All episodes

John Everson, CISO of Afiniti

Apple Podcasts Spotify SoundCloud

In this episode:

John Everson, CISO for Afiniti is our feature interview this week. News from: Denver Airport, Colorado.gov, System76, Ping Identity, Automox, Red Canary, Threat Stack, InteliSecure, LogRhythm, CableLabs and a lot more!

All the single ladies love Denver

We couldn’t land Amazon, but Denver does land the single ladies. DIA is the best large airport in the US (and getting better). Our state website is pretty great too. And our economy is growing like crazy. Some insight on System76 bringing their computer manufacturing to Colorado. Ping Identity hires some execs. Automox raises money. Red Canary partners with Threat Stack. InteliSecure releases their big 2018 report. LogRhythm holds themselves accountable for their predictions. And CableLabs releases Micronets.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10818 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

All the single ladies, all the single ladies, all the single ladies, all the single ladies, all the single ladies, all the single ladies. The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Rob Rack and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 93 for the week of November 26th.

And if you're wondering what was that music you just heard, well, we're going to get to that in a little bit when we get to the news. But first, this is Robb and I am solo this week. This is the first time we've ever had just one host on the show. Alex is out of town and I just got back from my own vacation and didn't have time to get a co-host for us this week. So I thought rather than depriving you guys of yet another episode of the show, we'd go ahead and roll with, with just me by myself.

Before I dive into the news, go through a little bit of housekeeping. We do have a few things to mention. We have a Slack channel. If you're looking for an opportunity to chat with folks, if you're looking for a chat room for security people in the Colorado security scene, this is the place for you. You can join the Slack channel by going out to the, to our website, colorado-security.com, and clicking on this, the Join the Slack button.

We also have a mailing list on the same website, colorado-security.com. Go to the bottom, enter your email address, and you will have the show notes delivered into your inbox every week. If you were on the mailing list this last week, you would have got a special thank you or Thanksgiving note from Alex. We do appreciate all those who subscribe and listen to the show. Obviously, we'd love it if you'd subscribe on your favorite podcast listener.

Of course, rate us and say nice things about us on there so we can find new listeners. If you want to even do more than that, if you want to do more than just put a note, we'd love it if you tell one of your coworkers or friends about the show and help us get new listeners. And of course, if you want to go that extra mile and support the show financially, we do have a Patreon campaign. You can go to our website and find Patreon. We would love it if you do that.

And a big shout out, big thankful to those people who are helping support the show right now. We really do appreciate it. All of the money that comes into that goes right back into the security community through the podcast and the other stuff we do here in the community. With that, let's go ahead and dive into the news. Number 1, so if you're wondering why did we get to hear all the single ladies, well, Denver made the top list of cities for those single ladies who are career-minded.

This is a list that was put together of the top 20 cities for single career-minded women. Denver came in number 18, so we didn't lead the list, but hey, all the single ladies do apparently like to come to Denver to get a job. Take a look at the news on that one. Next show we have is that Denver International Airport is the number one best big airport in the nation. So we, we've come a long way from that airport that was opened about 20 years ago to, you know, maybe not such good reviews with baggage issues.

At this point, Denver International Airport is, is the number one big airport around. This was rated on, I'm looking this up here, this was rated on security, wait times, the on-time arrival, average fares, and reliability for, for the flights. So basically, you know, all around, DIA has done very well. If you dive in into what is the convenience score here, we actually talk about like Wi-Fi speeds, the Yelp ratings for airport restaurants, the in-building walking distances between stuff. Anyway, on all these things, Denver came in no lower than 4th.

So we did very well on that. And a big shout out to the folks over there. And of course, Tim Coogan, our friend who is the, the CISO at DIA. Congratulations to that whole team. Next story, as we talk about accolades piling up for the local Denver stuff, the colorado.gov website, which is the official site of the state, was ranked as the 5th best, best site in the country.

They rated this on 4 criteria: the page load speed, friendliness, security, and accessibility of it. We ranked highest in page speed, accessibility, and security. Another shout out to security here in Colorado. Um, this is also kind of— it got a little bit confusing. They also combined some of the scores from services within the, the state.

So if you look at like different services you can use from the state, like DMV and other stuff, that was combined as well. But overall, uh, Colorado has done very well. So a shout out to the OIT. That's, um, that Ms. Nadapalli, who's, uh, who's our CIO for the, for the state, and all the good work they're doing over there. All right, uh, we have some, some good financial economic news here for, for Colorado.

Uh, in, in the second quarter, which is the, the numbers that are just coming in right now, Colorado, uh, grew at, uh, one of the highest rates we've had in quite a while. Um, so we grew at a 4.9% increase in Q2. Uh, this is the best in over a year, um, and it puts us as the 5th highest or fastest growing state in the country. We're behind Texas, Michigan, Missouri, Minnesota, but we're ahead of lots and lots of other good states. And we're also above the U.S. national rate, which was at 4.2%.

So congrats to us on that. Looking ahead, we have a story in the news this week about System76, which is a local company that's brought manufacturing of PCs here to Colorado. So they have been around for a long time. They're a Linux and open source-based software for their systems, but high-end systems that they had been building, building overseas. They brought manufacturing into Colorado.

So it's a really interesting story talking about why they might have done this. There's actually some interesting facts, not just about them, but about the manufacturing scene in Colorado overall. It is a $23 billion industry in Colorado. It actually brings in more revenue than tourism does. We have about 6,000 manufacturers in Colorado.

That's, that's a lot of little companies, not a lot of huge companies, but a lot of little companies in town. About 80% of those companies employ 20 people or fewer. And there are about 140,000 people who work in manufacturing jobs in Colorado. So really, you know, while we think of, you know, importing a lot of stuff, it's cool to know that there are so many things being built here. As you looked at why did System76 choose to start manufacturing in town, they gave a couple of stories.

Some good examples of things that they've had. But, but basically they've had these problems where the hardware that they get from manufacturers overseas, they're just not able to keep up with the demands and the speed that they need for these high-end systems. So they're not making, you know, cheap commodity systems. They want to make high-end, high-quality systems, and they don't want to have— they don't want to be limited by the, by the power buttons that this manufacturer has overseas, or the inability for them to put, you know, 2 processors in this, in the same chassis. So really cool stuff where they have decided to do it in-house and really a lot of flexibility from it.

They're not looking to be the, the lowest cost. They're looking to deliver a really high-quality product. So anyway, if you're looking to hire a— to buy a high-quality PC and you're interested in maybe a Linux one, take a look at System76, the Colorado choice. Moving ahead here, Ping Identity has a press release this week. We hired a couple of new executives over to the team.

Actually, one of them's a new hire, one of them's just an internal promotion. Bernard Harguindaguy is the new Chief Technology Officer for Ping. We actually had Bernard join the team as he was previously the CEO of a company called ElasticBeam, who Ping acquired back in May. He's now been moved over to the CTO position where he's helping really drive intelligence throughout the entire Ping product portfolio. And the other new hire is Richard Byrd.

Richard is the new Chief Information Excuse me, the Chief Customer Information Officer. So he's the customer CIO for us. I maybe also call it like a field CIO, working with our customers, working with the larger industry to talk about how does identity work in the industry. We got Richard from Optiv, so another Colorado company, and he's going to be working for Ping here in Denver. So a couple of cool things, and welcome aboard, Richard, and of course, congratulations to Bernard.

Next, Automox, who is the Boulder-based security company, has raised about $9.3 million in a new round, which is going to allow them to grow quite a bit. So, you know, looking at what they're doing, Jay Prassel— we had Jay on the show a few months ago— he said that the money is going to be used to allow the company to add about 20 people in 2019 to their current 32-person team. So, you know, really, you know, a good 70% increase to the size of the company. They did just recently move to a 6,000 square foot office in downtown Boulder, which is 3 times the size of their previous office. So they are investing for growth and they might be, you know, the next big success story here in Colorado security.

Looking forward to seeing Automox grow. Next, speaking of success stories in Colorado security, Red Canary released a press release this week. They are partnering with ThreatStack to offer an agent-based solution for It's basically— all right, talk about— we talked about Red Canary on the show lots of times. They do a managed detection and response where they'll, they'll monitor like your Carbon Black or CrowdStrike type logs. ThreatStack is another solution, but rather than being like a laptop or workstation one, it's really meant for Linux servers and especially meant for those servers in AWS or in the cloud.

So they're, they're now partnering with Red Canary ThreatStack and Red Canary are working together to get those agents feeding into Red Canary's machine learning algorithms and providing that managed detection for their customers. I'm a big fan of Red Canary services, and I actually like ThreatStack's agents as well, so I'm really glad to see those guys come together. I think it's going to be a good thing. Next, we have a new study from InteliSecure. They have released their 2018 State of Critical Data Protection report.

They've done this in the last couple of years, and It's good to see the summaries here. I'm not gonna read all of the details out of that, but a couple of key findings from the corporations they talked to, 75% of board of directors are now holding a C-level executive responsible for security. This is 33% of them say CEOs, 42% say CIOs. So it's neat to see that increase of companies who are really now holding someone accountable. There were a bunch of takeaways.

You know, they talk about the need to identify where your sensitive data is. Of course, this is a big part of the, the backbone of what InteliSecure does, so of course that's going to be their key takeaway, right? But, but I do think they're right. We want to be focusing on knowing where your data is and putting the right controls around it. They also want to talk about the need to have a, a recurring program where you're not just, you know, putting a policy in place but actually monitoring for effectiveness and, and making sure that you're, you're continually protecting that data.

So there are a bunch of other cool findings in this report. I recommend you guys take a look. I'm not going to go through all of that right now. Next, LogRhythm has a, has a year in review from their predictions from last year. And I think they actually did the same thing last year.

They talk about what their predictions were for the year and then talk about whether they got it right. I think it's fun to do that and wish more companies would spend time talking about what they got right, what they got wrong. They do talk, you know, one of their predictions was that there was going to be a new record for largest breach. They got that one on the head. There are a number of very large ones this year, and the year itself was the largest ever.

They did have a prediction that the US was going to have legislation around privacy, you know, kind of a GDPR for the US. They missed on that one. You know, there's some stuff going on, but no national law at this point. They had predicted that there would— the cyber war campaigns between the US and North Korea were going to move from the shadows and directly impact the the public. I would say that they, they had a swing and a miss on this.

While there was some talk about it, you know, and certainly North Korea is still doing some bad stuff out there, this is certainly not moved out of the shadows and into the public. They predicted the IoT was gonna be a more common target for ransomware and cyber extortion. They call this a win. I, I don't know if I buy it. Uh, you know, I'm not saying that there's none of this.

I don't think it has become a significant source of extortion and ransomware. The IoT itself is still relatively untapped in that market, in my opinion. I haven't heard a lot of campaigns where, you know, someone's Nest or Ring doorbell is, is now, you know, being ransomed, which I really think was kind of the gist of the prediction initially. They do say that denial of service is going to become a— or denial of service as a service is going to become a thing, and people are going to start selling that as a service. I think that that's That's true, you know, people are certainly able to do that.

We see that happening in the market, so that looks like a hit to me. I'm actually not going to go through all these, there's a few more on here, but I'd say overall, you know, about 50/50 between what I think is, you know, on the money and some stuff that were a little bit too optimistic or a little too forward-looking. Last piece of news for the week, CableLabs has released a new standard, they call it Micronets. It's It's interesting. So when I first saw it, my first thought was, you know, well, all this is is basically network segmentation for your home.

And then I got excited because it basically— what it is is it's micro-segmentation for your home that doesn't require you to be an IT person. It's— they've created technology or a standard for technology that'll help identify what devices are connecting, and it'll segment those devices based on that. So if you're talking about like a you know, a connected thing, if you're talking about a smart refrigerator, it's going to segment that off from your, your laptops and from your, you know, your more sensitive devices and kind of create some dynamic, transparent to the user segmentation so that if something gets compromised, you know, it's not able to move between them. It's a really cool idea. I'm really looking forward to seeing does this get implemented and does it work?

But good, you know, good work to the team at CableLabs who's, you know, doing good research in town. And thanks to Mike Glennon for sending this over to us. That's it for the news for the week. Moving over to our Slack message of the week. Thanks to Andre Gaeta.

Andre, I know you are enjoying Hawaii right now and the beautiful scenery out there. Appreciate all you do to help support the show and hope you're enjoying your vacation. This week we want to do a recognition for Brian Becker. Brian had a comment in one of the great threads in the last week or two about IT after 40. So he shared a thread that came from Reddit.

Which is this really interesting conversation about— from IT people talking about what it's like to be doing IT, you know, 20+ years into your career and how things have changed. It got some good conversation on the Slack channel and it was a really good read. So anyone who's either, uh, either maybe in their 40s or later, or someday might be in their 40s and later and still working in IT, I think it's worth taking a look at. Moving over to our events— oh, sorry, also Brian, of course, will get the a piece of Colorado Equal Security swag, and we do thank Andre for sponsoring that. Moving over to our events for the next couple of weeks.

As a reminder, we have an event calendar on the website at colorado-security.com. You can see all the stuff coming up for the next few months. On the 26th of November, SecureSet has one of their Denver War Games events. This is Applied Cryptography 2, so this is a continuation of what they did a couple weeks ago. On the 28th, Denver's Densak is doing their November meeting at the Rheinhaus.

That's downtown. On the 20— also on the 28th, uh, SecureSet is doing another Denver War Games. This is Network Security 1, focused on ARP poisoning. Um, also on the 28th, a lot of stuff going on that day. ISC² Pikes Peak down in the Springs is doing their November meeting.

On the 30th, there's a lockpicking event at the Kivu offices. So this is a chance— this is really informal. They've— this got organized on the Slack channel. Uh, Douglas Brush is been nice enough to volunteer their office space to do the lock picking event. This is a chance for you to come and meet people and learn how to pick locks.

Not a lot, there's no program, just some socialization and, and some picking locks. So chance to go do that. That's on the 30th at Kivu. Also on the 30th, SecureSet is doing their women's only intro to capture the flag. So if you're a female who's maybe been intimidated by the fact that it's really a lot more men than there are women doing these things, here's your chance to go and, and learn how to do capture the flag without having a bunch of guys around there taking up all the space.

And I think that takes us to the end of the next 2 weeks. ISSA Colorado Springs does have their chapter annual awards on the 6th of December. And I guess one last thing here, Colorado Springs Cybersecurity First Friday social and mixer is happening on the 7th. So all these events are on the website. They're also in the show notes.

Take a look at that. Jumping over to our jobs. At Ping Identity, I have a couple of positions open on my team. First one that reports directly to me is a security program business analyst. This is someone kind of working hand in hand with me, keeping track of all the stuff we do, doing metrics, doing financial work, doing some communication, some awareness type stuff, a lot of hands-on helping me run the program, good exposure.

If there's someone who has a project management background, program management background, business analyst, and looking to get more into security, this might be a good opportunity for that person. We're also hiring a GRC analyst who's focused on business continuity and incident response. So if you want to be focused on those things and help run those programs within Ping Identity, here's your opportunity to do that. We have a few big leadership roles here coming up as well. So the Colorado Secretary of State is hiring a CISO.

We've had Rich Schliep on the show previously. Rich was the CISO. He was promoted to be the CTO there, and they're now hiring a backfill for the CISO. So that's open, uh, the link is in the show notes. Fort Lewis College is hiring a Chief Information Security Officer as well, and Soma Logic is hiring a VP of Information Security.

This, I think this was open several months ago and we talked about it on the show. I don't know if they haven't hired anyone yet or they hired someone and it didn't work out. I'm not sure, but there is another leadership role there that's open right now. Risk-Based Security is hiring a software security analyst. I have it on good authority that this can be filled in Colorado, although I think it shows Virginia on the, on the job description.

Bank of America is hiring a cybersecurity threat hunt specialist. That sounds like a pretty fun job. And CISO LLC is hiring a maritime operational technology security specialist. It's a mouthful of a title, Maritime, hey, you know, you get to go on boats maybe, or secure boats or something with boats, I assume. Sounds like it could be a pretty fun job.

The Hersheybeck Group is hiring a commercial sales representative here focused in Colorado, located in Colorado. And finally, Regis University is hiring an assistant or associate professor focused on cybersecurity. And that takes us to the end of the news for this week. Tough to do on my own, but I certainly appreciate having Alex around. Looking forward to having him next week.

Hopefully I didn't make it too tough for you guys. Uh, we do have a feature interview with John Everson. John, uh, we, we had him on about a year ago, maybe a little bit more than a year ago, when he was the CISO for Dish Networks. And John has been the CISO for Afiniti, uh, which is a company focused at— or that's a company located out in DC where he's been running security for about a year now. We'll get to hear from him about what it's like to run security there.

Alex sat down with him a week or two ago, and that's it. So appreciate all your guys' time. And we'll look forward to talking to you next week. Hi, I'm Jay Wilson, CISO at Healthgrades. Welcome to Colorado Equal Security, for security professionals by security professionals.

Welcome to Colorado Equal Security. This is Alex Wood, and I have a very special guest today, a returning guest, John Everson. Now CISO of Afiniti. Hey, John. Hey, Alex.

Thank you. How's it going? Good. I left my house, so it's fantastic. You did leave your house.

I'm glad I could get you to come out of the house and see the world. And it was daylight. And daylight. You know, you actually had to drive and get somewhere on your own. You're fully functional.

I had to put on shoes. That's good stuff. Right. So last time we talked to you, and it was actually Robb, I think, I did the interview last time. You were CISO for DISH still.

I was, yeah. I left DISH just over 9 months ago, back in December of '17 was my last day at DISH. Yeah, and so now you are with Afiniti, which is a much smaller company, very different. What sort of precipitated you making that move? Yeah, so I was at DISH for 8 years.

I built the security program there. I mean, they had some pieces, but not under a cohesive department. I did that for 8 years. DISH was a fantastic place to learn and grow, and it's a huge part of this community, so I really enjoyed that, but after 8 years, I felt like I was kind of doing the same thing over and over and over again. Not quite Groundhog Day, but I didn't feel like I was necessarily moving the program forward, and I felt like I stalled out a little bit.

So, plus, I hate to say it, but I'm not getting any younger, right? And so I was looking at either do I retire from DISH in X number of years, or do I try something a little bit different, right? And it felt like it was time to try something something different. At the same time, give someone else an opportunity to come into DISH, put, put their fingerprint, their character on it, and hopefully they'll grow as much as I did because it was a great place. Yeah, I mean, I think no matter how hard we try as, as security program leaders, you know, at some point things are going to get stale and, you know, you, you take certain things for granted.

Maybe you you realize, oh, this thing has been hard that we've been pushing for forever, and okay, maybe we'll just move that down the list because I know I can maybe get something else done. That's exactly right. Trying to keep it fresh, and a lot of it's relationships. Yeah, right. If, if you, if you don't have the proper relationships going into a new role and you can't build that after a couple of years, you probably can't fix that 8 years later, right?

Right. Yeah, you need that other person to leave too, right? It's like Yeah, I need a new person in that role so we can help move this thing along. Right, right. So hopefully someone new comes in, they actually build a different relationship with other key partners, and they're able to move the ball that much further, right?

Plus, when you're building a program for the first time, a lot of the executives that you, you interface with, they may not necessarily understand this is why you're doing it, the rationale. Maybe you don't explain it properly. Right, but having someone else come in and they say the same thing you said, and they're like, damn, John said that too, right? It must be the right thing to do, right? Or even saying the same thing in a different way.

Exactly right. And, and maybe you said that same thing 8 years ago when you were starting the program, and I know you're not the same person now that you were 8 years ago. So, you know, if you were gonna have that initial conversation again now, it would probably be different. It would be a much different conversation, right? So, so yeah, I mean, I think that those are definitely benefits if someone— Yeah, yeah.

Plus, for me, at my young age, this is exciting. I worked for DISH for 8 years, Fortune 200 company, US-based. It was real easy to put in geo-filtering rules that said, hey, if you're in China, you can't talk to me, right? Or whether it was one of the Korean states or whatever. Could put in all these geo-filter rules because that was not where your customers were.

My current company, it's smaller, but it's very global, so I don't have the luxury of doing these very basic rules. So that's been a nice education shift for me. Yeah, so I guess first, maybe tell us a little bit about what Afiniti is and how is it that you got hooked up with them. Were you searching out a startup to to go move to? Did you just sort of run across them?

How'd that happen? Yeah, yeah, it's always, you know, in your career path, is it what you know or who you know? Yeah, right, it's definitely who you know. It was definitely who I knew, right? So Afiniti is a— they call themselves a startup company, they really aren't.

They're about 10 years old. We're almost— we're over 900 employees employees now. So I think it's technically like a medium-sized company, right? 2 years ago we were half that, so we're growing quite a bit. The company has a product/service that is pretty unique.

If you talk to the marketing guys, it's an artificial intelligence engine. You know, this was built on machine learning and data patterns behavior kind of analytics, right? But basically, this is a solution that goes into a large contact center's call routing platform, and it replaces traditional call routing with this new improved AI-based call routing. And the whole goal is to make it a better experience for the person calling in, right, to the person who's answering the phone. Yeah, so is it something like, you know, it'll ask you what it is that you're trying to have you know, help with and it'll point you to the right place, kind of, you know, maybe this queue instead of that queue, or— Yeah, I think, I think every workload sharing, maybe not, not as much as that.

I think every client implementation is a little bit different, but basically it, it tries to derive some kind of a profile based on the inbound caller ID digits, the, the ANI, right? Whatever CRM data the client has whatever public data might be available, build quickly, build a profile around that. And then you've already done the same thing for all your agents on the floor, right? And you try to do like— it's like speed dating, right? Right.

So you try to match personalities, and, you know, hopefully there's a good lift at the end of it. So, so you came into Afiniti. Was this a place where they had a program as established? You were starting it from scratch? What— no, this is— what was— what did things sort of look like coming in the door?

This is all brand new. And this is where, you know, I think that the claims of being a startup company is true, because they still felt like they were in a startup mode. All the resources in the company are all client-facing, right? And if you look in the behind the curtain at the back office, everything running the corporation, it's like a skeleton crew. And there was 1 or 2 people that were doing security functions, but it was largely a compliance effort.

No real security operations, policies, GRC audits, that sort of thing, but less on the technology side. Does that mean that you got to come in and you got to build your own team, or how does that work? I inherited a few people. I think I started with 6. We're up to 8 now.

We're still trying to hire some more.

The resources I have have been really good. Not only have they been with the company for a couple of years, so there's some history there, but on the compliance side, they know all of the ins and outs of the clients, who's requested what kind of requirements, the ISO 27001 7001 audits, they've been handling those for a year, PCI audits. They've been a really good staff. I've been fleshing up on the technical side, making sure we're getting actually alerts, making sure our SIEM is working, making sure that all the endpoint management pieces are in place, all the stuff that the other team felt like operationally we were doing, but we may not have been doing so well. Were doing in a checkbox sense, right?

It was a very compliant checkbox. Something's happening there. We must be fine. We have, we have one. I get, I get logs, right?

Yeah. Stepping back a little bit. So obviously DISH was based here. Yep. Big corporate headquarters here.

Is Afiniti also based in Colorado or— No. And that's really been an awkward shift for me personally. You know, being in a Denver-headquartered company with a lot of employees in Denver, being a Chief Information Security Officer, that was kind of a unique circle and it was fun hanging out and going to some of these sessions as a local boy. Afiniti is based in Washington, D.C., so when we were negotiating for the job, The whole idea was my family and I would move to DC. But as we got closer and closer to the offer, it turned out that the cost of living is a huge difference and it was going to be a problem.

So when I got the offer letter, it was like, hey, congratulations, you're going to work from home. So that part was pretty cool because now I get to stay still in where my family lives and we enjoy this place. I don't want to leave. Colorado, so it's kind of the best of both worlds. But now I've got a professional network in DC where I'm not there 24/7, so I'm trying to build those relationships there.

It's not the same community as it is here. What you and Robb have done is absolutely amazing in the Colorado Denver community for CISOs. Nothing like that. I've not run into anything like that that in DC. So that change is quite a bit different.

And so now I also fly once a month, I go to DC for a week, which is not a bad place to visit. You know, some frequent flyer miles, get your status going, get your hotel points, all that stuff. I did, I did get elite pretty quick. Yeah, sure. So had you worked at home for any significant amount of time prior to this?

Never. Never. DISH has a pretty straightforward policy about working from home. You can work from home in the evenings and on weekends, but not during the weekday. So on your personal time, you can work from home.

Exactly. It's encouraged. But on work time, you can't actually work from home. Right. There's a little bit of flexibility there.

It's not quite that bad, but no, I've never had an opportunity to telecommute, work from home or anything like that. So that's been— this has been very educational. We use a collaboration tool that has— you can buy some dedicated monitors for this collaboration tool. They've got built-in cameras and nice screen. Without that, I don't know how I could get my job done.

But with that, it's like I'm almost having these one-on-one sessions through a screen, but they're There's hardly any latency. It's an amazing experience. Is it sort of like an always-on kind of thing, or is it more like a teleconference kind of— it sounds sort of interesting. Well, there are apps running on your desktop that interface with it. So you can choose to answer a call on your computer or on this thing, this monitor, right?

Because I have heard of some places where, you know, you've got a remote workforce and you basically have a, you know, a video chat with your team or people or whatever, you know, 24 hours a day. Like, it's— or, you know, work time. It's like it's always on. So, right, it's sort of like you're in the same place but you're not in the same place. So it's not— you don't have to make a conscious effort to call somebody to talk to them.

It's kind of like— oh, I see. Oh, sort of like— right, we have sort of an open line of communication. And then when I need to talk to, you know, Joe in Washington, I just sort of turned to the camera that's on the dedicated monitor and go, hey Joe, blah blah blah blah blah blah. Right. Yeah, that's interesting.

We kind of had a little bit of that scenario at Dish. A couple of headquarters had dedicated connections like that, right? So you can walk down the hall and see the other hall, you know, that was in a different location, right? And people walking towards you as It's really kind of weird. We've got a command center at my current company and they've got different locations, so they have these always-up connections.

You can always see what's going on in the other command centers. That works that way, but the solution that I use is kind of an on-demand. It's a videophone really is what it is. The cool thing though is we had We kicked off because next week is Cybersecurity Awareness Month. Yes, it is.

We've got posters. We're starting to do our awareness campaign. We had a meeting of all of the information security coordinators from each of our locations, so Madrid, London, Canada, Seattle, oh, you name the city all around the world. It was my first time being on one of these video bridges with all of these little heads from all over the globe. And it's like The Brady Bunch, you know, all the little— it was, but it was cool because, I mean, you've got people that are— their primary language is French, right?

Right. But having all of these people on the same bridge for a security anything that was not a security incident, that was cool. Yeah, that is cool. Right? And we were talking about awareness and CSAM and all that kind of stuff, so that was fun.

Is there anything in particular that you've either learned or found challenging being at home full-time?

I'll leave the hygiene out of it.

When I was considering this job and I spoke to people, including yourself, about working from home, people who've worked from home, I was seeking their advice. And almost all of them told me, you're gonna work more than you do today. And I kind of scoffed at that because I was working my ass off before. Yeah. And they're right.

Now that— so before I had I had a beloved BlackBerry, right? I finally turned that in when I left Dish last year. Welcome to the 20th century. I know, I know. But, you know, before I go to bed, I would check the phone.

Everything's good. Put on the charger, go to bed, right? When you work from home, you don't do that because your computer's right around the corner, right? So it's like, oh, I'll just shuffle into the office and log into my computer and see what's going on. And then the difference between that, as we all know, on a mobile device there are certain emails, certain things that come through that you're like, oh, I can't possibly do that on a mobile device, so I'll wait till I'm in the office and do it on my computer.

Well, now you just screwed yourself because now you're actually on the computer and you start doing the work that you normally would during the day. And I do that around the clock. It takes discipline. It does. Yeah.

As you alluded to, I'd spent probably almost 10 years working from home. And when I first started doing it, I was, I was in a place where I had roommates. So basically my— we didn't have an extra room. So my office was in my bedroom. And so my computer was more or less next to my bed.

Right. And if I had the volume on, You know, an email would come in and bing, and you know, you know the sound, right? Oh, that's an email. So there'd be times when I'd be laying in bed going to sleep and bing, and be like, oh, you know, I'll just check that real quick. Yeah, and you get out of bed and you check your email and then you're like, okay, um, well, I'm not tired now since I'm sitting here.

Let me work for an hour, right? And then I'll go back to bed. And then all of a sudden it's like 3 in the morning and you're like, oh, I guess I'm not gonna sleep tonight because I have to be up in a couple hours. That's right. And so yeah, it's very dangerous.

Or you hear the ding and it's like 10 minutes later, you're still thinking about it. You're still in bed like, ah, yeah, I'll get up and go check it, right? Well, I wonder what that is, right? And so, you know, later I was able to move it into a separate room in that same place. But even then, it's, you know, you're, you're sitting in the dining room and you hear the ding in the office.

You're like, oh, well, let me go in there and check. Yeah, it's It's just super convenient. Eventually, when, uh, when my wife and I got married and we were in our own place, um, I had my office in the basement, so it was very much harder for me to hear the bings, right? Right. But I still had that to make myself aware that, okay, don't go down to the basement because you're going to start doing work and you don't want to do that.

And my wife was very good at yelling at me and like, don't go down there, don't, you know, come out of the basement, that kind of stuff. But, you know, I thought it'd be more convenient that you could actually do the treadmill or do some weights because I have all that at home, right? But it's not convenient. Even though I moved dumbbells into my office, it's not like you could be on a video conference, right? You just can't do that, right?

Yeah, so I'm not working out. I'm not walking from meeting to meeting to meeting. I've got an unlimited supply of food downstairs. In many cases, my wife actually brings food up to me because she'll hear me on the calls all day long, right? And so I've become a prisoner.

You're gonna have to break out of prison, right? Get scheduled some times for some visit with the outside world. Yeah, so the discipline piece is huge, and I don't have that yet. Yeah, it takes time. But this past week I've done pretty good.

I've got, you know, my Fitbit reminds me to get up. And so occasionally it's at a good time, a good break, right? And so I can walk around the block real quick and come back in and do my work. So I'm getting there. Yeah, I think people think, oh well, if you work from home then you're just going to be constantly doing the laundry or mowing the lawn or whatever.

That's what I thought. And I've— early on when I didn't have a job that was necessarily a lot of meetings and things like that. I did some of that, but the, you know, I'd get up and I'd take a break and I'd go switch the load of laundry, right? But, you know, when you get to the point where you're, you know, on the phone or whatever for meetings nonstop, it ends up being the other way. And, you know, as you were saying, it's like now in the middle of the night I'm doing work as opposed to doing less work.

So, right, it's tough. Yeah, if you're hosting a meeting, you certainly can't do anything else, right? And when I was doing this, there also— we didn't have video as part of it. Yeah, so you could get up and walk around. You know, I had a speakerphone, so it's like, you know, if I'm over here, over there, it doesn't really matter.

If I'm laying on the ground stretching, who cares? You know, no one can see me, right? Right. So yeah, so yeah, working from home is a huge new experience for me. It's been 9 months.

I, I don't have it perfected yet, but my— I finally have my office to where it's comfortable. That's good. And that took a long time. Yeah, it took longer than it should have. Yeah, that can't be overrated, right?

I mean, I've got a stand-up desk that I don't use, but that was, that was like the first 3 months. I needed, I needed something else, and it turned out I needed a better chair because my chair sucked. Yeah. Yeah, but once I got them, once I got my good chair, that was pretty much probably 60% of my office. That's good.

Yeah. So obviously another one of the differences is that you're now with a much smaller company. Yep. As opposed to a giant, you know, Fortune whatever company. Have there been any differences there in either corporate culture or, you know, the way that things operate because it's a smaller startup company?

Yeah. I mean, there's been significant changes in terms of, you know, who you have direct access to. That didn't really change so much, except it's a lot more personable in this company than it was structured in my last company. So really, like, I can get almost all my work done if I talk to the CFO, chief general counsel, and HR, right? And we talk every single day, all day long kind of stuff.

So they're at immediate beck and call, as am I to them. That wasn't the case at the other company because they had tens of thousands of people to deal with. Here we only have a couple hundred, so that's a huge difference. From a security standpoint, the problems are all the same.

I mean, they're exactly the same. It's internet access, visibility, logs, patching, searching out zero days, am I exposed, same kind of problems. It's nicer in that my current product is not internet-facing. It goes into a more secured environment. That eliminates a lot of the midnight kind of stressful calls.

The attack vector, if you're trying to break into us, is much smaller than it was at the prior company. That's a huge difference. At the same time, I kind of miss some of those calls, knowing that you're being attacked versus knowing that you probably are being attacked.

Then culturally, it's been a huge difference too. Most of our workforce is not in the US. Even though we're headquartered in DC, that's where all the C-levels work primarily is out of DC, but everybody else is outside the US. Whether they're in London or Madrid or we've got people in China now, having that kind of a fabric of employee base, different time zones, different languages, different requirements from GDPR or privacy. Brazil's got a privacy law now.

We've got an office in Brazil.

You know, the crazy things like we have to actually feed the employees in Brazil as part of, as part of like the laws down there. Nice. Yeah, it's, it's, that part's fun. Learning all that's been very interesting. Do you see cultural differences in terms of attitudes towards security?

And I suppose that could be a good thing or a bad thing. You know, my thinking from the outside, I would think, oh hey, the folks in Europe, maybe they care a little more because, you know, privacy is a little bit more forward in Europe than it is here. Yeah, you can tell the difference between a developing company or country and a more established— like if you're talking about, you know, anybody in the EU, well, Let's talk about Germany, France, Spain, and soon the UK won't be part of that, but those guys all get it, right? And they're very serious. And the clients that we get from those environments, they have a very lengthy set of requirements that you have to go through, and it's all GDPR-based.

The other developing countries, not so much. They're more flexible and less caring. The interesting thing is, from a workforce standpoint, whenever in my prior companies, which were all US-based companies, in my prior companies, if there was an incident, if there was a security event, if you're investigating something and you're trying to figure out what's going on and you open up a bridge and it's Friday at 3 PM, you kind of expect everybody to hang out until it's resolved, right? It might be Saturday or Sunday, but you guys are all on the same bridge. People might go home, but they're still on the bridge, right?

That's not the way it works at my current company. When, when their time is up, they're like, bye. But they don't even say bye. They just kind of close down and go home. And so you start talking to them and they're like, oh yeah, they're not on the call anymore, right?

Well, it was funny because my first experience was January. So in January when Spectre and Meltdown were announced, and I kept seeing all of these different articles about it, and I was brand new, so I didn't really know the environment. So I opened a bridge, and people are like, why is this guy opening a bridge? So I finally got everybody on the bridge, and we're trying to work through what's our exposure, what's our visibility, You know, blah, blah, blah. And then after— well, most of our workforce is trying to align to the Eastern time zone.

I'm in Mountain, right? So it was probably 5 o'clock here, 7 o'clock everywhere, you know, in DC and such. And I found out that I was the only one on the bridge. Everybody else had left. And they just didn't— they just didn't get that this is something that we had to deal with right now.

Right. They're used to, oh, it'll be there tomorrow and we'll reconvene in the morning. Yeah. So that's been a huge— that's been a huge learning for me as well as for my, my fellow employees. Have you, have you seen any positive differences from, from the different cultural perspectives?

That's a very nice question.

I learn a lot. I'm learning. I'm learning a lot about you know, just different approaches to life in general, religion. I'm learning a lot of different languages. Yeah, that's always— it's, it's kind of a kick.

It's fun for me to be on it. I mentioned earlier being on a call and someone you can tell they predominantly speak a different language, and it's just, it's just fun to kind of learn and interface with that versus here in the US, my experience has always been people who transplanted to the US, and we all speak English, right?

And we all kind of adhere to— sorry, we all kind of adhere to the US traditions in corporate life.

Very good.

So beyond the new job, I know that you're also involved in in some other activities, some advisory work. Maybe we want to talk a little bit about that. First, I know you're advising a couple cybersecurity educational programs. Yeah, yeah, yeah, thanks. Yeah, I've really— it was interesting.

I was asked to participate at my old school, University of Missouri, back in in Columbia, Missouri, and they were building a data science program. And I think what they were trying to do, this is part of their university relations outreach, they were trying to get a better relationship with my prior company in terms of placing graduates, right? That was pretty obvious. They didn't beat around the bush about that. But the fun part was, is I was the only security person on the board advising this program and they were trying to build a new master's program in data science.

I was able to weave in some cybersecurity things, some cybersecurity elements into data science. Like, hey, what kind of datasets are you messing with? Do they contain PII? Do they have encryption requirements? I was able to influence them in that way, so that was kind of fun.

I'm still on that board. They're in their second year now, and so they're starting to spit out some master's degree students, which is kind of cool. The other one that I'm on is ACC, the Arapahoe Community College, and they're trying to do the same thing. They're building a new program. It's cybersecurity-focused.

We're at the very early stages of that, and it's interesting because you get a lot of people from the community in, and they all have their different perspectives over what's important, right? And so you're battling it out in a small room over what's the most important thing about cybersecurity and what, what do you teach these students. And then at the same time, I found out that the, the college is having a hard time, you know, placing students for interns and other things in the community, which is weird because when we meet at the CISO level, we're always complaining how we can't find people. Ultimately, it's a communication problem and a relationship problem. It goes back to who you know.

Being able to be on these boards and connect people that have common interests but they don't see it, that's the fun part. It's not about security. I'm curious about the development piece of it. You mentioned there were multiple people from the community, community in quotes, who were there trying to define the program at ACC, right? So, what sort of constituencies were there?

Obviously, there's some security people, security program leaders, other things like that. What other sorts of people were there? I found that in meetings like that, you get some— you can tend to get some very different members members of different communities that you might not expect to care about that sort of thing. So I don't know if there's any of that there. You know, there's only been a few meetings so far.

I would say largely everyone there is security-focused, and these are all from big businesses. You'd recognize most of the names. But the interesting thing is whether it's forensics or it's compliance, risk management, pen testing. Some of these people have their own hotspots that they're interested in, but this is a 2-year degree program, and so you can't teach that level of focus. These programs may be a little bit more broad, but if they're too broad, then it's no longer interesting to you.

You're going to want to hire someone that has a random sampling of topics. You want them to be able to show up and have some kind of contribution from day one. So it's a fun challenge, but ultimately it gets down to building that network and getting these people, getting these students experience in one thing so they know what to do. Yeah, I think on your second point with getting people experience and internships and whatever it may be on that side. I think, you know, as an industry, we're at a weird spot, right?

We need a whole lot more people. We need more bodies.

And we also want people that have experience. So we have not gotten to the point yet where entry-level positions have zero experience. People want certain experience for an entry-level position. And I think we're also still at the point where internships are a summer thing, right? So you're— you have a couple months in the summer where you have one or two internship positions that you get people to come in, you know, theoretically students on summer break from college.

Yeah, that's, that's why you do it in the summer. You have them in there for a few months, maybe they do something useful, maybe they don't, they're just kind of hanging around getting some experience and then they go back to school. Where I really think we need a lot more of that type of thing because there's these programs like ACC, there's SecureSet, there's all these places now that are starting to pump out individuals with some knowledge but functionally no experience. And it's not necessarily, okay, they're going to graduate in, you know, end of May, June, and then you're going to have a, um, you know, a process to get them in into different places. You know, other industries, you know, I'll think about like finance or, you know, something like that where you can go into, um, into, you know, a big audit firm or something like that.

They've got these pipelines that are already established, right? Yeah, those people come into the school, we've got a broad bench, they say, hey, you know, you accounting people, you can come out and be an auditor, you know, for PwC or Deloitte or whoever. And, you know, we're going to hire 500 people and, you know, come in, you'll do this, and then, you know, you'll get the experience. You could come in with zero experience other than having a degree. We'll train you, and then, you know, maybe some of you will leave, but we'll keep promoting some of you.

We just— I don't think that have that defined yet, and, and we're just kind of in the middle of transition, I guess. Yeah, but there's, there's a part there that you mentioned You mentioned— I picked up on it, right? When I talk to a lot of people who are trying to get into this field, it's interesting because they just know they want to be in this field. Most of them want to be a hacker. They don't even know what that means, but that's what they want to do because it's glamorous.

What I try to do is I try to figure out what bucket are they interested in really and where do their skills align, right? And that's one thing that's missing in these programs, even the ACC program, is they're building generalists, but these generalists, they don't have enough exposure in one field to know that, oh, I want to be this threat hunter, I want to go dig through logs, or I want to go do audits, or I want to deal with people, all these kinds of things, right? So the idea is being able to to build these internships like you mentioned that gives these students exposures early on so they know that I do not want to run a SIEM or my passion is to run a SIEM, whatever that is, right? They either want to be a network person, an app scanner, they want to actually work with coders, whatever it is, we have to give them the experience so they know what best suits them. In the past, I've hired SecureSet graduates.

They were all trained as threat hunters, but I don't know if that was really the passion.

Over time, they'll figure out where they want to be in the security space, but that's what the internships do. I need to do a pitch for ACC real quick. Their internships, they're very, very flexible. What they're trying to do is build a program that allows the students to be on campus 3 days a week but in the office 2 days a week, and that's part of their program. That's different, that's new, and I like that.

I like the thinking of that. Yeah, and that might, that might work out well for us as employers in the space. Yeah, I think it's gonna take some, some forethought by, you know, program leaders to think, okay, well, maybe I need to have a permanent intern position that is open and and, and something for that position to do, uh, I mean, obviously it's still going to be finite, right? But so if you have a pipeline of people that can, you know, do 2 days a week or 3 days a week or whatever it is, um, then okay, I know that I will always have a spot for one of those people. I have one of them on for, you know, 2, 3, 4, whatever the time period is.

They move on to do something else and you you go back to the program and say, hey, I need a new person, right? They shovel another person in your spot. It's kind of like a temp agency. I couldn't help but think in our last meeting that whenever— at my prior company, whenever we were doing the PCI audit, there was always a ton of work to be done, right? And very few bodies because you can't staff that, you know, full-time.

You can't have a staff of 5 people waiting for the PCI audit that happens once a year, right? I mean, there's work to do throughout the year, but at that peak moment, you have a lot of work and very few bodies. We always had to borrow people, right? This is a perfect case for an internship. It gives them exposure, some exposure, some relevant resume-building exposure, like they helped with an audit, whether it was collecting evidence or organizing evidence or trying to compile an auditor's checklist.

Checklist with what you've, what you've generated internally. It's huge experience. Yep. And at the end of that, half of them will be like, I don't want to be an auditor. Exactly.

And the other half would be like, I want to be an auditor, I love that. Yeah, but that's, that's the kind of experience we need to get these people so that the next opportunity they have is more fruitful for the employer and the employee. So if someone was interested in, in one of those folks from ACC for an internship, do they reach out to ACC directly? Can they contact you to get— I'm happy to help. They can reach out to ACC.

I believe— I forget the number— 87, 86, some— there's a large number of students, okay, that are looking for some meaningful experience, and they're very flexible on what that is, where it is, and how much it is. And I'm sure we get the details and put it in the show notes too. Oh yeah, I'll find that out. Yeah, awesome. Well, we're getting short on time.

Anything else that you wanted to talk about, John, that I haven't touched on? No, I, I, I, you know, thank you for inviting me back out. I feel like I've been a recluse in my house, and it's fun to be in this business. And I think ultimately it's more about networking than really any kind of knowledge, and connecting people is my theme for the for the moment. So one last question before we go.

So you're 9 months in. Do you think that this was a good move? Um, yeah, I think this was a fantastic move. It was, uh, it— I needed a break. I needed a change.

Yeah. And I don't know if I can keep doing this thing for 5 more years at this company. I can't imagine there's enough work at this company to do it for that long. But once, once the program is established and matured, I feel like I'm ready for that whole next thing, and I could probably do 2 more of those and then I'm done. So this is awesome.

This has been fun. Change is good. Change is always good, and new experiences and growth, can't go wrong. Awesome. Well, thanks, John.

Thank you. Appreciate your time. I'm sure we'll have you back on in another year or 2. Yep, I'd love to. Up to then.

Awesome. For now, this has been Colorado Equal Security, and we'll talk to you next time. Bye.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security. Security.

Back to all episodes