All episodes

Steve Wostal, Director of Security at Starz Entertainment

Apple Podcasts Spotify SoundCloud

In this episode:

Steve Wostal, Director of Security at Starz Entertainment is our guest this week. News from: DISH, Catalyst Accelerator, ProtectWise, CyberGRX, Swimlane, Threat-X, Colorado Matters, Red Canary, Kroll, LogRhythm, Webroot, Optiv, Virtual Armour, zvelo and a lot more!

We are Colorado's A-Team of security - or - 'Colorado = Security Stadium' anyone?

First Invesco Field, then Sports Authority, next... Colorado = Security Stadium? Works for us. DISH buys ParkiFI, Catalyst Accelerator launches a cohort, Colorado has some great startups (including several in security), Debbi Blyth was on the radio!, GDPR is coming to Colorado, Red Canary partners with Kroll, LogRhythm & Webroot team-up, and a whole lot more!

Come join us on the new Colorado = Security Slack channel to meet old and new friends. Did you catch our trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11903 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

10 years ago, a crack commando unit was sent to prison by a military court for a crime they didn't commit. These men promptly escaped from maximum security Stockade to the Los Angeles underground. Today, still wanted by the government, they survive as soldiers of fortune. If you have a problem, if no one else can help, and if you can find them, maybe you can hire the A-Team.

The Colorado Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Rob Rack and Alex Wood. Welcome to Colorado Equals Security. Alex, you fired up? I am totally fired up, Robb.

I can't believe that somehow the mainstream media missed the 35th anniversary of the A-Team. I think that everyone just had their head in the sand because they didn't want to think that it was 35 years ago that it was actually The A-Team. Yeah. So as we celebrate our first anniversary, we also celebrate the 35th anniversary of most of our introduction to Mr. T, right? Yeah, I think so.

Yeah. So do you have a favorite A-Team character or memory? You know, obviously they were all pretty good. I think pretty much every episode had the same plotline. You know, throw in a couple cars that flip over or planes or helicopters that blow up and then you make it a little bit different.

I don't know, probably Murdock. He was probably my favorite. You know, gotta like the crazy guy. For me, it was definitely Mr. T. Like, you know, he's just so bigger than life and something you'd never seen before. That was pretty fun.

Anyway, that's our fun thing. I guess I have one other interesting fact this week. This is today, the 4th of February, is the 14th anniversary of the launch of thefacebook.com. That's pretty crazy.

Again, it shouldn't have been 14 years ago. It does not seem like it has been that long. Something that has turned into a fixture of American life. Yeah. None of our kids— really isn't that old.

Our kids have never heard of a world without the Facebook. Yes. Yeah. Good old Mark Zuckerberg. Maybe we can do some real news here, huh?

Before we do that, again, let's make sure everybody knows to sign up for our mailing list. So we can get show notes out to you. And also join our Slack channel, growing every week, lots of chatter in there. Added some new channels. It's been, been really going well.

One other thing, if you haven't gone and reviewed the show yet, please do. I was just looking, we have, we have a good number of views now on iTunes, but we— it doesn't look like we have much of anything on Google Play. Well, hit us up over there. Android is clearly much less secure, so no one uses Android. Absolutely.

That must be it. It's Google's fault. It's Google's fault. So first actual news story. Former Mayor Wellington Webb wants to bring back the Mile High Stadium name.

Yeah, he doesn't want to go sell it to yet another corporate sponsor. He wants to call it Mile High Stadium. I think what was at Pat Bowlen Field? And field. Yeah.

No one had yet pitched to him the Colorado Equal Security Stadium idea, I think. And I think if we get a hold of him, that could have some real legs. Well, I think one of his plans actually was to essentially sell smaller sponsorships, not a big name, you know, so, you know, people get to buy bricks and seats and stuff like that. So I'm sure we could afford to get a, you know, a piece of that somehow. Colorado Equal Security brick.

That's right. Look, everybody, this is the chair of the Colorado Security— Colorado Equal Security chair at Mile High Stadium. Maybe cup holder. We can afford that. Yeah, probably.

All right. So next piece of news, Dish Networks has bought a parking startup called Parkify. And this is really an IoT play, it looks like. Yeah, seems like they are moving in the direction of building out their wireless network. They've bought a lot of wireless spectrum over the last few years trying to, I think, eventually transform the company.

One of these days, your traditional cable or satellite TV is not going to be in existence anymore. We're going to be doing something else. So I think they're looking for other business models. So they spent $11 billion on additional wireless spectrum, and, um, you know, they're thinking that things like parking sensors, streetlights, gas meters can all be connected to this network that they're creating. That could be, you know, where they go next.

Yeah, and I think this is, you know, a little bit of an acquihire for Parkify. They're an IoT company making parking sensors, so get that team in and, uh, and help build out that network. Absolutely. Uh, next Catalyst Accelerator launches their first cohort. So this is a— I don't think an accelerator that we've talked about before.

They're actually down in southern Colorado, sort of Colorado Springs area. But cool that there is another technology accelerator that is out there, and they obviously just launched their first class. As you might expect in Colorado Springs, they're focused on defense and national security, but they are, you know, starting up brand new companies. And this is their first cohort, just launched on January 30th. At their Catalyst campus in the Springs.

Yeah, and they noted a couple companies in there. Looked like one was something about radar and other sort of defense-related technologies there. So next we have the ChickTech Denver that's really kicked off to help young girls find STEM careers. Yeah, so this is another women in technology focused organization. They actually have 2 programs, one called ChickTech Career, which is open to all women, all ages.

All industries, and it's around networking and workshops. And then they also have a Chick Tech High School program which focuses on getting teenagers excited about technology and training in STEM, obviously. So good thing again there. Yeah, lots of movement in this area. Similar story, one of the podcasts I listen to every day is Colorado Public Radio's Colorado Matters podcast, which is about— it's about 45 minutes each day that Talks just about local Colorado stuff.

And last Monday, I heard our friend Debbi Blyth on the podcast along with a high school student talking about the Girls Go Cyber program. So really launching that and kind of an interesting opportunity. We have a link in the show notes if you guys want to hear that podcast and hear them talk about that new program. We always like to have people listening to other podcasts as long as you hear ours also. Yeah, yeah.

And you'll see that it's It's not really very competitive with that, but it is a good one. It's way higher quality than us, but they're not talking about anything we talk about is what I mean by that. Next, there was an article this week about the 50 Colorado tech startups to watch, and we had some security companies that were on that list: ProtectWise, CyberGRC, or GRC, GRX, Swimlane, and ThreatX. And then also on there was a startup called Salt Lending. They're a with lending in the name, a financial services startup, but it's also blockchain-based.

Yeah, I think it's all cryptocurrency-focused lending, right? Yeah. I think that's what they're doing. Interesting company up north, and we're gonna have a job from that company coming later in the show. Yeah, glad to see that there are cybersecurity startups on that list.

Next, we have an article talking about GDPR and how it's impacting Colorado tech businesses. Some stories from Optiv, and there's another example or two in there from local companies and how they're dealing with GDPR. So this is probably for those who are not front of the line thinking about GDPR, but those who are wondering what the downstream effects are going to be. Yeah. I mean, I think it's a good example.

If someone, you know, you're talking about GDPR and they're like, it can't be that much work, can it? Yeah. Yeah. Maybe read this article. Maybe read this article.

Yeah. Next, Kroll announced an exclusive partnership with Red Canary. So interesting stuff there. Kroll, among other things, does incident response and forensics, that sort of stuff. And they are teaming up with Red Canary, sort of have Red Canary be that frontline, the management detection response, and then Kroll could do the backend, the actual incident response, and that sort of thing.

So I actually have worked with both companies in the past, and I have no insider information about exactly what their relationship looks like, but I would assume that this is a chance for Kroll to resell what Red Canary does. If they have any kind of integration, that'd be interesting, but it seems like there's probably not a lot. It's probably more of a resell relationship Yeah. Next, we have news about one Colorado company partnering with another Colorado company that's coming to us from New Zealand. It's a little odd, right?

But LogRhythm is getting threat intel directly from Webroot. And Webroot is, you know, one of their big offerings is threat intelligence. They're going to use Webroot's threat intelligence to enrich their SIEM. And we get this news from Security Brief New Zealand. Well, you know, they are earlier on the time zone, so it may be that they just picked this up before everybody else.

News breaks first in New Zealand. I like it. Exactly. I like it. I'm sure somebody down there already has that slogan.

But, you know, LogRhythm, they do have sort of a built-in ability to consume threat intelligence into their product. And this looks like Webroot is now another one of the folks that is built into that. Yeah. Optiv had a blog this week about cloud critical controls. Looks a little bit interesting here.

They were taking the CSA cloud control matrix and CIS standards and kind of putting them together into their, their own cloud control standard. So yeah, it looks like there's about 10 different categories. They've got architecture, identity access management, data visibility, threat protection, application security, governance, risk, and compliance, incident response, business reliance, and legal and privacy. And really looking at how do you do each of these things in the cloud. And I love this approach because it's fundamentally different than how we do all of these things in an on-premise environment.

Yeah, for sure. And, you know, those who've, you know, the days of thinking you just kind of move from one data center to a cloud data center are way, way in the past. You know, your fundamental changes as what you do in the cloud. And I think they do a good job capturing that here. So next, there was a blog from Virtual Armor, Cyber Threats: How Finance Directors Should Prepare.

Yeah. So this is for those of us who might want to have, you know, something to bring to your CFO or your finance team to say, why does security matter? If you have any problems getting buy-in from that team or you want to give them some talking points, this is a good article that really speaks their language, and you guys can use it as, as ammo to help with that conversation. Next, we have a blog from Zvelo, and we've never talked about Zvelo before on this show, have we? No, because it's not the easiest to say.

Zvelo. Yeah, I'm not sure if I'm saying it right or not, but it's Z-V-E-L-O, and it looks like what they do is really categorization of URLs and websites that other companies will, like OEM and into what they do, Um, yeah, so your, your web filtering product, right, may use Velo's, uh, intelligence, but they're here in Denver, right? They're in Greenwood Village, the tech center area. Uh, so the blog is about IoT cybersecurity and, uh, reach— whether it's reaching a tipping point. Yeah, uh, so really just talking about how IoT security is becoming more and more of a topic of conversations for security leaders and something we need to come up with solutions for.

You know, part of the solution they're suggesting is of course using their types of technology to get more categorization and make better, more intelligent decisions about it. I think this is a, you know, obviously a big conversation that we don't have one solution for. Yeah, I think it was a little bit more of a hopeful blog post. I'm not sure that it really— IoT security is really reaching a tipping point, but, you know, maybe if you said, we really hope soon that IoT security will reach a tipping point and people will start to do something, then that might have— Well, I think it's reaching a tipping point into becoming a massive problem. It's tipping into massive problem territory at this point.

Yeah. Yeah. Jumping over to trivia, right? We had our question last week, which was name the 2 other security podcasts that are created here in Colorado. The tense of the word are is important because there was a previous podcast that was created here by Chris Nickerson.

Remind me the name. Exotic Liability. Exotic Liability. That is out of production now. But there are 2 current ones.

There's the Cybersecurity Interviews podcast by Douglas Brush. He moved here last year, and we've actually been on that show. And then there's the one from the Springs called New Cyber Frontier, put together by Christopher Gorog, that really focuses on a little bit more military-ish defense type stuff than we do. But he's also looking at a national picture, not the Colorado picture. Yep.

We had a winner, right? We had a winner this week. So winner for this one was Brian Barnhart. Brian, congratulations, and enjoy your Colorado Equal Security water bottle. I believe he picked the water bottle from the store.

Congratulations, Brian. And as always, thanks to Andre Gaeta, who is our sponsor for the show. So this week, our trivia question is, what Colorado statutes prohibit computer/cybercrime? What Colorado statute, Hunt? We want to know what law it is.

This is interesting. This is obviously a more Colorado-focused question. We know that people are breaking the law when they do bad things, but what is the law? And yeah, what is the law, Robb? Yeah, I guess people are going to have to look it up.

Look it up. Send us a note. If you get the right number, you're the winner. And I did say statutes, not statues. There's no statues that prohibit Colorado and cybercrime.

And send an email to info@colorado-security.com or hit us up on the Slack channel. Don't do it in a public channel. Do it in a DM if you do it there. Exactly. All right.

So let's move on to events. Of course, on the website, we do have our event calendar. So please check that out for all the latest events. And the first one we have this week, on the 5th of February, there is a cybersecurity reception with the British government. Also on the 5th, DENSEC is doing their South meetup.

I saw on Twitter they were looking for a place. I suggested they meet at the Chinook Tavern. So if they don't meet at the Chinook Tavern, there's something wrong. Yeah, clearly. On the 6th, Women in Security are having their quarterly meeting.

On the 7th, CTA has their CTA 101 event where you really can get introduced to CTA and learn what places you can get plugged in there. Also, CTA, uh, booking on top of themselves. Also on the 7th, they have an actionable analytics event. On the 8th, SecureSet has their career conversations with Elaine Marino. Um, also on the 8th, CTA has a SkillWorks skill-based hiring and training.

This is a really big week for the CTA. It appears to be because also on the 8th, they're doing their Go Code Colorado kickoff. Nice, nice. Following that, on the 9th through the 11th, CTA is doing the Startup Weekend Women Denver. Yeah, they're doing a good job in the next week or so.

ISSA Denver has their February meetings on the 13th and 14th. So if you're looking to do something really romantic with your sweetie, I think taking her to the DTC ISSA meeting and getting some free food at the Microsoft campus, that sounds like a pretty romantic way to spend the afternoon. That's exactly what I was thinking about doing, Robb. You read my mind. On the 15th, SecureSet is doing their Cybersecurity Expert Series with Chris Roberts of Accalvio.

So Chris is great, and it looks like Chris is actually— I talked to the folks at SecureSet. He's actually going to be doing 2 meetings with them in February, and then he's going to come back again in March. So if you want to get a chance to get to know Chris and his very interesting story, I recommend coming to one or both of those. On the 15th as well, we have ISACA doing their February meeting, and it's active defense. When can you hit back, basically?

And then finally on the 15th, DENSEC is doing their North meetup, which probably will not be at the Chinook Tavern because that is not in the north. Let's jump over to jobs. This week we have a fun job over at Schwab. They're hiring a Director of Risk Analysis. Sweet.

Camping World is looking for a director of IT systems and security. Did you know that Camping World was in Denver? You know, it's funny when you say that. Actually, I believe their office is not far from mine. Really?

Yeah. I'd driven by it and hadn't realized that that's what it was. Maybe you should have known that. Arrow Electronics is hiring a security architect. Conversant is looking for an IT security engineer.

I'll just say a couple of positive things about this. I had the chance to go in, I think I mentioned this, an interview the CEO and founder at Conversant, and I was just blown away at what a great culture, what a great place to work this would be. So if you're looking for a security job at a, at a company that's doing some really good stuff, trying to make the world a little bit more ethical and treat people better, and you want to work at a really fun place where there's as many dogs around the office as there are people, this would be a great spot for you. And I got to talk with Cole Krems, who's, who's the hiring manager, the VP of security over there. I think it'd be a good place to work.

He's looking for— I did send him a note about this. He's looking for someone who's quite good at system security and network security. Those are kind of the 2 key skills for him. Cool. Next, Salt Lending is looking for a security analyst.

And of course, we talked about Salt Lending earlier. Get involved with cryptocurrency. I don't know if they pay you in Bitcoin or US dollars. That could be really good if you can get them to pay you in Bitcoin. Well, depending on when they pay you and when you cash it out, it could be terrible, right?

It could be awful. Kodolsky Security is hiring a principal advisor on strategy and governance. This is working for John Hellickson, a friend of ours. John was previously the CISO at First Data, and now he's, I don't know, bigwig at Kodolsky who runs this group. Stroess Friedberg is looking for a vice president for enterprise sales.

We have a few sales jobs this week. We know we have some salespeople who listen. If you're tired of that lame company you're working for, these better companies might be the right solution, right? Coalfire is hiring a sales executive focused on cloud and technology services. Silance is looking for an enterprise sales manager in Denver, and Stealth Bits is looking to hire an account manager here in Denver as well.

Sweet. That's our jobs. That takes— that's taken into the jobs end of the show until we dump it over to the feature interview. This week is with Steve Wostal. Steve, who we had to rush to get him into the show here, right?

Yes. So I interviewed Steve a couple of weeks back, and then we heard this week that Steve is actually leaving STARS. Yeah, moving on to another opportunity. So we wanted to get his interview out while he was still, still fresh before it ages too much. Right, exactly.

But really interesting interview with Steve. I know you guys are going to enjoy that. All right. Well, thanks a lot, Alex. We'll talk to you next week.

Thanks, Robb. All right. Bye-bye. This is Sue Lapierre, CISO at Pelagis. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

This is Alex Wood with Colorado Equal Security, and this is the interview segment. Today I am talking to Steve Wostal with Starz Entertainment. How you doing, Steve? Hey, pretty good, Alex. Thanks for having me.

Sure, glad you could make some time to come and chat. So I think like what we normally do, Steve, I want to give you a chance to introduce yourself, tell folks who you are, where you've come from in your career, what you've done, how you got to where you are today. So I'll kick it over to you and let you start. Great. So, so at STARS, my official title is Senior Director, IT Security Architecture and Solutions.

Okay. That's really hard to say without like taking a couple of pauses. It's a big title, but essentially STARS is— we're a mid-sized company. We've got, I think, in the order of 650, 700 staff total. IT and the technology groups, maybe, you know, about a quarter of that, right, between our broadcast and everything else.

My team was formed a couple years ago, so I used to be— prior to that, I was kind of the security guy, independent. I spent a bit of time managing the network team there and trying to also do security. We formed our team to try to engage more with the business and at the same time give a little more teeth to some of our security efforts.

That's what I'm doing today. In terms of how I came to this, it's interesting. I've listened to some of the other podcasts and a lot of folks really didn't grow up in security and I'm one of those.

I actually had an Apple II Plus when I was in, I think, junior high. I was trying to think back about this. You're going to date yourself. Yeah, no kidding. Well, I've got enough gray now, I think it's pretty obvious.

But I really had a lot of time, had fun programming on that. I got sort of addicted to the Oregon Trail game because it was like one of the first games, and then like Lemonade and all these games that probably wouldn't hold my interest anymore. So played with that, we got one at home. First we had one in class, then my parents sprung for one, we got one at home. Played with that for a while.

Went into college. Well, let me step back a little bit. Prior to college, we moved from LA to the Navajo Reservation, which is kind of interesting because it's funny how, you know, when you get to be older and you look back and you think about like, how did I get here? You see some of these pivotal events that kind of shaped who you are. And I've spent most of my life as a consultant, and this was my first consulting gig.

I'm on the Navajo Reservation, I'm in high school, totally bored out of my mind, and I'm working as an aide for the counselor's office and they're having this hard time with these paper records that they had. And meanwhile they've got this Apple IIe sitting in a box with AppleWorks sitting in a box, right? And I'm like, I have nothing to do, why don't I just convert all your paperwork to AppleWorks? Now, you know, AppleWorks had this thing kind of like FileMaker Pro where you could do like a database. So I put everything in there.

I don't know how long that took. Trained everybody, built them manuals on how to use it, supported it for quite a while after we got it going. And they used it as far as I know. I'm sure they're not still using it. So what was the driver for you guys moving to the Navajo Reservation?

Yeah, it was actually my mom. So we were in Irvine, which at the time LA smog was really at the peak of being bad. It's still pretty bad, but it was really bad back then. She was starting to have some lung issues, and the doctor said, you really kind of need to get out of here. My mom was a nurse, and so she applied to the Indian Health Service, and they said, where would you like to work?

She said, somewhere rural. So they just kind of covered their eyes and threw a dart at a map and said, well, how about New Mexico? So we're way up kind of by Farmington and Gallup. Know that area. Yeah, just, yeah, right on the edge of the reservation.

They call it checkerboard land out there. But okay, yeah, so it was a pretty interesting experience. I bet. Yeah, it's funny also, um, I was listening to a different podcast today and coincidentally they brought up the fact that FileMaker still exists and is still owned by Apple and it's still produced today and updated regularly. You wouldn't know it Really?

But it still exists out there. So if you wanted to make a FileMaker database today, you could go do it. Oh my gosh, that's amazing. Yeah. Yeah, that's funny.

So, so you had this initial consulting gig unbeknownst to you that you just out of boredom and then where'd you go from there? Okay, so then I went to college and I really wanted to be a double E, right? My whole thing was I was gonna make a solar-powered car. Nice. So the whole, you know, this is back in, this would have been the '80s, right, mid-'80s.

And so I thought, okay, we're gonna invent solar panels that are flexible and we're gonna put them on the car and battery-operated. And so went to drafting class, like, oh my gosh, this sucks. I hate drafting. I hated everything about it. Like, and then I went to my instructor, said, would I be doing a lot of this as an engineer?

He's like, oh yeah. Like, okay, maybe I'll do something else. So I went into the business college and I applied flopped around for quite a while trying to figure out what to do, and I was going in between majors, really not sure what I was doing. And meanwhile, I had an account on our local Unix system, and I was keeping in touch with friends of mine that had, you know, with Elm and stuff, right, that had moved on. And, you know, I had an email address at the college, and I was writing scripts to parse my email, and I was doing all these things with coding.

And my roommate says, you know, I'm talking to him one day about I just don't know what to do in life. He said, well, do you enjoy all that scripting and stuff you're doing? I was like, yeah, yeah, I do. He said, well, why don't you go into computers? I mean, you've got a computer, you're always on the computer, you really enjoy it.

I was like, well, yeah, that's not a bad idea. Maybe I'll look into that. So I ended up with an MIS degree.

That's kind of how I ended up in that field. What's funny is I started in security and I had no idea until I left and then came back and realized, oh yeah, I actually was in security and I didn't know it. I started as an intern at IBM in their federal systems group. Okay. And so we, the team that I was embedded with, did all the sonar systems for the older submarines.

So the diesel submarines, and we had a fully decked out lab that had all the gear that a sub would have. It didn't look like a sub. It looked like an IT room, right? Raised floor, and everything, but had all the computers. And then IBM had this directive that every department had to use an RS/6000.

They were all going to get one, and they had to figure out how to integrate it into their operations. And all the engineers were, you know, they were doing hacks on these Unisys computers and stuff, and they're like, I don't know what to do with this, give it to Steve, right? So I'm the intern, I didn't know TCP/IP, I knew Unix scripting, all right, but I didn't know TCP/IP. I'm in this DOD secure lab, I had to get a clearance to get my internship. I could call the IT people at IBM for support, but they couldn't come visit because they weren't cleared.

I'm having to kind of learn through them and then try something and then call them back and say it didn't work.

That was interesting, is I ended up doing 2 internships with them doing that. Then I ended up taking a full-time job as a sysadmin doing that. So I ended up doing about 3 years in that DoD environment where I ran, you know, we built a bunch of R/6000 clusters. I got them a bunch of compile software development tools that they could use on there, and the compile time was way faster than like, you know, trying to compile it on the Unisys gear and whatnot. So, you know, we did network security because we wanted to extend the lab into the offices because we had a cleared office space but nobody could do any technology in there because they had to always go to lab.

So we ran secure network and I worked with X-stations and all that stuff. So I didn't really ever think about that as being security till way, way later, right, when I realized, like, well, I've been through some of this. So yeah. Nice. And so after IBM?

After IBM, my manager at IBM met with me and he said, Steve, we really love what you're doing, but we don't see a career path for this at IBM. Meanwhile, I'm really loving this. Well, maybe it's time for me to move on. I had a friend at HP Consulting and he put in a good word for me and I got hired there. That's when I left security and started doing HP OpenView and I became an OpenView consultant.

I'm sorry. Yeah. Well, it was funny because sadly much of my legacy remains online. I wrote a doctoral OpenView column for the OpenView Forum. It was a big users group at the time, actually a huge user group around OpenView.

I wrote their column forever and I did a lot of consulting around OpenView. Although if you would have stayed at IBM, you probably would have ended up working in the Tivoli group and would have had similar pains with any of the Tivoli products. I guess one way or the other you would have gotten it. To be fair to OpenView, it was a good suite. Just like a lot of these things where they're like a SIEM or ServiceNow or anything, you can't buy it, spend some consulting time configuring it, and then wave goodbye to the consultant and not staff that tool appropriately.

It's just going to sort of languish where it's at. It took me a long time to realize in my consulting time, I was like, wow, I'm building It's kind of like, you know, I gave birth to this baby and I raised it to age 5, then I handed it to Alex. And Alex— I look back later and it's at age 4, it's like degraded, right? Alex took it and put it in a playpen and then went about his business without, you know, maybe threw some food at it every once in a while. And right, you know, right.

So, so I did that for gosh, I don't know how long. And then in 2001 some folks that I had met while working at a startup company, they started a security consulting company and they wanted to be a product company. There was actually another person slated to be the chief engineer for that, and he decided he had some other goals. He met with me one day and said, here's my idea for the product. Have fun.

He was there to help. It's not like he said, don't talk to me ever again. I ended up writing the product and it ended up being like a— it was sort of a Qualys while Qualys was still getting started. The idea wasn't so much looking for vulnerabilities as it was baselining a network and then letting you know when it changed. Got it.

More like a tripwire. Yeah, maybe like a tripwire for the network. It was an appliance. We had to do— I was the sole developer for quite a while and we had to get that whole compliance thing worked out and everything.

That was kind of me getting back into security, and I did that more as a developer. That was really fun. We were hoping to get some funding on that. We never really did, so my prototype ended up getting shrink-wrapped and sold. We actually sold a few of them, not really probably enough to pay the bills.

Then that company re-engineered itself. What happened was We found a niche for that product in the process control space, specifically in power and refining because they have these fairly static environments, right? Right. And so, and they're old school. There's not a lot of complexity and you're going to find a bunch of vulnerabilities in there anyway, so those aren't as interesting as these are hopefully fairly closed networks.

So if another system pops up in there, that would be interesting, right? Right. You want to know about that. Right, so we found some traction in there, but in doing that, we found even better opportunity around providing security consulting to those groups. So we developed a standard security architecture.

This was at the time where a lot of those environments had traditionally not been connected to the corporate network, and so they were secure because of their isolation, but then corporate started having systems where they want to pull that data back, right? It's kind of the precursor to big data. Yep. So they want to start pulling that data back. Well, how do you do that?

Well, let's hook you up to the internet or to the intranet, right? Right. And which is, you know, going to be a 2-way connection. And so now you're technically connected to the internet because the corporate intranet is connected to the internet. Yep, exactly.

So we developed, you know, the cool thing about that space is the control systems vendor landscape is fairly small. There's not like 10,000 players in that space, right? And so we— and they work similarly, that we could come up with a compartmentalization scheme where you could drop a firewall in and you'd have, you know, you'd have the important stuff in an important zone and you have like the view-only stuff in a different zone and all that. So we had a standard architecture around that and we implemented of that for quite a few different companies. So that was cool.

Yep. And then at some point you made it to STARS. Yeah, yeah, exactly. So, um, that company's still going, but there was a lot of travel. I decided I want to kind of come back home.

I'd done a lot of travel with the OpenView stuff. I was probably on the road 10 months a year. Yeah, for that's not fun some years. Maybe, you know, you're young and single, that, that's a lot of fun, right? You can travel all over the place and stuff like that, but then at some point it gets a little old, right?

You know, my wife picketing at the airport, like, right? Yeah. So, um, so yeah, I decided to come home. I did a brief stint at Comcast as an operations architect, and, um, that was, that was a good role at a bad time for Comcast. They weren't quite sure what to do with that role, so it was kind of hard for me to find my place there.

And so I decided it was probably best for them and me to move on. And so I found that opportunity at STARS. Nice. Yeah. So I think most people are probably familiar with STARS, the name at least, through the cable channel.

But I'm guessing that there's probably more to STARS than just a cable channel. So yeah, what functions are in there? Yeah. So some of the things that surprise people about, you know, the industry industry we're in, you know, we're premium content providers, what we are, by the way. Yes, yes.

And I don't want to sell you short there. Please, please don't. Yeah. And did I mention number 2? I'm sorry, just— oh, so the idea is, you know, there's our traditional business where we have relationships with the various studios and we can get content from them, right?

So a Disney relationship or an MGM relationship, and we can access their content. Yep. Hopefully before the other guys do, and we can show that to you early on, right? So we've had some, you know, we had a really close relationship with Disney. We've got close relationships with quite a few different studios.

Didn't you guys have a— I don't want to call exclusive, but sort of an early access to like one of the Star Wars movies? We did, we did, yeah. And I can't remember, remember which title that was, but yeah, I think it was sometime maybe Episode 8 when that came out. Oddly enough, for me in my industry, I'm not really— 7, sorry. Okay, yeah, whatever.

I'm not as in tune with— I'm really not a media guy so much. I've really tried. Everybody makes fun of me because I got rid of my tube TV about 2 years ago, you know. But yeah, we do have some of those kind of deals. And then, so, you know, we've got our ongoing catalog of titles that— from the studios.

But really, even before I joined in 2011, our CEO, Chris Albrecht, came from HBO and he said originals is where it's at. We're gonna really make our mark with originals. He had driven that at HBO, so, so he made that a point at Starz. I think that was the most amazing decision ever, right? I mean, I think it's really— he did the guys right on with that, right?

So you'll see, you know, I mean, we made an announcement a few years ago that we were gonna really push that, and you're seeing a lot more originals come out. Out to the point where, you know, me that doesn't watch a lot of TV, I can't even keep up. Just that's all I watch is our originals, and I can't keep up. Right. So, so we, you know, we, so we're the channel, right?

So if you flip over to Starz, there we are. What we do is when you buy Starz through that path, you're buying it from Comcast or DirecTV, you're not buying it from us, right? Right. So they buy it, and then they resell it to you. Recently, we've also offer an over-the-top model, right?

That's what we call where you can go direct. So that's kind of our first foray into direct-to-consumer, and that's been extremely successful. Having looked at a lot of the other online platforms that our competition has, I think I can honestly say we have a really tight app for that and it's a really good experience. So I'm sure it's 100% secure also. 100%.

Yeah. Yeah. This is not a challenge to anybody listening thing. But yeah, anyhow, that's us. Cool.

I noticed when you gave me your actual title that it is not just a security title, which I think is interesting. You wear a couple different hats or cover a couple different functions. I wonder if you want to talk a little bit about all the stuff that your group does or that you're in charge of. Sure. I mentioned we're a fairly small IT group.

We also are a little bit non-traditional in the sense we don't have a CIO. The functions you would call IT sort of fall into 2 SVP realms. The one I'm in would be what you'd probably call infrastructure and operations. That actually used to be our title a while ago. We had a director move on to another opportunity we kind of all got together and our boss said, you know, rather than just fill this position and keep going, is this an opportunity for us to retool a little bit?

All right, and so one of the things that we decided is, you know, back when I was in the OpenView days, I spent a lot of time running a combined process and technology implementations where you'd have ITIL consultants and, you know, the OpenView and the service desk, at the time it was Service Desk or Remedy, right, and we go in there and we'd give you incident management, change management, plug OpenView in, all that stuff, right. So I got my ITIL Foundation cert so long ago we had to fly somebody out from the Netherlands to do the testing because they weren't offering any testing in the US. Wow. So that was like '99, I think, or '98, so it was a while ago and I've I have gotten every penny worth out of that. I mean, I've really been working that, you know, and I've watched alongside as we have the pros in, right?

And I see what they're doing and it made a lot of sense. And one of the things that ITIL talks about is this whole concept of, you know, IT as a service provider. Yep. Right. What we kind of realized is we had been doing a really good job of answering the phones and in certain areas we'd done a pretty good job of being integrated a small part of the business, but we really weren't integrated into the rest of the business.

As a security guy, one of the challenges that we have in media and entertainment is very few of us are governance organizations. There's no little slot in the systems lifecycle where I can just, hey, here's where you call Steve and make sure he's okay with it before you move on. There's— I mean, we don't even have necessarily centralized procurement organizations all the time and all these different things. It's really hard to wrangle all the monkeys or whatever around security. What you have is the security organizations in the corner and they're doing the best that they can do with the ubiquitous infrastructure We've got firewalls, antivirus, and maybe DLP and whatnot, but there's all these side efforts going on.

At the same time, we wanted visibility into that, and at the same time, we wanted to help with that. Our CEO got in front of us, it was kind of good timing because he got in front of us in an all-hands and he said, we're going to really push originals.

We were talking about it, it's like, so how do we support that? The answer is not, well, let's get more networking and more storage. That's the easy answer, but it's like, how do we support that? That was part of what my organization was tasked to do. That's the solutions part.

That's that. How is it that you went about trying to enable that different framework, which I think is great? That's one of the things that I try and push to people is security, it shouldn't be about saying no, it shouldn't be about trying to prevent things, it should be about trying to enable the business to do what the business wants to do in a secure way. I'm 100% with you. That goes right along with what you're saying.

How is it that you guys went and put that into reality? It was interesting, and I have a fantastic team and they get all the credit for this, right? And I know some people have heard this story already, but so what I decided to do is we, you know, we couldn't cover— I have 5 people on the team, so I can't cover the whole business. I mean, even though we're small, there's so much going on in each of those areas. So we sort of carved out areas that were important to us that we thought were really key to that whole vision around let's produce more content You know, let's be more efficient, whatever, getting that, be better, serve our customers better, right?

So then what I did is we identified 5 areas because I have 5 people, and I went to each of the heads of each of those areas and I said, okay, hey Alex, I would like to introduce you to Steve Wostal. He is your IT guy, and I really would like you to have him at your staff meetings, and I would like you to involve him on your projects, and I would like you to task him with things. He is your IT guy. So wait, Steve, you're giving me another body that I get to manage? Yes.

Yeah, I love you, Steve. This is awesome. I wanted another person. No problem, Alex. Anytime.

I'll send you the bill. Yeah, but no, so I mean, and so we did that, right? And so then, and I explained our plan around that. I was very transparent, like, we want to be your enabler. We want to help.

And the reception was really good with that. At the same time, then I would take Alex, the person on my team, and I would pull Alex aside and I'd say, okay, Alex, go help these people. While you're doing it, you need to bring back to us how do they work, what technology are they using, what are the challenges, what are the risks that you're identifying there. I was also transparent. Transparent with the business, like, hey, this is Alex's— this is my evil half of why I'm having Alex engage with you, is that we want to learn more about you.

He's going to bring information about how you operate back to us, us being our IT group. We're called IT Services. That's part of our rebranding.

That's really worked well. We had an initial push on that, which was fantastic. We engaged out and We actually developed an architecture that's essentially like, this is how STARS works. We presented that to the IT services team. My team presented the whole thing.

It was great. We've got a lot better engagement in a lot of areas than we had before. I think a particular success that we've had is we had almost no engagement with the originals team. Yeah. I didn't even really know who to call over there, to be honest.

We've got a person embedded in there 100% right now. That's awesome. It's really good. What are some of the things that you've learned by having those people embedded in the different teams? Well, it's interesting because it's easy to go into an environment like that and say, hey, you know what, I want to help, just let me help.

It's a lot harder to manage the workload around helping. And there's so much going on and we want to be of assistance with everything and we're finding that we can't. Yep. And so then how do you manage that? So managing expectations around that, we've done okay.

I mean, we haven't had any complaints or anything, but it's always a challenge, right? And there's definitely a lot going on there. We've, we've, in terms of what we've learned, I think it's been an educational experience for our customers. I'm very fortunate in that the company is very security aware and they're very interested in security, so I don't have a lot of pushback on that front. And so we end up being able to extend all the things that we're paranoid about out to them and get a lot of traction.

So we have business owners coming back to us saying, hey, I want to do this differently. Hey, how do I segment this environment so it's not on the corporate network? I heard about that, you know, in some seminar. Like, yeah, okay, cool. So, so that's good.

Yeah, that's great. Have you— so you only have 5 guys, you're only in 5 areas. Have you seen any traction from areas that you are not in that maybe someone there said, hey, I heard that you've got this guy over in, in the Originals area that's helping you with all this stuff, how do I get one of those guys? Have you had anybody come back to you and say, hey, we'd really love to have one of your guys come over now that we've heard good things? Yeah, kind of, kind of.

Not quite that way, right? Because we haven't been like, hey, don't talk to Alex because he's the originals guy, right? And, um, while we went out the chute with this idea of Alex's originals and Steve's broadcast and whatever, uh, the reality is Alex has a specific skill set and Steve has a specific skill set. So in a way, those skill sets sort of apply and then you don't have a specific skill set. If the guy in original says, hey, single sign-on would be really useful for some of these cloud apps that we're using, he may not have the expertise to really execute on that.

Meanwhile, the single sign-on guy is the guy assigned over here to post-production or whatever. We found ourselves cross-pollinating a lot more than we originally thought we would, which is not a bad thing. It's a growth thing. Because of that, I think the company sees us more as a general resource than the originals and broadcast only. Yeah, so we don't have as much of that, like, I want that guy.

It's more people coming to us and saying, hey, I have a problem too, right? Can you help me with that? So have you— has this led to any discussions about increasing your staff or increasing more people to help in those other areas? Or so that you can, you know, you said obviously there's a backlog of things that you want, that these teams want to get done. Have you gotten to that point yet where it's, oh look, these guys are being really effective, we can be more effective if we had 1, 2, 5, 10 more people?

I mean, it's— I don't think there's any of us who's like, yeah, I could use more staff, right? The, the hard part is how to articulate that quantitatively, right? Yep. And so one of the things that I haven't done a good job of, that's, you know, this, this year is gonna be the back, the back-to-basics year for me. Okay.

One of the things that I need to do a better job of is capturing that workload in a way that I can articulate that and say, look, this is exactly where we're spending our time, exactly on what, right? We're, we're small enough that we've sort of been able to sort of not have to deal with project tracking and tickets and all that kind of stuff that we should really be doing. So once I can articulate that better, I would love to have that conversation. Yeah, yeah, yeah. So that's a great segue.

Into the stuff that you're looking to do this year. So back to basics, are there any, you know, besides trying to articulate everything that you guys have to do and how to essentially justify additional people to help do that, what are some other basics that you're trying to go back and look at this year? Yeah, so one of the things that actually popped something on the Slack channel today was this whole concept of like having risk register, right? So because of where we sit in life, we tend to be playing whack-a-mole with a lot of things with security, right? It's not anybody's fault, it's just kind of how it happens, right?

You know, I happen to be in the break room and hear like, what? Oh, wait a minute, you know, you're using Dropbox for, you know, highly sensitive stuff? Or, you know, we have this engine that if you drop content in the right place, it pops up online— whoops, sorry— pops up online and is automatically world viewable, and every once in a while the wrong thing goes into that engine and pops up, you know, out for the world to see, right? And just quick, take care of that. So there's all these, these, you know, um, opportunities that come up, right?

And how to capture that, you know, it's, it's the risk assessment and risk management 101, right? But it's kind of the stuff that's really easy to talk about, and then at least for me, at a little harder to execute on consistently. How do you grab that, track it, classify it, keep that updated, make sure you're managing it? I would love to have my executive team walk up to me and say, what are the 5 biggest risks that we have today? And be able to answer that with confidence.

Right? Yeah. I mean, I can come up with 5, no problem. But am I sure those are the 5? I'm not still 100% sure.

Right. So that's what that's all about. You know, we spent a lot of time in 2017 beefing up some core technology areas where we really wanted to have more capability. So we bought a lot of stuff this year. We'd like to really kind of roll that out and get some more traction around that.

So purposely kind of backed off a little bit from the new projects budget. We have some things, but a lot of it's gonna be around, you know, we've got cloud identity management, cloud identity provider capability now, so we wanna be able to leverage that. And we're already doing a lot of that. We'd like to do a lot more of that this year. Things around, we've improved our SIEM, we've improved some other hunting capabilities capabilities inside.

PAM. Yeah, so we just kind of want to just kind of get the most value out of it as we can before we start piling on new things. Nice. Yeah, those are some great ones.

So you have, you have this online over-the-top streaming service. I'd imagine that the folks that are developing that are, you know, sort of modern agile, maybe DevOps, quick to deploy kind of resources the way that they're doing this. Is that something that you guys are having to wrestle a lot with, trying to fit what you guys are doing into sort of a newer, faster model of IT in general? I heard some others mention SecDevOps, and that's definitely something I'd like to tackle this year. There's a lot of technology around that, but then there's, I think, some basics that are not even— there's some process basics around that, right?

Yeah. The team that develops the app and the online presence is fantastic, and they have really executed. The challenge for us is how do we get in there and help them with security. They're actually really good, so I don't spend a lot of cycles worrying about it, but at the same time, I'm sure there's there's opportunities, how do we get into that without interrupting that flow? I feel like, I think this is true of all the SecDevOps movement, but the idea is help them with their own tools.

Give them capabilities that they can use that just flow right in with the process of continuous integration, continuous build, and all that stuff. That totally goes back to the whole me, enabler conversation, right? It's like you want to help enable the business to be better, to move faster. A lot of times, the way that we do security in a development way is gates and more things that they have to do, and that's completely the opposite of making things go faster. Not to say that we don't want to accomplish those same things in the DevOps, DevSecOps kind of world, but just saying, oh, well, you need to do security and dropping security into what they're doing, that's going to blow a lot of stuff up.

That's our bread and butter right now. That's really hot for us. There's so much tension around that app and it'll just keep getting better, not just even for the over-the-top, but we had that app out for years prior to— as a customer. Let's say if you were a Comcast customer, you could pull up the app. And be entitled, right?

And yeah, that's really key. And it's funny because you mentioned something earlier I wanted to hit on. You talked about like you can't say no. And it's funny because I've had folks on my team that were brought up as security people their whole life, right? Yep.

And that was a hard pill for them to swallow a little bit, right? Like, I can't believe you're okay with this. It's like, well, you gotta understand it, right? The business is not trying to be malicious. They're trying to get something done.

And in today's day and age especially, right, if you're the guy with a no sign, you're just gonna— everybody just walks right around you and goes and pulls their credit card out and does it themselves, right? I mean, more than ever, you really don't have a no. You can't. So it's not no, it's like, how do I— you said it, right? How do I help you do this securely?

Yep. That's the message. Yeah. And, you know, from my perspective, You know, there are times when, you know, if someone is trying to do something that is blatantly stupid, right, you have to say no, right? Hey, we want to make, you know, our customer database with all the information, you know, publicly available on the internet because it's easier for X.

All right. Okay. Timeout. That's a no. You can't do that.

But if it's, hey, we want to develop some new capability to to share our customer information with partners, you're like, okay, some people might say, well, no, we can't make that available. It's going to increase our attack surface so much, and so on and so forth. The way I would look at it is, okay, well, this is a business requirement. I'm sure that we can talk about the business goal that this is going to help us meet. Okay, well, we got to do that then.

We got to figure out how it is that we can get these guys to do this in a way that satisfies what they want to do and satisfies what we want to do. Yep. Yeah, I agree totally. And you said it, right? You kind of whittle that down to, you know, like, what are you trying to accomplish?

And let's make sure you can accomplish that, right? And I've had a few of those pop up. They haven't been too bad. And you can very quickly defuse those with like, here's the risk. Yeah, exactly right.

And I'm not here to tell you no. I'm not telling you no. But I just want to say I want to do differently because here's the risk. And I've really not ever head. I'm like, well, no, we're totally okay with that.

One interesting topic too is I went to a— that's kind of changed my perspective on those conversations. We took the Gartner Security Risk Summit a few years ago. There was a presenter from one of the utility companies out on the West Coast, and he talked about coming into the organization as like the 20th CISO, like the other 19 of them or whatever had failed utterly, right? And they'd had breaches and they, you know, and so he comes in and he's like, okay, how am I going to be any different than the other guys, right? And so one of the things that he— his presentation was all around, and this theme is common now, but at the time it was the first I'd heard this.

He said, you know, the CISO can't really own the risk. Anymore. Yep. And so he went in and he convinced the executive team and the board, like, my job is to consult to the business and to help them mitigate their risks, but they own the risk and they— it's their job to present the risk to you, the board, and the executive team, which is big. That's a big political win, I think.

But it makes sense, right? Because when the business owns the risk, they're aware of it and it's there. They're not like— the situation I don't want to have at SARS is like, I can do whatever I want. If I don't hear from Steve, then it must be okay. Right.

Right. So I think that's another one of my evil plans at SARS is to try to foster a little more of that culture. So those are kind of how I have the conversation. Here's the risk that you are accepting by putting all these credit card numbers numbers out on the internet with no security rate or whatever. Yeah, and I mean, in business, everything really boils down to risk-reward, right?

So your job is to make money, and if doing something can make you $1 billion, but the security risk that comes with that is $1 million, every day you're going to go, totally, I'll take that security risk all day long. Right. If you can make $1 billion, but the security risk is $2 billion, okay, well, let's figure something out so that we can actually end up making money instead of in the long run losing it.

That's how we've steered a lot of the discussions. When we're in that mode of like, okay, I'm across the table from the business and they're like, we got to do it this way. You got a risk. At some point, I get to like, do you understand the risk? Yeah.

Are you okay with that? Yeah. Okay, you know, if this backfires and, you know, XYZ events happen, you know, how is that gonna affect you? Oh, it's gonna be a big effect to you. Okay.

Well, let's make sure that XYZ events are minimized. Yeah, great. Sounds good. Yep. So we're getting close to our time here, Steve.

Is there anything that you wanted to cover or any sort of final thoughts you wanted to talk about before we wrap up? Um, you know, the other initial One initiative that we have for this year is, and this may resonate with some folks, but given that I think ever since the 2008 crisis and everything, we've all kind of had to deal with doing more with less. I've been asking my team to focus on automation.

We don't have a security ops team, really. The good news is the entire IT organization supports security, so it's not like Steve is getting in there making firewall rule changes or chasing down a virus necessarily every time, but we do jump in and help with those. If there's a minor incident, we're in there. I've asked the guys to focus on, okay, let's take a look at things that we do that are repeatable. And let's automate those.

We have all the tools, right? I mean, if you go over to the DevOps world, they're all there. All the tools are right there for us to use and let's go use those, right? So, I mean, there's even simple things like if we get a report from a user like, hey, I think this might be a phishing email. There's all sorts of manual things we do today.

It's like, why are we doing that? Why aren't we collecting that? I mean, that's like a 10-minute job once or twice a day. Yep, exactly. I feel exactly the same way, and we're feeling that pain around phishing as well.

One of the things that we've looked at a little bit is LogRhythm released a tool last year called the Phishing Intelligence Engine or something. They built it themselves for their own work. It obviously works with LogRhythm.

Also with Office 365, but it automates a lot of that stuff. They made the tool freely available if it works for your environment or you can modify it or whatever, but it's that same idea. It's trying to take all this manual work out of what people are doing on their everyday workloads. Yeah, I mean, it just frees you up for higher functions, right? I know for every phishing email, I'm going to have to look up what the actual sending email server is.

Does it match what the actual email that it's coming from is? Who owns this IP? All these little things that you have to do. Are the links in there malicious? Stuff that's fairly easy to automate.

Then on the second process, there's the whole communication process. Someone reports it, maybe you have to ask them them a question, or maybe you have to pull some data based on that. Maybe you— and then you have to obviously contact them back. And then is it, you know, do I ask them to delete the email? Do I, you know, whatever?

And, you know, this automates some of that too, is, okay, we've decided this is malicious. It can actually automatically go out and delete the messages from, you know, from their inbox and anyone else that received that message too. And it's like, that's such a, you know, a scaling prospect right there to reduce that overhead? Yeah, well, I mean, my peer is the DevOps manager, so we all report through the same chain and I hear about all the automation that they've got going on on their side of the world and it's interesting how that's kind of burned into their mentality. If I have to do something more than 3 times, like, oh gosh, I should automate this probably.

Meanwhile, over here, we're back, I'm still doing everything you just talked about or having somebody else do it over and over and over. There's a lot of tools that can support that. I didn't know about the LogRhythm tool. Obviously, if you have a workflow management ticketing system, any of those can help with that. All these security orchestration automation tools that are coming into existence, that's part of their allure.

Obviously, some of these things are pretty easy script building blocks too, right? So pulling out an IP address and looking up information about it, not super hard to do, and I could see where it would be fairly easy to— if you get your workflow down about how it is that you're going to do this, to pull those out. That's part of it for me too, is I think a lot of times we do this stuff by rote, but we don't actually have the process that we follow even documented. Maybe you have something that says, oh, when we get a phishing email from a customer, We investigate, we open a ticket, and then we do whatever based on what we find. Okay, well, what's that investigate piece?

What's the standard that you do there? Getting people to document those everyday processes is sort of the start of it, but something I think we overlook a lot too. Because we're not documenting it, we're probably not doing it consistently. This guy investigates differently than than that guy does. Right, so, and then, you know, kind of goes back to, we personally haven't been doing the best job tracking all that information, right?

So that may not be something we're doing well. So if you were to ask me how many of those did I get last year, I'd have to kind of probably sift around through email and a bunch of things to kind of pull that. So I think having all that bundled in automation, it's just like anything else, right? The more you do that, then the more you kind of build a culture around doing that, and then the more you start seeing opportunities to continue to do that. That's my hope, at least.

So yeah, for sure. Well, cool. Thanks, Steve. It's been a great conversation. Appreciate you being on the show.

We'll have to loop back around, you know, maybe in a year or so, figure out how all these initiatives went. And, and thanks for being here. It was great. Thank you very much. So this has been Colorado Equals Security, and we'll talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes