All episodes

Debbi Blyth

Apple Podcasts Spotify SoundCloud

In this episode:

Robb interviews Debbi Blyth, CISO for the State of Colorado. News with Alex and Drew heading into the holiday weekend.

Happy Memorial Day!

This week Robb is on vacation and Drew Labbo fills in for the news. Ping is hosting their Cloud Identity Summit in Chicago this summer. SecureSet moves their Denver training facility to Blake St. Root9B is partnering with Chertoff group for expansion. Top Denver CEOs are all in the tech field. Blog posts from Red Canary and LogRhythm. Send your high schooler to CyberPatriot Camp this summer and finally, Brett Bradshaw leaves Ball Aerospace to move to Gogo Internet.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

Robb sat down with Debbi Blyth, CISO for the State of Colorado to talk about her path to being CISO of our great state. This is a great opportunity to learn about Debbi and security at the state level.

Local security news:

Job Openings:

Upcoming Events:

This Week's Events:

Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9382 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.

Hello and welcome to the Colorado Equals Security Podcast. This is episode 17. We are recording for the week of May 29th, and Robb is actually off this week. He's over in London taking a little trip over there. So I have a special co-host, Drew Labbo, back again.

How's it going, Drew? Going great. Looking forward to the holiday weekend, and thanks for having me. So we're actually recording a little early this week. Normally it's on a Sunday, but since it's a holiday weekend, we're going to get this over with on a Friday.

So you got any big plans for the holiday weekend? I'm going to take it easy, relaxation and recreation this weekend. How about you? I'm going to try and do that as well. I'm sure I'll have some yard work or other things like that that won't necessarily be relaxing, but that I need to make sure I get done.

So let's go ahead and jump into it. First on the list today, Ping hosts their Cloud Identity Summit in Chicago this year in June. Drew, what do you know about that? So Ping is near and dear to Colorado Equals Security heart. Robb is the CISO there, so got to love Ping.

I think it's going to be great. It's interesting that identity is such a hot topic right now. I think a lot of organizations neglect identity and access management, and I think a conference like this is great to show how it can be just so fundamental to a security program. Yeah, I remember Andre, their CEO, talking about how when they first started the company, there wasn't a whole lot that was out there in terms of identity and access management and thinking around it, so they started this conference as a way to, to promote the industry and to promote thought around IAM. So it's pretty cool to see it's still going.

Absolutely. Next we have SecureSet. They're actually standing up a new Blake Street location in downtown Denver. So they are growing like gangbusters. I just continue to hear such great things about Alex and his team there.

So that's pretty exciting. I'm glad to see them growing, and we really need more InfoSec talent. Such a shortage, and this is such a great way to directly start building that talent. Yeah, so they, you know, SecureSet's got kind of 2 focuses. They've got their education side, which I think most people are familiar with, and then they also have their accelerator for startups.

So that accelerator is starting at, or staying at their 38th and Franklin location, and then the education piece is moving over by Coors Field. So next, Route 9B. We've talked about them a number of times on the podcast. They're based out of Colorado Springs. They've partnered with the Chertoff Group, and they're using that to help raise capital and, and do some expansion.

So it's really good to see that that company is growing and that they're going to be getting a cash infusion, it sounds like, to, to expand the business even more. Yeah, and it's really impressive if you look at the military expertise. I believe they have a general that's one of the— from the Air Force, if I remember correctly— that's one of the co-founders. So I'm pretty impressive to see that, that level of expertise in the private industry. I'm really impressed.

So the next one, there's an article in the Denver Business Journal and it's talking about Denver's top-rated CEOs. It's interesting that Andre at Ping is actually number 4 on the list, so I thought that was pretty interesting. There was a little odd comment in this that made me laugh. It said that apparently Denver CEOs are not as well-liked as other CEOs in the country based on the Aler survey. And I've— interesting.

I kind of wanted to laugh at that. Um, I think it's— I, I think it's just because if you look at the entire country, there are quote unquote a lot of other top CEOs in the country. Um, but I, I thought that was pretty funny. And I believe, um, gosh, if you look at this list of the top CEOs according to this Aler analysis, uh, a lot of them are IT or security companies. Yeah, you look— I mean, all the way down through, I think through the top 6 are all you know, IT or technology companies.

And then you've got Molson Coors thrown in there at number 7, but then, you know, a number of other technology companies after that too. So definitely Denver still showing that it's a technology hub. Next on the list, there was a post this week from Red Canary, and this is on their blog. I think it was really interesting. It's about using tabletop simulations to do incident response planning.

And that's, I don't think, anything new in and of itself, but there's a lot of good information in that blog just talking about making sure you include the right people and, you know, how it is that you should organize those exercises. So I think, you know, if you're gonna do some tabletops, I think definitely check out the blog entry. Definitely valuable. Next we have a a playbook that LogRhythm has recently published, and I believe it was on a blog as well, and they talk about enabling 24/7 monitoring with automated response. And this is kind of the holy grail for security, right?

A self-healing security system and network. And one thing I thought that was pretty clever, it noted if it sees an endpoint, as an example, one thing they would do is disable the user's Active Directory account based on that domain controller data, and then also to communicate with a NAC as an example to cut off the LAN access. Access or even wireless access. So I really get excited about detect something, stop it in its tracks, and then, you know, go from there. So pretty neat, neat approach.

And I really— I never as a security leader was able to get to that fully automated component. We had a lot of good alerts and a lot of monitoring around a SIEM and a little bit of automated process, but that would have been my dream, is to really see that through. Yeah, and that whole security orchestration and automation that market has really taken off. So, you know, companies like Swimlane, which is also out of Colorado, we've talked about before, you know, they have standalone project or products that do some of that orchestration and try and bridge the gap between SIEMs and other products. But it's really neat to see LogRhythm touting the fact that they have some of this capability built into their product already.

Next on the list, We've talked a little bit about the National Cyber Center before down in Colorado Springs. They actually have an Air Force Association Cyber Patriot Cyber Camp this summer. So we just wanted to mention that real quick. It's July 24th through the 28th. It is for kids that are in 9th to 12th grade.

So if your kids are high school aged, they're interested in cybersecurity, or you want them to be interested in cybersecurity, and they need to do— need something to do for a week this summer, I think you should definitely try and check out that camp and, and get them signed up. Yes, for certain. It's— when we look at the ISSA Denver chapter goals for the next few years, we're really talking seriously, and I think this is going to go ahead and be a goal that we want to support that. I don't want to say K through 12 because we probably don't need kindergartners actually doing anything here coding, um, or touching security controls. But, you know, looking at high school, looking at colleges, how can we really invest in the Denver community and provide support and our expertise and maybe even be guest lecturers in a university course?

And I think the challenge is, if you look at academia, a lot of it's quote unquote the ivory tower. They don't— they look at a textbook and they've never maybe necessarily actually hands-on implemented a security control or tried to support the business and workflow while at the same time implementing security. We're really excited about this concept. We want to get involved with CyberPatriots. We talked about that before on the podcast.

So I think we're going to see a lot more activity with ISSA engaging with the colleges and the high school crowd that are interested in security. Yeah, that's great. And then last on our news list today, Brett Bradshaw, who I think we've talked about in the past, he was the CISO for Ball Aerospace and then actually was promoted to the CIO. Ball Aerospace, and he recently left and he's now the CISO for Gogo, which is, you know, a mobile internet provider. You know, you see them like at airports and other things like that.

I think maybe even on some airplanes and other things. So congratulations to Brett, exciting move for him. Glad to have him back specifically on the security side, not just on the general IT side. So that's what we have for news. Just a real quick mention for events that are upcoming.

As always, go check out the event calendar on the colorado-security.com website. We have a full calendar of all the different events that are happening around Colorado in relation to information security, so check that out. Really, this, you know, we're going into a holiday week. I think things are gonna be a little slow, so we really only have one thing to talk about for next week. We've mentioned it before, but ISSA Colorado Springs is doing a a prep class for Security+.

So this is actually over 2 weekends, so the 3rd and the 10th of June. Um, so that registration is open now, so go take a look at that if you're interested in getting your Security+. This is a great way to get some prep for that exam. I think that the— it only costs, you know, $40 or something like that for the, for the, uh, the prep, which is pretty amazing. Uh, so that's it for events.

We'll jump into the jobs here. So, uh, AT&T has a Senior Technology Security Engineer, I believe it is, uh, position open. Yeah, that one actually looked kind of interesting. You know, a lot of times you have, you know, big companies that are looking for things in that area, and that one actually, if you read the description, had some interesting stuff. Uh, next, uh, Vertella, they're looking for Director of System Security.

So Vertella is a I believe they're a managed VPN provider, but they're based here. Could be something interesting there. Excellent. Next we have Chipotle. They have an IT security engineer position open.

And to me, when you think about that retail restaurant space, PCI compliance is gonna be key, trying to enable the business while still architecting secure solutions. So that one's gonna be fun and challenging, I think. And you'll probably get some burritos. I would love some free burritos. Maybe I'll apply.

Compre Consulting. This— so this is someone looking to— a recruiter looking to hire, but they're hiring for a cybersecurity consultant around NERC. So I put that in here because it looked really interesting. If you're someone that is interested in energy and energy supply, definitely check this one out. You know, NERC compliance definitely could be an interesting position.

And talk about prescriptive— NERC is about as prescriptive as you can get. Yeah, you look at stuff like HIPAA where, what does this even mean? And some of these other regulations, and NERC is very, very, here's what you do. So, um, could be interesting. Um, next we have Kaiser Permanente Director of Cyber Risk Defense.

Uh, Alex, I imagine you have a little familiarity with that position. I do. So, um, uh, Christine Vanderpool, who is now over there managing the Cyber Risk Defense Center, they're looking for someone to, uh, to manage the team that is, uh, doing their monitoring and analysis around, I believe, with Splunk. So if you have Splunk skills and want to manage a team around that, I think that'd be really cool.

Visa, they're looking for a senior security program analyst. Visa, I think they're down in Highlands Ranch, so if you're interested in payment card, you should check that out. Next, we have at DaVita Kidney Care. They're right downtown here in Denver at their main headquarters. They have a position open, a senior director and assistant general counsel of IT health systems in cybersecurity, and this is really an attorney position, it looks like.

Yeah, not something we would normally have on the show, but I, I saw that out there, I thought it looked really cool. So if you're someone who is in the legal profession, is interested in cybersecurity, that might be a cool, cool one to get into. And then last, WOW Internet, which is based here, and they actually just went public this week, they are looking for a summer intern. So if you or someone you know is looking for an internship in cybersecurity, have them check that out. We will have the links to all of the, the jobs as well as the events and news we talked about today, uh, in the notes on the website.

So go ahead and check that out, colorado-security.com. And I think that's what we've got for today. Excellent. And I will say, looking at the event calendar for Colorado Equal Security, there's a lot to talk about in the rest of June. So looking forward to in the next podcast in the next couple weeks talking about some of these.

It's lots going on. It's really neat to see in the summertime we're not just resting easy, we're actually kind of ramping up as a community if you look at all that's on the calendar. So pretty neat. So, um, stay tuned. Uh, after the break we're gonna have our feature interview for the week, and this week we actually have Debbi Blyth, who is the CISO for the state of Colorado.

So Robb sat down with Debbie and had a great interview, so Stick around, we'll be talking to Debbie. All right, thanks Drew for filling in. Thanks for having me again, I really enjoy it. Awesome, and we'll talk to you guys next week.

Hi, this is Vincent Grimard, CSO at Nelnet. Welcome to Colorado Equals Security, for Colorado security professionals by security professionals.

Well, this is Robb Reck, and I have the fortune today to get to sit with my friend Debbi Blyth. Debbie, you and I have had a chance to talk a few times, well, like this. We talked a couple years ago when we did an interview for the, for the blog. You know, you've, you've had the opportunity to go through some pretty interesting things here in Colorado, and I thought it'd be nice for us to catch up, see, you know, get a little bit of background for those folks who may not know who you are, and let's talk about what's going on now and what you see going on through 2017 and 2018. So as a starting point, why don't you just let us know who you are, what's your job, and what keeps you busy?

Great. So I'm Debbi Blyth. I'm the Chief Information Security Officer for the State of Colorado, so that keeps me busy. But it's a job that I truly love. Our organization, the Governor's Office of Information Technology, is basically the technology services provider for the executive branch agencies of the state of Colorado.

And so that's 17 different agencies like Department of Revenue, Public Safety, Corrections, Human Services. I could go on and on. There's 17 of them. And so they, you know, they each have a very different business focus. And the Governor's Office of Information Technology has a gazillion projects going on.

We have something like 1,200 projects in flight. And my team is responsible for making sure that we are building security into those projects. Ensuring that, you know, it's built into the architecture. We roll out policies, and I've got a team as well that does the security operations for all of that. Yeah.

And so it's just, it's a huge environment. It's a ton of fun. There's a lot going on at all times. Yeah. So 1,200 projects.

Obviously, that's way too many for even a fairly good-sized team to know all the details of. I'd be curious, how do you triage? I assume you have to do some kind of a triage where you say we're going to look at the high-risk projects or something? How do you go through that triage process? Yeah, so they go through sort of an assessment process.

We have a project lifecycle or a, I don't know what you'd call it, but it's sort of a gating process where at gate 1, we ask the business, you know, what type of data, how critical is this to your agency, and then based on some of the information that they provide, we determine how involved we need to be. So my team may be very, very involved, or they may be sort of only lightly involved. Involved. But there's a very mature process that is, you know, that it goes through these specific gates, and then we determine at what point, you know, is the project ready to go live, and have we signed off on all of the security risk. So do you have the project management office going through those questions and giving you the output from them then?

Yes, absolutely. So you don't have to have one of your people going and asking questions for every project, it's just built into the project managers? Yeah, correct. Yeah, and I think honestly we'd like to be more involved, but with the, just the sheer volume of projects and work going on, we just don't have enough security architects to be involved in every project. So if there's any projects that you can share about, maybe just give us an example of what one of those projects means and how your team's involved, I'd love to hear about it.

Yeah, so one of them is called Decorum, and it's for the Department of Corrections, and we are basically replacing of their offender management IT infrastructure. They're actually— their systems where they attract offenders through the correctional facilities. Like the ERP system or the CRM of the correctional facility world? Exactly, yeah. And so it's really, really interesting because we're replacing a system that's like 20-something years old, and it does everything from tracking pharmaceuticals to tracking where the offenders are, what they're, you know, where they're at in their progress.

And so it's just, it's really amazing. I've learned a lot more about the state government and the services that the state provides just by, you know, being sort of a sideline bystander and, you know, listening in on some of these projects. So I'm having this flash in my mind to Ferris Bueller's Day Off when he hacks into the school system and changes his missed days from 9 down to, I don't know what he changed it to. So is this a system that you need to make sure We don't— they don't change their, you know, months to serve down from, from, you know, 56 to zero. Yeah, all of that.

But, you know, this program is really and truly like a life safety program. So I think about, you know, this is the first role I've ever been in where if the system went down, people could actually die. And so we actually, at the state, we have 120 what we call critical and essential systems. Critical means it's critical to that agency, and essential means there's a life safety component. And so, like, for public safety, for example, if an officer, if a state patrolman pulls over a car, he needs to be able to run the license plate before he even gets out of the car.

He needs to be able to have at his fingertips, you know, if there's fugitives in the area and what they look like. Because if he gets out of the car and approaches that vehicle, you know, it may be a life safety issue that he just simply wasn't prepared for if we don't have the technology up and running. And so, for the first time, I'm really thinking about my job as not just securing data, but it's really, it's the whole, you know, CIA triad. It's making sure that the systems are up and available and have integrity, and that, you know, the individuals who need to use them, that they are available. Department of Corrections is the same thing, because, you know, I think about those correctional officers that are in those roles.

They're in extremely dangerous jobs. And if systems are down and if they can't tell when was the last time that this offender had his medicine and what medicine is he on and when does he need his next dose, things can go bad in a big hurry if, you know, if they're not able to get that information. And so it's all very interesting and it's, you know, a system outage carries a new urgency that I maybe haven't seen before. So, I mean, that's one of your 1,200 projects. That's pretty great.

Well, I want to, I want to go ahead and back us up a little bit. You know, I know when we talked previously, you've given a pretty thorough background for where you are, and let's go just maybe not go into quite so much detail. In fact, I'll put in the show notes the link to our previous interview, the written-up one, so folks can go read more about your background. But maybe over a couple minutes here, talk to us about how you got, you know, into IT and into security, and then of course eventually to the governor's office. Okay, sure.

Yeah, I could talk for hours on this one, but I'll try not to. So actually, my dad really got me into IT. So long before computers were a normal thing to have in people's homes, he's a CEO of a computer consulting company, and he would bring home computers. And for the summertime, he would give me tasks, you know, data entry type jobs. And then he would also bring home programming books and say, hey, I want you to do some of these basic programs.

And so I would, you know, sit down at the computer, do some basic programs, and he'd pay me an hourly wage through the summer to do, you know, data entry and programming that, you know, were definitely not useful to his company, but just something to keep me occupied, I think. So he kind of got me into computers. Later on, I took a job with what was Covia at the time that became Galileo that became Travelport, and really, you know, I knew I wanted to pursue a career focused in computers, but I really wasn't sure what I wanted to do. And so I took a job with Covia Travelport and kind of bounced around in there. I mean, I worked in MVS, I worked as a tape operator, I worked doing automation, you know, creating programs to help the system basically self-heal.

So if a program blew up that needed to be running, it would the system would restart it. I worked in network. I worked in the Unix team. It was in the Unix team where we had a few days of firewall outages. They were kind of up and down, and finally the network team determined they needed to rebuild the firewalls.

In the process of doing that, they discovered that the firewalls were really Unix systems under the covers. They kind of just threw them over the wall at us and said, hey, Hey guys, these are Unix systems, you know, you guys manage them. And I remember thinking, firewalls, I mean, that sounds so important. And so I stopped by the bookstore on the way home and bought all the books they had about firewalls at the time, and it was only like 4 books. So I took all these books home and I started reading, and I just got really interested in security, interested in the firewalls.

And then I started doing, you know, health checks on the firewalls and doing everything I could do to make sure the firewalls were configured correctly, managed appropriately, putting in change management for the firewalls to make sure that we didn't have unplanned outages. So much so that I was really ignoring all the rest of my duties on the Unix team. Also, I was kind of making an enemy out of the director of the security team because every firewall change that he was seeing, I was pushing. He would get onto me at least weekly about, hey, you are making all the changes on the firewalls. My security team should be doing that.

And I was actually working very closely with the security team, and they were telling me they were not comfortable making changes on the firewalls, and so they were wanting me to do them. And so we were sitting together where I would put the change in, they would look at it, and then I would push it. And so finally I came to that director and said, hey, I'd really like to work on your team. I think you need my skill set, and I'd love to pursue a career in security. And so he actually created a position for me.

And so I worked in that team for probably, I don't know, 5 years, I think, and got my CISSP, pursued, you know, additional areas of learning. So learned a lot about network security, learned a little bit about application security, really wanted to be kind of well-rounded in the security realm. And then about 5 years later, when our director left, they promoted me to manager of the team. It was a shock to me and a shock to everybody on my team because I hadn't even been asked if I wanted to be the manager of the team. Quite honestly, I didn't want to be the manager of the team.

I really wanted to stay technical. I was actually disappointed at first.

It was really funny. I don't think I embraced being a manager right away. I was a reluctant manager. Still much more technical. But eventually, I did embrace that role, and now I'm really glad I did because then I finally went on to Teletech, where I was the executive director of security there, managing their security program for 5 years.

I would say I really developed as a leader there because at Travelport, I was really interacting mainly with developers, with applications teams, with architects, looking at web applications, also with infrastructure teams. But at Teletech, I got much more involved in the business. So I was working with marketing, and I was working with mergers and acquisitions, and I was working with the legal team, and I was meeting directly with clients and kind of selling security to clients. And so I, you know, it just— I really changed and really matured as a leader at Teletech. Spent 5 years there.

Just really, it was an extreme area or extreme time of growth and maturity for me. And then one day I saw a position open up for the state, which was Chief Information Security Officer of the State of Colorado. And I read the job description and I was like, wow, it just really sounds like me. And I showed it to my husband and he goes, oh my gosh, that really sounds like you. And I remember I told my parents, I told my mom that I had applied, and she had just come and eaten lunch with me at Teletech, and she said, why on earth would you leave Teletech?

You know, this is the most beautiful building, and you have a great office, and you love your job, and it's a fabulous place. And I said, but Mom, Chief Information Security Officer for the State of Colorado!

So yeah, so that was about 2 and a half years ago. And I've just been, you know, doing that job and absolutely loving it ever since. Well, that's great. Thanks for, you know, bringing us up to current. Sure.

You know, over the last couple years in the state, I'm— I'd be curious to hear, you know, what do you— how do you compare the job at Teletech to the job at the state? What's the difference between being public sector, private sector? Just, yeah, what's your impression been of that? Yeah, well, that, that's a great question. So, one of the things that struck me immediately was I'm working as part of the Governor's Office of Information Technology, and as I mentioned, we're a service provider to all of these agencies.

And so, it was easy for me to kind of draw that parallel between, you know, I'm a service provider, and at Teletech, I was also a service provider. And so, I think it kind of helps me to formulate, you know, what should our role be and what is my role in this you know, whatever it is that comes up, what should my role be versus what is the agency's role. But, you know, I've loved working for the state. I mean, I just didn't know very much about state government until I started with the state, and so just to see all of the various services that we provide to the residents of the state is just amazing to me. And also to see the passion, you know, when I'm dealing with agencies and they're just really, really passionate, and they may be you know, upset that a system is down, and they're extremely passionate.

And the reason they're so passionate is because they really care very deeply about the services that the residents are not able to access because, you know, the system is down or because of whatever event that has transpired. And so you just see a ton of passion there, and it's just a different kind of passion. I mean, it's a, it's a service kind of passion. Yeah. But the other thing that I love is The governor is just— it's just awesome to be able to kind of, you know, interact with the governor and to be able to get a sense of who he is as well and the things that he cares deeply about.

And he cares deeply about cybersecurity. And so that's why I've really been able to interact with him quite a bit is because he's so interested in cybersecurity. And he's been such a supporter of our program as well. In fact, we had a phishing incident that, you know, we had like one too many. We had a couple of them.

I think everybody's dealt with them. And then all of a sudden we had one too many. And the governor said, how do we make this stop? And I said, well, I have a solution. We can turn on 2-step verification.

And he said, all right, let's do it. And, you know, start with me. And so we started with the governor. User number one. Yeah.

The governor told the agencies, You know, you guys are just gonna have to live with this. I realize it's gonna be painful, but we're gonna go through this and it's gonna make us better. And, you know, when you start with the governor, nobody can say no, right? And so within 90 days, we had 2-step verification rolled out across the state, 30,000 state employees, because we had that support at the top. And so that's just something that, you know, not every state and not every company has that.

So that's something that I've been incredibly— I feel incredibly privileged in this role. Yeah, I certainly appreciate you helping us get the governor to come talk at RMISC. Yeah, that's fantastic. And another thing that he has been involved with security has been the National Cybersecurity Center, right? Yes.

Have you had any interactions there? Any— yeah, you know, can you share anything about what that's been like over the last year or so? Yeah, so he He went to Israel last year and saw some stuff that they're doing in Israel that he came back and thought, you know, I'd love to see something similar here. And one of the things that— so I'll back up a little bit. National Cybersecurity Center is based out of Colorado Springs.

It's separate from state government, so it's not meant to be tied in any way to state government. It's very closely aligned with UCCS, with CU of Colorado Springs. But that's not their only educational partner. They're certainly reaching out and wanting to be inclusive of other educational partners. But they've got 3 primary goals.

So firstly is an institute where they want to train county commissioners, local elected officials, national elected officials on the importance of cybersecurity, but not just public sector, also open it up to boards of directors, CEOs of you know, small and medium-sized companies so that they can understand why cybersecurity is important and that they're able to kind of factor that into decisions that they make. So first is the institute. It's a training center. Second is they realize that we have a workforce shortage right now in cybersecurity professionals. You know that.

I know that. Any of us trying to hire, we can see that. But we feel like it's only going to get worse as we look to the future. And so partnering with UCCS and other universities, they want to create a workforce development center. They also want to be partnering with private sectors, so like Securesat, for example, and other entities who can bring skilled professionals in to help train and help, you know, build up a strong workforce for cyber.

And then thirdly is they want to be a rapid response center so that small and medium-sized companies who do suffer a security incident or a breach that don't, just don't even know where to start, have a place that they can call. And then, you know, NCC will have partnerships where, you know, they'd be able to say, for instance, do these 5 things now, and then here's some partners if you need additional resources that could maybe come and help. So that really was kind of the vision of the governor, but then he got other folks that were you know, like-minded about the urgency, the need, the, you know, the desire to solve these complex issues, and brought them in partnership to create this NCC. And I'm hopeful that, you know, I made the introduction to Ed Rios, and I'm hopeful that you and Ed, who's their CEO of the NCC, will be able to sit down and talk at some point. So actually, Ed and I had a call, and we scheduled— we'll have an interview with him in the Next couple of weeks, sometime soon.

Great. Looking forward to that. So thank you for the introduction there. You bet. So let's go back to your day job for just a little bit longer, then we'll talk about community stuff.

Okay. You know, in your day job, a lot of what you're doing is supporting the initiatives of the different agencies, right? Yes. Yes. Do you have any initiatives that are, you know, security instead of, you know, you're supporting them, but stuff you're driving and that's important to you?

And if so, could you talk through some of those? Yeah, absolutely. So we have a multi-year strategic plan called Secure Colorado, and we are a state that I would say is very fortunate because we're one of the better-funded states in the nation. We set a goal that 5% of the overall statewide IT budget should be allocated to the cybersecurity program. It's a lofty goal, and at the time that it was set back in like 2012, we weren't even achieving 1%.

So now we are up to 3%. So 3% of the statewide IT spend is allocated to cybersecurity. That puts us in the top 20% of the states in the nation. So we do have money and projects every single year that are security-related projects. And so this year I launched a project for security analytics threat intelligence, and behavioral analysis to try to get those disciplines into our organization because our security analysts are seeing something like 8.4 million security events per day, and that's correlated.

So it's coming into our SIEM, they're looking at that, and I have no idea how they're determining, you know, what they need to go investigate. Now, they're super sharp, so they're figuring it out, and they tell me they've got it under control, but Um, you know, it worries me. So I am trying to get tools into the environment. We issued an RFP, the RFP closed, we did some proof of concepts, we selected some tools, and we are implementing tools that will help us to better detect anomalies in the environment. Because I would say one of the things that I was most worried about coming into the state, and that it really took me a long time to, you know, feel any level of comfort is, do we have appropriate detective capabilities and response capabilities?

And so we spent a lot of time practicing incident response, and so I'm feeling a little bit more comfortable about our ability to respond, but I still am a little bit uncomfortable about the volume of events and whether or not we're going to be able to see the anomalies. Sure. And so we did just make a purchase in that area The other thing is we have a joint cybersecurity task force that is— I have 2 members that are on my team that are on this team, also 2 members of the Colorado Bureau of Investigations who are cyber investigators, and then also 1 member of the Colorado Information Analysis Center, CIAC Fusion Center, who's a threat analyst. They're co-located at the FBI and led by the FBI. And they are responsible for detecting and prosecuting instances of cybercrime against Colorado resources.

And so these guys wanted to be able to hunt on my network. And so I was like, no problem. I want to get you tools to be able to do that because it's a whole extra pair of eyes on my network, you know, looking out. They're getting threat intelligence information. They are top secret classified or cleared individuals.

And so they're getting information from the FBI that I'm not even getting. They know what to go look for, and they're actually using my network to go look for it. So that was another reason why, you know, I wanted to get tools in place that they would be able to use. So not only is it bubbling up anomalies to my SOC analysts, but I've got threat hunters on the network that are using them as well. Yeah, that's great.

So that is a project that we're working on also. 2-factor authentication. So I talked about 2-step verification that we turned on on our Google G Suite. Yeah, we are going a step further. We have 2-factor authentication in certain places on the network, but we want to make more of a consistent approach across the network, and we want to be able to use it more, more widely.

So not just on this specific system or this specific system, but we want to be able to use it on all systems and all remote access. Are you combining it with single sign-on then, or do you already have single sign-on in place? So we're looking at single sign-on also. We don't have it in place, but that is something that we are looking at. Makes it a lot easier to do the 2-factor if it's one sign-in, one place.

Absolutely, absolutely. That's great. Yeah. Any other big initiatives you're focusing on right now? Obviously, those— that's a lot.

Yeah. Just don't want to change the topic on you if you have any more coming. So we are implementing the 20 critical security controls for effective cyber defense. And so every year we kind of look through that and determine, you know, how mature are we for each of those controls? And then we select projects and areas where we need to get more mature.

So like threat and vulnerability management is something else that's on the radar. It's always, it's hard, right? That's really an iterative process. You go from nothing to, hey, I got something in place, to then looking back at it later and going, oh, this is so bad. I know.

You get better and better each time you go look at it, I think. Yeah, I agree. The other thing is that we really have to get better about fixing the things that we find. That's just something that I think the infrastructure team has really stepped up to that and they have really improved that. But when we really start doing continuous vulnerability scanning, I'm afraid we're going to overwhelm the team with the stuff that we're gonna dump on them.

So, you know, I'm not exactly sure how we're gonna handle that yet. It's a lot easier to find things than it is to fix them. Absolutely. And we probably, we probably don't do a good enough job saying, okay, I found some stuff, I'm not gonna go find anything else now. I'm just gonna go fix them for a while.

Otherwise, it's just, it's, it's demoralizing, right, to have that stack always growing. Yeah. For the IT folks, I definitely feel for them. Yeah. And that's an issue we have too, is because We have all of these state agencies, and they interact with the federal government, and they get federal data or federal funding.

So the federal government is always sending some entity to audit some state entity at any time. And so my team is involved with all of those audits. And if it has an IT component, which everything does, any findings comes back to the infrastructure team to go try to fix. Then. And so we just, it just feels like we're in audit, you know, audit mode all the time.

And we have a constant list of things that we need to be fixing. So, you know, I really am concerned about when we really get better at continuous vulnerability scanning, dumping more stuff on the infrastructure team who are already kind of underwater with audit remediation. Well, I'm going to change topic a little bit here on us, you know, over the last couple of months, really since it started, we've, we've covered the Women in Security movement quite a bit here on the show and talked about that. And I understand you're, you're getting more involved with that. I'd love to have you share, you know, what's your level of involvement there and where, you know, where do you see the group going?

Yeah, well, I'm really super excited. Um, we have, um, on the board of Women in Security a very powerful board of women. So I'm just going to tell you who they are. So Sarah Avery from Logarithm, you know her. Sarah's really the one who, the protagonist who got this whole thing going.

She is. And has been really, you know, keeping her foot on the gas. Yeah. So certainly appreciate Sarah's work there. I do too.

And I think she, she was involved with another thriving Women in Security. Kansas City, I believe. In Kansas City, yeah. And so she really came here and was surprised we didn't have one. And so she took it upon herself to start it.

And she, I get the feeling, I don't know her very well, but I get the feeling that when she decides to do something, it gets done very quickly. Yeah. Yeah. Liz Van Ackeren with Optiv, Danielle Wilson with Fortinet, Nancy Phillips with Datavail, Mary Haynes with Charter, Patty Kettle with SecureSet, and Jen Wilson with MHR Partners. So I, you know, was really hoping I could be a part of that as well.

And so they are letting me, or I should say, Nancy is letting me be co-chair with her for community outreach. So I'm really excited to be able to talk to you today a little bit about this because I think, you know, women in security— every time I go to a security event, and certainly with all of these women I've talked about the fact that every time we go to a security event, it's mostly guys. And, you know, we're all used to working with a bunch of guys. That's not unusual. But it sure seems like it'd be nice if more women were involved.

And I certainly think about, if we talk about a workforce gap and we really feel like there's going to be a cybersecurity shortage of personnel in the coming years, you know, if as many females went into security as males, we could double the workforce almost, you know. And so I just feel like we need to find a way to encourage women to help, you know, either enter the field or to build their careers in the field. And so that's really what Women in Security is about. The mission is dedicated to advancing the leadership and professional development of women in the field of cybersecurity. And the next event— well, you know, I'll tell you too, we talked about— we're so proud to be a part of ISSA because ISSA provides great opportunities for networking and also for training, for beefing up skills as a cybersecurity person.

We don't want to say, oh, women, we have our own training, and you ISSA, it's guy training. You know, that's not our point. What we really wanted to do is promote ISSA and all of the great training that you guys provide, but then kind of augment that with training that we think would be helpful for women who are trying to build their careers in this area. And so the next event, June 27th, The topic is, who are you? And it's about building your brand.

So we're going to have an expert. It's a branding expert that's going to help us kind of explore this topic and talk about how do you build your brand. And then there's going to be a panel also on women, female security leaders talking about their brand and why it was important in their career development. So I think it's going to be a great event. That sounds like a lot of fun.

Yeah. Yeah, very cool. You know, I— you talked about the disparity. You know, I think it's something like 50% of the workforce in general are women, and something like 18% of the IT workforce are women. And security is— I would guess it's somewhere near IT.

It might be a little bit lower, but, you know, it's pretty low. As I— obviously there's a problem there. Yeah, um, I heard some really interesting research on this recently that you start from where we are today, you know, at let's call it 18% women in the IT workforce, and then you go look at computer science and other IT majors in college, and it's approximately 18% majoring in CIS. And then you go look even— you can go back further and you look at high school and people who opt opt into IT classes, and it's approximately 18%. Wow.

So the problem isn't— it's a really early problem. It's once you realize that people are opting in from, you know, adolescent age into, you know, women are opting in at a much lower rate than men are. Right. Well, the problem is more systemic than something later. Apparently, they're sticking around about at about the same rate that men are.

Um, but somehow we're not getting them into the beginning of the pipe. Um, so anyway, I— there's, there's got to be a way that we address it at each stage, right? Yeah, go talk to people like the Cyber Patriot and the Cyber Girls initiatives. Um, and but I think it's more systemic than that. It's like there's this— there's a perception of IT and/or security as being a, a manly or a male profession.

Okay, how do we, how do we address that perception, right? And systemically, so people don't say, well, I'm not going to go that way. Um, right, let's move, let's move them, get some interest there. I think that's great. And then the thing I'd say, you know, I would guess, you know, based on these numbers we're talking about, the majority of the people listening to us right now are probably men.

Um, and, and I, I think that as, as, you know, men in the security workforce, we need to think about what do we do to improve the, the leadership opportunities and the career path for, for women in IT and security, right? And I don't, I don't think we yet have the answer. And that's one of the things I've challenged Sarah to, to help us figure out as, as you guys as a group. Like, yeah, be very internally focused, help your members, um, get— improve theirself. But then let's come back out and report out to the rest of the community, right?

Let's, let's, let's get on this podcast and let's go to ISSA and RMISC on the, on the main stage, right? Yeah. And talk about, you know, what we've learned from women in security And how do we, how do we use those learnings to impact each of our departments? You know, there's a lot of people out there who are running security departments or companies who just don't know, right? How do I get better?

And we want to know. So I'm excited. I think there's a lot of opportunity here. I agree. And even recruiting, I mean, how do we recruit females into our companies in this area?

Because, you know, certainly every time I've had an opening in the state, whoever it is that's in charge of that would say to me, I'd love to get some females in this group. It's all guys. And so, you know, I don't even know, like, how do you— I think there's probably a way to write the job description. I don't know. But, you know, it's like, it's not that they're not qualified.

It's that they're not even applying. Yeah. And well, it— I mean, it goes back to what we're talking about, right? If there's— if just assume the 18% is right. If only 18% of the people are women, Then if you go— if you're hiring for an experienced person, you've just dramatically cut the ability for you to hire a woman.

Yeah. So, you know, one of the ways we can do it is by hiring different skill sets rather than having to have 5 years experience in IT. Maybe it's 5 years experience in customer service, which customer service is really valuable for some of my positions. Right. Yeah.

And I can hire and maybe I can find females that way. Right. Um, I mean, of course you're gonna have to train somebody on something, right? So pick, pick the skill you're going to train on. Well, maybe I'm going to train security and I'm going to have someone who's really good at project management and really good at communication.

And, and that gives you an opportunity to, yeah, to expand a little bit. Yeah, but it's a challenge, right? It is, because if you want someone to go run your sim, well, yeah, you probably want someone who's got that experience, who has some sim on their resume, right? Right. Um, you know, I think Regis university has been thinking about this issue, and they started something called Cyber Girls, where it was an event really targeted towards middle school students, girls, to get them interested in cyber and to show them, you know, what does cyber mean, you know, why do we think it's fun, what does a cyber career look like.

Twice they've had to postpone this event because not enough girls signed up. It's like 1 or 2 sign up. Starting a new initiative is, is so hard. Yeah. And getting, getting people aware of it and, you know, they've never heard— they don't have any success stories to go off of yet.

Yeah, it's, it's frustrating, you know. Anyway, I, I— it's something we need to keep looking at and find small ways to make a difference, and then let's amplify those so other people can hear about the successes. And yeah, let's get better at it. Yeah. Awesome.

Well, thank you so much for volunteering on that. That's, uh, that's fantastic. I think having your name on the, on the board is gonna, gonna help, gonna help out as well. Um, what else, what else should we talk about? Anything else you want to share with the listeners while I got you?

Um, golly, I don't even know where to start. Yeah, I would just say, you know, I'm incredibly proud to be affiliated with our state, and people ask me, you know, they have different thoughts about what does state government look like, what does security in state government look like. Um, somebody said to me, I shudder to think what it might look like, you know, it's my information. And, um, so I would say, you know, for Colorado listeners, you should be very, very proud that your state is funded in the top 20% of all states across the nation, and that, you know, we really take this seriously all the way from the governor on down. And that is just not true in other states.

And so I feel like we're very, very fortunate. That's great. And you've done a great job, you know, helping raise visibility here in the state, and certainly excited about it. I'm looking forward to seeing what you do over the next couple of years, and hopefully we can touch base with you again, I don't know, 6, 12 months or so and see what's happened and have you check in again and we talk more about women in security. I'll probably get someone else from the board more quickly because we want to keep you guys top of mind here.

Debbie, thanks so much for your time. We'll look forward to talking to you soon. Sounds great. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes