Behind the Shield
Behind the Shield is InfusionPoints’ podcast where we sit down with partners, customers, and industry leaders to talk about FedRAMP, compliance, and cybersecurity in today’s government landscape. Each episode offers laid-back, insightful conversations that blend expertise with real-world experiences.
Behind the Shield
Identity, AI, and the Future of FedRAMP 20x with Matt Topper
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of Behind the Shield, Gary Daemer sits down with Matt Topper, President of UberEther, to discuss identity, FedRAMP, FedRAMP 20x, DoD cloud authorization, AI, and what it takes to build secure platforms for highly regulated environments.
Matt shares UberEther’s approach to helping agencies and SaaS providers solve identity and access management challenges while accelerating authorization through inherited controls, private tenant environments, and secure platform design.
Gary and Matt dig into the realities of FedRAMP, FedRAMP 20x, and DoD Impact Level 5, including the “easier button” approach to authorization, the ongoing complexity of audit logging, FIPS validation, cryptography, access control, POA&Ms, and application-level security.
The conversation also explores how AI is being used in compliance and security workflows, from crypto discovery and audit control review to POA&M analysis, vulnerability noise reduction, log correlation, and security operations.
They also discuss change management, sponsor requirements, SCNs, agency expectations, and how FedRAMP 20x is shifting the conversation around certification, authorization, inherited controls, automation, and faster paths to assurance.
Later in the episode, Matt shares the story behind UberEther, his approach to company culture, growing without outside funding, and building a people-first business focused on long-term value.
What You'll Learn:
• How identity and access management shape FedRAMP and DoD cloud security
• Why DoD IL5 and FedRAMP 20x require both technical depth and process discipline
• How inherited controls can help accelerate authorization
• Why audit logging, FIPS, crypto, POA&Ms, and access controls remain major challenges
• How AI agents are being used to support compliance and security workflows
• Why change management can slow innovation in regulated environments
• How sponsorship impacts the federal authorization process
• Why non-person identities and AI-connected systems create new governance challenges
• How Matt thinks about company culture, long-term growth, and building without outside funding
Chapters:
00:09 Intro
01:19 Platform overview
02:58 Building for government needs
08:27 AI, audit, and FIPS
20:28 FedRAMP 20x and sponsor blocking points
20:56 Virtual ISO services
32:25 Future of the company
46:37 Big services company
Books & Podcasts Referenced:
• Traction by Gino Wickman
• Another Way by Dave Whorton
• The Ideal Team Player by Patrick Lencioni
• Multipliers by Liz Wiseman
• The Identity Jedi Podcast with David Lee
Guest Links:
Matt Topper: https://www.linkedin.com/in/matttopper/
UberEther: https://www.linkedin.com/company/uberether/
https://uberether.com/
Learn more about InfusionPoints:
https://www.linkedin.com/company/infusionpoints/
Gary Daemer: https://www.linkedin.com/in/infusionpoints/
Request a Demo: https://xbu40.com/
FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment
InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.
About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.
Welcome to another episode of Behind the Shield. I'm your host, Gary Damer, and today on the podcast we have Matt Topper from Uber Ether. Matt's been in cybersecurity for many years and uh has been a stalworth in the FedRAP community and the DOD cloud community uh for just as long. Matt, how about you give a few minutes and uh tell us who you are, what you're about, and what do you want to get out of this podcast?
SPEAKER_00Yeah, absolutely. So thanks for having me, Gary. So as Gary said, Matt Hopper, president of Uber Ether, been uh dealing with all the FedRAMP, DoD, and around all of that identity and access management problems for the last 15 plus years at Uber Ether and ran Oracle's national security group's identity and access management teams before that. So um I like to say I'm not very good at my job because I feel like I'm still solving the same problems 20 years later.
SPEAKER_01I was I always like to say that they are the exact exactly the same but completely different, right? They're at different scales and uh uh different uh um uh avenues for how you actually solve those problems. How about uh you spend a few minutes and talk about your platform and what your platform does and how it really is protecting identity uh throughout uh the Department of Defense and also in the FedRAMP space?
SPEAKER_00Yeah, absolutely. So about four years ago now, we got tired of watching a lot of those big integrators come and spend 12 to 18 months to get through the ATO process, if they're lucky, um, when they're repeating the same playbooks over and over in the federal government, and said it makes a ton of sense to put together a bunch of the uh identity and access management products that both run in a SaaS environment as well as on premises, pre-integrate them together, make them actually work from day one so that when the government buys it, they can get right into solving their business problems rather than waiting 12 to 18 months, paying two cycles of um right licensing with those customers before they even see their first applications integrated. Uh so we decided to go the hard path and take FedRAMP, skip FedRamp High and go straight to Department of Defenses and Pack Level 5. Um which is not for the faint of hark.
SPEAKER_01No.
SPEAKER_00As I like to tell people, it is the last, it's the highest level of security before they leave the internet and the DOD. So you can imagine the type of workloads they're trying to save and um protect on that side. So um as we went through that, we built it as a private tenant environment. So there's shared nothing between each of our customers, which is how the DOD likes to see it. Um, private encryption keys per customer. And as we were going through, um Jackie, who runs their board, was like, this is how we've been begging people to build solutions for us. Can you start doing this for others? And at that point, we continued down our identity path with our IM advantage product, but also introduced our ATO advantage product, which is where we help SaaS vendors get into the DOD or get their FedRAMP certifications much, much faster because we get 80% of their controls, all those boundary controls done for them the same way we did for the DOD.
SPEAKER_01So do when you do that, do you um do you pull them into your boundary um and then and and they become a part of your ATO? Or do you make them go through and get their own ATO as well?
SPEAKER_00So we have both models, one we call Express Advantage, which is where we extend them within our own boundary. Um and then our ATO Advantage product is the one where they go and get their own. But right, I like to say we get about 37% of the controls from Amazon or GCP, right? Those are the two platforms we run on top of. And then we get them up to a total of 80% with all the other boundary controls, all the identity and access management controls that we put in place. We take all uh, we give them like private Amazon workspaces so they don't have to bring their corporate laptops into the boundaries, protect those with PIV cart, basically piv's on a Yuba key versus a phyto token. And then from there, they're really just focusing on the audit controls and then the application level controls for their products. So they inherit from us the same way they would with the CRM, the same way they um inherit from AWS, and we just get them that much closer to done.
SPEAKER_01So, you know, I like to hear a lot of people say it's a it's an easy button, but what I like to call it is an easy err button. Maybe you can explain that a little bit as well, because I know you know I'm sure you feel the same way we do. This stuff is still very complicated, even if you inherit a lot of the controls.
SPEAKER_00Yeah, it's it's amazing how many companies we've worked with where we're like, wait, you don't have audit logs for that already? Or like you don't even know where your crypto is to even start telling me where it's FIFS compliant or not. Um so the easier button is honestly the exact same way I term it with them as well. Yeah. Um so yeah, like what we've done is said if you get your own private tenant account. If you run multi-tenant, great. If you run single tenant in there, we just X number of accounts out for you as you as those customers grow. But right, do all of the artifact controls, all the PoM controls for them, all the monthly reporting so that they're really just focused on deploying their application securely within the environment.
SPEAKER_01And enable them to uh build on their specific functionality and not have to worry about all those underlying you know general controls. Um Exactly. So and then uh do you work uh you know with DISA and the agencies to make sure that they get their uh authorization as well?
SPEAKER_00We do. So we will help White Glove all the way through the final recommendations. We work with a couple three PAOs that they've been it's been a great marriage, right? Because they understand our platform already and they understand where those control points end. So they really know, okay, we just have to focus on that last 20% every time, which so the customers they like it too, because it we actually allow it to bring the price down as well at third party. Right at the end of the day, it's pricey too. So yeah, exactly. But but it de-risks that whole part of it that you're not trying to fill that 37 to 80 percent gap that they would have to do if they were doing it on their own. Right. Um, right. There's accelerators out there that do that, but when you don't even have to reassess those controls, right, is really where the power has come in with our platform and bringing people on board.
SPEAKER_01And and then you can really help them with um helping them figure out what that last mile is. What does that requirement really mean when they say X, Y, or Z? You know, what are some of the toughest, tough, toughest controls uh that they that they work on, uh, or they have to work on themselves, uh that you see?
SPEAKER_00Yeah, a lot of times it is the identity and access management controls, which for us is great because that's our bread and butter. Right, exactly. So um really easy to get in there and say, okay, no, you want to do this, or here's how you delegate that off to the agency and let them fulfill the controls. Um, but it it always comes back to the audit controls, the identity, the access controls, the audit controls, and then still those FIPS controls.
SPEAKER_01Yeah, uh, for me it's it's it's usually the crypto ones, and and and I can echo back exactly what you're saying is cryptoware. I have no idea what oh well we're using 16 different libraries as we build our build our application. Okay, well, we maybe want to reduce that to one or two, and they all have to have FIPS on it. And the other one is is logging that I find uh to be some of the hardest. Um, because they that they might have some limited um observability logs, but not really a lot of security logs. Uh you know, not the ones that they really need to have in order to pass uh the IL four or IL5 audits.
SPEAKER_00Uh yeah, we actually um just released with our customers, we wrote specifically AI agents for those two areas with audit and with FIPS, where we say, take these agents, and we've got them running across most of the major platforms at this point, and run them against your code base. And it'll at least generate out a report of by language, here's where we found all your crypto that's going on in here. By audit control, here's where we're finding what you're missing where, so that they at least get those reports from their actual source, where things are going to go. And that's been one of the great parts of using some of the AI capabilities that have come out in the last 18 months.
SPEAKER_01That's a perfect segue. Um, how about how about we talk about uh how you are using AI uh in either a production environment or in the in the SDLC process, you know, your pipelines and whatnot, uh before it actually gets into the environment. Maybe you could talk about how, where, and and maybe even a little bit of why. That would be really insights.
SPEAKER_00So um being DOD IL5, uh it's taking us a while to get through the approval process to use these in production uh right now. But hopefully, fingers crossed, uh it's it's been in for over six months at this point. So hopefully, fingers crossed that approval comes through that we can move some of these agents into prod. But really from the beginning, we're helping the customers like through the CI CD process. When we run the POAMs every month, we'll look at the POAMs that come out and generate statements for them to say, yeah, this is really vulnerable in the tool, or it's not vulnerable in the tool. Look at their source code and say, oh, that vulnerability says you have to have access to it from the front end. Nope, yours is only a back-end library. It's never exposed to the customer, so it's not directly exploitable, and help them through a lot of that poam process of writing up. Um I think we both know writing those poam responses is more of an art than it is science.
SPEAKER_03Yeah.
SPEAKER_00And um, you're trying to explain what a lot of times are really complex topics of, well, this library is vulnerable, but it right, in our instance, it's not vulnerable because blah, blah, blah, blah, blah, blah, blah. And trying to make somebody explain that or explain that to somebody who's looking at somebody else that says, no, we are actually vulnerable to this, and years our path to fix it, and why both are okay.
SPEAKER_01Correct. 100%, 100% agree. Are you using it for any kind of like false positive analysis or anything like that as well? No, we're not at this point.
unknownOkay.
SPEAKER_01That's something that we're actually exploring right now, is leveraging AI to do some um some true, false positive analysis. Because I don't know about you, but we find that there's a you know, there's a ton of noise out there in the vulnerability community in this space where you can get, you know, half of the vulnerabilities that they find are just they're they're mislabeled for some reason. I don't know, I don't know what's going on, but it seems like there's a lot more of them here recently uh as well. Maybe it's ever so slightly you know different, or the NVD database is not quite, you know, in the right formats or something, but there's some some some issues that I've seen with a lot more false positives, and we have to do a lot more false positive analysis. We've not been able to figure it out totally because we're using AI in the same ways that you are, but we're trying to figure out more and more every day how can we use it for more?
SPEAKER_00Uh in that yeah, I think with some of those NIST gaps that happened in the last year with the people on the teams not being funded to continue doing their work. Yeah, right, that hurt a lot. And then um the other thing I'm noticing in the community in general is a lot of companies are pulling out of the um like vulnerability programs where they pay bounty programs and stuff. Okay, but bug bounty, bug bounty bills. Because so many of the submissions right now are from AI generated tools where people are looking to pick up a quick buck and they're getting overloaded with all these false positives where people are just trying to look make a quick buck somehow, and somebody goes, Oh, yeah, that really is a vulnerability. Here's three grand, five grand, ten grand, whatever it is. And I think that's really diluting a lot of what was good work going on previously. Got it.
SPEAKER_01And and even if they are a bug, are they really exploitable? And if it's exploitable, it can you do anything with it, yeah, once, you know, once you once you have a hold of it. It's been my f it's been my philosophy. We've I've been doing this for uh eight, it feels like eight million years at this point. Um but yeah, a lot a lot of times, a lot of times it's very difficult to see what it what what vulnerabilities are really of value, even though they get labeled as a high or a moderate. You know, I'm wondering if the calculations are the C VSS score is slightly off on those as well.
SPEAKER_00So yeah, I always love the ones where yes, this is a 9.5 or above, but you've got to have root on the box to exploit it. And you're like, you got root on that box, you're already screwed in so many ways, anyway. So like yeah, right.
SPEAKER_01Or you have to have physical access to the firmware. Okay, right. I'm kind of in a VM world way. So why does it why is that not a false positive? You know, and why can't you recognize that scanner as as as that as well? You know, it's a VM. So these 14, you know, uh um vulnerabilities don't even apply. And that's the kind of false positives I'm talking about right there, more than anything, is the ones that they have to have actual access, you know, to the physical, a physical physical box, which is like, okay, well, I don't either. So I doubt you really will either. You know. Yeah. And if and if they do, we're in a lot more trouble, right? We're in a lot more trouble than than uh just a vulnerability in the software that you only can access through the serial port in the back. So Yep, exactly. So how about um I know you I know you're in the uh IL four and IL5 space and the FedRAMP high space. Talk about you know, you know, the challenges you know that you that you go through on a day-to-day basis, week-to-week basis, and kind of planning perspective uh about you know around building you know for your customers and then also building for yourself in these environments, change management, approval processes, you know, um uh change notices, um, change requirements, you know, who has to approve that stuff before you have to change an OS in your environment. You know, talk talk about those kinds of challenges, if you wouldn't mind, for a few minutes.
SPEAKER_00Yeah, it's um it's difficult to say the least. Um the DOD changes, since we're DOD sponsored IL5 first, all of our significant changes have to go through there. So a lot of people are jumping up and down happy, where it's we've gone from SCRs to SCNs on the FedRAMP side, and I'm just sitting there going, yeah. I think P. Waterman said a week or two ago that like only 18% of the approved have gone through and moved to this SCN process, and he thought everybody would try and move to that. But I think at least from what I've seen, a bunch of the agencies are pushing back saying that's nice that FedRAMP said they're gonna do SCNs, but you're still gonna do SCRs with us if you want us to continue to sponsor us.
SPEAKER_03Right.
SPEAKER_00And um, at least on the DOD side, they haven't even addressed that change at all. Their attitude is no, it's gonna be an SCR and we're gonna have to. I mean, like I have just said, it's six months for a change to open us up to use. We're already approved for GCP access and running workloads on GCP, but we wanted to open up to the vertex AI capabilities that are over there. And we've been six months waiting for that functionality to turn on. And we use GitLab as a private hosted inside of our environment, and inside of there they have something called Duo, which allows you to do code reviews and some additional checking that we've had great great, great response within our dev environment where we can use this already. But we're just like itching and waiting to give that to our customers inside of the boundary. Um, but yeah, especially OS changes. Uh, we've got customers that'll come in and say, hey, I'm using ChainGuard hardened images. And right play I will I'll say a game, but it's not really a game. Okay, well, ChainGuard is technically Debian based. We already have Debian approved in the environment. Here's how it's the same or different. You've got to write those things up, and hopefully your approver inside of the DIS aside goes, yeah, that's pretty much the same. You already have Debian approved rock and roll, or nope, that's gonna be an SCR. And sadly, right now, a lot of times it's just depends on who you have on the team rather than having set hard rules on it. Right.
SPEAKER_01So do you think it's slowing your innovation down then for for changes? Uh you know, it's definitely six months in today's six months in today's world is it's a lifetime, in my opinion. Yeah. The the whole marketplace has totally changed over the last few years with AI and you know what what AI can do in these environments.
SPEAKER_00Yeah, it it definitely has slowed us down and continues to slow us down. It's one of the reasons we're actively right, we've got uh I I've flipped my brain to the uh ADCD levels of FedRAMP now. But as the D level, which is the new version of high essentially, is coming out, we're gonna go forward and do a D that we can do more rapid acceleration on, more rapid changes on.
SPEAKER_01Um not just a FedRAP high on your current system, you're gonna roll out a whole other environment just so you can you can maintain um and move a little faster.
SPEAKER_00Yeah, so we'll we're actually gonna keep it in the same environment, but it'll be a 20xD in that environment because of the way we handle our tenant accounts. We can say these are 20xD accounts that are being generated versus ones that meet the IL5.
SPEAKER_01So your underlining support infrastructure or management plane will stay in the IL5 space, and then you'll have an individual accounts for your FedRamp High uh perspective. So you can change things that's inside your FedRamp um high accounts, but just not in your man management plane yet, right? Is that correct? Okay.
SPEAKER_00Yep.
SPEAKER_01Makes sense.
SPEAKER_00So that'll hopefully let us accelerate a little bit faster, be able to use the SCN process with our customers that are using that. And then um, I know the DOD is going through some changes and revamps again and trying to figure out what they're gonna go um make some changes. Lawrence is leading that up internally. Um, so hopefully they'll start to drill out a little bit here in the next couple months.
SPEAKER_01So, how do you, you know, how do you see, you know, that uh helping or hurting then in the build space? I mean, do you have to make or or do you have to do uh SCNs to add new accounts in that environment as well?
SPEAKER_00No, they let us go ahead and deploy new accounts anytime because of the patterns we've established when we roll those accounts out, as long as we're following our same CI CD deployment processes, we're heavily Terraform based. Um as long as it's those same baselines that roll out to those accounts, they let us generate them anytime. Okay, good. So you've already got that approved in your in your boundary then. Yeah, and that otherwise that would kill us, right? We'd sign up a customer and it'd be three to six months before they'd even be able to get started. That'd be a a death march. Yeah.
SPEAKER_01Yeah, that would be, unfortunately. Uh and it like you said, I think it really depends on the reviewers and how they how they ascertain that as well. So how about what do you see from um you know, from individual companies? You know what what are the I know we talked about their biggest challenges, but uh just getting the ATO itself, not from a technology perspective, but the process perspective. I know you I heard you say you you you do the the white glove treatment, but they also have to be able to survive the audit and they also have to be able to survive talking to uh the review board and and the JVT and things like that. Or do you shield them completely from that?
SPEAKER_00So we will provide virtual ISO services for them, where they'll subcontract us to be their ISO for their services. So we get to sit at the table with them a lot and have those discussions, which helps um, right? A lot of these companies don't they've never gone through federal government ATOs before, and having us there to be able to do that, and then we'll also give them partial as part of our services uh engineering resources on a monthly basis. So sometimes they don't even have U.S. citizens that can roll out the software.
SPEAKER_01We deal with that, yeah, we deal with that all the time because most of our companies that we help through this process are usually really large companies with multiple business units, and they have uh um employees all over the globe. Uh, you know, so I could be on the calls at two o'clock in the morning with folks overseas somewhere. Yep. So they can't have accounts in this system, so you know we end up having to you know manage those and do release management and that kind of stuff as well in environments.
SPEAKER_00Yeah, we're doing the same thing for a lot and Doing late night screen shares and same type of thing to get through. But I I still one of the biggest challenges still is the sponsorship angle. Yeah. That's what we keep seeing. Like we're we've been really successful getting through the audits, helping them through. We've got a pretty good process of doing the SSP documents. We're big Ramify um users. So we love that tool from a documentation perspective, getting the SSPs done and like getting through that side of the process. But the sponsors just if they find one, maintaining them through sometimes the six to nine months like it takes to get through the process or longer, just depending on how quickly they can make changes inside their code. Um but yeah, that's still I'm hoping one of the things 20x is going to help us resolve and having the sponsor be the walking point. It's still a challenge on the Department of Defense side.
SPEAKER_01So we we have a platform that we got our 20x moderate uh certification through. Uh, but on our DOD side, which we have DoD customers with IL4s and IL5s in our environment, but they what they end up doing is having to audit the entire stack. So you do that four or five different times, uh, and it really becomes very difficult uh for us to maintain and manage all those different audits uh for different levels. But our management plane stays the same across you know all of that. We just do the same thing as you guys do, is have the multiple accounts you know for that. And then we have a um what we call our command center, and we have multiple command centers depending on the level of uh of of certification that you have, or authorization, depending on where you're at in this in this space, because it's gonna be a struggle certification or authorization. Uh I'm sure we could get Caitlin on on here for just a second to laugh about. We were we're doing our a sticker for our um uh our phase two pilot um uh certification. Uh how long did we spend?
SPEAKER_02An hour? Okay.
SPEAKER_01Oh, okay. So so we actually it it took us, oh that's right, we're not using, you're not here actually on site. So so it actually took us about an hour to build our sticker. And and it was how how do we do is it certified? Is it certification? You know, it is it authorization. So, you know, we ended up going with uh I I think it was certified, which is I think is what they is what they say it is. But if you look at two different places in the marketplace, it actually says two different things. So one certification and one says certified. So you have a FedRAMP certification, but you are FedRAMP 20X moderate certified. And that's what's in the uh actual uh marketplace listing. And I thought to myself, okay, we so we just spent an hour on this. How many other people can spend the same amount of time trying to figure out whether or not it's certified, certification, or authorization? So there's still this the confusion is still going to continue. And I don't think I realized that until we started to make the sticker out of it, the small nuance of change. And I'm not a words guy. You know, I always like to say, you know, English is my second language and I don't have a first. So, you know, I I don't typically argue over those things, but I know there are a lot of people who are like, oh no, you're not authorized, or you're not certified, or you're not, you know, so language, language is is important in this space, you know.
SPEAKER_00Yes, it is. Yeah, especially with the controls.
SPEAKER_01Especially with the controls, yeah. Yeah, exactly. So, you know, think about this. You know, uh the things that we do in these environments, you know, are they overkill? Are they necessary uh from a security perspective? You know, it it it is it is it way too many things from a security perspective, way too many things from a compliance perspective, way too many things from an audit perspective. I mean, how how do you judge that, right, from a from each each of the environments that you build? And to your customer, right?
SPEAKER_00So yeah, I mean justifying to the customer very much becomes a we don't really get a choice. We have to do this if we want to get to the certification or accreditation level that you're going for. But um I I tend to think that we are way over on the compliance side, yes, and then we don't do enough on the audit or the identity side.
SPEAKER_03Right.
SPEAKER_00Um, and that's really where I'm seeing at least 20x doing better. Um, I'm hoping as we move forward with some of the trust frameworks that people also start doing a better job exposing their audit logs to the agencies directly, which I know is always a challenge. But to me, the more eyes you have on audit logs, the better. And yes, in general, audit logs are I jokingly say needles and needle stacks because I wish it was a haystack because I can find the needle in that. But um it's I think with AI and the growth of some of the more ability to do ML pattern matching, the more logs we have in more places, the better we're gonna get at finding the adversaries. Yeah.
SPEAKER_01I I think it's one of the things that we do very well. We're a we're a we've been a pure security shop. We come at this from security operations perspective. So log management and log correlation and you know, getting the right logs kind of uh with the right rules, you know, on them to be able to alert or alarm on those is something that we do. You know, I'm sitting here in Western North Carolina at our uh cybersecurity center, and our my security operations center is like pretty much right behind me, where they set around and look at monitors all day long and and watch for the alarms to kick off because you know, human in the loop is also very important here. We've been we've been we've been exploring mostly on our commercial side uh how we use AI to uh look through those logs, look through look through those patterns. And we've we've done pretty well with it. We've actually built an agentexoc. Um it's only here again, it's only on our commercial side right now. We've not been able to bring it into our our federal side yet. And and and I I really think, at least from what we're seeing, it's really been able to review those logs. And what I really like about it more than anything else is it's it's able to correlate logs from different aspects uh of the uh of the system that humans or our rules we're having a hard time doing, you know. A lot of times you know the logs are very, very good in forensics analysis. I think this is really going to be able to bring these logs, you know, for folks to be able to see you know up front and really be able to uh take action. And then think about this, uh, and this is kind of where we're going with this is that automatic remediation, shutting down that shutting things down, you know, immediately, uh, coordinating off, coordinating uh, coordinating off um, you know, the attackers in the environments as well. And that's what we're really exploring with now. Everything that we do, uh I say human in the loop, the human really is on the loop. It's not making any decision for us as yet. They're still looking at the same logs that that the AI is looking at, and we're trying to figure out who discovers it faster. So we're taking all those kind of metrics. We've been running for a couple months now uh in parallel, and then we'll probably roll it out as a primary and a commercial within the next three to six months.
SPEAKER_00So that tells me it's the AI that's winning the race over the human right now? Yes. Yes.
SPEAKER_01It it it it's no surprise to me uh that they're able to recognize those patterns a lot faster than you are, you know, because what it can do is it, because you know, I remember this from two weeks ago. And I can go back and I can go, you know, the AI, that's what it's saying. You know, it doesn't really do that, but it can it can pull it, it can pull it up a lot faster to recognize those patterns, I think a lot faster than humans can. And that's one of the things I've always liked to say about myself is I can recognize patterns really fast. That's one of the things we train our soccer analysts a lot on is being able to recognize those those needles in the haystacks, you know, or those needles in the needles of the logs. And we have you know an alert module that that really you know does a lot of the uh the filtering for us.
SPEAKER_00So yeah, that's one of the pieces that I'm hoping we get to address as part of 20x and the changes. Uh from my I'll switch over for to my identity hat for a minute, but um all of the controls that we see inside of FedRamp or inside of DODIL are based off of the last generation of the NIST 863 REP3 controls. And there's been a ton of changes to address things like right before we would just say, here, as long as you've got one of these cards, you're good to log in in the federal government. Well, that's not good enough anymore. And really looking at the patterns, they're calling it germ inside of the identity space for 863, but looking at the context of not only do you have the right credential, but tying that to the machine you're on, tying it to your location you're on, tying it to the time of day, and then aggregating all of those factors to really understand if it's the person behind the keyboard that's supposed to be there, or if you drop that on the street and had your pin written in sharpie on the back so you didn't forget it yourself, but then someone picked it up and is using it from another location.
SPEAKER_03Right.
SPEAKER_00So and that's what I see AI is really, really strong at and finding when it's and right, we can look towards all the username and passwords that have been leaked over the last five years. That even if you do a good job at using different passwords on every website you go to, you still find a pattern that you're gonna use, whether that's putting the domain name in as part of the password or whatever that is. Um people can start spot using AI from the attack perspective to spot your patterns and then log into your accounts, even if they never had those original passwords. Especially if you're relying on the human memory for those patterns.
SPEAKER_01Yeah. Because yeah, especially as you age, uh your memory is always it gets better every day. I'll tell you that right now. Every day I can remember exactly what happened.
SPEAKER_00So not really.
SPEAKER_01Well, how about you if you don't mind, maybe spend a little bit more time here uh uh talking about uh your company, you know, uh where you know, where do you see yourself, you know, in the next few years? You know, maybe talk about uh your culture and and how you lead and drive and how do you recruit uh maybe in that in that perspective, if you don't mind. Yeah.
SPEAKER_00Yeah, absolutely. So um culture-wise, we're what you see is what you get. Um pretty open with our team members, open with um how things are going or not going well. Um everyone is wide open to talk to me anytime. We don't really have a lot of hierarchies internally. That comes from yeah, I especially when you're trying to grow a team that really excels together and right size-wise, like that's what you have to do to go against the behemoths and fight some living toys that we do on a regular basis.
SPEAKER_03Right.
SPEAKER_00Um so I started this company after working for Oracle for three years and spent so much time fighting for raises and bonuses for my best team members. I had people at Oracle that hadn't gotten a raise in seven years. And yeah. And we sat there one night working late on a proposal, and I remember it like it was yesterday, where it came across the screen, Larry Ellison buys the Hawaiian Island of Lanai. Right? And Lanai isn't a small island. That is like where they shoot movies on, and I think Jurassic Park got shot on Lanai. Um, and I just sat there and went, I'm fighting for a couple grand for this guy that's my best employee who's sitting here right next to me at seven o'clock at night working on this proposal to make that guy go buy another island, forget this, I'm out. And that was kind of the starting point where I said, I'm gonna go do my own thing and spent my first two years just billing individually and putting money in the bank of like the first two people I hired, I had a year of their salaries in the bank before I hired them. Because my attitude's always been if you're gonna take a flyer on me and a small business, I'm gonna make sure you and your family are taken care of. And I mean, if in cybersecurity I can't get people back to work in six months, let alone 12 months, I'm not doing a very good job myself. As a leader, it could be a struggle, right? So that's really been a kind of core to our culture is growth slow and with purpose and no outside funding, no outside investment, and really just growing organically.
SPEAKER_01I've got to introduce you to if you haven't seen if do you I don't know if you follow me much on LinkedIn or not, but I talk about an Evergreen and Tugboat Institute. I don't know if you've ever looked at them or not. I have not. So you just said two of their what they call seven P's, and I never can remember what all seven Ps mean. But if you look at my last post from uh two weeks ago, I talked about the seven P's. It it really is. It's about exactly what you just described. It's having you know uh pragmatic growth, uh profit, um, being persistent, um, and being able to have your people first. Uh and it's an organization that uh has um driven by uh a gentleman, his name is Dave Wharton, uh from uh he started a this institute called the Tugboot Institute. He actually was a VC and he saw how these uh companies were building, you know, um generational companies. And so he spent a lot of time studying them and came up with this this kind of uh certification process for evergreen companies. And uh, you know, you don't you gotta stay private and you gotta you know you gotta make sure that you're you keep your uh your profit going as well. Uh um and and pragmatic growth it as well. And uh I'll I'll think about all the seven Ps after a minute or two. Uh you know, it and and it's it's really cool. And the first time I went um at the summit, uh the the they have a um Tudbone Institute Summit uh once a year, then they have an exemplar in the fall, and then they have what uh they call the the gathering of teams uh in the winter time. Um and the first thing I went to was an exemplar, and it just I was actually I was blown away by how many companies were out there that were trying to do the same thing that I was doing. I thought I was unique, you know. I'm trying to build a company that is private, you know, it's funded by Gary Neighbor's wallet. I'm sure that's as well. Except yours is funded by Matt's wallet, you know. And um, you know, it's it's really it's it's it's it's a it's a beautiful thing because we get to build for the long term. You know, if you want to give you know Joe Johnson an extra raise, you can do that. If you want to build extra features into your application, you can. You want to give, you know, uh uh uh good roadmaps to your customers that last two years, you can do that. You don't have to worry about the quarterly reports or anything like that. I need to I need to send you a book called Another Way.
SPEAKER_00All right. I'm definitely uh I'm definitely all in. And I think you're like me where you can see in the industry patterns and see where things are going years ahead of time. Oh absolutely maybe not five or seven, but two or three years out. Right?
SPEAKER_03Yeah, yeah.
SPEAKER_00And if you have a BC in there that's looking at next quarter's profits, they're just gonna shortcut you and say, no.
SPEAKER_03Right.
SPEAKER_01They're looking for the exits, right? They're the exit doors that, yep, yep. And you know what? If uh I always like to say if I lose one money, it's okay because that was an investment for our future. Yep. So and I even tell my staff, it's not losing money, it's investing. We're investing this year. This is a big investment year. But you could do that. You know, you can do that when you know when you're your own advising board, you're you're your you're your own, you know, kind of uh setting your own destiny, and your customers are driving what you do on a day-to-day basis. And every time you win a customer, that that's that's somebody who's you invested in you, and they know that you can deliver. So let me let me ask you another question on that, then you know, how do you feel about you know some of these folks who do get all that uh the VC funding from a you know, from a from a just a general noise perspective and the general um you know marketing blitz that they get to they get to do with you know spending all the money they get on all all the all the stages and all that as well.
SPEAKER_00So how do you you know so I I I think it's people with different goals in life, right? Yeah um a lot of and this is gonna be very talking in generalizations because not everyone follows this, but a lot of the people who go that VC path and go that route looking for I call it using someone else's money to grow their business, which um they're looking for early exits and they're looking for multiple exits over their career. And I personally think there's no better exit than turning over the company to the team. Yeah, when I decide to retire someday, well, well, well into the future.
SPEAKER_01And I so employee ownership is is another is another really cool thing that uh evergreen uh companies can do. Um I have family members in my company, and I'll probably do the same thing is is you know, the next generation of damers will probably take it over, and then I'll give some back to the uh to the employees as well as we go with so with some employee ownership. So Yeah, I I can't.
SPEAKER_00I just know how hard it was to start.
SPEAKER_03Right?
SPEAKER_00Like you remember the early years and the grind of that, and thinking of selling out and having to go through that all over again with the next company. I I kind of like the snowball that we've built and don't want to have to start at the top of the hill with a snowflake again.
SPEAKER_01I'm right there with you. No, I like that. I love that analogy too. So I I I so I need to get you the the book another way. Uh Dave Wharton's uh book, it's it's it's very it's a very good book. I'll make sure we get it in the mail to you right away so you can you can look at it. Um actually have a little inscription that I put in the front uh of it as well. I I I've gone through a couple hundred books because that's how passionate about I am about this. You know, uh uh Chris Hyatt from um Risk360, I don't know if you know who they are. They spend most of the time in the commercial space. Uh you know, him and I talked a lot uh about this as well because there's not a lot of lot of a lot of us in this technology space that do it this way, Matt. So people I'm I'm I'm very happy to hear that. So anyway, as you can tell, and excited. I don't meet too many people like that, to be honest with you.
SPEAKER_00So I wish there were more of us. I think uh 100% agree. As a world, we'd be in a much better place if that was the case.
SPEAKER_01You know, I tell you, I true I'm I'm a firm believer in long-term investments. Um and when I mean long-term, I'm talking you know, 50 years long-term investments. You know, invest in people's future and not think about their short term. So Yeah. Well, on a lighter note, let me let me let me s shift topics. You know, it's it's so far it's been it's absolute pleasure uh speaking to you and absolute pleasure to finally get to meet you as well. I've admired you from afar from a long for a long time and what you've been able to do with your not only your company, but your your platform, because I know I'm I'm doing the same thing or very similar to what you're doing. And it's just really cool to see somebody else, you know, kind of going through the same struggle and and you're still alive. So so with as we said before the call, you still have hair. I'm I'm that off a long time ago. There you go. Yeah, I I still have some, you know, but it's you don't see the back side of my head, so let's just leave it at that. So with with that, so you know, I'm a big reader. I probably read a book to two books a week. I should say I listen to them anymore, but I do read them physically as well. I walk about 30 miles a week and I listen to to books uh all the time um when I when I walk. So how about do you have any books that you recommend? As you can tell, there's one that you know that I always recommend.
SPEAKER_00Yeah.
SPEAKER_01How about yourself? Any that you recommend that you that you read recently that you like?
SPEAKER_00So we're an EOS shop, so entrepreneurial operating system. So I always recommend traction for people that are struggling to grow their business and really put process like yes, you got smart people, yes, you got people that can pull off miracles, but sometimes that's not the best way. And getting a process around that and a prevention process to your customers that you can show here's how you can trust us as a small company and do this repeatably over and over and over again, and bring them to success as well. And traction does a great job kind of setting up how you give everyone in your company a rock, how you give everyone a goal, how those goals all roll up to be the corporate goals and you all win together. So traction's been great for us.
SPEAKER_01It's a great book, and one of my favorite uh pieces in there is uh the the get it, want it, and have the capacity for it, you know? Yep. You you get what do you get what we're trying to do here? Do you want to do it? And you know, do you have the the the ability, size, capacity uh to do it? I really like it because it pulls together quite a few different books together too, and it gives everybody acknowledgement on on that as well. Uh I always recommend um, as you can tell. Another way. And then uh Ideal Teen Player, uh, from Patrick Linconi. Very good book. And then uh Multipliers by Liz, and I can't think of her last name right now off the top of my head. But Multipliers, uh, it's a very it's a very good book as well. So how about uh from uh a uh TV show, uh internet, uh YouTube channels or anything like that that you like to listen to or watch?
SPEAKER_00Uh I I've known this guy for we actually he was on the first project I started when I started the company. Uh if you want to learn about identity and access management and the depths of it, and um what I love is not just the technical side, and this is where a lot of people with identity experience go wrong is I won't say go wrong, but have trouble understanding is that a lot of identity problems aren't technical, they're business problems, and you've got to lead with what is the business problem you're trying to solve first to actually get the traction within these companies to get things done. And um, David Lee, the identity Jedi, is his podcast, does an excellent job going through and talking about all the different topics in identity and how to best solve them.
SPEAKER_01So I I know I didn't talk about my history that much, but I'm an identity guy. That's where I got my experience is really identity and and cybersecurity around identity. And to me, it's always an enabler to get people access to what they need to get access to. Uh, you know, I I spent a lot of time at Booz Allen and um we helped write a lot of those NIST standards around identity. And that's where you know we helped a lot. We still helped the government with PIF and cat cards um as well, uh managing several PML offices uh within the federal government. It's pretty cool. I I still have a a big passion for it. And then we found this thing called the cloud, and it just absolutely took over my life. And now it's a whole AI and cloud thing together and identity on top of that. It's just uh the world is unlimited.
SPEAKER_00So yeah. Yeah, that'll be uh the next round is non-person identities and how we get it.
SPEAKER_01Yeah, it's gonna be a big challenge. Uh I I I could see it now. I was talking to one of my staff the other day, and they're like, well, what do you think if we put MCP servers on the front of our APIs? And I'm like, well, let's figure out what the APIs need to have access to first.
SPEAKER_03Yep.
SPEAKER_01Be able to figure out you know, if if and what, you know what, what kind of access should we should we give them? And you know, what what does it take you know to get them? I I I 100% agree. I think it's gonna be a a big, huge zero trust set of issues with with AI and giving them actual access and not uh uh over-escalating um that as well. So governance is gonna have to play a key role in that as well. Yeah. And anyway, one one last question. We're a big services company. We do a lot of work with nonprofits. Uh, we work with a couple here in town. And just curious if your organization you know gives back to any organizations. And if you do, do you want to give them a shout-out and maybe you could talk about how how and what you do for them?
SPEAKER_00Yeah. Um one of the ones that I love to throw out is a small organization out of Columbus, Ohio called Together We Grow Community Gardens. And they will write, it is literally a community garden that helps fill backpacks of kids that might not have food to write. A lot of states and schools have breakfast programs and lunch programs. But when those kids go home on the weekends, sometimes they're not sure that they're gonna have a meal before they get back to school on Monday. So they fill backpacks, they help families in need to make sure that people are fed with fresh, good food on a regular basis.
SPEAKER_01Cool, cool. We we do two here now. Everybody who listens to my episodes, uh, they always hear me talk about them. But one is the child abuse prevention uh team here in uh North Wilkesboro, North Carolina. And um, it really is about providing supervised visits and uh for court ordered supervised visits uh within within the county. And then my son has Down syndrome, my youngest son does, and so we spend a lot of time with the Special Olympics and um do it coaching. And my wife, she is also one of the chairpersons um uh for the the local community here in our county as well. It's a pleasure working with them and and um the athletes, you know, they absolutely smile from ear to ear with medals, you know.
SPEAKER_00Some of the most passionate athletes you'll ever you'll ever ever meet.
SPEAKER_01Uh we have a couple bicyclists that man, I tell you what, they're just they're phenomenal. And my son rides a trike and um he inches his way his inches his way around, but he absolutely loves what he does. So we we do it and and he enjoys it and we enjoy it as well. So it's amazing. Well, Matt, I tell you, I truly enjoy this conversation. Let's not not let's not make this our last conversation. Let's find some maybe some additional time uh to chat in in in the near future. I don't know if you have any questions for me.
SPEAKER_00Uh no, it was excellent. I appreciate it, Gary.
SPEAKER_01Absolutely, absolutely. Well, I I truly appreciate the time uh you spent with us this afternoon. As always, uh this is uh the the end of this uh behind a shield episode, and you may not always find me behind the shield, but you're always gonna find somebody else or somebody from the future behind the shield.
SPEAKER_02Peace out.