Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 95 for the week of December 10th, 2018. Alex, we're, we're just a few weeks away from finishing off this year.
We're getting really close, Robb. I think, you know, 1 or 2 weeks from functionally finishing and then, you know, a couple more after that when everyone's going to be on vacation. Yeah, I'm looking forward to having a little bit of time off for the holidays around Christmas and New Year's. And then of course, 2019 is going to be out on us super fast. That's crazy.
You know exactly what you're doing next year? I got it all figured out, you know, down to the minute. Nice. Well, obviously this last week we had— we got to have our security leaders happy hour. We did.
Last week. Holiday party. Thanks to all those folks who were able to come out to that. Look forward to having more great events in the next year. Before we dive into the news for the week, we do of course have a few housekeeping items.
A reminder, we have a Slack channel. If you guys want to come talk to the about 670-ish security folks here in Colorado, that's a good place to do it. We have a mailing list. Go to the website colorado-security.com, sign up for that mailing list. You will get the show notes in the mail.
So you'll be the first to know when we have a new episode and all the details. I would love it if you would subscribe on your favorite store wherever you get your podcasts from. Rate us out there so we can have good things said about us. We'd love it if you'd let us know what we can do better. If you would like to chip in and help us financially, you know, Robb and I do this out of the goodness of our hearts and the, you know, bounty of our pocketbooks.
You can join our Patreon campaign, help us to pay for the things that we do. We appreciate all of our patrons and we'd love for you to be one too. Yeah. Thanks so much to those who are already sponsoring us. We appreciate it.
And of course, if you don't have the finances to help support it, it'd be great if you would tell a coworker or a friend about the podcast and help us get those numbers up. All right. Why don't we move into the news first? There is a Longmont startup that is going to start shipping their snow fighting robots But they're also lawnmowers and golf ball collectors. So we talked about this company about a year ago.
I think it's Left Hand Robotics. And at the time they had like a beta, you know, proof of concept type robot out there. They're actually now shipping these, these robots that take care of snow. They're going to have about 20 of them go out this winter. Yeah.
And it sounds like while it is sort of the same robots, they've made a lot of improvements. So it's almost functionally something completely different. Um, same function, but, you know, brand new software, lots of upgraded hardware, better GPS. So automated snow removal, um, you know, in the summer, potentially automated lawn mowing. And they basically replace the same parts.
So the thing that is the shovel will get replaced with the lawn mower. The thing that is the, um, the salt distribution chamber, whatever, gets replaced with a fertilizer. So really pretty cool. You can have the same robot do different stuff. A couple of interesting facts from this.
They, they do go at about 7 miles an hour as their top speed. When they're not, when they're just traveling, when they're actually mowing or shoveling, they go at about 3.5 miles an hour. Once they go into kill mode, they are much faster though. You gotta be ready for the, for the robots coming after you, huh? Exactly.
I thought it was interesting. They're, they're only able to manufacture 2 or 3 at a time just because of space limitations. They only have like a 1,000 square foot area. So, but they have a new, a new warehouse coming up soon, right? Yeah.
I think in the coming up in the spring or something like that. And they're planning to like, Triple or quadruple the capacity at that point. More robots to take over the world. More robots. We need, we need, uh, I don't want to be shoveling snow, so go left hand.
If, hey, if you guys need someone to beta this out and you want to like, you know, have a showcase home in South Denver area, uh, you know, give me a call. I'm happy to be that, be that guy. Uh, next, our next story is about the— it's really a list of the best managed companies in the US, and there are a few different Colorado companies that made that list. Yeah, so on the list number 64, which was also number one in Colorado, is Molson. Molson Coors.
Yeah, of course. And they the number one in Colorado and really the only Colorado company that made the top 100 list. There's a few others from Colorado that made the list overall. VR Corp, the one that's is it VF Corp? Isn't that VF Corp?
VF Corp. The company that's coming here soon. That's the the attire company, they are at number 158. Ball Corp is at 214 and Newmont Mining is at 230. I thought it was interesting that Molson Coors, the beer company, and their distributor, the company that makes their cans for them, both made that list.
Yeah. And of course, this list was about, you know, top management companies, but also sort of buried in the article, they had a list of the most valuable brands in Colorado and Dish Network was the most valuable brand. I thought that was interesting. Right. I'm surprised that that's not Molson Coors as well.
Yeah. That's interesting to know. Next, these top 5 housing markets will be the biggest in 2019. What's the number one? Should we just cut right to the chase?
Number one, of course, is Austin, right? Because maybe just— no, no, no, no, it's not Austin. It's not Austin. Colorado Springs. Colorado Springs was a little surprising, wasn't it?
Yeah. Top housing market in 2019. But number 5 was Austin. Yeah.
So, you know, Colorado Springs, I believe, was the only Colorado city on the top 5. But good for them. There's a number of criteria that they had in determining the list. Things like job growth, vacancy rates, the ability or the availability of starter homes, things like that. Yeah.
Awesome. Next story here is Exponential Impact, which is a local tech accelerator, just got about $750,000 in a program that's going to allow them to really enhance their offering. So it's a, it's a newish accelerator. I think they just started in 2017 and they, they got part of this program that gives them that funding so they can really expand what they're doing. And, and they are working on entrepreneurial programs around cybersecurity, artificial intelligence, and blockchain.
So, you know, kind of the big 3, right? Yeah. Yeah. And they're sort of, uh, I don't know how tightly, but they're sort of teamed up with the NCC down in Colorado Springs. And we, of course, had Hannah Parsons, who's the CEO of Exponential Impact, uh, on the show, uh, when we interviewed Vance Brown.
The funding, they said, will be used to help, help some entrepreneurship apprenticeships. So that sounds pretty cool. Yeah, it does sound cool. Looking forward to hearing how that goes and seeing some examples of those companies come out. Next, CSU Global is partnering with the Colorado Technology Association to help give their members some discounts on education.
So pretty cool. Any, any corporate members of the CTA get a discounted tuition on any full-time programs. So, you know, Ping Identity, we're one member of CTA, and it's pretty cool to see that there's this discount. And they list the certification, or rather degrees, that are applicable for this, and it includes a couple of security ones. There's an undergraduate certificate in cybersecurity.
There's an undergraduate certificate in computer programming, IT operations, networking. There's a bachelor's in IT. There's a graduate certificate in cybersecurity. And there's a master's in IT management. Nice.
And I believe the discount is 10%, uh, so that is nothing to sneeze at. College is not cheap. Yeah, absolutely. Pretty cool stuff. Uh, moving over to the local security company news, we have a blog this week from Red Canary on— it's called Surfing the Mid-Career Wave: 5 Steps to Making Your Next Move.
It's kind of an interesting story. Uh, rather than just focusing on, you know, how do you get into security or how do you become a CISO, it's, you know, what do you want to do in terms of making those mid-career moves? And the author has 5 steps she goes through. I also thought it was interesting as we go through the 5 steps that it wasn't necessarily focused on continually moving up. Right.
It was— it talked about moving a lot to the, you know, the right place for you. But step 1, identify your strengths. You know, what is it that you're good at? Ask big questions. Some examples: What drives me?
Where do I want to challenge myself? Step 3, prepare yourself. You know, do some reading, do some research, education, things like that. Yeah. She recommended a handful of books.
Windows Internals Part 1. You know, if you, if you're doing security in a Windows environment, that's a good thing to learn. That's technical. Most of her other recommendations were non-technical. Drive, RADICL Candor, Deep Work— these are really more about just, you know, yourself and understanding yourself better.
Step 4, catch the right wave. So this is, you know, sort of talking about getting to the right place, not necessarily, you know, looking to always move up. Yeah. And I think kind of along with that is the last step is stop and reflect. You know, figure out what what you've done in your career.
Where are you going? Are you still going in the right direction? I thought it was pretty good stuff, and I appreciate this, this thought. Anyone who's, you know, looking at making a change at some point, I think this would be worth reading. Uh, next, some Ping Identity news here.
Um, I'll introduce it, and I'm sure Robbie will have more information on it. Yeah, uh, Ping announced their public preview of Ping One for Customers, uh, cloud-based identity as a service. Yeah, so, so Ping Identity, you know, is Uh, you know, we've been doing single sign-on, multi-factor authentication, directory services for a long time. For the most part, you know, as we started, we were a workforce-focused company, so really meant for, you know, offering these services to your customers. Over the last, I'd say, 4 years or so, it's been a big focus on moving from just workforce to helping provide IAM solutions to customers.
And this product is specifically created to be, you know, best of breed for customer-facing IAM. So you think about like consumer-facing stuff, if you're a, you know, if you're a store, a telco, some kind of service provider that has a lot of customers, you want to, you know, have a really good positive user experience. That's what this is meant to do. So really cool stuff. It is a, you know, all microservice, all the new hotness DevOps-focused solution that's been fun for us to create and for me to get to secure.
Also with that new focus on customer-facing But I think what everyone really wants to know is, is there any blockchain in it, Robb? I can neither confirm nor deny that blockchain is a part of that solution. It's not though. Okay, well, our next story here is about LogRhythm. No surprise, but it's good to see the news come out.
LogRhythm has made the leaders section of the Gartner Magic Quadrant for SIEM technologies. Congratulations to LogRhythm. They are in that upper right quadrant with a lot of names that you might expect: Splunk, IBM QRadar, McAfee's SIEM. But I think that, you know, there's also a few in there that, you know, maybe we didn't think would be up that way. Yeah, so Exabeam made it, and I think Exabeam does some pretty cool stuff.
I didn't think that they were in that leaders quadrant quite yet. Dell Technologies, or RSA, and Securonix made it up in the leaders quadrant as well. And really, I think you know, a big piece of news is who didn't make it. ArcSight, or it's in here as Micro Focus, right? Or formerly HP.
But ArcSight is not in the Leaders quadrant. They have moved into the Challenger quadrant. That's the upper left side. Yeah, very interesting. Next, Swimlane also received some recognition.
They have awards in several places. They were the gold winner for Security Solution for Enterprise. At the Golden Bridge Awards. I guess if you win this many awards, you just can't do a press release for each of them, right? You have to kind of, I guess, kind of lump them together.
Also, they were a finalist for the Emerging Tech Company at the Apex Awards. I sat at the same table as Cody Cornell during the Apex Awards. I think he was a little disappointed not to win, but happy to be a finalist and also a finalist for BizWest IQ Awards in the software application category. Finalist for Computer Security Excellence Security Automation Award. That's a lot of words.
It's a lot of words, but congratulations to those guys for all the recognition. I think they're doing some good stuff, and it's nice to see the industry talking about it. As we are talking about awards, you know, LogRhythm, Swimlane, let's talk about one more. Webroot has also announced an award here. They were recognized as a trailblazer in the 2018 Radicati— help me out here.
I'm going to say Radicati. Radicati sounds like— maybe Radicati. The Radicati Endpoint Security Quadrant. So the Trailblazer in here really means that they are doing some stuff that's pushing the industry forward. And this was specifically around their real-time malware protection and the ease of use of their product.
So congratulations to them for the recognition. I guess I hadn't realized that December was the time for awards, but, you know, I guess so. There you go. People get gifts all year round, but this is the best time to get them. I do know what December is the time for, though, and that is predictions for the next year.
So LogRhythm released their blog on 8 cybersecurity predictions for 2019. Some interesting ones in here. So how about if I read the predictions and you say whether they will or will not come true? Okay, let's do it. All right, number 1, a cyberattack on an automobile will kill someone.
No, it will not. Cybersecurity programs will grow but continue to lag behind the talent gap's growth by at least 25%. Yes, yes, it will. Bio identifiers will outpace traditional passwords.
No, no, I don't think they will. Now, it probably depends on how you measure it, right? If you went by growth, growth of them, you know, so there's in 2019, if you know, we went from having 4 bio identifiers being used to having 100, that would seem really good. But it depends on how you measure it. We go from, you know, 80 trillion passwords to, you know, 80 trillion and one password.
Exactly. It's still a lot more passwords. The US will experience the Balkanization of cybersecurity regulations. I'm gonna say true, because it already is true, right? It's, it's already experiencing it.
Yeah. The only way that this doesn't happen is if the federal government releases some federal laws that trump all those things. No pun intended. And I don't think that'll happen. So really, the prediction here is that the federal government will not release I believe so.
Single sit. Okay. China will manipulate the market to turn the trade wars in their favor. Sure. All right.
I believe that cloud-based ransomware will compromise a major corporation's infrastructure.
Cloud-based ransomware. Come on, man. Yeah, I'm gonna say no, but I don't— I guess I don't know what cloud-based ransomware really is. Are we saying that someone's cloud infrastructure will be ransomwared? Or are we saying the ransomware is cloud-based?
Yeah. And I don't have the actual body of the prediction to open right now. So we're just gonna go ahead and say no, no, no, will not happen. All right. Sorry, guys.
We will see a move to hold CEOs accountable for breaches. No. And finally, President Trump's cell phone will be hacked. His government cell phone or the one that he tweets from? I can see the one that he tweets from being hacked.
So is there an assumption here that it's not already hacked? That's true. If it's already hacked, does this count as a win? Yeah. And are we gonna know about it if it does get hacked, right?
Right, exactly. Okay, that was fun. Now we have, we do have a little bit more here. There's another article that's actually from Fortune with 60 different security predictions for 2019, and 2 of them are from local Colorado companies. Yeah, so the one was from Brett Settle of ThreatX, and one was from Gene Stevens of ProtectWise.
So I think that— did we have a ProtectWise one last week? I think that this one may have been in the ProtectWise article that we talked about last week. Yeah, that sounds right. But it's talking about teams will shift to prioritizing cloud-delivered security solutions over traditional appliance-based solutions. Kind of a continuation of a— And that's a yes.
That will happen. Yep. And then Brett Settles here, they're really talking about there will be a major attack on a US utility in 2019. What do you think? Uh, I don't know that there will be in 2019.
I think this is sort of like a little, a little hedgy in the actual prediction. Gives a couple different dates. You're right. It does say 2019 and then 2023 and, eh, okay. Okay.
By 2023 there will be, but I'm not doing 5-year predictions. Yeah.
Anyway, um, that there are 60 different predictions if you want to read the rest of predictions that, that you can, talk about not happening in 2020 from, uh, the end of next year, then go read those. All right, well, that is it for the end of the news. Moving over to our Slack message of the week. Thanks so much to Andre Gaeta who sponsors this, helps us point out the awesome stuff going on in the Slack channel each week. Uh, and this week, who are we gonna recognize?
Alan Gordon. All right, Alan. And really, this is, uh, around a couple different things. Number one, you did share the, uh, the story this week around Microsoft and MasterCard. Creating a digital identity plan.
But really, there's been a lot of good sharing you've done over the last few weeks, and we want to recognize that. Thanks so much for your contribution. As a part of this, you will get to pick something from the Colorado Equal Security store. We'll send you a link and you can pick your swag. Thanks to Andre for supporting.
So for all of you out there, if you want free stuff, all you have to do is join the Slack channel and say something interesting, say something witty, share some news. Yes. All right. Let's move over to events. Sounds good.
As a reminder, we do have an event calendar on the website. Colorado-security.com. There's actually a bunch of stuff going out all the way through the end of next year, and that's only because some of the Colorado Springs folks put their whole 2019 calendar out there. Wow. But we are filled up already.
It's pretty good. Monday the 10th of December, ISSA ISACA is doing their holiday joint meeting, which is the Colorado— they gave it a different name too, but it's, it's a, it's a big, big event. It's gonna be at the Soil Growth Dove Underground. Uh, got some big speakers there, should be interesting. I'm looking forward to it.
Uh, this is— I'm actually planning to be there. Um, they said there's gonna be about 300 folks there in the event, so that should be pretty good. Wow. Looks like they called it the Cybersecurity Community Holiday Bash. Nice, I like bashes.
Uh, next, SecureSet is doing their Denver WarGames System Security 1 Linux security, also on the 10th. On the 12th, they are doing System Security 2 with Windows security. On the 13th, SecureSet is having Nadine Turner do a Metasploit Pro demonstration and Q&A. And the last event we have on the calendar for the year is on the 17th. It is also SecureSet, and they are doing their Denver WarGames Capture the Flag event.
Awesome. That is it for events, so let's move over to jobs. All right, uh, we have an open position at Ping that's worth talking about. We're looking to hire a GRC analyst. That's going to be helping us support all kinds of fun stuff— compliance programs, vendor risk management.
Really a good opportunity for someone who's new-ish looking to get into security to help, help us mature the security program and provide compliance to our teams. Uh, next, Western Union is looking for an IT senior manager for internal audit. NREL is hiring a chief cybersecurity engineer. Does it seem like NREL hires a uniquely awesome title like once a month? Yeah, I think that there's lots of Uh, exciting NREL stuff going on.
Also, um, there was talk on the Slack channel this week about starting a red team at NREL. So yeah, if you want to be a red teamer, maybe they're going to have some jobs on that here shortly. Uh, CenturyLink is looking for a senior security research engineer. I think there was a second job that was also— there was also malware reverse engineering. Malware analyst, reverse— yeah, hunt botnets.
Hunt botnets with Mike Benjamin. Yeah, awesome. Elastic is hiring an application security engineer. Bank of America is looking for a cybersecurity ethical hacking analyst. So if you want to analyze ethical hackers, yeah, in the cybers, kind of wondering if you can do that.
Does that— my guess is it's probably, uh, you're looking for somebody to do offensive security here. Yep. Um, Synoptec is hiring a senior security consultant. GuidePoint Software is looking for a Splunk security engineer. Dark Owl, which is a security company here locally, is looking to hire an IT infrastructure specialist.
So IT job at a security company. And Micro Focus is looking for a security strategist. Probably this is your chance to get them back in the leaders quadrant. That's right. After, after dropping out this year.
They need some micro focus because they've been too macro focused. That's right. They fell out of the quad— the leader quadrant. That's a pretty good segue, Alex. Yeah.
All right. Well, hey, that is it for the end of the news. We have a feature interview this week with Richard Byrd. I got to sit down with Richard. He recently joined me at Ping.
Um, as our Chief Customer Information Officer, really kind of like a field CIO role. He previously worked at Optiv, previously was a security leader for JPMC and some other organizations, and we had a good time talking about where he sees the industry going. I look forward to hearing it. Cool. Well, that's it for this week.
We'll look forward to talking to you again next week. Thanks, Robb. Hi, this is Ed Fuller, CISO with Cloud Elements. This is Colorado Security. For Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. Today I am sitting with Richard Bird. Richard is the new chief— excuse me— Chief Customer Information Officer at Ping Identity here in Denver, and we're going to talk about what that means. And really, you've had a pretty, pretty fun career to get you here too, so I'm looking forward to talking about that. But first, I want to talk a little bit about what you've been doing a lot of the last 3 years.
So talk to me about the concerts you've been going to and how this whole thing started. Sure.
I got a late start in life. I went to a lot of music events when I was young, but in the last 3 years I've been to 18 music festivals with my fiancée. We met and started dating about 3 years ago, and we both had talked about how we liked music, and then we had that really awkward conversation about, okay, well, you know, who should we go see? What concert do we go to? And we had been seeing each other for only a few weeks, and I looked at her and I said, hey, instead of going to one concert, how about we go to all the concerts?
Why don't we try a music festival? And she asked me, she said, have you ever been to Bonnaroo? And I said, well, no, I've never been to any festival. And we were— we got ourselves all together, tent camping. That's all that we do.
We don't use an RV or anything like that. And we got our campsite all put together, and we were about 6 weeks out, and all of a sudden my fiancée looked at me and she goes, okay, I'm just now realizing that we've made an agreement to go to Bonnaroo as our first music experience. 5 days in the dirt and the dust in Manchester, Tennessee, and I have no idea if we're going to survive this. So we are either going to come out of this thing strong and it's going to be a fantastic relationship, or this is going to be really bad and we're going to crash and burn, and then we're going to have that awkward 6-hour drive back home. But we went.
It was literally a life-changing experience. Had a blast, met a lot of amazing people, made a decision subsequently that we do at least one festival outside of the United States. We've gone to a festival in Madrid, we've gone to a festival in southwest England, we're probably going to go back to another festival in either England or Barcelona next year. And we've had this incredible, you know, opportunity to see up-and-coming bands and then got to see U2 in their first festival appearance in 30 years. In their entire career they'd never done one.
Got to see them do the very first. And it has really been a big motivating factor for me now from a professional and personal standpoint because I'm much more planful now. I try and figure out exactly when the calendar is going to hit. Plan my vacations and figure out how to make these things work. And we find now that we have connection points with so many people.
We just start talking about music and it's, you know, a lot of studies, it's the universal natural language and it just causes great conversations to start. So what's— you mentioned you saw U2. What's your favorite band that you've seen at any of these festivals? Oh, favorite band is tough. I think that Um, we had an incredible double bill one after the other.
The one night we saw the Foo Fighters, and they came out at a festival, which is relatively uncommon. The time's usually blocked pretty, uh, you know, pretty strictly. But the Foo Fighters came out and played for 3 hours. Wow. The next night Green Day was on, and Green Day came out and played for 2 and a half hours.
Um, what festival was this? Uh, this was at the Mad Cool Festival in Madrid. Smaller bands, super excited to be in Denver because 3 years ago now we saw Nathaniel Rateliff and the Night Sweats do their first set ever at Bonnaroo. They're a really well-known local band here in Denver, and their energy was like off the charts. Like, we've seen so many big-name bands and if you could have bundled up all the energy they created that first time they played there and distributed that to like, you know, Coldplay and Foo Fighters and all that, they would have really kind of, I think, just exploded.
It was just so much fun. That's great. Yeah, so it's, you know, and we've seen everything from little tiny groups to— I'll give you another great one— Three Sisters Joseph, acoustic guitars, and they come out and they harmonize so well that it just makes— it gives you shivers, you know. So it's always like searching for the next. It's like potato chips.
You just can't have one. You can't have one performance. You got to see how many you can get in, and I look forward to the next one. We've already got 3 festivals scheduled this year, or for 2019. I think you told me you've been to 18 festivals over the last few years, which is a pretty good rate, 6 a year.
That's pretty good. For those, you know, you're making me want to go see a festival. If I'm gonna go see one, which one should I go see? Which should I go to? So the biggest resistance that we hear when we talk to people, it's really kind of fortunate I found, you know, someone in my life that's not afraid to, you know, get dirty and grungy, maybe not get a shower for 2 or 3 days, and just for the ability to go see something unique.
I don't think that's the best way to dive into festivals for most couples. I really strongly encourage people to look at urban festivals. So Shaky Knees is a spring concert and festival, and its fall partner is called Music Midtown, and they're both in Atlanta. The great thing is, is that it's reasonably easy to get around the inner core of Atlanta, get a hotel set up, get a great 2-day experience. And it's a well-established festival.
It usually has a great lineup. The other thing you have to kind of get past is the bigger festivals typically have a combination of country, rap, rock, alternative. So you— my biggest piece of advice for anybody that does festivals is just cast aside all of your assumptions and your biases and just go see everything. Thing. Never been a huge country fan, but I've now become an enormous American roots bluegrass fan.
Old Crow Medicine Show, there's another one that just puts on an amazing show. And then on the country angle, I saw Chris Stapleton perform at a Bonnaroo, and he and his wife were amazing. And I would have never gone, I would have never paid to buy a ticket to go see a Chris Stapleton show. Yeah, but, but you, you, if you put that aside, you'll really see some of the most amazing performances if you're willing to just say, hey, I'm not gonna watch this, just the stuff I'm comfortable with. That's awesome.
Well, maybe, maybe we should talk about security a little bit now. I'll take a little bit of a turn. You know, before we get into your career, talk to me, where are you from? Where did you grow up? So I grew up in a tiny little little town in northern Ohio, 13 miles from the Canadian border across Lake Erie.
And I grew up, no joke, the son of a fishing captain. I actually— a bit of useless trivia— I actually was a fishing captain myself with a federal navigator's license, so I could run large boats, and I kept that license for 20 years. But when I say small, I graduated in a senior class of 52 people, and it was one of the largest classes in the last 50 years. My sister, 6 years later, graduated with 36. Wow.
So I came from a really small place, and, um, you know, I grew up like a lot of kids in those circumstances, looking outward. I picked up— my love for music started super early because in Detroit they would boost the signals and we could pick up radio shows across the lake, but only late at night. I remember laying awake at 1 o'clock in the morning listening for the punk radio show. It was the late '70s, showing my age a little bit.
There were all these things out there. I always tell my friends that back in the day, if I had any idea what an investment banker actually was, Um, I probably, you know, would have gone down a totally different track in college, but we didn't have any exposure to that where I grew up. Very, very rural, very, um, very isolated, you know, from no social media back then, no Wikipedia, right? So yeah, it's definitely where I came from, and it's, it's important because it is, um, it's, it's the origin and the source of, uh, all the good things that have helped me go the directions that I've gone. Most importantly, my father.
My father's been my best business teacher now for, you know, for me, for almost 52 years. He's just been a great mentor, and he still wears a rope for a belt and boat shoes every day, and he's just the most down-to-earth guy. But, but he informs more of the thinking about how I manage my career than anybody else I've ever worked with. So, so you grew up in this small town in northern Ohio. Um, I assume you graduated from high school there.
Yep. What was next for you? Did you go into boating right away? No school, or what'd you do? Boating was a summertime, uh, job.
Uh, it helped pay some of the bills. Um, I always like to— I, I think it's really important, like, especially when we're talking about career stuff, it's really important to understand the whole person. So, um, I, you know, I wasn't really paying attention when I was a kid, so I became a father when I was 18 years old. It became a real big driver for me because I was in college when I found out I was going to be a dad, and I never stopped. In fact, I got through and got my degree.
At one point I had one full-time job, 2 part-time jobs, and a 20-hour credit load for the quarter, and because I just needed to do it, right? And, um, but I'm always entertained by my career because we'll kind of get to the point where I transition into technology. But, you know, the— it wasn't even in my windshield. I graduated with a political science degree with a minor in Japanese language. And, um, it's interesting because I'll tell you that I use not just a liberal arts education, but my political science background more as a reference point for cybersecurity these days than all the other things that I've learned on OJT, around statistical— or on-the-job training, statistical analysis and all those types of things.
But that led to me getting out of the service, or out of college at Ohio State, and wanting to be in the military or being a lawyer. But I was now with 2 kids, flat broke. And the Army had a program where I could get all my law school paid for. Unfortunately, I managed to start just as Desert Storm kicked off, which means I never became a lawyer. Now, several decades later, I'm really happy I didn't become a lawyer.
I will not tell Lauren Romer, the general counsel at Ping, that you said that. Everyone keep that quiet from her. But yeah, so I fumbled around like most people in their young years in their career, and, and, but I did go to work for Walmart. I was actually a construction project manager for them for 4 years. So what did you do in the military?
I was a, I was a paralegal, which helped inform me about legal careers. I worked in the Judge Advocate General's Corps, but more importantly, I spent a couple years on active duty, and I was in the 82nd Airborne. And I had no, I mean, no family background in the military or anything like that. And to be put into a situation where you're in the minor leagues of the Special Forces, the entry point by being an airborne paratrooper, that is something that still has a huge impact on me. Not just the whole veterans piece, but going through that training was something that really taught me that I could do anything for one more day, one more hour, one more minute if it meant achieving what I wanted to accomplish.
And airborne school was hard, but because I was in the 82nd Airborne, I was a paralegal. But when you're in an infantry unit, your first and foremost job has something to do with bullets and and metal, and mine was— I was the .50 caliber machine gunner for my headquarters company, which, you know, I gotta tell you, even to this day, it's still cool. It's a lot of fun to shoot a .50 caliber machine gun. So you served in, did you say Desert Storm or Desert Shield? Desert Storm, and never went over.
I actually was rear detachment command in in Fort Bragg. I got actually listed 5 times to fly over. 3 times I was actually on the airplane and got booted off by officers going over to get their in-country service requirements. It was a really tense time. I remember it was the only time I ever saw my father— well, first one was really personal, but the second time that I ever saw my father cry.
He came to visit me, and I was living in a very difficult situation where I was basically a prison guard for all the guys that were supposed to be getting chaptered out of the military for crimes, but they couldn't because they couldn't be demoted and sent to Fort Leavenworth and those types of places. So I slept with a weapon next to my bed, and I was one of the guys in the barracks that was responsible for making sure that none of them got away. And it was a It was a tough thing. My dad had never seen anything like that, and he— it kind of shook him up emotionally. It was kind of real for him, plus the tensions of Desert Storm at that time.
My kid's going to get sent over. Years later, I got to replay that because my oldest son is a disabled vet, and he did do Afghanistan and Iraq. And I'm thankful for my time in the service, both Guard and active, because it helped me to be both a listening ear for him as well as an advocate. But yeah, it also helped me understand how foreign all that was to my dad. He just— that was something he'd never experienced or understood.
But yeah, I mean, I came out of the service, and it's funny, with the recent passing of President Bush, I came out of the service and people tend to forget our economic cycles. I came out right in the middle of a recession, and, uh, I thought mid-'90s or early— yeah, '91. Okay. Yeah, right before Clinton took office. Yeah.
And I was like, I was like, I got a college degree and a— and I'm a military veteran, I should be able to get a job. No, I was bad. And I ended up getting real fortunate and getting that construction project management job with Walmart. It was good from a learning standpoint, and it was back— literally Walmart hadn't crossed $100 billion in company yet. Yeah, Sam Walton was still alive.
And, um, you know, but they— I remember our project plans were these massive plywood sheets, you know, with checkboxes. And, and years later, I would remind people when I was running large merger integration projects, uh, I would remind them that no Walmart store was ever late on grand opening, and they managed their projects with pen and paper. So by golly, we can manage our projects and deliver on time. But, but that discipline around, around project management first started there, and that ended up being— all great things from a career transition point involve some form of drinking in my life. And we had gone to a party.
We moved back to Central Ohio and gone to a party, and my, my late wife's manager, she was working at a call center at a payment processor, and she— he pulled a bottle of frozen tequila out of the freezer and he said— we got to talking— he goes, if you can manage a Walmart new store build, you can manage a mainframe migration project. Now, only alcohol will make you make those connections. Yeah, because I didn't know the difference between a mainframe and a toaster oven. I remember my first project working for this payment provider was migrating 5 mainframes at 4 different physical locations into a brand new data center. So, you know, 5-way mainframe consolidation into one geographic location.
Of course, again, showing my age, I remember us transporting data on on tape in privately chartered airplanes. It's still a fast way to move data around. It is. Faster than downloading. I actually heard somebody say it the other day around some SSDs they were trying to— for forensics.
They were like, chain of custody, they loaded that stuff up in a private airplane and flew it. So yeah. It still happens. If you need to move too much data, Amazon just brings a semi over to pick it up. That was my entry point then in the mid-'90s into technology, and I've never not been in technology after that.
You started off with mainframe consolidation. Maybe we don't have to go every single step, but talk me through what the arc looks like. Yeah. I worked for a great company. It was CheckFree.
It got bought by Fiserv years ago. It was a smaller company. It was awesome because Uh, the, the CEO and the COO both went on to other things. Pete sold his company, but, but they were there, you know, and, and I'm this young kid. I was real fortunate.
Now, you know, now 20-plus years later, one of my best friends is the guy that was in the cube next to me, and he was already like 13 years a mainframe programmer. Yeah, you know, so he took me under his wing and he, he like helped me, and, and that's a big thing about my career, the arc is always defined by names of people who had a huge impact and an influence on getting alcohol done. And alcohol. Everyone's always had a cocktail. Um, so yeah, one of the things that was really, really important about that experience relative to my career arc was I remember, you know, we went from mid-'90s to late '90s, and there were the beginning conversations about what would become the, the internet bubble run-up, and, and people are starting to do things of value on the internet.
Yeah. And so this payment provider was moving to do payment processing for non-banks and non-financial institutions. And I remember sitting in a conference room, and I'm surrounded by all these, you know, veterans, people that have been doing this stuff for years and years and years. And our CEO walked in and he said, hey, We've got an internet company that wants to do bill payment for its customers. I would also say this is probably my introduction to information security back in the day.
He goes, they're not a bank, and by the way, we've got 64-bit encryption. Who wants to take this project? All of the veterans around the table were like, I don't want to touch that with a 10-foot pole. They're not chartered. They don't have FDIC insurance, 64-bit encryption.
I mean, even back then we knew, you know, yeah, yeah, 2 kids with a calculator, right? I mean, it's just— and I was just young and dumb enough and uninformed enough to say, hey, pick me, let me do it. And the first 2 that I did were America Online and— who's the second one? AOL Bill Pay. And the second one has escaped me, but was another big provider.
And then even rolling forward, we did an RFP where we were working with this small company out in Silicon Valley that, you know, it was an e-commerce site. And I remember when we lost the RFP, literally to a couple of guys in a garage, my CEO, I said, man, I'm sorry, Pete, we didn't get that deal done. And he goes, yeah, it's no big deal. How big can an internet auction site be? And it ended up being PayPal and eBay.
Which is a great piece to my story as well, as I've been at these incredible intersections of kind of digital history and business history. Because reeling forward, and, you know, we'll kind of get there, but I was literally at Enron on the very last day as a solution provider. Yeah. And, you know, so I saw the PayPal just, you know, start, and I saw Enron just stop, right? Yeah.
And to be at those intersections is really fascinating because it's those stories that help make you understand a broader universe relative to risk and threat and all those kind of things. I've got your LinkedIn open in front of me and looking at— you did Accenture, so Arthur Andersen, right? Yeah. From 2001 to 2003. I assume that's where you were for your Enron stop.
But as I look at your resume or your LinkedIn at least, that is— I think that's a a pretty accelerating position, right, to get to go to do that type of role. Talk to me about what you did there for 3 years at Ericsson. So I think it's really important that for me at that stage, and I was a kid, you know, when I hit that payment processor, I always tell people, like, they were like, it's like you did a brain transplant. Like, how do you go from that first part of your life, you know, you're 27, 28 years old, now you're doing this stuff? And I might tell people all the time, It's, you know, when you go see a Little League baseball game, you know, 3 kids get up at bat.
First kid that gets up at bat, you go, oh, bless his heart, right? That kid, mom and dad shouldn't have him playing baseball. I'm sorry, right? The second kid, you go like, hey, pretty good. That kid's going to be all right, you know, at whatever, 8, 9, 10, 11 years old.
That kid's, you know, that might keep playing for a while, right? And third kid gets up to bat and it's like, well, that's That's the next A-Rod, right? It's not that they're talented, it's just that they're talented relative to the environment that they find themselves in. Once I got into technology, I found that the thing that I was particularly adept at that gave me my A-Rod moment, I guess, is that I found that at that stage and age in development of technology, there was nobody that understood how to translate business requirements into technical requirements. Yeah, and that's where I made my bread and butter.
So when I went to Andersen Consulting, it was an internet company that I was working at that went bust, but I had ended up getting one of my very first technical credentials. I became a TIBCO Certified Architect because my company was funded by the same company that funded TIBCO. And, um, as, uh, as I got picked up by Andersen Consulting because they want to do a lot of TIBCO deals I was put into the energy trading and risk management practice, and I was immediately put on a team that started developing trading platforms. This was an incredibly important component of my career relative to what I do now, because I was formally trained in financial risk management, and all the underpinnings of financial risk management are all evident within technology risk management, operations risk management, because it's the foundation. I remember my partner handing me a book on a Friday afternoon and saying— it was a massive college textbook on risk management— he was like, you need to be done with this by Monday because you're with Andersen and you will be an expert when you get on the client side.
We built high-volume trading platforms, financial derivatives, It was— it's like anybody that has that experience moving into an Andersen or a Big 4. It's drinking from the fire hose, right? It's 120-hour weeks. It's big client engagements. It was a great experience.
It's just, you know, after about 3 and a half years, it had taken its toll to the point where on my family, or I couldn't travel anymore. And that's the real big transition for me, was intentionally targeting Bank One because they were hometown in Columbus. And it took me 6 months to break in the door. And I really pushed in there based on my technology project management background.
Unfortunately, the day that I arrived, a decision was made to relieve the person that was— that had hired me from their position. And I got immediately introduced in the corporate culture where I was brought in, and I'll never forget the conversation. A corporate CIO said, hey, we've been waiting for you to get here because you're the Accenture strategy consulting guy. Thinking in the back of my head, I never worked in the strat group a day in my life, but believe what you want to. He goes, we really need our program management function fixed.
Can you do an analysis for us? I did an analysis for 6 weeks, came back. I got through my second recommendation. He goes, great, we need someone to lead it, we think it should be you. That was really my big step into IT executive management.
Completely by accident, somebody saw something in me that I didn't see in myself, which is a big factor in my career, and they said, we want you to do this. Then you just couldn't have timed it any better because at that point, 3 months after I bring this group together, JPMorgan Chase consumes Bank One and And now all of a sudden, I'm a Chase person. Now I'm operating at a scale that's mind-boggling. That really became the hanging onto the side of the rocket for the next few years until the bust. But then I did so much work in so many different technology areas that it queued me up to— after a few years, I became a Chief Information Officer.
Um, was that at Chase you're talking about? No, it was— I left at Citgo. Citgo, yeah, Curaçao Interest and Trust Company. Yeah, love that company. Um, it's a, uh, it's a fascinating little company that does a vast majority of the world's backend processing for hedge funds.
Um, so, uh, it was rarefied air. It was a totally— like, I knew about investment and all those types of things from servicing a lot of those when I was at Chase, but hedge funds are a different world. I remember being the first technology guy that was invited to come speak to an investors conference in Zurich, Switzerland. Let's go back to the kid from high school on the lake with 52 people. I'm standing in the middle of a conference room in Zurich talking to some of the biggest investors in the world and family offices, you know, and trying to translate those technical components back into understandable business pieces that that audience could understand.
And literally, kind of like the weirdest moment in my life was we went to dinner the night of that presentation, and down sits next to me George Soros. And regardless of what people's opinions of Soros, right, from a hedge fund standpoint, the man is a legend. And it just turns out that he was a family friend, and that's actually how their business got started together. And yet I'm sitting next to this guy, and he finds out that I'm part Hungarian, and we had lots of stuff to talk about. Yeah, so it was— but then the challenge was that hedge fund redemptions crushed the hedge fund business in '08, and that we just couldn't sustain you know, the, the employment contracts for me to move overseas, which is really kind of the beginning of my global stuff, which is another advantage.
I mean, you know, for, for people that are listening to the podcast, I cannot emphasize enough how important it is to either intentionally, or if you're lucky enough, accidentally have opportunities to, to work, travel, experience things outside of this country. When you have that opportunity, especially if it's in a working atmosphere, if it's volunteering for something no one else will, to go to some country that nobody else wants to go to, do it. Because that exposure that you get really helps you be a better resource. Yeah, it's helped me be a much better executive. But, um, uh, yeah, that was the beginnings of it.
And then '08 happens, and I find myself No more C title, back at JPMorgan Chase managing Washington Mutual and Bear Stearns being absorbed. Front row seat again to history, like these big, big problems in the industry. I'm going to take over a little bit because we're going to run out of time. We have a hard stop in about 15 minutes. I want to hear how did you go from really IT-focused CIO to getting into security?
One great leader. Amy Geiger is now the Chief Security and Risk Officer at Huntington Bank. She was a young head of security and risk function, and I went in and interviewed with her. I was already at Chase, I was doing all the work there, went in to interview with her, and it just happened to be a situation where the C-level executive that she was reporting to, I had worked with during a lot of the merger integration stuff with the economic collapse, and I just knew how to communicate with them. And she said, I need somebody to build this identity function.
And I had enough technical experience in my background to be able to understand the underpinnings of our homegrown solutions, because no solution providers could scale to our size at that time. And I was taking it over just for retail banking. And by the time over the next course of the next 3 years, I had consolidated and aggregated and also been promoted up through the director ranks to do that identity function from a security standpoint across about 80% of the population of the bank, so all the consumer businesses. So same kind of thing as the Accenture experience. When you do it at that level in that scale.
I remember any breach event, any exploit, and I remember distinctly the Syrian Electronic Army's attack on all the banks, which was a massive DDoS attack back in the day. You're in command centers and war rooms with not just your colleagues, but with the NSA, with the FBI, with the CIA, with the Secret Service. You just can't learn that stuff unless you go through it. And that, you know, going that trial-by-fire route for, you know, 3 years or so, it just exposed me to a lot of things now that many companies are just starting to experience in identity. But I gained enough experience there to become a Chief Information Security Officer.
So I left Chase for mainly for, you know, mental health reasons. It's a tough, tough place to work. I became a Chief Information Security Officer for Mettler Toledo, Swiss company, again, another global exposure.
I loved being a full control, full security domain leader. Being a CISO has its challenges, but being able to go across all of the problems that you face with threat and vulnerability management and firewall management and identity. I got the opportunity to do that, and it was only the result of a bit of a family catastrophe that caused us to have to recalibrate a little bit. At that point, I just decided that if I'm going to move the needle relative to cybersecurity, I was going to do it outside of the corporate world. I felt like I kept solving problems for one company and, and there were so many problems that were interrelated.
There's so much counterparty risk— I'll go back to my risk training— where so many companies are exposed to each other's risks that it's like you could fix it here, but if you didn't fix it in your third-party provider here, you were still done, you were still had. And I kept looking at it and going, it's got to be a better way to approach this. And, and that's when I decided to step out of the corporate functions and take all of that experience and try and apply it in a way that would really move the needle. I know it sounds altruistic, but I want the world to be a safer place. I think when you operate on those types of more altruistic aspects of cybersecurity, it's very difficult for you to work in a corporate setting because you just can't move the lever far enough to make a big difference.
You know, you may make a good difference for the customers and the constituents of your services and your, and your products, but you're not making the broader world safer. So, so, so what did that lead you to do? So I went, um, I know it, I know the answer. Yeah, you know the answer. Why don't you tell us?
Well, so I, I picked up the phone. Um, I actually had been asked to fix identity, um, in a company I was like, I said, hey, if I'm going to fix it in the 4th company that I've been at, I'm going to go fix it for everybody. I called up my sales team at Optiv. I had used them at 2 different companies. I loved my sales folks, and I said, hey, what do you guys got going on over at Optiv?
I knew they had an executive advisory practice called Office of the Chief Information Security Officer and that they hired former heads of security and CISOs. I said, look, if you've got something open. They said, we've had a requisition open forever in Cleveland. We can easily make it Columbus. I joined them and I spent that first 15 months, I went to about 35 different companies.
The beautiful thing for me there was seeing across multiple different industry segments seeing the commonality of core use case problems. Everybody always talks about, well, you know, we're pharmaceutical, well, we're healthcare, well, we're insurance, and our problems are unique. And the one thing that I found universally true is nobody's unique. And the second thing that I found was universally true is that it was really, really clear to me that the source of almost all security failings came back to this core notion of identity. I would say that I always kind of had that chip on my shoulder and that attitude from probably an unearned arrogance standpoint, but when I started to see the mechanics of it, I started to really understand.
I mean, there were certain things that I had been pushing for a couple of years. Role-based access control was one of them. I started taking a look back and thinking, how much of my drive for RBAC was my own bias and belief that that was the right answer, as opposed to learning from other organizations, other practitioners, other solution providers that maybe there were different ways to attack the problem. So that immediately broadened my experience and my understanding, and I was able to start changing my mind, which I think is critical at my age. I think it's critical at any age, being able to be malleable relative to understanding that there are different ways to approach the problem.
And then that started to get me aligned towards innovation. And, and I'm— I was like, if I can think differently about the problem and I can find other people that think differently about the problem, maybe we can come up with new solutions. And, and that really was a great testing bed for me to talk to clients, say, well, have you thought about this, right? Have you thought about just wiping out your entire Active Directory environment, standing up brand new Active Directory templates that are already securitized, migrating all your users to them, now having a clean data store to run all of these identity solutions. People were like, whoa, no, we've never thought anything like that.
That's crazy. We can't do that, until I showed a couple of companies they could. That became a real motivator, and it really was— I think that leads to the Ping opportunity It was on top of all of that great stuff, the one thing that Optiv did for me is it allowed me to do something I had never been able to do. When you work in the corporate environment, you're extremely restricted on your ability to write, speak, publish, because you, you might accidentally disclose something that would be, you know, there's no upside for JPMC to let you talk publicly. No.
No, they— yeah, they actually have people that they pay to do that, right? And, um, and so Optiv gave me that opportunity, and I was on— we've lost count in the last more than 2 and a half years— something like 35 or 40 different, uh, conference podiums, some small lunches, some big at InnoVerse. Um, and I found that being able to go back to my father. My dad told me, you know, from the time I was a kid, the best way to connect to people is a good story. And I found that I was a really good storyteller relative to helping people understand complex cybersecurity issues in easy, you know, metaphorical or analogous type of stories.
And it was shocking to me because people were so receptive to it.
That really opened up a conversation with Andre Durand. I have to laugh. I actually just put a picture in a presentation that's going to be shown tomorrow. The real reason that I came to Ping is because I'm looking forward to sitting next to you again because I got a picture of you and me when we did the panel the first time I was at Cloud Identity Summit. And, um, and, and those conversations led to a lot of discussions between Andre and I about, are we really moving the needle?
Are we really innovating? And this is the global we. Could we think about the problems differently? Can we attack the problems differently? And, and Andre has given— it was so gracious to say, yeah, we definitely can.
When can you start? And that really was was how, you know, all of this came about. And I, I'm pinching myself because I'm getting— even just in a couple of months, I'm getting these, these never-before-seen in my personal lifetime opportunities to deep dive into subjects, to talk to really talented technical people about their ideas, to, to dig into everything from white papers to conversations with small boutique stealth providers who are like, I got this part of the problem figured out. It's really my desire and hope that I'll be able to deliver on some of that altruistic belief that I, you, me together, Andre, this team here, we can make the world safer because I think that identity is the absolute foundational key. If you are who you say you are, then most of everything else in the cybersecurity world can be managed well after that.
It's when you're not who you say you are, but we think you are who you say you are, that all the trouble starts. I'm beyond eager. Every day I wake up, I'm like, what can I dig into next? Your role at Ping, the CCIO role— have you ever heard of that before? Do you make that up?
Where'd that come from? I laugh because I remember the first conversation that I had about your title is going to be Chief Customer Information Officer. I was like, well, you know what? If you're going to go with something, just make it up. Why not?
I do say frequently, and I've said it several times in the public sphere, that the beautiful thing about a title like Chief Customer Information Officer or is it— it is truly what you and I make of it, right? And I've shared that with, with so many staff members here. It— we know what it means. We know that the, the 4 key domains within, within Ping, that, that I am able to walk freely around. I always like to say I'm a mercenary for good, right?
I'm, I'm looking for opportunities to create better processes, to improve customer relationships, to dive into products, product development, and suggest an operator's informed opinion on, okay, this is what that'll really look like 2 years after you've implemented it when we don't want a customer to have to have hired 4 more people to run it, because I've lived that world. The domains are Our product, working with the product team, but not just working with the product team, working with the customer to provide input back to not just development requirements, but additional feature functionalities that we may need to look outward at partnering with. PR, strategy, and marketing, obviously a lot of talking and speaking and writing and publishing. Sales, Working with the sales team to be an advocate for the sales team, but also to be an ambassador for the customer.
I have— what's really crazy when you look at a career as diverse as mine, I have a massive global and domestic network. So there's only been a couple of companies that people have asked me about, hey, do you know anybody there? Out of dozens that I've been asked about so far that I don't have a connection at. That says nothing about me. It says everything about the talent of those people because they've gone on to become CISOs and CIOs and CEOs of companies from where we all started.
They've excelled and exceeded. I'm just fortunate enough to know them. I'm fortunate enough to remember what they looked like at that party with the frozen tequila.
Then the other component is our partners. I think this is a big thing. There's obviously within all these types of companies, there are people that are managing all of these functions. I'm not here to replace or displace any of those. I'm here to add rocket fuel to those elements, but within the partner space, I think one of the things that's really interesting is several years ago with my Optiv guys, they walked into my office and I had a greenfield opportunity.
I had nothing but kind of core basic free commodity pieces and parts to run my information security organization. I said, I've got a budget, brand new, I want to buy nothing more than 5 solutions to cover all my security domains Those 5 solutions will be 5 solutions because they will be highly integrated. Data will be shared between them. This is now 5 years ago. I will tell you that my sales crew looked at me and said, that's not possible.
Different security solution providers across different domains are not playing well together. Some of them are proprietary. Some of them are open standards. Some of them won't share data. Some of them don't.
He said, so we can't make that work. We can give you a dashboard. That was always the answer. We can pull it all into a dashboard and you can look at it. I think I was kind of pressing the edges of now what has become an expected standard around orchestration and automation and workflow, and yet I can't tell you that the market is that much better in cybersecurity.
Solutions than it was several years ago. From the partner standpoint, this is where we get the lever to move the world. We work together with partners to create truly tightly coupled and integrated, where it makes commercial sense, solutions that now allow for— there's always the concept of overlapping controls within a corporation, but they're overlapping but never connected. That's the problem. We've got to get it so that data-driven decisions, data-driven workflow, data-driven authorizations, authentications are natural, and the only way that we do that is through partnership.
That's another big piece of this. Those are the 4 big key components, and everyone has just been incredibly gracious about looking at this graph of this is what I'm supposed to do, and then going, okay, so we need you in this meeting. Okay, so we need you at this customer. Can you fly out here? People automatically intuitively get somebody that has almost like an ombudsman role, right?
And I'm just over the moon about it because I get to take all of that stuff that I've aggregated over all of these years and get to use it as a benefit to others as opposed to to me. I'm literally at a point in my career I have no— I don't care where it goes from here, right? The, the only value that, that I get in terms of professional satisfaction anymore is where I can get others, right? And, and I'm really, really, really excited about that. Awesome.
So, well, I know you had a hard stop here a couple minutes ago, but I want to give you a chance. Any final, any final stuff you want to say to the listeners? Um, I think that, uh, for me, the hallmark of my career has been something I didn't understand early. The hallmark of my career is being willing to take risk in order to expand your understanding, right? I remember being that kid sticking my hand up and going, you know, I'll do that.
Right, when I didn't even remotely understand the technical underpinnings. There's no way, and this should resonate with people that listen to this broadcast, there is no way that a kid like me from a place like where I came from could have ever even remotely made the statement, I am going to be a cybersecurity practitioner when I am my age now. Yeah, because my job didn't exist, right? And, and where people will be that are listening to this that are only in the first 10 years of their career will also be in a place, in a job that doesn't exist. And the only way that you get there is taking a look at all of the stuff that's known and going, I'm willing to take a risk to Step out into spaces that are uncomfortable, are difficult, intellectually challenging, because I'm not going to sit back and be comfortable and sit in a space that I understand and know.
Step out and be adventurous relative to your career growth. I don't think that there's a better trade right now than cybersecurity. That because there's more unknowns than we could possibly quantify. So that would be my encouragement. That's awesome.
I think that's great feedback.
The careers of the future don't exist yet, and if you're looking for a path, you got to make it. Yep. I love it. Absolutely. Richard, thanks so much for your time.
I think that the community's gonna love getting to know you, and you're living in Denver now. I am. So we're hopefully gonna get to see more things in town. Absolutely, and I am really happy I made the decision decision.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.