All episodes

Chris Rothe, Co-Founder and CPO at Red Canary

Apple Podcasts Spotify SoundCloud

Chris Rothe, Co-Founder and Chief Product Officer at Red Canary is our feature interview this week. News from: Denver International Airport, Charles Schwab, Gusto, Optiv, Coalfire, Zvelo, LogRhythm and a lot more!

What does Atari and Jared Polis have in common?

Both made our podcast this week. How connected in DIA? Why is Denver’s office space in such demand? How is Charles Schwab growing so fast in Denver? How does Gusto’s CEO like his job? Why can’t I stop myself from typing in questions? Also some news from Optiv, Coalfire, Zvelo and LogRhythm. It’s a cornucopia of news this week.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11210 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. Uh, this is the newscast for episode 135 for the week of September 30th Again, I am introducing the show, so that means that Robb is not here. This week I have a special guest co-host, Chris Triolo.

Welcome, Chris. Hi, Alex. How's it going? It's going well. Can you believe it's almost October, Chris?

I mean, like, fall is here. Yeah, you know, something I realized is that this is my second time on the program. It was actually one year ago today. Well, maybe not today, but within a week or two when I co-hosted with you. Wow, I did not even realize that.

That's pretty cool. It was Denver Startup Week. It was either the week of or the week after, and here we are one year later. Also, you know, Chris, you were on this podcast, but you were on an even bigger podcast this week. Yes.

So want to tell our viewers about that? Yeah, so I had the opportunity to speak with Patrick Gray from the Risky Business podcast. I did a segment that they call Snake Oilers, which is where they spend a few minutes with 3 different security vendors to talk about their products. And so I got a segment there. It was during— on that segment, they also had Richard Batelick was the first presenter, which I thought was kind of cool to be included with Richard.

That is cool. He's a luminary. Yeah, he's like the godfather of intrusion analysis, right? That is pretty cool, and he did a great job. Risky Business is one of my favorite non-Colorado-based security podcasts.

Always listen to that. So anyway, back to our podcast. So before we jump into the news, we of course have some announcements. We have a Slack channel. If you aren't on the Slack channel, we're almost at 1,100 people in the Slack channel.

It's pretty amazing what goes on in there, so you definitely should join that. Go check out colorado-security.com, click on the Slack channel button there, and you can join. It is completely open for anyone in Colorado interested in security. We also have a mailing list at the bottom of the page. Go to colorado-security.com, put in your email address, hit submit.

You will get the show notes in your email every week when we release them. You will be the first to know about a new podcast. And have all the details right there. We'd also love it if you would please rate us and subscribe to the podcast in whatever podcast tool you use, however you subscribe. Also, please tell a friend, spread that word around about Colorado Vehicle Security.

Let them know all the great stuff that's going on and why they should listen and tune in and check out the website. If you wanna help us with a monetary donation, we have a Patreon campaign. That helps us defray the costs of putting this on, things like web hosting. And, you know, one of the things I was thinking about too is even just getting the news, right? So, a lot of our stories come from the Denver Business Journal, and many of those stories are not free, so we have to pay for those.

And then finally, you may have noticed over the past few weeks we have had some volunteer folks doing interviews. Chris, a mutual friend of ours, Mary did interviews and those were great. And we have another one this week. If people would like to do interviews, we would love to have you interview people and get them on the show. Also, if you are interested in being interviewed and have something interesting to say, please let us know.

We'll reach out and figure out how to get you on the show. All right, so with that, let's jump into the news. The first story this week loosely has to do with Atari. So that's got to be a good thing, right, Chris? Yeah.

Do you remember Atari, Alex? I do remember Atari. Who doesn't love playing Pong or Space Invaders or, you know, all of those good games? Anyway, this article isn't really about Atari, but it's a good headline. So this is talking about the future of work.

There was a panel at Startup Week with Governor Polis and Nathan Bushnell, who is the founder of Atari, who also I did not realize was also the founder of Chuck E. Cheese. You know, very weird. I guess they both involve video games. But anyway, talking about the future of work and artificial intelligence and, you know, how we need to be looking forward and thinking about how artificial intelligence is going to be replacing all of us. Yeah, I think that they address this question of, and in the article about mundane tasks, right?

And it's trying to offload those mundane tasks to AI. And that's obviously where the industry is heading, our industries. But I liked how the article talked about the sort of worry there that people are gonna lose jobs, right? And what to do about it. I think some of what they've been talking about here in the government is to make sure that these conversations are happening.

Like, how are we gonna handle this if people are losing jobs? But I, I, it was very hopeful there at the end how they talked about, uh, when you talk about autonomous vehicles, for example, they had quoted something like 15 million jobs, you know, people who are drivers are going to potentially lose their jobs, but they could be replaced with building the new infrastructure for autonomous vehicles, right? Yeah, and part of the article also talked about how Governor Polis started a new department to look at the future of work and what that means. One of the things that always strikes me with this is, you know, everybody keeps saying AI, but like every example that people give in my mind is really just— it's really automation. I think that's a better way to look at it than AI, because when you say AI, I think still in most people's minds, you know, you're thinking about, you know, thinking robots, right?

And most of the stuff we're talking about here is not really thinking robots. It's, you know, it's getting rid of the easy stuff and programming away those kinds of things. Yeah, I guess maybe in a little sense, you know, an autonomous car is a thinking robot, but not really. It's just kind of following a set of rules that, you know, we do as drivers. So anyway, well, one way we talk about that is general AI versus narrow or specific AI, right?

And general AI is that It's the HAL robot that knows everything and can talk to you and all of that. Really, if there's any AI happening today, it's in the narrow AI area, more like the expert system. It's applied to a specific problem for sure. Yeah. And I, you know, the nuance I think is lost on most people.

So anyway, good discussion. All right. Well, article number 2 is about DIA. DIA is in the news again. This article describes where DIA was ranked among the nation's best-connected airports.

Yeah, when I heard that headline, I thought, oh, we're talking about, you know, who has the best free Wi-Fi or something like that at the airport, which is totally not what this story is about. You know, DIA, we know, is a sort of hub in the central United States, which means there are a lot of connections from the airport to various different places. And it turns out that DIA is the 5th best-connected airport in the US, which is pretty cool. And the winner was— the winner was— who was the winner? I didn't even remember.

It was Chicago. Oh, it was Chicago. I was gonna say Atlanta, and then I thought in my mind it wasn't Atlanta. So I think they were number 2 for the 4th year in a row. And I wonder if the most connected airports also have the most delays, because that's how it seems every time I go through ORD.

Yeah, one of the ones— I think it was number 4, but definitely in the top 5— was Detroit. And I thought that that was kind of weird, but I guess Detroit is a Delta hub. Okay, so if you're not flying on Delta through Atlanta, you're probably flying through Detroit. So I guess that makes sense. I think what's, what's funny about this article is although the focus is on the, you know, where it ranks and as far as how well-connected the airport it is, is it, it turns right to the question about the expansion project that's going on at DIA, or not going on at this point, or not happening, right?

There's a lot of controversy happening on that for sure project. Yeah, I can't wait till that is done, but hopefully they— and hopefully they get a new contractor soon to get that done. So, uh, next, uh, Denver is now the 7th largest flexible office space market in the U.S. So this article is talking about, uh, the WeWorks of the world and the other co-working and flexible office space vendors that are out there. And Denver apparently has the 7th most amount of space in that area in the US, which is— or I guess maybe not even in the US because they're talking about international markets as well.

But yes, pretty cool. If you want a co-working space, there it definitely is here. 2.4% of the total office space in Denver is flexible office space. I found that surprising because the article is geared towards, you know, how big this is growing, how fast it's growing, and then the statistic is 2.4%. And so apparently that is actually a significant amount, but, you know, I sort of expected it to be higher than that.

Yeah, I think the highest was about 4% in San Francisco, so, which makes total sense to me, but Um, but yeah, that you would think that that would be a, a higher number if they're talking about how, you know, amazingly large this part of the market is. The, the thing that I kind of focused in on in this article is, is the why, right? Why are we seeing so much flexible office space? Why is it becoming so popular? And the answer here, according to, to Shippets, the guy who's quoted in the article, is flexibility.

Right, it's having that flexibility to, you know, add, expand, and, and also remove space in a flexible nature. And so, yeah, you know, that, that definitely explains it. For us as a startup personally, it's really useful, you know, because as we're building the company, we're not ready to commit to large office spaces with leases and all of this. So, you know, obviously we could take advantage of— or even to commit to a small office space and then next year, oh well, we got to renegotiate. And exactly that kind of thing.

It makes them a lot easier to I can see that for sure. So our 4th article is about Charles Schwab and their growth in Lone Tree. I did not realize how large the facility is down there. Yeah, you know, you can see the, you know, they're sort of beacon off the highway. They have like a, looks like sort of a fake office, like you can see it right off of I-25.

But yeah, they've got, I guess, 4,500 people down in the office down there now, which is pretty crazy. And that's 500 more than they originally expected to have down there. The focus of the article is talking about how it's so big that they're building a parking garage now, like a 1,000-space parking garage for all the people that are working there. Yeah, they actually gave a significant amount of attention to this parking garage, right, in the article. But the— what I liked about it is that, you know, when you see the growth of a business like this, the the impact it has on the area, on, on the, uh, the economy, essentially having additional, you know, uh, even just, you know, the Schwab employees going to the businesses and the restaurants, the retail, and driving the housing market.

And, you know, it's really beneficial to the, to the growth of the area for sure. Uh, one of the things that I also thought was interesting, and we had an article about this a couple weeks ago, they had like one line at the very end of the article too, is that Schwab actually announced some layoffs recently here too. So it's not all quite as rosy as they're painting it, but I guess, you know, sometimes you grow too fast and you have to make adjustments. Next article, there was an interview with Gusto CEO Joshua Reeves about the secrets of being the top executive. So, you know, Gusto expanded here from California.

They're Their biggest office is now in Colorado, and this interview gave a couple insights into Joshua Reeves and what he does as CEO. Alex, is it Gusto or Gusto? Oh, you know, good question. I've always pronounced it Gusto, but I have no idea. I don't either.

We called it Gusto for some reason, and I've been corrected since then. Yeah, but I still don't think it's clear. It's an American company, not one with a Spanish accent, I guess. Exactly. So, well, the CEO, you know, he talked about what happens in cities like Denver if it grows quickly and companies like Gusto grow fast and what it, you know, sort of what it does to the infrastructure there.

And, you know, he made some comments which, you know, pretty you know, it's good common sense in that the public transportation is a key factor in making sure that people can live, you know, maybe outside of the city, but they have good public transportation to get in. And then the availability of housing, you know, this idea that if you're going to keep adding jobs and grow, you need to add adequate housing so it doesn't create an imbalance in the supply and demand, right? Yeah, my— the underlying message that I got from this was We're moving to Denver because it's not San Francisco, so please Denver, make sure you don't turn into San Francisco. Right. That came across very clear, I think.

For sure. All right, next story. There was an article from Optiv announcing a security survey that they performed. The headline, I think, is interesting, talking about how some businesses are prioritizing cybersecurity above all else. So this was a CISO-level survey that they took, sort of gauging, you know, people's priorities and how they're seeing cybersecurity, how things are changing.

You know, that statistic is an interesting one for me because frankly, it's dumb. You know, as a business, you don't want to prioritize cybersecurity over everything else. There are lots of things that you should think of first before cybersecurity. Not that cybersecurity isn't important, but, you know, you probably want to actually have a product to sell and, and, you know, marketing efforts and, you know, all of the things that you do in a normal business before you think about cybersecurity. Right.

And then think about how you're going to protect it. Right. And make sure that So, so I, I guess, you know, I think the headline is a little bit clickbaity, I guess, trying to get you to, to think about, ooh, here's a, you know, a crazy headline. But there were some other things in here that I think were a little bit more down to earth. 96% of respondents indicated that they're taking a more strategic approach to cybersecurity.

Not a super surprise, but I think that that's a good thing. Having strategy around cybersecurity is always a good thing. One of the findings that I found interesting was the sort of problem around the basic blocking and tackling of security problems, basic functions like vulnerability and patching, and it's not as high priority as it should be. The comments in the article by Andrej Kowalich, he's somebody I've actually worked with before, so it's kind of Cool to see his name pop up here. It really points to this idea of, you know, we need more automation.

And again, forget saying AI and let's just say automation is the more we can automate the typical tasks in whatever the SOC or in your security program, it gives you access to more resources to focus on basic security projects like vulnerability management, which according to this article seems to be lacking. Yep, I think that is a good point as well. All right, uh, next article. So the next article is, uh, from Coalfire, and in this one they talk about the new HITRUST CSF 90-day rules and what you need to know. Yeah, this was, uh, interesting.

I, I'm not a HITRUST person. I haven't ever had to be HITRUST certified. But basically, it sounds like a couple new rules around timing. One, that your controls need to be in place for 90 days before you can be assessed by a third party. That seems like a reasonable rule.

And then the second one was that the external assessments themselves can't take more than 90 days. So, I think that those are 2 smart things. If you want someone to externally assess you, you don't want it to take forever, and You probably should actually have been doing the things that you're being assessed on before you get assessed on them. There was some good advice here too, that performing a self-assessment is a pivotal step to identifying remediation efforts. It's just good advice for— this is good trusted advisor advice from Coalfire.

Yep, good stuff. All right, next article. There was a blog post from Zavilo this week talking about unsafe, banned, and counterfeit products. Sold in online markets. You know, this was an interesting article to me in that it really didn't have anything to do with cybersecurity.

But it just sort of, you know, personal safety, I guess. The article was talking about how, you know, many of the online marketplaces, Amazon, eBay, you know, now have third-party sellers. So, if you're buying from Amazon, you may not be actually buying from Amazon. It could be whoever. And I've bought plenty of straight drop shipped from China items off of Amazon myself.

But just talking about the fact that there are many that could be counterfeit or even dangerous because the sellers are a little bit sketchy. Yeah, exactly. And what you're seeing, I guess, is a lot of these online retailers are trying to build systems, these detection systems to determine if something is authentic or is actually counterfeit. It's hard to say how well it's working. The blog post talks through some of the examples where they've gotten some good performance on these things.

But I think you're right. From a safety perspective, I think that is what becomes the concern for the typical American, or the typical— well, in fact, anybody, consumer, anybody who's consuming products.

This trend towards seeing, you know, potentially counterfeit products coming through these online retailers might actually shift consumers back to the store. Huh. When you're in the store, there's this, you know, they verified that these are real products, they're, you know, FDA approved and all of these things. And I just felt like the trend towards online retail is just it's just going bonkers, right? And, you know, the big box stores, the physical stores are going to start to really see the impact of that.

This is actually one of those things that could reverse that trend. Yeah, that would be interesting to see. I'm sure that the online retailers will, will take steps to curb things if that really is what the trend starts to be. All right. And then our final story for this week was a blog post from LogRhythm.

Talking about doing OT, you know, operational technology security with Clarity and how that plays into LogRhythm. There was a good amount of detail in this blog post that they had talking about ways that you can use the data from Clarity to monitor your OT environments, how there's interplay back and forth, all that kind of thing. I really liked it. I've seen this from LogRhythm before in some of their blog posts where they really take the time to show you the use case and sort of spell it out. There was great screenshots that explain really end-to-end how to do detection, investigate, create cases, you know, kind of in the mind of someone who's trying to, you know, do monitoring and incident response.

They tied that together pretty well throughout the article. Yeah, definitely. It was a good blog post. All right, so that takes us to the end of the news. Let's jump over to the Slack message of the week.

Thanks to Andre Gaeta for being our sponsor of the Slack Message of the Week. He does this out of the goodness of his own heart and the depths of his own pocketbook. And this week our winner is Jake Barber. Congratulations, Jake. Jake shared a story about Google's new quantum computer, which on the surface, and, you know, some news articles have said is an amazing breakthrough.

But I think on deeper inspection, if you look at it, it is pretty cool for what it is, but it is— it's not really the, you know, the end of encryption or anything like that at this point. So congratulations to Jake. Thanks for sharing that. We will get you in contact with Andre, and you can get your free merchandise from the Colorado Equals Security store. All right, let's go over to events.

We have a bunch of events that are upcoming. The first of those is on October 2nd. Ballard Spahr is doing their annual Colorado Security— excuse me, Cybersecurity Summit. This is a legal and privacy-focused event. Colorado Equal Security will actually be there, so if you want to show up, we will see you there.

Also on October 2nd, the Denver IAM User Group is having an event at the Boiler Room Speakeasy in downtown Denver. Nice. Uh, finally on the 2nd, Colorado Springs, uh, is doing a Cybersecurity Summit and Industry Day.

On the 3rd of October, Splunk has their First Thursdays at Topgolf event. On the 3rd and 4th, uh, the CTA is doing their Global Blockchain Summit.

SecureSet is doing their Capture the Flag cybersecurity games on October 4th. On the 5th, ISACA is doing a CSA and CISM review session. This is Domain 4 for the CSA and Domain 3 for the CISM. ISSA Denver has their October chapter meeting on October 8th. And the 9th.

And Presidio on the 9th is doing their Red Sky Security Conference for 2019. SecureSet— Secure Your Future with SecureSet and Denver Women in Tech session is happening on October 10th. Pretty cool. And then our final event for this week, ISACA is doing their review session on the 12th for CISA Domain 5 and CISM Domain 4. Check out the link on the website for more details on those ISACA review sessions.

All right, let's jump over to jobs. We've got some great jobs this week. First, Bank of America is looking for a cyber program manager. Bank of America also is looking for a security vulnerability analyst. Bank of America is hiring like crazy in Denver.

Uh, Transamerica is looking for a senior cybersecurity fraud investigative analyst. Next up, CHI is looking for a director of security engineering. DISH is looking for a cloud security architect. And Pearson is hiring a senior application security engineer. Denver Water is looking for an information security analyst.

And Hock is hiring a product security architect. And finally, Direct Defense is hiring a security analyst. I'm assuming that is for their SOC because they do some MSS work. So those are the jobs for this week. Check those out.

Pretty good listing of jobs in there. And that brings us to the end of our news portion for this week. We will now jump over to the feature interview. This week we have another, as I mentioned earlier, another guest interview. So Ty Burke is doing his first interview for us, I believe, and he interviewed Chris Rothe, who is the Chief Product Officer and co-founder of Red Canary.

So look forward to seeing that. Thanks, Chris, for filling in. Appreciate you being here. Thanks, everybody, and we will talk to you next week. This is Clay Parker, Director of Security Operations at Trimble Navigation.

Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. I'm Ty Burke here with Chris Rothe, co-founder and chief product officer at Red Canary. Chris, good to be here. I got your name right. Way to go.

What percentage of people get— you say Rothe? Oh man, nobody ever says Rothe. I've just gotten used to Roth and Rothe, so I'll respond to any of them. I don't actually care that much. Yeah, with a name like mine, I've got, uh, yeah, quite a few silent letters in my first name.

You can imagine the trouble that, uh, totally that I've been in my life. Um, well, thanks for being here. Uh, really excited to kind of get to know you a little bit and hear the story. Um, obviously Red Canary is a frequent, uh, I don't know, company, and we highlight a lot of what you guys are doing on the podcast week to week. So I appreciate that.

I'm really excited to hear what you guys have in store here. Cool. Yeah, excited to be here and share what I can. Um, so tell us a little bit about yourself. You mentioned you, you grew up, uh, where you're living today.

Yes. Which I don't know if I know anyone else who can say that same thing, but tell us a little bit about kind of— sure, sure— childhood and what growing up was like here. Yeah, absolutely. Yeah, so I'm native Coloradan, grew up over in Littleton. My parents in 1985 bought a house up in Deer Creek Canyon mostly because my dad wanted to put up a big ham radio antenna.

He was big into that, and the neighborhoods they were living in didn't allow him to put up antennas as high as he wanted, so moved out there to get a little, a little bit of freedom. And so moved up there when I was a kid and grew up there, ended up going to CU Boulder, and then eventually went back and subdivided my parents' house and lived there. So kind of a cool experience coming full circle and living where you grew up and knowing kind of every inch of a piece of property and stuff like that. So when you say you subdivided the property, you mean like you built a new home on the property? Correct, yeah.

So my mom is— my dad passed away, but my mom's still there, next-door neighbor. So, okay. It's awesome. It's great having Grandma there for my kids. I bet, I bet.

How old are your kids? I got 3 kids, 3, 6, and 9. 3 girls. Okay. Yeah, just coming off a week of playing Mr.

Mom while my wife took a much-needed vacation, so. Oh yeah. Yeah, still recovering a little bit, but went well. That's great. I bet your mom loves having the girls around.

She does, yeah. Yeah. That's gotta be nice.

So I understand outside of, you know, security in the professional world, you're relatively involved in the nonprofit community. Sure. And that's, you know, one thing that we'd like to kind of highlight here is obviously the show is based on security, but so much of, you know, what we think makes really interesting people are kind of what they do outside the office. So tell us a little bit about your nonprofit work. Sure.

Yeah. For me, I focus on a couple areas, work with a couple different groups in helping them kind of find ways to use technology to do better for their ultimate— I don't know, for me I always think of it as customers, but the people they're serving. And so that's kind of the model that most of that's centered around. The company that— we'll get to this, I imagine— but that founded Red Canary has a nonprofit entity associated with that, Kairos Charities, and we put on what we call Accelerant Projects, which is taking a charity that has, you know, some need or something that they want to do to kind of move forward and putting together almost like a hackathon. They can take a lot of different forms, but we've done some cool things in the past just to get tools into their hands.

A lot of time they're resource-strapped, and it gives people an opportunity to take their skills, whether that's coding or marketing or whatever, and take them into that sector instead of just kind of donating money or time. Kind of a way to generate— donate time in a different way that aligns with what they're good at. So done a lot of that. And then, you know, having young kids, like, the other part of it is making sure that, you know, bring them up to have a heart and desire to want to help other people. We're obviously very lucky to live in the best state in the US and make sure they know that, make sure that they're giving back to people around them.

So that's the other half of it for me is doing things with my family to stay involved with that. Cool. Yeah, very cool. That's— I, with conversations I have with various executives around town, it's that type of kind of fulfillment really kind of makes, makes people's lives so much better. Like, you know, no matter what type of success they're having, yeah, uh, it's the impact that they're able to have on the rest of the community and, and give back to those people that, like, you know, just don't— weren't given the opportunities that they, that they were having.

Yeah, it's really special. So yeah, I was really fortunate early in my career to have a mentor who, you know, kind of looked at his, his career as The first half being kind of for him, the next half kind of being building a company and things like that, and then the last bit transitioning into, okay, now I've done this, I've sold the company, what do I do for the next 10 years? And so I've been fortunate enough to get a lot of good advice there. Think about what you do once you put together something that really works. Cool.

So you're up here, you went to Boulder, started out with Mercury. Pre-HP? Yeah, actually, yeah, actually started with Freshwater Software right before the Mercury acquisition. I'm actually not sure if it was right before or like the day after, but it was like my first few days there were all meetings with the Mercury team coming in and going through that acquisition. So that was a great place to be.

I don't know if anyone, some of your listeners may remember Freshwater, but the cool thing about working there is that every desk, like, they basically have this big open floor desk area with these diagonal desks and the dividers were fish tanks. So there's still pictures out on the internet of like this, the freshwater, literally freshwater. Yeah, exactly. And yeah, so I interned there kind of my last couple years of college and then worked for them full-time for a little while and then ended up over Lockheed Martin. Okay, yeah, so, so many security folks across the state, across the country, you know, tend to get their start in some of the really, really large defense contractors.

You had a good run there, 3, 4 years. Talk to us a little bit about what that experience was like to you, particularly for those listeners who may be 2 years into their security career working for Lockheed or something like that, and kind of how that helps shape you because it's an incredible training ground, right? Yeah, and you know, all 3 of the founders of Red Canary kind of came from that world, and I think the thing I always think back on and take away is there's no choice but to be mission-oriented when you're working in national security or defense contracting. You know, if you're not there for that reason, you know, there's probably better places to be, but for us it was always very meaningful to support the missions that we supported and did that as a, you know, Lockheed employee for a couple years. Hilariously, and this happens a lot in the defense industry, but I never actually worked in a Lockheed building until I left Lockheed Martin and went to Solidine, which is a small contracting firm that contracted back to the big players in that industry.

But the thing that I really look back on now and what I learned being in that world was the roles I had kind of right out of college were take big and sometimes ambiguous requirements handed down from government entities and deconstruct them, pull them apart, turn them into things that software teams could go build.

It was tedious work sometimes, tough work, but at a very young age, very early in my career, I had a lot of experience in leading teams and moving them forward and getting things done and then ultimately presenting those results back to our government counterparts and working directly with the people who are serving those missions. And so, yeah, so that was great experience and great kind of learning to go through early on in my career and then transitioned from kind of that systems engineering roles back into software engineering roles. My background, I'm an electrical engineer by trade, and I kind of grew up breaking things and playing with computers as kind of my main hobbies. Got out of school and was kind of like, all right, now what do I do? There's not a ton of hardware engineering in the area that I— that was really there, and so jumped over into into the software world with Lockheed and had a great run there.

After I left and went to Solidine, I consulted for Lockheed for a number of years after that. In total, I think I did 8 or 9 years in that world. I was lucky enough to meet Brian Byer, who's the CEO of Red Canary, one of my co-founders during that stretch working for Solidine. He had come over and we hit it off right away. And I think, you know, the thing I'm always amazed with, there's— if you go out and look at like startup literature or startup Twitter or whatever, they'll talk about the 10x developer, the mythical developer who can do more than anyone else.

And if you read into that a lot, a lot of times you'll find out like that person's not always a great person. A lot of times they're so single-minded on getting things done that they don't take the time to mentor and work with other people and frankly just be kind. And I think amazingly, to Brian's credit, like, he is absolutely a 10x developer and can crank out more beautiful code than anyone I've ever seen, but also is a great person and a great person to work with. And so I feel very fortunate that I crossed paths with him, and obviously we worked really well together you know, in that stretch. And then he got an opportunity to work— move over to a company called Kairos Technology, founded by a group of guys who worked at Mantec, another defense contractor back on the East Coast.

He had interned with them, you know, a number of years earlier and got a chance to kind of start their Denver office. And then pretty quickly after that, we ended up founding Red Canary kind of as an offshoot. So Yeah, like I said, if nothing else, like working in that defense contractor environment got me really used to kind of being beaten down by government folks and working really well with some of them, and then led me to kind of being introduced to the team I worked with. So as a double E in college, you go to Lockheed, you do your thing there, like was security something you were passionate about, or was it more of a— I guess this kind of evolves into the Red Canary opportunity, but were you really passionate about security, or were you like, wow, here's a problem, let's see if we can do something about it? Yeah, so the problems I worked on in the defense industry were not cybersecurity most of the time.

They were national security. A lot of the stuff based out here in Denver is, you know, satellite related. So, you know, I worked on that GPS ground station for a while and some other stuff like that. And it's funny being, you know, now being in cybersecurity for the last number of years, like you take a step back and you look at it and say, you know, are these 2 separate things or are they 2 parts of the same thing? And, you know, my abstract view is that they're, they're the same thing, right?

Physical security and cybersecurity overlap a lot more than I think people realize. And so, you know, the things we were doing in the satellite area were very much overlapping and complementary and ultimately part of the same overall mission as some of the pure cybersecurity things. So my real introduction to cybersecurity and everything that went along with that on the government side was once I came over to Kairos and worked with that team. We kind of did boutique security stuff for the government but also commercially. And so, yeah, it's kind of a long-winded answer, but never set out to be like a security guy and ended up kind of doing things within security for my whole career.

Okay, so you founded Red Canary. Co-founded a couple years ago. What was the goal at the time? What were you trying to do? And I say that because there's a lot of entrepreneurs out there listening, hopefully, that probably have ideas of ways to do things better, ways to do things differently, you know, but they're not ready to pull the trigger.

Maybe they just got married, they just had a child, maybe they're making good money or whatever. There's, there's, you know, all sorts of reasons to not start a venture. But, you know, where were you in your life? Yeah. And kind of what ultimately convinced you that, like, I'm gonna take the plunge?

Yeah. You know, here we go, let's give this a shot. And, you know, let's hope— I hope this works. But, but just talk us through that because there's got to be some, some parallels between what people are listening— people are thinking out there and where you were at that stage of your life. Yeah.

Yeah, I mean, if you looked at the ideal conditions for starting a company from a personal life perspective, I think I hit none of them. We talked about where I live. I was in the middle of building my house. My wife was pregnant with our second kid. We had one who was 2 at the time.

Come home and say, hey, we're going to think about taking this big pay cut because there's this huge opportunity. None of that sounds like ideal conditions for going full on into a venture. And so I guess I don't know if there's a message there. It was certainly hard and hard on my marriage with my amazing wife. But you come out the other side of that.

Look back on it and you're like, how did I— why did I think we could do that? It was so much harder than I thought it was going to be. And yet, like, it worked out for us. Like, I don't know that it would for everyone, but it was— I wouldn't— certainly wouldn't make any decision differently. Like, I think if you find an opportunity where there's something that you believe in and it's the right team, you have the right co-founders, the right investor team, or whatever, you just have to do it.

And is it always going to work out? Definitely not, but it's definitely not going to work out if you don't take the chance. So yeah, I would say in summary, there's never a perfect time, there's probably never even a right time to say I'm going to suspend my life and go try to launch a business, but you should still do it if it's something you're passionate about and you've got something that actually has a chance. For us specifically, we were working at Kairos. Kairos built this product internally to satisfy— we were doing a lot of incident response engagements and built this tool internally to use for that and ultimately decided to spin that out into a separate company.

Fund that company, and that company was called Carbon Black. And so Carbon Black split off, took a Series A, grew for a while, then merged with Bit9, renamed themselves back to Carbon Black, and then they IPO'd, I guess, last spring, and then actually just last week were acquired by VMware. So very successful business. Myself, Brian, our third co-founder, Keith McKeown, account. We stayed back at Kairos, continued doing incident response engagements using Carbon Black, and basically every time we'd get done with the IR and we'd say, hey, you should keep this here, keep this tool deployed, it's not just for deploying and then using for a short term, keep it here, keep it running so it collects telemetry, you know, when we're not watching.

And people would say, oh, that's cool, we like it, but we don't want to manage it. And so the initial thing we did was, okay, well, we'll manage it for you, right? Which meant nothing more than like turning it on in, you know, a rack that we had of servers and helping, you know, keep it alive. And pretty quickly after that, we realized like, why are we, you know, just hosting this for people and waiting for them to call us and say they think they have a problem? Like, we've got the data we're watching, we've got the telemetry of what's going on in their environment, let's just look for threats all the And that was kind of the genesis of what became Red Canary.

We've got this great telemetry set coming in, looking through this big volume of data and finding the interesting things is actually quite similar to the problem that Brian and I used to work on in the defense industry. Totally different datasets, but very similar. And so kind of applied that similar model and went from there. I think the other thing I'd say about that is early on you don't know what your ultimate customer is or what they're going to want, and so we tried a lot of different things. We were fortunate enough to, by the time we spun Carbon Black or Red Canary out from Kairos, we had 5 or 6 pilot customers who we'd been working with for about a year and kind of understood what they wanted and some of that, and then spent the first year as an independent company just focused on learning as much as we could from them.

What would be a valuable service? Do we need to take in, you know, IDS logs or, you know, work in their SIEM or whatever? Answering a lot of those questions and ultimately came to the decision about what Red Canary was going to be, and then going into 2015, you know, decided we had a product that we were confident we could go take to market. And so started our go-to-market efforts and went from there. But that was our approach, was to not rush into either taking funding rounds or trying to sell the product too soon.

Really focus on a core set of customers and make sure we understood what the value was and then how to communicate that to other people. Classic how how to start a business. Do one thing, do it really damn well, and then figure out what to do next. Yeah, it's funny. I think it's really easy to look back and say that in hindsight, and at the time, that is absolutely not what we were saying.

We definitely weren't sitting there like the nice clean story I just told. It's definitely not what we were sitting around doing. For sure. But yeah, it does end up that if you can get away with that, it's a great way to do it. To really focus on a small thing and then figure out how to make it bigger.

Yeah, so you're running the product team today. Actually, I'm not. You're not? No. Educate me, what are you doing today?

Yes, this is a fun thing about Red Canary history. So I mentioned that timeframe, 2015 timeframe. Really what it came down to is, all right, we've got to either raise a round or go sell the product enough to kind of keep the doors open. And so, you know, we were working on— Brian especially working on raising a Series A, and, you know, we looked around the table and I was like, well, the rest of us need to kind of go figure out if we can sell this thing and get some traction, if for no other reason than to show the investors that there's something here beyond our, you know, pilot customers. And so I think before that I had maybe like sold a car on Craigslist is about the extent of my sales experience.

But it was kind of up to me. So myself and Corey Boland, our head of marketing at the time, and we kind of sort of think of him as like the 4th founder of the company, he and I kind of just went barnstorming, went up to Carbon Black and learned a lot from how they did sales and started to figure out like where could we where could we start taking our product to market? And so we did that and did a lot of the initial sales of Red Canary, and then we ended up taking a Series A investment about a year and a half later, 2016, in the summer. Did the Series A, and then from there, for a while, I moved back over to kind of the product side of the house, and then I came back to what we call our customer machine, which encompasses sales, marketing, and customer success. That's where I sit today.

I still have the Chief Product Officer title because, maybe just because I want it, but more so I think I'm a pretty abstract guy and I think of everything that touches a customer as being part of the product, whether that's the first marketing interaction they have, the first time one of our sales reps calls them. Ultimately, that whole experience all the way through being a customer for 10 years is part of our product and our delivery. So I can at least rationalize that in my head. But yeah, for now, everyone kind of on the customer-facing side reports up to me. Okay, gotcha.

It's kind of a weird place for an electrical engineer to specialize. I wouldn't have expected it, I'll be honest, but good for you. Okay, so for all of the kind of— you've been in Colorado forever. A lot of folks like myself have come here and we've created traffic and we've driven up housing prices and things like that. We appreciate that.

But, you know, for those who are relatively new to Colorado who are trying to kind of grasp the scope of security and how it's evolved across not just the Front Range but the entire state.

Help us explain, help explain kind of where maybe where security was in 2014 when you guys started and where it is today and how you have grown with it. Maybe because you're so customer-facing, maybe you can talk a little bit about what customers are saying today that they weren't 2 or 3 or 4 years ago. For sure, yeah. So I think to address kind of the Colorado side of it, I think it's cool to look at the history and, you know, probably this is part of why this podcast exists. And you look at going back to the web roots and even before that, web roots, LogRhythm, Ping Identity, great track record of successful security companies here.

And with that, a lot of great minds in the community. Who've built those companies and then gone on to do other things. So there's a great community here that supports the security ecosystem, and that's why it's a great place to be to have a company like Red Canary, because we have no shortage of people to talk to and people to recruit and that kind of thing. So there's that side of it, and then I think if you think about the security landscape in general, what's changed over the last 5 years with our customers is as more and more things in IT change, the security landscape changes. More and more stuff moves to the cloud.

My primary device I work off of is a Chromebook. Security for that environment, cloud SaaS, devices that aren't traditional laptops, servers, is different. That's kind of where things have changed. And then you get kind of on the product side and you talk about Kubernetes and container security and a lot of fronts like that that are really not figured out yet. There's not good answers for what does it mean to collect telemetry.

You know, this relates very specifically to our business, but what does it mean to collect good telemetry in a containerized environment so you know what an attacker has done if you get into an IR standpoint? The container only lasts for 5 seconds, spins up, does a job, spins down, and it's compromised. What does that actually mean? There's a lot of questions like that out there that I think smart people are going to come along and found businesses and build great products to address that. And then, yeah, I think cloud security is kind of obvious at this point, but I still don't think we have a great grasp on it.

Certainly it's becoming more and more of where attackers focus their attention. You know, when endpoint devices, laptops, workstations were so easy to compromise, and to some extent they still are, if you're an attacker, why focus anywhere else? You can always get in by phishing and, you know, easy malware to get deployed onto a laptop. Why bother trying to attack a cloud environment. But as the industry progressed and we've gotten better at stopping threats that attack endpoints or even just detecting and responding quickly, attackers have to shift their focus.

And obviously the cloud is an area where IT still has maturing to do, and thus security also has maturing to do. And so if I was looking out a few years, I think those would be the domains that I'd focus on, which probably isn't earth-shattering. I think everyone would probably say that to you, but that's what we hear from our customers is, you know, what do you do to support containers or Kubernetes or the cloud or whatever? And, you know, as a company that's focused primarily on endpoint security, it's important questions for us to figure out from a business standpoint as their security ally, as a business that's in the trenches with them and prides ourselves on being an operations ally to our customers. How do we be an ally in this kind of new front?

As you guys have grown, no doubt there's been bumps along the road. You've probably had some really great days, probably had some very, very dark and depressing days, but you've gotten to where you are today regardless, in spite of all that.

Who has helped you? Obviously, I assume your family has been a big part, and your co-founders. Have you found value in external mentors or advisors or other people that you may not have— may know nothing about your business but help kind of keep you grounded? And because that's really important, right? Yes.

So many people in the security community they get chewed out quite a bit, right, for things that they can control or things that they can't control. But being able to wake up, dust yourself off, and do it all over again is really, really key to continuing things. So talk to us about that. Yeah, yeah. I think the best way I ever heard this described was actually one of the Carbon Black co-founders, Ben Johnson, who described startup life as very much a roller coaster ride.

And the first couple years of that, the roller coaster is like up and down very, very frequently. And so one day you think we nailed it, we're gonna be a billion-dollar, $10 billion company, and the next day you're like, screw it, fold it up, let's go do something else, this isn't working. And sometimes that can be the same same day, to be honest. And so early on, those ups and downs are very frequent. It's call to call, it's day to day, it's hour to hour.

As a company progresses, it gets— it's still there, the roller coaster ride is still there, but it tends to be a little bit longer arcs, bigger things happening, things tend to stabilize a little bit. So if you can be persistent and as a founder and as an early employee at a startup company. It does get better, assuming it's a good business. It does get to a point where you have more good days. You still have the dark times when things happen that attack your business, whether internal or external.

But yeah, I mean, I think that's that. And then I would say having great mentors and having people who you can rely on and learn from is critical. It's been super important for us. Like, you know, I joke about, you know, never selling anything before being in this. Like, I literally knew nothing about how to sell or even talk to, you know, a potential customer.

I had been, you know, working with government folks for a long time. I knew how to talk to them and knew how to kind of present and build good stories and stuff like that, but had no idea how to ask somebody, hey, will you actually sign the money over, right? And, you know, early mentor of mine, you know, said that like there comes a point where you just have to ask them, you know, will you, will you sign this? And like it was like this light bulb moment where I, you know, I thought, hey, you show them the product, you show them how good it is, maybe you let them touch it and play with it and do a proof of concept or whatever, and at some point during that they say, oh, this is cool, I'd like to buy this from you. And that just is not a thing.

That's not how it works. Until you say to them, okay, you think it's cool, here's how much it costs. Do you want to buy? That's not going to happen. I'll never forget the first time, one of our first big deals that we closed.

I was on a wrap-up call for a proof of concept and I asked the guys, are you ready to buy? And they said yes. Thing to do as a sales rep is say, oh great, let's talk about the next steps and outline how we get from here to the signature actually being on the piece of paper. And I think my exact response was, that's great, I'll talk to you later. And I hung up.

And I was running around my house yelling and screaming like, yeah, I'm a salesman or whatever. And then I had to reengage to get the process moving again. But anyway, so So that's areas where we leaned heavily on folks we knew from Carbon Black and them having gone through that fairly recently, and then leaned on others here locally to reach out and just get advice on where to start. We're having this problem, we're seeing this. Bill Diedrich was the VP of Sales and President at Ping Identity for a long time.

Time and has become, you know, one of my core mentors because he just thinks about things in a very clear way. And the thing I love about Bill— he's on our board as well— but the thing I love about Bill is that he may tell me the same story 7 times if I ask, you know, slightly related questions, but I love that because it's like he doesn't deviate. He goes back and says, I know this works, I've seen this work, and been doing this forever, like, did you do this thing I told you to do last time, right? And so that's the other part of finding great mentors is people who are consistent and have— are going to hold you accountable to say like, hey, I told you what to do, or I told you what I thought you should do. If you come back to me with the same problem or nearly the same problem, like, I'm gonna give you the same thing.

We talked about this. So that's been super helpful, and certainly as the company's progressed, The type of people we look to for mentorship has grown and changed. Here locally, we have a few companies that have had great success like Rally and others. Brian, our CEO, has some relationships with Tim Miller, former CEO of Rally, and folks like that who have gone from this stage up to the next stage. That's kind of the other key thing is you can't that somebody who is the right mentor to help you get a company from $0 to $1 million is going to be the right mentor to get from $1 to $10 or from $10 to $25 or $25 to $100.

It's, it's a constant process of kind of cultivating people that you trust. And fortunately we have, because we've had a number of companies in security and outside of security here locally that have done that, those people are out there. And being Coloradans, they're generally very willing to share. Yeah, yeah, excellent. That's really good advice.

So tell us about kind of what's in store at Red Canary. Sure. You know, what you can share for the last couple of months this year and beyond. There was a bit, you know, you've raised a decent chunk of change back in spring, so kind of curious what growth plans you all have for the future? Absolutely, yeah.

I mean, it's an exciting time for our business. We've had a great year so far and nothing looks like it's going to slow down the rest of this year. We're a little different than most venture-funded companies that raise money and then immediately start attempting to burn it as fast as possible to get to the next round. We always look at it as raising money to give us more freedom to take a bit more risk and try things that may or may not pan out and try to make sure our core business is growing and working efficiently. And so that's really what it is for us right now, is figuring out what are the other dimensions we want to potentially add to this business, whether that's additional product lines or it's, you know, maybe it's just growing vertically, you know, inside of our same product, adding additional features and capabilities that are our customers need or want.

So there's a big product component to it. There's certainly a growth component to the rest of this year and staffing up our team to try to be ready to meet our targets for next year. So that's kind of where we're at. And then, you know, as is always true with Red Canary, we make sure we are doing a lot for the security community. So making sure there's blogs and open source resources out there that are coming from our teams that address issues that we hear from our customers and try to be a good citizen within the security community.

That's something we really operationalize and live off of day to day. So that's kind of where we're at. We've got lots of expansion to do in terms of our team. It's one of those things where, you know, we've been very responsible and been pretty lean as a company, and then you hit certain growth curves and it's like Wow, we just need like 10 more people tomorrow, right? I feel behind, even though you aren't, or you weren't yesterday, but you are today.

And so that's a big focus of mine, is making sure that the teams are in place to support our customers and go find the rest that we want to get to. Red Canary is interesting, I think, too, because we are not focused on getting to an acquisition. We're not focused on exiting the business. I mentioned early on that coming from that defense background, like, you have to be mission-oriented, and that's something that Keith, Brian, myself, like, we are and we always will be, is very focused on what our mission is.

Hopefully, and what we think that'll lead to, is really building a generational company in security that lasts for a really long time and does a lot of great things for its customers. Customers over the years. That's what we're focused on. Not focused on getting to an IPO or getting to an exit. Probably never will.

If those things come along the way, okay, but for us it's about single-minded focus on what we're trying to get to. That's excellent. That's really good. I mean, you guys are kicking ass. It's great to hear the plans going forward.

You mentioned staffing. I'll give you a chance to do a little free advertising here. Yeah, I've got a number of positions on your website. So, you know, if you talk about those, but also what do you guys look for when you're, you know, if anyone's listening that loves the brand and loves what you guys are doing and, you know, may have an interest outside of having competencies A, B, C, D, and E, right? You know, where do you take chances on people?

If they may not be perfectly qualified but they have it, you know, they've done this, they answer questions like this, or, you know, what types of things you look for in candidates? Yeah, it's a great question. I think, you know, obviously like skills are one thing and competencies, but for us, like, sound like a little bit of a broken record, but it's really all about that mission-oriented approach, right? And so we want people who are great to work with and so fit into our culture and our going to be customer-centric and focused on delivering meaningful outcomes for our customers because that's what matters most to us. And then people who are just driven to kind of run through walls and don't like to be told that they're not capable of X or Y.

That determination, we call it relentlessness, is really the core attribute of what makes Red Canary people who they are. Across our organization really like to provide a lot of autonomy. Not a culture where we're going to micromanage and really get in people's knickers. It's a culture where you're expected to take objectives, take results that you're meant to drive, and kind of go figure it out. Not that there's no help, but it's not a situation where people are looking over your shoulders a lot.

So that's the other thing we look for is people who can operate pretty autonomously and don't have to be fully self-driving, but definitely able to work kind of on their own. That's what it's all about for us. I could certainly go down the list of what we need, but the reality is we're expanding across all of our teams, looking for great software engineers, great site reliability engineers, and folks to keep the platform alive. Then on the sales and marketing and customer success front looking for great people to come in and kind of be part of our team and bring our message to, you know, the next pile of customers that we bring on, as well as really support and take care of the ones that we have. So that's great.

Yeah, so across the board, if you're— any skills that you have, we probably need them at this point. Excellent. Well, look, really appreciate making the time for us here. Great Great hearing your story, and we look forward to talking with you very soon. Cool, thanks a lot, Ty.

Appreciate it. All right, thanks.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes