Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 71 for the week of June 11th, 2018, and I finally have Alex back. Alex, where have you been the last 2 weeks?
You know, I've been a world traveler, Rob. A couple weeks ago, it was my dad's birthday, so went back to Ohio to say hello. Turned 70, so that was exciting for him. It was nice seeing the family. And then last week, I had a college reunion in the even more exciting Central Iowa.
So when you say a world traveler, yeah, you mean a very small part of the Midwest of the United States. Exactly. Perfect. Yeah, perfect. Well, welcome back.
We're glad to have you. There is a plethora of interesting news for us to go through this week. Most definitely. But before we do that, let's just kind of go through our our spiel here at the beginning. As a reminder, we do have a Slack channel, an active Slack channel where you can come get involved with the security community here in Denver.
Um, what, 470-ish people involved in the channel? Good conversations on there on a regular basis. So come get to know some other folks in the Colorado community scene. Uh, please review us on all of the places that you can review us, including iTunes. We'd love to get, uh, high marks on that.
And then we also have a mailing list. So if you go check out the website, you can sign up for the mailing list. You will get notified when we have new episodes. You'll get the show notes, lots of interesting stuff like that. And did you know that you can have a— you can be a Patreon?
You can sponsor the Colorado Equal Security Podcast individually. We have a Patreon campaign set up. You can go out there and donate a certain amount per month. If you donate $10 a month, you get a shout out on the show and a free t-shirt. And we do have a new Patreon supporter this week, Trent Hein, who was a guest host or excuse me, a guest feature interview a couple of months ago.
He, he just signed up. So thank you very much, Trent. We appreciate your support very much. Thanks a bunch, Trent. And what we do with that money is none of it goes into our pockets.
This is all used to fund the podcast and to anything we want to do here around hosting fees and any new hardware we need. And we just recently this week bought a new set of Colorado EcoSecurity magnets, some magnets rather than just stickers, right? Yeah. So you can have it on your fridge, you know, stick it to the side of your car. I assume I'll see cars all over the city with them on there.
I'm sure you will after you're done with your, your batch of magnets.
Great. Well, let's jump into the news. So first, Colorado ranks number 5 on the list of best overall state economies. Super, super exciting there. This is a study done by WalletHub.
In addition to us being number 5 on the overall list, Colorado is number 2 in highest GDP growth and Number 4 in most startup activity, and was tied with Hawaii for lowest unemployment. Pretty good. So looking at that same list, they do have a worst economies in the United States. And if we want to pick on number 51, because there are 51 states if you count the District of Columbia as a state. So number 51 is Louisiana, 50 Mississippi, and then Alaska comes in there at 49.
So kind of an interesting smattering there of worst states. From an economic perspective. Yes. Yeah. Not from a cultural perspective.
Completely economic. Not passing any other judgments there. All right. Moving on. We, we have an article here that tells us that Denver is replete with Californians who've moved here.
So, Rob, where are you from? I'm actually from California. Yeah. Whoa. Yeah.
This is an interesting study all about me. You can see my picture right in the middle of it. I moved here in 2001. Because Colorado had the best girl in it. That's why I moved here.
Yeah, not for jobs or affordable housing. So Denver was the number 10 spot for California's Californians, attracting 2.7% of those moving out of California. Interestingly enough, if you were going to leave California, the number 1 place you're going to go is New York City. That's where 7.3% of them moved. You know, my thought would be, I'm going to leave California because it's too expensive, right?
There's, you know, I can't live in California. So where am I going to go? New York City. It's perfect, right? The most affordable spot in North America.
And after that was Las Vegas, which, you know, I guess it's not a surprise, close by. Well, I think what happened there was they were going to Las Vegas to gamble. They just got stuck, can't afford the gas to get home. And now they live in Las Vegas. Next, Salt Lending.
Is a blockchain company, and they are offering a course in blockchain along with Regis University. I'm really glad this article showed up. I was worried we were going to make it through a week without having any blockchain discussion at all. You know, so every week Rob and I, you know, scour the internet for news, and every week I do my best to find a blockchain story just to get under Rob's skin. Blockchain, blockchain, blockchain.
Uh, so this, uh, this 4-week not-for-credit pilot course is offered through Regis. Through their Anderson College of Business, and it's titled Blockchain for Social Impact. So this isn't blockchain for financial, this is a social impact aspect. And if you look at like the people who registered for it, it were not your general technologists. It was a bunch of more liberal arts and, you know, social, social perspective type majors.
And if you heard this and thought, man, I want to take that class, I am pretty sure it is sold out. Yeah, they said it sold out within 24 hours. However, if you just show up, you might get in. Don't tell them I sent you, but go ahead and give it a shot. All right.
Cybersecurity startups gathering in Colorado Springs as part of a program to help them grow. So this was put together by the National Cybersecurity Center, right? Yeah. So they, I believe, are doing an accelerator also down there. I think Vance Brown, the CEO of the NCC, or interim CEO of the NCC, put in some money to help the incubator get off the ground.
And they have 4 startups that they got coming in there together. I have never heard of any of them. I don't feel like I'm even close to ever having heard of any of them. It's Barn Owl, Biteable Foods, and that's B-Y-T-A-B-L-E for Biteable. Yeah, because it's computery foods.
Mandy AI, and Kubrics, Q-B-R-I-C-S. Like I said, I've never heard of any of them. I don't— they don't look even vaguely familiar. Yeah, and it— the, the possibilities for folks in the, um, in the incubator down there are around, uh, cybersecurity technology, um, or blockchain. And I don't know that any of these are specific cybersecurity, um, plays, but the that the last one you mentioned, Kubrix, um, is using blockchain to help automate regulatory compliance, uh, for workers in the H-1B visa program. So very exciting there.
That does sound really exciting. I couldn't agree more. Um, so moving on from that, uh, Aaron Lafferty, uh, put a post in LinkedIn this week, uh, talking about the data breach survey that he conducted and the results that came out of that. Yeah, so we had actually had this survey on our newsletter a couple times. We talked about it on the podcast a couple times to get folks to fill it in.
Aaron's just doing some research to see how do people perceive blame when a company gets breached. Is it the company's fault or is it the attacker's fault, really? Right, and it was a pretty significant sway in terms of people thinking it should be the company's fault. 60— basically you only had 2 choices. You had to, you had to pick who's it, who's, uh, at, at fault here.
And the company was at fault about 60% of the time. I think it depended on the scenario, but there was only like 1 or 2 scenarios, I think. Or maybe there wasn't. I think there's just 1 scenario, um, that swung the other way, right, to the attacker. So interestingly enough, the vast majority of people think it's the company's fault when they get breached.
I, I really struggle with this as There's no— I can't think of any other situation where we actually, as a society, agree that it's the fault of the victim when a criminal, you know, victimizes them, right? And I mean, I think that's the whole point of Aaron's research, right, is that we have this problem with victim shaming in cybersecurity where something bad happens to a company, they're victimized by a criminal, and we hold that company accountable and say, hey, What's wrong with you? Why did you get victimized? Right. It certainly is reasonable to say we're going to hold you accountable, but it's still primarily the fault of the criminal who did that, right?
Right. I think we got to find that balance somewhere that, you know, yes, we all have to make sure we're implementing security programs that meet the basics, but at the end of the day, it is a criminal who has broken the law to go do these things. And, and as a society, that's probably where we should be focusing most of our attention, fixing that, fixing the root causes and making that not so, so profitable. Maybe. I don't know.
It's a tough question. I don't know either, but it's some interesting research. Uh, so next, uh, we had an article. I know it was talked about last week even though I wasn't here, uh, but LogRhythm was acquired by Thoma Bravo, and we had an article this week from Chris Peterson Um, who is the CEO of LogRhythm, just talking about it. Chris, the founder, and he's not the CEO.
Andy Gronick's the CEO. Sorry, he's the, uh, Chris is— what is he, CTO? Yeah. So what's neat about this, and this came out after last week's podcast, uh, was all set, um, this, this part, this blog really talks about Chris's plan for the future with, with LogRhythm, right? So, um, there's been a lot of talk, you know, what does it mean to get bought?
Does it mean You know, does it mean you're, you're going to stay the same? Are they going to try and pull out profits? What are— what's it look like? And, and really, I think the good news for LogRhythm employees and fans and customers is, is these kind of private equity, Thoma Bravo, their intention is to add value to the company, right? I, I don't know exactly the details here on this transaction, but I do know Ping was bought by a private equity firm that's a competitor of Thoma Bravo.
And the basic model is they invest a lot of money into their companies that they buy so they can go sell them in some number of years to get a great return, right? So they're not looking to cut costs, they're not looking to get rid of people, they're looking to invest and make the company, you know, more successful so they can make another exit, you know, and call it 3 to 5 years. Yeah, so again, congratulations to LogRhythm. Uh, next we had a blog from InteliSecure: Theft of Intellectual Property Costs More Than You Think. Yeah, this was interesting.
I, I found this one, it's actually from a few weeks ago, it's not brand new. But I thought it had some really interesting perspectives. Talks about a study by Bromium that said that cybercrime generates about $1.5 trillion per year. That's globally. It's a lot of money.
It's a big number. And, and when they looked at what, what's that $1.5 trillion break down into, about $500 million of it, so about a third of it, actually comes from intellectual property theft, whether that means, you know, stealing of designs, you know, so you can go make the, the product that other companies making, or customer lists, or, you know, other kinds of intellectual property, that, that's a big, it's a big number, and probably something we don't think a ton about in terms of economic damage to our companies. Yeah, for sure. And I know that, you know, in many instances, that is something that, that really just gets overlooked, right? So you think, oh, well, I'm gonna, you know, protect the confidentiality of my consumers' data.
I'm gonna, you know, make sure that my systems are available. But people don't often think about intellectual property because it's less tangible, right? Yeah, it's pretty, pretty good. I appreciate them putting that together. Of course, it— of course, this kind of research always is going to tell you you need more DLP, which is what they do.
But it's still an interesting point, and I appreciate taking a look at it. Next article we have is actually from Mitch Tannenbaum. We've talked about Mitch's blog once or twice before. He did a really nice summary of the new Colorado cybersecurity law that we talked about a couple weeks ago. Were you here for that, or was that— I was not.
You weren't here for that either. So I don't know if you know, you're now probably breaking the law. Yeah, Colorado now has a new cybersecurity law, and let's go through what the law tells us, shall we? We shall. So just a nice summary of it.
To start off, you have to have a written policy for the destruction of, of paper and electronic documents containing PII. Okay. You have to implement and maintain reasonable security practices that are appropriate to the nature and size of your business. Sounds like a good idea. If you use any third-party services, you have to require that that third party implement and maintain their own security practices.
Also good. You've never thought about that, right? Never. Never once. In case of a breach, you have to notify residents, Colorado residents, with specific information about the breach.
I think it's within 30 days. 30 days, I think, was the one of the big headlines, right, is that, hey, now we have a 30-day breach notification. If the breach impacts more than 500 people, you have to notify the Attorney General. If it impacts more than 1,000 people, you have to notify the credit reporting agencies as well. Uh, if encrypted data is breached, notification is not required if the encryption mechanism is not compromised.
So everyone, please make sure do not include your encryption key or decryption keys with your encrypted data. And then last point here is that criminal charges may be brought against a business under certain circumstances. I don't know how you bring criminal charges against a business though. Negligence. I mean, if you're negligent under the law.
Isn't that a civil charge though? If it's negligence, isn't that money instead of— doesn't criminal mean you go to jail? I guess I don't really know. I think it's really more about the impact, right? It's whether you're fined or whether you're going to jail.
Yeah. So that's a nice summary of the new law that goes into effect. I think it's August 1st, I believe. And I think it's great. I'm glad to see that Colorado is pushing the states forward.
You know, in my opinion, there's, there's nothing that's too onerous in that bill. I think it's all pretty good things that people should be doing. The 30-day notification period could be onerous depending on the details of a breach. Right. That's depending.
But that's out there. You know, a company like yours or mine that does business across multiple states, That's, you know, that's not any faster than the fastest other states anyway, right? Yeah. Um, so next, um, Rock Cyber is a cybersecurity company launching in June. So, um, our friend, uh, Rock Lambros, uh, put out a, uh, a press release this week about his new cybersecurity company, Rock Cyber.
So congratulations to Rock. Yeah, so he's gonna do, you know, security consulting, CISO as a service, risk assessments, kind of your security consulting suite of services. Congratulations to him, and looking forward to hearing some success on, on how that goes. Uh, next we have some recognition for one of our own community here. Gail Corey has received ISACA's prestigious Chair Award.
Have you heard, have you heard of the Chair Award before? Uh, is that where they, uh, like at a Jewish wedding, they put you on a chair and hoist you up and walk you around the room? Is that Hoy vey.
No, I think so. This is, I think it's more like the sort of like the chairman's award or something like that. The chair of ISACA International gets to appoint one person, and she was recognized this year at their big conference last month. So big congratulations to Gail for that. Yeah, great work.
And she's done a lot of work in promoting women in cybersecurity, which I think was one of the reasons why she got that award. So yes, definitely congratulations to Gail. Yeah. And then finally here from the news perspective, congratulations to Dale Drew. Dale has headed over to Zayo as the new CISO.
So Zayo is a big internet provider and data center company here in Denver, and this is, uh, this is Dale's next stop. And he, he had previously been the Chief Security Officer for Level 3, then, then after they were purchased by CenturyLink, he became the Chief Security Strategist, and now he's moved over to Zayo as the CISO. So congrats to Dale, that's awesome. All right, so let's move on to our Slack message of the week. Message of the week.
Message of the week. Congratulations to, uh, Daniel Ayala. Daniel Ayala, yes, for the information he had shared about the U2F for Chromebook. So it's been a good conversation in the channel about, uh, what it— what U2F is, a 2-factor. Basically, it allows you to use the power button on your Chromebook as your fingerprint reader.
So you push the button, it authenticates you right there. Good conversation in the channel about, you know, using a Chromebook versus a Windows laptop versus a MacBook and the price differences and the security differences and And then I come in saying, well, well, where do I put my music if I use a Chromebook? But you can't have music on your, on your machine anymore. Yeah, yeah. So I gotta figure that out.
Anyway, thanks a lot to that. And of course, thanks to Andre Gaeta, who is our sponsor for the Slack message of the week. Andre has been a great supporter for us. Um, Daniel, you'll get to pick something from the Colorado Equal Security store, and Andre will get that shipped over to you. So I want to know how many people are going to turn their Chromebooks off by you know, accidentally using the power button, um, as a fingerprint reader.
It's probably not that kind of power button. It's probably the kind of power button that only turns things on. Oh, okay. It's not the old school button. Uh, hey, should we move over to jobs?
Let's talk about jobs. Yeah, so there's a couple of great jobs over at Ping Identity. Uh, Ping, we are looking to hire a senior security analyst that will work on one of my teams, the infrastructure security team there. Uh, that position will be focused on helping us secure and monitor our environment, both our SaaS environment and our corporate environment. So look out on the website and send me a note if you want to talk about it.
Also, Ping is looking to hire a site reliability engineer who's focused on security operations. So this is someone who helps run our product, our production environment, so the, the whole SaaS Ping stuff, but we'll be working on the security projects that are important to my team in that, in that area. Uh, so next, eFolder is looking for a security and compliance analyst. So you can go work with Joshua Foltz over there. Uh, Cherry Creek High School is hiring a security specialist focused on high school.
Uh, University of Colorado is looking for a security analyst. FirstBank Holding Company is hiring an information security project analyst. S&P Global is looking for a director of security architecture. Carbon Black is hiring a senior threat researcher. FireEye is looking for an industrial response security consultant.
Optiv is hiring a vice president and general manager of emerging services. Wow. And then finally, Overwatch ID is hiring for some developers. So if you want to— if you're a developer and want to go work for a security company, they're looking for a senior C/C++ software engineer and also a Java software engineer. Awesome.
Well, let's go ahead and dive into jobs as well. Does it— excuse me, we just did jobs. We did, we did jobs. I feel like we can't do that again. Let's not do that again.
Why don't we talk about events now then? Okay, we can do events. We have an event calendar on the website if you're curious what's coming up in the future. Events are, and there's a lot. So if you thought, hey, it's summertime and events are gonna be slowing down, you were wrong and you're stupid because they are really speeding up.
So first, This week on the 12th and the 13th, ISSA Denver is doing their June meetings. As part of that, this is when they do their annual election for board members. Absolutely. You should come there and, and just vote for none of the above to, to really, you know, stick it to the man. That's right.
Don't do that. I'm just kidding. Uh, SecureSet on the 14th is having their Hacking 101 PowerShell. So if you're listening and you don't know what Hacking 101 and PowerShell have to do with each other, you should definitely go. Because this would be a really good opportunity for you to figure out what you're missing.
On the 15th, ISC2 is doing their Secure Summit Denver. It's a full-day event, right? It is. They do this once a year. ISC2 comes to town and brings some people to talk.
Yeah. So I don't know who's going to be there, but I bet it's going to be pretty good. I hope. ISC— excuse me, ISSA Colorado Springs is doing their June meetings on the 19th and 20th. That's their Tuesday night dinner, their Wednesday night Excuse me, Wednesday afternoon lunch.
CSA is doing their chapter meeting also on the 19th. On the 20th, ISSA Denver is doing a June happy hour, and that is going to be held somewhere. I don't know why I started this sentence without having the answer for it, but it's going to be held somewhere really great in the Wazi area. It's going to be downtown at oh, it's it's at the CyberGRX headquarters. Pretty awesome.
Nice. Uh, DenSec is also doing their monthly meetup on the 20th. So this is at a, a bar somewhere that they will announce, um, on the, the day of or day before. Uh, it's, it's been downtown lately, so it's probably something like Wine Coop. I know they've met at the Wine Coop a bunch of times.
Um, and then there is an AI for GDPR compliance conversation on the 21st of June, and that's going to be an interesting meeting with the GDPR meetup groups. And then finally, ISSA Colorado Springs is doing one of their mini seminars on June 23rd. Yeah, it's not many seminars, it's a mini seminar. It's mini, not many. They have many mini seminars.
This one is a singular mini seminar. Yeah, this is a monthly series that they do where basically you get together for 4 hours on a Saturday morning and just get little snippets of like an hour-long presentation. It's like a mini conference really, and a good way to get CPEs and meet some people. Exactly. So that takes us to the end of the news.
I feel totally satisfied. As do I. Um, so hey, what are we going to talk about in the feature guest? Who, who did you interview this week? Yeah, so I talked to, uh, Mike Morris, who is the CTO of Route 9B. Uh, you may be familiar with Route 9B because they were the number one company on the Cybersecurity 500 for several iterations of that list.
They're down in Colorado Springs. And I talked to Mike about that issue in particular, about the company. They had had some, I don't know, some tumultuous times with parent company folding and other things like that. But, you know, talk to him about what they do and where Mike has been. It was good.
Good interview. Awesome. Well, appreciate it. And we'll look forward to talking to you again next week. Sounds good.
Thanks, Rob. See ya. This is Rob Winter, Chief Information Security Officer at Boulder community health. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
This is Alex Wood with Colorado Equals Security, and I am here today with Mike Morris, CTO of Route 9B. How are you doing, Mike? I'm doing good. Thanks for having me on here, Alex. Yep, appreciate you being, being here.
Glad to finally get a chance to talk to you guys. We've been going back and forth for a little while here trying to figure out a time that works. So I'm glad we finally got it figured out. So we are here in your, your beautiful offices in Colorado Springs. You guys have quite the setup here.
I love the layout here. We've got the fancy lights and everything like that. It's a cool space. So why don't we start by just giving a little background on you? How you got your information security start, how you got to where you are today.
Yeah, absolutely. So I'm prior Air Force. I spent just under 10 years in active duty Air Force. I was an enlisted guy. Started out as an intelligence body, so first duty assignment was Hawaii.
I got tossed into a counterterrorism mission out there. They taught me all the telephony type things while I was in, and then during that time the Air Force was standing up the 315th Network Warfare Squadron to be able to go through and conduct operations. It was the Air Force's premier operations organization. So I did work out in Hawaii for 4 years tracking down terrorists and things of that nature. And then from there, I was pulled back, went into Fort Meade, and went through the Air Force's training program basically to turn me into a cyber operator.
And then from there, I led counterterrorism operations as a tech lead inside there. I wrote the Air Force's initial CFETP for cyber operations, so I was one of the first few folks conducting ops. I think the 7th overall inside of the 315th. And then stepped out, became a private contractor, and then Eric Hipkins gave me a call. He's the CEO of Route 9B.
He gave me a call, asked if I want to change the world and change the way cyber's done, and so jumped on board and, and haven't looked back since. So what is it like being trained in the military for that sort of stuff? Is it a lot different than you see in the civilian world? I'd imagine it is. Oh, it certainly is.
I mean, if you think about it, in the civilian world, the way most folks are trained is, you know, they'll go through a comp sci degree program or something, and unfortunately most of that training is 1995 hacking at its finest, right, that they're learning to be able to provide defense. And most of your security products are already going through and identifying those. So in the military, what's nice is the military is learning firsthand kind of that new tradecraft, right? They're learning how an adversary maneuvers. They're learning nation-state level attacks.
And so what I'd say is the military folks have an upper hand compared to what the commercial sector is really seeing. And just because the amount of data and visibility that the government has over over some of these other entities. Do you think that there's stuff that we can learn on the, on the private side from what they do in the military? Are there ways that we could do things better in terms of training or getting people prepared? Yeah, so what I'd say is they're actually— the commercial sector is really coming around in the last couple years.
So when we— when I stepped out of the government, one of the big things I wanted to be able to do, and what Route 9B as an organization wanted to be able to do, was change kind of that mindset and And so what you're seeing now is commercial entities, your financial institutions, your energy grids, etc., are actually employing many military folks to come in and kind of stand up their environments. And so that includes building a brand new kind of culture, I guess is what I'd say. And that culture includes developing their own cyber operators, their own hunt teams, as well as educating their folks on some of the tradecraft that's out there. So that they're not just stuck with, as I was kind of mentioning, the comp sci education, the initial kind of, the initial, hey, here it is, cut your teeth on it, right? Yeah, exactly.
So what is your role here at Route 9B? What do you do on a day-to-day basis? Yeah, so I'm the Chief Technology Officer. I guess I would summarize that as anything technology-related comes through me. And so that includes the security of our own organization, the engineering of unique solutions for customer sets, right, having my hand there.
And then as well as the implementation of technology on the backend, so whether it be through security or through big data digestion or through our specific products like the Hunt platform or our credential assessment capability. Nice. So, and then I guess that leads us into, you know, what exactly is Route 9B and, you know, what do you guys do and what services do you guys provide? Yeah, so absolutely. So what I'd say is Route 9B's true differentiator is we're a hunting organization.
So we pioneered hunt, brought it into the commercial space in 2013. You'll see now there's a lot of other organizations using the word. It's overused, but really the difference is the way we look at it. What most organizations define as hunt, and I'll start with that, is they're really system log analysis or event log analysis. It's very reactive in nature.
So what Route 9B's true differentiator is, is on the other side of that wall right there, we have a 24/7 ops facility. Our operators will conduct remote interactive operations for our clients, proactively surveilling the network, looking for an adversary, and then actively engaging the adversary. So it's basically kind of human defender versus human attacker in real space, right? I call that kind of the cyber knife fight. So they're actively engaging each other and being able to go do a takedown.
If I was to make that more simple to understand, I guess if you were pulling onto a military installation, since we were talking about some of my background, as I drive onto the military installation, I will see a fence, I'll see barbed wire, I'll see cameras in each of the corners, I'll see a police shack, I'll see a barricade stopping me from being able to get on. As I pull up, if I'm supposed to be there for a meeting, I will pull up to the guard who will probably have a weapon. I'll hand them my ID, they'll check my access, and then they allow me through. As I continue driving through that compound, I'm going to see more troop formations, potentially with weapons. I'm going to see armored vehicles.
I'm going to see dogs. I'm going to see more cameras. I'm going to see badged access at buildings. So in that model there, when you look at it, if I was to liken that to cybersecurity, right now what most cybersecurity firms do and what most businesses are doing and calling cybersecurity is they're putting up a fence with barbed wire and camera systems. All necessities, but they're really just perimeter security products.
Every one of those things that I just talked about are defeatable. And so if I wanted to break onto that military installation, I bring a 13-foot ladder and I can now climb over the 12-foot fence. Now the camera's gonna see me, sure, but someone's gonna have to get there in time and be able to figure out where I went. The only real variable in that model there that I have to worry about in terms of if I was a burglar or breaking in is the human guard with the gun that is walking through that installation because he's using those camera systems and all that perimeter security product to help him navigate. And so I don't know if that human guard is going to shoot me or turn and run.
And so where Route 9B plays is we are the human guard inside the network. We use all of the network telemetry capabilities, all those perimeter security products, whether it's a FireEye product or CrowdStrike or Splunk. We use the client's infrastructure that they've already invested in to use that as network telemetry or intelligence inside there, informing the human guard that's walking around the network so that they can know if they have to hurry up and run over and respond, or when there's nothing that's popping, they can be looking at each window, making sure that the windows are locked and doors are closed. And so that's really our true differentiator. That being said, we play in a number of different verticals.
We have basically our hunt division, but we do your traditional IT security stuff— pen testing, vulnerability assessments, malware analysis, reverse engineering. I have an entire development division down in San Antonio that's responsible for my products that we sell to our clients. We have a training division, so we're responsible for the industry's first hunt certification, as well as we provide a good portion of mission qualification training to the cyber protection teams and other type operations. Then we have an MSS service offering as well that includes a proactive threat intelligence aspect. Nice.
A couple follow-ons to that. One, you mentioned the hunt part as being more proactive as opposed to the traditional reactive, looking at logs as they come in and maybe finding something. Do you feel like that hunt mentality can replace those proactive tools, or do you think that that's sort of something you should do in addition to the reactive? In addition. So what I'd say is that the defense-in-depth paradigm that has existed forever, being able to take all different layers of network telemetry, is kind of the way I look at it.
Taking all that network telemetry is fantastic, but if you try to automate it just by itself like many organizations are doing, the human attacker is always going to be able to defeat those passive technologies at the end of the day. The way I see it is you need all of that true defense in depth traditional, but really it's a redefinition of defense in depth. It's taking all that, using that as intelligence, and then sticking the human defense Defender back in the middle. It's a combination of manned information security with automation tied in to take care of some of the mundane tasks and then allow the human to actively be able to engage and respond. How do you typically see your customers using that sort of model?
Do they continue to do the reactive pieces themselves? They may have some monitoring or some tools that they look at and then bring you guys in sort of for that second level, the proactive looking around on the inside of the network for threats? The answer is it depends. I hate giving that answer, but if I was to take a look at financial institutions, many of your larger financial institutions have significant resources, significant funding. For them, they want to do everything in-house, and plus they have compliance and regulatory compliance requirements.
In that model, we will end up training them. We can equip them with our product. And then they can have reach-back support to our SMEs, or we could put an FTE on-site that's supporting them and helping them as kind of the advanced cyber expert. Then you have other organizations like retail where they've got very limited personnel in most cases, but they've got globally dispersed networks, right? And so in that model, often they'll have a very small staff.
Those staffs are responsible for all the traditional IT administration and IT security. So in that model, we are security as a service play. We can either provide MSS services for them and hunt services, or they may have already contracted an MSS service provider like Adel SecureWorks or IBM, and then we provide the return on investment through kind of that proactive component, right? And so you have 2 different varying components there. So it could either be done as a service from Route 9B, or we can just equip them, train them, and allow them to go Really, what I find typically is it comes down to vertical that we end up going into as to how sophisticated is their SOC, how much money have they put in, and then really how progressive is their CISO.
Do you guys ever find resistance to your services? My thinking being, you gave SecureWorks as your example there, right? I'm paying SecureWorks to do their MSS worked for me. SecureWorks came in and sold me and said, hey, we can detect all the stuff on your network. We're going to be proactive.
We're going to do all this stuff. Then maybe I'm finding they're missing things or whatever it might be, and I go, okay, well, what else can you bring to the table? You come in and say, hey, well, that's great. They're doing this stuff, but we can be proactive on top of that and be even better. If I was trying to sell that in terms of getting budget for bringing you guys in, I would think it would be hard for me to go, well, I already have the service over here that's supposed to be doing this.
How is it that I'm going to need to bring in some other service on top of that as well? What I would say is that, again, that comes down to how proactive is the CISO in that environment and really where are they at as an organization. Whether it's— I wouldn't just say Dell SecureWorks, I just say MSS as a whole, right, and not calling out any one organization. What I find is most MSS service providers, although they may paint themselves as proactive in nature, their proactive capability really consists of going back and looking at logs, as I had kind of mentioned in the beginning, right, looking at network traffic after the fact. And so although it may be near real-time, time.
It's still very proactive in nature. The way that we are employed when we come in is really unmatched in the industry. What I mean by that— it's a bold statement, I understand— but what I mean by that is we're taking a snapshot in time of the endpoints, the network security products, everything else that the client has inside of their environment, and we're basically acting as an attacker inside of their proprietary network. We're reaching out, we're executing capabilities just in time, right? So an agentless technology that'll reach out, target the endpoint.
We're very surgical and tactical in nature. So what we try to do is we try to understand that, hey, you are going to be breached, vice what everyone else is telling you. You're going to— the adversary is going to get in. What you have to be focused on is stopping the adversary from being able to get to their goal or being able to obtain their objective. And so when we start our proactive nature, what we're doing is we're looking at the crown jewels of that organization or that air quotes, your critical infrastructure, and then from there we slowly peel back the layers.
And so really what most organizations understand by the time we're done going through the pitch is that we're really a return on investment to everything else that they've bought, right? We are the now what for them, right? Because in most cases what happens is the MSS service provider may identify yeah, there was a breach, and then they tip that back to the client. The client says, what do I do now? And there's no answer for them.
Where Route 9B's ability, based off that cyber knife fight kind of engagement I talked about, is we can go and actively engage that adversary at whatever level the client's comfortable. Do you guys also do, when you just mentioned that, essentially like maturity assessment or recommendations for control coverage or your tools not doing this or missing these areas, that kind of stuff too? We do, and really what we do is we have this concept inside Root9B that we call Root Risk, which is really kind of— think of it as a report card for CISOs. It's really hard for CISOs right now to justify the spend that they're going through, and so the way that most organizations are doing it, unfortunately, is they'll take their SIEM product and say, how many events did we see in here? And then they use that to justify back to the CIO and the CFO.
The problem is how many got by that were undetected inside of there. What we do is we provide, through our services, we provide the ability to show how many critical risks they have inside their environment so that if, for instance, our credential assessment capability, if they have 1,000 critical risks, they can say, well, I'm not going to fix all 1,000 today, but over the next quarter, I'm going to take 250 and fix those, and then the next quarter, so they can show that their security team is actually making a difference and how much coverage area, to your point, they've actually been able to have inside their environment. Do you guys have a philosophy on how you look at those sorts of risks and the attacks that you're doing? I know a lot of people are moving towards MITRE ATT&CK, ATT&CK framework and other things like that, looking at sort of categorizing all the TTPs of attackers and trying to more systematically figure out, okay, these are the areas where you're lacking, these are the areas where you're covered. Do you guys use something like that?
Do you build your own? No, no, we do very similar models. I mean, we have kind of our own methodology obviously inside Route 9B, but we fit nicely into the MITRE ATT&CK framework and the cyber kill chain at the end of the day. And really, if you're a cybersecurity organization nowadays, days you have to fit into those because everyone knows those buzzwords. What I'll say though is for us it's very business context driven.
What I mean by that is if I'm a retail organization or if I'm trying to provide security to a retail organization, I need to understand the business context of that retail organization because it's not going to be the same as a financial institution, let's say. Unfortunately, the way that cyber has been done to date is organizations have looked at their competitor and said, Okay, what are they buying? I'll buy the same thing so that I can keep my job, right? And that's really, really how they've kind of justified their spend. So for us, what we do is we try to help them adapt and tailor their environment around the attackers that would come after them.
So understanding the business context and then understanding the attack groups and what the motive would be to come after retail organization X will help you start to define what that security model needs to look like. And so our threat intel team, staffed by former DOD guys as well, and good commercial entities. What they'll do is they will actually start to really map out the social footprint of that client before we go in. They'll start to understand what would be the pain points of that client. They'll sit down with the CISO, sit down with the CIO, understand where, again, air quotes, that critical infrastructure is.
Then they start reaching out through dark web components and whatnot and start trying to understand what attack groups exist. That would attempt to penetrate them, and then how would they come after them. It's really an outside-in type approach when we're providing security, looking from the outside back into the core, and then looking from the inside back to the outside and constantly making sure that there's no holes in the fences or that there's no car coming fast towards the organization. It's really trying to get out beyond the boundary. Obviously legally and not extending any of our capabilities outside their proprietary network.
Nice. So you mentioned earlier that you have a sort of a custom-built internal tool that you guys use to help enable the hunt stuff that you guys are doing. I wonder if you want to talk a little bit about that tool. Absolutely, yeah. So we have the Orion Hunt Platform.
It's version 2.0. We just released it at RSA. In fact, it was actually voted as a CSO online magazine top 10 hottest products at RSA, so we're very proud of that. Congratulations. Well, thank you.
So the concept of the platform is really, I guess, it's an agentless approach, right? And so what I mean by that is we don't deploy any persistent agent to the endpoint when we're going through to do collection, right? And so, and let me step back from a security perspective why that's important. If you take a look at many of these EDR or EPP-type platforms, endpoint detection and response platform, or endpoint protection platform, as they're called, EDR, EPP. What those do is they'll deploy an agent to the machine, very similar to an antivirus, but it'll allow for remote management.
Well, as a former attacker and having the skills from my DoD experience, if I would exploit onto a target, let's say, and I gain access to that target, Target X. Once I get there, the very next thing I'm going to end up doing is taking a look and seeing what security products do they have installed on that device that I just exploited, as well as what passive technologies do they have surrounding the device. Then, contrary to popular opinion, I'm not going to just lay down some command and control at that point. I'm going to steal their settings, I'm going to understand that security product, and then I'm going to bail, and I'm going to go back and I'm going to recreate it or go buy that infrastructure and I'm going to create myself a lab. And from there, what I'm going to do is I'm going to test.
If I do A and B, security product does C, so I'm going to do A and D. And then I'm going to constantly test, constantly test that environment of everything new that I want to deploy, because that's going to allow for me to maintain persistent access for several years potentially, right? So that— those products are fantastic, but they essentially tip the hand to the adversary of of the playbook of that security environment. So what we did is we took a slightly different approach. We said, okay, we want to be able to collect similar types of data. We want to be able to do remote incident response, remote forensics, all from one centralized location.
So I don't have to land Marines on the beach every time there's a potential incident. From here in the Adversary Pursuit Center, I can reach out and touch anything in the world as long as I have a route and some form of access. What we do then is we start doing the remote interrogation inside the environment. So I might want to scan 1,000 hosts today. Well, when I do, I'm going to put that, that list of 1,000 hosts in, and then I'm going to select the type of payload that I want to deploy.
And so for us, a payload is anything that causes an effect on the remote machine. That could be a collection. I might want to look at all the running processes on a Windows machine, or I might want to grep through memory looking for a specific string that's inside memory remotely over the wire. And so it allows for just-in-time execution of each of the payloads to deliver some form of intended effect to that machine, whether it be collection or response activity. And so what we do is, as we're going through using the hunt platform, that platform allows for all that interactive capability.
Everything that we do out of the platform is a RESTful API, and I don't mean to get too technical here, but now we're in my sweet spot, right? So it's a RESTful API. So when the operator says, I want to run this this particular payload against this particular host, that's an API hook. And so what that allows for is it allows for some of those automated routines we talked about earlier. We gave a platform when we created it, the platform was designed to allow the operator to interact and engage in that cyber knife fight aspect that I talked about.
But we do understand automation is a big part of kind of the cyber ecosystem. And so what we've been able to do through the platform is we can actually deploy deploy malware inside of an environment, right, as a use case we'll say. As the malware goes back through a network capture capability, let's say like ExtraHop or something to that effect, as it goes back out, if it hits a signature, right, maybe it's an identified command and control server that's been identified through IP address or something. As it goes back through that network capture capability, that can send trigger event over to an orchestration software, something like a Phantom or an NSA Walkoff or something to that effect. Then from there, we've been able to trigger auto-collection capabilities from the Orion Hunt platform to the target, as well as predefined auto-response activity.
So think of, I identified that adversary or APT 10001 is operating in the environment, and when he operates, he always uses some polymorphic codebase inside there, and as part of his operation, he always follows these 7 steps, 7 different steps, right, or these 7 steps in unison every single time. So through those types of capabilities, I can predefine and say if I see step 1 and 2 and 3 and 4, I know that step 5 is going to be X, and then the platform can auto-trigger a response activity to disrupt the adversary from being able to execute step 5. We've been able to actually collect the malware both directly from memory as well as off disk and then shove that into like Cuckoo or some of your sandbox environments. And so through that deployment, we've been able to have that inside of our environment, full autonomous, full execution, and then we allow for the human because that takes care of some of those basic setups, right, like lateral movement and things that are pretty pretty canned type exploiter tactics, we've been able to auto-collect and auto-respond in those environments and then allow the human to start looking at the more difficult tasks and be able to then roll those back into things like the Orion Platform, or we've recently invested in Darklight, which is an expert system, right, which then can pre-populate the way a human would respond, put those playbooks in, and then ultimately help trigger directly to the platform for collection. Yes, I mean, it sounds like because of the way that you guys operate, instead of doing more of a continuous monitoring, it makes more sense for you guys not to have that agent that's there that's always collecting data, right?
Because that's— you look at your Carbon Black or other EDR products like that, it's, all right, well, we don't know exactly what we're looking for, so we're going to collect every piece of data that we can possibly think of always, and then at some point we can look at that data and figure out what's going on. You guys are being a little bit more surgical, it sounds like. Oh, hey, we see some sort of indicator. All right, now we need to go out and do XYZ to go ahead and remediate this or other steps like that. Yeah, absolutely.
I'll tell you, those EDR platforms, I know I probably sounded negative, but they do serve a purpose. They are fantastic sources of data, and so what we've been able to do on the backend, because we'll leverage those if our clients have them. What we do on the backend is we're actually cross-correlating data from the EDR platform. So like if they had a Tanium, let's say, that's doing live streaming, or you mentioned Carbon Black, I can live stream everything from that host. And then what I can do is my just-in-time execution against a similar host and say, let me take a look at the memory structure.
Oh, there's a DLL inject directly into a running process here. It wasn't identified by the EDR platform, but I saw it. Now let's form formulate some type of response, whether it's through their product or through ours. Yeah, so since you don't have an agent, you do have to have some way to get access. How does that part work?
Is it service account based? Is it— how is it that you actually get access to the different systems you're trying to get access to? It's really tailored, so it was designed to be very modular in nature. So I can actually deploy my payloads because there's both remote payloads and then I can dump them out as local payloads. And so what that means is I can take a payload and say, I want to throw it over top of Tanium, or I want to toss it over top of EnCase Enterprise, or whatever have you.
If the client has a significant engineering aspect and says, this is only approved in here, then hey, we're going to facilitate that. Now similarly, what we can do and what's worked pretty well is we try to blend in with the operating environment. We'll typically ask for some form of credentials if we go in. They'll give us some form of elevated creds that can do remote interrogation that has those accesses, and that can vary. Sometimes they want to give us domain admin creds depending on their staff, or other times we'll say, hey, create us credentials that'll last for 2 hours and then lock them out so there's no potential replay, right?
And then from there, what we'll do is we'll shove over a payload. The payload acts as a stager, and we try to do direct memory injection everywhere possible. And so the idea is using that offensive mentality to provide defense. We don't want, if there's an active thinking adversary on that machine, for the adversary to be able to copy off our capability and know what we're trying to do. So the stager will go across, and then from there, every time we go and deploy one of the payloads, the payload gets injected into memory, we do the collect, and then we clean up after ourselves.
And so then at the end, we basically self-destruct, and then we use encrypted communications for the full path back. And then, like I mentioned, we clean up everything. All that forensic residue that they'd be able to leverage is all pulled off of the machine, minus we leave obviously event logs and things like that from a chain of custody standpoint. Nice. So I want to switch gears slightly.
That was all super interesting. I thought that was great.
A lot of people, you know, we've talked about Route 9B a number of times on the show, but besides that, a lot of people might not be familiar with you guys. And actually, the way that we became familiar with you was a couple years back there was some scuttlebutt on the internet, Brian Krebs and some other folks, I'm not sure exactly why, but essentially called you guys out, said, hey, there's this Root9B company, they're a bunch of frauds, or I don't remember the exact wording around that. First of all, I thought it was sort of interesting that they would call you guys out, but I wonder if you have any backstory on that or wanted to speak to that at all. So around that time, I think what you're talking about is probably the APT28 report. What ended up happening, that was May of '15 if my dates are correct, what ended up happening was our threat intel team had identified indicators of compromise and had identified APT28 prepositioning for an attack against financial institutions and others.
They released a report. There was some heavy marketing, right? That was Route 90, very early in our stages. The heavy marketing, a little bit of chest thumping going on. Going on in there, right?
And not afraid to admit it, but you have to start somewhere, right? So came out with our first report, then what you saw was Krebs said that it was incorrectly identified as African phishing threat, and then obviously he had a much larger follower base than us. What I'll tell you, right, is outside of that, what I'll tell you is that since that report has come out in May, the malware hashes that we identified as well as the command and control that were included in there were later used in the German Buddhist Egg exploit that ended up happening against the German Parliament. That was then attributed shortly after our report, about a month or two later, by Claudio. He's a pretty famous researcher.
Claudio is the one that did the investigation, and he verified that both that command-and-control server as well as the malware hashes were APT20X. Potentially Russian nation-state. Since then, that same command-and-control server has been linked to APT28 and has been in other reporting that's been utilized. And so what I'd say is initially we were— no one really knew who we were, and that report coming out I think was potentially for organizations when they saw it, like a Krebs or something, hey, who is this Root9b organization and how are they far exceeding the FireEyes and the CrowdStrikes of the world, right, that should be putting these types of reports out. And so, and then just the linkage that's there.
And so, so what I'd say is that that was kind of the initial component that came out. I guess what I'd say is we were later reported a second time by Brian Krebs. I think it was Rest in Peace Route 9B. As you can see from the spaces that you're sitting in today, Route 9B is not rest in peace. We are still very good and we're thriving.
What I'll say is the organization, what the events that happened last August timeframe, what ended up taking place was a foreclosure on the publicly traded company. And so, so to clear up any confusion, you have Route 9B, the cybersecurity Route 9B LLC, which is a cybersecurity arm, which is us, right? It's always been us. And then what you had was you had a parent company and we were a wholly owned subsidiary of the parent company, and the parent company was Route 9B Holdings, which was being traded on NASDAQ. The senior preferred stockholders at the time decided to foreclose on the parent company, which was Route 9B Holdings.
So 2 separate entities here, right? Route 9B LLC, Route 9B Holdings, child and parent. And so they decided to foreclose on the parent company, which was Route 9B Holdings. We were a wholly owned subsidiary underneath. The foreclosure ended up taking place, and then Tracker Capital ended up coming in and acquiring the cybersecurity component, which was us.
I think the problem with the, the reporting that ended up taking place is there was confusion between the name, between Route 9B Holdings and then Route 9B LLC, and it looked like we potentially looked like to, to the uninformed that we were one entity, when in fact we were really two separate, and all the cybersecurity assets were underneath of us. So I'm happy to report that Yes, we're not— you're still here. We're not rest in peace. We're actively growing. The organization's doing well.
And we effectively came out unscathed. I mean, we have the majority of employees that were with us during the event are still on staff. So, so things, things are looking promising here. Yeah, I'd also heard some reporting during that time that, you know, potentially you guys, your assets would be sold off, or, you know, you would be, you know, pieces, parts here and there, or maybe another company would buy you as part of a deal to make you their security operations play or something like that. Did you guys have any fear at any time that you guys were going to be affected by that?
No, to be honest with you, what we've built here, to us, we believe that we have the true differentiator in the cybersecurity space. We have the most talented workforce, another bold statement, but we have the most talented cybersecurity workforce that you could have, especially for being the size that we are. So for us, I mean, obviously going through that event, there was lots of phone calls from many large organizations, right? One, to try to recruit our people, but then also try to bring us on staff as a potential other entity of theirs or another subsidiary. I'll tell you that we felt very confident going through it, and that's how we were able to keep the people together that we'd come out unscathed on the back end.
And I'll tell you, being private is— it's a godsend. I think I'm much happier in kind of this role because we get to be heads down, focus on execution, and not have to worry about criticism from organizations or people like Brian Krebs. Yeah, no, I hear you. Um, that you mentioned your workforce. Um, so we are Colorado Equals Security.
Um, you guys are down here in Colorado Springs. Springs. Most of the coverage that we have is up in the Denver area since Rob and I are Denver-based, but what is it that makes Colorado Springs so great for cybersecurity workforce? Yeah, absolutely. So what I'll say there is a couple different factors.
Colorado is a beautiful, beautiful state. Sure is. Full of tons of outdoor activities. Right? And so from a recruiting perspective, it really helps because you can take some of the DOD entities, right, which are most of the talented workforce there is located in Maryland or San Antonio or Georgia, right?
And there's a good portion up here as well. But many of those folks want to be able to relocate. So it allows for the relocation components, allows for them to be able to, you know, to be able to go and recruit folks and bring them into the state. In addition to that, I mean, you have military installations right up the road, and then you have a very, very unique kind of small business entrepreneurship that takes place between Denver, Boulder, and then here, which presents a good portion of folks that are coming out of college that want to move into the cyberspace, want to move into the security space, and they're already in our backyard. Yeah.
So did you Did you come to Colorado Springs specifically for Route 9B, or were you here prior to that? No, so I came here when we decided the headquarters was going to be here. Eric Kipkins, our CEO, had already lived here, and so when we took a look at different locations— I was living in San Antonio at the time— when we took a look at different locations where we'd put it, we felt that with Route 9B, we wanted to change the way cyber really was being done, right? We wanted more of that proactive approach, and really what we wanted to do is we wanted to stop a cyber 9/11, right? We wanted to be focused on the adversary.
And so we felt, where else to put it than right in the heart of America, right? Put it right in the center. And so there's a couple reasons for that. Well, one, you have NORTHCOM right up the road, and we felt at the time that, hey, you know, cyber right now is really focused around IT assets. But, well, that's what most people were focused on.
But your nation-states are going to be focused around energy. They're gonna be focused around satellites. They're gonna be focused around all your military-type initiatives and objectives, right? And so for us, having, having that in our backyard, we figured, hey, why not, why not put it there? Plus you have the military installations in close proximity to be able to go and recruit some of the staff when they go to get out, right?
It allows for them to transition into a commercial entity that has a very similar culture to them. And so we put the headquarters here in Colorado. I relocated from San Antonio. We do have facilities still in San Antonio where most of my dev staff sits, and then we've got facilities in Maryland, Hawaii, Idaho. You guys didn't decide to headquarters in Hawaii?
That seems like a pretty logical place to put your headquarters. Unfortunately, it's pretty expensive. I got to imagine. I got to imagine. It does seem like Hawaii is a pretty central place for a lot of application security stuff though, so you guys could have gotten a lot of AppSec people.
Anyway, the, the one other thing that I wanted to touch on, we've covered several stories on the podcast about the Cybersecurity 500. It's, it's a report, as I'm sure as you know, that comes out talking about the 500 most innovative cybersecurity companies. You guys were at the top of that list for several versions of that list, and then the most recent one You guys had an amazing drop, I think almost 150 places down the list. What's up with that, I guess? Steve Morgan and the folks over at the Cybersecurity 500 have their own method to be able to go through and assess organizations.
It's mainly focused essentially around the types of clients that you attract and then the business model that you have. For us, I think, to be honest with at the end, we still have the most unique business model in the space, as we've talked about in here. And so when we were number one, you would find that probably around the same time as potentially the foreclosure and some of that confusion is really where we started to drop. And so really it comes down to the way that they do their assessment based off of their board discussions. And I guess on their most recent kind of assessment, they felt that we're we're further down the list.
Do they talk to you guys about that? Or is it all external entities that they talk to? No, they'll have, they'll have communications. Mostly what they'll do is they'll talk to clients or folks that are using us or where we're involved in the industry. And then, then whatever their criteria is to be able to come up with kind of that assessment is, is really how they do it.
Gotcha. Well, we are getting close to the end of time here. Was there anything else that you wanted to talk about that we haven't covered yet? No, I think this has been really good. I think we got to go through the products, walk through the company, do some level setting on some of the previous publicity.
Like I said, I mean, it couldn't be a better time inside of Route 9B. We feel confident about the future. I think we're in a really good spot to change the way cybersecurity is done, right? Instead of just being focused on IT security like most most organizations. We're really, we're adapting a different model which converges IT security intelligence and OT security together.
So I just appreciate the time to be able to walk through who we are and that, you know, we're still here and we're moving. Awesome. Well, Mike, I appreciate the time. It's been great talking to you. This has been Colorado Equals Security, and we'll talk to you next time.
Sounds great. Thanks.
Learn more about the Colorado security scene at colorado.gov/security.
Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.