Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for the week of October 23rd. Yes.
Yeah. Episode 38. And today I have a special co-host. Alex is out of town this weekend and we have Drew Labbo. Drew, how you doing?
Doing great. Getting ready for ski season. I did not enjoy the windy weekend. I don't know about you. I live in the West Suburbs and we almost got blown away.
So it was pretty crazy. Yeah, the weather this week was, was a little different for me than for you. I spent the week on the beach in Cancun, down in Mexico. The family, we took a kind of a fall break. Wonderful.
Hard to come back into the dreary Colorado weather right now. Drew, what have you been doing for— it's been several months since you've been on the show. What have you been up to? So work hard, play hard. The consulting is taking off more than I ever dreamed or anticipated.
So that's a great problem to have. Lots of playing with the kids. Did some mountain biking, fly fishing this summer. And like I said, can't wait for ski season. I'm a ski geek.
So I just cannot wait. Well, good stuff. We're glad to have you back and get your perspective on what's going on in the area. Thanks for having me. Let's jump into the stories.
There are 3 stories at the top of the feed this week around the Amazon HQ2 coming to Denver. You know, A couple stories talking about Denver, you know, officially submitted our bids with multiple different sites around the Denver metro area. And then there's also a story basically saying, you know, a lot of folks don't want Amazon to come to Denver. What do you think about all this? You know, it's interesting.
I think it's a double-edged sword. They're saying potentially 50,000 new jobs and $5 billion investment. What's interesting, you think about traffic congestion, housing, we already have a housing shortage. And there's an interesting quote from someone in the Wheat Ridge community. In one of the community groups there, and they said, should we be focusing on creating new opportunities in areas that are already thriving, or should we try— if we want Amazon here, should they be out in an area where we need jobs?
And I think if you look at this, is it really gonna end up in an area, right, where people need jobs and there's not as much infrastructure? Probably not. Absolutely not. Amazon's not even gonna look at an area like that, though. I mean, I think it's kind of the question between capitalism and socialism, right?
Do companies do what's best for the companies to maximize profits, or do they try and something that's right for like a big social good. I think asking a corporation that's responsible to its shareholders to, to look after some kind of a social good is, is an unreasonable thing to expect. Agreed. You're right, democratic capitalist society, to get a little geeky on it. Um, yeah, it'll be interesting to see what happens.
What, what I'm reading is it sounds like Denver's probably not going to get this from what I've read. Um, but who knows what happens. And if you think about location Denver's great, but we are flyover country, all right? So we're centrally located, but would this really be the best spot for Amazon? So I have mixed feelings.
Until I saw this article, I thought, yeah, I'd love to have them here for our economy. But some great points here to think about. So who have you heard is gonna get it? I haven't heard— I don't have any inside, like, you know, espionage or hacking info or anything like that. But I had just read a lot of articles that the opinion is that we're kind of a long shot compared to some other Like what countries?
I'm sorry, cities like on the East Coast, for instance. I know New Jersey's putting in— what was it, like $6 billion, $7 billion incentives? And we're at like $100 million. So massive disconnect in terms of the incentives there. But I really don't— I bet we don't really know exactly what the criteria is gonna be.
Certainly Denver qualifies, and it'll be interesting to see how it goes. It'd be neat to have Amazon here, my perspective. Certainly it'll change things, but it's it's not like they're going to hire 50,000 people overnight. There's, you know, there'll be a ramp-up process and we'll have the ability to plan for it. Hopefully our leadership is ready to do exactly that.
One thing I did see, Colorado's a little unique in that we are not going to make the taxpayers pay for these incentives, is what they're saying. So I do like that. I imagine New Jersey with $6 billion, the taxpayers are probably going to eat a ton of that, right? So, uh, kind of— I like the way Colorado's approaching this, and we will see what happens. All right, let's go ahead and jump into the next story.
Um, the Center for Digital Government has a, a set of awards they do every It's the, the annual Cybersecurity Leadership and Innovation Awards, which is anyway basically looking around the country and recognizing different government organizations for work they've done in cybersecurity. Cool thing is that the City and County of Denver won an award this year for their work on the 2016 Denver— excuse me, election— the election here in Denver last year and all the work Steve Corey did. Trying to secure that situation. Congratulations, City and County of Denver, and, um, nice recovery from the Anonymous, uh, attacks. Remember when they, they kicked the homeless out?
Um, interesting how Anonymous, they're the ultimate ethical judges, right? They, they get to decide what's right and wrong. So yeah, um, shout out to City and County of Denver, fantastic job. All right, um, the next one is a, um, the 9 best tech companies in Colorado from Matrix Marketing Group. It's an interesting post.
Um, so it's not top 10, it's top 9. It's kind of unique. Um, so some shoutouts, um, from the list, I'll just cherry-pick here. DigitalGlobe, uh, came in number 2, LogRhythm number 3, uh, Webroot came in number 5, and SendGrid came in number 9. Very, very cool to, to see, you know, 2 different security companies, uh, they're on the top 9 list, and also a couple of those companies who we've talked to on the show, uh, making it as well.
The top company on the list is called Oildex, and I didn't know Oildex. Have you ever heard of those guys? I had not, but software as a service for oil companies, it says. So interesting. And what I think what we're all seeing is software as a service everywhere, right?
If you're going to build a company, why build that yourself? Take these components and put them together. Yeah. From a paranoid security standpoint, how secure are these software as a service components? Is Oildex thinking about security?
Hey, if you guys are listening and you need some security guidance, reach out. We can help you get connected with someone Alright, next article. It looks like CenturyLink's next CEO is going to be coming from Level 3. So as of sometime in the next few weeks, there's going to be a merger, or rather acquisition, of Level 3 by CenturyLink is going to take place. And they've already announced that as of January 1st, 2019, so just over a year from now, the current CEO from Level 3 is going to take over at CenturyLink.
And then this article is basically saying, and by the way, he's not moving to Louisiana where the headquarters for CenturyLink is going to be. He's going to stay here in Denver. Yes, and it makes me wonder, just getting excited, would they potentially move their headquarters here, right, if the CEO's staying here? So we're making that up, yeah, but that would be neat. Well, the article does mention that they're committed to staying in Louisiana as the headquarters through 2020.
That's not all that far off in the future. Time flies. So absolutely could be preparing for that move there. Yes, so the next article is interesting. It's on the CableLabs blog, and this, this is definitely a little geeky, so we'll try to not get too geeky about it.
So, um, in the United States, more than 90% of households are connected to hybrid fiber coaxial. So that's the old-school coax cable. And if you look at your connections in your house, there's coax in there, right? Even satellite, right? Think about that.
And you start to wonder, is this interfering with my home infrastructure for speeds? And there's definitely an upload problem, right? So we get good download speeds, but uploads are terrible. And generally, if you have cable internet, you can get good speeds down, maybe, you know, 50 or even 100 meg down, and then your up is what, you know, a few megabits. It's pretty pathetic.
If you speedtest.net, you know, it's, it's pretty pathetic to see. So this is kind of a teaser article. There's not much detail here, but there's a DOCSIS 3.1 technology and protocol and specification We don't have much detail about what that looks like or how to implement it or what it would take, but I think it's the start of trying to make this better for consumers. Yeah, so just as a reminder for those who haven't listened recently, CableLabs is an organization that's owned by all the different big cable companies. They are a tech kind of innovation hub headquartered here in Denver where they're focusing on making new technologies for cable companies to use.
We know Mike Glenn, who's the CISO over there, and Mike shared this with us as something they're really excited about that's gonna be a new way for cable companies to get better performance out of the existing infrastructure. So what we don't know is how long is it going to take before they're able to implement this? You know, when do we start to see this benefit in our homes? And hopefully we'll hear about this soon. Yeah, and it's interesting they're betting coax is not going away, right?
Obviously. Well, I mean, it's everywhere, right? Yeah, it's a lot easier to, to do this than it is to run new fiber to all the houses for sure. Uh, so ProtectWise, uh, we got a note this week about ProtectWise standing up a brand new threat intel group called 401 TRG. This group is really focused on doing research on, you know, obviously threats on the internet, threats to enterprises, and sharing that information on a public blog.
So this is something right now, if you go out to the link on the show notes, you can see what they've done so far and look there in the future to see what they come up with and what kind of new research they share. Yes, and they are out of the gate quickly. They announced some interesting information about the Winti Advanced Persistent Threat Group. And how they're targeting online gaming organizations. So the hackers get more and more specialized, right?
The criminals and for espionage. Yeah. Red Canary has introduced an Atomic Red Team, which is a new testing framework for defenders. This is really interesting. As I was reading up on it, it sounds like they've really come up with a nice way for people to test small parts of their security posture.
So they call it Atomic to reference the small components of a larger team. So you can test these individual or these atomic components to see the effectiveness of them and how you would perform under a real attacker scenario. I love this. I— what we want to see from a security lifecycle approach, right, is build security in with some type of software development lifecycle, do some type of pen test like this, actually attack it. And until we start to see more of this, we're gonna— the hacker's gonna keep winning, right?
The bad guys are gonna beat us. So I love to see frameworks frameworks like this, uh, and I'm excited about to see how this takes off. Yeah, so sure, I, I definitely want to hear from anyone who starts using this, you know, share with us how are you using it, is it working, any tips you have that we can share with the larger community. Certainly interested in hearing more about that. Excellent.
So the next story is about Swimlane and how they've achieved some integration with McAfee. Security automation and orchestration is the space they're playing in. Um, really automated detection and incident response. And, uh, Robert, you and I were talking about this earlier. Is artificial intelligence and automation going to be disruptive in the security industry?
And I, I think it is. Um, how fast is this going to happen? I'm not sure. But we've been— the idea of a self-healing network has been kind of a nirvana for us all, right? We detect something bad happening and we stop it automatically.
So I think this has great promise. It'll be interesting, interesting to see, does this really take off and I have to wonder, can a human really be removed from this? I think there's going to have to be human interaction somewhere in this automation. What do you think about it? So my take, you know, I want to separate AI and machine learning as 2 separate principles for the sake of this conversation.
Machine learning is basically the machine doesn't have to have a human telling it how to get better at what it already knows how to do. It optimizes and learns as it's going. And then AI, artificial intelligence, is able to, to take the place of a human and make judgment calls in a bigger scope, right? A bigger scope. So I think from a machine learning perspective, most providers of security solutions at this point are using machine learning to do whatever it is they do better.
So your firewall company is probably using machine learning to be better at a firewall company. Your AV company is better at AV through machine learning. You know, across the board, people are using machine learning to be better at what they do. The real trick is going to be when you, when you try and get into the AI area where you go beyond just that narrow scope of what that solution provider does to make bigger decisions, look across tools and look across the organization to, you know, really take the place of an analyst. That's what— when I think we're a ways off, I think we're quite a ways off from that inter-tool interdisciplinary view of the world.
Now, of course, that is what Swimlane tries to help do, but it's, you know, highly manual at this point. You have to have workflows that are, that are well known and well defined. It's, it's when we get beyond those well-defined ones that AI would add a lot of value. One thing I'm seeing in the space is, uh, that software-based computing and software-based firewalls where particularly like an e-commerce site, then you just quickly spin up in Amazon Web Services and then spin back down, and these firewalls can dynamically do that for you, right? Set firewall rules, secure it, temporarily set up an external connection with egress and then turn it back off.
So I think we're already seeing that in that firewall space. So this is kind of a fascinating space to watch. And with a job shortage, on one hand we might think, oh no, they're going to take security jobs away. On the other hand, with such a huge— what's the number, Rob? I know you pay a lot of attention to this.
We're over a million jobs. Yeah, so over a million open jobs across the industry. Certainly we want to fill that gap. I know that there's people start to be worried about losing jobs to AI. I think we're so far off from that and it's going to create new, better jobs anyway.
It's like when robots take over the factory jobs. Yeah, okay, you did lose the job drilling holes in metal to the robot, but you got the robot manufacturer job and the jobs that are higher paid, better jobs in general. Great analogy. All right, well, let's go ahead and move along here. Um, I want to talk about SecureWorld, which is happening in 2 weeks.
It's on, uh, what, November 2nd and 3rd, or 1st and 2nd? We'll get to that in just a second. First, I want to just call out a session. Randall Frietzsche, who's a friend of ours, the, the CISO over at, uh, Denver Health now— yep, uh, he's doing a session on November 2nd at 11:15 AM called Maturing Third-Party Risk Management. This is going to be a great opportunity to hear him talk about how you mature your third-party risk program.
So go ahead and sign up for that. Try and make it if you can. And he is not the only local security guy who's going to be there. We've also got Alex, our own Alex Wood, as one of the speakers there. We have Cheryl Rose, Michael Stephan, Chuck Davis, Frank Vianzon, Mary Haynes, Dion Mahaffey, Lucia Turpin, Karen Orstel, and Jacob Rubin.
So a lot of local security leaders who are going to be talking at this event. Hopefully it's going to be good. Try and make it if you can. Excellent. We also have SecureSet.
They're doing a Hacking 101 workshop, workshop on October 25th. I always like going over there. So before, before we jump over to events, we just want to do a quick congratulations to JT Gaydo. JT has started a new gig over at Richie Mae. He is the executive director, excuse me, of their cybersecurity services.
So Richie Mae is a kind of consulting services organization in the financial services area, I think specifically mostly around mortgages, and he's going to be helping them head up a new cybersecurity services practice over there. That's excellent. And it's interesting when I think about some of the industries, you have law firms, you have CPA firms, kind of separate specifically from what JT's doing. And there's really not a framework around cybersecurity for them. And if you— I was talking to the FBI this week, kind of, you know, back channel conversation, and small, medium businesses getting attacked.
So these law firms, these real estate firms, CPA firms, they're getting attacked. And there's really— there's guidance out there, but there's nothing definitive. So I love seeing something like what JT's doing to actually help those industries, right? Yeah. Start with the financial Um, and work their way out.
And it— I hope we see something at some point for all these industries because they're literally flying blind right now. They don't even know what to do or what to look at. Yeah, so it should be interesting stuff. JT, of course, was the director of security at Square Two Financial, which went bankrupt, uh, what, a few months ago? And, uh, good to see him land at a great opportunity like this.
So we jump over to events. Just as a reminder for those listening, we do have a calendar of events on the website. Colorado-security.com. We have stuff filled out all the way into January at this point, but we'll talk through the next couple of weeks of events here first. So you, you were mentioning the SecureSet event.
Yes, on October 25th over at SecureSet. I like that facility over there. It's fun, a nice spot, and I appreciate what they're doing for the community. So I bet that will be great. Also on the 25th, the CTA, the Colorado Technology Association, is doing their Talent Series, Protecting Your Company's Trade Secrets and Other Confidential Information.
Once again, this is a really good opportunity for you to invite a non-security person to learn a little bit about the importance of security and how, how we should be looking at that. Yes. Next, um, ISSA Denver. Um, we have, uh, we've stood up our special interest groups for the past couple years. Um, we started in healthcare and that took off.
Um, we have Women in Security, which is going gangbusters, which I love. Um, we spread it, spread out to financial services, um, which JT is actually the coordinator for. We did our first government special interest group meeting last week. Oh yeah, how'd that go? We talked about that on the show last week.
Fantastic, fantastic smashing success. We had over 50 people there, um, and it was one of those meetings, just great energy. I was at the Hard Rock Cafe down on 16th Street Mall. Um, so the Oil and Gas Special Interest Group is coming up, uh, on October 26th, Thursday this week. Um, we have almost 60 people registered.
Great. So we're really excited about this, and it's really neat to get people in the industry together. And of course we have some people that aren't in the industry that show up to learn more about it. But great networking opportunity, great way to build community. And it's interesting, I learned something at these meetings about these industries that I wouldn't have known otherwise.
So we're really excited how this is taking off. We're thinking about expanding into K-12, that kind of primary education, maybe higher education. So that's kind of next, I think, for us. Great. But looking for volunteers for anything?
We are, yeah. Gosh, these special interest group meetings are pretty difficult to set up with the logistics. What we try to do is do it somewhere fun. So you're at a neat venue, you know, you're not sitting in a corporate office with no windows and falling asleep. So yeah, for that K through 12, that's kind of what we're looking for now, some help with that.
So yeah, thanks for throwing that out. Very cool. On the 27th, InfraGard is having a business email compromise workshop.
Yes, that's the vector, right? It's phishing, right? That's one of the top vectors we're seeing. And again, I was talking to the FBI and some InfraGard folks this past week. And they're saying that's what they're seeing right now.
It's all compromise that email and you're in. Yeah. So next, gotta love SecureSet and what they're doing for our community here. They're doing a capture the flag exercise on October 27th. For those, you can show up at 5 o'clock for kind of an entry level, get, you know, get acquainted for what's gonna happen.
And then the main event starts at 6 o'clock. On— well, we talked about this earlier. SecureWorld Denver is happening November 1st and 2nd. So those are the dates. If you're not registered yet, it is not too late.
You can get signed up now. Also, um, starting on November 1st, it's actually the 1st through the 3rd, is NCC's Governor's Cybersecurity Symposium. And that is kind of a who's who of security in Colorado and also some real national folks. Um, we've got General Petraeus is going to be there. Looking up who else we have.
Obviously Governor Hickenlooper, um, Ron Ross is going to be there. This Suma, who's the CIO for the state of Colorado, is going to be there. Dale Drew, the CSO over at Level 3. Lots of great folks will be at that event. It is not free to attend.
You need to register, but take a look. It looks like a pretty cool thing if you want to. And that's in Colorado Springs, I think, at the Broadmoor. It looks like it's at the Broadmoor. Yep.
Love the Broadmoor. All right. So jumping over to our trivia question. So last week, the question for the group was, who is known as the first couple of security in Colorado and why? And of course, if you've been listening to the show for a while, you know it is Steve and Gail Corey, the CISO.
Steve is the CISO for the City and County of Denver. Gail is the CISO for Oracle's cloud business. And of course, why are they the first couple? Because they are CISOs for a couple of very important organizations, and of course they're married here in Denver. We will go ahead and go with a new trivia question for next week.
Once again, thank you to Andre Gaeta who is sponsoring. And as a reminder, if you know the answer to this, please send us a note. Andre is going to give you an item from the Colorado Equal Security Store valued up to $25. We have had very few responses over the last couple weeks, so if you get something, if you think you know the answer, send it over to us. Even if it takes you a couple of days, I think you'll have a good chance.
All right, what is the name of the role or job that was created to protect gold and other valuables in Colorado and other U.S. railways when U.S. Marshal forces were insufficient in the 1800s? So this is something that I'd, I'd So Andre comes up with these awesome questions. I had not heard of this one before, but until— I didn't know the answer, I should say. But once I heard the answer, I'm like, oh yeah, I've seen that in movies.
So you guys might recognize this as you go take a look. You probably can find this with a little bit of Googling if you need to. And with that, let's go ahead and jump over to jobs. Oh, before we do that, if you know the answer, send it— send your answer to info@colorado-security.com and we will, uh, we'll get back to you. With that, let's go ahead and jump over to jobs.
Excellent. So, um, for their first job, we have PwC, PricewaterhouseCoopers. They have a cyber privacy manager position open. And we have a, uh, at Premier Members Credit Union, an info security analyst. Department of Defense has a position for a counterintelligence officer.
Well, that sounds interesting. Sounds like James Bond stuff, right? Right. Do you have, do you have to be able to kill people to do this job? All right, EMS Software is hiring a Director of Cloud Operations and Security.
Interesting. The City of Golden is hiring for Information Technology Manager, and it looks like that position does have security underneath it as well. Spectrum is hiring a Supervisor of Network Security Operations. Blackstone Technology Group is hiring for Project Manager, Risk Management and Information Security. InteliSecure is hiring a Data Protection Analyst.
Applied Trust up in Boulder has a position for an information security engineer, uh, and I know that, that group pretty well. They've gone from, um, 26 employees, I think they're over 47 now, and they continue to grow like gangbusters. Good for them. And finally, this one is actually probably the most interesting to me. Great West Financial is hiring a director of data science, security data science.
Wow, that's a big job. Do you have to have a PhD for that? Um, I, I, I don't recall I had to have a PhD, but certainly want someone who knows data science and can get hands-on with it. Really, this is the first time I think I've ever seen a security data science director position. Yeah, I don't— I don't— I'm trying to think.
I've seen some other, you know, business analytics, business intelligence, but data science is kind of the new frontier, right? Really understanding data, and especially for a company like them who's, you know, they're not, you know, a provider of security services. Uh, very, very interesting, and looking forward to seeing how that goes. And, uh, hopefully, you know, they can find the talent they're looking for. It certainly is a scarce commodity for data science and security together.
It is. And I've, I've seen an interesting trend, or I've read about this, that they're actually starting to hire data scientists as developers, which I think is pretty interesting. So understand data and how it works. And, um, I think that core skill set around data science and also hardcore math majors, it's interesting, they're starting to become developers. So interesting.
I also heard a quote this week that, um, there's this idea that if you want to be a security professional, you have to know how to code, just along those lines. So that's a whole nother conversation. Maybe it's a topic for another day. Um, I have mixed feelings about that. I don't think it's all about coding, but we'll see what that— see what that looks like.
All right, well, with that, we're going to go ahead and throw it over to the feature interview. This week's feature interview is with Mike Benjamin. Mike is a VP of Threat Intel and Security architecture over at Level 3. So talking about Mike, about the upcoming merger with CenturyLink, and just get to know him a little bit. He is one of those unique guys in this, in the security world, and really in technology in general, who spent pretty much his entire career with one company.
He got, he got hired into Level 3 on the call center. He was answering people's calls about their, you know, internet connectivity not working, and he's been there for, I think, 18 years now. Well, to go, to go from, you know, relatively a lower level position all the way up in the organization and When you, when you do that and you get to the top and you know you've worked way up, that's a really unique perspective. So I can't wait to hear this. Very cool.
All right. Well, thanks, Drew. Appreciate it. Thank you. Well, hopefully we'll have you back again soon and hopefully Alex will join us again sometime soon as well.
Miss you, Alex. All right. See you. Bye. This is Rob Winter, Chief Information Security Officer at Boulder Community Health.
Welcome to Colorado Equals Security for Colorado security professionals and by Colorado security professionals.
Welcome to Colorado Equal Security. This is Robb Reck, and we're doing our feature interview today with, with Mike Benjamin, who is the VP of Threat Intelligence and Research at Level 3 as of today. And, and we are recording here in early October, and you may have heard in the news Level 3 is in the process of merging with CenturyLink, 2 of the big ISP telco providers in the world and certainly here in Colorado. So Mike, I'm going to want to hear a lot of your, your take about what's going on in the industry and what you're doing at work, all that fun stuff. But first I want to ask you, what is your favorite flavor of moonshine?
I am ignorant enough of moonshine to not know that there's multiple flavors. Have you not enjoyed Lance Miller's homemade moonshine a couple of times? That is the only moonshine I've actually ever had. I know he makes his from potatoes, and that's about the limit of my knowledge. So sorry to disappoint you.
Well, so the, the moonshine that Lance Miller makes, it comes in different fruit flavors, and it's the only moonshine I've ever had as well. Okay. Um, and, uh, generally, you know, the peach or the, the strawberry, it's the little aftertaste after you, you know, you've kind of burned your, your mouth and your throat. You're like, I, I think there might have been some other flavor in there with it. Anyway, for those who haven't had it yet, come over to my house and we'll get you guys set up with some moonshine.
Is that a felony? Is it against the law to talk about moonshine on the air? I don't know, but you might find out. We might find out. All right, so let's talk about, about, you know, what, what you do and how you got to do what you do.
At some point, you were presumably a very young man who didn't know a lot about computers, and somewhere along the line you picked some computer skills up. Can you talk to me about that? I can. It's sad to think I'm not a young man anymore though, Rob. Thank you for that.
I appreciate it. I think I said very, very young. You're just young now. So, it actually starts pretty early. I was maybe 13 and my dad brought home this floppy disk.
It contained the software for the service called America Online. Yeah. And he put me in a teenage kid chat room and said, Chat away, Mike. Have fun. Nothing bad can happen in here.
Yeah, it was great. I quickly racked up a good $100 bill on my dad's credit card, and that made him ecstatic. And he really immediately— we paid by the minute. No, I know the bill. I remember the bill.
It was him being ecstatic. Oh yeah, just a little sarcasm there. And so he went back the next day, I think, and got a PPP Unlimited dial-up account for me, and he put me on a service called IRC. Yeah, and I joined. I found more teenagers to chat to, and it was great.
We talked, and then one day people came in and they took over our chat room. The next day, people were knocking each other off the internet, and I had no idea what was going on. I was fascinated by how were they manipulating the internet. This is, this is amazing. And I, uh, I don't think I ever stopped learning from there.
And so, uh, fast forward a few years, I graduated high school. I was a competent Unix admin, ran Linux and FreeBSD, could program in C, read every bug track email I could get my hands on, and I was a teenage kid who spent too much time on his computer and not enough in school, I think, some days. So where were you— where'd you live growing up? Grew up in Phoenix, lived there most of my life. And you got out of high school, I assumed.
What did you do after going to high school? I got a scholarship to go study computer science at Arizona State. Yeah, and I quickly got bored, to be honest. I, I was really excited because I knew these things about computers and talked to people on the internet about it, and I showed up to Arizona State and there really wasn't anyone to talk to. There was a fledgling Linux users group with a couple people interested, but I was mostly interested in security, to be honest, and there wasn't anyone to talk to.
And so I actually left after my first year and went and got a job. Yeah. What was your first job? I worked— so it's interesting, actually. While I was in high school, I did dial-up internet tech support.
And so when I left ASU, I was qualified with my 2 years of tech experience to go get a job as a customer service person in a technical call center. So customers had T1s go down, DS3s go down, their traceroute was slow, whatever. They called me and my, my crew of merry friends, and we helped them understand what the problem was and send it off to be repaired. Yeah, well, that's pretty cool. That's it.
That's a good way to get to learn the backbone, right? Mm-hmm. And probably gave you the fundamentals of how the internet works at a bigger perspective than you can from a Unix box somewhere plugged into the internet. Yeah, one of the things that I learned the most was how ignorant I was to how the internet actually worked when I showed up. To your point, you, you see it from a system endpoint perspective and you think, I understand how a TCP socket works, or I understand how packets get from A to Z, and quickly I realized I didn't.
And so I spent about the next 10 years working all the way up to network architecture and designing a really large internet network with a team of folks and learned a lot of fascinating things about scalable systems and, and the internet. So it's interesting, you were a customer service rep answering calls from people who are having problems with their service and that is an entry-level position with probably not a ton of exposure to the rest of the organization, probably pretty insulated. I've been a customer service rep before in my career, and I know it's not, not the best way to get to know the company. How do you go from that, that entry-level position to getting to do, you know, designing of networks and the bigger picture? Uh, slowly is probably the, the best answer, right?
So from the call center to the NOC, from the NOC to the backbone NOC, and on my way up. I think I really learned what the broader organization was doing when I first got into management though. When I was in the team that was developing all of the technology for our network, all our services, the standards for that technology, I had to work with product management. I had to talk to sales and I met with customers and that was the first time I think I really broadened outside of that technical role to get a clue really what was going on beyond those walls. Tell me about the career.
You made a couple of moves there. How long did you work there? I've never left. Is it just acquisition after acquisition? Yeah, we're a few acquisitions deep.
And yeah, so I've been there since '99. That's pretty good. That's a pretty good run to stick around at 18 years without having to go do a new interview for a new company. Well, I definitely had to interview inside the company, but yeah. No, and I'll say some of it was dumb luck coming through the dot-com downturn and other things, right?
I, yeah, I worked hard and had a unique skill set as it was Unix and other things, but it was— it's been a lot of fun. Had to do a lot of different things and got to learn quite a bit. Yeah, it's, you know, your path is definitely a rare one to see someone make it all the way up the ladder from individual contributor to a VP level while staying within an organization. Generally, it's hard to get recognized while staying in an organization, at least quickly. So how— tell me, how do you— what do you think you did there to put yourself in a position, or what were the unique circumstances, you know, over the course of those 18 years that gave you those opportunities?
That's a great question. You know, I think it's probably— it's not any one thing, of course, right? One of it is attributed to what makes a good security person in the first place, always wanting to know what's going on and always wanting to fix it. I always wanted to tear it apart and things. And so when you see projects going south, stepping in and picking them up.
When you see a technology implementation that's not effective, redoing it. And so picking up those things that are difficult and finding fun in those opportunities is— was definitely an attribute that helped quite a bit. The other was honestly an ability to articulate to management what was actually going on. Management does not care the inner workings of BGP scale, but understanding that it has a capital impact on a purchase is interesting. And so being able to articulate the technology back to the business was something that came in handy.
And, you know, I grew later in that timeframe, but that definitely helped quite a bit as well. So you've referred to yourself as a security person several times. You were a security person at age 13 or 14, then you got a job as a CSR. And while it sounds like you might be a security guy, your job was not a security job at that point. How did you make that move from kind of the mainline business to saying, you know, security is what I'm passionate about, that's what I want to do full-time?
So I ended up in an interesting position after our company was acquired where I was actually leading a product management team and found myself with business responsibility for— can't say specifically, but hundreds of millions of dollars in revenue. And one of those was our security business. And had an opportunity to sit down with leadership of the company and talk about the investments we should be making in security. Yeah. And why those were important to a lot of things that we were doing as a company.
And that gave me an opportunity to spend a lot of time with the security team. And there was an opportunity that arose. Our CSO was looking for someone to lead his architecture and engineering and threat intelligence team. And the time was right where I was finding product management was not quite what I wanted to do long-term. I really missed the technical day-to-day aspects of what I was doing, and I took that position.
So I was able to make the full circle by running part of the security business and spending time with them. Yeah, you are highly technical for being a VP, but for being a product manager, like, that's messed up.
It must have been very frustrating for you to know how to do the job better than some of the people who were doing the job in the technical area and You know, that wasn't your role there though. I'll admit a few times of putting the marker down when I started to whiteboard. Yeah, the— thankfully I do work with a huge talented crew of architects, right? So they didn't need me picking up a keyboard by any stretch of the imagination. So, but yeah, that's what I missed ultimately was I did want to do some of that, and that's why I went back to the technical role.
Yeah. So, you know, obviously the last— what's it been, 18 months since the announcement of the merger with CenturyLink? 2 years? About a year. About a year.
Yeah. Um, over the last year, there's been a ton of talk about what's it going to look like, new organization. And obviously you can't comment on any— anything sensitive, but just talk to me about how, you know, how this news came about. What— how do you guys see this, this merger? Whatever you can talk to me about in terms of the CenturyLink and Level 3, and what does that look like?
Yeah, so we're obviously both 2 successful global telecommunications companies. Yeah. Have a lot of customers that we think we can take advantage of each other's assets, each other's product capabilities, each other's staff, and service them better. And, um, you know, continue to do that on a global basis, on a local basis. Yeah.
And if I remember correctly, CenturyLink has a lot more employees, but the revenues were not that far off from one another. Level 3 and CenturyLink. Is that right, that roughly the same revenues between the companies? They are. They have a higher revenue load than we do.
But also, if you look at the markets that we both exist in, you'll see differences in how we run our businesses. So a direct comparison is probably not the most appropriate, but ultimately it builds, you know, one combined telecommunications company to service enterprise and consumer as well. So the, the, and I, you know, I mentioned we're recording here in early October. Um, by the time we, we air this in a few weeks, you know, things may change with the status. I know that there's been regulatory approvals going on in different states, and, uh, we several times we've seen news coming through on that.
Um, do you have any, any inclination on how the— this is going to impact you in the future going forward with what you're going to do? Is that something we could talk about or we can't talk about at I'm excited for the future, Rob. That's what I can tell you for now. So, I mean, I think it's fair to say that there's going to be a huge opportunity at this combined company, lots of interesting stuff to do. And I'll just say my perspective, they'll be very lucky if you're one of the main people doing it.
So, I know we've talked a little bit before about some of the stuff you do around, you know, we call it threat intelligence. That means a lot of things to a lot of people, but, you know, becoming intelligent about the bad guys on the internet. Would you mind talking a little bit about what it means to you, what threat intelligence means to you, and what one might do to become really good at that? Yeah, absolutely. The first thing it is, and the skeptic in me says this, is it's a buzzword.
To your point, it means so many things to so many different people. But the way I look at the area is really companies understand how to run controls. They know how to block things. They know how to filter things. They know how to protect things.
I think it's probably universal. Some are better than others, of course. What you see more difficulty in is the people monitoring, watching, looking for anomalies in their infrastructure. The people who then, after they put their control structure in, actually watch it. And a lot of companies struggle with it.
How do I actually effectively watch what's going on and discern the false positives from the true positives? And so to me, one of the things threat intelligence does is just helps with that. If you know where the bad guys are coming from, if you know what tools they're using, if you know what techniques, what capabilities, what their malware looks like, if you have that corpus of information and you can use that to know where to look a little more effectively in that big data set you hopefully are collecting about your company, it's really valuable because no one is perfect at every anomaly detection. No one is perfect at exactly knowing where to look for everything. And so, I mean, if you can add to that the information about where the malice is and what it looks like, that should help quite a bit.
So that's to us what threat intelligence is, is help people know where to look a little bit better. So use, you know, leverage your time to understand what the bad guys' TTPs are, right? Tactics, tools, and protocols. How basically, how do they go about their attacks and which attackers are targeting my company and then say, okay, I match those up and now those are the things I should be looking for. Is that, is that kind of where you're getting to?
Yeah, so more broad than that ultimately, right? Um, so there's, you know, varying risk scale of where a company sees risk from the most commodity-driven, you know, if you didn't patch 6 months ago, somebody's written an automated tool that's scanning the internet for that and you're probably in trouble, right? And so you probably need a list of what people are scanning for and where they're coming from. That's the lowest sophistication end of the scale. Where most of the damage is being done is more on the criminal side, right?
So we've got gangs, you've got organized crime in parts of the world where they're trying to launch attacks. And they, of course, have a bottom line themselves, and they're not churning over their entire infrastructure every day. They may turn over IP addresses, they may turn over malware samples, But maybe the functions within that sample are consistent. Maybe they're turning over the frontline infection points, but not higher levels of their botnet. They never wipe out the entire thing on a day-to-day basis.
And there's always a linkage day-to-day in what their, their attack looks like. And so an example for you, the Necurs botnet delivering the Locky ransomware. Everybody's got ransomware top of mind. How do I protect against it? If you knew where the mail was going to come from that contained the macro dropper or the binary or the link to click on, that'd be immensely helpful to stopping ransomware.
And so piecing together what the entirety of that criminal network looks like is really helpful to stopping, whether it be that stage or if tomorrow Necurs delivers a different point of malice, knowing where that comes from or knowing what techniques Locky does once it's dropped on the machine. Looking at that kind of information is really helpful to blocking the attack itself. So I've talked with some folks about this and there's this perception that there are so many adversary groups and so many attack types that a normal-sized organization can't expect to keep on top of that, can't know, you know, that, you know, every group and every attack type. So for, you know, for SMBs or even maybe really any enterprise as well, what would you expect as a reasonable investment in threat intelligence? What should they plan to get out of it?
Should they try and understand like the top 5 groups? Should they outsource the whole thing? What's your take on that? So to me, if the company's small or the risk of attack from a specific targeted actor is small, worrying about who the people are is of lower value. I know there's people in the market that disagree with me on that, most definitely, but I know if I was worried about protecting only my financial system at a mid-sized company, I don't care exactly where the attack's coming from.
I just know what it looks like, not stop it. That's my concern. As you get into the higher value targets, you do get more sophisticated actors, and that might, that might glean a little more value out of knowing exactly who it is because you know a little more about what they're after. You know a little bit more about what tools they specifically use when targeting you. But for most of the market, the, the actual knowledge of who it is is not where the value is.
It's all of the TTPs. Like you said, what are all the things associated with the attack that they can utilize to either block, find, detect, whatever it is inside that control or monitoring mechanism that they can use the data? Yeah, so we start to understand what does an attack look like, what are the very prevalent attacks look like, and look through our logs, through our SIEM, look through something to say, has this happened to us? And would we call that an indicator of compromise or an indicator of attack? What would you call that?
Depends on where it is in the, you know, if you like the kill chain model, where you are in that model. But ultimately the goal should be detection somewhere in that chain, hopefully before the exfil step, right? But even then, it's— even then, if it's just beginning to exfil, that's still of immense value. So would you mind taking a moment just to talk through the kill chain? You know, if you want to credit Lockheed Martin, you're welcome to.
If you don't, I won't, I won't point it out. So it's a model that's developed, and I won't go through it in detail, but it's conceptually a way that you can segment an attack. So it starts with recon. So I would like to attack Company X. I need to learn information about Company X. So our industry talks about attack surface.
So understanding the attack surface of, if you're the bad guy, what would you go after? Where are their public web servers? Where is their DMZ? Where is their NAT? Where do their users work?
What are some names, email addresses, anything you can find? And that's everything from using DNS to enumerate hostnames through one of the more popular ones lately is look at GitHub for accidentally committed code from the company, right? Find things about their company that you can use to compromise them, and that's recon. Thankfully, that can be noisy. Enumerating DNS hostnames means a lot of DNS queries, and so if you can find that step of the attack chain, Beautiful.
Now, you know someone from that particular host is looking at you. And it ultimately goes through and you eventually exploit, you break in, and you carry out what you were looking to do. And it's a model for, for a variety of things, but ultimately think about it like an incident response or a DFIR kind of view that says, if I can segment the attack into these pieces, I can think about each individual step. And so that can be used to link together common toolkits at each step. Yeah, so one group might use the same exploit 10 different ways, and by isolating the exploit step of the kill chain, you can now associate how they're working as a group and think about stopping the exploit rather than stopping the 10 different ways they're doing recon.
Yeah, from, from the CISO perspective, I love the kill chain model for me to think, all right, how— for a long time we focus really heavily on preventing them from the infiltration, preventing them from getting into our organization in the first place. But number one, there's stuff that happens before that. You're talking about the reconnaissance and starting to get that intelligence there. And then much more, I think, much more actionable is once they're in, there's a huge difference between that breach that you found out about right away and were able to shut down and the 6-month advanced you know, access that they have that, you know, ends up with, you know, 3 billion records on the internet or whatever, right? That's the big difference where it happens.
And I love that model as it's easy to talk about with other executives and really get buy-in for, hey, we're not just gonna put a firewall, we're also gonna have a person monitoring our system's behavior to look for something anomalous. I really appreciate that. So thanks for talking about that a little bit. Huge tangent. Where were we before we got into the kill chain?
What is threat intel? Yeah, how do you use it? Yeah, um, so companies that want to do it, we see value in, in understanding what they do versus who's doing it. Do you think it— do you think that it's— that is a commodity that they can buy from a service provider, or is it so custom to their— either their company or their industry that you think that we need to each have resources inside the companies? Again, it's going to vary, right?
And so for some folks, understanding basic levels of a list they can buy from someone's their right answer. For others, I'm a bigger fan of buying that more operationalized, right? So having someone else look at the log set of the company, associating it with the bad guy data, and putting back information into the hands of the analysts at that company. I think for most people that's a little more valuable because otherwise we're talking about you buying a list and doing a ton of IT development to integrate it into all of your security systems. Yeah.
On the high end of the market though, as you think about higher value, having someone insourced that can truly understand and retain the knowledge about what those feeds, alerts, alarms, however it's consumed, is really valuable because now understanding how it applies to the backend, to your company, to your assets, That's important. So knowing that we had an attack against a database that followed this technique 6 weeks ago and we're seeing it again is really valuable in defending that database and realizing that it must have something valuable that folks are after. Maybe we need to review how it's secured. Maybe we need to change it completely and move it to somewhere else, or maybe we need to go find out who it is that's attacking us. Yeah, I like it.
So you, you do it for level 3. Am I right that Level 3 sells this as a service to their customers? Yep. ISP customers, or is it just anyone who can do this? It's enterprise-focused, so not ISP-focused.
I'm sorry, you guys sell ISP services to— you're an internet service provider to customers, to companies, right? Yeah, among other things. But you can do this regardless of whether you use Level 3 as an ISP? Yeah, and that's some of the beauty if you think about Level 3's global network. We have information about the actor and its botnet from a lot of different places in the world.
And so while it may not have visibility to a direct customer, might be an off-net customer, the knowledge of the botnet communicating with that is still with us. Adding to that, we do a lot of other things from malware to honeypots to a number of other ways to detect the attacks. Spend a lot of time with DNS data and other things. Being directly connected the network's not absolutely not a requirement. Um, so it was, man, about a year ago when Mirai took down Dyn, right?
Um, and, and the Mirai botnet, you know, there's, there's those on listening who may not be aware of it. Uh, it's a, a really big network of mostly Internet of Things devices, um, cameras, DVRs that were being used to, to run attacks against various systems. The big one that I just mentioned, the Dyn network, was a big DNS provider that lots and lots of startup-y Amazon-type companies used as a DNS provider. That attack kind of came out of nowhere and really took down the internet for, what, a day, half a day? Big chunks of the internet, I should say.
I know you guys did a lot of research and learned a lot about Mirai. Can you share anything about your learnings from that or what you guys have done as a result? Yeah, that was, that was a lot of— I hate to say fun because it's never fun when things break or, or the internet has problems. But it was, it was fascinating from the timing and other things. So our team had been focused on a botnet that goes by the name Gafgit.
It's not a single botnet. It's a malware family. And it scanned the internet for default credentials, largely logged in, installed its malware, and then formed a DDoS botnet. And so we've been watching it along with some other groups that we do work with, and we were getting better and better at tracking down new instances of it and automating ultimately finding the new instances that were created. And so we're using a combination of— we're actually using machine learning as a component of that detection automation using some custom software development and other things in order to find them.
And one day our dataset went a bit sideways and we started losing the bots that we were watching and being able to detect. And we noticed they were connecting to a new command and control. And day one, we didn't know what that was, but very quickly we were able to attribute it back to the Mirai botnet. And The botnet's original command and control was hosted in Christmas Island, which I'd never heard of. So there you go, a new place to Google for everybody.
And the botnet had successfully attacked Brian Krebs' blog, or news website as you may, the Dyn infrastructure, and a number of other things. And so we were very quickly able to figure out how to interact with it. It, figure out how to understand it, and ultimately work on taking it down with some of the other research groups that we work with. We continue to watch it today. In fact, if I can recall, we caught another command and control last night.
And so they continue to stand up new ones, and we continue to find them and take them down. So a new command and control basically means that there's a central system that's controlling all of these infected— or it's not even infected necessarily— compromised IoT devices, that's gonna— that the command and control has the ability just to point at a server and say, go take that server down, right? So is it basically a race between a new command and control starting to take over the botnet and, and the good guys in some way just making it so that that command and control is unable to issue that command? Is that where we are? Yeah, that's, that's not too far off.
I'll say it's really a race between them and growing to critical mass, right? So if they build a botnet of 100 hosts, that's bad, of course, but it's not going to take down major internet infrastructure. They're not going to knock down major websites with 100 hosts. If they get to a million, then they can have massive impact. And so the goal is to get them before they hit critical mass.
Work with domain registrars, work with top-level domain DNS operators, work with VM hosting providers, work with the community of people, the abuse community that keeps the internet running, and work to get them shut down, knocked off, sinkholed, whatever the case may be. So if you get to spend time doing this, why would you do any engineering and architecture work? This sounds like so much more fun than the architecture work. So, so to be fair, the threat intel stuff requires a lot of engineering and architecture as well. We have a whole team of folks that are working on building the large-scale data analytics that sit behind the environment.
And so understanding how to scale that to our workloads and our distributed jobs is a part of our team. And so definitely have that, but the architecture side is a lot of fun too. And, you know, I spent a decade being a network architect and engineer, so it's a little bit of that in my blood as well, thinking about how we build products that defend customers and, you know, help them with their security.
So you have built a team over the last last few years, and I know you've built a pretty fun team. Could you talk to me a little bit about what folks you've hired, what, what their different roles are, and what, what those guys do day to day? They sit in their cubes with their headphones on and don't talk. That's what— no, uh, don't they work from their home mostly? No, we are, uh, as of now we're all up in Broomfield.
Okay, so we all come in, we all stare at each other, and then go into our cubes and put our headphones on. But, uh, so the, the team is is a great mix. I always say this is the most fun team I've ever worked with because they're all smarter than I am, right? And so it's great to be able to learn from people. It's great to be able to see the variety of backgrounds.
And so we have a few different disciplines. We've got security analysts, so folks that understand how a botnet works, how it attacks. They understand the protocols, they understand malware. And so think of them as, you know, hardcore technical security people. Then they work with a couple folks we call data scientists.
And so that is the, the market term for people that build big statistical models, aka machine learning. And so they work together. So we find a thread to pull, so to speak, out of malware, and we hand some of the information about what we find forensically from the security analysts into the big statistical models, and then they feed back information they find, and they work together hand in hand to be able to build the automation and models around detecting it. And that's our analyst crew. The other part of the team is focused on really building all the tools, the technology, the, like I said, the big data environment.
And so we have a big infrastructure that sits over there that collects all of the analytics, all the data, real-time streaming, anomaly detection, all of those components. So we have software developers that work in that. They, they have a slant towards the big data toolsets, and you'll find them coding their large-scale tools in Scala and Java, and then Python for our more day-to-day stuff. And then the big data systems people, they tend to come from a Unix background and things like that. But we've hired everyone from multiple physics folks, we had a civil engineer, we've had only high school graduates.
We've got everything in between, and it's a brilliant group of people. It's a lot of fun to work with. When you're interviewing, you know, pick a role, maybe security analyst role, what are the things you're most looking for during that interview process? What do you, you know, you walk into the room with them, what do you want to see? What do you not want to see?
What just doesn't matter to you? My recruiters hate me because I don't care about their resume. I don't care about their education, don't care about their certifications, none of it matters. I want to know that they know the information we need in order to do our job, and that they hate it because they can't pre-filter the resume. So I get all the resumes and I end up doing that job for recruiting.
And so the first chat I have with folks, just me and them, 30 minutes, how you doing, who are you, I look for a little passion in their jobs. They like what they're doing. Do they like the technology? I ask them what, what do they do outside of work? Having to do with technology.
I look for something that's really a core passion of what they do every day. Yeah. Um, and then we get deeper in, and unfortunately I put them through a barrage of trivia. You know, how does this work? What's this?
And just to get the technical aptitude. Yeah. And that, that's the painful part of the interview. Um, but part of that is we give them some abstract questions. Uh, one of the fun questions I like asking that now I can't ask now that I've said it on here, but, uh, uh, if you built a botnet How would you build it?
And most of the people have never thought of that, but the folks that smile and enjoy thinking about it out loud with us, yeah, those are the folks that fit better in the team. They can think about an abstract problem and they can enjoy the challenge of not knowing the answer and thinking about it with other folks in their world, and that's a lot of fun. Yeah, and so that's one of the things we look for. Look for people that they like it because we're learning and developing new things every day. In some cases, things that we don't think have ever been built.
Um, and it's fun and we want folks to enjoy it. Yeah, that's great. Um, anything that you mentioned, I guess you already told me what you don't care about that most people do care about, which is everything on a resume. And it's a good way to put it that what we generally screen on doesn't have all that strong a correlation to success in a position, right? It's, it's a bummer.
It makes it hard to hire people. It does. I have interviewed hundreds of people over the last few years looking, looking for our positions and had some great success and had a few failures too, right? The process we have, we like, but it's by no means perfect. Yeah.
So, uh, 18 years at the same place, same series of places. I'd like to hear— I'm going to ask you both the good and the bad. I'm going to start with the bad. Tell me about a failure you've had there, something that you, you went after, right, that seemed like a good idea and didn't work out. And what did you learn from that?
So I mentioned earlier that I, you know, I learned about the business later in that time frame. I learned about the broader environment I worked in, not just the technical task in front of me. And that was a bit of a downfall sort of in the middle where I believed I had an amazing solution I thought we should build, and I ranted and raved and made presentations and sat in as many meetings and talked to as many people as I could. Thinking we should build this thing. This is the next great thing for our company.
Yeah, and I got shot down at every turn. No, no one had any interest in it. The engineers I worked with were extremely excited at the concept because they wanted to build it. They thought it was interesting, but no one else saw the value. And I was ignorant enough to not see, oh hey, someone should want to buy this and maybe have a budget or see value in spending time in their day.
And the reality was what I was talking about, there was no market for it. It didn't make any sense. It was cool. Yeah, but it wasn't a marketable— right, it's a cool toy, right? And, uh, it would have been amazingly fun to build and we would have enjoyed it, but ultimately if there's no value in it— and that, that was a hard lesson to learn because, you know, you put your passion into something that you really think is going to be amazing and everyone tells you you're wrong.
And so learning how the business works and learning how to— oh, I shouldn't focus here, I should focus here. This is a real problem. We can actually solve this. That was pretty eye-opening. So that's neat.
That's a good thing. And that's, you know, when you mature at a place— I just think 18 years ago where I was professionally, I'm glad I don't work at that same place because they would have— yeah, they have a different perspective of me. Uh, let's talk about something really cool you've done. What's the most fun thing you've got to do in all that time and all the many projects you've had and big successes? What's the most fun thing and what thing you're most proud of?
The stuff we're doing now. Yeah, I mean, the, the, the botnet tracking, the malicious infrastructure finding, it is an amazing problem and it is fun to see the fruits of our labor. It really is. We're, yeah, we're thinking of problems in new ways and solving them. And, uh, I'll tell you, there's a couple folks on my team that have a lot of passion for the the takedown part, the actual making the internet better part.
Yeah, and it really does, it makes us smile. We see they couldn't break that thing they thought they wanted to break because of something we did, and it's not always us alone. There's a, there's a big community of security researchers and threat intel teams out there. We're not the only ones, but being able to participate in that and contribute to that's been a lot of fun. That's great.
So let's take a turn to talk about the Colorado community. And I've got to know you over the last couple of years hanging out here in Colorado. Um, what— I assume you, you got brought here for work. Is that, is that the case? Um, what's kept you here?
Why still stay in Colorado? Why stay in Denver? Yeah, so, um, so Level 3 acquired Global Crossing, and I was living in Phoenix. And shortly thereafter, I started living at the Omni Interlocken Hotel in Broomfield. And so My daughter, my second daughter, was born the day after the acquisition announced, and I missed too much of the first year of her life.
And so I wasn't forced to move here, but I definitely rose my hand and said, hey, let's, let's move the family to Colorado. And we've loved it here, from weather to schools to community. We really like the area we live in. We live up in Broomfield. Yeah.
And my commute's not too horrible, and It's been good. It's been a lot of fun. And we ask my wife every year or so, do you want to go back to Phoenix? And consistently get a no. So yeah, the only, the only yes I ever get is from my older daughter who misses having a pool in the backyard in Phoenix.
So yeah, you don't want to put a pool in the yard here. It's, uh, it's a— that's a big pain. Um, so you've been involved a little bit with the community. Have any, any specific stuff that you really have enjoyed here in Colorado? I think you've done a little bit of stuff with like the DenSec stuff with Jacob Torrey and stuff, but maybe just talk about a little bit of that engagement.
I've liked that there's a pretty varied community, right? So Rob, you yourself put together some things and I've enjoyed participating in those from time to time. The CitySec team that is now being led by Colin, and I can't remember the other gentleman's name, but they pull together very casual events twice a month and just talk techie at each other. I really enjoy going down and meeting other security people working on problems. The fact that it's so varied and that we've got the OWASP meetings, which I've never attended but I hear from everybody is amazing and a good chance.
Someday I'll have a free evening and make it down there. There's a lot going on, which is really good. I listen to the podcast every, I like to say Monday morning, but Probably Tuesday or Wednesday morning I get to it, and, you know, good idea of what I should be looking out for in the coming weeks is very helpful. So, uh, well, I guess the last thing I'll do is I'll ask you to give some advice for people in the community, and we'll start off with, uh, with CISOs, people who are running security programs. What do you think CISOs, whether in Colorado or anywhere else, are missing with our programs?
What could we do better, and what kind of guidance would you give us? Because I know you have a really good perspective across what's going on. And, and if you want to say that we're really bad at our jobs, you can say that. He's got a little smile on his face. Uh, that's not gonna hurt anyone's feelings.
No, I, I think, um, we have a hard problem collectively in front of us, right? And I include myself in the how do we protect things, uh, world. I definitely consider myself, uh, uh, of the blue team barrage. So I think really the problem that I see most consistently from people is they get too focused on the problem in front of them. They're not looking at it as more of a program, and that means everything from just doing what the audit told them to do or the compliance requirements told them to do through just patching today's bug.
And so looking more holistically, why were those requirements in the audit? What were they really trying to protect? What were they really trying to get at? Looking at that as a system, looking at today's bug and wondering, why did we have to patch today's bug? Why were we at risk from this in the first place?
Or if we missed it entirely, how would we have detected it as a class of bugs, as a class of problems, not as an individual item? There was a bug, a handful of bugs released by Google in a piece of software called DNSMasq this week. And I took a look at Shodan earlier in the week. There are 1.1 million DNSMasq banners exposed to the internet. Why are they exposed to the internet?
What reason did people have to allow them to be open resolvers and things on the internet? And, you know, I didn't go item by item, but I guarantee you a subset of those are sitting in enterprises. They're not all consumer devices. They're not all SMB. There's some enterprise devices in that number.
So looking at that systemically, how did the program allow that service to be on the internet? How did they grow the attack surface? How did they detect if that was compromised? What about a host, what would it exhibit when compromised? It makes people stop focusing on today's bug or today's requirement and start thinking about how do we protect the infrastructure holistically, how do we operate it holistically.
I see a lot of folks talking about how do I save solve today's problem without a lot of vision for how do I do this holistically. Yeah, I like that. And, you know, it would be nice if when we saw that vulnerability and that the patch needed, instead of just patching it, we said, well, we should patch this, but we should also figure out, does this service need to be turned on, right? Or does this server need to exist at all? And ask those questions that take some more time.
It makes— it's a harder job, but it ultimately fixes things in the long run a whole lot more effectively. Yeah, and I think one of the things that it does by focusing on collective mitigations as just being patching, it creates sometimes an adversarial role with the people running the technology. Yeah, pounding down that poor server admin's door every few weeks and having them patch something is not a fun experience for the security team at any company. Yeah, working with them to more holistically create something they can just incorporate into their everyday work would be a lot more fun for everybody. And so I think it's a real positive thing for folks to think about.
Yeah. So other guidance I was gonna ask you for, for those who are looking to get into the industry, maybe they read a news article that says we're short a million security engineers right now, or whatever the current number is. What would you say for someone who's looking to get into security and, and might want to work at a place like, like Level 3? Pick up something that looks interesting and learn it. I mean, that's— it's really that simple, I think.
Excuse me. As a starting point, I made a personal goal for myself to give one public research talk a year, at least one, a couple years ago, and I've kept it up so far. I don't know what I'm gonna do next year, but I haven't done anything amazing or anything special, really. I've picked something that looked interesting that I understood, or I had something to say about it, and And I spent a lot of evenings, thanks to my family, and I researched it and I talked about it. And, you know, as a security world, people think they understand what's going on.
What I find is they don't. And so, do people understand how to secure a wireless network? Yeah, they understand the 4 steps you should go through and you should set this type of encryption and this type of authentication and you should look for rogue APs and you should do these things, but do they really understand the underlying complexities to wireless? Probably not. That's not a new thing to our industry.
It's been written about before. Yeah, but people would love to hear about it. People would like to show up to CitySec and have a conversation with that individual who might be just learning about how does the security wireless network really work. Whatever you figure out during that research, other people are gonna find interesting and you share it and you you get yourself some credibility in the industry and you help us all get a little bit better at the same time. That's great.
And hopefully you fill a gap in your knowledge that you enjoy. You know, back to what I said that we look for in people that enjoy what they're doing with the technology. You know, hopefully you spark that and it's an opportunity for you to continue to move on to the next thing that you find interesting. Well, any other advice or any words of wisdom you want to share with the group? Do you have a catchphrase you'd like to share before we call it an interview?
I'm sorry to say I haven't developed a slogan yet, Ryan. We'll work on that for next time. There we go. No, I think, you know, back to the learn something statement. Like I said, I've interviewed, and I apologize to those that listen to this that I haven't hired, but I have interviewed hundreds of Denver security people over the last couple years, and I find people with a lot of superficial depth to their knowledge.
They may be able to operate a platform, but actually understand how it works is not a common thing I find. Yeah. And so for most people, they understand all of the information. Taking that extra step deeper into it is not difficult for them, and I'd encourage people to do that. It makes people have a greater understanding of how to mitigate attacks, how to look at classes of bugs, back to the other point I made.
So diving deep into these as abstract things, those conflict obviously but deep into things as class of bugs, class of problems, class of technology. How does TCP really work? Not a lot of people really know that. And spend time on learning something, makes you better at your job. Hopefully you learn something interesting.
I really think that's an important thing, not just for people trying to enter the industry, but people are already in it as well. Sounds good. Well, that's been great. I appreciate your time. Hopefully we can catch up again.
I can hear what happens with the whole merger coming up. And we, I think your catchphrase will be, Mike, all about the Benjamin. And, and I think that'll stick. Thanks, Rob. All right, have a good one.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex. Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.