Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 283. What?
It's February 2026. It is February 2026. Although it it may as well be May or June 2026, just because it seems like that outside. Yeah, the weather is not so cold. We are not really getting a lot of snow this year, but I don't think that that's actually the big segue.
This is a very special episode. Is there? There's other stuff going on, Robb. There's a big. This is a big special episode.
This is the last podcast for you and me to do together. It is. Also, this is our. 9-year anniversary. 9-year anniversary.
That's right. 9-year is— 9 is, of course, the number that we were shooting for initially. At the very beginning, we said, I want to do 9 years. I don't want to get to 10. Then that's too much to write, you know, the 1 and the 0.
But 9, that's perfect. It's a nice— it's a square number. It is. It rhymes with a lot of things. Fine wine.
Yeah, yeah, yeah. Yeah, and and just to to put people's fear at ease, the podcast isn't going away. Just Robb and I being the co-hosts of the podcast are stepping back and letting a new generation of podcast hosts take over and show us how it's done. Yeah, I assume they'll use like cool expressions like yeet, and I don't know what else they what else they could say. We're not cool enough to know.
Yeah, I don't even know what they say. Rizz? They'll bring the rizz. Oh man, this, this is cringe. All right.
Hey, before we jump into this final podcast, let's go through some housekeeping. We do have an amazing Slack community, which I've been struggling to keep up with. So many great posts across different topics. You can, you can join, get to get set up with lunch. We had a DTC lunch a couple of weeks ago.
I know the Boulder crew gets together regularly, get to know folks and, you know, look for a job, help get advice. All kinds of good stuff happening in Slack. We also have a mailing list. If you go to the website, you can sign up, scroll to the bottom of any page on the website and put your email address in there. We'd also love it if, as you're listening to this, you go to the place on your podcast listener and subscribe and then rate us highly.
Of course, only highly. We only take 5-star reviews, otherwise GTFO. And make sure you mention Robb and Alex because otherwise the credit might go to the new people. That's true. We can't have that.
We can't have that. We got to let them settle in before they actually get some accolades. All right, let's jump into— we have one, one more housekeeping, which is we have— this is our last month of having some annual sponsors, right? It is. We were just— a big thanks.
We had 4 annual sponsors last year, and their terms coming up here. Big thank you to CrowdStrike and Red Canary for supporting the podcast and frankly, just being great supporters of the community for, for a long time. For sure. Thanks. Let's jump into the news.
Big story for the first one. Especially if you like beer, or maybe in spite of if you like beer. The Great American Beer Fest announced that they are relocating from downtown Denver. Yeah, interesting that they have been at the Colorado Convention Center downtown, big indoor space, and they are moving to Levitt Pavilion, which is in a neighborhood that I can't remember the name of, but I have seen a concert there. I watched— they do— it's known for having free concerts, and I got to watch a Cake concert there, which was Fantastic.
Highly recommend free concerts at Levitt Park, Levitt Pavilion. You went the distance. I went the distance all the way to to Levitt Pavilion to listen to Kink, and I made it all the way through the concert. That's good as well. But Great American Beer Festival is moving outside.
It's the first time they've been outside. They say that that gives them new opportunities, and I imagine that their pale skin, since they've never been outside, will appreciate a little bit of sun. Slight correction there. This is the first time since like the second year. That they were outside.
There was one early year where they were outside. But I'm interested to see how that's going to work. That, you know, it's in October. Maybe it'll be 100 degrees, but maybe it'll also be snowy. So I'm interested to see how they set that up.
I'm sure with tents and other stuff like that. But well, make sure you start saving up. It's going to be $60 for tickets. What? But I assume that that comes with lots of beer drinking.
Yeah, indeed. All right, we have some Colorado stats. I have, you know, I have 2 sons who are in high school, and I said to one of them— actually, I said to both of them, but when they were not together— the first one, hey, Colorado just passed a milestone in terms of population. What do you think? And he goes, I don't know, 8 million, 10 million?
No, no, not right. Not quite yet. And I asked my other son, and he said, well, they just passed 6 million a little while ago, so I'm not sure what you're asking. Apparently I'm behind the news. Yeah.
So David knew Well, before we did, but Colorado just passed 6 million people in population here in 2025. And while that is a big deal, I think a bigger deal is that as part of that, population increases in Colorado are stagnating. So for a long time, we have been growing very, very quickly. But the annual growth rate for 2025 was 0.4%, essentially no growth. Yeah.
And, you know, I'll give you a little data behind your— we've been growing quickly. From 2010 to 2020, Colorado grew at— grew 15%. And the national average over those same years was 7.4%. So we just over twice the growth of the national average. When you look at what's going on here, we actually last year had more people leave the state than enter the state, but made up for it with births.
So we just barely ticked over 6 million, very slow growth rate at 0.4%. You know, we were over 2% growth in the boom years. And it's interesting, you know, I've always thought of Colorado as a fast-growing state and really not so much anymore. Not so much. And actually, I'm not super sad about that.
If we stagnate at 6 million, that seems like a decent number to me. As long as we also get our roads improved because going up the mountain sucks. Yep. With 6 million or probably with 4 million. All right.
Next story. Uh, Lumen had a big announcement. They have sold their fiber-to-the-home business called Quantum Fiber to AT&T. Did they sell their fiber to businesses? They did not.
Did they sell their copper to home? No. Yeah, so very specific. It's just one niche, right? Yep.
Um, but it was kind of interesting stats in here. They sold it for just under $6 billion. The— I think it made something like $700 million-ish in revenue. Maybe $700 or $800 million in revenue for this. But what the one interesting line on here to me was that they were, that the expenses with this business they sold were about $1 billion a year.
So if I do that math, they were losing $200 to $300 million a year, but somehow it was still worth $6 billion to sell. That was really interesting. That is really interesting. But you know, once AT&T has it, you know, economies of scale, they're gonna make a ton more money on that. Yeah, you just do it at scale and you make it all back.
No, I get it. That's how that works. It is interesting to see how these companies shuffle around assets that, you know, does it really fit better with AT&T than it does with Lumen? I don't know. But somehow they're— they see it that way.
And, you know, also part of it is like kind of like when EchoStar sells their spectrum, it's as much to free up cash position as anything else. And that just gives them some money to go. Yeah. They mentioned as part of this that the money that they are getting, they're going to use about $4.5 billion to pay down to pay down debt so that they will get under $13 billion in debt instead of $17 or $18 billion in debt. So, well, congratulations to Lumen, who is not headquartered here, but we kind of feel like it is because it's close enough because they have most of their leadership here, I think.
All right. Well, we have a Louisville company that is about to go public and they're doing quantum computing, sort of. Maybe it doesn't really say exactly what they're doing in the article, like all quantum computing stories. But the, the company Inflection, with a Q, with a Q, which used to be ColdQuanta, they changed their name at some point. They're going to be going public as part of a SPAC, special product public acquisition company, basically a sneaky way to go public here shortly.
And they say some glowing things about all the cool things that they're going to be doing soon related to quantum computing, but have no details about. Yeah, you know, it is— we are in the quantum age right now where people are just racing to try to have actual marketable technology there that makes a difference. I don't— I can't tell from the outside how real any of this is. This makes me personally like, yeah, reticent to want to invest. But I know that there's a lot of future in that industry, that technology, when we figure it out.
And hopefully, you know, Colorado is clearly one of the leaders in this space. And hopefully these guys are part of that. The other thing that I don't get exactly is why they want to be a public company. You know, I'm sure there is some advantage and some reason that they're doing this. It doesn't really say in the article.
And I can't off the top of my head think of why being public would be better for them than continuing to be a private company and taking private money. But I'm sure that there's some good reason. Yeah. At 185 employees, that's where they are. Yeah.
What's the— what's your upside? Right. Unless you're trying to take money off the table or you think there's some kind of a bubble in the public markets, I'm not sure why you'd do it. Yeah, that's a good point. I'm sure there is some good reason.
I just don't know what it is. Yeah. All right. Next, we have a Denver Post article talking about the legislature and what's going on in current lawmaking. And this is talking about some bills that are going around the legislature right now.
I don't know that any of them have been passed yet. But they're debating energy and tax breaks related to data center building in Colorado. Yeah, I find this really interesting. You know, they're building data centers is one of the huge keys to unlock the opportunity from AI. Right.
And the cost of data centers, that is one of the big constraints. It's a good thing for the AI industry and probably for all of humanity, although that's always questionable. Um, but is it good for the place where you're building it, right? That's— I think that's what the— these legislators are struggling with. And they, they're putting together incentives.
On the one hand, we want you here. And then on the other hand, they're putting together, I don't know, requirements like we want you to be selling a certain amount of energy to low-income people at this low— this low rate, or you have to offset the energy that you're using with green energy credits or things like that. So they're looking for kind of this, we want you here, but we want you here under our terms. And I find that to be probably how we should feel about this. Like, yeah, we think it's probably important to do and we'd love it to be in Colorado, but not at any cost.
Right. Just the right way. Yeah. And another of the bills that is talked about in this is one where they're proposing 100% exemptions from sales and use taxes for 20 years. Which to me, um, I guess I know that that is an incentive for people to come here, but that seems like we're just giving away everything.
They're coming here basically for free, not paying their share. I, I mean, I, you know, who knows 20 years from now, like, is that data center even going to exist there anymore? Well, we need that data center. You're— I think you think like, let's get them here and sometime in the future we'll get some benefit from it. But that just seems like you're giving it all away.
So the So I think that's the headline, but the nuance there is in order to get that 100% exemption, you have to commit to $250 million in data center investment, and you have to create a certain number of jobs, and there's some other requirements that, you know, the company doesn't just get no taxes. They gotta hire a bunch of us, right? And that's, I think, what the state's really trying to do is bring those jobs in. That's true, and, you know, there is obviously some nuance there, but, you know, to spend $250 million, you're gonna spend more than that to build that data center, so they're not, they're not going to do anything else besides what they were already doing in that part. And then I guess it depends on what those job numbers are and how many people are actually going to get employed and what benefit that does actually make.
So we'll see. All right. Well, we will see. I know that, you know, we already have a lot of data centers over kind of in the DIA area. And I think that that DIA Aurora space is where a lot of this is targeted to go.
All right. Jumping over to some of our security blogs here, we have a blog from Zvilo around agentic AI security and how it is actually exposing the limits of zero trust. Yeah, it's, uh, it's an interesting, uh, thought article here. Uh, you know, most often when we talk about zero trust, we're thinking about, uh, people and the identities of a person and how every time somebody does something, we need to be validating their authentication and, and making sure that we're not trusting them. Every time, you know, we're validating that they really are still in a good security position, that they really do have authorization to do what they want to do.
But when you're talking about agentic AI, these agents, they're not actually people. And some of the assumptions that you make for authenticating a person break when you're talking about an agent. You know, and I wonder how true that is. I get what they're saying, that zero trust is more about at the moment of doing a thing. And when you start an agent, start, set up an agent, you've kind of had that one moment and it's going to have access ongoing.
But I think that's exactly the same as a user session and exactly using the same technology. A user gets access and over time that agent can learn new things, you know, be compromised, bad things can happen, and so can a user, right? For sure. And I think, I don't think it's actually a new risk related to agents. It's just that agents, just like everything else in automation, Like, just make it go faster, right?
It accentuates the problems and make them more obvious. It's more scale for them. I think that there is some nuance there, right? Like, for, for a human, the, the access that they should have is pretty stable, right? Like, things will change, but it's going to be stable.
But with an agent, you could have multiple different people using this same agent, and there might be different access that, that is provided to each of those people. But through the agent, the agent is seen as one thing so that the agent has to be able to differentiate between those people and maybe provide different information back or other things like that. So it's possible that, you know, say you're granting the agent all of this access because you need multiple people to be able to get different things, right? So it's just a more nuanced zero trust conversation. But it's just Now you're talking about a service account, basically.
It feels like it's either a service account or a user issue, one or the other. And it is hard. I mean, I'll say I'm working on very similar problems at work when you think about data access and how do you make sure you're able to get the right insights from data while maintaining user privilege for the outcomes of that data. It's a hard problem and it's worth solving. And I appreciate Zvilo writing a blog post that gets you to think about it.
Exactly. Speaking of AI agents, we have a press release from Swimlane talking about their unveiling of their fleet of AI agents and agent builder to power the security workforce. We have a quote in this article from Cody Cornell, which if you've been paying attention to the blog, to the podcast you're listening to, he's our guest interview this month. Cody is the CEO and one of the founders for Swimlane, and basically they have really gone all in with, you know, turning the SOAR platform really into the AI agent platform for your security tasks. And the quote says they have like something like 60,000 AI agents worth of, or I guess SOC analysts worth of agents working now across their enterprise.
Yeah, and I think, you know, one of the things you might think is, well, how are these agents any different than the playbooks that they already had? You know, most of the sort of traditional SOAR playbooks are pretty deterministic, you know, do step A, do step B, maybe a decision tree, do C or D. But when you're talking about agents, they obviously can make more decisions real time and other things like that. So it's not necessarily deterministic. You can talk about outcomes and other things like that as opposed to just a recipe. Yeah.
Well, you know, if you're sitting here listening to the podcast thinking, man, how am I ever going to use AI in my security program? You could do a lot worse than looking at Swimlane to see if the, the agents they have can, can help you accelerate pretty quickly. So take a look. With that, next story is from RADICL, another Colorado security company that's, that's, uh, we know the founder. We've had the founder on the show.
Chris Peterson was the, was one of the co-founders of LogRhythm and has been at RADICL for a while. And, uh, and if you remember what, 2 years ago, 3 years ago when RADICL first came out, it was this like super marketing-y, we're coming to go make, bring security to the masses. We didn't know what it meant. Well, they've got really crisply clear about what they're doing now. They just raised $31 million, and their niche target now that they've zoomed in on is providing security services, specifically like MDR services for DoD, critical infrastructure, small and medium businesses.
Pretty nice narrow market. Yeah, and I think the defense industrial base does have a slightly different risk and threat profile than many other businesses, and There are a lot of small companies that can't afford to go with a big fancy provider. So having one that focuses on them is a cool thing. Glad that's happening. Good stuff.
All right. Next, we have a blog post from Ping Identity talking about zero-knowledge biometric authentication and what it is. Robb, what is it? Well, first I'll say the last 2 stories we have are from Robb's last 2 jobs before his current one. So we get to talk about Ping where I got to— I was the CISO there for several years.
Zero-based biometric authentication. This is something that, you know, I honestly wasn't super familiar with, but the idea being you're able to pass through the biometrics without having to give— sorry, the attestation of the biometrics being authenticated without having to give those things to Ping or to the SP on the other side, service provider. Yeah, one of the things they mention here is that, you know, traditionally with biometrics, um, the, uh, the service provider is keeping a store, a centralized store. Maybe they're doing some things to make it slightly less centralized, but basically a centralized store of all this biometric data to be able to authenticate against it. But that of course leads to the risk of that being compromised, and then now you've lost your biometric data, things like that.
And, and so for this standard that biometric data is staying local on a device. It's only tied to that one device, you know, a little bit like passwordless authentication, and then using cryptography or other things like that to be able to say, yes, that they passed and this is— give them the authorization, but not passing that biometric data through. So your device captures your biometric, your phone or your laptop, It generates a cryptographic proof. The server on the other side verifies the proof and you're in. You'd never actually share the biometric data.
So that's what it is. Cool stuff. All right. Last one. I kind of gave a little bit of a hint.
Last one is from our friends at Red Canary, the local friendly MDR. This is Go Jump in a Lake: Measuring the Data Lake Effect on Your SIEM. Yeah, this is actually a multi-part blog series and there's also some videos that go along with it, but Um, you know, it's talking about what, uh, data lakes and security data lakes are and why it is you might want to have a security data lake as opposed to, you know, storing all of your security data in a traditional SIEM or other things like that. Um, this is going to be a shocker, but Red Canary offers a security data lake product. And while they don't talk about it a ton in here, they do give a lot of great detail on the amount of data that you can cut down on and the cost that you can save by, by using a data lake.
And obviously, if you want to use theirs, I'm sure they'd be happy for you to do that. But they talk about, you know, how you could roll your own and other things like that too. So it's interesting and a deep dive on security data lakes and things I hadn't really thought about. Awesome. All right, that's it for stories.
Let's jump over to events. As a reminder, we have a calendar of events at colorado-security.com/events. Go out there and see all the things happening, not that we're putting together, but that the whole community is putting together. Alex, what do we got coming up this month? Yeah, first CSA Colorado is doing an event, Enabling AI Rules of the Road on the 17th of February.
Couple events on the 19th. ISSA Colorado Springs has a February trivia night and ASACA Denver has a February meeting with the IIA. On the 25th, we've also got a couple events. Denver ISSA is doing an AI/ML special interest group. And I'm seeing a trend here, some AI-related events.
And then finally, ISC² Pikes Peak is also doing a chapter meeting on the 25th. Fantastic. That is it for events here in February. And that is just about it for us on this podcast. We do have a— we do have an interview coming up.
And we thought it was fitting to have Cody Cornell, who is the the co-founder and CEO over at Swimlane. I think he's— I think this is his 4th time visiting us over the years. We've loved getting to know Cody and seeing how that company has matured and made so much progress. And he's been just a great, a great human and a great leader over there. But before we throw it over to the interview, Alex, any, any reflections on 9 years?
Yeah, I think before we talk about that, one thing I wanted to mention too is, you know, we mentioned that we are going to pass this on to new co-hosts. I think we mentioned it in the last episode, but I don't think we specifically said it in this one. Joe McCallister and Chelsea Weiss are going to take over for, for us for the, the co-hosting duties. Frank Victory has been nice enough to stay on and continue to do some of the interviews for us so that, that won't change. But we're excited to have them.
And, you know, they'll be coming in to do the podcast and you'll be hearing them in the coming months. So I am so excited to be a listener to the podcast coming up here. And huge thanks to Frank for all his years of helping us out. And I'm so excited to see Chelsea and Joe take it in a new direction. Hopefully they have better humor than we do and better insights for sure.
I know they're better looking than us, so no doubt in every way this is a step up. Maybe they'll do a video podcast. Oh yeah, we are giving them some latitude to change things in the future. So maybe, maybe things will change. We're still around, but we're excited to pass it on.
You know, you can think about us, you know, we're going to keep the executive producer kind of, kind of title, right? Like, we'll still be behind this, but not doing the day-to-day work anyway and supporting as much as we can. You know, this has been a great journey for me. It's been a lot of fun. So some things that I remember, one of them is actually getting recognized somewhere in public by my voice.
Somebody, I think it just happened one time, came up to me, was like, hey, are you Alex? I recognize your voice from the podcast, which is not something I ever thought would happen. That's hilarious. Which is pretty cool. But one specific podcast memory that I have is actually from episode 4.
Oh, wow. Going way back. This was probably the first recorded, like, real— I'll call it real interview that we had. It was with Brian Beyer. Sure.
And we did it at the Red Canary office. And this was their, you know, 2 offices of theirs ago. And it's funny, we, we still didn't really know what we were doing. And so we have the equipment that we're still using today was the equipment that we bought then, but it's these, these mics with mic stands and like, it's a, like a mixer and there's a lot of equipment more than like you should just carry around with you. It's not really meant for that.
Yeah. And I mean, I showed up with like a grocery bag with like all this equipment in it and then put it into a conference room there and had to set it all up. And, you know, Robb actually did the interview with Brian, but I was there sort of like the audio engineer, like making sure all this stuff was gonna work and how are we gonna do all this stuff? 'Cause we just really didn't know. It was a lot of fun though.
I do remember that one. Thanks for that reminder that we learned and we stopped using these mics for that. We did. We're still using these mics for the, for the newscast. But, um, when you go do a remote one, you get a little lapel mic, USB hub, everything works better.
Uh, one of my favorite, my favorite interview, and I've mentioned that I have 2 favorite interviews, um, Patrick Quinlan, who was the CEO and co-founder or co-founder of, uh, Conversant, which doesn't exist anymore. They're part of OneTrust now. Um, we got to talk with— I got to talk with him and holy smokes, the guy had this just amazing perspective having grown up in Europe and in Germany when Berlin, when Germany was, what do you call it, separated, whatever the word is, you know, the Berlin Wall, all that. And just telling the story of going into Berlin on the Freedom Train. They called it the Freedom Train because if you're like me and you didn't realize this, Berlin was not on the border between East and West Germany.
Berlin was hours into East Germany. So, but, but Berlin itself was a divided city. So half of Berlin belonged to West Germany and half belonged to East Germany. That's weird, right? So what that meant was there was a train you could take from West Germany into West Berlin that went through East Germany, and you would end up on the West Germany side.
And he just tells this story of like seeing the kind of the poverty and the sadness of East Germany versus the freedom of the West and how that really helped establish his perspective on, on life and the world. And anyway, nothing to do with security, but a lot to do with who he was as a person. I remember that vividly. Second, one of my favorites. I, I have been a longtime listener of other podcasts, and I got to interview Cal Fussman, who was one of my favorite podcast hosts.
And he was on the show back, man, 6 years ago, 7 years ago. And Getting to talk with him, just a cool moment that this community set up because we have him come into town and talk at RMISC that year and getting to, getting to hear his stories, just amazing, right? So my favorite things on the show had nothing to do with security, all about people, all about community and the learning we did through this. I would say, I'd venture to guess that he is probably the, the most famous or well-known person that we have had on the podcast too. Didn't we have, uh, um, McAfee, John McAfee on the, on the podcast?
Do we actually have him? I think we had, well, we had him do an interview that I think we might've run on the podcast back when he came to RMIC. He's pretty famous too. He is. Yeah.
Crazy. He's passed away. Rest in peace, my friend. Yeah. Good man.
I don't know. Maybe he was, maybe he wasn't. It's hard to say. What do I know? At some points, maybe.
What do we know? All right. Anything else before we throw it over to the interview? No, this has been great. It's been a great ride.
A lot of fun. And, you know, maybe you'll hear us back on here every once in a while, from time to time, in case we're needed. But this has been great. Or it'll be Colorado Equals Security 2. We have a different podcast that competes with theirs.
Who knows what's going to happen? We're not doing that. Colorado Equals Security, the Ocho. The Ocho. All right, let's throw it over to Frank.
Hi, this is Nick Purcell. I am supervisor at Toronto BCT. Welcome to Colorado Equals Security for Colorado Security Professionals.
Good morning, good afternoon, and good evening, State of Colorado. This is the Colorado Equal Security Podcast for February 2026. My name is Frank. I'm the host of the interview portion of the podcast. And today, I guess for the 3rd time, we have Mr. Cody Cornell.
He is the CEO and founder of Swimlane, but That's not his only job. He also has the volunteer and Sawyer for Team Rubicon and partner and co-founder of Phoenix Cyber. How are you doing today, Cody? Good, Frank. Thanks for having me.
Thank you for coming. So we've, you know, you have a lot of different experiences and, you know, but before we actually get to that, right, and before we get to some things that I really want to ask you on this podcast, Let me get you an icebreaker question here, right? You're the CEO of Swimlane, right? And obviously well known here.
How did you come up with that name, right? And, you know, one thing to talk about, but the other part to talk about here is that if you were the captain of a pirate ship, what would your pirate ship name be? Oh, So it's funny you say icebreaker and pirate ship, and I think I shared this in the last podcast. My— when I got out of high school, I joined the Coast Guard, and my first duty station was an icebreaker, literally. Yeah.
So whenever I think of boats, I think of that. And, uh, I am not a very seagoing person. I get seasick pretty easy. So it would probably be like, you know, the USS or Her Majesty's, like, seasick, because I do not do well. Yeah.
Like I would not be a pirate. I'd be the world's worst pirate. Like, as a big fan of The Princess Bride and the Dread Pirate Roberts, I always thought about like, man, that it's a great story, but like that never would've been me because even for the year and a half, almost 2 years I was on a boat, I was seasick the entire time. So why did you, if you were seasick, why did you join the Coast Guard? Yeah, it's like a really terrible life choice, right?
I grew up in like middle of nowhere Montana. So I'd never spent much time. I'd never actually spent any time in the ocean, so I didn't know I got seasick. I didn't know until, you know, we pulled out of the Puget Sound in Seattle and actually got into the ocean that I actually am a terribly sea— I'm terribly not seagoing. Like, it's just not for me.
So would you suggest that anybody that's looking for a career in the Navy or the Coast Guard, maybe you want to try what water feels like first? Yeah, I mean, it's probably not a bad choice. I think most people adapted fairly well. I mean, there's a lot of people from Middle America that joined the service, the Navy or the Coast Guard. And do fine.
I just never adapted. Most people kind of adapted. I, you know, I was downing Dramamine, but that didn't do enough for me. So unfortunately, those were pretty miserable moments between diesel fumes and, you know, the boat sloshing back and forth because the icebreaker shipped like a bathtub. It doesn't cut through the water, it just kind of floats on there and made for a pretty terrible life experience.
So in that sense, okay, well, since we're kind of on that subject and before we move on again to what I really want to ask you about Could you take some of that experience from that icebreaker and apply it to your business life today? I mean, could we come up with some kind of meme? Can we come up with something that says, well, I'm going to break the ice with somebody, or I'm going to figure out how to navigate these waters in cybersecurity? I'm sure we could build some type of cliché or something like that. But I mean, I don't know.
I mean, being someone who was in the service and knowing a lot of people that were in the service, I think, you know, by and large, man, the leadership things that you learn, both good and bad. Like any organization, they're both good. I learned a lot of great things about, you know, leadership and, you know, leading people, and also like how you build camaraderie, especially in this online world. There are things about being in the military that I think people miss that were there because you, you're kind of put in awkward situations, you're forced to be around people you might not have met otherwise, and kind of those bonds that are built And I was never in combat. So in the trenches is probably the wrong cliché to use, but those people that I spent a lot of time with and on those trips and things like that were, they're still friends, still people I talk to today.
And I think that's hard to do in modern society. So there, I think there's some things that I learned there. I don't know what meme I'm going to create, cybersecurity meme I'm going to create out of that, but those are good experiences. Well, from a pure leadership standpoint then. Are there things that you learned in the Coast Guard, in the military, that you use today?
Absolutely. Um, okay. I think one of the things that really stands out for me, and, you know, we— there's a lot of talk right now, and I think kind of what's happening with AI and entry-level jobs, you know, people are always wondering how they get into this career because it's been a great career for me for 20 decades— 2 decades— 20 decades— 20 years, a couple decades. And I've been very fortunate to kind of hit that, the timing of that really well. And I think one of the things that I learned in the military is that I, I was very green.
I didn't know what I was doing. And, but I had a boss, especially early on, it was one of those guys that took all the blame for things that went wrong and took none of the credit for the things that went right. And I think if you're thinking about like, how do you groom and get and train junior people Part of it is, you know, they have to get in and do the work and learn how to do things. And there's some— but you gotta provide them some air cover so that they can make mistakes and that they're willing to take risks and to learn. Because if they're always just kind of worried about, you know, a misstep, then they're really not gonna challenge themselves.
They're not gonna try new things. They're not gonna be willing to be creative. And I think as technologies evolve, one of the things in security that's gonna continue to be important is that people are, willing to try new things and be creative because that, that is going to be our job. Because unlike almost every other part of technology, there's a person on the other side of the wire that's trying to undo the work that you're doing. And that's always a strategy match.
Okay. Well, I want to get back to that because I think that's going to be a very good discussion. But before we get into that, I'd really like to talk about your previous guy where you said, wait a minute, He took all the blame for things that went wrong, but then didn't take things for when things went right. That's pretty much the opposite of most people that we know in this industry, right? Yeah.
So this next section is about the boss who took heat, leadership, and psychological safety, right? A team breaks broad, but the boss walks into the project room and takes responsibility. The inspiration for Cody's story is a boss who took all the blame for things that went wrong and took none of the credit when the things went right. Why does psychological safety reduce turnover? One practical action, like what I learned retro from an incident.
Yeah, I mean, and as a vendor, it's hard because your job is to market and sell software. So like that ability to You know, you really always want to be kind of projecting that you know what's right and that you did this work, especially as a leader. You get a lot of credit for the work that hundreds of other people are doing because you're the face of the business. And, you know, I think back to, to Tony, and that was— he was my boss at the time, and how, you know, when things went really crappy, when, you know, the people that worked on my team made, you know, bad decisions and broke things or, you know, were late or whatever bad decision they made, they He kind of would, like, would step up and, like, take the heat for that. But when things went right, which was generally because of his leadership, he would give the credit to the people that, you know, did the work along with him.
He never really took the credit. And, and because of that, like, I think that's— it's not common, but I think what it does is it, one, as a leader, you get people that really want to follow and help you because they know that they're going to get credit for the work that they do. And if they make a mistake, they're not going to get bludgeoned for it.
So I think that goes back to what you're covering, even with the entry-level people, giving them that safety net, giving them that. So it applies more than just the entry-level people. Yeah. No, I think it's any time you're in a leadership position with your team. I mean, it's not about coddling people.
It's about making sure that the people that do the work get the credit. Yep. I absolutely agree with you on that one. Cool. Okay.
Again, I think that's the, the people. But what I've— and I tease this a little bit, so I want to talk about this one. We've had plenty of CISOs in here, VI, you know, technical security leaders and other people that have come in here. CFOs are in our last podcast. We had a CFO in there and we all talked about how to convince a CEO of making decisions.
We are now in a unique position, or a new position, at least for when I'm doing the podcast, where we're asking a CEO and we're looking, I guess, from the top down, right? We've always said, what do I have to do to convince a CEO? What perspective can you give us as security leaders, as either a technical security leader, VP, director, etc.? What could you give us to say, well, This is how you would convince me to make a security decision because obviously, and I'm making assumptions here, you've got a lot more than just security to be concerned about. Yeah, absolutely.
You know, I think the advice that is typically given is accurate. You know, the, you know, the CISO can't be thinking exclusively about security. They have to be thinking about the business. How is security an enabler of business? So on and so forth.
So I— we're about to jump into something that could be called glasshouse governance, selling boring security work to execs, right? There are 3 talking points that are coming up that we can use to frame governance as a business enabler: revenue, procurement, and renewals. We're going to draw on Cody's experience of governance as an enabler angle.
That's the advice I typically would hear that folks are giving, and that is— I think that's accurate, right? When I think about our business, Mike Leiborg is our CISO, total rock star, and the thing that he does really well is, you know, he understands what we're doing and how we do business. And security is an enabler for us, right? The security of our product— our customers are security buyers, they expect security to be baked into the product. But also if you think about the security process for selling, you have to respond to RFPs, you have to answer questionnaires, and a lot of that stuff is, do you meet these object— you know, these security requirements?
And those change depending on where you're at on the globe. In, you know, Europe it's GDPR, in the US it's, you know, ISO and SOC Type 2. And what Mike has always done is done a great job of understanding the value of the certification and what it means for the sales process and how it helps the business generate revenue, helps our sellers, helps the marketing team, but also that it's not just security theater, that all the things that he's backing it up with are actually the security controls, the practices, the operational things that actually drive security, both within our enterprise, small as it may be compared to a big, you know, Fortune 500 organization, but also more importantly, the customer environment, the actual SaaS environment in which that we operate in. Okay. Well, How about this, right?
And let's say that, you know, and we'll of course do it on a product that you know well, right? Automation, right? So I work for ABC Company and I need to go ahead and I said, we need some automation in here because we're just doing way too much manual and we want to use a product like Swimlane or something else to go ahead and, you know, make our lives easier. You're the CEO of ABC Company, right? And you make widgets.
How do I convince you to spend X number of dollars for this product to make my life easier?
My life easier as the CISO or as the CEO? As the technical— oh no, as the— so you're the CEO, you obviously have to worry about the entire business of making widgets. How would I as a CISO, right, convince you to do this, to go and invest X number of dollars, whatever the budget is, to go in there and say, hey, I need these much dollars to make my people's lives easier. How would I convince you, or what would I have to do? Should I do, you know, an email to you?
Do I have to do an entire PowerPoint? Do I have to do a cost-benefit analysis? What should I bring to you? Yeah, I mean, I think all executives are super busy, right? So I think the You know, there's something that you hear a lot in like government is, you know, the BLUF, the bottom line up front.
Like you need to bring the data and all the supporting facts and all that thing. But really what they want to know, especially if they trust the individual, is, you know, give me the information that helps me make the decision. And if you have a recommendation, let's hear what it is. But I think you want to bring, you know, what is the, what's the problem you're trying to solve? You know, what is it?
Why is it a problem? For us specifically? What are our options to solve it? What are the pros and cons of each of those options? How much do they cost?
And why do you recommend the one that you do? It's not, you know, it's not rocket science. I think it's really about being clear. I think the hardest part about the whole thing is security can become very nuanced and very technical, and the rationales of the why and the technology and how they work, those are all important. But ultimately, there's got to be kind of a synthesis that allows us to make a business-driven decision.
And probably more importantly, before that, you got to help educate folks on how security is relevant to the business itself and how it's a business enabler and how not doing it properly could have negative business ramifications. Okay. And is there any specific advice, though, that you can give to you know, a tech head or to a security leader to convince you? I mean, is there a magic phrase? Could I say this magic word to Cody?
And if I say this, something triggers in his brain and says, yes, approved. How to convince a CEO. 2-minute pitch template for security buys. We need to give exact slides, phrases, executive bullets. What's the problem?
How this solves it. Options, recommendations. ROI and risk delta? I don't think so. I mean, that feels a little like you're fearmongering slightly if you're trying to like find a trigger word.
I mean, obviously, you know, organizations that have been through different experiences, be it a breach or, you know, some type of security violation that kept them from, you know, executing business, like bringing those things up, obviously, to a leader that's had to experience them, you know, can definitely be triggering. I don't know if it's triggering in the way that you want it to be, but those definitely get attention. But you got to be careful not to beat on that drum too hard because there's also the fear of the crying wolf. If I come to you with the sky is falling for every security purchase, then eventually I don't think anything's going to happen. The sky is never going to fall.
And now I'm wondering why I keep writing checks. Okay, well, and I mean, I think what we're talking about, of course, is FUD, right? And yeah, never to use FUD, or should we ever use FUD? Is it— is there a rule, again, a rule of thumb? And I'm trying to get your unique perspective from a CEO versus, you know, going— again, going up as a CISO.
Yeah, I think one of the hardest things to deal with when, you know, when I meet with our CFO and we talk about, you you know, different security investments and things like that. You know, we've been in business for a while and, you know, we've, you know, thankfully that, you know, we've had some good luck along the way. But you go, we've survived this long without this technology. What has changed in our environment, our needs, what's happening in the world that justifies us adding something new? And, you know, because there's always the, if we've gotten this far without it, why do we need it now?
And I think part of that is, you know, and for me, again, I'm not hands-on keyboard triaging security alerts and cloud configurations every day. Sometimes I need to, you know, be educated on like how things have changed, how we've moved to, you know, infrastructure as code or why we're doing kind of like GitOps and things like that I don't have to deal with on a day-to-day basis myself and how those things have changed the technology landscape and why what we did yesterday might not work tomorrow. And why this piece of technology is highly— is going to help us make that transition. Okay. Well, let's kind of build on that because I'm looking through your background and when we're looking at your background, you were an IT security architect with IBM as well as with American Express and obviously 2 big companies that are gigantic.
And then all of a sudden you switched over to more on the business. So what is one technical habit that most security leaders must unlearn to become an effective executive? Ooh, unlearn. I had to unlearn a level of idealism as it related to security. I think, and maybe not so much as I transitioned from being a practitioner to starting businesses, but I think later in my career working at Amex and IBM, I think I started out very much as an idealist and working like everything could always be better and it could always be more secure and we could always do more.
But there's just limitation, operational limitations, financial limitations that just— you— there is some level of risk you have to accept. That's what insurance is for. And you have to find the things that are going to give you the most value that are realistically, pragmatically actually able to be implemented. As opposed to, I know we can do more because the more is infinite there, you know, to the point where there's no connectivity and no one can actually use the thing. So that, that's what I think you have to find is you're trying to strike that balance between, you know, more isn't always better and more isn't always realistic.
And I had a— and I'm not saying this is for everybody, but I had a fair amount of idealism that I had to kind of tamp down a little bit as I went through my, my, my career. So is it possible to achieve perfect security? No. Yeah, I would love the person that says yes. I'd love to chat with them about how that works.
So what's acceptable to you though? I mean, and again, obviously this is a very subjective kind of thing, but what makes you say that I'm going to accept this risk? I'm going to allow product, you know, our widgets to go out there and be insecure. Is it, you know, your likelihood? Is it, well, security through obscurity?
What makes you that decision? And I know I'm asking you from a very high level, and there's probably 500 details that you would need to really make that decision, but in general, Yeah, I mean, it's a risk-based decision, right? I mean, when you think about like security risk as it relates to the organization or your product, I mean, obviously ones that are existential, you have to really, you know, those are non-negotiable. Like you have to fix those, you have to make those investments, you have to do whatever it is. And then every, you know, then as you kind of move down that, you do the classic, you know, formally or informally as a leader, you're doing the mental math of you know, what's the risk here?
Which means what's the likelihood of this happening, at what frequency, and if it did, what's the potential of the impact? And you might not be writing it out as an algebra formula to give you a quantifiable number, but that's what you're really thinking about. Or you're, you know, what is the likelihood of a meteor hitting the data center in which your software provides? Well, it's probably pretty low. It's not zero, but I'm not going to deploy any capital to solve for that because if a meteor hits you know, US-1 or, you know, AWS East, let's be honest, no one's gonna be talking about Swimlane.
They're gonna be mad because Netflix is down. Like, we're gonna be a rounding error in that conversation. But that doesn't mean that we haven't, you know, made investments in availability zones and, you know, different data centers and the availability of the product. We do because we know that those things can go down. So those are things that we think about and that we make decisions on.
But I think You know, every time we talk about that, you know, if it's the additional engineering capacity we have to allocate to security initiatives, if it's more product that we have to put in to, you know, to improve security or visibility of what's happening with our technology, that we're doing that kind of risk analysis. And, you know, again, I'll kind of parrot what Mike always tells me. It's all about risk, right? Like you're making a risk-adjusted decision. Is there an area, though, that makes you really drive this decision?
Is it always budget? How about that? Is it always money? That says, I'm going to accept the risk because I can't spend the money right now. It's less about money for a product company.
It's more about engineering capacity. Okay. Like, I mean, obviously we don't have infinite funds. We, you know, compared to the IBMs of the world, we have very limited funds. Right.
But what it, what really is expensive for us is the, the balance between innovation and, you know, tackling security technical. Like those 2 things are always in conflict with each other because the people that are responsible for it are always the same. You know, you have an engineer that can go out and build the next feature that is, you know, going to help you against your competition, that your customers are asking for, that a partner is asking for, or, you know, you have, you have an infinite backlog of more security things you could do. So the trick is balancing those 2. The most expensive thing in a product company is foregoing innovation to deal with security debt.
So customers' volume drives prioritization. If we fixed every security issue, we'd never ship a new feature. Can we teach prioritization matrix for feature versus security work? Okay. I'm going to ask you something here and it may make you upset because I'm going to challenge you here.
Right? Go for it. Is there a few minutes ago you were telling about how you had to lower and not be an idealist, but then you just talked about now about innovation. Aren't those kind of in conflict with each other? Like innovation and idealism?
Yeah. I don't think so. But maybe you're thinking about it differently from me. When I think about innovation as it relates to building product, you kind of think about it in, you know, a percentage of engineering capacity. What percentage of engineering capacity are you going to allocate to what activities?
Is it, you know, improving the quality of the product? Is it improving the integrations that are with the product? Is it adding new features? Is it, you know, tackling UI/UX, whatever it might be? Is it fixing bugs?
Is it fixing security issues? And obviously you're always allocating a percentage of that engineering capacity to all those activities at any given time. But sometimes you have to allocate larger percentages to different things. If you have, you know, customers that, you know, maybe I need to close a deal, so I have to go and build a feature. That's the innovation I have to go do to get a customer on board.
Inversely, You know, you might have, you know, a bunch of CVEs that come out and now you have a bunch of backlog work. You gotta go bump a bunch of packages. And that doesn't— your customers don't see that, right? That isn't going to generate revenue for the business unless you think about it from a buyer's perspective where security is an important element to the product. And I think that balance is always hard for us because we have limited resources.
Well, I mean, you talked about, and for example, in a little bit you gave some examples, but innovation, UI/UX, right? Is that innovation or is that idealism? UI/UX and innovation, is that idealism? Or new product, or, you know, a product in general. Is that something new, right?
You know, you know what I'm saying? I'm trying to get into the point of what's that difference in there, or is there one, right? Or am I completely off and they're 2 completely different things? Yeah, I'll be honest, I'm struggling to draw the parallel between idealism and innovation, but I think the idealism for me would be we don't ever build another new feature unless every security problem we've ever identified within our product is fixed perfectly. That means we would never ever ship a new feature because there is an infinite number of security things we could do.
Like, there's always one more thing. Like, why are you not using, you know, quantum-level encryption? Or, you know, like, you could always be moving forward. But if I was always doing that, we wouldn't be able to invest in, you know, the AI agent-building capabilities that we add to our product, whatever the new capabilities we're adding. So I do, I guess, in that sense, I do think there is a parallel between that.
And you have to balance how much you can, how much idealism from a security perfection you can get, but you still have to continue to innovate. You still have to be a relevant product in the market. Well, right. I mean, obviously, if we try to make things perfect, if we try to make it to that point, we'll never release a product, right? I mean, we'll never get it out of there because, you know, we all know that we'll never be perfect for anything like this.
Okay. Well, I think that was very interesting here. How about this then? Because we are talking a little bit about, you know, strategies and selling for governance and compliance, right? Is that a business enabler or is that a cost center?
For us, it's an enabler. I mean, there's obviously a cost associated with doing that, but if you think about the people that use our product, you know, Fortune 500 companies, Global 2000, large managed service providers, the government, Those are all people that use the product. They do not purchase products that don't have, you know, not only just good governance practices, but have, you know, passed audit, have certifications, things like that. So for us, there is a cost to do it. And it is, you know, from a P&L perspective, is a cost center.
It goes into the cogs of selling the software, but it's not a— it is also a business enabler because it allows us to sell into organizations that demand that. Okay. But we sell it, we sell it. I think if you're talking about enterprise B2B software, there is an element of cybersecurity that is expected in order to get sales done. Okay.
Do you, how often do you want to think that sales is, you know, do you ever want to sell something that maybe is not a business enabler, right? Or, you know, have you ever tried to not sell something? Right? If I want something in a product, if I'm your customer and I want, you know, this fancy new feature with blinky lights, have you ever said no? You— no software company could ever build all the features every one of their customers ever wanted.
It's just impossible. Okay. Yeah, I mean, if you're, if you're at any scale from a software perspective and you have, you know, hundreds of hundreds and hundreds of customers and thousands of users, the amount of feature requests that you get will always outstrip the engineering capacity you have. And you'll add more engineering capacity because you get more sales. And that just is an exponential problem.
Now, the thing that you think about is themes. What are the things that are consistently being asked from customers that would benefit lots of customers that they're all asking for that you can build and you should prioritize those? Okay. Okay. Is there one thing from that build perspective that is better?
I mean, is there something that— what's that driver? If you've got 1,000 problems and 1,000 bugs and 1,000 features that you have to put in, are you solely relying on your engineering team? I mean, I'm assuming that at one point your engineering team is going to have to consolidate those up and bring those forward to you, right? So that they, you know, where the capacity is. Is again that secret keyword that's going to make you say this is where I want to spend the money and the effort.
I think every business is going to have different metrics and how they evaluate that. I mean, we really look at it across a couple things, but the most obvious is, is this a bug/feature request that is being asked for by the largest number of our customers and prospects, the people that have the software or the people that want to buy the software? And I mean, and that's again, that's pretty, that can be done in a spreadsheet. Obviously it gets harder the more customers and the more features you have, but generally that's how you're thinking about concentrating your energy from a product innovation perspective. And then you also have to be kind of, you have to balance that with where the market's going.
There's the things that customers are asking about today and they're generally, you have a few customers and users that are canaries in the coal mine. They're kind of seeing around the corner a little bit for you. It might be because of the type of environment they're in, the data they deal with, the skills of their team. And they're kind of giving you indications of where the market is going. And, and sometimes if you hear a clear signal from a few of those and it's the same, you listen to that.
That's a little bit louder signal than just I'm hearing this from, you know, one or two people. But if you're hearing it consistently across some of your kind of key customers, that sometimes can give you insight into what's important to prioritize. Okay. Well, we've been talking so far about features and new features and getting better and using things like AI, being idealist or being innovative, right? But as we move forward, and generically again, in, in a site, in any company in the cybersecurity realm, we're always looking forward.
But why do you think many organizations fail at the basics even if they have these multimillion-dollar budgets?
I think it's— the job is hard. And, you know, and the thing that about— I spent a portion of my career doing pen testing. And the thing that I realized in doing that is, as a pen tester, I had to be right through kind of one attack path at one moment in time. Right. And that path might be, you know, secure today, vulnerable tomorrow, just because of patch level or vulnerability disclosure or whatever it might be.
So in doing that, I realized really the hard job is from a defender's perspective because you kind of have to be right all the time across your entire landscape. And that's a really difficult job. And I think that that's what makes the basics hard is that any, you know, if your job is to secure your laptop and you're, you know, a technical person, you can probably do that because you can keep it patched. You can make sure you're at all the updated applications. You can You know, take your— you can make your allow list for your processes super tight, like, but as every time you add a node to your environment, the shifting nature of that just exponentially makes it more complicated and more difficult.
I just, I think the modern environment is very complex because it's moving very fast. I mean, I think the increase in number of CVEs reported year over year just goes up by, you know, triple-digit percentages every single year. That You know, multiply that by 100,000 endpoints and 200,000 cloud nodes, and all of a sudden you've got like a ridiculous problem on your hands. Like, that's really hard. Mm-hmm.
1,000 CVEs, one engineering team. CVE roulette. Why the basics fail at scale. So if that's a problem, right? If you're, you know, again, we know your position here, but If you were, you know, the CEO of IBM, of, you know, big giant Fortune, you know, 100 type companies, how would you suggest fixing that?
I mean, again, from a CEO, obviously from a CEO's perspective, CVEs are just one very small thing that you have to worry about. Oh yeah. You have hunt on IOCs, you have security alerts, you have phishing emails, you have configuration issues, you have vulnerabilities. Like, your life is a litany of signal. I think, you know, and I have founder's bias, right?
So I think a lot about Swimlane and what we do and things like, I do think for my entire career, we've always had either a budget restraint or a talent restraint. We just couldn't get enough people into the organization to do the amount of work that we had to do. And I think we are starting to see the glimmer. I don't think AI is a panacea. I don't think it's gonna solve every problem tomorrow.
I think that's an unfair characterization. But inversely, I do think we're starting to see a way to really superpower the people that are on your team by allowing them to leverage AI and agents to do more work than they've ever done before. And I, I do think that's something that you, you, you, I don't know that you dive headfirst into, But you should start wading into now because it's accelerating. The tooling is getting dramatically better and the infrastructure that— the speed at which it's going to impact infrastructure and the velocity in which it's going to allow infrastructure to expand, both from an ownership perspective as the steward of an enterprise, but also how it's going to be leveraged from a, you know, a campaign, attack campaign perspective, is it's going to accelerate. You probably need to start wading.
You can't just sit back and see what's going to happen. You got to start figuring out how you're going to leverage it to your advantage. Well, I mean, and actually, you know, people that listen to this podcast are mostly concerned about the security part. But where I wanted to really get your unique perspective is that you have, let's say, for example, I'm assuming a board of directors, right? I do.
That you have to please. And the board of directors probably are more concerned, or at least have other concerns besides security. What other things are those drivers? I mean, when you are balancing and I say we've got 1,000 CVEs, but you also got to please that board of directors, you've got customers, you've got obviously ultimate control over the budget. What again drives that decision in a day-to-day basis as in a company in general?
Yeah, I mean, I absolutely have a board of directors. Investors, you know, they're financial actors. That is their kind of biggest and most important kind of element of the business. Thankfully, we work with investors that are also, you know, they understand security and they understand the value of security. That's why they made the investment they did.
So, you know, we're kind of uniquely positioned where if I ran a grocery store chain, that might be different because they might not have that appreciation. So, you know, for us, yes, they're financially motivated. But because we understand security, we're a security vendor, we can also kind of position back the business element of that. Our buyers are security practitioners. They value security.
The security of our product and our services is directly related to the likelihood of them procuring them. So for us, I would say it's actually slightly easier to justify security investments than it is probably for your standard brick-and-mortar business or, you know, businesses that are not aligned with the cybersecurity industry. Just because the value proposition from a, you know, an investor's perspective or a board's perspective are not so tightly correlated. Okay. How would you feel about something about the glass house, like strategic governance versus this glass house, right?
How do you sell boring governance work to a business? I mean, from— and again, it depends on which industry you're in. And I would keep coming back to it. But if you're a product in any software supply chain, cybersecurity is a business enabler. You know, now if you sell physical goods, I don't know that industry as well.
I mean, if you're selling to the federal government, the whole kind of CMMC and SBOM, you know, supply chain stuff becomes very important. So security is a business enabler there. But in the technology industry, you know, you're part of a, you know, either a stack of technology or part of a bill of materials. That generally security is an element of the procurement process and the renewal process. And so, you know, I think, you know, for us, that's obviously what makes it important.
Okay. Well, let's shift a little bit here and kind of go back to something that we just touched on. Every podcast, this obviously is the hottest element, is the AI hype. And you did mention something here that I think is different from other people that I've had on the podcast before where, you know, most of them are like, AI is gonna solve all our problems. AI is gonna do this.
AI is gonna do this. And I think, at least to my recollection, you're the first person that I've talked to on this podcast that sounds like, eh, right? You know? Yeah. I am definitely not meh about AI.
I think it is transformational for what it's gonna do to cybersecurity and the technology industry. What I think people need to really think about is how do they leverage it in a way that they're actually gonna get an outcome they can afford? You know, one of the many things that we spend a lot of time talking to folks is, you know, where does automation stop and where does AI begin? Because the outcome of both of those is really how do we get more done with, you know, the same or, you know, less effort? And automation has been doing that for a long time for a lot of industries, including cybersecurity.
And, you know, obviously AI is changing that. What we're seeing is that a lot of people want to just take all of their problems and kind of spread AI all over them and they hope that they go away. The problem that we see is the predictability. So hallucination rates, the latency, the speed, volume and scale of the scale of data that you can process and just the kind of the, the guardrails that are associated with getting things done at scale, right? So if you're a, you know, again, our customers are generally really big organizations.
They're triaging millions of signals a day. So even at low hallucination rates, you're talking about lots of errors. So that's not acceptable. So the trick is to really balance automation and AI. Automation is really great at high speed, highly predictable, low latency, and is very cost efficient.
AI, you can do the same thing with AI, but you're doing it all with tokens. And tokens are exponentially more expensive and less predictable. So the trick is, is how do you do more from a deterministic perspective where you can get a lot of volume and a lot of scale in the places where you typically would have to inject humans into the process because that was not an easy if-then-else, or does this contain or does it exceed this threshold decision where you need some more. Generally, you would throw a person into that spot. Now you can throw an agent into that spot.
That can use non-deterministic logic, can use reasoning, can use historical examples, and can build a decision for you that over time you can learn to trust and test and trust. And because of that, the aperture of use cases that you can support is so much bigger. So I, I think AI is gonna be a watershed change in cybersecurity. I just don't think you can just AI everything right now because it's very cost prohibitive for a lot of problems people are trying to solve. Okay.
Well, let's handle that 800-pound gorilla in the room, right? Will AI take our jobs? And we've actually seen this with what, Facebook and CrowdStrike, right? I mean, I think earlier last year, CrowdStrike laid off what, 5% of their company? And they actually were very blunt about it.
They said AI was responsible for that. Facebook laid off what, 600 people all in the AI department. Well, do we, you know, do I have to go pick up a new skill of becoming a lumberjack or something like that just to be able to survive in the world because my job is now going to be taken over by the robots? Right. I don't think so.
I, I think— and I don't work inside of Facebook, I don't work inside of CrossRock, I don't, I don't know how they make this— there has been an immense amount of pressure on technology businesses over the last, probably since really since the peak in 2021, when multiples and all these technology companies were flying high, the world has changed pretty dramatically. And with that comes a lot of pressure, especially from investors, to become more efficient and to reduce their operational expenses and to cut costs. And when you do that, these businesses all have a marketing department, they all have PR, What's the reason why you just laid off a bunch of people? Because you're trying to cut costs or because we became much more efficient with AI, which sounds better. So I can't speak to any of those announcements, but I think sometimes what is said and what the real rationale for reducing headcount inside of a business can be very, two very different things.
I mean, at the same time that Facebook was laying off folks and saying it was AI, they were also getting immense investment. To get more lean. So I don't know, you could argue either side of that. I don't know. I wasn't there.
I wasn't the investor. I wasn't the executive that made the decision. I wasn't in the PR department. I don't know why they did that. Right.
But I think like anything else that's, you know, kind of managed from a public relations perspective, there's elements of all of the above. But on the AI element, I think because historically we've had a talent gap, and because we're going to be able to do more work and because there's going to be more work to do, I actually think for the foreseeable future that we're going to need more cybersecurity people that are AI savvy than we are going to need less people to do the job. Okay, well, and that's good to hear because the thought of me holding a chainsaw is not a good idea. I mean, it's almost like the inverse of Texas Chainsaw Murders because I would hurt myself more more than anyone else here. Um, but let's get into things like, uh, more gratifying than running a chainsaw.
It is a pretty fantastic feeling. Is it? Well, you had some experience in that, right? I mean, I just kind of go outside here. Yeah.
So, yeah, I mean, as you mentioned at the beginning, like, I volunteer with Team Rubicon, and Team Rubicon is a— it's a veteran-founded organization that is for folks that want to volunteer mostly for disaster response. It's both veterans and, you know, non-veterans, civilians that want to go participate. So the organization started after the big disaster in Haiti, but you see it after hurricanes, be it Katrina or otherwise. The Team Rubicon folks will go in and do a lot of disaster response. So they'll clear down trees and they'll help people clear out the houses and tarp roofs and they help clear the roads so they can get, you know, more and more vehicles down the interstates.
And there's a lot of work here in Colorado where I live. We do a lot of fire mitigation. So we go up into the mountains and we do fire mitigation. So we're, you know, mostly it's elderly folks that live in the mountains that, you know, can't afford and can't probably do the labor associated with, you know, clearing vegetation and trees from around their houses. And obviously forest fires, and our weather is crazy this year, so I'm a little nervous about what the spring is going to look like.
So yeah, that's what we go do, and it's a lot of fun, a lot of camaraderie. It does remind me of being in the service where You know, you're out there, you're doing work, and running a chainsaw is really fun, especially when you get to help somebody out and, you know, help somebody around their house. And yeah, it's fun work. Satisfying. I like that.
I mean, being able to help people, it's one of the reasons why I help run the OWASP Foundation, or at least not the foundation, but the Denver chapter here. But I actually do have something here, you know, trying to get back because, you know, one of the things that I do is I do a lot of entry, you know, or helping out the entry-level people. For mentoring. I teach at the universities. What advice would you give to my students, the ones that are just coming into the cybersecurity realm now?
We talked a lot about AI and trying to become more AI savvy. Is there any skills or anything else? I mean, you know, I gave a talk at the University of Michigan last year about the 4 realities of becoming a cybersecurity professional. What I'm asking you is, how can you help me enhance that talk? What is the one thing that you at the very top level says I have to have in a new person that's working in cybersecurity?
You know, this conversation, and if I wish I had a crystal ball, because I think it's changing quickly. If I were to go back a few years, you know, one of the things that was definitely different when I started in cybersecurity, one, it was there wasn't specialties. It was just like you were in security. So, you know, you did, you know, forensics, you did vulnerability scans, you triaged security alerts, like you configured firewalls, you did all of the above. And then obviously, you know, I don't want to date myself, but that's going back to like the early 2000s.
As obviously over the last 25 years that we've special, you know, the specialization within security has become immense, right? There's lots of different niches and specialties. And I think if I look back, one of the things that definitely happened is You know, we went from like configuring tools and understanding how like, you know, network topologies worked and all that fun stuff to really becoming code, right? Especially with kind of cloud. So like the software development skills became, you know, very important for, I think, an effective cybersecurity practitioner.
And I don't think that's different, but I think the tools they have at their disposal now with cloud code and with Cursr and things like that are starting to kind of change that. And I don't know if it's a full circle moment. I don't know if that changes it from being less, you know, like coding and, you know, building Terraform scripts and things like that to, you know, being more of a prompt engineer with something like Cursor. I can't see the future. I don't know.
But I do know that it's changing. And the things that are, that were probably really critical, you know, 48 months ago from a skills perspective, are changing and they're changing fairly quickly. And I think you should think about that. Like, I think a strong foundation in computer science, I think, you know, all the soft skills that, you know, people always talk about, you know, can you show up for work on time? Are you willing to work hard?
Can you talk to people? Do you have critical thinking skills? Can you collaborate with other people? Like, those are always gonna be important. But I think the actual technical skills are evolving fairly quickly right now.
And It would be a great roundtable. I don't think I know the answer. I wish I could say this is what it's going to be, but I think predicting the future right now is really hard. Yeah. Yeah.
Well, and I think it's like you said, it's always constantly changing the needs of the business. I know I put you almost in that pretty much impossible question.
So now I'm going to actually, you know, unfortunately for you, I'm not sorry about it because I'm going to ask you one more impossible question, the one that I always end up with. What is the biggest challenge in cybersecurity today? Now, I'm not asking you to solve it. I'm just asking you to identify what it is. The biggest problem in cybersecurity today.
I don't know that I could put if it's any one thing. Okay. I think right now it's There's so much that— what do they say? History rhymes.
I think that's what we're about to see right now. We have all— we're developing this new era in technology. And anytime we went through, if it, you know, we went from servers to virtualization, you know, virtualization to cloud, the implementation of mobile, you know, web app. Every time we go through these big, we almost have to go back and go, we always learn the lesson too late. Like, you know, is it secure by design?
Are these things, you know, being secured from the, you know, from the outset? Is security important as part of the initial build and design of these products? But I think every time we do this, we find out that unfortunately the commercial ambitions of the change outpace the security understanding of the change. And I think as this stuff becomes baked into every single application and device that you use, we're going to very quickly realize the security ramifications of that. And what, you know, I think that is just, we're going to do the same damn thing over again.
I think that's inevitable because the economic opportunity that is available for AI is tremendous and we're running at it really hard as an industry. You know, I'm not talking about cybersecurity, I'm talking about technology in general. Like valuations of these businesses are just tremendous, and they're just accelerating at this crazy rate. And because of that, they're going to move very fast, and there's a lot of stuff that's going to be left in the wake. It's going to be easy pickings for threat actors, unfortunately.
Okay, so we're going to repeat, and honestly, we almost went back to, uh, what we were talking about earlier, is we're being— we're missing the basics. We're missing some of those basics. And yeah, yeah. Okay. And the base, and maybe they're doing the old basics well, but are we doing the basics on the new stuff?
I mean, these, these things are black boxes. A large language model is an entirely black box. It's an unpredictable thing. It's a next token. I think there's a lot about that we don't understand.
And I think because of that, and that we're trusting it to do more and more things in our lives, that There, there's going to be a new, there's going to be the new basics. Unfortunately, they're going to look a lot like the old basics, but they're not the same. So we don't, even if we're getting the old basics right, there's going to be some new basics that we're probably missing because of AI and other things, right? Yeah, exactly. Yeah.
Okay. Well, any final thoughts? Because we are at the end of our time. Any final thoughts? Anything, any wisdoms that you want to give out to the podcast listeners today?
I don't know. I, I get a lot of questions on, you know, how do I transition from being, you know, a security person to working in business? And that can mean, like, moving into the business element of the organization that I'm working at, moving into the vendor and product community, or starting my own business. You know, I, I think that is— it's always a really interesting conversation. I think there's more opportunity than ever for people to do that.
Again, you know, with AI, the things that you might not have been able to do yourself, You know, a lot of people are looking for a technical co-founder or for someone to kind of help them, you know, give them more capacity to achieve some, to solve some problem either in their business or in a new business that they've always wanted. I think now is a very opportune time to go and chase that. I'll admit as a founder, you know, if I'm a hammer, everything's a nail. Is that the cliché? I think solving, solving a business and going out and building something yourself solves a lot of problems.
But that's because that's the worldview that I have and that's what I get excited about. So it's probably not for everybody, but inversely, I think there's a lot of opportunity in the world right now that people can go pursue. And, you know, I think cybersecurity is going to be a really interesting market for a long time to come. And, you know, I would encourage people to go and think about how they can make their dent in the cybersecurity industry. Yeah.
Well, I mean, that's why I was actually asking earlier about the unlearning part, right? Because you were an architect, obviously very technical. And now you're a business, right, person, and you made that transition. And maybe it's, you know, what was that driver to make you successful? Because obviously you are successful.
So what, you know, what could we learn from you? Right. I think the one thing that was very interesting for me, especially really early in building Swimlane, was that we were in a brand new product category, which was you know, automation or SOAR that didn't have a name. Gartner hadn't given a name, Forrester hadn't given it a name, but we were living in a world where we were trying to solve this problem every day. And I think the people that do this job have such a deep level of domain expertise and such a clear understanding of what makes their day hard and what things could be done better that there's— those people are most uniquely enabled to go and build something and create something that will solve that problem.
And that could be an open source project. That could be a, you know, serving at an advisory board at a vendor and helping them design something. That could be going and starting and trying to solve that problem yourself. But I think, you know, I spent 7, 8 years triaging security alerts and I knew there was a better way to do it. And being just kind of fed up with what I was doing and how unsatisfying that job was.
And how many people, like good people, I watched quit to go do other jobs. Park rangers was always the funny one. A guy left, decided to be a park ranger because he was just sick of it. It was just like, this isn't fun anymore. I'm just doing the same thing all the time.
So that digging into that problem, and because you know it so well, I think it's something that folks that are doing the work every single day are uniquely kind of able to do. All right. Well, hey, Cody, thank you for your time. If you do want to, you know, reach out to Cody, talk to him, he's out on LinkedIn under Cody Cornell. Uh, of course you can also go out to swimlane.com.
Again, thank you for your time. My name, of course, is Frank Victory. I am the president of the Denver OWASP chapter, instructor, podcast host, etc. You can also find me on LinkedIn and our upcoming conference, snowfrog.com. We are filling up.
We're going to have a 2-day conference this year for the first time with some really cool stuff of electronic badges and some lock picking villages. And of course, the totally awesome and local person here, Jason Haddix, giving out a class. Again, thank you again, Cody. Appreciate your time, and I'll talk to you later. Thanks, Frank.
Really appreciate it. Thank you.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.