Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a newscast for episode 164 for the week of May 11th, 2020. Alex, happy Mother's Day.
Yeah, happy Mother's Day to you too, Robb. Since we are both mothers, we can celebrate. Well, we can at least look at mothers across a table and say thank you. So thank you to Kristen and thank you to Tamara for, for what they do. I meant we're, we're bad mothers.
Yeah, we are bad mothers. There's no R in that word. It's mother. Yeah, that's true. Anyway, once again, thanks to them and we appreciate all that good stuff going on there.
Exactly. We do have some housekeeping type activities. Remind you guys that we have a Slack channel if you want to be a part of it. We got over 1,400 of our closest friends in the Denver and larger Colorado security community getting together, talking about all kinds of good stuff. This week has been hard to keep up with, a lot of good conversations.
We also have a mailing list, Robb, in case you didn't know. If you go to the website colorado-security.com, scroll to the bottom, there's a form for you to fill out with your email address to let us know you want to receive an email every week with the show notes. You'll be the first and only people to get those. You know, you know, we just have that whole website, colorado-security.com. That's a good place for you to spend, you know, let's say 10 minutes.
If you spent 10 minutes on that website, you could probably find just about everything going on there, and you'd get to know a lot about different groups going on in town and the events coming up. So I think it's worth spending a few minutes on that website just for all this kind of information. You know, extra clicks are appreciated too if you want to, you know, needlessly click on some things, that's fine. Raise the stats up. But don't DOS us.
We don't need that kind of clicks. No, not quite that much. You could also, you could also rate us and subscribe to the podcast on your favorite podcast listening service, whether that is through iTunes or the Google Play Store, through Spotify, or, you know, anywhere else where you can get fine podcasts. That way you'll get it delivered to your podcast player every week, and by rating us, you'll let people know that we're awesome. We'd also love it if you tell a friend about the podcast and about the movement, hopefully get those folks involved with Slack and into a bigger group.
We'd love to have more folks as a part of what we're doing. And of course, if you would like to support us financially, we do have a Patreon campaign. You can sign up for that and help cover the costs that we have at Colorado Equal Security. All that Patreon money goes back into producing Colorado Equal Security content and back into the community. A big thanks to those who are supporting us.
I'm so appreciative of those folks who are doing it. We know it's tough times right now, and we are thankful that those who do donate are doing so. So keep it up, and we appreciate you guys. Yeah. All right, let's go ahead and jump into the news.
First big news this week is Conga, local tech company here in Broomfield, they were acquired this week for $750 million. $15 million. Yeah, I thought that was interesting, um, kind of out of left field. I guess I don't really follow, uh, the market that Conga is in, so maybe there were rumors about it, but I hadn't heard anything previously. They were acquired by Aptus, which is out of San Mateo, and Aptus is owned by Thoma Bravo, which owns Logarithm also.
And they're actually gonna combine the companies but keep the Conga name. That's pretty awesome. And it's going— they do a lot of work process management, document management lifecycle stuff at Conga. This new company is really playing in the Salesforce world. I get the impression that they kinda work with and compete against Salesforce, kinda depending on the situation.
So obviously, it's a big world there and there's a lot of room, a lot of business. Exciting to see, and hopefully this is gonna be good news for the Conga folks. Yeah, I did think it was an interesting line in the article. It said, together, the combined company expects to compete better within the Salesforce market. Yeah, I, I guess I don't think of Salesforce as a market, but I guess it is.
It's pretty big. All right, moving on. Uh, next story this week is Techstars, which is really the, the big, um, startup accelerator here in, in Colorado, up in Boulder. They are announcing a new accelerator that's going to really be focused on workforce management. Which is driven by the kind of what's happening here with coronavirus and kind of the changing landscape of workforce in this new world.
Yeah, they're starting this accelerator in partnership with Zoma Lab, Strata Education Network, and Colorado Thrives. And they're gonna have 10 startups in this cohort for a 13-week program that's starting in November. Pretty cool stuff. And really what they're trying to do is they're looking for companies that are focused on bringing new, ways of getting talent networked and connected with potential jobs and educated in this new world. So, so really, it's all about talent development, talent establishment, you know, connecting those— that workforce with the new jobs that are going to be coming in the next couple years.
Yeah, I think, you know, getting any more new companies in those kind of fields is a great thing to help get people employed and re-employed and everything else that we're gonna need in this kind of environment. Pretty good stuff. And of course, they, they're not just looking in Colorado. This is a global search. But this is a Colorado-based accelerator.
So cool stuff. Very good. Next, there was an article in the Business Journal talking about 3 tech companies which are seeing opportunities in Denver despite COVID-19. They had 3 tech companies that we know, I think we've talked about all of them at some point. JumpCloud, which does like cloud-based identity management, account management.
As people are moving more from their on-prem stuff to the cloud, that's really an opportunity for JumpCloud to get tied in. And it looks like that's been a big movement here since COVID took over. Yeah. Second one is Xactly, and they do software for salespeople to get commissions and other things like that. They're seeing that things are still going well for them.
They're seeing a slowdown, but keeping their products going. Sounds like they're doing okay. The third one is Quizlet, which is an online education, basically quizzes, right? That they're seeing a lot more usage as everyone's had to shift to online school. Quizlet's actually having a pretty good run.
Yeah, good for them. Good stuff. Cool to see the companies that are thriving through this process. Somebody's got to. Yeah, absolutely.
Next story, there's a company in Golden called Phase Change, and they are looking to make developers more efficient. Specifically, they have a really specific mission right now, is to help make developers be efficient with COBOL, you know, old code when all the new developers don't know how to use COBOL, don't know how to write in it. Yeah, so they still call themselves a startup even though they're 15 years old, but I think it's actually a cool idea, the product that they are developing. It's basically an AI buddy, you know, an extra coworker to help you if you are coding. So if you are somebody that had this— wasn't, say, a COBOL expert and had to pick up COBOL, you know, because you didn't have the COBOL resources or, you know, something like that, then, you know, it can help you make— help make you more effective when coding in COBOL.
Yeah, it's pretty cool. I know, I know what you and I have both worked at companies that had COBOL as a core part of some really mission-critical applications, and there's always this concern, right? Well, there's that one guy who knows how to do this. If he's not around, who can fix it? And this is gonna start to really address that concern.
If they're successful, I think there's a really good market opportunity for them. Yeah. I mean, I'd imagine that, you know, those one guys out there could even get some help from an AI assistant as well. Yeah. I bet they'd love that.
Yep. Next, we had talked about this previously. Cognizant had suffered a ransomware attack. I think it started in April, if I'm remembering right, maybe even in March. But they made an announcement that they were gonna expect to lose between $50 and $70 million from this ransomware attack.
Yeah, this was in their earnings call talking about, you know, what their projections look like. This is a big deal. There were some new details from this. Obviously, the kind of the range of how much this is gonna cost them, $50 to $70 million, that's material, that's a big deal. A couple other interesting things to me that popped out.
Number one, they, you know, as they talked through this, they said this only impacted internal Cognizant systems, no customer systems, no customer networks, but it significantly impacted their ability to work remote because it was impacting work-from-home setups and it was impacting their laptops that were being used for work from home. So that really just massively impacted their employees, right, you know, just a couple weeks after having to make this shift out of the office and into a work-from-home full-time. Yeah, I think it's a positive that it didn't affect customer systems, but if you can affect the systems that are being used to build laptops, you have to wonder if there was anything else fishy that got in those laptops that then, you know, maybe trickled in or had data trickle out of customer systems. Yeah, there's a lot of suspicious-looking stuff about this one that really the, the way that the customers talked about it. It looks like a bunch of customers of Cognizant had reached out to the media saying, you know, initially Cognizant wasn't very forthcoming about the situation.
It looked like, you know, potentially we were impacted. And I will point out that this $50 to $70 million estimate includes lost revenue as a, you know, as a result of this breach. So it's not just like hard costs. This is like, you know, reputational impact, you know, long-term customer retention impact. So there's a lot of details kind of tied up into that.
Yeah, they did mention it in the article that some customers had paused some of their services until the customers could get a better handle on exactly what was going on and until they were, you know, more comfortable that their— the services Cognizant was providing weren't causing any risk to those companies. Yeah. Well, anyway, I'm glad to see that this is coming around. Of course, we've talked about it before. Cognizant, while they're not a Denver-headquartered company, they did buy Trizetto, which was here in town, and a lot of the folks in the Denver community work or have worked at Cognizant over the years.
Next, our friends Route 9B, or R9B as they seem to be portraying themselves more often recently, they signed an agreement with Baker Hughes to expand their cybersecurity offerings. So Baker Hughes, they have a company called Nexus Controls, which is really big in the energy technology organizations, and apparently do what they do, a lot of training there. So now Route 9B is going to be able to use Baker Hughes or Nexus Controls to deliver their services, their managed services, into that new industry where I assume R9B didn't have a ton of exposure previously, right? Yeah, so basically a reseller agreement, but yeah, I mean, good for them to get into an area that I'm sure needs some MSSP MDR help. So congratulations to them to be pushing forward into a new market.
All right. Well, next story is one that I will stay totally silent about other than I'll just read the headline. Ping Identity, we reported the first quarter 2020 results and provided an outlook for the second quarter and the rest of the year. So that's all, you know, that's out there. That's public information.
You're welcome to say whatever you want to, Alex. Yeah. So I've read through some of it and did not discuss it with Robb.
Some good numbers in there. Looks like around 20% increases in things like ARR and revenue, uh, from a previous year and previous quarter. So those are all good things, some positive numbers in cash flow. So all the stuff that's in here looks like, uh, good stuff for Ping Identity. They did note that guidance is going to be a little squirrely right now just because of all the COVID-19 uncertainty, but not necessarily related to how the business is going in general, but just the general business climate.
So hopefully that is not something that affects Ping too much, but obviously it is going to be something that affects everybody these days. All right, next story we have is Red Canary has some news. They have, they have actually have a new agent that they're supporting. You know, generally they started off with Carbon Black Bit9 as their— I guess it was actually the Carbon Black, the EDR. That was their original product that they offered their service on top of, and since then they've extended it to quite a few additional EDRs.
I think they, they went to CrowdStrike next and Endgame, and there's been some others as well. So now they've now come up with a new deal with Microsoft's ATP, or Defender ATP, to have the same Red Canary backend offering looking at the telemetry coming out of the Defender ATP product. Yeah, so I mean, it's pretty cool. I have heard good things about Defender ATP in general. It's a horrible acronym because, you know, ATPs protect you against APTs, and that just gets confusing.
But I heard good things about the product, and then layering Red Canary on top of it to give you, you know, more intelligence and monitoring sounds like a pretty good thing to me. Yep, pretty good stuff. I'm glad to see them moving forward there. Next, the National Cybersecurity Center. We had talked a little while back about their Secure the Vote initiative.
They announced some webinars that they have coming up that they are going to be presenting around this topic. So, I think we've got 2 that are— I guess it's every week. The first one is this week on the 12th, then one on the 19th, and then the 3rd one on the 26th of May. Pretty good stuff. I'm looking forward to seeing what they can do, and hopefully they can help not just Colorado but the larger, uh, government organizations with keeping the vote secure.
Yeah. All right, last story, uh, yet another, uh, training one. And this is really based on— I only picked this because it's 2 local companies who are partnering together. LogRhythm has selected Optiv as an authorized training partner. I think it's really cool to see those guys working together.
Obviously, Optiv is not only the biggest Colorado value-added reseller, but they're actually globally the biggest security-only VAR. And LogRhythm, one of the big few security companies in Denver, they're going to be working together. Optiv is now delivering training classes for LogRhythm. Pretty cool stuff. Yeah, that is pretty cool.
I think previously the training classes came directly from LogRhythm. And, you know, not that LogRhythm is small, but I would imagine that that was something that was fairly hard to scale, especially for an in-person kind of class. Getting in a company that has services that can give those trainings is a good thing. All right, good stuff. That is it for our news.
Let's move over to the Slack message of the week. A big thanks to Andre Gaeta, who has been sponsoring us and giving, you know, each week we get to give one prize out to someone who says something interesting or, you know, thought-provoking in the Slack channel. Andre gets one item out of the Colorado Equal Security store to, to give those guys a nice piece of swag. Yeah, good stuff. This week's winner is Mike Pedrick.
Congratulations to Mike. He posted about the upcoming free ISACA CRISC course that the ISACA chapter here will be giving. They normally do these trainings in person, but obviously with everything that's going on, they're going to be doing that virtually. And Mike is actually the training coordinator, I believe, still for the, these trainings with the ISACA Denver chapter. Um, I think— I'm not sure if he is doing these specifically.
Yeah, he's delivering this training, and that's the reason I picked it out is because, um, not only is it, you know, it's good to see these things in the Slack channel, but yeah, it's big thanks to Mike for— he's giving a lot of his time, volunteering a lot of time to do these, you know, prepping to do the training and then doing the training themselves. He's been doing this for quite a while. I think it's great stuff. I'd like to see him recognized for that. Congrats to Mike.
He will get one item out of the Colorado Equal Security store. Cool. All right, let's go ahead and move over to events. You know, as a reminder, we do have our calendar events on the website. And frankly, you know, these next couple of weeks, Alex, they look kind of like pre-COVID levels of events.
Yeah, we're starting to get back up there. People are figuring out how to do virtual events. And so we're starting to see things pick back up. The first of those things is actually really interesting looking. ACES is doing an event called Detecting Elevated Skin Temperature with FLIR Convergent and ACES.
So this is a virtual event that they're talking about using thermal energy— excuse me, thermal imaging to detect people that might have a temperature from COVID-19. Pretty cool stuff. Next, the Colorado Springs ISSH chapter is doing a number of May online events. So I think they're doing one per week. So the 14th is the second one, We actually missed the one last week.
I didn't, I didn't see that series until too late, but it's pretty cool. There's going to be other events. So obviously if you're in the Springs and you, and you're already a part of that ISSA chapter, you should make these. But if you've always kind of wondered what's happening down to the south and you're Denver folks, this would be a good chance to get a virtual tour of their meetings. Yeah, Northern Colorado chapter is also doing their May chapter meeting virtually on the 14th.
On the 21st, Women in Security is doing a virtual event. This is a panel discussion on the impacts of COVID-19 to our lives, Business and Information Cybersecurity and Compliance. Also on the 21st, Colorado Springs ISSA is doing the 3rd session that Robb mentioned. And finally, DC303 is doing a virtual event on the 22nd. Good stuff.
Let's move on over to jobs. Robb, does Ping have any jobs? Yeah, I got 2 jobs in the security team that we're looking to fill right now. I'm looking to hire a product security engineer. This is someone who does have a development background and is able to really embed closely with development teams to help us ensure product security is, is embedded from the beginning of the development cycle.
We're also looking to hire a GRC analyst, and this is kind of a jack-of-all-trades GRC analyst position that doesn't have to have much experience, will help us, help us do risk assessments, policies, uh, vendor risk management, fill out RFPs for our customers, kind of really have their hands in a lot of different areas of GRC. Empower Retirement is looking for a senior security engineer. CenturyLink is hiring an information security engineer 1, federal SOC. Newmont Mining is looking for a senior manager of cybersecurity delivery. DaVita is hiring a senior IT auditor focused on assurance.
Uh, Booz Allen is looking for a red team senior. Twitter is hiring a senior infrastructure security engineer. That's pretty cool. Yeah. Uh, New Relic is looking for a senior cloud security engineer.
And finally, Wells Fargo is hiring an adversarial cyber operations specialist ISE 6. I do not know what that is. I put that one in here this week, Robb, just because of that job title. It looked pretty crazy. I have no way.
Is there some kind of government thing going on here with this? I don't know, but, uh, it was— that's an interesting title for sure. Well, if you work for Wells Fargo or know what ISE 6 stands for and you want to let us know, uh, that would be great. I'd love to have that, that itch scratched. Sweet.
Well, that's it for the news. We do have a feature guest this week, and it is Scott Gerlock, our friend, uh, who is who's co-founder and the chief security officer over at StackHawk. Caw caw! Previous to StackHawk, he was the CISO over at SendGrid, you know, right before they were acquired by Twilio. I'm looking forward to hearing this interview.
He sat down with John Hubbard and they had lots of good conversation. Good stuff. Look forward to it. All right. We'll look forward to talking to you guys again next week.
Sounds good. Thanks, Robb. Hi, this is Chris Martinez, CISO at DigitalGlobe. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Hey there, Colorado Equals Security. This is John Hubbard. I'm sitting here with Scott Gerlach. Scott, how are you today? I'm great.
How are you? Doing fine, thanks. It's springtime in Colorado. It's getting warm. Are you thinking of playing some golf soon?
You know, I gotta wait a couple weeks. It's the first— this is like the first weekend where it's actually warm, so everyone's out Uh, so it's too crowded. So you gotta, you gotta wait a little bit and then you can go and have fun when everyone else starts hiking. That's right. Mountain biking.
Yeah. Okay. You've been golfing for a while? I started playing golf when I was 12, I think. Okay, from a young age.
And then have you, uh, improved over time? No, God no. No, uh, I played golf in high school on a high school team.
And did poorly. Okay. The high school team was small, so I was on the team technically. And then, you know, drop it here, drop it there, pick it back up, those kinds of things. Uh, it's just one of those things.
Golf is a really good time until it's not, and then you're like, okay, I need a break. Yeah, take some time off. That's right. Yeah, I honestly have never gotten the appeal, and I think it's because I think I would get really frustrated out on the links, you know, like when the ball doesn't go where I want it to when I bowl, I get really upset. Sure.
That'll be magnified even more on the golf course. Yeah, the most fierce competitor on the golf course is your brain, and it's, it's tricky. Yeah, it is a tricky thing to beat. You have to psych yourself into it, not psych yourself out of it, right? Okay.
Any golf heroes or role models you look up to? There's a lot of famous names out there. Yeah, I don't know. I mean, I'm a fan of Tiger because his birthday is like one day before mine. Okay.
So as he's getting to be a pro, I'm like the same age and like, cool, that could be me one day. He did some bad stuff. I'm gonna, you know, but that doesn't mean I don't still like him. But I also like Brooks and Spieth, Jordan Spieth, and, you know, there's a handful. Rory McIlroy, those guys.
Do you watch golf when there's the PGA tournaments on? I do watch some golf, much to the chagrin of my family. Yeah, because it, you know, can be divisive on whether it's entertaining to watch a golf tournament. Yeah, well, so my wife used to hate it. I get up before everyone on the weekends, so if golf is on when they come downstairs, they're like, oh, not again.
And my wife did not play golf, but I got her golf lessons Did she enjoy that? And now she's like, how are these guys so good? Right. Because she understands the difficulty of the game. Uh-huh.
Uh, and so now she like takes a little bit of enjoyment in watching them play. My daughter does not at all. She hates it. She's like, I'm out of here. But your wife has a higher appreciation after seeing those people hit the ball 300 yards?
Maybe a little smaller bit. Yeah, a smaller bit. Well, you mentioned you guys started playing golf when you were young. Did you grow up in Colorado or somewhere else? No, I grew up in Rapid City, South Dakota.
Okay. So the booming metropolis of Rapid City. Yeah, I've been there. Yeah, yeah. Mount Rushmore and some other attractions around.
That's it. Black Hills. You've named all the attractions. Oh, there's the reptile museum. Okay, there's reptile gardens.
There's, there's the What's it called? The mystery area. I can't remember what the name of it is. There's a cave too. We went to many caves, many caves.
Jewel Cave, Rushmore Cave. My— one of my favorite things to do is to tell people they put the Mount Rushmore faces in the Mount Rushmore cave in the wintertime. People are like, wait, really? How big is that thing? I'm like, it's not as big as it looks like on TV.
So Rapid City is only a 6-hour drive from Denver area, so highly recommended if anyone wants to take a road trip this summer. Yeah, go be a tourist, but maybe don't go that fast because it's like a 6.5 to 7 hour drive. Yeah, through some of the beautiful country of Nebraska and Wyoming to get there. That's right. Okay, so you graduated high school, Rapid City.
Yep. And you wanted to head somewhere else, is that a fair assumption? Uh, let's say maybe. Yeah. So when you grow up in South Dakota, in Rapid City, when I grew up anyway, in the wintertime, the only thing you could do is just be inside and watch the news.
And the news, there's that state down south that's always like 70 or 80 degrees in the wintertime, Arizona. And I've got some relatives that are down there, and I was like, oh, that looks like a great place. But in the summertime, you're outside all the time. And so you missed the part where it's 118 in Phoenix. In Phoenix, yeah, Tampa area.
Okay, yeah, so, uh, graduated high school, um, went to college, got myself kicked out for academics because strangely I don't like doing school so much. Okay, or maybe the structure of some, some of the school stuff. Like I had to take gym. I wasn't in college. Yeah, I was in a comp sci computer engineering class course structure, and my very first thing was gym.
Interesting. The first 2 semesters I had to take gym. That was your requirement? I passed those classes, but you know, like just that kind of weird stuff. Like I did really well in my computer classes, I didn't do great in my English classes, which you could probably tell if you listen to this whole podcast.
You'd be like, yeah, clearly that guy did not English.
But then I got myself suspended ultimately. Okay, so you decided to pursue other paths? Yeah, so then I was delivering car parts, which is a lucrative career. Driving a truck? Driving a truck around with car parts, making minimum wage or something like that, and that was going nowhere real fast.
Maybe not what you had in mind when you wanted to study computer science? Something like that. They had a computer there. So I got to type on it every now and then. Um, but then I got a, I got an advertisement for a school in Tempe.
Uh, it was called Collins College at the time. It was something else now, defunct. All right. But, uh, they had, they had a brand new PC networking course, associate's degree thing. And that appealed to you?
That appealed to me. And so I went and begged and pleaded. I was like, I really want to do this thing. I'm dead. And they were like, okay, it looks like you actually do.
So then I went and did that. Okay, so they, they wrote the check to— they wrote a check to get me down there. And I drove my beat-up Toyota down to Phoenix, and it died shortly thereafter because hot, all that good stuff, right? Um, but I did really, really well at that school. Okay, it was my jam.
Were you working during that time also, or focused on school? Working as well. I was working in a call center for the Ramada Inn properties. I think you're calling Ramada. Yeah, it's Ramada.
Yeah, so I was doing that and doing the college thing and, you know, just working on consuming computer books. Right, so you were learning not just in the classroom but on your own time? Yeah, constantly. Okay. And then did that help you land your first computer job?
Yeah, so the first job out of there was at Kyocera, the printer company. Solar down there, but yeah, same company. So Kyocera Solar was in Tempe— no, sorry, Scottsdale. And I got a job as like a help desk system admin, something something something. Fix-it guy.
Yeah, fix-it guy. Yeah. Which I have mad respect for help desk, IT help desk, because I clicked the thing and now my computer doesn't work is a thing. That's true. People are not always lying about that.
Yeah, so I was there for 7 years and graduated into— like, didn't graduate into, but like worked my way from help desk and laptop or desktop support to bought a new Cat 5000 and I configured that all up for the network, new switch.
Firewall stuff. Okay. Did some SCO Unix administration. All right. Before they went off the deep end and decided that they should sue everyone.
Mm-hmm. So did that, you know, just kind of grew that, grew that network and the user population to a pretty big size and ran a couple big implementations of ERP software and that kind of stuff. Okay, so wearing a lot of different hats. Help desks. Admin, application administrator, all those different things.
That's right. Okay, anything specifically security-focused, or was that just like a strong foundation? Always, always security-focused, right? Like in the background, right? Like we got to stand up our new Exchange server.
They had Exchange when I got there, and I got to keep upgrading it through all the fun pre-2000 Exchanges. Got ourselves spam bombed a bunch of times. And so I worked on setting up SpamAssassin and Sendmail through the old like compile sendmail config stuff. All right, which is good times.
Put that into, into the DMZ, which they didn't have before we set it all up. And then, you know, we started dropping tons and tons and tons of spam on the floor.
That was the first, the first incarnation of giving users some kind of indication that something might not be right here because we were prepending stuff to subject lines. Oh, your whatever you put in front of the Exchange server was modifying. Yeah, SpamAssassin stuff was doing that and it was working pretty well. And then there was an acquisition. No, it wasn't an acquisition.
There was the international— Kiesera International Incorporated. Like parent company. Yeah, they wanted to get more integrated in IT and they had their own stuff, so a lot of stuff went away. Ah, okay. When, when corporate came in, it has to be this way.
That's right. Okay, this was early 2000s or so? So, uh, yeah, 1999 to 2006. Yeah, so spam was still a big problem even back then. Oh yeah, email was taking off, becoming really more common, and then People were getting sick of spam.
Yeah, it was, it was, uh, I think it was just about to explode. Like, you get the random, like, porn spam at that point. You didn't really get the pharma stuff, the Viagras and the whatevers, right? And very little of it was malicious, but there was the occasional, like, virus zip file, right? And trying to get you to open an attachment.
Yeah. Yeah, and did your role change once the corporate here at Sierra came in? It sure did. I almost had nothing to do in a bad way. So yeah, so that was the point in time when I was like, look, I gotta, I gotta go somewhere else because this is just too small, right?
Not learning here. Fortunately for me, 100 yards away was the GoDaddy headquarters. GoDaddy, the domain registrar? That's right. Web hosting company?
So it was Kyocera Solar, Alcor, the place that freezes heads, and then GoDaddy right down the street. Okay. So I decided GoDaddy was probably a better choice than freezing heads. All right.
Yeah, makes sense, makes sense. So you started GoDaddy about 2006-ish, started in the SOC there? Yeah, well, they didn't have a SOC, so when I started there was, I think there was 6 of us, and we were just doing kind of 9-to-5 security stuff. And 2— one user admin, a security engineer, and maybe 4 security people that were doing stuff there. And hilariously, we could get through all of our security systems every day and look, look at the alerts, investigate them, resolve them, and get through every security system and all the alerts they generated at that point in time.
Because there weren't that many? Because there was a lot of stuff, but there was enough of us and not enough bad things happening at that point for us to be able to get through all of them. Well, I'm sure there's some information security professionals today who would kill for being able to get through their workload in one day. In theory, yes. Right, right.
So was this picking up logins or abuse or attempted attacks? Uh, it was no attempted attacks. It was almost always legit, like trying to compromise servers, RDP traffic, MySQL stuff, okay, PHP backdoors, those kinds of things. We had signatures for all that stuff against GoDaddy's backend systems or— No, against the hosting environment mostly. There was, again, the 2 big places that I've been lately, people don't really attack the company.
They're attacking the infrastructure and the platform to leverage it to do something else with. There were the occasional like corporate side type attacks, right? But more often than not, it was about the platform. Okay, anything interesting pop up during your time in investigations that you can talk about? Tons of stuff.
We had a bunch of nation-state activity, which you wouldn't think was, you know, stuff that you'd see, but there's a lot of fairly large Asian country that like to mess around on our network and leave us notes. They would leave us notes. Really? Like talking or what? Well, they knew that we were looking at them and we were trying to set tripwires here and there, and they'd leave us little text files like, hello, GD admins, those kinds of things.
But we did it. I thought we did a really good job of trying to keep that under control. We never really had any data breach stuff, like customer breach stuff, so that was really good. It was more of detect and respond quickly. And shut things down?
Yeah. And what did that response look like? Was it blocking IP addresses? Was it deleting accounts? It was all of that stuff.
So usually it's closing a vulnerability in somebody's website to start that they didn't close themselves. Yeah, because that is— okay, so I tell this story a lot now because of the product that we're working on at StackHawk, but we had a product there that was called Secure or something. We were scanning people's WordPress sites for vulnerabilities because it was happening constantly. Like, dude, we can make a product out of this. People will know and then they can fix it.
Turns out GoDaddy customers, uh, mostly small mom-and-pop— think of like a coffee shop owner. There are businesses running coffee shops, not upgrading WordPress. So everyone was like, cool, thanks for telling us. When can you fix that for us? And we were— we didn't really have a we can fix it for you package.
Just point out the problem. Just point out the problems. And that didn't really win for anybody, more or less. Okay, so is the offering different now? Is there a way that you can tell GoDaddy manage my WordPress for me and keep it up to date?
You know what, I don't know. I know they have managed WordPress, but if you're still self-hosting WordPress, then you can get yourself in the same trouble. And that was before WordPress had like auto-upgrade stuff, before it would upgrade itself in place, and before the plugins would upgrade themselves in place. It was like you have to FTP in and upload new stuff and hope it doesn't break. And who's gonna do that?
Yeah, when they're trying to run a coffee shop. That's right. Yeah. So did you ever find any secrets to success to keep an entire nation stayed out. That doesn't sound like an easy task.
It's not an easy task. Just try to stay one step ahead. Those are the definitions of advanced persistent threats. Um, yeah, it's not, it's not an easy task. It's just, you know, you got to stay on top.
Yeah. So we had to staff and come up with creative ways to alert and respond automatically. Um, and, you know, I haven't been there for 5, 5 years, so I have no idea what they're working on now. Sure. Could be completely different.
Okay, and was everything— was that role that you worked in pretty much entirely in Phoenix, or was there some level of travel? No, it was all in Phoenix at the time. That's GoDaddy's headquarters. GoDaddy was headquartered in Phoenix, and we had a Gilbert office and eventually a Tempe office, and now they're in Kirkland, Washington, and in Sunnyvale, California, and Austin, Texas, and, you know, They're a huge company. Yeah, spread out a little bit more.
Yep. Uh, did they, uh, go public while you were there? They sure did. Okay, what was that like? A crazy roller coaster.
Yeah, because you have to kind of lay the groundwork for SOX, and I'm sure you're already taking credit card payments. Yeah, we had all that stuff in place, so that wasn't actually as crazy as you think it was. So we were already doing financial audits and WebTrust audits for our PKI business, the SSL business, PCI audits. We're a Tier 1 merchant, so we had to do QSAs for a long, long time. Sure.
So that all of that kind of security program stuff led to a pretty robust program itself. And so there wasn't a lot of scrambling to take care of that. There was some scrambling for access control and permissions and some of those things, but it wasn't horrible. It was definitely a different experience than what we kind of had to ramp up with at SendGrid. Okay, well, let's move into that then.
So GoDaddy, you were there through 2015, and then looks like you moved into SendGrid back in the Denver area. They were headquartered in Boulder. At the time, is that right? Uh, when I got here, the headquarters was pretty much— seemed pretty much to me to be in Denver. Okay, so they were in Denver at that time.
Okay, how'd you make that jump from GoDaddy to SendGrid? Yeah, I was just looking for the opportunity to, to CISO somewhere. Um, one of the people that was in charge of GoDaddy at the time, Warren Adelman, super good friend of mine, was on the board at SendGrid. He's like, hey, they're looking for a security architect. I was like, that's right up my alley because that's what I was doing when I left GoDaddy.
Got here, talked to David Campbell, who was actually the CISO at the time. Seemed like a pretty good fit, and they were, they were just kind of reaching that plateau where they're working on SOC 2 stuff. They're worried about denial of service, how to protect against that. They're making a more robust security program so they can go faster. And those things I had really good experiences to bring from GoDaddy.
Sure. Um, to just be able to talk sanely about them, right? And maybe is there some overlap there in terms of environments that both would be very customer-focused, both with a low barrier to entry? Anybody with a credit card can create an account. Yeah, totally.
Those are both very much self-service SaaS kind of businesses.
Maybe the term didn't exist when I was at GoDaddy, but they're both very much low barrier to entry, as you said. Anybody can start using it. Wide range of customers. Or start abusing it right off the bat. Yeah, exactly.
So was that part of your responsibilities, was to make sure customers didn't use SendGrid to spam? There is actually a really good abuse team at SendGrid that lives under the support crew. I don't know, that's where they were. I don't know where they are now since Twilio, but they were actually super strong at kind of doing the abusey stuff. And the trick there that we always had to toe the line on was how do we, how do we keep threat actors from using the platform illegitimately and allow good customers to be able to send mail successfully, quickly.
Those, those 2 things are in opposition to each other because you think like, okay, if we hold on to mail, we can do some inspection stuff and then we can deliver it. That's not— that wasn't our business. That hurts. Yeah, that's not the same great business. Like, if you get yourself and Uber, and when you're done, you get a receipt like almost instantly.
That's because it's coming through us, right? So maybe not because, but that's, that's one of the pride points is from the time it hits our system to the time it goes out is sub-seconds, milliseconds. Yeah. And so it makes spam hunting challenging. Mm-hmm.
Yeah, I could see that you want to reduce the friction. And let the legitimate stuff go through ASAP. Yeah. Yeah. Okay, so you started there as Senior Director of Information Security, and then did you end up getting that CISO goal that you set out for?
Yeah, so when David Campbell decided to retire from that particular job, uh, then I was the CISO for a year and a half. Okay, something like that. Um, it was— I don't know, it was a crazy transition, but I did learn a lot from about how to talk about InfoSec with the exec team. Um, I reported to the CFO, Yancy Searle, who's now the CEO at DigitalOcean, which is— sure, to me that's hilarious. Like, he's in the mail business and I came from hosting, and then he left mail and went to hosting.
Sure. Um, so was the security org part of IT or— No, security org was separate but under the CFO. Interesting. And so he and I did a lot of like, how are we communicating the value of the security organization to the company and what kinds of things do we tell the board of directors and, you know, stuff like how to, how to promote the security organization within the business and not make it just seem like another line item in the budget. And so what we, what we tried to do was really avoid chasing the 100%.
Like, so we've got 900 vulnerabilities, and there's that English part, uh, 900 vulnerabilities, and we've got— we almost have them all patched because now we're at 236 patches or whatever, right? That's just not information that people want to care about, especially at the board and exec level, um, or they shouldn't. Caring about it, probably. So how'd you frame that differently then? It was more about what— so I always talked about the big 3 risks.
Here's the big 3 risks that are in the business. If something causes an existential threat to us, it's gonna be in one of these things, and here's what we are or are not doing about it. Were those 3 unique to SendGrid? I don't think they were. So like, how would you break out that classification, or are you willing to share your secret sauce for the 3?
Yeah, I don't think I want to share that particularly on an individual basis. I might do that, but they're, they're kind of issues that all organizations have a problem with. And at the time, the Verizon deal with Yahoo was happening. Yep. And if you remember, the Yahoo board had no idea about the mass compromise that was going on, and Subsequently, the deal got like a $2 billion haircut.
Yep, I remember that. That was in the news. So my goal was like, hey board, this is stuff you're gonna know. And so if something happens in one of these areas, you'll know about it and you know about it now. And so like part of the board's role is, are we taking the right risks in the right places?
Those kinds of things. So we, we tried to engage that board in the kind of the correct context. Sure. Instead of letting them kind of go, okay, no one has a story to tell me, so I'm gonna ask questions, and those questions are gonna be, how many vulnerabilities do you have? Right?
Because that's, you know, you can find those kinds of things on the internet. That's not necessarily the right question. Yeah, it's not the right stuff. Like, okay, so there's 400 vulnerabilities. Why are they— why are they important, or why are they not important?
Right. And that's a much bigger conversation than just the individual homes. Okay. I think. And you mentioned an acquisition.
SendGrid did end up getting acquired by Twilio, right? Were you part of that process? Yeah. So SendGrid went public before that. That's right.
Which is an IPO and then were— That's right. Bought out. We did it the most smartest way ever. Turned out well for everybody. So we went public and then about a year later the deal got announced with Twilio and I was part of that.
I was working on some of the diligence while I was on vacation in South Africa, so the time difference there was fun. Not exactly sure how Jack Dorsey is managing his Twitter in Africa and blah blah blah, but it was interesting just kind of doing some of the, some of the background work on the InfoSec program and what the things are. I think when Twilio— I think Twilio was pretty surprised of how small the InfoSec team was at SendGrid and still doing a pretty good job. Sure. Kind of directing resources in the right places and not hiring a ton of people.
They had a different idea of how they wanted to run the InfoSec program, and it requires much, much more people. And I think they're in the middle of still doing that today. Okay, so there's still some integration work going on between Denver and San Francisco. Yep. But I think Twilio is pretty committed to Denver from what I've read.
Yeah, they're keeping that— they're keeping that Sangre office, which is 3 floors in the 1801 building.
And I know they're trying to focus on hiring people in the Denver area. Sure, sure. So all you job seekers out there, be sure to check out SimGrid's jobs page— or excuse me, Twilio now— Twilio's job page. There you go. And then you had an opportunity to kind of go out on your own with StackHawk.
Yeah. All right, let's talk about that. So the deal kind of closed And I wanted to go find something else to do at that time. They had a CISO, I wanted to be a CISO, so I took a couple months off, worked on my golf game, made my handicap go up instead of down, that kind of stuff. Wrong direction.
That's right. I'm pretty sure golf has the game all wrong, like higher scores should be better. That's what I'm used to. Yeah. But I took 3 months off, and that's the first time I got to take 3 months off in between roles.
It's always been like maybe 2 weeks, right, in between. And I set out some goals. One was lower my handicap— fail. The other one was like work out and get myself in pretty good shape. I did a pretty good job of that.
The other was find a job, and I did a bunch of job interviews, and I wasn't super excited about any of them. Like, some of them seemed interesting, but I wasn't just like, yeah, this sounds awesome. None of them were calling your name. Yeah. Um, and so I got to— I had coffee with a co-founder, my co-founder, um, Joni Klippert.
She came from— she was the VP of product at VictorOps. And so she went through the Splunk acquisition and came out and was like, I think I want to start a company, and was doing a bunch of research about pen tests. Okay, and, and she likes to say how intellectually dishonest they are because you get a pen test once a year and right about the time the pen tester walks out the door, you release another deployment and the pen test is basically invalid. Sometimes, sometimes, right? But that, that's kind of the thesis of her story.
And we sat down and had coffee and she's like, hey, I want to talk to you about pen tests. She's like, and I said Great. This is my favorite crappy topic because ultimately we're talking about application security, right? Which is the biggest customer-facing part of, or externally facing part of, most businesses. And I've always found AppSec program the hardest program to build because it's, it definitely has an external dependency, and that's the engineering team.
PS, it has another one, the product team.
And so you can't just kind of do things in isolation like you can with sort of a security operations center or kind of monitoring and alerting. You can sort of do that stuff in isolation in the security team, but this particular one is one of the most— I think one of the most integrated with other teams and external dependencies because you basically can't do any of it You can only go consume, consume, consume. Hey, maybe we should— I think, right? So it's always hard because it's really hard to find good AppSec people. Sure.
That are good at AppSec but also good at like building relationships and not alienating people. Uh, the tooling out there today is okay. Um, some of the legacy AppSec dynamic scanners are terrible. Static code analysis stuff is decent, but it's kind of noisy because it doesn't understand the context of the app. And a lot of times it'll, it'll print out a report that has 400 findings across your codebase and you don't know where to start.
That's right. Yeah. And then, you know, there's new tools out there, IAST and some of those other things that are kind of internal to the code that is protecting the code from itself. I don't know how well that works, but, um, in a defense-in-depth program, that's great. Like, do stuff on the code side and have another thing backing you up in prod.
That's great. So we talked about that and I railed against it. And a couple of things that we did at SendGrid to allow engineering teams to self-service some of this risk I think went fairly well. You might get a different opinion if you ask the engineers, but I think it went pretty well. We made a migration to— started a migration to AWS, and we were like, how are we gonna do this?
Because no one really knows how to AWS, and no one— and we don't have the manpower to middleman check everything that's going there. So let's not do that. So we talked to, you know, we talked to a bunch of players, Netflix and some other people, figured out our account strategy, and we're like, look, engineering team, here's what we're gonna do. We're gonna give you admin control of your AWS accounts. Like, you could be admin, do anything you want.
We're gonna, on the side, audit it with Security Monkey and then tell you about things that we find via Slack. So you deploy some stuff, we're going to Slack you about a thing. If you fix it, good to go. If you don't fix it, we will fix it, quotes, for you. And sometimes fix it means delete it, and sometimes fix it means undo public access, right, to restrict it to only internal teams, those, those kinds of things.
Um, and there was a lot of— I think there was a lot of resistance to that at first, but people were I think people ultimately were like, this is cool. I have the access I need to be able to do my job. And there's this thing that's got my back telling me about insecure things I put out into the world in case I click the wrong checkbox or something, click the wrong checkbox, write the wrong Terraform, those kinds of things. Ultimately, what they wanted was something that would help them check the Terraform, like a— sure, a linter. And are there Terraform linters out there?
There is now. Really? Yeah, there is one now. Okay. But, you know, that was, that was maybe one of the first realizations I had that devs really don't want to put insecure stuff into the world.
They just can't know right now, right? It's, it's impossible for them to know for sure how secure or insecure their things are. So they just kind of internalize that and go, well, I write pretty good code. I'm assuming that what the security posture of it is pretty good. So it's not malicious, it's maybe more ignorance, or— I wouldn't even say it's ignorance.
I mean, ignorance has kind of a negative connotation. It's just that they can't— there's not tools out there to know, right? Um, and when we go and try to train them, I always tell this story. I was just talking at SnowFROC last week. This is my favorite analogy.
For how this works. When the executive team goes, hey, we want to raise prices and see what that does to the top line and bottom line of the statements, the P&L, the accounting team doesn't go, cool, I'm going to teach you about the GL. You know what I mean? That's— and that's what we do when they're like, hey, I want to know some stuff about security. We're like, yes, excellent, let's talk about risk, shall we?
We're not just like, here's some tooling that can allow you to make strong decisions. Because even then we go, and then check in with us and we'll tell you whether or not that's a thing you should do. It's so arrogant-ish of us to think that they can't make good decisions while they're building all of the stuff that makes the company work. So is that the market need that StackHawk is solving right now? Yeah, I think so.
I think that's what we're trying to do is, is give engineering teams the ability to do StackHawk— right now is dynamic scanning, but dynamic app scanning while they're writing code. So do it on a laptop while you're writing code, put it back, put it into the CI/CD pipeline so it's got your back. Yeah, at commit time, or anybody else gets into that code, and know that you're putting stuff out there that doesn't have severe security vulnerabilities. Into it. So where does the product live?
Is it an API endpoint? Is it SaaS? Is it something that runs on my Jenkins instance? All of those things. So the scanner gets delivered via Docker right now.
Okay. So the scanner can be anywhere, right? That's one of the problems historically with DAST is it has to live somewhere and then it can't have access to things. Right, whether it's laptops or internally or whatever. But if it's a container, I could run it in my laptop, could run it in AWS.
Yep. And it reports findings back to the platform, so you can look at over time the posture of an application, better troubleshooting, like visualizations, those kinds of things. So there's some web portal that comes home to— that's right, does it reports. And we want to be able to catch stuff on laptops and in CI/CD so that we're not— we fix— we're fixing things before they get to production. Okay.
Those kinds of— those kinds of things. And we have an idea of translating, retranslating security language from security person speak back to dev language. Instead of 15 different acronyms for input sanitization, let's just call it input sanitization. Sure. And then we also want to have an opinion.
Here's the things that we think you should be fixing, and these other things, defer them or don't fix them or whatever. If you come up with a bucket of empty time some magic way, fix these other things. But right now you should be focused on this and this, and we're, and we're trying to do that via how important is the app to the company and what kind of data does it handle. Okay, so it's not just critical, high, medium, low. That's right.
Takes in more context. Yeah, because that's the first thing that we ask when we have AppSec program. We go, cool, what does this thing do? How important is it to the business? Right.
So let's just ask them right up front and then know. And then as a security team, you know, in a company that has a security team— there's tons of them that don't— so they, they get to pay a huge security tax when they're like, Well, now we need security team, and that, and that team has to come in and start fresh everywhere. So now there's a little bit that you can start building. And then the other thing is, when the security team gets there, they can look at the same stuff and have a conversation about why someone chose not to fix a thing or deferred it or whatever. Sure.
Instead of, hey, you've got to fix this crap, you know, drawing the black and white line. Yeah. Okay. Without any context, like All the vulnerabilities, we have to fix all of them, you know what I mean? Yep.
And then how's it going so far? It's, uh, not quite a year since— it's been 7 months. Okay. We got funded, first round of funding in July of last year. Uh, we're about to launch alpha for the platform this week, which I think is March 9th, the week of March 9th, right?
Do you have some early adopters? We've got a couple of people that have been running the scanner for us and giving us feedback about how that works and how developer-y it is. That's been going really well. Yeah, so we're using Zap on the backend there as the scanner. The world doesn't need a better scanner, the world needs an easier scanner with easier to understand results.
Yeah, so we spent a lot of time making it easy to instrument. Zap has about Let's see, 5,400 settings or something like that. I don't know if that number's right, but it has a ton of settings, lots of dials. And even as a person that uses Zapier, it's— if you don't use it every single day, it's hard to get back into and go, okay, what do I gotta do to make this thing run? So we took most of the really important settings and put them into a YAML config file.
So you can just fire up the config file, right? Dump that in your repo and scan, scan, scan, scan. Scan, scan, and then change one or two settings. Change one or two settings. Yep.
Okay. Is it specific to any certain web application language? Nope, it is not. It's a dynamic scanner. So if the app is running, right, it'll scan the app.
Okay. We're still, you know, there's still some single-page app problems and REST API if it's not defined via Swagger or something like that, right? Still some challenges there, but we're working on that stuff. Um, but yeah, that's the other thing that I mentioned when I was talking with Jody is like these static code analyzers are great except for they're very, very language specific. And if you're not running Java and maybe Python and something else, you don't have coverage, right?
Right. Because that was the thing we ran into at SendGrid. There's a lot of Go at SendGrid. There's no Go static code analysis. So how do you do it, right?
Yeah, exactly. Okay, so you're focusing on the dynamic side of things. So log into the app, start clicking, have your automated process crawl everything. Yep. Okay.
Well, that's really exciting. That's really cool. Is your partner Joni— is she based here in Denver as well? Yeah, Joni is here, and then our other co-founder Ryan Severance came from VictorOps as well, did a stint at JumpCloud, but us 3 co-founded the company. We've got 10 people now, which is super crazy.
Yeah, growing fast. Yeah, and then we'll see what happens this year, right? We had, we had a whole bunch of plans last month, and now we're like, hmm, do these plans still hold water with quarantine yourself and coronavirus and everything else that's in the news? I think we're in a good spot. We had a really good plan on how to go out and kick the market and start convincing developers you can and should own this.
And so, you know, we'll keep executing on that this year and it should be a pretty crazy ride. Awesome. Well, we're coming up on time. Is there anything we didn't cover today that you want to be sure to mention for the Colorado Vehicle Security Group? I don't, I don't think so.
I just want to thank Robb and Alex for keeping the whole thing going and pushing it forward. Our fearless leaders. That's right. Robb keeps hating on me because I keep shamelessly plugging StackHawk in one of the channels. He's like, that's for sales pitches, guy.
But I like it. Yeah, well, we don't want you banned from the Slack channel, so fall in line. All right. Yeah, yeah, sorry. All right, well, thanks so much for your time, Scott.
Really appreciate it. Have a good one. Very nice to meet you. I appreciate your time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.