Episode 322 ·

Tim Woods - VP of Technology Alliances at FireMon

Today we are talking to Tim Woods, the VP of Technology Alliances at FireMon.  And we discuss how FireMon is bringing simplicity to enterprise cybersecurity, why you should never be afraid to make mistakes, and what the future looks like for enterprise network security.

All of this, right here, right now, on the Modern CTO Podcast!

Check them out now at FireMon.com!

About Tim:

Tim Woods brings more than 20 years of systems engineering leadership experience to his role as VP of technology alliances at FireMon, where he has global responsibility for developing and growing the relationships with FireMon’s technology partners. Tim’s personal passion is educating others on new and emerging technologies, with a desire to build strong organizational security postures.

About FireMon:

FireMon is the only agile network security policy platform for firewalls and cloud security groups providing the fastest way to streamline network security policy management, which is one of the biggest impediments to IT and enterprise agility. Since creating the first-ever network security policy management solution, FireMon has delivered command and control over complex network security infrastructures for more than 1,700 customers located in nearly 70 countries around the world.

Links Mentioned:

The Future of Network Security Report

The Future of Network Security Infographic

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Tim Woods, the VP of Technology Alliances at FireMon, and we discuss how FireMon is bringing simplicity to enterprise cybersecurity, why you should never be afraid to make mistakes, and what the future looks like for enterprise network security. All of this right here, right now on the Modern CTO Podcast. Here we go. This is the Modern CTO Podcast.

(Joel Beasley at 00:00:35) Man, this is great, dude. So we're just going to hang out and chat, like if we're hanging out at lunch or something. I'm just super interested in what you guys are doing and who you are. But I was curious, can you give me the ten second overview of FireMon?

(Tim Woods at 00:00:51) Sure. You know, a lot of people don't know FireMon has been around for better part of fifteen years, over fifteen years, and we're a leader in the network security policy management space. We affectionately call it agile NSPM.

(Tim Woods at 00:01:03) The agility piece comes into play to where we're helping enterprises break down some of those barriers to agility, which there's a lot of them. But we extend visibility, continuous compliance—I like to say proactive compliance is a big part of it—change process automation. And I think at the end of the day, we always have an eye on risk too, right? It's like, how can I help you identify that you're managing risk to a level that's acceptable by the business and things like that? So markers that you can kind of look at very quickly and determine, you know, where am I at today? What does my risk level look like today? Things like that. So, yeah, it's been a great ride. We're very humbled because we have a lot of very large enterprises that are trusting us to help them with their security journey, so to speak.

(Joel Beasley at 00:01:50) So when you do that, when you do that analysis—like, here's where you are today, your current risk—then do you show them a forward picture of here's where you want to be and this is how we can get there, or are you just the first part, just the analysis part?

(Tim Woods at 00:02:05) It's kind of both, right? I think in any journey, you kind of—where am I at today? Where do I want to go tomorrow? And how do, once I get there, you know, how do I stay there? And how am I going to quantify the return on my investment? You know, I get the luxury of talking to a lot of really, really smart people, and I'm humbled by that. CISOs, security directors, and things like that, and they're very interested—and even more so today—you know, they have so many things in their repertoire, so many things in their gun belt, so to speak, that they're trying to bring to bear on the challenges that they're faced with. And every time they adopt another one, you know, there's care and feeding that goes along with that. You can have the best technology on the planet, but your people have to use that technology effectively or you're not going to get that return back.

(Tim Woods at 00:02:51) And so right now, they're trying to consolidate that. They feel like they have things that are—the worst word in the world to them is shelfware, right? I don't want to invest in something that's not going to give me the return. But to answer your question, yeah, I want to be able to know kind of where I'm at today, and we kind of help you do that. We use something called a security concern index score that kind of gives you—it doesn't mean anything other than it helps you build a baseline of kind of where you're at today. And then I have something to trend against, you know, as I'm getting better at compliance, as I'm getting better at managing risk, as I'm getting better at managing change. How am I doing from an SCI score perspective? So I think you have to build that baseline first. Where am I at? And am I getting better or worse? Are the things that I'm doing making an impact, right, on a day in, day out basis?

(Joel Beasley at 00:03:41) You seem pretty passionate about this.

(Tim Woods at 00:03:43) I am. I've been here a long time, and there's a lot of satisfaction when you can help move the needle within an organization to truly help them become better at either managing risk or having better visibility, especially today. I mean, when you think about what they're faced with today, in this new—I call it the hybrid expanse—there's a lot of things going on, a lot of complexity. And that's my platform. What can I help you—how can I help you to combat complexity? Because I think that's one of the biggest adversaries that we're faced with on a day to day. As complexity goes up, the probability of human error goes up. The probability of risk goes up. The probability of misconfiguration goes up.

(Tim Woods at 00:04:30) There's a lot of things. And there's always a certain amount of complexity, what I call good inherent complexity, in any good security architecture or implementation. But what we find ourselves today is with too much unnecessary complexity, overly permissive policies, overly permissive rules, way more—especially if you're trying to embrace zero trust or you have a zero trust strategy—and it's just the opposite. You know, zero trust doesn't mean zero trust. It means allowing some trust.

(Tim Woods at 00:05:00) But in today's policies, what we find typically is way too many overly permissive policies that are allowing way more access than what the company really needs to achieve the business.

(Joel Beasley at 00:05:15) Now, your ability to help—like you said, these CISOs, they have so much—there's so much complexity, there's overly permissive policies. Your ability as a person, though, I'm always interested in who Tim is. And you seem to have this knack for taking these complicated things and boiling them down to something simple. And I saw in your history that you used to be in the Navy. And I found, just like a personal connection through growing up with my dad being in the Air Force and getting to meet other people that have military type backgrounds, that they tend to be pretty good at focusing and sorting through things at a rapid pace. Do you think that your experience in the Navy helped shape you in this way?

(Tim Woods at 00:05:58) It definitely carved out my career path, right? I was in Naval Intelligence for better part of eight years. Enjoyed it. You know, I think the question I always ask people, when I meet other veterans and things like that, it's like, hey, would you do it again, right? And, you know, my answer is, yeah, I'd do it again in a heartbeat. It was a phenomenal experience for me, and it set my path for the future as well. But being involved in that, you know, we—I was—we use the term, you know, and you've heard this—loose lips sink ships. But what it really boils down to is you weren't given access to information unless you had a need to know, right? You had to have a need to know in order to access that information.

(Tim Woods at 00:06:43) Otherwise, you just didn't get access to that information. Simple as that. And so again, even today in some of today's security in depth type strategies, you know, in zero trust—I go back to zero trust as a strategy because it's not a standard, it's a strategy—but I relate a lot of what people are trying to achieve with zero trust with what I experienced during my time serving in the Naval Security Group as well. So, yeah, we processed things quickly. We were always working around the clock. I mean, there was—it was a 24 hour clock that we wore, and we were always on. So it was a fun experience and, yeah, would definitely go back and do it again. It taught me a lot.

(Joel Beasley at 00:07:26) So your official title, you were cryptologic technician. Am I saying that correctly?

(Tim Woods at 00:07:32) That's right. Yeah. Cryptologic technician in the maintenance branch. There's cryptologic—the cryptologic field in the Naval Security Group spans a lot. There's cryptologic technicians, intelligence operators, receivers, and we all have our specialty so to speak within the cryptology community there. So, but yeah, we learned ciphers and some of the cryptology technology and got to work on a lot of really cool equipment as well. Yeah, for sure.

(Joel Beasley at 00:08:01) That area of knowledge in the universe, I grazed it for like a weekend, like understanding these concepts. And I was just blown away by how interesting—and they're basically, like, if you like puzzles, that is your playground as a professional, right?

(Tim Woods at 00:08:21) Oh, it was fun. I mean, and if I put it in perspective, even when I joined back in the day—and I'm not going to date myself too much here—but I will say that I was working on equipment that would take up a couple of racks just for what I will call the transmitter and the receiver. You know, that piece of cryptology that I had on my end that connected to somebody else's piece of cryptology equipment on the other end, and we had to change ciphers and we had to synchronize when we changed ciphers and stuff like that. But literally that equipment, that technology would take up an entire rack like the height of a human. And by the time I got out, just in that small eight year span, you know, we were working on things like that. So I went from troubleshooting to the component level. By the time I got out, it was push a button, oh it's A1, so now we need to replace this board, you know, things like that. So that's two extremes that happened in an eight year span and very fast. And mind you, I mean the equipment was already in use that I was trained on initially. Now I was trained on new equipment. But today, you know, we fit that on a chip. That chip goes in an iPhone. It goes in a watch. It's just amazing.

(Tim Woods at 00:09:31) You have cryptographic equipment the size of a stamp that goes on a computer board today. And that once took—like anything, I mean, it just took a lot of space.

(Joel Beasley at 00:09:45) Can I check—I like to bounce ideas and concepts, things that I'm thinking about off people sometimes, like, on a personal level? Is that cool? Can I detour the conversation for some time?

(Tim Woods at 00:09:54) Yeah. Absolutely. Let's go.

(Joel Beasley at 00:09:56) So I get to talk to people of all experience levels. So the 20 year old doing the startup to the person, you know, in their late sixties, seventies doing—they're, like, on the brink of retiring, right? I get the entire spectrum. And then for myself, just to give you some context, I'm 33. So I'm kind of in the middle there, right? And one of the things that I'm experiencing now—and what brought this up or made me think about this is—I noticed that people that are probably over their mid forties, they constantly use this phrase, I don't want to date myself, when I'm talking with them.

(Tim Woods at 00:10:36) Yeah. Yeah.

(Joel Beasley at 00:10:36) It's like standard.

(Tim Woods at 00:10:38) When I was—

(Joel Beasley at 00:10:39) When I was 20, all I wanted to do was be older. Like, I just wanted to be older so bad. I was rushing for it. Like, I was running as fast as I could. Like, just let me be old. Like, let me get farther in life, and I just want these. And then I turned 30, right? And now I'm having kids, and I've watched how fast they go from zero to three, or zero to four, you know, because they're under five years old. But all of a sudden, I've noticed myself personally in the past, I don't know, six or eight months where I don't want things to speed up anymore. Like, I'm happy at the rate that they're progressing. I don't want to live farther up in the future anymore and rush it. I'm like, this goes by fast and I really kind of want to enjoy this time. Like, not to be lazy, it's just like I noticed my mindset shifting.

(Joel Beasley at 00:11:26) So the question, because you're ahead of me, is this—the thing I want from you is this. Did you experience that? Like, did you experience that wanting to be older and then you got to a certain point, maybe in your thirties, and then you were just like, oh, okay. I kind of want it to—I like this. This is good. Or no?

(Tim Woods at 00:11:47) You know, everything's relative, right? From where you're at in a given time, space and time. Definitely, when I was a younger man, I wanted to be older as well. I remember I joined the Navy right out of high school, and it was good to me. I had a lot of vocational training that paid for my college and all of that. But I remember looking at guys that were 24 years old, and I'm thinking, God, you know, here I am. I'm 19, 20 years old. They're 24, and they know so much, you know. And here I am well down my journey, and I have a lot of things that take up my time. I'm a country boy. I live in the country. We have a nice little ranch and cows and horses and things like that. And so we love to kind of put technology on hold on the weekends and enjoy the outdoors.

(Tim Woods at 00:12:42) Have a 14 year old boy that I get to, you know, live life through his eyes too, vicariously. And so we do all kinds of things and big outdoors people. But, and gamers too. He loves, you know, I still get to—I still get to go against him on the Xbox, which is fun. But, yeah, you know, I've learned that the clock does seem to speed up. I just—I don't worry about the things I can't control. You know? I try to focus on the things that I can control, you know, as far as having a positive outcome. And don't worry too much about, you know, the hands of time moving quicker than I want them to. I think they definitely do though, as you get older. It just seems like they go by a lot quicker than they used to when you were younger. But you're absolutely right, when you were younger they couldn't go by quick enough. And as you get older, you are trying to slow them down. And we see that in a lot of different areas, even in the kids. You know, as the kids are growing up, you're like, oh my God, they're growing up too quick. I want to freeze them right here. But, yeah, they grow up way too fast.

(Tim Woods at 00:13:33) Everything kind of moves. But, you know, I also, like I was talking about the technology, I love to see advances in technology and the things that we've seen come to fruition during my age as well too. So, I mean, yeah, love it. I don't worry too much about it. I just—and I sure don't—I don't make any judgment calls anymore about what somebody knows or doesn't know. I mean, I've met some of these young IT professionals that have, you know, I don't go in there and say, you know, I've been there, seen that, done that. Some of these guys are just, oh, God. There's always a learning opportunity. They're so smart.

(Tim Woods at 00:14:12) Some of these young kids are so smart that are well into their cybersecurity type path or road or journey. And there's always an opportunity to learn. So I always look for those opportunities to learn. I don't care how old they are. It just blows me away sometimes how much some of them know.

(Joel Beasley at 00:14:30) Yeah. Well, they also have a leg up too. Like, for me, I had a huge advantage because my dad started teaching me at eight just so he could get his work done. He'd be like, alright, go play on this computer and do this just so he can go do his engineering work and keep me busy. And, yeah. So what happens is, you know, you have all that free time as a kid, right? So I grew up playing, experimenting, being on the Internet, you know, all through school. I mean, that's like a good decade plus of experience. So when you get out of high school, you know, you've got it. If you've self educated, you've got a decade of experience in a given category.

(Tim Woods at 00:15:04) Yeah. Yeah. No, I was kidding my son the other day. We were talking about something to do with cell phones or whatever. I said, you know, I said, you're lucky. I said, you're probably on your third cell phone already. You're 14. You're already on your third cell. I said, you know how old I was when I got my first cell phone?

(Tim Woods at 00:15:20) And, you know, he giggled. But yeah, no, we'd done, you know, we built our first computer together so that we could do, uh, you know, we could support the first Oculus Rift for the virtual reality type stuff. But I made sure that he had his sleeves rolled up and his fingers were deep into the construction of that PC. You know, we've been flying drones a lot lately and he's ready to go to the next, you know, first person view drone and things like that.

(Tim Woods at 00:15:45) So it's, you're right, they're immersed in technology at a young age and they just kind of gravitate toward it naturally too. I mean, they just consume it. I didn't have that technology at his age or wasn't exposed to it. And I think that when I joined the Navy, it's the first time that I was exposed to technology. Like, wow, this is a whole other world. This is an area that I didn't even know existed. And, you know, I just came alive, you know, for just another area having no idea what path that would set me on down the road. But it was amazing to me.

(Tim Woods at 00:16:24) I studied advanced electricity and electronics, and that's what led me down the path to cryptology. But yeah, it's great. But you're right, kids nowadays, they're already exposed to it, you know. But by the time they're out of diapers, they can already work up an iPhone. So that's crazy.

(Joel Beasley at 00:16:40) Oh, my daughter has been rocking and rolling on her Android kid tablet since, I don't know, two and a half. I mean, she can do everything.

(Tim Woods at 00:16:50) Oh, yeah.

(Joel Beasley at 00:16:50) She could operate that thing and pick her shows that she wanted before she could form sentences. Yep.

(Tim Woods at 00:16:56) Yep. Yeah. My oldest daughter, I mean, when she made the, I have four kids for the audience, for those in the audience that may be curious, but I have four. The oldest one is grown and has her own kids now. But when she made that relational link between the mouse and the cursor, it was just amazing. It was amazing to watch. You know, the it was just, you know, game on. The race was on at that point, you know, once they made that. Now it's the finger on the screen. You know, then it was the mouse. Now it's the finger.

(Joel Beasley at 00:17:24) You're a big outdoors person. In our—

(Tim Woods at 00:17:27) Love the outdoors.

(Joel Beasley at 00:17:28) In the prep call with our production team, I got a note that you had like a small chainsaw accident. And I was like, that's my type of person. Like he's an outdoors. We go camping. We love that. And I was just curious about, you know, when I find other people who do the outdoors thing, how do you, I guess the question would be, sometimes I see some people and they're so burnt out or on edge or they haven't spent enough time in nature. Sometimes I feel like the prescription for what their problem is is to just pick them up and throw them in the woods for a little bit. Because I wasn't always an outdoors person. And when I started going outdoors more, man, you know, I learned more hiking up a mountain than I learned from reading a hundred leadership books, you know, just because it's this personal experience that you're having. Have you do you ever sell people on nature?

(Tim Woods at 00:18:21) You know, I don't. I mean, I guess, the circle of friends that I hang around with outside of work, you know, we don't get as much. I mean, anybody that meets me for any length of time knows pretty quickly that I'm kind of an outdoors kind of guy. You know? And then I try to, I have a fine balance between technology and making sure that I spend enough time outdoors and things like that. But now the kids all grew up, you know, camping and, you know, I remember the first time I took the girls out camping and, you know, I bought them a, we did like a little rental cabin, you know, with a little pond outside and stuff like that. And the whole time we're there, it's like all they want to do is like, when are we going to set up the tent? I'm like, what do you mean? I got you a cabin. It's got an air conditioner. I think it's even got a TV. It's got this. And they're just like, let's, but where's the tent? And so we started tenting it from there on out.

(Tim Woods at 00:19:14) And, you know, it's just a better experience. I mean, you come away from it just, you know, I don't know, feeling more satisfied whenever you put that tent up, especially if it rains, if bad weather comes and your tent withstands the elements and you, you know, and you make it through the elements, you know, in your own little house that you constructed in the middle of the woods. So yeah, no, it's fun. I don't know, do I try to sell people on them? I'm more than happy to talk about it, you know, and talk about what we've done and where we've went, things like that. I enjoy, you know, enjoy camping, and we enjoy hiking. We go up, we're very close to Oklahoma, and we go up to Robbers Cave a lot and things like that where Jesse James supposedly hid out. But I'm a diver also. My son and I dive. My youngest daughter dives. And so we spend a lot of time, you know, above the surface, but we spend a good amount of time, you know, below the surface as well.

(Joel Beasley at 00:20:09) Nice. Nice. Yeah, I'm certified. I have my basic and then my nitrox certification. And yeah, I mean, I live in Florida. Like how can you not have fun diving if you were born and raised in Florida? It's like the thing to do, the beach, you know.

(Tim Woods at 00:20:24) Yeah, no, absolutely right. We loved it. My youngest wanted to get certified when she was 13 and she sucked me into it. And I was like, I'll, you know, I'll support you doing it. I don't know that that's going to be my thing, but, you know, it can be your thing. And she's like, no, you're going to do it with me. And so I did and got hooked. That's definitely an area that I try to, you know, I promote, you know, as long as you're comfortable doing it. I don't promote, you know, as you know, scuba, you need to be comfortable in your skin when you're underwater. You don't want to be, last thing you want to be is uncomfortable, you know, with a tank on your back.

(Joel Beasley at 00:21:00) We don't go diving with anxious people.

(Tim Woods at 00:21:01) Yeah. Yeah. No, no, not at all. So I don't recommend it. But as long as you're comfortable and, you know, you don't have a lot of anxiety underwater, then yeah, it can be a great life changing experience.

(Joel Beasley at 00:21:14) How can I help? Like what type of people, what do your customers look like? Like tell me about that. Yeah. What do your customers look like?

(Tim Woods at 00:21:22) Yeah. You know, traditionally our customers are very large enterprise where they have a lot of heterogeneity. They're usually global in nature, a lot of complexity, and they're trying to make sense of that. They're trying to get better visibility. Probably the number one thing that I hear is I need better visibility across my estate. Now it's across my hybrid estate. You know, it's not just on-prem anymore. It's going up into, they're adopting SD-WAN. You know, how do I, they're adopting SASE. How do I get visibility into my policies in SASE? How do I get visibility to my policies in the cloud? Both my native policies and virtually inserted enforcement point technologies. How do I get a good view across my entire hybrid expanse and also when things change, right? I need to be on top of when something changes. I need to be able to very quickly assess, did that change have any type of impact either on my compliance posture, my business posture, my security posture, you know, and how do I know? There's some basic questions, you know, that need to be answered anytime a change takes place, right? It's like, did I expect the change? Did the change have a negative impact? Do I need to do something, right? Do I need to go remediate that change? Or do I need to back that change out?

(Tim Woods at 00:22:46) And that's reactively, right? I always like to say I want to be faster than the change within the environment for my customers, right? And so I want to be able to analyze proposed change in the context of the policy that it's destined for and try to head off the problem before it becomes a problem. And so if you can take that proposed change and put it in the context of the policy, it doesn't do a lot of good to analyze it outside the context of the policy that it's destined for. So you need to kind of be able to, we're able to take a policy and sandbox it, insert the change, and then analyze that prior to implementation so that we can say, hey, you can do this, but here's what's going to be the potential impact here. You know, you're either going to break a compliance control or you're going to increase risk by X, or you're fixing to allow something that's a big no-no. You know, somebody puts something in that allows a clear text protocol from the inside to the outside or something like that. Or it opens up an S3 bucket, you know, if you do that, if you make this configuration change or something like that. So being able to do that before I shoot myself in the foot, which is the analogy that I always use, I want to try to keep myself from hurting myself. Then that's better. Reactively is good. You know, that's still important. I want to be able to see change. And when change happens in, in today's world and in the hybrid landscape, the hybrid real estate, change happens very quickly. It's very dynamic. How do I analyze that change when it happens? But then also recognize that change, but then also how can I get in front of change? How can I be faster than change to help me take that proactive stance? And I think in anybody's journey, when I look at the enterprise journey, their digital transformation journey or their cloud first journeys or whatever, that's where I want to help them get to is how can I, from a change process automation perspective, how can I leverage automation to my advantage so that I can be faster than change, if that makes sense?

(Joel Beasley at 00:24:53) Oh, I've got so many questions, Tim. Alright, I had to write them down. Okay. The first thing I want to clear up is policy. The word policy is like model. Super ambiguous, right? Are these AWS policies, firewall policies? Where, what type of policies do you manage?

(Tim Woods at 00:25:09) So I call it enforcement policies, security enforcement policies, and they're everywhere, right? I mean, when I, again, as I, if I'm looking on-prem, you know, I've got traditional firewalls. I hate the term legacy because it tends to bring up, it's not a bad word, but people tend to put a bad, you know, it's like Tim's legacy.

(Joel Beasley at 00:25:30) You know, like failing old. People don't like failing old.

(Tim Woods at 00:25:32) No, no. You know, it's legacy. But legacy is here and legacy still has a very valuable place in the constructs of our world today and in the constructs of the hybrid network. And we're going to be in a hybrid state for a very long time, very, very, very, very long time. But from the ground to the cloud, there's a lot of policies. And here's what I tell people is to be reality. If I'm being brutally honest with myself, and I'm always trying to get people to be brutally honest with themselves, if you're going to have effective changes, you got to really kind of score yourself and say, if I've done a bad job managing my policies just on-prem and now my policies are expanding both, you know, enforcement policies in my SD-WAN arena, enforcement policies in my SASE cloud, if I'm embracing SASE policies in the cloud. And yes, you're right. There's native controls or native security controls, native security groups, VPC rules, and now there's, you know, both Amazon and Azure both have their own virtually inserted firewalls or virtual firewalls as well or cloud based firewalls. Zscaler, a really big technology partner, you know, they have an advanced cloud firewall in the middle of their SASE cloud. So there's policies up and down the stack. But if I've done a bad job of managing the hygiene around the traditional firewalls that are just on-prem, what's my true expectation of doing a good job of managing even more policies across a wider expanse? You know, how am I going to get my arms around that? And that's the journey that I want to help people go down. That's the journey that I want to help people take to say, how am I going to get my arms around this bigger thing and do a good job of managing all those policies? So yeah, you hear the term policy a lot. When we hear the term, when we talk about the term policy, we're talking about security enforcement policies that are helping to control access. You know, if I'm constructing or trying to put together a zero trust strategy, you know, you're going to use, you know, a big part of zero trust, of course, is identity management. Big part of, but network security enforcement is also a big part of it. And being able to establish those zones of controls, those areas that I'm going to define who has access, how big those zones are, and who has access, whether it's north-south or whether it's east-west, whether we're talking about segmentation or microsegmentation. I still have to define my zones and determine who has access into that zone, who am I restricting out of that zone. Because if I'm opening that thing up, then it's just the opposite of what I'm trying to achieve. So anyway, that's what policies mean to us. It's network security enforcement policies.

(Joel Beasley at 00:28:21) So I can have like lots of segments or pieces of a network, and you define them as zones, and you help control the access in and out of those zones.

(Tim Woods at 00:28:30) That's right. We normalize or homogenize the policies to a common view regardless of what the vendor is. Right. We talked about the acceleration of heterogeneity. There's a lot of heterogeneity in our, in the type, you asked me what our customers look like. A lot of heterogeneity, meaning that they have a lot of technologies, a lot of enforcement technologies up and down their stack. And so how can I give a common view that looks the same for all of those, for all of those technologies, right? How can I give a single, I want to provide that single lens or that, I hesitate to use the term common pane of glass, but that's really what I'm doing. I'm giving you a common viewpoint or a common lens into all of those policies across all those different vendors. So I'm trying to give you a more homogeneous view of that.

(Joel Beasley at 00:29:17) That's amazing. You're this, you're an abstraction. You're a policy abstraction.

(Tim Woods at 00:29:21) Yeah. Definitely a policy abstraction.

(Joel Beasley at 00:29:23) That's right. Ruby, it's like you, it's like a DSL, like a domain specific, like you have this new language that helps you control all these sub-languages that have all these commonalities.

(Tim Woods at 00:29:33) That's correct.

(Joel Beasley at 00:29:34) That's brilliant. That's going to win. You guys must be doing well.

(Tim Woods at 00:29:37) We are doing well. I mean, we're doing well. And, I mean, like I said, customers are, you know, I think there's a strong appreciation. I think the other area that is growing also around the same thing is not only, it's not only homogenizing that view into those policies, but it's also being to, it's important that we understand that we're not the center of the universe and that there are a lot of other security technologies out there that you have to integrate with. And so what's becoming also important for our customers is the strength of the APIs, the commitment that the company has to their API sets in order to easily integrate with all the other technologies that have been deployed within their organization.

(Tim Woods at 00:30:21) So can I enrich — can my data enrich one of the other technologies, or can that technology enrich my data in order to raise the total value of my solutions across my organization? So the power, the strength of the APIs is becoming more important, and people are just starting to understand that a lot better too. And customers are starting to interrogate their vendors more to say, what's your APIs look like? You know, for the first time ever, what's your commitment to the APIs? How much of your product is exposed via your APIs?

(Tim Woods at 00:30:57) You know, are they secure? How do you secure them? And what percentage of your product exposed? What percentage of your product functionality is exposed, you know, via your APIs?

(Joel Beasley at 00:31:08) That's brilliant. So I'm gonna reiterate it so I understand. And my background, seventeen years of software engineering, typically, I would build small products with teams, like small teams, like under 30, and I would sell those off. So while I've gotten to work and collaborate with enterprises, I've never held a senior management position inside of an enterprise. So that's a perspective I am lacking, the day to day task of those things.

(Joel Beasley at 00:31:32) But what I wanna get to is, okay, so let's give a hard scenario so I can understand, so I can know how excited I can get and connect you with people. So let's say you have your AWS servers and clusters and policies. You have your whole AWS infrastructure, right? And then you have, you know, like, let's say your firewalls or your policies. You have another group of technology over here. And then a third group of technology over here. So you've got these three different types of technologies. They all have their own version of security or policy management. And you're this abstraction that can help control all of them. Am I — so far, are we kinda tracking?

(Tim Woods at 00:32:12) Yeah. We're tracking. We're there.

(Joel Beasley at 00:32:14) So then, if I am hiring people or, you know, expanding my business, and I need to grant access to this new hire or I need to delegate to a manager so that he can get or she can get their team, these people in. So now, I have one place where I can go that can — I can plug people in and take people out and it'll, you know, filter down into the correct systems. Is this right?

(Tim Woods at 00:32:39) Correct. I mean, that's what we're — it usually takes place in what I call the ITSM world. You know, a ServiceNow ticket is generated, and that ticket is going to request that access that you need as managers. You know, you've got the new person. Sally comes on board, and Sally needs access to HR. So a couple of things could happen there if that request could trickle down into a system. We have an automated workflow system that we would interpret that request coming in. The people responsible, would not necessarily responsible for granting that access, would not necessarily have to be inside of that ITSM. They wouldn't even have to actually touch ServiceNow. They would see that request come up as a ticket within their own policy workflow system. They would look at that. They would grant it. More importantly, if it already follows the correct script or it follows the correct scenario, they could have it automatically enabled. It's like, hey, she's got the right credentials. It's part of our AAA or Active Directory. You know, she's just — they're just trying to add it to this group. So that's something that could be accelerated or flowed across the acceptance process rather than somebody manually having to get in there and say, okay, well, I need to go in and manually accept this. You know, one of the biggest things I hear, Joel, is I have my — I have my best people. You know, they come to FireMon, they say, how can you help me? These are the challenges that we have. And one of the things that I hear over and over and over again is I have my best people doing some very repetitive tasks, mundane tasks that's taking them away from the higher skilled activities that I hired them to do. How can I get some time back? You know, I'm looking to buy time in a bottle. Yes. You're right. I wanna be able — how can I get some time back in my day? And that's really what they're asking is, how can I help them to be more efficient so that I can give them more cycles to focus on the things that I need them to focus on and not these reoccurring mundane things that happen? And that's where automation comes into play. That's a lot of value that can be extracted in those things that are very repetitive and happen over and over again. So, yeah, you're talking about multiple systems that integrate, you know, using those APIs to communicate, to map out the different disciplines in the processes in order to achieve something that accelerates the approval process is a great example of one way that you can benefit.

(Joel Beasley at 00:35:09) I like that you bring that up about the smartest people because I was really agreeing with you. What happens, or at least what I've experienced, is you build trust with some of the smartest, brightest people. And then you're definitely gonna want those people, you know, to delegate who gets control through some of the smartest people. And then they end up becoming full time gatekeepers and all the — you're not getting all the creativity and the ingenuity and the innovation from them because they're gatekeeping. And so that's when automation can come in and really shine.

(Tim Woods at 00:35:43) You're absolutely right. Yeah. No. It definitely can. That's, you know, we've experienced also companies that have had failed attempts at automation. They come in a little bit — I don't wanna say soured, but with a little bit of a, you know, skeptical disposition to say, you know, we've already thrown some money at some of our automation attempts, and it really hasn't produced the fruits that we were looking for. So, FireMon, how can you help me? How can you make sure that I'm not just doing good money after bad? And so we start looking at some of those things. Right? I do look for the low hanging fruit. You know, where can I make a positive impact the quickest? And be — again, I go back to being brutally honest. What are the things that are gonna require a little more heavy lifting that may even, you know, that's gonna give me good returns down the road also? And what's my expectations of achieving those? And it goes back to the aligning the right people with the right process with the technology, right? It's that three pole Venn diagram or whatever you wanna call it. You know, you gotta make sure that you have the right people involved in the project. You gotta make sure that you've identified the right thing that you're trying to automate also. I'm not trying to automate something that's broken already. Right? I mean, it's gotta work. And then I gotta make sure that I'm using the right technology and that the people understand that technology. Again, I go back to what I said earlier. You can have the best technology on the planet, but if the people can't use it effectively or it's not scaling to your environment, then you're gonna have a problem before you get out of the gate.

(Joel Beasley at 00:37:15) Do you have any real world examples, some past customers? You can leave the name out if you want or you can include it.

(Tim Woods at 00:37:19) I've got a thousand stories. Let's see. Um, you know, we were working with a client. I will leave the — I'll leave the name out. But, you know, that's the other thing in our world. People don't always like to tell their security stories when they put their names to it. Right? Even when clients come to us sometimes and they say, hey, we need some help. We've had an impact. What they're really saying is we got breached, you know, and that's a bad word. The b word is a really, really bad word in our community. Right? So they don't want to advertise, although sometimes they're mandated by regulatory compliance initiatives and things like that. But anyway, we were engaged with a customer. This is a customer that anybody listening to this podcast would recognize. And they were drawn to one chart. They had our system up and running. It's collecting information, and they were drawn to this one chart that talked about policy complexity. And that's one of the things that we do. We try to analyze the policies to say how complex is it. And what we're really saying is, how promiscuous is that policy? How open is that policy? And people tend to put things in the rules that will make them overly permissive, like an "any" in the service field, to get a little more down in the weeds technical. And so they pointed to this chart and they said, why is this ranking this policy as complex? Why is this policy so high? So we said, well, let's click into it. And we follow kind of a one, uh, a two click, three click rule. You should be able to get to the underlying data within just a couple of clicks. Any more than that, then you're getting off chart. So, you know, with just a couple of clicks, we click on that policy, and it shows you here's the policy out of all the — here's all the policies and how they're ranked. You click on this, it brings up that policy. Then you click one more click, and it shows you the rules that are contributing to the complexity score. And in a rule, you can have what's called logical paths. You can have, you know, from point A to point B in source, destination, service, users, application, things like that. There's a lot of tuples within a security rule. But anyway, this particular rule was providing 4,000,000 logical paths through it. 4,000,000. And the rule right below it, the other one that had been identified was providing 2,000,000. They go, oh my — they stopped our meeting right there to go off and fix this. They go, we have to fix this right now. And what had happened there is they had put an overly permissive statement in the rule on purpose for troubleshooting and forgot about it. You know, it's like, hey, it's working. Now we need to go figure out, you know, what actual ports are being called here. We'll come back to this. And in the haste of the day and the other 15 priority ones that were on their plate, they started doing other things, gone and forgotten. This thing got buried, and then we were able to surface that for them very quickly. So those overly permissive rules can get buried. And if you don't have a way to surface them, then sometimes they can just lie there late until somebody takes advantage of them. You know, a bad actor comes in and takes advantage of an overly permissive rule, and then you're on the front page of The Wall Street Journal, which is where you don't wanna be.

(Joel Beasley at 00:40:38) You should have your marketing team design up some caricature, like a Marvel character that's called FireMon, and that character can save the day with policies.

(Tim Woods at 00:40:51) You know, I think at one time, I'm gonna say, you know, like I said, I've been at FireMon quite a while. I think we had some superhero personas that we had developed around, you know, making you a — making you a superhero. You know, making the IT people superheroes and stuff like that, creating those personas. So I think we actually —

(Joel Beasley at 00:41:09) FireMon sounds like a character.

(Tim Woods at 00:41:11) Yeah. Yeah.

(Joel Beasley at 00:41:13) So when you were first exploring working with FireMon, what sealed the deal? Was it the people, the culture? What made you wanna work there?

(Tim Woods at 00:41:22) Oh, it was definitely the people. We knew the owners of the company. The visionary, Jody Brasel, was the visionary, and Gary Fish had created the company and had spun it out of FishNet Security at the time. And we had long history with Gary. And so when Gary was ready to — at a very young — I was employee twelve, twelve, thirteen, fourteen. There was three of us that came over together, you know, thirteen years ago. And so, yeah, it was — you know, I was just excited to work with these guys. These were industry giants to me, and, you know, I couldn't have been more excited to join a small team of people to help launch to help carry this thing forward. So yeah.

(Joel Beasley at 00:42:04) Oh, it's pretty cool. So you were working at FishNet and this spun out?

(Tim Woods at 00:42:08) I was actually — no. I was actually working for another company. I was actually working for a company called Crossbeam, which was a virtualized hardware platform, which was a lot of fun, really cool technology. And I was very happy there doing really cool stuff and managing the security engineers. And then Gary came to us and said, hey, why don't y'all come over and join us? We're ready to kick this thing off and put sales at a higher level. And, you know, three of us came over together at the same time kinda. So, yeah, it was fun.

(Joel Beasley at 00:42:39) What's the future? Like, what's the next thing coming? What are you really excited about there?

(Tim Woods at 00:42:45) You know, it's combining more. Today, you know, we're giving visibility into — we're homogenizing those security policies, those network security policies across that entire hybrid expanse, you know, and that's only growing. People are — people, you know, we were looking at one of the — I think Forrester came out and said, you know, where are people going to spend? 62% of the security directors that they had surveyed said they were going to invest greater in some particular areas. And one of those areas was acceleration of cloud adoption. You know? And it's like, I thought it was already accelerated. You know? And it is. You know? It's accelerated to the extent that the business is moving faster than our ability to consistently honor some of the security requests, and we're helping companies with that. You know, how do I gain — one of the questions is, how do I gain parity with the speed of business? My business has definitely increased its acceleration. And so that's gonna continue. That's not stopping. They're not gonna say, okay, we'll wait on you. You know, security, y'all come catch up with me. You know? What happens is when the business outpaces your ability to secure it, they go around you. Right? Security can't be seen as an impediment to process. It can't be a blocker. It has to be an enabler. And so that's where we need to go. We need to have a paradigm shift in the way that we are securing those things. If cloud adoption is going to accelerate, if more workloads are going into the cloud, we have to make sure that we are aligned with the business to secure those things that are going into the cloud. And so those are the areas that we are investing heavily in, is making sure that we are with our customers on their cloud journey, that we are helping them to enable security along that journey, along their digital transformation and their cloud first strategies that I talked about earlier, making sure that they do have parity with the speed of the business, that we do have a centralized security policy that is in concert with the organization and that we don't have fragmentation where people are doing their own things, you know, across different areas of the business. And so being able to help them to enable them to make sure that, you know, their DevOps is aligned with their — that development is aligned with deployment, and deployment is aligned with security, that they do have strong APIs that they can leverage, that they are able to challenge, identify complexity, and then challenge complexity within these growing environments, that they do have the visibility that they need. And then, of course, you know, you've got people everywhere now. You know, the pandemic has definitely kinda distributed the workforce as if the perimeter wasn't already kinda blurred or grayed. You know? It's really blurred and grayed now, and maybe permanently. You know?

(Tim Woods at 00:45:45) We'll see at the end of this. But, you know, we have to be able to connect the people to the resources that they need to have access in order to do their job, and we need to do it securely and timely and consistently. And so that's the journey that we're on. That's where we're trying to help our customers is to make sure that we're helping them to have an impact in that digital transformation journey.

(Joel Beasley at 00:46:08) Yeah. And that's why I'm starting to understand more about how, you know, earlier you were talking about being brutally honest. I mean, that's so important, especially when dealing with something as critical as security. But we had done something new that we don't always do. We asked your sales team, or your sales leader or you or somebody, like, what are the top sales questions being asked? Because I wanted to better understand the product. Right? And I realized over here at my company, I'm like, alright, well, somebody wants to understand our product, they should just look at our top five sales questions. Right?

(Joel Beasley at 00:46:41) And so we did this for your episode, and it came out really well because one of the things I picked up on, and thank you to your team for getting that together. But one of the things that I picked up on was, I don't know how to talk about it. You had such beautiful words talking about, like, this parity of the speed of business. That was like a fancy way of saying they're, like, insecure because they grew too fast. But as I was reading through here, I felt like it was the same thing said in different ways. And that thing that was being said was, hey, our security is not great, can you help us with that? And that's hard. Because I was actually thinking about you and that. And I was like, that must be interesting how they train their sales people. Because you have people reaching out to you that are like, we're not happy with what we're currently doing, or we did it the wrong way. And I know this in a parallel universe, I guess, because people would come to me for, like, software rewrites, you know, when they got, like, venture capital funding, and they would be like, alright, yeah, we just Scotch taped it and bubble gum. And so some people were super shy about it. Right? And they were super shy about, like, letting someone in and seeing the mess that they've made. And some people were okay with it. But that takes a lot of special, like, hand-holding and a lot of special care and the right words to help people that don't necessarily have a great infrastructure to start talking about it. Does any of that make sense, or am I hitting on it?

(Tim Woods at 00:48:09) No, you're hitting on it. I mean, we see that when someone new to the IT organization, and it could be a senior person, they inherit, you know, people come and go. Right? Companies go on, but the company remains, but people come and go. But sometimes you're that new person coming on, and you inherit something from your predecessor. And maybe if we get back to the brutal honesty fact of it, maybe it's not as pretty as you would have hoped it was. So where do I start? You know, where do I start to dig in to make it better? And, yeah, we definitely talk to a lot of CIOs and security directors that are looking to say, I'm trying to make sense of this. We've had, I can't tell you how many security directors that have used us somewhere else, and they come over and they're like, hey, get in here as quick as you can. We need you. You know, we need you to help us. You did a great job for us here. Get in here and help me roll my sleeves up so I can make this, we have a mess. A lot of times you find policies, and you can relate to this from the code perspective, because, you know, there's nothing worse than inheriting somebody else's code and there's no documentation around the code. Right? Security policies are the same way. You take a security policy and you're like, well, why is this security rule in this policy? You know, I used to be, I could see a security policy and it may have, I remember the first time I saw a security policy, it had 2,000 rules. And I was like, God, how could anybody possibly use 2,000 rules in a policy? It just blows my mind, doesn't make sense. And now routinely, we see security policies that are 30,000, 40,000, 100,000, you know, security rules in them. But we also see policies that have 50% bloat, 40% bloat, rules that are technically inaccurate, technically not doing anything, technically allowing access or inadvertent access that doesn't need to be there. We just see all kinds of hygiene problems related to the policies themselves. So some of that is really easy. The technical mistakes, finding rules that are doing nothing, that are redundant or shadowed or duplicate, you know, that's just a mathematical equation. That's not even an analytical study. There's no analysis to do there other than running the mathematics against it. And so those are what I call, like, some day zero exercises that we can help to have an immediate impact. And then there's the longer term where we start looking at usage and how things are being used, what's being used the most, what's being used the least, what's not being used at all. And if it's not being used at all, it's not that it's a technical mistake, but if it's not being used at all, why is it there? But if there's no documentation, there's no context related to that access, you know, then there's this fear of, well, do I really want to get rid of that? You know, what if somebody does need that? How do I, you know, and so there's this fear. So from a top down, it really works both ways. You've got to give your people the tools they need to analyze the policies to get them cleaned up. But then also, management has to be able to empower them to say, hey, go clean it up. Get rid of this. Get rid of the overly permissive nature of the policy. If we accidentally kill something, it's okay. We'll put it back. But when there's no context, you either have to do nothing to it, which, you know, complacency is, I said complexity was our biggest adversary. Complacency is a big adversary also. But if I do nothing, that's worse than doing something, I think. And so you need to go and you either have to go and run down the history of this rule, which can be a terrible time-consuming process where you put documentation around it. And we're very big about capturing documentation at the time of the change and putting it in the context of the policy. Because when that QSA or that auditor comes in and he wants to know, or she wants to know, tell me now, Joe, tell me about this rule right here. What is this rule in here for? And when you can point to it and say, yeah, well, it was added for access to our new, you know, marketing database server, and it was updated blah blah blah day. And the next time, you know, it needs to be reviewed again for our PCI compliance standards. It needs to be reviewed again, within the next 30 days as well. So when you can point out that type of data and give that type of feedback to an auditor or quality security assessor, you know, that's very powerful. But too often, we find these policies with no substantial documentation and little to no context around them. And so trying to figure that out is a firewall manager's worst nightmare sometimes, especially if you've inherited. So if you're the new guy coming in and you have to make sense of it all.

(Joel Beasley at 00:53:03) Gotta build that mental model. It's very labor intensive. Yeah. Now, I want to talk a little bit about this beautiful infographic report that your PR team sent over. We'll put a link to it, so we don't have to go over the whole thing. But we'll put a link to it in the show notes so people can, I mean, I'm a sucker for, like, really well designed stuff, and so I thought it looked good. But I was curious, your perspective, you obviously had a hand in that report, because you're having to talk about it and you're sharing it with your customers and things of that nature. What's the one thing that you must read in that report? The one thing that's the most interesting thing to you?

(Tim Woods at 00:53:43) You know, it surfaced a lot of areas. Right? The report, we called it the Future of Network Security. We've done several of these surveys, and the reason we keep doing them is the customer is saying, really, I got a lot of value out of that last. We did a State of the Hybrid Cloud. We did a State of the Firewall, I think, maybe three years in a row. And this time, it was on the Future of Network Security. And we partnered with Pulse Q&A to deliver this and commission them to do this independently for us. And there was, you know, automation was surfaced, embracing zero trust, implementing SASE, addressing security dev misalignment, and then the last one was accelerating heterogeneity. Those were the areas that were surfaced in the report that we asked questions to these security professionals, about 500 of them. And that's after you throw out the things that don't qualify. But out of all of those, I think, you know, automation, understanding the impact that automation can have in your environment, and we've already kind of talked about this, you know, it can't be understated. It's being able to give time back in the day to my people, being able to make me more compliant and stay compliant. You know, I hate the fire drill when the company says, oh, we've got a big audit coming up, and everybody rushes to try to become compliant in getting ready for the assessor. The assessor comes in, and they pass their audit, you know, by the hair of their chinny chin chin. And then they just go right back to norm until the next time. Right? And then it's another fire drill, you know, or it's a crash diet exercise. And so, you know, I don't want to help companies say, how can I get in a posture to where my compliance can become continuous and dynamic, and I can stay there once I get there? Right? It's like we said at the very beginning. Here I am today. Here's where I want to be, and I want to stay here once I get there. And so one of the things that surfaced in the report was the importance of automation. The importance of automation around better consistency and security, better consistency and compliance, making my people more efficient, understanding change when it happens, and leveraging automation to benefit me in those areas. So, yeah, I would definitely, if we're giving links to this, you know, people can go access it, and it's on our site as well, and would solicit them to go take a look at it. Because it's really, out of all the reports we've done, it's really chock-full of some really good information.

(Joel Beasley at 00:56:20) So this most recent one, you did with Pulse Q&A?

(Tim Woods at 00:56:23) We did. Yep.

(Joel Beasley at 00:56:24) Dude, they're awesome. I've gotten to go out and meet, I think you say his name is Anand, but he's the CTO over there. But I've actually been in their physical offices in San Francisco.

(Tim Woods at 00:56:35) Awesome. Yeah. No, they did a great job, and there was a lot of good feedback. And, yeah, well, I'm quite sure that we'll be partnering with them in the future on some other things. Yeah. They're cool people as well.

(Joel Beasley at 00:56:46) When I saw them, I was like, hey, come on the podcast. I interviewed them, man, probably about two years ago. I was like, this is really cool what you're doing. And I think I had, like, tweeted at them or something when I was visiting in San Francisco. And they're like, come on by. So I just literally stopped by their office and got to, and some of the people that were on their, they had this big screen in their front room of, like, the different Q&As and the different people who are active. And some of the names on the list were, like, either past podcast guests or people that I know that message me sometimes about, like, you know, regular listeners and stuff like that. I was like, man, this world is so small, but it's so big at the same time. It's unbelievable.

(Tim Woods at 00:57:23) Yeah. That's right. No. I say it's smaller and getting smaller. Yeah. It's just like, it's amazing. You know, I miss part of that. You know, the pandemic has restricted some of our reunions. You know, it's always fun when you go to the big conferences and you get to meet people that you've worked with in the past, and it's just like a homecoming many times. And, you know, I do miss some of that. You know, with the virtual conferences and stuff, you just don't get that same, you know, reuniting of friends and past associates and things like that. So, yeah, hopefully, we'll get back to a better norm here in the future.

(Joel Beasley at 00:57:58) Yeah. I think, like, and everyone's gonna hate this. This is, like, a realistic timeline, not like an Elon Musk advanced timeline. I think, like, three years, this thing will be, like, forgotten about, but that's a gradient. That means, like, the end point. We're already in the creating the lax, you know, part of it. But I think it'll take, you know, it'll be, like, in three years, it'll be, like, one person still, like, wearing a mask when they sleep.

(Tim Woods at 00:58:28) Yeah. No. You're right. I mean, you know, we're probably, like, in the middle of the gradient and, you know, you're right. You know, sometime we'll look back on it and say, you remember when? You remember when? Yeah. I remember that. Yeah. But, you know, I am not there yet.

(Joel Beasley at 00:58:42) And I mean, I need to clarify too. I was thinking, like, three-year cycle. So from, like, when this began. Not, like, from today. But I think, like, a three-year cycle is probably what it takes for people to forget stuff, because we forget really fast. Dude, this is great. All right. As we start to wrap up here, I want to be respectful of your time. Share with me, like, some of the best leadership advice that you've ever gotten.

(Tim Woods at 00:59:05) Don't be scared to make mistakes, you know. It's like, you know, as a manager, I managed our sales engineers for a long time. I want to make sure that I empower my people. If you want to have creative thought on your teams and you want to empower your people, just to make sure that, you know, they're not afraid to come up with different solutions and think outside the box. I know we use that term a lot, but what that really means to me is, hey, there's nothing off the table, right? It's like, entertain it. Make sure you're entertaining those ideas and those thoughts and for the people that you have that you have responsibility for. And engage with them and network with them and understand where their creative juices lie and how you can leverage that, how you can harness it, how you can, you know, make sure that that match stays lit in those arenas. So, yeah, from a leadership perspective, the first time you stifle creative thought, it's just stifled forever, and that's just a really bad thing. So you want to just make sure that you're giving way to that, you have a path for them to let those creative juices out, you know, for the betterment of the team. Yeah.

(Joel Beasley at 01:00:14) You gotta get the bad ideas out first. That's why you don't say no.

(Tim Woods at 01:00:16) Yeah. Yeah. There's nothing, no. That's right. No. It doesn't mean I'm gonna agree with it every time, but definitely, you know, I definitely want to talk it, debate it. And that's the other thing. You know, if somebody doesn't accept something, that doesn't necessarily mean no. It just means that we're debating. We're talking. Let's look at the pros and cons. Let's look at both sides of it.

(Tim Woods at 01:00:34) What's the positive? What's the negatives? What's the neutral? And what do we want to do with this idea?

(Tim Woods at 01:00:43) So yeah, I love it.

(Joel Beasley at 01:00:44) I love it. It sounds like you have a strong team over there that understands their role in this innovation, and so you can move quickly and debate these ideas and bring this to the market. I think it's great what you guys are doing.

(Tim Woods at 01:00:56) We have a great team of people. I can't say enough about the culture at FireMon and the leadership at FireMon and the people that are here. It's just really some great people. Like I said, I've been here a long time. If I didn't enjoy it, I wouldn't be here.

(Tim Woods at 01:01:11) I think life's too short not to enjoy what you're doing, right? So no, absolutely. I can't think of anywhere else I'd rather be right now.

(Joel Beasley at 01:01:19) Are you guys hiring?

(Tim Woods at 01:01:21) We are. We're definitely hiring, and you can go to our website. Anybody that's interested, especially in the development arena—we have some aggressive timeframes on some of the functionality that we're trying to bring to bear on the challenges that our customers are faced with. And so we are definitely hiring.

(Tim Woods at 01:01:37) I would solicit people to go check out our website and go to the career section. And if you think you have an alignment and you have the moxie that we're looking for, and we have the moxie that you're looking for, then yeah, by all means, throw your hat in the ring.

(Joel Beasley at 01:01:54) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.