All episodes

Cody Cornell, CEO & co-founder Swimlane

Apple Podcasts Spotify SoundCloud

In this episode:

Cody Cornell, the CEO and co-founder of Swimlane is our feature interview this week. News from: VF Corp, Honey, Gusto, Direct Defense, Intelisecure, Ping Identity, LogRhythm, Coalfire, Swimlane, Threat X and a lot more!

A lot of companies are coming our way

I'm not kidding, lots of companies are coming to town. The Springs has lots of jobs too, and not enough workers. Direct Defense and Intelisecure make a national list (it's a good thing). Robb gets honored. Blogs from LogRhythm, Ping Identity, Coalfire, Swimlane and Threat X.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11903 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

What you want, baby? I got what you need. You know I got it too. All I'm asking is for a little respect when you come home. Just a little bit, baby.

Just a little bit at home. Just a little bit. The Colorado Equals Security Podcast. Is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.

My problems when you get home. Just a, just a, just a, just a baby, just a baby. Welcome to Colorado Equal Security. This is the newscast for episode 80 for the week of August 20th. Alex, that was some Aretha Franklin for you.

It's a sad week, Robb. It is a sad week. We know we are not a national show, so I had to find a little bit of tie-in. Why would we want to talk about Aretha, who, who obviously passed? Was it Was it Wednesday she passed?

Thursday she passed? Yeah, I don't remember. During this week, during the last few days, she passed away. So I got a story for you. Okay.

Back in 1968, Aretha Franklin was, was scheduled to come play at Red Rocks Amphitheater. And back, back in 1968, it cost about $6 to get a ticket. Wish it still cost $6 today, Robb. Absolutely. So exactly 50 years ago, she was scheduled to play there.

She, she shows up and her promoter had had made some mistakes in, in the finances and didn't have her $20,000 prepayment ready to give her. So she got in front of the stage and she said, I'm not playing because I didn't get paid. And, and there was a riot at Red Rocks. They destroyed a grand piano. They set a bunch of stuff on fire.

And Aretha Franklin, she, she took her, her, her car back to the— I think it was the Hilton back in Denver. And, and she did a couple of interviews and, you know, said, hey, I gotta get paid before I sing. Hey, that sounds reasonable to me. You know, I was glad that when I showed up today you had my check because otherwise I would not be on this podcast. Absolutely.

Yeah. So there was a little conversation at the most recent— oh shoot, what was it? I should have been prepped for this. But one of the most recent performances she did just last year, she set her purse down on the piano before she started and apparently it was symbolic of back in the pre-civil rights era where Black performers would always need to try and get paid ahead of time in order to be treated fairly. And I think she's trying to be an example of, hey, we're still here, and really trying to get her message across loud and clear.

Yeah. Anyway, so interesting story. Very sad. She was an amazing singer. I really enjoyed it.

All right, we do have some housekeeping. Go ahead. Sure. So we have a Slack channel in case you haven't heard of that before. Great conversations going on in there.

How do you join the Slack channel? You know, it's very easy to join the Slack channel. You can go to our website, colorado-security.com, and there's a button there that you can click and it'll give you all the details. Yeah. And it's also in our, in our show notes that we'll be mailing out.

Also, we have a mailing list. Again, if you go to the website, sign up for our mailing list, you will get the show notes emailed to you every week so you can hear about all of the wonderful stuff that is in the podcast each week. We'd love it if you would subscribe on your favorite podcast listener. If you're using an iPhone, go to the podcast app or whatever you use, and Google Play. And of course, rate us wherever you can, you know, go out and give us 5 stars and hopefully get new listeners to join us.

Also, if you would like to give more support to the podcast, we do have a Patreon campaign going. So this is where you can subscribe to, to give us money to help support the show. That of course goes directly into the show itself, not into Robb or my pockets. Buying equipment hosting fees, things like that. And we would like to thank Daniel Clements.

Daniel is actually an intern for me this summer, and he must be very close to getting a real job because he has enough money to afford to support the podcast. Awesome. Daniel, thank you very much for your support, and congratulations on your real job. It's awesome. All right, should we jump into the news?

We should. All right, so Colorado is rated the 8th best place to open a business. These are out of states here in the US. 8. How can we only be 8, Robb?

This is crazy. Well, there's a bunch of powerhouse states above us on the list. Yeah. Places like Nebraska, South Dakota, Iowa. All great places.

At least North Dakota is not ahead of us on the list. Oh, wait. No, they're not. Oh, they are. North Dakota is number 6.

So we don't have a ton of respect for this particular list. But the criteria it uses is what's the cost of starting a business? What are the taxes, the labor market? Cost of living, startup activity, access to capital, and quality of life. These things, such small percentages across the board, it's really hard to get a good answer here.

About half of— 50% of the criteria is based on how cheap it is to do business in the state. And so, you know, you get places like Iowa and Nebraska and the Dakotas where it is cheaper to operate. So Wyoming. Yeah, Wyoming. But you know what I don't see ahead of us on the list?

I don't, I don't see Austin. So suck it, Austin. Exactly. Suck it. Next, a great announcement from this week.

VF Corp announced that they are moving their headquarters to Denver. This is actually a really big deal. Yeah, this might be the story we spend the most time on today. VF Corp, I had never heard of them before, but they own a ton of brands that we do know. So North Face, JanSport, Eagle Creek, I don't know, Altra.

They also own Dickies and Timberland and Vans. They also currently own Wrangler and Lee. They have a lot of brands underneath them. Yeah. And even some brands that I didn't notice or that I don't know.

But yes, lots of them. They're a very big company, multibillion dollars in revenue. There will be one of, if not the highest companies in terms of market cap when they get here. They will be the number one market cap company. They won't be the number one revenues company.

Exactly what it looks like. So Previously, they owned so many different brands, they've never really consolidated all the executive leadership from their brands. And this is their new intention. They're moving their headquarters, which was in Greensboro, North Carolina, to Denver. And then they're gonna consolidate all their different headquarters into one place here in Denver.

It's gonna be a big force here in town. We have given them a very significant tax incentive to come here, which is about $27 million, I think the second largest that's ever been given. However, very cool. VF Corp has made it clear that the incentives aren't the reason they're coming. And in fact, they vowed to match every tax dollar that they receive with a donation, which is going to go directly back into supporting local charities here in Denver.

That is pretty cool. Yeah. They also said by 2025 they will have 1,200 jobs here. So of the 70,000 employees that they have, that's a pretty good percentage. So we mentioned that they're going to be the largest market cap at about $36 billion in market cap.

And the current largest here in Colorado is Newmont Mining, which is about $19 billion. So really twice as big as the number 2 largest market cap. Looks like second largest now is Dish at about $16 billion. That is awesome. So we welcome— so one trivia for you, Alec.

What does VF Corp stand for? Very Fine Corp? Vanity Fair. It was Vanity Fair Clothing, actually Vanity Fair Lingerie, which had nothing to do with the magazine. But a few decades ago, they changed their name and And now they're just, they're just basically a private equity who only owns everybody up.

Yeah. Yeah. Pretty cool stuff. That is pretty cool. Next, Honey signs a lease on the Boulder Street— Boulder, Boulder Street— Pearl Street Mall.

So Honey, which is a Los Angeles-based tech company, they have a browser extension that helps you save money on websites, has signed for some space on the Pearl Street Mall. So kind of going back to our point that we are the 8th place 8th best place to have a business? Well, here's the 3rd example of that. Um, we have, uh, Gusto, who's, who's had an office here in Denver for a while there, but their Denver office has actually grown bigger than their San Francisco headquarters, and they expect to grow, um, another 100 folks or so here in Denver, and it's going to be, um, their largest going forward as well. Um, so they were formerly known as ZenPayroll.

They do online HR and payroll for, for small companies, um, and they're they basically have, uh, have invested as Denver is the place where they want to have most of their workforce. Yeah, you don't see them, uh, consolidating on North Dakota or, uh, or Iowa. So, you know, I guess number 8 is a good place to be. And I did find a job for our job section from Gusto. Oh, nice.

Um, so we'll talk about that a little bit more in a little bit. Cool. Uh, next, there was an article, uh, in BizWest interviewing some CEOs from northern Colorado companies. And they said that talent and security breaches, uh, weigh heavily on them. So a lot of conversation about how it's hard to find talent, but then the other half of this article is all about how the CEOs are worried about the security of their organization.

Yeah. They mentioned how, you know, many small and medium-sized businesses, if they have a security breach, uh, can risk going outta business. That was a concern for them. Uh, you know, other general things like, uh, phishing or email security, talking about how, uh, they and their companies do phishing email scenarios, other things like that to try and help maintain their security. Yeah, there's a, there's a quote in the article that, you know, the, a cyber breach of any significance can definitely mean shuttering of the doors of the business.

And these CEOs are well aware of it. It's interesting, you know, Alex, you and I were at a CISO event on Friday where the FBI presented the stat that 60% of small businesses that they were hit by a breach end up going out of business. And I haven't seen these examples. And it sounds like, you know, these guys are well aware of that, at least. Yeah, it would be great.

Well, not great for that company, but it would be good to have a hard example. People keep saying it. Having those examples of the companies that have gone out of business to hear their stories would be interesting. Yeah, agreed. So there's a, there's a story in here really all about how cybersecurity is booming in the Springs.

So there's a recent study that says cybersecurity brings in nearly $1 billion of annual benefit to the local economy. Um, and this is, uh, this is just to the Springs, right? So if you, if you guys are interested, there's a, a TV clip in the, in the link. You can watch a story about this. You don't have to just read it.

Um, they also mentioned the stat that there's supposed to be about 1.5 million jobs across the US just, uh, that are gonna be open, unfillable in the next few years based on cybersecurity. And they also mentioned how it is lucrative to be in cybersecurity. In that the average cybersecurity worker in Colorado Springs earns about $104,000 annually. So that'd be great if I was making that kind of money. Yeah, absolutely.

One of these days. There are— so we have the Inc. 5000 list, Alex. This has finally come out. We've been anxiously awaiting this for, for months, right? You know, I mark this day on my calendar every year so I can go and check out the new Inc. 5000 list.

So Inc. 5000 is the fastest growing companies across America. And there are 136 Colorado businesses that made the list this year. Companies like PopSockets, which is based in Boulder. You know, those silly little things you can stick on the back of your phone to hold it. Those silly little things have made $169 million in revenue in the last year.

Wow. Yeah. Also Velocity Global, Mindful Health, Pax8, and Adcelerant were high up on that list. They were all in the top 100. Uh, there were a couple security companies that were on that list as well.

Direct Defense, we've talked about before, they grew 395% and they were at $1,224. And InteliSecure grew 185% and they were at $2,659. And these are 3-year percentage— percentages of growth, I think. So it's over the last 3 years they grew by those percentages. Anyway, congrats to those 2 companies for their, their steady increases.

Exactly. Also, we had some awards nomination or announcements this week. The Denver Business Journal revealed their 2018 C-Suite Awards. And so this is basically awards for executives for Denver area businesses. And there was someone on this list that was honored that we know.

Hmm. I wonder who that was. I believe it was Robb Reck. Yeah. Yeah.

I'm on, I'm on the list, so we don't know. How that's all going to shake out yet. It's, uh, I think the results actually come out on the 25th of September. Yeah, so this is listing all of the honorees. They have not made the final announcements of who wins which awards yet.

We'll see if I can grease the right palms to, to make it happen. Well, I think this is a start, right? We're, you know, giving them some positive press. I'm sure that'll help. There you go.

Uh, next story, we have a story by LogRhythm about measuring and optimizing your SOC performance with new LogRhythm tools. Alex, you're a LogRhythm customer. Any, any insight of these 2 new tools, the The shiz? Yeah. So LogRhythm has been doing some good stuff in tracking metrics for security operations.

And this is sort of adding to those dashboards and views of that. You know, how fast are you getting to your, your investigations and your incidents, you know, mean time to closure, other things like that. Also some sort of more operational metrics and dashboards. Anyway, it's some good stuff that they put out. Have you used these new tools to fire anyone yet?

I have not used him to fire anyone yet. Well, I'm pretty sure you're missing the boat then. Very soon. All right, next story is actually a blog by Ping, and I can take this one a little bit. Really what they're doing is showing how customer identity solutions can help meet the requirements of GDPR.

So obviously we know GDPR requires or gives consumers the right to erasure, so you can erase your data from a system. You have to consent to things. You have to be able to take your data with you, it has to be secured appropriately. So how does, how does CIAM, customer identity access management, do this? Well, through having unified customer profiles.

So there's one place that they go to, to give their consent, to say what they consent to, to see what, what data there is. There's easy consent capture and then auditability of that consent capture that you get through those types of systems. Self-service, for all these things versus having to, to send a help desk ticket or contact support to get this stuff. There's some other things in the, in the blog post as well, but really having this, you know, this one place where you can do all of the interaction really addresses most of the concerns. Sounds pretty cool.

Uh, Palo Alto— excuse me, uh, Coalfire had a blog post this week about the dangers of client probing on Palo Alto firewalls. This was actually an interesting blog post. Yeah, I read the whole thing. I, I don't, I don't frequently read a whole thing, but this was interesting. Yeah, so talking about how You know, Palo Alto, one of their sort of claims to fame is they, they have policies that follow the users.

So they have to know, you know, who's on what computer and other things like that. And this is probing unknown devices to know who is on those devices and some potential vulnerabilities that lie in that probing. So basically you have the, you have an account that the Palo Alto firewall has on it, and that account should have some kind of rights on the localhost. Right? So what they're trying to do is they're sending, they're sending these credentials out to the, out to the host to log in and say, let me see who, who's logged in on that system.

Now, if you have an unknown host that you send these credentials to, that unknown host can capture the username and password, and now they have an account that has access, some level of access, to every other agent on the network, right? Yep. So it's a, it's a pretty compelling thing. And as you go through this blog post, um, they describe that Palo Alto— I don't think Palo Alto is really the one missing the boat here. They, they make it pretty clear what the risk is of doing this and, and how, how you should do it right.

But if you implement this the wrong way, it's a pretty massive risk and really makes it easy for someone to get access across your whole organization. Yeah, it was a very good blog post. I would recommend reading that one. Esteban Rodriguez from Coalfire, thank you for writing this up. Good stuff.

Uh, next, uh, Swimlane had a blog about, uh, farewell to their summer interns. So They, uh, Swimlane participated in a, uh, CU program to have some summer interns, and it sounded like they all had a good time. I think, you know, while it was an interesting article, I think Robb also wanted to use this, uh, and I wanna use this as an opportunity for us to say thanks to our interns that we've had this summer. Yeah. Uh, so I wanna say thanks to, to Daniel and Kim who were great this summer for us.

Yeah. And, and Nicholas Connick. Nick, good job working with Ping this summer and, uh, good, good luck at school the 6th year as well. And of course, we did learn a little bit about Cody Cornell, who is our feature interview this week, and that Cody, you know, if you read this, this blog post, Cody loves peanut M&Ms. And in fact, it sounds like he might be addicted to peanut M&Ms.

Yeah, so, you know, I'm sure if you want to get a job at Swimlane, all you have to do is, you know, send a truckload of peanut M&Ms. Absolutely. Our final story this week is a blog post from ThreatX, and it's a— it's actually an interview with their CTO and co-founder Andrew, I think it's Usecas. Andrew is one of the, really the technical guy behind that product and goes through what they do. We're gonna have him on our show pretty soon, so I'm not gonna go too much into detail on it.

I don't want to bury the lead when we do get there, but hopefully it's gonna be interesting. Yeah, should be good. All right, now to move into the Slack message of the week. Thanks once again to Andre Gaida, who is our sponsor for the Slack message of the week. Andre, we appreciate you keeping this going for us.

So this week we have a, a slightly different Slack message of the week that we're gonna, uh, honor. Usually it's a single person that we recognize, but this week we had a, a large discussion about lockpicking, which result— excuse me, which resulted in us, um, eventually creating a lockpicking channel specifically. And that, uh, group is going to get together, um, in the not too distant future to, to do some lockpicking in person. So we're just gonna donate some Colorado Equal Security swag to that meetup so that they can give away however they see fit as part of that discussion. Sounds good.

All right, moving over to our events coming up in the next couple of weeks. As a reminder, on our website colorado-security.com, we have a calendar of events, stuff going out to the end of the year or so, and we have a lot of stuff coming up in the next couple of weeks. First, Alex, do you want to mention our Ballard SPAR Summit we got coming up? I don't remember the dates of that exactly. Yeah, so we are working in conjunction with Ballard Spahr to put together the Colorado Cybersecurity Summit.

This will be the second year that they're doing that, and this is a legal-focused cybersecurity event that is happening on the 18th of September. So that is a half day in the morning, and we will be a part of that. So we would love to see all of you there. Awesome. Looking ahead to this next week, on the 21st, ISSA Denver has the Women in Security meeting coming.

That's going to be great. Um, as all— as they have been every other time. I think if you, if you're a woman or you're someone who's interested in helping support women have a bigger role in security, please show up and help, help the organization. On the 22nd, ISSA Colorado Springs is doing their Cybersecurity Training and Technology Forum. This is their big conference of the year down in the Springs, so go check that out.

Good chance to get a lot of CPEs. Also on the 22nd, SecureSet has one of their career conversations with Scott Bowman and Alex Reed. On the 23rd, ISSA Denver is having a happy hour. On the 27th, the Denver Splunk Group is having a meetup. So this is a new thing we haven't talked about before, but it is open for anyone and it's free.

So if you're interested in getting to know more about Splunk, especially how can you— how you use it for security, this group would be a good place for you to go. On the 28th, the GDPR Meetup Group is having an event The Single Subject Search: The Missing Link to GDPR Individual Rights Compliance. And finally, on the 31st of August, SecureSet has one of their capture the flag events. So this is similar to what they usually do from 5 to 6. If you show up early there from 5 to 6, they'll give you kind of a tutorial on how to do a capture the flag, and then at 6 o'clock they'll, they'll dive right in and you can participate whether you're experienced or inexperienced.

You'll now, you'll know how to do it. Awesome. Let's move over to jobs. Uh, first job this week, ForgeRock is looking for a product management director for IoT. Uh, LogRhythm is hiring a manager of security operations, and this is, uh, because Greg Foss has moved into a new role over there.

Congratulations to Greg with his new research role. Uh, that should be a lot of fun, and of course it opens up a brand new fun position for someone else. Exactly. Uh, Slack actually has a couple jobs. They are looking for a senior security detection and response engineer and also a senior product security engineer.

NBCUniversal is hiring a senior product security tech lead. Red Robin is looking for a senior security engineer. Splunk is hiring a technology advocate. This is interesting, it's going to be working on collaborative incident management, working with developer relations, and it's part of their DevOps and VictorOps business unit. UDI is looking for a security analyst.

Zanterra is hiring an IT security analyst. And as Robb buried the lead earlier, Gusto is looking for a risk operations person. So risk operations here is, is actually a little different. It's not necessarily security, it's really more fraud. As we mentioned, they are a payroll organization, so it's looking for payroll fraud and an internal fraud.

Frog protection. Frog protection. Yes. Yeah, I think we're on the same page. Keep the frogs out of there.

Absolutely. All right. Uh, I think that's it for, for our news. We have a feature interview here with Cody Cornell. This is part 2.

Cody, we talked to a little bit over a year and a year ago, I think actually a year and a few months ago. Um, they've had a lot of growth at Swimlane in the last year and he's excited to tell us all about it. And of course, The biggest part of the interview is about peanut M&M's, right? Um, I, I don't want to give it away, Alex. Okay, you're gonna have to listen to find that out.

All right, all right. Well, we'll talk to you next week. Thanks, Robb. Hi, this is Mary Haynes, VP of Network Security at Charter Communications. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals.

This is the Colorado Equal Security podcast, and today I am revisiting a meeting we had last year with Cody Cornell. Cody, you are a co-founder and you're the CEO at Swimlane up in Louisville. So it's been, it's been over a year. I think we said it's been about 15, maybe even 16 months since we last talked. So what's been going on?

What is— what's changed for you guys in the last year? I mean, I think the things that really kind of stand out for us is that our team has expanded dramatically in the last, you know, 16 months or however many months it's been. I think the market which we're in, the security automation and orchestration space, is garnering a lot of attention. Both of those things going together has made for pretty exciting times at Swimlane. We're kind of enjoying the ride and enjoying expanding the team and bringing on customers and all the stuff that goes along with that.

It's been a fun ride for the last year or so. I think it would make sense to start over for those who didn't listen last year. Obviously, go back and listen, but Why don't you take 2 or 3 minutes to just talk about what does Swimlane do? Yeah, so Swimlane falls into the security orchestration automation response category, which is basically our goal is to automate the work that security ops teams do on a daily basis. So anything from alarm enrichment to phishing response to vulnerability management all require a lot of repetitive tasks for those security teams.

There's been a lot of innovation in the threat monitoring and threat detection space, but very little innovation around kind of the people, which has historically been a bottleneck for a lot of organizations. Too many alarms, not enough people is kind of a common theme you'll see at any trade show. And we're really hoping that building an automation capability that enables those analysts to do more, more efficiently, more consistently, will help organizations provide better security services, either if they're a service provider or internally into their organization. So right before we recorded, I had a chance to see a demo of your product, and get a better understanding of what you guys do. It seems to me like a lot of what you do has an overlap with the traditional SIEM market, what a SIEM product would do.

Obviously, you guys are not doing— I don't believe you're doing like a central log repository aspect, right? That's not part of what you do? Correct. Yeah. But you do have quite a bit of you can help with enrichment of information, and you help with some of security analytics as well, as you'll help automate some of the security analytics stuff.

How do you see your technology coexisting with, augmenting, taking the place of a traditional SIEM product? Yeah, so I really see what we do as complementary to SIEM. I mean, to your point, we're not a log aggregation source, we're not a log management system, we're not doing correlation of alerts and logs as kind of our core competency. It's when you have that point in which an analyst needs to take over, where remediation needs to happen, that's really where Swimlane picks up. I mean, traditionally that might be something like a SIEM case management system, it might be you're sending your alarms into a ticketing system, but then you're really managing them by hand.

There's a lot of copy and paste that happens there, so we really see what we're doing as complementary to that. So yeah, we're taking in those alarms, be them a high-fidelity alarm from something like endpoint or network or proxy or whatever it might be, or we are receiving those from the SIEM. We're taking all the steps that you hope that your analyst team would do, setting a severity score, enriching it from all the available sources both internally or externally, and then from that making decisions. Does this require a notification? Is this something that we can— a workstation we can automatically quarantine?

Is this a revenue-generating ecommerce server that we need to notify the application owner on that you can take offline. So there's different degrees of remediation that you see people taking, but the goal here is that as organizations go from hundreds to thousands to tens of thousands of alarms or tasks they have to do in a given day, that becomes overwhelming and really kind of untenable for organizations to actually manage on a daily basis.

The UI of your system seems kind of reminiscent of what I would see from a SIEM. The dashboards, it'll show alerting coming from different systems. How do you guys see, you know, in a SOC that has adopted Swimlane as the automation orchestration for their workflow, how do you see them using your guys' tools versus their ticketing system versus their SIEM in terms of what's up on the screen most of the time? How do they move between them? Yeah, so I mean, within Swimlane, we have a case management capability, we have reporting and dashboarding, and obviously all the workflow and automation that goes along with that.

I think some of the difference you'd see in a dashboard from something like Swimlane is if you think about the metrics that you're trying to gather from your security team, you have your mean time to respond or dwell times or things along those lines, that really is measured after the SIEM has generated an alarm. So what's the time it takes to go from the point where you got the alarm, did the enrichment, identified your remediation, take the remediation? That really doesn't generally live inside of the SIEM. That is usually in a ticketing system or some other system. So we're consolidating all that, so that's a little bit different.

There's that component that I think is a little bit different from some of the metrics you might get out of a SIEM. Yeah.

Examples of a task that you've seen a customer automate and has just reduced a massive amount of time that they may not have seen coming? Yeah, I mean, I think a lot of times the ones that are most obvious are phishing or alarm triage or vulnerability scan assignments to system owners, application owners. Walk through those. What do you mean phishing? Yeah, so I mean, if you think about an organization where maybe you have a little button in the top of your Outlook client that forwards your phishing emails to a mailbox that your SOC monitors, right?

So if you're a security analyst, your job for that is to determine if that's a malicious phishing email or if that's benign, right? So how do I do that? I'm going to pull all the email headers out. I'm going to look at any domains, URLs, IP addresses that are in that message. Who is the sender?

Who is the recipient? Was there an attachment? And that's just kind of parsing all the— normalizing all the data out. And then I have to take that information and do an investigation on it. So, was the infrastructure come from the mail headers known to be malicious?

Was the attachment malicious? Did I sandbox it and what happened? Are any of the IP addresses or links inside of that phishing email known to be used for nefarious activity? So, all that process, that'll take 10, 15 minutes per email, depending on the size of the organization.

Because the consistency or the quality of the filtering that's happening at the mail gateway and things like that, you're going to get a lot of those in a given day. That's just one thing that kind of soaks up time. I mean, I think one of the use cases I think is more interesting that is a lot more fun is, we talked about before we got on, was credential dump sites or credential compromise sites. If it's Pastebin or GitHub or wherever someone might be posting compromised credentials, or maybe you subscribe to a service, but not everybody does, you want to know, do we have user accounts that have been compromised? So to monitor that manually is a very time-consuming task.

There's lots of opportunities for you to be in a situation where you missed one, or it went through, or it happened at night, and things like that. So if you can see that— So let's talk about what would the manual— I can definitely imagine the manual process for phishing emails. What's the manual process here for credentials? Checking on those sites. Right, so I mean, someone at any moment, at any day, could post a list of 5 or 5,000 different accounts that have been potentially compromised from a website or from any other source.

Like on Pastebin or something? Like on Pastebin, yeah. Pastebin is probably the classic example. At that point, if I'm a security analyst, I could scroll through that looking for not only the domain that we all use, but if we have any subdomains or alternative domains. Any of the third-party vendors that have access to our environment, is there a valid domain and is there a password associated with that so that credential is compromised?

For internal stuff, the first thing I want to do is test that credential. Is that a valid credential in Active Directory or wherever else, Salesforce, Dropbox, whatever it might be? If it is, at that point you have exposure. You want to disable that user account, you have to notify that user, you have to reset their password, you have to notify them of the password reset. Again, especially if you have more than one credential that was compromised, that becomes a really burdensome response, and the speed at which you respond really affects your exposure, your dwell time, the time that someone has to leverage those credentials.

On the flip side, the ability to remediate impacts the user's ability to do their job, so can they service the business? In the manual world, We're doing manual searches of Pastebin maybe for our domain. If we get a hit, then we're going to take the credentials and try and log into the system, maybe into whatever system you use for authentication. If it's positive, yes, it works, then I'm going to maybe disable an account in AD or I'm going to make a password change, whatever that process is. So that's in the manual world.

In the automated world, how do you handle it? Yeah, so I mean, the nice thing is Pastebin has an API, so we can watch for those pastes. Every time they come in, Swimlane will ingest that using— Swimlane will pull— Is that a push from Pastebin? They'll push it to you? We'll pull it.

So we pull that API. So on some regular basis, you're pulling the API to see it? Some interval, yeah, exactly. Bringing that in, then you're going to parse through the results, and you're looking for strings that match, again, those domains. That you might use or might be familiar with, and then if you get matches, then you kind of have a different step in that workflow process, which is, all right, take the strings that matched and let's test them against our AD infrastructure to see if they're valid or not.

Even if they don't work, you probably want to let that user know that this username and password combination has been compromised, because even if it's not compromised within your Active Directory environment, they might be reusing that somewhere else. I mean, Box or whatever else it might be. Nice to know. So then the automation would not only do the pulling of the API, it would also automatically do the testing, and would it also automatically do some kind of outreach to the users? Yeah, absolutely.

So I mean, it's not uncommon for us to connect to Active Directory, disable the user account. Obviously at that point they can't get an email because they can't— It's probably hard to communicate with someone after that. Yeah, exactly. So then you might hit like a Twilio or something like that and send them an SMS message notifying them that they received that. Obviously, you want to make sure that people know that that's the process, because if they start getting random SMS messages from you saying your password's been reset, they should be wary of that.

But if that's the security awareness training that's happening on a regular basis, they know that that's the process. I think that's great. I think we've sufficiently covered roughly what you guys do. I'd love to hear a little bit more about business over the last year or so. One of the big things that— the big piece of news in the last year from your orchestration automation world is Phantom being acquired by Splunk, right?

Talk to me about what does that do for your space? Good news, bad news, where do you come down on all that? Yeah, so I mean, I think it's great. I mean, it's validating of the space. I mean, obviously Splunk is very common machine log collection technology and SIEM inside of a lot of customers that we have, a lot of prospects that we work with.

They continue to be a great partner of ours. We're part of their adaptive response framework, and they're a very common integration for us to this day. Obviously, they have a product in our portfolio. They're a large organization. They have a lot of reach.

The nice part is them doing that has got the attention of a lot of people, their competitors and their partners alike. They're looking for options. Obviously, if Splunk has invested the amount of money that they did in that type of technology, there's value there, and they're trying to figure out how they become part of that. Part of that story that they're building, that they've built with Splunkbase and their acquisition, is it's community, it's collaboration, it's integration. I think a lot of organizations don't have that story, and a platform like Swimlane provides that.

If you have a portfolio of products, we can help with integrating your portfolio of products, or if you're trying to demonstrate to your customers that you're willing to work with other best-of-breed endpoint solutions, that we can help bridge that gap. I think the great majority of the market is out in front of us right now, and we're excited about what that means for the space in general. When you go— if you put together your typical customers, are you talking SMB, large enterprises, government organizations? Where do you mostly try and sell? Yeah, so I mean, I think what's typical for most emerging security technologies is the people that have more discretionary budget that are buying newer technologies are people that have higher regulatory compliance or just larger budgets.

For us right now, the large majority of our customers are financial services, federal government, pharmaceutical, high-tech, but we do have customers that have 2 security analysts. Analysts. I think they actually probably get more value than an organization that has 100 security analysts, which we have as well. If you look at how those organizations evaluate the return on investment in a platform like Swimlane, it's if I have 100 analysts, I'm trying to get a 50% reduction in level of effort so that I can keep my staff stabilized and continue to bring on more and more capacity and do more and more as a security team, where if you're a 2-person security team, you're worried about all the things you're not getting to, and automation becomes the mechanism to actually get to them. I'm trying to think about, to your point, when you have the big scaled enterprises, they're going to be focused on things they're already doing and trying to do them more efficiently and being able to scale better.

When you look at the smaller organizations, they're probably going to be trying to look at things that they don't currently do. Do you have any examples of things that they don't currently do? Obviously phishing email is one that they're probably already doing. The search for credentials on the web, that might be something they're not currently doing. Any other examples of stuff that people are not doing that they can add on?

I think about reviewing SIEM logs for the source of VPN connections. Are those coming from a geolocation that they should be? You could maybe create a SIEM alarm for that, but If not, then how are you identifying should that VPN connection be coming from Dallas or from Dubai, right? And if it should be coming from Dallas and it's coming from Dubai, you have a problem, right? So how would your automation— off the top of my head, I don't have an answer.

How do I know where it's coming from? How would you do that? Yeah, so I mean, you think about it as you're going to have a source of that VPN connection. It's going to have an IP address, which you can do a lookup in something like MaxMind, which will give you a geographic region. You might have just a general policy where we don't have people in that region.

Or you might have to do a lookup to some type of travel database or something along those lines to say, is this person in that region? And if they are, then maybe it's okay. If they're not, then again, if they're in Dallas, then that's a problem. For organizations that do a lot of travel, that's an interesting problem for them because it's not always black and white that this connection from a country we don't have an HQ in is not supposed to happen because we have a traveling salesman or we have some type of field operator or something that's going on in that environment. That makes sense, and it's nice to be able to just try and find those use cases that say, we're not taking anyone's job.

We're making you more effective, and we're adding these other things so you can get that better coverage. When you're at the 100-person SOC, maybe you are taking someone's job at some point, moving them into higher-value stuff, or they don't have to hire as many folks. I'm still getting my arms around how you how you add more coverage at the lower end.

Personally, as many vacancies as we have right now, I know plenty of organizations that have budget, that have open racks, that can't fill those roles. The concept of displacing people, I think, is a misnomer. We've never seen it. We see people that are trying to manage service providers, trying to manage more customer with the same amount of staff, but there's never like, we need to get rid of people. I think the other thing is, especially for me, I spent a number of years as an analyst and working in a SOC, is I didn't get into security to copy and paste data around, send email notifications, and create tickets.

That is not very fulfilling work. Being able to take that off the plate of those teams, I think it's a pretty big morale boost. It's almost kind of an inverse proposition to say, I'm trying to recruit people to work on my team, and I can tell you that if you're going to work in our stock, you're not going to have to do these 20 things because we've invested in technology to automate that away. Your kind of work life is going to be a lot better. It's gonna be much more interesting.

Yeah. So speaking of hiring, I'm gonna make a little bit of a change. You know, I know you've, you've grown up the team quite a bit in the last year. So, so where were you a year ago and where are you now in terms of headcount? Yeah, I was trying to do the, the mental math before we started.

I don't know if I got it right. I think we're between 20 and 30 people about this time. We're at 60 people now. So more than doubled. We've more than doubled, which is great.

I mean, we've expanded internationally and continue to— what's interesting is I think 50 was kind of an inflection point where you hire less people that do a lot of things and more people that have very focused skills, which is a lot of fun. I mean, you, you are able to kind of really drill in on folks that are experts at what they do, anything from design to marketing to sales to DevOps to to really good sales engineering. I mean, there's a broad spectrum of skills that you need, and early on you have to hire people that can kind of do all of the above, and as you expand, you get more specialized, and that brings kind of an interesting dynamic into the team. So what has the investment looked like in the last year? You mentioned a bunch of departments, but of the 30 to 40 people you've added, how does it break down in terms of where you're really putting your resources?

Yeah, I mean, last year we made a pretty significant in investment in scaling our R&D team. I mean, we were in a great spot, we had a great team, but we were also looking to make sure that we were maximizing on it. So we had a couple spots that we didn't feel like we were getting as much throughput as we wanted. So I mean, at one point that might be, you know, we're committing enough code but we don't have enough QA. Or before the design— engineering kicks off, the design was— we didn't have enough resources to do design.

Or we build a lot of integrations and build a lot of content for our customers, so they can get going really easily out of the box. That team needed to expand because our customer base was expanding, and there was more expectations there. Then obviously on the other side, we've made a significant investment in sales and marketing. We went from a handful of sales folks to 9 reps throughout the US, people in Europe, and throughout the rest of the world. We continue to expand our sales reach.

What's your breakdown of US versus international in terms of either headcount or sales, however you think of it? Yeah, I mean, we're probably 90/10 from a headcount perspective. We're probably 70/30 from a customer perspective. Okay. So US to international.

Yeah. And that's off my cuff, so. Right, just off the top of your head. I get it. And where have you been hiring?

You've mentioned you've hired some sales internationally, but is everything else in your office there, corporate office in Louisville? Yeah, the great majority of our staff is right here in in Colorado between Boulder and Denver and Louisville. And, you know, that's, you know, a lot of engineering hiring that's happened there. We're pretty open to hiring remote staff when it makes sense for the right people that, you know, have kind of proven they can work remotely and execute well. But obviously salespeople are in the field, and, you know, we continue to hire here locally as well for, you know, department heads.

We just hired a head of customer success and things along those lines. So, you know, we're trying to make sure that our team leads have at least some ability to have some office presence. So you're a customer success person. This is for your post-sales customer experience? Yep.

Do you guys have account managers for all your customers? So right now the reps continue to maintain their relationship with our customers, the sales reps. So adding Jordan, who is our director of customer success, gives them another resource. We haven't fully handed everything off at this point, but it's It's good for them to have an objective, non-sales, third-party representation in the conversation. If it's for a bug fix or if it's for a feature request or whatever it might be, they have an advocate now.

I think that's something that we believe in. We want that feedback, so building that relationship, getting that real-world feedback on what's working, what's not, and how we can improve is good. Sales might not always be the best avenue for that. So, you know, I think our reps do a great job, but it's always good to give them a dedicated resource. Well, yeah, sales is all coin-driven, right?

So they're gonna be motivated by making their quota, maybe not necessarily as relational-based as you'd like, much more transactional in general, right? Yeah, I mean, that's speaking for you necessarily. Yeah, no, I think salespeople typically just self-describe themselves as coin-operated. I think that our guys have done a great job of building relationships and rapport with our customers. I mean, I think as an emerging organization, it's important because that feedback is invaluable.

But yeah, it's always good to give them somebody else to talk to.

Similar topic, what is the SecOps Hub? SecOps Hub. SecOps Hub is our community. It's basically a non-vendor-specific place for security ops and incident response folks to go and share ideas. One of the things that we get a lot from customers, they would always ask us, if I have a question on how to do memory analysis or how to query recursively through Active Directory, there was no good single source for them, so we thought that we would try to build that community.

Obviously for us, a lot of the conversations do drive towards automation, but it's not a swimlane-centric concept. The idea here is that we have a place where people come and ask questions about their career, questions about solving particular problems in their environment. But obviously we have some spots on there for our customers to talk about use cases and share that content as well. So between our App Hub, which is our marketplace, and SecOps Hub, we have customers contributing content, sharing content, sharing ideas. We talk a lot internally about how the the scenario is kind of asymmetric.

You have many adversaries versus a single organization. Threat intelligence is slowly breaking down this gap, but the ability to kind of do a course of action, take actually remediation response to that, is an opportunity to continue to collaborate so that it's kind of a many versus many. I think it'll take us some time to get that sharing to happen, but that's really what we're trying to achieve by sharing content and having that shared community. Is it a forum? Is it a wiki?

I'm trying to figure out what SecOps Hub actually is. Yeah, it is a forum for the most part. It is connected to our marketplace, so if you want to share content that you've created, you can share that across those 2 components. We'll continue to expand the cohesiveness of those 2 platforms together so they interrelate with each other. This is created in the last year or so, isn't it?

Yeah, that's— it was there. Yeah, it's fairly recent. I think we launched— actually, I know we launched SecOps Hub at RSA this year, which was later in the year. April. Yeah, April as opposed to typically February.

Newish. Newish. Yeah. So, and then we again launched the Marketplace, similar timeline. So yeah.

So you're at about 60 people now. You mentioned DevOps. What the DevOps roles that you've been hiring folks, but you guys are not a SaaS organization, right? Yeah. So when you're talking about DevOps, what does that mean for you?

Yeah, so I mean, Swimlane is deployable software— physical, virtual, cloud, doesn't matter. So our DevOps team really supports our engineering team and the organization in general, right? So anything from being the administrator for, you know, our mail infrastructure to, you know, managing Jenkins and all the builds and the security assessments we do of the code builds and things like that. They manage that entire infrastructure. All the QA environments stand up, and obviously we do a lot of integration work, so we have a lot of our partner technology running in our environment so that we can maintain those integrations, and they do that.

For a smaller organization, we have an equally sized DevOps team that does a great job, and they definitely got their hands full, but there's a lot going on there. Do you guys yet have a security leader? We have been working with the DevOps team. The DevOps team has been embracing the security for both— I'll use air quotes for our corporate environment because corporate environment is we have workstations and everything else is in the cloud.

They've really taken the lead on that. We haven't hired a dedicated security infrastructure person at this point. Thankfully for us, security is in our DNA. Almost every hire that we we have has come from some security realm or another, so we have a lot of domain expertise internally and a lot of opinions that go along with that that we've been able to incorporate into how we manage our own security internally. All right.

Let's turn our focus to what's coming. We get together next year and call it next summer, next fall. Where has Swimlane gone in the preceding 12 months? Yeah. I think there will be a lot more international exposure for us.

I think we have a lot of prospects that are running in the Middle East and India and Japan and places along those lines. So I think for us the customer base will be much larger. We're really focused on this. We think that there's a lot of problems to solve within the incident response and security ops space. So you'll see a lot more visualization coming from what we do, enabling analysts to get to decisions without just text and numeric data, but actually having visualizations, really expanding on that community component, really helping folks and encouraging folks to share content.

Obviously, there's opportunities here for learning and other concepts. I avoid throwing out the buzzwords that go along with that, but if you think about what we're doing around alarm classification and how you do that without doing it more of a fuzzy match versus a binary or a regex style, and then mapping that to remediations, so you have recommendation engines and things along those lines, which fall into some of those categories that people like to talk about when they talk about security products. You're trying to avoid saying machine learning. Just like you don't like to say blockchain. Are you going to put it on the blockchain?

I am not putting it on the blockchain, though the state of Colorado is going on a blockchain for some reason, which I think you guys touched on. Yeah, the whole state.

So, you know, big change is trying to get smarter I mean, I like to— I actually like to summarize the ML/AI as being intelligent, right? Like being smarter with how we do everything, being more aware of what's going on. The system should be smart, right? It shouldn't be dumb that, hey, I had to code if X then Y. It should be able to figure out if one of these interesting things happens, we'll do one of these interesting reactions to it.

I agree. And I think the thing that makes that interesting is that, you know, you can do that within your own organization. Organization, and that's great, and you probably can find some value there, but as you look across multiple organizations, multiple verticals, you start to get a better baseline for what is and what should be, and that learning, that intelligence, that smarter is, I think, a lot more valuable than it is within really closed silos. That's a hard thing to do when you're installed software, right? It is.

I assume you're not getting any logs from your from your customers and how do you take learnings from one enterprise and help another if you're not getting that? We're definitely talking to customers about— we already have customers that share, so we're talking about how we take that information and collectively provide that back to them. Obviously, not every customer is willing to share. We really look at partnerships as a good mechanism to do that. We have MSSPs that run Swimlane and they obviously have access to a broad set of customers they're supporting.

In those cases, there is data that's available, that's shared, that you can start building some of that learning on top of that is tangible and valuable. Do you see customers willing to help contribute to that kind of network effect? Have you had any conversations with your customers to try and push them in that direction? It's interesting. Definitely around content.

There's a willingness to share, right? I mean, historically we're talking like the apps you create and the rules, the automation, right? Because there's no data there, it's just automation. It's basically if I see this type of alarm, what are we doing, right? And that's really an interesting conversation where you have 2 people that are doing— let's go back to phishing, that phishing use case— and one of them is doing a whole series of checks that the other one's not and vice versa.

Collectively, that use case is much more powerful when you combine those 2 things together. Maybe my internal investigation process is much more sophisticated than my peer, but inversely, they've figured out how to tap into all the open-source threat intelligence capabilities that are out there at no cost. If I combine those 2 things together collaboratively, that use case is significantly better than any one of them were individually. Because it's not threat detection or prevention technology, it's not which IPS signatures I'm running, which firewall I have, which endpoint I'm running. People are a little bit more willing to share because they don't feel like they're exposing what's going on inside of their environment because someone's not trying to circumvent XYZ technology.

Yeah, that makes sense.

Now, talking about obviously the future of your company, the future of where you want to go, do you see any bigger trends in security that's going to change the landscape of where you're trying to do business? Anything else going on bigger, meta, outside of Swimlane? Yeah, I mean, we talk a lot about how DevOps is eating SecurityOps. I mean, obviously the transition to the cloud is well underway. We just talked about 2 organizations that have basically been there their entire existence.

I think that's one of the biggest things is just people The way that we've deployed security configurations and controls historically has been through robust change management and things along those lines, which all makes sense, but as the way that we're servicing our customers and providing services changes and the speed at which it changes and the delivery of that, it needs to be able to support that. I think for us, that's one of the trends that we see is that without automation, it sounds like a plug, but If you can't plug yourself into their automated DevOps process for how they're delivering services, you're really going to be left out in the cold. That kind of macro trend is really interesting, is people figuring out how they can inject themselves into that process so they don't— all the stuff that they've done to build security around their, for lack of a better term, legacy infrastructure is incorporated into their new infrastructure. Have you given any thought to you guys getting in the cloud, doing your own SaaS? For this offering?

Yeah, I mean, it's something that we've always considered as we've built the product. I mean, as you think of the investments you make as an organization, having a SaaS product that stores really sensitive data, in our case we call it the dirty laundry of security. This is when the bad things happen, it comes into a product like Swimlane. The security requirements for that as far as compliance and audit and things like that are fairly extensive and fairly expensive. I'm sure you're familiar with all the audits that go along with that.

So, you know, we're trying to decide, you know, when it makes the best sense for us. Like I said, the product itself is ready to go. It's all the auxiliary things that go around that that you have to really be honest with yourself about and ensure that you've invested in the people and time and resources and third-party auditors. And there's a lot of preparedness that goes into that. And to kind of jump into that and pretend like that's just going magically happen would be doing your customers a disservice.

So we're trying to be very thoughtful in how we move in that direction. Yeah, that makes sense. So what else, what else do you want to talk about with Swimlane or where you're going? Um, you know, for us, I mean, we talk a lot about how organizations are deploying DevOps kind of concepts and, you know, also skill sets into their teams, right? It's one of the trends that we've seen is, you know, in injecting people with software development skills into their SOCs, which we see a lot and we think is really a powerful thing to do regardless if you're using an automation platform or not.

I think that's one of the trends that we've seen that you talk a lot about in the podcast about becoming an expert on whatever piece of technology it is and with that learning how to secure it. For us, one of the things we want to make sure is it seems to be easier to teach developer security than security practitioners how to develop. I couldn't agree more. The skill sets of knowing development, knowing whatever it is you're trying to secure is much more important than knowing security. We can teach security.

We can teach that mindset, but it's really hard to go teach someone how to pick up a computer and start coding. I think the other thing is talking a lot about how you can collaborate with your peers. I mean, I think it's something that we do behind the scenes, even competitive banks and competitive retailers. If you talk to their security teams, they actually generally get along pretty well. But how do we continue to extend that?

Threat intelligence sharing is an example of that, but how is it that we start working collaboratively to make everybody better? Because it's kind of a raising tides raise all ships type of scenario, and that's not always easy. Sometimes you become very focused within your organization, but I think there is an opportunity here for collaboration that is greater than the sum of any individual organization that we, I don't know, I guess challenge folks to continue to think about because I think there's a lot of opportunity lost there right now that it'd be great to tap into. It makes sense. It is, to your point, that the security teams for competing banks, they get along great, but they don't necessarily have easy ways to share information.

There's some threat feeds and FS-ISAC, and there's some organizations that you can get some stuff, but it's a pretty small subset of everything. How do we get better at sharing the stuff that really matters? I don't know that there's an easy solution, but I think it's a worthwhile pursuit. Yeah, there's definitely not a silver bullet there, but I think it's something that people want to do and I think will help. You know, you see, you know, you see the industry or the standards bodies trying to build things like OpenC2, which is really around automation and how to standardize that automation communication.

Obviously we have STIX/TAXII, you know, and the different, you know, standards bodies like OASIS and things like that that are working on that. Um, you know, sometimes innovation will outpace standards bodies, and that's usually a good thing. But there's, there's definitely, I think, an appetite to do it. But, you know, uh, you're dealing with people who want to do good, and you're also dealing with the fact that, you know, there are software vendors that are out there to, you know, generate revenues and build organizations. And those 2 things don't always come together.

And I think, I think we're getting better, but I think there's always room for improvement. So, so I was just poking around on your LinkedIn profile, and you've got, you know, your headline isn't CEO of Swimlane, it's hiring, and you list a bunch of things you're looking to hire. Tell me what it is you're looking to hire right now. So we're hiring sales development reps, sales development rep manager. We're hiring for a, I guess what I would call a security research engineer, which is for us a really exciting role.

Basically, if you want to help us build the content and manage the content we're creating, as well as be the forward face of Swimlane on our community, as well as, you know, things like BSides. That's a fun one. It is. I think it's a really fun role. It's not an easy role.

I mean, you're a one-person army. For lack of a better term, in that role. But it's one of those things where you get to contribute back into engineering, you get to have a forward-facing presence, you get to work on open source projects. There's a whole kind of gamut of things that you can work on there, which is a lot of fun. You know, always hiring for sales engineering.

I mean, that's always a hard role to fill. And yeah, I mean, we're always looking for good people. We tend to find good people and make up roles where it makes sense. To bring those folks in. And what makes someone a good person?

Why would you want to hire somebody? Quite frankly, it's a startup, right? So you have to really, really want to be there. I mean, that's the thing is, you know, early-stage product companies are fairly unique, and I learned this the hard way. I historically had worked at places like IBM, inside the federal government.

Working in an emerging technology company is a whole different animal. Expectations are different, and the people that thrive there, they have different expectations. Expectations, and it's fun and it's in a good way. You can't hide. Everything you do is internally public, and you have a huge opportunity to make an impact.

I think that's something that I was really looking for myself was you could do the best work in the world, but inside of a 100,000-person organization, it doesn't really register. You do great work in an organization of sub-100 people, I mean, you become a hero in for lack of a better term, and people really appreciate that because it has an impact on their day-to-day. If it's helping a salesperson get a deal closed or getting a new feature out the door or making a customer happy, it's one of those things that you can feel and you can see, and it's not some kind of net effect that rolls up into an SEC filing. That's awesome. Well, we're close to the end of our time.

I'll give you a chance. Anything else you want to say before we call it? No, I mean, always hiring, always looking for people, always looking for people to contribute to our community, SecOpsHub.com. You know, please come take a look, and, you know, always, always looking to have more conversations like these. This is a lot of fun.

Well, I appreciate your support for the show, and we'll look forward to talking to you again next year. Sounds good. Things have changed. All right, thanks, Cody. Thanks a lot.

Learn more about the Colorado security scene at Colorado-Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes