Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 52 on January 29th. Alex, Your favorite child is turning one this week.
He is? Is it a he?
I've got only boys, so it seems pretty likely that it's a he. Well, I mean, you've got your boys and then you've got the podcast. Oh, that child! Yes, yes. It's been a year, Robb.
Can you believe it? Yeah, I can't believe it. It seems like only yesterday we had this silly idea to create a podcast. And it seems like maybe it wasn't quite so silly. It's been good for a year.
Yeah, it's been fun. Uh, what have you learned anything? Um, I've learned that, um, I no longer have Sunday mornings. Oh yeah, that's, uh, that's kind of a sad learning out of this. It is.
Um, but, but a good one nonetheless. How about you, Robb? Um, you know, we've talked about it before, right? The The technology has been probably the hardest learning out of it, trying to figure out how to get levels to stay consistent throughout a whole podcast is not always easy. But it's been great getting to meet a whole bunch of different people in the community.
You know, it's just, I guess the biggest learning has been that we have a much broader and more eclectic community in Colorado technology than I ever had known. And it is much, much larger than I ever would have thought it was. Yeah, there's lots, lots more people in this community. I thought I knew a lot of people, but I was not even close to knowing a lot of people. Well, here's to another successful year.
Maybe, maybe— wait, wait, wait. I thought we were done. We're doing this another year? Wasn't that, wasn't that the agreement, Robb? We'd do this for a year and then, and then we decide, we'd make a decision, right?
Whether we're going to keep going. And so I'm just going to do it on the air here right now. You ready to keep going another year? Yeah. Okay, let's keep going.
Let's keep going. We'll do one more. We'll see how it goes after that. All right. Well, why don't we go ahead and jump into the news then?
Sounds good. Before we do that, a reminder, everyone, please sign up for our mailing list. That way we can keep you updated when we do have new episodes and get you show notes. First story for the week. Denver is testing smart technology to ease the traffic congestion in town.
Yeah, it's kind of interesting that there's a pilot program that's going to be aimed at using technology to move folks around. It's going to equip like freight trucks with technology that talks to the traffic signals and shows them how to move more efficiently through the system. It's also going to have technology in the vehicles that are like owned by the city to help communicate with infrastructure. So really just trying to make it more effective as people are moving through the streets and, you know, less congestion at intersections. Hopefully, uh, whatever, you know, grant money or whatever it was that they got to do this also included a headcount for somebody on Steve Curry's team to look at the security of all this stuff too.
Yeah. It seems incredibly likely that as soon as you implement this, somebody is going to figure out how to use, how to hack it. And either number one, you know, on the, on the worst side, right. You know, use it to cause problems and send cars into each other and whatever on, on the other side, maybe they use it to themselves kind of ride through some green lights. And well, it's, you know, there's always sort of that urban myth, you know, you could flash your lights a certain number of times at the stoplights and it would change, you know, that was for the ambulances.
Exactly. I don't know if that was ever true, but I certainly heard that. Yeah. And now you're going to be able to, you know, bring out your, your Bluetooth jammer and figure out how to change the lights and all that kind of stuff. Yeah.
So Our next story this week is actually just a follow-up from last week. So we talked about the National Cybersecurity Center, you know, that had used about $8 million on a building in Colorado Springs. And there was a little bit of outrage on the show from— I can think of things you could do better with $8 million than rehab a building. But we did hear from Andre McGregor, who is one of the board members for NCC, and talked about it just a little bit with him this week. He provided some great insight, which was that While that was a grant for NCC, it was a stipulation of the money that it had to be used for a facility.
So they didn't have flexibility to go take $7.5 million of that $8 million to go use on building a program. It really had to go to a place where they were going to be. Yeah, I mean, that makes sense. That makes sense. Next, there was an announcement this week from Red Canary that they have teamed up with CrowdStrike.
So, so Red Canary is the local, uh, managed endpoint detection and response company here. They had previously only supported Carbon Black as their EDR platform, and they've added on CrowdStrike as another option. Yeah, so if, uh, if you were somebody that was using CrowdStrike previously, or for some reason you didn't like Carbon Black and wanted to have CrowdStrike instead, now you can. Yeah, like maybe you've been using Carbon Black but they continue to fail on your Apple laptops and And maybe that matters to you. Maybe you have to use something else.
Or yeah, I mean, theoretically you could use a mix, right? Yeah, absolutely. Uh, next, Optiv, they named a new executive. Uh, Simon Church has been named general manager and executive vice president for Europe. Yeah, so they're obviously trying to grow significantly outside of North America.
They are the biggest security company here in North America, but as they're looking to, to get out into EMEA, Europe, that this is an opportunity for them to do that. And it sounds like a pretty good thing. Simon, I just did a little bit of reading as we did this, has got a history in the, in the industry and hopefully can help build out their presence outside of North America. Yeah, good luck to them. Next story is a blog by Swimlane about how to use Swimlane and really just how to use Slack to do ChatOps.
So ChatOps is this idea that rather than having a formal system that where you're going to get an alert that generates a ticket and maybe generates an email. There's interactive, you know, if you haven't used Slack before, it's really an IRC or a chat room where you kind of have real-time notifications and people who are on duty would be looking for those notifications and you can have your system, your swim lane or even your SIEM, something else alert you in that system to what's going on and get people to work on an alert immediately. Yeah, interesting new paradigm. I'd also say if you haven't used Slack, then Clearly you haven't joined the Colorado Equals Security Slack channel, so you should definitely go out and do that and you can test your chat ops in there. I think it's kind of fun to give a little update each week.
We're at like 250 members right now. It's crazy. It's right in that ballpark. So really, obviously it's been a really needed place for folks to get together. And if you're not there yet, the link to join is in the show notes and it's part of the email every week too.
Also on the front page of the website. One more update. I started a new channel on Slack yesterday, Robb. Yeah, a second intel channel for threat intel. Excuse me, for folks to go and talk about new threats.
Yeah, you opened it and immediately became the most popular channel in the place. It did. Although it was mostly, you know, just a couple of folks talking to each other. But, but still, moving forward with our next story, Route 9B has hired a couple of new executives. They have a new CFO and a new CRO, a chief revenue officer.
Revenue officer is usually over sales and marketing. Yeah, and we were actually, uh, really close to getting an interview with Really Nine— really, with Route 9B. Um, had them scheduled and they had to, to reschedule that. But, um, perhaps when we do that we can talk about these new executives they have. Uh, one of them joined from, uh, Shriver Medical, which is a local company here.
Um, and then, uh, the other one, uh, he's out— he's out of state. I didn't put the company he was from, but But Mr. Bruckner is from Scriber, which is where we know Johan Heibonette had worked as a CSO there previously. And then Route 9B also had a blog post about some unique educational opportunities in Colorado. I think the one that was most applicable to us was talking about the University of Denver's cybersecurity program that they have there. So you're saying you don't want to talk about the Arvada Center for Human Arts and Regis, who've combined to work on a a kind of dancing, acting, and ceramics program.
Well, you know, music majors are great for cybersecurity. Absolutely. So that seems like something that's applicable to us. Yeah. And then, and then the other one was an outdoor, um, outdoor training for guides at CSU.
So yeah, I mean, both of those things are really cool. Yeah, but they're not, they're not cybersecurity. Is that what you're saying? The thing that's probably most applicable to us is, uh, the, the programs at at, uh, DU, which is cool, which is actually where I got my master's. So yeah, go Pioneers.
Very cool. Uh, and the, the last little bit of news here is, uh, just a congratulations to Ed Fuller. Ed's a friend of ours who, um, just recently signed on as the, uh, CISO and VP of Technology for local company Cloud Elements. Cloud Elements does, uh, you know, kind of your AWS cloud monitoring, and I think, you know, it helps you save money and all that kind of stuff. I think they do like API integrations and other things like that too.
Yeah. So congrats to Ed. We're looking forward to hearing what you're going to do there and see you at one of those CISO events one of these days. Yes. So let's move on to trivia.
Last week for episode 51, we had a— I don't want to say it's an impossible one. It was a little difficult. A little difficult. Yeah. Maybe not exactly straightforward, but the question was, if blank breaks, it interrupts a circuit which causes the system controller to immediately stop the system.
And Robb gave a hint that this was in relation to skiing. And then we're very fortunate. We have some friends who work for Vail Resorts who listen to the show. And one of our Vail Resorts friends, Ian Buxton, was able to get the correct answer, which is a brittle bar. A brittle bar is that— is that— oh, yeah, no, no, no.
That's one of those energy bars, right? I had one of those the other day. Oh, no, wait, no, it's something else. Sorry. So it's just one of control, one control of many on the ski lifts that'll stop it if it's broken.
Try and keep passengers safe. Yep. So the trivia for this week, we're back to another podcast question here. So this is name the 2 other security podcasts that are created here in Colorado. It used to be one other.
And then another podcast moved to Colorado. So there's 3 of them out there, us included. So let us know what those are. You can give them a listen, let us know what you think. Maybe rate the 3 podcasts when you send in your note, and you can guess which rating would be the correct answer.
That's not a requirement though. Let us know what the other 2 podcasts are and send us a note. Send the email to info@colorado-security.com.
And once again, thanks so much to Andre Gaeta, who is our sponsor for this. And without Andre paying for this, we wouldn't have the trivia show. And we look forward to all those correct answers. Upcoming events. Don't forget, we do have a calendar of events on our website.
It's pretty well packed out all the way through March right now. So go out there and see what you want to be doing here over the next couple of months. First up this week, SecureSet is doing one of their Hacking 101 workshops. This is Intro to Social Engineering on the 30th. That's the only thing this week, interestingly enough.
We, we have a lot of events the week after, but this week is pretty pretty light. Uh, next week on the, the 5th of February, we have the cybersecurity reception with the British government. So this is, uh, an interesting idea. You can get to meet some of the folks coming over here from the UK, and they want to just talk about how the different countries are doing security. Um, also on the 5th, DenSec is doing their South meetup.
On, on the 6th, we have Women in Security doing their, their, I guess, kind of every other month meeting. Um, following that, we have CTA doing their CTA 101 on the 7th. And on the 8th, SecureSet is doing a Career Conversations with Elaine Marino. Also on the 8th, CTA is doing SkillWorks: Skills-Based Hiring and Training. That sounds interesting.
Yeah, absolutely. And that is the end of our, of our events. Let's jump over to jobs. Um, we see we have an IT security analyst focused on SOX compliant at Zachly. That's a great name for a company.
Uh, Optiv is looking for a practice manager for, uh, attack and penetration. So if you want to lead their attack and penetration practice, we have SCL Health is hiring a security analyst 1. NCAR, which is the National Center for Atmospheric Research up in Boulder, It's looking for a, um, a Student Assistant 3 in their cybersecurity program office. Xcel Energy is hiring an Electric EMS SCADA Programmer 3 job. Yeah, and this one is not, um, directly security related.
You're obviously gonna have to do some SCADA programming, but there was lots of talk about security in that job post. Looked pretty cool. And, uh, there were lots of other Xcel jobs that were out there directly related to security too. Seems like Xcel is hiring a lot. Uh, Visa is looking for a senior secure— or excuse me, senior software engineer in application security.
That's pretty good. Uh, First Bank is hiring an information security senior analyst. Uh, QEP Resources, former company of mine, is looking for an IT security analyst. Pretty fun place to work. Yeah, great place to work right downtown across the street from Robb.
Yeah, absolutely. Good stuff. Uh, Bank of America is hiring an information security engineer. And finally, GE is hiring an IT cybersecurity engineer. I believe this one was up in Longmont.
Does GE have a pretty good presence here in Colorado? Yeah, this is a— I forget, it was a company that they acquired up in Longmont. But so yeah, they have a good amount of presence up there. Yeah. All right, well, that is the end of the show.
I think we're gonna go off and have a full Sunday in front of us. I get to sit and watch my youngest son play basketball all day, so that should be fun. Good stuff. Our featured guest this week is Andre McGregor, who is the director of security for Tanium. He lives— he's a Denver native.
He's also on the board of directors for NCC, and lots of fun stuff he's got. You're gonna hear he's got a lot of interesting stories to tell. Awesome, sounds good. Look forward to hearing it. Thanks everybody, have a great week.
Thanks, Robb. This is Chris Abbey, IT security analyst at Douglas County School Districts. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
This is Robb Reck sitting with Andre McGregor. Andre, I want to start off with a little different question today. What was the most interesting thing you saw in Europe when you were out there the last few weeks? Oh, okay. So I was originally supposed to be in Italy for the week and But then I looked at the weather and realized it was raining all week, so I rerouted myself to south of France, in Nice.
And I rented a car and was driving around and kind of zipping through the mountains, and I ended up in this market. And I'm walking and I meet this old artist. And we're talking, he's got some oil paintings out, and I'm learning his story, and he's telling me about one of the pieces that I liked and giving me the story about it. And he's saying how he's more of a drawer than a painter, and I'm like, well, I really like it. So long story short, that painting is now home with me in Denver.
But he also was able to tell me where he painted it. So the next day, I went up to the top of this mountain with the painting and was able to look and see the exact view that he had when he was painting it. So it was pretty cool. So you have a photo of that view? I have a photo of that view as well.
Oh, you put it next to the painting? Next to the painting. And it's pretty cool. I realized that I like local artists and I like being able to support that capability because I don't have it. And it was just a great experience.
So now everyone listening is super jealous. We're all very jealous that you have done this. Well, they shouldn't be jealous because I said I gained 3 pounds on this trip. So the food was fantastic. All right.
So, Andre, you are the Director of Security and you really run this internal security program for Tanium, right? That's correct. And, you know, a little bit of color for probably you as well, but definitely for the listeners. Someone from Tanium reached out to me like 6 months ago and like, oh, we'd love to get someone on your show. And my general response to this is, hey, we're Colorado-focused.
And while Tanium's a great company, they're not in Colorado. I'm not interested. So they replied back and said, well, we have our Director of Security in Denver. And you know he'd be a perfect guest for your show. And you know my immediate response was, "Oh, you're full of it." You know, it's a sales guy.
No interest in it. That's totally my immediate thought whenever someone says that. And so, but you and I've got to know each other over the last six months or so, and and I can vouch for you and say you're you're not a sales guy. Well, you know what it is? I I think we're all salespeople at the end of the day.
We're selling ourselves in some capacity, whether it's to our spouse or partner to get us to go to a movie or something, down to, you know, technology. I enjoy speaking passionately about problems that I see and solutions that make sense. And so, you know, if I could do it over beers, great. If I have to do it in a suit and tie, okay. Yeah, so anyway, it's good to get you on the show and talk about some of the stuff you're doing.
Well, let's start off, but, you know, going back early in your life, where'd you grow up? Where are you from? I am from Denver proper. I am a Denver native, born and raised. So my parents, Jamaican parents, somehow ended up in Colorado where it's cold, and I was, I was born and lived in Park Hill and went to George Washington High School.
And, you know, love nature and love— I was in a youth group called Environmental Learning for Kids. Where it took underprivileged and nontraditional students into the natural world, taught us about hiking, hunting, fishing, camping, you know, wildlife management, things like that. And so I originally wanted to go to school for that. And I actually had, you know, a full ride to CSU. I was going to do wildlife biology.
And I was lucky enough to get a Daniels Fund scholarship. So Daniels Fund, a big organization that gives scholarships out every year, full rides. And Bill Daniels was dying at the time, and he was looking to start this program and get an initial set of kids. And I was lucky to be selected. And they said you could go wherever you want in the country.
And I ended up going to Brown University where my brother went. And he was like, you need to study computer science. That's where things are. Your brother told you that? Yeah.
So he went to Brown and studied comp sci. He ended up coming back home when I was 12 years old to help take care of the family because my dad had some health issues. He started a nonprofit in Curtis Park, which I guess is now RiNo.
I'm still learning the new terms for neighborhoods that used to be Five Points and whatnot. But he worked at a community center teaching inner-city kids and the elderly computers. He came up to me one day and he said, hey, what do you know about computers? And I said, Nothing. And he's like, good, you're gonna be my guinea pig for my lesson plan.
So I had to learn, you know, how to do web design. I had to learn, you know, SCSI, that was, you know, Terminators and how to, you know, build, build, you know, computers back when, you know, you actually built computers. Uh, and then there's no such thing as plug and play, right? Yeah. ISA cards, remember those?
Like, you know, things like, you know, memories that didn't work and trying to swap out, all that fun stuff. But as a result, he ended up getting me into IT, getting me into comp sci interests early. And then I went off to college and did that while also working at the help desk. Ended up managing the help desk while I was at Brown. And got my first job at Goldman Sachs as an IT server engineer.
So you went to Goldman Sachs, pretty much the pinnacle of, you know, capital. Yes, pretty much. So what year did you go there? 2004. So you're a few years before things got bad, right?
Goldman's an interesting culture. Goldman is cutthroat. It's sharky. Yeah, I don't think anyone that's in Goldman would deny that. I'm definitely someone that's more public sector, someone that's more helping people that can't help themselves, because I had those opportunities presented or afforded to me.
And so Goldman wasn't a fit for me, and so I ended up working at the Cancer Research Institute as their IT manager. So how long did you make it at Goldman? Uh, about a year. Then I went to Cancer Research Institute. I was their IT manager there.
We were working through a big big migration from Novell to Microsoft. Remember Novell? Oh God, all these old technologies. I feel old, like a dinosaur. Getting rid of all the NetWare.
Yeah, absolutely. Um, you know, and, and transferring everything over, and, and that was fun, um, you know, being, being part of that. And then, uh, after doing that for about a year, I got convinced by a friend who was starting a trucking logistics firm out in central New Jersey And he's like, hey, you know, I'd like you to build up our infrastructure and be our, you know, VP of tech and just sort of build everything out for us. And so I went out to kind of work on this startup and did that for a couple years until I ended up at Cardinal Health. Cardinal Health, the big pharmaceutical company.
Most people haven't heard of them, but the pills that they take are probably produced by Cardinal Health. And they're a Fortune 50 company, so they're a very large company. But I ran IT. I was IT director for one of their divisions up until when the FBI started knocking, and then that changed the course of time. So what do you mean when you say the FBI started knocking?
What's that mean? So one day I got a phone call, and it's like, "Hi, this is the you know blah blah blah from the FBI. We'd like you to come in and take our phase one test." And I'm like, "No." Why? Why did they call you? How do they know you?
And Well, it's the FBI, they know everything, right? No, I think at the time what I didn't realize is that there was a need for cyber agents because actually we really didn't even have a terminology at that point as a cyber agent. There was a need and so they were recruiting. So I think, you know, being in the area, I think I probably at some point even submitted an application to some government job, you know, that sits in OPM somewhere and They pulled that information and they made a phone call. They called and asked me to take a test.
I said no, I'm actually happy in my current job. I, you know, especially at Cardinal Health, I had a development team, I had engineers, I had help desk, you know, it was kind of a good overall position and it was close to home. And they're like, no, no, seriously, we're the FBI. And I'm like, no, no, seriously, I don't want the job. And they're like, no, no, really, just come take the Phase 1 test.
And I'm like, Okay, like, might as well, you know, I've never got a call like this before. So I go to the Newark FBI headquarters office and I sit down in a room and I, I take a test and it was a logic reasoning test. And essentially it was a day in the life of an FBI agent, everything from investigating a crime to collecting evidence to, you know, bringing it to prosecution. And there was a series of questions through the test and I remember taking that test and I'm like, man, if being an FBI agent is as fun as it seems like in this test, I gotta see where this goes. So then I was like, all right, let me keep going.
So I took the Phase 2 test, which was another test and an interview, and I apparently passed that, and they picked me to do the physical fitness test, and I failed. And I failed miserably because I'm a computer engineer and I have soft hands. Would you talk about what the— we actually interviewed in different FBI agent recently on the show, but tell me about your experience with the physical fitness test. What was that like? What'd you do?
So the physical fitness test is pull-ups, push-ups, sit-ups, sprinting 300 meters, and then running a mile and a half. And you do it all in succession with a 5-minute break. And, you know, it's just something that, you know, you have to either already be in shape to do that, and half of FBI agents are former military or law enforcement already. So they're already used to this, they're already used to physical fitness tests that happen all the time, or they're already in shape. And then the other half are people like me.
And so I just wasn't ready. So I could do the push-ups and I could do the sit-ups, and the sprint I was okay. The mile and a half though, I had an— it was abysmal. And so I failed. I actually puked as well.
Oh yeah. So they give you 30 days to kind of, you know, get back, get into shape. And so I just sort of like every day just hit it and muscle memory, just kept taking the test every weekend to be ready for it. And I took the test and I passed. And then they put you through the background investigation and the polygraph.
And the polygraph is probably one of the worst experiences I've ever had in my life. I mean, it's awful. So understanding that maybe you don't want to give a specific thing that you were uncomfortable with, can you give a general thing that makes it so terrible? So, okay, like, what's— having put people on the polygraph, you know, from an agent perspective, and it's kind of fun when you're on the other end of the mirror and you're able to sort of see people squirm or get uncomfortable or a variety of different things, but they're usually criminals or subjects or sources. They're not, you know, trying to get a job.
And so at the end of the day, the FBI cares about hiring somebody that doesn't have a criminal background of significance, recognizing that, you know, if you break a traffic law or something like that, not hiring someone that has connections to people in the underworld, you're not a spy, and you're not a terrorist or connected to that. So those are the main questions that you're asked. And then there's a bunch of other questions that they ask because we're gonna ask you those questions and really try to hammer and needle you and put pressure on you to put you in a corner So you crack, and then you'll answer the rest of our questions truthfully. So it's a very long, drawn-out process. My polygraph was 3 and a half hours long.
Oh my goodness. And some of the questions that they ask, they have no bearing on— there's no right or wrong answer because you will be lying regardless. Have you ever told a secret that someone trusted you to keep? Okay. Have you ever told a secret?
Of course the answer is yes, right? Right, because if you say no, you're lying. Right. And if you say yes, Now you're telling secrets. No, now you're telling secrets.
We can't trust you with secrets. So my answer was yes. And she's like, oh, so you're telling secrets now? We're gonna trust you with secrets? Like, what secrets are you telling?
I'm like, I was, you know, like, you know, when I talked to my mother or I talked to, you know, my girlfriend. Like, nice. Like, no, no, that's not what I'm talking about. I'm telling someone trusted you with a secret that they didn't want anyone else to know, but you had to tell someone. What was the secret that you had to tell?
And it was just like, you get that stress level that's going on. You're just like, he's not, he's not gonna give up until I give him something. Or, you know, there was others like, have you ever cheated in an academic setting? And it's like, that's a very generic word, right? Cheating.
Did you cheat? Did someone cheat off of you? What's that? So I remember I said no. And then as I was going through it, because he asked me questions several times, several iterations of it, 3 and a half hours worth.
So at one point I'm like, I think there's something there, like in middle school, like I think someone cheated off me, or I don't know, but there's something there. So I changed my answer and he got mad. He slammed the clipboard down. He's like, you're changing answers now. What's the problem?
I'm like, just something popped in my head. He was like, well, just tell me what it was. I'm like, I don't know what it is. I just think that something— he's like, just tell me, you know what it is. I'm like, I really don't know.
And he's like, just tell me. I'm like, like, he's like, okay, okay. When you came here this morning, did you rob a bank? Like, no. He's like, well, how do you know you didn't rob a bank?
Because I remember. He's like, well, if you can remember not robbing a bank, how come you can't remember what, what you— the aspect of the cheating that you're thinking of? And I'm like, I just don't know. He's like, all right, all right. When do you think this happened?
I'm like, I don't know, somewhere in middle school. He's like, all right, I'm gonna change the question. Since the age of 16? No, 18. Did you cheat in academic setting?
I was like, no. He's like, all right, good. So this kept going and going and going. So then finally I was like, I don't like this guy. So I'm like, I'm just gonna mess with him.
So every time he asked me a truth question— so there's truth questions which will give you a baseline of what the truth is like, and then there's lie questions, control questions. So my truth questions are, your name is Andre McGregor, you were born in 1982, and you went to Brown University. Yeah, you should know those. There should never be any fluctuations in your biorhythms. So as he would ask me these questions, I think of the craziest things in my head and just throw my whole body off.
And he detected it. He was like, what's wrong? I'm like, I don't know, I'm just tired. He's like, do you want this job or not? Stay with me, stay with me.
I'm like, all right. So then like my stomach's grumbling because I'm hungry because I've been here now for 4 hours and I had another 4 hours earlier and it's just, it's It's now like 4 PM. I got here at 7:30 AM. And I'm like, my stomach's grumbling. He can feel it because there's a diaphragm strap.
And he's like, what's wrong? And I'm like, my stomach's grumbling. He's like, why is it grumbling? I'm like, well, I think I'm hungry. He's like, why were you hungry?
Did you not eat? Were you running late? I'm like, no, I'm eating smaller meals. I have a nutritionist to kind of help me get going. He's like, why do you have a nutritionist?
Is it something you're keeping off the health questionnaire? Why is everything a question with you? I just am tired. So then the test is over. He goes out of the room.
He comes in. He's like, well, I think you passed. I think there's something you're hiding in your drinking history though. I don't even know what. You didn't ask me any questions, but whatever.
He's like, I brought you a muffin. And he brought me this chocolate chip muffin with like the crumble on top. Yeah. And he's like, here. He said you were hungry.
And I'm like, no, no, no. I'm I can't. I'm trying to be healthy. My nutritionist— he's like, don't worry, I won't tell. I'm like, is the test still going on?
I don't like this at all. That was my— that was like the jarring experience where I'm like, I don't think I got this job. I don't know what's going on. 6 months later, I'm in Quantico. So there you go, I guess.
Wow. So what year did you start with the Bureau? What year was that? Uh, so April '09. '09.
Yeah. Um, and, and so what'd you do for him? I mean, obviously all kinds of stuff, right? Because you're not— no one's just a cyber agent, right? You, you're a full agent who does right everything, right?
Yeah. And New York is New York. So as much as, uh, New York is a hard place to work, it's very expensive, a lot of traffic. Um, you know, it's just the, the speed of New York is very, very fast. It's also one of the best places to work as an agent because while it's not a good thing to say, it's some of the best criminal terrorist work that you'll ever get because everyone's trying to take New York City down in some capacity at some point in time.
And so when I first got to New York, every new agent ends up working terrorism in some capacity. And so my first investigation that I supported as a new agent before I, you know, it was a major investigation was I don't know if you remember Najibullahzadeh. He was the subway bomber from Denver, drove cross-country. So got to work that investigation, which was cool in the sense of being in the middle of a very high-profile, very scary, unnerving situation. Worked surveillance, and my team was involved with the Times Square bomber.
Remember the car in Times Square? So working that investigation was pretty pretty cool as well. Italian organized crime, so the Gambino, Lucchese, Bonanno crime families, so being able to effect arrests and arrest of a hitman after a high-speed chase through the streets of New York City. Oh yeah, it was movie-quality high-speed chase. And because we're the Bureau, we don't have marked cars and we're a surveillance team, even though we're surveillance with enforcement now because we're about to arrest this guy.
We've got a minivan, you've got a pickup truck, you've got like all these different cars that like are lights and sirens, like, you know, souped-up engines. I was just always wondering like, what are people thinking right now? Like, what is going on? Like every possible diversity of car with like full-on red and blue light packages going on and sirens, and you're just like, people must be like, I don't know what's— or they're New Yorkers where they're just like, whatever. I always remember my first arrest.
Was for— there was a— NASDAQ got hacked back in 2010, and one of the individuals we found was in Sacramento. And admittingly, we were trying to arrest him before Secret Service found out because there's always a race between FBI and Secret Service when it comes to cybercrime. And so I flew out to Sacramento. You know, he had apparently got arrested for auto theft because he was driving on a stolen car and he had no legitimate reason for that. So he was already in Sacramento County Jail.
So I was like, all right, just go pick him up and bring him back. So Sac Jail gave me some belly chains, and, uh, you know, I got rid of habeas corpus so that he was mine, boarded a plane on, you know, United with, with my prisoner, um, in the middle of a normal plane. Oh yeah, which is funny because, well, we, we actually have jackets that like hide the belly chain, but you still hear the chains rattling as he's obviously got chains on his legs too. The airline does make you take off the ones around your ankles while you're flying, obvious reasons for evacuation. FAA requires planes to be able to evacuate within 90 seconds, so it doesn't help when you have legs that are chained.
But we sit in the way back of the plane and my guy had to go to the bathroom, so I took him to the bathroom, I unshackled him, and I remember the guy that was in the bathroom, he comes out, he sees me taking off the handcuffs, he's like, oh, He jumps this passenger and just runs up there. I'm like, well, at least he's got a good story to tell whoever he's sitting next to. That's what's going on. But I always remember, like, I had him, I was interviewing him at the FBI office in New York. The district court's across the street.
And I mean, it's literally like 2 blocks away distance-wise. And I just was like, I'll just walk him across to go meet with the attorney. He's in full orange, like jumpsuit orange. And I'm walking across the street with him handcuffed. And not a New York— not one New Yorker batted an eye at all that like you're just walking a prisoner that's handcuffed like 2 blocks down New York City Street because it's just New York.
Like, New York, I got other stuff to deal with. Doesn't concern me. Not a relative of mine, not a friend. Go ahead. So, wow.
But, um, that was the first like, you know, year, year and change. And then, um, what happened was, uh, the FBI New York office said they wanted to open or start a squad that dealt with investigating cybercrime from nation-states. So up until this point, most of the cybercriminal work that the FBI worked was digital media intellectual property theft and child pornography, both of which are not considered cybercrime in much capacity anymore. I guess it depends on the vehicle in which that data is sort of extracted and and whatnot, but for the most part intrusions are not that. So no one was really working China or Russia at the time.
So they pulled a bunch of us from our various squads that we were on that were not working cyber, put us together and said, go forth and conquer and do good things. So we were working China before people talked about China hacking publicly. We worked Russia and then 2011, 2012, Iran came in the picture. If you remember the DDoSing of the banks. My squad had that investigation.
Stuxnet, if we remember that, once it made landfall in America, and I will not confirm or deny attribution of the development of this, but it made landfall in Atlanta and they needed to assign it to a squad to deal with. So our squad in New York had the Stuxnet investigation, which was interesting to work from a from an investigative perspective. Iran hacked a water dam, so I had that investigation as well. And then, you know, working critical infrastructure and some of the other attacks that are going on. So it was a pretty solid, you know, 5, 6 years of just dealing with, you know, some solid intrusions from nation states.
So, you know, the 2014, 2015 timeframe, you ended up moving on? June 15th. June 15th. So, so why, why were you done in June 15th? Um, I mean, you can— 20 years is retirement normally, right?
This is true. Yeah. And it's interesting because everyone kind of looked at it from a— looks at it from a very binary perspective. Yeah, like, you know, you have a great job in government and you get a pension after 20 years, and then you can go do other things after that. For me, I said, well, hey, I can't leave before I'm 50, and I came in when I was 26, so it's more than 20 years, it's 24 years before I could actually retire.
But really, like, I want to do something meaningful. And not saying that I'm not doing it at all as an FBI agent, because I have, and I can point to some, you know, awesome accomplishments that have, you know, reverberated through the community, but I still wanted to be— I wanted to have a sort of a bigger impact beyond just being being a single agent. And so I was torn, and so I sought advice, and that advice was through FBI Director Comey. And I reached out to him, I sort of took a shot in the dark, and I was just like, I did kind of this like, you know, novella of my life and just sort of, you know, sent an email and didn't know if I'd ever hear back because, you know, it's the FBI director. You didn't know him at that point?
I did not know him at that point. Point, and I'm 15 levels below him. So there was also the potential of just getting in trouble because we are a paramilitary organization. Your supervisor is who you talk to. You don't talk above that.
And even though I was a supervisor at the time, my ASAC, Special Agent in Charge, is the person I talk to. But I took that shot. And he got back to me. And he emailed back. And he was just like, hey, we should talk.
And try to figure this out. And so we started talking, emails back and forth, text messages, right, different things. I mean, like, over the course of a solid month, he was trying to understand who I was, what I wanted out of life, what I wanted out of the FBI, what were my thoughts on how we do things well or not well, and where do I see myself in advancing that. And so after about a month of conversation, we sat down for lunch and I mean, he really— I mean, this guy's got a countless number of things that he's dealing with every single day, and the fact that he decided to spend that much time with me, I still thank him to this day. He said, hey, I think you should leave.
I just think, you know, for what you want at the speed that you want it, you can't really get it here because we're a seniority-based organization, and it's gonna take you many years to get to the point where you can have that impact. And you want that impact now, and by the time those years are in, the problem you're trying to solve will be solved, potentially. And that was my thing, is I wanted to be on the cutting edge of solving the problem than sort of being reactive. And as much as the FBI does great work and continues to do great work in the space of cybercrime and nation-state attacks, It's very reactive. We have no real stake in sort of the development of better technologies or better best practices.
We always kind of dump that onto DHS, US-CERT, ICS-CERT to say, hey, my job is just to investigate the crime, collect evidence, and arrest the bad guy. I can't help you on how to fix your problem or give you advice on what you should be doing, even though I know the answer. I can't. That's not my mission. That's not my job.
I wanted to be on that other side. Yeah. So I thought Tanium was a good fit there. So did you did you leave the FBI to go directly to Tanium? Yes.
Okay. Yeah. So so that was June of fifteen, you said, right? June of fifteen. So what ended up happening?
Yeah, it's been a while. I I remember the first couple months like I I we call it phantom. Block where like you're used to having your gun all the time. I mean, I carried my gun more than I carried my wallet and my keys. Like it was on me all the time with the exception of cutting the lawn and actively working out in the gym.
That was just a part of who I was. So to not have that felt very like weird. 2 and a half years later, I'm glad I don't have it. Like the liability associated having, you know, I've broken up fights where, or been in situations, I had to arrest a guy on the side of the turnpike you know, once, and it's just like stuff like that where it's like, you know, like I now can be a regular citizen again. I will still intervene and help where I can, but I don't have to, you know, think about deadly force, which is very calming and very relaxing at this point.
But, you know, I saw a demo of Tanium, and my friend Dave D'Amato, basically said, hey, you should, you know, look at this product and tell me what you think. And if you're interested, we should have more conversation. If not, then don't worry about it. Yeah. So me and my partner Jason Troopy, we both sit down.
He's in DC, I'm in New York. We both log into a WebEx in, you know, FBI offices, and we see this Tanium demo by a guy named Egan. Who now runs our technical account management team, and he goes through Tanium, and we're looking through the product, and we're going through the demo. We ask some questions, and it's like, at the end, I call Jason on the phone. I'm like, Jason, what do you think?
He's like, I think we should go to Tanium. And he was also thinking about leaving, and we sort of made this sort of decision that we would do kind of a Thelma and Louise Yeah, if one's gonna go, the other's gonna go. So at least like we can both feel like there's someone else that understands. Yeah, the struggle of, you know, giving up, you know, a profile, you know, like the FBI. You're, you're an FBI agent first, and then you're your, your, your other life.
Like you're not— there's no 2 lives. There's no dual life. It's you're an FBI agent. Yeah. And then, oh hey, you may also, you know, sing in a church choir.
You know, no one sees you as the person that is the coach of your son's team. They see you as the FBI agent who's also coaching your son's soccer team. So we decided to, when we saw sort of how the TAME technology worked, we were like, man, all the investigations that we had worked, if the companies had this technology, we would have had answers faster. When we're looking for indicators of compromise, when we're looking for machine assets that they can't find, this would be able to help discover that, to do instant response better. If we could be at the cutting edge of helping to develop that, what better way?
So I took that to Comey, Director Comey, and he was like, I couldn't see a better place for you to go mission-wise to still be able to accomplish what you want to do while staying true to what you've been doing at the FBI. Wow, that's really cool that he spent time talking to you about that. Yeah. So what did you join Tanium as? Uh, at the time, yeah, at the time there were 2 positions at Tanium.
Either you were sales or TAM. Okay, technical account manager. Um, so I came in as a TAM knowing that that wasn't going to be the case long term. But there's only literally only 2 slots that, that existed. How many employees were there?
Uh, about like 175 at the time. Um, but the majority, everyone was either a salesperson or TAM. And there was a very small back office and very, very small, like 2 HR specialists and, you know, 2 finance people and things like that. And your partner came over too? Yes.
So Jason came over as well, and then we had, we basically went 2 different paths. So I went to the security team and built up the security team and built out the functionality. Jason went over to the EDR, Endpoint Detection and Response team. That got built out into a bunch of guys that built our content for the security side of Tanium. So Jason, is he like product management?
For EDR, or, um, basically. So I mean, EDR doesn't, uh, they're not under the TAM structure the same way as the rest of the TAMs. So if I were to break up how Tanium works, uh, you have a salesperson that sells Tanium, and you have a TAM that will support the installation and troubleshooting and implementation of it. And then you have this kind of like dotted line team that is the EDR team that's basically staying up to date on current threats, creating content within Tanium to be able to look for different types of attacks, different ways, different signals that we would be detecting, being able to support engagements when there's an incident response. Even though we're not a services company, we'll never be a services company, some of our customers will have an incident and then they'll need help.
So, you know, this team will fly out and help you use Tanium properly to, you know, collect your forensic artifacts or do your remediation so you don't blow up your system or you do it at a quick enough pace. So would it be fair to call it like a tier 4 technical support specific to that product? Yeah, that sounds about right. Yeah, I've never thought of it that way, but that makes sense. Because they're not product management, so they're not actually sort of developing the— They're not telling the developers what to do.
Yeah. But they are giving feedback. Giving feedback. And I mean, our technology is used by US-CERT and by some other agencies that do assessments and response. And then what's great is they'll come back and they'll say, hey, it would be great if you had the ability to search for this.
We can't tell you because it was classified. And so now we're able to provide, like I said, cutting-edge capabilities in Tanium to our customers without them needing a threat intelligence feed coming in for old brittle IOCs that may be useful to them a month ago or has no effect on them whatsoever. So when you went to Tanium, where did you work? Were you— did you work from New York or did you move to San Francisco? Oh, I worked from New York.
Yeah. So Tanium is 75% remote office. And so most people don't work in a Tanium office, which makes it great for securing Tanium because, you know, if everyone worked from an office and a desktop and egress points were all things that were within my control, then, you know, my life would be a lot easier. But when Most people are working out of hotels or working from home and working from laptops, and I can't really control access to that laptop. You know, it does make things a little bit different or a little bit difficult.
But I worked out of New York. I did that for a couple years until March when I decided it was time to come home. Nice. So I packed everything up in a U-Haul and then surreptitiously left New Jersey. Because I said, if I, if I tell everyone I'm leaving, they're going to stop me.
So I'm going to leave and then come back and tell everyone that I left. Otherwise, they're gonna convince me that I should never leave. Which is true. They were trying to convince me not to leave. But it was nice because I'm a volunteer fireman in my town in East Brunswick.
I've been there for 12 years, volunteer. And just today or yesterday, they made me an honorary member. For life, which is really cool. I used to love driving the fire truck, 40,000 pounds of truck, just going to a fire, going to a car accident, and being able to do that. That's sort of one of the reasons I went to the FBI was that sort of emergency services world that was there.
So a couple more threads I want to pull on here. We haven't talked about the NCC yet, the National Cybersecurity Center. I know you've been involved there. Maybe you could just start from the beginning. How did you get involved and what are you doing there?
Yeah, I tend— I tell people I'm a very transparent, candid person, for good or bad. But at least you know where I stand. I'm very good at sugarcoating things. I'm not a mean person in any way. I think I'm a very likable person.
But in the case of the NCC, Governor Hickenlooper had a delegation that he sent out with himself to Silicon Valley and they met with a dozen companies in the Valley, one of which was Tanium. And so when the governor's coming to Tanium, they're like, oh hey, the governor's coming, you should sit in on the meeting and do a demo of Tanium and Orion, our co-founder, will be there too and a variety of people. So the full delegation's there, we have some people from Tanium, we're talking through issues. Long story short, they were only supposed to be there for 45, I think 30 or 45 minutes. They were there for 2 hours.
Like, we were just talking and we were just being very blunt and honest about, you know, the way society is, the way systems are, the problems that we're seeing. And, you know, I guess it was just a fascinating conversation that they decided to kind of push off the rest of their next event to stay with us. And then at the end, they mentioned the NCC. And sort of what they're trying to do with the NCC, which is to be a conduit of information and capabilities for local state government as well as, you know, small, medium-sized businesses in Colorado, really from an effort that the governor saw when he went to Israel. So at the end they're like, you know, what do you think of the NCC was the question that they asked me.
And my response was, I think it's going to fail. And they're like, what? And I'm like, well, honestly, I mean, you're new. It doesn't sound like you have anyone really that's on the NCC that is operational, that understands the technology and understands really the day-to-day of what's going on. And you're gonna get— and you've got money— and you're gonna get the sharks that are gonna come out and say, you know, the big companies that are out there that do do contracting work that say, hey, we'll throw out a big ticket, you know, price tag to you and we'll provide this.
And then at the end of this, they're not really going to provide it, and you feel like you didn't get any services, and they won and you lost. Like, that's what's going to happen. And then your second version of this is going to be much better. That was my response to the governor. So then he was like, um, do you want to be a board member?
I was like, oh. Maybe, I don't know. It's like, well, we'd really like to have you as a board member. And I'm like, oh, all right. So then I've been being a board member, and, um, we've had, you know, many board meetings where we've, we've now sort of moved the ball forward than, than where it was before.
Uh, I think, um, there was sort of an identity crisis within the NCC of what it wanted to be— everything to everyone. Yeah. Which really meant it was not really being much of anything to anyone. And so once we sort of streamlined the focus of capabilities of what the center should do, who it should focus on, and the capabilities it should provide— Vance Brown, who's the new CEO right now, is fantastic from an energy perspective. He's, you know, started a startup before, so he understands sort of that, you know, footwork that needs to be done at the ground level to get things going.
And You know, we have some solid interest from, you know, local partners, military, other governors as well. And so the idea is if we can create this as a center that can be mimicked by other states of similar size and stature, then it works out well. Because I think Colorado is a state that can actually relate very well to not only an Idaho but also a California. You know, whereas some other states, you know, it's very hard to see that. You know, you can't really say, you know, what California government is doing, you know, Idaho could do because it's California and California is very big, even though you could break it out and say that, you know, it has as much agriculture, if not more, than Idaho.
But Colorado is just such a blended, you know, world that I think everyone lives in 'Cause you've got what's happening in the Denver metro area, but then you've got the digital divide that's happening down in Pueblo, right? Or some of the other smaller communities. So having to balance both of those really kind of shows Colorado as being that middle ground for most of the states. So we met with the CEO and COO previously, and they both turned over since we had them on the show. And they, you know, he had articulated a vision for the things that NCC was gonna go after.
Could you articulate what it's going to be like? You know, there was the incident response assistance, there was some training. What is— what's the vision look like now? What's the 2018 version of NCC? So the 2018 version, we, we dropped incident response.
Okay. For a variety of reasons. Not only are we behind the curve on being able to have the skill set to do it. There's also a liability factor that goes into it as well. The primary focus right now is going to be training, workforce development, and research, and supporting research engagement.
So if you think about it, we all can agree that there's a workforce development need. You have people like Alex at SecureSet that's supporting educating new people into the cybersecurity space in Colorado. You've got universities that are also trying to do the same, but there's not really a place where we can sort of bring people together to, I don't wanna say recruiting, it's more than that, really sort of a way that you can synergize what big companies are looking for to what's specific to how Colorado works and really sort of develop a pipeline through all these different channels that are not sort of disparate. So yes, SecureSec can still do what they want to do, and yes, you know, the universities can still do what they want to do, but if we can pull that all together into one bigger picture, it's sort of like when you look at consortiums, you know, pooled together And bringing everyone in just makes you stronger because now you're able to share resources, share money, share people, and it works out. So that's the workforce development side.
On the training side, you know, we woefully need to have better training for small and medium-sized businesses and local state officials. I think for the most part, and I'm being a little flippant by saying this, There's a lot of people that don't respect the cyber threat. And it's not— I don't think it's because they are arrogant. I think they just don't know. They don't understand it yet.
Right. And so, you know, it's up to us to sort of do 2 things. Either I make better technology that makes it easier for you to not have to think about the complexities of cybersecurity, because it is very, very complex, and— or I do better at teaching. And the problem that we have right now is that when you look at someone, you look at a place like the city of Aurora, for example, I met with their, what would be their sort of equivalent of their InfoSec coordinator. And, you know, he's got a daunting task because he's got to think about all different types of cyber threats, and he's not a cyber guy.
From all different facets, whether it's, you know, the police department, or it's a DDoS of a website, um, or it's patching and vulnerability issues with another, you know, like there's so many different things that he has to think about. And we forget that in like the cyber world, it's, you know, asking that one individual to do all of that is the equivalent of like going to a random doctor and saying, I want you to cure cancer, right? I'll do all of the things, or, you know, Cure health. Cure cancer and also do the surgery and also fix my bunions on my foot. Right.
You can't expect that, nor should you. Unfortunately, we've put these people in positions to fail because of our lack of understanding and quite frankly respect for the threat. We think that the IT guy in many of these cases, because they're smaller places, is also someone that can understand the security security nuances of the technologies that they have to deploy and keep available, which is what, you know, if they don't keep that technology going, then either they lose a job or they get a lot of complaints. So are they gonna care more about the availability side of the confidentiality-integrity triad, or are they gonna look at the others? Probably the availability side.
So, you know, getting people to understand, especially in government, because How else are we going to get the funding? How else are we going to get the changes in technology that we need? The fact that we, you know, one of the reasons I enjoy being at Tanium is just because we solve issues that we see all the time with just multi-tenant federated environments where it's like, all right, you've got 40 different agencies and you've got 5 different patch solutions. Like, I'm not saying you need to use I'm just saying you need to use one. Like, because now I've got 5 different types of people with different skill sets that don't talk to each other.
And so when bad stuff happens, all of a sudden now I can't use those people because I can really only use those 2 people because they're the SCCM people. The other Altiris or, you know, BigFix or whatever people, you know, you know, so like that's our problem is we need to better the training side of things. And then of course there's the research side, which is, you know, we're at the UCCS, which is the whole UC system, University of Colorado system. So being able to support student research in this space and being able to expand that out and have some agreements with international universities to do peer-to-peer sharing and whatnot. So I want to keep us moving a little bit, but I want to ask one more question about NCC before we move on.
What is a deliverable that we can expect in 2018 for NCC to start going— going to market isn't quite the right term, but you know what I mean, like start offering. What could we expect to start seeing this year? So one of the things that we're gonna offer is in March we are gonna offer executive-level cyber training course or courses. So, you know, everyone says the board must be better educated or The C-suite needs to be better educated. We're going to provide the training in that capacity.
And I kind of got bullied in a corner to support that, and I now— by teaching it. Oh, you're teaching it too. All right. So, but I'm excited to do it. I just have to come up with a lesson plan, which is mostly done.
But really, it's going to be exciting because we just got to— we're going to get a bunch of Fortune 1000 board members that are going to come in from around the country and take these courses. So can people start sending their board members to go to do this? People who are listening right now who are like, ooh, I want my board member to get that education. Oh yeah, please. What should they do?
How should they reach out? Go to the NCC website, nationalcybersecuritycenter.org or cyber-center.org, and you'll be able to click on buy tickets for this particular event and go ahead and do that. Another thing that we're going to do is offer more research opportunities in blockchain technologies. So I've become insanely interested in blockchain recently. Like, I had no interest in it prior— I mean, I had no interest in it prior to about 2 months ago.
Is that when you bought your Bitcoin? So I never supported Bitcoin because we arrested so many people at the FBI in New York for crimes in and around Bitcoin. You know, a lot of the interesting arrests in 2014 were my squad or sister squad in New York City around Bitcoin. And so when I talk to people in that world now, they're very squirrelish because they still see me as an FBI agent. And it's like, no, no, really, I'm just, you know, interested.
But yeah, no, we're gonna offer more in terms of helping people to understand and do more research around blockchain technologies and the security that's associated. All right, I'm gonna move us along. We only have another 10 minutes or so, and I wanna ask you about, you know, kind of the skating dog, the skateboarding dog, right? The fun stuff. How did you get involved with Mr.
Robot? Ah, yes, Mr. Robot. Hopefully everyone— what is Mr. Robot, by the way?
Mr. Robot is probably the best attempt that we're ever gonna get to showing cybersecurity and hacking on mainstream television. So Sam Esmail, who's the creator of the show, who loves technology and loves cybersecurity, decided to develop this show. And if you, you know, everyone's probably watched like CSI Cyber and cringed at like, you know, How is it 2 people are typing on the keyboard at one time? Playing piano together.
Right, I don't understand that. Or I actually don't understand how Lil Bow Wow, or I guess he's Bow Wow now because he's older, is an FBI source that is a hacker. There's so many. And then there's like green code is good and red code is malware. It was like, I don't know what this show is about.
I think I got in trouble with our legal department because I did an interview and I mentioned that CSI Cyber sucks. And they're like, we could be sued. I'm like, why? No, it's true. You can't say that.
Right, it's libel. I thought libel was true. If it was good, I would say it was good. But Mr. Robot needed a consultant to ask some questions on, at the time it was just about FBI-related things.
And so they, they, um, uh, sought out through a friend of mine, um, you know, someone that could answer these FBI questions. He's like, oh yeah, you know, former FBI agent, and put him my way. And I started having these like cryptic phone calls. I never watched the show. And this was now— so season 1 had happened, okay?
And, um, they were obviously working on season 2. And so they're asking me these cryptic questions. So If we were to arrest someone and they were, you know, we were at the door, what, what, you know, what, how many people would be at the door? Like, would you knock down the door? Like all these like questions about just procedural things.
So, but they wouldn't tell me anything. So I'm like, so I just kept answering the questions. And then finally one day I'm at home and I get a phone call and it's Sam Esmail, the creator, and he's on speakerphone. He's like, hey Andre, it's Sam. I'm with all the writers right now, we're on speakerphone, we gotta write this scene, so we're just gonna ask you point blank a bunch of questions.
And they just started asking me questions, and it's just like, and he's like, all right, we're gonna send you an NDA at this point because you need to. I was like, okay. So we started working on that, and then they're like, well, so we want to hack, we want to do a hack that does X, or can you help us, you know, understand, you know, what would be involved if we were to try to get into this system or try to get into this account. And so it was like cool because it's like, all right, well, you're trying to get it right. Yeah, you want to get it right.
Like, you're asking like very like specific questions. It's not just like movie magic and, you know, we'll just sort of let people figure out that it just happened. As an aficionado of the TV show Hawaii Five-O, that show is absolutely abysmal when it comes to how all the technology capabilities they have. I watch it, I'm like, Man, I wish the FBI had those capabilities, but I know that no one has these capabilities. Like, no one will ever have these capabilities except for maybe like London with all the surveillance state that it has.
But Sam was very, very much about getting things very accurate, and so we started working through some of the hacks for season 2, and it was at a certain point where it was just like every day that they were trying to get more detail and design and actually, you know, can you get us some code or can you spit out the output of what that command would do and then send it to us in a video and send it to the art department? It turned into a full-time job. So I reached out to our chief security architect, Ryan Kazancian, who works at Tanium as well. He came over from Mandiant and I was like, hey, do you like Mr. Robot?
He's like, oh, I love the show. I'm like, do you wanna consult too? And he was like, what? Yeah, like we're doing consultant work, like do you want to help? He's like, absolutely, 100%.
I was like, all right. So then the 2 of us ended up, you know, working season 2 together, working season 3 together. Obviously season 3 has just finished, so hopefully I won't give any spoilers away for anyone who hasn't started yet because I find out that a lot of InfoSec people either like are up on it and watching every episode as it comes out Or they wait to the end. I'm a binge watcher. And they binge watch the whole thing.
It's gotta all be at once at the end. I don't want to wait for episodes. Right, right. So that's why I've just learned, like, don't even just give anything away because I've learned that people— like, we have a Slack channel for Mr. Robot, and like at one point, like, people are like, you know, something came out and there's an article that was put in there and people are like, spoiler!
Oh nope, I'm out. And you just saw like 15 people leave the channel. Just like left, left, left, left, left. They're like Don't wanna know, don't wanna know, don't wanna know. So it's been really cool though because the accuracy is there.
Being able to sort of like dust off your pen testing chops and some of the stuff I learned years back, 'cause you're not really using that anymore. I'm a blue teamer, I'm not a red teamer, and I'm definitely not a black hat hacker. Right, but to be able to put that in a way that makes sense on TV, something that my mother could watch. Yeah, and, and what's, what's sad, maybe it's not— it was sad is my mother started to watch the show because she's like, oh, my son helped, you know, consult and write for the show. And so she watches the first episode of season 2, which I did a lot of work on, and that was the one with Ransomware.
Okay. And afterwards she's like, all right, I've got 3 things to tell you or ask. Like, one is it's really dark. And I'm like, yeah, it's a kind of a darker show. He's like, no, no, no, like the hue.
Like, it's just really dark on my eyes. So like, yeah, you're 65 years old. Got it. Okay. Number 2 is I finally understand what you do.
Wow. Like, well, that's good. That's kind of cool, but bad because I feel like you should know what I do. I've Arrested people. I've done perp walks where you've actually turned on like ABC World News and you saw me.
Like, okay, whatever, I'll give you that. And then the third is, the dog's name is Maxine. My mother's name is Maxine. Yeah, did you name the dog after me? I'm like, dog's name's Maxine?
So I'm like, I don't know. So I would go back to script, I'm looking like, oh shit, no, I didn't. Sorry, it wasn't really like Not on purpose, I didn't name, I didn't even name the dog, but it was funny that she like picked up on that. But like that was the point of the show is having someone at that level. And it's interesting because I've talked to so many fans of the show in InfoSec and they're like, man, we wish there was more hacking, which you'll get in season 3.
But you have to balance that with the fact that like you're the InfoSec guy that's going to pause the screen and check the code and make sure that it actually works. And we've had enough people that have told us, like, oh, there's a missing semicolon or an extra space. And so now we QA the code before it even shows up on the air. We make changes with the art department at the end in case we see something, because we don't want to deal with Reddit, because the Reddit crowd will get you. But you've got to balance that with the fact that your spouse is sitting next to you and probably doesn't know or care about that side.
So you got to keep the plotline— keep it interesting for both sides. Yeah, so that's the balance, is like you can't just be all hacking and all IT because then we would have a much smaller audience. Yeah, well, we're running short on time. A few more minutes.
Tips for people listening, maybe CISOs that are listening or security professionals. What are they doing wrong right now they need to get better at? And their jobs. And everything isn't good enough. I know, I was like, geez.
I mean, I could be the one that says the same thing that everyone says, which is we should be doing good cyber hygiene. And honestly, at the end of the day, every one of the major hacks that I've been to and worked at at the FBI were all related to either a system you didn't know about or a system that wasn't patched. That's it. So 2 things. That's it.
I mean, don't get me wrong, like, I, I, I now understand the woes. Don't forget about stolen credentials though. Stolen credentials. Stolen credentials. It's pretty popular.
It's more popular. It's popular now on the criminal side. Okay. With nation-state at the time, it was still just popping machines with, you know, drive-by downloads and some stuff. I mean, but you're right, stolen credentials are still very I mean, let's be honest.
Spearphish email comes in, looks like an email I'm gonna click on. I click on it, I go in, I put in credentials because it looks like the same system that I have. It man-in-the-middle me to the system that I'm supposed to go to. I don't know anything's wrong. I've just got the credentials, boom, done.
I wrote the story. And 95— I think the Bureau is still saying 95% of its intrusions still happen from a spearphish email. Why? 'Cause it's easy, it works. It's easy, it works, it's cheap, and email will always be open.
There's no way that I'm gonna be able to shut that down. So you're right, stolen credentials is there, but at the end of the day, I still have to pivot, I still have to escalate, and there's a lot of things that are involved there that if I had a better understanding or protection of those key systems in my environment, I would limit that exposure. So at the end of the day, network segmentation obviously is something everyone should be doing if we're not doing it now. IAM is something that everyone should be doing. We just deployed Cisco ISE at Tanium, and that's been pretty fruitful.
For NAC, Network Access Control? Yeah, so that's been pretty fruitful right now for especially controlling VPN activity and directing certain people to certain areas and enclaves. But at the end of the day, the major fires that we see still still come from just the poor hygiene stuff. And everyone wants the easy button. I get it.
I want the easy button. I also, I also can respect how difficult it is to do the easy things. Yeah. Without good technology or good people, you're behind the curve. It's hard.
It's simple. It's not easy. It's simple. Yeah. And it's easy for me to say like, hey, you should patch all your systems.
And it's like, yeah, okay. Like, you know, So yeah. All right, we have one more minute. Any final words before we call it a day?
No, I mean, I think it's a lot of fun. We do this again, maybe we can get you back in 6 months or something. There's a lot more stories that we just didn't get into, but I try to keep it to an hour. And of course, I have to run to a meeting here shortly. Yeah, no, not a problem.
I, you know, I— and the next time we talk, I can tell you about how we drone strike the terrorist or cyberterrorist hacker. Well, there's a good cliffhanger. Season 2 of Colorado Equals Security, Andre McGregor will include the drone strike on the terrorists. Yes, it's a very— it's a different way of disrupting a cyberattack, I will tell you that. Thanks, Andre.
Have a good one. Thanks. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.