Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 217. For, uh, it's the day after America's Independence Day, July 5th, uh, 2021.
What day is Independence Day, Rob? Well, it's the 4th. Well, the 4th is, is, is the, uh, Independence Day, but it's July 5th, the week that we're recording here. You are correct. You are correct.
And happy 4th of July. Happy 4th of July to you. Uh, our country— how old is our country this year, Alex? Oh, now you're gonna make me do math. 245.
We turned 245 this year. So we've got a, uh, got a pretty good, uh, got a pretty good run going here. Yeah, a few more years, we gotta celebrate 250. That'll be pretty fun. That'll be a fun one for sure.
Fun fact, I will be turning 50 the same year that the country turns 250. Wow. So you're 200 years younger than the country. They call us bicentennial babies. That's the fact of the podcast for folks.
Yeah. As you know, I missed that by just a slight bit. Just a little bit. You're much younger than me. Yes.
Anyway, I hope everyone had a great Fourth of July. Didn't blow their hands off and or start forest fires. Yeah. Or, or neighborhood fires either. Yeah.
All right. Jump into some housekeeping stuff. Yeah, let's do it. Uh, so Rob, did you know we have a Slack channel? I did know that.
How many people are in that Slack channel these days, Alex? Uh, we're getting close to 2,000. I don't know exactly the number, but 19-something. Yeah. It looks like we're about 1,947, which, you know, somewhere in between World War II and the Korean War right there.
Um, how old was the, the US in 1947, Rob? Oh, that's a great question.
And for those of you that don't know, we made the Slack channel invite-only a little bit back. So if you're interested in joining, go to the website, submit a request to us, or find somebody that's already on there and they can make a request on your behalf. Good stuff. While you're on our website submitting that request, you can also join our mailing list. We'd love to have you get the show notes in your inbox each week and give us any feedback you have about the show.
We'd love to hear it. While you're at it, you can go ahead and subscribe to receive the show in your inbox at your favorite podcatcher. And give us a good rating on there. It's been a while since I've looked at our ratings, but I would like to think that all of you are doing ratings on a regular basis. I'm sure only 5-star reviews, Rob.
Also, if you would like to tell a friend, let them know how great Colorado Equals Security is. And if you want to do something financially, we do have a Patreon campaign where you can contribute to the costs of running the podcast and all the other things we do for Colorado Equals Security. A big thank you to our current patrons. We really do appreciate all your guys' support and keeping us going. And we do have a new patron this week.
Oh yeah? We do. Sue Lapierre. Oh, awesome. Yeah.
Thank you, Sue. Thanks, Sue. Sue is the— actually, what did I— I was just on a panel with her recently. She is the VP of IT governance or something like that.
She's the CISO for Prologis. But she has a slightly different title at Prologis. And And she signed up for $10 a month. So we appreciate that, Sue. We need to get Sue a t-shirt, and we're giving her a shout out on the podcast.
You could get the same if you join the Patreon campaign as well. We appreciate you very much, Sue. Thanks for supporting us. All right, let's jump into some news. We have some local news that's quite tasty.
The most famous chocolate company in the US, Hershey's, has bought $425 million to buy a Colorado snack company. Yeah, not only snacks, but it's, it is a sweet snack company. Lily's Sweets based in Boulder was purchased by Hershey and they are in the, I love this, the category of better for you snacks. So these are not good for you snacks, but they are snacks that are better for you than bad snacks. Yeah, they say that they don't have any added sugar.
What they do, it looks like instead of adding sugar is use Splenda for, for most of their sweeteners. And they have, was it 20-something different kinds of chocolate bars, different flavors? They've been selling at Whole Foods and I think some other high-end grocery stores. I was not familiar with Lily, but now that I see it, I'm more interested. But now that I see it, it's not a Colorado company anymore either.
So, you know, it's kind of a little bit A, a little bit of B. Yeah, you better hurry. You know, they're, they're still technically here even though they're owned by Hershey's. Yeah. Well, looking forward to to seeing the success for those folks. And of course, big congratulations to that whole team.
Also, Rob, did you know that the Colorado Convention Center is the 3rd most popular convention center in the US in one category according to rankings? Yeah, in terms of they were ranked number 3 based on visitor reviews, how much visitors liked it, which is interesting. You know, I think our convention center is just fine, but it's a little disorienting sometimes getting from one area to another. Sure. Just makes me wonder how much harder other convention centers must be to use.
Well, I have, I've been in several convention centers. Some of them are like mazes. You know, you go in one entrance and have to go up and down and around to get to other places. So, um, you know, sort of having more or less one entrance and, you know, not too much, uh, too many ways you can go, I think is, is pretty good. We were also ranked number 3 for the most environmentally sustainable.
Good scoring there behind San Francisco's Moscone Center and Los Angeles. Uh, overall we were what, number 10? I think, I think we were number 10 overall. Number 13 overall. Excuse me.
The number 1 overall ranking was from Chicago, the McCormick Place in Chicago. And number 2 was the Las Vegas Convention Center. I have been to both of those. They are fine convention centers as well. I'll tell you that what surprised me was we were ranked at number 16 in terms of safety.
Yeah, I feel like it's a pretty safe convention center. I thought that was interesting too. I mean, I wonder, is it like visitor safety or is it like how many people fall down the stairs or something like that? Yeah, good question. Anyway.
Yeah, well, that's, that's our local convention center. Go team. Built, built during our lives.
I do think it's also interesting that we are low in terms of most affordable for hotel and food costs. I would have figured we would have been a little bit higher on that. Yeah, I would have too. All right. Next story we have is from a new company, new to me at least.
It's a personal personal chef platform, and you can think of it like an Uber or a Lyft for personal chefs coming to your home. It's called— I didn't pronounce this ahead of time. It's Intuit? Intuit? Intuit?
I think it's probably Intuit. Intuit. Like, like, like it's intuitive, but you're eating. Yeah. Or maybe Intuit.
Into— I think Intuit sounds good. We're going to call it Intuit. So Intuit is a platform where personal chefs can list their services and they can be contracted by individuals who want to have them come into their and deliver a, a gourmet experience, you know, for a personal party. Yeah. And, um, I, I think I would think about it more like a, um, like an Angie's List or a HomeAdvisor for personal chefs or something like that.
Right. You can go there and they have a list of, of chefs that you can use and then you can contract with one of them. Um, it, it said right now, I think that they have 5 chefs on their platform and they have at least 5 more, uh, in the pipeline that are, that are getting approved. So still a pretty small platform, but, you know, sounds pretty cool. I know next time I want a personal chef in my house, which would be a first time, then this would be a place I would go.
Yeah, not like I've done a lot of these things, but I've had catering to the house a few times in my life, and this seems like an interesting alternative to that. The— they said that the average price was between $60 and $80 a person, and then they also had gourmet options up to like $200 a person. But, you know, $60 to $80 for a for an event is actually pretty reasonable. So interesting to know. And it's nice to have this option out here.
And of course, it is a Colorado company with a Colorado footprint. So you can, you can give it a try. Yeah, pretty cool. All right. Denver-based EverCommerce, who we've talked about recently, announced their IPO pricing and apparently went public and is now trading on the Nasdaq.
Yeah, I, I mean, I didn't realize that this was so fast. It was coming. I think it was just last week we talked about this maybe, or maybe 2 weeks ago. The article we had last week, it didn't really seem to say that they were this close to IPO. I didn't realize it was this close.
I think this is just a quick update. Um, you know, they listed at $17 a share. They had more than 19 million shares go public, and they're currently trading over $17 at $17.24. So you call that a successful IPO. Um, the company's, uh, market cap is— I actually looked, it was about $3.3 billion.
So a good valuation, and, you know, just real positive stuff for them. Congratulations. Yeah, good stuff for EverCommerce. Hope things keep going well for them. Did we— have we talked about this next one?
This is a New Zealand tech startup that's picked Denver for its, you know, HQ too. Yeah, I don't know if we have. It didn't sound familiar to me. Yeah, I remembered reading it, but I didn't remember that we had actually chosen to talk about it before. So I think it's called Filevent.
Is that right? Filevent? Looking to confirm. No, excuse me, Fileinvite. Fileinvite.
Yeah, Fileinvite is the name of this company, New Zealand-based. They, they apparently, you know, have, have grown really big internationally and have about 40% of their customers in North America now. So they decided they needed to put a, uh, what they're calling their, their global sales headquarters here in North America. And it came down to Utah, Texas, Illinois, or Chicago. And, you know, pick Denver, I think in large part because of the success of Xero, which is another New Zealand company that has moved its like HQ to here, to Denver, and how, how positive the move has been for those guys.
Yeah. And this is the appropriate place to say screw you, Austin.
Sorry you didn't get chosen. And, you know, it does just say Texas, but we all know that. We all know that's what they meant. Yeah. Yeah.
So this looks like good stuff. There are going to be 140 new jobs for them in Colorado and they're going to be hiring immediately. So pretty cool. Good stuff. Jumping over to the security portion of the show, we have an update from CloudRise.
You know, CloudRise is the The DLP, sensitive data protection company started by Rob Eggebrecht, the one of the co-founders of InteliSecure, which we've talked about on the show for years, who recently was sold to Proofpoint. Rob started CloudRise out in Grand Junction, and we talked about it a couple of months ago on the show. Well, they just closed their seed round of funding. Yeah. And in the article, they don't talk about what that number is.
But being an experienced entrepreneur, I'm sure it's a decent number. They also mentioned that they were actually launched in October of 2019, which seems like an awfully long time ago, but that they've also delivered on over 100 projects so far with over 60 customers globally, including several in the Fortune 50. So they're making good progress. I'm really glad to hear it. We still need to get Rob on the show.
I think so far we have dropped the ball on reaching out. We need to do that and, and hear what they're doing and what the vision looks like for Cloudrise. Yeah. Next we have a press release from Swimlane. So they have a new release and with it they are going to be what they're calling the security system of record.
So this is some new features for Swimlane. You know, maybe just a tease for some of the stuff that might come up in the feature interview today. Um, but, uh, but yeah, so they've got a few new things that they're highlighting. Um, they've got a quick start service. Um, they now have a collaboration hub, uh, as part of the, the platform.
Um, and also some new dashboards and, and reporting. Um, but, uh, you know, this is good stuff for Swimlane. Um, more new stuff and glad to see them continuing to go on. Yeah. As I read through this article and, and I was trying to figure out some of this kind of marketing speak at the beginning, you know, being the system of record or source of record for security.
What does that mean, right? Does that mean you're my SIEM? Does that mean you're my GRC tool? What does that mean? Well, when I get to what I got out of it is this dashboard and the reporting that they're going to offer starts to tell you the effectiveness of what you're doing from security operations.
And I think one of the biggest challenges that SOAR has always had is, yeah, it sounds really good, but what am I actually going to do? Am I actually saving time? Am I actually, you know, getting more things done, you know, the value prop that I've heard from lots of SOAR companies is, well, if you had infinite time, what more would you do? Well, now that I bought your tool, am I actually doing those things? You know, if their dashboard and their reporting can actually get me that information, you know, I think it could be a game changer in terms of showing the ROI on that investment and, and really start to open up new markets that currently were closed.
Yeah, I think, um, you know, one of the other things is, you know, when you think of system of record That's really the source of your source of truth, right? And, you know, there are some tools which might be the source of truth for pieces of security, but with, you know, sort of the expanding use cases that you can do in a SOAR platform, you know, maybe someday you could get to the place where wherever you need something, your SOAR is the place where you go and that is your system of record for everything. I don't know, how are you ever going to make spreadsheets not be this source of truth for security? Security program. It's gonna be a tough, tough ask.
Tough ask. Gotta automate those spreadsheets in the SOAR. Yeah, that was sarcasm. Yes. But sadly, it's not sarcasm.
Well, it is where we are as an industry for sure. All right, moving on. We have a blog from Coalfire asking the question, what is FedRAMP+? Yeah, I'd like— I actually did not know what FedRAMP+ was, so I was pretty glad to read this article. So FedRAMP is a set of requirements in order for you to, to offer, to offer a cloud service to the federal government.
And there's like a nice centralized office that helps guide you through that process to be given authority to operate in FedRAMP. Well, the plus part of it is all of that FedRAMP stuff plus the requirements to meet the DOD's requirements for security. So, you know, the Department of Defense does have a significantly higher bar for security than, you know, the Department of Labor or Treasury or whatever. DoD is kind of the highest tier, right? Um, so, so FedRAMP Plus is basically, hey, you already got your FedRAMP ATO, we'll come add this other stuff, and now you can have DoD approval as well.
Yeah, so they have what they call the Cloud Computing System Requirements Guide, which are requirements that will go on top of FedRAMP. And so if you can meet those requirements as well, then in addition to being FedRAMP compliant, then you can sell to DoD for your cloud services. Yeah. So a good article by, is it Keith Kidd, is the director of FedRAMP assessments for Coalfire. And I think it's worth taking a look at if you're FedRAMP or thinking about getting in that area.
Yeah. It does go into some detail about the different levels that they have in the system requirement guide for DoD. So, you know, if that's what you want more information on, some good information in the blog about that. All right. Final blog this week is by LogRhythm and I, Pulled this one out because it aligned with a conversation we had last week on that panel.
So the headline is Cybersecurity and the Water Supply: Managing a Growing Risk Worldwide. You know, during that panel we had during Identiverse, one of our panelists, who I won't say by name because I don't remember if that person wanted to be quoted, mentioned, you know, we were talking about the fact that, you know, the SolarWinds breach was, you know, it wasn't the first time we saw Russia, or excuse me, a nation state in bed malware into the supply chain. It was the— it was just the first time that it really hit the US hard. The previous time that, you know, they'd gone after the Ukraine with that tax software. And then I had asked the question, okay, well, what other thing have we seen an example of that we're not taking seriously enough yet?
And he threw out the water supply issue with that issue from Florida. And then San Francisco recently happened as well. And that's what this article is getting into here. Yeah. And it talks a little bit about the background and what the problems are.
And it talks a little bit about, you know, what LogRhythm sees as a potential solution. And, you know, not surprisingly, that involves centralized visibility to see, you know, what's going on in all your environments, something that LogRhythm can provide. But that is true, having centralized visibility into not only your IT but your OT environments and, you know, all the sort of disparate things that you might have running a water supply company organization, centralized visibility is a good thing. Yeah, I think to me the key is I don't have any problem with vendors who do some part of this solution talking about it because that's how we get there is enough people saying, hey, go look at your water supply, go, go think about this type of a risk. And there's probably 50 different vendors who'll say, you know, Ping Identity might say we got to have MFA on all those systems.
And, you know, Red Canary might say you got to have, you know, EDR or MDR monitoring those systems. And everyone's going to have their own angle on how to solve it, but Right. We should all agree we should solve it. And let's have some security people thinking about that answer. And then just do all those things, whatever everyone tells you, just do all those things and you'll be fine.
Well, at least, at least think about which ones to do. Yes. That's probably a better idea, Rob. All right. Hey, let's, that's it for news.
Let's jump over to events. As a reminder, we do have a calendar of events. Um, there's a couple of things coming up in the next couple of weeks. Uh, I think we are going to be taking off a week, um, in here. So I actually, I went out to 2 weeks out or 3 weeks out into the future versus our normal 2 to get a little further out there.
Sounds good. The first one that we have is the Cyber Mountain Colorado Springs is doing their hybrid First Friday on the 9th. On the 14th, ISSA Denver has a July meeting, and that's Douglas Brush who's going to be talking there. Very nice. On the 16th, the Secure Software Development Life Cycles group is meeting.
I think the last— oh, well, 2 more here. The 20th, ISSA Colorado Springs is doing their July meeting. And then on the 24th, ISSA Colorado Springs is doing their July mini seminar. Good stuff. And those are, those are great for getting yourself some CPEs on a Saturday morning if you want to spend a few hours at it.
Yeah, good stuff. All right, let's jump over to jobs. Starting off, we have a Kaiser Permanente job. Jen Vasquez, who's the CISO over there, recently joined the Slack community. I think she shared a whole bunch of open roles that they're hiring for, right?
Yeah, and this was one of them. So if you don't like this one, go check it out because there's many more. This was a Senior Program Manager for Cybersecurity and Vulnerability Management. Is this supposed to be Cobalt.io? Yes.
Sorry, we've got a little typo there. Cobalt.io is looking for a security program manager. Cobalt is not based here, but that is a remote job. Awesome. Xerox is hiring a vCISO or a fractional CISO role.
Denver Water is looking for an IT security analyst. Centura Health is hiring a security engineer senior. Sigma Computing is looking for a head of information security. This is basically their VP of security CISO role. And Ross Hosman, who's in the Slack community, will be happy to tell you all about it, as that's the role he's leaving.
Ibotta is hiring a security architect. JumpCloud is looking for a security engineer for incident response. Dish Network is hiring a wireless security architect. That was probably pretty cool because I'm guessing wireless here is 5G. Yeah, I bet so.
And Charlotte's Web is looking for an IT security and controls analyst. So if you want to help secure, uh, someone in the, the marijuana industry, then, uh, there's your job. I, I assume that there's samples. I don't, I don't know how this works. Yeah, who knows.
All right, that is it for the news. Uh, we do have a feature interview. What are we doing this week, Alex? Yeah, so I talked to, uh, Cody Cornell. I think I teased it a little bit earlier in the podcast.
Uh, Cody is now the Chief Strategy Officer, uh, still co-founder, uh, but Chief Strategy Officer for Swimlane. And this is the 3rd time we've had Cody on the podcast. I'm pretty sure he's the first person we've interviewed 3 times, or at least feature interviewed, right, for the 3rd time. But it'd been about, about 2 years since we had last caught up with him. So we thought it was a good time to get back and see what Swimlane was up to.
Awesome. Well, I'm excited to listen to it. Of course, Cody's a fantastic fan of the show. We appreciate— they bought the stickers for us when we changed logos. They did.
Thank you. All right. Well, that is it. We'll look forward to talking to you guys in a couple of weeks. Thanks, Rob.
This is Jay Wilson, CISO of Healthgrades. Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. Uh, we've got our feature interview, uh, here today with, uh, Cody Cornell, who is not the CEO of Swimlane. Um, Cody, I— we were talking a little bit earlier Um, you are— you're sort of, uh, gonna become an honored guest today.
A— you're gonna be in the pantheon, whatever, whatever you want to think about it. I think that you are the, the person for the first time that we've interviewed for 3 times on the podcast. It's awesome. No, I'd say it's always a pleasure to be here, and, uh, I didn't realize that, but, uh, thank you for bestowing that honor on me. We'll have to go get your plaque.
Yeah, I'll put it in the mail. Don't worry. All right, all right, I'll be looking out for it. Um, and it's very exciting because we're sitting here in person. Yeah, actually talking to each other in a conference room, which is fun.
Yeah, it's, uh, I'd like to say that, you know, everybody's come running back to the office, but I think, you know, from a COVID perspective, folks are trickling in. But, uh, it's good to be back. It's good not to have to wear a mask everywhere. Yes, I went out for, you know, beers last night with a friend, and, you know, it was very normal. So it was pretty weird.
Good. So I mean, it's cool and it's fun, but it I think it's, you know, it's still a little bit weird and people trying to adjust and all that kind of stuff. Yep. Yeah, I think, I think so. I think, uh, I think people want to get back, but there's also— they got used to it.
Like, there is something to be said. We were talking about commute times and getting an extra hour of sleep a night and all of those things that you get when you're not, uh, having to commute in. And I think some of those things are gonna be hard to give up. But I think also people definitely want to be around other people again. Yeah, I mean, besides their family anyway, right?
It's like, let me go talk to someone besides my wife, my dog, my kids. All that stuff. Please, someone, let me come talk to you. Yeah, I mean, as someone who travels a ton, or was traveling a ton before COVID I mean, being home was— it was awesome. Like, I don't— I cannot remember the last time I've slept in my bed and ate at my own dining table that many times.
And, you know, I think our family is better for it. Um, but, you know, I think we're starting to see— I got my first request yesterday to go out and do like an executive briefing. So it's, it's starting up again. So I, I imagine we'll see it'll, you know, normal— what's normal, I don't know, but I think we're heading back. Yeah, it's going to be interesting to see what normal becomes, but hopefully it's a better normal than what we had before.
Yeah, agreed, agreed. Hopefully people feel, you know, much like, you know, we want people to— can we make this meeting an email? Can we make this travel, this 4-day trip into a Zoom meeting? Like, right there, I think there's a place for that. So I agree, I agree.
All right, so for people listening, Like I mentioned, this is the 3rd time we're interviewing you. So I went back and listened to the 2 interviews just so I could be prepared. But for everyone else, if you want to be prepared, the first interview was episode 15. And go listen to that one if you want to hear about Cody's background, how he started in security, how he started Swimlane, all that kind of stuff. And then the 2nd one was episode 80, which was just about 3 years ago.
I think it was like 18 months between the first time and the second time we, we did it. Now we're doing 3 years, so they're expecting some, some big changes here. There's Ben. And, uh, and so if you want to go back to episode 80, you guys can hear about, uh, more about Swimlane, about what Swimlane does, um, and, you know, direction, at least at that time, right? Um, but I think the first thing that I wanted to talk to you about is, you know, for those first 2 interviews, you were the CEO of Swimlane.
And you're no longer the CEO of Swimlane. I'm not. So, uh, so what happened there? Yeah, um, it's interesting, right? I mean, starting a company is— it's a journey, and when you're smaller, you have this opportunity to kind of learn.
And, you know, for me, it was trial by fire. I'd never worked at a product company, so every function inside of the organization was new. If it was marketing, if it was sales, if it was product, if it was engineering, if it was back office, whatever it was, you know, I was kind of learning on the fly. And, you know, that worked out really well. I mean, scaled the business, and I think we got to 135, 140 people, you know, a fair amount of great customers globally.
And but there comes a point where, you know, we raised $40 million last year, and, you know, one of the jobs that I don't think that, you know, until you've sat in the seat or you've had an opportunity to sit down and talk to somebody who's done that, is you make a lot of decisions with incomplete information. Like, that's your job as a CEO of a startup, is you have to make a lot of decisions with very vague and incomplete And one of the things that helps you a lot in that moment is a ton of experience, which as a first-time founder and a first-time product company exec, I didn't have. So I find myself in those situations where I was like, well, I could probably go learn and ask and read and listen, but as the company grows, you're venture-backed, so runway is important, capital burn is important, so how do you improve your situation likelihood or success of making the right decision? Well, you have people with experience. Finding the right person is hard.
We looked at different ways of structuring that. At the end of the day, we wanted to have the right person, and to get the right person, which Jim is, we needed to bring him in as a CEO. I'm excited to have him at the helm because as a partner in running the organization, he brings a ton of experience to making decisions that I didn't have, right? You know, he leans on me very hard on technology and market and competitive landscape and what it's like to be an analyst and things like that. But as it relates to, you know, what's it like to run a public company or build a public company or work with, you know, tier 1 investment bankers and venture capital firms and, you know, things like that, like, he's, he's had to see that whole life cycle many times.
And that context informs our decisions still within employee data, right, much better than I could on my own. And I think that that change for me has been great because I'm learning a ton, and, uh, I feel like we make better decisions and we make them faster than we could without that, that experience at the table. So yeah, well, and you know, you're, you're a security guy by trade, right? That's why you did this, because you wanted to make security better. And you know, at some point as a CEO, you know, your job becomes more more focused on raising money, on talking to the public, on talking to investors, on all those kind of things.
And, you know, if you're someone that wants to do security, that's not really, you know, core competency and things that you want to do. So, you know, I can see where, okay, let's bring someone else in who can do this stuff and I can focus on the things that I'm best at. Yeah, I mean, obviously I started Swimlane because I love security and I learned to love to build product. Like, I really enjoy that process now. But I also learned that I love building a business.
Like, as much as I love security and still do, there's a portion of my mindshare every single day that goes towards things that are not security-related or they're more business-related. And I really do enjoy those things. And it's funny, as there's, you know, I'll be honest, like, if I would have known how difficult it was going to be to build the organization organization before I started, I probably wouldn't have done it. So like, the ignorance is bliss was like truly the case for me. Um, but now, you know, I spend a lot of time, you know, spending thinking about security and the product, but also the business.
And I think there's the problem solving that you use as a— you know, I was always on the blue team side. I was never really breaking into things. That wasn't my jam. Yeah, but that problem solving and systematizing things and the way you think about how you, you know, build a security program the team and the structure of that team and the methodologies that you use, there's a lot of that that's applicable to building a business. How do you build the team?
How do you fill gaps? How do you get visibility? How do you make decisions with incomplete data? And I think folks are thinking about, should I make that leap or could I make that leap? There's a lot of those skills I think are equivalencies for people that want to go down that path.
So yeah, it's different. I mean, not being the CEO of the organization is definitely different, but I'm probably learning more now than I probably did in the 12 or 18 months leading up to the point that Jim joined. So, well, you know, you sort of have a built-in— you call it a mentor or whatever. Oh, absolutely. You know, so it's, um, instead of you having to go elsewhere to figure out, okay, am I doing this right?
You know, it's someone else is doing that and you can work with them too. Yeah, I mean, it takes a village. Like, there is no doubt that, you know, doing something big requires a team of people. You don't do generally, unless you're an anomaly, probably do really big things by yourself, right? So having that team is allowing us to do things that I think we maybe we could have done, but we're getting to faster and probably with a higher success rate.
Yeah. So you're not CEO. Nope. What is your actual title now? I am the Chief Strategy Officer and co-founder, right?
So I get to keep my co-founder status forever. So that's, you know, arguably the one I'm probably most proud of. But yeah, strategy for us is what does the product look like, what are the opportunities inside of the market from a competitive landscape perspective, what do our technical partnerships look like, services partnerships. So there's a lot that is the same that I'm doing that was really kind of taking one position and dividing it up. But yeah, I spend a lot of time talking to our customers, prospective and existing, spend a lot of time talking to our technology partners, right?
So what's the ecosystem look like? How do we partner? How do we help each other out both economically, but also how do we help the customer get the outcomes that they're looking for? And spending a lot of time talking to the product teams. How do we make the lives of security teams better?
How do we reduce chaos and uncertainty and actually allow teams to get more done? Yeah, yeah. So you were mentioning earlier also that in a pre-pandemic world, you traveled a lot because your job is to talk to customers, talk to partners, all those kind of things. How has the last year affected you and being able to get those kind of things done? You know, we were, you know, our first several hires were remote.
So like we've been a remote organization since day one. So we've always been comfortable with working remotely. So that was nice that, you know, we'll call it the accelerated digital transformation of an organization went really well for us. I think what I learned is there, there's always going to be a place, and it's generally, you know, to be honest, when you want something. Like, if you, if you want a customer really bad, if you want a partner really bad, you want a key hire, you're going to go to them, right?
And not having that as a lever to pull, it feels— it's difficult. I mean, we raised capital in the middle of COVID uh, we found a CEO in the middle of COVID Like, there's things that you never thought were possible that you can actually absolutely do remotely. But on the flip side, you also feel like some of the tools in your arsenal, right? You know, building a relationship with somebody is difficult over Zoom, right? There's no hallway conversation, there's no dinner afterward, there's, you know, it's very finite times because everybody's calendars are really tight.
So I think it's— I think I realized you can do more remotely than we probably give ourselves credit for, but it also reduces the, the levers that you can pull in the moments where you're really trying to get something over a hump. So yeah, and, uh, I've noticed that as well. You know, my job is also to meet with people a lot, and, uh, you know, I've got a portfolio of companies that I, I help manage their security programs. And, you know, I started basically 3 months before the pandemic, so I, I got a chance to meet a few of the people in person when but not everybody. And luckily for me, I have had someone that worked for me that, you know, had relationships with all those people.
So, you know, that was helpful. But still, you know, the, the people that I have met in person, it is much easier to go to them and say, oh, hey, you know, we do have a relationship. Can you do this thing for me? I need this information, whatever it might be, because that relationship is there. And then there's also people that well, even some of those people where they're just really busy and it's hard to get a hold of them, whereas if I could just, you know, show up at their doorstep, I know that you're going to make time for me if I am here.
Yeah, there's definitely a tactic of— I always called it sitting on someone's desk, right? I did a lot of work in government and, you know, inside of big organizations where sometimes just physically being present would allow you to get your work prioritized, and, you know, that there's things like that and You know, you can't do that, right? Or you— it's also harder to, you know, you have to be conscious about how you collaborate and things like that. And I think being, you know, one thing that I did notice when everybody is remote versus kind of in a hybrid where you have some people remote, like, the collaboration style changes. And there's moments where you feel much more inclusive, right?
And that's great, right? You like that feeling like it kind of everybody has the same access and the same visibility. But there's also things that that are harder, right? Like we have this massive whiteboard in front of us right here. Like, yes, Zoom has a whiteboard feature, but let's be honest, it doesn't feel the same as being able to get up and use a whiteboard.
So, but you know, again, there's things that we've learned that we could do that we didn't think we could, and vice versa. There's things that you really miss. So yeah, you know, it is funny, virtual stickies on a Kanban board is not the same as actual stickies on a wall that you can, you know, all work together and move around instead of, you know, clicking and dragging. And, you know, there's just always going to be something about being there in person that's going to be better in some instances. Yeah, absolutely.
I, I don't know if it's tactile or physical world, but there's, you know, something to kick. Like, if you're mad, you don't want to, you know, virtually shake your fist. Like, you want to, you want to kick something, or, you know, you want to high-five somebody, right, when you get that win. So, and that just doesn't feel the same online. But then again, it's very obvious that it's not needed to move the ball.
And that's, that's exciting to see. There's got to be some physiology to it because, I mean, I know lots of people that say, you know, if I physically write something down, I remember it a lot better than if I type it, right? Yep. So there's got to be something with actually touching and moving things or doing, you know, seeing somebody in person. Anyway, um, well, uh, we don't need to go down that road.
One of the things that you mentioned a second ago was how much capital you guys have raised. Where are you guys now in that process? I know we've covered it on the show, but I don't remember what the last raise you guys had was. Yeah, so we announced it, it was basically Q4 of last year. We did a $40 million raise, Series B.
So continuing to grow the organization. We're 150 people globally now, and we have customers that are global. So we're really excited about the category, right? There's no lack of appetite for automation. There's been a lot of really good successes from a product company perspective in the space, but there's also the great majority of organizations have still not adopted automation across a broad set of security use cases.
So we just, we think the appetite for it and the opportunity for it continues to grow. And what we see is people taking automation into places that, like, quite frankly, we never even thought of. Like, we never thought you would use our product in that way, but we're happy that you are. And now that you are, we're gonna tell all our other customers. We're gonna try and productize that now and share it.
It's funny is that, like, there's been so little, in my opinion, innovation around the people component of security in the last couple decades. There's been things here and there, but generally we're talking about, you know, machines. We're not talking about people, and where automation comes in is there's a very human element of it, and people are very excited to participate and to share and to collaborate, a lot more than I had seen with endpoint security or network security or even kind of log aggregation search, all that fun stuff. Like, there's the appetite to share ideas and concepts and improvements, and those components is, I think, is really high. For this niche within, you know, within security, which is not really a niche, right?
Automation is applicable to every, you know, every use case that's out there. I mean, as we all know, the folks that have to go turn the dials and send the notifications and things like that, there's, there's a lot of appetite for, you know, just being happier on my job. Like, I don't want to do those things. Like, I'd rather spend time building a hunt hypothesis or doing incident response or improving my tools set, but I don't want to really be sending out email notifications. Yeah, you mentioned the sharing.
On the last interview, you and Rob talked a little bit about SecOps Hub. You guys had just released that. Is that where a lot of this sharing is happening for you guys? Is that something that has turned into a vibrant ecosystem? Yeah, I mean, there's definitely people sharing information.
It kind of happens in 2 spots. You have kind of traffic on the public forums, and then you have a lot of traffic that's, I would say, happens kind of through our tech support portal as customers. So that happens there. And, you know, you have a situation where, you know, folks are getting into automation, and that's generally where you see a lot of the public, you know, information. But, you know, I think a lot of the sharing is happening between customers and, you know, prospective customers and things along those lines, as well as like service providers, right?
There's a lot of our partners partners are managed service providers or MDR vendors or big consulting firms, right? And they awkwardly compete in the market publicly, but behind kind of a very thin veil are collaborating aggressively, which is really interesting to see, right? And I think we see that in security, if it's threat intelligence sharing or anything else. You know, you might be competitive in market, you might be in retail, but— and you have— you're competing with another big box store or another provider, but those security teams know each other and they actually are helping each other out. Yeah.
One of the other things that you mentioned a minute ago was seeing people do things with the product that you weren't expecting them to do. What are some interesting use cases that you've seen people come up with that you wouldn't have thought the product would have been used for? Right. I mean, we see folks that are using the product for application development lifecycles. So what's your CI/CD CD process look like, and how do you track that, and what tools are you using for container security and vulnerability assessment and code quality and linting and all these different things and actually tracking that process?
Generally, when people think about automation, they're thinking about the security operations. They're thinking about alerts that are coming in from all of your telemetry and monitoring systems, but people are using it for, I would say, I would call it almost cyber hygiene, so application security or vulnerability assessment. Assessment, or even quirky ones like I would call high-risk travel. Workday isn't way high on the list of integrations you would expect, but it's really common. Am I traveling to a high-risk region for my company based on what I do?
Should I change the security policy on your device because of where you're going? Where does that start? It doesn't start in your endpoint monitoring tool or your forensics tool or your firewall. That starts in your HR system. Right.
And those are use cases that, you know, just they weren't top of mind for us, but they're becoming very, very prevalent. So yeah, I was actually on a CISO dinner last night and the topic was compliance. Okay. And one of, one of the people said that I was asking, you know, how are you getting better at, you know, managing all the different regulations and all that sort of thing in your organization? And one person said, I would suggest everyone get a SOAR for compliance.
And, you know, he would, you know, his, uh, his idea there was, hey, well, we're automating all of the evidence gathering, all of the reports, all of the whatever, so that if someone shows up to do an audit on whatever it might be, they just click a couple buttons and they can produce all of the documentation that they need. Are you seeing other people doing that? Absolutely. I mean, audit support support, compliance support are two, I would say, they're use cases that people are buying for, but they're also byproducts. You have this moment where you're, as a security team, we don't have a system of record.
Sales has Salesforce, engineering has Jira. Maybe that's kind of the closest, but not really. For machine data, without a doubt. But what SIEM doesn't capture is human decision information. Sure.
And that's really what you're being audited on. That's what you have to produce artifacts for. So if I'm doing an OCC audit or an SEC audit or I got the Big Four coming in or whatever it is, like they're going to come in and they're going to pick, you know, 25 security alerts and all these different things. They're going to say, show me the evidence, right? And where do you go, right?
I mean, I know what I used to do. I go search email, I go search through my ticketing system, I go search through my alert logs. And I'd put it all together and I'd hand it to them and it was all from 8 months ago and I'd be like, you know, cross my fingers and hope it goes well. Are you a good auditor or a bad auditor? Yeah, right, like how deep is this guy going to go?
You know, but what we see now is, you know, through a quick search and a really easy to produce report, I can show you not just the 25 you asked about, I can show you all 80,000 from last quarter. And here's every decision we made, why we made it, how it ties to our policies and procedures. Here's all the artifacts, here's them all stored. It makes the life of someone who has to deal with audit requests, be ad hoc or quarterly or monthly or annually, whatever you're getting, it just makes your life better, right? I mean, it's stressful to go through that audit process and it's time-consuming, and to have the confidence to have that data readily available whenever they ask for it and not have to like, let me think back 9 months ago to when this happened.
What system were we using again? Did we switch this investigation tool? Do we have a different mail gateway? Like, what was I doing in that moment? Like, you have to kind of go back and mentally reconstruct that moment, and that's, that's damn near impossible to do.
And I think, I mean, even for around audits, for the non-security people, the things you don't think about— like, you did, you know, you mentioned Workday for a different use case, right? Right. But, you know, if you're doing, uh, any sort of audit, you're probably going to have to generate a a population of your employees and a population of, you know, people that have been terminated in the X, you know, X amount of time, right? And, you know, most places where I've been, it's like, all right, well, I need to go ask the HR people to do this, and if they're nice, then they'll get it back to me, you know, in a week, um, or, you know, whatever. And, you know, maybe I can get them to do an automated report so that they— it's faster when I ask them for for it.
But if you have that system plugged into your SOAR, you can just boom, now I've got my report and pass it along. Absolutely. And I think that's a great example of where people are applying automation inside of security that isn't, I guess, typically associated with the category is like user onboarding and offboarding. Like, how do I track that? How do I keep a record of, and it's not just for Active Directory and it's it's all your SaaS services, right?
Like, how much are you spending on Office 365 for contractors that are no longer here? So there's a cost savings component to just having good hygiene, but along with that hygiene, you get data loss prevention. You don't have credential reuse opportunities. There's all sorts of surface area that you're contracting when you're using automation as a mechanism to optimize different aspects of security, right? And user onboarding is just one of the many examples.
Yeah, yeah. To make all this work though, you have to integrate into a lot of things. Yep. I'm curious, what's, what's the weirdest thing that you've seen someone integrate with? Oh man.
Or how about maybe not -est? What is a weird thing that you wouldn't expect someone to integrate with? So we actually see a pretty big uptick in Fusion Center, right? And everybody uses the term a little bit differently, but we're seeing this convergence of, let's So I'm starting to see video feeds inside of the Swimlane UI from physical security. You're like, oh, interesting, makes total sense, right?
And then you start thinking about, I mean, it's kind of a tried and true SIEM use case, how do you converge the physical world and the cyber world? If I didn't badge into this building, I shouldn't be VPNing in from this building or single sign-on from this building. There's some things from a correlation, the impossible login scenario, right? But that also plays out as you're triaging. Converging alerts, like what's the convergence of fraud and cybersecurity and physical security.
So I think there's, again, it's not so much that it's a weird integration, it's just, I think it's kind of where things are headed and how people are thinking about, I'm gathering lots and lots of data from lots of different sources, that's only going up, what do I do with that and how do I actually action it? I'm spending a ton of money to capture it, Now how do I do something with it? That actionability of data I think is super important. Yeah, that's really cool. Uh, one of the other things you mentioned in the last interview was that, um, you guys were— you were preparing your SaaS service, um, but you know, you were, you were holding until you guys were ready.
Yep. You were making sure you were compliant, making sure all this stuff. Um, are you guys— is that a service that you guys offer now? Uh, so not today. Yeah, and I say today because time horizons are, are pretty close.
So, um, we, we definitely believe in a cloud-delivered opportunity for us. You know, you'll have Swimlane available as a Swimlane Cloud, and we're pretty excited to make that available. Um, you know, did not expect to be giving a date right here, so I'm not going to, but, um, it— I say not today because it's not far off. So, um, we're pretty excited about that. We think it opens up a lot of opportunities.
These for folks. It also opens up a lot of opportunities for us as a vendor. So yeah, that is on the near-term horizon. It's not for the faint of heart. We've historically— I mean, we have hundreds of customers that are using the product in their environments deployed, and getting that into the same parity, the same capabilities with all the security requirements that are associated with that is, as you know, and I think I've asked Rob a lot of questions, building SaaS offering and being the CISO for a SaaS offering.
There's a lot that goes into that, and we're making sure that we do that right, but we also want to bring some new— there's some new things we're bringing with it, which we're really excited about. So it's not just, can you get Swimlane in the cloud? There's things above and beyond that that we're really excited about. Yeah, so why now or soon, finally? Is it customer demand?
Is it just something that makes more sense for you guys as a company, these new secret features that you— Secret features? I wouldn't say they're secret, but they're additive for sure. It's, I think now makes sense. I mean, one, obviously we saw a huge push towards using SaaS services as it relates to COVID. I mean, I think that's without a doubt, but there's also things that we think we can deliver inside of the product as a SaaS offering that are much more difficult to deliver on-prem, but there's always going to be a need for a prem deployment.
There are types of organizations that are going to run this inside of their private cloud, that are not going to let this information go outside of their environment, but there's also folks that don't have the resources to run some of this stuff at scale that they need, and they would like to consume it as a SaaS offering. I think there's advantages for customers that we're excited about making available. There's advantages for us from a learning and recommendation perspective and things like that. From a business perspective, there's obviously— SaaS companies are tracked differently. We're a subscription company, not a SaaS company, as some people say, but we're moving in that direction and we're pretty excited about making that available.
Can you give an example of one of those things that is easier or better to deliver as a SaaS that you guys can't deliver or it's harder to deliver? Yeah, no, absolutely. I mean, if you just think about just general data aggregation, right? I mean, you see it inside of, you know, the network capture world, you see it inside the SIEM world, like the ability to, to capture more and more information and hold it, store it, make it available, historically referenceable, use that to build models, right? I'm not going to use the hand-wavy, um, you know, machine learning and artificial intelligence, but in order to build recommendations for, you know, customers and things along those lines, having aggregate information is an advantage.
For me, that opens up opportunities for small, what would seem like small insights that we see at particular accounts, being able to provide outsized outcomes for other organizations, and we're really excited about that. I think that's kind of the power of aggregate information, being in that data path. Great example.
You've been at this for a while now. Yep.
When you started, you obviously had a vision of where you were going and what the company would become, what the product would become.
Is that where you are today? Do you— have things changed? Are there— were there unexpected things that pivoted you away from where you guys thought you were going to be? I think so. I mean, I would say the North Star has remain pretty constant.
Yeah, the, the need to reduce the amount of human effort to do the job of security is like, that's still, that still needs to happen. And I think it's gone from being the privilege of a few who could afford it because it was, it's still a new technology for most organizations, to a necessity, right? The amount of information, as we talked about, is too much for a human team to respond to well. If not, you end up just looking at the most high-severity things, and as we all know, generally there was a canary in the coal mine there. There was something earlier that if I could've reacted to, might've prevented me from getting to this spot.
So I think that general thesis is still terribly applicable. Like, that's without a doubt, you know, that's the case. I think from a product perspective, you know, you always think you can move faster. Things are always harder than you think. Opening in new markets, you know, trying to get into Australia and Japan and other places, like those, I'll be honest, I was probably a little naive, right?
The way people buy, the way the distribution networks work, there's a lot of learning that I had to do and we still continue to do, but I think we have, we've built a team that knows that well. So there's things that were easier than I thought and there's things that were harder than I thought, but directionally, the need to solve this, which still primarily an unsolved problem is still there. So yeah, yeah, I mean, even though that need is still there, I feel like the market that you guys are in has changed a lot. You know, for, you know, when this started, as you know, many new markets do, it's lots of point products, you know, everybody doing a startup. And now, while many of those products still exist, they're now part of somebody else's platform as opposed to an individual single platform.
How have you seen that change, and do you think that's the way that it has changed, is that a positive for you guys? Is it a negative? Is it neutral? Yeah, it's interesting, right? I mean, you never want to fault somebody for success, right?
I mean, the folks that have built organizations and scaled them and they've been acquired, like, hats off to them. That's really, really hard, right? So, and they're our competitors, and I know most of with them, and they're all good people. Surprising, you know, as much as I want to, you know, run around and be like, no, they're, you know, no, they're actually all really nice people. Um, I think that the thing that's interesting about what we do specifically in security from a technology perspective is the ability to work with everybody is pretty unique.
That independence to work with my competitors, with, you know, my well-aligned partners and things like that, is a unique spot within the segment. And being part of a bigger organization, yeah, they have tighter integrations with their products and things like that, and probably access to things that I don't within their ecosystem, but outside of their ecosystem, it becomes a little bit of an interesting dilemma, right? How well are they going to work with their competitors on the long term, right? And I think being where we're at is actually an advantage for us, and we have one product, we're focused on that product, everybody in this this organization is trying to make that product better, and I think that is, it creates a different culture inside of an organization, and it creates, full bias here, it creates a better product, because you're not trying to figure out how this is going to help us upsell and cross-sell something else, and there's nothing wrong with that. They have to run those organizations, they have to build those companies, and that's why they do those acquisitions, But it changes your focus and it changes what's important.
And I think, you know, being independent the way that we are gives us an advantage. And I think customers see that. I mean, and again, I know I'm the vendor, so I'm— yeah, I'll stop beating the drum. But well, and I think, I think it works the other way for them as well. Right.
So if, you know, they, they How well they work with other people is great, but how well are those other people going to work with them? Right. Right? If Splunk bought Phantom, are the other SIEM providers now, are they going to be as readily out there coming to Phantom now going, hey, we want to integrate with you? Right.
Now is it kind of like, eh, I don't know that that really makes sense for us anymore? Yeah, I mean, much like the folks that we compete with don't give me demos, I also don't get to have probably in-depth conversations with their business development teams. So it'd be easy for me to just kind of like throw the flag and say, absolutely, there's no way they're working with anybody else. But it's security. There's a general appetite to work together, and I don't think anybody is trying to full Heisman, keep everybody away, but the incentives don't align.
As well as when you're an independent. And so I think that there is advantages. I mean, we've seen really strong partnerships from folks that don't have an automation solution inside of their portfolio. I mean, we have some great partnerships that we're building because folks see the value of automation. They want to be able to deliver it as part of the offering that they're giving to their customers, but they need a partner to do that.
And I think that's where we have an advantage.
Stuck in that, you know, walled garden, to use the Apple term. So, right. Yeah, um, we're getting close to the end of time here. Um, what have we not talked about that, that we should have talked about? Oh man, that's always the hardest question because I, I, you try not to repeat yourself, and like you said, now we're at the third time.
So, um, I think for me, it, you know, it's— I've spent— I'm spending a lot more time talking to folks you know, both that have been at Swimlane or outside of Swimlane that I probably didn't have time to talk to before that were trying to make the leap. Like, I, I, I see this problem, I see this gap, I think there's an opportunity to build something here and solve a problem. And, uh, you know, those, those are conversations I like. I always laugh, you know, my parting comment in most of those first conversations is some people like to talk about cars, some people like to talk about sports. I really like to talk about grow-to-market strategies for cybersecurity companies.
Like, it's my favorite, like, dinner conversation, which drives my wife bananas. But, uh, I think there's— I think there's an opportunity for folks to solve problems that they feel every day by, you know, being an entrepreneur themselves, by being innovative, you know, inside of their organization, or, or, you know, trying to, you know, pull off the stand-up and own their own company. And there's a lot of resources out there for those folks, both within your local community. I think other founders want you to succeed. They want to help.
And I think, you know, if you're sitting there and there's something that's really, really bothering you, and there's a lot of people that you talk to and it bothers them as well, like, take a long hard look at it and think, you know, is there an opportunity for me to do something there? It's not for everybody. It's not for the faint of heart. But on the flip side, I think there's something within this security community, and then that kind of startup ecosystem that will help you if you're second-guessing making that jump. Awesome.
Well, Cody, it's been great talking to you again. Appreciate you taking the time. Excuse me. Of course, good luck to you. Good luck to Swimlane.
We expect to hear and see much more great things in the future. Yeah, we got some pretty good exciting announcements coming up. So kind of hinted at them already, but, uh, yeah, be on the lookout for that. And, uh, I mean, not, not to, you know, selfish plug here, but we're hiring. Like, please, yeah, check out the, check out the page.
We're hiring for security people, you know, on the services side of the house, uh, on the product side of the house, on the sales engineering side of the house, software development, marketing, you name it, we're hiring. So, um, if you, if you want to work at a security company, if you want to work, uh, you know, inside of a startup, um, give us a call. We'd love to, love to talk to you. And are you guys still primarily, uh, hiring here, or is it all over the place, remote? Yeah, all of the above.
We've always had the mantra, it's better to have the right people in the right location. But, you know, we're a Colorado company, no doubt. So, I mean, there's a good percentage, probably a majority of our folks that are here. Actually, I know it's a majority, we just did the count. But, um, yeah, we're hiring here.
We'd love to have people in the office. You know, I'll give you a tour of the office, you can tell me if it's nice or not. But we think we did a good job, and, you know, we'd love to get some folks out here. And, you know, now that we're breaking out of COVID fingers crossed, no crazy variants, uh, we are, you know, we're back to the office, so we're excited. Awesome, good stuff.
Well, great talking to you, appreciate it, and I'm sure we'll do this again for number 4 sometime. All right, look forward to it. Thanks. Uh, this has been Colorado Equals Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.