All episodes

Rob Winter, CISO at Boulder Community Health

Apple Podcasts Spotify SoundCloud

In this episode:

Rob Winter, CISO at Boulder Community Health is our feature interview this week. News from: White Fence Farms, N3rd Street Gamers, Intelisecure, Sumo Logic, Optiv, Ping Identity, Coalfire, and a lot more!

Get your White Fence Farms while you can

Another historic Denver restaurant is closing. But an esports arena is coming. Election security is top of mind in our Secretary of State election. Three Colorado communities make the top 20 tech towns list. Denver’s Fast 50 list is out. Sumo Logic is presence in Denver is growing. Finally, blogs from Optiv, Ping and Coalfire.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12261 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 90 for the week of October 29th. Alex, happy Halloween.

Happy Halloween to you, Rob. That's a beautiful costume that you have. Thank you. I'm dressed as a Colorado Equal Security fanboy. Nice.

I like it. So what are you going to be for Halloween this year, Alex? You know, I think we're having a bunch of people over on Halloween. We do an annual chili cook-off. Yeah.

So we're doing that. I still have to figure out what I'm going to dress up as. I've been more concerned about making sure the house is ready and my chili and all that kind of stuff. So nice. How about you?

I, I think I'm going to be a knight. I was a knight for the company, the Ping party on Friday night. And yesterday I, I was Barney Rubble for a little while. Nice. I think we're going back to the knight costume, which, you know, worked pretty well.

You strike me more as a Fred Flintstone than a Barney Rubble. But hey, yeah, I had a Barney Rubble costume though. So well, okay, you go from there. That makes it easy. We have an extra hot dog costume at my house.

So that, that's always one that I could use if I can't think of anything else. Throw that on. I also have a couple pirate ones and some other stuff sitting around. But I did pirate last year. Yeah.

Hey, let's go ahead and talk about some housekeeping. Hey, first of all, we do have a Slack channel. This is an opportunity for you to, to come chat with other folks in the Colorado security community. If you've ever used IRC, this is kind of like our IRC with a GUI. Yeah.

And if you don't know what the heck IRC is, then you're probably a little younger than us. You probably already know what Slack is. You already know what Slack is because it's IRC. Anyway, we also have a mailing list. Check out our website, colorado-security.com.

Both for information on the Slack channel and to sign up for the mailing list. We'll get you the show notes in the mail. And we'd love it if you would rate us and review us on the— your, your favorite podcasting application. If you're on iTunes or Stitcher or wherever else you're getting your podcasts, and make sure while you're there you subscribe so that you keep getting the podcast automatically delivered to you. And if you really like it, you should sign up for our Patreon campaign.

Donate some money to us to help run the show. I'm actually wearing a Patreon shirt right now. If you're lucky, you could actually get the exact same shirt I'm wearing. I don't know if I would call that lucky, but it's possible. Is that not how it works?

Well, I hope not. And then finally, you know, if you don't have the financial resources to support us, but you'd like to support us, we would love it if you tell a friend and get your coworkers and colleagues interested and help us grow the podcast. So jumping into the news, we've got some very sad news to start off the podcast here. The White Fence Farm. It's a chicken restaurant here in town.

If you don't know what that is, the White Fence Farm. So much more. So much more than a chicken restaurant. It is a petting zoo. Yes, there's a farm.

It's a— there's a big barn, tractor, all that. Anyway, it's closing. It's closed. So first we lost Spaghetti Factory and now we're losing White Fence Farm. I don't know how we're going to keep eating here.

I don't know either. All these nostalgic foods are going to be gone. So it's a bummer we're losing White Fence Farm. I actually, to be totally honest, I don't even like it. But, but it is kind of a landmark, right?

My wife was actually a waitress there a long time ago. So. There you go. She's very sad. I bet she is.

So we are losing an old chicken restaurant, but we're gaining an esports arena coming to Lakewood. Is it gonna be in the barn at the White Fence Farm? It certainly seems possible since it's coming to Lakewood. It's called Nerd Street Gamers, and they're gonna be opening up the Local Host Arena in Lakewood. Nice.

So if your kids are into gaming and competitive gaming, you can take 'em there, or maybe even it's just you. That, you know, you don't have— no judgment here— anything better to do than to, you know, to play a whole bunch of video games. I think they said 18,000 square feet. That's big. It's going to be a big— that's really big— big arena.

So pretty cool stuff coming to town. Yeah. Also, we had an article this week. We are coming up on voting day. There was an article about— it's called A Tale of Two Campaigns for Secretary of State.

And this was about both the Democrat and the Republican that are running for Secretary of State. The reason that we have this listed here is the Secretary of State's office is in charge of election security. Yeah. And there's some talk about cybersecurity and election security in the article. I think we have talked in the past about how our friend Rich Schliep, who was previously the CSO over there, and now he's the CTO for the Secretary of State.

Yep. And there's been great things coming out of the Secretary of State's office for election security. Colorado was one of the highest rated states for election security. So really interesting to see that both campaigns are, are talking a lot about security. It's a key part of especially what the current Secretary is touting as his success so far.

And it's good to see security being treated as a first-class citizen in the debates. I would also say, no matter which candidate you like, you should definitely get out there and vote. Again, voting day is coming up. Make sure you fill out that ballot and you can cancel out whatever Rob does. Go follow, go follow Alex on Instagram and see his picture with his ballot and who he voted for.

Exactly. Moving over to our next story. There are 3 Colorado communities that made the top 20 tech towns list in the United States. Yeah, so there were only— we were one of 2 states that had 3 communities in that list. So Denver, Boulder, and Colorado Springs were all in that list.

Congrats to those towns. Denver came in at number 8. Really cool stuff. The other state that had 3 was North Carolina. Which obviously is nowhere near as good as us.

Clearly not anywhere close to as good as us. So that's cool. 3 good tech towns here in Colorado. Next, we had the 2018 Fast 50 winners and finalists from the Denver Business Journal announced. So these are the fastest growing companies in Colorado.

And in the medium-sized company category, InteliSecure was number 9. Yeah, I was surprised that that was the only security company that made the list. There were not even a lot of tech companies, to be honest. There were a few in there. There was a few.

The biggest number, the number one fastest growing extra large company was Ibotta. That's a tech company. Exactly. But there was a lot of oil and gas companies and construction and stuff that made the list. GE Anderson or GE Johnson, I mean, I saw was pretty high on the list as well.

Yeah. I mean, I think that's one of those things too where, you know, fastest growing is a little bit deceiving, right? Because it's, hey, you know, I made a dollar last year. This year I made $10. Whoa, look at that increase.

Well, that's why it gets interesting at the extra large size where if you're still growing that fast once you're a good-sized company, it becomes a whole lot more interesting. That is for sure. Next piece of news, the Bay Area firm Sumo Logic is really expanding their presence here in Denver. So they are a security company. They compete directly with Splunk and other SIEM technologies, and they've gone from having just 3 folks in Denver to having about 50 here over the last year or two.

Yeah, that is pretty cool. Good for them. Glad to see that there is another security company that's expanding in Denver. And this is especially interesting. They only have 400 people in the whole company.

So when you think about Denver, you know, it is— they say it's the number 2 biggest office behind their headquarters, and they're looking to grow here even more in the future. That is cool. Uh, there was a blog this week from Optiv called Will Blockchain Change the World? Okay, let's move on then. Easy enough.

So it was an interesting, uh, post though. They, they kind of walk you through what is blockchain, how, you know, how is blockchain not the same as Bitcoin, talking you through how you might look at it and think about it. This actually is a good chance for us to talk about that podcast we listened to this week from Risky Business where— Yes. Oh, I love that. What was the direct— do you remember the direct quote?

So I don't remember exactly, but it was— there was a study that was done. They spent $700,000 on doing this study. And basically the conclusions of the study were there is not a single application for blockchain where there isn't something else that is better for that application. Yeah. Something other than blockchain that can do the job better.

And so someone, so someone tweeted this and then there was a tweet in response to it. Uh, this guy who's an author of a blockchain book and he said, uh, this is great. Exactly the right conclusion. I hope that you bought my book and then spent $15 for $15 and then spent the other, you know, $699,000 whatever dollars on alcohol because that's what you need, uh, to be able to have to deal with blockchain. It was, it was a pretty good one.

It made us both laugh. Yeah, clearly. Next, we have a press release from Ping Identity this week. Ping's announcing a program that they're doing with Yubico to get a couple of free YubiKeys to help you get single sign-on. And really, it uses FIDO2.

If you're familiar with FIDO2, this is the standard that allows you to have passwordless authentication, basically just using your hardware token. Yeah, pretty cool. We are moving to a world without passwords, and that will be one that is very welcome. Next, we had a couple blogs from Coalfire. One was more of an announcement rather than a blog.

Coalfire is partnering with Virta Labs for Virta Labs' BlueFlow software suite, which is for medical device security. So Coalfire has a medical security consulting practice, and they're going to be using this software as part of it. So this was sort of announcing that partnership. Yeah, so they're going to be using their software as a part of the Coalfire practice. Good stuff.

The next ColdFire blog we want to talk about was their automating incident prevention and response in AWS. I love this blog post. I love this topic. I think that there's just not enough thought about how does incident response change in the cloud. This is specific to AWS, but the concepts are very similar.

And how do you, number one, you know, get controls in place? But if the worst happens, you got to be ready and not just, you know, trot out your incident response playbook that you use for in your own data center, because you're not going to be able to pull that hard drive. You're not going to be able to get that physical access and There are other things that you need to think about as well. Uh, Rob, I'm not moving to the cloud until I can get Amazon to confirm with me that anytime I ask them, they will pull hard drives for me for my incident response. You know, if you have the right contract and you're willing to pay the right amount of money, they will do that for you.

I'm sure that they will. Uh, but the blog talks about, uh, using CloudTrail, CloudWatch, uh, Config, and AWS Lambda, uh, to help watch and then automate some of the incident response processes using— in AWS. And they give some specific threats that you may need to be preparing for and, and really how to be ready for those threats. So interesting stuff there. And once again, good job to Coalfire for, you know, having a relevant post.

And that is all of the news for this week. Let's move to the Slack message of the week. Thanks again to Andre Gaeta, who is sponsoring the Slack message of the week. He has been doing this for a long time now, spent a lot of money out of his own pocket helping promote the podcast. So thanks again to Andre for doing that.

We appreciate it. So this week we wanna recognize John Hubbard. John asked a great question that sparked a lively conversation. His question was around which compliance framework should he go after first? And of course there is no right answer here.

Right. But it was really good to get to see conversations about, you know, why might someone go after PCI and what are the other compliance frameworks or certifications, you know, SOC 2, ISO type certifications, and why might someone prioritize one over the other? Yeah, it was a good discussion. And, uh, congratulations to John. So he'll get a piece of swag from the Colorado Equal Security store.

Hey, we haven't mentioned the store in a long time. You know, uh, we haven't mentioned the store, but it's out there. People can buy stuff. So if you go to colorado-security.com, uh, there's a store button that takes you to a CafePress store. You can get all kinds of Colorado Equal Security swag.

Lots and lots of cool stuff. If you want some, uh, magnets to put on your car, advertise Colorado Equal Security. If you want a shirt or a hat or a vest, A vest, you know, I don't know if there's a vest. Who knows? All kinds of good stuff.

All right, moving over to the events. As a reminder, we do have an event calendar on the website. You can come and check out what's going on here. We're going to go through the next 2 weeks worth of events here. First, SecureSet is doing a Hacking 101 for Microsoft PowerShell on 10/29.

Sounds like a good event. Sounds good. Starting on the 29th through the 2nd of November, the Colorado Technology Association is, is, uh, helping put together a Security+ training. So this is your chance to get ready for the certification. On the 30th, there is a Cybersecurity in the Future: What Every Organizational Leader Needs to Know.

And I believe this is the CSU Global one. Is that correct? I think that's true. Yeah. Yep.

SecureWorld Denver is coming to town. We have that sessions here on the 31st and the 1st. Alex, I believe you are doing a training on that Wednesday. I am doing How to Build and Mature Your Cybersecurity Program Using the NIST Cybersecurity Framework. So if you want to sign up for that, you are still able to.

It's an extra class, a plus class as part of SecureWorld. So I've got 3 hour-and-a-half sessions as part of that. And I'm gonna be doing a talk on Thursday morning if you wanna come listen to me blather on even more than you get to on the podcast. Next, CTA is doing their Day of Service from, along with PMI, and that is on the 1st of November. Also on the 1st, ISSA Denver is doing their Oil and Gas Special Interest Group.

So if you're either a part of the oil and gas industry or you wanna get to learn more about it, this is a chance to network with other security folks. One more on November 1st, SecureSet is doing Hunt Hacking 101: Intro to Wi-Fi. On the 2nd, their— the Colorado Springs First Friday group is doing their Cybersecurity Social Mixer. On the 7th, CTA has their annual Apex Awards. Again, we have some great CISO of the Year nominees including Robb Reck, James Carder, and Debbi Blyth.

Also on the 7th, ISSA Denver is doing their Women in Security special interest group. That's during the afternoon, I think. Uh, CSA is doing their fall summit on the 8th. This is a big event for them. Um, I believe that, uh, if you were on the Slack channel in the events area, you would have seen a discount code that would have posted there.

So yeah, I think it's 30% off or something like that. You should definitely go join the Slack channel and check that out if you're interested. All right, moving over to our jobs now. First job on the list, Nordstrom Bank is hiring a security GRC compliance Credit Information Security. I don't understand what this is exactly.

It sounds like it's about security and compliance and credit information security. I think maybe Credit Information Security is a department name. That might make sense. So this is probably just a GRC compliance type of role. Denver Water is looking for an IT Director of Cybersecurity.

So if you have interest in the water sector, that should be fun. Transamerica is hiring a Security Operations Center Leader. Platform.sh is looking for a security and compliance engineer, and this can be remote. Panasonic Automotive is hiring an information security specialist focused on smart mobility. This one looked really cool.

You know, some of those smart road initiatives that we've talked about have involved Panasonic. So I'm guessing that this is maybe something in that vein. Awesome. That sounds really cool. If you want to see security, you know, correspond with the real physical world, this might be the job for you.

Also sounding really cool, NREL is looking for a postdoctoral researcher in cybersecurity. So if you want to research cybersecurity as it relates to the, the energy sector, that sounds awesome. So do you have to be like a postdoc candidate right now? How's that work? Yeah, so I assume that you have to have just gotten your PhD and want to do a postdoc.

Pretty awesome. InteliSecure is hiring a SIEM security platform engineer. LogRhythm is looking for a strategic integrations engineer. And finally, Children's Hospital is hiring an IT security analyst professional. No amateurs need apply.

Well, it's good news because that means they're going to pay. Exactly. Well, and that'll be working with DJ MacArthur, our friend from ISSA Denver, and for sure the current director of security over for Children's. Should be good. Well, that takes us to the end of the, of the newscast, Alex.

We're going to have a feature interview this week with Rob Winter. Rob is the CISO over at Boulder Community Health. He came and talked to me and tells his story. He has a really interesting story. He does have a very interesting story.

I'm looking forward to hearing that. Good stuff. All right. Well, we'll talk to you again next week. Sounds good.

Thanks, Rob. Hi, I'm Dionne Mahaffey, Security and Compliance Manager at Antero Resources. Welcome to Colorado Eco Security for Colorado security professionals by Colorado security professionals. All right, welcome to Colorado Equal Security. This is our feature interview this week, and I am sitting down with Rob Winter.

Rob, you are the CISO at Boulder Community Health, and I want to hear all about what you're doing up at Boulder Community Health. But first, it's been a little while since you've given me an update. How many miles have you put on the bike in the last few years? So as of this morning, for this morning, you tell me, about 6,500— or I'm sorry, 3,500 miles for the year. 3,500 miles so far in 2018.

Right now we're just starting September as we're recording. So you're on track for 5,000-ish miles? If my— about 5,000 to 5,500. And so how do you get so many miles in? When are you finding the time for that?

Get up early. The easy answer is you get up at 5:00 a.m. and the second the sun breaks, you're outside. And is this every day? Almost every day. So usually it's 6 days a week, 1 day off.

Wow. And what does a typical ride look like for you? In the morning rides, they tend to be anywhere between 25 to 30 miles. Weekend rides can be up to 75 miles, maybe even up as much as 100. And is that— that's not going to work.

You're riding and going back home and showering and then driving into work? For the most part, yes. You know, commuting-wise, to go from my house to work is about 15 miles. And then coming home, because I go up towards the foothills, ends up being about 20 more miles. So I could still get some in, but, you know, then again, I'm a wimp, you know, with the heat.

It's, you know, preferred just to get done. Too hot to start the day. Too hot in the afternoon. Exactly. And then go out there and you start the day already refreshed.

So is it— does a 30-mile ride take— is that 2 hours? About an hour and 40. Because that's 20 miles an hour, a little, a little bit somewhere between, you know, 18, 17 to 18 is usually what I average. Okay. And obviously you're talking road riding.

Where— what kind of roads? I don't know what part of town you're living in and riding in. So I live in northwest Longmont, and so a lot of the rides go up towards Lyons. Yeah, there's a lot of old roads back there, roads that just aren't well traversed with cars, so easy to go back up there and kind of just go get lost and enjoy nature. So what do you do when there's snow and ice on the road?

So there's a software package called Zwift. And it allows you to ride your bike. Think of it as social media for bicyclists. So you're able to ride with people from all around the world indoor cycling. But so they're over there, so a lot of guys I ride with are from Great Britain or Germany, especially in the mornings.

That's their evenings. So you'll be having— you'll have a lot of people and just you get on there and you can do little chats with them just through instant messaging. And you just start learning about people from around the world. So you're riding on a stationary bike, or are you riding on one of the trainer things for your own bike? So for mine, it's what they call a smart trainer.

So as you go up a hill, it gets harder. As you go downhill, it gets easier. So it really mimics the road feel itself. And is it— this is not using your normal bike though? This is like its own standalone device?

You could actually go ahead— there are ones like Peloton that you can go ahead and do that, but there's ones like mine where you go ahead and attach it to your bike. To your normal bike. That's pretty cool. How long you been doing this? So cycling-wise, I started out when I was in high school going ahead and racing until I blew out my knees shortly after I started college.

Okay. Got nice and fat, so got into IT. I don't know which came first, but you know, either way, ended up deciding, you know what, I got to get back in shape. So started doing that, ended up going to the same hospital, so Boulder Community Health, and to what they called at the time Boulder Center Sports Medicine and rehabbing with them. So even years before I started there, went ahead and started working with those guys to rehab, lost about 50 pounds, started racing, uh, started actually doing fairly well in 2015 where, you know, started placing in the podium again.

So, wow, I've got nationally ranked in a time trial, which is that race against the clock. If you think about, you know, years ago what Lance Armstrong or Greg LeMond would win a lot at. Yeah, that's the same type of thing. It's you versus the clock. Wow.

And so just, you know, enjoy it. It's my zen, you know. It's after a hard day at work or, you know, starting the day like I mentioned. It's the way to go ahead and, you know, keep the mind fresh. That's awesome.

Well, let's, let's go ahead and back up. I want to get your story. Where are you from? So predominantly from Denver. Okay.

Before that, military brat. My dad was a JAG in the Marine Corps. Yeah. So predominantly was in Camp Lejeune, North Carolina. And then after he got out of the military, moved to Denver, and basically from that point, born and raised.

So you came to Denver as still in school, is that right? What school did you go to? So, you know, for high school, Regis High School. All right, and you graduated from Regis. What did you do after that?

After that, went up to Colorado State, so up to Fort Collins. Well, I was for a whole year. Okay, so, you know, I'm one of those interesting stories where somehow I found myself on the football floor where the quiet hours between about 5 to about 7 in the morning. And so after year 1, I was politely asked not to come back to CSU. So came back down to Denver, dabbled around a little bit, was working at a bike shop, was working here at Turen in Denver, and, you know, started trying out different things.

You know, I was pre-law for a little while, finance for a little while. Where were you going to school? Down at Metro. Metro, okay. And so just kept dabbling, and then one of my friends who was already in IT went ahead and said, hey, you got to try this.

Yeah. And, you know, we were talking about what to do, and we decided to start our own web design firm. And so during lunch hours at the bike shop, I would go up to the roof to sit back, read an old HTML book. This was about 1996. Okay.

And so it started doing it This is before any WYSIWYG was around where you just started hand coding everything. Yeah. So built the first, uh, my first website was for Turin. So they were the second bike shop in Colorado to have a website. So, you know, it's really kind of cool to actually get it out there.

And we were having people coming from all over the state saying, hey, I saw you on the web. They came in and would buy stuff. I saw your rotating GIFs on the web and I exactly come in. Yeah, because there's no way to buy it on the web. No, that's for sure.

GIF89 was big at that point.

So you kind of taught yourself? I very much taught myself. So after a while, I decided to leave the bike shop, did some contracting for a little while just to get my feet wet, get some experience, ended up finding myself down at US West. I was part of a group called the Law Group Technology Services. They were the offshoot kind of rogue IT for US West, but specialized in supporting the legal group, public policy, which are basically lobbyists, HR, and then security.

And so ended up doing a lot of Y2K projects for them, refreshing desktops and servers, and worked my way up to team lead there. After a while, I had some friends tell me that Quest was knocking on the door, get out now. So went ahead and jumped ship, moved to JP Morgan. They started what they called their Wealth Advisory Center. Was that here in Denver?

That was here in Denver. That was in the Tech Center, and so right over by Oracle. And so we— that lasted about almost a year. So that was supporting their poor millionaires. So poor millionaire was defined as $1 million up to $5 million in assets.

To be a poor millionaire, yeah, it's a tough life. So I'm not sure how those people would feel about being called a poor millionaire. That was the official term, unfortunately. So unfortunately, they deemed it more of a startup, and that was right when the bubble burst. And so it was one of the first casualties that happened with that.

So found myself on the job market, I ended up moving to Perot Systems. And as in H. Ross Perot? That was him. But this is a few years after his presidential election. That was— so it's 2001, moved to Perot Systems, and they had the full outsourcing for Budget Truck.

So if you remember the old Yellow Ryder trucks and now the Blue Budget trucks, we had the full IT department. So I worked there as a sysadmin, worked myself up into the manager role. I remember a boss one time came to me shortly after I started. She was like, you know something about security? I'm like, yeah.

And she's like, great, teach our security administrator. And it was more access control at that point. So I kind of used it to my advantage, said, okay, I need a SparkStation, need a whole bunch of books. And once again, self-taught with this. Yeah.

And so I just started reading up more and more, always dabbled in it, you know, even at US West did some investigations with them because EEO group, which is more the investigative side of HR, had to do work with them on that one. So I'd always dabbled in it but never had formalized it. So was it Perot Systems that you really went from being kind of formal IT to really becoming a security professional? That was actually— no, I stayed formal IT At that point was a sysadmin, became the team lead, became the manager. Unfortunately, the account moved out to New Jersey and they gave me the option to move there and I said no.

So I ended up doing other things with Perot, did some project management for a little while, then I made the formal leap back into security. So I started doing more SOC transformations, which is basically coming in, take over other companies' SOC units. Security Operations Center, or do you mean like a SOC audit? A SOC, uh, it's more moving the SOC to Pro Systems. The Security Operations Center.

Security Operations Center. Got it. Okay. And at that point too, I had started dabbling a little bit back in school, so went to Regis University. Okay.

That was right around 2003 is when I started back. That's just when they started their security program. Uh, they had started— that's early. It was very early. But they— what happened is they had partnered up with the Air Force There's a big presence of Regis down in Colorado Springs where they wanted to go ahead after September 11th to go ahead and start training on more about cybersecurity.

They had started one class down there and then they brought it up here to Denver. I was the first class with that. There were 4 core of us, 4 guys that started in that class. It was 4 classes is all it was. It was basically a Security+ CISSP training class.

It wasn't heavy in technology, it wasn't heavy into a lot of things. And that's when I started going to my professor and going, hey, have you looked at this book? Have you looked at that book? Yeah. And they ended up starting to adopt a lot of that, those books.

Yeah. So it started adding to it, and that's where I started feeling it was great giving back, not just consuming, but that point giving back to the culture, giving back to the community. So it started— did you end up getting a degree from Regis at that point? Got my bachelor's from there. Okay.

And they convinced me to go back for my master's, uh, with pretty much the, hey, we want you to start teaching as well. So started doing that. When I graduated in 2010, they basically brought me on as an affiliate faculty. Affiliate just basically meaning you have a full-time job but then you teach in the evenings. And so I've been teaching now for 8 years with them.

And you've been doing that continuously for the last 8 years? Uh, this semester is actually the first semester I can recall that I have no classes I'm teaching. Okay. Regis teaches in 8-week chunks, so you're able to go ahead and sometimes I would teach 8-week 1 of a semester and sometimes just 8-week 2. Yeah, but this is the first full semester I'm off.

Now, is that, is that because you're, you're done or you're going to start again next semester, or what? I'll start again next semester, and part of it was because I'm actually redesigning a couple courses, reworking the curriculum. Correct. So is that a job if you're reworking curriculum, or is that a job, or is that just something you do so you can teach later? It's, it's a job.

I mean, I definitely get paid for it, but it's also because we have to keep the technology fresh. We have to keep all the curriculum fresh. If we don't, it grows very stale, as you know, very quickly. Sure, sure does. So, you know, we're jumping around a little bit.

The Perot Systems gig, it looks like you did that through the end of 2007 while you, while you were still doing the Actually, and then, but I moved to another account in 2008, so I moved out to Stanford Hospital and Clinics. Okay. And so they had the full IT outsourcing as well. And so I was traveling back and forth between Colorado and San Francisco basically half-time. So, you know, had a nice apartment out there, you know, stayed out there, fly back, you know, every other week to see the family and go right back out.

So it was very fun, very educational, got to play with a lot of toys being in the Bay Area. A lot of companies wanted Stanford as a name, so it's great to go ahead and just try different things out, try different technology. You were the security architect there at Stanford? I was security architect and then eventually moved my way into security manager.

It looks like that was 4 years there. That's a pretty good run. What was the highlight, best thing you did there? Best thing I did there was being told by the CIO that she would put our security team against any other healthcare security team. And so to hear that from— basically Stanford is up to, I believe, the top 7 hospital in the nation.

To be told that, that was very much of a pat on the team's back. Yeah. And knowing that I had a part to play in that with the whole team, you know, that was a great thing. That's very cool. Um, and you were there through 2011?

Till the end of 2011. What happened there? Yeah, so one of my bosses from Stanford moved up, became CIO for University of California San Francisco Medical Center, so UCSF, and asked me if I'd want to come up there and be their CISO. Thought about it for a little bit, talked to the family, and decided let's move up there. Is it because it's the next step up in your career in terms of title?

Title, and at that point it was the number 5 hospital in the nation, so moving up in the world. It was kind of getting more exposure. And able to run my own team at that point. So not just under my CISO at Stanford, but running it as the CISO. And I talked to my boss at Stanford and he said I'd be foolish not to.

It was just a great opportunity. Yeah. So did that for 2 years. Very educational. Even though Stanford was academic, being state academic with UCSF, it was just— it wasn't the right culture for me at that point.

You know, I found myself working 16-hour days, very much the Bay Area. Type of environment, uh, you know, traveling back and forth between Walnut Creek where I lived. I would take the train out at 6 AM, get back somewhere around 9 PM, and then, you know, say good night to the kids and immediately start working again. There'd be weekends where I knew my boss was watching— he was a big Texas Rangers and San Francisco Giants baseball fan— so all of a sudden the emails would start flooding in as he's watching the game. So there wasn't a lot of downtime.

Time. And it was— it definitely— I recognized it back in 2013 when for Christmas I just shut everything off and I could feel my blood pressure coming down. So I figured at that moment I would go ahead and have a heart attack if I didn't step back. And for the family, they're like, it's time. So ended up moving back.

We had our house in Elizabeth, so I moved back in there. So Elizabeth, Colorado, you already had your house ready to come back. So, you know, Did that, and an opportunity came up with Boulder Community Health. So did you move back before you had the job, or you— I had actually started. So there was also one little other little part, which was they were consolidating IT of both the campus and the med center for UCSF.

Yeah. And so IT security was also part of that. Okay. They offered me the campus role, but because it's you either got it or you didn't, if you didn't, nice knowing you. Yeah.

I was applying at that time. Yeah. And so just for fun, you know, I was already applying back here in Colorado. Yeah. And the job opened up.

And so, you know, right around Christmas time is when I got the offer, right when I was shutting things down. And it really solidified the decision to move back to Colorado. And that's the offer from the Boulder Community Health? That's correct. Yeah.

Now it sounds like, you know, from what you said, you know, Stanford and UCSF being, you know, top 10 hospitals, I assume Boulder is— Boulder Community Health is a significant step back in terms of size and the scope of what you're working on? To an extent, you know, part of it is being true to yourself, you know. So I looked at kind of where did I have the most fun. Yeah, you know, was it with the big teams that, you know, Stanford, I had a team of 50 people because I had Active Directory underneath me as well, besides access provisioning and operations. And so it was good to have big teams, but then when you can make an influence having small teams, that was really valuable too.

And so part of it's because I was teaching I had to stay technical. You know, some of these CISOs, they're definitely more administrative at points. You start losing a lot of the technical capabilities. I enjoy it, so why not go back to something where it's a smaller team and you can have more direct influence on patient care? Yeah, well, so for those who don't know, why don't you tell us about Boulder Community Health?

What's the— what does this health system look like? What's it made up of? And so we're one hospital and we're just about 30 clinics, so very small. We're Boulder Broomfield counties only. So we're not going to really extend outward.

We're going to open an urgent care clinic in Erie, so that's Weld County, but we're just barely creeping over the county line at that point. We just, we're really serving the community itself. We're one of only 2 community hospitals left in Colorado. So we're very much small but very much focused on the community. What's the other community hospital?

Yeah, there's one down in Pueblo. All right. Everyone else, you know, people, the long holdouts like this park, they finally rolled over to someone else just because they needed help. What does it mean when— what if a hospital is a community hospital, and then what are the other options? So a nonprofit, very much focused on the commercial.

So we have a lot of, you know, Centura surrounding us, we have Banner, we have HealthONE, we have University Colorado Health surrounding our area. And so we're just— we're not a big conglomerate, we're a one-hospital organization. Yeah, it's I mean, wouldn't University of Colorado Health be a nonprofit too? No, they're state. They're not nonprofit.

What's the difference? So just, it's just how the state— the state's not— it's how you file tax. They're making money as well though, and you guys are basically a nonprofit organization. We're a 501. And how many employees do you guys have total?

Total, we're just hovering right around 2,000. And I assume most of those are in clinics or in the hospital clinical, correct, kind of patient-facing. Is there a corporate back office side that's, you know, that's not— I don't know exactly how you break it down. I'm thinking like there is back office. I mean, you have finance, you have departments, uh, like, uh, patient financial services, uh, decision support.

You of course have HR on the back end. Yeah. So you do have those. Is that in— is that in your own like corporate office away from the clinic? They're spread throughout Boulder.

In the clinics themselves, it could be in a clinic, it could be like in our building. It's You know, so we have what they call HIM, so that's medical records is another term for that one. So that's in ours, um, just wherever there's room basically. And where do you sit? Is it just a building just for— it's a building about 6 minutes walk from the hospital.

Okay. And but for us, it's wherever we can put it because the critical, as you were mentioning, those are the ones that are patient-facing. So we really want to make sure all the good spaces, those are first and foremost for the the front line. You got there in January of 2014, it looks like. Correct.

You've been coming up on 5 years pretty soon. That'll be great. What was it like when you got there? Interesting, because I was the first security officer there. They had a security program that was run by the CIO and then the director of infrastructure, but it had never had that true, as a lot of guys know, that true security focus there.

I walked in the door, went from my roughly about $4 million budget at UCSF to a whopping $140,000. One of the first things they did is say, can we take some back? It's like, what can I do with that kind of money? What can I do to be creative? As most security guys do, they go in there, let's do an assessment.

Let's do an overview of the environment. Let's figure out what's working and what's not. A lot of stuff was working right. A lot of stuff needed to be tweaked, and then I was able to build my program from there. My experience has been if you go to a place where the security was run by IT, what that really means is it's not a program in any way.

They do the things that they are aware are important for security, but not necessarily documented, not repeatable, maybe not even actually happening, but maybe they they'd invested at some point. What were the, what were the areas that you said, you know, when you first came in, you said, hey, we've really got to get some programmatic, um, some, some programmatic approach to these things? So, uh, disaster recovery was one. Sure. Uh, back in 2013, they had Meditech, which was their major EHR, so electronic health records system, went down, was publicized.

And so it's, what do we need to do to get that up running, to get actual tests in place, get it documented. That was a big one. Other ones are security awareness. That's one that we're still constantly doing, of course, because it's a continual effort. Then the other thing is just more formalizing visibility of the network.

We started bringing in some technology to see both east-west and north-south.

Getting that visibility, but trying to do that with without a budget, really, right? Correct. So it's very creative, you know. Yeah, it's a lot of it was OpEx. Start reaching out to a lot of my vendors in the, uh, the Bay Area saying, okay, what can you guys do to help us, you know?

And definitely played the, hey, we're a community hospital, right? We don't have a lot of money, you know, compared to a lot of companies. You know, our margins are 2 to 3% on the high end. You know, if we hit 5% margins, we are doing excellent that year. You know, as a community hospital, you're trying to keep it as close to cost as you can so that it really helps the community.

So there's not a lot of money to go out there and go from, like I said, UCSF, I had a $4 million budget, and then going way down, and asking for more isn't always there. If you have a choice between a million-dollar Nuuk Med machine to help a patient, to scan them, or a million dollars of a security program, which one are you gonna go with? And always you should go with patient care. Yeah, first of all, I wouldn't say always. I mean, there's, there's got to be an equation there, right, where you figure out, you know, what is the overall good that can be done from, from these expenses, right?

Correct. You start being creative. You start figuring out what you can do. So instead of building up a team initially, I outsourced to— at that time it was Solutionary, now NTT Security— uh, just because I had no budget, no team. Yeah.

And so, you know, there are things that they did well and things that, you know, as they became a big company, they had some growing pains as well, but it was able to at least get me by in the meantime, get me visibility where I didn't have to hire a 24/7 staff.

One of the ways that companies might look to save that budget money is if they can go after open source software to perform some of those tasks, using Security Onion versus using Snort. Know, there are lots of examples like that. Do you have an opinion on that? Are you a fan of going after the open source tools, or— We're looking right now possibly going with Bro. Yeah.

So CU's done, from what we've heard, an excellent job, have Bro throughout their environment. Yeah. And so we might actually do the same thing. Just, you know, we have to look at what's the right solution and the right cost for us. So it's looking at everything.

It's not saying commercial only, open source only. What's the nice blend between the two? What is the— what's the risk What's the risk, the big threats for Boulder Community Health? Obviously, you're thinking about patient safety, but obviously we see a ton of ransomware attacks that are hitting health organizations. And what kind of things are you most thinking about, you know, maybe the keeping you up at night type of a question here?

So everything from, you know, it could be simple loss of data records, nothing malicious happened, To when you look at healthcare on the full spectrum, it can go up as high as death. So, you know, if someone was to modify a pump, some kind of infusion pump at that point, and either give too much or too little medication, at that point someone could die. So it's really looking at the full gamut behind it and then trying to figure out, you know, of course it could be from an insider, it could be from an outsider. Ransomware, you had mentioned that one, that's a definite threat because right now hospitals unfortunately had paid it, and so the bad guys know this is an opportunity to go ahead and get paid. You mentioned one of the first things you did was disaster recovery, which I assume starts off with all about backups and figuring out which systems are backed up and do those backups work and all that.

How else do you think about defending against these threats? Obviously, there's a lot on the line with potential death and unavailability of health services. What are the, what are the key fundamental things you're working on to try and avoid those? A lot of those is practice the basics, the blocking, tackling. Yeah, you know, it's football season, so I'll use that as an analogy.

It's making sure we have visibility in the network, making sure that we actually have— so we just recently, about almost a year ago, bought LogRhythm. So their part of their office is actually right across the street from our parking lot. Perfect. Uh, so, you know, it was a great partnership. We're their hospital, so they definitely helped us out setting it up and getting up and running, so it's getting more visibility into the environment, stuff that we didn't have fully at that point.

With NTT, as good as they were helping us, you paid per system that you had in there, so it got very costly to get more visibility. With LogRhythm, yes, you pay messages per second, but at the same point, we could put a lot more in there. We could go ahead and filter a lot better, and we really were able to do that. That's the basics. It's making sure we stay up top with— they didn't have a threat vulnerability management program, so they had no scanning when I came in there.

It's giving them the basic information of what do they need to do, the operations team needs to do, to go ahead and keep the system up to date. We're not doing anything radical there, nothing pseudoscience type of stuff. It's really the basics. It's stuff that every security company should be doing. Every program should be doing that stuff.

What about compliance work? Do you— obviously you have to be HIPAA compliant. Um, is that, is that a big part of your job? HIPAA and PCR are 2 regulations we got to deal with. Yeah.

And so definitely, you know, when I talk to the board, they're always asking about the status of that. Uh, you know, I'd say there's things that we— I, I try to have a critical eye and say we're doing things well, and there's things that we are, are working our ways towards doing things well. As with any company, you're constantly looking at how can I keep improving the program itself. Yeah, but HIPAA is one. HIPAA though is not as prescriptive as PCI, so there's some stuff inside of HITECH that made it a little bit more prescriptive, but it's, you know, you have a lot of things where they're either required or addressable.

Sure. And so it's just, it's the minimum bar is how I look at it, and no one wants to be at the minimum level. Yeah. Are you— have you guys looked at all at HITRUST? Is that something you guys have gone after or going to go after?

Part of it we're seeing where the Office of Civil Rights, OCR, they're the enforcement wing for HIPAA, where they're going to go with it because they're kind of looking like they're going after the NIST framework, but then again, HITRUST has elevated their program to now include part of the NIST framework. So where's the happy medium point? Our framework right now is kind of a blend of the two. Of the NIST Cybersecurity Framework and HITRUST. HiTrust, from everything I hear, and I haven't ever been HiTrust certified, it sure looks like it's a pretty daunting one.

It's more rigorous than something like a SOC 2 or an ISO certification or even PCI, from everything I hear. Is that your impression of it as well? I got certified in HiTrust back in 2010, and from what I've seen, It depends on how far you want to go with it. If you want to self-attest, then you can go ahead and do it. At least as of a couple years ago, they had a spreadsheet that was really nice.

Now they moved to more of an online Archer type of system, but you can go ahead and say, I'm this big of an organization, I have these concerns, and it will go ahead and kind of build what requirements of the framework apply to you. It doesn't have to be fully daunting. If you're a couple doctor clinic, a standalone clinic, It doesn't have to be 500 questions for you, but if you're a big healthcare organization, yes, you're going to want, of course, to have a deeper look because you're going to have a lot more avenues where a bad guy could come in. It sounds like the last 4 years or so you've really been focusing on getting the blocking and tackling in place, being able to show a repeatable program. What's next?

How are you finishing 2018 and 2019? What's going to be your priorities? The priorities, we're switching our electronic medical medical record systems. As I mentioned, Meditech is the big one we have for inpatient, and we have another one called Greenway for ambulatory, but we're going to go to Epic. That's kind of a big name inside— You're replacing those other 2 with Epic?

Those other 2 with Epic. That's the big priority right now for the whole organization is switching over. What is the— from a security perspective, how does that impact you? Thankfully, not heavily because access provisioning is not part of my team. Team that's part of the service desk team.

So, you know, a lot of mine is more the architectural design and validation. So we're going through, you know, the different— both not just Epic but the partners of Epic, making sure they meet our standards. Yeah. But, you know, from a lot of the actual effort itself, it's not a huge impact. It's definitely an impact because there's only 2 of us on my team right now.

Yeah. So it's, you know, a lot of work for 2 people, but it's still— it's not as bad as some of the other teams. And is that Does that take you through 2019? October 2019. October 1st, 2019 is our target date for go-live.

That's going to be your number one priority. Any other stuff that you're going to try and squeeze in around the edges there? I thought about it and just finished up my budget predictions for 2019 because we're on the calendar year and decided a lot of the blinky lights, it's not worth it because a lot of the stuff that we want to do, we would need help from the infrastructure team. Team. Yeah.

And they're so working on Epic, focused on Epic, that at that point it's not worth it. So the other, uh, gentleman Brian and I, we're just gonna be working on taking the systems we currently have and keep getting more out of them. So, you know, keep tweaking it, keep getting better at them. Yeah, I think, I think that most companies out there could, could do with taking a year to just optimize what you already have and maybe honestly get rid of a couple things you already have and get better at the stuff you don't get rid of. Exactly.

Especially nonprofit, we always look for areas to— if we can drop something because something else can do the same thing, we do it. What's the biggest lessons you've learned over the last few years there at Boulder Health? One of the biggest lessons, and this is more from a personal level than an information security level, is that it's not worth stressing over things. When you ask what keeps me up at night, the answer is not much. You know, as long as I go ahead and let my board know, let my— what we call management council, so our VPs and our CEO know, and they accept the risk, not a lot keeps me up.

And a lot of that goes back to— back in 2015, I was diagnosed with stage 4 colorectal cancer. So had spread from the colorectal region to my lungs to my liver. And you start realizing what's important in your life, and the answer is not much. Not much it takes. It's worth that level of stress, worth that level of just sleepless nights, right?

Short of fighting, you know, I have three kids. You know, my eldest now just started college, and so my I have another son who's in high school, junior in high school, and I have a daughter who's a seventh grader. And it's really what am I doing to stay around for them? I've been very fortunate, very lucky. You know, there's.

Hardly any other way to say it. I've been able to, you know, keep riding the bike. You asked me how many miles I've ridden. As far as since I was diagnosed 37 months ago, have just about 17,000 miles on the bike. Yeah, I've been able to race.

I've raced 5 times now. I did a time trial in my age category. I took 2 months— or rather, 2 weeks rather— off of chemo back in March and placed 7th out of 17 in my age group. So to know that I'm getting hit with that much chemo, and I've had radiation now, and still be able to work, still be able to function, still be able to teach, you know, that's where I thrive off of this. You know, just not that much stresses me out anymore.

It's just not worth it. So that's probably the biggest lesson that any of us can learn, is that at the end of the day, you know, it can be stressful, but how much you have to absorb the stress doesn't have to be there. So would you say that you know, in the last 3 years since you got the diagnosis, that the fundamental change for you has been kind of a perspective shift? Is that the biggest change? Tremendously, yes.

Any thoughts for how other folks can try and get that kind of a perspective shift without having a diagnosis of cancer? Yeah, that's one of those things. It's part of the club that you never want to join, so it's definitely not a good thing. A lot of it is just realizing that there's vendors who call and say, what keeps you up at night, as you just mentioned. If people are saying, hey, this is going down, sometimes you just got to let work go.

There's times that I look at Brian, my coworker, and I say, you're just looking exhausted right now. Go home. I already know he's going to work at home anyways, but it's like, go get a break. Take tomorrow off type of thing. It's not worth stressing, you know, where you can.

Think of it as we're all running a marathon. You can't run a marathon as a sprint, but so much of us are. And that's when I was in California at UCSF, that's what I was doing. I was just constantly, you know, work, work, work, work, work, work, you know. I was— and it wasn't work, it was trying to exercise a little bit, um, and it was spend time with the family.

But there's a point where you just can't, so you have to learn of when there is downtime, take advantage of it. You know, just go ahead and find something. If you don't have a hobby, find one. You know, do what you enjoy. And it may be security.

Security is one of my hobbies. You know, I like to say it's the hobby that pays. But find something else that can take you away. You know, maybe it's reading a good novel. Maybe it's, you know, in my case, exercise.

You know, maybe it's taking— going and taking the kids out back and hitting the ball with them. You know, play some catch, whatever you can do. You know, it's finding something that you have as that outlet, because at the end of the day, you're gonna look back and on your tombstone, it's not gonna say he was the best security guy he could try to be, right? You know, it's always gonna say trying to be the best husband, the best father, the best son that you can be. From my diagnosis, I have an 8% chance of living past 5 years by the numbers.

That means 92 other people have to die for me to live past 5 years. And if you— I mentioned I'm month 37 now. Yeah. So I have to look and say, what am I going to do with the next 24 months to make an impact? You know, I'm not slowing down with teaching, you know, still doing that, uh, doing some curriculum redevelopment for Regis.

And so what can I do to give back to the community itself when you're looking at how much time is there? Now those numbers, of course, they don't define me. They don't find any of us unless we let them. And so if I go ahead and lose, so be it. You know, I was talking to a friend who played football in college, and he's kind of asking, you know, my thought on this tonight.

I said, coach never taught me to lose, which is basically— think about when you were playing sports as a kid, or if you have kids in sports. The coach never says, hey, you know, Rob, you got a 33% chance of losing today. Go team, go get clobbered, right? You know, it's always talk you up, try And it was very sobering a year ago that the nurse who checked me in and taught me initially about what chemo was, 'cause you go through a class of it, she and I were having a very frank conversation and I was saying, hey, here's how I'm doing on the bike and here's how I'm still working. And she paused me for a minute and said, honestly, I didn't expect you to be around right now.

So even though she had, she ended up retiring, so with 30-plus years of experience, she didn't think I'd be around. And so that was kind of very— a song for the moment. Sobering statement, isn't it? It was, to think about that. And that was part of what made me realize stress isn't worth it.

We're always going to have something with security. You know, we're trying to plug up the 20,000 different holes in the system. The bad guys only need to come through one, right? And so how do I prioritize? And can I do all 20,000 at once?

And we all know that's impossible. So it's really looking at where's the risk risk behind it? And then where can I go ahead and attack first, second, third, but not try to take on the 100th, the 1,000th hole right away? Yeah, the— I'll say, and obviously as we're talking about it now, your, your approach is amazing, and it's something, you know, you should be very proud of how you're— how you've handled this. But, you know, for the last few years we've talked about this, you know, a dozen times or whatever, and, um, just while widely in the community it's you're well respected for how straightforward you are about your diagnosis and the work you're doing and how it has only been a positive thing to see the way you've reacted.

I'm sure you must have some really tough days. I know radiation and chemo do that, but you've been extraordinarily resilient through that. I think, you know, I think you're well aware there's nothing wrong with having tough days, but the ability to bounce back from that and, and come back, it's been, it's been something worth, uh, worth admiring. But that's part of it too, is realizing a lot of people have it worse than I do, not just with cancer but other diseases. Sure.

You know, ones that we're, you know, talking about, like Pat Bowlen's in the news a lot and his wife having Alzheimer's. You know, to me that would be so much worse. You know, here I have a fighting chance. You know, right now they don't have the cure. And so what do you do?

And, you know, that's where I find a lot of my inspiration, is that, you know, every time I go in for chemo— and right now, as of about 3 months ago, they switched me over to an oral version of chemo— but every week I was going in for— they would stick a needle in my chest and I get pumped with chemo. I'd go in for 50 hours, they come off. The next week I go for an hour and just keep repeating that cycle. And we've now been through 75 rounds of chemo. And, you know, I look at that and go, people have it worse than I do.

With those 50 rounds of chemo, you feel awful. But as part of the security mindset with that, I started trying to figure out how can I hack my own body. You know, when I first started going back and started riding, my oncologist said, hey, be careful, you're on chemo. And I was like, okay, what does that mean? You know, it's, it's, you don't crash basically, and you're going to be more exhausted.

And then after a couple months of him hearing how I was doing and seeing my numbers, he's like, whatever you're doing, keep it up. And what I started figuring out is after chemo, I'd get on my indoor bike. So I'd go do chemo from Monday to Wednesday, get on my indoor bike on Thursday, and I'd ride for about 40 minutes. And it was hellacious. It was not fun whatsoever.

But I started figuring out that my body would then start recovering quicker. Once the chemo's in the body, having it hang around in the system doesn't help the body, only keeps tearing it down. You can recover, the stronger you get. I would go ahead and be able to ride the bike, and then all of a sudden the adrenaline, the endorphins would kick in, and you'd feel better. Then the next day I'd do an hour, and by the time I hit the weekends, I would do a lot more.

It was learning what the body could and couldn't do. On my 50th round of chemo, my oncologist, the main oncology nurse I had, said, hey, why don't you ride your bike? Into the chemo, to get chemo. And for those that, you know, if you know where Longmont is, and I go to Midtown Rocky Mountain Cancer Center, which is over between downtown Denver and City Park, that's about 42 miles each way. And so I said, you know what, for round 50, let's do 50 miles.

So I, according to them, am the first person who ever rode their bike into chemo, but that's hacking that body. Wait, so how'd you get back? My wife. After I came home, it was a hot day, it was in July, so I was like, no, I'm not going to go ahead and ride back. Seems like the right choice.

Yeah. Oh, it was definitely it for that day. It inspired other people in the oncology office as well, other patients. They came up to me afterwards and said, hey, I need to get back on my bike. That's that hacker mindset, that security mindset that a lot of us have is, hey, we can do something that it's been designed to do, but let's do something different with It's not taking no as an answer.

It's taking it to the point of my oncologist was basically, I told him one time what the mileage I was doing, and he's like, that's low for you, isn't it? So we'd done that full pendulum swing. It's very much, it's doing what we do every day with security. It's taking it to that next level. That's great.

I mean, it's such an inspirational story. I thank you for sharing it.

We're getting close on time here. I want to give you the chance. Is there anything that haven't asked you about that you'd like to talk about a little bit? Other things I've done to give back to the community, and it's more of trying to get other people to do it.

I'm also part of the CompTIA Cybersecurity Board, their advisory board. If you want to blame me for the Security+, the Cybersecurity Analyst, now coming up the PenTest+ and the CASP certification, Those are stuff that we talk about. It's get out there, have every other person get out there, start volunteering, start being in the community. You've done a great job. We were talking before the podcast started about I started with ISSA Denver in 2005 and how that's changed so much, just for the good, and how much you and Alex have changed it from being a very vendor-centric environment to being very much a security-focused very much of a secure team member.

Yeah, community. It's a community thing. I do want to give a shout out to James Johnson, who's now running the chapter and continuing on with keeping the vendors out of the talks. The other thing is, because like we talked about me working at Regis, for everyone else, get involved with that. Whether you go volunteer and talk at a class or you go ahead and teach, you know, if you want to do that, give back to the community because you never know what you get out of it.

When I went to UCSF, I was told I'd never be able to hire a team out in the Bay Area. And a couple of the people I brought in out from Colorado, you know, people I— another guy I had met. No more taking Colorado people out of the state. We need to keep them here. Yes, but in a way, it's my own farm team.

Yeah. So I very much get to pick and choose because I've been able to watch people as progress. That's great. As a security leader, you're able to go ahead and give back and get back as well. That's awesome.

This has been awesome, Rob. I'm looking forward to seeing what amazing things you do in the next couple of years. We'll keep in touch, and hopefully we can get you on the show again soon. Great. Thanks very much.

All right. Thanks a lot. Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes