All episodes

Cal Fussman

Apple Podcasts Spotify SoundCloud

In this episode:

Feature interview with Cal Fussman, Writer at Large for Esquire Magazine. News from Optiv, Websense, LogRhythm, and startups and STEM in Denver!

Starting it Up in Denver

This week Robb is on vacation and we have Drew Labbo as guest host with Alex. We discuss a couple blog posts from Optiv and Websense. LogRhythm wins a Best SEIM award from SANS. There are more STEM jobs than job seekers in Denver and Denver is an up and coming area for startups.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Cal Fussman is a New York Times bestselling author, writer-at-large for Esquire Magazine, keynote speaker and corporate culture consultant. As a writer for Esquire, GQ, Sports Illustrated, ESPN, and The Washington Post Sunday Magazine over the years, he has transformed oral history into an art form, conducting probing interviews with the icons who’ve shaped the last half-century of world history, including: Mikhail Gorbachev, Jimmy Carter, Ted Kennedy, Quincy Jones, Jeff Bezos, Jack Welch, Robert DeNiro, Al Pacino, Muhammad Ali, and hundreds of others.

Local security news:

Job Openings:

Upcoming Events:

This Week's Events:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript8187 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for April 10th. This is Alex Wood, and I have a special co-host with us this week.

Welcome, Drew Labbo. Thanks, Alex. Great to be here. Thanks for having me. And Robb, hope you're having fun wherever you are at.

Robb is on vacation this week, but he should be back next week. So Drew is filling in. Thanks for having me. You've been up to anything interesting, Drew? Let's see, busy consulting.

I left Denver Health. I think you had mentioned that on previous podcasts. I've been consulting full-time since March 3rd, and it's crazy busy, which is a great problem to have. Other than that, work hard, play hard. Nice.

How about you? We are Facebook friends, and I did see the other day that you were doing some work on the ski lift in Breckenridge, so that's always positive. I actually was. I was responding to emails and I had a couple phone calls on the ski lift, so I was working from the Breckenridge office. So it's a nice way to work.

Very nice. I've been keeping busy as well. Actually was on an RSA webcast last week that went really well, so that was exciting. But other than that, things are going well. So Uh, let's get into it.

So news for this week. Uh, the first thing we have, uh, there was an article in the Denver Post about STEM job openings. So, you know, STEM is science, technology, engineering, and math. Of course, uh, IT and cybersecurity fits right in there with STEM. And the gist of the article was that there are lots of STEM jobs out there that are unfilled.

So in Colorado there are approximately 15 jobs for every person in the STEM field, which is pretty incredible. I think that, you know, beyond that, there were some other numbers for other states that were even more incredible. But I think it just goes to show how exciting and how happening, you know, IT and other technology fields are. Yes. Geeking out a little bit on some of the numbers, I was noticing that nationally there's a 3 million number job shortage.

So we're, we're less that many resources. And North Dakota apparently has 87-ish jobs available per worker in this field. So if you like North Dakota, sounds like it could be lucrative. Does not surprise me that North Dakota is a little short on workers. Yes, I had to visit up there one time for a previous job, and it was while very beautiful in places, not someplace that I would probably like to live.

Was it during the winter? Yeah, it was, uh, it was late fall. It was a little chilly. I can imagine. Uh, yeah, very interesting.

Excellent. So, um, this is pretty interesting. Normally we, we might not be too excited about a blog post. Um, however, uh, apparently Webroot, they're a Colorado company, they've been having some potential spoofing. So people calling people um, customers trying to say they're from Webroot but they're not really.

Um, and I thought it was interesting that they wanted to warn people about this, particularly with them being in Colorado. And, um, I've— I think we all have to remember, let's be vigilant if we get unsolicited phone calls, especially security guys. Um, quick story, I had a CenturyLink guy call unsolicited to help me with my internet speed at home. I was very interested. I said, hey, I'm a paranoid security guy, I'm gonna have to check this out.

So I spent a long time vetting that. I made some phone calls I found out it was legit and worked with the guy, and he, he was patient. He said, I understand why, and I understand why you're doing this. He didn't get frustrated. Um, and I think, I think it's always worth vetting if you get an unsolicited call, or just ignore it, right?

Yeah. For me, if I answer the phone and there's any hesitation at all between when I answer and when the person on the other end responds, I immediately hang up. I know there's also some, uh, some scams going around where people are trying to record you saying certain words so that they can use that as proof, you know, quote proof that you, you know, bought services from them or other things like that. So, um, I think it's, it's good for all of us to be aware of it so that we can make the, the non-technically literate folks that we know aware of it as well. Yes.

And then, um, I'm always obviously excited about this topic. I actually have received multiple phone calls over the years from security companies or technology companies, and They'll say, hey, we're doing a survey. Um, what operating system do you use in your environment? What are you using for SIEM? And I'll very quickly say, I don't take unsolicited calls.

I don't know who you are. Uh, but it, it kind of boggles my mind. It's probably a marketing person that's not thinking about security, right? But for a security company to be calling people unsolicited and asking details, they might want to think about that for sure. Uh, next on the list, uh, there was an article from Axios Talking about the top startup hubs in the country.

So, you know, I think we all think of, you know, Silicon Valley obviously is the startup area in the country. I had heard for a while that Boulder was number 2 behind Silicon Valley, but this is talking about, you know, sort of the top 10, you know, up-and-coming. So Denver was number 3 on that list, which is pretty cool. Washington, D.C., Atlanta were in front of us. But then also some other cities like Salt Lake, Portland, Dallas, Raleigh-Durham, and Worcester, Worcester, Mass.

I was— you said it right. Awesome. But basically, you know, it's Boston, just outside of Boston. And Philadelphia was last on the list. But it is really cool to see that there's all these places that are out there that have startup activity.

Absolutely. And it's great Denver's on that list. And shout out to Salt Lake City, right? Yes, real close. You know, we've got a ton of startups here in Denver, uh, you know, Ping, um, Red Canary, uh, we interviewed, uh, Scott Chasin from ProtectWise Cyber, all kinds of stuff just downtown.

So it's not surprising to me that, that startups are, are big in Denver. Yeah, and I also think about ThreatX, Managed Methods. It's really neat to see these companies taking off and getting funding and doing well. So who knew our little cow town, the big small town, was going to be such a hotbed? Exactly.

Excellent. So next, I want to recognize LogRhythm. They won the Best of 2016 award in the SIEM category. Although when I read SIEM, it actually should be SIEM, but we all say SIEM. So congratulations to them.

They're going to be honored in Orlando, Florida, April 7th through 14th as they give those awards away. So SANS, I respect SANS, so it's good for them. I respect SANS a lot too. They have great training. My only hesitation with this particular one, well, first, full disclosure, you know, I am a LogRhythm customer, so I do think it's a great product.

But, you know, these awards came from essentially surveys of, you know, different folks associated with SANS. You know, they're touting the fact that these are people that actually use these kind of tools, which I think is great. You want to have people that know these tools to evaluate it. But if you're somebody that's working in an enterprise and you're a LogRhythm customer, you're probably not going to know how well the other tools in this category work because you're a LogRhythm customer. Granted, I think it sounds like all the people that use LogRhythm like it and hence voted to have them get the award, which is great for them.

But I'm always just a little suspect of that, that sort of survey data for things like this. Yeah, that's some good insight into how they do that. And on one hand, I suppose it's better than not winning that award, but Exactly. I'm with you that, yeah, it's— if you're talking to everyone that's drinking the Kool-Aid, what else are they going to say? One thing I notice when I see what LogRhythm's focusing on, what they say they focus on, it's user and enterprise behavior analytics.

So there was user analytics, right? UAB. And now I'm seeing this other term of really merging in what else you see on your network. So I think it's interesting to watch the space develop. Yeah, I think that that is really sort of the next step where all these sub-vendors have to go.

Um, you've got sort of a separate category of, of products that just do user analytics, which I think is great. But if I already have this product that I have in, in my enterprise, it's collecting a lot of the same data, well, why shouldn't it do that user behavior analytics as well? So I think the, the, the SIEM vendors that start to build this in like LogRhythm is doing are really going to get a leg up on everybody else. Uh, so the next thing we had Um, on the Optiv blog this week, they had a, a post about third-party risk management. Um, I think that third-party vendors, it's a really big space.

Um, you know, being in the financial services industry, um, I am regulated, um, and have to manage third parties. You know, it's something that I have to do, but, um, a lot of other people don't necessarily have that, that same regulatory pressure. Um, that said, I think it really is one of the most important things that you can do. More and more, we're giving Um, we're either dependent on vendors for, um, specific processes that our business needs to run, or we're giving lots of sensitive data to third-party vendors because they perform some business function for us. So I think it's really important to make sure that, that you are really looking at the risks that are associated with third parties.

Um, they offered a couple suggestions here, you know, just that you, you know, understand the principles around testing and third-party management. And then, you know, second, make sure that your third-party risk management program runs in sync with your overall risk program, which I think is great. You know, these shouldn't be 2 separate things. Third-party risk management should be a, you know, a subset of the other risks that you look at. And then the third point was maintaining focus around these assessments, and they really gave 3 sub-bullets to that.

One is looking at risk assessment, of course. The second is contracts. And I think contract is really, really important when you're dealing with third parties. You know, we have a specific security addendum that we give to our third parties, and we use that in most of our contracts unless they have some better language that they've already given us. And then the last one was around incident response, which I think this is probably the best point that I picked out of the whole article.

You know, I think incident response is obviously really important, but we don't often think about how it is we would do incident response if we have a third party that breaches our data. We just went through an exercise in my organization to test our incident response process. Of course, the scenario we came up with was an internal breach of data. I can't think of a time when I've gone through an exercise where I've said, oh, hey, a third party breaches our— or is breached and leaks our data, and what do we do about it? These are great points.

If you think about this recommendation that's around the lifecycle of a vendor, So not just when you're kicking the tires, not just when you sign a contract, but while you're using it. And also when you decommission. I've seen situations where when an organization has not thought about it, a contract is not clear, they decide, okay, we're done with the system, not renewing our contract, and can we get our data back? Um, if we have equipment with our sensitive data on it and they— we have to give it back, can we get that data off before we send it back? And, and a lot of those situations are an unpleasant surprise.

If you don't think about it up front. Yeah, or something like a software as a service where, you know, hey, can I get assurance from you, some sort of proof that you have deleted my data from your systems? Um, you know, in the case of something physical, yeah, you might be able to get it back, that'd be awesome. But in the something— the case where there's not something physical, how do you get the assurance that in their systems they no longer have that sensitive data stored? Absolutely.

And, and did they delete the data or did they remove it with a framework like NIST, uh, 800-88 to get geeky. I love quoting NIST. I can quote almost all of them, but it's really if they just delete that data or format a drive, that data is still there, right, until it's overwritten operationally. So, you know, if you pull a hard drive that's been formatted, you can get data off of it if you know what you're doing. So these are interesting points to think about.

Exactly. Something you definitely have to have in your contracts about how to either delete or get that data back. All right. So that's the news that we have for this week. Uh, let's move into our events.

So, uh, the first thing that we have coming up, um, on the 11th and 12th are this month's ISSA Denver meetings. So, um, of course, uh, lunchtime on the 11th is Boulder, evening on the 11th is in Denver, and lunchtime on the 12th is in the Tech Center. And actually, uh, this month's Tech Center meeting is actually at my office, so Um, if you're coming to the Tech Center meeting, I'll get to say hi to you. And thanks to Pulte for sponsoring. We appreciate that.

Or for, I should say, for having the meeting. Yeah, for sure. We appreciate that. Yeah. So, uh, this month we have, uh, Jim McKinney from Optiv talking about how to hack a train safely.

Um, it sounds like an interesting topic. Should be fun. Um, and then, uh, next, also on the 11th, uh, CSA has their April meeting. So, uh, they are downtown on the 11th. Um, looks like they are talking about enabling lifecycle management and operational control across multi-cloud deployments.

That's quite a mouthful. That is quite a mouthful, but it is, you know, a very germane topic. You know, how is it that, um, if you are in multiple different clouds, you know, say for infrastructure as a service, how do you manage all those and, and maintain the lifecycle of your applications through multiple clouds? Yeah, absolutely. And I, I have felt that pain point in previous roles.

Where we have data in the cloud and it's all segmented, right? It's all, it's all an exception for us. We have to, we'd have to manage that pretty closely. So I'm pretty fascinated with this topic to how do you do that, you know, and bring that together. Should be good.

So next we have the Colorado Technology Association on April 12th. This sounds like a neat topic, the quest for Colorado's next $1 billion exit. So they're gonna be focusing on lessons from Silicon Valley, You know, startups getting funding. I hope they talk about what to do after you actually get the money. I've heard some horror stories from people.

You start to lose control. So that should be a fascinating topic. It looks like it's by invitation only. However, I think if you get online and Google this CTA, Google this event, I think you can probably get in touch and get an invite. And I think even better, you could go to the colorado-security.com website and look at our event page, and there should be a link on the calendar for it there.

That's the better place to look, yes. Next, on the 13th at SecureSet, we mentioned this last week, Chris Peterson, the CTO of LogRhythm, is going to be talking on threat lifecycle management. That should be an interesting one if you want to get down to SecureSet. So those are all the ones that are happening in the, the next week, but some other events of note that are coming up on the 19th, the ISSA Women in Security Special Interest Group is kicking off. We've talked about this a couple times.

I think they're up around or over 100 people signed up for that event already. So I think that's really, really exciting. If you are a woman in security or interested in getting more women into security, I think you should definitely check into that and sign up. That is down at SecureSet and it should be great. Sarah Avery of LogRhythm is really helping to spearhead this.

I think that that's going to be a great group. Yeah, great traction they're getting very quickly. So I I think there's a need here in what they're doing, and I'm excited that they're doing it and that they're part of the ISSA Denver chapter. Along the note of special interest groups, ISSA has started to stand up some special interest group meetings focusing on industry verticals. We've done 2 healthcare events, smashing success, exceeded our expectations.

We really focus on security in the context of healthcare, so people around healthcare that work with healthcare or that want to learn more are attending these. Next, we stood up the financial meeting. We had that a couple months ago. Again, the turnout just blew us away. We had no idea there was this pent-up demand for industry vertical type things.

And then we're going to be standing up a government vertical. That's our next one. We're, we're doing— we're in the process of doing that. Stay tuned for more details, but that should be this summer. And then we will also toward the end of the summer have our next healthcare meeting.

So if you're in these industries or want to learn more about them Please join us. It's really neat because we talk about a lot of the business problems that we deal with and the resistance. So it's really neat. It's kind of different than just meeting a bunch of people that do security in general, right? People that are in your field, walk in your shoes, and understand the kind of crap we put up with in each industry.

Exactly. I have to say, I think that the, the financial services one was the best, but mostly that's because I was on a panel there. Of course. Yeah. Uh, and then one last plug under the events.

Um, of course, uh, we have to put in our weekly plug for the Rocky Mountain Information Security Conference. That is again May 9th through 11th. This is the last week of early bird pricing, so if you're gonna sign up, you should do it now so you can get the cheapest rate. Also, if you are not a member of ISSA or ISACA, I would encourage you to join prior to registering because members do get a discount on the RMISC registration. So go ahead and, and get over and do that as soon as you can.

Rmisc.org is the website. It's 3 days this year. It is 3 days. So we've got 2 full conference days and then 1 pre-conference training day. It should be awesome.

And last year I was surprised we had a gigantic auditorium full at the keynotes. It was really impressive. So it's great to see that turnout bigger and bigger every year. All right, so let's move on to our jobs for the week. So first on the list this week, Great West Life.

Um, they have a security architect position open. I know a, a few people over there, so I think that that would be a great place to work. Um, check that out. Yes. Next we have Red Shield.

They are a Kiwi company, they say, so I think from New Zealand, I presume. Or maybe they like fruit, or maybe they like kiwis. Uh, so they are— they have junior and senior cloud security engineer positions open. They're really focused on website defense. And I like to see this, they have junior positions open.

That's— we talked about the shortage of professionals. To have a junior position, kind of on-the-job training, and get someone in, I, I think that's a great approach. So I'm really excited to see both junior and senior positions open. Yeah, I agree. Uh, so next, uh, LogRhythm has an Analytics Copilot engineer job open in Boulder.

So the, the Analytics Copilot is a service that they offer. So if you have folks on your team that are inexperienced with LogRhythm, or you just need some extra help Essentially, this is a more seasoned engineer that, you know, you can get time from that will essentially sit in the copilot seat, you know, with your engineers to help them get better at using the tool. I think it's a really great program. And if you're a SIM person, it would be something to look into. Excellent.

Next, we have Boeing, a cybersecurity assessment specialist. So this is really going to be focused in the Satellite Systems Division. This is interesting. It says TS/SCI clearance or higher with SSBI investigation or higher clearance required. I don't know exactly what all those acronyms mean, but it sounds impressive.

If you think about Boeing, you think about Northrop Grumman, those type of organizations, you're probably going to need— I'm sorry, think about Raytheon as well, right? You might need clearance, you might get clearance. Pretty fascinating. I always wanted to be a spy growing up, so that kind of excites me when I hear about the clearance. Sounds pretty cool.

Yeah, I think generally we leave the jobs that require clearance off the list. Just because there are so many clearance jobs and so few people that are cleared that usually, um, there's a— those people get snatched up right away. But I thought that one looked really interesting, so put it on the list for this week. Uh, next we have a vulnerability management consultant with GuidePoint. Um, so if you are someone that enjoys vulnerability management, uh, you want to be in a consulting role, maybe do some travel, you know, work with different customers, this would be something to check out.

Excellent. Next we have the State of Colorado Governor's Office of Information Security Technology. They have a senior IT security analyst position open. I know Debbi Blyth really well, Trace Ridpath, Muhammad. I know a lot of people over there.

They have a great team. I'm actually also on the cybersecurity board for the State of Colorado, and it's a really neat culture. Debbie actually stands up a committee to provide feedback on what's working in the security program what's not working, what do they need to do better. They have out— they have internal and outside people coming in, and it's really neat to be part of that. And Debbie's done great things.

She's really run with it since she's been there. I know Jonathan Troll, she gives him credit for starting this off, and she's really taken it and grown it even from there. So I think that could be a really neat position. And it— they talk about compliance and audit management, risk and vulnerability management duties, and really being cross-functional and working with all the different types of business units and other technology departments. Awesome.

Yeah, and I know Debbie is a listener, so hi Debbie, uh, here's your shout out for the week. Um, next we have a senior staff security analyst with Charles Schwab. Um, Charles Schwab obviously building up a big presence down in the tech center. Uh, Jeremy Cooper-Leavitt, a friend of ours, is, is down there at Charles Schwab. Great place to work, so you should check that one out.

Next we have Comcast security incident response engineer. And working at a telecom can always be fascinating. Talk about a big shop, right? And exactly. And keeping that, keeping everything available.

So that could be pretty interesting. Yeah, there are actually a few Comcast jobs this week. So it looks like they're expanding their security staff here. Next, Kaiser Permanente, Director of Cyber Risk Defense. So being a former Kaiser employee, their Cyber Risk Defense Center or Security Operations Center, whatever you want to call it, is here in Colorado.

So this is a director-level role, you know, working in that area. I think that Kaiser is a really interesting environment to be in. So I think that that would be a fun job. Obviously know a lot of people over there, and I definitely would recommend it. And I'm impressed with how Kaiser has— and you know better than me— but how they've staffed up this risk function.

And I think a lot of organizations miss that. It's all about toys, technology, but to actually focus on risk with a big team like that, I think is pretty innovative. Did you find it that way when you were there? Yeah, you know, there was a lot of really good people and a lot of exciting stuff happening. So I think that you would not, not be bored going over to Kaiser for sure.

Always something to do. So last but not least for this week, we have at CU Denver an instructor in information systems position open. So Could be interesting. Yeah, I actually, looking at the post, this could be on multiple topics, but one of the ones that they listed in there was cybersecurity. So if you're somebody that likes teaching, you know, wants to teach at the college level, I think this could be something that's really, really interesting.

So those are the jobs for this week. Thanks again, Drew, for being co-host with me with Robb out of town. I'm glad that you can come and fill in. Thanks for having me. I appreciate you thinking of me and including me, and I really enjoy the podcast.

It seems like they're taking off. So thank you so much. Yeah, of course. And as always, check out colorado-security.com for more information on the podcast, events, organizations, everything else that's going on. And then up next, we have our interview for this week.

Robb sat down— well, actually not physically sat down, but talked with Cal Fussman. Who was one of our keynotes at Rocky Mountain Information Security Conference this year. Cal is a really interesting guy. He has had a column, I believe, in Vanity Fair for a long time, essentially interviewing the most important and interesting people in the world. So he has got a lot of insight that he's learned from these people, and I think that you'll be interested to hear the interview.

So again, thanks, Drew, and we'll talk to you all next week.

This is Michael Glenn. I'm Vice President of Security at CableLabs. This is Colorado Equal Security, for Colorado security professionals by Colorado security professionals.

Well, this is Robb Reck. I'm here with Cal Fussman. Cal, thanks a lot for joining me today. Hey Robb, I'm really happy to be here and I can't wait to Yeah, we have you coming to do our opening keynote on the morning of Wednesday, May 10th for the Rocky Mountain Information Security Conference. Cal, the first time I heard you was during a Tim Ferriss podcast a ways back, and what I was struck by was the great breadth of experiences you've had in your time writing columns and basically just getting to know a lot of interesting people.

Would you mind kind of giving the audience an idea of what you've done in your past? And, and how you got to be the famous guy you are?

Well, for the past 20 years or so, I worked on a column for Esquire called What I've Learned, which is strictly wisdom in the words of people who have shaped the last 50, 75 years or so, and includes folks like Muhammad Ali, Mikhail Gorbachev, Robert De Niro, Jeff Bezos, Richard Branson. The list goes on and on. There are about 400 people, and I would sit down with them for about an hour and a half, 2 hours, sometimes longer, and just get to ask them any question I want in order to extract the wisdom that they've accumulated. So it's been a pretty amazing run. And oftentimes the interviews have been more than interviews.

I got to know the people personally and got to become good friends with them. And I just learned an amazing amount about life just listening to these people.

Yeah, so my first question for you is how did you get such a fantastic job? That sounds like it must be one of the most fun jobs out there. How did you get there? Well, that goes back to a single moment on a single day. And actually, I'll give you the exact date.

It was November 22nd, 1963. And back then, I was— I just turned 7 years old, and I was sitting in my second grade classroom when the teacher, Miss Jaffe, got pulled away, and when she came back, she was whiter than a sheet. And everybody in the class just looked at her and knew something was up. And then she started speaking so calmly that it was almost scary. And that's when I found out that President Kennedy had been shot.

And so everybody in the school was sent home, and when we got home, we all found out that the president had been killed. And later on in the day, it was all anybody was talking about. We were all glued to the television, and we found out that Lyndon Baines Johnson, the vice president, had been sworn in as president. And that night, my parents called me over to the kitchen table because this really was the first time I had ever confronted death in any way, and they didn't want me to be nervous or worried or lose sleep over it. So they sat me down and they said, look, Cal, this has happened before in our country's history.

We want, we want you to know that the country has a system, and you've seen it at work. New president's now Lyndon B. Johnson. Tomorrow morning when you get up Everything is going to be just like it was this morning. You're going to have your breakfast, you're going to go to school. We want you to get a good night's sleep and, and not worry about this.

So they left the table, and I'm sitting at the table, and I'm just thinking, this guy Lyndon B. Johnson, the new president, I'll bet you he always wanted to be president. And then I'm thinking, I wonder, I wonder how he feels, because he's probably happy to be president, but how could he be happy becoming president after the assassination? Maybe he's sad to be president, or maybe he's scared to be president, because maybe he thinks they're going to try and kill him too. So I'm sitting at the table and I'm thinking, man, I wonder what this guy Lyndon B. Johnson's thinking. And I couldn't wrap my hands around it, so I picked up a piece of paper and a pencil and I wrote, Dear President Johnson, how does it feel?

And I filled out the letter with all of my thoughts, wondering what was going through his mind when he took the oath of office. And then I folded the letter in 3 and stuffed it in an envelope Addressed it President Lyndon B. Johnson, the White House. Licked the stamp— we still licked them back in those days— and put it in the top left-hand corner, put my address on it. And next morning I went to a mailbox and dropped the envelope in the mailbox. 2 days later, I had completely forgotten about it.

I was 7 years old and didn't think anything of it. Until about 5 or 6 months later, it's May, and my mom comes breathlessly running up the steps to our apartment, and in her hand she's got a letter. It's addressed to me as from the White House, from the president. And everybody's going crazy, like, president of the United States is writing Cal a letter. And it was an amazing thing.

It came from his top executive assistant, Juanita D. Roberts. And there were 2 very cool things about it. The first was that it wasn't written to a 2nd grader, even though they obviously knew I was a 2nd grader. You got the feeling that she read my letter and walked into the president's office and said, like, what do you want me to do with this? And so she wrote me back, like, with respect.

And I knew that because the second sentence began, in answer to your query. And I said, I don't know what that means, but it sounds like I'm pretty important. So the other thing was that there was a misspelling in it, which told everybody that, man, this is really authentic. Uh, this isn't a letter that's getting copied and sent out to everybody. So now the principal's inviting me to school to show everybody the letter.

My mom and dad's parents and their friends, everybody's coming to see the letter. And I learned in that moment the power of a question, that with a good question I could reach the most powerful person on earth. And that was sort of the start of a long journey that took me first to newspapers, where I was a columnist for a while in St. Louis Post-Dispatch, very briefly, and then traveled around the world for 10 years without a home and learned to interview people even when I couldn't speak their language. And that took me to Esquire magazine, where I took this skill of meeting people and getting them to trust me into interviews with some of the most powerful, talented, and compelling people on earth. So that sort of got me to the place where I could sit down with Richard Branson or Woody Allen or George Clooney or T. Boone Pickens, and it all goes back to that moment.

And what I, what I really take from that is the simplicity of just being able to quietly sit down and ask yourself a question that can push you out of your comfort zone or put you in a better place, no matter what your job is. And in the last year or so, I've started speaking about this, and it's been an amazing experience because I didn't expect this to happen, but I was invited on a cruise ship filled with entrepreneurs, and it was also filled with big-time speakers. And I went up to speak thinking that maybe 17 people on the, on the boat would show up, But the person in charge had a pretty good idea. They advertised my speech along with happy hour, so there was free wine and also tales of my meetings with Donald Trump and Mikhail Gorbachev and Muhammad Ali. So when I got there, there was like a packed house, and when I got done, there was a standing ovation and a long line of people to see me afterward.

And after that, people who were there started inviting me to speak, and then Tim Ferriss heard about me and he invited me come on his podcast, and then more people started inviting me to speak. And so now I find myself going as far off as South Africa, or over to Facebook, or General Motors, and just talking about the power of basic questions to change our lives for the better. And I can guarantee you that when I come to Colorado, I'll be able to tell some stories that will make the people who are sitting there laugh, maybe probably tear up at times, also want to take a few notes. And when they walk out, they'll be seeing their lives and their work a little differently.

That's fantastic. So, Cal, you've— have you— obviously you're not a cybersecurity expert. Have you had any experience, any thoughts? What makes you interested in talking to a group of security guys and gals, of course? Man, I need you!

You know what, I'm just kind of getting into the whole internet revolution here, like 20 years late. And the interesting thing about it is that you could say, well, what do you have to say to people who work on the internet? And yet, because I look at it almost as a blank slate and I don't assume anything, when I start to talk to people who work in the internet, it always produces great conversations because I'm not saying what you're expecting to hear. My questions aren't the questions that you would expect to hear. There's something to be said for coming in with absolutely no idea.

And you want to— I'll tell you a little story about that, because when I worked at Esquire, they liked to have a lot of fun with me, because this is sort of my— the way I go about life. When I traveled around the world for 10 years without a home, every morning I woke up, I didn't know where I was going. I didn't know who I was going to meet. And I didn't really have any money to stay in hotels. So basically I was counting on my conversations with people to basically get me invitations to their homes because I didn't— I really didn't have enough money to put a roof over my head every night.

And people started to invite me in their homes, and then they started to pass me around, and that's how I got around the world, passed from dinner table to dinner table to dinner table. And so I go with a sense of a blank slate, and I'm really interested to hear what people have to say, and the conversations tend to be refreshing. And I'll tell you a little story because the Esquire knew that this was kind of my forte. So it was— I don't know if you know the actor Gerard Butler. He's, um, he was in the movie 300.

So basically what the editors at Esquire did is they promised Gerard a cover story, and then they called me up and said, Cal, we'd like to do a little story here. Uh, it's about a guy named Jerry. I said, oh yeah, like what's his last name? Oh, that doesn't matter. We're just going to give you his address and just go over and, you know, tell us what happens.

Just take a few minutes. It'll, it'll be, you know, a little story. And so I'm thinking, I don't know what's going to come of this. I, I drive over to the address they give me and it's, it's a beautiful house. I say, wow, this guy must be pretty important, this Jerry.

And I have no idea who he is. So I go and knock on the door, and Jerry comes out. Now Jerry is expecting me to be the writer from Esquire magazine who knows his entire history, and I have no idea who he is. And it was a very, like, funny exchange because he couldn't believe that I didn't know who he was. And so you're bluffing the whole time.

Yeah. Oh yeah, he's thinking. And here's the thing, I didn't even know like he was an actor. It took me like 20 minutes because I started asking like, well, where are you from? And he starts telling me about Scotland and we're going along and it's only like 20 minutes in that he mentioned he's an actor and As he's saying, and he's saying, oh man, I can't believe you don't know that, like, I'm being set up here.

This is just ridiculous. But he, like, he's going along with it. And the funny thing about it is, after maybe an hour or so, I, I said, you know, do you got a restroom around here? He says, sure, use my restroom. It's in my— right next to my bedroom.

And so he starts walking me over there, and as on the way, we pass on the bed stand, nightstand, an issue of Esquire. It had Megan Fox, the actress, on the COVID And he says to me, can you believe it? Like, you get Megan Fox on the COVID Why would they want me? And then I said, oh my God, I'm writing a cover story about this guy. I had no idea.

So the best thing about this, in this issue with Megan Fox on the COVID they have the 75 movies that every man should see. And so later on, when we start talking again, I say, okay, Jerry, like, what, what movies have you been in? And now he's really like, I know this is a setup. And he says, well, like, of course you've heard of 300. And I said, no, like, I never, I never— oh, oh, hold it.

I never saw it, but I remember passing a movie theater and there was this poster. There was this kind of gladiator with a beard and he says, that was me! And so he says, look, Everybody knows that that's one of the top 75 movies a man should see. I guarantee it's in that magazine. So we get out the Esquire and he's going through the first page.

He's, oh, these are pretty good movies. He gets to the second page. Am I allowed to curse on this podcast? Yeah, if you want to curse, you may curse.

I'm just, he's turning the pages and he gets to page 2 and the movie's not in it. There, he gets to page 3, fuck! Page 4, fuck! Page 5, fuckers! And he gets to the end and now he's screaming because he's not only did the writer not know who he was, but his iconic movie is not listed.

And then I said, well, all right, Jerry, what else are you in? And he says, Phantom of the Opera. And I said, you weren't in Phantom of the Opera, you can't sing.

And at the very end, it was, it was really comical because he's like trying to prove to me he, he was who he is. And at the very end, I'm leaving, and I don't know if he thought that he really had proved who he is to me. And so I'm like, as I'm walking out the door, he's got this stereo system through his house And all of a sudden, the music just starts blaring at high volume. And it was music from Phantom of the Opera. And he comes down the steps and he starts singing along to his own voice to prove to me he was Gerard Butler.

So my point on all this is I am not coming here as a security expert, although, hey man, I walked the rubble of 9/11, like, 2 or 3 days after. So, I understand the importance of what you all do. Make no mistake about that. You know, I sat with Mayor Giuliani shortly afterward for a cover story for Esquire. So, it is not like I am coming in here and do not understand your importance.

But I'm coming in sort of like a fresh breath of air. It's almost— if you want to, if you, if you would think of hearing music for the first time that you really like, that's kind of what I'm hoping to be. Maybe people have no idea who I am and they're going to sit down and then all of a sudden they're going to start to hear stories that Are you going to make them open their eyes or laugh or cry? I tell a story about spending a week with Muhammad Ali. And at the end, you walk away, I hope, with just some thoughts on taking your own questions and using them to solve dilemmas in your own lives.

Yeah, I love your— the fundamental of what you're saying is you have to be asking the right questions, right? I think that's— you're gonna help us ask those questions. I'm looking forward to that. Yeah, I mean, that's the thing. You don't need to be a— like, have a detailed knowledge of a subject in order to get to the right question.

You need to know how to get to the right question. And so that's, that's where, where I can help. It's sort of like Einstein said, if I had to solve a problem and I only had 10 minutes to do it, I'd spend the first 9 minutes thinking of the right question, then the last minute to come up with the answer. So that's how I'm coming at this. That's great.

So what can I— what can our listeners do? You know, I, I know I'm really excited. What can I do to be prepared for, uh, for your talk and, and in May. Is there anything we can do showing up, you know, certain mindset? How do you want us to show up there to your keynote Wednesday morning?

Best preparation is probably no preparation at all. Just come with an open mind. But, and so it's not preparing for me, but if there are certain questions that you have in your own lives, in your own business. That would be good to come with because after I speak, we'll do a question and answer. And I really find that the Q&As bring out an amazing benefit because I'm able to use stories that I've heard, wisdom that I've accrued, from these remarkable people to answer personal questions.

And oftentimes, like, I find the question and answer session equally, if not more fascinating than the keynote. And certainly for me, I'm learning a lot through the questions that come asked at me. And I really am very interested to hear get a glimpse of, you know, the questions that people in the field of security have. Yeah, so coming with questions is the best preparation. Outside of that, just come ready to have a good time.

Sounds fantastic. Well, Cal, I want to be respectful of your time. Do you have anything final you want to, you want to leave us with this afternoon? Well, I imagine that May 10th in Rocky Mountains is going to be a gorgeous day. Yeah, that absolutely— it sure should be.

May is a pretty good month to be out here. So I can't— I, I'm really looking forward to, to coming out, blue skies, mountains, and meeting some interesting people with good questions, because what I've learned is And this is taking— this speaking is now taking me all over the world. I meet people and then we stay in touch and conversations keep going. So I'm really looking forward to pushing this as far as it possibly goes. This is not sit down listen and walk away.

Let's, let's build something here. All right, Cal, once again, thank you so much for your time, and we'll look forward to seeing you in May. All right, Robb, thanks so much. Thank you. Take care.

Cheers.

Learn more about the Colorado security scene at colorado-security.com, where you can information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes