Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 66, the week of May 7th. Alex, it's finally it.
It's finally RMISC week. Yes, or as you like to call it, Security Mardi Gras. Security Mardi Gras. It's the big week. It's RMISC and it's Denver BSides.
Yes, fun stuff. Basically starting Tuesday morning all the way through, I don't know, midnight Saturday, you can do nothing but talk to security people and drink and hang out and do whatever else you want to do. Learn. Yeah, it should be a lot of fun. Other stuff like that.
Yeah, I'm really excited. We've had a lot of planning going to RMISC. It's that point in the planning process where I'm ready for it to be done. Um, so I'm really looking forward to this week happening. Yeah.
And of course you have your, all your speaking ready to go, right? You got it all figured out. I'm 100% prepared. 100% prepared. I love it.
Good stuff. Well, why don't we go ahead and dive into some stuff here? Uh, number one, of course we do have a Slack channel where you guys can all come and participate as a part of the neighbor, uh, the community. Uh, the, the link to join the Slack channel is in the show notes and on our website at colorado-security.com. Also, please take a moment to review us on iTunes or Google Play.
We hope that you enjoy the podcast and we'd love to see you show it there. And we have— we also have a Patreon campaign. Patreon is a way that you can support us on an ongoing basis to help pay for the logistics of the show, help us pay for the hosting fees and all the various costs that come along with doing this. And we do have a shout out and a thank you this week as well. Yeah.
So we had a new $10 a month donor this, this week. Kyle Vander Zanden, thank you very much for, uh, for doing that, and we will get you your, your t-shirt out here very shortly. And then last announcement here, we do, as a part of kind of this whole Colorado Equal Security movement, we put together Security Leader Dinners or CISO dinners on a monthly basis. There's some information about them on our website. Take a look.
If you think you are eligible to attend, send us a note through there. And of course, if you'd like to sponsor, it is an opportunity for you to get to know about 12 different security leaders here in an exclusive sponsorship opportunity. Sweet. So big news, Robb. Giordano's, the legendary Chicago pizza joint, is coming to Denver.
This is fantastic. And it looks like they're actually going to beat In-N-Out, the legendary California hamburger place, into opening their first place. Yeah, looks like sometime midsummer. I think that they're still working the logistics, but it's going to be down at 16th and California, down on the 16th Street Mall. So just a few blocks away from my office.
So Robb is gonna get fat. I, I think there's a decent possibility of that. Unfortunately, the lines will probably be so long that I will not have the opportunity to eat there for the first little while. That'd be my guess. You could probably go for dinner.
You know, it's a little quieter down there for dinner. Anyway, that's good news. Next bit of news we have is actually kind of a meta story about a whole bunch of different schools here in Colorado who are doing kind of research around improvements for the body and different ways to monitor the human body. Yeah. So, you know, they're calling it bioscience.
So CU Boulder, CU Denver, CSU, and University of Denver all have bioscience programs. And through that, there are, you know, obviously research and then comp— you know, companies that come out of that as well. Yeah. And so really interesting stuff. They, they have a bunch of examples, maybe like 6 or 7 examples of the types of research they're doing.
I pulled out a few that I thought were interesting. There are color-changing tattoos that can show you like different, different changes to the body, alcohol level, and, you know, I guess glucose levels and stuff for folks with diabetes, kind of, you know, interesting ways to see what's going on. Yeah. So you should put one of those like right in the middle of your forehead, right? Just so, you know, people can know when you're drunk.
I want everyone to know when my testosterone levels get too high, right? Another, another interesting thing they're doing is they're creating e-skin. So this is, you know, fake simulated skin that can be used for robots, but also it looks like maybe to, to help replace skin for folks who need it. Yeah, also lots of sort of science fictiony things in here, you know, working on tissue regeneration.
And then one that I thought was sort of interesting too, that You know, there's a knee brace that they're using that will generate energy. So not just keep your knee in place, but also generate energy along the way. So you can like charge your phone? Is that what you're saying? Yeah, you know, something.
Is that what we're talking about right now? You know, I gotta have my phone last all day, right? I like it. So moving on, SendGrid, one of the local tech companies here, has released some information about their own diversity movements internally. Yeah, so, uh, I think we know SendGrid this year had their IPO, did really well, um, great growth, best financial year ever, and they had some great increases in the diversity of their workforce as well.
Yeah, I think a couple of key stats here. Number one, they're at 35% female employees, which is pretty high for a tech company, very high for a tech company. And then they also— well, as a part of this, there's a quote from the article that says that, uh, the Denver-based Pipeline Equity did some research and found that for every 7% increase in gender equality, there is a 3% increase in revenue. So the more equal you see things, the more money companies make. Yeah, that's pretty cool.
So congrats to SendGrid. Um, next, uh, not some good news. CenturyLink announced that they are cutting about 2% of their workforce, blaming automation and, you know, some fallout from the merger with Level 3. Yeah, it's about 1,000 people. That would be impacted if they go with a 2% cut.
You know, this is not surprising. This is what you get when you do mergers and acquisitions. It is just disappointing to know that, that it's happening now and it's probably going to impact some of the folks here in Colorado. Yeah. And that, that cut is not just in Colorado, that is nationwide.
So it's, you know, we're not losing 1,000 jobs here directly in Colorado. So next story here is not so much a story as a plea to action, calling you guys to action. If you remember last year, the Denver Startup Week, we had a Colorado Equal security panel where I was a moderator talking to some founders from local security companies. Well, we are resubmitting that, that same panel to try and do it again this year. Um, so there's a link in the show notes to, to go and have you guys vote, and you'll be able to— if, if we do get into the show, you'll get to hear founders from ProtectWise, Red Canary, Swimlane, CyberGRX, and OverwatchID.
Those are the folks who are on the panel this year. Nice. Um, and just in general too with Denver Startup Week. You know, there's lots of other potential sessions that are out there, so go take a look. And if you have an interest in hearing some of them potentially at Denver Startup Week, give them your vote as well.
I already voted for you, Robb. There are a bunch of security talks out there as well, so this is not the only other one. Go, go ahead and take a look, and maybe we can turn Denver Startup Week into Denver Cybersecurity Startup Week. Sweet. So Microsoft has opened what they're calling a Startup for Big Business in the Tech Center.
This looks interesting. They have about a 10,000-square-foot facility in the Tech Center near the Oracle buildings. Really what they're looking to do is use that as a place for businesses to come ask questions about innovation, you know, help with digital transformation. They're actually going beyond that and saying you can even just use the rooms to meet with folks. They do have— and they're opening it for community groups, and I believe ISSA Denver has met there as well already.
So Obviously we're taking advantage of this now. Um, they do have one caveat, which is that you cannot charge a cent while you're there. It all has to be free. Yeah. So this, um, this reminds me a little bit of, uh, Microsoft Store but for businesses, right?
So they're, they're trying to give some space and help people, you know, figure out how to use the Microsoft products. Yeah, very, very cool stuff. Anyway, good opportunity. I'm looking forward to swinging by there and take a look at it. So in, in the, uh, from the file of marketing must have written this headline, we have a blog from LogRhythm entitled Augmenting Your Cyber Resiliency Strategy with Next-Gen SIEM.
So Robb, when you hear that title, what do you think that the blog is going to be about? Um, about places that I can buy things? Potentially, yes. Um, so the blog was mostly about the partnership that LogRhythm recently entered into with Mimecast. So Tighter integration between Mimecast's email security and the LogRhythm SIEM, which I think is really cool.
The email threats are a big issue these days, and having that tighter integration is great. You know, looking at that headline, I wouldn't have really thought that's what it was about. Yeah, but good on that partnership. We do love the folks at LogRhythm. This is an opportunity for us to maybe tune our headlines just a little bit.
On the next headline, This is sort of the opposite of that. This is telling you exactly what is in the, the blog post. So, uh, from ThreatX, we had a blog called New from ThreatX: Enhanced Edge Caching, DDoS Mitigation, and Bot Detection. So when you look through the blog post, the first section is all about their new advanced edge caching and site performance testing. Uh, anyway, I, we, we included this because we haven't talked a lot about ThreatX.
They are a local security company. They're, they're trying to be one of that, you know, next generation of WAF technologies. Um, so here's some new features that they've released, um, you know, enhanced site profiling for DDoS mitigation and then bot detection. You know, can you tell real users from, from bots on the web? Cool features.
I think it's worth taking a look if you guys have any interest in the WAF market right now. Yeah. Um, next blog, uh, it was from Automox. Uh, we had Jay Prassel on the show not too long ago. Um, this one is, uh, is sort of a third in, in this series, right?
So we had one that doesn't talk about what they're, uh, what it's about, one that gives you exactly what it is, and this one, you know, sets up a little bit of mystery. So it's about, uh, WSUS or SCCM for patch management. Which one is better? Yeah, so which one is better? Uh, if you have Automox's perspective, the answer is Neither, you should buy us.
I do think it's worth taking a look to understand what are the challenges with either of these technologies and understanding, you know, if you're using these, are there gaps in what you're getting from your technology right now? Yeah, exactly. And our final blog this week is by Mitch Tenenbaum. I think this is the first time we've had one of Mitch's posts on the show. This is pretty relevant and something we've talked about lately.
Log in using Facebook ID, understand the devil's bargain you make. Basically, what he's talking about here is what are the negative consequences if you do use Facebook for your federated identity. Yeah, so, um, surprise, surprise, if you do, you're giving up some of your privacy. Yeah, yeah, there's the punchline. There you go.
All right, that's it for news. Why don't we go ahead and slide over to the Slack message of the week? As a reminder, thank you to Andre Gaeta for sponsoring this. This is an opportunity for us to recognize someone who's, who's helping lead discussion in the Slack channel. And this week, Alex, who do we have?
Daniel Ayala. Congratulations, Daniel. So he gave us the news this week of the issues that Twitter had with putting everyone's passwords in their logs. So Twitter this week announced that they inadvertently were storing everyone's passwords. So you should probably go out and change that password.
Thanks for Daniel bringing that to our attention. Good stuff. And as a reminder that there is a link in the show notes to join the Slack channel. Moving over to our events calendar reminder, we do have a calendar of events on the website, so colorado-security.com, jump over to the events section. Uh, first on the events this week, on the 9th, CTA is having their CTA 101, and then we do have Rocky Mountain Information Security Conference all the way from Tuesday to Thursday.
We've— I know we've blown way past 1,000 attendees already for the, for the show. Um, we've, we've sold out the entire exhibit hall. Um, we've got a great lineup of speakers. I don't know what else there is to say about it, right? I think the one other thing I'd like to mention is, uh, Tuesday night the 8th.
So we are, we're having what we're calling Community Night. And so we have, um, ISSA, ISACA, OWASP, Cloud Security Alliance, and InfraGard, um, all, uh, giving presentations, talking about their chapters, what it is that they do. So Um, if you're a member of one of those organizations, great, you should come down and hear it. If you're not, um, then you should come down and, and learn about them. Or even if you are one, you can learn about another organization.
We're also doing a job fair during that time. So we have a number of companies, um, that are setting up tables, uh, talking about their open security jobs. So if you were a job seeker, uh, come down and, and try and get a, uh, talk with one of those folks. Yeah, it's both, it's both enterprises that are hiring and some recruiting companies that are there looking for folks. Yeah, also sponsors or exhibitors.
So, you know, could be security companies that have open jobs too. And now you do not have to have registered for the conference to come to that event Tuesday night, right? That is correct. It is open to anyone. And what time should they show up?
So it is between 4 and 7. All right. So come show up a little bit before 4 o'clock and you can learn about the local community groups and maybe get yourself a new job. And so, as we mentioned, B-Sides is coming up right after our MIAC, and that's happening at the SecureSet campus right across from Coors Field this year. CSA on the 15th is having their May chapter meeting, and on the 15th and 16th, ISSA Colorado Springs is having their May meetings.
DENSAC is doing their monthly meetup on the 16th. ISC2 Denver is having their May chapter meeting on the 17th. And on the 19th, ISSA Colorado Springs is having one of their many seminars. All right, let's go ahead and jump over into jobs. Uh, number one job on the list, number one in your hearts, number one on the list is, uh, the Senior Security Architect at Ping Identity.
Looking for someone who's got a strong technical background, who understands the underpinnings of the technologies you've supported, hopefully some Linux background, some network background, and, and looking to have someone who's a real senior contributor to our infrastructure security team. Sounds like fun. Ardent Mills is hiring a director of IT security. So I looked, I looked them up a little bit. Ardent Mills, they do, they make food, like they're making flour and so forth.
Nice. Didn't know that was here in town. Like an actual mill. An actual mill. Yeah, I, I didn't guess it.
Moving along, Layers Consulting. This is Chris Nickerson's company. They are hiring an AppSec practice lead. So you want to be in charge of the offerings around application security assessments and consulting, that's great. This is also a hands-on position though.
It's not just someone who can manage a team. Cool. ReliaQuest is looking for a solutions engineer. The link that we put in the show notes for this shows a different city, but they made it clear that they're looking for someone to do this exact same job in Denver, so don't be afraid to apply. Twitter is hiring a security engineer on focused on tooling and automation here in Denver.
That could be fun up in Boulder. Yeah, very cool. CableLabs is hiring a security engineer. LogicWorks is hiring a senior cloud security engineer.
Xcel Energy is looking for an associate cyber defense center analyst. So read someone who works in the SOC. But that should be fun. Yeah. Denver Health is hiring an information security or information systems security analyst 3.
Yeah, 3. Number 3. And then the final job this week, One Neck IT Solutions is looking for a cybersecurity analyst 1/2. And the reason that I put this one on here is I think that One Neck has the stupidest name of any company. Oh, man.
You know why they call it One Neck? Why do they call it that? Because you have one neck to choke. Yeah, that's pretty good. Pretty good.
Not good. Not good. Moving along, we are done with the news now. We have the best part of the show coming up. Well, the end, but before the best part of the show, we have the feature interview with Brian Beyer.
We actually interviewed Brian a little bit over a year ago. He's a founder and the CEO for Red Canary here in town. We wanted to get back up with him and see how things have changed. They've had a lot of changes over the last year. I am interested in hearing it, looking forward to it.
All right, that's it for now, and we'll see you guys at RMISC in just a couple days. Thanks, Robb. See ya. Hi, this is Sam Masiello, Chief Information Security Officer at Gates Corporation. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
This is Robb Reck, and I am today sitting in the new-to-me headquarters for Red Canary with Red Canary founder co-founder and CEO Brian Beyer. Brian, first thing I want to talk about is I understand recently you've embarked on a great adventure to put together— did you say it was a 7,500-piece LEGO set? The Ultimate Collector's Edition of the Millennium Falcon from the LEGO crew. So this started as with our boys who are 2, 4, and 6 years old. We have a lot of fun building LEGO sets.
Yeah, and as we go to the LEGO store, it's become kind of this question of what is the biggest LEGO set we can possibly get. And so I want to say 2 months ago or so, they released this new set, and it is, I think, the biggest LEGO set ever created. 7,500 pieces. A lot of pieces. I think it creates a Millennium Falcon, or it results in something that is 3 feet long.
Okay, 3 feet long. So this thing is going to be massive. That's, that's great though. Hopefully 3 feet long with some stability so it doesn't break as soon as you get finished with it. So we are, we are 90 minutes into the build so far.
Okay, we've gotten through 2%. We've gotten through half of the first bag. I think there are like 17 stages of bags. Okay, and so that's how long it's taken, and the only thing we've built is effectively the A-frame. Yeah, that is just going to be the center structural support.
And so it's actually quite fun. There's this huge instruction set that walks through the structure of how they had to design it in order to make sure that it was stable. It's a lot more engineering that goes into LEGO sets than I realized. So as I visualize the bear house, is this on the dining room table for the next 2 and a half months? Yes, we actually went from a trade-off of— we used to have 2,000 Red Canary t-shirts in preparation for RSA there, and now we are going to have 7,500 LEGO pieces.
Is it, is it really on the dining room table? Uh, so because we had just started it, I actually took it all off and set it on the fireplace this weekend. Okay. As soon as we dive back into the build, it's going to take over the entire table. That's fantastic.
It's huge. It actually was quite embarrassing after buying it at the LEGO store. Yeah, I'm walking out of the Park Meadows Mall carrying this massive box that weighs 50 to 60 pounds, feeling like a very strange, abnormal person walking through the mall with this big Lego box. How big a box is this thing? It's probably 2.5 feet tall by maybe a foot and a half inch, or a foot and a half wide.
So it's a good size, and it's heavy, man. That's— yeah, it's not, it's not what you normally expect to be carrying as you walk out of the mall. But no one's gonna steal it and run. No, that's for sure. They're all confused because it's a big gray Lego box.
Well, that's pretty fun. So is this the first big LEGO set, or is this just kind of the culmination of many building up to it? This is— so as we've talked about, I have a bit of an obsessive personality, and so when it comes to things we do, it's either family or Red Canary and tend to be all in. And so I guess that carries forward here. When we decide that we as a family are going to do a LEGO set, we're just going to go straight to the biggest one.
So does your wife also participate? Participate in this? I think she's mostly participating to make sure that our 2-year-old doesn't run off with half of the pieces and build something on his own. Well, there you go. It's, it's definitely a large enough project that it's fun to do as a family.
Good. Well, cool. Let's, uh, let's circle back and talk a little bit about work. We actually met about a year ago. You're one of, one of the first interviews we did on the podcast.
Um, I, I don't think we should assume that everyone listening now has listened before. So if you don't mind, you know, at a high level talking about what Red Canary is, how long you've been around, and really what services you provide. Yeah, absolutely. So we are a little over 4 years old now and started really to build what is a cloud-based service to identify any sort of cyber attacks or threats on your endpoints. So if you're running anything that runs Windows, Mac, or Linux, we have a combination of software as well as a security operations team who identifies bad things and tells you where and helps you respond.
So headquartered in Denver. Yeah. Been growing the team here for quite a while. We're about 55 people or so spread out throughout the country now. How many were you last year this time?
30-something? I want to say 30. We've probably just about gotten to 30. Okay. Yeah, that sounds about right.
And so you, I think in the Forrester Gartner world, they kind of call what you guys do managed EDR. Does that resonate with you? We've run the gamut. Do you not like labels? No, we've— yes, we've given up on labels because there's no label that actually describes what we do.
We have sat in the EDR bucket, so pure endpoint detection response, the MSSP bucket, which is a terrible bucket, no offense to any MSSPs out there. No, you can offend them. They're mostly pretty bad. Then Gartner attempted to solve that problem by creating the managed detection and response bucket. Which then had most of the managed detection and response vendors, or the MSSPs, rebrand themselves as MDRs.
And we came to the conclusion that none of these labels actually describe what we're trying to do, which is build this proactive blue team who is vigilantly defending your systems 24/7, all day, every day, in the exact same way you would want to build it yourself, but in general, you don't have the millions of dollars to go build that team. So this doesn't sound all that different than the same way someone would pitch your traditional MSP. But as I am a customer, as a customer, I can say that, you know, it's significantly different in that you guys have a much narrower scope on what you're keeping your eyes on and really what telemetry data you're bringing in, right? You're just focusing on endpoint data. From CrowdStrike and Carbon Black right now, and you're not also getting my firewall logs and my IDS logs and whatever else I might have pointing into a SIEM.
So I think that's a good summary for kind of where you guys are. I think one thing I think it's worth drilling into a little bit more is the agents that you guys ingest from, on their own would generate alerts, right? But you guys are not just— you're not depending on the alerts from those agents. Maybe talk a little bit about how you do that. Yeah, absolutely.
So I think if you look at the history of MSSPs and where they started from, or any managed service provider, originally they were the way that you would get some leverage and skills on managing devices, right? So if you had 150 firewalls spread throughout your offices or throughout the country, you would use a managed service provider because they were really good at managing devices. And where that grew into was the managed service providers said, hey, since we're managing the device for you, you know, why don't you let us do some security work for you as well? I think what you've seen, if you look at the outcomes and people's perspectives on how that's turned out, the company who you want to manage your devices is probably not the company you want to put all your eggs in the basket of being your security team. As well.
And so our focus really has been, we are going to be that blue team who's defending your organization, and we will do what we need to in order to deliver that outcome. Whereas the MSSPs, they want to collect as much, as many different data sources and devices as possible because their pricing model and business model is based on that. The reason why we're focused on the endpoint and that data is not because, you know, we just have this obsession with being very focused. It is we've been incident responders, we've gotten brought in after breaches. All of your investigations are going to lead you back to the endpoint.
Even if you get a network alert that says, hey, I saw something bad come across the network, you're never going to do your investigation only on that network data. The first question you're going to ask is, I saw that network alert saying something bad came in, What endpoint did it go to, and what happened on that endpoint? Because you need to know, did the endpoint's firewall block it? Did any sort of host-based IPS or AV, did they block it? So because every one of those investigations takes you to the endpoint, that's the most valuable data.
And so you start there and add the other pieces you need, whereas most of the, like everybody else you talk to, just tries to catch as much data as possible and then figure out how to correlate it. They're kind of looking at it the wrong way. That's a trend. So, you know, I think you guys obviously have a strong passion for endpoint, and I think that makes a lot of sense. And I think it's worth taking a second to define what do we mean by endpoint.
By endpoint, do you mean laptops? Do you mean laptops and servers? Do you mean laptops, servers, applications? What is an endpoint in your mind? Yeah, so endpoint to us is a computing device that runs Windows, Mac, or Linux.
And to us, we're very indifferent about whether that's running on a laptop, a server, or a workstation. It doesn't matter to us if it's a server in your office, in your data center, in somebody else's data center like AWS. All of those systems who are running Windows, Mac, or Linux, they are all where applications are running, and that's where you want data collected, and that's where you want eyes on those systems. Systems. Now, that's going to expand over time as we look to what does endpoint look like 5 years from now.
Your Office 365 mail server running up in Microsoft's cloud is definitely going to be an endpoint that we'll be pulling data from. SaaS platforms. Exactly. You start talking about serverless, a Lambda function on Amazon, these things, they're super immature from a— they're relatively immature from a technology perspective. They're super immature from a security perspective.
Right. Try and get audit logging off a Lambda function about exactly what happened, and you end up in a lot of interesting conversations with Amazon. Yeah, I mean, I think that there's— it makes sense that you're focusing on Windows, Mac, and Linux operating systems. I'd say that that is not the end-all be-all of all endpoints. There's mainframes out there.
There's all kinds of stuff that really does matter. If someone's going to go hack my mainframe, and I'm an enterprise, airline or a bank, like, hey, that's a pretty bad thing. And if they didn't hack it from an endpoint that I manage, then I have a real problem. And so this is where you get into a lot of, I think, the extra benefit we provide, even though it's not something we charge for on consulting or anything. We, in order to be successful, spend a lot of time working with our customers to make sure they are making good security architecture decisions, to reduce your risk.
So in that example you mentioned, yes, you may have mainframes that Red Canary is not able to view telemetry on 24/7 because they're running an AS/400 that no one runs telemetry off of. Well, that thing should never be exposed to the internet, right? The only way you should be able to hack that thing is if you got in through one of your other systems. So what are you gonna do? You're gonna double the guard and you're gonna double security around that entry point in, right?
So that's your layers of defense, right? Hypothetically. Yeah, hypothetically they're never exposed. You know, when you say it should never be exposed, you're always like, that's the next news headline you see. But still, yeah, it's like the air gap between corporate networks and the control networks for, for our oil and gas friends that— yes, as soon as someone needs to do anything, that gets bridged, right?
Exactly. But if you talk to them, I mean, we've talked to a bunch of great security teams in that world. Many of them realize exactly how that works. And even if there's not, even if there is an air gap, they'll then look at it and say, okay, I have Windows machines who are controlling the actual ICS devices and the PLCs. That's where they're going to spend a bunch of time and attention looking at the security of that controlling device and make sure they have good behavioral profiles of what happens on there, and they have lots of auditing around that.
So let's talk about what's changed in the last year. When we, when we got together, I think it was last January, you at that point were only working with Carbon Black. You know, talk to me about how you've evolved your approach here, or is it evolving in an approach, or is it really just, you know, we're adding another vendor to support? Yeah, so from day one of Red Canary, We built the data processing platform we do because, again, like you mentioned, we don't process alerts from other products like your MSSPs or MDRs would. We use those products as data collection sources.
And so the data we're collecting is the straight raw telemetry off of systems. And so Red Canary's software is actually processing, I would bet, probably more data than— I'll bet you we're in like the top 5 or top 10 of Colorado companies of how much data we run through every day. I mean, we're probably running 30 to 40 terabytes a day through the platform. And so that software was designed from day one to be able to support something else. Like, it was designed to support any sort of telemetry coming in.
And we got to say that for several years, but never actually proved it until CrowdStrike added support to collect several more data types that are very important to us. And once they added that support and we were able to bring them on as a partner, now all of a sudden we have the second data source flowing through the system. And it was great. I mean, kudos to Chris Rothi and the engineering team who designed all that. We went from first access to CrowdStrike data types to it fully flowing through the system in a week.
That's really fast. And the way it works, I mean, to kind of dive into the technology, the first step of the process in our pipeline is standardization. And so what you'll find is lots of security teams and organizations have started thinking about how do I define a common model. Splunk, for example, has their common entity model that describes certain bits of data, but no one's done this for the endpoint and for what actually happens in an operating system. So we did that, and then we created a standardizer whose first job is to take data from any source, and turn it into that standardized format.
And so because of that, when we want to bring in a new data source, we simply write a new translator into the standardized format, and now we have common data formats. And so you've gone from Carbon Black to Carbon Black and CrowdStrike. Is there any other plans you can talk about in that area where you might go there? Yeah, if you look especially on the OS X side of the house, you have the Facebook team who's done a great job with the osquery product. You have the Google team and what they've done with Santa.
There's a lot of good open-source options that lots of companies have already deployed for managing their OS X fleets. Being able to get data from those sources is a great additive piece of this architecture. Yeah, and that's just the start. I mean, we're also doing some experiments to look at pulling straight VPC flow logs from AWS as well as the comparison from Azure, and really understand what value do those data sources provide. The perspective we take is every data source can provide some amount of value in one of two places.
One is on detection. Can it help me find something new I can't detect right now? The other is context. Most of the data sources you have in your security program are very good at giving you context, but not great at helping you with detection. And so if you ever wonder, why does Red Canary, like, why do you focus so much on the endpoint?
Because all your investigations are going back to the endpoint, it's because that endpoint is telling you what actually happened. That's where you do detection. A lot of the network visibility you have and alerts from your perimeter defenses are helpful on the context side of understanding what came in and out. Yeah, that makes a lot of sense as you're looking to detect new things, right? You're going to be ingesting new sources there.
I am interested to see what kind of stuff you're going to want to ingest to give you that context that— I mean, you're walking down a slippery slope towards a SIEM, right? And towards being a full MSSP that says, well, we start with endpoint, but you know, everything else is used to enrich it. It seems like somewhere along the line you're going to be uncomfortable going too far down that way. The beauty of not caring about the labels anymore and not trying to fit inside of them is, again, our mission at Red Canary is to make your security better. There's not really a slippery slope we're worried about as we go down the path of making your security better.
If we pull in another alert from a network device and some set of organizations think we look kind of like a SIEM, that's going to happen. We have a handful of customers right now who bought Red Canary, and we are their favorite SIEM. Yeah. And it makes us chuckle every time they say it.
Yeah, and it depends on how you look at a SIEM, right? You're not a central log repository, but you're helping do security analytics, and that's important. You know, I'd love your perspective on this. I have found the security industry to be very fascinating around the labels and buckets used to describe products. Yeah.
I don't really understand the focus on bucketing a lot of the products in the way that they are, which is very focused on techniques that are used. So think about, for example, your endpoint protection world where everyone is bucketing things as next-gen AV. Yeah. Right. A lot of this stuff is focused on the technique that you're using instead of bucketing them around the outcome you get.
So I totally— I'm happy to talk about this. The— I believe it's all around Google search results, right? If you don't— if you don't pick a name that Gartner has written about, or, or, you know, someone has just made a big IPO around that thing, right, then who's ever gonna find you, right? How am I ever gonna find I'm not going to ever Google for local company that helps make my security program better, right? Like, that's not a thing that I can look for.
And if I do find it, by the way, I'm probably going to see your result among 6 others that are like one— 2 of them are consultancies and one of them installs security cameras. Like, like it just isn't a clear thing for me to look for. Right. And I, as much as I hate the way we segment and we bucket people, I don't see how you can fight against it if what you're trying to do is grow by anything other than word of mouth. Word of mouth doesn't care about what your bucket is, but the market does, right?
Because your word of mouth spreads completely based on outcomes, right? You say, I had a need for X outcome. Yeah, man, Red Canary delivered that outcome better than anybody else. Yeah. And so what— I mean, what you'll see from us, though, we've said— I think it really comes down to what do you use the labels and the product categories for.
We will absolutely, you'll see it on the website right now, there is a use case for Red Canary for managed detection and response. There's also a use case for Red Canary as alert triage and investigation, which would be your pretty traditional MSSP use case. What we do is not defined by the categories we sell into, but we'll absolutely use the categories to help if you meet us for the first time and say, Hey, are you an MSSP? And we'll say like, hey, we will absolutely solve that part of your MSSP problem. Yeah, that's okay.
But I think a lot of companies get too focused on trying to fit and contort their entire company inside the category, which is why you end up with the same exact solutions for the last decade over and over. It's because everybody gets stuck inside the box. Yeah, I think we can be a little bigger. And you do get challenges where if you do part of the bucket, like for example, you with MSSPL, I'd rather use a different company, but you're the first thing that comes to mind. If someone says, hey, I want an MSSP, and you say, yeah, we solve part of that problem, and they come talk to you and then they say, but let me compare you against SecureWorks.
Can you do these other 6 things? And you don't do them. For most companies, that pushes you to go do those other 5 things poorly, right? Because that's how you go check a box in an RFP, and that's what your salespeople, if, as you grow, as most VC-backed companies do, your salespeople start to become a huge driver for the product roadmap, for good and mostly evil, I think, that they push you in the direction of what does the market expect from that label that you've been willing to stick on yourselves. Right, yeah, it's absolutely the trend you've seen over and over with companies.
So how do you resist it? Being very, very stubborn and having a team who really believes why we're doing this. I think this is what's most fun to me about Red Canary. The team we get to work with is very unified in the fact that we are going to make your security better. We're going to take this cloud-based service and we're going to help use it to make a huge difference for you.
And that team comes from a lot of different places. Some come from past security companies, some come from being on security teams before, and I think it makes a big difference when a lot of your internal team have been a security buyer or they've been in your shoes before, and they've bought a whole bunch of things in those categories that were promised to them, and they've realized at the end of it what you wanted to buy was not something in a category, what you needed was an outcome. And so, hey, maybe it doesn't end up working out, and maybe we are the crazy people who thought we could do it differently, and time will tell if it's successful or not. I'll say right now, I'm super proud of what the team has done. They've caused a lot of people to rethink how they buy security products and focus on the outcomes that really matter.
So one of the differences I think I perceive every time we interact, and we've hung out a dozen times or a couple dozen times, whatever it's been, is that I don't feel, you don't exude the same level of maybe VC-backed stress that I see from many other companies, where it's really growth at all costs for most of those. You know, that you take, you take a round, and then you take another round that's bigger and requires— you're gonna have a burn rate that, that requires you to go take another round in 18 months. And in order to justify that next round, which you never want it to be a down round— for those listening, down round meaning with a lower valuation of the company— You know, as you kind of go through that process, it's just this vicious cycle, or virtuous cycle, depending on your perspective, of having to sell faster and faster. How have you been able to avoid that pressure to go down that road? So, I think one, I mean, one great way to avoid that pressure is to deliver results, right?
I mean, we talk about this very often. Revenue solves all problems. Cash solves all problems, right? That cycle is a very different cycle when you are having to cut corners in order to hit your numbers, and you're trying to— I mean, what you see happen all the time is people start being a little bit fuzzy about what the product does, right? Your sales team starts selling on futures, right?
How many products have you bought where the sales team said, oh hey, it doesn't do it right now, but that's coming next month? It's coming next quarter, right? Anybody who's bought software on futures before doesn't ever want to do it again because it almost never comes true. And so with that, I mean, what's our background, right? We're security people.
And I think the thing we've realized is with Red Canary, the team who's here, we are security people building a security company for security people. We're not software people or business people who are solving a security problem for the VCs. Like, they— it all works out in the end, right? Like, when we do this the right way, the bet and the dream here is that we'll build a great security company that will solve your and other people's security problems, and that's going to result in a very big, valuable business, and everybody sees big financial rewards from it, right? I think it's— I mean, at the end of the day, I'm much— I care much more about building a great security company that everyone says was the most valuable investment they made than getting to unicorn status as fast as possible.
Who freaking cares? I mean, would you— I don't ever want to be the unicorn CEO who has 75% of their customers hate them because they can't deliver on product or what they said they're going to do. That sounds like a nightmare. There's some good examples of some of the unicorns recently who haven't had the best behavior, right? Yeah, we've had some of those in the news in the last 6 months or so.
Absolutely. So bring together great security people. I mean, it's a common theme, you know, you've been to, and for anybody listening, every quarter we have a Red Canary security friends and other, you know, tech companies together at our offices for a big get-together. And that the people who come and who all hang out together, it's great security people and it's great tech people all, and they like get really excited about building a great security company and doing things the right way. Yeah, I mean, it's the same reason I think you've done a lot with Colorado Equals Security, like get that community together to go do good security things, not have it be just about how can I grow something as fast as possible.
Yeah, it makes it a lot of fun, doesn't it? So what does this have to do with the Atomic Testing Framework? Atomic Red Team? Atomic Red Team. What is— how does what you're doing for Red Canary as a company relate to this kind of open-source framework you guys have created?
Because if you said, how do you as Red Canary, as the typical VC-backed startup who's selling me a cloud-based service to protect my endpoints, what does that have to do with an atomic testing framework, right? Those 2 things don't seem like they go together. No, they don't. But if you go back to the core, do whatever we can to make your security better, Now it starts to make sense. So here's what we realized.
When we built Red Canary and when we were delivering it, we got in a bunch of these situations where we'd be working with security teams who were trying to make a decision between, do I do this myself, or do I have someone like SecureWorks or an MSSP help manage my EDR product for me, or do I have Red Canary do it? And a common frustration from our sales and our security team was that on the technical side, that was even a discussion. And they would sit there and say, are you kidding me? Like, we've come from that world before. There is nothing you could build that's anything like the platform we run internally.
We just deliver 10, 20x the quality of what they do. And so the question came internally of, how is it that we actually show you and help you understand how is Red Canary's detection that much better? And now combine that with Casey Smith, who locally had worked with First Bank and the Verus Group, now Coalfire, and several other places, comes and joins our team, and Casey has a huge passion for educating security teams on how to build a bigger and better security program. And so he and Mike Haag and Adam Mathis and Joe Casazza and a bunch of people on the Red Canary side, you'll also see that Red Canary has a lot of people who are very passionate about teaching. And so the idea they came up with was, let's build this open-source collection of knowledge about how you can simulate what an adversary is going to do, and let's use MITRE's ATT&CK framework as the roadmap or the common language, and let's start taking each of those tactics and let's define if you wanted to simulate credential harvesting on one of your machines, how would you do it?
Yeah. Now there's lots of products you can go buy and things you can pay a lot of money for to pay for a big platform to do all this. But if you, Robb Reck, wanted to go figure out if your security team would identify credential harvesting, what are you going to do? You're going to go to the Atomic Red Team GitHub page. Yeah.
You're going to click into credential harvesting. It's going to show you a little bash script or a little PowerShell command. You're going to copy it, you're going to go on your system, you're going to paste it and run it, and then you're going to sit there and see how long it takes before Ryan calls you and says, what's going on, Robb? Ryan, who is my infrastructure security manager at Ping. Yeah, it's awesome you guys have created this.
You've put a lot of resources into doing this. Now, was this something you created to use internally so you guys could like make sure you triggered your own issues, and are you just basically sharing out with the community? So it's actually come now, it is, it really has 3 different purposes altogether. One of it was we wanted to help people do a better proof of concept themselves and have it be something where like, I really hate it when a vendor comes to you and says, hey, let's do a proof of concept, here's all my samples to run. That feels too staged.
None of us liked that. So having it be an open source community supported thing, like do a better POC, also take the team's passion for educating teams and making it very accessible to do security testing. And then the third bit is this is actually the way that our internal applied research team does red team activities against Red Canary. So again, going back to Red Canary is that cloud-based service that defends your systems. We're the team who's figuring out what our adversary is doing next, what techniques are out there, what new zero-days are dropping, and what behaviors do they exhibit.
So we're responsible for keeping up on the cutting edge of that. Now we have an internal red team who's effectively our adversary as well, who's coming up with new techniques, and they're testing them against us as well. So you end up with a good internal red team that, you know, iron sharpens iron. We get better as a part of that as well. So really, I mean, it's such an exciting project because the community is wildly in support of it.
We have people, I think, in 15 different countries right now who all have contributed tests to a part of it. We are— How many of those are from Russia? I don't know. Go on the GitHub page and find out yourself. Just curious.
We are actually going to be going through probably in the next 2 months or so moving it all to a YAML format, so it'll all be machine readable, because you have great projects from the MITRE team, from local Chris Nickerson and his team, you've got Chris Gates and the Uber team with Meta. A lot of teams are figuring out how do I automate some of those tests and how do I run them in different places, and so it's actually going to be machine readable across the board. Be awesome. So really cool you guys are doing that. And we did have Casey on the show a month or so ago to talk about the framework.
If someone wants to learn more about it, go look in the archives and listen to Casey give more detail. Check out the GitHub page. I'll put that in the show notes as well. Yeah. And then attend the— actually, I have no idea how the attendance side of this works.
So you tell me. Attend the RMISC training that Casey and David are putting on. Yeah, the pre-conference day training on on the Atomic Red team. So that— I don't know where we are in terms of capacity on that either, but you take a look. Uh, all right, so I wanted to get into a little bit of community stuff with you.
You and I were on a, uh, a Denver Startup Week panel last fall. Yes. And we got to, to sit with some other folks. You can help me make sure I remember everyone who was on there. We had Cody from Swimlane, we had Gene from ProtectWise, we had Fred from CyberDierks.
Yep. And and yourself. I think that was it. Am I forgetting anybody? Okay, that's it.
So, you know, we've got to— we had a good time. Look, we're going to try and do it again this year as well. You've got to know quite a few different security companies in town. I'm going to put you on the spot and ask you to call out something cool going on in town that's worth chatting about and maybe educating the rest of the listeners on. Yeah, I think so.
The neatest thing to me, and it's especially special for us coming from the Red Canary side is a new company called Randori. And they are, they're going to be, I think their engineering team is going to be all here in Denver, sales and marketing back in Boston. And it's actually a team started by Moose, who many of you may know, also known as David Wolpoff, and Brian Hazard from Bit9 originally. And they're going to be building a platform to do APT-like simulation and recon and threat intelligence gathering against your organization. So they're going to use the same type— they're going to use the Atomic Red Team stuff to do this?
So I would— here's what I would expect from them. So their background, Randori is the 3rd or 4th spin-out from Kairos, which is actually Carbon Black spun out of Kairos. Red Canary was incubated there. Randori comes there as well. The work we did back at Kairos was offensive cybersecurity research and problem solving for the intelligence community.
Yeah. And so if you want to know what it's like to have a nation-state adversary poking and prodding and reconning your environment, those are the guys who know how to do it. Yeah. And so it's exciting to see what happens if you take that level of knowledge and and then figure out how do you democratize that across everyone. Yeah, it sounds like a lot of fun.
Now, we were talking about them a little bit earlier, and you mentioned that they're pretty, pretty early right now, and maybe a little too early for me to get on the show quite yet, but I'd appreciate the introduction, and we'll look at talking to them when the time is right there. Absolutely. And if you're looking to join a new and exciting security startup that's extremely early stage in Colorado, they're the guys to talk to. Talk to because they are building everything from scratch right now. Awesome, awesome.
Well, speaking of jobs, I assume you guys are hiring some people? Absolutely. What are you guys looking for right now? You know, biggest focus for us is really on the engineering side as well as the, I'd say, the sales side of things. Yeah, on the engineering team, like I mentioned, we have a massive data processing platform and we get to do it with some of the most cutting-edge tech that's out there.
So we run a huge Kubernetes fleet that has a fully Dockerized and elastically scalable data processing engine inside of it, sits all on top of AWS, and really, you know, we're growing our SRE team as well as our platform development team. That's going to be both front-end as well as back-end data processing. So you— I mean, that's quite a few different things you're looking for there, right? If you love security— let's talk about skill sets though. Let's talk about skill sets.
So engineers, you're looking for Java developers with— I'm assuming here, right? So I'm especially coming from the software side, I'm a pretty firm believer in the language matters less than like your ability and passion to write really good code to solve a problem. Okay. So I'd say the biggest things we're looking for are people who are passionate about the security problem. Because that's what we're obsessed with.
And then people who want to come in and deal with a, I'd say, a big and highly complex in the good way. Like, it's complex in the fact that there are a lot of different moving parts, but they're all nice and simple and have a single function. But one of the early things I learned from some of the team we brought on is they told me data has momentum. And data has a lot less momentum when you're processing a couple hundred gigs a day than it does now when we're processing 30 to 40 terabytes per day. And so everything we do is bigger.
And so if you have a passion for how can I, you know, very performantly look at massive amounts of data coming in and identify anomalies, or how can I scale this to go from 40 terabytes a day to 4,000 terabytes per day, those are the problems we get to solve. Pretty cool. Yeah, and unique in Denver, right? Yeah, there's not a lot of companies. I mean, it was a lot of fun for us at one of the Built and Brews events.
We got to go up and meet the DigitalGlobe GOI team, and they were talking about how they had taken— what was it, like 40 petabytes? Yeah, exactly. And so now if you start thinking, who are the companies in Colorado who are doing the most cutting-edge and interesting stuff on top of AWS in the cloud, it's not a big list. So, like, if you have any passion for security and want to solve those problems, this is the place to do it. In the sales area, what kind of— are you looking for account execs or SDRs, or what are you looking for?
Account execs. Okay. Yeah, we are— we run this great model of teams doing sales across the country, and given the continued success there, those territories are going to keep getting bigger and we're going to need more teams. Keep getting smaller, I assume. Well, it gets bigger as well because you start adding more international support as well and all that.
So it's both. Yeah, okay. And then you said SREs, so folks who would run your AWS production systems, I assume? Yes. Okay.
We're big believers in, if you've ever read the Google SRE book and how they talk about site reliability engineering and not wanting that to be all toil and for figuring out how to automate a lot of that and have healing systems. That's what we like. Yeah. And was there one more part? You said support.
Did you say anything else? I'm sorry. Those are the big ones. Okay. Sounds good.
All right. What else do we want to chat about here? You have any topics you wanted to make sure we brought up here?
What are you seeing? What did you see from RSA? You know, RSA this year was not, was not especially different, right? Most years they, you know, they kind of come up with a theme and it's going to be all about AI or, you know, APTs or whatever it is in that given year. Are you saying they've run out of hype?
Well, no, no, there's plenty of hype. I didn't feel like it was— there was a great theme. I did see a couple of really neat things. I think there are other companies out there who have recognized how bad the SIEM is and are coming up with innovative solutions to dealing with that. We— I talked with, uh, with Jask, who does some pretty neat stuff about, um, their, their vision, which they're nowhere near their vision, but their vision is a fully automated SOC, right?
It's a cool vision. Yeah. And they're very far from it, but they're— they are adding value and making it easier for your SOC analyst to do it. I also got to see Sumo Logic. They, they acquired a company last year called FactorChain, right, which has a lot of really cool workflow also.
And it kind of, you know, built into the SIEM, but trying to automate as many things as you can down the chain. Really neat stuff there. Those were probably my— the things I found most interesting. You know, there, there are— I feel like we are going to start to see that consolidation that people have been talking about for a while. I think it is starting, and consolidation is only going to keep growing here in the next couple of years.
The number of security vendors is going to shrink. It is shrinking already. And I think startups are going to get swooped up earlier in their lifecycle versus getting, you know, growing to unicorn. I don't think we're going to have as many unicorns going forward. That's my take, my walkaway.
Anything you got from RSA this year? So I thought it was interesting as well, the the amount of hype is just so over the top. I mean, the amount of made-up marketing that's up there is just exceptional. The number of companies talking about the AI they're doing and the machine learning they're doing— again, it goes back to the category, right? Like, the fact that AI or machine learning is involved is just a technique that should help you deliver the same outcome you've been trying to do better.
And that's— that is the problem. If you have AI or machine learning on booth, you're missing, you're missing the point, right? It's— you're not able to provide your antivirus or your IAM or your firewall, whatever it is, because of machine learning. You're able to do it because you've built a technology that's now able to go faster because of machine learning and more— it can be more effective. It always should be about the results, to your point.
And if you're leading with machine learning, you're just confusing the issue. So when are we going to see the first Ping marketing saying that you have AI as part of the IAM? So let's just be clear, I am not a part of the marketing team. Do you get veto power? I don't get veto power either.
I suspect that you will not see machine learning as the headline on anything, but, you know, certainly intelligence will be. And intelligence is a critical part of just getting better. And you can, you can be intelligent in lots of ways. You can have rules-based intelligence, you can have machine learning intelligence, you can have artificial intelligence that gets you intelligence. There's kind of a maturation process between those, right?
So I think intelligence is probably a better way to put it. I think so. Absolutely. I think what's really a shame is that the overmarketing of words like AI and machine learning have already caused. And we went to an event that Splunk had put on, which was really like a closed-door, bring together 20 people and talk about that.
And it was actually the data scientists from places like Splunk and several other companies. They actually know what AI and machine learning is and where it's useful because they sit on so much data. And hearing them, they're extremely frustrated. Right? It's frustrated in the marketing of things, and that's meaning that we aren't able to always have good, clean conversations about what we're really talking about.
And that's the shame in the fact that marketing is leading all that. I think focusing on leading with the problem you're solving, right? Leading with the result is a whole lot better than talking about the technology that puts it all together, right? So I'm excited for that. I think if we've seen anything in the last 4 years, It is that people are starting to really dig in and look more carefully as to what outcomes they want and make really better decisions about how they get there.
Awesome. Much less checkbox buying than in the past. I just remembered I had one more question I forgot to ask you. We talked a few months ago about a press release you had had, or actually you didn't have, that mentioned you, because you guys don't do press releases. There was a press release there was by Kroll talking about a partnership between you guys, and on the show we mentioned it and we're like, you know, probably just a thing where they're going to resell their services, and you gave me a hard time about that.
So I want to give you the opportunity to tell me about the partnership with Kroll and how do you guys make each other better. It was very hurtful. I mean, thinking that we would do a bit of marketing just for the sake of marketing. Partnerships, reseller partnerships, those are pretty common. So what's unique about Kroll, so the history there is Almost since the beginning of Red Canary, we've been talking to the Kroll team because they are, I'd say, like top incident response firm.
And the view we've always had of incident response is that incident response is going to change over time, right? So this was 4 years ago when everybody was paying Mandiant to come in all the time, paying them crazy amounts of money. And the belief we had and still have today is that in the future you will do less incident response, that's big bang incident response like that. Instead, what you're going to do is you're going to do this form of continual incident response, where you're gonna take the same practices that you used to pay Mandiant to do, and you're just gonna apply them inside your security team. And now that is, whether you wanna call it the blue team side of things, or what Red Canary does, that's a lot of what we do, right?
It's the exact same thing that someone doing an incident response would do, We're just doing it as the events happen, and so that cuts your time to response dramatically. There's still a lot of situations where you need an incident response firm, especially if a big breach happens, if you're going to go to court, a lot of these situations. And so Kroll had done a great job becoming the number one incident response firm using EDR products like Carbon Black, and so it's always been a natural partnership between the companies of sharing You know, we've built tools that they use internally. Some of their leads are actually in Colorado here, and so we've been good friends with them. What they realized was very often they were doing incident response or breach response investigations, and at the end of that saying, hey customer, if you don't want us to have to come back and pay all this money again, you really should have someone continuously monitoring and doing this investigation 24/7.
And so it's a great partnership there because Red Canary doesn't do incident response. We've always had a challenge swallowing the idea that you're paying us money to prevent you from getting breached, but then if you do get breached, you pay us more money. Like, that never really made sense to us, so we've said we're just not going to do it. And so it's a great partnership because if you do need incident response services, or you may need a retainer in in case everything does go sideways someday, they're a great partner who will do exceptional incident response for you, and will do exceptional continuous monitoring with our cloud-based service. And so it's a pairing that works really well together.
So every Kroll incident response now has Red Canary powering it, and a large amount of our customer base is working with Kroll if they do have incident response needs. So when you say it has Red Canary powering it, does that mean your guys' agents are sent out and fed into a Red Canary system to look for— So Kroll has always, since several years ago, they've always used Carbon Black as part of their incident response engagements. That Carbon Black data now comes to Red Canary. So for them, they get a ton of leverage in the fact that they can drop into an incident response engagement, and not only do they have their really experienced, forensics and containment team on the ground, they have all the full force and power of the Red Canary operations team and platform sitting behind it, sucking up way more data. Yeah.
So if, if you did want to release a press release, do you know the people who could do this? Do you have people for that? Yeah. All right, just curious. We've done it before.
So everyone listening, every week as we put the show together, I look, I go through the all the security companies looking for press releases and blog posts and Red Canary, you don't even really have like a press release webpage. You've got a— No, we have a blog. Yeah, but you have a blog, and I do keep— we do share your blog stories pretty frequently, but then you have a new Red Canary in the News section. Oh yes. Which you don't— you guys don't really update that section.
No. We have a nervous reaction because, and you saw this 3 weeks ago, Did you see all the press releases where companies announced they were going to RSA? I did, yes. I just— and I work for a company that did that. Oh shoot, I should have looked, should have done my research beforehand.
It's a pretty common thing, and like the press release will say, hey, we're going there and we have these 3 speakers, and it is just buzz, right? It's all it is, is try— is some more noise in the industry. And I, right, I get where you're coming from for sure. Yeah, I do prefer that as a blog post to a press release. Yeah.
So we'll, we'll continue to make the blog great and we'll have to have these conversations around news. And Brian Bell, if you're listening, I don't— I have no idea whether that should be a press release or a blog post. You're doing a great job over there. Okay. Well, I think that's it for us here.
Great. Anything else you want to say before we go? I'd just say keep your ears open. We are getting about to the point where our next Red Canary and security friends happy hour and party is going to be at the Red Canary office. We'll get on the calendar if you let us.
We'll definitely do that. Cool. All right, Brian, thanks a lot. Awesome. Thanks, Robb.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.