we're gonna do. And, you know, you write all the web content and you go out and sell it and you deliver the work, and then as cash flow allows, you can start to bring on help, whether it's help for additional delivery resources or, you know, administrative help or whatever. Now, of course, that may not work as well for a product business, but in a services business, it's absolutely viable. Yeah, you see, it seems like you can, you can do it pretty, pretty low risk that way, right?

Pretty low risk. Yeah. Yeah. And you have the opportunity to really focus on doing things right, right? You, you want things to be perfect in terms of how you position yourself in the market and what value you're delivering to clients, and you have a lot of control when you're the one doing all those things.

Yeah. So let's, you know, starting in 2001, there's 2 of you there. How do you go from 2 of you to, you know, building a larger, you know, quite scaled company? Talk me through the years. It really is a one-year-at-a-time thing.

You know, I would— you know, we can kind of walk through it. I would say by the end of year 1, we probably had 4 or 5 people on board. Okay. And by the end of year 2, sitting, you know, in the 9 or 10 range. And we did an interesting thing, which I also encourage entrepreneurs to ponder, is our second year, we had pretty good visibility into revenue.

Growth and so on. But one of our largest expenses beyond personnel is real estate, right, is rent for an office. Yeah. And of course these days maybe you don't need an office at all, maybe it can be virtual, but you know, sometimes it's nice to have that headquarters feel. And, uh, so in 2003 we actually purchased office space in downtown Boulder.

A buddy had told me, he's like, stop burning cash in the parking lot giving money to a landlord. If you're going to be here for a few years, go buy a building and pay yourself. And that actually turned out to be just incredibly good advice. Um, you know, we're blessed by what's been a great real estate market over the last, you know, decade and a half. But, um, uh, we, we bought a building in 2003, and that's where Applied Trust still sits today.

This is fantastic. And did you guys use the whole building? Were you renting it out and making back some of the payments, or So we were using all the pieces we owned. We eventually leased additional space adjacent to that so that we could grow. But, you know, it's interesting when you're an entrepreneur, even if you're a tech entrepreneur, you need to be thinking about, you know, what are those other ways that I can make our dollars go farther and build value in the organization, especially in a services business?

Because at the end of the day, your assets in a services business walk out the door, right? Right. And you've got to build some type of intrinsic value for the organization. So as you grew from 2 to 5 or 6 to 10, did you see the nature of your service offerings change? The nature of our service offerings changed a little bit simply because the market changed.

When we look at the— start talking about 2000, to 2010 era, enterprise IT and enterprise compliance was very aware of the threat that was out there in terms of cybersecurity, but still didn't really know how to address it. We started to see products come on the market, commercial products that helped solve the bigger problem. We can do wide, large-scale patch deployment or large-scale AV deployment or single sign-on where we didn't have those in earlier years. And so the problem got more complex and the need for consulting in that space continued to increase. So that was really awesome.

The other thing that of course came into play were external drivers, regulatory, and we look at whatever you want to call PCI commercial regulation, that folks were required to adhere to a compliance standard because of the type of data they held. Whereas before, maybe they didn't have a breach or they didn't know they had a breach, but now they're basically forced into thinking about and spending money on cybersecurity. Was Sarbanes-Oxley a driver for you as well, or is it Or is it really more PCI that you saw as the incentive? The top 2 drivers are really HIPAA and PCI. The ITGC part of SOX depends on the organization, right?

Different accounting firms interpret that differently, which of course is a problem, but unfortunately, I don't think that that's had the the teeth that one would want, at least as a security practitioner. So yeah, you haven't seen that driving a lot of opportunities. Yeah, I'm just thinking, I was trying to think of the early 2000s and what was bubbling around back then. HIPAA, that was before HITECH, right? So there wasn't the same level of guidance that, or at least the— Yeah, it didn't have the teeth, right?

So the concepts were there as of about 2003, but really didn't have the enforcement teeth until HITECH. Yeah. So I have some friends, and I actually myself have had a consulting company where it's done by a senior person, someone who knows security well. As you went to scale from the two of you to getting more folks in, I assume you've got some people who are less experienced. How do you think about, hey, I want to offer the high-quality product that Trent would offer, but with other folks scalably and with a larger staff.

How do you think about that? I think you always have to have a team, and I especially think in the space that we're in today where security is incredibly complex in any enterprise that you need multiple eyes and ears on it. The approach at Apply Trust was we'd always pair one or more senior folks with someone who's maybe more junior.

I think as an industry we have a problem in that we're not training folks well and not training enough folks to be good security practitioners. And so the more that we can do transfer, knowledge transfer with them, the better. And some of that is on a team working on a project.

Do you have any kind of a theory at this point about how to identify the right talent that you want to train up? What do you look for if you're bringing in someone at the bottom level to train up? Attention to detail across all of cybersecurity is incredibly huge. This sounds harsh, but you put 10 resumes in front of me, the ones that have typos on them, formatting errors, or whatever, are instantly off the table. If you don't take the time to have the attention to detail on your resume, I know you're not going to have that in the security space.

Whether you're sitting in a SOC, whether you're doing assessment work, whether you're doing some type of technology deployment, you need that incredible attention to detail. The other thing that I think you need today is a pretty solid foundation in what you could call computer science or IT or infrastructure, right? It's unfortunately because there's so much demand right now, especially in the audit space, you have people who have no background in technology doing compliance assessments, doing security audits, and sure, they have a checklist. They have no idea what the items on those checklists actually mean, and that doesn't provide the value that at least I would want to see. So you are— it sounds like you're more of the mindset that you'd rather train someone in the security and compliance requirements but have them have this, the technical IT background, versus having someone who, you know, knows project management or something like that and try and teach them the technology.

Absolutely, because the technology layers are incredibly important and incredibly complex, right? You need to understand You know, what do network packets look like? And how does traffic move? And what does a router do? What does a firewall do?

How does a database manage access? How does an application interact with a database and some type of server farm and the cloud? Those foundational technology concepts You can teach them, it just takes a really long time. And so I think it's easier to take someone who's a technologist and teach them the nuances of cybersecurity than, like you said, someone who's a project manager and trying to teach them technology. Okay, fair enough.

So let's keep moving forward. We got a couple years in, you're at 10 employees, and you're starting to focus more on, you know, helping folks with PCI and maybe some HIPAA requirements. Requirements? Talk to me about how does— how do things move forward from there? Uh, you know, really continued to grow largely through word of mouth.

Um, uh, lots of client-to-client referrals, um, especially in specific industries, right? Did a lot of work in healthcare, quite a bit of work in retail and entertainment and so on. Um, because once you have a reputation in that space, you're like, oh yeah, you should call Bob over at Applied Trust, whatever. Is that mostly in Colorado or is that nationally? Nationally.

And as you know, we're in a space now where it doesn't really matter where you are, right? You could, you could do consulting for a company in Africa just as easily as you could for someone in Aurora. And that of course helped us grow as well, just the, the, the ease of being virtual. And then around 2014, you know, we're approaching the 50 engineer Mark and Ned and I, we were really good through the years of doing annual planning, right? Taking a day or two, step aside and say, okay, where are we?

Where are we going? You know, as a business, what do we want to be doing? How do we, how do we keep moving forward? And around 2014, we got to the point where the bootstrap thing was getting harder and harder to justify, right? Is, is, is you're— when you get to the, the near the 50-person mark, it's like you start to need real marketing department, you need a real finance department, you need, um, you know, product development, um, you need all those groups that we just never had.

You know, everybody was someone's side job or multiple people's side jobs to do all those things. HR. And so the question is, what do we do? Do we start to hire our own HR department, our own marketing department, or is this an opportunity to go buddy up to someone that needs what we do, has those things, and there's some type of symbiotic relationship? And so we spent roughly a year looking at options in that space.

Is there someone who would be a good culture fit for our team? Technical. We had actually said it would be ideal if you could find someone in Colorado. It's a good Colorado company, but we didn't limit ourselves to that.

They're looking for a pro-serve InfoSec firm to grow with them. We came across Viawest. Of course, I'd known Viawest forever. Nancy Phillips, just a legend in Colorado and an amazing leader, and turned out to be just the perfect fit. They were in the process of expanding their offering set to include things beyond just cloud and colo, and we were looking exactly for that, someone who had all the larger company features but wanted professional services.

That turned out to be a dream fit.

I often think how lucky we were to have come across them at that time. So, so, I mean, it seems like a huge change, right? You're, you're 13 years into a company that, you know, the two of you are navigating on your own and, you know, totally control your own destiny, presumably have some kind of a goal in mind, whether it's an exit or a lifestyle business or some kind of a goal. And then this is a pretty big sea change. Seems like to me.

Is it— is it— does it not feel that way? Um, sure, it's a change, but it was— it's one of those things where when you're at that size and you're bootstrapped, you, you've got to do something, right? Either we've got to fundamentally change the structure of this company on our own and add all these— I'll just call them corporate structures— yeah, or we need to find some way to plug those in. And of course, there's a bunch of different ways to do that, and, and we looked at a bunch different ways to do that, and Viya West just happened to be the perfect fit. The fact that they didn't compete with us, it's not like they had a professional services group that then we're going to try to mash these together.

It's like, hey, we really want to add this on as an additional service offering, which was the perfect fit for us at the time. Sure. You were there, you went to Viya West 2014. How did that change your day-to-day? Life?

Not the boss anymore, right? Not the— yeah, not— you definitely continue to run professional services, but there's a lot of other players making strategy and business decisions, right? Certainly the nice thing about working with the leadership team at Viowest, Nancy and Mike and Jason, Jeff, was that they, you know, very much collaborative, very much wanted to work with us on Hey, where are we going? How can we grow this together? Right?

What are the, you know, how do we change the world in a positive way? And so I had just super great interactions with them about that. And, you know, then at the same time, we're going from an organization where every sale is made by an engineer that actually delivers work. Yeah. To an organization where, you know, at the time I think BIOS had like 40, 45 sales folks, right?

And they're selling work separately from engineers. And so I would say that's the biggest transition, is how do you get the, the, the sales and AE team up to speed on, hey, here's a— here's all the offerings we have, um, here's where they apply, here's where they don't apply, um, here's how you sell them, that type of thing. So that, that was probably the biggest changes, is, is learning to work with a large sales team. Yeah. So you came in with about 50 50 folks.

A couple years later, were you still at 50 folks doing the professional services of what used to be Applied Trust? You still actually went to market as Applied Trust, right? We did. There's been a lot of internal debate about that. Is that the right answer or not?

Certainly, in the security space, AT was a known brand.

Certainly, it worked well for us for for those years. I don't know what they'll do going forward, but it's definitely one of those things where when you become part of a larger company, you have to make those decisions, right? Like, what are we going to keep? What are we going to change? What are we going to adopt from the new company?

How many folks did Applied Trust have a couple years in after you went over there? Do you grow? Do you stay the same? Do you shrink? Uh, uh, we grew, um, and, uh, grew in a bunch of different ways.

So grew both in, in, in headcount, um, uh, with, uh, I think we almost doubled headcount in those 2 years. And then we also grew in office footprint, right? So previously all of our team was based in Boulder. Um, currently Applied Trust has offices in Dallas, and Philadelphia and Salt Lake City.

Some of that driven by market demand, like, hey, this is a great market to go and expand into, and some of it driven by really employee choice of like, hey, I want to live close to my parents, my aging parents or whatever. And it was like, great, virtual world, go build an office in Dallas. Yeah, that's great. So I know things have changed. It was last year, right?

It was 2017 that Viawest merged with Peak 10. Viawest got purchased by Peak 10, right, which is a company very similar in size to Viawest but really East Coast based. Yeah, I remember we— and we just covered that they have a terrible new name, the joined company. You remember what the name is? It's, I think it's Flexential.

I don't— Flexential. Yes. I hope I said that correctly. Yeah, that— so like I said, a terrible new name. But talk to me about that.

That acquisition process, what was that like? I had very little visibility into that. That was really the VIOS layer and above. That deal closed in early August, August 1st or August 2nd of last year. About 6 months ago.

Yeah. What did that mean for Applied Trust and for you? It almost doubles the number of data centers that the combined organization has.

I think that their going-forward strategy obviously is very data center-centric.

They continue to support and grow the professional services group in Boulder, now led by the amazing Dan Mackin. But it became clear to me that it was time for me to move on. It's just something I want to go do. There's so much opportunity in our space. That, um, it, it made sense for me to move on to go do something else.

So, so the second, second sale was the one that was enough for you, the moving to Peak 10? Uh, and when did you choose to move on? I left December 31st. Okay, so it's— yeah, I got you. So end of the year.

Um, now you say there's lots of opportunity. Clearly there's lots of opportunity. Is there something in particular that's especially interesting to you? Oh, that's such a great question. Um, um, yeah, and I wish I could narrow it to one thing, um, but I'll talk about a couple things.

So one thing I'll point out, as I'm sure everyone is acutely aware, 2018 is an election year, and I, for some odd reason, think that cybersecurity is going to be a pretty hot topic for campaigns. And I think it's an opportunity to make a difference, right? Like, it's— I always say, people ask me, well, what do you want to do? I want to change the world. Are you about to announce a You're running for governor?

Oh, that's hilarious. No, no, no, but I do think that maybe some campaigns could use a little extra cybersecurity help in the coming months. Yeah, because I think that unfortunately it's one of those things that, you know, still— I mean, it's true for large enterprise, but it's also true for campaigns. Folks kind of push by the wayside. It's like, oh, someone will take care of that.

Well, who's that someone? And how are they taking care of that? And suddenly I think that might be a lot more important. So 2018 is a unique opportunity in that regard. But then beyond that, there's a couple spaces that I am very passionate about that I want to go push on.

But they're all in what I would call the dark IT space. So here's the challenge.

Cybersecurity industry has done a really great job of highlighting, you know, like, oh, we have to secure desktops and we have to secure servers and we have to secure applications in the cloud and we have to secure mobile devices and so on. And every organization I work with, you're like, okay, cool, you guys did all that stuff, right? You got antivirus and you got IDPS and single sign-on and you got all that. And then, hey, let's go talk about all of these little devices over in the corner, the HVAC system controller that's connected connected to Ethernet, the camera system that's connected to Ethernet, the badging system, maybe we have industrial process control for our soy milk production line, whatever, all of those things have IP addresses, they're probably running an embedded operating system of some form, and when you ask most organizations, you're like, how are you securing those, you either get a a completely blank stare, or they quickly try to sweep that. It's like, oh, Bill takes care of that and he's not in today.

Yeah. And, you know, that's a problem, right? It's a problem for us as an industry is that we need to be securing those industrial, uh, IoT devices. Um, just, you know, of course in the consumer side we need to be securing IoT devices as well, but definitely in the industrial space I think it's a, a missed, uh, it's a missed opportunity. It's really the black sheep of the environment.

And a lot of times it's devices that are purchased outside of IT, right? It's purchased by some facilities management group or some business unit or marketing or who knows what. I always pick on marketing. But IT doesn't have any visibility into it and information security doesn't either. And so I think there's an opportunity to work with tools and process around that.

You know, the other thing that just keeps me awake at night is all this talk about machine learning and AI, right? It's the hot space, and a lot of folks, you know, we can go on and on about, okay, well, what, what is artificial intelligence and, and, and where are we as an industry and computer scientists? But the reality is, is that businesses are starting to make decisions based on what they got back from their machine learning model, right, which is really what we have. And then you ask them a question like, how do you know that that model wasn't tampered with? Or how do you know that the data that was provided to that model, right, uh, had integrity?

And then you also get that blank stare look, right? It's just like, well, it's machine learning, it's artificial intelligence, it's great. It's like, great, if we— if instead of having a machine learning model making those decisions, we had Scott in the corner making those decisions, for sure you would be making sure that Scott's work was audited, that you knew how Scott was making those decisions, and that he wasn't being paid on the side by some German hacker kid, whatever. But for whatever reason, right now where we are is when you talk about, well, how are you securing your machine learning models, there's really not an answer for that. And so I think that's also an opportunity to to go change the world.

Yeah, that's great. Yeah, it sounds, it sounds like you have some thoughts about it. Are you thinking a product company, services company, go work for somebody else? Product service company? Oh man, you know, I'm an entrepreneur at heart.

I love the entrepreneurial thing. It's so fun to go to build an organization where you can control technical excellence, right? Where you can do things the way they should be done. And, and, you know, let's be honest, your you-know-what is on the line for doing it right and doing what you say you will do. Yeah.

So I guess I'm gonna hear from you in the next year or so with what the next thing is, right? Yeah, let's get through election season and then let's— we'll see what's going on. Yeah, you know, it's, it's, it's, it's nice to have a few weeks here to ski and to think about, you know, like What, what's the next space to go jump into, right? So you're— you've been in Colorado your whole life. You know, you've seen us go from not having any kind of a security community at all to— we have a fairly vibrant community at this point, I think.

Hugely, yes. Yeah, maybe you could talk to me about what you— how you've seen that develop and what, what is it— what's it been like to watch this over the last few decades? It's amazing. The nice thing about Colorado in general and about the security community is that everyone is so giving of their time. I often say that you can get coffee with whoever you want in the Colorado community, whether it's the security community or the entrepreneurial community, and be like, hey, can we have coffee?

Great. Everyone will take your request for coffee. I think a lot of that's been a result of some of our early leaders. And one of the folks I'll call out is Rick Dakin. You know, Rick, the founder of Coalfire Systems.

Unfortunately, we lost him in 2015.

A friend of mine, and he, you know, always, no matter how busy he was, he was always up for grabbing coffee or breakfast and talking about, you know, how he started Coalfire and ran it, or, you know, how he pushed on the FedRAMP standards at the federal level or everything in between, right? And I think having folks who are willing to do that and be so accessible is unique. I have known a number of folks who have left the Colorado community, go out Bay Area, and that's the thing they came back and said is like in the Bay Area you can't just drop someone an email and be like, hey, can we grab coffee next week? Very different. And that's— and folks who commit their time, right?

Like Colorado Equals Security to help promote the security community here in the state is awesome. That's great. It's just amazing that, you know, we've gone from this dusty old cow town, right, where we oil and gas, maybe some telco, to somehow, you know, what's happened in Boulder and what we have now in Denver with this, you know, innovation of technical companies. It's been amazing. Do you have any idea why Colorado has been so fortunate?

In that way? Um, yes, I mean, I, I have my opinions. Um, I— where would— where else would you want to live? It's like the dream place. Like, if you're like, okay, where could I start a company?

I want to start a place that has amazing people, an amazing climate, 300 days of sunshine. Um, you know, skiing's an hour away, hiking, biking, rafting, you name it. We have everything here. And that we have multiple great educational institutions here, right? You look at the program, the cybersecurity program at DU, you look at the University of Colorado, you look at CSU, Regis, right?

It's like we have all of the assets to go build an amazing community that supports cybersecurity and IT. And I do think it helps a little bit that we had a lot of telecom to begin with because of just the natural, um, physical location of railroads and fiber junctions here. But, uh, it really is just the, the best place to live. Yeah, don't tell anyone that because we'll keep, we'll keep it secret. It could get full.

Yeah, as long as no one listens, we'll be fine. Uh, what about, you know, you've done this 20-plus years of really security-focused stuff, right? What are the things you see people doing wrong the most? You walk into a company and people who are trying to do the right thing, not ignoring it, but trying to do the right thing, what are they missing? Yeah, great question.

My biggest rant is often around checklists, right? And so sometimes that translates into compliance standards, but the perception is that, oh, if I get an assessor, an auditor, or whatever to come in and give me this stamp of approval, right? We're PCI Rock certified, or we're HIPAA certified of some type, we're secure. And the reality is, you just— nothing could be further from the truth. And I think anything you checklist like that is going to behave that way, right?

You have to look at the fundamentals. What data do we have? Where is it? How are we protecting it? Did we include everything in the environment, right?

Without even looking at the checklist, I'm not saying that the stuff on the checklist is bad, I'm saying it's not enough. And of course there's conflicting checklists, which is a problem. The story I will tell, right, to simplify that is recently had a house sitter. Um, you know, we have kids and have critters, right, like a salamander and a crested gecko and, and so on. So when we're traveling, someone has to come in and feed the critters, right?

So you give them a checklist like feed this critter this time and this often, feed this critter this time, this often, and so on and so forth, right? Of course, that's how you, how you handle that. So situation. We were gone for a week, come home and walk in the house. I'm like, wow, it's really cold in here.

Why is it so cold in here? Oh, back door is open. Why is the back door open? Oh, talk to house sitter. Oh yeah, you know, back door was open, but I figured you guys left it that way for a reason.

It's like, you didn't say to close the back door on the checklist. And it's, you know, but But that's exactly what we do in information security when we take a list of 740 controls and test for them and then say, done. It's like, oh, well, closing the back door wasn't on the 740 controls, and we leave the organization vulnerable. That's the number one thing, is you just can't get stuck in the checklist mindset or the compliance mindset. The other thing that often frustrates me And I, I'm— let me just jump in real quick and say you need a new house sitter.

That, that's the lesson I just got out of that story. Well, well, well, sure, that could be a good lesson too. Um, but you know, it's— that is the mindset when you give someone a checklist. Sure. Yeah, period.

Do you do that? You do the checklist, I get it, right? You do the checklist and then you're done. I'm sorry, you have a million other things going on. Uh, the, the, the other thing that drives me nuts is folks storing data that they don't need, right?

It's like, if you don't need the full Social Security number, or you don't need the, the full encryption key or whatever, do not store it, no matter what controls you have in place. Yeah, it's the data— it's the hoarders, right? Yeah, data hoarders, because someday we might need it. And it's like, no, unless we absolutely need it today, we shouldn't ever store it. And then that helps reduce our security burden.

So the other question I'd like to ask, I think you touched on this a little bit already, is around what if someone wants to get into the field? Obviously you want them to go get a nice strong technical background. Can you be specific? What technologies would you think someone should go learn about? Well, I would love to see folks getting degrees in computer science or related fields like ECE, but there's lots of different ways to do that.

The tech colleges have programs in in that. I think having a really strong background in networking is a great entry point into cybersecurity. You understand how packets move or don't move, where data is, and so on. I think from a networking background would be fantastic. Then go do an internship.

There's so many opportunities to go do 2-month, 3-month internships at a bunch of companies and learn not only how do they work and and how do they approach problem solving. But what do you like? I'm a big believer that you should love your job. Yeah. And, you know, there's— cybersecurity is a huge field.

Maybe you love pen testing, maybe you hate it, I don't know. You know, go learn what you love and then go pursue that. Yeah, well, that's great. So I— my last question for you is, have you ever tried blacksmithing? I have never tried blacksmithing, no.

And that's, that's probably something I should go do. No, that has just never been something. You might be missing out on your calling. Yeah, maybe it's genetic. It's quite possible.

So a tip for you, there is a place called the Littleton Historic Museum in Littleton, and they have a functional blacksmith shop. Oh, cool. You can go take it. I don't— they do lessons, I know, as well. You could go actually do a little blacksmithing and see if great-grandpapa comes through through and you're ready to, you know, that might be your next thing.

That's awesome. It's a great suggestion. Yeah. And maybe you can start making some— I'm trying to think of some IoT security devices that could really help us out. That's right.

A little Forge. I'm a little vague on exactly how you do that at the Forge, but it's a possibility. Anyway, do you have any comments, questions, anything you want to throw out to the community? Any call to action for folks or anything? Get involved.

So I think that as cybersecurity practitioners, we all have an obligation to help those in need of cybersecurity help, whether it's a nonprofit organization or your favorite political campaign or the neighborhood senior center. Everyone needs help with cybersecurity. Not everybody has dollars to pay for it, and so all of us should step up and try to get folks to a more reasonable reasonable state. It's a great message. All right, Trent, well, let's touch base, like I said, maybe after the election season.

Let's see where you go, and I'd love to hear what's going to be next for you. Thanks, Robb. It's been great. All right, thanks a lot. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.

Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes