All episodes

Mary Writz, SVP Product Management at Red Canary

Apple Podcasts Spotify SoundCloud

Mary Writz, SVP of Product Management at Red Canary is our feature interview this week. News from Tattered Cover, Arrow Electronics, PhotoPacks.ai, Ping Identity, Lares, LogRhythm and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11748 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 264 for July 8th, 2024. Alex, we're halfway through the year.

It's hard to believe we are already halfway through the year. We just also passed Fourth of July. Happy America Day. Happy Independence Day. Did you, did you throw some fireworks up?

I watched some fireworks. We were at, you know, places where people were setting off fireworks. That's, you know, that's my joy these days. I don't really need to be the one that actually puts the, the lighter onto the, the wick. But how many fingers do you have left over there?

I still have all of them. You got them all? All 12 of my fingers still left. You're winning. Well done.

You're the 6-fingered man, huh? Uh, hey, let's, let's jump into some housekeeping. We have our Slack channel. We'd love to have you join us on Slack. Um, to get, to get into Slack, go to colorado-security.com and click the Slack link.

While you're there, you might as well sign up for our mailing list, get details about things that are coming up, like the upcoming picnic that we'll talk about in a little bit. And, you know, if you want to help us out as well, you could rate us and subscribe to the podcast on your favorite podcatcher. Put a nice rating, say some nice stuff about us. Yeah. Just this week, Robb, the podcast is now on YouTube.

So, so if you want to subscribe to our YouTube channel, you can do it that way. And so we can stare at— they can stare at our faces while we do this. No, no, no, no faces. They can stare at our, our, our logo while it just sits there silently while, while we talk. Because I've heard we have a face for radio.

We do. We do indeed. Also, we'd love it if you told a friend about Colorado Equal Security. And if you want to support us financially, we do have a Patreon campaign. So you can also find that on the website, sign up, help cover the costs of what we do here at Colorado Equal Security.

Yeah, we really appreciate our patrons. We have a number of them out there who keep us going. And, you know, just a few bucks a month makes a difference. Thanks to all of our patrons. One of the things that we do with the Patreon money, Robb, is every year we have a picnic.

We do have a picnic. When is that picnic going to be? That's a great question, Robb. It's coming up here in August. I believe it's the 26th.

I was gonna say 24th. Let's take a look. Yeah, whichever one of those. 24th. 24th.

24th. Saturday the 24th, about 11 o'clock in the morning, maybe till about 1 o'clock. Come, come by and say hello. We'd love to have you there. You'll have— we'll have some free food, some free drinks.

If you want booze, you got to bring your own booze, but otherwise come and have some fun. Yeah, should be good. Uh, you can also find more information about that on the website. Go to the event calendar and there's an RSVP link just so we know how many people are coming. Love it.

All right, let's jump over into the news. Alex, Morrison is, uh, has, has put in speed cams. Basically, you can get a speeding ticket in Morrison now without a cop ever pulling you over. Yeah, I was just there earlier today, Robb, for dinner, and as far as I know, I did not get a speeding ticket from a speed cam, but I guess we'll wait and see if something comes in the mail. Uh, but in the, the first, uh, I believe it's month that they had it, Uh, 2 weeks, sorry, half a month.

Uh, they clocked nearly 9,000 speeding drivers generating 1.36 tickets every minute. Apparently this is something of a record that this is not a normal amount of speeding that people do through Morrison. Um, I, I think, you know, if, if you know the Morrison area, you know, you're going highway speeds, all of a sudden you get into the middle of a very pedestrian-heavy downtown through Morrison for what, just like You know, quarter mile, right? Right. Yeah.

And you're back up to higher speed. So it makes sense that that might be a place that people will be more inclined to speed and probably a good place for folks to, to start using a tool like this to keep people safe. Yeah. The speed limit there is 25, and if you are clocked going 10 over or 35 or greater, you'll get one of those tickets. It's a $40 ticket.

Um, they do say that, uh, you know, they, they do, they're doing this for safety, not for revenue generation, even though I'm sure that they're happy about the revenue generation. Uh, you know, it takes an officer, you know, I think they said 12 to 18 minutes or something like that to, to issue a ticket. And obviously they can do that much, much faster with a speed cam. Yeah, there's, it's interesting. And I was in Europe earlier this year and, um, they had speed cams everywhere and it was, it was interesting to watch the flow of traffic because apparently everyone knew where the speed cams were gonna be.

So people would speed all the way up to approaching the speed camera and it would slow down again. And so I, I don't know that there's a lot of changing human behavior, but it was a, it was interesting to see. Uh, if there is a spot where you want people to drive slower, uh, this seems like an effective control. Yeah. Right.

There you go. So, I mean, you just put cameras everywhere, I guess, and, and it'll eventually make us stop speeding altogether. Probably very expensive. Yeah. Oh, all right.

Let's move on. Um, we have the, uh, uh, a little bit of maybe sad news or maybe, maybe not that big a deal, but, um, the, the, uh, historic Tattered Cover chain, you know, know, we, I think there's, you know, a handful of them around Denver. Um, they have been sold to Barnes Noble, America's biggest bookseller. Yeah. I, I feel like, uh, these days maybe America's only bookseller is that, uh, or at least only major bookseller.

Um, besides of course Amazon, but they don't really have stores brick and mortar. Yeah. Um, but yeah, you know, the Tattered Cover has been having financial troubles for a long time, not surprisingly because, uh, bookstores are not super popular anymore. Um, and they've gone through several rounds of leadership as well as having financial problems, and they recently, uh, declared bankruptcy. And so Barnes Noble is buying them out of bankruptcy.

I think on the positive side, the plan is to keep the Tattered Cover name and essentially let them run as a sort of semi-independent bookstore. Yeah. But one of the things that Tattered Cover leadership is excited about is They're gonna get the technology platform that Barnes Noble uses, which I guess will be a leap ahead for Tattered Cover to accomplish their mission. I, I imagine also they will be able to, uh, buy books at cheaper wholesale prices because they're with a, you know, larger conglomerate, so they can probably get better profit margins, all sorts of good things. All that good stuff.

All right. Uh, moving on to our next story. Um, This is the first of several AI stories that we're going to talk about, Robb. But coming up, there is going to be an AI summit in Denver to focus on how to address affordability. Yeah, I think it's kind of an interesting idea that the mayor, Mike Johnson, is calling this, this summit specifically to get people who are thinking about AI, thinking about how AI could be used to come address some of the biggest problems for the city, one of them being affordability.

But they're looking for kind of big thinkers to come in and say AI can solve these other problems for the city as well. And, you know, at first it's easy to, to kind of scoff at the, the, the idea that we're just going to pull in AI to solve all these big problems. But, you know, this is, this is how you start to figure out where it's useful, right? Try, try and see if it fits any of these gaps. If the answer is no, you haven't lost a ton.

You probably still learned along the way. If the answer is yes, fantastic. Yeah. I mean, even if you don't solve the problems, I'm sure that there will be positive things that come out of the summit. Um, I did think sort of when I first heard this, like, eh, you know, that's kind of a little bit hokey.

But, um, I think like you were saying, I, I don't necessarily want to just completely dismiss it outright. So I'm, I'll be interested to see what the outcome of the summit is. Um, the summit is also happening sort of in conjunction at the same time as Denver Startup Week. So I think that that's a, a nice, probably planned coincidence that, uh, you've got a bunch of, uh, startups that are gonna be coming and presenting on things. As well as now having a specific place to talk about AI.

Good stuff. All right, let's move to our next story. This is just one of those kind of summary stories. Basically, there's some release, some profit and loss release news. Man, I had a hard time with that sentence.

There's some news about which companies in Colorado have had the best profit and which have had the worst losses in the last year. And it's kind of interesting. Some actually, at least the number one profitable company was one I wasn't familiar with. How about you? Yeah, I, I was aware of Avantiv.

It's— the name is new, but the company is old. You know, oil and gas company, and they've been around for a long time. And not surprisingly, oil and gas companies, they make money. Well, some years they make money, right? And some, some years they make no money.

That's true. So this year they made over $2 billion in profits, which is a record for them. And number 2, DCP Midstream, which, you know, as we know, has now been sold and, you know, to Phillips 66 and is not going to be around. So those are Colorado's top 2 profitable companies. Number 3, Liberty Media.

Number 4, Molson Coors, which, you know, is that a Colorado company? Yeah, maybe not so much anymore. Aero Electronics behind them and then Sun Energy. Oh, and there you go. Look at that.

Crocs coming in number 6. How about that? Yeah. Everybody loves Crocs. We want to talk about the ones that lost the most money this year.

Yeah, pretty big losses. There were some on the loss side also. Sorry, I'm trying to find the list again. Newmont was— Newmont Mining Corp. Newmont Corp., $2.5 billion loss. I think I'm interested the nuance behind some of these because I feel like Newmont made a big acquisition this year.

So That could be part of it, right? Spend a bunch of money buying a company. Second was Dish Network. We know Dish has had some problems. They also essentially acquired a company this year when they invested a ton, right, with building out the 5G network.

I imagine that, you know, they're still in an investment phase there. VF Corp was an interesting one that, you know, the fact that they lost quite a bit of money this last year was a little surprising to me as a retailer. I didn't see that coming. Yeah, I think, you know, retail has kind of had hard times lately just with everything going online. It, you know, makes retail sales a bit harder.

But anyway, and then the last one that I had on that list was SSR Mining. I don't know exactly why they lost money also, but I feel like they maybe also made an acquisition this year. Oil and gas did really well. Mining, not so much. Did not do so well.

Yeah, I guess we could look at commodity prices too over the past year. I don't know where they sit. Yeah. So, well, you mentioned, you alluded to the fact that there was going to be another AI article or 2 or more. Well, this one is, is kind of a follow-up to that Colorado's AI law that was passed, what, about a month, 2 months ago.

And there's a lot of leaders, especially technology leaders, who have been clamoring to see that law get amended before it goes into effect. Yeah. And so it has gone into effect, but There is, there's been some concern about it. I think mostly because people feel like that the law was a little bit rushed. One of the, the areas that is of concern is the definition of what AI is.

Right? Right. I, I think everyone sort of agrees on the spirit of what we're trying to accomplish with this law, but there's some work that needs to get done in order to clarify things to really make it do what we want it to. Yeah. The last thing we want is someone to, to interpret you know, AI to be any old application that gets delivered using an algorithm to make a decision.

Right. So they're trying to be more specific. I do want to just clarify, the law is officially enacted after the governor signed it, but the, the law doesn't go into effect until 2026. I think it's like March of 2026 or something. So we have, we have like almost 2 years to figure out exactly how you, how you fix this thing.

And the governor, governor did sign a letter also saying Hey, we, we, we understand that this is not perfect right now and we're gonna work to make it better. Yeah, there's an intent to change it. So this article goes into a few different folks, Dan Caruso, who's a local private equity guy, and actually one person who'd been on our show before, Chris Erickson from Range. Both of them talking about, you know, hey, hey, we're not opposed to this as an idea, but we gotta be, you know, smarter about how we write this so we don't scare off investment from coming to Colorado. Right.

Yeah. You want, you want people to succeed in, in technology and use AI. And make sure that the law supports that. All right, next story, another AI story talking about a Denver startup that is using AI to generate professional headshots. Yeah, this one was kind of neat.

It's a, when they say a startup, it's one person, I think, at this point. That's what it sounds like. One guy who helped lead engineering for a couple other tech companies and realized, he realized that the technology he had created or kind of for fun, you know, basically allowing you to enter some text and saying, you know, make Alex look like this. And he's like, well, I could use this for a, for a reason. And, and, and, and basically the first purpose he came up with was, you know, give me, give me 10 pictures of you and give me $10 and I will generate a professional headshot of you, um, that, that you could use on your LinkedIn or whatever else you need.

Yeah, it, it's an interesting idea. Um, I think that there are other, uh, startups out there doing similar things. Uh, but yeah, I mean, I think as you said, you know, at his previous company, uh, he developed this and, uh, sort of made it available to the company on Slack just sort of as a, hey, look what I did. And everybody really liked it. And, you know, you could send texts to the Slack bot and say, hey, it was, it was really a picture of one person.

You could say, hey, make a picture of this person doing whatever. Right. And then he finally realized, oh, well, I could actually use this for a real purpose instead of people screwing around and making silly pictures. He, he also mentioned that, you know, in addition to the headshot use case that he's, uh, he's created a, uh, the ability for you to have a photo of your dog made in all kinds of different scenes. So you can have a formal like oil painting of your dog from a photo.

You can have 'em in Christmas, uh, motif and they're in Valentine's Day motif. Just, just basically looking for different ways to, to use the same technology to, to make a little bit of money. Yeah. I, I don't know if he said it, the startup's name is PhotoPax. So check it out when you want to make your AI-generated headshot.

Good stuff. All right. Where are we at? We're— oh, I think we got the report card for Denver, for Denver security, right? Yes.

So next article, there was a report by the Denver City Auditor saying that the city lacks a comprehensive approach to cybersecurity risks, which I think on the face of it sounds pretty damning. Yeah. I mean, I think it's reasonable to say that most organizations do not have as comprehensive, right? Comprehensive is a big word. And, you know, depending on who's grading, I think anyone could be said to not be comprehensive.

But, you know, there's a lot of opportunities here. And, you know, you and I chatted about this a little bit when it first was announced. And I think our hope is that this gets the resources necessary to protect, you know, all of the citizens and, you know, those of us who use Denver water who don't live in Denver. All kinds of other folks who rely on Denver. Let's get some more investment.

Let's make sure we're doing the right things there. Yeah, it sounded like from this, you know, there, there are things in place. They may be not as mature or widespread as they should be. Things like, you know, not validating that controls are actually being followed through on and things like that, as well as, you know, like with any sort of municipality, there are multiple different constituents that use the city network. That are maybe not directly tied to the city, uh, you know, other departments and things like that, that, uh, the, the security team doesn't necessarily have control over, but, you know, trying to bring those, um, closer to a, a single program with, uh, with agreements and other things like that so that, you know, can be better for everybody.

I, I do think that there's an interesting note here that the assessment was performed over the course of 2 years from January 1st, 2022, uh, until the end of December 2023. Which I think just goes to show, like, when you get a big organization with lots of bureaucracy, like, if it takes 2 years to figure out how good the program is, right, how long is it going to take to, to make the program, right? Like, I certainly super appreciate the folks who are, who are kicking in there. You know, obviously our friend Ashley Bolton is running security there, and I'm confident, you know, she's, she's building the best thing that they can there, and whatever support they can get is going to be super appreciated. All right, moving on.

Uh, we have a blog by Ping Identity talking about session management. Uh, and how it works and why that is important. Uh, Robb, what is session management? Well, session management is, is how people— how an application keeps track of who signed in and what privileges they have. And I think it's really important to realize that it's not necessarily— there's not one size fits all for how, how that works.

And, you know, you might assume that because I logged in from this machine that no one could could take over that session. But, you know, oftentimes we're using cookies. Um, it's sometimes it is relatively straightforward for a bad guy to trick you to take a session over once it's going there. So, so I think that understanding, you know, what token binding is, what authentication looks like, authorization, what kind of risk factors might be a part of this is a pretty big part of session management. Exactly.

And the article talks about some of the possible attacks you can have related to sessions and session management, session hijacking, Uh, session fixation, which is similar but a bit different, uh, man-in-the-middle attacks, of course, and then also, uh, some best practices that can be implemented to help limit those particular kinds of attacks. I think it's fantastic when, when folks like this, like Ping, write these kind of articles that give us a chance to dive a little bit deeper into one area of security that, you know, frankly, for a lot of us is not, it's not second nature, right? Yeah. And identity is not the same as a firewall packet or a you know, as writing code, whatever, whatever you're comfortable with. So I love these things, and hopefully if you're not familiar with session management, you can take a look at this article.

Sweet. Uh, next we have a blog from Laris talking about the power of modern-day purple teaming, uh, a consultant's perspective. Yeah, I think that, you know, the key to purple teaming, right, is you're taking, you know, the red team, those attackers, pen testers who are trying to get in, and the blue team, the folks who are defending, and having them coordinate together to start to figure out, you know, where, where there's visibility, where there's not visibility, what kind of attacks are having success. And by combining the two together, that's, that's really where we get the power out of a pen— a red— a purple teaming engagement. Yeah, I think as penetration testing has evolved over the years, you know, the purple teaming concept has become more and more popular.

And, um, you know, I think it is really powerful because it used to be, you know, you'd have someone do a test, hand you a report, um, the, the blue team has to then go back, look at logs, or, you know, maybe just try and fix what was found, and you don't really get the value out of it. So doing those, uh, the purple team where everyone's together doing the testing at the same time makes it so much more powerful and better in the long run. I think moving away from these engagements where you hand a range of IP addresses to an attacker and say, go get them and give me a report, into something interactive like this, it probably costs a little bit more But man, you're going to get so much more value out of it. Agreed. All right.

Let's move to our last story. We have a blog by LogRhythm, How to Ensure Your Data Is Ready for an AI-Driven SOC. I guess this is our last AI article. Yes. And what I liked about this is it's not— to me, it's not actually really about AI even.

It's just about how do you, how do you ensure that data goes into your, your SIEM or your log repository is usable, right? And usable for whatever the purpose is. Yeah, I think you could totally take AI out of this article and the concepts would still apply to human is doing the exact same stuff. So some of the things that they talk about are the challenge of poor data quality for AI, right? Like if you garbage in, garbage out, if you don't have good data, you're not going to get good results out of it.

Yeah. If you're, if you haven't gone through and understood everything you're sending into your SIEM, it's, it becomes impossible for an AI to interpret, you know, quality consistency, then get rid of the noise. And I think it's really common for us as security people to just say, ship it all over there and then let me start to figure it out versus really taking your time to make sure we're getting the right things. Yeah, maybe, maybe everything sounds good, but wouldn't, you know, everything might not include the one thing you need if you're not careful. Right.

It also talks a bit about what the requirements for high-quality data would look like. So you want to not just like, here are the bad things, but here are the good things. Things like how easy can you get the data in? Um, you know, making sure that you can have good normalization and enrichment of that data. Again, all sorts of things that are important even if an AI isn't doing this, but, uh, doubly important if, if some— if it's not a person knowing the context, uh, is looking at the data.

Good stuff. All right, well, let's jump over to our calendar of events. As a reminder, on colorado-security.com, we do have a calendar. You can go out— actually, I spent quite a bit of time adding events. There's maybe like 30 new events, it seems like, got added in the last couple weeks.

Yeah, the summer is usually quiet for events. Yeah, well, through the end of the year, like, uh, we got— saw a lot of stuff get, get added on there. So, um, through July we have maybe 6 or 7 events. Awesome. First, uh, ISSA Colorado Springs is doing their Cybersecurity First Friday on July 12th.

On the 16th, we have a couple of events. ISSA Colorado Springs is doing their July meeting, Conversations That Count. This This is about having those critical conversations. And also on the 16th, CSA Colorado is having their meeting, Responding to the Quantum Computing Threat. Oh, very interesting.

On the 17th, there are a couple events. Denver ISSA is doing their annual barbecue and picnic. And Denver OWASP is doing an event, AI in the Age of Application Security. On the 20th, ISSA Colorado Springs has their July mini seminar. It's Blackout Brainstorm.

They're doing a tabletop around what happens if an EMP hits. Very interesting. On the 23rd, the Let's Talk Software Security group is doing an event, What Do the Developers Think of Your Security Program? And then on the 24th, ISC² Pikes Peak has their July meeting. I think we should also just call out, reminder, August 24th, sign up for the picnic.

We'd love to see you there. Yeah, also check out the event calendar. There's lots of events in August as well. All right, let's jump over to jobs. Top of the list is an IAM architect role at Pax8.

We'd love to have you there as we're looking to re-architect, rethink the way we do role-based access and zero trust at Pax8. Gates is looking for a senior cybersecurity analyst. Brownstein Hyatt Farber Shrek is looking for a CISO. Oh, very nice. Affirm is looking for a Director of Product for Trust and Safety.

That looks like a pretty cool, cool role. If folks haven't— if you're looking to work at a financial services company, that looks like a pretty good one. Bank of America is hiring a Senior Information Security Officer. Meta is looking for a Security Partner for Mergers and Acquisitions. HealthEdge is hiring a Director of Governance, Risk, and Compliance.

Presidio is looking for a Vice President for their Cybersecurity Practice. So this is John Jensen's replacement. He's retired. Oh yeah, I met, I met John a couple months ago, or I saw him a couple months ago, and he was telling me he was gonna, gonna take at least take a break, maybe not retired forever. All right.

Um, DAT is hiring a Security Analyst 1, and Ryder System is looking for an Application Security Engineer. All right, well, that is it for our newscast. Alex, I, I believe we have an interview. Could you tell us what we've got? We do.

Um, I actually sat down for a follow-up with Mary Writz Mary is now the SVP of product at Red Canary. Uh, we had Mary on the show way back at episode 112. Uh, that was in 2019. Yeah, it's a long time ago. Uh, it's been a long time.

So 5 years, Mary and I caught up, talked about what she's been doing in the, the meantime and what she's doing now and lots of other great topics. I also, uh, tried to convince her to maybe do some more interviews for us in the future. That, that, uh, the interview that did with her on in episode 112, she subsequently did a number of guest interviews for us with some women in, in cybersecurity product management. Awesome. Awesome.

Well, thanks, Alex, for getting the interview, and thanks everyone for listening. We'll talk to you again next month. Thanks, Robb. Hi, this is David Stapleton, Chief Information Security Officer with CyberGRX. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equal Security. This is Alex Wood, and this is our feature interview. I have a special guest today, a returning special guest, Mary Writz. Welcome, Mary. Hey, Alex, it's so great to be here again.

Uh, it's great to see you and, uh, great to talk to you again. Um, for those of you that, uh, don't know Mary, you can go back, uh, oh man, I looked at it earlier and now I forgot the number. I think it's episode 112 or somewhere just there about 5 years ago. We had Mary on the podcast, talked a lot about our combined background and Mary's background, things about product management and lots of other stuff that Mary had been up to. So if you want to get the part 1, go back and take a look at that.

We're gonna continue some of that today. Um, so Mary, uh, when we talked to you last time, uh, you were at Ford Rock. You are not at Ford Rock anymore. Uh, why don't you give us a little bit of an update on, uh, on what you're doing now and what your journey from there to now has been? Yeah, so a lot has happened in 5 years.

There was a global pandemic.

Um, but yeah, little things, little things. Yeah, so Fortrock isn't even Fortrock anymore. We IPO'd, which was really exciting, uh, and then Fortrock got brought back under private equity after, uh, the tech sector really got devalued. And then now they're merged with Ping. Uh, in the meantime, I did a hop at an online fraud detection company called Sift, which was really fun.

It's like the furthest I've shifted from cybersecurity, but it's it's so similar and it's so different, so we can talk about it if you want. But online fraud is interesting. And then now I'm at Red Canary, so back to sort of my roots of deep cybersecurity detection and response. Um, but yeah, it's— and then yeah, I feel like since we last talked, I was thinking about how much has changed. But different things we can talk about are like how tech companies are valued and what they prioritize.

And we've seen a lot of Like shifts in the market, especially with SIM. So the world is different, and whether you're building product or buying product, you're probably feeling some of these changes. Yeah, for sure. I think it would be interesting to talk a little bit about your time in the fraud detection world. The— I think security people probably think, oh, you know, fraud and security, that's basically the same thing.

Um, I'm guessing it's probably not. Yeah, I— to me it also felt familiar, so I felt really comfortable going to lead a product, and I really had a lot of fun. But I'll say the, the thing I noticed most about how fraud is different from cybersecurity, it— you feel it with, um, sort of like the MO of the team and the team culture. And that's because in cybersecurity, most people grew up out of IT, and in fraud, they grew up out of finance or customer service or help desk. So it's just a different demographic, a different profile.

And so the adversary is the same, and actually some of the things you're doing are exactly the same, like looking for account takeover, but the teams report up through a different group. They have different funding. They have different tools. A lot of the product work around fraud happens in payments. So it's specifically companies that are selling things online and want at time of transaction just to make sure there's nothing going on.

But it also gets involved in content, people posting content. Also just like general login or like refund fraud, loyalty point fraud, those things come up. So there's different areas of it, but it felt to me dramatically different than cybersecurity teams and identity teams, which are the 2 other places I've led products. Yeah, I'd imagine also, you know, sort of my experience with fraud and that sort of thing is there's an acceptable level of fraud, right? That's sort of built into how businesses operate, right?

You know that there's going to be some loss, some breakage, some whatever. And in cybersecurity, while it is completely unrealistic, the goal is always zero, right? Like, we can't have any cybersecurity incidents, none whatsoever. That's a failure. But in fraud, it's like, yeah, we're fine at X level of fraud.

So, I mean, that to me seems like a little bit of a difference too. It's— yeah, you're absolutely right. So there's an expected level of fraud, and you never go for no fraud because what's happening is you're impacting customer experience, which is an absolute no-go. So you're trying to balance not annoying your customers that want to pay money with the fraudulent activity. And so you definitely accept an amount of fraud.

And so it becomes probabilistic versus deterministic. Cybersecurity, you're trying to get to zero and have everything explainable and understandable. In fraud, you're like, uh, probabilistic in working in ratios. And the, the technology under the hood that's really interesting, the cool— it facilitates neural networks, machine learning in unexplainable black box ways, but it actually is really effective. But that technology would never be accepted in the cybersecurity space.

It would be considered like, no way, no way. You're just gonna give me a score of how bad this is and assume I'm gonna trust it. Like, that's not gonna happen. But in the world of fraud, you're like, I don't know, this fraud was like 99.123% fraudulent. Like, Why was it 99.123 versus 99.124?

Nobody knows. The data scientists, like, it's a total mystery. But on average, it works and your business operates. And so, and so it's okay. The other interesting thing I'll say that I noticed about fraud, I hadn't thought about it.

So you get pretty good at finding fraud when it's a bad person on a malicious device or network. The hardest part of fraud to solve, the thing that nobody's cracked, is the good people on good devices doing shady things. So you as Alex buying a thing and saying, I never got it, it wasn't ever shipped. That is the hardest thing to deal with. So similar to insider threat and security, which is super hard to deal with, sort of like good people doing bad things in the fraud world, also the hardest problem to solve.

Yeah, I hadn't really ever thought of that either, but that, that's a pretty cool parallel. Do you think that there are things from that fraud world that we could learn on the security side? Yeah, I, well, the first thing I was thinking of is like everybody's trying to, like identity is the common thread in all of this and account takeover, credential compromise is the, like if we could all join forces and use the like deep machine learning from the fraud companies, plus how we look and think about it very specifically on the cybersecurity side with like ITDR. I think we'd be really smart together. The hard part is like the bureaucracy of connecting these teams and the thinking, but that like there's joint areas that we could maybe tackle together, which would be fun.

But, um, have you seen that happen anywhere? I, I'd imagine that there are That there are some businesses somewhere that have also figured this out and are trying to do that. I, I saw like 3 businesses do this really well, and it was all almost always in the banking or finance sector, and they actually put these groups in the same organization. And so they have one like executive general manager type person that cares about all of it, and that worked the best. Yeah.

And yeah, that definitely worked the best. But it's like they're really forward-thinking, sort of innovative leaders in their space that are really trying to like make their mark in shifting thought leadership and how this can be done. So it's a certain kind of person and leader that's leading the charge. Yeah. Oh, that's great.

All right. Enough about fraud. You're not doing fraud anymore. But I do think that was an interesting sidebar. You have made yourself— you're— I can't talk.

You have made your way to Red Canary. Yeah. You are now the SVP of product at Red Canary. How did that happen? Why did you go there?

You know, what's the story behind all that? I have been a Denver-based cybersecurity product leader for a long time, over 10 years, and I keep flying to Silicon Valley to work with like cool cybersecurity companies, or because there's just a lot happening out there. And I've always had my eye on Red Canary as like a really cool company in the cyberspace that maybe one day would work. But it would— it's, it's kind of like, um, finding your partner in life. It's like the right person at the right time, right?

When was it ever the right you know, time. And so when I left the fraud company, I just, I decided to do consulting for a while to see what I would do next. And you had connected me to the CEO of Red Canary, so I had a connection with them. And I was just having lunch with the CEO, Brian Byer, and he said, why don't you do some work with us? So I spent, um, a few months doing some product strategy work with Red Canary, and then we decided, hey, this has been really fun, maybe we should keep doing this.

And we could use, uh, like, so yeah, it was interesting entry, but I liked that. It's not often you get to basically interview a company for 3 months before you join and see what everybody's like and see if you're a good fit. Product's very much, um, there's different kinds of product leaders and it's not neither good nor bad. It's just figuring out if you're a fit and sometimes you don't know till you're all in and then it's, this was fun to test. Yeah, it was sort of like a mutual contract to hire, right?

Like you were testing them and they were testing you and everybody decided that, you know, enough of this dating, let's make this permanent. Yeah. Yeah. And so I, yeah, so that's how it started and I've really enjoyed the team. It's also for me just personally been fun to be a part of a Denver-based company.

It's been a long time and I've really loved that. So very happy. Yeah, I'm curious, how has that been different? Is it just, um, just that there's more center of mass here, that there's more people or less travel, or what, what's been different about being culture? Yeah, a couple things.

One, definitely less travel. So I would— I was always flying, and so now when we do company meetings or gatherings, I can ride my bike. So way less travel. But also when we do events, like, we're doing it in the city that I love. So it's like an event at Mile High Stadium, or I'm doing dinners in a city, and I'm getting to— I'm just getting to be in the city that I love.

Um, and then also just random tips. So you're with— I don't know, Bread Carey is over 400 people, and someone will say, who's a good plumber? Or, hey, there's this fun concert happening. And I just feel like it's connecting me to my city. And I ride my bike in quite a bit, and I feel like I love— I just love that.

I love that I can do that. Yeah, that is awesome. So while a little bit different, I think, you know, Red Canary is kind of in a sweet spot for you in terms of experience. You've had a lot of experience in not exactly detection response, but SIEM and other, you know, security monitoring and things like that. Um, how's it been for you kind of going back to a, an area that, that you have, uh, great experience in?

It's, it's fun. And I, I thought what's interesting is, so I, I, it's so fun to go to back to something that I've been doing for 20 years and feel like I really understand the culture. But actually I had been gone for, I don't know, like 5, 6 years and it like things had changed. But when I had left cybersecurity, MDR wasn't really a big thing. It was just up and coming.

Nobody knew what it was. Everybody was doing the thing where you try— you buy a SIEM and you're putting all your data in it and you're trying to hope that you can detect something. I feel like the world's really evolved and we're getting much more deliberate about how we do detection and response and threat hunting. So it's been fun to learn how Red Canary has done this and evolved. I feel like while I'm bringing my product expertise to them, they're sort of teaching me what best looks like in this area right now.

So, um, it's been fun. Um, has it been any different for you 2? Because, you know, Red Canary is sort of a mix between a, a product and a services company, right? It's not— you guys, you're not selling services exactly, but there's a lot of services involved in an MDR product. Yeah.

Has that been different? Yeah. So it's interesting. So in product, I started building software and you'd ship it to people and say, hey, good luck with this, you know, ArcSight software we just built. Now you got to deploy it.

And then the world moved to SaaS. And so then we deliver not only product like identity software, but we run it and operate it for you. Now it's a SaaS service. What's different about Red Canary, it's like the next evolution. We not only build the software, run the software for you, we actually also operate it for you.

So we are doing the detection and response jobs on top. But no one wants to completely— well, some people want to completely outsource that. But most people say, hey, I want to know what you're doing, because this is really important. So then there's an element of sharing information. But yeah, so I think Red Canary is just ahead of its time on not only building the software, running the software, but being the operators of the software.

So it is a combination of software and services together, which actually is a great outcome. Who better, who better to operate your software than the people that build it, right? Yeah, I mean, and I think having that, uh, the expertise of, uh, of those folks there really helps too, right? So, um, in the, the past, you know, I, I've been a customer of many, uh, many SIEM vendors where it's, uh, you know, as you mentioned, hey, here's your software, even if it was cloud-based, like, here's your software, you know, figure out what to do with it. And most likely you had somebody that kind of knew what they were doing.

But whether it was the software itself, whether it was the incident response part, whether it was, you know, something else in that chain, you probably didn't have all of the expertise that you wanted in order to make that work right. But when that's sort of built in, it makes it a whole lot easier. Yeah, when I was at FortiRock, it was that SaaS model, and I would have killed for the team of 100 experts that just did identity and access management all day. And then at Red Canary, that's what they have. So it, it's like, it was exciting and, you know, different, but also it feels like the future of how software really should be and should continue evolving.

But also it's because, you know, if you think about the MDR space, Did you know, fun fact, over 600 people say they do MDR right now. 600 vendors say they do, which is crazy. Most spaces you can name 4, maybe 6. Yeah, 600. So what happened was just every MSSP said, I do MDR overnight.

So it's an interesting— Yeah, I mean, that is a good question. What What either is your definition or, you know, feel free to fall back into the Gartner or Forrester or whoever it is that makes up the definitions. What is the definition of MDR, the difference between that and say just security monitoring or something like that? Like, what— how can you say that for 600 companies if it's— are they all meeting that level of rigor for actually doing this, this thing. Yeah, they're not.

So Gartner and Forrester, like when they do their reports, there's like a dozen vendors that they actually feel like would qualify for doing MBR and would rank them. But then you, they start to like stack out. Are you a services-based vendor that does a lot of customization? Are you a pure software that allows no customization and things in the middle? True MDR is usually kind of defined by being more software-led, higher margins, meaning you have more consistent quality at scale is kind of what that means.

MSSPs just at high scale, their quality deteriorates. That just is what the numbers show. Yeah. Okay.

I think that the I'll just call it security monitoring as a bigger term than, than MDR, is one of the, the, the problems that has been in cybersecurity since the beginning. You know, that, you know, vulnerability management, identity, there's these, some of these big things that have been around forever and continue to be things that are core to, you can either call them core problems or core things for us solving the problem. Yeah.

Do you see that continuing into the future? And if so, for, for security monitoring specifically? And what do you, what do you see changes, you know, kind of looking forward? Yeah, I, I think it's been, has some really interesting changes happening. So historically, if you wanted to monitor for security detection and response, if you looked at endpoint data, that's all you needed to make sure you're not going to get popped.

And so there was all this focus on endpoint because of the, the difference with MDR and just general security monitoring is like really laser focused, just making sure you don't get breached. But now with modern adversaries, they might not touch an endpoint, or by the time they touch an endpoint, it's really too late. So now the surface area that's really interesting is identity, because that's the place where you can get data that gives you insights into what's happening. So I think you're seeing endpoint never goes away because it's really important. But there's this move to the surface area of identity and cloud for finding things that never touch endpoint.

So that's one thing is like the shift to identity, which, by the way, is really Identity is more probabilistic versus deterministic, so it feels different. Identity threats feel very different. But another change that's happening is in that deterministic space of endpoint. I think Microsoft is doing the most with trying to automatically disrupt things. So they have this automatic disrupt technology that I've been watchful of, but they're like not even giving any vendor a chance to look for a threat and respond to it.

They're just handling it inline and you don't even have a say about it. And so I think for threats that are really tried and true to understand, and there's a specific pattern, like, they're just gonna cap it at the knees. And so I think parts of endpoint detection and response will get more commoditized by software vendors. So those are a couple interesting things happening. But the last thing I'll say is around security monitoring.

Just if you step out and think about— I think about a lot about the vendor landscape and not the practitioner landscape. So I think about both. But when I think about the vendor landscape in cybersecurity, we're seeing this swing back to platform, and we've seen it a few times over the last 20 years, like platform to best-in-breed to platform. But they're— I'm calling them like mega vendors, but it's Microsoft, Palo Alto, Cisco, CrowdStrike. Those 4 are trying to own everything and sell everything.

So As far as security monitoring, they're trying to own everything really with the security operations stack. So that's another shift that's happening. So those things are— that's how I see it from my side. I don't know if you see it differently from your end. Yeah, I do see the platform piece specifically.

And I think part of it is the way that, you know, venture capital comes into play with security companies. Right? Like, you're, you're trying to incubate a whole bunch of different companies in areas where there can be disruption. And you're probably going to have a decent-sized number that make a little disruption, they're going to get bought by somebody. You're going to have a couple that are, you know, true leaders, visionaries, new something, and they have a chance to to continue as, um, as a company themselves with some new innovative product.

Um, and, and at some point, the, you know, the way that the, uh, the market goes, you know, they're gonna have to IPO. They're gonna have to continue to grow, uh, in order to, to continue to have their stock valued appropriately. And if they're gonna continue to grow, they've got to do new and different things. So then it— you have to become a platform, right? If you're going to stay around, you have to.

There's no choice. And so I think we've seen, though, you know, a few of those winners like CrowdStrike and Palo Alto and other things like that. And, you know, at, you know, for the longest time, you know, Palo Alto was a firewall vendor. Right. And that is not what they are anymore.

No way. Yeah. You can most definitely buy firewalls from them. But, and I have no idea what their percentage of revenue from different things are. But, you know, I have to imagine that that is, you know, a minor piece in their portfolio today versus all of the stuff that they do because they need to keep growing and Uh, so they got to add more and more things.

So I think at some point, uh, well, and also those cycles are fairly long because you can't become a platform overnight, right? So, uh, at some point there's going to be the next generation of those companies that gets, uh, incubated and, you know, some of them survive and then, um, disrupt whomever and eventually become a platform too. But this is, you know, 10 to 15, maybe even longer year cycles. So I think we're we're continuing to see that, and I think we're gonna, you know, see it over and over again. Um, it's just hard to figure out, you know, which winners to bet on or whatever, you know.

I know. Yeah, I think it— yeah, I think it's also— it's been interesting in the last 5 years since we talked, the tech market and the tech valuations changed so much. So it used to be when— oh man, when we were talking last 5 years ago, sometimes I look at Okta because they're public and because I was in the identity space, but they used to have the 40x valuation. So however much revenue they make, the market values them at 40x that revenue. Um, and then we saw this huge— so they were the top end, and like a lower end might be a 10x multiple, just a normal company maybe could get 10x, but that totally compressed.

Um, you know, it came— the highest end you can possibly get now is 20x, and most people are more at 5x. So it's a different multiple, but that made it easier to acquire all of the tech companies underneath to consolidate. So that's where PE came in and bought a lot of people. And that was kind of connected to, it was like 2022, the Silicon Valley Bank collapsed, the interest rates were rising. It was just like a lot of things compressed those multiples.

And then we saw a lot of acquisitions, particularly private equity swooped in. No one else had money, but they did. Um, but yeah, so I think, and I think there's, you know, pros and cons to the platform, but what I've seen is it's just a pendulum. You get enough platforms and, and then you realize, oh, it's impossible to do everything great. And there's a few things that maybe need to be great.

And then you'll see these best in breed emerge because it's a really important thing to be great at. And then it goes back and forth. But you're right. I, these swings feel like 10 to 15 year swings. Yeah, and I think the platforms are great for some people if the particular things you need can all be found on one platform.

Yeah, right. But if, if you need, you know, piece A and this platform company meets your needs for whatever reason and you need part B and this company over here meets it, well, now all of a sudden you have, you know, multiple pieces of different platforms. And then none of the platforms help you because you're basically at a point solution in multiple places. And, um, anyway, but yeah, the other thing I've seen is some of these, like Microsoft is really good at packaging their giant platform. They have so much security technology and they're really geniuses at pricing and packaging, but they'll get decisions made way like above the CISO.

Like we're going to go all in Microsoft. You've got to use MDE. You've got to use Sentinel because we've just bought that big license. And so some of the choice being taken away, which can feel, well, I don't know, it could feel frustrating or it could, I don't know how it feels, but it seems like the new, because the big platforms are such big enterprise plays, these, it's the selection of products, your choice can be taken away depending on your procurement and your leadership in your company. Yeah.

Yeah. And I've always felt like with Microsoft, that if they ever put any effort into the, the pieces of managing all of the different things that they have and made that easy, then, then they would win at everything, right? It's always like you have something that, that, that fits the need, but you have to have 3 engineers who are PowerShell experts to be able to you know, plumb it together with a bunch of stuff to make it work. Or, you know, they— it can only be done in the GUI and the GUI is horrible or, you know, things like that. And if, if they made something that managed all of these things easy and simple, then there would be no reason for people not to use them as a whole platform.

No, that's true. And I, I like them a lot. I like their technology a lot. I like them a lot. And I know they're working on things like that, but sometimes it makes me giggle to even understand how much you're going to pay them.

You need like a 2-week consulting engagement just to understand like your price. It was always amusing to me. You could, and maybe you still can, I don't know if you still can, but the, you would, you used to be able to get a certification from Microsoft in pricing. Yeah, just in like, like there's an actual, like you could, hey, let's train you in how to price your Microsoft stuff and get certified so you can be a, you know, Microsoft, I don't know, pricing specialist. You know, be able to, to tell your company how much it's going to cost to use Microsoft stuff.

Yeah, yeah. So they're like, their packaging is genius because you buy like this E5 license and you get everything, but it's still unclear what you're actually gonna pay. Uh, yeah, yeah, yeah. Anyway, um, uh, okay, you— I know between, uh, your fraud gig and Red Canary, you said that you Uh, you did a little consulting. You started a consulting business for yourself.

I think, uh, if I remember from talking to you before, a little bit of that was, uh, was quality of life based. It was. Um, I'm curious, um, what you do now that you're back working full-time, you know, what you do to make sure that you, uh, continue to have work-life balance and, uh, you know, have good quality of life. You have a a fairly young child still, so I'd imagine there's a bit of, uh, of time you got to put in there. But, um, I'd be curious to hear how that's evolved for you over the years and what, what you do specifically to, to help with that.

Well, thank you for asking this. It's close to my heart. It's something I've been fighting to figure out for a few years. I took a sabbatical for one summer before my daughter started kindergarten. I started the consulting job.

I've really been trying to figure out life because the paradox inside me is I love all this stuff. I want a big full life and just like sometimes my arms don't fit around it and it just makes me, it's just hard. A few things I do now is I really think a lot about where I get energy from. So some of these jobs, it's the same amount of hours that I work, but my energy level is completely different. So I need to be at the right place with the right team because doing the right kind of solving the right kinds of problems.

I like to solve big hard problems, but I need to get energy from them. So I need to, like, if I'm working at night, it should be because, oh, I can't wait to get this done. I'm so excited about this versus I've got to slog at night to get this done. And, and sometimes when you're depleted of energy, you think, oh, well, just jobs are hard and I just have to push through. But I would say actually sometimes a change can really Like a different job, a different environment can feel very different.

And I'm also learning what kinds of work give me energy and what kinds of work like sort of cost me a lot. And I think about setting up my team and my team structure to be right so that we all sort of are firing on all cylinders and we have the right support. And that doesn't mean I avoid doing hard things. It just— I'm like really thinking about that. And the other thing that I learned is that If I can periodically, I try to do it once a week, go for a 2-hour hike.

It's like an hour up, an hour down. I, I get so much focus that a part of my brain will figure out what's most important to do next. And it's like, I'll actually open up my phone and write a note. I'm like, oh, oh, I got it. I know exactly what I need to do next.

And it keeps me really efficient in making smart decisions every week on like what's most important next and sort of Clearing my brain. So I've been fighting really hard for that. And that came up with consulting where I decided in my company we hike on Fridays. But then I realized this is serving me, it's serving my health, it's actually making me more efficient at my job. Like it's serving everybody if I do this.

So for me, that was another thing. So I will say I, I haven't solved work-life balance. And I've also just accepted that this is a season of life that's just like really busy. And I just It's— I can't do all the things I want, but I also really, um, I feel really content now. I'm like, this is the big full life that I wanted, and I have the energy, and it's like, I don't know, it's good enough.

That's how I feel about it right now. That's great. Um, I think, uh, you know, we are lucky in that we are a little farther along in our careers. We have lots of experience. We probably have more options for for potential job opportunities than, than many people, especially earlier in their career.

How do you have advice for someone who it may be more costly for them to, to change jobs if they're in some, someplace that's not giving them the energy that they want? They don't necessarily have the luxury to, to move on. Some skills or tips to help increase their, their satisfaction or their work-life balance without having to make a giant leap like that? Yeah. One thing that I sometimes do and I encourage people to do is— so there is a reason why the company is paying you.

So you've got to get that done. But you also should have your list of what you want to get out of this job and the company and fight for that. And so sometimes I think about what the resume bullets would look like or what unique angle this company offers to me if I'm working for a very large company. Then I have access to a lot of data and information and resources. If I'm working for a small company, maybe have the ability to innovate or do something really interesting.

And generally speaking, I find it well received that you would sort of reach out, make sure you are doing cool things, because generally the company is going to benefit from that as well. But sometimes if I'm in a hard job that's depleting my energy, but I know I just need to stick around for a while, either I don't have the freedom to leave or it's— I would be hurting the company and it's like not aligned to my morals to leave just yet. I start to think about what, what is going to get me excited. And sometimes I think about it just in like 3-month chunks, like what's the next 3 months, and then I'll write a list. But then when it gets hard, I think, well, I'm getting something out of this.

So that's one sort of mental trick that I do. Another thing I try to do is just diversify, like get out of the office and have coffee with different people. So Denver is a great place to do that. A lot of friendly people and just, what are you up to? What's inspiring for you?

And share notes. And I've met, I don't know, I've met like a dozen people around Denver that I've never worked with that will have coffee with me periodically, just share notes. And that can help give me a lot of energy too. That's awesome. Um, one other thing for me is to, uh, actually take vacation.

Oh yeah, good call. I mean, people, uh, people often now have, quote, unlimited vacation at, at companies and things like that. But, you know, studies have shown that if you have those, you often take less because it's not a commodity of things that you need to get rid of. It's, it's just kind of there. And I think, uh, people, especially in security, are often scared to take vacation because there's so much going on they feel like they can't get away, right?

And so I think like allowing yourself to, to, to get away and take that, those vacations, that time off, I think is super important too.

No matter who you are, no matter how important you are, things will continue to run without you. I, I completely agree. And I would encourage anybody listening that's a manager or above, you got to take your vacations for your team to feel like they can take vacations. So like, I remember I have worked for companies where I thought, I guess we don't take vacations here. It's not seen as appropriate for executives to leave because I never see any other executive like taking time off.

Uh, I— and that unlimited PTO is such an interesting thing. I used to work at IBM and I worked there with you and long enough that I, I had 5 weeks of vacation and I would actually make sure I took every single day. And ever since I've left, I've never once took 5 weeks of vacation since, even though I have, in theory, unlimited PTO. I've never felt like I have the guts to do it because I, quite frankly, I don't see any other executive doing it. But like, yeah, so I, I, the unlimited PTO is a little bit of a scam as far as my experience.

I, I forget to take it. I don't, I never feel like I could really take 5 weeks. That doesn't feel possible. Right. Yeah.

Yeah. All right. Well, Mary, I think we're, we're getting close to time here. Any other topics you wanted to, to cover before we adjourn? No, it's been really fun.

I would— yeah, no, this has been great. It's nice to check in and say hi to the community virtually. I'd just say if any of you out there are in product land and want to connect and use me as your coffee excursion, please do reach out. I'm in Denver and I love getting to meet new people. Awesome.

One last thing for me. The last time that you were on this show, it was the precursor to you doing a bunch of interviews for, for the podcast. You interviewed a bunch of female product leaders. Yes. I'm springing this on you right now.

Um, maybe we should do a redo of some of that and have you, um, uh, do some more, uh, guest interviews for the podcast. That would be amazing. I should reach back out. All those women have gone on to do extraordinary things. It'd be fun to check in with them.

And I have even more contacts now. So yeah, that I did have. Yeah, my desire to get the female voice and the product voice louder. I loved that you entertained me and allowed me to do that. And incidentally, It was so fun for me and a lot of benefit came out of it.

So there was the 30 minutes you heard in the podcast, but then there was like the 2 hours that we got to bond and hang out outside of the podcast. So it was a big benefit to me. Well, yeah. So you're always welcome to come back and do more interviews. We would love to have that, whether it's a redo of those or other folks to hear from.

So maybe I'll bug you about that as we, we go forward. Awesome. Uh, well, Mary, it's been great talking to you. Uh, thanks for being here again. Uh, this has been Colorado Equals Security, and we'll talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes