Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 219 for the week of August 2nd. Alex, welcome back.
Welcome back to you as well, Robb. We are, we're pretty much done with summer breaks here, right? I know we're getting close. I think it's— well, my kids start football practice this week and they got a couple of weeks of that. And then I think school starts a couple of weeks after school.
I know, hard to believe. And the weather now kind of feels a little fallish. It's been, it's been raining this weekend. So nice. Instead of the, the uncomfortable 90s weather, it's the, you know, slightly more comfortable but sticky 70s weather.
Yeah, it is weird to have the humidity here. We're not used to that here in Colorado. But I am, I am excited about having a beautiful bright day outside right now and the temperature's not too hot. We're going to get to enjoy Sunday. Ooh, it is, it is Sunday.
Oh, this is what I was going to mention. It's Colorado Day today. Oh yeah, it is Colorado Day. That's right. It's our birthday.
It is Colorado's birthday in— it was 145 years, I believe. 145 years. Happy birthday, Colorado. Yeah. And I think that as Colorado Equal Security, that's like, you know, something we should celebrate here.
I believe that that's true. We'll have to put this on our calendar for next year too. Just make sure we talk about it every year. Or we can remember partway through the introduction, you know, one or the other. One or the other.
Yeah. Good stuff. All right, let's jump over to our housekeeping. We, we do have a Slack channel. Lots of great conversation going on over there.
If you want to join the Slack channel, go out to colorado-security.com and click that little button there to join. Yeah, we'd love to have you there. We also have a mailing list when you were on our website. Sign up for that. You'll get the show notes delivered to you in your email every week.
It would also be great if you would rate us and subscribe on your favorite podcast player so that people know how great the podcast is, and you'll get the podcast delivered to you automatically every week. A couple other things you could do to support us. Number one, you know, tell a friend. We'd love to have more folks as a part of the community, as a part of the movement. So go out and do that for us.
And also, if you want to help financially support the show, you can go out to our website and click on the Patreon link. That'll give you the chance to, to kick in whatever amount you want. We have some folks who are giving $1 a month. We have some people who give— is it, what is it, $50 a month? We have one that's pretty high there.
I don't know if it's $50, but there is one. $10 is our biggest general level. And we have, I think, at least one or two people that are over that. Yeah, a lot of folks at $10. We appreciate those folks.
Thank you very much for those who support. And if you want to be part of the movement and help us pay for this, we would, we would love that as well. Awesome. With that, let's jump into the news. Robb, did you know that if it wasn't a nice day like today, a little cooler, you could rent one of your neighbor's backyard pools?
Yeah, there's a new service called Swimply. It's like Simply, but with swim. Swimply. Clever, clever how they did that. And they call themselves the Airbnb for swimming pools.
And it looks like it's mostly, like you said, residential backyard pools. And this is not a Colorado company, but it just came to Denver recently. So there are, they said, just over a dozen different pools throughout the Denver metro area you can use to, to get a private pool for you and your family. Yeah, I checked this out after reading the story and it looks like there's one about 4 miles from my house. So if I wanted to go have a private pool, we could do that.
I also happen to have a neighbor with a pool. So, you know, maybe not my wheelhouse, but it seems like a pretty cool service looking through it. Looks like most of the pools that are on there are about $50 to $60 an hour for around 5 people. And then I think you can add, add more people for a little bit more per hour. But it's pretty neat.
You know, some of the chatter in the article, people were talking about how they can make a little extra money, you know, not only offset the cost that they have for maintaining their pools, but then make a little bit extra as well. Yeah, I mean, I was shocked at the number that was given in here. Someone said they made $3,600 in a month doing this. And they said that their maintenance fee for the pool was about $300 a month. I I mean, that's real money if you're making $3,000+ profit each month, the months in the summer, I assume.
It's not year-round. Right, right, yeah, you probably get that, what, for maybe 3 months, 4 months at the most? Yeah, during summer break is probably when you have the real common usage. But yeah, I mean, that's pretty cool. I guess it would, kinda like having a ski condo that you rent out for all of the times when you would wanna use it.
You know, it probably limits your own use of your pool when you might wanna be in there, but hey. Hey, maybe a little extra cash. Gotta get paid, yo. That's right. All right, next.
You know, Robb, we're familiar with some of the big businesses that were started in Colorado, like Coors and Chipotle. But you know that there are some other national brands that started here as well? Yeah, this is a Denver Post article that goes through some of maybe the lesser-known brands from Colorado. I am curious, you know, maybe at the end you can tell me, were you surprised by any of these? But we'll go through what they listed here.
First, Jolly Rancher was the— was started here in Colorado. And, um, they were made— or they, number one, they were started here, uh, 71 years ago. Yeah, I think that's an interesting factoid. It's an older candy than I had known, uh, and it was made here exclusively until I think the mid-'90s, like '96 or something like that. Yeah, it, it was, uh, maybe even a little bit longer than that.
But yeah, it was, um, it, it was sad that they moved out. And I think they— the company that bought them, I think now they make the candies in Mexico or something like that. Yeah, and now they're at Hershey's. They moved around a couple times, but now it's a part of Hershey's. Yeah.
Um, there's of course, uh, Smashburger, uh, which started a few years back, um, and is now a, a, you know, big national chain of hamburger restaurants. Uh, Celestial Seasonings, uh, which is based out of Boulder. So, you know, all you tea fanatics, uh, you can still go up there and do a tour of the, uh, the tea factory. I've done that before. It's actually pretty interesting.
My wife loves going to the Celestial Seasonings tea factory when I a new guest to Colorado comes in, that's on her list of tour things. They did open in 1969, so they've been around for quite a while. Crocs is a Colorado company. They were created in Niwot. This just says nearly 2 decades ago.
I don't know what that means exactly. I think that's 19 and a half or 19 and 3 quarters, something like that. Something like that. OtterBox, the phone case and other thing maker. They're based out of Fort Collins and they were founded back in the late '90s.
Yeah, that's the official list in here. Then they, they had like an offhanded comment in there about a bunch of other ones that were created here, a bunch of food places or food companies. So Noodles and Company, Quiznos, Qdoba, Illegal Pete's, Tokyo Joe's, Snarf's, Snooze, and Garbanzo are all Colorado companies, all that fast casual. So I mean, it feels like that whole sector maybe was really created here. Yeah, a whole bunch of those kind of companies all came from Colorado.
And this doesn't— that doesn't— that list doesn't include Modern Market, which is another Colorado company. It does. Yeah. It also— I feel like there's a lot of— these are sort of consumer brands. There's a lot of other obviously companies too that were started here that are big name companies as well.
So my question for you, Alex, is there anything on this list that surprised you here that you didn't know about? No, all of those were pretty familiar to me. You know, my, my wife is from Colorado originally, and I've heard her say several times about them doing tours of the Jolly Rancher factory when she was a kid. So I think that probably would have been the only one on there that might have surprised me. But how about you?
The only one I didn't know was Tokyo Joe's. I think I knew all the other fast casuals. I don't— I didn't realize Tokyo Joe's was a Colorado company. Very nice. Moving on next, Robb.
Both of us, we have solar panels on our roof, and I think we can tell you Um, it was kind of a pain to get them installed. There was a, you know, a process to get permits and other things like that that took a little while. There's a, a new app that hopes to help solve that problem. Yeah, so NREL, you know, our local government, what kind of a hybrid government-private sector organization here in town, that their whole purpose is getting renewable and, uh, renewable energy, uh, to be more widely available. They created an application called SolarAPP+, which, uh, which is really meant to make it easier to gather all the information you're gonna need to submit your, your permit requests to the county or city to get your solar panels installed.
Yeah. And, uh, this is something that they're now trying to, uh, push municipalities to adopt to hopefully stream— streamline that process. Um, it seems like this is something that is, uh, pretty standard across the board. In terms of the information that you need. And their hope is that places will adopt this so that they can really streamline that process.
And, you know, also because of that, that cut in the amount of time that it takes, cut down on the overall cost for installing solar panels. Yeah, it looks like a really good idea. There are thousands of municipalities that have to get on board for this. So it's not, it's not an easy, quick turnkey thing. But the Secretary of energy for the federal government is behind this application and trying to get municipalities to accept it.
So hopefully that means they'll have some luck and make it easier for folks to get solar and take some pressure off of our energy grid. Yeah, great stuff. All right, next we have an update about a private equity firm that is focused on the West here, including Denver, and this is Endeavor Capital. So Endeavor Capital has 4 different offices around the country and, and they just raised an $850 million fund focused on trying to invest in specifically Portland, Seattle, Los Angeles, and here in Denver. Yeah.
And not only that, their focus is on lower middle market companies, those that are $25 million to $300 million. And they also focus in some specific areas as well. They're not looking at all kinds of companies. Food and consumer companies, healthcare, technology and business services, and industrials. Yeah, it was an interesting article to read.
They had the guy who's the partner in— that's located here in Denver as the interview subject for this. They asked him, what are your plans for the new $850 million? A couple— I found this interesting. It takes 4 to 5 years to invest a fund like that initially. So it's going to take them a while to get that $850 million deployed.
Uh, they end up holding companies longer than most private equities. Uh, maybe they're, they're like 7+ years, uh, for holding. And the number of companies they're going to invest in ranges from 10 to 15, um, just kind of depending on how big an opportunity there is at each company. Pretty cool. Um, you know, I think one of the, the cool parts about that is that they are focused specifically, uh, in Denver.
And one of the reasons why they said that they chose for that, um, as well as the other sort of Northwest areas, is that you know, the previous lack of, uh, this type of capital in the area. And so they saw a real market for that there. Yeah, I love seeing that money be available in these areas. It just, it gives us more jobs, it gives us more companies, more interesting storylines. So, you know, more money here the better.
Yep. Next, uh, Palantir, which of course moved to Denver not too long ago, has launched an initiative to support new early-stage startups. Yeah, I read this and I read it maybe twice, maybe 3 times, because I didn't really get exactly what, what they're doing here. Yeah. So there's— so they have a thing they call Foundry for, for builders, and it's the Palantir Foundry.
It looks to me like it's a platform on which you can build your own application. Correct. Like, maybe think of like a Splunk app where you have access to Splunk's capabilities as a part of it. Um, but are you, as a part of that with, with Foundry, do you get access to, to data other than your own? Or is it just like they're, you're building a framework to, to code?
I, I don't, I don't know that I really got the value prop for this. Yeah. I, um, I didn't, uh, see that either, but my thinking was that, you know, Palantir is a big data company, right? That their whole point is to have this platform that can manage a whole bunch of data and get insights out of it. And so, um, I think that they're trying to get more people to put data into their platform.
And so if they have these startups, um, that, you know, don't want to build that backend part of the platform, the data part of it, they can just build on top of the Palantir platform. Palantir wins by people using that platform. Um, the startups win by not having to build that part of it. So I think, you know, kind of a symbiotic relationship there. But, uh, yeah, I didn't see also whether you get access to other data.
I wouldn't think that you would, but I don't know. Yeah, I wouldn't either. In which case, I wonder why would you use Palantir? Why wouldn't you you use one of the many other frameworks to build this on. Well, I think that that part of it is this program that they're doing.
My guess is that because it's the startup version, they're making it cheaper for, you know, more attractive for startups to use. I do, you know, from the Palantir perspective and why it's so valuable for them is generally their customer base is all like very large, you know, right? Big federal government contracts, big org— big private companies as well. This gives them a whole brand new market where they're going to get startups and, and, you know, hopefully grow this, this market along with themselves and really help them find new opportunities for revenue. They do have a list of a handful of companies that are already a part of it.
It looks like it started off like all of the first wave of companies doing this Founders Program are alumni from Palantir who've moved on to do a new company. Yeah, and, um, I remember when Palantir moved and they were talking about you know, some of the financials, and there was some very small number of their companies— customers, excuse me— that made up a large percentage of their revenue. So I can see from their perspective why getting these other companies into the platform would be super useful for them. Now that you say that, I remember that article as well. All right, moving on.
Next, the NCC has announced that they are going to be providing some adult education classes starting in September. You know, every once in a while I forget that we have the National Cybersecurity Center just down the road. So these articles are great for, for me to not only remember, but also kind of see what are they up to, because it is, it is really cool that they're there. They don't make a ton of news that I hear on a regular basis, but nice to see there's a new education program coming out there. This particular one looks especially interesting because I think it's really targeted for someone who's a career changer.
It's not It's not like, hey, you're a security person, but you need to go add a cert to it. It's, uh, you know, starting off with the, the certification for IT Fundamentals. And then, you know, as, as you— if you work quickly enough, you're able to then go into the secure— the, what is it, the second certification, which is the Security Professional. And then on top of that, uh, if you do that well and go quickly, uh, there's an opportunity to do an apprenticeship as a part of this. So, you know, you can really go from, you know, being out of the IT professional altogether to being an apprentice security person relatively quickly.
Yeah. And when I was first reading this, I was a little bit confused because me reading the headline, I was thinking, oh, they're providing this as education to the general public to help people be more cyber aware, or, you know, things like that. And then we got to that last part where it talked about the apprenticeships. And I was like, oh, well, that's a different angle that I hadn't really thought of. So it is interesting to see.
I'm curious how many people are going to go for this. More just for an educational perspective versus, uh, trying to make a career change, right? Well, hopefully lots of career changers because we could use more talent in the security industry. That is true. All right, moving forward, uh, we have some really cool news from, uh, about local company CyberGRX.
Fred Kneipp, who's the CEO and founder over there, was named by Ernst Young as one of their, uh, what do they call it, Entrepreneur of the Years, which is It's a pretty nice competition that they do. He got it for the Mountain Desert region. There's a panel that votes on what entrepreneurs should be recognized based on some criteria that they go into in this article that I'm not going to go into right now. But Fred was recognized and there's a profile here about kind of who he is and what he's been up to. Yeah.
You know, this is a competition that happens— excuse me— every year. And, you know, we see these come across through the Business Journal every year. I think most of the time it's folks that we're not interested in, so it's interesting to see CyberGX and Fred be in there, and so congrats to them. Good stuff. All right, moving on.
We have a blog from Coalfire talking about the strategic parts of data privacy and 4 questions that you can ask around data privacy strategy. And I think these are 4 questions that you ask at the beginning. These are not like, hey, I've got a program, right? Because they're relatively entry-level questions. Number 1, who owns privacy at your organization?
Number 2, how do your customers view your data, your company's data collection practices? How do your competitors talk about privacy? And at what point is privacy first considered in your business and product lifestyle— lifecycle, not lifestyle, the lifestyle of your product? So yeah, I think these are questions that you ask when you're thinking about, do I need to make a privacy program at my organization? Yeah, I mean, obviously really important questions to have good answers for.
If you do have a program and you can't answer those questions, well, there you go, maybe add it. I could imagine someone with a program who hasn't really looked at their competitors and how their competitors are handling it. It's probably a good thing to know. Your board would probably be curious. Yeah, for sure.
All right, uh, moving into some personnel news. Uh, we've got a couple big announcements on that front this year, this week. Uh, first, Debbi Blyth, who has been CISO for the state of Colorado for, well, like 7 years now. Yeah, I think about 7 years. Um, has announced that she is leaving that position, uh, to go back, uh, away from government and, uh, and do something else.
And so now that, that position is open. Yeah. So, so Debbi, uh, just an amazing member of the community. I think she's done a fantastic job serving us for as long as she has. She has announced that she's moving to the private sector.
Yes, from the public to the private. But for a public company. And has she announced officially where she's going?
I know that I know, but I don't know if she announced it. Yeah, we'll have to circle back and see if that's public information. But really happy for Debbi. Uh, who's, who's spent just a long time serving us in this way. Thank you, Debbi, for all you've done.
We've had her on the show at least 3 times, I'm pretty sure. Yeah. Because she did 2 interviews on her own and she was also part of the panel that we, we broadcast, um, here on the show as well. Well, and we did, we broadcast, uh, her interview at RMISC. That's what I was thinking of.
Yeah. Yeah. That we did. Okay. Yeah.
Yeah. Um, Debbi obviously is wonderful. She has done a great job for the state of Colorado, really moving that program forward. And I think, you know, also just the amount of time that she spent in that position. You know, these types of positions are often much shorter.
You know, you come in with an administration, you leave at the end of an administration. And I think having someone in that position for 7 years is a really great benefit to the state. Well, I mean, before Debbi, I think it was mostly 1 to 2 years. And it was— was it directly before her was Jonathan Troll and Yeah, I think so. And we had Travis Shaq for a year or two, and yep, uh, uh, Seth Kulikov.
We had a number of folks who, who were there for a year or two, but Debbi's really added some, some stability. And I can't imagine that that's anything but really positive for a team to have that. Yeah, that solid vision going forward. Yeah, I mean, and while it is a high-profile position, to be fair, you are making a sacrifice, uh, being in that position. You're not getting paid the standard rate that you would get if you were in this, uh, this position for a public company.
Yeah. Uh, or excuse me, in a private company. I did the opposite again there. Um, so, uh, again, a whole bunch of thanks to Debbi. Great job.
Uh, look forward to seeing what you're doing next. And then, uh, finally, we have an announcement from Red Canary. Uh, Robb, do you want me to read the announcement or do you want to read the announcement? Well, I'll go ahead to share it. You know, I've, I've started as the Chief Trust Officer for Red Canary.
Uh, so this is The link in here is to the press release announcing that, you know, kind of officially as of this week, working full-time over there. I've been helping out over the summer as well, but super excited to be there. You know, as you know, Alex, Red Canary had Brian on the show as a guest host recently. Like, they're just a big part of the Colorado security community, just a fantastic group of people with a great mission. I'm really excited to be over there.
Chief Trust Officer means I'm— we're really taking a look at not only security, but privacy and compliance and business practices and making sure that we're doing these things in a way that is going to build trust with our customers. How do you build trust? Well, by being trustworthy. So that's my vision, is to make sure we're doing the right stuff in all those areas across the board. So lots more to come.
Well, if they're looking for trustworthiness, clearly you are the wrong person for the job, but I guess they hired you anyway. I'm going to edit that out. No one will ever hear what Alex just said. Congratulations, Robb. Wonderful.
I'm completely shocked by this news. I had no idea. Yeah, I've been keeping it secret from you pretty effectively. So you'll start to see postings from Red Canary in the jobs area. I have lots of jobs we're going to be filling.
Awesome. All right. That is the end of the news. Let's move over to the Slack message of the week. Thanks to Andre Gaeta for supporting this initiative that we've had.
Um, you know, get trying to get people into Slack and talking and highlighting all the great things that are happening in there. Uh, so we pick one message from Slack every week, um, mostly every week now. Um, and, uh, that person wins a piece of swag from the Colorado Equal Security store. Hey, Robb, did you know we have a store? If you go to the website, you can buy stuff there.
Like we're all outfitted head to toe in Colorado Equal Security stuff right now. Exactly. Even my nail polish.
You just swipe it on and there's the logo. There's the logo. So thanks to Andre for doing that. We appreciate it, him for doing that. He's been doing this for an awfully long time.
He pays for it out of his own pocket. So Robb, who is the winner this week? This week's winner is Jacob Rubin. Jacob broke the news about the pretty significant GDPR fine that Amazon was hit with, $888 million. I imagine that this was just a round, nice round number that they wanted.
It was a pretty number. I don't know how they got that exactly, but, um, but Jacob let us know about that and he gets recognized for bringing that news and also for taking a little bit of guff from me, uh, in, in the, the thread in there where I suggested that, uh, well, you might want to take a look at it. Yeah, we'll leave it there. Jacob, thanks for your part of the, of the community. Awesome.
So we will, uh, connect Jacob and Andre and he'll get one of those things from the Colorado Equal Security Store. Good stuff. All right, let's jump over to the calendar of events. I feel like a few weeks ago, there was hardly anything on the calendar. And right now it's really filling up.
I went through and spent some time going through all the different sites to find all the events and people are really getting back together again. I will say there's not a lot this week. But that is probably because everything is happening in Las Vegas this week. But starting the week after that, we have a few things. Yeah.
So on the 11th, there's 2 items. We have the ISSA Denver August chapter meeting. And also SecureSet, they're getting back into doing events. Nice. They have a Hacking the Cybersecurity Job Market in-person event.
Cool. Uh, and then the last event for that week, uh, we have a Measuring Your Software Security Program on the 13th. Is this one of, uh, Dustin's? One of Dustin's groups? Yeah, they don't have a name for the group.
It's really tough. Yeah, they're the application security meetup group. Yeah, good stuff. Uh, that measuring your software security program looks like a really good, um, meeting. Yeah.
All right, stuff. Let's jump over to jobs. Jump over to jobs. Hey, let me talk about some Red Canary jobs. Uh, we are hiring a director of product security.
This is, uh, gonna help head all of the application security assurance stuff, and it's really like a DevOps method. So you're really getting from architecture all the way to operations, um, and helping run a team to do that. Also hiring a program manager focused on trust This is kind of your, your, the person who's gonna help me run both security, privacy, compliance, all that stuff, and gotta be a right-hand person for me. And last job for Red Canary, we're hiring a product security engineer. So if you're a developer with a security bent, we'd love to talk to you.
Awesome. Coalfire is looking for a director for strategy, privacy, and risk advisory in healthcare. Love it. See Coalfire hiring. Western Governors University is hiring an application security engineer.
Oh, that's interesting. Uh, Trimble is looking for a cybersecurity risk analyst. Western Union's hiring a cloud cybersecurity senior engineer. Premier Members Credit Union is looking for an AVP of information security, and I feel like this one's kind of been hanging out there for a little while. I agree with you.
IHS Markit is hiring a compliance manager. Crocs is looking for a senior manager for IT security. And finally, Guild Education, one of the sweethearts of the tech scene here in Colorado, They are hiring a senior security engineer. Nice. You could go work for Julie Cicillo over there.
Yeah, I think that would be a lot of fun. All right, well, that is it for the, the news this week. We do have an interview. Um, Janelle Hsia sat down with Chris Stolley. Um, so, you know, I know we've, we've both known Chris for a long time.
He was my first sales rep from Acuvant in like 2003, maybe. Um, I bought the Aventail SSL VPN from him and the, uh, Airspace Wi-Fi system, which ended up being acquired by Cisco and turned into the Cisco, um, Wi-Fi stuff. Anyway, so Chris was like a really early employee at Acuvant, ended up, uh, somewhere along the way like becoming a senior vice president of partnerships, and now he's the chief revenue officer for a new company called Security Mentor. Nice. Yeah, and, uh, I haven't heard the, uh, the company Aventail in a while, so it's a nice trip down memory lane there, Robb.
SSL VPN, baby. Yeah. All right, well, that is it for, uh, for us this week. We'll look forward to catching up with you guys all next week. Thanks, Robb.
Hi, this is Mary Haynes, VP of Network Security at Charter Communications. Welcome to Colorado Eco Security. For Colorado security professionals, by Colorado security professionals. Welcome to Colorado Equals Security. This is Janelle.
Today I'm excited to interview Chris Stolley. Chris is a longtime member of the security community here in Colorado, and so I hope you enjoy our conversation. Chris is the Chief Revenue Officer at Security Advisor, which is a personalized security awareness platform. Hi, Chris. Welcome to the podcast.
Thanks, Janelle. It's great to be here. Really looking forward to our conversation today. Me too, and I should turn off my cell phone. There we go.
So how are you doing today? I heard you just came back from Cabo. Yes, it was really great to get out and actually have a real vacation since, uh, you know, we've been locked down. Yeah, and sorry about that background noise, the dog just barked upstairs. That's what we call live broadcasting, right?
So no worries. Yes. Well, so tell me a little bit about yourself. Who's Chris Stolley? Well, great.
Um, you know, Chris Stolley. I've been, uh, you know, I'm a Colorado native, been here in Denver my whole life, and joined in the security community a little over 20 years ago. Um, you know, a couple of different resellers and, um, as a salesperson, and I worked in the community and building out different sales organizations, and I've been doing that for the last 20 years. I just said. Awesome.
So what brought you to the security industry? You said you were part of a reseller, so, but what's— what about security specifically? You know, it was interesting. So back in 2000, um, I was working for a networking company and we were selling, um, you know, different networking solutions. And we started selling NetScreen firewalls at the time, and it just sounded a lot more interesting to me to have a unique story to tell But also, you know, to help people solve different problems.
And, you know, just more ports and faster ports just wasn't as exciting. And when you got to start talking about different problems like, you know, firewalling, or, you know, back then it was, you know, web filtering, you know, users were doing, uh, you know, bad things on the internet. Like, how do you solve these problems and work with the customers to solve that? So that was interesting to me. And I, um, you know, from there just started paying more attention to the security vendors.
And so I know that, you know, you said you came from that security vendor space, um, and I think a lot of people here are familiar with Optiv and some phish tech companies. Um, so can you tell us a little bit about those companies? Yeah, absolutely. So I did, uh, spend almost 17 years at Optiv. So I joined, um, Acuvant back in 2004.
I was one of the first salespeople in Denver at AccuVant. And, you know, I spent my career doing that, 5 years as a sales rep. And then, you know, I grew up with the company, became a regional director, and then an area vice president, and was responsible for, you know, a third of the revenue. And, and then that's when AccuVant merged with Fishnet. And, you know, we did that to kind of build, you know, a behemoth security partner for our customers because the challenges were getting more and more complex. And we thought, you know, combined we could do better to help our clients become more secure.
And we really wanted to, you know, invest more in services and, you know, not just be the reseller. So we thought we could do that with the combined power. And so that's the background of kind of how Acuvant and Fishnet came together too. And I, you know, and I left Optiv just less than a year ago, actually. I left them back in September.
Yeah. And so one of the questions I had, I had actually opened it up to the community for questions to ask you. And one of the questions was, why wasn't Optiv named AccuFish?
That was, that's a funny question. We got asked that question a lot back in 2015. What were we going to be named? And really it was about bringing the 2 companies together and making a better organization. And we just thought there might be some, you know, animosity between the organizations, because we were really kind of the 2 biggest competitors.
And we were kind of archenemies in the space. And the CEO, Dan Burns, just felt, hey, let's go out there, create a brand new brand, have everybody work together under that new brand, and go to market that way. And that was really— it was his idea and his drive. To make that happen. Yeah, and it absolutely obviously worked really well.
Yeah, um, you know, it was— I always used to say it would have been easier if we just picked one name because then you wouldn't have to explain people who we were, right? Because people would be like, I've never heard of you. But, you know, since then, um, it's, it's turned out pretty well. Yeah, for sure. Um, and as you mentioned, you just moved to securityadvisor.io.
Um, so what was the pivot? What was the, um, attraction to Security Advisor? So, um, you know, as I left Optiv after almost 17 years, I wanted to do something a little bit different. And I knew that kind of the, you know, the OEM or, you know, the software side, vendor side as we called it, was where I wanted to go, uh, try my hand for a while. And, um, I was looking at all kinds of different, um, companies and, you know, I knew some of the VCs from, you know, some different working within Optiv and some of the VCs that would bring new solutions to Optiv.
And when, um, one of the VCs introduced me to Security Advisor and they were looking for somebody to lead sales, number one, I kind of wanted to, you know, lead sales again. Um, and my last job at Optiv, I wasn't quite doing that. I was running partnerships. But, um, I thought that was interesting. And then when they told me what they were doing, I'll be honest, They said security awareness training, and I said, oh yeah, nobody likes security awareness training.
It's not interesting and nobody pays attention, right? So it's probably, you know, a low-cost, cheap, um, you know, everybody tries to get in cheap and they just provide content that people put on the background and they don't pay attention to. So then I spoke with the CEO and, you know, the co-founder, um, and they started telling me what they really did. And it, you know, piqued my interest because if you can change and actually have an impact, that was interesting to me. Yeah, absolutely.
And I have to say that your reaction would have been mine too, where security awareness training is not sexy. No. And it's more of a check. It's one of my passion areas too, because I do believe you have to change the culture. And in order to do that, you need that awareness.
But it's— I mean, most people see it as a check-the-box exercise. So how do they go from that check-the-box exercise to like bringing you something that's super exciting to work on? Yeah, so, you know, most people are looking at it as check the box, but what Security Advisor does is we integrate with existing security technologies. This is the key unique differentiator for us, and we identify the detections and the incidents that come out of these tools. That, you know, everybody has.
And when we see these detections, we've created a, you know, kind of an algorithm, a patented, you know, machine learning that identifies what the detection was, and we pop up a relevant piece of information to the user in real time or near real time. We send them an email that says, you just clicked on this, you did that, or we could do it in Teams or Slack messages too. And when you can do something in real time, I think most people nod and go, oh, that's smart, right? Can tap them on the shoulder. And that's where the name of the company came from.
We're a security advisor, right? You're next to the user, trying to give them direction as they go through their day. And that was interesting to me. And I think the real challenge was, how do we— and this is the exciting part of being in sales and, you know, marketing— is how do we get people to listen to that story? Because it is unique enough, and we get to go craft the message, build a story out for people and then, you know, watch it, uh, watch it take off.
And that's kind of fun. And so you said that you're leading the sales, um, initiative there. So do you have a sales team right now? Um, I do. It's actually only, um, 3 individuals.
And then, uh, marketing is only 1 individual right now. Um, we're only 3 years old. We've been selling for a year and a half. Um, but my sales team is, um, 2 salespeople, and then we have a, a really unique person that has joined our team, um, Christina Susek. Um, she was leading, um, executive education at, um, Berkeley, and, um, you know, she joined our team because, you know, we are a learning company too, and, you know, we wanted her to— we wanted to have a perspective in the market of how people are learning, how they're changing their learning.
So we brought Christina on and she's kind of in this unique role of kind of our Chief Customer Experience Officer, Chief Learning Officer, but also, you know, in a small startup, everybody wears multiple hats and she's wearing a sales hat as well. And she's got some really cool unique relationships from her time at UC Berkeley as well. Yeah, I think that that for me too would be another differentiator, right? That executive education background, because I think most security awareness that I've seen has been written by security people. Um, and so if Christina can bring in that, you know, more— um, I don't want to say necessarily professional, but that different angle— maybe that will definitely help with those, um, you know, tapping people on the shoulder pieces.
Is there, is there anything specific that she's done recently that you want to talk about? You know, she's, um, you know, her— she's been part of kind of, uh, some of our processes working with customers and asking them how— what they're looking for in the tool, kind of chief customer experience officer kind of thing. But then working with some of her, um, you know, former colleagues at Berkeley to just kind of get some information and knowledge around how people are learning and then bringing that back to us so we can input that into the tool and kind of build new, new ways of coaching users. So that's one of the things she's done, and it's pretty unique being able to have her on the, on the team. That's awesome.
So I talk about teachable moments, right? And so it sounds like, yeah, you're taking what I would say is a teachable moment as a privacy and security officer, and you're automating that. Absolutely. As a matter of fact, we use the term teachable moments all the time in our organization. That's what we really kind of want to call them, right?
And we use, you know, the term nudges too, because we want it to be micro-content. Because, you know, if you go, hey, here's your teachable moment, now you have to go 30 minutes of training, that's not really going to do it. But, you know, doing it in this nudging micro-content learning, and that's, you know, another thing that we've learned is that's how people want to learn. And/or they learn best. Yeah, I know, I would agree.
And I think nobody has time for 30 minutes of training anymore. No, they have their full-time day, their day jobs, right? And if they just did something wrong and you say click here to do a 20-minute training or 30-minute training or even 10-minute training, they're going to put that off and they're going to put it in their, you know, to-do folder and they'll get to it later. Yeah, so another question that came from the community is, what is the average time it takes to train users to be aware of security issues and become security advocates? Do you know that?
So, you know, that's a really unique question because it really changes. I think you need to actually affect the cyber culture of the organization or the overall culture of the organization, but, you know, there's some people that automatically get it, you know, they pay attention. They're learning, and then there's others that don't. So what we found through some of our research is, you know, 5 to 10% of users are responsible for 80 to 90% of the problems in the organization. So those are the ones that are just not getting it.
At least they're not getting it through the traditional methods, right? They're not there to be the security advocate or the security proponent. They're an employee, they're in finance or whatever, you know, our job is to help them understand that security is part of their role. And, you know, we're just one component of that, right? I think it has to come from the organization as a whole to invest in tools like this, and even more, you know, just coaching and just general awareness that, hey, security is everyone's responsibility.
Yeah, absolutely. And going back to that, the fact that it's generally like just a small percentage of the population that cause the biggest problems, is there at some point that you say, you know, we'll say, Bob, you know, you have clicked on the link every single time that we have sent you a simulated phishing attack, and at some point that that becomes like a fireable offense? Do you ever see that in the future? I do see that in the future because that question has come up recently in 3 different customer conversations. One CISO just recently told me that his CIO has a 3 clicks and you're out policy.
He doesn't care who it is, especially in the IT organization, right? You can't make that mistake in the IT organization. Another, uh, another prospect asked me if we are starting to see that because their, um, CEO has mentioned that maybe we need to start firing people. And so you're starting to hear it, um, but there's only that one case where I've heard that they actually do it. Yeah, that, that's great.
3 strikes or 3 clicks and you're out. I think I like that a lot. Uh, I think all security professionals like that a lot. You know, what's interesting is, um, there are a handful of other organizations that are doing things where, um, you know, they're creating, um, you know, privileged groups within their Active Directory. And depending on your privilege and your risk score— and we can give people risk scores based on their behavior— they, they're going to say, well, this risk score, you get these, uh, this level of access to this type of data or to the internet, for example.
And they're doing that and they're saying, okay, well, you failed, you go back into this lower level of privilege and you can't get access to certain things. So that's interesting because if they can't get access to it, maybe they can't do their job then. So I mean, what's the consequence of not, you know, not having access to data to do your job because you failed the security requirements? Right, absolutely right. So it is getting, um, you know, interesting.
And with But people are starting to take this seriously. I think a lot of people for a long time have said, we keep buying security tools to solve this problem, you know, defense in depth. We've been doing defense in depth for, you know, over 20 years now. And I used to be, you know, an advocate of like, hey, defense in depth, because users are going to keep making mistakes. We're never going to teach them all.
They're not listening. And, you know, their full-time job is finance or whatever. But people are starting to take note that we have to do something differently. And, you know, trying to engage users and make them part of the security, you know, part of the security stack or the human firewall is something we have to do. So, you know, that's why some of these people are being a little more strict and maybe having repercussions or consequences to their actions.
Yeah, no, I agree. I mean, I think we all know that, you know, people are either our greatest weakness because they're clicking on everything, or if we can train them, they can become our greatest strength, right? Right. Yeah, absolutely. So you mentioned something kind of along the lines of, you know, you were, you know, using the security tools that you already have, probably like endpoint detection and some logging and monitoring.
And so, you know, I think employees may not know that they're always being monitored through these tools, but it seems like you're bringing some awareness to that by the fact that if I just did something and you send me an email saying, don't do that again, they can kind of maybe connect the dots a little bit easier. Are you finding any tension with that particular component of the training? You know, that is true. I think some people are not aware that, you know, there are tools monitoring their behavior, but You know, UEBA, you know, has been around for a while, and we are doing behavior analytics and user behavior analytics. But yeah, there's been some people that have asked the question like, are you Big Brother?
You're watching me. And, you know, we're, we're watching for the bad behaviors and we're trying to coach and advise. But it does make people aware that there is somebody on their shoulder are looking over their shoulder. Yeah, and I think I like how you phrase that. You're watching for those bad behaviors, right?
Um, yeah. And so, yeah, I mean, is that— are you finding in that sales cycle, like if you put on your sales hat, that that's something that you have to coach, um, your purchase— the people who are purchasing the product through that idea that you're not Big Brother, or that you, you may be, but you have a good— you have good intentions as Big Brother? You know what, I would say most of the people we're engaging with are, you know, they're definitely security professionals and they want to improve the security posture of their organization, and they know they have to engage the users, and they just haven't been able to directly engage users outside of, you know, traditional security awareness training or phishing simulations. So they're looking at our tool as a way to, you know, kind of that engagement tool from the SOC to the user. How do I— I'm now the security person, now I have a tool I can engage the user in a way to help them be better.
So yeah, there's the occasional question about Big Brother, but for the most part, everybody sees it as kind of this engagement opportunity, engagement tool. And then what tools do you integrate with right now? So, um, you know, EDR tools, endpoints are, are great data, right? They give us a lot of rich data on detections around ransomware, malware, other things that, you know, clicks that people are doing. And so, uh, CrowdStrike's a key, um, partner of ours.
We're in the CrowdStrike store, but Carbon Black, SentinelOne, um, you know, even Sophos and Malwarebytes are endpoint tools that we integrate with. And, you know, the traditionals, um, you know, McAfee and others. And, um, but the real-time APIs where we can do it in real time without batching logs and getting those logs, those real-time APIs— CrowdStrike, Carbon Black, SentinelOne. And then we also integrate with, you know, web gateways are a great, um, place for us to get real rich data too. You know, what are, uh, users doing when they're surfing?
Are they downloading a, um, you know, are they downloading uh, you know, Chrome, uh, links, or are they doing something, um, you know, weird on the internet? And, you know, most people, when we talk about like, oh, they went to adult content, they're like, oh well, you know, we blocked that, that's fine. Um, but do you want to send them a note says we block it for this reason, right? Um, or you went to a risky website, this website is known to be, you know, host bad stuff, right? Most people just block that, but you can send them a note that says, this is why we block that stuff.
Um, those are some of the rich ones. And then the email, you know, email gateways are, uh, key integrations for us too. Yeah, and I think I'd be remiss, you know, putting on my privacy hat with, you know, with all of that rich data that you have, if I didn't ask the question about it being personal data, right? Um, And so with GDPR being a regulation that is so specific about personal data and the monitoring of employees, how are you handling the European customer base? Yeah, so that is a little trickier, right?
But we're not really pulling personal data. We have the user information, who the user is, and the detections— what are they doing. So we really— the intent is to use that to coach the user. So Yes, it kind of is personal information depending, you know, with your privacy hat. But what we found is, you know, if there's no consequences to the action— this, we've run this up to a few customers and they will get involved with their works council in Germany and decide what they're looking for and say, okay, well, if you're just using this information to coach the user and actually better secure data, that's fine.
Right? But if you're taking this and you're giving everybody a risk score, and then people below this risk score and you're going to fire them or punish them, that's a problem in those European Union countries, mostly Germany, where they're a little more strict. But so far, you know, it is a question we have to answer on a regular basis. But what we've seen is if you're coaching the users and you're using to better secure data, that's been approved, but you have to be a little bit trickier on, you know, do you want to risk— provide those risk scores like I just said? Yeah, absolutely.
And I think for me too, um, I know in Europe the, the notifications that employees get about the type of activities that employers do is greater, right? So there's an— there's this whole idea of an employee notice. So do you think that having that employee notice at the very beginning So that employees are kind of told to be on their best behavior is also part of the, you know, the human firewall. It is, absolutely. As a matter of fact, you know, even with our POCs where we've helped some of our customers craft out, you know, information for the small group that is going to be included in the POC so they can see how the tool sends out, you know, the alerts.
Etc. So we, we tell them, here's what we're doing, here's why we're doing it, and here's the type of information. So depending on the organization, they might want to be, you know, more informative or less informative, but it's something we've kind of given our prospects as a tool to engage users. Yeah, I think transparency, you know, just in general from a privacy perspective is really good for users to understand that this data is being collected, and then, as you said, why it's being used. So having that transparency.
Yeah. Well, I think since you've been in the field for so long, what have you seen changed in the last 20 years? Oh, wow. That's a great question.
The fact that I started selling firewalls back in 2000, and I would call in customers, and they'd say, why do I need a firewall? Right? Um, so that was interesting. And I'm like, how am I ever gonna, like, you know, convince these people that they're at risk? And, you know, they have antivirus.
They— now I'm trying to talk them into a firewall, um, or, or other tools. Like, you know, back in the day, you know, I mentioned URL filtering. Hey, you want to keep people from, you know— and, you know, we became kind of— it was I would say, you know, trying to sell insurance, like, hey, you don't want something bad to happen to you, you have to buy all these tools. And now there's been just a lot more visibility on the whole security market and defense in depth. I mean, when I first started, nobody was doing defense in depth, right?
It was just a couple of tools here and there. So really starting to address, you know, defense in depth, but building out programs. You know, nobody had programs back then. It was kind of, whack-a-mole. What's the latest problem?
How are we going to solve it? And just over the last 10 years, really kind of helping, you know, organizations build out a program that, you know, what is your chief risk? How are you going to address that risk? What is the likelihood of that happening to you? And building out that program and being able to manage to something bigger.
So, you know, you know, kind of where to put your investments instead of trying to do the whack-a-mole stuff. Yeah, I think that's, that's right, right? We have to build a privacy program and then we can actually see how much we're making progress, right? Yeah, no, I like that a lot. And then we also talk a lot about burnout in this industry, you know, again.
And so drawing on your 20 years of experience, what have you done to help yourself not burn out and maybe your teams not burn out? Well, you know, what's interesting is, you know, after almost 17 years at Optiv, you know, the Zoom culture with COVID really kind of got to a lot of people, right? And I was at a stage where I had an opportunity to, you know, leave Optiv, but it was, you know, good timing because it was getting bad. You know, a lot of, you know, 10, 11 hours a day back to back on Zoom. And What you have to do is you have to find that time.
And, you know, I even, for my team now, we schedule 25-minute meetings instead of, you know, hour-long meetings, 45-minute meetings, etc. But, you know, like I said, I just got back from Cabo. Really encourage people to take the time, right, and take time away. And we need to, you know, we're, we're human, and, uh, the burnout has gotten pretty bad, especially on this work-from-home culture when your commute is from your bedroom to your office. And that just made it really challenging, I think, and you got to encourage people to get away.
So do you find the culture at the startup, you know, obviously you've got, you know, I don't know how many employees Optiv had, you know, hundreds, maybe tens of thousands versus, you know, a handful at a startup, right? So, you know, can you control that culture a little bit more? At that startup company? Oh, absolutely. You know, Optiv, I think, was up to 2,500 employees when I left.
And, you know, and depending on what was going on, you know, trying to just schedule a call, you needed these people on the call, that was hard because everybody's busy every day. It's a little easier to get access to everybody, and you can also cut to the chase real quick, and you don't have to have the longer meetings. And, you know what, all 3 of our founders came from McAfee, and they were there when Intel was there. And they've kind of implemented a culture for, of like fewer meetings, more, more IM. And they're just like, we're not going to have meetings for meetings' sakes.
You know, if there's something you need to say, can't get it in an IM, just a quick phone call. So that's, I think that helps with the burnout. You can get things done a lot quicker and you can make decisions quicker. So that's helpful. Yeah, and then sometimes, um, we talk about giving back as well, so volunteering and things that we do for the community.
Is there anything that either you or Security Advisors does from a giving back perspective? You know, um, we haven't done a whole lot yet, um, you know, because we're still small, we're in startup mode, um, but one of the things we've done is actually— this is through, uh, I mentioned Christina earlier Through her relationship, she's associated with an organization called TechSoup. And TechSoup is an organization, it's kind of like an IT reseller for nonprofits. So what they do is they go out to a lot of different software organizations, software companies, sorry, and they negotiate terms for like a group of nonprofits. And they get really good deals and, you know, help them with their corporate responsibility initiatives.
And then they make those deals available to small nonprofits. And so we just signed a deal with them at a super duper reduced rate to make security awareness training available to these nonprofits. So when you— that's huge, right? Like, I— the nonprofits have no budget. And so if we can make the human firewall at our nonprofits, because I think for most of us, we feel the worst when they're the ones that get hit.
Right? Yeah, they're trying to do these good things and then the bad guys don't care. So that's, that's not little, that's huge, right? And if you think some of these nonprofits, they probably have a lot of donor information and other stuff, right? So we have to help them understand, you know, where the risk is and how to protect the data better.
Yeah, absolutely. Well, so we're almost out of time. Is there anything we didn't talk about or anything that I didn't ask you before we wrap up? You know, um, I can't really think of anything. I mean, it's been a great conversation.
Um, you know, I, I know, um, I'd love to be more involved in the community, and I think now after COVID and etc., and because my last couple of roles at Optiv were a lot more national, so hopefully I get more time to be involved in the, in the local community. That's great. Where can people find you? Um, you can hit me up on, uh, at Chris S— so it's Chris with 2 S's— at securityadvisor.io, or, um, my LinkedIn profile, Chris Stolley. Awesome, that's great.
Well, Chris, it's been really a great pleasure talking with you, so thank you so much. Um, I hope you have a great rest of your day. Thanks, you too, Janelle. Great talking to you. Yep.
Bye. Bye. This is the end of our interview. Until next time, thanks everybody for listening. Bye-bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.