Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 98 for the week of December 31st, 2018. Obviously the last episode of the year.
We are taking this week off once again. Alex and I are enjoying time with our friends and families and sticking away from the podcast, but we do have an interview we're gonna replay from earlier this year, one of our best of. We had Nancy Phillips, the CISO from Centura Health, who's going to be our featured guest this week. I do have a couple of quick things we'll say, a couple of jobs that I'll remind you guys are out there. There's the manager of security operations and engineering over at Ping Identity working for me.
Be happy to have someone talk to any of you folks about that. We also have a GRC analyst at Ping Identity, more entry-level position. Take a look at both of those on the website, also in the show notes here. We will be back next week, the first week of January, with a new episode, new content, new news, catch you up on everything that's happened in the last few weeks. We're looking forward to it.
With that, I'll tell you guys, you know, enjoy ringing in the new year. Be safe out there on the roads. I want to make sure all of you listeners are still around to enjoy 2019 with us. Enjoy your holiday, and we'll talk to you again in 2019. Hello, this is Ian Buxton, Senior Director of Information Risk and Security at Vail Resorts.
This is Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.
Welcome to Colorado Equals Security. This is Alex Wood, and I have a feature interview today with a very special guest. I'd like to welcome Nancy Phillips. Hi, Nancy. Hi, Alex.
How are you? I'm great, thanks. Awesome. Appreciate you taking a little time to talk with us today. Absolutely.
So, we've known each other for, I don't know, a long time now. Yeah, quite a few years. But I'm sure there's a few people out there that don't know you. So, why don't we start by talking about who you are? Hmm, who I am.
Boy, that's a good question. So from a career perspective, I'm now the Chief Information Security Officer for Centura Health. Awesome. Which means, you know, a long history of jobs and stops along the way to get to here. So I started out, as many of us have, in the military intelligence community.
Was in the Air Force for about 9 years doing intel-type work. Where were you based? Um, I was based in Japan. I was based in Las Vegas, Nevada during the days of the 117 unveiling. Okay.
And the stealth fighters, right? Nice. And then Syracuse, New York, Rome Labs. So another area of interesting intel-type work. And when you were there, this is military intelligence, not what we think of, you know, like as security intelligence or information security kind of stuff, right?
Before information security was really information security, right? So there wasn't a cybersecurity force as of yet. Those things were just starting as I was coming out of the service. So I was doing traditional military intel. They called it electronic intelligence work.
A lot in the satellite arena is kind of what I focused on. Nice. So yeah, which was an interesting background because, you know, at that time we were doing a lot of development of tactics and techniques against our adversaries. So created that mindset that made it easier to apply how to protect Right, against an adversary. If at one time you had that adversarial mindset, right, it's easier to kind of figure out how you want to protect against those things.
For sure. So then at some point you obviously got out of the military. I did. And you had to figure out what you wanted to do with yourself. Yeah, yeah, I did like most and went right into defense contracting.
Okay. Right, so took off my military clothes, put on my civilian clothes, and became a contractor doing very much the the same type of work. And that's what got me out to Colorado, actually. I went and worked down at the Space Warfare Center, at the time Falcon Air Force Base, which is now Schriever Air Force Base. So I did a lot of the same work there and continued my education and finished my bachelor's degree in computer information systems management.
And so I had an opportunity to help another side of the organization. So I was on the clearance side, the top secret side of the house. I went to the secret side to help them prep for an audit, and that's because I was able to get hands on keyboards and change directory permissions and file settings and all that other kind of stuff to make sure that the system was locked down before the auditors came. While going through that process, the guy that I was helping out said, hey, you happen to have a knack for this. Would you like to learn about cybersecurity?
And so that's kind of how I made that transition from doing the defense contracting work into the cybersecurity work. And when was that? How long ago was that? Ooh, that was back in, I would say, about '95, '96 timeframe. Okay.
So did that for a little while. Actually, for the space, for Air Force Space Command. And here's an interesting story. We developed, 'cause we did a lot of security awareness training for the Space Command bases around the United States, and we developed a traveling hacking demo to do security awareness. And so we brought 3 laptops where my boss was the bad guy and I was the good guy, and we had our mail server And we took somebody's business card and did, you know, the typical— what you could learn from and hack and how you can hack into systems just based off of information from a business card.
Nice. And when you say laptops, were these still like, you know, as big as a pizza box and like 50 pounds? Yeah, my cell phone was a brick at the time too. Yeah, so we did that, but we got an opportunity with all of that to actually give that demo at one of the very first InfraGard meetings at Case Western University. Oh, that is awesome.
Yeah, yeah. So like I said, I've been doing this for a long time, almost from the beginning. Nice. So you did that for a little bit, and then where did you go next? Then I came up to Denver because I was down in Colorado Springs and started, you know, transitioning out of the contracting world into the corporate world, commercial world.
Went to work for a small up-and-coming boutique security consulting firm called Denver Tech Labs at the time. Yeah, way back in those days, which eventually became InSpherix, which eventually got bought by Cyber. So, you know, worked for Cyber in their consulting organization as well. So, did a lot of consulting work through that whole period of time. And then eventually started working for some of the folks we were consulting for.
So, went to work over at First Data. We consulted at First Data and helped build the security around the Electronic Federal Tax Payment System. Had to brief the IRS on why it would be okay to accept tax payments over the internet. Nice. And then eventually went back at First Data and helped, you know, do another round of improvements and actually worked for them on that system initially, and then eventually came over to work the SOC side of the house.
So the other thing during my whole career, especially in the consulting side of things, was developing security operations centers. So either managed security services or building out SOCs for organizations. So I did a lot of those. I probably built about 4 or 5 SOCs in my stint between, you know, doing that and then starting to work in the corporate space. Nice.
And so you spent some time at First Data and then you left there. Mm-hmm. And then I ended up over at Kaiser Permanente, which was my initial step into the healthcare arena. Yeah, which was a really fun time to be at Kaiser, where you also helped build a SOC, where I also helped build a SOC. And I would have to say probably my, you know, pinnacle of SOCs is the one over at Kaiser.
Not only did we get to build, you know, the process, the people, and the technology, but we also got to do a physical SOC build, which was the first time people— somebody actually gave me money to say, you know, go build a facility that houses people that pay attention to security events. It wasn't like, hey, we want you to have a SOC, here's a closet, right? Figure out how you can shove a dozen people in here. Exactly. Which is typically how that goes, right?
The poor people that are in the dark, dank areas of the data center. No, this was actually a very polished facility that became a showplace for the organization. So that was fun. Along came with that, which I didn't really realize, was a bunch of tours. So half my job was building the SOC and the other half was tour guide, but it was fun because, you know, we were able to do— to really give the organization something to touch and feel and see when it comes to this magic called cybersecurity.
And the byproduct of actually building that physical SOC, which we really didn't realize, was the awareness that it raised in the organization, which then allowed us to have really meaningful conversations a little bit easier when it came to talking about security and the improvements we wanted to make and why we wanted to make those. So, so that was a lot of fun. And like I said, and it— and we really kind of built what I would call the SOC 2.0, or what people have been calling SOC 2.0. It's probably on our 3rd generation now with AI and everything else. But we were looking at, instead of having Level 1, Level 2, Level 3-type analysts.
We were looking at building expertise in the kill chain, so early warning or threat intelligence, exploits, malware, ransomware-type teams, lateral movement teams, and then data exfil teams. And the reason we did that, right, is to give us eyes on the same type of data at different times within that process so that we had a better opportunity of catching things when they were going bad. Nice. And I'm sure if it was a SOC 2.0, it had to have a fancier pew pew map of the attacks going from here to there. I tell you what, that traditional map is golden.
You just can't argue it. You can't have a SOC without a pew pew map. No, you cannot have a SOC without a pew pew map. And half the time, because we did put up the pew pew map, right? People would just sit there and stare at it and start asking a lot of questions.
And yeah, it was always a good topic of conversation. Yeah. Seriously though, with, you know, you said that you built this, you know, sort of as a next generation.
What were some of the things that you learned along the way that you put into this next generation of SOC that you didn't You kind of thought, oh, I always want to do this stuff, and so now you had a chance to do some of that stuff. I think just having a lot of experience, you know, on the operations sides of things, it was an opportunity to really put in all the hooks at the beginning. And when I say hooks, those are really kind of the things that allow us to measure metrics. You know, I hate to say say it, but right, a lot of those things are important, not only from an effectiveness standpoint of the people but of the processes and making sure that we had automated workflow that supported how the people worked versus trying to force the people into an off-the-shelf workflow. So we, we spent a lot of time really kind developing that out because there are so many integral parts to that lifecycle of an event when it comes into the SOC, right?
Because you have the analysts trying to determine whether it's something of importance or not. That often gets escalated to a multitude of teams. Even once it gets escalated and contained, you still have to do that feedback loop and make sure it got remediated remediated to completion, that it got remediated across the organization, that the lessons learned and the root cause got fed back into the system. And then when analysts were looking at things and realizing that maybe the rule that triggered, you know, wasn't quite what they wanted, well, then there was that feedback loop that went into the teams that actually tuned those rules or generated the content or made the dashboards. So we, we were really able to put in workflow automation to allow all of those folks to touch things, but also expedite the fact that they could react and, and move at a greater speed instead of just traditional ticketing and stuff like that.
And then the benefit of all of that is, you know, that's all contained within a database which you can run any type of report and metrics from, which is very helpful when you're doing a lot of tours and answering a lot of questions. It just made life a lot easier so that we could just kind of be able to answer those in a heartbeat instead of, you know, taking a lot of people off of what they do on their daily job to answer the questions that the executives are asking. That's always the worst when you have to stop people from doing the work that they need to do so that you can report on the work that they're doing, right? Right. You have to be able to report on it.
Yeah. But if you don't have some of that stuff built into the process itself, then it's its own process for those people to come up with that stuff, and that's no fun for anybody. Yeah. So that was something along the way, like, if I ever got a chance to do it from the ground up, we'd do that. And we did that, and it, it was magic.
It really was. Especially too when the auditors would come in. We could tell a story or show a dashboard for every question that they ever had. And it just showed the maturity level of what we were doing, obviously. That's awesome.
So if somebody was going to start their security operations practice within their organization, maybe they don't have the resources and people and the budget to build out a fancy room like you got at Kaiser, but what are a couple things that you would say that where people should start? Yeah, interestingly enough, I'm going through that process myself, so what would I tell myself?
Yeah, you know, you really kind of have to assess, you know, what, what's important to the organization. What I put in at Kaiser fit for for what Kaiser was doing. Now, would I put in that same thing at Centura? No. Did I put the same thing in my previous organization at Datavail?
No, right? So it's really kind of just assessing what makes sense for the organization based on, you know, what technologies you have in place today, what are the skills of the people that you have in your organization, and then trying to assess those gaps to kind of, you know, give you that determination of, you know, which way should you go.
I've been in organizations— my last organization, you know, we just didn't have the team, the staff, the wherewithal, right? So outsourcing to a third-party provider made sense.
You know, where I'm at now, you know, we're making that judgment and going back and forth. Do we build the team in-house or do we outsource that level 1? I understand from a very big complex organization how it makes sense to often build that in-house, but if your organization isn't as complex and there's a little more maybe simplicity to the architecture, maybe you don't have to. So I'd just say it's just really doing that assessment and trying to right-size for the organization based on risk tolerance, based on current investments, based on people and the maturity of the organization.
So we kind of stopped short a little bit on our tour of your career.
And you just alluded to it there a little bit. So you left Kaiser and you went to Datavail. Maybe talk a little bit about that and your experience. And then, yeah, so Kaiser, I went in as a principal, not managing, and left as the deputy CISO for the organization, right? That's awesome.
And that was just a matter of just continuing to work hard and, and, you know, driving and producing and being good, you know. I think, you know, having done security for a long time, it allows you to be able to be very calm in situations, which then tends to, you know, help when you're in those leadership positions. So, and then I went to Datavail. So Datavail was the full-on CISO role, managed services company that does database management and other data management services for organizations. I've been in managed services organizations before, so certainly understood the challenges of what they were trying to do because they're working with a whole bunch of customers, right, and working on their very oftentimes protected information, their databases and their data stores, helping those organizations get the value out of those, right?
And our job was to make sure that we did that in a secure manner and we didn't introduce any issues into our customer environments. So the, the interesting thing going from healthcare, where you have a lot of people that are caregivers and not necessarily technology people, to a company of almost, you know, 1,000 technologists. Definitely different organization, different priority, different needs. And like we said, you know, they— we were our infrastructure. We didn't produce applications at the time.
We were just connecting into other organizations. So our concern was really on how we accessed our customers and make sure that we did that in a secure manner. So things like jump posts and golden images and making sure that we stored customer credentials in a very secure manner. Things of that nature were more important. So when I was talking about, you know, it made more sense maybe to do level 1 outsourcing or to do 24/7 outsourcing for that organization versus, you know, building something in-house for what we did.
Right. And then so you left there. Recently and started at Centura to run their program there. Yeah, so I've been at Centura about 4 months now. So we've just wrapped up, as you know you would coming into an organization, is doing the assessments.
We brought in third parties to give us an understanding of our maturity, and so now we're putting together those roadmaps and and starting to socialize the transformation that we're gonna undergo at Centura. Our organization as a whole is trying to transform, is transforming, right? As our consumers are more mobile, on-demand, you know, wanting information to their health data, wanting to share that health data, you know, how do we as an organization start to enable that but do that in a secure manner. So that's my challenge, is to make sure that we can give our patients, you know, the transparency that they want but ensure the privacy that they demand all in the same— all at the same time. Yeah, I mean, it's, it's a funny dichotomy, right?
Because people want their information to be secure, but then they're also willing to, to give it to a lot of other people if they feel like they're getting something from it. And then, you know, from your perspective, you have some pretty strict regulations with HIPAA on what you can and cannot do. And I know that sometimes people get frustrated with, I'll say, the limitations that that puts on, on some of the things that, that a provider can do. Right, right. Yep.
So, and being responsible for that, for all of it. Right, from a compliance standpoint, you know, from supporting the infrastructure standpoint, to try and figure out, you know, how are we going to be able to, to move into this digital healthcare age in a way that doesn't pose too much risk to our patients. Yeah, yeah, it's a lot to think about. Yeah, and so you've been doing a lot of assessments But things are going well, getting your feet under you. Yeah, yep, getting feet.
We had a lot of transformation. There was a lot of senior leadership change. So I'm coming in with, you know, new CEO, new CIO, and now a new CISO, right? So this wave of change, which I think is really positive because there's some exciting things going on at organization. There's some operational, just, consolidation, right, becoming one organization with many hospitals instead of many hospitals under one umbrella.
So that offers us, from a security standpoint, the opportunity to kind of put in some checks and balances and controls and governance and things of that nature. As we kind of build some centralized processes where before they might have been disparate processes. So, so that's fun. And then just working, you know, the digital transformation in healthcare and what does that mean, right? It means, you know, allowing people to, to do some interesting analytics to produce information at our providers' fingertips to help them make better decisions about the care of their patients.
It's also providing patients access to their information and allowing them to share it in a way that they prefer to share it versus any other way, right? But still giving them the tools to maybe retract that sharing at some point, right? So how are you able to do all that stuff?
Being able to do the compliance piece, who touched the data and when, and what did they use it for, and how did they use it, right? You know, maybe there's some opportunities for some ledgering technologies and stuff like that that we're looking into to be able to kind of provide that pedigree or credibility to where that data trail went. So we're looking at stuff like that in addition to, right, Taking a team and kind of changing it up a little bit from more of a compliance approach to more of a risk-based approach, right? You've got limited resources and you really need to make sure that you're taking care of the things that put the business at the most amount of risk. Going from just traditional worrying about the infrastructure of security security and learning how to be consultants to the business and the organization about security and integrating security.
Helping the team move from just being implementers of the technology to being consultants to the business. We're working through all that now. That's something that's super important, especially in that kind of environment. You know, when we were at Kaiser, that was sort of one of the roles that, that I played there. And you have, you know, Kaiser was always pushing the envelope in terms of technology and things that they wanted to do.
And you definitely had to have your finger on the pulse of everything that was going on so you can partner with those people in the, the different technology and business areas because they want to, you know, they see this transformation coming and they want to move fast, and you can't be the one that's holding them back. You have to be pointing out the risks that are there and helping them to put those risks at the right level and put the proper controls in place so that they can move forward with what they're doing without essentially stopping them from doing that stuff because you're losing your edge. You're not going to be number one in the market. You're not going to be, you know, give that stuff to the customers that they want if you're holding them back. Yeah.
And in healthcare right now, that's a dangerous place to be, is not at the leading edge, right? Right. With the state of healthcare in the United States and all those other business drivers that says that we really need to be working hard to stay relevant. Yeah. And, you know, obviously the medical side too, right?
It's— you always have to play nice and make friends with, with the folks that are actually doing the care. Because if they're not on your side, there's always that patient care trump card that's gonna essentially override whatever it is that you want to do, right? So if, if you can't get their agreement on stuff, they're gonna say, sorry, this affects patient care, we're not gonna put your security control in. Yeah. Yep.
It's, it's definitely, that's a That's a whole interesting other piece and part to healthcare that I think a lot of organizations do not face is, you know, the— right, our first priority is obviously patient care, and when we talk about putting in security controls and locking things down and having issues and wanting to, you know, contain that issue, well, you really have to think a little bit about what's on the other end of that IP address, right? Right, because it's not just a laptop in most cases. It's a laptop that's connected to some system that's, you know, monitoring a patient. And therefore, you know, the traditional things that you would be used to doing, you know, you have to think through it a little bit differently in healthcare. Yeah, when someone has to access a computer in a surgical room you know, while they're scrubbed in and wearing gloves, they're not gonna be really happy with you if the computer gets locked out every 5 minutes and they have to, you know, enter their 20-character password.
That's right. You know, all of a sudden they're gonna have to, you know, take all their stuff off, go scrub back in, get back to where they were. And yeah, you gotta have— I gotta think about that kind of stuff. You do have to think about that stuff, and that's where that risk-based approach comes in, right? Because when you look at ORs and you talk about screen timeouts, yes, we would like them to be 5 minutes, 10 minutes, 15 minutes, but to your point, right, they can't be.
Because the last thing you want is your doctor looking at an x-ray while he's doing surgery on your back and have that x-ray disappear, right? It's the last thing you want. Yes, I do not. So, you know, when you look at— oh, my doctor to have the map of where he's going. Exactly.
And so when you look at OR rooms, right, they're behind, you know, guarded entrances and secure doors and this. And so having, you know, 4 8-hour timeout values are reasonable when you look at all those compensating controls and the risk that's associated with that particular piece of equipment. So, and we just went through that same scenario, right? Could we please Absolutely, you can have 4-hour timeout in your OR, because if I'm laying there, I don't want the screen going dark either. Exactly.
Yeah. Yeah. So what— are there any sort of big projects that you're gonna have coming out of these assessments that you know of already? Yeah, yeah, we got a lot. I mean, all the typical stuff, right, that you would expect.
We need to deal with BYOD. In a big way. You know, when we worked at Kaiser, our doctors were employed and you could enforce MDM on their mobile devices. At Centura, we have some employed doctors and we have some that are not employed, right? So then MDM becomes a little more difficult when you're trying to, you know, put that onto somebody that already has an MDM based on the organization that they work with, right?
So that conflict So how do we give them access without caring about the device that they come into us with? So, you know, we'll be looking at that more probably from, you know, containerization and application control more so than device and device checking controls. So we have to look at that from an interesting way.
One of the most wonderful things that I walked into at Centura from my predecessor was a highly zero-trust type deployment in that organization. So we have whitelisting deployed extensively on, on almost everything that we possibly can, excluding medical devices that won't allow us, but some will. So, oh nice. Yeah, surprisingly enough, some will. Yeah, so, so we have, you know, good protection.
Things don't execute, so we don't— we're not chasing things from that standpoint. But I think we still have a visibility gap, so we'll be working on, on the visibility piece, make sure that, that things are behaving in our organization the way we would expect them to behave.
We're good on the 2-factor front, but we could do better on the privileged access management, so we will be working on some things there to shore that up, down. And security awareness. Yeah, I think security awareness can be better, more touchy-feely, you know, that seems to work out well. We've got a lot of facilities, they don't see our faces much, so we'll probably go on some campaigns a couple of times a year in each of the facilities so they know us. You're gonna dig out those those old laptops back from the Stone Ages and take those around and show people how it's done.
Gosh, yeah, I don't think those same things back then would work today. And I'm a little stale on being a script kiddie, so. I would bet that some of them would still work today, as sad as that is. Yeah, you're probably right, right? Oh my goodness, yeah.
Yeah, so things like that, improving vulnerability management and remediation governance, getting a better risk view of things. We didn't have a risk management practice before, so we're developing those to do more of the governance, the vulnerability management, the policy stuff. It was being done, but it was, you know, everybody had a little piece of the pie, and we're gonna provide a little more concentration. I can get my metrics back and start showing the pretty graphs to the board. Yeah, everybody likes to think about how cool and sexy certain parts of security are, but then you come in and you look at something and you're like, oh, we need to do all the unfun and the people and process parts.
We have to have better governance. We've got to have know, better policy, process, procedure, all this kind of stuff. Yeah, none of that, you know, shiny blinky box hacky stuff. We're gonna, you know, we got to do the things that can really move the needle. So yeah, yeah, right.
If you had talked to me early in my career, I would have been on the blinky light side of things.
Probably my big change was in the Probably First Data, you know, really working for the corporate organizations and really talking about risk management and governance and kind of what that can do to an organization as far as moving the needle, as you said, makes a big difference. For sure. Yeah. So I know one of the other things that you've been involved in in town is the Women in Security group here. Yep.
So I'm pretty sure most people know about that group and what it does, but why don't you give us a little background and some of the stuff that's been going on over there? Well, my involvement in Women in Security, I have all thanks to you, Alex, right? You introduced me to Sarah, and she just really came in through LogRhythms and said, hey, we'd did this out in Kansas City, would like to start it up here. You knew I had an interest in kind of that mentorship, and that really came from when I left Kaiser. What I didn't realize there, you know, I'd mentioned before coming in as a principal and then being the deputy CISO, is when I chose to leave the organization to take on that full CISO role, was there were a lot of people, a lot of women especially, in the organization kind of keeping a pulse on me and my career there.
As someone to aspire to, to see somebody come in and go through and become an executive at the organization like that in a short amount of time, I think, you know, I didn't realize those people were paying attention. So I really did get a lot of feedback from folks and, you know, actually still chat with and mentor a lot of folks. From there today.
And I've always liked the coaching part of things. I've done coaching things in my past for, you know, high school students and stuff like that. So coaching, mentoring, helping people develop a career, you know, what that looks like for them, has always been an interest. So you introduced me to Sarah, and, you know, a few months later we had our first women in Security meeting, and that was just a little over a year ago that we did that. So we've been holding quarterly meetings ever since and really trying to give a place for women in cybersecurity just to come together and network a little bit and get to know each other.
That's really the primary goal of what we're doing, so we try and make sure that we give them content that's relevant to their career and a little more tech-focused, and then the next meeting we might give them a little more content about how they grow their brand, or, you know, same thing, the blinky light thing, and then, and then, you know, the other things that are a little more touchy-feely. So, so we've, we've been doing that and been very successful. I think, you know, our average attendance is in the 70s to 80s each meeting, which I, which I think says a lot for, for the fact— because there are so many competing things that, that folks can do when it comes to attending after-work events, right? For sure. And it's, and it's really hard when, you know, often you're a working wife or a working mother to be able to find time that you want to be able to do it with something that has a little bit of meaning and whatnot.
So we've been trying to provide that. Plus we serve wine, so I think that helps. That's always good. Everybody likes wine. Yeah, yeah.
No, but it's been really great opportunity to get to know some of our younger folks. We've had a lot of interest and have been sponsoring some high school students that are participating in cyberpatriotic CyberPatriots? Yeah, right. And they're doing those gaming, trying to help them actually find internships. Yeah, with organizations.
You know, we talk about a shortage when it comes to cybersecurity professionals, and you know, if you have a willingness and you have some kind of talent or skill or knack for computer computers or cybersecurity. I don't see why we shouldn't foster that without the bachelor degree. Yes, right, for sure. And so we're working hard to kind of find avenues, companies that are willing, kids that are mature enough to come into the workplace. And I think that's where Women in Security come in, is we really try and help vet to make sure that, you know, if you are taking a chance on a younger individual, you know, that they have some ability to carry themselves in a corporate environment.
And then what we're really hoping to do is continue to provide that mentorship to that individual. So they're in here working for you, Alex, right? And they might be too timid to ask some questions, so they always have us to fall back on and, and to be able to talk through whatever it is that they're going through as they're trying to adapt to, you know, being in a corporate environment and working a real 9-to-5 type job. So it's— for women in security, I think it's that ability to provide that guidance, that mentorship, get their interest in and try and keep them engaged in cybersecurity, and then, you know, help our community by building more and more folks that might be interested in the career field. Yeah, and the internships are so important right now because we're at this weird time in our industry where there's a bit of a catch-22, I think, right?
So it's— we have this— people keep saying there's this big skills shortage, right? We don't have enough people, we need more people to do all the stuff we want them to do. But then you look at even entry-level jobs that are supposed to be the bottom of the ladder, right? This is where you start. Yet for those bottom-level jobs, they want people with experience.
They want you to have done some security stuff before. It's like, how do you get those entry-level jobs to get the experience if you need to have experience to get the jobs to get the experience?
And then with the internships, which is great, I've seen more and more pop up, but there's just only so many that are out there. So, you know, I think that they're super important. You know, I've had interns the last couple summers and it's been great, but I think, you know, we need even more than that. So it's great to see that you guys are helping push that too. Yeah, yeah.
And I think we as leaders, right, need to support it. It can be inconvenient. I get that, right? And so maybe what we've talked about in Women in Security is for those organizations that don't have a program to deliver them something to follow, yeah, right, to build the content that says, you know, here's kind of the way that you bring in an intern and be able to make that meaningful for you without you having to reinvent the wheel and figure that out if you haven't gone through that process before, right. So really what we're trying to do is help build some tools to make it a little bit easier to, to go down that path.
Because yeah, we do need more folks, good folks, you know. Get them engaged early, get them interested early, you know. Hopefully they'll stick around for a little bit. Exactly. Yeah.
Or get them somewhere, you know, for someone else that needs that skill, right? Yeah. You know, I've had that, you know, my 2 interns that I had this past summer both now have full-time jobs. That's awesome. Wonderful.
You know, so they— we didn't have a full-time spot here for them, but, you know, they stayed with us for the summer, got some experience, got real jobs, and now they're helping somebody else. Yeah, it is a good thing. So we are just about out of time. Anything else that you wanted to cover before we wrap this up? No, just been loving what you guys have been doing.
You know, thanks for asking me to be a part of that. I appreciate it. And yeah, it's the Denver community I appreciate a lot when it comes to, you know, supporting each other within this space, right? It's a pretty open, transparent community. You don't often find that, so it's fun to be a part of.
Awesome. Well, thanks, Nancy. Thanks. Appreciate you being here. Yep.
And this has been Colorado Equals Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.