Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 101 for the week of January 21st. Alex, how you been?
I've been good. How about you, Robb? Doing all right. I know you've been on a whirlwind adventure, so everything back to normal now? Yeah, I was over in— I was in India last week, my first trip, uh, actually to Asia anywhere.
Um, I guess, does— do we count New Zealand as part of Asia? Yeah, I don't know. I think probably maybe officially we might, but it didn't feel like it. Yeah, very different, very different experience. Anyway, glad to be back, getting back onto the Mountain Time time zone, taking a little bit of work.
And of course, uh, today, assuming you're listening to this when we released it. This is Martin Luther King Day, so happy Martin Luther King Day. Happy MLK Day. Good stuff. Hopefully you're doing something fun to celebrate.
Yeah, of course. Yeah, always good stuff. Before we jump into the news, a little bit of housekeeping to go through. We do have a Slack channel. It was a very lively Slack channel this week.
Yeah, lots of discussion on the Slack channel this week. I think we had about 30 people join too. Wow, I didn't notice that, but that's a lot of people. Yeah, had lots and lots of good discussions. Must have been people's New Year's resolution to join Slack.
Which is actually the perfect New Year's resolution. Perfect New Year's resolution. We also, in addition to a Slack channel, have a mailing list. So if you want to get mailed the show notes when they come out, please sign up for that on our website, colorado-security.com. We'd love it if you would rate us and subscribe on your favorite podcast player.
If you're using iTunes or something else that you like to listen to us on, go ahead and subscribe and get it in your inbox every week. And please rate rate us and let folks know that this is the best security podcast in Colorado. Yes, exactly. We also have a Patreon campaign. So if you think that we are so awesome that you're willing to contribute a little of your own financial wealth to help us pay for the show, we do this all out of, out of our own pockets.
We do have a number of wonderful patrons that help us support the show. Go to Patreon and sign up with us. Um, you can find the link for that on the, on our website as well, colorado-security.com. Exactly. And finally, um, if you don't want to do that, we would love it.
If you would, even if you do want to do that, even if you do want to do that, I guess, um, everyone helps in their own way. Um, just tell a friend, let them know how great the podcast is, that they should listen, that they should check out the website, look at the event calendar, all that kind of stuff. All right. Let's go ahead and jump into news for the week. Alex, there is a poll out this week and we beat Austin on this poll.
In fact, Austin didn't even show up on the poll. Anywhere. That is pretty cool. I'm not sure if it's something to be proud of or not. I think, you know, for some people, it's definitely something to be proud of.
This was a poll for the best places in the US for vegetarian food. And, and as I said, as you might expect, Austin, the barbecue place, did not make— did not make the list at all. But sorry, but I was gonna say, Robb, I'll give you one guess as to which city in Colorado it was that, that was on this list. Canyon City. It was not Canyon City.
Okay, I'll give you 2 guesses. I'll go with Trinidad as my final answer. You're completely incorrect, Robb. It was Boulder. Boulder, Colorado was number 3 on the best places for vegetarian food.
And I believe number 2 was Berkeley, which didn't— Berkeley, California didn't surprise me too much. But the number 1 actually did surprise me. It's Charleston, South Carolina was the best place for vegetarian food in the US. Yeah, I would not have guessed that. Next, Broomfield is creating a science city and other developments on some of the sites that they had submitted for the Amazon HQ2 bid.
So shunned by Amazon, they have moved on and they're bringing us the city of the future à la Tony Stark. Exactly. They're going to be building the Avengers headquarters there. And no, just kidding. They're going to be building a collaborative environment for researchers and companies to connect, collaborate, innovate, and transfer new technology ideas and innovation.
Well, it sounds amazing. I think I still think that the Avengers might be there. This sounds a lot better than Amazon's HQ2 with their piddly 50,000 jobs. Right. Hopefully with this new science, they won't lead to taking over the world like Amazon is.
So maybe it'll be a better thing after all. Next, we have some news that one of the big companies at least has a legacy here in Colorado is being acquired. It looks like Fiserv is in the process of acquiring, uh, First Data Corp for about $22 billion. That's a lot of money. Um, of course, you know, First Data still has some presence here, had a much larger presence for a long time, you know, big credit card processor among other things.
And, uh, yeah, so I think we're going to be losing the First Data name. I think once they combine, it will all be part of the Fiserv name. Uh, it looks like the, uh, the current Fiserv CEO is going to be the, the CEO of the joint company, but the current First Data CEO is going to be the president and chief operating officer of the new organization. So, uh, you know, big parts for both of those, both those guys. Yeah, good stuff.
Uh, so Crocs and an unnamed media company could be looking to bring 850 jobs to the Denver area. So I think Crocs is also still a little bit of speculation, but this article is talking about, um, they're the incentive requests that have been put in. One of them was in, um, a Colorado-based apparel company who they think is almost definitely Crocs. And then the other one was an unnamed broadcasting company who I, I think that they are saying is probably NBC. Oh really?
I didn't catch that. Um, okay. But anyway, uh, there are potentially several hundred new jobs coming to the Denver area through these incentives. Yeah. And it looked to me like there's one other company on here on this list, which is an American subsidiary of an Indian IT company that recently bought a company from Colorado.
And I was guessing this was Cognizant just based on the way, the way it read. It's interesting to see these because they, you know, they try and keep it anonymous but get, you know, say enough things to make you get interested in it. These incentives, they don't have to let us know who they are until they actually get paid out on them. Whereas right now they're just kind of applying to be able to use them if they, if they do bring the jobs. Right.
Interesting stories. In any case, good stuff. People want to come to Denver still. Next story, Richie May has recently launched a cybersecurity service to help protect hedge fund organizations. So this is interesting.
I reached out to JT Guaido, who is their, what, executive director over their cybersecurity services, and asked him about this. And, you know, he basically let me know that they are targeting small and mid-sized hedge funds for this to help them stand up security programs. Pretty cool stuff. You know, my first thought when I saw this was, you know, if you're brainstorming what's the organization that needs security help and can afford to pay for it. Well, a hedge fund might be the perfect place for that, right?
Yes, that's probably a good start for your services right there. They're going to have a little bit of money to pay out. So next, some very disturbing news, Robb. Very, very disturbing that the crypto winter is upon us. Yeah, apparently Game of Thrones has, has definitely percolated all the way through press releases about laying people off.
Yes. Interesting. So Shapeshift, which is a cryptocurrency, I believe, exchange here in town due to the, the lower prices of cryptocurrencies, has had to lay off 37 people, which is about a third of their workforce. Yeah. Through the press release, which was somewhat amusing, I have to say, which I don't know if you want your press releases about laying people off to be amusing or not.
The founder Noted that the the latest crypto winter is upon us, and today Shapeshift felt the bitter frost. Crypto, like the moon we strive toward, is a harsh mistress. Yeah, so this is interesting. Interesting guy here. But you know, it is it is a bummer to hear that these folks are losing jobs.
Obviously, that part is not so funny. The the realities of business, it seems like, caught up with this company where, you know, he makes it pretty clear that they weren't quite as focused as they should have been. And when market conditions were good, that was okay, something they could kind of hide. And then when they got bad, it became a lot more impactful for them. So they're going to try and focus on their core offering of a, of a crypto exchange and maybe less on the periphery stuff they've been working on.
Yeah. So sad for those 37 folks. But, you know, with those 850 jobs we just talked about that are coming, I'm sure they'll find some place to land. Yeah, I'm sure there's a lot of folks looking for that skill set. Next bit of news we have is Swimlane.
They basically released a press release kind of just talking about how good the last year was for them. It's pretty neat to see. They actually grew, well, since the beginning of 2017, they've grown by about 544%. So really good growth. And in 2018 alone, they, I think they said they tripled their ARR.
So that's their annual recurring revenue. Um, and they doubled the size of their staff. That is pretty cool. Um, hopefully we can look forward to similar announcements from Swimlane like we do from Webroot, that, you know, every quarter they have, you know, double-digit growth and record this and record that. Well, congrats to them.
If they're able to have a triple ARR every year, um, that's going to be a pretty good run for them. That would be. Yeah. Uh, next, uh, there was a blog post on the Ping Identity blog this week on APIs, the new security attack vector. So this was actually a guest post by a 451 analyst, so Garrett Becker, just talking about, I think, things that we have already talked about on the show, how APIs are proliferating and that their security is very important.
Yeah, you know, he talks about the fact that as mobile apps become more important, there's always this backend infrastructure that supports the mobile apps. Basically using APIs, and organizations have this sprawl. He talks about some facts that on average companies have about 363 APIs and over 2/3 of organizations have APIs exposed publicly. So interesting facts that they throw in here about how to look after APIs. So if this is something that you haven't really thought about yet, this blog post might be worth taking a look at.
Next, after a long and illustrious successful career, ProtectWise has been named into the SC Media Hall of Fame. Congratulations, ProtectWise. I don't know. I don't know how you can better put a cap on a great career than being elected into the SC Magazine Hall of Fame. I think generally you don't get into the Hall of Fame until 5 years after retirement.
So this is, this is pretty impressive, right? Yeah. So, you know, in the article, it mentions that they've been part of their— I forget the exact wording that they use, but essentially, you know, their, their up-and-coming innovators in network security for the past 3 years, and that is what led them to be put into the Hall of Fame. Obviously, you know, all kidding aside, it is kind of funny to see a Hall of Fame for a still startup-sized company, right? But also, kidding aside, they do have a neat technology that's being recognized here, and I think that that's what the recognition is about, is there's not a lot of places out there where you have this correlation replay of historic stuff, and that's, you know, I think that's what SC Media is calling out.
Yep. Good stuff. Next, there was a blog post from Brian Scriber of CableLabs talking about security for blockchains and distributed ledgers. So, of course, this is now irrelevant now that the crypto winter is here, but in case you still have interest in blockchains and distributed ledgers, I think this is a good rundown of some efforts that they've done to look at these technologies over the past few years. And, uh, and talk about potential areas that you need to think about if you're using this technology, uh, and, you know, the architecture you have to build around it.
Things like smart contract injection, replay attacks, permanence poisoning, other things like that. So if, if you're interested in, uh, helping to secure blockchain and cryptocurrency and distributed ledgers, take a look at these areas. Uh, probably something you need to investigate. Cool stuff. Uh, our final little story for this week, it's— this is the kind of thing that we generally wouldn't include.
It's a press release talking about Coalfire speaking at an event, but they're speaking in Davos, which, um, the city, the only thing I know about it is that normally all of the biggest financial folks in the world get together and basically plan our economy for the next year, right? Yes, it is the headquarters to the Illuminati. That is where they live. Yeah, so pretty cool that Coalfire is participating in Davos. They are chairing a panel on the cyber future.
So that's actually happening this week on the 22nd. So if you just happen to find yourself in Davos, Switzerland, and want to drop in, say hi to the Coalfire folks there. Yeah, pretty good stuff. Or if you are the Illuminati, we're sorry, we're not trying to expose you. We'd be happy to help with your plots.
Just let us know what we can do. Exactly. All right. That's it for the news this week. Moving over to our Slack message of the week.
Number one, I want to do a big thanks to Andre Gaeta, our ever-present sponsor for this. Andre, thanks for that. Of course, thanks for Andre coming and doing the interview for us last week. That was a lot of fun. Yeah, definitely a lot of fun.
But as a reminder, he does out of his own pocket support the Slack message of the week, and the winner of this message gets one item from the Colorado Equal Security store. Yes. So this week we would like to honor John Von Raider, who goes by Johnny Von Rotten on the Slack channel. And he definitely made an impact this week. He just, just joined the Slack channel.
Um, and wins the, the Slack message of the week first, first week. Um, he's been actually a, a Patreon, uh, contributor for a long time. So thanks for that. Um, but he posted a picture of a, a needlepoint. Uh, I believe it's a needlepoint anyway that his wife gave him.
That is, um, a needlepoint of a sticky note with a, a bad password on it. It is the most amazing thing I've ever seen. Password 1234, I believe, right? Yes. Yeah.
So it, it is great. I, I told him that he should have his wife you know, make multiples of those and, and sell them at security conferences. People would love that. Yeah, it was pretty cute and, uh, a neat thing to get to share. So thanks for doing that.
And of course, we'll reach out to you and Andre about getting you hooked up with your, your swag. Uh, moving over, we have a calendar of events on the website colorado-security.com. You can go see everything going on here throughout the next few months. Um, as of the next couple of weeks though, we do have the ISC² Pikes Peak January meeting on the 23rd. On the 24th, SecureSet is doing an info night at Swimlane.
Also on the 24th, we have a Splunk meetup with the Boss of the SOC competition. Ooh. On the 25th, the CTA is doing their office hours with Davis Graham and Stubbs and the Foundry Group. On the 28th, the GDPR meetup is getting together to talk about Data Privacy Day, or maybe this is Data Privacy Day, I'm not sure, focused on privacy trends for 2019. And finally, on the 30th, SecureSet is doing one of their capture the flag events.
Uh, you know, that's it for the next couple of weeks. Uh, just to call out, we do have a couple of fun events coming up in the next few months. Um, SnowFROC is scheduled for the 14th of March. That is the big OWASP, uh, Colorado conference that happens every year. They'll bring in folks from all around the world.
I know Jim Manico comes in from Hawaii, and generally You know, we get really good speakers to come be a part of this conference. I'm looking forward to that as well. Yeah, I was actually talking to Matt Shufeld about this, that this week. I believe Troy Hunt is going to be one of the people that is speaking. Wow.
Great. So that, yeah, that is pretty cool. Also coming up in June is the Rocky Mountain Information Security Conference. That is the 4th through the 6th of June. Right now our call for papers is open.
So if you are interested in speaking at the conference, please sign up for that. Uh, we are also accepting sponsors. So if you are a company that wants to reach out to the Colorado community, please go sponsor the conference as well. And we are, um, very close to announcing the keynotes for Rocky Mountain Information Security Conference. We've got 'em all set.
Just gotta wait for all the ink to dry on the contracts and we're gonna be talking about those. So look forward to announcements on that pretty soon. Well, I'm excited to hear about the keynotes. Yeah. For the call for papers, I'd say if you're listening to this and, and you're wondering, you know, if a guy like you or a gal like you should talk at this, the answer is absolutely yes.
You know, what we're mostly looking for are practitioners, um, you know, practitioners here from Colorado who want to talk about things they've learned through their job, either case studies, you know, talk about projects you've done, research you've seen. You know, if you've been through an interesting incident and you want to talk through how that went, those are the kinds of things we really look forward to. You know, we'd rather not bring in folks from outside of the area for most of these talks if we could avoid it. Um, so, you know, please do submit if this is something you're interested in doing. Yeah, I would say if you submit a case study, um, then it is a very high likelihood that you will get selected.
Case studies are always great. Yeah, good stuff. All right, let's move on to jobs. Um, first, there are a couple jobs at Ping Identity. Yeah, so I'll start off with one.
I'm hiring a manager of security operations and engineering. If this is something that's interesting to you, you can send me a note on the Slack channel Uh, but you need to apply on the website either way. But happy to talk to you about it, let you know what's going on with that position. Second thing we're looking to hire at Ping is a GRC analyst. This is someone to help us with things like our, our SOC 2, our ISO certification, our vendor risk management, business continuity, incident response, kind of all that GRC type stuff.
This is a more entry level. We have some seniors on that team, so looking for someone to, to help support the work that they're doing. Uh, next, WellTalk is looking for a director of security and compliance. This is actually, uh, to replace Travis, uh, Shaq, who is leaving, uh, WellTalk. So, uh, if you want information about it, I'm sure Travis would be happy to talk to you about it.
He's on the Slack channel too. You can reach out to him there. Um, next, there is an opening for Array Biopharma hiring an IT security and risk manager/director. I guess you just get to pick which title. It sounds like it.
Uh, Centura Health is looking for a data security risk management lead. The City of Aurora is hiring an information security engineer. The City and County of Denver, specifically DIA, is looking for an information security specialist. US Bank is hiring an information security systems architect. Dish Network is looking for a cybersecurity threat analyst.
Strava or Strava? I'm not sure. Strava, I believe. Strava is hiring a security site reliability engineer focused on infrastructure. And Strava is— looks like it's an app for kind of monitoring your bike rides and exercise stuff.
Yeah, I believe that they're based out of Boulder. They are in Boulder. I looked it up. And then finally, the Arcanum Group is looking for a cybersecurity intern. Good stuff.
Well, that is it for our news for this week. Our feature interview this week is actually— you sat down with Chris Petersen, the co-founder and CTO over at LogRhythm. Yeah, we had a nice conversation. Talked about LogRhythm, their past, present, and future, and it's a good conversation. Awesome.
Well, that's it for this week. We'll look forward to talking to you again next week. Awesome. All right, see you around. Thanks, Robb.
Hey, this is James Carder, CISO at LogRhythm. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Alex Wood, and I'm here here today with a very special interview guest, Chris Petersen, CTO and co-founder of LogRhythm. Chris, how are you doing? I'm well. Awesome.
How you doing, Alex? I'm doing great. You know, as we were talking earlier, it's a little bit chilly. Indeed. But besides that, I think we're— we've missed fall.
It is— it's officially winter-ish now. Yeah, I know, it's too quick. I need to get a few more rides in. Yeah, exactly. I was actually in the elevator with somebody yesterday, and they were— they had their helmet on and everything, and they were worried about having to ride home, you know, in the snow and the impending winter.
Yeah, I was like, yeah, you know, just put snow tires on your bike. You'll be fine. You'll be fine. Um, so thanks for taking a little bit of time to talk to us today. Uh, appreciate it.
Sure. So I guess why don't we start and, and talk about, um, you and your past and and how you got into security and kind of how you got to where you are today. So did you start your career doing security? For the most part, I began my career at PricewaterhouseCoopers. I was part of their— part of the audit side of the firm, and about a year into it, I was introduced to their EDP audit team and function, and that spiked an interest.
I had an information systems concentration in my college degree, and so I liked the systems side. And when I found out that there was a team within PricewaterhouseCoopers who was kind of looking more at the systems and the applications and controls and some of the early security around systems, that piqued my interest. And so I I kind of pursued getting into that organization. You figured you'd rather actually play with the systems instead of just asking people and auditing them about their systems? Well, yeah.
Well, yeah, you know what I'm saying? There's a whole other story about how I got in, actually got into PricewaterhouseCoopers. And actually, I was an engineering major in college. But on the engineering side, I found there to not be a lot of cute girls.
At that time at least, it was very male-dominated. So I moved into the business school and I focused on accounting because I thought I could get a job in accounting. And I was always good at math, and honestly it was kind of easy, at least initially. It got difficult later. But I got into the IS side in accounting school, and that was interesting and kind of what eventually led to me getting into PricewaterhouseCoopers.
And I think that even though I got on the audit side of PricewaterhouseCoopers, the systems side was really where my really where my interests were, you know. And once I found that I could apply more of the systems side and the creativity side, you know, to my job versus kind of financial audit, you know, that was a whole lot more intriguing to me. Yeah, yeah. You mentioned doing engineering and then accounting in school. Where'd you go to school?
CSU. Nice. Go Rams. That's right. So are you from Colorado originally, or— I am predominantly.
I moved around a bit when I was younger. But, you know, mostly grew up in Fort Collins. Nice. You know, and then, and then I went to work, you know, for the, uh, Denver, you know, Denver practice, you know, after, uh, after I graduated. Nice.
Yeah, so spend some time there, and then what'd you do after that? PricewaterhouseCoopers? Yeah, yeah, yeah, yeah. So, you know, so PricewaterhouseCoopers, you know, so, you know, they, um, so I got into the, I got into the, the, um, the, you know, EDP audit practice, and actually part, you know, Part of the other motivation for that and the way that actually I first learned of that practice was there was a New York Times article where they interviewed, I believe, George Kurtz, who is the founder of CrowdStrike now.
He was the top ethical hacker at Pricewaterhouse and was really forming their ethical hacking team. And that's actually what really most piqued my interest, was, wow, there's this group in PricewaterhouseCoopers where they're actually getting paid to try to break into networks and test security. I've always had a bit of a mischievous bent, and so I was really intrigued by that. And that's what really kind of— that was actually the the impetus to try to go into the EDP audit side of PwC, because that's where the security practice was, and it was my path over there. Because I wanted to eventually be an ethical hacker and learn how to do penetration testing.
And that's eventually what happened. Eventually I got into the internet security services practice that was really forming in Pricewaterhouse.
And then got trained up on how to do penetration testing and application vulnerability testing. And these were really early days in cyber. This is when corporate America was connecting themselves to the internet. And they were like, what's this mean for us?
How are we going to defend ourselves?
The projects I was on, a lot of them were like, we need to choose a firewall. I remember doing firewall product selection projects for choosing that first firewall that they were going to put in place to protect themselves from the internet. Yeah. Actually, it's funny, I had a pretty similar path in that I was working at IBM and had an entry-level job there. One of the guys on my team left to go work in the IBM MSS group.
Um, to go do ethical hacking at the time. And I was like, whoa, wait, that exists? Someone will pay you to go do that? Exactly. And I was like, that is really cool.
And then I eventually made my way over into that group too. Yeah, okay, that's great. Yeah, I think, yeah, it's— and I think I'm sure a lot of people, it's happened that way because, you know, that's the, the cool, sexy, you know, fun side of security, right? Yes, it's you know, it's where all the flash is. And I mean, at least on the outside, I think we all know doing the actual testing of that kind of stuff, it's not really, um, it's not like movie style where, you know, you're banging out a keyboard and then all of a sudden, you know, things happen.
Um, but I, you know, I think from the outside, that's, that's what everybody sees as fun. And I mean, even when today when I'm interviewing, uh, you know, people for internships and things like that, it's, oh yeah, I want to be a penetration tester. That looks so exciting. Yeah, yeah, but it's— but yeah, you do the work, you realize there's a lot of work there, right, and repetition. And, you know, and when I look back on, you know, and on kind of how I got to where I eventually got to more on the software side, I think it actually began, you know, PricewaterhouseCoopers.
I attribute some of my success to actually being lazy. That's good. Because, well, so I remember going in and doing pen tests, we'd use the ToneLoc war dialer. And so this piece of software that would just— you could load in ranges of phone numbers and it would just sit there and dial and dial and dial. And then it would output a file.
And then what we were doing previously was looking at all the output of this. We might have dialed 10,000 numbers to see if we got a modem on the other end of it or anything back from that connection. So I built a tool to bring all that data in, analyze it, and to allow us to streamline our ward dialing projects. So I became kind of a prolific tool developer within Pricewaterhouse and began to build different tools and pieces of software that began to accelerate service delivery, and also being able to differentiate our services. Anything that would have made it outside of PwC that people would know?
Well, the thing I built at PwC last was called the Enterprise Security Architecture System, or ESAS, which PricewaterhouseCoopers actually eventually sold that out of— spun it out of PW. And it was very early GRC. And at that time, I was fortunate to work with just some of the leading best minds in cybersecurity. PricewaterhouseCoopers had the best team. This was back in about 2000— or 1994 to about 1997.
And so we had some of the best minds in cybersecurity developing standards for all these controls, all these different technologies. So we would look at RackF, we would look at Unix, and we would look at all the technology at the time and we would document all the different controls, the best practices, and built a technology that brought all this together and we could then provide best practices and policy structures and standards to go and assess and then help companies lock down their technologies in ways they just previously weren't thinking about. And that technology eventually is what got me to my next job, which was Ernst Young, where E&Y came after myself and a couple other people to go help build their national cybersecurity practice. And the one person that— my boss at the time was John Derbyshire, who then went to E&Y. And John Derbyshire then after You know why I went on to start Archer, GRC, because that was John's passion.
But John came to me in PricewaterhouseCoopers and said, I have this idea for GRC. We didn't call it GRC back then. He said, I have this idea and you built these other cool tools. Can you build this? And so I built that for him and evolved it and took some of his vision and ideas and built this early GRC product, which eventually got us to then E&Y and building out their national team.
Nice. Yeah. And so stayed there for a little bit. Where'd you go after E&Y? Is this starting to go out on your own yet?
Yeah, no, so at E&Y, E&Y also pivoted more into software, so I built a software team there and we built like a portal called eSecurity Online and some early managed vulnerability service solutions. Solutions. But after E&Y, I then went out to Counterpane. And so I was in Kansas City for E&Y, then I went out to the Bay Area for Counterpane. And Counterpane was one of the first MSSPs.
It was founded by Bruce Schneier. And it was a chance to go work with some other incredible minds in cybersecurity. I've been very fortunate and blessed to Just have been able to work with some really great talented people to learn from them and be along for the ride. And Counterpane, that was— I helped to really build out their backend, their backend SIEM called Socrates, which would take all the sensor data that they would collect. They built their own sensor, aggregate it, look for signals in that data that might indicate a threat is present.
And then inform their SOC operators if they saw threats and deliver typical MSSP services. That's where I would say first got really introduced to the promise and opportunity around log data and analytics. That's, I think, where some of the ideas for LogRhythm began to form, was through that experience. Nice. So I had, again, I had a similar experience, although I wasn't necessarily the one building it out.
You know, at IBM, we went through a process of building our own backend infrastructure to manage all the alerts that we were using for our MSS and did that for a while. And it was interesting. And then, you know, started using some other products and went through that whole lifecycle and that sort of thing too. So that's kind of fun. Yeah, indeed.
So from Counterpane, Then you decided— is this when you left to start LogRhythm, or— No, not, you know, not, um, not, not immediately. So, you know, so CounterPain, that's when I began to have some, some ideas around analytics, you know. And that's when I say, you know, a key, a key idea began to form, and that was more the application of science to the problem, where I— where my premise was At that time, we were doing things like mapping the human genome and solving other complex big data problems, early big data problems. I didn't quite understand why can't we seem to detect threats in the environment and threats in data when we can solve some of these other analytics problems.
I had this idea we need to begin looking at more scientific approaches to network security and principally around data analytics. And that's actually where the conversation with the co-founder began, with Phil. Phil was a mutual friend and I would come back to Colorado with my buddies, we would go camping and stuff like that. And I would talk to Phil around the campfire after a few beers and tell him the things that I was thinking about and seeing. He was doing his PhD in physics at CU.
He was doing some signals analysis and intelligence and analyzing particles and things coming off nuclear warheads to see if, as he put it, they would still go bang after sitting in a silo for 20 years. That's kind of where our conversation started, was his physics and scientific background and kind of my thought of, I think we need to apply some of the things we are doing in the scientific world to the computer security world.
But at Counterpane, I felt I wasn't quite— after Counterpane, I wasn't quite ready to start my own company because I built at this point a lot of different software and had pretty good comfort that I could build technology that seemed to have to resonate and meet a need, but I didn't really have the go-to-market skill set. And so I went to work for Interacis Networks, who had just recently acquired the Dragon IDS. And, you know, I went there to— good old Interacis Dragon. Yeah, yeah, it's a good product. So I went there to, you know, pick up the product management skill set and also work with Ron Gula, you know, who was the founder of of Dragon and then later Tenable.
And, and so there I got deeper knowledge in product management, go-to-market, you know, and also just got deeper into kind of the state of the art around intrusion detection. Nice. Yeah. All right, so I think we've finally gotten there. This is your background, and now you go and start LogRhythm.
Yeah, yeah. So this, uh, did you just feel like you finally got to the point where, okay, I've got the the building skills, I've got the, you know, the business skills or other things like that, you know, we should take a shot at building this ourselves? Yeah, that's, you know, that's pretty much it. Yeah, I think after about a year and a half, you know, at Dragon and through some other things that were going on at the time, I kind of got to the conclusion it was time to jump and time to do this. And I came back to Colorado to kind of think about how to get this thing going.
And Phil was there, and Phil and I began talking again. And he was wrapping up his PhD and about to do his dissertation. And I said, hey, I've got this idea. What do you think about coming out to D.C. for 3 weeks after you give your dissertation, and we will know, maybe take a shot and see if we can go build something that we can maybe turn into a business. And so, you know, Phil was interested.
He didn't want to go into academia. And we went to D.C. in September 2002. And we spent 3 weeks around my kitchen table in my home. And we built out what we called the Vector Analysis Engine, or VAE. Which we had some authentication data, and Phil found an outlier detection algorithm from Bell Labs, and we applied it to the data with the theory that we could see patterns in that data that might indicate a user's behavior had shifted across time, which might indicate they'd become a threat.
This was today what we call very early UEBA. That was really the first thing we did.
That gave us some hope that there's something here with this vision around more of an analytics-driven approach to cybersecurity. That's really interesting. Did that actually make it into the earlier versions of the product? Were you doing, you know, in quotes, UEBA, uh, early on, or was that more of a proof of concept and then you, you went some different ways in the product? Well, so yeah, well, yeah, so the, the— well, you know, what we quickly determined is really, as we, as we said, you know, hey, you know, okay, we, we're seeing things in the data, you know, things that one, nobody else was even looking for at that time and nobody was really detecting at that time.
And so we had to ask ourselves, well, how are we gonna build a product out of this? What are we gonna do with this? And the conclusion we came to was there was really 2 paths. Was to one, maybe we could go and build the analytics, maybe go sell it to a SIEM vendor like ArcSight, 'cause ArcSight was really just starting to come to market around this time.
Reinvent SIEM. And we ultimately determined that we had to reinvent SIEM because even if we had built it and sold it to ArcSight, ArcSight didn't have the right data platform to take advantage of our analytics vision or our engine because what we built then and what we knew we needed to build and what the industry needed was analytics on top of the universe of data. And back in those days, SIEM was really solely interested in exception-based data. SIEM was first developed to just deal with false positive overload from IDS systems. They could take in other security device events, but it was more the event layer from systems telling me there might be something wrong.
To do behavioral modeling and to do deeper scenario-based modeling, you need access to the non-exception-based data, the things that normally happen every single day, all the log data. We knew we had to build a different platform that could collect a broader set of data and apply analytics across all of it. That's what we set out to do. We actually spent those first few years building the data platform. That would allow us to eventually get back to the class of analytics we wanted to realize.
So how did you guys early on— how did you fund the company? Was this out of your own pockets? Did you, uh— yeah, I sold my house. Yeah, yeah, yeah. I mean, luckily, you know, the markets were going up and I had bought a house.
I moved out there and had about $100,000 in, you know, in, uh, in equity in the home, sold it, and, um emotionally got to the point of being willing to say that $100,000, I'll put all of that into LogRhythm. At that time, the company was actually called Security Conscious. Interesting, I don't know that I knew that. Yeah. And then LogRhythm, we got LogRhythm as the product name, but the company name was originally Security Conscious, with kind of a little You know, you're super security conscious and also the security conscious.
Even back then, we knew that AI was the future, that analytics, AI, that things we were doing from a human cognitive perspective needed to move into the machine. So how long were you guys able to run sort of bootstrapped like that? You and Phil, or did you bring on some other people? Well, you know, I mean, initially, I mean, initially, you know, I wasn't even gonna— I wasn't even gonna write software. I mean, I'd written some software, but, you know, you know, I'd say my software was, you know, it was more on the POC, right, or proof of concept, uh, type level, um, tools.
But, um, then— and so we had a couple of, uh, engineers who were like pretty professional engineers and, you know, they're going to work for equity and, you know, evenings and weekends. And it ended up not working out, you know, because they, you know, they had jobs and families, right? It's tough. It's, it's, it's, it's, you know, hard. It's hard to ask people to, you know, it's hard to expect somebody to be able to put enough time in the evenings and weekends.
They already have a 40-hour, uh, 40-hour, you know, 40-hour week job. So, so eventually we realized we got, you know, we just got to do this and, and, uh, And, you know, Phil, you know, had done programming, you know, in his past and, and was proficient in C and C++. And, and so eventually I said, I asked Phil, hey, teach me how to teach me object-oriented programming. And I picked up some books and, yeah, kind of got, you know, got deeper into it. And then Phil and I just began to write a lot of software.
So for 2 years, you know, we bootstrapped and we wrote, we wrote We rewrote the collection layer, we rewrote the data processing layer, our first indexing technology, put a UI on top of it for search and data analytics, and got to version 2.2, which in early 2005 we were ready to sell and managed to land our first customer.
By that time we'd moved from DC to Boulder. You know, me being from Colorado, Phil had done his PhD here. You know, one day we're in DC, like, why are we here? I mean, right, once this, you know, becomes successful, you know, we'll be trapped here. So yeah, we had a chance to, you know, we kind of came to the conclusion of we can— this company can be anywhere where we can eventually hire, you know, hire engineers.
And so we moved back to Boulder, and, um, but then, then in, uh, And then in May 2005, landed our first customer, Wall Street On Demand, who wrote us a $40,000 check for our software. That was a big day. I bet. Because the money was gone. $100,000 is no more.
I want you to be a customer. I don't, I don't care what you pay me. You just need to pay me something so that I can get some money. That's right. Yeah.
Yeah. The best part though was, I mean, I was, you know, I was some crafty things. But the list price on that deal was $240,000. So we gave them a big discount, but we charged maintenance, you know, on list. That's good.
That's smart. That's very smart. Yeah. But they were, they were a great first customer. Great to work with.
They actually gave us, you know, some office space eventually because they were growing. We moved out and they gave us some Class A space to move into. And they were, uh, they were, you know, they were, they were, they were really good to us. Nice. Yeah.
So, um, you are— you're now in the process— you have, you have a little money in your pocket, at least for the time being. You're starting to build the company. Did you guys actually have an office at this point? Are you, you hiring people? Are you, uh, are you still bootstrapping and, you know, wearing all the hats?
Yeah, yeah, yeah. So yeah, so yeah, so that time At that time, we were in a 400-square-foot office above Perry's Auto Body in Boulder. 2 little offices and a little lab area with all of our cheap computers that we bought secondhand from secondhand shops.
Remember our software.
Once we got our first customer, we got some cash coming in. At that time, I pivoted from writing some software to also beginning to do sales. So I was cold calling, building pipeline.
And we were getting— we went to our first trade show and we had some interest. And we landed then our second customer and lined up our third customer. But we realized that we needed to scale the business faster. That what we built was resonating. And in fact, there was a company that was coming to market fast and furiously out of the Valley, LogLogic, who had— we saw their venture capital, Series A, Series B announcements.
And next thing you know, they've had $50 million in capital. And their website sounded a lot like ours, but just a whole lot more polished. And so we realized we needed to accelerate. And to help do that, fortunately, I'm a tennis player. And on my tennis team, there's this guy Andy Grolnick who was just a blue-chip executive in the area and had been a senior executive in some of the local high-tech companies around here.
And I began talking to him.
Eventually convinced him to join us as our CEO to help us, where Andy could really help us go raise capital, focus on the sales and marketing side, which would then allow Phil and I to really focus on the product and technology side. And then Andy joined us in September of that year. What year was this? This is 2005. And then we began to make plans plans for doing an angel round and, and, and started developing a plan to start scaling the company up.
Yeah, nice. Yeah. And so you guys obviously have been, been growing ever since then.
Sort of the, the end result of that, this year you guys, you were acquired by Thoma Bravo. Yep. Which, congratulations. Yeah, thank you. That's awesome.
Yeah, it is. Um, I wonder if you would talk a little bit about, you know, that process and, you know, how things have changed or, you know, what benefits you're seeing from this, other things like that. Yeah, sure. Um, yeah, so, you know, we, you know, we have been, you know, kind of looking at different options, um, you know, for the company from a, you know, just kind of a, you know, longer-term, you know, kind of capitalization perspective. I mean, the company has been around for a long time.
And so we had our 15th— 15-year anniversary this year. And we're venture-backed. And so we had investors who are looking to have liquidity events. Our investors were— we had just a great class of investors across the board. But we did need to get to an event where there was liquidity for our investors.
And shareholders. And there's the public market, you know, public market options. And we looked at that and evaluated that. And then there's, you know, there's, you know, private equity. Um, and after kind of weighing all the options and after kind of having met with Thoma Bravo and kind of understanding, um, you know, how they operate and, and how they, and how they invest in helping companies go to the next level, um, and, and get there without, you know, some of the the downsides of being a public company, it became a very attractive and interesting opportunity and way to move forward with a great partner that can help us continue to scale the business, execute our roadmap, keep innovating for customers, and ultimately just realize the our full vision, which is just to be the hands-down platform leader for next-gen SIEM, where Forrester just recognized us as first in their recent wave, and we've been in the top 3 with Gartner for many years now.
We just want to be the undisputed best when it comes to next-gen SIEM and running the SOC. Nice. So yeah, you're talking about the future and your roadmap and that sort of thing. What sort of things do you guys have on the horizon that are gonna put you in that number one position? I mean, Forrester thinks you're there already, but how are you gonna stay there?
What cool things do you guys have coming up? Yeah, so I mean, it's, we continue to invest heavily in analytics.
Nobody, no technology has gotten to the point of being able to say, we'll give you, you'll have no false negatives with us and you'll have no false positives. Nobody's there yet and that's probably an impossible goal, but we need to get closer. Analytics, I believe, is the key to that. We're going to keep innovating there. So we have a lot of innovation planned for our cloud AI platform, which is where we're really investing and innovating in the area of machine learning.
And so we're really looking at modeling broader datasets, looking for different observations in that data, ways in which we can have our ML be smarter from a supervised learning perspective. And so our customers will see a lot of innovations around cloud AI when it comes to detecting more of the user-borne threats for our UAV offering, and also the network-borne threat in support of our network detection and response offering. So a lot of work just around analytics and just continuing to push the state of the art in terms of how we use centralized, concentrated collections of vast amounts of machine data across long periods of time to detect those hard-to-see threats. And then the other area we'll keep innovating in is around our SOAR feature set in terms of orchestration and automation. So we'll continue to further build out our playbooks features and make it easier, even easier to execute more complex orchestrated automated workflows.
Just keep building out all the integrations that we have with the most common security devices and enterprise infrastructure that allows us to automate various mitigations, remediations, automate workflows for the analyst.
Our goal really centers around how do we make security analysts fast. Fast through our user experience, fast through workflows, fast access to data, and then just removing all manual repetitive work that we can through automation. I mean, the way I think of it is we want to— we just want to do our best to kind of preserve the cognitive cycles of people for those problems people can best solve and let software do the rest. Yeah. Do you see yourself getting to the point where— and I don't think you can eliminate it, but you can you can severely cut down the amount of work that, say, a level 1 analyst would do.
You know, you talked about, you know, obviously the outliers, the false negatives, false positives, the cutting down that window. So, you know, essentially, you know, you get an alert and that means this is something that you have to, you know, somebody has to do a response response on because this is something that is real, um, which is really the, the, you know, what a level 1 analyst is doing, right? They're, they're taking that first piece and going, okay, is this real? Is this not real? Yeah.
How close do you think that you can get to that?
Well, I mean, I think, I think, you know, over time we'll get, you know, we'll, you know, we'll get real close to it. And I think the, I think the, you know, the The area of analytics that I talked about, machine learning, behavioral modeling, that's an important area. But I think the other area which we have focused on historically and where there's just still a lot of innovation left in front of us is more, I would say, in the area of contextual corroborative analytics. How do we take contextual data around a given event and the various properties of that event event and use that context through machine-based analytics approaches to automatically corroborate and begin to determine through software that this is likely to be a true threat or this is much more likely to be a false positive and a non-threat. And so I think that is going to be one of the big area analytics going forward.
I think the ML side will be very important for the behavioral modeling and profiling, but I think deep contextual corroborative analytics, you know, where we're seeing— where the analytics engines are looking for other data elements around a given event to automatically, you know, raise or lower a risk score and determine with certainty that this is absolutely an active threat. I can initiate automation behind that, or it's absolutely a false positive and they can ignore it. That's a big area of needed innovation. I feel like we— I don't know of anybody who does that better than us today. There might be, but we'll keep innovating there as well because I feel like that's what's required to get to that efficiency of the frontline.
Is they just need to hire pre-qualified corroborated alarms. Yeah, yeah, and being a customer, I love the automation and the smart response stuff that you guys have, and a lot of it now is focused on making the analyst's job easier, right? So I love that idea that you have of more automated analysis, right? So now, I could say have an automated response that will get me additional data from somewhere else to help me look at this alarm, but it's a person looking at it, right? So I would love to see that in the future where instead of an analyst having to do those automated responses to get the data, you know, I mean, it's saving you time to get the data, but, you know, the analysis can then go, oh, hey, I need more data around this and reach out and get more data and then can say, oh, Nope, now risk is going down because I didn't see what I needed to see over here.
That's right, that's right. That would be really cool. I think there's big opportunity there, and especially, you know, one of the advantages I feel we actually have as a vendor is, you know, is that we have a big established install base of people using our product in enterprise SOCs. Yeah. And we can learn from that.
And we can learn, you know, and some of that learning can be applied towards ML-based approaches, which— and if you look at like AI and machine learning, access to the data and qualified data is critically important. And one of our advantages, I think, from an innovation perspective is we have access to a lot of highly qualified data through the workflows happening in SOCs around the world on our platform. Yeah, no, that's definitely a great advantage. Yeah, um, we're getting a little bit, uh, close to time here. I did want to backtrack slightly.
Um, it struck me earlier, you know, you— when you were talking about bootstrapping the company and, you know, having to, to buy, you know, used PCs to, you know, to, to get things going, how do you think that it would have been different if you were starting LogRhythm today, you've got all of this, you know, immediate resource with cloud and other things like that where, you know, instead of having to piece together servers that you might, you know, do to, you know, test your products on and things like that, you've got all the resources you could possibly want, you know, potentially more access to capital and other things like that today, I think, than probably, you know, 15 years ago, other stuff like that. Yeah. Um, do you think it would have been— do you think it would have been easier? Do you think it would have been harder? Do you think it would have just been different?
Uh, well, I mean, I guess it's— there's 2 different contexts. I mean, if it, if it was, you know, the me, you know, 16 years ago starting today, um, with, you know, in, in, you know, in today's environment, um, Certainly would have taken different technology approaches regardless would do that. I think if I was starting clean today, definitely be all SaaS because I do believe that a very meaningful part of the available market in future next-gen SIEM platform solutions, whether it's just the foundational log management, the security analytics, SOAR, UEBA, NDR, all of that. If you look out 3, 5 years, I think at least probably half the market is going to be in SaaS in terms of new dollars spent. I would be all in on SaaS.
From an R&D perspective, boy, SaaS is pretty great because you largely have one main branch. You can introduce new features and functionality in your platform so much more quickly without having to necessarily worry about all the permutations in the field and upgrading all of your customers and their versions. I think SaaS vendors, there's a lot of things to like from an R&D perspective in terms of if you're going clean SaaS. Especially if you're able to leverage a lot of the cloud-native features, go cloud-native with some of the technologies in AWS and Google and what they can provide, what they've built that can accelerate your roadmap if you fully embrace their tech stacks. It's really impressive.
Definitely a different technological approach. Kind of me today starting something, yes, I'd go SaaS, but boy, it'd be so much easier to raise money, right? You know, and I just, I mean, I have the benefit now of a lot of experience, and I feel like I have a pretty good idea of the playbook in terms of what it takes to build a company. So, but, you know, right now I'm very much focused on getting LogRhythm to the to the next level and next-gen SIEM global dominance.
One SIEM vendor, that's it. Logger. Well, there's, you know, it's good to have competition. There you go. Um, but, uh, but ultimately, you know, I just, I want to, you know, you know, fundamentally, you know, we want to just, you know, serve our customers, you know, the best possible way.
And if we do that really well, you know, the goal of being the just the way that we'll be measured, you know, as the— just the hands-down, you know, leader in next-gen SIEM is through the customers, our customers saying that to us and telling that to their friends. Right, right. And, and, and that's, you know, that's the right path through, you know, to achieve, to achieve that ultimate goal. Awesome. Yeah.
Well, again, we're just about out of time. Anything that you want to talk about that we didn't cover? No, no, no, this has been, this has been really, um, you know, really enjoyable. Hopefully I didn't talk too much about my past and all that. Then no, see, yeah, that's what people want to hear about.
Yeah, all right, that's the fun stuff. So, all right, anyway, thanks, Chris. Appreciate your time. It's been great talking to you. Yeah, thanks, thanks, Alex.
It's been fun. Uh, this has been Colorado Equals Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.