Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 238. What is it?
August 1st. August 1st. August. Gosh, Rob, I don't know how we got to August already. These kids are going back to school.
I know. The heat is on. People are going to Las Vegas in the middle of summer, which is the best time to go to Las Vegas. It's monsoon season with all these crazy thunderstorms, and it's been nuts. I'll tell you that.
But, you know, I know that talking about weather is a total waste of time, but let's talk about weather. It was brutally hot, and then all of a sudden the last few days. Yeah. Oh, down to perfect, like high 70s, low 80s. Yeah, that's the great weather.
Rain in the afternoon, even if it is thunderstorms. Beautiful hail taking down people's trees and so forth, but not my trees. So. Exactly. I love it.
Yeah, we were lucky at my house, too. Light hail, so not too much damage. Did you have your car parked in the garage? The Tesla? I had my Tesla in the garage.
We had some other cars not in the garage. Luckily, no additional damage to those cars. One of them was already hail damaged, so it's fine. I got hail damage on a car, and I know it sucked to get hail damage, but after I got hail damage, like, what do I care what happens to this car now? Who cares?
It actually is very freeing, right? This car now has no value to me. Other than driving it. If something happens, okay. Yeah.
Someone like door dings me, I'm like, yeah, have a good day. Right. Do it again. Whatever you want. Hey, let's talk about some housekeeping.
All right, let's do it. Uh, Rob, did you know we have a Slack workspace? It's great. We've got, uh, a lot of people in there. Lots of great conversations, new people every day.
If you're not there, you should be there. Go to the website, colorado-security.com, fill out the form. We'll get your information and we will add you. We will judge you. We will judge you first.
We'll find you, uh, fitting to be in our community or not. So, There are, it's very simple criteria. You need to be in Colorado. You need to care about security. We're not really checking on the care about security.
We assume by you applying to this that you care about security. So, uh, when you do apply, you know, give us some indication of the Colorado part, like your LinkedIn profile that says you're in Colorado or something else like that. Yeah. Yeah. Uh, while you're on the website signing up for Slack, once you go ahead and put your name or your email address in the mailing list so you can get our show notes in your inbox.
Um, we would also love it if you would subscribe to the podcast on your favorite podcatcher and maybe rate us while you're there. And maybe that'll help us find more folks. I don't know. I don't know if that works that way or not, but it, it can't hurt. Can't hurt.
Yeah. Can't hurt. If we're highly rated, um, then probably nothing will happen. My mom will appreciate that if nothing else. Yes, exactly.
Uh, also we'd love it if you spread the word, tell a friend about Colorado Equals Security and everything that's going on. And if you want to support us financially, we do have a Patreon campaign. Uh, we love people to be our patrons. We use that to cover the costs, uh, of the, the show and hosting and everything else. And, uh, money that we have left over, uh, none of this goes into our pockets.
We use it for something. Uh, in the past we've used it to, you know, buy swag and other things like that. But, um, we can jump into one of our next updates is that we're, we're having a picnic here in a, in a couple weeks. Yeah. Our first, our first Colorado Equal Security community event.
And the extra money that we have from Patreon is going towards that picnic. Yeah, super excited to get to do that. And of course, big thanks to the patrons we have. We have— I will say we have been losing patrons over the last 6 months or so. If you've been on the fence and you're thinking about supporting us, we'd love it if you would.
But for those who have been supporting us, thank you so much. And please, if either way you support us, you don't, we don't care. Come to the picnic. It's going to be a great party. We've got 150 of our closest friends RSVP'd.
Bring your kids. Can bring your dog. We're going to Clam Park. Yeah, bring your dog. Dog can be there.
But don't, don't bring your dog if it's gonna attack anyone. Yeah, we don't want that. Just bring nice dogs. Yeah, exactly. Additionally, some details on the picnic.
It's on the 20th of August. There is a link in the show notes that will direct you to how to sign up for that. Just, we want to know if you're gonna come or not. It also has the other details about the picnic. It's, you know, lunchtime to 3 or 4 in the afternoon, whenever we get tired and, and want to leave.
Um, and we're looking forward to seeing everybody. We will have free Chipotle for you to eat. And I have been guaranteed there will be enough guacamole for everyone. Um, and this is a big shout out to Dave Farrow for organizing the food and a big, uh, a lot of pressure on Dave's shoulders. If there's not enough guac, you know who to talk to.
Exactly. Uh, there will also be, uh, free non-alcoholic drinks. And if you want your own alcoholic drinks, those you have to bring yourself. You might want to bring your own chair. Yeah, I mean, maybe a camping chair or something like that.
There are picnic tables. There are a lot of picnic tables. But if you're going to have 150 people, there's not that many. You never know how much you're going to be able to sit. Yeah.
Anyway. All right. So, hey, we have a big conference coming up in Denver. Yes, we do. The Rocky Mountain Information Security Conference.
What are we, like 13, 14 years into this thing now? A lot. And it is the biggest deal that we have in security in Colorado. Alex, can you give us an update? What are we going to expect in September?
I sure can. First of all, for those of you that don't know, You can go to rmisc.org to find all of the information that you need about the conference, how to register, the sessions, the keynotes. If you want to sponsor it, there's information on sponsorship there. Whoever is sponsoring, their logos and all that stuff is on the website. All the information you need is there.
I wanted to talk real quick about the, the first day of the conference. So there's a couple of things that happen on that first day on Wednesday the 21st. So we have, uh, so 2 parallel things happening during the day. We have some paid trainings, uh, that, that are, uh, optional in an additional cost to the main part of the conference. And so you can learn some really cool stuff, but we also have a free community day.
So if you, uh, want to come that day and not pay extra, we have a, an all-day privacy session, um, that is, it's being organized. It's gonna be great. And we also have a, uh, small and medium-sized business security, uh, Uh, session. So that one, probably not for the folks that are listening, but, but maybe for a couple of you. But if you know someone that, uh, is an IT person for a small or medium-sized business and they want to learn more about security, this is a perfect session for them.
So I want to be clear. Do you have to have registered for the conference to come to the Community Day? You can just come to the Community Day if you want. So totally free. Totally free.
100% free. Amazing. Yes, it sure is. And that's the whole point. We want to give something back to the community.
Um, also in that, that evening, we do have our opening keynote, uh, for the event. And that is going to be Dr. Eric Cole. He is, uh, I think still, or at the very least, formerly of SANS. He spent a lot of time at SANS teaching there. So that's probably how, you know, his name.
Uh, he does some other things as well now. And a well-known speaker, was an advisor in the White House, I believe also. Awesome. So I think that's gonna be a really great opening keynote. Also completely free.
So if you're not signing up for any of the rest of the conference but you want to come see Dr. Eric Cole, you are more than welcome to come on Wednesday evening. There's going to be a reception, food, drinks, that kind of stuff. Free food. Yes. Also, the exhibit hall will be open that evening.
And probably the most exciting thing about what's happening on Wednesday is in the exhibit hall we are doing a game night. So we're going to have arcade games. Uh, we're gonna have, uh, like giant-sized cornhole, um, other games like that, uh, ping pong, lots and lots of fun things to do in the exhibit hall, not just talk to the vendors that are in there. So lots of stuff to do. It sounds like a really fun opportunity.
Uh, spread the word, guys. Everyone, let us, uh, let everyone who you know know that the RMIST conference is coming. Colorado Convention Center, uh, September 21st. Through the 23rd. Perfect.
All right, let's move on into some news. What do we got first? We got Red Robin has named a new CEO. They have actually named the former CEO of Torchy's Tacos as a new CEO, and I'm super excited. Yeah, so that— does it mean we're gonna get some trashy hamburgers?
Holy smokes, I can't wait. The secret menu from Torchy's coming over to Red Robin. So unfortunately, they're probably not gonna bring tacos over to Red Robin. You never know, burger place. I mean, they sell pizza.
Pizza is not hamburgers. Fair enough. So the new CEO is who? What's his heart? Something heart.
G.J. Hart. G.J. Hart, who? So he was the CEO of Torchy's and also California Pizza Kitchen prior to that.
And he's been on the board of directors for Red Robin for quite a while. He stepped down as the CEO from Torchy's back in November to spend more time with his family. Yeah. Apparently he got tired of his family and said, let me go run another company. You know, seems similar to Tom Brady.
I'm gonna retire. Oh wait, no, I don't wanna spend any time with my family. Who wouldn't wanna spend time with Gisele? Come on. I mean, I can't imagine anyone.
I can't imagine. No, it's, it's pretty cool though. Obviously a restaurant industry veteran. So pretty cool to see him coming to Red Robin. He was on the, I think you mentioned this, he was on the board of directors of Red Robin previously.
So he definitely had familiarity with the company. But great to see someone who's a veteran of the industry come in and, and hopefully beef up. Haha, no pun intended. Red Robin. Yeah, he had a lot of success at Torchy's.
They went from, I think it was like 50 or, or 40 branches into now having 90 restaurants around the US and really growing into a significant thing. And if he can bring that same success to hometown Denver headquartered Red Robin, we'd love that. He was also one that we didn't mention. He was previously CEO at Texas Roadhouse as well. Lots of big chains.
Is that even still around? It is. Yeah, you gotta live in the suburbs, Rob, like way, way out in the suburbs. Yeah, I do not. I'm right in the heart of downtown.
So you are, you're in the mid-suburbs. Yeah, exactly. Hey, hey, let's go into the next piece of news. You know, we love to talk about the Denver community and what's happening here. This was interesting to me that there are $2 billion in construction projects happening in downtown Denver right now.
At the same time as we have record office vacancy. Yeah, like they're building new, new offices and new space and they can't fill the current stuff. It's a little weird. It is interesting. And they also mention in here that this is on the heels of between 2018 and 2022, developers delivering $3.27 billion of development already.
So, you know, this is almost, almost $6 billion being spent in various things downtown. Um, some of that being, uh, condos, apartments, hotels, all that sort of thing. Yeah. So I, you know, McGregor Square, what was one of like one of the biggest developments here, if you guys don't know, it's a new development right next to Coors Field, actually owned by the Rockies. And it's, that's where the headquarters for Red Canary is and CyberGRX is in there.
Um, and, and like, that's where, so I get to go work in there. Uh, really neat space. It's just weird to know that they're building all this new stuff and And there's all these offices sitting empty. I would imagine that, you know, this is just because you have to make these plans years in advance. I hope that we can get some equilibrium here and hopefully, yeah, get more of this stuff filled.
Yeah, that was one of the things I was thinking, Rob. You know, it takes a long time for these projects to come to fruition. And so I'm sure these were being planned long before the pandemic. Also, to me, you know, this is not a sponsored post or anything, but this post almost read a little bit to me like it was like an advertisement for downtown? Like, hey, there's so much stuff going down on downtown.
Maybe you guys should all come back to downtown. Yeah. Uh, there, as it was talking about the things that are coming, you know, one of them is a major renovation at the Colorado Convention Center. Um, another one is a, a bunch of reconstruction of the 16th Street Mall. And you know, if you haven't walked along the mall recently, it could use some updating.
It's, it is definitely, I think it's date become dated very quickly. Yeah. Yeah, and I think also one of the things I was reading when they were talking about doing that project was that the, the mall is beyond its useful lifetime in terms of, you know, what they put in there. The— they only expected it to last a certain amount of time and we're well beyond that time. So it's definitely due for a renewal.
So I did— I just do a little bit of digging on what's the 60th Street Mall renovation going to be. Main objective of the renovation is an underground infrastructure and installing new granite pavers. Better drainage and lower maintenance costs. So it's just going to clean it up and make it, make it a little bit better to walk along and drive along, all that good stuff. Yeah, good stuff.
All right. Next in the news. Yeah, there's some bad news this week, I guess. Mostly bad. You know, we had talked previously about Sprint and Frontier and the merger that they were going to— Spirit, not Sprint.
Sorry. You know, almost the same thing.
You know, Frontier Airlines and T-Mobile, their merger and— oh, sorry. Anyway, Spirit and Frontier merging. Well, that's not going to happen. The deal was called off. And shortly after the deal was called off, Spirit accepted the offer from JetBlue.
That was, you know, one of the reasons why this has been held up. So now Spirit and JetBlue will merge. Frontier will go out on their own. Yeah. And I still think that there's risk on the Spirit and JetBlue merger.
Like, the reason, if I remember correctly, that everyone expected the Frontier acquisition of Spirit to happen was because they thought there'd be regulatory hurdles that, that JetBlue wouldn't be able to get over. So it's weird to me that now everyone thinks it's a done deal this other way. But, but Frontier is going forward as though they're not going to be buying Spirit. And, and the same day that Spirit announced that they were rejecting Frontier's bid to go after the higher JetBlue bid, uh, Frontier announced their record earnings and their massive growth that they've got. And like, hey, whatever ugly person I'm going to keep going anyway.
Like, right. They're definitely ready to keep moving on with their life. Yeah, they had some, some definitely some positive spin on, on the merger not going through and how now they're going to be the only, you know, budget carrier that's left. And that, you know, really puts them in a unique position. And it was them and Spirit.
And I guess the expectation is if JetBlue buys Spirit, Spirit will become more like JetBlue, which is less of a budget. So, so that now Frontier will be the only ones there who charges you $10 to bring your wallet on the plane. Is that— but, but only, only charges you allegedly, excuse me, allegedly, but only charges you 50 cents, 50 cents for the ticket. Right. So yeah, it's free to come on, but if you want to bring your eyebrows, it's going to cost you.
Every step you take on the plane is $2, but it's, it's Denver's hometown airline. It is. So we love to see them succeed. Exactly. One of the other things that I think they were thinking about when this was gonna happen was that Spirit and Frontier have similar fleets in terms of their airplanes.
Spirit and JetBlue do not. So there's some synergies there. But anyway, we can move on. Hey, let's go ahead and talk about our favorite thing, more blockchain and NFTs. If you don't know what a blockchain or an NFT is, then this is the part of the episode that you're going to enjoy the most.
Well, or why don't you put us on pause? Go out and figure that out. We'll explain it all. We're gonna simplify this whole thing. All right.
So there's a Denver-based insurance broker who has made the first ever insurance, I guess, what, like policy on the blockchain. So the company is called IMA Financial Group. And they went— some of this is just even hard to even say. They created a policy in Decentraland, which is a metaverse.
This is a metaverse location where they have, where they have minted an insurance policy. And okay, so we're going to spend a little bit of time talking about NFTs today. And no, we're not. We're like very, very little bit on the surface, not getting into it. But we're going to spend a little bit of time about it because we have another article coming up about NFTs as well.
I think most, mostly we scratch our head and say we don't understand it. At least we understand the idea of Hey, if you're going to mint an insurance policy, it's really nice if, if the, if someone on the other end can look back to see, hey, it was really minted by a real insurance company and it's still valid. Sure. And that's what the blockchain is doing here. Yes, there might be other ways to solve it.
It might not be the only way you could do this, but it is solving a real problem. And IMA Financial says they're, they're not doing it now because it's like the most expedient way to do it. And it's like the best, best technology for it. It's because they want to be there first, right? They think it's the future.
So they want to try and make sure that they're, they're not late to the game with getting into the NFTs. Right. I will say that was in my mind, the positive thing out of this article. IMA said, you know, hey, we realize this is not something that we need to do right now, that it's not necessarily adding anything today. But we feel like this is going to be the way that things will happen in the future.
And so we wanted to, to try it out now, right? Like, we realize this is a bit of a novelty, but we're doing it anyway. That's the time to do it, right? That's the time to do it. Right.
So basically, they made an NFT. That NFT is, is a representation of the insurance policy. So now you can prove that this insurance policy was, was made invalid on the blockchain, and who owns it. And just like the cheeseburger was first patented, or whatever it is in Denver, the first insurance policy was minted in Denver. So there you go.
We get to win this, or at least Colorado. Yeah. So I'm going to read a sentence, Rob. It was part of what you were talking about earlier, just because of, I think, of just the absurdity of this sentence. In March, IMA unveiled Web3 Labs, a research and development facility in Decentraland, which is a virtual world based on blockchain technology.
Yeah. And you know what the crazy part is? They don't go on to say, let me explain that sentence that you just read. No, they just They just put it out there. I think the, the author of this article's like, I have no idea how to explain this any further.
I'm just gonna put this out here. Just gonna move on. Yeah, exactly. Anyway. All right.
Speaking of moving on. Moving on. We've talked about Scythe Robotics before, I think, but a couple times. Yeah. They are a Longmont company that builds automated lawn mowers, robotic lawn mowers, and they now have done an expansion where they're gonna create about 400 jobs because they're building a Longmont factory to build their long— their robotic lawn mowers.
You guys are absolutely crushing it right now. Yeah. Um, they have 7,000 advanced orders and they are excited to get their first 10 out the door. Right. So they, they have a lot of capacity to go.
They think that they can get 200 by the end of the year. Right. So they, so they, I mean, this article is mostly talking about they, they got some state funding to to keep them in town and to build their factory in Longmont versus them going to Florida or Texas or wherever else they were thinking about. But there was lots of interesting stuff in this article. Like you mentioned, they're hoping to have another 200 built this year.
But they say that once they get their 50,000-square-foot facility completed, they're going to be able to make about 10,000 machines a year. And this is— I mean, the article is great. It goes into, hey, you know, mowing grass Man, you don't probably need a skilled human for this. If you can get a technology to do this for you, it's awesome. And this is especially, um, this is an especially good thing to keep in the country because these things weigh what they said, 1,300 pounds, over 1,000 pounds for a lawnmower, which I mean, I can barely lift that much.
So trying to ship that thing across the ocean, you know, that's going to be expensive. You know, keep it, keep it local and, and, uh, you save some money on shipping. Yeah. I think it's awesome. I'm glad they're going to be doing that here.
And I look forward to dying by being run over by an automated lawnmower. They do mention that, like you said, they're going to be hiring almost 400 jobs here with an average wage of about $116,000. Yeah, $117,000. Big boost to the economy. That's pretty cool.
We love to see that. And more jobs, more money. Good for everybody. Indeed. All right.
Moving on to our next story. This is one that, you know, it's a little mixed emotion here. It's a list of the, the busiest airports in the world, and Denver is not number one. But we've never been number one on this list. I think at one point during the pandemic, we were number one.
Okay, but not at a year-end list. No, no. And that's, that's sort of a fake number anyway. But, but yes, it's still a good number. Denver was the 3rd busiest airport in the world.
You know, wouldn't it I mean, I know it's kind of fun to like talk about these lists and stuff, but wouldn't it be better if we were like number 7,000 on the list? Like, hey, I keep going to the airport and there's nobody there. Yeah. I mean, it's, it's a give and take, right? Like you don't want it to be so crowded that it makes it hard for you to travel, but the busier the airport is, the more options you're going to have for flights.
It is great every time we get a story about a new direct flight to a new European city or, you know, Now you can fly direct to to Puerto Vallarta or to to Costa Rica or whatever. Like, I love that. Hawaii, Hawaii too. Yes, all three of those not in Europe. Just just so we're aware.
Well, I was saying or Europe or these other places. Okay, that's fair. I remember them having a new was it? I think it was Frankfurt maybe or Paris. There was a recent Paris announcement.
Yeah. Rome. I think there was a Rome. Yes, there was a Rome announcement also. Anyway, I think one of the things that I took away from this is.
Denver is not far off from their pre-pandemic levels. Also, you know, even with potentially, potentially less business travel, still Denver was only down a little under 15% versus 2019. It's good to see Denver. And actually Denver is doing better versus their pre-pandemic than— we didn't even talk about the ones above them, right? Atlanta was number 1.
Yeah. Oh shoot. What was number 2? Was it Chicago? Chicago?
O'Hare? Or no, no, Dallas. Dallas. Dallas is number 2. Yeah.
So we got Atlanta and Dallas ahead of us, but Denver at number 3. Yeah. And, and we had had a less significant drop-off than those other 2. For sure. And if you, you had to go to, like, number 7 or 8 on the list to get outside of the US, and then it got to China at that point.
Yeah. I, I think there was one that was in China that was, it was, it was the number 1 in the world for, for a little bit. And not surprisingly, they're much farther down because of the, you know, lockdown status and the restrictions. Zero COVID policy. Right.
Yeah. That have been happening in China still. So. All right, well, let's— I'm excited to get to our second NFT story of the day. This is another Denver Business Journal story, also written by the same author, Nikki Wendling.
And this one is going into— I think Nikki maybe had learned about NFTs in her IMA Financial article and was like, let's see, are there any other companies doing this? And she found 3 other companies in— actually more than 3 companies in 3 different industries who are using NFTs in different ways that solve Nothing. No problem. Absolutely nothing. But they're playing with some new technology.
Yes, they're playing with new technology. Good for them. The first area was, was around Farm. It's a land restoration investment platform based in Fort Collins, and they were essentially selling NFTs sort of as a fundraising effort. Right.
Almost charitable contributions. Yeah, almost. Yeah. I mean, it might not be charity in terms of government, but from our perspective, It's to help protect these lands. Right.
Right. In theory, you could resell these tokens and maybe make something for it. But I don't think that's the point. The point is really the original intake of money by them. Yeah.
And there's a direct quote in here that's like, yeah, this is— I'm trying to find the exact, the exact sentence here. It's more about the restoration and following along with the progress and being reported to and less about I want to make X number of dollars for every dollar I put in. Basically what I hear from this, you know, end quote, what I hear from this is Hey, you're not making any money on this NFT purchase, but you're gonna be able to help, you know, make a difference in these, these lands that you're protecting. They also do note that this is sort of a test. Yeah.
You know, and I think that's fair. They're not saying this is gonna solve all the problems, but it's looking at different ways to bring in some money. So second, the second area is 3 local breweries who went in together to create some NFTs. This is kind of an interesting thing. It was Resolute Brewing, Denver Beer Company and the Great Divide Brewing Company all together.
They each get to sell 6 NFTs, so a total of 18 that give you some, some like ability to go do a tour of their different breweries and like get picked up in a private bus and get some free beer out of it. It's really interesting that like the idea of buying an NFT to me is I get the NFT, right? But here it's you get the NFT and by the way, here's some benefits that come along with that. Yeah. And again, I think they're doing this as experimentation.
So they're offering some things that are, you know, free to low cost to them to help spur the sale of those NFTs. I think it was one of them, Denver Beer Company actually had done a previous NFT project, sort of selling NFTs a little bit like coupons. You know, you got the NFT and something else free that went along with it. So some interesting things there. And Oh, go ahead.
I was gonna say that the owner of Resolute Brewing Company, Clifton Ortley, um, he, he says, hey, there's a lot of barriers to getting involved with this and with, with NFTs, and he's just trying to bring those barriers down for customers. He says, we're always looking for opportunities in the brewery as well as in my Web3 communities and how we can bring this into the real world. That's end quote there. So he's, I mean, just trying, like you said, it's, it's not about like that they think these NFTs are super valuable, but how do you make these— this technology more approachable for humans and, and try and start to make it more comfortable? Yeah, exactly.
And the final one is, uh, with Outside Inc. People are probably aware of Outside magazine, and, uh, they are selling, uh, NFTs. And the, the NFT gives you a 3-year subscription to Outside as well as, uh, the access to a marketplace where there's going to be NFT-based art And that art comes with some other benefits as well. So again, you know, a bit of experimentation here and NFTs coming with a value of something other than just the NFT itself. Awesome. All right.
That is enough NFT conversation for the year. Yes. Can we maybe not do it again this year? I'm done. I'm good.
All right. Let's jump into some of our security news. LogRhythm has some changes. I know we've been running a little long today. So summary here, they've got a new CTO.
They've got a new CFO, and most importantly to us, they have a new CISO. Yes. James Carder moved on to a new position, and his deputy CISO has moved in to take his position. He is now the CISO. He's actually not based in Colorado.
I believe he's based in England, if I remember right. He's in London. Yeah. And also because of that, as we get to the jobs, you'll see they are now hiring a new deputy CISO since that role is open with the promotion. And I just want to correct myself.
They have a new CR. CTO and a new CRO, not a CFO. So head of sales, chief revenue officer. Go ahead. Uh, next we have a blog post from Red Canary, uh, one of their Better Know a Data Source articles.
This is talking about logon sessions. So this is one where they do a deep dive on a particular type of data that you can use as part of detections and why it is you might use them, how it is you might use them, what value they bring, how you collect them. All those sorts of things. So a lot of interesting technical deep dive information in this blog. Yeah, what I get from this is, hey, you know, just having just login information is not very interesting.
Like maybe you might get a brute force and like that might be good, but when you're able to correlate that login information with other things to start to see that bad behavior happening with this account across multiple places, that starts to get really interesting. It's that correlation that, that gives the power here. And I thought interesting article, worth a read for, for folks there. Yeah. Our last story in the news here, we have an update from our friends at CloudRise.
CloudRise, if you guys remember, they're the kind of services around CASB and DLP. They had put their headquarters out in Grand Junction, and they're partnering with the universities at Mesa State out there. And this is our friend, Rob Eggebrecht, who is the CEO there. Anyway, they've announced that they have raised $10 million in a venture round. Yeah.
And I think that this, this raise has been going on and that they've now announced the close of that $10 million round. Um, so that they are finished and have that $10 million. Um, one of the things, and you know, we've talked to Rob about this, that, um, you know, they went to Grand Junction because of the Greater Colorado Venture Fund and some other people that convinced them to do that, to try and, uh, take tech and and startups to other places within Colorado. So that, that's pretty cool too. Yeah, very cool.
They also have kind of a, a list of their momentum for 2022 in here. They acquired a company called Cyber Orchard, which was a services company out of the UK. They got a new CTO. They were named Netscope's Global Services Partner of the Year, put on Managed Security 100, um, top 100 list by CRN magazine or website. Lots of good stuff this year.
Good to see CloudRise kicking butt and making progress. Awesome. That is all of the news. So why don't we jump over to events? As a reminder, we have a calendar of events that I actually just, just tonight went and added things out all the way until November, I think.
So if you want to see what's coming up in the area, you can do so. On the 10th of August, the ISSA Denver group has their privacy special interest group meeting. On the 16th of August, Colorado Springs ISSA is doing their August meeting. On the 17th, OWASP, uh, the OWASP group, it's actually a combination of Denver and Boulder's OWASP, are doing a meeting, uh, that the topic will be The Insider's Guide to Mobile AppSec with OWASP. I don't know how you say this.
MASVS, I guess. That's on the 17th. Yeah, and that's at Dave Buster's. Uh, on the 19th, the Let's Talk Software Security group is doing, uh, a session with Making the Business Case for Software security. On the 20th, we have 2 events.
Colorado Springs ISSA is doing their August mini seminar, and that is the day of our picnic that we already talked about. Indeed. Oh, oh, for the picnic, you should bring your best dad joke because there will be a dad joke competition. There will be. Uh, on the 24th, we also have 2 events.
ISSA Denver is doing their August meeting, Cybersecurity is Like a Game of Poker, and, uh, ISC2 Pikes Peak is doing their August meeting. And then that's it for August. But looking forward to September, I wanted to shout out that the ISSA Colorado Springs group is doing a 3-week session of preparing for the Security+ certification that starts on the 10th of November— of, excuse me, of September, and it goes the next 2 weeks after that. Absolutely worth it if you're a member of ISSA or if you're not. It's a really affordable way to get this training.
I've had multiple employees go through this in the past. Really high quality. Highly recommend you guys sign up for this in advance and make it down there for that. Yeah. And just one other reminder after that, not too, not too far after that.
Again, RMISC is the 21st through the 23rd of September and registration is open now. So you should go ahead and get out there and register. All right. With that, we can jump over to jobs. We found a lot of great jobs for this podcast.
The first of those Bank of America is looking for a SOC Level 1 analyst in their cybersecurity defense group. The state of Colorado is hiring a director of security risk compliance. It can be anywhere in Colorado. Yeah, it is. It's interesting now that the OIT jobs are generally anywhere in Colorado, not having to go into the offices in Denver.
Yeah. Ibotta is looking for a senior information security analyst. Deloitte is hiring a cybersecurity ransomware readiness reporter. Reporting analyst. Yeah, Deloitte's title of the week, uh, potentially.
Um, Deloitte had lots and lots of open jobs. Many of them are listed other places but can all be done remotely. Uh, this is internal security, by the way, not, right, uh, consulting at Deloitte. Uh, Lumen is looking for a senior lead information security engineer slash vulnerability assessment. LogRhythm is hiring that deputy CISO like we talked about.
Charles Schwab is looking for a manager of IT audits and SOX compliance. Vail Resorts is hiring a Director of IT Security Operations and Engineering. Motive Care is also looking for a SOC Operations Analyst 1. And finally, RTD, the Regional Transportation District, is hiring an analyst for information systems risk. I assume this is working for Tim Coogan.
I would assume as well. So Tim, be a good opportunity to get over there and work with a great team. Good stuff. That is it for the news. We did spend a lot of time on the news.
This is what happens when we record on an evening. Indeed. However, we have a— we have an interview this week as well. Crazy talk. So big thanks to Courtney Chenault, who is a friend of mine from Ping and a great sales leader over at Snyk now.
She sat down with Julie Chickillo, who is the head of security for Guild Education. I know you and I have known Julie for years. We love having her as a part of the community, and this is our first time getting her on the podcast. I think that's great. I love Julie as well.
I love Julie so much She is also going to be part of one of the keynote speakers at RMISC. So hopefully she'll whet your appetite in this interview. Indeed. Show up to the conference. Indeed.
All right. Well, that's it, right? That is it. We can let everyone go for a month. Yep.
Well, we'll see you in September. All right. Thanks, Rob. This is Clay Parker, Director of Security Operations at Trimble Navigation. Welcome to Colorado Equals Security for Colorado security professionals by Colorado Security.
Good afternoon, Julie. How are you doing? Good. How are you, Courtney? Doing well.
Thank you so much for joining today. It is a pleasure and an honor to interview you. I look up to you a lot, and I'm such a huge fan of Guild. So thanks for joining. Thank you.
I appreciate the offer to join you this afternoon. So for those of us that are not familiar with Guild and with your role there, tell us a little bit about yourself and your role at Guild. Sure. So Julie Chickillo, the VP of Information Security at Guild, a late-stage startup here in Denver. Guild's been around for, I believe, a little over 6 years at this point.
I joined in 2019 to build out the security team. There was very little in place at the time, so really coming into a modern technology environment, they asked me to come in and build out a practice that met the business where they were at. Um, and so 2, 2 and a half, 3, 3 and almost 3 years later, um, uh, still, still building, still building out the team, still building out the practice, um, and just trying to keep up with the technology. That's awesome. And I'm really excited to hear your perspective both, you know, at Guild and from your past and how you build out a program based off of the type of organization you're walking into.
So super excited about that. Before we go there, tell us a bit about what it's like to work at Guild. Oh, sure. Guilds— so besides being a late-stage startup, we're also a B Corp, which means we have a double bottom line. And so a large part of the business is around doing the right thing.
So other B Corps out there are like Ben Jerry's, North Face. So companies that have not only committed to having a profitable company, but they're also committing to doing the right thing. And so Guild, really, we focus on— focus a lot on what's right for our learners and what's the right thing that we should be doing to help people in America skill up and make a better life for themselves. And so that's really different from any other place I've ever worked where it's a daily conversation about how do we do the right thing? How do we— how do we make sure that we're looking to the future?
And we're not just focusing on making money. I mean, we do focus on that as well, but also focusing on how can we help American learners today, especially those that are working on the front line or those that have never had an opportunity. And so it's just really inspiring. The other thing is being a startup, late-stage startup or earlier startup when I started, it's a bit chaotic. There's a huge growth.
When I started, I was around employee 400. We're around 1,500 people today, and all that growth happened— a lot of that happened in COVID. And so it's just, it's a bit chaotic but fun because everybody's really focused on the double bottom line and trying to support the company and learners, but also growing as fast as we can. That is so awesome. And I really enjoy looking at your LinkedIn posts and seeing all the amazing investments and partnerships that Guild is making constantly.
For those listening, if you're not familiar, Guild works with the likes of Disney and Walmart and Lowe's and Taco Bell to help their workers upscale or upskill themselves and have opportunities to have more relevant skills in the future and, and have jobs that are more meaningful so they can support their, their families more effectively. So really amazing. And I also think there's an interesting element here since you're in security. There's a massive lack of talent in this space. Do you feel that?
And is there— how are you thinking about that, that lack of talent? Definitely. So I, um, especially with the more modern practice that I have, I definitely feel the lack of talent. Um, when we, when we post a position, uh, our recruiters may have to speak to over 1,000 people before we get even one person to apply, uh, to fit, to fit a position where we're asking people to understand not only modern technology but a more modern security practice, and then on top of that, sometimes scripting skills such as Python. So for me, working at Guild is a way for me to also support helping other security teams in the industry build out their own pipeline.
One of our, one of our customers, Walmart, actually has a great program where they do hire from within, and they are using the security part of the catalog, the education catalog that Guilds helps connect the learners with. And so it's just amazing to see our own and partners really embracing this opportunity to take people working maybe a cashier's job at Walmart and learning new skills and getting a junior position on a security team. And so it's very inspiring. It's inspiring to me every time I hear these stories, and I just, I really appreciate the Guilds trying to find the right fit for all of our employer partners, looking at the catalog and understanding the technology. So I do consult on that a little bit.
I do try and help tell them what's important to me, but also understand that, that some of the larger companies may have a more legacy environment. And so discussing with them maybe some of the, the certs that are certifications that are probably more appropriate for a a more legacy environment. That's awesome. I hadn't thought about that, but I guess what things have you brought to the table as far as your focus areas and the things that are most valuable to you when you look to security folks to hire potentially from your own, you know, customers' organizations? So really want somebody with AWS knowledge.
We really focus on that. The other one that I would focus on currently as we build out the application security part of the practice We look for somebody who is actively pen testing. Maybe they're consulting, they're doing bug bounty, or they've had some experience with it at another company, or somebody who was an engineer getting into security. And so we do also try and build out incentive for engineers to learn a little bit more about security in the hopes that someday one of them may make a transition over. Or just speak about it.
If we were, if we were to evaluate the catalog itself, the Guild catalog, for, for what offerings are out there, I do try and ask the internal team to focus on, hey, cloud first, can we get some cloud certificates in here, but also making sure that people have the fundamentals. So if you're going from a cashier position to a cloud security engineer, that, that's a bit of a jump, so maybe learning the fundamentals first. Uh, focusing on those early certifications, uh, and then, and then having— looking for people with the right mindset. Uh, you can take somebody with an early, like a junior career, and with the right mindset you can work on scaling them up or focusing them on the right certifications that you need for your environment. Absolutely.
Yeah, that's great. And I love that you mentioned engineers. And many people that are in the security space, I think it's a constant struggle between security and engineering trying to work together effectively, but oftentimes feeling like your incentives are at odds or you're not speaking the same language. One thing I've heard you say many times is talk to the engineers. Tell us a little bit about your philosophy and how you work with engineering.
Yeah, I think talking to the engineers, it's easy to say that, and I do feel like I've probably thrown that out there one time too many. So what I mean by that is really understanding their language. And so really understanding in the beginning that the engineering team, software engineers, have their own language, they have their own philosophy, they have their own culture, and just the same as a security team does. So if I'm saying SIEM and I'm throwing around SOC audit, or I'm throwing around SAST and DAST, like those, those things security people understand. If you're, if you're in engineering, there's different words they're used to hearing— containers, Lambdas, pipeline, PR.
So they're— it's a different language. And if you don't understand it and you're not speaking to them in their language, they really don't respond very well. It's clear you didn't take time to understand what they're doing. And they really do better when you take time to really understand their philosophy, what they're working on, and their language and mimic it. Another interesting one that we're starting to see emerge really in the last year, there's probably been a movement for a couple years, but really starting to see a clear movement in the guild environment is that there's a big move for DE&I work in the language that the engineers are using.
And so making sure that we're staying on top of if they no longer want to use like master and slave for obvious reasons, that we're mimicking that, that we're changing our documentation, that we're We're ensuring that when we show up, we're, we're listening to the words that they're using and that we're speaking their language. I think the other part of talking to the engineers is it's not talking at the engineers, it's talking with them and taking the time to let them tell you their fears, their concerns, their roadmap, so that you're not just walking in and saying, here's my agenda, here's what I'm going to do. And here's the timeline and leaving the meeting. So they really, they really need the opportunity to feel like they were heard, not just feel like they were heard, they need to be heard, and you need to let them know that, that you, you heard them by using either the same language or responding to their concerns. So I think those, those are the— that's really what I mean when I say talk to the engineers.
I think the other thing that I would say when I'm saying talk to the engineers is don't pick one. You really need to, again, going back to the philosophy, there's probably very different groups within the engineering department. They probably all have different— there's a hierarchy, and they all have different roles. And you can't just pick one and be like, I'm going to talk to this architect over here. That's an architect for one area.
They probably don't represent the whole community, and you need to make sure you're hitting the different areas of engineering. So that you're, you're covering all the different aspects and all their concerns and not just one small area. Absolutely. And from everything you're saying, it's clear that you've gone the extra mile to understand, to be a partner to engineering and to really understand their world so that you can work with them more effectively. This may be self-evident, but why do you think it's so critical to be able to speak the same language as engineering?
Um, I think the first is respect. It's a sign of respect. Um, to— they don't— they're not incentivized to speak to me. So if I'm not using the same language and they're not really wanting to talk to me in the first place, they're not gonna— they're not gonna turn around and research all the— all my security terms. They're not going to.
So it really helps to smooth the pathway and the conversation. It helps to gain their trust. And it just helps me to show up like a partner. I'm showing up as a partner. And so eventually they'll learn your terms, they will learn the security terms, but it's on their own schedule.
And so just, it's, it's a way to show respect and gain trust. For sure. And ultimately there's, you know, typically a 1 to 100 relationship between security and development. And so What I love about what you're saying is you have the security capacity that you need. It's called developers.
If you can get engineering rowing in the same direction as you, your ability to succeed is just massively improved. So, really cool approach there. And I think that a lot of people talk about it, and shift left is such a— it's a buzzword right now, and everybody's talking about that, but bringing it into practice, I think, is complicated, and I think that there's a lot of nuance. So, What advice would you give listeners that are trying to improve their relationship with engineering apart from learning the terminology that their partners use? Yeah, that's a great question.
I totally agree shift left has become a big buzzword, and I think you'll see a lot of security companies tout shift left or say, oh, shift left, without— not that they don't understand what that means, but they may not even— it may not even be a part of shift left. Truly understanding shift left means understanding where the engineers are at in their development lifecycle or their maturity level. So if you have a team, if your team is working waterfall or they're deploying code once a year or every 6 months, shifting left for you is not going to mean the same thing as it does for somebody like myself where code is being pushed into production daily. So, and I think when you're starting the conversation with your engineering team, I have heard, I've heard a lot, I've heard some leaders be frustrated, like my engineering team isn't advanced enough, they're not doing this modern practice. So I think you need to understand where they're at and meet them where they're at.
And you might not get to, they might not be ready to move into like a DevSecOps type of practice, you may need to just work with them where they're at. And if it's waterfall, create a process that meets them. And then as they mature into this space, as they mature into more of a DevOps practice, or they start moving into daily push to production, or even weekly or twice a month, you'll have gained their trust that you were listening, and, and they'll start asking you to come along. So hey, we're going to move from, from waterfall where we deploy every 6 months to quarterly, you know, shift, shift your process, talk to them about what that means for you. And then, you know, as they go from quarterly to monthly, you know, that's a different shift.
You can continue to use the security tools that don't require a fast scan in these instances. So maybe just talking to them about, okay, when you reach a certain threshold, I need to find a different security tool, and making that, you know, having that conversation with them up front, but still supporting them where they're at. Because shifting left every 6 months means you're probably— you can't— you can still— you can still shift left. They— maybe there, there's ways for you to provide constant feedback or more timely feedback to them before the end of 6 months, and just understanding what that, that means to them, like what would be helpful. And then including their product team.
Usually if there's a product team involved, they may also be a good place to to start to understand the lifecycle. Absolutely. And you brought up a really interesting point, which is different companies are at different places. And even between different teams, a lot of people listening here may have app landscapes where part of the landscape is super legacy and part of their landscape is cutting-edge innovative technology. How would you think about coming into an organization and trying to build a program a security program if there was a super heterogeneous app landscape?
Have you dealt with that before? Um, I, I have. I haven't recently. I haven't had to do that recently, but, but if I did, if I had that situation, I don't think I would approach it any differently than I do today. Uh, I think the most important thing is, in this case, same thing I would do today.
I would, I would look at the whole engineering org. Really understand the different parts. And so this meet— this could mean different code base, it can mean different deployment practices, it can mean different technology that they're deploying to or that they're sitting on top of. And when you start to build out your application security program, you need to understand all of those different parts. One, it's likely one tool, one practice will not go across all of that, especially if we're talking anywhere from a very legacy all the way up to the cloud, you may be looking at several different processes and tools at this point.
But the only way you're going to know is to talk to the teams and talk to them about, okay, where are you? When you start your proof of concepts or you start to build out what you're going to do, make sure each of those parts has a seat at the table so that they're telling you, we use this type of— we use these languages, we're using this technology. So whatever you buy or use needs to work on my— in my process. At that point, you can then break them down into hopefully logical groups. Had to do that in the past, or you may say, okay, out of 6 groups, 5 are going to work here, and we're going to have to figure out a one-off for this last group.
I have had to do that in the past where they're using a code or a language that we just couldn't get supported. And so we will say, hey, we'll support you there. Is there a roadmap for moving off of this? So you also need to understand, like, just because they're coming to you with legacy technology doesn't mean they want to be there. And you really should understand their roadmap.
So when you have buying power, you know where to put your money. So in the case where I have 6 groups, one's an outlier, I may make a decision to say, okay, all my money's going into these 5, and we'll figure out something cheap for now on the, on the last one, or, or free. And we'll put our money where the 5 are. So I think that's important. But without really starting to have those conversations and sitting down and understanding the practices, you're just not going to— you're probably not going to pick the right tool.
So I think that would be— it's the same advice I would give somebody who walked into the environment I'm in today. Investing in the future and investing in the roadmap while understanding today's reality is a beautiful way to think about it. I'm sure it's a really hard balance, and it's a lot easier to talk about than to do in real life. But absolutely, if you're only making investments based off of the most edge case or that one stalwart group, I'm sure you can find yourself in a tough position down the road when you need to be able to move fast on new things. So it makes a lot of sense.
Definitely.
So if you had to choose, would you rather— actually, I'm going to ask a different question. What do you think about a lot of the security tools that are out there that have been around for a long time and are trying to catch up to the DevSecOps era? How do you think the vendors are doing? Talk to us about that. Oh, this has been a great frustration for me.
Um, I, I think one of the problems that the security industry has is the same one that like a lot of security professionals have had, is that they, they see the buzzword, they understand that something's different, but they haven't quite understood What's different? And so they're building new product, they're building new tools, or they're trying to put a square peg in a round hole and say, okay, this, this old tool will work. Here's how you shove it into this process.
And then put shift left on it. You're like, oh, shift left with our tool. Okay, that, that didn't meet the process where it was at. You just put shift left in front of your, you know, product description. So I think, I think that's my biggest frustration is that when you, when you go and talk to the vendors, when you get on a call with them, ask them the hard questions.
Bring an engineer with you. Definitely bring, if you're looking at the more modern stuff, bring a DevOps person with you and let them ask the hard questions. And if they don't even understand the words you're saying, they're probably not going to be able to support your practice. I remember early on I would get on calls with vendors, early on in my— as part of my career, and I would be like, oh, can you support containers? And can you, you know, can you support DevOps and Kubernetes?
I would use Kubernetes, you know, all the buzzwords. And if they didn't really understand what I was saying, I knew immediately like this isn't the vendor for me. They just weren't even going to understand my problem. And so really finding a vendor that understands the problem you're facing, I think, is the most important. I think this would go for legacy practice as well, as most vendors try and like focus on, hey, we're going to support the new shift left.
They could be, they could be leaving the problems of the legacy world behind, and then that could be problematic too. So if you're getting on a call and you don't want to hear shift left and you don't want to hear Kubernetes or Docker or Lambda, on the call, and that's what they're saying to you, then they're not listening to your problem. And so I think that's my biggest frustration is a lot of the vendors look at the buzzwords. And when you're on sales calls, they're really trying to talk to you about buzzwords when they don't understand the problem, the deeper problem, which is the speed of the scan, where it sits in the lifecycle, and how you get results back to an engineer. Absolutely.
And if you— if engineers are the people that are ultimately making changes in writing code and, and really building the things that you need to protect, I think that what you said around having engineering and DevOps at the table for those decisions is an excellent way to make sure that those voices are heard. Definitely, yeah. Every time I— anytime I deploy any tool that will go into an engineering environment such as the cloud or like in a developer lifecycle, I always have now DevOps because I have options with that. And software engineers in the conversation, and I, I give them the right to veto a tool if they need to, so they know that they have a stake in it. That's great.
So DevSecOps is obviously the future and really exciting, but there are tons of problems. We're not there yet. There's a long way to go. What are your top couple frustrations with the DevSecOps industry, and what isn't working well today? Um, I think, okay, one of my, one of my, one of my frustrations is that you— we aren't seeing one tool show up to do all, either all the languages or solve all the problems in the developer lifecycle when we're scanning for code.
And so I think one of my frustrations is that one tool will be very, very good at a couple languages and maybe a fast scan, another tool will be really good at a couple languages and a fast scan, And but you're really, you're really having to pick kind of the one that, that, like I said before, like 5 out of 6 groups got in and that last 6th one you're gonna have to do something extra for. And so I think that's frustrating where it's, it's hard to find a tool that fits every, everything you're doing. The other, the other frustration I have is that a lot of it seems to be in beta still. Every time I engage with a new a new vendor or I talk to people, it's like, yeah, we do that. It's in beta.
And it's in beta for quite a long time. But in order to support the engineering practice, I'm sometimes having to pick tools that are in beta or just out of beta, and they're not 100% functional. I think the last thing, and this is probably a little bit more on the mature side of my practice, is that where I'm frustrated is While the results can show up in a pull request or for the engineers in a certain way, if I need to pull statistics or I need to do any research on the practice itself, getting, getting reports, getting the data out and putting it somewhere where I can then do some actual analysis on it is, is not the easiest. We're still not seeing a lot of time and energy being put towards that. I do understand that as you're building a company out, reporting is probably the last thing you're doing for a security team.
But for me, and where we're at in our practice, like, that is the part that I need. I need, I need to be able to report out on it. Engineers want— they want statistics, they like statistics. And it's very hard for me to gather statistics a lot of times. And so we end up doing a bit more work in that area because the tools don't support it.
Working at Snyk, we hear this a lot from a lot of our enterprise customers that you have to have the visibility, you have to be able to communicate to the business the impact that you're having and why your tools are worthy. So definitely hear you there. Within that context, how do you choose partners and vendors even within those limitations and the reality of today? So I'm also lucky in that I do have another part of my practice where we're starting to do something called a security log data lake. And so it does open it up for me where if I have a partner, a a DevSecOps partner that we're using, or a security tool that's scanning, and we can get the logs out and put it into the data lake.
I'm able to do the correlations and more of the scripting outside of the tools, and so that's really opened it up for me. Um, as, as I think about reporting and all the things I just told you that are important, they've become lower on the list of must-haves for me as I work through this security log data lake. And I'm able to do more and more there. Um, so I think as a— for right now, as when we talk about application security in particular, I try and find the one that checks the most boxes. I'm not— I've never found one that checks all the boxes.
Um, and also the one that frustrates the engineers the least. So that, that is one that we, we definitely get engineers on the POC, we get the engineers involved, we have them test everything. And none of them like everything. You're never going to get everybody to agree. But we usually say, okay, which is the one you can live with?
Which is the one that you'll be least frustrated with? And so as we evaluate those partners, once they're in-house, we continue to ask that question to the engineers, you know, are you happy with this tool? Are you frustrated? Are you seeing problems? And so we continue that evaluation throughout the lifecycle of the security tool in our practice.
And again, if, if it's not working, like making sure that the vendor either understands that we will move quickly, like if we don't like something, we're just gonna move on, or figure out a way to make it work for the engineers in case we can't— it's not a quick move for us. So we'll go back to them and say, okay, what can we do to make this better? Are there ways that we can work around the problems? And so, so really it's kind of a balance between what the security team wants and what the engineering team wants when we're evaluating a partner. Absolutely makes a lot of sense.
And as a, you know, the security leader at Guild and as a key leader for the organization, I'm sure that you have to be able to work interdependently with the different groups within your company and that you, you likely need to build OKRs and business metrics that support your shared goals. Can you talk a bit about what it means for security to serve the business and how you think of that as you build business metrics for your organization? Sure. One of the really neat things we've done recently is the engineers started a program. It's just called Health of the Domain, and basically what it means is how healthy is, um, a part of the application.
And so that's— the application's broken into different pieces, and we'll call that a domain. The domain is then broken out into squads and repos. And what they have done is asked us to weigh in on what metrics could we pull for them and put, like, show that the, the domain is healthy. And so as we go out and write OKRs, um, like, or one of our previous OKRs was making sure that we had the logs and the information we needed in order to be able to start reporting out on the health of the domain. One of those being that a particular security tool was not turned off in, in the development lifecycle for the period of the quarter.
Like that, that would be a green, they got a green. Or not having highs and criticals in production, or that they were closed within the SLA timeframe. So those are the, those are the types of OCAREs we have written. As we look to the future, we're really looking more towards the efficiency. So one we're getting asked for is mean time to resolution.
So how long did it take an engineer to resolve something once it was discovered? So that's an OCARE where we're starting to figure out how we could support that. And this goes back to being able to get the information out of the tools in order to be able to support, okay, when was it found, what was the unique identifier. If you have 5 repos, the same vulnerability in all 5 repos, each repo and that vulnerability need a unique identifier so we can say when each of those was resolved in case they're resolved at different times. And so those are the type of metrics we're starting to hope to report out on.
I think the other part of the OKRs that, that is at least important at Guild is that we're supporting the team. And so one of the OKRs will be like how we actually support engineering, more like their satisfaction score with us. Are they satisfied with what we're doing? And I think that'll be one that we'll probably look to add in this year. That is so cool.
What I really admire about you is throughout this entire conversation, it's clear that you think of engineering as your customer and even asking for something like engineering satisfaction scores. That's like an NPS score, but, you know, internally. I think that's an incredibly wise way to think about things and that you get people in your corner and you can have folks act as an amplifier for your goals internally when they're on your team and they want to help, help row in the same direction as you. So kudos for that. Thank you.
Of course. I know that we're getting to the end of our time here, but my last question for you is you've clearly had an incredible career and an amazing impact at Guild and in this community in Colorado. What's the next step for you? What's the next step in your career? Yeah, something I've actually put a lot of thought into recently.
Um, I, I think my next step is actually, um, learning, learning how to get into the part of the industry where we're looking at future products and really influencing future products that are coming out, maybe security investments. Um, and so having some influence in that part of the industry. I think that really fascinates me as I've been very lucky to work with a lot of engineering teams that use really new technology. And I, we still struggle to see security tools either keep up or even be invented in the first place. And so I think I would really like to move into the space where I'm influencing investment dollars in the security industry.
Man, well, you know who to talk to for that, certainly from our organization. But I think that's really cool and can't wait to see the influence that you have. And, um, yeah, it's been an absolute pleasure talking with you, Julie. Thank you for your time and for joining us on the Colorado Equal Security Podcast today. Thank you.
Thanks for inviting me. Thank you.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.