Episode 217 ·

Dan Conrad - Federal CTO at One Identity

Today we are talking to Dan Conrad, the Federal CTO at One Identity. And we discuss the growing need for Identity Verification in remote working environments, the security culture differences between the public and private sectors, and steps you can personally take to make your online presence more secure.

All of this, right here, right now, on the Modern CTO Podcast!

About Dan:

Dan Conrad is Federal CTO for Quest Software/One Identity. He has been with One Identity/Quest Software since 2007 where his roles have included Systems Consultant and a Solutions Architect for Compliance Solutions as well as Identity and Access Management Specialist. He retired from the USAF in 2004 and returned to government IT as a contractor where his primary focus was Active Directory design, migration, and sustainment. He holds many certifications, the highlights include CISSP, MCITP, and MCSE/MCSA.

About One Identity:

One Identity helps organizations establish an identity-centric security strategy with Identity Governance and Administration (IGA), AD Account Lifecycle Management and Privileged Access Management (PAM) solutions. #SecurityStartsHere

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Dan Conrad, the Federal CTO at One Identity, and we discussed the growing need for identity verification in a remote working environment, the security culture differences between the public and private sectors, and steps you can personally take to make your online presence more secure. All of this right here, right now on the Modern CTO podcast. Here we go.

(Joel Beasley at 00:00:26) This is the Modern CTO podcast. Hello, hello.

(Dan Conrad at 00:00:39) Hello, Joel. How are you doing?

(Joel Beasley at 00:00:41) Fantastic. How are you, Dan?

(Dan Conrad at 00:00:43) I am good.

(Joel Beasley at 00:00:45) Where are you calling in from today?

(Dan Conrad at 00:00:47) I am just the north side of Indianapolis.

(Joel Beasley at 00:00:50) Oh, what's the whole COVID lockdown situation like there?

(Dan Conrad at 00:00:55) Well, we're not in a great situation. So it's not a lot of lockdown, but there is quite a bit of COVID going on. So I think maybe we'll have to take a few steps back into a deeper lockdown.

(Joel Beasley at 00:01:09) Well, luckily you have a guitar there in the background, so you can play while you're locked inside.

(Dan Conrad at 00:01:17) I only use that ironically or for sarcastic notes where I need to bend a string and roll my eyes.

(Joel Beasley at 00:01:24) So you don't play, like, regularly?

(Dan Conrad at 00:01:27) No, no. I'm just to mess around with, and if I'm on a call or something and I can sit in the background muted, I walk through some chords and that kind of stuff. It's a nice distraction. At the same time, it keeps you engaged.

(Joel Beasley at 00:01:40) Did you want to be, like, a rock star as a kid?

(Dan Conrad at 00:01:43) Not as a kid, maybe as an adult. The deeper you get towards the life that you've chosen, it's like, well, maybe I could do something a little bit bigger.

(Joel Beasley at 00:01:54) Yeah, I've seen a lot of actors do that. They'll have good acting careers, and then they'll end up going and doing a band. Like, I think, what was his name? Steve Martin? He's got, like, a really good band.

(Dan Conrad at 00:02:04) Yeah. I think, uh, was it Dennis Quaid? And I've seen him play some venues, you know, so interesting.

(Joel Beasley at 00:02:12) Well, maybe there's a future for you for that.

(Dan Conrad at 00:02:14) Maybe. Yeah.

(Joel Beasley at 00:02:15) This opportunity being locked inside, you just brush up, and then you end up starting, like, a seventies tribute band.

(Dan Conrad at 00:02:23) Yeah. Because I have that brand recognition already, right?

(Joel Beasley at 00:02:26) You do.

(Dan Conrad at 00:02:26) Well, I'll write a bunch of songs specifically about identity and authentication. I think that'll be a big hit.

(Joel Beasley at 00:02:33) You know what that reminded me of? Okay, so did you see the old, like, Microsoft product launch videos where, like, Bill Gates would dance?

(Dan Conrad at 00:02:43) Yeah. It really strikes home with the user base there, right? So...

(Joel Beasley at 00:02:47) Oh, yeah.

(Dan Conrad at 00:02:48) Yeah. IT security-based poetry or something like that. I don't know. Maybe that would work.

(Joel Beasley at 00:02:54) So other than music, like, when you were young, like, how did you get into technology?

(Dan Conrad at 00:03:01) Accidentally. Yeah. I'm a believer of you let your career find you. I was in the military for twenty years and migrated into technology because, you know, everything from the—I was the Nick Burns. Do you remember Nick Burns from Saturday Night Live?

(Joel Beasley at 00:03:18) Yeah, of course.

(Dan Conrad at 00:03:19) You know, the office IT guy. You want me to save that version of Minesweeper for you before I reboot your computer? To, we have moved on up to the enterprise level. I mean, you know, it was strictly by accident, and it just worked out.

(Joel Beasley at 00:03:32) So that was just—like, that's like brief story. What was, like, your first tech job?

(Dan Conrad at 00:03:37) Yeah. You're going to find out exactly how old I am. So I mean, the day I entered my first duty station in the military was in 1984, and they dropped a Zenith Z-100 on my desk and said, we don't know what this is, but we're supposed to figure out how to use it. And it was the first Air Force standalone computer system with—I had the nice one because it had the 10 meg hard drive in it. And, you know, first thing you do is you format the hard drive, and it took an hour and a half. And you had to move a jumper on the motherboard to do it. So, and then it was off from there. We did everything from, you know, basic office functions to moving data around our organization, which was a squadron. And we did a lot of amusing things that were probably easier to be done without a computer. But we insisted on using computers to do a lot of that kind of stuff, and it turned into things that were actually much easier, better information flow.

(Joel Beasley at 00:04:30) It's just so amazing to think, like, you had a 10 meg hard drive, and most of the photos we take today are larger than that.

(Dan Conrad at 00:04:36) Well, I mean, you think about the bandwidth that you just pump through, and, you know, I need a hundred megabits per second to be able to have a video call. So that's ten of those hard drives every second.

(Joel Beasley at 00:04:46) I know. We just got a new studio, too. This is actually the first episode with the with all the components of the studio, like, coming together. So, like, new HD cam. So we're still working on the lighting and all of that. But we just figured, you know, the show got big enough, and we were like, let's just take this Amazon principle of day one. We started using it in other aspects of our business.

(Dan Conrad at 00:05:10) And then...

(Joel Beasley at 00:05:10) We said, okay, well, like, let's make a list of every routine that happens at the company and then just go day one on them constantly. Just go in this iterative loop of just constantly improving the basic things that drive revenue and bring value to the customers. And we got around to the studio, and so that was, like, our project for this past couple weeks.

(Dan Conrad at 00:05:30) Nice. Yeah. That's an interesting mentality when you can do that. A lot of companies really aren't in positions to do that sort of thing, to make those kinds of major changes. And if you've got—anytime you've got a chance to make a fresh start, it's always a good thing. You know, it's the same concept of never miss an opportunity to reload an operating system. Right? Just start from scratch every time you can.

(Joel Beasley at 00:05:51) So yesterday, and I think you'll be, like, uniquely positioned to talk about this with me, but yesterday I was talking with Rafael, and he is, like, a filmmaker, and he created this documentary called Cyborgs Among Us, talking about how people were implanting, you know, different technologies. There's like an underground movement. There's people in Sweden doing it. There's people in the US doing it. But then there's also the commercialization for, you know, people with Parkinson's getting brain implants, artificial limbs for people who've lost limbs. And so that brought up this question where I was thinking, like, with identity, what's going to happen when, like, bionic eyes exist and you can, you know, change your retinas or clone retinas or your hands can be changed? Like, where are we at with, like, identity and security? And where we at today? And then, like, where are we headed?

(Dan Conrad at 00:06:47) The first thing that comes to mind is, you know, we're going to have to change a lot of the CAPTCHA screens that says, are you a robot? Like, I'm not—if I were a robot, would I know it? Or you might have to change it to say, I'm mostly not a robot. At this point, you know, there's a lot of—we think of things like the non-person entities. And, you know, of course, with my company, we deal with a lot of authentication and identity security. But there's more to it than just people. There's systems and authentication between systems. And, you know, the way that things have been breached throughout the last twenty years have always been, maybe breach a person, but at the same time, you can breach a system in the same way. And the system will act like a person sometimes. So with that, I mean, I think things are going to be changing quite a bit in regards to things like robotic process automation. That may be the next target. SCADA systems are always a thing. But then when you integrate robotic process automation into SCADA, that decision-making process changes. Hopefully, the robots are making the right decisions or the decisions that you've taught them to make. So, I mean, it's going to change quite a bit. I can see where the systems that are maintained in a human body are going to be an entire, maybe multiple career paths for people to learn how to do because it's just going to be so different than anything that we're used to doing now.

(Joel Beasley at 00:08:11) And so what's your primary line of business? Like, what creates sales for One Identity?

(Dan Conrad at 00:08:17) You hate to say that problems create sales, but I mean, we're all looking for the next big breach that we can jump on the bandwagon for. But in reality, we're about identity security. We think back to the way we were building firewalls and things like that ten years ago, fifteen years ago. And that was our security perimeter. I think of military installations where I worked, and we had the most robust firewalls. And it was a lot of emphasis put on the firewalls. That was because most of our work and all of our identities and all of the subjects and the resources were inside that perimeter. So that's where we protected it. But now, nobody works that way anymore. I mean, you think—Quest is, or One Identity is a Quest company. When I came on to Quest in 2007, I didn't go into an office for three years. Everybody worked remotely, and so we protected our identities that way. My mentality was that a lot of companies were capable of doing this, when in reality, a small percentage actually did that. So we were enabled. But at the same time, we were enabled securely. And I think that will be the new modern workforce that One Identity is out to protect.

(Joel Beasley at 00:09:26) So what did you notice? Like, when you were talking, I brought up this thought that, like, the culture—so my dad was in the Air Force, so I got raised by him and very disciplined, very structured. It's a very different world.

(Dan Conrad at 00:09:40) Very disciplined, but in an air-conditioned environment compared to my Marine Corps coworkers.

(Joel Beasley at 00:09:46) Right? And but I was curious to know the culture, right? So when it comes to security, I mean, I don't think there's a huge lack of technology. I mean, there may be, but I think there's definitely a lack of, like, discipline in the, you know, companies implementing the processes and sticking with them. And did you find that it was easier in the military culture to have security and process and procedures than it is within these, like, the public sector companies?

(Dan Conrad at 00:10:17) Well, you know, if you're talking about from a technology perspective, yes and no. I mean, I retired in 2004, so the technology had come to a certain place there. I mean, you know, we had Active Directory in Windows 2000 and that sort of thing. And security of those type systems didn't have as much visibility as it would today. Maybe because there weren't as many breaches, maybe because it was just happening under the covers and nobody noticed, that sort of thing. But, and again, that varies organization by organization. But I think in general, there was more of a utilitarian focus on security, like a lack of—let's put out a policy and we abide by that policy, and very few exceptions to that. So if there were exceptions, there were processes to examine your network and then write up—we call them POAMs, process something. It's basically an exception process, where if something was recommended or determined that it had to be done, you had to justify in detail why you weren't going to do that. And that was only on a temporary basis. So you had that limited capability to deviate, but you had to have a plan to get away from it and actually abide by the directive, at the cost of user experience and things like that.

(Joel Beasley at 00:11:34) What other differences did you notice going from, like, military, Air Force, into, you know, this sector?

(Dan Conrad at 00:11:40) I made a gradual transition. So when I retired, I went to work as a government contractor. So doing Active Directory Exchange migrations for the Army. And contract life was obviously a different work life, but from a security perspective, we had a lot more capabilities and able to implement things much quicker than I had in my previous government experience. And then when I moved over to a, you know, I was a presales engineer for Quest and One Identity. That was a commercial company for me, which was a completely different lifestyle, a completely different—the way you work is different. The way you interact is different. The motivations of people are different, that sort of thing. So within the military, you're in a situation where you've got a job to do, you get the job done, and then you take the day off or, you know, whatever it is you're going to do. There's not a monetary goal towards that. There's not a, you know, keeping the business alive. There's not really meeting needs of customers in that scenario, other than, you know, you being your own customer.

(Joel Beasley at 00:12:38) What advice would you give to people that are, like, transitioning from military into companies? Like, what's—obviously there's a lot, I'm sure, but what's, like, the one or two blaring things that just repeat themselves?

(Dan Conrad at 00:12:52) I've been through this with several folks. In fact, when I retired from military and went to work, I reached back in to hire a few people that were coming out. And there's a mentality when you're getting out that you're making another commitment, you know, another twenty or a four-year commitment to another company. It doesn't really work that way. You know, we've all worked in the commercial world where you've had people accept positions and not show up on day one. Like, well, I guess they got a job. So I mean, just kind of keep your options open and don't rule anything out. And, you know, you can commit, but it's not really the same commitment that you're used to in the military, where you're going to have all your stuff shipped, packed up, and you're going to end up in some overseas location for four years.

(Joel Beasley at 00:13:29) And then how did you get from sales engineer to executive at the company?

(Dan Conrad at 00:13:35) You know, I'm sort of a low—I wouldn't really call myself an executive. I've spent a lot of time in presales. So I made my way through presales, and I was the Federal CTO. So I spent, again, another sort of phased transition into commercial life. When I went to work for Quest, and when I did it, I strictly worked with federal and public sector customers because I held a security clearance, and I spoke the language, and I could decode acronyms at the drop of a hat, and couldn't make up acronyms at the drop of a hat and move forward. But up until probably—and I did that till probably about two years ago. And I became the Federal CTO on the Quest public sector or federal side of the business. So that transition really was kind of seamless. And then when I came over to commercial side, what's called a field strategist. So I get to work strictly from the One Identity portfolio of products. I get to work with the customers that have the most specific problems. I get to explore new solutions. I get to look at, you know, other types of technology and take those back to the company with recommendations. So, you know, call myself an executive, I don't know about that. But I do have influence on the executive staff.

(Joel Beasley at 00:14:40) That's interesting. So your primary, like, responsibilities are, like, researching emerging technologies, bringing back useful insights?

(Dan Conrad at 00:14:49) That and talking specifically with customers. I share a team with—we also do customer advocacy. So we take some of our highest-level customers that use the most creative solutions to do things. And we, you know, kind of come back and say, this is what solutions need to do looking forward. We look at the markets. We look at the researchers.

(Dan Conrad at 00:15:06) We look at Forrester, Gartner, Covenger Cole, all of those and figure out where we want to go and what problems we want to solve, what the market's going to be like in five years, two years, twenty years.

(Joel Beasley at 00:15:16) Do you then take those insights and, like, how far do they go? Do you just gather them and do the research, or do you actually begin to test and figure out, like, which of the three paths are going to have a nice return or gain traction?

(Dan Conrad at 00:15:33) Kind of all of the above. So on my team, we're also responsible for technical integrations with other providers, you know, other IAM vendors or things that aren't necessarily IAM, and even within our own company, because Quest is a very large company with literally hundreds of products. So we look at, you know, like right now, I specifically work with our Microsoft platform management portfolio folks, and I figure out are there solutions in that portfolio that strengthen the IAM message or the IAM solutions? You know, right now I'm working on something in an Active Directory security area.

(Dan Conrad at 00:16:06) Like, what solutions would work best for anyone running a large enterprise Active Directory? Would it be recovery? Would it be auditing? Would it be controlling of privileges? That sort of thing.

(Dan Conrad at 00:16:19) So blend those together.

(Joel Beasley at 00:16:20) Yeah. So it's a large company, hundreds of products. One Identity is like a sub-brand of Quest. Is One Identity a specific product, or is it a suite of products?

(Dan Conrad at 00:16:30) It's a branded business unit within Quest. So with it, it is a suite of products—things like identity governance, privilege access management, and then account management and things like Active Directory and the non-Windows environments as well.

(Joel Beasley at 00:16:44) So do you have engineering teams that are making these products, or are you just reselling?

(Dan Conrad at 00:16:49) No, no, no. Yeah, we develop our own products, or we acquire companies and then continue to develop and merge those in.

(Joel Beasley at 00:16:55) Oh, nice. Have you gotten to be a part of that process of finding and the M&A process?

(Dan Conrad at 00:17:00) You know, we've made recommendations. My team has made recommendations. We'll see if any of those have come to fruition anytime soon. It's nice to be part of a growing company, either grow organically or you acquire and grow, and it's great to be a part of that and finding some kind of, you know, I really like the new technology that not just makes you think different, but eliminates something that you were doing completely and makes it irrelevant. You know, so I'm really a big fan of that type of technology, so we'll see where some of that goes in the future.

(Joel Beasley at 00:17:30) So who runs the, like, who's in charge or, like, the CEO of the One Identity business unit?

(Dan Conrad at 00:17:36) The One Identity business unit is a guy named Daryl Wong. So he's, it's an interim position right now, but he's running the whole, you know, product, all the product set, as well as the marketing that goes with that.

(Joel Beasley at 00:17:49) Okay, cool. And so, like, One Identity has its own sales staff, its own product engineers. It's like its own branded business within...

(Dan Conrad at 00:17:56) Yes. Quest. Yes.

(Joel Beasley at 00:17:58) And then Daryl then reports up. And so Quest has, like, multiple different branded business units, or...

(Dan Conrad at 00:18:06) Right. We have three. We've gone from five to three right now and merged a few together. So the, you know, the two I work with, of course, is One Identity and then the Microsoft platform management, which does things like Active Directory, Exchange migrations, and on-prem Active Directory management. And they've got an Active Directory security practice that'll do analytics on your Active Directory.

(Dan Conrad at 00:18:27) That's the thing.

(Joel Beasley at 00:18:29) Yeah, because that's, like, what you did for twenty years. You're an Active Directory expert.

(Dan Conrad at 00:18:33) Yeah. Expert is a word I would choose not to use because I'm always, somebody that's way better than I am. Right? I mean, you know, I came back from the on-prem Active Directory days of deploying it in 2000 to, you know, things are sure a lot different now. But you have to stay, you know, with that whole, you have to understand the whole process to end up where you are now. I think it would be very difficult to jump in.

(Joel Beasley at 00:18:55) I think it's interesting, though. It sounds like a lot of fun. It sounds really cool. It's almost like, I guess the closest thing I've seen, it's like an office of the CTO. I typically see the offices of the CTOs will form when the CTO happens to, like, just really want to think about the future or the technology, or, you know, build services and try new things to help out the company internally. But that whole process that you talked about, like research, and I was just trying to find a way to fit it into, like, my existing thought structures.

(Dan Conrad at 00:19:27) Yeah. I mean, the group, the team that I'm on right now, there's five of us on the, we call it field strategist team, and then there's five on the customer advocacy. And we work closely together with our own specialties. So there's, you know, three of me in the US, and, you know, those other two guys are really good in the identity governance space. And then got a privileged account management expert in EMEA, and then we've got a guy in France that does a lot of things in the identity governance space as well. But they're just kind of people that can, you know, talk really well to customers. They can talk really well on, you know, they can write articles. They can provide opinions and that sort of thing. So it's a very diverse but kind of a flexible group that does a lot of different things.

(Joel Beasley at 00:20:09) Do you guys ever have, like, war games internally within the company where, like, you, your team tries to hack, like, your peers' team or anything fun like that?

(Dan Conrad at 00:20:18) Yeah, I don't think our internal IS would appreciate us doing that. You know, you just release Metasploit on the network. I don't think we really want that.

(Joel Beasley at 00:20:31) I have a question. I'm somewhat excited and reluctant to ask. So depending on how it goes, we can keep it or not. But purely from a data perspective, right, who is better at stealing identity, Russians or Chinese?

(Dan Conrad at 00:20:50) Well, that's a tough question to answer because if you're really good at stealing data, you've never been caught. So...

(Joel Beasley at 00:20:59) That's true. That's true.

(Dan Conrad at 00:21:01) Could be, it could be me. Probably not. But I don't know. I mean, that's the thing we really just don't, we don't know what we don't know. So, I mean, when, and getting caught, you know, different organizations get caught different ways, but we really, and how do you determine good at stealing data? Like, the quality of the data, the bulk of the data? I don't...

(Joel Beasley at 00:21:22) Oh, that's good. But you've thought about this a little bit. Right? Is it the quality? Is it the size?

(Dan Conrad at 00:21:27) Yeah. Quantity over quality.

(Joel Beasley at 00:21:29) Yeah. That's important.

(Dan Conrad at 00:21:30) We, I just stole two terabytes of, you know...

(Joel Beasley at 00:21:33) Cat images.

(Dan Conrad at 00:21:34) Social security numbers that don't have names next to them. Yeah. Yeah, two terabytes of cat photos. Congratulations. Well, you could have had those for free. We weren't hiding those from anybody.

(Joel Beasley at 00:21:44) Well, I have my private repo of cat photos.

(Dan Conrad at 00:21:46) Yeah.

(Joel Beasley at 00:21:47) Locked down pretty hard.

(Dan Conrad at 00:21:49) Yeah. That's right. I mean, you know, just as the honeypot. Right? So, you know, people are after that.

(Joel Beasley at 00:21:55) Oh, man. That's so far from me. I'm a dog person for the record.

(Dan Conrad at 00:22:00) Yeah. I've said it before. Like, dogs are the best people, aren't they?

(Joel Beasley at 00:22:05) Oh, yeah. Yeah. I'm waiting on the next thing we're getting is the shot's going to widen up, and we have a bookcase type thing that'll come here. So it'll have some books in to add color to the shot. But then also, like, I can put the pictures of, like, my family and my dogs and all that good stuff.

(Dan Conrad at 00:22:20) Yeah. You know, whenever you, wherever you see a Zoom meeting now, you always look to see what books are in the background. That's the new thing. Right? The subliminal messaging in the books.

(Joel Beasley at 00:22:27) Yeah, it's important. There's no books in your background, but there's music, and so that's...

(Dan Conrad at 00:22:31) Oh, they're a little higher.

(Joel Beasley at 00:22:33) Oh, I see them now.

(Dan Conrad at 00:22:34) My Future Crimes, and I've got my, whatever. Oh, Seth MacFarlane, A Million Ways to Die in the West book.

(Joel Beasley at 00:22:42) Oh, Seth MacFarlane's an amazing individual. Yeah. He's very dynamic.

(Dan Conrad at 00:22:47) Yeah.

(Joel Beasley at 00:22:47) Is that Red Stapler, like, homage to Office Space?

(Dan Conrad at 00:22:51) It absolutely is. I mean, Red Stapler didn't exist until Office Space came out, the Red Swingline one.

(Joel Beasley at 00:22:56) That's amazing. So, yes, speaking of, like, everyone being inside and looking at their backgrounds, have you noticed in the business trends or sales trends or maybe just customer requests, has this move to remote, like, sparked an increase in identity and identity verification? Like, has it impacted your business positively?

(Dan Conrad at 00:23:18) It's impacted our business because we've become very concerned. I mean, I personally have become concerned with, you know, things like if you're sending all your employees home tomorrow, that's a difficult thing to do. But if you had a new business plan where everybody's going to work remotely, we're going to take six months to execute this securely. Okay. That's interesting, and we've got, I mean, we know all the steps that we're going to have to take. But, you know, when I assumed that everybody could work the way Quest and One Identity did, I found out quickly, pretty quickly, I found out I was wrong. I talked to a few customers, and, you know, one of them said, we don't have laptops. So we told all of our users to make an appointment to come into the office. They would only allow maybe two people in the office at a time. Pick up your desktop, put it in your chair, and take all of it home. And then when you get home, call back to the help desk, and we're going to set up an appointment for you to hook all that up and how to VPN in and all of this stuff. I can't imagine the overhead to do that. So that kind of, those kind of knee jerk reactions were, we're all going to work remotely and securely. So I don't know that that's actually possible. So we became very concerned about things like, you know, how people are getting access to resources. If you weren't positioned for cloud, you simply don't have access to a lot of the resources. Are you going to give everybody a VPN? Are they going to start using their own laptops because you didn't have them? Are they going to get access to your network via a VPN that you just plugged into a laptop that you don't own? So you might as well just plug foreign machines into your network blatantly and see what happens. You know, a lot of those pieces didn't line up when you do things very quickly like that.

(Joel Beasley at 00:24:54) So then has, like, has company been reaching out to you asking for advice on what to do going remote?

(Dan Conrad at 00:25:01) Yeah. Not as much as we would, of course, not as much as we would like. Right? But companies have reached out. We've done some webinars. I've done some sessions on what it looks like, you know, the proper way to give someone, like, say, an admin with privileged credentials. You know, somebody just took a, you know, a domain admin account home with them, and now they're going to work from home. Because not only is your entire, you know, user base working from home, your admins are working from home, and they send everybody home from home. So it's just this, you know, layer on top of layer that goes with this. So we've got people carrying credentials home and accessing your network via, you know, whatever system. We've seen breaches of RDP protocol or people posting RDP open on the Internet to give their admins access, and then VPNs, VPNs with default credentials on them, all of these things that go with that and all the layers that need to fit on top of things for you to actually do it in some version of secure that it's difficult to communicate to every customer a standard set of operating procedures for that because they've all got different needs and different capabilities.

(Joel Beasley at 00:26:05) So you get to think of the future a lot. Right? You even have the book, the Future Crimes book. I'm curious, like, what, let's first talk about, like, today. So, like, today, what are some of the unique ways that you've seen in the marketplace that people are using to prove identity?

(Dan Conrad at 00:26:20) So I just finished a comment this morning on the NIST zero trust framework. Are you, I don't know if you're familiar with the zero trust framework.

(Joel Beasley at 00:26:27) I'm familiar with NIST and their standard framework, but I don't know if it's the same.

(Dan Conrad at 00:26:32) Yeah, NIST latched onto the term zero trust because it sounds really cool. It's got a Z in it. You know, marketing likes it. If zero trust were true, then we would just, zero trust is anonymous. Right? So but what it really is, it's a authenticate every connection kind of terminology. It looks a lot like access-based or attribute-based access control with policy enforcement points and policy decision points. But what they're really getting at is with the new architecture of identity being the new perimeter is we need to authenticate people in different ways. And that can be username, password. But username, password based on time of day, location, anything about the person or the connection or the system that you're coming from can be part of that decision process. So that's going to be, and then probably in the next three or four years, I would say that's going to be something that's going to change significantly in regards to continuous authentication. So, you know, once you establish a session and walk through the front door of your house with the key, that doesn't mean you get access to every dresser door and every pair of socks in the dresser door. So we need to kind of bring that back and get a little bit more granular with that. Like, sure, come in the door, but who are you again? And where are you coming from? And what do you need right now? So that's going to change significantly. And then in regards to things like behavior analytics, I think it's going to change quite a bit. So we'll see a lot of sessions that are controlled through behavior analytics or monitored or, you know, when we start to gather data, we'll learn more what we can actually do with it. If you don't have the data, you can't use it in the future to make decisions. So if we start collecting data on analytics of the way users typically operate, we can develop things like typical profiles of the way a user works or an admin works, and even a risk profile of this is a very risky person based on the access that they could have, or a very risky identity because it has access to several things that could cripple, change, fix the environment.

(Joel Beasley at 00:28:30) That's interesting. Yeah. Like, I like the analogy of the, how you use the analogy of, like, walking in the front door in the house because it really allows, like, a lot of people to understand. It's a good analogy.

(Dan Conrad at 00:28:43) Oh, thank you. Yeah. That's really all I know about that.

(Joel Beasley at 00:28:47) And I've also seen, like, I went to Colorado recently, and I noticed that all of these services I used, they required additional authentication because I was in a new location. And it's not like that's the first time I've seen it, but the big difference this year with traveling was it was just very, very obvious. Like, it was in more of my services than ever before. And it was amazing how one of the things I liked and, like, you know, to give kudos to the industry as a whole is the way it was set up where I wasn't running into it, like, in my town when I go from my home to my office and it's very close, and that's very, it only, you know, presented itself to me when I was, like, far outside of my normal routines. I thought that was pretty cool.

(Dan Conrad at 00:29:37)
Yeah. And, you know, to me and to us in this business, we don't see that as an inconvenience. We see that as a layer of security. I would hope that, you know, maybe we can educate the world that being prompted for credentials or an extra fingerprint swipe from time to time is a good thing. It's not, you know, here to cripple you or slow down the process. You know, any of that kind of stuff. We ask a lot of our users, you know, things like, you know, we know you have 224 passwords. Don't use the same password twice. Don't write them down, and they all need to be differently complex. Okay. That's not possible. So, you know, anything that we can do to add to that convenience but add security at the same time is a good thing.

(Joel Beasley at 00:30:20)
Yeah. Well, I mean, I started using a password manager seven or eight years ago, and that just makes your life so much easier.

(Dan Conrad at 00:30:29)
I have spent soapbox time with family and friends on, like, use the same password for literally everything. Well, it's the only way I can remember it. You know, so let me explain this to you. You know, I've done commentary on some things like some simple breaches. You know, they asked me to comment on an Instagram breach. Usernames and passwords of Instagram. I'm like, well, I don't really care about that. I'm not a 14-year-old girl. Well, wait a minute. People that use Instagram use the same passwords for their bank account because they can't remember more than one password. Or they may modify it slightly, change a capital letter or something at the end. It's a difficult thing to tell people that you can't do that, and this is the problem with that. But I have 225 passwords. Password managers are the answer.

(Joel Beasley at 00:31:18)
Yeah. I've always had complicated passwords because my dad was an engineer, you know, so he was very like—I said, he was Air Force, so he was very interested in security. So he had, like, the big thick wallet that looked like a Big Mac or something.

(Dan Conrad at 00:31:35)
Yeah. The George Costanza wallet. Yeah.

(Joel Beasley at 00:31:37)
The Costanza wallet. Yeah. And then he had, you know, essentially sticky notes with tiny little writing on them to remember all his passwords, and he kept them on him all the time. Right?

(Dan Conrad at 00:31:48)
And they were encrypted. Right? They were all encrypted.

(Joel Beasley at 00:31:50)
Encrypted stickies. Yeah. Right. No. But they were just, like, random letters and numbers and symbols. And so when I would log on to the Internet, you know, to do the dial-up, I would have to remember this string of, like, long characters. And so what I did was I just took that string and then, like, appended stuff to it. And that's how I used my—

(Dan Conrad at 00:32:13)
You gradually remember more and more. It's like remembering all the characters in pi. Right? You add more and more every day. Yeah.

(Joel Beasley at 00:32:18)
So the first, like, 12 digits were completely random numbers, letters, capitalizations. And I remembered that initial string, and then I might just make a site-specific password appended to that string. And that worked out really well. And that was just for me, it's not that I'm special or unique. It's like that's how I learned password making. And so it blew my mind when I got into high school and people started having passwords and I would see them written down. I'm like, are you kidding me? That's your password? It's "Password123." It's like, that can't be your password.

(Dan Conrad at 00:32:54)
Yeah. Yeah. I actually keep the—I don't know if you're familiar with the RockYou breach, but RockYou was a social media app that linked, like, Myspace and Facebook and a couple of other things together. But that organization, to get into that, you had to enter, of course, your Facebook password and your Myspace or whatever else they had in there. And they were storing their entire database—not their own password database, but the passwords that they collected—unencrypted. And it was taken. So I have the database on my desktop in a text format. It's like a 15-meg text file. And it's interesting. You just open it up, you know, and take a look and start looking for a password that you might know, and I bet it's in there. So there's just so many passwords in there. Anything that you've used, like I've used keyboard patterns, and they're in there.

(Joel Beasley at 00:33:39)
Oh, wow.

(Dan Conrad at 00:33:40)
Yeah, so when you do, like, a try to break a hash, you can link back to that file and see if it's in there first, and it usually is. So it works really well.

(Joel Beasley at 00:33:50)
Yeah. That's why the password managers now are just—they're beautiful because they autofill for you. They sync across your devices. And then if one network gets hacked, they don't—

(Dan Conrad at 00:34:06)
Yeah. It's one password. Yeah.

(Joel Beasley at 00:34:07)
It's one password. Yeah. Mhmm.

(Dan Conrad at 00:34:10)
Yeah. Cut the arm off and move on. You know, the problem, though, is when you take something like Active Directory and the way Active Directory uses passwords with NTLM and the hashing, you know, I don't know if you've ever seen this before, but you log on to, like, a Windows workstation, and it stores the hash of your password to promote single sign-on in the registry. So, you know, if your Active Directory domain admin password is 256 characters long written in iambic pentameter, nobody cares what that is. They just want the hash. So they extract the hash and, you know, what we do now in the PAM space, Privileged Access Management, is every time you use a domain admin credential on a Windows box, you cycle it. So that's one of those things that makes the way you were doing it before irrelevant. So I don't care how long your password is. They were taking the hash anyway. So if I reach into Active Directory and change the password, I've even done some work with a couple of our solutions where I integrated them. And what I'm able to do is the account that you're going to use doesn't have any permissions until I ask for it. So I go check out an account, and then it only becomes a domain admin temporarily. When I check it back in, it changes the password, which cycles the hash. But it also removes the domain admin group membership and disables the account. So if someone were to get access to that hash, it just doesn't matter. So there's really nothing they can do with it.

(Joel Beasley at 00:35:30)
What's one of the craziest breaches that you've seen? Like, craziest identity theft stories that you have?

(Dan Conrad at 00:35:37)
Well, I've done a session on—in one of the sessions I do is on privileged access management and why it matters to me. So I've got the three bullets. At the time, I held a federal security clearance. So the OPM breach was key to me because they took a database that was called EQIP, which had all of my personal information in it and everyone that I used as a reference as part of my clearance and their information in it as well. And that was through a pass-the-hash breach. And, you know, they got access to the database. You know, the database, I believe either the database was encrypted or it was on an encrypted drive. But when you come in with privileged credentials, you don't even know there's encryption there. It just doesn't matter. So they walked right around the encryption and took the database. As a result of that, you know, then there was a Target breach in, like, 2012. That one didn't really affect me too much. You know, the credit card that might—it didn't really matter too much. But after the OPM breach, they gave me Equifax credit monitoring. Okay. Then Equifax was breached. So, you know, I mean, just that chain of events that goes on and on with that. You see scenarios where the IRS has—people have found ways to breach IRS tax returns on old people that have, you know, years ago, they can find a way to get their tax returns, and that gives them access to things like—or the health records that they breached gave them access to IRS tax returns, and it's just this cycle that just goes on and on. So once you've had your identity breached, and somebody knows every bit of personal information about you, you're up a creek, you know? I mean, it just goes on and on from there.

(Joel Beasley at 00:37:08)
I do give credit, though, to Equifax because I think they, like, fired most of the people before the breach. But I didn't talk to anyone before the breach, but I did get to talk to Bryson who came in as, like, their CTO after the breach. Mhmm. And then I think his name is Jamil, and then there's another woman over there too. But I follow these, like, three executives at Equifax, and they are, like, crazy about security. They completely changed the entire company culture from the ground up through, like, new executives and whole new mission. And now they're, you know, it looks like, you know, PR-wise, they're positioning themselves as, like, you know, a titan of security. But, you know, you know how you talk to people and sometimes you walk away and you're like, that person is ridiculously sharp?

(Dan Conrad at 00:37:55)
Yeah.

(Joel Beasley at 00:37:56)
Yeah. That Bryson guy, I think it's Bryson Koehler's his last name. He is the head over at Equifax right now. And, man, that guy is just sharp.

(Dan Conrad at 00:38:05)
Interesting. Yeah. Yeah. They needed something like that because, I mean, as a company, the reputation is key. And I think the damage that that did to the reputation was very, very difficult to overcome.

(Joel Beasley at 00:38:18)
Yeah. They're still working at it because, I mean, you know, one piece of bad news, you need a thousand pieces of good news to counteract that.

(Dan Conrad at 00:38:25)
Yeah. You do. And not just, like, little tidbits. It's gotta be, you know, really great strides to recover from that. And not just, like, the security that you've invoked as a result of what you did wrong.

(Joel Beasley at 00:38:36)
And then the public sees it differently too. So, like, you know, the Twitter breach, the public's like, okay. Well, that's a social media account. But, like, a credit reporting financial account is, like, much more serious to everyone. So I'm curious to know. Do you have children?

(Dan Conrad at 00:38:54)
Yes.

(Joel Beasley at 00:38:56)
Okay. So what are your thoughts having children and having the experience of having been a child? What are you—

(Dan Conrad at 00:39:02)
I was never a child.

(Joel Beasley at 00:39:03)
Never a child?

(Dan Conrad at 00:39:05)
I was born at the age of 34.

(Joel Beasley at 00:39:07)
Benjamin Button style. What are your thoughts on these kids that, like, did the Twitter hacks or just the kids that are hacking in general? Like, should they be going to prison for that?

(Dan Conrad at 00:39:21)
I don't know. That's a good question. You know, there's an inquisitiveness there of somebody hand you something and I need to take it apart and figure out how it works. How do you teach that? And should we criminalize that, you know, that need for knowledge? But then maybe there's an ethics side of it as well that they just missed out on, that they need to learn what they should and shouldn't do with that. So I don't know. I don't think we should criminalize it. Should we capitalize on it, maybe? Yeah. You know, you look, other countries are doing great things in the area of cybersecurity, but teaching people to do things the right way, maybe. We've heard a lot of different countries teaching their military things like cybersecurity defenses and secure development and technologies like that. But, you know, we'd always say, oh, you've got to blame the developers. They've got to develop it from a secure mentality. Well, that's not really the way it works.

(Joel Beasley at 00:40:18)
No. That's not how it works. You get curious people and they're curious. Like, I was lucky. Right? Because I got curious about engineering very young and software development. And around 12, 13, you know, I had a—there was a downstairs computer and an upstairs computer and my sisters used the downstairs one. So I took it upon myself to, like, learn how to do the hacking and, you know, playing around within my own networks and trying things. And if I couldn't hack, I'd go downstairs and figure out, like, what's wrong and just doing that, like, curiosity ripping apart the engine type concept, but with technology.

(Dan Conrad at 00:40:57)
In a harmless environment. Right?

(Joel Beasley at 00:40:59)
A harmless environment. But then it's like, okay, well, does it work outside of my network? Like, now that I figured out how to do it—but you don't have the mental maturity at those—at these younger ages. I would argue even 18, you don't have the mental maturity to really understand things. But, you know, I think what you said, you alluded to almost maybe there's, like, a different type of punishment. Rather than throwing them in the county jail or, like, a federal prison, maybe we take those kids and put them in some other type of program. And then I also heavily agree with you that it's highly dependent on the demeanor, the behavior, and the personality of the individual themselves. Like, some people, you can just tell that they're up to no good, and that is their, like, life story. And so, you know—

(Dan Conrad at 00:41:46)
Well, but even to look back, I thank a lot of people for not giving up on me when I did, you know, lack of ethics or whatever you call it. But, you know, we all did stupid things when we were younger, and that's part of growing and maturing. And that's just, you know, a lack of maturity. You know, what's the "Catch Me If You Can" guy, you know? Now he teaches the FBI. So, you know, he was young and saw what he could get away with and didn't really realize the repercussions for that. And who he was affecting. I mean, that's a big part of it. You know, when you're taking information, if you're stealing it from a company, and then you're selling it to another country or organization to cause malicious, you know, whatever to happen to the people that you stole it from, you gotta realize that, you know, what are you actually doing here? You're not just making money on the side. You're, you know, you're really hurting people.

(Joel Beasley at 00:42:34)
Yeah. And then it depends on age too because as, you know, a 32-year-old, if I am stealing from a company and selling to a government, that's very different than, like, if I was 18 and maybe influenced by this circle of people who somehow began to influence me. You just don't have the mental capacities at those ages to—like, you do have a greater understanding than when you're, like, 10 when you're 18. Right. But you definitely don't have mature decision-making. It's like an AI algorithm that's, like, half-baked. It's, like, it can do some things, but it's not good.

(Dan Conrad at 00:43:05)
Exactly.

(Joel Beasley at 00:43:06)
Some things, but it's not good.

(Dan Conrad at 00:43:09)
Yeah. I mean, the only way to teach that is through time and maturity. Right? And maturity doesn't happen at the flick of a switch. You can't teach that sort of thing.

(Joel Beasley at 00:43:17)
No. And then it's even more counterintuitive because your entire path through it, you're always the most mature you've always been. And so you always feel like you're the most mature you've always been, and you always think you're the most capable. And you actually are. You're just not as mature as you will become. And so it's, like, a really interesting—like, I was the other night, I was thinking some of the people that I interacted with when I was, like, 21 selling technology and everything like that, I was like, wow, they were definitely mature enough to realize I was 21 and, like, let me have that flexibility of being a 21-year-old in my behavior because, you know, not like I did anything bad, just, you know, jokes you make or things you say, just things you do when you're young, right, that just you wouldn't do when you're older and have a better understanding of life.

(Dan Conrad at 00:44:06)
Yeah. But I think you should never give up on that. You should never make people wonder or get to a point where they're not really sure what you're gonna say next. Right? Well—

(Joel Beasley at 00:44:13) That's the art of life, right? You have to go through the stages of maturity, but you still have to retain some of those childlike excitement and quality. I love when I get to talk to executives or just people that are older, farther along in their career than I am, and they're still excited and they're still passionate, because to me, that's the win.

(Joel Beasley at 00:44:35) It's like they got through all of the junk that jades 80% of the people, but yet they still held on. And I think that's a recurring trait of people who I consider, subjectively, successful.

(Dan Conrad at 00:44:50) Yeah, I'm truly excited. Not, you know, "We do want to say" marketing excited, right, where you're really excited about—you want to say truly, let me show you something cool here. Let me, you know, sometimes let me tell you why this is cool, or that kind of stuff.

(Dan Conrad at 00:45:03) So we're always looking for people to do that as well. And we've got some great people that can get excited about our technology and kind of link some cool things together that you didn't think would work. And we've kind of found with this work from home that we're doing, you know, everybody's working from home now, and we're getting different groups of collaborators together at weird times and weird scenarios, and all of a sudden these ideas pop up. And it's just an amazing process to see. You know, like, I'd never thought about doing it that way. I didn't realize it would be that easy. Oh, they all use the same protocol. Let's do that. So it's really interesting to see.

(Joel Beasley at 00:45:36) Were you able to make any progress with your soapboxing on getting your families to get into the 1Password or LastPass type of things?

(Dan Conrad at 00:45:46) So the progress that I've made is that I take my father, all of his passwords, and I manage all of his accounts for him. So he's got a couple passwords that don't meet—that my password vault will tell me, yeah, you shouldn't be using this password. But so I take care of his. But, you know, honestly, the rest of the family, I don't think they get the message. Maybe I just kind of turned the world loose on them here.

(Dan Conrad at 00:46:10) But as far as that goes, you know, I still like to keep reiterating, and I've done it—I know they think I get a little bit nuts on this, but, you know, let me explain to you how dangerous this is. And, you know, even to the point of, you're accessing your 401(k)s from your phone, let me see this. So things like that, it just, you know, it baffles me.

(Joel Beasley at 00:46:32) And at the same time, though, it's getting better because the other day I got an alert from Chrome that one of the passwords I used was compromised. But I never enabled Chrome to do that. I never asked them to do it. I'm not upset about it. I'm actually pretty excited, but it was really cool that it was baked in. And it's like, hey, this password that you're using was detected in one of the breaches.

(Dan Conrad at 00:46:57) That's actually a service. And we, you know, we have a user self-service password reset tool, and one of the new features of that is we subscribe to that service for you. So when one of your users resets an Active Directory password, it bounces off that service and says, this is a password that was used in a breach. You should choose something different. Or guess again, you know? Oh, nice. And then somebody adds an exclamation point at the end of it. There we go. That's secure.

(Joel Beasley at 00:47:21) So you guys focus on that Active Directory line of business. You don't have a consumer competing tool to LastPass or 1Password, right?

(Dan Conrad at 00:47:29) No, no. I mean, we have—we've got a privileged access management, which is a password vault, a session management appliance right now. Within that, we actually have a personal password vault. So the users of that appliance can actually vault corporate passwords and things like that. But it's not like LastPass or, you know, RoboForm or any of those. It's not designed—you could use it that way, but it doesn't inject credentials the way those solutions do.

(Joel Beasley at 00:47:53) I feel better now because I'm talking about how great these individual personal password managers are. I'm happy that you don't do that for the consumer sales, right?

(Dan Conrad at 00:48:03) Yeah. I tell people that, you know, our new password policy is that you have to have six forward characters, and you have to have at least eight—six backspaces in your password. So use all of the backspaces that you want to get your password right.

(Joel Beasley at 00:48:17) Wait, I can't tell if you're being serious. Like, you could put a backspace in a password? Or what do you mean by backspace?

(Dan Conrad at 00:48:23) No, no, you can't.

(Joel Beasley at 00:48:24) So you're messing with my head here.

(Dan Conrad at 00:48:28) Yeah. So it requires six forward characters and six backward characters, which means we take blank passwords.

(Joel Beasley at 00:48:33) Oh my god, you just B-Up-A'd me. So we were talking about this the other day with my producer. Like, in the video games, whenever there's new people in there, they'd be like, oh yeah, it's a cheat code. Hit B-Up-A, and that exits the game. And I'm like, I have to follow you. I'm like, alright, six forward spaces. Alright. Six backspaces. Yeah.

(Dan Conrad at 00:48:52) And then hit Enter.

(Joel Beasley at 00:48:53) You got me.

(Dan Conrad at 00:48:53) And then, hey, yeah. Click Next.

(Joel Beasley at 00:48:55) Hit Enter. You got me, my friend.

(Dan Conrad at 00:49:00) Yeah. This is—

(Joel Beasley at 00:49:00) This is good. Oh, man.

(Dan Conrad at 00:49:02) Mission accomplished.

(Joel Beasley at 00:49:04) Yeah. So do you usually commute into work? Are you mostly—

(Dan Conrad at 00:49:09) No, no. I mean, I've—yeah, like I said, I went three years without going into an office, but most of the company—much of the company that are like me, you live and work anywhere. So pre-Corona, I spend probably three and a half weeks a month traveling to customer sites and things like that. Oh, cool. Yeah.

(Dan Conrad at 00:49:27) Yeah. That's when you can be face to face. This is good stuff. We can get a lot accomplished, and it's probably more effective use of your time. It's very rewarding to meet people face to face and discuss problems in a very give and take. We can sit in a conference room, and you can see facial acceptance of your solutions or eyes rolling or things like that. So I don't know how many sessions I've done where I'm sure half the people were asleep. But, you know, just get CPE credit and get out of here or something. So—

(Joel Beasley at 00:49:57) That's funny. That was actually one of the first comments, or first five-star reviews we ever got on the podcast. This individual said, I turned this podcast on to listen to something that would make me fall asleep at night. And he was like, warning, don't listen to this podcast at night. It'll keep you up. And I was like, that's exciting. Yeah. Because he came in—yeah, it was going to be boring, and I was like, I'll take it with a five-star review. Right?

(Dan Conrad at 00:50:22) You could probably just play thunderstorms in the background. Thunderstorm, rain music, tropical forest, or something.

(Joel Beasley at 00:50:28) Can you hear it? Can you hear the thunderstorm happening right now?

(Dan Conrad at 00:50:31) Oh, no, I can't. I didn't know what to tell you. Yeah.

(Joel Beasley at 00:50:33) I know. There was two or three big cracks of lightning. I was thinking to myself, we've got to go listen to the recording after this to hear if it came through or not.

(Dan Conrad at 00:50:40) Yeah. I didn't hear it. Yeah.

(Joel Beasley at 00:50:41) Florida in the summers, or at least I live in a vacation town. It's near Tampa, Florida. But like clockwork, 2:00 to 3:00 in summer afternoons, it's a rainstorm for an hour or two.

(Dan Conrad at 00:50:55) Yeah, yeah. Very refreshing.

(Joel Beasley at 00:50:57) Yes. So, dude, we did it, my friend. We made a podcast.

(Dan Conrad at 00:51:02) Alright.

(Joel Beasley at 00:51:03) How do you feel?

(Dan Conrad at 00:51:03) Enjoyed it. Yeah. It's an interesting, really interesting format. You know, I do a few sessions and a lot of the folks want to do a practice run. I don't do practice runs for anything because I think impromptu conversations are much more valuable for anybody listening. Yeah. And I'm sure you listen to a lot of podcasts and you can tell when they're not impromptu conversations. It's a memorized recorded—

(Joel Beasley at 00:51:25) Well, think about it like this too. You, as a human going throughout your day, you are 99% of your entire experience is impromptu conversations. It's unnatural to listen to the scripted conversation between two people. Like, it's different because when you have the context of, like, this is a sitcom, which—you can see sitcoms have become incredibly unpopular. Like, they used to be the thing and now no one's watching sitcoms. Everyone's watching cinematic because they want the storylines, the longer form storylines. So it's just, you know, paying attention to what humans like, what I want to listen to. I don't want to listen to a scripted interview.

(Dan Conrad at 00:52:06) Right. That's so fun. I know you said it slices, Joel, but does it dice? You know?

(Joel Beasley at 00:52:11) Well, I'm glad you asked because our marketing team gave me these three points to talk about. Step one, we've got the sharpest blades in the industry.

(Dan Conrad at 00:52:19) That's right. That's right. Yep. That's the ShamWow commercial, right?

(Joel Beasley at 00:52:24) The ShamWow commercial. Excellent. Well, I really appreciate it, and I look forward—we'll have you on again next year, and we'll catch up, and maybe you'll have some songs to play us.

(Dan Conrad at 00:52:37) Yeah. Exactly. Alright.

(Joel Beasley at 00:52:39) Thank you.

(Dan Conrad at 00:52:40) Pump in the water. Alright.

(Joel Beasley at 00:52:41) Thank you so much, Dan. See you, guys.

(Dan Conrad at 00:52:43) Thank you. Bye.

(Joel Beasley at 00:52:46) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.