All episodes

Drew Labbo

Apple Podcasts Spotify SoundCloud

Week two in the books

Well, the podcast for 2/6 was a bit rough (true fact - we got to record the whole newscast for the first podcast twice, due to technical difficulties). But this week went a lot smoother. We're looking forward to getting your feedback on what you like, what you don't like, and what you'd like to see added. Based on last week's feedback, this week we've added a summary of interesting jobs we've seen posted.

As always, this week's episode is available on Soundcloud page here. But we're now also listed on iTunes and Google Play.

Reach out with any questions or comments to info@colorado-security.com

Feature interview:

This week Alex and Robb sat down with Drew Labbo, CISO at Denver Health. Drew told us about his career, how he got into security, how he got such a great job, and what keeps him busy at work. If you don't know Drew, I recommend you reach out. He's a fine fellow.

Local security news:

Job Openings:

CISO moves:

  • Dan Collender hired as CISO for Ball Aerospace

Upcoming Events:

View our events page for a full list

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13014 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for the week of February 13th. Uh, Alex, Happy Valentine's Day.

Oh, Robb, you remembered! Absolutely. It's actually a couple days before Valentine's Day. Alex and I are in RSA at San Francisco for the RSA conference. Yeah, and I'm excited about a fun week here.

We've got ISSA events going on, and I'm also speaking on Wednesday morning. Fantastic. For folks who might want to make the session, you want to give some details? Sure. So I am speaking on a panel.

It's, uh, it's about the, the day in the life of a CISO. So that should be exciting. 8 AM on Wednesday morning. So for those of you that are here, no partying Tuesday night. Bright and early.

All right, well, let's go ahead and get started. Uh, we don't want to kill too much time. Did you like the new lead-in we've got? Obviously we have, we have a new, uh, more professional sounding lead-in for the, for the show. You're not professional?

Yeah, we actually got CJ Adams, uh, who's a local voice guy, to to give a little lead-in, and you guys will see at the end of the episode as well, we have an exit there. And there's also that new transition, a little treat for folks halfway through the show. So let's go ahead and kick off with the news. First thing on our list today is to talk about the Colorado Business Journal article that was about the biggest risks for small and medium businesses. This was pretty surprising to me.

Did you get a chance to review this? You know, I did. There were a couple statistics in here that really jumped out at me.

I think the biggest one, it said more than half a million SMBs will shut down in 2017 because of cybersecurity breaches. That just seems incredible. Yeah, there's also in this article that 60% of SMBs hit by a cyberattack wind up closing their doors within 6 months of the breach. You know, one of the things that I've always said, Robb, is that, you know, there's not a whole lot of evidence of of breaches, you know, harming companies in a major way. You know, you, you hear the big ones, Target and Home Depot and stuff like that.

You know, maybe there's a, a short dip, but, you know, eventually those companies come back strong. Um, maybe that's not the case with SMBs. And yeah, it might actually be that those companies who can least afford to, to pay for the security talent and the program are those that most need it. Uh, because— and but there's also another piece of data here, correlation and causation, right? What percentage of these companies weren't going to make it anyway?

Exactly. And, you know, I know that there's a vast majority of companies that don't survive, SMBs especially, anything. They just don't survive in general. And how much does security contribute? Anyway, don't know.

Obviously, this is just a really interesting article. Take a look at the show notes to review for yourself and see what you guys think. Yeah, so next on the list, we have something very exciting, not necessarily security-related, but still pretty cool. So in Lone Tree, there's a dedicated drone store that just opened. That's pretty fun, huh?

I didn't— number one, I didn't know that there was such a thing as a drone store. And number two, holy smokes, it's right down the street from us. I got to go take a look at it. Yeah, exactly. Very cool.

So that's fun. Cyber patriots. So this is one of the neater trends I've seen in the last few years. And it feels like this is one part of a larger trend that's going to really help the industry. So Cyber Patriots, it looks like it's basically similar to what CCDC does where you get a group of students together to practice cybersecurity defense drills, right?

Yeah, for sure. And this one is specifically with Altona Middle School, which is in the St. Vrain School District, which is up north, sort of Longmont, Fort Collins, that kind of area. And they have this, the Cyber Patriot uh, program going on at their school. So yeah, it's a competition, uh, much like CCDC but, but aimed at, uh, at younger kids. So this is the, this is the kind of trend that we want to encourage.

Anyone listening, if you have the chance to help volunteer and help these programs at your own local schools or wherever they're happening, uh, please do. Take a look at the video in the show notes. We have a YouTube video that's kind of highlighting what they're doing there at Altona. Granicus has a new CEO name. So Granicus is a, is a locally headquartered company that was recently merged with GovDelivery in downtown Denver.

Uh, the Grandicus has a new CEO. Uh, they, they do play in the security field, mostly delivering into the government. Thought that was interesting news. Yeah, exactly. Um, also another company, uh, that raised some capital, uh, cloud computing company Faction.

Um, I don't know Faction, but they raised $11 million in capital. Again, another indication that the The startup market in Denver is cooking along. Yeah, and very similarly, Cloud Elements is another Colorado-based cloud security company, and they raised $13 million. So this is a good time to be a Colorado cloud company, and it looks like there's quite a bit of equity to— or capital to be distributed there. Exactly.

Next story, IQNavigator. They're a company that's headquartered in the Tech Center. I think if you work in the Tech Center, you probably know that they have a building near Fiddler's Green that has their name on the top of it. I think that that's always a pretty cool thing. And they are merging with a company called Beeline, and they are— they're getting a new CEO from Beeline.

Yeah, so the article says merging, but there's kind of a little subtext there. It looks like, you know, Beeline's the larger company. Beeline CEO is taking over the new organization. So, I don't know, I do know one or two folks over at IQNavigator, but I haven't heard the story yet on what the narrative there is. But it sounds like maybe the larger company might be kind of swallowing the smaller one.

Next, Datavail. We talked about Datavail a little bit last week. That's where Nancy Phillips went, right? Nancy Phillips is now the CISO at Datavail. They're in the news because they made an acquisition.

Um, what do you know about that acquisition, Robb? Well, it looks like, you know, Datavail is that, you know, database and data services company. Um, they bought a Toronto-based, uh, Navantis company on, uh, a couple weeks ago. I don't know much about the acquisition other than, you know, Datavail, uh, has acquired 2 companies in the last year or so, um, as they got some pretty big funding recently, and that's allowed them to do some additional acquisitions. Sounds like Nancy's gonna have to do some M&A work over there.

Yeah, I think Nancy, due diligence time. Hopefully, actually, you did that quite a while ago. So this isn't security related, but this is pretty neat. I don't know if you guys had seen it, but BP, British Petroleum, is moving their, their North American headquarters from Houston into Denver, and they're supposed to get here in early 2018. Yeah, and obviously we don't know about what that means for jobs and for security with BP, but I think that that's a pretty good trend that, you know, we may have some folks here doing security for BP.

Yeah, I love to see, you know, people looking at Denver as a destination to bring their companies, whether they're security or not. It's going to help the security industry here for sure. Similar story, TapInfluence, which is a marketing company, is moving their headquarters to Denver. I don't know TapInfluence, but it sounds like they probably do something with mobile. That's what it would sound like to me.

Again, great indication that the business community is thriving here in Denver. So next on the list, we have, I think, what is a really interesting article or set of articles from Matt Sharp. Matt is the former CISO at Crocs. I think we all know them from the the silly rubber shoes.

And Matt actually left Crocs and went on a, I don't know, was it 1 month, 2 months, several months? Was it a vision quest, Matt? Matt went, he left basically to go on a tour down in South America, and he decided to come back and start looking for a new thing at that point. Yeah, but I think one of the things that precipitated him leaving was he got his MBA, and so he has a series of articles that he's putting out about lessons that he learned through getting his MBA. So we've got a link to the show notes in that very interesting set of articles.

Yeah, so I think that the title basically is CISO's MBA Lessons. So anyone who's in security might want to read this and think about how the business can better be helped by security. We do have one job change to announce this week. Congratulations to Dan Collender, who is the new CISO at Ball Aerospace. That is really cool.

They're of course up in the Boulder, Broomfield kind of area. You know, Ball is a very large company and the aerospace division is, I believe, based here in Colorado. So Dan was previously CISO or Director of Security for Intrado, and then previous to that he was the Director of Security at Digital Globe. So we talked last week about how Chris Martinez took the CISO role at DigitalGlobe. That was Dan's old job.

Now Dan's moving over to Ball Aerospace. And of course, Brett Bradshaw was the CISO at Ball Aerospace, and Brett was promoted to CIO and had the chance to kind of backfill his role there at Ball. Yeah, I think that that's a really cool promotion for Brett. Maybe he's someone we should get in and talk on the show too. You don't, you don't always hear about folks that are in security moving into more general IT, but I think it's it's definitely a path that is worth exploring.

Yeah, I'd love to talk to Brett and understand what made him decide to do that and how that opportunity opened up for him. Yeah, and Robb, I think that we have a couple updates on Rocky Mountain Information Security Conference. Yeah, so just as a summary for those who weren't with us last week, RMISC, Rocky Mountain Information Security Conference, is Denver's biggest and really only homegrown big security conference. We are in May every year. This year it's going to be May 9th, 10th, and 11th where we're expanding to that 3-day schedule.

Last week we talked about 3 of the keynotes. This week we were able to confirm the final 2 keynotes. So the, the keynote closing on Wednesday afternoon is Andre Durand. Andre is my boss at Ping Identity, where he is the CEO and founder. Ping is a 500+ employee identity and access management company, one of the leaders in the industry.

Andre's going to talk to us about what he's learned in that process about security and hopefully give us some, some tips. The second person we have who's going to be doing the opening on Thursday is John Kindervag. And John, I was chasing John to try and do a keynote at RMISC last year, really based on his work that he did at Forrester when he was an analyst there in creating the Zero Trust framework, Zero Trust networking, Zero Trust computing framework. When I tried to reach him at Forrester, it was quite challenging because with his schedule. I got very fortunate that John in January left Forrester and he became the CEO, or excuse me, CTO of the field for Palo Alto Networks.

And in his new role there, he's a lot more free to do talking, and we were able to get him to schedule as a keynote for Thursday morning. So he's gonna talk to us about things like, you know, hey, with the realization that the perimeter of the network is not a sufficient control point. How do we architect our systems in order to be secure? That's John. Looking forward to that.

Very exciting. So that's the news we have for this week. Let's get into the event calendar. So we've talked about a number of these in the first podcast, but coming up this week on the 15th at Dave Buster's is the monthly OWASP chapter meeting. It's gonna be around wireless technologies.

They always do a great job, a little more technical in nature than some of the other folks in town. So if you want to learn more about those protocols for wireless, that'd be a good opportunity. And they always have good food. We talked about these next ones. ISACA's February meeting where they're gonna have— they're gonna talk about 2-factor.

That's on the 16th. CTA also on the 16th has a CTA 101, learn about their organization. Cloud Security Alliance has their February meeting on the 20th. The ISSA full-day training on building a PKI infrastructure with open-source tools. I actually want to emphasize that one is really exciting where you're going to get just a lot of value, a full day of learning how to do this hands-on.

You should go back to your office the next day and be able to create a PKI infrastructure or maybe You actually create it during the class. I'm not sure, but really high value. And if you're a member of the chapter, it's absolutely free. Yeah, that's going to be on the 21st, I believe, in Boulder and the 23rd down south. 23rd in the Tech Center is sold out, but last I saw, the Boulder meeting had a couple of spots left open.

So also the Colorado Springs ISSA chapter is having their February meetings. They do 2 meetings. One is a dinner meeting and one is a lunch meeting. So I believe the dinner meeting is on the 22nd, and then the following day on the 23rd of February is their lunch meeting. Yeah, CTA— this is a new one on the calendar here.

CTA has a Talent Innovation and Immigration event. So this is for any managers who might want to think more about how can I get talent from other countries, if, you know, visa holders, green card holders, what are the options What's that look like? So something, you know, for those of us looking to hire might want to consider. Yeah, and I think that there's going to be some lawyers there talking about that, so that should be pretty interesting from that aspect. On the 25th, Colorado Springs has their free mini seminar in the morning.

Not a lot of details on this meeting, but take a look if you're in the Springs at the link and learn some more about it. So on the 1st of March, the Cyber Summit USA is coming to Denver. I'm not familiar with their conference in general, but I have received some promotional materials from them. Does look interesting. Looks like a sort of a higher-level executive kind of event, but this is their first time in Denver, I believe.

So we'll have the link in the show notes for where you can check out more details on that event. I think I remember that this is open just to security leaders. Does that sound right to you? That does sound right. Yeah, um, also, I, I, we don't know the group yet, but I can tell you some of the speakers on the list are pretty good speakers.

Also on the 1st is the CTA Day at the Capitol. So this is another Colorado Technology Association event. They're going to be spending some time at the Denver Capitol getting to know our legislators and, and how technology can be impacted by the the legal climate here in, in Colorado. This is really one of the reasons that I like to include CTA, even though they're not focused on security. They give a perspective that we just don't get from many other organizations, getting in front of the, the folks who make laws, giving us the opportunity to, to make a difference to the regulatory and legal landscape here.

Anyway, pretty cool stuff. Uh, next we have the ISSA March meetings, the 7th and 8th of March. Um, Robb, do you have, uh, yeah, the speakers? So, uh, so the 7th lunchtime up in Boulder, uh, over dinner will be downtown at the DaVita office near Union Station. The 8th will be at the— that's Oracle still, right?

That's at Oracle in the Tech Center. The speaker is going to be Crane Rutten. Crane is actually the same guy who's doing the PKI training in February. Uh, he's gonna do a little bit higher level talk at— during the chapter meeting and talk about why he— why you might want something like this and talk about why he did it in his own company. And then on the 10th and 11th of March is the Rocky Mountain CCDC.

We've talked about CCDC a few times. It's the Collegiate Cyber Defense Challenge. So this is the collegiate level program that is similar to the Cyber Patriot we mentioned earlier. And I don't know for sure, but they are pretty much always looking for volunteers. They're looking for volunteers.

Yep. So if you check out the link we have in the show notes, you should be able to contact them and help and volunteer. So that gets us through the next month's worth of meetings. We like to talk about a couple further out than that. CTA, the Sea Level at Mile High, is on the 16th of March.

This is a chance to mingle with the sea level folks of some big local organizations. SnowFROC. SnowFROC is OWASP Denver's big annual conference, and I get to announce here I'm gonna be doing a keynote there. I just found out this last week they asked me to to do one of the keynote talks. And it'll be, I think, 9 AM on the 16th.

And I'll come up with something interesting to talk about, hopefully. And then I'm also on a panel that same day with Jim Manico, Dave Campbell, the CISO over at hosting.com, and, oh, I don't remember off the top of my head who the last one was. I apologize, I'll pull that up here shortly. But then also, we have the Rocky Mountain Information Security Conference, as we mentioned, coming up the 9th through the 11th of May. And then following that is Denver B-Sides on the 12th and 13th.

So I think that the last thing that we want to cover here today is, um, we're going to be trying to, to talk a little bit about some of the available jobs that are, that are in the, uh, the area. Yeah, so, um, this is something that was actually contributed by some of our listeners who reached out and said, hey, love what you're talking about, I'd love to know if, if you have any— if you see guys come across any jobs that are Um, that are interesting in the area that you could talk about, share with us. By the way, Dan Cornell— sorry, Dan. Dan is one of the principals at Denim Group, and he's the, uh, he's the last person on the panel with myself at SnowFROC. Um, so, so on that, that, uh, the job front, if you are someone that is hiring and you have an interesting job that you'd love us to talk about, go ahead and send it to us at info@colorado-security.com, and we'll put on the list to talk about in the future.

Yeah, awesome. So let's go, we'll go through the list here. We try, we try not to focus too heavily just on leadership roles. Um, we really look for the leadership roles to lead a program and also those individual contributor roles which we think kind of stand out a little, maybe, maybe something unique and interesting. Top of the list, uh, one of the most desirable jobs here in town is, is Miller— is it Miller?

It's Molson Coors, right? The Molson Coors Senior Director of Security. Yeah, you know, with the Miller, Molson Coors, all that stuff, it's confusing to me as what their actual company name and who's what anymore, but it's a Director of Security over there. I'm pretty sure that this is the replacement for Christine at Molson Coors. So Christine Vanderpool, who we talked about last week going over to Kaiser, Senior Director of Security at Molson Coors taking her place.

We'll have a posting for all these jobs. Next one, Director of Information Security at PDC Energy. So they are an oil and gas company that is based here in Colorado. Yep. Pearson has a couple of interesting postings here.

They have a Director of Security Governance. Down at Centennial, and they also have a Director of Product Architecture. Yeah, and their, their offices, I believe, are right at South Glen Mall, so that's an interesting location. Next on the list, Director of IT Infrastructure Architecture and Security. So if you're someone that has skills in not just security but overall IT, this would be interesting.

It's for the company called Karcher. They seem to make some some construction and industrial type products. Yeah, I don't, I don't know them, but the posting looked pretty interesting. Nordstrom, next on the list. Nordstrom has a pretty good-sized presence in the Texaner area, and they're hiring an information security manager.

Next, uh, Newmont Mining. They have a global IT and OT security manager. Uh, that could be an interesting challenge, you know, talking about, you know, your normal IT security, but also you know, operation technology, um, you know, SCADA systems and that sort of thing. So that— I think their office is right across the street from yours, right? Is that on Dry Creek, just on the north side of the road, east side of 25?

Yeah, I would assume that this, uh, job is at that location, correct. Uh, Jacobs Entertainment IT Security Manager. We— I didn't know Jacobs Entertainment. When we looked at it though, it was a bunch of casinos that I did know. So it looks like it'd be probably securing the network infrastructure for, uh, for some of the casinos up in Blackhawk and Central Yeah, so if you want to be in the casino industry, sounds like a good job.

And then the last one on the list, Kaiser Permanente, they have a user behavior analytics leader position that is open. I put this one in here because user behavior analytics is a, you know, sort of a cool trend that's going on in the industry. So seeing that they have a position open for that, it's pretty neat. Well, that brings us to the end of our agenda for news. Thanks for sharing that.

After the break here, you're gonna have a chance to listen to Drew Labbo. Drew is the CISO for Denver Health. He's also a friend of ours who we're gonna get— we talked to a week or so ago and looking forward to sharing that with everybody. And take a listen here after— during the break, we have a new little transition piece and we'd love to hear your guys' feedback on this. We're planning to get some different folks to help us with it each week.

So with that, we'll sign off. Thanks, Robb. All right.

Hi, this is Merlin Namath, Director of Security at Red Robin. Welcome to Colorado Equals Security. Before calling Colorado security professionals by Colorado security people.

This is Robb and Alex. We're here with Drew Labbo. Drew is the CISO for Denver Health here in Denver. Drew, welcome to this, to the show. Thanks for having me, guys.

We're really glad to have you. We're gonna sit with Drew today and talk a little bit about his experience, how he became the CISO there, where he sees the industry going, what the Colorado security community looks like, and and what Drew sees coming in the future. So Drew, just as a starting point, why don't you tell us a little bit about how you got into security? Interesting story. I'll try to give you the Cliff Notes.

I was actually working for a software sales company doing data warehousing stuff, not the most exciting stuff, in the late '90s. I kept pushing my boss to get into security solutions. Uh, he finally relented, let me get into it. Uh, there was a job locally that opened up as a security auditor, and I had a little bit of software security audit experience, talked my way into that, and from there just launched off and kept working my way up at that organization into a leadership role. What organization was that?

Uh, Children's Hospital Colorado. Children's Hospital. That's right. You were there until about 2 years ago, right? Correct.

You were leading the security program there? Yes. And what's kind of funny how I got into technology, it was in the late '90s during the year 2000 scare. I found paid computer programmer training in the newspaper Back when people used to read newspapers, applied for this job, got it, and then just kind of launched from there into technology. And it's an interesting journey.

So what year did you join Children's Hospital? So that was in 2004. Okay. As a security auditor. And I assume at that point they probably didn't have much of a security program, did they?

They did not. It was kind of in its infancy and they had a managed services provider that they used here in Denver that helped augment a lot of what they were doing. And then they slowly started bringing a lot of that in-house and let me build that team. I got promoted from security auditor to security manager, and then my boss, the director, quit unexpectedly and they promoted me to that. So it was sink or swim and I started swimming.

And what years did each of those steps happen? So it was 2004, I joined as an auditor. In 2005, my boss promoted me to security manager, did not backfill the auditor position. And then he unexpectedly left and I took the interim role and just kind of hung in there and got through it and then got permanently promoted up to that position. So it was a pretty quick rise.

I didn't expect that. 2005 as well? The director? Yeah. So 2004 to 2005 from auditor to manager, 2005 to 2006 director.

And it just kind of went from there and it was definitely sink or swim. I keep saying that I was so in over my head. It was pretty terrifying. I made some mistakes along the way. Sure.

But learned from them and by some miracle was a success. How did you— do you see the role change when you were there? You know, was there a time when people started to pay more attention to security where, you know, maybe HIPAA started to have some more impact on what you were doing? Yes. So around 2009, the HITECH Act, to get a little geeky, came out and it really was really HIPAA on steroids.

There started to be some regulatory fines if you didn't comply. If you had breaches. And that really got people's attention. Before that, everyone kept wondering, so what if you don't comply with HIPAA? So what if you have a breach?

I actually had a senior leader there say, so what happens if we have a breach? And before that time, before 2009, I had to say, well, we don't know yet, right? We thought it might be a lawsuit. But that definitely upped the ante for sure. And the brand damage around that as it more and more got in the news around 2010 and after that, that really started to get everybody's attention.

So you came in there in 2005, you were a one-man shop doing security auditing. When you, you know, I assume over the course of, I know over the course of your time there, the department grew. Can you give us some history about how it grew and what caused the growth and what those different roles did? Yeah, so when I joined, there was a director of security. He was also the director of the project management office.

I think back then people didn't quite know what to do with security. So as director of the IT information technology project management office, then he let me hire 2 part-time people. It was kind of weird. 2 people were going to retire. We combined it into one job, and then we started getting so busy we went ahead and created another position and brought someone in for that attempt to hire.

That worked out pretty well. And then we had the managed IT services provider. It was about 3.5 FTEs doing some nichey hands-on stuff around security. Your team there, were they, were they mostly doing compliance type work, doing, you know, IT hands-on firewall management? What kind of work did the team do?

So we ended up taking over all of the security countermeasures like antivirus. What we found was the IT division would just turn antivirus off if there were a, like, a user outage. Um, web email, external mail acceptance, anti-spam— again, they would just set exceptions and let spam come in if people weren't getting any emails. So it was really the core competency of caring and nurturing and feeding of these systems So the IT division, humbly speaking, was kind of screwing it up and they dumped it on us. And that's why I needed to build my team, because we kept getting all this, you know, hey, there's ever an issue was, hey, take it over.

Hey, you're doing well, now take some more stuff on. And we just had to— we just couldn't keep up with it all. So, so the— it sounds like a lot of what you guys did was pretty technical in nature, but probably the, the reasons, the drivers for you to have more resources were non-technical in nature, I would assume. You're getting pressure from regulators and legal pressure to develop the security department. Did that drive visibility of the department higher in the organization?

It did, particularly we had a couple of virus outbreaks that really got everybody's attention, and it just kind of grew from there, and that's what really drove it. Virus outbreaks, who's managing antivirus, whoever's managing it's not doing a good job, take it over. Uh, and then with, as I mentioned, in 2009, the high-tech rule, the board of directors immediately said we need to talk to whoever's in charge of this stuff. Uh, and then senior management said, oh, we have this security manager, which was kind of interesting at that, that time. Um, and I had actually just been promoted to director.

And, um, yeah, the board wanted to know what was going on, what we were doing. And the— not very sophisticated, right? A board of directors doesn't know security as a core competency. So They just wanted to know that somebody was paying attention. So did they bring you into board of directors meetings in the 2009 timeframe then?

That's, it's funny that now that you mentioned it in hindsight, that's when they, when I first started getting exposure to the board. And it was because the board was saying, we want to hear about this stuff. And the chief information officer, kind of a deer in the headlights saying, I'm not a security expert. We have this security guy though, Crazy Drew, right? So they, they started bringing me up and having me report up and we started having a qualified third party assess how well we complied with HIPAA or not.

And at the beginning, HIPAA's kind of a journey. I think all compliance is a journey. Started off pretty poor, weren't formally documenting a lot of what we were doing, and we just kind of built those artifacts over time, and we had to present that progress. As an outsider looking in, I'd say kudos to the board for Children's Health for bringing in security in 2009. That's before the Target breach, right?

That's before most board of directors really got interested and asked security to come to the table. And good for you that you got that exposure relatively early on. Any lessons that you learned in talking to the board, you know, you could share with the audience, ways that you engaged with them that worked well or didn't work well? Yes, they do not want to hear about operational things. Management does not want someone to talk to the board about operational things, even if they think they might be interested.

So we had to talk about governance and risk, you know, what are their top 3 risk items? And I think it was really less is more. If I try to get geeky or technical, I would see everyone in the room start to just, you know, glaze over, not pay attention, and really starting to focus on risk. You know, here are the top 3, and when they weren't addressed, keep going back. Here are the top 3.

And the board would say, you know, these 3 risks have been around for 2 years. Why are we not addressing it? And I'd look at management, see what they said about it, right? And it was interesting to watch the board try to dabble in operations a little bit. They would say, we want to approve your funding.

The management team would say, nope, you can't do that. That's really an operational thing that we deal with in the budget cycle. A couple times I wanted to crawl under a rock because I had the chair of the board saying, I want to approve this initiative, and management saying, no, you cannot do that. And it was quite an interesting struggle. So I think really the management team wanted me to focus on governance, and they wanted me to keep the board focused on governance, right?

Not hands-on budget approval or Or really operational decisions. I'm curious if the board ever got into the weeds about how you came up with the risks that you had. So, you bring up this top 3 list. Is it just sort of carte blanche? Oh, yep, we agree those are the risks because that's what you said.

Or is it, tell me why, tell me how, what did you do to get here? It was interesting. Management scrutinized and challenged everything and would argue. And to your point, they would even say, we don't agree. This is a top risk.

And then the board, it was a much different interaction. They trusted me. And I wanted to sometimes say to management, why don't you see how the board is reacting to me? The board seemed to take this approach of, you're the professional, right? You've got the certification.

We hired you to do your job. We trust you. And then management in the background would just argue and try to tell me they didn't agree with some of the risks or didn't agree with how I'd assessed risk. They didn't think certain things were high risk. And I had to say, you hired me to do a job.

I literally said this in front of the board and management. You hired me to do this job. Here's what I think the risks are, and I wish you would trust me. All right. It was kind of an awkward situation.

So from your— I think you were there till 2014, right? So 5 or 6 years of experience talking to the board there. Can you give an example of— I'd love to hear the worst thing you brought up to the board that just didn't resonate, went over like a like a rock? Oh, and then the best thing you brought up, and it was really well received. So I didn't— I'm gonna try to ponder what didn't go over well.

Most of it did. I'll give you an example, um, a little related to security. We had financial auditors that said segregation of duties around code development in the environment was not appropriate. There's room for fraud, conflict of interest, etc., etc. So I worked with a the manager development we put together.

You know, you have development, then you have test production, you have different approval steps. So I'm trying to explain this to the board after a material weakness was found by an audit or auditor, and they glazed over. And finally one of the board members says, what's development, test, and production? And then the CIO steps in and says, let me use an analogy. If you play golf, if you go to the driving range, that's like development.

If you play with your buddies, that's test. If you go play a tournament, that's production. And immediately the board It's like, oh wait, now we get it. And I'm thinking, wow, analogies, that's a really neat way to think about it. And I realized I could not use jargon.

I could not get technical and geeky. I had to use analogies, speak from a business standpoint to the board because they're not technical, right? They're— that's not what they're there for. So, um, a success, kind of a success. We had some identity and access management issues that external auditors kept kept over and over finding as an issue.

I went to the board and sold them on it that we needed to buy a solution for this and have a program around it. The board signed off and that's where management said, well, we're not so certain this is really an issue operationally or priority. And then in the background they said the board approved it, but we're not doing it. And that was interesting. I didn't go run to the board and tattletale.

I just had to accept that, you know, can't really go around management's back unless it's really critical. Um, so definitely a learning experience. So taking a step, you know, away from the board of directors, which I find fascinating, and thanks for sharing your experience there, um, let's just talk about your overall tenure there. 9 years or so with Children's Health? Yeah, about 10 and a half.

Yeah, I'd love to hear— oh, 10 and a half. Wow. I'd love to hear a story or two, you know, a project that you're extremely proud of and it went really well. Let's start with there. Give me an example of project that went well?

So we needed to get compliant with HIPAA. We had a qualified third party that said we were about half, you know, 50% compliant. Uh, I realized that I needed to attend every audit meeting. Before, I'd said just go meet with everyone and report back, and I realized if I did not actually sit in these meetings, I wasn't aware what was going on. So I sat in a meeting and I would hear an administrator say, yeah, we don't have a policy for whatever you just asked about?

And I would actually say, yes, we do. And I had to own that they didn't know there was a policy, but at least we had one, right? Um, and I found if I didn't personally attend those meetings as a security leader, it would just go way off base. So we got about 25% more compliance just because I sat in the room and was able to say, whether or not this person's aware, we do have a policy on, you know, X or Y, you know, whatever they were asking about. Um, so we went Uh, at— when I was at Children's, we went from around 50% to 75% compliance, and then when I left, we were at 100%.

And a lot of that was because I just sat in the room and, and listened, and then I was able to hear exactly what they were trying to noodle on. Um, ended up writing a bunch of policies myself. Uh, I remember creating an audit program, and the IT division was kind of surprised. How did you create this? And I said, I sat in my office for 2 hours with my door closed And I worked.

And I, I think by the time people are done griping about what you have to do to get compliant, you can be halfway done doing the work, right? Just do it. Yeah. So that was a smashing success, and that helped lead to my rising up to director level and everything that comes with that— nice pay raise and all that. So I'm, I'm curious about that.

You said when you left you're 100% compliant. You know, some of the, the HIPAA regulations you have to follow certain, certain controls, but other ones are addressable. So you can do compensating controls to essentially cover yourself for those areas. Yes. But were you guys in compliance with everything sort of letter by the letter, or did you have to do some, some other things to get some mitigating controls, mitigating controls to get to where you need to be?

So I'm— I think I'm old school. There's required and addressable, and I consider it all required. And I was just able to do it. So password management, expire your passwords, right? Enforce complexity.

You need disaster recovery plan. We documented it. Do a test. We did a tabletop test, documented everything, reiterated, updated the DR plan. So really it was one of those, again, just do it, right?

Instead of arguing or talking about how hard it was going to be, we just rolled up sleeves and did the work.

So I, I really love to get examples of places where you had an idea for a project, you went after it, and maybe you got partway down the road and realized it wasn't going to work. Maybe you were investing in the wrong place or the company wasn't ready for it. Do you have any examples at Children's of, of projects like that that you could share with us and maybe why it didn't work and what you learned from that? I'll, I'll answer it a little differently. It was a spectacular failure, as I'll call it.

So getting geeky again, we had a portable media encryption solution. You plug in a flash drive or hard drive, it would automatically encrypt it. We realized in the surgical areas, we have these devices that plug in with a USB to a computer, like a scanner or something like that. And we were thoughtful about it. We said, let's just not install in the operating rooms, right?

Let's just leave those alone. We'll accept a little risk. There's more operational risk of causing a problem. So I learned a lesson about— I don't want to say being a control freak, but being on top of details from a project management perspective. So one of my guys went in the emergency department, scrubbed up, and got the names of every single machine that was in the operating room, got it to the IT administrator that was going to deliver the software.

About 4:30 PM the day before we were going to do this, he— my guy sent an email out saying, hey, I sent the wrong spreadsheet. Here's another spreadsheet that actually is more up to date with everything. Um, I just assumed— I didn't want to be a micromanager. I didn't want to be that guy. So I just thought, okay, well, he sent it in time.

The guy never checked his email, installed it in the surgical areas. They had to cancel some cases. They had to delay some surgeries. So that list was the list of exceptions? Don't push it to these systems?

Yes. And I think I should have been more clear about that. Yes, it was really here, all the systems that we don't want to push. Right. Um, the software too.

So they literally had to cancel some surgical cases. You know, talk about sweat, right? Red face, sweat dripping. Um, we did a postmortem on that. We apologized.

We said, here's what we're going to do to not let that happen again. And everyone said— postmortem in this situation? Probably a poor choice of words. No one died, fortunately. Um, talk about a spectacular failure and talk about me learning a lesson of being a control freak.

Um, operationally managing every detail of an upgrade of security software, pushing something out. Uh, I gotta tell you that when we went to ask for more funding for more stuff, it— people did remember that. Are you gonna screw this up again? That was the, you know, that was the question. Um, so, and we didn't.

So learn from your mistakes, right? That's all we can do. That's great. Thanks for that story. That was a rough one.

I know a couple years ago you, you chose to make a change. Um, would you mind just kind of talking through the process of leaving Children's where you'd been over a decade and what that looked like for you? Absolutely, absolutely. So Children's, Children's Hospital Colorado, I was a director and it was really kind of an operational, non-strategic function and I really wanted to go to that next level of executive leadership, be a CISO. So I saw this job at Denver Health open up and I think it's kind of like dating when you're a little ambivalent, everybody wants to date you, I think.

So I had this great job at Children's, I was happy and just to see what the option was, I went ahead and threw my name hat interviewed. And I think it came across that, you know, I was really interviewing them. And it was one of those, we got to have this guy. Everyone else seems to be desperate for this job. And we have this guy that seems like he could take it or leave it.

And I think that was a positive. It wasn't that I was rude about it, but it was really, tell me why I want to work here. Right. That was a question I asked. And just to be at that CISO level was something for my career progression I wanted to do.

And it was funny when I went to leave Children's, this is how it usually works. Oh, well, we don't want to lose you. Would you like to have a CISO position? And that's where I said, you know, I've already made my decision. Thank you.

And just went ahead and moved on. But to transition to a CISO, I realized instead of risk-averse security first, I had to help support the business. And to me, I found myself agreeing to things that 5 years before I would have said I would never agree to. Just to enable projects, to enable going to market, right, to enable the business. And I think that's a big shift that, that you have to make as a CISO, right?

I know you're both CISOs. Did you experience that as well, trying to change that mindset? Yeah, you know, thanks for asking that question. You know, going from thinking about what's the best way to make us secure as a company to what's the best way to make this company successful, right? That's, that's really the adjustment you're talking about.

And I think it's really a spectrum, right? Everyone acknowledges, yeah, yeah, we need to make the company successful, but what does that mean? Sometimes it means some pretty hard decisions, and maybe it means that security takes a back seat to de-risking other parts of the business. As we have a new product, as we have a new service that we're offering, the biggest risk isn't necessarily that maybe someone could breach the data in that system. The biggest risk is probably that the market may or may not want this product or service, and letting the business de-risk in the appropriate order, and getting in line, and making sure it's built in and not bolted on.

That process is a learning process. I don't think there's a right answer, but there's a spectrum for us to be aware of, and the most important thing, I think, is having a seat at that table where you can talk about the trade-off, making sure that the business is aware what those risks are, and And as long as everyone's on the same page and understands what the risks are, I think you're doing your job pretty well. Alex, you have any thoughts? Yeah, I mean, and I think part of that too is making sure that you can realize when it is that you have to have all of your security controls built in before going forward with something, as opposed to taking baby steps, ensuring that it really matches up to the risks that you're talking about. There are plenty of times when I've been in projects where people have said, oh well, we have to do all this stuff before we can go live because those are all the required security controls or whatever it might be.

If you take a step back and say, okay, well, if we don't do this or this or this, it's going to allow us to move much faster, and what is the risk that we're actually taking by not doing that? If that's acceptable, then we move forward. I think it also helps to realize that But, you know, in the end, this is all business. It's not security. It's, um, it's making sure that the, the risks are, um, identified and, you know, either reduced or accepted by the appropriate people.

And most of the time, that acceptance is not the security people. All right, absolutely. I, I had an interesting situation with it where I learned you have to ask questions. So it was some new software, was not secure like I wanted it And I was really concerned about opening it up outside of our perimeter. And I was so focused on that.

And finally I asked, does anyone externally need to use this? And the response was no, it's all going to be within the hospital. So I just reduced, right? That's a huge risk reduction. And, um, you know, to your point out, you can't make assumptions about what, right, what the project is going to do sometimes, right?

I assumed it was going to need to be remotely accessible. I asked and they said it didn't. And I thought, well, that just you know, I got rid of a lot of my worry, right? Reduced a lot of risk. So, so you started it at, uh, Denver Health— was it April, May, something like that, 2014?

Yeah, May of 2014. And you'd been at Children's Hospital for over a decade. You go into a new environment. Just talk to us about that, learning that new environment. How do you— you know, obviously you want to, you want to impress your new boss.

You want, you want to come in and make a difference right off the bat. What did that that ramping up process look like for you? So I told myself that I was not going to do anything for 90 days, maybe 180 days, and I completely violated that immediately. I found low-hanging fruit. I found some contractual issues that we had, some templates.

And my first day I was telling the attorneys we're going to add a few things into that. And so I just really hit the ground running, maybe a little too fast, but also treading a little lightly as far as learning who people are. I realized just like everywhere, there are a few people you just do not want to cross. You don't even want to come close to stepping on their toes. So I had to figure that out.

And I was a little cautious about that, ask questions. And I observed a few people that pulled, you know, had a lot of power and you just did not want to make them upset. So if I had a big thing I need to bring to the management team, I would go count my votes, as they call it. I would go meet with individuals, say, what do you think about this? Or, you know, do you support it?

Do you have concerns? And I found there a few times people were aligned and they were all ready to approve it before I even got there. Other times I had a couple of stakeholders that pulled a lot of power that were just adamant that we were not going to do something. And I realized I can't even take it to management yet. Right.

So on one hand, for low-hanging fruit things that I felt were within my authority, I just went to town and I proved myself, took control. For other things, I was a little more cautious and wanted to learn the politics. And I think that was more important than anything politically. Who do I need to get support from in certain areas? One other thing I realized is that the organization had education fatigue.

Right. So I had all these security initiatives I wanted to start educating people on. And I realized there were so many other things around clinical care that they were already overloaded with that I just had to hold off. Yeah, um, and I thought that was key. So really, to your point, I was trying to adjust to the culture rather than make it adjust to me, uh, and I— and that was a big deal for me.

I went— I was used to the culture, 10 and a half years at a certain place, and I stepped into a completely different culture, right? So, so who's your boss at Denver Health? So I report to general counsel in legal, and he reports to the CEO. And, you know, does that give you a different perspective than, you know, being on the IT side? Or can you talk to me about what it means to report to general counsel?

Yes, it, it, it has pros and cons. As a pro, it made me really start to think more about risk rather than technical controls. And you brought that up. You have a good point, Alex, around if you look at HIPAA, there's all these controls and safeguards you're expected to get in place. And I realize that's all fine and dandy, but it's about risk.

What's the real risk? Right. And how do I prioritize getting those controls in place? And general counsels understand risk very well. So if you say we need to do something because HIPAA says, they don't, that doesn't ring with them, right?

If you break down, here are the risks, here's why we need to do something, here's what might happen if we don't, it's a much different conversation. And I think they're really good at risks. And general counsel would challenge me. I would bring a risk up and they would say, really? Well, let's talk about some other risks, right?

If you do this, and very educational for me. The general counsel knows that there's a lot of regulations out there and that we don't comply with all of them. Correct. So just the fact that there's a regulation doesn't mean necessarily going to go do it. Correct.

And then there's some candid conversations, always wanting to do the right thing, of course, but it's really what are the odds that this is really going to be a problem? What are the odds that anyone's ever going to know about doing, you know, if we do or don't do something as far as prioritizing and when we're going to do it? So, um, not technologists though. So talk about trying to, to, to communicate technical issues to someone that's not technical is the art, I think, of being a CISO. And I, I've had to have some conversations where I've quote unquote dumbed it down the best I can and it's still not simple enough.

And that, that's quite a learning curve as well. How do I speak the language of someone that knows nothing about technology, someone that doesn't care about technology? Right.

So, you know, you've been there coming up on 2 years now, and I'd love to hear, you know, what you're most proud of in your 2 years there. What have you gone after successfully? And maybe give the same story you did over at Children's. So it, it's literally the same situation at Children's. I came into a situation where the organization was doing a lot of great things, but they had not formally documented what they were doing.

So even though we were compliant with HIPAA, we weren't, right? Because we, we couldn't prove that we were. So rolled up the sleeves, I did what's called a business impact analysis. From— if you're familiar with that term, it's really prioritizing how critical systems are or not to the organization, defining recovery time objectives and recovery point objectives. And I think that's what I'm most proud of, is that component compliance.

And when I went to the IT division, they were trying to do that. They were trying to define how important the technology was for their users in the business and clinical sides. Does that sound a little odd to you that the IT division is going to decide how important other— the technology is for other people? And they had this crazy idea to meet with business units, and they thought I was insane. Like, what do they know about technology?

I had to tell them, well, they use the technology, right, on a daily basis. I think we should be asking them how important this is or not. And what the business came back with was a lot of the most critical systems in the organization weren't that critical, right? And a lot of what the IT division thought was critical, and a lot of systems that the IT division didn't really think were that big of a deal, were ultra critical. So an example would be the closed-circuit television system in the organization didn't contribute to revenue, doesn't necessarily contribute to patient care, but everyone talks about how important all that footage is.

If you have someone fall in your hospital, right, someone says, I fell and hurt myself, it's interesting, sometimes you review tape and you see that that did not happen, right? So IT division was kind of neglecting the system, and it wasn't their fault. They just You know, it's not health— it's not a healthcare system, right? The business units came back and said one of the most critical systems in the hospital, and that was a big wake-up call. So, in addition to getting compliant, just doing that exercise to satisfy HIPAA requirements and also to open the IT division's eyes that the end users are really the ones that know how critical these systems are or not, to me was a big deal.

And we got it. That could be a 6-month to year project, and we got it done in 3 months. So yeah, and I— the hardest part of that project was getting people to show up. So I sent these invites out, and I would literally not hear back, and I would walk to people's offices, um, sometimes with coffee, all right, sometimes with donuts, just say, hey, I invited you to this meeting, I didn't hear back. Um, and I spent more effort getting people to show up than anything, which was— who knew, right?

Yeah. So, you know, you and I obviously have got to know each other pretty well over the last maybe 3 years or so, something like that. And I know that you have been doing consulting for the last few years, and I find that interesting to have a full-time job running the security program for, you know, one of the biggest health organizations in Colorado, but also, you know, having a side consulting business. Can you talk about, you know, how did that start up and where does that fit into your life? Yeah, so my wife would agree with you that I'm crazy to try to do both.

It gets tough. Um, I made a decision a few years ago that I wanted to just give it a try, and I actually had a former general counsel that I reported to at Children's called me, and he was working for a legal firm. They were having a contract dispute with, with 2 organizations around technology, and he picked my brain. I gave him some pointers, and the pointers I gave him pointed him in the right direction to actually rescue this, this contract dispute. And he said, that was really useful.

Did you ever think about consulting? And that, right, that was the moment, thinking back on it, where I thought maybe I should. Uh, and I didn't know how to start that, and it was pretty silly when I first tried to start. So I would have vendors say, hey, do you want to grab lunch? And I would say, well, yeah, my rate's $150 an hour.

And they would not get back to me. Imagine that, right? I didn't know the difference between networking and trying to build my consulting practice. Um, so I had a buddy who had his own landscape architecture firm, right? Nothing to do with security, but he consulted.

Um, he said that he had learned get a website, get a business card, get a logo, and he hooked me up with the guy that did that for him. Um, and the idea is if you meet someone and you introduce yourself, you don't want to just have a Hotmail address, right? Not have a business card. So I had that all teed up, just started networking, started getting referrals, and it just took off. Um, and I found myself many times giving free advice to people.

People would just call and pick my brain, and they would come back and say, that was really good advice, that was helpful. And I thought, why don't I start charging for this, right? And, and see, see what I can do. Uh, it, it's definitely lucrative, but to try to do both at the same time, it's nights, weekends, and personal time off. So instead of going on vacation, I took a week off and went and did a big project.

Um, the wife was not happy. But I've heard several mentors that have done their own thing, and they— what they applauded was instead of going cold turkey, instead of saying, I'm going to quit my job and right now start a consulting firm, I went ahead and phased that in over several years. Yeah. Um, and it was— there are definitely some stressful times. Um, you know, at midnight when a project is due the next day for a client and I'm not done yet, pretty scary, right?

Um, but just was able to power through. And one thing I like about that, um, small-medium business don't really have people that want to consult with them in healthcare. Um, usually it's the, you know, the big players like Kaiser, Children's Hospital Colorado, they will engage with an audit firm, but these, the small guys don't have a lot of money to spend. Um, and that's been a niche to be able to help them out and share knowledge. I've also worked with some startups, um, and they like knowing that someone understands it has to be stage appropriate.

So if I were to say you need to spend $500,000 on security, their response might be, we don't even have $50,000, not going to happen, right? So how do you phase that in over, over time and help them get their business? So have you been focusing on, on healthcare then, I assume? Yes. HIPAA compliance and assessments and so forth.

HIPAA compliance, risk analysis, HIPAA training. Um, I've gotten some more— some clients out of trouble with the government where they didn't do anything wrong, but you have to prove you didn't do anything wrong. Around a patient complaint or a disgruntled employee. So that's been pretty satisfying. So the reason I focus on healthcare— for better or for worse, I became a healthcare guy.

I have an MBA in health administration, all that experience at Children's Hospital Colorado and now Denver Health. But I, I realized I can talk about non-security things, right? What are their business challenges? What are their struggles? Um, what do they do when they have doctors that are angry at their security stuff?

Like, how do they navigate that? So I find I would say about half of the advice I give ends up not— as part of that relationship ends up not having anything to do with security. Yeah. Well, if anyone's listening and wants to reach out to you about your side business, what's the website or what's your email? So it's Rocky Mountain Hippo Guru.

It's www.rmhguru.com. So thanks for the quick plug there. Absolutely. So another thing that I know you've been doing, and I certainly appreciate it, is Um, you've been helping lead the industry verticals effort for ISSA Denver, which is of course the world's largest ISSA chapter with well over 500 members at this point. Um, so talk to me a little bit about what you've been doing there and, and where you see that going.

So as we had talked a while back about having events, I had this crazy idea, right? If you get people in the same industry together, what would that look like as compared to just everyone from every industry coming together for an ISSA meeting. So a bit of an experiment. Um, we've done 2 healthcare meetings so far, and I've, I've, I know more than 2 people that found jobs through just going to those meetings, which is pretty neat. Um, and the idea is really let's talk about security in the context of healthcare and what, and what do we struggle with, right?

Um, and we try to make it, make it a blend of something for everyone. So we do some high-level non-techie talks And then we've gone way into the weeds with, you know, full-on, here's some web application penetration testing. Um, and I found that the geeks in the audience will say, I really appreciated hearing the non-geeky stuff, right? It kind of opened their eyes around dealing with politics, around leadership. And then vice versa, some of the non-technical people were just fascinated to see someone attack a website, right?

And that was pretty neat. We also have a financial vertical. We're having our first meeting this month. Um, in Breckenridge, the Breckenridge Brewery down the Tech Center. Can't wait to see what that's going to look like.

Um, they switched gears. You can edit that out, right? Um, so we'll decide that. So we're having, um, our first financial vertical meeting at Maggiano's down the Tech Center this month. Can't wait to see what that's like.

I'm gonna— even though I'm a healthcare guy, I'm gonna join that, just see what it looks like. And I know we're looking at a governance a government vertical as well. And I think what we're talking like 2 to 3 meetings a year per vertical. Correct. So versus the monthly meeting we have for the whole chapter for ISSA, looking at less frequently but longer meetings, kind of half-day format with more time for networking, more time for education.

Yes. And really the idea is if you work in finance, vertical government, we're going to talk about the things that you experience every day. Security related and beyond security even. And just networking and getting to know people in your industry is pretty cool as compared to just networking with people that might work in another industry and not really get what you go through every day. We like to compare war stories.

All right, security can be tough trying to get people to do what they don't want to do and just comparing ways, techniques. How do you win people over? How do you succeed? Has been pretty neat to see that, see people sharing those ideas. So take— let's go broaden out a little bit from, um, just the ISSA vertical stuff.

Just let's talk about Colorado or Denver security community in general. You know, you've been, you've been doing security here for quite a while. Um, I, I don't think you've really kind of stepped out of your niche until a few years ago, but in the last few years you've been pretty active in the community. Can you talk about what your experience has been like, what your impressions of the community here has been? Yeah, so From the inside looking in, we have a great security crew here.

We have people that know what they're doing. Great CISO community in particular. Pretty kindred spirits. A lot of people live here because we like the outdoors, right? We appreciate Colorado.

Pretty laid back community, I think, especially compared to the coasts. We're pretty laid back here in Colorado. Friendly people. I've been pretty excited. I've actually made some great friends through ISSA and through being part of the community.

And then when I hear others talk, they're— people are pleasantly surprised that they think Colorado, and particularly in Denver, is one of the best in the country. I've heard people talk about Washington, D.C., Boston, and Denver as the top 3. And then I've even heard some people argue better than the Bay Area, right, as far as the dedication and the community being active. So it's been really cool. And again, the friendships I've made, it's good to compare security notes, but also good to share a beer, right?

And maybe go skiing. So we've got a really good community here, and I've been pretty excited about it. So, you know, obviously that this is the Colorado Equals Security podcast, so it's a focus for us as we look to get better. A couple questions for you for the community at large. For those who either are currently CISOs or who'd like to be security leaders in the future, what's a couple pieces of advice you could give them to, to do their job better or their future job better?

So certifications, I think, hold a lot of weight, and I think if I think you can learn a lot from certifications. And when I see hiring taking place, I see security managers wanting to see certifications in place on resumes. And I've seen a pool of candidates be kind of whittled down based on the certifications they have or not. The second— certifications, would you recommend people go after? So the CISSP is interesting.

I think it's, it's kind of polarizing. Some people will say, ah, CISSP is not really hands-on, it's generalist. Um, but to be a generalist and understand enterprise architecture and how it works together, I think is, is pretty, you know, pretty neat, especially to assess risk. I think the CRISC, um, the ISACA certification is good. Um, you know, I think your, your feedback on CISSP is pretty good.

You know, it's, it's not going to help you do your day-to-day job very well. I don't think that CISSP helps you program a firewall or be better at risk assessments. But what it does is really helps you have those conversations with folks in different disciplines and understand what it means when they talk about, you know, if you're, if you're a firewall guy, when someone talks to you about physical security, if you haven't taken that kind of curriculum to learn the stuff in CISSP, you might not understand, you know, the crossover rate for, you know, false positives and false negatives for biometrics. And these are things you learn at a high level from that certification. I think it's pretty valuable.

I affirm what you're saying there. I like the way you said that it's not going to help you hands-on acquire skills to configure a firewall, right, or do penetration testing. But for me and Alex, you talked about compensating controls. There are times where I've seen a glaring weakness in a certain area, and I realized because of the domains and the CISSP, we have all these other compensating controls in place that I probably would have never thought about, that high-risk item that we have in place is not really high risk, right? We have all these other controls in place.

Um, quick example, do you want to encrypt all the disks in your data center, right? The servers. What are the odds someone's going to get in there and actually physically get those out of there, right? Um, so all of a sudden, this, this high, high risk of not encrypting servers in theory in a physically secure data center where no one's ever literally going to be able to get them out, knock on wood, right? Um, I think that's something without a CISSP, you can't see the forest through the trees.

So to speak. Um, we talk about the CRISC, which I think is good. Um, Certified Information Security Auditor, if you want to do audit work, can be good. But I think the idea is that it shows that you, you're dedicated, you, you focus on a core competency, you got through it. Um, and that's how I started.

I remember my boss saying, you don't know a ton about security, go get a CISSP. I remember saying, well, maybe in a year. And he said, well, there's one in 2 months, go get them, right? Um, So I think if someone wants to do it, go schedule an exam and make yourself do it. Don't think, well, I'm going to study for a while and then work my way into scheduling an exam.

Schedule the exam and it'll make you do it. Being technical is key. Pick up a book or Google, get on Google. I've seen some non-technical security leaders, and frankly, sometimes it can get embarrassing, right? I don't expect security leaders to configure a firewall, to use that example again.

But they need to know how firewall works, what an access control list is. So definitely be technical. And then networking, right? Meet people, build relationships. And what I finally found, if anyone wants to meet up for coffee— in the past, I was, you know, years ago, I'd be really busy, didn't really know what anybody was going to get out of it.

But now if anyone wants to meet up, I'll meet with almost anybody. And the relationships that I've built both around my career, around consulting, just by meeting people and being nice, wanting to get to know people has been huge. So certifications, get technical and meet people.

Awesome. Alex, you have any last questions for Drew? I don't think so. This has been great. Thanks, guys.

Drew, thanks for any last comments for the group. Yeah, if you're going to be a CISO, as you guys said, it's usually not a security company you're working for, and even if it is, they have other priorities, right? Business priorities. So remember, security is there to enable the business. It might sound a little cheesy, but we have to remember that.

When I first started my career, I thought security— I thought we should be secure for security's sake, and it just doesn't work that way. So, well, thanks, Drew. This has been Colorado Equals Security, sitting with with Drew Labbo, the CISO from Denver Health, one of the superstars in Denver security. We're glad to have you, and we'll look forward to getting back with you guys next week to talk to yet another one of the superstars here in Denver. Signing off.

Thanks, Drew. Thanks, guys.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes