Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 30 for the week of August 28th, 2017. This is Robb Reck and I'm here with Alex Wood.
Alex, did you watch the fight last night? Fight? There was a fight? I wasn't aware that there was a fight last night. Well, I didn't get a chance to see it, but my understanding is that we finally proved that American boxers are better than Irish MMA fighters.
Yes, I think that is exactly what happened. You know, there was— everyone's mind was wrestling with this question, and now we know the answer. Yeah, and it's good because, you know, if you're, if you're going to prove you're better than an MMA fighter, the best way to do it is in a boxing ring, right? Right, exactly. I thought they should have done arm wrestling instead, but you know, what do I know?
All right, well, good stuff. Let's go ahead and jump into the news. Uh, before we do, just a reminder, uh, we ask folks to, if you like the show, subscribe on— go to, you know, iTunes, Google Play, wherever you go, subscribe to the podcast so it downloads every week. And do sign up for our mailing list. Every week we do send out the show notes It's a nice written reminder of all the articles we go through and the jobs that are posted and of course, the events that are coming up.
So first this week, news was that Sling TV's CEO has left to go on over to Pandora. Yeah. And I think on the surface of that, people might think Sling TV, why is that important? Well, Sling TV is part of Dish Network, which is based here in Colorado. And, and so I think that we know John Everson over there at Dish.
Yeah, it's interesting news on that front. Big news here in the Denver area and Certainly, as we're talking about the fight last night, that, you know, that was one of their big events for the year. And I think a big part of their internet presence is the Sling TV brand. So kind of big news for those guys. Yeah, I think it's pretty cool.
You can't necessarily get those sort of pay-per-view things on other avenues besides Sling. Yeah. Next, a French autonomous shuttle maker, Easy Mile, is moving its headquarters to Denver. So that's pretty cool. Before everyone gets excited, this is not a space shuttle.
This is a, like a little bus that'll drive you around town. Yeah, it's sort of, I don't know, it's sort of a funky looking bus. But it's a bus nonetheless, you don't need a driver. So congratulations to them, more people in the area. You know, we might have these automated buses going around town here pretty soon.
You never know. It seems like it's very possible that Stephen King's world that he imagined in Christine, where the car comes to life and attacks people, might not be that far from reality. Maybe we will have fights between the, you know, the automated Ubers and the automated shuttles. I love it. So next, identity thieves hijack cell phone accounts to go after virtual currency.
This is an article that we got from the Denver Business Journal. It's just interesting to me. The reason we included it is it's not Colorado specific, but it was specifically put in the Denver Business Journal this last week. Yeah, I think it's one that illustrates operational security and securing things that you might not think about. This is just, uh, phone numbers and other stuff like that that you can use to reset passwords, gain access to accounts.
Um, I think the bad guys are always going to go after the easiest avenue, and if, um, if the front door's blocked, you're gonna go to the side door. Yeah, and virtual currencies is a new thing. There's not a lot of processes in place around securing it, so it makes a lot of sense for them to focus there right now. We talked about it last week, but we have another article in here about, uh, the trouble that Route 9B down in Colorado Springs has been facing. They have an auction set for this week for all of their assets to be sold.
So interested to see how that turns out. Hopefully they can find some financing or whatever it might be to keep the company going so they don't have to go into this auction. Yeah, we'll know next week on the show whether they ended up delaying or going through with it. We'll let you guys know. On the other side, Webroot is reporting their 14th consecutive quarter of double-digit growth.
I feel like that's something that I've heard before, but only slightly different, Robb. Yeah, I think maybe 3 months ago we heard that they had their 13th consecutive quarter, and hopefully we get to talk about it in 3 more months, right? They did say it was a 15% year-over-year bookings growth for the fiscal year, so they're moving in the right direction and hopefully keep growing. Good for them. Next, InteliSecure earns their Crest certification.
So This is a longstanding, highly respected independent accreditation within the information security testing industry. The CREST certification provides InteliSecure clients the assurance and confidence in knowing penetration testing services in their organization conform to and are conducted using the highest ethical industry standards. So it sounds— that sounds a lot like marketing speak, but I'll say this. Um, InteliSecure historically has been a managed service provider, um, really outsourced DLP and then outsourced SIEM. As they're getting focused more you know, as they're broadening their focus to include penetration testing, you know, hopefully they're gonna get better at that.
And, and I know that it's a relatively new offering for them and something that they're getting better at here and hopefully giving some more confidence to their customers. Yeah. On a serious note, I had never heard of the Crest certification. So maybe something that I will look into as well. Yeah.
Next, CableLabs, which is— I don't think we've talked about CableLabs on the show before, have we? I don't know that we have. So they are a a member-owned organization that does testing and research for the cable companies. And Mike Glenn, who's the CISO over there, is a friend of ours. He sent us over a new white paper that they put together called A Vision for Secure IoT.
And it's really just kind of principles and governance for how you would create a secure IoT environment. They created it for, of course, their member organizations, but he wanted us to share it more broadly with the security community. It's pretty good stuff. I'd recommend you take a look if you're looking at IoT in your own organization. Yeah, I really appreciate the fact that CableLabs has a strong security person there and that they're pushing forward these strong security standards that the cable industry can help adopt.
Next, Red Canary had a blog on detecting ransomware behind the scenes of an attack. There's not anything crazy in there, but it's a good look at the steps that actually happen when a machine is being infected with ransomware. So it's some good, uh, some good graphical pieces in there looking at, uh, the steps that the machine is going, the, the, uh, the commands that are executed, the programs that are run, that sort of thing. Yeah, Red Canary does manage outsourced services around, um, around endpoint detection like this. So as they walk us through the specific technical things they see, this is stuff you can use internally as well, right?
Like, hey, what, what is it that they triggered on so I can start trying to trigger on that in my own program? It looks like some interesting stuff. I'd recommend you take a look if you do run security operations at your organization. Next, we have a blog from Ping Identity. It's What Is Web Access Management, also known as WAM.
This is one of the technology areas at Ping that not, not everyone's heard of. You know, most folks have heard of single sign-on or MFA, but what is web access management or even access management in general? And I'll just give it a real quick summary. It's, it's really that runtime security versus authentication and authorization up front. This is as the— as you have access already, your session's already in place, what are you able to do?
So this article goes through kind of summarizing what does legacy WAM look like with really, you know, kind of traditionally the agent-based stuff, and then what does more modern look like, and they go through the proxy model and what that looks like as well. So anyway, it's a nice little primer for WAM and maybe get some folks associated with that. And, you know, one of the most important parts of— I can't even say it. He's going to make a George Michael joke. Go ahead, Mike.
Go ahead. One of the most important parts of modern Wham! is that it doesn't include George Michael since he passed away. Now wake me up before we go on to the next topic.
Next, the CSA chapter here in town has a survey Um, they're looking for input on, uh, what you would like to see at their meetings, when you want to see the, the meetings, um, whether you'd be open to them charging for meetings. Um, it's previously has been free, but, um, they're looking about, uh, what sort of model they should adopt for support. So I will have a link in the show notes. Go out and, uh, take that survey. Um, let them know when you want to see the meetings and what you want in the meetings.
And I will point out they also are asking about location. You can meet up north Boulder-ish, downtown Denver, or DTC. So, you know, what's closest to you, what's most convenient, speak out. Finally in the news area, Cyber Girls 2017. This is going to be a full-day event really with the intention of getting high school and junior high girls involved with security and technology and get them more exposed to what's going on in that space.
Hopefully we can drive those numbers of having women in security and women in technology up. The event's taking place as a full-day event on September 23rd at the Regis campus in the Tech Center. Yeah, and we'll have that in the events section as it comes up too, but we wanted to mention it here specifically to get people to have more visibility of that because it is gonna— you're gonna want to give some notice on this one, right? Right, exactly. Um, and then that's really it for the news, but before we move on to the events, I did want to mention, uh, we do have a store if you want Colorado Equal Security merchandise.
I'm not wearing my beautiful Colorado Equal Security t-shirt today. Not that you folks would know any different, but there's plenty of stuff there. You should go check it out, order some stuff. We get a couple pennies on everything that you purchase, so it'll help us continue to make these podcasts. So events for this week.
As always, remember, we do have an event calendar you can look at. You don't have to just look about the next couple of weeks on the show. You can look as far out as you want to. But on the 29th, on Tuesday, CTA has their SIP and Connect event. Uh, on the 30th, SecureSet has a Hacking 101 Girl Develop It workshop.
On the 30th and 31st, we've been talking about this for quite a while, the Colorado Springs ISSA chapter has their 7th annual Cybersecurity Training and Technology Forum. We've talked about this a bunch. Uh, if, if you haven't decided to go yet, it's not too late. You can— unless you're listening to this on Thursday, then it might be too late. But you can register now, show up, and enjoy great content down in the Springs.
The NCC is doing a first responder cyber exercise on the 31st. I will actually be participating in that. I think that I am sitting on a panel discussion, so that should be fun. Are you gonna cause the problem that they have to respond to? Yeah, we'll have to see.
Maybe I'll just, you know, fake a heart attack in the middle and they'll have to respond. And then, and then on the 4th of September, DENSEC, Denver SEC, is having their South meetup. And this is just that real social group with no agenda. Get together at a bar, talk, get to know some folks in the community. It tends to be a little bit more technical in nature, but it's a great opportunity to meet some folks that wouldn't generally show up at an ISACA or ISSA meeting.
Right. And that's all we have on the event calendar for the next couple of weeks. There is a sizable gap between the 4th and the 12th for events. So if you were planning on taking a vacation, you should do it during that time because there's obviously nothing going on. Let's jump into jobs.
Number 1 job, top of the list, TeleTech is hiring a new CISO. We've had their current CISO on the show, Sam Masiello. Sam is going to be heading somewhere else. We will have that news for you as it, as it breaks. But, but for now, there is a new opportunity at CISO at what really one of the largest companies in Denver.
And, and I think it's a good opportunity for, for someone who wants to run a program. And congratulations to Sam and his new adventures. KPMG is looking for a manager of cybersecurity services. Similarly, Deloitte is hiring a cyber risk and compliance manager. Coalfire is looking for a client engagement director of cloud and technology services.
What it feels like to me is you need to go apply for all 3 of these and make them bid against each other for your services. Exactly. These are, these are 3 pretty similar roles there. Oppenheimer Funds is hiring a cybersecurity manager of identity and access. First Western is looking for a risk analyst.
It was— this was actually kind of a fun position. I looked this up. And it does include cybersecurity risk, but it also includes financial risk, operational risk. It's broader than just security-focused. So anyone who wants to get a little bit better business vision while still getting to do security stuff, they look like a good opportunity.
Yeah, that sounds pretty cool. LogRhythm is hiring a senior security analyst for GRC. Lockheed Martin is looking for a penetration tester, mid-career. So I don't know if that means a certain age or a certain experience. Yeah, my guess is that that means that they have this much money and not that much money, but, but more than just a little bit of money, right?
Uh, so McCully Brown Inc. is hiring an intercept coordinator. So did you look at this job? I didn't see this one, but that looks, uh, pretty exciting. So I, so I spent an inordinate amount of time trying to figure out what this, what this person does. It looks like there's— so there They're capturing signals.
It's around signals intelligence, right? Okay. So this is a— this is a— sounds like some spy stuff, counterintelligence type stuff where they're capturing the— they're intercepting messages and then trying to figure out what to do with it. So you do need clearance, but there's very little information posted on the job. Whoever gets this job, please let me know what your job is as well as you're allowed to, understanding that you can't tell me everything.
Because I'm very curious about what an intercept coordinator does. Obviously, you coordinate intercepts. Absolutely. Crocs is looking for an IT network security analyst. Yeah, this is a 30-hour-a-week job, interestingly enough, not full-time, but pretty close.
Digital Globe is looking for an information system security engineer, as well as an information system security site reliability engineer. So I know this, the feature interview this week is going to be, um, what is with Chris Martinez, who you talked to from Digital Globe. So I wanted to get these jobs in there, uh, same time we talked to Chris. One of these jobs reports up to Chris, right? I think it's the, uh, the site reliability engineer one, and the other one reports into their government side, which Chris doesn't, uh, doesn't— he has a peer that does that.
Yeah. Uh, well, with that, you want to just talk a little bit about the interview that we're about to start? Sure. Uh, yeah, so I sat down with Chris Martinez, um, earlier this week. Uh, we sat down on his porch and had a couple beers, which was nice.
Um, you know, Chris is from Colorado, been around here a long time, and is now running the program at Digital Globe. Uh, they've got some interesting stuff going on there, um, some sort of really forward technology that they're, they're working with. They're moving, moving to the cloud. Um, they've got, uh, Amazon's first snowmobile coming to pick up all their, you know, 70-some petabytes of data and move it up to the cloud. So that's, it's some interesting stuff.
I know Amazon has taken over a lot of industries. Have they also taken over the snowmobiling industry? I think that they have. So, well, at least they're starting. You know, this is the first snowmobile.
I'm pretty sure that there's going to be only Amazon snowmobiles from here on out. So a snowmobile in reality is a big truck that moves a whole bunch of data, right? Yeah, exactly. So it's sort of like it's just a semi-truck pulls up, you connect some power and network cables to it, put your data in there, and then they go and do the opposite into Amazon's Glacier environment in the cloud. What's interesting about that is it is the fastest bandwidth currently available in the world, is backing up a pickup or a semi to your building, putting the data onto it, and then driving it across the country.
It's the fastest way to move a lot of data. I found that interesting. Yeah, uh, it's, you know, old-school technology meets new-school technology. I think it would have taken them several years to do this over, you know, like a 10-gig link or something like that. Okay, well, Alex, thanks a lot.
We'll end up talking to you next week. Thanks, Robb. All right, everybody. This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
This is Alex Wood, and I am here with Chris Martinez, CISO for DigitalGlobe. Hey Chris, how you doing? Good, how you doing, Alex? I am doing just fine. Thanks for taking a couple minutes to sit down and chat.
Yeah, thank you as well. We, to make everyone jealous, we're sitting out here on Chris's back porch, beautiful day, drinking a couple beers while we're doing this, so perfect time for an interview. Chris, why don't we start out by, you know, you giving us a little background on yourself, how you got into security, and sort of your career path to where you are today. Sure. So, and I'll add to the setting here, it's also Friday afternoon.
It is also Friday afternoon. Even better. FAC.
Colorado native. Grew up in Arvada. Okay. Live in Littleton now today, as you already know, but started the technology career Late 1990s with JD Edwards. Started in desktop support.
Before that, I did state of Colorado for 10 years, finance, very different career path, but got interested in computers. So made the switch to JD Edwards, did desktop for a while, but that's where I really started my security career. And as JD Edwards was purchased by PeopleSoft, I had an opportunity to run access management for PeopleSoft. Great opportunity. Didn't last very long.
Oracle came along, bought PeopleSoft, and quickly went to a different side of the house from a security perspective. And Oracle Security Services. So back in those days, it's Oracle Cloud today, but it was Oracle On Demand. So I had the enterprise internal side of security services and then the customer-facing from an on-demand perspective. Stayed there for between J. W. Edwards, PeopleSoft, Oracle, 10 years, so a lot of tenure through those companies.
Next position was with IHS, so here local. Had the opportunity to build the security program from the ground floor, so no security person when I got there. Finally made a role, had 2 people reporting to me, and, you know, throughout the whole tenure there, learned a ton. Yeah, all over the board, but got pretty good at incident response. Those kind of jobs are always fun.
It's, it's really, it's really rewarding getting to figure that stuff out from the start. But yeah, also you're, you're the guy, so you end up doing a lot of the grunt work and You're going to end up doing a lot of incidents and getting pretty good at that. Yep. After that, I went to Aetna. So I just spent 2 and a half years, and I say just, I'm not one to typically jump jobs very much, but spent 2 and a half years there.
I ran security, CISO for the consumer business. So if you think about Aetna, Fortune 50, $65-ish billion in revenue when I left. And there, there were plans, and it wasn't all set yet, but there were plans to have 4 CISOs across the different business units. Then I found this opportunity here in Denver— well, actually Westminster— so with Digital Globe.
A lot of attractions to Digital Globe. The first and foremost would be By 2020, we anticipate to have our entire business in AWS. Wow. So we have a brick-and-mortar data center today, but we're rapidly moving to a 100% cloud business. So how did you end up at the Aetna job?
I know that they're obviously not based here.
Was that a lot of travel? Did you, uh, I can't remember exactly how you came to that one. Yeah, um, so the consumer business from an Aetna perspective, I was on the ground floor, and it started with a business unit here in Denver called iTriage. Okay, so down on 15th and, uh, Wine Coop, and over time added a business in Chicago a business in New York City. So I was on the road quite a bit.
It's interesting. So I worked for Jim Routh, wonderful mentor at, at Aetna. And his rule was no travel during Q1. Interesting. So that kept finance off our back for the rest of the year.
So we could do whatever we needed to do from a travel perspective. And, and that ended up being on the road almost 24/7. So Got a little bit old. I can imagine, especially I know you got kids. It's tough, tough with a family and being on the road all the time.
Absolutely.
So, so now at Digital Globe, you guys do imaging, obviously a lot of data there. Yep. What, what sort of concerns do you have around protecting that data, working with that data? I mean, obviously there's got to be some concerns with even security around the scale of that data. Yep.
Yeah, it's a great question. I've thought about this. So we have roughly 70 or 75 petabytes of imagery. That's nothing. Yeah, that's nothing over the last 15 years.
And as I put that into context, I'm like, you know what, it would take somebody forever to steal a large chunk of that data, and hopefully we're going to detect them in the meantime. So one of the fears that it pivoted towards is what about ransomware, something that can encrypt our crown jewels? Yeah. And thinking about the destructive nature of some of the attacks that are happening in today's world. Yeah, you know, I think being security professionals, we often first think about that C in the CIA triad, You know, we want to make sure everything stays confidential.
You know, if we're protecting it, it must be important, so it's got to stay confidential. But those other 2 are nearly, if not more important, especially in some businesses. You know, even if someone stole all your map data, it would probably be less of a hit to you than if you couldn't access your own map data. Absolutely. And we've had a, you know, couple here and there where a single system gets infected, and we will quickly contain I'm sure everyone's familiar with WannaCry.
I mean, we spun up an incident right away to let's do an assessment. Do we need to have a containment strategy? We didn't see any infections, but we still took that as a priority one incident. Yeah, I bet. Well, you know, seeing with the WannaCry and NotPetya, Petya, whatever you want to call it, You know, some of these big businesses that are taking multiple $100 million hits because their systems have been offline and they haven't been able to do their business.
Again, not on the minds of many security people, at least not in the forefront, but definitely should be now.
Speaking of that amount of data and your move to AWS, I had read an article. It was either in the Post or in Denver Business Journal about you guys using the AWS service where they essentially show up with a truck and, you know, like sort of a giant hard drive on wheels, I guess, and take a whole bunch of your data.
How's that experience been and just the move to cloud in general and that particular service and other stuff and, you know, moving to AWS? Yeah, so we were the first AWS customer to get a snowmobile. So to your point, it was a tractor trailer. I probably drove by it 100 times before somebody said, oh, that's the AWS snowmobile. And then I actually walked outside and we had fiber going into it, a whole bunch of power.
I was like, wow, I never even noticed it driving through because it was near our parking garage. It was pretty cool. It's sitting at AWS West right now. Offloading. And once that's done, we'll send it to AWS East and we'll have a replication of our data.
So when you say send it to AWS East, you mean the actual truck or they will replicate the data from west to east? They will send the truck. Yeah. Somebody told me how long it would take to actually do that over our 10-gig links and it was, it was years. That's crazy.
I was like, wow. So we're doing that all via tractor-trailer from west to east. So starting with west, and that's where our production is, and then we'll have failover and backup AWS east. Awesome. So you said they had fiber and power running to it.
So did they actually pull up the truck and then, you know, they connected it to your network and then you guys just transferred it through cables into whatever was in the truck? Yep, absolutely. That's exactly how it happened. That's pretty cool. Um, did you get a chance to look in the truck?
I'd be curious to know what it looks like on the inside. I didn't, and there was a— it was at least a 6-foot fence all the way around it. Oh really? I mean, it was logical when I figured out where it was and what it was, but looked pretty benign as you drove by it every day. Yeah, I wonder, is it just like a— is it like a rolling data center?
Do they have racks of stuff in there, or is it just— I don't know. Anyway, That just seems like a cool mix of old school and new school, right? It's, you know, all this electronic data, but it's on a truck. And what was amazing, one of our infrastructure folks did a presentation at the sales conference a few months back. It had pictures of this big IBM tape system in our data center.
Once everything's replicated, that's going bye-bye. Wow. So you think about, hey, old technology, new technology, and a whole bunch of different contexts. Cool. So you got to get the data there.
Are the applications there already in AWS, or are you guys in the process of moving stuff, and what's that experience been like? Yeah, good question. We are hybrid at the moment, so we figured if we can get the data there, the apps will move a little bit faster. In our data center, we have a private cloud with our continuous integration. We've got our development pipeline that's pulling data from a closed Amazon VPC.
So internet access is still via our main data center. So we haven't opened up the VPCs at Amazon to the internet yet, but that's certainly by 2020, we want everything up there. Yeah. And so as part of that move, are you guys changing your development processes, or are you, um, are you sufficiently new school enough in your development that you can just sort of port stuff over? Yeah, so another great question and another reason that this job was very, very attractive from my perspective.
I really enjoy software security, and our latest and greatest satellite, WorldView-4, is on our brand new P2020 platform. That platform is all microservices. It's continuous integration, continuous delivery. All other satellites are on our legacy platform. Also, it's called P800 internally.
That's a monolith code base. So we're trying to get everything right with P2020 integration of security, making sure we can take imagery when it's tasked to get to the right windows. That's where we make a large chunk of our revenue.
And the idea isn't to port code over. It's to take our older satellites and bring them onto the new platform. That's pretty cool. So you get sort of a fresh start. Yep.
Don't have to worry about any of the legacy cruft. So is there anything in particular that you've had to do around application security specific to AWS? Are you guys using containers and Docker and, you know, 8 zillion Amazon services that you have to worry about? Yes, so we bought a product called Evident.io.
Second company I've used it at. I like it. Think of that as one layer of the infrastructure security. Can do CIS benchmarking, has pretty good IAM capability and I shouldn't say that. Evident has good IAM capability.
They've done a great job of tying into the AWS APIs because they're just— that's all the data that they're pulling and putting it into a logical format that we can actually read. We created a KPI with a number of highs for each one of the teams that has an AWS cloud. Instance. And another telling feature is we see the highs month over month continually decrease in a pretty rapid fashion, which tells me it's pretty easy to consume from a development layer. Yeah.
And it resonates and it works.
The other security that we're doing, and it's not necessarily AWS related, but we're baking in static code analysis and open source management into the CI platform. Nice. So trying to get the defects as close to the development teams as possible. Yeah. And was that something that you started or was that started before you got there?
Yeah, there was certainly talk of it, but the first business case that I took to the investment committee was a pretty good dollar amount to do exactly that, static code analysis, Open source management, developer training. I mean, we've got a full program that we plan to implement around it. How has the reception from the development teams been around those pushes? Because traditionally you hear people, I don't want to say with horror stories, but it's, I really want to do application security, but my developers won't do it, or I keep getting pushback, whatever it might be. Yeah.
So the one technique that I learned from Jim Routh at Aetna is how to sell it. So I have a single slide that has the SDLC, trying to make this so you can picture it in your head, with a cost to fix. And the cost to fix is pretty stable until you get to the release point, and then it spikes up. So the selling point internally to the engineering management Hey, how would you like to have 15% more time to do more innovation, create additional features, do something different? Let's get these defects real-time to the developers versus getting to the release point where security is typically— we have no chance of stopping a release if they've been working on it for 6 months or a year.
And then it becomes a negotiation between my team and the product manager. Then it goes into the backlog somewhere and a developer ultimately picks it up that probably didn't even write that defect. So also tying in that developer experience, let's give that developer real-time feedback because I think generally developers, they want to know right there. If there's something wrong, tell me. They want to fix it.
And it really becomes a learning opportunity for the developers understand what cross-site scripting, SQL injection, whatever it is, it's not just fixed there, it's fixed forever in their code moving forward. That's awesome.
Do you, from the individual developers themselves, have you seen them grab onto this? Do you have, if they have questions, you guys have people embedded with the development teams or are they coming directly to the security organization? How are you making sure that that they're seeing the value in this and that they're not having questions, that they're not getting stuck on fixing the security stuff? Yes. So the team that's developing the continuous integration pipeline, they've also put together a dashboard.
So this dashboard will— the 2 components that I talked about, static code analysis, open source management, but it also reports on automated QA tests. So it's meant to be a single pane of glass where any developer or any team or anybody in the organization can look at it and say, hey, you know what, I just introduced 2 defects into the code. So getting it to the forefront and getting visibility, also creating competition between the development teams. Hey, you know, Team X has a defect density of 2.0. Team Y has, 0.1.
It's just starting to increase the velocity and people are, you know, they're competitive with one another at the end of the day.
Direct developer feedback, it's always hit and miss, to be honest, and it is a culture shift.
It's not perfect. Typical line that I'll use with a developer, you know, sometime in your career you're going to come up against somebody for your next job, you're going to have the same experience, you're going to have the same education, but you're going to write secure code. Just little things like that resonate. Something we did at Aetna, haven't done here yet, we're going to create a Maven's program.
There'll be 4 belts: yellow belt, green belt, brown belt, black belt. The yellow belt will be like OWASP-type training and then some quiz to, you know, yeah, that person got it and understood and passed the quiz. We're going to create some shirts, give folks a Yellow Belt shirt. Same thing, same concept from a Green Belt perspective, but this will be customized a little bit more. Front-end developer, back-end, maybe a QA.
So another set of CBT-type training with a quiz, but much less prescriptive when you get to a brown or a black belt. So brown belt, make a difference at the team level. Black belt, make a security difference at an enterprise level. Nice. I like that.
That's a really good approach. I can't tell you how many people when I was at Aetna, hey, Chris, how do I get one of those shirts? It's just a little thing that's pretty cheap at the end of the day if you get that type of adoption. Yeah, yeah, for sure. So switching gears a little bit, we've talked a little bit about the on-the-Earth security, but you obviously with satellites also have an in-space security concern as well.
What is the difference with security in outer space?
You know, it's a great question. And oddly enough, my boss this week asked me, you know, we need to start thinking about next-gen security in space. Because thus far, we've approached it in the same manner that we do everywhere else. So we've got operating systems on our satellites, typical stack, very isolated from a network perspective. But we still have the same issues as anybody else as operating systems get older, bugs, defects, whatever, and we have to be able to deal with them.
So it's about being able to deal with it but have a high degree of confidence that's going to not blue screen to death or— Right. It's going to come back up and be operational.
We've concentrated a lot on our ground stations. So if you think about, we've got, I think, 26 or 28 ground stations around the world. 4 of them on the commercial side. And the rest are— could be friendly foreign government-owned, et cetera, et cetera.
They're called direct access facilities. Facilities or DAFs. So those facilities we are just starting to fold into our threat and vulnerability management process. There are a lot of third-party components in there. So ensuring our third parties are up to speed, up to par, have the same standards we do, addressing gaps as we find them.
But again, not answering your question, it's a very typical security environment today, and we are thinking about how to do it differently moving forward. So, you know, if you guys brick a satellite because of a security scan or a bad patch, do they get to send you guys up into space to go fix it? Yeah, you know, that actually sounds appealing. We might brick it on purpose. But no, probably be in a lot of trouble.
Those are major revenue streams for us. And I think we depreciate the satellites anywhere from 10 to 15 years. So the life that they stay in orbit is important to us. Yeah. So what do you think, you know, you brought up the topic of next-gen security in space.
What do you think something like that might look like? It sounds like it's pretty standard today. Yeah. But where do you think you'll be in a few years in terms of security in relation to space? Yes.
So I know that between our satellites and ground stations, we have encryption so that we know when the images come down, we're going to decrypt it. We have the key to decrypt it. But starting to think through, and I don't have any answers yet, what could be some other layers of defense there? And how do we start thinking about it differently? How do we make sure it's ultra stable?
That would be first and foremost. But we also, we keep it safe.
One of my peer organizations, they have a direct line into Joint Space Operations. Wow. So JSOC. And they have They track everything in orbit around the world. So we do have layers of different types of defense.
We know if we're coming up on debris. We know if there's maybe a foreign satellite coming.
The capabilities of Russia and China, those are concerns. So one of the things that we've introduced into our organization And I'll joke with the folks internally, you know, don't poke the bear, don't poke the panda.
Because a lot of our business is with friendly foreign governments and we don't have to be overly verbose about what we do with those kind of things. I can imagine. So do you guys, do you build your own satellites or is that you contract with somebody to get the satellite or? Yes. So recently and typically in the past, we have contracted with Ball to build them and then Lockheed to get them into space.
But as you probably know, MDA is on the horizon. We're getting purchased. MDA can do all of the above and we buy our ground stations from MDA. So the end-to-end ecosystem, once the acquisition closes, will be MDA. Nice.
Well, so then you'll have another layer of security to worry about, the supply chain for all the pieces, parts that are coming in to build your satellites. Yeah, absolutely.
So one of the things that we had talked about prior to the interview is you guys have— you're obviously doing cool stuff, but you have the need, just like a lot of people, for really smart people to come do some of the work for you. So I wonder if you want to comment a little bit on challenges you guys have had in terms of getting quality people for these roles that you need, what sort of roles you're looking for, why is it somebody would want to come work for Ball— or Ball, we were just talking about— for you guys. Well, there's no reason to go to Ball. I would love to poach their people because they probably have knowledge that is very relevant in our space. Yeah, but, uh, you know, I, I think just like anybody else in the industry today, we're struggling with, with finding talent.
And, and I had a slide in one of our, our board decks around a million cyber openings. Yeah, I walked into the job, had 4 immediate openings. We have 3 filled now. Still looking for another engineer, but I also have a peer over on the government side that has a couple of— so that team is— they handle all of our secure side networks, but they've got an engineering opening. That's if people are familiar with ICD-503, very NIST compliant oriented.
On that side of the house.
We are ISO on the commercial side, but at the end of the day, my peer's name is Chris Schroll. Chris and I are trying to align to the point that we can. How can we have common processes, tools, procedures across our commercial and classified networks? Those networks will always be separate, but if we could use the same vulnerability management system, the same SIM, just starting to align those types of tools instead of having multiple expenses. How can we get economy of scale?
Yeah. The other organization in an internal decision that we made early this year, we have an organization called TSOC. So it's our Technical Support Operations Center. Okay. There are 4 shifts, 24/7, 365.
We decided to And they're doing mission control, make sure all of the imagery when it's tasked meets SLAs, that type of stuff. They're also doing Level 1 SOC. Oh, nice. So we've made an investment there. We're also trying to make sure as we foster talent, we have more career paths.
So that just created a career path into the US government security side along with the cyber side on on my team. So there is an opening on that team as well. We term it— it's an agile term— Site Reliability Engineer, but there's one for security. The Site Reliability Engineer for TSOC is responsible for working with my team to create the runbooks, making sure we get the repeatable processes in place. Following up on incidents.
And, you know, we want to push what we can to Tier 1 and then have our Tier 2 and engineering staff available when we get escalated events. And I'll let everybody know the reason that job is open is because the incumbent just moved into the cyber organization. Nice. Yeah. And she is responsible for above Tier 1 support and security engineering.
Well, I'm glad to hear that you've got some good people and they're getting promoted.
I think that's most of what we wanted to talk about. I wanted to give you a little chance if there was anything in particular that we hadn't covered that you wanted to delve into. Yeah. We actually talked about this a couple nights ago and it's about talent retention and we'd love to hear your opinion too.
I think, you know, while it's so difficult to find folks, we have to really work hard to retain who we have. And a couple of techniques that I've, well, I learned at Aetna, starting to use here at DigitalGlobe, give folks a portion of their time to go learn something new. Yeah. And keep folks engaged. And when I target new hires, I'm always looking, hey, I want to learn this, I want to learn that.
I want somebody that can go figure out what people just haven't figured out. The innovative approach to security, we can't continue to do it the same way. We've got to start thinking outside of the box. And I mean, you challenged me with the, the next jet in space, right? We need to go figure that out.
Yeah. Yeah. And I, you know, that's— it reminds me a little bit of— I can't remember, it's Apple or Google or both or, or one of those. Um, you know, they have the, like, a 10% rule. It's, you know, you get to spend 10% of your time on a project that, that you want to do.
Doesn't have to have anything to do with the business. It doesn't have to do with your job. It's just, hey, I want to go do something cool and I'm going to go do that. I've heard other people say, yeah, you know, I spend, let my people spend, you know, a certain amount of hours a week on threat hunting or, you know, other stuff like that. So it's, hey, you know, think of an idea and go see if it's true.
Is, you know, how can you prove whether or not we have Russian or Chinese actors in our network? Whatever, think of an idea and go test it. I think that is a great way to give people some freedom to let them go do what they want to do. I think for me personally, one of the things that I've always tried to champion too is I want people to grow, and if that means that they have to go somewhere else, I'm not going to hold somebody back because I know that they're good and I want them to stay. In the long run, it's gonna make them a better person.
It's going to, it's gonna come back to me, you know, whether I work with them in another position sometime or they come back in a different role. I think a lot of times people try and pigeonhole someone in the job that they have because they know that they're good at it, and then that's just gonna leave them, lead them to leave anyway, but not on a good note. Yeah, I agree with you 100%. Using the same 10% rule, give or take. I have a new hire.
She's been on staff maybe 3 months. We have a counterintelligence team, works heavily with law enforcement, a lot of top-secret type conversations. But she came to me a couple weeks ago during our one-on-one and said, hey, I'm very interested in this. I like the investigation aspects. And I paired her up with our counterintelligence expert.
So anytime he needs to task cyber to get something done, to go look at something, she's the go-to person. But yeah, I agree with you. If you pigeonhole somebody in, it will ultimately probably get negative and you want to avoid that where you can. Yeah, I think the opposite of that too is if someone is, you know, they're not the best at what they do, or they, you know, they're not showing an interest in something else. I think, you know, maybe a role swap or something like that can help retain them too.
Maybe it's not that they're a bad employee, but maybe they're not in the right position, and getting them in the right spot I think can help everybody the same way as well. Moving the deck chairs around a little bit can always always be a good thing. Yeah. And another— and maybe this is just a personal bias, but I tend to either go towards candidates that have a ton of experience or very, very new to the market. Yeah.
Yeah. And I, I've seen more and more people telling me that, hey, I'm going to the, the very new people, maybe not even people with cybersecurity experience at all, maybe IT experience or something else that will translate into that kind of experience, but that they want to learn. They have a desire to be in the field, and it's a lot easier for those people to come up than it is for you to hire someone with experience but maybe isn't real motivated or they're just looking for a paycheck, whatever it I'd much rather have somebody that you can train in the way that you want. This is where I have a lot of respect for DigitalGlobe. The HR department is so willing to listen because I've been pretty blunt about, okay, if we want to get somebody directly out of college, we need to have a good aggressive 3-year plan or we're going to be the training base for other companies to come and poach our folks.
Very receptive to those types of conversations. Yeah, that's a great point too. You know, it's one thing to hire the new folks, but if you don't have anywhere for them to go, you train them up, then eventually they're gonna want to go somewhere else. So, you know, if you want to keep them into a different role, then you got to have someplace for them to move up to. Yep.
Well, great. Thanks, Chris. I appreciate the conversation. Any other closing thoughts? I don't know.
Wonderful day here in Colorado. I want to remain in Colorado, and for the the folks out there, keep charged, keep motivated. Your passion is what's going to make the difference at the end of the day. Awesome. Thanks, Chris.
Thanks, Alex. This has been Colorado Equal Security, and we will talk to you next week.
Learn more about the Colorado security scene at Colorado Security. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.