All episodes

Joe McComb, CISO at Janus Henderson

Apple Podcasts Spotify SoundCloud

In this episode:

While we’re off this week, we are bringing you one of our favorite interviews from the past, with Joe McComb, CISO of Janus Henderson. Sit back, relax with an egg nog, and enjoy Doctor Joe talk security.

Job Openings:

Upcoming Events:

Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript8718 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a special episode for December 24th, also known as Christmas Eve 2018. Alex and I mentioned last week that we were not going to be doing any shows for the next couple of weeks.

We decided that for those folks who are working, you know, don't get the holidays off or traveling and want something to listen to, that we'd put something in your feed that you guys could hopefully enjoy. So this week we're going to have a replay of an interview we did with Joe McComb last year. Joe is the CISO over at Janus Henderson, and we had a great interview that a lot of folks gave us positive feedback on, so we thought we'd run that out there for you. No news this week other than I will mention that there's a new posting for a Manager of Security Operations and Engineering at Ping Identity You can take a look at that on the Ping website. So my hope is that you are all enjoying family and fun, maybe eating some Christmas cookies.

Now sit back and relax and enjoy this interview with Joe McComb, CISO from Janus Henderson. This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. All right, this is Robb Reck, and today I have the distinct pleasure of getting to interview one of my friends, the global CISO for Janus Henderson, Joe McComb. Joe, the thing I'm most looking forward to from you today is really getting some stock tips.

So, as I know, Janus is one of the big investment firms in the world. What are 3 or 4 stocks that I should sink all of my money into? Okay, so I actually briefed Robb earlier on this. I can't say anything about trading. Or any of the companies we trade in or anything else.

Compliance has made that perfectly clear that I can say nothing about that. So should I buy Bitcoin? I can't say.

So I do like to give Joe just a little bit of a hard time, and that's a good way to start the interview. Joe, first of all, congratulations on the kind of naming of yourself as the global CISO for the new company. I think it'd be a nice place to start by just talking about You know, Janus, which is a name I think most of the listeners have probably heard for the last— Yeah, 40 years. Yeah, a long time, most of our lives. It's no longer Janus, right?

Could you talk about that a little bit? Yeah, so basically what happened is we merged with another financial and active manager in the UK. A lot of that is really around market share, that if you look at it, they had a huge number of assets under management in the UK. We had a huge number of assets under management in the US. Uh, when you look at the direction they were moving, they were moving into the Asia-Pacific, that area, also South America.

We were also moving the same direction. It made a lot of sense strategically to combine the 2 companies. A lot of synergy in that respect. So true, true to say, Janus was headquartered in Denver, is that right? Cherry Creek, right?

Yep, absolutely. And, and Henderson was headquartered in London? London, yep. And now we're headquartered in London. Yeah.

Um, so yeah, I will be flying out there and Well, okay, I want to reveal what time, but fairly soon. Um, but the, uh, the, uh, the global CISO is here in Denver, which is pretty awesome. Is your team distributed between— uh, yeah, UK and here. Um, the team that Henderson had was a lot smaller, um, than the team that you saw in the US, and they were really beginning to grow in size. And so kind of one of the advantages they got with the merger is they got some synergy around that, the fact that they didn't need to, you know, suddenly add a US team or something similar.

Yeah, we were much larger. The CIO is also located in Denver, so you see kind of the major information— well, information technology presence is all located in Denver. Yeah. Okay, well, let's back way up. All right, so yeah, I assume that, you know, from day one you were always a security person, right?

And you went to college and got your security degree and so forth. Is that true? No. No, no, not at all. What'd you study?

Uh, boy, that's a long story. Um, okay, so undergrad was chemistry, of course, CU Boulder, you know. Yeah, had to be a Colorado school. Go Buffs. And I also got an anthropology, uh, major in that.

Then I combined chemistry and anthropology. That's kind of a strange mix, right? Seems kind of crazy, right? Um, a little bit. Um, human population genetics, all that cool stuff you see on TV, along with, um, the stuff that you see on CSI.

Um, so after I got that degree, I said, okay, I'm gonna combine these 2, whereas everybody else I knew was going to med school and they thought I was crazy going into anthropology. And I said, I'm gonna, I'm gonna go into anthropological genetics, it's gonna be great. Um, boy. Um, and so I went to the University of Kansas, um, and started studying anthropological genetics, and I was what you call classically trained. There's, uh, 4 primary fields in anthropology.

There's linguistics, sociocultural, archaeology, and there's physical. And I was trained in all those fields, trained also in what you'd call forensics now. So I had a whole class on osteology. What's osteology? Study bones, how to identify.

Yeah, it was great. You sit there and you work through, you'd work through if you had a bone that somebody handed you or a fragment, you'd sit there and you work through, okay, which side is it from? What part is it? Human or non-human? If it's a tooth, you know, upper, lower, adult, you know, the like.

And that field is kind of coming to popularity now in terms of that everybody watches the crime shows and you, you have this forensic pathologist, right, or somebody similar to that. And then you also have this whole area of DNA fingerprinting. I was also, you know, trained in DNA fingerprinting, uh, from paternity lab. And if you look at all— paternity lab means you're going to find out who the father is? Exactly.

Yeah. But I mean, they handle forensic cases too. Did you work on Jerry Springer? No.

No, oh boy, and that's a really— you missed your chance, I got it. That's a really seedy— no, and that kind of swayed me into why I ended up going more IT. So for a while there, I was— I'd gotten a PhD and I was being courted by— okay, I won't say what organization, but it was basically to run a forensics lab. And, you know, we're talking about this and I said, okay, so how much are we talking per year? And they said $17,000, so $17K a year.

Yeah, in 1999. '99? Yeah, so think about that. So that's not great. No, that's not great.

There's this dot-com boom. Yeah. And meanwhile, I've been putting myself through school doing, you know, what everybody else has been doing, you know, the help desk. Yeah. You know, service desk work, AV, you know, web development, things like that.

And, you know, because that paid fairly well. Yeah. And that's almost a minimum wage. It's not too much more than minimum wage. Exactly, exactly.

And then there's this big dot-com boom and everybody's like, You know how to code HTML? Like, yeah, of course, you know, who doesn't? You know JavaScript? Yeah, absolutely. You know Java?

Yeah, absolutely. And then all of a sudden they're like, hey, you're hired. Yeah. And we remember that whole boom, right? That whole boom period.

Yeah. And that brings me to a pharmaceutical company called Merck, and I worked there for about 6 and a half years. It was server administration. And then this is the fun part. So about 15 years ago they said, what do you want to do next?

And I said, there's a security position that somebody, you know, nobody seems to want to fill. I said, I've always wanted to do security. Yeah, you know, I love, you know, like trying to break into systems. This is great.

And so they came back and asked me about a week later, do you really want to go to the security position? It's like, yes, this sounds really cool. They're like, you're totally certain you want to go into security? Yeah, we got to put that in perspective. This is, you know, 2002.

Yeah. Yeah. And we remember those That era. Sarbanes-Oxley was coming around the corner. It was either there or coming around the corner.

Senate Bill 1386, so California just released that, you know, their first, you know, that you must report breaches. Data breach stuff. Yeah, exactly. But for the most part, everybody, you know, this was like that field where it was kind of the dumping ground and people just didn't like it. And so I think it's funny, you know, when you see postings for like, you know, 15 years of security experience, you must have a PhD.

And I'm like, come on, you know, people, people back then, we, you know, you got the people that really, really, really wanted to do this because, you know, nobody else was really— there wasn't a lot of defenders at that point. There was, there was the people who were hacking. Yeah. And then there was like, yeah, there was sysadmins who as a side thing would also try and stop the bad guys, right? I'm gonna try and get the system set up and maybe I'll lock it down at the same time.

Probably not. Yeah, that was exactly it, you know. Yeah, and you know, I was kind of this crazy guy who like, it's like, this is great. I'm gonna set up this Nessus server because I'm a server admin and I've got the resources to do this. So, you know, I set up the Nessus box scanning, you know, then I go talk to the— I was like a divisional security administrator and I go talk to the corporate security team and they're like, wow, this is really cool.

How do you do this? Because, you know, you're right. I mean, they were kind of access and administration and policy. Yeah, you know, that was what they did. Not security engineering, security architecture.

Not at all. And, you know, and so, so things like, you know, network worms which were coming through, you know, we'd see Sasser and all these other pieces. Yeah, Code Red, Slammer. Yeah, Slammer, exactly. Remember when all those were hitting?

Yeah. And so I'm the guy that's like reading the logs and I'm like, okay, I can see this. And they're like, great, can you tell us what's going on? I'm like, you know, I'm, I'm your regional guy. Yeah, you know, it's like Yeah, that's how you get to do new stuff though, right?

Yeah, and I admit it was a blast. Yeah. So you said 6 years doing that at Merck. Did you move around or were you doing the security stuff the whole time? So yeah, so for about 2 years I was doing web development, server admin, and then what, 4 and a half years I was doing security stuff.

And it's kind of funny too because I was one of those people that basically said, okay, when I get my CISSP, not to put other people on the spot here, but I'm actually going to get the requisite amount of education, um, you know, time— sorry, time spent on the job. That's what I'm trying to say. Oh, the 5 years? Yeah, the 5 years. Yeah, exactly.

Or with college degree, like 4. So, so literally right when I got that was when I went and took the test and bang, CISSP, and went from there. That's big times, right? Yeah, absolutely. What year did you get your CISSP?

Um, 2005. That's really early. Yeah, absolutely. That's early. Yeah, New York City.

Um, never forget that. And, um, ironically Like, there was one of the people that was proctoring it, he like sends me a note literally 4 weeks later, he's like, did you get it? I was like, yeah. He's like, do you want to come and interview with us?

Yeah, I mean, like that. It was just kind of funny. So did you end up— it sounds like you ended up changing jobs shortly after you got it. Yeah, I did. So 2006, And what happened then is there was this little thing called Vioxx.

So I worked for this pharmaceutical company called Merck, and Vioxx hit, and basically pharmaceuticals took a hit right there. What's Vioxx? Vioxx was what's called a COX-2 inhibitor. What that means is it's used to control pain, typically for arthritis. And so what we learned about Vioxx was that it doubled the rate of heart attacks, basically.

Yeah, so it gets pulled off the market. Um, there's one COX-2 inhibitor Pfizer still has, Celebrex, that's still on the market. Um, it's what's called a black box drug, which means— so, okay, quick lesson in pharmaceuticals. Yep. If you hear the term black box drug, what it means is when you look at things that are bad that can happen to you, there's a little black box around it.

The black box basically means that really bad things can happen to you, like death, right, cancer, you know, things like that. Yeah, um, and so the side effects are potentially life-altering. Yes, exactly, life-altering. And so it was a black box drug. So Merck stock took a hit.

Um, there was a huge series of layoffs after that. I watched a lot of my friends get laid off, but not in the security field. Um, you know, I kept being told, yeah, you know, you're, you know, you're important and valuable. And after about the 4th round, I said to myself, you know, life is really short. Why did I go back to Colorado?

That's, you know, I grew up, I grew up in Fort Collins. Yeah. You know, I just missed this lifestyle. And so I started looking for jobs out here. Yeah.

Um, and, you know, that really set it. And I, uh, ended up at Policy Studies, uh, for 2 and a half years. Interesting. Um, have you heard of Policy Studies? I have, yeah.

They're over by the ballpark, right? Yep, yep, yep, absolutely. I've known a few— now I can't— oh yeah, you're escaping me. I've known a few other folks there over the years. Yeah, Dan Collander.

Yeah, Dan was there. Yeah, yeah, from— who's a ball now. Yeah. Sue Lapierre. Yeah, over at Prologis.

Yeah, absolutely. Sue was my former boss. So it was spitting out CISOs over there left and right. Exactly, it was spitting out CISOs. Yeah, and it's ironic.

So it's true, right? Yeah. I mean, 'cause yeah, you get Marlene Villanueva. Oh yeah. Actually, she may have changed her last name now.

You get Sue, who— I think Marlene left Denver too. I think she moved up to Portland or something. That makes sense. Interesting. Yeah, and then you get Sue, who's very active in the community right now.

You get Dan Collander. Yeah. Um, and then, yeah, I went to, um, Janus. So how long were you at Policy Studies? Uh, 2 and a half years.

Okay. Um, yeah, I learned a ton at Policy Studies. So is that 2007 to 2009 timeframe? Uh, yeah, 2006, right at the end, to 2009. You got it exactly.

Um, yeah, so I was working under Dan Collender at the time. Yeah, really, really good team. Um, you know, really enjoyed the time there. Um, you know, we were, we were the best way to say it, a little underfunded. But yeah, I mean, that happens in security.

But, you know, when you look at it, I learned a ton of policy. Yeah, absolutely. And then I was tapped to go work at Janus, you know, in 2009. So what were you hired into Janus as? Manager, to basically manage the access control area, to manage kind of the project security, you know, basically guiding new projects that are coming in through the security reviews of projects.

Yeah, exactly. Pieces like that. SAP security for Sarbanes-Oxley because that was the primary financial accounting system.

Some other pieces, a little bit about the vulnerability management, that piece. Do you want to kind of continue? Yeah, that's great. So when you were hired, tell me about the Janus security team. We're talking 2009.

The year one of how many, and how'd that structure look? Yeah, so I go in, um, so I had 5 direct reports when I entered. Um, the security team had a director, and he had 3 reports— oh, 4 reports including me under him. Um, so that's 10 total. Okay.

All across the board. Yeah, relatively larger team. And how many people worked at Janus at the time? Uh, at the time it was what, 1,000 300, around there. Well, that's a really big security team for a 1,300-person company.

Absolutely. Yeah. Yeah, that's good. Yeah, it was. Yeah, and part of that was because the, the CIO at the time had gone through breaches at other companies.

Sure. And so he realized the value of this. Okay. And so he just said, okay, so I'm gonna, I'm gonna build up the security team a little more because I don't want to have that happen to me again. Yeah.

You guys have a lot of stuff worth protecting. Oh, absolutely. Yeah. Okay, so talk us through. You were hired in as a manager over IAM and projects and so forth, and, you know, 8 years later, what's happened over the last 8 years?

So then a couple years later, new management came in, actually reduced the size of the security team a little bit, another way to say that, and then tapped me to run the broad security team. So my boss, a wonderful man named Randy Carmichael, he's deceased, By the way. Yeah, he at the time when the new management came in said, okay, so I've been here for 14 years, I'm going to move on. He left and then I got tapped for his role. So I took on the whole vulnerability management team, including the penetration testing, that kind of piece of it, managing, writing up findings around patches, policy, all the things that you consider like classical information security.

So 2011 timeframe we're talking about? 2011. And you were Director of Information Security, is that the title? No, they did a trial period. They just gave you the work but not the title?

Yes, exactly. They did a trial period, so I was still a manager for— it was kind of the funny, you know, usual trial period that you get, you know. It's like I was a manager for, I don't know, like a year and a half, 2 years, around there. Yeah, I think it was about a year and a half. And they finally said, okay, so we need to promote, you know, promote you.

And it was kind of funny because one of the things that I did is I changed the focus of the team then. So, and this is the thing that we've all started doing during that period. We said, okay, so it's not if we're gonna get breached, it's kind of more of a when and what we do about it, right? And so at the time, we were heavily reliant on preventative controls. And so I said, okay, so what we're gonna do is we're gonna change to a monitoring posture.

There was this incredible guy that worked for me. Oh, I can mention him, Todd Garrison. Yeah, so, who has recently left my team, unfortunately. Yeah, it's a bigger loss. Was it Ty or Todd?

Todd. Todd Garrison? Yeah, exactly. Hi, Todd. Fantastic guy.

Yeah, brilliant. And so he and I began transforming the team. We said, okay, so what we're gonna do instead is we're gonna adopt more of a monitoring posture. And, you know, I'll never forget, so we went to management and we said, okay, so we want to free up money for a SIEM, and we also want to put in more IDS. We've got barely any kind of IDS support.

Yeah. And so, and I can mention products, right? Sure. Cool. Good.

Yeah, so especially if you have bad things to say about them, that's the most fun. Yeah, well, I have good things to say about FireEye. So, so yeah, so we brought in FireEye and Yeah, and, you know, fantastic. I remember the first time we stuck in FireEye, and they always say, you know, you stick it in and people like run in terror. We stuck it in and nothing happened for like days.

And, you know, I kept asking Todd, I was like, you know, what's going on with this? And he's like, you know, we've done the test, we did everything else. And then on about the third day, somebody hit an exploit kit. Yeah, I'm like, this works. This is great.

This is what we've been looking for, you know. So, you know, FireEye is kind of rolled out, rolled out the SIEM. Um, and then we began, you know, I said, okay, so what we're going to do from here, um, and people ask me, they say, okay, so you were— you did all this anthropological work, how does this relate to anything, right? And so, um, when you start going through all the work that I did in anthropology, so I did DNA fingerprinting, yeah, and the purpose of that was to look at human populations. So can I just real quick, for those who are not watching, yes, those who are listening, yeah, Joe just pulled out a book Which is his— is it dissertation or thesis?

So this one's the dissertation, this is the thesis, yeah. And Robb, you're actually the first person, I think, that gets to see this. Most people don't usually get to see this anymore. So I'm now holding a bound book showing the cluster analysis of populations using the RAPD frequencies. Yes, exactly.

So we're basically talking about looking at populations and how they're genetically related, right? And so when you think about this, what you're looking at is you're looking at this big data set of a bunch of stuff. And you're trying to figure out who's related to who, and you're looking for anomalies. And that, that's a lot of what my work, you know, what I did during that period. Um, the master's is much more interesting, I'll tell you that one.

Okay, this one looks at Native Americans and kind of how all that relates together with the Siberians and pieces like that. Yeah, yeah, you see, you see these, these frequency charts along here, right? Yeah, higher and lower. And if you think about this, if you're thinking data analysis is what we're looking at, that's exactly frequency analysis. Yeah, you're looking at frequency analysis and data analysis and And how do you, how do you parallel that out?

And so, and it's the same thing. We're getting a bunch of data in logs and we're trying to figure out how do we represent this in meaningful ways, one, to help defend our company, and then 2, when we're talking to management, what does this mean? Are we doing well in terms of security? Are we doing poorly? You know, so, you know, we start getting these, these FireEye results in.

Yeah. So, of course, what do I do? I start quantifying that, and one of the first things we figure out is we're like, wow, 50% of the compromises that we see are Java-based.

We see it, we detect it, we pull it, wipe the machine entirely, start over. Okay. So, our realization there is, what's going on outside the company? There's a really good paper by Microsoft. It's, what is it, Data-Driven Security Defense, 2015, big subscriber to that paper.

So looking at your environment and saying, what are the attacks that we see that are coming in and what can we do around that? So, you know, the first thing you do in that case is you basically change how you're patching Java, which we did. We heavily improved that. You look at how exploit kits are being developed and kind of the time that it takes from when you see an Adobe Flash vulnerability to when it actually gets posted. And you actually gauge your patching time off of that, and you change the patch priorities based off of that.

And so we began pulling in our metrics program and developing according to that, including changes in the firewall, changes to executables coming down. For example, not to pick on the Russians, but I will a little bit here. So one of my analysts who I won't mention the name because I don't want to be poaching him, Did a fantastic job. He did this analysis where he looked at the exploit kits we were getting hit by and geographically where those were located. And at the time, 50 to 60% were all former Soviet states.

And so it's funny because, you know, I would talk to management out there like, ah yeah, the Russians are coming after us. Like, no, this is bulletproof hosting. This is what it is. It's hosting facilities that nobody asks any questions, right? And so, you know, they don't care.

So Of course, that's a great place to, you know, put up any attack. Yeah, launch your attack. Absolutely. It's fantastic. I mean, here, here also California is on our list.

We block California. Exactly right. You know, and, and so what we did is we modified our firewall rules because we don't do a huge amount of business with Russia. And we said, okay, if it's an unclassified site coming in from Russia, let's block that. Yeah.

Yeah. And that heavily dropped the alerts that we were seeing coming in from exploit kits from that area. That's great. Yeah, absolutely. So yeah, so the way that this all relates is, you know, my primary focus was statistics and analytics, really.

And so, you know, I brought that into the company to say, okay, so let's look at this statistically and then say, how can we reduce, you know, prevent attacks but continue monitoring what's going on in the environment? And, you know, we've seen attack trends, you know, change dramatically. Yeah. I mean, if I were to ask you about ransomware in, let's say, 2000, You'd say, what? I'd say 2010, you'd say, uh, rogue AV, you know, what is that, right?

You know, maybe. But 2 years ago I said ransomware, you're like, oh yeah, I know about that now, right? And we've seen that pattern heavily shift. And I actually have a wonderful graph that shows that. You know, I say, okay, we were, you know, $40 for rogue AV, and what did we do if we saw, you know, rogue AV infection?

Wipe the machine, done, right? Yeah. Whereas now, you know, you see, you know, the newer stuff. WannaCry, we haven't seen. We've seen other types of ransomware, mainly blocked, which is good.

But, you know, when you go to that kind of level, you realize that if somebody's getting paid $200, $400 for, you know, Bitcoin for that, of course there's incentive to continue on like that, right? Looking at the attack trends. Let's move forward a little bit in your time at Janus. You, you, 2013-ish, is that when you got the official promotion? Yeah.

And where were you reporting at that time? I was reporting into operational risk. Okay. Yeah, kind of unusual. Is that the people who do like the financial risk, strategic risk for the company?

Or what's operational risk? Yeah, so what operational risk did specifically is they had business continuity, data protection under them, a true operational risk field. So looking at processes within the company and how those might go wrong, how they might affect stuff. A little bit of investment risk goes into that area. Quality, the quality too.

Quality was there, absolutely. Yeah, yep, QA was actually part of that area, you know, big, big focus on process analysis. And they were under the operations area, so Chief Operations Officer, and there's kind of 2 different areas if you look at it. There was CTO and there was the operational risk area. Okay.

And so kind of fast forward, set of management changes again. Yeah, and I was moved into the IT area. Okay, and when was that? That was 2016. Okay.

Yeah, so just last year. Just last year you moved to report to the CIO directly? Yep, exactly. And then when did you get the title? The actual CISO title?

Beginning of this year. And that was just basically as a part of the merger, we're ready to recognize this position as kind of being a higher-level executive? Yeah, yeah, and Kind of to that point, I had been doing the CISO work, and a lot of other people out there will appreciate this, for a long time, by the way. 2016 was really the first time that I was really beginning to speak to boards in that regard. So there was part of that.

I'd been managing the security program for years prior to that, and I consolidated. So there was some restructuring. I consolidated the security areas into my area from there. And then, yeah, it was 2017 when it actually— Has the change of title made a difference for you in terms of internal— well, ask 2 different ways. Inside Janus Henderson, has it made a difference for you?

Yeah, that's a hard one to answer. In part, yes.

I think there's more recognition really outside of the company around the title. Yeah, I remember going to this one session one time with E&Y and they said, We want you on this panel. I'm like, great. And so they went through and they're like, this CISO of this, this is the CISO of this, this is the CISO of this. And they get to me and they're like, and you're— I'm like, security guy, just call me the security guy.

Yeah, you know, half jokingly. Um, and for me, the recognition outside has, has increased. Internally, there's been some effect, um, but really, you know, my, my influence was always more metric-driven. And talking about how these are the threats that operate, this is what I'm seeing, these are my recommendations. It's like if— my team also does contract analysis, which makes sense.

And you'll appreciate this and other people will on the board, where we have a set of security requirements that we embed in contracts. And you will inevitably get some vendor that'll say, I refuse, I will not do any of this. And that's where my job is to go to the business and say, you know, the data that you, you've got here is either a low risk or it's a high risk, and they're absolutely refusing to adhere to any kind of security contract. Yeah, you know, language. And then of course ask me, well, okay, so did you do due diligence?

I'll say yes, you know, we went through, we did, you know, a checklist. Um, usually it's about 20 questions, it's not that big. And then I can say, I can give you an idea on paper where that risk lies. Ultimately, you know, there's— decision is going to be hitting you because you're going to be accepting this risk, you know, one way or another. Yeah.

So my influence was always kind of driven from those metrics. So I'm interested in just digging into that particular situation a little bit more because this— I'm sure many of us experience that same type of conversation. And, you know, I've always been the kind of guy like, hey, I'm here to enable the business. I'm here to— absolutely. I'm here to inform them about what— about it so they can make their own risk decisions.

But my experience after doing this for, you know, 10+ years is they don't— they really want me to give— to guide them to one answer. They want a recommendation. They want to recommend. They don't want me to say, here's the risk, what's your decision? They want to say, here's the risk, here's my recommendation.

Yes. And, and then they almost always go with the recommendation. Absolutely. And that, that's been my experience too. Um, and I will come in with a recommendation Um, you know, usually I'll give them, you know, kind of when you've worked through the risk and you actually have a classification, whether this is a low, whether this is a high, and I will come with recommendation and typically controls based upon that.

And then there'll be a conversation about cost of controls, you know, how does this work, other pieces like that. And they, they almost always ask for that exactly. And I'll say one other experience I've had, and I'd love to see if it resonates with you too, The, the higher in the organization I take the conversation, the less likely they are to accept the risk. The individual contributor level are willing to say, no big deal, the business needs it. Yeah.

And then as we get higher and higher, they're like, whoa, whoa, whoa, this risk really matters. Yes. Yeah. And, and typically, it's, it's funny, for when I've seen it, it's typically right around that VP level. I hate to say it like that.

But when they— when you kind of hit that officer of the company kind of level, yeah, that's when they're less willing to take that risk or more willing to discuss what, what is going on. And it might be that just the better visibility across the company, right, that they better understand things outside of their silo. And if you're, if you're in a silo and you don't see the rest of the company, you just don't have the perspective, the context to know whether that risk matters. Yeah, and that, that was actually a mistake that I kind of made earlier on, not at Janus but at other companies, where I, I was taking that risk level too low. There's no other way to say it.

Yeah. And, you know, I'd go to the manager and say, hey, sign off on this. Yeah. And they'd be like, oh, no problem, because here's my signature. Yeah, absolutely.

In fact, let me give you a stamp. You can just stamp it whenever you want to. Exactly. That's exactly it. And whereas, you know, as kind of my influence kind of, you know, pervaded among the, uh, the company, got out there Um, you know, I started moving up, and so, you know, I would go have those candid conversations with, you know, people that are much higher up.

Yeah, Chief of Staff Investments, or, you know, basically the head of marketing or something similar. And that was the right level, you know. I'd say, okay, so when we're looking at this risk, this, this is what I'm recommending. It's probably a low risk, you know. I'd recommend that, you know, you probably accept it, but here's some controls that are going to help control it.

Um, so I'm gonna— we only have 10 minutes left. I'm gonna ask you a couple questions while we have some time. Yeah. All right, so, you know, I now know a little bit about your, your research, your background, uh, and you're a security guy. Have you played around with CRISPR at all?

I have not. You know what I'm talking about? No, I don't. Tell me about it. It's a DNA hacking— Cool.

Yeah, it sounds right up your alley. Yeah, I should play with it. You should play around with it. And now there's like a home CRISPR you can like— Oh, so I can actually do my— Yeah, for a reasonable price. Yeah.

That'd be a blast too, because— I want to circle back with you in 6 months. This is your assignment to go learn CRISPR. Learn CRISPR in action. And then teach me how it works. My wife's going to love that, because I'm going to be back down in the lab with pipettes, and I'm going to be like, yeah, all right.

I guess it's actually genome editing is what it is. Yeah. Genome and DNA, is that interchangeable? Can I do that? It's fine.

It's fine. Let's just go with it. It's not, but it's fine. Let's just go with it. That's not my background.

Yeah. All right, priorities for you. What are your priorities for the next year or so in your security program? Oh gosh, integration. So we are still integrating.

Yeah, it's funny because, you know, for some people like in our company, they're like, aren't we done integrating? It's like, no. I mean, this is gonna continue on for the next, you know, year and a half easily. So integrating 2 different teams, incident management programs, vulnerability management, The vendor due diligence pieces that we just talked about, you know, all of those pieces majorly. And, you know, it's just funny, I just did a presentation on this where, you know, I put up 6 months of incidents, you know, and say, okay, so here's all the pressure that's coming in from the incidents.

Then I put up 6 months of regulatory responses, which were actually— they're kind of, if you think about it, all those regulatory responses are actually the incidents that happened like 2 years ago, really. And so I put all those up, and it's phenomenal change. I mean, we see that across the board. You know, people right now are all dealing with EU GDPR, and on the US side, we're all asking, you know, oh my gosh, how can they enforce it? For me, I'm a UK-based company.

I have to worry about this, right? Absolutely. And there's an immense regulatory change right now. Yeah, that's going on. Does the New York financial services regulation impact you guys?

A little bit. We're not specifically registered with that authority. Yeah, at least that's, that's what we've determined. But, you know, to say that I'm not watching it and not trying to adhere to it would be a gross misstatement. Yeah, you know, I've gone through the controls that they've recommended, gone through it, actually went through it yesterday with my vulnerability management testing team.

I said, okay, we need to be aware of this because if it's not New York, it's going to be, you know, the next state in line, and it will affect us. So the only— yeah, so I, I did quite a bit of research reading through it. The only thing on that that we shouldn't already be doing, right, if you already are running a good security program, you're absolutely right that most of it we should be doing. The only stuff that we shouldn't be doing was there's, there's like, you know, the CISO has to write a letter, has to like, yeah, has to like register, and that's, you know, I'm not going to do that because I don't have to, but, but I should compliant with the steps that they have in there. Absolutely.

Frankly, anyone out there who's running a security program, you should probably look at it. Yeah. And if you're not doing something, put it on your list of stuff to get to. Yeah. I mean, you know, the basics that we looked at yesterday, you know, the annual penetration testing, should already be doing that.

Risk assessments. Yeah, exactly. And the risk assessments too. Yeah. Yeah.

I thought the penetration testing was a little lower down in the line, but that's okay. I don't remember the— I don't remember the— because there was different timing for how they phase it in, and I don't remember all the phase-in timing. Yeah. And there was also the original draft Um, when I was looking at that, what I recall is it had like, you know, actual stated like vulnerability testing periods. Um, that changed when I looked at it later.

Okay. Because I saw some of the early drafts of that bill too. So, um, yeah. So priorities for next year: compliance, integration. Uh, anything else you want to throw out there that you're, you're thinking about for next year?

Um, absolutely always looking at staff development. Sure. Um, there's just no other way to say it. Um, we all know this, you know, everybody's kind of strapped. Um, I have a a good internship program, had some really good interns come up through.

Did you end up hiring some of those? Yep, hired one of them. That's great. Have another one that's still in college right now. Yeah.

So yeah, he's been doing a fantastic job. It's the one thing that we really need to do to help the community more than anything else. Make more security people instead of just poaching from each other. Yeah, and you know, and I think a lot of us have realized that, that, you know, we need to give back. The one, you know, this And also I had kind of a frustration where I'd see these programs and I'd see them kind of turn out security people and they, they're really, really book smart, but they didn't have certain strengths that I'd be looking for, you know, like I want to always keep learning and I really like, you know, either breaking into systems or there's something, something that's driving them in information security.

And I wasn't seeing that coming out of the people in the programs. And so I said, okay, so I'm gonna try to get back to the programs and try to nurture that in those people that really want to do that. That's great. I love it. So for those, I don't know if you're going to be hiring next year.

Well, I guess, are you going to be hiring next year that you're aware of? I think right now we're probably going to be relatively flat. Okay. Yeah, we're right now at about 13 people, which, you know, could be a larger program for, you know, 2,200 people or smaller, depending on if for financial services, depending. It depends on how much you put inside your security versus in IT, how much is oversight, how much is operations at all.

It's hard to compare. It's really hard to compare that model. We can compare offline a little bit. Yeah. If you do hire someone, what are the skill sets that you're most likely to be looking for?

Yeah, so typically, you know, a drive to always keep learning, you know, to keep up, you know, and just keep learning. Attitude. Yeah, attitude. And just, you know, I want somebody that's constantly coming in and kind of challenging and say, hey, did you look at this? Did you Did you see this?

This is neat. Absolutely. Kind of that drive to not accept— like, when you're looking at log data or something else like that, not accept the immediate answer, to kind of continue digging and to continue monitoring and doing analytics around data. I love that piece. They're constantly looking at data, this log data, and saying, okay, so it doesn't look like this.

Let me dig a little further. You know, what's the next piece?

I admit I do look for people that want to look for a CISSP. It's not a requirement, but that kind of fuels that kind of always learning because then they fall into the CPE cycle and they'll be constantly developing knowledge from there. One of the things I really— so I'm not a huge certification guy. I'm not going to turn away an applicant because they don't have it, but I will say one of the really big values of having especially CISSP Although Security+ gets you there too. Yeah, absolutely.

Is you can speak the language. Yeah, right. Yeah, you could be the most technical person in the world, but if you don't understand the difference between a vulnerability and a risk and a threat, yeah, absolutely. It's just harder to communicate, right? Yeah.

Yeah. So if we could talk, we could talk about it a little bit, a little bit better. If you've been through the training, you know, you've learned what they say, it's a mile wide and an inch deep. That is what it is, right? CISSP doesn't get you ready to do any job.

No, but it makes it so we can talk. Yeah, and in truth, we had this conversation about college. You think that I'm looking for people with PhDs. I'm not. Some of the people that I've had on my team don't even have a college degree.

That isn't the piece. I typically encourage them to get a CISSP over time because then it helps the language. They learn a bunch of different areas. That's not what I'm immediately looking for when they come in either, but I'm looking for kind of that drive to continue with that. And there's another piece around that too, around the certifications.

One of the reasons why I'm a little more pro on that is, you know, the fact is we've all worked a lot of jobs, and, you know, when you look at the market, you look at all these jobs that are looking for CISA, CISSP, CISM, there's a bunch of different pieces. And one of the things that I want to be able to do is still enable them, and I realize they're not always going to probably want to work for me or always will work for me, and so I want them to be, you know, prepared that, you know, if they leave they actually have something that's gonna help them, you know, move on to the next level. It does prove a certain level of seriousness about your security career. Yeah, right. You're not a tourist if you spent the time to get a CISSP, right?

That doesn't mean that you're good, right? It's just one piece of evidence. It's a piece of evidence. We talked about this with the Equifax breach, and we were all like down because Everybody's like, okay, there's CISO as a major. It's like, well, you know, 15 years ago, 25 years ago, you know, there weren't degrees in that.

And so kind of, you know, if you, you know, because I'm in those same shoes, right? You know, my degree is in, you know, anthropology biochemistry, right? But, you know, CISSP, GSEC, people never mention the GSEC, you know, G27000, you know, or 2700 is I think what SANS put it as. You know, all those different certifications. Yeah, you know, it does show a seriousness, right, to be part of the security community.

So I'm with you. All right, so we are just about out of time, Joe. I know we have, we have another meeting we got to run off to. Yeah. Is there any final stuff you wanted to say to the community?

Any, any words of wisdom that you want to leave us with? Oh, what are you holding right now? Well, I almost forgot. What do you— oh yeah, no, this is fun. So Yeah, to kind of relax lately, I've been learning how to make chainmail.

Yeah. Um, and it makes sense, you know, we're always the defender, right? So you're sitting there, you're thinking, I need a chainmail shirt, you know. We'll see if I ever get that big. This, this piece is about the size of my palm, you know.

Yeah, this would, this would not protect very much of you. Yeah, exactly. So maybe my pocket protector. So it seems like fairly lightweight metal here. Yeah, that's aluminum, which means it's easy to work with.

So I assume that this would not stop. No, not at all. This is more to relax and have fun. This is for looking cool. Yeah, this is for looking cool, and it's more relaxed and have fun.

Are you a ren faire guy? You're gonna be taking this to the ren faire? No, this is more relaxed. I went the other direction. I went to, you know, I was a weird part of my life too.

I fenced for years. Oh really? Yeah, I actually taught fencing for a couple years. Okay. Yeah, and So I went that direction.

So really, I mean truly, you know, competitive fencing, that kind of area. I was not all that good. Well, you don't need to be all that good if the other person's not a fencer. Yeah, that's true. So yeah, so this has been more for fun than anything else.

Oh, very cool. Yeah, absolutely. You know, and the big thing right now that I've got to say, if you're developing your security career right now, is link your security initiatives to business strategy more than anything else. Because really you're there to enable the business. Yeah, that's why you're there.

And it's a differentiator because so many security people think they're there for the sake of security. And if you can be the one who says, here's how we help the company enable these few things, it's so enlightening, right? Refreshing for them. Yeah, and absolutely. And we know some of the security community that go in there and they say, no, right?

No, we can't do that. Yeah, whereas if you go and you say, Yes, we can do this. This is what I'm recommending, you know, to enable us so we don't, you know, we don't run into the problems. It's like, you know, it's like if you had like a military convoy, the military convoy has, it has an objective. It's got to get somewhere, right?

And if your whole purpose is to say, we have to stop, rally, shoot, and that's all we're going to do, you never get there, right? Yeah, business strategy is all about getting there. Let's get linked back to your business strategy. Absolutely. And if you, and if you can find metrics that that show how you impact that.

Exactly. You're number one, you're a unicorn. Yes. But you just became incredibly valuable to your company. Absolutely.

All right, well, cool. Thanks a lot. This has been really fun. Yeah, hopefully we can do this again maybe in 2018 and yeah, absolutely see how it's changed. Yeah.

All right, absolutely. Talk to you soon. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes