All episodes

The Highlands Ranch High School CyberPatriots team

Apple Podcasts Spotify SoundCloud

In this episode:

Alex interviews the Highlands Ranch High School CyberPatriots team, Robb and Alex re-cap the best RMISC yet, and news from Xcel Energy, Ping Identity, LogRhythm, and a breach in Larimer County.

RMISC Recap - And meet some CyberPatriots

Ahhhh.... we made it. Last week was RMISC, the Super Bowl of security in Denver. This week we debrief about the show, share our favorite (and not so favorite) moments. If you didn't make it, you might want to tune out this week, as we're likely to make you depressed for having missed. We also discussed the curious case of a County Clerk in Larimer County who posted PII for citizens. We closed up the show with an interview with the Highlands Ranch High School CyberPatriots team. 

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Alex sat with the Highlands Ranch High School CyberPatriots team, who just returned from the National competition in Washington DC. They discussed the CyberPatriot team's practice, team dynamics, and what the future holds for the team's members. Congratulations to the team for their hard work and success. 

Local security news:

Job Openings:

Upcoming Events:

This Week's Events:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript8542 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to the Colorado Equals Security Podcast. This is episode 15 for the week of May 15th. Alex, are you recovered from the week?

You know, I'm, I'm feeling all right. Uh, you know, had a big kids' sport day today going and, and still some more to come. So that's taken a little bit out of me, but I think that I recovered from Rocky Mountain Information Security Conference. How about you? Uh, well, I'm, I'm, I'm recovering.

I'm recovered probably by now. We are recording one day early because tomorrow is Mother's Day. This will get released on Mother's Day, but, uh, we got this out of the way a little bit early this week. Um, you know, Rocky Mountain Conference ended on Thursday night. I was supposed to go out with Kristen to dinner that night, and we actually walked into a restaurant, sat at a table, and I realized I'm too tired to eat dinner at a restaurant.

I'm sure she loved that. Yeah, it was a little weird. So got up and went home and really just crashed Thursday night. Did you make it to B-Sides on Friday? Yeah, I made an appearance at B-Sides on Friday, hung out with the folks for an hour, hour and a half, got to say goodbye to a couple of friends.

One, Jacob Torrey, who's leaving, leaving Colorado and going out to Washington, D.C. Congratulations, Jacob. He's now a program manager for DARPA. That is pretty darn cool. Yeah, pretty cool stuff. And then Lance Miller, our friend who moved out to North Carolina, he moved out last year, but he came out for the conference and good to get to say goodbye to him as he goes back out to the East Coast.

Yeah. And I maybe recovered a little more quickly than you as I had to go to work on Friday, wasn't able to make it to B-Sides and, you know, needed to recover from the work-wise from the 3 days of being at Rocky Mountain Information Security Conference. So maybe that eased my way back into normalcy. Well, the cyber— the bad guys out there in cyberland didn't make it easy for us on Friday, right? They did not.

We had WannaCry, the new ransomware spreading all over the world. Is there a ransomware or malware name generation tool somewhere that people are using to come up with these? So hopefully, you know, that wasn't too hard for you on Friday. We have a relatively small Windows footprint, so not too bad for us to handle it, Peng. Yeah, and we're pretty much all Windows-based, so we had to— we didn't really have to scramble, but we had to make sure that we were covered, and I believe that we were.

So for those that haven't heard, this ransomware spreads partially through one of the vulnerabilities that was announced from the NSA leak. Um, it's an SMB1 vulnerability. So if you, uh, put in patch MS17-010, uh, then that mitigates the vulnerability. So you should definitely do that. Um, also being that it's SMB1, uh, you shouldn't run SMB1 if you don't have to.

And if you have to, um, you should limit its, its access, especially to the internet. Never have SMB open to the internet. Yeah. Good, good tips for sure. We'll have a link in the show notes to, to what happened here with this vulnerability.

It is big news. It made CNN's head front page. It was on just about every, every news site, local news, big news sites everywhere. And this is a good time for you to call up your mom or your grandma or whoever in your family may not be updating their Windows systems and get them to patch. Yeah, that's another great point for family members.

Make sure their Windows boxes are on auto-update. So let's go ahead and move into a recap of the conference. You know, we have a relatively small feature interview this week. We thought we could spend a little bit more time talking about RMISC and and really what happened this last week. It is, it is the big week here in Denver in security every year.

And it was a great conference like it is every year. Great attendance. We had a whole bunch of great talks being that we extended it by another day this year, had one full extra day of track sessions. Lots and lots of good things going on there. So kind of recap the keynotes.

We started off on Tuesday night with Jeremiah Grossman. Jeremiah talked to us about ransomware, but he came at it from kind of a unique perspective, something I had never heard of before. He compared it to the pirating industry, and pirating really is an industry apparently. And he dove in pretty in-depth about how the financial model behind Somali pirates works and what the— what the business model looks like there. Yeah, and then sort of the corollary to that was looking at kidnap and ransom insurance and how that has evolved because of piracy and the markets that are around K&R Insurance, which was really interesting.

And I didn't know some of the details around that. Essentially, that Lloyd's of London owns that market and all the data around K&R Insurance, which I think in this case is a good thing because they set the rules. So if you're kidnapped, you know, you can only— insurance can only pay out at a certain level. So there's no price inflation Right, around ransom demands, which I think obviously we want to keep ransom demands as low as we can. So that seems like a good place to have a monopoly for that to happen.

It's very, it's very interesting to see how the— see how that works. And then he had, you know, he drew the comparison to how ransomware works and how we're going to evolve a market there with insurance behind it and really business decisions being made. Do you pay? Do you not pay? And how do you get back at the bad guys?

After you pay. Very interesting stuff. Yeah. And insurance historically is one of the ways outside of regulation and legislation that habits in business are pushed forward. So seat belts, you know, in the car industry, you know, lots of other things like that really have come about because insurance required it.

So after Jeremiah's talk, we had the ambassador panel led by Anthony Fried. You know, just a good time for folks to disagree a little bit, have some debate up on stage, and share a little bit of industry knowledge. Tuesday night after that, you and I had the opportunity to have dinner with Cal Fussman, who was Wednesday morning's keynote. Cal is an extremely interesting guy. It was fun hearing the stories from all the people that he has interviewed, as well as him just asking questions.

He is definitely not a cybersecurity person or really even a technology person, So just hearing questions from a different angle is always really interesting to make you go back and think about how you answer those questions. Yeah, he really kind of challenged some of the fundamental assumptions we have around security. You know, he asked the question, what are you— what was the one moment or the one minute in your career that you're most proud of? And it's a hard question, right? Like asking an umpire, what are you most proud of in your career?

It doesn't work quite that way for us. And it really made me think about what does success look like and how do I judge it on a short-term basis? And I think that that goes from his perspective to the, the point what we heard in his keynote, which is asking quality questions, right? So, you know, he talked a lot about, uh, getting questions to, uh, to the heart, things that really make you, you know, you feel, and questions to the head, that, that questions that make you think. Yeah.

Um, and of course the first question that that he had out of the box was, you know, around the Mikhail Gorbachev story, you know, what was the most important lesson you learned from your father? Right. And that sort of led into his talk. It really makes me realize, in most of the times I am asking people questions, whether it's interviews or anything else, the low quality of questions that I ask them, you know, that a lot of the questions are just throwaway and, you know, may or may not get a good response from someone. It really makes you think that you should ask better questions.

So we do not have a recording of his keynote, but he has done a couple of podcasts. He did one for us a month or so ago. But if you want to get a lot more detail from Cal Fussman, you can look at the Tim Ferriss Show podcast. He has 2 different episodes on there where he tells a lot of the same stories and you can, you can learn a lot there. Highly recommend it.

It was the first time at RMISC we've brought in a non-security industry person. And I'd say, you know, I talked to maybe— I've tried to talk to 30 people so far, and I've had 2 people who strongly disliked it, and the other 28 loved it and really loved to kick off the conference that way. Yeah, I thought it was amazing. I would definitely hear him again. Obviously, we're not gonna have him back at RMISC ever, or if not soon.

But that kind of keynote, someone who is outside of the industry, I think can really bring a different perspective. Yeah. So we'll keep moving here. Um, uh, Wednesday was, was closed off by Andre Duran, CEO of Ping. Andre really talked about the evolution of security from the perimeter to discrete identity tokens and access zones.

Uh, do you have any thoughts about Andre's talk? I thought it was interesting how he tried to tie in, um, you know, physical and logical access and just all the places where you, you know, use essentially a different token to do something, whether it's you know, opening your car or getting into the office, and then obviously into, you know, getting in your computer and everything else. You don't really realize all of those access points because we use them all the time. Yeah. And then Thursday morning kicked off with John Kindervog.

John was the sole creator of the Zero Trust computing, Zero Trust networking model at Forrester. He talked a lot about what Zero Trust looks like and basically the idea of removing trust from your business, from your computer systems, and really trying to get to really granular, just-in-time access. And it was amazing to hear how much he is going about trying to espouse this. I think, what did he say? 90 days, 30 days, 30,000 miles, 90 days, 90,000 miles, some large amount of miles he's flying to talk to this principle at different conferences.

And the concept is really neat. I think it's where the industry is going to be going. I was a little disappointed that at the end of his talk, it devolved a little bit into him talking about Palo Alto, who he works for. You know, we try and keep these things vendor neutral, but it wasn't awful. Yeah, it is.

For those listening or those who attended RMIC, it is always a challenge to get purely educational content and try and avoid the sales pitch because there's a spectrum, right? There's all these people who submit talks who, who say that they're— they know they're just going to do trainings, but if they're pulling a paycheck from a company, it's, it's hard for them not to make a little comment for their companies. And I wasn't directly involved with much of the planning this year, but having done it in the past, I know we try our best to screen presentations and, and figure out what people are going to say beforehand, but there's just so much that you, you know, only so much that you can do. I, I am that directly responsible for any key— any sales pitches that got in there. It is the number one rule on my list is if it looks like it might be a sales pitch, say no.

But they still, they still get through. So anyway, after John Kindervogt, the governor, Governor Hickenlooper, was our keynote. And that was, that was really a neat opportunity for me to get to meet him for a few minutes before he got on stage and get to introduce him. Thanks so much to Debbi Blyth for helping us get his time. So the legislative session ended on Wednesday, and he was up till you know, after midnight dealing with the fallout from the legislative session, up early the next morning to come to go into work and then made it over to our conference.

Really appreciated that. You know, he talked a lot about the NCC, the National Cybersecurity Center down in the Springs, which was his brainchild based on the trip he had to Tel Aviv. And then he told some fun stories about President Obama and himself as well. Yeah. And I think one of the things he pulled out of those stories was that when he had asked President Obama what his biggest concern was.

President Obama had said cybersecurity was his biggest concern. He said, not North Korea, not ISIS, not Russia, cybersecurity and the potential impacts of a cyber war. Kind of interesting to hear the most powerful man in the world at the time more concerned about security than anything else. It was also interesting to hear that the president is, or former president was a bit of a pool shark. Yeah.

Yeah. Apparently the governor and president Obama played a game of pool together. And the governor had owned the Wynkoop Brewery and had played a lot of pool, he said, over the years. And he was a little nervous about should he go play all out and beat the president? And apparently he played all out and he got smoked.

Yep, exactly. There's a picture out there, I guess, of Hickenlooper paying the president $20 that he lost in a bet to him. So that's fun. Did you have any favorite sessions you attended during the conference you want to quickly mention? Well, I'll say real quick, we were both part of the Colorado CISO panel.

I moderated and you sat on it with some other folks, Dale Drew, John Everson, who's been on the podcast, Nancy Phillips, and Sarah Griffith. That's everybody, right? I'm not missing anybody. John Drew, Nancy, Sarah, and myself. Yeah.

And I think that was a great session. I got good feedback that people were were pleased and they liked the answers that people gave. We were all over the board a little bit on what we talked about, and that was fun, and a little play between Dale and Robb. I also listened to Mike Benjamin's talk, essentially a primer on threat hunting. So if you're someone that was new to it, talking about what it is, how to get into it, some tools to use.

And the best part of that, a lot of times people do an intro-level presentation like that, and we'll just talk about theory. Hey, you can do these things. Here's some tools you can use. He actually essentially built a lab at his house and used all these tools, validated that they worked, found insights on his home network and shared those through the presentation. I thought that was really great.

Yeah. Very cool. I didn't get to attend that one. The conference or the session I'll mention that I really enjoyed was Rafael Los's about how to build good requirements. The talk, the title didn't necessarily grab me, but the content was really quite good.

And it was really not starting your project until you understand the problem you're trying to solve and what success might look like. Even if you don't know for sure, you know, let's at least put together an MVP, a first draft of what success would look like, so we can have better requirements and better understand, you know, are we doing a good job with our security projects? Yeah, that's great. Also, you know, we had a bunch of school people, middle school and high school kids down for the Cyber Girl, Cyber Patriot activities. Yeah, we had, I think we had somewhere between 60 and 70 junior high kids come in.

That was really cool. We had 3 different sessions that they were encouraged to attend. The focus had mostly been on girls. And we had the women in security panel. We invited them to attend that.

And then we had the 2 Cyber Girls focus sessions, and it was really neat to see the, the youth being served at the conference this year. It was nice to see packs of, of children walking around at various places in the conference. Yeah, everybody that I saw was really excited about that. They were probably the, the only people at the conference who really enjoyed the video games that were in the expo hall. There was a couple vendors who brought video games, stand-up arcade games.

So the, uh, the conference did— we did go over 1,000 attendees this year. Fantastic. A big milestone for us and something we've been looking forward to for a couple of years. And again, a great, uh, exhibit hall. Lots of sponsors in there.

I think we were around 70 sponsors. Yeah, lots and lots of sponsors. And, uh, you know, of course, thanks to all those sponsors, um, this wouldn't happen without them. Yeah. Uh, the, the last thing to mention is— was the closing keynote, right?

We had Josh Blue, local comic. Actually, I think previously I said he's from Boulder. He corrected me. He's from Denver. He was born and raised in Denver.

He's still there. He came and did a stand-up show about an hour at the end of the day on Thursday, and the whole keynote room was just filled with laughter. It was, it was a neat thing. It was not PG by any means. Hopefully there was no cyber girls there at that point.

Yes, exactly. But it was extremely funny. A great way to close out the conference. Yeah. So, so that was RMISC this year.

You know, we'd love to hear your feedback if you were there. If you liked it, what did you not like? What did you like? Let us know, how did you feel about us having really 3 different speakers who didn't know much about the industry between Cal, the governor, and, and Josh Blue? Is that a trend you guys want to see in the future?

Alex and I are going to be part of planning for next year as well, so we can definitely help out. With that, why don't we go ahead and move into the, to the news? Sounds good. The first is a story from the, the Denver Post this week actually talking about Rocky Mountain Information Security Conference, among other things. Yeah, we got some great coverage.

Tamara Chuang is the local tech reporter, and she talked to quite a few of our friends. Mary Haynes, a VP of security over at Charter, who is involved with the Women in Security movement. Debbi Blyth, CISO for the state of Colorado, also involved there and certainly involved with RMISC overall. There's a quote in there from myself. There's a quote from Don Mapes, the former president of ISACA.

Now Rick Lucy has taken over as president for the Denver chapter of ISACA. Sarah Avery, who runs the Women in Security chapter here, and then Jen Ferdo. And Jen is the new COO for the National Cybersecurity Center. And we should have an interview with her, with her coming up here in the next month or so. It's really great to see articles like that in our local newspaper, not only about cybersecurity in general, but about specific things going on here in Denver.

Yeah. Another local area coverage. Colorado has been named in the top 10 of what they call innovation champion states. Yeah, by the Consumer Technology Association. This is a, a different CTA.

This is not the Colorado Technology Association, but they, they had a couple things that they liked about Colorado: business-friendly tax policies, strong job and small business growth, and obviously a large technology pool. Yeah, so very cool to be named in those, in those top states for technology and Innovation Championship there. The next story was something that kind of surprised me when I, when it popped up into our feed. It looks like Larimer County Clerk had posted a lot of sensitive information out on the web. Yeah, you know, this was a really interesting one.

And when I was talking to Dale Drew before our panel at Rocky Mountain Information Security Conference, he mentioned this to me. So, you know, it's the clerk and recorder's job to post public records online. So, the Larimer County Clerk posted a number of records, including death certificates and court proceedings and other things like that. And some of them had PII in them, Social Security numbers and other things that the people might not want posted online. Right.

And she has removed that data at this point. But there is a challenge. She does, you know, she doesn't know how do you make these things available without, you know, giving away the sensitive information. And Of course, redacting is the obvious answer there. But she says redacting is very expensive, and it's not foolproof.

There is, there is definitely a challenge here to fulfill her job without exposing people's sensitive information. Yeah. And I'm not sure— she mentions that the Colorado laws around this and feels that they were in her favor, that the legislature had, had talked about the fact that we should be posting complete records online and not doing redacting. I don't know the, the statute myself, but I would sure hope that it doesn't say that it should post our personal information online, even if it's, well, just at all. Well, so I'm not a lawyer and I am not a legislator.

It does feel to me like this clerk is either misinterpreting the spirit of the law or the law overall. Otherwise, we'd be hearing an awful lot of other counties that are having the same problem. Right. But it is, it is really interesting to see. So check out the link in the show notes to to learn more about that.

Next on the list, Xcel Energy is proposing a number of power grid upgrades. One of the cool things in this article is they talk specifically about upgrades for security. Yeah, so, you know, we know that critical infrastructure is a target for malicious attackers, especially as we look at, you know, how would a small nation attack the US? Well, they're probably not going to try and send tanks and aircraft carriers after us, but they very well may go after our citizens through the critical infrastructure. Yeah, there weren't a whole lot of specifics in the article about what security upgrades would happen, but I think, uh, knowing anything about critical infrastructure and the power grid, any security upgrade is a good upgrade.

Yeah. So local security company news— Ping Identity has a press release this last week about their new support for PSD2 and open banking. These are a couple of standards out in Europe that are about how banks can communicate with one another and really take away the monopoly that banks have on how they connect, and they have the ability to charge money for those connections. And this is trying to move things into a more open, interconnected area, and that is a big focus for Ping. Next, uh, LogRhythm had a blog post this week talking about some of the awards that they've received.

We, uh, I think we've touched on a couple of these in the past, but they put them all together in, into one post. So, um, they were recognized as a leader in the Forrester Wave. I'm pretty sure we talked about that. Uh, SANS named them as, uh, top SIEM I believe. And then SC Labs also named them as either one or one of the top sim products.

Well, I think it's kind of a given, right? I know that they, they generate this kind of content to get buzz around what they do. But this— none of these are a surprise. If you're going to do a list of, of top sims, if Logarithm isn't on the list, then your list probably isn't comprehensive. It's probably not right.

So yeah, certainly appreciate that they're sharing this. And that's good news for them. But it's kind of a no-brainer at my point that they're up there with those top 2 or 3 others. The final piece of news this week, Gail Corey. I just want to do a shout out to Gail.

We had her on one of the early episodes of the podcast with her husband Steve. Gail has been the VP of Security for Oracle's managed security service offering for quite a while, and just this last week she was promoted and named the CISO for their cloud offering all across Oracle. So this is a global position that's focused on not only what she was doing previously, but a whole lot of other offerings for Gail. This is the first time that they have ever had a Chief Information Security Officer. They've had a CSO who was focused on their product area, but this is really cool for Gail, well-deserved, big congratulations to her.

Yeah, and Robb said it, but it really is a big deal that that she got this title. And I don't think that that should be underestimated. Yeah. So anyway, Gail, big congratulations. So events for the week, before we dump into the specific events, I just want to call out, if you guys aren't aware of it, we do have a calendar on our website that goes through all of the events that we, that we're pulling together for the weekly podcast.

And we actually go out quite a ways. I think we go out all the way to October right now on the, on the agenda. So if you ever are wondering, hey, what's going on? When is the next ISSA meeting? When is the next Big conference in town.

We're really trying to capture all those things on the website under the events link. And if you're someone that plans events, security events, you should also let us know about these events so we can get them on the calendar. And then when you're going to plan future events, you should check the calendar first to make sure you're not planning your event over another event that already happens. Yeah, I can't tell you how many times I've seen people scheduling really redundant events for the same night, where if you just move it a week off or even a night off, you're much more likely to get that good quality audience coming there. Exactly.

And the first event we have this week is the National Cybersecurity Center. They have a cybersecurity oversight training that's in Denver on, on the 16th. So this is a training for executive boards around cybersecurity. And they have these about every other month. And they're alternating between Denver and Colorado Springs.

Also on the 16th, Cyber Excuse me, Colorado Cyber is putting on a cybersecurity insurance event. That looks really interesting to me. It's late afternoon. If you want to know more about cybersecurity insurance, this would be a good place to come and ask questions. Yeah, I can't make that one, but if I was here, I would definitely go.

So next on the 17th, OWASP is having their May meeting. Yep, and that'll be at Dave Buster's. On the 17th, and 18th, the Colorado Springs chapter of ISSA is having their May meetings. So that's the 17th in the evening and the 18th during lunch. Come to either one and hopefully, you know, get signed up for that early.

If you're, if you're in the Springs, try and make one of those. And then also on the 18th, SecureSet is having a cybersecurity career trends event. If you are looking which areas of cybersecurity you should be getting into, that's something that you want to go check out. And, you know, we have been talking about BSides and RMISC for the last few months in the kind of forward-looking stuff. In terms of forward-looking stuff right now, I'll call out a couple of things.

We do have— excuse me, Colorado Springs does have their Security+ training coming up in June. Get signed up for that if you want to go get ready for a Security+ certification. And the Avanta CXO event is coming at the end of May— excuse me, end of June on the 29th. This This is a 1-day event that really pulls in a lot of high-quality leaders. So if you are a security leader in the area, I recommend signing up for that.

There's a link for that in the show notes as well. And then of course, looking way ahead at the end of August is the Colorado Springs Annual Conference. That's the 30th and 31st. It's not too early to start looking at your schedule there. One other thing that I wanted to call out, Robb, the annual SANS Rocky Mountain training is here on June 12th through the 17th.

I'm a big fan of SANS training. It's hard to get to SANS training because they're extremely expensive. And then if you also have to travel, that adds even more cost on top of it. So this is their big event in Denver every year. So if you're thinking about SANS training, that was— it's probably a good time to look at it.

Yeah, maybe you can eat some ramen for a while to be able to pay for the training. Exactly. So jobs for this week. Uh, starting off with Miller Coors is hiring a Director of IT Audit. Optiv is looking for a Program Manager Central.

I'm not sure, uh, what you're central to, but you're definitely central to something. Uh, they're looking for that person here in Denver or remote. I basically think that means you're going to be covering the Rocky Mountain region. Comfort, or maybe it's Comforte, is hiring an Enterprise Solution Architect focused on security. This looks like you'd basically be a pre-sales engineer helping, you know, put together solutions for Comfort customers.

AT&T Consulting has a couple jobs. One is focused on GRC and the other is focused on incident response and forensics. So if you want to work for a large telecommunications company and, and do some travel and consulting, those jobs are for you. Salute is hiring a DevOps engineer. This does have a security focus, although I think that's probably built into availability and engineering, just as it's the DevSecOps movement.

Blackstone is looking for a cybersecurity engineer here in Denver. I thought that was interesting because I don't believe that they are based or even have offices here. Yeah, they're not based here, but I do believe they have a presence here in Denver. So I'm not sure if you work out of an office or work from home, but interesting hire there. I know they definitely have some companies that they own parts of that are here.

The Cybersecurity Network is hiring a regional sales director focused on cybersecurity. So a sales job. Sweet. Uh, next one is pretty exciting. Uh, the FBI is looking for a special agent.

So if you've ever thought about joining the FBI, uh, this is your chance. Uh, there aren't a whole lot of details in there other than sort of the standard FBI boilerplate. Um, but some of the skills they are looking for are cybersecurity related. So I would think that this would be something that could end up in the, uh, the cyber squad over there at FBI. I think, Alex, I think you and I are a little bit too old to do this.

I believe they do have an age cutoff. Unless you just came out of the military. There's some kind of exception there. But they are focusing on cybersecurity. I think you go through training and they put you— they assign you to an area.

But I know cybersecurity is one of the skill sets they're really trying to hire right now. So Lockheed Martin is hiring a Manager of Computer Systems Security Analyst 2. That is a long title. I'm not sure exactly what that means. I believe that one also required at least an interim clearance.

Okay. Uh, GBProtect is hiring an information security analyst, and, uh, looking at the job post, uh, it's a little bit contradictory. This is either a tier 3 support position where you need at least 5 years of experience, or you need a minimum of 1 year experience. Not sure which. It says both.

So if it were me, I'd go ahead and just apply and let them tell you you're not the right person if you don't have enough experience. And for the GB folks, if you're listening, maybe clean up the job description just a little bit. There you go. All right. Anything else we want to share before we call it a day?

I think we should say Happy Mother's Day to all the mothers out there. Absolutely. And Happy Mother's Day to my own mother, Gaye Reck, and to my wife, Kristen Reck. Awesome. All right, guys, have a great week.

Thanks, Robb.

This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

This is Alex Wood with the Colorado Equal Security Podcast. I'm here at Highlands Ranch High School with the Cyber Patriot team. I want to go around and let them introduce themselves here real quick, and then we'll get into some questions. Hi, my name is Jacques. I am a junior at Highlands Ranch High School.

Hi, my name is William. I'm a junior at Highlands Ranch High School. Hi, my name is Melanie. I am also a junior at Highlands Ranch High School. My name is Trevor.

I am a senior at Highlands Ranch High School. My name is Adam. I'm a senior. And I'm Addie Newman and I'm a senior. Awesome.

Well, thanks. I appreciate you guys taking a few minutes to talk to me today. You know, we've talked about you guys and the stuff that you're doing in some of our news in the past couple weeks, but I just wanted to start real quick. You guys were just at the national finals for CyberPatriot, but some people probably don't know what CyberPatriot is. So does one of you want to take a shot at telling what CyberPatriot is?

CyberPatriot is a network security competition. So essentially throughout the season we are given, we call them images, they're just virtual machines of various Windows and Linux-based operating systems, and they have pre-configured vulnerabilities. So we have to find those and fix them. In addition, there's also a Cisco component where we have to configure a network using Cisco equipment. And then at Nationals, which is what we recently went to, there is— we had 7 different machines.

Some of them were Windows, some of them were Linux. Each of them ran a specific server, so you might have a web server and a a POP3, so on and so forth that you had to secure, keep the server up and running, all the while you have a live red team trying to hack into your machine. And then there was also a Cisco lab component, digital forensics, and encryption. Right, between the regional competitions, the qualifying rounds that you had to do to get to Nationals, and Nationals, there was a lot of differences. Those live red team components as well as the need to keep your required services up and running were very different.

Also, the Cisco component, it requires a lot more, like, sort of looking into the challenge and configuring the network in a way that you don't do in the qualifying rounds. And the Cisco component is physical at Nationals, but it was virtual via Packet Tracer. During the qualifying rounds. Nice. So how many qualifying rounds did you guys have to go through?

I think there were 4. There was a— there's 2 qualifying rounds, and there were a bunch of exhibition rounds that didn't really do anything. But there are 2 qualifying rounds. They seeded you into either a silver, into a silver, gold, or platinum tier. Only the platinum tier can compete to go to Nationals.

And then after that, there was a state round, which we won, and And then a regional round which took the top few teams from every state to be in the regional round, which we won our region. We didn't win the whole thing that round, but we won the region, took 3rd place. And then the top 12 teams from that regional round go to Nationals. So at Nationals, it sounds like it was a little bit of a different experience. You guys got thrown some curveballs.

Why don't you maybe talk about some of the stuff that happened there that you had to hadn't seen previously? So they definitely show us and make us use some different things like Facebook. The Facebook challenge is pretty much going through Wireshark packets and something new that we had, which was Volatility, right? Yeah, so we had Volatility, which we have never heard before, but then we also had to use Guacamole. So they just throw like— they'll tell us a couple, like a week before, different programs that we have to use, and then it's our choice— our— what am I looking for?

Unfortunately, this year at Nationals, neither Guacamole or Volatility became a part of the challenge. Apparently they had to go to Plan F because of technical difficulties, so they threw together a Wireshark capture and just had us do some forensics on it, which was really good for us because we did a ton of practice with Wireshark. And that was a lot of fun. It was cool to be able to work on our strength instead of the programs that we'd been thrown into about a week before. Yeah.

So how did you guys do at Nationals? We got top— well, we're not supposed to really say. Right. No talking, guys? Yeah, they place the top 3 and the top 1 or 2 in each event, and if you don't don't place, they don't say.

How do you feel like you guys did at Nationals? Better than last year.

A lot better. Awesome. We took a very different strategic approach this year, focusing on specialties rather than the images as a whole. We just have to be careful because we don't want to give away the game plan. Right.

Well, it's something that the industry, the industry people at the challenge tell you to do every year. A few other different changes, especially on the images side, was again the red team was definitely big. You'd just be sitting working on your machine and all of a sudden your mouse would move, or you would restart your machine and all of a sudden you don't have— I was working on the Windows side, so I would be saying, hey, what happened to Explorer? I don't have an Explorer anymore. I don't have a command prompt.

They just renamed all of my critical operating system things. They knocked down the whole GUI on one of our images. So I'm like, I've got to secure this DNS server, but I can't get to my DNS server because they knocked out my DNS server. So, and you can't like say, oh, like what you do in the industry and just say, I'm gonna restart this image. You can't do that.

If you restart it, it goes back to square one with all the vulnerabilities configured. So it was a much bigger challenge. Sounds like a pretty big challenge. So, you know, I see you guys have a lot of equipment out here. You've got some lab stuff.

What do you guys do to practice to get ready for these competitions? Practice? Just lots of images, lots of coming in after school sometimes, you know, especially near Nationals. A lot of us come in and practice more Wireshark stuff, different like volatility stuff that we had to do earlier, but because, you know, they threw that in like a few weeks before we even knew about it and made learn and stuff. So obviously we had to just keep practicing with a lot of different images on our own and with each other and with lots of notes.

We had to keep writing, you know, more notes and stuff so we knew what we were doing at Nationals. One important element, I think— so when I was talking to other teams at Nationals, you know, they have 3-hour practices 5 days a week from the time the qualifying rounds start, and We're over here, you'll hear a coach complain about it all the time. We're all in AP classes, we have other extracurriculars we do, so we're, we're really busy people. A lot of it's self-motivated, finding gaps in our schedule that allows us to participate in this club. So a lot of the practice is really take this image home, do it.

You have access to the Cisco textbook, read it, do the quizzes that go with it. So a lot of self-motivated stuff. So it sounds like you guys are really motivated. You're doing this on your own. Do you think that's part of the reason why you've been successful, or what do you guys see as the reason for, for being successful as a team?

I think we need to give a lot of credit to our mentors and our coaches. They do a lot to help teach us, especially our Cisco mentor is wonderful and super helpful. He does a lot of hands-on work with us, including making a physical network that simulated our school network last year. We had all the Cisco gear in the class that we plugged together, configured the devices. He's, he's a really good teacher.

Also, DeBolt has been doing this a really long time, and when it comes to training new people, he's really good at getting them the base-level knowledge that allows them to then explore the new stuff that's coming into the challenge. And the new stuff that the seniors like myself and Adam and Addie, what we learn, we try to put either into notes, into new images for people to practice on, so that way for future years, someone 5 years from now can still learn the crap that I did from this competition. So everybody isn't starting over afresh. Every time someone graduates. And if you could teach people that work for me to do documentation like that, that'd be awesome.

So I noticed that the team makeup here, you have 4 guys and 2 girls. Is that pretty standard? Are you seeing sort of gender differences like that in the other teams? I wonder if you'd comment on that stuff. Pretty standard.

To have lower gender. We're actually on the high-ish side. As a general, Nationals, it's about 22% is what I think. Yeah, so the people who won the national competition, there were one team, a couple teams in 3rd place that had a few girls in it. From there on, however, there wasn't as many girls.

I don't know if it's just because that they just don't want to have want to have any techie girls in there, or if no girls want to go and try out. But I think what Nicky DeBolt here is doing is that he's actually recruiting girls so then we can start having— raising that average because we need women in technology. So he's helping direct us forward to our future. Every year I've been working with DeBolt, he's been talking about how he wants to create an all-girl team. I do, I do, I want to create an all-girl team.

Well, they, they, it's really amazing to see the amount of attention that they get from all industry professionals at CyberPatriots. You talk about 2 girls, 4 guys, I think we were the only team that had 2 girls on it. If a team had girls, it was 1 girl. So, at least in the high school open division. So it is actually a lot of high end.

How do you guys see that affecting the dynamics of the team? You think it makes you guys a stronger team? Yes, I think so. I think it makes us, you know, think more cohesively as a group because I have a different view from where Adam or Trevor might have, and then that helps us, you know, look at different things and find something that we might have not found. So you You guys last week, you got to go meet the governor and the state CIO and CISO.

I wonder if you wanted to talk a little bit about that. Sounds like it was probably pretty exciting. So they, the CISO and the guys down there, they were talking about, it was pretty impressive. It was us and then the Colorado Springs Cadet Squadron team that was part of the the JROTC division that went down there. So they were telling us about how they started with $6,000 of funding to protect your driver's licenses in Colorado.

So from there, I mean, they were very interested. And I think that, I mean, had both teams gotten gold, I think that we wouldn't have been able to walk out of that building or have jobs. But even then they were talking about how they'd love to get internships. And then we went down to the governor's office. He's quite a funny dude.

I mean, yeah, he was talking about how Colorado should be called the more laid-back state than California. Yeah, because we don't do regular practices and stuff like that. Yeah, the other really interesting thing that they were talking about was how old a lot of the gear they have to really locked down is because it has really important information on it inside these huge mainframes that are still running stuff that it might be hard to hack just because there's not that much stuff developed for it. They were saying how they were glad that they had their few COBOL programs still in the building. Right.

It was definitely an interesting experience and they kept bringing up job opportunities and internship opportunities. It really is crazy because I'm not— I know a few of us aren't specifically looking into going into cybersecurity, but seeing how many opportunities there are in the field, and they kept emphasizing you can do this as a part-time gig and do your— let it fund your hobby, it really— it did help me reconsider a little bit. Yeah, so I know a couple of you are seniors. So what are your next steps?

I'm going to be going to Embry-Riddle Aeronautical University in Arizona. I'm studying mechanical engineering and cybersecurity. If we're doing full titles, I'm going to California Polytechnic State University San Luis Obispo to do computer engineering next year. I'm really excited about it. So I lean more towards the computer engineering side a bit because of CyberPatriots.

I was thinking more mechanical, electrical, robotics before I started doing CyberPatriots, but seeing all that the advances going on in the computer science and sort of scripting side of CyberPatriots got me interested in computer engineering. Awesome. And then I'm gonna just stay more local. I'm gonna go to Colorado State University, and I'm looking at computer science just because I think that if you want to learn security, you also have to learn how to program because that's going to be a large step in just helping you be more available and make you look more good for— marketable. The CISO was talking about this when we were talking to her.

She said that a lot of people in cybersecurity don't know how to code. Which— and they talked about that at Nationals of CyberPatriots this year too. It was kind of a revelation to me. I realized how different these 2 fields are between computer science and cybersecurity. But they also talked about working and solving these problems and creating programs that can prevent these cybersecurity threats.

I don't think you can be actively problem-solving without being able to code. I think it's more on the— I'm still trying to process this, but I think the delineation between coding and cybersecurity is really interesting because I've always viewed them as one and the same. It's like, are you a robot following a script or are you a developer in the field making new steps towards achieving? Right. Yeah, good way to look at it.

And then the rest of you who are still going to be back here for at least another another year. Are you guys gonna be on the team again next year? Yes. Yeah, for sure. We would like to thank our presenting sponsor Northrop Grumman for providing us this opportunity.

Always got to call out your sponsors. Yeah, well, thanks all you guys. I appreciate your time. Congratulations. This sounds like a great program.

You guys are doing really well. And congratulations to you seniors on your next steps. Thank you. Thank you.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes