Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.
Welcome to Colorado Equals Security. This is the newscast for episode 240 for the week of October 10th, 2022. Alex, how you doing? I'm good. It seems like fall has fallen finally.
Yeah, it's a little bit chilly. I was in San Francisco for work this week. And when I got off the plane yesterday, wearing my shorts and t-shirt, I was like, whoa, mistake, put on a jacket. Yeah, it's— it is Saturday while we're recording. Last night, went to a kids football game.
And it was chilly. I had to wear a coat and hat and gloves, all that kind of stuff. It's like real fall now. Yeah, I love it. Fall has fallen.
Good stuff. Let's jump into some housekeeping. As a reminder, we have a Slack channel, you can sign up for Slack or get your friends invited to Slack, there's a link out at colorado-security.com. We just want to make sure that the folks who join are, are associated with security and Colorado. While you're there at colorado-security.com, you should sign up for our mailing list.
That's how you can get all of the news that's fit to print about local security here in Colorado. Mostly we send you one email a month, but occasionally we'll talk about things like the picnic we did over the, over the summer or any other new stuff coming up. Uh, if you're listening to this, you're likely listening to it on some sort of podcast player. Uh, in that player or the service that you use, we would love it if you rate us and subscribe so that you get this automatically delivered to that player when we have new episodes. Uh, maybe not quite as important now that we're only doing this monthly, but still would love to have you subscribed.
Uh, also let other people know about Colorado Equal Security, both the podcast and the Slack workspace and the website, all the stuff that's going on so that we can make sure that everyone knows us and that we're spreading the word. We'd also love it if you would be willing to support us financially. We have a Patreon campaign with some, some really fantastic supporters who've been loyal to us for years. If you've been thinking, you know, I should support Colorado Equal Security, this is the right day for you to do it. Why don't you go out there, go to the website, click on Patreon, get signed up.
We would love to, to have you support us financially. And every dollar of that goes back into the community, including, you know, paying for hosting fees and other, other like technical stuff. But then, you know, if we have any excess, like we did through COVID, we put together, you know, community events like the picnic we did. Good stuff. And hopefully we'll have some more of those coming up.
All right. Let's jump into kind of local updates. You know, since we last got together, the big conference, Rocky Mountain Information Security Conference, took place. Alex, can you give us an update there? Yeah.
You know, I think we had a great conference for sure. I've had great feedback from people. We had some wonderful keynotes, lots of great training and speakers there. We were somewhere north of 1,300 people attending, which I think is a great number. Not a record attendance, but I think pretty good for coming out of COVID It was wonderful seeing people in person.
You know, that's one of the best things about conferences is getting to see people and love doing that. So I hear bad news. You have stepped down as the chair for that conference. So it's going to take a horrible turn for the worse. Is that true?
I mean, I'm not saying that I am the one that does all the stuff. But no, I'm just kidding. Yes, I have decided I'm, I'm going to take a little break and not be chair anymore. There's a couple things I think I'm still going to help with. But yes, passing the reins to someone else.
James Johnson, former ISSA president, is going to take over as the ISSA co-chair. Doug Slike, who is on the ISACA side, I think will still be ISACA co-chair for next year. It's in good hands. Things are going to be great still. And The biggest thing is we're going back to our regular schedule.
So we will be back in June next year. So it's a very short runway until the next RMISC. So perfect time for me to duck out when there's a lot of work to do. Yes. Get your talks ready to go.
Get your sponsorship ready to go if you want to be there, because it's coming up soon. All right. The other big event coming up is actually what, next week? The 18th. So the Cloud Security Alliance Colorado Fall Summit is happening, and that looks like a great event as well.
Yeah, I believe the Attorney General is one of the keynote speakers there. I think that will be great. I love him. I think he's a great speaker. Wow, you love him.
I love his— This is a moment here, you two. Politics and the way that he does his job. You know, we are not in love.
I mean, you know, he's a handsome man though, so what can I say? Anyway, he is going to be speaking lots of good talks at CSA. So I think maybe if you want to go, I don't have it on me, but if you reach out to Tyler Warren, who is CSA president, he might even be able to get you a discount code. Yeah. If you jump out to the Slack community, I suspect we can get that for you.
If you're part of the Colorado Equal Security community, that's available. That's it for that stuff. Let's talk about news now. We have some interesting news starting off with some bad news, Alex. Well, also some uninteresting news, but Denver has been named the 4th drunkest city in America.
So, so this is the kind of thing that you expect to get from the hard-hitting news of the Westward. There, there was a, a company called Clever that did just a, some analysis of all the different countries, or excuse me, all the different cities in the country, measuring on 6 different categories to say what's, what's the drunkest city. So included number of bars, number of breweries, The, uh, gosh, I don't have the list of all the stuff they measured on. There was one where it was their, you know, people, their web searching for things like happy hour and other stuff like that, certain terms that they were looking for. Yeah.
So Denver came in 4th. Yeah. Um, we actually, you know, we came in for, for a number of bars and breweries per 100,000 people. Uh, we came in quite a bit above the, the national average. National average is, is 18.4.
So once again, this is number of bars, breweries, or wine bars per 100,000 people. 18.4 is the national average. We came in at 28.5, but that's not anywhere near the most in the country. Yeah. Las Vegas was number one.
This should— I think it was New Orleans. Oh, wait, sorry. New Orleans. New Orleans was number one. Sorry.
New Orleans. And yes, that, that should not shock anyone there. What's, what's nuts though is, you know, I mentioned that national average is 18. Denver's at 28. New Orleans is at 57.
Like, like, sit, hold my beer, everybody. Right. All right. So top rest of the top 5 rounds out. I, I was a little bit surprised by number 1.
Number 1 is Milwaukee, Wisconsin. I mean, yeah, it's, I guess it's a little bit shocking. I would've guessed New Orleans or Vegas. There's a lot of drunk people in Milwaukee. Uh, number 2 is New Orleans.
Number 3 is Portland. I know it's a beer place. I didn't really think of it as being the drunkest city. Uh, obviously, like we said, number 4 is Denver and then complete surprise to me, number 5, Providence, Rhode Island. Oh yeah, that's a bit of a surprise too.
I don't know where Las Vegas came up in my mind, but anyway, you know, it's good to know that we enjoy our alcohol here in Denver. All right. Moving on to our next story. Another piece of hard-hitting news. You know, Colorado has digital IDs that you can use in the My Colorado app, and now you can put affinity icons onto your digital ID.
So when I first saw this, I said, what in the world? And, and then I figured out what it was and now I say, what in the world? All right. So you guys, hopefully you've all installed the My Colorado app by now. If you had a bad first experience with it 2 or 3 years ago when it came out, it actually is a lot better now.
It was all Ping's fault. It was, it was a, it was an app that was not quite fully baked when they rolled it out. But it is, it is a much better app right now. And anyway, you can do lots of cool stuff on there. Not only can you have a digital version of your license, which you're allowed to use in like with Denver City Police.
I think most of Colorado Highway Patrol in Colorado, it is, it is an official ID. You can go to a bar with it and stuff. You can do that. But you can also like check your vaccines are on there. Now you can see fishing licenses, registration for your cars, all kinds of cool stuff.
Anyway, on your driver's license on there, it's a— they show a digital version, a picture of your driver's license on the back. You can add a little affinity icon to say what you're a fan of. Right. So it could be fishing, it could be skiing, it could be other Colorado-related things. So, you know, if that is important to you to, to show that the group that you, you are in, then go ahead and go for it.
So this is my question for you, Alex. Which affinity icon have you added to your license? You know, I added the best one, which is none. I— you want to see what I've got? I've got it right there.
I've got the little peak. I've got the— I like it— the little mountain peak that I've added to mine. And I have switched it a couple of times just to see what they all look like. So you like to switch it, like, depending on who you're with to try and fit in with those people? To be like, hey, I like to fish too, and throw a fish out there.
Yeah. Yeah. Good stuff. I'm not sure that I've ever actually used my digital driver's license anywhere, but yeah, I'm ready to. Also in the, in the article, it notes, and this is very important, we kind of alluded to it, that The digital ID is still not good outside of Colorado.
Right. So if you're using it for something federal or in your— in another state, you're— it's not technically a valid ID. Somebody might still accept it, but it's not technically valid. And speaking of other things, the article notes they are expecting that this might be something they'll add to the physical driver's license, too. So Polis was playing around with that idea, you know, kind of a why not perspective.
All right. Next story we have kind of following the same trend of Colorado embracing new technologies. Colorado becomes the first state in the union to accept crypto payments for tax. Yeah, this shouldn't come to a shock as a shock to anyone. They announced previously that they were going to do this.
The state has also hired a— I forget what the official title of the person was, but they got it right here. It's the blockchain solution architect. There you go. Someone in the state who's in charge of Thaddeus Batt. Thaddeus Batt, um, moving the, the blockchain forward in Colorado.
Um, so, but yeah, if you've got a, you know, a couple Bitcoin sitting around and, uh, you, you've got to, uh, pay your taxes, you can use that to pay your taxes. Uh, you can pay not only your state income tax, but you can also pay sales taxes, severance taxes, withholding taxes, excise taxes, and fuel taxes. Nice. Um, I'm very curious how I pay my excise taxes. I, I would be, uh, excited to pay excise taxes because that would mean I would be doing something that required excise, like being a, a brewer or distiller.
Hmm. Um, but I'm not, so I don't need to pay any excise taxes. Anyway. All right. What, what do we got next?
Is there some more government news we can dive into? There, there's tons of government news, uh, this month, Robb. This one is some sad news. Um, it, uh, A Denver suburb did not pay a ransom but was a victim of a ransomware attack that closed some of the city offices for a short time. Yeah, it was.
So on August 29th, there was a cyberattack against Wheat Ridge, a northern suburb up there. And it took them 3 weeks to determine that they had the right backups and they were going to choose not to pay the ransom. I'm so glad to hear that, you know, they're not you know, continuing to, to give money to these criminals who, who are holding us hostage. Unfortunately, there was quite a bit of impact, though, as a result of this, this breach. Yeah.
There were some, some services that were knocked offline. They had to do some work to get everything back together. They took down all of their phones, all their email, all their websites and networks. And it was down for, for more than a week. Yeah.
No, not as bad as, as some. I'll say only being a week, but— well, they had to close City Hall, Alex. Yeah. That, that's kind of nuts. It is.
Closing City Hall for a week for— yeah, definitely an impact. But also in this article, it was, it was BlackCat ransomware, which is the one that, that got Wheat Ridge. But they also note that Fremont County, which is in southwest, southwest of Colorado Springs, was also a victim last month of BlackCat ransomware. And it sounds like they were even more of a mess because of it. They— the sheriff's office down there noted that the inmate accounting systems for a jail that they have was permanently taken offline.
They lost all of the data. So they're not going to know how much was in these. Yeah, there was like— they had a backup, but it was— they had a backup that was like weeks old. So anyone who had deposited new money had to show a receipt to get that credited eventually. Rough stuff.
Yeah, it is no good. All right. On a— on better news, we have news of a new startup, actually a tech unicorn called Virta Health, who's moving their headquarters here to Denver. Yeah. So this is one of the announcements from— now I'm forgetting the name of the group, but the, the group that gives incentives for, for folks to come to town, they announced that Virta Health is moving their headquarters here.
They already had an office, but they're going to be expanding that. I think they have a couple hundred people now going to be expanding to around 1,000. So they currently have— they're a 400-person company, 392 employees total, with 100 of those already in Denver. But they plan to create 1,000 new jobs with the move of the headquarters here. They're going to be hiring engineers, researchers, sales account managers, clinicians, and administrative roles.
Yeah, the company actually sounds pretty cool, too. They're a platform for helping to— for patients suffering from type 2 diabetes with the overall goal of reversing diabetes in 100 million people. That sounds really good. That is a pretty cool goal. If you, if you get, you know, halfway there, you've done pretty good too, right?
Yes. 100 million people the way that, you know, 10% is 1%. That's awesome. Anyway, regardless, really cool to have those guys here. Looking forward to getting to meet them.
Speaking of my favorite person, the Colorado Attorney General, he has now given his first public comments on the privacy rules that they have created around the new Colorado Privacy Act. They've been going through the rulemaking process for quite some time now, and that was released here recently. And he gave comments on it at Ballard Spahr's annual privacy event. Yes. So there was— it was interesting.
This is one of the 4 non-California states that have privacy laws going into effect next year. And we're the only state that has implementation guidelines or regulations giving details on how to do this. So there's a lot of eyes around the country around How is Colorado gonna do this? And expecting that, that whatever we come up with might be followed in other states. Yeah.
Excited to see that he did this at that event as well. I've been to that event the last few years, although I did not go this year. And, you know, he was talking to Greg Zweycheck, who we have had on the podcast before, about these rules. And I'm interested to see where this goes because I think the biggest thing is the, the universal opt-out. That Colorado has, uh, required and, and the technology that it's going to take to enable that.
Yeah, I think it's interesting. They're looking right now for, for public comment on their implementation guidelines, and, and basically the earlier the better because they don't want to be changing things last minute. So if you have opinions on, on how these privacy laws should be implemented, this is the time to look into it and let, let them know. Um, I'm really looking forward to seeing what this ends up looking like. Me too.
All right, next story. A— this is sort of a mixed bag of news. This is sort of a national story, but it just so happens to have happened in Colorado. There was an ex-NSA worker in Colorado Springs that was arrested recently for espionage for trying to sell secrets to what he thought was Russia. So Jera Sebastian Dahlke, Dahlke, maybe.
He's accused of 6 counts of attempting to provide documents to related to national defense to the Russian Federation. So big news here. He apparently is a former military— was it Army? Is that what he was? Shoot, I know it was in here.
Army veteran. Yes. Yeah, he's an Army veteran who has, you know, financial troubles and saw this as a way for him to take care of his financial troubles. And apparently, according to this article, he also has some heritage ancestry that's related to Russia and saw this as a way for him to help them and help himself at the same time. Yeah, I mean, it's very sad.
But I'm glad that they were able to, to root him out and catch him in the act and make it so that he wasn't giving these secrets away. You know, he believed that he was speaking to Russian agents, but he was actually speaking to, to US agents. And they lured him to Union Station to, to give these documents and then subsequently arrested him. Yeah, I am glad they caught him. And I guess this is, you know, news for anyone else thinking about selling secrets.
Don't do that. Yes, bad idea. Don't do that for lots of reasons. All right. Next, some more bad news here from Colorado.
CommonSpirit Health, which is— they're not headquartered here, but they might— they have a huge presence here in Colorado. They were hit by a ransomware attack. So CommonSpirit was the is what CHI, Catholic Healthcare, has— they merged into as they joined with Dignity Health, I believe, out of California. So now, you know, together they are called CommonSpirit. It looks like they've been hit pretty hard by some ransomware.
Yeah, they haven't publicly announced that it was ransomware, but I think it's pretty obvious by the steps that they have taken that it was ransomware. You know, they noted that they are undergoing a security incident. They have preemptively taken down some of their, their hospital networks, including a hospital in Des Moines, that they're, you know, running on, on paper records and don't have access to the electronic health records of their patients there. This was maybe about a week ago, maybe a little less than a week ago when this, this first started. And so I haven't heard where, where the status is currently, but it sounded like it was pretty serious.
And I'm sure that the folks over there are doing a lot of work to get it themselves back up. Yeah, I know you and I both have friends over there. Hopefully they're, they're recovering okay and this is not taking away their ability to get any sleep. I know this can be, you know, incident response can be pretty brutal. Yeah, especially something as major as this.
It's, uh, a lot of work to get back. Well, we're thinking about you guys. Yep. All right, uh, next, uh, we have a blog from Red Canary talking about detecting an email payroll diversion attack. Yeah, this is, uh, you know, I think we've talked about lots of times Red Canary's blog is, is often a fantastic read for security operations teams.
They go into really technical detail about how they find bad things and, and give you some tips on how you could find them in your own environment. You know, same thing here again. This one is, is really focused on Red Canary's, you know, visibility into email and, and what does it look like when a bad guy gets access to your email? What are they trying to accomplish? How do you technically defend against it and then detect and respond?
Yeah. Again, pretty good blog. It's— this one is focused a bit on Office 365, but I love how the, uh, the MITRE framework for attacks in Office 365 is tied into it. Um, and, you know, some areas in there where you've got a lot of great detail about what is being done to look at things and the, you know, the different logs and everything else. But, uh, really great blog, uh, again by Red Canary.
If you've been resisting learning the MITRE ATT&CK framework, you should probably stop resisting. It's really, it's really valuable. And frankly, like, it's, it's a common vernacular for us to talk about how attackers and defenders work. Anyway, good stuff in here. And as always, looking forward to their next blog post.
Finally, speaking of local security companies' blog posts, did you know that this is Cybersecurity Awareness Month? You know, I had heard that, Robb. I'm not sure where, but I heard it. All right, so there's a blog post here from Jason Keys, who's the CISO for Ping Identity, and he's going through the the top 4, um, practices that you should do around security to keep yourself safe. Yeah, the, uh, some, some good practices here.
These are things probably that most of us know, but, uh, it's a great article for those folks that might not be in security, um, or doing this every day. The first of those is enabling MFA. Yeah, you should have multi-factor just about everywhere you can, everywhere you don't want something stolen at least. And your email should be at the top of that list. Yeah, because that's the thing that everything else is usually based on.
Second recommendation he has is around using strong passwords. And of course, in order to do that, you probably need a password manager. Otherwise you're going to use weak passwords or use one strong password everywhere. Number 3 is updating software, making sure that your software is patched and up to date and free of vulnerabilities is super important too. And the final recommendation here is recognizing and reporting phishing.
If you can, if you can recognize phishing, if you can stop people from tricking you with emails, if you got MFA in place, you're using different passwords, updated software, you're gonna be a much harder target than most people. Yeah, these are some great recommendations, and pass it on to, uh, to anybody that you know who needs a few, uh, basic, uh, requirements for security. Yeah, basic. All right, we do have events coming up here. As a reminder, uh, we have a calendar of events on the website colorado-security.com, and let's go through what's happening here in October and in early November.
First, we have the Let's Talk Software Security group Uh, they are doing a meeting about software security engineering and automation, and that is happening on October 14th. On the 18th, we've got 2 separate meetings. ISSA Colorado Springs is doing their October meeting and the CSA Colorado Fall Summit. We already talked about this at the beginning of the show, but this is a big event. You get to meet 100 or 150 of your closest friends.
Highly recommend showing up if you can. On the 20th, ISACA Denver is doing their October chapter meeting with a couple different topics. One is Cloud Auditing and View from the Top— how— or sorry, Cloud Auditing. And the second one is View from the Top: How Boards and C-Suites Value Our Work. And that's a pretty long event.
It's most of the day, so you can get quite a few CPEs if you show up. Speaking of getting quite a few CPEs, on the 22nd, Colorado Springs ISSA has their October mini seminar. Those are usually like 8 to 12 in the morning on Saturdays and a great way to get some CPEs and learn some good stuff. On the 26th, ISC² Pikes Peak is doing their October meeting. And finally, we have another Let's Talk Software Security meeting on the 4th of November.
Uh, there is a talent and strategy diversity in AppSec topic that they're gonna be headed— handling. Yeah, sounds like a cool topic. All right. Uh, let's jump over and let's talk about some jobs that we have. Uh, first on that list, Visa is looking for a senior director of product security architecture and assessments.
Uh, next, Sovereign, a local tech company here, is hiring a privacy system engineer. I suspect this is reporting to our friend Melissa Cooper and I think that'd be awesome to work for Melissa. Boulder Valley School District is looking for a Director of Information Technology Security. Janus Henderson Investors might have the longest title of the week, IT Operational Risk and Business Continuity Manager. That is long.
Charles Schwab is looking for a Director of Security Development and Engineering Principal. Dotcom Therapy is hiring a Director of Information Technology and Security. Denver Water is looking for an IT asset manager. Western Union is hiring a leader information security cyber threat intelligence. Banner Health is looking for an associate director of cybersecurity GRC.
And finally, TIAA is hiring a lead info security governance and risk specialist. Awesome. A lot of, a lot of long titles this week. Yeah. And that's all the jobs that we have.
Robb, do we have an interview this month? We do. I got to sit down with Patrick Dennis. Patrick is the CEO of ExtraHop. He's located here in Denver.
Super interesting background. Before being at ExtraHop, he worked for Guidance Software and, you know, the makers of EnCase, which I think we're all, you know, all of us who've been around for a while have had our hands on once or twice and has had a really interesting career. And I was excited to get to talk to him. That's awesome. These are the cool interviews that I like.
I had no idea that the CEO of ExtraHop lived in Colorado. I didn't either until recently. Yeah. All right. Well, that is it for the news this week.
Do stick around and listen to Patrick. And after that, we'll look forward to catching with you guys in November. Sounds good. Thanks, Robb. Hi, this is Mary Haynes, VP of Network Security at Charter Communications.
Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is a special interview where This Is Robb getting to sit down with Patrick Dettes. Patrick, I'm excited to get to know you. You're currently the CEO for ExtraHop, which is well known in the network and network security space, and I'd love to talk about your career and what got you there.
But first, I want you to tell me, what is, what is Point Easy? Somebody told me that I should just ask you about Point Easy. What is this? You got like the inside track. I got the inside track on you.
Uh, see, that's, that's what happens when you do these things that are a little more local. Yeah. Um, Point Easy is a restaurant, uh, that we opened, um, in Whittier here in Colorado. It's off Race Street. Um, super cool restaurant.
A bunch of people that were associated with the Kitchen Group came. Oh, cool. Um, been a passion of mine for a long time. Uh, my partner's in it, shockingly. Like, if I'm running a security company, they do most of the restaurant work.
But we have an awesome chef named Laith who's just been crushing it since we opened. Um, Andy's close friend and a good partner. He's been running the business. Um, Dan has been doing drinks in front of house. Um, it's just awesome, man.
So I'm— so there's so many questions I want to ask. So let's start off by saying what, what's the concept or type of food? What is Point Easy? Yeah, so, um, if you go back, it was actually the Whittier Pub. So it was like your classic, like, show up in a neighborhood pub sort of place, right?
Like, think stained glass, dark wood, bar orientation kind of thing. Sounds like Cheers. Yeah, kind of like Cheers. Yeah, like, I'm from Boston. Yeah, in fact, quite like Cheers.
Okay. And we obviously, we wanted to do something different. And COVID came around, which was unfortunate for a variety of reasons, including restaurant and service workers were kind of disproportionately impacted. And we thought it was actually like the right time to like go build a restaurant, which probably seems crazy. So yeah, we stripped it down, built it back up.
It feels super modern. So if you go in there, it should be modern, it should be sleek. We have great relationships with people locally like Cure Farms that do many of our vegetables. It's super seasonal. And it really is kind of like a passion project for both for myself and for the folks that are running it every day.
But, you know, if you go in, you'll get some good food. What kind of food would I get? So you can get a lot of different things. So Laith has spent some time in the Middle East, has family there, right? So you get, uh, for instance, we had a ratatouille spin, okay, which brought a little bit of Middle Eastern flavor with our local vegetables.
Um, we had a sea bean and salmon dish. It was quite popular for a while. Yeah. Um, there's some classics. We have a very light, what I would refer to as summer bolognese.
So like instead of like that heavy bolognese, it kind of like goes up. Yeah. Um, Dan does an awesome job curating the wine list. So depending on when the this goes on. There's like a Cab Franc, Gamay blended red on the menu for $50.
It's super good. Um, yeah, it's, it's really great. And, and, you know, what's most important to us is, uh, this— the team that, like, the service team is amazing. So it'll be a place where you go and people will smile and people have a good time. That sounds, sounds awesome.
What, what is your favorite thing on the menu? Should I order if I want to, if I want to get your favorite thing? So from day one, we had lamb meatballs on the menu. Yeah. Even if you're not a lamb person, try them.
They're amazing. Yeah. That bolognese, absolutely everybody should try. And then insider tip, we have an amaro, which is— I don't know what that is. Yeah, so it's like a post-dinner drink.
Okay. Okay. It was from— generally associated with Italy. It was almost medicinal. We found an amaro maker in Brooklyn.
Hmm. It's just like an awesome drink. Ask them to bring the bottle over so you can see it. It's just like one of those special curated products that like you can't find anyplace else that we got, and it's super, super good. Awesome.
Well, that's the insider tip I was looking for. I am curious how like the CEO of a tech company can be like, you know what I need? An extra job, some more to take some more time. Like, what was going through your head? Um, you know, you need a reason to do it all.
And, uh, the, the truth is Andy's an amazing guy. Um, Leith's an amazing chef. Dan's just an amazing guy in the front of house. And, you know, I'm sure this— well, I've listened to many of these shows. I think it's resonated with you and a lot of folks, you know, like COVID was a weird time.
And, um, I, I was pretty sick of the screen. Yeah. And again, like, these service people are affected. And, you know, if you don't know this, like, a lot of those people, they kind of need the money. Yeah.
Right. And so it was a good time for a new project that didn't involve screens. Yeah. Um, I cook at home. Like, I take that super seriously.
So it really is like a passion. And it just was— it felt like the time. Yeah. You know, and you never know That was one of those projects where more fail than succeed, right? So, um, like whenever you tell anybody you're doing a restaurant project, they're all like, it seems like the fast path to lose money.
And it wasn't like we did it to necessarily make money. That wasn't the primary aim, right? But it's, it's gone super, super, super well. And, um, I'll tell you, like my favorite thing is like if you go in, I, my wife actually works every Thursday night. She works at the restaurant.
Yeah, she sees people. Right. But like when we go in, you know, you see just people smiling and having a good time. And, you know, I know you appreciate this because you take the time to do this podcast. Like it's all locals.
Yeah. Right. And, you know, see a bunch of folks that are local to that neighborhood, which is a super, super cute, super awesome neighborhood that gets overlooked a lot. Know, we're starting to draw some people from other parts of Denver that are more into cuisine. Like, it's actually doing quite well.
Um, this is fun to watch all these people smile and have a good time. And, you know, you know you're a part of it in a different way, and it, uh, it gives you a little bit of satisfaction. Yeah, you don't necessarily get in software, you know. So does success for this, this venture for you look like, you know, building a sustainable business that can go for 5 years, 10 years, whatever it is. Uh, it sounds like you've achieved success by a lot of measures already, where you have customers who are happy, you've got employed staff, you got great food.
What does success look like to you? Is there a time frame? Because nothing goes forever, right? Like, what is— what does success look like for this venture? I think if you asked all the people around the restaurant, um, we would probably say, if you've ever been to Tavern at a super high-quality Italian place here.
It's run by a guy named Bobby Stuckey, and he's done an amazing job with that restaurant. He's sustained over time. They still kill it. Like, there's a part of this that's, um, about that. But if we can do that in a way and still make, like, really authentic, genuinely good food— yeah, um, we're pretty judgy about that.
Like, You know, there's a lot of people that are super into food and super into restaurants. And, you know, I tell you more often than probably the industry would like to admit, like, you don't really get food from the heart. Like, we don't want to lose that. So if we can keep that over time and the relationships that we have with some of the purveyors of products that let us let a product show through, you know, that'd feel pretty good. Yeah.
It certainly doesn't mean like let's make 50 You know, like that's not the goal. Yeah. Right. And quite honestly, if we did another one tomorrow, I'm not sure we would recreate the exact same experience. Like I think we might try to tap into something new.
I think there's something to being unique, right? Like totally. It, there's the scarcity of it seems, makes it more special. And yeah, I don't know. You know, like we, I think there's something to be said for this too, for like software people where like our job is persistence.
Like we make stuff that lasts forever, right? Or as close to forever as possible. Like the reality is we make seasonal food, not to sound cheesy, but it's true. And like stuff stops growing. Yeah.
So, you know, I'll give you a product that's a really good example of that. Like if you've ever had great corn, yeah, great sweet corn is amazing. Yeah, it is. Okay. But like what goes on after great isn't even good.
Yeah, it goes quick, drops off quickly. It goes straight to poor, right? And so in those moments, you try to catch those products that like have those fleeting moments, you know, those, those vegetables' fleeting moments in a, in a season and put them into a special preparation, let them shine through. Like, yeah, that's fun. It's, it's interesting, you know, you talk about it, the, the permanence of creating software or hardware, whatever you're creating from an IT perspective.
Versus when you're creating food. I mean, it's just like chalk art, right? You put it out there and it's gone. You know, chalk art, when the rain comes, or here, like, you know, 20 minutes later, that food should be gone and enjoyed or not enjoyed. Yeah, that distinction, if you were to distill it down to one thing, most of us in tech assume we're making a product, even if that product is a service.
Right? It's a product. The reality is if you ever get into the restaurant business, and I think if you go to a— if you enjoy food, you could probably relate to this. It's not a product, it's an experience. And so, you know, we measure things like how— what are the levels that people like in terms of music, right?
You know, so we sample decibels. Right, like there's all these things that you wouldn't necessarily associate with like the restaurant per se because most guests think of it mainly as like the food. Food and the waitress. Yeah, yeah, but like the reality is what most people are judging is an experience. Yeah, and an experience should be something that you like, you participate in, and then it begins and it ends.
Yeah, you know, that's not what products do really, right? Yeah, that's interesting. Yeah. All right, I, I could talk about this all day. We should talk about A little bit about your career as well.
But honestly, now, now everyone knows a little bit more about starting their own restaurant. Yeah. And maybe they will. All right, let's, let's back up. You— where are you from originally?
Let's start there. Born in upstate New York. The city most familiar would be Rochester, New York, between Buffalo and Syracuse. Kodak country. Kodak and Xerox country.
That's right. I worked at Kodak at one point. All right. As did my dad and my dad's dad. So yeah, I grew up more in the farm side of that.
So I grew up in a place called Victor. So okay, that would be kind of like the southeast side of Rochester. Yeah, you know, the demise of Kodak has got to be one of the sadder stories, like their unwillingness to embrace new technology. You know, they went from like a dominant massive company that we thought would never fail to To— do they still exist at all anymore? If they do, it's in some weird way.
Yeah, the brand exists. Um, it's funny, like, uh, you know, we didn't talk about this question ahead of time. One of the more formative moments in my life. So, um, my dad's dad worked at Kodak, uh, believe it or not, in downtown Rochester. They used to have the manufacturing line.
And so we have a whole bunch of old cameras. Yeah, that his dad over you know, was providing oversight on the manufacturing of. So we have all those old accordion-style cameras and all that. Then my dad worked there. He worked in finance until finance became the department that bought a mainframe.
Okay. So he worked on a mainframe a million years ago. And then I wound up working there mainly because, to your earlier point, there were 2 places to work and I needed a way to pay for school. But I remember the moment where it happened, and it's a moment that like very distinctly sticks with me. And it came down to 2 things.
There was a moment in time where there was research and development going into film, and it turns out most of us, when we— when we— well, I guess today we don't do this, so I don't know if this is true on iPhone, so don't judge me, audience. But on, on regular film, most of us couldn't get the red levels right. Like, we would shoot pictures and they wouldn't have enough red. Okay. So the primary competitor at the time was Fujifilm.
They just dialed up the concentration of red to correct for what was the average photographer. Okay. Kodak was unwilling to do it because it wasn't true to form. There's some purity there. They're saying that— oh, that— yeah, yeah.
Now I want you to think about the irony of that. Like, most of that film got sold in like Kmart, you know, retail, like discount retail locations. So like they're being developed at a 1 Hour Photo somewhere. Totally right. And yet the decision was made, like, we're gonna stick with purity.
Yeah. The second one that I remember was when I finally got to Kodak office, which was like a big deal for me at the time. Like, I went to this town hall meeting and the CTO at the time came out and was like, the future of photography isn't digital, it's still film. And we're going to give people new ways to print the photos. And so that was a moment in which the internet existed.
Kodak was using a mainframe to determine whether or not the packaging and pricing of products was correct. Yeah. Okay. We were communicating with email systems. I'll date myself, but like, this is Lotus Notes.
So there was like graphical user interfaces and stuff. I wasn't Notes admin, so don't get me wrong. Oh yeah, okay, all right, right. But like in that moment, they actively made a decision that film was the future. Yeah, yeah.
I mean, it just goes to show that the thing that got you here won't get you there, right? Totally. It's also like that innovator's dilemma thing, which is kind of cheesy at this stage because we talk about it a lot. Like I watched that like, yeah, in a very real way. And like these days the cycles are so much faster Yeah, you know, like I think that that happens much more quickly, but back then like you watched the old saying like I watched the train wreck.
Yeah, so, so is this— how does that influence you as a leader now? Being— I'm much more sensitive to when my signal-to-noise ratio is like super fine-tuned. Um, I'm— I am willing to make adjustments that in the moment might seem like they are super aggressive.
Because the other thing I learned is in companies that big and that sophisticated, and these days many companies aren't that big and that sophisticated, but they're faster. So let's just use that as a proxy for complexity. If you get overrun by the complexity, you're in trouble. And so I'm a bigger fan of let's move fast, let's tack our way through whatever seems like the situation. But I think, you know, my experience at Kodak was don't ever let anybody point the boat at the wave and think you're just gonna break it.
Like, if you're in that spot, you're late. Yeah, I, I'd love to hear maybe as we go, talk about your career a little bit, and I'd love to hear if you've, if you got any examples of times where where you've seen what seems like the tough decision, the aggressive decision you needed to make and where you've made them? We could do it now or we can do it as you go, as you prefer. I mean, I think an easy one actually that we'll all remember is I was running Guidance Software, the makers of EnCase. Best forensics tool out there, yeah.
And we chose to used that forensics tool also in an endpoint detection and response application. This was like 2013, '14. I'm sure somebody will tell me if I get it wrong.
And that was super early for EDR, right? Like, people were still doing signature-based antivirus. Like, it wasn't even considered an endpoint protection platform yet, right? And I think for those of us that were pretty early in EDR, we're like, oh, this is gonna go. Yeah.
But so many companies doubled and tripled down on, you know, just kind of signature-based antivirus protection, right? Like, that was a bet we made, worked out well for us, worked out really well. You know, it's funny, I go back to my competitive matrix. Like, CrowdStrike wasn't on my first competitive matrix. Yeah.
And I think we all agree, like, they've done an exceptional job. Yeah, they sure have, right? That was an example of like George did an amazing job leaning in at like the exact right moment. And that's just one that, you know, this audience I think would all identify with. Yeah, that's great.
But there's a million. I mean, you look back in tech, right? Like we all know there's these cycles. And I do think, and I'll feel like sometimes when people are like, what's it like to be like a CEO? And I'm like, it's a little bit like being the technology historian.
You know, you got to kind of pattern match some of the things you've seen before. And, and be good at identifying the patterns that are worth pursuing and identifying the patterns that, you know, might be noise. But that's a big part of the job because a lot of these tech cycles, you know, they do manifest themselves in new markets, new ways. And yeah, if you think about it, most of them have been flow, and like sooner or later a market's created and it's destroyed in favor of a new market. Yeah, I like security because I think that cycle moves faster in security than it does in the rest of tech.
We could talk about why that is, but that interests me. Well, let's go ahead and start earlier in your career. You said you worked at Kodak. I'm guessing that was early in your career? Super early, yeah.
Well, I was in college, actually. Okay, so where did you go to college? Where did you graduate? What's next? Yeah, my dad got really sick my senior year in high school.
I thought I was going to go to some fancy-pants computer science school. I wound up at the Rochester Institute of Technology, which is a really highly regarded school today. Maybe, maybe honestly a little less so when I went. Really? Yeah, but amazing program, amazing, amazing program.
So I decided to stay at home with my folks. I worked during the day at Kodak. I went to school primarily at night. Did a combination of what was then called like, it was adjunct computer science, information technology. I was focused on databases at the time.
And economics. And so Kodak was super, super interesting time in my life because Kodak like gave you the opportunity to work all day, but then, you know, you'd go to school at RIT and RIT was super interesting at the time 'cause they ran on trimesters. So like I was on a massive grind, you know, for that period of time. Period of my life. Like, I'd go to work, I would work on really interesting systems because I wound up supporting Kodak's R&D systems.
So like Silicon Graphics, IRIX systems, all these like esoteric, you know, now like again back to being the computer historian, like I got to use all that stuff, right? Notes Admin, NetWare, like, you know, 100VG AnyLAN, like all that and all this like weird stuff going on in my job and then I'd go to school at night and work on comp sci stuff. Yeah, learn the theory behind it all. Yeah, exactly. The practical during the day, the theory at night.
Totally right. That's exactly right. On trimesters, right? So that's a 10-week cycle because I don't think they do those anymore. So, you know, like I learned C++ in 10 weeks.
All right. Right? And yeah, I think back sometimes. I have kids college age now and it's just a different world. Yeah.
So did you end up graduating from RIT? Yeah, graduated from RIT. It's a little bit of an unusual cycle. I can't remember. I think it ultimately took 5 years because I turned Kodak into my co-op, which usually adds a year.
But I left with super practical experience. I got to work on systems that most people my age didn't get to work on. I had a great experience. You know, to your point, later on Kodak turned out to be, you know, something that's kind of long forgotten or just a brand. But, you know, when I was there, I owe them a lot.
They were my first professional education. Yeah, that's a— I mean, what a neat opportunity to get to do that while you were in college and when you were young enough that, you know, you could probably sleep a little bit less than you need to today, right? Yeah, my journey at least is certainly evidence that like if there's a time in your life when you're making the decision about when to grind, I made the decision to do it then. Yeah, worked out really well for me. Yeah, you know, so look, when you graduated, what was next?
Did you go back to Kodak? You moved to Worlds? I mean, I messed around. I did, I did some dot-com stuff. I, you know, wound up running a dot-com which we sold for a modest amount of money.
Don't go back and try to Google it. It's was nothing to be, uh, certainly nothing to write home about. And then my mom at one stage— but by the way, for that age I was doing great. Yeah. My mother came to me and she's like, I want you to get a badge.
And I was like, Mom, I'm like doing so well. But in my family, like, that wasn't how it worked. Like, there weren't entrepreneurs. Yeah. So, um, so I wound up at EMC, uh, and wound up being at EMC for like 15 years.
So another good run. So what did you start off doing at EMC? Because somehow, somewhere along the way, you went from entry-level college kid to an executive for EMC, right? I'd love to hear a little bit about that path. I did.
So, you know, some of it, looking back, and it probably applies now, like, if there's anybody that listens to this that's early career and you're listening the news and there's like talk about recessions and things slowing down. Like, that happened for me too. I started at EMC right when the dot-com bubble burst, and I remember being scared for like, hey, am I going to have a job? Yeah. Which, by the way, legitimate concern.
Yeah, right. It's a real thing to want. It's a real thing, right? Um, my decision in that moment was, hey, I'm just going to work harder and learn more. And I was— yeah, it's probably a terrible thing to to say now, but it's true.
I was always like, well, I'm probably less expensive, so like I should just go demonstrate value, right? And so it was an interesting time. Like, I wound up with bigger and bigger and bigger jobs, mostly focused on how you develop solutions for customers in the field organization. And then, I don't know, sometime in the 2000s, they came to me and said, after doing several jobs, right, hey, do you want to come to headquarters headquarters. And, you know, they kind of said like, here's your offer and here's your relocation package.
And that's when I left upstate New York and went to Boston. So you're, you're getting close to the customers early on and totally figuring out what they needed and then helping giving that back to the business to say, here's how we can get better. Yeah, I always, I always summarize it as saying like somebody in the— somebody has to be able to do the impedance match between a customer need and what a company has to offer. Right? And the closer you can get those 2 things to matching, it's great.
But when they're not gonna match, forcing it isn't the answer.
Figuring that out. Yeah. And then, you know, more importantly, how you communicate with both parties that, you know, like, hey, it's not gonna match 100%. Here's where we're disconnected. And have that be authentic and genuine in a way that's like good for the customer and good for the company.
I don't know, putting time into that is worthwhile. Yeah, it served me really well. I, I still use that. I still use that trick today. Yeah, I mean, it's— I don't know if I call it a trick.
I'd call it like being, you know, being the, the translator between needs and, you know, supply and demand, right? Yeah, but I mean, like, you mean you work in this business too? Like, not that many people can do it. It's hard. Yeah, right.
Um, it's hard. It takes a— it takes I think a transparency— there's, there's incentives on both sides that sometimes push against that, right? A salesperson who wants to, who wants to kind of shade the truth, or a, a, uh, or, or a buyer who's, you know, who's, who's looking to, you know, get something in immediately, right? Like, you have to sometimes push against both of those incentive problems. Yeah, uh, like someone in my career said, like, hey, remember, just remember, reputation is forever.
And I wish I could attribute that quote to somebody, but I can't remember who said it, but it stuck with me as like a, hey, I'm not willing to make that trade-off. Yeah. Right. Especially when, you know, I think the longer that you're in a technical career, the more you realize the vast majority of the problems don't get solved like easily. 2 people are going to compromise on on a solution the majority of the time.
So getting used to helping people understand what is a reasonable compromise or what's not, that's a pretty good thing to learn early. That's great. So you moved to Boston, get to go to headquarters. Was that a good choice? Yeah.
I think, listen, you need professional development in your career is an important thing. You're probably gonna get more robust professional development in a larger environment than you would in a smaller environment. If you can get that professional development early in your career and then leverage it for the balance of your career, that's not a bad way to do it. Can you do it in smaller places? You can.
You might be more actively involved there might be less of a system. I got 2 rounds of superior professional development. I got one of the best companies during the '80s, Kodak, and I got the benefit of one of the best technology companies in the 2000s in EMC. Yeah. And, you know, I run a, I run a much smaller company today.
I love this company to pieces. We don't have the resources to do the things that those 2 companies did for me. Yeah. And it's not because I, I don't appreciate it. I'm obviously here telling you how much I do appreciate it.
I just don't have the resources to do it. So yeah, if you're earlier in your career and you can do that, that's great. And hey, if it turns out to be for you, that's awesome. I got to a place where I knew it wasn't for me, and that's okay too. Yeah.
So when you decided it wasn't for you, how did you decide what the next thing to do was and what was the next thing? I more knew what the moment was.
So for me, I've always said, like, if you ever get to a place where the PowerPoint feels like the work, that's a time to reevaluate. By the way, I still think that's true today in the job that I'm in today. If I ever feel like people are like doing PowerPoint, you know, as a proxy for the work, that's a signal to me something's a little off. And that's not the way, that's not my style of working. And, you know, in some of those larger organizations, that's a big part of what you do, right?
And I eventually got to a place where I was like, you know, I just wanna go like put my hands on the outcome a little bit more than just try to get people convinced that we need to go put our hands on the outcome. And, you know, I also feel like I reached a place where I wanted the accountability accountability.
And I think that's an important point. Sometimes people evaluate their careers and they think to themselves like, oh, I want more— we'll use the proxy we've used before— money. Yeah. Well, you're going to make a trade-off, you know. So if you want the money but you don't really want any accountability, like, that's probably not going to work in the long run.
Yeah. You can find a place where it works for some amount of time, but— Totally. Yeah. Totally. But you'll eventually be outed.
Yeah. I mean, like, I sometimes get asked, like, you know, what's the most common attribute among CEOs? And I've answered this question a few times and I've always chosen to answer it truthfully and I think it's a weird answer, but I think it's the truth. It's sacrifice. Like, they're hard jobs.
So if you want to be really good at it, by the time you get to them, like, smarts are normalized, drive is normalized. Like, it's a small pool of people. So what you really wind up doing is kind of dialing in, like, how much you're willing to put in. Yeah. Right.
And, you know, it's a good example. Like, the restaurant example is actually a good example. Like, That's an example of where I don't have the time to do that anymore at the level that I would like to, but my financial resources are probably more flexible than most people's. So I'm getting to see that carried out. Yeah, right.
Because I don't have the time right now, given that I'm a super blessed problem to have, right? But, you know, in these jobs, sacrifice means a lot. Yeah. And by the way, early career, I think that that played a role too. Too, kind of by the middle of your life, you know, when you're thinking about family, kids, that sort of stuff, that may be when you want to deal with your sacrifice dial a little bit.
Yeah. You know, so I kind of front-loaded it and back-loaded it. Yeah. So, so, all right, you, you made the decision you wanted more accountability, you wanted to be closer to solving the problems. What, what did that lead you to do?
So I had met a guy a long time, uh, sometime before that, and he calls me one day He's in the recruiting business and I had used him for some searches and he had kind of shown a fondness to me and kept in touch with me. And this was his opening line. I think it's hysterical. He goes, nobody's first CEO job is Coca-Cola, Patrick.
All right. And I'm like, okay. And he's like, we got this little company in Southern California. Called Guidance Software, and they're doing a search for a CEO, and I think you'd be the right candidate. And that's how that started.
Wow. And that was your first exposure to security then? Is that true? Yeah. Well, not exactly.
So at the time at EMC, EMC had acquired RSA. So a long time ago. And then the infamous RSA breach occurred. Stole the seed files or whatever it was. Yeah, I can't comment, but it was one of the first times I'd been brought to the boardroom at EMC, um, supporting an executive.
That individual got to bring 2 people with them to that situation. I was one of the 2 that supported that particular executive, and it was a super tense moment. Like, it was a very, very tense moment, and there are some people I think all of us consider like, you know, the grandfathers of security. Like, Art was there, obviously, it's his company. And you could tell 2 things in that moment.
You could tell how seriously everyone was taking it. Yeah. And quite honestly, it's one of the few times in my life where I actually felt like the world changed in front of me. I was like, oh, this is a thing. Yeah.
This isn't— it's not going to go away. Nope. I knew in that moment. Um, and so I'd had an interest in security, um, because of all that, and we had been doing some other projects that were related, but it never really hit home to me until that moment. Yeah.
You know, so you got the opportunity to go to, to Guidance Software, and they'd been around for a while, right? When was that? Company started. It was an early one, I think. Yeah, it was early, right?
It was early. I mean, and it started— I mean, talk about interesting applications. Uh, Sean, wicked smart guy, had realized that people couldn't do, um, the forensic work on computers that they could do in the physical world. He just tried to replicate it. Yeah.
And, um, by the way, did like the best job in the world, right? Yeah, it was the best tool for sure. Best tool for sure, right? Wasn't even close. There was— I mean, there competitors, but they were not very— they weren't as strong.
No, that's right. I mean, by the way, people forget this, like, he built a $100 million business doing that. Yeah, it's amazing. $2,000 at a time, by the way. So was he the CEO before you?
He was the founder. Okay. And there was a CEO before me named Victor who had helped the company scale. But what's interesting is, you know, this story, all these companies, sooner or later, if you're in one of those markets and you kind of like test the boundary of You need to do something new. And so the obvious choice then, and by the way, probably the right choice, not a criticism, was, well, if you collect evidence, you give it to lawyers, so we should move into an e-discovery market, right?
So they moved into e-discovery and they had done some work there and that product was also quite good. What we didn't know was going to happen and happened when I showed up was, you know, so many of us security professionals come out of law enforcement agency work or the military.
What do you think they use to do the first incident response? Well, it looks like a forensic investigation. So all of a sudden, I'm talking to customers and they're like, yeah, well, we use your forensic tool, but we're using it for incident response. And I'm like, well, that's different. And then This is such a simple thing.
It tells you kind of like sometimes unlocks and products are not like enormous. Like the real problem though is, and you may remember this because it sounds like you remember the tool, it was very point to point. Like we're sitting across from each other right now, right? Like we would have to be this distance from one another for me to have used that tool to like— I vividly remember those challenges. Yes.
Right. So then we networked it. Yeah. And then all of a sudden we were like, oh, You can use it for incident response. And then quite honestly, back to the earlier part of this conversation, endpoint detection and response wasn't a super well-formed category.
Yeah, didn't exist for a couple more years. Yeah, didn't exist for a couple more years. So we used it as an early EDR tool. Yeah, awesome memories, awesome time. We used to put on a conference called Enfuse, which is where all the forensic people went.
I made a lot of friends at that time in my life. Actually, kind of interesting comparison, right? One of the reasons why I feel like these localized security communities are so cool is because those people stick together. They're hardcore. You were there for almost 2 and a half years, it looks like, until you guys got acquired.
Could you give a little story around that? Yeah, I mean, this one gets super technical on the finance side, but ultimately that company, if there was one criticism, So it probably went public too early. That can create challenges just in terms of how a stock trades. And so without going into details, it really needed a liquidity event. And so once we made the pivot into security, it became pretty obvious that 2 things, it was going to take a lot more money if we were going to compete with— if you think back, that's when Tanium launched and Carbon Black launched, super heavyweight competitive landscape.
And so it was just a good time to exit the company. Yeah, it was good for shareholders, super good experience for me. Most people's first CEO job is in a public company, so, um, really grateful. It was awesome time. And you guys sold to OpenText immediately, is that right?
Sold to OpenText. And OpenText has bought a couple other companies we know locally. Webroot, correct? Um, and then was it— help me remember, what's the other big one they, they bought that I know? Security tool?
Well, the Webroot one is funny, right? Because those folks are here, right?
There were 2 things that I had always wanted to do with EDR that I'll give credit to the OpenText folks, they've tried to do. One was connect EDR with a backup tool so that if your file got known bad, you could just replace it. That always seemed obvious to me. They started to work on some of that and then The Webroot thing was funny because by that time I had sold the company and I wound up helping a firm that was looking at Webroot diligence Webroot. So probably the part of my career that's the least marked up in LinkedIn or whatever was I spent some time in private equity just looking at companies.
And so I got to look at 350 to 350 180 companies before I ultimately went to Aspect Software, many of which were security companies. And so it was super interesting. I can't be specific, but I looked at companies we grew up with that were getting a little older and thinking about how you could break them up and how you could spin them out and things like that. And then got a call to do diligence on Webroot, and they're like, now they're in Colorado, so you're probably going to have to make travel plans. And I'm like, yeah, from my garage, like up 25, right?
That's awesome. Yeah, super funny. Yeah, so the other company that they bought that I was thinking of is Zix. Oh yeah, yeah, yeah. If you remember Zix, the secure email platform.
Yeah. ZixMail.
Mark Baranchay at OpenText, he's the CEO, but he's also the CTO. Okay. He thinks pretty big. Yeah, he's an interesting guy. Awesome.
Yeah, well, uh, tell me, you took some time— is it venture capital or private equity? I've done both, right? I'm the chairman of the board of a company called Ripcord that makes robots to scan paper, read it digitally. That's backed by Kleiner Perkins, Google Ventures, Lux Icons. That's super venture-y.
And then more of my time is spent in private equity. Okay. So you mentioned, you know, your next CEO gig after Guidance was, was at Aspect, and that's a name that I remember, but I don't remember what they do. Yes, they were a contact center company. They were— had been around for forever.
Okay. Um, at one time it was a billion-dollar company. Actually, to your earlier comment, this is a good example. Missed the transition. Um, wound up in trouble.
Uh, we bought it out. In February of '19, I think.
Fixed it, turned it around, and then went on to merge it with another company and take the merged company and sell it to a private equity firm. That company's name was Alvaria, and that happened a summer ago. Nice. Yeah, yeah. So I think that I'm remembering aspects from when I worked in a call center.
Yeah, yeah. This is 20 years, 20 more than 20 years. Did you do outbound or inbound? Inbound. Okay.
I only ever had to do inbound. Okay. Which is a different kind, like you get angry people either way, but they're different angry for calling you. Yeah, yeah, yeah. So that would be where, yeah, using the contact center.
Yeah. Um, so that, so it looks like that's actually a couple of your next jobs here, Aspect and then Alveria. Yeah. Alveria? Alvaria, yeah.
Alvaria. Um, if you ever want to rebrand a company, it's not easy. And so Alvaro was a tricky rebrand because both prior companies, both Aspect and Noble, had very specific, well-known customer bases, and we were trying to get them to not just immediately retreat to the original brand. So it had to be pretty different. Yeah, do you think you were successful at the end, the rebrand?
For sure, it's so funny. If people call me and ask me about that, my first question is, who is the audience that you wanna rebrand it to? And in that case, we were rebranding it actually for the financial audience. That transaction was reported at more than $1 billion. I had to raise more than $950 million in debt to make the deal work, and Aspect had been troubled, so there was a lot of value in kind of trying to wash away some of the trouble.
Yeah, new, new company, new story. Let's hear this news. Yeah, and the users all know it for what it was. Yeah, yeah, awesome. Yeah, so yeah, you left there just this year, right?
This is not too long ago. Yeah, and, and it looks like you didn't take any time off. What's going on with that? That was poor planning. I was gonna say, man, that's, that's a lesson I think, I think we all should learn.
Take some time off. Take some time off.
It's probably the story, and if there's one thing you can't control in life, it's timing. Yeah, opportunity. Right? I mean, I'd wanted to work with this team at Bain and Crosspoint for some time. They're amazing people.
They do a great job with companies. And, you know, I had looked at 300 and some odd companies, and when I found ExtraHop and they sent me the material, you know, this is private equity and growth equity people sending venture and private equity person material, right? So it's not like I don't know what I'm getting. I've looked at that same material. For 300 companies.
300 companies. I'm like, this is the best company I've seen in 380 companies. Why?
It's a funny place to start. The product NPS is so high. Our product NPS score is always in the mid-50s. Yeah, that's great. Which is hard to do in the enterprise, and we really only serve the enterprise, and it's been that way for a really long time.
Yeah, that's one. So for those who might not know, you know, I'm from the product space, not everyone is. What's NPS? Net Promoter Score. And it's a pretty hard measure without like— don't judge me for those people that know I'm about to way oversimplify this.
You're basically measuring how many people would recommend your product versus how many people would be neutral or wouldn't. How many people are like out there saying nice things? Totally. How many are saying bad things? Yeah, totally.
And neutral people kind of get discarded. So it's, it's, it's a, it's a pretty tough ranking. Yeah. To put in perspective, like iPhone has been around a long time, but it's usually in the 70s, and I think that's pretty close to the most perfect product. Pretty, pretty close.
Yeah, right. Is it normally like Nordstrom's is near the top of the list? Nordstrom's does well. There's a few, there's a few companies that are known. Virgin Airlines I think there's a few.
Virgin does well, but most airlines are more like 15. Yeah, right. Or negatives. Yeah, or negatives. Yeah, I've seen— and by the way, I've seen negative software products.
Yeah, for sure. So the product score is quite good. The founders are awesome. Jesse and Raj are awesome, awesome people. Are they still there?
Yeah. Okay, so they were both original F5 folks. Uh-huh. Both strong engineering backgrounds, you know, brilliant people. Give them credit.
Like, you know, a lot of— I'm a professional CEO, right? I tried to build something early in my career. We talked about that, and my success was limited. So I have a ton of respect for the people that like really build stuff. Like, that's a different gene.
And not only did they build something, but they built something and then they realized like they could reapply it in a security use case, and it's done exceptionally well. And it takes a Takes a certain mind to build something, A, and then B, not be so wedded to it you can't see what it's really good for. Yeah, they did both those things. Super awesome guys. So do me a favor, just like give the high level.
When was it founded? What was it founded to do? Has it pivoted? 2007. Um, 15 years old.
Okay. Yeah, they put a ton of time, longer than I was guessing. Yeah. Um, and probably, I don't know if it's totally reported that way, but that's like roughly when they— yeah. Started it, originally had come out of F5.
They worked on network products, right? And so product started kind of solving network performance issues, which were, you know, at the time difficult. Is that competing with like a Gigamon in that space then? More like the APM guys, like those kind of folks. But then, you know, what's super cool about this tech is, and it'll become very clear really quickly, like, why the security use case makes so much sense.
Like, one, many times when performance is off in a network, there's some unusual event taking place. More and more frequently, one of those unusual events is something that is related to a security incident. Okay, park that. That's obvious, right? Next part, like, our tech lets you look at network traffic, look at packets, open them up, take a look inside and see what's going on.
And where I think these 2 really hit the grand slam is not only do we do that, but for certain protocols, we'll decrypt those protocols and look inside encrypted traffic. And this doesn't get talked about a lot, but these days, 70+% of an enterprise environment's encrypted, and for as much as that's great for all of us, it also gives a people a place to hide. And then the last part that the team did, and Jesse's team just does an amazing job on this, they started to realize that they could do behavioral detections and those kind of things using the advantages of cloud scale. So they were early on that. Without sounding cheesy, the artificial intelligence and machine learning, they do it in a really sophisticated way, which is like far too dorky for the amount of time we have today, but it's not the comic book stuff.
They take it super, super seriously.
It's been super effective for our customers. And then the last thing that I'm particularly proud of, I think it's the thing that I think is the most interesting about what we do.
We release these things we call threat briefings. And so when we see an incident, we'll go through and help a customer figure figure out like how would you use our tech to find that particular attack vector or solve for that problem. Or, you know, recently when the war started, we went and we took all the kind of common Russian attack principles and we put them into a threat briefing. And the first part kind of makes it easy for someone to consume. And then the second part is if we find a way to automate it, we'll automate it in the tool.
And what I'm excited about is between the time an event's identified and the time we release a threat briefing now, like, it's often like a week. Like, these, these folks are getting super good at that. And, you know, listen, I'm not telling you anything you don't know. In this industry where we're understaffed, things are happening more frequently. Getting like an assist like that from, you know, from one of the people you partner with, I think is a big deal.
Yeah. So why'd they hire you? What are you there to do? Well, one, I saw that EDR thing rise.
I probably have a little bit of a chip on my shoulder over that one because that was the right market at the right time, but I didn't have necessarily the right asset. If I could rewind the clock and if Guidance was private at that time, the EDR landscape might have been different. Who knows? Just because you can't take a loss to invest if you're a public company, is that— It's really, really, really hard.
Well, venture got really popular back then too, like more money flooded in. Yeah. And so there was a moment in time where Tanium was spending more in marketing than we had revenue. Yeah. And so there's hard to compete, just a resource issue, right?
We had we been private, we maybe would have raised more rounds and and tried to compete effectively. And you see how the chips fall, right? So I've gotten to see that cycle once, and I've gotten to see that cycle in a category we would consider adjacent, right? So I think of, you know, EDR, I think of logs like Splunk, and I think of NDR. Sure.
It's like, in my mind, what are going to be kind of like the big 3, right? So I've seen that cycle before. I do M&A for a living. Yeah. So I know how this works.
I've run businesses that are this big, twice this big, and then, you know, $12 billion. Let's hope we ever have that problem. Right. Right. So I don't know.
Maybe I'm a nice guy. Well, what are you going to do for ExtraHop? Like, if we meet again in 2 years and, you know, you had whatever wild success over the previous 2 years, what does that look like? Remember when I said it was the best company I saw in 300 $180 million.
That gives you the option someday to be public. That may or may not ever come to fruition or may or may not be the right thing to do, but if you pick the right company, you can put the odds in your favor. We have a shot. We have to execute really well. If you go back and you look at our trajectory and you look at CrowdStrike, it's very similar to what CrowdStrike was a few a few years back, and, you know, we'd be blessed if we had that level of success.
Yeah. Um, but I can sit here today, you know, at this moment in time and tell you, like, we have that opportunity. That's awesome. That's hard to find. Yeah.
So why is the CEO of ExtraHop sitting in Denver? Do you guys have an office here? Oh no, not yet. I have a, I have a place close by. We were joking about that earlier.
You know, I like to see customers, and I found over the years— this is a philosophical thing— some CEOs are very headquarters-centric. I'm not.
I have a really strong operating model, and I want HQ to run on the operating model. And if they do that, I can see customers a higher percentage of the time, both through the lens of helping them make buying decisions, which is where I grew up, so I'm very comfortable with it. We talked about that. But also because they give you the best ideas. Yeah, truth is in the field is a saying I believe in.
Truth is in the field. Yeah, if you're too close to your own HQ, you can make it a place to be. Hmm, you make it a place to be. I'd rather, like, quite honestly, I'd rather see them with customers. Yeah, you know, COVID— I mean, like, we probably don't want to dive down this rabbit hole, but Obviously work from home last couple of years have changed a lot of this, but still the philosophy is still the same, which is like, I would rather be close to a customer.
If somebody told me I have a marginal decision to make and that decision is go to HQ or be with a customer, they should go see the customer. Yeah, I love it. So what you— all right, we got lots of, lots of that. Anything more you want to say about Extrahop? I want— I don't want to cut you off if you want to give a quick sales pitch or Say who you want to hire.
Anyone you're looking for to hire right now? They might be listening. No, there's some big— so listen, we have some big jobs open. We have, um, we just hired a new CFO, a new CMO, a new Chief Legal Officer, and a Chief People Officer. A lot of change.
Holy smokes, a lot of change. Um, and so one, I mean, there's always sales positions open if people are interested in those. We We've scaled the sales force. We've almost doubled it since I joined. And that includes other kind of sales-oriented roles, sales engineers, those kind of folks, CSMs.
If you like to service customers, we'd love to talk to you. But then when you bring in an executive team like that, there's big jobs in the finance function that are open if that's something you're interested in doing and if you're interested in a company that has a future that's bright enough to consider something like perhaps going public, look us up. CMO is awesome. Christina is awesome. She has a couple of really super big jobs open.
So if you're marketing-oriented, she's amazing. You would be working with a CEO that also likes that too, for what it's worth. And yeah, there's some great gigs. It's a great place to work. And listen, part of the reason I took the job was You know, if we do wind up in a spot where times get a little tough here, like, I'm planning on building a great company during these times.
I think the best companies are built when stuff gets tough.
And maybe one bit of evidence of that is like we've seen some, you know, pretty big turnover in some of the bigger large tech companies right now. Like, hey man, come do something cool with us. Yeah. Right? You're plugged up in some Google or Facebook AI/ML thing that was like trying to figure out what recipe to recommend next.
Don't do that. Come visit us and help find a threat. Yeah, that's awesome. Well, I love it. I know you have a lot of happy customers.
I've talked with several of them recently. Folks are looking for more visibility on their network. That's not a bad place to start talking. You can't escape it. You can't.
The one part about the network is, for better or for worse, in our generation, I mean, someone made a decision that all this stuff was going to communicate the same way. You know, you can't get that coverage on endpoints just because they're, you know, like, doesn't even support them. And you got like, you know, manufacturing environments, healthcare environments. Any campus-type environment is going to have an awful lot of stuff that endpoint detections aren't going to see. We have a large retailer who has large screens in their stores displaying basically digital advertising, and they push digital advertising.
Yeah. And every one of those screens has a USB port. And yeah, you know, whatever, you know, we're on this podcast. Bad things can happen. You can go from there, right?
All right. Uh, I think I've asked everything I needed to ask. What should I have asked you that I didn't? That's a great question. I always use that question.
Well, it was super— it was, it was an awesome conversation today. I, I guess You didn't ask me this, and it's maybe not a question, it's more of a statement. So we moved to Colorado 5 years ago. Um, I did make the decision to come here in part because I was really interested in the community that's being built here. Um, and if you think about 5 years ago, the more obvious choice would have been like Austin, Texas, right?
We picked here, we love it here. My family here. We have a restaurant here, right? Super invested in this community. And I just say, I'm sure after listening to this podcast a few times, there's probably people that join this podcast like every single time you post something.
Like, don't take advantage of that community. Like, that's hard to build. And it's super cool that somebody's like taking the time to do it and curate it and all that. So You didn't ask me what I thought about the podcast, but I think it's pretty cool. Well, I appreciate it, Patrick.
This is— this has been really fun. Hopefully, like I said, we get together in 2 years and you can— you can tell me how— how, you know, we're on the other side of some amazing, cool stuff that I'm looking forward to hearing. Progress report, right? 2-year progress report. That sounds great.
Thanks for having me, Patrick. Thank you very much. And this is it for Colorado Equal Security. We'll talk to you guys again next month. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.