Follow The Brand Podcast with Host Grant McGaugh
Are you ready to take your personal brand and business development to the next level? Then you won't want to miss the exciting new podcast dedicated to helping you tell your story in the most compelling way possible. Join me as I guide you through the process of building a magnetic personal brand, creating valuable relationships, and mastering the art of networking. With my expert tips and practical strategies, you'll be well on your way to 5-star success in both your professional and personal life. Don't wait - start building your 5-STAR BRAND TODAY!
Follow The Brand Podcast with Host Grant McGaugh
Software Isn’t Written Anymore. It’s Manufactured with Darius Radford
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Most security teams keep buying tools and still feel behind. That’s not because you picked the “wrong” scanner or missed the latest AI feature. It’s because many organizations are trying to secure software like it’s a one-time project instead of a repeatable manufacturing process. I’m joined by Darius Radford, founder and CEO of Knights Watch Cyber, to make that idea concrete and practical for any software-driven business.
Darius breaks down why applications, APIs, CI/CD pipelines, cloud platforms, open source dependencies, and identity are the real battlefield now. He shares the core insight behind what he calls the Secure Software Factory: software isn’t “written” anymore, it’s manufactured. When you adopt a factory mindset, you build in quality control, governance, automation, standards, metrics, and feedback loops so secure software development becomes consistent instead of heroic. We also walk through the four capabilities he sees as non-negotiable: orchestrated delivery, developer-centric application security tooling, supply chain and artifact management governance, and unified risk correlation that turns endless security data into real context.
We go straight at the AI era too. Developers and AI will build the next generation of products together, which makes AI security governance and testing even more urgent. Darius gives practical guardrails for AI-generated code, including input validation, session management, authentication and authorization checks, and permission modeling. We also talk about how a mature DevSecOps approach can help you win deals by proving security by design with repeatable metrics and alignment to common risk frameworks like OWASP.
If you build software, lead engineering, or sell into security-conscious customers, this conversation is for you. Subscribe, share this with a builder on your team, and leave a review with your biggest question about secure software development, what are you struggling to make repeatable?
Thanks for tuning in to this episode of Follow The Brand! We hope you enjoyed learning about the latest trends and strategies in Personal Branding, Business and Career Development, Financial Empowerment, Technology Innovation, and Executive Presence. To keep up with the latest insights and updates, visit 5starbdm.com
.
And don’t miss Grant McGaugh’s new book, First Light — a powerful guide to igniting your purpose and building a BRAVE brand that stands out in a changing world. - https://5starbdm.com/brave-masterclass/
See you next time on Follow The Brand!
Welcome And Why AppSec Matters
SPEAKER_01Hello, everybody, and welcome to the Follow Bread Podcast. This is Grant McGaugh. And I'm going to take you back a little bit in my history and working in the technology field. I worked with a particular individual that I'm going to introduce you today. And we both work for a company out of the West Coast in the Seattle area. And in which I was doing a lot of technology, technology technology solutions. And one of the things that I had to get really good at, and he helped me get good at, is understanding cybersecurity and cybersecurity opportunities and how to have cybersecurity conversations in a digital world and what that really looked like. Because there's all kinds of like, wow, that seems very intricate. And I had to get a better understanding of what that would look like. So my guest today, I say he's rare in cybersecurity. Not in the marketing department, but where it actually works. His name is Darius Radford. He's the founder and CEO of Knights Watch Cyber, which is a boutique firm helping software-driven organizations build security into how they work, not bolted on after the fact. That's very important. So after 20 years or so as a CISO, security architect, professor, PCI assessor, his fingerprints are on security programs at a lot of different companies. So he's got the lived experience that we need. And he's built what he's called the Secure Software Factory, which turns secure software development from a compliance checkbox into a competitive advantage. So I want to get you introduced to Darius Redford. I want to welcome you to the Follow Brand Podcast. How are you doing out there, Darius?
SPEAKER_00I am great, Grant. Hey, thanks for having me on, God.
SPEAKER_01Oh man. First of all, it's my pleasure to be with you again in this particular venue because I think you're one of the most impressive guys that I've met in what I call your domain authority, that you actually know and breathe this type of thing. So we got to first understand how you how you acquired your superpowers. Spider-Man acquired his superpowers.
Security Superpowers From Childhood
SPEAKER_01Exactly. Or like Superman, but how did you acquire your superpowers, Darius?
SPEAKER_00Wow. That's a that's an interesting question, Brent. And actually, it goes way back um to childhood, actually. Both my parents went to Tuskegee University. Okay. So my mom retired from the Atlanta Police Department, and my dad retired from the Pentagon. Okay. I mentioned that because I feel like my upbringing greatly impacted me becoming a security professional. First off, if you're raised by a police officer, your entire life, okay, is incident response. That's the biggest thing. Your entire life is incident response. Okay. My mom worked in larceny, she worked the streets, she worked in internal affairs, you know what I mean? So it was always incident response. And then she was a police officer doing the Atlanta child murders. Okay. Right. So her whole life was incident response. So I grew up with that. Then, about the fifth grade, my mom decides to become a licensed polygrapher.
unknownOkay.
SPEAKER_00Yeah. Not the best of things for a young Darius. Okay. And so uh let's say sixth grade, I find her polygraph manual and decide to study it. Okay. Then maybe it went a little too well. Because by seventh grade, she felt it was probably a good idea if I go stay with my dad in Alabama. So I'm gonna let you guys fill in the blank there. But yeah, so my dad, as I mentioned, he was a uh worked for the Pentagon, but prior to the Pentagon, he was a safety man at Republic Steel, which was you know the steel plants before they all moved across seas. Okay. So being a safety man, all I heard about was compliance, policy, and safety regulations. That was it. Compliance, policy, safety regulations. In addition to that, as a teenager, my dad had a really tight curfew. Okay, and his curfew and my event times always conflicted. Of course. Always conflicted, right? So when and then he would lock the door at curfew time, locked. So very quickly, I had to figure out lock picking if I wanted to get in there and get to sleep or sleep in the backyard with the dogs, right?
Lock Picking To Pentagon Internship
SPEAKER_00Um, then I went to Tuskegee. Yeah, okay. Went to college, follow in my parents' footsteps. My mom's a Delta, my dad's an Omega, so I decided to pledge. Yeah, yeah. Of course, I want to, I'm I'm a legacy. So I'm pledging, and the day before we crossed, my money didn't show up to cross. So I panicked, got on some computers, and let's just say we found some credit card numbers. Oh, okay. The plan was take the credit card numbers, get some stuff, take stuff back, get cash, cross over. Okay. One of those transactions didn't quite work out right, right? So us and the entire line of Omega Sci ended up going to jail spring break of '94. Wow.
unknownWow.
SPEAKER_00Not a good look, especially when you're at the school that you're a legacy at. So not a great time for me, right? So anyway, we get in front of the judge and we explain what happened. The judge asks, Whose idea was it to get into these computers? And of course, everybody looks at me. So I have to go up there and explain how I got into computers in 1994.
SPEAKER_01Yeah.
SPEAKER_00I used the modem and did this and all this fun stuff. So then he calls recess and we're freaking out. I'm freaking out. Um, we're all in the back freaking out, and I'm thinking about all these possibilities. So he comes back out and he starts telling me about his old college roommate that now works at the Pentagon. And I'm like, well, this is not how I'm expecting this conversation to go. Then he starts saying, Well, you know, uh, at the Pentagon, uh, they need people that think a certain way. I'm like, huh? And next thing I know, I got an internship making $9 an hour for the Pentagon. I looked at God and said, Look, I hear you. I got it. I will now use my evil superpower for good, and I'm not doing any more shady stuff no more. So that's kind of how I started, right? So at an early age, I learned social engineering from the polygraph stuff, I learned incident response from having a police mom. I learned policy and governance from my safety man dad, and penetration testing from lock picking and not having pledge money. Right, right, right, right. So go figure.
SPEAKER_01I love it, man. See, that's a true story, and that means you're a crime fighter. That that's how a crime fighter is born. You have to understand both sides of the world. Sometimes in the cyber world, you have the black hats, you have the white hats, kind of how they operate. But if you don't understand how the bad guys work, it's hard to then defend against that, right? But you have to understand the whole holistic. Now
Evaluating 50 Plus Security Tools
SPEAKER_01you've you've done something that you confided to me, what I thought was remarkable, that you yourself have has evaluated over 50 cybersecurity tools, applications, and platforms, in which you are now, you know, can can can speak to and it kind of become the precursor of what your own platform is all about. Talk to me about that.
SPEAKER_00Absolutely. Um over time, the evaluation of tools, uh, that became one of my go-to's. Every organization, every consultant project, I was helping these organizations determine look at what was there, look at the current tool set, evaluate, take the requirements of what they needed, right? Understand those requirements, and then go out and look at tools that fit into that environment and more importantly, integrate it with the pre-existing tools. Okay. So that tool evaluation is kind of what led to each one of the tiers in the secure software factory, if you will.
SPEAKER_01Nice.
SPEAKER_00Absolutely.
SPEAKER_01So these things I think are important for our conversation and for our audience to understand how you would say your side work now becomes your real work and what you're able to offer as a service to other people. Can you walk us through like the day you decided that Knights Watch Cyber was going full-time? What was your thinking around your risk and what did you know that made it worth taking?
SPEAKER_00Yeah. Um, I start seeing the same problem. Okay. I mean, literally, no matter what the environment was, right? Whether it was man, whether it was Florence DeCor or Jack Henry, a fifth third bank, a Wales Fargo bank, or Fannie Mae, or ATT, okay, I was
Software Is Manufacturing Not Writing
SPEAKER_00seeing the same thing. And even if we kind of look at the the the how we got there, okay. I started my career, everything was about the firewall. Okay, everything was about the firewall. Attack, protect the perimeter, protect the perimeter, protect the perimeter. That was the big thing, okay. Um, but over time, I realized something changed. Okay. Applications became the battlefield. Um no longer were they attacking through the firewall, they were attacking the applications, the APIs, the CI CD pipeline, the cloud, open source, the identity, people's identity became the new thing. I then started to notice a pattern. Okay. Every company had the same issues pretty much. Okay. I go into a company, they've had Fortify and Checkmarks and Sneak and Imperva and PrismaCloud or ThreatFix or Wiz, any, any, and it could be the latest AI security tool, no matter the cloud, whether it was Azure or AWS or GCP, all different logos, the same problem. Okay, same problem. Then it hit me one day. We don't have a tooling problem, we have a manufacturing problem. Okay. And here's what I mean by that. Software isn't written anymore. It's manufactor. Okay, and I'm gonna let that sit. Software isn't written anymore, it's manufactor. Let me draw this analogy for you, okay? Yeah, if Toyota built cars the way most companies built software, nobody would buy one. Okay, they wouldn't. Okay. Every factory, every factory Toyota has, or you build cars in, what do they have? They got quality control, they got a supply chain, they got an assembly line, they got standards, they got automation, they got periodic inspections, they got governance, feedback loops, repeatability, they got metrics, software development. Most of them got either none of that or a small portion of that. So then I start asking myself, why don't we treat software development like manufacturing? Okay, it shouldn't be a developer writes the code, they deploy the code, and then they hope and pray. Okay. That should not be the approach, right? Instead, how about we create the requirements, look at how that impacts development, um, add security, do some testing, crazy concept. Okay, supply chain. Where are you getting these updated libraries from? Artifact management, okay? Then you apply policy, then you look at risk, and then after all of that, you deploy. Once you deploy, you monitor and grab feedback. That is a factory, that's repeatable. Okay. So I call you, yeah. I'm sorry, Greg.
SPEAKER_01No, no, no, no, no, no. I want you to continue because this is important to understand. You just nailed it. I call that the scroll stop sentence right there. Is that the whole manufacturing world, how we assemble cars and a lot of other things and the software engineering, we're not doing that type of quality control. And that when it hits the market, it's almost like that's why nobody likes to buy Rev 1 of a software because you know it's full of bugs, right? But they test it and find out if it works or not in the market, not not in your organization, right?
SPEAKER_00You just hit it right on the head. Nobody wants to test before service pack one, right?
unknownExactly.
SPEAKER_00Exactly. So, yeah, so after years of seeing these same failures, right? Over and over, I realized
Four Pillars And Tool Overload
SPEAKER_00there were really four capabilities that every secure software factory needed. Okay, pillar one is what we call orchestrated delivery. You can't consistently build, you can't build software consistently that you can't secure consistently. So here we had crazy questions like uh, is these it's are security checks built into each phase? What is the developer velocity? Okay, how does security impact that developer velocity? Different questions like that. In pillar two, we call that developer-centric app sec tooling. Okay, security shouldn't slow developers down, it should make developers better. So, as such, developers should not have to go to the security tool. The security tool should go into the developer's workflow. Yeah, okay. That's the IDE, that's the repo, that's the pipeline. The tool should be where the developers live. Okay, they shouldn't have to learn anything new, just fix your stuff as far up the life cycle as possible. Okay. Pillar three is called supply chain and artifact management governance. Okay. I don't know if you guys remember solar winds, but that attack changed everything. Before solar winds, nobody was talking about supply chain attacks or any of that, but that changed everything. Okay, after that, supply chains became the targets, and this is probably the most critical piece, okay. If you guys remember the term patch management, yeah, this is patch management on steroids, and that was before AI. Since AI, this has completely exploded, okay? Completely exploded and become even more critical. And then the final pillar is unified risk correlation. Okay, companies don't have too little security data, they got too much. They need context, okay? How do we put all this data from all these different places in context? Stuff like cross-tool vulnerability aggregation. We got all these tools. What are they telling me holistically about my environment? Okay. Code to runtime risk mapping. Okay. How can I see throughout the entire life cycle, okay, the entire build cycle, and it's nine stages, by the way. But throughout that, how do I get to see the risk through all of that? And then continuous risk posture monitoring. And the key word is continuous. Risk just don't stop. So the assessment of those
AI Governance And New Liability
SPEAKER_00risks needs to be continuous through through the thing, through everything. And then after all that, AI happened. Okay. A lot of people were asking how do we use AI? My team was asking how do we secure AI? Okay. That's why a lot of the work we done recently with AI security assessments and AI governance and AI platform evaluation and model context protocol security is a natural extension, not a pivot from the secure software factory. Okay. Last year, Black Hat announced that AI security is a subset of application security. So I'm like, wow, I'm already in it. So I'm already there, right? So it's a subset of it. So our big insight was is that for 25 years, we weren't just building security programs. I was actually collecting evidence. Every customer taught me the same lesson. The tools change, the cloud change, AI change, but the underlying problem never changed. Okay. So I stopped asking, how do we secure the application? And I started asking, how do we build software that is secure by design? Yeah. That is essentially where the secure software factory comes from.
SPEAKER_01Wow. Okay. Yeah, no, you that helps everything. You you've you frame the whole technological discussion around this and understand. And we know third-party involvement in these breaches have doubled, and the vulnerability exploitation keeps climbing, especially during this AI era. And you've also coined this secure software factor. You've kind of you now I understand this. So if you're if a CEO says, listen to this, who builds software, or their CTO is building software, whoever it may be, and especially if they don't think of themselves as a software company, this now becomes important because most I think mid-market leaders think security is a cost center. They'll invest in it after the next funding round or after they land what you call the big client. Remember, we're talking about version one, like, oh hell, now it's horrible. But man, now they know it costs a lot of money to go ahead and relaunch that new software, and you can get a lot of legalities depending on what it
Secure By Design Wins Deals
SPEAKER_01is. Help us make the business case on how does secure software development actually win deals if it's already embedded.
SPEAKER_00Absolutely, Grant. That's a great question. Um, looking at it from a lot of angles, right? Um, it gives an organization a certain level of assurance that their software is built with security by design. Okay. It gives a certain level of assurance that um down the road, I'm not gonna have a privacy breach. Okay. That there's something out there called the OWASP top 10. And they have the OWASP, the top 10 for API security, for AI, as well as app set. Okay. That's one of the key things we we check, okay, is to make sure your software, in addition to all the other stuff we check, right? We're looking to make sure that it's protected against those key vulnerabilities. All right. And being able to show that you have a repeatable, okay, consistent uh piece of software that is being manufactured in alliance with best practices, okay, and a in a factory type environment, that that's huge. Being able to show those metrics, being able to show that value is just absolutely huge. The next generation of software won't necessarily be built by developers alone. Okay. It'll be built by developers working alongside AI. So our challenge isn't simply building a secure software. Software factory is building a secure software factory where humans and AI can collaborate safely.
SPEAKER_01This is important because AI is the new elephant in the room. And all of a sudden, I just had this discussion like had to be two weeks ago. I said, all of a sudden, now me and you, we're career IT people. We've been involved in information technology for decades. All of a sudden now, you got AI that's in the last two, three years, and now this AI agents, this AI nation, all of a sudden the world is becoming digital IT experts, right? And it's like it's so easy to go to cloud, let's say cloud code, like, you know what, build me a software stack, and it'll model it, you know, but you have no understanding what that's going to look like once it's released into the wild. You don't understand it's not just a matter of building a uh some code and then having it, you know, perform some kind of uh digital application, but not understanding what the life cycle is like. That whole manufacturing that you just talked about, all that quality control of software engineering, once it becomes out, remember this this legal, there there there are implications that that are out there. There are all kinds of things that you're gonna come across that you're probably not that aware of. So my question to you is, is now we've got this whole new world of digital amateurs, I would say, that are out there, you know, building code and releasing it to the wild. And I'm sure you're the the hackers that out there are just like just they love that just up. Talk to us if if you were talking to that audience right now, what what type of information or guidance
Guardrails For AI Written Code
SPEAKER_01would you give them right now?
SPEAKER_00Make sure all your code is being tested throughout that life cycle. Okay, do not just take AI's word for that code you're building. Okay. Um make sure things like input validation, session management, okay, um, authentication, authorization, those key items are being checked once that code gets produced. Also, analyze how that code fits into your existing code base, okay? Understand the the roles, the accounts, the permissions those roles and accounts have as it moves, as it can integrates with your existing code base. There is so much to change. And then those those LLMs, okay? Those LLMs that are producing this code, how are you governing that? Okay, that has to be governed. That's huge. A set of standards just got released um um in the last two, three months that internally produced or internally created LLMs, what they do outside your organization, you are completely responsible for. Okay. The onus is now on that organization. So if you create an insecure piece of software and it kind of uh and and through AI, it goes outside of the realms of what's considered your security policy and does something out in the wild, okay, um, that that that causes financial damage to another organization or individual, then you're now responsible for that. So governance of these AI tools we're creating is becoming huge.
SPEAKER_01100% what you said there. You've got to know, you know, you can't just say ignorance of the law is no excuse. And there are laurels out there, and cybersecurity is one of those things that you've got to be aware of. Now, I'm going to tiptoe to another side because I know you've done this at very large institutions.
AppSec Coaches And CI/CD Guardrails
SPEAKER_01You led an application, security transformation at a, I'd say a major national retailer that uh I think vendors still showcase today. And then without giving away any trade secrets, let's say, what actually changed inside that organization? And what does that story teach a 200-person software company about this kind of security transformation?
SPEAKER_00Absolutely. Um big thing we saw at this organization, right? Or the big thing that really helped is throughout the way, well, first, the first thing we did is we assemble what I like to call an app set coaches team. Okay. And what is an app set coaches team? Um, we initially evaluated all the different applications, the pipeline, everything, the developers and the different development groups. Through doing that initial evaluation, we were able to identify people who were in charge of some kind of security function. They were managing secrets, they were managing the encryption part, they were handling the login, which was the input validation and things of that nature. But I started noticing people who were doing key security tasks in development. Okay. So the first thing I wanted to do was organize those guys. Okay. And so I created something called an app set coaches group. We would meet periodically. They would talk to me about what they were working on, okay, whether it was encryption and I would be able to weigh in by them telling me what they were working on. I was able to weigh in with this encryption, make sure we're using these libraries. Okay. If you're doing secrets management, make sure we're using HashiCourt Law. Okay. If you're doing input validation or you're doing logins, let me show you how to properly do input validation so we can make sure we don't have cross-site scripting problems, buffer overflows, or SQL injections. Okay. So, and then what started to happen is once these guys start trusting me, they start telling me stuff. Yeah, guess what? Guess what Petey's doing over here? Guess what these guys are doing over here. So that was step one. Okay, just kind of mobilizing and kind of orchestrating the team and getting developers bought in to security. Because while they were telling me what they were doing, I'm telling them all of our security initiatives. If I wrote a Java security policy, first people I gave it to was the AppSec team. Tell me why this wouldn't work. And they would. They would tell me why this wouldn't work. Okay, oh, this is too restrictive. Oh, we're never gonna do this. Oh, I know how to get around this. You know, so having these guys help me craft these documents. When I would create some kind of app sec or cloud security policy, I took it to them first. Is this gonna work? Is this not gonna work? You know, if it is gonna work, let's talk about it, you know. So when we set up a devsec ops team, because eventually what happened is that all my apps start moving to the cloud. I didn't want to go to the cloud, but uh, but I had to follow my apps. Okay, all my apps went from that traditional three-tier web uh uh app server database um uh uh architecture to everything was containerized and Kubernetes. Okay, so I had to adjust. Well, first I had to learn what Kubernetes was, right? So then I had to then I had to adjust. And so that's what kind of took me to the cloud. And once we got there, we realized how you built it was key. And initially we used to scan, we used to just kind of scan when they told us to scan. And so when we start seeing CI CD pipelines, okay, we're like, wait, wait, wait, wait, wait, wait. We need to integrate in that CI CD pipeline. So anytime anything's being built, let's scan it then, okay? Give it a pass or fail then. Because once it gets in production, it's so tough to fix that problem then. Of course, and it's more expensive, but it's kind of what gave birth to it, okay?
SPEAKER_01I like that. I see, and so you're helping the audience, especially our software engineering um vice presidents and and people that own the architecture
Culture, Operators, And Night’s Watch
SPEAKER_01to understand this. Now, Knights Watch, you have assembled a I call a senior heavy fence. You got people that understand OT or operational technology, you've got an offensive security team, you've got people that understand uh identity and access management, Microsoft Security Def. What's your philosophy on building a team of operators versus building just a team of scale?
SPEAKER_00Absolutely. Well, first let me take you back to what nice watch means, okay? And that ties dead into how I chose my people. Um I'm a huge Game of Thrones fan. Okay, just I'm a ridiculous, stupidly blind Game of Thrones fan. Game of Thrones, House of Dragon, uh, Knights of the Seven Kingdom, all of it. Love it, okay. So, like many Game of Thrones fans, I became immersed in the show. The drama, the pageantry, the fantasy aspects of it, even the historical implications. Love it, okay. And what's crazy is I can remember being in Hamburg, Germany, Nice, London, and I'd be on a bar somewhere, and I would get into these in-depth Game of Thrones discussions all over the world, okay? And I would be amazed at just the reach of the show. And so in the show, okay, there was this great wall. Okay, and the great wall separated the north from the south. Okay, and the north represented this, oh my god, uncivilized, uh uh terrifying, frozen wasteland. Yeah, okay, that was full of spirits and ghosts and goblins and unexplained stuff. Okay, and so the people that manned this wall that protected the kingdom, the realm, from from all the dangers that lurk outside on the other side of the wall was called Nightwatch.
SPEAKER_01Uh-huh.
SPEAKER_00Okay.
unknownYeah.
SPEAKER_00They were called Nightwatch. And they were known as the protectors of the realm. Okay. So at Site at Night's Watch Cyber, we say we're the protectors of the digital realm. Okay. So in the movie, in the in the show, Game of Thrones, Nightwatch is considered a sacred order. Like these guys think it's a it is it is like a life's mission to be a part and an honor, to be a part of the Night's Watch, to be able to protect the digital realm. And they obviously they take that stuff serious. Like they take their job serious. So likewise, when I chose my leadership team, okay, I wanted people who didn't just do cybersecurity. I wanted people that live cybersecurity. Okay. And so everybody on my leadership team is somebody that fits that description. Okay. They eat, breathe, and love cybersecurity. It's more than just their job. It's it's literally their part. It's who they are, it's their life. So that's my leadership team.
SPEAKER_01A bunch of geeks that know nothing but people, all of them, good people. I I've talked to them. Um, we've been, you know, kind of close here the last five, six weeks, just working with Night's Watch, understanding your story. I like that you're standing guard on that wall. My last question I want to ask you, I want you to project a little bit into the future. Five years from now, when a mid-market software company hears nice watch cyber, what do you want them to think, feel, and do
The Five Year Vision
SPEAKER_01in your own words?
SPEAKER_00I want them to associate us with the secure software factory. I want them to think about night's watch and think about the conversion to how software was made to it being factory-like. Okay. I want them to think about the manufacturing process itself and how security becomes repeatable, measurable, and scalable. That's the software factory. That's the secure software factory.
SPEAKER_01That is beautiful, man. I want to thank you uh again for being on this show. I want to thank you for working with me. I only have one last question because I'm like that. And that is you work with me, you understand my process and how I work through the uh brave blueprint strategy. How'd you feel about that?
SPEAKER_00I feel it was great, man. Um let me tell you my grant story when I knew I had to work with Grant. We were, of course, you mentioned that we worked at zones together. And every year, every year, you're one of the leading sales guys. Okay. Always happy, always smiling. What's he so happy about? So yeah, okay, well, he's winning all the time. Well, okay, maybe he's happy about that. So I decide, and me, I'm a talent evaluator, so I like to be around talent. So and I was a solutions architect, which is a fancy word for pre-sales engineer. Okay, yeah, so I had to learn how to sell. So I targeted you and someone I wanted to learn from. So I went to Florida. I think you had some kind of health care, executive showcase conference thing, right? I'm like, all right, let me see what this dude is doing. So I go there and um I'm down there to learn how to sell. Okay, down there to learn how to sell. And I watch everybody in the room gravitate from me around you, want to work with you. Uh, hey, Grant, um, what kind of stuff you do? And you know, how can and and just everybody just want to work with you? And you didn't sell nothing. You didn't say anything. You position yourself a certain way, you connected with people. I think you interviewed a couple of executives and and helped raise them up, if you will, but you didn't sell in the traditional sense, but you position yourself to where the sales came to you without you having to be that pushy sales guy. Yeah, so I was like, you know what, as a Star Wars fan, I'm gonna learn that Jedi Lion trick. You know what I'm saying? Anyway, here we are, right?
SPEAKER_01You do not work software engineering. Yeah, that's that's funny. First, man, I'm gonna tell you, I love your your your origin stories got me, man. And I tell you work with you and understand what nice watch cyber does. Love to position you in front of so many different companies that need your expertise because it's nothing worse than releasing a product that all of a sudden just just gets hacked to pieces, or it affects their client base. Also, oh my god, you don't want to be that one. I remember I think it was either Targeted C or that they they targeted one um one of their uh software suppliers, got inside of it, shut target down for I don't know, week, compromise all kinds of different credit card numbers. This is an important thing to understand uh why you need a professional like this. This is not a cost center, this is gonna protect your profits. If you're looking to make money, you will make money by working with Knights Watch Cyber. So I want to thank you again for being on the show. And I can't wait to work with you some more, Darius.
SPEAKER_00This is doing thanks a bunch, Grant. Oh, you gotta tell us how to get to your website.
How To Reach Knights Watch
SPEAKER_00Oh, yes, definitely. kwcyber.net, guys. kwwsyber.net. Come see us.
SPEAKER_01I love it. I love it. And you can visit all your friends can come to five star number five star BDM. That is the number five, that is star be for brand, d for development, infromasters.com. See all the episodes that I have. I got over 280 of them with people just like theirs who are telling their story for you to get better at what you do. So I want to thank you again for being with us today.
SPEAKER_00Thanks, guys. Welcome.