Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Rob Rack and Alex Wood. Welcome to Colorado Equals Security. This is episode 62 for the week of April 9th, 2018. Alex, what were we just listening to?
I don't know. It doesn't sound very familiar to me, Robb. It's like a blast from the past. It sounds like my high school to me. That was my high school, my high school free time.
So 25 years ago this week, Beavis and Butt-Head premiered on MTV. You know what that means, Robb? Hmm. We're old. We're officially old.
Yes. Many of you listening don't even know who Beavis and Butt-Head are.
Good stuff. Well, As a couple of reminders here as we start off the show, number one, we do have a Slack channel. This is a great opportunity for you to get to meet other folks in the Denver and Colorado security community. We've got about 400 folks on there right now. If you are listening to this, it is likely that you are subscribing on iTunes or Google Play, but if you're not, we would love you to.
And when you do, and to show your love of us, we would love it if you rated us highly, of course, but you know, Yeah, put it— if you could rate us in Google Play or iTunes, that'd be great. We also have a mailing list on the website. You can sign up to get the show notes delivered to your inbox every week. And finally, we have a Patreon. A Patreon is an opportunity for you guys to sponsor the show, help us pay for the cost of the hosting and the microphones and all that stuff.
And everything you do donate would only go to supporting the show. And we actually did have one new member of our Patreon this week. We had a $1 a month donor. So thank you for that. Appreciate it very much.
Yeah, exactly. So let's go ahead and jump into the news. First, this— there's a new flight launching from Denver to Paris, direct flight to Paris. Anyone who wants to get over there and go to the City of Lights, this is your opportunity. I think it's neat, the more international flights we get out of here.
Yeah, especially the nonstop flights like that. It did seem like there are some discounts as well, at least in the short term, like a couple hundred bucks for a flight to Paris. That's pretty amazing. Like, it costs only a couple hundred dollars to get there right now? Yeah.
Oh, how— why am I not there yet? I'll see you later. All right, let's finish this up first. So next story for us this week is that Denver tops the nation for small business growth this year. We actually got ahead of Seattle, which was number one last year.
Yeah, so there is a survey that's done by IHS Markit, who is in town, and another company, I believe, looking at job growth and wage growth in small businesses. And Denver came out on top. Yeah, they did this Denver survey combined with Paychex, which is a pay company out in New York, I believe. Yeah. So good, good for us.
I guess the good news is we're number one. There was some little bit of bad news in there too, which is that over the— across the whole country, small business growth has been going down the last couple of years. So hopefully we see some rebounding on that in the next year. So next, there is a new marketing campaign that has been started here in Denver to attract Silicon Valley workers out of the Bay Area and to Denver. If people don't want to spend $6,000 a month for their rent, if they don't want to have, you know, it take an hour and a half to get from their home to their office, you know, we're trying to appeal to come to folks out to Colorado.
Yeah. So this is a collective of companies here in Denver that are trying to do this marketing effort. Including Four Winds Interactive, SendGrid, Xero, and Ping Identity. Yeah, so obviously, you know, we have lots of opportunities for jobs here in Denver. We could use some more folks to help do the jobs, and obviously it's neat that they're trying to reach out to those highly technical people in the Bay Area.
Moving along, Conga, which is a document management and analytics company, has revealed another acquisition that they've made. Yeah, so this was a, uh, a company, um, uh, Counselitics. Yeah, Counselitics. That uses, uh, AI and machine learning to analyze contracts and, you know, pull clauses out of that and things like that. Yeah, Counselitics is a New York company with just a handful of employees.
Uh, we don't know how much it cost for the acquisition, but it is an integration with Salesforce and, and the ability to manage documents in there. Uh, looks like a pretty neat thing, and obviously we try and keep you on top of any tech news here in town, and that one looked fun to us. Next, the SamSam ransomware that affected CDOT looks like it's going to cost somewhere upwards of $1.5 million to remediate. Yeah, I know that this has been just a massive problem for us. SamSam is a relatively advanced criminal group that's been hitting different government entities with ransomware and using that to extract as much money as possible.
I have not heard anything to indicate that The CDOT paid the ransom. However, the $1.5 million has been incident response costs, you know, consulting costs, and probably impacted productivity, I'd assume. Yeah, the, the local state government angle seems to be, um, a big MO for them. I believe it was SamSam that hit City of Inglewood also, and also, uh, City of Atlanta, which was, uh, one that's been in the news lately. I think Baltimore as well.
Uh, yeah, very well could be. One thing that I noticed in the article that they said that they had a group of, uh, 25 core people working on this incident. Um, but at times ballooned up to as many as 150 people working on it. That's a, a big incident response. It's a lot of people.
Uh, ThreatX landed venture capital, uh, what was it, $8.5 million? I believe, yes. Um, so this is in a— this is not in addition to— we believe that this is a closing out of the run— the round of funding that we talked about back in December, uh, when we heard that, that they had raised money. We actually said $7 million back then. Uh, we— it looks like this is finalized now that they've, they've released more than the $8 million.
Um, and it's good for them to grow and, you know, double their presence here in town. Yeah, good for them. Also with funding, Chairwall Software, which is out of Colorado Springs, they are an IT service management company like a ServiceNow or something like that. They landed an additional $172 million in funding from KKR, which was already an investor in Chairwall. Didn't we talk about them getting money last, about a year ago?
Yeah, I think it was February of 2017, they got $50-some million So this is again another round of funding for them to grow. Um, in the article it says KKR really thinks they have a great growth potential. So, and they're kind of a ServiceNow competitor. Um, obviously that's a huge market. They've also now taken a lot of money, so they must be growing pretty, pretty quick.
Big. And they have, you know, big eyes ahead of them, it looks like. Exactly. Um, Swimlane has, has partnered with Lastline to augment their automated security platform. So Swimlane is the local play in the security orchestration and automation, really trying to automate as much of the security response as possible.
And it looks like they've partnered with Lastline. What do we know about Lastline? Yeah, so before this article, I honestly hadn't heard of them, but they look like an automated malware response and investigation platform. So basically, the partnership allows people using Swimlane to swim lane, um, to send their malware off to, uh, LastLine and get it, um, looked at automatically, saving people time. Um, seems like a perfect combination for a security automation company.
Yeah, very cool. Uh, and then next, um, there was a press release this week from Ping Identity. Um, there was somebody's name on it. I can't remember who. That might've been Robb Reck.
Um, RMISC, the biggest security conference in the region. So Ping Identity is one of the premier sponsors this year for Rocky Mountain Information Security Conference, and glad to see that Ping is putting out some press releases announcing their participation and how great RMISC is. Yeah, so trying to play it up wherever we can, right? I think it's going to be a great conference, and certainly it's an opportunity for us to make it more well-known wherever we can. Exactly.
Last news this week, Coalfire had a blog talking about sleuthing in the cloud, really the challenges of forensics and cloud environments. I think that this is a super important topic. We're used to doing forensics in a data center where you grab a, grab a machine, maybe you pull it out of a rack, or maybe you're making a copy of it and you're really getting that, that physical memory. It's different in the cloud. Everything's different in the cloud.
You're not able to pull anything, you're not able to, you know, to control the physical hardware in the same way, and a lot of the services are different as well. So this blog post kind of goes into some of what that looks like, and I think that they actually have some tools to help with that, right? Yeah, so for AWS, it sounds like that they have a service that can help do some of the pulling of those virtual machines or other information you might need for incident response. But I thought the article was great too, because it talked about some of the other cloud services as well. You know, I think a lot when you hear cloud, everyone says AWS, and then you hear, you know, whatever it is you can or can't do in AWS.
But the blog also talks about Azure and Rackspace and IBM SoftLayer, I think, and all the things that you can do in those areas too. I also like to draw a distinction between infrastructure or platform as a service and SaaS, your software as a service, where you really can't do any forensics in a SaaS platform. All you get is some logging information and you can make a request to your Salesforce or your Concur or Workday or whatever. Anyway, to me, you got to make sure you're careful what kind of cloud we're talking about around incident response. Exactly.
So that's it for the news for this week. So let's go ahead and talk about our Slack message of the week. This week we had a message from Trent Hein, who was our interview last week. Yeah. And Trent said, pretty much everyone here will give you the shirt off their back.
We all watch out for each other. Yeah, this is in his response to someone who is looking to come to Denver from Chicago, I believe it was, talking about what it's like here in Colorado. So thanks to Trent for participating in the channel and Big thanks to Andre Gaeta, who is our sponsor for this. Trent, you're going to get a free item from the Colorado Equal Security store. We look forward to more participation going forward on the Slack channel.
I do want to make one other winner announcement. Speaking of Andre, we had the Colorado Equal Security March Madness bracket, and Andre was the winner. He properly picked Villanova was going to be the national champion, and he was less wrong than the rest of us about the rest of the crazy upsets. So congratulations to Andre who gets a shirt out of that. And we also had a second category for the March Madness bracket, which was someone who would get to win the Colorado Equal Security thong that belonged to Alex before the tournament.
So yeah, there's this mythic thong that is out there that, you know, if you go out to our web store, you actually can buy a Colorado Equal Security thong from there. I honestly do not have one, but there's this myth that I do. So the loser of the bracket this year was going to get my mythical thong. Luckily for me, I lost, so I get to keep it. Congratulations, Alex, coming in last.
That's pretty good. I'd like to say I didn't just come in last, I came in really, really last. This was a bad showing in terms of picking my bracket. Very bad. All right, why don't we go ahead and move over to upcoming events.
As a reminder, we do have a calendar of events on the website colorado-security.com. It actually goes out just about through the end of the year now. Uh, ISSA Colorado Springs put like 20 things on their calendar this week, so we're kind of blown up out through the end of the year with our stuff too. But looking out here in the next couple of weeks, we have the ISSA Denver meetings coming Tuesday and Wednesday on the 10th and 11th. And that is lunch in Boulder on Tuesday, dinner in Denver downtown Tuesday night, and then lunch in the DTC on Wednesday.
Yeah, the National Cybersecurity Center is hosting a workshop, Beyond Bitcoin: Cryptocurrency and Blockchain for Beginners, on the 10th. This is down at their offices in the Springs. This is the National Cybersecurity Center doing this on blockchain. We might want to change this to crypto. National Cryptocurrency Center, maybe if this is going to keep up.
On the 12th, we have SecureSet's Cybersecurity Career Trends with Nadine Tanner from Rapid7. On the 17th and 18th, ISSA Colorado Springs is having their April meetings. On the 19th, SecureSet has a Career Conversations with Kevin Ford, Cybersecurity Risk and Security Specialist at CyberGRX. And then also on the 19th, uh, ISACA has their annual meeting. This is their big event every year.
They bring all their membership together. Yeah, talk about the past year, uh, give updates, that sort of thing. They're free for members, and I think they, they generally do some kind of like party-ish type stuff there as well. Yep. Yeah.
All right, so looking to jobs now, we have a couple of jobs from Ping still on the list. And as a reminder, uh, I am looking for a senior security analyst if you've got some experience Um, really looking for someone who's quite strong with Linux security, uh, networking security, application, uh, application architecture, web application architect architecture, and AWS would be the skill sets we're most looking for. Go out to our website. We also have a position for a GRC analyst, which was a lot, a lot more entry-level. Someone who has a background with compliance or regulations or legal would be great here, but 0 to 2 years experience is what we're looking for.
So Robb normally hogs the top of this job board, but I'd like to say that I have a job to talk about here as well. Uh, Pulte Financial Services is hiring a couple interns this summer. So if, uh, if you are interested in, in coming and hanging out with us and, uh, being an intern for the summer, uh, go ahead and check out the link there and apply. What would make an excellent intern applicant? So, uh, someone that ideally is in school potentially computer science or some other related field.
Doesn't have to be security. Someone interested in learning security, figuring out how it is that, that you can operate in an enterprise doing information security. Awesome. We also have one in here from LogRhythm. James Carder sent over to us a senior engineer on compliance research.
So this is someone who can really kind of walk the line between compliance and regulations, but being able to do engineering and automation for that work. Yeah, and, uh, Dave Harold over at Splunk sent us this next job. They're looking for a principal DFIR analyst. This is something that can be remote and work from anywhere. Cognizant is hiring an associate director of corporate security architecture.
Thanks to Jacob Rubin for sending that over to us. Prologis is looking for an IT governance risk and compliance manager. Redwood Trust is hiring an IT risk and compliance analyst. And Optiv is hiring a senior director in the office of the CEO. Sounds pretty impressive, right?
That, that does sound impressive. Yeah, I don't know what you'd do, but you'd be in the office of the CEO. I didn't even know he shared his office with anybody. So that's, that's a little surprising. And you direct seniors.
Yeah, there you go. All right. Well, that is it for the news this week. We are going to throw it over to our, to our feature interview with— was it Jay? Is it Prassl?
Yes. Jay Prassl. You want to talk about who's Jay? Yeah. Jay is the CEO of Automox.
So Automox is a startup based out of Boulder, and they do essentially, you know, patching and other stuff like that, trying to help solve that problem, asset management, things that we seem to have a hard time getting done well. So we had an interesting conversation with him about what they do and where they're looking to go. Awesome. Well, thanks, Alex. We'll talk to you next week.
Awesome. Thanks, Robb. Hello, this is Jeremy Cooper-Leavitt, Managing Director of Assurance at Charles Schwab. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
This is Alex Wood, and I am here today with Jay Prassl. Jay is the CEO and founder of Automox. Welcome, Jay. Hey, good afternoon. How are you?
Awesome. I'm glad we finally got together, get to spend a little time talking about you and what you do. You bet. So I think probably most people, I would say, are not going to be familiar with the name Automox. You guys are probably not the top of the list in terms of front-of-mind cybersecurity companies that are in Colorado, but I think we're going to hopefully change a little bit of that.
Before we get into that though, why don't you tell us a little bit about yourself, how you started, got into where you are, and your journey as a CEO and founder? Yeah, we don't probably have enough time to cover the whole thing in detail, but I can give you kind of the crib notes on it. I've kind of been in startups for really the last 20 years or so, primarily in the storage infrastructure space beginning with Left Hand Networks. I had the opportunity to be the 5th person at Left Hand Networks as that company kind of came on the scene in Boulder at the time and was really looking at kind of scale-out storage before iSCSI really became a thing. So we spent 10+ years there.
We sold that company to Hewlett-Packard. Then I kind of had a Groundhog Day style experience where I ended up getting introduced to a guy named Dave Wright down in Atlanta, Georgia, and met up with him who was building kind of the next generation scale-out data storage architecture. It was built on Flash. Kind of same thing happened. Joined him, invited him to come to Boulder and meet some of my friends.
We had the opportunity opportunity to bring a lot of the left-hand folks into SolidFire that gave us both some speed and scale. We've grown that to— I think it was about 500 people when we sold it to Network Appliance, so we had a good exit there. In classic early-stage style, I love that 0 to 250-person stage. Being part of the Boulder community and some of the tech scene there, got connected with— actually, a gentleman at this time was actually in New York at the time the CTO of something called PatchSimple at its beginning. He had this unique kind of technology about just simply trying to automate the patching of Linux machines.
I think at first blush a lot of people would kind of yawn at that. I think even when you talk to people about patching and config management and truly what is kind of cyber hygiene, people kind of yawn and be like, isn't that taken care of by auto-updates and things like that? As I began working with Mark and thinking about this project, we started to expand it and think more about not just the Linux space, but Windows and Mac machines. And as we kind of broadened the product and kind of expanded who we were going after, it was fascinating to see just with a very simple one-page website and a very simple product at the time that 7 to 10 companies a month would just kind of sign up for this. And so, and like many things where there's smoke, there's usually some fire behind it.
As we spent more time broadening the platform beyond OS to think about patching and maintaining configs that include third-party software and other configs within an endpoint platform, we really started to unpack the idea, or I guess more realize the idea, that this is a very unserved— or there is a problem that exists that has not been clearly and effectively solved in an elegant manner. That really revolves around endpoint protection and the hygiene that goes into that. I think one of the good examples is you see companies who now are taking data from things like Tenable and Carbon Black, and maybe you're using 5 different scanners out there in the world or vulnerability managers, and now there are companies that sit on top of that to help you decipher the news that those things are presenting, which to me is kind of an odd way to think about solving this problem. At the end of the day, we believe that there is a single basic 101 problem in the security space that simply isn't being done, which is people aren't staying on top of the OS and third-party software patching of their systems, and as a result, have a huge open issue from a security standpoint within their infrastructure. We've really designed Automox to automate and solve for that problem.
Entirely. Yeah, and you know, it's funny, everybody loves their shiny new technology and, you know, new blinky boxes and artificial intelligence and all this stuff, but you know, when you look at it, you go back to the SANS Top 20 or you go to NIST Cybersecurity Framework, other things, you know, building on a security program, the first couple things are always asset management and, you know, config and vulnerability management, right? Making sure you're patching and all that kind of stuff. Exactly. So, you know, I think that you're in a great place because it's— it really is one of those fundamentals that for a long time has been hard.
Yeah. And people haven't wanted to deal with, so they've kind of pushed it, pushed it to the side. Yeah. There isn't an elegant solution to it, right? And you think of it from an investment standpoint in early-stage companies, where does most of the money go, right?
Well, the money goes into what we really kind of determine as the detection side of things, right? You know, the red canaries, and the Carbon Blacks and all these others that exist potentially, let's say, around the fringe who are great at telling you what is going on, right? Those are valuable, super important tools. For us, those are partnerships and neat opportunities for us to relate to. I don't compete with those companies necessarily.
What we do find in talking to them is that when they scan or look at the vulnerability of an infrastructure, 60% of what they see of problems or of the news that they generate that has to go to an IT manager to do the fix, 60% of the problem is unpatched systems. Another 20% are misconfigured systems. The additional 20%, as it's described in talking to them, has to do with then the human bad behavior and other areas. Part of what's on offer with Automox is the ability to try and automate upwards of 80% of just the basics. There's no reason your high-paid IT staff should be spending time stopping what they're doing and responding to a list that comes from their CISO that says, go and patch this.
We want to take what is often a security exercise of stop what you're doing. Where are we with WannaCry? Do you know? How long is it going to take to figure out? Okay, how many systems are out there?
How will we patch them? What's the mechanism for all this? We want to take that entire exercise, the panic, the brainpower, and the time that comes with that, and take that from a security exercise and move it into an operational exercise. That this is something that should be automated behind the scenes. Now, I think for people listening, I think primarily in your audience, that listening to, I'm going to automate patching for all endpoints, and an endpoint being both the client side and the server side, I bet people sit up in the chair and be like, no way.
Not really sure I want to automate every aspect of this process. I think that's when we start to tease apart client and server infrastructure. On the client side, laptops and all that, people, I think, or our customers are much more willing to automate that process very easily. They want to get it on rails. They have certain things they want to happen automatically.
7 patches from Microsoft, deploy them. Don't send me an email, don't tell me something new, just do the work. That's the key of what Automox is doing, right? Okay, maybe the other set of those Windows patches I want to review. Fine, we can kind of set that up.
But on the client side, you definitely see— we see a very Windows-heavy customer who has some Mac and Linux boxes around, and they want to kind of put that on rails. But there also are then on the opposite side the server-side customers we have. And it's interesting, we have big customers like Thermo Fisher Scientific, you know, who are managing 5,000 Linux endpoints with the Automox platform. But as you get deeper into larger companies like American Airlines and others who in their server-side infrastructure, the desire to hit the full automation button isn't there yet. And that is absolutely the right way to go, right?
Because there's Right, they're afraid they're gonna break something, right? That's 100% the driver. As a security guy, you never want to be the person that causes the operational— right? And so this is the beautiful part of kind of where Automox is headed, is how do we solve for what I'll call a lack of confidence, right? I think of a patch or any update like a cup.
You don't know if there's gas in there or milk. And how does American Airlines actually test and figure out whether there's gasoline or milk in that cup? This is the proverbial, I'm going to hand the cup to you. That's what they do. They take 10 people, they give them those patches, they wait a certain amount of time.
It's fully arbitrary and it is made up. There's no platform of record. There's no way to automate that process today. Where Automox is headed, and we're early still in our lifecycle, but where we are headed is to be able to infuse that process with data. Because what's different about Automox versus maybe the SolarWinds system you're using or the BigFix system or even a Tanium system you might be using is that it is not on-prem.
It doesn't require server infrastructure, and you don't necessarily need, you know, a body to sit and manage it all day long. This is a cloud-based platform with a lightweight agent that works anywhere that endpoint is. So, you know, people who are geographically dispersed, who have mixed OS environments, they tend to be really the best customer for us. And people who want to go from problem to solution in a short amount of time, right? Because you think of what does it take to stand up a Tanium system?
You need a month and a person and a lot of time and, you know, a lot of money. A lot of money. Yeah, it's ridiculous. So we have some advantages from a cost perspective in the lightweight nature of the agent. Pull it down, it's on your machine.
If you literally just put the agent on your machine and walked away, It would look at the OS, it would look at the third-party software you have on there, and it would bring them up to patching spec without you ever doing anything. Now, one of the things we found is that, hey, you know, we got to kind of turn some of the automation back, give people more control, because it's like a driverless car, I think, is how— what I use as a kind of reference point here, that you're not going to jump in a driverless car today with— or a car with no steering wheel and just sit there and go for a ride. I wouldn't. I'm not ready for that. Doesn't feel natural.
Doesn't feel natural. And I think it hasn't— we haven't proven it. We haven't earned the right yet to jump in that car and feel totally confident. And I think the same is with the automated patching space. But I argue I could put you in a car with a steering wheel, but I could probably get you to put your hands in your lap.
We'll go around the block, right, and kind of build that comfort. So we don't expect companies to kind of come in and just close their eyes, hit the automation button, and patch all their infrastructure. But we want to give them steps and data that support the movement to that over time. We think we're going to help people accelerate that. You talk to customers, we talk to them all day long, we have a heavy inbound interest in our product, and they are all coming to us with the issue of, I don't know what infrastructure is there, I don't know its status, and when I find that out, I have no clear, quick way to solve the problem, and I'm also struggling on how to communicate that to my boss or other people in our company.
Automox has really kind of brought— we're bringing a single cloud-based solution to those really 4 key elements of the problem. What's there? What's its status? How do I patch it, meaning take action, and how do I communicate it? You mentioned some other folks that are in this space and have been in this space for a long time, including BigFix.
Obviously Windows has SCCM or other tools like that. This is a problem that people have been trying to solve for a long time. Why do you think people hadn't solved it already, and what's the big idea that you guys came up with that's, oh, this is why we are so much better? It's a really good question. I think if you look at it, You can approach this, your question, kind of from a couple different angles.
If you look at it from the Microsoft angle, SCCM, WSUS, it's interesting. That is a big driver for our business because people have trouble, very specifically, just even updating their WSUS server, which does what? Turn around and update all your other Microsoft servers, right? So there's that just kind of base mechanics of the problem where it's kludgy, hard to deal with, there's not an elegant solution to that. So we will ride often on top.
We'll have people either sometimes get rid of WSUS because they don't want to continue with that and use us in its stead, or sometimes they'll run them side by side for a little while and then kind of let the WSUS kind of come out of the system. But there are others like Tanium, BigFix, others that are out there. If you look at it from the Windows side, Windows solutions solve for Windows OS and Windows third-party software. That's it. You know, you'd have trouble getting into the third-party software side.
Something like Shavlik had come to the table a while ago and said, hey, we'll help you patch all the third-party stuff on Windows. Okay, here we are with 2 solutions. Now we're going to add something else on top of it to deal with Mac, etc. So when you think of it from one angle, there are certain solutions that solve just for their specific OS. Jamf, Microsoft-style tools, etc.
You go on the other side and you look at it from third-party software, and there are tools that solve just for that. Okay? And then there are some solutions that try and do many things together, à la BigFix or some of these others. And I think one of the things we see, and we see it in the Symantec systems as well, to manage OS, third-party patching, software deployment and enforcement, and configuration management. To actually handle that full stack, you often need 3 or 4 different products to do it and the people that you have to wrap around it.
So when you then look at it from a competitive angle and say, hey, what about BigFix, what about Tanium, what about Ivanti and that whole side of the world, it's— those guys are really— they have complex, heavyweight, expensive solutions that are difficult to manage. So we really attack kind of that segment of the market from a revolutionary and kind of, we'll call it even beautiful design of what it means to look at your entire infrastructure, ease of setup and use, and ease of communication. Because the things that Automox really is known for is not necessarily the fact that we can deploy the patch. A lot of things can deploy the patch. But what is the system that gives— makes it easy to see where you are, easy to deploy, low and lightweight cost and management, and to be actually very effective in not only seeing that status but then communicating it to someone else.
So there isn't necessarily always a big— we'll call it IP wizardry that's going on here, but it's about thinking about the problem in a more comprehensive way and thinking about it, frankly, in the way the world is operating now, which is cloud-based, at scale, and not geographically dependent or bound within a VPN or within the current firewall. So It is really the complement of cloud-based, cross-platform, the geographic independence piece. Bringing all those together shows a big differentiation. I think the proof has just been in the pudding with big companies that are calling us as a small company here in Boulder yet, who are reaching out to us saying, this is an unsolved problem for us. We like what you're doing, and we like where you're headed.
And that's happening on the direct side, which is cool. But what's been really interesting for us as a company, and I think you'll see kind of more announcements coming from us shortly on this, is on the OEM side. Can you approach patching an endpoint configuration as an API? Can somebody plug into Automox and say, let's take those APIs, we want to offer this functionality via our MSP platform or what have you, and say we want to just offer that tool. And so we're really positioning ourselves to be able to be very easy to plug into, very easy to use, and ultimately give just the CISO, but really more importantly in my mind, the IT manager, the automation tools to go ahead and act on all this key information.
And that's where neat combinations with guys like, you know, Carbon Black and AlienVault and others start to come into play, where Hey, they're generating a lot of great info. Here's a great tool that allows you to kind of complete the circle and actually act on the patch deployment, the config maintenance, or enforcement of a certain set of software that needs to be on. Yeah, because I know one problem that I've always run into with patching, that sort of thing, mostly around SCCM or other built-in kind of tools, is you figure out what it is that you need to patch, You send out a package to get these patches out there. It says, okay, I'm done. I did all the stuff that you told me to do.
Then you turn around and, you know, you run your vulnerability scanner, and your vulnerability scanner comes back and says, hey, you got all these problems, right? And then you've got 2 different systems here, say Nessus for example, or it could be Qualys or Rapid7 or whatever, saying, hey, you're missing all this stuff, and the patch management tool saying, Hey, we did all this stuff, and then it's never easy to marry those things together. So are you guys looking at that sort of thing too with this sort of API approach where you could marry those kind of systems together and make that comparison easier? Yeah, it's early stage there, but yeah, that is the goal of kind of the OEM side of our world is to not be the consumer of the Tenable-style feed, but to actually provide the solution that gets embedded, let's say, in something like Tenable that then is now offered to their customer base. So we're kind of positioning ourselves more— we'll call it, to use that terrible euphemism, that kind of Switzerland in this space.
Yeah, to give— we want to give that tool to as many people as we can rather than kind of having to carry the burden of every of aligning ourselves and working with Tenable and Qualys and the rest of them. And this is, it's interesting to bring up Tenable in particular, 'cause you probably know Matt Alderman, who's kind of how we got connected. He's an advisor to us at Automox, and his counterpart at Tenable, Ron Gula, who's the chairman and founder of Tenable. Ron and Matt actually found Automox Boy, I'll probably say maybe 6 months before I even really knew of them at the time. It occurred because they were looking for a way to close the gap of they can identify, they can show where the threats are, they can deliver the information, they couldn't take it the final step, do the work.
They found that thing called PatchSimple I was mentioning way back when. Ron's an investor and an advisor with us at Automoxie. Continues to kind of work closely with us as we go down the line. And I think it's one of the things you'll see in our kind of current press release that just came out with our current funding round is that we've really attracted folks from AlienVault, Carbon Black, Tenable, RSA, all to kind of invest because they all see the same thing we see, that there isn't a single platform of record that elegantly solves this kind of endpoint patching and config management problem. Again, it's not sexy.
It's not the latest whiz-bang thing, but it is basic 101 of a security stance that you have to patch your stuff. You could put other euphemisms in there if you like, but it's pretty simple. I think we're going to make t-shirts that just say, patch your you-know-what, to make sure that you're— because again, if you just simply patch your infrastructure and your third-party software, you would close down 80% of the attack surface. It's à la WannaCry, right? À la, you've seen the Apache Struts issue, right?
Just dealing— there's a Windows and a Linux vulnerability. 2 different teams, 2 different platforms, 2 different things. How do you know? I mean, come on. There's a better way to do this now.
We think it is a cloud-based single platform of record that can both give you the information you need, and actually do the work, because that is the thing that drives us— if anything drives us crazy, it's like, we should really go and do that. We should really patch those systems. Come on. There's a system out there that will allow you to automate that work. Let your guys go do something more important.
Yeah, and that's always been the problem too, right? So it's the security team owns figuring out what's wrong, and then somebody else owns fixing it, right? If I as a security guy can figure out what's wrong with whatever tools I might have, Tenable, whatever it might be, but then can obviously with either some approval or some guidelines click a couple buttons and it just goes off and fixes itself, that's a much better story than, okay, well, I'm going to generate a report and I'm going to use that report and I'm going to attach it to a ticket and I'm going to take that ticket I'm going to send it over to the infrastructure team, and the infrastructure team is going to take it, and then they're going to break it down, and they're going to spend days doing this and figuring out what they have to do. And then finally, they're going to come back and say, I don't understand this, or I can't do these things. Which of these should I do?
You need to get somebody else's approval, so on and so forth. I completely agree that if you can close that loop, it's a much more elegant solution. Even how do you know it's done? How do you know it's done? Technical or as your CISO, the only way you answer the problem is you schedule another scan and now you do a compare.
Again, you can route all that into a single system and I would argue instead of— because there are tools that will— I think Red Canary and others will do things like, hey, there's an issue. They'll deliver you something with a button that says quarantine this device or set it off to the side. Don't let it on the network. All good stuff. But that requires you to be in front of your email to see the button and to hit it.
We think that information will give you the opportunity to take another step instead of acting, which you absolutely can do on the fly, patch now, you can do that. But take it— I'd like people to take it one more step and say, hey, you know what, I see this problem a lot. I see that passwords are all wrong, or I see that, you know, these patches don't get applied. I'm going to create a policy here. That policy is going to always look for maybe a certain situation or a certain piece of software or an unapplied patch.
And when I see this, I'm going to take an action. And one of the things— and that's how we manage all of our policies, really, that way, with an evaluate and remediate step. There's an interesting part of the Automox platform that is not in any of the other tools that I think you see out there, which is a custom scripting tool. We call it a custom policy engine, and it works across Windows, Mac, and the Linux OS in the native scripting languages that those use. And the whole reason that exists is because there's no single tool that ever matches the endpoint customer exactly with what they want to do.
There's always an esoteric software, there's something they want that they— you don't have. So within this custom scripting engine, people can take the power of Automox and tailor it however they choose. I'll give you an example. We had a customer that said, hey, I've got a lot of these outdated Symantec antivirus pieces out on a variety of different machines. Can you help me find them, pull them off the machine, reinstall it with the proper version?
And can we just set a policy that, well, whenever one of those shows up, that it's just taken care of? The answer was yes, and we did it through a custom policy script. Look for it, take action, and here's the repository for the new one, be it local or in the cloud or whatnot, and apply it.
It starts to get both interesting and broad when you include this custom policy piece. That's one of the things that some of our OEM partners really are interested in because that's a level of power, if you if you will, for lack of a better term, that gives folks, especially if they have some DevOps and some scripting chops to them, they can really do some neat things with Autopilot. Yeah, so I keep putting numbers on my fingers of things I want to keep asking. One, so you've mentioned configuration management a few times too. I wonder if you could unpack that a little bit more in terms of what you guys think of in terms of configuration management and how that implements itself?
Yeah, I'm glad you asked that because I think you can use— some of these terms have a lot of different meanings to other people, like endpoint protection even, or endpoint. Any of those terms can be thought of in different ways. In terms of config management itself, we think of configuration— I'll call it really at a basic level at the endpoint. At the core, I think these systems have, for instance, part of a config is a software. What are all the softwares that need to be on this device?
Well, you can take Automox, you can set a series of required software policies. Think of this almost as eradicating the gold image requirement, right? And saying, okay, these are all the softwares that need to be on this device. And so when I take the device and add it to the group, it sees the gap and makes sure that those softwares are on there. So that could be thought of as from a kind of gold image standpoint, but could also be thought of as very specifically, hey, I need to have Carbon Black on this machine at all times, right, is one part of it.
So what software is on the machine is one part of it. The other part is from a configuration standpoint. We think of patches as that too, right, that hey, it has to be configured with a certain level of patches and these are the ones that need to be installed. So that's the other part. But the third part starts to kind of again get wide where configs could be something as simple like I want to make sure that the USBs are locked down.
People cannot turn them on and download data on all of, let's say, my finance laptops. I met with a company earlier this morning that customer data is really important. That's the thing. They need to make sure that that is always locked down on those machines. So they can write a custom policy, if you will, that allows us to enforce that on the device.
Password lengths is another common one. So you can continue to broaden that. We don't come to the table and say, these are the policies or the config policies that you have to set up. I think as we go down the line, we might have some packages, if you will, that say, here's one for PCI compliance and other things, and coalesce those together. But today, we really leave it up to the customer based on their corporate or industrial security requirements, from their industry and let them use Automox as the tool, if you will, to kind of get to that end and meet those requirements.
Yeah, I was thinking in my mind you have things like CIS benchmarks or something like that. Hey, this is a standard that has been put out there that says, okay, to be quote-unquote secure, you should configure things in this way. It sounds like maybe in the future you could have a package where someone checks a box and says, okay, you check this and we will make sure we enforce all of the CIS benchmarks. In a perfect world with enough money and people from an engineering standpoint, absolutely, that is a direction we want to head. We just have to choose our battles right now of where we're spending our time.
Really, it's about— for us today, it's focusing on bulletproofing this endpoint patching process itself. Because again, you look at Shavlik and you have to ask yourself, why isn't everybody using that? Or you look at WSUS, why isn't everyone using that in the Windows space? And there's clear reasons, because it's unpredictable, it works some of the time, not all of the time, reporting is hard. So we're really— I think it is the sin of any startup is to start to spread yourself too thin.
We're very focused on on solving that problem in a robust manner. Then I think as we go on, we'll add the CIS pieces and other elements to it. You had mentioned earlier that you guys are lightweight, you're cloud-based. There's got to be something on the endpoint though, right? This is an agent-based setup?
This is an agent-based solution, yeah. We probably should have covered that out of the gate, but yes. You put a small agent on the machine. It's about 5 megabytes. About 5 megabytes in size and extremely lightweight.
That's kind of— you can think of that as your listener, if you will. It's paying attention to what is on the device and then taking instructions that are coming from the cloud. When we see something like, you know, for instance, a Windows patch that needs to be applied or something of that sort, when we see the delta there, it's important to know that that agent is both identifying the gap and then the cloud component, if you of our platform is in saying, okay, let's take the Microsoft patch. And in most cases, we'll take it directly from Microsoft. It's important to know that Automox is not taking a patch, holding onto it for a while, and then deploying it down to the machine.
We feel there's a risk in doing that, both of corruption and there's a time problem in there. So we're really kind of— think of us as mediating the executable. Now, some people will host— they have a WSUS server where they're caching those updates. And things like that locally, we can easily point our system there. Oh, that's nice.
Yeah, so you've got some flexibility on where that repository lives for sure. But the agent is extremely lightweight. We actually work with Dijon here in Denver who does desktop as a service, right? And they had an interesting problem. Their desktop's on a USB stick.
All right, so tiny. It goes in the pocket of folks who are in call centers. They come in, plug in. How do they update that OS and that image? How do they maintain its configuration?
Well, they used other products or tried, and they were heavyweight agents. They took up a ton of I/O and overhead on the system, just cratered them. It could not work. We have worked with their team, and now we update all of the DISH desktops, if you will, because the Automox agent is really just built as part of their image. That sits on all those USB sticks.
So it's kind of a neat build design win, if you will, for us. They're a great partner of ours, and it's a neat way to maintain and make sure that all the desktops— I think most of them are Windows in their case— are up to date and configured properly all the time. Yeah. One of the other things that you had mentioned earlier was around the server side, and you never want to break anything. You want to make sure that doing these patches is tested and that sort of thing.
But you also mentioned the way that most people do it, which is, all right, we're going to install a test group. We're going to let it sit there. If nothing breaks, then we'll go forward. That must mean everything's okay. You mentioned giving data to try and help make that process better.
What are you trying to do in that area? Is it testing scripts or is it— How does that work? So there's a crawl, walk, run component here, and I need to— you need to know and your audience needs to know that this is kind of where we're headed, right? This is not in the platform today as we speak. That's kind of stuff that's on the way.
But there's— and we think of it from a kind of a crawling and walking standpoint. There is the base ability that we want to develop for our customers that say, okay, you have a process today. You know how to drive the car currently. And yes, your process is giving patches to people and testing for their success or failure and then moving that forward into production if you choose. There's simply the automation of that process.
You talk to University of Colorado or CU Boulder, they do it via a spreadsheet and they have 12 people on their staff and that's how they do this process So there's the crawling part of this is simply the, can we automate that piece for you? Here's the group of patches that we're gonna test. They move through these certain gates, and then upon success or failure, you can deploy or not, right? So that's kind of step 1, if you will. But as we look down into the kind of the walking and the running part is you can think of Automox ultimately as kind of a sensor network.
Ability to see the complexion of an endpoint. We can see the complexion of the update or the patch that comes together. And what we'd like to do, and again, this is not in the platform today, but something we're very excited about, is can we look in just the rearview mirror? Can we say, hey, I know the complexion of this endpoint, I know the complexion of this patch or update, and looking in the rearview mirror, I've seen this combination many 10,000 times before. Can I just surface that data for an IT manager to see that that has been successful and allow them to raise the confidence to be able to deploy that patch, let's say, or update more quickly.
I think long-term, I think you can— your listeners are a smart group of people. They're probably thinking, well, if you can look in the rearview mirror, can't you look out the front of the windshield and maybe be predictive of success and failure? I think, yeah, I think there's an opportunity to do that. We're going to go down that road, but the data to me is, I think, one of the most powerful things. Think of something as simple as, okay, you've got 10,000 Mac laptops in your organization.
What's the variance of those? When I have to really test something there, how many permutations do I have to consider? And we can really— think of a scatter diagram in your mind— we can help you understand where these— what this distribution looks like and just allow you just some very basic data that you're just blind to in just about every other system to help you understand, just to guide your process a little bit better. Again, there's kind of a crawl, walk, run here, and I think when you think of server infrastructure overall, the comfort level of people going into full automation and just deploying patches willy-nilly, that's not— that's a hard audience to win over, right? I think how you move them more towards a comfort level being willing to patch and manage those endpoints is going to be through educating them and giving them more info that details, hey, you know what, as we mentioned before, this cup is full of milk and it's easy to drink and you're going to be fine with it.
Go ahead and deploy those into production. It's not going to break anything. There's a lot of greenfield here. I don't want to oversell what we're doing, but I do want to indicate the level of thinking and how we're approaching this problem, which is not just blind command running. There's a more intelligent way to solve this problem, and I think data in the world that we live in today really supports that.
Again, we're seeing large companies willing to manage what was classically an on-prem, behind-the-firewall type of approach are willing to manage that process through a lightweight cloud-based infrastructure and largely do not want the cost, time, education that comes with something like BigFix. I mean, when you really look at what is, what is most of the work of managing an endpoint, where's all the work? It's in making sure it's patched, configured correctly, and up to date. I think, again, if you can automate that process, it's our belief that you're going to solve a big part of a longstanding problem. On the automation piece, a lot of what is buzzing around today is DevOps and even beyond that, moving out with containers and all this kind of stuff where you're I've seen the promise of people saying, well, you're not going to have to patch anymore.
You just update your repositories. You tear these servers down. You pull them back up. Or even beyond that, in a container, it's not even actually a server. It's some components.
Again, you're making sure that those components are the latest, and when it gets torn down and a new one comes back up, how do you guys see that and where do you play in that kind of space? Do you feel like that really could take over for fixing this kind of problem on the server side? Yeah, so that kind of ephemeral infrastructure, containers that tear down and the buildup of them, I think is absolutely— continues to be where I think things are headed. The DevOps teams, even Automox, we use a container-based environment, so we're doing similar things. Yes, at the core, a way to update a container or revise that container and make sure that it is patched is not actually patching it.
You chuck it or tear it down and build it again with the new base image. But one of the most important parts, I think, of that process is you've got massive amounts of containers. You've got to know what they are, what their status is, and there's an orchestration element of understanding what needs to be updated and torn down and rebuilt. How do I move that service off to, let's say, another container while I tear down and rebuild this one? And the orchestration of that process is something that Automox, we feel, has a good hand to play in as we go down the line.
I don't think it flips over tomorrow where everything becomes containerized infrastructure, and that's why we think we kind of earn the right, if you will, to orchestrate that process for people in the very same way we orchestrate the Hey, this virtual machine or this server is not patched, it's at the wrong level, and allowing a customer to set the parameters of which that both is evaluated and remediated. We think we can do the same thing in the container space as well. Yeah, that sounds really cool. Yeah. So I want to pivot just a little bit.
Sure. We are— we're getting a little bit towards the end of time, but I want to hear about where Automox is today as a company, not what what you guys do, but how big are you? Where are you in your— you mentioned funding earlier. Where are you in your lifecycle? What do you see in the future from the company perspective?
Right. So we are growing like a weed right now, which is a lot of fun. It's a fun time to be at Automox because we're about 20 going to 27 here in the next probably 6 months or more. So that's kind of a look at kind of the size of the team. All those folks are in kind of Boulder, Colorado proper.
We do have a few folks offshore as well, so we've got a team of about 6 or 8 over there as well. And so that's where most of the, the work is happening, both from a backend and frontend side, is happening kind of in Boulder. We just closed a $2 million financing round that was led by Blue Note Ventures, which is in Boulder proper. You can think of it as an inside round, but we had the opportunity to invite a lot of the names that I've been mentioning to come to the table. So you'll see in that press release guys like Mike Viscuso and Tim Belcher and Ron Gula and others from Tenable and AlienVault, etc.
All these folks kind of coming around and being part of this investment round. As we move forward, we're obviously excited accelerating our revenues, growing our OEM partnerships. And again, we're hiring upwards of 10 people over the next 6 months. So for those of you listening, looking for something new to do and want to be a part of an exciting growing company with— and I think important to know— with folks who have done it before, right? This is my third time around the horn.
We've got a number of kind of the veterans from my time in the space and bringing others to the table. So it's, I think sometimes when you use the word startup, it can be thought as small first-timers, you know, big eyes and big dreams. You know, this is very well rooted in reality. This is very much solving a targeted prevalent problem in the space. So it's an exciting time to be growing a company and we're thrilled, right?
Every WannaCry, Petya virus, that comes out, it's, uh, you know, it is just more gas, uh, into what we're doing. Awesome. Um, so what do you see as, as a more long-term picture? You obviously, you took a little bit of money, now you're growing. Yeah.
Do you feel like, um, you're going to continue growing the platform? Do you see, you know, you guys are— I see, you know, you go a couple ways, right? You could continue to make it a larger and larger platform or you can continue down a more narrow focus trying to solve this sort of specific problem that you're talking about. And then a lot of times if you go down that narrow route, all of a sudden somebody's gonna come knocking on your door and going, hey, we're missing this narrow solution that you guys provide. Do you wanna come join us and be part of our bigger platform?
Yeah, it definitely, those things happen, right? Having been through this before, the focus is, is one of the key parts of, I think, successful early companies. But, you know, when you're successful in doing something well, yeah, people come by and be like, hey, that's, that's neat, or we're missing it. But the vision at Automox is really we want to be the protection platform behind every endpoint. And we think we do that successfully through these kind of OEM and partnership strategies that we have that allow people to embed our technology broadly into their platforms and go forward from there.
Even though there's often a, yes, we want to add you into— we want to be the only ones that have this function, you can certainly expect that to come around.
I think that's our burden to bear, and whether we can, as we move to market and continue to broaden who uses our platform, we think that's a more compelling road ultimately down the line. Now, you know, we're all capitalists. We're here to have some fun and continue to offer a great product to the market, but we're just going to have to see as how that develops over the coming years. But really, when you think about being the protection platform behind every endpoint, again, people on the other end of this call might be going, every endpoint? What the hell does that mean?
Right? And so now you can lean into networking infrastructure that needs to be updated. You can lean in a lot of different ways. Today, we're very focused on client and server infrastructure. That's— we want to kind of earn our stripes there.
But you can certainly play this out further. Your internet light bulb, your internet baby monitor, what have you. We haven't necessarily been hacked or exposed via those things quite yet. How do you update them today? Well, you throw them away.
Over time, I think there's an opportunity for Automox potentially to play a role in that space as well, as these things need to be identified, updated, and, if you will, kept patched, be it at the firmware or software level.
Should General Electric write that code into those tools? I would argue no. I think they should use patching as an API platform that they can plug into. And let something like Automox, whose expertise and focus is in that space, handle that problem. We think there's a lot of scale to be gained there over time.
Hopefully I haven't tipped my hand too much, but there's some interesting places to go there that we're excited about. Again, it's early days, and that's why if folks are looking for something new to do and have a strong skill set, we're on the buying side of that all day long right now. Awesome. Well, Jay, we're just about out of time. Anything else that you wanna talk about real quick before we wrap this up?
You know, I think I would encourage folks, if you're— if what you hear, the folks listening find what they're hearing interesting, they can go out and just grab a free trial from Automox. There's no cost to this, there's no credit card to put in. You can simply just download the agent just onto your laptop, see what happens. How exposed are you? Do you know?
I think it's an interesting question to ask. We find people who do that often kind of go down the hall to the IT manager and go, hey, take a look at this. Look at what's going on. I would encourage people to do that. They can do that at automox.com.
It's real easy to do that way. If you're kind of a Twitter follower, you can follow us on Automox App out on Twitter and kind of keep track with us that way. But if you have any questions, feel free to reach out. You can reach me directly at jay@automox.com. So it's always the fun of early companies, right?
You get your first name and the rest of your suffix there. So feel free to reach out that way if you choose. Awesome. Well, thanks, Jay. I appreciate your time.
Likewise. Thank you. Great conversation. Yeah. And this is Alex Wood, and this has been Colorado Equals Security, and we'll talk to you next time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.