All episodes

John Nellen, CEO at Todyl

Apple Podcasts Spotify SoundCloud

John Nellen, Founder and CEO at Todyl is our feature guest this week. News from Sphero, Related Development, National Cybersecurity Center, Ping Identity, Red Canary, LogRhythm and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9877 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 189 for the week of December 7th, 2020. Alex, we're, we're not quite back in lockdown, but it seems like we're moving in that direction.

Yeah, it does seem real close. I heard that California went back into lockdown. I mean, here, you know, they had to make up that new level so that we didn't go into lockdown. And we seem to be in about the worst spot pandemic-wise that we've been in. So, it's gonna be too long.

California does set all the trends, don't they? Isn't that— They do. They're always first. Everything starts there. Yeah.

Or Paris, which I do think Paris might have got there before us too. Anyway, so we are remote. We're following good social distancing rules by not being in the same zip code right now. We are distant, very distant. But even though we're distant, we're gonna have a lot of fun today.

Most definitely, we always have fun. Speaking of fun, did you know we have a Slack channel? We have, it's really almost 1,700 people who are part of this community where we really kind of share what we're doing in security in the Colorado region and use it as a way to talk silliness and ask for recommendations on technology, all kinds of good stuff. If you want to join the Slack channel and be part of that group, maybe you can be lucky number 1,700. Go out to colorado-security.com and click on the link for the Slack channel.

Yeah, I think if you like to have conversations with people, there is probably a conversation about something that you want to talk about there, but just about any kind of topic is in there somewhere. We also, on our website, colorado-security.com, We have a mailing list. If you'd like to receive an email, uh, with notification of the new podcast and the show notes, go to the website, scroll to the bottom, put your email in, and sign up for the mailing list. Love that. And of course, we'd love it if you would rate us and subscribe on your favorite podcast listening application.

That's one way you can tell people about the show. Another way you can do it is you can just go tell one of your friends, tell a coworker, tell a random person who you socially distance see somewhere, and we'd love to have new listeners. Yeah, um, if you'd like to do even more than that, uh, we would love it if you signed up for our Patreon campaign. Uh, we did get a, a new patron this week, which is pretty exciting. And, uh, you know, I, I love it when we get those.

Um, this is what we do to help defray the costs of putting all this stuff together, uh, hosting costs and equipment costs, other things like that. So Um, we would love it for you to, uh, go sign up for that as well. If you sign up for the $10 a month level, you will also get a cool t-shirt and a shout out on the show. And, uh, last thing, we'd love it if you want to give us a, a Christmas gift this year. I think the thing we would most like would be, uh, for you to do an interview for the show.

Um, one of the great things we've had the luck over the last couple years is some awesome members of the community just like you who have, uh, who have gone and talked to other folks in the community who they thought should be profiled on the show. And that way, it's not Alex and I who are doing every one of these interviews. If you're interested in doing that, reach out to us on Slack or an email, and we would love to set that up. Yeah. So I think our last piece here is to, to call out our new patron for this week.

And that patron is Daniel Ayala. So Thank you, Daniel, for, for signing up to be a patron with Colorado Equal Security. Um, a great member of our community, and we appreciate the support that he gives us. Yeah, a big, big thanks, Daniel. We really do appreciate that.

All right, let's jump into the news. Uh, you know, we like to start off with some stuff that's kind of fun. I actually really enjoyed this article, and I think it might be worth— you know, usually we are pretty cursory. I think we could go through most of this here, uh, on the show. Um, this is a, a write-up by Colorado Inno, uh, which is now part of the Denver Business Journal, talking about gift ideas if you want to buy your Christmas gifts just from Colorado startups.

Yeah, and you know, when I think of startup, I think of technology startup, but that's not exactly what they're talking about here. A lot of these are not technology related, which is good because there are lots of good gifts here that are not technology. You know, we've got a couple here in the food category. First, Blonde Beards, which I think we've actually talked about on the show before. They make hot sauces, including an IPA buffalo hot sauce, and Little Secrets, which is a chocolatier.

Yeah, that one, those sound really good, and I know my wife would love the Little Secrets chocolatier. I went down the next section, which is around the, for the thirsty one, around drinks. There's one that's, do you love that hoppy beer flavor but you don't want the alcohol? Well, look no further than the hop tea. It's Hoplark's hop tea.

So if you want to get the hoppiness of beer without the alcohol or beer, You can have some tea that apparently tastes as disgusting as hoppy beer does. I, I'm sorry, that's like my least favorite part of beer right there. Yeah, uh, moving down to the gadgets, gear, and tech section, uh, we have another couple products we've talked about before. One is Butterflies with a D. Uh, these are the, uh, the headphones that are, uh, supposed to fit better so they give you better sound quality. And then also, uh, Josh.ai, which we talked about last week or maybe the week before, which is, you know, high-end in-home sort of entertainment, you know, like an Alexa or something like that to help control your AV products.

Yeah, I remember when we talked about it last time, the big differentiator for them was that rather than being big, that they focus on being really small with their technology. The next one on here in the tech area is Rover Products, and it looks like it's basically like Colorado's version of a Yeti cooler. That's what I think I'm reading here. Highly, you know, bear-resistant, Made for outdoors, puncture-proof tires, 10 days of refrigeration. Pretty cool stuff.

Yeah, one of the other ones that's, uh, sort of near and dear to me, Bond Pet Foods. They have animal-free, protein-rich pet food that you can get. They're based out of Boulder. Having some pets myself, I think that that's a good thing. Yeah, uh, if you scroll down, there's a couple of hygienic ones.

So, uh, they have— there's a company here called Wipeez, which does wipes here just in town, non-toxic wipes for, for travel and cleaning needs. And then there's Spinster Sisters, which is a local company that does a line of sustainable soaps, bath bombs, and skincare products. All kinds of cool stuff. Yeah, so support your local Colorado startups and, and find some good gifts while you're at it. Yeah, we love that.

All right, uh, next we have a a few Denver-based foundations that are joining to help keep rural movie theaters open during the pandemic. Yeah, you know, I had— it never even occurred to me that obviously, now that I read it, obviously this, this industry is just getting crushed. And it's for rural cities who have movie theaters kind of like the main street of those towns. The movie theater is often right at the heart of that. And through the pandemic, they're just not there.

Obviously, they're doing terrible. They can't, they can't stay open. So this, this is a A few different organizations. So the, the, is it Boettcher Foundation? Um, the Gates Family Foundation of Denver and the El Pomar Foundation of Colorado Springs have joined together, uh, with a government, uh, organization to offer aid to those organ— to those movie theaters.

So there's somewhere between 25 and 35 theaters across the state. They're gonna get grants, um, as much as $12,500 just to, to stay open through the pandemic. Yeah, this is pretty cool. You know, I grew up in a small town that has this kind of movie theater in it, and, you know, it was definitely, you know, a gathering place in the center of town, and you don't want these things to go away because we have a, you know, temporary issue like the pandemic. So seeing people step up like this is great.

Love to have those movie theaters available after all this goes away and people can go back and watch movies. Awesome. So This next one that needs a little bit of a preface, I think. I'm sure you're aware, and I'm certainly well aware of, Time every year does a Person of the Year award. Um, and, uh, you know, Person of the Year last year for the first time ever was a kid, and it was, uh, oh man, I'm not ready to say her name.

Gretchen Thunberg. Thunberg, thank you. The woman who's been very— or young, young woman who's been very active on climate change and trying to get, you know, PR around that. So this year, for the very first time, Time has chosen to select a Kid of the Year. And unbelievably, that award has come from Colorado.

Yeah, so Gitanjali Rao, who is a young scientist and inventor who attends STEM school in Highlands Ranch, she's 15 years old and she was named Time's first ever Kid of the Year. Yeah, it's amazing. So yes, she attends STEM school and she's 15, and that by itself is amazing that someone 15 years old is able to do this. But she's been, she's been like on the national stage. At least since she was 13.

Yeah, because I know, I know we've talked about her on the podcast. I think we talked about when, when she did the, uh, uh, a clean water invention in here. I think her clean water invention is the thing that's given her the most publicity. But, uh, she's, she's— so I have a, I have an 11-year-old who actually goes to that same school, and I was like, hey, you should see, so one of your classmates won this award. And I pop open the video and show him, um, And she starts describing the nanotechnology that she's using to clean things, and I can't even use all the words she used because it was, it was very complex.

And he's like, what is she doing? Like, I mean, there's just no way, considering the age of her and the things she's already done. It's just, it's over the top, super, super impressive. And a big, big shout out to her for, for being recognized, and hopefully we're going to get to talk about her every couple years for a long time. Yeah, one of the newer things that she did too is we— she created, uh, an app to help with, uh, cyberbullying, bullying online.

So that's pretty cool as well. Yeah, good stuff. All right, uh, next, uh, we have a story about the Sphero, uh, spin-off that I believe we talked about when it happened, Company 6. But they've, uh, released their first robot for first responders, and it's a, uh, it's a throwable, which sounds funny, mobile video robot. So you can take this and you could say, I don't know, throw it into a building where there's a fire or something like that.

Yeah, it's only 1 pound. And really the idea is it becomes a set of eyes that you can send into a dangerous place. You can have as many folks as you want streaming and watching what it observes. And of course those people are able to stay out of harm's way and really kind of, how do you find the, the people who are trapped inside of a fire, you know, how do you, how do you look for these things in a really dangerous area? Well, now we can not have one of our first responders have to put their own, their own selves at risk.

Uh, really cool stuff. Um, it's, it's using first responder networks rather than, or rather than just using, um, commercial networks. So, right, um, pretty cool stuff. It is pretty cool. All right, uh, moving forward, uh, there's a new company moving to town.

So a national apartment developer called Related Development. I didn't know them, but I guess that's not a surprise. I don't know a lot of big apartment developers. I know all the apartment developers, Robb. I'm very familiar with these guys.

So, Related Development, you must be excited to know, is coming to town. They're going to have Denver be their kind of their second headquarters. Yeah. Thankfully, they didn't say HQ2 or something like that, but this is their West Coast headquarters. They are based in Miami, and it sounds like they do sort of upscale kind of apartment units.

So, they said that they're going to be based here and also doing some work in Denver. So, they're going to be creating some luxury rentals most likely here, obviously, as well as being the base for other West Coast operations, but also going to be looking at building— this is funny— some more attainable housing as opposed to affordable housing, because it probably won't be affordable, but it's going to be nicer housing that is more attainable. Sounds pretty good. And I did look in the article to try and give the relevant stats, like how many Denver employees they have now and how many they're planning to hire. They didn't share that in this article, so I don't know if that means there's no one here yet or what, but the article did call out that they're planning to have a partner located here in Denver to head up that practice, and that person is not yet identified.

So more to come on that. Nice. All right, moving on. There is an announcement from the National Cybersecurity Center down in Colorado Springs. They have named a new CEO who is a retired Air Force Lieutenant General.

This is Harry Radwidge, who is in Colorado Springs and taking over there for Vance Brown, who had been CEO for a couple years. I think not necessarily by choice, he had kind of taken over as an interim basis and, you know, just kind of hung around for a little while. So now they've got New person there to take over the reins. It sounds like he had been involved with the NCC for a little while, coming up with a strategy for them for, you know, strategic plan, and then they hired him to be CEO. Yeah, this is really, really interesting stuff.

I don't know this gentleman, but he definitely has an impressive resume. He was one of the— they say kind of one of the fathers of cybersecurity within the military. He was the director of the of DISA, the Defense Information Systems Agency. He was the chairman of the Deloitte Center for Cyber Innovation, and he was a managing director over at Deloitte doing cyber risk services. A lot of good background there.

There, a little bit more about Vance Brown, who did this for— it was actually 3 years. If you remember, we had him on the show right at the very beginning of his tenure. Yeah, so pretty hard to believe that was 3 years ago. Pretty crazy, right? I, I was shocked.

It says he's been here 3 years. Uh, under his tutelage though, the organization grew from, um, 2 employees to 14. And they, they actually called out some other stuff he did. Uh, they launched the Space Information Sharing and Analysis Center, which I think that just happened this year. I think that was one of the most recent things they've done there.

Yeah. Um, they also started a program to make mobile voting secure, uh, through technology to be used in elections. I don't know why blockchain technology is part of that, but apparently it is. Uh, they began a program to make smart cities more secure, and they also initiated a workforce development program, um, to help combat the, uh, this skill shortage. So a lot of programs got started down there, and hopefully Harry comes in and keeps those things moving forward.

Yeah, and Vance is not staying around. He is going to be— well, he's going to be close by, but he's going to be now the chairman of Exponential Impact, which is sort of an accelerator down there on— for cybersecurity and other types of technology pieces. So Awesome. Good to see news coming from those guys. Next piece of news is another Denver security company.

Ping Identity has been named a leader in the most recent Magic Quadrant from Gartner. So you guys, I mean, we all know Gartner does their magic thinking around where folks go, and Ping did great this year. The number 1 company on ability to execute in the quadrant. You can see, you know, most of the way up to the upper right. Significantly higher than last year.

It's pretty cool to see that kind of improvement in the IAM category. Yeah, congratulations to you and to Ping for continuing to put out great products and for being recognized by Gartner. Good stuff. Next, we have a blog by Red Canary. This one is another good blog by them talking about how to detect Yellow Cockatoo, which is a .NET remote access Trojan and some other things that they've been seeing.

This is also a collaboration in terms of some notes with another group from Morphisec who has been seeing some similar activities. So lots of technical detail in here. Again, one of these great Red Canary blogs that talks about the actual detection opportunities, some IOCs, exactly what to look for, things like that in terms of finding what they're calling Yellow Cockatoo. Yeah, they do mention this is one that, you know, I'd never heard of Yellow Cockatoo. I think that they just recently named it that, but they said that this is one of the highest or most commonly recognized threats that they're seeing for several months now.

So, you know, this is something that might be worthwhile for you to send to your security operations team to see if it's something you guys are experiencing in your environment. Pretty cool. All right, moving forward, we have a blog post from LogRhythm this week talking about the state of data privacy and what that looks like like in different states. Yeah, and the question that they're sort of asking in this blog is, do you have rights to your data? And not like in a philosophical way, but basically, you know, where you live, in our case, Colorado, or potentially most places in the United States, is there actually legal recourse for you to ask companies either for, you know, give you your data or, you know, remove your data, things like that?

Obviously, we know GDPR is in place and CCPA is in place in California, but, you know, this blog is a bit of an experiment actually. So they actually made some requests to various companies from people of different places to see what they could get in terms of seeing what data companies had on them. So pretty interesting— I was going to say thought experiment, but actual experiment there. Good stuff. Our last story for this week is, uh, is actually a, a link to another podcast.

So it's— this is pretty meta. So we are— we're on our podcast, we're going to talk about a podcast. Well, about a podcast that's about a podcaster. So, so Doug Brush, Douglas Brush, who— he's, you know, local guy who is pretty very active in the, um, the Colorado Equal Security community. Um, he's all— he's got his own podcast called Cybersecurity Interviews, and he was interviewed on a podcast called Digital— or Forensics Focus, rather, really talking talking about his own career.

He talks about, you know, gives some advice around career paths, whether you should go generalist or specialist and kind of how you do each of those. He talks about training, you know, what training makes sense and how do you use limited training budgets. Talks about mentoring. And of course, you know, Douglas is really big on trying to get new folks into the industry. And I think that's another focus of this conversation.

And so, for anyone who's considering getting in, this might be a good one to listen to. Yeah, and I would say if you're sitting there thinking, oh my gosh, another podcast to listen to? I mean, I only have time to listen to the Colorado Equal Security Podcast every week. Well, you are in luck. The link that we have here actually has a transcription of the podcast too, so you could actually read it instead of listen to it.

Yeah, that way you don't have to listen to people talk. That's the worst. Couldn't agree more, man. I hate people talking. Hey, speaking of, uh, people talking, let's talk about the Slack message of the week.

Um, A big thanks to Andre Gaeta. Every week he's, uh, he's using his own money to recognize folks who are continuing to move the conversation forward in the Slack channel, um, and, and he pays for a, uh, an item for each of those people out of the Colorado Equal Security store. Um, this week, uh, we're recognizing Flint. Um, Flint has, uh, was sharing a little bit about his own professional experience on trying to get his company to be better at shifting left and, and kind of adopting that DevSecOps mindset. He talked a little bit about how they do that, and he also does a shout out to RMISC where he, you know, we had a DevSecOps workshop there for the last few years.

We've had it, I think, and he learned a lot there, and I think it's a good conversation and certainly love to see people getting value from those types of engagements. I love it when we put out something that we think is going to be interesting in the community and someone sees it and absorbs it and actually uses it to make a difference. Yeah, it doesn't happen enough, does it? It's nice when it does. We don't hear about it enough.

One way or the other, probably doesn't happen enough and we don't hear about it enough anyway. All right, congratulations to Flint. Thanks to Andre for supporting the Slack Message of the Week. Let's move over to events. We are getting really close to the end of the year and events are getting thin.

Normally, this would be a time of year when I think we would have a lot on here, when everyone is doing their, you know, in-person holiday events and happy hours. And we've got a few, but not nearly as many as we would if we could get together in person. But we will persist. So first, on the 8th, there is a Colorado Equals Security poker night. You go.

Yeah, this is awesome stuff. Jason Jaques has been putting this on for us for what I feel like it's been most of COVID that he's been doing these every month or so. It's a good chance you do come and yet you have to bring your own money. I think it's like $20 per person who participates, but there's a prize that money all goes back out to the winners. And I believe that the company that he works for, Chorus360, also kicks in a bottle of booze for the winner.

So there's a little bit on top. Anyway, that's the 8th. Also on the 8th, CSA, the Cloud Security Alliance, is doing their December meeting. On the 10th. The Northern Colorado ISSA chapter is doing their December chapter meeting.

Uh, on the 16th, ISC2 Pikes Peak has their, their, uh, annual meeting. On the 17th, ISSA Colorado Springs is doing their December meeting and chapter appreciation. And I think the last meeting that we— to talk about of the year is, uh, on the— also on the 17th, ISSA Denver and ISACA Denver is doing their annual joint holiday meeting. This is, uh, you know, Alex, you and I were both President of ISSA Denver, and this is one of the big events of the year for, for both chapters. Uh, in person, it was, it was always wonderful to get to see those folks who, you know, if you're in ISSA, you might not see the ISACA folks all year, and it was always really nice to, to see them.

You know, other than RMISC, there's just not a lot of joint stuff. Uh, so this is a really— what was a really cool chance to do that. I'm looking forward to seeing the format they use this year, and hopefully folks from both chapters can, uh, can make that work. Should be a good time. All right, uh, let's move over to jobs.

Robb, are there any Ping Identity jobs this week? It's funny, I've had a few jobs every week for a while now. We must be near a new year and a new budget coming free. Uh, so I have a few things I'm hiring. I am hiring a manager of GRC focused on privacy.

Uh, so if you want to help run the privacy program at Ping, I'd love that, that to talk to you. I'm also hiring a manager of GRC focused on programs, so someone who would do like our SOC 2 audits, our ISO audits, policies, standards, and all that good kind of the meat and potatoes part of GRC. And then the third thing we're hiring is a product security engineer, someone who's got, you know, maybe think of it as an appsec engineer. If you have an appsec background or development background and you want to get more into security, that's the role for you. All right, Otter Products is looking for an information security analyst.

The Colorado Judicial Branch is hiring a manager of information security. InteliSecure is looking for a vulnerability management program lead. United Launch Alliance is hiring a cybersecurity analyst 3. Smarsh is looking for a senior information security analyst. Smarsh, that is a tough name.

Yeah, Smarsh. Uh, Agon is hiring a, uh, a senior information systems security analyst. And Aegon, you know, you might not know the name Aegon, uh, but they are the parent company that owns, uh, Transamerica. So it— they, they're, they're actually in the same building as the Transamerica building down in downtown Denver. Big company, a lot of really cool opportunities.

And finally, OpenText, uh, in this case that is, uh, the Webroot business unit at OpenText, is looking for an advanced threat researcher. All right, well, I, I think that's it for jobs, and that is it for news this week. Um, we, we've, we've completed the podcast Other than, Alex, we do have an interview this week, right? We do. I was actually able to interview John Nellen, who is the CEO and co-founder of Todyl.

That's T-O-D-Y-L. They are a startup that just moved here to town from New York. I believe we talked about that maybe in May, June when they were doing that, and finally had a chance to get together with him and had a nice conversation. Well, I'm looking forward to hearing that, and, and I remember us talking about them, but I can't for the life of me remember what they do, so I'm excited to figure that out. Well, you will hear in this interview.

Cool. All right, Alex, well, that's it. Uh, we'll look forward to talking to you again next week. Sounds good. Thanks, Robb.

Thanks, everybody. Hi, this is Chad Payne, Executive Director of IT Operations for Kraken Sports and Entertainment. Welcome to Colorado Equals Security. For Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security.

This is our feature interview, and this week we have a special guest with us, John Nellen. Welcome, John. Glad to have you on the podcast. Glad to be here. Thanks for having me, Alex.

Yeah, glad we could finally connect. You know, we've been trying to make this happen for a little bit, so I'm glad it finally worked out.

You are the CEO of Total, which is a company that's pretty new here in town. Very new. Yeah, very new. I think you guys, you just moved here, I want to say in August or something like that. Is that right?

Yeah. So basically June to August, we moved in waves just to keep everyone safe with COVID But yeah, we moved from Midtown Manhattan to Denver. So what was that like, I guess, first, moving in the middle of a pandemic, and then second, how has it been in your first few months being here in Denver? Yeah. So I guess everything, all the moving companies, everything was very busy.

There was a lot of people leaving New York at the time. So it was scheduling challenges and things like that, but nothing too different. I mean, we were in the summer, so things were a little bit more open than in the winters and things like that. So we didn't have to find space on Zoom or anything like that. But yeah, it was certainly challenging and just making sure that we did it in a safe and efficient manner was not easy.

We love it. The whole team loves Colorado. We love Denver so far. It was almost like a natural fit for us. We were talking about different locations and this had nothing to do with COVID We were talking about this December of last year and just going forward with capital efficiency, right?

You know, we're a company that works with MSPs and MSSPs and then sell to small and medium businesses. So how can we make the most of, you know, the funding that we had, right? And yeah, we were looking at a couple different places, landed on Denver, and everyone was just really excited about it. Awesome. Yeah, well, you know, we're glad to have you here.

That's a great story, and we're gonna dive into that a little bit more, but I wanna get a little bit background on you first before we get there. So I noticed that this is not the— Total is not the first company that you have founded. Seems like this is a thing for you. Maybe talk a little bit about your background and, and, you know, some of the stuff you've done, you know, prior to founding Total. Yeah, sure.

So I've been in, you know, networking and security space for probably about 15 years now. I had a startup. I think what you're referring to was actually I was in college, TXT160, and Essentially, it was a crowd-driven messaging marketing tool for local businesses where they could promote deals and then people would show up and things like this. This was before Groupon and before Flash Deals and everything else like that. It transformed into more of a question and answer system for large stadiums and trivia and things like that.

We sold that. But yeah, I mean, kind of my journey was really around, you know, kind of started in software working for financial services companies and then worked at Cisco Systems for a little bit. And then after that, worked at a large HR services provider where I ran security and technology for a while. And, you know, was fortunate enough to be able to see, you know, what everyone's interpretation of, you know, best practice world-class security was. We worked with, you know, about 70% of Fortune 1000s, so there's a lot of due diligence, a lot of compliance, and basically got a pretty good perspective and, you know, realized over time, you know, the security program itself is just, you know, becoming more expensive, more complicated, and I believed it didn't have to be.

And that was really the catalyst for starting Total, was to change that.

That's awesome. I think one of the most interesting things there is that you started that that first startup of yours during college. I think for me, I was much more interested in drinking beer and hanging out than being productive in my college years. So I'm pretty impressed by that. Was there something in particular that drove you to do that during that time, or what was the background there?

Yeah. So I was more on the technology side. I thought it was a great business idea, but it was really just my passion for learning more about technology, and this seemed like a great vehicle to do it in. And this was pre-cloud, right? So I had literally, it was a server rack in the closet of my apartment.

We had to disconnect the garbage disposal and run extension cords so we could power everything we had. I think one month we had like a $500 electric bill or something silly like that. It was extremely inefficient, but it was really just passion-driven, right? It was about learning as much as I could, And just the culmination of building something from the ground up. I had the opportunity to build the infrastructure, build the website, build the interactive texting and everything else.

So yeah. Yeah, that's pretty cool. I'd imagine based on that, while it sounds like it was successful, you probably made a couple mistakes. What were some of the things you learned from that first startup? Yeah, I think, and again, I was pretty young at the time, but Just the business versus technology mindset, right?

And just embodying the idea that the technology supports the business, not the other way around. Probably sounds silly, but as I was 19 at the time, things like that, it's pretty easy to lose track of it. But yeah, I mean, just, I guess that was probably the biggest one, right? It was just that perspective and focus on what the purpose is and how to fuel the business versus how to fuel technology. Since it was a big hobby and a passion of mine, it was a little bit easy to get distracted and go down different paths that obviously weren't optimal for the business.

But yeah, that's what I would say. Yeah, that's a great one. I think myself coming up as a technologist, it took me a long time to learn that part of it too, is everything for me was sort of technology-driven. So that's a great lesson to learn for sure.

You mentioned a little bit about it in your previous answer. What is it that really drove you to, well, one, to start Total, but also just to be an entrepreneur again? Because it sounded like you were working for some companies in between there. Yeah. I mean, I really believed in the idea and I saw a very big problem.

And did it over time. So kind of worked nights and weekends for a year on prototypes and things like that before we were able to do our first round of funding and move over full-time. But yeah, I mean, I just really believed in it, saw a big problem, and the more people I talked to, the more excitement there was, and just decided to run with it.

Nice. And I've I've seen many people sort of do the similar thing where they have an idea, they start working on it, it's kind of a second job. What was it that led you to think that this was going to be successful and really move forward with making it a business?

Yeah, that's a good question. I mean, it honestly was It was a problem in the market opportunity, and I believe there wasn't a great solution for it. Doing it on the nights and the weekends, most of it didn't really amount to anything. It was just more of proving it out, seeing the difficulty of it. I think at the start of it, I started out with, how hard would it be to do this, with an MVP mindset, and took it from there.

But yeah, it was just the excitement that we saw and just the scale of the problem that that has kept us and continues to keep us very excited and very motivated to kind of, you know, running towards this vision that we have. Yeah, you know, so with that, maybe I think it's time now to talk a little bit about, you know, what Total is and, you know, what it is that you guys are trying to do. Yeah, sure. So in short, we combine multiple networking and security point solutions together into a unified security cloud platform for MSPs and MSSPs, right? So the core of our platform is what we call Secure Global Network cloud platform.

It's basically a SASE platform, and we have integrated SIEM and GRC, governance, risk, and compliance, but it's all built and focused on the MSP and MSSP channel for those who sell to small-medium businesses.

Nice. And so my assumption here is the problem that you saw was, you know, something related to, you know, many businesses, especially smaller, even medium-sized ones, they might not have the resources themselves to really come up with a technology solution for all of these different pieces, right? So they would obviously need a large team and maybe they would go to a service provider for that, but it sounds like maybe that this particular piece was not available in the service provider market. Yeah, it wasn't, right? And kind of taking a step back and looking at the channel, service provider channel, a lot of it's kind of tool-focused, right?

Very narrow point solutions where you have some sort of a VPN tool, a secure RDP tool, secure DNS tool, right? Then you'll have a firewall and you'll have, before you know it, you have 10, 12 different products that don't really talk to each other. They're all independent, right? And it's super inefficient and it just gets more and more expensive over time and that creates these difficult decisions, right? What do we take out?

What do we leave behind? And we came in with the perspective of, you know, there was a need for a platform, right? How do we start tying all this together in a single place to help the channel, you know, make it easier to operationalize and implement best practice security?

Yeah, so I am curious, my technologist side, how did you guys go about, you know, trying to solve this? Did you Did you start developing all these individual, I guess we'll call them point products yourself in a combined platform? Did you go out to the market and take products or open source that was already there and then try and pull them together in a platform? How does that part work? Yeah, so it's a little bit of all of that.

We actually started out as a hardware company. So back in 2016, 2017, we were approaching this from a hardware angle, which is very difficult for startups and also wasn't really solving the platform, right? Because it was creating a lot of the complexity and costs that we were trying to get rid of. So we basically kind of ported this engine that we created into the cloud. And then I guess, what, 3 years later, it's now called SASE, right?

But yeah, we moved into the cloud and we just kept adding additional features and functionality to it, whether we developed it in-house from the ground up, whether we kind of ride on top of open source. Yeah, it's kind of a mix of all of that, but that's what really powers the engine there. Yeah. So I think I have the most important question that's going to come this entire interview, which is, what is your opinion of the term SASE? Yeah.

So I mean, I think it's great to be able to call us something and call that kind of product something.

It's interesting, right? I look at it as, you know, just the confluence of networking and network security together in the cloud, right? And just kind of aggregating all these different solutions together. I think it's super helpful. I think it makes sense.

I think it sounds kind of cool too. It's catchy. Yeah, so I'd imagine that most people listening know what the term means, but, you know, how is it that that you would define from your perspective and I guess from your product perspective? Yeah, the way I usually describe it, I'm not sure if it's more clarifying or confusing, is bringing the edge down to the user, right? And just bringing the edge down, right?

So the idea of combining together different elements of SD-WAN, cloud VPN, secure web gateway, all the different features and functionality kind of molding them together, but the idea being that rather than having kind of, you know, like a single network, single edge that all the traffic is flowing through. You're able to bring it closer to the users to deliver better performance, you know, better security in an environment that's, you know, more distributed than ever. We call it the everywhere and anywhere kind of, you know, working paradigm now. Nice. Yeah, and I know, you know, there are many providers out there that now do provide SASE or you know, whatever you want to call these solutions.

Sure. Is there— granted, you're not— you know, many of them are marketing directly to enterprises or small, medium-sized businesses, you know, which you guys are not. But, you know, what is it that makes your platform different than, you know, one of these other platforms that's out there already that someone could just go out and buy? Yeah, absolutely. Well, there's a number of different things, right?

So, you know, first is just the broad spectrum nature of what we're doing, right? So we're not just SASE, we have other components that we're combining together into this unified platform for the channel. But beyond that, there's, you know, a lot of products out there that, you know, you can kind of spin up an instance in AWS or a cloud service, right? And then you kind of deploy the agent and everything goes through there. But those tend to be more of like a zero trust SDP solution.

Then you have more of the enterprise providers, right, which are, you know, true SASE, but they're, you know, complicated, expensive. Some of them still rely on hardware in order to to make that happen. The way that we built this was, you know, to be pure software, right? To be endpoint-driven and to create the ability to have like a full mesh network, right? So every device gets its own static cloud IP.

So you can have devices talking to devices and everything else, which is powerful, right? Since, you know, look at the small and medium business, a lot of them are going, moving rapidly towards cloud-first, right? So being able to have, you know, a cloud-native networking and security platform that, you know, kind of capture and integrate all those different things together. Yeah, and I'm curious also, everything that you said makes sense to me. However, I'm not sure how much sense those differentiators would make to someone that is, you know, more on the purchasing end of this.

Sure. How is it that you guys, you know, help translate that into a, you know, a more more business-centric language so that people can understand what it is that you're actually delivering? Yeah, so I mean, it's almost like a double hop, right? Because when we talk to our channel partners, right, it's a different conversation than when they talk to the small and medium business owner, right? But the way that we designed it and the way that we built it is truly a platform for MSPs and MSSPs, right?

So you can white label it, you have all of these different solutions together, but what we do is we help them compress their stack and eliminate a lot of the tooling that exists so that they can have something comprehensive. Yeah, I'm sure that's a great proposition for them.

I am curious what sort of challenges that you have run into as part of this. It's one thing trying to create a product to sell to someone. It's another thing to create a a product that can be multi-tenant, that you can sell to multiple companies to resell to multiple companies, that seems like it would be a pretty daunting task. Yeah. I mean, that was our biggest challenge and continues to be one, is that we do a lot.

So when you're a startup, usually the idea is to focus on something very narrow, MVP, go to market, grow. Whereas we decided to almost do the opposite where we went wide. So it took us a while to go to market. There was a lot of R&D behind it, a lot of money to fuel that, that went into it. But yeah, I mean, going wide versus narrow was the only way that I believed we could solve this problem, and it was very difficult to get to that point.

Yeah, I can imagine. I mean, the other thing that comes to mind for me is you know, you guys are a startup. I'd imagine you're still fairly small. And, you know, most startups in that stage, they are worrying less about their own security. They're more worried about, you know, getting a product out and, you know, getting adoption of that product.

Whereas, you know, you guys providing a product that does security in some senses, How is it you make sure that you are building the right level of security into your product for your customers? Yeah, I mean, I think it's a great question and probably going to be a pretty lengthy answer.

Yeah, I look at it through a couple different lenses, right? There's one, how do we at Total keep ourselves safe, right? And that's our responsibility to, you know, protecting not only our business but the platform and everything else for for our customers, for our partners, but then also how do we create the best possible platform for them to then deliver to protect the small and medium businesses with, right? So yeah, I mean, we drink our own champagne here at Total, right? We, you know, we use Total internally, we use it through and through, and it's a balance of, you know, just taking more time to plan, right?

So it's, you know, measure twice, cut once, and, you know, making sure that we're approaching any new modules, any new features that we're adding to the platform correctly with inherent security versus sometimes startups are just running at 100 miles per hour. We're a little bit slower than probably some others, but there's a method behind that. And the method behind that is just to make sure that we're doing things right from the start. We also have a number of different partners that we use to make sure that we're not in an echo chamber, to have an external perspective on architectures and everything else. But yeah, I mean, from that perspective, Again, a lot of our backgrounds come from the security space, right?

So we kind of had it in our DNA to kind of do this right, and that's really what leads us there. Yeah, yeah. And then I am curious, you know, as you go down this road and you mature the product more and more, you know, your market has been managed service providers. Do you think there'll ever be a time when you start doing more direct sales or enterprise sales or things like that? You know, someone might, you know, first, for example, use this as part of a managed service provider when they're at a, you know, a smaller business and then go to a larger enterprise and go, man, I really want to use Total still, but, you know, we're, you know, we have our own team.

We don't, we don't need this managed service provider. Yeah, yeah, that's a great question. We have a lot of work to do. To get to where we want to be and really fulfill our vision of getting this platform to where we want to be for the channel. I think there's a number of aspects of the channel, but we're committed to the channel right now and going forward.

That's awesome.

Speaking of that, I think I'd love to know a little bit more about where you guys are as a company? I know that it sounds like you're still fairly small, fairly new. How big are you guys? What are your plans? Are you growing?

Stuff like that. Yeah. I mean, we're growing tremendously fast.

So can't give away any specific numbers, right? But yeah, I would just say, and then on top of that, yeah, I mean, again, so We're channel only, so all the partners that we bring on, they have their small-medium businesses that they then go and sell to, and that helps create kind of this multiplier acceleration type path, right? Because we work with one partner, it's like working with 30, 50, 100, or even more small-medium businesses, right? So that's why we love the channel and we're committed to it. Yeah, and how big are you guys in terms of employee base and things like that?

Are you And I guess, I don't know where you are in terms of stage of that sort of thing. Is it all in-house? Are you outsourcing some of this stuff or how's that part working for you guys these days? Yeah, no, we're all in-house. We have about 10 people and we're looking to hire 5 more.

So now that we're in Denver, we're aggressively hiring, looking to meet the right people and continue to grow total. But those 10, did they all come with you from New York to here? No. Some of them came from Denver, some of them came from the Bay Area, but they all moved here. Nice.

That is pretty cool. And now you're all here in Denver and can't see each other.

Exactly.

Yeah. No, that's great. And you talked a little bit about it earlier about why you moved to Denver. In terms of maximizing capital. I've got to imagine it is very expensive to run a business out of New York City.

What was the reasoning behind Denver specifically that made you guys want to come here? Oh, the talent. It was almost an easy decision. So there's a lot of different channel companies that are in the Denver-Boulder area, but on top of it, a big push was for the talent. So just looking at, you know, the available cyber talent, things like that, Denver seemed like a great fit.

Nice. Um, I, I'm curious, as you, uh, you move on through, uh, through hiring and, uh, and growth, you know, what does that— the, the next stage look for you guys? Just, uh, you know, continuing to plod forward, adding incremental functions and things like that, or do you guys have larger plans for what's coming next? We have pretty lofty plans, and as we continue to hire, we're building out teams to attack different areas and additional kind of tooling that exists that we can continue to grow and consolidate into our platform. Yeah, and I know you're not going to give away any secrets, but but what are some areas in general that you think are being underserved in the cybersecurity market right now?

So obviously you mentioned that you guys have several pieces to the platform already, whether it's things you're gonna add or other areas that you think people aren't doing enough or there's a gap today. Yeah, I think segmentation, right, especially internal segmentation is a big challenge, right? How do you, how do you get that right? In the SMB world, visibility, right? So DPI and SSL inspection is, you know, there's very common gaps that exist.

Vulnerability management, right? The whole vulnerability management lifecycle for the channel, I think, is another opportunity too to help Yeah, I especially the— well, vulnerability management, that's one where, you know, it's been around so long you would have hoped that it would have been solved by now, but I think we all know that there are still problems in that area, right? So yeah, I think the— yeah, we're pretty good at finding what's wrong, but there's still the second half of making sure that it gets fixed. I think that's one of the biggest pieces in that area, but I definitely agree with you that segmentation, especially, you know, as you get smaller and smaller segmentation, you know, that's something that I think that everybody can use, especially those small and medium-sized businesses. Absolutely.

Yeah.

John, what have I missed? What should I have asked you that I haven't asked you yet?

No, I think you covered a lot of it. Something that's on our minds and what we're really thinking about is, you know, how does 5G play in with everything, right? As you know, especially since we've been hearing about it, right, for a while, it's slowly starting to come to reality. We're seeing that, you know, small areas have, you know, very good throughput. However, it's almost creating ubiquitous connectivity, right?

In major metro areas, you could usually find Wi-Fi, you can, you know, your hotspot usually works pretty well, but the idea of having these, you know, 5G-enabled devices, right, especially when you have, you know, very distributed organizations, that's something that we're, you know, we're really thinking about, we're really focused on because it changes the idea of the network, right? Especially for, well, really both for the enterprise and even the SMB, right? And that's something that, you know, we believe Total can really help with and something that we're digging pretty deep in. Yeah, I mean, I think it was one thing when the SASE-type vendors, you know, before they were called SASE, you know, started to come about as people were, you know, becoming more cloud-native, becoming more mobile. And, you know, it was like, oh, you know, the edge is moving closer and closer to these devices and And at the time it was kind of like, yeah, I mean, it is a little bit, but nothing's fundamentally changed.

I can see where if all of a sudden there is large adoption of 5G and it's everyone connected everywhere all the time, really that edge moves farther and farther out and you really do need something that can work with all of those devices that are constantly connected. Yeah, absolutely, right? And it's been a transition over time where, you know, we've seen what I would call the rise of the unmanaged network, right? Where you have, you know, coworking spaces, you have, you know, home offices, you have, you know, on-the-go coffee shops, hotels, airports, all that good stuff, right? And it's been growing, right?

And it's creating a challenge of, you know, ensuring connectivity and security on the unmanaged network. And then 5G just takes that, you know, to the next step entirely. It only makes sense that we're going to have 5G-enabled devices.

I can't see it any other way, right? It's just, it's a lot more cost-effective for the telcos and for the providers. And yeah, I definitely think it's the path forward and a big opportunity too, right? So some of the partners that we have are looking into, well, how do you just drop ship 5G-enabled devices with Total, right? What does it mean to not have to set up the internal network, and what does the internal network really mean anymore, right?

Can you just move it entirely to the cloud? So it's a very exciting time overall. Yeah, things are changing fast, and it sounds like you guys are going to be on the edge of that, pun intended.

All right, well, I think we are getting close to time. John, it's been wonderful talking to you. Before we wrap up, you did mention that you guys are hiring. What sort of positions are you guys hiring for? Yeah, so we have about 4 senior software engineer positions across networking, security, full stack, desktop applications, APIs.

We have DevOps openings, and we also have sales openings as well. So come check us out, total.com/about, to see the job listings.

And I'm sure people will be able to figure it out, um, based on the, uh, the posting of this, uh, podcast, but Total is spelled T-O-D-Y-L. So, um, don't want anybody going to T-O-T-A-L.com. Uh, important clarification. Thank you, Alex. Uh, awesome.

Well, anything else before we get out of here, John? No, that's it. Thanks so much for having me. Awesome. Well, it's been great talking to you.

This has been Colorado Equals Security, and we will talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com. Info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes