Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 177 for the week of August 24th, 2020. Alex, good to see you this week.
Good to see you, Robb. Back together in person. Back together, getting the band back together, man. That's right. Speaking about that, last weekend I think it was, I watched Blues Brothers with my whole family.
This is the first time my kids had seen the movie. And while, you know, Blues Brothers is still a good movie, it's just amazing to me how different they made movies like in the '70s and '80s. Yeah, everything is so slow. It's like there's this giant buildup and all these things happening to like, you know, a, a 15-minute scene at the end of the movie. Right.
The, the, the, the, well, the, the drive back to the assessor's office. Right. Right. Basically everything's building towards that. That is one of my very favorite movies and it's almost exclusively about the music.
Not right. Not the drama. Well, and that's the other thing too, you know, that's, it's such a celebrity music cameo movie and my kids obviously know none of the people that, that were— Aretha Franklin. They know who she is, right? Yeah.
Right. Maybe, maybe kind of. And so it was kind of like, who's that person? What? Why are they?
Anyway, Ray Charles. Yeah, such a good movie. Yeah, it was a good movie. Okay, let's dive into some of our housekeeping. We do have a Slack channel with over 1,500 of Colorado's best security professionals.
You can come join that if you if you'd like to join us. Go out to colorado-security.com and click the Slack button, or we do have a new vanity URL for co-sec. .co/slack. Yeah. Yeah.
That's maybe not as easy as I was hoping to say. I'm sure everyone followed that just fine. Yeah. Uh, also if you go to the website, uh, you can find the mailing list that gives you the show notes in your email every week. Uh, go to the bottom of colorado-security.com, sign up, and you will get that delivered to you every Sunday when the new episode comes out.
I'm kind of tired of our housekeeping. Let's just blast through this really fast. We have a— we'd love it if you'd rate us and subscribe on your favorite podcast listening app. We'd love it if you would tell a friend about us if you like what we do. Pay us money if you want to support us on Patreon.
And of course, we'd love it if you'd help do interviews. We've actually had like a good run of a month plus of interviews, but we're just going to be out. I think we have the last one we're doing today and then we're out of our backlog. So I got a couple that I'm working on. So maybe, maybe we'll have some coming up, but we'll see.
We do like help. Other news in the area, we do have a salary survey going. Once again, big thanks to Jeff Ellis for helping put this together. But if you want to contribute your own salary information, you'll get a report of all the different security salaries in town. Obviously it is anonymous, and yes, if you participate, you get the data back.
Also, speaking of Patreon, we have a new patron this week, Chris Soans of Perforce Software. Thanks, Chris. Signed up at the $10 a month level. Not only does he get a shout out on the show, he gets a sweet, sweet Colorado Equal Security t-shirt. Yes, my plan is to have my son drive me and drop that off in person.
It hasn't happened yet though. Love it. And then other piece of local news, we have our book club, the Colorado Equal Security Book Club. Thanks to Douglas Brush for putting this together. They're gonna be meeting on the 27th.
That's this week, talking about the hard thing about hard things. So it's about hard things. That's what we're saying. Sounds pretty easy to me. Yeah.
Yeah. Simple. Cool. Hey, let's go over to talk about the news. We have a couple of new companies coming to town.
This first one, it sounds kind of fun. Yeah. So I guess technically the company is here already because they can deliver cars to you. But the cool vending machine that they have is not yet. So Carvana, they're an internet-based car buying service.
And, you know, you can buy something, they'll deliver it to you. But also in certain cities, they have these giant car vending machines where you can go and pick up your car. Yeah. So I saw a commercial for that on TV, I don't know, years ago. And I thought for sure it was a joke.
Like, like, you know, it's just hyperbole or this is what the future might look like. But they actually exist where I guess they give you a big coin, you put the coin in the machine after having paid for your car. Right. And then it'll bring the car down to you. It's a pretty cool idea.
Yeah, it is pretty cool. So this is going to be on I-25 and Evans potentially. Just take this to the freeway. Isn't that where the fire burned out that hotel? Oh yeah, maybe that.
I think that's where that is. That seems right. Yeah. But the plans show it being 14 stories tall. So you'll have a whole bunch of cars in this car vending machine.
Not going to miss that when you drive past on the freeway. You are not for sure. So that's coming. I couldn't see a time when it's going to be built. Did you see that anywhere?
I didn't. I think it's they're still in preliminary stages of planning. So hopefully soon. So if you, if you like to have, you know, your cars from a vending machine, we have that. And also, if you like to have all of your data followed all the time, there's a new company coming to town for you as well.
Yeah, Palantir, which has, you know, been in the news somewhat frequently, just in general, because of the work that they do. They are moving their headquarters from Palo Alto to Denver. So they, their CEO is really, you know, I guess there's a number of reasons for the move, but it sounds like trying to get out of the Bay Area, as he calls it, a monoculture is a big part of it. You know, they've had it been in the news a lot because of, you know, working with the government and helping the government do tracking and so forth, especially like things with ICE, you know, immigration. And the Bay Area is not supportive of such activities.
He's hoping to find a, a less— more supportive. There you go. A more supportive, less not supportive area in Denver. That's, that's interesting. They're also in the process of, of moving towards an IPO.
So there's a second article this week talking about their finances. Yeah, I thought that one was pretty interesting. Um, Palantir, I think they said, is 17 years old now or something like that. I was surprised how old they are. Yeah.
So they were kind of sort of a stealthy company for a long time, but, um, they, for being around 17 years, they actually don't have that, that big of a revenue, about, you know, $750 million in revenue in 2019. So they're, they're, I thought their revenue was, was okay. The problem is that they're losing $500 million a year. Yeah, that's a problem also. Yeah.
So, so if you're, if you're gonna make $750 million, maybe you should spend about $750 million, but they're spending, you know, like I said, about, about $500 million more than that. Some interesting numbers in this article. Not only, um, they had 25% revenue growth, which, you know, the article kind of takes a shot at that, but 25% revenue growth on a on a $500 million, $550 million revenue is actually pretty good. That's, that's pretty good growth at that point. Yeah.
And one of the other things they talk about is that they almost exclusively sell to the government. Well, now they went from what, like 45% government last year to like 55% this year or something. So they're growing their government business much faster. Yeah. And I think they started out originally only selling to the government and then tried to do private enterprise, and it, it has grown a little bit, but now they're sort of doubling down on the government work.
Well, yeah, during the pandemic and, you know, trying, trying to do contact tracing, I think that they have a piece of that as well. So they're doing a lot of interesting stuff. They're coming to Denver. You know, I think we're gonna— they're gonna be a controversial company here in town for us as well. Um, we'll be interested to see from a security— you know, just like if you don't even care about the ethics of it, um, from a security perspective and a privacy perspective, that's kind of interesting as well, right?
We're gonna have a We're gonna have opinions about that over time. How do you, you know, how do you track people for a government in a way that's, that's appropriate from a security and privacy perspective? I don't know if I know the answer to that. Yeah. I don't know either.
Yeah. Anyway, should be good. One more company in town. So next, you know, the reason that Palantir has been able to do this is through venture capital. And there is a new group that is working in Colorado to connect startups with growth capital.
Yeah, so Colorado Startups, which is a kind of on-the-nose name for what they do, is a group that's, that's really helping put together all the resources that startups here in town can use along with those companies. So folks, you know, who have great ideas, who are ready to scale, have some options. Yeah, and so it really is in that, that sort of initial growth phase, right? There, there do seem to be things already in place for, you know, accelerators and, you know, very early stage. But they felt that there was this need for, you know, finding more resources in that next stage, that growth stage.
And so they've partnered with Denver Angels, Kick Further, and Bigfoot Capital to help do this. This is, this is interesting, and I just love to see any way that we can make building a company in Colorado more approachable, more doable. This is how you, you build a network of successful startups. There have been a lot of startups in town that have been successful, but But, you know, what I hear is that they have to go to the coasts to get there to raise their money generally. Right.
So we want— we want to avoid that problem. The more you can stay in-state, the less you're going to have a venture, you know, investor who says, well, sure, we'll give you the money, but you got to move to the Bay Area. Right. Yeah, for sure. So hopefully that'll be good for all the startups out there.
Speaking of local companies with a privacy bent, FullContact is a local ad tech company and they have named a new CEO. And what was interesting to me is is I came into this article with a— I mean, it's ad tech, right? There's not a lot, right? There's not a lot positive for me to say about ad tech, that's the whole purpose of which is to track me across the internet so you can better market to me. But I thought that the article at least gave some counterpoints to that, that narrative.
Yeah, I mean, it seems like they are trying to do ad tech in a way that is more consumer-friendly as opposed to, um, just, you know, let's gobble up all the data that we can gobble up about you and then, you know, sell it to the highest bidder. So I mean, I think that's positive. Yeah, he— they say they want to have empathy and humanity in the way they approach this. And he's very specific in saying that, that all sharing that they do is, is meant to be with full consent from the user. Yeah.
Does full consent mean that I clicked through a banner without reading it? And because there's so many annoying banners in the way, I don't know. Right. But they're saying things that that at least give me a little pause on my generalization about ad tech in general. Yeah.
The other thing I, I think I remember FullContact from earlier on in their life when they were doing things like sort of address book centralization and other things like that. Maybe that was their, their first step in gathering all my data to know who I am and market to me. But I feel like they had that kind of software. So didn't even mention the new CEO is Chris Harrison. He was actually the president of the company, now CEO.
So it's not, not a big change. The former CEO has just moved in onto the board of directors, which is, it's like the most common way for these things to happen. So a natural progression. But, but it is a new opportunity there. Yeah.
Good for them. Next, Liberty Global is acquiring a Swiss telecom company in a deal valued at $7.5 billion. I feel like Liberty Global is the biggest Colorado company that none of us think of on a regular basis. Right. Yeah.
And I guess I hadn't realized some of the brands that they operate under. So they are— I think Virgin Media is one of the brands which, you know, that Virgin Media, Virgin Group is— if you'd asked me, I would have said that was Richard Branson, though. Yeah, maybe he sold that to them. Maybe so. Yeah.
Yeah. But I assume it started with him. Otherwise, something weird. I think that, you know, Liberty Global, Liberty Media is a They're a Colorado company in that their headquarters is here, but I don't think hardly any of their companies are headquartered here. Could be.
So like, you know, their, their big biggest wigs are in town, but, you know, probably a few dozen employees, not, you know, not the thousands. It might be kind of similar to Anschutz in that, you know, they own— they have a headquarters here, but then they have companies all over the place. Yeah. I mean, in this in particular, they're buying this telecom company to help further their interests in Europe. So they seem to have a bunch of these telecom companies in Europe and they needed in another market, which I think was one of the other— one of the main reasons for this acquisition.
Yeah. So they're spending 6.8 billion Swiss francs. So, you know, that's like $0.04. Is that a— is that what I think? I think it's roughly $7.5 billion.
So apparently the Swiss franc is worth more than the US dollar. Wow. Yeah, the franc is strong. Goes to show that the Swiss are doing just fine with those knives of theirs. No holes in that, in that Swiss franc.
Hey, oh, well done, Alex. Thank you. Thank you. All right. Moving over to our local security news.
You know, occasionally we throw in an article that's probably not meant so much for you guys as listeners, but for you guys to pass on to your friends and loved ones. Here's an article this week from Webroot around, you know, if you're working from home for the long haul, Here are the tips that will help you create a resilient home network. Yeah, and, um, there are not going to be any surprises in here, but again, good thing to, to pass on to the non-technical savvy. Things like using your VPN, getting MFA set up, uh, making sure you update software, the kind of backups, backups, the kind of things that are, are super important that, um, you know, we probably take for granted sometimes as enterprise security professionals, but things that everyone really needs to know and continue to pay attention to. I know I say this here, but yet I have not sent this email over to my mother and other less technical members of my family.
I probably should do that. That would be a good thing. All right, next article we have is from Swimlane. Uh, interesting, you know, we've had quite a few compliance regulation type stories over the years. This one is, I thought, kind of a different angle.
So it's going through the the privacy laws, the, the rights that you get under GDPR, and it's talking about how you can use orchestration automation to respond to those things. Yeah, I thought it was actually pretty cool. Um, the, you know, last week we talked about OneTrust, which was the number one company on the Inc. 5000 for, for growing companies. Yeah. And, you know, one of their biggest, uh, things that they do is what exactly they're talking about here in the, the SOAR platforms is basically automating the process around data requests, data subject requests.
I love this. I guarantee you that of our listeners out there, most of your companies are manually responding to data subject access requests, the vast majority of you, and they're probably low value for you guys, kind of a high pain threshold for that, and it would be a good challenge to say, okay, How many DSARs, data subject access requests, have we got and which of those can be automated going forward? Yeah, I mean, I think even parts of it, right? Because, you know, you got to manage the front end part with the consumer and their request to you, but then on the back end, you have to have a team that does the things that they're asking to do, right? And so even just automating or, you know, tracking the time to resolution for some of those things.
Hey, did I delete this customer's data? You know, when did I get the request? When did I do it? Those sorts of things. Um, I think it's a pretty novel way to look at it through, uh, through automation.
Yeah, I, I really appreciate Swimlane taking this angle. Obviously it's a sales pitch for them, but it's, but it's a really good way to, to show the value of what you can do with, with automation. Yeah. Next we have a blog from Coalfire talking about, uh, IoT, finding IoT vulnerabilities in embedded smart doorbells. Yeah, I mean, ColdFire continually, like, I gotta admit, like, they regularly impress me by the breadth of what they post on their blog and press release.
Like, you know, last week they probably were posting about how they're the first PCI assessor for whatever, and then this week they're doing an incredibly in-depth technical breakdown of IoT hacking. Yeah, I think the interesting part too is that this was just sort of like a learning exercise, right? It was like, Oh, hey, I want to learn more about embedded IoT devices and their security. And, you know, how should we do that? Oh, let's pick a random smart doorbell to look at.
And then they go through the process of, you know, how it is that they stripped the thing down and got access and, you know, figured out some interesting things that it was doing. Yeah. So, I mean, it is a very long blog post and it has technical specifications, physical hardware specifications for these things. It walks you through every step of the way. If you You know, there's, there's folks on the Slack channel just this week asking, how do I get into red teaming?
Um, my goodness, read this blog post, go do it. And, and you just got a really important skill that when, when you're in an interview and someone says, tell me about a cool thing you've done, you know, right, you can walk through every step of the way. Uh, I, uh, I took apart this doorbell and figured out that it talks back to China. That would be a good thing. Yeah, I think this is, this is really highly recommend for those who are, who are new at getting into things here and And anyone who just wants to understand how easily— easy it is to own your, your, your IoT devices.
Yeah, if you want to geek out, take a look at that article. And then finally, we have a blog post from Ping talking about Capital One and putting identity in the cloud. Yeah, you know, not often do you get to see big banks that are, that are willing to put their name on, you know, a kind of a case study for, for how to do stuff. And it's cool that Ping was able to get Cap One to agree to this, really talking about how they've gone from, you know, in their own data center identity model to this hybrid model where there's, you know, there's so many things still in their own data center they have to use, but then they can leverage the cloud to do it. So it's a good story talking about how to make that migration over time for big enterprises.
Good stuff. All right, that's it for the news. Let's jump over to the Slack message of the week. Once again, thanks to Andrej Gajda for sponsoring this. He has been Uh, been a sponsor of our prizes for the podcast basically from the beginning.
Um, so all 177 prizes that we've given away have been from him. That's a lot. Uh, so thanks to him for that. Um, and, uh, this week we have a Slack message of the week winner. And Robb, who is that?
Serge Borsow. Serge, thanks for your contribution. We had an interesting conversation in— oh, what channel was it? Was it— I think it was maybe under, under dev or AppSec or something. Um, around CISSP as a potential, uh, like, you know, how good is the AppSec content in CISSP?
And Serge took some shots at it as, you know, not being the, the best place to use. Of course, you know, uh, OWASP is, is specifically built for that. Um, and I think that was his point is, hey, you're gonna get better content from something like OWASP and their, their, uh, or even, I mean, if you wanted to stay in the ISC² family, they do have a CSSLP. Yeah, a more focused one on that as opposed to CISSP, which is more general. I did, you know, I did give him a little bit of feedback that I don't think— I think that the point of CISSP is that you should be able to discuss AppSec and everything else intelligently.
You should be able to walk into a meeting with experts in that area, but you're not going to be an expert on anything just because you get through your CISSP. And the same is true for physical security. I now know what a retina scanner is, but man, I don't know how to use the thing, right, from a CISSP. And that's the idea of the cert. And I think it's still a valuable thing to have, Robb.
But do you remember how long the, the runs of cable you can have for various different cable types and connectors? Man, they did get pretty in-depth on some of that stuff, right? How tall fences, security fences needed to be. I remember it anyway. I do remember where you were supposed to put the bollards in front of your, in front of your doors to stop the cars from running into the building.
Right. Anyway, congratulations to Serge. Thanks to Andre. Because of this, Serge will get a $25 credit towards an item in the Colorado Equal Security Store. If you didn't win this week, you could also go to the Colorado Equal Security Store and get your own stuff from there.
We've got all kinds of things. There's a link on the website. Or if you don't want to pay, say something really witty in Slack. That's right. And if you haven't won recently, you have a pretty good chance because we're always looking for new, new folks to recognize.
Exactly. All right. Let's talk about some events, Robb. Sure. So this week on the 25th, Denver ISSA is doing one of their online events.
They're doing a behavior-centric approach to securing data. That sounds fun. On the 26th, ISC² Pikes Peak chapter will be doing their August chapter meeting. On the 27th, ACIS, the physical security group, is doing Women in Security Coffee Chat with Carrie Darling. On the 28th, the DC 303 chapter will be doing their August meeting.
On the 3rd of September, ACES has another meeting. This is a webinar on de-escalating dangerous situations. That sounds like something that is very useful. Yeah. And then also on the 3rd, Colorado Springs ISSA is doing their September 2020 online series.
All right, that's the end of events for the next couple of weeks. Let's jump over to jobs. I have a Ping Identity job we just opened up in the last few days. We are hiring a a GRC analyst on my team. This is someone who's going to be focused on helping us with sales support for basically as we have customers.
It's not just sales, it's also like customer support around security. If someone wants to send us a questionnaire, we have to provide assurance to them, you know, helping with contract negotiations, really being the interpretation layer between how a security program works and what our customers and prospects need. Sounds like fun. If you want a different kind of job, The CIO for the state of Colorado is open, so you can apply to that. Didn't that didn't that personally make it maybe two years?
I don't think that they've been here very long. I remember that we covered that story pretty well when when it was a she right when she started working there. I feel like it was right at the beginning of Governor Polis's term. That sounds right. Yeah.
So I think that it's probably two years and a half. And she was she was in Boulder. I mean, I feel like I should remember the details. I should have prepped for this. Conversation.
Prep, what's that? Anyway, yeah, not, not a super long stay there. Cognizant is hiring a manager of security architecture and engineering. Trustwave is looking for an information security advisor. Bank of America is hiring a network security engineer.
Deepwatch is looking for a security analyst 3, weekday afternoon, remote. Does that mean that they start in the afternoon? It's a part-time job? Does that mean— I think that sounds to me like this is a SOC job. Yeah.
And so the shift that you work is weekdays, noon date. Yeah, something like that. Maybe a second shift kind of job. Yeah, but you get to do it remotely, so sounds all right. Western Union is hiring an IT audit manager.
Interstate Restoration is looking for an IT network security administrator. Federal Express, which I didn't know that they were hiring security people in town. FedEx is hiring a cybersecurity advisor for infrastructure security. And then finally, Route 9B down in the Springs is hiring a defensive cyber operations analyst. Love that.
Yes. Lots of, lots of good opportunities this week. And also just to settle what we were talking about a couple of weeks ago, they listed it as Route 9B, not R9B. Well, there you go. Just saying.
So either, either it really is Route 9B or that person is just as confused as we are. Yeah, exactly. All right. Well, that is it for the news. We do have an interview this week.
I sat down with Matt Alderman, and if you remember, you, you interviewed Matt. I did. I was thinking, oh, a year and a half ago. It was 3 years ago that you interviewed Matt. Time flies, Robb.
Yeah. So I sat down with Matt and learned about what he's been up to. So he— when you last talked to him, he had just left Tenable and was kind of in between, you know, advising some companies. He's been the CEO for Security Weekly, the podcast network, for 2 years now. Well, hopefully we get a shout out on the PSW network to get some people to come listen to this podcast.
Good, good stuff. So anyway, hear from Matt, and then we'll look forward to hearing or talking to you guys again next week. All right. Thanks, Robb. This is Josh Ryan, network manager for Ultra Petroleum.
Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is Robb, and I'm sitting today with Matt Alderman. Matt, you have so many titles that I'm gonna, I'm gonna go ahead and, uh, I'll just give the one. You're the CEO for Security Weekly, but you do a lot of other stuff too, and I'm interested to hear what you've been up to.
We had you on the show, we were just talking about, just, just less than 3 years ago, which is a, that's a pretty good, pretty good cycle for us to come back and see what's happened. You've done a lot since then. Oh yeah, been a, it's been a busy 3 years, that's for sure. Yeah, I'm looking forward to hearing about that. Before we do, let's kind of just talk about how have you been handling living it through COVID and, you know, staying at home in the Springs where your home is?
It's interesting, you know, I've been a remote worker since 2009 when I joined Qualys, so I'm used to being at home. And right before COVID hit, we had just moved into the new house down in Colorado Springs. I was doing the podcast remotely 3 weeks every month and then going into Rhode Island to the studio once a month. So I, I was set up for this type of event, because it's the way I had been working for years. The only thing that's a little different and kind of weird now is last weekend, last week, when I went back to studio for our Virtual Hacker Summer Camp event, was the first time I've been on a plane in almost 6 months.
Holy smokes. That's crazy for me. Because people who know me, you know, when I was at Tenable, we— I was flying, you know, around the world. I was flying overseas probably 6 times a year, right? My, my wife doesn't know what to do with me because I'm like homeless.
All the time now. So the honey-do list is getting really, really long. Like I was telling you earlier, I got a wine cellar built. I've been doing a lot of landscaping with the new house and trying to get all that done. So it's just been stuff around the house, but it's been weird not to be on an airplane.
Have you, have you settled in, or you're still, you're still feeling antsy to get traveling? I like to be in studio. I like to be out there.
The reason I went into studio last week was because of this event. We wanted to make it easier for all of our other remote guests. I didn't want to be remote and then have remote guests. And it was great to get back in the studio, spend time with the team, you know, just those things you do. I mean, we didn't walk out of there until 1 AM on Friday.
It was our last show, Paul's original show, Paul Security Weekly. It was 1 o'clock in the morning before we walked out of there. I'm like, I kind of missed that, right? Because you're just hanging out and talking. And, and so those are the things you miss when you can't be You know, back in the office or whatever.
Yeah, I, I think that what gets lost in all the conversation around whether it's, you know, if you're just as productive from home or you're not as productive, gets— what gets lost is the relationship element of it that you just— I mean, as much as we all try to do Zoom happy hours and put a little bit of time at the beginning of the meeting for fluff conversation or, you know, whatever team building events you can do on Zoom, it's just not the same thing as Sitting next to somebody while you eat, while you walk over to the restaurant. Well, what all these things that you just cannot get virtually is what I what I miss the most. And and I think we're effective for some number of months, but I think we're spending that relationship capital. And as you hire new employees into the system who don't have any of it, it's going to become even more difficult. Yeah, it's difficult.
I think for a couple reasons. Number one, I can't have a cigar when I'm doing a podcast unless I'm in studio because my wife won't let me have cigars. Guys in the house. Yeah, so I missed that. But it is sitting down and eating and joking with each other and building those relations, continuing to build those relationships.
We're on Zoom and Skype every single day. Yeah, through the podcast, through our meetings, everything else. It's not the same as being there. And I think that's the one element we miss in this environment. I've talked to a number of people, they're like, I've hired people that I have never physically met.
Like we hired them via Zoom. We have never met face to face. How crazy is that? Right. Well, I've, I've a few people we've hired that way now and so far so good, you know, knocking on wood, but it is, uh, you know, it is a different world.
That said, I think we do way too much. We think we're better interviewing than we are anyway. So, so, you know, it could be a machine that picks them and probably just as good as we do it anyway. So yeah, let it go. Well, let's, let's talk.
I think when you last talked with us, it was actually Alex who interviewed you and you guys were talking about Um, you know, you'd had a nice run at Tenable, and I think you were at the time when you interviewed with us kind of, uh, in between full-time positions doing some advisory work. Uh, what's— what have you been up to since 2017? Yeah, when I left Tenable, I kind of— I didn't know what I wanted to do next. I was, I was kind of in that mode of I didn't know what I wanted to be when I grew up. Um, so I took time off and primarily spent time doing advisory consulting work for a number of startups in the space, and I just I love the startup community.
I love innovation, helping early-stage companies figure out kind of what their message and category is and getting them out there. And one of my advisory clients was a company called Layered Insight in the container security space. Now, at Tenable, we had done a lot of research in the application security and container security space, made a couple acquisitions in that space, and one of the, the theses out of that research was that you could inject something into the container and protect the container from the inside out. That's what Layered Insight was doing. And so, uh, it was just a perfect fit.
Uh, I went full-time with them in January of '18, and then 10 months, 10 months later, we were acquired by Qualys. Uh, and for anybody who knows me, I spent almost 3 years at Qualys, uh, so I'd been there, done that. Really didn't expect to go back to Qualys. Um, so I started looking like, what's my next thing? This is October of 2018, and I was out looking at other companies and doing some work, and Paul Asadorian called me.
I, I'll never forget, um, the moment. My son attends the high school at the Air Force Academy, okay? And back then he wasn't driving yet, he wasn't old enough to drive, so I was driving him on and off the Air Force Academy every day for school. And so I come out of the Air Force Academy, I just dropped him off at school, and I'm on I-25 heading back up to our old house in Larkspur, and I get a phone call from Paul. I'm like, hey Paul, what's up?
He goes, he goes, I want you to come be my CEO. Just, just out of the blue. Just, that's how he starts the conversation. That's how he started the conversation. I've known, you know, Paul worked for me and did a lot on our competitive lab and a lot of our— that was at Tenable, right?
At Tenable, yeah. And he left in 2016. He left a year before I did. And so I was always helping Paul on the side, but he's like, no, no, seriously, like, come over here and help me grow Security Weekly. And I started thinking about it for a minute.
I'm like, okay, I could go back to a company. I could go do another Qualys, another Tenable, another whatever. Yeah. But the podcast has this just this great community and great audience where I felt that I could help many. I didn't have to pick one.
I could, I could help a lot. Yeah, but it took me a little bit of time to convince my wife because she's like, really, you want to go do podcasts? And I'm like, but this is why. And she's like, all right, go ahead. And so that's— so right after the Layered Insight acquisition was announced in October, I joined Paul and the team over at Security Weekly to help him run the company.
So talk to— what is the Security Weekly company? That's a good starting point. I know they do some podcasts. What's the company more broadly? What I think is interesting about Security Weekly is it actually started in 2005 as a video and audio podcast.
Now think about that. Most of the podcasts like this one is very audio-based. Paul had the vision 15 years ago to do everything in video and audio. Yeah. And the premise of the show was to sit down with his buddies smoke cigars, drink beer, and talk security.
Yeah, shop. But with one, one really important piece in mind: always give back to the community. So from day one, Paul made all of his content available to the community for free to download, to be able to learn and keep up with the latest and greatest. So very innovative if you think about it. Paul went through, you know, he was a consultant, he was a Uh, working at Tenable.
He was a product marketing manager for Nessus and always had the podcast kind of as his side gig, right? It was never his full-time thing, but he loved the podcast. So in 2016, he leaves. He decides to grow, uh, enter, uh, the Security Weekly brand. So what was really one show is now 7 shows.
So we produce 7 podcasts every single week on different aspects of security to the different security personas and audiences. Because as you know, security is such a broad topic, you can't cover it all in one show. So we ended up breaking it up into multiple shows, and, and that's what we do. All that content's free and available to the community. Yeah, so walk us through the 7 shows.
Uh, so we start on Mondays with Application Security Weekly— AppSec, DevOps, cloud security. Uh, the second show is Business Security Weekly. That's my primary show, which is really focused at the CISO level and the VP level. We talk leadership and communication. We don't cover the news.
I bring a CISO on that show once a month to try to help CISOs learn from other CISOs. So Alex has been on that show. You are actually on Enterprise Security Weekly, um, but also a very good fit for you because I want CISOs to really learn tips and tricks and recommendations from other CISOs. So that's really CISO senior level audience focus. On Tuesdays then we do Security and Compliance Weekly, which is a crossover between security and compliance.
Privacy and risk. Let's get into the GRC stuff. Yeah, we get into GRC, we get into compliance frameworks, we talk privacy, CCPA, GDPR kind of stuff. And who's the host of each show? So who hosts Application Security Weekly?
Uh, that is Mike Shima. Mike Shima runs product security at Square. He also built the web app scanner at Qualys back when I was there. So that's how I know Mike. I host Business Security Weekly.
Uh, Security and Compliance Weekly is hosted by Jeff Mann. Former QSA, PCI. He's been a big part of Paul's show for years. So that's his primary show. And then also on Tuesday, we do our short format news show, Security Weekly News, used to be known as Hack Naked News, kind of rebranded it a little bit.
You get a little bit of pushback from the corporate side on the name. So we kind of rebranded it this year. And I know that there's been, you know, this drive for inclusiveness and security. And the original graphic for Hack Naked was, was something that offended some people, right? And I think getting kind of moving further away from that's probably not a bad idea for— yeah.
And we still have the low— so we've got both the lady version and the man version. And one of the jokes we made last year is we're just going to print out a bunch of things and let people make their own so they can pick whatever they want. As part of their Hack Naked logo. People still want the t-shirts though, Robb, which is crazy. I mean, if you think about the environment we're in, people are like calling up Sam going, hey, can I get a t-shirt?
So she's like doing like special mail order t-shirts to people because there's no DEF CON or anything this year, right? Crazy. So that show, Security Weekly News, is our top 6 to 8 news articles, expert commentary. Doug White, who is over at Rogers Williams, he teaches over there, is now hosting that show on a primary basis. Then on Wednesday is one of our biggest shows now.
Enterprise Security Weekly was really the first show Paul added after he left Tenable, and it took a lot of the work and research we were doing in the competitive intelligence team and our competitive labs to really talk about what's happening in enterprise security. Product announcements, funding, all the enterprise news all gets covered in that show. That show on Wednesdays, along with Paul's original show on Thursday, are our 2 largest downloads. Yeah, 18,000, 19,000 downloads an episode. Thursday night is Paul's original show, still starts at 6 o'clock on Thursday nights Eastern time.
That show will go 2.5, 3 hours easy. Yeah, super practitioner technical focused. It's Paul's primary show. Paul also hosts Enterprise Security Weekly as well. And then on Friday we do a recap news show, part of, uh, Security Weekly News, but instead of just the top articles, we pull the top articles across all the shows.
So it's a nice recap show on Fridays just for people to get another update on all the big news across all the different environments on Friday. And then if you're a cigar smoker, then you can hang out for Stogie Geeks, which is Paul's 8th show. But who hosts the recap show on Fridays? Doug White again. Yeah.
So Doug does both. Yeah. And the Friday one. Yeah. Cool.
So you guys have obviously a pretty big schedule of podcast stuff. Is there other— you know, you talked about giving back to community. Are there other projects, other things that the company does other than, you know, producing those 7 or 8 podcasts? Yeah, there's a number of things that we try to work with on the community. Number one, anybody who has an open source project, has research that benefits the community, can come on and do a free interview with us at any time.
No more than half of our content is ever sponsored. Again, we want to create a platform for people to come on and share. So if you're out there working on something really cool or open source and you want to talk about it, you're more than welcome. The other thing we do— so like last year at DEF CON, we did a number of community-based interviews both at the Blue Team Village and the Social Engineering Village. And we did those with the community to bring some of that content on to help people understand what's going on at these different events.
We also did one down in Orlando, Florida. There's a high school down there in Orange County that does a CTF every year with all the schools in Florida, for example. High school, that's awesome. Yeah, high school kids, right, competing, which was awesome. And so I went down to cover that and did a number of interviews.
So we will do events like that. Paul and I will go out and do a keynote at an event, right? I mean, we always try to, try to get back into those environments. So this year has been a little tough because we haven't been able to do that kind of travel. Paul supports a ton of the local stuff in Rhode Island— Layer 8 and other conferences locally.
We promote those for free, uh, so people in the Rhode Island area South Boston can come in and get access to some of that content. So those are a number of the things that we do. That's great. What— and I'm curious, coming in as the CEO of a podcast company, what does success look like? I mean, it's easy to say, you know, drive revenue and listens.
Is that it? Is there more to success? How do you define— determine what you— what's your mission at Security Weekly? Yeah, I mean, outreach and audience growth is definitely a key component. Component.
If in order for my sponsors to be successful, they need to get as many impressions as they can in a program, which means I need to continue to grow my audience. So we've done a lot in growing that audience over the past number of years to continue to expand and extend that reach. That's good for our sponsors, that's good for anybody coming on to the show because more people are listening. So that is a big metric. The other one is really success for our partners and our sponsors.
More importantly, we have an interesting business model. It's a little different than most. I don't have a product to sell per se. I mean, I kind of do, but it's, it's not the way we think about it from a security perspective. Yeah.
In the past, I have to take what is a 100% anonymous audience because anybody can download or listen to my podcast. And turn it into a lead attribution for a sponsor. Yeah, that's an interesting challenge, and one that a lot of companies face, by the way. Go to your marketing team, for example, they'll have the same challenge. If you buy a billboard somewhere, exactly, what did I get for that?
Yeah, if you put an ad on an airplane, how do you create attribution? How do you know that a listener that is now a prospect heard it on Security Weekly? Now instinctively we know that, But I have to build better metrics programs for my sponsors in order to show that. And that is a huge part of success for us, is measuring downloads, measuring call to action to landing pages, measuring form submissions, measuring registrations to webcasts, and making that consumable by our sponsors. That is a big part of what we do.
That then leads to more renewals, more guests, more programs, et cetera. So there is a revenue perspective of that. But again, the way we treat the content and the way we've treated our audience in that we never require them to register, we never cookie the user, creates a really interesting marketing challenge for, for us. I'm just thinking, you know, my first thought was, well, this is no different than the problem of buying a Super Bowl ad, right? And people spend $1 million for whatever it costs for a million Super Bowl ad.
But, but maybe it's not quite the same because generally the Super Bowl ads are B2C, right? You're trying to reach consumers, a business going to a consumer directly, which means you're just by default, you're going to have big numbers. You're going to have, you know, I'm selling X number of GoPros, you know, every month. And do I see a spike after my Super Bowl? And, and for enterprise sales, which is what the vast majority of your sponsors have to be, doing.
Like, it's just lumpy, right? Like, everything— what, one, you know, $1 million deal just changed your whole month for the good or the bad. And did that come from Security Weekly, or did it come from something else? And it just makes it so much more difficult because the numbers are so small. Yeah.
And again, we're also very targeted. We're not a broad— we're not a Joe Rogan podcast. Yeah, right. Who reaches hundreds of thousands of people, but from all various backgrounds. We serve a security community purpose, so we're highly— our audience is very focused and specialized, so that creates some fun challenges.
But again, the basics are the same though. I need to build brand, I need to build some level of thought leadership, and then I have to generate leads. I mean, the programs are similar. We do them in various ways on the podcast. But it's what every single marketing team for every single product company needs to do, whether you're in security or not.
We just happen to have a security focus. So you've been there for almost 2 years? Yeah, a little over a year and a half. What's the biggest lesson you've learned? And I'd love to hear the best part, the worst part.
I'd love to get both sides of that, if you don't mind sharing. But what have you learned so far? Attribution is really hard. Yeah, I mean, it's super difficult, and it's super difficult when you put constraints on yourself about what you can and can't do from a tracking perspective. If you visit a website, you're getting cookied.
Mm-hmm. Almost anywhere except for when you come to Security Weekly. I don't cookie you. Yeah, that makes attribution really, really hard. That is one of the most difficult things, I think, to really figure out in a way that we can drive really good metrics for our sponsors.
That's the hardest one, no doubt about it, because we know we have a large audience, but measuring that large audience into unique people is very, very hard. And then who's taking action is even harder. So I know some podcasts have done surveys. Have you guys— have you done an annual listener survey every year? That's where we pull a lot of our demographics and information out of.
Those work well, but again, that's a subset of the audience. It's not the full breadth of the audience, and it might be a subset that's skewed towards some demographic, right? It's probably not a representative, but, but the numbers do align. So the good thing is when we distribute our content out to all the podcast catchers, we use Libsyn to do that for us. Libsyn gives us really good download metrics, and it breaks them down by country.
So it actually correlates pretty well when I— by geography, by geography. And so when I— but I guess what I mean is like what your sponsors would love to hear is you've got 80% purchasing decision, you know, people listening and, and, but I do, and I have that data, but it's all survey data. But exactly my point is, is that the survey, I would, I would venture to guess that the people who are most likely to have purchase authority are least likely to fill out your survey. I don't know that that's true, but, but I would guess that those people are like, nah, I don't have time for this versus— I think you'd be surprised actually. Yeah.
Because look, there have been some loyal listeners from Paul from day one. I mean, they're now CISOs in the environment and they still listen. And some of those folks do fill out that survey. I think some of the results of some of those folks would actually surprise you. I think we get a good cross-section.
You think so? Okay. But again, So it's way harder. So you're in what percentage of your listeners fill out the survey? Oh my gosh.
That's the hard part to measure. Well, but you have that, right? Cause you know how many downloads you get and you know how many, we don't know how many are unique. Okay. You assume that you got to assume that the majority of the 18,000 per week are the same 18,000 people, right?
Yeah. In that show. I mean, when I look at across all my shows, I mean, we're doing somewhere between 2.5 and 3 million downloads a year. Okay. Across all the shows.
Yeah. I mean, I would think that most people who listen probably subscribe and you get a download every week because of that, right? That's true. And then if I do use that number, then I'm probably getting somewhere between 2% and 3%, which sounds about what I would expect, right? That's kind of the ballpark for where survey responses are.
Yeah. Interesting. So that's a tough thing you've learned. Any great stuff? Like, you're so glad to have come across this in the job?
Uh, I think one of the things that's really interesting about what Paul started and built was he built actually some really good software. Hmm. Remember, I do— we do 7 podcasts a week with 7 employees. Yeah. The scale that we can publish content's actually pretty amazing for the staff.
I have basically one full-time production engineer that has a helper, kind of an intern, producing somewhere between 16 to 18 segments a week, 8 to 9 hours of content every week. Now you run— you do this podcast, and when you're done, you're gonna do some editing, and then you're gonna get it all cleaned up, and then you're gonna post it. Paul's automated that whole back-office function. And what's really interesting is when you know the podcasting business and you've been doing it as long as Paul's been doing it, there's so many things that we can automate that allow us to scale. And that's been amazing to see that because I didn't, I didn't understand that before.
But now that I'm there, I'm like, wait a minute, we can do this, we can do this, we can do this. Think about just from a publishing perspective, we record a segment, we drop it into our software, and within 30 minutes it's posted everywhere. It's on YouTube, it's on our WordPress site, it's ready to go out through Libsyn to hit all the podcast catchers. We've already blasted out on social media, and the guest already has an email with the link to the YouTube video saying, hey, thanks for, you know, joining this segment within 30 minutes. Okay, that's pretty amazing.
Pretty amazing. Yeah, if you think about it, both in video and audio. Okay, we also use that same software then to pull Libsyn and YouTube and WordPress to figure out all of our download and view stats and bring that back into the software. Now I can take it even one step further, and it's kind of my vision of where I want to take the software, is now I can have the sponsors have a self-service portal to log in to see all their metrics. We still do it manually today, but we're getting to the point where we can automate so much of that.
I can actually create self-service portals for our sponsors to actually see which episodes are getting more views, you know, where, what kind of, uh, how their, uh, ad is performing. There's so many things we can do. We're just at the tip of the iceberg. Yeah. So I mean, if you guys have created such great, or Paul has created such great software, like, is there, is that a business to get into offering that software?
Starting to have that conversation with sponsors now. So we have a lot of sponsors, you know, it's interesting. Sponsors mature sometimes out of what we can offer them. Hmm, you take some of the more mature sponsors that have their own podcast. They don't necessarily need us anymore in some respects.
I mean, they still might want the reach, they still might want the independence, but now they have their own podcast going. What if they used our software to distribute it? So we're actually having those conversations because Paul sees that as a new potential revenue driver, is look, if you have your own custom podcast, use our software and attach all the metadata and automate the distribution. Uh, so we are— that is very interesting. I mean, that your, your sponsors might be a good place to start, but like the podcasting world is huge, right?
Like, and, and if, if you, you can get it priced to some point that it's, you know, based on number of listens or whatever, you— there's a massive audience that, that you could get to that. Anyway, that's a pretty cool idea. Yeah, I was talking to a VC firm. He's like, you know, If you're ever interested in going broader, because, you know, Spotify is buying up businesses. Yeah, crazy.
Joe Rogan's podcast, for example. I mean, could you imagine doing some sort of licensing deal with Spotify to leverage the platform to do it? I think we have a little, a few more enhancements. The scale's not quite there, probably too, right? It is an interesting business opportunity.
Yeah, that's pretty, pretty good stuff. So any, uh, you know, any 2020, 2021 stuff that you're excited about? Going forward with Security Weekly you want to talk about? Yeah, I mean, a lot of it for us is growth. I think we're in a unique position in 2020.
We've always been virtual. We've always been able to bring in people remotely via Zoom or Skype. I think we're positioned really, really well as we think about the world we're in, at least for the next 6 months, of virtual. There's no more physical events. If we think about the way we've spent money in security, we spend them on the big events.
We go to RSA, we go to Black Hat, we pick our other events. You guys would do stuff in Identity, for example. Those events are gone, and there's a mixed review right now on the virtual event experience. Yeah. And so, but we have a proven virtual event podcast that's been out there for 15 years.
It's that we know how it works. It's proven. I think it creates an interesting opportunity for marketing teams as they're shifting away from physical events to look at podcasts as a way to continue. There's a lot of budget that's not being used right now, right? That is true.
Yeah. But, but we also noticed budgets are getting streamlined as well, right? I mean, and the bigger challenge for us, I think right now in the short term, is when budgets are released, they're released by quarter. So it's harder to do a longer term. Yeah.
And you're not trying to schedule 2 months from now, right? Right. Yeah, exactly. So I think we're in a good position. I think it'll be really interesting to see how 2021 shapes up with RSA conference being the first one coming back in May.
And to kind of see, do we get back together physically or not? That'll be the interesting kind of trend to watch. Yeah, didn't— way off topic— didn't Paul and John Strand create some kind of a product together that I can't remember the name of? That's Countermeasures. Is that still happening?
It's still there. All right. I mean, Paul So when Paul first left Tenable, he— it was called Offensive Countermeasures first. Now it's called Active Countermeasures. I think I got that right.
Uh, Paul and John did it together. They ended up hiring a CEO, Chris Brenton, to run it. Uh, so Chris runs it primarily. John continues to support it. Uh, we advertise for them.
Yeah, under Security Weekly umbrella. Uh, but Paul doesn't have much day-to-day interaction with it anymore. He is 100% focused on Security Weekly. I mean, that's between the software and the podcast and all the other stuff we do that keeps him more than busy. All right.
So I'd love to hear, now kind of taking off your Security Weekly hat, you know, you have so much visibility into, uh, through Security Weekly, but also the advising you do, like where security's going, where the focus is. Is there anything, you know, I don't want you to just give me a bunch of buzzwords. Is there anything that you're thinking like, practitioners and leaders out there in Colorado should be, should be going and getting themselves trained up on, should be reading about, you know, what's coming down the pipe that we should all be getting ready for? You know, I have this philosophy, and I look at it when I look at sponsors, I look at it when I do advisory work, investment work, whatever it is. I'm an app user data guy.
And what I mean by that is, regardless of what happens in digital transformation or remote work or whatever transition we're going through. There's 3 types of security controls that always have a play. Applications and how to secure the application, because everything we're communicating with is either a mobile or a backend web application. That's what we're dealing with. Yeah, we have to protect user machine identity, um, and how those identities interact with these applications, etc.
So identity has a big strong component of what we have to manage from a security perspective. Then ultimately nirvana is data. It always has been. And I'm seeing some really interesting innovation happening in all 3 of those spaces. And I love those spaces because I can make investments there and they're investments that are there for the long haul.
Where some of our traditional security approaches are starting to wane, right? We're starting to have to change them out. Especially network-based. Yeah, anything that's network-based, perimeter-based, uh, could be firewalls or VPNs. I mean, I had Richard Steinin on last week at IT Harvest, and he basically said, look, the firewall and the VPN markets are dead.
Zscaler's in a great position as a business, right? And so what you're going to see is this expansion of the perimeter explode. We knew it was happening. We instinctively knew it was going to happen, but it wasn't happening, happening fast enough for people. COVID-19 put it into acceleration mode.
And to the point where now that the genie's out of the bottle, I don't know that we can ever get it back in, where we're seeing CFOs and others say, look, we're gonna keep up to 30% of our workforce remote, right? That was never in the scenarios before. It is now, right? And so you're gonna see a lot of stuff there. I think you're gonna see some interesting innovation in remote worker teleworking environments.
Right, outside of app user data. What are we going to do with the home networks? What are we going to do with the endpoints at home, etc.? I think some of those vendors are in good shape, right? You've got some great endpoint vendors that I think are benefiting, but I think there's going to be some interesting innovation that has to happen there to continue to protect those environments.
Those are areas we see a lot of traction in right now. Cloud security is another big push. I kind of roll it into my application security But there's some really innovative stuff happening with the different cloud players, how to integrate cloud configuration validation into the DevOps CI/CD pipeline so that you can validate configurations before you actually deploy. Just some really interesting technology there. Any favorite new tech vendors that we should be aware of?
Yeah, there's a few, right? So on the data security side, a company called Secure Circle. Is just amazing what they do. They call themselves a data access security broker. They really sit between the user and the file system and protect data as it moves around, which means if I try to cut and paste data and move it, it actually encrypts it so it can't be tampered with.
So this is, this is an agent that's installed on your workstation and is— it's got to be some kind of structured data that you're accessing, right? Uh, this would be— or is it even more unstructured? Actually, so files, file systems, Word docs. So how does it know? I guess, yeah, I, I, I, all of a sudden, circle.
All right, all of a sudden I want to ask you a bunch of questions that an SAA for that company would have to answer. It's all policy-based. Okay, so you create, um, policies based on different, um, they call— I think they call them rings or circles of trust, uh, and then the data access security broker enforces those. Really interesting technology. When you think about unstructured data, there are some good structured data plays out there.
BigID and what Okira is doing in data lakes and stuff. But these guys are doing something very interesting in like stuff we have to protect every single day. They can do it in SaaS-based applications with SaaS data. They can do it with source code in Git and other repositories. Just a really interesting, cool technology.
Just absolutely love what they're doing because data security to me has been like the nirvana that we've never figured out. DLP was a, uh, at best, right? At best.
And this is kind of taking data security to the next level. So they're, they're really interesting. Um, on the cloud side, a company called Accurix, which is some of the old, uh, Layered Insight founders, are actually building some really interesting technology to validate Terraform, CloudFormation templates, uh, what's known as infrastructure as code. Prior to deployment and then look for misconfigurations, but then also look for drift in production. So you've seen vendors really monitor drift like the Dome9s of the world.
They can do it pre and post, which is really interesting because now it has a really interesting tie into the DevOps pipeline and validating configurations beforehand. Um, those are a couple of them right off the top of my head, but there's so much cool stuff out there. Yeah, that's awesome. And then what is, you know, what does it look like for the future look like for Matt? You know, you 3 years ago you were trying to figure it out.
Now you're, you're going to drive Security Weekly for some amount of time. Is, is this it? Is there, is there another startup coming in the future someday? What do you think? I do get pings occasionally.
Paul shouldn't hear this, but you know, I don't worry, he won't listen to this occasionally. Yeah, I don't— he's not, he's not in Colorado anyways, but I, you know, I get pings periodically. Yeah. Of startups coming by and wanting to do something. I'm like, look, I'm committed to Security Weekly, and my short-term vision is Security Weekly.
And, and I, you know, Paul and I joke about it. Look, we could do this forever because we're having so much fun, Robb. I, I mean, the amount of stuff we cover, but we're having fun while we do it. It's not like a normal job. It's actually really, really fun.
Um, we could do this forever. But there are some really interesting areas every once in a while that pique my interest. I'm like, it would be kind of fun to go do that again. It's not going to happen for a while. Yeah, I've got a commitment to Paul to really help him continue to grow the podcast.
And like I said, as long as we're having fun, this could be it. Somebody was joking with me the other day. They're like, so it looks like you're semi-retired. I'm like, dude, if this is semi-retired, this is way too much work, right? But, but it's fun work, so it's okay.
Yeah. I mean, I can imagine the title CEO of a podcast does sound semi-retired, but you just described the schedule and that was 5 days a week of creating podcasts. Yeah, it's a lot more than people think. They, they think, oh, I want to get in the podcast and I want to do— do you know how much work it takes? You got to find content, you got to find guests, you got to get— there's so much coordination that has to happen.
Yeah, I'm well aware of this. Yeah. This is why half of our podcasts lately haven't had an interview because we're like, We have jobs to do as well, right? Exactly. We're not semi-retired like Matt.
Yeah, I guess. Um, I— but I, I don't consider myself there either. I mean, we're so busy, which is good. Yeah, it's good for, for everybody. Um, but yeah, this, this is kind of the, the fun.
That's why I still have the advisory clients on the side. Yeah, I still have a number of advisory clients. Um, keeps you in the game. Up and, up and, up and— how's it go— how's it going with those guys? Uh, a Colorado company that does automated patching.
How are they doing? They're continuing to grow. We use them internally. Yeah, they're not currently a sponsor. They've been going through some transitions with their marketing team up north, but they're still growing.
Um, I think they're doing really, really well. Love their solution. Uh, they, they just— they were working with CrowdStrike pretty closely with, with some stuff in their store, so they continue to do well. You know, I still ping Fred every once in a while up at CyberGRX. They seem to be doing really, really well.
I think they had a tough couple of years, and it feels like maybe 2019 they turned a corner there. Yeah. And things really have got accelerated in the last 12, 18 months. Right. And so I think they're doing pretty well.
You know, LogRhythm, uh, I keep in touch with the LogRhythm folks. They're, they're still around. You know, they got bought by Thoma Bravo, so changes there. The Webroot guys got bought by what? Carbonite, and then somebody else.
Carbonite didn't— someone bought Carbonite, right? Yeah, was it Code 42? No, no, no, no, it wasn't Code 42. But I know a bunch of Webroot people that went over to Code 42 also. They've hired a bunch of people in town.
Have they? Yeah. And then, you know, ThreatX is up north as well, up in West Michigan. Swimlane's up there too. Swimlane's up there.
Cody, we've, you know, we've spent— we talked a lot with Cody over the past couple years. So there's still some great innovation here in Colorado, um, which I think is great. I mean, what you guys have done, a successful IPO for Ping, I thought that was great for Andre and you guys and all on the team. And I think it's great for Colorado, especially the Colorado security scene. You know, it's our first— I think it's the first IPO for security company in Colorado.
And there's, you know, we were really hoping Optiv would do it, we were hoping LogRhythm would do it, and it's still, you know, they still both could, but it's nice to see someone actually, you know, get across the finish line there. Yeah, I mean, Optiv is interesting because, you know, they've gone through so many different PE transactions over over the years, right, that you get to the point where, are the metrics ever there to go IPO, right? It's a huge resale business. You know, I worked at AccuVant when I first moved out here. I mean, I merged my consulting business in with AccuVant in 2004 when I came to Colorado and built out their compliance services practice.
Then we spun ControlPath, the GRC solution, out from there. Um, you know, I've watched those guys over the years and it's like, I, I just think they stay under a PE umbrella. I really thought LogRhythm had a chance. Yeah. And Thoma Bravo is going to do something with them.
You know that. I mean, Thoma Bravo has a track record of taking some of these companies. They've acquired a bunch. You know, they could do some really interesting things. They took SailPoint public.
Um, but the most likely outcome is for them to sell to a strategic somewhere. And, you know, I don't know, IBM could say they're tired of their own stuff. You know, one of those, one of those big companies, although there's not as many as there used to be, right? There's no Symantec now. There's no— yeah, I mean, it was interesting.
I mean, again, I was talking to Richard and he's like, you know, everybody's, you know, the endpoint market's on a boom because Symantec literally just disappeared overnight. I mean, literally just disappeared as soon as it went into Broadcom. It was like poof. And they made the decision that they're not going to support other than like the top 200 countries or companies in the, in the world. They're— everyone else is, you know, good luck.
Yeah. Yeah. Crazy. I mean, it's like crazy. It's like, so it's like one, like the CrowdStrike CEO had a dream and, you know, woke up and it came true, right?
Like, yeah, right. That's where it is. George is having just a, a great thank you party for, for Symantec for pulling out of the market. But, um, you know, even the Carbon, you know, there was a big division of Carbon Black folks up in, up in Boulder. You know, they're now part of VMware.
So it'll be interesting to see how that goes. You know, VMware, it's done a couple interesting acquisitions. So yeah, you know, we see a lot of that, but it's good for Colorado to have a good solid IPO company. I think it's good for more innovation coming in here. And look, we're seeing a lot of people come in from California and elsewhere, especially now.
Why would you pay rent in San Francisco if all you do is stay in your very tiny apartment every day, right? Like it's just all of a sudden the dynamics have shifted to getting out of these expensive Of course, Colorado is becoming an expensive geography too, but it has been. Yes, especially downtown. Yeah, I mean, downtown Denver. I mean, it's still reasonable down in the Springs, but we're seeing a ton of growth down there.
And I think you're going to continue to see real estate shortages and upticks, which I think is great for the state, don't get me wrong. But you're going to— you're going to— I think you're going to see more influx. Yeah, I think we are too, at least in the short term. We just covered a week or two ago a story that the average sale price of a home in Denver is over $600,000 now. So that's the average jumbo loan territory for your average home.
It's getting, uh, yeah, it's getting expensive. I wouldn't want to be a first-time home buyer. No, you'd hope that you'd pull some equity out before you go into the next one. But yeah, right. Yeah.
Well, this is great, Matt. What else? Anything else you'd like to share with the community? Uh, if you don't listen to Security Weekly, it's all free. So just, yeah, get out there, watch it, download it.
Tell us how we're doing, connect with us. How should they tell you how you're doing? On the website, there's emails for all the shows. So every show acronym@securityweekly.net gets to us and to the show hosts. We encourage that feedback.
We've got the YouTube channel that people can leave comments on. We check those weekly. Our Discord server, so if you sign up and subscribe, you can gain access to our Discord channel. Interact with us. We've been live streaming all of our shows during COVID because people are now home to watch, uh, and we're getting great interaction with the community in our Discord server during these live streams.
It's a really great way to interact with your peers and folks in the security industry. So, and we get a lot of feedback through that mechanism as well. Well, thanks a lot. Hopefully we'll get you, maybe not 3 years from now, hopefully we can get you even sooner and get whatever new things you get into, especially if you have any other local security company news in Colorado. Let's, let's stay plugged in.
Absolutely. Pleasure. Awesome, Matt. Thanks again for your time. Thank you.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.