Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Me me me me me me me me me na na na na na na na na. Moi moi la la la la la. Welcome to Colorado Equals Security.
This is the newscast for episode 102 for the week of January 28th. 2019. So how are you doing, Robb?
Nothing funny going on here. Well, I hit the record button a little earlier than Alex expected, and we got to hear Alex's weekly vocal warmups. You know, for a voice this good, you got to make sure it's primed. You know, you don't just work out the body. I know, I know how it is.
You got to work out everything. No, I don't work out the body. Just, just the voice. Just the voice. That's fantastic.
January is just about over. Can you believe it? This month has just flown by. It has just flown by. It's pretty amazing.
This is the last couple days of January, almost into February.
I still can't even write 2019 right. I know, right? We do have a little bit of housekeeping before we jump over to the news for the week. Reminder, we have a Slack channel. Slack channel's been super active.
A lot of good stuff going on there. Over 750 members on the channel right now. We also have a mailing list if you're interested in getting the show notes delivered into your inbox. Directly, we would be happy to have you guys sign up on the website, colorado-security.com. And we would love for you to go to your favorite podcast application and subscribe to the show.
And while you are there, it would be great to rate the show, you know, preferably a high rating so that we get more listeners. And yeah, please do that. And next, we have a Patreon campaign. Patreon is a website where you can donate to support what we do here. Really, what we're looking for is those followers out there who have, you know, a few bucks extra per month, maybe $5 or $10 if you don't mind, uh, that you'd be willing to kick in helps us do things like pay for hosting fees, uh, pay for microphones, uh, whatever things it takes to, to keep the show running.
We appreciate it. None of this goes into our own pockets. We've made it pretty clear that the intention of these funds is to go back into the security community. Uh, and if you don't have money you want to give, that would be great if you just tell a friend, um, you know, pass it along, let people know about the podcast and the website, colorado-security.com, obviously. And, uh, yeah, spread the word.
Let everyone know how great Colorado is for security. So, Alex, you know, as we jump into the news here, you know, for years you've been telling me I have a huge head. Um, and, and I've always told you, well, it's because I'm smart. And, and now there's actually some research to, to back up my claims. Holy cow.
Uh, it's hard to believe, but it's really because Colorado wields the most brainpower west of the Mississippi. So apparently we do have a lot of smart people here. And, and that's really based on some smart people who did some research. Is that what I'm learning here? Yeah.
So WalletHub applied 20 metrics to all 50 states to come up with the rankings. Denver was first in percentage of associate's degree holders or college-experienced adults, second in percentage of bachelor's degree holders, also 14th for high school diplomas. And 8th for graduate or professional degree holders. So we did come in 5th place overall. So obviously those folks in the oldest part of the country apparently have been, you know, they have a lot of old institutions.
Number 1, no surprise, Massachusetts, Harvard, MIT. You know, it's tough to compete with that. Yeah. Maryland, then Vermont, and then Connecticut. So I guess this is a suck it, Austin moment for us right here.
That is right. One area, though, where Colorado is lacking is in university quality, believe it or not. We ranked 47th, only ahead of Kentucky, Montana, and South Dakota. So I guess you can't be perfect. Wow.
We don't have, I guess, a lot of the big private universities, right? We've got DU and School of Mines. That, that's private school too, right? Yeah. I mean, that's— there's a couple of pretty high-quality universities there.
Yeah, I guess, guess the rest of them are not quite as good. It's probably quantity of high quality. I'm just guessing. Could be. I should do some reading instead of just guessing, huh?
Yeah. So in addition to that, Colorado was named the 3rd best state for retirement. So the sad part here is that last year we were the 2nd best state. So we're moving down. But, you know, again, with a suck at Austin, we are way ahead of Texas.
So, you know, no surprise that number 1 is Florida. And I'm, you know, that's really based on tax and weather, healthcare, those types of things. But I was actually surprised number 2 South Dakota. South Dakota is the second best state. Yeah, I can't imagine that, you know, that you would want to retire there.
It gets pretty cold. But hey, what do I know? I think no surprise that Florida is number one. Yeah. Next, you know, we talked that there is a new CIO for the state of Colorado.
We mentioned that a week or two ago. And now there's an article here just talking about the CIO's plans. The CIO wants to deliver customer delight both to the workers and the residents of Colorado. Yeah, as you mentioned last week, Robb, our new state CIO came from industry, you know, and she's had lots of experience doing consulting and other things like that. So she really thinks of herself and the IT departments there as consultants to the 17 agencies in the executive branch.
There's also a big push to move things to the cloud. There's going to be an application that goes live here pretty soon that will be the first fully cloud application for the state of Colorado, and they're looking to do more of that. She specifically in this article talked about cybersecurity being a big focus for her administration and the desire to really be an example for other states on how you prepare. And then, of course, how do you respond if you do get hit with a cybersecurity attack? Yeah, good stuff there.
So we will look forward to good things from the state CIO. So as there, you know, next story here, Maxar, if you remember, formerly known as Digital Globe. They were acquired and merged into another company called Maxar. So they had some bad news here in the last little bit where one of their satellites had a failure and it's caused their shares to plummet quite a bit. Yeah.
So the satellite itself was a $150 million satellite. It sounds like they're going to be able to recover a lot of that money through insurance. But I think there's just, you know, lack of confidence now that they're gonna be able to recover from this. It's pretty amazing. Since October 2017, when Maxar acquired DigitalGlobe, the shares were trading above $60, and now they're trading just above $5.
So we'll be really clear that this is not advice for trading stocks because we are not good at that at all. However, wow, holy smokes, that seems like a buying opportunity, doesn't it? Yeah, their market value went from $3.6 billion to $303 million. That's quite the drop. Well, if the community here wants to chip in, maybe we could make it the Colorado Equal Security Organization and we could just, just buy the whole thing.
Well, you know, I'm sure we could do some good with satellite imagery. You know, that, that seems security-focused. Absolutely. Sure. Why not?
On to another not quite so happy piece of news. Denver cable company WOW or Wide Open West, I believe is what it stands for, is laying off more than 200 employees. It is interesting in the statement that they made, this is not necessarily because of things that are not going well for them, but almost, or at least the spin is that they're doing really well and they've essentially automated this call center out of business. So they've done a lot of things to make it so that they don't need as many call center workers anymore. Yeah, it's a It's a big number of folks for them to let go.
Out of the 460 people in Colorado, they're letting 184 of those people go. So obviously for those people, a big impact. But to your point, the story here is actually that they say that things are going very well, that their automations worked and that their investments in technology have allowed them to do this. You know, I think this is kind of a vision of the future, right? As AI and new, more efficient technologies come onto the scene, you do expect to see some of these jobs get moved out.
Yeah, and it is nice in the article they stress how they are, even though they're getting rid of these employees, they're doing their best to treat them well and provide them with good packages going out the door. Yeah, I'm sure, you know, it doesn't feel good to be one of those employees anyway, but as you read it, I got the sense that they were doing just about everything they possibly could to give these people their next opportunities. Moving on to security company news, there was a blog post this week from Ping Identity talking about a survey where it found that security concerns are preventing cloud and SaaS adoption. So this survey, which was commissioned by Ping, it found that people are still reticent to move to the cloud in some instances because of security. Some of those key findings were most of folks' infrastructure is a hybrid cloud infrastructure, which I think that's interesting.
Security concerns are holding back the adoption of cloud and SaaS, and enterprises are spending more to protect customer identity. Yeah, it was interesting to me to, to hear this. I think there's this perception that everything is cloud at this point, um, and, and it's just not true for the enterprises. What I think is really happening is there's a really big push that new procurement and new purchases be much more cloud-focused than they were in the past. So vendors are really heavily— because, you know, all, all their money comes on new purchases, or a lot of their money does, um, so they're really focused on cloud.
But enterprises just have this you know, just enormous investment in their, in their data center and their legacy systems. And those things have certainly not kind of gone away, and they look like they're not going to go away all that soon. I think one of the interesting points from this is something you and I have talked about a lot on the show and off the show, uh, the fact that, you know, security is generally seen as the number one reason people don't move more quickly into the cloud. And I think that that's something of a shame, that, you know, the security teams need to, to really kind of examine themselves to say, how do I get there faster? How do I enable the business to get the value you can get from the cloud and not be the reason that they're not doing it?
Yep, exactly. Next, Webroot had a blog about smart wearables and balancing convenience versus security. There's not a ton of content in here. I'd say that there's a couple points, you know, they're really, when they talk about wearables, they're really talking about like fitness trackers here. And really the point that they make is there are risks in having these fitness trackers and you should be thinking about what are the risks?
We've seen a few different things where the, you know, breaches of, um, like run tracker applications that show, hey, the military's been on this island over here. And right, uh, these things that really leak information about you, you may not expect. And then they, they go through a few different recommendations on, uh, what should you do about this. Um, you know, I guess really looking into the particular device you're thinking about acquiring before you buy it, you know, what do the vulnerabilities look like there? And then they make the the recommendation that you should read through the privacy policy for whatever you buy.
Yeah, please do that. Everyone read all, you know, 1 million words in small print of the privacy policy. I think even recommending someone does that is just going to get you laughed off. How about this? Maybe skim through and see if there's any big bold words that scare you, right?
Something like that might be useful. Yeah. They also talk about good password practices when using devices like this. You don't want to have your smart wearable hijacked because you use the same password that you use everywhere else. Next, we have a blog from SecureSet, and as I looked at this blog, it's really just basically like, here's the business case for going to SecureSet, right?
Yeah, I think that's basically what it is. I would completely agree with that, which is— which I think is really valuable, uh, you know, for those of you who know someone who may be considering either a career change into security or coming out of school, either high school or college, you know, what, what am I going to do? I think taking a look at this blog post might be useful. You know, the argument here is, you know, you don't have to be an experienced technical person. You don't have to, you know, have some kind of specific background to really be able to learn the skills to become a security person in a relatively short amount of time.
Yeah, I think even if you aren't interested in going specifically to SecureSet, you can read the blog and sort of take SecureSet out every time they talk about it, and the principles that are there still apply. Yeah, I think it's right, and really we do need to get more folks into the community, and it sounds like, you know, they're part of that charge. Next, Coalfire had a blog this week talking about the California Consumer Privacy Act and will it apply to your organization. So they start off with just the highest level, you know, who does it apply to, the rules of the CCPA. So they— I say I'll give you the high level.
It says companies that receive personal information for California consumers and meet one of these 3 thresholds. So number one, you have to get data from California consumers. You have to either exceed annual gross revenues of $25 million, obtain personal information of 50,000 or more California residents, or obtain 50% or more of the annual revenue of— by selling California residents' personal information. Yeah. So those are the 3 things.
I think also, you know, one of the nuances here, they do talk about what California considers personal data and other things like that. If you look at that second bullet, it's not only California residents, but residents, households, or devices. That's kind of weird, huh? So there's a— if If you look at the, the CCPA, there's a very broad definition of what information falls under it. So it doesn't even necessarily have to be directly attributable to a person.
It can be attributable to a household. And I, I forget the exact language around devices, but there, there's some play in there too. So Coalfire does a good job breaking apart all of those phrases. You know, I say California residents and they actually drill into what does that mean? So if, if you have, if you're wondering, am I gonna have to think about this?
Number one, this is the time to do it. Yes, we're just about a year out from this regulation going into effect. Number 2, this is a great place for you to start. Take a read through this. Obviously, I'm sure Coalfire would love it if you'd give them a call if you, you want some help parsing through this stuff.
But if nothing else, you can use this as a starting point, you know, before you talk to your own legal counsel internally or externally. And finally, there is a blog from Virtual Armor this week, Keeping Your Network Secure in a Bring Your Own Device World. So this was talking about the risks that could crop up if you're using BYOD in your organization. There was some interesting stuff in here, a few things that I agree with, a few things that maybe I don't agree with, but it was, you know, interesting information. Yeah.
So they start off talking about what are the risks of BYOD, and they listed 5: increased risk of data leakage, increased exposure to vulnerabilities, the mixing of corporate and personal data, increased chances of malware infection, and increased IT infrastructure. So those are the 5 risks they identified. Yeah. And I think one of the things that I don't agree with here is that, yes, those are all possible risks, but I think it depends on how you're implementing your BYOD policy too, right? If it— if you're saying, I am making my, my BYOD devices exactly equal and on par with my corporate-owned devices, yes, I would agree that all of those risks probably apply and are probably pretty high.
Um, but there, there's a lot of ways to do BYOD where you still limit a lot of those risks. Well, they do go through, uh, you know, some recommendations on how to do that, including some of the stuff I know, you know, you guys do and we do. Um, you know, so, and how to protect your network while using BYOD. I'm not gonna go through all these cuz they have a pretty long list here, but they talk about using MDM, uh, talk about requiring strong passwords, um, you know, doing NAC-type controls. So, so you're not getting access to the network from your BYOD.
Some stuff that you can really do to, to minimize those risks. Yep. Yeah, so they do have a good list there, and check that blog post out if you're interested in BYOD. Yeah, all right, moving over to the Slack message of the week. Thanks to Andre Gaeta, our, our loyal sponsor for this section.
Andre, we do appreciate you doing this every week. We get to recognize one of the people from our Slack channel who had a great comment this week. And this week, Alex, who do we have this week? We are going to recognize Daniel Ayala. So congratulations, Daniel.
Um, he had, uh, someone had asked about a, um, a privacy policy. Now, well, not specifically about a privacy policy, something about, um, well, the sort of the principle that you would put in a privacy policy. And so he shared the privacy policy that he's created for his organization. Um, definitely had some interesting stuff in there and, uh, and really enjoyed him, him sharing that with everybody. So, so thanks to Daniel.
Uh, keep it up. I would say that Daniel is probably if not the most prolific Slack slacker in our Slack channel. If not, he's in the top few, top 5 for sure. Yeah, there's a few people who really help, you know, welcome people when they get to the channel, provide lots of good information, answer questions out there. And we appreciate Daniel's continual contribution to the community there for sure.
So we'll get you hooked up with Andre and you can get your free Colorado Equals Security swag. Awesome. Moving on to the events. As a reminder, we have a calendar of events. On our website.
This is, you know, kind of for many of you probably a behind-the-scenes thing you don't think about much, but it takes quite a bit of work to keep updated. And we do try our very best to make sure that this reflects all of the security events that are happening throughout the Denver metro and Colorado Springs areas over the next, you know, actually throughout the rest of this year, everything we're aware of. So take a look there. We, in the next 2 weeks, we have several events coming up. On the 28th, there's the GDPR meetup.
It's a data privacy day, privacy trends for 2019. On the 30th, SecureSet is doing one of their capture the flag events. On the 1st of February, Colorado Springs Cybersecurity is doing their first of the year First Friday, the social and mixer. On the 4th through the 6th of February, the CTA is doing their DC fly-in. This is an interesting event.
It's getting a bunch of people from Colorado on a plane and flying to D.C. and talking about policy issues with lawmakers there, really advocating for what Colorado wants to see from a tech community in D.C. So pretty cool stuff. I assume, you know, now that the government's reopened again, this might actually be more useful. That's— that is true. And I think that the temporary opening lasts through this date.
So I think the government should still be open when people get there. The final event next couple of weeks is the CTA. Colorado Technology Association is doing one of their SheTech events. This is a women in technology event. That's going to be on February 8th.
Awesome. Let's move over to jobs. Robb, I will let you kick it off. Yeah, I've got 2 jobs at Ping this week. We have our manager of infrastructure, uh, what is it called, manager of security operations and engineering.
This is a person who runs our security team that really does like our corporate and production AWS and networking type security. We're also looking to hire a GRC analyst, someone who's, uh, you know, maybe entry-level-ish, maybe a year or 2 experience, who's going to help us with our Uh, policies, risk assessments, ISO, SOC certifications, business continuity, incident response, really kind of helping that team, uh, with those GRC type functions. All right. Uh, there is a job at Janus Henderson, the head of technology and SOX audit. So we're gonna let you do something fun and something that sucks.
Well, I, I think that probably what they're— I assume what they're saying is that they're doing audit for technology and SOX. It's probably an audit position for those 2. Okay. Um, so I, what I assume here is that they're the ones who are gonna tell Joe McComb if he's doing something wrong. That could very well be.
Yeah. So Joe, you know, hopefully we get you someone who's really good at their job and gets you in a lot of trouble. Uh, next we have a position at CoBank. This is a senior security analyst. Uh, really, if you want to go work over there with some really cool guys, we got Stanton and Rob Neyer who are both over there.
Uh, Pensco Trust Company is looking for a senior information security program manager. GBProtect is hiring a senior security consultant. Bellco Credit Union is looking for an OTS information security intern. DU, one of the universities that I just mentioned a little bit ago, is hiring a professor of cyber physical systems and cybersecurity. This is part of the Daniel Felix Ritchie School of Engineering and Computer Science.
That is quite a long position name there, Robb. The state of Colorado is looking for a financial and credit examiner for DORA, which is the division of— or sorry, in DORA, the Division of Banking. Yeah, I think DORA stands for like Department of Regulatory Affairs. I believe so, yes. Yeah, DORA does all their certifications and stuff.
I know that because my wife is a physician assistant and she has to get her DORA like license renewed. Do they all have to wear little backpacks and have monkey friends? There's a lot of exploring as part of that, yes. Our final job for this week is with Zvilo, right? Uh, Zvilo.
I thought it was— I thought we said Zvilo, but it's really Zvilo because there's, because there's only one L. I, I think it goes with velodrome, so I think Zvilo. Zvilo. Okay. Yeah, Zvilo has a VP of DevOps that they're hiring, so it sounds like a pretty fun job. Yeah, so if you want to work at a security company helping, uh, get their systems going, that sounds like a good, good job.
All right, well, that takes us to the end of the newscast. Um, so Alex, I think for this week's feature interview, you sat down with a couple of new folks. Right? Yeah, so I talked to 2 of the founders of a startup out of Boulder called Alpen. Ben Soulier and Mark Evans, had a nice talk with them, learned about how they got there and what Alpen's all about.
Well, looking forward to learning about Alpen. And before we go to Alpen, we actually have a really short interview where I sat down with Nick Tate. Nick is the director of communications for the brand new Northern Colorado chapter of ISSA. He talks to us about what is that group that's meeting together up there, and if people want to get involved, he talks through how we can do it. And I actually do have some links in the show notes to social media if you want to get connected with the ISSA Northern Colorado chapter.
Awesome. All right, well, that's it for this week. We'll, uh, we'll look forward to these interviews, and then we'll talk to you guys again next week. Thanks, Robb. This is Michael Stephen, Privacy Security Officer for Connect for Health Colorado.
Welcome to Colorado Equals Security. Security for Colorado security professionals by Colorado security professionals. All right, this is Robb Reck and I'm here today with Nick Tate. Nick, you are the Director of Communications for the relatively new, uh, chapter of ISSA here in Colorado, up in Northern Colorado. So I'd love to have you talk to me a little bit about what the chapter is doing up there and how folks can get involved.
And I guess maybe starting off to understand, how did you first get involved with the chapter up there? Yeah, absolutely. I've been communications director maybe 4 or 5 months now, and it was just good timing on me showing up. They were having elections the day that I arrived. They needed communications director.
I realized I couldn't find information about the club from the external world. There's very little on social media or online in general. So I basically signed up to fix the problem that I was having. I couldn't find the club. So we've been running— the club has been existing and running meetings for over a year, about once a month.
Someone gives a presentation— security, cybersecurity, physical security, a lot of different topics. Yeah, and where do you guys generally meet? The group was pretty much founded out of the USDA building up there, so there's quite a number of current government workers and alumni from there. But as with the shutdown right now, the building is locked, we can't use it. We've had to, had to adapt around that.
So meetings are always in Fort Collins, right? And you're, you're pulling in folks from, from what, what areas would you say folks are coming to the chapter meetings from? Fort Collins, Loveland, uh, some folks come down from, uh, potentially southern Wyoming as well. Wow. Actually, we're only like a half hour from the border.
I, I lived in Fort Collins like a year before I really realized how close we were. Wow. Uh, and you get some folks from Greeley too, or— Oh yeah. Okay. Greeley, Windsor.
Um, that's, that's pretty fun. And so what's the, uh, what's the feel? Have you been to other ISSA chapters, maybe in Denver or Boulder? How would you say that, you know, differences in terms of the feel of the meetings? Oh yeah.
So I've come down to the Lodo as well as the Boulder events a couple times, and comparing those, we serve like a somewhat different niche in that a lot of our speeches are done directly by our members. We are gonna have a couple sponsors come in soon, but it's a little bit more low-key. We don't serve food, but it's at the end of the day, works over you can focus on, on what we're talking about and just kind of relax. So when do you guys meet? What's the time?
Usually it's the second Thursday of the month at 6. 6 o'clock, second Thursday of the month. Yeah. And it's generally at the USDA building, but right now not so much. Who knows how long this shutdown will go on, right?
Well, hopefully by the time this runs, it's open again, but fingers crossed. Not just for us, right? For, for, was it 800,000 people who were impacted? For sure. Um, so it sounds like, you know, what kind of needs do you have from the community?
Obviously this is a place where people can go, um, to, to go get to meet other folks in the area. Um, but I, and I, I'm suspecting maybe you need volunteers or speakers or sponsors. What kind of, you know, call to action would you put out to the listeners? The most important thing we're looking for is more folks. Uh, it's the same group like week in and week out.
We're a dedicated group, but, uh, We need to grow. We're trying to build out our speaking schedule for the rest of the year. We have a couple months booked so far, but we want to get a bit more structure, a bit more planning, and hopefully build our leadership team as well. Yeah.
Okay. Anything else that you want to say to the listeners before we, before we call it in?
No. All right. Well, Nick, we appreciate you volunteering and helping, you know, drive the chapter. Obviously, it's a wonderful thing to get able to serve a brand new area that, you know, certainly the, the existing chapters of ISSA were not serving. Um, and hopefully we can help you guys, uh, be successful and help you grow.
It looks like you have one more thing to say. I do have an idea. Um, I'm a huge rock climber, and, uh, if anyone's in the InfoSec area or is trying to get into that area and is interested in rock climbing, come say hi to me on Twitter. All right, love to talk. I also say, I don't know, Nick, if you're on the Slack channel, that'd be a good thing to talk about.
We have the whole random channel, pull it up there and If there's people who are interested, we can create a whole new, a whole new channel in there to talk about rock climbing. There's a skiing one already, a ski and ride one. So awesome. Thanks, Nick. Appreciate you coming out.
We'll look forward to hearing back from you soon and seeing the success of the chapter. Cool. Thanks so much.
Welcome to Colorado Equals Security. We have our feature interview today. We have a couple very special guests with us. We have Ben Soulier and Mark Evans from Alpen. Or is it— do you guys put the IO on there or just Alpen?
Or no, we just go with Alpen. Just, we're just with Alpen. Okay. Um, you know, it's funny with all of the the, the weird— the .ios and stuff like that. Sometimes you get a startup and it's like, you know, they have a name and their domain name is .io, but they call the company .io too.
Anyway, um, so, uh, thanks for joining us. I appreciate, uh, you guys being here. Um, I'd love to hear a little bit about you guys and get to know you and then get to know the company. Um, Ben, maybe start with you. Yeah, talk a little bit about, uh, your background.
Where you're from, what your career was like, all that kind of stuff. Of course. I mean, starting with my accent, I mean, my outrageous accent, you can understand that I'm not from here, so I'm French. So basically, I started back my career in IT in 2002-ish, approximately. Been doing a bunch of stuff between, let's say, Unix Windows type of thing at the time.
Moved to doing some consultancy back in Europe, so I did that in France, in UK, and in Switzerland at last. I worked for quite a lot of Fortune 500 companies. There's a lot of them in Switzerland actually. And so building my career and doing really interesting things for very large-sized companies like Nestlé, for example, like some of those companies are 300,000 people, so very interesting challenges technically speaking, I would say. Yeah.
And from there, I mean, always interesting of doing things here and there, so meetups, those kind of things, as you know. So interacting with people, learning new things, learning— I mean, knowing new people, this kind of things. And what happened at that time is that, so Julien which is not there today, who is one of the co-founders of the company. We spent some time together and we were having the same kind of issues all the time. You know, when you are doing that kind of job, we had like basically one laptop per client.
So each time a different password, a different login to remember, and those kind of stuff. And at the time, this was, let's say, beginning of the 2010s. We were starting to have this idea of saying, man, having all of those passwords and all of those things to remember, that's lame, that's not very helpful. Would there be a way to actually have something that would not make you remember all of those passwords and logins and just log in you automatically to something? And this is where I started just doing tech stuff because this is what I liked.
Just building, putting blocks together, and coming up with an idea of, oh, I have actually a small POC of something that helps me to connect to an endpoint without a password. Yeah. And that was the first glimpse of the first company we had at the time, which was called LogR. So doing that, that's most of the background. And from there, I can probably give that to Marc for the switch on the new product and the introduction of the new platform.
Basically, I'll just— 2 side notes on that. We were also trying to build this company. We started to do Techstars in 2015, so we did the Techstars Barclays program in New York. Okay, so this program was more for fintech, so this was kind of the scope of what we are doing in some ways. So we had a few, uh, in at the time with Barclays and a few other big clients were really interested on what we do and how we do it especially.
And I mean, even if the technology was cool and everything was working really fine, most of the issues we had at the time was we're facing is those big companies are not seeing that necessarily as something which is urgent, or neither something that they would need to implement in the next month. And for startups, when you actually roll out a product or you run a platform, you need to get things going, right? You can't just wait, oh, it's going to be Q2 in 2 years. That's great, but if we wait on you, we'll probably be dead by then. So not really the best time to wait for that.
So basically with the clients we had and the product we had at the time, we started to look at what we have and saying, what can we do with what we have as a base? So knowing that we have a directory of users and connectors to plug to different places and so on. So what can we do on top of that that we can sell faster, that could have some some value, let's say, in the very shorter term, right, to actually make something. And this is where Alpine is starting to take shape. Nice.
Yeah. Well, Mark, let's hear about you. What's your, what's your history? How'd you get to where you are today? How'd you get involved with these guys?
Yeah, so I moved to Colorado in 2010, and I had been leading a marketing agency in Los Angeles. And that was built on kind of the foundation of work I'd done at a search engine called GoTo.com back in the early 2000s. And several of us left this search engine and started some businesses, one of which was an agency. And lo and behold, it took off really well. So we started that agency, and one day I woke up and said, my God, I'm leading an advertising agency.
I don't want to be doing this. I want to get more into technology. So we had developed some things internally to manage campaigns, and essentially we built our own— well, it was an on-prem product at that point, but we SaaS-ified it and then said, hey, let's roll this out and make it a SaaS product for running campaigns. So that was my background, and when I moved to Colorado, I knew that I wanted to do something different and new, and I started getting involved in angel investing. And I was at the Boomtown Demo Day, and some of my fellow investors— I just said, hey, I'm looking for something to do, and one of them said, you have to do Logger, taking me by the shoulders and shaking me.
And Logger was, as Ben mentioned, the predecessor product and the predecessor or company name. And Logger was really intriguing. Ben didn't describe all that it does, but in a nutshell, Logger is a passwordless, biometric, mobile, cryptographic SSO and IAM technology. So everybody listening to this project— this podcast is certainly familiar with the idea. And so the Logger technology was really cool because there's never a password, there's nothing to remember, nothing to reset.
Set, really interesting. And Barclays did the pen testing on it and took 4 guys, 4 weeks, couldn't break the apps, couldn't break the web app, couldn't break anything. So it was, it was really solid. But as Ben mentioned, great technology does not necessarily mean great success. And so I, as an angel investor, was looking at the company and thinking about, you know, who are these guys and is this an interesting space, are they good people?
And boy, really interesting space and really great people. So I started essentially spending almost full-time working with the company. And then one day, as Julian was leading the fundraising efforts, Julian said, hey, can I put you on the team slide? I said, oh wow, that's a big move. If I go on the team slide, that's pretty, pretty much a commitment.
So I thought about that, but it only was about 2 minutes of thinking, and then said, okay, yeah, let's do this. And so we raised money, and it was really under the auspices and idea that lager was going to be the product. And with the help of Rockies Venture Club and a number of different individual investors, raised that first round. And so then I was able to come on board. The funny thing was Ben and Julian, because they are not US citizens, could not be employees of the company.
So I was the first employee of the company that they had really been pushing for years. And so when we, when we had this really great technology working well, deployed at some scale, we also discovered that, as Ben said, not everybody has the urgency to deploy an SSO solution right away. And if you don't raise a fair amount of money, then you've kind of set yourselves up for a tough time. So we said, well, gosh, we're pretty good knowing about security. We're pretty good knowing about connecting apps and users.
What other things are the customers actually looking for? What do they want to solve? And the problem that we consistently heard was, we want to know what we have, right? Number one. And then what the heck do we do with it?
Who's using it? Is that a problem? Is it costing us extra money? Are we compliant? We have all these programs.
And so as we started building out this new product that went by the clever code name of Logger Next, we then had a massive effort to figure out the product name and pulled in all the, all the ideas from everybody on the team. And of course ended up finding not the marketing-driven name, but Ben came up with the name. So our technology team and lead built the product, named the product. So I'm actually not going to work here anymore. I'm just going to step back and let Ben kind of handle everything.
So we switched to Alpen. Sweet. So Mark, you said that you moved to Colorado at some point from LA. Ben, you said that you guys did Techstars in New York. Were you here but doing Techstars in New York, or did you guys come here after?
How did you guys end up here? Okay, so some more background on that. So at the time, I was still in France, so working for some clients I used to work with. And what happened is that, I mean, the life cycles of things happening with those kind of programs are pretty short, right? So what basically happened is that we, we had a few calls and then we had a few meetings online just trying to understand what we do, how it works, and so on.
And in a matter of, I think, 5 weeks, we got the answer saying, oh, by the way, in 2 months' time, you have to be in New York. So that was kind of the break that has to happen. And then at that point, Julien was in Canada, actually, at the time. So he moved over there because his wife was doing a postdoc. So he was already, let's say, on the right continent, which I was not.
That's a bonus. That's a bonus. We have planes, so that's fine. Just one land border that he had to cross as opposed to a water border. Right.
Yeah. It depends if you go by train, because by train is almost as long as going by plane. But anyway, the funny thing at that time is that then I just literally took 3 months away from my wife and my daughter at the time, which was 4 or 5 years old. So it was really hard for her, but we were committed and really trained to do that. So 3 months all immersed in the program in New York, we learned so much things.
I mean, never being part of a startup per se and working in the corporate environment is kind of different. So we learned a lot, we failed, And we failed fast on a lot of things to be able to learn and to do things better and differently. And from the time the program ended, Julien had the chance to go back to Colorado thanks to Brad Feld, because Brad Feld at the time was already looking at issues for founders who are part of Techstars to be able to come on board and to actually be and do things in Colorado. So what he did at the time, I think, if I remember everything correctly, he funded basically a program in CU with some money saying, I want those guys to get a visa to be able to be in Colorado. They'll give you entrepreneurship classes for CU on their part-time, and the rest of the time they can at least be here to actually try to do something for their product.
So this took place, and Marc mentioned that for the fundraising part, and until the fundraising ended up. So Marc was already on board, as he mentioned, and Julien was already there also because he was working at CU. And I moved April— was it? Wow, time is flying so fast. I think it was April last year, or at least 2 years ago.
I don't even remember. Wow, I think it was April last year. Awesome. No, no, no, we are in 2019 now. We are 2 years ago.
So technically, yeah, my counter is not yet set to the new year. So it does seem weird to say 2019 still. I'm not quite adjusted yet. No, at least we're not writing checks anymore, so you don't have that mistake every time. Exactly, exactly.
So you guys, I appreciate the fact that you list everyone as co-founders. You don't always see that, even if it's, you know, you have 3 co-founders, it's the co-founder but this, and co-founder and, you know, CTO and CEO, things like that. Anyway, so my point is, I was getting to what exactly are your guys' roles in the company? Mark, it sounds like, you know, you, you put yourself out of a role. You don't have anything to do anymore, but I'm gonna leave now.
But what are— what do you guys do for the company? Yeah, so Julian is the CEO. Okay, and somebody has to have that title, and he focuses on And well, he does a lot of stuff, but he leads the fundraising effort, for example, investor relations, which for a startup is a huge amount of effort and really important. And he's also a great mobile developer, but we don't have mobile apps right now, so that's nice. He's incredibly crafty at coming up with ways to collect, organize, and process data, which for us is huge because we have massive amounts of data on our customers.
So that's really, really handy for, for us. And he works with bringing in new organizations that are trying and deploying Alpen. And Ben is the CTO, so he leads the architecture and backend, frontend, all of that. And I came in because I was more of a business person and with some sort of technical savvy, but I'm not a security analyst by training. Yeah, I am not a coder by training.
So any offers that I give to Ben to help out are rebuffed, sadly. Yeah, so that's how we split it up. It's a pretty straightforward thing. And then we have a team in Boulder and some people in France as well. Very nice.
Very nice. So, all right, so I've been, you know, beating around the bush a little bit, but so tell me about Alpen. You guys talked a little bit about how you got to Alpen, but what is it that Alpen does? What problems do you guys solve?
Give me the pitch.
It's really based on the needs of several different types of people within an organization solved simultaneously.
From an IT perspective and a CISO perspective, What SaaS applications are my employees using? Okay, and the problem is immense. So whenever we talk to somebody and they guess at how many applications they might have, their guesses are typically almost an order of magnitude below what the truth is. So I can tell you with some stats that our team pulled up, if you are a company of let's say 100 to 250 people, so average might be 150 people out of that, you have about 160 SaaS applications that are in use. Most people think, oh, we have about 20 or maybe 50.
Once you start getting up into, let's say, 10,000+, and these numbers are based on our customers, 10,000+, our customers have over 5,000 SaaS applications that are in use.
Most detection of that is done either from a firewall basis, where what's getting pinged, or from a financial basis of what's getting paid. The knowledge is not really spread. Having a central dashboard to say, what do we have, who is using it, when are they using it, and specifically how are they using it, is Kind of problem number 1. Problem number 2, once you know that, okay, so tell me about the security implications. I think a great example is in a G Suite environment, really, really prevalent, people sign in with G Suite.
When you sign in with your Google account, you grant permissions to that application, and everybody just clicks right through, almost everybody. CISO is not going to click right through, mostly. I click through all the time.
So the permissions that are given are really outrageous, and some stuff is surprising. Adobe Acrobat actually has full access to Gmail permission. Now, that is probably sloppy programming. It's not a malicious dark web, you know, they're selling information. But My.com is a Netherlands-based, Russian-owned gaming site.
And in one of our customers, 50 people had authorized my.com to get access to all of their Gmail. If that's your director of finance or a security person or an M&A person, who knows exactly what they're doing, but it's a big risk. And that's not just G Suite, because if you give Calendly access to your Outlook calendar to help you with scheduling, well, that thing needs access to your calendar. And what do you have in there. Just knowing— and that's one slice of the security pie, obviously, but that's something that it's really hard to depict that.
We have an approach to say, here are the applications, here are the users, here are the permissions, and we've scored those to make it actually usable to say, well, what do I do about this? That's a problem that some people realize they face, and some people don't realize they face on the security side. Something which is really funny on top of what Mark was saying is that the fact of not realizing is really the onboarding and the first access to the platform because everything is automated in terms of discovery up to those information is people then experience, let's say, the knowledge of those applications and those things firsthand. They just ended up on the dashboard saying, wow, I was not suspecting any of that. So that's the wow effect that's really interesting in that case.
So when you describe the product and the things that you're trying to solve, the first thing that comes to my mind is CASB, Cloud Access Security Broker. Is that a category that you would put yourselves in? And, oh well, and whether or not you do that, do you feel like that, that is, uh, that is sort of what you're doing, or you guys think you're fundamentally different from, um, you know, a, uh, Sky High or, uh, yeah, Managed Methods or, uh, you know, whoever else? Yeah, no, we are similar to, complementary with a CASB. CASBs typically are going to be incredibly powerful very granular control, and that comes at a cost, sometimes monetary for sure, but in terms of configuration, deployment, setup, management, that is something that realistically takes time.
Talking with a number of folks in the CASB space, and again, you and your listeners are going to know this inside and out if you've researched CASBs and used them, deployment can take many months to actually get it set up and running, fully, and if you want to use a reverse or forward proxy, then it's also kind of, hey, it's a choke point now, so that's a decision you have to make versus basically just APIs. We do 2 things that are pretty different. Number one is we're pretty instant on, and number two, we display things in ways that we haven't seen in CASBs. Ours is truly a dashboard in the sense of what is there, just give me the list prioritized by security risk, and that's from a what are the applications perspective, but you can also slice and dice and say, I want to see a particular user and what they're accessing, or I want to see— I've tagged a bunch of users as this is the GDPR compliance team, and what kind of stuff have they used? Is their stuff even GDPR compliant?
And when do they use it? So you can slice and dice things differently. But we operate really in parallel with a CASB, and we don't claim to go after the depth they have at this point. And I don't think that's something that we're going to go after because it's just— that's an intensely high-investment business to build a great CASB product, and there are a bunch of them that are really good. So we're quick, and the display of information is very usable.
Usable.
It sounds like— do you guys have a remediation component as well, or is it just an exploration knowledge, who's doing what kind of stuff? It's funny. You can think of the world of applications like this in terms of dashboards that give you information and control panels that let you actually take action. We're a mix. On the dashboard side, collecting information about the different applications in use and the different users, different permissions, files being shared, email, kind of DLP-related stuff.
When it comes to the control panel side, I would say here's a good example. We are able to essentially blacklist applications and stop them with the push of a button.
If you find some permissions that you don't want to have for that my.com for example. So push of a button, you can actually take control of that, or you can do it at a user level. From a DLP perspective, we're more of a DLN, like a digital loss notification, as opposed to— or data loss notification rather than data loss prevention at this point. That will change over the coming year, but right now it's only a piece of it. So some of the things that we also do are like deprovisioning.
So some applications we can help deprovision. So those are kind of workflows and actions that aren't necessarily part of a CASB, might be part of another thing. Okay. So Ben, how does it work? I guess that's the easiest way to get to it, right?
You guys mentioned that most of the time to know this sort of stuff, you're looking at network traffic or Or you're talking to your purchasing department to see who paid for what. How is it that you guys get all this information and how does the product work? Basically, the way it works today, you have to see our platform as being the dashboard that Mark was talking about. We have a bunch, quite a lot of integrations that we have around the application that you choose to integrate or not. It's up to you to say, oh, I want to connect to— so the firewall is one.
From an API point of view, it could be Salesforce, could be Box, Dropbox, and any of those, let's say, big players in the SaaS market. And basically what we do is making sense of all that information in the box when it's there. The interesting part, and I'm just going to make a small a small thinking of what we had with Logger is what was painful with Logger, which is not the case with Alpine, is that having SSO for a company is usually a kill switch. You have to implement it for everyone or you don't implement it at all, right? In the case of Alpine, what's interesting in that case is that we give insights and information just monitoring and plugging into different systems without having to interfere or to start to be put in place or in front of things that could break or that could involve additional, as Marc mentioned, setup or anything like that.
We just look at streams, basically streams of information, and make sense of that to give insightful data to people to then take either actions from us or take actions at a different level. From the company point of view. Gotcha. So it sounds like if you have some sanctioned SaaS apps, right, your company uses Salesforce, you guys can hook into Salesforce, pull data about who's doing what, who has access to what. If you're on G Suite, you could plug people into G Suite, I assume, and get that kind of data.
But then it also sounds like for the ones that maybe are not sanctioned ancient cloud apps, you could plug into my firewall and say, oh, hey, where are people going? Let's pull that data and see what SaaS apps people are connected to. Exactly. What we figured out just building the product alongside is that there is no such thing as having one way of getting the data and having only one. That's really what we've learned across the whole lifecycle of the product, which makes I don't remember how many— we have tens of discovery methods today.
APIs is one. Logs is another one. We can actually— and we do look at your emails in the sense that— I mean, not intrusively. We restrain— I mean, coming from the security world, we usually restrain ourselves just to look at the bare minimum of what we need to have to be able to make sense of something. One of those things is, for example, your email headers.
We just only look at when the email was received, what's the title of the email. We have some machine learning type of thing that runs behind the scenes to make sense of that, to kind of try to articulate that, saying this person is probably paying for that because there's like an email saying, oh, your Slack bill of that much has been received, blah blah blah. So that's another way. We go into multiple ways, but even with all of the mechanisms we have, we are not at 100%. And that's the thing, is neither any solution could be, because there's always ways of doing it aside, outside of the company's network, using a hotspot or whatever could be the, the possibilities to avoid going through those kind of platforms.
So we're just trying to have as many boxes as we can from And just take all of that data to try to make some sense of it as a whole. Nice. I would also imagine that since it is sort of an API plugin kind of solution, that it's probably pretty easy to set up and fairly low overhead. You're not going to send me a pizza box to put in my rack and things like that. Right, right.
We don't sell you like Google was doing at the time, like a Google search box that you plug in your own network that sniffs for everything to provide you search experience or anything. Right. So we have on the dashboard, it's pretty simple. You have an integration list. You say I want to integrate that.
We do either OAuth type, OAuth OAuth type of thing. We ask for tokens or endpoints we can actually get the data from. And that's about it. Nice. Yeah, those discovery methods, there are 13 of them.
So I was seeing 10s. Yeah, not 10s. When you said 10s, I'm like, wow, that's— there's 13 of them. But some of them are API-based, whether that's to an individual application like a Salesforce or something that can be like an Okta on the SSO side, G Suite and O365. Then there are essentially working in partnership with, you know, a firewall or a proxy server and getting the logs from that and then processing it and just displaying the logs in a fundamentally different manner, more usable manner.
And then there's endpoint detection, whether via browser plugin or an agent. And then there's financial system detection, so looking at online banking or expense reporting systems or accounting systems. We also recognize that not just security people are worried about giving too much data. The finance team might not want to integrate NetSuite with us. That's fine.
Just dump a CSV file, and we'll analyze the CSV file and apply some intelligence to it to say, what is our confidence level that this item is actually a subscription to Lucidchart as opposed to something else. Yeah. Oh, that's cool. So it sounds like you guys have some good base-level capabilities. What is on the roadmap?
You said now you can do— what was it, DLN? I said data loss notification. What is coming up? What else should we look for? Yeah, I think some of the biggest things we're looking for for our— fit into several different categories.
So first category is reporting and alerting. So right now we have a bunch of canned reports and canned alerts, and making them more customizable by the end customer is really useful. So didn't mention the cost side, but one of the things is when you start looking at applications, you find substitute applications like you're using Basecamp and Asana and Jira. And then the second thing is you find users who are— or rather different pools of the same application. You want to pool them together into an enterprise, and then you want to know when they're renewing.
So notification of when that's happening. So the reporting and notification center, beefing that up is one angle just for usability. A second thing is looking at the workflow control panel angle from a, I want to do something, and from a checklist perspective, just to make sure that I say, here's somebody who's offboarding, let's have the checklist, let's assign it to different people, let's make sure that the steps are all taken. We have a kind of an alpha version of that, but that's a big deal because that's a pain point for people. So we want to solve it in a way that makes it really simple.
Then from a detection and telling you what's happening perspective, building out even more integrations and more data collection to show what people are doing so that you can forensically look back and say, hey, a week before Alex left the company, what was Alex doing in various applications? And oh, that was interesting. Alex downloaded all the contacts out of Salesforce. That's curious. Why would Alex do that?
Of course I did. I work at the company. Why wouldn't I take all my contacts with me?
Discovering more and more types of stuff and putting them in there is big. Ben, there may be some other things. Not sure if I hit them all. That's pretty much it, yeah. Cool.
So what about on the— not on the product side, but as a company? You know, you guys are clearly a startup. What's the path right now for the startup? Are you guys— are you hiring people? Are you— I mean, as a startup, you're probably always doing some sort of fundraising, but— Well said.
What does that stuff sort of look like right now? So our team right now, is most people are in Boulder and a couple of people in France. As I mentioned before the pod started, one of our team members was in the US on a J-1 trainee visa from France and went back and is now working with us from France, which is fantastic. And we will probably hire more in the United States rather than outside the United States. We found that the, the benefits of being close and in the same time zone pretty helpful.
We'll expand, but I think we'll start that phase. As you mentioned, the fundraising— we're always fundraising. Luckily, right now we've raised a couple of rounds, and in the last round, our investors were super committed to leading the A round as we start growing and hitting some more metrics. And as any startup does with the bumps and plateaus, we've still been able to power upward And now looking at the next few months, we should be able to actually raise that next round and add more people. And the big thing is not just the product, but the customer success side of this, because there's so much data.
I mentioned there's so much data that we're collecting that we, we have to build the tools to automatically analyze them. And in order to do that, we have to manually analyze them first to figure out what the heck we're doing and what needs to be automated. Working with our customers to give them the insight so they can take action is a huge area for us to invest in. Those are probably a couple big areas we'll be hiring for in the next few months. Awesome.
We're getting close to time here. I don't know if there's anything that you guys wanted to touch on that I haven't hit yet or any other topics that we need to to cover while we're here? Yeah, the big thing for me was discovering the team here doing the podcast and all of the people associated with it. And by that, I mean, when Ben and I were looking through and listening to some of the pods previously, there is a great cast of characters that exist in Colorado. There sure is.
We don't know them all, and it's just, it's super exciting actually to be part of a community and know that there's there's still so much more opportunity to make those connections and meet more people. I mean, it's just, it's a bunch of really solid, smart, capable people, and that to me is just a great learning from getting exposed to this. So thank you for that. You're welcome. Appreciate you guys being here.
Yeah, thanks for, thanks for having us. It's— I would, I would just, I would just, uh, add on top of what Mark was saying. I mean, before, before you contacted us to, to, uh, talk about that. I was not seeing that there is that much already people communicating and talking about those kind of subjects, let's say, at the scale of Colorado as a whole. Yeah, it's what I like about Colorado as a state, because I mean, I've been for work in multiple places, but Colorado is kind of a unique place in the middle of all the US.
In the sense that there is this community type of thing, especially on technology, that I don't necessarily find in other places. And yeah, that's— it's really energetic and it's really great, and I really like being here. Awesome. Well, that's great to hear, and we're glad that you guys are here, part of the security community in Colorado, and it's been great talking to you. I'm sure we'll have it in the show notes, but if anyone wants to find you guys, it is alpin.io, correct?
A-L-P-I-N dot I-O. Exactly. Awesome. Indian Ocean, that's where we're located. That's right.
Ben, Mark, it's been nice talking to you guys. Appreciate your time today. This has been Colorado Equals Security. And we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security. Equals security.