Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 88 for the week of October 15th. Alex, winter is here.
It's snowing. It sure was snowing, although not right now unless something just changed. Depends on when they're listening to this. That's true. Or where.
Yeah, it definitely is still snowing if you're in the mountains. It's very snowy-ish right now. Anyway, the point is, winter is coming. Yes, winter is coming. Watch out for ice dragons.
Speaking of things, we have some housekeeping to do here. Number one, we have a Slack channel, and Alex, this week we surpassed 600 guests. That is awesome. I can't believe how many people are in there. It's great.
Always a good discussion. Just about every day there's a good discussion happening in the Slack channel, so check it out. We also have a mailing list, so if you go to colorado-security.com, you can go out and subscribe to get the show notes delivered into your inbox every week. That's all we do with it. Unlike things like Google+ and Facebook, we do not sell the API to our list to anybody.
That's true. Very true. Also, please, please, if you like the show, subscribe to the show so that you get it automatically downloaded into your favorite podcast player. And then also, please rate us on the services where you subscribe. We would love to have a good rating on those services to help us attract more listeners.
Speaking of attracting more listeners, if you like us, we would love it if you would tell a friend to get them to, to come listen to us as well. If you have somebody at work who you think might be interested in hearing the news we do, tell them to come listen to us. And finally, if you really, really like us and you want to support the podcast monetarily, we would love it if you joined our Patreon campaign. Feel free to donate at that campaign and help us cover the costs for the show. If you sign up at the $10 a month or greater level, you will get a shout out on this show and also a free t-shirt.
And any amount of money you want to give would be fantastic. But speaking of Patreon, we actually have a new patron this week. And thanks a lot, Dan Collander. Dan is the CISO over at Ball Aerospace and a friend of ours on the show. Dan, we appreciate it.
Thanks for your support. Yeah, thanks, Dan. Really appreciate it. So let's jump into the news. First, Denver is not getting a 5G network anytime soon.
Do you want to know why, Robb? I would like to know why. Well, the reason why is with 4G, the wavelength, it was easy to put up a few cell towers and get good coverage. With 5G, you have to put up a whole bunch of smaller antennas to be able to get good coverage. So that takes a long time.
Yes, thousands of antennas around town basically to make this happen. When I first read the headline, I thought there was going to be like a big reason, like, you know, the city says, hell no, we won't go or whatever, but nothing like that. It's just going to take time. At this altitude, those wavelengths just don't work, Robb.
So it also sounded like maybe there is some some political problems in there, you know, making sure you get the permits and that kind of thing with all of the little antennas everywhere. So we may not have 5G, but we do have a lot of venture capital here in Colorado. We sure do. See that segue? Wow, you are professional.
In Q3 2018, the venture capital projections for this year are on track to beat the 2015 record. So we are through 3 quarters, we've already raised about $1.3 billion in venture capital here in Colorado. The record back in 2015 was $3. $3.6. So with another quarter to go, uh, we, you know, we should blow right past that.
They also show the number of deals, and it looks like the, the actual number of deals is pretty constant. So we're just talking about some bigger deals this year, which is a good thing also. Yeah, it's, it is interesting. I've seen this a lot in security where your A round used to be a few million dollars and your B round would be like $10 million and your, your C might be $20 or $30. The numbers have just gone, you know, way bigger.
Your A might be $10 million and you're seeing you know, Bs at like $30 to $50 million. And those Cs will be up in like, you know, over $100 million sometimes. Really big numbers. For sure. And also, as part of this investment, there's been a lot of venture capital money going into fintech, which could make the Rocky Mountain region and Denver a hub for financial innovation.
Yeah. And that was an even better segue. Thank you. Well done, Alex. So the next story is about how we do see fintech as being really one of the specialties here in town.
Obviously, over the years, telecom, telecommunications and oil and gas have been the main drivers and call Colorado's industry. Security is obviously the number one today, obviously, but they think of fintech as maybe being the future here in Colorado. Yeah. And there have been a couple of stories we've talked about recently that are in that area.
KPMG is doing their innovation accelerator thing, right? And also Western Union is doing another accelerator payment ones that they're doing with Techstars. Yeah. Some good stuff. Yeah.
That sort of thing. So. It seems like a lot of fintech stuff going on around town. And it looked like Boulder actually had more, had more venture funding than Denver did. A little bit surprising.
So Boulder's had a lot of venture funding around fintech specifically. Yeah, pretty cool. Next, AngelMD, which is a startup from Seattle, is moving its headquarters from Seattle to Denver. It's speaking of financial tech technology companies. This is a fintech platform for medical startups.
So interestingly enough, you know, they got the message. Yeah. And they're moving to somewhere up— there's, there's this kind of communal building up there where a bunch of startup health companies are working together. It sounded like near Brighton Boulevard and I-70-ish, sort of north end of RiNo. Speaking of Colorado companies, SendGrid has been ranked among the happiest companies in the country according to Comparably.
Yeah. So they— that list had 2 components. One was large companies and one was small companies. I think the 500 was the cutoff. Between the two of those, SendGrid being in the smaller side of that.
They actually, for the overall rankings, were number 2, but— and let me catch my breath here— they were number 1 for best company happiness, as we said, best company perks and benefits, best company compensation, best CEOs for women, best CEOs for diversity, best company leadership, best company managers, and best company for professional development. That's a pretty good list. Well, well done to SendGrid. So this is survey was done based on feedback from employees of the company. So this is coming from SendGrid's own employees.
They seem to like where they work. Yeah, pretty cool. Congrats to them. Good for those guys. Webroot this week released a story about— it's really a mid-year update to their threat report.
But in this update, crypto mining has dethroned ransomware as the top threat. So all I have to say is thank goodness for crypto mining, because now I don't have to worry about ransomware anymore. That's exactly how it works. Yes. Because this new threat totally eliminated the old one.
Exactly. Yeah. Whoo! They do. There was quite a few interesting things in this report.
I recommend taking a look at the press release that we have in the show notes to see it. Some stuff that's obvious, what we just mentioned about the shift from ransomware to crypto mining. And of course, a lot of this is happening from cryptojacking, where you have folks who are, you know, kind of taking over your browser when you go to a website. But some, some stuff you might not have expected was around Windows 10 adoption. They said about 75% of consumers are on Windows 10, only 40% of businesses.
Kind of interesting stat. There are also some ones that you would expect, like ransomware attacks exploit unsecured RDP to find the most vulnerable systems. We've talked about that several times in the past, right? Yeah. Phishing attempts skyrocketing.
And what it was, another interesting fact on here is that Dropbox is now the primary target for phishing attacks. Interesting. Dropbox over, you know, Gmail or Microsoft. That's surprising to me. That is a little surprising to me.
I still tend to see websites being spun up random places that are, you know, sort of phishing kits and things like that. So anyway, but that's some good information there. Next, we had a blog from Ping Identity, 3 Common but Risky Authentication Practices to Avoid. Yeah, so the first one I think we're all in agreement on is password-only authentication. You know, obviously at this point, password reuse and the the prevalence of data breaches out there, it's just so easy to compromise a password.
And phishing attacks is another way we do it, right? The second one, I think, you know, we mostly agree with, right? That he talks about using SMS and email for your second factor, for your MFA. You know, we know that there's vulnerabilities with SMS. And of course, you know, I hardly even think of email as a second factor, to be honest.
You know, if I got your password, I probably got your email too. Right. And there's, so there's risk. Of course, either of these is still better than nothing for a second factor. Yeah.
Going back to the first one, right? You don't wanna be password only. Right. If your only option is SMS or email sort of second factor, yes, still probably a good thing even though not the best thing. Yeah.
Uh, and then the third one, I think we, we both are kind of looking at askance, which is, um, you know, password vaulting. And there, there really, the article's talking about there's quite a bit of risk with password vaulting and having all your passwords in one place. Yeah. And I, I think in a perfect world, um, password vaulting should never happen because you shouldn't need, uh, to remember the password. There should be other ways to do it, whether it's, um, you know, some biometric or some something, you know, MFA, things like that.
Uh, but we are not in a perfect world and there are people with many different passwords and they need to remember them. And I would much rather them have them in a password vault, um, than, you know, all the same password or kept on an Excel file in their email or, you know, whatever, that a secure password vault is going to be better than many options in today's world. And I can speak a little bit from the perspective of the author, as I know, you know, Ping's perspective is you'd much rather see federation where you have a single sign-on, which is, you know, which you have one password you remember that gets you into everything. Unfortunately, you know, we just don't live in this world where federation works everywhere. You know, we don't— we can't get single sign-on into those random places where frankly, It just costs more effort to set it up than it saves in time and risk to have it there.
Or cost. Yeah. And I think the point here is, you know, the name of the headline of the article is Risky Behaviors in Authentication. Yeah, there's risk to password vaults. It's a risk that you should consider and you should decide, is it right for you or is it not?
I use a password vault. Is the risk of a password vault more than the risk of not using a password vault in certain cases? So, yep. Next. Optiv had a blog this week, 3 key ways to improve your incident response.
They were plan, automate. It's a good idea to plan for incidents. Automate is the second one. Automate getting breached. Exactly.
Automate, just open firewall rules automatically to let in 3389 for RDP. All you have to do is expose RDP. Automate that right away. And the third is to orchestrate. So Alex, uh, put you on the spot here.
What's the difference between automating and orchestrating in this context? Ah, you know, it's a good question, Robb. I sort of feel like orchestrating is like multiple automations. Okay. So hey, I can automate one thing.
Orchestrate is, you know, doing a whole bunch of those automated things together. But so I'm not sure there's still that much difference between the two of them. So, so as we look at what they're saying, and of course they're right, you know, yeah, you have to plan for incident response. Make sure you have a plan and of course test that plan. I think that's a critical part of it.
Automate your response. So it's not just, hey, Alex has done this before, we know we can do it again, but Alex is gonna go launch these scripts that are gonna do these complex technical things more quickly for us. Right. And then finally, the orchestration part, I guess, you know, making them work together versus kind of manually asking multiple scripts to go. That part I'm a little fuzzy on.
Yeah. But I mean, I think the bottom line here is put some effort into incident response. Yeah, that's fair. That's fair enough. Continually put effort into incident response.
Our next blog is from Red Canary, and it's really them celebrating 1 year since the Atomic Red Team launched. This has been something we've talked about on the show, I don't know, a dozen times, and it's really been a cool thing that they're working on, giving back to the community and making it, you know, just as a summary, the idea is you come up with discrete ways, you know, atomic meaning, you know, broken down to the smallest component, discrete ways that you can test the individual parts of your security program. Yep. And we had Casey Smith on the show, uh, I don't know, 6, 8 months ago talking about it. He's one of the creators of that framework, uh, and the article is good if you haven't gone back to look at the, the red team framework yet.
This article is a good summary of the history and things that they have done and where they are today. So, uh, sort of a good background. And the article does point out that they have some sweet swag now. And if you don't have an Atomic Red Team shirt, number one, it's an awesome logo. Number two, they have these super high quality shirts.
If you listen to the podcast a couple weeks ago with Brian Bear talking around the fire with Robb, you know that they make quality swag. It's not just junk. It's gear. It's not swag. It's gear.
He looks at his gear. Yes. Yeah. So anyway, congratulations on a year for the Atomic Red Team. Good stuff and keep it going.
Finally, Coalfire had a blog this week about what you need to know from the North American PCI community meetings. So there was obviously, basically this is like a meeting report, what happened at that meeting. Some interesting stuff. They talked about PCI DSS in the cloud and really how do you navigate PCI in this reduced visibility that you have in the cloud? And of course the cloud can mean many things.
If you're in an infrastructure as a service, maybe you don't have reduced visibility, but if you're in a SaaS platform, you definitely do have reduced visibility. So you have to figure that out and how do you get assurance from vendors? That was one big topic there. The next one was the State of the PCI Standards Security Council. So the interesting piece there.
Third, Women in PCI and Cybersecurity, talking about a little bit about diversity and how diverse teams are good. They were talking about how innovation is changing payments and security. Obviously, there are lots of changes coming. We already talked about the Western Union innovation investment where they're trying to, to really accelerate payment changes, and this is going to impact PCI DSS. I think, yes, it'll impact it in the fact that, you know, maybe people will start using the— stop using the card brands and do it outside of them.
So who knows when PCI will go away, right? They're not a huge fan of that. Yeah. And finally, proliferation of point-to-point encryption, which is a good thing. Yeah.
So interesting blog. If you guys have any interest in PCI, you might want to read this and probably reach out to Coalfire for any questions you have there. Yeah, that blog was written by Dan Fritchie over at Coalfire, who's a former colleague of mine. So Good job, Dan. All right, Dan.
So that is it for news. Moving over to the Slack Message of the Week. Slack Message of the Week. Andre Gaeta, we appreciate you sponsoring this. Thanks so much for doing this.
We would not get to have this segment of the show without you. And of course, this every week when we recognize someone who posted either a good conversation starter or an insightful comment on the Slack channel, it's to drive more content there. So this week, the Message of the Week was by Eric Halverson. Congrats, Eric. So he started a conversation about the Bloomberg chip, you know, China hack that may or may not have happened.
And it may or may not have involved Apple and Amazon and anybody else. But his point was, he was asking if this story actually hurts security and security awareness as opposed to help it. Yeah. And I think what his point is, you know, this story gets on the front page of CNN or wherever. And it says basically, you know, China has infiltrated every part of our cyber systems.
And then a few weeks later, people have to walk it back. Have we done harm to the importance of security in the long run? Right. Are people going to think, oh, all these security stories, they're just made up. This stuff isn't really happening, kind of deal.
My take actually kind of went the other way where I thought this conversation might, you know, it just brings more light to the supply chain risk and the fact that, you know, even though it looks like this story is BS, it is possible, right? What they reported on is not, you know, some, you know, unicorn. It's a possible thing that could happen. And we should be thinking about that kind of a risk. Yep, for sure.
So, Eric, congratulations. You'll get to pick something from the Colorado Equal Security store. And once again, thanks to Andre for sponsoring. So let's move over to our event calendar. As you all know, or if you don't know, now you know there's an event calendar on the website.
So go check that out at colorado-security.com. We have a consolidated list of all of the security happenings for around town. We do have 2 events on here that are brand new, and they're just coming up in the next day or so. So on the 16th of October, the Cloud Security Alliance Denver has their October chapter meeting. And also on the 16th, the ISSA Colorado Springs chapter has a Women in Security special interest group.
So if you want to get together either in Denver for the cloud security or in the Springs at for for the Women in Security event, make sure you're on top of the ball because it's just coming up here on the 16th. On the 17th, you got a little bit more time. CTA is doing their CTA 101. And that's over lunch. If you have even a little bit more time that evening, the DENSEC group is getting together at the WinCoop on the 17th.
Nice. SecureSet is doing their Cybersecurity Career Convos with Elaine Marino. On the 18th. On the 19th is the Global Blockchain Summit in Golden. Nice.
On the 23rd, the GDPR meetup is happening. Data Privacy by Design: Securing Your Employees, Customers, and Service Providers. So the 24th is one of these days where all of the stars have aligned and we just have this, this massive number of meetings. First, the Ada Lovelace Day celebration is happening in Denver. This is a women in STEM meeting.
Very cool stuff. If you want to learn about Ada Lovelace, this is your chance to do so. SecureSet is also doing a capture the flag on the 24th. ISSA Colorado Springs is doing a mentorship program meeting. And the ISC² Pikes Peak chapter down in Colorado Springs is doing their October chapter meeting on the 24th.
On the 25th, ISACA is doing their October meeting around internal audit innovation. And that's actually a joint meeting with the IIA. Nice. On the 26th, Colorado Springs Cybersecurity is doing their Cybersecurity for Small Business Summit. And finally, on the 27th, Colorado Springs ISSA is doing their mini seminar.
That's that 8 o'clock to noon Saturday morning event. Good way to go learn and get some free CPEs if you need it. So lots of events coming up in the next couple weeks. Let's move over to jobs. First, we have the cloud security architect job with Ping.
That's working with me over there. I'd love to hear from you if you are an AWS security guru through, send me a note. Spry Squared is looking for a Vice President of Information Security. The American Cybersecurity Management Company is looking to hire a CISO, and, and this CISO position is actually— it's not doing CISO work for inside the company, it's helping their customers. So this is a consulting firm looking to have folks who will do that kind of CISO as a service for customers of theirs.
Yeah, it also looked like they were hiring a few other positions, including a DPO. So if you are into privacy and want to be a privacy officer, you could work there as well. CenturyLink is looking for a senior information security engineer. Overwatch ID is hiring a security engineer. Alex, do you know anything about this?
What is this person working for, internal to Overwatch ID or helping customers? I think it's a little bit of both. There is some customer-facing work there. Okay. MedKeeper is hiring an information security engineer.
EverCommerce is hiring a security engineer. Lots of security engineers this week. The US Department of the Interior is hiring an IT specialist in InfoSec. The state of Colorado is hiring a data privacy and security trainer for information management services. Yeah, cool.
Yeah. So it looks like you get to develop and, and do the program for training at the state. That's awesome. And then another education opportunity. Circadence is looking for a cybersecurity curriculum developer, and this is a remote opportunity.
Fantastic. Well, that takes us to the end of the news. Next, we have our feature interview with Dr. Charles Lively. Charles is the head of the IT and security programs for CSU Global Campus. I sat down with him recently, talked about what's their IT program look like and specifically what does their security program look like and where they go on in the future.
Very good. Go Rams. Go Rams. All right. Well, that's it.
We'll talk to you soon, Alex. Thanks, Robb. All right. Hi, this is Debbi Blyth. I'm the CISO for the state of Colorado.
Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is— today this is Rob Recht sitting with Charles Lively. Charles, you are the program chair for CSU Global's IT and computer science degree program, is that right? That is right.
Did I get that right? So I'm looking forward to talking about specifically within that program what you guys do for security. Security, the offerings you have there and what that program looks like, where you see it going, and I want to dive into that. But first, I want to talk a little bit about your background and personally what you've been up to. You mentioned something really interesting that you've done.
I'd love to know about your career in gymnastics. Talk to me about how did you get into gymnastics and where did that lead you? Interesting little intro. I started off gymnastics when I was about 7 or 8. Yeah.
Competed up to Class 2, which is kind of about 2 levels before Olympic level. Competed up until high school, and once I got to high school, I started coaching and just working out recreationally. Every now and again, I'll still go and, you know, work out and do a little tumbling or whatnot. Been a part of my life for about 25 years. So when we talk about, uh, just, you know, kind of a lot of us only see gymnastics in the Olympics, right?
Yeah. Um, and so you— excuse my ignorance, there's a lot of things that I don't know, but we talk the different events that one might do, uh, you know, rings and parallel bars and what are they, the non-parallel bars, uneven bars, right? Yeah. So do you do all those things or is it some subset of these Yeah, so women have 4 events, which is— you mentioned vault, uneven bars, beam, and floor. Men have 6 events, which are floor exercise, ring vault, rings vault, pommel horse, as well as steel rings and high bar.
Okay, and so you do all 6 of those then? Yeah, I did all 6. Um, now when I work out, I normally will just focus on, you know, Keeping in shape doing rings or a little bit of high bar and floor. So could you do that thing where you hold the 2 rings out to the side and like keep yourself flat? Yeah.
That's amazing. For those listening, I have my arms straight to the side, you know, like the— so you're wearing a coat so I can't tell how ripped you are, but you've got to be pretty ripped to be able to do that. Not really because I don't work out every day anymore, but— All right. Well, that's great. I love to get the background, so thanks for sharing that.
But now let's talk about the other stuff you've trained in, right, and technology And how did you get an interest in technology? And how is that— start at the beginning. How'd you get interested? Um, I've always been interested in technology. Um, I was the, the kid that, you know, asked for the chemistry set for Christmas.
Um, and so I think I, I got my first computer when I was in 6th or 7th grade, and I've been addicted to technology since since then. I got my bachelor's and master's and PhD in computer engineering. My bachelor's was from Mercer University and my master's and PhD were from Texas A&M University. That's great. And throughout my college studies, I was a Gates Millennium Scholar, so that afforded me the opportunity to attend college without worrying about any finances or anything.
So what is it— what did it take to qualify for that? So actually, when I was awarded it, I was an inaugural scholar. So in 2000, when the Bill and Melinda Gates Foundation started the program, it was, it was, you know, essay, you know, transcripts, recommendations. A real process. And I think it was— it took about— I didn't find out until maybe about 2 months before I was leaving to go to start my freshman year at Mercer University.
Yeah. And so— but it was an excellent network of scholars, afforded me the opportunity to not have to worry about my education financially for 10 years. They paid for a master's and partway through my PhD. I, I guess I exhausted them. So you say you, you outspent Bill Gates' fortune?
Is that what you're telling me? Not quite that. Yeah, no, I don't think so. Did you get to meet Bill or Melinda Gates as a part of that? No, no, I didn't.
Yeah, okay. Maybe in the future though. Yeah, I hope so. Pretty cool. They've done some pretty cool stuff.
Oh yeah. Um, so when you did your master's and you did your, your PhD I assume you had a big project, a thesis and dissertation. Can you talk about what you studied for those? Sure. So for my research area was performance modeling and performance optimization on multi-core and distributed systems.
So you would think about supercomputing platforms that are normally at national labs. A Cray machine? Yep, Cray machines. Um, I interned at 2 of our national labs here, Oak Ridge National Lab as well as Lawrence Livermore National Lab in Livermore, California. And so in my research work, I focused on optimizing energy consumption and power— energy consumption, power consumption, and performance of applications.
And normally they were simulation codes, so You would think about the big weather simulation applications that require hundreds of thousands of processors in order to complete the simulation in a timely manner. And so you have all of these different factors that come into play. Is the code structured efficiently?
Data requirements for it, requirements for the systems that it's being executed on. And so in my work, I analyzed all of those factors to determine an efficient way to reduce how fast the application would execute. Interesting. So you helped optimize how to use these supercomputers. Was that your dissertation or thesis or both?
It kind of built on itself? For a master's, I started out just focusing on optimizing performance. Then as I progressed to my PhD, energy consumption and power consumption consumption became a big factor. You know, with big data centers and supercomputing centers, you have to keep the— it requires a lot of electricity to keep everything going and then keeping the systems cool so that they don't overheat and shorten the lifespan. So that was kind of the progression from just focusing on execution time or memory and including how can we predict how to reduce the energy consumption of it.
That's great. Did any— is anyone using the research you did? Um, so I had actually about 6 to 8 publications. I do get a lot of citations from other people that have built on my work as well. My advisor, she did continue the research with some of her students as well at Texas A&M.
So it looks like at least it's being referenced and improved upon. That's great. That's really cool. Good for you. So one other thing I see from your LinkedIn is you're also the Chief Technology Officer for a company called DROFICA.
DROFICA. DROFICA, excuse me. Can you talk about that? Yeah, so we are— DROFICA is a decentralized data center. So we're working on building new computing network, a fog computing platform essentially.
So it's taking the cloud to the next level in that we have to take into consideration various factors, the virtualization of resources, efficiently managing distributed computing environments, as well as security. So those are some factors that we are considering. Are you guys still in, yeah, in build phase right now, or do you guys actually have a— Still in build, early startup. Very cool. When do you expect to have a product to go sell?
Hopefully within the next 6 months to a year. Great. Of course, and then let's get into what you're actually— what we're here to mostly talk about, which is your role leading the IT and computer science program for CSU Global. Talk to me about, number one, how did you even get plugged in with this group? Well, I started teaching, um, programming and software development as I was finishing my PhD at Texas A&M.
So I started at a small, um, college, Blinn College, and then I started teaching online and doing consulting. And I, I started— I was— I saw an advertisement for just a adjunct faculty for CSU Global. And from there, the ball just kind of progressed. I was hired. I went from being an adjunct faculty to being a program coordinator for their computer science program, and then towards being a program chair for IT and computer science as well.
So I've been with CSU Global since 2015. Yeah, and how have you seen the, the whole school and really, of course, the IT program change over the last few years? Oh yeah, it's been a lot of changes. Specifically in IT, we've updated our courses and our core requirements. We're looking at becoming ABET accredited, and so that required some— What's the accreditation?
It's ABET, which is the Accreditation Board for Engineering and Technology. Okay. It's considered one of the top accrediting bodies. And what does that get for you as you get that accreditation? It gets you basically notoriety from industry leaders and most of the top technology and engineering schools you want when you think of Georgia Tech, MIT, those are all that accredited programs.
Yeah. So that's kind of, um, for any IT program, it's considered a gold standard. IT and engineering. Sure. And computer science.
And what kind of work is it going to take you guys to get that accreditation? Uh, just, uh, we're, we're making sure we meet those requirements. Um, they have specific requirements for science and technology, like, like the content of the courses or the, the the certifications of the instructors, or what is it that, uh, it's a combination of both? Okay, the content of the courses as well as credentials of our faculty. Yeah, need to be in alignment with that.
Okay, and time frame on when you guys might be able to achieve that? Well, it is, uh, it's a long process, so, uh, obtaining ABET accreditation could be 18 to 24 months. So it's not too long. I mean, that's achievable, right? And are you getting started now, or are you into that process?
We're starting, starting the process now. Okay, so the next couple of years getting a major accreditation will hopefully draw in more, more students, I assume, and also help them have better outcomes, right? Finding better jobs and, and, and make it easier for them to, to turn this education into something for their careers. Is that really the goal here? Right.
Yeah, awesome. I should have asked one other question before we got into the details here. Maybe you could help with any confusion about what is CSU Global. What is the difference between CSU Global and CSU or any other schools? Well, CSU Global, you can consider it as kind of a sister campus to CSU.
We're the online campus. We only offer online programs, and our programs and degrees are completely different and accredited. Differently from CSU. So we're online nonprofit state, Colorado State System school. But it's still, you know, lower tuition for Colorado residents.
It is a part of the CSU program system, right? Even though it's not actually a physical campus. We're kind of just a sister campus. So I know CSU's President Tony Frank recently just stepped down. Was he your guys' president as well?
Is there impact to his stepping down for you guys? No, he was not our president. You guys are still around? Yeah. All right, cool.
All right, so let's dive back into your program a little bit. Obviously, I'm especially interested in hearing about what you guys are doing around security, cybersecurity within your program. Talk to me about what kind of offerings you guys have there. Okay, yeah, definitely. So for our program, for— we have a bachelor's in information technology as well as a master's in information technology management.
In each of the programs, we offer cybersecurity certificates as well as a specialization. So our cybersecurity certificate for our bachelor's degree is a 6-course sequence focusing on networking, security security, ethical hacking, and digital forensics. And also, that's a 6-course sequence, and it's aligned with 7 of the 8 CISSP domains. And what we do with the courses to ensure that they stay up to date is every year we have a program, or every 2 years or 18 months, we have a program review, and those courses, they get reviewed and updated to make sure that they're in accordance with the latest guidelines and standards. Yeah.
So would you mind telling me what the 6 classes are? I know you mentioned the topics, but what are the 6 courses? Yeah, so we have Introduction to Networking is one of them, Computer Security, Digital Forensics, Ethical Hacking, and There is one more. That's okay. Um, sorry to put you on the spot with those.
Um, and you mentioned that there's a certification and specialization. Is that hand— is that the same thing, or are there 2 different— well, different things? Specialization is a 5-course sequence. Okay. Um, a certification is basically, um, eligible for financial aid.
So if a student wants to attend CSU Global but not seek a degree, they can do our certification. Yeah. And still it can be used, financial aid can be used to fund that. Yeah. But a specialization, most students will take that if they, they're already enrolled as a degree-seeking student.
So is the certification instead of a bachelor degree, or it's in addition to? Uh, it can go either way. Okay. So if someone does not have their bachelor's and they just want to do a certification, they could just do that. Yeah.
And a lot of times what we see is that students will start with the certification and then decide, okay, let's add the rest of the courses. Those courses transfer over into our degree program. So those, those 6 courses you're talking about, is that— was on the bachelor's side, or is that on the master's side, or is it— are they the same class? So the bachelor's is 6 courses, a master's certification is 4 courses. And is that the the same types of courses, same stuff?
It is the same type of courses, but since it's master level, it's at a higher cognitive level. Okay. Yeah. And what do you expect someone who comes out, let's say at the bachelor level first, someone who comes out with that certification or specialization, either way I guess, what do you expect them to be able to do? And I'm thinking about for employers or for potential students who might want to do this, what would you hope that they're ready to do at that point?
Well, at that point, we're hoping that they'll have the necessary knowledge to walk into a position as an information security analyst or cybersecurity specialist and hold their own by contributing and helping to resolve issues, identify appropriate best practices. They might not have the work experience of someone that maybe finishes with a master's, but it'll establish them with a good foundation. Yeah, okay. And the folks who would go into that bachelor's program, are they generally, you know, just kind of your typical incoming to any college, you know, maybe right out of high school, maybe someone, you know, a little bit later in life who's ready to go back and get a degree? Is that basically no real requisites other than they want to go learn?
Most of our students are working adults. I believe the average age is about 34 to 36. That's starting to— we're seeing a shift in that. We're getting a lot of younger students as online education, you know, online education originally started as being targeted towards working adults, but now it's it's kind of become the norm. So it's across all, you know, demographics essentially.
Yeah. And so that is— we're seeing some changes in our, um, the demographics of our students and age is coming down a little bit. Yeah. And recently, um, we were just approved to start admitting students, uh, straight out of high school as well. Previously we weren't allowed to.
I didn't know that. Okay, so interesting. So, you know, if we talk about the difference between those incoming to the bachelor's degree versus those going to the master's program, is there different demographics for that? Is there different expectations for those coming into it? How does that look for coming into— well, with the master's degree, of course they have to have a bachelor's degree.
Yeah. Um, our master's degree is in IT management, so some students don't necessarily have an background. If we have any concerns with admissions, we might require them to take some, some of our core courses in IT. But typically the— our master's degree is aimed at IT management, so it includes IT principles with more of a managerial role. And then cybersecurity is a certification and specialization that students can pursue in that as well.
Yeah, so the folks going into the master's program generally will have some hands-on IT experience, it sounds like. Are you looking for people who are already in management or those who want to move into management, or is it really for both? For both, really. Then they get out of that master's program and they have the IT specialization certification, assuming the security specialization certification as well. When they graduate, what are they ready to do?
What's their job look like? Hopefully they will have the capability to contribute and lead a security team within their organization. It depends on the kind of the trajectory that they want to go in. So our programs are more equipped with helping our students understand security principles and policies and how can they be effectively applied within their organization. That's great.
Do you have any success stories, folks who've come out of there and that you can talk about, you know, what they've gone on to do?
Okay, well, I don't have a kind of specific student-based example, but our data does show that once students graduate from our program, they end up getting a return of investment of $4 for every dollar that they've spent on tuition. So it's definitely enabling them to live a better life after graduating. That's great. So let's kind of look at the future. Do you, do you see a future where you guys have focused and actually have cybersecurity-specific degree programs?
Is that coming anytime soon? That is something that we have talked about and and kind of brainstormed. We're going through just so many positive changes at CSU Global with the growth and migration of our technologies. So eventually I do think that we're going to offer a full bachelor's degree in cybersecurity as well and probably expand upon the specialization offerings that we have as well. Yeah, it sounds like there's a lot of opportunity for diving in deeper on the programs you have.
So within forensics, it sounds like there's 1 or 2 courses that get into that, but that could be a whole specialization or really a whole degree path for those who are really interested in doing it. Do you guys— have you guys seen growth in that interest in security? When did you start offering the specialization and certifications? The specialization has been around for at least 4 years, and it's actually, it's one of our largest specialization offerings with about 350 of our 1,600 students choose that specialization. So it's one of our biggest.
So it might be a place that you guys want to invest and get more offerings, hopefully, in the future. For those of us listening, you know, You know, I'm hiring folks on a regular basis, and I know a lot of my other listeners are in a similar boat where they're trying to find more talent and we're having a hard time keeping up. Is there anything we can do to help, you know, you guys, you know, deliver that high-quality education that will make these people employable for us after they graduate? Oh, definitely. We regularly solicit industry feedback, perhaps being able to serve on our Programmatic Advisory Board.
We also offer cybersecurity events. We have an event at the end of the month that we would— it would be great if anyone would be able to attend that. So there's ample opportunity.
You can look at our degree programs at csuglobal.edu.
And reach out to myself or our marketing program manager, Andrew Dixon, as well. We regularly seek and solicit feedback from industry leaders to help guide us in our curriculum changes and development. Yeah, so for those who want to reach out and It sounds like maybe showing up at your event might be a good first chance for folks to get plugged in, right? Right. That sounds good.
Now what about, you know, if folks just want to start to get connected with your students as they're graduating? Do you guys have career fairs that are— is there a career fair that could be focused on security for your students to show up at? Well, that would be a great idea, and actually we could work with our career services department to try try to establish a cybersecurity-focused career matching. I can tell you there is just such a need for security talent in the area. If you could bring in folks who have some experience and some relevant knowledge, they'd have no problem finding a job somewhere in the Denver area.
The Springs, of course, as well is hiring a ton. Very good stuff.
For those who are on the fence about whether they want to go back and get more education, I know a lot of folks in security have learned their skills on their own and could do a good job without having any education. What would you tell them to get them to take the step of applying and going through a program? What's the value to them? There definitely is value in being able to learn on your own, but getting the necessary skills, whether it be through a certificate or a microbadge from an institution that is able to offer a structured curriculum and guidelines, it kind of gives you that stamp of approval from, from, for other prospective employers and organizations that you, your knowledge is validated essentially. And when you go on to interview, the, the degree or your resume will get you in the door, but the skill set that you have is what will get you the job.
And hopefully for someone attending CSU Global, they'll have that complete package. Yeah, that's great. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.