All episodes

Mike Wilson, CTO and Founder @ Enzoic

Apple Podcasts Spotify SoundCloud

In this episode:

Mike Wilson, CTO and Founder of Enzoic is our feature guest this week. News from: Amazon, DaVita, Trimble, Swimlane, Red Canary, Lares, Coalfire, CyberGRX, LogRhythm and a lot more!

We know where to find your margs

It’s not too late to enjoy a Cinco de Mayo margarita. Amazon’s bringing 400 jobs to town, and DaVita brings one big job. Trimble is innovative - that’s cool. Red Canary gets mad stacks of cash. Swimlane seeks new partners. Lares finds a new man. Coalfire is a great place to work, they say. CyberGRX and LogRhythm bring home some hardware.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11359 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Bienvenidos a Colorado de Seguridad, el episodio ciento diecisiete. Oh man, I can't do this. Mi amo, Robb.

Hola, Robb. ¿Cómo estás? Muy bien. This is the Cinco de Mayo episode of Colorado Equal Security. Yes, it is.

We're sitting here with margaritas in our hands because it's Cinco de Mayo and you can't have a Cinco de Mayo episode without margaritas. Good stuff. And of course, the weather is beautiful and it's actually accommodating for us to enjoy the the perfect day today. Exactly. Are you gonna do anything fun for Cinco de Mayo, Robb?

I am probably going to eat some ethnic food, leaning towards sushi. That's always a good thing for Cinco de Mayo. But I heard, I heard after the battle that this commemorates, they had sushi. That's, that's what I heard. They didn't have anything to cook over, so that's perfect.

I have heard that there are some sushi places that have fantastic margaritas. Oh, so there's actually a play here that we could use. But before we get to that, yeah, why don't we talk about some housekeeping? Let's do it. So, uh, in case you hadn't heard, we have this cool thing.

It's a Slack channel. Um, we have 900 people in the Slack channel, um, all from Colorado, all excited about security. Uh, you should come in there and you should have a chat with us, talk about security, see what's going on, uh, join the conversation. You can find a link to the Slack channel on the website. At colorado-security.com.

And on that same website, if you go to the bottom, there is a spot where you can sign up for our mailing list. You can get the show notes delivered into your inbox every week, along with exclusive discounts on Colorado Equal Security merchandise. Yes, they are 0% discounts, exclusive only for the mailing list. Also, if you like the podcast, please rate us on your, your favorite subscription service, whether that's iTunes or Google Play or whatever podcast listener you listen through. And of course, please also subscribe to the podcast so you get it automatically downloaded into your podcast listener.

We would love it if you would also tell a friend, tell a coworker, tell a random stranger on the street about Colorado Equal Security. That's how we get new listeners and that's how we hopefully continue to improve the quality of security in the area. And if you also want to tell that friend that we do all of this out of the goodness of our hearts and our pocketbooks, that they should also, if they feel like they wanna support us, sign up through our Patreon account to give us, you know, a couple coins here and there to help us support the show, defray the costs that we have in making Colorado Equal Security. You know, it's been like a couple of years since we really talked about why we do this. So just as a summary for those who've joined lately, you know, we do this as really as a way for us to amplify what's happening in the Colorado security community, help make sure you know the different resources you have.

I think we both realized at one point that, um, you know, it's really hard to, to have a perspective to see everything that's going around on in town. So we thought we'd make the place for you to get that kind of a perspective. Yeah, some of those things are figuring out what events are going on, uh, the different security companies we have here in town, the organizations that you can be a part of, and also, you know, to get together and chat with your fellow security folks in Colorado. You know, our— I say our big picture mission is to make Colorado the number one place, the mecca for security jobs, security talent, and security investment. Yeah, for sure.

All right. Why don't we go ahead and jump into the news? All right. First, since it is Cinco de Mayo, our first article is about Denver's top 25 restaurants for margaritas. And fortunately, it's not just within Denver proper.

It's actually some parts of the area. The number one restaurant according to this list is the Blue Agave Grill on the 16th Street Mall. Oh, sweet. Have you been? I don't know if I've been to that one.

I've been there a couple of times. I can't remember. It used to be Used to be one of those. Oh man, I'm gonna get in trouble. One of those restaurants where they have the waitresses not dress all that appropriately.

Not Hooters, but Tilted Kilt. It was that one. Yeah. So it's that same. So I haven't been there.

I haven't been there. So so that's the number one. Yeah. On this list, Alex, what's the number one place for a margarita on your list? I think probably Adelita's.

There's actually a couple locations of Adelita's. There's one in downtown Littleton now, but there's also one on South Broadway. Yeah, great food and good margaritas. So my favorite place to get a margarita is if I'm forced to go to Casa Bonita, is that the 7th or 8th margarita there. So I no longer mind the food I'm eating.

Yeah, there you go. I think also it's a, it's a decent list. I think I've been to about 6 or 7 of the ones on that list. Lots of good margarita places in Denver. Yeah.

Machete's Tacos is on the list, a place that we've been quite a few times. And to the allusion I made earlier about sushi places, there is actually Blue Sushi on the list of top margarita places, which surprised us both. But there you go. Yeah. So maybe I'll go there tonight for my sushi.

Next, we have a story really about the final day of Colorado's legislative session. So the legislative session just ended on Friday. And if you— this article that we posted has a lot of different stuff. You can go see all of the many bills that went through there at the end. However, I was just going to call out there's specifically a tech one that They've extended the tax credits for the purchase of electric vehicles, which were supposed to expire in 2020, through 2025.

Yeah, I've always thought it's interesting. And I get the reasoning. You know, these people, it's sort of a second job to be a legislator in Colorado. It's not a full-time job. So it makes sense that you only have a pretty short legislative session.

But every year, it's, hey, we have all this stuff that we want to get done to govern the state, let's cram it all in, and then you run out of time. I wonder if it makes sense to rethink how we do those sorts of things. And, you know, at my company, if we decided, all right, for a few months of the year, we're actually going to cram in all our work, and then we're just going to go away and do something else, I'm not sure how well that would go over. But there's something of an artificial constraint that makes you prioritize and go after the critical few things. I could see it either way.

What I wonder is if you went from the, you know, a few-month-long session to a 11-month-long session, would we get any more work done? Would we just spend more time talking about this stuff? Could be. It's a hard question. Well, and at some point, if you do it either most of the year, all the year, then you'll probably run into more like full-time politicians, right?

And I think that, you know, we see problems with that in the national government. And for those interested in getting an insider scoop on this, we had Cole Wist, who was a— who was formerly a state representative, right? Correct. On the show about a year ago. So you guys can listen to that interview talking about how he helped get the Colorado cybersecurity law passed.

Privacy bill. Yeah. Yep. Next, Amazon is bringing 400 new jobs to downtown Denver. I think we've talked about this a little bit before in that they're, they're moving.

I can't remember the name of the building, but it's the same building where Red Canary is. Yeah. The 1515 Wine Coop, I think. Yeah. This is— they're moving to the space where Chipotle was because, of course, Chipotle vacated and moved to California.

Bastards. Yeah. But I don't think previously we knew the exact number of people that were going to be in that space. 400 jobs. That's, that's lot of jobs.

It is a lot of jobs. It's gonna be awesome. I look forward to our new Amazon overlords. You better. Uh, so, uh, DaVita has named a successor to Kent Thury.

Kent has been the CEO of DaVita for the last 2 decades. He's been a little bit of a controversial leader. Um, he's got some like national political tie-ins. Um, I remember, you know, seeing him on the Colbert Report or, or whatever took the place of the Colbert Report. What's that guy's name?

Um, I can't remember. Yeah. The, the one that took that guy's place, kind of making fun of him for, you know, for the way that they do business. And he had a, what was it, an eagle or a falcon in the background, or probably a bald eagle. He's dressed up as sort of like King Arthur before and, you know, other, other things like that.

And I, I have heard some people say it's a, it's a little bit cultish or something like that in the way that the company culture is. But obviously DaVita is, is a great company. It is always on the list of best places to work. And yeah, and I know I have some friends there who love working at DaVita and actually like Kent quite a bit too. Um, he's replaced by Javier Rodriguez, who has served as the CEO for their kidney care division for the last 5 years.

And this goes into effect on June 1st. Yeah, and this, uh, keep in mind, this was part of a planned succession. So it wasn't, uh, you know, the result of a scandal or something bad that happened. You know, this is something that they've been planning to do for a while and now just putting that plan into motion. Next, Colorado-based Trimble is looking to change the face of development with mixed reality, you know, AR/VR software.

This is especially interesting to me because when I think of Trimble, I'm thinking of— and the article actually alludes to it— like hardhat-type jobs, right? Jobs where people are out in sites, you know, doing mining, doing big construction. And not the places where you first think about augmented reality kind of coming in right off the bat. Yeah. I mean, and one of the things that they talked about in here was, uh, sort of, you know, a situation like that during construction.

You know, if you're going to make changes to something, um, you know, say you're, you're making a plumbing change and you can't really visualize how that is gonna affect, say, the electrical or the, the, uh, heating and cooling or other things like that. You know, with this mixed reality software, you can sort of look at at how things are going to be laid out after making the change and see if there's, you know, any problems that would happen because of that change. And I physically walk through a site wearing these glasses and see where these new pipes would be and kind of figure it out. Right. You know, this— that's the augmented reality, right?

You're actually walking in the place, but you're seeing these, these nonexistent things. Oh, hey, you know, this plumbing work is now going to be in the middle of our foyer. Maybe we shouldn't do that. Right. Or that's where we plan to have the egress point, whatever it is.

So really cool stuff. And it's interesting to know that a, what we would think of as a non-tech company is really just completely digitally transformed here. Yeah. Also on last week's show, we mentioned that the security director position at Trimble is open. So if you want to be part of that company, you could be.

Speaking of Colorado companies that are doing great stuff, congratulations to Red Canary. This week they closed on a $34 million round of funding. This is a, this is an opportunity for them to really, you know, kind of go big and invest in what functionality they want to be expanding across their, their offerings. Yeah, good for them. Um, glad that they're gonna have a little more funding to expand and get better and, uh, look for good things from Red Canary.

And I, you know, I asked— I got to talk to Brian just a little bit about this this week. And, uh, Brian Beyer, who's the CEO, one of the founders, um, I asked the question, you know, did they take any money off the table as a part of this? And he said not only do they not take money off the table, they're, they're trying to do their very best to, to, you know, they'd love to get more money on the table as they think that this is an opportunity that Red really a successful company that's growing and going to continue to grow. And they're excited about the new investment partners they have. It looks like good stuff.

Awesome. Love those guys. Glad to see they're doing well. Uh, next, Swimlane announced a channel and technical alliances program. Uh, the, the channel program is really, uh, talking about how they're gonna be working with their partners, uh, certification for partners and resellers to be able to, you know, install and and train on, uh, on Swimlane and, and that sort of thing.

And then the, the technical alliances program is, uh, you know, similar to what a lot of security companies have. If you want to integrate with their product, they now have that, uh, technical alliance program. Um, it did, it should make it easier for, uh, integrations to happen because, you know, basically Swimlane, that's what they're all about is integrations, you know, integrating with other products, right? Uh, making sure that you can automate those other products. It, it probably more strategic for them than, than just about any other company out there because they don't work if they don't have those good integrations.

Exactly. Next, we have an article here from Layers. We don't talk about these guys much. This is Chris Nickerson's company, but they have named a new COO. Andrew Hay comes over as the chief operating officer for them.

Andrew is a, you know, well-known guy in the industry. He's written a couple of different books, featured, you know, he's in the media on a regular basis. Yeah. And, uh, I've met Andrew before. He seems like a wonderful person.

Um, as Robb said, he has been around for a long time. Um, glad to see that Laris is growing and that they can, uh, you know, expand their, their leadership and, and have some more folks in there. Yeah. Directly he came over from, uh, he was a co-founder and the COO for LEO Cybersecurity, mostly focused on doing credit union financial services type, uh, type services. So congratulations, uh, to, to those guys, to, to Andrew and Chris and the whole Laris company.

Yeah, good stuff. All right. Next, we have a story from Coalfire. They were put on the list of top workplaces in Colorado by the Denver Post for the 2nd consecutive year. So congratulations to them for being a great place to work.

Yeah, it's good to— good to know that those guys made the list. I haven't looked through the whole list yet to see if there's other Colorado security companies. Have you taken a look at it? I did not see the whole list, but I have not seen press releases from other Colorado security companies. So I'm guessing that maybe there aren't any.

Yeah, that might be true. Or it might be that they just got a little bit of a preview on it and we haven't seen the list come out yet. So congratulations to Coalfire. Certainly, you know, one of the bigger security companies in town. And when you're bigger, it's always, I think, a little tougher to, to stay with that quality workplace.

So good luck. Congratulations to those guys. Next, CyberGRX. They actually won an award too. They, they received the top rating from SC Magazine as a— what do they call it?

Um, a, as the largest global cyber risk exchange. Yeah. So this was looking at, uh, service providers that have software for, uh, doing third-party and vendor risk management. And, um, yeah, as part of that, um, SC Magazine rated them, I think it was, it was not a perfect score, but it was a pretty, it was 4.75 out of 5. Yeah.

All right. So pretty darn good score. Um, so congratulations to them on, uh, SE Magazine thinking that the solution is a positive one. And then finally, LogRhythm. Also, this seems to be an award show list.

They were named a Gartner Customer Choice recipient. So Gartner asks for feedback from their— from customers of different companies and takes that feedback sort of independently to determine, you know, which companies have you know, good customer satisfaction and are happy with the products. And, uh, and LogRhythm received that award from, uh, from Gartner for being one of their customer choices. Congratulations to LogRhythm for that. And, uh, I actually think this is their, their second year in a row winning the same award.

So yeah, nice to know that their customers like what they're doing. Next, that's it for news. Let's go ahead and move over to our Slack message of the week. Uh, Andre Gaeta, thank you very much for sponsoring this. This has actually become one of the more popular things in the, in the, uh, uh, Slack message area.

What people appreciate knowing that, that you're doing this and we appreciate what you're doing. So speaking of appreciation, this week we actually had someone nominate a Slack message of the week. Normally Robb and I painstakingly review every Slack message that went through in the previous week to determine, um, you know, through some amazing algorithm that Robb came up with, uh, to figure out which is the best Slack message. And that's what we choose as Slack messages of the week. Week.

This week we actually had a nomination from someone else. There was an article that was posted by Cynthia Summers about a hackable insulin pump that is on demand these days. And so it was nominated by Flint for her to get the Slack Message of the Week. Yeah, this is a really interesting story. Alex and I read this earlier and we're talking about how it's kind of cool.

It's an old vulnerable version, but basically because it's vulnerable, the kind of do-it-yourself market, was able to, uh, add a new algorithm that assesses, you know, what you're doing and kind of in real time determine how much insulin, insulin you need. So people can actually, versus having to do kind of painstaking calculations outside of that system, actually have it integrated directly with the pump itself to give you more or less insulin based on, you know, what you're actually up to. Yeah. And what they were talking about in the article a little bit is, you know, there's been this concept for a long time of an artificial pancreas essentially, being able to read your blood, figure out what amount of insulin you need, and then pump it back in. And, uh, the DIY market with this insulin pump has been able to essentially create something like that on their own, which is pretty cool.

Awesome. All right, well, let's go ahead and move over to our events. That's it. Actually, I guess I'll say for Cynthia, congratulations, you're going to get to pick one item from the Colorado Eagle Security store thanks to Andre Gaeta. Moving over to events, we do have a calendar of events at colorado-security.com.

Go to the security events calendar. Take a look at what's coming up here. We'll, during the show, we go through the next 2 weeks worth of events, and sometimes we'll do a call out to one other event out in the future. And that's usually right now we're in RMISC season. Yes, we are.

So June 4th through 6th is the Rocky Mountain Information Security Conference. That is the biggest event here in Colorado every year. We'll get, you know, I think we'll get over 1,500 people there this year at the Colorado Convention Center downtown. Yeah. And As we've been doing the last few weeks, um, been trying to highlight some things this week.

I'd like to highlight another one of the, the pre-conference sessions. Muhammad Malki again will be teaching his cloud security training as part of the conference. Um, this has actually even expanded from last year. It was a great success last year. Um, he's expanded it to a full day.

Uh, previously, um, for the Cloud Security Alliance, he teaches the CCSK class. This class that he's teaching at RMISC is actually of his own creation. The CCSK is very AWS focused, which is fine if you are an AWS person, but he goes over multiple different clouds, multiple different topics, full day of cloud security training. So if you're looking to get up to date on what's going on in the cloud, you should definitely come take this one. Love it.

All right, uh, this— for all those people who always ask us, how do I get more valuable for potential employers? Go to this training. There you go. Right. All right, uh, so looking at the next couple of weeks, on the 6th of May, SecureSet is doing a Hacking 101, creating a virtual lab with AJ Menendez.

Also on the 10th, it looks like they are doing a similar one, creating a virtual lab on the 10th, also SecureSet. So that's the only 2 events this whole week. Isn't that crazy? Wow. Yeah, you know, we're getting towards the end of the school year.

I think people are winding down a little bit, taking a little break before, before summer. Well, the next week, starting at the 13th, it is getting started. So on the 13th, NCC is doing their Beyond Bitcoin 102, the future of the tokenized economy. On the 14th, SecureSet is doing their expert series with John Morton on the MITRE ATT&CK framework. ISSA Denver have their chapter meetings on the 14th and 15th.

The 14th will be at lunch in Boulder, dinner in the downtown Denver area, and then Wednesday the 15th will be at lunch in the Tech Center. On the 15th, there is an event called Open Source, Open Taps, Open Possibilities. Robb, what do you know about this event? Um, I now got to remember what this was. Uh, looking it up.

Oh, this was Veracode. That's right. Yeah. So Veracode does their, their DevOps security kind of city tour at different places. So there, I guess I should have put that on the calendar, but this is specifically them coming into town talking about how do you get security embedded with your DevOps process at the application level.

Awesome. On the 16th, ISC² Denver is doing their May chapter meeting. Also on the 16th, SecureSet has another event. They're doing a capture the flag event at DenHack. Awesome.

Uh, on this— the 18th, ISSA Colorado Springs is doing their May mini seminar. They do these periodically, I think a couple times a year, on various different topics. A way for you to learn something and get some extra CPEs. That is it for the events for the next 2 weeks. We can jump over to our jobs.

Um, a couple of jobs at Ping, still jobs, the same ones we've had open for a few weeks. I'm hiring a junior product security engineer. This is someone with a development background who's looking to move over to the security side and help us secure the SDLC. And I'm looking for that person's boss. We're looking for a product security team lead.

As we're growing out that team, we're really looking to, to build a couple of different team pods. So this person would work with 4 or 5 people on their own team helping us secure our SaaS applications. Nice. Twilio is looking for a cloud security engineer. So if you take Muhammad's training, maybe you'd be up for that one.

Absolutely. Metro State is hiring a computer information systems security instructor. You wanna teach how to do it? There you go. Nice.

Verizon is looking for a cybersecurity leader for managed services. Red Canary, as we've already discussed earlier, they are looking to hire a director in incident handling. Nice. DigitalGlobe/Maxar is looking for a director of cybersecurity audit. Get to work with our friend Chris Martinez over there.

Colorado State University is hiring a senior cybersecurity engineer. So this isn't a teacher. This is someone to actually do the work internally. NREL is looking for an energy systems cybersecurity undergraduate intern. That's a very long intern position.

I like it. We definitely have folks who are looking for their internships, and I'm glad to see that not all of them are filled at this point. And finally, Managed Methods is hiring a customer success manager. Managed Methods is the local CASB provider here in town. So this is a way for you guys to, to get your foot in the door working with customers, and it's for a security company.

They're also up north in the Boulder area, so if you're up that way, probably be a good job. Awesome. Well, that is it here for, um, that's it for this week's news. Alex, this week you sat down with Mike Wilson from Enzoic. I did.

Um, Mike Wilson is the founder of Enzoic. They are a service that you can use to check password strength Make sure that you're not on a, um, using a password that is on a, uh, breach, you know, similar, uh, to other services that are out there, like Have I Been Pwned? Um, and, uh, it was an interesting conversation about him and, and Zoic and what they're doing. And they were formerly PasswordPing. So, correct.

So we, we've talked about them on the show a few times with that name. Um, cool. We're looking forward to it. Uh, that's it for the news this week, and we'll talk to you soon next week. Thanks, Robb.

This is Joshua Fultz, CISO at eFolder. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

This is Alex Wood with Colorado Equals Security, and this is our feature interview. Today I am talking to Mike Wilson, CTO of Enzoic. How's it going, Mike? Great, how are you doing? Awesome, thanks for, for coming down and talking with us.

Sounded like you had a, you know, a little extra traffic getting down here, the long drive all the way down from Boulder. Oh, it's Denver. Yeah, I mean, it takes forever to get down to the Tech Center. So yeah, well, again, I appreciate you coming down here. So for the people that don't know you, maybe just give a quick background on, on who you are and what you do.

Well, my name is Mike Wilson. As you've already said, I'm currently Chief Technology Officer and founder of Enzoic. In that role, I kind of basically am managing products as well as the development team and engineering, and also kind of do some coding and a little bit of architecture myself still. And, you know, in terms of my background, I've been in security since 2004. I've been doing software development since since around 1995 full-time.

Before that, I was actually in college, did a bit of consulting here and there, and even all the way back to high school, actually. Nice. If you only got into security in 2004, only, I guess I'll say in quotes. Only, yeah. Only, what were you doing?

It sounds like programming, but what was your focus prior to that? Various things. I actually started my career after college working at NASA. I actually worked for a contractor, Loral Space Information Systems, down in Houston. We actually were doing a contract to replace the old Mission Control Center.

Back in the mid-'90s, when I started, they were still using all the old Apollo-era green screen consoles to manage shuttle flight control. There was a desire to modernize the center. I was part of the contract that was charged with doing that. So we were coming in and replacing all of these old consoles with modern, at the time, Unix terminals and Unix servers, building big clusters of those and all modern X Windows GUI apps for everything and bespoke application development for all these different flight simulator things. That's funny to hear now, modern and X Windows.

Exactly, yeah. In the same sentence. At the time, modern, yeah. Um, yeah, it's sort of random tangent. I was listening to something the other day and they were talking about, um, there was supposed to be a spacewalk and it was going to be— I think it was going to be 2 women.

And that would be the first time ever when there were 2 women doing a spacewalk. And it ended up not happening because they didn't have enough, uh, they didn't have the right size spacesuit. Right. And I was like, that is so weird. And then they went, they went through the story about how, um, you know, essentially they're using the same spacesuits that they've used since the '70s.

And so, you know, sometimes they only have like a certain number of a certain size of spacesuit. So if you are a certain size person, right, and you can't— they don't have the right size spacesuit for you up there, um, then obviously you, you can't go outside. You can't go out in space. Um, and, uh, that was just a weird problem. Yeah, um, you wouldn't think that would happen, but they also said like every one of those spacesuits is like $15 million or something like that.

So there's not really an incentive to get new spacesuits, but right, right. I don't know, very strange problem. Yeah, exactly. Um, so anyway, uh, you were— you're doing, uh, replacement work for, for NASA, and, uh, that was— that was down in Houston? Like, that was down in Houston, yeah, at the Johnson Space Center where Mission Control is at.

And so as part of that, I, you know, I'd actually get to go go into the control center during missions and help support some of the missions and take performance data on what at the time were all these brand new applications and figure out if we had performance hotspots that we need to address and just kind of monitor health and status of the system during missions, which was really, really cool. I was really excited about that. Were there any interesting or scary or anything sort of scenarios that you got to witness? Like while you were in there, something crazy happened in a mission or something No, I never really saw anything crazy happen during a mission. I did see at one point, you know, the network— one of the things I had to do actually was monitor the network periodically, which it was all this kind of fiber network.

It was FIDI, if you remember that. Yeah. And basically, I plug in this network analyzer and, you know, we would take just random traffic captures. And at one point, I did actually see— I think somebody was imaging a bunch of new workstations during a mission, and I saw the network just kind of max out for a long period of time, you know, just hit the 100 megabit per second limit on the network for a long period of time, which was kind of interesting. You didn't really want that to happen because, you know, these consoles would just start dropping data when the latency would get too high on the network.

And so, you know, you can just have periods where the controllers couldn't see any data coming from the shuttle, which is always problem. Yeah, you don't want that. No, you don't want that. Although that did happen sometimes. That's kind of crazy.

Yeah. And so then you moved on to where after that? Actually, after that, I actually went to graduate school. So I went up to Penn State to do graduate school. And, and then when I came back from graduate school, I actually started a company.

Well, I had a couple series of jobs, but I was doing some consulting for a little while, and then actually in the late '90s kind of started a company doing next-generation voice over IP kind of applications. So like fax over IP, voice over IP, which in the late '90s was kind of a cool new thing. And so I started a little company with 3 other partners at the time down in Houston, and we did that for a couple of years. And we actually You know, we were relatively successful in the sense we were, you know, making money, paying salaries. You know, not wildly successful or anything like that, but I ended up leaving that company because our CEO at the time, one of my partners, basically came in and told us that— he was also the one who kind of focused on sales— and came in and basically told us that, I'm gonna be spending a lot less time on the company because I'm going to go pursue a career as a professional poker player.

So it was kind of a good indication the company was probably gonna start winding down at that point. And so I had spent at that point, actually, I guess about 3 or 4 years doing that and was a little burnt out from the startup grind of kind of bootstrapping this thing for the last 3 to 4 years. And so I kind of went through this period of just not knowing what I wanted to do. I mean, I was still there and still kind of pulling a paycheck, but I just, at that point, I was kind of just done. And considered all sorts of a variety of different things I might want to do, but at the end of the day, I kind of said, well, maybe a change in location is kind of what I need.

It's tough to go from being in your own company and having that going and to segue into just going and working for someone else. I was trying to find something that made it more palatable for me. So I, I had, you know, really heard great things about Boulder. I'd never actually been to Boulder, I have to say, but I'd heard great things, read great things, and I just kind of got curious. And I said, I'm going to pull up Monster and just see what kind of jobs are available.

Yeah, in software development in Boulder. And I hit upon a job where it's one of those kind of weird things where it's like you read it and you're like, this is just— this is me. This is my totally almost reads like my resume. So it turned out that job posting was for a company called Webroot. Might have heard of them.

Might have heard of them. Yep. Recently got acquired by Carbonite. Yep. And so I applied for the job, you know, did their code test, which was a lot of fun.

And, you know, that point when I think when I first started interviewing them, they— with them, they were about 20 people or so. Wow. And so they'd never actually reload anybody, so they were kind of like, well, we don't know if we really want to do that, but you did really well on our code test. We really like you, so we want to bring you in. We'll bring you up here for an interview and let's see how it goes.

And so they flew me and my wife at the time up there and brought us into the office, brought me into the office, and did an interview on site and got to go to their Beer Friday that they did every Friday where they had a keg in the office, and, and that was cool. So I got to kind of meet everybody and talk to everybody. And we spent the weekend there in Boulder, decided, you know, kind of just get a little bit of a feel for the place. Loved it and said, you know what, if they make me an offer, I think I want to do this. And they ended up making me an offer and gave me some relocation allowance.

Nice. And that's how I got into the security space. So next thing you know, you know, I'm up here working for Webroot. And, you know, initially they kind of had me doing some groundwork on sort of their nascent antivirus product they were considering building at the time. So what were they doing?

I'm trying to remember what they did before they did antivirus. What products did they have when you got there? So their main— their 2 main products. Their first product was a product called Window Washer, which essentially kind of cleaned windows, like cleaned up your history, browser history. Oh, like a CCleaner kind of— Yeah, yeah.

So they, you know, That was a pretty successful product for them back in the day, and then they kind of just got this wild hair to try and do an anti-spyware product. This is, you know, 2003-ish timeframe, I think. And so not really much of a market for it at the time, but it was one of those just sort of perfect timing things where they said, let's roll the dice and try and put together an anti-spyware product. I think you had like Spybot out there at the time. And AdAware were the two probably most popular ones.

But they, you know, Spybot was free, and it was a small, small, small space at that point. And but they released it, and it was just sort of at the exact right time. And then this sort of tidal wave of awareness about adware and spyware hit, right? Kind of, I think, more like early to mid-2004 timeframe, right about the time I started. And Spy— I mean, SpySweeper, which was their product for anti- Spy Sweeper just took off.

I mean, it was crazy how successful. I mentioned there were about 20 people when I first started interviewing in like May of 2004, and by the time I joined, by the time I actually got there, probably like late June or July 2004, they were double that. I mean, that's how fast they were growing. They were like 40-something people. So the trajectory they were on for growth was just insane.

So yeah, I joined the company and it was just sort of a wild ride of growth when I first got there. People were just being added all the time and new faces in the office all the time, and they just moved to bigger offices right as I joined. But they kind of had me working on this antivirus product and then decided they just really wanted to expand the development team on SpiceWeeper. And so, and they were in the process of rewriting SpiceWeeper at the time. And so they had me join that effort and so I ended up being on the 4-person development team that rewrote SpiceWeeper.

Got in on the ground floor of that and then they were kind of looking for a leader for the team and of the 4 of us who were on it, I was really the only one that kind of had any type of leadership experience. And so they just picked me and said, hey, you want to lead this team? I said, sure. And that's— ended up becoming the manager for the SpiceWeeper team. And yeah, from there it was just the next, whatever, 2 years were just kind of crazy, kind of riding that.

So, you know, 5 straight Editor's Choice Awards we won on that product from PC Magazine, and that was a big driver for a lot of that growth too. We kind of were like, for a while there, were pretty much acknowledged to be best of breed for consumer anti-spyware. So this was your first foray into security, and I know your current company is in security. So did that experience hook you on security, or is that just sort of convenient that now you have the security experience to go forward and do that kind of stuff? No, I mean, I really enjoyed it.

I mean, it was probably one of the best experiences of my life, was working on that team, feeling like we were really making a difference in the security space and helping people fight this really atrocious problem that was was AdBurn Spyware. The nice thing about that product too was there was sort of this ongoing challenge. It was kind of like it was a product that fought back a little bit because the bad guys are constantly evolving. There was never a point where you could say, well, we're done with this. It's like, no, it's almost daily there was new stuff coming out that we had to evolve to meet.

It was an interesting challenge. And so very rewarding product to work on. Nice. And then I assume at some point that ran its course, moved on to other things? Yeah, I mean, the market started to change a bit, obviously.

The antivirus vendors, the traditional antivirus vendors kind of started adding that to their products, and Webroot was trying to pivot over more of a generalized antivirus product as well. And so things just kind of changed around there. And we had a change in control as well. There was some new venture capital had come in and invested in the company. And I just wasn't enjoying it quite as much as I had before.

So I had the opportunity to go work at another startup in Boulder that was being headed up by one of my former coworkers there at Webroot. And so I left in 2006, I guess, mid-2006. To join that startup. Yeah, from there, it was not necessarily a security-related startup. I mean, it was more of an aggregation platform, so it was a consumer-facing product still, but we were doing sort of email and social networking aggregation.

So basically trying to bring together in one UI all of your communications, if it's email, Facebook, Twitter, MySpace at the time was a big thing still, so bringing all that together in one UI. And, you know, I came in and kind of did that for a few years, led the team there, built the team from the ground up to work on that product. And it was a lot of fun, but just not really— ended up not really being a market for it. And I just ended up winding down. That was Jared Polis's company, actually.

Fuser was that one there. Place. So you and the governor are close then? I wouldn't say that, but I know him, but certainly don't feel comfortable calling him up on the phone and saying, hey, do me a favor. No, not like that at all.

So what led you to starting the current company that you have started now? So post-Fuser, I ended up working at Webbert again, actually. And I actually kind of had a different role there this time around and ended up sort of prototyping and releasing their first mobile security product. So that was around 2009. So this was kind of a market that hadn't really existed before that.

It was just starting to come into its own on Android, at least, that there was kind of a market for mobile security. 'Cause I initially started off kind of— they brought me back kind of more of like an R&D type role where I could just kind of pursue almost like whatever I thought might end up being a good product. And so I started looking at the mobile space, and I originally looked at iOS and kind of determined pretty quickly that there's not much to be done there. It's, you know, I'm sure there's vulnerabilities in the platform, but because it's so locked down, we can't do much to defend it either. And so went over and started looking at Android instead.

And you said, man, this is a hot mess. Android is kind of like, yeah, there's a lot of potential both to defend the platform but also to exploit the platform. Those 2 things kind of go hand in hand. So yeah, I kind of put together the first Android security application, which certainly wasn't the first in the industry or anything, but the first for Webroot. Kind of prototyped that and showed it to the executives.

They were kind of sold from the moment I demoed it and said, this is something we need to jump on and we want to productize this. They said, you want to build a team and productize this? I said, yeah, absolutely. I spent the next few years doing that in the mobile security space, which was an interesting new world. Interesting in the sense that it definitely was a market there, but not necessarily one people were willing to pay extra for.

Because mobile, I mean, people just kind of expect for things to be free or at least very low cost. Right, yeah. Is your app $0.99? No? OK, I don't want it then.

Right. So it ends up usually getting bundled in with these suites now. So I did that for a few years. And then it kind of ended up getting a little stagnated there towards the end of it. Got approached to come on board with a company called GFI and work on some of their products.

So I did that after Webroot, and then GFI, which became LogicNow while I was working there, kind of did some more MSP-focused type products, managed service provider type space.

But initially started off with kind of some wireless security research/development products that didn't end up really panning out, unfortunately. But, and then kind of moved on to building out more of the antivirus effort that they had integrated into their MSP remote management and monitoring platform that they had called Max. So worked on that for a while, and really I'd kind of gotten started getting the itch to start my own thing again while I was working there. And, you know, had a few ideas and here and there, and I kind of was just waiting for a good natural inflection point to do that. That kind of came in 2016 when LogicNow sold to SolarWinds.

That was a good exit point for me to go off and start what ended up becoming Enzoic, originally PasswordPing, then later Enzoic. What was the idea? What was the problem you were trying to solve? Well, actually, I had the idea in 2015, and like I said, I had a number of ideas, but this one I kind of really settled on as being the star. I just was seeing all of these data breaches, right?

I mean, we really started seeing these big mega breaches hitting— really, the first one was Adobe, which was earlier, but I started seeing, I think, at the time, LinkedIn and MySpace were kind of all right there around the same time. Same time, 2015, 2016, and started seeing all these, and it just kind of occurred to me that it would be really good if you could check your user credentials against some of this data that had been leaked. People just tend to reuse passwords all over the place. I think the statistics are between 40% and 50% of users are reusing passwords. So it's just, you know, I started researching it and figuring out, yeah, this is a problem.

There is such a thing as credential stuffing, where people are trying these things to find accounts where someone reused a password and are having success with it. There didn't really seem to be a product out there that really allowed people or allowed companies to check their users' credentials against a list of these known bad credentials. It's a pretty simple approach to it, but there just didn't seem to be anything out there that did that. That kind of was the crux of the idea. And what I wanted to pursue.

And so that was kind of just really the start of the idea. And initially I just kind of did passwords because they're simple and I could get it out. So just, you know, when someone goes to reset their password, hey, you should check that against a list of known bad passwords and make sure it's not in there. That's one good step of improving user password security. So our first little product that we built was just sort of this freeware password strength meter.

It was branded, so hopefully we were getting— hoping we'd get a little bit of visibility just from the branding of it. So just kind of put that out there, and it's like it had this open source library called ZXCVBN built into it as well, so it kind of did more like the algorithmic strength check coupled with a check against our API to see if a hash of the password the user just entered existed in our known list of or a list of known bad passwords. And so that's kind of where we started, and, you know, kind of put that out there like starting I think September of 2016, just kind of as our first little product. And from there, you know, kind of kept building the ability to check full credentials and, you know, come up with a way of really allowing that to be done in a secure fashion without necessarily having to pass us, you Last thing we wanted to do is somebody pass us plaintext credentials, obviously. So we spent a lot of time and a lot of effort trying to figure out not only how could we build a database where it wasn't just a giant database of cleartext credentials just sitting out there that's ripe for someone to come invade and steal, so we didn't want to do that, but also a way for people to securely pass their credentials to us in order for us to check them.

And also dealing with the amount of data that we had as well, which was at that point billions, already billions of records and growing daily at a very high pace. Now I'm sure it's multiple billions of credentials. Yeah, and then the flip side of it is the threat research side of it, which essentially consisted of building a very large suite of automated sniffers that just kind of go out there and look in all of the the right places for this data, bring it in, and then ingest it. And ingesting the data actually turned out to be a sticky problem because a lot of people trading this data or putting this data out there, these aren't computer scientists, and they have this like— it's the Wild West of crazy file formats. And there's not a, you know, a standard XML model of, you know, how to share breached credentials among the dark web?

Yeah, unfortunately not, no. And, you know, things like comma-delimited files except the delimiter is actually embedded in the data, so there's no field delimiters. Just crazy stuff like that. So building some sort of automated parser that could deal with all of that and recognize— email addresses obviously are easy to recognize, but things like plaintext passwords, if it is a bunch of data— usually there's a bunch of data in these files. It's not just username/password.

There's a bunch of other data like addresses or phone numbers. Numbers, dates of birth, things like that.

Recognize what's a password versus what's something else. And so that's kind of what we spent much of the first months of the company doing, was building this stuff. And it was a bootstrapped effort, so it was pretty much just me on the development side at the beginning. So yeah, it was a fun time. Then my partner, Kristen, she was kind of handling the marketing and sales angle initially, at least.

Then after about a year, we brought in another partner to kind of help us focus on that. I am curious on the technical side, you mentioned some of the technical challenges you had to overcome. I'm curious what some of the solutions are that you came up with to make sure you're not storing people's breach credentials in clear text, that you're not that I don't have to hand over my password to you and trust that you're doing something good with that and that sort of thing? Well, essentially it kind of all relies on hashes and salted hashes. So it's— when we index a new set of credentials into our database, what we're typically going to do is we're going to look and see, is this user already in, say, like a users table that we keep?

Keep, right? And we don't store like the plaintext user, we store like a hash of the user's email address or their username. We look and see if we've seen them before. If we haven't, we add them and we assign them a salt that they're going to be in our database. And then when we go to index their actual credentials, we're going to take the username and password that we found, and a lot of times it's not a plaintext password, it's a hash of a password, concatenate those together, and then we can calculate an Argon2 hash which Argon2 is one of the newer sort of memory-hard algorithms out there for hashing that's a little safer than some of the ones like bcrypt that are older.

And we're gonna calculate an Argon2 hash of those things together with that salt value. And then we have another table which is literally just credentials, and so just these credential hashes, and there's no linkage back to the user. So it's just a, just a essentially a giant list of Argon2 hash values without the salt. So you don't have the salt and you don't know what user it's associated with, so, you know, it's kind of like good luck cracking it, right? If you ever got a hold of this thing, this giant list of salted Argon2 hashes when you don't know what the salt value is, you don't know what user it's associated with, and you know it's got a username and password in there, but getting it out would be really hard.

So that, that goes a long way towards defending our database. From being used maliciously if somebody ever got it, got a hold of it. Obviously, we keep a lot of controls in place to make sure that database stays very, very secure. In terms of how people check a given set of credentials against it, it's kind of going in reverse. They're going to do that Argon2 calculation on the client side, and then they're going to take just the hash once again and pass us just the prefix of that hash.

So they'll pass us some some small number of bytes at the beginning of that hash and will return just a list of the potential matches. So they never pass us the full credentials hash. They're just passing just literally a small part of it. We'll give you back any of the candidates that we've got on that, and then you can decide locally whether there's any matches. And that's in a nutshell kind of how the Credentials API works.

So you mentioned that your first thing was the strength checker. Is your aim today— are you aiming at individual users, or are you aiming at, you know, people who are building applications to include this kind of functionality so that, you know, when someone's using their application, they're not putting in bad credentials? Are you plugging into, you know, company directories? What are people using this for? Yeah, so today our product offerings— we have a bit of a range.

So initially, yeah, when we started with the strength checker, that was very much targeted at hopefully developers, development teams who were just looking for a password strength checker out there, you know, might latch onto this as being a new cool way of doing this that's also more secure. Now, you know, now we've got a range of products. We've got the API product, which is sort of our base-level product that someone who's, you know, wants to integrate this into their environment at a custom level can use. So if they've got their own authentication system that they've built or their own application, custom application that they might want to use against this, the API is the way to go. And we've got various SDKs that wrap it and make it easier to use for various languages like JavaScript and Java and .NET and all that good stuff.

So that's kind of our base-level product. On top of that, we've also got some integrations. So we've got an Active Directory product. That provides this type of functionality for Active Directory. And so with this product, you know, we're basically going to sit on as an agent on your directory controllers, your DCs, and listen for a variety of things depending on what you want to configure.

So we can listen for password changes, and whenever a user changes the password, we can check it against our list of known bad passwords, and if it's, you know, on there, you have a variety of things you can do, but basically it's going to reject it by policy. It also will do things like monitor the user's existing passwords, so once they have a new password set, it'll monitor their current password to make sure it doesn't become compromised. And this kind of ties into some of the new NIST recommendations as well. NIST kind of recently changed their recommendations to this type of an approach. And then we also have the ability to monitor full credentials, so you can basically watch for a given user's credentials to go bad, not just that the password that they're using has become compromised, but are their full credentials actually leaked out there?

And then you've got remediation options of forcing the user to reset their password on next login, disabling the account, notifying them, notifying admins obviously whenever this kind of stuff happens. So the Active Directory product is another one of our key offerings. Then we've got some integrations in progress to some of the other IAM solutions out there, which is a natural place for us to be. We're working on integration into FordRock, for instance, which I think you had a VP from FordRock here on your last podcast. I don't know if you've met Mary or not, but she's in town, so maybe you guys could have coffee.

Yeah, we've actually talked to some folks over there. That's one of the integrations we've got going in progress. Always got a lot of work going with some of the IAM vendors trying to get some integrations going into those. Some of them we can— we're working on some integrations that we can do ourselves using what's publicly already available, but some of them it's kind of more of a business development type approach that we're having to take. I imagine when you started this, there were probably no other people that were trying to solve this.

That you knew of that were trying to solve this problem. I know of today at least one other, Have I Been Pwned, is doing something similar. I know Azure AD is trying to build in something directly into Azure AD to do— it's not quite exactly the same. I think it's basically just a password list that they're checking against, but something similar. Have you seen a lot of, I'll call it, competition starting to pop up around this problem?

Absolutely, yeah. I mean, apart from the ones you've mentioned, there's at least 2 other competitors in this space, maybe 3 or 4 depending on how you look at their products. But yeah, for sure there's other competitors that popped up, which in some ways is a good thing because it validates that there is some value in this type of approach. Product. And so yeah, we weren't aware of anyone at the time.

Have I Been Pwned actually was around at the time, but their solution was a little different in that they kind of just took these lists and indexed any emails. This is a different product. Yeah, I think when they first started, it was just kind of like, put your email in and we'll tell you if you've been pwned. Right, which I looked at and I said, that's really cool. I mean, it's a really cool idea.

I said, I wanted to extend it though so that you can actually say, make it more actionable because you can actually say, well, yeah, sure, I was exposed in that breach, or one of our users was exposed in this breach, but that could have been a password they haven't used for 10 years for all we know, so what are we going to do with that really? It's just kind of another data point, and you can use it to potentially score risk, but not necessarily actionable in and of itself. So that's why I wanted to include— make sure we had full credentials and full credential checks because we felt like that was just a much more actionable thing than No, it's like, no, your user with their current password has been exposed, so they are in danger, you are in danger, what have you.

Gotcha. And I assume since you are still running the company that things are going well, people are interested in the solution, you guys are growing? Yeah, things have gone quite well. We are up to about 10 full-time folks now. And we're about to add probably 11 and 12 within the next few months.

So we are growing pretty nicely. Like I say, we were bootstrapped from the beginning. We've really been profitable almost, well, since year 1, not since day 1, but since year 1. And, you know, kind of remained profitable ever since. And so this year is set to be our biggest ever in terms of revenue.

Nice. I'm pretty sure I remember you guys were selected at RSA for the Innovation Sandbox. Is that correct? We were, yes. How was that experience?

I didn't actually attend.

I got busy with other stuff here, but my partners did actually attend, and that was great for us. We talked to a lot of great folks and got to kind of really get our solution out there a little more. So a lot of great people from that conference. Nice. So what does the future hold?

This is— you came up with one really great idea, sort of narrow in focus, and it sounds like you're solving that pretty well. What's next? Really just kind of expanding the toehold we've got in this area and building the product out into more of a larger offering to help with authentication risks. Right now, as you mentioned, we are rather narrow. We can't operate standalone.

It's better when we're integrated into something, so pursuing integrations into all of these various IAM vendors' products is very, very high on our list for the near term.

Past that, growing the number of risk indicators that we can provide. There's some unique insights into the data that we get. Unique insights we get from this data and from when customers are using this data. And so by getting a little more information from customers, such as things like the source IP of the authentication request and whether it was actually successful on their side, we can start building out some other interesting data points behind the scenes. Like, we can potentially map out whether an IP appears to be part of a botnet that's conducting credential stuffing attacks is one obvious thing that we can kind of back out.

So that type of data, expanding our reach into that type of data and providing that data as additional signals for customers to use is one of our areas of focus at this point. And really just trying to become more of a valuable service for these risk-based authentication products, either internally built products that people have or potentially commercial off-the-shelf products they're already using. That they can add additional signals into. Yeah, you mentioned you guys have grown to 10. Are you looking for additional expansion?

Are you— am I gonna hear about some venture money that you're raising here in the future, or what's the plan there? Gonna keep going with the bootstrap model? What's the— at the moment, we are continuing to bootstrap. We don't really necessarily have any plans of taking outside capital at this point, but we are continuing to grow the team. Um, you know, as it makes sense.

And, and we will be definitely adding additional headcount over the next year. And so we'll see where it goes from here. But nice. Yeah. Um, well, we are getting close to being out of time.

Is there anything that you wanted to talk about that I didn't hit on? Um, I can't really think of anything else. Um, you know, I think it's been great talking to you. Thank you for having me. Awesome.

Well, thanks, Mike. Appreciate you being here. If people want to find out more about Enzoic, where should they go? www.enzoic.com. Perfect.

Well, thanks again, Mike. Appreciate the interview. This is Alex Wood, and this has been Colorado Equals Security. We will talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes