Episode 345 ·
Syed Abdur Rahman - Knowledge Graphs in Cybersecurity, & Tech Needs To Keep People In Mind
Today we are talking to Syed Abdur Rahman, the VP of Product Management and Marketing at Brinqa. And we discuss why it’s challenging to create a one-size-fits-all tool that fixes every problem. How Brinqa utilizes knowledge graphs in their cybersecurity tools, and why technology should always be built with people in mind.
All of this, right here, right now, on the Modern CTO Podcast!
To learn more about Brinqa, check them out at https://www.brinqa.com

About Syed Abdur Rahman:
Syed brings a passion for design thinking and engineering to Brinqa where he leads product management, strategy, and marketing. He is responsible for driving the overall strategy and technical direction of Brinqa product lines. His previous experience includes technical software development and delivering large enterprise security applications at Sun Microsystems and Oracle.
About Brinqa:
Brinqa is a leading provider of cyber risk management – enabling stakeholders, governance organizations, and infrastructure and security teams to effectively manage technology risk at the speed of business. Brinqa software and cloud services leverage an organization’s existing investment in systems, security, and governance programs to identify, measure, manage and monitor risk. With Brinqa, organizations are reducing response time to emerging threats, impact to business, and technology risk and compliance costs by over 50% through real-time risk analytics, automated risk assessments, prioritized remediation, actionable insights and improved communication.
Transcript
(Intro Narrator at 00:00:00) Hello, my friends. Today, Joel is talking to Syed, the VP of Product Management and Marketing at Brinqa. And they discuss why it's challenging to create a one-size-fits-all tool that fixes every problem, how Brinqa utilizes knowledge graphs in their cybersecurity tools, and why technology should always be built with people in mind. All of this right here, right now, on the Modern CTO Podcast.
(Joel Beasley at 00:00:29) Here we go. This is the Modern CTO Podcast. So can you share a little bit about your upbringing and background?
(Syed at 00:00:49) Yeah, sure. So I'm from India originally, and I came here for grad school. And my background actually is in computer engineering. So that's what I studied for my undergrad. But I think I've always been very interested in design. Just design and architecture, how you build things. And a lot of it is, now that I know more, I sort of look back on my decisions at different times of my life, and I can sort of draw that line and correlate why I took those decisions. But I think early on, getting out of high school, I really wanted to get into technology. I liked the idea of building things and designing things. And I think for me at the time, I felt like that was where the cutting edge was. And I ended up doing computer engineering. I really liked it. Particularly, you know, computer engineering, just to give you some background, at least in India, it's a lot more hardware than software. So it's a lot more about computer architecture and finite state machines and all that good stuff. And I really liked sort of thinking about these things. Not so much actually building the practical aspect of building machines and so on, but really the theory of how things work, the design and architecture and all the different considerations and how you go about all those things. But I ended up not pursuing computer engineering or at least hardware once I graduated. And sort of looking back on it, I feel like maybe I was a little scared because it's such a specific field that if you're doing that, you're kind of doing that for the rest of your life. And I think that maybe scared me a little bit.
(Syed at 00:02:30) So when I did my master's, it was really generic. I basically studied everything. So I kind of, I guess, took the opposite route, which is that most people start with studying something more general and then specializing. And in my case, I was moving to a more general model later on. But I really liked it. It really worked well for me because I feel like I had a lot of the design principles and architecture design from my undergrad, and then I had a good solid background for how to apply that to other things. And I think in grad school also is when I came across—you know, it's kind of weird to say that a book changes your life. It's a bit of a cliche, I guess. But I think somebody recommended the book, The Design of Everyday Things. I don't know if it was a professor or a friend or somebody. And that was really quite a turning point in my life because I realized that a lot of things that I would be thinking about intuitively or, you know, were in my own mind, there was actually a whole field of study around it, and people had actually spent a lot of time thinking through why we take these decisions. And so that was really interesting for me. And I think since then, I still don't have any formal training in it, but on my own, I feel like that's something that I'm really passionate about and that I try to read up on and just get more familiarized with.
(Joel Beasley at 00:04:03) And where did you do your master's at?
(Syed at 00:04:05) I was at USC in LA.
(Joel Beasley at 00:04:08) Did you enjoy it?
(Syed at 00:04:10) I loved it. Yeah. It was amazing. I think the way that education is approached, at least in India and in the US, it's very different. So in India, it's a lot of theoretical stuff, and it's great because you know the fundamentals by heart because you're just on it all the time. And I think in the US, it's a lot more practical. So it's a lot more about projects and group work and building things. And so I really enjoyed it because it was kind of different from what I was used to. I had a really good time in LA. Back then, this is 2007, 2008, Downtown LA, which is close to where USC is, it was not a very nice place to be. Now Downtown LA is much nicer. People actually live there. Back then, nobody did. So I did. Yeah, I really enjoyed it. It was a bit of a shock. I have to say it's not what I was expecting when I moved to the US. I didn't anticipate so many homeless people, and it was definitely a shock. And, you know, coming from India, that's saying something, because you sort of get desensitized to a lot of the stuff there. But yeah, I think problems, people problems are kind of the same all over, I guess.
(Joel Beasley at 00:05:24) Well, people are kind of the same all over. Right?
(Syed at 00:05:26) People are kind of the same. Exactly. Exactly. Yeah.
(Joel Beasley at 00:05:29) First time I got to travel internationally, I was just so excited. Like, I had just had it all built up in my head how different the world would be. And yeah, there were differences, but I was shocked by how the same we are everywhere.
(Syed at 00:05:43) Yeah. Yeah. So true. I know. Yeah.
(Joel Beasley at 00:05:46) So do you still live in LA now?
(Syed at 00:05:48) No. I'm in San Francisco. I've been here for almost ten years.
(Joel Beasley at 00:05:53) You're gonna stay around? You're not in the exodus of everyone?
(Syed at 00:05:57) No. No. Honestly, this is much more normal now. This looks like, this kinda looks and feels a little bit more like San Francisco because I moved here ten years ago, and the last five years have been really intense, I think, for the city. It's just changed a lot. And, you know, it's kind of weird. Like, the tech industry has always been here. But ten years ago, things were not quite like this. And I think it's also because a lot of the companies used to be in Silicon Valley or in Palo Alto or Santa Clara. And a lot of the newer companies tend to be more in the city, I guess, which is why we've had all these problems with housing issues and people being in the street and stuff like that. So I feel terrible for saying this, but post-pandemic, San Francisco feels a lot more like the San Francisco that I moved to. So I don't hate it. It's fine. I love the city, by the way. So yeah, I don't foresee myself moving anywhere.
(Joel Beasley at 00:06:55) I get it too because I grew up in a small town and it became a big town over the 20 because it was, you know, it's voted in the top five beaches in the United States. And so it's a huge vacation destination. So people come down here on vacation, and that's where they wanna retire. That's where they wanna go move to. So, you know, we still get the boom and burst population and season like you do when there's conferences in town. Right?
(Syed at 00:07:18) Right.
(Joel Beasley at 00:07:18) And yeah, it's definitely not what it was, but sometimes at the right part of the year when everyone's left and have gone back, it's like it feels like the smaller town that I grew up in for a little bit.
(Syed at 00:07:32) Yeah. That's so interesting how, you know, cities have their own lives almost. So Brinqa is based in Austin, Texas, even though I've always been on the West Coast. And I think Austin is kind of going through some of those growing pains as well, which is not, you know, over the last five years, it's just exploded, and people are moving there from all over, especially from California, which I think the locals don't really appreciate. So, you know, they're dealing with massive traffic and, you know, it takes a while to build infrastructure. It takes a lot longer to build infrastructure than it does for people to move to places. So it's interesting. I think it's natural, I guess.
(Joel Beasley at 00:08:10) Yeah. It's not the same as building technology. Like when you have to build roads, that's a lot of manual labor.
(Syed at 00:08:15) Yep. That takes a while. It takes a while.
(Joel Beasley at 00:08:19) So tell me a little bit about what Brinqa does.
(Syed at 00:08:22) Sure. Yeah. So Brinqa is a cyber risk management company. I've been with Brinqa for a while, and I've been in cybersecurity for a little bit longer. So, kind of interesting how I ended up, I guess, at Brinqa and in cybersecurity as well. To be honest, I think it's mostly luck. It was not really something that I think I was actively pursuing. When I was in grad school, I was really interested in design again. I think one of my favorite courses was compiler design, which is all about building the software that actually reads language and converts it into machine language and things like that. So I was pretty sure I was going to get into something like that. But my first, well, my only summer there in grad school, there was this opportunity for an internship at Sun Microsystems. And I was really not planning to go for that internship or trying to apply for it because one of the requirements there was that you had to know Java. And I didn't know any Java at the time, but a friend convinced me that I should go. And I ended up going and, you know, had a really interesting interview process. They wanted me to design a traffic light. And so right up my alley, nobody asked me to write code. It was all pseudocode, which I loved. And at the end of the day, you know, I go through the short list. And for the final interview, I'm going to talk to the big boss, the head honcho. And I walk into his office, and this is my current boss, Ahmad. And there's this guy who, you know, long hair, flip-flops, wearing shorts. And I was just surprised because that was not my understanding of corporate America at all. I had interviewed Motorola before that, and that was all, you know, suits and ties. So I walk in, and the first thing that I told him was that I don't know any Java. And he was a little amused, but then he was like, okay. Well, you know other languages? And I was like, yeah, sure. He said, don't worry about it. You'll pick it up. But the company or the team that I ended up working in worked on this product called RBACS, which is role-based access management. So it's a part of identity and access management in cybersecurity. And I didn't know at the time that Ahmad was there because his previous company that he had founded had just been acquired by Sun Microsystems. So he was there for that period where he was making sure that the company gets integrated and his team gets integrated and the product gets integrated. And, you know, he left shortly after, and he founded Brinqa, and he asked me if I wanted to join. So really, you know, Brinqa and—sorry for that long, long rambling story.
(Joel Beasley at 00:11:04) No. It's good.
(Syed at 00:11:06) But essentially, what Brinqa does in sort of a simple way is that we help companies make sense of all their cybersecurity data. And our focus is very much on cyber risk. So how can you make sense of all this information that's coming in from your cybersecurity tools, from any of your IT programs, and how do you combine that with business information, which is really the context for how cyber IT is being used towards identifying risk and operationalizing risk and how we take decisions around risk. So our core focus is cyber risk management, but on a technology side of things, it's really a very generic platform that's built to be able to consume and correlate and build data models from by pulling data from essentially anywhere within an organization.
(Joel Beasley at 00:11:58) That's pretty cool. Let me better understand this, but explain to me the pain point a customer has when they find you and they're like, oh, thank God you exist. I wanna buy this.
(Syed at 00:12:07) Yeah. Definitely. So, you know, we address specific areas within cybersecurity, those that tend to be more appropriate for a risk-based approach. And this could be things like vulnerability management or application security or cloud security. But typically, what's happening for them is that, you know, they have certain tools within their organization, like a vulnerability assessment tool or their static testing tools for the applications that they're building. And they have a lot of this information. So if you're talking, if you're thinking about large enterprises, we're really thinking about millions of vulnerabilities coming in at any given period of time. So it's not really possible to take actions on all of this data. They really need to be able to figure out which, you know, what part of this, let's say, what 10,000 of these million vulnerabilities are the ones that can potentially impact them the most and that they should be taking actions on. So we help them go from that million to 10,000. But I think a big focus for us, like I said, is making sure that everything is risk-based so that those 10,000 vulnerabilities that they're now addressing, they're the ones that impact this particular organization the most. Not in a general sense, they're not the most severe vulnerabilities for the rest of the world. They are the vulnerabilities that impact this particular organization the most. And so the way that we're doing this is by bringing in a lot of additional data points, typically a lot of business data as well, because let's say you have a server and you have a sev-five vulnerability on it. Unless you know what that server is being used for and how it actually impacts your business, you're not really in a position to take that decision. Without that, all sev-fives are the same, and you don't necessarily want to be fixing all sev-fives. You want to be fixing the ones that really impact you the most.
(Joel Beasley at 00:13:59) Why don't you guys just build a tool that makes everything secure so that we don't have to worry about security? Just buy one tool, everything's secure, and we're done.
(Syed at 00:14:08) Yeah. Yeah. That would be nice. That would be nice. But yeah, things, unfortunately, cannot work that way because, you know, the reason why we talk about risk so much is, think about risk in the context of people. Right? Any two individuals, the risks that apply to them, they're going to be different regardless of how similar these two people are. Doesn't matter if they look the same, they're the same age. The risks that apply to them are really unique based on where they live, you know, what their profession is. Are they a firefighter, policeman, or somebody that's just working in a cubicle, what their age is, what their medical history is. So risk is inherently a very subjective concept. The risks that apply to any individual, they're very unique to them and who they are as a person. And the same thing applies to businesses. Right? So it's kind of the same thing. The risks that apply to businesses, they're really unique to what that business is, what services and products they deliver, who their customers are, what type of information they process, a lot of these different things. So it's not really possible, unfortunately, to have one solution that's going to work exactly the same for everyone. And you have a lot of, you know, you have a lot of great cybersecurity tools that do specific things, but they do them from a technology standpoint. Like, you can have something that is going to identify or fix something on a Windows machine. Right? And maybe it can do that uniformly for every single Windows machine on the planet. But without really knowing what that Windows machine means to you, it's not really possible to get the results that you want as an organization. And I think we also have to consider, we have to think about what cybersecurity means to organizations. I think that's a very fundamental question that I think a lot of people sort of struggle with, and that has very real impacts on how effective an organization is in their cybersecurity efforts.
(Syed at 00:16:08) Because the old way of looking at cybersecurity is that it's a part of IT. And you can see why people make that correlation. The skill sets are similar, or at least they're adjacent skill sets. So a lot of times people sort of think that cybersecurity should be a part of IT. But that's not really a good model because these two functions, IT and cybersecurity, they are actually in a little bit of conflict.
(Syed at 00:16:35) Because for IT, the main thing that they're concerned about is uptime and availability, because their internal customers are other functions within the organization, like sales or business or whatever the case might be. So for them, these other functions are the ones that are paying the bill for IT. So that's what they would like to focus on. They would like to make sure everything is up and running all the time and everything is available. Whereas here's cybersecurity coming in and saying, "Hey, you have a problem here. You need to go fix this." And to fix this, you're going to need to take down the server. So if cybersecurity actually reports to IT, that's a problem because that's almost like—that's why self-regulation doesn't really work in industries, right?
(Syed at 00:17:18) That's why you have independent bodies that do the regulation part. So cybersecurity, essentially, the good or modern way to look at cybersecurity is that it's just another vertical within the organization. It's just like sales or marketing that's, at the end of the day, trying to achieve the same goal, which is helping business deliver their services and products to their customers or grow. And in this model, cybersecurity's clients are sort of the business side of things and not the IT side of things. And this is also what can actually drive change, because now a business, somebody that owns a part of the business that is using IT as a resource, that's, let's say, getting a server or a cloud instance from IT, now they can point to them and say, "Hey, listen, I'm finding out that this thing that you gave me has a lot of potential problems, and I'm putting all my data on here. You need to fix this." And then IT can come back to them and say, "Okay, if you want us to fix this, it's going to take us some time. This is the cost you're going to incur. It's going to be down for a while." And now because we have all the information, we can take this decision about whether it's worth it to actually have this downtime to fix a problem.
(Syed at 00:18:21) So yeah, it's a process. I think most businesses are getting a little better about how they look at it. But that's unfortunately why it's not really possible to have one solution that works for everyone, because you need a lot of different stakeholders to be involved in this process for it to actually work the way that we need it to.
(Joel Beasley at 00:18:55) And your design skills is something I was thinking about, right? You've got all those nice pictures behind you as well. You mentioned that at the beginning of the conversation. How do you get to apply those skills to your role at Brinqa?
(Syed at 00:19:08) Yeah, no, I think from the beginning, the reason why this was such an appealing job to me was—sure, part of it was that I knew Ahmad, and I had worked for him before. And I'd seen that he had a track record for building and taking a company to an exit. But something about the mission of the company also really resonated with me personally quite a lot. And one of the things that I started thinking about a lot during grad school was also the purpose of technology and what technology is and what it should be. And when you start reading about design, there's a great school of thought around human-centered design that talks about the fact that technology and design should be built with people in mind. And at the end of the day, they should be making life, or really anything, easier and better for people, which is not necessarily what technology in general is doing right now.
(Syed at 00:20:09) I think right now it's sort of making things more complicated. It's more focused on putting things in front of people to consume as opposed to solving problems that they need to address. So when I came to know about what they were trying to do with Brinqa, which is making it easier for people to make sense of cybersecurity and make it easier for people to take decisions about it, I felt really connected to it. And I started off working at Brinqa on the engineering side of things. So I was a senior engineer for a couple of years, but I fairly quickly transitioned into product management because I felt like that is where I had the most potential to apply my passion for design and be able to focus on the bigger picture and how we need to approach what we're building from this approach, this idea of putting people front and center and really building our tools around the audience that we're trying to address.
(Syed at 00:21:08) And yeah, I think the really amazing thing with such early-stage startups, which is what it was when I joined in 2011, is that there's more work to be done than there are resources. So if you have a natural inclination for something and you want to do it, nobody's really going to stop you as long as you're doing whatever else you're supposed to. So I just started picking up more and more product management stuff because I really enjoyed it. And then eventually I moved into it full-time. And now I also run marketing, and that's kind of how we—so I would say my design focus, or my passion for design, I try to inject it in everything that I do, whether it's building a process, building a program for marketing, or building the way that we get feedback from our customers.
(Syed at 00:22:01) I try to make that a part of everything that I do. And there's actually—I don't know exactly if I remember the line exactly from the book, but it talks about how every artificial thing is designed. So if it doesn't automatically occur in nature, someone is designing it. Now it could be something material like a chair or a table, or it could be something intangible like a process or a plan. It could be anything. So I think design thinking is amazing because you can apply it to pretty much everything in your life. And as much as I can, I try to apply it to whatever I'm working on. Right now at Brinqa, that is a bit more about product positioning and how we talk about our products and what we do, as well as building data-centric programs for marketing and things like that.
(Joel Beasley at 00:22:54) Can you give me an idea of the size of Brinqa?
(Syed at 00:22:57) Yeah, sure. So I think we're around 70 people right now. We are headquartered in Austin, but we are pretty remote. We've always been very remote. So I've always been here on the West Coast in LA for a few years and then here in the Bay Area. Ahmad, our CEO, he's also in the Bay Area. He's in Palo Alto. And we've had an engineering team in Argentina pretty much since the beginning. We've had people on the East Coast, specifically in New York, because a lot of our early customers were financial services industry. They're sort of the leading edge for cybersecurity and definitely cyber risk. And we also have an office more recently that we opened in India. So we're pretty remote and distributed. I think that's a big part of our DNA.
(Joel Beasley at 00:23:46) A few years ago I looked up a population growth graph to really understand how many humans there are and the rate at which we multiply. It's pretty crazy how we multiply. And that's why I wasn't surprised when I heard Elon Musk complaining about how much we spend on space travel versus how much we spend on beauty care products. He's like, "We spend like 1% of that on space travel and exploration." I'm like, "Yeah, it's because we're busy here doing the beauty thing." But yeah, it's a—the question that I have for you, to be specific, was, as the population grows, this is kind of just a fun question, do you think that we're going to go more into other planets, or do you think that we'll build these low Earth orbit giant cities just orbiting near Earth?
(Syed at 00:24:33) I think the latter makes more sense. I think in terms of technological capabilities, I think we're a lot closer to that than what it would take to, let's say, go terraform a planet, right? And finding a habitable planet is not probably very likely, at least in our lifetimes. If we find one, it's going to be really far away. It's going to take a lot of time to get to it. I don't know if you're familiar with The Expanse, the TV series and books? Yeah. So I mean, that is—I don't want to say it's hyperreal, but it's quite real. The things that they talk about in that show, whether it's geopolitics or even the fact that it takes—in old-school sci-fi, it's like, "Oh, something is happening light years away and you can see it on a screen." Now it takes time for light to travel, so it doesn't really work that way. But that's a really interesting show, and I think they have a lot of these similar concepts where Mars is trying to terraform, but terraforming would take generations to develop the capabilities that you need to do that. So I think the near-Earth orbit stuff, I think that's a lot more likely. Or we learn to live under the water or learn to breathe underwater or something. We have a lot of water. If we could figure that out, that would be cool.
(Joel Beasley at 00:25:55) Yeah, increase in shark attacks though.
(Syed at 00:25:58) Yeah, I know. You'd have to build domes though.
(Joel Beasley at 00:26:00) Domes. Domes underwater. All right, there we go. No, you're right. I'm actually looking forward—and we'll get back on topic in a minute—but I'm actually looking forward to how fast the biologics, I guess for lack of a better term, what they're able to do with cells and printing them and making artificial limbs and programming all of this stuff. I think I had this one person on that was from a really large company, and I asked her, "How long until we have the technology where you could give me wings? You know, like you could install wings on me and they would work?" Because they do stuff like that. They'll grow an artificial heart off of a pig or something, off of its back. Crazy stuff, right? And she said, "No comment." And I was like, "What? What? That means somebody in your mega org has thought about that before."
(Syed at 00:26:53) Yeah, yeah. If you want me to drop that, that's like the worst thing you could have said.
(Joel Beasley at 00:26:57) Yeah, I know. Or she just gave me a Christmas present. She's like, "I know if I say no comment here, he's going to get real excited."
(Syed at 00:27:05) Yeah, there you go.
(Joel Beasley at 00:27:06) Sorry, go ahead.
(Syed at 00:27:07) No, no, please go ahead. I think we could chat about this forever. I think we do want to get back a little bit on topic, so that's fine.
(Joel Beasley at 00:27:16) Yeah, we've got to show Brinqa some love. Let's do a call to action right now. Let's bring it back with that. So what's your lead magnet? How do you get people to warm up to your brand?
(Syed at 00:27:26) So yeah, the way that we built the company, it was definitely very much focused on technology and product, and that's a really good thing to build a great product. But at the same time, it's not that good for marketing and sales and things like that. And I just told you that my background—I run product as well as having marketing responsibilities. So a lot of our growth and demand gen, it's all organic. So it's really people finding us based on content that we're putting out, or webinars or things like that, or word of mouth, hearing it from other customers.
(Syed at 00:28:08) So yeah, I think definitely come to the website and check out what we do for sure, because I am sure that we are addressing a problem that almost everybody has. And while our focus is still very specific, which is cybersecurity and cyber risk management and vulnerability management and application security, I think the applications for the technology are really what we are really excited about. Because we have chosen to address these problems because we have some background in it, but the problems that the platform and the technology can address on its own, I mean, it's absolutely limitless. It's essentially a mechanism where you can put all kinds of data and do really complex calculations on it for really any type of problem, specifically because with cybersecurity, data management and automation is a huge problem. And to take these decisions, you have to have the information.
(Syed at 00:29:05) We talk about this term called knowledge graph. Are you familiar with it at all?
(Joel Beasley at 00:29:12) Like the database?
(Syed at 00:29:14) Yeah, like the graph database?
(Joel Beasley at 00:29:15) The graph database?
(Syed at 00:29:17) Yes. So the graph database is one thing, which is the actual database, but the knowledge graph is more of a conceptual model for how you build data on it. And that's kind of what we do. So we are essentially a knowledge graph for cybersecurity. We came to this—it's not like we came up with the idea. I think Google search is basically the first technology that built a knowledge graph, and they're the ones that I think came up with the term. Now it's adopted by everything from Facebook to LinkedIn and all of that. But it's a really powerful tool for essentially building knowledge. And it's kind of an odd thing to say, but there's a huge difference between data and knowledge, right?
(Syed at 00:30:04) So from data you have to go to information, which is really making sense of this data. And then from information you have to go to knowledge where you're actually coming up with new insights based on this information that you're capturing. So it's a very wide application of the technology, and really being focused on cybersecurity, we definitely want people to come up with more use cases for what they can do. It's super common for us because we built the data architecture, which is the knowledge graph, but we still need to consume data from other cybersecurity tools and programs. So we have this ever-growing library of connectors or integrations. It's currently at like 150. But most of those integration requests are things that are coming from our customers or from our prospects. So they're the ones that are saying, "Hey, there's this tool that has this great information that we would like you to bring into this knowledge graph so we can take actions on it."
(Syed at 00:31:02) So the more eyes that we can get on what we're doing, I think it helps us grow the ecosystem and it helps us grow the scope of what we're doing as well.
(Joel Beasley at 00:31:13) Yeah, I just looked it up real quick. Neo4j was like a knowledge graph database.
(Syed at 00:31:20) Well, so Neo4j is a graph database. So it's basically a graph database, and a knowledge graph is a little bit more defined than that. Because a graph database is really just a way of collecting information in a graph. And graphs are amazing things because they are super simple as well as super complex at the same time. Because at its lowest level, all a graph is is a node and an edge connecting various nodes. But you can add infinite amounts of data on it. You can add infinite amounts of data on the edges, which are sort of the relationship aspect, as well as on the node.
(Syed at 00:32:01) And by changing this information or changing the context, you can add a ton of information on this. Knowledge graphs are a little bit different. So for a data architecture or data structure to be a knowledge graph, it has to have four characteristics that it has to meet. The first one is that it has to be an actual graph. So that is a given that underlying whatever your business data model is, at the end of the day, the base data model has to be a graph.
(Syed at 00:32:32) The second thing is that it has to be semantic, which is that it has to have an ontology. It's not a data lake. It's not a data store. It's not a key store where we're just putting information. Any information that goes into a knowledge graph, it has structure.
(Syed at 00:32:47) So we are establishing structure and relationships on that information as it's going into the knowledge graph. The third thing is that it actually generates new knowledge. So, again, it's not just a way to store information. You have to have some computational aspects on it that are coming up with new data or new information based on all the data that you're collecting. And the final thing is that it has to be alive.
(Syed at 00:33:12) So it's an alive mechanism, which means that, let's say, today I'm representing my neighborhood and I'm keeping track of stores and apartments and people, and tomorrow, if I want to add additional information on it that is not currently represented, I should be able to do that. And that aspect is really key as well because, especially when we talk about cybersecurity, which works off of IT, these things are constantly changing. Right? Ten years ago, nobody really thought about—or I don't know if it was a thing or not.
(Syed at 00:33:45) It was definitely not common—cloud infrastructure and cloud apps were not really a thing ten years ago. I mean, people were doing other forms of virtualization, but it was mostly in their own data centers and things like that. But technology changes so quickly, and enterprises have changed a little bit in this regard because I think ten or fifteen years ago, they used to be much more closed systems where the things that they would allow people to use were very restrictive. You couldn't really bring in your own phone, for instance. You had to use the phone that they were giving you.
(Syed at 00:34:18) But now that's not really the case. Now they have to make all technology available for their people to use because it's a big competitive advantage. And if you don't, then you're kind of falling behind. Like, if you're this odd company that's like, no, we need to have everything in our data center, we're not going to use cloud infrastructure, it's a disadvantage. And, I mean, for some companies, maybe you have to do that because you have some really sensitive information. But at the same time, you absolutely have to be evaluating any new technology to see if you can use it because it's an absolute competitive advantage.
(Joel Beasley at 00:34:56) Do people ever call you, like, a Google Analytics for security data?
(Syed at 00:35:01) People have called us Google Search or Facebook. We've been called those things. But, yeah, I mean, we try to stay away from comparisons because, you know, like I said, I don't think we even know the full potential of what this thing can do yet. And it's kind of hard. Right?
(Syed at 00:35:18) So when we initially started, or in the early days of the company, we built this amazing platform that was super dynamic that we really wanted to do a lot with. It was not yet a graph database yet. This is still early days, and we put a lot of effort into making that platform super dynamic, and we thought of everything that a company might need to be able to use. And it worked for, I wanna say, maybe one or two years. It worked well.
(Syed at 00:35:47) But we started seeing that, you know, anytime somebody wanted to bring in some additional data that we hadn't thought about, it was a challenge. We would have to go back and sort of code it in and then bring it back. And I think the turning point for us was that we came across this prospect—I don't even know if they ended up becoming a customer—but it was a public university, which was extremely underfunded in terms of their cybersecurity resources. And the person that was responsible for network security, which is what they were looking to solve with Brinqa, was also responsible for the physical security of their campuses.
(Syed at 00:36:25) And one of the things that he wanted to keep track of was fire extinguishers because, you know, fire extinguishers get inspected every so frequently. So they wanted to keep track of fire extinguishers and see that everything is being inspected or when they need to make replacements. And we had thought of everything that we could think about from an IT infrastructure standpoint, but we hadn't thought about fire extinguishers. And that was a big turning point for us because before that, we were still on a relational database, and we had to take some hard decisions because it was a big change to our technology. But we're like, you know what? Let's bite the bullet and let's do this right because there isn't really a binary state here. Either we allow people to do everything and bring in all the data, or you're always playing catch-up because you're working off some assumptions and base models.
(Syed at 00:37:01) So, yes, you know, Google Analytics, we've been compared to that. But in truth, it's a lot more complex than that because, you know, Google Analytics and a lot of other similar tools like SIM tools, if you're familiar with them, that process logs coming out of machine data, they're really good and they're really built for processing very large volumes of data. But they don't necessarily have a lot of depth, which means that you can't really build very complex data models for them. You can do quick calculations, and you can look for quick things that you want to see, and you can build reports and dashboards on it. But you can't really build complex data models with a lot of entities that have a lot of relationships between them that have different contexts at different periods of time, which is a lot of what we do. So, yes, the presentation in the form of analytics and reports and metrics is a big part of it. But the computation that we're doing, I think that's really where the real value lies in the fact that we're able to build data models for really complex problems, which, you know, most cybersecurity problems are fairly complex.
(Joel Beasley at 00:38:26) So who's the person in the organization that would be using Brinqa?
(Syed at 00:38:30) So that's a good question. And I think I totally got sidetracked because I was answering a different question of yours, which was—what was the question? Sorry. I keep getting sidetracked here. But the end of that long story was that, you know, in our early days, we tried to sell the platform, and we realized that it's difficult to sell a platform. As amazing a tool as it is, if you're expecting people to figure out what to do with it, it's a pretty wide gap that you're expecting them to cross on their own, especially if they have a problem that they're looking to solve immediately. And so we sort of—not necessarily pivoted—I think the platform is still where 80% of our development effort goes. But now we actually sell applications to problems that people are looking to solve, and this would be something like vulnerability management. And this, I guess, ties into your current question as well in terms of who the audience is or who's actually buying this.
(Syed at 00:39:25) So the answer to that is that it depends. It depends on what problem they're looking to solve. So for instance, if it's network security, vulnerability management, it's usually the vulnerability management team. There's usually a cybersecurity function that's doing vulnerability management that is telling IT what they need to fix and why they need to fix it and how they need to fix it and how much time they have and things like that. So a lot of times, it's a vulnerability management tool.
(Syed at 00:39:51) Another application of our platform is AppSec, so application security, which, as you probably know, is constantly in flux with DevSecOps. You know, who owns application security is also changing. It's moving more towards the development teams, which is actually really cool. So a lot of times, the people that are acquiring our solution are also the DevSecOps function. And then, you know, it really depends on the application that they're using our platform for.
(Syed at 00:40:21) Cloud and container security is another out-of-the-box application for us, and there's usually a team in SecOps that is taking care of that type of stuff. Asset management is a big use case because it's a huge problem for most organizations. They don't really know what technology assets they have. It's a mess because different parts of the asset management problem are being managed by different people. And, again, it's the same thing. How do you bring that all together? So who is buying the tool really depends on what problem they're looking to solve with the tool. I think people that it really resonates with the most, though, are cybersecurity architects. It takes a little while for our product within a customer's organization to get to the cybersecurity architect because usually, like I said, someone is buying it to solve a very specific problem. But then as the tool gets used and it gets circulated, it comes to the cybersecurity architect who's like, what? I can put all kinds of data in this. I can analyze anything. And that's where things become really exciting for us. And I think, eventually, that's who is going to be the perfect target audience for us.
(Syed at 00:41:21) But right now, you know, it really varies based on what the main problem for an organization is. And, you know, we also talk about risk so much. It's a good entry point for various cybersecurity executives. There's usually somebody from the CISO's office who needs to keep track of risk because, again, risk is a function that really needs to interact with other functions besides just IT and cybersecurity.
(Joel Beasley at 00:41:59) So it looks like you're doing well. You guys are growing. You've got a cool product. Your website and brand look good. In the prep call, they mentioned that you really like design and that's something that I talk about a lot. I don't do design. I mean, I can, but I don't consider myself a designer because I see the great designers that I follow on Dribbble. I'm like, those people, they're designers. I'm just a fan.
(Syed at 00:42:23) Do you—any particular kind of design or just everything in general?
(Joel Beasley at 00:42:27) I typically appreciate aesthetics that cause an emotional reaction within me. So I could see a car and feel good just based off of the lines of the car and, like, maybe the lines of it will stand out, or I'll see some art. Typically, like, paintings don't do much for me. But, yeah, I don't like ooh and aah through a museum. But sometimes I just notice this beauty in nature—like, symmetry really gets me. And I don't know. I just, I found myself—it's like, not that I'm doing it, it's like I'm watching myself. Kind of sometimes I get caught up in these moments where I'm like, oh, that's really beautiful and I don't know why. And so maybe I was a designer in a past life or something.
(Syed at 00:43:09) Yeah. Or in the current one. Are you familiar with The Design of Everyday Things? Or there's actually the author—his name is Donald Norman. He's amazing. He's written a lot of books around this idea. In fact, one of them I think is called Emotional Design. If you haven't read it, you must—it is necessary. It is fantastic because he talks about, you know, the psychology of things, the psychology of ideas, and how human beings process information and how we take actions on it. It is fantastic. That's the book that I was telling you—it changed my life, I think. That might be a bit of a stretch, but I think it definitely helped me verbalize a lot of things that I think I was thinking about. And I'm guessing that based on what you're describing about your emotional reactions to certain things, I think you probably—you will—I'm not—probably—I think you'll definitely find it very interesting. And the edition that I read in, you know, back in grad school, actually, I think he wrote the book in the eighties. So all the examples for everything were obsolete. The things that he was talking about, they were just so old. But even then, it was super connected—I super connected with it.
(Syed at 00:44:29) And I think there's a newer version of the book that came out—a newer edition that came out in 2013, which is a lot more recent, which probably is all obsolete now, but at least it talks about UX and UI and actually software and graphic design and things like that as well.
(Joel Beasley at 00:44:46) Yes. I actually just ordered it. I clicked it up. It was right there. That's the beauty of Amazon. Just one click.
(Syed at 00:44:53) That's true. Yeah. Here's my credit.
(Joel Beasley at 00:44:56) I order the book on Audible, and then I order the physical copy. And I keep the physical copy around because every time I see the cover, it reminds me of what I learned. And then that helps me. So I care more about the covers I keep out because I have a bunch of books. But I only keep out a certain set of covers. And when I look at them, I remember things from them.
(Syed at 00:45:18) Nice. Yeah. I like your bookshelves there. My apartment is tiny, but I have a stack of bookshelves just behind me. It's like a vertical thing. Yeah. I have a lot of books too.
(Joel Beasley at 00:45:28) Yes. I like learning, and I like even more putting things into action. And so, like, I'll learn a hundred things, but, you know, maybe one or two will stick with me, and that just seems to be the process of how life goes.
(Syed at 00:45:39) Yeah. It's the important thing or at least what's most relevant to you at that time that is sticking with you for a reason. So yeah.
(Joel Beasley at 00:45:48) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn, or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.