Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.
Hello and welcome to episode 12 of the Colorado Equals Security Podcast. This is Alex Wood. And I am joined today by a special co-host. Uh, welcome Steve Knight. Thank you very much.
Glad to be here. So, uh, Steve and I, uh, worked together for, uh, not a whole lot of time, but, you know, a little bit of time at, at Kaiser Permanente a few years ago. And, uh, Robb was a little bit ill today, so Steve was willing to jump in and, and be co-host with me today. I will be Robb number 2. Robb number 2.
Robb number 2. All right, well, let's go ahead and, uh, jump into our news. So the first story that we had today, Verus Group, which was recently acquired by Coalfire, they completed FedRAMP assessments of several AWS services so that they could be used within government work. So I am not the biggest AWS person, but this is, I think, pretty interesting. So Amazon Glacier, CloudFormation, Key Management Services, Elastic MapReduce, a bunch of other services have now been certified for FedRAMP so they can be used for government work.
Yeah, that's really good. The fact that Coalfire was able to go in and do the assessment to gather the appropriate information and give feedback to those that want to use those services, that at least it meets that level of quality and certification around FIPS 199. So governmental bodies, even state agencies, might feel more comfortable if they look to move services into an AWS cloud versus the continuing cost of maintaining a data center and staff on their own. Yeah, for sure. I think it's also a big win for, you know, Veriff/CoolFire, you know, doing this kind of work.
The government sector obviously is one of the biggest sectors that are out there. So showing that you can get things certified through FedRAMP, I think it's a really big deal for them. I think it'll obviously get them some more work in the future. Very much. Next on the list, CyberGRX.
We've talked about them in the past. A former coworker of ours, Ed Fuller, is over there, I think, with maybe even a couple other folks at this point. They are looking to be an exchange for third-party risk assessments. They just got an additional $20 million in funding from Silicon Valley. Which I think is really cool.
Yeah, actually, this is a great model and a great company. The service they're providing makes a lot of sense. It goes back to the philosophy of test once, use many. In this particular case, they're gathering the assessment information from third-party vendors where organizations can actually go pull that information and get a pretty good idea of where they stand in terms of controls as a third-party vendor and be able to rely upon that information along with whatever additional due diligence they might want to do. Yeah, and I know they've been spending a lot of time building the actual platform that they have to do these assessments, um, you know, to, to do the questioning, um, you know, do the modeling, all that sort of stuff.
And getting this additional funding, I think, is going to really help them ramp up in terms of people, because even though they are, you know, uh, you know, based on a computer model, they do have to have the people to validate the assessments, um, you know, that sort of their higher level tier of assessments, make sure that they're going out and and validating evidence, other things like that. So this is really going to help them grow in terms of people to get those assessments done and really become that kind of platform they're looking to be. Well, and organizations benefit from the value-add service they provide for sure. Uh, next on the list, um, LogRhythm. Uh, James Carder, the CISO over there, um, we're going to get him on the show and interview him, um, not too distant future here.
But, uh, he put out a blog post about some, uh, free security awareness posters that, that they'll— that they're putting out. As he puts it, free security awareness posters that you'll actually want to use. So it looks like the first one that they have on is on passwords and passphrases. Uh, obviously a great target, um, for, for doing your first poster. Um, I think authentication passwords in general are one thing that, um, you know, it's a big hurdle for people.
You know, everyone's trying to get away from passwords, but, you know, having good strong complex passwords is always a positive. Security awareness kind of couples in with this as well, which as we know, the human is the weakest link in the chain. One other thing to add to this would be for those who are interested in picking up security awareness for the organization, but not necessarily having to staff it completely, if you go to CSO Online and a few other places, but CSO Online, which is the magazine, in the Salted Hash section, there's a section where they do security awareness. And they'll provide you like 4 PDFs a year for a certain cost, and it's complementary to what is the LogRhythm stuff that's provided here. So for roughly $10,000 a year, maybe less, you could actually pull in an entire security awareness program for your small organization without breaking the bank.
Yeah, and I know SANS has some additional free resources as well. It's great to see LogRhythm, you know, they're a SIEM company, you don't think of them normally as security awareness, Great to see them stepping up, getting some other free tools out there for not just their customers, but for the entire community. Sure. Another value add.
Next on the list, this is a story that Steve actually brought to my attention.
There's a woman who is a medical student and who actually posed as a— I believe as a doctor, essentially posed as more than what she should have been posing as to actually treat patients at Denver Health. So, I think this kind of goes back to just talking about physical security, right, Steve? Oh, absolutely. According to the article, she was a student from CU and she was supposed to be there to learn, but apparently— and they're not going into great detail for obvious reasons how she was able to alter credentials, but she got to the point where she was able to get in and actually participate in seeing patients. In a healthcare industry, we often worry about biomed devices being hackable and impacting patient care, but here's a physical example where a student who was presumably inside the trusted circle was able to circumvent physical security controls and actually get in and participate with patient care.
That's pretty frightening. It is frightening. Although I have to say, I have had treatment from a number of medical professionals that I was a little suspect about. You know, maybe she would— maybe she was smart enough that she's actually good, giving good care. Uh, but obviously the point here is that, um, you know, you do need to continue to focus on the basics, um, things like physical security and other controls that you might have in place.
While it's great to have a, you know, a shiny new tool or something like that, making sure you're doing the right stuff like physical security is always a good thing. It'll be interesting to see what the after-action analysis comes out to be why the student decided to do this because they've definitely brought down the attention of the Denver Police Department as well as the Denver District Attorney's Office, so I hope it was worth it. Yeah, even if she's good, she may not be practicing medicine anytime soon. No.
Last on our list of news today, we have an article from Google. This is actually posted by someone that Steve and I used to work with at at Kaiser, Michael Janosko. He left a few years back to go work at Google. And, you know, he's been doing some of their sort of internal security work, which is— it's some cool stuff. You know, we've talked about BeyondCorp in the past.
I know Robb is big on that whole BeyondCorp and identity-enabled security. So they put out an ebook this week about how they're doing their tiered levels of security in terms of access. Again, the BeyondCorp initiative is sort of rethinking how you do corporate security, not necessarily the castle method, but really looking to expose things more directly to people, but then use identity as the method to get in and provide the right access to those people. Yeah. Looking at the program and talking a little bit to Mike when we saw him out at RSA, BeyondCorp is, is really an evolutionary piece for Google right now where they're trying to push more to the edge with less control devices, or basically to reduce the amount of hoops you got to jump through to get to a physical device where there's information.
So they're using multi-factor authentication going through what they call an identity-aware proxy, and then also using identity along with multi-factor authentication to gauge the level of access that you have to sensitive applications or sensitive data. Yeah, and it's a fairly detailed ebook. I think it's definitely worth a read. We'll have a link in the show notes.
Really, in the past, it was binary. You were either in or you weren't. Maybe within an application, you obviously had access control, but this is even a step before that where we're talking about, okay, now you're getting authenticated, but what's that base level of access that you have just by being authenticated? Can you get to this application that you want to get to? Can you get certain levels of access within that application?
Are there other things that you can get to? I really like the more fine-grained model as opposed to just the binary traditional model of the firewall or the VPN, either you're in or you're out. I think it speaks to broader language as well in the sense of data classification. Because access, if you're really wanting to use identity to gauge the level of access a person gets, to a system or to data, if you get it down to rudimentary root terms, then you're, you're talking about, well, we know what our data is and we know where it's at and we know what its classification or sensitivity is and we know who should be able to get access to it. Obviously something the federal government seems to have a hard time with, especially in the CIA.
Yeah, for sure. Yeah. Um, yeah, and that's a great point too. You know, you have to have a lot of these things sort of baked in from the beginning. You can't just turn on sort of an identity-enabled access like this.
You have to know what you're getting access to. Well, and they're very explicit in that this is the 2nd edition of their best practices, and right now they're focusing on Edge. Eventually they want to carry this model once they test it to other devices. Today it's mobile devices. Very good.
It's definitely interesting stuff from them. So yeah, check out that link for the ebook. And that's all we had today for the news. So let's, uh, let's jump into the events that are coming up. Um, so we've got 3 events that are this week.
Uh, and actually, quickly before I get to that, I was at the, uh, the ISSA happy hour last week, and I just want to say thanks to all the folks that came out to that. It was a good event. Uh, saw lots of people there. Uh, this week we have 3 events. The first one, um, Automating Security in the Cloud for AWS.
So this is a free training from Amazon. It's actually a 2-day training, so I would say definitely check that out if you are doing any work with AWS and want to learn more about how to do security in AWS. Well, I think it also gives you a little bit of a sneak peek into how Amazon conducts cloud services and maybe even cloud security. And well, in fact, it is cloud security. And then in that instance, if you're looking to use a cloud provider, perhaps this is a good primer to what you should be looking for in dealing with a cloud provider.
For sure. And, uh, I don't, don't know if I mentioned or not, that's on the 25th and the 26th this week. Uh, next, SecureSet, they're hosting one of their capture the flag events. We've had a few of those in the past. Um, you know, these are good events if you're, uh, even if you're an entry-level person, you can come in and sort of get the lay of the land, uh, before the, the event goes on, and then you can go ahead and do the capture the flag event.
If you are a seasoned person and just want some extra practice messing with stuff, you can just go in there and go straight to it. That's happening on the 28th at the SecureSet offices there. And then the third one we have on the 29th, ISSA Colorado Springs is having their free mini seminar. This is a slightly longer event for them. Not quite a conference level, but, you know, more than just a luncheon.
They don't give a whole lot in terms of what the topic is, but if you're in Colorado Springs and want to get out and talk to them, get a little education in, go for that. So those are the ones that are coming up this week. Obviously, we're getting closer and closer to the Rocky Mountain Information Security Conference. That is on the 9th through the 11th of May. I don't have any specific news for that this week.
We have gone past the early registration period, so if you didn't register yet, then you missed out on that. You still can join as an ISSA or ISACA member if you're not one already and get a discount. Definitely worthwhile to do that. But again, Rocky Mountain Information Security Conference, we feel like is the best conference that we have every year, so you should definitely go to that.
Finally, on the 12th and 13th of May is Denver BSides following Rocky Mountain Information Security Conference. Again, great event, a little bit more casual. Come and hang out, learn some stuff, listen to some people, drink some beer. It'll be a good time. Absolutely.
So that's all the events coming up for this week. Let's jump into the jobs. So first, Ball Aerospace, they're looking for a Network Security Administrator 2. Obviously, that is twice as good as a Network Security Administrator 1.
Hopefully, it pays that way. Probably not. Probably not. Ball Aerospace, of course, located up in Broomfield, sort of South Boulder area.
CHI, Catholic Health Initiatives, they're looking for a Senior Compliance Specialist.
Oppenheimer Funds, If you're looking for financial services, they're looking for a cybersecurity manager for identity and access. That's actually a sort of a mini trend that I'm seeing this week. So Oppenheimer Funds is looking for an IAM person. The next job, Kaiser Permanente, someplace near and dear to both Steve and my hearts. They're looking for an executive director of cyber identity and access management.
Steve, I don't know if you have any insights on that particular job. Leadership role over identity and access management, so quite a bit of responsibility and accountability, and reports directly to our good friend Jim Goddard. Yes, Jim Goddard, who I keep pestering to try and get on the podcast. Yes. So Jim, if you're listening, I still want that interview.
We're coming for you. Next, Palo Alto Networks cybersecurity manager for CSS. So that's cybersecurity services. So this is people that are providing the services around Palo Alto Networks gear. So if you want to manage some folks delivering those services, this is the job for you.
Arrow Electronics Information Security Architect 1. Sameer Seth, the, the CISO over there, he's a good guy. I like Sameer a lot. He'd be a good person to work for, so you should check that out. Arrow's a really interesting company.
Uh, KPMG Director of Cybersecurity Services. And again, this one, looking at the job description, is focused on identity and access management. So, uh, if you want to work for one of the, the big consulting firms, um, and, and manage some of the folks that deliver their services, I think this is a good opportunity. I think the bottom line for all of these, uh, the 3 that we talked about, is If you have skills in IAM, you seem to be in demand. Yes, the other interesting thing to bring up is the development and growth of tech startups in the area, from the large to the small, and it looks like Boulder is seeing a lot of activity in terms of Microsoft developing a new campus.
Google has already started the development of their new building and they're expanding their footprint up there, so it looks like all good news on the employment side. Yeah, for sure. Um, and then the final job we have, uh, Cobiz Financial, they're looking for an IT senior risk analyst. Um, so if you have some IT risk management experience and, uh, again, financial services, uh, that would be a good one for you. Um, Steve, on, on your point a minute ago, there's actually one story that I was going to include and I forgot to include today.
Um, there was an article in Denver Post by, uh, by Tamara Chuang talking about how a number of the startups, not just security startups that we have in town, are definitely maturing sort of beyond that initial stage and are getting to be sort of mid-tier, you know, sort of longer-term companies. And I think that that's a really good— something really good in the evolution of the startup scene here in Colorado. One of the things that they mentioned was that Um, you know, because of sort of all the resources that they have around now, um, you know, with, uh, with Techstars and, uh, Blackstone Executive Network and other things like that, it's really a, uh, not just a place for initial startups, but, you know, these companies are becoming, you know, longer-term, bigger companies. Absolutely. Uh, on, on the personal side, I've seen a lot of movement of individuals coming from California to here and being a part of organizations There was a gentleman that you and I used to know by the name of Darren Yamaki who was in identity and access management for Kaiser.
He actually joined a small firm, consulting firm out of Boulder, to start providing those services on a national level. You see such things as Ball Aerospace is just now going to develop— they're breaking ground, it'll be ready in 2019— for a new aerospace manufacturing center, which is going to require a lot of security and identity access management specialists to fulfill those roles. Denver's kind of— Denver and the surrounding suburbs are starting to grow into, uh, like a Silicon Valley East. Yep. Yeah.
And of course, you know, we had this story last week with, uh, first quarter this year Denver was number 4 in terms of, uh, VC money. So it's definitely growing. It's coming. Yep. Yep.
All right, so that's all we had for this week. Uh, Steve, any final comments? Uh, thank you for allowing me to join today, and, uh, if there's ever an opportunity to come back, we'd be happy to. Awesome. Well, thanks for being here, Steve.
It was good to see you. Thanks for being on the podcast. And coming up next, we have our feature interview with John Everson. So Robb sat down with him, and that should be a great interview. Thanks again, and we'll talk to you guys next week.
See you next time.
This is David McGuire, Director of IT Security at QEP Resources. This is Colorado Equals Security for Colorado security professionals by Colorado Security All right, well, welcome to the Colorado Equal Security Podcast feature interview. This is Rob Rack, and I'm fortunate enough to sit with one of my friends, John Everson. John, you want to introduce yourself to the listeners? Sure, Robb.
I'm John Everson. I'm the Chief Information Security Officer at Dish Network, and I've been there for about 7 years. And Sling. And I've been there for about 7 years, actually over 7 years. Now.
Yeah, so you've been in Denver for 7 years, is that right? I moved to Denver from Kansas City in 2010 for this job. And what were you doing before you came here? I worked at Sprint and I spent 15 years at Sprint in various roles. And anywhere from security to running email systems to research and development.
So when you were brought into Sprint, were you on the IT side? Were you security? Doing operations? I don't think I was formally IT, but I had a shadow IT kind of role. But I supported one of 14 different email systems.
You guys had 14 email systems? We had 14 email systems. This is back in the mid-'90s. So was that for the workforce? This is for the workforce, yeah.
Now, is that different instances of the same email systems, or there's 14 different technologies? Oh no, there's 14 different systems. I didn't even know there were 14. Yeah, well, back then there was some mainframe-based email systems that we managed. But I was brought in to manage CC Mail.
Of course you were. Yeah, CC Mail before Lotus bought them. Well, that's pretty fun. Yeah. So how did you get from, you know, kind of managing IT stuff to getting over into security there?
Well, one of my bigger projects at Sprint was a couple years in and they wanted to reduce the 14 email systems down to 1. And so the only way to effectively do that across multiple divisions. It was a big company back then, probably over 100,000 people, and mainframe, we had Mac, we had Lotus email, Banyan Vines, we had Banyan Vines back then. So the only way to really effectively do that was with an X.500 directory. So we bought a scalable directory and we customized some solutions that was pretty fun to build.
And we ended up— because we had 14 different email systems, but no one knew who was in them, right? So you may have had email in 7 different systems, but as an admin, I didn't know that. Why didn't you know that? We just didn't have that good of provisioning records. No visibility.
No, people— you needed an account, you got an account, right? So we had to first discover, you know, which accounts existed, which accounts were active, and then which accounts were actually being used to send email outbound. And so we built this elaborate system to identify a brand new email address that was being used outbound, and we would hold the email and we would send a return message back saying, identify yourself. And they would identify with their employee ID and whether or not that was their primary email, and that was it. All email-based.
So we did that. So you phished your employees? We did. You man-in-the-middled your employees. I got it.
We actually probably kind of did a bunch of different security protocol. Oops. Yeah, yeah, yeah. But at the end of that, at the end of the 9 months, we identified all the users and it was very, very, very, very successful.
Shortly afterwards, this is late '90s, Sprint wanted to build an a PKI. And so they were looking for people who knew directories. And I happened to know directories pretty well. You had just done a lot of work there. I didn't know anything about security, but they brought me in as a low-level manager and I built Sprint's PKI, internal and external.
What year was that? This is back in '97. So then over the next few years, I worked in corporate security and we built all kinds of authentication technologies The PKI was really your avenue of getting into their corporate security area? Yep, yep. Learned all about authentication, learned about encryption.
I knew a lot about LDAP and authentication from our NetWare and Microsoft networking aspects, but it really kind of cinched in when we started building— we built a lot of managed security services for folks around the DC area. That makes sense. Yeah, 3-letter people, I assume. Yeah, it was fun. Yeah, so starting in '97, you were in security then?
Yep. And what did you— what all did you do? I guess you were there for 13 years after that, right, in security? No, actually, I left security in 2001. Okay.
I realized that no one wanted to encrypt their files. Hmm. Yeah, so, you know, I was advertising and marketing encryption internally. I was selling it to the execs, nobody wanted to encrypt their files. They didn't want plugins for their Outlook to encrypt their files either.
So I got kind of disillusioned at that time. It was after the internet, you know, the bubble burst, and I realized that there was an opportunity to get even earlier in the process and do research and development. And so when the opening came up, I jumped for it. And I brought a security focus to the R&D group at Sprint who was trying to build some new wireless technologies with this crazy thing called 802.11. Yeah.
Yeah, it was brand new. Yeah. Right? And you had the opportunity to really kind of move into a whole new area, it sounds like. We did, we did.
So we were focused on building not only new services but also new products, new lines of business kind of around Wi-Fi back when Wi-Fi was still kind of unknown. Yeah, that's pretty cool. And we had to prove out that it was secure, so we spent a lot of time digging into a lot of the security issues. And during this time, we— I managed to get a lot of patents. Yeah, yeah.
How many patents is a lot? I filed for 100 patents and I have 86 to date. And yet The other 14 are maybe in process? They are in process. It takes years and years to get these patents.
So you have patent pending on here? I don't record all the patent pending ones because a lot of these actually beget other patents. Yeah. And then they— a lot of the patents get filed internationally too. So that's kind of neat.
It is neat. Yeah. So how long were you doing the R&D side? Probably about 8 years. Okay, from 2001 to 2009?
2009. And then, uh, and during that time it was a lot of product development, business development, uh, proving out new technologies. We did, uh, wireless power back in 2004. So the whole idea is you can actually charge your phone via a wireless pad. Seems impossible.
I know, it's crazy. It shouldn't be possible. You need a patent for that too, I guess, right? Um, but yeah, it was a lot of fun. One of my favorite projects during that time was— and we patented this too.
But it was the idea— we were actually doing a project for the Department of Energy, and they wanted us to build kind of a public Wi-Fi network, but they wanted to make sure it was all secure, and they didn't want to have a whole bunch of WEP keys or anything like that. Do they know what secure means? Yeah. So what we ended up doing is we kind of built a hybrid solution. This is pretty fun.
So we bought Actually, we worked with a company, they're out of business now, RGNet. We worked with this company to build this gateway. They already had the gateway, but we modified the RADIUS daemon running on that gateway. And so basically we told all of the access points to do a MAC-based authentication. So they would get the new connect message from the wireless client.
They would pass back the MAC address to the gateway. The gateway was configured to accept all. They were all approved, but it would randomly assign a VLAN back to each unique MAC address. So every connection that came in on this open network ended up getting— actually, it wasn't quite open because we did have a WPA key, but every connection ended up getting their own VLAN. So even though if you and I were competing in this environment, right, using the same Wi-Fi network, Your VLAN was different than my VLAN and I could not attack.
You have to do some kind of MAC spoofing to— I assume that MAC spoofing would defeat this? MAC spoofing would just get you on a different VLAN. The VLAN of the person you were going for. Yeah, yeah. Anyway, interesting.
Yeah, it was fun. It was kind of a fun thing. It was fun. So is that your last game sprint or did you run somewhere else after that? Briefly, I developed some 4G devices.
That wasn't much fun. So were you there for 15 years? 15 years. So I mean, it's something, something interesting must have happened after 15 years to make you say you're ready to leave a successful company and that you had interesting stuff to go on. Yeah, you know, I felt like Sprint was kind of on the decline a little bit.
They certainly weren't investing in R&D. Okay. So I was, like I said, I was developing 4G devices. Devices, which is not nearly as much fun as climbing on buildings and installing radios. So there was an opportunity here in Denver at Dish Network, and I knew the CIO.
I worked with him back in the early '90s, even before I went to Sprint. No, actually late '80s probably. And so he invited me to come out and help him run security. So it does, you know, it seems like kind of a jump from being an R&D guy for 8, 9 years to, you know, going and running a security program for a Fortune 500 company. It was a huge leap.
And how, number one, how do you, how do you show you're qualified for that? Number two, you know, how was that kind of a transition? Yeah, well, luckily I knew the guy, right? I knew the hiring manager, and I guess he vouched for me. Yeah, I don't know how I landed it.
You had some photos, I assume? I had no photos. I had no photos. A lot of old stories. Yeah.
But yeah, no, we worked together for many, many years and he knew my work ethic. He knew that I was a problem solver and that I would roll my sleeves up and get the work done. So I think that's what he was counting on. So you were hired in 2010, was it, as Director of Security for Dish Network? As Director of IT Security, yeah.
And you moved to Denver for the job? I moved my family to Denver for the job and I've been there ever since. The team that I have now is about 50 people and we started with 9. So it's grown, yeah, but we've added some functions too. So obviously DISH is, you know, it's always on the list of biggest companies in Colorado every time you see it.
Big name, you know, Charlie's always on the list of richest people. He's Colorado's richest man, Charlie Morgan. Self-made billionaire. Yeah, so obviously a big story here, and you know, you guys do some pretty cool stuff in the area. I think it'd be interesting to hear a little bit about, you know, what did security look like in 2010?
You mentioned 9 people. You know, what was the functionality there versus what you've done over the years to build it out? Maybe just give us a picture of what it looked like in 2010 when you came in. Sure, yeah, there wasn't much of a security program. We had 3 guys in a room that nobody talked to, and in fact, I think everybody avoided the hallway.
Occasionally they'd be invited out, but none of their advice was ever heeded. And that was a security team. Yeah. I also, when I started, I had a provisioning team. So that was, um, I think about 4 people, 3 or 4 or 5 people.
Is that just onboarding everyone who joins the company? Onboarding, but it was all manual. Everything was manual. So a swivel chair, oh, they're going to want Active Directory, an email address, Oracle access. So they had a piece of paper checklist that they were going to go through to make sure they got added to all the right groups and stuff?
There was actually electronic ticketing, but nothing else was automated. But they had their own checklist that they followed for provisioning users. It was very manual and very error-prone. Yeah. And then the last group was compliance, which is probably the most robust group that we had, and that was because we were a PCI shop.
Sure. And they had already passed PCI a couple of years. PCI, and I assume SOC, Sarbanes-Oxley as well? Yep, SOC's IT governance controls. Yeah.
And that was pretty much the focus, policy writing. Sure. They wrote policies. So your compliance group did your internal security policies? They did, they did, all just to meet the PCI requirements.
So, you know, you came in 2010 and you saw where you were, and what was your vision? You know, if I was interviewing you in 2010, a month or, you know, 6 months in, what would you say you were gonna go after, you know, start early on? You know, it was going back to my roots of problem-solving. It was as I was interviewing people, or actually, as I was being interviewed for the job, I asked every one of the people that were interviewing me, what's the biggest problem with security today? And what problem can I solve for you today?
And mostly it was getting quick access to things and then internet access. It was pretty tightened down. I want to highlight what you just said and really echo it. If you're doing interviews and you don't ask the question, what's wrong, or how can I make you successful? What do you need?
What could I— the way I ask the question is, if I've been here a year from now, what will I have done to make your life better during that year? And helping them imagine it, right? Right. And then you go execute on it when you're there. You have to.
So I heard speed, you know, getting better access, being more nimble. Was that kind of job number one? That was. So provisioning-wise, people wanted to have better access. They wanted to have their people working day one.
They did. They did. And they want internet access. And at the time, internet at DISH was severely locked down. So most, most people could not use the internet.
They were only able to get internal access, right? So you're a brand new employee, you show up day one, you have no internet access whatsoever. Interesting. You can't even Google anything. Yeah, that'd be a tough work environment.
And then you had to go find the form that would allow you to request it. Hopefully that wasn't on the internet. Hopefully that was internal. It wasn't the internet. Yeah, but it wasn't advertised.
So How did you address those things? So really, going back to those questions you were asking during the interview, those become your 100-day plan. You need to solve those first because you need to build those relationships and you need to have the people that you're peers with, they need to be your stakeholders. And so you need to prove your worth to them. So that was really kind of the goal.
That and of course learning your team. You have to learn your team and I spent really the first 30 days running around interviewing everybody else in the company. Yeah. And doing the same kind of thing, you know, getting the lay of the land, trying to build those relationships. And you're trying to find the skeletons.
Yeah, that's fair enough. Yeah. So, you know, over the first couple years, you know, we could fast forward and start talking about 2011, 2012, 2013. What did you accomplish that you're proud of in those early years? You know, getting the Getting the security guys out of the room and more engaged in the pipeline, that was a challenge.
That was a challenge process-wise because nobody wanted the security gates in the process. No one wanted us to review the projects as they were being, you know, going through the intake process. Nobody wants us to do that. But getting that and getting the guys in the public was probably the biggest accomplishment we had. Refreshing the tools.
Security guys love tools. So refreshing IDS— actually, refreshing IPS was the first thing we did. Yeah. And then investing in a separate technology for our IDS was a decision I made that was discussed frequently on the security team. So having 2 tools to do the same thing.
Yeah. So we were talking about this before we started recording, you know, the way the way you look at tools and the way you grade them. Would you mind just kind of sharing how you evaluate the effectiveness of your tools and where you want to be? Sure, but this is, this is relatively new. So we've made a lot of investments over the years, and it got to the point where we had so— we had more tools than we had people, and we were trying to figure out how are we managing those tools.
Are we managing them effectively? Is the tool being used to the best of its ability? And what we ended up doing is getting a— just a grading score, like a high school, junior high school grading score of A through F. And so we have the team actually rate all of the tools, and everybody rates it all independently, and then we aggregate all the results. What's the criteria? A means what and F means what?
An A means that it is completely patched, running the latest signatures or filters, and eyeballing it every day and it is— you're proud of it. You would want to bring people in from the community and show them how effective that tool is. Sure. Right, that's an A. And an F means it's sitting on a shelf somewhere and maybe it's not being used, or if it's used we don't know it?
I think it's running. Yeah. And I looked at it last week and it was still running. Okay. That would be an F. Okay.
And what do you do with those grades? We evaluate the tool to see if we need to either invest in some training, bring in new resources to help manage that tool, or eliminate the tool and buy something else. And so we did this recently. Yeah, last year, maybe it was 2 years ago. We took one of our bigger tools that was getting probably a D, and it was up for renewal, right?
You know, the end of life, end of life the hardware, and it was up for renewal. And so we ended up trashing it and buying a brand new tool. In a different space. Just, you know, using that budget money to just ultimately reduce the risk of the overall company, right? Right, yeah.
It required very little approvals because we were reusing money because it was already in a budget. So, you know, during the 7 years you've been there, can you highlight a project you've done that you're especially proud of that's, you know, that maybe was more difficult than you thought going in or something that people said couldn't be done? Well, the project that I'm probably most proud of would be on the fraud side. So my team does— we do compliance, we provision users still, BCDR, business continuity disaster recovery, eDiscovery. So we're helping the legal team find and collect data.
Anti-fraud. I've got IT contracts. What does anti-fraud mean for you? It's not internal fraud. It might be, but rarely it is.
It is looking for people on the outside that are abusing our systems, trying to glean bits of data. Interesting. Any kind of information that's out there is useful to somebody, and everybody who has a machine exposed to the internet is being used by somebody, whether you know it or not, right? And it's being used in ways that you don't— you never expect. Sure.
And so what we found over the years is that a lot of our tools are being used by other people for some other intent. And it could be something as easy as testing credit cards. So we're trying to get new customers. We've got self-service flows. You can, you can go to our web page and sign up and enter a credit card and we'll tell you if the credit card is good or bad.
Right. So then so people will hang out on our website all day long testing credit cards. So you become their way of knowing if that cache of credit cards they found is good and how many are still good. That's right. It's cheap.
It's a cheap tool. Anyhow, so the anti-fraud team, they look at a lot of our traffic pattern and they try to find patterns in our traffic logs and identify people that are abusing us. Sorry, I cut you off. You were going through your teams. Yeah.
So IT finance. Also rolls up to my— within my department, and security architecture. Gotcha. So you've grown quite a few teams. Grown quite a bit.
Yeah, our provisioning team is actually split into 2 teams. We have an identity management team and then we have an access management team. So the access management team, they're the ones that are working all the tickets and making sure that all the automations are working. Yeah. And then the identity management team, they're the ones that are building those automations.
Yep. So I, you, you started into this because you were going to talk about the projects you're most proud of, and I think you're going down the fraud road. Yeah. So on the fraud side, what we identified is a bunch of bad guys, and no one knew this was going on. It took us 18 months of digging to find this out, but a bunch of bad guys were, uh, were using our resources to find out if, uh, if certain identifiers like phone numbers, if they belonged to a customer or not.
And if they did, then they would do things to that account to make money. I can start to imagine some of the ways they might do that. Yeah, so I'm very proud that we found this, and what we ended up doing is we ended up randomizing the account numbers that we assigned to subscribers. Because that's the identifier they were using actually, is the account number. So how visible was that type of a project in your company?
Is that something that CFO cared about, CIO cared about? Who had visibility there? Everyone realized the impact of it. And it had to go to— it didn't quite go to Charlie, but it had to go to the top for approval. Is that a win that went to Charlie though when it was done?
I doubt it. Okay, I doubt it. And I wasn't doing board updates at the time. Now I do board updates. Charlie's on the board, so he would have heard it firsthand.
Yeah, that was years ago, right? But yeah, so getting, getting a company to change how they assign account numbers to subscribers— and keep in mind that we were, we were doing 25,000 account numbers a day. Yeah, so it's a big— so randomizing that, working with our partner, it's all mainframe-based. Yeah, getting all that changed. Is, uh, it's not a small feat.
No, that's, that's pretty great. Um, so what about, you know, you've been there long enough that you've, you've hopefully tried lots of stuff that was very difficult. Do you have any, any stories of projects you've done that maybe didn't work, that you failed on, and that you learned something from? Um, projects or tools? There's been a lot of tool failures.
Initiatives or— yeah, yeah, we— there's been a number of, of, of things like that. They're, they're not, they're not huge Luckily, we fail fast and we move on. But I'm thinking through some tools. We bought a tool to help us manage firewall rules better, but the operations team didn't— they weren't fans. They didn't have buy-in.
And so we didn't get the data we needed. So is that like the— I'll say a few names like the Tufin, Firemon, AlgoSec, Sec, that whole genre of things. Yeah, something like that. Something like that, yeah. Fantastic tool.
And when you actually have the right data, it was very, very effective. But if you don't have the right data, like everything else in security, right? If you don't have the data, it's not going to work. So you bought the tool, you said, hey guys, go implement this. What happened?
First of all, we had to get the right permissions, the right log levels, and a lot of these tools tools, they only work if they can log back into the firewall and actually pull configs. That's the breakdown. So the operations team, they didn't want us to have a security tool logging in and scraping config files.
So what was the resolution out of that? We no longer have the tool. And is there a lesson you got out of that that you you've taken forward from there? The buy-in is the biggest lesson, but even though I thought we had buy-in, to be honest, but yeah, you have to have buy-in from all parties and you have to keep reiterating what the benefits are. Yeah, it sounds like the relationships there, right?
Maybe you thought you had buy-in, maybe the relationship wasn't quite where it needed to be at that time. That's right, yeah, and that was early on. Since then, I think if we brought a tool like that in now, it would be largely successful. It would help us kind of vet our firewall change requests too. So you were hired in 2010 as the Director of Security, and you're— was it a year and a half ago maybe you were promoted?
It was at the end of '15, yeah. So about a year and a half ago. You were promoted to Vice President and CISO? Vice President and CISO, yeah. So what do you think it was?
You know, I'll tell you, it's not all that common that someone gets promoted after that long at a company. That's right. It's generally you get kind of thrown into, it seems to me like generally people get kind of put in a box as this is your level and that's where you'll be. What do you think it was that changed the dynamics? Was it, you know, your relationships or was it the kind of the market in general changing?
What do you think? You know, I think it was a bit of everything. So there were a lot of breaches, and the publicity of breaches has gotten bigger and bigger and bigger each year. And I leveraged those, right? Never let a good incident go to waste.
So I capitalized on all the things that were happening external to DISH, and at the same time, we were growing our program internally, and we had implemented a a really effective tool internally that touched everybody. They all like it. We had moved a lot of our services to the cloud. A lot of these were security-initiated services or efforts. So, we were showing some value there.
We brought on— we built a brand new eDiscovery team. That was new a couple years ago. So, as a result of all of these accomplishments, everything else going on in the world, a lot of new Chief Information Security Officers was being defined, I took that opportunity to go back to my management and said, hey, I'm already doing the job, give me that, give me the title. So you made the case for it? I did.
And was it— did it take a while, or was it relatively quick, or what do you think? You know, it was an easier argument than I thought it would be. Yeah. Upper management did not want any more chiefs. Yeah.
Chief marketing, chief technician, they didn't want any of that. And then, so I made my case in 2014, okay, and I was thinking that I was gonna have to leave the company to go someplace else to earn that title or to achieve the title. And a year of stewing, upper management decided, okay, we're gonna have some chiefs. So at the end of 2015, we ended up with a Chief Technology Officer, Chief Marketing Officer, CIO, ISO. Yeah.
Well, anyway, congratulations. This is huge. 9 of us were promoted that day. Wow, that's fantastic. I remember you and I talked at the time.
It's a great accomplishment. You know, what are you guys, Fortune 200 somewhere? We're 180s. Yeah, I mean, it's a big accomplishment, so you should definitely be proud. Yeah, so, but you asked about failures.
Oh yeah. I've got a couple more failures. Yeah, okay. So the Firewall Policy Manager thing was a failure. I tried to do a homegrown, part of the anti-fraud efforts, a homegrown tool using Snort.
The tool seemed to work in the labs, but it failed. It was never an effective tool in prod, and I'm not sure why that is. I suspect it wasn't getting the data that it needed or the feeds that it needed, but I also believe that my own team didn't fully believe in the solution either. Was that a case where you had a vision for where you wanted things to go and maybe pushed that vision down rather than seeing if it was reflected from— Yeah, and it was a bit kind of R&D-ish kind of idea. And so yeah, it was my idea and I really just wanted them to execute on it.
And I didn't socialize it very well. I didn't get their buy-in and frankly I don't think they understood what we were trying to do. That really resonates with me as, you know, coming from a career of doing, you know, highly technical things. And, you know, you can imagine every step of the way how you get from idea to delivery. And you say, I'm just going to hand it to someone else to go do the delivery, right?
And they take a totally different path, right? Yes. And maybe they didn't really catch the vision in the first place, so they're trying to take your vision and it doesn't work. It does not work. We have to share that.
Anyway, it resonates with me. I think— thanks for sharing that. Yeah, you've got to socialize it, and you, you really have to kind of walk through and even follow up, right? So it's all about delegation. And it's, it's funny, you know, as a, as a people leader, how we can sometimes think, well, all you do is manage at this point, and, and, you know, hey, you need to be more involved in technology.
And we think of it as being a good thing, but man, sometimes being too involved in the technology is a bad thing as it, as it, you know, disempowers, unempowers the folks underneath you who are supposed to be doing that job. That's right. And if you get too involved in their business, they can't, they can't make decisions because they're paralyzed wondering if it aligns with yours. Exactly. Yep.
Yeah, it's a tough balance. Development and delegation. That's what it boils down to. Did you have a third? I do, but it's not a very fun one.
It's a key safe. It's an enterprise key safe for apps. For apps and people. Secret management. Yeah, and another 3-year tool that we paid for that never got used.
What was your lessons there? Oh man, I had buy-in for this one. All the appropriate teams that were part of the proof of concepts and we We did real— it was real-life POCs with the vendor and everything worked. Then we bought it and when it came time to actually implement it in prod, no one trusted it. Even the guys that worked on the development pieces to get it customized to work in the POC.
Was there concern just availability? It wasn't going to run when they needed it to run? It was— it may have been some of our application stacks that we were hoping to solve. And in hindsight, we may have sold it as this overall solution that ends password management, and the guys that were supposed to implement it for their tools, they had a certain stack in mind, and we never actually tested with that stack. And web methods, I'll mention it, it's web methods, and it didn't work.
So because it didn't work for the problem child they wanted to solve, they decided it wasn't for anything else. Why bother? Yeah, I want to solve that problem, but they're all tools. Yeah. So, and really, I think, you know, one of the things I experience at Ping and at Pulte and Harland, other places I've been, is if you get your purchasing in front too early in the process, you doom the project, right?
I think we— that's what I've seen. If I buy a tool before before I have buy-in on the implementation plan and the yes that I'm going to give you resources. There's this lack of— there's this presumption by me that I'm gonna get those things, and I think there's a little— people don't appreciate that, right? Yeah, I agree. I need to make sure procurement comes rightly at the very end, and I work pretty hard on that because, you know, we were talking about it today, you know, and end of quarter, when you get to the end of quarter, vendors push pretty hard to close a deal.
And hey, I'll cut that price, you know, by 20%, but it's only good till the end of the quarter. And they push hard, and it'd be tempting to say, yeah, I'm pretty sure we're gonna buy that solution, and why not take this killer deal? But I think it's not a good thing to have it in pocket as you go have the conversation about, do you have capacity to help me implement it? Right, right. Well, one thing that I've learned recently is for these, for the larger tools, because we're talking, we're talking to over 20,000 people at Dish.
For these larger tools, we'll just buy a very, very small set of licenses, POC, and do an extended pilot, right? Right. That way I'm buying it, the vendor is not necessarily happy that I didn't buy 22,000 licenses. Yeah, but I bought 5 and we could try it, see if it works. If it doesn't work, then not a lot of investment gone, gone bad.
You mean 5,000 or 5 licenses? No, it's usually around 100 to 5,000 depending on what the tool is. You need a good sample set. Yeah, right. So let's, let's talk about, you know, current day.
What is in, you know, your 2017, 2018, what are you— what is it you're gonna try and accomplish? Where are your ways that you can improve DISH's security or risk posture going forward? Yeah, so one of our— well, email security is top of mind. Sure. We— most of our attacks these days are through email, and, uh, it doesn't require much sophistication to do those attacks, and they work.
It's amazing. It's amazing all the companies that are out there that fall for these W-2 scams. Yeah. So just kind of, you know, having proper hygiene on the, on the email is, is definitely top of mind, but also improving our data. So we have a lot of different data sources now going into our SIEM, and we want to use the SIEM for more automated threat intel and correlation.
But if the data is bad, or if we're missing some of the data, then we're not getting good data. So I'm really focused on improving our data going into the SIEM. Enough so that I'm hiring, I'm hiring 2 people to do that. Is that data scientists? No, it's more of a data architecture than data science.
I'm not asking them to analyze the data. I'm asking them to make sure the data is pure. Yeah, that makes sense. Okay, so, you know, I think we met maybe 2 years ago. I feel like it was at Avanta 2 years ago.
No, it was longer than that. 3 years ago? It was out in Baltimore. Was that Gartner? Oh, we met at Gartner.
Yeah, I think I think you were stalking me. I was actually talking at Gartner that year. It was 3 years ago? Possibly, yeah. So you're sort of involved in the Colorado security community.
Why don't you talk about what you do around town and where you're engaged? Yeah, I'm trying to get more and more engaged. I keep getting these oddball projects thrown at me that take up all my time. I was doing Ivanta for a little while. Yeah, you were on the board.
For Avanta, wouldn't you? Yeah, I was on the board for a couple of years. Did you do SecureWorld too? Do I remember that? I think I was supposed to, but I couldn't make it.
Okay. And that's kind of how things happen, is I have every intention of going, but something flares up at work and I can't get out. So I'm trying to get back into that space, and I'm not there yet. Yeah, it's hard to find free time, right? Yeah.
It's always a challenge for all of us. I want to do more. I want I want to have a group of people that can get together and share ideas and help maybe smaller organizations achieve their security needs. I don't think that we need to rely on vendors for all of that. I think we can help that way, and I want to do that, but I'm not sure what the right venue is for that.
That's interesting.
You're going to be on the panel at RMISC coming up in May. You're on the Colorado CISO panel that Alex Wood's gonna be moderating. I think that's the Thursday morning, like 11 AM, something like that, 11:20. We've got, you know, yourself, we have Sarah Griffith who's the CISO for Euronet, we have Nancy Phillips, the CISO for Datavail. I'll be on the panel and Dale Drew, the CISO over at Level 3, is going to be on the panel.
So we should have an interesting group of folks to talk about what we're doing in security, kind of a mix of the larger enterprises, you know, with you and Dale. And Euronet's also large, although not headquartered here in Denver, and then a couple smaller ones with Nancy and myself. Yeah, so that should be fun. Well, you know, what else do you want? Anything else you want to talk about for the Anything you want to share?
I don't know. Going back to what I want to do. Yeah. How can we build that? Yeah.
The— well, who do you want to talk with? You want to talk with people who are running those security groups or security departments or you want to talk to IT people or who do you want to talk to? I want to talk to people who want to build an effective security program and don't know where to start. So it's not, it's not necessarily a consulting gig, but there's some lessons learned, right? Start here.
Build, build an information classification program first, right? Is that the first thing you do? That's the first thing I did. How do you, how do you talk about data if you don't know how to classify it? Interesting.
So we didn't have, we didn't have a program at DISH. Yeah. So that was the first thing that we had to do was define what What was public data versus private data versus restricted data? What's sensitive? You have to know what's important, what's worth protecting.
And then you socialize that and you start talking about, well, do I have any sensitive data that's exposed? And that's been a big effort of ours over the past probably 4 years is defining what DISH data is. Those are in quotes, air quotes. DISH data is, and what protections need to be on those things going— as that data goes from party to party, like a third-party processor. So I'm just thinking about your question about how do we build something that's to help folks who need to know where to start.
I think generally, you know, my own involvement with ISSA and all the other, you know, there's CSA and ISACA and OWASP, all these groups in town, they really— we kind of preach to the choir. We're talking to security professionals about how to do security, which makes perfect sense because that's who cares the most. But that's not what you're talking about. But coming into this field, I'm thinking about myself back in 2010. I didn't know where to go.
I had to go to vendors to get any kind of advice. And then do you even trust the advice, or do you solicit enough advice that you kind of aggregate the advice and make some heads or tails out of it? Yeah, I'm trying to think of one. And if I were to go to one of those organizations, I would feel like a fish out of water. If you were like to an ISSA type group?
Yeah, I wouldn't even know where to start.
So it's the introduction to security group. It really feels to me like you don't want to market a group like that to security people. You want to market it to IT people or maybe even business people. To business people, yes. To your— to the board or CFO, CEO groups.
Sure.
It wouldn't be hard. Honestly, the content would be really pretty easy to put together, right? Because it's stuff that we just know, right? Yeah. And it wouldn't be that hard to find those groups.
I've actually had the chance to talk to a couple of those, but it's all been ad hoc. There was one last year that I got asked to talk at a business group that met at the Cable Center at DU. It was a bunch of small business owners and the CFOs of those groups and talked about, you know, the fundamentals of starting your security program. Right. So that— I already created that content from my perspective and I delivered it to 2 different groups.
And I think Alex has given a similar talk once or twice. But the question is, how do you find— how do you recurrently find those avenues? Yes. To talk to those people. Yeah.
And kind of market the interest levels, right? I participated in an exercise. It was a hackers and defenders kind of exercise. It was interesting because I was one of the few security people in the exercise. There were a couple of attorneys, a CIO, CFO, that sort of thing.
These guys didn't know anything about the whole exercise. They didn't understand it, and it was kind of interesting standing aside and watching their reactions as they were picking and choosing how they were going to battle each other. And those are the people that you want to talk to. Yeah, I mean, there's the Colorado Technology Association. Yes, that's a good one.
But even that group has a pretty decent foundation of security, right? It might be a good place to start. They do now. But they're, they're still, they're pretty technical, right? They're gonna, they're gonna understand the fundamentals.
I'm not sure where you go for the, for the non-technical business folks who we both need to talk to. Yeah, that's a, it's a good, it's a good conversation. You know, for those who are listening, you know, send a note, send a note to, you know, info@colorado-security.com with, with your thoughts, suggestions. I'll make sure to, you know, to help plug you in with John and we'll hopefully find a way to start, start doing something like that. I mean, we've been there and done it.
Yeah, right. It wouldn't be too tough to find the content, and I suspect that it'd be a pretty big value-add. So a couple more questions before we call it an interview here. What kind of advice do you have for those who are looking to get into security? You know, someone who you might want to hire in the future, or just, you know, hey, I think security sounds cool.
What do you tell them they should do? Well, I can't help but think about my first pet peeve. So in an interview, when I'm interviewing a new junior-level candidate and they tell me they want to be a hacker, yeah, I can't stand that. Everybody wants to be a hacker, right? I want defenders.
I want people that are willing to look through data and try to find ways in which we're exposed and to help us defend, right? And nobody has— there's no glamour in that, but that's, that's really we need. That's where you're adding the value. Yeah, and start at the ground level. Look at the basic, like, you know, help run a SIEM.
Sure. That part is a very good intro level to security. Yeah, and you can get that experience, you can get paid for it. Go work for Alchemy Security or DB Protect or InteliSecure, who are, I think, generally looking for— those are local MSPs here in town, generally looking for people who are either entry-level or very close to entry-level and they'll train you. They'll train you, spend a couple years there, hone some skills, and then go to an enterprise and help them out.
Right, that's great. We need help. What about for other people who are maybe not quite in your position but where you were a few years ago? Someone who's been running a security program for a little bit, they're looking to get to the next level. What do you think that they need to do to differentiate and add value to their organization in a way is going to advance their career?
Yeah, I think they need to look internally. Most often I think the gut reaction is to look externally. They need to look internally, pretend like it's a brand new job, go do those interviews, go figure out what's broken, and during that time you market yourself. You've got to market yourself and show your worth, and that way you can come back, and if you do this on a regular basis, you can come back and you can say, hey, look, I've demonstrated this. And I've seen people do that internally at DISH.
To me, me where I had a low opinion of them a couple years ago and they've kept coming back to me and talking to me and demonstrating what they've done and it's like, wow, you know, you're actually doing it. And of course you're mentoring them too along the way kind of in an ad hoc fashion. And if you have enough time with that individual and they do that, then that's— those become your people that you want to have on your team. Yeah, and I would just add to that, when you do those interviews you know, this is, this is very valuable face time. You don't want to look like an idiot.
You want to, you know, if you're going to get time from whoever it is, whether it's a, you know, a senior executive in your company or a peer, when you ask for their time, show up prepared for the conversation. Don't cancel on them. Don't be late. Just take advantage of this time to have that right. Be a few minutes early.
Yeah. Be polite. Don't you, don't you go Um, this is an interview. These are all, these are all interviews. Every interaction you have is an interview.
Yeah. Well, that's, that's all I had for you. Anything else you wanted to chat about here, John? No, but I appreciate the opportunity. This is fun.
This is fun. My hope is, you know, we'll get, you know, we'll get together with you in a year or so. We'll see where you've gone in the last year. Update us on your, on your journey. And might be 2 years.
It's not, it's not that adventurous. Well, we'll see how things go. Okay. All right. Well, thanks again.
And this is, uh, This has been another Colorado Equals Security feature interview, and we'll talk to you guys next week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.