Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 28 for the week of August, uh, 14th. Alex, it's going back to school next week.
Can you believe summer is really officially over? It's pretty sad. My kids are not happy. My wife who works in the schools is not happy. Just unhappy household.
This last week we had fall weather. It really is like we're back to school. Did you guys have an end of summer blast, something to capstone it? You know, actually, I think some of my family is going tubing in the Platte River today. So that is— that would I guess be our end of summer celebration.
How about you? Yeah, well, you know, we were out in California visiting family last week. Went to the Santa Cruz Beach Boardwalk, which is a real blast. We went to Alcatraz, got to see the prison. We got out, so good news there.
Didn't leave the kids behind. Did not leave the kids behind, but hung out with grandma and some family and had a good time out in California. Very good. Let's dive into the news. This week was a little bit slower week for news, especially around the tech companies.
I wonder if they kind of all spent their ammo at Black Hat. You know, a week or two earlier. Could be. Yeah. All right, so number one, Colorado is number one on the list of easiest states to work in in terms of running an internet business.
Yeah, we had a 100% score. I think that that just means we're at the top of the list, but basically, you know, access to internet and other things like that make it a great place to have a business. So it's a good place for you to come run your internet business or add more internet-facing aspects to your business here in Colorado. Good stuff. Next, Galvanize is teaming up with Amazon to help train people on programming for the Amazon Alexa.
Yeah, so, so Galvanize, which is a Denver-based school, was picked as the partner with, with Amazon to do this training in 7 different cities, and they're gonna be doing 35 free workshops teaching developers how to program on Alexa. Yeah, that's pretty cool. There is a national hotel chain that's moving their headquarters here to Denver. Yeah, the Red Lion Hotel chain. Yeah, there's— I know one of them is out by Stapleton.
You know, it's been there a really long time and they are moving their headquarters here, which is cool. And so they're one of the smaller national chains. It looks like they're about 1,700 employees, but they are a public company and it's going to be neat to have them here in Denver. Hopefully that means there's some new security jobs. Working there at Red Lion.
Uh, next, uh, there was an article in the Denver Business Journal about Colorado beating— being a cybersecurity center. Yeah, so, so it— the Denver Business Journal has a, has a paywall around this one, so Alex and I kind of did the, the metadata analysis on this article. We can see, you know, they talk about Webroot, they talk about Red Canary, a couple of the companies we talk about regularly out here on the, on the show. Um, but anyway, this emphasizes what we've been talking about. They are recognizing that cybersecurity and security in general has become a big industry here in Colorado.
Yeah, and so if you're a paying customer for the Denver Business Journal, you should go ahead and check out that article and maybe send us a screenshot or something. Ping Identity has a blog this week, basically taught— it's what is Identity as a Service, IDaaS. This is an acronym that I don't think existed more than about 2 years ago, and certainly Gartner has helped push that along, but I Identity as a service has become something that it's something of an industry trend and something you might want to know about. And here's a nice summary about what that means. Yeah.
And I think it's, it's pretty cool too, because you might not think about it on the surface, but identity management is not easy. And so having that as a service capability, uh, definitely can make it easy for a number of businesses. So, uh, next, uh, Coalfire had a blog post this week about changes that are coming to the criteria for SOC 2 reporting. Um, I think that there was some interesting stuff in here. The one that stuck out to me most, uh, was the fact that there's going to be, well, potentially, I think these are just, uh, proposed changes at this point, but, um, a higher bar for what you have to report in terms of incidents in your SOC 2 reports.
Well, I think currently you don't really have to report them, but with the, with the new requirements, you would have to give a list of all availability incidents, not just, not just security breaches, but anytime your system goes down within that previous, that 12-month window. So really good information. If you imagine going through your vendor SOC 2s, you'd like to see how many times they were down in the previous year, right? Another interesting thing they're looking to add is their subservicer agreements. You know, who, you know, if you're, if you're working with, you know, Company X, how many companies underneath them do they have that might have access to your data?
And having that nicely spelled out in the SOC 2 would be, would be pretty nice. Yeah, that would be really nice. A lot of times you'll see subservice organizations mentioned and that's about it. And you may have to do your homework on them as well. So if, they increase that amount of information in the reports, it will be definitely easier to read.
Yeah. Uh, finally here, uh, InteliSecure has a blog post which is the top 10 DLP pitfalls. If you're looking at installing or implementing a DLP program, this might be a good thing to look at, figure out how to do it right, what things other companies have made mistakes on, and how you can avoid those. And then finally, just as sort of some general announcements, uh, first, as always, uh, you should go sign up for our mailing list if you want to get information from us on when the shows are released and show notes and other things like that. As well as, uh, we mentioned this last week, but we do have a CafePress store that is up now.
So if you want some cool Colorado Equal Security merchandise, you should go check that out. And I, I had a Colorado Equal Security polo shirt sitting in my, in my mailbox when I got home. So if you're around maybe Wednesday this week, come say hi and you'll get to see a Colorado Equal Security shirt in the flesh. Very, very nice. And then, and let's go ahead and dive into events.
As a reminder, we do have a calendar of events on the website going out several months in the future. You can see what's coming up basically through the end of the year at this point. Here this week, ISSA has a financial services special interest group that's going to be meeting on the 16th. SecureSet on the 17th is doing a cybersecurity trends event with Sean Owen. CEO of Salt Lending.
There's a Denver SEC, that's the kind of less formal group that gets together at a bar every other week. They're going to have their North meeting on August 17th. On the 19th, ISSA Colorado Springs is doing one of their mini seminars. So check that out to get some learning in and get some CPEs. As a reminder, that's their Saturday morning at 8 AM to 12 PM, 4-hour, just, you know, intensive, uh, training time.
So you can get, get some nice CPEs for either free or cheap depending on where you're from. On, on the 22nd, so the next week, CTA is doing their CTA 101. So if you want to learn about the Colorado Technology Association, that's your chance to show up and figure out what they do and how to get involved. On the 23rd, the Cloud Security Alliance chapter here in town is doing their August chapter meeting, and that's held downtown, I believe. It is, and I think it's actually at the state of Colorado's IT— was it Office of IT?
This month. SecureSet on the 23rd as well is doing a Securing Your Digital Health Company. This one just actually popped up on the feed here in the last couple days. It looks interesting. If you're involved with healthcare or want to get involved, it might be a good chance to get to know that area.
And then finally on the 25th, SecureSet is doing a Cybersecurity Hackathon. Uh, so I don't— this looks different than their capture the flag kind of events. So, um, I don't know if this is just going in and, and messing around or what it is, but it's taking, it's taking the place of one of their regularly scheduled capture the flag events. So my guess is they just do a little bit of a different spin this time. Hopefully we'll find out more before next week.
So that's it for events. Let's go ahead and jump into jobs. Um, this week we did a little bit different, uh, strategy for jobs versus going through and finding, you know, 10 different individual postings, we started looking through at companies that had a lot of positions available in the area. Before we dive into those, we got a couple folks who reached out to us. So John Everson, who's the CISO over at Dish, and we've talked to on the show, he mentioned he's got an identity management admin position that he's looking to hire.
Yeah, I think he actually has 2, and I linked to one of them, um, but there's— it sounds like he's definitely hiring a couple people. Uh, Mary Haynes with Charter also reached out to us We're specifically highlighting one job in the notes there, which is senior manager for the security operations center. So basically running their SOC. But she said that she has a large number of positions open. And then they're also doing a job fair for Charter, and there's going to be a link to that in the show notes as well.
So it's going to be a security job fair. So a couple of good leaders in town. We had John on the show, and I've been trying to get Mary on the show. We'll get her sometime soon. We were talking about September after summer ended.
Look for that next couple months. So I mentioned that we looked through a bunch of the companies in the area. Uh, my intention initially was, well, we'll look through it and we'll find, you know, 5 or 6 companies, security companies, that have postings for jobs right now. And as I started going through them, the list just got longer and longer and longer. So rather than go through every single company in the area, which is about 20 of them that have jobs, we thought we'd highlight a few that have quite a few positions open.
Yeah, so Optiv has 27. Yeah, LogRhythm has 20. Um, Ping, never heard of those guys, they have 16. Webroot has 10. Uh, Coalfire's got 9.
Route 9B, I, I say I didn't even say how many because they just have this very long list of jobs. And no, many of them are available in Colorado Springs or out in DC. And then there's a handful of others that are, you know, anywhere from 1 or 2 to a little bit under 10. But just about every security company in Colorado right now seems to be trying to hire somebody. Yep, absolutely.
And some of the ones that might be worth mentioning, even though they're not quite as many, is ProtectWise, Red Canary, Swimlane, these younger startups. Alchemy. They're all hiring people right now as well. So you can get involved with the big ones and the little ones. Exactly.
Well, I think that's it for the news this week. Uh, we have our feature interview coming up with David Willson. David is a security lawyer who has his own law firm called Titan Info Security Law Firm. Yeah, and so he's based out of Colorado Springs, and Robb did an interview with him. Uh, should be interesting.
Uh, it's a shorter interview, so hopefully you have time on your commute to, to tuck this one away. Uh, I'll tell you, the first time I met David was at, was at an event where he was arguing, um, very vocally with, I think it was Chris Nickerson, around hackback and, and whether hackback is a good idea, a bad idea. We talk a little bit about this on the interview, but that's That's the thing that's firmly etched in my mind around David Willson. Awesome. Sounds good.
All right, well, have a great week. Thanks, Robb. Hello, this is Jeremy Cooper-Leavitt, Managing Director of Assurance at Charles Schwab. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb Reck, and I'm sitting here with David Willson. David is a lawyer who focuses on cybersecurity. I had the opportunity to get to meet David a few years ago at one of the BSIDE Denver events. And when I, David, when I think of you, I think of the hackback argument, right?
That was the argument I think you had there. And I'll tell you, in the last, what, just several months, that's become a pretty big hot topic in Washington as there's a bill that was maybe gonna be introduced around hackback. And I'd love to talk with you about that a little bit later. But before we do, I wanna ask you, you know, As we look at your career and the things you've accomplished as both a lawyer and in the security world, what's the thing that you've done that you're most proud of and that, you know, you want to share with us to start off the interview? Probably the fact that I spent 20 years in the Army, and at one point in my career, shortly after 9/11, I ended up at NSA, and we were on the cusp of creating cyber weapons And I was doing all the legal reviews all the way up the chain to the top to determine whether those were actual weapons under the law and how the laws of war and international law applied to the use of those to assist combatant commands fighting in Iraq and Afghanistan.
Wow. And I assume that there's some stuff you can't talk about there due to confidentiality, but is it— Yeah, I don't want to get arrested. You know, at the highest level, um, do you— is what you did save some lives? Like, what's the, what's the output of that then, you think? Um, the— well, at least for me, the biggest frustration was, um, and this was back in 2003 to 2006, and so, um, the policymakers all the way up to the top didn't really understand cyber and what we call computer network operations: attack, defend, and exploit.
And so their impression was doing stuff online was gonna blow up the world or start a war or do something like that. When you looked at it obviously realistically, you put a 500-pound bomb on that target or do you just disable it through using cyber tools? And they couldn't get past the fact that It was a huge unknown for them. And I got asked like every 30 days, if you were king for a day, what would you do? What laws would you change so we could do this stuff?
And I would tell them, I wouldn't change any of the laws. The laws don't impede what we want to do. It's the policies and the policymakers. And then there was a lot of politics involved. People trying to claim territory over, you know, this is my area, you can't touch, stay out of my sandbox.
Yeah, commanders screaming, hey, I need something, do it, stop goofing around with it. So, well, so let's back up. You mentioned that you, you, uh, had spent 20 years in the military. Yes. Was that right out of high school?
No, I grew up in New York. I went to college, got an ROTC scholarship, um, was, uh, given active duty military police And I got an educational delay, went to law school and transferred to the JAG Corps, went on active duty in 1990. So you're like the superstars on TV who are doing JAG. I didn't fly any airplanes or sexually harass my female partner. Well, good call on that.
So you actually got your law degree before you went into the military service. Yes. And then 20 years as a lawyer in the military. Yes. Okay.
And so I did a lot of litigation, prosecuting, defending, so I was in the courtroom a lot. And I still, I do some normal legal work today, primarily to keep me in the courtroom and keep me sharp because my goal is to start defending a lot of these data breaches. Because I think it's easier to defend a data breach than it is to sue, although the plaintiffs lawyers are making a lot of money for themselves, not so much for their— So you're saying defend the companies that were breached who are being sued for, uh, maybe for neglect or something? Like the Targets and the Home Depots. Because when you think about it, the plaintiffs are claiming that the companies were negligent.
And in a lot of cases, granted, they were. A lot of them aren't even meeting basic security. Um, but if you get on the stand and say, I suffered identity theft, because XYZ was breached, I'm going to ask you, where else have you used that card? And how do you know it wasn't because you used that card at Home Depot or Target or Michaels or P.F. Chang's?
So claiming damages, right? How do we know the damage? Exactly. And you can, you can never make that connection. I don't want to say never.
It'll be very difficult to make that connection, you know, with everything out on the dark web. I was part of the OPM breach. So as far As far as I'm concerned, everything's out there. Yeah. And so anyway, but change your fingerprints as a result of that?
Yeah, I burned them off. But so I did a lot of litigation, and then the Army has a master's program, and I applied for that. They sent me to get a master's in, in information technology law, and then the follow-on was to NSA, and I was there for 3 years. We morphed from different organizations to what's now CYBERCOM, and I had the pleasure of working for General Hayden and General Alexander. That's great.
Going to Iraq for a little bit, and then back, I got stationed back here in Colorado for a second time at Army Space and continued to do cyber and space control. What's Army Space? I don't know what that is. Their focus is on Army cyber. Okay.
They're the Army component to CYBERCOM. Okay. And they also do space control. So if we want to prevent, like during the first Iraq War, we needed to prevent Saddam Hussein from using the French SPOT satellite and taking pictures of the battlefield and knowing where everybody was. Yeah.
So things like that. Is that in the Springs, I assume? The headquarters is, yeah. Army space? Yeah, the headquarters is.
Um, so you— so, uh, 2006, uh, you— I'm guessing you made the choice to move a private sector. What can you talk about what happened? Why? No, 2010. Oh, 2010.
That's when I retired. Okay, so 2003, 2006 you were doing— I was at NSA. NSA. And then you had 2006 to 2010 you were doing the Army, uh, um, well, then I went to First Army and I was training, uh, troops deploying on rules of engagement. And what they can do and, you know, see enemy, shoot enemy, right?
Um, and then, uh, 2008 I came back here. Okay. Retired in 2010. So that's relatively recent. I, I'm just thinking of when we met, it wasn't, you know, 2011, 2012, something like that.
So, um, right, really you just come, you just joined the— yeah, I was, I was kind of wide-eyed and trying to figure out how do I put the law and security together. Yeah. Well, how did you— tell me how it happened, right? You got out in 2010 and what'd you do? I worked for a contractor for a few months, left there, and then started my business.
Titan Infosecurity Group. And you're still doing the same practice you started then? Yeah, I'm the whole group, me, myself, and I. Sure. My focus is risk management and cybersecurity.
I, I've now refined it to the point where— and I don't consider myself a technical person at all— um, I can give some advice on, like, I teach a lot of cybersecurity awareness classes, tell people, you know, change your— and this is, you know, I get a lot of the advice from other people like Brian Krebs, how to disable HTML and photos in your Outlook email so you don't pull in viruses and things like that. But the main focus is the majority of leadership in companies do not understand what their own security is. And, you know, it's been a real tough sell because they don't understand, they don't want to know, they point at the IT department and say, well, ask them, I don't care. So they're now starting to understand the risk. And, but they're not in a position if they were sued, and I ask at all my briefings, if you were breached tomorrow, who would you call?
As you know, if you were management or the CEO, and they say, oh, I'll call my IT guy. I say, no, the IT guy or girl has been in an accident, they're not available. All right, call my COO. Same accident. You have to be able to articulate to whoever's asking you about this breach, what did you do to secure this information, and they have no idea.
And it's got to be driven from the top. And most of the concepts and the sort of cultural speak that I use is all from the military. If the general's not following the same rules he wants everybody else to, then nobody's going to follow it. It just, you know, like I unfortunately I worked with a number of generals who didn't even know their own password. Their secretary had the password.
It's like, wow, okay. Really. So in your practice, you mentioned you do training. Are you doing incident response preparedness? Are you doing incident response?
Are you actually getting involved with cleanup, or what do you say your specialties are? I've been primarily proactive. I'm pushing more into the reactive. The problem with the reactive is, you know, as you know, people don't Google once they've been breached and look for somebody to help them out. It's referrals and somebody they knew or someone in the IT department says, oh, we'll call this guy.
But I've been mostly proactive doing risk assessments from the perspective of showing the company where the vulnerabilities are, what their level of risk is and why, and what they need to do to fix it. Reviewing and developing the policies, making sure they're compliant with whichever industry they're in. And then doing the training. And while I do that, most of it is all interviews, and my goal is educate the leadership as we're going through that and showing them. And then if we do a pen test or vulnerability assessment, then I'll bring people in to do all that.
Get partners for the technical work, right? And I use people based on, you know, location, size of the company, You know, sort of I look at personalities and figure out, okay, who would be best fit for this type of work. And so then incident response plans. Yeah. Most of what you just said is what, you know, your typical security consulting group can give.
But as a, as an attorney, you're going to have a unique perspective, right? So can you talk a little bit about, you know, what does your unique perspective give in there that that you wouldn't get from just calling that local security consultancy down the road? My focus is what do you need to do to lower your risk and reduce or eliminate liability when you get breached? And the proactive is how do you do that in advance? And like I said earlier, if the leadership can't articulate what the security of the company is, then they're going to be dead in the water.
And a great example is I spoke at a conference recently and I was going to do a standard pitch and everything, and I decided last minute, let me do sort of a mini mock trial. And I— this was actually the PSA conference, which is the Physical Security Association. And so I had 2— there was a lot of company owners in the audience. I asked 2 of them if they'd be willing to be cross-examined, and they were hesitantly said, oh sure, you know, I'll do that. And it was a good time.
Nobody— I said, I'm not going to embarrass you, don't worry about it. But I asked them pointed questions about their security that they could not answer. Well, give me a couple examples if you don't mind. What'd you ask them? I said, can you explain how you secure data in your company?
Well, we have good passwords and, you know, we use, you know, security locks and, you know, things like that. And they just They couldn't articulate it at all other than what they did as a user and what they were aware of as a user versus we've got firewalls, they've been enabled, we changed all the default passwords, you know, and if they had had a risk assessment and understood the risks and the vulnerabilities and the plan, they would know from that report, okay, here's what my security looks like and what I need to do to fix it, where the holes are. And they could articulate that and come out with a policy or a statement that they could give to people publicly and say, here's how we're protecting your information. It's interesting, and I'm just thinking about it in my own company. I run the security program for Ping, and we talk about it a lot, but I wonder if you sat down with my CEO and you asked him those controls, you know, would he know?
Has he read all the controls in our SOC 2 to be able to say, oh yeah, here's the things we do, or would it be, let me check the SOC 2, right? Yeah. And I don't know the answer to that, and something that I probably need to think about. Well, and chances are if you asked him anything about the financials for the company, he would know exactly. Yes, he could explain exactly how the GAAP accounting worked there.
And they need to know that. I mean, and it's not to the point of you have to know how the firewall is configured and what type of firewall and, you know, access controls other than username and password, maybe 2-factor authentication, whatever they're using and whether— but you should know, will we encrypt this information? Is it encrypted on the fly or is it, you know, standalone on the server or do we use outside vendors? How do they integrate into our security? Security, you know, things like that.
A lot of the basics. And I can tell you the majority of them don't understand. They're just kind of throwing money at the problem. The other aspect is I can offer, if I'm hired as an attorney versus a consultant, I can offer attorney-client confidentiality. From the proactive stance, if we discover vulnerabilities, like let's say they're using a server that has an XP operating system.
Well, it's not supported. That's a huge vulnerability. And if they say, well, we can't afford a new one right now, that's potentially protected under attorney-client confidentiality versus on the flip side, if it's a data breach investigation, and granted, this is a little self-serving on lawyers' parts, but the mantra now is hire the attorney first who will then hire the forensic examiner, public affairs, everybody else, because then they all funnel through the law firm and you have attorney-client confidentiality. And, you know, and then the other aspect of that is the laws have gotten so complicated only from the perspective of the legislators writing them didn't know what they were doing. So they say you have to notify of a breach within 14 days or 30 days or 60 days, but it doesn't define really what a breach is and what notification is.
And of exactly what point do you have to notify? Exactly. You know, that I suspected something might have happened or actually have conclusive evidence it happened, or God forbid, from the date that it actually happened. Oh yeah. There's all kinds of ways to interpret that.
And some of them are, you know, really bad in that they require you to do monitoring and send out notices to people who have been potentially impacted. Well, you've just handed discovery to the plaintiff's attorney who's now going to take what you put in that letter and turn around and put that in the complaint. So it's bad juju. So, you know, it's been what, 6 or 7 years that you've been running your own practice now? Yes.
I'd love to hear, you know, some stories about, you know, engagements you've been on where you saw some, something incredibly good happen and maybe some situations that didn't go so well. So either one that comes to mind first and then we go to the other side. Mostly bad. Yeah. Just from the client perspective.
Sure. I don't know if you know Charles Tindall. The name's familiar. Okay. Charles and I did a job together And we were both amazed.
He was doing the pen test and vulnerability assessment, and when we got to the company, they dealt with healthcare information.
And that's one of the things I've come to a conclusion over the 6 years. If I go into an engagement and the leadership's not there, I leave. I'm not sticking around because if the leadership's not engaged and they say they have other things, they're too busy, then as far as I'm concerned, it's not worth it. I'm not, I'm not hard up for money, so, you know, I can walk away from, from a job. Yeah.
And, you know, basically, if the leadership is not involved, I know I'm gonna go through all these motions and put all this work product together and give all this advice and nothing's gonna happen. It's just going to be pushed off to the side. Okay, we check that block and move on. Anyway, we showed up. The attorney from the company had brought us in because I know her, and leadership wasn't there.
The IT department was there, and they basically sat there with their arms folded, you know, like, I don't know why you're here. We've got this under control. And they claimed, we use XYZ, you know, routers and servers We're locked down tight, nobody can get in. Well, Charles got in in 5 minutes. And it was embarrassing.
And just the, you know, one thing after another, medical paperwork and documents all over the place. Cleaning crew would be in every night, 5 days a week, unescorted. So the huge HIPAA violations as far as I was concerned. And then The— we did a phishing attack on them a couple weeks later, and 73% of the company clicked on the email, and 63% clicked the link and gave us full access. 100% of the IT department did so.
And it was 2 weeks after that that somebody in the IT department said, um, something doesn't look right about this email. And it wasn't the company email scheme, it was the name of the attorney at Outlook.com versus whatever the company's name was. And it was just, you know, they— So, you know, we all have the bad stuff. What about good stuff you've seen? Or maybe if you don't have any great examples, maybe what are some lessons you've learned that, you know, remember people listening, we're security people, you know, we don't have the companies that don't have anyone in security probably listening here.
What do you think, what have you learned or what have you seen that went well that we can take take back to our organizations? Well, I teach a lot of classes, and I'm starting to hear more and more people from companies say that they experienced the— I forgot what you call it— but the scam where somebody asks, they pretend to be the CEO. Yeah, wire some money to your email, whatever. And they've defeated it. They either caught it, by accident or they had procedures in place to try and defeat it.
So from that perspective, at least what I'm hearing is people are getting a lot more aware of that and doing things to try and prevent it versus saying, oh no, we lost $100,000 or $1 million or something like that. I'll talk to that one. You know, at Ping, you know, when I, when I got there, that was one of the first things we looked at. It was super common. It was a year after a year and a half ago is when I started there.
It was super common at that point. And the first thing we looked at wasn't, will we stop all phishing emails, because we know we're not going to successfully do that, but what are the financial controls that are in place to say, if you do believe that my CEO sent this email, how do we validate it? What, you know, are the 2-person, 2-man controls, 2-person controls in place? Are there— do we have a process to make sure even if you're fooled, we're still going to catch it. And I think that that's the key because we know that anti-phishing tools are not perfect, right?
But we can get pretty good with our financial controls. So, from that perspective, and I'm starting to see a lot more concern about cybersecurity, but it's still, you know, people say, oh, companies are doing a lot more. I'm not seeing it really. I see a lot of money being thrown at it and companies paying it lip service but not really doing the hard work and getting engaged. And unfortunately, a lot of CEOs, if you say computer or cyber or anything technical, their eyes roll in the back of their head.
You know, they say, oh, we'll talk to my IT person or people. Yeah. Which is, you know, again, from my perspective, I'm not going to get on the box or the network and pull up a command prompt and check their configurations. I'm talking to them about risk and how they're dealing with that risk across the organization. They're just, you know, if they're a really big company, then they understand, and they've— and certainly financial.
I think healthcare is getting beat up big time because they've not had a good attitude about it, but the financial industry has really been serious about it, and so they're they're doing the assessments that they've been required to do and, you know, making sure they have the outside audits and all that kind of stuff. Mostly because the law requires, but they have started to put things in place. So it was funny though, I did a lecture for a really large law firm in New York maybe 5, 6 years ago for the IT department, which was like 70 people. My goal was to be able to train all the attorneys because they're walking around clueless with all these devices and client information and have no idea what they're doing, riding on the subway while people are reading their stuff. And the person who was in charge of IT there basically said, well, you know, I'll never get all the lawyers together, so that's not going to happen, sorry.
And they got breached about 2 years ago. I'm like, oh, well, sorry. Now maybe they'll get the lawyers together, right? Yeah. So, you know, kind of, I know we're actually getting close to your time where you need to be done.
So I want to give you an opportunity to tell us, you know, if someone wanted to reach out to you, what would be, you know, what kind of work would you like to have folks reach out to you about and how should they do so? Well, like I said, I want to get more into defending data breaches. I do data breach investigations. Investigations, overseeing it. As far as I'm concerned, you should never do a data breach investigation without a goal toward going to court, because if you don't collect the evidence and then suddenly later you need it, then you don't have it.
So if you go in figuring, well, we're going to end up in court, we better do everything we can to make sure we preserve it, then you're good to go and you can make a decision. Unfortunately, I'm finding a lot of companies that are suffering data breaches and kind of, you know, say clean it up, sweep it under the rug, let's move on, and ignoring compliance. And, you know, that's fine if they never get caught, but if they get caught, then, you know, the fines could be a lot larger than they thought. But so I want to, I want to get more deeply into the reactive piece, but like I said, that's word of mouth and referrals and things like that. From a proactive standpoint, again, I do the risk assessment.
I'm I'll bring in teams if I need them, make sure the leadership understands what their responsibility is and they're doing their due diligence to protect the company against a data breach. And they can walk away and say— and not get fired because of the data breach. Be able to explain to the board and the shareholders and the customers, here's what we've done to try and protect your data. Granted, you know, everybody's going to get breached. We did do X, Y, and Z, and that was the best we could do.
I did want to circle back on the whole hacking back topic. Sure. And see where you are now, and maybe you can better summarize than I can where current laws are and how companies should think about hacking back. Maybe you start off by defining it if you don't mind. Well, broadly, hack back is you've been breached and you decide you're gonna go get those guys that breached your network And I did a lecture before RSA one year.
It was for HBGary and it was a private lecture. And afterwards, a gentleman came up to me and was saying he worked for— and I don't even remember what organization, but he used to work for a huge hotel chain. And he said when they were outside the country in one of their corporate offices if they were breached, they would hack back. And he didn't really say what he meant by hacking back. He did say they ran into a law enforcement investigation and that law enforcement organization was not happy, but he didn't say, oh, we all got in trouble or we all got arrested.
And he said the legal department said, oh, well, we're outside the US, it's okay. Which, according to the Computer Fraud and Abuse Act, it's not okay. But from my perspective, active, you can hack back or utilize active defense under certain circumstances. If you're— it's similar to self-defense. If somebody punches you in the nose and runs away, you legally cannot chase them down and beat them up.
But if somebody's standing there repeatedly punching you in the nose, you have the right to defend yourself. Similar to a data breach, it's going to be a lot more difficult to prove But if you're persistently attacked, and the example I like to use is there was a variance of the Zeus botnet that if you, even though you thought you cleaned it up, when you rebooted your system, it re-energized itself and the attackers were still in your network. So if you're sustaining damage and feel like you're being persistently attacked, at some point you're going to, the company's going to have to say, we have to do something. We can't go on and allow this attack to continue. Maybe it's a DDoS that just keeps going on and on and on.
At that point, you can do something, and then that's where in my lectures and my papers I get into a theory of what you can do and how you can do it. The key part of it though is the leadership is involved, not, you know, a few guys in the company deciding after work or when nobody's looking, well, we're going to fix this. Years ago, there was a government contractor who was upset about hacking from another country, so he went home and tried to deal with it himself and got himself in trouble. Well, he got fired. He didn't get into any legal trouble.
But if the leadership's involved and it's a planned— and you need a team. It's not the IT department. It's a malware expert, a forensics expert, a traceback expert, an attorney who knows what they're doing. You know, you have to make sure you have the team that covers all the different aspects of it. And the leadership is updated at different points.
Okay, here's where we are. You have to decide, do we move forward? Do we go this way? Do we go that way? And they have to be comfortable with, yes, go forward and do this.
Because in the end, there's potentially going to be a lawsuit. And they have to be able to take the stand and say, here's what we did, why we did it, how we did it. And then I get into why I don't think attribution is that important. And there's no innocent victim, as people have yelled at me when I'm lecturing. You know, because if a company server is compromised and it's being used to attack my company, they're not innocent.
They're a victim like me, but they're not innocent. If I can identify them and tell them, hey, shut it down and they say go away, then I say, okay, yeah, game on. I'm going after you. I'm taking it down because I'm not going to suffer damage because of your incompetence. And typically if you tell them, oh, by the way, you're not just attacking me, you're attacking 100 other companies, maybe I'll go tell all of them that it's your incompetence that's getting them breached or attacked.
So are you familiar with the legislation that's been proposed Propose it? I am. I think it's not underway, right? It's just proposed. No, it's a Georgia senator who's going to introduce it but hasn't done so yet.
And I've, you know, offered some comments. Okay. A couple of my articles. And what's your, what's your opinion, high level? Um, it's not well written right now.
Um, they haven't— anything like that, you're going to have to include a lot of definitions, right? And you're going to have to be able to put people in a box based on what they're doing. And I would not allow— I would cut individuals out of it. It has to be a company, and like I said, the leadership has to be involved. They have to be cognizant of what's going on.
I told them I would try and give them some more language, but they're very slow to respond, so I'm waiting for their last— Well, thanks for the update there. You know, I do want to make sure— how should people get a hold of you if they want to talk to you? david@titaninfosecuritygroup.com. And I will go ahead and put your email address in the show notes if that's okay with you. Sure, yeah.
Folks can reach out to you that way. Are you on Twitter or any of those things? I'm on LinkedIn. I don't do a lot of social media. It gets you breached.
Privacy is important. And I don't have time. I certainly don't do Facebook. I will definitely get that out there. Anything, final things you want to say to the community before we call it a show?
Not that I can think of. I mean, my interest is I really love this stuff. I love talking about it. I love, you know, going to lectures and listening to other people talk about it and debating it. And so it's, you know, it's fun stuff.
And that, and I love the courtroom. So if I can combine the two, then I'm in a perfect world. Well, once again, thank you very much for your time. It's good to have you on the show, and hopefully we'll get to talk to you again soon. Okay, appreciate it.
Thanks, David.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com. At colorado-security.com.
Until next time, remember, Colorado equals security.