All episodes

Mark Logan, CEO at LogRhythm

Apple Podcasts Spotify SoundCloud

Mark Logan, new CEO of LogRhythm is our feature interview this week. News from: Frontier Airlines, Amazon, Regis University, Coalfire, Optiv, Zvelo, Ping Identity and a lot more!

Denver is affordable. Seriously - we have data

At least relatively affordable. I mean, we’re no El Paso. Frontier is going green (and maybe public too). Amazon is building one big solar panel. Regis University is hit by a ransomware attack. Coalfire has AWS ATO news. Optiv, Ping, Zvelo and Swimlane have blogs this week.

For LogRhythm jobs here in Colorado: https://www.builtincolorado.com/company/logrhythm/jobs

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11019 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 131 for the week of September 2nd, 2019. Alex, it's Labor Day.

It is, Robb. I, I I'm really tired. We've been laboring really hard putting this podcast together. I'm glad that there is a long weekend that I can relax, right, and enjoy the fruits of my labor. And depending on when you're listening, maybe your long weekend is over.

Maybe you're right in the middle of it. I hope you're right in the middle of it. That would be awesome. You're relaxed. You're, you know, maybe two drinks in, and you got two more to go.

Who knows? Wear sunscreen. Don't want to get sunburned. I don't want to get sunburned, Alex. I heard you know.

Uh, this last week there was some big news about a, uh, a dental software, dental record software. It got hit and you had a personal experience with this attack, right? Yeah, it was pretty funny. My son had an orthodontist appointment. We walked in, he had his checkup, and then we had to schedule a follow-up and they're like, sorry, we can't schedule your follow-up now because our computers are down.

And I thought, oh, well, you know, that kind of sucks for them, but you know, we'll, we'll do it later. And then I got to work and I read this story. It said, hey, ransomware has taken down a big dental service provider. And so all these dental offices are out. So I thought, oh, hey, not a strange coincidence.

Maybe my orthodontist has been ransomwared. Yeah. So there was actually a story on Krebs about that. So I saw the story, but I didn't, I didn't know. Obviously, it's nice to have a little, you know, close to home.

I like that. Well, I don't know if it's nice to have it close to home, but it's, it is good to be in the know, I guess. It's good to be in the know. Hey, let's move over and talk about some housekeeping. We have a Slack channel.

We have, Well over 1,000 members of the Slack channel, very vibrant conversations on there. If you're looking to get to know people in the area, uh, if you want to come rant, if you want to come say nice stuff, there's channels for all those things. Uh, go out to colorado-security.com to find the link to join the Slack channel. If you don't like that much interaction with people, then we do have a mailing list. The mailing list sends out one email a week, just one.

Uh, you get the show notes in your mail. Every time we release a new episode, go to colorado-security.com, sign up for the mailing list there to get the show notes. Also, if you like the show and you want to help us out, we'd love it if you would go subscribe on your favorite listener so this gets delivered every week and rate us out there, especially out on iTunes. That would be a helpful way for us to get found by more people. We are also on a couple of different players.

Alex is committed to getting us signed up for Stitcher. I have committed to it. We will get it done, Robb. We're going to get Stitcher out there coming up soon. So we'd love it if you'd review us wherever you are.

Let us know. Also, we would love it if you told a friend about Colorado Equal Security and all the wonderful things that are happening. The podcast, the website, the event calendar, the Slack channel. Just, you know, blurt it all out to them. Just random strangers.

It doesn't even have to be a friend. And I can imagine there's one person saying, I've told everyone I know. I've already signed up for the mailing list. I've already subscribed and rated the podcast. What more can I do to help?

Robb, what more can you do? Well, they could sign up for our Patreon. We'd love it if you want to financially support us. That money in the Patreon goes directly into the podcast. None of it goes into our very thin wallets.

It goes right back into the community. So we'd love it if you'd help support. Sweet. Those are our announcements. Let's get on with the news.

So this week, number one story is that the Denver— there's a story kind of comparing the cost of living of being in Denver versus, what was it, 75 other major cities across the US? Yeah. So Denver came in at number 20, which is, I think, a good thing. The average monthly expenses were $1,869. And 97 cents, as compared to number 1, San Francisco, which was over $4,000 or something like that.

So that's like rent for an apartment, your utilities, your internet, gasoline, and food. So if I, you know, my math is right, $1,800 a month, you're talking, you know what, like $22,000 a year-ish, something like that. Yeah, I am thinking that the expenses really are talking about like a just out of college person that doesn't have a whole lot of expenses. You know, they say one-bedroom apartment and things like that. So it's, you know, for expenses for you, Robb, it's going to be a little bit more.

Whoa, big spender. Your lavish lifestyle. Slow down. I also will say it was interesting to see that Colorado Springs was number 50 on the list. So just down the road, there is a place that is that much cheaper.

So if you don't mind an extra hour commute to work, right, that's the place for you. Exactly. We do have a lot of listeners in the Springs and we love you guys and we're glad that you guys can live for less. Money than we can up here. If you really want to go budget, El Paso was last on the list with the least cost.

And if you're thinking, you know, I really want to blow all my money every month, San Francisco was your place, right? I think it was like $4,500 a month. It was a lot. Yeah. And I think it was $4,500 or $4,600.

And like 3 quarters of that was rent. Right. Right. And yes, and it says one bedroom, but that probably is not true. You know, one bedroom there is— you're sharing one bedroom.

Right. All right. Moving, moving along here. We have a story about from the Frontier CEO talking about their green campaign. So Frontier Airlines is the local, the local budget airline, really the only local Denver airline, I think.

Right. And they actually in 2017 had announced a potential IPO. They released their S-1 a couple of years later. They haven't actually gone public, but CEO talked a little bit about that possibility. No, Robb, I'm surprised you know what an S-1 is.

They talked a lot about the fact that The Frontier is driving to become a very green airline. So they're, they're thinking that the IPO could help position them to be the greenest airline. That sounds pretty fun. Yeah. In addition to that, there's a study that was commissioned by DIA and done by Intervistus, and it said that Frontier drove nearly $10 billion in total economic activity.

Is that million or billion? Billion with a B. Billion. Billion. That's a lot of money.

Sorry if we just blew your ears out there, everyone. Next, we have a story about Amazon. They— there's an Amazon warehouse in Colorado that is installing Colorado's largest rooftop solar system. Yeah. So there's a new Amazon warehouse that's opening in I-25, sort of north of town, Thornton-ish.

And it is installing 6 megawatts of electric power on top of the roof. Is that 1.2 gigawatts? It is very close to 1.2 gigawatts. You'd need plutonium to do that, wouldn't you? No, don't you know solar is much cleaner than plutonium and competitive price-wise now, Robb?

So for anyone who has not watched Back to the Future in the last 30 years or so, that's what I'm referring to. I don't think that they will have a flux capacitor at the Amazon warehouse. But you know, actually, I bet that you can order a replica one, maybe even a real one from Amazon. So they may have a whole stockpile there. I bet if you Google or if you Amazon search flex capacitor, there are a lot of interesting things that come up.

Yeah. So anyway, congratulations to Amazon, to their new warehouse and the amount of power that they're going to be generating there. And speaking of cyberattacks hitting close to home, one of our very own universities in town, one of the ones that actually has a master's in cybersecurity, was just recently hit by a, by a cyberattack. Yeah. We don't have a whole lot of details on exactly what happened.

We do know that there were many systems, basically all systems that were down at Regis for a bit. They are starting to come back up at this point. Maybe by the time you listen to this, everything will be back to normal. But, you know, it's hard for the university because this is when classes are starting, students are coming back, and systems are offline for things like that tell you what books you need and class schedules and that sort of stuff. So very impactful.

And certainly, you know, it looks like it's been quite a while, over like a week now, right? Um, where they've had inter— some systems that weren't running. Uh, they got some stuff back up, but quite a few things still down as of, as of the time we're recording this. Not a lot of details on exactly what happened, but we will try and get to the bottom of that. Uh, next, Coalfire has been selected as a partner within ATO on AWS APN program.

So what are all those acronyms? Well, uh, ATO, Authorization to Operate, or Approval to Operate, which is, uh, federal government's basically saying, yeah, you're certified to run. So basically what this means is that Uh, Coalfire is going to be one of the 24 companies allowed to help federal companies, uh, move into AWS and basically deploy their own infrastructure there in a compliant fashion. That is pretty cool for them. Uh, congratulations to Coalfire for that.

And only 24, and the federal government is very big. That's true. It's a lot of money there. There is a lot of money there. Lots of people moving to the cloud also.

Cha-ching, cha-ching. Uh, next we have a blog from Optiv talking about a Retro risk appetite. Alex, what in the world is a retro risk appetite? Well, I'm not exactly sure, but, uh, the blog post is talking a lot about, about tech debt, you know, legacy systems, legacy software, uh, things that you need to do to try and get rid of some of that retro stuff that you have in your environment and reduce those risks. I think basically they're talking about the fact that, you know, by not making a change, you're, you are accepting risk, um, or all these systems as they get older.

They specifically talk about Windows XP as a great example. Of a system that, you know, does not get better with age, that, that, uh, you know, because it's deployed so widely, is really looked at as a really good way to get into places. Uh, speaking of risk, Robb, you know what has a lot of risk to it? Open APIs on the internet. Uh, next, there's a blog post from Ping Identity talking about, uh, trusting API tokens.

Uh, that's true, and, and this is a blog post that I was just, just kind of paging through a little bit ago. Uh, what it really looks to me like is they're talking about the need to lock down your access beyond just saying, do you have the token or do you not have the token? And, you know, for those of us who, you know, maybe aren't as familiar with APIs, if you, if you're doing token-based access, it's really no better than a static password. And in some ways it's worse because it's gonna be stored in so many different places. As soon as it gets transferred somewhere, you know, it could be out in the open.

You know, a lot of folks will put those tokens out in, you know, GitHub on accident and, you know, Now it becomes public. So this blog post is just talking about the need to start looking for contextual access or contextual data around the access to let you know, is this a high-risk transaction? What else have they been doing? Um, you know, have they— have we— are we seeing weird behavior from this connection? And use that as a way to turn things off.

Those seems like, uh, things that are good, good ideas, Robb. And of course, Ping offers a solution that does just exactly that. What? I don't believe it. Speaking of blog posts that are sales pitches, we have one from Zavilo today as well, right?

We do. There is some interesting information in here. They talk about, well, it's about single-use phishing URLs and the need to detect malicious URLs faster. So one of the interesting things is talking about how the length, the lifetime of phishing URLs has changed over the years. So the stats that they give is back in 2016, You know, you were okay taking about 15 hours, uh, to, to figure out that a, a URL was bad because, you know, that's how long it took for bad guys to spin up sites, start using them, so on and so forth.

And now it's down, uh, to seconds. You know, these single-use URLs can get spun up as someone comes to, uh, to check something out. And strangely enough, Zivilo has a, a way to help you prevent that. So, uh, it is really interesting to know that how quickly these things are coming up and down. It's also nice to know that we have a local company that helps with that.

Good for them. Exactly. Our final blog post news story of the week is a blog post from Swimlane talking about vulnerability management, and I don't think this directly addresses something that they sell. Yeah, well, I think they help with things. They could help with parts of the vulnerability management.

They could automate parts of your vulnerability management program, but really they're talking about the key components of a vulnerability management program. Being identification of, uh, the hardware and software asset owner and identification policies related to scanning, reporting, and remediation of vulnerabilities. So those are sort of the 3 big buckets of things you do need to do to have a successful vulnerability management. I think anyone who's looking to create or improve their own vulnerability management program might want to take a look at this blog post and see if it's applicable to you. That's it for news.

That means we're gonna check out the Slack message of the week. We should say thanks to Andre Gaeta. We should. Andre is a sponsor of this every week, uh, very loyal, uh, faithful sponsor. Thanks, Andre, for doing that.

Um, this week, uh, I picked Chris Abbey as our winner, um, because Chris Abbey referred to— he, he had a— he started a, a thread actually on LinkedIn, but then brought it over to Slack, um, talking about that Webroot article that you and Brian talked about last week. And you guys made a— you guys gave it a little bit of a hard time around the VPN question. Uh, it was, it was much more brutally treated in the Slack channel. Yeah. There, there was a lot of discussion around that this week in the Slack channel.

Um, especially some people in education saying, you know, how it is not necessarily, it would not go exactly the way that they talked about in the blog post. Yeah. So really interesting conversation. Thanks to Chris for bringing that up. I don't think that there's necessarily a right answer to the debate of, you know, Is it better to talk about password guidance that gives complex passwords and asks you to reset it?

What do they say, like every 45 days or something like that? Or is it better to, or is it better to, you know, go the other way? I think that, you know, you can argue both ways. I think it was a really good conversation, though. Yeah, for sure.

So thanks again to Andre for sponsoring that. The— with the Slack message of the week, Chris will get a cool $25 piece of swag from the Colorado Equal Security Store. Awesome. Let's go ahead and jump over to our events. A reminder, we have an event calendar on our website.

At colorado-security.com. You can go check out what's going on. Man, it is— it— I know it didn't feel like it was calm during the summer, but it is really picking up here now that people are getting back to school. Most definitely. Uh, first on the list, uh, on September 3rd through 5th, ISSA Colorado Springs is doing their Peak Cyber event.

That's, that's 3 days. Hopefully a good event. I'm looking forward to hearing how that goes. On the 4th, Secureset is doing one of their capture the flag events, and this is for all levels. So So you can come if you're a beginner or if you're kind of a badass.

On the 5th, Splunk is doing their First Thursday at Topgolf. So if you want to hit golf balls and talk about Splunk, check that out. And if you are not a Splunk person, if you're an Elastic person, Elastic is doing a SIEM hands-on workshop on the 5th. So really you get to pick between those 2 competitive technologies. Good times.

Also on the 5th, there is an event about following the evolution from Deming, TPS, Lean, DevOps, and DevOps. DevSecOps. Really, I like, I like that, going from deming all the way to current DevSecOps and figure out what that means. And then finally, on the 5th, Interface Denver is happening. This is one of those vendor conferences downtown.

I'm sure if you haven't got your email for a free pass, it wouldn't be too hard to get one. On the 6th, in Colorado Springs, they're doing their Cybersecurity First Friday social and mixer. On the 7th, which is a Saturday, ISSA Denver is doing one of their CISSP seminars. This is on Domains 5, which is Identity and Access Management. Near and dear to my heart, and Domain 8, Software Development Security.

On the 9th, SecureSet is doing a Hacking 101 Intro to Wi-Fi. I think it's Wi-Fi, actually. It actually— I apologize, it is Wi-Fi. Uh, on the 10th and 11th, ISSA Denver is doing their September chapter meetings. On the 14th, there is a CISSP seminar, and this is, uh, for Domains 2, Asset Security, and 4, Communication and Network Security.

And finally, on the 14th of September, ISSA Colorado Springs is doing a Security+ prep exam, so our prep session. So there, there's, they're gonna do 3 weeks in a row, the 14th, 21st, and 28th. Um, they're super cheap. Um, this is a really good way for you to get the, the Security+. We've already talked about the CISSP, so if you're not doing that, maybe this is the right one for you.

And Robb, since you said finally, that means that we are done with events finally, and we can move over to jobs. And speaking of jobs, uh, there is a job opening at Ping Identity. We have a GRC analyst role. Maybe today we have it open. I don't know.

But as of the time of recording, it's open. We're having some great conversations right now, though. If you're still interested in talking to Ping about a GRC analyst role, apply online. You can send me a note on the Slack channel, and I'll give you whatever info I can. St. Anthony's is looking for a director of security engineering.

I assuming— I assume that means the hospital. I assume so too. It's in Englewood. That's where the hospital is. Hitachi Vantara.

Is looking for a Director of Information Security Operations. Cool. So Cadence is looking for a Lead Cybersecurity Engineer. Arrow is looking for a Cloud Security Senior Risk Analyst. So if you want to analyze the senior risks in the cloud, this is working for Rishi over there.

Rishi's a good guy. I think you'd like— might work— might like working on his team. He's a good guy. You should check that one out. Uh, Bank of America is looking for a Third-Party Assessment Manager.

Johns Manville is hiring a Cybersecurity Engineer. Red Canary is looking for a senior incident handler, and that job, like many Red Canary jobs, is remote. And this was posted by, uh, by Chris Abbey, our Slack message of the week winner. So this is kind of a double dip week for Chris. He's on fire.

And finally, Netizen is hiring a senior cybersecurity engineer, also remote. Sweet, lots of remote jobs. I know there's people on the Slack channel who, who don't, you know, it's not convenient for them to drive into town. These might be the jobs for you. I don't want that job in Boulder because I live in Parker.

I don't want that job in In Parker because I live in Boulder. Yeah, we get a few of those. Well, that is it for the news this week, Alex. I finally— we finally pinned down LogRhythm's brand new CEO, Mark Logan. And after security dragged me off, he was still willing to be interviewed.

So we have him on the show this week. I think the key question, Robb, is are they pressing charges? And you won't find that out until you've listened to the entire interview. Very good. All right.

Well, enjoy your holidays, everybody, and we'll talk to you again next week. Thanks, Robb. This is Artie Wilkowsky, CISO at Dish Network. Welcome to Colorado Equal Security, the podcast for Colorado security professionals by Colorado security professionals. All right, this is Robb Reck with Colorado Equal Security, and today I have the pleasure of sitting in the LogRhythm headquarters staring at a beautiful view of the mountains with the new CEO, Mark Logan.

Mark, I'm really glad to have you here, and I'm excited to learn today about your own background, you know, what made you interested in coming to LogRhythm and coming to Colorado. But before I want to talk about that, I want to hear about your passion for hockey and the fact that you're playing hockey as an executive and, you know, not a 20-year-old man. How did this start and tell me about what you do? Well, so thanks. It's a lot of fun.

I have a lot of fun with it. I wouldn't characterize myself as NHL quality, but I have a lot of fun with it. I grew up in the greater Boston area, so there's a big hockey culture there. And I grew up playing pond hockey and, and just really got bitten by the bug. And I've continued to play on various teams throughout my whole career.

And the beauty of it, Robb, is it doesn't really interfere with family time because you play at these crazy hours. Because you can't get rink time during the normal hours. Exactly. So it's 9, 10, 11 o'clock, and it keeps you relatively fit. Except for when you break things.

Except for when you break things, which, you know, knock on wood, I haven't done that too often. No, you've been pretty, pretty healthy through it? A couple of nicks and scrapes here and there. Yeah, I know it seems like everyone who I know who plays hockey is, like, really serious about playing hockey. Yeah.

You're not, like, partway into it. You could characterize myself as very serious, and I just enjoy it. It's a lot of fun. We have a lot of laughs. So do you still play in a team right now?

Well, so I'm in the process of moving here to Boulder, so I'm in mid-move, I guess I would characterize it as. And, uh, so I think I might, I might find— there's a couple rinks right around the corner, so nice. Yeah, I might bring the gear over. So you're going to be looking, looking for a new team in town. So if there's anyone recruiting for— what position is your— I'm a centerman.

You're center, okay. So if anyone needs a center here in the Boulder area, give me a call, please. Mark a call and set some low expectations though. I like it. Okay, well, let's talk a little bit about your background.

So sure, you know, I think you said you're from Boston, Correct. Recently, but originally, are you also from Boston? I am. Yeah. Yeah.

So no more. So right now I'm moving from Washington, D.C. area, but I grew up in the Boston area. I got into technology very early on in my career. So way back when I worked for some great companies like Hewlett-Packard, big public companies like Sybase and Informix. So that's where I would say I got a lot of the grounding and foundation building of my career.

So I know a lot of chief executives often come up the sales route. Is that true for you as well? It's very true. Yes. Yeah.

So I came up through the sales route in the early days and then to sales management. And one of the real meaningful pivot points for me was myself and 4 of my friends and colleagues from Sybase went off and co-founded a CRM company. Really? So we did that in Charlotte, North Carolina. Okay.

So I moved from Boston and it, it was a really fun, meaningful time of my career. So, so I got into management. There were 5 of us to start. We went through rounds of venture financing. We grew to about 350 people right during the dot-com bubble.

So we rode it up, rode it down a little bit too, but then we ended up selling to a Denver-based firm called JD Edwards. So was this in the late '90s then you're talking about? It was, yes, exactly, exactly. And what was the company you started? So it's called YouCentric, and it was very tech technically focused CRM solutions.

So the landscape was littered with the likes of Siebel, Vantiv, Oram, Scopus, Janna Systems, SalesLogix. I mean, there was literally dozens. We were a little different in that we were one of the first internet-based solutions back when it wasn't as common as it obviously is today. Were you SaaS-based? Is that what you mean by internet-based?

We were Java-based, and then we leveraged— I'll get a little technical on you Enterprise JavaBeans. It was an object-oriented environment. So we were known as the most flexible CRM solution, and we were able to close some very big accounts like Federal Express and Bank of America. So we had some nice wins. It was a really great experience.

What was your role there in that company? So I ran all global sales, global marketing, global alliances. Maybe we might call it a chief revenue officer these days. You could say that. I don't know if that exists title existed back then.

But yeah, yeah. And then upon being acquired by JD Edwards, so I was one of the few of the co-founders that stayed on and ended up running 2 divisions at JDE. Great company. Yeah. So, so I can kind of continue the leadership path there.

Edwards got acquired by PeopleSoft. You may be familiar with PeopleSoft. And I ran a large division there as well. And, and then when they were being they were embroiled in a hostile takeover from Oracle, and I did decide I didn't want to stick around for all of that, and I was recruited for my first CEO job. Awesome.

So, and that was a company— that's what brought me up to the DC area. So it was in, in the Northern Virginia area. And what kind of industry or position was this? So that was also enterprise software, and the niche space was called telecom expense management. Management.

So we would, we would integrate with all of the large carriers, and we would pull billing information and invoice information. And we would work with very large enterprise customers that were spending $50, $100, $200, $500 million on telecommunications all in. Yeah. And these were typically Fortune 500, Fortune 1000 companies. We would reconcile all of their monthly billings, and we would deliver back a series of expense reconciliations and we'd find savings.

And it ended up being— we were a very profitable business to do business with. So our customers would end up saving literally millions of dollars upon using our solution. Easy to show the ROI for. Very easy to show the ROI. Those are great.

So that was a company that it was a perpetual on-prem business that I inherited, I took over. And over time, we evolved to 100% SaaS, 100% recurring revenue, and if I think of the timeframe, 2004-ish, we made the move to SaaS before it was an obvious move. Wow, 2004 going to SaaS, that is early, that's fantastic. Yeah, so we started to, we moved to a single-tenant environment, then we moved to a multi-tenant environment, and it was a great run, so we grew, it was a very hyper-growth business. Went through a series of acquisitions.

We acquired some of our like companies and competitors, and that helped some of the growth. So it was both organic and inorganic growth. Yeah. So I'd love to kind of pull out nuggets for the listeners who are thinking about their own careers. You know, as you kind of developed over your career from sales, sales leadership, being a GM, you know, what did— maybe just, you know, talk about these 4 different roles, right?

Sales to sales leadership, sales leadership to GM, to GM to CEO. Like, what are the— what's the difference for you in terms of success in each of those positions? Well, so I think on the sales leadership side, it's— you have to be very direct. It's very numbers-oriented. Yeah.

And I've always enjoyed that there's a scorecard at the end of the quarter. You know how you did. It's not— there's not an indirect correlation. There's a direct correlation. Did we hit our number?

Did we not? Are we growing? Are we not? So So I think the successful sales managers, they have to have a keen focus on the numbers. I also found that it's equally important to be able to lead, to impart wisdom, to be able to recruit well, and to motivate your sales teams.

So I've had the good fortune of being able to recruit pretty well and to motivate teams. Teams pretty well. But then as you get into the GM role, which I did at JD Edwards, I sort of did at Eucentric as well, now it's not just top line. Now you've got to be focused on bottom line. So to be a little more specific about that, it's not just about closing any business at any cost.

You need profitable business and you need to have a great profitable relationship with your customer. You need to always be focused on delivering value to your customer. Changes from a transactional to a more holistic view, is that a fair way of putting it? I think that's a very fair way of putting it, yes, exactly. As a general manager, one of your key metrics is profitability, gross margins, and things of that nature.

Obviously, then there's the collaboration with your colleagues, so you go from being a salesperson really focused on the numbers to a leader focused on what's best for the business. So collaboration with finance becomes critical. I've had the good fortune of partnering with great CFOs throughout my career. So having that interaction and that collaboration is really important. Sure.

Understanding the larger strategic win results of the business, not just of your own discipline. When I think of a GM role, and I definitely want to hear your take about the difference between that and CEO, I think of a GM as being similar to a COO in a lot of ways, that they're going to have— they're going to be responsible for the internal focus more than— with customers as well, but not so much like investor relations and trying to be the face of an organization as much as you would as a CEO. Is that where you see the difference? I think you've really captured it well. It's probably— boy, let's pick a percentage.

It's probably 65%, 70% of a CEO's role because you've got a business unit. I'll go back to my JD Edwards general management position. We had a budget. We had profit goals. We actually did have developments, so we had product management and development teams.

Teams rolling up. We had release schedules. We had tight collaboration with finance, as I mentioned before. But no, a lot of those external aspects were not under the purview of that GM role, and I think oftentimes they are not. Maybe a second nuance to it is you're part of a larger organization, but you're less focused on your sister divisions.

You know, you're, you're the other pieces of the business. As a CEO, obviously, you're doing all sorts of qualitative decisions on where do I put resources? Yeah. On which line of business gets a disproportionate share of our resources? Sure.

So as you, as you went from GM to CEO, what was the— what would you say was the biggest adjustment you needed to make to be successful in the new role? Well, an area that I had only a modest amount of experience in was fundraising. Yeah. So at the Eucentric days, we did do a couple of venture-backed rounds, one with Technology Crossover Ventures, TCV, one with ABS Capital. So, but, but I was an arm's length away as the CRO.

Once you're the CEO, you spend a little bit more time on that than perhaps I was really familiar with. Yeah. So So that was, that was one area that you had to get pretty good at pretty fast. Yeah, I had Andre, the CEO of Ping, say to me one time early on that, you know, the job of CEO and founder in his case was, you know, finding the right talent and the right funding and doing it at scale over and over and over again because it wasn't a one-time deal, right? And I think, you know, there's also running the business, but I think running the business can be handled by a lot of people.

But really it's getting the right people on the bus and getting the right funding was his, was his take on it. Indeed, indeed. Now, not to skip too far ahead, Robb, but in the current scenario with Thoma Bravo, yeah, a lot of that is, is sorted out already. Yeah, it's taken care of. So, so in the PE world versus the VC world, there's a lot of benefits to the PE world because we don't have to look out for other funding sources.

And with their goodness gracious, $36 billion in assets under management. They're in good shape in that area. Let me set a little context for anyone listening who doesn't know what we're talking about. So before we even talk about Thoma Bravo, let's talk about LogRhythm. So LogRhythm is one of the biggest couple of security vendors in Colorado, and you guys have been around here for, what, 15 years?

Not quite 15 years. Sounds right. Something in that ballpark. 15 and change, yeah. Headquartered in Boulder and built here and really grown here in a very significant way.

And was it last year, Thoma Bravo? I think it was about last year. It's almost exactly a year ago. Yeah, Thoma Bravo acquired LogRhythm from the venture capital fund, correct, that had it. Thoma Bravo is a big private equity firm.

So maybe you could just talk to me about like, what does a change like that mean to a company like LogRhythm? So, so from my perspective, and it wasn't there back a year ago. For your listeners, I've been on now for 5 weeks. This is the end of my 5th week, so I'm a bit of a rookie. So I took you down as quickly as I could.

Mm-hmm. I appreciate that. I appreciate that. So the— so I'll make a few statements about the quality of investor that we have here. So Thoma Bravo has been around for, boy, decades, many, many years, and they are considered really best in class, probably number one in the PE world, maybe number 2 when it comes to investing in— okay, you can go with that.

Of course, I work for them, Robb. So no, but in all seriousness, in the enterprise software space, they are traditionally delivering at the highest levels. Then when you look at not just enterprise software as an umbrella statement, specifically in cybersecurity software, that's where they also set themselves apart. And I'll give you a few case studies. So the folks at SailPoint, they were acquired by Thoma Bravo, I want to say 3.5, 4 years ago.

TB put significant investment in the company, in the technology and so forth, and then they went public and they've been a great success story ever since. 2 weeks ago, same story, not a cybersecurity company, but Dynatrace up in Boston. They were acquired by Thoma Bravo 3.5 years ago, put a lot of money in the technology, and they went public at just under $7 billion 2 weeks ago. So it's a, it's a really interesting playbook that they, they run, and the result is a lot of growth, a lot of success. Yeah, and they also own Centrify, which is another IAM company.

Thoma Bravo is the owner there, and I think there's a couple others that they own that security space too that I off the top of my head can't remember. For those listening who don't know why I said the little second best comment, the company I work for is owned by Vista Equity Partners, which is, you know, a competitor to Thoma Bravo, very similar. Aha, I see. Very similar model. So I'm just getting, you know.

And we work for them, I love them. You work for them so well, Robb. I know, right? But that's a very good point, yeah, those are probably the closest comparison companies. Pretty comparable companies.

So, you know, I don't wanna spend too much time on the, the structure of the company, I want to talk about what you guys are doing. You guys have been one of the leaders in the SIEM market for a decade, whatever it is, quite a while. What are you focusing on now? Why— obviously bringing in a new CEO means significant change. What is it that you're coming in here to accomplish?

Sure, sure. There's a couple things, and I might even give a little bit of background. The cybersecurity software space and our piece of it, it's the SIEM space, is growing at a very good trajectory. So that's number one. And so we're in a great market.

And one of the reasons I've joined is because of the strength of this market. Number two, we are very, very well positioned. So if you look at almost any industry analyst that covers our space, Forrester has us as the number one ranked company in the SIEM part of cybersecurity. The Gartner Group, they do their Magic Quadrant You've heard of this. We're up and to the right and we're up in the leaders quadrant competing with these companies that are many times our size.

So we're right next to IBM, we're right next to Splunk, so we're right next to some real heavy hitters. And from a feature functionality and time in the market and domain expertise perspective, there's nobody better. So I don't have to change anything there. We just have to keep doing what we're doing. So now to answer your direct question, some of the key changes.

I referenced how our friends at Thoma Bravo tend to find great technology companies, double down on investing in their R&D, and then grow— growth and scale comes from that. So our priority number one is, you know, we're in the process now of finalizing a very large investment in our R&D.

The focus of that will be on delivering a more cloud-centric solution, a more continued— we have some very large customers, but investing in our scalability, investing in cloud-centricity, and investing in feature functionality so we continue that lead that I referenced.

I know you and I have talked a little bit. I've been a customer in the past. The beginning of LogRhythm was a physical appliance that you bought and you put in your rack, you screwed it in yourself. You guys moved to a virtual appliance over time, and I know you guys currently have at least a single cloud offering. Maybe talk to me about where you are today and how it's going to be different in the future.

I'm glad you brought that up, Robb. We want to be flexible and we want to answer to market demand and market choices. We want to give the market more choices. Point number 1 there is we are now separating our hardware and software so that those companies that want to put their software— to acquire software directly from us, we've now separated. In fact, some of the separation is just taking place here and now over the last couple of weeks.

We want to be able to flex to their needs of putting our software to manage security on their premises or on the cloud or in a hybrid environment. As I'm sure you're pretty familiar with this space, many, many enterprises don't want to put data up on the cloud, and many do. Some view cloud as a way to more easily administer if the vendor, i.e., LogRhythm, takes care of that administration. I don't have to buy servers. I don't have to buy databases, I don't have to have DBAs, you take care of it all, I will compensate you for that, put it in the cloud, we can check that box.

We announced a solution called LR Cloud, LogRhythm Cloud, about 6 months ago I believe it was, and we are now delivering on that to our customers. Is that a single tenant, you know, you have your own basic implementation of the LogRhythm solution in the cloud, or is it a multi-tenant SaaS type of thing? So today it is a single-tenant offering, and really customers, whether we get to multi-tenant, which we will, or not, there's going to be very little impact to our customers. It helps us to be able to deliver in a multi-tenant environment because it's more profitable for us. Scale.

Yeah, we can scale. Exactly, exactly. And indirectly, we'll be able to then price the product even more competitively, but the early-on feedback is we're very competitively priced. One of the things that was very important to our product delivery team was mirroring the feature functionality in the cloud to our on-prem solutions. As far as I know, we are the only competitive offering in our entire market that has that exact same feature functionality in the cloud as we have on-prem.

I assume that's got to mean that you're using your software the same software that you use on-prem, you're using in the cloud, right? We are. You haven't created a separate solution for the cloud that's like its own thing. I'll make a general statement that that is correct. That makes sense.

Otherwise, feature parity's just about impossible, right? It just takes forever to create a decade-old product as a multi-tenant immediately. Exactly, exactly. So with this large, soon-to-be, late in this quarter investment in our R&D. We're going to take a lot of that and just double down and increase, get to multi-tenancy, increase scalability to even greater levels to be able to take on even more capacity.

As you well know, the big data world, data is growing at an exponential rate. We want to continue to be there to be able to manage the largest global customers in the world. So there's got to be a trade-off here. I'm trying to think of the right way to put this. The single-tenant version of your software in the cloud, you can get feature parity for what you have on-prem.

When you get to a multi-tenant environment, the configuration customization of the solution has to go down in order to be a multi-tenant solution, generally. Maybe I'm wrong, but that's generally what my experience has been just about everywhere. You just don't get as many bells and whistles if you're using a multi-tenant solution. Solution. So is your intention that in the long run there's going to be, you know, 4 different ways to do it— physical appliance, virtual appliance, single-tenant cloud environment, multi-tenant cloud environment— or do you plan to kind of centralize on one or more of those options?

Well, so the less code bases that are out there, the easier it is for us to serve our customers' needs. So we'd like to get to a core codebase. Without getting into too many confidential details on what we'll be delivering in the future, we want to give our customers choices. We want to be able to provide a state-of-the-art, out-of-the-box solution that can then be configured, maybe not customized, but configured to meet some specific needs. That can be done in a SaaS multi-tenant environment as well.

Look at the likes of Salesforce. Everybody knows Salesforce, everybody has Salesforce. They offer a cloud-based multi-tenant environment that is highly configurable. We know that very well because we've highly configured our version. That's our goal, to continue to extend that level of flexibility to our customers.

I would add, you mentioned 4 potential deployment options. Another central to our success and central to the market demand is how we deploy into our partners' environments.

The market looks to the MSSPs, managed security software providers, as a critical component of demand. We don't intend to get into that market. We're the software folks, but we have a very robust, maybe the most robust channels partnership and alliances group in the market. So, you know, the likes of NTT and Unisys and Presidio and Optiv. Optiv is, I'm sure you know them quite well, they're right in your backyard.

They are outstanding at providing that full service, and we as a software provider, Robb, have to understand their needs to properly manage the algorithm inside. It's really the B2B2C, right? Business to business to customer, where instead of you selling directly to the customer, you're selling to this MSSP that has to have the ability to do their own segmentation and really maybe even kind of run their own multi-tenant SaaS from their perspective. Exactly. That's great.

Exactly. We're very cognizant of our partners' needs, so much so that in the last week, we had a big event in the last week. We can get to that in a bit, but in the last week, I met with the top leadership of those, at least those 4 MSSP providers, to make sure that they're getting everything they need from us because it's a central part of our go-to-market strategy. Yeah, that's great. Well, so you talked a little bit about your priority going forward.

You didn't mess it up. Only a month on the job, that's pretty good. Okay, okay. Let's talk about like where do you see, oh gosh, I don't know where I want to go here. Where do you see LogRhythm's biggest opportunity for expansion?

Obviously you guys have been doing great in enterprises. Where do you really want to focus on kicking butt in the next few years? Yes, it's a great question. I'll give you 2 answers. The first of which is we have determined that there is a market demand for more flexible, honestly more flexible licensing.

There's a big player in the market that they're public called Splunk. A lot of people know them. They're free. Did you know that? They are very expensive.

You couldn't be— free, just put it, install it. You couldn't be further off on that one. So is it free for 2 gigs a day? So, so they're— if you go to the guard— if you go— I have a lot of respect for their growth and for their profitability, but as I interact with customers that have experience with, you know, their model versus ours, or there might be a dual environment where they're running some of their solution and LogRhythm, there's a need to provide a few things. A more predictable cost structure, because what's unpredictable is this big data growth.

How much data am I going to have next year? Absolutely, you've hit the nail on the head. As data grows, CISOs, Chief Security Officers, and CFOs they can't be hit with surprises. And there's a big market demand right now for that consistent view on how I'm going to pay for this solution. So in the coming weeks, this will be known as a leading teaser, I guess.

In the coming weeks, we're going to make some announcements about how we're going to really disrupt the market, providing a little bit more flexible licensing because you never want to put a CISO in a position where his chief financial officer says to he or she, you have to start pulling data out of your SIEM solution because it's too expensive. What data do you not want to protect? Your consumer data, your IoT data, your IT. Or you start getting rid of it more quickly, and so you're no longer able to keep as much history as you want, whatever games you play, they're not games you really want to be playing. Indeed.

So there's a big opportunity to take share from some of the leading providers, some of the other leading providers. So that's number one. And I think you'll see in the weeks ahead, perhaps we can catch back up the end of next month and discuss some of these announcements. Secondly, there's another growth area is geographic So we're a global company. We have a very large operation in EMEA.

I saw just a press release a month or so ago about a new data center out there. Is it London, I think it was? Right outside. So we have operations in Maidenhead, UK. We have a large and growing operation in Asia-Pac.

We have business in LATAM. In fact, I heard we just closed a nice big deal in Mexico yesterday. Congratulations. Thank you. We have a great team down there as well.

So, but there's a tremendous opportunity to grow. And oftentimes some of the, certainly the European markets, they lag the US slightly, maybe by a year or two. So a lot of growth will come from those remote markets as well. That's great. It sounds like a good strategy.

You know, you mentioned, you alluded to Rhythm World a little bit. What is Rhythm World? And why wasn't I there? Well, yes, that's a really good question. Why wasn't Robb there?

So it was outstanding. And if you could see— What is it? For those listening, what is it? So each year we have an annual user conference and we call it RhythmWorld. And we gather users from really all over the globe.

We had the CISO from Qatar National Bank. He's a recent customer, a great guy. So he traveled, I think he told me, 24 hours to get to this event. We sold out, and then we ended up packing a few more people in. So don't tell the fire marshal.

Yeah. Oh yeah, indeed. So it was right downtown in the Hyatt Convention Center, and it was, it was wonderful, Robb. So it's essentially, it's a customer gathering for 3 and a half days, and at its core, it's sharing best practices. So we teach a lot of courses to our Chief Security Officer customers and their associates and their analysts on best practices, threat detection.

There's— so there's a lot of learning. There's customer panels where they're sharing their case studies and how they're setting up their operation and, you know, where they're seeing threats come. There's a lot of partner engagements, so we have our alliance partners attend and they run some sessions. I think by the end of the day yesterday, around 5 o'clock when we closed things out, there was a lot of enthusiasm around how that sharing of best practices and the knowledge transfer took place. You said it was in Denver this year.

Is it always in Denver or does it move around? Well, so our first one was actually at Vail, of all places. Yeah, it was fun, but we very quickly outgrew it. So from the first year, we doubled last year. That was our second year.

This was our third year, doubled again. And, and I threw out some numbers to the event team that I foresee us doubling yet again next year. So, so they grabbed their hearts and they, they, they took a deep breath breath, but yeah, it's a big event, a lot of work, but a lot of positive goodwill. A lot of value for sure. Yeah, I got a chance to meet with literally hundreds of our customers and got great feedback about our roadmap.

So, you know, a lot of how you build a great company is listen to your customers, you pulse the market, and our customers will tell us, hey, these 10 features are great and they're meaningful. These other 2 or 3 features we need to see. So very quickly we pull those requirements into our product roadmap. Yeah, that's great. So I want to take a little bit of a left turn here.

Obviously you guys make wonderful security solutions and you guys have been a great part of the economy here in Colorado. You're also an employer here in town. So I know you're hiring. I'd love to hear what kind of positions are you hiring for right now? Now, and what is it you're looking for for folks who, who'd be looking to hire for those positions?

Well, we, because we're growing, we're always looking for quality folks across the board in all areas. So I would say, so number one, anybody with the cybersecurity background, whether they're developers, if they have SaaS background, multi-tenancy, real contemporary development skills, we're always looking to build. In fact, we just announced opening up a small R&D hub up in the Denver Technology Center, in the DTC. I didn't know that. And the reason was we want to make sure that we're attracting all of the best and brightest talent.

So there's a lot of folks here in Boulder, and there's great talent in Denver. In fact, there's great talent all over the globe. So wherever that talent is, we want to make sure that we're we're available to recruit them. I'd say the second— so it was a little bit of a general answer, but we're always looking for talented individuals. But what's core to our recruitment strategy is fitting with our company culture.

The company culture here is honestly one of the reasons I joined. So as I was going through the early-on evaluation and interview process, meeting with members of the leadership team, meeting with the investors, meeting with some of the employees, it was, it was clear that there is a great culture of collaboration, of work hard, play hard, you know, respect for the individual.

And, and all those things really core to our, to our inner being. Yeah, that's great. So finding folks that adhere to that culture is critical. I love it. And, you know, if let's say someone heard what you said, they're really excited about it, and, and they don't trust submitting to a website is going to get them significantly considered, what's the perfect way for them to, to try and, you know, get known, get, you know, have an opportunity for a job here at LogRhythm?

Well, so our head of human resources, Dennis, would be a person they should reach out to. Yeah, so I'm sure we can get his email out there. His inbox may get slammed. That's what he's here for. Exactly.

He'll thank me at some point, I'm sure. But yeah, just reach right out to our head of HR. Okay, awesome. His contact information should be on our website. And what's going to make you, you know, you've been here for 5 weeks, let's say a year from now, a year after you've been at LogRhythm, what's going to make you say that year worked?

Yes, we've had success. What's the— call it 1 to 3 things that's really top of mind for you? Well, we've delivered a series of go-to-market strategies that the market has requested, they've demanded, and they've then responded to. And that'll be measured in customer growth, revenue growth, honestly.

Some of the strategies I'm alluding to, and I'm being a little vague purposely, that some of those strategies resonated, and in return there was a significant uptick in new customer wins across the globe. Basically being able to see data that shows that these, you know, few things we've talked about already are actually, you know, moving, moving the needle, right? Indeed. Yeah, okay, awesome. We— one of the other strategies that we'll be telling a year from now that we didn't talk about much is This move from perpetual to subscription.

I think the listeners will know the difference between perpetual licensing, typically a capital expenditure, and subscription, which is typically an operating expense. I've said this a few times and it bears repeating. We want to be flexible to flex to the market demand. Some industries, utilities, and some federal agencies, they have to buy capital capital assets. So good news is we can deliver.

A big, big part of the market adheres to operating expense and these subscription licenses. Look no further than Marketo and Salesforce and NetSuite and Workday. That booming SaaS market, well, it's subscription-oriented, and we haven't traditionally focused on that side of the market, which in the next year we will have a heavy emphasis on delivering that type of a customer engagement option. I love it. That's great.

So I want to ask, is there anything that I haven't asked you that you wish I'd ask? Anything else you want to talk about? Well, we love Boulder, so we are a big member of the community here. I think we alluded to that a little bit. Were you here in time to do the Tube to Work Day, or did you miss it?

Goodness gracious, you're going to ask me about this. You're going to ask me about this, aren't you? Oh, so I was hoping you would. No, it was a lot of fun. It was my first week on the job.

Oh, awesome. And, uh, so what is tubing to work— Tube to Work Day? Uh, so if you had asked me, uh, 6 weeks ago, I would have no idea. But since I was a participant, and I now know— so Boulder has for years, for 10 years, uh, they've been running Tube to Work. So Boulder has a, a river that runs runs right down the middle of town, and individuals get inner tubes.

You hop in the inner tube, and this river, which I thought was a bubbling creek, come to find out it's not. You could run an Olympic whitewater rafting competition on this thing. So I think it started with a couple of dozen people years ago. This year there was 1,000 tubers that gathered around 8, 9 o'clock in the morning. 5 weeks ago.

The mayor of Boulder comes, kicks things off, and LogRhythm has been a long-standing sponsor. We were the lead sponsor for this event. One of our co-founders was there to cut the ribbon. I was there as well. And I would say there were 100, 150 LogRhythm employees that participated.

And you hop in the icy cold water and you raft down for, I don't know, half hour to an hour. Yeah. And theoretically, if your business is close to the creek or the river, you can in fact tube to work. That's your commute. Yeah, right, right.

It's very ecologically sound. Sure. So yes, there are photos of me in a wetsuit with an inner tube that will not be released anytime soon. Oh, that's fantastic. So, you know, as a, as a member of the community, I want to just make sure, you know, you are where we are a huge supporter.

We believe LogRhythm is really important to the Colorado security community. You have been entrusted with an important part of our community, and we're really looking forward to your success. Whatever we can do to help you guys continue to grow, continue to be one of the jewels of the crown here for Colorado, we wanna do. So I'd say reach out to me, reach out to Alex, whatever we can do to help you guys be successful in that way. Anything else for the community that they can do?

Obviously buy your stuff, get that. Of course. What else could we do to help you guys be successful? Well, I, you know, I've often heard that we are the best-kept secret in the cybersecurity market. That's not an attribute that I'm proud of.

That's not what you want to be. No, no, we want to be the most well-known. Yeah. And after coming out of our customer event just in the last couple of days, We deliver such value to our customers. Value as measured by fast time to production.

Customers buy our solution and they're up and running in days in some cases. Value in that it is very easy to use. We come packaged with all sorts of different threat detection capabilities out of the box where in many cases our competitors, I referenced one of them, there's a lot of manual building. So they might give you a framework, but there's no house there. You have to build the rest of the house around it.

Where with LogRhythm, right out of the box, you've got a solution that can be stood up, delivered, and drive value protecting your enterprise immediately. So we need to get that word out. That's our responsibility, but as a friend of the company, the more we can get the word out that we have a highly unique high-value solution that is very customer-friendly as well, that we will flex to whatever the customer's needs are, whether it's a deployment option— on-prem, cloud, hybrid— whether it's a licensing option, whether it's how they finance the solution. So we are— we aim to be the most customer-friendly solutions provider providing the highest-value cybersecurity software in the market. Awesome.

Awesome. Well, that sounds great. And of course, if people can share that, if people can talk about that, I think that's really what they can do for the world. Indeed they can. Yes.

Well, Mark, anything else we should talk about before we call it? Just that I'm having a lot of fun. So I'm 5 weeks on the job and it's flown by. Yeah. But you're itching to hit someone, aren't you?

You really want to check someone into the boards. I can tell it's been too long without getting to play. Yeah, yeah. I'll hold off on checking anybody. In the office, but no, it's inspiring to come in and see the great people here.

It was very inspiring to see a segment of our customers over the past week. There's a real buzz around the company and around our ecosystem of customers and partners. Now we just need to get the word out. Yeah, I love it. Awesome.

Well, thanks, Mark. It's really a pleasure having you on. Like you said, I want to reconnect later and hear how things are going and, you know, certainly keep the, keep the story going forward. Outstanding. Thanks, Robb.

Appreciate it. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes