Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 40, the week of November 6th. Alex, don't you love that intro music?
I love that intro music. It's one of my favorite artists. Yeah, so the song is called The Language of Blame. The group is called The Agrarians. It's free.
I love the intro. I love the transition from the same song. The rest of the song's pretty bad. You guys are all welcome to click on the link and listen and see. As soon as the singing starts, it becomes pretty bad.
This is the sort of the required semi-quarterly plug to the people that give us the free music, right? Is that— Well, it's not required. It's just something that I think that I'd love to give them. I Probably bet they wish it was a little more positive plug. But, but once again, we do appreciate the music.
The news this week, there is a 7th grader who is way smarter than us down in Highlands Ranch. Well, that's not particularly hard, Robb. But yes, so there is a 7th grader that attends the STEM school in Highlands Ranch. And she was awarded based on an invention that she had that can detect lead in water. Yeah, so her name is Gitanjali Rao, and she's a student at a STEM school in Highlands Ranch.
And she's not only invented this, this test for lead in fresh water, she also has invented a film that goes over the windows for planes to stop lasers from blinding pilots. She's invented something to test the level of venom in snake bites and something that helps counteract the effects of allergies from pollen. So pretty impressive stuff that this 7th grader's done. Yeah, she clearly has accomplished more than either of us, and she's only in 7th grade. Not to mention the fact that as part of this award, she took home $25,000.
Yeah, so that's a reasonable haul. My favorite part about that award is she said— I don't think it's in the article here, I heard her in an interview on a podcast— she said what she's gonna do with the money is number one, she's gonna use it to help get this lead testing thing to market, and for the rest of the money, she's gonna give it to all of the charities that she works with. So the seventh grader is working with multiple charities already. That's pretty good. That's pretty amazing.
What I want to know though is since you won this money, does she now have to move up to the pro scientist league? She can't be an amateur anymore. So she can't make the amateur Olympics. That's right. The amateur science Olympics.
I like it. So next, this week the the merger between Level Three and CenturyLink closed. So now there is no more Level Three. Yeah, I saw I saw some stories showing them replacing the signs at the Level Three headquarters up in. Was it Broomfield?
So, you know, obviously a little bit sad for those who have a history with Level 3, but, you know, good hopefully for the future, and hopefully they build out a really strong security practice there. I think the other, you know, long-term benefit is gonna be that while CenturyLink is headquartered in Louisiana, they are gonna have a good bit of their leadership here in Colorado still, including the— what is now or was the Level 3 CEO, which will be the CenturyLink CEO, who's gonna stay here in Colorado. So that's pretty cool. That's good stuff. Next story, we do have a list of the top 100 tech companies in Colorado.
This is based on number of employees here in the area, but it's just really neat to see. I think there's 7 different security companies that made the list. Webroot, LogRhythm, Optiv, Ping, Conversant, ProtectWise, and InteliSecure. All companies we've talked about on the show, you know, dozens of times, all on that top 100 companies here in the Denver area. Great to see all those security companies on that top 100 list.
So next there is a— well, Robb, as you know, marijuana is legal in Colorado, in case you hadn't realized. I've heard that. Yeah. So there is a company that is based here called MJ Freeway. They make software for folks that are in the marijuana business, and they've been running into some issues lately.
Some of them sound like some operational issues, problems with growth, no pun intended there. But the other part, it was interesting to see that they were talking about having a number of cybersecurity issues. Yeah, they've been hacked, it looks like, you know, Why do you, why do you rob a bank? Because that's where the money is. And why do you rob a marijuana software company?
Well, there's a lot of money there and a lot of it's not very well tracked. And from what I hear, a lot of, a lot of cash transactions happen in that industry. So it makes sense that someone might target it. It's interesting to see if you look at their press release or their comments about this, MJ Freeways really talking about investing heavily in security. I believe what they say is that they invested more in the last quarter on their security resiliency than most companies have net income or gross income for the entire quarter— for an entire year, I think, is how they put it.
Yeah, that's pretty cool. Um, it noted that— didn't give the names, but they're working with a couple local security companies to help them shore up their security. Yeah. Uh, next, the Denver Art Museum has warned donors, members, employees that they had a data breach. And what it looks like looking at the article is they probably had one of those phishing attacks where someone you know, gave their credentials to the email.
The bad guys got into the email and, and were able to look through everything that was in there. Probably means they didn't have 2-factor turned on. So this is a good moment for you guys to all talk to whoever you work with or work for and tell them to go turn on 2-factor for their email. Yeah, it sounded like the attackers weren't able to get access to any of the databases or applications where they had larger amounts of, of their donor data, but, you know, whatever was in that particular person's email is potentially compromised. So Uh, next, uh, there is a Colorado accelerator, um, that was awarded some funding from a federal program.
So this accelerator focuses on companies that have female founders, which I think is pretty cool. So the company's called MergeLane, and it was one of 20 winners of the U.S. Small Business Administration's competition, and they got some funding basically to help them grow. MergeLane's been around since 2015. And like you said, really focus on helping get, get funding for women-run businesses. Yeah, I think that the criteria is funding for any business that has at least one female founder.
Yeah, pretty cool. So Red Canary had a blog this week. You know, I don't know if you're aware, Alex, this week was Halloween. And really, I hadn't noticed. Some people do things for that.
So they— Red Canary did a blog around what are the scariest things out there. And really what they say is scary is stuff we can't see. So this blog is really, you know, a little bit cute, but I think the point of it was here are some tools you can use to get visibility in your organization to help, you know, de-scare the environment a little bit. Yeah, definitely some good hints in there. Additionally, LogRhythm had a blog this week sort of on a similar topic, not exactly on general visibility, but they were talking about SCADA network security monitoring.
So they're talking about getting visibility into your SCADA networks and network monitoring. Yeah, using their network monitor product, which got some good information in there too. Um, so finally on the list, um, you guys may or may not have heard, but our very own Robb Reck, uh, was on 9 News this past week talking, um, about how to do security and sort of the end of Cybersecurity Awareness Month. Yeah, just a few points we made on there. I got— I had 3 minutes with, uh, on the air.
I really talked about turning on MFA. Thinking about, you know, how do you get rid of data you don't need to have? And then, you know, good password hygiene, you know, don't reuse passwords and go to passphrases instead of, instead of those non-complex passwords. You know, they usually say that people that, you know, do podcasts or radio, it's because they're not good enough looking to be on TV. But I think Robb, you know, definitely proved that wrong.
Oh, thank you. I thought you were gonna say proved it right. That was much nicer than I expected. Uh, let's jump over to our trivia questions. I guess before we do, just a reminder Sign up for our mailing list if you want to get these show notes into your inbox every week.
And sign up on iTunes or Google Play to subscribe to the podcast and hear us automatically each week. Trivia from last week. The question was, name 2 of the podcast guest co-hosts we've had. So over the last, what have we been, 9 months or so we've been going, we've had 4 co-hosts. We had Drew Labbo.
I think Drew's done it 3 times now. Matt Sharp, Matthew Sharp before he moved out to New York, Andre Gaeta, and Steve Knight. Those are the 4 we've had. We did have a correct response. Thanks a lot to Brian Thornton.
He was our winner and he got a shirt from Andre Gaeta, who's sponsoring this whole trivia thing for us. Congratulations, Brian. And I think we actually did have a couple correct answers. Yeah, we had, which was nice. But so make sure when you're getting those guesses in, get them in very quickly so that you get that cool swag from the store.
So this week we have another trivia question. This is a Colorado trivia question, and that is, what is the 2nd most secure location in Colorado? We have 2 hints for you. Number one, the number one most secure location in Colorado is Cheyenne Mountain. The 2nd hint is that number 2 is not Buckley Air Force Base.
All right then. My guess is going to be the secret passages under DIA. I was, I was going to say it's the Colorado Equals Security studio. Oh, even better. We have worked very hard to secure this environment.
Sort of like the Batcave. Absolutely. All right. Why don't we go ahead and jump over to upcoming events? On the 6th, we have DENSEC.
The South meetup is happening. And I saw a little scuttle on Twitter that it's going to be at Baker Street Pub on Bellevue, just a little bit east of 25. Cool. SecureSet on the 7th is having their Hacking 101 workshop on AppSec. On the 8th, the CSA has their CSSK training.
This is a fee-based training, so if you're gonna do it, you gotta sign up early. Hopefully it's not too late, but get on it right now. Also on the 8th, CTA has their annual APEX Awards, so show up if you wanna hear who the CISO of the Year is going to be, as well as some other less important awards. Yeah, there's, there's a few other ones. Um, the— as a reminder, the finalists for the CISO of the Year: Matt Shufeld, who is our feature interview this week, Sam Masiello, um, who we had on the show 6 months or so ago, and then John Everson from a few months ago.
So very cool to see those guys getting recognized. Uh, on the 9th, ISSA Denver is having a full-day training on GDPR. Last I saw, it was sold out, but there is a waiting list and Also, last I saw, there was nobody on the waiting list. And I guess give you guys a hint, usually 5 to 10 people cancel in advance. So if you're not on the waiting list yet, you might want to do it right away.
Next, CSA, also on the 9th, is doing their 2017 Colorado Fall Summit. Yeah, that's their big conference, and it's up on 36th. Should be interesting and good stuff. They have some really nice speakers up there. ISSA Denver has their November chapter meetings on the 14th and 15th.
The session for this is gonna be about honeypots and how to use honeypots to distract and divert attackers in your environment while you get there to stop 'em. Nice. On the 15th, CTA has their Insight Series, Are You Prepared for AI in the Workplace? I really love this topic. Yeah, I don't know who the speaker is, But the topic sounds really good.
And for those of us who, you know, know AI is important, but maybe haven't put it into our programs yet, it's a good way to start talking about it. Is this going to be one of those things like, you know, how to deal with millennials and stuff like that? How to deal with AI in the workplace? It might be just like that, really. Here's how you trick the millennials into working hard for you.
Same thing for AI. I don't know. Exactly. On the 15th and 16th, Colorado Springs ISSA has their November chapter meetings. Also on the 16th, ISSA Denver is having a Women in Security meeting.
The 16th is very popular. We also have on the 16th the ISACA November chapter meeting, and DENSEC is doing their North meetup also on the 16th. And there's one more. Well, ISC2 is having their November meeting that evening. It's gonna be with Stephen B. Armstrong talking about enterprise risk management.
I think everybody was trying to get all of their events for November in on the 16th before Thanksgiving. As we pointed out, there's a pretty big gap between the last event on the 16th and the next event, which is on the 29th of November, which I'll throw it out real quick. Optiv is doing a roundtable to really talk about application security and how do you do application security. It's a focus group where they're putting together some research. It's a good way to get plugged in with some really smart people in the area.
Rafael Los is running that here in Denver. So there's a link in the show notes to that as well. You can sign up and hopefully make it out there. Yeah, I think, uh, one of the benefits for participating is you get access to some of that research. Yep, you get— I think you get early access too.
Let's go ahead and jump over to the jobs. There's, uh, some pretty good jobs available this week. Vertella is hiring a Director of System Security. Quantix is hiring a Senior Manager for Incident Response. The Jewish Family Service of Colorado is hiring, hiring a compliance manager.
Looking at this role, it's not just focused on security. There was other compliance aspects as well, but it did have a big security aspect to it. So do you have to know Hebrew law to do that so you can be in compliance? I don't think I'm allowed to respond to that question. Western Union looking for a director of information governance.
Yeah, working for Mike Kalak over there. It should be a pretty cool opportunity. IHS Markit is hiring a compliance training and awareness director. Uh, GuidePoint is looking for a vendor relations manager. TIAA is hiring an info security analyst, and I didn't know they had a presence here in Denver, but this is a local job up in the north side of town.
Yeah, uh, TIAA has a pretty big office here, I think. Yeah. Cool. Um, Hitachi Vantara is looking for an application security specialist in interns. So if you are looking for an internship, sounds like a good opportunity.
Yeah, absolutely. Well, that's the end of our news for the week. We are going to throw it over to the feature interview with Matt Shufeld. We've been trying to get Matt on the show since, since we started. And we finally got him to confirm.
So looking forward to this interview. Yep, sounds good. Thanks, Robb. All right, everyone, have a good day. Hello, this is Rock Lambros, Information Security Manager at Marquis Energy Partners.
This is Colorado Equal Security, for Colorado security professionals by Colorado security professionals.
So today, not only are we going to do a little interview about Colorado Equal Security, we're also going to be drinking Colorado Scotch. So Matt Shufeldt and I are sitting in the basement with an open bottle of Stranahan's whiskey, and we're, we're here just really to talk about Matt's career so far, how he got to be one of the finalists for the Colorado CISO of the Year, and really what he sees going on in the security community. So to start off, Matt, tell me, how do you like your Stranahan's? It's good. I have to correct you that it's not Scotch, but yeah, as soon as I said it, I really— we almost drank Scotch.
We grabbed the whiskey instead. But by the way, for boys and girls at home, we're drinking responsibly. Don't think we're down here pounding a whole bottle or anything. But it is very tasty. And, and, uh, do you, do you drink your Scotch neat?
On the rocks? Well, today it is on the rocks. Sort of, right? Sort of on the rocks. Actually, what's funny is, uh, uh, not to make this about, uh, Stranahan's tasting or anything, but the, the interesting thing about, uh, the frozen blocks that you're using instead of regular ice cubes— I thought about it after.
It's kind of a neat novelty, so I was like, yeah, let's do that. Then I was thinking about it, I'm like, well, the whole point of ice is to slowly release water and activate the Well, so is that the point, or is the point that you like to have your whiskey a little bit cooler? Because for me, I— we're using the, what do you call them, drinking cubes, drinking, drinking stones I think they're called. Uh, so basically, you know, they are, they are hard stone-like substances you put in the freezer, you put them in your drink, cools down your drink. Yeah, you don't get any, any dilution of the whiskey, and but you did get it a little cooler.
So that's— so, so, um, I've been to a couple of, uh, tastings And they will actually point out that the flavor profile changes based on the release of minute amounts of water at a time. Yeah. So I don't know. I'm not an expert by any stretch. Well, but it tastes, it tastes nice.
This is, this is, this is fun. So I've been trying to get Matt on the show for as long as we've had the show, 6 months. And I'm really thankful we got this to work out. Matt's going on vacation and we still managed to get this thing in. So appreciate your time.
Why don't we talk a little bit about security and then we can go back to talking about whiskey and lacrosse and whatever other fun things we want to talk about. Yeah. Matt, how did you go from, from being a little kid who probably was messing around doing some fun things, playing music, to becoming one of the CISO here in Colorado? So I was kind of born into it, actually. So my dad was a programmer and did computer systems maintenance for the Navy starting in the '70s.
And then he went on to do mid-range work for multiple companies, and then he was with one company for a very long time. He did everything from programming to data process management and ended up being a senior VP in that, in that company. So he basically did everything end to end. I kind of modeled a few different chunks of my career after him, actually. I don't think intentionally at first because I was highly competitive, but Because of that, I was around computers, big, big computers, really interesting projects since I was a kid.
And I actually got into computer operations when I was still a teenager, very young actually, before most people would have graduated high school. And then I went from being a computer operator to being a system administrator, AS/400s. Yeah, did that for a number of years. And where were you living at this point? So, so what's interesting is I started out in Texas.
That's where I'm from. Um, I moved to Colorado the first time when I was 18, and that's where I had my first AS/400 system admin job. And I got the job because I figured out that the previous company, uh, basically was paying me operator pay for being a system administrator. Yeah, and, uh, it was kind of neat. I got to do that for multiple years.
It was fun. It was a company called Intelligent Electronics. They were the second largest computer reseller in the country at the time. The largest being Ingram Micro. Yeah.
And yeah, I'll save everybody a whole lot of snoozing here. I spent the next several years doing everything from DR consulting to doing more system admin work on AS/400s, HP 3000s, HP 9000s, RS/6000s. Imagine a mid-range system, I probably worked on it at some point. And then I got into change control and security. I was actually working at REI.
Okay, REI corporate in Washington. Hmm. And I realized I had been doing security, right, for most of my career, and I finally got a focus position that focused on change control and security. And then I kind of just bounced around doing both of those things for multiple companies for multiple years, everything from consulting, going all over the country. I got to do little bits of work up to multiple several months of work in 32 different states.
So that was kind of neat. Wow, 32 states. Yeah, that's a lot of them. It is a lot. It's about 64% of the country, give or take.
Never pegged you as a math geek. Anyways, I found myself, I found myself working and enjoying the security side more than anything else. I was doing a gig at Janus Funds years ago and, uh, decided to leave there. And I was gonna go work for Northrop Grumman IT, and I got a call from a little sporting goods outfit called Gart Sports, uh, and they said, hey, we have a change control administrator position. And at that time, I'd already been in management positions, seemed like a step down.
I was about to just tell them, no, I'm gonna go work this other place. And then I just thought Wait, this is retail. They probably don't have hardly anything. Yeah. I said, would I be allowed to do security and change control?
And they said yes. So I went there figuring I could move up and well, that seemed to work out okay. What year was that?
2003. Wow, 2003. So you just, you know, kind of zipping way ahead, you just left Sports Authority last April? Yeah, so I've been— I think I've been at Cognizant now for 14, 15 months, so that's probably about right. Yeah, so you left there last April, so you were there for 13 years, and I know you and I have talked about this quite a bit.
Why don't you talk a little bit about, you know, you came in as an individual contributor, and there's got to be a lot of folks listening right now who are in that type of a role. How did you go from being an individual contributor there with, I assume, reporting probably to an IT manager? Something like that. Yeah, what's actually interesting is I was reporting to the director of QA. Okay, and then you reported there and somehow somewhere along the way you presumably created a new security manager and then a new security director and then a CISO role.
So I'd love to hear how that process went. Yeah, I'll try to give the interesting version here. So interestingly enough, I was there for about 18 months and I had built out all of our initial change control processes. They didn't have any. To speak of.
I did a bunch of system management stuff as well and helped out the QA group with some of their, their scripting and programming, but I was focusing really heavily on securing the systems because nobody had really taken a look at that. Well, earlier in my career, I had actually been doing some DR consulting, and why that's important to this story is we had a brand new vice president who had just started and And her first week, she's there, she's doing a great job already getting to know people, getting things aligned. I'm multiple levels beneath where she's at, so I hadn't really talked to her. But I come in early one morning, I'm walking down the hall with one of our telco guys, and we hear the data center large thunk and quiet. So it turns out there was some construction that we were doing on the data center, and it actually tripped our EPO switch.
Okay, the vibrations. And so we lost every system in the data center. So I spent that whole day organizing all the different teams, getting them arranged, getting them calling in statuses, getting everything brought back up. And towards the end of the day, everything's good. I get an email from Cheryl, actually Cheryl Monroe.
She is my vice president. And she said, hey, would you come chat with me? And I'm like, yeah, that'd be great. So I come down there and she said, well, so who are you and, you know, what do you do? I said, oh, I'm, you know, Matt Schufelt and I'm your change control administrator and your security guy.
She's like, okay, why did you do all that today? I said, because I didn't think nobody else— I didn't think anybody else knew how and I just thought I'd do it. Yeah. And then she very politely looked at me and said, Well, I'm really glad you're here. I hope we get to know each other over a course of time.
And I said, well, I'm actually thinking about leaving.
And it wasn't a setup, it was just brutally truthful. And she said, why? And I said, well, I figured I would build all of these things, um, and I have to say I was more impatient back in those days. I said, I've been here like 18 months and I built several things But nobody seems to understand the value of it. And honestly, I gave up management to do this, and I figured there would be some recognition.
So no big deal, but I'm just probably gonna move on. Wow. And she said, give me one week. Within one week, she gave me a brand new department called Systems Compliance. I had security oversight, security design.
I had everything basically except for security compliance. And I also had change control and a bunch of other stuff that I liked. She basically said, what do you like? Yeah, I said, I want all these things. She said, okay, you can't have this one thing, you can have everything else.
So she gave me a department and I just started building up from there. Over the course of time that I was there, I went through several different evolutions. I owned everything, everything in IT except the programming groups at one time or another. At one point, I actually was the director over everything in infrastructure, everything in operations, and everything in security. Yeah, that was a bit much.
It was like 13 direct reports. Yeah, that's too many direct reports. Oh, I agree. Yeah, but my sweet spot was definitely when I got to go back to just focusing on security and compliance. Yeah.
So, you know, I know let's talk a little bit later in your tenure at SA. Well, It was Gart Brothers, and then how did it not— how was it no longer Gart? So, so interestingly enough, when I went there, it was called Gart, but it wasn't Gart Brothers. Gart Brothers had gone away multiple years earlier when the Gart Brothers left, and they had sold the company. So it was Gart Sporting Goods.
Okay. They had already done a merger of equal parts with a little Kmart spin-off called Sports Authority out of Florida, uh, and they had brought all the executives for both companies and put them together in Colorado out in Englewood. And I think probably about a year into me being there, they decided that the brand name on the East Coast for Sports Authority was much better. And frankly, there hadn't been a Gart working there for years, so they just rebranded everything. Yeah.
And actually, we had at the time, we had Gart's, Sportsman's, Sportsmart, Oshman's as well. So we had all those brands and we brought them all together. So you didn't have to go through an acquisition or merger. It was, it was just really a rebranding at that point. Interesting.
I would say I did go through the merger because I was, uh, the first IT employee after the merger. Oh, okay. So I definitely lived through the merger, the integration, commissioning systems and doing all those things. Yeah, all the integration work, that's— which is a big part of the work for sure. Yeah.
So, so late in your, in your tenure at Sports Authority, um, I know you, you went from, you know, a director role, right, into getting the CISO role maybe 3 years ago. Can you talk through how that happened? And I actually think it's been 4 years now. Okay. Basically what occurred is we changed CIOs and we actually ended up getting a CIO from— he was at Target for multiple years and made a big name for himself and he's actually done quite well everywhere he's been, a gentleman named Fred Arger.
And Fred actually really— I had several people that invested in me get to this point, so don't get me wrong. But Fred actually, in addition to all the great things Cheryl did for me, because she's really— she was really my mentor those first few years, getting me where I needed to be, making me a solid director, which I think is the key. Yeah, I think people that jump— I'm getting a little tangent here— people that jump from being a manager to just naming themselves or having someone name them a CISO, I think are missing out on some good maturity steps. Hmm. So I was really glad I spent multiple years as a director.
But anyways, I'm getting off topic. Fred had me focusing, even though I didn't directly report to him, he had me focusing on several different key initiatives for him. And through that, there started being retailers getting popped and there became more and more awareness. Yeah. And it was really interesting.
We were going to do a big presentation in New York. We So Sports Authority, they were primarily owned by a large PE firm named Leonard Green, Leonard Green and Partners. And we used to go to New York and present in front of all the CIOs of all of the companies that were owned, which was a great learning experience for me. And I was going to actually talk about breach preparedness and what you do after a breach. And it was really interesting because I had gathered a few statistics, you know, but Fred kept pressing me.
He's like, okay, Mr. Shufelt. He would always say that when he was, he was politely judging me. Okay, Mr. Shufelt, why don't you have your presentation finished? Yeah, I said, well, because almost guaranteed I'm gonna have a couple more breaches between now and then and I want to incorporate them. He's like, okay.
He's like, you don't have to give me an excuse. I'm like, no, I'm dead serious. So Sure enough, a large shoe retailer got popped the morning of my presentation, and I added all that in, gave a great presentation, went really well, and he gave me a bunch of extra responsibilities and gave me a— you're probably gonna think this is super cheesy because looking back it kind of is, but he gave me this certificate that said security officer. Yeah, and it had like a bad, like word art dude in a suit with sunglasses. Yeah.
And I'm like, well, that's kind of cool. That's a pretty neat recognition. Because at the time I was just happy that he looked at me that way. Well, the very next CIO, oh, probably one of my favorite bosses of all time, Kathy, she was just an amazing boss. And she actually promoted me up to be directly reporting to her.
And I loved working with Cheryl, but I still love working with Cheryl as a peer. But she made me director in CISO. Hmm. And I spent another 10 months as a director in CISO. Yeah.
And then eventually they leveled me out to VP. Yeah. So, and that was like you said, 2013 timeframe. Things at Sports Authority did not remain good, oh, you know, for several years in the future. And there are probably people listening who don't know the story.
If you want to give high level what happened to Sports Authority and, uh, kind of the end of the road over there. Yeah, what's interesting, and you know this well because I talked to you about it, but I had actually started to look for other opportunities just because, uh, the program there, I was very, very proud of it. My team was great. We did— I thought we had a really good program. Uh, and frankly, it'd become a little dull.
Yeah, I was looking for things to optimize, so I started looking for other opportunities. Well, interestingly enough, uh, our company, senior leaders— and at this point I was pretty high up in the chain, uh, so I had good exposure to this— they were just looking at our overall future, and it very much appeared that the best thing to do was to figure out how to make ourselves ready to move into our next decade of business. Okay. And sometimes you have to look at that more aggressively than others and figure out how you're going to manage your debt and do all these different things. So what I would say is, without going into any specific details, that's what the company was attempting to do when all of the initial talk around, you know, the bankruptcy started to happen and how we moved into that stage.
So interestingly enough, I had a great recommendation from a good friend and colleague sitting right across from me here to go work at Cognizant already, and I had already accepted that position when that stage hit, and they actually had asked me to stay additional time just to work through different things. And Cognizant being a great company, they, they agreed to let me have that extra time. Yeah, we worked through it. So end of the road, Sports Authority they ended up having their— it went into bankruptcy. They ended up having their assets auctioned, basically, basically everything going out of business right there.
Sure. Unless I'm, unless I'm missing something, I don't think there's any going concern for Sports Authority at this point. It's, it's really— yeah, I think, I think that's probably fair to say. I mean, I've been out of the loop now for a while, for over a year. Yeah.
Yeah. Um, so then maybe you can't answer this question: when are they going to take it off of the, the Broncos Stadium? When the Sports Authority isn't— when is it not going to be Sports Authority Field? Well, based on what I read in the Denver Post, yeah, uh, that was actually a move by the Broncos, uh, to block less savory naming rights. Taking Shotgun Willys.
Actually, I think it was something about Mile High and it was like a dispensary or something. Oh no, was it really? Yeah. Now that's just what I read in the Post, so, uh, I don't know how accurate that is. Well, so now I really— your current role, honestly, the last year and a few months is one of the really great security stories in Denver that I've ever heard.
You came into Cognizant as the BISO, right? Business Information Security Officer assigned to— correct me if I'm wrong— the Trizetto business unit at the time, which is now called Cognizant Healthcare. That's really changed over the last year. So if you don't mind just telling the story, where you came in, what your job responsibilities were, and what has that turned into for you? Yeah, so thanks for teeing that up.
It has been a really, really fun time. So Cognizant is extremely security-focused and wants to make sure that we have the right quality for all of our customers. And I have to say, so I was originally brought in to be the Business Information Security Officer, as you said, over Trizetto, which was a good good company here in Colorado right before it was acquired and became part of another great company. And my job was basically to give a strategic roadmap forward and kind of design things more from a leadership perspective, build up a team to take us to the next level. So they already had some good bones there.
It was really just to bring things forward and kind of, I think, establish more of a leadership culture. Yeah. The cool news is it went really successfully. There's a lot of great folks there and really good support from leadership. And people may be thinking I'm like overly sugarcoating this, but it's true.
It's been a great experience. And I think you can remember how many times I've been happy in the course of time that we've been— that I've been there. For those listening that don't know, Robb and I are good friends. We talk all the time. And within a few months, they actually recognized the contribution, actually asked me to move up into a full CISO role, which really was a big deal in Cognizant because other than our CSO and our global head of cyber, there hasn't really been somebody appointed with that type of leadership role.
Yeah, so I moved up to report directly to the global head of cyber, who's been a great boss for me. I focused on that. We built out the team more, made more key hires, did more strategic expansion. I want to flesh that out a little bit. And starting point, did you say 240,000 employees for Cognizant globally?
I believe we're right over 260,000 actually. Okay, so we'll call it an even quarter of a million and we'll call it— we'll call that good. Yeah, so huge, huge international organization with You know, like I said, a huge presence both in Asia and in North America and Europe, all over the place.
Your presence in Denver as the head of the CISO for Cognizant Healthcare, right, has changed the look and feel of the, the TriZetto area. When you were hired, how many people were there in Colorado that were in the security area? Call them security employees? Yeah, so we probably had around— sorry, it's been a busy year. Yeah, I would say it's probably around 12.
I was gonna guess 10, so right. Yeah, and then let's put it— give me a number now. Where do you think you are today, and then maybe where are you gonna be at the end of, you know, in the next 6 months? Yeah, so we've been in the high 20s this year, and I think you're gonna see more expansion, more hiring. You've been kind enough actually to talk about a lot of our open roles over the course of time.
It's actually really kind of exciting as we acquire more business and as we look to do more strategic expansion into different things. Denver's really being looked at as a really key area. I think it has a really healthy technology atmosphere, and frankly, I think the security community is one of the best I've ever seen. Yeah, you're a big, big part of that, by the way. I appreciate that.
So thank you. Um, you've been, you've been vacuuming up a lot of security talent in the area. You know, you've hired, uh, former CISO Jacob Rubin as a director. Uh, I know it's— his job's changed. He's, he's had opportunities over there in the last year too, right?
I think originally you hired him as your director of security architecture. And what's he doing for you guys now? Yeah, so now he's actually over our merger and acquisition cyber, uh, peace and our cyber governance for all of our global applications. Yeah, so Jacob was the CISO for ProBuild, uh, previous to coming to you guys, and then you hired Frank Viazon. By the way, yeah, Dr. Jacob Rubin.
He's now officially doctor? He, he is officially doctor. Congratulations, Jacob. Uh, and Frank Viazon— am I saying Frank's last name correctly? Frank, who you guys recently hired, he was at Hitachi.
Um, he's now— he's also a professor over at Red Rocks in their cybersecurity program. So great, you know, he's now on your team as a director, and you've hired Shane Cox as a director on the team. So you've brought a lot of great talent. So I can't take credit for Jacob's initial hire or Shane's initial hire. Um, uh, a gentleman that preceded me did that, uh, but I've definitely taken advantage of it.
Yeah. So, um, I, I did get the chance to, to have Jacob move into these other areas, and interestingly enough, Frank is the backfill for Jacob. Yeah. So he's the, the architecture director? Yeah, he is.
That's great. But we, we've had a lot of other really good acquisitions. Uh, I was actually lucky enough to steal, uh, a few different members of my team that had rolled off their final acts, uh, at Sports Authority. Yeah. Um, yeah, and I, I don't know, I, I see, I see, um, more healthy controlled expansion in our future.
That's great. So since we're talking about hiring, what, what is it you're looking for when you hire someone? Obviously it depends on the role, but high level, what is it you're looking for when, when you go through candidates' submissions? Yeah, so for me, and this may sound a little trite, but I absolutely mean it, the, the most important thing for me is attitude and aptitude. Uh, and what I mean by that is if, if I'm interviewing somebody and they're super nervous, I'm not the type of interviewer that just tries to drill them into the ground and finish the, the collapse.
Uh, I really believe that you have to spend time with people in interviews and really dig into what they've done, make them comfortable, figure out where their strengths are. Our absolute best application security tester is— and I know he wouldn't mind me saying this— he's a very uncomfortable interviewer. I interviewed and hired him at Sports Authority, and then he interviewed and was hired at Cognizant. And I think that you need to dig in, figure out how well people adapt to questions you're asking, how genuine they are with you, how, how much is their background integrating into their actual personality.
I don't believe that formal education is the only road to get to a successful place in cyber. We have great people that have great formal educations. Dr. Jacob Rubin was one of the people we mentioned. But we also have others that have just spent a long time in the community and worked through things. Yeah.
So I would say you really got to drill in, look, look to see how adaptive they are, look to see if they're eager and want to actually contribute to your team, or they're just looking to join somewhere. Yeah. Like, you don't want that second person unless it's a really key skill set you're hiring for and you don't have another choice. Yeah. So for those people who, you know, are career changers— and I talked to quite a few career changers, and of course we want to encourage as many of them as we can to change careers careers.
What's a— except developers, we need really good developers to stay developing— is if they have an interest in security. Yes, yes, yes.
Um, if someone's looking to make a change into security, what, what would be the right way for them to get their foot in the door, you know, at Cognizant working with you guys? Yeah, so I, I would say, uh, it always helps if your current role has elements of security in it. Yeah, change your current job rather than changing jobs. Yeah, we actually have 2 really great team members that were more in the system engineering space. Yeah, and when they came over, they've been phenomenal because I think they had a good fleshed-out IT background.
And then we just had to, in one case, hone security principles, and another one, teach security principles. Yeah, and they're actually 2 of our absolute best. And if you're listening and you figure out who you are, don't get cocky.
But I would also say if you're not currently in a security field, you should look to see, hey, why do you think you're interested in security? Hmm. I think a lot of times the attackers get most of the press and most of the, most of the glory. Mr. Robot.
Yeah, it's all about the bad guys, right? Yeah, well, I mean everything, right? It's from the social engineering all the way back to sneakers. Yeah, up to Mr. Robot now, right?
It's always about that. Yep, it is. But I'll tell you, I think what we need the most in our field today— I mean, we need everybody, right? There's so many. So I can't remember what the last statistic was.
How many million? 8 million or whatever. Yeah, whatever. So there's a lot of cybersecurity jobs to go around. But, you know, very few times Do our operations people, our architects, our application security people get the amount?
And I mean, by application security, I'll be specific, more of that architecture side, more of that integration side. They don't really get that proper exposure. So most people that aren't from security that get interested in security are instantly interested in the attacking side. And I think it isn't what they think it is most of the time. Yeah, it's like, what do you mean I'm gonna spend a third of my life writing reports?
Yeah, but on the other side, if you think, if you think attacking is really sexy and exciting, give it 6 months and you'll realize you use the same 3 tricks to get in everywhere. And then you come back later and test it and the same 3 tricks work again. It's really not a very creative job when you do it professionally. Yeah, I would say that I've met some really exceptional creative folks. Are they frustrated by their jobs?
Um, most of the pentesters I talk to eventually get frustrated. So honestly, I think it's how their jobs are situated. Yeah. So if there's a research element, uh, normally not. That helps a lot.
Uh, if they have some sort of, uh, internal, uh, bug bounty type of structure or anything that allows them to expand and not just do the same 3 things over and over again. I think it keeps them motivated, keeps them very interested. Yeah. So I think that's great guidance. I didn't actually answer your question.
I just talked forever. Didn't you? No. So let me answer the question that you actually asked very, very quickly. Yeah.
So if you're in those other career paths and you want to get into security after you've figured out why you want to be in security, look for your best path in. Something that gets overlooked all the time QA people make awesome security testers and awesome application security engineers and architects if they have the, the attitude and the aptitude for it. Um, and it's just one of those things that's not looked at. The other thing that I think we should encourage all of our security leaders to do in our community, because frankly our community is pretty, pretty hopping, but it's also a hot competitive zone. We don't currently have as a community a mechanism for going after recruiting people that might be more in like traditional system engineering or these QA or developer roles and getting them interested and getting them mapped over.
And we're going to have to do something like that soon because otherwise we're just going to run out of talent. Yeah. And, and if you're, if you're a security leader and you're not looking at your IT help desk or your QA department or your, you know, whatever other internal folks as a potential source for incoming talent, I think you're really missing out. And, you know, I've hired 14 people in the last year and a half, and maybe 3 of them were security people before, right? Yeah.
But you find someone who's excellent at what they do, and you say, well, now add security onto that. You know, I'm gonna hire someone who's excellent at managing infrastructure. I say, well, now you need to be excellent at securing that infrastructure. And it's an easy transition because they already know they already know all the bells and knobs. They just got to look at it from a different perspective.
Yeah. And that's, that's my belief. And, you know, it sounds like we're almost completely— yeah. Yeah. I am gonna change topics on you.
Top 3 priorities for the next, next year, 2018 priorities. So I would probably say continued strategic road mapping, you know, with our business always focused on evolving and and growing, we need to make sure that we're getting out in front of that consistently so we're not just reacting to the latest business challenge of the day. Yeah, so that's definitely a top priority. I would say looking for proper synergies between our other business groups and security. So I know you and I are both relationship builders by nature, but I think one of the greatest strengths that you can have is if all the teams actually doing the work get security, understand it, want to deliver value in the form of quality, in the form of security, it's a huge win.
Yeah, so that's number 2. And then I would say probably number 3, and, and I think you'll, you'll get this because you have a similar type of goal, is really to get out in front of all of our customers and hear what's important to them, hear what their challenges are, and make sure that we're focusing some strategic objectives towards helping them realize theirs. Yeah, and getting that feedback, it's one of the key things about what we were talking about before we started recording— not being a security bolt-on to your business, but being integrated and making sure your priorities map to the business's success. Yeah, and for context, for those who obviously are not me and Matt, we were talking, we were talking about GDPR and and the requirements around a data protection officer. And some of the requirements for that position are that the person can't be compensated based on the success of the company, and you can't be fired for doing their job, and some other things that really seem at odds to, you know, aligning really tightly with the success of their business.
And something that kind of puts me off a little bit about the position is how it puts you in an adversarial role against your your team when, you know, God, that is what security has been for the last 20 years, right? We've been the Department of No, trying our best not to be the Department of No. Anyway, so tell me about lacrosse. How did— how in the world does a, does a, you know, man in his late 20s— I'm proud to be in my 40s, man— go from never having played lacrosse to, you know, I'm not gonna spill your secret for you, but from having some, you know, some pretty fun times doing that. So interesting, we had a friend group, so several of my friends and I, and a couple of the younger members of the friend group decided that they were really interested in lacrosse.
And by younger, I mean probably mid-20s at the time. And they just decided they were gonna start doing pitch and catch and doing all these things. And then one day they just informed all of us We're gonna have a lacrosse team.
Does anybody want to join? And actually what's funny is 4 of the people I'm talking about were on my team at SA.
And so a lot of my older friends, so by older I mean our age, we thought that sounded fun. We had all actually done athletics, including my girlfriend Michelle. She's been a lifelong athlete. Most of us in the older group had been lifelong athletes. None of the ones in the younger ones had ever played any real sports.
Yeah. So we thought, well, that'll be really cool. So we got together, we— I kid you not, we watched YouTube videos trying to figure out how to do everything. Yeah. And we got okay, and then we just joined a men's league.
So we show up, it's our first game, and everybody on the field had been playing since they were like 10. Yeah, and several of them have been playing in Division 1 schools, and multiple of those had played for scholarship. Yeah, so needless to say, we spent our first few seasons getting absolutely trounced. Uh, what's the trounce score? Is that 10 to 1?
Uh, yeah, so, so I would say that first season, because they were being kind to us, uh, it was staying at about, uh, you know, the 10 to 12 to nothing. Yeah, okay, like we didn't score, right, uh, until like game 3. At all. But what's really cool is we're now 2 years in, like 6 seasons in, and we've won multiple games at this point. Much to the actual— the league is super supportive.
They're shocked that we actually got good because we were really bad. Yeah. And we're not good, but I mean, we've become competent. Yeah. And about, I'd say, so we were playing indoor we had finally won a few games and we're like, okay, well now if we really want to get serious, we should take a season off and actually try to learn how to do things, how to play this game we've been playing for the last 2 years.
Yeah, yeah, yeah. So about that, at that point it'd been about a year and a half. So I actually found this really cool app called CoachUp, and CoachUp allowed me to see— it's like free advertising, I should get some sort of credits, I think. Um, but it allows you to see all the profiles for all the coaches in your area. Yeah.
And it's all sports. Yeah. And it tells you if they've been background checked, it tells you what they do. And I actually found our coach, who is also the strength and conditioning coach for the Outlaws. Yeah.
In the app. So, so you— the Outlaws are one of Denver's professional lacrosse teams. Is that the indoor or outdoor? Outdoor. Outdoor team.
Multi-time champion. So, you found the coach for the local professional team and you engaged him to come work with you one time or? No. So, we've actually— I think we've probably been through probably 12, 14 practices with him now and he's attended and coached multiple of our games. Yeah.
Well, this must have cost thousands of dollars to get this guy. Wow, you're such a good setup guy. No, so it's super reasonable. It's super reasonable. Um, and I'll just actually give him a free shout out.
So Chris Spangler is our coach. He's, he's awesome. Yeah. So if you do have kids that are into lacrosse or you're into lacrosse, he's, he's really awesome. Just don't take my practice times.
That's all I'm gonna say about that. But, um, and he's actually playing with us this season. What? We actually said, hey, do you want to play with us? And he's like, Sure.
So he's probably pretty good, huh? Yeah, he's ridiculously good. But what's funny is most of the people we play are really good. Okay. Really, really quick side tangent.
It was funny. So Michelle and I— so Michelle, once again, is my girlfriend. She plays on the team as well. And we played in our game, and then as everybody was leaving This is just a couple weeks ago. One of the coaches for the next game came up and said, hey, we don't have enough people.
Can you stay and play? Yeah. And Michelle and I and our friend Trevor all decided to stay. We didn't realize it was the unlimited division. What's that mean?
It means everybody we were playing was about 23 to 26, and everybody on the field other than us were straight out of Duke, North Carolina, Yeah, it was— oh, we got absolutely trounced. It was super fun though. How many, how many players are on the field at once? Uh, so for outdoors, 9 plus the goalie. Okay.
Yeah. So, so I think another thing you had told me before was before Michelle started, that it was not a co-ed league. Yeah. So actually it's not even just Michelle. We, we had other, uh, female players as well.
So we had a total of 4 our first season. Yeah. And we just showed up once again, watched our YouTube videos, got gear, showed up. Yeah. And they just looked at us and realized that we have women on our team.
And, and then, and basically you can just see the gears turning. And our co— and our captain at the time, he had taken the league runner through it. But some of the people just on the field were like, uh, are there rules against this? Sure enough, there aren't. So we played and just had a fun, fun time.
The league sent us this nice email to the whole league and said, thank you to the Dragoons, that's our team name, for making the league co-ed. And now 4 other teams have women that play. That's awesome. That's really cool. It's really fun.
Yeah. Well, so we are recording in early October, and as I change topics on you quite dramatically, we've had 2 big announcements recently. We had a breach of a little credit agency, Equifax. In late September, and then we had the announcement from Yahoo of, you know, their records going from 1 billion to 3 billion. And, you know, I don't even know what to think about that.
It's whatever, right? But I guess I'd ask you, you know, as you think about the breaches we've had and what your job is and what we have coming, you know, is there a lesson to be learned from from what we've seen from these failures, right? It's a failure when you have a breach, or at least it's the indication of a failure. Is there a lesson to be learned? And if so, what do you think it is?
Well, I just think the main lesson is realize our jobs are very, very hard. Yeah. And you need diligence. And once again, you need your partners. Like, it's really easy to look at these situations and think only of the security people, the security people being negatively impacted with, you know, in some cases probably their careers ending, in other cases just serious downgrades to their careers.
But it's also, you know, the infrastructure partners, in some case the app people. And so I'd say understand it's a team sport, back to the whole kind of lacrosse connection there. You cannot get there as just the security group. Yeah, you need your partners to be successful. And I, I think that there's really a couple different examples.
I know Equifax was raked over the coals and has been raked over the coals for what they did, and some of, some of it rightly, some of it wrongly. End of the day though, they were breached on his— not an O-Day, but, you know, the 6th day of a known vulnerability. If you find a company out there that doesn't have any vulnerabilities that are more than 6 days old, God bless them. That's pretty impressive. Whereas you have the other side with Yahoo, where it doesn't seem to me like that was quite so tight a ship that was being run over there.
The partnership you have and the culture in the organization of how much does security matter really matters a lot. I think for us as security people, we need to make a decision. Where do you want to work? Do you want to work in a place that doesn't value security very highly? It's really risky.
It's really risky for you professionally. Alex Stamos, who was the CISO at Yahoo, you know, he didn't stick around there to be a part of a company that was not going to take security seriously. And, and I'd recommend that those of us, you know, we need to, to show our disapproval by making, you know, good career choices. Yeah, I know. I think that makes a lot of sense.
I would also say though, and you and I have talked about this in the past, you know, we need the most passionate of us to look for the big jobs. Hmm. Yeah, I'm not saying bad, difficult jobs. Like, you don't need to find a place that's completely jacked up, but you need to find— if you've reached the stage of your career where you have the set of skills and experience to manage a very, very large operation and contribute to the existing success or bring new success, don't shy away from that. And I think I see some of our peers like kind of drifting towards the easier gigs.
Yeah, um, step up to the plate, huh? It's good feedback. Well, I think— I just think we need to. Yeah, you can't— not gonna solve the problem from the sideline. Yep.
That's, that's a good, good story. All right, we are, we are coming up on our time here. Um, you need to get to sleep so you can get on a plane in the morning. Let's, uh, let's— I want to give you an opportunity to— is there anything you want to leave the community with? That was a great challenge right there.
Anything you want to leave the, the listeners with other than that? Um, yeah, so I think it's very easy, uh, to get negative headspace in our jobs. And I don't think much good comes out of that. So if you find that you have become a burnout, or you have become overly negative in how you're dealing with your partners, or the community for that matter, or you just like sitting on the sidelines and, and sniping at things, realize that you're, that you're contributing to the problem, not, not helping. And for those of you that are staying positive, and those of you that you know, are consistently contributing to community, thank you incredibly.
Um, it's a lot of hard work to keep the community going and growing it, and I'm just going to take another second to thank you. So for those that don't realize it, Robb never really takes credit for himself, but Robb is one of the main reasons we have a great security community here for leaders. There have been other good partners that have built up individual contributor communities, but we have a great leader community in a big part because of what you've done, Robb. So thank you very much. Thank you.
And, you know, kind of back at you about OWASP. I know you've been on the board for OWASP for multiple years, the Open Web Application Security Project, really putting together those monthly or bimonthly meetings. For how many years have you been doing that? A couple of years. Yeah, it's really neat.
I appreciate you doing that as well. Keep it, keep it going. I'd like to check in with you, you know, next year, maybe about this time next fall and see how things have changed and see if you've taken over the whole world by then.
And good luck on your vacation and good luck in the CISO of the Year award stuff. By the way, I didn't know that that was general knowledge. It's on the website. Oh, okay. Yeah.
All right. Well, thank you very much. All right. Well, have a good one. Yeah, you too.
Bye-bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.