Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is our newscast for episode 209 for the week of May 3rd. Alex, uh, how was your week?
Uh, my week was pretty good, Robb. Can't complain. Um, Actually had, uh, had visitors this week, had some family in town for the first time since pre-pandemic, so that was, uh, that was nice. Uh, how about you? Uh, you know, I went up to the, to the mountains and I actually rented a cabin kind of in the middle of nowhere.
And, you know, as a part of my time off, uh, I decided just to be by myself. I took my dog, did some hikes. I, I made the mistake of, uh, well, so Thursday was like the most beautiful day. There was a bunch of snow up in the mountains over during the week, but Thursday, it was perfect. Like, I don't know what the temperature was.
It was like mid, maybe high 30s, low 40s. But like with the sun out there, it was, it was literally like the best weather it could have been on the hike. We did like a nice 7-mile hike. But I also got like the most burned I've ever been during that hike. Apparently wearing a hat is not good enough against reflected snow.
So I definitely, I definitely look like a lobster right now. You should also wear clothes while you hike, Robb. Well, let's not go overboard here, Alex. I'm going to enjoy the great outdoors. You know, you got to do that au naturel.
Yeah, you know, that's how it goes. I get it. Yeah. Hey, let's jump over to some housekeeping. As a reminder, we have a Slack channel.
We'd love to have those of you who are in the Colorado community interested in security join us over there. The link to join is on the front page of colorado-security.com. We also have a mailing list that is on that same website. You can sign up to get the show notes delivered to you in your email every week. Uh, we'd love it if you would rate us and subscribe on your favorite pod catcher.
That way you can get the show notes delivered— or excuse me, the show downloaded into your own phone every week. Yeah, uh, we'd also love it if you told a friend. That would be great. Just let them know how great the, the movement is and that they should come join. As well as if they want to support us financially, we do have a Patreon campaign that we use to help cover the costs of Colorado Equals Security.
You can also find more information about that on the website, so people can go there. And thanks to all our patrons, we, we appreciate their financial support. Speaking of patron money, Alex, is it true that you've been using our Patreon money to go to the casinos in Colorado? Um, I haven't, Robb, but based on this next story, I might. It was a smooth accusatory segue, wasn't it?
That was. Uh, well, you know, how else are we gonna get the money for the show if I don't, you know, double, triple, quadruple it up? Right, right. If you don't, if you don't go play. And now the good news is now you can, you can bet a lot more money with, with each, uh, with each hand of cards or roll of the dice or whatever it is that you're doing in the casino.
Yeah, there was a bill passed a few months ago that, um, basically takes the, the limits that we have off of bets in Colorado at casinos. Originally, when the measures were passed to allow gambling in Colorado, there was a cap put on table games and things like that. So you can only do, I believe it's a $100 maximum bet, and that has been lifted. I'm not sure if it was completely lifted. The story was a little bit vague in that part, but I know it's going to be much, much higher.
Yeah, so originally, I know you and I have both been here long enough to remember, it used to be there was a $5 limit for any bet at the casinos. And what was it, like, maybe like 12 or 13 years ago, they raised that $5 limit to $100 per bet. And now I actually believe they just simply removed the limit. What I did see one place where it said that these casinos were planning to have bets up to $3,000 per hand, but that the highest of rollers could request a different table where they would have higher limits. So I think there is no limit at this point in Colorado casinos for what they can bet.
Not only is that going to have bigger bets and so forth, it's also going to bring in some new games. And I'm not sure if it was part of the law specifically that they can have different games that weren't allowed before, or just that the higher limits mean they can bring in some new games, but they specifically talked about baccarat as one that's going to start showing up as a result of this change. That's awesome. More games I can lose at. Yeah, and the more games I don't know how to play is, is a much easier way for them to take more of my money.
Good for, good for them. Pai Gow is another one that they're bringing in. I am a fan of Pai Gow. It's fun to sit down at a table and play 1,000 hands of Pai Gow and get up exactly where you started. Uh, a couple other things that I noticed from the story that were interesting, uh, the casinos, you know, they were closed for a few months at the beginning of the pandemic, but they have been open the rest of the time.
And, um, uh, now they're operating at 25% capacity. And I guess what's— that's actually causing, uh, casinos to have long lines outside with people waiting to get in, but they just can't come in until somebody else leaves. Yeah, that's kind of crazy. Um, I hadn't really thought about that until I saw the article, but, um, I guess that's good for the casinos that, that there's demand there. So, uh, hopefully they get to open up past 25%, uh, soon as the pandemic begins to lift more.
All right, good stuff. Moving from casinos to rubber shoes, we have some news from Crocs this, this week. Um, Crocs had record growth, uh, in Q1 of 2021. Uh, does that mean that they've lifted the price cap on Crocs so we can pay more than $100 for a pair of Crocs? I think that— I actually think that that might be what's coming in this story, Alex.
Oh, so, uh, uh, Crocs, they have been on a bit of a roll, and, uh, they expected that 2020 was going to be a good year for them. They had predicted adding 20% to 25% to the record sales. And now they predicted 2021 will jump 40% to 50%, which is pretty crazy. Yeah, they booked a record $460 in revenue in the first quarter of this year, which is 63% more than their revenue from a year ago. So my goodness, they have been absolutely killing it this year.
They also saw their profit. So revenue went up by 63%, 64%, but their profit went up by 9 times. So what would that be? 900%-ish from 16 cents per share to $1.50 per share. That is a pretty large jump.
And they also talk about in the story how now they're going to be doing some other things going forward. It does sound like throughout the past year or so, they have raised prices a little bit, and maybe they'll even be doing it more as the market allows. Sounds like they've also had strong sales in Asia, and also they sold almost 26 million pairs of shoes worldwide in the first 3 months of this year. That's a lot of shoes. Yeah, that is a lot of shoes.
What they don't say is what percentage of those shoes are the you know, the well-known rubber with holes in them. I don't, I don't know if there's— I know that they do have other kinds of shoes. I'd be curious to know what the breakdown is between the different types. Yeah. Uh, or industry or, you know, where, where they're getting sold to, that kind of thing.
Yeah. Good stuff. They— I'll say one thing that surprised me in this article was, you know, near the end of it, there was quite a bit of conversation around, uh, different celebrities that have been either endorsing or been seen in Crocs and, and that that's really driving a lot of their success. Yeah, that's pretty funny. They actually have a process where they do limited releases.
You can go to their website and sign up for information about limited releases. I knew this before the story because my younger son has for a long time— well, when he was younger, he had a pair of Lightning McQueen Crocs, and he's wanted to get another pair of Lightning McQueen Crocs, and they don't make them anymore. So they just announced a limited run of adult size of Lightning McQueen Crocs. Um, and we missed the window, uh, when they, they started selling them, um, by a couple hours, and they were already sold out by the time we got back to, uh, to check it out. So, so, so if anyone knows a way for you to get one of those, is this something that you're reaching out to the community?
Help, help out the Wood family. Maybe we should reach out to some of our friends at, uh, at Crocs and see if they can help me out. Yeah, I think, I think there might be someone we know who could help with that. Yep. All right, moving on.
Uh, we have an acquisition. SpotX, which is a local advertising company, has been acquired for $1.14 billion. Yeah, you know, I, I know just a little bit about SpotX, um, mostly because, uh, one of their security leaders, uh, from a couple years ago is a part of the community here in town. Um, so I reached out to him, Ryan Jameson, and said, hey, do you want to make a comment? And he's— he did want to.
So, uh, So SpotX was sold from RTL to Magnite, and Magnite was one of the biggest competitors for SpotX. Ryan says this is a good thing for all 3 parties. It looks like the Boulder presence for SpotX is going to stay where it is, and they're not going to decrease that size. I guess Mike and Steve, who are a couple of the leaders of the company, have close to 100 engineers working for them. So the continued investment in the ad space over the last 18 months is going to continue, and Ryan suggests it's going to continue growth for Colorado and for the company.
So he thinks it's a pretty good thing. Nice to get his opinion since I have no idea, but I do love to hear about local companies and what looks like a successful exit for those guys. Yeah, that's awesome. And for those that don't know, we mentioned SpotX does advertising. They specifically do video ads.
So a more specific and sort of, uh, targeted area of advertisement. But good for them. All right, we have a story from Galvanize, the local development boot camp. They have hired a new CEO, and, and this comes, what, about a year after they were acquired by a new company? Yeah, so, uh, Ricky Hamilton is named the new CEO.
Prior to being CEO, uh, Ricky was Executive VP of Revenue Operations, so sounds like a CRO kind of role. And, uh, was also chief of staff to the former CEO. Um, also before that, he worked at McKinsey Company, which is, you know, a global management consulting firm. So, uh, congratulations to Ricky on that promotion. Sounds like a good thing.
Yeah. So, so Galvanize, they were, they were bought by, um, what was it called, K12, when they were bought last year. But since then, K12 has rebranded as Stride. And, uh, and Stride is kind of a larger for-profit education-focused company And they— but the cool part here is right before this announcement of the growth, or excuse me, the new CEO, Stride announced that their— what do they call it— their career learning arm of the business had grown by 191% year over year. So that's very clearly a big part of the success for— or a big part of that is the success of Galvanize, and looking forward to seeing those guys continue to grow under the new leadership.
Nice, good stuff. All right, uh, next, a Colorado startup called Kickfurther has just closed on a $500— uh, excuse me, $5.9 million round for physical, uh, product crowdfunding. Robb, what's this all about? Yeah, you know, I obviously— Kickstarter sounds— or excuse me, Kickfurther sounds like an allusion to Kickstarter, and I was, I was not sure I understood exactly what the difference was, and After reading this, I think I get a pretty good idea. Um, so, so Kick Further, rather than, you know, the— it's just a platform where you're gonna, um, be able to, to ask people to pay for whatever it is you want.
They're really specialized on, um, putting together a platform that's— that allows just those people who have physical products to, to say, hey, in order for us to run this certain batch of whatever it is we're going to make, we need to sell this number of them in advance. And when that number gets hit, it's going to kick off that run, and the company that did it now gets a share of the profits, basically like they're being sold on consignment. So it looks to me like Kickfurther is much more involved in the manufacturing process and the the actual owning of the hardware than Kickstarter was. Yeah. I mean, it seems like with Kickstarter, all you're doing is having a platform where people can ask for money.
And then I've been part of a number of Kickstarter programs, and then you go and you give them money, and then they go off and try and figure out how to make their product, how to design it, and where they're going to get it manufactured, who they're going to work with, things like that. So it sounds like You know, this is a much more integrated process so that if you have a product that you want to get made, you know, you can work with Kickfurther to actually get it made, as opposed to, you know, sometimes months or years of delay in a Kickstarter project from the time that you commit to funding to whenever you get your product. Yeah, it looks pretty interesting to me. I, you know, coming in, I'm like, well, I don't know what problem they're trying to solve, and it seems to me like they're actually solving a real problem for, for those companies. So I'm excited to see these guys be successful.
Um, they do say that they have about 25 people right now split in between here, here in Colorado and Buffalo, Buffalo, New York. And the CEO mentioned that they're going to be adding between 5 and 10 new employees each quarter over the next year and a half. So, so good growth both here in Colorado and in Buffalo. Looking forward to seeing that company grow. Yeah, good stuff.
All right, moving on to our next story. Um, we have a story about Automox also closing a round of $110 million. I believe this is their Series C just about a year ago, they closed a $30 million Series B. So continuing to grow and sounds like good stuff for Automox. I mean, this is obviously a significant raise, over $100 million for a relatively young company.
I believe that they've been around less time than we've been doing the podcast. I remember them coming out and us interviewing Jay on the show shortly after they went live. It's really nice to see these guys. It looks like they're having quite a bit of success. I am curious, you know, how they're gonna be growing in the future, 'cause very clearly they're looking to go beyond just the patching, the automated patching that they do.
When you look at the notes in here, it says that they're planning to expand the platform into orchestration, monitoring, and inventory management. You know, what places are they gonna get into? Are they talking MDR? Are they talking about SOAR? Or are they talk, you know, or is it just a kind of a replacement for like a Jamf for a big fix or what?
I'm definitely curious about how they're going to grow. They do mention that the funds from this new raise are going to go toward hiring new folks, specifically on sales and operations, and he also mentions hiring engineers. So that looks like the big focus here, at least for the next year. Yeah, one of the other things that I noticed in the story, they talked about the fact that Dmitri Alperovich, who is the co-founder of CrowdStrike, Uh, has been named as the, the chairman of the board for Automox. And, you know, one of the things that they say about him is that they're trying to, to use him as a catalyst to help build Automox into the IT ops cloud.
So yeah, I, I mean, I don't know exactly what that means, like, like you were saying, but it's interesting— gonna be interesting to see where they go. Yeah, I definitely am curious about that. And I think that they actually just recently named him the new chairman of the board, and that was, that was a couple weeks ago, and we didn't have that one on the show, just you know, due to numbers for that week, but an interesting new change. All right, next story we have is a blog post from Laras. You know, we've— this is the well-known offensive pen testing company headquartered here in Denver.
We've talked about a couple of times, but this was a different pot— different blog than we usually have, and I actually found it really interesting. And I'll say, I don't always read every word of every article. I think I read every word of this. They're doing some pretty interesting stuff, basically walking through how do they do open source intelligence gathering and giving details specifically about how to do that on LinkedIn and GitHub. And I think there was one other place as well.
Yeah, it was definitely an interesting story. This was written by one of their testers talking about, you know, how they prep and, you know, what they do in terms of getting ready for tests, but also, you know, just in general, you know, how an attacker might do the same thing and areas where you can look and potentially lock down some information so that that's not as easily available to that are looking to profile your company. Yeah, it's definitely good stuff. I appreciate that. And I think if you're, if you're a security defender and you have a company, you might want to, you might want to take a read at this and think through, all right, what are, what do I need to do in order to protect my company from these types of attacks that, that clearly the bad guys are doing, not just the good guys?
Right. All right, next we have a story from Optiv talking about the basics of risk scoring. I thought that this was an interesting article as well. It's a little bit rambling. They start talking about risk fatigue and the fact that potentially newer risks that you have may seem more important than ones that you've known about for a while, just because of currency bias.
But they go into a good primer in here about what risks are, how you evaluate risks, how you score risk, and things like that. I thought if someone has an interest in understanding a little bit more about information risk management, then this is a pretty good blog. Yeah, I had a similar thought that this was really pretty useful for someone who maybe hasn't ever done a risk assessment and you want to learn, well, how do you do one and how do I maintain those risks year over year? I think they do a pretty good job going through that. You know, certainly not going to be a surprise for anyone who's been doing this for a while, but for those folks who are getting into risk for the first time, if you're maybe more on the more technical side and you want to learn how a risk assessment works, is a good read.
I agree. All right, final, uh, post for the week from the news section is, uh, is a blog by Red Canary. And, and this is a, another one of their, their great posts that's going to get into the real technical details of, uh, of an investigation. This is specifically around, um, where one of their, uh, investigators found a, uh, a signed renamed version of Mimikatz, um, that appeared to be you know, a legitimate part of a different program, but it's still a version of Mimikatz sitting on one of their customers' networks, and they had to decide, what do we want to do about that? Yeah, and, uh, it was very interesting as well, looking, uh, talking about the thought process and what they did to investigate and, and what they ultimately came up with.
And, uh, definitely an interesting read there.
All right, by the way, I'll, I'll ruin it by saying, um, they decided that it it was something that needed to be reported, but it probably was something that was intentional. So it's kind of an interesting dynamic to think, you know, maybe you find something that, that looks like it could be misused by, by bad people. It could be a hacking tool in the environment, but probably it was installed on purpose and being used for a migration. So, you know, just the thought process that goes into, well, if it's on purpose, should we be attacked? Should we be reporting it or not?
I found that pretty interesting. Yeah, probably, uh, also an interesting angle to think about, uh, you know, should you be installing this as part of a legitimate tool so that, you know, if you do have something bad happen, uh, you don't want attackers to have those tools sitting around just waiting to be used. Yeah. All right, let's jump over to the Slack message of the week, uh, starting off with a big thank you to Andre Gaeta. Andre's been our, our benefactor for this for, for years now.
Andre, thanks so much for what you do. As a result of his sponsorship, we're able to give one member of the Colorado Equal Security community a free item from the Colorado Equal Security store each week. Um, and, uh, and that's basically based on someone who starts a great conversation that, um, that comes from a part of what they posted. Yeah, and, uh, this week's winner is Jen Wilson. Congratulations, Jen.
Uh, Jen posted a link talking about the 2021 Denver Pub Pass, and there's also a Boulder one too. But this is sort of a coupon book where you can go to local breweries and things like that and get some discounts. Yeah. Basically, I think how it works is you spend $25 and you get a coupon to get one free beer from something like 20 different pubs in downtown Denver. So financially, it makes a lot of sense.
And then obviously, in terms of getting the opportunity to go out and socialize, I'm really looking forward to that. So I'll say I bought one of these Pub Passes and some other folks in the Slack community were buying them as well, and I'm hoping we'll get some, uh, Colorado Equal Security pub days together, uh, once things get a little bit more safe to go out in groups. That would be fun. All right, let's jump over to events. Uh, of course, we do have an event calendar on the website if you want to know everything that is going on in the, uh, the community around here.
Come check out that, uh, that calendar. But if you want to hear about what is happening in the next 2 weeks That's what we're gonna talk about next. All right, so on the 7th of May, coming up Friday, Colorado Springs Cyber is doing a hybrid First Friday. So they've had a First Friday thing there for quite a while, which is basically, you know, once a month the group gets together. And then during COVID they were doing a virtual First Friday.
And I think this is the first hybrid one they've set up. So you can get together in person or online, and hopefully that meeting's gonna go great. On the 12th, ISSA Denver is doing their May chapter meeting. We have a couple meetings on the 13th. First, ISSA Denver's Women in Security special interest group is getting together for their May meeting.
And also on the 13th, ACES, the local physical security group, is doing a crime prevention through environmental design to discourage, to discourage vagrancy meeting. Interesting. And then on the 14th of May, The Security Champions program, uh, is doing a meetup talking about is it necessary, what works and what doesn't. Yeah, it's a, it's a new group that, um, I think maybe we've talked about once before, but Dustin Lehr has put together. Um, and, and this is the, the name of the group isn't Security Champions, this is just the, the name of the week.
They don't have much of a name for the group itself. So, uh, it's an AppSec focus group that's getting together every once in a while through, um, what's it called, Meetup? No, that's not what it's called. What's the name of that website? Well, Meetup is one of them.
Meetup's the website. Yeah, yeah. So it's a meetup group that's, uh, getting together and they're talking about AppSec, and this month it's specifically around security champions. All right, I believe that is it for events. For events, yeah.
Let's jump over to jobs. Uh, first on the list, EchoStar is looking for a senior security engineer. Trail of Bits is hiring an application security engineer. This got publicized here in Colorado even though it's remote, but Trail of Bits is a well-known security company. I think it'd be a fun place to work.
Splunk is looking for a senior security specialist. Deloitte is hiring a cybersecurity operations manager. Direct Defense is looking for a principal application security consultant. Guild Education, one of the sweethearts of the tech scene here in Colorado, they're hiring a senior security engineer, and you get to work with Julie Ciccolo, the security leader over there. Zillow is looking for a senior security engineer for insider threat.
Epic is hiring a senior security engineer here in Denver. That was a surprise to me. Ibotta is looking for a senior security engineer. Lots of senior security engineers this week. And finally, a non-security job but for a security company.
Coalfire is hiring a head of inclusion and diversity. This is obviously a great position to see hired, and, um, it's not— be nice if we can get someone here in Colorado for that. Yeah, that's pretty cool. All right, well, that takes us to the end of the news this week. Uh, we do have an interview this week.
Aaron Bray, the CEO and co-founder of Phylum, which is a, a very small security startup that has— that he's headquartered here in Denver. I had him on the show, or on an interview, just a couple of weeks ago. Um, got to learn a lot about that, and I'm excited to share with you guys this new security company that hopefully we'll all be hearing a lot about as they as they go wildly successful. Awesome. I look forward to hearing about it, Robb.
Cool. All right, everyone, have a great week. Thanks, Robb. Hello, this is Benjamin Ealand, Chief Information Security Officer with the City of Boulder. This is Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.
Welcome to Colorado Equals Security. This is our interview this week where I am sitting down with Aaron Bray, Aaron is the CEO and founder of Phylum, and we're gonna get to learn about Phylum, which is a, a security company. And Aaron, as the CEO, is here located in Colorado, so we'll call this a Colorado security company. Um, Aaron, before we dive into the security stuff though, I, I understand you lived in northern Alaska. So number one, I want to know, how did you, how did you end up living there?
I would imagine that that's not a super populous part of the country. And number two, what was it like? Absolutely. So I actually lived in Kotzebue, K-O-T-Z-E-B-U-E, Alaska for a couple years during my childhood. My parents actually moved around quite a bit, and so we ended up up there for, uh, for a couple years.
It was a very interesting experience, uh, you know, when you're sort of that far north, and we were actually on the Bering Strait for whatever that's worth. And, um, there were no roads in or out, and the only way essentially back to the rest of civilization was by boater plane. So, uh, believe it or not, that town is actually somewhat of a major hub of that area. It has about 2,500 people, I believe. Um, so, so what kind of thing— by the way, I'm looking at a map of Alaska right now and seeing where this is.
Um, that is— that's an interesting place. The— there's a, a big bay there. Uh, what do we call this, this body of water? Um, just, just south of it, the— well, it says the Arctic Ocean, I guess. Is that— that's all it is there?
Uh, effectively, yeah. I mean, it was, uh, it wasn't a bad place overall, but, you know, it's, it's rather austere compared to most of the rest of the US and you know, really most of the other places I've lived. Probably the, the most comparable place is, you know, being in like a deployed environment. Yeah. So the, you know, when I think of northern Alaska, I think of lots and lots and lots of snow, uh, and, and probably it's dark most of the year.
Is that, is that basically what you experienced there? Well, so it's actually a bit of a split. Um, you know, during the summer it would get up to, you know, 60s, 70s, 80s. And of course, during the winter, it'd get quite cold, often, you know, down in the negative 20s, negative 30s, uh, you know, quite a bit of snow. During the summer, it was actually light almost all the time.
Um, so, you know, there's a period, of course, where there's 24 hours of light, but, you know, even, even surrounding that, it— you'll often see the sun will just set for maybe an hour, and then it'll come right back up again. And of course the same happens in the winter, just, just the reverse. So, you know, it'll be dark all the time, but then the sun will rise briefly, briefly, and then set again. And that sounds fairly miserable to me. What, what age were you when you lived in, in that, uh, in that part of Alaska?
So that was my late teens, so I was around 16, 17 during that time. Well, I guess at that point it gave you excuses to stay up all night, which You know, you don't need much of an excuse at that age. Absolutely. Uh, all right, good stuff. Well, so I'd love to hear a little bit more about your background.
You know, you obviously, you said you moved around. Why did you move around and, and where all did you live? Sure. So I spent a lot of my growing up time in the Southwest. So, um, you know, southern Colorado, New Mexico, um, you know, then of course later Alaska.
And I ended up joining the Air Force after that. I spent about 8 years in the military. You know, of course, my, uh, the sort of sale there is, you know, you're gonna go join the, join the Air Force, see the world. Well, I ended up mostly seeing San Antonio. I spent the vast majority of my time in there with a couple trips to places like Mississippi and Keesler, and also to Afghanistan.
After that, I ended up spending a little longer in the government space as a government civilian. I ended up leaving there to go help a friend of mine stand up the— stand up a red team at a large Fortune 500. And after working there for a bit, I ended up leaving to go work at startups for a little while. Which, you know, we— I ended up leaving to found my own startup, Phylum, last year. So that brings us to present.
So how did you get involved with technology and security? Was that before the military or something that came as a part of the military? Great question. So really, I think I've always been very interested in, you know, computing, you know, and information security and things of that nature, I ended up getting a lot of opportunities to have much deeper exposure to that during my time in government. And in fact, it was during that time where, you know, we— I first kind of came across the problem that we're working to solve today, you know, really understanding the supply chain of the software that goes into, into all of the products that people use.
So was it— was this a— when you got into the military, did they say, hey, you've got an aptitude towards computers, you've done something previously, and we're gonna give you more support? Or was it, hey, you know, names drawn out of a hat, you're gonna be the computer guy? Like, how does it go from, you know, you get in there, it's like getting this kind of exposure while you're in the military? Well, that's, that's a great question. So in my case, And it depends a little bit, I guess it varies a little bit from branch to branch, but at least for the Air Force, there's a lot of specialization toward various parts of essentially computing and information security.
At the time I joined, you know, I sort of got rolled into a position as sort of a system and network administrator. And so I did that for a bit. I started working on the defensive side. At that time, you know, of course went through training and tech school, you know, spent some time working in the, in the field, so to speak, in that capacity. And, you know, just gradually worked toward getting my degree, which, you know, my undergrad is computer science.
And so I was just very fortunate in that I had some great opportunities to continue on both during my time in the military And then also after I transitioned out. That's— it's so cool that, you know, the military, which, you know, I think generally we probably think of as mostly about fighting wars, right? But it also gives you all these fantastic skills that are, you know, directly transferable to what you're doing now. So what a neat opportunity.
All right, so talk to me about, you know, the idea that that prompted you to start a new company and how you figured you could, you know, have a unique angle on trying to solve it? Absolutely. So one of my co-founders and I, you know, we sort of initially got exposure to the landscape of package analysis and what things are really currently being done to understand, well, fundamentally, the supply chain of software. And what we found was that There are a lot of products that do a great job of reasoning about things like what the bill of materials of packages you're using are, or what vulnerabilities libraries that you're using might have in them that are well known and well understood and well documented. But what there isn't is anything that really does a good job of reasoning about all of the myriad other issues that you can run into with the software you're pulling in from upstream.
You know, some great examples of that are there have been a vast number of malicious packages that have been published into the open source ecosystem over the last few years. There have been some pretty high-profile incidents like SolarWinds, you know, just a few months ago, and there aren't really any products that do a good job of helping to recognize those things and reason about what I'll term the unknown unknowns of the software in dependencies that you're using. Yeah, so talk, talk to me about what kind of, what kind of, uh, unknown risks might, might exist out there. You know, not vulnerable— we're not talking about vulnerabilities within open source, right? What are we talking about?
Absolutely. So we're actually talking about things like no-kidding malware. Um, you know, I think it was maybe within the last month or two that the, the Python ecosystem had somewhere between 3,000 and 5,000 malicious packages where an author had taken a popular package, they made a copy of it, and they'd added either like a crypto miner, credential stealer, or a backdoor to it, and then re-uploaded it with a very similar name. And so a large volume was taken offline, you know, just within the last month or two. But even if we look back over the last couple years, there's just been a steep increase over that period of time in some very high-profile attacks, not only like that, but where people have actually gone to steal developer credentials, cryptocurrency, and other things.
So, so you're talking about for someone who's able to replace the binary and from a trusted source, and, and you guys help identify that? Is that the specific there? It's actually even a little bit more insidious than that. So the trusted source, if you will, is effectively a package manager that functions as almost a marketplace. Place.
So developers can write new software, new packages, and effectively anyone's able to go and publish these packages to these package managers. Interestingly enough, the graph of these packages— so if I, if I look at the software that my product depends on, I also have to look at the software packages that those packages depend on, and the packages that those packages depend on, and it ends up actually being a tremendous volume of software. The average number of dependencies has just skyrocketed over the last few years. And so now where, you know, someone might expect to get 3 or 4 packages, they end up pulling by just adding a single dependency to their project hundreds to thousands. And the consequence of this, of course, is that now instead of having a small number of authors that you know and trust, you've now got potentially hundreds to thousands to tens of thousands of authors that are all contributing to the code upstream, that's able to not only influence packages and products that are being built in-house, but also have the opportunity to run and execute logic developed by all of those upstream contributors on developer workstations and through the CI/CD pipeline.
And so how do you guys help solve that problem? Great question. So We really tried to change the question, you know, so we're not really focused so much on package component analysis and trying to tell you what the bill of materials of software you're using is, but instead we split that out into 5 axes of risk that we consider. So we examine everything from the source code itself that goes into these packages, we look at the authors and the relationships and how they contribute to code, So what their behavior is, you know, from package to package, how many packages they contribute to. We look at things like the issues that surround the packages, so in places like GitHub or GitLab and similar.
And we essentially take and tie all these together, and we layer on heuristics and analytical models that allowed us to basically tie together things that might indicate significant amounts of risk and sort of aggregate those into meaningful, meaningful findings. So for example, we can take and look at, you know, a set of calls into libraries. So a great example there would be to find a combination of 3 actions. So a download from the internet, then the decryption of a payload, And then the execution of said data after it goes through those steps. And, you know, certainly by applying only static analysis, we can't get with 100% certainty all of these things, but we can definitely identify spots where this is— where this is happening within the software graph upstream from things that people are using.
This, by the way, is a pattern that has shown up in, you know, malware both historically in the desktop computing environment It was actually a big indicator in the SolarWinds attack itself. And it's also happened— there's a great paper called The Backstabber's Knife Collection that came out, I think it was last year, that gives a great taxonomy of attacks to the open source ecosystem over the last few years. And it talks extensively about how this sort of attack and how this sort of behavior applies to, to many of these packages. That, you know, successfully executed attacks upstream through the open source ecosystem. So the SolarWinds one wasn't open source though, right?
This is presumably, it looks like somebody got access to the build environment within SolarWinds and added a backdoor. Exactly so. So how do you guys help in that situation? So in that situation in particular, we don't help today. But we can identify similar behavior in open source libraries that are being pulled in, as all of those essentially provide a similar attack vector.
All of them are able to weigh in at build time. They're all able to access the, you know, build server and CI system and surrounding environment. And so we're able to weigh in and help prevent those sorts of attacks from occurring through that vector. So you're looking in the environment And just, I'm trying to make sure I understand. You're looking in the environment at the, at the open source code to see, is there a callback?
Is there a command and control functionality that's within it? Is that what you're talking about? So that is, that is one potential thing we search for. Another great example would be, I mentioned the packages that had similar names that were taken down in the Python ecosystem. Because we have such a broad view of the data points that comprise that software, we're able to string together essentially information about how popular the packages are, how similar package names are, and the— what the actual components of those packages look like.
So how similar the internal pieces of each package are from, from one package to the other. And by stringing those sorts of information together, you know, we're also able to sort of proactively prevent users from downloading and using malicious packages that are rehosted in that fashion as well.
So you're— I'm sorry, I'm just trying to boil it down to like the actual like organizational risk. The thing that you're doing is using a pattern-based analysis to say this is what normal looks like, to say there's a new thing and that new thing is abnormal and the the new pattern is likely bad because we've seen other folks who do something like that, basically where they're replacing the legitimate version of this with a backdoored version. And as a result of that, we're gonna give you a risk, an elevated risk score for this open source component in your environment. Is that kind of a good summary? Absolutely, you got it.
You know, if we wanna make an analogy to the IDS world, instead of being something like Snort where, you know, we have a lot of pre-baked signatures that are either a thumbs up, thumbs down, We want to be a little bit more like a product like Bro, where we identify things that look weird and, you know, need to be addressed, need to be looked at further, and possibly be remediated. That makes sense. So when you, when you look at, you know, what, what's the right type of organization for you to partner with, you know, customers that, that could use you guys, is it, is it to replace an existing technology and they're portfolio? Is it augmentative or you're additive to what they're currently doing? Or is it a different place where, you know, folks maybe aren't even looking at all right now?
What do you think? Great question. So at this stage, we've seen it essentially be across the board. You know, we're able to weigh in on the same sorts of things that conventional package analysis products do, but we're also able to be augmentative to those products and essentially come in alongside and weigh in on the things that they're not able to examine and catch. So, you know, we certainly maintain, maintain a database of known vulnerabilities.
And, you know, as we're indexing packages and examining everything, you know, including source code, we're able to reason to a great degree about things like commercial license issues and things of that nature. But we're also looking pretty far beyond that. So And what companies are you— I guess I should ask kind of where are you in terms of do you have customers yet? Are there folks you're working with? You know, what state are you as an organization right now?
Great question. So we're a little bit pre-general release. We are basically working with a number of pilot customers right now across a pretty broad spread of different market verticals and sizes. One of the great things about the product that we're building is it generally applies to any organization that's concerned about security and also has a significant amount of software development.
And when you, when you guys look at, you know, you just did a lot of technical conversation. If we kind of take off your technical hat and put on your, you know, business development hat, you know, when you look at the market opportunity for you guys, I assume that you're kind of, you're tiering it, right? You're probably not expecting you can go after everyone all at once. Do you have a market segment that you think is first to start, the right place to start off initially? Absolutely.
So, you know, the spots that we found a lot of success so far have trended toward, you know, places sort of tangential to defense, the financial and fintech side, Uh, you know, those have been, have been pretty great places for us so far. I think, you know, even more broadly, it may be less about— at this stage at least, it may be less about the specific markets those organizations reside in and maybe a little bit more about their security maturity. So what things are they really concerned about? How concerned are they about their, about their software and AppSec program and, and sort of where are they at along that journey, if that makes sense. So I imagine from what you just said that you're looking for, you know, you partner best today with more mature security programs?
Absolutely, or, you know, even organizations that are a little more forward-leaning in terms of, you know, their willingness and ability to work with early-stage companies. Yeah, so, okay, so that's great and it makes sense, especially considering you guys are are going into an area that's not well covered now. It's going to be those companies that are, um, that, you know, have already done the basic blocking and tackling and are ready to move on to the next thing. Um, now let's talk about the, the structure, the process of building your own business. You know, this is, you know, your first startup, right?
How did it, how did it go? Were you like, hey, I got an idea, I think I can solve it? How do you go from that to actually having a company out there that's they're starting to do it? Great question. So we put a lot of effort initially into, you know, how to structure the founding team, what skills we needed to really cover in order to, you know, to put our best foot forward, so to speak, in getting the business off the ground.
I think there's also a great quote somewhere by Paul Graham about how the fact— how important the founding team of a company is. I'm paraphrasing here, and I'm probably gonna do a terrible job because I don't remember exactly how it's worded. But the crux of it is that, you know, it's a lot like buying a house. You can change almost everything about the house except for where it's located. And, you know, essentially the same is true with the founding team of the company.
So put a lot of effort into that. And then, you know, a lot of effort into market research and all of the things required to go out and raise our first round. So we put all of that together around May of last year, got the company off the ground, and, you know, we've, we've been charging forward ever since, you know, building the product, you know, working through all the hurdles to bring it to market. So tell me about the team. I know you mentioned you have a co-founder there.
Talk about the team you're working with. Absolutely. So I founded with, uh, with 2 other individuals. One, uh, Lewis, who's my co-founder and CTO. He also kind of came up on the government side, spent a lot of time in the intelligence community with me, which is where we first worked together.
He ended up leaving when I did to go work at that Fortune 500. You know, we've, we've worked together over quite a long period of time, and he's extraordinarily technically capable. My other co-founder, Pete, is also extraordinarily technical, but he's also got a rare blend of sales experience as well. And, you know, more, more of the business, business management side as well, you know, which we've been able— I mean, I've been extraordinarily fortunate to be able to work with and found with both of them. They're very talented.
So you've got yourself a CEO, a CTO, and then is the other one Chief Revenue Officer, sales guy? What's his role? I apologize. He's currently president. Okay.
And but running like the customer-facing side of stuff? Absolutely. Yeah, that makes a lot of sense. And then You know, have you guys taken funding? Did you start bootstrapped and get funding later?
Are you still bootstrapped? Or what are you guys doing in terms of that? Great question. So we raised a pre-seed round at formation, and then we just closed out our seed round, which was about $3 million, just this last month, actually. Well, that's got to feel pretty good to have that behind you.
Absolutely. Compared to, you know, I mean, compared to the technical work, you know, how hard was it for you to kind of, you know, put on the CEO, talk to investors, go raise money hat? Like, how do you, how do you do pivoting between those 2 parts of the job? That's a great question. Um, you know, it's, it's a bit of a different skill set, I suppose, but, you know, it sort of reminded me that the whole process reminded me a lot of when I was in grad school working toward, you know, writing academic papers.
There's a certain amount of research and, you know, exploring what sort of the prior work in the space looked like and all of that that you had to do even before getting started. And so I think there's sort of a strong corollary between those sorts of things and the types of research activities that went into, you know, building materials to go pitch investors and things.
Um, how do you like it, the pitching investors, that part of the job? You know, how does that compare in your mind to— I assume you sometimes sit down and write code? Certainly a lot less now than, than I did in, in positions past. But overall, I've found it to be very enjoyable. One of the things I've always enjoyed, especially on the technical side, is sort of piecing together the building blocks of what eventually ends up being a large project.
And, you know, it's sort of exercising the same muscles, if you will, on the business side to put together all of the disparate pieces that will eventually build up to both, you know, the product and the sales and marketing efforts and all of the pieces in between.
That sounds like a pretty fun opportunity. If you, if you look at, you know, what's the next, what, I don't know, 24 months look like for Phylum, you know, how do you see things changing? Great question. So, you know, obviously things are going to change very drastically as we start opening up for more of a GA release. We're anticipating that coming along over the next couple months.
And really the next steps after that, you know, it's really fleshing out the product, you know, expanding our capabilities. And, you know, we're gonna be in a great place in the next 24 months. But what's gonna be changed in terms of new capabilities? You know, how is that gonna make you guys better positioned over those next couple months? Great question.
So one of the, one of the more tangible ways I think that, you know, I, I can speak to that is you asked about SolarWinds versus open source. Well, one of our big goals over the next few months as we sort of wrap up this, you know, open source package analysis capability is to turn that lens inward and start focusing on customer code and customer-built systems and you know, helping to really solve those parts of the supply chain as well. So customer code, meaning internally developed code? Absolutely. And so basically giving them the ability to look for an insider risk within— that somebody who has the ability to change code within their environment and what risk that puts them to.
Is that, is that where you're thinking? Absolutely. And even maybe a little beyond that. So, you know, events like SolarWinds weren't necessarily the work of an insider. They, they might have been, but the, I guess you'd call it infection itself, actually, you know, occurred through the build server.
And so being able to sort of weigh in on those types of, types of threats is a, is a big goal of ours. Yeah, the, the SolarWinds one, you know, I, I think we don't know enough about it yet to say, but it could have been an insider, right? And absolutely, I think that, that makes it interesting that that what we're, you know, we defend an awful lot as an industry against the outsiders getting in, you know, successfully or unsuccessfully, probably more unsuccessfully than we'd like to admit. But this does change the dynamic, and we have to be, you know, really thinking about what could these outsiders be doing to us and how do we build protections— excuse me, the insiders, the folks who have access to those systems, and how do we build protections in so that you know, if they're changing binaries, we know it, or, or whatever those things look like. And it sounds like those are some of the challenges you're going to be trying to help combat.
Absolutely. Yeah, that's, that's fantastic. I've, I've heard from a couple other companies, not, not Colorado-based, so boo to them, but I've heard from a couple other companies that are, that are working really heavy on, on that idea. And the phrase I've heard, I don't know if you've heard the build integrity compromise, kind of a play on the business email compromise. But build integrity compromise being the idea that, you know, someone is going to target your build system and, you know, talking about how you prevent it, detect it, respond to it when those things happen.
Have you at all heard of that phrase or heard of other companies that are starting to play in that space? I've heard of a few. I think they're fairly early as well, but this is the first time I've actually heard that phrase. Yeah, I don't know if it's gonna stick or not, but I figured what the heck, if someone has a name for it, let's throw it out there. That's great.
Well, good stuff. You know, in terms of the company structure, I know you're here in Colorado. I think that you told me that you guys are really just, we're all working from home right now. Do you have an official HQ and any plans for where you're gonna hire in the future? Great question.
So our company is actually fully remote. And we, you know, we plan to, uh, to remain so for the foreseeable future. Uh, you know, one of the, one of the big drivers of that being, you know, it's easier to attract talent if, you know, you'll let them work from wherever is most comfortable for them. Sure. So I, and, you know, really the, the company are sort of headquartered here in Colorado, but my co-founders are are in Southern California and in Texas.
And, you know, we have folks, we have other folks here in Colorado and, you know, a number of others spread out across the US. So when you look at hiring in the future, is your intention to just let people be hired wherever they want to be? Absolutely. And is that US only? Thoughts on that yet?
Um, so that's where we're primarily focused right now. I think we'll be more willing to open up in that regard once we're a little further down the line and we're able to better support that logistically. Yeah. So does the, does the closing on your seed round, uh, kind of open up the floodgates for doing some hiring? And if so, where are you looking to hire, or what positions are you looking to hire?
Absolutely. So we are actively looking for, um, a few developer roles and a a data science/machine learning engineer role right now. Awesome. Well, those are, you know, certainly skills that are, that are in high demand. We got some good folks in Colorado, so hopefully anyone listening to the podcast who is looking for one of those roles or who has someone who is, let's get them connected with Aaron.
And Aaron, if they wanted to apply, what's the right way to connect? Is it on the website, or what's the website, or reach out to you, or what? So website would be great. We also have a mailbox, careers@phyllum.io. You know, which is where we were sort of aggregating a lot of the applications.
Yeah. Well, I mean, I think it sounds like obviously a great time to be building a supply chain company. You know, we're all recognizing more and more that the interrelatedness between our organizations is probably putting us at more risk than we might have guessed. And I love to see, you know, technology solutions wherever possible to addressing that. Any thoughts you've got kind of in closing around how people can help mitigate against this risk in the meantime?
You know, while these things are still under development, what can we do to help reduce the risk to an acceptable level within our own companies? That's a great question. So I think probably the most comprehensive steps that can be taken are to really make sure as people are putting together their build systems, especially for package managers that support it, like, you know, the JavaScript package managers or Ruby and a number of others, you know, ensuring that your lock files for your build systems and build artifacts are well set up, and things of that nature are probably a good step in the right direction. And at least making sure that you understand what versions of things you're using, and what the risks are of moving from one to another. Yeah, I think that, you know, the key that you're talking about there, one of the keys is really understanding your build system well as well.
Like, absolutely, yeah, you know, you can't do a good job of building a secure build system when you don't know all of the components of it. And, you know, a lot of times in the security teams, we're just not that close to the development or dev tools teams Getting close and having a well-documented, well-understood, and agreed-upon build process makes it a whole lot easier to put any kind of control in place. Well, you know, I know you mentioned before we started recording you love hiking. Any other stuff you're looking forward to doing this summer other than working on Phylum? Well, fortunately, and perhaps unfortunately, you know, my current role takes up a lot of my time.
So, you know, aside from that and just having the opportunity now is hopefully things start opening up and going back to a bit of a more normal cadence. Um, you know, being able to take some time to do some activities with families is probably on the horizon. No, no trips scheduled? Road trips, camping trips, nothing good like that? Nothing as of now.
All right, well, I look forward to number one, seeing you guys just blow up and you know, start to really grow as a company. And number 2, hearing you go actually do something outside of your house and let me know what that is. I'm looking forward to hearing that as well. Absolutely. All right, Aaron, any final words you want to give to the community before we sign off?
I can't think of anything else to add. Thank you so much for having me on. Absolutely. We always root for the local folks. So let us know how it's going.
Let's keep in touch. And we'll, you know, we'll definitely follow for any press releases you have coming out as well. Awesome. All right, well, that, that's it for this interview. We'll talk to you guys again next week with Colorado Equals Security.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.