All episodes

Joseph Dhanapal, CEO at SecureAuth

Apple Podcasts Spotify SoundCloud

Joseph Dhanapal, CEO at SecureAuth is our feature interview this week. News from Casa Bonita, SpaceX, Blackpoint Cyber, Lares, Optiv, NCC and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12475 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 266. This is for September 9th.

Alex, we're in— we're just about the fall now, right? Um, there's some leaves changing on trees in my yard. Uh, it's cool at night. Football is starting. If football is starting, Robb, then it must be fall.

Is today the first— is there like football on right now? As we're talking, there is football on right now. Apparently have not paid any attention. I don't have a fantasy team. I'm doing very bad at this.

Or if you do, your fantasy team is probably going to be doing poorly. You know, uh, based on my previous history of drafting, this actually might be the best way for me to have a team. Um, I have a fantasy team and, uh, I paid attention and my team is still going to do poorly. So there you go. Well, that's exactly my point.

Yeah. All right. Let's do a little bit of housekeeping. Uh, as a reminder, we have a Slack channel, but with, uh, over 2,600 of our favorite, uh, Colorado security people in it. If you want to join the Slack channel, you can go out to colorado-security.com, click the Slack button.

Um, while you're there, you can sign up for our mailing list. Uh, you can get all the news into your inbox each week and occasionally other random stuff like the picnic that we just did just a couple weeks ago. Yeah. Also, we would love for you to subscribe and rate us on whichever service you use to listen to the podcast. You know, Robb, I saw something the other day that the top 3 podcast services are Apple Podcasts, Spotify, and YouTube.

YouTube. YouTube is in the top 3 now. And so we are on YouTube so people can watch the podcast on YouTube. If you are listening to us on YouTube, please tell us. Yeah, I'd be interested to hear.

I'd be interested in knowing if anyone is doing that because we're not showing our faces. While you're listening on YouTube, it would be great if you told a friend about Colorado Equal Security. Let them know of all of the good things that are going on. And if you would like to support us financially, we do have a Patreon campaign. It helps pay for things like the picnic that we just had, hosting fees, other things like that.

Yeah, and hosting fees are going up. I don't know if you see all that recently. Yeah, yeah, it's, it's not cheap. Power, data centers. Uh, are we done with this?

Should we move on? I think we are. I think talk about the news. Yeah, go to colorado-security.com, check everything out. Yeah, all those sort of things we just talked about.

Uh, let's talk about some news. You know, I, I thought we were done. We got one more story here about Casa Bonita. Um, you know, I, I got to go to Casa Bonita for the first time a little while ago, and, uh, I'd say that the food was better than it used to be, but still not great. And the atmosphere was amazing.

Really well done with the, with the atmosphere. I would give the food a slightly higher rating than that. I, I think it is good. I also wouldn't go there specifically for the food. It's very expensive for, it is, it's expensive for what you get.

Yes. It is not the, the most value, but you're going to, you know, Disneyland or, you know, whatever. It's a, you're Disneyland. I like it. It's, it's the same kind of thing as an amusement park, right?

Or, or, you know, Something like that. It's gonna be more expensive, but I think the food is decent. And yes, definitely the atmosphere is great. But that's not what we're talking about. That's not what we're talking about.

There is an upcoming documentary that's going to be released on the the remodeling of Casa Bonita. Yeah, some documentarians were following around Matt Stone and Trey Parker, who are the the co-founders of South Park and now the owners of Casa Bonita. And as a part of the documentary they were making about them, they were like, "Oh, we'll do an episode or two around or a little bit of the the documentary around this." whole Casa Bonita thing. And then they realized, oh my gosh, there's so much content here. They decided to create a documentary just about that.

So it's called Casa Bonita, Mi Amor, and it's going to be streaming here— actually, it's today, um, September 6th, 7th, 8th, and 12th at the Alamo Drafthouse Sloan's Lake. You can go see this documentary. Yeah, and it sounds like it'll be, um, in a few other theaters soon, not a gigantic wide release, but some places, and then also at some point in the future, it'll be available for streaming on Paramount Plus. There's a quote in the article. Oh man, I'm looking for the one.

It was Matt Stone, I think, said that basically throughout this process, as they figured out it was going to cost about $40 million, I think he says they got kicked in the nuts a little bit. Isn't that what he said? Yeah, I think he said that. They also said several times, like, any any person that didn't have a great love for Casa Bonita would have just abandoned this and walked away, taken their losses at, you know, a couple million dollars or whatever it was and walked away. But, you know, they have a deep-seated love for Casa Bonita.

And because of that, they were willing to sink all of this money into it. Yeah, I think, you know, we talked about it for years, we've been talking about this and the bids that came from the Save Casa Bonita kind of nonprofit group versus these guys winning it. I think we really got lucky that they won because, you know, the people who were just barely able to raise the money to, to make a bid for a few million, right, they weren't going to have $40 million additional to throw into remodeling. No. And not part of this story, but also Casa Bonita news.

It was recently announced that they are getting rid of the email-based lottery system to get a reservation. So middle of September, you'll be able to just go online and make a reservation for Casa Bonita. I imagine that those, at least in the beginning, will fill up quickly. So you may not be able to do it immediately. But, but check that out.

Go get after it. All right. Moving over to our next story. There are— there's a new space program coming, or space— what do we call it? A journey?

Mission? A mission. Thank you. The mission is the word I'm looking for from SpaceX. And 2 of the 4 astronauts have a Colorado connection.

Yes. Scott Poteet and Sarah Gillis are among the 4 astronauts that are hoping to make the first commercial spacewalk. And they are— they have Colorado connections. Yeah. So this is interesting.

I learned a lot from this article. I'm not a huge space fan. Like, it's interesting. And, you know, I'll, I'll be interested to see the stories. But I didn't know about this, this billionaire.

Oh man, Jared Isaacman, who started a couple of different tech companies and basically became a billionaire and said, you know what I want to do? I want to fund these space flights. And by the way, I'm going to be a part of it, right? So he is one of the 4 astronauts who's going to be a part of this. And they're, you know, it is commercial, like you said, that means there are no military government employees on this thing.

It's just commercial aviators, and they're going to go out there. And one of the things I thought was really interesting is the definition of a spacewalk is not, you know, you're necessarily outside. It's that you're in the vacuum of space. So for the first time ever, all 4 crew people on this thing are going to be officially in the spacewalk because this thing doesn't actually have an airlock. Yeah.

When they, when they go to get out, they just decompress, decompress, depressurize the entire vehicle. So everyone who's still inside has to be suited up and they're in the vacuum of space as well, rather, even though they're not walking around. I thought maybe that was the most interesting part of the, the whole article. You know, not something that I would've ever thought of. Like instead of, hey, let's, you know, we need an airlock, right?

If we want to go outside, instead it was like, well, let's not have an airlock. Let's just depressurize the whole vehicle. Okay. I imagine that You know, the, the cost of sending things to space and the efficient— the need for, you know, keeping your weight as low as possible drives some really interesting conversations around potential ways to become more efficient and really think outside the box. Yeah.

This story was published back in August. And it was noted in the story that this mission was going to happen at the end of August. But I actually, I checked today. And it still hasn't happened. It actually is scheduled for potentially this next week upcoming.

So good stuff. If you want to see the launch and see more about it, you may be able to see it in real time. It's not too late. All right, moving on to our next story.

It's that time of year when laws change the way that things work in Colorado. Once the legislative session is done, and all of the laws that have been passed and signed, it's usually about 90 days from that time until those laws become into effect. And so that was in August, and there are now more than 200 new laws that are taking effect. Yeah. So it's— I guess what, what happens is there's a default day.

If you don't— if the law itself doesn't say the day that it goes into effect, it will default to going into effect that 90 days before, which was somewhere in August. It just happened. Yeah. I think it was, uh, Second week in August, maybe, or something like that. 200 new laws.

I, I took out a few that were my favorite laws that are coming out here. All right. Let's hear them. Maybe favorite's not the right word, but most interesting. There's the new motorcycle lane filtering law.

So I'm from California. And in California, they allow lane splitting where like a motorcycle is allowed to ride right next to you, whether that's on the freeway at 100 miles an hour, I guess not 100, but at 55 miles an hour or at a stoplight, you're allowed to split lanes. Um, in Colorado, they've, they brought in a, a variation of that, which is motorcycles are allowed to pass cars at intersections or in traffic when they're stopped up to 15 miles an hour. So they're not allowed to, to do this, you know, at speed on a road, but when you're stopped, they're allowed to get to the front of the line. That's a new law.

Yeah. Uh, that's a cool one. Um, and it's funny, uh, before I read this story, I was actually at a stoplight the other day. And a motorcycle did that, pulled, you know, they were probably 4 or 5 cars back and went between people and went up in front of the front car. I'm like, oh, you frickin— you're not supposed to do that.

You can still hate him. It's okay. And then, then I read this article. I'm like, oh, okay, I guess I don't hate that person now. One of the other new laws, there's some event ticketing reform laws that went into effect.

Part of one of them is that if concerts are canceled, the ticket companies are required to give you a refund. The— in prior to this, they could have given you the refund, but they weren't required to. So maybe the concert gets rescheduled for sometime in the future and rescheduled and rescheduled, and you've got this ticket that's basically held up there. And maybe you can't go to the new— maybe you can't go to it or whatever. And then you're kind of screwed.

I was actually kind of in that situation with one of my kids. I bought a concert ticket for them that it was a fairly expensive concert ticket. And then the concert got rescheduled for like 6 months in the future and then rescheduled again for 6 months in the future. And then, you know, we, we had this ticket hanging out there for, for probably a year before it was finally, uh, concert was finally canceled and they did give us a refund, but getting that refund right away would've been much nicer. Yeah.

So there's also, um, as a part of that same law, transparency around fees for concerts. They, they, they're not allowed to, they ha— they have to show all the fees upfront in the ticket price. They're not allowed to change the price while you're, while you're looking at it. All kinds of interesting stuff there. Another one that I had written down was that the new laws around holding your phone while you drive.

So previously there was no texting while driving, but I assume other things like clicking something on a map on your phone or starting songs on your phone were acceptable. And now this new law is much more clear. If you're driving, you can't be holding your phone and using it. Yeah, I should probably read the details on that, Robb. I'm wondering if, you know, I have like a little holster that holds my phone in front of me.

I'm not holding it, but I might touch it. I don't know. I mean, how is that any different than having a screen on your car that you would use to be pushing stuff? Or, or no screen, just a stereo where you hit volume buttons and stuff. I don't know.

Be curious to know. Anyway, my last one that I had noted down was the reintroduction of Wolverines. Made this. You know, we had— we brought in wolves. Maybe somebody got confused.

They thought we need to bring in wolverines too. Obviously I'm kidding, but they are reintroducing wolverines in Colorado. Does that have anything to do with the recent Deadpool and Wolverine movie? No, I assume so. Yes, I assume so.

Yeah, I mean, you get good PR out of that, right? That you do. You definitely do. All right, moving on. We got a new cybersecurity company who has moved their headquarters into town.

Black Point Security, which is a, uh, an MDR. Um, they do MDR services specifically for MSPs. So I know them because Pax8 is a partner of theirs. Um, so they'll work with, uh, MSPs who, you know, maybe they serve like little, little companies providing outsourced IT for them. They'll partner with Black Point to be the security arm, the monitoring arm, and they do a really good job.

So it's, it's kind of cool to see yet another MDR in town. I feel like We must be the, the most MDR-heavy place, you know, in the, in the country. Red Canary and Optiv has an MDR and, and was, what's the, the one that broke off from GuidePoint? Yeah. Deep, DeepWatch.

DeepWatch. DeepWatch. DeepWatch. Yeah. Anyway, we got, we got a number of MDRs.

Total's another one. So really cool stuff. Yeah. And Black Point Cyber, their headquarters is now downtown at 1099 18th Street, though it sounds like they don't really have any employees here yet. No one relocated as part of the move, but it does sound like their CEO was already here.

So you've got the CEO in town, but they're going to be hiring people local. Going to be good stuff. All right. Moving on to our next story.

You know, I think everybody is interested in generative AI and large language models, Robb. And this is an article from Laris talking about guidelines for integrating LLMs into systems securely and safely. I think We've probably talked about articles like this in the past, and there are others out there. I think it does a good job giving you a nice framework for thinking about how do I get my LLM brought into my technology, into my, into my company. Yeah, there's lots of different things that you should think about.

This is all very surface level, which is fine. Areas you should think about, not specifically what you should do in those areas, but yeah, I think to your point, Lots of different areas to think about when trying to bring an LLM into your organization. Just a few categories here. Data privacy and protection, bias and fairness mitigation, robustness against adversarial attacks, explainability and transparency. This is one that's interesting to me.

It's not that you necessarily need explainability, it's that you should think through explainability. Anyway, there's quite a few other sections here. I think that having this as a checklist to talk about as you go through things with your engineering team, you know, whatever teams are, you know, if you have an AI team, whatever team it is that's bringing in this type of technology, this is going to make good conversations. I agree. Good article.

All right. Next, we have an Optiv blog talking about preparing for a quantum world, about migrating from current encryption to quantum-resistant encryption. In the interim, like maybe where you're in a hybrid state. Yeah. So if you had talked to us 5 years ago and said we were going to be talking about how to implement your new AI technologies and how to implement your quantum computing cryptography algorithms, I think we would have said, yeah, sure.

Yeah, whatever. Tell me another one. We'll also have been taken over by Skynet, huh? Right. Yeah.

Oh, geez. Don't say that. Um, but the, uh, to be fair, the quantum one is still more future-looking, right? We still haven't— we still don't have quantum computing that, that works to— that we have to have these solutions against. But it was a really interesting point, like, hey, for some amount of time you're going to have non-quantum computers and quantum computers, and they're going to need to be able to communicate with each other.

How are you going to do that? How are you going to— how are you going to allow the quantum computers to have quantum-level encryption with these other computers, you know, that don't. Right. So I, I'd never thought about this before. This is a super interesting topic.

And the answer is it depends, right? That's the answer to the how do you do it? It depends. There's, there's 4 or 5 different options. Yeah.

I hadn't really thought about it either. While I know that the, the risk of quantum computers breaking current encryption is something that's on the horizon, it's not something that has risen super high on my risk list. But this was an interesting read, thinking about the potential ways that you could change your PKI to be sort of a hybrid system to accommodate both, or maybe make the choice to only accommodate one or the other depending on, you know, what your use cases are. Mostly when I've thought about quantum cryptography, I've thought about quantum-resistant cryptography, which doesn't require quantum computing to use. Right.

Right. And this is This is talking about the fact that, well, okay, that's fine. In the future, you're going to want to use actual, you know, quantum cryptography that only a quantum computer can do. And so this migration path is gonna be interesting. And hey, you're gonna need, and this is all about asymmetric encryption, you're gonna need to be able to support, you know, old RSA asymmetric encryption while you're also supporting the new quantum options.

I don't know enough about those yet. I need to go take a 101 version of tell me all about the quantum cryptography options. But this gives you a nice summary of how we can implement them once we understand them. For sure. Check it out.

All right. What do we got? What do we got next here? Next, we have an article from the NCC talking about some of the Cyber Patriot camps that they did this summer, which sound awesome. Yeah, this is cool.

I think every summer we've talked about it in advance. Hey, make sure you get your kids signed up. They do a good job getting— they break it into 2 groups, right? There's an intro level of Cyber Patriot camps and then a more advanced one. They go through like, hey, basics of operating system security, basics of network security.

And then for the more advanced ones, they'll get into much more advanced techniques. And then they'll actually do like a red team or capture the flag type exercise where some folks are supposed to defend and some are supposed to attack and give a bunch of students, mostly middle school and high school students, a chance to experience what a security profession looks like. Yeah, it's pretty cool. I'd say if you have kids of that age, you know, obviously it's too late for this summer, but think about that and get prepared for next summer. Yeah, and maybe volunteer at your local school for Cyber Patriots, and maybe you could help be a part of that solution.

Our final story is a second from NCC. I don't think we've ever had 2 NCC stories before, but this was interesting because it's our friend Mark Weatherford. Mark was the CISO for the state of Colorado a long time ago, and he's a Colorado resident. He wrote this blog post Burn the ships. Gen AI is here and not going away.

Yeah, it's an interesting article. And he, you know, he's talking a little bit about kind of both sides of the coin of generative AI, you know, some reasons people are trying to resist it. In this case, talking specifically about creative applications, how, you know, it's, you know, potentially ruining sort of the human creative process, but then also On the other side, how it can make the human creative process so much faster and easier and more robust. I think the punchline is, you know, we can have— as technologists, we can have our judgments about whether we like it, whether we don't like it. His perspective, though, is it doesn't matter whether you like it.

It's coming, right? And you're not going to stop it. You better figure out how to deal with it and secure it. It's not only coming, it's here. Right?

Right. It's here. It's going to be everywhere. Right. Very soon.

And the burn the ships analogy that he used was when Cortés explored and came to the New World. Not surprisingly, they landed in this strange place and his crew was, you know, hesitant to stay. They wanted to kind of turn around and go back home. And he was like, nope, we're here, we're staying. So they burned all their ships.

And once they did that, he didn't have much choice. He had to stay. Um, the, he, he gives the example in here, you know, around companies that choose to or choose not to embrace new technologies. And he specifically, you know, throws out the Kodak example, which, you know, they, they were the creators of digital, uh, digital images, digital pictures, but they refused to embrace it because they made a ton of money from film sales and this was going to kill their film sales. Right.

Well, Kodak, you know, went bankrupt later. They're not a player in the, in the, uh, in the camera market anymore. And this is just a good example that, you know, it doesn't matter whether you understand it, whether you like it, whether you don't. You've gotta, you've gotta adapt to the new technologies. Yep, for sure.

All right, that was the news. Uh, let's move over to our events calendar. Uh, of course, on the website colorado-security.com, we have a calendar of events. You can check these out anytime, see what's going on. And we've got a list here of the stuff that's coming up in the next month or so.

You know, this month we got some good stuff. On the 7th of September, ISSA Colorado Springs is doing the Security+ review. So that's, that's in the past, but the reason I wanted to mention it was this is a series that they're doing, a series of Security+ trainings. If you're interested in, uh, getting involved, you know, you may— maybe you missed the first one, you can still join in. ISSA Colorado Springs is also doing their 14th annual Peak Cyber Symposium on September 10th through the 12th.

On the 12th, the Let's Talk Software Security group is doing, uh, one of their meetings. They're going to talk about, are software security best practices really the best? Uh, on the 18th, Denver OWASP is doing their September meeting. And also starting on the 18th, uh, Mandiant's big conference that they do every, every year called M-WISE, um, I guess now Google, Google Mandiant. Uh, is on the 18th at the night and the 19th at the convention center.

Uh, also on the 19th, ISACA Denver has a big meeting. This is a serious meeting. It's a full-day event with 7 CPEs. Uh, if you're an ISACA member or you're just interested in getting some good education, take a look at that. I think that would be a great event.

And our final one for September, the ISC2 Pikes Peak chapter is doing their September meeting on September 25th. All right, let's jump over to jobs. Um, we have, uh, we have 10 jobs to chat through here. First, a job with me at Pax8. I'm looking to hire a GRC analyst.

Uh, if you're looking to, to help us with compliance, third-party risk, incident response, we'd love to chat with you at Pax8. Vertafore is looking for a VP of cybersecurity. That's, uh, their head of security there. Head of security there. Yep.

Um, Denver Water is hiring an IT security analyst. Google Mandiant is looking for an Associate Red Team Security Consultant. Western Union is hiring a Senior Information Security Analyst. Micron is looking for a Product Security Engineer. Bank of America is hiring an Identity and Access Management Defense Senior Specialist.

I think you win the longest one this week, Robb, with that. CommonSpirit Health is looking for an IT Cybersecurity Senior Engineer. RTD is hiring a Senior Cybersecurity engineer focused on network trust. And Tallgrass Energy is looking for an analyst for CyberGRC. That is it for the news, Alex, but we do have an interview this week— this month.

I got to sit down with an old friend of mine, Joseph Dhanapal. Joseph and I worked together at Ping, and just, just a few months ago, he took over as the CEO for SecureAuth, which is one of the, the well-known identity companies have been around for about 20 years. He's, uh, he's helping them rethink their product, uh, and go-to-market strategies, and I'm excited to get to share that interview with you and the rest of the community. Awesome, I look forward to hearing it. All right, well everyone have a great month and we'll see you in October.

Thanks, Robb.

This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado Equals Security. Colorado Security Professionals by Colorado Security Professionals.

Welcome to Colorado Equals Security. This is Robb this week sitting down with my old friend Joseph Dhanapal. Joseph, the folks have, you know, they've already heard a little bit that you are the relatively recent CEO for SecureAuth, but in my heart, you'll always be the chief of staff to the CEO over at Ping. Obviously followed by other roles. And, you know, you and I had a chance to work together for several years, really some of the, I think, the best years of Ping, if I get to, you know, kind of selfishly say so.

But, you know, I'm looking forward to getting to introduce you to the rest of the community here today. Thanks for joining the podcast. Great, Robb. It's always great to chat with you. And thank you for inviting me to the podcast and all the others.

Hello. And We'll see where we get to meet sometime in the future. I'm going to take full credit for those years being the best years for you. It's all about me. Because what you did is you came in and you instilled accountability at the executive level that helped drive the performance that sent us public and, you know, made Ping a household name.

Right. And we can't take full credit for it, but I will accept all of those, all the accolades. Well, as we talked about as we were preparing, We— I love to start not talking about work, but talking about, talking about some personal stuff. And, and you, your life has, has recently sent you on the road quite a bit, especially out to Southern California. And I know many of our listeners will occasionally make their way to Southern California, maybe to go see Disneyland or see some family or whatever it is.

And it sounds to me like you have some tips for me. So for the best hikes and beach trips in Southern California. Tell me, why have you been going to the beach so much, and what should our listeners do when they get out there? Yeah, I grew up at a coastal place, but for the past 3 decades, we have lived and enjoyed and experienced Denver. We love it.

It's— it is our permanent home. With this job, having been here and working out of Irvine, we come to experience the Irvine beaches around here in Southern California. So the beach walk itself, my favorite is San Clemente. It is flat and we can go end to end. If you did the full loop, it's 5 miles and we walk bare feet on the coast and that's a great experience.

And the second place I would recommend is the Crystal Cove hiking area. It's across the beach on the other side of the Coast Highway. And if you did a clockwise loop there, going up, you're going to lose your breath because you're climbing up on these hills and mountains here. But coming down, it takes your breath away in a different sense. You get to see the vastness of the ocean and enjoy this beauty that is so amazing in Ostrich.

Um, you know, it was like the first time when I was in Denver and experienced the mountains with the snow. In some ways, this is, uh, going to be that kind of an experience when you come and see the beauty coming down the mountain. So those are 2, 2 of my favorites, and my wife and I have been there multiple times even in the short duration in Irvine. That's great. You know, I know you've only been there for just over 100 days.

By the time we post this, you know, you'll probably be almost 4 months or so since you started. Um, but I want to go back quite a bit further. You said You grew up on the coast. Where did you grow up initially? Where are you from?

So I'm from India, southern India. If you think of the India V in the bottom, I'm on the east coast side of the V. I grew up in a very small place. It's a place called Kalpakam, only 5,000 people. And that by itself is like a big miracle. Like in India, you hear about these major cities, 10 million, 20 million.

And here is a small town with only 5,000 people, but it was a great growing experience for me. It was a research center in nuclear science and a lot of our folks in the cutting edge of the science and technology. So it was a good upbringing for me. Well, that's, that's so interesting that a 5,000-person town had a significant nuclear science research facility. That's pretty cool.

Like, it's, I guess, you know, like we had the Mayo Clinic built in rural Minnesota here and it, you get these little niche areas that, that's probably most of what the town was built on, huh? So how did you, how did you end up leaving the little village in southern India? So the township or all of my schooling was all in the township itself. I was getting great schooling and I went to do my bachelor's and master's in engineering and joined a company called Tata Consulting Service, TCS. Now they have hundreds of thousands of employees.

At that time when I joined, it was like 10,000 something, and to me it was like big, but now it is nothing compared to their current 350,000 or 400,000 that they have. I was there and one of my early customers was US West. So my first travel out of India was to Denver, coming in as a C/C++ programmer for US West. We came and I worked, uh, here for a couple of small quick trips trying to understand the business and what they were building. And then when I went— left TCS, I got an opportunity to work in New York.

I was living in Princeton area but working for a company in Wall Street. And that was like a 2-hour each-way commute. So it was a long commute, but being a single guy, it didn't matter. I came back to Princeton to sleep and get ready and leave for doing the whole thing again next day. But that was only for less than a year.

Got an opportunity to come back to Denver as an employee of US West, and I jumped on it. Loved the cities, loved the people. It has been our home for close to 3 decades now. So was that the US West opportunity? Was that basically based on what you had done for Tata, the same relationships, kind of an opportunity opened and they pulled you over?

Were you doing— I see you nodding your head. Yeah. Were you doing development work at that point too? You said C++ development at that point, or had you moved on from that? Yeah.

So my initial, again, for many years it was all focused on building software that would connect to the network elements and turn on the features for your phone service. Yeah, one of the earlier innovations— US West was the first to release PCS, same as the cell phone now. It used to be called Personal Communication Systems, but the innovation was to only have one number for both your home phone, wireline phone, and PCS. There was a network element called AIN, Artificial Intelligence Network, This is in the '90s we're talking about, and you would program it to, in a way, to say how to identify where the presence is. So is the person outside the house, then route it to the cell phone.

If you're in the house, it would come to the wireline. So did a lot of those kind of things and then grew up in management of implementing large ERP and those kind of things. So moved from developers into leadership. That's great. Now The building that you and I worked at for Ping was a former US West building.

Is that the one you were in? I know they had a lot of buildings downtown. Yes. When I first came to Denver, this is late '90s, you couldn't throw a stone without hitting a telco building. US West had by itself, like every other block, they had a building.

On top of it, there was MCI, Verizon, Frontier, on and on and on. A lot of those. The primary building where I worked off was a couple of blocks from where we were working together. It's a 930 15th Street. Okay.

But one of the projects, again, as you grew in US West for— I was there between contractor and employee about 15 years or so. One segment of my lifetime in the US West was in our building, the 1001 building, and that was in the 14th floor. I used to take the stairway all the way up to the 14th floor. So when we came, when I came to our previous employer, which was on the first floor and the eighth floor, it didn't seem that bad. It was easier climb.

Yeah, Joseph, you were, you were always the one who, who was setting the standard by taking the steps to taking the stairs. Always, always taking the stairs up. Love it. I was a lazy guy. I couldn't find other times to work out.

I incorporated it in my walk. So, so you, you know, you, you were at, like you said, US West in a Quest or whatever it was when you left for 14, 15 years. What ended up motivating you to make a change and move on from there? So my focus always, whether it was enterprise IT or even on the software vendor side, has been to increase the value that I offer to the organization and my customers. At every role I have had, there are always somebody who's getting value out of my work.

And enterprise IT, it is mostly internal teams. And when you come into the vendor side, it is both internal teams and external customers who procure. So as I was in the developer role, I was offering a value in one particular transaction. Then as I moved into leadership, I was able to multiply that, uh, impact that I had. So where US West had become Quest and then CenturyLink.

So I'd seen 2 major integrations. I got an opportunity to become the business systems owner, a much bigger portfolio in a company called Teletech, which is now called TTEC, T-T-E-C. And so looking at that, or at that point, I said, okay, I can increase my value to the company. So I joined them. As I was working there, I realized that my desire was to become a CEO of a tech company at some point in the future. I didn't know when that is going to come, but I wanted to prepare myself.

So the folks that I got to work with, these are all real kind people. I spoke to the CFO of Teletech, Regina, and I said, hey, would you mentor me so I can learn the business side of it? In all honesty, with the amount of work that she had being the CFO of a publicly traded company with $1.25 billion in revenue, she could have said, Joseph, Just do your job, man. But she was very kind to me. She, um, she brought me in into these decisions, discussions, so I can experience how the business was done.

And that got me to understand the teletech business. Later on, when I approached Andre, it was the same kind of talk track, and I wasn't even an employee at Ping. And Andre was extremely kind to me in meeting, and, uh, then One thing led to another to the Chief of Staff role. So did you meet Andre, you know, as a part of, you know, applying for the role at Ping or was this a networking opportunity? How did you guys get to know each other?

Oh, in our— this is where all this serendipitous meetings translating into value in the future comes into play. So I've always desired, I prayed, I asked God every day like, God, I do want to increase my influence and grow into this CEO role. But I didn't know when I was leaving US West that things were getting into motion because my first person to interview in Teletech was John Canova, who is the current CIO at Ping. So I have told John about my aspirations where I wanted to grow. So after a few years of him being in Ping and I was still at Teletech, he's like, hey, you should meet our founder CEO.

I think you learn from him. So he makes an introduction. I tell Andre that I'd like to just hear a story of how he started the company and grew it to, at that point, about 14 years in. And he being a kind man as he is, he meets with me. So I've spoken to him, asked him various questions.

We met for lunch and dinner, and this was like over a period of like maybe a quarter or maybe even 4 or 5 months. And then he comes and says, hey, I just got acquired by Vista and I'm looking for my first chief of staff. Are you interested? And again, that was another kind gesture from him. Vista's model for chief of staff would not have been somebody coming with my profile from an IT background, but just allowing me to even apply for it.

And after going through multiple rounds of interview, even being chosen for it, that was a big blessing and a turning point for me. Yeah, that's neat. And like I said, you know, you coming in, helping instill accountability and structure to that executive team was super valuable. Was the— now you got me slightly curious, would the more typical profile for Chief of Staff be on the finance side or is that— That's right. Yeah, typically most of my other counterparts within the Vista ecosystem were mostly coming from the CFO organization.

Sure. Makes sense. Okay. Well, so yeah, let's fast forward over to, you know, you joined Ping, you got to ride the crazy wave as we, you know, got like you mentioned acquired by private equity and that you came in with that. We also got a new CFO during that process and then what was it about 3 years and a few months later, you know, we went public.

So it was a a fun run, you know, maybe tell some of your favorite stories from that or, you know, what did you learn coming into a company that had to quickly mature and get ready to go public? Yeah. So when I joined, again, some of these people I was familiar with, people that I worked in the past were already in Ping. Raj and I also worked in the previous company. So we had some awareness of each other.

Raj was the CFO, Raj Dhani, the CFO for Ping. Raj Dhani, yes, Raj Dhani, the CFO at Ping. We had been coworkers in a previous place. So coming into Ping itself, learning this new role, Chief of Staff, it was an introduction of that role. I'm not taking somebody who was already operating in Chief of Staff and me coming.

So I have to define what is going to be my value prop and how do I help with whatever I am accountable for and helping others too. It wasn't really a top-type role, but coming alongside and making sure that we are all progressing at the right pace to get to the outcomes that we were expecting. That learning of something that was brand new from my past 2 decades of work was very exciting. Along with that, Vista had this program called HPLP, Uh, which was almost a year-long program, um, and significant investment. You have to do book reports, you're doing a lot of case studies, you're learning their secret sauce, right?

How do you identify a target to acquire? What is the investment thesis? What is the value creation thesis? How do you execute on it? And how do you exit?

Uh, I had— I was there at Ping for a few months when I heard about it, and I I asked Andre if I could put my name in the hat to be considered, and again, he graciously agreed. That was another blessing where I got to not only learn how Ping operates but also learn the best practices. At that time, Vista had about 60 companies or so, to be able to put it all together and see all these different models and learning. It was almost like, in my mind, a university experience. I learned from the typical legal officer.

I learned from Vertafore chief of staff. I learned from the Bullhorn recruiting sales leader there. All of these variety of leaders who could sow their wisdom into my life and help me through that journey. That translated into me being part of the right of being the first Vista Portico to go IPO, being close there to see it. And yes, as a company, it was 3 years and a few months.

As an individual standing in New York Stock Exchange, I recognized it was my 3rd year employment anniversary. I don't think I knew that. That was September 19th, right? Yeah, September 19th, 2019. So 9/19/2016 I joined, and 9/19/2019 we are in NYSE.

I didn't even think about it until the evening when we were having those gatherings. Yeah, oh my goodness, this is the same my anniversary day. So that was such a great experience to be part of that. And then coming through and figuring all of those, like even going through those process of for IPO how each sentence matters and each preposition matters. That, that was like sometimes I could have seen outside in, I would have said, why are we wasting time on some brochure that no one is going to read?

But from a legal perspective, it was such a big deal. And all the others that I got to work with, uh, Ryan Gall or Russin, uh, Lauren Romer, all of those, that was all exciting time. Yeah, the number of hours that went into, you know, not building the business, but putting together the paperwork to go public, it's staggering, right? It's a big price. It's a lot.

So if I remember correctly though, wasn't it about this time that you were moving out of the Chief of Staff role about when we went IPO that you moved out of that role and into a different role? Yeah. So I view my tours of duty with every company. Again, this increasing throughput of value to the company itself in terms of 3-year cycles. Year 1, learn the job.

Year 2, scale and grow the job. Year 3, figure out who else can you pass it on, who could do the job better, and you can go and take on the next adventure. So coming into the 3rd year, even as we are trending towards the IPO, I was talking to Andre, uh, the CEO. I was talking to a few other leaders, to Chris the COO and, um, Aaron Lapointe and so on. Like, hey, what else can I be focused on?

One of the areas of advice I got is like, again, the goal being the CEO at some point in the future. Andre was kind enough to say you, you need to look at getting some experience in go-to-market side. Nothing gets done in a software company unless you're able to sell that you're not just building, but you're translating it into value for the customer. And we were just then trying to figure out our plans for a new cloud solution, a single-tenant solution. So I put my hand up and I said, hey, I'd be interested in taking that on.

Or I know it's a very, uh, infancy stage of this new offering. I'll be accountable for it and if things don't work, you can chop me and no harm, no foul. And again, uh, the kindness and goodness of all of these people, uh, giving me a shot. And so, so people could have looked at it and said, you're an IT guy who has done chief of staff, I don't know how you're going to do it and go to market. Uh, Dave Packer, Chris Nagle, and Andre all being, uh, willing to give me a shot, that, that changed the next tour of duty in Ping.

But towards that 2019, early 2020, getting into being the general manager and owner of advanced services came about. Yeah, I mean, you got, you got a sales number hung around your neck and it wasn't just that, right? It was, it was, well, how do I make sure this product is ready to go to market? How do I get the documentation to make it ready to go to market? And, and, you know, you and I worked together a ton on how do I make sure that the security and the compliance and, and, you know, how do I answer all these questions for large enterprises, right?

The biggest enterprise in the world who are gonna be interested in using this thing. And I'm sure you gotta baptize them by fire going through that process. Yeah, most new offering as you come through, you take it on and apply it or present it to the lowest risk people and you're learning with it. You're not throwing it away, a crappy product at anyone. You're, everyone's desire and intention is right.

You want to build a solid product. But the offering itself that we were building, this was for the largest of large who had a high throughput single tenant needed. So the way it turned out, brand new offering, but the ICP, the ideal customer profile that you're targeting, are the biggest enterprises like the stock exchanges of the world, the biggest pharmacy company of the world. And you need to be ready on day one. Of course, it wasn't just me.

There was a big team working on it, or from where, 7 different function areas, about 70 people or so. But getting through it, it was amazing. Our first year when the number was given to me, coming from an operator role, I'm like, it's another number. I know how this works. 20% comes in Q1, 20% in Q2, 20% Q3, and 40% Q4.

Easy peasy, we'll get in there. But boy, was I wrong getting into go-to-market. It's a whole different beast than anything I've done, whether it is enterprise IT or even chief of staff or other areas that I've helped out with the product and engineering side and so on. But it was a great learning experience, and as difficult as it was, uh, some of the times I had to go and, uh, find a shoulder where I can, uh, just cry and say, what did I do? But all of you guys supported me well, including you, Robb.

Like me coming to your office and I'm like brainstorming from with a whiteboard. I'm like, how do I get some traction? There were not too many promoters for the offer, uh, let alone the customers. But even before getting to the customers, like people who believe or even give valuable suggestions of areas that I need to shore up. To get this offering, the outcome-oriented value-added offering to outsiders.

So finding those friendlies who could guide and coach me through helped me during the dry wilderness season. So when we ended that year, we were 30% ahead of the plan. Wow, that's— it's such a cool thing to get to do. And I think, you know, we have a lot of listeners, maybe most of our listeners who are technologists who have, you know, they've never made a, they've never had a sales number.

You know, your first thought when you hear someone maybe thinking, oh, you know, I'm getting a little tired of technology, maybe going to the go-to-market side sounds good. What do you think? Is that something you'd encourage or discourage? What's your first thought? I will always encourage because I think like sales is the one place where the scoreboard is so evident.

When I was a developer, I could say that, hey, I worked 18 hours, I built blah, blah, blah, this compiles, this can run. And I felt good about it. I'm like, hey, this is doing what I wanted. Sales is a place which all are, if you distill everything that you're doing, it translates to, am I solving some real problem that people are willing to put money on it and give it? Or I don't know how much, uh, of success you would experience in the short term, but opens up opportunities even beyond making a sales number.

For one, it tells you like what people value, what they don't value. It might be the coolest thing as a developer for me to do something, but people might look at it and say, I don't care much about it. And 2, you can see tangibly how this impacting your customers' lives in terms of like identity-based security, giving a great experience while also protecting the users who are using your solution. That's a great experience. Like, it's so much more fulfilling.

So if you are considering it, I don't want you to go in with assuming everything is smooth and easy, but I am strongly encouraging you to take the leap Because you'll learn a lot and it'll change the way, even if you continue to become an engineer and just go back to building stuff, it'll change the way you're building stuff. It is such a great experience. One of our shared role models, Andre, always says run toward fear. And I think, you know, this is, it's scary as a technologist to go try it. I think it's good advice.

And I also just, you know, give you a shout out to say you didn't do this in your 20s. You did this in your 40s when you're, you know, you're a ways into your career trying to make this kind of a change. I think it's, it's courageous and it's, it's a cool thing to get to do. So, you know, kudos to you for doing that. Thank you.

So you did it about 5 years, right? You were the GM over there of Ping One Advanced Services. Close to 4 years. About 4 years. Okay.

Yep. Yep. So, you know, you did that role for 4 years and then, and then what happened? So you're not doing it anymore. Tell me the next story.

Yes, sir. Going through it again, going back to that whole thesis of 3-year tour of duty. So year 1, again, I was learning the job, trying to figure out. Quarter 1, going in with googly eyes, looking at it, it's just execution. Now what's the big deal?

Quarter 2, having learned that how difficult go-to-market is. And then actually end of the first quarter, we went into shutdown with March 13th, 2020. So everybody is out. My first people to influence was internal employees to say where this offering can add most value to the customer. But the end of the year, we came 30% more than the original plan was.

So we overperformed. Year 2, my number was 3x the plan for year 1, and I was freaking out. I was like, what, what number indicates that we're going to be able to make this 3x? Now I've been already trained on how the— how difficult sales is. So, uh, but the leaders again were not throwing the numbers at me and saying it's your problem, go figure it out, but rather like, hey, we do believe in you and the offering and, uh, well the team that is delivering, we can make this.

So we had to change strategy, think about like, what is a different way of tackling it? We worked on a promo that helped us in accomplishing 15% more than the target in year 2. I also had a change in my leader.

So that new leadership coming in, again, they were— Jason Wolf was also a big supporter of me and helping me through these various steps. Year 3 coming in and we doubled the ARR for the offering. So that all worked out well. In year 3, I'm talking to Jason Wolfe and saying, hey, what's some of the areas to go and grow? And he was giving me different ideas and concepts and so on.

So year 4, that's what we were primarily working on. Like, how do we redefine my role? And then this major acquisition and merger happens between Ping and Fortrock. So we're trying to figure out like, hey, what's this new world going to be? There are 2 of every role.

What do you do? And again, Peter Barker was very kind in getting me into his organization and trying to figure out like, hey, how can you solve this problem and that problem? We were trying to work that out. But I also got to the recognition and acknowledge the awareness that I want to go in moving towards this dream of becoming a CEO. But before I hang my hat and here I was, just turned 50, I was looking at it and saying, oh, I got to this big milestone age.

What do I do? And as I was seeking counsel and asking people, there were various advice being provided. Again, all these people, both internal in Ping and outside Ping too. Like these, the network of people who are my well-wishers, that just blows my mind away. And I've spoken to you too, Robb, like by then you had gone out of Bing and I'd come and brainstorm with you like, Robb, how do I think this through?

And you all being kind, you didn't give me this flippant one-word answer like, try hard, man, push harder or do this. But being able to engage with me in the messiness of what I was dealing with to give some tangible suggestion that was critical. So one of the ideas was to explore and see, are you a better fit for a smaller company and where you could go and take on a higher role whereby you increase the impact of the company? So with Ping, the last GM role, I've taken that offering from zero to, I think by the time I was done with that role, about 10% of the standalone Pings our Snowball was attributed to that offering. That's huge.

So I was looking at, uh, which grew from 0 to 10 in, uh, what, about 3 and a half years or so, 4 years. So I was looking at where can I go and increase that impact to a higher percentage. Is it a COO role or some other role? And conversations and serendipitous meetings led me to this, uh, whole role, um, with SecurOps they were considering about, um, what could be the next chapter in Secura. The previous CEO was aware of it, and, uh, I was given the offer.

So I, I was amazed at it, and I was talking to Andre. I was saying like, here are all the components I'm thinking through with regards to the offer and whether to take on this role. And, uh, Andre being such a well-wisher, he's like, hey, this is going to be good for you, Joseph. You're going to learn. You should take it.

And that has been how that helped me in taking the leap. And here I am. Yeah. So I mean, it's so cool to see you, to see you, you know, kind of complete that arc of, of getting to that, that CEO role to help, you know, bring the skills you've learned over the years to this new company. It's new to you, right?

It's not a new company. I assume most of our listeners are at least familiar with the name of SecureAuth, but maybe don't know what you guys do. I'd love it if you'd spend a few minutes and describe, you know, you're in the identity space. I know that, but what element of the identity space and, you know, what problems are you out there solving? Absolutely.

So I'll also make this comment. I'm just in the starting lineup. Yes, I got in the role that I wanted, but my desire is to get to the outcome from that role. So there's a ways to go, but every day I'm learning and I'm excited that I've been allowed to play this role and be part of this team. Uh, Securath, as you said, it is in the identity space, founded in 2005, so coming up close to 2 decades, uh, have remained with some of the areas they were the pioneers in introducing the concept into identity security, or, and they have remained, uh, with a very faithful set of customers, over 300 customers Some big logo customers that many people would be aware of.

Uh, you could see some of those logos on our website too. And there have been a couple of acquisitions here in the past few years. So about 3 years ago, they acquired a company called Accepto, which got them into the passwordless space. Uh, end of last year, they acquired a company called Cloud Entity, which is in cloud SIEM space. And that, that all came about As I come in, I'm looking at it and look at the components of what are all the offering that we have as SecureAuth, the combined entity.

We do do the standard IDP, SSO federation, your cloud directory. We do the MFA. We have over 30 different methods for MFA, or 2-factor, cards, and so on and so forth. We also have 45+ patents assigned to us, so we've been in the forefront of a number of these innovations. I'm looking at it and saying like, well, those technology components are great, and this is where I recognize the engineer in me too.

I'm excited about talking about how the technology works, but we have not been crisp enough in talking about the problems to solutions that we offer. And we just had a new rebranding done beginning of this month, August 1st, or with our tagline being Welcome to Better Identity, where we want to get the conversation from security being, oh, like a roadblock or a speed bump in the companies deciding to do whatever they do, to security being an enabler for the company to grow and accelerate. So when done right, identity security is going to be the one to cut down the cost of your internal operations by your workforce being most productive, and to gain revenue by acquiring external customers who would stay with you longer and buy more stuff from the enterprise. So those are the two ends of the spectrum. It's no different than many of the other vendors in the space.

We look at workforce and SIEM. We look at using all of our capability in a seamless manner that they're interacting with our single platform experience to be able to get the full value of this whole spectrum of security to experience where you need the dial to be. When we look at— are you guys more mature on either the workforce side or the customer identity side? Now based on the acquisition itself, we have gotten a good maturity level on both of those. So the bread and butter for initial offering that SecurAuth came with was on the workforce side primarily, although the customers— there were some enterprises who are using that same platform for the SIAM.

The latest acquisition about a year ago was on the SIAM side, but as you look at it combined, we are able to utilize it for both the workforce and the SIAM use case. So it's a nice acceleration on the SIAM side through the acquisition. Yep, yep. And so what are the types, you know, and I know, you know, you're relatively new and maybe this isn't the right time for the question, but what are the types of buying companies that are especially good fits for SecureAuth? If I've got, you know, we got CISOs listening who may be interested, you know, what's the profile that you think, hey, this is worth giving us a call?

Yeah, so if you think about the capability offering itself, again, our IAM, there are table stakes offerings like single sign-on, federation, directory, MFA, all of those. Our differentiation is within the risk engine itself. We have a lot more sophistication there. Our fine-grained authorization is much more advanced than many of the other offerings in the marketplace. And not only do you write policy based on the roles, the attributes, the transaction type, we can bring in the concept of relationship between entities when you're deciding the authorization level.

So that's a unique one. And then, uh, within the MFA, advanced MFA, we can get you to the full passwordless and delegated admin pieces. Those are all Like the way we implement that gives you a lot of flexibility. So if you think about the users who are going, or the types of customers who would be a good fit for us on the workforce side, or it are, it is primarily users who have high regulation needs or security needs, but don't have large enough teams to handle all of the nuances of it. So think of it as small, medium enterprises.

You've gone through some M&As, and each of your entities came with its own set of ABC identity providers, and you don't have big IT teams to go and handle all their consolidation or summarization of it. We can come in there quickly and make SecureAuth within weeks be the primary portal for your combined workforce. And you can slowly migrate from your other identity providers into the secure one. So, but a user experience perspective, it could be fast. Again, weeks to get it all up and running, and then you can bring it on.

And, or as you think about it, like this is both for workforce and SIAM. MFA, which used to be like, put that in your, you can now solve all of this phishing attacks or stolen credentials. It's now become a big burden. MFA happens like 20 different times. We have components within our solutions where we can make that MFA invisible MFA.

We have our risk platform, our risk engine working with all the other components to make it as limited MFA, friction-filled MFA as needed. All the other MFA becomes in the background. One of those components that helps us do that is the DBFP device and browser fingerprinting that comes with it, the behavioral analytics of the user along with where and the locations and so on. So workforce, if you're trying to cut down your MFA only when it is absolutely needed and you're having lots of complex multiple ID providers and you want to get quickly into a consolidated view, we should be the one. On the SIEM side, speed of execution is our big value prop there.

Again, we, we could do scale. Most, most of them need a large scale, but we can get you up and running again within, within days to weeks. If you are a global company and you're saying that, hey, we're— I'm going to be here, I'm operating in Middle East, I do need it in AWS Qatar, or some of the other solution vendors may not have something running in AWS quota, we can be up and running in a region of your choice within 2 weeks. Oh wow, 2 weeks. That's great.

So we could do that. And the delegated admin piece in B2B2B or C or E scenarios, our B2B2B type use cases, we don't have a limit on how many levels you can go down. So if you're thinking about like you are a rental agency and you have multiple properties and you have multiple renters across the country or across the globe with various regulations, you can have n number of sub-delegated admins and you can allow for a global policy, secure identity security policy, to be affected everywhere and then allow for regional, state-based, or even country-based policies with those delegated admins to handle. So that's another big value prop which our FGA allows for. That's great.

Yeah. Well, I know we're kind of coming up to the end of our time together. A couple more questions for you. You know, what kind of, you know, folks who are looking to get into the field, what kind of roles do you foresee hiring in the future at SecureAuth? People who are looking to go to school or, you know, maybe, maybe they're just looking to somehow get noticed in the process.

What, What kind of roles, what kind of individuals are you looking to hire? That's a great question. I should probably talk to 2 of my college kids who are trying to do the same thing. Here's my macro thesis. Cybersecurity as a component is going to exist as long as digital channel exists.

It's never done. So cybersecurity as a macro theme is going to remain. And this can be seen even from the physical world, right? Or every time there is like a new way the thieves are attacking, you add more security to the physical side. The same is gonna happen and continue to happen in the cybersecurity.

You put AI for good to protect you and there are bad guys put AI for bad to attack you in cybersecurity. So that is going to continue to remain on. How you address the problems to a place where it can be easily consumed is going to be the, biggest challenge. Or as we have heard this multiple times, Robb, even from our time when we were working together, like there are not enough cybersecurity people, uh, but the jobs and needs continue to exist. So even as sophisticated tools like SecurAuth or other vendors develop and make it available in the marketplace, today we are reliant on extremely smart people who understand those technologies to come and configure and make it easily accessible to others.

We need to get to a place where GenAI not only just answering you how to configure, to also configure it. Yeah. So getting to a place where different cybersecurity tools can be put together and you have means by which a business analyst can formulate what needs to happen and a solution that could be put together with GenAI-based integration, I feel that's where the industry would tilt and move on. And for us to get to that place, we need people who can build it into the platform that it becomes easy and fast to configure and consume. Most people know what they need at the end.

Again, it may not be 100% there. They mostly, they know 80%, but the speed at which they can get it configured, try it out, and then fine-tune it, and that'll be a job that will exist. People wanting to come into this industry, figuring out how to make that configuration easier would be a well worthwhile investment. The user experience as an outcome, right? That people, you know, we're not leaning on technology.

Well, we're not selling the technology. We're selling the ability to get problems solved. And I think that that's right. We're selling outcomes. Huge.

Yeah. So that's a good Better way to put it. Well, Joseph, I really appreciate it. I got to learn some about your background that I never knew. I got to hear an update on your story.

I'm looking forward to us getting lunch and you telling me all the craziness that is being the CEO for a growing tech company. Any final words you'd like to share with the community before we sign off? No, I do appreciate this opportunity itself. Like, I consider this a privilege to be, or to be brought into this podcast. So Robb, thank you for inviting me and also sharing my story.

I'm not the be-all end-all. I've not achieved everything. Again, like I said, I'm in the starting point of this new role. Uh, do want to see this through and be successful in it. And it is not a one-person superhuman or superpower My experiences from the past has taught me that my success is on the shoulder of a lot of other people who have helped me along the way.

Yeah. So you guys who are in this community, in some shape or form, you helped me in the past. And if I can be of value to you, I would love to hear from you and be able to support in whichever way, shape, or form I could do it. I love it. Yeah, please reach out.

Well, I'm gonna, I'm gonna put you on the spot. If you take SecureAuth public, are you gonna invite me while you ring the bell? Oh, absolutely, Robb. Let's do it. Let's put it on.

Let's go.

All right. All right, Joseph. Once again, thank you for your time and Colorado Equal Security. We are signing off. We'll see you next month.

Learn more about the Colorado security scene at coloradosecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes