Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.
Welcome to episode 6 of the Colorado Equals Security Podcast. This is Robb Reck and this is Alex Wood, and we're here doing the newscast for the week of March So Robb, what's going on? Well, daylight savings, right? This is a— we just had daylight savings, so it is an hour earlier right now than it should be. I'm awfully tired.
How about you? I'm awfully tired as well. Yeah, I expect to be for several weeks until my body adjusts. So one of those social media memes going around saying that heart attacks go up by 24% and accidents go up by 17%, all these bad things as a result. I know that there was a bill at the Colorado State House to try and get rid of daylight savings time, but it failed.
So we will continue to have it for at least another year. Probably the supporters weren't able to wake up and get there in time to vote. I was gonna say, you know, the big-time lobby.
They were against the bill. The lobbyists for the clocks. The clock changers lobby. That's right. Let's go ahead and dive into the stories here.
Top of our list today is RadioShack is going bankrupt yet again. Yeah, you know, this isn't a particularly big security issue, but I know when I, when I worked downtown, if you, just from being a geek, if you ever needed a cable or you needed, you know, anything that was, you know, sort of out of the ordinary, there's a RadioShack on 16th Street Mall that, you know, you could always depend on having things that you needed. Yeah, I think Radio Shack is a big part of a lot of our childhoods and lives growing up, and especially the nerdier you were, the more it was. We don't know which stores necessarily are going to be closed yet, but the one on the mall that you just mentioned does have a big Everything Must Go sign on it, giving us the— at least the illusion that it might be closing. Next on the list, there was an article that was published about DDoS preparedness.
There's some people that may or may not be in this room that were part of making that article. Yeah, so Sam Masiello, the CISO over at TeleTech, and I helped prepare this article, really kind of giving enterprises the basics on what is it you need to do to get ready for potential DDoS attacks. So we're not going to go through the details today, but something you might be interested in if you're not ready, if you need to start thinking about how to get ready for that, take a look at the article. Yep. Big news this week in the security world.
Veracode was acquired by CA Computer Associates. I guess it's now CA, right? It's no longer— it's not Computer Associates anymore. It is now just CA. So, so neither of those are Colorado companies, but we do have a pretty good-sized presence for CA up in Boulder when they bought Rally Software a couple years ago.
And Veracode has been a huge supporter of the Colorado community, security community, over the last 5 or 6 years. Yeah, I mean, it's an interesting move. CA seems to be definitely getting into the, the DevOps, you know, more of that, that type of mentality. And I think getting Veracode to integrate with that whole process, I think, is a really interesting play. Yeah, so Veracode, for those who may not know them, they do static analysis, dynamic analysis, runtime analysis, third-party software analysis, really application security throughout the different stages.
Anyway, hopefully good news for everyone at Veracode. I'm sure that those guys who founded it, who, you know, we know Chris Weisopel, who keynoted RMISC last year, and Andre Gaeta, who's the account executive here in Colorado. Hopefully, you know, good news for all them, and congratulations to the whole Veracode team for sure. Next on the list, SendGrid acquires a San Francisco company called Busy. So again, not a direct security acquisition, but we do know the security team for SendGrid.
They're obviously based here in Colorado. Dave Campbell is the CISO over there. Good guy, he's been in the community a long time here. Yeah, and just good news for SendGrid, right? It's nice to see the local technology companies in Colorado growing.
They're real well known everywhere, and hopefully keep growing and keep doing their work there. For sure. CRN Security 100. This is an annual list that goes through and says what are the cool vendors in each of, what, 5 different categories, right? I think they've got network security, they got SIEM and threat detection, endpoint security, identity access management, and, uh, web— there's the email, web email, and something else, right?
Yes, exactly. 5 different categories. So we have, uh, 4 different Colorado companies that made the list. Yeah, so, uh, ProtectWise was on the list for network security. LogRhythm under the coolest SIEM and threat detection category, Webroot under endpoint security, and Ping Identity under the identity and access management.
So nice to see the Colorado companies well represented, and hopefully next year we get even more, right? And I think a little bit like the Cybersecurity 500 from last week, I'm not sure exactly what the CRN 100 means, but definitely being recognized is a good thing, right? Yeah, we don't know how how subjective and how objective it is that, you know, it's cool vendors, not necessarily growing or big vendors. This is, in a lot of ways, it's content generated for the sake of generating clicks, right? And nothing wrong with that if that's your business, but it is nice to see if you're gonna have a list that the Colorado companies make it.
For sure. Next on the list, Webroot partners with Kaseya. Before seeing this article, I wasn't familiar with Kaseya. But they seem to do IT management. They have a platform that automates those kind of tasks.
So Webroot is integrating with that platform. And the play really is to help get Webroot integrated for managed service providers here, right? That's the goal, is that as a managed security service provider looks to extend, you know, around either endpoint security or threat threat intel feeds that they'll be able to use Webroot. Yeah, for sure. Good for them.
So next, Dale Drew was named to the top 100 CISOs for 2017. Yet another list, right? And, and, you know, we don't know exactly how they come up with all the folks on the list, but Dale Drew, who we really respect, the CISO at Level 3, is being recognized as being one of the forward-looking CISOs in the country. Yeah, and he was the only Colorado CISO on that list. So Hopefully there should be some more there in the future.
I'm not sure why I wasn't on the list. Yeah, present company here maybe, maybe got overlooked. But in 2017, you know, 2018 really, hopefully we can get to talk to those folks and make sure they know the great things that are happening at a lot of the companies in town. And I think we have, you know, 5 or 10 different CISOs in Colorado who are worth taking a look at there. Yeah, so if you made the list, come talk to us.
We feel slighted and we need to make sure to set you straight. Yesterday was the CCDC, or this weekend, last weekend was the CCDC, the Rocky Mountain Cyber Collegiate Defense Competition. And we've talked about this for a while. We have a link in the show notes about how it went and all that. Now, I just wanna once again, you know, as we close out this year's event, say thanks a lot to Regis for supporting.
Thanks to all the volunteers who got out there to make it work. And let's really, rally around the education of collegiate students and young folks who are looking to get into security. Yeah, we continue to hear more and more about how there's a talent shortage, how we need more workers, getting folks in college interested in cybersecurity. And obviously these are some of the best and the brightest that are out there competing, but we need more and more of that to help mature the industry. The Rocky Mountain Information Security Conference registration is up.
So this went up just a few days ago. And we have early bird registration open until April 15th, so you're going to save some money if you get registered before, before tax day. And I think we've already kind of talked about all the keynotes there, so now it's just time to go get signed up. I think I'd also note that if you're not a member of ISSA or ISACA, it may be worth your while to join one of those organizations because there are, there are member discounts for RMISC as well. You can sort of double dip and get your Um, your ISSA or ISACA membership and get to RMISC for just a little bit more money.
Yeah, actually it's less money for ISSA this year. The, the pricing was put together such that I think you save $150 by doing— by being a member of ISSA or ISACA. And at least ISSA costs $120 to join, so you save $30 plus you get free meetings the rest of the year. There you go. Uh, there is a new section added to our website, to colorado-security.com You want to talk about that, Alex?
Sure. So we added a section, you know, took us a lot of sweat and hard work, but we did it, about the security companies in Colorado. You know, that's one of the focuses that we have, obviously. We talk about them a lot, but I think we have 18 companies there on the page now, Robb. Yeah, there's 18 companies on the site where we have a short description of what the company does.
We have links to their main page, their press releases, and their jobs list. Links. And of course, we know that there are more than 18 security companies in Colorado, or actually we've learned as we've gone through this list. And if you're a company that's not on that list, reach out, let us know. We'd love to get you included.
So if anyone ever tells you that doing web development is not a blue-collar job, I'd ask you to come over here and try and figure out how to edit a template in this CMS that we're using. It's definitely been a challenge for us. Yeah, go ahead. And then finally, you may have noticed if you've been to the website that we have a subscribe link at the bottom. You know, you can put in your email address and sign up for our mailing list.
We would encourage all of you to do that if you want to keep in contact with us. And more specifically, we're going to be putting out a survey about the podcast, about what we're doing, just to get feedback from the community out there. Make sure we're going in the right direction, see what people want that we're not already doing, see what we're doing well, what we're doing poorly. So if you want to contribute, make sure you get your email on that list. Yeah, get signed up in the next week and we'll put out the survey shortly thereafter.
We're also each week, along with releasing the podcast, we're releasing a mailing to the, the folks who sign up to the mailing list so you can be in the know on what comes out and get the show notes delivered to your, to your inbox. All right, let's go ahead and take a look at what's going on this week in the Colorado security community. On the 14th, which is Tuesday, the Cloud Security Alliance has their March meetings, which is a CASB overview, and they also have their board of directors elections. Yeah, so if you want to be involved, get to that meeting. Maybe you can be on the board of directors.
On the 15th, there's a free application security for developers course. This is sort of the pre-training for the SnowFROC conference, and that training is actually being led by Jim Manico. He's one of the premier application security teachers in the world. Not only is it a great teacher, but it's free. All you have to do is go sign up for it.
Yeah, Jim is a fantastic teacher. I've had the chance to join one of his similar courses in the past. He's going to give hands-on technical training. It's really targeted for developers. You want to try and get this over to your development team so they'll start to understand how application security works in their area.
I know I've passed it around work and I expect to see quite a few folks from Ping show up there.
Thursday is basically the biggest day in security all year round here in Colorado. We have 5 different events going on and a few of them are quite big events as well. First, we have the ISACA monthly meeting. I'm not sure of the topic this month, but regular monthly meeting for them. Then we have the full-day SnowFROC event.
We've been talking about SnowFROC quite a bit. And, you know, yesterday, the day before we have the training, Thursday is going to be a full-day conference at the Cable Center at DU. Going to be kicked off by yours truly giving the keynote, and then a couple of— there's 3 different tracks throughout the day, including a hands-on track where you spend all your time actually doing hacking and really getting into the technology. Also on the 16th, the CTA Sea Level at Mile High. This is their annual executive-level event.
It's in the evening, I believe, on the 16th. So if you're an executive and want to be involved in the technology community in Colorado, this is a perfect event for you. And then SecureSet that evening has a talk with a malware reverse engineer from Sylance, Devin Bird, kind of talking through how to do malware reverse engineering. Awesome. So that— there, you know, you can take a look at our website or take a look at the show notes to see all of the events coming up in the next week and in the future.
There's one other one coming up up that, that was posted this last week that I want to call out specifically though. On April 19th, ISSA is kicking off a new Women in Security Special Interest Group, and they're going to have their first, uh, kind of introduction meeting that evening. Yeah, so I think this is a really great, uh, beginning. So if you have interest in women in security, I think you should definitely attend that event. And if you want to have a, have a say in what does the, the program look like, this is a good time to show up.
For sure. So, on to jobs for the week. First on the list, we've talked previously with Drew Labbo, who was formerly the CISO of Denver Health. He has since left. I believe we mentioned that in a previous show.
But now that job is posted, so if you want— if you have healthcare experience and want to be the CISO of a healthcare organization, that job is out there. Molson Coors is hiring their VP of Global Internal Audit. Um, so if you want to drink beer and check IT, check IT controls, this is the job for you. Uh, Ping Identity Director of Infrastructure Operations. Robb, you have more information?
Yeah, this, this is a huge strategic position for Ping. Uh, this is the person who really runs the cloud infrastructure, AWS-centric, someone who understands, you know, the, the microservice architecture and deployment, really that, that modern infrastructure stack headquartered in the cloud is someone who'd be good for this. And there's a lot of integration with security. I work with this person very closely, and if you're interested in learning more about the job or applying, reach out to me. So if, if you want to work with Robb but maybe not for Robb, then this would be a good job.
Wells Fargo is hiring an IT Senior Lead Auditor. FireEye Industrial Control System Security Consultant. Webroot is hiring an advanced malware analyst doing research. Yeah, you know, and, um, looking at that one, it does say advanced malware analyst, but looking at the post itself, it does have sort of a lower level number of experience, uh, years of experience. So even if you're not a senior, well-seasoned, uh, research analyst and you want to be in research, that might be something to look into.
That's great. Uh, we have Edge Alliance or Allegiance Consulting hiring an IoT security analyst. Yeah, and I'm not familiar with the company, but it looks to me like a staffing company. So we don't know who the end company is, but IoT security analyst sounds like a cool job. FirstBank associate analyst in information security.
Again, FirstBank, a local company here in Colorado. So if you want to do security in financial services, that'd be a good place to look. And then Alchemy Security is hiring a cybersecurity junior analyst intern job. This isn't Fantastic way to get your foot in the door. Jobo, who's the, I don't know, president, owner, founder, CEO, whatever he is over at Alchemy, uh, great guy who, who will help you, you know, learn, learn the ropes, get your, your feet under you in terms of security to, to really launch a new career.
Yeah, for sure. And then last on the list, um, there are a number of security companies in Colorado that have jobs that are open. These aren't necessarily security jobs, but we thought it was interesting in the fact that if you want to work for one of these Colorado security companies, there are definitely opportunities out there. Ping has 17 jobs open. Red Canary has 7 jobs open.
ProtectWise, 6. Webroot, 17. And LogRhythm, 14. So lots of stuff out there. Yeah, we have links to all of their career pages in the show notes if you want to take a look and go see what jobs are available there.
Awesome. All right, well, that takes us to the end of the newscast. We're gonna go ahead and go over to an interview with Rock Lambros. Rock is the ISSA chair for RMISC this year. That means jointly with, with Rick Lucy from ISACA.
He really puts on the conference. He's in charge of all of the details of it. So you sat down with Rock and really kind of talked about what's going on with the conference and give, give a little bit more detail into the event, right? Yeah, and we talked a little bit about some things that you've already heard about, but also, you know, how they do the planning and all that, that sort of thing. So I think that should be interesting.
And then we actually are gonna do 2 feature interviews this week. After Rock's kind of short interview, we also have a short interview with Colleen Murphy Colleen is the president of ISSA Colorado Springs, and she talks about what does the Colorado Springs chapter look like, what are they doing. And actually, I was surprised, there's quite a few things that the Denver folks could really get value out from, from what they're doing down there. So take a listen and see if that's something you might be interested in. Great.
All right, with that, we'll go ahead and sign off. Thanks, Robb. Thanks, Alex. This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security for Called out of security professionals by called out of security professionals.
You know, one of the main reasons that I wanted to come talk to you was not because what you do during your day job, but what you do, you know, other times. So I wonder if you could tell me a little bit about, you know, one of the other roles that you have with the Rocky Mountain Information Security Conference. Yeah, absolutely. So I am the ISSA chair of the Rocky Mountain Information Security Conference. If you don't know, Rocky Mountain Information Security Conference is the largest security conference in the region.
It is put on jointly by the Denver ISSA and ISACA chapters. Rick Lucey is my counterpart on the ISACA side. This is the 2nd year I've been chairing it. I inherited an absolute mess by the— from the last guy who was chairing it, which happens to be Alex Wood. Just kidding, Alex.
And, uh, no, but it's been great. It's been a lot of fun. The last 2 years have seen a tremendous amount of growth in the conference. Uh, I think you guys have mentioned it on a previous podcast. It's, uh, moved to a second day of full briefings.
Um, we were just shy of 1,000 attendees last year. My anticipation is that we'll— we will definitely cross that threshold this year. I mean, and it's really you know, to drive some valuable education and networking opportunities. Kind of started out throughout the Denver community but has really expanded into a really good large regional conference with some really, really good content. I've also been on the— not only have I chaired it, but Robb has been responsible for programming the last few years.
I've been on his committee helping him. We've turned down some really, really good talks just because of space. Um, so it's— I'm excited to see that the, the word's kind of getting out there. A lot more people are submitting talks for it, a lot more people are registering, a lot more people are coming from out of state now. Um, New Mexico, Texas, uh, uh, you know, just the Rocky Mountain region, Utah, Wyoming, that sort of stuff.
So awesome. So for the maybe, you know, one or two people that are out there that that don't know about the Rocky Mountain Information Security Conference. Both, for both of them? For both of them. Would you just talk a little bit about the format?
You know, you mentioned it's going to an extra day today, or this year, so what is it that we're going to see? Yeah, so it's May 9th through 11th at the Colorado Convention Center here in downtown Denver. The first day is what we call kind of the pre-conference sessions. They are, you know, half-day or full-day trainings. I think we've got a session this year on— let me think if I can remember all this off the top of my head— pretty much architecting your cybersecurity workforce.
That's a half-day session that's really geared towards kind of like manager, anybody who's managing security people, right?
There is an executive leadership forum that's put on by Ernst Young. They've been sponsors of it for God, I don't know how many years. So, and that is really geared towards CISOs in the area or, you know, CISO responsibilities.
You know, in the last couple years, we've also expanded that to try and include chief audit executives as well, so that way we can talk about, you know, how do we as a security community work better with the audit community and vice versa, because really we're there to You know, we're all after the same goals, right? You know, a lot of us in the security community tend to see audit as adversarial. Really, I consider internal audit as, you know, friends who are trying to keep me out of trouble. You know, you external auditors out there, that's a different conversation. But anyways, and there's Ben Tomhave is doing a full-day session on DevOps and DevSecOps, which is really cool.
Obviously, those are 2 buzz terms, but really kind of changes the mindset of what we think of traditional kind of security architecture and implementation and how we interact with the business and get baked into business processes into the development lifecycle. And how we can be, again, another buzz term, but lean and agile in our thinking in our implementation of security controls. And then Evan Wheeler is coming back to do another session on practical risk management. It was wildly successful last year, which is why we've asked him to come back. And I believe ISACA is working on an audit course, but that is to be announced.
Awesome. So that's pre-conference sessions. Yes. And then the 2 Uh, the 2 days of general conference sessions, you know, typical breakout sessions. We've got several tracks ranging from incident response to architecture, security management, audit, risk, and compliance, career and emerging trends, application security.
And then also we have some really, really interesting keynotes to share. So first of all, it's going to be kicked off all by Governor John Hickenlooper. That's awesome. Um, yeah, and now credit to your partner Robb Reck in getting that lined up. Uh, he will be kicking it off Tuesday night, uh, May 9th at 4 PM at the convention center.
Um, you know, he may speak for 5 minutes, he may speak for 2 hours, we don't know, but it's always a, a good talk. He is really IT savvy, um, and he also spoke at RSA this year. Yeah, and I know Governor Hickenlooper has had on his agenda cybersecurity. They've been pushing that a lot in the state, so it'll be interesting to hear what he has to say. Yeah, you know, the National Cybersecurity Center down in the Springs and how that's all going to tie together.
It'll be interesting to see how that gets staffed and what kind of public-private partnerships come out of that. And then Jeremiah Grossman, a big name in the industry. He's with formerly, I believe, White Hat, but now SentinelOne. He'll be the keynote right after Governor Hickenlooper on Tuesday. Wednesday morning, we'll be kicking off the sessions with Kal Fussman.
Kal Fussman is not a traditional— he's not in the security industry, right? But he has done— he has interviewed God and country, from Mikhail Gorbachev to presidents, to actors and actresses. And so he'll have an interesting take on kind of what he is seeing as, I'm guessing, kind of the cultural landscape of how security kind of fits into our day-to-day lives. And then let's see, oh, Andre Durand Wednesday night. He is the CEO of Ping Identity.
You may have heard that company referenced on this podcast once or twice. Great Colorado company. Great Colorado company based right here a block from me in downtown Denver. And then John Kindervag, he is kind of a field CTO for Palo Alto Networks. Not sure what he's going to be talking about yet, but he's always a good listen as well.
And then to close off the conference on Thursday night is Josh Blue. And for those of you who don't know Josh Blue, no, he's not a security guy. He's a comedian. He was one last man standing, or last comic standing, sorry. And, you know, he's disabled and uses his disability as part of his act.
Hilarious, right? So, you know, come join us. Make sure you join us for the closing keynote. We'll have a bar. We'll have some food.
It'll be a good time to kind of wrap up the conference. I think also appropriately, you know, Josh is out of Boulder, you know, local person to help support the local conference. And again, going along with the Colorado Equals Security theme that we've got going on, that sounds awesome. Sounds like we got some great content. I want to jump in a little bit about not the sausage itself, but how to make the sausage.
So I wonder if you'd talk a little bit about the planning process, you know, When do you guys start actually planning for this conference and what does it entail? So we actually start planning in September, and it entails, well, several different committees that we kind of try and break up the work for, you know, ranging from sponsorship to programs to marketing, and then just all the logistics of dealing with the convention center and the different vendors vendor management required to really just put off a conference of this size. You know, food and beverage to audiovisual to stage setup, right? We have a— we have planning partners, iPlanet. They're awesome.
We've been working with them for years. They deal with a lot of those logistics, you know, thankfully, because we're all volunteers. We don't get paid. This is our night job, as Alex mentioned before, and really planning a conference like this is a full-time job. So we started September, the conference is in May.
We opened a call for papers, got an insane amount of submissions this year. Robb has a very good process in place to churn through them, down-select them, get them all scheduled. In the meantime, Um, you know, we have volunteers cold calling sponsors, right? Uh, we have several different sponsorship packages. A lot of the Colorado companies have been awesome in supporting us over the years.
Um, if you're a Colorado security company and have not sponsored CFRMIS, please reach out to me and Alex. We'll get you in touch with the right people. It's a great opportunity to get in front of your peers. And to kind of get your name out there within the Colorado community and really the region.
And really, from my perspective, I honestly can't take any of the credit, right? It's all of the volunteers on the different committees, the sponsorship committee particularly, right? Just really putting their ears to the phone, their keys to the— their fingers to the keyboard. Emailing sponsors, vendors, all their contacts, and trying to bring them on board. Although all the money that we make out of the conference goes right back into the chapter, right?
And that's why we always say it's the NYSCSA chapter can provide, you know, the free trainings to members we do throughout the year and stuff like that. So it's It's really satisfying for me, uh, to kind of not sit back and watch, but to be able to kind of coordinate all the different aspects and see it all come together. Um, again, the volunteers are key, our planning sponsors, our committee or conference sponsors are key, and again, for me, it's very satisfying. Yeah, and obviously I know from experience It does take a whole lot of work, 9 months of planning.
It really is satisfying once you get through it, and I really appreciate and want to thank you for your support in doing this. So thanks for that. Well, I thank you. I kind of made a joke earlier, but I thank you for not handing me a grease fire, right? It was, you know, a lot of, you know, those gears were pretty well greased, so I appreciate it.
So I know recently that registration opened. Yes. I don't know if you want to talk about that and what folks can do if they want to register for the conference. Yeah, so registration opened this week. We have early bird pricing available until April 15th.
Just go to the website rmisc.org.
The .org part is very important. And there's gonna be a big fat click here to register link at the at the top of the page. So, and there's— you'll see different pricing for ISSA Area Stockholm members versus non-members. At least from an ISSA perspective, we have incentivized you to sign up for ISSA, right? So you'll find that it's a better deal to sign up for ISSA and then register for the conference than it is to pay for the non-member price.
So we encourage you to do that. Again, all the money we make from the conference is Goes right back to our ISAC membership. And then, you know, yeah, early bird closes April 15th, and then, you know, prices go up from there. So awesome. And I know you mentioned it several times, there's lots of volunteers that help with the planning.
How are you guys doing on volunteers? You guys still need help? If someone wants to help out with the conference, what, what should they do? If someone wants to help out with the conference, definitely reach out. To go ahead and reach out to me, rock.lambros, L-A-M as in Mary, B as in boy, R-O-S as in Sam, at markwest.com, and I'll get you in touch with the right people.
Awesome. Well, I think that's all I had, Rock. Appreciate your time. For those of you listening, rmisc.org, whether you want to register, whether you want to sponsor, can find all the information there. Great conference, and again, I thank you for helping organize.
It really is the best conference around. Granted, I'm biased, but I can say it anyway. Any closing thoughts, Rock? Come to RMISC. It'll be a good time.
Oh, I, you know, I think, you know, one thing I'd like to get out there every time I give any talk is, uh, there's definitely, as we know, there's all a talent gap in the security industry, right? And it's not just a numbers shortage, but it is quickly turning into a skills gap shortage. So even though me as oil and gas, you know, I say the industry is kind of old school, um, we as security professionals, everything is turning into code, right? Everything as a service, software-defined networks, X-defined software-defined anything. I came up through the infrastructure ranks.
I think a lot of us in Alex's and mine generation came up through the infrastructure ranks.
I wish I took more coding classes in college, right? So I would, I would encourage you all to start looking more at application security, start actually looking more into coding classes.
Mobility, mobile security is gonna— is is key. Cloud security is key. I always say if I were to start a new company today, I would buy zero infrastructure, right? Everything would be in the cloud. So, you know, I hope to see future generations coming up out of school with more coding knowledge, whether it be from an automation, just a scripting perspective, being able to deploy massive environments in minutes versus months, you know, that sort of stuff.
And then understanding just how code impacts security, right? It all starts with the code. Anything we try and secure, there's bits and bytes behind it, right? So I just encourage you all to start focusing more on that. Awesome.
Good advice. Thank you. Well, thanks, Rock. Appreciate your time. Have a great weekend.
Happy St. Patrick's Day. Thanks, everybody. We'll talk to you next week. All right, this is Johan Hyvinen at Hostinger.com, and this is Colorado Equals Security.
All right, this is Robb Reck, and I'm here with Colleen Murphy, the president of ISSA Colorado Springs. You guys have been one of the larger chapters in the world for quite a while. I think most of the listeners know I'm also the president of ISSA Denver, and, um, we are 2— I think we're actually 1 and 2 in the whole world now. We are, we are, we— so we have a lot of good stuff going on in Colorado between our chapters. Um, so this is a chance for us to kind of share what you guys are doing down there.
Uh, over the last, uh, you know, since the podcast began, we've been highlighting the, uh, the activities you guys do, but I haven't had a chance to really get real specific on what you guys are focused on. So that's what we're here for today. So, you know, as a starting point Why don't you kind of tell us what ISSA Colorado Springs is like, how long it's been around, and what you guys focus on? Well, thanks, Robb. Really appreciate you inviting me up here.
The Front Range has a very significant influence on ISSA International. We've got a lot of cyber professionals in the state of Colorado, all up and down the Front Range. You guys are— I think Colorado Springs is pretty well known as being the government or defense hub area. Is that what you guys focus on at ISSA? We have a large government/DOD focus in our chapter, but we also have a lot of education perspective and a lot of commercial industry and defense contractors.
So, we've got a lot, but you're correct, it's, it's probably more heavily towards the DOD federal side than perhaps the Denver chapter is. But because we have several installations, we've got the Air Force Academy, Fort Carson, Schriever Air Force Base, Peterson Air Force Base, Cheyenne Mountain. So it's, it's heavily DOD. Yeah. So what is your, you know, what is your focus as a chapter?
What is it you guys are, you know, doing on a regular basis and you're trying to drive toward? One of the biggest things we focus on, I think, is training and giving back to the membership. We have several initiatives that are ongoing every year with many seminars, Security+ you know, seminar and a CISSP seminar. Those are pretty much our training mainstays. We do mini seminars most every month.
They're just on a Saturday morning for 3 hours, and we present one or two topics to give people a career broadening perspective and allow them to do some professional networking and get some continuing education credits that they can use to help maintain their certifications. Those have been a big hit to our membership, as well as the public, because we've opened them up to just any cybersecurity professional that wants a little bit of career broadening. And so, those mini seminars, those are usually on a monthly basis, you said? Right. And I know your website has the details on what they're doing there, and we'll continue to share those as well through Colorado Equal Security.
Is there a fee to attend those if you're a member and if you're a non-member? No, right now, Robb, they're free, and we expect to continue to have them as free because we want to encourage that collaboration and that career broadening to the greatest extent possible. We've had topics on the risk management framework. We've had presentations on ICS, industrial control systems, SCADA systems. We've had presentations on career progression.
We've had presentations on payment card industry, a wide variety, and we take input from membership as to what they would like to hear, have a presentation on, as well as people that want to get an opportunity to speak, they propose different topics. So it sounds like for folks in the Springs area who want to make a trip over there, not only is this an opportunity for them to learn about whatever that month is It sounds like you're looking for folks who might have something that they want to share and in a longer form than a normal chapter meeting. And I know Denver and Springs, we both have similar formats in that you get about an hour to present normally at a chapter meeting, whereas this whole— this 3-hour block gives you a whole lot more wiggle room, right, to do some interesting stuff. It does, although sometimes we'll set up 2 speakers for the 3 hours, so each one has about an hour and 15 or an hour and a half. We had Route 9B come in in November and give a presentation on things that they deal with as a cybersecurity company.
Right. We do 2 meetings each month, most months, so that members that can get away at lunchtime can attend a membership meeting. Those that can't can typically make an evening dinner meeting. And is it the same content for both meetings, or are they kind of separate? Yes.
Okay. No, it's pretty much the same content. Myself and the vice president of our chapter and a couple other key board members will attend both, and we'll give basically the same chapter events, chapter management overview, and then we try to have a guest speaker each time for about an hour, hour or so. Sure. And yeah, and then I know you guys have a couple other I mean, the big thing you guys do is your August conference, and we started talking about that here on the podcast.
Do you want to talk to us about that and what your vision for that conference is? Well, the August conference is our Cybersecurity Technology and Training Forum. That's a 2-day conference that we do the end of the month. This year, I think it's on the 30th and 31st of August, and we're just now building our speakers and getting confirmation from speakers, so I don't have anything firm to say who's coming to the August one. We usually have that in, I think it's the DoubleTree Hotel down on the south end of town.
Yeah. 2 tracks maybe over the 2 days, somewhat focused a little bit more on training opportunities, but a variety of guest speakers. Sure. We don't have a specific theme yet for that one because it's still, you know, 4 or 5 months out. We're still kind of focusing on our March conference right now.
Sure. So why don't you tell us about the March event? Okay, the March conference is called a Cyber Focus Day. It's a 1-day conference and it's held at the University of Colorado in Colorado Springs. And the speakers on it are all firm.
We've got, coincidentally, we have the CISO for Denver, the City and County of Denver, coming. Steve Corey. Yep, Steve Corey. He's coming down to give a presentation on, let's see. It's the election one, right?
The election hacking presentation? Yes, yes, Should We Be Afraid of the Russians? A Case Study in Collaboration from the 2016 Elections. And we also have the President of Federal Engineering, Infoblox Federal, coming. We have— that's Paul Parker, by the way.
We have Lynn Van Arsdale from Health Information Exchange Innovations. We have Michael— I can't pronounce his last name. Everyone's an insider, Federal Director for Exabeam. And we'll have vendors set up too, so there'll be a separate section where people can walk through and see. So, so you have the, the March event, you have the August event every year.
Well, as a chapter, anything else to highlight that you guys are doing? Well, we also do in October, we do a 1-day event at Peterson Air Force Base and a 1-day event at Fort Carson. These are cyber awareness and technology days, so more of a technical exhibit, and it's on the military installation. Okay, so we do those in October. Prior to that, though, we host 2 Security+ seminars each year.
The first one is going to be in April, April 1st and April 8th. It's a 2-day seminar on 2 sequential Saturdays, roughly 6 hours each Saturday, and we go through all of the Security+ material. It's a good review. We don't really teach it, but it's a very comprehensive review of all the material that CompTIA looks for on their exam. That's taught by chapter members, volunteers who hold the Security+ certification or a CISSP certification, and they basically present the different material.
Usually maybe one instructor for it for 2 domains for Security+. And the second Security+ seminar will be in June. I think the dates are the 3rd and 10th of June. And then we also hold a CISSP seminar in the August-September timeframe. That one is over 5 Saturdays, alternating though, so you don't lose 5 Saturdays in a row.
It's every other Saturday? Correct. So like the 29th of July, I think, will be the first day of the CISSP seminar, and then it's every other Saturday for 5 Saturdays, a total of a 40-hour seminar. Sure. To cover all the material in the CISSP And that's also taught by volunteers within the chapter who hold the CISSP and have had it for, you know, a few years.
And we split that up, have sometimes 2 or 3 instructors per domain so they can kind of tag-team and help each other out. And so we've done that for a number of years. We do that once a year though. That's great. It's a big resource, and I know as in Denver we've been Talking about trying to spin that up and finding the volunteers to teach it is a challenge.
It's a challenge. We have a training committee that's probably 20, 25 members that have offered up their time to teach these seminars at different times. The Security+ seminar, because we have so many excellent volunteers, we can offer that seminar for $40. And we also make it open to the public. You don't have to be a member.
You do not have to be a member for the Security+ seminar because we want to use that as an entry point into the cybersecurity career field, and hopefully they see the benefits of it and become members. But $40 is, is nothing, okay? It's an excellent review if you're thinking about getting a certification. It's a great way to step in, get exposed to all the material, find out if you're ready for the test or if, well, no, maybe not. I better go back and read this chapter again because I don't really— I didn't really understand that.
So you will know by the end of that 2-day seminar if you're ready to sit for the exam or not. Now, the CISSP seminar, we do want you to be a member by the time you take that. Sure. But even that seminar, we only ask for $125. Yeah, it's amazing.
For a 40-hour seminar. But again, it's because we have so many amazing volunteers that have offered to do this, and it's gotten rave reviews and great feedback. You know, I'd frankly, I'd say if you're not a member and you don't— even if you don't live in Colorado Springs, get down there and take this class if you're looking to get a CISSP. Even with an hour-long drive, it's a That's a really great value. It is.
We think so too. I mean, it's been a huge selling point for our chapter. And we also, space permitting, we will allow members to sit through and audit the seminar per se if they need CPEs. Oh, really? Okay.
Now for CISSP, that's fairly easy to do because we usually have a few empty seats. For Security+, that's harder because that actually tends to be standing room only each time we offer it. How many people do you allow in? For Security+, we usually have 20 to 25 students each time. CISSP, we probably have about a dozen students each time.
No, it works great. Those are the huge, very significant mainstays of our chapter. Well, that's fantastic. Another thing that I know you guys do, I'd love to hear you tell us a little bit about, is a mentoring program. I assume that, you know, especially folks coming into the Security+ courses or coming out of them, that might be a good fit for that.
Why don't you tell us a little bit about the mentoring program you have? Excellent, you read my mind. I was just gonna try and get the mentoring program in here a little bit. We started this last year, so we have a mentoring committee, and I'm not sure how many members are actually on it right now, but probably at least a dozen if not 20 mentors. Who have basically been cybersecurity professionals for a few years at least, and they're willing to meet with other chapter members and help them identify the career path they should take, give them some feedback, give them some lessons learned as to what they've experienced, what's, you know, a good way to approach different things.
It's worked really, really well. I'd say for anyone who's new to security listening, this is a really viable way for you to advance your career. It's not a— there's no hidden formula here, right? You go do it, you spend the time, get to know the folks, and you can really achieve your goals. The biggest thing you need to do is you need to take it seriously and show up with questions.
Show up, meet your timelines, do what you say you're going to do. And whether you're in Denver or you're in Colorado Springs, there are folks who are willing and happy to help you be successful in your career. It's a good thing to take advantage of. And I would tell everybody, keep in mind cybersecurity changes every day, so nobody's an expert. It helps all of us if we share what's going on and, you know, different career paths, what's worked for some and worked for others.
Yeah, there's no book answer. Right, there's not one right answer. So I'd like to ask you about you a little bit. You know, how long have you been as the president of the board, and how did you get where you are? And maybe just kind of go back from here.
Well, I've been the president of this chapter for, what, about 7 weeks now? Yeah. So I just got elected in as of January of this year, but prior to that, I was the vice president for training in our chapter, held that board position for 2 years, and prior to that, I ran the CISSP seminars myself for a couple years. So I'm very familiar with our training initiatives and kind of helped keep them going and grow them a little bit. And Luke Ingerman has now taken over the training side and, you know, it's just exploding the training opportunities even further.
But so I've been with the Colorado Springs chapter since 2008, I think it was. That was when I sat through the CISSP seminar as one of the regular students, became a member because of that, and continued my membership, took the test, passed after, you know, the first time. The seminar was a big help in that, and have just continued since then. It's been fun. I mean, you meet so so many wonderful people, right?
And, um, it opens a lot of doors for you, a lot of professional networking, a lot of good opportunities, a lot of training. Do you have anything that you're thinking you'd like to expand into in the Springs? Any, any ways that you think you're going to be able to add more value going forward? Actually, what you said is one area that we're looking to get into, is to provide a little more of the hands-on technical training. Yeah.
We started building a relationship with Route 9B in the hopes that we could leverage them, and we'll still continue to talk to them about it. But I'm interested as to how you managed to work your technical training aspect. Was that membership, or was that a sponsor, a vendor, or what? So as a general rule within Denver, we do our very best to avoid having sponsors ever talk at anything. Yeah, same here.
Um, that, you know, at RMISC, our big conference in May, um, we don't prohibit them from submitting to CFP, but there's, you know, frankly, there's a bias against vendors. And if there's someone who's not a non-vendor who's gonna— who offers to talk about some— a topic, they're going to get preferential treatment. But at our chapter meetings, vendors aren't allowed to talk. At our trainings, we've never had a vendor talk. I, I could imagine the possibility that we might at some point allow a vendor to do one of those since they are Frankly, they have a lot of great talent.
They do, yeah. But it's really hard for a vendor not to sell, even if they come in saying they're not going to sell. We had an example a couple years ago where, before I took over the chapter, where we had a vendor who I don't think I need to name here give a talk. The whole talk was— they didn't mention their product or their or their company at all through the whole talk. All they did is they described a problem, and at the end they, they described this problem, and it's a real problem, in such great detail that everyone in the room had to say, well, how do you solve this problem?
And then the speaker's answer was, I'm sorry, I can't talk about that because that's what we do. And, you know, it— I think I really don't believe the guy intended to, to, to turn it into a sales pitch, but That's just, that's just what it was, right? So anyway, yeah, that's off topic, but back to your question, how do we find the— how do we find our presenters? It's mostly from, from members, and it's, and it's from our network, right? People who we know, hey, you're really good at this, would you be willing to come talk about this?
And as a chapter, we will kick in, you know, an honorarium for those folks because it is a full day out of their schedule that they're, that they're, you know, usually taking vacation from work. Um, so we'll, we'll try and make sure we have a little bit of money to do that. And of course, we find a sponsor to help pay for the events. No, that's true. The sponsors are awesome.
They really do a great job and they help us stay afloat, right? But we've had real good luck with our sponsors and we've had them come and give different presentations, and we've all pretty much done a great job at having them give information with very, very little product or marketing as a result. It's a fine line. It is. It can be a challenge at times, but we've done quite well, I think, most of the time with that.
So, you know, I kind of put it out to you as you have this audience right now, hopefully, you know, throughout all of Colorado. Any message you want them to hear about Colorado Springs and a call to action or anything you want to share? I guess the main thing I would share to everybody is, you know, take a look at the news. How often do you see something about cybersecurity in the news nowadays? The president is focused on it, and he's only been in office, you know, 6 weeks, 7 weeks.
Cybersecurity is exploding around us everywhere, and the state of Colorado is becoming a hub, shall we say, for it. With the National Cybersecurity Center being established. Yeah. Okay, Governor Hickenlooper pushing that. That's why we say Colorado equals security.
It does. So to everybody out there, if you're in cybersecurity, stay current. Take a, take a look at everything that's going on. Be aware of it. If you're not in cybersecurity and you're looking for a career path, it's wide open, folks.
There's a lot of opportunities in cybersecurity in a wide variety of forums and industries on the health side, the financial side, the security education and awareness side, as well as the techie side. Yeah. And so it's a, it's a great opportunity for everybody, and it— you won't get tired of it. Because it changes all the time. Well, fantastic.
I, I appreciate you, you finding the time to, to talk with us. No, that's great, Robb. And for any of the Denver chapter folks who may be listening in, all of our training is, is open to all of you folks too. So, um, you know, keep that in mind if you're interested in CISSP seminar or Security+ seminar or mini seminars. I know it's a little bit of a drive, but our 2 cities keep getting closer and closer.
It's going to be one city eventually. It is. And really, Robb and I are trying to increase the collaboration between our 2 chapters because we are so close to each other and we are so large and have so much going on. It only benefits both of us to leverage each other's abilities in every way we can. All right.
Well, Colleen, thanks so much for your time and we'll look forward to talking to you soon. Great. Thanks a lot, Robb. Bye-bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.