All episodes

Kris Kistler, CISO at Centura Health

Apple Podcasts Spotify SoundCloud

In this episode:

Kris Kistler, CISO at Centura Health is our guest this week. News from: Firmspace, CDOT, ProtectWise, Coalfire, Ping Identity and a lot more!

#10 overall, but #1 in your hearts

Whatever formula ranks North Dakota over Colorado has some serious issues huh? But don't miss out that Colorado does rank as the strongest economy. And luxury co-working is on the way to make it even better. Election security is top of mind, and CDOT is still struggling with their ransomware attack. Lots more stories as well.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure.

Trivia: Nobody knew that the Colorado = Security podcast has had no sponsors yet. You guys let Andre Gaeta off the hook last week. Did you catch this week's trivia question? Be the first to reply to info@colorado-security.com with the right answer and get any $25 item from the Colorado = Security store.

Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11073 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 57, the week of March 5th. Alex, one of my neighbors is stalking me.

Really, Rob? How do you know? Yeah, she's been typing my name into Google on her computer. Oh, really? Yeah, I saw it last night through my telescope when I was watching her.

Oh, Rob, it's so silly. All right, number one, we have a newsletter. If you guys haven't signed up for the newsletter yet, go out to our website and we'll get you these show notes in your inbox every week. Subscribe on iTunes and go, go or Google Play and go review us there as well. And only 5-star reviews, none of that other junk.

Just, just good stuff. Thanks. Good stuff. Thanks. So I saw— I don't know if you saw this week on our Slack channel, some folks were talking about RSS feeds and podcasts that they like to use.

Yeah, so there was a good discussion about places that people look for, you know, blogs and other things for their news. And some people posted their feeds, which was cool. And then also some good other podcasts besides ours. I know Risky Business came up, which is one of my favorites. Always a good one.

Yes. If you guys are looking for places to get your news on a daily basis, and you know, that's a, that's a good place to go check, check our Slack channel. There's well over 300 people. I think we're at like 330 folks on the Slack channel now. Good conversation going on just about every day.

Yeah, good stuff. So let's jump into the news first. US News and World Report. Noted that Colorado is number 1 for the economy and number 10 overall. Yeah.

So, you know, they, they have about 8 different categories that they rate each state. Colorado did really well on the economy section. We, we also did pretty well on healthcare and quality of life overall. Some areas we did not do so well is crime and corrections and financial stability. But overall, they put us at number 10.

So, you know, top 20%. Hey, good job, Colorado. Congratulations. Number 1 state. If you're looking to move somewhere, Iowa was, was number 1.

And believe it or not, somewhere above us was North Dakota. Wow. Yeah. So, you know, my guess now is that Iowa will be named the Amazon HQ too, since this is obviously the number 1 place to live. Obviously.

Why would you go anywhere else at this point? Obviously.

Next, there was an article this week about US governors and their worry about cyberattacks during the fall elections. This is in the Denver Post. And I know John Hickenlooper, our governor, was, was there as a part of this meeting and kind of talking about how we need to be ready to respond in the event of election hacking, right? Yeah. And we've obviously talked several times about Colorado's election preparedness and what folks have been doing in the previous election and for upcoming elections.

Specifically, Governor Hickenlooper said that election security is one of the most, if not the most immediate threats. And so what is it? What's the response? What are we going to be doing about, you know, Russia or whoever else that's trying to hack our elections? Yeah.

If you remember the ratings that were in that recent evaluation of different states' readiness for hacking for their elections, you know, Colorado was at the top, but the top was a B, right? So no one's really ready for it is what the evaluation was. Exactly. So Firm Space is a luxury coworking space that's been— I think it was Austin they've been previously, and they're coming to Denver. So we're going to have luxurious office coworking spaces that we can use here in town.

Yeah. And, you know, there are a number of coworking spaces that are around town, you know, WeWork and other things like that, Galvanize. But this looks like it's just sort of a higher-end, right? Nicer, more luxury kind of space that you can cowork in. Yeah, they have like really high-quality conference rooms you can use with all the latest technology and beautiful shared waiting rooms and so forth.

It just really looks like a nice upscale office. Yeah, yes, looked like a nice high-end office that you might visit, you know, a lawyer's office or something like that. So it makes sense. So as soon as Colorado Equal Security is ready to have a working space, I think we found our spot, right? Definitely.

Nowhere else. Next, last week we talked about how CDOT had been affected by a ransomware attack. Well, there's an article that they got hit a second time, so they're in the process of cleaning up and they had a second infection hit them. What a terrible week, right? If you're part of that incident response guy, you just, you just had a really bad week.

Yeah, you've been working around the clock trying to get this back online and all of a sudden, you know, someone kicks you again. So if you were part of the incident response there at CDOT, um, let me know, I'll get you a drink. You know, we don't even need to talk to you about the— if you just want to drink to forget what happened in the last week, uh, we're happy to, uh, to, to drink one for you. Um, and it also, I think we mentioned this last week, it was the, the SamSam ransomware. Mm-hmm.

I think that was the same thing that hit the city of Inglewood. Um, so I'd say if you're out there and you don't know if you are protected against SamSam ransomware, I think you should probably check. Yeah, it's probably a good idea, right? Yeah. Coming around.

Uh, so next we have an article written by Cam Williams. Cam was our feature guest, uh, what, a couple weeks ago, right? Yes, he was. And, and he wrote an article for, uh, for Colorado Business Magazine about how Colorado is really becoming a hotbed for cybersecurity. Um, so not a lot of, of news to folks who are listening here into this, but it's cool.

He does, he does have an interview with, uh, Brett Fund from, uh, SecureSet, and he also name drops a bunch of the Colorado companies that we know and love here with, uh, with Ping and LogRhythm. Optiv, Webroot. So, so really nice to see this conversation getting— making it to the more mainstream business magazine. Yep, we always love more news in the Colorado security space. Next, the Denver Business Journal had an article where they had a— called it a table of experts.

So this was a cybersecurity and fraud roundtable. So they brought in several folks for, for the panel and asked some questions. Rebecca Pearson, who is SVP for FinEx Cyber, Dave Mahon, who's with CenturyLink, and Brett Fond of SecureSet. So a number of questions and answers in there, some good content, talk a little bit about SMB security and how that is still an area where people probably need more help. But again, just cool to see that there is more talk about this Denver security community and cybersecurity in the mainstream media.

Yeah, Denver Business Journal doing a Q&A around this is pretty neat. The biggest thing I learned is that Denver Business Journal actually has a physical office here in Denver. You know, the business journals, they're a series, right? Every major city has their own business journal. Colorado Springs has a business journal and, you know, every major city does.

So I kind of thought there was one central place, you know, in Washington, D.C. or whatever where everyone like, you know, works from, right? Yeah, it's 2 people who are, you know, doing it all, but no, apparently we actually a staff here in Colorado as well. So that's pretty cool. Definitely cool. Um, next we have, we have an analysis of the Satori botnet.

So we talked to you guys a while back that ProtectWise was creating their own threat research group, that was 401, right? Um, and we mentioned that they were going to be doing some new research and sharing it with the community. And this is one of those examples of some pretty in-depth analysis. If you want to understand how this botnet works, uh, understand how it gets infected, this is a pretty good piece of research for you to take a look at. Yeah, definitely go check that out.

And then finally, Coalfire had a blog post this week about the new SEC cyber risk disclosure guidance. So the SEC came out and gave more clarification on how companies should deal with cybersecurity incidents in terms of reporting them. So a couple of things that they talked about were that people need to think about cyber risks before they happen, not just reporting that they had an incident. And then also around how it is you should deal with selling stock when you have still private news of a big cybersecurity incident, like, you know, with Equifax. They basically said don't sell it, right?

Right. So we had the Equifax one and then the Intel recent vulnerabilities. Both were situations where, you know, because of the fact that they had knowledge about bad stuff going on, any stock trades that happened in that window were really subject to people know, questioning, right? Did they— were they doing insider trading? So, so SEC is just giving guidance to say, just don't do it during this window at this point.

So there's no question about whether it's okay or not. Yeah, I can't remember who it was, but I heard someone say this week, it's going to lead to some new interesting meta-analysis, right? So if you see all of a sudden, you know, a major company that, that none of their executives are selling stock. Yeah. You know, you see a normal pattern, then all of a sudden it stops.

Oh, they're going to report a breach soon. Yeah, that's gonna be funny. Uh, that them not selling stock could be a reason for other people to go sell stock. Right, exactly. All right, that's it for the news this week.

Let's jump over to trivia. So last week's question was, uh, name Colorado Equal Security's first podcast sponsor. And that was not a trivia sponsor, which is the podcast sponsor. And the winner this week is Andre Gaeta, because Andre, who is the sponsor for trivia, doesn't have to pay anyone, right? We didn't have a correct answer this week.

Um, I want to say it's not quite a trick question. Yeah. Um, but it was one that that didn't have an obvious answer, right? Yeah. So the answer is we've never had a sponsor on the podcast.

We've talked with a couple folks about maybe doing it. And we haven't, at this point, haven't had anyone sponsor. So Alex and I have been paying the funding for hosting and all this stuff, and all the mics and all these fun things out of our pocket. So I guess this kind of goes hand in hand with an announcement that we are going to open up a Patreon page here. Yeah.

And so those that aren't familiar with Patreon, It is a website, a service that, that you can use to have patrons. So it works in for artists or podcasters or tech writers, anyone out there. If you want to have essentially your audience fund what it is that you're doing, then you start a Patreon page and people can sign up to give you support. Yeah. So if you go out to, to our website, we also have a link to it, but it's also at patreon.com/ColoradoSecurity.

You can see there's a few different levels you can support us at. Uh, and they're all set up for per month. There's the $1 a month level, uh, there's the $5 a month level. If you sign up there, you'll get a free Colorado Equal Security t-shirt. Um, there is the $10 a month level where you get the t-shirt and you get a mention on the podcast, which is very, very important.

And I'll even throw in there, if you, if you do this one, let me know who you'd like me to insult on the podcast, and I'll do that as well. And, and those are just some goals that we had, um, you know, some possible ones to throw out there. You can obviously do any other dollar level that you want as well. And I just want to make sure that we note while we're doing this, this is not to, to help line Rob's pockets, you know, because I don't get any of this money anyway. We're— anything that we make in this is going right back into the podcast and Colorado Equal Security.

Yeah, certainly no intention of us, of us making a profit on this. I'd say if we happened somehow to have more money coming in than we use for the podcast, we would use it for other Colorado Equal Security stuff, some swag, some stuff to give back to the community. We have no intention to take any money out of this. Or maybe, you know, we'll get so much money that we'll have, you know, enough to start getting our coworking space at the Luxury Coworkspace. Absolutely.

All right. Moving on to this week's trivia. What is the top security company protecting Colorado's cannabis stash? Ooh. Yeah.

So there's, there's a company that's pretty much responsible for protecting most of the pot in town. So let us know who it is. Send an email to info@colorado-security.com or hit us up on the Slack channel directly. Don't, don't do it in a public channel. And we'll, uh, we'll let you know if you're the first one and you got it right.

And we won't assume if you answer that you're a stoner. Just, just saying. We'll assume you know how to use Google. All right. Uh, once again, thanks to Andre Gaeta for sponsoring our trivia.

We appreciate it very much, Andre. So let's move on to events. As always, we have our event calendar on the website, so make sure you go check that out for the latest events happening in the area. And first on the list is a CTA. I cut Alex off because the first thing on the list is wrong.

So CTA is doing their Daybreak Education Series, The Business of IoT. That's going to be happening on the 6th of March. Second, it is SnowFROC time. So OWASP's annual conference is happening on the 8th. Day-long conference, gonna be good stuff.

Rob is not speaking this year, so you should definitely go. Absolutely. The, the next week we have the Denver ISSA March meetings. Those are happening on the 13th and 14th, and they'll be on the 13th, which is Tuesday, lunch in Boulder, the dinner in the downtown Denver area, and then lunch on Wednesday in the DTC area. Next on the list, we have the Sea Level at Mile High, which is on March 15th.

This is the, the big event that they have, sort of a networking event. Lots of executives get together, talk about technology, other things like that. Yeah, and we do have some, some CISOs involved this year with their, their celebrity auction. So this will be a good time to come support some of your friends of the community and, and see what's going on out there in the larger tech world. The next event we have is also the 15th.

There's actually a few events here on March 15th. ISACA has their March meeting. This is on combating fraud and corruption with data analytics. Uh, if you weren't going to go to C-Level at Mile High, SecureSet is also having their Cybersecurity Expert Series with Chris Roberts on the 15th. And then finally, also on the 15th, ISC² Denver is having their March meeting.

So you guys have a lot of opportunities there on March 15th. Yes, exactly. Uh, so that's it for events. Let's move over to jobs. First on the list, we have a couple Ping jobs.

Ping is looking for a GRC analyst and also an application security engineer. So for the GRC analyst, we're looking for someone pretty entry-level, maybe 0 to 2 years, who, who knows about compliance and is interested, excited about getting more involved with compliance around ISO, SOC 2, and GDPR. For our application security engineer, we're looking for someone who has a Java development background. So we're not looking for someone who knows how to run Metasploit, someone who knows how to code, hopefully has actually done coding for an enterprise application at some point, um, and, and wants to get more and more involved in security. Having a good concept of network protocols as well is pretty valuable.

Uh, next on the list, PDC Energy is hiring a Director of Information Security. Uh, Crowe Horroth is hiring an IT Audit and Consulting Senior Manager. CenturyLink is hiring a senior information security engineer. Um, Polycom is hiring a senior security analyst. Spectrum is hiring a security engineer 1, or I, not sure, it could be either.

Yeah, or lowercase L. Western Union is looking for an information security analyst. HomeAdvisor is hiring an information security engineer. And what looked to be to me to be the coolest job of the week. NREL is hiring a cyber-physical systems security and reliance engineer. Yeah, that does sound like fun, right?

Yeah. So if you're looking for how, um, how cybersecurity and the physical world interact, that sounds like a pretty cool job. Very cool. Well, that takes us to the end of the news. Our feature interview coming up is me sitting down with Kris Kistler.

Chris is the CISO for Centura Health. Um, he's been there for quite a while and, and kind of talks to us about what it's like to try and secure, um, biomedical systems, his favorite framework, which is HITRUST, and talk— talks about how that ties into other frameworks and how you can use that to help get more compliance, some of his highest priority projects for the year, and what his biggest accomplishments have been over the last few years. Awesome. I look forward to it. Cool.

All right, everybody, have a great week and we'll talk to you soon. Thanks, Rob. Hi, this is Jose Calvillo, CISO at ASM Payment Solutions. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

Alright, this is Robb Reck and today I'm sitting with Kris Kistler. Chris, in addition to being the CISO for Centura Health, you're also a psychologist, is that correct? Psychotherapist. Psychotherapist, excuse me. So as we talk here, I assume you're gonna be analyzing me, is that true?

Am I gonna get a bill at the end of this? You are gonna get a bill at the end of this. I'll tell you all about things you never wanted to know about yourself. Well, I'm looking forward to learning some things about myself that are probably deeply disturbing and not any surprise to my wife. That's my guess.

But that is one of the— I think that's a unique combination in a security leader. I've never come across someone who's a psychotherapist and a security leader. Have you? Are you the only one you know? I am the only one I know.

I do know there was another gal I know that was in security and she had a psychology degree, but I can't remember the name of her. She was here, I think, in Denver though. Oh yeah? Yeah. So apologies for not remembering your name if you're listening.

Well, if you're that mysterious woman, send a note and Chris is going to send you a wonderful gift. Yes. All right, well, let's dive in, and I'd just like to get some of your background, learn how you got to be where you are. I want to get to Centura, but first let's back up. Where'd you grow up and where are you from?

I grew up quite a bit— my dad was military, So we traveled a bit when I was younger, but I did most of my growing up in Kansas City and then spent 10 years in St. Louis and— or actually 20 years in St. Louis and then moved to Denver. I've been here in Denver now about 8, 9, actually almost 10 years. Be 10 years this fall. And what brought you here? Brought here?

My beautiful wife brought me here. Okay. She's a Colorado native. Yeah. Yeah.

Did you get married here or you met somewhere else? We met somewhere else. Actually met at a Black Hat conference. Yes. So she is a security person too?

She was DOD and project manager for DISA defense stuff. So yeah. Yeah. So let's back up. You know, you grew up in Kansas City.

Talk to me about, you know, how education— what do you do in terms of, you know, you went to high school and then what happened after that? Yeah. So high school. Yeah. Kansas City.

I went out of that. I actually— my history, right? I trained dogs for a while. You trained dogs? Yeah.

So, right. A little dog psychology, right? That went into my stuff. I also was firefighter, paramedic, and police officer for 10 years. Wow.

That was afterwards and in St. Louis, right? Went from training dogs to police dogs. And so you were a firefighter, a policeman, and a dog trainer. You are all of the jobs that my 8-year-old wants to do. And a paramedic, right?

Don't forget the paramedic. That was actually my favorite out of all of them. All the sirens and very— and you were a teacher at some point as well? I've taught, yes. I've taught, you know, when does That's going to date me now, Rob.

I taught Windows 95 and Windows NT Server back in the day and taught SANS GSEC actually for a year. I was actually number 30 to be certified by SANS on the GSEC. So let's talk, obviously a lot of cool background. How did you get interested in security? Where does that start?

Well, it started back in the police days, right? So back in my police stuff, I was one of the technical geeks, right? Taught myself computer stuff. I had my little laptop in the police car when I wasn't out doing calls and taught myself some programming, some database stuff, and actually had one of the first computerized sketch artist programs that came out, but way back in the day. That was like, my God, back in like 1993, '94.

Where were you working there? That was in St. Louis, so I worked in a suburb of St. Louis. Well, 2 suburbs. I actually worked in Ferguson, Missouri for 5 years. And I got out of there in time.

Yes, I got out of there and worked 5 years in City of Des Peres. And so I did a lot of stuff with computers there with networking back in the days of before Ethernet. So I see you're a cop pulling people over, going to calls, and in the interim you're messing around learning computers. Sure, yeah, exactly. And I did some investigations at the time, right back then, hacking was pretty much limited to dial-up modems, but it still happened.

People would dial into companies through backdoors. There was a lot of pirating going on with software back in the days over the modems. Glad we got rid of all the pirating. None of that anymore. Yeah, exactly.

It's been real effective, right?

So did you make it— did you kind of fall in love with it as a cop, or was it— Oh yeah, it became my passion. Yeah, you bet. And that was my goal, right? I got out of that, taught myself networking, got Novell certified, and and then Microsoft certified, and then went out, started on the help desk, you know, for another health organization. Cardinal Health actually was Medicine Shop International at the time.

Okay, and that was in St. Louis? St. Louis, yeah. And worked there for, gosh, 5 years, I guess. Yeah, went there for 5 years, did a lot of my SANS training there, got Microsoft certified, Novell certified, Citrix certified, actually wrote the book Configuring Citrix Metaframe on Windows 2000. So you're, you're an author.

I mean, I'm in the presence of a famous person. Okay. And it was a co-author. So I was— there was, I think, 4 or 5 of us that co-authored that book. But yeah, I wrote a major part of it.

I probably wrote a good third of the book. Yeah. All the good technical stuff is mine, folks. Yeah. Any mistakes, that was the other guy.

That's exactly right. So you're working for Cardinal Health. Um, and, you know, it sounds like not focused on security specifically, more, more broadly system administration. Uh, started there on help desk and then went to help manager of the help desk and then redid all their servers and then became the server guy and then manager of the server team and then went to networks and redid all their networks and became manager of the network team and then got into security and started my SANS training and certification. So I've been to I think I only certified on a couple of the SANS courses, but I've been to like almost all of them, and I love education.

I'm a chronic learner, right? I have a little bit of OCD and ADD, so I get bored easily, and I just love education and reading and studying. So a lot of self-study, self-learning, went through that. So I'll tell you what I heard you say was they brought you in and you solved the help desk problem, you solved the systems problem, you solve the network problem, so they put you somewhere where you'd never be able to solve the problems. Yes, exactly.

It doesn't work that way. Well, I mainly— I got bored and wanted more, right? And just kept taking more. Wrote all their policies and procedures back then, right? Back then it was BS 7799, right?

Before the ISO stuff even came out. Yeah. And, uh, and we did, you know, SOX. Sarbanes-Oxley had just come out back then. HIPAA was still there.

I may even have had some comments in the original HIPAA you know, RFPs that went out.

So what else from there? Went from there, did this, like I said, did the security thing and then got bored with that there. And because as everybody knows, right, healthcare tends to move slow. It was bored for me. Went to Savvas Communications and started there as a security administrator.

And then again went up through there. I was there at Savvas for 10 years and Eventually went from just being security administrator to going up through again the supervisor, manager, director, and then senior director. Yeah, there at Savvis, both over the corporate area and their managed security services. So, and I was there when we took over Digital Island and Exodus Communications, a lot of acquisitions and mergers. So lots of interesting stuff there, a lot of interesting background, right?

Savvis Communications, for people that don't know, holds part of the— probably 90-some percent of the stock market companies that are doing all the stock market tickers. So obviously, business continuity, disaster recovery, failover, you know, the ISPs and important— yeah, they're the one providing that service. So really learned a lot. My boss at Savvis, actually the boss I had then, Don Bertier, he was actually one of the bosses I admire the most. He was a He actually programmed some of the code for the guided missiles, right?

The big— what do they call the big missiles they shoot off the ship? Tomahawks. Okay, sure. They go off and travel and then go explode places. Yeah, he actually designed some of the guidance stuff for that.

So this guy knew what he was doing, right? And also did a lot of SNMP programming development work. So awesome guy to work for. Yeah. And just an amazing boss.

Taught me a lot. When I first went there, he told me, he said, One year at Savvis is going to be like 10 years anywhere else. And you made it 100 years. And he was right. I feel like I spent 100 years there.

And was that in St. Louis? St. Louis is where it was based. Yeah, they were bought out by CenturyLink here several years ago. But great experience. Great.

You were there. When did you leave there? Because you've been at Centura for a while. So I've been at Centura now. I did a short stint at a credit card company that I won't name.

I didn't like it. Right. Credit card collections. It was just, yeah, kind of sleazy. Didn't like it.

Didn't have a good feel. Didn't stay there long. And now, yeah, I've been at Centura Health now for a little over 6 and a half years. Okay. So, and started there as a consultant actually, and then promoted up to manager, director, and then VP CISO where I've been now at for the last 2, 3 years.

Were you the first CISO for Centura? I actually was. Okay. That's, that's always cool. It's neat, but it also means that, you know, it's, it's an organization where you kind of have to train them about what it means to have a security person.

There was a lot of education there because, again, having spent a short stint in the healthcare area, right, I knew some of the challenges. But having been in an advanced telecommunications company and as an MSSP providing services to all kinds of companies and in a very fast-paced environment, it was challenge to slow back down and obviously I was not happy with the current state of healthcare security when I first went there and wanted to bring them up to not just a par of healthcare but up to an equal standing of all companies in all industries because I'm compulsive and OCD. So let's just talk about kind of how you went through that. Obviously it's been several years that you've had a chance to do it but You know, you came in and you targeted some number of things you wanted to go after. How did you figure out what to go after first?

Well, and there's definitely an art and a talent to that. Yeah. I believe, right? The experience I had at Savvis, I believe I'm pretty good at that. We did that for a lot of companies.

We got paid to do that for them. But at Centura Health specifically, when I first went there, they had zero security people. Yeah. Right? They had gotten rid of the 2 that they had for whatever reason and had outsourced some of it to Verizon, had like a virtual director and I got brought in first as a consultant to actually just look at some data loss prevention opportunities and then said, well, you know, I could do this and this and this.

So, the good thing is I was able to go in and then basically start from ground zero and I started from scratch and Initially, I had planned on using the ISO framework, which I was very familiar with. Someone at the time said, well, what about this HITRUST framework? Have you looked at that? I said, well, no, I haven't, but I really like ISO. I don't know if I want to do anything else.

I went and looked at it and then saw it was based on ISO, and I really actually liked the framework. We should talk about that. I know there's some companies that are hesitant, that believe it's too expensive or costs too much. But the actual entry point to HITRUST is free. So are you talking about HITRUST compliance, or are you talking about HITRUST certification?

Well, there's— and that's a good question because there's 2 very different things there, right? HITRUST certification, yes, is expensive. Yeah, right. But using HITRUST as a framework is free. You can download it for free just like you can the NIST.

Yeah, right. And you can use it. I highly recommend people to at least subscribe to their little web service because I don't know, what is it like depending on the size of your company and how many audits you want to do, for $10,000 to $15,000, $20,000, I'm sure they have higher things, you can get access to their great web portal which has outstanding dashboards and graphs and you can slice and dice and mix and match. So the HITRUST is not people that don't know, right, it's not any additional controls. What it does do is takes and normalizes over 25 of the existing regulatory controls, and it normalizes those into a single set of controls.

And when you go into the, the HITRUST portal, you can actually select and pick and choose which of these regulatory controls apply to your environment, and it will adjust which controls you have to answer right in there automatically. So that's— it's much nicer than trying to download the 800-some page CSF document and then try to Excel it and do your own thing. But you can then adjust that for where it's at, and then you can actually adjust it for the size of your company and do all those things. That's pretty cost-effective. If you don't want to use their portal, well, you can certainly do it on your own for free, but like I said, it's a pretty low cost of entry to do that.

Then you can self-validate. If you're going to go pay for certification, depending on the size of your company, Well, you can easily run over $100,000 on those audit and certification fees. But whether you do that or not, it's a great framework. You can report against the NIST Cybersecurity Framework, you can report against PCI stuff, you can report against all this. That's what I like to do, right?

We audit once and report many. So let's talk just a little bit about HITRUST. I'm familiar with it as a healthcare compliance framework. Built on HIPAA, or at least built to support HIPAA. Could you talk maybe a little more detail for those who maybe aren't familiar with it?

Where did it come from, and how— what is the relationship between HITRUST and HIPAA? And if you have more details, that'd be great. Sure. Well, it does contain HIPAA, and it was originally designed for healthcare, but it certainly has morphed into something much bigger, right? It now includes, like I said, PCI.

It includes ISO. It was built off the ISO standard. You'll— people that know ISO will see it very familiar to them. Is it based on 2005 or 2013? It is based on 27001, it was— is what it was based on.

Yeah, but the 27001, the 2005 version or the 2013 version? It was initially built off the 2005 version, the early version, but they have updated it. They update it typically every year, at least once a year, which can be both a blessing and a curse.

Version 9, the version 9 of the HITRUST just added lots of controls from the version 8, which was in effect last year. So for those people who may have done or certified under version 8, luckily we slid in under the radar. That was not accidental. But the v9 is— I mean, it added like 300 more controls. Yeah, right, because they're incorporating all these new standards, right?

The updates to NIST, the NIST Cybersecurity Framework, the updates to NIST 800-53, I'm guessing they added updates in there for Texas privacy controls, Massachusetts privacy controls. I'm guessing, I don't know if they have yet, maybe they have and I didn't search it, but the GDPR for the UK.

It's a nice thing to centralize, and I'm not here to sell that, but I encourage people that are looking for a framework to design their program around, very effective for the security person, for the security professional. Because what's the challenge we have? The challenge we have as security gurus, or what I've always had in a company as director or CISO, whatever the title is, is selling that security. And, well, why do we have to do this? Why do we have to do that?

Well, being able to show that HITRUST framework out of the CSF— I mean, go look at it, download it, and look at how they have it organized. Here's the control, and then they list not just the control, but here's all the regulatory rep that it references. So when you send somebody not just the control of, well, here's why you— example, you have to change your password so many days. Bad example, I know. But here's why you have to do this particular control.

And then you say, oh, and by the way, it's required by PCI and CMS and Joint Commission and blah, blah, blah, blah, blah. Right? Well, that adds a whole lot of weight to your conversation when you're having that with these other directors and developers and whoever it is. It basically shuts them down. Really valuable for the security professional to have in their toolbox, even if you're not using the framework, just to have that control reference to go look at it.

Do you guys use a GRC tool to support that, or are you just doing it through that web portal? We're using that web portal. We used to use RSAM as a GRC tool, and actually the HITRUST portal is built off of RSAM and provides pretty much all we need.

Decided to not maintain the RCM and go just with the portal. The dashboards and graphics out of it for taking to management are just wonderful. You can look at it by category, you can look at it by— and then drill down into those things, right? The things that are showing up red, well, you can now drill directly into it and see what they are. The gap reports, the gap analysis it provides, Yeah, I'm a big fan if you can't tell.

No, obviously that's great. Yeah, and I've done pretty much everything out there, right? So, well, good stuff. Uh, let's talk a little bit about the security side, you know, like the compliance side. Let's talk about what, what are the controls that you've implemented over the last 6+ years that you think are most important, most effective, and you, you do first if you had to do it all over again?

Yeah, so I like to say one of my favorite quotes, right, is Compliance does not equal security. Yeah. So we, we had a big program around compliance, right, with doing this reporting and bringing it in. But you also have to watch for tactical security. So in addition to look at compliance risk from that, we also have a whole separate program that looks at tactical risk.

Tools that we've deployed— my first go-to is multi-factor authentication, right? To me, that's the, the single most effective thing you can do is to deploy multi-factor authentication. And what kind of use cases would you deploy it for? Is it every login? Is it high-risk logins?

Is it VPN only? When do you— Well, you know, I don't have my visuals here and since it's on the radio, but if you guys go look at it, what I carry about, my best thing to sell to management, right? There's a little tiny book that's about 3 inches wide and about not even 5 inches high, and it's about as thick as 2¾, okay? And I've got all the— what I like, my favorite demo is I like to bring one of these people into my office and say, look, I've got all these books on hacking because I got these bookshelves with all these books on hacking and breaking into things and everything. Well, then I show them this little bitty tiny skinny book and say, look, this one right here.

It says Website Security for Dummies. Right? And inside that little tiny skinny book that says Website Security for Dummies, 2-factor authentication is mentioned not once but twice. And I like to say, well, you know, we have all these things of hacking and things that we should do. Don't you think we should at least do the things that are in this little tiny bitty book for dummies.

Yeah. Yeah.

So on that note, what parts is important? Well, what's the biggest threat vector and the biggest threat exposure, right? For healthcare, really, in my opinion, the biggest threat vector and the one I've seen catch more companies than anything else is Outlook Web Access. Sure. Right.

Email is OWA. And Outlook Web Access specifically more so than the Outlook Native Client. Why? Well, because it's easier to hack. It's easier to get to, to be untraceable, right?

It's a pain to have to install Outlook Client and then connect, and even if you have credentials, and or to install it on the phone and do all that, right? But OWA, you can hit from any random web browser, so it's very easy. Yeah, so that to me is the biggest risk vector. The next one would be, you know, public-facing websites with logins. That have it, especially nowadays people are using single sign-on.

If they sniff the password to one thing, well, they've now got the keys to all of your apps and all of your systems. Not just internal, but external cloud apps should go there. Many tools for that, many things that are out there, lots of options for multi-factor. Some of them are now offering additional services besides multi-factor. Um, and replacing MDM, right?

So one of the things that we've deployed is using the multi-factor authentication solution as an MDM replacement. So because what we found in our environment specifically, we have conflicting MDM. We have a lot of non-employed physicians that— or they may be employed somewhere else. Well, we can't push our MDM on them because they've already got somebody else's. Yeah, so we can't manage those devices.

So healthcare specifically We have to be able to prove if that device gets lost or stolen, we have to be able to prove it's encrypted and passcode protected in order to get our get-out-of-jail-free card, right? Otherwise, it's a reportable incident. If we can prove that, we do a risk assessment and it goes away. So that's what we're using for that. We can now enforce it at the gateway.

And instead of forcing to have to manually install this on these doctors who don't want you installing anything on their system anyway, let alone control their device, oh my God. You know, now we can just say, hey, we're not gonna manage your device, we're not going to force stuff on you. All it is is we're going to check it at the gateway, and if you don't meet these minimum standards, you don't get in. Yep. Until you do.

Much, much nicer. So we've done that. That was a big rollout we did. Uh, the next biggest thing that has come up now was not in my repertoire 3 years ago. Yeah, right.

But obviously now ransomware, right? Especially for healthcare. Yep. So next generation endpoint protection. Yeah, um, really a huge fan of that.

I'm not as much a fan of some of the AI solutions as I am the old, uh, kind of combination, you know, standby. So we— the, the tool we're using does a combination of whitelisting with one part of the product, a very robust whitelisting that makes it easy to manage, right? It's always been the problem with whitelisting is it's a pain to manage. Well, this makes the management of it very easy. It makes it very quick to respond to user requests.

Then we've also then paired that with both an incident response agent that goes on there and now a newer next-generation inspection part that can intercept some of those PowerShell exploits and out-of-memory. That's the new thing, is it's not just file-based attacks. Fileless attacks. Fileless attacks and non-malware attacks. So yeah, those are the 2 biggest ones, I think, bang for the buck.

And then my 3rd one would be email filtering. Sure. We block— I guess I can say that we blocked it the last quarter. I just ran the stats for my quarterly report. 280,000 malware and ransomware, mostly ransomware.

Yeah. And attacks from our email gateway. Right. We have a nice, you know, web inspection sandbox and tool that goes out there. I'm trying not to name any brand names.

I get it. I like it. I can if you want, but I'm trying not to. That's up to you. If you want to, you can.

So we're real happy with that. And like I said, 280,000 that it successfully blocked and dropped. And that's just incredible. Typically, this quarter actually went up. We've seen in the past year, we usually average about 220,000 a quarter.

And this last quarter, it went up. I think that some people are correlating it to some of the Bitcoin value increases, right? Sure. Yeah. Yeah.

So that's great. You've had a lot of good stuff you've done over the last few years. I hear those 3 things, and I think you've hit on at least 2 of the 3 things I would say. I think multi-factor, number one, absolutely, totally agree with you. Endpoint, you got to protect the heck out of it.

You know, kind of the web security is the last aspect for me, and how do we protect our resources, and it depends on what you've got. I guess I'd now ask you, looking forward, you know, your 2018 plans. What are those big initiatives that you still want to get through? What are you focused on? Well, and just OnRite, I mean, that's not all we've done.

I want to be clear. People think we have gas, right? Lots more with IDS and all that kind of stuff. But our biggest challenge and our biggest project right now is identity and access management, right? You know, I'm hopeful I'm not stealing this quote from one of the vendors, but identity is the new access perimeter.

It's not just a firewall anymore. Right? That access is all over the cloud. It's all over the place. So that's what we have to start managing better, is that identity.

And there's— it's possible that multiple IAM vendors say that, but only one IAM vendor has an employee on this podcast. So I can tell you Ping Identity says identity is the new perimeter. Really? There's another one that says something very similar. Yeah, well, they might have taken that from us.

They may have. Uh, so yeah, so your focus on just kind of getting federation and, and, uh, and better control of, of everything that way, is that, is that the focus, or what are you thinking? Federation, um, engaging single sign-on, and ideally, you know, pointing it back, yeah, um, where it can come back to our authentication sources either via AD FS or SAML or whatever it is, and where we can then also enforce the multi-factor authentication on it. So yep, absolutely, it's a great, it's a great model. It simplifies your attack surface.

Makes it so you can protect it, you know, really well in one place and get access to everything, right? It's— yeah, well, and again, it also serves you in audit. Yeah, right, because that's one of the biggest gaps I see in audit, right, is, is accounts that have been left hanging on, on many systems that may not— they may not tie into Active Directory directly, right? They may have to, to have some other management of them, and it's those, those one-offs of management where they tend to catch people. Yeah.

So any other— IAM is a great focus. Any other focuses you want to chat about for this next year-ish?

No, we recently did a big uptick in our vendor management and third-party vendor things. So that's, that's an uptick. Yeah. To do that, we went from, you know, manual Excel-based questionnaire kind of process to more of an automated tool that gives us good background, and then we go. So that has really helped streamline the process.

Very cool. And improve it. Um, well, those are our big initiatives. I mean, we're in a pretty good place, but yeah. So, so kind of changing topics on you, I think we, we know that healthcare has unique challenges.

You know, you mentioned ransomware. Everyone gets ransomware, but it's very visibly hit healthcare in the last few years. And then there's other stuff that you guys get. You know, you get systems that need to be connected in order for you to perform you know, health procedures that maybe you're running on Windows 98, or, you know, and somehow they're connected to the internet. I'd love to hear if you have stories about these things and how do you start to deal with those kind of strange requirements that you guys get.

Well, 2 things on there, I guess. Um, 2 things that I see big on the horizon. So one, obviously biomedical equipment, yeah, is a challenge. I don't think it's any secret that there's a lot of opportunities there for improvement from a lot of those biomedical vendors, right? And new ones— biomedical vendor, what's that mean?

A biomedical device. So, and that's the terminology we use. That's typically the equipment that they use on you when you go to the hospital. Okay, right. The infusion pumps, the X-ray machines, the MRI machines, the right heart— the pacemakers that go in your body.

So most people are familiar, right, with the infusion pump vulnerabilities that have been publicized, the heart pacemaker vulnerabilities were publicized last year. Now, I just heard this week, right, there's been a whole new focus on some of the imaging systems. So there was an article that came out today about how they can actually go into some of these MRI and CT scanners and actually bump up the radiation levels that are going on there, which could be incredibly damaging. Yes. Right.

To your body. Right. Yeah, yeah, yeah. Super damaging to your body. The other area I see is stories of stuff, right?

DoS attacks, denial of service attacks that are going out there. Great story, how easy it is. I think we see this whole push for the cloud, and I'm not against the cloud. I worked at Savvis. We were a cloud provider.

Cloud can be very effective if it's done right and secured properly. However, internet-based things are typically always subject to DoS and DDoS attacks. The DDoS attacks, really, there not being any prevention for those really, right? All you can do is react and mitigate and help reduce some of that, but there's no way I know of to actually truly prevent a DDoS attack. It depends on what the attack is, right?

If you get a network, you know, volumetric attack, maybe you can use a service, an Akamai or a Cloudflare type of a service, Prolexic, to defend it. You start to get to application-specific attacks, something in, you know, within 443, and it's incredibly difficult. Yeah, and it's still a reactive thing. And again, some you can prevent with tools and things. It's usually reactive, and there's still some impact.

Others are still almost impossible to defend against, some of the bandwidth consumption attacks, right? How do you defend that? Well, there are some cool routing tools. I won't go into those vendors that can do— we used to use as an ISP, but not really there at the end user or typical business level. But that gets so prevalent of how easy it is.

A great story I had from back when I was at Savvis, we actually got lucky. I mean, most times you can't even trace these. We got lucky and we traced one back. This ended up being a 14-year-old, right, who got angry at his psychic reader. He had a psychic reader that was like his girlfriend.

That's funny. And she finally cut him off when his parents' credit card ran out, and he got angry, and he's gonna show her, and he launched a denial of service attack against the psychic company, right? Well, little did he know that that it actually— this was back, I was trying to think of who the company was. This was back in like the, the late, um, '90s, and it brought down half of the, the East and Central Coast, right? You have the East Coast and half the Central stuff.

I mean, as a Savvis, as a big tier, tier 3 provider, right, it brought half, literally more than half of our connectivity down, our backbone down, right, as well as all of the others. And we were able to backtrace it and backtrace it, and it finally went back to this poor guy who was out of the country, was down in South America. But we got a hold of the FBI. They actually went back and found this guy, and he was right, of course, just a kid doing it from a connection in his mom's basement. Right?

But that shows you how damaging that is. And it was just an unusual— not quite like the ping of death, But it was a very similar UDP-type attack that was amplified, right? It was an amplified attack that he did it and brought in all these other amplified, and it just DDoSed the whole thing out. But it was kind of a cool one that we actually— one of the few cases, right, we were actually able to trace him down and find him and track him. Um, that's great.

So, you know, looking at the— let's— different topic. Talk to me over the last, you know, 6 years, or if you want to go back to previous job, Do you have any stories of projects you've gone through that you're really proud of? Or, you know, also maybe a project that didn't go well that you learned from and maybe some listeners can learn from as well?

Projects that went well. Well, I was really proud of our multi-factor authentication rollout. That went well. We actually just completed an epic failover. Let's talk about the MFA.

How did you make— why did it go well? What did you do that, you know, not every project goes well. This one did. So, why? Well, when we rolled it out, we initially brought it in and we did a pilot.

And one of the benefits of the tool we used is it allowed us to roll it out gradually. So, we could roll it out like on a volunteer basis where once we sign people up, it would force them to use the 2-factor. But other people would still be allowed in without it. Sure. So, we were able to kind of roll that out gradually pretty quickly then to a large number of users.

And then within, I would say, a month from the time we got the initial pilot completed to then deciding to roll it out there, but within a month we'd rolled it out to 30,000 users. Yeah. And how do your doctors like it? Uh, the doctors like it better than some of the other methods they've had. I know generally doctors are the tough part, right?

Yeah, it's still an extra click for them, right? So they don't like that click. But one of the benefits is the caching. We actually let them cache it for 30 days like they do at Google. So, yeah, that helped tremendously getting that sell-in where it's not every single day, every single time, 100 clicks a day.

How many doctors do you guys have? We have— I want to say, I think we have about 4,000 unemployed physicians. Right, that is, that's a whole nother challenge, right? Because they're not employees, you can't enforce everything on them, but they're contracted. And I don't want to say somewhere around maybe 6,000 employed.

So call it 10,000 doctors. Yeah. Is it like you have 10,000 bosses? Is that what that's like?

A little bit sometimes? Yes, sometimes it is. Yeah, that's what I hear about working with doctors. So what's the— what about anything you've learned from it? And on that note, that we've had some of them that are really— that love to see us securing things and making and protecting that information.

We also have a few that are vehemently opposed, right? So anything you— any projects you've gone through that didn't go well that you're willing to share with us? Of course not. Everything's gone well. All right.

You know, we actually had our We had— and again, I won't name vendor names, but we had an identity and access management program and project that did not go well. And we actually documented it, kicked the vendor out. We spent 6 months with them. And basically, they couldn't— didn't complete any of the deliverables that were supposed to get done in that time frame. And we asked them to leave.

Luckily, we had really good documentation and we did not pay them for that. Engagement and went with a different vendor and are very happy with the second one we chose but it's a prime example, right? We tried to bow to some of the wishes of management and the first time around, we picked the cheaper vendor, right? Oh, go with the cheaper, save money, save money and we went with the cheaper one and we wasted 6 months of our time, almost 8 months of our time and then had all this legal hassle afterwards and got zero value out of it, right? That's a pretty big cost to the business, actually ended up being more cost than what it would have been to go with the good vendor to begin with.

Looking at the— we're running a little bit short on time here. I'll ask you a couple questions about the community and folks who are looking to get into the community. We have quite a few folks who listen who are just getting out of programs now, looking to maybe get their first full-time job in security. Do you have any guidance for them about what skills they should be working on and and how they want to go into those interviews? I'm a big believer on when I bring somebody new in, right, I want somebody that's enthusiastic, that is into it, that has some tactical ability, right?

There's lots of things people can do to learn at home, to come in and offer me something to do, right? You can get Snort and learn IDS at home for free. You can learn firewalls for free. You can get Snort down— I mean Splunk downloaded for free and learn logging and reporting and dashboarding. I want— when I go to hire somebody, I don't just want a degree.

That's great background and good theory, but I want people that can actually do something for me on the job. Go get some of that hands-on experience and bring it in. Other things, training, hands-on tactical training. SANS, to me, SANS is hands down some of the best training out there. I love their programs.

They're expensive, though. How do you afford all these SANS trainings? Oh my God. Well, this was back in the day when I took them. All right.

They were, they were not even $2,000 back then. I think when I was buying them, they were like— I think it's like $6,000 or $7,000 for a week-long training now. Oh, yeah, yeah, yeah. The last one I looked at for one of my staff was like $6,000. Yeah.

If you work at Ping, let's not talk about SANS. Let's talk about something else. But they are so— it is such good product, right? Especially some of those early basics, right? Their GSAC and some of the early ones and then some of the specialty programs.

They've got one of the best incident response forensics programs out there, right? I'll plug the instructor, Rob Lee, ex-FBI guy. He is just unbelievable. To me, probably one of the leading experts in that field. It was just incredible learning under him.

There's other good stuff out there too, right? There's other good forensic data providers and gatherers out there. And they provide training that's also good. That's just my favorite. Okay.

But so, you know, get some other— get some training, right? Don't— and don't have to— you mentioned the cost. It doesn't always have to be expensive. Get some doggone books and learn something yourself, right? You know, when I was growing up in this environment and stuff, right, I had 15 computers in my basement, right?

I ran a small ISP out of my basement running 10 web servers, 5 FTP servers, 3 or 4 different email servers. You know, that's how you gain experience if you're just breaking into the business, is start doing it. Yeah. So flipping around a little bit, you know, I think that's great advice for new folks. What about for people who are currently, you know, CISOs, other people who do your job?

What do you think we're doing wrong? What's the one thing you see consistently? Yeah, we gotta get better at this. I think we all need to gang up and and go into senior leadership and get us reporting to the CEO. Why is that?

I think that there's often resistance and conflict of interest there, right, between the CIO in many companies that I see, or depending on who else they work for, right? Sometimes they're reporting under legal or under privacy group or wherever. But security is at the point now where it needs to be reporting to the CEO and not be threatened by those other groups or be held back. It needs to be at that— to have that equal say at the table and not just be able to be overshadowed because of cost or because of, oh, that's going to delay our rollout. It was one of the things when the big Obamacare stuff rolled out.

They're pushing, pushing, pushing, and they rolled out garbage that the security people told them not to. I see that same thing happening in company after company. And it's going to continue happening until we are not put into those people and we can actually be at that level. And hopefully, right, that the security people don't take their job as being the— trying to be politically correct— the security super strict people.

You know, our job is to empower the business, is to embrace that and provide them ways to do things, not to sit there and say no. Right? This thing is say, yes, but. Yes, you can do that, but you need to do this and this and this to keep it secure. And we need to be at a level where we can do that to continue enabling the business.

Otherwise, we're going to keep running into those blocks. We roll something out, oh my god, we got to pull it back because it was hacked. We rolled something out, oh my god, here's all the public branding damage that was done because it got hacked. You know, people, once they start getting hacked like that and taken advantage of, they stop trusting. And we've got to rebuild and regain that trust.

And the only way to do it is to let the people that have that education and training have that equal say at the table. Fair enough.

Anything else you'd like to share with the audience out here, those who are listening? Did we get everything? Stay secure. Stay secure. And I think everyone out there wants to know, what have you analyzed me?

What have you determined over the last 45 minutes? What I've determined so far, Rob, is that you have a very inquisitive mind, a very driving personality. Yeah. However, there's these 2 flaws. Okay, I'm listening.

I can't discuss them. Alright, well, I guess maybe after I pay the bill, that's when I get to know the flaws. I get it. Alright. Well, Kris, thanks so much for your time.

Hopefully we'll catch up with you soon and hear how things are changing and we'll keep talking in the future. Thanks, Rob. I enjoyed it. Have a good one. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.

Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, remember, Colorado Colorado equals security.

Back to all episodes