Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 43, which is a very special episode for the week of, uh, November 27th, Right? This is our Thanksgiving episode, and this week Alex and I decided we want to take a week off from the normal news and really just talk to you a little bit about the things that we're thankful for in the security community.
You know, we've been slaving hard for, you know, the better part of a year doing this, and we thought, you know, we deserve a week off. Yeah, so this week, rather than going through the news and the jobs and the events, we're just going to talk to you about the things that we're most thankful for here in the last in the security community and basically since we started doing this podcast. And, you know, we could probably talk for several hours on all the things that we're thankful for. But, you know, we thought we would just go through a few of them and leave you guys with a little bit extra after that. And there's some leftover pie upstairs that we're ready to go eat, right?
That's right. All right. Pie. So the first thing I'll say I'm thankful for is something I wasn't— I didn't know about before we got into this, which is that we have a governor here in Colorado who really takes security seriously and has made it a top priority for him and his administration. I think that is awesome.
I'm a big fan of Governor Hickenlooper. I think he's done great things specifically around cybersecurity. And there's, of course, been talk that he has potentially other political aspirations after he is done here as governor. So potentially, maybe we have someone that moves on to some other political positions that also cares about cybersecurity. I think that would be really cool.
A couple of the things he's done, obviously, you know, the creation of the National Cybersecurity Center in Colorado Springs was a big initiative for him. We've had him put together several different, like, workshops and panels to talk about security in the area with local companies. He was one of the keynote speakers at RMISC this year. And once again, he's just made it clear that this is something that really matters to him. Yeah.
And I think, you know, if you talked to Debbi Blyth, who's the state CISO, she would agree. And I know that he's been very supportive of their efforts as well. So next, we're definitely thankful for all of the volunteers that run the different organizations that we have around town. We have a big ecosystem of volunteer organizations— ISSA, ISACA, OWASP, Cloud Security Alliance, Women in Security. I'm not trying to leave anybody out, but there are plenty that are out there.
And these are all organizations that are run by volunteers. None of those folks get any financial incentive for doing what they do. It's just the love of building a security community here in town. Yep. And so, you know, there are obviously people that are in leadership of those organizations, but also many, many, many other volunteers that help with events, that help with planning, with, you know, doing communications, lots and lots of tasks that you might not even think of that, you know, we need volunteers to continue to make sure that those things run.
Run, and we are definitely thankful for all of them. This is how Alex and I both got involved in security in the community, and highly recommend anyone listening right now who feels maybe you're not plugged into the community yet, the best way to get plugged in is to go, to go sign up, to go help. Go find one of these groups that really aligns with your mission. You know, if you're focused on cloud, go get plugged in with Al Barton at the CSA. Or if you want to, if you're a web application security guy, go talk with Steve Kostin at OWASP.
If you're just a security guy who wants to be plugged in with other security folks, ISSA is a fantastic connection. James Johnson leads that group. If you're on the audit side, risk side, ISACA, and the current president is Rick, right? Rick Lucy. Rick Lucy is the president over there.
And of course, if your mission is to help get women more involved in security, please get plugged in with the ISSA Women in Security. Sarah Avery is running that. Yeah, exactly. And I think what Robb just said highlights the fact that we are also very lucky, and we should be thankful for the fact that we have this many, the quantity of organizations here in Colorado. Not every city has this many groups available.
Yeah, and there's more than I just mentioned, and I apologize I can't get to all the groups, but if you go to our website, colorado-security.com, and go under security organizations, there's a list of all the ones in town and some good contact info to let you know what do each of 'em do, which is the right one for you to get involved with, And I do believe it's a great way for you to excel, you know, move your own career forward. Next, I just wanna— I'm thankful for some of the bosses I've had in my career. You know, I've been incredibly fortunate. I've never had one of those bosses like, you know, you see on TV that's, you know, Office Space boss, right? I've had a really good set of bosses over my career that have helped me go from, you know, from early in my career, I was actually tech support answering phone calls at a at a call center for Electronic Arts, up to, you know, IT help desk and network administration and getting into security finally.
I just wanna say thanks to some of those bosses and, you know, some who might be listening, Jeremy Cooper-Levitt, my boss from Variel back 15 years ago, he's now one of the leaders at Charles Schwab Security. Appreciate you, Jeremy. And Mark Sanner, boss of mine at Triple Creek. Mark, probably not listening, but I appreciate Mark. And Doug Peterson, who's now the Chief Security Officer for Great West Financial, was my boss at Aurora Bank.
Thanks a lot, Doug. Doug, for your support there. And then Don and Gary, both at Pulte, who I worked for there. Just great people who helped me develop my career and move in the right direction. Yeah, so we obviously, we have shared a boss, Robb.
So I would echo the message about Gary, who is my current boss. I don't want to kiss up too much because I don't know how couth that would be to kiss up to your current boss. But I'd also like to give a shout out to Tom Wager, who was an early boss of mine who I really got a lot out of and helped shape my career. Also, my very first boss, not in information security, his name was Tom Reed. Still keep in contact with him.
He was the manager of the bowling lanes where I worked in high school. Oh, neat. Great guy. He was actually just out here this summer to visit. So, gotta love great bosses.
And I would encourage those listening to reach out to your either current boss or your previous boss who's done a good job helping you with your career and let them know. It means a lot to hear that kind of stuff. Recommend you guys do that. You know, I'm also very thankful for a supportive family. You know, Robb, you and I do a lot of things that are not part of our, you know, sort of 9-to-5 kind of job, including the podcast.
And this takes, you know, a good amount of time out of our, out of our week away from our family doing other things. You know, we were down here in the studio on a Sunday recording this when we could be hanging out with our families. So I really appreciate that My wife, Tammy, and my kids and all the rest of my family really appreciates and supports the fact that we do this. My wife, Kristen, has been amazing, as supportive as I've done, obviously, the podcast, but ISSA over the years, and then the dinners that we do. It is a significant chunk of time, and she's been a great foundation for the family at home.
It's neat that my kids are starting to be interested in this whole podcast thing. And you saw Just today, one of my sons was watching through the door as we were recording, and they always ask me about the podcast and, and can they, can they listen to it? And then they listen and they actually act a little bit interested, which is amazing because they probably don't get very much of it. Well, that's slightly different than mine, Robb. You know, I have a new teenager who, you know, is disillusioned and hates everything.
So, you know, he could care less if I was doing the podcast. But yeah. So next thing that I want to be thankful for is just this community. You know, we've been I would say that as of, you know, 5 years ago, that I wouldn't have called it a community. And it's really become a community over the last few years, and people who have really embraced the idea of moving outside the walls of their company to share best practices, to build relationships, to be that resource to others when they have questions about security.
And they've really embraced, uh, not only become a community, but they've embraced the whole Colorado Equal Security movement and helping to, to really elevate Colorado as the place for security. It's been a wonderful reception, and that's, that's why we're still doing it, right? Exactly. Yeah. As people come to town and, you know, I talk to folks that, that have moved here and are becoming part of the community, I really hear over and over again the fact that this is different here than it is a lot of places.
People are willing to help. People are willing to accept you into the community. People are willing to go out of their way to make sure that you feel welcome. I think that that's really important. And if you don't know how to get involved in the community, strongly recommend number one, sign up for our Slack channel.
We talked about that last week. Go to the website and get the link for the Slack channel. It should be in the show notes as well. But go talk to folks out there, go to meetings, ask questions. It is not meant to be cliquish here.
If you're experiencing it that way, You know, try a different group. There are so many different ways you can get plugged in. I do believe you'll, you'll have a pretty easy time finding folks to connect with. And I think you would be surprised the number of people that will be happy to have a lunch or coffee or whatever else and just to talk. So if there's someone that you want to meet or, you know, you need to get some information, hey, you know, send somebody an email, connect with them on LinkedIn, ask them out for a coffee.
Yeah, just don't send a blank connection. Put a note in your, in your invite on LinkedIn, say why you want to connect, and that works a lot better. Exactly. And I think lastly, for me, I'm thankful for the fact that I chose to be in information security. So early on in my career, I sort of fell into this.
I think like a lot of people, I didn't really know what I wanted to do with my life, and I was able to find information security. And it's really done a lot for me. I enjoy the work. I enjoy the challenge. I enjoy, obviously, the community.
Um, and, you know, it's been something that I'm really thankful for. Yeah, I, I actually, I remember I was making a decision. Do I want to go down the path of, of security or project management? Those were the two paths, you know, relatively early in my career. Yeah.
Uh, and, and I'm very thankful that I went down the security path. It's been, it's been a wonderful opportunity to contribute, I believe, make the world a little bit better place while at the same time, you know, have— make a nice career out of it as well. So it's been, it's been a really good thing. I'm also thankful for Robb.
Working with Robb on this stuff has been great. And, you know, he's probably not thankful for me, but that's okay. It's been fun doing this stuff together, and we're looking forward to keeping it going. Alex and I— so Alex was the president of ISSA when I started volunteering, and I, I sent a note saying, hey, I'd like to help. Do you guys need any help?
And the response I got back was, here's the 3 board positions that are open. Which of them would be the best fit for you? I'm like, board position? I was just gonna gonna go like set out some brochures somewhere or something like that. But it's been great.
Alex and I have been doing this for, uh, I don't know, 6 years, 5 years, whatever, total, all the stuff we've been doing. Uh, and it's been a partner, right? We've been partners. We do our side business. We did our side business.
I don't think we really do that anymore. But, uh, really been a fun process as we've kind of figured out what does the Colorado security community need and helping to do that. So thanks a lot for all you've been doing there too. Awesome. With that, we are— I think that's it for this week.
Uh, no news. But we do, we are going to throw it over to one of the interviews from our archive. And since Thanksgiving is a holiday tradition, family holiday tradition about family, we're going to have the first couple of security here on here, Gail and Steve Corey. One of the interviews we did early in the show, one of my favorites from the archive. You guys hopefully listen to this and get to know those 2 a little bit better.
Curl up in front of the fireplace, put it on for the family to listen to. It's, it should become a family tradition for you. And we'll catch you guys, catch you guys the first week of December. Have a good one. Thanks, Robb.
Hi, this is Vincent Grimard, CSO at Nelnet. Welcome to Colorado Equals Security for Colorado security professionals by security professionals.
Hello, this is Robb Reck with Colorado Equals Security. I am very fortunate today to have Gail and Steve Corey here at my house. To do an interview and get to know them a little bit. So as a starting point, I just ask you guys to introduce yourself and tell our listeners a little bit about what you do. Gail, go ahead.
Okay, thanks, Robb. Happy to be here. So I work for Oracle. I run security compliance risk, business side risk, for one of our cloud businesses globally. So it's a global role.
I have people in my team that are associated all around the world. Our job is to make sure that we're managing the security of our customers' data that they've entrusted to us in our cloud. The exciting thing, I think, about the job I have and what I really like about it is I get to touch lots of different industries. I have customers in everything from manufacturing, healthcare, big web commerce, e-commerce customers, also government. We service government and different industries all around the world.
And so I have an opportunity to really learn about, you know, what is critical information, what is sensitive information in these different industries, and be able to, you know, take our security controls and make sure our security controls address that. And so it's always challenging. I think I've probably seen most every regulatory requirement that there is. I remember one time I was asked, you know, if we comply with the Dutch bookkeeping laws, and I was like, well, let me think about that one. But yeah, so that comes up all the time and how we comply with certain regulatory requirements.
And, you You know, the big one we've got coming up is GDPR for all our European customers. So, everybody's, you know, concerned about that new data privacy regulation and how we're going to be able to make sure that we can meet the requirements there by May of 2018. So, we'll be working on that a lot this year. So, that's a little bit about me. So, Danish bookkeeping regulations.
Yeah. That's not one that I thought much about. What was the acronym? The GDPR? GDPR, what is that?
Yeah, General Data Protection Regulation. It's the new regulatory requirement the EU passed last year, and we have 2 years to get in line with it. And it really is replacing a lot of the data privacy law in Europe. And when we had the invalidation of Safe Harbor for onward transfer of data from the European Union to the United States that kind of shook up the whole data privacy space in Europe and how could companies who have data in the United States be protected from that. And it kind of was driven a lot by, you know, all of the, I would say, spying on personal kinds of communications, etc., that sort of blew up about a year, year and a half ago.
And, uh, so anyway, that's our new regulatory requirement. So anyone who has data outside of the EU or even within the EU has to be able to comply. So any, any company who, who has data either of companies that are located in the EU or companies that have, you know, offices in the EU are going to be asked to be compliant with this. Yep. Yeah.
So Steve, would you introduce yourself as well? Sure. Hi, I'm Steve. Steve Corey. I'm the Chief Information Security Officer for the City and County of Denver.
We are not GDPR compliant, and I don't have any short-term plans to do that, but I'm sure I could easily meet all those needs. One of the things that's interesting about my job is that the city is a collection of agencies, and each agency has a mission to serve the citizens of the Denver, the residents of Denver. Each agency has its own IT requirements, and they all, because they are chartered to be what they are, they are the most important thing. So I provide security for over 50 different agencies, and they're all the number one in terms of importance. And so did you say 50?
5-0? Probably, yeah, probably over 50. That's a lot of agencies. Yeah. And those range from, you know, some of the bigger ones are public safety, police and fire.
We run 911 for Denver. There's, you know, agencies that plant the flowers in the park, that organize the repair of streets, the traffic lights, you know, all these things. It's a lot of— most of the things you take for granted in a city are you know, provided by the city. So, uh, the trash pickup, uh, wastewater, sewer management, and all this, uh, really all kind of tie into being portions of, of critical infrastructure. And, uh, so it's never a dull moment because there's always something going on somewhere.
When I've worked in, uh, for the city, I'm going on 9 years now, and that's my first foray into the public sector. Most of my career ahead of this is in financial institutions, mostly banks and insurance and telecommunications. So I've worked for a lot of time in the private sector, but particularly in banking, it was you had one customer or you were doing one business, which was basically keeping track of money. And the city, every day it's something else. And it's not so much just keeping track of money.
Yeah. So I want to dig some more into both of your guys' backstory, but first I want to know, how did you become the first couple of security, which is what I've heard you called many times, or the royal couple of security, depending on who says it. Talk to me about your guys', you know, personal history. Yeah, well, you know, I started off my career years ago as an application developer and And eventually worked my way into IT audit. So I needed a little bit more of a 9-to-5 job, so I wanted to use my technical skills.
So I started auditing systems, looking for, you know, weak controls. And back in, in the day, right, that was primarily mainframe systems and things like that. And eventually I ended up— actually, Steve hired me. So that was a long time ago. He was running audit at Great West Life at the time, and I went in as an IT auditor on his team.
So that's kind of how we met. Yeah, we worked together. Yeah, from water though, you went into security. Well, you know, eventually I ended up at Galileo and I was in IT audit at Galileo and this was in the late '90s and they were, you know, historically, you know, big computer reservation systems companies. So big mainframes and a lot of, you know, point-to-point kinds of connections coming in from all the hotels, the cars, the airlines, right?
And all S&A traffic and everything coming into their systems. So anyway, I was an IT auditor there for a few years, and I had uncovered a few things around security that they needed to shore up. About this time, you know, the internet was becoming much more of a business tool, and Galileo was putting a presence on the web, and the person who was running security at that time didn't have a lot of experience with TCP/IP and, you know, firewalls. Why do we need those? And all that kind of thing was— it was all new, right?
And so he decided to retire. Oh. And so he's like, you know, too new stuff, I'm done, I'm out of here. So, um, I was asked to step in and take over the security function at Galileo. And then I was asked to fix all the issues I had uncovered when I was there doing the audit work.
So that's how I made the move from audit to security. I stayed there a couple of years, and then I moved on to JD Edwards. JD Edwards had just become a public company. They had just filed their IPO and everything about 6 months prior. And so they did not really have a concept of security.
It was a family-owned company, and JD Edwards, you know, I shouldn't say they didn't have a concept, but everyone was, all of the employees were, you know, a big family. But when you have a— when you're a public company and you have shareholders, you need to start thinking about how do you, you know, segregate data and access to data. Not everybody— Before or after Sarbanes-Oxley? Before. Okay, so you didn't have the stick?
No, no, we didn't, but there was definitely a need. The company was growing into a global presence, and there was definitely a need to bring in information security as a function. And so I came in, there was one other person that was there for security, and together we sort of established the program. Eventually, I was named the CISO at JDE. That was in 2000, I think.
I worked for the CIO there, and then, you know, just went through the acquisition in 2003 by PeopleSoft, and then the acquisition by Oracle 18 months later. And that was 12 years ago. I'm still at Oracle. So that's how I made my way to Oracle, but that's how I made the jump at Galileo from audit to security, and I've been a security leader now for almost 20 years, which, yeah, time has gone by. I've seen a lot in those 20 years, a lot of change.
So now, do I remember that you guys have been married about 20 years? Yeah, we're coming up on 20. 20 this year, 2017? Yep. So that means, you know, 1997?
That would be correct. Your math is correct. So you were at Galileo at the time? Um, when we got married, I was at Galileo. Yes, I, I left Galileo in '98.
Okay. Now, do I remember correctly that Debbi Blyth went through Galileo? I guess I'm thinking she did. She did. And then, yep, we knew each other there.
Was she there when you were there too? You guys crossed paths? Um, I think we did, yes. And then, if I recall, she remembers working there with me, so yeah. So Debbie Blight, the CISO of the state of Colorado, who is someone else who we run into pretty frequently.
So Steve, talk to us about your backstory. Yeah, so I'm going to go back to the Great West Life days, and I was just running IT audit. So IT audit was relatively new, and I had a position to fill, and Gail was making a leap from her prior career, which was, I think you were doing programming at a church or running a school and church software. So she was trying to get back into the more bigger business. I think you were volunteering or working for her to pay for your kids' tuition.
You got free tuition, tuition remission. Anyway, the, yeah, so at that time, viruses, computer viruses were just becoming, um, an issue in, uh, in security and in technology in general. And I was always, uh, you know, I guess a forward thinker. And so I thought, well, I need to learn about this. And so, uh, Gail was already on board, and I said, you know, do you want to go with me, uh, to get some books on viruses?
And so we went down to the, uh— she agreed to go. And so I think for lunch we went down to the Tattered Cover Bookstore when it was downtown, down in Cherry Creek in those days. And then we must have bought, I don't know, a lot of books. All the books. All the books.
Here's one. And it was amazing how much information was available. Not very many people in technology were even talking about it. And so we got the books and And Gail's a really good reader. I'm not so much a reader.
So she started to read about this. And then we had the Dark Avenger virus breakout at Great West Life. And Gail had read the books. And so she was then the virus queen because she knew— we knew what to do. And it was like we came from audit.
And the security people at the time were all mainframe security people. So they were focused on ACF II and mainframe. Yeah, well, we had an ACF II shop, but it was like Rack F in that category. So they didn't understand anything about the PCs. The PCs were just kind of coming into being.
And I came, I moved here from New York, and in New York we used other tools, but in Colorado everybody used WordPerfect. I thought it was some kind of state law that you had to use WordPerfect. And that's how far back this goes. This is WordPerfect before the GUI interface, which they did horribly. So anyway, the computers were just starting to proliferate to the desktop, and in my department at the time, people had to sign up to use the computers.
There was like 4 computers on a table, and you had to reserve your time. And I was insisting to my management that all the IT auditors needed their own computer. And so I was cutting this thing and then there was this envy because the IT auditors are so special, they have their own computers. And then so they were starting to proliferate throughout the workplace. And so we had a desktop technician, a very helpful guy.
And anybody, if you had a problem with your computer, you called this guy. And one of the things that he carried with him was a floppy diskette that had his tools on it. And so people would have a problem. And anyway, this turns into the fact that the virus spread the way it did because the guy that walked around and inserted his disk, inserted his diskette in all these computers. And so it was like we named him Typhoid Mary, I think, because he was actually spreading the virus.
And we were the first ones to have antivirus software. And I remember we were at an ISACA conference up in the mountains, Keystone I believe, and one guy stayed back at the office and he called me and he said he was having trouble with this 3270 emulator program that wasn't working properly. In the end, I found out it didn't work right because he had the virus. But so I said, well, why don't you scan it? And so we had this scanning software and what what we found out was in the process of scanning that we could spread the virus faster because every file that was scanned was then infected once the system had the virus on it.
Anyway, so we ended up being, um, doing a presentation at ISACA about this event, and, and it was really kind of interesting because a lot of the people were like, well, what are you recommending, Steve? What's your recommendation? And my recommendation at that time was you must run antivirus continuously scanning, in a continuously scanning mode. And most companies were not willing to do that. They said, well, we'll scan once a week, or we'll scan, you know, once a month.
I got hate mail from people that had seen that presentation and saying, this concept of viruses is all made up, and that this guy was an author of a book on writing Word macros. You know, he had his book. And, um, and so, uh, but it was funny because he just told me, you know, you're just making this stuff up, and I would never tell anybody to run antivirus software. And, uh, so I think we were, we were pioneers of the day. And actually, yeah, they used to, you know, Ghostbusters was— the first Ghostbusters movie was out, and, uh, somebody drew a caricature of Gail and I with the backpacks on, uh, with the, you know, shooting our, our, the thing out to kill the viruses.
Yeah, getting the ghosts out of the PCs. Yeah, yeah, that's Do you still have that picture? Can I get that as a part of the poster for us here? Could I find it? All right, that's a challenge.
That's a challenge for you to find this picture. I vividly remember it though. Yeah, so I think we've seen a lot of change. You know, I remember early in the early 2000s, you know, back at that time, the whole idea of having a virus or a worm you know, released out on your network was the big thing of the day where people either wanted notoriety, they wanted to get in the news, they wanted to be able to take networks down. And so, you know, I remember I was— there was a— we had a Microsoft Exchange mail server, and this was at JD Edwards when I was working there, and I kept saying, we're gonna get, you know, an email-borne virus.
And all the tech people kept saying, well, you know, we can't run antivirus on Microsoft Exchange. It's not certified to run with it. Microsoft won't support, blah, blah, blah, blah, blah. And they kept fighting me about this. And then about 3 in the morning, my— I had a 2-way pager at the time.
It went off and it was my people in Singapore calling me because they had the I Love You virus. I don't know if you remember, but that was— it was taking down our entire mail system. And, uh, and so, you know, it took us several days really to clean that up. And, um, 1999, is that right? Oh, that would have been in the early— maybe 2000.
It was maybe '99. I remember coming into work, and at the time I was, I was a, uh, help desk person at a Electronic Arts, if you guys know, video game company. I remember coming in one day and just, you couldn't use your computers. Everyone's computer was disabled. They just wouldn't let anyone log in because they hadn't figured out how to deal with it yet.
And we're on the West Coast, so had a couple hours of foresight on it and just, nope, we're not gonna use computers today. Yeah. All right. Yeah, what are you gonna do, right? And so anyway, that sort of demonstrated, and I remember at the time that, We got all the way through that.
I was at the office probably for 36, 40 hours straight, just trying to deal with all of the issues and the ramifications. The CIO at the time said, next time you guys listen to her.
That was interesting. Then we had all these, like Code Red, and we had SQL Slammer. I remember One time I was at— when I was working for PeopleSoft at the time, I was in California and we were in this big conference room and all of a sudden we were having a huge problem of traffic on the network. And we had a big screen and so we popped up what some of the traffic monitoring was looking at. And I remember standing there and I was seeing the traffic pattern and I said, that's sequel slammer.
And they said, it can't be, we are— we don't, you know, we've dealt with that, we're good. I'm like, I'm telling you, I believe that's what it is. And as it turned out, we had gotten another infection, a sequel slammer. But so part of that is just the experience of going through and being able to deal with those kinds of incidents. Well, now, you know, that's not so much, you know, the the big risk anymore.
I think what we're seeing now is it's not about being noisy and, you know, there's still distributed denial of service and all that kind of thing that can happen, but more the threat that we're seeing is around, you know, the stealth kind of threat and being on your network and not being picked up because what you're what the whole idea is, to look for data and get that data. Data exfiltration, espionage. Yep, exactly. Of course, ransomware has become pretty popular. I would guess you guys are probably not as big a target of ransomware, but I might think that the City of Denver might be.
Oh, we have been. Yeah, that, that seems like something that, you know, we've seen hospitals, we've seen government, we've seen police stations attacked by that. Yep. So, so, you know, you guys both have, for different reasons, are fairly big targets. You know, Gail, hosting lots and lots of customers in a cloud environment, pretty big target.
And Steve, I know I've heard you talk about, you know, how you were targeted a while back by the group Anonymous. And probably, you know, you're representing a government in a high-profile large city in America. You know, any stories you can talk to about what that's been like? Well, Anonymous, and I have got a lot of time together. We've been targeted multiple times.
One of the most interesting ones was, this would have been, gosh, when did the movie about Korea, what was that called? The Interview? Oh yeah, The Interview. That was like Christmas time 2 years ago, I think. The Interview with— Yeah.
Yeah. So The Interview movie had come out around Christmas time. And I think this was around the Sony hack. The Sony hack. Yeah, it was around that.
Yeah, right after that, right? And that was like the Sony hack was viewed as like retaliation. I remember it was a Sunday that I was asking Gail, where's our son? And she said, he's watching a movie. I said, well, what movie is he watching?
And then she said, The Interview. I said, oh my God. I said, get him off, they will find us. And so that weekend we were doing a major network upgrade. And then Monday morning, about 10:30 in the morning, I remember the deputy CIO came in and said, what's wrong with the internet?
And she's holding her phone in her hand and looking down at it like she's got no service or whatever. And we're saying, what do you mean, what's wrong with the internet? And then we found out that we really had no access to the internet. We were— had actually lost the— we were under denial of service attack. And we didn't know it at the time.
So what we thought was something went wrong with the network change. And we were trying to get ready to back out all the work that we did and how complicated it was. And in the middle of all that, we were trying to figure out what's going on, one of my team sends me an email and it's a news story about a person that was shot by the police. And I thought, well, why isn't he helping solve this problem and why is he sending me an email about a police incident? And so what had happened is as that news of the shooting had spread, that then Anonymous led a very large effort against us.
And this was— and they basically burned us down. We were at the point where we couldn't access our equipment. So we disconnected from the internet. And so that was the only way we could regain control of our stuff. However, during the process of once we figured out that there was a connection, that we were under a denial of service attack, my team was watching Twitter and Facebook, and we found various personalities that were bragging about taking Denver down.
And that data we captured real-time, and later in working with the FBI over a period of time, we were actually— the data that we collected helped them get the connections between the cyber attackers and the main person. I think at the time he was maybe 14 years old, but he was eventually arrested by Interpol in the UK in his parents' basement. And the FBI said that they had attacked so many, many, many governments, and of which we were, you know, just a minor, minor victim, but that our data that we collected at the time was instrumental in helping them determine who it was, who the personality was, and then led to the arrest. And it's fortunate that it happened in the UK because in the U.S. the FBI would not arrest a minor or would not charge a minor for this kind of crime. So they would have just had to just let it go.
But anyway, they commended us. I asked them, you know, will you come in and tell my management? So yeah, so the FBI and CBI Colorado Bureau of Investigation sent people and they did a presentation and basically thanked us for helping us— helping them and the world over capture some major cyber criminals. Now these guys were, you know, I think hacking for fun. I mean, they were just saying, can we cause— can we knock them down?
And as Gail said earlier, you know, they were just going after a tally. And the cyber criminals that we are facing today, now that is 2 years, right? And so it's like, it has become so much more vicious.
But we still have a good relationship with Anonymous. Any city social policy that isn't popular or whatever, Anonymous may take, identify with that and use that to attack us.
They've stayed away lately, but I guess you gotta knock on wood. Can I do that? Okay. But people say that that will lead to You know, if you say they're going away, they'll come back. But, and it's one of these things, you know, it's not like you can get a childhood disease and you become immune to it, you know?
So it's kind of like, well, I already had chickenpox. Yeah, I already had an office once. So I'm not gonna get ransomware again. I'm not gonna get another denial of service again, you know? So it's kind of like, it's always there.
It just, yeah. So denial of service has come back frequently, but we're pretty good at handling it. These days. Gail, you have any stories about attacks against your service or, you know, people out to get you that you can, you can share? That was a little bit different in a private, private sector.
You know, um, I probably— yeah, nothing that I want to go into, you know, a whole lot of detail about, but, um, you know, we do see You know, we are targeted distributed denial of service from time to time. You know, we've gotten very good at being able to offload our traffic and get it cleaned up and come back. You know, when you have a huge amount of customers, a large number of customers you're servicing, that results in a huge amount of network traffic. Going through your network, you know, the layers of control have to be pretty strong. And I feel like we do a very good job there.
There's always little things that come up here and there. I think one of the things I would say today that we see a bit more of is, you know, credential capture and reuse. And I think that companies have to really think a lot today about whether they should use only a user ID and password for anything critical over the web. You know, there is just too much opportunity for those credentials to be captured and replayed, and we have seen that happen. So strong authentication on the front side of anything sensitive needs to be in place there.
So I think we're seeing that whole thing move. I've seen it shift in the last 18 months, probably 2 years to 18 months really become critical. And oftentimes companies are a little bit hesitant to, you know, adopt a new technology, right? We've seen a lot of technology change. We, we talked about how, you know, there was a time when people, you know, didn't believe viruses existed or didn't believe that you should be running antivirus software.
Now you wouldn't think, you know, of having a system that did not have antivirus software on it and your personal firewall. And then we, you know, we've added intrusion detection and intrusion prevention, and we've added SIEM technologies and web application firewalls. As companies use technology to deliver their, their services, their products and their services to market, more than in, in more in different ways, then that changes your whole threat landscape and you've got to continue to adjust your controls. So I would just say those are some of the things we're seeing. Yeah, the, the example getting multi-factor implemented, I think, is just a no-brainer for just about everything.
Now, as a baseline, multi-factor, even if it's not the strongest multi-factor, just getting rid of credential replay, you know, someone gets the breach from Yahoo or whatever recent data breach there is, they're going to use those credentials and try and get in everywhere. And it's great if you make it harder for them, right? Just adding a little bit more difficulty. Now, when you get to targeted attacks, just any old multi-factor may not be good enough. But just as a starting point, I think that's really good advice.
So, Gail, would you mind kind of sharing anything you're especially proud of, either from your time at Oracle or somewhere earlier in your career? Any successes you've had that you'd like to share with the group? Yeah, I think one of the things I've experienced throughout my career, sort of my perspective on security, is that, you know, security needs to be an enabler. And if you can enable your business to move forward in different ways, then you're seen more as a, as a partner, and you're not seen as this gatekeeper that's always perhaps making it difficult to move to new technologies. So one of the things, you know, just as an example here, and this was probably back in about 2006 or 2007, we had an opportunity in our managed services space to, you know, host U.S. government with Oracle.
The opportunity came in, and everybody said, can we do this? Can we do this? I said, well, let me look and see what type of security controls we need to really put in place to support this business. We did some investigation. I had a person on my team that came from military, with a military background, and so we looked at all the requirements and needs At the end of the day, it had been tried— I was told it had been tried 2 or 3 times previously, and it was not going to be accepted to go forward.
The risk of hosting and managing this type of data was too great.
But we came forward with, here's the proposal: we're going to isolate physically and logically, you know, our government service, our federal service. We're We're going to have US people, we're going to get them through security clearance, we have all these controls, we meet all these regulatory requirements, and we ended up getting a sign-off to go ahead and proceed. And that business operates today for us, and it's been very successful. So I think, you know, you can— in this particular case where we had a lot of the technology people saying, being the naysayer and saying can't be done, security really just did a little bit of due diligence to come back and say, well, we can do it, and here's how we can do it. And if you're willing to put that investment in place and make sure that it's being run and managed properly, your risk is, is, you know, substantially reduced.
And, and so that's how we did it. And I think, you know, we have to always be creative about, you know, how can we, you know, help the business, how can we be seen as value-add to the business. And I think when you do that, then the next time you come forward with some other kind of effort that you want to do, you have some champions and some support in your business for that. So it sounds like, you know, the big success there is enabling Oracle to open up a, sounds like, profitable side of the business that they otherwise wouldn't have been able to do. That's pretty great.
Yeah, yeah. And, you know, we've done a— we've gotten to a point now with, in the cloud side, you know, that we're almost from a— we add services for our customers like PCI services or HIPAA services. And, you know, we've become self-supporting.
So my organization is really not a cost center. And that's another way that you can add value. So you always, you have to think about it in different terms and different perspectives, right? But how can you use your security capabilities to move your company or move your entity, a public sector, into being able to distribute maybe some of your services in a more economically feasible way? Right, in which, you know, overall it's lower cost.
There's, there's a layer of there and of security that you put in to make sure you're doing it the right way. So, Steve, any— I'd love to hear from your perspective, any successes, you know, on your— yeah, that you'd want to share with us. You know, it's every year I think we have something fantastic to talk about, but, um, I'm going to go roll back here to the Rocky Mountain Information Security Conference, 2016, early 2016. One of the keynote, our lunch keynote speakers, I believe, was talking about the importance of information sharing.
Gene Spafford? Yeah, Gene Spafford did the lunch keynote. That's right. Rocky Mountain Information Security Conference, the biggest security conference in Colorado, coming up May 9th, 10th, and 11th at the Colorado Convention Center. Yes, that's exactly the conference I'm speaking of.
And one of the points that he made was that the hackers exchange information, exchange tricks, have no reservations about holding back on here's how to break something. And they constantly share that information. However, on the other side of the coin, the, you know, let's say if you're a bank, you don't want to talk too much about being hacked. And so that information tends to stay within the bank and doesn't— you know, there is an FS-ISAC for financial services that does help promote exchange of information, but a lot of times that data is more about, you know, these are the patches that you've got to apply and what the latest vulnerability is in a particular commercial software, but not so much about what somebody would actually do to you. And I think that I was kind of inspired by that, and I took an initiative for this year.
And actually, the inspiration was our last anonymous attack. When we were having that happen, our director of marketing was with us. We were working on this in the event that we had to make a public statement. And then she kind of said, well, it seems like we get these attacks when there's something good going on in the city or something significant. And maybe Anonymous is trying to show up and dampen that experience.
And so she had asked, well, what would be the Anonymous forecast? When could we expect to have something else bad happen? And I thought, oh my gosh, it would be the elections. And so then I— this was in April of 2016. So I started a project and I had this crazy idea that we would work with other governments to plan and protect ourselves for the upcoming election.
And this has never been done before in Colorado, where a municipality or a county, County of Denver, reached out, the technology people from the city working with the technology people of the state, to collaborate on what possible things could happen to us and what could we do about it and could we communicate during an event and an incident. Back in the election of 2014, not the presidential election, the off-election, we had a lot of difficulties. One of the things that was really weird was we were having a problem, and if it was after hours, you called the state, and the state people had gone home for the day, and so you would get their voicemail, and you didn't know how to get ahold of them.
Examined every layer of something that could go wrong, even from finding out who to call. Do we know what their phone numbers are? What types of services do we have for protections? Can we alter our traffic patterns if we do become under attack? What if we're physically attacked?
And any aspect about that. And so, you know, we had a— so I'm have proposed for the 2017 Rocky Mountain Information Security Conference. We submitted a paper where we're going to tell the story. We've just recently did a presentation in Colorado Springs on it. We're going to— ISSA in Colorado Springs has invited us to speak at their Cyber Day, March 30th.
Yeah, so we'll be telling that story there and hopefully at the Rocky Mountain Information Security Conference. So we're presenting this myself as the CISO for the City and County of Denver, Rich Schliep, who is the CISO for the Secretary of State's office, and one of my team, James Stoner, who was our information security manager, who really is a brilliant man and did a lot of the magic for us. So, we were, you know, just kind of a contrast, we were able to watch network traffic real time. We could see our traffic from the Secretary of State from the external view and we could see their internal view, which never before had happened. And when I first brought up this idea of, you know, I'd like to watch your network traffic, you know, Rich and those at that time, he says, well, I'll send you our report.
We, we do one weekly. So that's not going to help us on Election Day. So we, we now, and during Election Day, had real-time, real-time visibility. So we, we could tell the state of any of our network devices from a switch to a router to physical locations all within the city, and the state had that as well within the— for the whole state. So it's really a pretty good story of collaboration.
So I'm excited about it. I think that there's opportunities for governments to improve their stability and reliability and resiliency of their systems by working together. So I look forward to hearing more about it in a few months. That sounds great. So I'm gonna ask the question, you know, those are great success stories.
I'd love to hear if you guys can share a story of something you've done that didn't work out. Something, you know, I think all too often we talk about all the good stuff and we don't share so much what didn't work so people can learn from that as well. Do you guys have any stories from your current jobs or previous jobs of something you tried that, you know, maybe didn't go well and what we learned from that and how you've used that to get better? Wow, I think I usually purge those from my memory.
Gosh, I don't know. I don't know. I have to think. I can think of where you had a challenge, but it ended up going well, but it was rolling out desktop encryption. That was— you were a pioneer, and the user experience, if I recall, was not so good.
Yeah, initially. I mean, I think we had some real Challenges. I know, you know, we felt like laptop and desktop encryption needed to be deployed, and it was really a very challenging deployment for a lot of reasons because, you know, you wanted— you didn't want to have huge performance impact on people, and we did experience some of that. You didn't want to have anybody anybody lose their data off there and have their data be unrecoverable. And we did have a couple of experiences of that.
And so, you know, you— that does, um, it, it makes a project not go well and then makes everybody want to run away from it completely, right? But we were able to, you know, technically solve those problems, provide those assurances, and eventually get it rolled out. And now desktop encryption— that was back when we did that encryption project. I think it was long, quite a long time ago. Yeah, it was pretty new technology.
I always say it was JD Edwards, when I was still at JD Edwards, so it had been before 2003. So that was a long time ago. The technology's got— it's much better. Technologies work a lot better. Yeah, back then it not so seamless, and you probably had a lot of key problems where you actually might lose data.
I think there's this balance, right, between, you know, we always want to be the security people who enable the business to be successful. We don't want to go put barriers in place, but at some point there's this risk balance. If we don't do desktop encryption, you know, there's all these— all of these many lost and stolen laptops across an enterprise turn into data breach problems. If we do do the encryption when the technology is not ready, we're going to cause user impact. It becomes a risk management decision in these tough conversations.
They're not as easy as we'd like them to be sometimes. I know that makes perfect sense. I had forgotten about that. I do have a story. This is from, I guess, 2015.
The fire department put in a request for a garage door opener that they wanted to connect to the internet. And so this is an IoT story. And the position, you know, and then the request came up to me, are we gonna allow them to connect the garage door opener to the internet? And I was like, you know, I'm all about security. This makes no sense to me.
No. And so the only time we've said no. And the repercussions of that was from, you know, the fire department coming back and say, well, how are you technology people helping us? And what had happened was that I wasn't ready to understand what this problem was. And, you know, just because I didn't know what— why would you connect a garage door opener to the internet?
It didn't make sense to me. I gave it no thought. And that really was a big lesson for me because after the fire was on internally, then I went and visited the fire department. And said, what is it you're trying to do? And, uh, which is what we should have said before.
But, you know, my team said, you know, this is a, uh, you know, it's a home type of device, there's no place in the business. And they all poo-pooed it. And it was basically, we were now found ourselves repeating this story of security over and over again. It was like you, you look at the future based on what you know in the past. And so, uh, it made some really poor, uh, decisions there.
And so politically it was very damaging. However, I I owned up for it. And the interesting part of the story was that the— it's not just a garage door opener. This is— these open the bay, the bays that the fire trucks come out of. And then the equipment that they had to open the doors were, were very old and needed to be replaced.
But one of the problems that the fire department would have is that they couldn't tell sometimes how— if the door has risen high enough for the truck to clear. And so they'd have occasionally where they'd go out to, you know, to be dispatched, you know, very horrible event or something, and they would take off too fast and break the garage door in the process and damage the truck. And so, uh, because the, the engineer that's driving the truck cannot see above, uh, above the truck because, because the truck is so huge. And, uh, anyway, so part— they wanted to introduce some technology there where they could just have a light on that said, you know, the door is up high enough, you can leave now. And, uh, that was one of the little things they wanted to do.
And, uh, and then what happens is that sometimes, because with the old garage door opener they were the single button pusher, and if like you pushed, you accidentally pushed it twice, it would do 2 cycles. And so close back, start closing again, basically. Yeah, yeah, it could start closing. Or, um, if they saw that and they hit the button, then they would leave the firehouse and the garage door would be open. And so then that's an invitation to hoodlums and things and vandals to come into the fire station.
And so if the truck was being dispatched, uh, they would have to call the 911 and ask for the police department to go shut the garage door at the fire station. So there were all kinds of problems here that could be easily solved with a garage door opener that had a video camera that the 911 dispatch center could use, anybody they could go and say if that door was still open, they could close it, and would it, you know, and it wouldn't rely on the button that was inside the truck. And, uh, and so it was like, oh my God, they're— they are way ahead of us. They've got this IoT kind of device, and, uh, and we just slammed the door in their face. And this has been— now it's— we're, we're, we're golden because I turned that thing around and we helped, you know, facilitate it.
And they actually had asked to connect that device to a Wi-Fi network that is highly regulated from a CJIS, or Criminal Justice Information Services perspective, of which, you know, we're under regulation through the FBI. And I asked, why did you want to connect it there? And they said, well, because that's the Wi-Fi we have. Yeah. Oh, well, I'll get you a Wi-Fi that you can put your IoT on.
So anyway, with that, that, that was a story, and I think that's really a big lesson. It's Because I think IoT especially is— it's coming, and it's coming in such huge waves that we need to really be prepared for that and thinking forward and how are we going to control it, especially, you know, with the Mirai, you know, denial of service attacks and things like that, that these devices can be misapplied to, that it's important that we be on top of it. I watched the proposal go before the city where they're looking at in order to save money on energy, that they're going to put in, you know, various monitors inside the building so they can, you know, shut down the heating when necessary or turn off lights and be able to have all those under central control. And so all those proposals are going forward. There's no mention of technology behind it, you know.
So I know that within a year when these projects are implemented, they're going to want to put those on Wi-Fi. And, you know, and then all these devices now are going to be vulnerable. So yeah, we had— I think we need to all kind of look at what, you know, how do you stay abreast of this is really kind of the question. And I just think, you know, you got to go out to your customers and ask them, you know, what are you looking at? What is the problem you're trying to solve?
And not— we're not— we shouldn't be security organizations that say no. We should be security organization that says, let me help you do that the right way and reduce the level of risk as much as you can. We're never going to be risk-free unless you disconnect completely from everything. There's always risk associated, but what you want to be able to do is get that risk to a level that's reasonable and acceptable and support the business. So, I think that's what how security has changed in the 20 years I've been leading security teams.
And I, you know, just come full circle back around that. I mean, we really, we have to be smart, we have to be knowledgeable, we have to ask the questions, and we need to bring the right solutions. And that's what makes the job fun, but it's also, you know, a challenge for every organization. So I— we're doing a good job here. We're almost 50 minutes in now.
I don't want to close up quite yet though. I want to ask you guys a couple questions about the security community here in Colorado. Also, as you called it, what you know, Cyber City USA. Yeah, here, here right in the middle of Colorado. You know, I just want to hear from you guys.
I'll say over the last few years that I've got to know both of you, I really appreciate your, you know, your engagement in the community. And your willingness. You know, Steve, I've heard you talk several times. You know, Gail, I know you're involved with several different organizations helping with leadership. Um, you know, talk to me about your guys' experience here and what's keeping you engaged after, you know, 20 years leading.
What keeps you, you know, getting outside of your comfort zone, outside of your job, and still, still out there helping, uh, helping other folks out? I'll start with Gail, if you don't mind. Sure, sure. So, you know, I get involved, um, in a lot of different different areas professionally within Colorado. First of all, I love Colorado.
I've lived here the majority of my life and, and don't plan to live anywhere else. So, and I feel like we have a small community and we know each other, right? People cross paths, people that you've worked with in the past, you know, you'll run into again, just like Debbie and and I have burning to each other and others. So I'm involved with the Colorado Technology Association Women's Initiative. So I represent Oracle there.
It's a subcommittee off the CTA board. And we put on or sponsor every year the Women's Summit that occurs in June. This year it'll be, I believe it's June 9th, and it'll be in Larkspur. But we generally get somewhere in the neighborhood of 500 to 600 women that have some sort of role in technology that come, and we do a day-long event specifically to, you know, have some seminars and some speaking speakers that talk about, you know, some of the challenges sometimes there could be for women in technology, or some of the great kinds of careers you could have and how, you know, give people food for thought. So I'm involved there.
I'm involved also with ISACA. So ISACA has a Women's Initiative Program connecting and inspiring women. And, and as a matter of fact, there's an article actually that I'll be in on in the new release of the ISACA Journal. So you'll sort of see a little bit about me and my background there. So I've been involved with that for probably a year and a half or 2 years trying to help our membership in the ISACA organization.
I've been a past president of ISACA. So in ISSA I'm involved with as well. And, you know, just From my perspective, it's a way I can give back, give back to the community, give back to people who are, you know, help give, you know, extend a helping hand or a lift up for people who are coming up in the business. We don't have enough really, you know, good, skilled, talented security people. We don't have as many as the, you know, we need today in the industry.
So anything I can do to inspire or bring someone forward or get them excited about security is something I really enjoy. I think I remember both of you guys signed up as mentors in the ISSA mentorship program. I know Gail did. So I'll twist your arm a little bit then. Uh, you know, opportunity of one-on-one mentoring there.
Steve, I, I know I've seen you around quite a bit. What keeps you from— you have a full-time job. I know you can spend as many hours as you want to doing your job, you know, but what keeps you engaged in community at large? Well, I think that's maybe something Gail and I share, is that there's a, like, a giving back aspect. I feel it's really important that professionally you can help other people.
I enjoy it too. I mean, I've got to be very honest about that. I just, I love to, love to speak. I am a frustrated comedian, so if I can ever add something humorous to a story, I like to do that. So, community involvement is really important.
I think as I work with a lot of my ex— I don't know, it's probably closely related to my job, but I work with Homeland Security and the acronyms are too long. I can never remember all the letters to say, but we're working to at least in the kind of like from a local area more working from smaller circles to larger circles of exchange of information of incidents.
We have started a collaboration with a few counties in the state of Colorado and some municipalities on trying to find out, can we alert each other of cyber risks as they are happening? There are mechanisms within Homeland Security to communicate information, and it usually, by the time it gets consolidated and scrubbed and ready for return, might run a cycle of 3 weeks to 4 weeks. So the information is well vetted by that time, but it's stale. So, but nonetheless, it's still very valuable. So what we're trying to do is, what we've got going currently is a text like listserv, and we can put out a quick bulletin.
We had a recent web defacement that was exploiting particular vulnerabilities, and I was able to— it wasn't quite a tweet, but I don't know how many characters, I didn't count it, but I could notify my peers in the state of this particular vulnerability that was exploited and what we've done about it, you know, very short, and then it goes out instantly. That's great. And yeah, so that's something we're working on. Yeah, but you've also been really— your team, you and your team, I think, have been involved at the Cybersecurity Challenge. Oh yeah, like the Rocky Mountain CCDC.
Yeah, yeah, the Rocky Mountains Cyber Collegiate Defense Competition. That's it. So, you know, I haven't talked about this recently, but the CCDC is, I think, maybe one of the most valuable, interesting educational things I've seen. Basically, you get college teams together and they're assigned to defend or secure an environment, and then they're competing against other college teams that are doing the same thing with— there's another, the red team out there that's trying to break in. Yeah, we actually designed the platform for the competition in the Rocky Mountain.
We set it up as an exploitation of the traffic network and that we brought our traffic engineering people to meet with other folks from Regis University and they provided hardware that they could use during the competition. I wasn't able to attend it though, so I didn't actually see that, but you know, we set up like, you know, what's it take to hack a traffic light, and then what, uh, and once you're in on that network, can you get to another part of the city network? Yeah. And so we provided that framework for last year's competition, and I think this year's competition is March, early March. I don't have dates off the top of my head.
I will get it for, for later, but, uh, early March at Regis, and there, there are opportunities to come observe, and there's also opportunities to volunteer for anyone who's interested in getting involved. Yeah, we volunteered every year, I think. I think for the last several years. We've also provided financial support as well in the past. Well, you know, I really appreciate your guys' time.
I think you got some great tips for people who are running security programs and some stories of stuff that went well. And can I finish one? Yeah, of course. On more of a personal note, right? On what it's like to live with 2 security people in the same house.
So our son, Our youngest son is, uh, just used to be, you know, he, he is just off to college this past fall, but he, when he was at home still, you know, he would hate going to dinner with us because he would say, all you're gonna do is talk about work and it is so boring, boring, boring, you know. And we do have these discussions. You can imagine how, you know, at the end of the day and we go under the cone of silence Right? And then we discuss maybe some challenges or problems that we're facing in our jobs and give each other ideas, you know, on how to resolve that. So from that perspective, it's really great.
But I would say that, you know, I'm going to say this about Zach because we were on our way home from school. We were ridesharing when he was a senior. And, you know, he was thinking about colleges and where he wanted to go and what he wanted to major in. And all of that. And he said to me one day, he goes, Mom, I want to do what you do.
Wow. And I was like so thrilled and proud of him. And so yeah, he's a computer engineering major now off at Seattle University, but hopefully he'll turn into an excellent security professional one day because that's really where, you know, he has set his sights. So if we can get more people excited about this profession. You guys did your job at home.
Yeah, well, we need to spread that around a little bit, but we wanted to end with that. Well, I would say, you know, one last question for you guys. What kind of advice would you have for someone who's looking to break into security who maybe doesn't have, doesn't have the baseline skills? What should they go after and learn? What would you tell your son?
You know, he wants to go after security. What have you told him, and what would you tell others who maybe want to do a career change and get into it? Well, can I just— this is a blast to the past. So when I first arrived in Denver, I was asked to be on a panel. Institute of Internal Auditors, the Denver chapter, had a panel.
They wanted an IT auditor on there. And so I went and volunteered to be the speaker, or one of the speakers. Several, and I had asked Gail, she was attending the event, I said, if nobody asks the question, how do I get into that profession, would you please ask it? And so they were getting down, it was the end, and there weren't any final questions, and so then Gail remembered her job. My job.
So she stood up and she asked, how does one get into IT auditing? I said, I'm so glad you asked that question. And so what I had prepared in advance was a nerd kit. And so I said, well, the first thing you got to do is you got to look the part. And so then I pulled out— had these eyeglasses that had the tape, you know, on the— over the nosepiece, you know.
So you got to put those on. You need a pocket protector, you know. Brought out the pocket protector and put the pens. You got to have that. And it was— anyway, the place, you know, one of those things you kind of had to be be there, but it was totally very, very funny.
But looking the part was part of the story. Anyway, they thought— her people at Gail's table thought she was privy to what I was gonna do, and she was not. She kind of discovered early on that they'd be very careful with me. But, you know, I think that to help somebody get into the profession, I think it's really I wish I had a good answer for that. I think that there's a way that you need to get people into it, but, you know, this is a hard job, and it's the hardest job I've ever had in security, and it can be incredibly stressful.
A lot of things are depending upon you making the right decision, and as you know, they say that a hacker's only got to be right once to get in, and from the protection side, you've always got to be right. And a bad decision on my part can be catastrophic. And so, I don't know, I think the challenge is there. It's very rewarding. I think when you see, you know, the ability that a business can continue to go forward and, you know, conduct its business, it's, you know, when you realize what's going against it, that's very rewarding.
So, yeah, there's a couple things I think if you're First of all, I think you have to have some background experience with technology, right? I mean, this is a technical business, so you have to have something. So, you know, either you go to school for that, or you've been a network administrator, or you're a system administrator, or something, right? You have to have some knowledge of technology. And then I find a lot of really good security people also are, you know, come out of the audit sector because they have a really strong knowledge of controls, IT controls, general controls, and so on, you know.
So the technology, the knowledge of controls, and sometimes you just— some of the best people in this business are people who just, you know, they— you have to have your, what we call the, your guys on hands on keyboards people who just love— they're inquisitive and they're just going to look and search for stuff, right? And they make your best investigators. And, you know, there's, to me, so there's a bunch of different skill sets, but clearly you have to have a passion for security. Once you get that passion, you'll be good at one of those aspects of the job. It takes different skill sets to do all those things.
So your auditor, your compliance person is not going to have the same skill set as your network security engineer versus your application security engineer versus your forensics analyst, but they all have some stuff in common, right? They're going to be inquisitive. They're going to understand whatever it is that they're analyzing. They have to know the ins and outs of that, the technical details of that, and curious and want to learn, I think, is probably top of the list there. Well, I guess, you know, closing up here, any final comments?
Anything else you want to shout out to the Denver community, the Colorado community? Oh, I think we just stay with it, get involved, participate, and share. Well, thank you very much, guys. You're welcome. Have a good one.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.