Security Confidential S6 E1 Brian Stoner

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Brian Stoner. Brian has a long history with cybersecurity OEMs starting with CA where Manoj first met him. Vice President of Worldwide Channels and Alliances at DTEX Systems. Brians has extensive experience in MSSP, Channel, Strategic Alliances and OEM for high growth security solution providers. Brian has a long history with cybersecurity OEMs starting with CA where I first met him. Brian has been with McAfee, Fireeye, Cylance, Stellar Cyber, and is now with DTEX Systems.

00:00 Introduction

02:04 What are the elements of a successful cybersecurity channel program?

06:10 Is there an inherent conflict with having a salesperson be managing a partner?

08:12 Where do the programs have mismatched expectations between the OEM and reseller?

13:20 Is the pure Var model the way forward? Are clients in cybersecurity not locking more for a total solution for defense in depth vs a pure technology play.

16:11 What market sectors in cybersecurity do you see doing well in the coming year?

20:17 Explain what is XDR?

31:28 How have you been able to avoid the pitfalls of storage and computing power as it relates to the cloud?

39:52 Thoughts on AI

41:00 Events and Contacting Brian

Transcript

Manoj Tandon: Hello, everyone. Welcome to the show. This is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security Confidential. Today, we have another awesome guest joining us from halfway around the world. But before I introduce him, I’ve got to remind you guys: please hit the like and subscribe button. The algorithms are fairly stern about this, and if you want us to keep bringing you this great content, you’ve got to hit those buttons. It’ll help us out. Or like us on Spotify, or wherever you get your podcasts.

With that, I’m honored to introduce this week’s guest, Brian Stoner. Brian has a lot of experience in the cybersecurity industry. I’ve known him for nearly 20 years, since 2007. That’s getting to be a long time now, going back to his days at CA. He’s a great person and has a ton of knowledge about cyber. He’s worked for some fantastic companies that are household names, like McAfee, FireEye, and Cylance, which is now BlackBerry. Today, he’s joining us from Stellar Cyber. He is running their global channels program, and we have a lot of questions for him to tap into his experience. So stay tuned. Brian, thanks for joining us this Friday afternoon.

Brian Stoner: Thanks so much for having me, Manoj. It’s great to reconnect and have a conversation. This should be really fun.

Manoj Tandon: Yeah, this should be. I think our listeners are going to be interested to hear this. We typically have a lot of CISOs on. We’ve had some recruiters on. Heck, we even had a laughter yoga coach on the program once. But you’re the first channel person.

Brian Stoner: Great. Well, I hope I represent our community properly.

Manoj Tandon: I hope so as well. I can tell you, at Dark Rhino Security, being an MSSP/MDR firm, we work with a lot of different OEMs. Some people have great channel programs that are very well thought out. I think others probably are not as strong. So my opening question to you is: enlighten us a little bit. You’ve built these programs for some of the world’s largest cybersecurity companies. What are the elements of a successful cybersecurity channel program within an OEM?

Brian Stoner: Sure. I think, first and foremost, it starts at the top with the leadership of the company. The reason I say that is I’ve worked for a number of manufacturers who say, “Oh, we’re 100% channel, we love the channel,” but they’ve never really been able to get their technology to the point where they trust their partners to run an entire sales cycle themselves.

You kind of see these things. It happened at a few different big companies that you mentioned in my background. You’re a partner, and a channel person comes to you and says, “Hey, work with us,” and then they introduce you to the local enterprise salesperson. The enterprise salesperson takes you to lunch, and you start talking about accounts, and then he’s off to the races on your accounts and has nothing to do with you until he thinks he’s got a purchase order ready. So that’s an example.

Manoj Tandon: That’s very true. Go ahead, sorry.

Brian Stoner: No, I was going to say, first and foremost, when you’re looking at a new technology to potentially support your business, understand where the channel falls in priority with that manufacturer. That is my point, because everything flows from that: how much they invest in their programs, how much they invest in their partners. It comes from the top down.

Sometimes, even though they’re a great brand name and they do a great job of creating technology, they may not feel that they need the channel as much, and they may treat the channel more as fulfillment. Depending on the type of partner that you are, fulfillment is great if you’re a large account reseller. But if you’re a local VAR or a managed services provider, you want a partner that’s going to leverage you as part of their channel, not just for fulfillment.

Manoj Tandon: Yeah, you’re absolutely right. In fact, we have gone to great lengths to tell our customers we’re not VARs. Opportunistically, we’ll do an odd deal here and there that involves shuffling paper back and forth, but the vast majority of everything we do, we’re selling a solution. Our product is defense in depth, and we want our providers to be on board with the fact that it’s a solution.

For them, this is all bluebird money, because we’re running our sales cycles from beginning to end. With most of our OEMs, we’re on the hook for Tier 1 and Tier 2 support, so their cost of sale is nothing in this.

Brian Stoner: That’s exactly right. If they’re willing to invest in you to get you to that point where you can be competent in identifying opportunities, qualifying the opportunities, carrying them through any kind of technology proof of concept, and then closing the deal, that’s super high-margin business for the partner because they didn’t have to spend the money to generate the lead. They didn’t have to leverage their pre-sales resources to qualify the opportunity, and they don’t have a salesperson holding out a hand for a check at the end of the month once that deal closes, because it’s been done through the partner.

Manoj Tandon: Is there an inherent conflict with having a salesperson manage a partner, or should that be a discrete role?

Brian Stoner: Well, there shouldn’t be. I think one of the things that we’ve done really well at Stellar Cyber is that our salespeople get credit for every managed services provider in their territory. So now, if that managed services provider closes an opportunity and supports them, they get credit for that just the same as if they had sold that account directly.

We don’t do direct sales, but we do resale through value-added resellers as well as MSSPs. So what we’ve done there—instead of having a channel manager who gets compensated on it and a salesperson who gets compensated on it—I’m an overlay to our partners. Then our salespeople work directly with the partner, so there’s no channel conflict in this new model that we’ve developed.

Manoj Tandon: You know what, that’s very interesting because a lot of times we have seen—I think we both know some companies on that list that I mentioned—where those conflicts are there with the sales organization. That’s a conflict that is like the kiss of death for a channel program. It creates a lot of problems.

Brian Stoner: It is. And a lot of security technologies are so new, and there’s not a talent pool to pull from that’s going to be able to demo and deploy them quickly. The manufacturers kind of go out and do that role for the partner without enabling them, and that just doesn’t build the leverage that the channel is going to provide.

It gives maybe a good experience on the first one or two, but when the partner goes and tries to do it themselves or they have challenges, the varnish quickly wears off that relationship.

Manoj Tandon: I agree with you. All right, good insights there. So let me ask you: you mentioned it starts from the top. Is there an expectation mismatch from leadership when it comes to the channel sometimes? How do you avoid that, or how have you built these world-class programs where that mismatch doesn’t happen?

Brian Stoner: That’s a lot of questions there.

Manoj Tandon: Yeah, I know.

Brian Stoner: I think it kind of goes back to the metrics that the business is using to demonstrate profitability to their investors. Most of these cybersecurity startups are Israeli-based or U.S.-based in California. They have investors. What I saw maybe three to five years ago is that everybody was focused on TCV—Total Contract Value—because that helps with cash flow when you’re starting a business, because you have negative cash flow or you’re receiving VC money. The more money you take in from a TCV contract up front, the more profitable you are as you’re growing.

There has been a fundamental shift because we’ve just been through our B round of funding, and the investors actually put a heavier weight on ARR—Annual Recurring Revenue—than TCV when they were evaluating our company. I think the investors are finally evolving to understand that monthly recurring revenue and annual recurring revenue are more predictable. They grow at a steadier pace, and there’s much less churn than there is in TCV deals.

There’s this concept called “swallowing the fish.” I don’t know if you’re familiar with this or not, but you can take a business that’s focused on TCV, like a value-added reseller, and try to convert the sales team and the business into MRR. This is actually a concept that the founder of Zuora talks about in his book. He was one of the CTOs at Salesforce and started this company, Zuora, that does billing automation work.

Essentially, what happens is, in TCV sales, the sales kind of go up in an arc and then reach a peak and start coming back down. With MRR, your costs kind of go up on that curve, but your revenue kind of goes down for a little bit until you get enough to cover your monthly recurring costs, and then you start making more money. Then you start making a lot more money.

At some of the companies that I’ve worked for—and I don’t really want to say the names, but one of them was an endpoint technology company—in two years, we grew it from zero to 30 million in ARR, and it was a quarter of the revenue for the whole company. More than TCV recognition was on a quarterly basis, so the executives finally figured that out once they saw it.

So that’s the big dichotomy that I think we’ve had in the cybersecurity business: how the investors look at revenue, how the finance guys look at revenue, and ultimately what’s better for the business.

Manoj Tandon: In our world, I can tell you from a valuation perspective, we’re seeing other MSSPs and MDR firms out there getting anywhere from 12x to 20x on their valuations because of ARR. For us at Dark Rhino, our number one metric is: how many subscribers do we have? That’s directly correlated to the number of renewals and directly correlated to the quality of service. Because if we’re unable to keep the client and deliver a good-quality product as our service offering, our ARR goes to hell in a handbasket, and that would not be good.

Thankfully, that’s not the case, but you’re right. Initially, in that model, there are a lot of costs that you are absorbing until you get to a run rate where you can distribute those costs and absorb them. At that point, your margins do really well.

Brian Stoner: Exactly. I think there’s a very large appetite in the VC community right now for this type of business because they understand that it’s very difficult to get to the smaller customers without having this type of channel. I think that’s one of the big things that I took away from that last round: people are finally starting to really weigh the impact that a managed services provider can have in their plans.

Manoj Tandon: Very cool. When you’re looking at managed service providers versus VARs, what do you see as the future? Do you see the future being the VAR model, or do you see the future being more—especially in this mid-market—a very solution-oriented model?

Brian Stoner: I have been in the channel now for a very long time, and the challenge for the reseller is that the margin on a per-line basis keeps going down, so their overall profitability has kind of flattened out or is declining. That’s why you see them attempting to either partner or begin to build their way into the managed services realm.

The challenge they have is that they have a bunch of sellers who’ve been compensated on gross margin for so long. The analogy I use—and I don’t mean this in a mean way—is that’s the car salesman model. Somebody’s in the dealership, you’ve got to sell them today, you’ve got to get the margin today.

Whereas managed services providers have a much longer-term relationship with their customers, and it’s much more of what I would compare to an insurance agent relationship. It’s somebody you go to see when you have a kid, or you buy a new house, or you buy a different car. You’re constantly working with them.

Crossing that chasm is difficult because salespeople are very coin-operated. They’re used to getting paid for what they do. So the challenge is: how do you convert somebody? The first step to that typically is, “Okay, well, you can sell MSSP, and we’ll figure out what the gross margin is on it for a three-year deal, and we’ll just pay you on that.” That’s fine, except that’s an expensive model for the reseller because they’re paying out on future revenues that they haven’t collected yet.

That’s kind of the interim, and then your overlays go away, and then people get used to selling MSSP instead. But that could take a year to two years of adjustments to the compensation plan and adjustments to behavior before you get to the ultimate goal.

Manoj Tandon: You’re optimistic. I thought it would take longer than that.

Brian Stoner: Well, it depends. You and I know some of the same people, and we know it would take them a little bit longer. But I like to be positive on these things. I’m a glass-half-full guy.

Manoj Tandon: That’s fantastic. So let me ask you, since I asked you about reading tea leaves here a little bit, what sectors do you see in cybersecurity doing really well? If you had personal bets, where would you place them? What types of companies?

Brian Stoner: In the last two years with COVID, I think a lot of customers realized that if the user is no longer sitting behind the firewall on my corporate network, I need better visibility into what’s happening with them when they get out into their homes and home offices and shared workspaces.

I would say in the last year or two, there’s been a huge tailwind for the EDR manufacturers: CrowdStrike, SentinelOne, BlackBerry Cylance, Carbon Black. Because if your users are no longer behind the firewall and subject to all the controls that you’ve developed there, you need to have better control over your users, or at least visibility.

I think the other two sectors that are really important right now are any kind of cloud security that you can deploy and any kind of SaaS security that you can deploy. Because now, if the user is out of the office, and let’s say you don’t have a data center anymore—you’ve moved everything into a cloud, all your core applications are there, and they’re using Salesforce and Box and all these other things—one of the things that we’ve done at Stellar Cyber is we’ve built detections that can pull in data from all those sources and correlate things that are happening between them, so that it gives the SOC the same or better visibility than they would have if that user was sitting behind their firewall in the network.

So I think the technologies that are supporting those remote work applications are the ones that are going to be the growth opportunities, at least for the next year or two.

Manoj Tandon: Okay. I would agree with you, except I would just add one more. I think all the zero-trust guys are doing really well. You look at—and I’m going to say there’s a whole category of people in that—all the guys in the single sign-on and MFA business have been doing extremely well, as their annual results have been showing. I lump them into the whole zero-trust category.

Brian Stoner: Zero trust is kind of like XDR right now. Everybody says “zero trust,” but it means something different to everybody. From my perspective, zero trust goes beyond identity. It’s network segmentation and preventing lateral movement. Zscaler, I would put in zero trust. That kind of stuff.

But what people are underestimating is the level of effort to stand that up and make it work properly. The cultural ramifications for the organization are substantial.

Manoj Tandon: That’s something that we run into. We’re dealing with a client right now where there is a compliance mandate, but to make that achievable, there are going to be a lot of cultural changes from the “wild, wild west” approach it has been. And the first time the CEO can’t get to an application that he was always able to get to, it’s going to be a fire drill.

Brian Stoner: Sure it will. And that CEO is going to have to adapt. If he or she does not, then they won’t have a compliant organization. So what you’re saying is absolutely true: it’s a heavy lift to actually implement some of these things.

You mentioned XDR. What the hell is that?

Manoj Tandon: Enlighten us a little bit here. I see that on your website, and a green alien up there too.

Brian Stoner: It means about a hundred different things to a hundred different people right now, so I’ll do my best to try to distill it down.

XDR obviously stands for eXtended Detection and Response. If you look, there are several different camps that are looking at this. There are the EDR guys. And this is such a brilliant business—I don’t know why I didn’t think of this sooner. I’m going to build an endpoint technology, and because it doesn’t stop everything, I’m going to create another technology that records everything that happens on the endpoints. And then, because it’s so complex that the customer can’t manage it, I’m going to charge them to watch it for them.

I mean, who thinks up this stuff, right?

That business kind of got commoditized so quickly that those vendors need to extend their monitoring into other areas so they can charge more for their services. That’s why the EDR players compete quite a bit with the MDR providers. That’s something that was always a weird channel conflict that I had at some of the endpoint manufacturers I worked for.

So you’ve got the EDR guys, and the EDR guys in general—like CrowdStrike with Humio and SentinelOne with Scalyr—they bought big databases. They haven’t created any detections yet. They haven’t created any rules. They just bought these big databases and slapped “XDR” on it and said, “Shazam! Here it is: XDR.” So they’ve got a lot of work ahead of them.

Then you’ve got the network guys: Palo Alto, Fortinet. I’ll pick on Fortinet for a second. To get XDR in Fortinet, you’ve got to buy FortiSIEM, FortiAgents, the FortiXDR module, and a few other things. It’s a vertical stack where you have to have everything from them to make it work. Same thing with Palo Alto Cortex. They want you to have their endpoint agents and all this other stuff before you can get XDR.

So that’s kind of the other camp—that stack approach. Then we’ve got some pure plays that are out there that are just getting going, and the VCs are throwing a ton of money at them, even though they haven’t really built anything yet. I’m thinking about people that do cloud monitoring, where you can dump all your data into Snowflake and analyze it or something.

And then, funny enough, we see a lot of the NDR providers starting to look at XDR—like Awake, Exabeam, and ExtraHop. You know a lot of those guys. It’s becoming commoditized as a term. It’s an overused term, just like “machine learning.”

Manoj Tandon: Totally agree, which I have some questions on too for you. But yeah, I guess the thing would be: you guys talk about XDR on your website. What exactly does Stellar Cyber do? What space are you guys in?

Brian Stoner: Let me just back up and explain the concept of what we started doing first, and then I’ll tell you how we came to the XDR messaging, and then I’ll talk about what it is.

At the end of the day, six years ago, we set out to solve the problem of SOCs being manual today because the tools they use are manual and they’re rules-based.

Manoj Tandon: That’s very true.

Brian Stoner: We saw a huge opportunity where we could leverage machine learning to replace rules and provide a better experience and higher-efficacy alerts and remediation than you could get with current SOC technologies. Six years ago, nobody had coined the term XDR at all, but we have over 1,273 data scientists whose job it is to look at different security detections and figure out how we can do them better with machine learning than with rules.

Because rules are binary. If somebody fails a login five times and I set off an alert, somebody failed the login five times. But if it’s an older guy like me and I do it twice a week because I forgot what I updated my password to the week before, I could be triggering alerts and it’s not really an incident at all.

So anyway, we built this platform, and our first customer was an MSSP, Joe Morin over at CyFlare. He was familiar with our founders because Changming Liu, our CEO, was one of the founders of NetScreen, which spawned Palo Alto, Fortinet, Imperva, and a whole bunch of others. Changming also founded Aerohive, which, if you’re familiar with wireless security, built the first wireless platform with security built in.

Manoj Tandon: I was not aware of that, actually.

Brian Stoner: So they created this beautiful company where it’s great technology, it’s super intuitive and easy to use, and it completely eliminates the rules-management piece that you have with a SIEM.

Manoj Tandon: Completely. But then how do you account for differences in behavior across clients? What may be something that does not trigger an event at Client A should absolutely trigger an event at Client B. How do you account for that?

Brian Stoner: There are about three different categories of machine learning that we use, but there are about seven different types of machine learning that we use.

The one you’re talking about is what we call unsupervised machine learning. Unsupervised machine learning is machine learning that baselines everything on that tenant for that particular customer: when do they normally log in in the morning, when do they log out, who logs into which machine, where do they log in from—these are just some examples. Over a two-week period, I can baseline what normal behavior is: how much ingestion do we normally get from their sensor, how much traffic do we normally see on their network? We can baseline it, and we continually baseline it; it’s not just a one-time thing. But after two weeks, all these unsupervised machine-learning alerts can trigger.

What this does is it allows us to tune out all the noise of a thousand Snort or Suricata rules down to two things in the IPS that need attention. That’s the whole benefit of using machine learning instead of rules.

That’s one type of machine learning. The other type of machine learning is supervised machine learning, where we can train it on what’s good and what’s bad. That’s pretty simple.

Manoj Tandon: Don’t you need a large data set to do supervised machine learning?

Brian Stoner: Yeah, and we get that data set from over a dozen different threat-intelligence sources that are integrated into the platform, and we have a sandbox built into the platform.

Part of the reason we have the ability to use the machine learning so efficiently is because, as we’re ingesting data, we’re not just ingesting straight syslog data. We’re actually taking the metadata out of the syslog, comparing it against those dozen different sources of threat intelligence. If we don’t have a reputation, we can run it through the sandbox. If it’s a zero day, we’ll highlight that in the record itself.

We’ve created this record format called Interflow that’s based on JSON, where we standardize all those fields into one record type. That record type goes into the data lake, and I can use any type of machine learning I want to query that data.

That’s where, in a current environment, you write a rule, you update the rules, you look at threat intelligence and create new rules, and then you monitor. Then, when something hits, you compare it against threat intelligence to see if it’s bad or not. We’ve automated that whole process. So now the analyst only gets high-value alerts that already have all the threat intelligence in the alert itself, so they don’t have to go looking for things. It’s all correlated and built into that Interflow record.

Manoj Tandon: Well, what’s the third type of AI then?

Brian Stoner: The third type of AI is called graph machine learning, and we’re the first company that’s introduced it in a production product.

What graph machine learning does is it can key off the related Interflow record fields in multiple alerts and connect them automatically into an incident. Then we can score the severity of the incident and prioritize those incidents for the SOC. So now, instead of them having to correlate alerts—like if you do incident management today in most platforms, it’s a workbench: you pull the alerts in, you connect them, and then you create your visual representation—we’ve been able to figure out a way to do that with machine learning.

Your analyst can still play with that image and add things to it, take things away from it, and change it if they need to, but the first level of identification is done by machine learning instead of the analyst.

Manoj Tandon: Let me ask you this: I assume you folks are completely cloud-based, and our experience with the cloud has been that there are two limitations that make the solutions exorbitantly expensive: the cost of compute power and the cost of storage. Specifically when we’re talking about a SIEM technology, because we get into cases where there’s a regulatory obligation, like in banking, that we have to keep the logs for a year. There’s no way around that. We’ve got to do that. There are certain Hitrust rules that we have to follow, whether we want to or not.

How have you been able to avoid those pitfalls of storage and compute power as far as cloud?

Brian Stoner: I think two things.

One is, if you’re using disparate data sets and trying to create multiple rules to run across them, it’s going to take really high compute to achieve the goal. Because we’ve done the normalization process on the inbound data and stored it in a standard format, the compute—I’m not going to say it’s a lot less, it’s maybe a third less than a SIEM—that piece of the equation is reduced because of that ingestion process that we do.

Now, to your point, there are customers that need the raw logs, not the Interflow logs. We actually set up our sensors so that we can automatically forward all the raw logs to cold storage, and then we’ll just pull back the metadata for the Interflow record. They can keep it in extremely cheap cold storage.

Now, the Interflow records themselves, we can compress. Once we get them into cold storage, we can actually compress them before they get there, and we store them on a per-tenant basis. You can pull them back and do forensics on older data if you need to, kind of like rehydrating them. We’ve been able to figure out how to compress that data for storage on the back end.

Today, we don’t even offer a SaaS service; it’s all software. All of our customers are running it either in public clouds, on virtual infrastructure in their data center, or on hardware. We offer all of that. That’s one way to solve the data-localization issue.

One of the other things that we did that I think was pretty forward-looking is that we’ve always had multi-level multi-tenancy. The partner has root-level access, then you’ll have customers and partners below them that may also have tenants underneath them. We created a partner-tenant level.

In addition to all of that, we have customers who have entities in Europe or Asia that need to keep the data local. We have a feature in the data processor called Data Processor Central, where you can monitor remote instances in one console. Even though it might be coming from China or Japan or wherever it may be, you can deploy what we call a data processor out there, and then you can monitor it from your SOC centrally as if it were another tenant in your local network. It’s all the same.

But the data is localized in that region, so that issue is completely avoided. You’re just viewing a screenshot of the metadata remotely. That’s all you’re doing.

Manoj Tandon: From what I remember, GDPR has some strangeness about that itself. Even the metadata, unless it’s anonymized, is a pain in the ass to deal with.

Brian Stoner: We have multiple partners who work through that, and SOC 2 and everything else. We’re very familiar.

Manoj Tandon: Do you have any metrics on how much the workload reduction has been with your technology?

Brian Stoner: I’ll give you an example of a partner that I talked to last week in person, and actually another partner I talked to this morning. The partner that I met with last week in Dallas has been doing a proof of concept with us, and they’re getting ready to purchase the platform.

They have three full-time analysts whose entire job is rule management and threat intelligence. This is going to completely eliminate the need to have those people doing that. They’re going to be repurposed to be Level 2 SOC analysts on the platform instead of doing threat intelligence and rules management. Right there—I think he’s got a team of about 18 people—so that’s a pretty big percentage reduction in the number of people that he needs to run the platform.

Then he can actually grow. I have partners who’ve told me that they can handle three times as many customers on our platform with the same SOC team as they could with SIEM technology.

Manoj Tandon: Okay, so you can grow with fewer resources because of the automation.

My counterpoint to that would be: I don’t know what I’m missing in that approach. We’re really relying heavily on AI and trusting that it is getting at least everything that a human would. There’s a mental trust block there.

Brian Stoner: Trust, but observe.

Most solutions that deploy machine learning are kind of a black box. Ours is completely open. You can tune our machine learning if you need to. Every machine-learning detection that we have, if you click on a little question mark by it, it’ll tell you all the fields that generated it and how we calculated it. So we’re very open about that.

When I started here a year ago, when we were bringing over partners that had a SIEM they’d been running for a long time, and they were really proud of their rule set—it was a thousand rules long—so we’d bring it into the platform and recreate all those rules, and we’d run it for 90 days and say, “Okay, let’s compare what we saw.”

Inevitably, it was tons of false alerts from the rules, and a handful of alerts on the machine-learning side. They would sunset the rules after that quarter of viewing them side by side.

I think people are now getting to the point where, once they do the proof of concept and they see how easy it is to tune a customer—when you onboard a customer now, how long does it normally take to tune the environment? Oh, it takes us at least six weeks to go through all of it. You’ve got to collect all the records, find all the exceptions.

Where we run into it is a lot of exceptions because a lot of our clients have never had a SIEM. We primarily are mid-market, and they’ve never had a SIEM, so there are no rule sets. So we’re starting off with our rule sets based on our experience, and then we have to sit there and tune them from there.

With our machine learning, you can deploy it the first week in about two hours. You can let it run for the first week. We usually have a touchpoint with the customer for an hour, answer any questions they have. In the second week, the unsupervised machine learning is tuned, and it takes about an hour to tune the environment, and then you’re done for full production.

Manoj Tandon: I’m going to have to check this out at some point. This is kind of cool.

Do you guys have a demo our listeners can go watch?

Brian Stoner: If you go to stellarcyber.ai, there are all the videos you’d want to see. If you reach out to me personally, I’m happy to schedule the right person to do a demo for you. My email address is super simple: it’s just brian@stellarcyber.ai.

Manoj Tandon: Well, that’s pretty easy. Now watch, you’re going to get flooded with stuff.

Brian Stoner: Let’s see what happens.

Manoj Tandon: You’ve spoken a lot about AI. Where do you see AI going? I’m going to guess that you’re very pro-AI and you see it changing the face of cyber. What are your thoughts on it?

Brian Stoner: I think it’s going to continue to mature. I think, as people do more zero trust, there are going to be more detections that need to be built. I think it’s going to continue to evolve and get even more sophisticated.

I think that all of the companies that talk about having a program around XDR are going to have to start doing the hard work that we’ve been doing for six years: actually building those detections. They’re going to realize it’s not as easy as they think it’s going to be.

I think with the bigger players, it’s going to take them a couple of years to catch up, but they’ll catch up. Everything that we’ve built on our platform, you could build in Splunk or Elastic or some other platform; it would just take you six years.

Manoj Tandon: Hell, you could probably build it in Excel if you had enough resources.

Brian Stoner: Absolutely. But that’s not realistic.

Manoj Tandon: Splunk is the Godzilla of the SIEM world. That’s a project, and a big one. You’re buying a Bentley.

Brian Stoner: Ingestion is the expensive part of Splunk, in addition to the development piece.

We have a lot of partners who implement our technology to pre-filter all the logs and just send the alerts into Splunk so they can use the workflow that they built.

Manoj Tandon: Huh. I was going to ask you about use cases. That’s a very interesting one.

Brian Stoner: It’s a simple one, but we pre-filter everything. We can compress the storage and make it a lot cheaper. The alerts that they’re ingesting are a fraction of what they were ingesting before, so they can use that money to—I don’t know—develop models on how much they’re going to sell next quarter instead of spending it on security.

Manoj Tandon: I’m sure the guys at Splunk are grateful to you for doing that.

So, Brian, we’re at the hour here, and I wanted to give you an open platform to plug anything that you would like to talk about. It’s your floor. If you’ve got any events coming up, if you’re involved with any books or anything else that’s going on out there, let us know.

Brian Stoner: Well, for anybody who’s going to IT Nation next week, I’m sponsoring the block party that’s on Wednesday night. If you go to my LinkedIn, there’s an invite there in a post where you can register to go. Anybody’s welcome. If you’re going to IT Nation, it should be a lot of fun.

Manoj Tandon: That’s Florida, right?

Brian Stoner: That’s in Orlando. It’s Wednesday, coming up quick.

Manoj Tandon: Running hot. It would be nice to get away. We’ll put the links in the show notes, because this will air on Monday. So we’ll make sure that the show notes have the links to IT Nation.

Brian Stoner: Perfect. I’ll send you the link to the block party registration too.

If you’re at all interested in Stellar Cyber or learning about machine learning and security—something I know a lot about—you can reach out to me at brian@stellarcyber.ai. Since I joined Stellar in the last year or so, we’ve brought on 1,273 partners around the world. So it’s been a really great experience. We’ve got some really great partners that you can meet and learn how they’re using the technology, so definitely reach out to me about that.

Finally, I do advisory work. So if you’re a manufacturer or a salesperson who wants to understand how to get into the MSSP market—and what’s important to them and how they consume the technology—you’d be amazed how many people don’t really understand it. I do advisory work on the side to help people do that. Any help that you need, we could do a couple of quick sessions and give you some good direction too.

Manoj Tandon: Well, that’s fantastic. We’ll make sure to put a link to your LinkedIn page there too, so it’ll be great. We can reach you there, and your email for sure.

It’s been wonderful, Brian, to have you here on Friday. I hope you have a great weekend, and we hope to have you back again in the future.

Brian Stoner: Yeah, it’s been a long time since we’ve been together, so I can’t wait to grab a beer with you soon. I think it would be a really fun conversation. Thanks so much for having me today.

Manoj Tandon: Yeah, we’ll get you actually into our studio in Dublin, Ohio, where we have a lot of good things to imbibe. We used to do whiskey and whiteboards every Friday, and unfortunately COVID put the kibosh on that entire marketing program. But we were left with a whole bunch of bottles of bourbon, and people walk into our office and they’re like, “Are these people cybersecurity, or are they just alcoholics?”

And we’re not. I mean, it was a marketing thing. But when you mentioned getting a beer, I thought, you know what, maybe it’ll be a bourbon instead.

Brian Stoner: Well, actually, I do love bourbon. Near my vacation home, there’s a distillery that makes awesome bourbon in Galena, Illinois. It’s called Blaum Brothers.

I do have whiskey glasses with the Stellar Cyber logo on them, so I’ll see if I can get some of those mailed out to you so you can use our glasses and enjoy some of that bourbon.

Manoj Tandon: Thank you. We would love to have that. We’ll make Old Fashioneds when I get there. It’ll be fun.

Brian Stoner: That sounds like a great plan.

Manoj Tandon: That sounds like a new show. Well, hey, you have a great weekend, and it was great talking to you.

Brian Stoner: Thanks. Great to catch up with you again.

To learn more about Brian visit LinkedIn

Check out the other episodes in Season 6:

Ep. 0 Bonus: Why do People Get Hacked?

Ep. 1 Brian Stoner – VP of StellarCyber

Ep. 2 Dr. Joseph – Russia, Ukraine, and Cybersecurity

Ep. 3 Tim Chase – Ethical Hacker, CISO

Ep. 4 Brian Haugli – CEO of SideChannel

Ep. 5 Nat Schere – Cybersecurity as a revenue

Ep. 6 Endre Walls – Starting in Cyber, Vendors, and Diversity

Ep. 7 Erika Carrara – Veteran, Mentor, C-suite executive

Ep. 8 Eddie Thomason – Podcast Host, Author, and Entrepreneur

Ep. 9 Greg Schaffer – vCISO, Author, and Podcast Host

Ep. 10 Jake Belcher – Sr. Director of Security Strategy

Brian Stonerprofile picture for Dark Rhiino Security's Security Confidential podcast

Brian has a long history with cybersecurity OEMs starting with CA where Manoj first met him. Vice President of Worldwide Channels and Alliances at DTEX Systems. 

Brians has extensive experience in MSSP, Channel, Strategic Alliances and OEM for high growth security solution providers. 

Brian has a long history with cybersecurity OEMs starting with CA where Manoj first met him. 

Brian has been with McAfee, Fireeye, Cylance, Stellar Cyber, and is now with DTEX Systems.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top