All episodes

Sue Lapierre, CISO at Prologis

Apple Podcasts Spotify SoundCloud

In this episode:

Sue Lapierre, CISO for Prologis, is our guest this week. News from: Qdoba, Marketo, Convercent, OverWatchID, Swimlane, NCC, DirectDefense and a lot more!

Meltdown and Spectre are kind of a big deal

Not exactly the quietest start to a year so far, huh? This week brought us one of the biggest vulnerability disclosures we've seen in quite a while. Plus some other news like... someone paid how much for a burrito? Marketo's got a big presence in Denver. Convercent, OverWatchID and Swimlane all raise money. NCC has new leadership and a new plan. And DirectDefense provides some insight on the processor mess.

Come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12760 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 49, the week of January 8th. Alex, the year has not started quietly, has it?

It has not started quietly, Rob, at least not from a security perspective. This week we obviously had a number of big issues with the Spectre and Meltdown bugs that are affecting most processors, at least some of them affecting most processors. Before we dive into all the details, we'll talk a little bit about Spectre and Meltdown. Let's do a couple reminders. Number one, we have a mailing list for the show.

If you're not signed up, Go out to colorado-security.com, enter your email address at the bottom, and we'll give you the show notes each week in your mailbox. That's all we use it for. So don't look for any sales pitches or anything good like that. Also Slack channel. Yes, come join the Slack channel, growing every day.

A lot of great discussion going on in there. Yeah, especially this last week as we've been talking about the happenings over the first week of the year. You know, we started off with an 0-day dropped on New Year's Day about, Mac, a privilege escalation on Mac, right? Yep. I thought that was kind of cute and, you know, not a huge deal.

And then a day or so later, we got a bigger 0-day that came out, right? Yeah, so a couple vulnerabilities, or I guess there's more than a couple vulnerabilities, but 2 names and they're cute icons. I like the Spectre one that looks sort of like a Pac-Man ghost with little hands there. But Meltdown and Spectre Um, these are essentially design flaws in, uh, the way that the chips have been built. Yeah, I— so I, I appreciate, uh, there's a lot— a link in our show notes to Daniel Meesler's kind of breakdown about these 2 vulnerabilities, or at least these 2 attack types, and it shows the difference between them and what the different impacts are.

If you're not real familiar yet with this, I think that that's a great place to start. We also have a link to a blog post from Direct Defense, a local Colorado company, that did a nice a nice post about this right away, and I appreciated the, the speed with which they came out with the post. It is easy to hold off and wait as you try to get more information, but they at least gave, you know, here's what we know right now, uh, really early, uh, after the, the post came out. I'll just say, you know, this is not the kind of fix that we're able— we're gonna be able to go do some patches and everything's all better, right? This is a fundamental hardware issue on the processors in the vast majority of computing systems in the world.

From the servers you have in your cloud provider to your data center, to your laptops, to your phone in your pocket, where they're all basically impacted by this vulnerability. Yeah. Some of them more than others. I think there are a couple of them that do affect basically every processor that has ever been made. Yeah.

Which, you know, some of that is interesting if you think about, you know, IoT devices and, you know, all the things that have been out there for a long time that probably are never going to get fixed. Right. Yeah. Over the, over the next month or so, I expect most enterprises that have a security team are going to mitigate the impact within their data center and probably within their laptop force. But that leaves all of the rest of the world, right, that is not going to be mitigated quickly.

And when I say mitigated, it doesn't mean we've reduced, we eliminated the risk, right? We just reduced it because number one, there are probably ways to get around it outside of the OS patches, ways to impact this, vulnerability that we're not aware of yet. And number 2, there is a, there's an impact from this, right? The, the ability to share memory in the processor, which is what's led to this vulnerability, allowed for a lot of improvements for speed. Exactly.

A lot of, you know, performance increases that we're not going to see. They say there's somewhere between like 15 and 50% impact to performance based on these mitigations. Yeah. And I've seen various reports on that where, You know, sort of those higher numbers are probably, you know, edge cases where under certain workloads you might have some issues like that. Well, so we don't know yet what the impact's gonna be.

I think it's safe to say that this is the biggest impact we've had in years. You know, Heartbleed kind of seems maybe roughly similar to this. And certainly the amount of work that it's putting the security teams under is quite high. Yeah, I mean, and obviously there are already some patches that have come out. I expect after the OS patches, we'll probably see some, you know, firmware updates and other things like that.

To fix some of the lower-level systems. But lots of work for everybody. In case you didn't have enough work to do, yeah, now you got to do this. So yeah, moving on to the next story. Alex, what is the most you've ever spent on a burrito at Qdoba?

Oh, at Qdoba, I don't know. I'll say $10. So Apollo Group recently spent $305 million on a Qdoba purchase. Holy cow, that's a big burrito. It's a big burrito.

So of course, Apollo Group is not the people who own University of Phoenix. This is a different Apollo Group that owns Chuck E. Cheese, and they've recently purchased Denver-based Qdoba from Jack in the Box, who owned them previously. Yeah, I guess burritos are big business. Congratulations. Now, obviously, Qdoba's queso has been pretty one of their hallmarks of success, and Chipotle is trying to steal that, I believe.

I'm I'm gonna let you in on a secret. I'm a diehard Chipotle guy. Yeah, but I have to say that I do like Qdoba's queso better. I don't like either of their quesos, honestly. And I prefer Chipotle as well, but I think neither queso is is all that good a queso.

Hacienda Colorado, they do a good queso. Yeah, give me a real queso fundido any day. I'll take that. Next on the list, Marqueto. Which is, strangely enough, a marketing company.

Yeah. They moved an office here to Denver. So they are a California-based company, Bay Area, and they are moving the bulk of their workforce, including their CEO, here to Denver. And they're calling it an HQ2, kind of. Right.

Amazon coined the term, but these guys like it too. Yeah. I mean, I think it just, again, goes to show we do have great talent here. We are not as expensive as the Bay Area. We have space where people can get offices and there's great quality of living.

So you start to see more and more companies like this moving here. So for those who don't know Marketo, it's kind of the biggest player in the marketing operations world. You know, similar to how Salesforce kind of runs the CRM world, Marketo is the biggest one in marketing operations. And they're also owned by Vista Equity Partners, which is the private equity firm that owns Ping Identity and Granicus and Vertafore and a few other Denver-based enterprise software companies. Cool.

Obviously Vista's taking people to Denver. Uh, so next, uh, Optiv pulled their IPO paperwork. So I think it was 2016, um, Optiv was deciding whether or not they were going to be sold, bought by private equity, or they were going to go for IPO. They were kind of going down a dual track. And then of course they were purchased by private equity, uh, but they still had that IPO paperwork out there.

So it's, it's It was being reported that they finally pulled that back. Yeah, so I remember one of our first shows, we talked about Optiv doing the IPO and then getting acquired by KKR, excuse me, doing the IPO paperwork and then being acquired by KKR. They have now officially said they're not going IPO anytime soon. That doesn't mean they can't change their mind and go do it, but they'll have to file new paperwork when the time comes. We have a few different companies who've actually taken funding in the last month or so.

So biggest on the list here is Conversant. They raised $25 million. Now, as a reminder, Conversant's the company that does ethical and compliance training. Obviously, been big business for them lately with MeToo and the way Uber breach went and all these other things that have been happening. They seem like they're growing very quickly.

Yeah, I think it is. It's probably mandatory now for all Hollywood-type companies to have the Conversant training. Yeah, probably so. It should be. You hear, I listen to Colorado Public Radio podcast every day and They, they had an interview with some lawmakers from Denver talking about how now the, the legislature in Colorado is going to require— number one, they're hiring an HR person, and they're gonna have a bunch of sexual harassment training for those.

Yeah, there had been some issues in the legislature as well. Either 3— I can't remember, 3 or 4 lawmakers who have been accused of sexual harassment. Yep. Also, Overwatch ID took in $2 million in funding. They're those guys, identity access management company.

I think you're— you've talked to one of the guys there, right? Yep. So, uh, Cam Williams, uh, we have an interview pending with him, so that should be up here pretty soon. Yeah, I think in the next couple weeks we'll hear about what they do in a little more detail. And then finally, Swimlane, who we've talked about a lot over the last year, they took— they have another round of funding, uh, a smaller one at $1.35 million, a little bit smaller than the last fund they took, which was, which was, uh, $3 million about a year, a little bit over a year ago.

Cool. Uh, so there was an article in the Colorado Springs Business Journal about the National Cybersecurity Center and the new faces that they have and their new plans for this year. So if you remember, I interviewed their CEO and COO for the show, maybe it was like last April or May, I can't remember exactly when. They've turned over both of those positions. They have a new CEO and I don't think they have a COO, but the COO has left that was there previously.

I think it's kind of a— well, it's not a very well-kept secret that NCC has not really achieved the goals that they've been going for, right? They had some missions that they were trying to accomplish. Clearly, they haven't accomplished those. So, you know, they were going to try and be an incident response center. I think that that, that as a, as an initiative has gone to the wayside, they're not going to go after that right now.

They're really trying to define exactly what they are going to be as an organization. Yeah. And Vance Brown, who is the former CEO of Sharewell, which they do ITSM software, ServiceNow competitor. He is the interim CEO down there. I think he's going to do that for a little bit and then they're going to try and find a permanent CEO.

I will say that, you know, the, the description of what he envisions them being was a worldwide leader in security and blockchain, right? Kind of an interesting add-on rather than just security. They're talking about being a blockchain leader. I don't know what that means exactly. Yeah, I don't know exactly either.

And Those things do not exactly seem to go together. Yeah, it could be a marketing buzzword or maybe there's something going on there we don't know about. And then finally, I want to say congratulations to Steve Winterfeld. Steve was the information security officer for Nordstrom Bank and he was traveling to Seattle half the time to do that job. And he recently just started at Charles Schwab down in Lone Tree as a managing director running their threat intel group.

So congratulations to Steve. Yeah, good job, Steve. Welcome back to Colorado. Welcome back. Welcome back.

And I'm sure your wife is very glad to have you home. Yep. And then finally in the news, our feature interview today is with Sue LaPierre, and conveniently today is Sue's birthday. This is your birthday song. It isn't very long.

You know what? I think that the patent— or not the patent— the copyright finally ran out on the birthday, you know, happy birthday song. So I think we could actually sing it if we want to. I love it. I love it.

And not have to pay royalties. Let's not do that.

Anyway, happy birthday to Sue. Happy birthday, Sue. Good timing. Glad that you're, you're finally 21. Yeah, go out and have a drink.

Good stuff. All right, let's jump over to trivia, Alex. The question that we have— we have 2 questions we need to give answers for this week. Exactly. So 2 weeks ago we asked the question, which reindeer has the strongest Colorado connection and why?

And I'm gonna look at you and say, what were the best answers we got for this? Yeah, so I've got a few here that we got that we wanted to note. So first, Andre Gaeta, who actually is the sponsor of the trivia contest, so he obviously can't win. But he said Donner. He had to change his name from the original Dunder because Harwig's in Steamboat Springs serves a Dunder Burger.

Reindeer Relocation Protection Program. I like it. That's creative. So that's a good one. And then Rob Winter, he replied, while Cupid's name would be best tied to Loveland, Rudolph is the correct answer, as his shiny red nose is the only thing that can compete with Blucifer's glowing red eyes.

I like, I like the Cupid Loveland combination. Yeah. And so that's, that's of course the, the big blue horse at the airport with the devil eyes. So those are our runner-ups, right? Who's our actual winner?

Yeah. So Tom Hagel with ProtectWise, he said Cupid. I picked Cupid because of Cupid Mountain. The 555th highest mountain in Colorado, the 13er east of Loveland Pass. Also, it's going to— also, I'm going to hat-tip Dunder, the original name for Donner Reindeer, that obviously second call out of that, because Michael Scott from The Office, who worked at Dunder Mifflin, moved to Boulder in the show.

It's a little bit of a grasp, but the Cupid one was good. Congratulations to Tom. Congratulations, Tom. We'll get you in contact with Andre and you can get your swag. Yep.

All right. So then we have last week's as well, which was, what was your best Christmas gift? And the winner for this one is Rob Winter, who was one of our finalists for the last one. Rob's best Christmas gift for the holidays was he was told by his general counsel that they do not— they're not impacted by GDPR and don't have to go through the compliance fun that the rest of us do. I have to say that is probably a better gift than anyone else got for Christmas.

Yeah, absolutely. Great gift. All right, so I will go ahead and ask a question for this week. I want you guys to name 6 security startups that have formed in Colorado since 2013. So 6, there's more than 6 of them we're aware of.

I've got more than 6 on a list in front of me. If you come up with one that's not on my list, that still counts. So give us 6 security startups that have started since 2013 here in Colorado. Ready, go. All right, all right, so let's move on to events.

Obviously we have our event calendar on the website. You should go out and check that. Rob's been busily updating that for 2018, getting all the new events up there. So if you want to know what's going on in Denver, check that out. First on the list, ISSA Denver is having their January chapter meetings on the 9th and 10th.

Congratulations to ISSA, who recently passed 700 members here in Denver. That's— it's huge. It's been the largest chapter for quite a while, but continued growth. I think there's just obviously the chapter's providing a lot of value out to members. Yeah.

Yeah, congratulations. On the 10th, CyberGRX has an open house for their new office. They moved into a new headquarters and they'll let you come take a look at it. And I think that's really about all of it from the next couple weeks. But we're— we got a couple on here that are still close.

CSA is 2 weeks out. So CSA is having their January meeting on the 16th. Yeah, ISSA Colorado Springs has their January meetings, their dinner on the 16th and their lunch on the 17th. Uh, DENSEC is doing their North meeting on the 18th. And then Optiv, we've talked about this for the last couple of months, they have their solution and program focus group really talking about AppSec.

This is a chance for you to share your insights on how do you do an AppSec program and learn from others who are struggling with the same thing. And this is happening on the 18th. Apparently the 18th is a popular day because ISACA is also doing an event that day on GDPR. So if you want to know about GDPR, you can go to that. And not to be left out, SecureSet has an event on the 18th as well, which is their Cybersecurity Expert Series.

I think they had a speaker identified who ended up sliding, so I don't know who it's going to be for that week, but I'm sure it'll be someone good. They're usually pretty good meetings. Definitely. So that really is all the events. Uh, let's move on to jobs.

Opus Bank is hiring a Senior Information Security Program Manager. Schwab is looking for a director of risk analytics. That sounded interesting. Wells Fargo is hiring an IT senior lead auditor in their infrastructure audit team. Payments Processing Corporation, which is, I think, part of First Data, is looking for a senior systems— excuse me, senior security engineer.

SecureSet is hiring a cyber threat intelligence instructor. Sounds like fun. Yeah. IQ Navigator is looking for an information security analyst. And that's actually Julie Chiquillo.

They're gonna be reporting to her. And I actually reached out and asked. She actually has 2 jobs, that one, someone who knows compliance and looking to maybe make a move into security. And then they also have someone that's going to be their client front end for all of their audits and requests from customers. So if you want to deal with customers on their security program.

There's a job for that as well. Pearson is hiring an information security risk manager. Xcel Energy is looking for a senior security governance and controls analyst. Uh, Ping Identity has a security intern position available that's going to be on my team, and it's, it's actually not open till the summer. So if you know someone who's in school right now and when, when they're, you know, looking for a summer break, something to do, it's a paid internship.

You get visibility across all of our security teams and hopefully provide some value on both sides. Uh, Hain Celestial is looking for security and compliance director. Nice. Do you know Hain Celestial? Um, I think that that might actually be Celestial Seasonings, like the tea people.

Really? See, so my wife would love it if I would go work there, come home with tea. Yes, I believe that that is the tea folks. Nice. BP is hiring a security architect.

Remember, we were talking about how they moved their— British Petroleum moved their North American headquarters from Houston to Denver last year, and it looks like we're starting to get some jobs as a result of that. And LogRhythm is looking for a Director of Product Marketing. All right, good stuff. Well, that's it for jobs. We do have our feature interview, as you mentioned, with Sue Lapierre.

Sue and I sat down a few weeks ago and talked about how she got to be the CISO for one of the largest companies in Denver and, and really what she's planning to do here in 2018. Awesome. All right. Well, thanks, Alex. We'll talk to you soon.

Thanks, Rob. Hi, this is Mike Kalax, CISO at Western Union. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

This is take 3. I am Rob. I am sitting in my office at the Ping headquarters in Denver, and I have a special guest today who's going to introduce herself so I don't mess it up a third time. So, hi, I'm Sue Lapierre, and I am the Vice President and Information Security Officer at Prologis. Sue, what has been the most impactful thing that's happened to you at work this year?

If you want to go back beyond this year, that's fine too. Something that's impacted you, hopefully for the better, but if you have— if you want to go another way, that's fine too. Wow, that's impacted me. Yeah, most impactful.

You know, it's hard to say what one thing has impacted me, so I'm gonna kind of lump it all together. I started with the company a little over 3 years ago, and they did not have a security program at all. They, you know, maybe had a couple of, you know, people doing some firewall stuff or something like that, but I was hired to do 2 things. First one was to build a security program, And second one was to create a secure, aware culture. And I think it was actually this summer that we actually, you know, my team sat down and actually at the beginning of the year when we were doing our goal planning and everything and looking at all the things that we've accomplished, and we just like, we've rocked it, you know.

3 years we've built this powerful security program, and we've actually made a huge dent in the security-aware culture. We have, you know, executives that are actually coming to us and saying, oh my gosh, I, you know, did X, Y, and Z, help me. And, you know, you always want to— when I build a security program, I always want to make sure that, um, that we're memorable and that people come to us rather than us going to them. And I think that, you know, we hit that this year. Is that people are starting to come to us.

Now, Prologis is not a tiny little company. Probably some people here listening, all they know about you is that you have a building near DIA, right? Yeah, a bunch of buildings. Yeah. Could you give a high-level summary?

What does Prologis do? Yes, we're one of the world's largest— well, we are the world's largest owner-operator and developer of industrial real estate. So logistics and big warehouses, but we're also kind of a financial services company because we have real estate investment trusts as well. So we're in 19 countries. We are a $2.5 billion company.

We've got $77 billion in assets under management, and we have 1,500 employees. And your headquarters is here in Denver? No, it's actually not. Oh no, our headquarters are actually in San Francisco. Francisco.

Pier 1, right next to the Ferry Building. Oh, really? We're actually on the pier. We're actually at the end of the pier, so it's a very cool location. And yeah, so is there a— I mean, I know you're here in Denver.

What kind of departments or functions are here in Denver? We used to be considered kind of the operational headquarters, so IT is based here. Our accounting department is primarily here. Primarily are legal, you know, back office, HR, that kind of thing. Okay, and then what's in San Francisco?

Executives? Executives, yep. Okay, smaller office with, with the bigwigs. Yeah, so beautiful office though. Yeah, I'm sure.

Yeah, it's a good place to have a beautiful office. Well, let's go ahead and start over way earlier, right? Okay.

I assume that before Prologis you had some kind of educational background and maybe some experience in the working world as well. Could you kind of start me? How did you get here? Well, it was a long time ago. Yeah.

And I always say I didn't come up the way that normal CISOs grow up. Okay. And I know that there's been kind of some scuttlebutt discussions, you know, in the security realm about, you know, people's backgrounds and when they, you know, when they graduate from college, you know, what they graduate in. Well, if you graduated in the 1990s and you didn't have a security degree, I'm really disappointed because, because, you know, there were so many of those degrees available. Well, actually go back a little further, but, you know, um, but the thing is though, when I grew up, yeah, um, you know, I have to bring up, you know, I'm a female, and at that time there were things that you did and you didn't do.

And, you know, I was raised in, you know, good Midwest, you know, location. And, um, I got a liberal arts degree. And so, um, what was your major? Education. Education, sure.

Yeah, with a music minor. I mean, I first started going to school to actually have a music major, and, you know, that didn't work out very well, and so switched it to education. Uh, if I— you know what, if I was to do it all over again today, I probably would not even do that. I'd actually go into like meteorology or engineering or something like that that I never even considered at that time. But, um, so, but I, you know, went into education and, um, I did student teaching in Germany and, you know, it was really cool experience and came back and, you know, nobody could— they were like, what do you mean you did some, some work in Germany.

I don't know, at that time, you know, I can't call Germany, you know, that kind of thing. And so, um, I had to go into a different route and went into financial services, did a lot of different things. Um, I've always had the opinion that, you know, I could do anything, so I just tried lots of different things and, um, did back office You know, supervising call centers and, you know, managing different departments within a financial services organization. And then finally, I was on the side, I was actually running ski trips with the ski club at the company I was at. Where were you living at the time?

Minnesota, so Minneapolis. And so I took 100 people, you know, skiing. I, you know, coordinated everything and led them to Austria and Germany and took other people up to Banff and, you know, the South of France. And then I thought, well, heck, I could do this for a living, you know. So I up and quit my job and I went to travel school and I moved to Colorado and said, hey, I can do this.

And then found out that you make nothing as a, you know, travel agent. But I was able to go to lots of different places. And then I was like, well, I could be a tour guide. And so I went to school and did that and, you know, then decided that I can't make any money and then went back into financial services and got into, you know, stand-up training, things like that. Delivering training.

Delivering training, yeah, and then, you know, I was getting burnt out and I finally was looking at that time, it was an actual job board, you know, and looking at a job and somebody came up and go, you and said, are you interested in that? And I said, I don't even know what it is. And it was BCDR coordinator. And she was like, you'd be perfect. You know how to talk to people.

You can write, you know, procedures. You're perfect. I'll hire you. And that's how I got into business. What company was it?

Disaster recovery. Janus Funds. Okay, sure. Yeah. I think I know you were at Janus.

Yeah. I just talked with Joe Siso over there. Dr. Joe? Yeah, Dr. Joe. That's right.

Very cool. So when did you— were you at Janus previous in doing the training there before you went to BCDR? I was doing training and then I did BCDR. But at Janus? At Janus, yeah.

Okay. Yep. And what years were you there?

A long time ago. It was in the '90s. Mid-'90s? Mid-'90s, yeah. Yeah.

And I don't remember anymore. So BCDR is a fantastic way to get into security. Yeah. And it's a kind of a— from a technology perspective, it's a lower barrier to entry, right? Because what you have to know is process and communication and organization, and, and not so much, you know, need to know how a firewall works, you know.

Well, that's the thing is, as I was doing that and I moved on to like Invesco and, um, and still doing BCDR, um, you know, I, I knew because of the stuff that I had done with managing back office, I knew the business. So I knew back office quite well. Yeah. And so it was very easy for me to figure out scenarios and test those and then pull in the technical piece for the DR rather than just the business continuity. And so, it happened to be that, oh, well, if we have somebody hacking into the system, that's just another scenario.

And so, I just started learning that and it was like, okay, well, you know what? I see a direction here. And so, I just kind of started along, you know, that line. So this is, this is a lot like— it's different that I've never heard a story quite like this, right? But it's the same idea, which is you go do something that you're good at and you find a way to turn that into the career you're going to eventually go to.

Maybe you weren't planning security at any point, not even remotely, but that's how you, you got there. Not by saying, hey, I'm gonna stop and go become a security person. It's I have these skills and here is something I can do with it. And you change your job a little bit at a time until it all of a sudden adapts into this new fantastic opportunity in security. Absolutely.

So you said you left Janus and went to Invesco? Yep. And did BCDR for them as well? And, and same thing, did you leave Invesco and go somewhere else? Actually, I was getting ready to be, um, boy, I think I was— they were downsizing and Their parent company was kind of, you know, moving things around.

And so I actually put together a proposal and said, you know what, you know, the company was Invescap, and I put a proposal together, got in front of the right people, and said, you need to hire me, and this is why. You know, I can do this for all of your entities at Invescap and not just Invesco. And so, and, you know, they picked me up and said something Sounds good. And so I spent a little bit more time with them before they wanted me to move to Atlanta, and I said, no, don't think so. I'm staying in Colorado.

And so I moved on from there. Where'd you go next? I went to a company called Policy Studies. Oh, so yeah, that's another place where Joe was, right? Joe was at it.

Yeah. Yeah. So I went to Policy Studies, or PSI is what we called it. It's now Maximus. Is the company that took over PSI.

Oh, I didn't know that that was related to Maximus. Okay, now they're out in headquarters in New Jersey or something, right? Somewhere on the East Coast. Yeah, it's all capital Maximus. It's not, it's not, it's not capital M, the whole word is capital.

Yep, yep, that's exactly right. Okay. Yeah, so, so I got hired by them to do, um, started out BCDR, and, and I could just see, you know, hey, we need, you know, some security and Um, started doing some other things along the way. Um, we brought in, um, Marlene Behm, and she's— she was way ahead of her time, and the company wasn't quite ready for everything that— I mean, she, she was a visionary. She knew exactly what we needed to do from a security aspect, and they weren't ready for it.

And so, um, so I was able to kind of, you know, move that. And Dan Collander was there as well as Dr. Joe and Keith Rella. And so we, you know, I— they've— they moved on. You know, they were again better than what we needed at that time, really. You know, they can't— you know, you have to— you have to look at and see what the business is ready for.

Yeah. And you kind of have to move along with the business because Because if you're, you know, you're just gonna beat your head against the wall if, you know, the business is— you're trying to do something, you don't have the support and things like that. So I stayed, built that program, and got into, you know, I just tried to look and say, okay, we need to do some IT audits, and went and got my CISA. And, you know, looked at, we need to do some privacy, and got my CIPP. And, you know, my CISM.

You know, add on as, as I needed. So, so you have a, you have an alphabet after your name now? I do. I, I absolutely do. Yeah.

So I like it. Um, so how long were you there with Policy Studies? 6 years, almost 6 years. Okay. And that gets us into like the mid-2000s, 2000, 2000, uh, something.

You know what, I actually, you know what, I need my resume to, you know, I don't You know what, those are, I don't even have to think, remember those, right? I mean, that's kind of purged in my brain. As long as I've got it written down on a resume, I'm good. So what was next? So I went from there to, I loved that job actually.

It was really great, except I was really burnt out 'cause we were doing so many things. I was doing physical security with them as well. And PSI was a really interesting company. It was outsourcing to state and local governments. They did child support enforcement and workforce and subsidized children's health insurance.

And so I loved it. I mean, we, we had offices around across the U.S. and doing physical security. We had a hurricane in Florida. I was able to, you know, we like totally— I ran the renovation of that, ripping, ripping it guts or gutting the side and, you know, redoing it. Yeah, it was, you know, so that was a really cool job.

So by the way, I looked you up on LinkedIn. You've got my resume on it now. 2005 to 2011 year with PSI. And now, and I'm not going to ruin the suspense, but where did you go next? Guess what I did?

I just walked down the street and got another job for, um, I went to Intrawest. Yeah. And so, uh, Intrawest, they have like the least intuitive name for what they do. I know, right? For those who don't know Intrawest, could you give a quick highlight?

Sure. Um, ski and resort company, um, competitor to Vail Resorts, I assume? Yes, yes. They've— they're kind of in transition now with some, some other things I don't know all the details with, but at the time that I started with them, they actually were headquartered in Vancouver, Canada. And, um, the CEO said, you know what, let's— you know, they, they just got done doing a Whistler kind of spun off on their own, and the biggest holdings that they had in the U.S. was they ran Winter Park and they owned Steamboat.

Okay. And so they moved headquarters here to, to Lodo, and except what they did was they outsourced their entire IT department. Really? So they basically rebadged, you know, another company came in and rebadged the whole IT department but stayed in Vancouver. And so, they hired 5 of us, CIO and 4 others, I was one of them, to run the IT department.

And so, I came in as the security person. And I said, okay, so, where are the security people? It's like, there weren't any. And, you know, it was like, well, you know, we have an outsourced, you know, contract with this company in Vancouver. And so you're gonna have to figure that one out.

So how did that— I'd love to hear your take on having, you know, outsourced versus internal. Yeah. Um, do you— did you have dedicated security staff in the outsourced, or was it just IT people that you were telling them how to do their job in a secure fashion? How's that work? It was a little odd, and, um, it was— it ended up being a negotiation.

That, um, there was a misunderstanding as to whether or not there was going to be a security person or not. So I actually had to negotiate to get a headcount with the, um, with the outsourcer or the, the vendor and, um, and get someone that could actually assist. And at the same time, I started looking for, you know, somebody else to, to help out. Ended up being able to have the vendor pick up one of my previous security guys, Joe Lowe. And so Joe was able to come on as contract, and I'd already been working with him at PSI.

So it was like, Joe, I need you to help out. And so in the 3 years that I was there, we basically, with the other— with my peers in IT, management, we actually tried to level it out to make that right balance of what's outsourced and what's insourced because we needed to have some specialized skills to actually be part of, you know, the company. And then, you know, those commodity kinds of skills, you know, were outsourced. And so we went from completely being outsourced to being a little bit of a balance. You know, we actually were kind of like 10%, 90%, and ended up being about 30%, 70%, 40%, 60%.

I think security is an interesting thing. As I would generally— my first answer, insource or outsource for security, would be, oh, definitely insource. But it's not, it's not that easy, right? Like, we probably don't all insource our penetration testing, right? Most companies will hire a third-party penetration tester.

Um, maybe you don't insource security operations. Maybe you have a, you know, an MSSP you work with. Um, you know, there's all kinds of different point things that we will outsource. Um, but I think fundamentally you can't outsource the caring about it, right? And, and as the CISO, of course we're the, the throat to choke in terms of the one who has to care the most, but we can't care equally about everything.

And that's why you need people inside who care about it for this area and for this area. And really, there has to be that hybrid because otherwise it's all just basically sitting on the CISO's attention. Which one did you remember to think about this week, this day, this hour? Yeah. Again, you have to look back at the business and see what they're willing to provide to support that security program.

You have to have a bench somewhere else. It's interesting. I, I, I've been on the record in the past of saying, you know, I— yeah, the question being is, you know, is an MSSP ever a good thing? And I think, well, you know, communism is a good thing in theory. Just, you know, in practice it doesn't work either.

And that comparison there— yeah, I, I don't— well, I, I've never seen an MSSP that, that I think works well, right? Yeah. In theory, it's a really good idea because they can scale better. They're better at it than I can get, than I can hire internally. They should be able to deal with the talent shortages more easily by training people up because they're at a bigger scale.

But then the reality is there's just not this alignment with the business, and you lose visibility, communication. You lose them caring. It's just so hard to manage the MSSP. I'd actually love to get— if anyone's listening and has had a really good experience with an MSSP, I'd love to hear the story, like what worked well.

I have outsourced management of our EDR to— actually, I'll even say it— a local company here in town, Red Canary, who I think does a great job with it. But the reason I don't bundle them is because they do one really narrow thing. They'll only do this. They'll only watch our EDR deployment, and they can do that well. And as soon as they start adding 5 other features, I bet the whole thing falls apart.

And I've told them that, at least just don't add anything else, because even when I ask you to add more because you do a good job, you should say— you should tell me no, because we're going to keep doing a good job for you instead. Yeah. Anyway, that's— well, no, ramble, you know, talking about like my current position. And again, you know, one of my objectives was building a secure, aware environment. Yeah.

You can't do that when you're outsourcing, you know, some of the— you have to have people that, you know, um, are memorable, right? That, you know, when someone from a department looks at, at me, I want them to think security. Yeah. And, um, so that— and again, you can't do that when you're outsourcing everything. Yeah.

So let's go ahead and jump. You made the move over 3 years ago from Intrawest. Yeah. Yeah. Over to Prologix.

What, what was the motivation? You know, obviously career progression, all that's great, but, you know, was Was it a new challenge? Anything you want to share about that? That's a really loaded question, actually. And you didn't know anything about it, did you?

No, I didn't know. There was actually a very specific reason why I left.

The CIO that hired me, Mickey Nelson, was fantastic. She ended up leaving the organization, and they brought somebody else in. And, you know, throughout my whole career, and it's been been a, you know, lengthy career. Um, I've always been— had people— I've been— I received a lot of respect for the things that I've done, and I've never had any issues. Unfortunately, the person that they brought in, um, you know, to be quite honest, I don't think liked women.

And so, um, really, I had no— got no respect, basically. And I had a very a very difficult time, and I kept on thinking, oh no, this is gonna be, you know, I'll win him over, or I'll, you know, oh, he'll see what I can do. And I was doing, you know, bringing the company to PCI compliance, and, you know, like, okay, when I hit that, you know, this is— everything's gonna be great. And you know what? It still didn't happen.

And yeah, it wasn't just me. I mean, it was, you know, a number of individuals, and I thought, you know, I can't do this. This anymore. I've got it, you know, for my own sanity and my self-worth, I got to get out of here. And so, so I, you know, I wanted to go to a very successful company, an international company, and I like building things.

I like building security programs from scratch, and I had that opportunity to do that at Prologis. And so, you know, I've had a great experience there, and immediately, you know, I look back now and go, oh, I I should have left a long time before that. And that's why I always, you know, I'm, you know, whenever the women in security from ISSA, you know, they're like, hey, can you help out? Absolutely, because, you know, I've had that experience and, you know, don't want to have that again and don't want anyone else to have that. Yeah.

Well, I want to dive into women in security, but I want to finish just a little bit more about your career pathing. Prologis, you came in there, looks like 3 years, 3 months ago, if LinkedIn is any guide for me. And you walked into a place without a security program, and you told me that you want to build a security program and you wanted to build a security culture. What was step one? What do you do?

And I think I'm just thinking for people who are making the change, maybe they're getting their first security leader position, or they're the only security person at a company. What's the first step you do in a new company? You need to listen. You need to go out and you need to meet the people in the organization, and you need to talk to them, and you need to listen. You ask questions and listen, and don't come in trying to, you know, I'm making, you know, I'm gonna make my mark, and I'm gonna do this, I'm gonna put this in place.

You need to figure out what's in place already and what are the pain points. And I always look too at, you know, what compliance, you know, needs are there. That always is helpful because, you know, it's kind big stick if you need it. And then you can go from there. You can say, well, I noticed that you've got this piece of compliance and, you know, are you having issue with this?

And you really do need to sit down and just listen before you make any changes at all. And then, you know, and that also helps to, you know, build your relationship with those individuals too. Then you have to, you I always look at right now, I mean, the perimeter is— is there a perimeter? Yeah, the perimeter as a moat around the organization no longer exists. Exactly.

So, 4 years ago, so a year before I started, the company actually had a cloud-first vision. It's like, okay, everything we're doing is cloud-first, cloud-first. And so, I had to come into the organization and look differently and go, okay, this is not gonna, you know, my, the things I did in the past, you know, with everything on-prem, that's not going to work in this organization. So I had to look at things differently. And again, I had to not just the business, I had to look and talk to people within IT and go, okay, what are you doing?

And tell me about this and tell me about that. And why are you doing it this way? And why are you doing it that way? So I could have a better base so that when I made a decision. I had it, you know, it was a good decision that I made.

So, and security doesn't, you know, sometimes we fall a little behind, you know, when the IT department is moving ahead, we need to be right there in lockstep. Is that right? Lockstep. Lockstep. And making sure that we're securing whatever they're doing at the time that they're doing it.

So, you know, I Jump ahead to, what was it, 4 years ago, cloud-first, 3 years ago I started, 2 years ago we closed our last data center. Everything's in the cloud. And so everything that I've had to do, I had to look differently and think differently about how I'm doing it. And I couldn't use the products and services that I used to use. I did everything all new.

So I, I suspect that many people listening will be very interested in how you're doing that. I, I think you and I have talked about it. I also have gone down a similar path. As to whatever detail you're, you're willing to share, whether it's, you know, just a philosophical secure security, uh, defense in depth, or if you want to actually go into products, I'd love to hear how do you do security in a perimeterless you know, cloud-first environment?

So I guess my philosophy is that, again, it kind of goes back to, like, your compliance and all of that. I look at the data first. Sure. So because you don't have a perimeter, because it used to be that you would look at your perimeter and you go, okay, I got my firewalls in place, so like, you know, I'm going outside in. Yeah.

I actually look at it inside out. Yeah. Because I need to look and see or do you have specific compliance requirements? And if you are, or if there's, you know, compliance, privacy, and, um, and then look at that first and look at the data and where the data is, because you can't do everything all at once. You've got to focus on something.

So we actually look at data first. Where is it? How am I going to secure that? And, um, you know, our, our viewpoint is that you should be able to get to any of our applications, any of our data on any device anywhere. So any device, any data, any device anywhere.

You've got to make sure that you are protecting the data. So if you can do that, then, you know, you know, I'm not saying that you're not going to put, you know, some basic things on, but, but that's the look on my face. He's like, what? I don't believe you. I've had that.

Actually, it was funny because I was talking to Tyler Warren, my senior security architect today, and having this conversation with— I remember going to a couple of CISO dinners when I first started at Prologis and was talking about, oh, I'm looking at this, and everyone was like, yeah, yeah, uh-huh, sure. What do you mean it's not working? It's like, no, that product doesn't work in my environment. It was like, yeah, sure. Truly, that's exactly what it is.

And you have to, you know, have to search, but really we look at the data first and making sure that we're securing it. We log everything. Everything. So could we— I want to define cloud a little bit. Absolutely.

So cloud can mean infrastructure as a service, platform as a service, and I think we can kind of bundle those 2 together for the sake of conversation. On the other side is software as a service, where we don't really get our fingers into, into, into the infrastructure and the security of it. When you say cloud-first, which of those do you mean mostly? All of them. We have all of it.

So your security posture has— your security plan, defense-in-depth strategy has to be quite different for an infrastructure as a security offering where, you know, someone like AWS gives you an EC2 instance And, you know, you're just, okay, they wash their hands of it. Here you go, do whatever you want. Versus Salesforce, where you have a few, you know, levers and knobs that you can, you can adjust to get your security the way you want it. But, you know, you really don't have all that much flexibility with it, right? You're correct.

Yeah. So focusing on the infrastructure as a service part, what are the, what are the kinds of— you mentioned you're going after data, but assuming that there's sensitive data on this particular, you know, VPC or, or system we're talking about. What do you do to secure that in, in a, in a, you know, cloud-friendly way? Um, that's a great question. And you know what, actually, Tyler's the guy to ask that question.

So I always have a belief that I hire smarter people than me. Okay. And, um, so But to, to try to, you know, I'm not the technical person, I'm not going to get into the details. Yeah. Um, but, uh, you know, you have to look at, you know, um, we love— because we're, we're kind of on the edge, we love to also work with, um, our service providers and our product providers and be the beta testers so that we can, you know, if there's a know, brand new, you know, cloud firewall, guess what?

We're going to be on it. You know, if there's, you know, anything, anything new like that, we're like going, we want to be first and we want to test it because we need it and there's nothing there for us right now. Very cool. AWS is coming up with everything, by the way. It seems like every week there's a new— I don't know if you guys are AWS shopping, you don't need to say, but if that was one of your vendors, like they're going to have a solution for you next week if they don't this week, right?

Well, they're gonna— most likely. What is it, their Las Vegas, you know, re:Invent is? Yeah, the week after Thanksgiving, I think. Exactly. Yeah, they're going to be, I'm sure, you know, um, probably presenting a, you know, promoting a few new things.

There's a couple new things that are coming out there. One of the interesting ones is around, uh, application-level denial of service stuff. Anyway, um, Priorities for you next year, 2018, what are you gonna go after? DevOps security. So we're at the point where, you know, again, starting from scratch, we've done everything in the last 3 years.

And so this is one of the areas that we really need to do a lot more. Are you guys a CI/CD shop? Continuous integration, continuous deployment? Basically, you know, making little changes that go out to production immediately? Or do you guys bundle them up and have traditional releases every couple weeks?

So, okay, so it's a little different again, okay? Because we don't have the traditional, um, we don't have a traditional development shop as well. So we have a platform that we develop on. Yeah. And so it's, it's a cloud platform.

Yeah. That's— we develop on, right? And, um, our developers, we have very few that are on staff. And, you know, a lot that are, well, a lot that are outsourced all over. And so, so one of the challenges is how do you get, you know, those individuals trained to do what we want, to develop in a secure, you know, manner.

And, you know, you go back to contract management and vendor management and making sure that it's in the contract that they have to go through specific training before they can actually work on our products. So security in your DevOps process. And what else? What else is 2018? Anything else you want to talk about?

That's really the biggest one. The other one is GDPR. We're in a number of countries in Europe, And we are sitting back a little bit, allowing our legal counsel in Europe to do the analysis and let us know what they want to do, and then we'll be coming in. We've been working with them pretty closely. I have a governance risk and GRC manager that was Cynthia Summers that was just over in in Europe last week and working with all of them.

And so they're like, hey, come on over and help us out, because, you know, they're trying to figure it out as well. I'm— as soon as we stop recording, I'll talk to you about this in more detail. All right, so now I really want to hear community involvement. You know, you mentioned Women in Security. I think that's one of the, the neat things that we've been, that we've been able to see come out here in Denver in the really this year.

It's only 6 or 8 months in, not even 8 months in, and it's already, you know, such a huge success here. Can you just talk about any exposure you've had to that group and, and any thoughts you have there? Uh, the Women in Security, um, you know, uh, I've been to all the meetings. Uh, so, um, you know, Sarah Avery, if she needs something last minute, you know, hey, I need a speaker or, you know, panelist or whatever, you know, I'm happy to help whenever I can. Just because I think that it's a great group.

I was at a user conference a few weeks ago, and I was looking around the room. I was at a couple of different sessions, one that was an executive session and the other that was like an analyst and an administrator section, and I counted how many women besides the the actual product and company. And in the executive, I was the only one. And in the other 2, there were like 2 or 3, and that was it. And it's like, okay, there's something, you know, there's out of balance here.

And so I always think, you know, I go to the Women in Security and the first meeting, it was like 130 people, right? And I kept thinking, where were you when I was just at that user conference. So, you know, I wanna get people, women— It's probably a little bit self-perpetuating, right? That let's say there's 15% of people in security are women. It might be 11%, whatever it is.

Call it 15% for the sake of the conversation. If they go to an event and there's 15% there, maybe they think this isn't for me. And next time, 10% of women show up. And the next time it's 5%. And that might be part of what we're seeing is it looks even lower than it is because they don't feel welcome.

Yeah, I don't know if that's true, but it's a hypothesis, right? Yep, that's true. Yeah. Yeah. So ISSA also has a mentor program.

And so when was that started? Almost 2 years ago. Okay, so, so I have a mentee. Yeah, Beck Larson. And Beck's great.

Beck's at Coalfire. Yeah. Yeah, and so we've, you know, we've, you know, I don't know if the, the mentor program was only for like a year, but we've like continued. Yeah, that's great. So, you know, and it was funny because, you know, a lot of, um, as we were talking and, you know, meeting and everything and talking about things, it wasn't about security things.

It was just about, you know, basic, you know, hey, how do I— I've got this problem. I've got a, you know, I've got an employee that, you you know, I need some help on, or whatever it might be. And, um, so it was just— it wasn't just security, it was just mentorship, right? Just getting to know another person and, and helping them out with where they're going. So I'll put in a couple plugs here.

Number one, if you, if you are interested in being a mentor, you go to the Denver ISSA website and sign up to do it. There's, there's a form out there. And same if you want to be— if you want to be mentored. I would say don't be afraid to reach out to the people who you want to have mentor you. It's very infrequent that someone not only asks but then follows up.

I personally get requests maybe once a month from someone who wants to be mentored, and I always say, yes, I'm happy to help you. Here's what I'd like you to do. Kind of write up what you want to accomplish from this. You know, let's make a commitment. And then they always go away because they they were hoping that by asking me that I would magically, you know, give them everything, right?

So, you know, ask the person you want to talk to and come prepared to do some work. Like, the relationship's meant to be driven by the mentee, not the mentor. Yeah, and I think that, I mean, the mentor gets a lot out of it as well. So it's not just the mentee. I mean, it's funny because as Beck and I would talk and she would ask me a question, I would have to think back and I would pull, you know, a learning that I had from many years ago and go, oh man, I should be doing that now.

You know, just that remembering of, you know, yeah, that's really good advice. I should use it myself. And, you know, that kind of thing. So you get a lot out of it. So I— this is strange.

I worked for a mentoring company. You all listening probably didn't know that there was such thing as a mentoring company. But the largest, most successful mentoring company in the world is headquartered in the Denver Tech Center. It's a very small company because it's not a very big industry, but it's called— when I worked there, it was called Triple Creek Associates. Now it's called The River.

And we did research when I was there that showed what percentage of mentees ended up getting a promotion within, I think it was 24 months of their relationship, of the of the, uh, of the relationship, um, and then compared to the baseline, and it was a significant improvement versus the baseline. But then they showed, they showed the percentage of mentors that got a promotion versus the baseline, and the mentors actually got a bigger increase of promotions than the mentees did. They got— so by that one measure, they got more out of it, right? Which, not, not intuitive, But, but to your point, I think you really do get a lot by giving back and getting those relationships and kind of having to be on your game. Uh, similarly, and I've had employees at some points in my career who, uh, and some weren't always easy to work with, and as soon as they became managers, like, their whole perspective changes and they're like, now I'm part of the team to help my employees be successful and they become better employees at the same time.

I, I I just think it puts on that better hat, right, to how you think about things. Really cool. All right, so Denver community stuff, obviously, you know, you and your husband is also in security. He is, yep. And where's Dan working now?

I know he— He works for Online Business Systems. Yeah, he's a security consultant. Yeah, and they're a financial services provider, right? No? No.

No, I'm not helping you. They do, you know, like he does PCI audits. Okay. Audits, security consulting stuff. Yep.

Okay. Yep. Um, so you guys have been in the community for a while here. Any feedback on what we do well, what we need to do better? Yes.

Is this a plug for Rob and Alex? Because it is. No, no, no, no, no, no, no, no, no, no, no, really. I, I, and like I said, I said this before we started, but, um, I really, um, because I have been in the community for a while now, and, you know, everything that you guys have done, especially with Colorado Equal Security is so great. I mean, everyone that I know, we faithfully get the emails on Sunday and we're like, oh, here's a new one, and listen to the podcasts and the events.

I know that if I'm looking for a date or something, you guys have it. And so I really think that you have done a really tremendous you know, benefit to their— to the, the community, the security community in Denver. We are so, so strong, and we feel we are part of a community. It's not like we're just security people and we go to— oh yeah, we go to an ISACA meeting or an ISSA meeting or OWASP meeting or whatever it is. We're really— we're a community.

Yeah, so this really helps. So I really thank both of you guys for, for doing this. Well, it's been a ton of fun. In terms of how we in the community can get better, any thoughts on where there's opportunities for us to improve? Obviously, you know, the Women in Security Initiative was badly needed, and I'm so glad it's being tackled.

Is there other stuff we need to be thinking about? You know, I think, you know, again, getting into the schools. I think that that's really important. I know that you were just on, was it 9 News? And, you know, again, outside of the security community.

You made a comment on a previous podcast about talking— you can talk to security people and everything, but you're preaching to the choir, right? You need to get out to those other— the people that are out there that aren't in the security community to share that information. Because it hits home. Every time you turn around, you see something in the news about security, cybersecurity. It used to be that I had to explain what I did.

Now all I have to do is go, yeah, cybersecurity. It's funny, it's the exact same thing. So for most of my career, what do you do? I'm an IT guy. What kind of IT guy?

Well, I try and stop the hackers. That's, that's how I, how I had to do it for years, and now they know what it is, right? It's kind of interesting, isn't it? Yeah, same as my wife. My wife's a physician assistant, and I used to have to say, well, it's kind of like halfway between a nurse and a doctor.

And now everyone knows what a PA is, and they usually like their PAs better than their doctors. Yeah. Yeah, I love it. One of the great examples we've had recently was we got to get involved with Denver Startup Week, where you're getting outside the security community. CTA with doing their CISO of the Year Award this year was another really cool thing.

That's huge. The more places we can get involved, there's like the Better Business Bureau does events. I don't know of anyone who goes to those. Anyone listening who's looking for something high value to do, any of those would be a really cool place to tackle. And let us know what you're doing, we'll promote it and we'll see if we can get you some support.

I was going to say, you know, maybe that's something also that you can do on Colorado Equals Security about volunteer opportunities. Yeah, that's a good idea. We'll take it, take a note. Yeah, cool. Um, so, uh, I can ask you a couple more questions.

For those who are looking to get into security, maybe who want you to hire them as a security analyst or any other kind of entry-level-ish position, what are the skills that they most should go after trying to get?

What are you looking to hire for? Is it skills? Maybe I'm asking the question wrong. You know, it's a great question. Well, I just hired somebody.

Yeah. And so Dana Sanchez from DaVita. How good is Dana? And should I steal this person? No, you cannot steal her.

No, you cannot. But you know what, it was funny because I knew I wanted to hire her at the Women in Security. She was there and it was the one where they had the high school— September, August to September. Patriot, what's it called? Cyber Patriots.

Cyber Patriots. And so they were giving, you know, presentations and everything and it was really loud. And so she was sitting next to one of the presenters and he was talking and he couldn't be heard and she just like jumped in and was like, Okay, what he just said was, and repeat it. And it was like, I want you because you know what, you're not afraid to jump in. And what I always look for, again, going back to you got to be memorable, and you got to be able to build relationships and talk to people.

Because again, I want to build a secure, aware culture. You can teach, you know, the technical skills, you can learn that, right? I mean, I've got tons of letters behind my name because I learned that, right? But you can't necessarily— it's not easy to actually stand up in front of all these, you know, people and go, hey, what he just said was, and do that. Those are those skills that I always look for.

If you want to call them, I don't know, you know, there's lots of names, but soft skills or anything like that. I want people that can do both, that can do the technical skills and also be willing to just get out there and say, you know what, this is, you know, security is really important and this is why, rather than having somebody just head down. You know, we need those people as well, but, you know, when I'm— when you want to get into cybersecurity, and I really think that if you want to become a CISO, you need to have some of those skills because you're gonna have to be reporting to executive management and the board. Yeah. And if you, you know, you need to be able to talk to them and And you only have like 2 minutes, right, to be able to tell it everything that you've done.

And so you need to be able to do those kinds of things. So, you know, that's what I look for. I'm not necessarily stuck on— I mean, I love looking at seeing the certs. I mean, I've got the certs, right? So I recognize those certs, but I also want to see what you've done.

Yeah. And You know, so any kind of experience that you can get is great. Yeah. And so I look at, you know, well, you know, well-rounded people. Yeah, that's great.

I especially resonate with what you're saying about someone who shows some initiative, right? Someone who's willing to go solve a problem, following up with a— come into the interview prepared and show that you're prepared and you've done some research, and maybe you didn't just walk in with a slightly edited version of your resume, you actually have thought a little bit. And then, you know, coming up with creative solutions to problems you hear. You don't have to be the most technical person if you show that you're willing to go, right, come up with creative solutions and work hard. Makes a huge difference.

Attitude and aptitude is way more important than, uh, have you ever worked with this version of this security tool. Yeah, well, this has been great. Any final stuff you want to share with us? Security world? You know, one thing that we didn't really talk about, but I really think is important when you're a security person, and that is, you know, we use lots of different vendors, right?

Everything is— we outsource a lot for a variety of different things. And, you know, make friends with your vendor management people, your procurement people, because you absolutely want to get some language, some security language into those contracts. That's going to help you in the long run. And so you definitely want to make sure that, you know, you can scan, you know, you put that in the language of the contract if it's a, you know, um, a SaaS provider. No, no scanning your SaaS providers.

That's not scalable.

Don't put scanning your SaaS providers in the email. Yes, in the contracts. But the bottom line though is You know, this is one of the ways that you can protect yourself. So make friends with, you know, your vendor management people and, you know, open up to them. Have some, you know, visibility about what you do because they probably don't necessarily understand what you do.

And so tell them and tell them why it's really important, you know, that you have good language in your contracts. Yeah, you actually reminded me of a question I didn't get to ask you earlier when you mentioned coming into the new company and listening and it meeting with folks, I wanted to ask you who it was. It sounds like one of the folks you'd want to talk to is vendor management. Yep. Who else is it?

Luckily, I have vendor management report to me, so— okay. But, um, I would say that, um, your, your operations people. So especially if you are, um, if you have offices, you know, you're not just one office, if you have offices regional or international, whatever it might find out what's going on in each one of those offices because most likely you don't have— if you're a smaller company, you don't have a security person in each of those offices. So you want to know what's going on there and you want to make friends with them so that you can have a quasi-security person. You've got somebody, you know, that you can reach out to to help, you know, if need be, if you have a situation or anything like that.

So those are really important. Legal people, man, get them on your general counsel. Get all the way down to— if you didn't say that, I was gonna— yeah, you gotta have, man, those, you know, uh, your general counsel and your head of, you know, um, people, HR, whatever you want to call it. Um, so those are key people that you absolutely have to have on your side. Yeah, awesome.

Well, Sue, thanks so much for your time. I— we almost got to an hour. This time is just— time has flown. It's good. Well, we'll look forward to talking to you.

Maybe we can get together next year and, and see how things go. All right, thank you so much. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, Remember, Colorado equals security.

Back to all episodes