All episodes

Dale Drew, CSO at Zayo

Apple Podcasts Spotify SoundCloud

In this episode:

Dale Drew, CSO at Zayo is our feature interview this week. News from: Richey May, LogRhythm, Ping Identity, Red Canary, Alchemy Security, Rule4 and a lot more!

Selfies Kill More People Than Sharks

A selfie couldn’t hurt anyone. Could it? Denver is the 5th fastest-growing big city in the US. But Colorado execs are losing their swagger. Richey May isn’t… they bought some other companies. Blockchain is blockchaining a blockchain. Blockchain. LogRhythm got a patent. LogRhythm, Ping Identity, and Red Canary write blogs (and stuff). Alchemy Security is offering a new service. Rule4 is upon us.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12662 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 87 for the week of October 8th. Alex, how you doing this evening?

I'm doing well. How are you, Robb? Doing fantastic. Ready to dive into one fantastic podcast today. Spent all weekend at a soccer tournament.

Fun stuff being out in the cold. It's a little chilly. Yeah, it was awesome out there. Gotta love it. I had a couple of soccer games today myself and definitely, definitely earlier in the day it was warm.

Later in the day, put on a sweater. Exactly. All right. Well, let's go through some housekeeping here. As a reminder, we have a Slack channel.

We're just a few people away from hitting that magic 600 member mark. Yeah, that is, you know, what everyone thinks of as the magic number, 600. Yeah, absolutely. So we're just about there. If we get 1 or 2 more people, that'll be great.

Magic will happen. Yeah. We also have a mailing list. Yeah. If you go out to our website, check out the mailing list, you'll get the show notes in the mail.

That website is colorado-security.com. We'd also love it if you would subscribe to the podcast and rate us on your favorite podcast application. Also, if you really, really like us, please support us through our Patreon campaign. You can find more details on that on the website as well. If you like us a little bit less or you don't have a lot of money sitting around.

Right, right. Yeah. Then you can tell a friend how much you love the podcast and, you know, that they should listen. Yeah. Help us get some more listeners.

We'd love that too. All right. With that, we do have a new patron, Patreon, to thank. This is Justin over at Cyber Reason. Justin, thank you very much for your sponsorship.

And of course, thanks to Cyber Reason, who I believe is footing the bill for this. We appreciate you guys' help. Yeah, and you too can get a shout out on the show and a free t-shirt if you support us at the $10 a month level. Awesome. Hey, we have some news to talk about.

News, Alex. One of the big travesties of this new technical world is the prevalence of selfies everywhere. You know, we just see selfies. I was at a concert recently where my view of the show was inhibited by people taking selfies, and apparently that's not the only bad thing that can happen because of a selfie. Yeah, you know, if you're not too careful, you might die.

So there's a story in the Denver Post this week that in the last couple of years, over 250 people have died taking a selfie. So just make sure you, you have some situational awareness when you're taking your selfies. Don't fall off a cliff. Yeah. Don't stand on railroad tracks with a train coming.

You know, don't stand in traffic. You know, other things like that. You know, sort of common sense kind of stuff when you're taking your selfies. If you are taking a selfie during the Running of the Bulls, maybe stop that and look at the bulls. Yes, just some advice for you guys.

Yes, I think it was a little funny in the article, though. Someone was quoted as saying that it has become a major public health problem— selfie deaths, that is. And I'm thinking, of all the things that you die from, 250 deaths in a year is really not that much. I don't know that I would call 250 deaths in a year a major health problem. But I will say it's more than 10 times as much as the number of people who die in shark attacks per year.

So this is, this is pretty serious stuff. It is serious. Let's keep, let's keep things in perspective. Let's do that. There's no movie as the theme for selfie death like there is for Jaws, right?

Or Selfie NATO. So, all right, let's move it along here. Denver has been named the fast— 5th fastest growing big city in the US. And also Loveland and Greeley were among the fastest growing overall. So you'll have to bleep me out as I tell you what the number one city on the list was for the fastest growing big city.

What is it? It's big. It's Austin. Yeah. Unfortunately, Austin has taken that number one spot on the list of biggest fastest growing big cities.

Miami, Florida, number two. That that one did surprise me. I didn't see Miami coming there. Seattle, Charlotte, and North Charlotte, North Carolina, and then Denver is number five. So some people may know.

I grew up in the Cleveland, Ohio area. And if you go look at the list, the number 66 big city in terms of growth is Cleveland, which I believe is last of big cities in growth. So we're saying the 66th fastest grower or the slowest grower? Correct. Yes.

The slowest growing big city. Let's call it the 66th fastest. 66th fastest. Yeah. All right.

So we actually have a little bit of bad news about the economy, Alex. This is a— this is maybe a first for us. We've had a couple of layoffs we've announced, but this is the first time we've talked about something like this where Colorado executives are losing confidence in the economy. Yeah. So it's, it's a little bit of bad news in that it's sort of forward-looking.

So it's not quite bad news yet. People think that there might be bad news coming. So executives were surveyed and they thought that 4th quarter still looking good for the economy, but they were feeling maybe 1st or 2nd quarter next year, maybe not so hot. Yeah. Well, hopefully that was them just trying to be optimistic about this year and, you know, think Yeah, anything bad is going to come out way in the future and we're not going to worry about that.

That's right. I think some of it was uncertainty around the midterm elections, you know, other things like that. People just didn't necessarily know what was coming. So, you know, fair enough. Well, hopefully they're wrong and 2019 is a fantastic economic year.

I hope so as well. Next, Ritchie May, which is an accounting firm here in town, acquired 2 IT consulting firms, Arrow Partnership and Corporate Blue. This is interesting to us, uh, especially because we, we know JT Gaydo, who is the head of their cybersecurity, uh, services practice. That would— so they, they offer security services to financial companies, and he was part of this acquisition and, and going to be working with these new firms. Yeah, and so Corporate Blue specifically was a cybersecurity firm.

I believe they were based out of LA. Um, so they acquired those guys to help, uh, move that practice along and, and gain some more traction. So congrats to them. Congrats to those guys. Yep.

Uh, big news, Alex. This is, this is big news. The global— that's worldwide— Blockchain Summit is coming back to Denver for Blockchain Week. I'm not impressed unless it's the Universal Blockchain Summit, Robb. Yeah, there is actually a bigger one happening on Jupiter, uh, which is to be expected.

Yeah, but that is pretty exciting. We have, uh, the, the Global Blockchain Summit happening here in Denver. Earlier this year, there was a big Ethereum hackathon. So Colorado is showing that it is a central place for blockchain technology. And this is going to be happening in Golden.

So if you, if you're looking to go to this and maybe swing by the brewery and get a Coors from the, from the tap, that might be a good fit for you. Or you could even go to Golden City Brewery, which was at least at one point the second largest brewery in Golden. Okay. So next, the CTA Apex Awards named their finalists, and they're going to have their award ceremony on November 7th. So as you heard last year, and I guess a little bit leading up this year when the nominations were open, CTA's Apex Awards has a CISO of the Year category.

So the nominees for this year are Debbi Blyth, the CISO for the state of Colorado, James Carder, from Logarithm and our own Rob Rack.

They do have my name spelled incorrectly in that, don't they? Well, congrats to Rob Rack, whoever that guy is. Well, I'm sure he'll be very pleased with the nomination. Next, more great news.

We were just talking about Logarithm, but congrats to them, not only to James Carder, but the got a patent for data processing technology. Congratulations. Congrats to them. It looks like this is, you know, obviously patents are only when you have some interesting technology going on. We're gonna have to see how they implement this in their product.

If it already is implemented, I haven't heard of it, but I'm looking forward to seeing what they do with that. Yeah, the title of it is Risk-Based Priority Processing of Data. Sounds pretty good. It does sound pretty good. So looking forward to those details.

Good for them. Next, we have a blog from Ping Identity around the Facebook data breach. So it's always nice when we have a local company talking about a national story so we can chat about it just a little bit. If you guys were aware, last week Facebook was breached, or they announced a breach where, you know, there's a vulnerability in their application that allowed people to get tokens to access other users' accounts, about 50 million of them it sounds like. So, so this post is talking about how this kind of programmatic access probably happened over APIs, and, you know, if you had some kind of security tool in place watching your APIs, it maybe would have been stopped.

The most amazing thing for me on that breach was that it was about a little over 2% of the Facebook users that were affected. Right. So it's 50 million. 50 million. It is a little over 2% of all Facebook users.

It is amazing. I'd say as we're talking about that breach, you know, they had a CISO, Alex Stamos, who was, you know, a pretty well-known CISO over there, left in August. The big announcement from Facebook when he left was we don't think we need to replace— we don't need to replace him. We're going to embed security in the business units. And then just a few weeks later, this thing comes out.

It just couldn't look much worse for them from a, from the perspective of taking security and privacy seriously. Yeah. I mean, and I think as we know, this is not the only instance that they have had around, you know, more around privacy than security. Um, but yeah, not, not so hot. Not so great.

There's another Ping blog here. And actually this one is, uh, is about a, well, it's about the white papers. We talked about the white papers a little bit ago, but the reason this this blog post came out was I was on— I was featured on the CyberWire, which is one of the podcasts I listen to every day. It's the afternoon drive podcast for me, just talking about the Ping CISO Advisory Council that we have with our customers and some of the research we put out. So it's a chance for— if you guys are interested in reading what that research is all about, or you want to hear me on a different podcast talking to different people, then there's your opportunity.

Exactly. So congrats, Robb. For the white papers and being on the podcast. Alchemy Security, who is a security monitoring company here in town, had a press release about their expanded cloud security portfolio with the Alchemy Defense Cloud. So they're still using Splunk.

They're going to be using the Splunk Cloud for this stuff. It looks like a really good offering. It's nice to see them moving into that area. Basically, you know, if you have a cloud-first approach, they're going to be able to support that. Yeah, I mean, I think like with any other cloud technology, this allows them to expand and contract as they need to.

Um, you know, they can be a big player without having to put in, uh, the resources you might need to set up a giant infrastructure. So good for them. Yep. Uh, so next is we have a blog post from LogRhythm about insecure FTP transfers and SCADA environments. This is Keith Buswell, who's an engineer over there, talking about how you monitor your vendors who are monitoring your SCADA systems?

Interesting question. And, you know, I know you have some oil and gas background. I'm curious if this resonated with you. Yeah, for sure. Uh, you know, part of it was just looking a little bit deeper at what's going on on your network, in this case on your SCADA network.

Um, they were sort of challenging some assumptions that, oh, you know, FTP, that, that seems like it should be legitimate traffic, but it was, you know, well, let's look deeper. What is this, uh, this traffic doing? You know, what else is going along with this FTP traffic. So interesting read there. Definitely check out that blog post.

Next, we had a blog from Red Canary about attacking the Mac. So this is looking for post-exploitation in macOS. So unfortunately, what they're saying here in this blog post is that Macs can be compromised. So I actually need to pause here, go back to work, and do a little bit of a little work on securing those Mac endpoint devices. Yeah, they, you know, start out the article talking a little, uh, you know, tongue-in-cheek about how, uh, you know, everyone says that Macs can't be hacked.

And so, you know, this blog post isn't going to talk about that because it's impossible. Um, but it's really, you know, some interesting things. You hear a lot about post-exploitation, lateral movement, other things like that on Windows hosts. So it is interesting to read about the techniques that you could use to do something similar on the Mac. I really think it's interesting if you do run an environment that has Macs in it, you should take a look at this.

Uh, of course, looking to stop exploitation is great, but of course being able to detect it is probably even better because no matter what we do, we're going to need to be able to detect bad stuff after they get through. Exactly. Uh, next, uh, ProtectWise. This wasn't actually an article, but we did see an SEC filing, uh, that ProtectWise raised another, uh, $5 million in funding. Uh, previously they had been through their B round of funding.

I think they've raised $77 million so far. Um, so as we looked at it, you know, we don't know what's going on here exactly, but, you know, we could conjecture that, uh, you know, this is either part of a new round or the tail end of the other round or something in between that, that looks like they're raising. The, the filing, and, you know, to be fair, I don't understand how to read these filings real well. Uh, the filing says they checked the boxes for both, uh, debt and equity. So does that mean that it's a loan from a bank or it's actually new equity issued or it's a combination of both?

I'm not sure. But anyway, they raised $5 more million, and presumably that's good for them to have some more capital to keep operating. All right. And then our final story here this week is that Rule 4 has launched. Rule 4, this is a new company.

If you guys remember, was it just a couple of months ago we had Trent Hein on the show as a feature interview? Trent was one of the founders of Applied Trust, and Trent is one of the founders of this new company as well. Yeah. So they're doing some consulting, some of it security related, some of it not security related, uh, some of it related to DevOps and sort of forward-looking technologies. So it's interesting to see, you know, what they're coming out with and, and what they're going to be able to do.

Yeah, I— this is— it looks to me like they really kind of rebooted the idea of what they've done with, uh, with Applied Trust, but really rebooted it with the new technologies in mind. So if you, you know, if you're looking for security consulting but someone who can also help you get into, you know, IoT, uh, blockchain, all the new stuff there, right? That's where they're positioning themselves. Yeah, I noticed that they have a service around site reliability engineering, you know, so if you are big into DevOps and you need some consulting around that area, um, seems to make sense. So congrats to them.

Yeah, look for big stuff. So that's it for the news. Let's, uh, go over to our Slack message of the week. So first of all, thanks to Andre Gaeta, who is our sponsor. Andre, we appreciate you doing this for us.

And this week, we— who are we going to be recognizing? So for this week's Slack Message of the Week, we want to give it to Lunar. So I'm not sure exactly who Lunar is. It is apparently a pseudonym. But Lunar was the first one to post this week on the Bloomberg story about the super micro motherboards and the extra chip, you know, potentially infecting Amazon and Apple and some other folks.

And that conversation took over the Slack channel for a day, and it took over my my life for that same day outside of the Slack channel as well. Yeah, pretty cool. There's a lot of stuff going on. In a bad way. Yeah, pretty cool in a bad way.

Yeah, well, thanks to Lunar. Of course, you will get to choose something from the Colorado Equal Security Store with a value up to $25. We'll get you a note and you can let Andre Gaten know what it is and he'll get that sent over to you. So once again, congratulations and thank you. So let's move over to events.

First event that we have this week, SecureSet is doing one of their Hacking 101s. This is asset management with Matthew McDonald. I'm not sure how that's a hacking one. I'm a little bit, a little bit, I don't know, and that thrown off. That's it.

They're throwing me for a curve right now. And I did not mention it. That is on the 8th. That is on the 8th. Um, and we also might want to mention we have a calendar of events.

Oh, we do. That on the website, if you go to colorado-security.com, you go to the events page, you can see what's going on every day for the next several months. On the 8th and 9th is the big National Cybersecurity Center Cyber Symposium. This is your chance to go down to the Springs and have 2 days with bigwigs and hobnob. And, and you'll probably be the smartest security person there because it sounds like they're not bringing a lot of security folks.

It's really policy people and company executives that are going to be there. On the 9th and the 10th, ISSA Denver is doing their October chapter meetings. It's actually James Carder speaking this month. Oh, what's he talking about? He is talking about zero trust networks.

Oh, I love it. That's good. That's great stuff. You guys should make it. Boulder will be The Tuesday for lunch, uh, downtown Denver.

Tuesday dinner, uh, Wednesday lunch will be the Denver Tech Center. Uh, on the 10th as well, we have a cyber risk management event, and that's the one with Svelo and Route 9B, right? I believe so. On the 11th, ISSA Colorado Springs is having a professional networking event. So if you want to network with professionals, go to that.

So if you are not a professional, can you still go? Uh, that's a good question. Or do they pay you to be there? What does this mean exactly? Uh, it's a good question.

And so on the 11th and 12th, there is, there's an invitation for you guys to participate in an industry event. Um, so the, the university, uh, I think it's CU, is doing an intelligent IoT symposium, 2-day event. Go learn about intelligent IoT at this thing or contribute to intelligent IoT, one or the other. Uh, on the 17th, CTA is doing their CTA 101. Also on the 17th, that we have the DENSEC meeting downtown.

That's going to be at the WinCoop this, this month, and that's usually about 7 o'clock to 9 o'clock. It's a great group of folks. If you haven't connected with them on the Slack channel, that's a good place to connect as well. On the 18th, SecureSet is doing one of their cybersecurity career convos. Elaine Marino Um, of Equally and Lady Coders.

That's on the 18th. And then finally, for our events, uh, there is the Global Blockchain Summit coming on the 19th of October. This is in Golden. We already mentioned it. So I think we've talked about blockchain enough.

And that is, of course, as we mentioned, the lead-up to the Universal Blockchain Summit, which I assume will still be here, right? Uh, you know, Jeff Bezos is doing that. You know, get on one of his rockets and go off somewhere and have the Does Elon Musk rocket go faster than Jeff Bezos? I don't know either. So let's move on to jobs.

I would be happy to talk about the number one job on the list, which is the Ping Cloud Security Architect role. I am looking for someone who can help us with architecture in AWS. If you have good experience with AWS and your security skills are strong, give me a, give me a note about this and we'd be happy to talk about it. We also have lots of other great roles in Denver. If you see something else on the jobs page you're interested in, send me a note either through Slack or email and I would be happy to get you connected.

Connected with the hiring manager. Uh, next, Aegon is looking for a director of cybersecurity. This is Aegon from the Ghostbusters? Yes, exactly. Um, so if you want to be the director of security services for, uh, for the Ghostbusters, uh, look there.

I don't know Aegon. Do you know anything about those guys? So Aegon is a global provider of pensions, insurance, and asset management. Well, it sounds like a good place to be a director of security. I think it probably would be.

All right. Kaiser Permanente is hiring a senior manager of cyber risk defense. Cognizant is also looking for a senior manager, but in cybersecurity architecture for their corporate services. Apple, the people who, you know, you probably heard of them. They made Macintosh computers back in the '80s.

They're hiring a security tools developer and engineer. That sounds really cool. Zayo Group is looking for a cybersecurity analyst. 3. Uh, finally, been a lot of 1s and 2s, but we finally got a 3.

Good. Moving on up. Uh, Digital Globe is hiring a security architect. Carbon Black is looking for a threat researcher. Dark Owl is hiring a threat intelligence analyst.

Alchemy Security, who we mentioned earlier, is looking for a junior analyst on the night shift. This is a great opportunity for those who are looking to break in, a, a really good first job to get some experience hands-on with technology. Uh, and then Red Canary is hiring an account executive. So if you want to go sell Red Canary, this is a good chance. We've talked with Brian Bear multiple times on the show, and including last week, we really like those guys.

Uh, that is it for our news this week, Alex. I can't believe we finally made it through that jam-packed. It was a lot of news. It was a lot of news. Uh, but don't go away because we have a feature interview with Dale Drew.

Dale is the chief security officer at Xeo. He's hiring a, uh, what was that? I guess Uh, he— the Cybersecurity Analyst 3 probably worked for Dale. Yeah, so Dale's hiring that cybersecurity analyst, but he, previous to being at Xeo, he was the CISO at Level 3. He was a chief security strategist for CenturyLink.

Uh, he has a great background. We got to talk about how he got to Colorado and what he's done to build some really world-class security programs. So it was a good interview. He's a sharp guy. Well, that's it for now, and we'll talk to you again next week.

Thanks, Robb.

Hi, this is Sam Masiello, Chief Information Security Officer at Gates Corporation. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Robb Reck doing a feature interview today with Dale Drew. Dale, welcome. I know you are the new CISO over at Zayo. It's been about 4 months or so since you've been there.

I'm excited to get to hear about your background, what you did before Zayo, what you're doing at Zayo. But what I'm most interested in is understanding, tell me about this regular invasion that you're getting at your house of some nighttime prowlers. Talk to me about this. Well, you know, it seems like the theme of physical security follows me wherever I go, but I just moved into a property about a year ago in Arvada. It's about an acre or so, and it's right next to a creek.

Sounds beautiful. And it's gorgeous. I mean, there's 80 trees on the property and it's just gorgeous. I love it. And so this family of 5 raccoons has been invading the house at night.

And so it— and I've been having, I mean, just bare-knuckle brawls with this family of raccoons. It's been amazing. So the 2 most notable things are they started out by invading my trash can. Sure. And I tried over the course of like a month different ways of protecting the trash can from keeping them from getting in.

And, you know, I did the classic physical security approach. I put a barrier in front of the garbage cans. Well, they climbed up the side of my house to get past the barrier to get on the trash can. So they could drop in from the top. Yeah, from the top.

So that didn't work. Then I tried putting something heavy on the trash can and they pulled the trash can out from under the bottom and knocked it over. Okay. So very, very creative, uh, little animals. Yeah.

So I ended up having to, uh, create like a, like a 4-point harness for the lid of the garbage can. So like belt and suspenders around the garbage can lid? Right. That was difficult enough for the raccoons to open, but easy enough for the garbage guys to open. And so, so, uh, so I had a really small victory, uh, there.

And then, um, What happened was I had a camera. I had an Arlo wireless camera pointing at the garbage cans, watching all this unfold. And when they couldn't get into the garbage can, they climbed up the side of my shed where the camera's installed and took the camera and took off with it. What? So I have this awesome video of this raccoon popping his head up in the camera view and then his mouth going over the the lens of the camera and then running off with the camera.

So it's a wireless camera, so battery-operated and it's also wireless. And so I have to see it for quite a while. So I'm watching this unfold. Yeah. And I go running out there and he drops it and I have no idea where the camera is.

So I had to get a live view with a flashlight and look for my flashlight on the live feed to figure out where my camera was. And retrieved it. But so do you— have you now fastened down the camera as well? No. So I have it— I had it— I have it in a different spot that's difficult for them to climb up.

Okay. And but they're not— they're not in the garbage can anymore. Now— now they're on the other side of the house trying to find, you know, find insects, and they're in my pond and things like that. Are you ready to claim victory at this point or not yet? So I'm claiming victory from the standpoint they're not using my house as a food source anymore.

And I've been thinking about putting a little piece of ham closer and closer to my neighbor's house.

But good neighbors and good fences. But, but no, they're, they're, they still make a pretty regular visit to the house. Now, now my goal is to keep them out of the attic. Yeah, that, that's the, that was my biggest fear when you mentioned this is, is getting into the attic. It's awfully tough to deal with that.

Yeah, I've heard horror stories about like really significant damage to homes when that happens. So yeah, I've got cameras sort of watching, you know, most of my camera systems are designed to keep an eye on the raccoons as opposed to like other actual threats. Well, you got to know your— this is about threat modeling, right? Yeah, exactly. You got to know your threats, you know who your threat actors are, and maybe we'll talk more about that later.

Yeah, on the bar chart of threats, the raccoons have a pretty significant height. So yeah. All right, well, let's, uh, let's talk a little. Let's move into some other stuff. Uh, back me up, you know, where are you from?

Oh my, um, I'm from everywhere. I was, uh, I was born in Spokane, Washington. My dad was, uh, uh, in the Air Force. Okay, so a bit of an Air Force brat. So we, we moved around quite a bit.

I mean, I moved around mostly on the, um, uh, on the West Coast. Midwest. Sure. So Idaho, Iowa, things like that. But spent most of my time in Cheyenne, Wyoming.

So is that your childhood or your adult life? Oh no, my childhood. I mean, I, after I graduated, I went to Phoenix, Arizona. Okay. And, and then shortly after that took a job with the U.S. Secret Service.

Oh, I didn't know you were in the Secret Service. Yeah. Did you have to go back to D.C. for that or? So you go back to— so you go to Florida for training. Treasury has a training department in Florida in the middle of nowhere.

And so I did my training in Florida, and then I opened up the Secret Service's first computer crime division out of Phoenix. So this is really interesting. Before we get into what you did there, I'd like to know what kind of background or education did you have that kind of made you the right person to go into the Secret Service? So my interest in computer security started because my mother's checkbook was stolen when I was a kid. So I think it was in junior high, and her checkbook was stolen.

I was intent on finding out who it was. And so I launched a one-man investigation. I went to local police, went to the FBI. They were really not interested. I took the canceled checks from the bank, went to the stores where the checks were canceled, asked for access to the video.

I got copies of the video from all the stores, right, and was able to build a relatively compelling case on, on who it was. And it was actually 2 people, husband and wife. Did you guys know these people? No, no, we had no idea. They just apparently went to our neighborhood and were going through people's mail.

And they pulled it out of a mailbox. Just so happens that she had her checks delivered at the time that they went through it. And they didn't actually take the box. They took— they were really smart. They took just one section of the checkbook out of the checks.

One of the little packets, right? Exactly. Yeah. So, you know, I built a case. We presented it to law enforcement.

They were able to positively identify the husband. From there, they got the wife. And I got a letter of appreciation from the chief of police, and I was hooked. So you put together the case and presented it and they were willing to go indict? And yeah, did they end up getting found guilty?

And they got, they got charged. They got, I mean, it was over, it's over $5,000 in fraud. $1,000 was the minimum at the time. But I don't, I don't exactly remember what they were charged with or whether it was a misdemeanor or a felony. Yeah, I was just giving myself high fives on the fact that we caught them.

And that's amazing. How old were you? I was either in 9th or 10th grade. I was really young. That's pretty cool to get to do that.

Yeah. All right, so that got you hooked. You ended up going to— what did you go to college for? So I went to DeVry and focused specifically on a computer science degree. Yeah, early on it looks like in the computer science world too.

Did your DeVry time overlap with Secret Service? Yeah, I actually left college to join the Secret Service. I got a really, really amazing opportunity at the Secret Service. There was a lot of debate between the FBI and the Secret Service about who was going to be taking over computer crime investigations. Department of Treasury felt that it was financial fraud, and as a result, they should have purview.

Their law enforcement arm was the Secret Service, so they wanted that to happen. And so, you know, that conversation was happening about the time that I walked in the lobby of the Secret Service. I actually handed a proposal to the Secret Service in starting a computer crime division, and they hired me fairly quickly after that. As like an 18, 20-year-old kid? Yeah, I was 18.

Oh, I suppose. Precocious. Yeah. Yeah, now I'm just looking at your profile. What is Operation Sun Devil?

So Operation Sun Devil is essentially what started it. We wanted to make a pretty big name for ourselves, and so the goal was try to find and attract those people who were involved in serious credit card and toll fraud crime. And, and back then, you know, there was no internet, right? It was all dial-up modems and bulletin board systems and all that. And so They were going after major players in credit card crime and the calling card fraud.

We did that, and then we also— at the time, there was 2 data communications companies, one called TimeNet, one called— one was Sprint, and they had a network called Telenet. They were global X.25 networks. If you were a global defense company or credit card company or banking company, that's the network that you connected to. And so we caught the Legion of Doom and Masters of Deception breaking into those networks and built cases against them, as well as 30 other people in 25 states. And so, you know, we created a bulletin board system.

We were accessing other bulletin board systems looking for people, not the kids who were just doing, you know, small-time credit card fraud, but the ones who were more organized, the ones creating a significant amount of fraud. Yeah. And so we built a case of, um, what, 30 or so people, 25 states, plus a case against, uh, Legion of Doom and Masters of Deception. Yeah. And, um, and prosecuted.

It looks like you, you're only there for 4 years, so You did it pretty quickly. Yeah, yeah. Wow, that's a pretty neat start to your career. And when I was messing around at a college, you were out there putting people in jail. Yeah.

Pretty neat stuff. Yeah, and right after, I mean, right when Sun Devil finished, excuse me, right when Sun Devil finished, the Arizona Attorney General was building a computer crime division. Yeah, and so he invited me to join that organization. So when Sun Devil finished, that was your kind of your excuse to move on from Secret Service at that point? And what did you do for the Attorney General?

So I ran the state's evidence lab, and so all of the computer crime-related evidence that would come in, whether it was Well, so a fun fact. At the time, there were more retired mafia bosses in Arizona than any other place in the nation. And so, and they would get bored out of their mind and they would launch, you know, online scams and drug running and, you know, murder for hire and other things. But anything that they did computer crime related, Yeah, uh, you know, went through my, uh, my lab. So I'm not sure if you want to be the one putting all those mafia— retired mafia dons in jail.

Well, it's funny that it— at, at the Attorney General's Office was the first time I, I had operational, uh, undercover, uh, names. Oh yeah. And so I had like 5 or 6 names that I used for my personal use and business dealings and all that when we were doing undercover operations. But I got to pick one. Okay.

And I loved it. I got to— so my name, my undercover name was Gene Pool. Gene Pool. You don't want to be eliminated from the gene pool. Exactly.

And I had a fake wife. Her name was Cecily or Cesspool. And I loved it. It was just so awesome. That's so terrible.

So how long— it looks like you were there for a few years at the Attorney General's office. Yeah. Yeah. And what caused you to leave there? So the Attorney General was Bob Corman, and pardon me, he lost the reelection.

Okay. The new Attorney General didn't have a lot of affinity for the computer crime section, didn't think that was the way of the future. Right. And closed. So I stayed on board for about 6 months because I was the guy who was supposed to close all the cases.

Okay. And so we either transferred cases to the District Attorney's Office, or we closed them out entirely. So it was a complete sort of shutdown of— and what I'd say is I worked for a prosecutor by the name of Gail Thackeray, who I thought was pretty much a pioneer in the computer crime era. So she started the first computer crime addiction program, And so if someone was convicted of a computer crime more than once, she would enroll that person in a computer addiction program and try to get them out of the sort of social environment of the internet underground and so on. And her quote that I love was— and this was true at the time— but the quote that she had, which I loved, was, we could stop computer crime in its tracks if we just convicted these guys to a girlfriend.

Oh my goodness.

Not the most politically correct thing to say, but yeah, okay. But, you know, but I mean, it was somewhat true of the particular era, you know, back when computer crime was made up of, you know, when you were between 13 and 17 years old and you could break into Fortune 500 companies. Um, you know, it was, it was a virtual playground. It really wasn't for money at that point, right? It was, it was for fun and cakes and friends.

Yeah, interesting. All right, so move us forward. Uh, from there I went to a company called, uh, TimeNet. Okay. Um, and it was, uh, when I got there, it was owned by McDonnell Douglas, but it was a global X.25 backbone.

Like I said, if you If you were a global company, that was the network that you were connected to, and Legion of Doom had fairly significant access to that network. We built a security organization, a cybersecurity organization, for the purposes of not only protecting the network from those sort of advanced threats, but also tracking and getting enough evidence to be able to prosecute for the purposes of setting a fairly large, visible example of why you wouldn't want to break into a network like that. And so that sort of went in this huge sort of progression of, you know, TimeNet was purchased by BT North America, which was then purchased by MCI and so on. But I sort of got my start in commercial large-scale network protection at TimeNet. Did you ever own one of the Captain Crunch whistles at that point?

I have 2. I have 2 Captain Crunch whistles. For those listening who may not know what we're talking about, could you summarize what that was used for? Yeah. Back in Back in the day, before the phone switch was digital, when it was analog, it used what's called in-band signaling to be able to administer all of the functions of the phone network.

Like the tones you hear when you push a tone button phone, a push-button phone. Yeah, like when you dial and you hear all the tones behind the numbers, That's in-band signaling. And so it used to be that if you were an operator, you would have the same sort of line that everyone else would have access to, and your sort of password was the tone that you generated to tell the network what to do. And so if you were a long-distance overseas operator, you would emit a specific tone, and that would tell the phone network that you get to have access to the long-distance network. And then The number of tones after that would be the number that you wanted to reach out to.

Well, it turns out that that tone was 2,600 hertz. And so, and there was a whistle that was provided in Captain Crunch cereal. Like a little toy prize inside the box? Yeah, a little plastic whistle that emitted that exact frequency. That's the funniest coincidence.

So John Draper, who became Captain Crunch, John Draper was what's called a phreaker. He was a phone hacker, a phreaker. And he loved to sort of play with the phone network. And he happened to be talking to someone on the phone. He had the whistle in his mouth and he blew it.

And he heard a kerchunk and a dial tone. And he dialed a long-distance number and he got to make free long-distance phone calls because the network thought he was an operator. And so the whole era of blue boxing and orange boxing and rainbow boxing, creating boxes that could artificially generate those tones to pretend that you were an operator, and they had different operators doing different things, that sort of exploded into toll fraud on the phone network as we know it. And it wasn't like today where we found the vulnerability, we could just go patch it. I assume changing the infrastructure was monumentally or impossible, monumentally difficult or maybe even impossible.

Yeah, I mean, it was a physical replacement of phone infrastructure to go from in-band signaling to out-of-band signaling using SS7. And so, you know, there was, I remember we were doing investigations where there were still what's called a crossbar network where, you know, it simulated the operator plugging one one hole and plugging another hole to create a circuit between 2 people. And a crossbar network would do that. It would be these 2 little plates that had those little hooks, and they would pick up and move and connect. And so, you know, there were little cities and large cities that had to replace their entire network to get out of billions of dollars of cost and phone fraud.

Yeah, that's amazing. So you were at MCI, it looks like, through about 1998.

During that time, did you see an evolution of the bad guys, the hackers, from being those 13- to 17-year-old kids to being something more professional, or was that not for another decade or so? I'd say it happened fairly quickly. I mean, so I took a job. I was at TimeNet— MCI purchased TimeNet, and Vint Cerf, who ran the data division, brought me— Vint Cerf, the father of the Internet. Vint Cerf, the father of the Internet.

He ran the MCI data division. He brought me to Virginia and wanted me to— and MCI just was awarded the contract to be the first company to commercialize the Internet backbone. At that time, the US Internet network was operated exclusively by US government interests. MCI won the contract to get the first public Internet bid. We ran the first cybersecurity division of that public Internet.

Vint brought me over, and so we had the X.25 network that was slowly being moved over to the Internet, and then we had the Internet Network, which was based on a frame relay backbone.

We built a global backbone in a very, very short period of time, less than a year.

We worked with a number of government agencies and with a number of research agencies to create some of those initial fundamental models about how to protect router infrastructure and DNS infrastructure and so on from the sort of global footprint. But what I'd say is the first handful of years of that was still— the white noise were the kids, right? Just the volume of attacks and We were pretty proud that we could audit our entire infrastructure every 24 hours, but we were getting scanned every 6 seconds.

They were finding weaknesses in the architecture long before we could. But it quickly transformed. I'd say within 5 years, we were battling organized crime syndicates who were trying to make as much money as they could off of compromising e-commerce sites and endpoints. When would you say it transformed into that organized crime versus the kind of amoral hackers? Yeah, I'd say it went from the Hacker Manifesto years to more organized crime, I'd say mid-'90s.

Yeah, that is pretty early on. Yeah, I mean, the advent of DDoS attacks, I think, in my personal experience, the advent of DDoS attacks— so DDoS attacks were used mostly for vandalism purposes and creating notoriety of the hacker era, but bad guys saw that as a way of holding companies hostage pretty early on. And so we saw there was a DDoS attack that time called a Smurf attack, which was a very popular DDoS attack at the time. We saw organized crime syndicates using tools that they found off the internet, written by kids, and then commercializing that in order to ransom e-commerce sites before they knocked them off the air. So it's been 20-plus years of ransom is what you're telling me.

Right, yeah. At MCI, we actually launched— we released public domain tools that other backbones could use to trace DoS attacks because it was all forged IP address traffic at the time. Well, let's move forward. It looks like you were at MCI through about '98 or so? Yeah.

What caused you to leave there and move on? MCI was purchased by WorldCom, and we sold And as part of that deal, the government required that MCI sell its internet assets to Cable and Wireless.

And so the company kept Vint with WorldCom and kept me with WorldCom. We were the only 2 data assets that didn't get sold off. So my job was to separate the company and then I worked for WorldCom for about a week and couldn't take it.

When did things go really bad? Was that 2001 that things— that they got the front page of a bunch of newspapers? Yeah, that was— yeah, I mean, not— I mean, a couple of years later, Bernie's management. So Bernie Ebbers, who ran the company, his management style was, was, was very involved and very direct. Yeah.

And And so we were changing policies like, you know, we had all the nice amenities that you would want in the break room, free coffee, free tea, and that was immediately gone. And then if you were traveling to a city at the same time that a colleague was traveling to a city, you both had to stay in the same hotel room. That's a common thing among some tech startups these days. I wish it would die a horrible death. But that is something that techs— not Ping Identity, if you're thinking about a new job.

Don't worry, we don't make you do that. So yeah, I just— it's just a culture and environment I couldn't— just did not work well for me. And so I moved on. All right. So it looks like Level 3 was next.

So talk to me about that. Yeah. So no, actually, what's interesting, I don't have this on my profile. I left WorldCom and went to Qwest for a year. And so Qwest had just purchased LCI, which was a small regional internet provider.

And so I worked out of Arlington and worked there for about a year. And they wanted me to move to Denver. And so I had a moving van in my driveway and I had a pregnant wife, and I went to Denver to meet Mr. Nachio. Yeah. Met Mr. Nachio for about an hour and walked out of his office and quit.

So it was pretty obvious pretty fast. It was really pretty obvious where he was headed. And so where he was headed was prison. Yeah. And so I, I got in my rental car and I drove to Level 3.

Most of the MCI folks that I knew were at Level 3. And so I showed up unannounced, unsolicited at the front door wearing a suit and asked for a job and was hired on the spot. So holy smokes, called the wife and said, I got good news and I got bad news. You know, bad news is I don't have a job. Good news is I just got a new one and the moving van's going to the same location we thought it was going to just a few minutes ago.

That's hilarious. So were you hired in there as a chief security officer, or did you work your way up to that? No. So at the time, I'd say Level 3 was a fairly traditionally structured telecom company. So they had a security organization for corporate and a security organization for production.

And so I took responsibility for the production side of the house.

They didn't have an officially named CISO in the company. It wasn't until much later, 7 years or so, that I had a proposal to combine all of that together.

It saved the company some money, but it also— the whole proposal was The bad guys were starting to look at us as a single threat landscape, and we were still protecting ourselves as siloed-based organizations. We needed to start looking at our assets as if it was a single threat landscape. That was the proposal to combine all those things together.

I'd say it's never a perfect decision, right? Because every company— we were a pretty flexible security organization because we were embedded in the technology groups that we supported. That had a significant number of advantages. The disadvantages is that it takes a lot of effort to be aware of the total landscape that you've got. If someone was trying to break into a production system, but they were trying to do it through corporate email phishing attacks, that required at least 3 groups to be talking to each other to make sure that they were aware that that was all going on.

So yeah, we combined it, and then I became the CSO because we also had physical security responsibility as well. You were there for a long time. It looks like you were there for about 18 years. 18 years, yeah. Things have changed a lot between '99 and 2017.

Talk to me, give me some examples. What are the biggest things you saw change at a company like that? Obviously you guys grew a lot, but what were the big changes to the way things worked from a threat perspective, or, or your job day to day? My job day to day, um, I'd say, um, the biggest evolution that, that we really had to learn was, um, how to become a business advocate.

What I'd say is it became pretty painfully clear that if you were approaching security from a security academic perspective, you must have this length of password, otherwise the risk is too great. Then the company would say, no, we're not going to have all of our users type in a 28-character password. Are you kidding? Okay, then you accept the risk. And I'm going to go back to the group and say, the company said.

We saw too much of a trend of the company said mentality. I changed the leadership team pretty substantially to go from more of a technical organization to more of a business leadership organization and sort of talk to the company in terms that the company could understand. We ended up being our own risk advocates. We would evaluate the investment level and what it would take to protect the company and how much it made sense based on the culture and the investment. Then we'd go to the company and say, here's what our peers are doing.

Here's what we should be doing. Here's what we think the investment cost is. Here's your 3 options. Here's the academic option. Here's the we just take the risk option, and here's the option we think we should go with.

That really transformed the way that we did security. Instead of us relying on management to make investment decisions, we were given a lot more freedom in being able to employ whatever security measure we thought was appropriate, because they knew that we were taking the business into account in that process. It gave us a lot more empowerment, transformed us from a victim mentality organization to a very empowered organization, and really sped up the process of implementing and maturing security controls. I think you just said some really great things, and I want to spend a few more minutes talking about it because I think it'd be easy for folks to gloss past it. I've had the opportunity to run security at a few organizations.

I haven't had 18 years at a place, so I've had a few more than you. I'd say that when you get a bunch of us CISOs together, the general way we talk is saying something like, it's a business decision, they need to make a risk, and people will talk about the form they created that someone's going to sign to accept that risk. Hypothetically, before you've done it, it sounds like it makes sense, right? And then you get into it and you see what, what you're creating by putting— by operating that way, and you're creating an organization that they don't like, that they don't want to work with. And they don't want to work with you, you're not very effective, it's not serving their needs, right?

At the end of the day, regardless of who you, who you say is choosing to accept the risk, when the business looks to you and says, should we do this, Robb? Should we not do this, Drew, you— your answer is then how they decide the risk, right? So stop pretending that they're the ones doing it. Be willing to admit, hey, I am, I am a part of that risk decision. Maybe I'm not the only part, but you're a big part of it.

And for the— for 95% of the time, you are the one doing it. Then there's the 5% where you say, listen, we're just— we disagree, let's escalate it, let's get to the point where somebody above both our pay grades should make this call. Exactly right. I mean, I've worked in security organizations where the security group really has no idea the services and products and the customer base that the company themselves deal with. They are there just to apply the security discipline on whatever widget, box, function, app, or piece of data they have.

The same way they would do it in an accounting firm or in a manufacturing company or in a hotel. Exactly. It doesn't matter where they are, right? Exactly. So, you know, so making them aware of the business, of what products they sell and why they sell them, what markets they're in, and, you know, what customers they have and what the concerns of those customers are really makes them more integrated with the business and be able to speak business terms.

And so, you know, you say you are You are a business leader in this organization. Your function is security. Those 2 things are sort of the position that you need to be talking from, and it gives a lot more comfort to the business.

You were there at Level 3 for a long time and did a lot of great stuff. I don't want to brush it aside too fast. I want to give you a chance. Are there things you're most proud of having accomplished in your time there? I know you guys did a lot of work on— after the Mirai botnet, did a lot towards shutting that down globally, and I'm sure you've done other really cool stuff.

What have you done there that you want to share with us? I'd say the 2 things I'm probably the most proud of at Level 3 are 2 things. One is the team. We were able to build a really good technical and management organization that, again, was really integrated with the business, but was also able to really mature the program over time. Not only were we focused on all the fire drills of solving all the things that the business was doing very dynamically and quickly to create new products or MacGyver things together to provide solutions for customers and try to figure out how to protect all that stuff, but we were also able to mature the program as well.

Really, really important to, to, you know, for the team to have a discipline of not only, you know, in that wind tunnel environment, but also take that step back and say, how do we make that control more, you know, more mature? How do we make it more automated? How do we get better at detecting? And so I think we did a really, really good job at that sort of maturity model, and, and I felt really good with that. And I think the other thing that, that, you know, I'd say probably the last 5 years or so of my time there, we really focused on making the community better.

We were so focused on protecting our asset base and our backbone.

We made a very cautious decision. We went to executive leadership. We went to the board of directors. We said, We want to do things that are going to make us a bigger target. We want to stop bad guys proactively, not just ones that are impacting our network, but ones that are impacting other networks and other customers who have nothing to do with our backbone.

We don't want to be too public about it. We're not doing this to sell a product. We're doing this because we want to make the internet better. And so we want to protect the brand of the internet. And so we got very surprising but very strong support from both the leadership team and from the board of directors.

And so we started a campaign to collect a— we were using NetFlow, right? So we were collecting NetFlow and applying artificial intelligence algorithms on it to look for— to model the behavior of traffic and look for deviations in that traffic, as well as look for specific traffic behavior of known bad guys, organized crime, nation-states, and all that. And when we see it, we would stop it regardless of where that traffic came from. Some nation-states are a little closer to home than others, right? You know, I mean, we operated in quite a few countries, and so, you know, we would be blocking traffic from a number of nation-states that, you know, we were rather close to.

And so, but, you know, but our goal was to stop bad traffic. Yeah. And so, you know, we did a really good job at it, and they're still doing a very good job at it. I didn't didn't stop when I left. But, um, those, those are the 2 things I'm probably the most proud about.

That's great. So in early, uh, 2017, uh, CenturyLink announced the intent to acquire Level 3. And was it November of 2017 that that closed and, and you moved over to being a part of CenturyLink? And you want to talk— it wasn't a very long stint. You want to talk about what happened there?

And, uh, yeah, so we, we We sort of split. Dave Mahan was the Chief Security Officer of CenturyLink. He remained the Chief Security Officer of CenturyLink. We sort of split the security function. I was the Chief Security Strategist, and I ran all the managed security functions.

All the architecture, engineering, and the operations of our managed security functions, firewall and threat intelligence. That's what Brent Wentworth was doing, right? Yeah. Brent runs the security operations centers for the agency. We did have Brent on the show 6 months ago or something like that.

Yeah, I think he talked about his fish tanks for 40 minutes. Saltwater.

I love Brent, by the way. I'm just giving him a hard time. I ran the managed security side. Dave ran the corporate security side.

Shortly after integration was— or the combining of the companies was complete, Dave moved on to a position outside the company, and I moved on to a position outside the company. Um, and that's how I found my way to, uh, Zayo. Yeah, I remember we were all wondering during the integration which of you was going to end up being in charge, and, and then neither of you ended up sticking around. So I think we all lost money on that bet. Uh, yeah, so you're at Zayo.

You know, Zayo is a company that everyone should have heard of, but you guys are, you know, young enough, um, or at least, you know, the name recognition is young enough that people might not have have heard of Zayo yet. So maybe just a high-level summary. What do they do? Yeah, so Zayo is a Boulder-based telecommunications company. I'd say, you know, they're a full-range telecommunications company, meaning that they do pretty much everything but voice.

They, you know, anything with fiber. So a very large metro fiber footprint globally. And then they then they deploy services on top of that fiber footprint. And so we have colo services, you know, where we'll host, we'll provide the physical environment for customers. There's a cloud or an enterprise environment where we have AWS-like services where we'll provide compute and storage.

We offer internet services, Waves, Ethernet, you name it. So a pretty wide variety of transport services as a traditional telecom, as well as enhanced services like managed security, colocation, and compute storage. And which you guys grew mostly through acquisition, right? Yeah. What was the big Denver company that you guys acquired, like the data center nearby that I'm familiar with?

I'm trying to remember the name of it. I'm trying to remember the name of it. I could probably tell you before you asked me that question. Yeah, the company's had 48 acquisitions in 3 years. Yeah, yeah, yeah, a lot of growth.

So you came in as Chief Security Officer for Zayo, right? That's correct. And are you the first security officer there or are you replacing somebody or what? I'm the first security officer for the company. They have a security function today.

Zayo is a little different. So there's Zayo Group, which is the parent company, and then there are different operating companies, self-contained operating companies underneath. So there's a fiber services division, there's an enterprise division, there's a Zicolo division, and they have a president and HR and financial and the whole bit. And so I work for Zayo Group and I protect all of these sort of operating companies underneath. Okay.

And I'm doing things a little bit differently. I asked the company to indulge me in a bit of a social experiment. And so I, when I came on board, I also took on the IT infrastructure. So I own the corporate data centers.

And then I also own the corporate network. Okay. I've got the privacy function, I've got physical security, I've got logical security, but I also have essentially the IT infrastructure and the corporate network infrastructure. That's definitely broader than you get for most CSOs out there. Yeah.

I don't know if it's going to stay with me forever, but it's It's definitely the disciplines that you have to implement on top of an IT infrastructure for inventory and availability and confidentiality. Patch management. Patch management. Those are all the disciplines that the infrastructure team has to do anyway. I don't own the applications.

The actual IT organization owns all the applications that that reside on the systems. I just own the infrastructure.

From a security discipline perspective, it's great. There are no conflicts and discussions about what's best for the company. We've combined those interests together. For the infrastructure side, it's great because they're able to lead through through a discipline that they need to manage their infrastructure anyway. That's great.

What are your biggest priorities there as you're building out a team? You've been there for 4 months. I've been there for 4 months. What are you prioritizing right now? I'd say everything at once.

My primary objective has been to assess— anytime that you land in a new spot, and of course it's been 18 years for me, so But anytime you land in a new spot, the objective is understand the culture of the company, understand what makes the company operate from a business and tactics perspective, and then perform a risk assessment and meld those 2 things together. Sounds right. Yeah, so I spent a lot of time with the finance organization. What's the investment strategy of the company? What's the the sort of run rate and where do you put money in, how forward-leaning are they on investments, what's the vocabulary the company uses when they want to do an investment, making sure we're talking the same talk and building a business case the same way.

And then while you're doing that, you perform a risk assessment.

You do a control assessment and a gap analysis and build a roadmap and off you go.

A lot of really good controls already in place. We're just prioritizing based on risk. There were some places where they were investing a lot of resources and very little risk, and some places where they were investing no resources and a ton of risk. Getting the right balance of that. Anything you're willing to share about priorities, the things that you really want to focus on next year or so?

You don't need to get too in-depth, but high level. Well, I'll say a few things. My big thing right now is beyond Zale. It's industry-related. I'm going to be like the guy in his lawn shaking the cane on this one.

When I was at Level 3, we built a compliance organization, a governance, risk, and compliance function.

The initial goal was to be able to answer customer questions about transparency of security, and then that turned into more of a formal governance, risk, and compliance arm to test the effectiveness of the controls and so on. I'm doing the same thing here, and I'm dealing with a lot of the same customers I've come to the conclusion that governance, risk, and compliance is broken because our customers force it to be broken. Here's my frustration. Again, this is just my perspective, as uneducated as it is, is that in almost every other security discipline, for the most part, there are industry-accepted practices that you could develop that assess what you need to do and then provide guidance on what you should do and provide guidance on the methodology in which you could do it and then provide guidance on the methodology to test the effectiveness of what you've done. Okay.

Right, and the nice thing about that is depending upon the approach you could take, it could be somewhat independent of the guy who sits in the chair, right? How I'm building the program now, if I am not there, somebody else could come in and there's a relatively reasonable industry standards approach to how we're doing things to where they could just take over and everything sort of resonates and makes sense. And, and that, that, that makes me feel good, right? It's no one's particular religion, right, that, that is, uh, dictating how things get done. Yeah.

And so same people sitting around the table, they'll, they'll have the same decisions made every, every time. When it comes to things like compliance, there are industry-accepted methods for how to get security certifications and how to provide transparency, but in an organization, a telecommunications organization that serves a wide variety of industries, every industry has their own requirements on what portal you use, how much transparency you provide, what the scoping of the security certification you have, how much of that is acceptable to them. There's no way to wash, rinse, and repeat in that field. There's no way to build a predictable model that satisfies the concerns of transparency to the industries that you deal with. You have very, very large financial institutions that are so practiced at this function that it's a separate biological entity inside that company, and it's completely independent from a power decision process than any of the other organizations they have.

And they run— they get to dictate and decide how much security they get to have. I'll give you an example and I won't name who it was. We had a large financial company that decided we were a critical vendor. We were providing waves. We weren't in possession of any of the data, but they said from an availability perspective, we are a critical vendor.

As a critical vendor, we have to abide by their security policy and their security controls at their risk level. We had no choice, so we said, Yes. During that risk assessment, one of the findings— and there was some findings, but one of the findings that I will walk away with the memory of forever was they said, you do fire drills twice a year, and our requirement is you do fire drills 4 times a year. You have 30 days to implement a new procedure to do fire drills 4 times a year, or we will mark you as materially deficient. That is a broken process.

It has nothing to do with the security of the company or the service we're providing or the risk they're taking. And we had to implement fire drills 4 times a year. And so, um, how silly it is. It's very silly. And so I'm— I am on a campaign.

I'm on a campaign to, uh, uh, to either, um, complain about it until I'm exhausted and, and can go on to something else, or until that, that we can get agreement of creating a predictable model that people can follow. I support you 100% on that. It's not easy. We can get things like the SIG and obviously local companies, CyberGRX, trying to offer some third-party assessment, but the problem is these big enterprises who just will take nothing but their own process. It's going to make it tough.

Well, we are running out of time here. I want to give you the chance. Is there any Anything else you want to share about your experience here in Colorado over the last 20 years or the community you've been a part of? Anything else you want to go into? Yeah, I mean, quickly I'd say I'm really, really impressed with the growth of not only technology sector but the cybersecurity sector in Colorado over the past 20 years.

When I got here, it was Webroot.

And now, I mean, Colorado is a beacon. It's a model for cybersecurity companies. And so the growth has been explosive. What's nice about that is that there is definitely a Colorado culture where people are a lot more open, they're a lot more cooperative, they're a lot more involved in the community, and a lot more willing to share ideas and failures. I mean, not only is it is that, you know, on the East Coast it was— we couldn't talk about vendors we used or whether they were good or bad because we might be endorsing or, you know, vilifying them and we might be liable for taking market share.

It was horrible. It was a bad environment. But here it's, you know, people really want to do the right thing for the right reasons to help the overall community. And I've been very, very happy with that. That's been great.

Yeah. Well, Dale, thanks so much for your time. I think we could have gone another hour here, but we're running short on time. Maybe we can get you 2019 and see what you've done and hear about the awesome stuff you're doing there at Zayo. Yeah, I'd love it.

Cool. Yeah, thank you very much. Thanks for your time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes