All episodes

Identiverse Interview with Mike Benjamin & Alex Weinert

Apple Podcasts Spotify SoundCloud

Our feature interview this week is a recap of the Identiverse keynote panel with Mike Benjamin (from Lumen), Alex Weinert (from Microsoft) and our own Alex Wood. News from Africa Adventure Consultants, Canoosh, Valyant AI, EverCommerce, GrayLog, VirtualArmour, Phylum, Ping Identity, Red Canary and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10364 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 216 for the week of June 28th. Alex, we're, uh, we're halfway through 2021.

Man, it's hard to believe. I feel like we're still at the beginning of 2020. This year really has been flying by, as opposed to last year that seemed like it was about 4 years. Yeah, and, and we also have some pretty decent weather this weekend, meaning not so hot. We're able to get out and do some good stuff.

I'm pretty excited about that as well. Yeah, and we can take a minute to be weather forecasters for, you know, anyone that's listening to this as it comes out. It's supposed to be nice all week. I think like highs in the 70s most of this week, which is weird considering, you know, we've had several days over 100 already. That's fantastic.

That means we maybe we can, uh, avoid having the blistering heat until late in July. That'd be, that'd be great. Yeah, I did. Not that it's Colorado weather. I also saw in Seattle that they had a couple hundred degree days, or maybe just one, and there's another one coming up.

But they've only had like, you know, 3 days total over 100 in the past like 50 years or something like that. So crazy weather all around. So, you know, I went to college in Portland, and so I have a number of friends on social media from Portland, and one of them said today that they were setting their all-time record. This is on Sunday, and I looked and the forecast for today is 113 degrees in Portland. Wow.

The only places that are hotter on Earth are like the Sahara Desert, the Mojave Desert, and some places in the Middle East.

Well, I guess we're just going to have to keep dealing with this stuff, Robb, and hopefully you're in a place where you get the better of it. Well, we had the NREL interview last week. Hopefully NREL is able to to help, help us with this whole climate change stuff. That'd be, that'd be pretty good stuff. I think they need to do like, uh, like Mr. Burns and develop the, the giant dish that blocks out the sun.

There you go. That'll, that'll solve all our problems. Sure, that'll be perfect. All right, let's do some housekeeping. Uh, reminder, we have a Slack channel.

If you're listening to the podcast and you're, you're thinking, what is this Slack technology? We'd love to see you join us and, and learn how to type to people. That's basically what it is, typing to people. If you want to, uh, to To join us, go out to colorado-security.com and click on the Slack button to request to join. While you're there, we have a mailing list.

You can sign up for that. You'll get one email delivered to you every week with the show notes and other interesting stuff about the podcast for that week. While you're doing that, um, we would love for you to also jump over to your favorite podcast player, uh, wherever you get your podcasts from, uh, rate us and then also subscribe so you get this automatically delivered to you every week. And, uh, we'd love it if you tell a friend. If you want to tell some folks about the show and about the movement, get them involved in the community, we'd love to see more folks be a part of the Colorado Equal Security community.

And if you want to help support us even more than that, we do have a financial sponsorship program through Patreon. You can go out to our website to find the link to get to Patreon, help pay the bills to keep the lights open. And we appreciate our current patrons. Thank you very much for all of you who are kicking in a little bit of money each month to keep this thing moving forward. Uh, so, uh, Robb, I think with that, um, I was gonna make fun of you for saying the lights are open, but that's okay.

I'm gonna move on. Uh, thanks for not mentioning that. Uh, you're welcome. And jump right into the news. And Robb, I did not know this, but Denver has one of the world's top safari operators, and we have a story this week talking about how it was for them in the past year without much revenue at all.

Yeah, and let's just be really clear there, this is an African safari company. It's called Africa Adventure Consultants. They're located here in Denver. I think that that's really the punchline of this whole story, that one of the biggest safari companies is here in Denver. Yeah, and they, in 2020, they had been coming off a year of big growth.

They had 40% growth going into 2020, and they were also named one of the 10 best safari outfitters in the world according to Travel and Leisure. And then, of course, it all came crashing down. The story talks about how they, they made it through the pandemic. Lucky for them, they were able to get some, some loans, some other stuff, and just kind of made it through by the skin of their teeth. And now things seem to be looking up for them again.

Yeah, it is fun to see the story of how a small business makes it through. And of course, now, if any of you are thinking, man, I've always wanted to go to Africa, you can, you can talk to Local Folks. They have an office here in— I think it was in Cherry Creek that they, they just got a new office. So you can actually meet them in person and ask all your questions and keep the money in Colorado and hopefully help this company rebound from COVID It is something on my bucket list, Robb, so I will have to give them a call. Sounds awesome.

Maybe they'll give us a Colorado Equal Security discount for talking about them on the podcast, but probably not because no one ever has. We can only hope. Move it along. Speaking of local companies, a Colorado family during COVID they're so into board games that they took an opportunity to, uh, to create their own board game in the last several months. Yeah, so, um, this family, they loved playing board games and they wanted to invent something where, um, it was a game that was easy to play for everyone, uh, all ages.

You know, sometimes you have a board game where, uh, you know, you kind of have to, as an adult, you know, lay back a little bit so that the kids can keep playing without just destroying them. Um, or on the opposite side, it's a, you know, very kid-oriented and adults aren't having any fun. So they came up with this board game called Canoes, and it's actually a game of luck, and it's based on the probability of dice rolling. Yeah, you know, they— I read through this whole thing. They don't describe the game in enough detail to really understand exactly how it works, but yeah, I think basically you're claiming squares on a board based on the likelihood of those numbers being rolled on the dice, something like that.

And they have a few different varieties of of, uh, of how the game can be played, different modes. Honestly, it looks like it could be fun. I was, I was tempted to get it. You can buy this game, um, in person at Golden Goods, which is a store in Golden, Colorado, or you can buy it online at their website. You just have to pay shipping if you do it online, and it's about $15 to buy the game.

Yeah, um, I'm interested, and, you know, maybe I'll get a copy as well, but I really hope with a name like Canoeshe that, uh, part of the game is when you win, you have to jump up and yell kadoosh! I, I could only assume so. And frankly, if it's not part of the game, Alex, you can make it part of the game at your house. That's— that is very true. It's kind of like Jumanji.

All right, just like Jumanji. Just like Jumanji. Less, uh, less animals and, you know, whatever else, but, uh, lots of yelling. Anyway, uh, next, a Denver AI startup, which I believe we've talked about on the show before, is, uh, growing because of the restaurant labor shortage. So this is Valiant AI.

We've talked about them in the past. They're, they're a company that helps with restaurant ordering. And they were doing, I think last time we talked to them, or talked about them, a pilot with Good Times. Yep. And this article is talking about how they are taking that technology and rolling it out to multiple different companies and getting much bigger because of the labor shortage from the pandemic.

Yeah, it sounds like they really had a big growth last year. Just as a reminder for those who didn't listen or forgot what this was about, they've become like the conversation that you have at a drive-through as you're ordering your food versus having to have a person on the other side. This AI will take your order, and generally there's a human listening into that conversation so that if there's a problem with it, if you're getting frustrated, they can jump right in and help. But it does give It does give the ability for fewer humans to help support this so the humans can work on other stuff. When we talked about it before, they said that even at the pilots with Good Times, the system was doing about 5% of the orders.

But as of now, they're working with a fast food chain in Atlanta called Checkers. They said that that AI is handling about 70% of incoming orders. So obviously from 5% to 70%, a very material change and the impact they're able to have. And it looks like they're moving in the right direction. Yeah, that 70% is a much better number.

They also mentioned that they're working with multiple different companies beyond that, although I don't think that they gave names for the other, other companies that they're working with. But I suppose pretty soon when you, you go through the drive-through, you're going to be talking to some AI assistant from Voyant. Yeah, you know, this is an interesting topic. There's, there's good and bad, right? Like, I think we as technologists are interested in seeing how AI advances.

The article specifically talks about, hey, this is not taking the place of people, this is additive. I think there's no argument though, at some point this takes the place of people, right? Like you're reducing the number of employees because of this. And it'll be interesting to see how do we as a society deal with that. And I mean, you can't stop it, but we have to be thoughtful that there's gonna be impact to people who are probably in pretty vulnerable situations that may lose jobs as a part of this.

Anyway, something to think about, and I hope that that gets addressed at the same speed that the technology is being improved. Yeah. I have to think though that they're going to keep needing people at least for the foreseeable future, even if this gets really good. It is only taking the orders. You still have to have people making the food, processing the orders, things like that.

With the amount of turnover, especially in fast food and things like that, I have to imagine that it's not going to be putting too many people out of work. Well, I don't think it's a question of emptying out the back of the store. It's a question of, okay, well, if you had 10 people back there today, and you have 8 people back there 6 months from now, or 2 years from now, and then what's the next innovation look like? Somewhere along the way, it does become— it is significant enough that now people who used to have jobs do not have jobs. I think it's going to have to happen, and we'll need to be thinking about it as a society.

Maybe already outside the scope of what Colorado equals security though, huh? Uh, on that happy note, let's move on. Um, the, the next article is talking about, uh, EverCommerce, which is setting its IPO and could be valued up to $3.46 billion as part of this. Yeah, you know, um, I, uh, sorry, I somehow missed that. Oh, there it is.

Yeah, I didn't actually know this company, or if I did, I forgot. Um, they, they, they go to market with a number of different, um, uh, names. So they, they have EverCommerce, EverPro, EverHealth, which are focused on different industry verticals. And previous to, to last year, they were actually mostly, uh, known as PaySimple. Um, so this is a, you know, a couple different changes, a couple different names for me to try and figure out.

Um, have you— are you familiar with these guys? Is this one we've, we've ever talked about or you've seen in other places? I feel like maybe we've talked about them once, but I'm not positive. From reading the article, it sounded like they started out more as a payment portal, but now they have moved on to being more of, you know, sort of an operations portal. You know, they have a healthcare-focused version that, you know, I didn't look at it, but to me sounds more like it's what you use at, you know, at a doctor's office or something like that to sort of run your practice.

Versus just a place that takes payments. Um, same with, uh, you know, they have a fitness and, uh, and wellness one. I'm guessing same sort of thing, you know, where you, uh, maybe manage memberships or other things like that. Um, and, uh, so it's interesting to see that it looks like they've also, uh, you know, at one point acquired a different company and, uh, that, that helped them on their way. Um, so, uh, I guess to your actual question, Robb, I wasn't particularly familiar with them as well, but Looks like an interesting group of products that they have.

Yeah, good stuff. You know, it is interesting to know that there's just a company of this size and scope here in town that I, that I wasn't familiar with yet. You know, as a point to that, their total revenue for 2020 was $337 million. So they, I mean, they're definitely at large scale and still growing pretty quickly. Cool to see them be successful and looking forward to seeing, you know, the good news about their IPO when it comes out here, uh, in the, in the near future.

Good stuff. All right, uh, next we have, uh, update about Andy Grolnick. So Andy was the longtime CEO of LogRhythm who, who left, well, just a couple years ago. And, and I know we've talked about this on the show before, he is now the CEO for Graylog. Well, Graylog, the— it's another log management log aggregation company.

They just raised $18 million in a Series B, uh, to help, uh, speed the growth of that company. Yeah, uh, so Greylog is not based in Colorado, but, um, of course Andy is. And, uh, they do mention in the story that, uh, Greylog is growing and a number of those people are being hired here in Colorado. Um, they also expect that, uh, Greylog's headcount to be somewhere between 95 and and 100 employees by the end of 2021. So sounds like they're getting to be a decent-sized company.

Yeah. So they are planning to use the $18 million to invest in go-to-market, so sales and marketing, and also more development. I think that's kind of the standard, right? Everyone who invests, they're going to do those 2 things. Good for them.

I was unaware that they're used so widely. They say that they have more than 50,000 installations around the world. So Certainly, you know, got a good footprint and now have a good investment to grow from here. Yeah, and good for them. All right, next we have an acquisition announcement.

Virtual Armor, which is a local managed security services provider here, is being acquired by Evergreen Services Group. Evergreen is a managed service provider, no security in there, and they are acquiring Virtual Armor to help get them into the security side of the market as well. So good for them. It looks like Evergreen has been on a tear. I think, where was that number?

They've acquired 28 managed IT providers since 2018. So I guess maybe they ran out of MSPs to buy and now they're moving on to MSSPs. Yeah, it's interesting because their strategy seems to be that when they buy these new companies, they actually don't acquire, they don't merge them in. They're letting them operate separately and still go to market with their old name and their old leadership. So the leadership of Virtual Armor is gonna stay in place and exist under, is it Russ Armbrust?

He's the Virtual Armor CEO. He's still gonna be the CEO, still with that name. It's just, they're now gonna have the resources of, of Evergreen and all of those other companies under Evergreen as resources that they can partner with. Yeah, so I'd imagine, uh, you know, cross-marketing across all those managed service providers, now there's a new place for Virtual Armor to sell into, and hopefully that's a good thing for everybody. Yep.

All right, so speaking of funding, we had a lot of funding this week. Um, Phylum, who we had Aaron, uh, the Bray, the, uh, the CEO there on the show Uh, just about a month ago, uh, they closed on a $4.5 million seed round and they're coming out of stealth mode. Yeah, congrats to them. Uh, they are an application security, uh, company, but they're focusing on, on supply chain and that sort of thing. Um, it sounds to me similar like a, uh, a Black Duck or one of those types of products where you're looking for vulnerabilities in, uh, in open source libraries and other things that might be in, in your product.

Um, I thought it was interesting that the, uh, the seed round was, uh, was led by, you know, a couple of funds, but also a few people, uh, CSO for Coinbase, the CSO for Robinhood, for example. Um, but, uh, you know, it looks like good stuff and they're well on their way to, uh, to being a, a bigger company. And that, you know, that is a Colorado security company. So I'm sure, you know, as they, as they continue to grow and have success, we'll We'll stay on top of that and we'll get Aaron back on the show to tell us how they use this money to fuel the next iteration. Yeah, and on the same vein of acquisitions and funding, Ping Identity announced this week that they have acquired a company called Secured Touch to accelerate their identity fraud capabilities.

And Robb, I don't know if you know much about this one or not. Um, so I, I know about it from reading the press release. I don't know about it from being a former employee there. Um, basically, they, they are giving them a risk indicator, a risk engine, to, to better provide, uh, signals on what's good behavior and what's bad behavior by users. Um, and you can use this, this fraud detection for a number of way— a number of ways.

You know, obviously, as the customer, the enterprise itself, you could say, I just want to know what fraudulent stuff's happening, but the real power comes when you integrate that fraud engine with the PingOne product, which is their cloud service, to say, okay, well, because of this score from our fraud engine, we are going to require a step-up authentication, or we're going to disable this account, or we're going to not allow transactions over X amount of dollars, whatever that action you want to take is. That's where the power of this integration comes from. And I imagine that since the acquisition just happened, that it's not there yet, but then over the next couple of quarters, that there'll be a lot of integration so that customers of both platforms, as it's moved into the Ping platform, will be able to take advantage of those new capabilities. Yeah, and it looks like from the article that this Secured Touch is focused on bot detection and mitigation, stopping account takeover and other kinds of fraud. And it also looked like while you'll be able to do what you mentioned, Robb, how, you know, how it'll be integrated into the PingOne engine, sounds like you'll still be able to purchase this as a separate product if you're just looking for something that will help prevent those fraudulent behaviors.

Yeah, I think it would help detect if you didn't have it doing more, right? And then you could use a detection somewhere else. I think that's, that's the key, is that the prevention comes when you can, you can tie it into something like PingOne or Or you do your custom in-house development to do that integration. Sure. Alright, and we had another piece of news from Ping this week.

So Ping— so this week was Identiverse, and you're going to see we have the feature interview, which was our keynote from Identiverse, but that was in town, and that's kind of the big identity conference of the year. So Ping, you know, coordinated a bunch of news this week to come out. Another one of their pieces of news is actually once again worthy of talking about. They're releasing a brand new capability and a product which is called Ping One for identity. Yeah, and this is what they're calling a personal identity solution, and I thought this was interesting.

It sounds like— and you can correct me if I'm wrong, Robb, because you probably know a little bit more— it sounds like this is more a customer identity and access management kind of play, but with the ability for end users to have more control over the data that they share with various different people. Basically, this is their go at making a wallet for users to be able to share their identity in a way they want to. I think we've talked about this idea on the show before when Ping bought Showcard about a year ago, a little over a year ago. This is the ability for an individual like you or me to walk into a liquor store, and if that liquor store has set up this type of a product, we can show, we can give just our proof being over the age of 21 without also having to give everything else from our driver's license. And it gives us the ability to show proof of vaccination without all these other details.

That's really the promise here of personal identity. It's giving the individual control over what they share and with whom. And they're basically releasing this capability that enterprises can go out and set up so that their customers have that capability. Very nice. It sounds to me like it's a more generalized version of the, uh, the app that the state of Colorado released where you can have a digital version of your driver's license.

Yep, I would say that's a great example of, of a first wave of what that could look like. And, and other— there's a million other places that it can go, but absolutely right, that's a great example. All right, and then moving on to our last story of the week, this is a blog by Red Canary. They did a survey of security leaders to reveal what worries them most and why. And sort of the headline here is that 82% believe their organization is vulnerable to cyberattack.

Yeah, there's, there's a whole bunch of interesting stats in here. This is part 1 of a 3-part series. First, you know, this first part is talking about what are the concerns that are keeping leaders up at night. The second part's going to be what are the obstacles that are standing in the way of effective incident response, and the third element is what can organizations do to turn the tide and improve security. So this one, there's, you know, some nice graphics and discussion about what, what are the biggest concerns.

The number one thing people are concerned about as a, as an impact is damage to the organization's reputation. That's, that's right above compromise or loss of sensitive data as, as number one and number two as, as areas of concern. Yeah, I'm honestly, I was a little bit surprised that that was number one. Um, you know, that obviously is an important thing, but I would have, uh, I would have assumed that, uh, the number 2 and 3 would have been ahead of damage to reputation. Yeah, and number 5 on the list, way down at 50%, is negative legal and regulatory impact.

So they're basically— compliance is not anywhere near the top of the list either. Another one that, that might be a little surprising as well, right? Yeah. And if we move down a little bit farther, talking about the, the attack vectors and what people were most worried about, Number 1, 57% was exposure to ransomware attacks, and that one does not surprise me at all, except, you know, maybe 57%, I would have expected maybe even a little bit more than that. Yeah, the other, other big ones— actually, number 2 is decreased endpoint visibility due to work from home.

I mean, the majority of companies said that that's high on their list. Interesting to me that most companies haven't solved that problem yet, and I guess that leads the— leads me to think that there's a lot of opportunity for current providers in that space to, to expand, and maybe even for new providers to jump in there and make it easier. Because I think the challenge is, it's not that we don't have solutions that do that, it's just clearly it's not easy enough, or more of these companies would be doing it, right? Yeah, well, good stuff there by Ready Canary. And as you mentioned, this is one in a 3-part series, so, uh, I imagine we'll see the next 2 coming out soon.

All right, jumping over to our calendar of events, remind you that on our website we do have a calendar of events. You can go out and see what's coming up here in the next few months. In the next couple of weeks, there's very little because we do have Fourth of July, and I think everyone decided the week before Fourth of July and the week of Fourth of July, it doesn't make sense to do a lot of events there. Yeah, so I think we just have one event this week, and that is the, the Colorado Springs Uh, is this the Cyber Mountain Colorado Springs? Yeah, that— the name seems— the name for this thing seems to change every, uh, every month, but this is that First Friday event, and, and it's— this time it's called the Second Friday event because it's the second Friday of the month, but, but it's that Cyber Mountain Colorado Springs group.

All right, so if you're down there, check it out, and that's on the 9th. I don't know if we said that part. All right, and then with that, we can jump over to jobs. We have got— well, for those of you that aren't aware, we do jobs every week, and Robb has handpicked some wonderful jobs for us to talk about. So the first of those is CommonSpirit Health.

They're looking for a system vice president. Is that maybe senior vice president of cybersecurity transformation? Yeah, I, I have never seen the title system vice president either, but that is what it says in the, in the job description. So I assume it's— I assume it's true. Um, anyway, I think the idea of working at such a large healthcare organization doing, um, doing, uh, cybersecurity transformation sounds really exciting, and hopefully they get a good person for that.

Uh, next, S&P Global is hiring a Director of Data Security Architecture. Sounds cool. Poly is looking for a Senior Manager of Enterprise Security, and Poly is Polycom. Um, so the, the phone manufacturer. Clearly, that's C-L-E-E-R-L-Y, is hiring a senior manager of information security.

Never heard of Clearly. Me either. Here's a fun one. The Denver Center for Performing Arts is looking for an information security manager. That's awesome.

What a cool thing to get to do. University of Colorado is hiring a security operations manager. Cushman Wakefield is looking for a security strategy and operations senior manager. Well, if you want to get into commercial real estate, this is your opportunity. That would be it.

The state of Colorado is hiring a manager of identity and access management. The Colorado School of Mines is looking for a security analyst for incident response. And finally, Berkshire Hathaway Home State Companies is hiring a senior security— or excuse me, senior cybersecurity engineer. And that's here in Colorado. I didn't know that they were— I didn't know they had any presence here.

Nice. Yeah, I wonder, even though it says Berkshire Hathaway, I wonder if it's a portfolio company that is hiring on their behalf or something. Yeah, I think that I made a little joke about what company you might want to get into. This is a company I would definitely be interested in getting more involved with. And if I think— if you're thinking about getting an engineer role, maybe look at this one.

Well, agreed, Robb. You know, I also have some kids that are coming up to college age. Maybe that Colorado School of Mines job would be a good one if it offers some tuition benefits. Yeah, there you go. If you're— and if your kid's able to get into Colorado School of Mines, that's pretty awesome.

Yes. All right, uh, that is it for news. We do have— I mentioned earlier the feature interview, which was, uh, us basically talking at Identiverse. We had a keynote panel and we have a couple other guests as a part of, uh, basically a debrief after. So we did the panel, then we immediately shuffled off over to the podcast recording studio and we, we sat down and talked about how the panel went.

Yeah, it was a lot of fun. Looking forward to hearing. All right. Well, that is it. We will talk to you guys all again next week.

Thanks, Robb. This is James Carder, CISO at LogRhythm. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

All right. This is Robb at REC, and I'm running kind of a different interview this week. For Colorado Equal Security. We're sitting on the floor at Identiverse, the first, as far as I'm aware, the first in-person security conference here in town. It's a national conference that really kind of moves around to different cities, and this year we're lucky enough to have it here in Denver.

It's a hybrid event this year where there's a few hundred people here in person and maybe another 1,000 people or so who are doing it remote. I don't know the exact numbers, but 1,000 So anyway, I'm doing an interview this week with, with the panelists that were on one of the keynote panels. So with me is Alex Weiner. Alex is the director of— Alex, I'll just go ahead and let you introduce yourself. Yeah, I'm the director of identity security for Microsoft.

So we do try to prevent fraud and account takeover in the Microsoft ecosystem. And, and you are not a Colorado guy. Where are you from? Actually, I'm from Colorado. I didn't know that.

Yeah, I grew up on the Air Force Academy in Colorado Springs around Monument, but I moved to Seattle 25, 26 years ago to join Microsoft. Yeah, so you had perfection, you lived here, and then you chose to leave. This is hard to believe. Yeah, yeah, well, Seattle's got its upsides. Seattle's not too bad?

Not too bad. All right, we have Mike Benjamin. Mike, you're a friend of the show. We've talked about you on the show, and I think we've had you on the show in the past. Mike, want to do a quick intro?

Yeah, I'm the Vice President of Security at Lumen. I also run a team called Black Lotus Labs. So our teams, we build products that serve security to our customers and operate them, as well as threat intelligence focused on hunting threats within the internet. Mike, I feel like you have done roughly the same job most of the time I've known you, and you've had more titles than anyone I know over that time. And part of it's because your company name keeps changing, and part of it is It's just, you know, promotions and so forth.

Anyway, it's good to have you back on the show after, after a long break. And then we have a total stranger here. Who's this? Oh, hi, Robb. How's it going?

This is Alex. I was on the panel also. I'm not going to introduce myself because everybody knows me, hopefully, if you've listened to the show before. I also, you know, in our tradition of dad jokes, I wanted to let everyone know that, that Mike clearly has a bright future at Lumen. Ouch.

Ouch. Hold on, we got to have this. That's not a laugh.

So this is the first time we've ever had a soundboard where a rim shot would have been good, where we can just randomly do sounds. So if you, if you hear us playing with that technology, then you know what's going on there. All right. So we did, we did just do a panel really talking about this Solarigate SolarWinds series of attacks and what the impact of that was. And we're going to do a little bit of recapping on that here during the interview today.

But I'd love to hear from you guys. You know, for me, this is my first time walking into an in-person event in, what, 15 months? Since RSA conference last year, I think. For you guys, is this your first time coming back to real-life people doing stuff together? It's so awesome.

I mean, it's so good. Yeah, it's my first time back at an in-person event. All wearing pants. I'm glad none of us forgot how to put pants on. That was— I have a non-elastic waistband for the first time in like 15 months.

Yeah, it was a little bit weird when I walked in. Um, one of the keynotes was already going, so, you know, the everything else was deserted and it was just, it was sort of like walking into an empty hotel, you know, which has been pretty common, uh, recently. But then all of a sudden, you know, getting into the, uh, the area where they were doing the keynote and all of a sudden seeing all the people, it was awesome. I think when Alex walked up, he didn't recognize me. That's how long it's been.

So yeah, it's good to see everybody. Yeah. All right, good stuff. Let's talk a little bit about the panel we just did. You know, the point of it and the reason the 3 of you guys were brought together for this is you have really different perspectives on what happened with these attacks.

And Alex Weinert, with Microsoft being really early into the incident response and I'd say leading the charge on recommendations to the industry, reaching out to impacted organizations. I think even how we met. Yeah, that is how we met. You gave me a call to say, here's what's going on, make sure you guys are keeping an eye out for it. You guys have a really interesting perspective there.

Mike, you know, at Lumen, I think maybe CenturyLink previously, Lumen, you guys had a different perspective on it. You want to share kind of how you you guys got to see what was going on there? Yeah, so really as the event was unfolding, it became a few different perspectives. One is helping our federal customers understand the impact. Obviously they were high-value targets from this particular actor group.

Another was that threat intelligence side, going out and hunting the entirety of the actor infrastructure. What could we find out that they had done? What could we find out was being impacted? And obviously that feeds back into the latter, which is after understand more of the backend infrastructure, the tooling used, etc., we can go hunt more things on behalf of our customers and make sure that we're cleaning that up. Yeah.

And then, Alex, you know, from yet a different perspective, why don't you talk about how you got involved and like what your role was? Yeah, I mean, it's funny, I don't normally talk about my day job perspective on the show, but yeah, we, you know, we're a portfolio company and we have a lot, lots of companies that I look after in terms of their security program. And so, you know, we spent a good deal of time doing, you know, research and incident response once the announcement was made about what was going on, determining which of our companies were affected, how they were affected, how we needed to respond, things we needed to do, you know, and all that sort of thing. So, you know, it was a good bit of work for us too. Yeah.

So, so what I'd love to do is recap just a little bit of what we talked about in the panel. Not, not going to rehash the whole thing, but Alex wondered if you don't mind giving your summary of what these attackers did and the fact that we really mischaracterize it with SolarWinds. Maybe you could kind of walk through that. Yeah, I think, I mean, SolarWinds obviously is a supply chain attack. It's compelling, and they were involved in one of the, I think, the first victim that we were looking at.

But the thing that was really common to all the attacks was that the attacker was using the application infrastructure. So looking at application identity, as a way to call to data that was theoretically protected. And the reason for this is applications are generally not as well tended as users. They're expected to be more predictable, and the volumes of traffic are higher, so it's easier to launder your traffic in with them. Then there's like, you know, the 20 different ways that they got to where they could add those permissions.

But I would say the other, you know, important thing to deal with in the mischaracterizations is that the number one way they got in was password spraying accounts. Without MFA, right? So it's old news, right? The SolarWinds thing, even those attacks were probably involved with, you know, just basic credential compromise that then resulted in being able to do these supply chain attacks, which gave them more pervasive access and more importantly undetectable access. These guys were all about not getting caught.

I remember, you know, when the reports came out that there were 3 different types of ways they got in, right? SolarWinds was the one that caught all the headlines, like password spraying where there wasn't MFA in place is maybe the second one, and then I remember a third one around supply chain, other supply chain attacks, and are you able to comment on that? I think I have a hypothesis on what happened there, but maybe you can say more than I can. There are a couple of different, there's things we know and things we suspect, right? The things we know are that there was a third-party third-party mail security provider that was compromised, and their private key that they used for all of their customer installs was compromised.

And so every single one of their customers in turn was vulnerable through that mechanism. So that was another supply chain attack. There's also some suspicion around recently announced compromise of organizations that do things like software signing and, you know, the sort of the code stack management, and that some of that may have had an influence in the upstream SolarWinds compromise. But those are more— that latter is more hypothetical. I think the thing we know is about the third-party mail security vendor.

Yeah, and some other things that I had heard through this, and it's not substantiated, and you can tell me this is crazy if you want to, was, you know, through these attacks they would go for like IT service providers you know, think of a body shop, and by compromising the body shop, be able to then get to that body shop's customer base. Any confirm, deny, no comments? Absolutely. I mean, if you look at the SolarWinds attack, you talk about something like, what, 18,000 organizations impacted by SolarWinds malware binaries, and then you look at the actual target victims list, from our perspective, it was in the low 100s, kind of 150-ish. Right?

And so they had this huge footprint of available targets, but again, I think that's actually an important thing to think about in these attacks, that as attackers move to this world of saying, well, if I can get something upstream to get to my one target, then more and more attacks are moving upstream, right? And so, you know, as providers, we have to be ready for that. Yeah, good stuff. So that's kind of the basics of what happened there. Mike, would you be want to talk a little bit about, you know, how you guys saw this flowing through in your customers and how you helped them respond?

Absolutely. So the first reaction anybody has when they hear about a potential compromise is, am I compromised? And so the typical reaction you'd have in a scenario like that is going in and looking at your data and ascertaining, do my logs say yay or nay? And the unfortunate reality and this is, you know, somewhat true across a number of incident response events, people are not logging enough information, they're not retaining it long enough. And so for some agencies or some customers or some folks looking for impact, the answer was a quick yes or no.

It was great. And those were the situations where you saw maturity. But unfortunately, there was a substantive footprint where the answer was, we still don't know. And that obviously drives a much higher cost response. It's much more human-intensive.

You start talking about drive forensics rather than network and log forensics, and it drags it out and it takes it much longer in order to understand. So the time with customers was spent across that full spectrum. Where were they in that journey? Where were they in that maturity? And then after we looked at the impact, there were varying degrees of impact from the attacks themselves, and I'll focus specifically on the, the SolarWinds side.

Those that installed the implant didn't necessarily call back the actor. Those that did call back to the actor didn't necessarily have the actor take any further exploitation or compromise or data control or anything. And so understanding where they were on that spectrum, thankfully, to the point Alex made, the numbers at that highest risk were low. And so we weren't looking at the planet, we were looking at a relatively small number in collective compared to those that use SolarWinds in the end. Alex, you want to talk about how you got involved?

Yeah, so for us, you know, really the first involvement that we had was once this was made public. So, you know, we had heard some rumblings about, you know, potentially something coming, something big coming, but we, you know, we didn't really know what it was. And then when the announcement was made, you know, we have a number of folks that on the team that do threat intelligence monitoring and news scraping and things like that. So, you know, we found out from that perspective. We also have a monitoring provider that let us know what was going on and began looking in their logs for, uh, for the initial indicators of compromise and, and things that they could look for.

Um, and so, you know, we really from that started to, to spin up our incident response process. And, you know, part of that also was determining which one of our, uh, our entities were using SolarWinds, what version they were using, Um, if they were using a vulnerable version, um, you know, then there was a little bit of confusion up front too about which versions were vulnerable. And then, and moving down that path, um, you know, starting to do investigations and, uh, you know, even as Mike mentioned, doing forensics and other things like that if necessary. All right, so we did— we talked a lot about, um, you know, how this might change things going into the future and, and how we look at third-party how we use third parties and third-party risk in general. I know, let's have a few comments on you guys.

What are your big takeaways from what we discussed in those areas? Anything you want to make sure we reiterate here for this audience? I'll start with you, Mike. So there's a term that shouldn't be foreign to any of us, least privilege access. And so we all have third-party technologies in our environments.

Every customer, every company has some third-party technology. How much privilege, how much trust is given to those is one of the most important takeaways here. Is, should that have full access to an enterprise? Should that have an ability to truly control at an administrator level every machine in the entire corporation from a single install? And so looking at this from a, how do you contain an issue?

How do you minimize its impact? And how do you lower the access and trust given to technology? Is an important part of this. As we look at a third-party technology provider, also understanding what it is they have from a maturity perspective should influence how much you trust that technology and operation in your environment. And so that's one of the most important things to me to take away is how much do you really trust every component inside your environment?

Alex Weinert, you want to take a shot at that? Yeah, I think, I mean, so we're big proponents of Zero Trust and, you know, sort of as a model to think about, and least privilege access is one of the pillars of that. Another one is explicit verification, right? I think that where we get into difficulty is that organizations, you know, they have finite resources and they have a motive, which is to push the profit forward and be productive and that sort of thing. Your vendor is really no different from a perspective of they want that first touch with the software that they're offering you to be as easy as possible.

Of course we'll give you more access, right? Like the defaults here are going to be as open as possible so that when you get that software, it's like, oh, this is an easy user experience, I can use all the features. We have to kind of flip that model around, right? We have to start, you know, getting to a place where, hey, let me help you think about what you really need to give, right? And then the other one is I think, you know, we have to try to stop stopping at the boundary where it gets hard, you know.

So we'll do like least privilege access all the way down to vendor solution, and then we don't want to look behind that wall because that's hard to do. Like, asking for that, you know, extra information is hard and it's expensive. But here again, I think when we talk about explicit verification, which is a big part of Zero Trust, like, the attackers doesn't— they don't have boundaries, right? They're not going to stop because, you know, this is where you signed a contract instead of writing the software yourself, right? So you have to— if you're going to do explicit verification, you have to know what that software is doing.

At least at the boundary. I think you said something really good in the keynote, which was, you know, know your normal, right? At the very least, you can look at what the software is doing today and start quantifying what's the expected traffic, what's the expected pattern, what's the expected error rate. And if that shifts, you know you have something has gone sideways inside that software. So that's like the bare minimum.

But I think we have a long, long way to go in terms of maintaining those relationships in a secure way. Do you want to take a shot? Yeah, I think, and it was brought up in the panel too, that vendor management is important, but it's also hard. So I think coming together as an industry and figuring out how to do that better, one of the things that I think that we mentioned during the keynote was you can have all the certifications that you want, but A certification probably isn't going to check the build process to make sure that it has integrity. Maybe they should, but that's not a fairly standard thing as part of ISO 27000 or a SOC or other things like that.

So I think we all need to raise our games in terms of doing that and really think about how we can do it better, whether it's large companies pushing their vendors to be better because they have the resources to do it, or the government doing it, or other things like that.

Mike Benjamin, during the panel you said, you pointed out that while we acted as though this was the first time a nation-state had really done a supply chain attack, that's not the case. And in fact, it's not even the first time we were on the front page of the newspaper as a result of it. Do you mind talking a little bit about that other example and really what that teaches us going forward? Yeah, absolutely. The event that I was referring to happened a few years back where an attacker from the same nation targeted the tax software of the Ukraine.

And companies, businesses within that country use this tax software in order to do their taxes. And the impact that ended up happening was ransomware was delivered. You'll hear this referred to as NotPetya, is the attack I'm referring to. And this particular attack, it crippled some of the infrastructure within that country. And the way they did it was a simple implant in the software update process of the tax software commonly used.

Sounds very similar to let's use SolarWinds, the Orion software, with an implant in the software upgrade process. From a technology perspective, it's not drastically different. And as we watched that, many people from a security perspective should know not not Petya as a name. It was popular in its impact, uh, discussion, but it also was in the news as the impact to the Ukraine. And that's where people in the, the real world outside of our industry really understood the impact.

And for us to look at this and say this is new, this is the time we're going to learn from it— I think we're at what, 6, 7 months since the news broke? Are we still actively reacting to it? Is our industry still adequately focused or have we moved past it? And so if we've moved past it, is it going to occur again? Is it really going to occur again?

It's something we really need to look in the mirror and say, did each organization, each technology provider, did they solve this problem or did they at least improve their posture to solve it when it occurs again? It's such a depressing thing to think because I vividly remember the NotPetya attack in the security circles. I mean, we talked about it a lot. It was big news. And it should have been a wake-up call that this could happen anywhere.

And now we've actually had it happen with relatively, you know, significant impact, but not world-changing impact. Do we have to have a bigger impact in order for people to actually do something here? Like, how do we get from where we are? Maybe I'm being too down. Anyone want to comment before I spiral?

I mean, I, I'm a cheerful person in a job that encourages a lot of pessimism, right? I think that we are going to either walk or be dragged into a world where we fund and mandate a lot more security. I mean, we just, you know, at the end of the day, you know, we all have to, like, from the government level, from the implementers' level, and from the vendors' level, we all have to step up for this because if we don't, it will happen again and the stakes keep getting higher. That it's wonderful the way that we can collaborate and, you know, like code sharing and people's innovation is super, right, and like open source, but the attackers do it too. And any attack that's successful is in GitHub like months later, right?

So, you know, we are really, we are running a race here, and I think that the level of investment we have to make, it needs to go a lot higher. And again, I think there are very encouraging signs right now. Do I think we're talking about it enough 6 months I don't know. I don't really care whether we're talking about it. I care whether we're acting on it.

There's a lot of investments that we need to make. We're certainly investing really hard internally. I know a lot of other companies are too. Yeah, I mean, I would agree. I don't think we're talking about it enough, but that's, I think, partially because there have been so many attacks that have— big attacks that have come one after the other.

You know, for a long time, it wasn't that the attacks were happening. It's that— and I don't want to minimize data breach, but it's like, oh, another data breach. Oh, another data breach. Now it seems like the result of the attacks are, you know, maybe there is a data breach associated with it, but it's, oh, you know, now our gas prices are going up because a pipeline is down. Now the, you know, a water supply is potentially compromised because there was an attack on a municipal municipality and things like that.

And, you know, I think it, it takes the whatever attention we had on the previous one and quickly refocuses it on the next thing. And it's hard to make sure that you're looping back and, uh, doing everything that needs to be done for those things that, that you, you did learn from the, the one, you know, 2, 3, 4, 6 months ago. Um, so it's, it's hard. Yeah, I do think though, if you look at it, it— that message right there helps reinforce This is a journey and it's a programmatic thing that needs to be solved. And it's no different than risk programs.

Nobody has zero risk. They're always working to improve it. Well, here we are looking at state-sponsored things that can impact us and incorporating that same risk management program, the same technology, you know, evolution and architecture shifts and investments. It's part of a program. And being distracted by the event that's in the news next week is not the right answer if you really have a good program and you really are going down that journey.

All right, let's, let's bring it home, guys. We ended up in there giving you guys a chance to say one thing we wanted the audience to walk away from. I'd love to give you guys the same chance here. What's the one thing you want this audience to learn from this and maybe change in their behaviors and in their organizations?

Well, I'll go ahead and throw it to Alex Weinert to start this off. All right, you know, I'll say basically the same thing I said in the keynote, which is I think that we are, as people who are in the security industry and in the identity industry, we have to recognize that we are in the job of global security now. Like, you don't just have a job, you have a mission, and we all need to step up to that mission right now. Like, we are, I believe we're on the cusp of a time when the combination of nation-state actors, sophisticated attacks, and the connection to our operational technologies technology and IoT worlds is going to, you know, we're going to start seeing some really serious attacks starting to happen if we don't step up. So it's time for us to like all kind of band together and get it done.

Mike? I would like to ask who let Alex play with the buttons that make sound. That's our first pressing issue. There we go. All right.

So from my perspective, it's data, right? Described, as we engaged with our customers, the journey was relatively swift as it pertained to anybody who had adequate data to understand what was actually happening in their environment. They could look at the DNS callbacks and they could ascertain, did they hit stage 1, stage 2, or stage 3 as it pertained to this particular attack? And so data collection is hard. A place to store it, a place to query it, a place to look at it is not easy.

And some of these in some environments are big data problems. These are not trivial things to ask, but they're important. And after the data is there, that's where the real power comes in, is looking at it, proactively understanding what's it doing, why does it say what it says, and doing something about it. And then that builds a corpus of information as to how the company operates and what things are abnormal and what you should be reacting to. And more and more of that will allow people to be more proactive in this kind of environment.

And I think one of the takeaways that I offered at the panel was really thinking about, you know, business continuity or resiliency or whatever terms you want to use for it these days. I think many of these attacks are highlighting the fact that we are extremely dependent on technology for very important processes. And when all of a sudden that technology isn't available, or we need to do investigations or other things like that to take it down, that kind of thing, that we're not really in a good place for keeping our critical operations continuing in those kind of events. So I think really thinking about what those— the bad things that can happen are, the worst-case scenarios, the black swan events, whatever you want to call them, and making sure that you at least have a a people process for how to deal with those things when it happens. I will close out with my takeaway for everyone, which was already mentioned, but I want to reiterate just the importance of knowing what normal looks like in your environment.

The better you understand normal behavior, the harder it will be for bad guys to do things that you don't want them to do. You should be able to see those changes, and every change has a reason. Understanding those things will be a big part of success. Well, that's it, guys. I think we're good with this interview.

We do have a lunch to go get over to, and I, I know I want some conference food after a long time away from it. Any final comments before we go? No, thanks for letting us do it. This is a great opportunity. Yeah, this has been great.

Awesome. All right, guys, well, this has been Colorado Equal Security, and we'll talk to you again next week.

Learn more about the Colorado security scene at coloradodecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes