Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.
Welcome to Colorado Equals Security. This is the newscast for episode 35 for the week of October 2nd. Alex, last week was Denver Startup Week. We have a couple of news articles from there, but We also had our panel. How did it go?
I thought it went really well. You know, it was you and me and Joe Bunnell, who was a participant and moderator. We had maybe, I don't know, 80 people? Yeah, 100. It was a pretty full room.
We had 90 minutes to talk about security and compliance for small businesses. It was an interesting topic, a lot of audience participation. Yeah, we managed to make it through without a lot of preparation and, you know, some good answers. Yeah, it's funny, you know, as much as us as security people, we think about security, it felt to me like most of the people there were thinking more about compliance and, and what did they need to do for their business to be able to operate in the markets where they wanted to work. Yeah, I think it was interesting, you know, Joe kind of took that, that tack at the beginning talking a lot about compliance, and it, to me at first, it was like, well, why are we talking about compliance?
But everybody was totally into that. Yeah, they all wanted to hear about compliance and And that was interesting. Well, let's go ahead and jump into the news. As a reminder, we do have a— we are on Google Play and the iTunes Store. You can listen to us on SoundCloud, of course, as well.
But if you subscribe, you get it weekly right into your podcast player. We'd appreciate your reviews and, and your ratings on the, on the stores, and hopefully that'll help us get some new listeners. So, and we are now official and have a rating on iTunes. Yeah, go check it out. And you won't know what our rating is unless you check it out, right?
Exactly. All right, let's dive into the news. Speaking of Denver Startup Week, there was a kind of one of the big stories this week because we had Mark Cuban in town doing a panel with Charlie Ergen that was moderated by Brad Feld, uh, really talking about innovation and, uh, and what it was like to reinvent yourself after being successful for quite a while. Yeah, and, uh, I think one of the sort of subheadlines of the, the story was that, you know, Mark Cuban made some incendiary remarks about the, the president, but Called him a Twitter troll, right? Well, you know, yeah, pot calling the kettle black, I guess.
So, so, but, you know, Brad Feld was on our show a few months ago, right? So kind of cool to get to see, you know, one degree of separation between us and the bigwigs there on the stage. Pretty fun. It's also cool when a few billionaires show up and just have a chat. So yeah, that part too.
Another big piece of news in the Denver community this week, we were named one of the 17 entrepreneurial engines that power our nation. Yeah, that was pretty cool. As part of this, the Indiana-based Lumina Foundation is targeting some grants towards Denver, $350,000 in grants towards education beyond the high school level. So that's pretty cool. Yeah, we don't know exactly what that means.
How do we get those dollars? Where are they going to go? But, you know, pretty cool that we've been targeted as one of those places that help America grow. And we're looking forward to hearing more. There is a list of the other 16 talent hubs, you know, a lot of places you'd expect.
And of course, Austin is on the list, just like every other list that Denver is on. Yeah, there are a few in there also that I was a little bit surprised at, like Tulsa, Oklahoma. You know, nothing against Oklahoma, but Fresno, California, I would not have put either of those on the list of, you know, cool happening entrepreneur places. Racine, Wisconsin. Hey, yeah, you know, that's one I wouldn't have thought of.
Exactly. Good stuff. So next, there was an article in the Business Journal about Business Advantages of Blockchain Smart Contracts. So, uh, this was just sort of giving a primer of Ethereum and the way that you can use Ethereum to make smart contracts. Yeah, this is really one of the, the difference makers, I think, for the new technologies that distributed ledger technology, which is what, you know, blockchain is part of.
And, uh, the idea that rather than having to trust when Alex tells me, hey, you know, when you lose 20 pounds, I'm going to give you $100. We can write it into a contract that if I do it and I can prove it, automatically he has to pay, and it's built into the technology. That's really what these smart contracts get into, enforcing contracts by technology. Yeah. I think I've seen some stories also about how there can be loopholes that you don't think of.
You write some sort of condition and something happens. Well, that condition might get met in a way that you don't expect. So the contract can execute in a way that was not intended. So you have to, I think, put a little bit more thought into how you're writing these contracts as well. Yeah.
And you still need some kind of arbiter, some kind of trustworthy source for whether a condition is met, because not every condition is as simple as, you know, stock price reaches an amount which the stock, you know, which, which is data that you can get from a feed. Anyway, interesting stuff and kind of a good article for folks to get a primer on, on where blockchain technology is going to take contracts in the future. Or a primer even. Uh, well, if you want to say it wrong, yeah, I'll give you a primer. Uh, Route 9B— so we've been waiting on this news for a couple of months, right?
Route 9B this last week actually got acquired. So their, their asset sale was scheduled for the 28th of September, uh, and that same day they took the auction down and ended up being sold to a capital company called Tracker Capital Management. Yeah, and so, uh, they're gonna take over Route 9B Route 9B will now be completely separate from Route 9B Holdings, which was the previous parent holding company. So the holding company is a public company with stock traded on NASDAQ. After they— the holding company sold off Route 9B to Tracker Management Capital— Capital Management— they had to actually pause trading on the holding company as they're trying to figure out what does this actually mean.
And, you know, are— is— are the stockholders for the holding company going to get the payout for this? We just don't know all those answers yet. Yeah. What we do know is it looks like the same management team that's been running Route 9B is going to stay in place with the new organization. And while, you know, you don't know if there's going to be any layoffs at all, it sounds like largely the company is going to exist doing the same type of work with the same people doing it.
So good news for those people who are getting their livelihood from Route 9B and for those who depend on them as customers. Exactly. Uh, so next, uh, CyberGRX was named one of Denver's 6 Gazelles. So, so Gazelles, every year, um, this is kind of a part of Denver Startup Week, uh, they name the city's list of rapidly growing companies that show the most potential for raising money and creating jobs in Denver. Um, so very cool to see a security company on the list again.
I know Ping Identity has been on the list before. I'm sure some of the other big companies have, but really cool to see CyberGRX recognized there. Yeah, I mean, you know, we talk a lot about how Denver's a great startup town, but even at that, having a security company on one of these fastest growing lists is really cool. Yeah. So next, there was an article, an interview, actually video interview on the LogRhythm blog with Sarah Avery.
We've talked about Sarah, I think, a couple of times on the show. She has helped organize the Women in Security group within ISSA. And this is sort of a brief glimpse into sort of her day and things that she does. She talks a little bit about women in security and other things like that. Yeah, she talks about the mission there.
Really, Women in Security is not just to help with women who are in security, but really to get exposure for girls and, you know, in school, junior high school, high school, junior high, get them exposed to security and help them see that as a viable path. She makes the very bold claim that her goal is to get women to at least 50% representation in security, which is awesome, right? What a great goal. I'm looking forward to seeing some success there. Next, we have a blog post which is a kind of an introduction to the new CEO at Webroot, Mike Potts.
He took over, I think his first week was actually last week, the 20-whatever that was, the 24th, whatever, last Monday. So he wrote a blog post here to let us know really what his mission is at Webroot. You know, I won't go into a lot of detail summarizing what he had to say, but take a look at it. He says he's gonna focus on reaching out to customers, automating and really scaling the processes they have, and investing in new technology. Awesome.
Alchemy Security had an announcement about their cybersecurity continuous monitoring solution. So we mentioned Joe Bonnell earlier as part of our Startup Week panel. Joe is the CEO of Alchemy Security, and they had a press release this week about using Splunk as sort of the backend for their continuous monitoring SOC services that they offer. Yeah. Well, so Joe does some really cool stuff there.
If you're looking for a personal touch for outsourced security services, he'd be a good one to reach out to. Our last article from the news was a blog post by Ping talking about whether it makes sense to use SMS for 2-factor for your customers. It's really kind of an interesting thing to think about. Generally speaking, we think about 2-factor for like our workforce users, right? You know, you know, as the CISO of a company, you think about making sure your your employees are using 2-factor to get access to corporate resources.
But it's a little different when you're talking about consumers or customers who are using your products, who you can't tell them what they, you know, have to install on their laptop or their phone. And how do you get 2-factor out to those? So this blog goes through a couple different options. SMS, what are the downfalls of it, but what are the benefits? You know, everyone has a phone, everyone uses SMS these days.
The drawbacks are that it's not as secure. And there's some other options where you can embed 2-factor into a mobile app. Anyway, interesting, interesting perspective on it. Yeah, and I think, you know, with 2-factor authentication, there's lots of ways to do the second factor, you know, whether it's a biometric, whether it's a, you know, an app on your phone, whether it's SMS 2-factor. And I think, you know, the most important thing is to look at that particular situation and see which one makes sense to you.
Yeah. Well, let's go ahead and dive into events. As a reminder, we do have 2 things. We have a store on our webpage if you want to get some Colorado Equal Security swag. We'd love to have you guys, We'd love to walk around town and see someone wearing the logo, right?
Number 2, we have an event calendar on the website, colorado-security.com, showing a lot of events. I'll tell you, as I went and added events late last week, probably added 20 different things. There was a ton of stuff coming up through the end of the year. So take a look at what's coming out further in the future, but we'll go through the next 2 weeks right now. First, DENSEC is doing their South meetup on the 2nd of October.
ISSA Colorado Springs has a professional networking event on the 5th. On the 6th, Coalfire is doing a HITRUST community extension program. On the 10th, the October OWASP Denver joint meeting with the SANS DevOps Summit. So this is, you know, the general OWASP meeting, but they're combining with another group. Looks like interesting content.
Hopefully you guys can join them on the 10th. Also on the 10th and 11th are the ISSA Denver October chapter meetings. On the 12th is ISACA's monthly meeting. And those are— that takes us through the end of events for the next couple of weeks. There are some interesting stuff coming out in November especially.
Take a look at the calendar for the first couple weeks of November. You know, we've got the CTA APEX Awards. We've got the Cloud Security Alliance's Fall Summit. Um, the, the governors with the NCC Governors Consortium meeting, a lot of cool stuff coming up there. So make sure you set your calendars for that.
Uh, I will say also on that, the OWASP one, you know, they're doing it in, in, uh, joint with, with, uh, SANS, but SANS is having their DevOps Summit and training here. So if you are interested in, um, learning more about security and DevOps, um, they do have, it's sort of a conference as well as normal SANS classes on, uh, DevOps and security that's happening. We'll go— let's go ahead and jump into jobs here. So first, um, Digital First Media is looking for a cybersecurity director. That looks like you would be running the security program for Digital First Media, which I hadn't heard of before but has a lot of different media outlets, and they say they have 75 million readers each month.
So pretty good reach for that organization. Ball Aerospace is hiring a cybersecurity operations lead. InteliSecure is looking for a cybersecurity intelligence expert. Oppenheimer Funds is hiring a cybersecurity engineer. eFolder is looking for a security engineer.
Xcel Energy is hiring a senior analyst threat intelligence job. I don't know why the word job is thrown on at the end, but that's kind of fun. Frontier Airlines is looking for a senior network security engineer. Vantiv is hiring a network security architect. And, uh, I know Mike Morado, who is probably the hiring manager for that job over there at Vantiv.
So if you, uh, if you're interested in that one, let me know. I can probably make an introduction. Uh, Edgelink is looking for a robotic network security architect. So humans need not apply? Is that, that's where we are?
Yeah, maybe cyborgs. Does that count? I, I assume if there's any robotics involved, you're probably okay to apply. All right. Yeah, then we do have 2 positions here for companies hiring, uh, presales engineers.
Ping Identity is hiring a presales solutions engineer, and then Swimlane is hiring a security solutions engineer. So if you want to work up in Boulder and work for a security automations and orchestration company, or in Denver for an IAM company, those are a couple good options there. And that's all the jobs that we have. That's it for the news this week. Uh, we have our feature interview with Mary Haynes.
Mary is the VP of Cybersecurity for Charter Communications here in town. Had a really good conversation with her a couple weeks ago, understanding how she's been in telco for quite a while and kind of the change over the last decade or so of what the job looks like and really sharing where she thinks it's going to go in the future. Yeah, I look forward to that one. I like Mary a lot. Cool.
All right, Alex, well, have a great week and we'll talk to you next weekend. Thanks, Robb. This is David McGuire, Director of IT Security at QEP Resources. This is Colorado EPA. Colorado Equal Security.
For Colorado security professionals, by Colorado security professionals. Welcome to Colorado Equal Security. This is Robb Reck, and I'm very fortunate today to have in my, my very own home, in the studio for Colorado Equal Security, Mary Haynes, one of the great leaders of security here in Colorado. Mary, I've got to know you over maybe the last 2 years or so? Probably so.
And is that about when you moved to Colorado? I moved to Colorado exactly 4 years ago. 4 years ago. Awesome. And from Kansas City.
Kansas City. I see she's holding a Kansas City Chiefs cup there. Go Chiefs! Woo-hoo! So not going to make you real popular in the Colorado Equal Security community.
But let's chat about your background. So you and I, before we started the interview, were just talking a little bit about recent current events. But what I don't know is exactly how did you start getting your career and how did you get into security? Ah, well, that's kind of interesting. I actually started 32 years ago in the communications industry.
I got a job at AT&T as a customer service rep. Yeah. And I did that because I wanted a Monday through Friday, 8 to 5 job. Prior to that, I'd been in retail managing retail stores, and I was young and single. So I got this job in customer service and worked my way up into management. So, so customer service, you were taking phone calls, people complaining about what?
That's what we always get, right? Well, it was right after divestiture, right after the Bell companies had divorced and AT&T was on its own. So customers calling about their bills, wanting to know rates for long-distance calls, that kind of thing. Awesome. Okay, go ahead.
Sorry. And so eventually I got into a leadership development program, and in that program I was identified as having a high technical aptitude. I also had been exposed to Unix and loved doing things in Unix, and so they needed more women in technology, and I literally got plucked to go be in the network security organization at AT&T, and that was about 25 years ago. Wow, that's pretty good. So you've been in telecom— well, you started in telecom a long time ago, right?
And obviously you're still in telecom now. So as you went into the networking area, how did that manifest itself, and what kind of stuff did you get to do? Well, I was brought in because I had a Unix background, and back then there were no tools to determine if Unix was secure or not. It was actually something Bell Labs was starting to look at, and my first assignment was to come in and take Unix systems, and we're talking, this was Unix System V, and so that's how old it was, and my job was to manually go through a system and figure out if I thought there were any security holes. And after doing that for about a year or so, I thought, this is really crazy.
Can't someone write a program that could do this more automated? And so they hooked me up with a couple of Bell Labs guys. We created what I would call the very first configuration auditing software. We called it the SWAN, and it was the security watchdog analysis tool. Nice.
And it was specifically designed for Unix, and it worked really well. We started rolling it out to all of our systems so I could get an automated view of what I considered security holes or misconfigurations. And then, of course, Windows was starting to become really big about then, so then we designed it for Windows. And we patented it, and it's the basis of a lot of security auditing functionality today. So you were, you were one of the first people to create a really long list of work for the sysadmins to do.
Yeah. That they never got through. Yeah. But I fell in love with security. When I joined AT&T's security team, they had some amazing security engineers.
Some of the guys that worked on the very first firewalls for the government, had developed some of the very first security technologies. So when I walked in, this girl from a call center environment, I was in awe with all these smart guys I was working with, and I think that's what got me so energized to be in this industry. Yeah, so, so you're talking like early '90s at this point when you're, when you're doing this hardening. It's interesting because we've had a couple of folks on the show, uh, Brian Martin, um, and, uh, Chris Nickerson, who in the early '90s were breaking into systems like, like yours to, to basically to learn, is what it sounds like. Did you have any, any run-ins with with not necessarily those guys, but that type, you know, the hackers who were trying to get access to the systems or, you know, do phishing or excuse me, phreaking, trying to use your phone systems to make free calls?
I knew about the phreaking, you know, and to be honest, it was a real mind shift for me because I'm a good Catholic girl, grew up, you know, going to parochial schools. And it was a real mind shift for me to move from being a very customer service oriented, helpful person to have the mindset of someone might be attacking me. And it took a long time. I couldn't believe why anybody would want to do that. But then as I started exploring, well, you know, someone could do this, or someone could do that, and if they did do that— so I saw myself those first couple of years take a complete different mind shift.
I didn't really run into people doing that personally. I just heard the stories about it. Interesting. So go ahead and take me a little further forward. You got your system and now kind of vulnerability scanner running and you used that for a while.
What was next after that? So, you know, obviously when I joined that team, I was the only girl. I remember going to my very first meeting and it was in New Jersey and I was based in Kansas City. And I had a coworker that when I got hired, he got hired too. And we were going out to New Jersey for our very first staff meeting.
And I remember walking into a room and opening up the conference room door, and we were late because we just traveled in that morning, and peeking in and seeing this room of all these men. And I thought, oh, I'm in the wrong place. Shut the door. And, and Bill's like, no, Mary, I think this is the right room. So I opened up the door again, and they said, are you Mary?
Well, obviously I'm the only girl in the group. They were expecting me to be showing up. And it's like, yes. And so, you know, here I'm in this organization with, you know, all guys. And as we started working together and had been there about a year or so, I think they really realized I brought a whole different skill set than anybody else did.
This is when we were trying to create our first security assessment methodologies. We were really trying to look at security more as a business versus I'm just a tech geek and it's all about finding holes and vulnerabilities. And so I brought in with me a lot of management skills and a lot of process skills. I'd been a Malcolm Baldrige quality facilitator. I had gotten our call centers to be quality certified.
And so the leadership began to recognize that. And so then I started leading a whole lot of process. How can we build processes? Not just go out and do something, but How could we write security policies and have a process to govern those policies? And with that, that kind of moved me into management positions and leadership positions.
So these guys that I used to be in awe of, now all of a sudden were working for me because I could take on those management responsibilities that they had no interest, no interest at all in doing, and really help build the organization. So I spent several years at AT&T, and then in 2000, AT&T was going through an opportunity where 50% of the employees could leave the company, and it was a voluntary option. And I put in for that because my kids were in middle school, and I thought, wow, this would be great to take a year off. And it was a great package. I'm going to take a year off, take this package, go back to school, get a few more technical classes behind my belt.
And I didn't get the offer. I was considered too critical at that point. That pissed me off. I said, great, my boss took it. And so right after I found out he took it, I told him, well, I'm taking another opportunity.
Yeah. So I eventually left there, went to a CLEC. What's a CLEC? A CLEC is considered— it's called a Competitive Local Exchange Company. So, right around the late '90s, you know, it used to be only a Bell company could be a local exchange company, and companies like AT&T and MCI were fighting that.
So, the laws changed, and it created a new business opportunity where people could create their own local exchange companies. It ended up being pretty much a failed business model. You don't really hear of Celex today. There are still a few of them out there, But I was attracted with a lot of IPOs to come over to this new CLEC that they were building in Kansas City. Yeah.
And walked in, knew that was a disaster right as soon as I walked in. So I did eventually leave and go to Sprint. And if people look at my resume, they'll think I changed jobs a lot, but I really haven't because then I went through lots of mergers and acquisitions, ended up at CenturyLink leading the security team at CenturyLink. But that was all through mergers and acquisitions. I technically never changed companies or lost my service.
It's just Sprint spun off their local telephone division. They created a company called Embark. They needed somebody to lead the cybersecurity team for Embark. So I did that. Then CenturyTel came in and bought us and made it a company called CenturyLink.
And then CenturyLink came and bought Qwest. And made it an even bigger CenturyLink. And so through all those mergers and acquisitions, I continued to lead and build and grow the security organization through those mergers and acquisitions. The Qwest one, when we bought Qwest, you know, that was— they have a huge security team, and it was based in here in Denver, Colorado. And that's when I fell in love with Denver, Colorado.
So when I started coming out here all the time for business meetings and to meet with the team, That's when I was like, wow, this is a really cool city. Yeah. And my whole long-term retirement plan of moving to Florida was now maybe I'd like to do Colorado in the summer and Florida in the winter with a couple of ski trips thrown in there. Yeah. So, um, that's what made me start looking at Colorado.
Um, I was kind of tired of all the mergers and acquisitions and the whole telco business and It's stressful going through a merger and acquisition if you've been through one. So I actually left CenturyLink and took a CSO job at our local electric company because I thought in 2012— That was in Kansas City? In Kansas City. Ted Koppels talking about how the smart grid is the biggest risk we have in the country, and it sounded like the exciting place to be from a security standpoint. And so I went over there.
A good friend of mine from CenturyLink had taken the CIO job, and so she really recruited me hard to come over to the electric company. And I thought that would be really exciting from a security standpoint. But what I learned, you know, I learned a lot about the electric business. And what I learned is most of it's not IP-enabled, and it's all in air-gapped networks. And, you know, while there is threats, I was actually spending most of my time doing physical security.
It's right around when the Sandy Hook event occurred. There were other active shooter situations. So I was— and copper theft was really big. We actually had 2 instances where people trying to steal their copper theft, they actually died because they got live wire. So they were electrocuted.
And I was spending 80% of my time dealing with physical security, which is not my passion. So I started looking for other opportunities, found this at Charter, and it was in Denver, Colorado, and I knew it's what I wanted to do. So I'm back in mergers and acquisitions again. Yeah, what was the big acquisition you guys had since you started at Charter? So the big one, we've had several, but the biggest one was last year we acquired Time Warner Cable.
And also Bright House Networks. So those are 2— obviously Time Warner Cable was the 2nd largest cable operator. So now I work for a Fortune 100 company, 2nd largest cable operator in the US, and the fastest growing cable operator in the world right now. And we were talking a little bit before that, you know, you're running— are you running all of the security functions for Charter, or is there another team that does some of the different stuff? That's a really good question because we have a really unique business model at Charter.
I say it's the 3-legged stool. So there's really 3 of us that run security. We do not have anybody that has a CSO title or a CISO title. I run the network security. So that means as a cable provider, I'm responsible for the security of our video services, your cable box, and all of that, your voice services if you subscribe to our voice services, and then our high-speed internet, the pipe that connects you to everything, right?
A peer of mine runs the IT enterprise security group, so I don't have to worry about Active Directory or any of that, although we share tools because, you know, anyone knows something that happens on your corporate network could bleed over into your service delivery network. And then I have another peer who runs what I call the traditional corporate security. She has an FBI background from out of DC. She recently joined our company, and so she has all the physical security, executive protection. Yep, all of that.
And then we have a governance model, so we have what's called operational steering committees and executive steering committees. Once a month, the 3 of us come together and put together basically a readout. We present it as a security program. We come together and monthly read out to all the business units who are part of our operational steering committee what's happening, what are our biggest incidents, what are the things we've done to improve our security posture, what's the status of where we're going, What does our vulnerability management results look like? And then we also, usually about a week later, then meet with the Executive Steering Committee, which is our Tier 1 leaders.
So everybody has a visibility into what's going on into security. And then every probably 3 months or so, we meet with Tom Rutledge, who's our CEO, and give him a summary of what's happened in the past quarter. So it's It's interesting. People, you know, a lot of people question how, you know, governance by committees really works. It can be challenging.
It's a model I've never had done before. I really struggled with it when I first got to Charter, and there was a lot of pushing and pulling between me and the IT security team. We've got our groove now. Yeah, like right now we're dealing with a couple of things going on, like there's an incident People probably remember a few years ago the shootings that occurred in Ferguson, Missouri, where young black men were killed by police officers, and there were a couple of events. And when that was all happening, Anonymous was very active during all that.
So not only were all those protests going on in the streets, and businesses were burning in protest, But also Anonymous was attacking the police stations, the court systems, the police officers' homes, tons of DDoS attacks. So that was a coordinated attack in many ways. And so I had to work very, very closely with the physical security people who were trying to patrol the streets, protect our employees, protect our facilities. While I'm trying to protect our customers who could be, you know, a victim of a DDoS attack. Yeah.
And sometimes those DDoS attacks were so big that it was affecting more than just the target. You know, the dang router that served the whole community was being impacted, and it could cause major outages in neighborhoods. So it's, it's interesting how closely we have to work together. My world is not just a pure cyber world, and I, I have to work really closely with both of my other legs of the stool. So I have a couple of, uh, maybe in-the-weeds questions for you about the committees, as this is something I think about a lot.
Uh, so you say you meet once a month. How long do those meetings last? About an hour. And how many folks do you have, attendees do you have there? Oh, probably about 20, 25.
So pretty good-sized group. What is the— is the intention of that meeting to get feedback from them or just to download information to them or something else? What's the purpose? Both. So one is to keep them informed of what was going on, also to provide direction and guidance, and then third, they have a voting role.
So as we introduce new policies and standards, they all have to be approved by the OSC and the ESC, and then they all have to review and have an overall vote on any exceptions. To security policy. So when you say policy, do you mean policy? Do you mean standards? Do you mean procedures?
What's a policy? What would they be voting on? So a policy would be that everyone needs to have a unique user ID. Yeah. And then the standard would get into much more detail, and the ID can only be used for this, and you've got to have a password, and the password has to be 8 characters.
Those would fall under standards. So no one's ever going to disagree, yeah, we all need a unique user ID, right? But then, because they're all, oh yeah, that makes sense. And then when you get into the standard and then all of a sudden they start to realize the implications of that mean, oh, that process I've been using for a decade is going to break, that's it. That's where those people's putting their hand up starts to add some real value, right?
Right. And I will have to say, our executives are really, really supportive of security, and I've actually in just the 4 years, seen a paradigm change. You know, again, we service millions of customers and millions of customers have to use our internet and our voice and video services. And when I first came in, I had lots of concerns about, you know, how customers authenticated, what we used for security questions, how we treated customer passwords. And it was like, well, we got to keep it convenient to customers.
We can't generate calls to the call centers. And that was the attitude when I walked in 4 years ago. Now, it has completely shifted. Even my customer care organization is putting security people within their organization to help promote all the principles and standards we're trying to create. And they've understood the value, you know, as we're now doing our plans for multi-factor authentication for our customers.
They're very, very supportive and are helping me drive these things, because they've really realized how this is going to impact their customers. Our customers expect everything to be secure. They don't want to have to worry that they've got malware on their computers. Most of them don't understand it, and they assume the ISP is just taking care of all that. It wasn't.
Our executives did not have that view 4 years ago. Now they have that view. It's our responsibility to take care of security for our customers. We're responsible for providing a safe and secure internet experience is now our mission. That's great.
That's really neat. So what are your— obviously that's your big charter. What are the key strategic things you're doing either throughout the rest of 2017 or looking into 2018? What are the projects you're going to be working on to help drive toward your charter? So keep in mind, when I came 4 years ago, there was nobody doing what I was doing.
I was technically employee number one for network security. We really, prior to that, only had an IT security group, and then we had a few people responsible for physical security. So nobody was looking at the security of the service delivery network except for those engineers that provided the services. And to be real, I don't think they ever thought security was their responsibility. So I had to start the program from ground zero.
And so some of the things you— I may talk about, you'll think, well, I would have expected that to be there already. Like one of our big initiatives is putting in centralized identity management for all of these backend systems that support the voice, video, and high-speed network. Today, each one of the teams manage their own. And through a NIST cybersecurity risk, using the NIST Cybersecurity Framework, we've identified risks and leadership truly believes we need a centralized identity management. And in the telecom space, you know, the only place you really saw that was around your network devices, TACACS, Cisco TACACS.
And I now need to go way beyond that. I need to look at all these video devices. I need to look at all these voice infrastructure devices, how does DNS play into it, and I need to take away that management from these teams that have probably created some problems for us and move it into a technology that can be centrally managed. We can utilize one identity and authoritative source for that identity and really get control. So that's one big initiative along with making sure that it's not just a password to get in.
Because these are considered, this is considered critical infrastructure. We serve a lot of critical utilities and businesses and so forth, and so we're applying all of the FedRAMP rules to it, even though we're not FedRAMP required. It's a good standard, that and the 800-53, for what we need. Network anomaly detection is a big one for us. We've been doing a lot of evaluations around that and are about ready to implement something.
Then cloud security. When I got there, we already had a lot of our business out in the cloud, in the public cloud, with our own private clouds in it. There was an assumption that, oh, they take care of security. It doesn't work that way. I've always come from a traditional environment.
I had never dealt with cloud security. Security until I got here. So that was a challenge for me because now I had to understand what did they do and what should we do. It's a big learning curve. It is a big learning curve.
And it was before people were actually doing presentations on here's AWS's responsibilities and here's your responsibility. I think AWS was just coming out with a document on that. Yeah. And, and now, you know, people talk about it all the time. But then I had to then help educate the business, oh no, they're not taking care of that, and I have no visibility from a security standpoint.
These are all of our customer portals.
So we've been spending a lot of time and we will continue to spend more time just really making that a tight, tight environment. I want to have as good of control. Then with containerization coming, And I shouldn't say coming, it's there already. How do I increase my visibility and have control over what goes into that container, make sure it stays secure, and I have the visibility into the container? Yeah, and you and I have talked about that a couple times in the past, and containerization is one challenge, which I think we can get our arms around containerization fairly well.
It's the CI/CD world that So the continuous integration, continuous deployment world that gets a lot tougher because all of the tools we've ever used all depend on having some time to run against them. And that doesn't necessarily live in a CI/CD world. And that'll be interesting to see how we adapt to that and move as quickly as our business wants to move from a security perspective. Any other priorities that you had that you want to talk about? Those are pretty good.
Well, you know, the other one that's a continuous one is just continuing to monitoring what's happening in the distributed denial of service world. With them doubling in size every year, we have— actually, Charter probably has the most aggressive approach to protection of DDoS. When I got there, there was nothing. And it was, you know, if you think about January of 2014 when amplification attacks were really getting big, we didn't have anything. So for years I was really beefing up the architecture.
And even as we acquired Time Warner, they really hadn't addressed it either. So we've been spending a lot of time, we have a very robust DDoS environment, but my team has to monitor every day looking for new ways they're doing DDoS. What protocol that we didn't think about that they might be using today? Do we have the bandwidth? Can my routers absorb all that?
And, you know, what can we as a sector be doing differently in standards to try to get this dirty traffic off our network sooner than later before it reaches the endpoint? So it's interesting. I'd love to hear your take on the question of where responsibility lies in a DDoS. You know, for a volumetric attack that's, you know, bandwidth heavy, I'm sure you guys think of that as kind of something you can handle. When we start to get to, you know, a super nuanced component-based attack that's not volumetric, it's, you know, hey, we're just gonna do, we're gonna hit this, make this request to this API a certain number of times.
You probably don't have insight to help your customers with that because it's not your APIs. Somewhere in the middle, there's a line. Do you have any feel for, you know, what you think of as your responsibility versus what's the customer's responsibility? Well, the FCC kind of lays out some of that for us. There's actually things I think we'd want to do to help better protect our customers, but we do have limitations as to what we're allowed to look at from a network standpoint.
We can look at the Layer 1, Layer 2 traffic. We're allowed to protect our networks. So if we see anything that could potentially damage our network, we have full authority to take action on it. But when you start getting into the data layers, we're not allowed to really look at the data layers. We have to anticipate from the network flow what's occurring.
And it's— this goes back to some old rules. They want to make sure that we don't have a competitive advantage over, let's say, a Google or a Facebook. But I will say, I think they know a lot more about you. But the Googles and the Facebooks of the world don't want us to have that ability So there's been laws and restrictions put in place that limit what we can do. If we didn't have those limitations, we could look at that traffic and better protect our customers at the application layer as well.
What about— I know some ISPs will have like an add-on service that's, you know, a higher level of DDoS protection. If you have— if they opt into an additional service, can you at that point get that additional access because they've engaged with you not as an ISP, but as a service provider for this DDoS mitigation? Is that something that's an option? It does have to be an opt-in capability. Right now, we protect our customers by default.
The same way I protect my network is how my customers get protected. Many companies are making a lot of money providing managed security services as an add-on. Our CEO's view is he wants to provide the best service for the best value. So he doesn't want to charge for every little feature and functionality. So as I implemented this DDoS infrastructure, I was not just looking at my traffic.
I was looking at my customer load traffic as well. And how can I protect them? Now, there are certain customers we don't automatically protect. You know, there are large enterprises. They probably don't want me auto-mitigating their traffic because they could be doing a big data center move that would look like a DDoS attack.
And so for those customers, if they need our assistance, we'll assist them on demand. But it's not our practice to offer a whole lot of managed security services. Gotcha. Okay, well, I want to take a left turn here if you don't mind. Okay.
Take us away from Charter and just talk about some of the work you've been doing in the community. I know you've been an active part in the new Women in Security special interest group here in Denver, and I'd love to have you just talk a little bit about what that group is. We had Debbie on here several months ago, but there's been a couple meetings since then, and maybe you could just kind of update us on, for those who've never heard of it before, what is the Women in Security group? And then for those who know about it, tell me about recent news there. Sure.
I'll be— I'm excited to talk about Women in Security. Actually, there were about 6 of us, and I have to give a lot of credit to Sarah Avery from LogRhythm. She's the one that really kind of kicked this all off. But we came together and we all agreed there was a need to create a networking group within Denver, and we called it Women in Security. It's actually a special interest group under ISSA.
So if you're an ISSA member, you can come to our meetings for free. We hold quarterly meetings. And we literally just kicked this off last June. So this is still pretty new and fresh. And we've had 3 meetings thus far.
Our first meeting was really a get to know everybody. And what do you guys want? You know, the 6 of us came together, a couple of CISOs, you know, Debbi Blyth, Nancy Phillips from Datavail, myself, and then a lot of other people from Optiv and LogRhythm. And we had our ideas, but we wanted to hear from the women in the community. And at our first event, we had almost 150 people show up.
We were hoping for 40, and we were shocked when we had almost 150 people. Yeah, it was really— I got to be there and see it, and it's just neat to see the need that's being addressed is obviously real. Generally, when a group starts, you know, it starts pretty small, and I'd say if you have 20 people come to a first meeting, that's really good. The fact that number one, you know, you guys were plugged in with ISSA and had some other channels to kind of get the message out so everyone knew about it, and how many people showed up for that first meeting was really amazing. Right.
Really, it really shows that there's a big need for this. Absolutely, absolutely. And we were kind of parroting off of— there was a women in security group in Kansas City, and it is significantly smaller. Yeah. So what we were expecting happening happened in Kansas city, that's what we were expecting here.
And in fact, the need is much greater. Our first meeting, we really did— we just were surveying, trying to get ideas. We had idea boards, and women love that kind of stuff. Let me do my goal board. And we did a lot of surveys, and we did a lot of networking to collect ideas.
And then our second meeting, we focused on your brand and why this is so important. We actually did 2 things. We had a guest speaker come in and talk about what is your personal brand. And then we had a CISO panel. So my peers and I got up and talked about what personal branding meant to us.
And for women in security, this is really important. Only 11% of the folks that are in security are female today. And, you know, and if you look at how we rejuvenate that workforce, we get a lot of our workforce as ex-military. Again, highly dominant male. Still at this point in time that are coming out of the military.
So our feeder pools don't really change that dynamic or that number. And so, and we're finding that women aren't staying in the field because it can be sometimes pretty demanding, especially if you're in an operational role. Anyone who's in security operations knows that's a 24/7, always-on, and sometimes can be pretty demanding if you're in a middle of a potential incident or something like that. And so we tend to lose women in the field because they have a hard time balancing. I think the other big reason we lose a lot of women— and this is the thing I talk the most about— is that women generally don't come across as confident as men do.
And there's a lot of studies behind that. There's a great book out there called The Confidence Code that I encourage all women to read. But it talks about how, for example, if a man is looking for a job in security and he sees that he meets at least 40% of the requirements in the description, he's gonna apply for that job. And when he goes for that interview, he's gonna talk about how he meets all of those requirements. If a woman sees that same job, she'll only apply for that job if she meets 80% of the requirements.
And she'll go in and talk about what she doesn't meet. So we all kind of set ourselves up for failure. And even how we conduct ourselves in meetings, it's very common that a woman is the only woman in the room when we're dealing with some of these security issues. And we don't always come across confident with our ideas. Clearly, I don't have that problem.
You've seen that at most of our CISO dinners. That's something I overcame a long time ago. In my career, but it's something really women in security need to work on. So having that meeting around personal brand and then kind of sharing our brands as executives and how we went with it and how we make ourselves appear on Facebook and social media. And then our last meeting was so much fun.
We just had a meeting this past week on September 14th. We brought in the Cyber Patriots from Highlands Ranch High School. And we had 4 different tables where the students got to show us what they had learned. We had one student showing us how to use Wireshark. We had one set of students showing us how they did offensive security, because that particular CyberPatriot team actually won some competitions at nationals.
And so they were— We talked to them on the show, by the way. Yeah, and they were showing us how They defended it. They showed us how they did Windows security, Linux security, and why that was so important. And there were girls in that group as well. But we wanted to really encourage these young people who are looking into security and really wanting to be in the offensive side, that there's this whole community out here that really supports them.
And how can we as local businesses create internships for these students? 10 years ago, if I could have a kid coming out of high school with these skills, that would be amazing. Yeah. And now we actually have kids coming out of high school with some of these security skills, and now we as employers need to figure out how can we build that into our programs and get these folks into our world and onto our staff. So we're trying to do a thing with Women in Security.
We're meeting quarterly. We're trying to balance soft skills with technical skills. So this last meeting we had was hopefully teaching some of our own women how do you use Wireshark, giving them some technical skills. We also had several companies there that were doing recruiting, and we do hope to plan to focus on mentoring also, because we do have a lot of female executives that are part of that program that are more than happy to start mentoring some of the other women that are either entering into security or need someone to help coach them through their career. It's been very exciting.
So you can follow us by looking at the ISSA website. You don't have to be an ISSA member. You do have to pay a fee if you're not an ISSA member. It's actually cheaper to just be an ISSA member and come to all of our events, and we'll tell you about other female security events that are going on, like Cyber Girls and other things that are going on. Then we also have a LinkedIn page, a Facebook page, and a Twitter page, Women in Security Denver, so you can follow us there too.
Awesome. One of the things you talked about a little bit was some of the why behind why there aren't as many women in security as there are men. I heard some interesting research. I'd love to bounce it off you and kind of think about it for a moment, where the number of women— and it's not security specifically, but in technology and IT— it's about 18% of the workforce in IT is women. And then if we go back to the number of women who are enrolled in undergraduate degrees in colleges around technology, it was about 18% as well.
And when they looked at high school opt-in attendance at technology stuff in high school, it was about 18% as well. So there wasn't a lot of dropping out along the way. It was just people not opting in. And which really, I think if that research is true, which I suspect it is, I got a pretty credible source, it kind of tells us where we need to focus, right? Maybe we don't need to focus quite so much on the, at the end of the pipe, but at the beginning of the pipe.
And how do we, how do we make technology an attractive field for, for young, for girls and young women to, to pursue as they think about their career? Have you guys talked about this at all? Any thoughts about, you know, how do we start funneling more folks, more, more women into, into that area? The Women in Security, we've been spending a lot of time talking about that, and that's actually one of the reasons we brought CyberPatriots in. 'Cause we actually do believe it begins in our schools.
And getting the girls to change— I've seen 2 things that really have a huge influence as girls are trying to decide where their career path is gonna be. One, just what's their family setting? When you look at a lot of the girls who are going into technology, more than likely, they have a parent that's in technology. So that is helping. And I would encourage other people that are in technology, if you've got a daughter coming up through the ranks, really, you know, don't just talk to your sons about it.
Talk to your daughters about it too, because you have a huge influence. And then the schools that have these programs, like my kids, I'm an empty nester, so my kids are all grown. And when I look back at at my boys, you know, they never want to do what their mom's doing, right? That would be uncool. And their teachers are huge influencers.
And my kids never had a program like a Cyber Patriots or a Cyber Girls program. So it's— I think it's up to the schools. And so what we can do as being involved in the community, if we as technologists can start spending more time with the schools and help them build those programs. I think that's what we really need. And as women in technology, we need to really focus our time because those girls need to see us and see how successful we've been in our careers and see how we've been able to provide for our families.
I've always been the breadwinner in our family. And I think girls need to see that, especially if they have a stay-at-home parent. You know, you don't have to be a stay-at-home parent. You can have a very successful career. I mean, I raised, you know, my kids.
I was the president of the PTA and had a great career in security. You can do it all if you're willing to take that all on. So it does start in the schools. Did you see the news a few months ago when Palo Alto teamed up with the Girl Scouts? Palo Alto Networks teamed up with the Girl Scouts to release— Saw that announcement.
They call them cyber badges or cybersecurity badges. Uh, it, you know, for those who are— who aren't aware, um, you know, both Boy Scouts and Girl Scouts, they have a badge system. You go do some work and you get a badge to put on your vest. And, uh, so they're— they've created, uh, some badges around security. It's cybersecurity.
Very, very cool. And, and a way to, to go earlier in the pipeline, right? That I thought that was one of the most encouraging things that I'd seen. I'm sure that Girl Scouts is a very small percentage of the girls out there. I don't know what it is.
2%, 5%, I don't know. It's very— I'm sure it's a very small percentage of girls, but at least it's something, and someone's really going to the right place. So very cool stuff. Uh, well, I just want to say thank you for your work, um, helping get Women in Security going and, uh, helping organize and be part of that, that core team that's, that's helping to do that. I think it's something we really needed in Denver.
We've, we've known we needed it. Uh, you know, I've been involved in the community here for 7 years or something, and I probably had 20 women over the 7 years come and ask for something like this and encourage them, yeah, you should go start it and, and then not do it. And then Sarah Avery all of a sudden went from, I got this idea, to like doing it 3 days later and making this whole thing, you know, pulling together a community to do it. So also big kudos to Sarah for, for being that driving force. She's absolutely— she is relentless on this stuff.
She is. She's, she's cute. She's quite the taskmaster on all of this. That's what we need, Sarah. Keep it up.
But we're having so— we're having a lot of fun. It was a little crazy in the beginning, but the networking and the relationships that we're building— we spend more time networking at these meetings versus having content, and the women really enjoy and appreciate that. Matter of fact, we have a hard time getting people out of the building when the meeting's over because everybody's continuing to network. And I think it's been very, very rewarding. I've met hundreds of people that I probably would have never met before.
It's interesting that you talk about the networking versus education paradigm, and you're putting it in the context of women in security, but from my perspective, this is applicable to everyone. It's easy for us to see the tangible benefits of education, of going and getting trained on a certain technology. It's a little bit harder to for us to see and get motivated to go do the networking. But if I was to say, my experience has been if you want to impact your career positively, invest more in networking than anything else. The people you know, and it's not even just about who you know to get your next job, it's about the people who you meet.
Like getting to meet you and hearing your experiences has taught me a lot about how to do my job better and make me better at the job I already have. And then knowing people who I can call when I— when something comes up at work and, you know, there's a network of 100 different security leaders in Denver now that, you know, one of them knows how to solve this problem that I'm running into. Exactly. Who do I call? Just the networking.
And don't do it— let's say one thing, the big thing I see is don't do it just when you want to get a new job, right? It doesn't sound— it comes across as self-serving and it's just not part of the community, you know. Do it early, get involved, you know, go get networked early, meet people, offer to help, and then when you need help, they're going to be there to help you as well. Absolutely. I, you know, I, I— the main reason I do networking is I learn so much from my peers.
You know, the problems I'm facing, somebody else has probably already faced that same challenge, and why should I have to go through all the pains they went through? And, and vice versa. So if, you know, I tend to openly share— I won't share information about my company specific, but, you know, well, have you thought about this? And oh, watch out for this. I get so much more from that.
So, you know, if it ever does become a career thing, you know, at least I could leverage that. I can't say I've really used networking for my career. Most people do at some point. You got your job from it at the electric company from a boss who you used to work with. Right.
And I— That's who you know, right? And when I applied for Charter, you know, I didn't know anybody at Charter because I came from telecom, which is a little bit different than cable. Sure. But they saw my name come across and they're like, that's Mary Haynes? Well, we know her from all these committees in DC.
I mean, I literally got a phone call that afternoon from HR saying we want to interview, and I was on a plane the next day because they knew who Mary Haynes was because of my reputation in the telecommunications industry. And so you, you may be networking and not even know it, you know, and it may come to play when trying to fill a position. Just help people. And exactly, I don't know if I believe in karma as an idea, but karma as the way it works here is absolutely true. You know, you help people get— they're gonna know who you are and they're gonna help you later on.
All right, so we're getting a little bit short on time. Anything else you want to share with the community? Any pearls of wisdom or anecdotes you want to tell? I don't know if I have any anecdotes I want to share, but right now my philosophies are all around 3 things for my organization. Don't come to me with a solution unless it can automate something we're doing, it takes advantage of machine learning, or it has artificial intelligence, which we all know today most of that's machine learning.
But as we look at initiatives going forward, I'm trying to move away from all the standard detect and alert and all the traditional ways we've been managing security. We really need to look at security orchestration and how can we move forward. I think we're going through a paradigm shift in how we're going to do security going forward, and how can we be more proactive and preventative versus detecting and responding, which is where we really have been the last 10 to 15 years. Those of you can help me move in that direction, I think that's where we need to be, and if you're not there yet, definitely build some plans around that. Have you talked to the local guys at Swimlane?
We had Cody Cornell, he's the CEO founder of Swimlane. They're one of the security orchestration, you know, there's only a few of them, like 4 or 5 that have got significant mass doing orchestration and they're local here in Denver. You should get to know them. Good guy. I know some of my engineers have met with them.
Yeah, right on. All right. Yeah. Well, Mary, thanks so much for your time. Hopefully we can catch up with you maybe next year and you can tell us what's changed and where Charter's going.
Well, thank you for inviting me, Robb. All right. Appreciate it. Thanks, Mary. Alrighty.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Remember, Colorado equals security.