All episodes

Chris Brazdziunas, Chief Product Officer at ThreatX

Apple Podcasts Spotify SoundCloud

Chris Brazdziunas, Chief Product Officer at ThreatX is our feature interview this week. News from: Noblr, Bye Aerospace, DISH Networks, Ping Identity, Secure64, LogRhythm, ManagedMethods, Coalfire and a lot more!

Rest in Peace Rob Winter

Sad news about our friend and CISO of Boulder Community Health, Rob Winter. New triceratops found in Highlands Ranch. Fined by HOA for poor property maintenance. Nobl car insurance collides with Colorado. Bye Aerospace is bringing an electric plane to Colorado. Two new tech firms bring another 1500 jobs to Colorado. In-home tech support is a DISH best served to everyone. Ping partners with iovation. Secure64 Labs is now a thing. LogRhythm weighs in on Zero Trust now. ManagedMethods talks O365 security. And Coalfire introduces Slackor. No indications if Slackor burninates villages.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10026 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 122 for the week of— what is it this week? 24th, I think?

Yeah, June 24th. June 24th, 2019. Uh, Alex, uh, well, let's go ahead and jump into our housekeeping type stuff and then we can talk about some news. Go ahead. So, uh, we have a Slack channel in case you hadn't noticed.

We like to get together and have folks talk. So that Slack channel is out there. You can go to the website colorado-security.com, find a link to that, come and chat with nearly 1,000 people that are in there talking about security in Colorado. And while you're at colorado-security.com, you can join our mailing list. You can get the show notes delivered directly into your inbox each week with the description and links to all of the stories we talk about here on the podcast.

And if you want to do something else automatically, you can subscribe to get our podcast in your favorite podcast player. And then if you like what we're doing, you can rate us in whatever service that is. Let everyone else know that this is a great podcast. And if you want to do even more, we would love it. One favor you could do for us is if you would tell a friend, tell one of your coworkers or colleagues, anyone who you run into on the street about Colorado Equal Security.

The more listeners we get, the more fun we're having on this podcast. And if you really, really like what we're doing and want to support us financially, we do have a Patreon campaign that is ongoing. You can sign up for that. Depending on the level you sign up for, you'll get some cool swag and probably a shout out in the show. All right.

Well, we had— we got some really sad news yesterday. We did. A little bit downcast here at the beginning of the show. One of our good friends, Rob Winter, the CISO for Boulder Community Health, he passed away after a long— what's been 4 years, 5 years? A number of years battling against cancer.

Yeah, yeah, it really sad to hear that. Rob was a wonderful person, uh, did a lot for the community. Um, he was not only CISO for Boulder Community Health, but he also taught cybersecurity and, uh, just an all-around good person. Yeah, I, I think the last time I saw him was actually recording the podcast that we, that we had where we had him on the show. Yeah.

Um, you know, he used to make it to, to CISO dinners in town in the last and 6, 9 months or so, he hasn't been able to make it. I know he's, you know, he had a, a rough run there, obviously, uh, ending with his passing away on Saturday. Uh, we'll definitely miss him. I, I've already reached out to ask, you know, are there things the community can do to help? We don't have any answers for that yet, but for those of you who, uh, who are interested, uh, definitely join the Slack channel, or actually just send me a note if you want to, and as I find out, I will pass those things along.

Yeah, but definitely keep his family in your thoughts. A tough time for them and definitely a tough time for the Colorado security community. Yeah. So excuse us if this show is a little bit more somber than normal. We obviously are, are grieving the loss of our friend.

Yeah. All right. Next, we have a salary survey. And this, I think this is going to be the last week where we talk about it. We're planning to close the salary survey here at the end of June.

And this is a chance for all of the members of the Colorado security community to get together, share data points. If you share data points, you get the results of the survey and you can, you know, hopefully use that to help yourself decide maybe what focus within security you want to go after. You want to be an AppSec person, you want to be a network security person, and, and of course to help you with your own salary negotiations in the future. Exactly. All right, well, let's jump into the news.

Uh, first, you guys may have heard about this, but there was a dinosaur skeleton that was found in Highlands Ranch during a construction effort, and it has now been identified what that is. ET, is that, is that correct? No, it was not ET. I do remember that initially when they found it, they were thinking it might be a new dinosaur. Yeah, they were wrong.

They were not. It's a Triceratops. Yeah, I did not know that Triceratops was the most common type of dinosaur found in Colorado. I did not know that either. Yeah, that is interesting.

Yeah, I did just listen to a podcast yesterday, totally unrelated, about the fact that in the last few years searching for dinosaur skeletons has become big business and that private, like, basically Indiana Joneses will be— will go to ranchers, especially in like the Badlands, to look for T-Rexes. A T-Rex is worth multiple millions of dollars when they find one of those. But do they have hats and whips, Rob? I don't know how you could do this job without those things. Next, there is a new car insurance firm that is launching their app in Colorado.

Noble, and of course it is a tech company, so they had to leave off a letter. It's Noble with no E at the end. They are an app-based technology that tracks their customers' driving, and they reward good behavior behind the wheel with discounted insurance rates. I assume this means they punish bad behavior. Yeah, well, I guess that's possible.

It did not say that in the article. It did, it did talk about discounts, so I assume that there is some, you know, base level, which is probably higher than you would get with other car insurance. And then depending on what your driving habits are, you can lower that. It's set up to 51%. Well, so you might be wondering, well, how do they know if I'm driving well based on an app?

Well, and I'm here to tell you what the answer to that is. Number one, they look for smoothness or how hard a driver turns and brakes. Focus, whether the driver is texting behind the wheel. Road choice, are you going on safe roads or unsafe roads? And finally, the time of day when you drive.

Yeah, I think all, all things that make sense to look at as to who would be better to insure and who better not. And I think it also means maybe I won't use them for insurance.

Next, we have a story. You know, obviously there's been a significant change in the focus or in the perception around electric cars over the last, what, decade or so? Yeah. And now all of a sudden there is a shift to try and create and Uh, go to production with electric airplanes. And, and specifically, there's a Colorado company called Bye Aerospace that's working to bring an electric plane to market here in Colorado.

I thought this was a really interesting article, not just because of the fact that they are talking about electric planes, but I guess I hadn't really thought about the, the small-scale commercial, um, aerospace industry. And, you know, basically this is going to be potentially replacing some of the smaller Cessna planes that are out there. That people use for, I'll, I'll call it personal travel, but, you know, smaller, you know, 2, 4-seater kind of planes. A lot of 'em that are used for, for training purposes for people learning how to fly. And one of the things that they're talking about here is that they're, the workforce for pilots, there's a number that are gonna be going out of the industry and they're having potentially a hard time getting people into being pilots because of the cost.

Right. Well, so the baby boomer generation's all retiring, right? And there's a very large number of pilots and baby boomers, and like most other industries, but pilots is a big one. And then the training has become much more rigorous with, you know, significant safety concerns. So it's harder to get new pilots.

All that said, this new technology is going to significantly reduce the barrier of entry to being a pilot. So generally with a Cessna, they say the average cost per flight hour is about $110. And with this new, this new electric plane, it's going to be $23 per flight hour. That is a Pretty big savings. Yeah, I mean, that's like 75% savings or some craziness like that.

Wow. 80-ish. Some good math there, Rob. Yeah. And not only is it the ongoing cost, but the purchase price is lower too.

So a Cessna, maybe a relevant Cessna here, costs around $438,000. And they say that their 2-seat eFlyer is going to cost about $349,000. Yeah. Save up front, save for ongoing. Pretty cool.

You know, when you think about it too, they mentioned that it used to be— it took about 250 hours to be certified as a pilot. And now, as you mentioned, because of safety concerns and other things, you have to fly for 1,500 hours. Oh, wow. Yeah, way more. So that is a much more expensive endeavor.

So cheaper anything is a good thing. So are you ready to spend that $350,000 on an airplane, Alex? You know, maybe if we get a little bit more into the Patreon campaign, we can get that Colorado Eagle security plane. Colorado Equal Security e-flyer. Yeah.

Anyone who's listening who's like, that's a great idea. You come in with $1,000, I'll come with $1,000, and we'll just get another, you know, 350 people and we'll be there. Yeah, we'll be right there. Next, the Colorado Economic Development Commission announced that they are giving incentives to 2 tech companies looking to bring about 1,500 jobs to Denver. So these articles are— I'm never even sure if we want to talk about them because These articles specifically do not give the names of the companies.

They talk about the fact that this committee has agreed to give incentives to unnamed companies. Right. They give some, some hints in the article that maybe you could piece together who it is. One of these companies is a local tech-enabled services company that's going to grow by about 1,400 employees over the next— was it 8 or 9 years? Right.

Like that. The other is from out of state and would be bringing in somewhere in the same ballpark of jobs. Anyway, what's really cool is just to see this continued interest and pressure to bring in new companies and bring in new jobs to Colorado. And really, you know, while, while we already know that the job market here is really tight and there's not enough talent, it looks like it's really going to continue going forward. Yeah.

One down note. I don't know if you noticed it or not, Rob, but the last paragraph of this article said that previously the commission had approved $10 million in incentives for one called Project Beam. And that was for about an 800-worker tech center relocation. But that company decided to go to Arizona instead of here. Yeah, we didn't want that company anyway.

I didn't think so. But, you know, thought I'd mention these new ones who we don't know who they are. We definitely want. But that other one, we didn't know who it was. Screw those guys.

All right. Next, we have a story about Dish. Dish Networks is going to start offering in-home tech support for people regardless of who your television provider is. You don't have to be a Dish provider to use them. Um, really interesting stuff.

Yeah, this is focused on sort of the new wave of in-home electronics, you know, smart home devices, cameras, um, voice-enabled whatevers, um, all the different things that we are now putting in our homes that are internet connected. And so Dish has learned over the years with, you know, installing TVs and soundbars and obviously cable, uh, satellite TV, Um, that, uh, they have some expertise in this area, so they're starting a different company to be able to do this home electronic stuff. So installations for these standard things like your, your smart doorbell or your smart thermostat are going to cost $99.99. They, they also sell the devices themselves. They sell things like Google Nest, Ring, Linksys, Roku, and they are launching in a number of cities including Denver on— well, they've already launched on June 17th.

They're also in Atlanta, Dallas, Houston, Kansas City, Los Angeles, New York, Sacramento, Salt Lake City, San Francisco, and St. Louis. Wow, sounds good. Um, sign me up. All right, next time you need to have some tech support done, there you go. Uh, next, a quick note.

Uh, we had talked to Red Rocks Community College a couple weeks back about their team that was going to Singapore to compete in a competition there, and it looks like they have finished in the bronze status. So remember, they were, they were representing the United States, right? Yeah, they were the only team from the US. So we are number 3. Congratulations to us.

Congratulations to the Red Rocks Community College team. Um, very cool stuff. I, I'm so happy to hear that the local boy makes good— local team makes good is probably a better way to put that. Um, and hopefully, you know, next year we can get back out there again. Yeah, and once they are back from that trip, we may be able to get some more information as well.

All right, next we have a press release from Ping Identity. They partnered with Iovation to provide user and device risk as a part of the ongoing Ping Identity focus on zero trust. That is very exciting. What does that exactly mean, Rob? Well, what Iovation does is it sets up a profile for risk for the devices that are connecting.

So, so as a part of Ping authenticating and providing access into systems, they can take, they can look at what's the device risk and say, yes, I trust this device because it's got a low risk, or no, we're not going to trust it, or we're going to make them do it, you know, we're going to only give them access to low sensitive information based on a high risk score. Ah, good stuff. Uh, next, Secure64 has announced that they are launching a research division called Secure64 Labs. So this effort is being driven out of their Fort Collins headquarters, and they're going to be looking at things such as the implications of 5G, privacy issues, artificial intelligence, and how that all relates to security around DNS. Really cool.

I'm looking forward to the many research papers we should expect to see coming out of there that we won't understand, right? These guys get really technical there at Secure64. Next, we have another Zero Trust article. This time it's written by LogRhythm, and our friend James Carder, the CISO over at LogRhythm, wrote a story really talking about how LogRhythm sees Zero Trust and kind of what their model is. I thought this was an interesting complement to the one— was it last week or two?

I think it was last week that Ping Identity had written. Yeah, kind of talking about the framework for Zero Trust. Yeah, and this is also talking a little bit about what LogRhythm has done internally to implement Zero Trust for their own enterprise. Next, there's a blog from Manage Methods talking about secure— or excuse me, Office 365 and secure email issues and settings. Manage Methods is a cloud access security broker, and one of the areas that they focus on is Office 365.

And just, they give some tips about things that you should do to secure your Office 365 environment and how they can help. Yeah, they go through 4 different risky areas for there, and then they give some specific examples of how you can manage those risks. Uh, we also have a, a blog post from Coalfire this week. Um, they are introducing a new technology called Slackor, or Slacker, Slackor. Are you a Slackor?

Um, I don't know. What is a Slackor, Alex? Oh, that's a great question, Rob. So, uh, Slackor is a command and control persistence application that they developed, you know, for pen testing. Basically, you know, it can be installed as an implant and then provide command and control access through Slack as that communication channel.

Awesome. So this blog post, and I assume this technology was created by Esteban Rodriguez, and we've actually had 2 or 3 other blog posts of his on the show. I think he might be winning the references on Call to Equal Security tally from Qualifier. That is very true. He does put out a lot of good, really technical blogs.

Well done, Esteban. Uh, and finally, another reminder, uh, the APEX Awards, which is the Colorado Technology Association's annual awards ceremony, is currently accepting nominations for all of their different awards: CIO of the Year, Company of the Year, Project of the Year, and most specifically here, Chief Information Security Officer of the Year. Yeah, I think this is a great thing. Uh, we've had some good winners in the past. We want to get a lot of nominations this year.

So that we can have a good pool of candidates. So go out and nominate people. And if you're not interested in nominating people, go talk to your HR or public relations people and ask them to nominate, uh, your CISO or, or someone else. All right. That is it for the news.

Moving over to our Slack message of the week. Big thanks to Andre Gaeta. Andre has been loyally sponsoring this segment of the show for a long time. Um, we, we appreciate it, Andre. And of course, if anyone's interested in talking email security, give Andre a holler.

Uh, this week we want to, uh, Wanna give the Slack message of the week to Matt Parks. Matt is a, is a friend of ours, works over at Kaiser Permanente, and he specifically was sharing the results that his, that the Kaiser Permanente Boss of the SOC team finished, was it 5th, first in Colorado and 5th nationally? So what is Boss of the SOC? Yeah, so this was sort of, I mean, I guess I'll call it a capture the flag competition. It's a, it's a competition that Uh, that, that, uh, they put out to go out there and, and look for different pieces of data, use, uh, use the Splunk tools and other things like that as part of a competition.

It's specific to Splunk, right? Yeah, specific to Splunk. Yeah, using, using Splunk to, to be able to, you know, look for threats within your, your defensive environment. Yep. And so if you are a, a SOC person, then this is right up your alley.

And there were a number of teams that were here in Colorado that competed We had some talk about that on the Slack channel this week, and it sounds like the Kaiser team was the best. Awesome. Congratulations to those guys, and congratulations to Matt Parks, who will get to pick one item from the Colorado Equal Security swag store. Hopefully he picks, you know, a coffee mug or something like that that they can, you know, pass around to all the different people in the SOC team down there that helped with this. All right, let's go ahead and jump over to our events for the week.

We actually have an event for a new group, Alex. This, uh, This is a group called the Emerging Technology Thought Leaders, and they're really— they present on a variety of topics that are really impacting the way technology is going to be changing and our jobs in technology in the future. But are all of those topics emerging? Well, more or less. Oh, okay.

Okay. Yes or no is another way to say that. So the— there is an event from them on the 25th called RPA Took My Job. What is RPA? I think it's robotic process automation, Rob.

Well done. Robotic process automation might be taking your job, so what do you do about it? Uh, that's a good question. I guess you'll have to show up to that event. Uh, also on the 25th, the GDPR meetup group is doing a case study of how to use data privacy as a competitive advantage.

On the 26th, ISC² Pikes Peak is doing their June chapter meeting. Also on the 26th, SecureSet is doing a women's only beginner's intro to capture the flag. On the 28th, ISC2 is doing their Secure Summit Denver. This is the big ISC2 event in Denver for the year. On the 1st of July, SecureSet is doing a capture the flag cybersecurity hackathon.

And that gets us through the next 2 weeks. Uh, I don't know, you know, next week we'll be together though, right before 4th of July. The week after that, we haven't figured out our schedule quite yet. Yeah, so we'll see how that goes. All right, jumping over to jobs.

Uh, we have a couple of jobs at Ping. I actually have, I think I mentioned last week, 3 open positions right now in product security. Uh, if you are an application developer and you're looking to get your foot in the door in security, this would be a great opportunity for you. We're looking for junior product security engineers, we're looking for full product security engineers, and I'm also looking for a manager of product security. So if you like product security, they should come talk to you.

I'm your guy. All right, KPMG is looking for a manager of IT security compliance. This actually looked like it might be an internal position at KPMG. It did, yeah, as opposed to consulting. Uh, there's a couple of jobs at Kaiser Permanente.

They're hiring an IT consultant, principal risk portfolio management, and they're hiring a senior associate of cyber risk defense. Very different type jobs. Yeah. That second one, my guess is, um, works with that SOC team that was, you know, one of the bosses of the SOC. Might work, might, might work for Matt Parks.

That's possible. So it sounds like a good job there. Uh, Xero is looking for a security operations analyst. Google is hiring a technical risk solutions consultant. That's here in Colorado.

Yeah. And that actually looks also like an, internal job, like internal technology risk consulting. Johns Manville is looking for a Senior Data Security Administrator. Cognizant is hiring a Network and Security Administrator. And Virtual Armor is looking for a Regional Sales Director.

So if you want to sell security products, check that one out. All right. Well, that takes us to the end of the newscast. This week we have— I'm going to try and say her name. I'm sorry, Chris, if I do not say it right.

Is it Chris Brazdziunas? I think it's Brazdziunas. Okay, close enough. I think we probably both said that wrong. Well, we— this is the last in our series of interviews by Mary Writz, uh, sitting down with women in security here in Colorado.

So I'm excited to hear her conversation with Chris. Yeah, Chris was— she was the product officer or something, VP of product at LogRhythm for years, and now she's at ThreatX. Yeah, now she's the chief product officer for ThreatX. Yeah, and then, uh, One last thing. Thanks again to Mary for doing this series of interviews.

It's been really interesting, and hopefully we hear more of those in the future. If there's anyone else out there who wants to get you know throw their hat in the ring and help us do interviews around the area, we would love it. Reach out to us at info@colorado-security.com, and we'll chat with you about it there. Awesome. All right.

Well, that's it for this week. We'll talk to you guys again next week. Thanks, Rob. Hi, this is Merlin Namath, Director of Security at Red Robin. Welcome to Colorado.

Colorado Equals Security. For Colorado security professionals, by Colorado security people.

Hey, this is Mary Writz with Colorado Equals Security. I'm here with Kris Brazdziunas. Kris is the Chief Product Officer for ThreatX, a local startup here in Colorado. She had a really interesting career building security products, and Kris, I'd love to hear just your background. How'd you get started building products, and specifically in the cybersecurity space?

Sounds good, Mary. So, you know, it's kind of a long-winded story. My career really started in product development. I was a software engineer, software engineer in telecom back in the '90s, and building large enterprise carrier-based solutions. At one point, got into interesting products like wireless data over amps or cellular for a point application of policemen being able to type in license plate numbers to see if that license plate is valid.

Right? So, you know, very small data type of applications. Okay. And, you know, over the years in product development, I also developed the desire to understand products and understand, you know, why is roadmap set up the way it is? You know, what's driving it?

Because I want to build products that actually matter. And that's why I got into the product product management space. And so over the years, I moved in from telecom to wireless to VoIP and then to enterprise unified communications solutions for hedge trading and financial services. And over my years in the early 2000s, I started running into security, and frankly, I thought this is a pain in the butt. You know, it's in the way.

It's in the way of innovation, right? And I almost got frustrated with it when someone would ask, Can you encrypt this data stream? I said, why would we do that? Put a perimeter around it and call it good, right? And protect the network infrastructure.

And I felt that pretty strongly. So, you know, the start of my career was more about building great products and building scalable products, and it was really not a lot about security. I came into a product development opportunity where all of a sudden I'm building trader voice communication infrastructure for financial services and big financial institutions, Deutsche Bank, Goldman Sachs. And as we're building these solutions, I find out there's kind of this process before you actually can put that product into that investment firm. You had to go through a complete security assessment.

Right, makes sense. Right, it's hedge funds, right? And I was like, wow, I guess I can't ignore this stuff anymore. But yet it was still getting, getting pretty hard. But, you know, so that's where I started to gain a lot more respect and started to really thinking about application security.

And then from there, probably around 2011, being in product development and also just loving to build new solutions, I kind of recognized it was time to make a switch in my domain. And ironically, I fall into cybersecurity, and I joined a company called LogRhythm, which was a, you know, as we know, a Colorado company that we all love dearly. Yeah. And is a big player in the SIEM market. Right.

And it was there that I had the opportunity of working with some pretty talented folks in the security space, some of the founders over there, as well as the LogRhythm Labs people. And as I was, you know, developing product for product for them from an engineering perspective and growing their engineering team, I also got the chance to work in the product management area. Yeah. And that's how I just got more and more into understanding the cybersecurity domain, which then finally led me towards where I'm at right now, which is a company called ThreatX, which is a startup, an emerging startup in the application security space today. Nice, nice.

And so Actually, so I ran ArcSight product maybe at the same time that you were running LogRhythm, and I was always impressed with what you guys were doing. Oh, that's so cool. Okay. So, I was trying to bring some product management influence into the podcast and thinking into the podcast. And what do you think is a big challenge about building products in the security space?

That's unique to security because you've been in multiple disciplines? Yeah, it's a good question. I think from security, things have changed from what's important. If you look today and what's unique about security is that, you know, we have a very small group of enterprise security staff who have a really large job. Yeah, right.

And so when you think about products and as I've talked to a lot of customers over the years, I kind of learned to understand that Really, one of the most important things to do is get a product that works, that works reasonably well, and it has minimal friction, right? It's easy to deploy. You don't need a 100-page book or document to figure out how to use it, right? And you can gain value out of it relatively easily. And those things are actually probably more important than building that, that next additional feature.

In fact, a lot of large enterprises I talked to at LogRhythm would say that. And so that's one of the big challenges today is making that product that just works and, you know, you can gain value from it from an enterprise perspective pretty quickly. Yeah. Do you feel like— sometimes I feel like— so I get pressure for that too, and sometimes I feel like that limits me from being innovative because I'm working on simplicity, UI, intuitive product, and I can't work on that next cool big flashy feature. Yeah, I think that there's some truth to that, though I think you can make operational ease to be slick.

Yeah. Right? You can make a deployment experience to be pretty slick. And so, while I would tend to agree from, you know, some of those topics are more boring, I think they can be very interesting. I think what it does stop, and I'll use one of the buzzwords we use today, is machine learning.

Right? If I talk to you, being in a startup right now, investors are like, so tell me, what machine learning algorithms are you using here? And I'm like, why don't you ask me about how our product works and how it really detects adversarial attacks? Yeah. Right?

Yeah. And that's where, you know, you have to help our investors and help the business understand and put them back in line saying, This is what the customers are asking for. Here's what we're hearing from our customers. Here's what we're hearing from some of the partners in the security community are some of the pain points. I think, you know, so really from that perspective, I think it's important to listen to your constituents and then, you know, really take a look at where you think you're going to grow your business the most and focus in there.

Right. Well, what— so you're working in web application firewall space, which is new. What cool things are happening in that space right now? Yeah, so this is a pretty cool space in and of itself. The WAF space historically has been much like the SIEM space.

It hasn't been the one that's been most liked, and if anything, it's been probably an area of frustration for enterprise security teams. Why is that? Well, operationally pretty complex, you know, a lot of operational activity that is required to tune the solution, tune the solution when the app changes, tune solution when the attack spec landscape changes and overall just never really being able to get it right. Yeah. And, and, um, and so, and that this is a space that probably hasn't had as much innovation as other areas of security like EDR, identity, um, etc.

And so, you know, what's going on in this space now is I think there's becoming increasingly more recognition that app security is important. Yeah, right. I think if you look at, you know, Forrester just released some data that I actually saw through a webinar that indicated the top 2 reasons enterprises get compromised. One is due to software vulnerabilities, and the second is due to poorly engineered web applications. And so as a result, this is why I think there's becoming— there's an opportunity here now to solve a problem that hasn't been solved well.

And that's what's going on in web application security today, and particularly at ThreatX. Yeah. And so you guys are— you're a SaaS and you're inline, so you get to see all of the malicious activity going to all these sites. Have you seen anything cool? Yeah, you know, this is the thing that has been pretty cool in my first 3 months here at ThreatX.

As you and I talked kind of before we started this webcast, you know, we both being in the SIEM market, and really being in operations, right? And, and some markets and, and security operations is cool, yeah, but seeing the, seeing the attacks is something else. So, you know, ThreatX has, you know, a good number of customers. Same token, we're not Akamai, right? But, you know, we can, we can during the week see attacks and we'll see, you know, credential stuffing attacks.

And I'm like, why in the world are are attackers doing this? Well, you start to think about this and you say, well, maybe they're trying to figure out which user IDs are valid, and then I guess they're going to sell them on the dark web for a bit more. I have no idea. Yeah, but we're seeing these kind of things. Another thing I saw recently, um, and this was just over a week ago, there's an e-commerce infrastructure called Magento.

Now, something that I don't have a lot of familiarity with based on my background, But, you know, there was a vulnerability that was recently released that says that an unauthenticated user could still perform a SQL injection. I mean, SQL injection, we're 10 years into this, 15 years into this, and we're still looking after these things. So this vulnerability comes out and same day and across the next days, our customers who have Magento sites, which we know because we can fingerprint them, They're getting attacked. Of course, our solution's protecting them, but we're like, wow, it's fast. It's fast.

So vulnerability comes out there, you know, maybe a proof of concept data, um, is also out there, and all of a sudden people are trying it. Yeah. So I think that's pretty cool. Yeah. So, so that makes— it makes what I do and what we do as ThreatX real.

It's like, wow, there's a lot of need for application protection. And we can really help a lot of businesses keep their e-commerce sites or other sites more available. That's pretty cool. Yeah. I think about— so as products move into managed services space or SaaS space, there is some advantage to one person getting to see all the traffic and start to put together trends of what's happening across multiple customers versus everybody looking at their own stuff and wondering what's unusual.

Yeah, exactly. Cross-customer analytics is a capability of our products, a differentiated capability of our product and Even with our size customer base, we see it. Yeah, and that is certainly true. And then also from a services perspective, since we do see it, we're able to at least apply, you know, some of that consultative type of service to our clients as well, which is, I think, helpful when you have an enterprise security organization that oftentimes is made up of IT personnel, network security-focused folks who probably didn't come from the app dev space. Right.

How has it been moving from— so LogRhythm, pretty large product. Of course, it went— it was a startup and then it went into private equity, and now you're back in startup again. I guess, what's the difference? What's the difference between those 2 environments and building products? Yeah, you know, I think first of all, when you're in a larger company, you know, first at LogRhythm, I guess I went through a couple of transitions at LogRhythm.

First, we were probably 130 people when I joined. Oh, wow. And at that time in 2011, security, I don't think, was as strong of a focus for enterprises as much as it was a few years later. And in fact, I mean, there were times when I first started there and I talked to a support guy and he says, well, this customer is complaining because the data is backed up and They're trying to— is there a way that they can get a month's worth of data in faster into the SIEM? And I'm like, well, why did this happen?

And then the support guy says, well, because they had it turned off and they just wanted to turn it on before the auditor came. And I'm like, oh my gosh, really? And so I came from a space, I came from a time where security— we're trying to convince enterprises that security was important. To then I got into a place, you know, say 2014, 2015, when the Target breach happened, you know, security became, you know, something important to enterprises. They're actually investing in it.

You know, we're measuring the percent of IT that's going to security, which is great. And then it was a lot, in terms of my role, it was a lot about understanding the customer and spending a lot of time, you know, talking to our customers and talking to our partners. Understanding what those needs are and then trying to triangulate those needs into the product. Going into a startup here, that base of people and constituents that I have to talk to are a lot less. Oh yeah.

So, you know, you really have to do a lot more. You have to leverage a lot of different contacts that you have that could maybe be a bigger spokesman for certain areas like the partner community. You know, leveraging industry analysts, leveraging meetup groups, right, and things like that. So I'm having to find ways to increase the number of people I talk to to help understand what's really going on in the industry because my pulse and my sample is a lot less, right? So that's one of the big differences.

The other probably big difference is I spend a lot of time in the weeds. Yeah, you know, at LogRhythm, I didn't spend a lot of time really understanding a specific attack or really taking the time to understand a specific vulnerability, let alone writing it out and then issuing it to our, you know, issuing a notice to our customers. And that's something I do today. Yeah. Being in a smaller startup where we have to wear multiple hats.

And I think that's pretty cool. Yeah. Yeah, that is cool. I've— yeah, it seems to me when you're in a startup, you get a chance to innovate a lot more. Your investment profile is higher so you can move faster.

But on the flip side, you don't have that name recognition and all of the contacts that you can reach out to quite so easily. Yeah, exactly. And so what you have to rely on is your network and the relationships of people that you built. And so that's a lot of what I do today. Yeah, that's pretty cool.

So what are your favorite products in security today? Yeah, so that's a good question. So, you know, this is— I don't necessarily have a favorite product, Mary, but I will tell you right now what I think What right now is important to me and I think is going to change the industry, and that's what I'm excited about, is the MITRE ATT&CK framework. Oh yeah. Are you familiar with that?

Yeah, so it's kind of like the kill chain except it's not linear and more comprehensive. Yeah, yeah. I mean, I would say that, you know, it's, it's the kill chain, um, that's been redeveloped based upon a bunch of data that MITRE had, and MITRE taking a bunch of data and then saying How do we map this to a set of behaviors that then— atomic different behaviors that then we can look for independently to see if there's an attack going on? Yeah. And they found a way to do it, right?

So they have their kill chain states, which is effectively a set of tactics. Yep. You know, kill chain has 7. The MITRE ATT&CK framework, I think, has 11. I think it's 11.

And then And then it has a set of techniques which are effectively TTPs or behaviors, like things like brute force, things like the use of PowerShell, right? Things like the use of encryption or the use of a connection proxy to obscure where you're coming from. And so these are different types of TTPs or behaviors that then you could— that attacks in history have been put together that then form the entire attack or the attack lifecycle. And so, you know, what I like about it is that it's really grounded in a lot of detail, and it's grounded in detail that shows, that talks about, you know, what each TTP is, talks about how to detect it, talks about how to mitigate it, talks about what type of telemetry What type of ways can you use to gain telemetry into it? And then what attacks used it?

And so, you know, that grounding has kind of allowed, you know, enterprises now to say, well, let's see how many of these techniques can we actually see, observe, and detect in our enterprise security architecture. Right. And I think that's pretty cool. Yeah, it's a nice way to measure products and how much coverage they give. Yeah, exactly.

So you can kind of take a product and say, how much coverage does it give? And what's probably even— what even excites me more is that there's actually vendors who are supporting it and adopting it. Right. Really, this is more of a product towards traditional enterprise security and around, you know, attacks around hosts. And so the EDR community has embraced it.

And so MITRE actually did an evaluation last fall of a number of different EDR vendors, and those results are published. Yeah. So it's public. Yeah. And so the vendor community is embracing it to some degree.

It looks like the enterprises are embracing it. And now we may have potentially common vocabulary to talk about enterprise protection. Right. So I think that in general, like I said, and that's what makes me excited about it because I'm like, finally something's going to work. Yeah.

Like we all can talk to each other and really understand what our security products do. Right. Yes. It's funny you say that because often running product, you're told, hey, go check out what your competitors are doing so that you can compare. And I tell you what, you go to these websites or you'll go to RSA and I cannot figure out what anybody actually actually does because it just says machine learning, blockchain, automation.

Yeah, exactly, exactly. It becomes really, really hard to understand that. Here we got this framework where these atomic units all have good definitions. Yeah. And kind of at ThreatX, we're utilizing ironically that similar approach where we're looking for atomic behaviors, and if we see enough of them, we're going to dynamically block that stream.

Yeah. So we're not kind of a normal rule-based type of WAF. We're looking for TTPs, and once we've seen enough TTPs and they've accumulated enough risk, you're going to get blocked. Right. And so it's very similar in approach.

And so that's probably what motivated me also to think why I'm so excited about ThreatX as well. Right, right. So how have you found— so machine learning, always a buzzword and always pressure to get value out of that. I have mixed feelings about machine learning. I've looked into it and I really like the potential because we are now able to collect lots of data, computation power is really high to process it, and yet, how has it worked for you building it into your products?

What have you found effective, not effective when it comes to machine learning? Because I know there's a lot of other kinds of math that work really well, but machine learning is the thing everyone likes to hear about right now. Oh, absolutely. And I think machine learning has a place, right? I think there's a couple of different things.

So first of all, We know that the business market uses analytics for trending. Yeah. Okay. So, if we have— so, anything that involves trending, you want to know, you know, for if I take web applications, okay, what does normal traffic look like? Well, assuming that you can figure out what normal traffic is, you could trend and say, yeah, this is probably what normal traffic is going to look like up until the app changes.

So, you can use trending, I think, in certain areas of security, to be able to predict, well, this looks similar to this other thing. The other place I think that's more commonly used is anomaly detection. This looks different. Yeah. Okay, well, that's great, it's an anomaly, but as we all know, is it security relevant or not?

And that's where other types of math I think come in. Correlative capabilities are incredibly important to bring in information about, well, not only is this an anomaly, but, you know, these type of TTPs were also observed. Yeah. All right. And so I think now we have a higher chance and higher degree of probability that this is probably, you know, bad behavior.

Right. So I think it's important to be correlative, corroborative, you know, trending, computational, whatever it costs, advanced algebra. Yeah, it all works. Yeah. The important thing is really to, you know, be able to put it all together and then really— and then with the result being something you're highly confident of.

Yeah. And then second, something that a security analyst can actually investigate and understand. So, it can't be a black box. Right. Well, I found it's interesting you say that because I found, you know, you'll play around with clustering, like nth-degree clustering, and you can find out that something's mathematically weird, but you have no idea why.

You just can't tune the dials on clustering the way you can with a KDE model. So, a lot of the user behaviors tend toward that kernel density estimation because at least you can tune those dials and you could explain why it was weird. It's not easy to, but much easier because you've predefined all of the models underneath. But I, yeah, I completely agree. Telling someone that something is statistically weird is just not helpful right now in our industry.

No. And I think, I think security teams kind of discount it. They're like, that's great. It says anomaly, but I don't know why. So I'm going to go over to the data.

Yeah. And that's where we're going to say something less complex but comprehensible is more important and is more valuable to those organizations today. Yeah, the best ones I've seen are really use case driven. So I'm thinking about a particular kind of attack and I'm thinking about the math that would best find that, and then I specifically dial it in and look for it versus the black box approach. Yeah, and I think we're starting to see a realization in the market, especially with the growth and kind of the excitement around the MITRE ATT&CK framework.

I think people are starting to get more grounded into reality again, and maybe we're off the hype cycle of machine learning and we use it in the right spots. Yeah, because it does have a lot of potential, for sure. I also wanted to ask you, speaking of innovation and machine learning and the buzzwords, how do you balance what your customers want and what the business needs are? That's a big challenge with product management. Is trying to get that really in the right balance.

Yeah, it's true. And, you know, a big part of that comes from, I would say, an important thing that a lot of us take for granted. It's called listening. You know, as the product manager and the product leader, we're not the ones who are really making the decision. We're fostering the decision.

And what's really important, and especially in security today, is to make sure you understand those different stakeholders. Some of those stakeholders are going to be internally, support organization, your professional services organization, your engineering teams, and then your sales teams, of course. And then there's those external ones, your partners, and then your customers and your prospects. And I think what's important is to really listen, really seek to understand what are organizations really trying to do? What's their motivation?

What's their pain points? And make sure that we can communicate them in an unfiltered manner. All right. And get them on the table. And then I think when the business stakeholders come in and see that, I think it becomes fairly evident in terms of where we need to wait.

And today we do need to wait more on the customer and the market because security is more about getting security to work well versus getting something new and cool. Yeah. And I think, I think that fad's kind of passed us. Yeah, I definitely see the same thing. I see the shift toward customer success.

So not just trying to sell a product, but actually getting the customer to use it and get value out of it and check in with them regularly. So I've seen that shift in product development, the move toward customer success. Exactly. And then more importantly is how do— how does our market buy? Our market today largely buys by word of mouth.

Yeah. So I think that actually motivates the right behavior for us vendors. Yeah. Right. Is that we need to have those, those, you know, flaming customer advocates because the security community is small and people all talk to each other.

If we look at the Colorado Security Slack channel, you know, what do you think about X comes up once in a while. Totally. Yeah. As a product insider, a bunch of people listening are not on the vendor side, they're on the customer side. How would you advise them when selecting products?

That's another good question. First of all, do your intelligence in terms of talking to people, but remember your environment always could be different. The other thing is sometimes people don't want to bust relationships, and so you really don't know every— you may not be hearing everything you need to hear about that product. So do your testing. Yeah, I think that's important, especially for any product that is going to be more difficult for you to pull out if it doesn't work out.

So I think, you know, first of all is, is do that. Yeah, the, the second of all, um, thing I would do is, is make sure the product's easy. You know, honestly, today we shouldn't be seeing 100-page documents. Right? Your security team— a manual that's a PhD in that product.

Yeah, exactly. I mean, there's, you know, I can see, you know, understanding some of the vocabulary that a vendor utilizes and maybe a need to have some documentation around that, but user interfaces should be intuitive, right? You should be able to discover things. It should be obvious. And if they're not, then ask yourself, Is this going to be something that is going to be frictionless for my organizations?

Yeah. And maybe it won't be perfect. And if it isn't, test out the vendor and give them feedback. Yeah. And see if they're really listening.

Yeah. Ask them to repeat, what did I just say? Right? Ask them to repeat what, you know, what you as an enterprise is important to you. And ask them, you know, to really provide you some level of commitment.

I mean, you know, dates are hard to commit to, but, you know, I think salespeople and all of us know that if you're going to commit to something, that's something that is important in relationships to honor. And hopefully they'll do that. If they don't, I'd walk away. Yeah, and I guess a little secret is there's this thing called revenue recognition, where as a product leader, if we've promised a feature to you by a date, we can't recognize the revenue of the sale until we give it to you. So, you know, put that word revenue recognition, just sort of file that away somewhere.

Yeah, that's actually a good point. That's something that you and I don't want to hear about. Yeah, for sure. We go to great lengths to avoid it. And I think probably the other thing is make sure your product is really future-proof in terms of and supports the enterprise topology and that you have planned for the next 5 years.

A lot of that is cloud. Products that are cloud-native are going to be probably— they could be more appropriate for the environment than ones that are not. Really think about what type of product that is going to be important to you, and a lot of times it could be that cloud-native one.

Okay, so let's do a time check. We got a couple minutes. I wanted to get— so we rarely get to talk to female Chief Product Officers, so this is exciting. I wanted to get your tips on your leadership tips. So you lead big teams.

Any advice for those of us that are leading teams? Any words of advice to us? Oh, Mary, that's an interesting question. Another one. You're hitting me up today.

Um, yeah, I think, you know, first of all is spend the time and do the hiring right. Yeah, yeah, okay. You got to do the hiring right because if you— you've got to have people that kind of have that growth mindset, right, who can learn and adapt. And then, and probably the other thing is, you know, is to make sure that you've got really good relationships within the teams. Yeah, when people like each other they tend to work well together.

It's true. Yep. Right. So I think, you know, people don't often think about that, but when I hire somebody, the first thing I think about for the first month is relationship. They can say, okay, you know, I pretty much give them a, you know, a little bit of latitude, but I know what my aim is, is make sure I really understand them and, and they trust me and, and I show trust of them.

I hire them. I, you know, I'm gonna assume I hired a great person. Yeah. So that's a, that's a big part of it. And after that, I think another big part of what we need to be doing is trust.

You know, a lot of things aren't going to be happening the way we had thought they should happen, but in the end, things will probably work out. So if you've done the right hiring, and there's no reason not to trust right away. Yeah, right. I like that. Right.

And so that's kind of a big part of what I believe in from a leadership perspective, and if anything, listen more. Yeah, I like that too. So there you go. Cool. And lastly, your thoughts on diversity and how you include that in your teams?

You know, it's a topic that honestly is not one— it's not one of my favorite ones, right? Being someone who's a woman in leadership, you know, you get asked this question and you're like, I don't get it why I'm different. Yeah. And over the years, I've started to understand something, and maybe it's a blind spot for me, and that is one of the challenges I think we have in creating diverse environments is the fact that we like to hire people like us. Yeah, well, I mean, if you're talking about relationships and getting along, yeah, you tend to pick somebody that's going to get along.

Exactly. Oh, that's awesome. I can go out and have a beer with this person, right? Well, I think the way we really need to be thinking about hiring is what are the skills that we have on the team and what are the skills that we need? And usually those skills are the ones, or soft skills or technical skills, that are gapping.

And then, and recognize that and put that part of your hiring process. And then second, really encourage your recruitment process or hiring process to recruit diverse candidates, right? In the end, hire the best person, right? But at least get diverse candidates in there so you can see how those gaps and the needs that you have to fill the team could be met by the various different types of candidates out there, right? So there's my thought.

I love it. Well, Chris, it's been a pleasure to be with you on the Colorado Equal Security Podcast. Any last thoughts before I close out? No, nothing for me other than I'm waiting for spring and excited to play some golf and If you're a golfer. You know, I'm not a golfer, but I noticed you ski or you snowboard, right?

Yeah, I do. So I'm a big skier, so we could do that together. Oh, there you go. All right, well, the golfing, I'd have to like drive the cart for you. That's— oh, that's all I'm good for.

All right, well, I'll go anywhere you can ski unless there's just a lot of trees. I'm gonna be terrified, so you'll have to— I'll do it, but just know in the end I'm gonna be a little scared all along the way. No problem. I, I'll take you right up to the double blacks. There you go.

All right, you're on. All right, thanks everybody, talk to you later. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes