All episodes

Holiday Special

Apple Podcasts Spotify SoundCloud

In this episode:

A look back at the best of 2017 with 11 local security leaders.

2017 was a great and terrible year

This week we interviewed 11 local security leaders to find out the best and worst of 2017. Take a sip of egg nog along with us as you listen.

  • Chris Abbey, Douglas County Schools
  • Tim Coogan, CISO for DIA
  • Steve Coury, CISO City & County of Denver
  • Joshua Foltz, CISO eFolder
  • Mike Kalac, CISO Western Union
  • Sue Lapierre, CISO for Prologis
  • Colin Mariner, VP of Infrastructure for Home Advisor
  • Lucia Milica, CISO for Polycom
  • Rich Schliep, CISO for Secretary of State
  • Bryan Becker, Director of Security at Kroenke Sports & Entertainment
  • Sam Masiello, CISO Gates

Please come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript7683 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 47, which is a very special episode. This is our holiday special.

Happy holidays, Robb. Happy holidays. Happy Christmas and Hanukkah and Kwanzaa. We were just looking up Kwanzaa and getting some details. Yes.

Kwanzaa, for those who don't know, is a holiday that was created in the mid-'60s to celebrate West African folks who've come to North America and kind of give them an opportunity to celebrate along the holidays with other folks. Happy Kwanzaa. Happy Kwanzaa, everybody. And actually, as we record, today is Festivus. I assume you know this.

I do. And I have brought my list of grievances that I plan to air. We won't do that on air, but I appreciate that. The feats of strength will, of course, follow the— yes, follow the airing of grievances, of course, around the Festivus pole. My feat of strength is consistently lifting my glass of eggnog to my mouth.

It gets harder and harder the more times we refill it. Yes, exactly. All right. Well, so we're not going to do much and we're not going to do any news this week. We're not going to do any jobs.

But we did want to do a little bit of trivia. So we have a winner from last week's trivia question. If you remember what the question was, we were doing who, which former guest used to work at the Mayo Clinic? Answer, of course, is James Carder. And the answer was given us correctly by Blake Ketchum.

Blake, congratulations. I know Blake is getting a free shirt. Thanks to Andre Gator for sending that. Early Christmas present for Blake. Well, probably a late Christmas present.

So I guess when it gets there, maybe an early President's stay present if it— if the shipping's not too fast. But we did have a trivia question for this week, and this one you guys really need to put on your thinking caps. So of Santa's reindeer, you know, Dasher and Dancer and Prancer and Vixen, Comet, Cupid, Donner and Blitzen, and Rudolph. Rudolph, of course. Which of the reindeer has the strongest connection to Colorado and why?

So you need to take a few minutes and think this up. Spoiler, there is no correct answer. So you let me know what's the best reason that any of these reindeer has for being connected to Colorado. We expect some very creative answers. Yeah.

So in the spirit of the trivia, we also have a different topic for the show this week. Yeah, exactly. So we will not be having a single feature interview. The Colorado Equals Security CISO Christmas party It was a couple weeks back, and at that party we did some interviews. Some of the folks that were there, we asked them a number of different questions, some about 2017 and some about 2018.

And, you know, we've compiled those answers and we're gonna be airing those after this. And we'll go through and talk about some of those topics with you guys as well. We have 11 folks that we, that we interviewed, and we'll just kind of introduce you to who those people are. So Chris Abbey, who is a security specialist at Douglas County Schools, is one of the folks with us. Tim Coogan, who is the CISO for DIA.

Steve Corey, who you've met before, the CISO for the City and County of Denver. Josh Foltz, who is the CISO for eFolder. Mike Kalac, the CISO over at Western Union. Sue Lapierre, who is the CISO for Prologis. Colin Mariner, VP of Infrastructure for HomeAdvisor.

Lucia Milica, who's the CISO for Polycom. Rich Schliep, the CISO for the Secretary of State. Brian Becker, who is a director of security at Cronky Sports and Entertainment, and Sam Masiello, who's now the CISO over at Gates Corp. So we talked to the 11 of them, asked them some questions, and what we're going to do is we're going to throw it over to the— to those questions, let you guys hear their responses, and then we'll give you some feedback on that. Exactly.

Here comes the first question. Here we go. What was the best thing that happened this year in information security? I would say probably the best thing to happen in this year in information Security is a new security-focused law that came into effect here in Colorado in terms of student data and transparency and security. So what was the best thing that happened this year in information security?

Potentially blockchains, I guess. We'll see what happens with blockchains in the future, but I think blockchains coming to light potentially will solve a lot of problems for us moving forward. Steve, what was the best thing that happened in information security this year? Well, the best thing that happened was ransomware in our local communities. Because it helped raise awareness.

Hey, did you— were you able to set up a tabletop? Excellent. Yeah, so we made connections with local community leaders. They shared their experience and their, you know, the issues that they had, and it helps everybody get better. And they cooperated with your company to build a tabletop exercise, and in the end, everybody's better off.

What is the best thing that happened this year in information security?

Bitcoin. Bitcoin's created an interest in cryptography and security. All right, Mike Kalach, let's talk a little bit about 2017. Tell me, what is the best thing that's happened for you in security this year? The best thing that happened to me was not in information security.

It was actually getting my oldest daughter off to college. See you, Boulder! She's a Buff and everything's great. Congratulations. What was the best thing that happened in information security this year?

That the demand is out there and People are looking for security professionals, and I think that it's getting more visibility because it's mainstream now. Okay, Colin Mariner, we're gonna talk a little bit about 2017. Why don't you tell me, first of all, what's the best thing that's happened for you in the security area in 2017? Best thing that happened to me in the security area in 2017 is becoming a part of an organization that cared about security. Security and it actually mattered.

Lucia, let's talk about 2017. What's the best thing that's happened for you in security this year? I will say for 2017, the best thing for me personally is the free marketing. All of the bad stuff that's happening is giving us some marketing? Absolutely.

What was the best thing that happened this year for you in security? We ran a very smooth election this year. We implemented the first state in the nation to implement risk-limiting audits. So that we can guarantee that our voting machines have not been hacked and that we are accurate. So you're telling me that I can have confidence that our election went the right way this year?

From a— it was high fidelity, I guess I mean. Absolutely. Brian Becker with Cronky Sports. Let's talk a little bit about 2017 in security. What was the best thing that happened this year in the security world?

So in my mind, the best thing that happened in the security world was people are getting more aware of the security problems in the technology, that it is actually going to have to be a regular piece of their daily life now. They have to think about it, they have to be more open about it. We got a lot of feedback from our C-level execs on even after Equifax and these other hacks, like, what do we have to do that helps us build momentum for our program? So it's kind of— it's starting to become more in people's forefront of their minds despite the pain that they might have went through with being affected in a breach or something like that. Sam Masiello, let's talk a little bit about 2017.

What was the best thing that happened in information security this year? So I think the best thing that happened this year is just the amount of awareness that has come into people's minds relative to, you know, the importance of security. And that's not just individual people awareness, like social awareness. It's also within organizations as well. It seems like organizations have really come to really realize what the importance of security is to their organizations and why it's important to their organizations and why it can help protect them from potentially being in a very bad situation like being in the news.

All right, so there's some good answers about the best thing that happened in 2017. Alex, what was the best thing that happened for you this year? You know, I think from my perspective, it's that cybersecurity is in the mainstream now. We're seeing more and more emphasis put on cybersecurity, both in the government, in industry. Executives, leadership are all saying that cybersecurity is something that's really important.

Of course, that is because lots of bad things continue to happen. So it pushes it more to the mainstream. But I think nonetheless, it's something that's going to be good for the industry. Yeah. Well, and that kind of goes hand in hand with mine, which is, you know, now if someone asks me what I do for a living, I used to just say I'm a computer guy or I'm an IT guy.

And now I can say, oh, I do cybersecurity. And they all know what that means. You know, hand in hand with that, we are, we are maturing as an industry. It's slower than we'd like, but we're going from being that that black magic back office to, to really having repeatable processes that someone could come in and understand at a higher level. Yeah.

Focusing on risks and all the risks that come from cybersecurity as opposed to just pointing at things. Oh, that's really bad. Some bad stuff could happen over here. Yeah. Or, you know, there's that guy in the corner with the hoodie on who does, who does stuff that's really important.

You know, now we know what that guy does, right? Exactly. He still wears a hoodie and maybe he doesn't shave and maybe he doesn't take showers as much as he should, but at least now we know what he's doing. Well, you know, you can always pick the right people out. So let's go throw back over to the, uh, to the guests and, and ask maybe a little bit, a little bit worse question, right?

Not so much fun. What was the worst thing that happened this year in information security? IoT seems to be, uh, great for the world but bad for security, and I think it's only going to get worse. What was the worst thing that happened in information security this year? Ransomware in our community.

Because it totally devastated some of our metro partners. And, you know, in some ways we were able to help them, helped our people, helped our self-image that we could help other communities that were having challenges. And overall, it was really a good thing for both in and out. The best and the worst all came from the same incident. What is the worst thing that happened this year in information security?

Bitcoin wallets. They've lost a lot of Bitcoin. Now, what is the worst thing that's happened this year around security? The worst thing that's happened in security, actually it's a little more personal to me, is that my boss left Western Union. So he was the greatest boss I ever had.

I'm not sucking up because I don't have to suck up anymore to him, but he was, he was a fantastic boss, supported my program 100% all the time, and I'm sad to see him go. What was the worst thing that happened in information security this year? Well, let's see. I think that Equifax, of course, was a huge breach that took everyone, I think, a little off guard, expecting that they were going to be secure and they weren't. Well, what's the worst thing that's happened this year then?

The worst thing is just overall trying to rush to get to GDPR compliance. So now, what was the worst thing that happened in security this year? We obviously had some major breaches, you know, between Uber and Equifax and lots of others. We have a lot of catch-up to do. We've learned that companies are still not applying best practices and that we're kind of behind the ball.

What was the worst thing that happened in 2017 or in the security world? So clearly the most obvious thing was the Equifax breach. We are going to be cleaning up that mess for the next decade, if not more. Just because of all the depth of all the data that was stolen. I guess that people just don't— that they don't know the full extent of what can be done to be used against them.

That they'll be hopefully not learning the hard way. So what's the worst thing that's happened in 2017? So I think that's kind of a— I kind of segued my previous answer into this one, right? I think if you think about the worst things that happened this year are— think about the breach at Equifax, right? And the impact that that had on so many people.

And the potential impact that it still may have on so many people going down the road. When you think about all the type of information that was stolen, how it could be used to steal identities. And so when you think about what the potential longer-term impact is and how it could potentially continue to impact people for years and years down the road, I look at that as being the, the kind of landmark event for this year. Great answers again. Um, a little more depressing this time, but, uh, but great answers.

Robb, what do you think was the worst thing that happened in cybersecurity this year? Well, as evidenced by our earlier conversation, the worst thing is you and I have both given in and started to use the word cyber, which we still don't know what that means exactly. Very silly word. Doesn't mean anything. We've been information security for the vast majority of our career, but the media loves cyber.

So we're cyber. We are the cybers. We're the cybers. Obviously, a lot of real bad stuff happened this, this year. But I'll stick with my cyber answer for the worst thing for the year.

From my perspective, I think the worst thing that I saw this year was, was NotPetya. And I say that because this is the first time when we really had some significant losses that came from some sort of malware. You know, we had FedEx and Maersk and Merck, all of them suffering, you know, hundreds of millions of dollars in losses because This essentially took their systems out of commission. Yeah. And we get to see the details from their public filings, right?

I know Maersk and Merck were both $300 million plus impact for the— I think it was in one quarter. So really, you know, multibillion dollar impact across the industry. Yeah, pretty bad stuff. Yeah. Well, obviously some big breaches this year as well.

We're going to go ahead and throw it over to our guests again to talk just a little bit about that and we'll come right back. Which breach do you think was worse, Equifax or Uber? I would have to say Equifax because none of us opted in for Equifax. So I think we were all kind of forced into that breach. What breach was worse, Equifax or Uber?

That's a great question. Probably Uber.

You know, Equifax was bad, but I don't really— PII has been lost for a long time, so I think that information has already been floating around. The thing about Uber is that it was kept under wraps for quite some time, and I don't know, I don't really have any tolerance for that. Which breach was worse, Equifax or Uber? Well, I think Equifax because it was a place where I never gave them my data. They took it.

Because of the way that the business is, it's like I had no choice in that. Whereas Uber, I was able to decide to be their customer. Equifax, I never signed up for that. Which breach was worse, Equifax or Uber? Equifax, because they didn't have permission to have my information, but they still chose to lose it.

Which breach is worse, Equifax or Uber? I would say I'm going to answer this in both ways. Equifax from a volume, you know, $145 million. But on the other hand, Uber, from the continued, uh, just bad behavior, and then this just to top it off. So I'm picking Uber.

Which breach was worse, Equifax or Uber? That's a clear answer. The worst technical breach is Equifax, just because that is your core business. But by far, it was worse for Uber. It damaged an already damaged reputation.

Almost entirely disputed their reputation in the industry and just killed any ability to hire talented engineers within that organization. They were already going through so many other events that were public events, and the fact that they didn't just own up to the issue really, really shows what kind of organization that is. Now, which breach was worse, Equifax or Uber? Oh, that's a tough one. Hmm.

Uh, I will say obviously the, the CISA Uber behavior is by far outrageous in the security industry, but in terms of impact, um, I will say, um, Equifax. So that, that leads me to my next question. Which is worse, Equifax or Uber? I think Uber for sitting on it for so long. Which breach was worse, Equifax or Uber?

And why? Uh, to me, Equifax by a long shot. Uh, if I think about, you know, the types of information that were stolen between Equifax and Uber, uh, at the end of the day, I mean, did Uber do something bad by not reporting the breach to regulators? Yes, of course. Right.

Uh, but the type of information that was stolen, again, when you think about that longer-term effect, far, far, uh, worse with Equifax than it was for Uber. All right. So some takes about Uber versus Equifax. Alex, what's worse, Equifax or Uber? I think it's got to be Equifax.

Um, the biggest reason being that none of us opted into Equifax having our data, so there wasn't a whole lot we could do about it. And then of course the sheer volume that was lost. Yeah, there's some positives from the Equifax breach. Um, the fact that, you know, this assumption that we've had that we can trust data that, you know, that is about your past, you know, we can trust asking a question like, which car did you own in, right, 1993 and you, you know, check, check 5 options and that tells me that you're really Alex. That's been total BS forever.

Uh, and maybe now there's a little bit more scrutiny on it. Yeah. I've been using those, um, what seemed to be more obscure, um, shared secrets. Yeah. Uh, now those, those are out the window, right?

So I have a little different perspective. It's not to say that I think Uber is worse, um, but I think Uber was extremely educational for us. About the, the PR cycles and what happened around that breach. The first narrative that came out is, hey, there's a new CEO in. He heard about this breach and was, you know, up in arms that it didn't come out.

And, you know, they cleaned house. They got rid of their CSO. They got rid of a bunch of leadership and security because, because they didn't report this breach. And then there was a drip and drab that came after that about the details, right? Oh, it looks like somebody, somebody found a vulnerability and reached out to Uber and used that, you know, said they wanted money.

Uber pushed him through a bug bounty platform, paid him, and I don't know if you've seen the details, they actually got access to the guy's laptop so they could do some forensics analysis, see what he did with the data that he got. Um, so they, they went pretty far down the road of getting some assurance. Now they did the wrong thing. They should have, they should have notified. Clearly they did the wrong thing, but the, the narrative, the way it came out was, you know, these guys are the devil.

And maybe they— maybe they're not the devil, right? Maybe they just made a bad decision at some point. Yeah, it's definitely— I don't think it's as bad as it seemed, um, in terms of people's— the protection of people's data. I don't think it's nearly as bad in terms of the way that they handled it. It definitely is still bad.

Yeah, it's an interesting story. Uh, I think it's probably a more educational story than Equifax, whereas Equifax, you know, they didn't patch a system and You know, in a few months, if there's an enterprise in the world that doesn't have an unpatched system after a few months, I'd be— I'd love to see it and go shake their hands. I mean, I think Equifax was very educational as well, too educational in the way that you should not handle a breach. Yeah, that's it. They did just about everything that they could possibly do wrong, wrong.

PR perspective, PR perspective, everything. So, you know, you look at what they did, and when you have a breach, just do the opposite and you will probably be okay. The insider trading you know, the feel of insider trading, the fact that they bought an identity, identity monitoring company after they found out about the breach, but before they announced it. Just all of these things looked really bad. Yeah.

You know, putting up a brand new website with a brand new domain that looked like a phishing site and then tweeting, tweeting out, tweeting out an actual phishing site. Yeah. All right. Stuff. Well, let's go ahead and throw it back over for the next question.

So, Chris, what accomplishment are you most proud of this year? I guess a lot of the work that we're doing with our high school interns program and stuff like that. So getting kids excited about cybersecurity careers and getting them connected with businesses. What accomplishment are you most proud of this year? Being a father to my 3-year-old son, first and foremost.

I think I'm Dad of the Year, and I don't think anyone else would agree with that, but that doesn't matter. You know, I've hired a lot of really, really, really great people this year, and I'm very proud of that. My team at DIA is probably the best it's ever been, and I think it's just going to keep getting better. What accomplishment are you most proud of this year? Well, this year, believe it or not, we are finally launching multi-factor authentication, and I feel like, you know, I know we're maybe one of the last people carrying the torch into an already bright room, but I'm happy to carry that torch.

What accomplishment are you most proud of in the last year? I think, actually, the reorganization I did of my group, and finally assigning what I now have a deputy CISO as part of my organization, which has really given me some ability to kind of a little bit more breath. What accomplishment are you most proud of this year? Probably that I passed the CCSP, so I'm pretty happy with, with that. Nice, congratulations.

Thanks. What happened in 2017 that you're most proud of? That I'm most proud of? Well, let's see. So I moved into a new job a few months ago.

That's a you know, good achievement in and of itself. But at the same time, I've been able to do a lot of new things in this new job. A lot of culture changes have been brought into the company relative to not only my introduction to the organization, but also we've had some other leaders on the IT side that also came into the company around the same time that I did that really instituted a lot of change in the company. And so I'm very proud of that and a lot of the changes we've been able to introduce there. Also very proud of a nomination that I received earlier this year for, uh, to be finalists for CISO of the Year through the Colorado Technology Association.

So from a personal perspective, you know, a very honoring, uh, very honoring achievement and something that, you know, from the standpoint of how that process goes about and how you're nominated by your peers and colleagues, you know, to me that was a very important, um, aspect of my year. What accomplishment are you most proud of this year? Um, our, um, ISO 27001 certification. You guys finished certification this year? Absolutely.

And that was quite a large scope certification. So it was corporate services and engineering, which was huge. What's the thing you're most proud of that happened in 2017? So the thing I'm most proud of from a personal level, my son was born. And then we're really excited about that.

But then my, from a professional level, is that I set some really big stretch goals for KPIs and stuff at work and what we wanted to achieve. And I felt like we made some big-time steps towards meeting those. So hopefully I'll make us more secure, quote unquote, if we can. So a lot of good things happen at the corporate level that I'm happy about. What happened in 2017 that you're most proud of?

That I'm most proud of? Well, let's see. So I moved into a new job a few months ago. That's a, you know, good achievement in and of itself. But at the same time, I've been able to do a lot of new things in this new job, a lot of A lot of culture changes have been brought into the company relative to not only my introduction to the organization, but also we've had some other leaders on the IT side that also came into the company around the same time that I did that really instituted a lot of change in the company.

And so I'm very proud of that and a lot of the changes we've been able to introduce there. Also very proud of a nomination that I received earlier this year for— to be finalist for CISO of the Year through the Colorado Technology Association. So from a personal perspective, you know, a very honoring, uh, very honoring achievement and something that, you know, from the standpoint of how that process goes about and how you're nominated by your peers and colleagues, you know, to me that was a very important aspect of my year. A lot of pride there in those answers. Robb, um, what accomplishment were you the most proud of this year?

You know, I think obviously done a lot of great stuff at work, really proud of ISSA where we've, you know, where I got to hand that off to James Johnson and James is doing a good job growing that and we're still You know, ISSA Denver is still the largest in the world. But, you know, for me, I'm really proud of what we've done in the Colorado security community, just the visibility that we've been able to raise, you know, working with groups outside of security and helping bring together the organizations that are already doing it. It's been a lot of fun, and I'm proud of the progress we've made. There's still a long way to go, but we've come a long way already. Yeah, I'm, I'm really proud of Colorado Equal Security as well.

You know, going in, I don't think we really knew how things were going to go. It might have been just, you know, us talking to each other and no one listening, which would have been okay too, which would have been fine. You know, I enjoy your company most of the time, but, you know, it's really gone well. But I think one of my great accomplishments from the year was finishing up my term on the ISSA International Board. It was sort of the culmination for me.

You know, I started out many years ago volunteering for the Uh, ISSA Denver chapter, uh, was on the board and then president and then international board. So kind of taking that all the way through to the end has been a really cool experience. Yeah, very cool. And I know that, I know they really liked working with you and, and not, weren't real happy that you didn't run again. Yeah.

You know, I got plenty of stuff to do. Yeah. So, all right, well, let's go ahead and throw it back over to the interview here. What was the worst vendor behavior that you saw this year? Saw some, uh, professional services engagements with some vendors where they just would not accept any responsibility for their actions.

So, uh, we followed the practice of failing quick. What was the worst vendor behavior that you saw this year? I, I think the, the worst behavior I have is probably not on a particular vendor, but it's on the, uh, organizations that help sponsor them. Um, and I feel like sometimes we are sold as commodities with emails and phone numbers, and it's gotten me to the point that I don't answer my phone unless I know the phone number, because most of the time it's somebody I don't want to talk to. What was the worst vendor behavior that you saw this year?

I had a vendor kick me out of an event because I asked if I could bring my wife to a black cat event. What is the worst vendor behavior you've seen in the last year? I would say it's the emails that I get where it's, uh, reply with 1 if, uh, you don't care, reply with 2 if you're asleep right now, reply with 3 if you're on some beach and you don't really want to hear from me again. I love those. What was the worst vendor behavior that you saw this year?

The emails that I received from vendors are becoming more and more Strange and off the wall. It's— I almost now, you know, I hate to say, I almost now read them instead of delete them right away just because, you know, I'm comparing them to other folks that get the same ones that go, okay, my gosh, is that worse than the last one? I mean, that kind of behavior from a vendor is just, you know, It's just annoying because I keep on deleting, deleting, deleting, and they keep on coming back over and over and over. Colin, what's the worst vendor behavior you've seen in the last year? I'm not sure if anyone here has worked with Oracle in the past.

However, when you're willing to spend and budgeted for and signed off on $150,000 for a single license for a single set of servers, And they don't call you back for 2 months. That's the worst vendor experience I've ever had. So please, please let me give you my money, and they say no. They say we'll get back to you in 2 months. Yes, it's been great.

What's the worst vendor behavior you've seen this year? Security vendor? I will say it, not to name vendors, but the worst thing is there are a couple of vendors out there, they basically just write the tag and don't provide any customer service. They're not willing to negotiate. They're basically, this is my price, deal with it, take it or leave it, which I think is absolutely not customer-oriented.

What was the worst vendor behavior you saw this year? So there's a lot of it. People won't leave me alone even though I tell them to leave me alone. People that are trying to sell us a product that clearly isn't a fit for us right now, or maybe never will be, and they're a little bit overly aggressive on it. So I would say over-aggression and just stop calling me, right?

So that's the, the worst one, I would think. Sam, what's the worst vendor behavior you saw this year? Unfortunately, it's the same vendor behavior I see many years, right? It's the, uh, it's the cold calls over LinkedIn, it's the spam emails that aren't compliant with CAN-SPAM, so I don't even have the opportunity to opt to unsubscribe. Subscribe from them.

I mean, it's really getting to be ridiculous, the amount of just cold outreach you get on a fairly regular basis. So one thing I tell people, I get the question quite often, like, what do we need to do to be better communicators with the CISO community? How do we get into the companies that have CISOs? And to me, the thing I tell them the most is establish relationships of trust first, because if I'm going to talk to a vendor, it's going to be very likely because I have a trusted friend who's in the community who recommends that I speak to this person or speak to this vendor. I'm going to speak to that person light years before I speak to someone who just cold calls or somebody who sends an email or somebody who sends an email to my CIO who then forwards it to me, right?

If you want, if you want to be able to get into, get my attention, then the most important way to be able to do that is be able to have established relationships already in place. Because again, the cold calls just don't, just don't work. And for me anyway, somebody who's been involved in the anti-email abuse community for a long time, I'm never gonna respond to spam. I'm never gonna accept spam anyway. So it's just, it's just not a good tactic.

It doesn't make you an effective marketer, and it certainly, at least from my perspective, isn't gonna work on me. So contrary to how that might have sounded, we do like our vendors here, right? Oh, of course we do. Yeah. So Alex, what's the worst vendor behavior you've seen this year?

You know, for me, I'm not gonna call out any vendors in particular, but The thing that I hate the most is when people that I don't know that are trying to sell me something send me blind calendar invites. Hey, I'm, you know, I wanna talk to you. Here's a meeting invite for 2 o'clock on Tuesday. Never spoken to you before. It's on your calendar now.

Yeah, I've seen that a few times and that bugs me too. So for me, there's this tension between vendors who come in with the intention of trying to ask me all about my program, Which is, you know, exactly how they're trained to do it. But why in the world would I tell every random person who sends me an email about my program, right? And then trying to get them to talk about their product. And for me, if I'm interested in a product, before I tell you about my program, I'm gonna wanna understand kind of what you guys do.

And so I generally ask vendors, tell me about what you do, tell me about your offerings as a starting point. And I'm amazed by how often the salespeople cannot tell me what they sell. They just can't answer, you know, some, some relatively basic questions about where this would fit for me and how I would incorporate that into the— I'm sure they can say a lot of buzzwords though. It's, hey, it's all in the cloud and there's AI and we use big data. And then let me get my technical guy in here to talk about, right, you know, how you might actually get value from this solution.

Right, exactly. All right, let's go ahead and throw it back over to the interviews. What was the best information security event that you attended this year? I would, I'm partial, but RMISC was a great first event that I went to here locally. It was a great networking opportunity.

What was the best information security event that you attended this year? Honestly, it was anything that Colorado Equals Security puts together. But really, no, really, no, really, no, I'm just kidding. I attended the Aviation ISAC ISAC annual summit this year, and that was really good for me because so much of the events that I've attended are just, you know, general information security, cybersecurity type events, and this one was really targeted to aviation, and it was really great sitting in on, you know, we did a tabletop exercise with the whole aviation sector, and it It was really interesting to see how tightly coupled we all are, how, you know, we're all part of the same supply chain, product chain, what have you, and how one problem in one area has effects in the whole sector. And it really is allowing me to see my work at the airport on a much larger scale.

So I really learned a lot from it. What was the best information security event that you attended this year? I know you go to a lot. Being your speaker and things like that? Yeah, so I had, um, I went to the Secure CISO event, um, and initially we were, we had lots of, uh, very negative things to say about it because first off, they promoted themselves as having like over 100 CISOs attend.

I counted 3, uh, so it was kind of disappointing from that standpoint. However, it's a very pleasant experience with the vendors. Uh, their keynote speaker was was phenomenal. I don't remember his name right now, but he was the guy that hacked the first Jeep Cherokee. And they had a moderator who was a former NPR person.

I got to talk to him personally. And overall, my experience was pretty good. But I, in the end, I'm like, I don't know if I would go again. But it was really a hard thing to say. But that Secure CISO event, they hosted at a very posh event that was at the the Four Seasons Hotel.

It was very attractive that way. They provided Uber transportation. They did all the right things that way, but there weren't very many CISOs there, so I was kind of disappointed from that standpoint. What was the best security event you've been to in 2017? I just attended an IANS one that was pretty good.

It was in LA. It was a little bit tighter-knit community in the LA community. But I've never really met a lot of those folks. So it was really good. We went over a lot of metrics and some other areas that was, and I was kind of a guest speaker there too.

So it was a pretty good event, IANS. What was the best information security event that you attended this year?

You know what, there've been a lot of them. You know, RMISC is always a great event to go to. You know what, women in the women in security, you know the kickoff for women in security and each session after that has been fantastic. What was the best information security event that you attended in person in the last year? So the best one this year has been the Colorado Security Happy Hour that that we're at tonight.

It's been fantastic. The group of people here is fantastic. So if you are in the information security world, talk to Robb, talk to Alex. Be a part of this, be here when you can, because it's worth every minute. What was the best information security event that you attended in person this year?

Personally, I always love RSA. RSA is a good event, and I think there's a lot of good content there. What was the best security event that you attended this year? So the best security sessions I saw were the opening RSA keynotes. We had a DoD guy and a Navy guy and Homeland Security, and then there's some other good demos that I saw.

But the best event that I went to was an Optiv event. They had Brian Krebs there. They had some really good sessions, especially one of the better sessions I saw was an Optiv guy gave on culture and how we can help persuade the enterprise to have a better security culture and how to ingrain that into the— actually how the whole enterprise works. What was the best security event that you attended this year? So we have something that is put on, so Gates is owned by a private equity firm, and every year they put on a summit of the CISOs that are in their portfolio.

And to me, that was a, that was a great event because it not only allowed me the opportunity to speak to a lot of the various CISOs that are in that portfolio that I don't normally get access to, at least face-to-face. We do have a Slack channel where we talk on a fairly regular basis, but you know, that face-to-face communication is so much more important. So if I were to think about all the various events I went to over the course of the year and the content and just the importance of building not only a network, but also the type of security talk that we had there and the level of that security information, that was probably the best one. So those are some great events. You know, I'm a big fan of information security events, Robb.

What was your favorite event of the year? Well, you know, there's been a lot of great stuff here in town, and I love to focus on what we've done in Colorado. I think maybe my favorite one this year was SnowFROC. They had great— they made a great choice for their keynote speaker. Who was the keynote speaker, Robb?

I think it might have been the CISO from Ping Identity. And, and who might the CISO for Ping Identity be? It's hard to remember. Oh yeah, it's been a while. Not a very memorable person.

But it was a really great event. And certainly, you know, I like the size of that event. It's a little bit smaller at, you know, 300 people maybe at the Cable Center down at DU. Anyway, great stuff. Jim Manico came out.

Vince Grimard talked. I'm going to forget a whole bunch of folks who were great speakers, but they're a really good slate of folks they had there. And keeping on the local scene, it's hard for me not to say Rocky Mountain Information Security Conference. You know, I was the ISSA chair of RMISC for 6 years. So it's a little bit of my baby.

And I think it was a great show again this year. We had Cal Fussman speak. He was great. Lots of good speakers there. Josh Blue, of course.

How can you forget Josh Blue? You know, Made a few people uncomfortable, which was even better. Yeah, great, great comedy and a great way to finish that event. I'm also going to cheat and sort of double up here. The event that I liked the most that was not in town, I was able to attend the Avanta Global CISO event, which was down in Phoenix this year.

Really great event. I really enjoyed that a lot. Lots of great content there. Well, great. So that is the end of this week's show, right?

All the questions we want to go through this week. So we're going to go ahead and put together another episode for you guys next week, kind of talking about 2018 planning. A couple of reminders for folks, if you do have an answer for our trivia question, the reindeer question, send your email over to info@colorado-security.com. We also have a mailing list you can sign up for if you want to get these emails with our, with our show notes in your inbox every week. And there's a new Slack channel.

Alex, have you been on the Slack channel? I'm always on the Slack channel. And you can get the Slack channel, there's a link to that on the website also in the in the show notes. You can find how to get access to that there. Awesome.

Well, that— you ready to go have Christmas with your family? I am. Happy holidays, Robb. Happy holidays. Talk to you soon.

Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes