All episodes

James Carder

Apple Podcasts Spotify SoundCloud

In this episode:

LogRhythm CISO James Carder is our featured interview. News from Secure64, LogRhythm, Ping Identity, Vector8 and Managed Methods.

100,000 Cosplay-ers can't be wrong

We hope you've recovered from a week of cosplay, fireworks and flag waving, and you're ready to get back to the real world. The news never stops here in Colorado. Besides Comic Con, we got news that a local college placed in a national cybersecurity competition, Secure64 looks to secure DNS for major carriers, LogRhythm and Ping Identity win prizes, and blogs from Vector8 and Managed Methods.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. We're continually working to improve the show, and appreciate the feedback we get from our listeners. If you discover any audio issues, or have suggestions for our format, let us know.

This week's episode is available on SoundcloudiTunes and the Google Play store. Reach out with any questions or comments to info@colorado-security.com

Feature interview:

James Carder has had an interesting career on his way to Denver. From Air Force, to Raytheon, IBM, Mandiant, the Mayo Clinic, and finally LogRhythm here in Colorado, James has had a great career. He sat down with Alex to share with you all.

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11881 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security episode 23 for the week of July 10th. Alex, how are you doing? Are you recovered from the vacation?

Well, you know, technically, Robb, I'm still on vacation. Um, until Monday when I have to go back to work. So I'm not technically recovered yet. I'm still trying to take advantage as much as I can. Yeah, I got, I got back into town Saturday and was, was excited to not have to wake up the next morning and go right to work.

Yes, that does make it nice. Yeah, it's been good. But, you know, we've spent the week up in the mountains. I think you did as well. Um, you know, we went to Snow Mountain Ranch, which is the YMCA camp near Winter Park, did some— um, they have a tubing hill all year round.

It's a tubing hill. We did archery and did some crafts and just had a good time with family. How about you guys? Nice. We were up in Breckenridge for the week, which was a lot of fun.

It was much cooler, which was nice. I heard it was pretty hot down here. Fires, though, right? We had a fire that was close by. We were on voluntary evacuation orders for a little bit there, but we stuck it out.

Was it smoky? It was a little bit smoky depending on which way the wind was going. So the fire in Breckenridge was on Peak 2, and we were staying on Peak 7. So if you can do math, that's 5 peaks away. Yeah.

Well, I'm glad you had a good time. Welcome back. Let's get back to the real world. While we were up enjoying our family and the holiday, many people were in downtown Denver dressed as the Silence from Doctor Who. And I don't know, I'm sure there's a number of Marvel characters.

Yeah. A lot of cosplayers down at Denver Comic-Con. So, you know, the annual Comic-Con came into town. We had, what, 115,000 people? And it looks like from the newspaper article, about a $10 million economic boon to the area.

Yeah, that's really cool. I still have never made it to Comic-Con for one reason or another, but I would definitely like to make it down there. It's been a— sounds like a meteoric rise from, you know, a small gathering to 115,000 people. Yeah, so I, I had— I didn't really even know what happened. I knew that there was an expo floor where people like sold stuff and you could buy whatever, you know, comic books and whatever.

Um, so I asked a coworker who was going and he gave me the lowdown and it's really not that much different than, you know, a normal security conference where they'll have different track sessions and you can go in and talk about like, this session is going to be telling you how to make a costume. And this, this session is going to be a Q&A with what's the guy's name? Nathan Fillion, the guy from Firefly. They just have different track sessions where you go to learn about whatever random stuff you want to learn about. Yeah.

And I think— I'm not sure if at the Denver one, but many of them, they do, you know, reveals of, you know, upcoming movies or TV shows or other things like that, cast members, that kind of stuff. So I was not aware of that. Yeah, they do. Yeah. Anyway, interesting stuff.

So that has nothing to do with security, but it's kind of a fun story. Also something that has nothing to do with security. There's a story this week about a Colorado high school robotics team that took a world championship and is now on to the champion of champions event. Yeah, so they won the event in April that was the world championship against 128 teams from around the world. Absolutely, they are the world champions right now.

And it looks like they're from Highlands Ranch and their robot is called the Millennium Falcon. Yes, it did not mention the high school, but they are high school students. It sounds like at the end of the month in New Hampshire, they're competing against other champions from different competitions. It was from Montana, right? It was just one.

There's just 2. There's Champion A against Champion B. It is the unification battle to see which one will be the true world champion. Unifying the WBC and WBA belts so someone can be the true world champion. Well, you know, our rooting goes out for the Millennium Falcon folks from Highlands Ranch, and we will certainly cover it if we hear that they win.

If they lose, we'll probably bury it as deeply as we can. Also, a shout out to my now nephew Avakai Cooper, who is actually right now as we speak competing in West Virginia in a robotics competition as well. Not the same competition. All right, let's go. Uh, so another piece of news from local education.

Red Rocks Community College won a National Science Foundation, uh, competition. Actually, they came in second place in a National Science Foundation competition for the work they're doing on cybersecurity learning. Yeah, so they did some work to create essentially lab environments that people can use to, to do their learning in. To play around and not have to worry about, you know, hurting actual production environments or other things like that. The competition was not a security-focused competition.

So there were other community colleges with projects that were not security-related. But this was one I believe that they came in second. Yeah. It's neat to see just looking around the Denver area, the Colorado area, how many different schools are getting in on the act on trying to really make a difference around cybersecurity. Recently spoke to folks at Colorado Community University, college, whatever that is.

Excuse me, Colorado Christian University, who are looking to start a master's program in cybersecurity. And we've talked about, I know DU does a lot of stuff there, CSU, CU. Regis. So there's just a lot of great educational stuff going on in town and neat to see Red Rocks getting in the act too. Yep.

So Secure64. Uh, they had an announcement. Uh, they are teaming up with Mavenir to bring NFV-ready IMS to carriers. So Secure64 is a, uh, is a Denver-focused, headquartered Colorado, that helps do secure DNS devices, appliances. That's, that's been their specialty.

And I got to meet with their CEO earlier this year. I've been thinking about bringing him on the show. I understand what they do around secure DNS appliances. What I'm, I'm not sure exactly what Number one, I don't know what NFV is, and number two, I don't know what IMS is. So really at some disadvantage trying to read this press release.

Yeah, you know, you look at the press release and it is— it does go over my head a bit as well. But I think the important point here is they have a new partnership and it's aimed at carriers, and those carriers are definitely going to be very excited.

LogRhythm has added yet another trophy to their trophy case. They won the 2017 Forst and Sullivan Asia-Pacific Enterprise Security Product Line Strategy Leadership Award. They must be, uh, have a pretty big trophy to put all those words on it. Yeah, I wonder if there's some kind of acronym happening there, but congratulations to LogRhythm on that win. Uh, also, uh, Ping Identity, they get another trophy for their trophy case.

Um, they were named a— for KuppingerCole Leadership Compass on customer identity and access management. They were, they were named a leader. It sounds like a Gartner leader magic quadrant sort of thing. Is it similar to the magic quadrant or Forrester Wave but for Cupringer Cole? Managed Methods, who is the CASB up in Boulder, they have a blog that we found kind of interesting this week, really focused on schools that use Google Docs for their collaboration software.

Yeah, and of course, you know, Google Docs and G Suite is not limited to education, but it seems like they have made a big penetration into that market. Pretty much have taken over all of education for that kind of thing. And as I think you probably know, Robb, G Suite is great, but it's not the easiest to secure. Yeah, it's really easy to do it wrong. And I think that their point here is just if you're running a school and you're using Google's G Suite, you need to start thinking about how do you secure it and how do you make sure you're not making a bunch of kids' data inappropriately locked out.

Of course, their product offering does help secure those things. So there's, I'm sure, some self-interest there. But I do think that this is something if you guys guys have kids in school, you might want to mention, hey, are you guys thinking about how you secure this? Would it be really easy to get access to the wrong data there? Yeah, and at the bottom of that blog post, there's a link to a case study with, I think, Steamboat Springs Schools and how they're using managed methods to help secure G Suite.

So the last article we have here, Vector8, The 5 Dimensions of Hunting. So Vector8 is a They create a platform to help you with threat hunting. Um, so this blog, they were very nice and they put a TL;DR right at the beginning of it in case you didn't want to read the whole thing. Uh, so they want to show you how to qualify your data with scope, resolution, animation, qualify your analysis with technique and accessibility. So, uh, this talks through really the process of doing threat hunting in a little more detail about it.

I think a lot of times when people say threat hunting it's just sort of amorphous. It's like, I'm going to look for it, but this is really more a methodology of how to do that. It's one of the trends that's really picked up over the last year or two, and I personally think there's a lot of value there, but you know, you need to define it. What is it? What does it mean?

And how do you get lots of value out of it? So if you're trying to get value out of it, Vector8 is doing a training course on threat hunting here late summer. You go to their website, which we have a link for in the show notes, take a look at, at the training course. You can get signed up and hopefully you know, learn how to get a lot of value out of it. Before we jump over to events, we did want to mention, you guys, if you're listening to this on SoundCloud or you're downloading these individually, we'd appreciate it if you'd go subscribe either in iTunes or Google Play or wherever you get podcasts from.

That way you'll have the podcast delivered directly into your, into your Play Store every week, and we'll of course have more people subscribed. Yeah, if you use a podcasting app to, to listen to your podcasts, Uh, most likely you'll be able to search for us in whatever search feature they have, find it, and, and subscribe to the podcast. All right, let's dive into the, the news for the week. As a reminder, we do have a calendar of events, everything going on for the next few months there at colorado-security.com. Um, so first thing on, on Tuesday of this week, the Colorado Security— excuse me, Cloud Security Alliance has their monthly meeting on the 11th downtown at the DaVita office.

Denver ISSA has their July meetings on the 11th and 12th, Boulder downtown and Tech Center. Yep. Colorado Springs ISSA has their monthly meetings the evening of the 12th and lunchtime on the 13th. Uh, on the 13th, SecureSet has their expert series, uh, Brian Becker from Cronky Sports. And on the 13th and 14th is the Colorado Innovation and Technology Experience, which is a CTA event really figure out what's going on in Colorado.

It's a 2-day event where you get to go see a lot of the cool stuff we're doing in the state. And then the following week, OWASP has their July meeting on 7/19. Yeah, that'll be at Dave Buster's. And then on the 19th through 21st is the NCC's Cyber Center Chariot 2017 event. And then finally DenverSec, which was formerly CitySec, has their meetup on the 20th, so you can check out the link there for more information on where that is.

All right, and then we'll jump into the jobs for this week. And as a reminder, we have a link to each of these job postings in the show notes so you guys can go apply if you're interested. First, Ping Identity— we are still trying to hire a GRC analyst, and we would love it if you want to apply. This is someone who has a year or so of controls experience and wants to get involved with compliance and control monitoring. Trust Company of America is looking for a senior manager of information technology policy and governance.

So if you like writing policies and you like trying to get people to follow them, sounds like a job for you. Aimco, they are a Denver-headquartered management of like rental properties company. They're hiring an information security analyst. Reed Group, is looking for an information security officer, and they're up in Westminster. And that company does— was it get back to work basically for people who are sick?

I'm not sure what that means exactly, but interesting. Trace3 is hiring an identity architect. Uh, Lariz Security Consulting, they're looking for an application security consultant. And so Lariz, that's Chris Nickerson's company. So if you want to work with Chris and the cool guys over there, then apply to that.

My guess is that you need to know more than just how to run a Metasploit package. It's actually an interesting job post to read because there's lots of stuff like that splattered throughout the job post. Yeah, if you are very, very good at application or tearing apart applications, that might be a good opportunity for you. And then finally, Red Shield Security is hiring a cloud security engineer. They're actually just moving a lot of their team over here from Auckland from New Zealand.

So kind of interesting opportunity to, to get to know a company. And I bet, I bet if you work there, there's a chance to fly back to New Zealand once or twice. I think I might apply. I'd like to get to New Zealand. All right, well, I think that's it for this week.

Uh, we're gonna go ahead and have your, your interview with James Carder after the break. And James is the CISO and VP of Labs over at LogRhythm. Um, any, any highlights from the interview you want to share? You know, we had a, a nice chat, um, just about you know, his team over there, some stuff that he's done in his past. Um, I think it'll be a really interesting interview.

All right, we'll see you guys next week. Thanks, Robb. Hi, this is Jose Calvillo, CISO at ASF Payment Solutions. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

All right, this is Alex Wood with Colorado Equals Security. I am here at the beautiful LogRhythm headquarters with James Carder, CISO for LogRhythm. Hey James, how's it going, Alex? I'm doing well, how are you? Good, good.

Thanks for taking a little bit of time to talk today, looking forward to it. So you are the CISO here at LogRhythm, but obviously this is not your first position. Correct. So I'm just curious if you could first give us a little background on yourself and where you've been, what you've done in your career, how you got here? Yeah, definitely.

You know, in addition to being the CISO here at LogRhythm, I actually run our advanced research team as well. So we have a team called LogRhythm Labs here, so I'm kind of dual-hatted, and it's pretty interesting because I get to drive the security of the organization, of a security organization, and then I have an R&D team to where if I want to develop something or I think there's gaps in how we're implementing something on the CISO side, I literally just tell my other half to go and develop it for me. So it's actually a pretty cool role. But I've been in security for 20 years now, so I got into it when I was 18 years old. Joined the Air Force, did 4 years in the Air Force, you know, primarily focused— I started out as a network guy.

They said, hey, this new thing called security in the mid-'90s, and we need, we need some smart folks to do it. So they said, would you like to do it? I said, sure. And that's really how I got my start in security. And so I did that for 4 years, got out, went to work for a defense contractor.

I did some exploit development work, did some consulting work with them, did that for a couple years. And then I said, I gotta get the hell out of the government. And then enough of this bureaucracy, right? That's right. You know, people, you know, strict on everything.

And And so I, you know, even though the fun— the work was fun, most of the work I probably can talk about now on the exploit side for the government, but I probably shouldn't, especially with all the latest news and things like that that have happened recently. So I'll keep things quiet there. But went to work for IBM after that, spent close to 5 years at IBM, you know, working with some of your old colleagues, Alex. Yep. You know, we did ethical hacking, pen testing, some exploit dev, as well as just general security consulting.

And so I left the mostly offensive-focused world and went into the incident response world after that and worked for Mandiant before the FireEye acquisition. Spent almost 6 years at Mandiant. I ran their New York City office. I ran their criminal kind of contracts with the FBI and a few other kind of government organizations there. So if you combine all that, I spent pretty much my entire career consulting at that point in time and then went, learned my lesson of leaving IBM after the ISS acquisition.

And I was a part of X-Force then, but just wasn't what I wanted. I learned my lesson there and decided, you know, I'm gonna leave before this happens. And there's some folks in the leadership levels of FireEye that I really didn't see eye to eye with, so I decided to leave and I went to Mayo Clinic and spent a couple years there. And, you know, it was the CISO, the new CISO at Mayo Clinic was actually the old CISO at a customer of mine back when I was at Mandiant. And so he left that organization and went to Mayo and asked if I'd join and build up their program from the ground up.

So I did that for a couple years, but then I realized that I when you're at the front end, cutting edge of technology and security and everything else, and you're seeing all the latest incidents in the world and the, you know, all the cutting-edge threat intel, and then you go into healthcare, uh, and that's about a 20-year shift in time for you. Yep. Um, a little bit of a different beast there. A little bit of a different beast. Very political, very, you know, very, uh, you know, regulatorily driven, if you will.

But, you know, I went from, you know, investigating intrusions that were in the news and all the latest things to explaining to executives what phishing emails were and why they could be potentially damaging. And so that was a 20-year shift in time that I thought I was ready for at the time, but I really wasn't. I did about a couple years in healthcare, and then, you know, I got a relationship with LogRhythm through that, and the CTO and co-founder here said, hey, if you're gonna leave Mayo, how about you come here? And I was a director of what they call security informatics at Mayo, which really means I was in charge of incident response, threat intelligence, the operations center, as well as the red team side, which included both, you know, kind of traditional red team activities on vuln management and pen testing, but also included things like testing of medical devices and stuff like that. So that part was actually really cool.

And so jumped ship and came over here to LogRhythm. Been here for 2 years and building this program up as well. So the Mayo Clinic, obviously not in Colorado. Yeah. So was it strictly LogRhythm that got you to move to Colorado, or did you have other desires to move away from where you were previously?

Well, Colorado had always been on my list as a location that I would be willing to move to and kind of settle down in. And I wasn't yet at the settle-down stage. I had, you know, I met my now wife in New York City when I was with Mandiant, and we both moved together to Minnesota. And we gave it a shot, and it's funny, we joke around now because my wife actually went to college in Minnesota, and so she thought it was great. And we go there, and there is a term you hear called Minnesota nice.

And I like to call it Minnesota passive-aggressive. And so, you know, and Rochester was very much where Mayo Clinic's located, is just a smaller community that's all built around Mayo Clinic. And so you couldn't even go into a restaurant without having another Mayo employee there. You couldn't even do anything. And so it just, it just felt real kind of closed off, and my wife and I didn't really like it as much.

So, you know, that's what brought us to Colorado. But yeah, I mean, the logarithm opportunity was a great, I guess, opportunity to match up both an area that I wanted to live in and a pretty cool company and job. So nice. Yeah, I spent a couple summers in Minnesota, and so I definitely get the Minnesota nice. It's a great place to be also when the weather is not bad, which is a short period of the of the year.

Yeah, when I was building the program up there, I used to joke around that our recruiting season was about 3 months long. It's only during the summer. Yeah. And usually from about July to about September. And after that, it starts getting cold again, and before that, it still can get cold.

Yeah. And the funny part is people always think of Minnesota as maybe a place that gets a lot of snow, and it was actually a place that got a lot of snow once and then just never melted. And so you just had this constant like foot of snow in your yard all year long. So yeah, I think we're really spoiled here in Colorado with, you know, it snows and it goes away, as opposed to sort of Midwest where it snows and then gets gray and black and that's right, just sits around for the rest of the winter. Anyways, I want to jump into a little bit of your experience.

So you spent a lot of time doing incident response.

It sounded like a little bit with the testing of medical devices. That sounded pretty cool too. But on the incident response side, from the incidents that you've seen, are there any patterns? Is there stuff that people should be doing that they're not doing? I know we hear a lot about the basics and other things like that.

Is it just that we're just, we're not doing the things we need to be doing, or are there other patterns that you saw when you were doing incident response that can help people be better at doing security? Yeah, you know, I think that— I think first you have to do is you kind of have to separate classes of incidents. You know, you could be, you know, in the pool called, you know, victim of kind of like chance or circumstance, right? You have like, you know, people drive-bys on the website, on websites, and pulling stuff down, or phishing emails and things like that. Then you've got the more targeted attacks.

I generally think as a good rule of thumb is, yeah, I mean, if you're really good at the basics, if you just take like the SANS Top 20 and you start working through that, that, you know, calling them the basics makes it sound easy, but if you actually look at that list and if you have a complex organization, it's actually pretty challenging. I think it's more like the SANS Top 127 or whatever the— yeah, the 20 breaks out. Yeah, that's right, that's right. But I mean, you know, it's It's a good starting point, and if you can get good at the basics, you get good at keeping your systems up to date, backing them up, patching them, implementing good compensating controls, knowing where your critical assets are and not, and just applying some level of control around that, you're usually in pretty good shape. Most of the— I think I counted recently, I did something like 160 different incidents or something like that when I was at my previous organization, and the majority of those just were were really bad at IT and just general security practices.

And so that's why I think you hear people a lot say just get good at the basics, is because if you're at least good at the basics, you put enough of a barrier there to where, you know, you may not be an easy target. You may not be somebody that says, oh, you know what, I can compromise them tomorrow because they're just really bad and then steal their data. You're gonna, you're gonna create a little bit more of a barrier that they're gonna say, you know what, let me move on to the next person, or let me move on to the next company, and you make it at least a little bit challenging for them. It's like putting a lock on a door. I mean, you can obviously break through the lock half the time, but it causes people to think about, well, maybe I'll go to an easier target.

So I think that's one aspect of it, but I think if you're an organization that's gonna be targeted, you know, whether it be a nation-state threat actor or something like that, if you're really good at the basics, you're probably still gonna get broke into, and that's just you know, if someone really wants access to you and your data, the likelihood is pretty high that even if you have a pretty decent security program, pretty decent IT controls, and IT practice good IT hygiene, you still may probably have a high chance of getting broken into. And that's something that we saw quite a bit. And then is it just making sure you've got a good monitoring and response team, or what's your recommendation for there? You know, you're being a target, you're doing the basics. What's your next level?

Yeah, I mean, I think not only do you have to raise the bar on the basics into a higher level of maturity for your program and really go after kind of those, you know, you may be a case where you might start looking at some niche technologies and cases to be able to, you know, augment or supplement your security program. But then yeah, having a good and practiced instant response program is key. Is whenever you do pick something up or you do get notified by a third party or the government or something like that, that you have the ability to be able to react quickly and contain the situation. And I think that's probably the differentiator between most companies is when you look at maturity of a security program is, you know, it's easy to say, hey, I had a malware breach breakout or incident at a compromised system of ransomware, but yep, you know what, we picked it up, we saw a new process spinning up on that system, we were able to contain it, boom, done, closed deal. It's different when you have an advanced threat actor that's targeting you that may not be using just commodity malware and that's, you know, hiding more under the covers.

And the larger and more complex your organization is, the harder it is going to be able to detect. But you have to kind of add that next layer of maturity, next layer of technology, next layer of visibility into that, and then be able to get to it quickly. Because if you can at least understand what's normal and not normal in your environment to a level, you can usually pick up those advanced threat actors. And that's, that's a really key area that a lot of people don't focus on. They rely on these threat intel companies giving them feeds of IOCs and signatures.

And this whole IOCs thing, you know, you know, in my Mania days, we talked about, you know, we actually, you know, had Open IOC. We were the ones that created Open IOCs. And IOCs is this thing where you, you know, you'll get this one signature, this one indicator, and then you go look for it. And really, people should really look at their own data as a source of threat intel and be like, hey, look, this is normal behavior. Hey, look, this is an outlier.

Let me go look at that. And that's how you're gonna pick up on more of that. And the quicker you are, if you're in an organization that's mature enough to be able to do that and then quickly respond and investigate, respond to that, that's going to put you in a really good spot. So yeah, I think that the, the baselining, the anomaly detection is great. I think that's, as a practicality, I think that's hard for a lot of people.

Yeah. Um, what do you recommend for people being able to get that kind of capability in place? I think, I think the first thing is, is maybe limit your scope. Uh, don't try to tackle your entire environment at one time. I think that's where probably a lot of people make a mistake.

They try to eat the whole elephant, if you will, is to take a look at what are your most critical systems. What are the ones that if they took an outage, your business would go down or be down for a period of time and you'd lose money? You know, what is it that drives your core business and start there. Look at the normal there. You know, in the healthcare world, medical devices don't do a whole lot of different things.

They have a function, they have a certain application that drives that function, and they stay pretty static. The communication is pretty static. You know, they have— some of them have a built-in ability to kind of do the computing aspect of things and running applications and updates, and some of them have a backend controller that does a lot of that, similar to ICS systems and everything else. They communicate the same way, they do the same things. If all of a sudden you've got someone RDPing into one of those devices That's not normal.

It's a really easy indicator, but we focused and looked at that because if a medical device gets hacked into, especially when you're dealing with high-profile patients, the last thing you want in the news is the fact that this hospital let this medical device get broken into and it killed a patient. Any patient, let alone a high-profile patient. So look at like what's critical to your business and the system and start there and kind of build that first, that baseline first around that and kind of expand beyond that. I think that's great advice, and you did, you did a perfect segue for me, uh, into the next topic of medical devices. So, uh, you know, there's been a lot of research, uh, over the past few years about, uh, medical devices and their insecurities.

In your time at Mayo, how bad are they really? You know, I, I don't even know if I'm allowed to talk about that stuff from my time at— from my time at Mayo. We'll just say that, um, From your industry experience. From my industry experience, thank you. You know, I think they're in pretty bad shape.

You know, the interesting part is I've been at, you know, NH-ISAC meetings, which is healthcare's version of the, you know, their version of like FS-ISAC, which I kind of look at as the best ISAC that's probably out there right now. I've been to other conferences and things like that, talking to folks about medical devices, and a lot of the manufacturers are like, oh yeah, we now have a focus on security. We're now doing this. We actually are now testing our devices. We're now making them like, you know, using NIST as like a framework to harden them and do the right thing.

And I think that's good, but that's only happened in the last couple years, and as we know, most hospitals don't buy new medical devices every year. So they're running devices that are 5, 10 years old, still running Windows XP, uh, still running even older operating systems than that. Some of them I've seen, they're like Linux kernels that go back to like the early 2000s, late '90s, uh, which was surprising. Uh, you can do basic old— my old hacking skills and break into a hospital, which is pretty, pretty bad. You're not a cutting-edge Not anymore.

And, you know, I don't want to say I was an elite hacker to begin with, but like, you know, if you can knock down devices with like UDP floods and things like that, you know, your basic scanning products, that's a problem. And so, you know, I look at all these manufacturers and what they're doing now, which is great, but what they have not considered, and the question I always ask is, what is— how do you apply that to all your legacy equipment that's already out there? And there's no answer for it. There's like, we're basically not gonna even address it. The hospital is gonna put in compensating controls around it, and we're gonna move on with our current strategy.

And that's kind of the consensus that I've gotten from a lot of the manufacturers. Do you see the hospitals putting in those compensating controls? You know, I spent some time in the energy industry and SCADA and that kind of stuff, and it was, oh yeah, we're gonna have, we'll have, you know, air-gapped, in quotes, networks, separate networks for all the control systems. That obviously is one potential compensating control for the medical devices. Do you see anything like that happening?

Sometimes. I think some probably healthcare institutions do a pretty good job of that, of segmenting those network devices or segmenting those medical devices off onto their own segment and and not having that communicate with the core infrastructure. The problem with that is that there's always exceptions to that. And there's a— and, you know, the thing with medical devices, it may be different with, I think, ICS and energy devices and devices in the energy sector, is that medical devices move. So I might be on, you know, I might have a monitoring station on one floor in a building.

I may wheel that thing all the way over to a different building on a different floor. And so while the ideal of network segmentation is great, you have to consider the fact that in order for the hospital to operate, they have— a lot of this stuff has to be mobile because they just don't have one for every room, etc. And so I see them doing it, but also see it as a challenge, and I don't think there's enough compensating controls being put around them, especially the vulnerable state that they're in. Yeah, and sort of the other side of that with the medical devices too is, you know, you've got a lot of them that move around, but then on the other hand, you've got a lot of them that are gigantic, and, you know, they build the hospitals around these devices, and so they're never going to change. It's going to be 20, 30, 40 years before they replace an MRI or something like that.

Yeah, an MRI is not moving anywhere anytime soon. No, for sure. So that always makes it hard too. Yeah. So let's shift gears again a little bit into your, your current role here at LogRhythm.

So you, in your introduction, you said you wear at least 2 hats. That's right. You know, in our conversations before this, it sounds like at least maybe one other hat, maybe more than that, that you have. So, you know, I run a security program, and while I do other things outside of that, like do these interviews. I technically really only have one hat.

So how do you— what's your time that gets allocated between these different hats, and how is it you manage that time? Yeah, you know, that's, uh, time management I think is a skill set that everybody needs to have if they want to kind of grow their career out, especially get into management, because, you know, you're gonna get to a point where you're gonna have to do multiple jobs where multiple hats, and even if you have a primary job, one of your kind of unspoken, unsaid jobs is probably to help enable all the other leaders around you. And so you really have to figure out how to do that, how to allocate your time effectively. Now a lot of people would say that's just part of my main job. So, you know, to get back to your question about my situation here at LawRhythm, you know, we have the CISO job, which is For a security company, it's important because if we got breached or got hacked or whatever it is, I'm sure all of our customers would say, what the heck?

And, you know, we would be under the microscope of, did you have the right controls in place? Did you practice some due diligence? Did you do all the right things to make sure that, you know, you at least had the basics in place and that you were doing a pretty good job there? We can't, you know, we're not a massive company, you know, with, you know, hundreds of thousands of employees and billions of dollars in revenue to where if we took a— all we do is security. So if we took a hit, that is pretty damaging for us.

The lab side, so I probably spend 50% of my time as the CISO of LogRhythm. The other 50%, and I'll sprinkle my third hat here in a second, is really focused on the research and lab side and driving that mission because my background's in incident response, my background's in threat intel and pen testing and things like that. So we want to drive, and even compliance during my consulting days, so we want to drive compliance and threat research back into our product because one of our differentiators is to be able to do that so our customers don't have to. Have to. So we do all the threat research, we'll do malware analysis, we'll look at intel, we'll look at all the changing kind of TTPs that are being used by the attackers and drive that back into our product.

And we'll drive in all the latest compliance packages and governance that's coming out, we'll drive that back into our products so our customers don't have to build it all from scratch. So it's our differentiator. So both of them are really critical to our business. And then, you know, the third hat that we kind of joked around about earlier earlier, which is, you know, marketing and PR. I think that the best part about it is that I am not officially a salesperson, so I am not part of the sales organization.

I don't get a direct kind of revenue or direct income around like a bonus around, you know, making certain sales. I don't get anything like that, and so really they, you know, with the see someone in the labs role in my background, they just say, be a thought leader for us in the space of security. And oftentimes that leads to webinars, presentations, conferences, customer meetings, prospect meetings, only because I will speak to things differently than what our sales folks will speak to. I'll speak to it because I've built these programs before, I've done this before, and so I have a different relationship with that prospect or that customer. Or the audience that I'm presenting to.

And so they leverage that as a way to drive, you know, security thought leadership and making sure that LogRhythm is part of that conversation wherever we go. So that's, that's probably like the third hat I kind of wear quite a bit of. And on that third hat, I saw recently some video that was posted of you. You got to do an interview on CNBC. Talking about the new security law that was passed in China.

I wonder if you could talk a little bit about that experience in general. It would be interesting for me. I don't know how I would do speaking on television. It's one thing doing this and, you know, recording sort of out of band, and I can fix any of the mistakes that I have. How was that experience?

Being interviewed on a major cable news network? You know, it was, you get pretty nervous up front I think because you know there's no, you know, I always love the interviews where I get questions ahead of time, I can prepare, I can do certain things. Like today, I gave you all these questions beforehand, right? Right, right, you gave me some basic guidelines, like we're going to ask some questions and that was pretty much it. But you know, the interesting part is they actually did, they actually gave me 5 questions ahead of time, and they didn't ask any one of those questions on the interview.

So you have to be really— I think that was something too, is I got a little bit of coaching from our PR agency to say they gave us this list, but they may ask them, they may not, and they may go a totally different direction. And so you just had to kind of be ready for the unknown. And it was interesting because You know, the whole experience, you know, you get conferenced in and you see the background, you see the news station that they're in, you got all these, you know, lights flashing by you with the stock tickers and things like that. And they say, hey, you've got 3 minutes. This person will go, this person will go, this person will go.

And then come in, they'll go, you got 1 minute. In the background, you hear the anchor kind of practicing his voice over like what he's gonna say next. And it kind of reminded me of the whole like Anchorman, Brown Cow, Brown Cow type situation. They actually do some of that work, some of that voice work, uh, before, uh, they go live. Or, you know, and so, uh, once they go live, they go live.

And, uh, you know, you look back at afterwards, you're like, dang it, I said, uh, about 50 times. Um, I could have answered something differently. And I was ready to go deep into the regulation, the Chinese regulation, and they didn't go there. They went strictly high-level business impact. And so I had to keep it at a high level.

And so, you know, I would have liked to have gone deeper, but there's a lot of things that you see after the fact that you might do differently if you're better prepared or you can edit or you're not live. So I know a lot of people that do those sorts of interviews on a regular basis. Get formalized media training. Have you had the opportunity to do that? Not yet, but it's on my to-do list.

One of the requests I'm having— it's kind of funny, I think once you become a CISO or any type of executive, I think the training that you get is less and less sometimes. Your staff gets training and you drive that, but I think your training is a little less and less. One of the things that I'm actually gonna put forward is to have a lot of our execs do media training because, you know, I could have probably smiled more. I had the— I did the interview from a cabin in Steamboat Springs, Colorado because I was on vacation at the time. So I could have probably set the background.

Just look, I had a Logarithm shirt with me. Otherwise you'd see me in like a t-shirt and some shorts and flip-flops, and I don't know if that would represent us too well to the kind of, you greater market outside of Colorado. Everybody's just like, oh, you're in Colorado and that's what the look should be. But outside of Colorado, they may not get that. So, but yeah, I think media training is a really important aspect and something that I'm actually pushing for.

Well, that's really cool that you actually, you know, in a cabin, but you had the bandwidth and everything else to be able to do that interview. Yeah, no, I was lucky I had internet. It wasn't like a rustic cabin or anything like that, we'll say that. It was a nice log home. And so they had good internet there, so I was lucky enough to have that.

That's good. So on the— I'm curious, on the Logarithm Labs side of your job, what sort of stuff are you guys working on? Is this, you know, you mentioned reporting and some other things like that as part of the responsibilities over there. Is this stuff driven specifically out of what you guys see as needs Is this stuff that comes from customers? Is it just looking at the industry?

And what are some kind of cool stuff that you guys are working on, if you can talk about that? Yeah, I think it's all the above. You know, we've got a pretty strong threat research team here that came from, you know, organizations like my previous organization at Mandiant. We've got folks from CrowdStrike, we got folks from the NSA, you know, that all work as a part of the threat research side. And really They are in a— they constantly go out and they look at what is the industry saying around different attack vectors, what is our, you know, we have some underground channels that a lot of us are part of that you have to be kind of accepted into that we read a lot of that content, understand kind of like what the threat landscape constantly looks like.

And so we're always taking that data and taking those leads, if you will, and then going in and doing our own research and then generating our own content. And so some of it may be as simple as— obviously WannaCry is an easy example because I think 2 weeks ago or whenever that— finally 3 weeks ago, whenever that broke out, every vendor, every company, every organization was looking at that. So, you know, instead of trusting what the media was saying and what other security researchers were saying, you know, we pulled the code down ourselves and we do our own investigation. So we do our own analysis into it, and then we write all of our custom content for our customers so they could just pull the rules down that we wrote and protect themselves and detect so they can detect and respond. And so, you know, you know, there's a new variant of Ghost, you know, that came out, and so we're looking at that as far as what's new, what, what can we look for, what are some of the, you know, signs that it's been being used in your environment and things like that.

So we'll pull down all the latest code and look at that. We'll pull down all— we'll be involved in a lot of threat intel and threat research around that. And so it's really a true R&D function there. So that's the kind of stuff that they work on. They also work on module content for our customers.

So we take all that kind of data that we researched and all the learnings that we got from that and turn it into custom content for our customers. And so we've got threat detection detection modules that we write that leverage user endpoint and network behaviors, and we bake— and we use TTPs as a part of that to basically— so that we were not chasing all the latest signatures all the time, and neither are our customers. They can use TTPs to detect like attacks and like different threats, so we developed that kind of content as well. Compliance, you take the same thing and you just move it over to a compliance world. So they just came out with our— it's a global compliance group, Singapore MAS, which is basically the Singapore version of Sarbanes-Oxley.

They've got— they just released that as a new module for our customers out in Asia.

PCI just had a, you know, 3.2 update that's coming into effect here soon. They released an update there for those, you know, customers that are impacted by that. GDPR, you know, that's one that's probably on the tip of everybody's tongue right now. And so we're working on that. It's very actually similar to the Chinese regulation that I did speak to on CNBC where it's really privacy-centric and it's pretty vague as far as what controls are actually going to be enforced and how do you enforce them.

And so we're actually having to review all the regulation for GDPR and say, okay, what's going to be our take on it and how are we going to actually help our customers comply with that? And so they're building that module right now. And then, you know, we've got stuff in the Middle East coming after that. We've got an MDI team, our Machine Data Intelligence team, that really just focuses on integrating, you know, third-party products and technologies into our SIEM so we can actually, you know, take in all that data and bidirectionally leverage it. And then I have a newer team that I built at the end of last year called Strategic Integrations, and that's actually a pretty cool team where they look at industry-specific challenges, and they look at, you know, third-party or vendor-specific challenges.

So if there's an integration with Carbon Black or something like that that we want to do, that team will build all that stuff. They'll build the dashboards around it. They'll do the automated response mechanisms so that way our customers don't have to build all that stuff out. If they've got Carbon Black and they've got LogRhythm, they can put them together and say, hey, if this happens, I want Carbon Black to go do this, and I want it to go put it here, and then I want to report on it, and then I want to go do this, and automates all that workflow. So they build all that stuff out.

We actually have some pretty cool use cases coming up with industrial control systems. So I've got— I'm talking to a few laboratories in— not in Colorado actually right now, but a couple outside of Colorado to take a look at their ICS infrastructure and their ICS labs and how can we do stuff like that. We've got a local mountain hospitality company. I don't know how you would call that, how you'd reference them, but, you know, potentially looking at stuff with them of saying, hey, mountain operations, you know, lifts and snowmaking abilities and all these different things. So these aren't really hardcore security, you know, you know, ones we'd see as like a security challenge, but at the end of the day, they have a security ramification in a lot of ways, or regulatory ramification.

Or something with compliance. So we'll do work with that, we'll do work with the energy sector. And so those are— that team that really is focused on that. So that's pretty cool stuff. So if you're, you know, that way we can tie in some of the just core business operations of that, whatever that, you know, third-party, you know, company is, into the SIEM.

Just because it's so powerful, we can take it on. We just don't— a lot of customers aren't there yet. And So we want to do that for them. Yeah, and how directly are you guys tied into the product release pieces? So, you know, a lot of times a research group or something like that, you know, you'll come up with content or new things and then it gets, you know, tossed over the fence to the, you know, the development team or the product manager or whatever it is, and then it'll sit there for a while and then, you know, maybe someday it'll get released as, you know, part of a official module.

Are you guys releasing content directly to customers today, or is it sort of a feed-in to the general product management and development cycles? Product management will be involved, and product marketing for that matter, but this team is a true R&D team, so they'll actually do the research, do the development, and push it out. We'll leverage QA to help QA some of our work, but for the most part we control a lot of that content development on our side. The other part though is from a pure product perspective. You know, people think of our SIEM technology or NetMon as another product of ours as well, our network monitor product, but we'll help drive stuff in those product lines as well.

So we won't just do the R&D of our content that goes and powers our product, we'll actually say things like, hey, we should really focus over here, you know, or make this enhancement with our product, or add this feature in, or, you know, fix this certain thing over here. And that'll help drive the kind of product-specific R&D team's roadmap. And so we have a say-so in their roadmap, they have a say-so in our roadmap. It's a, you know, everybody that has an R&D function, so my labs team and the product R&D team, our product engineering team, all report into our head of R&D, which is Chris Peterson, our co-founder. Nice, that's really cool.

So one thing that we like to do as part of the interviews is talk about some good things and some bad things that have happened during your career. So first, is there a project or a a memory, something that you have that you're— it was a great success for you or that you're really proud of. And, you know, I'd love to hear a story about that. Yeah, you know, um, the interesting part is some of the story I probably can't share, but, you know, I think, you know, when I look back at my career, I got to do a lot of cool things. Um, so I got to, you know, be in Sergey Brin's house, you know, the co-founder of Google.

Uh, I got work on some things with them, and that was a really cool experience to actually just be face-to-face, you know, in that person's house. I met his wife. He had a baby at the time. The kid's probably 4 or 5 now, but it was a little baby at the time, and the guy was just a really cool guy. I mean, he was still— when I got there, he was like, hey, I'm setting up this Asterisk box.

At my house because he wants to set up voice over IP for his home, and he's doing it. And he's at this point, he's like the co-founder, you know, he's wealthy beyond his years. Why doesn't he have someone else do that? But he was doing it himself and asking me questions about it. And so, you know, that was really cool.

I got to meet Bill Gates. I really wanted to, you know, interesting enough, I wanted to meet Warren Buffett instead because they had a board meeting and Bill and Warren were part of the company's board. So I was there around that time frame. I got to meet Bill, but I didn't get to meet Warren. But, you know, cool things.

And then, you know, the work I did at Mandiant with the FBI, that kind of goes back to kind of the core thing of why we even joined the military, of kind of, you know, serving your country, making a real difference. And that work with the FBI, I actually, from a cyber perspective, we actually got to put real criminals in jail. Now, I wasn't out there doing the arrests, of course, right, but the work that we did was leading to criminals getting put into jail. And so, you know, that was an amazing aspect of my career, is understanding that the work I was doing was making a real difference and putting bad guys in jail. And it was just, you know, nothing feels better than that.

And that's honestly what when I left Mania and said, I'll go into healthcare because the mission of healthcare is amazing. And, you know, then you get there and it's like, okay, there's some challenges we gotta work through here. But, you know, when you think of healthcare, you're like, you know, the work that you did, or, you know, you can map it to like saving lives. And one of the kind of most satisfying things that we used to do is we used to go through and do doctor's rounds. And what we would do is like they would take us and we'd go into the operating room with them and just to see like, you know, with your security lens on, like what they go through.

So I got to see some really gruesome surgeries, which are, you know, one of the things that you get surprised at is, you know, whenever the doctor sees you and you're about to get knocked out and have this surgery, they're like, okay, you know, we're gonna count backwards from 10. And they're very nice and gentle, but as soon as you're out, man, things change in that room. And, you know, you start seeing some limbs getting pulled and things happening. Holy cow. And it made me rethink.

I've had 2 surgeries before I started doing that, and then afterwards I'm like, now I'm a little fearful of surgery because I saw what kind of happened. So those parts are really cool, probably aspects of my career that I've had so far. I think it's always really cool when you get to actually be a part of what your business does. Yeah, you know, it really helps you understand what sort of friction you can either put in place or take away as a security practitioner. I'm sure that they would not have been appreciative if you would have, you know, rebooted the machines that they were in the middle of using during a surgery because you had to patch something, or, you know, hey, critical security vulnerability, sorry, you can't use this machine right in the middle of your surgery.

Yeah, but you know, it's interesting that you go see, and you know, there's that, right? And of course that's, that's an issue, uptime and being available. And otherwise, not only that, not only can they not help this patient now, but now they're also losing tons of money while this patient's sitting at the table doing this. But one of the things that came out of that was how many times a doctor has to log in. So they go into their office, they have to log into like 3 different systems to get like to do their, their just business for the day.

And then they go to the OR, they have to log in. You have your anesthesiologist, they've got like 4 different computers they gotta log into. You've got the doctor's gotta log in, you've got this, and then so I was thinking like literally a doctor has to log in probably 50 times a day. Yeah. And if you think about that, and some of these systems are faster than others, and so if you think about that, how much time is that taking them?

And that was one of the big things that I came out of this business was, wow, this is really inefficient for them to do their jobs. And the least we could do is try to streamline that from an identity access management, and so they don't have to just do that. And if they can reduce that 50 down to a more manageable number, they might be able to see 2 or 3 more patients in a day. So it's something to think about. Well, the last thing I want you to do after you're about to put your hands into my body is go type in your password on some keyboard that's been sitting in this room for 20 20 years, right?

You know, that's right. Who knows what's on that? That's right. I don't want any of those germs inside. Well, hopefully these rooms are pretty sterile, so you'll be in a pretty good spot.

But you gotta hope, but you never know. Yeah. Um, cool. So sort of the flip side of that, uh, not everything can be rosy all the time. Yeah.

Uh, have there been any times that, that you've had, uh, setbacks or, or things not go as planned, a project that failed? I'd love to hear any insight about those? Yeah, I would say, you know, whenever an individual contributor moves into management, there's always growing pains. And I think you don't, you don't foresee that whenever you're going through it because, you know, if you're like me, maybe slightly cocky sometimes, and have a little bit of, you know, you think you're a rock star as an individual contributor, and then you realize that, you those years trying to be a rock star yourself really isn't what life's about, and really it's about making other people rock stars. And so, but you go through that change, and, you know, at Mandiant, you know, I say I ran the New York City office for 6 years, but the last portion of that I actually had someone get hired in above me, and that was a real shot to my ego because, you know, before that I was like, you know, I'm a new manager, everything's got to be perfect in my vision.

Someone writes a report, it's got to go through me. Someone does this engagement, it's got to go through me. And it just doesn't scale. You don't actually grow your business and you don't empower the people around you to be able to do it because they all just need to funnel everything through you. And I think that was a very important— I burnt myself out.

I worked the most hours in the company one year doing that. I think I jokingly got this award called the Red Bull Award when I was at Mania for that But I burnt myself out. And so that was a huge lesson learned and a shot to my ego and caused kind of a wake-up call for me in my career of like, if I really want to take things to the next level, then I need to get through that transition quicker. And I'm no longer an individual contributor. I am actually a manager or director and moving myself up.

So I think that was, that was a huge important lesson for me. And the other one was more of a smaller story was I got kicked off an engagement at one time. It was actually the only time in my entire career I've been kicked off of something, and it was a, it was a not-so-fun project dealing with a defense contractor that had been compromised. And again, this is a point to where probably my, you know, ego of I've been here before, I've done this before, Your situation, Customer A, defense contractor, is the exact same as the 50 breaches I just investigated for all these customers before. Same scenarios, same situation, same everything.

And they did not really appreciate that because they're like, no, we're unique. We are, you know, this certain thing. And what the lesson I learned from that— and so they did not like me. And they wanted me off the project. And so it was the only time I've ever been kicked off a project, but then I look back on it and it really shifted— that moment shifted what I did later on because, you know, really you have to look at every single customer's unique.

Every single— even if it's the exact same, you know, attack and threat actor and breach scenario and everything else, it is new for them. And so you need to, you know, if you really want to build that consulting relationship with them and help them through that, you need to be a part of that with them. And so if you're on one side of the fence saying, I've seen this and done this before, and they're on the other side of the fence which they've never seen this and done this before, then you're gonna have an issue. And so it changed how I consulted off that project. But that was, you know, probably a couple years into Mandiant when I got kicked off that project, and I was like, you gotta be kidding me.

But it was a good lesson learned. Yeah, that's a good one. So we're getting close to the end of time here. Any final thoughts? Anything else that you want our listeners to hear about?

No, I mean, I think, you know, obviously with today's, you know, I guess interviews with James Comey and where our government's at and where, you know, how that impacts our cybersecurity kind of landscape, if you will. I think it's a pretty interesting time, and, you know, I would probably just encourage people to stay actively involved and try to drive a difference. I mean, cybersecurity has come so far in the past 20 years from, you know, the struggle of not getting budget, not being heard, and not really being important to now starting to become a core part of a business. Core part of a— even a company that's a primary core business like a healthcare organization or something like that, cybersecurity is starting to become really important. And so I think it's a really awesome testament to the folks that have been in it for a while driving this, you know, sometimes like an uphill battle, you know, going against the grain constantly.

And sometimes it can get tiring, and I think my message for, you know, I like to have for folks is keep fighting. Keep doing the work and keep driving it. You're seeing change, you know, you're seeing cybersecurity being at the forefront of everything now, and let's keep pushing it forward because it's still not where it needs to be. And so that, that's just really be just my, my encouragement to keep fighting the good fight. Yeah, it's making a difference.

No, I think it definitely is. I think, sure, on that same topic too, I think we have to keep constantly upping our game, you know. It used to be we could just, hey, the sky is falling, the sky is falling, someone pay attention to me. Now everyone's paying attention. We actually got to deliver.

Yeah, that's right. Right. A lot more pressure on people in security to make sure that we're delivering stuff that makes sense. Yeah, I heard one executive one time say, you know, I'm tired of security professionals telling me what's wrong, do something about it. Yep.

And now we have to put our money where our mouth is, if you will. And, you know, like you said, no more fearmongering. Uncertainty and doubt. We have to show return on that investment that they're making in cybersecurity. Exactly.

Awesome. Well, thanks, James. Appreciate your time, and we'll talk to you again soon. Yeah, thanks for coming out to Boulder, and I'll, and I'll sure see you tonight at the dinner. Great.

Learn more about the Colorado security scene at colorado-security.com. Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes