Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 86 for the week of October 1st. Alex, we've made it to the 4th quarter.
We have. Happy October. Hopefully we have a great comeback and end up pulling out the year here in Q4. That's right. You know, the— yes, the Broncos against the Raiders, down but charging back.
I don't know. I don't know what's happening right now. We're going to finish the year strong. Let's do that. All right.
So we got some housekeeping. Starting point, we have a Slack channel. We'd love to have you guys get engaged with us on the Slack channel. The link for that is available at Colorado-Security.com. We also have a mailing list.
If you want to get the show notes in the mail every week, go to the website and sign up for that. And we'd love it if you would subscribe on your favorite podcast application and rate us and say nice things about the show. Yeah. And when you do that, you should also tell a friend that, you know, we're a great podcast to listen to and that you should listen to us every day. Yeah.
We'd love it if you would just reach out to someone, someone who you work with, someone you think might appreciate us and help us grow. That's, you know, we're not doing this for the acclaim. We just would love to get to help other folks in the community. And finally, if you do want to support the show, we have a Patreon campaign. You can go out on our website, go to the Patreon campaign, and give some money to help us pay the expenses of doing this show.
Awesome. Let's jump into the news. Uh, first story, we talked a few weeks back about the Old Spaghetti Factory closing, which was very sad. Um, but they're gonna put there, Alex, instead now you can go there and play mini golf. Well, that's not sad, that's exciting.
That is very exciting. There's gonna be indoor mini golf downtown at, what is that, like Lawrence and 18th? Yeah, exactly. So for anyone who has been missing mini golf in downtown Denver, sometime in 2019 you'll be able to play. So I assume they're gonna just have to like scrape the whole outside of the building and start from scratch, is that right?
No, no, Robb. They're actually gonna be putting in quite a bit of money to restore that building, including putting back the original arch entryway. Awesome. Now that's That it's an old cable car building. Is that right?
Is that what it's saying? Old cable building. Pretty cool. That should be fun. Uh, if you're looking for team events or if you live downtown and you want to do something fun, there'll be new mini golf in town.
And it's not just mini golf, it's also a restaurant and bar and event center. Oh, hey. Yeah, not just mini golf. All right, well, did you know, Alex, that Colorado Springs has one of the most hottest— one of the most hottest— one of the hottest zip codes in the entire country for real estate? Irregardless of what you think, Robb, it must, must be in Colorado Springs.
I could care less. All right.
Yeah. So the number one hottest zip code is in Kentwood, Michigan. But Colorado Springs 80922 is the second overall hottest. Well, they do rate hotness based on how frequently people are visited on online to look at the houses in there and also how long it takes to sell a house in that zip code. You know, I think I would like to live in that zip code with a median house price of $297,000.
That seems a little bit low for much of the Front Range. And the hotness score is 99.3, which is scorching hot. It's a little hot for fall. Maybe it'll cool down a little bit as we're going into winter. And do we even say what the zip code is?
Do we Did we mention that? I did. Yeah, we did. Okay. Well, congratulations to those folks.
Next, Shell and NREL are teaming up for a startup for electrical grid and battery startups. This is pretty cool. They're going to recruit 4 companies in the fall to participate in this. It's a multi-year program, and they're going to add another 4 companies every 6 months or so. Yeah, that is pretty cool.
Energy obviously is very important, and I think we hear a lot how we have an aging power grid and instability, things like that. Getting battery and grid startups more in the forefront will be pretty cool. And the startups that are the part of this will have the opportunity to be eligible for $250,000 worth of technical support and validation, the use of some lab space and equipment, and follow-up opportunities for funding and partnership. And I did see that this is also a part of the Royal Dutch Shell's larger strategy around the Paris Climate Accords compliance. Yeah, which is awesome because, you know, oil is not necessarily the best for the environment.
So, hey, batteries and power grid stuff. This next story comes from Denver Startup Week, where a number of tech companies go in and we're talking about how their senior engineers from all over the country are really interested in living in Denver and doing tech work here in Denver. Yeah, they talked to some executives from Slack and Gusto and I think a couple others. Just talking about how people are really interested in being here in Denver. You know, some people might apply actually in San Francisco for a job with them and then say, hey, well, you know, I'd actually rather live in Denver and work for you.
And they said, well, we'd be happy to have you in Denver for a 50% pay cut. Right, right. Exactly. Yeah. I, I would imagine if I was going to get hired on and get paid what I get paid in San Francisco and then turn around and say, oh, well, I'll work in Denver instead.
It seems like an extra bonus. I believe we call that arbitrage.
Next, Colorado has the most expensive state for coworking desks, Study Finds. So this is interesting. We are the state with the 5th most coworking spaces per capita. But even compared to California, New York, Massachusetts, we're still actually the number one most expensive coworking location. Yeah, I wonder why that is.
You know, the story was a little bit all over the place talking about states and cities and things like that. But I think overall, I was just surprised in general at the cost of a coworking desk. Yeah, it costs $1,250 a month for the average person to have a coworking desk here in Denver. That's, that's a lot of money. You know, I could get pretty nice digs for a room in my basement for $1,250.
Yeah, that sounds like a business we could have coworking spaces in our homes. An Airbnb of coworking. I like it. Oh, you shouldn't have said that on the podcast. People are going to take that idea.
Somebody's new billion-dollar idea. There are 222 coworking spaces here in Denver. And the number one— excuse me, the number 2 most expensive place behind us is Massachusetts, just at $1,213. So not too far back. Nice.
Next, let's move into the security news. So Ping had a blog this week talking about the why, when, and how of customer multifactor authentication. And obviously this is something that's critically important as we look at like this last week, Facebook announced a breach and that would have been one of those things that could have been prevented by having an effective 2-factor in place. Right. So looking at— they have a nice little chart in this blog showing, you know, here's the activities that are low risk that you wouldn't want to put 2FA in the front of because it's inconvenient.
And here's the activities which are clearly Um, secure enough or sensitive enough that you need to have 2FA in front of them. And then for your business, there's this whole middle ground where you need to figure out what kind of business you do and which of these activities and what's your risk tolerance that you want to put 2FA in front of. It was pretty interesting. Yeah. I mean, I think we're getting to the point now where, uh, 2FA is— it needs to be pretty standard for any customer sort of apps.
Um, obviously, you know, as you said, Robb, there's some exceptions there that they talk about in the blog. But being able to provide that in an easy and secure way, I think, is super important. Yeah. And then the next story is a Red Canary— it's actually a repost from the Carbon Black blog, but Red Canary posted it about the MITRE ATT&CK framework and, and how to use it when researching attacker behavior and running unit tests. Yeah.
And we've talked about Red Canary and what they've developed around MITRE ATT&CK framework, and this blog is just talking about Essentially one use case that Carbon Black came up with. They had a hackathon and used the ATT&CK framework to come through and develop some tests that they could do some, what they call automatic blue teaming, which is just a pretty cool concept, something you could probably do in your own organization. Next blog is by Zvelo, and it's using DNS RPS to protect against malicious threats. That's a lot of acronyms all in a row. Yeah.
Basically, this is talking about a DNS filter. So you can use an RPZ filter between your resolvers and your clients. Essentially, it's like— I think of like URL filtering, but before the point you get to the URLs, just when you're doing the DNS lookups. So if you have, you know, some of these filters, they suggest a whitelist, a malicious list, and a suspicious list. You know, you won't even get to the point of looking up those domains because your— the requests will get dropped before they get to your DNS.
Yeah, that's great. Uh, next, LogRhythm is— has announced that they were put in the leaders portion of the Forrester Wave. If you look at the, the image in this link, uh, they're not only in the leaders portion, they're actually all the way in the upper right. They're further than IBM and Splunk. Yeah, uh, congratulations to LogRhythm.
Um, best in SEM, I guess, is the only thing you can say there. Yeah. It's interesting. If you look at them, there's, there's a lot of them all the way on the left is AlienVault. Poor guys all by themselves.
Yeah. You know, for, for a while, uh, they seem to have a good amount of promise, but now all I hear is bad stuff. Yeah. It's a bummer. It is a bummer.
Uh, finally, Coalfire had a blog this week talking about leading in privacy. So, uh, there are some work groups that are starting with NIST. To develop a, a privacy framework, a NIST privacy framework, and, uh, Coalfire is contributing to that. And they're, they're gonna be doing a series of meetings similar to how they did with the NIST Cybersecurity Framework, where they get public-private, uh, organizations together to talk about what they need, what this should look like. Um, so there is still opportunity to get involved if, if you're inclined to do such a thing.
Yeah. And, uh, I was involved a little bit with the formation of the NIST Cybersecurity Framework. And, uh, that was an interesting experience. So if you have a chance to attend one of those meetings, I'd say go for it. All right, let's go ahead and move over to our Slack message of the week.
Uh, big thanks to Andre Gaeta, who is our sponsor for this portion of the show. Andre, we appreciate you doing this. And our winner this week is Ben Downing. Ben, we appreciate your commentary. And especially we were talking, we had a conversation this week about, um, about Facebook's activities.
This was actually before their breach came out, right? Um, but it came out that Facebook was, is using the phone number you gave for your 2-factor authentication to market ads to you. And of course, Ben's, Ben's comment here was right on point that, you know, the last thing you ever want to be doing is putting, uh, 2-factor, selling 2-factor and giving a reason that someone shouldn't want to use a security control like this. Exactly. Um, you don't ever want to have to sacrifice things, uh, to get better security.
So, Sacrificing your privacy for better security is not a good thing. All right, let's go ahead and move over to our events for the next couple of weeks. As a reminder, we do have a section of the website which is a calendar of events. You can go out and see what's going on really out through the end of the year, and, uh, hopefully we'll catch you at one of these events. First on the list, SecureSet is doing their Expert Series with Chris Martinez on the 4th of October.
Chris is the CISO over at Maxar, formerly known as Digital Globe. Also on the 4th, there is the Lockton Mountain West Cyber Day. Lockton is a law firm in town, and I assume this will be kind of some, some law-related security stuff. Colorado Springs Cybersecurity is doing their First Friday Cybersecurity Social and Mixer on the 5th. So this is down in the Springs.
The business development group down there is having a cybersecurity mixer. On the 8th, SecureSet is doing a Hacking 101 Asset Management with Matthew McDonald. Also on the 8th and the 9th, the National Cybersecurity Center is doing their big annual conference, the Cyber Symposium, 2nd annual, down there in the spring. Some good speakers. Yeah, this is a place for you to get to see some really good speakers, get to see some governors and some other political folks.
It's not really targeted at practitioners. This is what we learned from Vance Brown on the show. Was it last week or 2 weeks ago when we had him on? It's really targeted more for Uh, policymakers, business executives, people who aren't day-to-day in security. So maybe send your boss to this.
I will say one of my favorite speakers, Dan Gear, is speaking there. So if you want to hear Dan Gear, head down to the Springs. Be great just to go for that. Uh, Denver ISSA has their October chapter meetings on October 9th and 10th. That'll be, uh, lunchtime in Boulder on the Tuesday the 9th, dinner in downtown Denver on Tuesday the 9th, and lunch on Wednesday in the Denver Tech Center.
On the 10th, there is a cyber risk management event. I say that because this is all in caps. This is Route 9B and Zavaro. I really wanted to say Zavello, but now that we have a Zavello and a Zavaro in town, I know I'm going to get confused one of these days. So they're doing an event on cyber risk management.
On the 11th, Colorado ISSA, Colorado Springs ISSA is doing a professional networking event. And I believe that is it for our events. That is it. Yeah. So let's go ahead and move over to jobs.
Um, as per usual, we, we have a couple ping jobs. I'll let Robb talk about those. We're growing like crazy, and I have 4 jobs to go through, and I'll make it a little bit quicker than usual. I am on my team directly working with me. I'm hiring a cloud security architect.
Also in my security team, we're hiring a product security engineer. So if you have some development background and you want to help us secure the SDLC this is a job for you. It's not actually building code day in, day out. It's making sure that the code that's built is secure. So doing manual testing, security assessments, and all that.
We are also hiring a GRC analyst here in Denver that's going to help us with, uh, help us with compliance and assurance for our program and talking to customers about what we do. And then finally, I mentioned this a couple weeks ago, we are hiring an API security product marketing manager. So that's helping us tell the story about the new API security product that we've recently released. Reach out to me directly if you're interested in that last one because I can get you into the right folks. That sounds like a cool job.
Next, Prologis is hiring an IT security engineer. This one's actually focused on Secure SDLC as well, so very similar to the product security engineer job I mentioned. Elastic is hiring a senior security engineer, and Elastic Elastic is also hiring a senior risk and compliance analyst. Oh yeah. And then finally, Ardent Mills is hiring a senior security analyst.
Some good jobs this week. All right. Well, that takes us to the end of the newscast. We have a feature interview, which, Alex, I actually recorded this feature interview with Brian Beyer and James Carder up in Alaska. Wow.
Yeah. So it was after— Wait, wait, wait. Does that break the rules that you recorded it outside of Colorado, Robb? This isn't— Yeah, if I take— if I take Alaska equals security, Colorado security people with me, I think it still counts. All right.
I will say it might have been after a drink or two, so you might get a little more truth than you normally do from these guys. Was this around the campfire or like while riding moose or what was this? It was actually both. We were riding moose around a campfire. Sweet.
Yeah. Well, I look forward to it. Good stuff. All right. Well, that's it for the show.
We'll talk to you next week. Thanks, Robb. Hi, this is Jose Calvillo, CSISO. At ASAP Payment Solutions, welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. We are doing a feature interview from the great, the great north. We are in Alaska, Alaska this week. I'm here with James Carder, the CISO from LogRhythm, and Brian Bear, the CEO of Red Canary. And for those who don't know, not only am I the co-host of I'm also the CISO for Ping Identity, so I thought we could talk a little bit about being on the vendor side of things.
What have we learned being on the vendor side? What kind of things can we share with other folks as we're doing this? Does that sound okay, guys? Sounds great. So we also have drinks in front of us, so if this gets a little off the rails, that's okay.
Everyone's okay? Yeah? All right. So the first really hard-hitting topic I want to get into, guys, is The news out of DIA. We know that there's a big remodel going on.
They're kind of restructuring where the gates are, but it looks like there's actually quite a bit of controversy here with the lizard people spaces underneath DIA. Have you guys heard about this? The lizard people are there. In fact, it looks like the Denver Airport is now trolling all the conspiracy theorists with billboards of lizard people and the Illuminati saying, what are we really doing? There's a— apparently there's a cornerstone, like, that was put down when the airport was built in, I think it was 1994, and it was put there by 2 Freemason chapters and some group called, like, the New World Airport Coalition or something that has, like, there's a time capsule underneath it basically saying, you know, open this up in 2094, and I can only assume that there's some kind of Illuminati stuff in the time capsule.
I mean, we'll never find out until at least like 3045 because everything about DIA has always been delayed so far. There you go. I think I get a pass as I'm technically not a Denver native. I've only been here 3 years, so I'll believe whatever you guys are telling me about this. I don't think there's any Denver natives.
Does that mean I get to be a Denver native because I've been here 9 years? Well, you know about this DIA conspiracy theory, so I would assume yes. Gotta follow the right parts of the internet. All right, let's get into some real security conversation. Let's talk about the Scoville security ratings.
Have you guys experienced with the Scoville security ratings yet? This is different than Gartner and Forrester and everything else? There's a hot pepper rating for security? Are you serious? Oh, I'm dead serious, guys.
You guys haven't had a chance to see this yet? No. So there's a Forbes article out here that's helping us compare risk to the Scoville scale of hot peppers. Pepper hotness. So you guys are familiar with, you know, the Scoville scale, right?
Where a jalapeño— I got it in front of me here— a jalapeño is somewhere in the 2,500 to 8,000 Scoville units. What a habanero puts us up at, um, about, you know, 100,000 to 300,000. The Carolina Reaper up at a couple million Scoville units. Well, this article, uh, written, as I mentioned, by Forbes goes into giving a Scoville rating for all of the security risks out there. And we can give a couple of examples of what that might mean.
Data breaches, data breaches as a risk, they are at the ghost pepper level. Wow. Yeah. Malware, that's just at the jalapeño pepper level according to this article. Everybody has that.
Ransomware is at the Fatali pepper level. That means nothing. Like, where does that fall on the scale? Between jalapeño and habanero. The fatality is just hotter than habanero.
So pretty hot, right? Okay. Um, we have, uh, we have phishing at the habanero level, uh, the distributed denial of service, which is like a Trinidad pepper. I, I, I think really rather than going through all of these risks, I want to get your immediate take on how How useful is the Scoville units measurement for your security risks? What's the Scoville rating for zero?
Zero useful. Bell pepper. Green pepper. The answer is bell pepper. The answer is bell pepper.
Well, I already thought this would go perfect for my next board meeting. It'll be like, hey, how's the security program going, James? Well, let me show you how we measure that. What I could see you doing is going to the board meeting with a box full of peppers, and you say— Exactly. Depending on how spicy this is, you're gonna know how high the risk is right now.
Take a bite. Let's see how much you guys trust me. Sounds like a winning board strategy. Yeah. Now would your board members take that bite, guys?
Budget's immediately approved for the next year. So you're saying we've stopped attempting to quantify risk altogether and we've given up and started using food? We're using, we're using the hotness of peppers as the solution. Does this mean we've— have we jumped the shark? In terms of rating risk.
We jumped the shark 2 days ago when we read the article that said EDR is dead and it's been replaced by XDR. Speaking of this, this was actually my next topic. I had a feeling this was going to come up. I don't see how we could have this conversation without at least addressing— I mean, the elephant in the room is you guys who are selling, Brian, at Red Canary, you guys are selling managed EDR as a solution, and obviously you're kind of behind the times. And point detection in response.
This is not a forward-looking statement, but Red Canary is apparently over because EDR is dead and now XDR is here. And what is XDR exactly? The article said it's whatever you want it to be.
So what would you like your X to be, James? I really don't know. It's just hard to choose like a handful of things when you've got so much to choose from. So let's make it simple. Assuming— just take a moment just to assume that not everyone listening has read this article.
Maybe you could kind of summarize what they're missing. James told me that CSO Online is no longer allowing vendor CSOs to write articles, and thus, as a final hurrah, someone selling the world's first XDR solution said that EDR is dead. And, and EDR is replaced by extreme detection and response, or the X, I think, was supposed to be a stand-in for asterisk. I think, I think whatever you'd like, the Stardiar. What do you think X is?
Just next-gen AI, ML, blockchain all wrapped into one? Maybe. I mean, we all did try to endorse Robb for blockchain skills on LinkedIn, and the AI didn't let us. If this gets edited out of the, out of the show, don't be surprised. Uh, so talking about you know, what we got, we get from analysts at this point.
What do you guys see now? Let's get a little bit serious now for real. What do you guys see the value of analysts in the industry being at this point? Analysts as in Gartner? Yeah, your Gartners, Forresters, KuppingerCole.
So we, you know, as a, I guess not so young, but when we were young as a company, everyone always described it to us as the Gartner tax that everyone paid. And so we went into it with a pretty low opinion of how the experience would go because of it. And I've talked to a bunch of other people and different parts of the security industry have different experiences, but we've been really fortunate in Gartner around the EDR and overall detection and response space as having really good analysts. I mean, we, we talk pretty frequently with people like Peter Firstbrook, Anton Chuvakin, Ian McShane, Toby Bussa, and many others. Like, I really respect their opinions and the customers that they've talked to.
They've been great to work with. What value do they give you, or do they give the customers? I guess I, I don't even know what value they're providing either side in your perspective. So for us, in our case, the value they provide is that they have had hundreds of customers asking them questions about what they should be investing in and trends they're seeing. And as a security team building a security product for security people, sometimes we're so deep in our vein and we feel like we know the answer that people are looking for, but we don't always know exactly what messaging or what words to use, and they can be helpful in bridging that gap.
And I think they've got, you know, like you mentioned a number of analysts, but I think they've got a lot of great analysts, and I think from a non-vendor perspective, most CISOs out there at major corporations, if they're going to buy a product, they're going to look at Gartner's upper right and say, okay, who's in that upper right? Let me evaluate that. And so on the flip side, from a vendor perspective, we obviously want to make that upper right quadrant so that way whenever there is a— and there is obviously a SIEM Magic Quadrant, so for us, we want to be in there so whenever a prospect decides that they want to go take on SIEM, we're one of the, the top 3 that they're going to pull in to evaluate. So I think it helps us from a sales perspective as well. And I'd say similar for, from my perspective working with analysts, I think one of the main things that they give— and Gartner and Forrester, all of them do it— is helping come up with kind of a standard vernacular, standard language to use to discuss what we do.
Because if you left it up to, to LogRhythm and Ping and Red Canary, you know, it'd be very solution-centric language that addresses what we do, but maybe wouldn't be similar between our competitors, right? And it makes it tough for someone to search for the right solution. But once EDR becomes the thing to search for, or IAM, or SIEM, or whatever it is, it makes it a lot easier for us to go Google it and compare and contrast across different solutions. I think it can be a double-edged sword sometimes though for a lot of innovative companies that, you know, come out with the capabilities. So as an example, LogRhythm really came out with SOAR a number of years ago with our whole Smart Response package, Security Automation, Orchestration, and Response.
And we called it Security Automation, Orchestration. We first called it Smart Response, and then we said, okay, it's Security Automation, Orchestration. And then Gartner came out and said, nope, thou shalt be called SOAR. And so we had to then go back in and change our marketing around to say, yep, this is SOAR. Same thing with UEBA and user and entity behavior analytics, entity meaning anything else.
We had to adopt the language of Gartner. So that's the downside of it, right? Is that, in my opinion, and I think this is partially because many CISOs like to buy products and don't focus as much on what outcomes their business actually needs, you end up with security teams looking for products that fit in categories. Gartner takes everything everyone does and puts it into categories instead of focusing on what's the actual outcome you're trying to achieve, right? When you guys started to do this with Smart Response, it wasn't, I want to be at the top right of the future SOAR quadrant.
That's right, because that wasn't even a thing. You said, when something bad happens, I want to be able to take action. And so that, I think, as much as I like the Gartner analysts we get to work with, I think as an organization or really all of the analysts, by putting things in product categories, they actually do everyone a huge disservice. People stop focusing on the use cases and the outcomes they want, and they get way too wrapped up in categories. Which is a problem that the industry faces.
Like every CISO, some are good, some are not so good, but It seems like every time I come across a prospect or a customer or anything like that, when I talk to these folks, getting back to the why is it that you're here, why is it that, what problem are you actually trying to solve, is always a very tough question for them to answer. They're like, well, we've got all these products here, we're going to integrate them, and what? But why are you here? And they have a hard time with that. The other thing relating it back to the whole Gartner piece is that there are a number of companies that you either A, don't have a quadrant, and so therefore people don't go out and look for that particular thing, or B, they get pigeonholed into a quadrant because it's, you know, that's what Gartner thinks you're best fit at.
So for us, it's a double-edged sword to be in the sim magic quadrant because you have one side of the community that says sim is dead, and so they're not going to go look at whatever the sim magic quadrant is, but then you have other ones that say that You know, it's obviously well alive with next-gen, etc., etc., um, and but we're pigeonholed in that. So we don't get the UEBA quadrant, we don't get the security automation, orchestration, and response quadrant, but we're pigeonholed into SIEM. I think, you know, it's, it's a real challenge that having the language is great because now there's something that CISOs can Google for, and, and really, you really do need that. You can't, you can't Google for a, a problem you're trying to solve very easily. The language doesn't work very well.
But you look at something like Signal Sciences, we've talked about them this week, and I think we all kind of like what they're doing. They initially didn't want to be called a WAF, but I think they realized the only way to get budget, to show up in Google searches, and to actually be a part of the conversation is to say, yeah, we're a next-gen WAF. And they didn't want to be that, but that's the only way for them to be a part of the conversation, and they can win opportunities that way. I don't know that there's a better solution right now. I think I actually don't even think it's the analysts.
I think it's like the optimization for Google search results that's actually causing the problem is you want to be on the first page 1 of Google for whatever term you're looking for, and if there's no term for you, then you're not going to get any natural search. That's right. I think there may not be a direct solution for it, but what is really important is that security companies like ours do not get wrapped up in their identity being what quadrant they fit in or where they get bucketed, and recognize that you exist as a security company for a reason. You exist to help your customers solve certain problems, and one year that means you're going to sell into 3 different Gartner quadrants or 3 different Gartner categories, and the next year it might be 5, and the next year it might be 2, right? Those are helpful tools, like you said, from a messaging perspective, but they never define you, right?
Like, Red Canary is not managed DDR, right? Like, we're here for a very different purpose. LogRhythm is not, or I hope you guys don't think, like, hey, our only goal in life is to be a SIEM company. Like, that's a really sad, confusing— security operations play, right? That's right.
And you're actually both security operations plays coming at it from a different perspective. That's right. Find bad things, stop bad things. That's right. That, that's something we have mutually, mutually— we're mutually agreeable on, is your Venn diagrams overlap, right?
That's right, that's right. Yeah, it's interesting. So, you know, kind of moving on from the analyst side to another, another part of the ecosystem we've been talking about this week is the VAR, the reseller. Where do you guys see the resellers playing in? And let's talk about it as a vendor, but then we can also swing over to the CISO side.
But as a vendor, how do you guys see value-added resellers playing a part in the ecosystem? I mean, I think from my perspective, if I have my CISO hat on slightly separate from just my corporate sales side of things, from a CISO perspective, obviously you want a trusted partner. You want one organization to funnel things through. And for us, being a vendor, we also wouldn't mind some anonymity. There you go, anonymity.
I always have a hard time pronouncing that. So that way we don't actually upset our vendor partners out there. So if we choose to go with one direction on firewall or endpoint detection and response or whatever the case might be, we don't want to upset our other vendors. So that's also very important. And then from a sales perspective, it's no secret LogRhythm is a channel sales type organization, and so those vendor value-added resellers, or VARs, they bring us a lot of business.
And so it always helps us to be very closely aligned to their needs and what they're seeing as well. And tailor some of our product around that as well, so that way they continue to push our product. I'd say very similar to your answer from a go-to-market. Ping, for the most part, does direct sales, but we've been getting significantly more invested in channel. I think as we look at scaling to get bigger and bigger, channel becomes a bigger part of the plan.
Having those relationships is very important that you're kind of getting getting a larger sales force by expanding into the channel. However, the negative is you don't control that sales force, you don't control the messaging, and you don't necessarily get the right opportunities until you've really invested into that channel. It takes quite a bit of work to get there. It does, it does. And you have to be okay with the fact that whenever you make a sale, you've got one more hand to put money in.
You've got one more person you've gotta pay. So to me, it's less about the money though, and the bigger downside is not that you are taking margin and you're effectively raising your customers' prices, right, by adding a reseller in the loop. To me, the biggest negative is that you're adding in someone else in between you and intimacy with the team you're working with. That's one of the biggest reasons, you know, we are probably 95% direct today is because we have such an intimate relationship with our customers it is a big challenge when you end up with other teams in there. Now, we have a handful of them who are exceptional teams to work with, and it's why you'll see Red Canary with some of them, but it's very few and far between.
And that's an excellent point, because I think a lot of these VARs are trained up on a whole plethora of products that they need to know and be an expert in, but no one knows your product probably better than you do. And so if they they want to control the relationship side, and then you can never actually solve the problem for the customer, that's a huge challenge. And then, you know, what does the customer think? Does the customer think it's your product, or is it your service? A lot of times it's just they say, oh, the product doesn't work.
It's like, well, no. That's never a question. They always think it's the product that's the problem. That's right. So that is a huge challenge.
It's something that we've run across quite a bit as well.
From the buying perspective, as the CISO who's going to buy a product, if I'm going to buy LogRhythm or Red Canary, I would much, much rather talk to the LogRhythm or Red Canary salesperson. And when I have feedback, good or bad, I know you're getting it, right? And I— and it's one step for me to go from my AE to the product manager or whoever it is. As you try and do it through that reseller, the, the relationship gets more confused. You don't get that direct feedback.
I don't actually know if I even trust their motives along the way, that what I hear from them may be, you know, maybe truthfully that they're having a problem with, you know, their LogRhythm product, or it may be that, hey, now they're in bed with this competitor to LogRhythm and they're trying to move things in that direction, right? And you just don't know that you can really trust what you get. So I prefer whenever possible to go directly to the vendor and And by the way, I don't think it impacts the sales price much either way. I think I get basically the same price either way, but I get that good relationship directly with my vendors instead of playing a game of telephone where it's customer through a VAR through something else back over to you. So with all that and both of your opinions on that as CISOs, what is the future of a VAR 5 years from now?
Do they still exist? I think they do. I think they do. I think they're, you know, if I look at a number of the VARs that are out there that I think they provide, some of them provide a level of value for their customers, and they're a trusted advisor. So that way it's not the vendor trying to sell them something, but it's a trusted advisor that's supposed to be there to say, this is what you need based on the use cases or problem you're trying to solve.
So I think that need will still be there. I don't see it going away for the next 5, 10 years. Do you see it shifting heavily to the advisory side with the resale and procurement gear on the side is just a bonus along with it. Honestly, I think that's the way it should be. I mean, I think that's the way it should be today.
I mean, obviously everybody gets measured probably on their sales targets and things like that, but at the end of the day, the sales will happen if you're providing the value to the customer and being that trusted advisor. And I think probably one of the problems in the industry is that there's less of that now, and there needs to be a lot more being that trusted advisor. But that's what they talk about, right? If you go talk to any of these VARs, that's all they talk about is, hey, we're trying to get out of being 90/10 product services and be, you know, 50/50 product services because services are the future. That's where we want to be.
And that's, that's how they can add that, that value. But they've been talking about it forever and they're not delivering that, that new ratio. It's because revenue is addictive, right? Yeah, revenue is addictive. And, and I think it's hard to be good at everything too.
You know, if you're good at pushing product, you can be good at some services. But when you try to offer too many services, you want to be the best at doing managed EDR and managed SIEM and managed IAM, you're not going to be good at all 3 of those, probably. They're not incentivized to focus on being a trusted partner because a trusted partner doesn't return cash. It can, but it's not a direct match. The reason why I look at products and services as well is that if you buy a product, it's a one-time shot, but you've got maintenance.
Maintenance tied to it, you may have a multi-year agreement with that. So you've got this continuous stream of revenue that comes in from a single sale, and it's usually a pretty high dollar amount. Where in services, oftentimes you can get— it's a lower dollar amount and a shorter period of time. So it's not something that's going to reoccur year over year over year generally. See, so I think this all shifts, you know, personal opinion, as we go from today's state where where probably 20% of security products are SaaS recurring, provided as a subscription, and 80% still the on-prem type, you deploy it yourself.
As it moves to being almost completely SaaS, I think this whole dynamic changes a ton. I agree, I agree. That's a great point. When we go buy things, it is always easier to say, hey, we just want to turn this thing on right now. I just want the outcome.
It all comes back to outcomes. I want the outcome right now. Take my money, deliver the outcome. We've asked a lot of questions inside the general technology space of, do value-added resellers exist around other parts of SaaS? The answer is not very often.
I can see maybe from a managed services type perspective, even if you go through a SaaS product for security, you may still want a third party to manage it if you don't get that from the actual SaaS itself, SaaS provider itself. That's kind of getting away from SaaS though, right? That's becoming like an MSP, or not even MSP necessarily, just a managed service, right? That's right. But it ends up being a lot of consulting, right?
You see it, so think like marketing worlds like HubSpot and Marketo. You're always gonna buy HubSpot and Marketo through them directly. But you absolutely can have your HubSpot and Marketo consultants come in and manage it by some other agency. It's interesting.
All right, moving into another topic. I know you guys want to talk about blockchain. So what I want to hear is, how is blockchain going to disrupt your industry in the next 12 months, 5 years, 10 years? Whatever it is, how's blockchain going to change? Well, if Bitcoin prices go back through the roof again, all the Bitcoin we're sitting on for ransomware payoffs becomes worth a lot more.
No, it, it won't. I don't see how it affects us at all. Not in the next at least 5 years I know of. I mean, I know, you know, I've got a— we put a paper together to speak at RSA next year, and it's going to be one around voting systems and blockchain. And we've got folks from, you know, City and County of Denver, State of Colorado, and then we're actually trying to bring onto the panel the representative from the State of West Virginia because oddly enough the State of West Virginia, which, you know, I lived there for a number of years, but they're actually going to be the first state to implement blockchain as a part of their voting process.
And so, you know, I do see there are some potential potential limited, you know, some uses that they could have for it today. But I think from a security industry perspective, I don't see anything changing for us for the next, you know, 3 to 5 years. None of it makes any sense to me around that, especially on the voting side, right? Every single recommendation over and over is that you use paper ballots that are verifiable. Everything that's been done on the voting side that's electronic, let alone blockchain, is going to be more and more disastrous.
Yeah. I'll push back just a little bit on that. As much as I'm not a big blockchain proponent, I do believe we will be moving away from paper and into electronic balloting, and whether they use blockchain or they use some other kind of ledger, we need to do a better job of figuring out how to secure that, 'cause it's not going to be paper forever, and people are gonna keep pushing us and pushing us, and there's, you know, there's disaster or there's success one way or the other. But can you explain how, I mean, I mean, it's not a ledger you need from a voting perspective. All you need is a record, right?
You need a database. So isn't the ledger a database? In what case does the blockchain go solve something that when you press the button in the voting machine, just sending it back to a server— like, in what case does blockchain solve something that TCP doesn't already? So the only real difference between blockchain and a database is the distributed nature of it, right? That's, as far as I can tell, that's the only significant difference from a practical perspective.
Distributed, you have distributed trust with the blockchain versus, you know, a centralized trust with a database. And is there value in having decentralized trust in an election situation? I think it kind of is the opposite of elections, right? Elections are all about centralized trust. Centralized trust, right?
It should be. Uh, I'd say from, from the IAM perspective, there are a lot of conversations about how you can use blockchain to be interesting. Um, getting me— I can't— I still can't prove someone's identity from a blockchain, but I can say that they've been claiming the same identity for a very long time. You know, if you've been claiming to be James Carder for, you know, 30x years, you know, there's a better chance that you really are James Carder than the guy who started claiming it 15 minutes And that's a place where identity and having a centralized store, or I guess it'd be a decentralized store that's used all over the place, starts to add some value. I can see that disrupting things from a consumer perspective.
Having the government use something like that, I struggle. If the government uses it, it's no longer decentralized and it kind of loses the whole— So, I mean, hearing us talk about that, this is what I have flashbacks to. Remember when Git first came out and it was going to replace CVS and SVN for all of our source control? Remember how everyone talked about how the huge benefit of Git is that it's decentralized? But that's not how anyone actually used it.
I say anyone, like 99% of people using Git are pushing to a centralized master on either GitHub or GitLab or a location like that. So maybe that's an interesting question. Will blockchain actually support a useful use case but not be decentralized at all and turn into something like GitHub? I hear about some of the large banks using internal implementations of blockchain, and when I hear about it, they'll talk about stuff like the immutability and the audit record you get from it. But there's nothing— as far as I can tell, there's nothing different about that than you would get from any old database that's got, you know, some kind of atomic database operations.
Like, that was why we use databases. So we're still a ways away, I think, from figuring that out. But I have figured out how to get Robb to defend blockchain. That's right. Very confused where we are right now.
Which is not easy. Which is why we should go back to make sure we endorse him for blockchain. Exactly. On his LinkedIn profile. All right, a couple more questions for you guys.
We're doing a good job here. What events are worth spending money on? What security events, and I'm talking about now, we're all vendors here, right? What are the events that make sense for us to have our marketing dollars spent on? You know, that's a great question because I see too often where marketing dollars are spent on all these events and the return on that investment is negligible.
And then there are other cases where if you don't attend that event, or invest in that event, then you're just not a player. If you don't show up at RSA conference, everyone notices that, right? That's right. RSA, Black Hat, those types of conferences. Rocky Mountain Information Security Conference?
Sure, sure, sure. National events, yes. And yeah, so if you're not at one of those major events, then you're just not a player in that space. But there are a lot of other smaller events that we just tend to throw money at, and I don't think we get that much of a return on. So for the big events, I think we think we have to be there because otherwise there's questions about your viability as a company.
That's right. But maybe you don't get the money out of it. If you go spend a million bucks on RSA conference, maybe you do, maybe you don't get an ROI, I don't know. Are there other events though that you do get an ROI on that you don't have to do? So opinions on that?
At Red Canary, the way we separate these and what helped all of this make a lot of sense to us is that There are events you will do for branding purposes, and there are others you will do for lead generation or relationship building. If you go into RSA and think that you are going to generate leads that will make it worth your while to spend $500,000 or $1 million, I think you'll be sadly disappointed every time. Like, the way we look at it is, you know, in the same way you were talking about, you go to events like that for branding. You want people to realize the Ping brand, the LogRhythm brand, the Red Canary brands. They're great brands who are going to be at events like that and who are leaders in the security industry in general, but you're not going to get a tremendous number of leads out of them.
You might be surprised. I think, you know, when I look at, you know, we get access to, our marketing team sends us like, hey, here's the number of leads, here's the number of hot leads that were generated from these events, but Black Hat and RSA are obviously our 2 biggest, and they generate a ton of leads. And the way we look at it is if 1 or 2 of those leads become a customer, it's already paid for itself. It's a break-even, and anything on top of that is gravy. So, you know, I would push back a little bit too, saying that, you know, even though they're expensive, we do get a lot of leads, and there's a lot of foot traffic that goes through our booth, and, you know, people that, you know, may have never even heard of us before all of a sudden get to hear about us based on our location in the vendor hall.
So it does do a good job for us generating leads. But I think your point is there's 2 different axes to think about it on, right? There's lead generation and there's branding. There is, and there's a difference in terminology. So we, obviously because of Shared Investors, you know, we've learned a lot about how you guys market at RSA and how a lot of other companies do.
To me, You know, when we're talking about leads and your marketing team telling you they got leads, that's equivalent to business cards, right? Yeah, they got names and contact information. That's not opportunities, a relationship you're going to follow up on directly. That's somebody you're going to blast with an email or cold call. Yeah, and there are obviously different classes of leads, as you might say.
So if they've got, you know, obviously the largest pool is the business card lead, but then they have tiers below that that talk about other leads. And like I said, even if out of that, you know, 1,000 leads or whatever that were generated, if 1 or 2 are hot enough and they become customers, it's paid for itself, right? And there's, there's like, we have, you know, marketing-generated leads, marketing-influenced, marketing-touched, and all these things that, you know, they all add up to showing some kind of ROI on the big expense. That's what they're measured on. Yeah, and they should be, right?
But I do like the idea that maybe it's It's not all just about opportunities, that there's some spend that you just have to do for the brand to say, hey, we're a healthy brand that's a part of the show. Then there's some events where you don't have to be at that little tiny thing, but gosh, we see a great ROI there, and that's all ROI-based. The events we've done like that, our favorite ones have been local to a geographic area, primarily led by our customers, and fun. Like, some of the most fun things we did have been brewery tours in Atlanta, in the Bay Area, where, you know, one in Denver as well, where a couple of our local customers go. And it really is a time for people to hang out and spend time together and a quick little presentation to walk through, like, hey, here's why we selected Red Canary for this and why it makes sense for us.
Is that the bike thing, the bike around Denver thing you guys did? I think so. Yeah, that was the Denver version of that. Sometimes I think you also want to be at events because your competitors are there. I think that's another piece, and I don't think that's a big enough piece to force you to contribute actual money to be at an event, but sometimes you may look at it and say, okay, well, if this is an event and your top competitors are there and you're not there, what does that say about who you are?
If there's somebody who needs a sale, or an IAM or an EDR, then they're going with the other people. Same thing with partner conferences for all these other major security vendors that throw their own user conference. If you're not at their user conference, what does that say about your ability to integrate with them and leverage them and partner with them if you're not there? Yeah, that's why we've always invested. One of our favorite events we like doing is Carbon Black's user conference.
Conference every year because we go, and for several years we supported the developer days that they had, and it was a great chance to work with teams and answer really hard questions and also make it really clear nobody knows how to do this better than we do. And by the way, we know what you're doing is really hard and you're probably not very good at it, right? Who would never say that? Now there's another type of event as well. I'm interested to know how you guys think about them.
What about speaking at the SANS summits or DerbyCon or GRRCon or events like that? Yeah, I mean, I think DerbyCon's a, we always try to submit some pretty technical talks to DerbyCon. I think it's actually from a technician perspective. You may not get, in my opinion, the budget owner at DerbyCon, but you will get the influencers influencers at DerbyCon, the folks that actually are more technical, understand what's real about security versus folks that are more focused on the business side. So I do find value in there because even though, like I said, you don't get the budget owner, you still get the influencer.
And usually those guys and gals are smart, trusted advisors to their CISO or to the budget owner. So yeah, I actually— we like investing in conferences like that. I think they're awesome recruiting as well, right? I mean, that's it. You get to send your best technical people up there to talk about what they get to do every day, and they're generally presenting side by side with other people who you would love to have on your team.
Yeah, or you have other folks that are trying to now recruit and poach those folks because they're so smart. This is just like the whole— it's like this whole bunch of goodness, right? Those talks, I suspect there is not a great ROI on them. There's this thought leadership idea that goes, you goes into giving those talks. Generally, you're not talking about, you know, exactly what you do.
It's not a vendor pitch, right? It's good research you've done, but it gives those people who did the research and did the talk the opportunity to advance their own career, get their own skills doing public speaking. It gives them a chance to network, and they come back with this new knowledge, things they've learned while they're there. It's good for the industry, it's good for those people, it's good for the people who are there listening. It's good all the way around.
I'm not sure that it, it's really the way to go and invest and go sell your product, but it's a really good thing to do. It is good for your brand quite a bit too, and that could lead to product sales only from the perspective of if you've got a sharp technical person and they're up there giving an amazing presentation, what's left with the audience is like, oh, you know, Logarithm knows what they're talking about. They actually know this space. They have smart people. Maybe I should talk to them.
Yeah. And, and so I think it does end up there is a return on investment, but it may not be as heavy as RSA or Black Hat or something. No, what we need to be careful of is we don't want this community to turn into a group of people who are running around trying to become celebrities by speaking at the same events, you know, and going over that. Like, some of this content, once it's been presented once or twice, probably shouldn't be presented again, right? And people— I really hope we all encourage people people, your contributions to the security community should be the information you share, the tools you share, and the work your company does, not how many presentations did you give or how popular, you know, how are you close to Swift on security or not, right?
Like, that's not how we actually make a difference for companies. It's not a popularity contest. Yeah. So last question for you guys. Swag.
What, what is, what is the value of giving out swag at the booth? Uh, as, as you know, an attendee, of course you're looking for the, so the thing, the battery pack you need, or the thing to bring home to your kids, or whatever it is. But as you know, as the vendor side buying these things, why are we spending so much money on all this stuff? What do you guys think? Well, I'll start by saying this is probably the most technical interview you've had on your show, as we talk about vendors, events, and swag now.
But, you know, at the end of the day, I think just having cool swag is just something that, especially if it's, you know, something people will actually use, it has your brand on there, so they're always gonna look at that thing and see your brand whenever they go, you know. Walking advertising. That's right, that's right. It's just walking advertising. And then, oh hey, look, Buddy A needs a power pack.
Great, let me hand this over. Oh, it says identity on it or whatever the case might be. It's just something that is— it's just always, like you said, walking branding. Welcome to my soapbox. We— Red Canary does not and will never have swag.
We have gear. This is on the record now. It is absolutely on the record. We, we will never have pens. We will never have stress balls.
We will never have the stuff that you can get at our booth and everyone else's. Yeah, we go with the nicest shirts you can get. We have the nicest jackets. We try and make sure that everything we do— we've got one of these really nice Red Canary Growlers right here. I think your gear that you give away is a manifestation of your brand.
And so for us, we will spend substantially more money on quality and have substantially less quantity because that's really synonymous with our brand. And so if you see someone in a Red Canary t-shirt, it's not because we gave away 20,000 of them. There's not that many people who have one. Right. But, you know, you look at all these conferences, a lot of security people go around with their swag bag.
Yeah. And they are looking for things that they either bring home for their children or just something to put in their office. And, um, you know, last I checked, I don't think I want to give my kid a Growler, uh, as an example. Um, but no, don't get me wrong, I would be very impressed and happy with a Growler, but it's just not something I'd pass on to my kid. And the other part, as I'd say, is, you know, even if it's cheap swag, like, you know, these— those carbon black swords are like all over my office still, uh, from Black Cats.
So there's probably 15 carbon black swords office. See, I would have— if I had been saying that sentence, I would have said, you know those swords that someone gave away at the conference? There's all over the— all over the office. Because I don't remember who gave them away, and they don't— it doesn't accomplish that goal for me very well. So, you know, you just hit the nail on the head.
Like, we don't— we don't do special gear and things like that for you to give to your kids. Yeah. Like, thankfully there's lots of other people who do cool things like that that give to your kids. Plus, you don't want to give that swag anyways because it breaks and falls apart. Yeah, it's a choking hazard.
We want stuff that's memorable for you, right? Walk around and wear— like, when you put on the Red Canary shirt, you're like, man, that is one of the softest shirts. It is a comfort— it is a comfortable shirt. Exactly. It's a quote we actually heard today, if I recall.
It was up here in the middle of nowhere, Alaska. Uh, we— I'd say one of the, one of the reasons I ask about this is I, I think about swag. I walk around the RSA expo hall or whatever. And just think about the millions and millions of dollars that are sunk into this junk, right? And a lot of that junk literally will be thrown away after the conference.
I don't know, 30%, 80%, you know, some significant percentage of that stuff is, is gonna get wasted. And it's just, we're so inefficient as an industry. And, you know, the prices are getting— are high and, and only going higher because of that kind of stuff, that, that wasted marketing spend. I'd like to see us be smarter about this spend. I like how thoughtful, Brian.
I like how thoughtful you are about what you guys invest in. And you have a point. Everything you make is high quality. It's going to people who will appreciate it. Otherwise, just don't make it.
Like that thought. So, that's all the questions I had, guys. I'll let you guys ask questions if you have any. What event are you most looking forward to in the next 12 months? Oh, man.
I really don't know. I'm looking forward to events where I don't actually have to present at. That's always a nice option. I don't really have anything for the remainder of the year. I am going to Minnesota for an event in Minnesota, 2 events in Minnesota, and a few others, but nothing that's big.
I'm talking at the SecureWorld Denver conference coming up. Nice, great. What's the topic?
That's a good question. You put me on the spot here. Sorry. I don't remember off the top of my head exactly what it is. I do have a talk ready to go though that I put together for it.
That's great. I'm doing that, and of course Rocky Mountain Information Security Conference is not that far off. It's just next June, so that's what, what are we at, 9 months from now basically? Yeah, that's great. So that'll be good.
What about you? What's your favorite event coming up? You know, I'm really looking forward to DerbyCon. I went for the first time last year. It was a great event.
We, you know, by the time this airs, we actually had a couple extra tickets. So Rachel Toback and the Women in Security and Privacy group is going to be raffling those off. So excited to see some of those extras. Yeah, I've got a lot of my team going to DerbyCon as well. Yeah, a bunch of folks going to AWS re:Invent, which is now like one of the biggest conferences in the world.
It is bigger than RSA now, I think. Yeah, it's like RSA but bigger for technology people. Yeah. Anything, James? Anything before we call it?
No, I think I'm good. I'm ready for a refill. All right, guys. Well, thanks for your time. This has been fun.
Great. Thanks, Robb. Talk to you guys soon. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.