Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 169 for the week of June 22nd, 2020. Alex, uh, how's your weekend?
How's your week been? You know, it's been good. This is a big week. It's Father's Day this weekend. So, happy Father's Day to all the fathers out there, yourself included, Robb.
Thanks, Alex. Happy Father's Day to you. Do you have any— we're recording Saturday night. Do you have any exciting plans for Father's Day? You know, nothing crazy.
We're going to go hang out with my father-in-law for a little bit. I'm not sure exactly what we're doing. And my one request always for Father's Day is to take a nap. Maybe I'll take a nap tomorrow. Leave me the hell alone.
That's your one request, huh? Yeah. It doesn't have to be a long nap, just a nap. Good stuff. How about you?
We are actually taking my father-in-law and my whole family out for a bike ride. We're gonna ride downtown, which is a pretty good ride for us. It's like, I think it's 17 miles each way. Have lunch downtown at a patio and have a little bit of fun in the afternoon with the family. Very good stuff.
Should be fun. All right. Well, let's go, go ahead and go through a little bit of housekeeping. You know, we do have a Slack channel. We talked about this every week.
Join the Slack channel and 1,400 of our closest friends out at colorado-security.com. You can find the link to join. In case you hadn't heard, we also have a mailing list. You can sign up on the website colorado-security.com. Once you sign up, you'll get the show notes emailed to you every week.
As soon as they are available. I would also love it if you would rate us and subscribe on your favorite podcast listening app. That's a good way for us to find new listeners and hopefully really help this Colorado Equal Security movement gain some momentum. You know, if you also wanna subscribe on your least favorite app that you never listen to and get an extra download, that's fine with me too. In addition, it would be great if you told a friend, let them know about the podcast and everything else, Slack channel that we have going on, get them involved in the community and have them join up with Colorado Equal Security.
And other ways you can help, number one, you can support us financially on the Patreon, help us pay for the cost of this. We know a lot of folks have been impacted by COVID. If this is not the right time for you, no problem. But for those who can help, we'd love it. We'd also love it if you'd help, if you want to do interviews for us.
You know, we like to have feature interviews as a part of the show. We've, you know, had a hard time recently keeping up with our schedules to keep doing those interviews. We're faithfully doing the newscast every week, but interviews have been a little bit sparse. We do have one this week, thanks to some folks who came up with the idea. Alex sat down with a couple guests this week, but we'd love it if you were interested in getting involved, getting to know some folks in the community, highlight people who you think the community should know about.
Send us a note at info@colorado-security.com and let us know, and we'll, we'll figure out how to make that happen. Awesome. You know, also, Robb, one of the things that we have coming up, which is a new Colorado People Security thing, is a book club. So on July 15th, we're having our first meeting to talk about the book Start with Why. Yeah, you know, I've been reading it and I actually think I do have one little correction there.
I think we're going to be changing the date from July 15th. Somebody, it's actually me, is unavailable to meet that day, so has asked to reschedule the date. So we're still figuring out when that's going to move to, but excited to do it sometime middle of July. We'll be having that meeting. Awesome.
I look forward to it too. All right, let's jump into the news. We actually have some pretty interesting non-security stories this week. There's a company called Boulder AI which was selected by the city of Denver to help use their AI technology to make pedestrians safer as they're crossing intersections. Yeah, I thought this was a pretty cool idea.
You know, basically some camera systems that can tell not just that something is there, but what kind of something, whether it's a child or, you know, some— something else where someone might need extra time to cross the street. So, you know, you can potentially change the length of a signal or other things like that to make sure that people are safe. I love that. I especially love the idea that, you know, in the article they specifically mentioned like a sight-impaired individual might need more time crossing. I love the fact that, you know, if this gets rolled out, that those folks can have a little more confidence crossing the street and know that they're more protected.
That's pretty cool stuff. So Michael, is it Finocchio, who's the engineering manager for the City of Denver, also talked about this system not only making pedestrians safer, but also talks about how they do have privacy built into this. The system does not, capture or transmit any video of residents or of the pedestrians. It just reacts to their motions to assure the safety. So there's really privacy as a part built into the way this is engineered.
Pretty cool stuff. I think that is pretty cool. Usually when you see articles like this, you know, my first thought is, well, that's going to be a nightmare. You know, whether it's security or privacy or both, but good to see that they've thought about that, you know, before they even put it into place. So pretty cool.
Awesome stuff. Next, Robb, did you know that nearly 1/3 of new pandemic unemployment claims last week were fake, according to the Colorado Department of Labor? I had no idea that there was this kind of rampant fraud in that system. That is a massive claim. So they said about 5,600 claims were fake last week.
So, you know, about, like you said, about a third. Number one, 15,000 is a big number. But number two, over 5,000 were fake. And they've only identified about 2,800 of them specifically that they know are fraudulent. So they're still looking through the rest to figure out which are fraudulent.
And it looks like they expect that they, you know, by stopping those fraudulent claims, it's going to save about $34 million. Yeah, I mean, one of the things I thought was interesting is because of the way that the program works, you can technically backdate when you want to claim, right? So you could backdate to the beginning of the pandemic if you were actually affected by it. However, if you were actually affected by the pandemic, you've probably already filed by now. So that was one of the criteria that they were using to find the fake claims.
There were a bunch that were all of a sudden saying, oh yeah, by the way, I've been affected since February, so please give me my money. Imagine being the guy who just woke up from a coma, lost his job, and now the government says you can't do it because you took too long to ask for your backup. Unemployment. That sounds like a, sounds like a romantic comedy in the works right there. Definitely.
I know also that these types of scams have been happening in other states as well, not just Colorado. So yeah, while we like to feel special, we're not the only ones. Next story this week, there's a Boulder tech company called Tectonic that is going— that is pledged to hire 100 people of color as apprentices. Now they've had an apprentice program going for a while, but they are, they're gonna make sure that their next wave is incredibly heavily slanted towards going after people of color. Yeah, so I thought this was pretty interesting.
Obviously, there's the big Black Lives Matter movement going on right now, lots of protests, things going on. And, you know, they say in the article, well, you know, we had discussions, you know, should we make some social media posts talking about how we support Black Lives Matter and things like that? And instead they said, well, you know, instead of just, you know, putting support on social media or something like that, let's actually You know, put our money where our mouth is, essentially, and offer some internships— excuse me, apprenticeships to folks of color. It's pretty cool. Yeah.
So these are all paid college-accredited internships, 14-week courses. And it looks like— and I don't know a lot about their program, but it looks like they'll partner with local companies. So if there are those who think, wow, what a great idea, I wish we could do this, I actually think you can partner with Tectonic to do this pretty easily. I think that's what they're there for. Yeah, that's pretty neat.
So hopefully that takes off and they get those 100 folks in a good place. Next, Denver-based startup Uncharted has shifted to being much lazier. I mean, to having a 4-day, 32-hour workweek. Yeah, really, it's a really interesting article. So their CEO, Banks Benitez, had read extensively about Microsoft's project that they did in Japan.
And I actually heard about this as well. Microsoft Japan had gone to a 4-day workweek and had seen their productivity boost by 40%. And he thought, is this possible? Could it be possible? And he was thinking about it as COVID struck.
According to this article, right when COVID struck, he's like, man, it would be crazy to do this right now, or maybe this is the best time to try it. And they decided that due to the remote work and the fact that people had so much distraction right now, that this would be a great time to try and and start the 4-day, 32-hour workweek. Yeah. So it sounds like maybe this is not the whole company that's doing this, but they're trialing it. And maybe I'm just reading that wrong, but they have a 13-person team that is transitioning to the 4 8-hour workdays for the remainder of the summer to test this out.
And I mean, it's interesting because a lot of times you think, oh, well, you know, go to a 4-day workweek, but that means you're going to work, you know, 4 12s or something like that, right, to get all your stuff done. But no, they're really trying to fit their entire workweek into 4 8-hour days. So, yeah. The way I read it was that they are a 13-person company and I think that they— I could be wrong, right? It isn't clear.
Now that I reread it, it makes sense. That's how I read it. But I think either way, he hits really heavily on a couple of important points. It's incredibly important to be able to measure productivity. If you're just going into this and saying, hey, let's see how it feels.
Does it feel like we're as productive after? That's not nearly as good as having some data you can trust. Yeah, the other thing is that they're specifically trying to track their hours to try and stay around that 32 hours. And Benitez, who was the one that they interviewed for this, said, you know, he worked 34 hours the first week and then 32.5 the second week, which is a sharp decrease from the, you know, 50 to 50-hour work weeks that he was normally doing. So, you know, definitely cutting back on that time and hopefully they are still being as productive.
They had a couple other strategies, a couple other findings I thought were interesting. They prioritized that no meeting would be— well, every meeting would be less than an hour. So there's no 2-hour meetings, there's no full-day meetings at this point, keeping every meeting shorter to try and prioritize what's most important. They made everyone in the company read the book Essentialism by Greg McKeown. It really talked about how to focus on what's essential and really cut out what's not essential.
And they did have some findings 2 weeks into the trial. He said that one of the big findings is it seems like people are asking others for help less frequently, under the assumption that everyone's time is more precious now. They're trying to avoid burdening them with questions, which is certainly not the intention, and they're trying to work on ways to mitigate that. Yeah, pretty cool. I'd be interested to see how this looks at the end of the summer and whether they've been successful.
Yeah, good stuff. Next story we have is about a Denver company, Pairin. That's P-A-I-R-I-N. They have raised an A round and they're doubling down on their technology to make hiring more equitable. Yeah, so it sounds like originally being equitable was not necessarily their exact mission, but they've sort of pivoted a little bit that way.
They wanted to help people to have employers hire people based on their soft skills, not just sort of the traditional way that you might hire someone. Yeah, I think basically they're a hiring platform, like a recruiting platform companies use, and they were focusing heavily on trying to identify soft skills for candidates. And now they've pivoted, you know, kind of as we talked about with Black Lives Matter and really the social awakening that's happening right now, they're really focusing more on helping companies hire for diversity and hire for things other than what's the best technical fit. Yeah, pretty cool. Hopefully that they succeed as well.
Seems like a pretty good venture. I'll say a couple things. Number one, they've been around since 2012, so they're not a new company and they just raised $2.1 million. So it's interesting that considering where they are, they're probably relatively small. Hopefully that means they can pivot pretty quickly and use that money to really figure out what's next for Perrin.
Yep. Next, CNBC leads with a story. Excuse me, released their 2020 Disruptor 50 companies list. And there was a Colorado company that was on that list. Holy smokes, CNBC.
That's like a national media, right? Big time. We don't get that very much here. Big time. So, I'll say I was reading down the list.
I'm like, because Alex, you put this in the news this week. And I was wondering, man, what Colorado company is going to be on here? Well, I saw SentinelOne. So, there's a security company as we went. But then, later in, later on, we do see a local company, Guild Education.
They made the list. Yeah, pretty cool. As people probably know, Guild Education does what they call education as a benefit, you know, so they help working people get continuing education and training to help move up and on in their careers. You know, they try and get companies to offer that to their employees as a benefit of employment. And so seems like they're doing good stuff, at least according to CNBC.
Yeah, that's really cool. It seems like Guild Education has had a ton of momentum lately, and I'm excited to see how far they're going to go. For sure. All right, next we have— now we're moving over to the security company news. Automox, which is the— well, they're up in Boulder, somewhere up in that area.
Um, the— they're a patch management kind of automated patch deployment company. Um, they have appointed a new board member, and it's, uh, I'm gonna butcher his last name, it's Dmitri Alperovich. Um, he is one of the co-founders from CrowdStrike, and I didn't know Dmitri before reading this, but I'll say after reading his bio, I'm, I'm feeling a little bit jealous. He seems like a pretty badass. Yeah, for sure.
It seems pretty cool for Automox to get him on the board. Obviously CrowdStrike is a very successful company, and I'm sure the experience that he's had there will help them to get even bigger and better. Congratulations to Automox, another company that's had a lot of momentum. Next, Virtual Armor had a blog post this week, Proximity Tracing and You: What to Expect as the World Returns to Work. Yeah, you know, I think that this, this headline is way underselling what's in this article.
They go They do a lot talking about just kind of where we are today with COVID and really what this world's going to look like. So they describe how contact tracing apps work and why there is privacy built into this. For you, any of it, all of us, you know, we're going to have friends and family who are wondering, what is this contact tracing stuff? Is it the government tracking me? What's the risk?
This does a really good job describing in a relatively approachable, you know, you don't have to be cryptographer to understand it, a good way to understand why this is anonymous and how it works, how you're opting into it, and really what's the impact of whether people use it or don't use it in terms of how it will reduce the impact of COVID and the spread, the R-naught, which is what they call the spreading rate. So I really thought that was interesting. And then they go into talking about what workplaces look like after folks come in. What's the new norm going to be? So a lot of really good content here.
And like I said, I Number one, I think they probably should have broken this up into more than one because there's so much good content here. It is pretty great. Number two, I recommend everyone send this to friends and family who wonder how contact tracing works. Yeah, I think the— I agree with you, Robb. I think the only issue that I had with the blog was, you know, when they talked about contact tracing and contact tracing apps, they really talked about how those apps should work, not necessarily how they are actually coded and designed to work.
So, I mean, for a security-focused company to not, you know, put at least a mention in there that you should verify that, you know, the contact tracing app that you're using is reputable, I think was a miss. But, you know, besides that, I thought it was a good idea or a good overview of contact tracing and how it works and what the benefits of using it are and And obviously the second part about returning to work. Yeah, anyway, good stuff. Like you said, probably could have been better, but really high-quality content there. I appreciate Virtual Armor putting that out there.
Next, we had a blog post from Ping Identity. This is a part 2, Keep Me Safe, Make Me Happy. Yeah, so Richard Byrd, who's the Chief Customer Information Officer over at Ping, is really just kind of emphasizing something that I think we all know but sometimes forget, which is part of customer satisfaction, part of keeping your customers engaged is not letting hackers steal their information. Richard spends a bunch of time in here talking about how, yes, we have a bunch of privacy regulations, but those privacy regulations don't get granular enough around what the security requirements are. And, you know, you can have the most stringent privacy controls in place, but if there's not good security around them, they're all for naught, right?
If I can just step in as Alex and take all Alex's information out of there, that's not going to be good. So he talks about that and how it makes a difference for companies. And, and of course, you know, Ping does help with that customer experience and customer security stuff. So it's probably can give him a call and I'm sure he'll help you get into a brand new piece of software. Good stuff.
All right, we had— next article is by LogRhythm and it's talking about 7 steps to building a security operations center. Obviously, it's important to keep monitoring your environment and that's really what this is all about, how to do that. Yeah, and the, the blog post itself is kind of an overview and then they have an attached slide deck, I think, that goes into a little bit more detail. But, you know, they're talking about the 7 steps to build your SOC. These are pretty straightforward.
You know, you want to have a strategy and then design your SOC and then create processes, procedures, and training, prepare that environment, implement it, deploy the use cases, which is maybe one of the most overlooked pieces there is, you know, figuring out what it is you're actually monitoring for, and then, you know, sort of continuous improvement evolving your solution. Good stuff. I appreciate LogRhythm putting this out there. Obviously, security operations is something that they do, and I think we all need to get better at. Thanks for sharing that.
Of course, James Carder was one of the content creators on this. I think there's a, there's a video in there by him, and he is one of our featured guests today. He is. Next, there is a blog by Swimlane talking about preparation and process in incident response. So Swimlane is the local security orchestration automation and response company here in town, and generally, you know, when they're doing these posts, it's It's kind of about the technology and the process about how you do automation.
This one is not at all. This one is really all about policy and standards and really the non-technical parts behind it that allow the technology to work. Really interesting stuff. If you have to stand up a new incident response process, how do you define what an incident is? How do you go from all of the events occurring in your environment down to the incidents that are worth managing?
They do a good job addressing that, and hopefully you can use this to start from scratch. Yeah, I think it is very important, and while Swimlane does normally focus on the technology, if you don't have a good defined process, it's not really going to help you very much to try and automate it. Yeah, awesome. Our last blog this week is another one from Red Canary. We, we talk about Red Canary blogs on here so frequently because I think they just put in such great content, and it's, you know, it's just I think it should be on every security analyst, every security operations person's reading list, this blog.
So this one goes into the details on Blue Mockingbird, which is the Monero miner, and how you can detect this threat in your environment and hopefully how you can prevent it. And it is a video, actually. There's a really short blog, but it goes into a 23-minute-long video describing how to detect this. Yeah, so for those of us that don't actually like to read, this is a Great blog post for you. Here's your chance, non-readers.
Yeah, go for it.
Excuse me. Well, that, that is it for news. Uh, no, no worries, Alex. Uh, let's jump over to the Slack message of the week. Let's start off by thanking, uh, Andre Gaeta.
Andre is, you know, every week has been an awesome supporter for us. We appreciate that. He makes sure we can buy one item from the Colorado Equal Security Store for our lucky winner each week. Um, and that week, this, this week Who is that person, Alex? Uh, this week our winner is Rishi Malik, uh, posting about the horrible eBay cyberstalking story that has been in the news.
Uh, yeah, that was a doozy. That was a— that was an insane story. Anyone who has not read this yet, you've got to read it. Um, basically some members of the security team at eBay, uh, decided to take out, you know, not physically, but kind of Well, kind of physically, but not kill, but really get retribution against some company from— or some company, a couple who run a blog that basically talks about e-commerce sites who said some unfavorable stuff about eBay. These people did all kinds of terrible things to this couple.
Yes. I think there was some insinuation in the article that maybe even some executive management at eBay had either hinted or, you know, said maybe people should do something about this couple. And then, of course, the security team took it into their hands and, you know, sent them horrible things in the mail and just did all kinds of mean and horrible stuff to them. Well, so we don't want to glory on this too much. Fortunately, those people have been indicted.
They've been fired from eBay. eBay is cleaning up the environment that allowed this to happen. So that's all being dealt with appropriately. Hopefully those folks out east are going to be able to heal up from what happened to them. On the good side, Rishi gets to pick one item from the store for sharing with us kind of a lesson that we can share with our own teams and say, never do this.
Never send people threatening things in the mail. Yeah, never send a— what was it? Like a fetal pig or something like that. Yeah, it was awful. Anyway, that's enough of that conversation.
Let's jump over to our events. We do have a calendar of events. There's a pretty busy week coming up this week, starting On the 23rd, where ISSA Denver continues their, their thread of getting the RMISC talks that didn't get to happen because the conference was canceled. They're gonna have John Stock talking about securing connected devices and preventing wireless attacks. On the 24th, ISC² Pikes Peak is doing their June chapter meeting.
There's a couple events on the 25th. First, ISSC Colorado Springs is continuing their June online series. And second, ISSA Denver is doing another talk. They have Toby Zimmerer talking about addressing the need to dispose data. On the 26th, DC303 is doing a meeting talking about Android app reverse engineering.
And then finally, Akamathon is the conference happening on the 27th, and that is a full-day event that should give you guys lots of good learning. And then, Robb, we have a nice big gap in events. Um, I'm thinking because it's going to be 4th of July already. Yeah, I've got my flag ready to wave. That's good.
Um, be a, a, a good American and get out there and shoot off some fireworks and You know, have some hot dogs because, because our hospitals need more business right now, right? Exactly. Just, you know, make sure you keep most of your fingers. All right, let's go ahead and jump over to jobs. Speaking of jobs, I think I see something here that you might have something to say about.
I do. I am hiring for a security program manager. This person helps me run the enterprise security program at, at the Anschutz Corporation. Helping me make sure that, uh, projects get done, things get implemented, oversight, uh, that sort of thing. So someone with some project management and security skills would be a great fit for this role.
So if that is you, would love to hear from you. Awesome. Next we have Dispatch Health who's hiring a Vice President of Information Technology and Security Officer. Elliott Management is looking for an Information Systems Security Manager. DISH Network is hiring a Senior Cybersecurity Threat Hunter.
Twilio is looking for a Lead Offensive Security and Assessments Engineer. Cognizant is hiring a Project Manager for Corporate Security. They're competing with me for my spot. State of Colorado is looking for a Security Solutions Architect for IAM. Maxar is hiring a Cybersecurity Operations Analyst.
NREL is looking for a cybersecurity analyst. And finally, Workboard is hiring an information security intern. So that's awesome. I know a lot of internship programs got closed because offices closed, but awesome that Workboard is still hiring here. Yeah, I think if I'm remembering right, Workboard is a kind of cool company too.
They make like physical, like mini whiteboards and other things like that that you can use Instead of like sticky notes if you're doing Scrum kind of stuff. Sounds awesome. I think they have some software that goes along with that as well. Cool. All right.
Well, that is it for the news, Alex. I think we do have an interview. You want to, you want to give it— whet the appetites at all? Sure. So we, we had James Carder that you mentioned earlier, CISO of LogRhythm, and Steve Winterfeld from Akamai came over.
We hung out on my deck. You know, drank a little bit of booze and, and talked about security. So it was a good convo and had a good time. I think so. I will enjoy it.
I do want to be clear, you were drinking booze at— it was 9:30 AM, is that right? You know, it's 12 o'clock somewhere, 5 o'clock somewhere, whatever. It was early in the morning. I had coffee also, a little Irish coffee, something like that. All right, Alex.
Well, I think that's it for the newscast this week. We'll look forward to talking to everyone next week. Awesome. Thanks, Robb. Hi, this is Ed Fuller, CISO of Cloud Elements.
This is Colorado Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is a feature interview for the first time in person. Since we've all been at home. Very excited about that. Got a couple special guests with me since this is the first one.
Figured we'd get more than one person together. This is Alex Wood, and with me I have James Carder, Chief Security Officer at LogRhythm. Good seeing you, Alex, in person. You too, James. And Steve Winterfeld, Advisory CISO for Akamai.
Same, nice to be able to get together with people again. Yeah, maybe I'll start doing this, call it the Deck Series, hanging out on my deck here, having a couple beverages, talking about security.
You know, since we can see each other in person, you know, how have you guys been holding up? What's been going on the last 3 months?
So, I mean, for me, I'd always working from home, so it was less disruptive, but I had a high travel job, so You know, that, that was very disruptive. Yeah. You know, learning the new culture of online interaction, you know, dealing with, for Akamai, multiple customers with multiple business models, some doing better, some, you know, being crushed. So trying to, trying to, to work with people in different industries has been fascinating through this. I feel like for us, you know, our, our production— first of all, the workload just feels like it's gone up, right?
Because I don't have to commute anymore, 35 minutes each direction to and from the office. You, you don't get as much of the water cooler time, that kind of stuff. But I feel like people are putting in like 10, 12-hour days right now because they're going to get up at the same time, they go down to their home office or whatever, start work, get off at 4 o'clock or 5 o'clock, and then they're right there at home and don't have to commute. So I feel like, you know, overall, at least my teams or anything, I've been super productive. And from a security perspective, we were already, you know, 50% of our workforce was remote.
So we, you know, having— we were already built sort of for this remote workforce piece, and we had just finished our annual business continuity disaster recovery test where we actually— the scenario was pandemic, funny enough. So we already had everything in order. But no, I think Things have been good and I see it— I see us probably staying at home more in the future. Yeah, I think it's funny. I mean, working at home, if you're doing it temporarily like, oh, my kid is sick, I have to work at home today, that's one thing.
But being a full-time work-at-home person, I mean, there really is some skill to it. And I think that the people who weren't working at home full-time that now are, are having to learn that. And that's kind of to your point James, with, you know, working 10, 12-hour days, right? So if home is the office and you're always at home, then you're always at the office unless you take the time to think, okay, this is where I'm gonna start work, this is where I'm gonna stop work. So I think, you know, I worked at home for 10 years, and for a long time I did the same thing.
It's like, all right, I'm gonna work basically around the clock because I'm here and I can do it and I like what I'm doing. And I could probably guess those 10 years because I did the same thing for 5 years. Yeah, and so I mean it took me a while to realize, oh okay, I really actually have to figure out a balance and have to say, okay, this is when I'm at work and outside of that I gotta stop and do something else. Well, and I think you're right, part of its boundaries, the other part of it is though the standards have changed because as my, you know, somebody at work said, we're working out of crisis centers. So, you know, there are kids, there are dogs, there are spouses, right?
There are people that we forced their way into their home that don't have a home office. So you see, you know, some days you'll see people out of their kitchen because, you know, their, their significant other has the office or something. And so, yeah, it's, it's really tough to figure out those boundaries. For sure. I think it's going to be interesting to see, you know, most, most kids are at home sort of, you know, because of summer.
It's sort of summer plans anyway. Now you expect that to happen come the fall if there are still disruptions around, you know, either people being in the office or kids being at school full time. You know, what's that going to look like for, for workforce and things like that? Yeah. It's gonna be, uh, it'll, it'll be interesting with, you know, when, you know, right now I think the DPS, at least for us, Denver Public Schools, has talked about it's gonna be a mix of, you know, people, you know, students at home, students in the, in the classroom.
And so I, I still think your level of disruption, if you've got some disruption at the house— lucky for me is that, um, you know, it was funny, my wife gave birth to our second kid and then we decided after, after her maternity leave, they started— the hospital started messing with her schedule. And she's a neonatal ICU nurse. And so she's like, you know what, I'm done. And this was probably January-ish. And so 2 months later, you know, this whole thing happens.
And, um, you know, she, she was like, oh man, because she would have definitely been floated to ICU to basically go treat COVID patients. But because of all this, she's been at home with our kids homeschooling, and they're all up upstairs. I have a secluded basement office, so it's actually been really, you know, really nice from that perspective. But I had to joke with you because, uh, when you and I were on a video, I saw you were in a jacket and I was in my hoodie because both of us in the basement are freezing because of the air conditioning. That's right, it's about 10 degrees cooler down there.
That's awesome. One of the other things that I've noticed too, because I haven't had a commute, because It's been more relaxed. I track my sleep, and like the instant that we were at home full-time, I started sleeping on average 30 to 40 minutes longer every day. Yeah. And you know, it's amazing how much just that little bit makes a difference.
The other part too that's interesting is just for this podcast, I actually wore shorts today without an elastic waistband. I've been— I've literally for the whole full 3 months we've been work at home. And they fit? Yeah, yeah, we've been— I've worn nothing but elastic waistband shorts. Sometimes a polo or button-up if I have to do something, you know, that's more visible, but always elastic banded shorts.
Yeah, you always wonder what the bottom half is doing there. You don't always wonder. So another thing I think will be interesting though is how do you onboard new employees or new team members You're reading my mind, man. I was just thinking about that, you know. Yeah, so what do you— how are you going to approach it?
Well, so I mean, the other part is especially if you haven't been used to hiring people remotely in your office culture, how is it that the hiring processes go, right? So I'm actually— I have a position that I'm trying to hire for right now, and, you know, prior to this, we were very in the office culture. I mean, not that I haven't had to, you know, hire people remotely before, but so, you know, previously it would have been, oh, you know, we bring people in for, you know, a first round of interviews, you know, sit them in a conference room, run a bunch of people in front of them, then maybe bring some back, you know, a few days later, and then maybe, you know, a couple go on to some later rounds with, you know, some executives and some other things like that. As we started to go through this process, I was like, Well, what am I gonna do? How is this gonna happen?
And so we're just kind of thinking about it on the fly. I don't think we've had to hire a whole lot of people yet since, since this whole thing has started. I was gonna say, we, you know, we've even gone through a little bit of a hiring freeze right now, so we've had to worry about that less. And it's probably, you know, primarily a reaction to the uncertainty of what the whole pandemic was gonna cause for us. So we just wanted to— we froze a lot of the hiring component of it.
So we haven't had to do a whole lot, but I think, you know, we have had to do some, and it's been all video interview sessions and everything else. But you're never meeting the person before you actually make the offer, or after. Yeah. And that's my problem. I mean, so now that you've done the hire, how do you build a team?
How do you, how do you get them in there? Yeah. You know, we used to fly them out for a week. So, you know, for a week, they, you know, when, when there was, you a smaller percentage of the team was remote, you know, you bring them into the mothership. And so now we're trying to figure out ways— do we do round robins where they have video meetings with everybody on the team?
Or how do you build those relationships? Even the logistics of it all. Like, so, you know, I don't know if you guys have seen this or not, but when we've onboarded folks, if we didn't have an inventory of, you know, Dell laptops as an example, or MacBook Pros, you know, there was a backorder on all this equipment. So Dell even came out as like one of our main partners and said, look, if it's got a screen, you're gonna see at least a multi-week delay. And so now you're like, okay, do I need to enable this new employee with a, you know, by letting them use their home system, uh, or give them a VDI, or figure out what that is?
So just the logistics of it can be a nightmare. Not even like your own logistics, but the impact that the vendor that you use or third party that you use has on, on your ability to, you know, make people productive. Yeah, I mean, the, the time that I mentioned earlier when I worked at home full-time, there were a few times in that 10-year period where I had managers that I, I never met in person. So, you know, they either— they would come into the team to take over and manage and then, you know, leave after a little while, or, you know, me moving internally within the company to different jobs. And it was always just very strange that there was never a great process for building up that relationship.
It would be, you know, we have some kind of check-in every once in a while, but it's like, you don't know, am I doing my job well? You know, how am I meshing with, you know, with them, with the rest of the team? What's my, what's my rating gonna be? I think, you know, you have to be much more intentional and, you know, set up, you know, specific times to get together and talk through things. I mean, it's hard to get those culture aspects when it's remote.
Bingo. You know, and even if you talk to someone a lot, if it's, if it's through Zoom or whatever, it's still hard to get the little personal interaction stuff that you really need. Or check in with them. How are you doing? I mean, you know, and different levels of stress out there.
I'd be curious if people have comments to throw them out on Slack. I know I need to do better about getting on Slack, but— Slack slacker. Exactly. But yeah, I'd be curious to see what people say about this on Slack. Yeah, for sure.
I think one of the other things that I think has been interesting around this time is thinking about how, you know, obviously this has affected our own organizations and, you know, we've got security challenges with people working remote and things like that. But then, you know, turn around, you have to think everyone else is having those same problems too. So how are you making sure that your vendors, that your, the people that support you you know, onboarding new vendors, things like that to, you know, maybe you have to have someone now that is, whether it's Dell or somebody else, that's doing remote builds for your systems, right? Because you don't have someone in the office that's doing that stuff. Is that something you guys have run into concern around that or?
There were a couple areas that, you know, we'd never ship from factory direct to employees. And so now we've got to, you know, some of those physical checks that we had, we've had to redesign for and it's not been smooth. I mean, it's just, it's figuring out where you had those, those touchpoints that are harder to do. You know, we're working through it. But yeah, the logistics and like you said, some of the options where we're having unexpected delays, it's making us You know, we all rushed to just-in-time inventory, and now we're rethinking that.
I think one of the, you know, obviously Steve and I work for a vendor. I've got a, you know, a traditional operational CISO role within the vendor as well. And, you know, all of our customers have at least, at least probably not all, I would say it's not all, I'd say a small percentage, but probably, you know, 100 customers that we've had reached out, out of our 4,000, reached out and said, hey, you know, not only tell me about your BCP/DR strategy again and your testing and, you know, basically those security questionnaires we all have to answer, but in a shortened condensed version just around the pandemic. And there were questions on there around your third-party vendors that support you and subsequently them. And so we had to make sure that, you know, all those touch points with those third parties that impact us or could impact our customers, we had to go respond to and talk to and say, what is your strategy?
How are you dealing with it? What's our delay cycle? And get all that stuff flushed out so that way we could have a good response for our customers. And so that, that is where we've seen, uh, some of that stuff come into play. Did you also, also see questions around, um, work from home and changes?
Oh yeah. You know, have, have you made changes here? What are you doing to make sure that you're employees are still secure. Yes, yes, we got all that. And luckily, you know, for us, like I mentioned before, and people have heard me talk about the whole zero trust piece, but I've been— we've been trying to drive that for a while.
And so that, that, that sets you up really nicely for this remote workforce piece, uh, and so does the fact that 50% of your workforce— our workforce is already remote. So we already were prepared for a lot of this, but we did still have to answer the questions of like, you know, what are you doing to protect the endpoints at home? What are you doing to control access and authentication? You know, there are things that probably you should be doing anyways as a security organization, but just a heightened focus on it, right? Yeah, I think one of the other things around that too is around compliance, right?
So, you know, both of you guys working for vendors, your services are probably certified for various things, whether it's ISO or SOC 2 or SOC or FedRAMP or whatever it is. And international. Yeah. Yeah. And so I don't think we always think about the fact that, oh, hey, we made— we probably just made a whole bunch of changes to our control structure.
How does that actually affect my compliance? Well, and your risk radar. I mean, you made— so let's say 10% of my experience, most companies, 10% or less are remote. Average company, you went to over 90% remote. Yeah, you know, some of those risk decisions you made when 10% were on VPNs, and, you know, now that 90% are on a VPN, you need to reevaluate is what are the risks, you know.
So it— a lot of war rooms are going through, um, you know, I always talk about the storming, norming, and performing. You know, we're through the storming. Got everybody operational. We're trying to figure out what the new normal is or the next normal. That's probably a drinking game by now.
And then, you know, trying to move towards performing, you know, time to go relook at the risk radar, time to go relook at the compliance stuff. You know, it's interesting. I was saying at the beginning of this pandemic that, you know, if we suffered a breach, there's no way you could just shrug your shoulders and say, ah, the pandemic, right? It wasn't going to be a viable answer. But, you know, some of that shifted, right?
So there's been a bunch of cases with insurance companies and things like that covering breaches to a certain degree based on some pandemic gap— gaps in their coverage during the pandemic. Uh, some regulations have allowed some, some leeway and, and loosening up some of the hard requirements within their, their, their, you know, their structure to be based on the pandemic. And so that's where governance and compliance has been a little bit loosened. But there's other sides too where HIPAA and all these other ones, SOC 2, everything else, that there's no loosening up of those regulations. Like HIPAA has basically came out and made a public statement, the folks that, that run that, and just said, no, you, you will still need to be compliant with all these HIPAA regulations.
And so you just have to If you're not there, you better get there really quickly. Yeah, I've always wondered about that because, you know, generally the compliance stance that I've taken and that I've seen at places where I've been is, all right, we're going to comply with all the stuff we need to comply to, but, you know, our business comes first. And if there is some kind of emergency or disaster, hey, we might have to make some changes. But, you know, the idea was always like, oh yeah, well, that's great, we'll make some changes for a week or 2 weeks, or, you know, whatever the short period of time is that you have to, to work through that emergency situation. And then, you know, you tell your regulators, hey, look, we had something unexpected come up, and, you know, we had a real emergency, so maybe we didn't comply with this little thing or that little thing during this time.
But then now all of a sudden, if if it's 3 months, if it's 4 months, if it's 6 months, you know, where is your— where does your window end for having to move either back to your original control set or to, you know, completely changing your controls so that your, your new normal is now in compliance? I mean, I think, I think, you know, as a— you know, I used to do obviously some audit work here and there and everything else in my past life as a consultant, but, you know, auditors and the folks that actually test your adherence to various regulations, they love compensating controls, right? As long as you've got a compensating control for something. And I think the pandemic situation really highlighted— you're right, 100% operations of the business comes first, productivity of the business, making the business money comes first. And I feel like there are many CISO-type roles are out there in a more reactive stance of like, okay, if operations comes first and productivity of the business comes first, there may be some things that we're going to have to get looser on.
But now I'm in a position where it's like, okay, I have to figure out compensating controls quickly around that. And so I think, I think as long as you have that stuff in place, whether it's temporary or long-term, you'll be in a good position from a compliance perspective. That's always been my stance, is the, the mission of the CISO is to make sure the business leaders understand the risk they've taken and the options to mitigate it. You know, and if you're saying this is the amount of risk you're taking here, be it, you know, real risk, be it brand risk, or be it compliance risk, they've got to keep the business operational. And then you come up with the best mitigations you can.
And the risk appetite is definitely different in each business and who your board is, who your executive team is, how you operate the business. Us being a security company, they're less tolerant of taking security risks and they'd rather err on the side of let's be more secure than less. And so that has come into play too where we may experience some delays in operation with allowing people to use their home systems systems as a good example, right? We put that in, we updated our policies to reflect that we were going to allow that under very certain stipulations around it. And then being able to do that.
So there's the delay there now, right? So we can get them set up, but now we have to push software to it. We have to do a bunch of different things. But that's where they erred more on the side of security than we're just going to open up access to these home systems, period. I agree, it's different by industry.
It's also different by size of company. You know, startups have to accept a lot more risk. As the company gets more mature, you see them take, you know, more conservative risk postures usually. It's also interesting when I look at our customer base, even some of the— or prospective customer base— even some of the hardest hit industries, their security budget hasn't been cut. They're, you know, now don't get me wrong, uh, there are a number of them, you know, I have folks that came from healthcare where a number of them have been furloughed, right, to help save because, you know, in healthcare elective surgeries is such a massive portion of their revenue base.
And if they would— if they're not doing that, that's a significant loss. And so there have been a number of them that have been furloughed, but we see spending as far as like software technology, infrastructure, all that's still happening right now. Now, you have to go through various levels of approval now, but we haven't seen even— like, I know someone who's a CISO of a travel resort company that does nothing but that. So one of the hardest-hit industries that we've had during this whole thing, and they were still moving forward with their purchase of security technologies because their budget wasn't touched. Everything else was touched within the company, but not them.
Yeah, I've seen, I've seen some cut the least, you know, security, you know, everybody gets cut 20%, they get cut 10%. I've also seen right during the crisis, I saw some customers surge everybody out of security into IT to get all the remote workers set up. You know, kind of like you were talking, your wife would have been moved over to ICU, you know, that, that short time, move everybody over here. And I think in some ways that was a positive by pulling security into that crisis to how it was done. You know, there was a voice of security in there saying, well, that might cause us problems down the road.
Let's do it this other way. Yeah. And James, you were talking about healthcare. You know, one of the things that I thought about too is, you know, obviously they— that's an industry where they were, you know, directly affected by the crisis in terms of having to shift resources, you know, all of a sudden having influxes in ICU and in other places from, you know, people with COVID all of a sudden having to, you know, potentially onboard tens of or hundreds of ventilators or other things, life-saving equipment that's probably internet-connected and has to be managed.
Have you heard anything from people that you know around that process? We're talking about, hey, we're going to let some things lapse during the emergency. We know it's hard enough to secure internet-connected things things like that, then all of a sudden you have to do it even faster, maybe stuff you hadn't even planned on having before, emergency ventilators, things like that? I'll say this with a grain of salt because not every healthcare organization is alike and some are 20 years behind the IT security curve. Some of them are on par with it.
I don't know very many that are ahead by any stretch of the imagination, but I would say that a number of hospital organizations have done a decent job of being able to segregate and isolate medical devices and things of the like. So if they have to onboard ventilators or anything that's internet connected, it'll go into this medical device portion of their network that already has some perimeter controls around it and everything else, and the internet access is controlled. And so I think a lot of hospitals have that piece in play. The interesting part for me, from a healthcare perspective, I'm actually slightly less concerned. I think the residual risk that was already there with medical devices is still there regardless.
But I think the interesting one is the sudden ramp-up in telehealth and telemedicine. And it went from being such a small fraction of how they operated to a massive component of how they operate now. I mean, I mean, like, you know, no one wants to go into the hospital and be like, oh, you know, I'm gonna go to the emergency room because I, you know, I have a, you know, a cut on my hand. It's like, okay, okay, that cut may put you at risk for unnecessary risk for contracting COVID. I don't know.
And so telehealth is such a big thing, and you've got all these players like Zoom and some of these other collaboration technologies that are really hammering on healthcare into wanting to be that telehealth provider. So you would think it's not you know, it's not just a, you know, homegrown telehealth system you have to worry about, but then all the privacy concerns around it, you know, the concern, inherent concerns with the, the vendors. So if you're using Zoom as an example, whatever they've got from a security perspective you're inheriting as a part of that. That part is the part that really freaks me out, and seeing people's homes and, and, and videos and, and being able to record things and store them. Like, how does all— how's all that transacting to keep that patient safe?
Well, I mean, we know Zoom data all ends up in China anyway, so that's probably HIPAA compliant. Yes, of course. The one area, the one resource I would point out that I appreciate is, you know, I think MITRE does a lot of great things. The MITRE ATT&CK framework is a method that kind of tries to categorize all the potential threats, and they said that the industrial control system, all those legacy type systems, of which I would, you know, put a lot of those medical devices in that category. You know, you've got the OT and the ICS, and they have an ICS just for, you know, IT ICS ATT&CK framework separate from the normal one.
And so that's a great resource if you're in any of those type of industries to go look at. Yeah, their cloud and their ICS frameworks they just, I think, released actually at the beginning of this year and maybe late last year, but I know we're starting to develop content around it right now just to help our customers that have to deal with manufacturing systems, medical devices, anything else that could be considered an industrial control system type situation. I know they're doing one for insider threat too, so they're continuing to expand on those frameworks. They're also doing things in partnership partnerships. Again, coming from healthcare, I've got a little bit of a closer affiliation to that industry, but they're doing things around— there's a whole NIST Cybersecurity Center of Excellence.
I'm sure you've probably heard of it, but MITRE is a big player in that. We're working with them even on how to secure telehealth, how to do all this stuff. They're going beyond just coming out with the ICS framework, out with Insider Threat, they're actually partnering with a number of companies to do studies on how to protect certain components of various industries, which I find pretty interesting as well. Yeah, I have seen some of those NIST publications where it's more case study, focusing on something narrow as opposed to just putting out a generic standard that people can adopt. That's right.
Those have been pretty cool. They're in the process, I don't know if it may be out by now. I remember reviewing the draft for Zero Trust, very focused on that Zero Trust. You can see in there they debate some of the methodologies of segmentation versus more the Layer 7 access control, more the Google— if you've read the Google Corp docs, more of that technique. Beyond Corp.
I'm sorry, Beyond Corp, thanks. The, you know, so I think that I like some of the stuff they're trying to do there. Yeah, you know, I mean, one of the other things, hearkening back to the people too, is everything that we're talking about is, is stressful. And, you know, especially now you're working 10, 12 hours a day instead of, you know, 8 to 10 hours a day or something like that. You're you're cooped up at home, you know, with only your family, although, you know, people are starting to get out a little bit more now, and very stressful times.
I mean, how have you guys been dealing with stress, and how have you— have you seen any of that stuff boil over, or are you guys working with your teams or your companies on any particular ways to help people manage with the additional stress? Because cybersecurity is stressful stressful enough by itself. Yeah, I mean, A, we have seen stress, right? So I mentioned in healthcare you've got organizations that are furloughing their security staff, people are going hiring freezes, some are doing hiring cuts, and we already know about the shortage of cybersecurity folks in our industry in general already. So you've already got that kind of inherent stress, and then now you're adding additional stress on those people.
But the problem with— well, it's not a problem, it's just like security folks feel like this responsibility to still be able to carry through that security mission. And so I found even folks on my staff where they're adding— they're picking up any slack that's been left off to try to basically ensure that we can stay protected. And some of them, you know, that makes them work 10, 12, 15-hour days trying to keep up with the pace of what's happening. So we have seen that stress. And, you know, our companies are doing certain things.
So, you know, we did a, um, yeah, the reason why I originally mentioned maybe doing this podcast on, on Friday is because, you know, we're doing a relaxed Friday now. So every Friday throughout the summer, um, you know, we do a half day off, right? So that way people can take off at noon and go do whatever they want to do. We've added a few extra days off into the calendar as well. And so we're doing a number of different things to try to give back some time, but the hardest part about being a security professional is that half of them don't take that time and you have to almost micromanage them to go take that time because otherwise they'll be like, oh, this is great.
I get a full day where I won't be bothered. I can crunch through all this work and leverage that time appropriately, but then they never ever get to take a break. I think that is going to start to add up and And I think I can see the stress levels rising. And I think at some point, it's going to, you know, kind of hit the peak and then you'll have to figure that out. So I did an article, I've posted it out there on LinkedIn, basically looking at some of the lessons learned from the military on POW camps.
I mean, you know, that's an interesting take on this. And it's just that same thing. I mean, how do you maintain your mental health when it's Groundhog Day. Right. You know, and in no way am I comparing to what we're going through to the POWs.
It's just some of the techniques that they use to stay mentally healthy are relevant. You know, and it talks through that, the terms like hope and, you know, what is stress and all that. So I thought that was interesting. And it has helped me with perspective as well, because I think perspective is important. We also struggle with our folks not, you know, not implementing those boundaries, working longer hours, working, you know, weekends, not stopping, and are worried about that long term.
You know, it's going to have a worse effect. Our productivity is very high right now. Because the options are work or your family or your apartment or whatever it is.
But yeah, there's a lot of focus on that with us, and we're hearing that from our customers as well, that we're right now experimenting with a No Meeting Monday because statistically we have 25% more meetings than we used to on most of our people's calendars, and so we're trying to figure out how do we give them those days where they can get stuff, more stuff done so they can take the weekend off. Just 25%, I think that's surprising in itself. I think we've probably seen a 50% increase across the board for our folks. I'll take it a slightly more morbid turn. You know, I read a study and I can't remember all the details.
It was probably 4 or 5 years ago about suicide rates in cybersecurity professionals. And I would be curious— again, slightly morbid— but I'd be curious to understand and see how this situation, as an example, has impacted the stress and the burnout and everything else that's happening now. How much is it going to impact that rate? And, you know, I, I could see it. I could see a correlation where there's a spike in that activity associated with this whole work from home, remote workforce, you know, furloughing, staff cuts, all that stuff adding to that stress level.
You went the exact opposite direction I went because I said, you know, once we started the lockdown, I said, how many babies are we going to have 9 months from now? There's that aspect. So there's another form of stress. Yes. My wife has already started talking to me about number 3.
So, um, yeah, I, I think, uh, James, to your point earlier about, you know, making things intentional, making people take time off, you know, I realized in the, the middle of April that I hadn't taken a single vacation day yet all year. Um, you know, we originally had some, uh, some plan. I mean, you know, I started a new job in December, so, you know, it wasn't going to be early on me taking vacation anyway. But then we had plans. We were going to go somewhere for spring break.
We had some other stuff going on. We were going to be visiting my parents at some point. And but then, you know, all that got canceled. And so, you know, I realized between, you know, the beginning of the year and middle of April, I had worked every working day of the year. And I thought, I just got to take a day off.
I mean, I can't do anything different, but I'm just not gonna work today. So I took a day off and just relaxed. And, you know, it was actually— even though I— it was basically the same day, same thing as having, you know, an extra weekend day because I couldn't go anywhere, I couldn't really do anything. It was just nice not to have that extra stress, not to have to worry about doing anything. And just, you know, the day I took like that, I made a no-screen day, which made it even more different.
Yeah. Yeah, I mean, I was supposed to leave for California to visit my Korean side of my family in 8 days, and they haven't met my youngest who's just turning 1 on the 5th of July, and all that got canceled. And so, you know, part of it was I already had a week blocked off, and usually I time the week similar to probably what Alex does with kids. It's like, all right, if they're on summer break or spring break or this, you time it around that. And so, you know, my kid is in pre-K, my oldest So we were timing it around their, their summer break.
And, and now we're like, all right, we're not going, right? We canceled all that. But I kept the vacation days on the books so that way I'm sort of forced to take them. Even if I do absolutely nothing, I'll take the time off. You know, the only problem is we said, okay, we'll do a staycation.
And, uh, but that's what everybody's doing. So like everything is like, like going camping is hard enough in Colorado because you have to get all the permits and everything else, but now it's like almost impossible, right? Uh, and so we're doing a lot with the extended family camped in the backyard. Oh yeah. And, and, uh, interestingly enough, only 2 people made it all the way through the night outside, but it's just something different.
Yeah, I mean, even little things like that, changing it up, make a big difference. Uh, we were lucky enough, we have some friends that have a a cabin, and we went up with them last weekend because it is nearly impossible to find someplace to actually camp these days, uh, because everybody wants to do it. Um, and so it was nice just disconnecting, and, and we were in an area where you basically had no signal for anything, so even if you wanted screen time, you couldn't really get it. And, uh, we didn't do a whole lot of anything organized, just kind of relaxed and, you know, rode some four-wheelers and did some fishing. And I'm thinking Alma, Fairplay, Buena Vista, like that, you know, just going out there where you can disconnect and all the activities out there, and it's nice.
I'm hearing VRBOs are, are maxed out, which surprised me. I didn't, I didn't think they would be. Um, but, but yeah, it's harder to get a VRBO. We're renting a trailer and, and going up to, you know, Painted Desert, so some more thought process. By the way, those prices have shot up too.
Like, it'll cost you $100 plus a night to rent a camper to take around. It's crazy. Yeah, yeah. Switching topics slightly, have you guys seen either within your own organizations or other places— obviously we've been in emergency mode— have you seen areas more than others that have been neglected or put on hold? Obviously there's, you know, could be budget stuff that you— for specific projects, but, you know, what is it that you've seen that people have, you know, put aside or put on hold because they're dealing with all this other stuff?
Well, that's a really interesting question. I didn't put much thought into it. I mean, you know, we're small enough where I've got visibility still into, you know, all aspects of the business. And I would say, you know, for the most part, we're still operating, you know, all systems go, as normal as we normally would. So I wouldn't say there's any particular group or project or anything that's being neglected.
Now, I will say is that, you know, we've been asked as, you know, executive team members of, hey, take a look at your budget, take a look at what you're trying to do in 2020, see if we can delay it, see if we can get some concessions from vendors, see if we can do certain things to be able to just making sure we're doing the right thing to maximize cash for our business. And so, you know, you know, you'll see a little bit of that where I've taken a project and I pulled it back and said I'll push that to 2021. But, but overall, I wouldn't say anything's being neglected. My experience has been industry-specific, so gaming and streaming media they're accelerating, right?
I see other customers in hospitality and, you know, that everything's on hold because they don't know what their long-term revenue model is going to be. So basically everything got paused. And then there is that middle group of customers that haven't had a lot of disruption but aren't sure what the long-term revenue is going to be because of the economy and everything else.
And there, a lot of the stuff that they were doing to transform has been paused because they don't know if that transformation is still going to be the right investment 18 months from now. Right. And so kind of a spectrum is what I've seen. I think it'll be interesting too because I feel like the reason why I have— I take the position I do on this, and for the year of 2020, right, it's been a kind of a year of uncertainty, unknown. Most companies didn't know if the pandemic would impact them, impact their revenue, whatever the case is.
And I think what's going to happen is we're going to see, I think, the real effect as you get into Q4 of 2020 and Q1 when you go through— we're going through your budgeting cycle, whenever they're really taking a look at, okay, this is— now we know over the course of 2020 this was a total potential impact to our business based on the pandemic. Now I need to adjust for that in 2021. And so you may have gotten, you know, a larger budget number or larger spend or anything like that in 2020, but I'm really curious to see as we transition into 2021 if that gets leveled out based on the impact of 2020. And so I don't think we're seeing it fully yet. Uh, you know, I think a lot of companies that had started to start looking at software and technology and things like that continued on that trend for 2020, and some of them are accelerating for— because they have to because of the, the demand that they have as a business.
But some of them are accelerating it that we're seeing even because they're afraid of that budget going away in 2021. The other— so FS-ISAC, Financial Services ISAC keynote had an interesting talker or speaker. Talker. Talker. Yeah, he talkered.
And so we are drinking Johnnie Walker Blue Label at 10 in the morning. So morning drinking, open mic. Nice, nice discussion. So he said during the last recession, there was an interesting trend that people that couldn't find work were doing startup businesses. And so he said 5 years from now we're gonna see a lot of startups that had started now.
People graduating from college couldn't find a job, got together with some friends, did a startup. You know, people that lost their job became consultants, you know, became their own company, continued to do that. So he said that's another area of growth is just the number of startups. And obviously, you know, very small percentage become unicorns. A lot of them become steady businesses.
Um, but I thought that was— would be fascinating to look at. Yeah, I hadn't thought about that, but it's, it's totally true. Um, so we're getting close to time. Um, just thinking about something, James, I think that you said earlier Um, when at some point we are— we're gonna get back to— I don't want to call it normal, but we're gonna get back to, um, whatever the new normal is, even though I hate that term. Next normal.
Next normal. Um, what does that look like? Does that mean, uh, everyone's gonna be working from home full-time going forward? Does it mean businesses are completely changing how they're operating. What is the— when do we either get back to where we were or what it's going to be going forward?
You know, it's— that's an interesting question because I, you know, we took a poll, a survey with our employee base, and we asked them, you know, how effective have you been, productive have you been working from home? And well over 90% of our employee base said that they've been productive or more productive working from home. But then the next question was, you know, in the, in the future, would you prefer to continue working from home, come into the office, or a mix of both? Well over 50 to 60% said they want both. I actually think that's what we're going to see because the other part too is most businesses have signed leases potentially for an extended period of time.
Those, those, those, you know, owners of those facilities are not going to just be like, you know what, we get it, we're going to let you out of this you know, multi-million dollars worth of leases and, and let you do that. So the space is still going to be there, but I think we're going to start seeing a shift of probably a 50/50 workflow of from home and in the office. Um, there are some groups, developers, you know, teams that do better together. They'll want to come back to the office or they'll be driven back to their office. There are some things that I think that compliance and security is easier to do.
A call center, highly regulated industries, they may end up coming back. A security operations center.
I'm, you know, I'm very cultural biased, having built some of those, run some of those.
It just feels like it would be easier to have a SOC together. But the other half of me thinks about the amount of talent I could get to if I didn't have to have them all live in this zip code. And so part of me is like, let go. Let's go to a talent-based SOC, not a geographical SOC. Our surveys, much like you, are reflecting people, especially, you know, I have a friend who's in an apartment downtown in Denver.
Who desperately wants to go back to the office because he's at this point would like to talk to another, see another human. Right. And so I think there is some of that bonding, some of that culture that would be easier. I agree it will be a hybrid and very different by industry. The more tech industries are obviously going to have the ability to do it more.
Yeah, I think the other thing that people can't overlook in that is that we, we went from people being in the office. I mean, obviously there's some mix of people that were already working at home to then being at home.
The— you had the culture built in already because the people knew each other, right? They were already in the office with each other for a while. If you then go to 100% remote, at some point there's attrition, there's new hires, and then now you don't have that culture anymore. So if you're not doing some of that split where you do still see people from time to time, I think it's gonna be much tougher to maintain whatever culture that it is that you had and keep going with that. That is actually a very astute point because you're absolutely right.
The reason why people are successful right now being work from home is because the culture has already been built and they're already in it. They live it, they know it. But as that starts to erode away with being remote, it's very hard to maintain culture remote. And as that starts to erode away, your culture 100% is going to change. And I feel like there's been— Alex and I worked for an organization a number of years ago where you were fully remote and the culture was almost nonexistent.
You knew each other through maybe a Teams— or not Teams, it was same time back back in the day, uh, or something like that. But, uh, you know, there, there wasn't that sense of kind of culture that you would see at the same time. Yes, Lotus SameTime. You know, and I want to be careful because, you know, when the, when the telephone came along, the telephone was going to ruin everything because you weren't in person. And we had that whole generation of, you know, the phone is going to ruined this.
And then, you know, we saw it again with the mobile phone and texting, and people don't have relationships, they're talking to their device all the time. So I think we're gonna have to discover the new way to develop culture in a distributed way. And this is something international companies and, you know, companies like that have done fairly well, so it's not like this is uncharted waters here. If you've got a workforce that's spread across the globe, you have to somehow pull that stuff together, create cohesion, create culture, make sure that everything's collaborative. Otherwise you're gonna have pockets of people, which you still have too in a lot of international companies, where they feel like they're off on their own island.
And, you know, each island has its own culture. And so, but it's not uncharted, you know, companies have done this well. And so it's a matter of taking a look at some of those learnings and, and seeing how we can adopt some of that. But we, we in the US haven't done it consciously, right? For sure.
Awesome. Well, guys, I appreciate your time. It's, it's good to see your smiling faces. Um, Steve, thanks for bringing the booze. Appreciate it.
Um, and we'll go ahead and wrap up with that. Uh, this has been Colorado Equal Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.