Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to the Colorado Equals Security Podcast. This is Robb Reck with my friend Alex Wood. Alex, this has been a big week.
Have you, have you heard anything in the news recently? Uh, no, it's been pretty quiet this week, Robb. Not a whole lot going on. Yeah, a little, a little bit of, uh, a little bit of news. Hopefully, um, you don't need to go get any credit anytime soon.
Might not be the safest thing to do. Obviously alluding to some pretty big news that came out, uh, Thursday of this last week. Exactly. Yeah. So I think everyone has probably heard by now, but Equifax announced a gigantic breach, uh, essentially affecting half of the United States.
Yeah. I, I mean, I— half of the 143 million potentially impacted, right? Uh, which is most of the adults that probably have a credit history. Although I have to say, you probably don't know if you're affected or not because their website is so poor that you can't really tell. Yeah, there's— you go from equifax.com to, uh, what is it, like something equifaxsecurity2017.com to, yeah, to trustedidpremier.com.
It's pretty bad. It was nice of them to set up a brand new WordPress site for this Equifax 2017 security with essentially, um, no security on the WordPress site. But hey, yeah, but they're throwing in their secure— their monitoring. All you have to do is give them a little bit more information and yes, they'll track you, uh, and you know, wait for them to ask you for more money about it later. So there's a lot of interesting news about this breach, and while it's not Colorado specific, it does impact everyone listening to this podcast.
So let's just talk a little bit about the implications. We don't yet know all of the information that may have been breached. Um, certainly, you know, some of the obvious stuff— Social Security number, driver's license, home address, name— all those are pretty presumably part of the— That was definitely what they said, that those were affected. Yeah. But I don't, I honestly don't know that they know very well.
Yeah. I don't trust the fact that they have completed their investigation and that it's been thorough, but you never know. You know, the big thing that concerns me, and I think we talked about it just a little bit, is the idea about our out-of-wallet type questions, that knowledge-based questions where, you know, if you're signing up for a new loan, they might ask you, you know, which of these streets did you used to live on? Or, you know, Which of these cars did your sister own? You know, they'll ask you those types of questions.
And that, that gets really difficult because, you know, if you go reset your bank password and you reset your, all your information, it's those out-of-wallet questions they use to get back in again. Right, right. And they said that their main credit monitoring databases were not affected. Yeah. So presumably that information is there.
But honestly, we really still don't know. Yeah. It just sounds awful, and it's going to be a bad thing for everybody. So a couple of, uh, really interesting side notes that have come off of this breach. Number one, uh, was reported just a couple hours after the initial breach that it looked like there was some insider trading, some executives of the company who sold stock after Equifax became aware of the breach, but before they announced it publicly.
Yeah, the official statement from Equifax was that those folks didn't have any knowledge of the breach when they sold the stock. Um, but come on, one of them was the essentially North American head of security. One of them is the CFO. Uh, you would think that if there was something that was potentially this big, that they would have known nearly immediately. You'd also like to think that they wouldn't be so stupid as to do that, right?
It's really, it's really hard to tell, and certainly we're not able to pass judgment on it. It seems it's a horrible press for them, whether these guys did it intentionally or not. Makes Equifax look significantly worse. The only thing I can say on the insider trading piece is that many times if you are a certain level of executive with a certain amount of stock, you prearrange the date when these things are happening. So if this stuff was prearranged, okay, that makes sense.
But beyond that, it seems a little fishy. So before— well, before we, you know, crucify them, right, let's go ahead and get the data, understand what actually happened, and then, uh, they'll go to prison. And then crucify them. Well, they'll go to prison if, uh— no, no, no, literally crucify them. And that's That seems fair.
Yeah, it's a measured response. And then the other tangent that came out that I've now seen a couple articles about, and we'll put one in the show notes, was that there's a rumor that this— the attackers, the people who stole the data, are actually not looking to sell or monetize the data. They're looking to extort Equifax to get basically to pay to get this data from being released. Yeah, I think that they were asking for like $6 million or something. $2.7 million, 600 bitcoins.
So 600 bitcoins, yeah, $3 million. And the reason that they asked for $3 million was That was, I think, twice the amount that the, the people who sold stock profited from. It was twice the profit of the insider trading that they saw, which, you know, it's, it's, it's an interesting thing. Of course, if you're Equifax and you believe that, that they really would delete the data, this is a no-brainer, right? Go, go spend— you spend $20 million to make it go away.
However, is there any level of assurance that this goes away after that? I did see that those attackers were being very nice, though, and they said that if they do dump this data, they're not going to dump people's credit cards, you know, to help us all. I mean, instead to keep those credit cards to use them on the black market. Oh, is that what the plan is? I did— they said that they wouldn't be selling the data.
They were just gonna dump it and give it away. Except credit cards. Except credit cards. Oh, well, they do have to make their money, right? Exactly.
They have to pay the bills. Well, if they're not gonna get the $3 million from Equifax, they got to get something out of it, right? Yeah. So obviously there's a ton of information on the web. Every major media is covering this.
We are Uh, obviously not gonna get a lot of new perspectives, but I wanted to make sure we talked about it just a little bit. And the one other thing that I want to add is that, you know, the rumor that I had heard is that it was a, an unpatched web application flaw that, uh, that led to this, which it's extremely disappointing if it's, if it's something that is known and really that easy, you just didn't patch. Patches are available, but not applied. That's, that's the rumor. Now, once again, unsubstantiated, we don't know, but, but that is the rumor out there.
Yep. We have, we have some good news, something interesting going on, right? Well, some potentially good news. So, uh, it was announced this week that Amazon is looking to start a second US headquarters, um, which is sort of odd for a large company. You know, usually you'll have a North American headquarters or a European headquarters or, you know, global headquarters, global headquarters, whatever it might be.
Uh, but they've decided they want a second US headquarters and they're, going to have essentially a bidding process to have cities bid for the potential location for this. It doesn't seem like it should be called a headquarters. Like, you should be— you should have one of those. But it's a really neat thing that they're doing. I'm kind of thinking of it as the golden ticket from Charlie and the Chocolate Factory.
You know, what are we going to do to get one, to make sure we get it? I think the good news is Denver meets all the criteria, right? Amazon gave a few criteria. You have to have at least 1 million people in the area. You have to be close to an airport.
Yeah, I think it makes a lot of sense. Legalized. I made the last one up, but we do hit all those, including the bonus question. And there are several Amazon warehouses here already, so they definitely have a presence. Yeah, I think that they have more than just warehouses.
Isn't there some stuff towards Boulder? Yeah, there's employees in both Boulder and in the tech center. Yeah. So this is potentially, you know, $5 billion towards the headquarters, which is a good economic boost. Plus 50,000 jobs, right?
50,000 jobs potentially. That's a lot of jobs. So I, I'm sure that people will be throwing their hat in the ring for tax incentives and other things. It sounded like both Denver and Aurora were going to put together packages at least, and I'm sure more than that. Well, big hick.
And we want to get— we want to make sure we're in there. Don't, don't fail to, to come to the table with something good here. I think it would be fantastic. I'm willing to, to get part of this Hunger Games. And if we have to kill the people from Austin or wherever it is, it's got to be Austin, right?
It's going to come down to Denver and Austin. Austin. I'm thinking like, you know, Omaha, Nebraska, maybe. I don't think they have the population, Alex. Probably not.
I think we're in good shape. Minneapolis, maybe though. Minneapolis. All right. So anyway, that's gonna be fun.
And obviously, we'll cover this as more news comes. Next on the list, Optiv had some announcements this week. They added 2 big names on their board. So Dave DeWalt, formerly of FireEye. And also, was it McAfee or McAfee?
Right. He was the McAfee founder, I think. And then before he went over to FireEye. And then also General David Petraeus. Yeah, so big, big board names.
And they've had, they've had a ton of kind of churn over the last year or so since KKR— well, 6 months since KKR took over. But, you know, hiring some, some big names to maybe stabilize things over there. Interesting, interesting news, and hopefully great news for them. Certainly glad to hear that they're making some big acquisitions on their board. And it looked like in that article that Dave DeWalt wanted to be involved in sort of day-to-day operations and not just someone that is on the board.
So interesting. So another leadership change in town. This one kind of came out of left field for me. Webroot has a new CEO. They announced that Dick Williams, their previous CEO, has retired, stepped down, and Mike Potts is taking over as their new leader.
Yeah, congratulations to Mike. I don't know him personally, but I'm sure it'll be a good move for Webroot. And I know we've actually reached out to see if we can get a chance to talk to him and get him on the show. Yeah, that'd be fun. Next, Conversant, who we've talked about, they make compliance and training software.
They are hosting their 2nd annual ethics and compliance event, Converge '17, on the 3rd through the 5th of October. And I have a brilliant idea, Robb. I think we should invite all the Equifax executives to the ethics training. I can't understand what the relationship might be there. Obviously, there's no hint of any unsavory things going on at this point.
Yeah. No, no, it's perfectly fine. But I agree, it couldn't hurt to make that invitation widely available. Anyway, interesting stuff. Conversant, they're doing really well here in Denver.
And if you want to go learn about the ethics and compliance training, that sounds like a pretty cool thing to do. Next, Ping Identity, we're having our Identify customer conferences. That's kind of traveling around. There's an event in San Francisco, New York City, and London. And we put this in here because this is also my travel schedule.
I get to, I get to go to these things in the next month or so. It should be fun. Basically here, you know, Ping gets to talk with, with customers showing, you know, what we do and, and how to be successful using our products. So if you want to stalk Robb, go check out the, uh, the Ping Conference series and figure out where he's going to be. Yeah.
Uh, next, SecureSlet had a blog this week. New NICE framework creates consistency for employers and agencies. So NIST released the framework called NICE. I'm going to forget the acronym, but it's— it involves, uh, cybersecurity workforce. So basically they're trying to standardize on the, the types of jobs that are out there for cybersecurity.
So I know a lot of times you'll see, you know, security analyst, security engineer, security— you know, lots of different names. But so they're trying to, to, to get a consistent way to look at the different things you can do in cybersecurity and then make sure we all have a consistent understanding of them. Yeah, that's great. Uh, next we have a blog here from Swimlane, and this one is Realizing an Information Security Risk Management Framework. Headline might not mean a lot, but I love their, their subheadline: Every security manager must confront the reality that there are far more risks than it can ever be reasonably managed.
And really the point of this blog post is to say, hey, you can't just reactively go after you know, whatever's top of mind. We really need to be systematic about what risks we're going to address. Risk assessment, a process that looks holistically at the whole environment. And what this blog post goes through is a lot of different formats and standards one can use in order to implement a risk management framework. It's really kind of a good starting point.
I'm not sure Swimlane— I was a little surprised that they were looking at it, but really good information in here. Yeah, it is good. And they do talk a little bit at the end about security automation and orchestration, which is their bread and butter and how this fits in with that. Dialing out of order, right? Exactly.
And then finally, we wanted to say thanks. For those of you that have gotten a sticker, you know we have wonderful stickers, but the amount that we had only went so far. So Sean Murray from Colorado Springs of the Murray Security Services Cyber Academy, also a board member on the ISSA International Board, we work together there. Was nice enough to donate some stickers to us. So we now have a fresh supply.
So if you're in need of more stickers, we got those for you. Yeah, I really appreciate that. This is the first sponsorship we've had as a show, right? Everything else has been out of pocket for us. And so big thanks to Sean and his company for, for stepping up and helping support the, the show and the movement.
If you guys see us around, ask for a sticker. And if we don't have one with you, hit us. That's fair. So a couple housekeeping things before we move into events. Uh, we've said it before, but we have a store, so go out and buy some Colorado Equal Security stuff.
Also, if you want to go to iTunes and rate us, we would appreciate that, uh, as long as it's a perfect rating, no other ratings besides that. And also, you know, if you give us a little, little text of a review there, that'd be great as well. Yeah, it takes— it actually takes quite a few reviews before it'll show up in the store with, with a rating. So if you guys don't mind going out and spending a few minutes doing that, it'd be, it'd be helpful for us and Doesn't hurt you guys too much, I hope. Perfect rating.
As we, as we dive into the events, a reminder on the website colorado-security.com, we have an event page. And if you remember, last week was pretty mellow. It's the exact opposite here going forward. So we'll go a little bit quicker in the next 2 weeks. I think we had like 23 events to come up in the, in the session here.
So the first one on the list, ISSA Denver is having their September chapter meetings on the 12th and 13th. Dionne Mahaffey is presenting and she is talking about their selection process for replacing their endpoint security. On the 13th, the CTA has their Insights series with Forrester Research. So some Forrester analysts available to come talk. ISSA Colorado Springs is doing their September chapter meetings on the 13th and the 14th.
And also on the 14th, the ISSA Women in Security Special Interest Group is getting together. And yet again, a great turnout. Looks like we're going to have well over 100 people at this one again. And I'll tell you, the first time it's not just women signed up, quite a few men coming out to support. How do we help women be more effective in security?
SecureSet is doing a Career Conversations, Hillary Constable, on utilizing your network. We talked about that one last week as well. That's on the 14th. And on the 16th, there is a CCSK training— that's Cloud Certified Security Knowledge training— that's going on. And that's with, uh, Muhammad, who is one of the, the board members for CSA in Denver and also one of the employees over at the state of Colorado.
On the 16th, ISSA Colorado Springs is doing one of their mini seminars, so go down and have a couple hours with them, learn some stuff, and get some CPEs. And next week, the 18th through the 23rd, SANS is having their SEC511 Continuous Monitoring and Security Operations. That's going to be held at the LogRhythm office in Boulder, and it's not too late to get signed up. OWASP is having their September chapter meeting on the 20th. That'll be at Dave Buster's in Denver.
On the 21st, Chorus 360 is having their security symposium. This is a free event, right? It is. And it's, I think it's a half day, basically. Go get to learn about some security stuff and get to meet some cool people at Topgolf.
I believe it's a Topgolf. So maybe there might be some fun as well. I think there'll probably be a little bit of fun there. Yeah. Um, on the 21st, ISC2 is doing a Denver meeting.
Uh, John R. Nye, um, from Synergist Tech is speaking, and that's going to be at the SecureSet location. On the 21st, we have one of— another one of the Denver Sec Meetups. That's the kind of laid-back happy hour, go to a bar and meet some other security people. If you're going to go to this, go on Twitter and follow them there, as that's how you get the communication and you know what table they're at. On the 23rd, there is a CyberTech Girls event.
And that is it for our events for, for this, this week. Let's jump over to jobs. We have some pretty cool jobs this week. First, Opus Bank, which I hadn't heard of before, but they're hiring a senior information security program manager, probably someone who's helping really run security for the bank. Yeah, that sounds like a top-level sort of security leader position.
Vertafore, they're looking for an application and product security manager. And we talked about that last week. But Robb, I think you have some additional information. Yeah, I talked to Adrian. Who's the director and the boss of this one, and I asked him, hey, give me a sentence or two summarizing what you're looking to hire.
He said they're looking for a thought leader that's ready to change the traditional relationship between developers and security into a more collaborative interaction instead of really looking at a gatekeeper mentality. So you want to really run an enabling application security product, this is going to be it. Next, Prologis is looking for a senior security analyst. Awesome. Wow, which is Wide Open West, they're an internet provider here in town.
They're hiring a senior security engineer, and we did talk to the director hiring this, Steve, and he mentioned that the ideal candidate here will have strong Splunk skills, preferably using Splunk ES, which is enterprise security, a strong technical background, and they want a problem solver, not just a tool manager. Proofpoint is looking for a senior sales engineer. And Tenable is looking for a regional sales manager for the West here, located here in Denver. Nice. SecureSet is looking for a career services manager.
So if you want to help the students at SecureSet get jobs, it sounds like that's what they'd be looking for. It's got to be the easiest job out there, right? Those are some quality people coming out. So the, the career services managers just got to be fielding incoming calls from employers saying, how many good ones do you have? Maybe taking bribes to send people their way.
Anyway, as you said, good candidates coming out. Really good program. Pearson is hiring a cloud security architect. And then Security Wolf is looking for a cybersecurity consultant. That takes us to the end of the jobs.
We— sorry, go ahead. I was gonna say we did have one other job from Digital Globe. But when we were checking it out just before the show, it looks like it's been filled. So congratulations to the Digital Globe people for filling that job. Congratulations to you listeners.
For getting that job filled. Exactly. Uh, with that, we're gonna have— go over to our feature interview with Randall Frietzsche. Randall recently took over as the, the CISO for Denver Health. Uh, if you guys remember, I think the, the second week of our show, we interviewed Drew Labbo, who was at that time the CISO for Denver Health, and he's now moved on, and Randall's coming in to take his place there.
Yeah, and, uh, Randall's a great guy, uh, lots of involvement with ISSA both here and previously when he was in, uh, in Tennessee. So he's going to talk about how he, how he went from law enforcement. Did you know he was a, he was a deputy sheriff? You know, he looks like he could have been a deputy sheriff. He did not show me any, any bullet scars or anything.
I didn't ask. I probably should have asked. That would have been appropriate. Get him the big 10-gallon hat and, you know, give him an old squad car. I think he could be a country sheriff.
Absolutely. Well, this is, this has been a fun week. We'll talk to you next week and hopefully we don't have any more massive news. By the way, no updates from Route 9B that I could tell. Looks like they're still exploring other equity options right now.
The saga continues. All right. Talk to you guys next week. Thanks, Robb.
This is Carlin Dornbusch, CISO at Think Tank. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb Reck, and I'm sitting here with the somewhat freshly minted CISO from Denver Health. Randall, you know, you and I have known each other, it's been about 2 years, about 2 years since you moved into Denver. It's been, it's been a fun 2 years and things have changed a lot since then, right? Yeah, absolutely.
Um, I, I think it's, it's been neat to, to see you, you know, get integrated into a whole new, whole new culture and really see you get, you know, dug in with the ISSA group and, um, and then of course with your fantastic new chapter that you've you've headed into. Before we dive into that, I want to ask you, what is the most fun thing you've done in Denver since you got here? 2 years or so since you moved in, what's the most fun thing you've done? I would say Estes Park is probably the funnest that we've done. We go up there quite frequently, um, and the last time I was there, we had an elk walk right behind our little cottage.
Yeah, he was right next to me and sort of, you know, could have reached out and petted him, but I certainly thought, thought I'd probably better not. You like having 2 hands. I like having 2 hands. And, uh, but yeah, that's— we always enjoy that. It's very relaxing and be able to unplug.
So my, my wife and I had spent a couple— a little bit of time in Estes Park, not a lot, but a little bit. And I'll tell you her favorite thing. Kristen's favorite thing is they have caramel apples on their little touristy strip there, and, and they are, they're among her favorites. So if you haven't done that yet, next time you're up Maybe give that a shot. Yeah, if you, if you haven't taken the tour of the Stanley Hotel, that's really cool.
Yeah, we spent the night there, oh man, a long time ago, 15 years ago. Uh, and I would say do the tour of the Stanley Hotel and maybe even have dinner there, but you don't really need to spend the night there. It's, it's like a 150-year-old hotel, right? 150-year-old hotels are not very nice, right? You know, there's gaps between the door and the wall, and you know, the floors are not really even, right?
It's not scary, it's just kind of uncomfortable. Doors don't always shut completely. Yeah. So anyway, well, let's dive into your background. I know, obviously, let's not start with today.
Tell me about Randall early in your career. So I started out in law enforcement. I was a deputy sheriff in Indiana, which is Marion County, which is Indianapolis. I did that for 5 years.
Traditionally, our law enforcement officers are not paid very well, and if you have a family to raise as I did, I, as much as I enjoyed it, I needed to make sure that my family supported and I was home more frequently. So eventually I moved into technology. I had an aptitude for technology.
It was funny because we had the NCIC computers with the sheriff's department, and I was sort of like, what does this key do? What does this, you know, F key do? And I just kind of realized I wanted to go in and look at the technical infrastructure and see how this stuff works. And so really, that kind of all blossomed. I went into technology.
I got Microsoft Certified Systems Engineer in NT 4. So for those of you who were even born then, That is a Windows platform that used to be there before Windows 2000, where they kind of changed the whole thing, went to Active Directory. And so I upgraded my MCSE to 2000, Windows 2000. Started out basically in consulting, did that for a little while, went to work for an organization that software company, so that's always a really cool culture to work in. Really kind of a startup.
We grew from 50 people to 300 people when I was, you know, the time I was there. Yeah. And I started out in tech support and ended up managing the tech support team and also helping them go through a SAS 70 back in the day, the SSA-16 SOC 1, because we wanted to sell to bigger banks. And without that stamp of approval, the SAS 70, you couldn't sell to any big banks. Once we got that, and I think that really was a big driver for them to grow the companies because they didn't end up being bought by Experian.
So that was an early lesson for me in how security can enable the business, really. And I went on to work at Humana. So it was my first stint in healthcare, worked there for 3 years. That's when I moved to Louisville, Kentucky. Where are you from?
Indianapolis? Indianapolis. Yeah. Okay. So Humana in Louisville, I worked there for a little over 3 years on their IT security team.
Did a lot of cool stuff like redesigning DMZs and building remote access platforms, writing policies. At that time, we started talking about secure coding, so my task was to Go talk to the developers and get them to do secure coding. And of course they didn't want to do it. It cost them too much money and they had deadlines they had to meet and they didn't want to add any extra work to the timeline. So not very successful back then.
Certainly today I'm sure they have that. And then I went back into consulting. So I went over a 5-state area. I did security I did VMware training and installations. So how did you make the shift from IT, you know, sysadmin to security?
So I find that, and this is what I tell people when they're trying to get into security, I say start out in IT, you know, get on the help desk. Start figuring out what your aptitude and your interests are, and then show that you're willing, show a passion. And IT staffs are traditionally short-staffed. And if you have an aptitude and interest and you're capable, they will, they'll use you. You know, can you help us go out and install antivirus?
That's one of the ways that I got kind of into security. You know, can you help us rack the firewall? You know, can you help us, you know, install this server and harden it? So those are ways that you kind of transition from just pure IT into security. And with my law enforcement background, I kind of had an aptitude for technology, but I also had an aptitude for protection.
Sure. So those 2 things really came together really well, and I really loved security, had passion for it from the very beginning, and went into consulting, did that, traveled, you know, 5 days a week for about 3 years. We kind of really got tired of that, took a job with a local cloud computing company, a couple different cloud companies. They were really cool that we had Was that hosting.com? No, because they, because they're out there in Kentucky, right?
They were at least. Um, so one was just a real small IT security company and they did, among other things, they were trying to build a cloud for customers, just pure hosting, but they also had a firewall management service. So we had some franchises from retail and restaurant. Yeah. And we would manage their firewall and manage their VPN connection.
So it was cool. I built a Nagios server to just constantly ping 250 firewalls, right? And if it went down, it would page their on-call person. So, you know, a lot of cool stuff there. And then I worked for a company that was an IP communications company, but they had a security cloud.
It's kind of what they branded it. And basically it was just firewalls that we had. We stuck them in our data center in 2 or 3 different geographically disparate locations, and then you would MPLS back to us as your internet gateway. And then we would do all your kind of the, your, you know, UTM functionality at the firewall level and we managed it for you. Sure.
So the folks that didn't have any IT staff and certainly no security staff, we did that. Moved in back into healthcare, University of Louisville Hospital, which was, uh, kind of like Denver Health. It was a city hospital. It was a level 1 trauma center for the region, safety net hospital, and it was the place, you know, if you're, if you were going to have brain surgery, you probably don't want to go there, but if you got shot or if you're having a heart attack, they're a drive past 5 hospitals to get there right. That's what they do.
Did that, basically took it over. Their idea of security at the time was identity access management. That was the security team. Sure. The network guys did the firewalls and the web filtering and the AV.
So I took that over and I brought all that into security team, built the program from scratch, built the HIPAA compliance program. Yeah. So that was pretty cool. And then the Catholic Health Initiatives came along and purchased the hospital. So they assimilated us into the Morganship and we became CHI and I was brought onto the national CHI team.
Yeah. Did that Kentucky 1 region, which was Kentucky and some Cincinnati, some southern Indiana. And then they moved me out to Denver to take over the insurance business. A little over 2 years ago. Yeah.
So that's why— that's where I'm at. So I've worked for CHI, including the University of Louisville Hospital stint, a total of about 7 years. And then I heard about this, this place called Denver Health and this guy, some guy, some stranger named Drew Labow. And kind of speaks to something else I want to talk about later, but it's that building those relationships and I had met Drew through the ISSA, through the CISO dinners. And, you know, we kind of started, you know, having lunch together.
And, you know, he said, you know, he's leaving Denver Health. And so I put my name in the hat. And so here I am. So, and that kind of gets to the heart of one of the main things I wanted to talk about with you. How did you tackle coming into a new organization?
You know, you know very little, although you probably knew more than a lot of people because you could talk to Drew and ask questions. But how did you tackle coming into a new organization, getting your feet under you, getting the relationships and prioritizing your work? And you've been there 3 months now, right? So talk me through that. So once I figured out where the bathrooms and the coffee were, I started having discussions with the right people, IT security folks.
So I am a CISO and privacy officer, so privacy as well, and just a great privacy analyst and just started meeting with those folks, kind of what do we do here, you know, what are you used to.
Started to put together a list. So I have a spreadsheet for everything. So I have a spreadsheet that has partnerships tab and I started trying to find, you know, who are the people in this organization that are leaders at titles. Just even titles— Chief Medical Officer, Medical Information Officer, Chief Technical Officer— putting those titles down and then trying to put a name to those titles. Sure.
Then trying to figure out how do I get in touch with them. Thankfully, at Denver Health, they are very security-minded. The board is very interested in making sure that we, we keep a good strong security posture and everybody gets it. So Started reaching out to those executives, wanted to do a meet and greet, 30 minutes. I'll work with your admin, get something on the calendar, and just really, you know, quick response, happy to see me, and sit down with them and start talking about what's their role in the organization, what's their mission, their goals, and kind of how are they helping Denver Health as an organization to meet its strategic goals, and then ultimately, how can I help you?
To help you be successful. And that makes them very happy. They're glad that you took the time to reach out to them. They're very open and welcoming, and they're willing to share what they're trying to do. Obviously, they're passionate about their area, so just really tapping into that passion and just trying to make sure that channel of communication is open with them.
So getting that kind of big picture of the organization's strategic direction and then So for security, you know, the guy before me, he was pretty good. So Drew did an excellent job of bringing in some very cool stuff to make sure that we're covering everywhere we need to cover. And the IT security team, just fantastic, great bunch of guys and really smart. So that was really important to start doing that assessment, see What do we have? What does it do for us?
How much are we paying for it? Who's the vendor? Yeah. How's it work? How's this tool work with this tool?
And really, I didn't find anything that, you know, was of much consequence in terms of gaps. For me, it's just continuing to mature. Right. Yeah, we checked the box. We got maturity level 1 in this area.
You know, let's get some formality around it. Let's get some policies and procedures. In place or maybe modify those to better fit. And then the maturity can go to the next level, you know, measuring and managing it. How do we pull metrics?
How do we know how well this tool is working? How can I take this to use it to go to the board and say, here's where we're at today and here's the things you care about and here's real numbers? So that was really— that's kind of where I'm at today. And then just with the privacy stuff. Just every, every day something walks through the door that I've never heard of.
It's so— Denver Health is so complex. We have public health, we have poison control, we have the jail, we have a clinic in the jail, and we have an internal correctional care. You know, if you're in the jail and you stub your toe, you need a Band-Aid, you can go to the Denver Health clinic in the jail. If you need an x-ray or brain surgery or something, you come to the correctional care facility inside the hospital. So, that's interesting.
We also have a health plan, fully owned subsidiary of Denver Health.
So much research, you know, from all the different universities and from the state. State public health does a lot. So, we have so much complexity and there's always that question, can we share this data with this entity? And so, when I think I know HIPAA, that's HIPAA security. When you start talking about HIPAA privacy and security is very black and white.
It's a science. It's this is on, it's off, right? Privacy is an art. It's very gray. And, you know, you have to translate the regulations to make sure that you're meeting the needs of the organization.
And I always say HIPAA is the spirit of HIPAA is what you have to understand. It says this, but it's vague enough that you can use it to apply it to your organization, the situation, because they don't want you to shut your organization down just because you can't meet this one line in the regulation. They want you to serve patients, treat people, and heal people, save people's life, but they want you to protect their privacy as you do it. So, you know, if there's something that you're not doing, not doing perfectly right to the letter, they're not going to ask you just shut down your hospital because you're not doing it. They want you to continue to treat patients.
So that's what I, you know, I really enjoy the new privacy role. I drive back and forth to work, I listen to podcasts and things about HIPAA just to continue evolving my knowledge. You know, you get to my age, and as long as I've been around, and you find you have a whole new discipline you have to learn. It's almost like being an attorney. So for me, it's really cool that way.
So it's something else new to learn, and the way I do things is I always try to be the best I can be at it. So what's been your biggest surprise from the privacy side? What's been different than you expected? Well, from security, it's, you know, did they get in or didn't they, or did they not get in, right? Are they, you know, it's pretty much black and white.
With privacy, it's like this happened, but if we have these 3 other things or one of these exceptions, then we can justify it, defend what we've done, and it's totally reasonable and totally defensible. So for me, that is totally different than being in security. You know, we're very black and white, and, um, but I'm enjoying it. It's, it's interesting to really see how security and privacy overlap, you know, on almost everything. And there's almost always a technology, unless it's somebody printed something they shouldn't have, and the paper PHI is falling around, it's almost always including security.
So I think it's a good fit at Denver Health to have those 2 roles in one person. But for me, it's just continuing to improve my knowledge and, you know, become an expert in the privacy side. So what do you think got you prepared, you know, during your career so that when you, when you had the opportunity to go be a CISO that you were not only— not only did the interviewer identify, yeah, this guy is going to be a good fit, but also you just were ready for it, right? You were able to step in and be effective, right? So I've been— I don't know that it was CISO that I was shooting for, but I have been kind of grooming my career forever.
Right? So ever since I started in security, you know, what do I want to be when I grow up? Right. And CISO was sort of that idea. I don't think I knew what a CISO was at that point, but I, you know, I knew what I wanted to do.
I felt like I had the ability to lead. I feel like I had the ability to manage people, manage processes. And as, as I thought about it, I kind of put that out there as a goal. And then I said, okay, let me start reading job descriptions. What would I have to have to be that?
Yeah. And, you know, 5 years of this, master's degree, bachelor's degree, CISSP. I didn't know what a CISSP was yet, but I knew that these things are needed. So I started dissecting that, figuring out what each one was, what would it take to get that. Along the way, I continued, you know, where I could, I would you know, check that box.
I did that, right? I did that. The experience, I just knew that I'm gonna have to be doing this for 10 years or 15 years, right? Um, it's not something I can just go do today and now I have 15 years experience, but I can go get that certification, you know, start out Security+, then, then go get a Network+, uh, Network+ or a CCNA or something to continue understanding What knowledge will I need to be successful in that job? And so continue to grow technically, but then also I watched other people who were, you know, my supervisors, my managers, you know, the directors and, you know, and the leaders, and asked them to mentor me.
Ask them, what did it take you to get this job? Watch them. How do they carry themselves? What do they know? What do they know that I don't know?
Can I do this job? And so just become a sponge and learn everything you can. Learn from those people.
But it's really what I call swimming in the executive waters. That's completely an unknown thing. I mean, until you're doing it, you have no idea what it even looks like. So, you know, a lot of time being in technology, you're kind of stuck in the basement and You never really talk to anybody and you just deal with the technology and your communication skills are never really honed. So if you just kind of jump out of that right into the executive area, you're kind of a fish out of water.
So it just took a long time of just studying that. I watched a lot of YouTube videos. If I saw an interview with a CISO, I would watch it. And I'm not just trying to learn, take what he's saying, learn. I'm studying him in terms of his, his appearance, the way he carries himself, the way he talks, um, and, and just continue to learn that way.
Uh, it's interesting because I, I've, you know, been around a lot of CISOs in the last 5 years or whatever it is, and there is a, there is a CISO look. Yeah. Um, from a fashion perspective. Yeah. I do not ascribe to the CISO look.
I don't enjoy wearing a sport coat. And, um, there, there are, there are a bunch of those kind of like Hallmark things that, that the, uh, the, you know, your— especially like your financial services CISO, whatever it does, right? No, I hadn't really thought about it, but as you say it, yeah, that's, that's totally true. That's so funny because you know, shopping for clothes and everything, I say I have to put my CISO uniform together, right? Because it's a, you know, it's a suit or sport coat, button-down, you know, no tie.
Yeah, that's pretty much universal CISO uniform. Um, even when you work in a shop that is, you know, they wear a tie, I see CISOs just not wear a tie. I don't know what it is about CISOs and ties, but Steve Corey wears a bow tie a lot. He does, a wood one. Steve, Steve, the, uh, with CSO for City and County of Denver.
So I had my own— I'd call it the Robb uniform that I wore for 3 years, which was like khaki pants and a short sleeve button-down shirt. And I came to Ping, and maybe a year in I realized that I was like tilting at windmills wearing mine when everyone else in the company wears the Ping uniform, which is long sleeve, uh, button-down shirt and jeans. That's just what everyone wears. I'm like, well Well, I start wearing that. I don't have a problem with that.
So it's funny, like, to talk about, like, the, you know, the, the uniform for CISOs. You're, you're absolutely right. That's, it's kind of the look. Um, but it also depends on your company. You know, there's, you know, if you're the CISO at, at, uh, SendGrid, or, you know, Dave Campbell is over there, I think it's, you know, shorts and a t-shirt whenever you want to.
And right, but if you're the CISO at, I don't know, I'm just guessing Charles Schwab sees it, but Bishar might be wearing a suit and tie every day. Right. Really interesting, though. It's kind of a fun conversation. And that's true in definitely that culture in some places.
But I can tell you, when that guy goes to a CISO dinner or a conference, he's got the CISO uniform on, you know, and I learned that, right? That's one of the things I learned along the way that I wouldn't necessarily have thought I learned. But, you know, you kind of adapt to what you see.
All right. Talk a little bit about your, again, your personal life. Before we started recording, you were telling me about, you know, you're kind of a nerd with spreadsheets, right? Why don't you talk to me, and you talked directly to my heart. I'm also a nerd with spreadsheets.
Talk to me a little bit about what you use them for and, you know, how. Yeah, yeah, absolutely. So spreadsheets for me are definitely my friend. It's cheaper than trying to buy something. Software solution.
So they have tabs, they have— they can add stuff for you. You can also use the data list function, which will allow you to kind of put a list of things and then it makes it a dropdown. I use that all the time. Data validation. Data validation, yeah.
I use it all the time for things that are— it's always going to be one of these 5 things, and you want to force it to be those 5 things. But what are you using spreadsheets for in your personal life to make to make you more effective? In my personal life, obviously finances. For goals, I used a spreadsheet with charts and everything. Talk to me about your goals.
So my goal was obviously to be a CISO, to work in security, and to work in healthcare because I have a big passion. I love security. I have a big passion for that. But if we were just making widgets, I'd have a hard time connecting to it, right?
So if we were making widgets, I wouldn't be able to connect to that mission very well. Every day I come in, I'm not a doctor, but I make sure that the stuff the doctor needs to help save lives and heal people works every day, that they can get into it, that they have the data they need, that the data is in the state that they expect it to be in, make sure the people are not getting to the data they're not supposed to get data. So that's the confidentiality, integrity, and availability. And if you're in school and they talk about that and you think that's just some weird concept I'll never use, that's wrong. You will use it every day.
That's the core of our jobs. It's funny, we don't talk about them very much, but it's behind everything we do, right? Absolutely. And it's— I do think we as a— you talk about the CISO uniform. One of the other attributes of the CISO is we focus way too much on confidentiality and and not nearly enough on availability.
Integrity is probably in the middle somewhere. But the need to think more about, you know, in your case, especially with like the Petya and WannaCry and stuff that impacted some, you know, the national health system out in Britain, taking hospitals offline, it kills people, right? And of course there is a potential that you can kill people through confidentiality as well, but it's a whole lot less likely. Yeah, and I always say a lot of people say confidentiality is the most important of the 3, but I don't think so because if it's not up, it doesn't matter if you can get to it or not, it's not up. If it's a critical service, especially in an inner-city hospital, level 1 trauma center, it has to be up.
You have to identify those critical systems and make sure those DR plans are in place, understand when do they go up. How long can they be down until you start having a real problem and people dying maybe? But at the same time, it doesn't work on an island. Availability is no good if the integrity of the data is bad and we're going to get that surgery pulled off and we give them a vasectomy instead of a heart transplant, right? The integrity is all 3 of them.
Without working in parallel have no value, right? And I spent a lot of time thinking about this, and we do have these debates, right? Which one is the most important? And my opinion is none of them is the most important. They're all equally important, but the requirements for each of them might be higher or lower.
Your availability requirements may be, you know, 8 nines, or, you know, maybe it's 100%, but that's equally important to your integrity requirements, which might be Hey, just don't let this one field get changed, but if that one field gets changed, then that 100% uptime doesn't matter. They're all— and confidentiality, I can come up with a use case for that too where it's 100% important in order to be effective. We just have to figure out what those requirements are along each of those 3 axes. And it depends on the application, depends on the organization.
Yeah, and the integrity is another big one for us, obviously. If the system goes offline, you bring it back up, then you got to check the integrity, right? The data gets corrupted. And the issue is certainly with ransomware, integrity is a big deal. Ransomware is a big deal in healthcare in general, because used to be you get ransomware, you have good backups, you go restore the backups, and then you move on.
Now the OCR said that ransomware is a breach. Unless you prove otherwise. Yeah. Which you can't do. Which you— well, so now you have to say, was there unauthorized data exfiltration or unauthorized access to the data?
Well, I'm not sure. Well, then it's a breach. So how do we now improve our systems, buy the tools, and hire the people to make sure we have that advanced, more forensic capability to understand, did that happen? And if I can show you it didn't happen, then I feel comfortable saying it wasn't a breach. It was just an encryption event.
We recovered from it. Nothing was lost. So we're good. But that's a big challenge now for healthcare. It's funny how one decision made by somebody maybe didn't understand what ransomware was.
Yeah. But now it's affecting everybody and just the extra work and cost and effort you have to put into sort of proving that you didn't have something that probably didn't happen anyway. You just have to be able to show it. So the last topic I wanted to make sure to get some time on was, uh, was the big news yesterday, right? We're recording on Friday, September 8th.
Um, we're going to be releasing this podcast episode here on Sunday, uh, on the 10th. Just yesterday we had the huge breach from Equifax, and I know in my world, you know, Equifax isn't all that close to where I work, but My goodness, it's a huge topic of conversation. Absolutely. And certainly big news in our world. I guess I'd just ask you broadly, what's your perspective?
Do you have anything you want to share about that real big recent news? So, I was on Twitter yesterday and somebody said something like, I guess they're going to have to issue new SSNs to every citizen now. And I kind of chuckled, but not really that funny. Um, you know, what information about you does Equifax not have, right? Your work history, every bank account you ever had, every credit card you ever had, places you've lived, family, you know, just everything.
And those are really identifiers, right? So, you know, have you ever lived at any of these addresses? And then your address is on the right. Now they can use that. That all comes All those out-of-wallet questions, right, which many, many financial institutions use as an authenticator of who you are.
Absolutely. You know, we focus on the SSN and the driver's license and the date of birth and address, and those are easy data points that are probably already breached for all of us. Right. But those out-of-wallet questions that they're using to authenticate you, and it's probably on your password reset function on your bank, right? Right.
It's all these things that, as you're really working to try and keep yourself safe, that are the inherent backing of what we do, right? And that the whole— just the volume of data, the number of people that are potentially impacted. We still don't know what happened or the scope of it or what type of data was breached, if it was all of your stuff for everybody or just a little bit for certain people who did this or that. But I can just tell you, you know, this is one of the biggest ones we've seen, and it's going to impact pretty much everybody.
Ironically, they're offering their identity theft protection service to people, Equifax is, which I find ironic that they were the ones that caused the breach and now they want to help you, you know, identify any. But definitely go get one, right? Use a service to keep an eye on that. And really the scope of the threat is just about everything, right? Your tax returns, opening up accounts in your name, medical fraud, right?
Medical fraud, everything that you can think of. They have everything. They may have everything that they need to completely impersonate you, and if you don't keep an eye on it, you may have— yeah. So I mean, I'm really— it's fascinating to me to think, kind of think through 5 years, 10 years from from now, what's it going to look like? What's the world going to look like, right?
Because all of our data has been breached, you know, probably 10 times. And these applications, the way banks do business, the way the government validates you, it all just has to change because it's all built on obscurity around a few facts which are not secret at this point, right? And, and so it's all built on this this foundation that doesn't make any sense. In some ways, and these guys, whoever did this is criminals, I wish they wouldn't have done it, it's terrible, but maybe this is what we need in order for us to actually fix the fundamental flaw we have in our system that says, hey, your Social Security number that used to be your college ID number, yeah, that's the thing we're gonna use to secure your identity. It just doesn't work that way.
And then some folks I know that work for the federal government, you know, they— the OPM thing, and they were just like floored by that. You know, people who have clearances and background checks for clearances, and they were floored by that. I mean, these are people like FBI agents who now— you may have my home address. CIA operatives. Yeah, that's scary stuff.
And I'm, I'm just kind of thinking, if, if there was a nuclear bomb of cybersecurity, what would that look like? And would it be worse than what we just had, right, with either the Anthem or the Equifax What does that nuclear bomb look like? Well, I think it, it involves people dying. And we, you know, we may have had people die from NotPetya with the, the impact of some of the healthcare systems, but we haven't had a mass event, right? You know, cybersecurity taking out a nuclear power plant, blowing it up.
You know, there's— there, God forbid, right? But there are some, some terrible things that are probably going to come because apparently nothing else is waking us up to take it seriously. Well, I heard somebody say something about they were thinking about, you know, giving all the nuclear warheads IP addresses, you know, and I was just like, could there ever be a worse idea? We'll use port 80 for that, I hope. Port 80, yeah, you definitely don't want to use HTTPS and you don't want to authenticate it because that would be too hard.
All right, next, we're a little over time, over 30 minutes. That's okay, we can go a little longer, but I wanted to get your take on the community here in town. You know, you've been here for, for 2 years. Previously you were the president of ISSA in Louisville. Yes.
Um, you know, I know you've been— you and I worked together on the ISSA Denver board for a couple years. You know, it's, it's been, it's been a fun couple years. Anything you want to share with the community, uh, talking, talking about that? Uh, yeah, so, uh, coming from Louisville, Kentucky, I was the president of that chapter for 8 years. Just amazing people, great community, but small.
And really a different community than Denver. Not as much communication and connection between the folks that work in security. So the ISSA meetings really were somewhat about learning stuff, but it was getting to know people. But then coming to Denver, just an amazing group of people, not just the chapter, which is the biggest in the world now. And that happened under Robb Reck's tenure and was built up by Alex Wood.
Just fantastic, right?
And having the community the way it is, I mean, I started asking CISOs out to lunch, you know, like the day I got here, right? And just willing to talk to you, go out to lunch with you, share stories, share advice, mentor you, you know, that's just amazing. And just that connection, started going to CISO dinners, which Robb was kind enough to invite me to, and just started making— I mean, now I've gone out, you know, gone to you know, guys' houses and had barbecue with their family, you know, and just— it's amazing, yeah— building friendships more than just professional. I think my takeaway from that is those folks who are here in the community looking, you know, how do I get involved, you just reach out to people. Reach out, send an email, send a note, say, hey, I'd like to take you to lunch, right?
Be generous with your time, and, you know, like I said, take them to lunch, right? And I think over time, you know, you develop these great relationships But you have to be proactive. Don't just sit there and hope, gosh, I hope someday someone's gonna ask me out, right? Go do it, take that first step. Well, they don't know who you are.
You have to go out and show them who you are and make yourself known and kind of make them know what you're about and find out what's in it for them. I mean, most likely they like helping people progress in this career. They like sharing their knowledge. I've found CISOs to be to be very open and approachable and willing to mentor. So we all need more people in the industry.
There's no shortage of jobs, right? Exactly. Yeah. And I mean, I think that in terms of kind of the values, kind of the key things that I would, you know, that I found valuable in my personal life and has certainly translated into my professional life and, you know, whatever level of success. You know, definitely communication skills.
Those are so important because we communicate constantly. It's technology, but you want something to happen and you have to be able to say, here's what I need and here's what has to happen and build the communication and those relationships with those people. And then as you kind of climb up the ranks, that becomes even more and more important, probably more important than your technology skill at that point. And you just have to be able to communicate and communicate the right message to the audience that you're in front of. That's really so important.
Another thing is just a never-ending, you know, I'm a CISO now, so I don't need to learn anything else, right? No, that's just wrong. You never— your knowledge in this, especially in technology, when it's just changing every day, right? The threats are changing, the technology changes. You just have to constantly stay on top of it.
I listen to podcasts in my car. It's always something maybe different, but it's always— I'm always taking that time that I'm down pretty much to use it to continue to learn and I think that in our field, another really key value is integrity. You're trusted the keys of the kingdom, right? You're the security guy or the security girl. You have to, you have to have that integrity and you have to be able to show that integrity.
They have to trust you, not only that you're going to take care of them, protect them, but also, you know, we're going to, we're going to trust you to help us going forward strategically. So that integrity really is really important. And a spirit of service.
You're serving your organization. I think in security, that's one of the— security is one of the areas where we transcend. It's not just a technology job, and we are serving that organization. You know, if I didn't get this server rack today, it's not, you know, it's probably not going to be catastrophic. We deal with some things that are going to— could be very bad for the company.
So just having that spirit or that heart of service, I promote the idea of sheepdog. So if you're in military police, you kind of get that. You know, there are sheep out there, they kind of don't pay much attention to what's going on around them, and there are a lot of wolves, and somebody has to stand in the middle to protect the sheep from the wolves. And to be protected from the wolves, you kind of have to be like a wolf, right? You kind of have to understand the wolf.
You have to be able to tactically respond. So in security, in information security, cybersecurity, I think that concept is perfect for us as well. We do that. We have the sheep and we have a lot of wolves out there. So definitely You know, the networking, the building relationships, and just being prepared.
I have kind of a motto, you never show up to my meetings without a notebook.
It just boggles my mind how you can show up to a meeting without a notebook. And I mean, unless you just know everything and you can remember everything we talked about, I mean, how can you do it? So just being prepared, making sure you have your resources kind of cataloged and available to you.
And being able to have a system of organization, for me, that's probably my biggest challenge. How do I sit, take notes, and then how do I figure out what do I need to keep, what do I need to save, what I need to follow up on, and how does that translate so that I can organize it in a way that is efficient? So I've I'm, you know, over 50 years old and I'm still struggling with that concept of how do you do it. And it's because there's not a real standard way of doing it. Everybody has their own way.
Yeah. So I've really tried over time to figure out how do you organize your, you know, your, your work, how do you organize your thoughts and get it all together so you can be effective. Um, but yeah, yeah, a couple things you said there, a lot of great advice. 2, 2 I want to pull out. One, early on You know, the higher you go, the more people skills take over.
I say the higher you go, the more every job turns into a sales job. Yeah, you're now selling your peers, you're selling the other— the CEO, you're selling the board about the value of security, about why this is the place to invest their money and their precious resources, right? We all become salespeople at some point, but probably not paid as well as salespeople. I'm not sure how that works. And then the other thing you said is just the integrity part of it, that I think if there's a question about the integrity of a CISO, you're doomed.
And so don't ever give them a reason to question your integrity, right? Absolutely. Don't— that one little thing that doesn't seem like a big deal, the expense report or the whatever little thing, don't— just don't give them any reason to question your integrity, right? Otherwise it really eats out the foundation of your job. You have to be a trustworthy person as a CISO, no matter what kind of CISO you are.
If you're the no guy or you're the business enablement guy, I don't care either way. If they can't trust you, that's not going to work. That's so important in building those relationships, which are so critical both in building your career and maintaining and advancing.
If you're a person of integrity, it means you say you're going to do it, you do it. When you're supposed to you'll be there, you show up. You know, if you— if they need something from you, they know they can ask and you're going to help them do it. Um, that integrity is just so key. And, uh, and obviously, you know, you have the keys to the kingdom.
We're trusting you to help protect our organization. And if you don't know what you're doing and they can't trust you, you're not gonna have— you're not gonna get that role. Yeah. Well, Randall, this has been great. Any final words for the— for our group here?
Well, I would just say, uh, get out, make yourself known, go to ISSA meetings, ISACA, InfraGard. Be part of that community because you're going to get so much value out of it. You're going to learn, you're going to meet people, you're going to have fun, and those relationships and that education that you have is really going to be critical to continue advancing your career, and networking is the key. For me, networking trumps it all. I know people that have an associate's degree and they're CIOs, right?
They know somebody and they were a good enough trusted partner that they were trusted with the role, and maybe they couldn't do it, but they came up to the challenge. So that's so important. The networking for me, it trumps all. Make sure you have those networks. If you're in a room, ISSA meeting or whatever, you don't know somebody, go change that.
Go shake their hand, introduce yourself, because that person is most likely either going to be really glad you did, or maybe they're shy too, and they're glad somebody finally helping them open up. So try to be a leader in your field. Get to know people. Leaders talk to people. Yeah, absolutely.
It's really cool. Cool. Right, Randall, thanks for your time. Let's— maybe we can do this in a year or so and catch up, you know, how it's changed a year and a half in. Yeah.
All right, fun. All right, have a great weekend. Thanks, everyone. This has been Colorado Equals Security. We'll talk to you guys next week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.