All episodes

Joe McComb, CISO at Janus Henderson

Apple Podcasts Spotify SoundCloud

In this episode:

Joe McComb, CISO at Janus Henderson is our feature guest this week. News from: In 'n Out, City of Boulder, Sparkfun, LogRhythm, Optiv, SecureSet, Ping Identity, Convercent and a lot more!

I'll take my double double animal style

Everyone's favorite California hamburger place may be coming to Colorado (just don't eat the fries... they aren't good). Colorado is working on some futuristic tech (JetBike anyone?). Colorado public sector starts thinking about security (Boulder asks private industry to help, the State creates a program for veterans, and the schools prep for ransoms). A local company creates an  Androit app to detect skimmers (hint: it's looking for bluetooth). LogRhythm features Sue Lapierre (Sue's going to be a guest on the podcast soon!). Optiv unveils their 10 tips for the holidays (and KKR might have an Optiv problem). SecureSet opens a campus outside Colorado (Florida, here we come). Ping Identity makes deploying to the cloud easy (especially AWS). Convercent tells you how to monitor your culture for sickness (check out the 3 KPIs).

Please come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Feature interview:

Joe McComb sat down with Robb this week to talk about how he got to run one the security program for of the biggest names in investing. Joe's background takes us through genetics, archeology, data analysis and a whole lot more. 

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12555 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 44 for the week of December 4th. Alex, this is our first time taking a week off from recording.

How are you recovering from not getting to do this? What do you mean, Robb? We had a podcast last week. I'm not sure exactly what you, you mean by that. Well, so Alex and I recorded the Thanksgiving podcast a little bit before so we could spend the holiday with our families.

What did you do for Thanksgiving, Alex? You know, we were actually here in town. We had some family come in, a couple of my uncles, my brother was here. It was a good time, just sort of relaxing, you know, spent a couple days cooking. Besides that, it was good.

How about you? Well, we ended up kind of last minute deciding to go to Glenwood Springs. We took my family and my wife's parents and spent the day in the springs. We found some caves near Rifle, you know, Rifle State Park, Rifle Falls, I guess it's called. Some caves.

The kids love going in the caves. We had a great time. Fun to explore a little bit of the state that we hadn't been in. Awesome. Yeah.

Well, let's go ahead and jump into the news. Reminder that we have a Slack channel and it's really become quite lively. There's, I think, about 90 people in the Slack channel right now. Um, this is a good place for you to come talk about what's going on in security. This last week we talked about that, that Mac flaw where you could, you could get into a root account with no password.

Uh, we call that zero-factor authentication, I believe. Uh, lots of talking about the, some of the interesting breaches we've had lately. Um, so anyway, go to the Slack channel. The, the link to join is in the show notes, and, uh, we'd be happy to have you there. I think even bigger news than our Slack channel is that In-N-Out Burger is finally coming to Colorado.

There have been rumors for years and years that eventually In-N-Out was going to come to Colorado, and now it's true. And they say North Colorado Springs, right? So they have purchased the land for the building. Yeah. So it sounded like they have land for a distribution center.

So they're going to set up their infrastructure and then also open a restaurant down there in the Springs and one at the same time or nearly the same time in Denver somewhere. So that should be exciting. What's your favorite In-N-Out order?

It's hard to say. I think the favorite one that I've ever seen, though, is the founder of Zappos in Las Vegas ordered like a 100 by 100 or something like that. You know, it's— I like a good hamburger. It doesn't really matter to me what's on it. I hope we can agree that their fries are not very good, though.

Like, the burgers are delicious. I agree. But the The fries are kind of— I think that, you know, there's different camps in terms of the fries. All right, we'll move along to a little bit more tech-related news. There is an article here in the show notes about some futuristic technologies that have come to Colorado and those that are still coming.

So it's not that many, so we'll go through them real quick. We talked about this one already, the real RoboCops, these security guard robots that folks have already created. Those are out now. But what I like even more is this, the Apollo jet bike. Yeah, that looks really cool.

It's, it's a bike that can go 100 miles an hour. And by the way, it flies, right? You know, flying cars. And there's a picture of it in the show notes if you want to take a look at this. Apparently, it's available right now for the low, low price of $279,000.

Which is either that or a Tesla Roadster, one or the other. Yeah, there you go. And then this thing that's coming out in the next year or so are these new ski lifts that have basically an entertainment screen on them. When I first saw it, I was like, oh my God, do we need yet another reason not to pay attention to people around us? But it was kind of interesting.

They'll show, you know, what the current state of the different ski slopes is, you know, where are any closures, what's the weather look like coming up, and of course advertisements, which we all need. Yeah, that's not nearly as exciting as a jet bike, but I guess it's definitely a step forward. Yeah, a few more things that are on the coming soon. They mentioned the Hyperloop, which we've talked about quite a bit. Some new satellites from Lockheed.

And then interestingly enough, invisible TV screens. Yeah. So when they're not turned on, you see right through them. I like it. Hopefully you don't have anything dirty behind the TV.

Hopefully you can just paste that to the wall and then, you know, put a piece of art behind it or something, right? So when the TV's off, you get a nice piece of artwork. Next, the city of Boulder, they are looking for a startup in residence. So essentially, You know, Boulder being a great startup culture up there, the city of Boulder has some stuff that they would like to get done, and they're sort of putting proposals out essentially to have startups come in and help with it. Yeah, and I don't— I think it maybe is for free that they're asking for help.

I'm not sure about that, but they have 3 problems they're looking to solve, right? They're not all that complex either. They're looking to solve an open data PDF converter, basically something that can convert PDFs on city websites into more easily accessible open data. They're looking for someone to help improve the council correspondence process so they can enhance responsiveness to residents. And they're looking for someone to help automating their accounts payable process by developing a solution that improves the city's finance team's ability to, to process tasks and analyze spending.

So basically some, some solved problems here, it sounds to me. Yeah, for sure. Uh, next, uh, we had an article that talked about states looking for cybersecurity workers, essentially. So, um, programs that are being put in to help build that next generation of workers. And as part of that, they highlighted Colorado, and the state has a $900,000-ish program to do internships for veterans, which I think is really cool.

And they have some quotes from our friend Debbi Blyth, the CISO for the state of Colorado. Talking about, you know, why these are kind of ideal folks to have bring into security, as they've obviously shown a commitment to protecting the infrastructure and they have some tenure and longevity in a position. Yeah, I was actually talking to Debbie and she mentioned this program. It was funny. She said, you know, I was going in there pitching for interns for, you know, a bunch of different things.

And I said veterans right out of the bat. And they were like, that's fine, approved. Yeah, go ahead. No one wants to say no to veterans, right? That's right.

Uh, so next story for us is that Colorado schools have been preparing for cyber ransom attacks. They're running some simulations and some exercises because apparently the bad guys are now targeting schools pretty heavily. Uh, and there's been some schools where, you know, they get into the systems and they, they threaten to either delete or release sensitive data, or actually terribly, they've, they threatened to hurt children if you don't pay money after, you know, after getting control of video cameras. They've made some of these threats. Yeah, this, I think it came from an event.

What was it in Montana? I believe, you know where this happened. So I think education is finally on notice that they've got they're in the crosshairs now too.

There next, a Colorado company created an app that you can use to detect credit card skimmers at gas stations. Yeah, so this is SparkFun, and we talked about SparkFun already. They're the same company that did that. That robot that could break combinations on safes, right? Yeah, I think they presented that at DEF CON over the summer.

So this is a new, it's an Android-only app, and I'm just telling you, if you have an Android, go take a look at this app. What it does is it'll search for Bluetooth near your phone, and it'll look for that Bluetooth signal that skimmers at a gas station or wherever you're gonna pay would be exhibiting. So hopefully you know about the Bluetooth, and you can report it before you put your credit card in there. Right, so this is sort of the next phase for these skimmers, right? It used to be, you know, they'd put them in there and they'd have to come back and collect them at some point, right?

Because it would save credit card numbers onto, you know, some memory chip or something like that. Well, then they added Bluetooth, and now since that would be out there beaconing, this app can detect it. Pretty cool idea, and glad to see that that's coming out of Colorado. The next article is a blog post from LogRhythm with an interview with Sue Lapierre. Sue is the CISO at Prologis.

It's a short little talk about why she enjoys her job, what Prologis does, And it's a nice profile in one of the Women in Security. Sue is also going to be one of our featured guests. So we have interviewed— we've recorded the interview. It's going to be a few more weeks before it's posted though. Next, Optiv put out a blog this week about 10 tips for businesses to optimize security programs during the 2017 holiday season.

So reading this, I don't know that I would necessarily say it's 10 tips for security programs, but it's, you know, some good tips. I think more aimed towards non-security folks or small businesses. There's definitely some good stuff in there, a lot of straightforward things, but definitely things that you should think about. One of them being, hey, maybe you should start getting prepared for all of these new devices that are going to be coming into your organization after everybody gets them for Christmas. Yeah, right.

So yeah, go ahead and check that out. Some good info in there.

Next, another Optiv article. This actually was in a website called The Information. You know, Optiv was purchased this past year by KKR, private equity firm, private equity firm for $2 billion. And the article talks a little bit about, you know, some of the hurdles that Optiv has been trying to get over as part of that acquisition, potentially some problems with meeting sales figures. Dan Burns, the CEO, has been put in charge.

Tim Hoffman, their former operational leader, had stepped down. There had been some layoffs at Optiv. It sounds like it's been a little bit of a rough road for them trying to make the transition from where they were into what KKR wants them to be. So hopefully Optiv can get back on its feet. I'm sure they are still doing fine.

They're a, you know, a giant in the security industry, but looks like maybe not exactly smooth sailing over there. Well, sorry, we don't actually have a link for— we haven't seen it covered in any press— is around CyberGRX. They had some layoffs here in the last couple weeks. Rumor was somewhere in the ballpark of 20 employees, and considering the size of the company, that's a pretty big number. I would say it's not too surprising when you get these small vendor startups that You know, they get the funding, they go after it, they ramp up quickly.

If sales— if the sales trajectory doesn't match with the projections, then, you know, you have to pull back on that spending to make the, you know, to manage your burn rate on that investment. So not a big surprise, but kind of a bit of bad news to hear for the local CyberGRX. Yeah, too bad. I hope everything's good over there. We like those guys.

Next, SecureSet announced that they are now open at their Tampa location. So they've been expanding Um, you know, obviously started here in, in Denver. There's a Springs location. Um, now you've got a location out in Florida too. Pretty cool.

And, and that's another opportunity that a local company is growing, doing really well. Um, you know, Brett Fund's another, uh, upcoming feature interview on the show. Um, he's, he's the, uh, founder and CEO over there at Secure Site Academy. They're doing a good job and looking forward to seeing them continue to grow. Next is a little bit of news about Ping Identity where I work.

Ping— this is actually one of the, one of the more fun pieces of news we've had lately. Ping has historically been a software-based company. About 5 years ago moved to offering a SaaS version of the product. What we've really seen at Ping is this need for the high complexity that you get with installed software and the ability to customize to your environment, but doing it in the cloud. So Ping is— this new announcement is a really simple deployment of all Ping software, or excuse me, some of Ping software into the cloud, especially into AWS, making it easy for companies to have that customizability, but also taking advantage of the cloud scalability and cost.

I sure hope that the security guys over there at Ping are making, uh, those cloud deployments secure for everybody. As secure as the cloud can be, yes. Uh, next we had an article from, uh, Conversant. We've talked about them before. They do, um, compliance and ethics training.

Um, I think this actually was probably my favorite article of the week. It's titled Monitor Culture Like a KPI: 3 Indicators That Your Culture Is Secretly Sick. And they're talking about culture in general, but I could see where some of these might apply to security directly as well. So the first one being reports of bad behavior decline. And normally you might think, oh, well, that's good.

There's no more bad behavior. But the indication there being that things have just sort of gone underground. No one's reporting bad behavior anymore. Um, and this is so relevant, you know, especially right now with, uh, you know, obviously there's been the Uber issues with reporting and Yahoo before that where maybe there's a cultural aspect, but then the other side of it is all the sexual harassment, sexual assault that we've seen across every industry. This is really in the wheelhouse of what Conversant works on, and I'm sure been a big driver for their business lately.

Yeah, the second one, um, everyone's anonymous. You know, again, if people are scared to report things or they don't want to put their name on stuff, maybe you have a problem. And then third, every ethics conversation happens in a conference room, you know. So when this is not part of your culture, when it's something forced, say from HR or somebody like that, or from legal, then, then maybe you do have a culture problem. And again, I could see you replacing ethics or other things with security here, you know.

If all of your security conversations are your formalized you know, security training for the year, and there's not conversations outside of that, you know, maybe you need to work on that security culture. And another, another thought would be, you know, if every conversation is let— is started by a security team member, right? Right. If we don't have other folks in the company who are thinking about security and asking those questions, that's, that's a good indication that it's not a healthy security culture. Exactly.

Last story of the week, yet another, another one without a link associated, but Former guest John Everson, CISO from Dish Networks, will no longer be the CISO for Dish Networks very soon. John has, uh, has moved on to work for a company called, uh, Affinity, who does, um, matching for call centers. And, and really it's a startup and he's gonna have a different kind of a role going from, you know, a Fortune 200 company here in Denver to a company that's headquartered out of state, but he'll still be here local with us. Yeah, congratulations to John. Um, I think it's a good move for him.

Sounds like it's going to be a fun time in his new place. And while it's not posted yet, DISH is going to be looking to backfill him. Obviously, they can't get somebody as good as him, but hopefully they can get someone who can, who can carry the water. He was nominated for CISO of the Year this year. So, you know, one of our finalists, theoretically one of the top 3 CISOs in Colorado.

Absolutely. Congrats to John for that, that move. So let's move on to trivia. So our previous trivia question, you know, we didn't have one for the Thanksgiving show. But that was, whose mission is it to support and promote statewide emergency preparedness, disaster response, and mutual aid assistance for public and private water and wastewater utilities?

So the answer for that is CoWARN, C-O-W-A-R-N. It's, it's a statewide water wastewater agency really responsible for, for keeping our water and wastewater safe. Really interesting stuff. And this is a— there's a national program behind this. Congratulations to Aaron Lafferty, who who was the first to respond with the correct answer on this.

Aaron has got himself a nice piece of Colorado Equal Security swag. Very good. We have our, our next question. So those of you ready, this one should go pretty fast. If you don't, you don't have to know a lot.

You just have to be willing to do a little bit of research here. What is the least expensive item in the Colorado Equal Security store? Hmm, I'm gonna go with, with the thong. I know you go with the thong on a regular basis. Yes.

Just do remember that there are 2 sides to the store. There's this side where we have the horizontal logo and the vertical logo. And so, you know, you could make a mistake. Be sure to check both. All right.

So let's move on to events. Again, as always, please make sure to check out the event calendar on the website. We try to keep that updated with all the stuff that's going on. And we're now loaded up till— there's events all the way out into May with Rocky Mountain Information Security Conference. We've got a lot of stuff in January as well.

Awesome. First, CitySec is doing their South meetup on December 4th. The CTA has their C-level volunteer kickoff on the 7th. ISSA Colorado Springs is doing their awards banquet on the 7th of December. You got to be a member of the chapter to attend this, but it looks like it should be a fun event, kind of a holiday celebration, I think.

SecureSet has a capture the flag event on the 8th. CSA is doing a CCSK training on— also on the 8th. And that's a paid training that you wanna sign up for in advance. So if you haven't signed up yet, don't dawdle. This is the time to do it.

On the 13th, the CTA has their CTA 101 event where you get to learn about CTA, meet who the people are, and see how you can get involved. On the 14th, ISSA and ISACA have their annual joint meeting at Comedy Works. This is always a big event every year. It's a really fun time. You know, until last year it was always at the Wine Coop downtown, and we moved down to the Comedy Works.

Still brought the booze with us, a couple of really good speakers, hopefully a lot of fun. So a good chance to get to meet a lot of interesting folks in the community. Great networking opportunity. And if you are an ISACA member, there's a cost, and if you're an ISSA member, there's not. So there you go, huh?

Sorry, ISACA guys. And then finally, also on the 14th, CTA is doing their legislative outlook meeting. So this is, you know, meeting with potentially with legislators and other things like that about what's coming up for the, the coming year. Yeah. All right, let's jump over it.

Well, I'll say a couple of things coming up in the future. Be thinking about SnowFROC. That is the OWASP Denver big annual event. It is scheduled for May 8th— excuse me, March 8th. March 8th, and you can start looking at that.

And if you have a talk for it, submit that. Speaking of talks, RMISC call for papers is open. We're looking for people to submit talks for that. If you have any, especially any case studies, anything you've implemented at your job, we would love to hear, hey, I tried to implement DLP and here's how it went well and here's how it went poorly, or whatever it is you've done. We'd love to hear about it.

Yeah, and for that CFP, all you really need to have to be able to submit is your title and abstract and what people are going to learn. You don't necessarily have to have the talk done yet, right? So if you've got some good ideas and feel like you can put it together by May, then I'd say go ahead and submit. Submit early, submit often. Also on that same front, we are looking for sponsors for Rocky Mountain Information Security Conference.

So you can check out the website rmisc.org for that. And we're actually doing attendee registration a little bit differently this year. In the past, we have waited until all of the content was ready, we had all the speakers in place before we opened up registration. This year, we've opened it up early, so right now, if you wanted to attend, you could go out and register right now. You're not going to see in the past, like in the past where we had the different tracks and everything all set up.

If maybe you have some budget open at the end of this year and want to get it in for 2017 instead of 2018, Baby, go ahead and take a look at that. Sounds good. All right, let's jump over to jobs. We've got a CISO job open. We've got the Chief Security Officer at Dominion Voting Systems, which is headquartered here in Denver.

Yeah, I hadn't heard of them before, but looks like it could be very interesting. Cognizant is looking for a Senior Manager of Corporate Security Engineer. There you go. CHI, Catholic Health Initiatives, is hiring a Manager of IT Security Risk. BioScript is looking for an IT security operations manager.

A lot of leadership roles this week, huh? Yeah. Reuben Brown is hiring a senior auditor for information technology. The city of Broomfield is looking for an IT security analyst. And Chipotle is hiring an IT security threat analyst.

So it sounds like a tasty job. If you want free burritos, go check that one out. All right. Well, that takes us to the end of our news for this week. Our feature interview is with Joe McComb.

Joe is the CISO for Janus Henderson. He's been in Colorado for a long time. You know Joe, right? I know Joe. Yeah, Joe's a good guy.

Yeah, good stuff. We talked a lot about his background, which is not what one might expect. He does not have a degree in computer science or information technology or even music. Not even music. No, he's the— what did he call it?

The genetic anthropologist, basically looking at the history of genetics over time. Yeah, it's amazing. That sounds pretty cool. Yeah, archaeologist, genetic archaeologist. I don't know, whatever.

It's really interesting. Take a listen, and hopefully if you get a chance to meet Joe, recommend you guys say hi to him. Sounds good. All right, guys, have a great week. Thanks, Robb.

Hello, this is Stanton Meyer, CSO of Cobank. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

All right, this is Robb Reck, and today I have the distinct pleasure of getting to interview one of my friends, the, the global CISO for Janus Henderson, Joe McComb. Joe, the, the thing I'm most looking forward to from you today is really getting some stock tips. So as I know, Janus is one of the big investment firms in the world. What are 3 or 4 stocks that I should sink all of my money into? Okay, so I actually briefed Robb earlier on this.

I can't say anything about trading. Or any of the companies we trade in or anything else. Compliance has made that perfectly clear that I can say nothing about that. So should I buy Bitcoin? I can't say.

Yeah. So I do like to give Joe just a little bit of a hard time, and that's a good way to start the interview. Joe, first of all, congratulations on the kind of the naming of yourself as the global CISO for the new company. I think it'd be a nice place to start by just talking about You know, Janus, which is a name I think most of the listeners have probably heard for the last 40 years. Yeah, a long time.

Most of our lives. It's no longer Janus, right? Could you talk about that a little bit? Yeah. So basically what happened is we merged with another financial and active manager in the UK.

A lot of that is really around market share that if you look at it, they had a huge number of assets under management in the UK. We had a huge number of assets under management in the US. Uh, when you look at the direction they were moving, they were moving into the Asia-Pacific, that area, also South America. We were also moving the same direction. It made a lot of sense strategically to combine the 2 companies.

A lot of synergy in that respect. So true, true to say, Janus was headquartered in Denver, is that right? Cherry Creek, right? Yep, absolutely. And, and Henderson was headquartered in London?

London, yep. And now we're headquartered in London. Yeah. Um, so yeah, I will be flying out there and Well, okay, I want to reveal what time, but fairly soon. But the global CISO is here in Denver, which is pretty awesome.

Is your team distributed between— Yeah, UK and here. The team that Henderson had was a lot smaller than the team that you saw in the US, and they were really beginning to grow in size. And so kind of one of the advantages they got with the merger is they got some synergy around that, the fact that they didn't need to, you suddenly add a US team or something similar. Yeah, we were much larger. The CIO is also located in Denver, so you see kind of the major information technology presence is all located in Denver.

Okay, well, let's back way up. All right, so I assume that from day one you were always a security person, right? And you went to college and got your security security degree and so forth. Is that true? No.

No? No, not at all. What'd you study? Boy, that's a long story. Okay, so undergrad was chemistry, of course CU Boulder, you know, had to be a Colorado school.

Go Buffs. And I also got an anthropology major in that, then I combined the two. Chemistry and anthropology, that's kind of a strange mix, right? Yeah, that seems kind of crazy, right? A little bit.

Human population genetics, it's all that cool stuff you see on TV along with Um, all the stuff that you see on CSI. Um, so after I got that degree, I said, okay, I'm going to combine these 2, whereas everybody else I knew was going to med school and they thought I was crazy going into anthropology. And I said, I'm gonna, I'm gonna go into anthropological genetics. It's gonna be great. Um, boy.

Um, and so I went to the University of Kansas, um, and started studying anthropological genetics. And I was what you'd call classically trained. There's, uh, 4 primary fields in anthropology. There's linguistics, sociocultural, archaeology, and there's physical. And I was trained in all those fields, trained also in what you'd call forensics now.

So I had a whole class on osteology. What's osteology? Study bones, how to identify. Yeah, it was great. You sit there and you work through— you'd work through— if you had a bone that somebody handed you or a fragment, you'd sit there and you work through, okay, which side is it from?

What part? Is it human or non-human? If it's a tooth, you know, upper, lower, adult, you know, the like. And that field is kind of coming to popularity now in terms of that everybody watches the crime shows and you have this forensic pathologist, right? Or somebody similar to that.

And then you also have this whole area of DNA fingerprinting. I was also, you know, trained in DNA fingerprinting from paternity lab. And if you look at all— Paternity lab means you're going to find out who the father is? Exactly. Yeah.

Yeah. But I mean, they had a forensic cape. Cases too. Did you work on Jerry Springer? No, no.

Oh boy, that— and that's a really— chance. I got it. That's a really seedy— no. And that kind of, kind of swayed me into why I ended up going more IT. So for a while there, I was— I'd gotten a PhD and I was being courted by— okay, I won't say what organization, but it was basically to run a forensics lab.

And, you know, we're talking about this and I said, okay, so how much are we talking per year? And they said $17,000. So $17K a year. Yeah, in 1999. '99?

Yeah, so think about that. So that's not great. No, that's not great. There's this dot-com boom. Yeah.

And meanwhile, I've been putting myself through school doing, you know, what everybody else has been doing, you know, the help desk. Yeah. You know, service desk work, AV, you know, web development, things like that. 'Cause that paid fairly well. And that's almost minimum wage.

It's not too much more than minimum wage. Exactly, exactly. And then there's this big dot-com boom and everybody's like, you know how to code HTML? Like, yeah, of course, who doesn't? JavaScript?

Yeah, absolutely. Java? Yeah, absolutely. And then all of a sudden they're like, hey, you're hired. And we remember that whole boom, right?

That whole boom period. Yeah. And that brings me to a pharmaceutical company called Merck. And I worked there for about 6 and a half years. It was server administration and then This is the fun part.

So about 15 years ago, they said, what do you want to do next? And I said, there's a security position that somebody, you know, nobody seems to want to fill. I said, I've always wanted to do security. You know, I love, you know, like trying to break into systems. This is great.

And so they came back and asked me about a week later, do you really want to go to the security position? I was like, yeah, this sounds really cool. They're like, you're totally certain you want to go into security? Yeah, we got to put that in perspective. This is, you know, 2002.

Yeah, yeah, and we remember those, that era. Sarbanes-Oxley was coming around, coming around, and it was either there or coming around. Yeah, and Senate Bill 1386, so California just released that, you know, their first, you know, that you must report breaches, data breach stuff. Yeah, exactly. But for the most part, everybody, you know, this was like that field where it was kind of the dumping ground and people just didn't, didn't like it.

And so I think it's funny, you know, when you see postings for like, you 15 years of security experience and must have a PhD. And I'm like, come on, you know, people, people back then, we, you know, you got the people that really, really, really wanted to do this because, you know, nobody else was really— there wasn't a lot of defenders at that point. There was, there was the people who were hacking. Yeah. And then there was like, yeah, there was sysadmins who as a side thing would also try and stop the bad guys, right?

I'm gonna try and get the system set up and maybe I'll lock it down at the same time. Probably not. Yeah, that was exactly it, you know. Yeah, and you know, I was kind of this crazy guy who like, it's like, this is great. I'm gonna set up this Nessus server because I'm a server admin and I've got the resources to do this.

So, you know, I set up the Nessus box scanning, you know, then I go talk to the— I was like a divisional security administrator and I go talk to the corporate security team and they're like, wow, this is really cool. How do you do this? Because, you know, you're right. I mean, they were kind of access and administration and policy. Yeah, you know, that was what they did.

Not security engineering, security architecture. Not at all. And, you know, and so, so things like, you know, network worms which were coming through, you know, we'd see Sasser and all these other pieces. Yeah, Code Red, Slammer. Yeah, Slammer, exactly.

Remember when all those were hitting? Yeah. And so I'm the guy that's like reading the logs and I'm like, okay, I can see this. And they're like, great, can you tell us what's going on? I'm like, you know, I'm, I'm your regional guy.

Yeah, you know, it's like Yeah, that's how you get to do new stuff though, right? Yeah, and I admit it was a blast. Yeah. So you said 6 years doing that at Merck. Did you move around or were you doing the security stuff the whole time?

So yeah, so for about 2 years I was doing web development server admin and then what, 4 and a half years I was doing security stuff. And it's kind of funny too because I was one of those people that basically said, okay, when I get my CISSP, not to put other people on the spot here, But I'm actually gonna get the requisite amount of education, you know, time, sorry, time spent on the job. That's what I'm trying to say. Oh, the 5 years? Yeah, the 5 years.

Yeah, exactly. Or with college degree, like 4. So, so literally right when I got that was when I went and took the test and bang, CISSP, and went from there. Big times, right? Yeah, absolutely.

What year did you get your CISSP? 2005. That's really early. Yeah, absolutely. It's early.

Yeah, New York City. I'll never forget that and Ironically, like, there was one of the people that was proctoring it, he like sends me a note literally 4 weeks later. He's like, did you get it? I was like, yeah. He's like, do you want to come and interview with us?

Yeah, I mean, like that. It was just kind of funny. So did you end up— it sounds like you ended up changing jobs shortly after you got it. Yeah, I did. So 2006, and what happened then is there was this little thing called Vioxx.

So I worked for this pharmaceutical company called Merck, and Vioxx hit, and basically pharmaceuticals took a hit. What's Vioxx? Vioxx was what's called a COX-2 inhibitor. What that means is it's, it's used to control pain, typically for arthritis. Yeah.

And so what we learned about Vioxx was that it doubled the rate of heart attacks, basically. Yeah, so it gets pulled off the market. Um, there's one COX-2 inhibitor, um, Pfizer still has it, Celebrex, that's still on the market. Um, it's what's called a black box drug, which means— so, okay, quick lesson in pharmaceuticals. Yep.

If you hear the term black box drug, what it means is when you look at things that are bad that can happen to you, there's a little black box around it. The black box basically means that really bad things can happen to you, like death, right, cancer, you know, things like that. Yeah. Um, and so the side effects are potentially life-altering. Yes, exactly, life-altering.

And so it was a black box drug. So Merck stock took a hit. Um, there was a huge series of layoffs after that. I watched a lot of my friends get laid off, but not in the security field. Um, you know, I kept being told, yeah, you know, you're, you know, you're important and valuable.

And after about the 4th round, I said to myself, you know, life is really short. Why don't I go back to Colorado? That's, you know, I grew up, I grew up in Fort Collins, um, you know, and I just missed this lifestyle. And so I started looking for jobs out here, yeah, um, and, you know, that really set it. And I, uh, ended up at Policy Studies, uh, for 2 and a half years.

Interesting. Um, have you heard of Policy Studies? I have, yeah, they're over by the ballpark, right? Yep, yep, yep, absolutely. I've known a few— now I can't— names are escaping me.

I've known a few other folks there over the years. Yeah, Dan Collander. Yeah, Dan was there. Yeah, who's a ball now. Um, Sue Lapierre.

Yeah, over at Prologis. Yeah, absolutely. Sue was Sue was my former boss. So it was spitting out CISOs over there. Exactly, it was spitting out CISOs.

Yeah, and it's ironic. So it's true, right? Yeah. I mean, because yeah, you get Marlene VM who's at Oracle. Oh yeah.

Actually, she may have changed her last name now. You get Sue who— I think Marlene left Denver too. I think she moved up to Portland or something. That makes sense. Interesting.

Yeah, and then you get Sue who's very active in the community right now. You get Dan Collander. Yeah. And then yeah, I went to Janice. So how long were you at Policy Studies?

2 and a half years. Okay. Yeah, I learned a ton at Policy Studies. So is that 2007 to 2009 timeframe? Yeah, 2006, right at the end, to 2009.

You got it exactly. Yeah. So I was working under Dan Kollender at the time. Yeah. Really, really good team.

You know, really enjoyed the time there. You know, we were— the best way to say it— a little underfunded. But yeah, I mean, that happens in security. But, you know, when you look at it, I learned a ton in policy studies. Yeah, absolutely.

And then I was tapped to go work at Janus, you know, in 2009. So what were you hired into Janus as? Manager, to basically manage the access control area, to manage kind of the project security, you know, basically guiding new projects that are coming in through the security reviews of projects. Yeah, exactly. Pieces like that.

SAP security for Sarbanes-Oxley because that was the primary financial accounting system.

Some other pieces, a little bit about the vulnerability management, that piece. Do you want to kind of continue? Yeah, that's great. So when you were hired, tell me about the Janus security team. We're talking 2009, year 1 of how many, and how did that structure look?

Yeah, so I go in, I So I had 5 direct reports when I entered. The security team had a director and he had 3 reports, oh, 4 reports including me under him. So that's 10 total. Okay. All across the board.

Yeah, relatively larger team. And how many people worked at Janus at the time? At the time it was what, 1,300, around there. Well, that's a really big security team for a 1,300-person company. Absolutely.

Yeah, yeah, that's good investment. Yeah, it was. Yeah, and part of that was because the CIO at the time had gone through breaches at other companies. Sure. And so he realized the value of this.

Okay. And so he just said, okay, so I'm gonna build up the security team a little more because I don't want to have that happen to me again. Yeah. Do you guys have a lot of stuff worth protecting? Oh, absolutely.

Yeah. Okay, so talk us through. You were hired in as a manager over IAM projects and so forth, and And, you know, 8 years later, what's happened over the last 8 years? So then a couple years later, new management came in, actually reduced the size of the security team a little bit, another way to say that, and then tapped me to run the broad security team. So my boss, a wonderful man named Randy Carmichael, he's deceased by the way, yeah, he at the time when the new management came in said, okay, so, you know, I'm I've been here for 14 years, I'm going to move on.

He left and then I got tapped for his role. So I took on the whole vulnerability management team, including the penetration testing, that kind of piece of it, managing, writing up findings around patches, policy, all the things that you consider classical information security. So 2011 timeframe we're talking about? 2011. You were Director of Information Security?

The title? No, they did a trial period. They just gave you the work but not the title? Yes, exactly. They did a trial period, so I was still a manager for— it was kind of the funny, you know, usual trial period that you get, you know.

It's like I was a manager for, I don't know, like a year and a half, 2 years, around there. Yeah, I think it was about a year and a half, and they finally said, okay, so we need to promote, you know, promote you. And it was kind of funny because one of the things that I did is I changed the focus of the team then. So, and this is the thing that we've all started doing during that period. We said, okay, so it's not if we're gonna get breached, it's kind of more of a when and what we do about it, right?

And so at the time, we were heavily reliant on preventative controls. And so I said, okay, so what we're gonna do is we're gonna change to a monitoring posture. There was this incredible guy that worked for me. Oh, I can mention him, Todd Garrison. Yeah, so who has recently left my team, unfortunately.

Yeah, it's a bigger loss. Was it Ty or Todd? Todd. Todd Garrison? Yeah, exactly.

Hi, Todd. Fantastic guy. Yeah, brilliant. And so he and I began transforming the team. We said, okay, so what we're gonna do instead is we're gonna adopt more of a monitoring posture.

And, you know, I'll never forget, so we went to management and we said, okay, so we want to free up money for a SIEM, and we also want to put in more IDS. We've got barely any kind of IDS support. Yeah. And so I can mention products, right? Sure.

Cool. Good, good, good. Yeah, so especially if you have bad things to say about them, that's the most fun. Yeah, well, I have good things to say about FireEye. So yeah, so we brought in FireEye.

Yeah. And, you know, fantastic. I remember the first time we stuck in FireEye, and they always say, you know, you stick it in and people like run run in terror. We stuck in it and nothing happened for like days. And, you know, I kept asking Todd, I was like, you know, what's going on with this?

And he's like, you know, we've done the test, we've done everything else. And then on about the 3rd day, somebody hit an exploit kit. Yeah. And we're like, this works, this is great, this is what we've been looking for, you know. So, you know, FireEye kind of rolled out, rolled out the SIEM, and then we began, you know, I said, okay, so what we're gonna do from here is Um, and people ask me, they say, okay, so you were— you did all this anthropological work, how does this relate to anything, right?

And so, um, when you start going through all the work that I did in anthropology— so I did DNA fingerprinting, yeah, and the purpose of that was to look at human populations. So can I just real quick, for those who are not watching, yes, those who are listening, yeah, Joe just pulled out a book which is his— is it dissertation or thesis? So this one's the dissertation, this is the thesis. Yeah, and you're— Robb, you're actually the first person I that gets to see this. Most people don't usually get to see this anymore.

So I'm now holding a bound book showing the cluster analysis of populations using the RAPD frequencies. Yes, exactly. So we're basically talking about looking at populations and how they're genetically related, right? And so when you think about this, what you're looking at is you're looking at this big data set of a bunch of stuff, and you're trying to figure out who's related to who, and you're looking for anomalies. And that, that's a lot of what my work, you know, what I did during that period.

Um, the master's is much more interesting, I'll tell you that one, because this one looks at Native Americans and kind of how all that relates together with the Siberians and pieces like that. Yeah. Um, yeah, you see, you see these, these frequency charts along here, right? Yeah, higher and lower. And if you think about this, if you're thinking data analysis is what we're looking at, that's exactly frequency analysis.

Yeah, you're looking at frequency analysis and data analysis and how do you, how How do you parallel that out? It's the same thing. We're getting a bunch of data in logs and we're trying to figure out how do we represent this in meaningful ways, one, to help defend our company, and then two, when we're talking to management, what does this mean? Are we doing well in terms of security or are we doing poorly?

We start getting these FireEye results in. Of course, what do I do? I start quantifying that. One of the first things we figure out is we're like, wow, 50% of the compromises that we see are Java-based. And, you know, because we see it, we detect it, we pull it, wipe the machine entirely, start over.

Okay. And so our realization there is, what's going on outside the company? And there's a really good paper by Microsoft. It's— what is it? Data-Driven Security Defense, 2015.

Big subscriber to that paper. So looking at your environment and saying, what are the attacks that we see that are coming in and what can we do around that? So, you know, first thing you do in that case is you basically change how you're patching Java, which we did. We heavily improved that. You look at how exploit kits are being developed and kind of the time that it takes from when you see an Adobe Flash vulnerability to when it actually gets posted.

And you actually gauge your patching time off of that and you change the patch priorities based off of that. And so we began pulling in our metrics program and developing according to that, including changes in the firewall, changes to executables coming down. For example, not to pick on the Russians, but I will a little bit here. So one of my analysts who I won't mention the name because I don't want to be poaching him, Did a fantastic job. He did this analysis where he looked at the exploit kits we were getting hit by and geographically where those were located.

And at the time, 50 to 60% were all former Soviet states. And so it's funny because, you know, I would talk to management out there like, oh yeah, the Russians are coming after us. Like, no, this is bulletproof hosting. This is what it is. It's hosting facilities that nobody asks any questions, right?

And And so, you know, they don't care. So of course, that's a great place to, you know, put up any attack. Yeah, launch your attack. Absolutely. It's fantastic.

I mean, here, here, also California is on our list. We block California. Exactly right. You know, and, and so what we did is we modified our firewall rules because we don't do a huge amount of business with Russia. And we said, okay, if it's an unclassified site coming in from Russia, let's block that.

Yeah. Yeah. And that heavily dropped the alerts that we were seeing coming in from exploit kits from that area. That's great. Yeah, absolutely.

So yeah, so the way that this all relates is, you know, my primary focus was statistics and analytics, really. And so, you know, I brought that into the company to say, okay, so let's look at this statistically and then say, how can we reduce, you know, prevent attacks but continue monitoring what's going on in the environment? And, you know, we've seen attack trends, you know, change dramatically. Yeah. I mean, if I were to ask you about ransomware in, uh, let's say 2000, you'd say, what?

Yeah. And I'd say 2010, you'd say, uh, well, maybe rogue AV, you know, what is that, right? You know, maybe. But 2 years ago, I said ransomware, you're like, oh yeah, I know about that now, right? And we've seen that pattern heavily shift.

Yeah. And I actually have a wonderful graph that shows that. You know, I say, okay, We were, you know, $40 for Rogue AV, and what did we do if we saw, you know, Rogue AV infection? Wipe the machine, done, right? Whereas now, you know, you see, you know, the newer stuff.

WannaCry, we haven't seen. We've seen other types of ransomware, mainly blocked, which is good. But, you know, when you go to that kind of level, you realize that if somebody's getting paid $200, $400 for, you know, Bitcoin for that, of course there's incentive to continue on like that. Looking at the tax returns. Let's move forward a little bit in your time at Janus.

You, 2013-ish, is that when you got the official promotion? Yeah. And where were you reporting at that time? I was reporting into operational risk. Okay.

Yeah, kind of unusual. Is that the people who do like the financial risk, strategic risk for the company? Or what's operational risk? Yeah, so what operational risk did specifically is they had business continuity, data protection, under them, a true operational risk field. So looking at processes within the company and how those might go wrong, how they might affect stuff.

A little bit of investment risk goes into that area. Quality, the quality too? Quality was there, absolutely. Yeah, yep, QA was actually part of that area, you know, big, big focus on process analysis. And they were under the operations area, so Chief Operations Officer, and there's kind of 2 different areas if you to look at it, there was CTO and there was the operational risk area.

And so kind of fast forward, set of management changes again, and I was moved into the IT area under the CIO. And when was that? That was 2016. Okay. Yeah, so just last year.

Just last year you moved to report to the CIO directly? Yep, exactly. And then when did you get the title? The actual CISO title? Beginning of this year.

And that was just basically as a part of the merger, um, we're ready to recognize this position as a, as kind of being a higher-level executive. Yeah, yeah. And, you know, kind of to that point, I had been doing the CISO work, and, you know, a lot of other people out there will appreciate this, for a long time. Yeah. Um, you know, 2016 was, was really the first time that I was really beginning to speak to boards, um, in that regard.

Um, so there was, there was part of that. Um, I've been doing, you know, managing the security program, you know, for years prior to that, and I consolidated. So there was, there's some restructuring. I consolidated the security areas into my area from there, and then, yeah, it was, it was 2017 when it actually— Has the, has the change of title made a difference for you in terms of internal— well, ask 2 different ways. Yeah, inside Janus Henderson, has it made difference for you?

Yeah, that's a hard one to answer. In part, yes.

I think there's more recognition really outside of the company around the title. Yeah, I remember going to this one session one time with E&Y, and they said, we want you on this panel. I'm like, great. And so they went through and they're like, this CISO of this, this is CISO of this, this is the CISO of this. They get to me and they're like, and you're— I'm like, security guy, just call me the security guy.

Yeah, you know, half jokingly. Um, and for me, the recognition outside has, has increased. Internally, there's been some effect, but really, you know, my, my influence was always more metric-driven, you know, in talking about, you know, how these are the threats operate, um, this is what I'm seeing, these are my recommendations. You know, it's like if, you know, my team also does contract analysis, which makes sense, and, you know, you'll appreciate this and other people on the board, where we have a set of security requirements that we embed in contracts. And you will inevitably get some vendor that'll say, I refuse, I will not do any of this.

And that's where my job is to go to the business and say, you know, the data that you've got here is either a low risk or it's a high risk, and they're absolutely refusing to adhere to any kind of security contract language. And then of course ask me, well, okay, so did you do due diligence? I'll say yes, you know, we went through, we did, you know, a checklist. Um, usually it's about 20 questions, it's not that big. And then I can say I can give you an idea on paper where that risk lies.

Ultimately, you know, there's— the decision is going to be hitting you because you're going to be accepting this risk, you know, one way or another. Yeah. Um, so my influence was always kind of driven from those metrics. So I'm interested in just digging into that particular situation a little bit more because this— I'm sure many of us experience that same type of conversation. And, you know, I've, I've always been the kind of guy like, hey, I'm here to enable the business.

I'm here to— absolutely, I'm here to inform them about what— about it so they can make their own risk decisions. But my experience after doing this for, you know, 10+ years is they don't— they really want me to give— to guide them to one answer. They want a recommendation. They want a recommend— they don't want me to say, here's the risk, what's your decision? They want to say, here's the risk, here's my recommendation.

Yes. And then they almost always go with the recommendation. Absolutely. And that's been my experience too. And I will come in with a recommendation.

You know, usually I'll give them, you know, kind of when you've worked through the risk and you actually have a classified whether this is a low, whether this is a high, and I will come with a recommendation and typically controls based upon that. And then there'll be a conversation about cost of controls, you know, how does this work, other pieces like that. And they almost always ask for that exactly. And I'll say one other experience I've had, and I'd love to see if it resonates with you too. The higher in the organization I take the conversation, the less likely they are to accept the risk.

The individual contributor level are willing to say, no big deal, the business needs it. Yeah. And then as we get higher and higher, they're like, whoa, whoa, whoa, this risk really matters. Yes. Yeah.

And, and typically, it's, it's funny, for when I've seen it, it's typically right around that VP level. I hate to say it like that, but when they— when you kind of hit that officer of the company kind of level, yeah, that's when they're less willing to take that risk or more willing to discuss what, what is going on. And it might be that just the better visibility across the company, right? That they better understand things outside of their silo. And if you're, if you're in a silo and you don't see the rest of the company, you just don't have the perspective, the context to know whether that risk matters.

Yeah, and that was actually a mistake that I kind of made earlier on, not at Janus but at other companies, where I was taking that risk level too low. There's no other way to say it. Yeah. And, you know, I'd go to the manager and say, hey, sign off on this. Yeah.

And they'd be like, oh, no problem. Yeah, absolutely. In fact, let me give you a stamp. You can just stamp it whenever you want to. Exactly.

That, that's exactly it. And whereas, you know, as kind of my influence kind of, you know, pervaded among the, uh, the company, got out there, um, you know, I started moving up. And so, you know, and I would go have those candid conversations with, you know, people that are much higher up Yeah, Chief of Staff Investments, or, you know, basically the head of marketing or something similar. And that was the right level, you know. I'd say, okay, so when we're looking at this risk, this, this is what I'm recommending.

It's probably a low risk, you know. I'd recommend that, you know, you probably accept it, but here's some controls that are going to help control it. Um, so I'm going to— we only have 10 minutes left, and I'm going to ask you a couple questions while we have some time. Yeah. All right, so, you know, I now know a little bit about your, your research, your background.

And you're a security guy. Have you played around with CRISPR at all? I have not. You know what I'm talking about? No, I don't.

Tell me about it. It's a DNA hacking— Cool. Yeah, it sounds right up your alley. Yeah, I should play with it. You should play around with it.

And now there's like a home CRISPR you can like— Oh, so I can actually do my— Yeah, for a reasonable price. Yeah, um, that'd be a blast too because— and I want to, I want to circle back with you in 6 months. This is your assignment to go, to go learn CRISPR. Learn CRISPR in action. And then teach me how it works.

My wife's gonna love that, 'cause I'm gonna be back down in the lab with pipettes, and I'm gonna be like, yeah, all right. I guess it's actually genome editing is what it is. Genome and DNA, is that interchangeable? Can I do that? It's fine, it's fine.

Let's just go with it. It's not, but it's fine. Let's just go with it. 'Cause that's not my background. All right, priorities for you.

What are your priorities for the next year or so in your security program? Oh gosh, integration. So we are still integrating. Yeah, it's funny, 'cause for some people in our company, They're like, aren't we done integrating? It's like, no, I mean, this is gonna continue on for the next year and a half easily.

So integrating 2 different teams, incident management programs, vulnerability management, the vendor due diligence pieces that we just talked about, all of those pieces majorly. And it's just funny, I just did a presentation on this where I put up 6 months of incidents and say, okay, so here's all the pressure that's coming in from the incidents. Then I put up 6 months of regulatory responses, which were actually, they're kind of, if you think about it, all those regulatory responses are actually the incidents that happened like 2 years ago, really. And so I put all those up and it's phenomenal change. I mean, we see that across the board.

People right now are all dealing with EU GDPR and on the US side, we're all asking, oh my gosh, how can they enforce it? For me, I'm a UK based company. I have to worry about this. Right. Absolutely.

And there's an immense regulatory change right now that's going on. Does the New York financial services regulation impact you guys? A little bit. We're not specifically registered with that authority. Yeah.

At least that's, that's what we've determined. But, you know, to say that I'm not watching it and not trying to adhere to it would be a gross misunderstatement. Yeah, you know, I've gone through the controls that they've recommended, gone through it, actually went through it yesterday with my vulnerability management testing team. I said, okay, we need to be aware of this because if it's not New York, it's going to be, you know, the next state in line and it will affect us. So the only— so I did quite a bit of research reading through it.

The only thing on that that we shouldn't already be doing, right? If you already are running a good security program, you're absolutely right. That most of it we should be doing. The only stuff that we shouldn't be doing was, there's like, the CISO has to write a letter, has to like register, and that's, you know, I'm not gonna do that because I don't have to, but I should be compliant with the steps that they have in there. Absolutely.

And frankly, anyone out there who's running a security program, you should probably look at it, and if you're not doing something, put it on your list of stuff to get to. Yeah, I mean, you know, the basics that we looked at yesterday, you know, the annual penetration testing, should already be doing that. Risk assessments. Yeah, exactly, and the risk assessments too, yeah. Yeah, I thought the penetration testing was a little lower down in the line, but that's okay.

I don't remember the— I don't remember the— because there was different timing for how they phase it in, and I don't remember all the phase-in timing. Yeah, and there was also the original draft, when I was looking at that, what I recall is it had like, you know, actual stated like vulnerability testing periods. That changed when I looked at it later. Okay. Because I saw some of the early drafts of that bill too.

So, Yeah. So priorities for next year, compliance, integration, anything else you want to throw out there that you're thinking about for next year? Absolutely, always looking at staff development. Sure. There's no other way to say it.

We all know this, you know, everybody's kind of strapped. I have a good internship program, had some really good interns come up through. Did you end up hiring some of those? Yep, hired one of them. That's great.

Have another one that's still in college right now. Yeah. So yeah, he's been doing a fantastic job. It's the one thing that we really need to do to help the community more than anything else. Make more security people instead of just poaching from each other.

Yeah, and you know, and I think a lot of us have realized that, that, you know, we need to give back. The one, you know, this— and also I had kind of a frustration where I'd see these programs and I'd see them kind of turn out security people and they, they're really, really book smart, but they didn't have Um, certain strengths that I'd be looking for, you know, like I want to always keep learning and I really like, you know, either breaking into systems or, you know, there's something, something that's driving them in information security. And I wasn't seeing that coming out of the people in the programs. And so I said, okay, so I'm going to try to get back to the programs and try to nurture that in those people that really want to do that. That's great.

I love it. Uh, so for those, I don't know if you're going to be hiring next year. Well, I guess, are you going to be hiring next year that you're aware of? I think right now we're probably gonna be relatively flat. Okay.

Yeah, we're right now at about 13 people, which, you know, could be a larger program for, you know, 2,200 people or smaller depending on if for financial services, depending. It depends on how much you put inside your security versus in IT, how much is oversight, how much is operations. Exactly. It's hard to compare. It's really hard to compare that model.

We can compare offline a little bit. Yeah. If you do hire someone, what are the skill sets that you're most likely to be looking for? Yeah, so typically, you know, a drive to always keep learning, you know, to keep up, you know, and just keep learning. Attitude.

Yeah, attitude. And just, you know, I want somebody that's constantly coming in and kind of challenging and say, hey, did you look at this? Did you see this? Yeah, this is neat. Absolutely.

Kind of that drive to not accept, like when you're looking at log data or something else like that, not accept the immediate answer, to kind of continue digging and to continue monitoring and doing analytics around data. I love that piece. If they're constantly looking at data, this log data, and saying, okay, so it doesn't look like this, let me dig a little further. What's the next piece? I admit I do look for people that want to look for a CISSP.

It's not a requirement, but that kind of fuels that kind of always learning because then they fall into the CPE cycle and they'll be constantly developing knowledge from there. One of the things I really— so I'm not a huge certification guy. I'm not going to turn away an applicant because they don't have it, but I will say one of the really big values of having a especially CISSP, although Security+ gets you there too, is you can speak the language, right? You could be the most technical person in the world, but if you don't understand the difference between a vulnerability and a risk and a threat, it's just harder to communicate, right? Yeah.

So if we could talk about it a little bit better, if you've been through the training, you know, you've learned what they say, it's a mile wide and an inch deep. That is what it is, right? CISSP doesn't get you ready to do any job. No. But it makes it so we can talk.

Yeah, and in truth, you know, we had this conversation about college. You think that I'm looking for people with PhDs. I'm not. Some of the people that I've had on my team don't even have a college degree. Yeah.

That isn't the piece. I typically encourage them to get a, you know, CISSP over time because, yeah, because then it helps the language. They learn a bunch of different areas. That's not what I'm immediately looking for when they come in either. But I'm looking for kind of that drive to continue with that.

And there's another piece around that too, around the certifications. One of the reasons why I'm a little more pro on that is, you know, the fact is we've all worked a lot of jobs. And, you know, when you look at the market, you look at all these jobs that are looking for CISA, CISSP, CISSM, there's a bunch of different pieces. And one of the things that I want to be able to do is enable them, and I realize they're not always going to probably want to work for me or always will work for me, and so I want them to be prepared that if they leave, they actually have something that's going to help them move on to the next level. It does prove a certain level of seriousness about your security career.

You're not a tourist if you spent the time to get a CISSP. That doesn't mean that you're good, right? It's just one Piece of evidence. It's a piece of evidence. We talked about this with the Equifax breach and we're all down because everybody's like, okay, there's CISOs in region major.

It's like, well, 15 years ago, 25 years ago, there weren't degrees in that. And so kind of because I'm in those same shoes, right? My degree is in anthropology biochemistry, right? But CISM, CISSP, GSEC, People never mention the GSAC, you know, G27000, you know, or 2700 is I think what SANS put it as, you know, all those different certifications. Yeah, you know, it does show a seriousness, right, to be part of the security community.

So I'm with you. All right, so we are just about out of time, Joe. I know we have, we have another meeting we got to run off to. Yeah. Is there any final stuff you wanted to say to the community?

Any, any words of wisdom that you want to leave us with? Oh, what are you holding right now? Well, I almost, I almost forgot. What do you— oh yeah, no, this is fun. Uh, so yeah, to kind of relax lately, I've been learning how to make chainmail.

Yeah. Um, and it makes sense, you know, we're always the defender, right? So you're sitting there, you're thinking, I need a chainmail shirt, you know. We'll see if I ever get that big. This, this piece is about the size of my palm, you know.

Yeah, this would, this would not protect very much of you. Yeah, exactly. Maybe my pocket protector. So it seems like fairly lightweight metal here. Yeah, that's aluminum, which means it's easy to work with.

So I assume that this would not stop— no, not, not at all. This is more to relax. This is a— this is for looking cool. Yeah, this is for looking cool, and it's more relaxed and have fun. Are you a— are you a ren faire guy?

You're gonna be taking this to the ren faire? No, this is more relaxed. I went the other direction. I went to, you know, I was a weird part of my life too. I fenced for years.

Oh really? Yeah, I actually taught fencing for a couple years. Okay. Yeah, and so I went that direction. So really, I mean truly, you know, competitive fencing, that kind of area.

I was not all that good.

Well, you don't need to be all that good if the other person's not a fencer. Yeah, that's true. So yeah, so this has been more for fun than anything else. Oh, very cool. Yeah, absolutely.

Absolutely. You know, and the big thing right now that I've got to say, if you're developing your security career right now, is link your security initiatives to business strategy more than anything else, because really you're there to enable the business. Yeah, that's why you're there. And it's a differentiator because so many security people think they're there for the sake of security. And if you can be the one who says, here's how we help the company enable these few things, things, it's so enlightening, right?

Refreshing for them. Yeah, absolutely. And we know some of the security community that go in there and they say, no, no, we can't do that. Whereas if you go and you say, yes, we can do this, this is what I'm recommending to enable us so we don't run into the problems. It's like if you had a military convoy.

The military convoy has an objective. It's got to get somewhere. Right. And If your whole purpose is to say we have to stop, rally, shoot, and that's all we're going to do, you never get there. Right.

Yeah, business strategy is all about getting there. Let's get linked back to your business strategy. And if you, and if you can find metrics that show how you impact that, exactly, you're number one, you're a unicorn. Yes. But you just became incredibly valuable to your company.

Absolutely. All right, well, cool. Thanks a lot. This has been really fun. Yeah, hopefully we can do this again maybe in 2018 and yeah, absolutely, see how it's changed.

Yeah, all right, absolutely. Talk to you soon.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes