All episodes

Robb Reck and Alex Wood

Apple Podcasts Spotify SoundCloud

Podcast is live!

The podcast for the week of 2/6 is live and available on our Soundcloud page here. We are still working to get it listed on iTunes and Google Play, but should be coming soon. Bear with us as we figure out this whole podcasting thing. My first thought as I listened was that we need to smile more, and maybe not record at midnight... The notes for the show are below.

Feature interview:

For the first episode we thought it would be nice to interview each other, and explain what this whole podcast is about. Robb and Alex talk about professional backgrounds, why Colorado=Security exists, and why this is a movement you should get behind.

Local security news:

CISO moves:

  • Matt Shufeldt promoted to CISO of TriZetto
  • Merlin Namuth appointed Director of Security for Red Robin
  • Nancy Phillips hired as CISO for datAvail
  • Christine Vanderpool moving from CISO of Molson Coors to Deputy CISO of Kaiser Permanente
  • Chris Martinez leaves job as CISO for Aetna Consumer to become CISO for Digital Globe

Upcoming Events:

View our events page for a full list

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12562 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the first episode of a weekly podcast focusing on security events here in the Colorado region. I'm Robb Reck, and here with me is Alex Wood. Say hello, Alex. Hello, Alex.

Well, we are excited here to bring you guys the first podcast made by Colorado security professionals for Colorado security professionals, and this is really the first aspect of what we hope to be a larger vision where we're really seeking to make the Colorado security community more aware of itself and really just better known for what we do here. I mean, our community here is so great. Not only do we want to make sure that people in the area know what's going on, but also make sure that folks that are not here know how great the security community is here and hopefully attract more folks to that. Yeah, so Colorado Equals Security is more than just a podcast. It's a vision for how we want to see the Colorado become the premier location for cybersecurity talent and jobs throughout the world?

Yeah, and I mean, there are already a number of great companies here and obviously lots of great people. But again, I think that as we stated earlier, it's just about getting the word out about that, making sure that folks in the community are aware of all the different events, all the different happenings, as well as the great people that are operating in our community. Community. So the first aspect of Colorado Equals Security is this podcast where we're really gonna get the word out about what we do here and really try and group in, loop in the other organizations in town. So, you know, in addition to, to our organization, there's also, you know, ISSA, ISACA, OWASP, CSA, the Cloud Security Alliance, CTA, Colorado Technology Association, Colorado Cyber, and InfraGard, CitySec, all these organizations that we want to make sure are included here.

We are able to get their feedback and understand what they're working on and bring to you guys kind of the best of the best of what's going on here in the area. Yeah, and to that point, you know, we just went through a list of a number of the different groups that are here. That doesn't mean those are all the groups. We're not trying to be exclusionary to anybody. If we didn't mention your group and and you want us to get on our radar and have us talk about events that you're doing, definitely feel free to reach out to us.

You can go to our website at colorado-security.com or send email to info@colorado-security.com.

I think that's probably the easiest way to get ahold of us. And this podcast, will also be on our SoundCloud page. You can find the link to that on the website as well. So the format of the podcast going forward— this week's a little different since we wanted to give you guys an introduction to what we're doing. The format going forward is going to be a short introduction and newscast for, you know, 10 to 15 minutes where we talk about news and local current events, who's changed jobs recently, any mergers, acquisitions, what's going on in the Colorado security community.

And then we'll go through a calendar of events, stuff that's coming up, and we're kind of scouring the web looking at all those organizations we just talked about to find trainings and events that they're doing so we can bring those guys to you here. And then, you know, after that introduction, the newscast, we'll do a feature interview. And in the feature interview, we're going to sit down with one of the great characters we have in Colorado security and do a 45 to an hour-long interview. Interview where we get to know them, know what they're doing, and hopefully get some advice that you guys can use to make your own careers better. Yeah, and these people could be, um, you know, CEOs of a startup.

They could be, you know, folks that are heading a nonprofit educational organization. They could be, um, you know, CISOs in the area, you know, anyone that's doing something exciting in the security community here. So again, if you're somebody that you're doing something exciting and you want to tell people about it, get a hold of us and we'd be happy to get you on the interview list. Yeah, we, we actually have just a fantastic list of folks that we're— we've already started to meet with and we're gonna be meeting with to bring you guys insight into what they do. Reach out to us and let us know who you'd like us to talk to.

Fantastic. Best list ever. It is the best list ever. Everyone says it's fantastic. So for this first episode, like I said, we're gonna kind of break from the format.

We wanted to give you guys some insight into who we are. So over the next hopefully, you know, many years Alex and I are gonna sit down and talk to you guys a lot about security, talk to other folks in the community. But we wanted to give you some insight into who we are and where we're coming from and our individual perspectives. So we're gonna talk to each other today. Exactly.

I think it'll be helpful for you guys to know who we are so that, you know, a little credibility to what we're doing and why we're, we're, we're putting this together. You know, who are these 2 schmoes that are out here just just talking about Colorado security. What do they know and why are they experts on that? So, Alex, as a starting point, let's dive into your background. Talk to me about— first, let's start off with your professional background.

You know, what's your job now and how'd you get there? Sure. So I am the Chief Information Security Officer for Pulte Financial Services. I've been there for nearly a year. Prior to that, I have run security programs or been a part of security programs at healthcare organizations, energy companies, and then early on in my career, I worked for a long time at IBM doing, for the most part, managed security services.

So that's kind of really where I got my start in information security. So in your current role where you're the CISO for Pulte Financial, Talk to us about what's the scope of your responsibilities there and what are you working on? Sure. So I manage all of the information security, IT compliance, and risk management for our organization. So I have a team that reports to me that helps me with those responsibilities.

So we make sure that all of the information that we hold from our customers is safe. We kind of run the gamut. We do security operations and monitoring.

We do network security. We do the risk management and risk assessments. We also manage the various different IT compliance regimes that we have to comply with. For those who may not know Pulte, can you give just background on the company itself? Sure.

We are part of a larger company, PulteGroup. And that really consists of 2 main pieces. So, Pulte Homes, so we're the 3rd largest home builder in the country. We build homes all over the United States. And then Pulte Financial Services, on our side, we do mortgage, title, and insurance for the folks that are buying our houses.

That's great. So, you know, what kind of, what are the biggest priorities for you in 2017 and going forward? I think we are at a good point and we have a lot of strong controls in place. I think for us, it's really taking what we have and taking our maturity to the next level.

We have a good security monitoring program in place. It's just taking that, making sure that we've got full coverage of all of our network, all of the events that are happening, fine-tuning that. We've got a good vulnerability management program in place, and again, just sort of fine-tuning that. So I think this year for us is really a year of maturity and just getting better at all the stuff that we already do. That's great.

So yeah, I guess we can shift to you, Robb. If you want to just tell our listeners who you are, what you do, and what your history has been. Sure. So currently I am the Chief Information Security Officer for Ping Identity. Ping is one of the 4 big security companies here in Colorado.

You know, there's Ping, there's Optiv, Webroot, and LogRhythm, kind of the big 4. And then we've got a lot of other great companies who are up and coming and hopefully join us in that in those ranks soon. I've been at Ping for a little bit over a year and was extremely excited to get the opportunity to go there. I have been, and we'll talk about this a little bit later, I've been really engaged in the Colorado security community for a number of years and having the opportunity to lead the security program for a security company here in Colorado that's really trying to make Colorado one of the best places for security It's just been an exciting thing for me. There at Ping, I have the opportunity, kind of similar to you, I run information security.

Probably the biggest difference is, you know, as a company that makes software, the most important thing I do is product security, so making sure that the products that we create— and Ping makes identity and access management software and services, managed services— making sure that those products are secured through the SDLC and then secured as they run in the managed service environment are the most important things I do. Next to that, you know, making sure our internal corporate systems are secure and then really enabling our business to be successful in the sales process. So if you're, you know, for those of you listening who buy vendor products, you probably have a third-party management, third-party risk program. And I get, I'm the recipient of all of those questionnaires, right? All of the people who want to do due diligence on their vendors, that comes to my team.

I, and have the opportunity to, to get better at providing assurance of our program so we can enable the company to be successful. So that's really compliance programs. We do a SOC 2, we're working on ISO certification, and, you know, kind of looking at what makes sense going forward in the future as well. So really focusing on those 3 different areas: the product security, the infrastructure security, and then the compliance. And I have 3 teams that are aligned to those areas.

One of the, one of the things I really love about Ping and what got me going over there is, um, you know, we've, we've been for, I don't know, a decade plus, uh, we've kind of acknowledged as a community that perimeter-based security doesn't work very well. And, uh, and, and there's just been this question of, okay, we all know that the old paradigm of perimeter-based security doesn't work because people can defeat the perimeter, but we haven't done a great job of of figuring out what takes the place of that paradigm. And I've been very excited at Ping to start to get some visibility into the paradigm that probably takes the place of it, which is, you know, at the highest level, zero trust networking. So if you've read any of the Forrester research on zero trust networking, the general idea is make sure that whatever network you're plugged into doesn't give any extra rights beyond what Basically, being whatever network you're plugged into doesn't matter. You have, you have the rights based on what the user's access is and what the access control policies are.

So really having the opportunity to learn more about that and to drive Ping's internal program toward aligning with that, and I think getting the chance to help the community move in that direction as well. So that's been exciting for me. So that's what you've been up to now. How did you get your start in information security, and what are some of the other uh, jobs you've had in that area. Yeah, so I, I'll go back.

My very first job in technology was in the, in the '90s. I worked for Electronic Arts, the video game company. So I, I actually got a job doing technical support where people who, who were trying to, to load and, you know, install our video games would call and say, hey, it doesn't work. And basically most of the time what I got to tell them was your sound card driver needs to get updated, or or something like that. Um, that you're, you're doing it wrong.

Well, it's always— you're always doing it wrong at some point. But, uh, it was a really interesting process to get into IT that way and getting to, getting to feel the pain of, um, of technology getting in the way of people, you know, trying to accomplish their goals. Anyway, I started off doing technical support and I went up the, uh, moved over to IT doing desktop support and help desk, um, and it kind of went up from there into to network administration, system administration. In the, in the 2006 time frame, I had the opportunity to go to a really small MS managed service provider here in Denver that, that did, uh, uh, talent. Um, it's basically a mentoring company, and what we did was hosted data for really large organizations.

So I was working with, you know, Fortune 50 type companies hosting their internal data to help them build mentoring programs. And even though, you know, it was 10, 10+ years ago, um, they still had an awful lot of requirements around security. And that was where I got my trial by fire, going from, you know, previously I'd had lots of exposure to technology but not really a programmatic approach to security. And as I was at that MSP, I got to, to learn what it meant to have assurance and what it meant to have repeatable controls and documentation and And at that company, I was a manager of information security and IT and got to really build a program, a program with, you know, at a small company that didn't have a lot of resources, but that met the needs of those large organizations. And that was quite fun.

Shortly thereafter, I moved. I was there for about 4 years, and then I moved into the financial services area. And I've worked for a few different companies in financial services, helping to build, at each of those organizations, build a security program that's maintainable and provable and really measured and, and able to report on the effectiveness of it. So I did that for about 6, 7 years before I had the opportunity to move over to Ping. So most of my background has been either in software or financial services with, you know, now at Ping, obviously as an organization that sells to global companies, I get to, to try and meet the compliance requirements of of all the different industries.

So it seems that, you know, with Ping being a security company, that it is a bit different than the other places that you've been. What do you see as— are there any big differences between running a security program for a security company versus running a security program for a financial services company or, you know, any of the other organizations that you've been with? Yeah, it's been dramatically different for me. It's been wonderful and in a lot of ways, it also is quite challenging. So the great part is at Ping, security is quite strategic, and the idea of us, you know, suffering a major breach or losing the confidence of our customers is a potentially company-ending event.

So it's quite important at the very highest levels of the organization.

The challenge there is, you know, we're a technology company that wants to move very quickly, So how do we— how do I enable us to move quickly while also mitigating against the risk of, you know, potentially company-ending events? So that's, that's been one of the really fun challenges for me. And I'll tell you the kind of the secret of how we do it is really, for the first time in my life, really being able to embed security very early on in the process. So we have engineers in our security engineers who are actually mapped into the development teams, and they are at the planning meetings, they're at the requirements meetings, and we're really getting security input involved from the very earliest phases of the SDLC, not as a gateway later on in the process. And we also have a cross-functional steering committee for security to make sure we're aware of where the organization is going, have a seat at the table in the executive meetings to understand, you know, company roadmap and what we're doing.

Really getting embedded early in the process has been the biggest key. But, you know, there's absolutely, you know, there's no magic formula here. There's a challenge for sure between How do you make sure you can be quick and nimble, and how do you make sure that you're protecting data appropriately? And I see that tension more than ever at a security company, and I'm just excited that Ping has been willing to invest and really willing to make security a very high priority for us.

Okay, switch back to me. Yeah, let's talk about the community here. Alex, you know, you and I met, I don't know what, 5 or 6 years ago. Here in the security community. I know you have been involved as a volunteer, and I'd love to hear how did you get involved in the Colorado security community?

Talk to me about ISSA and RMISC and all the other stuff you've done here. Yeah, for sure. So back when I was still at IBM, you know, we had a very large security organization there, not only the group that I was in that provided managed security services, but also throughout the company. You know, it's a several hundred thousand person company. There were a lot of security folks in IBM, and we had a really vibrant community inside the company.

I could always reach out to folks and have discussions about security, and I learned a whole lot from those folks. One of the things I realized was that I didn't really know a whole lot of people here outside of that group. I thought, I know that there's a lot of other people out there doing the same things that we're doing. I'm sure I could learn a lot from those people. I'd love to know those people.

So one of the folks that worked with me was involved with ISSA. For those that don't know, ISSA is the Information Systems Security Association. We're an international organization that's chapter-based. So there's a Denver chapter here. They were part of that Denver chapter.

And so I went to a couple meetings and thought it was interesting. So I went and joined and became a member. About a year later, after, you know, participating as just as a member and enjoying the content, the president at that time, Paul Herpka, he asked for volunteers, and they were looking for some people to help organize the security conference that they were putting on, which is the Rocky Mountain Information Security Conference. And so after that chapter meeting, I went up to him and said, hey, that's awesome, I'd love to you know, put in some of my time and volunteer and help with that conference. And he said, that's great, I would love you to do that.

You're the first person to volunteer, so you're in charge. So I was a little hesitant. What year was that, Alex? Uh, that would have been— oh geez, what year would that have been? Um, 2009, 2010, something like that.

I think it might have been 2009. Okay. Um, yeah, so we were— they were just starting the planning process for the the 2010, I believe, Rocky Mountain Information Security Conference. So, so all of a sudden I was, um, I was a leader for ISSA, for the Rocky Mountain Information Security Conference, and, and got involved with that. Um, you know, we, uh, went through a whole lot of, of planning.

Um, it was an interesting time because it was a sort of a time of transition. Um, you know, there are some folks, um, that, that help with the conference that are, are conference-playing professionals, and we were, we were switching from one group to another. So I was bringing on new people. The previous year there had been some organizational problems, so the conference lost a little bit of money. So that was tough.

So there was a lot of pressure to make sure that the conference that year made money, otherwise it probably would have folded and not happened again. But it was a great learning experience. The people that I worked with in organizing it, you know, which is in conjunction with ISACA, so That was great. I got to learn a lot and meet a lot of people. I got to really know not only our members through that, but also sponsors and security companies, trying to help get them to sponsor the conference and things like that.

During that time, the communications director for the chapter, he had to relocate, so he stepped down from that job. And Paul asked me, hey, you know, you're going to be doing a lot of communications for the conference. Do you want to become the communications director as well? And I thought, well, I don't know if this is really what I wanted to sign up for, but yeah, it's going to be really important that we make sure that we, we get this stuff communicated so we have a successful conference. So I stepped up and became the communications director for the chapter as well.

Um, and that I think was a really great stepping stone for me because Um, you know, my, my personality, my name was in all the emails that went out to the folks in the chapter for all the communications. And, you know, I really tried to make that personal and write stories in those, uh, those communications. So when I would meet people and, and give my name, they'd be like, how do I know you? Oh, oh, you're the guy that sends me those emails. So, uh, it was really, really rewarding having that happen, people coming up to me and saying that they, uh, they really enjoyed my communications and things like that.

After doing the communications director for a couple years, the president Paul stepped down and asked if I was willing to run for president. Anyone that's been part of a volunteer organization knows that it's hard to get volunteers and hard to get people to commit to things. So, you know, finding somebody that was willing to step up and take his place was hard. So I decided that yes, it would make sense for me and stepped up and became president.

Obviously, that's a voted-in role, but it's one of those things where if you're the person that doesn't step back, then you're probably going to be the only person running. So then I did that for, I believe, 4 years and then stepped down. And strangely enough, Robb, you were the one that took over for me. Well, so why don't you share with folks what you did after you stepped down? Sure.

So it was, it was good. 2 years ago, that was 2015. Yes. Yeah. So like a year and a half ago.

Um, so it was good timing. Um, as I stepped down, the elections for the ISSA International Board were happening. Um, and, you know, I'd had a good amount of contact with the, the folks at ISSA International, um, through being president. And, uh, someone encouraged me to run for one of the director positions. So, I threw my hat in the ring there, and, you know, through some campaigning and talking to a lot of folks, I was able to get elected to the International Board.

And I've been doing that for about a year and a half now. We'll have elections coming up again this year, and I'll need to decide if I'm going to run again for another term and keep going in that direction. But that's been a great ride, and, you know, getting to know people on the ISSA International level, you know, from all over the country, all over the world. It's been, it's been pretty valuable. Yeah.

So I think it was, I think it was about this time, 2012, where you, you took— or where I started coming to ISSA meetings, and I met you there. And a few months later is when you took over for Paul as the president. And I, I remember there was a slide at the meeting asking if someone wanted, you know, if you wanted to volunteer, send an email. I'm like, oh, I'll be willing to volunteer. And, and there, I think the response back I got back was, great, you're willing to volunteer.

Here's 3 board positions. Which one's the best fit for you? And I'm like, oh, a board position? That sounds like a lot. And if I remember correctly, they were, um, it was, it was definitely a sponsorship, and I think there was programs.

I'm not sure which one the third one was. And I, and I was thinking to myself, well, which of these, you know, what's the best fit for me? And I didn't know a lot of people who would be willing to talk, which is what programs was. So I chose sponsorship because, you know, I was leading a security program at the time, so I got a lot of vendors calling me, and I figure, perfect, I can just, you know, turn the tables on them. And I ended up joining the board, I think about the same time you became president is when that happened.

ISSA, you know, and we talked a little— you mentioned ISACA briefly around RMISC. Before I joined ISSA, I actually went to both groups, and trying to figure out what was the right fit for, for me and my, you know, in my community involvement. For those listening on, if you're trying to figure out what's the right group for you, I'll probably give a little, just a little talk-through on what the difference is. ISSA is focused a whole lot more on security, right? You're— it's the security practitioners.

It's how do you do the more technical aspects of things. Sometimes it's, it's governance side, but it's always on the security side, which is, you know, the defenders of the organization. On the ISACA organization, it's, it's about audit and compliance primarily. So they're looking to see, are the security people doing their job the right way? Can we test it appropriately?

And it's a little bit less in the hands in the technology and more about how do we validate that the technology is being done appropriately. So for me, where I was in my career, it made a lot more sense to go after the more hands-on security side of stuff. Other groups in town, since we're talking about them, OWASP, the Oh geez, Open Web Application Security Program— Project. Project, thank you. OWASP is, uh, is also another chapter-driven organization, and Denver has a chapter.

They meet every other month at the— usually at Chinook Tavern in the Tech Center area. I think they moved to, uh, to Dave Buster's recently. Oh, thank you. Um, so OWASP is, you know, primarily focused more on web application security, right? And it's, it's application security and pen testing in, in the highly technical program side of things.

I think they sometimes branch over into other security as well, but, you know, as a focus, I'd say that they're more on the web application side. So, you know, as you're, as you're looking at what organization makes sense for you to get involved with, just think about, you know, do you align with their mission? And, and, and really, are they gonna, you know, are you gonna be able to help them move forward? Cloud Security Alliance focus obviously much more on, on, on the cloud and, you know, kind of that next generation of cloud infrastructure. Um, and, and that, that group, um, they have a meetup that you can go get involved with there, and we'll hopefully have more meeting— more information for you on them coming up as well.

Um, so anyway, uh, back to, to, you know, my kind of coming behind you there. We worked together on the board for, uh, I think 2 years with me as the, as the, uh, sponsorship director, and then we made some, you know, bylaw changes and you were ready to step down and I said, well, no, do another year and then I'm willing to take over at that point. And, you know, we changed the bylaws to really add a vice president role to, you know, have a succession plan in place and I took over as the vice president. That would be 2014 and then 2015, you know, you stepped down and I took over as president there. I think, you know, it's worth sharing that I think we're both proud of the chapter we've built here.

When we took over, both joining the board, you as president and me joining the board in 2012, there was 130, I think 138 if I remember correctly, 138 members of the chapter. We had the one meeting in the Oracle building in the Tech Center and very little other than that going on.

5 years later, we're at over 500 members. At last I saw was like 510 or 520 members. And we've got the meetings in the Tech Center. We've also got a meeting in Boulder that we do at the, uh, at the CA, formerly Rally Software office there. And then we have a meeting downtown.

So 3 different meetings for 3 different populations, very vibrant communities in each of those areas. We do happy hour events Trying to kind of move them between the different areas. We do the training events every couple of months. The vision there is if you're a member of the chapter, everything's free. So you get to come to the monthly— the lunches for free.

You get to have these full-day trainings, which I'm so proud of what we've been able to do there, getting full-day, high-quality technical trainings or non-technical in some cases. So Alex actually gave a full-day risk training last year. And, you know, in Q1 of 2017, we've got a training on the books for how to build your own PKI, public key infrastructure, coming up. And if you're a member of the chapter, it's always free, and we really just try and make sure we're delivering as much value back to the chapter as we can. Yeah, and I think that this— the road that we've gone down with ISSA really is sort of the genesis of why we're doing Colorado Equal Security as well.

It's You know, ISSA is great and we do a lot of great things, but it still isn't for everybody. It doesn't cover all aspects of security, at least not in the depth that some people would like for some areas. So, you know, we want to make sure that we can help espouse the other organizations that are out there and, you know, hopefully, you know, get them, you know, more attendance and, you know, have even better meetings, you know, try and move the whole community forward. You know, and there's, there's groups that we just don't have a lot of access to visibility. DC303, the kind of our, our hacker friends here in town, are one of, one of the best communities of the, of the black hat groups around as well.

But, you know, we, we're not a part of that, so we don't have as much visibility. That's something we'd love to, to help get the right folks involved with. Um, so anyway, you know, I joined you at helping with the RMISC conference over the years, and we've had the opportunity to to help that conference become something, something pretty impressive. Rocky Mountain Information Security Conference, every May we really put together what is clearly the best security conference here in the Rocky Mountain region. 2016 we had, I believe it was 968 attendees if I remember correctly.

We expect 2017 to kind of blow past that. We'll give you guys updates on a weekly basis around where RMISC is and what's going on, but I can give you some you know, lead-in information. We have— we've confirmed a few different keynotes already for that. Jeremiah Grossman. Jeremiah is one of the founders of— or the founder of White Hat Security and formerly the CEO over there.

He's going to give us a keynote. Cal Fussman, who you guys may not have run across yet, but I guarantee you, you're going to love it. He has written a column for Esquire magazine called What I Learned for decades, and in that capacity he's had the opportunity to sit down with some of the biggest names in the world— Ronald Reagan and Mikhail Gorbachev during the Cold War. He sat down with Robert De Niro, Arnold Schwarzenegger, Michael Jordan, just all these people. And what he'll do is he'll share some of his stories and experiences that he's learned through that.

Very excited to have him. And then we just confirmed last week Josh Blue, the stand-up comic who won Last Comic Standing is gonna give the closing keynote on Thursday night. So hopefully you guys will be able to make it to that and enjoy some learning and some fun as well. We have 2 more keynote spots that we'll be able to announce pretty soon, but I don't want to talk about it till the ink is dry. So, and as you mentioned, Robb, that's 4 keynote spots, right?

There's 5 total, but yeah, 5 total. So part of the reason why we have that many is because this year we've expanded the Rocky Mountain Information Security Conference to an additional day. So we have 2 full days of, you know, your sort of standard tracks of speakers, and then it's still a 1 day of pre-conference trainings. So, you know, again, getting better and better. We got basically 3 full days of conference this year.

Yeah, that's great. Thanks for pointing that out. And, you know, hopefully you guys will make this work out for us. This is an investment, and the more folks who show up, the better. We do believe that the content's only going to get better though, and I look forward to having you guys there.

And of course, with that one, you can always find more information on the conference at rmisc.org. So the last thing I talk about with my own personal community involvement is, you know, I've had the opportunity to, over the last 2 and a half years or so, help put together some, some dinners with security leaders in town that we call CISO dinners. And a lot of the folks who we're going to talk to on this show are folks that we've— I know you and I, Alex, have both developed relationships with over the last couple years. And it's really part of the genesis of this idea is as I— as we started to do these community building dinners and getting to know these folks, just realized what a rich, deep community we have. And really having the chance to sit down with folks like Drew Labbo, who's going to be one of our early interviews on the show, CISO at Denver Health, folks like that.

And there's a whole lot more that are going to be coming that I'm not going to throw out there until we have them recorded and confirmed. But getting the chance to know these interesting folks who, who are leading the security community here in Denver is one of the exciting things about, about this show. Completely agree. I think it's gonna be a lot of fun. I would be remiss if I didn't mention the fact also that, you know, you've been involved the past few years with helping to uh, also organized the BSides conferences that we've had in town, um, that at least in a couple cases have, uh, followed on, uh, after RMISC.

Um, so I don't know if you want to talk about BSides or anything. Yeah, I think that's great. Thanks for bringing that up. So the BSides Security Conference was, was a— and hopefully Banshee or Jericho can smack me if I'm wrong— was initially created alongside Black Hat and DEF CON in Vegas. And the idea was the people who submitted for those conferences in Vegas who didn't get selected, well, they still had some really good content, the content that was really worth putting on.

So that's where the B-sides come from, right? This— if you— those of you who are quite a bit younger than us may not, may not remember, uh, like singles that used to get released, musical singles. Like, you know, there's a hit song that would get released on a cassette tape or a record. On the one side's the single that was a hit. On the other side is called the B-side.

It's the other song. And so that's the idea here is the B-side would be the talks that didn't make the original cut but are also often, you know, very, very good. So that was a movement that was started. I think Jack Daniel was one of the original founders as well, but Jericho and Banshee, who are local security personalities, could probably provide some insight there. Anyway, Denver, we started one gosh, uh, 2010, 2011, something like that.

And I got, I got to go to it and I liked it. I liked it so much I was like, well, hey, let's do it again. I think it was 2010. And, uh, and I started emailing, uh, Jobo, uh, Jobanel, who runs Alchemy Security in town. He had hosted it back then.

Like, hey, let's do it. And, you know, no one, no one really wanted to put the effort in in 2011. And then 2012, we're like, hey, no, we really need to do it. Get one going. So I— so, you know, they needed some help and I ended up volunteering to get that moving.

And for a couple of years I was, I was involved. We moved that next to RMISC the day after it so that, so that, you know, folks who happen to be flying into town could stick around and do both. In 2016, I was not a part of the, part of the group at that point. Jacob Torrey actually helped organize that organization or that conference. But that's been a great vibrant community.

You know, you'll get 200, 250 people just to show up for this, you know, for this awesome fun sharing opportunity where, you know, there's, there's always beer starting first thing in the morning. There's a lockpick village if you want to learn how to pick locks. That's your opportunity to do it. There'll be a capture the flag program if you want to, to test your hacking skills against others there. And then of course there's interesting tracks that get more into the offensive or pen test side of things instead of the defensive side, which is what we focus more on at RMISC.

Anyway, big supporter of that. This year they're having it the 12th and 13th, which is the Friday, Saturday after RMISC in May. So if you, you know, if you're already going to be around in town and you want to go to both, highly encourage it. Great. All right.

So I think we've kind of, you know, gone through why is it that we're doing this podcast? What can people expect going forward? You know, what's your background? Um, professionally and of course in the community. And we've talked about my background, uh, as well.

Anything else we want to cover here today? I don't think so. I think, um, just to let everybody know to, to be on the lookout for, for podcasts coming out soon. Um, you know, as I mentioned, we have a SoundCloud page where we're going to be hosting these, uh, Colorado Equals Security, uh, in SoundCloud. And, uh, you can always find all the information about what we're doing and, and news and everything else at colorado-security.com.

All right, and go ahead and stay on here after the break. We'll come back and we'll give you the news of the week, uh, and what current events are coming up. Thanks, Alex. Thank you, Robb.

Welcome to Colorado Equals Security podcast. This is our first effort at a newscast here for the week of February 6th. It is Super Bowl Sunday right now, and I'm here with Alex Wood. Alex, did you have a chance to watch the game? Hey, Robb, I did watch the game.

You know, it didn't turn out as I was hoping. I was rooting for the Falcons, but that's the way it goes sometimes. Well, congratulations to the Patriots and the Patriots fans. I also was rooting for the Falcons when there was that drive. I think it was late 3rd quarter where the, the Falcons had those 2 amazing plays, got the ball down to like the, like the 30-yard line or 20-yard line, uh, and then had that, that terrible sack and that, that holding call that really felt like the, the backbreaker for me for them.

Anyway, fun game, uh, glad to get to watch it. A little disappointed by the outcome. Exactly. Well, we have a lot of news to go through today, so let's get started. Uh, generally as we do the newscast, we're only going to have one week's worth of news to to share.

We did go back through the last several months and pulled out the biggest stories we'd seen, and we wanted to go through all those with you guys today. So we're going to go a little quicker today than usual through the, through the individual stories. Top of the list, Optiv. If you guys are not familiar with Optiv, this is a good chance to get to learn who they are. Optiv was created about, about a year and a half ago in combination between AccuVant and Fishnet.

When, when those 2 companies merged, they created the new company Optiv, and they are the world's largest security services and reseller. And fortunately for us, they're headquartered here in Denver. That's always a good thing. Alex, you want to talk about some stories about Optiv? Yeah, so, you know, Optiv is headquartered downtown, and there is a new office tower being built over near Union Station.

It's at 1144 15th Street, and Optiv has already leased out more than 200,000 square feet of that new office tower. So that's pretty cool. Yeah, so they're gonna be— from what I hear, rumor on the street is they're actually gonna have their name at the top of the tower. So when you drive into downtown coming from the Auraria or Spear entrances, you're gonna see a security company's name right there at at the beginning. That's pretty neat.

Of course, that is a rumor. We'll see if it comes true, but I hope so. It'd be great to see those guys in the Denver skyline. That would be a cool sight to see. One other— yeah, sure would.

They had one other big piece of news a few months ago. Optiv had been, had been pretty well known and had made it known that they were planning to do an IPO, looking to at least have a partial IPO. And then that changed. You hear that changed recently, right? Yeah, so, um, they, uh, they were, uh, purchased by, uh, by private equity as opposed to going through with the IPO.

Uh, KKR, the, the private equity firm, uh, purchased a majority stake. Um, I believe Blackstone still has a minority stake. Blackstone was a previous investor. Yeah, KKR is the new majority owner, uh, kind of responsible for oversight and I assume having, you know, the majority of the board, but Really interesting for Optiv. You get to see what they do with KKR to help lead them, and looking forward to seeing where that takes them in the future.

I know one of their big pushes has been to move to a mix with a whole lot more services versus, you know, product sales, and hopefully KKR can help them accomplish that goal. Well, next thing we wanted to go through— Colorado has an acting US Attorney going after cybercriminals here in town. Pretty neat stuff. This is not a Colorado-focused investigation, but we do have U.S. Attorney Bob Troyer located here in Colorado leading up a team of 6 attorneys who, who are really going after cyber criminals from around the world. They've been involved with things such as the U.S. v. Snowden investigation, economic espionage, trade secret theft, some of the denial of service attacks, child exploitation, child pornography cases.

Really a lot of different stuff that they're doing. And while they're not— like I said, they're not specifically looking in Colorado, it's great to know that Colorado is the home for this group. Yeah, for sure. You know, we obviously focus more on the business side of cybersecurity, protecting the organizations that we work for, but knowing that the folks that are doing the legal side of that are here is pretty cool. Yeah, so next news item here for us, uh, Coalfire.

Coalfire is one of the, the biggest security firms definitely in town and really around the world, um, providing security services really around compliance. And anyway, the big news there is that they have acquired, uh, one of their competitors, Veris. Veris is, is very similar in a lot of ways. They offer compliance work. They have, um, one of the neat things about Veris they have one of the best research arms out there.

If you go, you know, spend much time looking through technical research, you'll find some really good stuff written by Varus, really kind of pushing the edge on offensive security and how to improve systems. You hear it. What do you think about this acquisition? You know, it reminds me a little bit of Acuvant and Fishnet coming together, you know, 2 similar type companies, you know, maybe not having overlapping markets or overlapping customers, but similar services. So, you know, they come together and can make each other stronger.

Yeah, very cool. Hopefully this allows them both to get better and grow and offer more services to the customers. Uh, next news item, you know, a little bit different scale, right? You know, Coalfire at a couple hundred people acquiring Veris with a couple hundred people. And the next on the list is CenturyLink acquiring Level 3.

This is obviously CenturyLink, one of the big telcos around, and Level 3, one of the big backbone providers, coming together. Alex, you have any thoughts about what this merger is gonna look like? Well, you know, I think that, you know, while they're both fairly big players already, you know, this is gonna put them combined to be on the scale of, you know, an AT&T or Verizon, you know, one of the real premier large-scale network carriers in the country. So I think that that's, that's a really cool thing, um, you know, both of those companies, uh, being located here. Yeah, you know, CenturyLink, um, I believe this, uh, came out of Louisiana, but, you know, has a very large presence here.

So, uh, so I think that's, that's going to be really cool. Yeah, I know CenturyLink's headquarters, I believe, is officially Louisiana, but they do have a lot of their IT leadership here in Denver, including Dave Mahan, who is their CSO, Chief Security Officer, one of the, one of the well-known guys in the area and, you know, in the government, and really has done a lot to help security in the telecommunications area. And on the other side, you know, Level 3 side, Dale Drew, the, the CISO there, is, is exceptionally well-known, well-respected in the security community, and he was also one of the guys called to talk about the Mirai botnet in front of Congress after, after that takedown of Dyn. It's going to be interesting to see how this plays out. From the community perspective, I'm a little disappointed to see, you know, there's— it seems like there's a little risk that these 2 great security departments who add so much to the community may end up, you know, shrinking or changing as a result of this merger.

And I hope that there's some way we don't— we, we can avoid that and get a lot of value to to the community through this. Yeah, you know, hopefully like these other mergers we were talking about, uh, the security departments can come together and, you know, make for one stronger department and, uh, and coexist with, uh, with everyone that's already there. Yeah. So as we talk about these local security companies, you know, we, we have in the Colorado region— and this is one of the reasons we started the podcast— is we have a lot of talented security entrepreneurs who started companies here, from the big boys. We mentioned Optiv already, then we have LogRhythm up in Boulder, who's, you know, one of the top SIEM providers in the world.

We have Ping Identity in downtown Denver, who's one of the big players in identity and access management. Webroot in Broomfield, who does antivirus, mostly consumer antivirus, but also enterprise, and then getting into threat intelligence as well. We have those kind of 4 big security companies, and then there's a tier below them, the up-and-coming companies who are doing great stuff stuff. Red Canary, the guys who do managed security services for endpoint detection and response. And then a few that we, that we're about to talk about here who have taken some funding recently.

And it's neat to talk about those companies that are, you know, going from small to medium or from, you know, tiny to, to having, having some funding. Starting off here, do you mind just starting off talking about the ProtectWise news here? Sure. So the first one on the list is ProtectWise. Um, you know, they're based in, in downtown Denver and they offer, you know, I think I like to think of them as, you know, sort of a next generation, uh, you know, SIEM type product.

But, you know, they build themselves as being a, uh, a DVR for your network and they landed $25 million to help with expansion. So I think that's some really good news for them. Yeah, I'm excited about this. I had the chance to sit with ProtectWise last month. I got to meet their, their, their CEO Scott Chasin, who I've met once or twice before, but we sat down for a while.

I got to look through the product, and I'm really impressed with what they've built. You know, any, any security department that's looking to get improved visibility on the network, improved analytics about things that are happening on your network, this, this is a play that you really should take a look at. They've, they've made not only a beautiful product, and it is beautiful. It is, it's something you'd want to have up on a screen and you want to interact with. It makes it easy to work with, but also done a good job of taking various threat information and making it easy to digest as well.

So anyway, highly recommend talking to those guys if you, if you run a security department. Yeah, and then the next that we have on the list is Swimlane, also a local security startup here. They raised $6 million and You know, Robb, I'm not really familiar with Swimlane. Uh, you know, what is it that they do? Yeah, I don't know them real well either.

What I do know that they do incident response orchestration, so helping you deal with incidents in the organization, and there's some automation aspects to that. I don't know the product very well. I guess this is a kind of an invitation to the Swimlane folks to reach out, let us know what you guys do. We'd love to talk with you and understand what you guys are doing. Very cool to see the, the $6 million raised there.

Hopefully that's what it takes for them to get the product development and marketing that they need to, to build a company that can grow and be successful here in Colorado. Yeah, and the next one we have on the list is SecureSet. They raised $4 million. SecureSet is sort of twofold. First, their, their primary mission is being, you know, a security training academy You know, so they have these 6-month, you know, I don't want to call them boot camps, but, you know, highly intensive training sessions for folks to get really from, you know, any point in IT skills to being a, you know, really top-notch sort of entry-level cybersecurity person.

As I said, they got $4 million. I think they're going to use a lot of that for expansion. They just opened a campus in Colorado Springs, and I believe that they're opening a location in Florida. And then the second part of SecureSet is that they're starting an incubator for other startups to help get them off the ground. Yeah, I'm excited about really both parts of that.

You know, the incubator obviously aligns really well with what we're trying to do here and getting the word out about what happens in security in the Colorado area. On the training side, you know, I've had the opportunity to sit down with a number of their graduates and and talk to them about opportunities for jobs. And in fact, I had the chance to make an offer to one of the folks over there. I really like what SecureSet is doing. I think that they're, they're helping, you know, uplevel the security talent in the area.

We're gonna need more talent. We're gonna need more folks getting into the area. So I respect what they're doing and look forward to seeing their successes going forward.

All right, so Next, we have some companies that are moving headquarters as opposed to taking more funding. The first on that list is Route 9B. They were a North Carolina-based cybersecurity company, but they had a presence here in Colorado Springs, and they're actually going to be moving their headquarters there. It's an interesting company, one that I'm not particularly familiar with, but they were ranked number 1 on the Cybersecurity 500. Yeah, I've only heard good things about them.

I haven't had a chance to work with them professionally yet, but I do know a lot of folks who have and have said a lot of good things about them. Looks like they have a number of services and they also have some products. So if you're interested in getting some assessment work done, consulting, they, they can help with that. They also have some network hunting products and visualization around identity access management. Anyway, good stuff.

Recommend you guys take a look at them. Very cool to know that Colorado Springs is going to have the number 1 on the Cybersecurity 500 list. Pretty good stuff. A second company that's moving their headquarters is from— to Denver here is actually coming from Atlanta. So maybe the, the Atlantic Southeast there is, uh, is losing to our gain.

eFolder, who is a cloud storage provider, is going to be moving their headquarters here. They, they're— they compete with the likes of Box and, and Dropbox and those folks. Alex, are you familiar with them? I am. You know, we have Joshua Foltz, who's a friend of ours, who's the CISO there.

He is already located here in Colorado, so I'm sure he'll be excited that the, the rest of the company is moving out here. Yeah, pretty cool stuff. Next thing on our list was to talk a little bit about Governor Hickenlooper's State of the State address. In January, he did his annual address, and I was really excited to hear this year he had several mentions about security and cybersecurity. This kind of, for me, came a little bit of a surprise, but a little bit of a vindication as well, right?

That what we're doing has gone beyond a niche technical thing to being something that really needs to be considered kind of across the board. Alex, did you have a chance to either look at those or read them? Yeah, you know, I think anytime you have elected officials talking about cybersecurity, you know, especially here in Colorado, you know, it's a positive, really does reinforce the fact that cybersecurity is becoming a greater and greater issue, not just, you know, for us, but for everyone. Yeah, very cool stuff. And I know he was, you know, he was a big part of getting the funding and getting the plan in place to create the training facility down there in the Springs, the National Cybersecurity Center.

And I'm sure that that was part of what he was talking about. And really the government helping to be a part of solving the skills shortage we have in security across the nation.

For sure. Anyway, so good stuff there. Next on the list is really to give an update about the Rocky Mountain Information Security Conference. RMISC is the premier conference here in Colorado. It's been going on for, This is going to be the 12th year of the conference.

Very, very cool stuff. We had about 1,000 folks last year. We had 958, I think it was. We expect to surpass the 1,000 attendee mark this year. Alex, I know you've been the chair of the conference in the past, although not this year, but I think 6 of the last 7 years you have been.

You want to say anything about the conference and in general, any big news for this year? Yeah, you know, I agree. I think probably the, the greatest conference here in town. You know, we've traditionally had, you know, a 2-day conference where we've had 1 day of sort of a, you know, traditional hour-long speakers, and then, you know, a day prior to that with an optional either full or half-day training sessions. And this year we're increasing that to 2 days of Uh, for the full conference and then still the, the single pre-conference, uh, day before that.

So I think that that's really exciting to be able to move up to 3 days. Yeah, it's good stuff. We're gonna have, you know, twice as much track information, twice as many CPEs for those who attend the, the conference itself. A couple, couple announcements we have around the keynotes. Won't spend too much time on this as we want to move quickly, but, uh, Jeremiah Grossman— really excited that Jeremiah is going to kick off the conference on the Tuesday evening.

Jeremiah is the, the founder and former CEO of White Hat Security. White Hat was one of the first companies to come along and do real-time security dynamic analysis of running websites. He's recognized as one of the international leaders, thought leaders, you know, you owe me a drink, for application security. Good stuff there. We on, on the Wednesday morning, we have Kyle Fussman.

Cal is the journalist who did a column in Esquire magazine called What I Learned, where he just talked with the who's who throughout the world for, you know, 25 years. Mikhail Gorbachev, Ronald Reagan, Robert De Niro, Arnold Schwarzenegger, Tiger Woods, all kinds of big-name folks have come through and talked to Cal. And he tells a lot of the interesting stories and really what he has learned doing that column over the last few decades, uh, and he'll, he'll be talking to us about security. And I do recommend you guys take a listen to Cal, even if you don't make the conference, take a listen to him. He's a, he's a really good storyteller and an interesting guy.

Uh, and then the last one we've announced is the closing keynote on the Thursday evening. We have Josh Blue. Um, Alex, you want— you know Josh, you want to give a little— yeah, so for him, so he's not— yeah, he's not what you would think of as a typical speaker at a security conference. You know, he's a comedian. Uh, based out of Boulder.

And, you know, a few years back he won Last Comic Standing. Um, you know, a really funny guy, and I think he's gonna, uh, put on a good show for us. It's, you know, it's not necessarily going to be, uh, you know, what you would think of as a security keynote, but I think it's going to be a great way to close out the conference. Yeah, I think when you get to the, the closing keynote there, it'll be time to, to grab a drink, sit down, and enjoy some laughs and hopefully, you know, relax after a couple of long days. So RMISC, it's going to be May 9th, 10th, and 11th.

That the 9th, the Wednesday, Tuesday is the training, and then the, the full-day tracks of the 10th and the 11th, the Wednesday and the Thursday. The CFP is closed. We'll be able to give you guys some info from this, from the presentations as they get accepted. We'll, we'll kind of let you guys know what the highlights are going to be. Registration should be opening up in a couple weeks, and let you know when that's up as well.

We'll definitely get you in before the, the early bird expires. So look for— look forward to more of that coming up. Next section here, we want to talk about any job changes. We have a few folks who've changed jobs in the last few years, and we want to recognize them and give a congratulations, let the community know what's, what's happening there. First, Matt Shufeldt.

Matt was the CISO for Sports Authority for quite a while. I think he was at Sports Authority for about 12 years. He left there middle of last year to take over as the the Business Information Security Officer, or a BISO, over at Trizetto, which is a wholly owned subsidiary of Cognizant. At the time, Trizetto didn't believe in giving out CISO roles to folks in the business units, but it didn't take long for them to recognize really what a stellar professional Matt is. And just, I think it was October of last year, he was promoted to the CISO for Trizetto.

So big congratulations to Matt. I'm glad he, he landed really well. I know Trizetto got a great guy out of Matt. Yeah, congrats to Matt. Um, you know, of course, you know, one of the reasons for him leaving Sports Authority was the financial troubles that they were in, and of course they ended up folding.

You know, another person that was there at Sports Authority but left and has, uh, landed a good job is Merlin Namuth. He is now leading the security program for Red Robin, obviously the the hamburger restaurant chain of hamburger restaurants that's based here in Colorado. So congratulations to Merlin. I think that's going to be a good fit for him. Yeah, congratulations to Merlin.

And also congratulations to Bill Daniel. Bill was the, uh, the director of security at Red Robin before Merlin, and he moved over to MarkWest Energy.

Yeah. And so, uh, next on our list we have Nancy Phillips. Uh, I was coworker of Nancy's at Kaiser Permanente. So she is moving from there to be the CISO for Datavail. Datavail is a database management company.

So I think they're really lucky to have Nancy. I think she's going to do a great job over there. Congrats to Nancy. Next announcement here, Christine Vanderpool. She was the CISO for Molson Coors for a long time.

She has left— she's left Coors and she's moving over to Kaiser Permanente where she is the new deputy CISO reporting into Jim Goddard over there. Yeah, congrats to Christine. I think that she's going to do really well over there. And the final person we have on our list is Chris Martinez. Chris is the new CISO for DigitalGlobe.

He was CISO for, for Aetna, one of the business units at Aetna, and just recently moved over there to DigitalGlobe. Yes, Chris was the CISO for their consumer health business unit, also known as iTriage. Big congratulations to Chris. I know DigitalGlobe is one of the bigger, more important technical companies here in Denver that not a lot of folks have heard of. They do a lot with satellite images for, for both public and private sector, and they work with a lot of those 3-letter agencies.

So a lot of sensitive info that he will have the opportunity to secure. They're probably watching us right now. Probably are. They're probably pretty bored. Well, let's go ahead and move over to the upcoming events, the event calendar over the next month here.

First thing on the list is there's an InfraGard active shooter or workplace violence event here in February. You have to be a member of InfraGard in order to get all the details on these events. If you're not a member and you're interested in getting involved in this, go ahead and, you know, look up Denver InfraGard and get yourself signed up. There's a a background check and a vetting process involved with that, but it might be something that's interesting. They do have a lot of information that really helps you get visibility into what's going on globally and nationwide.

Also this week, ISSA has their February chapter meetings. Those are Tuesday and Wednesday. Tuesday the 7th downtown— or excuse me, in Boulder for Tuesday lunch, and then Tuesday evening, it'll be at downtown Denver, and Wednesday lunch will be in the Denver Tech Center. You can view all of the meeting information at denver.issa.org. This month, they do have a gentleman from the Department of Homeland Security coming to talk about what resources there are from the federal government to help private sector and folks outside of the government with security needs.

Highly recommend taking a look at that and, and try and make one of those meetings if you can. And then, uh, next on the list we have the, the February ISACA chapter event. Uh, that's on the 16th of February. So Brandon Williams from the, the governor's office is going to be talking about 2-factor authentication. Uh, 2-factor, you know, very important technology.

So I think that that should be a good meeting. Yeah, that one's one I personally would really like to be at. I'd like to hear, you know, the, the story of how did they— how did 2-factor go for the state and what did they learn? What went well? What didn't go well?

Very good stuff.

The 16th of February, we have the CTA, the Colorado Technology Association 101 course. This is the 16th at noon downtown. Anyone who is interested in learning more about what the Colorado Technology Association does and get some visibility into what resources there are, this is a good chance for you to show up and get that information, ask your questions. Great. Yeah, the next one we have on the list is the Cloud Security Alliance, their February chapter meeting.

Originally, that was going to be the 13th of February, but it's been moved to the 20th, I believe, to not be in conflict with the, the big RSA conference in San Francisco. Oh, that's a good point. Not a lot of folks are going to be around next week. Yeah, for sure. So Mohammed Malki is going to be speaking at that.

He is also with the the state of Colorado. So folks from the state getting out and doing a lot of speaking this month. Yeah, Debbi Blyth, the CISO for the state of Colorado, is a big supporter of the community, and I'm hopeful we'll get her on the show to do an interview pretty soon. I believe she'll be happy to get involved here. That week we also have ISSA's training.

So the ISSA chapter here in Denver tries to put on full-day trainings that are free for members. These are the kind of trainings that you'd normally pay a few hundred bucks for, getting in-depth technical training or hands-on risk training. In this case, it's a PKI training— how do you set up a public key infrastructure using free tools? So one of the members of the chapter has, has done this in his own organization. This is Crane Rutton, who works for Distil Networks.

Crane set up a PKI infrastructure internally, and he's gonna come, you know, show us, walk the members of the chapter through how to do this. So the, the first instance of the training is going to be the 21st up in Boulder, and then the second one will be on the 23rd in the Tech Center. So go to whichever one's closer to you. However, space is limited. Sign up as soon as you can.

As always, the Denver Tech Center ones are gonna sell out. They're gonna sell out earlier. So if you want to be in the Tech Center, go sign up to that one as soon as you can. Yeah, and then next on the list, the, the 22nd and 23rd of February, The Colorado Springs ISSA chapter is having their monthly meetings. So on the 22nd, they have their evening meeting, and then on the 23rd, they have their lunch meeting.

So you can check out more information. Just take a look at the website. We've got links to get registered for all these events. So that takes us through the end of February. There's a few events that come out of February that we probably want to highlight.

The 10th and 11th of March is the Rocky Mountain CCDC, or the Rocky Mountain Collegiate Cyber Defense Competition. Alex, you want to talk a little bit about what RMCCDC is? Yeah, for sure. So, you know, this is a competition for collegiate teams, cybersecurity professionals at— or not professionals, cybersecurity students. Their charge is to get an infrastructure and protected as part of the test there.

It's a pretty cool environment. Not only is it technical, but they also have to do communication. They get thrown a bunch of curveballs. There's a lot of volunteer support there. They have a big group of folks that are trying to attack the different student groups, and so there's some really good folks there making sure that the students are on their toes.

I highly recommend getting involved if you can. This is one of the most effective, valuable events I've seen in security. I really applaud the, the groups doing this. Uh, next on the list, big stuff coming up. The, the 16th of March is going to be a big date.

There's, there's 3 different big things happening. Obviously, ISACA's monthly meeting is that day, but then we have a full-day conference by OWASP called SnowFROC. SnowFROC is Denver OWASP chapter's big annual meeting. If you are an application security person or you want to get involved with application security, this is the conference for you. Take a look, get a ticket, and show up and, and learn something.

Yeah, then also in the evening on the 16th is CTA's C-Level at Mile High. This is one of their, their big annual events. It's a, you know, an executive-level mixer that they have. So if you're a CEO, CFO, CTO, CISO, this is something that you're probably going to be interested in to take a look at. Yeah, good stuff.

The last 2 things on the agenda in the next few months, Rocky Mountain Information Security Conference, we talked about already, that's May 9th, 10th, and 11th. And then following that, we're going to once again have a Denver BSides Security Conference happening directly after, so the 12th and 13th. B-Sides is taking place. Get involved. They always need volunteers, always looking for speakers.

I love B-Sides. You know, you go to, you go to the RMISC, you go learn a lot, but there's a lot of folks wearing ties and it's a whole lot more corporate. You go to the B-Sides conference and everyone's holding a beer starting at 9 in the morning, and you're really there to socialize and have fun and learn at the same time. Good stuff. Well, that takes us to the end of the agenda here.

We, uh, we We did went a little bit longer than we hoped to in the future weeks, but we did have a lot more to go through. So until next time, this has been Colorado Equal Security.

To learn more about the Colorado security scene, check out colorado-security.com. There you can see a list of local security groups, a calendar of upcoming security events, and learn more about Colorado Equal Security. Reach Robb or Alex by emailing info@coloradosecurity.com. Until next time, remember, Colorado equals security.

Back to all episodes