All episodes

FBI Special Agent for Denver

Apple Podcasts Spotify SoundCloud

In this episode:

Denver's local FBI Special Agent is our guest this week. News from: Chipotle, Cyberpatriots, Threat X, LogRhythm, Ping Identity, Coalfire and a lot more!

Are the Olympics coming to town?

And more importantly, do we want them to come here in 2026? (Spoiler alert- No.) The Denver job market for 2018 looks good (especially for security). Chipotle is moving (but keeping the guac I hope). Highlands Ranch high school kids are better than you at security. Threat X takes a round (7.3m). And some blogs from LogRhythm, Ping (Robb wrote it!), and Coalfire.

Please come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Feature interview:

This week's feature guest is a special agent for the FBI, focused here in Denver. To protect his privacy, we're not sharing his name, but he does share a lot of stories about what it's like to join the FBI, what his day-to-day job looks like, when we should engage with the FBI, and how he's experienced the Colorado community. Here is the FBI's position on encryption: https://www.justice.gov/opa/speech/deputy-attorney-general-rod-j-rosenstein-delivers-remarks-encryption-united-states-naval. 

You can reach the Denver FBI field office at 303-629-7171

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

 

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13207 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 46 for the week of December 18th. And I, I think Santa's getting ready to come visit us, isn't he?

Yeah, you know, we're getting close there, Robb. I think— I don't know about you, but I'm pretty well through my Christmas shopping at this point. I'm gonna get that started real soon now. We're right in the middle of Hanukkah, so for all of our Jewish friends out there, happy Hanukkah, everybody. Yep, thanks.

Yep, besides that, I think I'm about ready to go. The Last Jedi, we saw the movie. We did. I think it's time to let everyone know it turns out Rey is Yoda's daughter. That was a surprise reveal halfway through the movie.

I was shocked. I was shocked as well. But it makes sense. I mean, her— a little bit appalled. Shocked and appalled.

But it was good. Yeah. So we got to watch that last week. Hopefully everyone's got to see it. We'll look forward to talking about what you guys thought about the movie soon.

Why don't we dive into the news? Let's do it. This is again a banner week for news. Let's first though remind you guys that we do have our mailing list. So if you want to get show notes in the mail and other communications from us, sign up for that on the website, colorado-security.com.

And the Slack channel has been, been burning up. We've got well over 100 people in there now, and, and hopefully some, some good conversation and a good way for you to connect with local security people. Yeah, exactly. So first on the list this week, um, Denver is exploring a 2026 Olympic bid. So that's the Winter Olympics.

Um, you know, we had originally been picked as an Olympic— a Winter Olympic location back a couple decades ago, right? And turned it down. Yes, I think even more than a couple of decades ago. But yeah, it was the only city to ever be awarded the Olympics and then turn it down. So what do you think?

Should we, should we be interested in having the Olympics here in town? You know, it's one of those blessing and a curse kind of things. I think it would be great exposure. It'd be wonderful to have them when they were here, to have it so close. But, you know, you do get saddled with a whole bunch of debt.

Well, they said the article here is pretty clear that it would not be any public funding, that it would all be privately financed. And I don't know exactly what that means, but if they can come up with a way to do it without a bunch of public debt and without, you know, building structures that are going to sit there and just, you know, get old and not get used, maybe, maybe. Well, I'm pretty sure that the only city to ever make money on the Olympics was Los Angeles. So I think you're even, even if you can say on paper that you're not going to lose money, historically everyone has lost money. Yeah.

So It's an interesting thing. You know, I think living here during the Olympics would be pretty terrible. You know, yes, winter traffic is already pretty bad, and now we're gonna have, you know, an extra, I don't know, 2 million people in town or whatever it is. So I'm voting we don't do it. But yeah, what do they care about my, my vote?

So next, there was an article this week about what does the Denver tech job market look like for 2018? I think look like things are not necessarily, I don't know, as rosy as they have been in the past. Still positive, right? Still positive. Still a lot of jobs.

There's going to be job growth, but the growth is slowing down based on where it was for the larger tech economy, right? But not for security, right? Right. Yeah. And then I think that the key thing out of this article was that they did a survey and one of the questions was, what are the hot tech jobs?

And cybersecurity was mentioned by 51% of the folks that were surveyed. Which was the highest of anything that was mentioned. So right behind it was what, cloud computing? Cloud computing, um, and business intelligence. Yeah, and I assume that's big data and machine learning for business intelligence.

Exactly, all the hot stuff there. All right, uh, Chipotle's headquarters is moving. You know, Chipotle is a Denver company. The first, the first Chipotle opened was by DU, and they're moving their headquarters into the new building at like 15th and in between Arapahoe and Lawrence. Yeah.

So that's pretty cool for them. It sounds like they have their, their corporate folks in a couple of different locations now. So they have the ability to consolidate into one space in a new building. So I was surprised they have 450 corporate employees there. So pretty good size back office.

Yeah, exactly. Next, the Highlands Ranch Cyber Patriots were profiled on a Douglas County Schools website. So that was cool. Yeah, so the Cyber Patriots is the high school kind of the club that gets together and does both security and, you know, red teaming, right? Learning how that works at a young age.

Yeah, and it just talked a little bit about, you know, what Cyber Patriots are, you know, what the team is, how long they've been going, things like that. So a good profile on those guys. Nice to see that they were popping up on a school website there. This is a nice bit of news. We haven't had a funding event in a little while.

ThreatX, which is a Denver-based startup, just got a $7 million round, venture capital round here, hopefully, you know, to fund their additional development and of course marketing and sales for them to go to market. Yeah, congratulations to them. Glad to see that they are still growing. Absolutely. Next, LogRhythm had a blog post this week.

Looks like it was by James Carder from the LogRhythm Labs folks talking about the consolidated compliance framework module that they have in LogRhythm. So this looks to me pretty similar to the UCF, the Universal Control Framework, where they're coming up with a way to, to have a single set of controls that maps out to all the different standards. So you can just go to this one single set of controls and, and get your compliance, you know, for everything else. Is that kind of what your read on it was? Yeah, it sounds like that.

Also notice that they have a GDPR module in there. So for everyone that's freaking out over GDPR, LogRhythm has you covered. Some parts of it. Oh, there you go. They'll take care of my GDPR problems for me, huh?

Exactly. Oh, that's, that's pretty good. Uh, there's an article from Ping this week. Actually, um, I wrote this one. It's, uh, about implementing high-quality control— high-quality controls to protect private keys.

And really what this is is a response to the, the research by CyberArk recently about— they called it a golden SAML— the ability to, um, to compromise a private key and, and go issue a bunch of new SAML certs. Uh, so this is really, you know, talking about how private key private key encryption works and how important it is to really protect that private key and what the best practices for that are. Yeah. If you have secrets, you should try and keep them secret. Yeah.

If you don't keep them secret, it doesn't work very well, right? Exactly. Yeah. And then finally, Coalfire had a blog this week, Cyber Incident Response and Lessons from Uber's Story. So they had a couple key takeaways here.

One, review your computer security incident response plan. That seems to make sense. Yeah. Definitely. Every once in a while, right?

I would say even before that, make sure that you have a plan before you review it. Not much to review if you don't have a plan. Their second piece was they wanted to make sure that you understand and sort of normalize the terms that you have in your policies. You know, what is a breach? What is an incident?

Things like that. I think this is to go to the point where in the Uber breach, right, where they believed that they had put enough mitigations in place that they could not call it a breach anymore, right? And, and to your point, you know, when we were talking about this offline, um, it doesn't really matter if the company thinks they're okay. If the law says this is a breach, then, then it's a breach, right? Exactly.

When, uh, when data leaves your premises, if that's what's defined as a breach, you know, if you recover it later, um, and can confirm that it didn't go anywhere, well, it still left your premises, came out, went out of your control, so that should still be a breach. But anyway, And then the last one, they note that you should ensure that your board of directors and legal counsel have signed off on your incident response plan as a matter of company policy. So I agree, your legal counsel needs to be a part of creating the plan and needs to approve it. But I think asking your board of directors to review it is probably, probably not realistic for most of us. Yeah, I think what they're trying to get at here is that there should be some formal approval of this incident response plan.

You shouldn't just draft it up and say, hey, I got an incident response plan, right? I don't know if board of directors is the right folks to be doing that. I mean, I agree with you. I can't imagine there are many people out there that are having their board of directors read word for word what their incident response plan is, but you should have some formal policy approval mechanism that's there, and this should be approved through that. That's reasonable.

All right, let's jump over to the trivia. For last week's trivia, which if you remember was a little bit of a choose your own adventure up in the mountains trying to build a structure, What's the densest rock to use? We didn't— we did get one response that was correct. Unfortunately, it was from a previous winner, and you're not allowed to win within the same quarter. Wah wah.

So we didn't actually have a winner this week. The correct answer is basalt. Basalt is that densest stone that you should use if you're going to build your permanent structure in the mountains. So a little bit of a tip for you guys if you ever, you know, have a zombie apocalypse need for a place to live. So prepare now.

Make sure you can identify what basalt is and you know how to mine it. And then you'll be able to build a shelter out of it when everyone else is gone. You should probably practice and build one now, just in case there's an emergency. Probably, exactly. You don't want to be trying to implement this plan without having practiced it.

Yes. And make sure your board of directors signs off on your shelter building plan. Trivia for this week. You want to go ahead? Yeah.

So this week we have a back to the podcast question. Which feature podcast guest previously worked for the Mayo Clinic. Hmm, that's a good one. And this is not like mayonnaise, you know, just in case you're wondering. We're not the health of the mayonnaise.

It might be. All right, let's jump over into events. There is a total of one event for the rest of the year. Coming up this Thursday, CitySec, or Denver CitySec, is happening up north at the Colorado Keg Company. I think that's what it was called.

I did confirm their Twitter account shows that they have a meeting and a place identified. So hopefully you guys can make it and, you know, hopefully get a drink, a drink with some friends around the holidays and get ready to take a little bit of time off. Yeah, so you should definitely check out their Twitter feed for the, uh, the actual name in case Robb got that wrong and the time and, and, uh, when they're gonna be there on the 21st. Good stuff. A couple of events we wanna just highlight coming up in the future.

One, we talked about this in November, it got pushed due to a couple of holiday things, but Optiv is having their application security focus group on January 18th. It's not too late, not too early to sign up either. So you can go get signed up for that and go attend. It'll be some good stuff to talk with Optiv folks. And then also, I think we are gonna be now in our weekly review of the Rocky Mountain Information Security Conference.

We are very close to being able to announce all of the keynotes. But the call for papers is still open right now. Call for papers is open. We've had a nice surge of submissions. You should get your stuff in early.

We as a committee start to review early, and of course it's nice, you know, to be early in the process, you get your answer earlier too. And I think I mentioned it previously, but we changed user registration this year, attendee registration. So if you have a little bit of budget at the end of the year that you wanna get rid of and you wanna register for RMISC now, you can. So go check out rmisc.org and sign up as an attendee. I haven't actually seen much about BSides yet.

I don't know if they've started planning or they're still waiting on stuff, but we'll look into that and hopefully get back to you guys in the next couple weeks on status of BSides. Sounds good. All right, so let's take a look at the jobs this week. Uh, first, Cigna had a cyber threat responder and malware analysis lead. Sounds like fun.

Yeah. So Ping Identity— this is working on my team— is hiring a cloud security engineer. We're talking to a couple folks about that, but would love to have you guys submit as well. We're also hiring a couple of security-focused SREs, site reliability engineers. So if you have experience working at Amazon doing kind containerization with Docker.

That'd be great to hear from you guys for that. Sunflower Bank is hiring an IT risk specialist. Yeah, and I reached out to the hiring manager there, Nina White. She's looking for an energetic, passionate person who wants to— who's either got a couple years experience or really wants to learn about IT risk and security. Transamerica is hiring a lead paralegal in privacy and cybersecurity compliance.

FAST Enterprises is hiring an information security analyst. And I put FAST on there this week because I think that they were one of the ones that were on the Glassdoor article from last week about one of the best places to work. Yeah, and we hung out with, uh, one of the director over there, our information security officer from over there, uh, Todd Mortensen. He came to the, to the, uh, Colorado Equal Security CISO holiday event. Uh, next, uh, Cherokee Nation Businesses are hiring a network and cloud security specialist.

Wells Fargo is hiring a Systems Architect 5 focused on crypto security. So I, I wanted to see this one in there because it's very— not very often that you get a level 5 kind of job in here. It's funny to me that you hire in at a 5, right? I can see like, hey, we're gonna put some numbers after your title so we can give more promotions, right? But if you hire at a 5, how high can you go?

How many more numbers are there? Well, I would say if you're working on crypto security, you probably need to be a 5 anyway. All right. Next, Carbon Black. They are hiring a SOC analyst.

This is surprising that they're hiring it in Denver. I wonder if it's just work from home. Do you know? Well, so Jim Trynan, who used to be at ProtectWise and now is at Carbon Black, I used to work with a long time ago. He's actually— he lives up towards Boulder and they're hiring a bunch of folks for Carbon Black in the area.

Do they have an office up there then? I don't think yet, but I think that they're working on that. Okay. Black Knight is hiring a Threat Intelligence Analyst 1. See, this is an opportunity to go up, you know, several numbers.

That's right. Exactly. Akamai is hiring a Technical Project Manager for Security. And then the, the Merkur Group is hiring a Privacy and Data Security Attorneys and Partners. Yeah.

So I think that they're looking for multiple folks. Yeah. So if you're an attorney or potentially an experienced one that could be a partner, I think the Merkur Group is looking to hire folks who know cybersecurity and the law. Well, good stuff. That's the end of our, uh, of our news for this week.

We're gonna throw it over to the feature interview, which is with the FBI special agent here in the Denver area. Uh, so got to ask a lot of interesting questions about, you know, what they do around cybercrime, um, when we should reach out to them, a couple of stories about stuff he's been involved with. His name is Jason. We don't use his, his last name. He doesn't want that.

So, uh, but anyway, hopefully a good interview, and we'd love to hear from you guys if you have any questions or comments about it. Secret agent man. Secret. Anyway, yeah, so I'm looking forward to that, Robb. And oh, I did want to mention we have 2 different additions to the interview with the FBI agent.

Number one, during the interview, I had asked him if the FBI had helped respond to the shooting up at the Walmart here in town a couple of months ago. He wanted to clarify that they were involved in working on that with local law enforcement. And number two, he asked me to mention and actually put a link in our show notes to the FBI's official position on encryption. You know, we we we didn't talk much in the interview, but I talked with with him quite a bit about you know the FBI the FBI and Apple with the iPhone decryption conversation and and asked him for some clarity. And he he wanted to point us to the official statements just so he doesn't get in the way of that.

Okay, with that, well, I think we'll throw it over to the interview. And if you guys have any questions, drop drop us a note. Thanks, Robb. Hey, buddy. This is Mike Benjamin, a big fan of.

Colorado security. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. All right, today this is Robb and I have the fortune of getting to interview one of the special agents assigned with the FBI assigned to the Denver office here. Rather than giving his name out, we're just going to call him Jason. Jason, thanks a lot for joining us for the show today.

Thank you, Robb. I'm happy to be here. Yeah, we have a lot of fun stuff we can talk through today. The first thing I'd like to ask you is is did you join the FBI because it looked really cool? Is that what it was?

No, because it does look really cool. It does at this point. Um, I obviously, um, well, just, I was on the path. Let me say that I was on the path long before I knew I was on the path. Um, and to unpack that just a little bit, uh, I grew up, I didn't have computers really available to me.

And I got to about the time in high school where I had to focus on a major for college. And my guidance counselor brought me down to the office and basically said, what do you want to do? And I was all over the map. I liked a lot of— I had a lot of different interests. So I didn't know if I wanted to do medicine, law, science, history, what have you, computers, quotes.

So my guidance counselor looked at my schedule, goes, oh, you're taking an intro to programming course. And I was— it was the BASIC programming language. Yeah, if you remember. I know BASIC. Yeah, BASIC.

I wrote some programs in BASIC. Yes. Okay, so I'll tell you what I did in BASIC. Go ahead. Yeah, I— we used to buy magazines and you would, uh, and the magazine would have pages of code that when you typed those pages of code into your computer would be a game.

Yes. So that's how you got free games, right? Yeah, right. That was my basic— that was my intro to BASIC. So that was my intro to computers, if you will.

I mean, it's a broad term, it's ambiguous, I get it, but that's how it was kind of, um, introduced to me. And I didn't really understand— translate that to what I was seeing in the world with, um, you know, like the gaming systems, Nintendo. And so it's— I'm trying to make this, you know, mental cognitive leap from how is basic getting to these environments that you play Super Mario and all that other stuff. So I really didn't get it, but for whatever reason, I was curious about it. And so it was almost a whim, I guess you could say, but I said, okay, let me do this.

I'll study computer science. And so that's what I did. And I went to school at an engineering technology school, heavy in that regard. Very quickly I found out that I was a very newbie to technology. A lot of my classmates coming in as freshmen had computers with them growing up.

I didn't realize until then that there was, you know, the Advanced Placement courses, that there's Advanced Placement programming computer science courses in high school. I didn't know that, so I was kind of naive with all that. And those guys were talking about C++ and what they're doing, and again, I'm coming from this this exposure to a syntax-based programming language in BASIC. So I was in over my head and I actually immediately started questioning, did I make the right choice? But I stuck with it and I'm glad I did because 20-some-odd years later, I guess closer to 25, I'm so passionate about technology and it worked out well for me.

So there was a guiding light there. I'll say after college I went into the private sector, so my focus was more application programming by large and in part. So I also had a bit of a Goldilocks syndrome with trying to find the right job that motivated me, to be upfront. I jumped from large corporations to small and in between medium. I tried different sectors from finance education, even communications.

And every time I would get stuck with— I enjoyed the programming element of what I was doing, but I would— it would be the puzzle that needed to be solved and I'd solve it. And I felt that after doing that, I'd be asked to just essentially solve the same puzzle again and sell that again and again. So I felt like I was doing widgets a lot and I wasn't in any innovative technologies or anything like that, and it wasn't really moving me. But I'd say this, being on that path to get into the FBI, one of the things that I just naturally kind of gravitated to was thinking about security implications to the code that I was writing. I was doing a lot of the web applications, a lot of database backends, frontend.

I did some ASP, I moved into PHP, I started following the open source, the LAMP stack. So Linux, Apache, MySQL, PHP at the time was the thing. And I really enjoyed doing that. It was immensely fun. But again, I was thinking about the security implications.

There's no guidance as far as at that time, to kind of date this, late '90s, early 2000s, there was no guidance for how to, at least I didn't see it, no one told me where to go. It said like how to like protect against SQL injection type of attacks, how to filter inputs, do all that. But naturally, I would follow news about computers and security, and I would read about an attack and how it happened, and I'd think about that, about how can I prevent that from happening with my applications, and things like even encrypting passwords and databases and so on and so forth. So I naturally gravitated towards that. So I might have over-engineered to my supervisors at the time to their liking.

But so I had that inherently in me. People who know me well will tell you that I do have a little bit of paranoia in me. So I think that's a good trait to have when you do things with cybersecurity, if you will. And ultimately, I had a confluence of events happen in my life where I was still searching for that passion and the job at this point, because I knew I was in the right spot with technology. I just needed the right job.

I actually became a victim of a crime. It seems small at this point because of where we are today with things, but I had my credit card compromised and I was just offended that somebody could do that. And so I was like, wait, And then at the same time, the FBI stepped up its cyber division in 2005 at this point. And so, and I read an article about that, and I kind of, all this was happening at the same time. I said, you know, I'll give this FBI thing a shot.

And that's kind of how I was on that path, and the rest is history. I've been doing this for 10 years now, and it's been a blast. Yeah, that's great. You know, you and I met and had lunch few months ago, and you told me the story about the, you know, the application for the FBI, and it's, you know, not super easy. The physical fitness tests you had to do and all that.

We've, on the show, Alex and I have a couple different times covered that there's some special agent postings out there. People, they're looking to hire special agents in Denver. So any words of advice you want to give anyone who might be thinking about trying to join the FBI? Yeah, yeah. So upfront, I would start with whatever you do, regardless of— don't think about FBI being the final goal.

Just choose something that you enjoy doing and that you want to do. And what I mean by that is some people who don't know how the FBI really operates think that they might look more attractive if they maybe have a law enforcement background. And so they might tailor their school and just the work experience that they have in law enforcement, and they're not really that passionate about working in that area. It might even be the same thing with law. If someone wants to pursue law in school thinking that this is going to be what's going to get them in the FBI, that's not a good match.

You really just want to follow what you— and that's what I did. I didn't know it at the time, but I just followed inherently without even knowing the FBI was a destination for me, what I wanted to do. And then in the hiring process, the FBI, as the eligibility requirements come, if you meet the requirements, which broadly speaking, and you can get all the requirements at our website is fbijobs.gov, and you could get all the detail that you need on this, but being a US citizen, having a college degree, STEM is something that is encouraged and we need a lot more help with. But you could be in law, you could be in medicine, you could come from a military background. And so as long as you have that, you're going to be fine.

You could apply and really you have to meet these baseline eligibility requirements. If you pass that, it's really just like almost like a selected-by-algorithm type of thing where you meet all the requirements, then you'll move forward in the process where you'll be looked at as an individual, right? So, long way to say, whether you have an IT background or any other law background, if you're interested in being an FBI agent, if you're between the ages of 23 and 36, and those are very specific ranges, the 23 more from the The FBI wants a more mature candidate. 36 more because we have a mandatory retirement age of 57 as an agent, and so if you start the process at 36, you need to be at the Academy by 37 years of age so that you can clock— put 20 years on the clock to get that full retirement. All that being said, so my advice would be follow your passion.

If the FBI is still something that you want to do and you meet those minimum eligibility requirements, go ahead and apply because we definitely would need— we need the help as much as we can. I love the job and I would encourage anybody. I tend on the technical side, so for a career in technology and computer security, I would definitely encourage you to apply. Then you do talk about When you get through meeting the minimum eligibility requirements, you do have to eventually be interviewed by a panel of FBI agents. It could be intimidating.

You do some writing. There's some other testing like logic and reasoning, personality tests. There's a whole slew of tests that you'll have to go through those hurdles. And we haven't even talked about what you alluded to is the physical fitness test. I talked with our HR people just yesterday because I just wanted to make sure I was giving out updated and good information.

And they tell me as late as yesterday that the part that trips most people up on the agent side is the physical fitness test, which for those who might be wondering, that test consists of 1 minute of as many sit-ups as you can do in a minute, and then a 5-minute rest period followed by a 300-meter sprint, then another 5-minute rest period. And then you do maximum push-ups. You can go as long as you can go. There's no time limit, but you can't stop. So there's no pausing for breaks.

And then finally, after another 5-minute break, you do a mile and a half run. So independently, each of those events don't sound too bad for, I think, most people. But when you put— when you string those things together, even with those 5-minute rests, yeah, it really, um, when you do it, it's like, wow, okay, it's a different— it's different. Um, so anyways, I have fun with it. I, again, if anybody's interested, go out to the website, take a look at those requirements just for fun.

Socially, if seriously, if anybody would want to do the— as a social the FBI fitness test. You're up for it, huh? I'll do it. I need to practice it myself because I still take it. But anyway, so yeah, definitely encourage everyone to consider it if that's something that they think that they would like to do.

Well, so my next question for you is, what are the top priorities for the FBI right now? Okay, well, so we start looking at the problem from a national security threat and criminal threats. So, we basically, we start to separate from there. And national security threats are going to be, you know, nation-state-backed threats to our infrastructure, to companies, our way of life, that type of a thing. So, that's going to be where we're going to want to spend most of our focus as the FBI on the national security side.

On the criminal side, you have the financially motivated attackers. You have corporate espionage is in play. You have insider threats, which I would also include your disgruntled employee, which by my experience is if that's the scenario where you're most likely to have an arrest in, say, Colorado is that disgruntled employee scenario where someone's been let go or has just been jaded with the job and they decide to do something, unauthorized access, and do something destructive to systems.

Then there's what we call the hacktivists, so those who have some sort of political point that they want to make, but they cross that line into some criminal behavior. Doxxing might be one of those things that you'll see where someone has a personal axe to grind against another person or group, and it's the attack on just trying to doxx that person to get as much information, shame them, type of— Doxxing basically means I'm going to go find out where you live, all the information about you personally, and just go post it on the internet. Right, right. Yeah. And you'll have that directed at law enforcement, you see it directed in the press, you'll see hackers do it to each other, right?

Just kind of a, I don't know, some sort of tiff happens or someone wants to just out somebody else and they'll actually put out some information like that. Yeah.

So, you know, taking a step back further, just help me understand the the difference between the charter or the mission of the FBI versus other law enforcement or other intelligence. You know, obviously there's, you know, the CIA focused externally outside the US, but maybe talk about what's the FBI's big picture charter. Well, we're domestic law enforcement. Yeah. So that, that's— we— but not all.

I mean, you also— we also have, you know, police and sheriffs. And what's the difference between your guys' purview and, and any other domestic Right, so federal government, right? So federal laws. And we are organized to essentially address threats specifically that are in violation of Title 18 Code, the United States Code Title 18. So all the violations, I think there's about 300 of them.

So it's everything from things that you, might be more familiar with, like bank robberies, kidnappings, um, the corporate espionage, money laundering, healthcare fraud, public corruption. There's a lot of different, uh, violations that we can pursue, and that is different than— there's no other federal law enforcement that has that breadth of violations that they could charge under. Yeah. So that's something that does separate us. And we do, we do have, because the nature of everything these days is global, we do have what we call legal attaché offices all over the world.

I forget the exact number, but we do have them overseas. So, and they're an extension, they represent the FBI in a foreign country, but they're not They don't have law enforcement powers in those countries, so it's just liaison, and it's necessary, frankly, with everything with computer security these days. A lot of our attacks are coming from overseas, so we need to work with our law enforcement partners overseas, and we do that through our legal attachés. So, you know, a guy like me, most of what I know about the FBI comes from TV shows, fictional TV shows. So, for example, in The Wire, the FBI says that they're really focused on terrorism and not looking at other stuff.

Do you guys get mandates like, hey, this is how we're going to— this is the crime that we're most focused on right now? Yeah. So we do have our top priorities and terrorism is still our top priority. Cyber is, I want to say it's now second. Okay.

I probably should address the cyber term at this point because it's definitely pervasive in government, just calling everything cyber. And for an audience like what I anticipate with your podcast here, I hope that they give me the leeway with that. There are times, frankly, I do think about that because I might be interviewing people and subjects that if I drop cyber in this conversation, that I lose credibility in front of them. And so I get that and I'm sensitive to that as well. But at the same time, I work for the cyber division within the FBI.

I'm on the cyber squad. I can't say it any other way. It's almost like programmed into me at this point. So I've come around a little bit on that. I've been an information security guy for a long time, right?

And when cyber first came out, one of Alex Wood's quips was, what does cyber mean? Can anyone explain cyber to me? And what I've decided is it makes sense if I take it from the perspective of a military person who's been focused on security for hundreds of years, right? Right? Um, that to them, security does not mean what I do, what Robb Reck does for a living.

And information security doesn't mean securing a computer, because they've had to do information security since before computers existed. So none of the phrases that, that I use in a day-to-day life made sense for them. And so they had to, they had to make their own. You know, maybe I could say it should have been computer security instead of cybersecurity. Well, Or maybe I can say that just dropping the word security bugs me, right?

But still, at least it makes sense. They couldn't just use our information security nomenclature. So I try to— I'm trying not to be quite so about it. I don't take it personally. But you see, our show is not called Colorado Equals Cyber, right?

Right, exactly. No, I totally get it. It's a shortcut. Let's be honest, it's a shortcut. If you have a 2-syllable replacement, I'm all for it.

So, you know, now that we've talked a little bit about the high-level priorities for you, how does, how does that flow down into your day? I know from our previous conversation that you don't spend 40 hours a week focused on computer work, right? It varies, and it can be pulled in different directions based on what is happening in the office. For instance, one of the things that I enjoy being an FBI agent and being part of the FBI, because our professional staff do this as well, is that we are really good at responding to crisis when the time calls for it, as well as just surging resources to an investigation. Unfortunately, things like that come up.

It could be like a child kidnapping, for instance, is something that that will come up where the entire office will drop everything, literally what we're doing, and focus on like getting out to the neighborhood, doing canvases, talking with people, trying to, trying to identify a missing person. And so that is unpredictable, and we don't like to see any of that, but in reality we do get work like that. Yeah, um, even things in, in the world that happened, uh, We just went through an incident in Las Vegas with a shooting. A lot of resources out of the Denver FBI office went out there to support that, and that covers everything from FBI agents through analysts to support staff and IT people who just need to set up a command post. So, it's one of those things where it separates, I think, us from, frankly, just the private sector.

It's just, you're kind of, responding to real-world events that at the end of the day you feel like you're contributing to a good cause. So recently in Denver we had a violent crime committed at a Walmart, right, up north. Is that something the FBI gets involved with? I'm sure we were. I'm sure we were.

Not personally, just because where I'm sitting, I didn't get any particular insight. It was almost like, I wouldn't go so far as calling it need-to-know. It's just that we do have resources, I'm sure, that were used. I don't know what they were, but in that example, maybe because it was as, frankly, that one has a, there's a state and local piece to that where state and local law enforcement will request resources. I'm sure, those conversations were had and whatever the state and locals needed, we were willing to provide.

Yeah. Okay. So I have a couple questions for you around— well, one more thing on that. What percentage of your time would you say, you know, I know every week is different, but like take a big picture over the course of a month or a year, what percentage of your time do you get to focus on the cybersecurity part of your job?

So percentage, I'd say So averages, I think I'd like to say I put 75% in. Okay. So most of your time is really a security thing. The rest of it, and just taking apart from, and actually that might be high because now you're still not doing the whole, we have a lot of training that's required of us through Congress, frankly. So Congress requires us to do a lot of training, whether it be— we have legal training all the time, well, once a quarter.

We have firearms training once a quarter. So those days kind of come off the calendar. We do have meetings with the public. We, as much as we can, we like to come out and speak at conferences and stuff. The reality is, is because of just what the workload is, is we, we have a lot more requests to do speaking engagements than we could reasonably accommodate on top of the rest of the work.

So we do have to be very choosy as to what we do choose to speak at. And we really try to be like anybody, what's going to be the most— where are we going to make the biggest impact? For instance, this podcast is a great time for me to spend here because we could talk about what the FBI's priorities are and what we're dealing with, And I'm sure your subscriber count is— we'll get a few hundred people. Is, is, uh, that's great. And that's more than, you know, most places that we can get to.

So, so I said 75, 70, 75%, but it's probably as they start, keep on knocking these days off, it kind of goes down to overhead and admin stuff like that. Uh, okay, so a couple of the topical things I wanted to bring up first. You know, ransomware has been everywhere over the last— it's been 4 years now since CryptoLocker kind of burst on the scene. And, you know, question of should we pay the ransom? Should we not pay the ransom?

Love to hear, you know, your take as an FBI agent— special agent, excuse me. Should we pay the ransom? What do you think? Well, the official FBI response is that we do not ask you to pay that ransom. We recommend that you do not.

And the reason for that is it just proliferates the problem. It makes it more profitable, makes it more common, brings more criminals into doing it. I look at it as there are some countries in this world where kidnapping is like a— it's a thing for for making money, to monetize. I think if we were all— no one would choose, if they had a choice, to be in a country like that. And so, when we cross into computer security and internet technologies and the crimes that are going on, things change as far as your assessment on everything, frankly, where in the real world, I think we know, like we will talk about, you don't negotiate with terrorists.

On the ransom side, in the real world, we don't pay ransom because we don't want to feed that demand there. And so that's why that recommendation's there. The other thing is that we have documented reports where The sticker price on the ransom is not the final price. So there are some groups that are out there that will— speculation is it's almost like they throw the proverbial spaghetti on the wall to see who kind of— whatever sticks, whoever they get hooked into. And those people come out and say, I'm going to pay that ransom so I can get my hard drive back.

Or whatever, they'll turn around and look at you a little bit closer, and they might realize that they have you in a tighter vice than— because maybe you're in a corporation now instead of your grandmother's computer. So they might turn around and say, okay, they'll up the ransom. So long way to say is that you get into those games, so that becomes a problem. You also get into problems where we have documents cases where the ransom was paid, but the keys that you got back might not have been provided, or if they were provided, there was a mistake in something, you know, because it didn't decrypt the files. So malware has bugs too?

Yeah, exactly. So it's kind of— and then from an InfoSec perspective, it's like the way I look at any computer that's been compromised, I don't want to I don't want to use it. I'm starting over. So if you have a compromised computer that's been— that you paid the ransom to get decrypted, how do you feel that there's nothing else going on behind the scenes? You never feel that good, which I think for those reasons, those are some really solid reasons as why that recommendation of not paying the ransom is is a good one for those who can help with not paying that ransom.

Yeah, and I certainly agree. I think the hard part is, you know, some people put themselves in a really bad situation, right? Where you have critical data sitting on a drive and that's the only one way to get it. You know, even if you know you're not ever going to get— even if you know there's a 50/50 shot that paying the ransom doesn't get you your data, you know, some people have a different equation which says they have to pay it. Yeah.

Course, from the security hygiene side of it, right, you want to avoid just— don't put yourself in that situation altogether. I will say, I will add that, you know, as you do, if you start threat modeling for your organization where ransomware fits, it is relevant to everyone. Like, I think any company— there's any company that's out there that's connected to the internet, which is every company, can be affected by ransomware. As well as you and I at home and such. So, but just strictly talking about the corporation, I think one of the more concerning things in the assessment is that we're seeing more sophisticated ransomware attacks.

So where the groups are acting more like what we would see in even like an APT, the advanced persistent threat type of behavior where we'll see that these— that the sophisticated groups are like looking for vulnerabilities that they could get that toehold into a network, and they'll spend some time in there. And so the problem that I have for that is that there are certain sectors that have the APT target on them, and they know who they are. Namely, if you want to guess, you could probably come to pretty quickly to the defense contractor industry and such. And at least they know what they're up against. And they're orchestrating their tools and, you know, they're getting their personnel up to speed and trained up as to how to deal with that threat.

The problem that I see with ransomware as it gets sophisticated is that there's other sectors and just to select one at random, say healthcare, for for instance, where you could arguably say that you're, as you do your threat modeling, that APT is not my, I don't have to worry about that. So I don't have to like dial up my— China's not trying to get your intellectual property probably. Right. Some community hospital somewhere. Exactly.

And then so now if we're starting to see this bleed of those type of tactics into that type of, say, organization, as an InfoSec, person, my threat model has just changed. It's like, okay, well, maybe I do need— we could go into a discussion about what cyber threat intelligence means and do you need to be doing more trending towards that.

It's a can of worms and it can bring heartburn to our CISOs and such. Probably the biggest thing I wanted to talk about is as someone who runs a security program, and we have a number of different security leaders and security analysts listening to the podcast, when is it right for us to engage with the FBI? What kind— obviously, we, we all experience an incident frequently, and if you define incident broadly enough, you know, we get a piece of malware on a laptop, we get ransomware on, on a system, uh, you know, we get an email saying, hey, we're going to deny a service you, we get yada, yada, yada. There's lots of different kinds of incidents. I don't want to call you every time.

I don't think you want me to call you every time. From your perspective, where does it become profitable for me to reach out to you? So I would start with we try to look for the biggest impact in the work that we do. And so you're right. There's a level of activity that is important to report.

But do I need to know it personally? Not really. Just to give you a quick example, if you— some people do this. If you just happen to have come by a spear phishing email, That's 1 in a million probably that's been sent. Not really, in the big picture of things, that's not where my focus is going to be.

People do want to report that, and so if you do want to report that, you could do that at a couple spots. One online is we have the Internet Crime Complaint Center, which is there for the military folks, and they'll remember the alphanumeric codes or What I'm trying to get to is indigocharlie3.gov is the web address. So, you go www.ic3.gov. Okay. That'll get you to the Internet Crime Complaint Center.

And you could submit— and it's really meant to be a clearinghouse for this type of— yes, it meets a threshold that you want to report it, but you can't— you get that it's not going to be be a major case from that single report. The good thing about reporting it though is there is that it's being collected in one database. So if we see that, if we correlate reports across the country where everyone's saying the same IP address was responsible for dropping the same malware, then we will be able to identify that pattern, that trend, and work it from that perspective. Which would be much more efficient for our purposes. You could make a call into the FBI office with that.

It doesn't really, at that level of reporting, doesn't, it's hard to report on the telephone. So, most people, when you do make those calls into the office, we would redirect you to the ic3.gov website. But then there's things that you would inherently, I would expect, know that is a crime and that you would naturally report to law enforcement, like some sort of major data breach, something like that, ransomware, for instance. And then there's the chasm in between the two that I'm explaining is like, okay, where do you kind of, where do you draw those lines? And I, we talked about ransomware, anything ransomware, that's related to ransomware right now would be, from a cyber threat intelligence perspective, would be good for us to collect.

So if you are aware of, like, if you, if you're dealing with a ransomware situation, you should call us immediately. Because there's a couple of things that we can help you with. One is We do track based on the different strains, if you will, of ransomware that's out there, the different attackers behind them. We do track behavior. So we would be potentially, depending on what you have going on, we might be able to feed you indicators of compromises, give you hints of places to look where, if you don't know at this point where the intrusion had started, we might have that information that we could share with you.

About that. So again, on the ransomware side, you've got that going on. So for ransomware, you say that'd be a good time to call. What if, you know, what if I have one laptop in a corporate network that gets ransomwared and I have a backup, I'm just going to wipe it? You know, do you want us to let you know, or are you saying if we need help in case of ransomware, give you a call?

So here's the thing. In that situation, I don't need to know personally. That's better better suited for IC3. Okay, like that level, give the technical info and just, just to help. Exactly, because that— it's going to get logged, it's going to be tagged.

Okay. And if that comes up again, it will— again, across the country, if it's being reported, that, that little blip will, you know, kind of be, be louder for us and we, we pay more attention to it. Uh, so yeah, certainly. Okay. And then, and then other types of incidents that, like— so I, I say one of the For a long time, one of the perceptions in the corporate world is when you call in the FBI, you kind of lose control of things, right?

That the FBI has their processes and it's going to change the flow of your incident response if you do call in law enforcement. So, what's your take on that and how do we deal with that? So the victim has a lot of control. As a victim, number one, you have to contact law enforcement. We're not going to come in and look to disrupt your business in any way.

We would make an assessment and give you some of, you know, our views as to maybe some options that you can take, but they would be merely suggestions. We'd never force you to do something that you didn't want to do. So, you have a lot of control as the victim. But you bring up a point, as I talk with folks in private sector, it's a common theme that I keep on hearing, and I could only speculate that it comes from either the movies, to be honest with you, from television and movies where this perception that the FBI is going to come in and take over and take your stuff, or It happened prior to, like I said, I've been involved in the FBI for 10 years. I've never heard of that happening.

But if it happened prior to 10 years, it might have worked a little bit differently with respect to even just the size of hard drives and computers and all that stuff. Years ago, it might have been easier for the FBI to really ask and suggest that they take your computers to do the analysis and forensics and stuff like that. Nowadays, things are so— the volume size of hard drives and such, and the sophisticated nature of what we're looking at, we tend to not want to march out of anywhere with— well, we're not going to do it on the victim side. I also should mention, I think people might conflate that with of being a subject of an investigation, right? And they might have seen, you know, the TV reel of someone, you know, the FBI agents walking out with boxes and servers and stuff like that.

Well, if, you know, let's be sure that we're talking the difference between a victim of a crime where we're going to be working hard with that victim to assist them in any way we can and also to do an investigation as best as we can versus a subject, which at that point we would have a search warrant and legal authority to seize equipment. Right. So, so what kind of— we talked about ransomware as those that— and there are all kinds of other incidents. One of the ones that you mentioned earlier is the insider threat, which is easiest to prosecute. That feels to me like one that we'd want to bring in earlier than others, or what's your take there?

Well, so the timing, we would want to be involved as soon as you, as a company, is willing to make contact with us. There's not one crime that's more— that's benefited more from being slower to report to us versus one that's faster to report to us, if that makes any sense. Because we would like to make that assessment with you even early that this doesn't seem like something the FBI would be interested in, because sometimes we come to that conclusion relatively quickly. But it's hard to anticipate where something will go upfront. So, I guess my guidance would be, if you're— I think we all know, especially those who operate complicated corporate environments, there's a threshold of So, you know, something might be moving towards needing law enforcement action.

And when that starts to, you know, that idea starts to percolate, that's really the time you should reach out to us. I fully understand that there's corporate counsel involved and you're gonna be talking internally with lawyers and so on. I've been in the rooms with lawyers and I'm not, I'm accustomed to that. In complicated corporate environments, I expect to have that type of a situation when we're doing our onsite consultation. And it's really about working as much as we can together to, again, make sure that you protect yourselves, get yourself fixed, but also help us move an investigation forward where we can go to prosecution.

At the end of the day, a real big component of when we charge is that we need to know that a victim thinks that a crime occurred and that they're willing to testify on a criminal side. So absent that, it's that old standby of something happened, like an incident in a street and there was 50 people who saw that, but nobody wants to be a witness. Law enforcement doesn't go forward with it. You know, a similar thing in the computer security realm as well. So, if we don't have a willing victim to help stand up and say that, you know, we were victimized here and this was the damages to us, then we're not going to have much of an appetite to continue with you because we know that we won't be able to bring that successfully to where we would want to take it.

Okay. What about denial of service attacks? Someone who's actively attacking one of our infrastructures, is that the kind of thing that you guys could help respond to quickly, or what do you think about those types of attacks? So that is something where we are not resourced to really help out, to be honest with you. That would change, the only thing that would, so for what we'd call, say, an average company, we wouldn't be able to bring resources to bear on that.

It'd almost be, that's just out of our lane. The exception to that would be if you are a company that's operating in something that we are, is a priority to us to protect. Like, is health and welfare affected, health and safety affected potentially, like critical infrastructure, is the DDoS going against critical infrastructure? That could change our assessment as to whether or not we would deploy a resource to help you. But again, a lot from my experience on the peripheral of companies that have been dealing with the DDoS problem is that there's the DDoS mitigation services is where they need to essentially relieve the pressure.

Yeah. So I guess I should be clear that I'm talking about that piece of it right now as far as the resources to relieve the DDoS. You're not going to get it from the FBI. It would almost be— it's just not where we're at. But from the investigative side, so when you get to a point of, all right, we would want you to share that analysis of, okay, what IP addresses assuming, you know, that this was several thousands to, you know, even a million IP addresses that were involved in the attack, we would want that intel.

Was this like an IoT botnet that was involved in doing this? We would want that. And we don't have that to start with. So that's where it's important for us to message that if, as a victim of a DDoS attack, sharing that information with law enforcement will, will help us understand who's behind that act. And also to ultimately what our goals are, frankly, is to disrupt, right?

And to, if we can apprehend, we're gonna, we're gonna apprehend, uh, those who are responsible. So that's, that's where our goals are, yeah, um, oriented towards. So the— it's, it's challenging on— I'll tell you, just from the corporate side, the conversations are, well, do you really want to bring in law enforcement? As you know, it can become, you know, a PR issue. It can become— it complicates the incident response.

Do you see negatives to bringing in law enforcement that you can talk to, that we can just kind of balance it, right, and help figure out? Because obviously your message is, you know, share lots of information, share it early. And I don't think that's generally what I'm hearing in the private side. So, I'm just kind of curious if we can figure out where the disconnect is. Yeah, no, I'd love to engage you here.

So, one of the things, just to address the PR side of things, we— one thing we're really good at in the FBI is not talking about ongoing investigations, not talking about— if you bring in the FBI, for instance, we're not going to have a press release saying that we're investigating this with so-and-so. Oftentimes when you hear that, it's usually the company making that statement is that we brought in the FBI. It's from their side. So we take it very seriously who we get information from. We protect the source of that information, who we're working with.

If you're a victim of a crime, we're not out there touting you as a victim. That's— I could be a little— it's difficult sometimes when I talk with people in the public because I could There's times where I just have to stop short of mention. Like, I'm not going to drop a name or a company that's a victim. I'll never do that. And the FBI does not do that.

It's just a bad way of carrying yourself, as well as the repercussions of that is then no one will want to share information with us if you think we're just going to turn around and put it out there. So that's the PR side I just want to address. To do that devil's advocate, trying to look at this from 360 degrees, the downside— well, I do not find— from my perspective, I honestly don't see a downside for bringing law enforcement in it because, again, you as a victim control the entire conversation and we're not going to— I'm very careful. I know the members on my squad are very careful. We're not going to put you in a position that you're vulnerable to an ongoing incident, right?

We might have a conversation and say, hey, this is what you're dealing with, and if you want to collect more information on the threat, these actors, you can keep that window open, if you will, before— like, if you're going through your incident response step, if you're still in that containment step and you haven't moved on to remediation, then I'm a believer in that just from— I guess this is more from less practitioner but more speaking with those who have done this. Is that you don't want to close the window early anyways. And I'm sure, I'm guessing, I can only guess because I don't have insight to stuff that I don't see naturally, but I'm sure from the real mature organizations that are dealing with very sophisticated threats, that's what they're doing. They're not shutting down immediately, pulling plugs and saying, oh good, it's gone, because it's not. Long way to say on that, we won't, ask you to stay vulnerable.

We can't because it puts me in a difficult position. I don't want you to turn around and say, based on my advice, you suffered more losses. Yeah, I'm not going to put myself in that position, nor is anybody in the FBI going to put ourselves in that position for you. Um, so, so that's, that's my perspective. I don't know, can you tell me more about like what the downside would— at least a perception of the downside would be?

I suspect that it's just that you're bringing in another variable, right? A powerful variable that you have to have trust in. And I think if you take it from a cynics perspective, these people have badges and guns and they weren't involved. They weren't a factor I had to consider. And I bring them in now, they are a factor.

And maybe it's based on fictional accounts of the past, or maybe someone 10 years ago had an issue. I don't know. The conversations are usually, be thoughtful about when you would bring the FBI in, right? Not bring them in every time, but be thoughtful about it that you're ready. It's a formal thing.

It's a big deal to bring in law enforcement. That's kind of what I perceive. Okay. I don't think I've seen a lack of trust. I don't— I haven't seen a lack of trust.

I've seen that there, there isn't necessarily a lot of perceived value in bringing it in because, you know, if I'm sharing information and you guys didn't have anything about it yet, well then, you know, great, you guys are getting more information and maybe down the line you help somebody else, right? But in the, in the heat of an incident, maybe that's not my top priority. Yeah, I, I could appreciate that, that perspective. And there is some truth to it. There are times where we frankly cannot divulge more information than we can.

That being said, I do think from my side of it, just knowing how we operate, I wouldn't— if I'm in the private sector in the future, I'm not going to be hesitant to share information with the FBI and be concerned if I don't get anything back, only because I can say that because I know what's going on behind the scenes. And some of it might very well be that we have no more information. Some of it might be we do have more information, but it's at different classification levels. That can come up, but I don't have a lot of heartburn about that. What I'm doing, my future self, is I'm asking the FBI, I'm providing them some information, but If there is a concern that the FBI has or more information that they could provide, you're going to get that.

Now, for every situation, most situations, I'm not going to say here that you can't expect to have a tangible result. So, that's where I think from private sector and law enforcement side, it's just You know, finding the right— that whatever that threshold of what to report is always— it's a dance. Yeah. And we're— we would want— we wouldn't even want it all, right, frankly, because we're not resourced. You know, you can't take— you can't look.

Yeah, exactly. So we would— we just want maybe, you know, the biggest fish, right? Now chasing the biggest fish is the easiest way to do that, right, is to say it. And if what you think you have is a pretty big fish, then call us in. Yeah.

And we'll work with you. And if you're like, if you're at, you know, you invite us in, right? And we can't just walk in. So one of the kind of general tips for security leaders, and it's part of the ISO standard and NIST, is, you know, establish relationships with law enforcement, you know, kind of open those channels. And ideally, you're opening those channels in advance of an incident, right?

I'm not scrambling asking someone, I'm not sending a note to Robb saying, hey Robb, do you know who the local FBI agent is? Right? I already know who it is. But from your side, while that might sound like a great idea, if everyone does it, you're probably overwhelmed with, hi, please come meet me. So where's the happy medium here?

What do you recommend we do? That's a tough one because there's a side of me that I want to be personable to everyone. Yeah, but I can't, and we're not resourced to do that. So, uh, I would say this, you can kind of get known, if you will, to us through participation in like InfraGard. That's, you know, that's something that we, we run.

So we know that's a vetted list of, of membership there, of— so we know who's comes around for the meetings and we're available to chat, right? And not for nothing, if that's all that you do, then you, you cross— you did that checkbox as far as, okay, I've— I— we could exchange business cards, right? That type of a thing. And so, so that's one way of doing that. The— I, I'm struck because I really want to say, you know, um, just come out and reach out, but yeah, that That'll be a denial of service attack of another nature, and my supervisor won't be too happy with me with that.

So, I would, for those, maybe naturally, so maybe slow roll it as you review your incident response plans. We do have people call the office and say, hey, it's more or less a cold call, but they're saying, and they're really going, they're checking a box to what you're talking about, and they're saying, hey, I just want to make sure we we, you know, this is the right number to call. Yeah. Do we have an incident? That's fine to do.

Yeah. And again, find us at events that we— the InfraGard event will be most likely where you will find an opportunity to interact with us. I will— I do try to get out as much as I can, and I know others do as well. Um, we're— we don't— it's hard to say where we're going to be though. It's like we don't have a regular, we're going to be at this meeting.

Type of a thing. But, but I think joining InfraGard is a great recommendation. I, you know, it is a vetted— is a vetted group. You can't— you don't just go to a website and pay your $20 to sign up there. There's a background check aspect to it.

But, you know, as a result of that, you get, you get some information you wouldn't get otherwise. Yeah. And so we know you by sector, and where InfraGard helps us too, it helps you. Let's say you're in the energy sector. We bin you like that, so we know that these are our energy sector participants, members, and such.

When we get threat information that's specific to that industry sector, that's the first list we start with. So we're going to get them the most timely information that we have. And I've seen it, it could be, again, it could be really rich information in the form of specific IOCs, MD5 hashes of malware very timely, and that's great to have, and that's gonna be a first look. After that, we might be going through what amounts to going through the phone book to say, okay, who else is in this sector that didn't join? And you don't— so you're just distancing yourself from getting that information.

So again, not for nothing, you're checking a box, You're getting involved with, uh, you're nurturing a relationship with the FBI. You're getting some information that's really pertinent to, to you, to your sector. That alone, um, and it— there's no membership fee that I'm aware of. I don't, I don't remember there being one. There's been a while since I joined it.

Exactly. So it's kind of— yeah, that's where it's at. Very cool. So if folks do want to reach out, if they, if they have an incident and whatever, what's the best way to get a hold of of you or the Denver office, whatever they should be doing? So I would say if you're dealing with something that needs to be addressed immediately, call the FBI Denver field office first.

And that's— what's the number? 303-629-7171. Okay. I'll put it— I'll put this in the show notes too. And the reason why you'll do that, because I've had this happen and it's You feel bad.

I might be— if you send it to me, for instance, personally, I might be on an airplane somewhere, right? Okay. I might be on vacation. I might not be checking that phone that closely. And so it could go into a little bit of a black hole for some time.

And if you have something urgent, call the number. You'll get the FBI field office, which— ask for the cyber— say you got a complaint, actually, what happened. Just say the word cyber. Yeah, just go cyber. It magically gets you there.

Say cyber. Cyber, cyber. They'll know where to route you. Just explain what you've got going on. They'll route you to the right guy.

I'm trying not to get any flack from my supervisor because if his phone goes off the hook after this, it's going to be— But anyways, a bad idea to put more work towards your boss. But nonetheless, truly call that because even after hours, you'll be switched over 24/7. Someone's going to answer that phone. You'll be switched over to— It won't be somebody sitting necessarily in Denver proper, but someone will be listening to that and they'll know, they'll train to know if you got something that really needs to be worked on immediately, they have back channels to get to like my phone and my supervisor's phone and so on and so forth. So that's where you could cover it all through just one telephone call.

Yeah. Cool. I really appreciate your time. We're over time here today, but this has been a great conversation. Any final words you want to leave the audience with?

I would just say, you know, we are part of the Denver cybersecurity, InfoSec security, network security, however you want to term it. I see myself as part of that community. This is where I make my home. I enjoy the work. I think there's— we all could go a long way with knowing each other better as far as our positions on things and how we could work together.

I really think there's opportunities where, that are not being, that might be left on the table that we both don't know about 'cause we're not talking. I'll point real quickly to an example. The finance industry has done a really good job with sharing their information with law enforcement. And that's part— some of it's self-serving, admittedly, because, you know, they want to stop fraud, they want to stop losses, they want to improve consumer confidence in using online banking, doing e-commerce, so on and so forth. You see some of that on the communication side and the communication sectors.

I think there's an untapped area with computer security companies. Yeah, in general. And I would love to to talk with the great companies that are here in Colorado doing, whether it's threat hunting, cyber threat intelligence, however you wanna term it, but if you're sitting on some information that you think can be helpful to the cause of bringing in the FBI with the intent of disrupting, dismantling groups and doing arrests, We want to have those conversations, and I just want to make people like unintimidated, unintimidated from you know reaching out and finding us. All right. Well, once again, thank you very much for your time, Jason, and well hopefully we can catch up with you maybe next year and get another update.

Absolutely. All right. Have a good one. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security. Security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.

Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes