All episodes

Trent Hein & Dan Mackin, Founders of Rule4

Apple Podcasts Spotify SoundCloud

In this episode:

Trent Hein & Dan Mackin, Founders of Rule4, are our feature interview this week. News from: CDOT, Coinbase, Webroot, OverWatchID, CyberGRX, Convercent, ThreatX and a lot more!

SamSam in the SlamSlam

The bad guys who hit CDOT are identified and indicted. Colorado is your blockchain hub, just ask Coinbase. Colorado’s breach law is going to impact health companies too. OverWatchID starring at Gartner IAM. CyberGRX says ‘cha-ching.’ ThreatX teaches us how to security in a DevOps world. Convercent talks about how to instill a risk culture.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10848 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is the newscast for episode 94 for the week of December 3rd. We're, we're in December. Oh my gosh. I know.

Isn't that crazy? Yeah, this, this year just flew by. Yeah, I think we're getting older if time's going faster. Is that what that means? Not only that, episode 94, we're getting, you know, almost to triple digits.

We should be thinking about episode 100. We should probably think about that, Robb. Listeners, if you have a great idea for what we should do on episode 100, we would love to hear from you. You can send us an email. Reasonable ideas.

Whatever.

As long as it comes with sponsorship. If it's unreasonable, we're in. Oh, there you go. Okay. Um, send us an email at info@colorado-security.com or come to the Slack channel or some other way of getting ahold of us.

We'd love to hear what you wanna suggest. Speaking of that, we do have a Slack channel. We do have a Slack channel. Uh, everyone should come and join the Slack channel. Check out colorado-security.com for a link to the Slack channel.

Join and, and join the conversation. Did you see the, uh, exchange this week where, where AI CISSP joined? I did. I thought for sure we had an advanced intelligence that had, had joined the, uh, The channel. I also saw that someone posted a link to bedtime stories, which were someone reading the verbiage of GDPR.

It's good stuff. We do have almost 700 people in the channel now. I'm now looking forward to 1,000. Yeah, let's do it. We're getting there, right?

In addition to the Slack channel, we have a mailing list. If you want to get the show notes into your inbox every week, go out to colorado-security.com and get signed up. Also, please subscribe. Go to iTunes or Google Play or whatever your favorite service is, subscribe. And then when you do that, please make sure to rate us so that we have good quality ratings on our podcast, and it's gonna get people to find it.

That's one great way that you can support the show. Another way is you could tell a friend about the show, tell a coworker, tell someone who you like about it so we can keep growing and get expand the reach of what we do. Another great way would be for you to join our Patreon campaign and, and support us monetarily. Robb and I do this out of the goodness of our heart, and it's not that good, which is not that good. And, you know, besides the Patreon campaign, all the money for the show comes out of our pockets.

So this is just us trying to help offset those costs. And any money that comes in through Patreon goes back into the, into the show, not back to us. And huge thanks to those paid patrons we have right now. What a great group of folks who are supporting us. I think we got like 20-ish people who have been helping donate.

We really appreciate all you guys do. And thanks, thanks for your continued support. Bravo. Yeah, thanks a lot, guys. Well, let's go ahead and jump into the news.

There is a big event coming to town. You know, I know we've been talking about the Olympics, whether we want it or not. Honestly, I think this is just as big, but been kind of flying under the radar. I think it might be even bigger. In April of next year, there is going to be a live Mario Kart event here in Denver.

Yeah, so if you want to dress up as a Mario Kart character and drive around a track, uh, you should definitely check this out. Uh, you're basically— you're driving around trying to capture stars, and I think it's a 30-minute competition. Uh, they, they won't say the location of the event until right before the event. I think day of the event, in fact, because they don't want people to something. I don't know.

They don't want you to go scope out the tracks. Maybe they don't want to put bombs out on the track. I, I don't know for sure. Uh, they don't want to throw any, uh, any strange turtles out there either. Yeah.

So anyway, pretty cool stuff. Take a look at the link in the show notes. Next, some big news. 2 Iranian hackers were indicted for ransomware. And the tie to Colorado here is that these guys were doing the SamSam ransomware, which is what infected CDOT.

Yeah. So this is— it's fantastic that we have indicted these 2 folks who look like they're in Tehran in Iran. So as of right now, we don't have a way to actually put them in jail. But we do, you know, we've identified the 2 people. We've actually started, you know, legal proceedings to try and figure out how to get these guys.

Yeah, they are obviously out of reach of our government at this point. But, you know, if they were to happen to go on vacation somewhere or maybe something else, then they're out of reach in some ways, right? Yes. In the legal sense. I thought it was interesting that, that SamSam had netted $6 million in Bitcoin payments.

That's a pretty big number, you know. And I saw In this article, it said $30 million in impact. Did you hear the podcast? I think it was CyberWire that said $30 billion was the impact of it. It might have been Risky Business.

I don't remember. I'm curious and maybe we'll be able to find details for that for you guys later. But certainly big impact from what these guys did. Moving on to the next story. Robb, I know you're going to be excited about this one.

Colorado will soon be the epicenter of blockchain for real estate deals. So, you know, I tried to read this article and I didn't have a subscription to get all the details for it. I know we've talked about it previously and basically having the ability to use blockchain to settle real estate transactions more quickly. Right. That was the— that makes it thrustier.

Yeah. Well, I mean, if you think about it, you know, the whole title industry, which is obviously part of the real estate process, is based on the fact that they're, they're guaranteeing that there aren't any other claims on the title to your house. Right. So if you had a blockchain-based title system and you could through that guarantee that there were not any unknown claims, That, you know, that's something that would relatively go away. You know, you can have a distributed nature of it.

You'd still probably want to— you need a high level of trust for the people who can make those claims on the blockchain there. But I think that it's actually not a bad use case for blockchain technology. It's pretty cool. Whoa. Robb just said— it's not a bad one.

I'm not saying that there's not a better one that's not— Robb just said there is not a bad use case for blockchain. Let's cut that piece out. Not a bad use for blockchain. Yes. And we just use that all over the place.

Speaking of blockchain technologies, Coinbase, which is one of the highest valued cryptocurrency exchanges, got their Colorado money transfer license. Yeah, I saw this and I thought it was interesting. You know, there had been some recent changes to the regulations around that. So they are the second cryptocurrency company to get this with a new— or total, the first with the new regulations. But I It doesn't really say in the article.

I don't really understand what that means. So in September, the Colorado State Banking Board issued new guidance on how cryptocurrencies could get trusted or treated under the Transfer Act. And it basically says that they're mandating that companies move away, they move, excuse me, that the companies that move money, they have to do background checks and they have to have business plan examinations. So basically, it's just people are looking at what they do, making sure that their employees are trustworthy. You know, it's a step.

But it doesn't seem like it's, you know. Yeah, well, I was not going to technology. It doesn't look like for sure. I was thinking more, why is it that they're getting this? What, what, what does it mean now that they have this?

Right. Could you, if you could, you not be a Coinbase customer if you were in Colorado before because they didn't have a money transmitter license here? Or does this mean that they're, you know, potentially moving some operations to Colorado? I don't know what that part really means. Yeah.

What is it? What is, what's the benefit of being a money transmitter? Yeah, I don't have the answer for that, but neither do I. Interesting question. All right, let's move on before we make ourselves look dumber.

The Colorado's— or excuse me, Colorado's advanced industries are booming. So this is an article talking all about that the big industries in technology and, you know, IT and engineering and aerospace are a huge part of the Colorado economy. And I think they said it was like 30% of all salaries in the whole state, right? Yeah, and one of the things that I liked about this article is that they talked about how cybersecurity is important to making sure those advanced industries are effective, essentially. And before we dive too much into that subset of it, I thought it was especially interesting when they say 30% of revenue or salaries come from that.

You think about the way a service economy works. For every job that you or I have as working for a company, there's going to be multiple people who do services for us, right? There's, you know, your, your restaurants and your, your car repair shops and your, you know, all these other things. So the fact that we have 30% coming from these industries, to me, is pretty staggering. It's a really big number.

Big number. Anyway, to your point, we also— they also have a lot of details about security. I think some of what they have in here is maybe exaggerated. Yeah. Well, one thing they say, there's approximately 85,000 people in Colorado working in the cybersecurity industry.

That's a lot of people. We had previously got 18,000 as the number. And, and this, this does say people working in that industry. That doesn't necessarily mean cybersecurity professionals. So if you are, you know, working for, uh, a company, if you're working for Ping Identity and you're doing marketing, okay, fair enough.

Um, I don't know that you're a cybersecurity professional, but you're working in cybersecurity, but you're working in the industry. Yeah. Um, and I guess, you know, $85,000. I don't know. It's a big number.

I'm, I'm trying to justify, but it's still a big number. They do say, uh, 100 cyber-focused businesses. Um, which now I, I actually think I could buy. That, that seems reasonable to me based on what we've learned. Honestly, that's probably low.

I, I would bet that if you call, you know, consider consultancies and other things like that, CyberFolks— Elevation Security Consulting. Exactly. I, I think that, uh, that's probably a little bit low. Anyway, they do have a couple other interesting things. They talk about, uh, the security salaries entry level being in the $55,000 to $65,000 range, um, and with folks with like 10 years experience earning up between like $80,000 and $100,000.

So kind of nice to see some numbers written out there. Those entry-level role numbers sound about right to me. Those 10-year roles sound a little bit low to me. Yeah. Yeah.

Finally, in the article, they do talk a little bit about different educational organizations that do have cybersecurity education programs now. There was a good number of those listed there. I was actually surprised about that part, the number of people that have those programs. Yeah. Awesome.

Next article, we— there isn't the— this is about that new Colorado privacy law, breach notification law. Amendments to our data breach notification law in Colorado are gonna actually impact HIPAA-related organizations. Yeah. And there wasn't any new news in this article. It was sort of an opinion piece.

But I wanted this in here because I thought it was interesting that there— this was something that people thought was important enough to put out an opinion piece now, even though this has been in place for, I don't know, 6 months now. But it was talking about the, the fact that there are some additional requirements. There's essentially a HIPAA out in our— in the Colorado rule. If you're following HIPAA, then you're not subject to it except for these couple things, which is that you have to do notifications of breaches in 30 days as opposed to, I believe it's 60 for HIPAA. And you also have to make notifications to the Colorado Attorney General, which wasn't previously needed.

So if you're doing security at a HIPAA-regulated organization, maybe a good thing to think about these things. For sure. Next, Webroot has put out their 2019 cybersecurity predictions. So as we've mentioned in previous episodes, it is getting to be that time of year where we start to see these predictions. Yeah, I know we have more of these coming.

I know LogRhythm is almost done with theirs, and I know personally that Ping Identity is almost done with theirs as well. So we can dive into Webroot's. Roots first. So they had, I think, 5 on here. First, the AI disruption.

There will be further adoption of AI leading to automation and disruption around that. AI is gonna be crucial to the survival of small businesses using AI to be a differentiator and to be able to compete. Yeah. And I think sort of reading between the lines on that one, I don't think that they're saying that small businesses are necessarily going to start developing their own AI. No, but I think using AI in products will help small businesses.

Yeah. Not everyone's going to have a core capability around AI, but everyone's going to utilize products that give that to them. Yep. Ransomware is out and cryptojacking is in. This isn't a prediction, though.

That's just— that's just reading the newspaper from the last 6 months. I think they're saying that it will continue to happen. Yeah. Targeted attacks. They see a lot of targeted attacks coming versus just the target of opportunity.

Uh, and then finally, there will be more zero-day vulnerabilities. Um, they really went out on a limb on that one, huh? Yeah. You know, the, I think they're trying to make that a little bit more nuanced than it sounds, but, um, yeah, it does seem sort of, uh, basic. So this, uh, this prediction list was made by LeVar Battle, who is the, uh, senior social media manager.

Uh, LeVar, you might wanna step up your game on going out on a limb a little bit. Well, I will say that each one of those predictions, he does have quotes from the people within Webroot who essentially made those predictions. Oh, fair enough. So, so he, he gathered them together. But I don't think he made all of them himself.

That's a good point. Next, some PR news. Overwatch ID is going to be hawking their wares and, and talking about their products at the Gartner IAM conference coming up this week in Vegas, Las Vegas. Yeah, I know that I saw that they have their press release. Ping will be out there also in force.

It is, you know, one of the biggest IAM events of the year, maybe the biggest IAM event of the year. So if you're gonna be in Vegas next week, you can, you can go learn about some IAM from some local companies. Yeah. Next piece of news, CyberGRX, our local third-party management platform, raised $30 million in a seed funding round. Yeah, good for them.

As you mentioned, this is a seed round. They've done 3— I think it was sort of like $9, $20, and now $30. Yeah, in that range over— and it was over the last I think over the last year, just about a year in between each round, something like that. Yep. So they've— yeah.

So they've gotten $59 million total in equity financing.

One note from the article, it says in the last 12 months they've seen over 1,000% growth in annual revenue. That's pretty good. I mean, pretty good if you go from, you know, I don't know if they're at $1 million to $10 million or whatever they did, you know, maybe from $2 to $20. That's— that's no matter what, right? That's pretty good for the last 12 months.

I did find— I don't know if you actually read all this article— that it's written in the most casual language I've ever seen. Yes. There's a sentence in there that says, ye fintech gods. I did. I did see that.

That was sort of interesting. So interesting. I really want to get all of my news from this outlet in the future because they apparently just make them a little bit more fun. But in any case, congratulations to CyberGX. Glad to see that they're still growing.

Next, there was a blog this week from Conversant talking about how to increase risk awareness and create a risk-aware culture. It's funny, you know, I loved the fact that this article was here, and this is the kind of headline for an article that you or I could write about putting security in, but they're not talking about security. Yeah, there's nothing— I read it and I'm like, ooh, that sounds exactly like something I would say. Yeah, and it's all about ethics and what's the risk of, you know, different kinds of risk, and I love kind of finding different places where we can use the same language to help, you know, impact company culture. They did kind of break it down into a few steps and how do you do this, you know, agreeing on a vision.

And, and they— you're talking about getting at the highest levels of the company. What does the vision look like for a risk-aware culture? Assess your risk culture and create a roadmap. How do we get from where we are to where we want to go? Tone at the top.

Make sure the whole— the leadership is, is helping drive forward versus kind of working at at cross purposes to you. And then finally, education and training and helping and educate across the organization. It was, it was an interesting blog. I enjoyed it. Um, as you said, to see those, those parallels between stuff that we would do and what they were talking there.

And our final news story for the week, we had a blog from ThreatX this week talking about 3 hurdles that security will need to clear to succeed in a DevOps world. Uh, so they had a couple things here. Not surprisingly, DevOps brings an increased pace, so security teams will need to keep up with that. DevOps is all about removing barriers, making things work more seamlessly, so you'll have to be ready to, to help move those barriers instead of being the, the traditional security people and putting barriers in place. And finally, there's a different skill set that people will need in order to survive in this world, so you're going to have to make sure that you and your team have those skills.

Awesome. Uh, good article from ThreatX. Moving over to the Slack message of the week. I want to do a big thank you to Andre Gaeta. Andre is our ever-present sponsor for this.

Uh, we appreciate that very much, Andre, doing this out of your own pocket. Um, and of course, the winner this week, Alex, who is it? It is Mike Benjamin, uh, of CenturyLink. Congratulations, Mike. So this is actually for a couple posts.

Um, Mike did post a news article about, uh, some takedowns of some pretty major botnets that CenturyLink helped. So this was a, um, a press release from the federal government talking about how they took these down, and CenturyLink was named as one of the companies that really helped with that. Yeah, big shout out for those guys. And the second one, we do have a threat intel channel on the Slack group. So if you're not on the threat intel channel and you're, you know, nerdy about that kind of stuff, um, which is totally cool, um, you should go check it out.

And, uh, Mike and, and some other folks were talking about, uh, some botnets in there and Mike, you know, dug into his bag of tricks and, uh, and pulled out some, some cool data that he shared with some folks. So yeah, it was like, hey, I, I've seen this thing before. And then Mike's like, here, I'll give you more details about that thing. Right. It was, we've seen this and this and this.

Yeah, it was pretty cool. Oh, oh, what kind of devices were those that were communicating? Oh, they were these kind of devices. Oh wow. That is cool.

Mike, thanks for, thanks for what you do there. Uh, let's go ahead and move over to our events for the week. Before we do, as a reminder, we have a calendar of events on our website. At colorado-security.com. You can see all the stuff coming out.

I think we got events out there through about March. I don't think we have RMISC on there yet, but we probably should. Yes. Registration is open, right? Registration is open.

Call for papers is open. If you're a sponsor and you want to sponsor Rocky Mountain Information Security Conference, the sponsorship links are open now too. So go check it out. rmisc.org. Awesome.

First, SecureSet is doing their Denver War Games Network Security 2. Network hijacking on the 3rd of December. You wanna learn how to hijack a network? On the 4th of December, the Cloud Security Alliance is doing their holiday party. That's downtown Denver.

Come on, come do that. Come enjoy the evening there. On the 5th, SecureSet is also doing another war games. This is Network Security 3: DDoS and Countermeasures. I like that.

On the 6th, the Colorado Springs ISSA is doing their chapter annual awards banquet. I think that's their holiday party. On the 7th of December, Colorado Springs is having their First Friday Cybersecurity Social and Mixer. On the 10th is the ISSA and ISACA Holiday Bash. This is a joint meeting.

It is going to sell out. There's, I think, 300 spots available for registration, and the expectation is it's not going to have any openings eventually. It'll be at the Soil Dove Underground in Denver, so pretty cool venue. Should be fun. Um, also on the 10th, SecureSet is doing another Denver WarGames System Security 1 Linux security.

Um, this— there is a trend and we're not done yet. Uh, on the 12th, SecureSet is doing their Denver WarGames System Security 2. That's Windows security. On the 13th, SecureSet is having a Q&A with Nadine Tanner on Metasploit Pro. And that is it for events.

Jumping over to interesting jobs. So just as a reminder, every week Alex and I look through job postings and job bulletin boards to see what's an interesting job that we want to share with you guys. Sometimes it's, you know, just, you know, a security analyst role. Sometimes we find something a little bit more interesting. Anytime there's a Ping opening, that gets to make the show, if it's a Ping security opening at least.

And we do have 2 of those this week. I'm looking to hire a security program business analyst. If you're someone who has a project manager, program manager, business analyst background, this is a good opportunity for you. I'm also looking to hire a GRC analyst. This is going to be somebody who helps support our compliance initiatives around like SOC 2 and, um, and our ISO certification type work.

InteliSecure is looking for a senior program analyst. NREL is hiring a chief cybersecurity engineer. That sounded pretty cool. That's pretty good. Specialized Bicycle, which I don't think I realized was actually in Colorado.

No idea. In Boulder, head of security and architecture. That's awesome. Which includes running the security program. I— man, that's really cool.

I didn't know that was here. Colorado Judicial Branch is hiring a manager of information security, and Xcel Energy is looking for a senior cyber defense center manager. Sounds like a SOC type of a— that's what it sounds like. Cobank is hiring a security manager. I assume this is working for our friend Stanton Meyer over there.

That is my assumption as well. Pretty cool. He's getting to hire a little bit of leadership to help him out. Faction is looking for a DevSecOps architect/engineer. Zapper is hiring an application security engineer.

Do you know anything about Zapper? I don't. Okay. And Colorado— state of Colorado, sorry— is looking to hire a new CIO. Our CIO moved on and is now at Dish Network.

So Suma Won the CIO of the Year at— and then dropped the mic and walked away and walked it. And she's at Dish Network. Is that what you just said? Yep. They just announced that this week that she is their chief digital officer, I believe.

But also, if you do want to work in leadership at the state government, now is the time. I don't think that the CISO position is open presently, but Debbie's made it clear that she is not planning to leave the position at this point. Yep. But As they are transitioning from one administration to another, this is the traditional time when almost all of those types of positions become open. So if you want to have a leadership position at the state of Colorado, now's your chance.

Yeah, go into the show notes and click on that CIO link and it takes you to like a whole bunch of roles that are open in the administration. So I think that's it for the news this week, Alex. We have an interview where you sat down with the, the, a couple of the founders and the co-CEOs of a new company in town. Yeah, so I sat down with Trent and Dan from Rule 4. We've had Trent Hine on the show before.

Robb interviewed him sometime earlier this year. Yeah, talking about Rule 4, what it is that they're doing, why they started the company, some other things like that. It's a good interview. Awesome. Well, that's it.

I guess that's it for this week, and we'll look forward to talking to you guys in a week. Thanks, Robb. Hi, this is Merlin Nameth, Business Information Security Officer at the Reed Group. This is Colorado Equal Security, for Colorado security professionals, by Colorado security professionals.

Welcome to Colorado Equal Security. We have a very special feature interview today, not just one guest but 2 guests. We get, we get a twofer today. So first, welcome back Trent Hein. You have been on the show before.

So thanks, Alex. Excited. I can't speak. Try that again. Thanks, Alex.

Happy to be here. Awesome. Welcome back. Um, and Dan Mackin. Welcome, Dan.

Thanks. Thanks. Excited to be here. So you guys are both with the newly announced Rule 4. Um, you guys, uh, I think co-founders.

Is there another, another person involved or just the two of you? We actually have, uh, 5 5 founders, correct. Awesome. Well, for those that don't know Trent, you should go back and listen to episode 61 where we spent a lot of time, Robb specifically, talking to Trent about what he did and where he came from. But Dan, we don't know you, so maybe let's take a minute and talk about you.

How did you get started in security? What's been your career path? How did you get to where you are today? Absolutely, sure. So I actually got started with Applied Trust, the company that Trent founded back in 2001, right as I was finishing up my degree at CU, which is in electrical and computer engineering.

Got started as an intern at Applied Trust and really built my career there, I would say, from learning from experts like Trent And, you know, the other Applied Trust founder, Ned, as well. Certainly spent a decent amount of time getting my Linux chops up to speed, had the opportunity to work on the Unix and Linux System Administration Handbook with Trent, which was really exciting. And, you know, got into credit card security, healthcare security, that type of stuff with Trent at Applied Trust. And, um, yeah, nice. And so I assume you continued with Applied Trust over to Flexential, correct?

Yep, one of the best names of all, all companies out there, no doubt. Yeah, for sure, we did. Um, we were a part of the acquisition by Viawest together. You know, I was lucky enough to be involved in that with the rest of the leadership team at Applied Trust and learned a lot from that experience, so that was cool. Nice.

And so, as I said earlier, you guys recently started Rule4, so maybe really quickly, whoever wants to take the first shot at it, what is Rule4 and why is Rule4? Yeah, that's a great question. So we provide consulting services in really 2 spaces: cybersecurity and emerging technologies. And we exist because we feel like there's a gap in the market. We can get into the very specific details of it, but there's demand for very focused services in a couple spaces.

And one of the challenges we see in general is we could talk about cybersecurity, or we can talk about technology. We as an industry do just a terrible job relating to the business, right? It's like, oh yeah, here I've got my certification checklist, or I've got my regulatory standard I have to comply with. And, you know, those are absolutely important things, but talk to me about how that drives the business forward, how that makes the world a better place, how that makes— helps the planet. Those start to become pretty difficult conversations fast, and we actually love that space.

Like, how do we tie all this stuff, this awesome technology stuff we do, back to the real world? Yeah, I think a lot of times people think the other way, right? There's a lot of opportunity. I'll call that the high end of the market, what you guys are doing. There's also a lot of opportunity at the low end of the market where it's like, hey, we can provide all kinds of, you know, sort of simple services, and there's lots of room for people to do that.

And it's, you know, it's sort of easy to do that, right? There's not a huge bar to to doing that stuff. So it's good to hear that you guys are kind of taking the other approach, and it's like, hey, let's tackle the hard stuff and, and really help with people there. Oh, love it. And I love challenging problems, love really unique problems, because it's, you know, that's inspiring to get up in the morning every day.

You know, it's like I want to get out of bed and be like, I am going to go change the world in this way. I'm gonna go help solve this hard problem. And yeah, that's fun, and that's why we have real fun. So, so one of the areas that you guys said that you focus in is emerging technologies. So how do you guys define emerging technologies?

Is that, is that something that it's like, oh, that looks like it's emerging, or is it you have some kind of criteria, or is it like, I don't know, no one seems to be paying attention to this? How are you guys figuring out what part of that the business is focusing on, on that stuff? That's a great question. You know, the way I've been describing it is that it is an area where we're seeing businesses start to, you know, dip their toes into or their big toe into, you know, take machine learning as an example. We're starting to see companies explore leveraging that technology to help them make business decisions, but it's certainly not widely adopted.

We believe that in the future it will be widely adopted. And so that litmus test of, are we seeing some companies start to explore in this area, and do we foresee them, you know, growing beyond just a handful of companies trying it out and it becoming just a part of regular business, I think is how we're determining whether or not that fits into the emerging technology perspective. Well, and how do you responsibly apply that, right? This is a fad that the machine learning or AI, and I've we could have a debate for an hour about what the difference is, but let's call it machine learning for the moment, is yes, we can apply it to a lot of problems. Responsibly applying it to problems is a totally different story.

It's like, great, I'm gonna feed this machine learning engine 3 million healthcare records and associated outcomes and see what it can come up with for how we can get better outcomes. That's a fantastic goal and a very achievable goal. We have to be very aware though that when we do that, we feed 3 million records of potentially sensitive data. Not only do we have to protect the confidentiality of that, but we also have to protect the integrity of the process. Like, how do we know that something's not getting altered unexpectedly as it goes through that system?

Really where machine learning is right now, I'm not convinced that all that stuff is already built in, right? We really need to thoughtfully think about how do we apply this. Yeah, so I mean, you touched on some great issues there, sort of on the security part of that. Are you guys also thinking about, um, I guess I'll call it maybe like the ethical issues around that too? So, um, I guess more like quality of data or other things like that.

It's, hey, you guys also need to be thinking about if you're trying to solve these health problems, are you feeding in records of people that are homogeneous, right? Is this— are you basically saying, all right, for this one person replicated 3 million times, you can solve this problem and the machine picks out the patterns, but does that actually apply because the population is correct. So we're not ethicists, but we're computer scientists and engineers, right? And so how do we, to the appropriate limit of our expertise, how do we make sure that the right science is applied? Absolutely, right?

We should be applying— this really gets down to, and really cybersecurity often gets down to this issue of, are we applying computer science appropriately you know, at the right level in the right cases and, and usually using actual science versus like, oh hey, this looks good, let's just try this out, right? Yeah, the— so clearly machine learning is one of those areas of emerging technology where you guys are thinking about. What other areas fit into that, that bucket? IIoT, which is the Internet of Industrial Things, right? Industrial Internet of Things and IoMT, Internet of Medical Things.

And so what we're seeing is companies really adopting these technologies very quickly and not quite realizing the risk they're putting themselves at or at what rate they're really adopting these technologies and devices. You know, we believe that you're gonna get into an organization and ask them for, you know, inventory or look at, you know, what are your connected devices that you have, and by helping them really figure out what that inventory looks like, they're going to be quite surprised at how well or poorly, I guess I should say, those things are being managed. You know, we've done a decent amount of investigation into some of the connected devices, and the vast majority of them are running Linux, and they're subject to the same security holes and vulnerabilities that any other Linux Well, so this is hilarious because I think we could play a game show very easily. It's like you find this embedded device, whether it's a medical device, some type of biomed device, or it's, you know, industrial lighting or HVAC control, and you're like, oh well, here's this box that controls our lighting. Let's say for example we could play a game show and be like, hey, what does that run?

And you know, you can probably win that game show most of the time answering Linux, which is awesome, and it's also surprising all at the same time. And I think if you want to hedge your bets, the only other option that you could say is some old version of embedded Windows, right? Right, which makes me squirm just a little bit more. Yeah, that's— yeah, I mean, there's huge problems in both of those things, I will say. I don't know that one is necessarily worse than the other.

You know, if you've got an old version of embedded Linux, there's going to be a whole lot of problems with it. Absolutely. Just like there's going to be an awful lot of problems with an old version of Windows Embedded too. In a previous life, I did some work for an oil and gas company, and we had lots of things that were out there that were running Embedded Windows, and it was like, well, for the lifetime of this device, it is always going to have problems. There's nothing that we're going to be able to do about it.

So, you know, what am I going to put around to help protect it? Yeah, how do you deal with that situation? And I think that there's no one answer to that, right? That's the challenge, is you got to figure out, like, what do we do? We can't just leave it open.

We can't just leave it insecure. So do you guys— I think IIoT and IMoT— sorry, I'm trying to remember all my— IoMT. IoMT, yes, thank you.

Are these— those are new names, but are these really new problems? You know, is there a new space there, or are we just identifying, uh, the fact more specifically that these things have been around for a long time and now we're really, we're really thinking about it, right? Because, um, you know, most of the— I've also done some healthcare work, and most of the stuff that I've seen, it's— there's not necessarily new devices, um, it's just we're paying attention more to now that these things are plugged in, right? Uh, I would say 2 things have changed. You're right in that we were renaming some spaces, and let's talk about just IIoT in general quickly, right?

So the SCADA space is what I think we would have maybe called that, right? But SCADA grew up on like the RS-485 bus and the protocol called Modbus, and, you know, it was very— by its nature, it was isolated because it required, you know, hardwired short-distance links, and you had a very defined control structure. So the awesome thing that happened was those device manufacturers figured out like, hey, we could use commodity chips. We could use, you know, commodity networking, Ethernet and TCP/IP and the internet to haul this and make it more manageable, more accessible, more scalable, which was great for all of those whatever plant building process operators. But in doing so, then it brought all of that equipment into, quote, our traditional world, which is almost enterprise IT, right?

We have the same scalability, patching, connectivity problems that enterprise IT has with, let's say, a desktop. And I'm not sure that all those steps were taken appropriately as that happened, right? So what has changed is scale and protocol and technology that's applied to that space, but sure, The IIoT in a lot of senses is what years ago we would've called SCADA. Same with IoMT, right? What we would've called biomed, but the biomed space, you turn the clock back 10 years, a lot of proprietary buses, protocols, and now it's largely based on open standards and open technology.

Awesome on one hand, not awesome if we didn't secure it well. Gotcha. Yeah, so I know that I saw a lot of times where you would have those, those old proprietary protocols still, but it's, you know, Modbus over IP essentially, as opposed to direct and things like that. Yeah, so it sounds like maybe we've now eliminated some of those things and it's, it's more direct, but you still have a lot of those inherent problems because people just never fixed pieces of it. Like, you know, Modbus, there's no authentication, right?

So yes, that's just missing from Right. Yeah, the other thing I just want to reiterate what Trent said is the scale, you know, the how quickly these things are being adopted. They're certainly getting cheaper. They're becoming more mobile. You know, if you talk about in the medical space, the concept of folks bringing home some device with them that monitors their, you know, vitals while they're at home, I think isn't that far off, right?

And it's gonna really potentially change the how care care is delivered, and certainly where those devices are and how they're secured, is absolutely critical to that being a, you know, good long-term societal impact, I think. So, uh, one thing that I didn't hear you guys talk about that I'm wholly surprised about in, you know, emerging technology, you know, Robb and I have a specific love for blockchain. Do you guys have a, a blockchain consulting practice? Because that is clearly the next big problem, or next solution to every problem. Wow, you almost took the words out of my mouth.

It's a solution to something. So some of that stuff does fit in our space. One of the things we do is specialized forensics. There's a lot of folks out there that do, let's just call it run-of-the-mill forensics. Your laptop, needs forensic image and analysis, right?

We can go find 30 providers that will do that here in Denver. But when it comes to things like, if you have an integrity incident on the blockchain, how do you trace that back and do analysis of that? That's a much harder problem. That's squarely in our space as things like API forensics. Like you have an API interface that potentially has been breached.

We've got to go figure out what happened on what time and why. That is not a common skill set. Yeah, I would imagine that is true. We talked about it on the podcast recently. There was a— which I had heard it from the Risky Business podcast.

Someone made this tweet about a study that was done somewhere. They spent $700,000 dollars in grant funding to do this study, which doesn't sound crazy, but their conclusions were in every single case there is some other technology that does it better than the way that blockchain could do it today. And which I thought was incredible that they found this, but then someone responded to that tweet and said— actually, it was an author, he wrote a book on blockchain, and he said, this is absolutely the right conclusion. I hope you spent, um, $25 buying my book, reading it, and then writing your conclusion, and then the other $699,975 buying alcohol, because that's what you need to be able to cope with the blockchain. That's great.

Um, anyway, um, so, uh, so yeah, so That sounds great. It's very interesting stuff. Definitely stuff that is needed. I don't know that there are other people out there that are— I'm sure you can find people in consulting practices that are doing this kind of stuff, but I don't know of anybody else that has a dedicated practice on stuff like this, which is, I imagine, why you guys started the company, right? Yeah, and it's fun stuff.

It's fun, challenging stuff, and I do think it's things that the world needs, right? It's like when you— we want to be doing things that make the world a better place and tie all of our activities to that, because you can misapply technology really easily, right? And a little harder to apply it correctly.

So that's the emerging technology side. You guys also have some more, I'll call them in quotes, standard security services too, or are they Are they more unique or is it just sort of general standard security services? Well, I don't know if I'd say they're standard security services. We're looking at, from a consulting perspective, being more of that partner, building relationships with clients, taking the time to understand their business, their needs, and being able to be relied upon as sort of a stand-in CISO, if you will, being able to help them navigate all of the different security concerns, look at whether or not the tools and processes they have in place are being effectively utilized, not just whether or not they have tools, you know, and checking the box, but are we leveraging those tools to the maximum extent possible, and is this benefiting the business ultimately? And so certainly coaching, guiding organizations through the cybersecurity minefield is something that we want to take a really personal touch to, make sure that we have these really well-defined, strong relationships with our clients so that they feel comfortable relying on us for those types of things.

Will this go as far as a virtual or outsourced security officer kind of deal? I've seen a lot more companies trying to come out with that kind of role just because there's not a lot of not a lot of talent in that area, right? There's only so many people to go around. Right, and potentially an organization, depending on their size, doesn't necessarily need to have a full-time CISO. And so absolutely, that is a virtual CISO offering, is something we have on our website today.

That is something we want to be able to help organizations out with because again, it is that relationship component. It's like we get to know that client really well and they know us, and then we just are an extension of their maybe existing cybersecurity team, or maybe that we are their cybersecurity team. Nice. So other than that there are cool problems to solve, what was the motivation for you guys to do this now? You know, obviously, you know, there was the acquisition to Flexential.

Are you guys going to continue down that path? Was it just that opportunity was ripe? Was it needed a change? How did that come about? That's a great question.

Definitely, we had identified a team of folks that were really passionate about being high-touch consultants and building a company culture from the ground up that is super dedicated to making the world a better place and really focused on, you know, just an incredible level of service. And so when we identified that there were a group of folks that were really passionate about that, we saw that as just the perfect opportunity for us to start a company that is dedicated making the world a better place by helping great companies and organizations do good things in the world. And I think one of the drivers for that actually is the B Corp stuff. So, you know, we're in the process of becoming a B Corp. You have to spend a year at least doing that. And if you look at Colorado law, that really wasn't fully embraced by the legislature until last July.

July of 2017, where they made some tweaks to the public benefit corp law that just make it— I don't want to say stupid easy, but give you a really clear path to, hey, you can be a B Corp and have a greater impact mission than just like, you know, hey, we want to have a business makes profit. We want to help the planet. We want to help the community and do that all at the same time. And so that B Corp structure And for folks not familiar with B Corps, other B Corps you might know of are folks like Ben Jerry's and Patagonia and now Danone, a huge food conglomerate. And thousands of others worldwide have gone down this path.

Yeah, so for those people that don't know, can you explain a little bit in more depth what a B Corp is and why that's different from a C Corp or an LLC? Or something else? Yeah, absolutely. So if you're a B Corp, you have some type of greater impact than just corporate profit. So maybe it's help the planet, do something more ecologically friendly, or help the community in some way.

And the change in law that's required is that you want the the board of the entity to be bound not just by shareholders' financial interests, but be bound to the greater good. Like whatever you declare your greater good impact is, the board is trying to then balance that, right? Greater good and financially viable entity. And so then there's a formal B Corp certification that, you know, just like, you know, get HITRUST certified or PCI, DSS certified, but instead in the B Corp space where you measure against, you know, hundreds of different metrics like, do you have a diversity program for your staff? Do you have a diversity program for your board?

You know, how do you source sustainable supplies for your business?

Compensation ratios between your lowest paid employee and your highest paid employee. You know, they're looking at everything from benefits to the employees, to how much philanthropy the organization provides. And it's really fascinating. It's a great, I feel like, framework and just mindset that a company can get into. And in fact, Boulder, recently I found out that Boulder has the highest concentration of B Corps of any city in the world, which is pretty fascinating.

And so there's a lot. Namaste Solar, some other folks. Uh, lots of different companies there in Boulder that— I am shocked, shocked that Boulder has that many B Corps, right? You look shocked. Yeah, yeah, but that's awesome.

I think that's really great. So you guys have to, you have to spend time before you can technically become a B Corp? That's— you can't just say, yeah, I'm gonna do this and then, then sign up for it and, uh, and all of a sudden get all the benefits from it? You actually have to prove before you can become a B Corp? You have to have a year of operating history.

But there's a pending status level, which is where we're at now, and then basically a roadmap of what do you do over the next year then to get your certification. It's kind of fun. Everyone has been motivated by it. That is awesome. We feel like it's a differentiator both to potential talent, but then also our clients.

They want to work with companies that more and more folks want to work for companies that are focused on providing a benefit to the community, and, you know, you want to work with other companies that do the same, are like-minded. Yeah, that is really cool. The, you know, I think you see a lot of times with consultants or value-added resellers or other people like that, it's like, hey, we want to be a partner, we want to help you do things. But, you know, no matter how much they say that, you know, at the end of the day, their goal is to make money. And if their goal is to make money, no matter how much they want to do that, that, that your goals are misaligned.

Yeah, right. So having, uh, you know, having a greater purpose and having it be part of the company, I think, is really cool to, you know, to help people get to that point too. Keeps everyone aligned to the right thing. Yeah, for sure. Um, so I know you guys are still pretty new, um, and, you know, you started out with things that you thought you wanted to do Are there areas where people have come in and, and said, hey, can you also do consulting in this area?

And maybe you guys hadn't thought, oh well, this could be a great area for us. Or, you know, other emerging areas— you said machine learning or, you know, you know, IIoT, things like that— where you've thought, okay, people are gonna definitely want these services, and maybe it hasn't been quite the demand that you thought it would be yet. So yeah. Either side of that? Sure, on the first side of that, more interest in forensics maybe than we initially anticipated.

Forensics across not only API forensics, but helping folks as they have more and more services in the cloud using SaaS platforms, things like that. How do you integrate? How do you handle forensics and incident investigation? Investigation in those situations. We're seeing a little bit more of that, and so for sure that's something that as a team we were like, yeah, that's fun, it's exciting, it helps, you know, there's tough problems that we get to solve.

And so that was an area that I would say we were surprised a little bit by the need and have responded accordingly. Yeah, yeah, it's squarely in our expertise set, but I wouldn't have anticipated it. But I do think it's a little bit explainable in that server or laptop forensic stuff is very commoditized, right? You can find a whole bunch of people that do that, but as soon as you step out of that box, you end up with a lot of variability into how something was deployed, what SaaS platform was selected for a particular purpose, and what does that vendor do for security? How do they interact with the enterprise?

You start to get into this really mucky area of lack of standardization, but you still have the same problem, is we still have to be able to produce a forensically sound incident timeline and analysis even though it's not perfectly contained in a single physical box, for instance. Right.

Yeah, and then on the flip side of that, anything that you guys have thought, ooh, this is going to be— this will be our leading seller right here? And maybe not as much as you thought? I don't think so. I don't think there was anything that we necessarily had identified, you know, this is going to be our leading seller, and we're disappointed by the lack of, you know, interest necessarily. I will say that, you know, some of those, you know, again, emerging technologies, we haven't seen maybe as much interest from clients yet, but we're not saying that, you know, that's— we've had our doors open for a month and a half, and the expectation is that that's going to continue to ramp up.

You know, we're definitely seeing plenty of clients come to us with needs in the IIoT space. You know, I do believe that— we believe that that is something that is going to continue to ramp up on the machine learning AI side, just because we haven't seeing a whole lot of interest right now doesn't mean that we're gonna just be like, oh wow, that's a fit, that's a fad, right? Like, that's not really something that people need, right? I think time will tell on that. And then one of the things that's great about being a small, you know, lean company is that we can adapt and, you know, be able to take on work that maybe isn't necessarily just square in our wheelhouse while we're waiting for those things that are square in our wheelhouse to start to populate.

Yeah, I mean, a lot of this stuff isn't going away. The thing I have consistently seen, which is probably the most telling, is that there's a lot of folks out there applying technologies like machine learning, and on the whole, when you ask the question, hey, that sounds awesome, how do you secure that? You get that magic blank stare. It's like, wait, what do you mean, how do I secure that? Secure that.

And that's not just an opportunity for the space that we're in, but it is a little bit of a problem of our industry as a whole. It's like, how is it that it's 2018 and when we talk about being cybersecurity practitioners, somehow there's a bound to that that doesn't include necessarily where the business has already gone? The business has already gone to machine learning. The business has already adopted, in some cases, thousands of IIoT devices, and that didn't naturally get sucked into the cybersecurity process at a lot of organizations. I know there are exceptions out there, but I also know that there's a lot of blank stares.

Yeah, it's interesting. You talk about organizations already using machine learning, but when you start asking them about security, it's maybe a bit like, credit cards many years ago where everybody was using credit cards and nobody was really thinking about credit card security until a bunch of breaches happened. And then all of a sudden, you know, we're looking at having— now there's PCI QSA companies all over the place. And so maybe it's a little bit of that where we're seeing, you know, a lot of folks start to adopt, or companies are starting to adopt machine learning, but it's not until we get a decent number of publicized, you know, poison datasets that ended up you know, causing real financial damage to companies that they'll start to take that stuff seriously. But that's terrible, right?

I know. As an industry, sure, we're smarter than that. We should be. Yeah, we should be. So how do we get in front of that?

It's visibility, right? It's visibility to this problem. And that's, you know, that's why I love talking about it, because it gets folks thinking about, well, what are— because I'm sure there's, you know, we've talked specifically about these areas. I'm sure there's, you know, 3, 4, 5, 10 other new emerging areas we haven't talked about today that are just like this, where folks are applying technology and using data to solve a business problem that somehow has fallen outside of the purview of the natural cybersecurity process. As practitioners, we've got to go find those.

Yeah. Well, I also think sometimes even if it has fallen within the cybersecurity process, since this is emerging or an edge case, it may not hit the top of the radar. So it might get a cursory look by somebody, but it's like, hey, I've got more important stuff that's currently going on. I'll get to this stuff eventually. And that's maybe as big of a problem too.

We are getting close to time, but one of the things that I wanted to ask you guys before we go, and I'm sure everyone is curious about this, where did the name Rule 4 come from? That's a great question. That's awesome. Yeah, um, so are you familiar with Isaac Asimov, the science fiction writer from the '40s? Um, you know, he, uh, in his writings came up with what is commonly known as the 3 laws of robotics, and I'll do my best here.

The first one is that a robot shall not harm another human being. The other one, the second law, is a robot shall— or it's actually the laws of the positronic brain, but we call it, you know, AI or robots. The second law, sorry, is that a robot shall not harm another robot. And then the third one is that, you know, barring those other things as long as it doesn't, it should do what it is, you know, sorry, what it is programmed or designed to do, right? Why it was created.

It should follow the rules as long as it doesn't interfere with the other 2. So some time went by and then he realized that that was fairly short-sighted and that there should be another rule or a 4th rule, sometimes known as the zeroth rule, that is, as long as it doesn't conflict with the other 3, a robot should do what it can to better and help humanity. And we just thought that was a fascinating sort of analogy for how, you know, we're trying to build this organization to be a B Corp, to be— provide, you know, benefit and to make the world a better place. And it's just really, I don't know, it's interesting that it took so long for him to realize is like not only should it not hurt things, but it should also try to help things. And that's just an interesting sort of shift.

Well, and where we are as a society right now, we're applying technology faster than we ever have before and in more cases than we ever have before. But, you know, are we doing that to the benefit of humankind in all cases? I don't know. I'll leave that as an exercise to the listener. Right.

I'm sure there are varying opinions. I'm sure there are. Well, awesome. Guys, any areas or questions that I didn't ask that you guys wanted to touch on?

You know, here's the thing. I think I said this when I was here on the podcast last time, but I'll say it again. One of the things I love about Colorado and the security community is everyone is so approachable, right? You can drop an email or an IM on the Colorado Equals Security Slack channel and be like, hey, Anybody know about this, or can you help me with this? And everyone is so welcoming, and I hope everyone realizes that because I know that has been a huge influence in my career.

Reach out and work with folks about anything, whether it's a specific security incident, issue, whatever, or whether it's a, hey, how do I grow my career in this direction? And so I hope everyone knows that, and I hope folks continue to support that philosophy. Yeah, you know, I travel a decent amount and, you know, talk to a lot of people that are not in Colorado, as well as people that have come here from other places and are now part of our community. And I almost universally hear, um, if they're not here, some jealousy, right? It's like, I don't have the stuff that you are talking about in my local security community.

Or if they have come here, it's like, I can't— I heard that the community was good, good, but I didn't really understand until I got here how good it was. So, you know, I echo that as well. Well, I certainly appreciate your efforts to help continue building that through the Colorado Equal Security podcast. Thank you. Well, unless you guys have anything else, I think we'll end it here.

Trent, Dan, thanks for your time. Thanks, Alex. Yeah, appreciate it, Alex. This has been Colorado Equal Security, and we'll talk to you next time. Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security.

Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes