Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 18, the week of June 5th, 2017. Alex, how How's your June going so far?
Not too bad. It definitely is summer already. My kids were in a football camp Thursday and Friday last week, and yeah, so it sure seems like summer. How about you? Yeah, same thing.
We had our first swim meet of the year yesterday. That's 7 hours spent watching your kids swim for what, like 3 and a half minutes, something like that? I have some mixed emotions. My kids are not swimming this year for the first time in several years. Sad that they're not swimming, but also happy that I am not up at 6 AM every Saturday morning to make it to a meet where I get to roast in the sun and then just watch them swim for 3 minutes.
Yeah, so thanks for covering for me last week. As you know, I was, I was in London and Tel Aviv for a work trip. The, the interesting thing for that, for me about the trip was, you know, 6 days overseas, it probably took me 5 days to get adjusted to the time and not be exhausted the entire time. And then now I've been home for 5 days. And just as of today, I'm getting back onto normal schedules.
I think you're going to have to work a little more on your, your cross-country time zone shifting. Yeah. Or, or less. Or less. Or just don't travel as much.
One or the other. All right. Let's go ahead and jump into the news. Denver boasts the lowest jobless rate of any major city. Yeah.
So we've seen similar articles to this recently, but again, The jobless rate continues to fall. Metro Denver is down, I think, to 2.1%, which is amazing. Yeah, there were a couple areas in there that were even lower than that. Boulder, it looks like, was 1.8%. Yeah, it was.
So, you know, Denver, the cutoff for major cities was over a million population. Boulder falls underneath that, but was the second lowest city anywhere at 1.8%. And then the article shows other places in Denver that were even, even lower at like 1.7%. Pretty impressive. It was pretty impressive.
It was interesting to see that the lowest in the country was Ames, Iowa, I think at 1.6% or something like that. Pretty good. So some sad news for those of us who are children of the '80s. The last video rental store in Denver is closing at the end of June. Yeah.
So, you know, if you want some bad movies on VHS, or DVD, I suppose. I don't even know what they have at the video rental store anymore. Then you might want to swing by there and pick some up before they're completely gone. But it's good news for those who have been holding on to those videos with the late fees attached, hoping to avoid having to pay it. You might, you might get out of this after all.
Exactly. I think it's a little more likely there than, you know, a library book. I don't think the libraries are ever gonna go out of business. So video store, you might get rid of those fees. But don't worry if you do need to fix your, you know, get your fix of physical movies Redbox is still available in just about everywhere now.
I think they've actually installed it at the bathroom at work.
Next on the list, VertaPhone. They're moving their headquarters to Denver. So Vertafore. Vertafore, sorry. They're an insurance industry software company, and they happen to be owned by Vista Equity Partners, which is the same company that owns Ping.
So I've met the guys from there a couple of times. I think that the Gist of this story is we're getting a large software company. They're going to have 400 people just at their headquarters here in Denver, moving into Denver, right in the middle of downtown. And the reason they're moving is because this is where the talent is. And where are they moving from?
Bothell, Washington, right outside of Seattle. So another one of the big tech hubs moving headquarters here for talent. Just another indication of how great the economy and how the tech scene here is. So my favorite crazy story that I didn't know existed, So in Lakewood, we have a robot security guard company. Yeah, you know, I'm not sure if this is a good thing or a bad thing.
But the company is starting to raise funds so that they can build, you know, essentially an initial production run of these security robots. So the company is called Gamma Two Robotics. And they just raised $6 million. And I think you said, I don't know if it's good or bad. I think it's really good if you're a science fiction author.
And all of a sudden, your predictions are going to come true. I've got a quote from the article here that these robots— the robot name is Ramsey— will change the world of security because he never rests. He operates at a fraction of the cost normally paid for cameras, technology, and guard services. Can you imagine this being in a movie? I feel like that is straight out of RoboCop.
I think that they actually lifted that quote directly from RoboCop. Anyway, so this is fun. If you look at them, you guys need to take a look at the link in the show. The robots look like they're from Doctor Who. They look like little moving, what, balustrades, ATM machines rolling around.
It's sort of R2-D2-ish. Yeah, pretty good. I hope that they are more RoboCop than Skynet, but we'll have to see. I'm sure it'll be one or the other. Next on the list, Deloitte.
They are picking up LogRhythm as their threat lifecycle management platform. So this is an interesting partnership. Uh, Deloitte, they're using for their managed services and some of their, uh, SOC deployments, they're partnering with LogRhythm to do those. So, so kudos to LogRhythm. Sounds like a good partnership there.
Yeah, I thought this one was funny. When, when I read LogRhythm's headline for this story, it said Deloitte and LogRhythm joined forces to provide advanced cybersecurity solutions. I had no idea what that meant. So, so I rewrote the headline to, uh, Deloitte Canada MSP picks LogRhythm threat management lifecycle management platform. So are you taking a side job as a marketing analyst for LogRhythm?
So yeah, so Chris, Andy, if you guys need some help with your headlines, let me know. Another LogRhythm story. I thought this was a pretty fun one. They started a contest. The product manager for their NetMon freemium product, starting a contest basically to say they want you to deploy NetMon Freemia in your organization and solve a business problem.
And then, you know, once you've solved it, submit a case to them saying what problem you solved and how you did it using their tool, and you have a chance to win cash. Yeah, I think that they have 3 different categories that you can submit in. And then I think there's— I think it was $3,000, $5,000 for number one. Yeah. And then number— I think number 2 was, was $1,000 and number 3 is a free copy of NetMon.
Free freemium. Yeah. Uh, interesting though. I think I may, uh, may download a copy and, and take a look at it on my home network, see what, uh, see what pops up. Yeah, I mean, why not, right?
It is a free tool. It gives you visibility in your network. This is a clever way for them to get some, uh, some people using it and hopefully some free PR for them as well. Yeah, so next on the list, uh, Optiv. We've talked about their Avantix, uh, product here a couple times in the last few weeks.
They've made some previous announcements, but they, they just announced that they are now integrating with BitSight. Yeah. So, BitSight is a security ratings company. So, they take publicly available data, um, and then essentially give companies ratings based on their security practices. So, it looks a lot like a credit score.
Yeah, exactly. Uh, so, Avantix is the, the third-party management software, uh, vendor risk management software from Optiv. And so, now not only can you manage your vendors through surveys and other data that you, you might already do, but you can now integrate it with the, the BitSight scores, which I think is pretty cool. Yeah, good, good feed. I think that's a good idea for, for AvantX to take advantage of the, the data coming from BitSight.
Uh, so the last, uh, well, this interesting story here. Coalfire's blog has a post around the anatomy of paying a ransom. They were, they were hired to come into a company that had had ransomware go throughout their organization, impact a lot of different servers, and really take the business down, right? And this organization brought in Coalfire to say, help us pay the ransomware. Yeah, and I think that it's something that you may not think about.
Um, one of the, the topics at Jeremiah Grossman's keynote at RMISC, he mentioned this a little bit, that, you know, you should have a, um, a Bitcoin wallet and some way to, to have Bitcoins available in case you need to do something like this, worst-case scenario. But, you know, reading the article, it seems even a little bit more complicated than that. Yeah, the, you know, just because you have a Bitcoin wallet doesn't mean it's easy to go, to go buy $35,000 worth of Bitcoin. How quickly can you do it? How do you— and how do you have confidence that the people who you're paying the ransom to are actually going to give you your data?
So this story goes into detail around how they, you know, slowly, you know, gave money to show that proof of concept, and then, you know, tried to buy half of the servers and then the other half, and did some testing along the way and worked with the ransomware folks. It seems to me like this must have taken multiple days by reading this story, but Really highly recommend you guys take, take the 3 minutes to read through this article. Um, it might give you a little bit of a jolt to say, you know, might need to be prepared yourself to pay a ransom in the event that your controls don't prevent something like this. Yeah, I think, you know, as security professionals, we, we want to think that this is something that wouldn't happen to us, that we're prepared well enough, we've got enough controls in place, we have the, you know, the anti-malware, the whatever else it is that we have in place so that we're not going to get infected, we've got good backup procedures. But there's always the chance that something could fail and you might have to, to go down this route.
So being prepared, uh, in this, just like with, uh, disaster recovery or anything else, is a good idea. So the, uh, the security consultant from Coalfire who wrote this is Bryce Baerschel. Uh, Bryce, thanks for writing this. We'd love to talk to you more and learn about the experience. So we'll look to go from here.
Uh, and then the, the last story that we have on the list, um, Janus Capital Group. Which is a Denver-based company. They just merged with another London company. So they're, they're now no longer independent. But I think the, the biggest piece of that is, you know, we have, we have some friends over there at Janus.
Yeah. So Joe McComb, I got to have a chance to have lunch with Joe this week and got the news that Joe is the, is the global CISO of the new organization. Joe had previously been director of security for Janus for quite a while. I think he was named Janus CISO a little bit back, but now he's the global CISO for the new group, which is called Janus Henderson Group, headquartered out of London, but he'll be here in Denver. I'm sure that he is disappointed about not getting to move to London.
I think he's very fortunate and very happy to be getting to do the new job. So congratulations, Joe. Yeah, good stuff, Joe. So new events for this week. We decided this week we're going to go not just this week's worth of events, but go 2 weeks in the future for those who might listen to the podcast a little later in the week.
It'll be more relevant for you. So we're gonna go a little bit faster because that means we have, you know, quite a few events to go through here. As always, go to the website, take a look at our event calendar, and you can see not only what's happening this week, but what's happening for the next 6 months or so. Top of the list on, on the 5th, which is, uh, what, that's Monday, right? Um, SecureSet is doing a What Is NetSec?
What Is Network Security event. Uh, the CTA on 6/8, they are doing their SheTech event. We talked about that for a while, right? Uh, then the 9th, they have the Women in Technology Conference. Uh, on the 10th is the 2nd day of the Colorado Springs ISSA's Security+ training.
So if you, if you went to the first one on Saturday the 3rd, make sure you go to the 2nd one here on the 10th. Uh, also on the 10th, uh, it is Cybersecurity Night at the Sky Sox This is sponsored by the NCC down in Colorado Springs. And the NCC is the feature interview on the podcast this week. So you get to learn a little bit what they do. And if you can go down and watch the game, you get to talk to some folks there and hopefully get involved.
This is a good chance to get involved with NCC. So that's the— for this upcoming week. The following week, there's actually something pretty big. Sands Rocky Mountain is kicking off their week-long training class here in Denver. So that goes the 12th through the 17th.
And that's in downtown Denver. They're offering several different classes if you want to take SANS classes. The Cloud Security Alliance is having their June meeting on Tuesday the 13th. That's going to be at the DeVita office downtown. Interestingly enough, there's going to be 2 security meetings at DeVita that night because the ISSA group is having our big, our annual meeting where we do our election, and I will no longer be president of ISSA after that.
I'm very excited. James, I think you mean you're very sad. I'm very excited to have James Johnson helping lead the next generation of the chapter. That is assuming that the chapter doesn't revolt and not vote him in. Highly recommend you don't do that.
That'll be awkward. But the ISSA meetings are the 13th and 14th. The 13th will be downtown Boulder, where we'll be having lunch at CA. And then Tuesday night at DaVita, like I mentioned, and Wednesday at noon will be at the Oracle Building in the DTC. So also on the 14th, ISACA, they're having a social event at Topgolf down in Greenwood Village.
So that should be fun. You do need to be a member of ISACA to go to this, but it's not too late to join. The Colorado Springs ISSA chapter is having their chapter meetings on the 14th and 15th. That's the 14th at dinner and then the 15th over lunch. And then also on the 15th, SecureSet is doing their expert series with Michael Boucher.
Boucher? Boucher? I don't know the— sorry, Michael, I don't know either. Yeah, correct pronunciation there. But a couple more events here.
I know we had a lot to go through this today. We have the Colorado Cyber— that's the group that Um, was originally kind of created with security companies in the area. Uh, they're, they're on the 15th doing a cybersecurity insurance event downtown. That's in the afternoon. It looks good if you're in the downtown area or just want to learn more about insurance.
You might want to take a look at that. And then finally on the 16th, ISC2 is doing their annual training that they have here in Denver called Secure Denver, strangely enough. So if you're an ISC2 member and want to get some CPE credits, go take a look at that. All right, we'll move into the job area here. We do have a theme this week on jobs.
We've had a couple folks ask about leadership positions in the Denver area and thought we would just highlight those that we're available— that we're aware of right now. And there's, I think we have 7 positions to go through. Yeah, so, um, first on the list, uh, Gates Rubber. They're looking for a Director of Information Security and Risk. So this, this will be the leader of security at Gates.
There is no— there's no higher position. So If you want to run an org— run the security group for a large multinational company, this is a good opportunity to do that. Speaking of that, MillerCoors is hiring a senior director of IT security. And as mentioned by you, Robb, this is MillerCoors, not Molson Coors. Yeah, I'm not sure what the nuance is in terms of whether this is the same position that, you know, Christine Vanderpool had at Molson Coors or not, because I do believe they were merging MillerCoors and Molson Coors.
So I don't understand how that works, plays out, but it does look like a good opportunity as well. It's all beer. Next, TIAA, they're looking for a seat— excuse me— a senior director in IT audit. So did they get rid of the word CREF? You know, they did.
They did a rebranding, I think, within the last year. So it's like Deloitte got rid of Touche. Yes. Interesting. Poor Touche.
All right. Ball Aerospace is hiring a senior security manager of tactical solutions. Yeah, and that actually It's a little misleading. I think Tactical Solutions is one of the business units at Ball Aerospace, as opposed to you're doing tactical solutions in cybersecurity. Do you know if this rolls up into Dan Collander?
I don't. My expectation is that it would be, but I haven't reached out to Dan to talk about it. Well, if Dan is listening, Dan, you could let us know and we'll follow up next week. EMS Software is looking for a Director of Cloud Ops and Security. Looked like an interesting position there.
Absolutely. Spectrum is hiring 2 different positions. One, they're hiring a senior director of network security ops, and second, they're hiring a senior manager of vulnerability compliance. Now, I am quite curious what a vulnerability compliance position is. Does that mean you are compliant with the vulnerability?
Yes, yes. You know, you have to make sure that you have all the vulnerabilities. Isn't that how it works? It seems like it might be vulnerability management. That might be what they're looking at here.
Not sure. But anyway, lots of good opportunities here. All of these are links in the show notes. You can go in and apply for these positions. And, you know, it'd be nice if someone hears about a position here on the show and ends up getting a new job.
We'd love to hear about it. It would make us feel vindicated that we're wasting, you know what, 3 minutes of your time every week on these postings. We might even talk about you on the show. Absolutely. That'd be great.
Well, I think that's it, right? I think we're done. All right. Well, everyone have a good week and, uh, send us a note if you have any recommendations or anything you'd like to see on the show. If there's any news that's going on in the area, if you've done anything really cool at your company that you think we should highlight, we'd love to hear about it.
And as always, check out the website at colorado-security.com for, uh, all the events, companies, and everything else going on in the area. All right. And stick around here for the feature interview with Ed Rios and Jenifer Furda, who are the CEO and COO for the National Cybersecurity Center in Colorado Springs. You guys have a good week. Thanks, Robb.
Hello, this is Stanton Meyer, CSO of CoBank. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Well, this is the Colorado Equals Security podcast, and today I'm lucky enough to interview the CEO and COO for the National Cybersecurity Center in Colorado Springs. So with that, I'm going to go ahead and let Ed and Jennifer, if you guys want to introduce yourself, that would be fantastic. Sure. Yeah, Ed Rios, the CEO of National Cybersecurity Center. I've been the CEO there since November of last year.
I also own 2 other companies. One of them is a cyber and space company, and been in this line of work for about 31 years almost now. In various names and capacities. I've been in the private sector now for 15 years and transitioning now to the nonprofit area. The NCC is nonprofit, and I work, of course, with the NCC and other nonprofits as well.
Fantastic. Jennifer, what about you? Sure. So I'm the COO. I've been there since March 1st, so I'm even newer than Ed.
And I am, interestingly enough, I am new to the cyber industry, but as the COO, where my specialties are, it's events and programs, marketing, PR, and really standing up day-to-day operations of the NCC. And quite frankly, kind of running the show when Ed's out, you know, in DC and, and doing what he needs to do as the COO. So I'm just— I'm really there from a support standpoint. Not the technical person, but absolute believer in what we're doing as our little nonprofit. So let's back up even before either of you guys came on board.
When Governor Hickenlooper talked at the Rocky Mountain Information Security Conference last week, he mentioned his trip to Tel Aviv, and when he was there seeing what the security community looked like in Israel. Maybe you guys could each give some high-level you know, a summary of that experience for him and what really led to the formation of NCC? I can only speak second and third hand. I've talked to him, of course, about it. I think he also went to Beersheba, where in Israel the academic community, academia, industry, the private sector, and government all come together for innovative research as well as education and training.
And his vision was to create something similar to that here in the United States, scaling up from the state of Colorado, of course. And that's who we are, is an organization that provides response services but also education, training, and research, and to some degree a think tank that we have started out with as well. So you've described it to me, Ed, as kind of being a 3-legged stool for what you guys do for the services. Could we just talk through each of those 3 and where they are right now? The Rapid Response Center is the first leg.
We call them pillars. The Rapid Response Center is an ISAO, Information Sharing and Analysis Organization, and so receives in that capacity threat information from the Department of Homeland Security on a regular basis. We do that in partnership with the National Cyber Exchange, which is another nonprofit in Colorado Springs. So that's the foundational situational awareness for the response activities, and then from there We provide subscribed services or to anybody that wants to call if they have an issue with cyber in any capacity. Could be a breach, could be a question, could be searching for services or capability.
We're there to help them. Currently, that's only 8 to 5 Monday through Friday, and the number to call there is 1-877-90-CYBER. So when you say you receive this data, are you a SaaS platform that's pulling this data in? Is it humans sitting in a closet somewhere parsing data? What do you do with this data that you receive?
It's a SaaS platform of sorts. It uses STIX and TAXII, which are MITRE-derived hardware and software components that allow us to pull in the information. The information comes in as IT-related information. At that point, that is taken by humans and analyzed as necessary. And then posted on a portal or provided to subscribers if it's an urgent activity.
Although we have the most mature capability outside of MITRE in the nation to do this, it's still a very rudimentary and difficult process that we are trying to automate so that the data doesn't only come in for IT folks, but it comes in for a layman executive, for example, in a small or medium business, or state or local elected officials and their staffs as well. Well. That's part of the research component that we're trying to do, which is in our second pillar. So, so you say you have the most advanced outside of MITRE capability here. What do you mean?
I mean, there's a lot of companies offering threat intel feeds. What's the differentiation here, and what have you guys done to mature beyond what the rest of the industry is doing? Well, there's a lot of information that comes out, obviously. I mean, you can imagine the amount of potential breach attempts a day across the world. So if you combine that from the government's feed, and it's an unclassified sensitive feed, so it's not classified data at all, but if you combine that with other information we have, database algorithms, ways to manage it, we have the most mature capability.
It's the most mature in terms of process and in terms of technology and algorithms in order to present that information concisely and accurately. Before we go on to the second pillar, a couple of things that I want to remind people. We have a banner that we wave at the NCC. On one side of the banner, it really is cybersecurity for all. Our target market and our mission, who we were stood up to help— small and medium businesses, small and medium nonprofits, and elected officials.
Not that the big guys don't need the help, but typically they have an entire team behind them. So that's one side of our banner. The other side of our banner that we wave is really cybersecurity is more than an IT issue. And so we really focus on CEOs, you know, whether when we're doing cybersecurity training, which we'll talk about in a minute, we're really focusing on, you know, CEOs, boards of directors. We've made a little bit of a pivot and now we're really focusing on general staff associates and vendors.
We all know that there's a huge vulnerability there, but our intent with NCC is workforce development, helping to really bolster workforce development within cyber, economic development, and bring business and companies and people to, you know, around cyber. And then lastly is this kind of cybersecurity for all. So that first pillar, that rapid response, it really is a great— it's a confidential, secure cyber 911, if you will. We do have this 800 number, which again is 877-90-CYBER. And if a small or medium business out there, you know, if the worst of the worst happens, they can give us a call.
We can do an assessment. We're not going to blast it out to the to the newspapers or the news stations and say, hey everybody, look who just got hacked. We won't do that. We'll assess if something really did happen to your organization, and then if it did, we will give advice and guidance, uh, as to where to go next. And these would be with companies that we know and trust, companies that we know if they say they're going to do a pen test, they are doing a pen test, they're reasonable, you know, things like that.
So that's— we are a collaborator. Within this cyberspace. That really is what our goal is. So, so the data feeds you're getting, uh, that is— is that meant to be, um, forensic data to help with incident response or proactive data to help defend against things? It's signature data, really, to understand what the threat is and hopefully protect against potential breaches.
Yeah, but the signature data as you know, can be part of the forensics analysis. We offer forensic services if it truly is a breach. Most of the time, I mean, almost 80% of the time, it's just compromised credentials that lead to someone accessing private or confidential information.
And so, I mean, that can be a difficult situation, even with ransomware, right? There's only so much that you can do. But there are some forensics that we could pursue if our customers and clients need to go that route. So, and do you guys offer those services directly, or do you have partners with outside organizations? We do it with partnerships.
As Jen was saying in that first pillar, the— although we would respond to anybody or any call, we then provide a registry of solution providers as the services for you to contact. We would, of course, make that introduction, and we would endorse them because they've been vetted by the NCC under specific criteria. So, fair to say, if I'm a security or IT leader at a small or medium business, I believe I've been breached, I should give you guys a call, I should call 877-90-CYBER, right? And someone will pick up the phone and what will happen? What's my experience look like at that point?
Well, probably it'll go to an answering machine because we're getting so many calls nowadays, but after we answer the voicemail, we'll give you call back. If we're fortunate enough to get it right away, we'll start working an incident response checklist. It's a very standard NIST-related, industry-related response checklist just to first determine if there was a breach, if there was a hack, and then what the severity is and what we can do in terms of offered capability for reconstitution. And do you guys have like a security operations center that are answering those calls or calling people back, or is that outsourced? Not yet.
We have a new facility— it's not new, it's an old facility that's been refurbished— that will be provided to us in July. We'll actually rent that. Once we get inside of there, we'll do the tenant finish to build out the ops center there. The current responses are from disparate locations around Colorado. Subject matter experts here in Denver and Colorado Springs, servers in downtown Colorado Springs, folks across the parking lot from our administrative offices.
It's just kind of spread everywhere until we get into— So is that your staff though, or is that outsourced or volunteers or what? It's a combination of staff, volunteers, and outsourcing, uh, 1099s. Okay, interesting. And the new building, once we're in the new building, you'll see the ISAO, the SOC, they'll be inside with NCC headquarters. We'll have other cyber companies who have cyber mission will be in our building.
We're going to have a cyber cafe, or as Ed says, it's a cyber secure cafe, uh, 200-person training facility. It's going to be pretty cool. We're looking at doing labs, cyber labs will be inside the building, and then we're also discussing, um, SCIF capability inside that building. So what's SCIF capability for our listeners? SCIF, I'm going to say SCIF is secret squirrel And then Ed's gonna— it stands for Sensitive Compartmentalized Information Facility.
It's to do classified government work. Yeah, so I think we understand, uh, capability of column— pillar 1, is that what you call it? Pillar 1. The first pillar is a response, a rapid response center. Second pillar is a cyber research, education, and training center.
It's largely university and corporate training affiliated. The prime university that we we depend on a lot is University of Colorado Colorado Springs and the UC system. That, of course, has expanded beyond that to the state systems here and in other states. Currently, I think 7 states and 10 universities are participating today. There is a very loose common thread among them as centers of excellence either to Department of Homeland Security or other government agencies.
But we hope to expand that to 60 universities by the end of this year. The thinking with that is that no matter what discipline you're going into when you're going into school, whether you're going in for law or business or healthcare or marketing, cyber truly touches everything. So the thinking is that we're getting this cyber thread through all of these disciplines at the academic level. That's one aspect. An example would be innovative education that I believe— I know UCCS is doing, but I believe there's a University of Texas and University of Florida that's following their lead.
Rather than just have cybersecurity traditional curriculum of software engineering, computer science type courses, there would be a certification capability in cyberanthropology, cybersociology, cyberpsychology, kind of useful traits for marketing business degrees. Also cyber and business administration, cyber and public administration, obviously economics, law. So various disciplines can all have a cyber application of sorts so that there is cognizance and relevance when they graduate from their traditional degree. So I'm not real clear on what your guys' role is. You're not going in and teaching these classes, right?
What is your guys' role in education? Our role is to spur the curriculum development at the university system. The universities themselves are developing the curriculum, but we do have a separate role in the training area, separate from the education piece, with various contracts with companies in Colorado and elsewhere that provide boot camps or certified training, marrying that training up with the education does some very innovative and good things for workforce development. For example, if you have someone working on a software engineering degree and at the same time they're getting a Certified Ethical Hacker certification, perhaps there's a way to offset an hour or 2 or 3 hours in their 4-year education by doing that. It's a bit difficult in the public university system.
It's a little bit easier in the private university systems, but we've been very successful in making progress there. So that is all NCC initiative. So when you go into a new school that has never done this before, let's say, you know, you walk up to CSU, or maybe you're already there, but regardless, a new school, and you say, hey, we want to get you guys, you know, looped in with what we're doing around education at NCC, what's your sales pitch to them and what do you ask them to do? Well, usually it's the other way around. They're trying to really keep up with the workforce requirements like Jennifer was saying.
And in that capacity, not only does it bring relevancy to the student, but it brings relevancy to the university, right? The curriculum. You have folks who are practicing in the field that are actually students. And oh, by the way, instead of working at a fast food place, perhaps they're part-timing at a technical company of some sort. So it's really, it's building this education consortium is really what it is.
And again, as I said earlier, I mean, NCC, we're collaborators. So we're really just trying to get as many people around the table as we can. So a CSU would come to us and say, hey, we want to add this cyber thread through there. Or, you know, where Ed was saying, great, we have these students that are graduating with psychology degrees and sociology degrees, and really what we want to do is we want to sprinkle them with a little cyber knowledge so that it's not only kind of the ones and zeros, but it's why are the bad guys doing what the bad guys are doing, because that's where their degree is. As an example, at UCCS, there is an endowed chair for cybersecurity there.
That chair would be 50% dedicated towards the university as a professor, particularly in the research arena, but also 50% dedicated to the research and the activities going on at the MCC. And that's an endowed position. So, so you guys, the value add you guys are giving is helping them find the resources to help them put together the curriculum and, and really bringing the conversation together, right? So it's not an isolated, it's not an isolated conversation at one university. And why recreate the wheel when you don't need to, when we can bring to the table, hey, here's what all of these other universities are doing.
Yeah, so, so there's, we're still in column number 2, there's the, there's the work you universities, and then there's the training, which is, you know, obviously not degreed programs.
Help me a little more understand what you guys are doing there and who is that targeted at? That's principally workforce development, and it depends on the audience. Jen, you want to expand on that? Yeah, so we have partners because that's what we do. Every time somebody hears the word partner, we get to scream for the word of the day.
But so we have people like LeaderQuest, Securaset, SANS. There are groups out there that it might not be a 4-year academic institution, here's your degree, but you can walk out of there with cyber certificates. So not only are we playing with the academic institution, the 4-year traditional academic institutions, we are also in the world of cyber certificates and everything that Ed said earlier, you know, where there's the ethical hacking or there— and there's different levels. I mean, all the way up to SANS, who has master-level degrees in this cyber world. So we are familiar with SecureSet.
We've had Alex Krylan come talk about the training. He's our favorite. He did an interview with us a couple months ago. So understanding though, they do their 6-month boot camp, you walk out and you basically learned a very good entry-level security skill set. You know, what's your value add to SecureSet in that situation?
So again, we are big supporters that workforce development piece of really kind of sounding the bell and waving the flag of getting people into this crazy industry called cyber. So our goal, you know, we want to focus on veterans, we want to focus on women, we want to focus on minorities, and really just getting anybody who says, you know what, I think I want to do this. We— there was an article just in the Post, and I say this very lovingly, but cyber is an awesome opportunity for people that if you— and I say this extremely lovingly— but if you want to get your geek on, cyber is there for you. And, you know, not everybody wants to get— sit down and talk with people, and not everybody wants to be around all these people. Cyber's an awesome option for people.
So that's what we want to do, is just wave that banner, bang that bell, and really get people and tell them that there are options. You know, we're doing this cyber camp for high school students coming up. And again, getting kiddos to be interested in STEM and keep them interested, you know, all year long, even through summer. And it's just getting people into the cyber. What's happening, uh, we have good friends at SAIC.
Any given moment, any given moment, they have 40, 40 cyber jobs that are available. They cannot get them filled. Principally coding jobs. Yeah, principally coding software. But I mean, so it's just, we really, and I mean that one, that's a problem, but two, there's a huge opportunity there for us.
So again, so how do we fit into it? It's grabbing those partners and it's really being a good cyber partner and getting people into the industry. In fairness, Alex probably has to answer that question about value to SecureSet, you know, and he could do it better than us, but certainly we bring him the to meet these folks who are in need, both on the workforce side who have vacancies, as well as on the student side, folks who want to learn and pursue the career. Seems like it's kind of back to bringing the people into the room. You guys are amplifying the message that we need, you know, we need more people doing security.
You're bringing together the training organizations, and hopefully, you know, people are all congregating around you guys and and as a result can find the resources they need. Does that sound like a summary? That's absolutely true. And of course, we're very loyal to our state of Colorado and the economic development of the state, so that helps quite a bit as well. So that's column 2, right?
Pillar 2. What do we have? What's our final? Well, we're not done with 2 yet. Oh, I'm sorry.
Because in the CERETC, the R stands for research. So as we look at the real-time issues in the first pillar, or as the education and training community are experiencing desires for change, there's research opportunities. And that research opportunity might be something that we saw as recently as the WannaCry stuff or the DDoS attack back in October. These are innovative new techniques and technologies that perhaps lend themselves to a research opportunity, and that could be in a hardware sense or a software sense. That takes place also in that second pillar.
It's principally done by interns, fellowships, and grants, and we're just getting that kicked off. Jennifer is actually in charge of making all that happen, as well as our chair of that pillar, Dr. Martin Wood, who's a senior vice chancellor at UCCS. Our endowed chair will also play a role in that research area. Fantastic. Okay, and this is, this is the new idea, basically a way for you guys to curate and derive more value out of the information that's already coming through.
Is that how you see it? Absolutely. But more importantly, to move forward to the next solution or the opportunity. Yeah. Okay.
Is that the end of— that's the end of the second pillar. All right, so the third pillar. The third pillar is essentially what we call the think tank. It's the Cyber Institute. The Cyber Institute puts on a lot of the events that Jen was talking about with regard to board director training, C-suite training, state and local elected official training, It also works policy issues, and in fact we introduced some bipartisan legislation at the national level with Virginia and Senator Gardner here in Colorado to bolster the grant opportunities for cyber organizations like us.
We work harder policy issues. Let's say, for example, we saw a problem in the first pillar of the Response Center. It transitioned over to the research area and we find a great solution, but there are policy or legal issues that keep that from moving forward as a viable solution. The Cyber Institute would work those issues at the PhD levels, postdoc levels. We have a fellowship program that's just kicking off that Jennifer also runs, and we hope to be able to work those problems a little bit more rigor.
Another aspect of the Cyber Institute Institute, not only with the think tank but this kind of cybersecurity for all. And really, that aspect of cybersecurity is not just an IT problem. This is where we're really honing our skill set, and it's doing the cybersecurity training for CEOs, for boards of directors, general staff. And it's doing everything from cybersecurity hygiene, how to be a cyber citizen. Who are the attackers?
What are they after? How are they getting your data? What are they doing with your data? You know, not to, not to be crass about it, but when they come in, we really kind of try and scare them a little bit so they realize, hey, there, there is a problem here. But not only, you know, we have one of our sessions that we do is Life's a Breach, and what do you do, you know, when it, when it happens?
You know, how do you, how do you communicate this you know, to your staff? How do you communicate this to your legal? How do you communicate this to the media? So we really do all of these different trainings, whether it's fiduciary responsibility. A lot of boards of directors don't realize that there is a fiduciary responsibility.
If, God forbid, your W-2s get hacked, what happens? Um, cyber insurance— this is a whole wild, you know, I mean, it's just coming up. Cyber law— there are things right now that are being fought in the courts right now. We don't know the outcomes to them because there is— it hasn't happened yet. So really just explaining to people, what are your options?
What are the rules? What are the rules of engagement today? Rules of engagement for tomorrow are going to change. So we really want to incorporate all of this cybersecurity training into this Cyber Institute? It's already there, and that's part of the monthly training initiatives that we have.
Law and insurance and budgeting, the financials, communicating from the boardroom, from the server room to the boardroom is really essential for board directors. I mean, cyber is somewhat generational. You look at most board directors, they're not as familiar with the technology as some of the folks who are working in that IT shop. And how do you communicate that? How do you communicate and understand the priorities?
So, so who are you targeting to educate? Are you targeting— it sounds like some of it is for the business folks who may not know a lot about security, but then some of what you were talking about was pretty in-depth, you know, research that would be targeting, you know, very in-the-weeds, granular, highly technical people. Do you— are you targeting anywhere all the way around? Did you have a few different focuses? It's a little bit of both in that capacity.
For example, Let's just talk state and local elected officials. There's a county very near here whose IT department is one person, right? And then most of their elected officials are grassroots folks who really don't understand cyber at all. They come up from other careers and other areas. But these are folks with a responsibility to half a million people.
How do you protect that information? How do you know at a technology level what's important, what isn't? What are you going to buy and what are you not going to buy? Liability issues and where are you on the hook for all this stuff. So, that's just one county.
Now, multiply that by the state of Colorado and then by the United States and all the parishes and counties that we have, this problem is prevalent throughout. So, that's our target audience. But in that audience, just in the state and local elected officials, you have the technical guys and you have the very basics that really need the basics. So, again, kind of going to who are you focusing on, It really does depend on who the audience is. Boards of directors, we're probably going to talk a whole lot more about governance, fiduciary responsibility, law, insurance.
And then when we're talking to elected officials, again, it's kind of getting in there, showing them where the issue is, but then showing them how to protect themselves and what threats really are out there. So it kind of depends, I mean, from that target market standpoint. But the beauty for us is that we really customize the package What do you need? There is a local company that we're doing a training for their staff. They get hit with wire fraud a lot, so the training is going to be specifically geared towards how do you avoid wire fraud.
There's a, there's a recent example, another county nearby whose school district got, had a DDoS attack, got attacked. They called, I believe, the FBI first And the FBI said, sorry, we can't help you. They called law enforcement, the local law enforcement, I believe the sheriff's office, and they said, well, call us when there's a crime. Then they called the National Guard. The National Guard said, well, we certainly have the talent and technology to help you, but we don't have the funding or authorities.
Call the NCC. And so that's kind of how that circle works. And now we're in a project with that school district to help them in a secure fashion. Um, it sounds like you're doing a lot of different kinds of education. You know, I, I wasn't aware you were doing, you know, for specific companies.
That's, you know, a little bit different than, you know, the public meetings and stuff that we've talked about in the past. Uh, who— why should someone reach out to you? Who do you want to have reach out to you for training? Uh, everybody should reach out to us for training, largely because of, as Jen was saying, we're, we are a collaborative organization. So, we can bring a lot of different skill sets in various capacities depending on the audience.
But one of the important distinctions between our Center and every other Center in the United States, so every single one that you look at, I think Jen was mentioning this on the way up, is either a .gov or a .edu. We're the only .org, and there's a reason for that. We don't receive state funds, we don't receive federal funding, and because we don't have appropriated monies, we're not subject to the Public Records Act. If you had a breach at at Ping or wherever, then certainly you can contact us and it stays confidential between you and us. What we will do for you besides giving you the response solution providers on a technical sense, we'll also offer up folks who are experts in the legal arena, the insurance arena, the public relations and media arenas to help you deal with that breach, but it always stays between you and us.
So, since you're not taking, you know, federal or state money, how do you get funds? And are these all for, you know, You know, for fee engagements we're talking about? That's a great question. We started largely with philanthropic donations and grants, foundational grants, corporate grants. We were still very dependent on that as a startup.
We are developing our own revenue streams where there is an opportunity to pay for a subscription for the ISAO information, for example, or for discounts or participation at different activities around the nation or even our own events. Typically, we find corporate sponsorships and scholarships for folks who don't have the ability to pay for it themselves. And we are in a big building, as Jen was pointing out earlier. We have other partners going in that building with us, and they'll be subleasing space for us. So we're building our own revenue streams.
But as you dissect the future, at the 2-year point, we're probably just under 50% of donations, and then at the end of our 5-year plan, we're, we're still partially dependent on those donations and grants. So if someone calls with, you know, in the middle of an incident, is that a fee-based engagement? No, we would immediately answer the phone and provide that service at no cost. To pursue it any further in terms of solution providers, forensics for example, that would be a fee-based engagement. So, and as a nonprofit, this is extremely common when, you know, we're working with partners and somebody's in the middle of middle of a crisis, uh, there is a referral fee that with the partners so that if somebody does, you know, a company called us up and said, hey, we need to encrypt our email.
And I said, great, we're going to give you a couple of companies that do it. We have partnerships, sure, with those companies. So there is a referral fee. That's a piece of it. As Ed said, you know, rent from any cyber mission companies, yeah, um, that's going to be a piece of our, our revenue.
Events and programs is about 15 to 20%. And events and programs, even those trainings, all of that kind of goes in there. So the trainings, there's a, there's a fee to attend generally? Yes. Yeah, sure.
Yep. And it kind of depends, you know, I mean, is this— do you want an all-day training? Is this a 4-hour training? Probably our sweet spot at this point in time, because we get it, time is money. You're not going to send your staff out for an all-day training, but typically about 3 hours.
We have a 1-hour training that is that cyber kind of cyber hygiene, Cyber Citizen 101. We show people kind of what a social engineered attack looks like. You know, a lot of times what we are combating is cyber fatigue. People know the risks and they know the solutions, but people just kind of say, you know what, I'm still going to go to the local coffee shop and I'm still going to download the song and I'm still going to put my credit card out there. And so it's really, we really want to change kind of the attitude and it's really kind of a cybersecurity culture, changing that culture of people protecting themselves.
And in, you know, cyber, you know, the cyber threats, they're getting more and more sophisticated. So we as the victims need to get more and more sophisticated in protecting ourselves. So that's really kind of what we're here to do, and that's, that's what we're screaming from the rooftops. That's great. So, um, a while back I had John Everson.
John is the CISO for Dish Networks here in Colorado. He was on the show and we were talking about, um, he was, he was asking about better ways to start really engaging people who, you know, not preaching to the choir, not going and doing a security talk to a security group, right, but going and getting more involved with, uh, the business leaders, the, the finance folks, you know, someone other than security. And it sounds like you guys might be at a place where you, you can offer that type of an opportunity. If there are volunteers, uh, listening right now who'd like to be engaged and, and help out, uh, what kind of roles would you have for them and how should they get a hold of you guys? Sure, it kind of just depends what do they want.
If they're super technical, hashtag get your geek on kind of people, we're probably gonna have to grab their help in the rapid response. If these are people somebody just says, look, I want to be involved in, you know, something happened to me and my, my grandmother was hacked and so now I have a soft spot for it, if they want to help us with these programs, here's the deal, we're working with our local BBB, our local SBDC. To your point, we don't— Small Business Development Center. So they help small businesses. So we really, you know, clients that we're working with now, large equipment manufacturers, title companies, real estate companies, those are the types of businesses that we want to help.
Exactly what you were just talking about. Don't talk to the choir. We need to turn around and we need to talk to the congregation It goes back to that whole cybersecurity culture shift. It's not, you know, Joe or Susie who's your IT department. That's the thing is so many businesses say, oh yeah, we got cybersecurity, we got our IT guy on it.
That is not cybersecurity. It's everybody making sure that people don't use bunk, you know, USB drives and updates. You know what's kind of happening Right now, where Europe, you know, just got— it was a massive attack. If people would do their updates, you wouldn't be, you know, the low-hanging fruit and as vulnerable. So it's just getting out there and teaching people those simple fixes.
We have one title company who has asked us to write a couple of papers for them at different levels for different audiences, to put on training for their staff and to put on training for their realtors. Believe. Yeah, they're vendors. So I mean, none of those are cyber people, right? It's all about getting the message out to the wellness of the folks.
So if people want to volunteer, how should they get a hold of you guys? Best way is probably just to shoot me an email. It's jfurda@nationalcybersecuritycenter.org.
It's the longest email in the world. Clearly NCC was taken. So it's jfurda, F-U-R-D-A, at National Cyber securitycenter.org. Can I put that in the show notes? Okay, absolutely.
Uh, we have a volunteer form that we ask people to sign, fill up, just so that we can start our database. Uh, Ed and I were joking, he was like, you should get a volunteer to start your volunteer database. It's not a bad idea. But again, whether you're super technical or you just want to help us out and you want to help run registration at one of our trainings, we really can use everything You know, as I tell our interns as they come in, you could be doing something as mundane one day as stuffing envelopes, but then the next day helping us put together a cyber exercise. Anything we ask you to do, it's, it's, if you weren't there, we would be doing it ourselves.
We'll eventually have a link on the website that will allow you to volunteer. Absolutely. The website is undergoing some modifications now to ensure that we can put that link on there and keep it secure to some level. So, we'll continue to do that. Of course, we have our social media as well.
Facebook, LinkedIn, and Twitter. Follow us. And if folks, you know, do they need to be in Colorado Springs to volunteer? No. What are the right places?
Gosh, any academic institution or company or ISSA guys. I mean, anybody that wants to volunteer anywhere. Cyber is so virtual, it doesn't necessarily have to be in our same regional area. And we're taking the show on the road. We're about to do trainings in Idaho, Utah, Wyoming.
I think we have one coming up in DC. So as we're branching out, and part of this volunteer form is where are you, so that if, you know, we have something going on, we can reach out and have people come and help us out. I'd like to add one more thing to that last pillar if I could. What we also do there are major exercises, and we just did one, for example, on critical infrastructure. It was principally electric grid-based but other utilities as well.
We got one coming up September that's healthcare-based. It's got a large sponsorship, large participation of about 200 people or so. Jennifer's in charge of this as well, and the scenario will follow a track of both ransomware and compromised IoT devices that causes casualty. That sounds, that sounds really interesting, and I know there's some other healthcare groups in town that we can forward this over to. Yes, and we're partnering with some of them already.
I'll translate that. So yeah, again, partnership, partnership, partnership. And we'd be happy to come back on. Yeah, and you know, as a nonprofit organization that's here just for the good of the community, we're happy to help anybody anytime and look forward to it. Well, certainly your guys' vision aligns very closely with what we— our vision here at Colorado Equal Security.
We look forward to hearing about your guys' success going forward. I don't know, maybe 6 months from now we can reengage and see what's changed in the last 6 months. I know you've only been going for 6 months so far. Yeah. So there's going to be, you know, I assume a lot, a lot of iterations as we go.
Any final comments before we call it a day? Well, our largest and longest training event was our kickoff event in November of last year that Governor Hickenlooper hosted. We'll be doing that again this year. It's a 3-day event. It brings in a lot of different states, governor level and other elected officials.
So we'll be doing that again here this November. So we can scale this to an hour or to 3 days at the national level. So it depends on what our customers and clients would like. And we'll definitely have that, the details on that event on our, on our website as it gets closer. And we'll talk about it here before we get there.
Excellent. Thanks for having us. Thank you for being here. Thank you very much. Good luck.
Learn more about the Colorado security scene at colorado-security.org. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.