All episodes

Chris Rothe, Co-Founder and CTO at Red Canary

Apple Podcasts Spotify SoundCloud

Chris Rothe, Co-Founder and CTO at Red Canary is our feature interview this week. News from Keystone, Sweater Ventures, TiLT, MSU Denver, Monarch Casino, Red Canary, Ping Identity, Secure64 and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12417 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the, uh, newscast for episode 246 for the week of April 1st, 2023. Alex, how are you doing?

I am wonderful. How are you, Robb? Doing fantastic. You know, I think we should really cut right to it and announce the big news. Yeah.

You know, this is actually sort of our last newscast, at least in this format, because, you know, we've got a big, big, big announcement that we're doing. Yeah. You know, Colorado Equals Security, as you know it, is going to be changing. We're no longer going to be Colorado Equals Security. We're going to be Colorado Equals— Colorado Equals Blockchain.

And, you know, we've seen this coming. You know, we've been pushing back against it for a while, but we've known that the tide It's inevitable, and blockchain has really proven its value in a lot of use cases where no other technology can service you. And as a result, we've decided that we should focus on that exclusively. I mean, at some point, you just have to join the Borg and be part of it, and we're all in on blockchain. All in on blockchain.

With that, let's do some housekeeping and get kicked off here. We have a Slack channel you guys can join at colorado=blockchain.com. Go out there and click the link to get in there, and of course, if you are in, if you live in Colorado and you have some kind of interest in blockchain, this is the place for you. Yeah. You can also sign up for our blockchain newsletter while you're there.

This, you know, gives you daily updates on all of the blockchain happenings across the world and in Colorado, of course, you know, because why would we limit ourselves even though we're the center of the blockchain universe? There's so much going on in blockchain. And, you know, while you're on the website, we would love it if you would take a look at sponsoring us with our Patreon campaign. You can get out there and give us some money. Of course, we do accept money in any of your favorite cryptocurrencies.

Well, you know, Robb, I have to say, one of the first things that we're going to do, first project for Colorado Equals Blockchain, is we're going to be starting a new service. It's going to replace Patreon. People can, can sign up and be members through a blockchain-based service. I think that this is a, this is a natural next step for Colorado Equals Blockchain. Of course, lots of other good stuff.

Rate us and subscribe on your favorite podcatcher. Go tell a friend about what we do. And of course, we look forward to seeing you at the virtual blockchain events that we'll be putting on. You know, we're a little slow. There was an Ethereum conference that was here a couple of weeks ago, Robin.

We'll definitely be there in full force next year. All right. So, Alex, that's it with housekeeping. Before we jump to news, It's April Fools'. It is April Fools'.

April Fools'. If people couldn't figure it out, it's April Fools'. Surprise! We are not Colorado equals blockchain. In fact, nor will we ever be.

But hopefully, hopefully we gave you guys a little bit of fun for your Monday morning. And by the way, it is— this is for the week of April 3rd, but we're recording on April 1st, so it seemed appropriate to us. Robb, speaking of Patreon, in the last month we have had a new patron. Uh, very exciting stuff. We'd like to, uh, to thank Mark Campbell for, for signing up and being a new patron of Colorado Equals Security.

Mark, who is the CISO for GMR over by, um, by, uh, Fiddler's Green. Appreciate your support, Mark. We're looking forward to, uh, to getting to keep working with you over the years. Awesome. All right, let's jump into some news, um, for Colorado Equals Security.

The, uh, we love to start off with some local news that you might not have heard other places and not always tech related. This first one Um, Keystone, you know, one of the well-known ski, um, resorts in Colorado, just recently took a vote for their citizens and they are planning to become the next, the newest town in Colorado. Yeah. Uh, Keystone, um, and I believe that I knew this already, it was not actually a city. It is, you know, it is just the ski resort there and the areas around there are called Keystone, but it's part of, uh, unincorporated Summit County.

And, uh, there have been efforts over the years by the residents there to to start Keystone as its own city, hopefully get more representation with, with different groups and things like that, have more of a say instead of just being part of Summit County in general. Yeah. So a couple of interesting things here thrown in the article. Number one, there are 970 active registered voters in Keystone. So it is not exactly a thriving metropolis.

And what was interesting to me is, you know, I would think like, you know, this is a big question for people who live in Keystone. When you, when you talk about, you know, voter turnout, I would think at smaller numbers, the voter turnout would be better. But when they had to do a vote on whether to become a town, only 44% of their 970 people showed up to vote. Although in the article, it did say that people were pleasantly surprised that it was 44%. So I guess it's all relative, right?

I guess I just, it just feels— I know voter turnout is generally less than half. Yeah, but, but holy smokes. Like, it's such a— when you get a small number like that, I just expect it to be higher. Yeah. And I believe it was 2 to 1 for becoming a city.

And so they, they will move forward with that. The next step is for them to, to form a charter and essentially, you know, letters of incorporation and things like that. Once they have that and can vote on approving those, then they will actually be the city of Keystone. So they'll be— they're going to be joining towns like Breckenridge, Frisco, Silverthorne, and Dillon as home rule municipalities. And if they, if they succeeded with their first vote, but they can't agree on a charter, then rather than home rule, they would be ruled by state ordinances.

Yeah. There were a couple of people in the article that were talking about some opposing viewpoints for becoming their own town of, you know, will this increase taxes and other things like that to, you know, be their own city? And will becoming their own city actually achieve the goals that they're hoping to? You know, just because they're a city now, are they actually going to get a bigger voice with CDOT and Vail Resorts and other things like that? So we'll have to see.

Looking forward to it. It's not going to be a huge city. That's not going to make the list of the top 10 biggest Colorado cities. But, but it's a well-known one. All right.

Up next, Colorado unemployment has reached pre-pandemic levels. Also, Coloradans are in general are working less and making more. Yeah, it's cool to see that not only is the percentage of unemployed folks going down, that the percentage of people participating in the job market has gone up. It just ticked up a little bit. I think it was, was it 6— from 68 to 68.1% joined the workforce.

But, you know, it's not just because a lot more folks are sitting out that this percentage is getting higher. Yeah. You know, it would be interesting, though, Robb. They didn't— they don't have a lot of the historical numbers about percentages and things like that. It would be good to know what the sort of historical average and things like that of, you know, percentage of people in the workforce and things like that.

One of the other things that I noted was that national unemployment dropped by 0.1 to 3.4%, which is a 54-year low. Yeah, it's, you know, as we talk about a potential recession and we talk about inflation, it's interesting that as the Fed has been working really hard to slow down the economy, to, you know, to slow down inflation, and it has not impacted unemployment yet. Yeah, jobs, jobs are like almost all-time high. And obviously in our sector, in the tech sector with security jobs, like, you know, those things are still hard to hire experienced people even with all the layoffs that have happened recently. Yeah, that's one of the things that I thought was interesting too, is, you know, you hear about all of these layoffs, some of them in the tens of thousands, yet we're still nationally at the lowest unemployment that there, there has been in 50 years.

So, and very interesting. One last bullet from this article. They say Coloradans are not only more employed, but they're also working less and earning more. The average workweek for employees dropped from 33.5 to 33.4 hours, and the average hourly earnings went up from $34.18 to $36.14. So congratulations, Colorado.

On average, you're working 6 less minutes a week and you're making— you're making more— a couple more bucks extra an hour or whatever that was. Was that— yeah, that was per hour. Yeah. Good stuff. Yeah, good stuff.

All right. All right. What do we got next here? Next up, a Boulder fintech company has launched a new app, I guess, a new function, which is, you know, being billed as a VC for everyone. Yeah.

And so this, this guy was interested himself in building a venture, a venture capital fund and investing in startup companies as he started going through the process of creating his VC. And looking at what it was going to look like, he realized that he did not qualify to invest in his own fund he was creating. He couldn't put his own money in. And that's because of a rule, a federal law called accredited investors, which requires that anyone who invests in private companies, basically they have a certain income level and they have a certain net worth level that this guy didn't meet. And he said, well, that doesn't seem reasonable.

And his solution, rather than know, going out and, um, trying to change the law was to try and create a new platform where people who are not accredited investors can put in any amount of money and, and get in early on, on venture capital rounds. Yeah, and, uh, by any amount of money, I think the lowest is $500. Um, and, uh, yeah, there are no requirements for, uh, for being an accredited investor, any, uh, income requirements. Obviously there are some disclosures and other things like that relating to risk of the investments. But yeah, this really is something that can be for everybody.

So this company is called Sweater Ventures and based in Boulder, based in Boulder. In order to do this, you download an app, you invest through the app, and then on their side, they figure out the companies to invest in. Yeah, it looks like— but it's more than just that. They're also looking at creating like a Shark Tank type of a feel where they have a bunch of companies who apply to be, to be funded by this organization. And they will come present their, their pitches like at a theater where you can go attend either, either in person or virtually to see the pitches and see, you know, I don't— I think there's even a voting thing that they're planning to do as a part of that to help pick, you know, which, which companies get funded.

Yeah, they actually— they did the first one of those called Barn Burner. And it kicked off in February. They had 450 founders that applied. They narrowed it down to 75. The founders pitched their startups in short videos and people voted through Sweater.

And then that resulted in 5 finalists who will compete in person for a $500,000 investment. And, and they do have the 5 companies listed here. One of them is a Denver company called FarmShare, which it looked like it was getting food fresh from farms to people's houses. But there's one on here that's not from Denver, from Cleveland, but that it looks like a security company. I looked it up and they call it EverKey.

It looks like it's, it's meant to replace your passwords and maybe also replace your physical keys, which I don't know that I understand quite yet, but it's some kind of a combination of like a physical token that you can use to log you into stuff and also get access to other stuff. Oh, that's cool. One thing I thought was interesting that in the first 7 months, Sweater Ventures considered 2,000 deals. They spoke to 600 founders and they did due diligence on about 80 of them, and then they selected 26 for investments. Yeah, pretty cool stuff.

If you're interested in getting involved, I get the impression that you could actually get quite involved. They mentioned they have, of their members, the people who join the app, they have like 200 who have been trained to be scouts out there looking for companies to invest in. So my guess is if you're interested in this type of a thing, you know, you should Sign up and take a look. All right, moving along. We have another local company.

We love to highlight local tech companies. A company in Fort Collins raised $10 million to humanize HR, and their company is called Tilt. Yeah, they are aiming to make parental leave more organized and empathetic, and their platform helps streamline the process of taking leave. Uh, they, they talk about parental leave, but I think that they're, uh, really, you know, aiming at any sort of leave of absence, whether that's parental or military or medical or anything else like that. Yeah.

And this company was actually awarded the Emerging Tech Company, um, award at the, uh, Colorado Technology Association Apex Awards. Um, they, this, they've raised a total of $25 million in capital so far since it was founded in 2018. And they have tripled their size up to— they have 90 employees now. So they're definitely not a tiny little company. No, that's getting to be pretty big.

They're going to use— there wasn't a lot of detail in here what they're going to use this new $10 million on, but to increase investment in product and sales is what they said. Nice. All right. Next, we have a story talking about Metro State University and their cybersecurity program and the new program that they're doing that helps guide students with autism to cybersecurity careers. Yeah, really, it's a really neat program.

And it's based on some success that they had had in England. And one of the creators of this program was part of that. Man, I can't remember what it was from out there in England. But he was a member of that group that was doing the training. Do you have it?

I don't, but they're partnering with a group called TACT, which is Teaching the Autism Community Trades. So a guy's name, Richard McNamee, he is the director of the cyber range at MSU.

He was talking— oh, here it is. In the UK, the British spy agency Government Communications Headquarters has had this concept for years of training and hiring neurodiverse employees. And McNamee, who was a former British Army officer, saw it work there and was excited to do this here as a result. Yeah, and excuse me, those folks that, um, that are neurodiverse have a lot of the traits that you might want to be a cybersecurity analyst. Um, you know, looking at patterns, being able to focus on certain things, and this program tries to help, uh, focus them towards the things that you would need to be, you know, a cybersecurity analyst— partnering with people, um, you know, working through problems, things like that.

Yeah, it's neat. I have actually heard of TACT as well. It's Teaching the Autism Community Trades. That's what that stands for. And they do from, from like really hands-on trades, like car repair and woodworking and stuff to, to this more, you know, security of trade.

I don't know exactly, but like a broader set of stuff. What I really loved about— one of the things I loved about this article as well was they talked about from the very beginning, you know, there's often within folks with autism and also, um, with insecurity, there's also like an isolation where people don't, don't always work well together. Right. Um, and, and from the very beginning of this program, they all sit around one table and are problem solving as a team to try and overcome some of those, uh, prejudices or some of those tendencies. So anyway, really cool program and I love to see MSU at the leading edge of that.

Yeah. Good stuff. All right. Uh, next story is a big one. Some very, very crazy stuff.

Black Hawk Casino. Monarch in Black Hawk. Sorry, I'm reading the headline. Was victim of the largest heist in Colorado history. Yeah.

So $500,000 stolen from Monarch Casino. And if you guys haven't read the story, it's just, it's just worth a quick read, but we'll summarize it. So, so if you don't, you get the gist of it. The cashier got a call, or the cage operator, whatever you call that person, got a call supposedly from the owners of the casino saying that they had some kind of a medical problem emergency and they needed her to bring $500,000 in cash to them in at a hospital in Denver. So could you please go take a bunch of money out of the cage, put it in your car and come drive down to Denver and give us that cash?

Yeah, she did it. That seems like something that would normally happen. So there were no alarm bells that went off. And yeah, this person, she did it. She drove it down there.

It was very odd, as you might expect for, you know, something— a social engineering attack like this. But then I think after she delivered the money, I think she may have realized that something was not right. And, and came back to the casino and told some people what had happened. And, you know, sort of mentioned that she thought she might get arrested, which she did. She did get arrested.

You know, I am— man, I really have a hard time with this. Like, if someone gets tricked, did they commit a crime? Right? I just— I don't know the answer, right? Like, if someone tricks her into stealing, and she believed she was doing her job.

Like, yeah, maybe she's not a person you want working in your cage anymore, or maybe she's the exact person you want because she'll never let it happen again because she spent time, you know, behind bars, like literally behind bars as a result of this. Well, I don't know. I think the other part is that there, there was clearly a lack of control in the process for taking money out of the vault there. For, for an amount that large, you would think that there would have been some other checks and balances that would have prevented anyone from taking $500,000 out of the vault and out of the casino. Yeah.

Imagine if she actually was malicious and she was like, hey, you know what? $500,000 is enough for me to live the rest of my life happily wherever. And instead of driving that money to the hospital to give to someone in Denver, she drove to the airport and got on a plane and she just never came back. Right. Like, it seems like the controls were lacking regardless of what the motive was.

Yeah. Anyway, interesting stuff. Like I said, it's like the real-life boring version of Ocean's Eleven. That's right. And, you know, Robb, we were in, in Blackhawk recently gambling, and we did not go to the Monarch Casino because we figured that they're going to be doing things to try and get that money back.

Yeah. Yeah. There's no longer free drinks. You're paying $20. I mean, we're making this up, of course.

Just, just kidding. At this point, slots are a bit tighter, you know, all that kind of stuff. Yeah, only well liquor. Blackjack pays instead of paying one and a half to one, it now pays half to one. You're right.

You know, winning less money if you get blackjack. All right, moving along. We have officially as of what? Like just a couple weeks ago, the Colorado Attorney General released our finalized oh shoot regulations for regulations for privacy. Yeah, for CPA Privacy Act.

Yeah, thank you. Yep. Yeah, so on March fifteenth. The Attorney General's Office, they filed the final Colorado Privacy Act rules in the Colorado Register, which you can find them there. But we have an article here that, that does a decent summary of some of the differences that they have between the Colorado Privacy Act and other things like CCPA, CPRA, and Virginia and other things like that.

Yeah, it's— I actually think it's a pretty good write-up here in the National Law Review requirements around, you know, flow-down when someone, when someone requests to have their information deleted. Not only do you have to does the company have to delete it? They have to tell all of their subprocessors to delete it in the same way. And if there's any situation where someone asks for a deletion and it can't be honored, you have to say not only like that it wasn't honored, but like, here's the data elements that we were not able to honor. Because you just can't come back with a, no, we can't, which I guess was okay before.

Well, and it sounded even like not just a blanket, no, we can't, but like, we can honor some of this, we'll delete these things, but these are the things that we can't delete. Right. And sometimes there's probably a good reason for it. Yeah. Right.

Regulatory requirements and stuff. But, but knowing those details, I think, is an important part of these rights. Yeah. I mean, other things like universal opt-out and some other things that are very specific to the Colorado rule versus some of the other ones. Anyway, it's a good read.

You should check it out if you care about privacy or even if you don't care about privacy. All right, just do what we say. Just do what we say. Read it. Uh, next, uh, we have a blog post from Red Canary talking about a guided tour of the 2023 Threat Detection Report.

Robb, what is the Threat Detection Report? Yeah, so every year Red Canary spends a lot of cycles on analyzing all of what we learned the previous year, and there's, there's monthly releases you guys have seen. We've talked about like the intelligence insights each month, but at the end of the year we, we bundle it all together and say, all right, what did attacking look like last year? What, what kind of exploitations were most, or most important? What were, what were attackers going after?

Um, what were defenses that worked? And, and what, what are commonalities among places that were exploited? So the threat detection report gives you all of those learnings for the year, um, for those things that, uh, that, that we're seeing. And there's like 40,000, uh, different types of attacks that are a part of this. So lots of great information.

And this webinar that we have a link in here to actually walks through all those results. So if you want to know, hey, within my security operations function, am I covering the right stuff? This webinar is going to be a great place for you to start. Any spoilers, Robb, or are people going to have to go read the report themselves? You know, I'll say that my— the biggest takeaway I got is attackers are going after 3 things.

They're going after endpoints, which they're going to use to pivot and gain additional access to. They're going after identities, which they use to get obviously access to other systems. And they're going after email boxes. And of course, you can, you can imagine, right? Endpoints, you're going to be able to do things like ransomware.

You're going to be able to do things like exfiltrating data. Email boxes, you're going to be able to do things like business email compromise, right? So they're looking at those 3 things as the main targets. Nice. All right.

Next up, we have a blog post from Ping Identity. It's actually an announcement of a new product that they have called Neo. Which is their new decentralized identity solution. Yeah. You know, when I was at Ping, we bought a company that did, that did some decentralized identity, like a wallet on your phone, which you could use to, to display and hold identity information.

What it looks like to me as I read this, and I didn't know this was coming, I read it last night. Um, it looks to me like they've taken that initial technology and just added a bunch of capabilities and features to make it really useful for corporations that want to have identity offerings or, you know, claims offerings for their customers. It really went from what I would say initially looked like kind of a consumer-based technology to this is something that's going to make a lot of sense for companies to adopt. Yeah, so instead of, uh, you know, when you needed to validate a claim or do something like that, uh, going back to the source system where that claim came from Now you can use this to, you know, to get and set up your claims and store them locally on your mobile device. And then when you want to go use the claim, you have all of the, the information there so that you can just use it directly instead of the, the third-party system that you're using it against having to go back and check those claims and things like that.

So this, this, if you read this article, this press release, like the first half of it is more explaining what is decentralized identity and training you to understand what the second half is going to say. Jumping to the second half though, the service is— I said there's really 2 parts. One, which it's related but not the same thing, they're doing identity verification. If you want to know, hey, this is really Alex who's signing up for this account, you can take a picture of a government ID. They have integrations they can do with other systems.

They do a liveness check to see, all right, does that picture on his driver's license match the face that's that's in the selfie. They'll do those things to identify this is the person. And this is important for things like setting up a bank account, you know, setting up any, you know, employment agreement with somebody. If you, you know, in this remote-first work environment, does someone really have to come see us in person, or can we, can we use an app like this to get them onboarded? So there's the employee— or that's gonna be the identity verification element there first.

The second one is this presentation of claims, which I think that the great first example they give, which is the most obvious one, is, you know, you have a driver's license in your wallet. That thing is really— the reason it exists is so you can prove you can drive. But there's all kinds of places that use it for something else. The most obvious is, you know, you go to a place that requires you be over a certain age, they want to see your driver's license to see how old you are. When they look at your driver's license, they can see, you know, your, your weight and your, your home address and, you know, your your eye color and all these things that have nothing to do with, are you over a certain age?

Well, with this decentralized identity and these— this claims presentation model they're working on, you should be able to— you can present just my proof that I'm over 21 in a credible way, right? You don't get to know where I live, but you get— you don't get to know if I have a commercial driver's license or a, or, you know, normal, whatever the other one is. You just, just see that I'm over 21, and that should be good enough. Yeah, and that's, that's one of the 3 advantages that they list about, uh, you know, why you would use NEO. Second one is, uh, decentralization of data, right?

You know, we know that there are all kinds of credential breaches, big password, uh, breaches and things like that. If you have decentralized identity, now you no longer have a central store of those, uh, things that can be stolen. And the third is to, to eliminate friction. Um, you know, once your identity has been verified, the credential can be issued so that you never need to go through that verification again. Anyway, it's cool stuff.

I'm looking forward to seeing the use cases this actually gets used for. I know they have some, some good ideas in the blog post, but as companies adopt it, they're going to find new ways that it can be useful for them. I also think as security people, it's— it'll be interesting to see what the drawbacks are of it as well. Right. Like there are definitely some advantages of centralization, too.

You know, I think with— since we are Colorado Equals Blockchain, you know, with the decentralization of blockchain, There are definitely some negatives of that too, right? Like if you lose something, it's gone because there's no central authority to, to get it back to you, right? Like what happens in cases like that? And I'm sure some of that stuff will come up as well, but probably some misuse cases we haven't thought about because of decentralization. Yeah, I bet there are.

All right. That is it for our ping one. We have one more story here. Secure64. I feel like we haven't talked about these folks in a while.

They are our local DNS appliance security company. Yeah, based out of Fort Collins. Based out of Fort Collins or Greenwood Village, kind of depending on which press release you see at which time. I think they must have offices both places. But they have announced a new product for them too.

They call it Secure64 Vision, Vision with a Z, which is of course cooler. Yeah. Alex, tell us all about it. It reports on the data that their appliances put out. There you go.

And it looks like, you know, a really pretty way to see You know, their appliances were getting a lot of information about things like— let's get into that section here— denial of service attacks, malicious sites that people are going to, phishing attempts, DNS tunneling attempts, fraudulent sites, all kinds of security stuff, right, across these, I think, usually like telco-level type networks. Well, now they have really nice reporting about what all the stuff they've seen is. Is that about right? Yeah. Good stuff.

Reporting is always good. We love to see our local security companies making progress. All right. That is it for news. Let's jump over to events.

As always, there is an event calendar on the website, colorado-security.com. Go and check that out for all of the latest events. All right. Starting here on the 7th of April, ACES Denver, that local physical security group, they have a coffee chat with Lisa Buckley. On the 12th of April, ISSA Denver is doing their April meetings, 3 Game Changers and 3 No-Brainers by Doug Stabach.

Those are going to be both in the DTC and downtown on the 12th. The— on the 14th, Let's Talk Software Security is getting together and having a conversation around software security OKRs and KPIs. Oh, that sounds interesting. On the 20th, which of course is 4/20, ISACA Denver is doing their annual chapter meeting in person. Also, CSA Colorado is doing a chapter meeting search party threat hunting in the clouds.

What are they going to be clouds of? What kind of smoke is it on the— Yes, there's gonna be lots of clouds to hunt in. On the 26th, ISC2 Pikes Peak is having their April meeting. On the 29th, Colorado Equal Security is doing our first giving back event where we have some people that are volunteering to help clean up a park in Denver. I think at this point, we're pretty well— last I heard, we had one more spot.

Okay, maybe we have one spot. If you're interested in this, let us know, but we may be full up with all the volunteers we can take. And then the final event to go through here on the 2nd of May, it's another ACIS Denver group. This is Next: Your Digital Profile with Carrie Sutherland. But we should also jump ahead.

Let's jump ahead a month. That is when the Rocky Mountain Information Security Conference is happening. It is. I know you, you and I are not as involved as we have been in previous years. Do you know anything, any intel you want to share on who we got keynoting or anything?

I don't know that I can tell you about keynotes, but I can tell you registration is currently open. And I believe that the agenda has been published with, I think, at least some of the, the individual speakers that are speaking. And early bird registration prices go through the 14th of April. So if you're going to go, you should probably register soon so you can get the best price. Love it.

And of course, it is the best security conference in the state. You should be there. I will not be there. Unfortunately, I'm out of town. Not that unfortunate because I'm going on an amazing trip over that time.

But, but you guys should all be there. All right. Let's jump over to jobs. Some interesting jobs this, this month. This starting with this first one.

US Bank is hiring an operational risk crisis management executive here in Denver. That sounds interesting. RingCentral is looking for a Director of Data Security. RTD is hiring a Manager of Cybersecurity Operations. Credit Union of Colorado is looking for supervision supervisor, I suppose, of information security.

SiriusXM is hiring a Senior Security Architect. Cloudflare is looking for a Lead Email Security Detection Engineer. That sounds interesting. Yeah. Oracle is hiring an Offensive Security Manager.

Now, I think it's about a manager of offensive security, but I've known some security managers who could just be called offensive. So it could probably go either way. I mean, if you're one of them, you should probably should apply. This next one's really interesting though. TIAA is looking for a senior director of cyber AI.

Yeah. Wow. Yeah. And this person, the salary range on this went up to like $280,000 something, I think. Is cyber AI different than regular AI?

I mean, probably on the blockchain. Conga is hiring a product security engineer. And last but not least, Epic is looking for a junior network security engineer. All right. Well, that is it for news, but we do have an interview this week.

Tell us about this interview. We do. I sat down a little bit ago with Chris Rothe of Red Canary. He is one of the co-founders of Red Canary. What?

He's CTO. CTO now. Very interesting conversation, some about Chris, some about Red Canary. It was a good chat. Awesome.

Well, that's it here for April. We'll look forward to getting back together again in May, all about the blockchain. Thanks, Robb. Hi, this is Desiree Robinson, Senior Information Security Manager with Smarsh. This is Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.

Welcome to Colorado Equal Security. This is Alex Wooden. I have a feature interview today with special guest Chris Rothe of Red Canary. Hey, Chris. Alex, good to be with you.

Good to be with you too. Good to see you. Beautiful day today. Glad we could get together and do a little chatting. Yep, yep.

3 degrees, I think, this morning when I left my house. That's great. Yeah, you know, it's beautiful spring weather.

You know, you've been around the security community here for a long time, and obviously Red Canary, a big pillar of the security community here in Colorado. But I honestly, I don't know a lot about you personally, and I'd love to learn a little bit more. Are you from Colorado? Are you from here originally? I am, yep.

I grew up in Littleton. Oh, nice. Yep, and then went to school up at CU, so. Go Buffs. I've never, never been anywhere but here.

First job was here and just success of, uh, of, of jobs after that and always been in Colorado. That's awesome. Yeah. Um, so you're, uh, you super excited about Deion Sanders then? Very much so.

Yeah, it's been a dry spell for, uh, for Buff football, but, uh, but he's— the excitement is real. It's, it's great. The Buffs have not been, uh, up to par the last seasons. Yeah, it's good. It's, uh, we'll have to see how it goes, but at least there's excitement back in the Buff community.

That's all we can ask for at this point. It's been, it's been a rough, uh, rough run. When it, when it's a toss-up between, uh, who's worse, CU or CSU, then, uh, you know, yeah, that's a bad, bad couple years. Yep. Awesome.

Um, so, uh, so you went to CU. After CU, uh, what did you do? Did you go to school for, for computers? Did you decide that was what you wanted to do, or did you fall in? Yeah.

Yeah, yeah. So I, you know, my dad was an electrical engineer, and so grew up around computers with hard drive parts all over the place and, you know, circuit board diagrams on the walls from patents he had and stuff like that. So it's sort of in my blood. I went to CU, studied electrical and computer engineering, and definitely leaned towards the computer side of that. So I like to joke that despite all the hours I spent in power lab and embedded systems and everything else, I haven't done any of that in my career ever.

Immediately went into jobs writing software. My first job out of college— well, job during college and then right out of college was with a startup up in Boulder called Freshwater.com that got bought by Mercury Interactive, and then they became part of HP. Server monitoring software in the early days of the internet. So that was pretty fun. Got to learn a little bit about startup culture.

And then my first real job, I guess you'd call it, was very much the opposite end of that spectrum with Lockheed Martin. And obviously a very big company and lots of hush-hush type projects. But I learned a lot there. I learned a lot about how you take a big problem and carve it up into smaller problems? And, you know, when you have lots of data to process, how do you sort of create systems that are fault tolerant and scalable?

Like, one of the things we've really carried forward from our time there was just, you know, you can scale simple things. Complex things are very hard to scale. That's been sort of an architectural tenet that we've, you know, served me well throughout my career and certainly with Red Canary. But yeah, I spent a few years at Lockheed Martin, and then as happens a lot in sort of defense and intel space, I went to a smaller contractor. I think I was employee 10 or 11, maybe 13 at that company, subcontracting back to the big defense contractors.

So didn't change a lot about my day-to-day job, but did get a feel, a little bit of a flavor for being an early employee at a company and what does it take to grow and find new sources of revenue. And so we were able to scale that company pretty well while I was there, and then they did lots of great things after I was gone. But got a taste of it there, and next up was the things that led to Red Canary. But that was the early part of my career in that space. So I'm curious, what led you to go from being at Lockheed to being a contractor to Lockheed?

Was that other people or you thought, you know, I want to do something a little bit different? Yeah, really, I'd be lying if I didn't say part of it was money. So definitely— It's always more lucrative being a contractor. Yeah, let's be honest. Significant pay bump in it.

But, and I think you would see this if I were to show you my W-2s over the years, I'm not financially motivated. So the bigger thing really for me in that was the team I joined at this company, Solidine, was known as some of the best contractors in that area. And really liked the idea of, hey, join sort of the A-team and help recruit other members to that and get to a place where, you know, in that forest of many many thousands of contractors, we're the ones that really are, are moving the needle on some of these defense projects. So that was the idea and sort of the concept for that company. The 2 guys who, um, who founded that company, Andy Marshall and Mike Pearson, were— had really clear vision for what they wanted to do in that area.

And I, I really respect those guys. They've since sold the company and, and, uh, are doing— off to doing other things. But, um, you know, their energy was something that really drew me to that. And then the entrepreneurial piece of it, you know, it's easy to get lost in big companies and not feel every day like your work matters. And so going to that smaller company gave us— gave a lot of that opportunity as well.

Nice. So, you know, defense contracting could be related to information security, but probably especially back then, probably wasn't. Sure. I haven't heard anything in there yet that says information security. How did you go from doing the defense contracting to pivoting into information security?

Yeah, I mean, I'm a pretty abstract guy, so to me they're not that different, but the common word would be security, right? So national security versus information security. But yeah, the stuff we worked on in the defense space was largely satellite data processing type programs, both data processing and ground stations. I worked on the GPS ground station for a while and then some other stuff I can't say too much about. But the problem was similar to, to one that we ended up facing, or that everybody has in information security, which is how do you take huge, huge volumes of data and find the things that are actually worth looking at?

Right? And so the pivot for me was less about going from something outside of security into security and more about one flavor of security and detection into a different flavor of security and ultimately detection. So the transition, really the way it worked is Brian, our CEO, my very close friend, we both worked at the company I mentioned, Solidine, as contractors and worked on a lot of kind of side project research projects together while we were there. And he has some contact or previous experience with some guys who had spun out from a defense contractor called Mantec and were doing some interesting stuff in and around the intelligence community, but also commercializing some of the results of their, their work. That company is called Kairos.

So Brian went over there to sort of open their Denver office, and about 6 months later, I followed him over there. The project I worked on with him along with Keith, our third co-founder, originally was Kairos Managed Security. And the idea was to start our own sort of boutique MSSP. And we realized very quickly that part of the problem with quality in the MSS space was just breadth, trying to do too much. And so with the sort of advent of EDR and, you know, Kyrus incubated and then spun out Carbon Black, sort of the original EDR vendor.

So with that, we were able to kind of focus very intently on endpoint detection, and that led to the creation of MDR and everything else. But that was sort of the pivot for me, was going from the national security space and focusing on sort of satellite data processing problems for the purposes of detection to sort of naturally over into security and doing a different form of— or information security and doing a different form of detection. Yeah. I'm curious how you guys decided this was the problem to tackle. Obviously, there's lots of problems that are out there in information security or national security or whatever.

Of course, yeah. This is definitely a big one. What was it that drew you all to what became managed detection and response? Yeah, it really started with incident response. Kyrus was doing incident response on a pretty small scale.

We had a handful of customers and it was largely in and around the defense and intel space, so defense contractors who had had breaches of some kind or another. On one of those engagements, and I wasn't there, this sort of predated me, but on one of those engagements, they brought along a guy who came more from the offensive side of security and said, hey, take notes. Tell us what you think about the way we're doing incident response. After a couple weeks of the IR, he's He comes back and he's sort of like, that's it? Like, that's IR?

Like, why did you spend all your time taking disk images and rummaging through logs and like 5 minutes doing any actual like tracking of the threat actor? Why don't you just build something that collects all the data and, you know, hands it to you? And we're like, well, that'd be cool. Can you build it? And it turned out that that particular team had the skillset to the kernel-level development required to create what became Carbon Black.

And so they did that. And so we continued doing incident response using Carbon Black as our tool. So we landed an IR, do deployment, collect the data, clean up the incident, and get to the end, hand over the report, and do all the wrap-up and walk away feeling like, well, we're going to be back here in 3, 6 months whenever the actor decides to come back, because they're not going to do any of the long-term improvements they need. So one of the recommended actions we would have coming out of IRs was, hey, keep this thing collecting the data so that when we do come in, we don't have to go through deployment again. We can just, you know, start investigating.

Maybe even look at it every once in a while. Yeah, maybe notice anything going on. Yeah, and that was sort of the big realization we had is we're like, You know what, they're not going to look at it, and someone should. And they were also asking us, hey, we don't really want to host this thing, like, can you host it for us? And so we said sure.

So we started running Carbon Black servers for these customers, and pretty quickly the next step was like, well, why don't we look at it for them and tell them when there's a problem instead of waiting for them to call us? So I'd love to say we had this like great insight that led to Oh, you know what, there's this gap in the market, but really it was more organic than that. It was sort of like this progression from, hey, somebody did get breached and we came in to help them clean it up, to, hey, they need this tooling longer term so that if they have another breach, they can deal with it more quickly, to, hey, why don't we just do this continuously for them? And so that's sort of the original concept was if we can do incident response level monitoring of an environment 24/7, 365, then maybe nobody ever has to call a capital I, capital R incident response firm. So we sort of put our own IR firm out of business.

We stopped doing it and shifted our focus to what became managed detection and response. We didn't know what it was at the time. We just knew, hey, this is providing value and we're catching things before people have a bad day. Yeah, I am curious since you say that, what is it, were there names that you guys called it before it became MDR? You know, yeah, we tried a few things in trying to explain it to customers.

We would talk about sort of continuous incident response or just continuous monitoring. We even like Gartner coined, so we spun the company out and started in 2014. Gartner didn't coin the term MDR until 2016. And even after 2016, for a couple years, we sort of rebelled against the name just because it didn't, like the other folks in MDR didn't really feel like the same thing as what we were doing.

We tried detection response as a service, things in and around that area. And ultimately, like, the big business lesson learned we got from that was once Gartner created the category, just use the category name because you're stuck. Yeah, you're just causing yourself more pain by trying to explain to the market and customers how you're not that, even though you sound like it. Right. The other thing I was going to say back on your point about this being sort of more organic is I feel like that's how the best products and companies happen, right?

Like someone has an experience that they see a problem, they've experienced it themselves, and they try and find a better way to solve it. I see a lot of times now where, you know, people that are, you know, sometimes previous founders or, you know, venture capitalists or things like that, like do research to figure out, you know, where there's a hole in the market and like, oh, could a product fit here. And then you spend a whole bunch of time trying to figure out what that means and probably do it badly. I don't feel like that works as much as when there's really the, oh, I experienced this thing. There's a way to solve it.

Let's try and solve it that way. Yeah, solve your own problem, right? And we had the benefit, you know, I'm not a person who came from information security before that. Neither is Brian. But we did have Keith and he was, right?

And Keith was the IT and security leader for a large defense contractor that went through a breach and effectively had to burn their entire network down and start over and build it from scratch. So he knew the problem inside and out, right? And so for many years, like that's the way we thought of it is we're solving Keith's problem here. And so that, kind of insight was what led us to be able to kind of progress through that. But totally agree with you.

I mean, the other thing we see a lot of is cool technology looking for a problem to solve. I think the biggest example in security with that over the last number of years is definitely AI and ML. They're great tools. Like we use ML in a variety of places in our system, I think you could confidently say every time someone started from, I'm going to use ML to solve a security problem, they got to a weird place. Whereas if they started from, here's the problem that I really truly understand and I've validated with customers and I know everything about, now what are the best tools?

And ML is one of them. I think you would find a very different success rate between those two. Right. Yeah. We're trying to solve this problem and we're doing We're doing binary things.

We're doing, you know, rules. We're doing things like that. We, you know, we can't do that anymore. We need it to be better than that. Let's try and figure out a model to do it as opposed to, oh, here's a problem.

Is there a model we can apply to this that's gonna find what we wanna find? Right, right. Or like, I think the— I think ChatGPT and the whole generative AI space is amazing. I think as often happens with these things, people get ahead of themselves. Themselves a little bit and they're like, oh, this could do this thing.

And it's like, well, yeah, it could, but is it the right— is it the most efficient way to do that? Is it the most cost-effective? Is it even the best experience for the user? And maybe the answer to all that is yes, but if you start from the technology and work your way back to the problem, you're going to struggle. I remember years ago when Hadoop first came out and amazing power.

All of their databases are going away. Exactly. This is how to solve big data. And for years, I looked for a problem to apply Hadoop to because I thought it was so amazing. And every single time, it ended up being, nah, dude, you just need a big database, or you just need a flat file storage or something.

And it turns out, yeah, Hadoop's amazing for what it's amazing for, but that's fairly narrow MapReduce-type use cases.

That's the trap a lot of folks fall into many times when they start from the technology and go looking for a problem. So we never did that. And some of that means that we've been slow to adopt some of the things that other folks in the market claim to be getting a lot of success from. But that's okay. We'll use them when they make sense for us to use them.

Yeah, for sure. So you mentioned that you and Brian ended up working together before coming here. How did Keith come into the picture? Yeah, so Keith had worked, uh, so the company I mentioned, Kairos, uh, the 5 founders of that had all been connected back, uh, at a defense contractor, large defense contractor. Um, and Keith and Brian had both worked with those guys at that defense contractor in sort of the mid, mid-late 2000s.

So Keith was actually at Kairis before Brian or I were, and he was the one who sort of built their initial incident response practice, forensics practices.

And then, yeah, so Keith was there, Brian and I kind of came along to help build out some of the systems and software and company around the problem Keith wanted to solve. Yeah. So the 3 of you, what, like 9-ish years now, coming up on 9 years? Yeah, it'll be 10 years that I've been working on this problem in just a couple months. Wow.

It was weird. I realized that the other day. I was like, oh man, that's big now. So the 3 of you started working on the problem. You're all still here together at Red Canary working on the problem.

Don't hate each other. Most days. Um, yeah, I'm curious how that, that works for, for all of you. Is, um, how have you guys been able to manage that, that relationship with the company and things like that? Because, you know, oftentimes you'll see, totally, you know, at one point one of the founders leave, or, uh, company gets to a certain size and they've, you know, you decide, okay, um, you know, we've, we've been pulling Brian along this far, but, you know, we need an actual CEO now.

Like, so let's Let's get a new CEO. How has all that dynamic worked for you guys? Yeah, I mean, I guess it would start from the fact that like, and I'm speaking about the other 2, I hope they would say the same about me. Like they're such good people. Like it starts with that.

Like they're low ego, high character, great human beings. Right. And I think because of that, some of the typical things that you see in startups where ego or greed or jealousy drive people apart. We just haven't had to deal with that.

Not to say we never will. I mean, who knows what could happen? But to date, we all kind of row in the same direction and celebrate with each other and get down when things don't go well together. And all that. One of the things, I don't know, like just external validation, I could say that, but one of the things I think really struck me is several years ago, the 3 of us plus one of our other early employees, Corey, who's a legend in Red Canary circles, the 4 of us were on this trip with a bunch of other guys in Scotland.

And one of the guys on the trip was the founder of another company that had had some conflict in, in not just their founding team, but then when they brought in outside executives and worked on some very combative executive teams. And at one point on the trip, like several, several days into it, he's like, you know, it is so cool to see you guys interact. Like you all sort of take care of each other. You know, he's like little things, like when one of you gets up to go, you know, refill a water bottle, you ask if the other guy needs one, like stuff like that. So, you know, I, I don't know, it's hard to say that.

It's hard to like, uh, say this is exactly why, but I think that's some of it is that like we legitimately like each other, we care about each other, and, and, uh, and generally are pretty low ego individuals. Um, you know, from a company culture perspective, like how have we tried to map that into the company? Uh, Our core values are an attempt to sort of recreate that into something back to like simple things can scale, complex can't. Our way to sort of codify that into something that we can scale up and we've been really successful with that. Our number one company core value is do what's right for the customer.

And I think if we've ever, if we ever have arguments, it's about disagreements over what's right for the customer in a certain circumstance. Which is a good thing to argue about, right? To debate and figure out what is the actual right thing to do here. So that's sort of, you know, if I were to go to another business and advise someone else in some other area, I would say like, how customer-centric are you? Like, how much do you start there and then work your way back to yourselves and to the rest of the company?

That's awesome. Yeah. So your role is CTO. What does that mean for you on a day-to-day and sort of, I guess, a strategic part for the company? Yeah, so it's a, to be honest, a relatively new role for me.

I've had that title for about a year. My journey at the company, as a lot of founders would have, has been to wear a lot of different hats. Started the company, we started the company and, you know, I'd never sold anything in my life before that. But at some point you realize, hey, you gotta, you have to have customers in order to have a business. And so had a several-year run there of figuring out how to sell myself, not myself, but sell our product.

And then how to build the initial sales team and scale that up to to a certain level, and then how do you hand that off to professionals who can continue to scale it up? So I had a chance to work on the go-to-market side of the business for quite a long time, which has really helped as I moved back over into the product and technical side to have a lot of context about, you know, what should we do, what shouldn't we do, what provides value, what doesn't provide value. And so what that leads to in my role as CTO is being able to sort of map the big picture context onto things we're hearing from customers, technology that exists that could solve problems, making ourselves more efficient internally, evaluating new technology for possible improvements in various areas. Probably the least favorite part of what's within my scope is sort of policing. You know, as an engineer, I love to tinker with new things and different technologies and see what's going to work.

You know, when you're scaling a system like we are, we have to, you know, one of my favorite blog posts that's out there is called Use Boring Technology. And the concept of it is like, hey, if it's been around and battered for many years, like it's reliable. So You know, we love Postgres databases. Every once in a while somebody will suggest, and you know, why don't we try this one? It's new.

It has this different thing or it's this or that. And it's like, dude, we've like Postgres database has been beat to death for 30 years. We're going with that, you know, unless there's some hugely compelling reason to change. Why can't I use Hadoop? Exactly.

So that's probably my least favorite part of my job is sort of being the, the drawer of boundaries that says, here's what we can use, here's what we can't use, but it is my responsibility. And then, you know, with the current economic climate and just the way company valuations have changed and fundraising and everything like that, we've always been a very capital-efficient company, but everyone's trying to get more efficient. And so a big part of my job for about the last year has been to drive cost reductions in our cloud spend. Which is surprisingly fun. You know, you wouldn't think that would be fun to sort of go stare at your AWS bill a lot and try to figure out what are the things we can change.

But yeah, it very much is. So I've been doing a lot of that over the last year. And then probably the third big pillar is evaluating new technology. What are those things? When stuff like ChatGPT show up everybody's excited, like where's the meat there?

Like what are the potential applications? What are the risks, et cetera? So that we can have a sort of consolidated company position on it as opposed to just, you know, here's an idea, here we could go do this. So what you're saying is you've already added ChatGPT to the Red Canary platform? No, we haven't.

You know, there are some efforts in underway to sort of figure out what, what might be interesting there. But I don't know, I probably shouldn't even brought up ChatGPT. Every podcast I listen to, they get on the subject of it and I'm just like, okay, I get it. Quiet. It's cool.

It is interesting. Yeah. It's maybe not quite that interesting. It's definitely interesting. Like our discussion about technologies.

There's great technology there in the GPT models, but that's right. Yeah. So, so it sounds like you've been doing a lot of optimization and, and perfecting of the things that you guys are doing. Yeah. Um, do you feel like the, the core mission of what you guys are trying to accomplish has, has stayed the same and, you know, the, the things that you're delivering are still delivering on that?

Because, you know, we mentioned Gartner earlier, right? Like, at some point Gartner is going to take a left turn and decide that this market is something else that it's not, or it's whatever. Do you guys feel like you're still in the right direction? Yeah, it's funny you say that sentence. I was literally on a Gartner call yesterday, and one of the overarching messages is endpoint's effectively dead, which I think is too strong.

Endpoint's not dead, but the concept is correct. The core mission of Red Canary is to create a world where every company can do their best work without fear of damage from cyberattack, right? That hasn't changed, right? And we set up our mission intentionally so that it wouldn't be tied to any particular dataset or problem to solve other than keeping companies safe from cyberattack. So what's changed about the MDR space?

The main thing is that this was already happening, but the pandemic and work from home kickstarted it. Huge move towards SaaS, cloud, work from home, that kind of stuff. And with it, adversaries follow. And so whereas several years ago we would've made very strong statements that, hey, if you're doing great endpoint detection, you're like 90% of the way there. I don't know, made-up number.

Nowadays, that's not anywhere close to that, right? You have to be monitoring identity, monitoring your cloud infrastructure and what's happening inside of that. And so that's been the big shift over the last couple years is we were known as the experts in using endpoint telemetry and endpoint data to detect threats. And we're still really, really good at that. And we find threats continuously.

I think we, you know, some reports coming out, we found something like 37,000 threats, confirmed threats in customer environments last year and continue to do that every day.

But now we have to kind of expand that aperture And one of the ways our customers communicate that to us is they say, you know, tell us the whole story of this threat, right? Several years ago, cool, you told us what landed on the endpoint, but now I gotta go trace through my email and security, you know, email security products and everything else to figure out how did that malware get there, right? We've done a lot in the last couple years to fill in that story and also to be able to detect threats that never touch an endpoint. So that's been the big shift that we've made and it's ongoing, but we've done a pretty good job developing expertise in those different areas, specifically SaaS and cloud. Yeah, I think a good example of what you're saying is the recent CircleCI breach.

Yeah. It started on the endpoint. The attacker landed there and stole a session cookie and then was off doing other stuff. So if you're just looking at endpoint data, you probably would have detected that somebody was there doing something, like something weird is going on, and you could probably figure out that the session token was stolen. But then now you've got to go figure out, okay, well, what did they do with it?

Where did it go from there? Yeah, and in that case, prior to a lot of the new work that we've done, that's sort of getting lucky that they did touch an endpoint, as opposed to they just stole the thing off of, social'd it out of somebody or got it off of a public GitHub repo or wherever else people find session tokens. MFA bombing or something like that. Yeah. Well, that's awesome.

Any exciting things that you want to tease upcoming for you or Red Canary? Yeah, the biggest one would be our community team has been hard at work on the new version of the threat detection report. So that drops here pretty soon. I was talking to Keith, leads that effort, and talking to him this morning and he just looks haggard. He and that team have been working really hard and he's really, really excited about some of the new insights and stuff from that.

We do that every year. One of the, one of my favorite things about what we've done at Red Canary is that we have this focus on making everyone better and positively influencing information security folks. And so Keith leads our community team who has a charter to just go do great things for the community. So they do a lot of talks, they do open source projects like Atomic Red Team is probably our most well-known one. And they lead the threat detection report every year, which is tons of effort.

They spend a lot, a lot of time and energy on it. And then we give it away for nothing. Like, sure, we connect it to the top of our marketing funnel, but it's a giveaway to the community. And so, yeah, anyone who hasn't checked that out in previous years, definitely recommend checking that out when it comes out here in the next couple weeks. Cool.

We're almost out of time. One of the last things I wanted to ask you is, you know, you grew up here. Yeah. You went to school here. You stayed here.

It's sort of a 2-part question. Why are you still here? Yeah. And second, how have you seen the security landscape and the technology landscape in Colorado change? Over your time here?

Yeah, why am I still here when I love to play golf and it's 3 degrees outside? I ask myself that a lot. But no, I mean, it's home and I love it. And I think one of the things that, you know, we aren't explicitly a company that's trying to change the technology ecosystem in Colorado. We're a customer-focused company, right?

We are here to do great things for customers. But I would say I really do love the idea that we're a company that's been built in Colorado. We're a Colorado-based company.

There's been a lot of great Colorado-based security companies, and so we're following on the shoulders of the Logarithms and Pings and everybody else. But the reality is we want to go past what they were able to do and keep going and become a really big, meaningful, dominant player in our industry here in Colorado. I think that'd be really cool as a Colorado native to be able to say, hey, we built the biggest security company in Colorado. Not that size matters in terms of the size of the company, but in size of impact that we were able to make on our customers.

So how's it changed? I mean, I think Colorado is such an— and Denver is such an interesting ecosystem for startups in general.

You know, there's not a ton of VC here. There's not a— you know, VCs from outside the area are sometimes hesitant to invest here. And so those are some of the perceptions that I would hope that success of us and Ping and some of these other companies, especially in security, can help change.

But that's probably the thing we've seen seen most over the last several years in terms of how things have changed is Silicon Valley used to be the only place that you could get funded in a meaningful way, and that's not true anymore with the rise of Utah and Austin and Miami now and everywhere else. And I hope that we can continue to help put Denver and Colorado on the map there, especially in security where we have such a core competency here and so many, so many people who are passionate about it. Awesome. Well, I love to hear that.

Final— anything else that I didn't ask or anything that you want to close with? Nothing, nothing immediately comes to mind. I mean, I really appreciate the time, appreciate you coming down here to our office when it's freezing outside. Stay warm out there. That's Colorado.

Awesome. Well, thanks, Chris. Appreciate it. Good talking to you. This has been Colorado Equals Security, and we will talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes