Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.
Hello Colorado, this is Robb Reck here with Alex Wood to give you the, uh, February 20th newscast for the Colorado Equal Security Podcast. Hey Robb, how are you doing? I'm doing great. Welcome back from RSA. Yeah, I had a great week out in California.
Lots of stuff going on. I read that there were 43,000 people at RSA this year. Yeah, the number just keeps getting bigger every year. It's gone from, you know, a niche industry conference to obviously just a huge, a huge part of our industry. Yeah, definitely the— I think the biggest and most influential conference that we have every year.
Did you have a— did you learn anything good there? What was your favorite thing about the week? You know, I spent a lot of time meeting with different vendors of mine and potential vendors. Did end up going to a few sessions, including one that I spoke on, a panel with some other CISOs. So that was good, enjoyed that.
How about you? You know, I didn't go to any sessions, but I did quite a bit of time talking to peers and really Talking to folks who run security organizations that are similar to mine and getting advice from them. You know, at Ping, we're going through ISO certification and we're looking at FedRAMP certification. So talking to folks who've been doing that, talking about some of the initiatives that we work on, it's been— that was a good time. Good stuff.
Why don't we jump into the news? All right. So number 1, Esker is a French tech company that's moving into Lakewood, Colorado. I'd never heard of this, this company, but they are a cloud-based document process automation solution provider. A couple, couple buzzwords there.
Yeah, I don't, I don't know what that means, uh, but it's great that they are going to be, uh, coming to the US and, and opening their office here in Lakewood. Hopefully there's a couple, uh, security jobs that result from that as well. Absolutely. Yeah, similarly, another international company, uh, Xero, which is X-E-R-O, They're an online accounting company. They do something kind of like QuickBooks does.
They're moving their US headquarters from San Francisco to Denver. Yeah, and they already had a presence here. I think about 100 folks in Colorado, but now they're moving the headquarters officially here. So that's good news. Yeah, they said that they're planning to grow to approximately 300 folks in the area soon.
And they're at the Orchard and Quebec or Bellevue and Quebec area, kind of by Landmark. So anyone on the south side of town, like, maybe it's something to look into. I think their headquarters is in New Zealand. Wow. Yeah, that's quite a move.
A little ways away. So, uh, so next on the list, uh, Forbes, they put out their list of most admired companies. Um, there were a few Colorado companies that were mentioned, but none in the, you know, the very top. Yeah, so we didn't have any winners, but we had, what, 5 different companies that were on the honorable mentions list and These are some companies that we've talked about already. So Arrow Electronics, uh, our good friend Samir Sait is the CISO over there.
Uh, Dish, where John Everson is the CISO. Ball Corp. So this is not Ball Aerospace, which we talked about last week. This is the manufacturing side. And hi, Matt Morton.
Matt runs the security team over there, so hopefully all is going well. Did run into him at RSA this week. I saw Matt as well. Uh, DaVita, uh, which is the, the local dialysis company headed with the security programs headed by Steve Oberg. And then Liberty Media, which I do not know the security leader for.
Neither do I. Anyway, so those 5 companies made the honorable mentions list. Hopefully next year one of them breaks through and makes that most admired companies. Next on the list, some not as good news. ULA, the United Launch Alliance, is cutting some jobs.
This will be not the first round of jobs that we've heard about them cutting. Um, I think that in 2016 they went through a round of cuts asking for folks to, uh, to volunteer to, to be cut, but I think that they're, they're going back to the well and cutting a few more again. Yeah, it's definitely disappointing to hear about, and while I haven't heard anything impacting security there, ULA is a fairly big employer of security folks and, uh, relevant to a lot of us in town, the defense contractor side of stuff. Another company we've mentioned recently, Digital Globe, we talked about Chris Martinez going over there as the CISO. They're actually now in talks to be acquired by a Canadian company.
I guess they need maps in Canada too. I guess they do, and there's, there's a lot of land up there, right? That's true. Hopefully, you know, for Chris, this gives him some fun stuff to work on and is just nothing but good news. It's always fun to come into a new company and then all of a sudden have to do M&A work, right?
Right. Right. Amazon— this is, this is fun news— Amazon is opening a 1,000-employee fulfillment center in Aurora. Yeah, I don't think that this is going to be jobs that folks that are listening to this are interested in, you know, unless they, they want to be, you know, drone pilots or something like that and moving, moving boxes around. Anytime you get 1,000 people somewhere, you need to secure the facility, you need to secure the drones.
I don't know if any of those jobs are going to be in Denver, but it's cool to know that we're going to have that presence here in town. Well, it also means that there will likely be faster Amazon deliveries. Nothing wrong with that. Absolutely. Cologix.
Alex, have you ever heard of Cologix? You know, I hadn't heard of them before this article, but, you know, they are a data center company, you know, similar to a, you know, a Hosting.com or a ViaWest or somebody like that. Yeah. So it looks like Cologix has been acquired by a private equity firm from New York. Uh, from, from the news, I had never heard of them before.
They're a Denver area data center company with 24 data centers throughout North America, and they just sold for what they estimated to be $1.25 billion. That seems like a big number to me. Yeah, it's a very big number. I, you know, one of the reasons might be because data center revenue is very sticky. You know, if you're making, you know, $50 million a year, you're very unlikely to lose that next year.
So you get a good multiple on your revenue. That's for sure. Next on the list, TeamSnap, which is a company that I am familiar with. They're a sports technology company. They've raised $25 million to help them grow.
So I'm familiar through youth sports. So some of my kids, their teams have used TeamSnap to help manage the team schedules and you know, news, photos, all that sort of stuff that goes along with any sort of youth sports team. And they're a Colorado area tech company. I had, you know, I'd seen those types of apps, but I did not know they were local. So very cool.
Yeah, and I believe their headquarters is in Boulder. So $25 million raised for them to hire dozens. That's what— that's the news we have. Not sure what that means, but, you know, hopefully that means a security person. And if you're in the Boulder area, it might make sense to reach out to the TeamSnap folks and See if you can get involved there.
Next, we have a list of the 10 hottest jobs in Colorado. What this means is it's actually a survey of the jobs that have the most postings in the area. So by hottest jobs, how many are open currently? Correct. Yeah, and you know, on the list you see some of the similar things you usually see, you know, retail jobs and stuff like that.
But it was interesting to see that there were 3 on there that were computer-related. One was computer support technicians, one was sysadmins, and then the third one, which I think is probably the most surprising, which is software developers. Yeah, there was over 2,000 openings here in Denver for software developers, and those, you know, obviously those are high-paying jobs and something that is a real opportunity here in town. So if you're looking for what skill set to go after, you know, if you're not going to be a security person, a developer might make a lot of sense. Well, I think, you know, that highlights that As we see more and more developers, we need more folks, more and more folks doing application security.
Right. And that folds directly into our next article. Hired.com released a survey, a North American survey of the highest developer salaries by city, and Denver came in number 5. That is pretty cool. So we're behind cities like San Francisco, San Jose, Seattle.
I think DC was on that list above us. So really near the top of the list. And then the, the last thing we have in our news list for this week, not security related at all, but if you're someone that gets around town and travels at all, I think it should be very interesting to you. The R Line of the light rail is opening on the 24th. So that's the line that is going to connect all the way through I-25.
So say you were in the Tech Center and you wanted to get to the airport, now you could go uh, from there and up I-25 and get on the A-Line, you know, up at, I think, Peoria and I-70 and go to the airport instead of having to go all the way downtown. Yeah, it's fun to watch this city grow up around us, right? To, you know, go from, you know, 15 years ago where there was very, very minimal public transportation to, you know, really starting to build a real infrastructure. Good stuff. And, and I assume, is it this RTD who does this?
It is. Shout out to Sherry Lee who runs security over there. Sherry, I hope all is going well. Got to make sure that our public transit stays safe. Upcoming events.
So tomorrow, or actually the 20th, Cloud Security Alliance has their February meeting. On the 21st and 23rd this week, the ISSA member training for building a PKI infrastructure will be happening. So we were sold out for the Tech Center one. We had one cancellation over the weekend, so If you're, if you're the first one to hear this and think of it, you can jump on denver.issa.org and get signed up for that, that DTC one. And there's a couple open still for Boulder, so if you want to go and you're a member, go ahead and sign up now.
On the 22nd and 23rd, the Colorado Springs ISSA chapter will be holding their February meetings. The 23rd, we also have the Colorado Technology Association's Talent, Innovation, and Immigration event, which we talked about last week. So we're kind of skipping through the ones we've talked about previously pretty quickly, but the next day, the 24th, is a new event, at least new to us. SecureSet, which is that local talent development and training organization for security, has a capture the flag, a cybersecurity hackathon. So that's Friday night.
You need the links in the show notes. Go ahead and get signed up for that, and hopefully you can come meet some cool folks and get some tech, tech experience there. And then back to Colorado Springs ISSA on the 25th, they are doing a free mini seminar in the AM down there. And on the 1st of March, the Cyber Summit USA Denver— that's that leaders-focused full-day event that you can get signed up for. And then also on the 1st, the Colorado Technology Association Day at the Capitol.
Yep, we talked about that last week. And then on the 7th of March, SecureSets has a has the free hacking workshop, which is App Security 101. Um, they do some pretty good content training there. If you're looking for app security and you're trying to get introduced, this would be a great time to come show up. Yeah, I'm really pleased that they're doing these sort of mini events at SecureSet, you know.
So I think, you know, some of it is probably a bit of marketing for them to try and get folks in so that they, they learn about the programs, uh, but it's some great free education. Yeah, absolutely.
Then March 7th and 8th, ISSA has their March meetings, which will be in Boulder and in the Tech Center. On the 10th and 11th of March, Rocky Mountain CCDC. I am, I'm sure as always that they're still looking for volunteers, so if you go to the CCDC website, I'm sure that you can get in contact with them to help out. And as a reminder, this is the This is the collegiate cyber defense competition where college teams get together and practice defending a network against attackers. Real time, you get to see these folks trying the real-world skills in the college level.
Then on the 16th of March, we have the next ISACA monthly meeting.
Also, the 16th is a pretty big day. There's 4 different events. There's ISACA monthly meeting, There's also the Colorado Technology Association's Sea Level at Mile High. There's SnowFROCK, which is one of those big events of the year we talked about last week. I'm gonna be helping keynote that.
Also, Debbi Blyth is gonna be there, CISO for the state of Colorado. Jim Manico, international man of mystery. We got quite a few big name folks. Jeremiah Grossman's gonna be there. So hopefully you guys can make that event.
And then finally on the 16th, SecureSet is having another event, Cybersecurity Talk with an Industry Expert. Yeah, there's still a little TBD there. I think they're locking down who the expert's gonna be, but that should be coming soon. And then the final one, looking a month out, one more SecureSet Cybersecurity Talent and Trends Career Conversations on the 23rd. So I'm not sure, I assume that that's really for folks who are looking for jobs or who are looking for some career advice.
But you can take a look at the website to get more details on that. Exactly. So that's the end of the events in the next month. Then we have, you know, a couple updates on those things further out. We talked about it, we're gonna keep talking about it, the Rocky Mountain Information Security Conference, the big conference in the area, May 9th through 11th.
Big news this week is we have, we have a date that we should expect to see registration open. Should be the first week of March. You should be able to get registered and you'll have a few weeks to get early bird pricing. We'll certainly let you know as soon as it's open so you can jump on top of that. And then of course, immediately following RMISC is Denver BSides on the 12th and 13th.
And BSides call for papers is open right now. I think it's open till about the 15th of March, so get on top of that, try and get, um, try and get plugged in there. And if you are someone who might want to help run a capture the flag event, they are looking for, for a volunteer to do that. They had a volunteer who's not going to be able to do it, so they're kind of looking to swap someone in. There are resources.
You won't have to figure it out all on your own, but it'd be great if you can get involved and help out with those folks. And then we're going to give one here that's a way far out announcement. So the Colorado Springs ISSA, their 7th annual Cybersecurity Training and Technology Forum, will be coming up on August 30th. So if you want to put a placeholder on your calendar for that one. And that's really Colorado Springs' big conference of the year, kind of their version of RMISC.
Not quite as old. Sorry, Colorado Springs folks, but, but really good content. Hopefully you guys can put that on the calendar. Awesome. So let's jump into the job postings.
You know, there are hundreds of security jobs available at any given time. What Alex and I are doing is going through those postings and trying to find about 10 that we think really stood out as stuff that you'd want to hear about. So we're not going to give you the same postings we did last week, even though most of those jobs are still available. But we do want to call out some of the interesting stuff. Yeah, and again, if, if you're a hiring manager that's looking for someone and you have an interesting job, you know, please feel free to send it to us at info@colorado-security.com.
Or even if you're a job seeker and you're looking for a specific type of job, again, hit us up. We'll see what we can find. Sounds good. So top of the list is at Spectrum, which is a part of Charter Communications. They're hiring a director of of network security operations.
Next we have for Transamerica, Director of Digital Risk Management. Yeah, I'm not positive what that means, but it sounds like a lot of fun. Yeah, you know, I'm always into risk management and, you know, digital the better. The digital the better, exactly. WorldStrides is hiring an Information Security Manager.
I had not heard of WorldStrides, so I spent a little bit of time trying to figure this out. Uh, they're a local organization. They're the largest in the— in America that helps students travel for educational purposes. And, and I was thinking that it was going to be college students, but when you— when you look on there, it's actually pictures of elementary school kids and stuff. So it sounds like they, they work with all different ages to help get them immersive educational opportunities.
Sounds like something that might be kind of fun to help secure. Good job in a fun environment. Uh, so next on the list, we have an incident response lead for cybersecurity at Cognizant. My assumption is this is at Cognizant Triseto where Matt Shufelt is the CISO. Yeah, so great organization down in the Meridian area down south by the Tech Center.
They've really built a strong security team over the last year or so and it'd be a good place to get involved. FireEye, or maybe it's Mandiant, but FireEye is hiring a professional services consultant. We know a couple of those guys here in town. Basically what they do is they parachute into places that need help and they get to go be the badass who comes and fixes it. Yeah, so if you want to work for a cool company and learn a whole bunch and do cool stuff and travel a whole bunch, then this is a job for you.
Yeah. Next on the list, Johns Manville. They're a construction materials company, you know, siding and windows and that sort of thing. And they are looking for an IT risk manager here in town. Yep.
And then LGS Innovations is hiring an information systems security officer. It looks like you'd be one of the people who's responsible for a business unit smaller than the whole company, but get you a chance to kind of run a program by yourself. So next on the list, State of Colorado, they're looking for an application security engineer 3. I'm not sure of the different levels of jobs that they have over there, but my assumption with a level of 3 is that you're a fairly senior AppSec person. You have to be 3 times as good as Engineer 1.
Yes, that's right, and they're gonna test you on that. Yeah. Maximus is hiring an information assurance analyst. Maximus is headquartered out east. Our good friend Ed Padgett is the CISO there, and they have a pretty good-sized security team here in Denver.
Might be worth taking a look at. They're downtown. Great West Financial, they have a couple jobs on the list this week. So they're looking for a senior information security engineer, and they're also looking for an IT security architect. And that architect, they're looking for skills like firewall, DLP, SIEM, and database security.
Yep, so apply there. I know the leaders over at Great West, they, they're really good folks. You'll enjoy working with them. If you're looking for a new technical opportunity, that'd be a great place to apply. So that's about it for our newscast today.
We are going to transition over to Alex's interview with Don Mapes. This was a couple of weeks ago in January. And then next week, we're excited to tell you we're going to sit down with Brian Baier. Brian is the founder and CEO of Red Canary, which is a local security company here in Denver. And we're looking forward to having that talk with Brian.
Well, thanks, Robb. Great newscast. Talk to you next week. Have a great week.
Hello, this is Jeremy Cooper-Leavitt, Managing Director of Assurance at Charles Schwab. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Hey, this is Alex Wood with the Colorado Equals Security podcast, and I am here with Don Mapes. How you doing, Don? I'm doing very well. Awesome. So, Don, why don't you give us a brief background on who you are and what is it that you do?
Oh, well, what I do right now, I'll start with that first. My day job is I'm Director of Internal Audit for TUSA Petro. That's an oil and gas exploration and production company. We're a pretty small shop right now, so I kind of have to cover all the bases, and that includes IT audit and security. My part-time job is being president of the Denver ISACA chapter, and I've held that position now— this is my 3rd year.
I've been actively involved in the chapter for at least 4 years prior to that, been to many conferences on the international level even. As far as my background, I started out in audit in 1996— pardon me, 1994. And then in 1996, I actually became interested in IT audit, and I kind of fell into it in a roundabout way. For one thing, I'd always liked computer gaming, and so that passion in computer gaming, which continues today, drove me towards learning how systems worked and really how to network computers together, because we used to have LAN parties. We'd all bring our computers over to somebody's house, and then we'd hook them together with old coaxial cables and had to use terminators and nick You're dating yourself, Don.
So that's kind of got me interested in IT. Then at my day job at that time, I worked for an insurance company and we had been paying one of the Big Four to do our IT auditing and the director there said, you know, I'm tired of paying this money and not having the person around 12 months of the year to ask questions of. Would anyone here be interested in skilling into that route? And I said, pick me! And so that started a drive, learning more and more about IT audit and security.
Many training courses and conferences later, I passed the Certified Information Systems Auditor exam, and that's got me going where I've been today. Every job I've been through since has had some element of IT audit and security in it, whether I was a dedicated IT auditor or whether I was in more general audit but did the IT stuff as a side. That's where I am today. And of course, a few years back, we actually worked together for a short time. You know, you were the IT auditor at a previous company where we both were, so that was fun.
That's right. When you were in security there at QEP, I was the IT audit manager at the time. Awesome. So when you started in audit, did you have a— how did you get to audit? Did you have a finance background, or was it just something you fell into, or how did that work?
I actually started out going to college to be a mathematician. I wanted to be an actuary because I heard they made the big bucks. So I then kind of hit a wall as I was going through school and I just got burned out doing like really high advanced math. I'd already had 27 credit hours of math, ironically. I switched over to the business school as an accounting major, finished off there at UCCS in Colorado Springs.
I figured out within about 2 months after graduating and being in my first job at Colorado State Gas that much to my horror, I hated doing accounting. Seriously, doing the same thing that literally told me— I came in there, I said, okay, what's my job? What do I do? And they said, you're responsible for the 17, the 81, and the 63 voucher. What does that mean?
Take last month's, make this month's look like last month's. And that's what it was, what we affectionately called ape work— make it look like it was before. So you're putting different numbers and rebuilding a month thing. So I knew I couldn't keep doing that, and I left there. I went to Farmers Insurance Group as a field auditor for them, and that got me into audit.
From there, I've moved through a few companies since. I came up to Denver and it started this program there, this pattern of when you hire Don, your company gets acquired. Total Petroleum acquired, Guaranty National acquired by Orion, which got acquired by Royal Sun Alliance. I actually kept my job through a couple mergers, landed at Xcel after their merger, came over to QEP and we did divest. Remember, we split apart companies at QEP, the midstream split off and Then, oh, I worked at Venoco in between too, and that company, I got there when we went public and I left there shortly after we went private.
So it sounds like, Don, you need to reach out to some startups around town that want to get acquired, right? So, you know, hire you, you'll get acquired. No kidding. I seem to be the bait that gets you acquired.
You know, so a lot of the folks we talk to are more IT security focused than IT audit focused.
Being on the IT security side myself and talking to a number of people, I often hear, oh, I hate those auditors. They just give me a hard time. Why do we even have to do this stuff? I wonder, what's your opinion on how IT audit and IT security play together? What's the synergies that can happen there?
How do you best make your relationship with your IT auditor work? That sort of thing. Okay. You know, I never really viewed it as an adversarial role, and at most firms that I've worked, it really hasn't come across that way.
It's something that— it's a necessary evil, and I'll tell you a quick story about internal controls over financial reporting, or as everyone affectionately calls it, SOX, the Sarbanes-Oxley Act. It kind of made it the, quote, Full Auditor Employment Act. And everyone's always, that's what they charge to you right now. But I'll tell you something a CFO said at a former company, I really agree with this. We don't do those things that allow us to comply with the SOX Act, we don't do them just for the SOX Act.
All those things are things we should have been doing all along. We do them because they have a good, sound business reason. When I talk to a system administrator here at my company, or the VP of Operations or something, and explain to them, You know, what's the system you use for production accounting? And they say it's ProCount. Okay, great.
Now, you only want people to be able to update that system that you know about, right? And you get the head nod right there. You know, you're talking about the database to a database administrator, and you kind of explain the risk to them. You don't want anyone else but you and your approved team making changes there, and everyone gets right on board with that. So that's kind of the way you have to approach it.
You've got to sell it to them as something that helps them out in their job. I do understand that a lot of times it does look like form over substance. It's important that things happen, but oftentimes it's important to be able to prove that we did it too. As we've moved farther down the road over my career, as cybersecurity has become more of an issue, and hacking and denial of service, ransomware, as these things have progressed and become more and more a threat to a company, it's become more and more important for people to do the right things at the right time and be able to show they did them. That allows you to recover from a lot of these things, hopefully prevent them from happening, but most importantly that you can identify it happened, fix it, and get back to a normal operating state.
Well, you know, and I completely agree. I would say that I think that you can definitely have not only a healthy relationship, but a relationship where IT audit is bringing security forward as well. There have been many instances for me where maybe I couldn't get traction in some area, and I know that we have an issue, and then working with IT audit, oh, hey, IT audit, can you guys help help us out and maybe look in this area, you know, you guys find something, and now there's 2 voices talking about that instead of just one. Exactly. And one of the things that auditors are always supposed to do, and I believe in thoroughly, is that you have to do things that are risk-based.
And when you're talking about that, I can think of examples in my career working for Xcel Energy, for example, where putting in a system implementation, having the IT auditor come in and look at that was very key to them because when they were about to go live and there were some senior execs in the company saying, wait a minute, you can't put that in, how do we know it's going to work, etc., so forth, they quickly pointed to the fact I'd done an audit over in a report, looked at the risks, saw that they'd covered them off appropriately. You can never guarantee that everything's going to go perfect, but we can look at and say with a fair degree of certainty the team did everything that they should have done in considering what the risks were, what security problems might happen, how the operational flow is going to work, how the accounting is going to work before they flip the switch and turn the system on. And that validation from an auditor can help out a lot of time, and it has helped in other instances too. I can think of just an example you said. I see the security team, the IT security team, they are trying to get either a critical piece of software, or establish a critical function, or just get resources, another person, to help them take care of and sign off a risk that's addressed.
And very often, auditors are that second voice, or can help explain that to senior management. Remember, as an auditor, I have the ear of the board. So, the audit committee, I meet with my audit committee chairman every week. I talk to them for half an hour, and we have a formal meeting once a quarter. If I see something that I know that people need help with here, and not framing it in a way that, oh, I want them to get that person, but hey, they need to be able to do this.
Right now they do not have sufficient resources to do that. If we don't get them that resource, or the money, or that cool software program that's going to help, you, the audit committee, and the board are sitting on this risk. And that usually is where, I mean, this is what it's all about. The board is going to say, well, we're fine sitting on that risk, that meets our risk appetite and tolerance, and that's fine. That is their domain.
Or they look at that and say, whoa, no, no, no, no, no, no, no, I am not taking that chance. We're going to fix that right now. And it helps a lot. So there you have it, information security folks. Make friends with your IT auditor, you can get stuff done.
So, you know, as you mentioned earlier, Don, you know, as part of your secondary responsibilities, you're the president of the Denver ISACA chapter. So why don't you tell us a little bit about ISACA, what it is, what it is that you guys do, what your focus is? Cool. It started out as the EDP, or Electronic Data Processing Artists Association, in the Wayback Machine. California and Orange County area, and then Chicago.
It evolved over time. First, it was just people doing the old EDP as Mainframe World, and things evolved over time. It became Information Systems Audit and Control Association, recognizing that it's not just serving auditors, but the people in the IT security area as well. And that evolved into just shortening to ISACA, yes, the initials just shortened to that is our name now, but they put forth a variety of certifications now, and it's tailored to the various disciplines. For example, you have the Certified Information Security Manager.
That's not geared for audit. That's geared for the person actually doing the job of IT audit and security— IT security, pardon me. When you come to myself with a Certified Information Systems Auditor, I'm more skilled at assessing risk and literally finding out, looking at where it could break. I affectionately tell people that my forte is not in— I couldn't run that system for you, but I could tell you how to break it and I could tell you how to protect it so it keeps from getting broken.
The chapter or the national organization now, in addition to those certifications, that they currently already had, they now have the cybersecurity credentials they're coming out with, where the earlier certifications like CISA, CGITEC, CRISC were all knowledge-based. You took an exam, you got the credential because you demonstrated through the exam and supplying work experience you knew your stuff, and then you have to get continuing education for all those. The new certification, the Cybersecurity Fundamentals certificate will be knowledge-based, but the other ones, the practitioner side, is going to be devoted to the 5 aspects of cybersecurity, you know, identifying risk, response, etc., so forth, and they are all practical-based. So in order to get the practitioner certification, something like with the Cisco networking credentials, I understand, you have to go in and take a test where where they drop you into a simulated environment. You're now the security manager.
Take care of all the things. Attack comes at you, respond, get it back going. And you have to keep doing that every year to maintain it. I haven't run for that one yet because as I pointed out, my skill set tends to run more towards the audit side than the actual security side. That sounds like a pretty cool certification.
I like the way that they're doing that. Me too. So if someone wanted to get involved with the ISACA chapter, what would they do? Where do you guys meet? When do you guys meet?
That sort of thing. What sort of events do you have? Oh, sure. We generally meet 9 months of the year for chapter meetings, and actually, I say 9 months, one of those actually is the Rocky Mountain Information Security Conference, which we put on in partnership with the ISSA. Our meetings move around town.
Since our chapter, its official range is 50 miles around the center of Denver, But in practicality, there is no chapter in Wyoming. There is none in southern Colorado, western Colorado. So we wind up having those people as part of our chapter too. Very difficult to serve their needs, unfortunately. We do try to move the meeting around Denver a lot.
So for example, January 19th, we'll be up at the Arvada Center in Arvada. We just met with the ISSA chapter in partnership down at Landmark Center down south. We'll meet downtown here using the History Colorado Museum in February. We'll be out at the Sheraton off of Union and 6th in March. And then we're gonna be all the way back down south at the— used to be called the Wildlife Experience, now it's CU South.
And you guys normally do lunch or sort of middle of the day kind of things? Usually it's lunch and networking and lunch. For about an hour, and then we'll have a 2-hour CPE presentation. And the topics vary widely. We have 2-factor authentication coming up in March— pardon me, February.
At the April AGM, we actually have an instructor coming in from the SANS Institute to talk about securing mobile devices. I can't remember the rest of the topic right now. We also have a website, isaca-denver.org, Full description is out there on the website. And just recently, just, I mean yesterday, we rolled out our chapter app. Yay!
So why don't you talk a little bit more about that? So this is a, you know, like an iPhone, Android kind of app? Is that— Yes, an iPhone, Android app. It even also has a Windows link you could go to. But it's actually built— we chose Company Guidebook to use, and the reason that we went with them is If you pay their branded fee, you remain in control of the content entirely, completely.
So you build a draft, they publish the draft out through their channels into the Android Store, into the Apple Store, and now it's just content management and hooking together blocks that already exist. So I can create a new meeting event and push it out to my membership. I can create a survey that goes along with that meeting. It's hopefully going to give us a whole new range of communication and bring us better in touch with people. It's difficult today.
You would think it'd be easy, but I'm telling you, I think even constant contact emails are winding up getting caught in the spam filters now. So we're hoping that this is going to bring us more in touch with our constituents. Awesome. So when you mentioned the website earlier, I happened to notice that, excuse me, the end of that is a .org. So you guys are a nonprofit, correct?
ISACA? We are a nonprofit. However, when ISACA was organized, the chapters were organized as a 501, as opposed to the typical is a , I think. So we're nonprofit, but donations to us are not tax-deductible, and we do have to pay sales tax. So kind of interesting, a little wrinkle.
The IIA chapter, the Institute of Internal Auditors chapter, for example, is a true nonprofit, and if you donated money to them, you could write it off on your taxes, etc., so forth. So being that you guys are also a nonprofit in one state or another, you're also volunteer-run, correct? Completely volunteer. So how is it that you guys stay on top of getting all the stuff done that you need to do and finding folks that are willing to volunteer and put their time in? Superheroes.
Yeah? We actually have a very active cadre of volunteers. I think we usually have about 70 to 75 people who actively volunteer in doing things for the chapter, things from the website, the education program, the treasurer, participation in the RMISC Planning Committee. All those things are all volunteer, and we've just been very fortunate in that we found a lot of people who have a lot of passion around getting some things done. Awesome.
Yeah, and you've mentioned that a couple times, you know, the Rocky Mountain Information Security Conference is near and dear to my heart, but, you know, maybe I'll give you a second here to give a plug and talk a little bit about RMISC. And what it is and why it's so great? Sure. The Rocky Mountain Information Security Conference, if I'm correct now, this is our 11th offering. Last year we were well over 700 people.
I think we may have even gone beyond that. I can't remember if we broke the 800 mark or not, but it's grown every year. It gets bigger and better. We're coming out for basically 3 days, 2 days of tracks, 1 day of pre-conference seminars. This is— we went 2 days the year before and the year before that.
It started out as a 1-day event. This is growing. A lot of people are now making this a destination conference, something they see as worthwhile traveling from out of state to come to. The offerings are that good. There's a lot going on in Colorado now.
We have a lot of companies, a lot of IT security professionals here. You have a lot of tech industry. Especially down the road in Colorado Springs, you also have a lot of military. And obviously there's the general that's named the head of cybersecurity that's based at UCCS, as I understand it. Yeah, and I don't remember his name, but I do know what you're talking about.
And, you know, they're gonna have the— totally blanking on the name, but it's the the Cyber Resource Center or whatever it's called down there in Colorado Springs. One of the other cool things that we're doing in the chapter that's going to dovetail in with the RMISC, we've noticed in ISACA at the national level, they have a Women in Technology group, and we've seen it not so much with our chapter membership. I got to tell you, our constituency is probably about 55% male, 45% female, but that is not the norm around the United States, maybe even around the world. World. Seems we don't have as many ladies or minorities in IT as there is in the general population.
Well, where that becomes hard as a person who hires is I have to hire the most qualified people. So we have to start attacking this problem at a far younger age. And that's one of the things we're trying to get in partnership now. The Cyber Patriot is an event that is put on by the United States Air Force, in cooperation with Northrop Grumman Foundation. And this event encourages middle school and high school students to learn about cybersecurity, and then it has a competition.
It's very analogous to the Collegiate Cyber Defense Competition, but now at a lower level. So these kids form teams, and usually they'll have a mentor coach, one of the teachers at the school, And then they download an image from the Cyber Patriot at certain times of the year, and they all compete. Who can best take this problem they're given? And basically, they're given, as I understand it, a situation, a machine, an image of a machine or a network, and, OK, secure that. Find the vulnerabilities and patch them up.
It's totally a defensive exercise. There's no outbound hacking involved in it. It's teaching the kids how to defend in a cybersecurity event. And this is awesome. And I just found out about this last year, and I'm kind of shocked.
It's been going on for many years. So, for one thing, we're having a Cyber Girls Summit to try and get young ladies who are not— or have not been exposed or interested yet in this competition interested in becoming involved. As a follow-on to that, the committee for RMISC has agreed to set some time aside on the Wednesday at the conference that will have a couple track sessions, and one will be more geared towards those people or coaches who are just getting their feet wet and into it, and also to expose the IT community, security and our community in Denver here and at the conference to, hey, this is what CyberPatriot is, here's things you might be able to do to involve, and by the way, these kids that are coming up through here generally have a passion. You might want to touch point with them, network with them, because in 4 or 5 years, those are going to be the college graduates you may want to grab for your— fill your needs at your company. And we all know that there is a dearth of qualified people in the cybersecurity arena right now.
So this is the next crop up and coming. This is our opportunity to help them come along, to encourage more ladies, more minorities to come into this field, and that will help solve our problem of the inequity of what percentage of this career field is minority versus the white Caucasian male standard. That's awesome. I'm glad you guys are tackling that. That's a great thing to bring forward, and of course I'm glad to see that it's going to be part of the Rocky Mountain Information Security Conference as well.
For those folks that are listening, you can always find more information about that at rmisc.org.
So a couple of last things here, Don. So how long have you been part of the Colorado security community? And what are some things that you see that are either interesting or unique about the community here? I've been a member of that community really for more than 10 years now. I'd really put 1996— pardon me, that's 20 years.
20 years now. '96 is really when I started coming into it. One of the biggest things I'll tell you right off the bat is when I started being involved in the ISACA chapter, our membership when we met was about 25 people showing up at the event. And now we're usually about 100 that are showing up. The chapter's grown from maybe about 300 people total to about 1,100.
It's my understanding that the ISSA chapter has similarly flowered and blossomed and grown over these years. So we're seeing a lot more involvement, a lot more sharing in the community now, and just a lot more opportunities. So I see that as a very, very positive thing. Awesome. Well, I appreciate your time and talking with us.
Is there anything that, that you'd like to close with? Any other things that you'd like to share You know, this has been a very, very eventful life for me, and I've really been happy with the career path I've chosen. I got to say, choosing this career and being involved in this field is very satisfying to me. I feel like I'm making a difference. That's awesome.
So thank you for the opportunity to share, Alex. You're welcome, and thank you. You know, I've done a number of volunteer things in my past as well, so I Thanks to you for, for giving your time and volunteering. I think that's help— what helps make our community great. So thanks again, Don.
This is the Colorado Equals Security podcast, and thanks, and we'll talk to you next time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.