Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 37, the week of October 16th. Alex, you just got back.
We missed you last week very much. Yeah, sorry I couldn't be here, Robb, but I was out in San Diego missing the snow here for the ISSA International Conference. Had a good time there. Did you learn anything?
I learned that aircraft carriers are large. We had a party on the USS Midway, which is, you know, a World War II aircraft carrier. So that was fun. Drunken sailors everywhere. Of course.
Yeah. Nothing but drunken sailors. Well, good stuff. Why don't we go ahead and dive into the news for this week? First thing we'll mention, we have some news on our website, right?
We have a new page out there. We've talked about it a couple of times and maybe not as a news thing, but we have been doing for a few years some security leader dinners and we added a page to the website to kind of talk about what those are. So on a monthly basis, we get together with some, some different security leaders in the area. If you are running a security program and you're interested in getting involved, You know, there's a, there's a contact form on there to get, to get contact to it. And of course, if you're looking to sponsor, there's, there's an opportunity to get to sponsor those as well.
So the first news story that we have, there's an article this week that said that a surprising number of men think that women are well represented in the executive ranks when it is 1 in 10 women, you know, so 1 woman for every 10 men. Well, there's— that's about right in the general population, right? There's exactly about 10% of people are women. Yeah, sure, sure. That's exactly how it is.
So about 63% of men apparently are bad at math. That's what this survey has come to show. 63% of men thought that women were well represented in the executive ranks. So some local news, the ex-head of the NSA and CIA, Hayden, came to Denver and started talking to some businesses here. And really the message that he gave to business leaders in Colorado was, hey, if you're waiting for the government to ride in and save you from security threats, You should stop waiting.
It's not going to happen. Yeah. So this was a panel on Thursday for the Colorado Association of Commerce and Industry. Of course, it was at the Brown Palace. Where else would it be?
But they focus a lot on, you know, small and medium-sized business and the challenges that they face in terms of security. I think it is— it's a little bit sad that there isn't that sort of government response for this sort of thing. You know, if Yeah. If you think of, you know, actual kinetic warfare, you know, if another country was attacking us, then, then, you know, the Army, Navy, other armed forces would be out there helping. But, you know, in cyberspace, it's completely different.
Yeah. I'm just not confident that they really could help in this situation. Right. There's not a lot that the government could do anyway. So there's— if they could, I bet they would.
Yeah, I suppose that's true. So next, Xero, which is a financial application company, sort of like QuickBooks or something like that. They have claimed the, the top floor for the new Circa building on Platt Street in Denver. So when I first saw this headline, I was thinking, didn't we just talk about them? And we did talk about them about 6 months ago.
They moved their US headquarters from San Francisco to Denver. So actually, their headquarters is just about a mile from my house at like Orchard and 25 area. And, and they are moving now their headquarters from the DTC up to downtown, about a block away from REI. I think that they probably realized coming from San Francisco to the Tech Center that the Tech Center isn't a super cool place to be. And then the Tech Center sounds like it's going to be really techy, right?
And so instead they got a nice building downtown. So they're not the biggest company that's investing here in Denver. Apple is right now looking to hire a number of developers here in Denver. Nice segue, Robb. That was a good one.
Yeah. So it's funny, this is, this is a lot of engineering that they're doing around Apple Maps and some other big data projects, which is sort of interesting. It's not something you normally think of Denver for, but, you know, MapQuest is here. Yeah. And we've, we've talked about Digital Globe a lot of times, which does the, the images that you use for maps.
So apparently Denver is a mapping headquarters. Yeah. So since September 12th, they have opened 3 new software engineering positions here. And it really, apparently there was some scuttlebutt that they're going to lease significant space downtown to build a big dev office. And maybe this is adding up to say that that's the way they're moving.
So the position that opened on Monday was in mapping data, and they say to join an exceptionally skilled group working with data science, statistics, geospatial data, and deep learning. So there you go. That's all we know. One more reason that Denver is a cool place to be. So is that the the last company that's moving here and investing heavily in Denver?
Or is there more? I don't know that it'll be the last, but, you know, I know it won't because Trimble Navigation, the GPS company, is actually doubling down in Denver and looking to double the size of their investment here. So they're an international company headquartered, I think, in California somewhere. And they're going to go from their current 500-ish employees to about 1,100 employees at their office in Westminster. Yeah, so we've heard from Clay Parker, right?
Yeah, Clay Parker, who runs security over there. And it's a very interesting company. They're very, very diverse in the things that they do, a lot of different services. I think that would be a pretty cool place to work. And it sounds like definitely expanding here.
Yeah, good stuff. So next, there was an article this week about how to avoid the network outage that could cost you the C-suite. Basically talking about how to secure your DNS. And this was by one of the co-founders of Secure64. Yeah.
And of course, we've talked about Secure64 a number of times. They, strangely enough, provide secure DNS solutions. So one of the cool things about this is they talk about what does that, you know, kind of DNS Armageddon look like. And then they also— another cool thing about this is it wasn't actually a Denver article. This is a national article that, that we happen to pick up and see.
Look, Pretty cool. Colorado company is the one who's writing it. Yeah, good stuff. Optiv was named a strong performer in 2 of Forrester's newest waves. So Forrester does their— the wave that kind of shows who's the leader in each area, and they were the winners for 2 different ones.
Yeah, I think people are probably more familiar with the Gartner Magic Quadrant, but it's the similar thing from Forrester. And the 2 areas were information security consulting services and digital forensics and incident response. So I want you to read this next headline. Oh, so LogRhythm has unveiled a self-evolving cloud-based analytics to enhance its threat lifecycle management platform. We'll do that one more time.
LogRhythm has unveiled a self-evolving cloud-based analytics to enhance its threat lifecycle management platform. In case you guys didn't get that, so they released a new product this week. I think they're calling it Cloud AI or something similar like that. So they're They're taking their SIEM product and enhancing it with a cloud-based solution. It's actually a pretty neat solution.
We've, we've seen it in action, you know, where I am, and it definitely has some good potential there. I think you're, you're starting to see a lot of these companies leverage the power of the cloud for things like, you know, behavior analytics and other stuff like that. Yeah, very cool stuff. And congratulations to them on getting that out to market. Last, last story here is not really an article, but just kind of a congratulations to Merlin Nameth.
Merlin's a friend of ours who was until a week ago the director of security at Red Robin and running their information security program. And as of this Monday, or I guess last Monday the 9th, he started as the business information security officer for Reed Group. Yeah, congratulations, Merlin. Sounds like a good move and good luck over there. Absolutely.
So that's it for the news. Once again, wanted to remind everybody that we do have a store. So if you want to buy any Colorado Equals Security merchandise, go ahead and check that out from the link on the website. Or if you don't want to buy it, maybe you could answer the trivia question first. Hey, so last week we did our first trivia question.
Thanks so much to Andre Gaeta, who's personally sponsored this. And thanks to those of you who reached out. For those who don't remember, the question was, what role did Blodgett Peak play in Colorado's history? And the answer is it was the alternative site that was considered to Cheyenne Mountain for NORAD. So it wasn't selected because there was an evaluation evaluation, they said the structural integrity of the mountain had veins in it that could split and cause it to crumble in if there was a massive shockwave or basically someone hit it with a missile, which seems relatively likely when you're building NORAD, right?
Yeah, exactly. I think you would want it to be secure. Don't want it to split in half. Yeah. So we're going to do our second trivia question, and I think we're going to be alternating.
So, you know, one week we're going to do something related to Colorado. One week we're going to do sort of a Colorado equals security trivia question. So the trivia question for this week, you're gonna have to go way back in our archives. Who is known as the first couple of security in Colorado and why? Yeah, I love it.
First couple of security in Colorado. So send us an email at info@colorado-security.com. First person to reply with the correct answer gets $25 worth of credit to buy something at the Colorado Equal Security Store. Sounds like a good deal to me. All right, let's jump over to events.
As a reminder, we do have a calendar of events on the website. Go out there and you can see what's coming all the way through. Actually, I think we're into January at this point, but over the next couple weeks, you want to start us off? Sure. So the first on our calendar, CSA is having their October chapter meeting on the 17th.
On the 17th as well, Carbon Black is holding an event called Becoming a Threat Hunter, really giving a couple hours of how you can use an EDR to become an effective threat hunter in your environment. Yeah, that looks pretty cool. ISSA Colorado Springs is doing their October chapter meeting on the 18th and 19th. On the 19th, the Denver ISSA meeting is doing their first ever government special interest group. So this is where people who either work in security in the government space or, or want to get involved there, or we want to just want to get to know more about that area, can get together and talk together.
Also on the 19th, SecureSet is doing their Cybersecurity Expert Series. Chris Roberts, who we have interviewed on the podcast from Calvio, is speaking for that. On the 19th, DENSEC is having their meetup. Make sure you follow them on Twitter to find out exactly where they're gonna meet, what table to go to. On the 25th, there's another SecureSet event, Hacking 101.
This one is on network security. And then on the 25th as well, the Colorado Technology Association is doing a talent series, Protecting Your Company's Trade Secrets and Other Confidential Information. This is probably a really good opportunity for you to invite some non-security people to this, some of your business leaders, maybe your legal folks, as probably they'll be speaking a little bit less security-ese in this type of a meeting. ISSA Denver is doing their oil and gas special interest group on the 26th. Yeah, so that's the first time that, that group's ever met as well.
Obviously, the ISSA has been trying to target those industries that have a good presence in Denver and give them a chance to kind of talk to each other and get to know one another from a security perspective. Um, also on the 27th, InfraGard is doing a business email compromise workshop. Well, we don't know for sure if it's about how to properly pull off a business email compromise system or to defend against it. So you really, you know, kind of flip a coin, see what it's going to be. Yeah, and I think this is a— I don't want to say an entry-level kind of event, but it's not one that's necessarily aimed directly at information security professionals.
So if you're someone that is, you know, in industry or an IT person or a business person and you want to know about business email compromise, this would be an event to go to. Yeah. And then finally, SecureSet on the 27th is also doing one of their capture the flag events. Awesome. All right.
Let's go ahead and jump into jobs. We have a couple of leadership positions this week in healthcare. So starting off, we have a CISO role at Healthgrades. Do you know much about Healthgrades? Yes.
So they, they've been based here for a long time and they do among other things, I think they do ratings on hospitals and medical providers. Okay, pretty cool. Um, Children's Hospital is hiring a director of information security, and so that's the position that, that runs their security program. Yep. Gates is hiring a security architect, and this would be reporting to Sam Masiello.
We talked about Sam moving over there. We had Sam on the show, a huge fan of Sam Masiello. This would be if you're looking to be an architect, or if you've been an architect and looking for a new opportunity with a great team. I'm sure he's going to build a great team over there. Vail Resorts is looking for a network security engineer, and we know those guys as well.
Ian Buxton and Ryan Dunn are friends of ours who work there. It's a small team, is I think, you know, for the size company they are, they have 5 or 6 security people. So you get to do a lot of really good stuff at a really large company that— and of course, skiing, free skiing. Of course, DaVita is hiring an IT security risk analyst. While we're at it, you know, Steve Oberg, great guy.
Ben Gilling, great guy. Also good folks to work with. Chan Healthcare is hiring an IT audit manager. I don't know Chan Healthcare. I don't either.
Okay. But it looks like an interesting position. We do know Western Union, and Western Union is hiring a senior information security analyst. I assume this is a few levels below Mike Kalach, but Mike's a great guy over there as well. Yeah.
Mantech is hiring a software vulnerability researcher.
Description here actually looked pretty interesting. So if you're someone that wants to be a security researcher, I think this would be a pretty cool job to take. Yeah, very cool. Ball Aerospace, we've talked with, uh, with Dan Collander, who's now over there, uh, that they're hiring a security awareness training and educating education coordinator. This is really neat.
Uh, not a lot of companies have something like this. This will give you a chance to, to really help enlist the rest of the workforce to helping security. Exactly. And then finally, Alchemy Security. We've talked about Alchemy before.
I interviewed Joe Bunnell, the CEO over there. They're hiring a systems engineer. Very cool. So that's it for the news this week. We are going to throw it over to the feature interview, which was with Al Barton.
Al is the president of the Colorado chapter of the Cloud Security Alliance, and, and really talking about what is CSA, what does this group do, and, and he does go a little bit into even how you can secure your own cloud Nice. Should be good. Well, we'll talk to you in about a week. Sounds good. Have a good one.
Thanks. This is Clay Parker, Director of Security Operations at Trimble Navigation. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb, and I am very fortunate today to be sitting with the president of the Cloud Security Alliance Denver chapter, Al Barton. Al, I have been excited to get to see you guys' chapter really flourish over the last few years, and as we sit together today, I want to hear a lot about the background on that. But the first question I want to ask you is, what is the hardest thing about cloud security? Well, hey Robb, thanks for having me.
Hardest thing probably about cloud security in my opinion is just all the moving parts as well as the different laws and regulations that different organizations have to deal with, whether it's you have data in the United States or North America, Canada, the EU, the different laws there versus if you're an international organization, you also have things going on in APAC. Just see a lot of organizations and I hear of a lot of organizations struggling to keep on top of all that while keeping focused on what they're their primary businesses. Yeah, it's really changed things, hasn't it? The outsourcing of managing our infrastructure. And of course, one of the hardest parts about cloud security is, what does cloud security mean?
If I ask you, you might be thinking about platform as a service or infrastructure as a service in AWS. And maybe I meant, you know, SaaS products like Salesforce. Right. And the problems are so different between the two. Yeah, most definitely.
Yeah, so let's back way up, right? Al Barton, the president of CSA, how did you get into IT? What, you know, were you a music major? Were you a CIS major? Talk to me how we got here.
How I got here, it was a long twisted road. My major was actually business management, human resources as a specialty, and I never, never really got into HR. Uh, started off in retail after I graduated college, moved out to Denver back in '93, um, and from there I did— I continued to do retail until I happened into, uh, work doing customer service at Oppenheimer Funds. Oh yeah? Yep.
So I did customer service for about a year, year and a half there, um, you know, just fielding investor and dealer, uh, phone calls on account maintenance and things of that nature. And then they had an opening on their help desk and I I thought, I like messing with computers, but I don't know that much. I didn't major in IT, but it was an entry-level position, so I applied for it and luckily I landed it. So I started at Oppenheimer Funds on the help desk down in— this was actually before they were at the Tech Center, when they were down off of Hampton in Havana, across from Kennedy Golf Course. And then from there, about 6 months later, I moved into desktop support, working in their remote technologies team, handling all the laptops.
Became A+ certified, Toshiba Tech certified, et cetera, and just went on from there. Moved to a startup in Broomfield in 2001. Unfortunately, the dot-com burst happened, so I moved from there to a company now called Trumo BCT, but it was Gambro BCT in Lakewood. Sure. Spent 13 years there doing everything from desktop support to some network work, work, eventually moved to security operations, and my last job there was as an SAP security administrator.
Yeah. Decided— did SAP security for 3 years, realized it wasn't something that I wanted to do for the rest of my life. I wanted to get back into security operations. So at that point, I moved to DaVita, spent 2 years there in their IT security operations. What years were you at DaVita?
DaVita was 2013, 2014, I was at DaVita. Yeah. And then I had an opportunity to become a sales engineer. I was approached to become an SE, and I always thought it was a cool job, a fun job, whenever I sat across the table from SEs that I admired and worked well with. Yeah.
So I came to what they call the dark side and started off with Trend Micro as an SE for about a year and a half, and now I'm at Zscaler. As an SE for Mountain States. Very cool. So, and when did you get plugged in with Cloud Security Alliance? Cloud Security Alliance was probably about 2 and a half, almost 3 years ago.
I took over. The previous board and president, you know Andy Lewis? Andy was in charge of Cloud Security Alliance, and I attended a couple of their meetings, and they had a board meet— they had a board election meeting, so I threw my hat into the ring, and— You were the one who didn't step back? Yeah, basically, that's almost what it was. For all those listening, it's not that hard to take over one of these groups.
Just show up and raise your hand and we'll put you to work. So wasn't Andy doing OWASP or was that quite a bit earlier or what? I think he was just finishing up with OWASP and he had started the Cloud Security Alliance and was working on that. Oh cool, so he started it? Yeah, he started the Denver chapter.
Thanks, Andy. Yeah, obviously the Denver chapter. Yeah. And so why don't you talk to me, I know a little bit about it, but for those listening who might not know, what is CSA? What's the larger organization?
And then maybe talk about the chapter. Okay. So CSA, the larger international organization is based out of California and we have multiple chapters across the world, Boston, New York, Denver, Singapore, Philippines, UK, et cetera. But it's basically to promote secure cloud computing practices.
And the CSA also creates some resources, right? You guys, they create the— I can't remember what this questionnaire— the cloud security. They got the CCSK. Well, there's a certification. There's— and I am CCSK certified.
I'll have you know. That's the Certified Cloud Security Knowledge. Knowledge. Yeah. I think I got the earliest version where you didn't have to Yeah, I took a test, but I think I've heard it's got a lot harder since then.
But then you guys have some other resources that, like, when you're evaluating your cloud security providers, there's a questionnaire that you guys created, the STAR assessment. STAR assessment, yep, there's that. They also do a lot of research and publish a lot of white papers. Because the cloud's changing so much, you know, IT's changed so much in the last 5, 10, 15 years, cloud is just seem to be accelerating that by, you know, a factor of 2 or even 3 sometimes. So, um, they're just trying to help organizations and professionals like us just keep on top of all that.
Yeah. And so you guys are, are a child organization of the big one, is it? Do you, do you guys have like a formal structure in that, or is it just kind of loosely federated stuff? It's more loosely federated. Um, the international or the, the parent structure is becoming more involved.
They just issued what's called their Summit in a Box to help the smaller organizations like the local chapter, like Denver, plan their summits. Um, and they just published that actually this, this month. But prior to that, you know, we don't pay national dues, we don't charge local dues here in Denver. None of our monies go back to the parent organization, so we're self-sustaining from that point. Yeah, so they have some resources for you, but it's, it's pretty loose.
So ISSA, on the other hand, Uh, if you're an ISSA Denver member, I think it's $120 a year, right? And $95 go to international and $25, whatever it is, go to Denver. Yep. Um, something like that. And it's, it's a much more structured relationship.
So interesting to hear how it works for CSA. So if, if someone's, um, someone comes to one of your chapter meetings and you generally meet on Tuesday, on a Tuesday evening downtown Denver, correct? What, what do people expect? What should someone who's coming there expect to get out of What we typically try to do is we have our chapter meetings, like you said, on a 2nd or 3rd Tuesday of each month. We try to have great speakers who are entertaining, and we try to stay as vendor-neutral as possible.
Because we don't charge any dues at this time, we're 100% reliant on those vendors, whether it's a company like Ping or Zscaler or Optiv. To sponsor that, that meet— that particular meeting. And, um, you know, afterwards we'll do a happy hour, which they'll pay for. And Netscope is usually what is pretty active there. Netscope has come in a couple times.
Um, actually, they're— one of their board members in Phoenix, Arizona is the SE covering Denver, uh, and I've gotten to be friends with him just talking about CSA stuff. Yeah. So we've had them up and, and they've, they've talked and they've supported us as well as Zscaler and, um, CenturyLink's been another big sponsor last couple— the last year. They've provided some speakers as well as the state of Colorado. Yeah, and I know Muhammad works for the state and he's on your board.
Correct. So actually, let's take a minute and tell me about the board. Who else helps you run this chapter? Okay, so on the board there's myself, we have Muhammad, we have Trish McGinnity, we have Trapper Little from DaVita, We have Brian Lewis from CenturyLink, and we have Janelle Heiss. She's in between some stuff right now doing some contracting.
And I know there's one other person I'm missing. Dario Monteglo. Oh yeah, Dario's at Netscope, right? No, that's Dario— different Dario. Yeah, different Dario.
Okay.
And so how do you break down the work between you guys? Um, so I'm president, uh, and again, I was the one standing there and everybody backed away, but, uh, we just talked amongst ourselves and like, um, because Muhammad's so involved in like SecureSet and doing teaching and stuff like that, he's in charge of our education. Okay. Um, because Trish is so well connected and she's got that great personality and she knows tons of people in town, she's, uh, in charge of our sponsorship. Okay.
Uh, Brian has a financial knack, so he's good Treasurer. He's our treasurer. Um, Trapper's our vice president. Janelle is our resource liaison to Nationals as we try to build that relationship there. And then, uh, Dario is our membership, so helping to drive membership.
So he likes to go to a lot of meetings and talk us up. Yeah, that's great. So over the last— earlier you were just telling me you guys have now had 24 months in a row of meetings. About that. Yeah, that's pretty great.
2 years of consistent meetings, and I know that's a lot of work, so good job to you guys for pulling that off. Well, thank you. Any highlights, any favorite meetings you've had over the last couple years? I think everybody's favorite is December, 'cause it's a holiday party. What do you guys do?
We usually just go drink. We've done the, oh, what's the, the, the, the presents that nobody likes when you get a white elephant gift. Yeah, the white elephant gift. We've done that the last couple years. Yeah.
Uh, and we try and make it fun. Um, where do you meet? We— so we, we used to meet at DaVita, um, but we've had some scheduling conflicts there. So what we've started doing is meeting at Muhammad's office for, um, Colorado State. Yeah, Office of IT.
OIT. Yeah, OIT up there off 16th and Pearl, I believe it is. Or 17th and Pearl. Um, but, and then we adjourned to Walter's 303, uh, Pizzeria. Oh, nice.
So that's— is that where the happy— the happy hour is and the white elephant gift? Uh, that's where it will be this year, probably, most likely. We used to do it at McLaughlin's, but I understand they recently closed. Okay. Uh, down there by Union Station.
So let's talk a little bit about, uh, you guys met— you mentioned, and we just actually announced it on the podcast, a recent episode, you guys are gonna have a Fall Summit coming up. And yeah, you mentioned that the resources that internationalize around Summit in a Box. So tell me, what is a Fall Summit? Is this the first time you guys have done it, and what's it gonna look like? No, it's actually our second time.
We did our last Fall Summit, our first one, last year. This year's Fall Summit for 2017 will be Thursday, November 9th, and it's gonna be at the Arvada Center for Arts and Humanities with free parking. Is that off 36 up there? No, it's off of, uh, just north of I-70 off of Wadsworth. Okay.
Um, so if you want to take a look at csacolorado.org, yeah, there's a link there for Fall Summit, and you can register and get more information on speakers, uh, and things of that nature. So basically what we're going to do, we're going to do something similar to Rocky Mountain Information Security Conference but not nearly as big. We're a one-day One-day summit. We're gonna open up with a keynote speaker. From there, we're gonna have 3 different tracks.
We have a business track, a technical track, and we're gonna have a compliance risk track this year focusing a lot on GDPR as well as, you know, we'll have some vendors there that are gonna be sponsoring. They'll have booths and just try to provide a lot of good content around cloud security best practices. Try to keep it as vendor-neutral as possible, but there are going to be some vendors there because they're sponsoring us to help us pay for the Arvada Center, pay for the food and things of that nature. But, you know, we're just excited to have a successful summit. We had 125 attendees last year for our first one, so we're shooting for 150 this year.
That'd be great. Have you identified any keynote speaker at this point, or are you still kind of on the hunt there? No, we got the keynote speaker identified. David McCurdy, CTO for State of Colorado, will be our keynote speaker. And then, like I said, we're gonna have 3 different tracks.
We're gonna offer 12 CPEs, and we're looking to finish up the day with a panel discussion. We don't have the topic yet, but Mark Weatherford, former state CISO, is gonna be our panel moderator, and We're shooting to get— we're almost locked in to have panelists from Google, VMware, and possibly AWS or Azure. Well, you have some really cool speakers. I'm just looking at the website. We have Drew Labbo, and Drew's a friend of the show.
He was the CISO for Denver Health and previous to that over at Children's Hospital. We've got Carlin Dornbusch, who was the CISO for Think Tank and now doing his own consulting service. Yep. Um, some other folks that I know on here as well— Merlin Nameth over at Red Robin. Yep.
Um, so anyway, a lot of good folks. Should be really interesting. Yeah, we're excited for it. Uh, you know, looking forward to a successful, uh, summit. And then next year, um, actually the CSA Nationals picked Denver because they, they can't help all the chapters every year, uh, with their summits or conferences, but they picked us.
So we'll have some national or international assistance from them as well. Nice. So that's great that your national or international group's going to be coming here next year. Do you have a date for when they're going to be coming? No, not yet.
Probably it'll be again sometime in November. We're going to try and keep with a fall theme. Yeah, that's really cool. And that also offsets nicely, like you said, RMISC, it's in May. It's kind of, you know, the other side of the year.
Nice to have an event, um, gonna count. Yeah, SnowFROC is in— yep, yeah, something like that. And SnowFROC, for those who don't remember, is the, uh, the, the Front Range OWASP conference that happens, happens every year that OWASP puts on. Um, so very cool, cool agenda. Registration is open right now for folks to sign up.
Yeah, we have early bird registration which is going on until, uh, October 30th. And then the prices go up after that. So please visit csacolorado.org and follow the links for the Fall Summit registration. Very cool. All right, so let's, let's chat about your guidance.
And, you know, you can give this from your CSA perspective or your, you know, working for Zscaler perspective. What's your guidance for people who are working at those companies who for years have been saying, hey, no cloud for us, we're staying internal? And, well, maybe we do need to start getting into the cloud. What's first steps? What should people start doing?
First steps are, you know, make sure— take small steps. Do deliberate planning. Make sure you understand what you want to go to the cloud first with. And actually, a lot of organizations might already be in the cloud, they just don't realize it. They might be using something like Ping Identity Management or Salesforce.com or Workday.
Things of that nature, and they don't realize, well, that's a cloud service. As far as moving their internal infrastructure and things of that nature, internal apps, maybe SAP or some internal manufacturing app up to AWS or Azure or CenturyLink or Rackspace or something like that, take a look and make sure that— actually, take a look at the CSA website to see exactly If there are any resources and white papers, see how other people have done it and how that might fit your industry or your vertical. And then you could start to make a project out of that. Take small baby steps and make sure you're comfortable with what you're doing. Make sure your stakeholders are comfortable, whether it's your internal stakeholders, your external stakeholders, your board, people of that nature.
And then, you know, there's only one way to eat an elephant. It's one bite at a time. Yeah, I like what you said about, you know, they're probably, they might be using the cloud. I say they're definitely using the cloud already. And their definition of what's cloud is probably just not quite right.
Yeah. And everyone is using some kind of a SaaS platform, whether you're using your HR system, payroll system. Exactly. Something like that's probably out there already. And I think you take that as an opportunity, right?
Hey, we've already made some investment in the cloud. Let's use this chance to look at what we've already done and start to make plans for what makes an acceptable cloud usage for us. As you come down the stack from that SaaS platform, software as a service, and start getting into infrastructure as a service, that gets a little bit harder and a little bit more management, but probably also where, you know, that's where a lot of companies are going at this point. Right, exactly.
Okay. For folks who, who are looking to get involved, so there's a lot of us, a lot of folks out there who, who look at cloud and security and say those are 2 big buzzwords, there's got to be a job there for me. Do you have any guidance for people who are looking to get into the field? How do they start? Where should they, you know, where should they put their toe in the water?
Um, you know, start coming to the meetings for all the different organizations, whether it's ISSA, ISACA, CSA, OWASP, ISC², and start talking to people. Find out what they do, especially if they're involved, you know, obviously all the groups I just mentioned are security-focused, but start talking to people, you know, are they network engineers, are they cloud security engineers, are they application, you know, where is their focus, and just ask them for guidance or pick their brain to see what excites them about their job. What it— what— where you might be able to relay those interests that you have personally into that type of role and go from there. You know, go to some conferences, hear some different speakers, and see, see what ignites your— the fire within you. You know, I know guys that are total network security and that's all they want to do.
They, they're not big on app security, and vice versa. There's guys that are very big on app security and Yeah, network security, it's, you know, they'll do it if they have to, but they'll leave that to the network guys. Yeah, good stuff. Well, I guess I'd ask you if you have anything else you want to talk to our audience about, to tell the community in general, any guidance for folks listening?
Yeah, just get involved. You know, Denver is a great security community. I love what you and Alex have done with Colorado security with these podcasts and the resources you have up on the website, something that was long overdue. You know, myself, when I— before I became involved with CSA, you know, I thought about, okay, yeah, maybe I should get involved with this group because I came to, you know, I went to an ISACA meeting here and there. I went to an ISSA meeting here and there.
But, you know, you're busy with work, you're busy with kids and family and, you know, trying to have some sanity in your life. But you got to just take that step and dive into the pool. I took that step and became involved with CSA. And at first, the first couple of months, I was struggling. We had 2, 3 people showing up at our meetings.
And finally, I just took the bull by the horns and I got a good board on board with me and I said, let's make this successful. How can we make How can we make it successful? So, you know, we sat down and started planning and looking at different things and, um, just tried to build it from a grassroots effort. And it's, you know, it's been fulfilling. Yeah, I just echo that, you know, getting involved, you know, life is not a participant or a spectator sport.
Yeah, life is not a spectator sport. We have— the more we remember that, the better we are at making that choice to get actively participating in what we do, right? The the more happy, fulfilled we are, and the better the world around us is. Yeah. Someone listening to this right now, it doesn't take that much effort.
Go spend a couple hours getting to know these groups and figure out what your mission is and go help out. Most definitely. Very cool. Well, Al, thanks for your time. Hopefully we'll check in with you maybe in a few more months, 6 months or so.
We can see how things are going at CSA, what you guys are doing, and hopefully we'll see the listeners at your summit on November 9th. Great, appreciate it, Robb. Thanks for having us. Have a great one. Bye-bye.
Bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.