Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Hello and welcome to Colorado Equals Security. This is episode 58 for March 12th, and this is the newscast. I am here with Drew, Drew Labbo.
Thanks for having me again, Alex. Robb is off again on an amazing adventure, so we've got a fill-in again. You know, I know everybody's thinking, why is Robb always the one that's off doing something else? Well, you'll be happy to know that I do get to take vacation next week, and we'll have another co-host for you. But for the time being, it's me and Drew, so you get to hear us this week.
So we'll go ahead and jump into the news. A couple announcements first. First, as you guys know, last week we announced our Patreon. So thank you. We had a couple people sign up this week for the Patreon support.
Actually, we had 2 at the $10 a month level, which is awesome. So those folks are going to get a t-shirt. And as part of that, we have to give them recognition on the show. So I want to give a quick shout out to Chris Abbey and to Andre Gaeta. Thank you very much for the support.
And if you guys go out to our Patreon, we would love to get additional support to help support the podcast. Also, we have our Slack channel, so go out and check that out. Some great conversations going on there. You can sign up for our newsletter on the website. Please subscribe to the podcast on iTunes or Google Play, and then make sure to review us and hopefully give us good ratings on those.
So Drew, let's jump into the news. Let's do this. First, we've got some great news this week for all of you that have bought wine baskets or, you know, bottles of booze at your local PTA auctions. Well, now that's no longer illegal, so congratulations, you guys are in the clear. And let's see some cybersecurity events with some Straining Hands whiskey, right, for a prize as an example.
Let's get into this. Exactly. Yeah. So previously, I'm not sure this is something that people would have really thought of, but auctioning off alcohol at a charity event was illegal. So one of our great legislators thought, hey, you know what, that's kind of silly.
You shouldn't really have to have a liquor license to auction something off, alcohol off at a charity event. So they put through a law and Governor Hickenlooper signed that at the beginning of the month, so everyone's free and clear now. Good stuff. And you know, when I think about why is this pertinent to cybersecurity, sometimes I think being in Security Fuel might make us want to drink heavily. Exactly, exactly.
Next, Amazon had an announcement this week that they're gonna open a physical bookstore in Colorado. So it looks like they're gonna open one location to start at Park Meadows. I guess this is just the next step in Amazon taking over the world. Yes, Amazon Skynet. Yeah, and so, you know, I have heard, I think you said, Drew, that they are looking at this, you know, sort of as market research, not really looking to, you know, put a big footprint in terms of physical locations.
But again, they got to get their data so they can figure out how to take over the world. Absolutely. Fun stuff. Go Amazon. And we'll see if they come to Denver, right, for the headquarters.
I heard it's a long shot from what I've read, but who knows? You never can tell. Uh, next we have Niche ranking Colorado's top 20 high schools for STEM. Yeah, so, uh, you know, we talk about that a lot, uh, on the podcast, trying to make sure that, you know, we're pushing cybersecurity into schools and, you know, along with all the other STEM education that is out there. So the Business Journal this week had a ranking of the top 20 STEM schools, high schools in Colorado.
It included Kent Denver, Fairview High School, Cherry Creek. I believe Arapahoe was on there. Vail Mountain School, if you want to live in the mountains. Devlin Junior and Senior High in Jefferson County. Lots of good ones on there.
So check that out. And, you know, if you want your kid to be in a STEM career, these might be good places to look at. Yeah, I was surprised Warren Tech is not on this list. I've heard so much about that living out in Jefferson County. Um, but it's nice to see these— this ranking and that someone is actually paying attention and thinking about this.
Exactly. And then next, along those same lines, we just had the 28th Annual Colorado Science Bowl. So this is a high school competition where a bunch of high schools get together, answer a bunch of questions around science, and this year Fort Collins High School was the winner. And, you know, we just had this previous story that talked about STEM schools and the best ones out there. Well, strangely enough, Fort Collins High School wasn't on there.
So I guess, you know, you can still get a good STEM education even if you're not at the top 20. Yeah, it is a little bit curious it's not on that list. You know, it's interesting when you think about the state of Colorado, we have a bigger security community than anyone might expect, I think, if you look at the entire United States. And I was thinking about this when I read this article. We have— if you look at Colorado and the history here of science, we have NIST, Lockheed Martin, National Renewable Energy Laboratory, National Weather Service Center, Air Force Academy down in Colorado Springs, Colorado School of Mines.
And I started to think Think about the engineering, the mechanical engineering way back in the day, right? We were a leader there, right, for our minds. So it's just interesting to look at why are we such a science leader? Why are we such a great security community? Seems like we have a history here, right?
Yeah, for sure. So pretty neat to see. Let's wish Fort Collins High School luck. They're actually going to be going to Washington, D.C. April 26th through 30th to compete at the National Science Bowl representing Colorado. So really cool and congratulations.
Nice. That should be great. Uh, next, there was an article this week from Red Canary, uh, Cryptocurrency Trends: Will Ransomware Be Overtaken by Miners? So basically, um, some discussion here around, you know, what path criminals will take, cybercriminals, uh, to essentially to make their money, right? So we've seen giant amounts of ransomware over the past few years.
But it's starting to creep up a little bit. Instead of these folks trying to infect your site with ransomware to get some money out of you, but instead putting cryptocurrency miners on your site so that you could— they can use your, your CPU to make money instead. Yeah, it's a pretty interesting article. Not something I would have thought about. And are we giving people new ideas, right, as we just— we talk about stuff like this?
Maybe. But I noticed they talked about how bots are built for this, right? Let's, let's take over a host, let's utilize it. I start to wonder if this starts to happen and we try to make a counterplay, are we going to start looking at how much power consumption is coming out of CPUs, right? Who knows?
It's like playing whack-a-mole trying to stay ahead of these guys. Yeah, so I guess we will just have to see. Next, Webroot, they announced that they have 4 years of double-digit revenue growth. Anyone who has listened to the podcast for a while, just about every quarter, uh, we have had a story that said, uh, you know, Webroot has another quarter of double-digit growth. Well, it looks like they've had that for 4 years straight now, uh, so congratulations to them.
Uh, you know, not a, you know, huge amount of news in this particular story, um, but this is, you know, just one where Webroot continues to grow. So I, I think that's good stuff. Love to see Colorado companies doing well. Next, we have an announcement from Automox. They've secured $2 million in funding, and they do patch management, vulnerability management.
And I think it's an interesting space. I've managed security programs and tried to patch systems. It's like bailing water out of a sinking ship sometimes, right? And then as you patch, are you going to cause problems? So anything in this space to help a little bit, I think is great and be interesting to look at their model and what they're going to bring to the table in this space that's been around a long time.
Yeah, and I actually got a chance this week to sit down with, uh, Jay Prassel, who's the CEO over there at Automox, to do an interview. So he's going to be on an upcoming show, and he actually— he talked about this funding. It's interesting, they, they're not necessarily going too big yet, you know, $2 million of funding. And a lot of this was, um, you know, getting some of, uh, these, these participants and, and visionaries from different places on board. Ron Gula, Art Coviello, Tim Belcher, Roger Thornton, big names sort of in the security industry, you know, chipping in to help bump up Automox and, you know, really showing that this is a problem that needs to be solved.
So good stuff there. And then finally, there's an announcement this week from GTRI and Route 9B. I don't know if we've talked about GTRI on the show before, but, you know, they're a a local reseller service provider, and they're partnering with Route 9B, who we have definitely talked about on the, the show before. So they're partnering to deliver secure cloud solutions. So it looks like, you know, Route 9B, who does security services, MSS kind of work, you know, managed SOC, is going to be, you know, partnering with GTRI to help secure some of those cloud services that they, that they provide.
So that's pretty cool. Uh, so that is it for the news for this week. So why don't we jump over and talk about our trivia? So last week our trivia question was, what is the top security company protecting Colorado's cannabis stash? So we actually— we didn't get a correct answer, but we did have someone who got really close and had some other answers that probably could have been correct answers.
So, uh, the correct answer that we had was Blue Line Protection Group. Um, so they are a protection service for the cannabis industry. We got a couple answers from someone named James W. James did not provide his last name. I, I guess I can understand if we're asking a question about, uh, about marijuana, maybe, maybe you don't want to provide your whole name. Uh, but that's, uh, that's good anyway.
Congratulations, James. Uh, we'll get you in contact with Andre and get you your prize for winning this week's trivia. So moving on to the trivia question for this week, this one is going to be a little bit different, and we're going back to the questions about the podcast. So the question is, what was the best interview from last year and why? So this one is totally subjective.
Totally on you guys to give us some good answers. You know, what is one interview that you liked and why was it the best? And we'll take a look at all those submissions and figure out which one we like the best. Excellent. Next, we're going to look at the upcoming events for the next couple weeks in Colorado.
So we have the ISSA Denver March meetings, March 13th and 14th. We've got the Sea Level at Mile High on the 15th. This is again the Great networking opportunity for executives with the CTA. It's one of their big networking events of the year. Next, we have ISACA's March meeting.
They're doing combat fraud and corruption with data analytics as their subject for that meeting. Also on the 15th, SecureSet has their Cybersecurity Expert Series with Chris Roberts of Accalvio. That should be very interesting. I always like to hear Chris talk. Indeed.
ISC² Denver, For those of you that know security certifications, CISSP is one of theirs. They're having their March meeting, and that is going to be on March 15th. ISACA, we got a note this week from the folks that are doing the certification training for ISACA, and their certification training is coming up starting on the 17th. So, if you are an ISACA member, and you are looking to get a CISA, a CISM or a CRISC certification. Being a chapter member, you get access to this free certification training.
I am CISM certified, and when I did that, I went through their, their security training for the, for the certification. Great training. It's taught by ISACA chapter members. They do this all in-house. You get together on Saturdays for, for several months and talk through the material.
Really, really helpful. So If you're thinking about doing one of those certifications and you're an ISACA member, it's free. If you're not, maybe it's a good idea to sign up to be an ISACA member. Next, we have the Lady Coders on March 20th. They're doing a meeting centered around personal branding, branding yourself for a pivot, which I think that's great, right?
In the security community, a lot of times we might want to change careers or do something different. So that should be very interesting. And I love to see all the women that are getting together doing these these events. Yeah, that's awesome. In Denver, it's really neat.
CSA is also having a meeting on the 20th. This is their March meeting. Next we have the DENSEC North meetup on March 21st. Yeah, and actually I think we need to change that title. I think we mentioned this last week too.
DENSEC is sort of changing up a little bit. I think instead of doing a north and south meeting, they're only gonna do a single monthly meeting. But it is on the 21st, and I think you can still check out their Twitter to see where that's going to be. I think they're going to be a little more central. ISSA Denver is doing a happy hour on the 23rd of March.
And that looks like it's at the Lila B Lounge down in Greenwood Village. Exciting. And then our last event for the next 2 weeks, SecureSet is doing a capture the flag cybersecurity hackathon also on the 23rd. So exciting stuff. So that's all for events.
Let's go ahead and jump over into our jobs. First on the list, Coalfire is looking for a director in their healthcare practice. Cognizant is also looking for a security manager for corporate security focused on GRC, governance, risk, and compliance. Prologis is looking for an IT governance, risk, and compliance manager. Coalfire also has this position open as a principal in their service organization controls practice or SOC.
Yeah, so if you want to be someone that goes out and does SOC reports, probably the most exciting thing on earth, you can do that. Staples, they are looking for a senior application security engineer. ProtectWise is seeking a DevOps engineer. CenturyLink is looking for an information security engineer 1. Direct Defense has a position open for LogRhythm security analyst.
And essentially, right, they didn't just put SIEM analyst, they specifically said they want LogRhythm. So I like it. Go LogRhythm! Love Colorado company and a great ISSA Denver sponsor. Pearson is looking for a senior cloud security engineer around DevSecOps.
And finally, we have LenderLive looking for an information security analyst. Awesome. And that is it for the jobs this week. And so that is it for the newscast. Coming up, We have an interview this week.
I sat down with James Johnson, who is the president of the ISSA Denver chapter, sort of coincidentally since Drew is here and James is the vice president of the ISSA Denver chapter. I'm the vice— yeah, I'm the vice president. James is the president. So, you know, got to talk to James a little bit about ISSA Denver, you know, what he's been up to, what the chapter's been up to. So look forward for an exciting interview there.
Excellent. Well, awesome. Thanks again, Drew, for filling in, and let's go listen to that interview. Everyone do the snow dance. Let's get some more snow for the rest of the ski season here.
There you go. Thanks, and we'll talk to everybody next week. This is Michael Glenn, Vice President of Security at CableLabs. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals. So this is Colorado Equal Security, and this is our feature interview.
And today I have the pleasure of talking with James Johnson. James, welcome. Thank you, Alex. We really appreciate being with you today. Awesome.
And so James is the current president of the ISSA Denver chapter, largest ISSA chapter in the world. Gotta get that plug in there. And I've known James for a number of years now, back to when I was on the ISSA board. Absolutely, that goes back to 2011, 2010. Something like that, something like that.
So James, I'm sure many people out there know you, but why don't we give an introduction to who you are, what you've done, how you got to where you are today. So I came back, I came from a technical background, electrical engineering. I majored in information systems and digital controls. And I came out of school, I worked in robotics, and I automated manufacturing plants, and then had the opportunity to move to a Department of Energy facility, which was definitely high security. So I started getting indoctrinated into security, working on nuclear reactors, specialty nuclear chemical facilities, and so security was everything.
Then I moved over into the IT field, and when I was the manager of end-user computing, the executive vice president called me and said, James, I need you to take a temporary 6-month assignment in information security. This would have been in early 2001. It was supposed to be 6 months, and he said, look, we've got a million-dollar fine from the Department of Energy. We have congressional oversight. You've got to go solve these problems.
And I knew the people in information security, had great respect for them, went over, and in 6 months we pretty much had things going fairly well. So, and then the next thing that happened was 9/11, and I was sitting in the security operations center when 9/11 happened. So we were watching it on the screens, you know, what's, what's happening here, what are we got to do. So what was a 6-month temporary assignment became permanent very quickly, and I was happy about that because I was really enjoying the work in information security. The corporate company called from Boise, Idaho and said, we want you to come and start our corporate information security program.
So that allowed me to move from the government sector over to the private sector, at the same time still overseeing government sector work. So was able to start that program for a Fortune 500 company. And this is really where I became involved in ISSA. We had the largest corporation there in Boise. We had several of us as members of ISSA, and we would help put on the ISSA Security Conference in our facility.
What company was this? This was, at the time, was Washington Group International. Okay. And so, of course, it's an engineering and construction company and was bought out multiple times. And that's how I ended up in Denver in 2010.
And so it wasn't long and I was at an ISSA event, got to meet you, and later on got to meet Robb. So just really have enjoyed being part of the security community here in Denver and really have enjoyed watching it really explode over the last several years. So I've had a great opportunity of working in Fortune 500 companies of the government and the private sector. And then in 2015, had the opportunity to do consulting work and have really enjoyed that. So it really helped me get into multiple sectors and to understand a lot of the different challenges.
So overall, I've really enjoyed information security. So I wonder if you could talk for a minute about the differences that you see from the government side to the private sector side, because I think, you know, it's interesting that the couple markets that we have here in Colorado— so, you know, you've got You know, the greater Denver area, which is almost exclusively, you know, private sector companies. There is some government work up here. And then you've got, you know, Colorado Springs, which is almost exclusively government and government contracting work for security. You know, as we go through and we do the, the jobs every week, um, you know, I usually pull from Metro Denver and things like that.
But, you know, sometimes I'll look in Colorado Springs and you look at it, it's the jobs are completely different. So I wonder if, you know, maybe you can comment on that. Sure. Well, when I was in the government sector, I did classified work, and so all of that was very, very rigid in terms of— it wasn't a standard, it was a government mandate of exactly what you had to do. So your program was measured exactly by what was specified as far as requirements.
And then when we looked at our unclassified side At the time, the internet really wasn't that well known, and as that came on, as wireless came on, then all of a sudden people were like, wait a minute, the risk has totally changed. So what kind of standards should we have? And there really weren't standards. And so that's where NIST 800 series started coming in. We had a group that made comments on those and helped get those where they are today.
But when I look at that, I almost say, when you went over to the private sector, what standards? So you've got responsibilities, you know you need security, but what is your standard? Someone may not be telling you what standard you have to meet, so you have to decide what standard is right for that organization and apply that standard. Of course, there's PCI DSS that's mandated in in certain areas and more standards have come out. But the biggest difference to me was government was very structured in terms of what you had to meet and then the private sector was very loose and you really had to define your program.
And in a way, to me, the private sector was more of a challenge because you had to do that analysis, you had to do that risk assessment and that gap analysis. To determine what you needed to do. Well, I'm sure obviously you had less flexibility too, right? So it's, you know, whether it made sense or not, whether it was focusing on the risks that you had, you had to do these exact same things. Exactly, exactly.
And then the government started realizing, hey, just because you have a standard doesn't mean you're secure, right? And then they started down the path of let's look at this from a risk approach. And to me, that's really the way security should be done, right? Look at the organization, see where the risks are, and do what's right for the organization. Completely agree.
Completely agree. All right, so you, you were in Boise, you moved down here.
What is it that you're— besides being the ISSA president, what is it that you're up to today? I am currently the cybersecurity program manager out at DIA, Denver International Airport, and there I really bridge the project management organization and the CISO's organization. So I'm responsible overall for all the cybersecurity projects happening at the airport. So it's been a really exciting challenge. It's a little different than what I've done.
I think 61 million passengers came through the airport last year. Exactly. And so you're providing services to them. And that's a different view for me. But it's really been a great challenge.
And I've really enjoyed working with Tim Coogan, the CISO there, who has a really great vision for Denver International Airport. Yeah, I like Tim a lot. I'm sure you guys are doing great stuff out there. Sure. So, so you're here, you got involved with the ISSA chapter.
You know, along the way, we got you involved on the ISSA board. And, you know, lo and behold, you know, people kept stepping back and you stepped forward to be president. So congratulations on that. Thank you. Thank you.
So I don't know if maybe you want to tell us a little bit about the ISSA chapter in Denver. You know, we, we do— sure. And I talk about it a fair amount, but maybe I'll get your perspective on that. Well, let me talk a little bit about how, you know, I arrived to where I am today with ISSA. So I got into Denver, really busy, a lot of things happening, and I really didn't go to a chapter meeting.
And then I was like, you know, I've just got to get involved. So I go, I really like the organization and the leadership with you, and then to Robb, and I'm going, hey, this is really a great opportunity. Got involved as the recording secretary. That was somewhat of a— you didn't have to know everything was going on, but you were learning everything that was occurring. And then had the opportunity to be the volunteer coordinator.
So I'm now really getting a great opportunity to talk to all these different people, finding out what their experiences are, and really enjoyed that. And then the opportunity came along to be the president of the organization, and I've really enjoyed that. And being the president of the organization, I have a duty today to ask the president of the Denver ISSA With unanimous recommendation from the Board of Directors and in coordination with Denver ISACA, on behalf of the Greater Denver Area Security Community, we present to Alex Wood and Rob Rick recognition for 1 year of Colorado Equal Security dedicated service, solidifying Colorado as the premier location for security companies and talent in the world and helping to further the global security cause both locally and internationally. So I feel that we can speak for the overall community here in Denver. You and Robb have done an awesome job with Colorado Equal Security.
And I think February 6th, 2017 was your first podcast. Yep. And we're here at a year. Can you believe it's been a year? It is hard to believe, and thank you very much is the first thing that I'll say.
For those people that are listening, this was not a setup. We had already planned to have James on for the interview, and, you know, when he showed up today, I got this great surprise. So we really appreciate the award. It's been fun. You know, we're working hard to help highlight Colorado and the stuff that we're doing around here for information security, so much appreciated and And thanks for all that you're doing as well.
And from an ISSA standpoint, I can tell you your website is really a blessing. It really helps us in that— so in the past when we would schedule events, it was very hard for us to know what was going on in the community. And we would schedule an event and just schedule right on top of someone else. So there would be, well, I've got to choose whether I'm going to this event or the other event. We have our own internal calendar, but that doesn't do us a lot of good other than we don't schedule over ourselves.
Now we go to the Colorado Equal Security website, bring up the calendar, I can see every event going on. And this is totally awesome because I can go, oh, we're not going to have it that day, let's move it out a week and let's plan around here. So it helps us distribute those opportunities, you know, when people can't attend different events. And that's just one one area that you're helping the community in overall. And another way is I have people call and, hey, I'm new to the Denver area, I'm just moving in, I'm in IT security, who am I supposed to talk to?
How do I know who the organizations— how do I know what's going on? Or I might have someone that's just getting out of school and saying, hey, I really want an information security career, what do I do? And I tell them about ISSA, but I say, look, you've got to go to this Colorado Equal Security. I said, you need to understand all these organizations going on and listen to these podcasts and know who you're interviewing with potentially before you go. So it's— I think overall it's just totally been great for the community overall.
Well, good. I'm glad, you know, that those— the things that you talked about were obviously some of our goals that we were trying to do. So I'm glad to hear that it's working. So I'm gonna deflect the focus on me back to you. The ISSA Denver chapter, they do a lot of things.
One of the things that I think people might not be as aware of is some of the stuff that's happened recently, especially with the special interest groups. So I wonder if maybe you talk a little bit about the special interest groups that you guys have and what they are and how they operate. Yeah, so special interest groups, some people may refer to them as industry verticals. That's easier for some people to understand. But as a chapter, we got to looking and saying, hey, we have a dinner meeting, we meet for an hour to 2 hours, and we cover a topic.
But what our members were telling us is we really want to delve into some topics. We said, well, how do you do this? And the idea was, let's have these special interest groups, let's let them meet however long they want, maybe 4 hours or so, and they can delve into topics. The first one that we launched was healthcare, and that was a great success. We had visitors like the Office of Civil Rights lawyer come in and talk about HIPAA.
So she is personally managing HIPAA violations, so we're hearing firsthand what is occurring there. So we delve into topics such as that, and we try try to make them fun and try to give a lot of flexibility on where those are done. We have the Women in Security organization, which was a huge success. I think the inaugural meeting was over 100 individuals there, and they're doing an awesome job with that program and bringing women into the field and really being an encouragement. So really kudos to that group and what they're doing.
We also have a government SIG, and so government is a wide net, right? It's been broadcast very wide. And so what we expect is going to happen with the government SIG is as we bring these people together, they're going to say, hey, maybe we want one that's focused in on education, maybe we want one that's focused in city-county government. So we've got a great group started there. We've got a finance group, and I went to a couple of their meetings and doing a great— GDPR, I didn't even know how to spell GDPR.
I went to a finance SIG, and I'm not an expert on GDPR, but I sure know what it is, and I know that there's lots of implications that I have to look out for. So that, you know, that's just an example of some of the things that you can learn. And then we've also launched a oil and gas as well. There, I think, I forget how, it's tens of thousands of people that are involved in the oil and gas community here in Denver. I didn't realize it was so large, and so we're looking for that one to take off as well.
Yeah, and you know, I had a previous job working in oil and gas, and before I had that job, I didn't realize how big it was in Denver, you know, before the drop in oil prices, I heard a statistic that something like 70% of the office space in downtown Denver was oil and gas companies. Yeah, which is it. I mean, I don't know if that was the true number or not, but I mean, it's just, it's crazy how many oil and gas companies. Well, I do have a true number associated with the impact when oil prices did drop so low. About 40,000 jobs in the Denver area were impacted.
Of course, we've totally recovered from that with, with everything else going on. But yeah, we have a large oil and gas presence here in Denver. Yeah, well, it's good to hear that's going on. So is that one— has that one kicked off, or that one's gonna be coming soon? It's very close.
I— yeah, it's a good question. I don't think they've had their first meeting, but it's very, very close. So if anybody out there has a question about a special interest group or wants to have more information, they can reach out to me. Just go to denver.issa.org and just send it to president@denver.issa, and I'll be glad to respond to you. Awesome.
Typically I respond within 24 hours, so give me a few hours to get to it. But we try to be responsive to those questions and try to help people. I know how that goes. And that brings up a great point. ISSA, like some of the other organizations in town, is a nonprofit.
It's run by all volunteers. So I mean, I think that that is one of the things that makes it so great. You have other organizations that are, you know, commercial entities where, you know, they're, they're doing this, you know, maybe to help the community but also to get a, get a buck. And, you know, people like ISSA, just, you're in it for the community? Right.
So we have about 20 individuals associated with our board of directors now. And like you say, we are all volunteers. And, you know, our whole focus is developing information systems security professionals. And our secondary is to help further the information security goal in community in terms of, you know, advancing the profession and how well we do our jobs. So that's our focus.
That's why we have meetings, we have educational opportunities. I like to see, you know, some people that really want to get into speaking, give them opportunity to get up and speak in front of the crowd. You know, you're amongst friends here, and so whatever we can do to help, whether it's educate or whether give them an opportunity, and volunteering— volunteering is a great opportunity to expand your horizons and get to know people and contacts. And it— I think volunteering is really, really awesome in terms of advancing one career if they're interested in it. That's not why you're volunteering, that's just one of the, you know, things that happen when you do.
Yeah, and I completely agree with that. Um, you know, I got into volunteering with the ISSA because I wanted to give back, because I wanted to be in an involved with the community, but it really has helped my career just getting to know people, getting involved with the community. I really think that it definitely gives back as much or more than you put in. Yeah, and the networking. If you're even in a technical job and you've got a security problem, if you've been to these events, if you've been networking with people, there's probably someone that's already run across that problem.
Here's the one thing that really attracted me to the information security profession more so than any other area of IT or either in process control. If I've got a security problem, even if you're one of my competitors, even if you're half a world away, you're willing to help me with that problem. We are all after the same goal, and that is protecting the information and and the assets and make sure those that want to harm us don't make it in. And so I was just astounded the first time. I mean, I was sitting in a room with competitors and we were all trying to solve this problem.
It benefited us all. As a matter of fact, it went far greater than just benefiting those that were in the room. It benefited everyone else that were able to apply those solutions. Really like information security for that. So if someone wants to get involved with ISSA, we talked about some new stuff that you're doing, but what about some of the traditional stuff that you're doing?
Do you have chapter meetings, volunteer opportunities? What's some more information on that? Oh sure. Well, first of all, speakers. We love to have a wide variety of speakers, and whether you want to speak on something very technical or maybe something more at the management level or administrative level, we would welcome that.
We are always looking for people to help with chapter meetings. We have happy hours, and we just got 2 of those scheduled very recently, so we got a lot of energy in that area. But, you know, someone could just say, hey, I want to put this meeting on. I'm going to take responsibility for getting the location, getting whomever is going to speak, or what that structure is going going to be. We definitely have opportunities like volunteer coordinator.
I'm the president, but I'm still doing volunteer coordination. So when that person comes along that really wants to get to meet individuals coming in and learn more about them and learn more about the chapter, that's a good opportunity. We're always looking for sponsorships. So someone that may know a lot of different companies or a lot of people may want to help us with sponsorships. So however much they want to be involved— oh, we've got Rocky Mountain Information Security Conference coming up in May, right?
Yeah, can't forget about that. Exactly. What's that, 8th through the 10th? So that's something that you could get involved in and contact us, and we can put you in contact with the right people there to volunteer, whether you've got 4 hours or whether you've got 8 hours or If you're really looking to volunteer and do something long-term, we have lots of opportunities. And if somebody wants to come and maybe they're not ready to volunteer yet, they just want to come and learn, so you've got the monthly chapter meetings.
Correct. And so those are the, the second Wednesday of the month? Well, second Tuesday and second Wednesday because we now have 3 chapter meetings a month. We have lunch in Boulder, we have dinner in downtown, and then we have the next day's lunch in the DTC area. So that's the 2nd Tuesday and Wednesday of the month, except for May, which is the Rocky Mountain Information Security Conference.
But go out to our website, look, and if you've got any questions, feel free to email me. And I enjoy talking with people and getting to know them, so Don't hesitate to ask or say, hey, I've got an idea here. And, you know, special interest groups was an idea. Yep. And it's a huge success, and I've personally gotten a lot out of it.
I've talked to so many people that have gotten so much out of this. Yeah, I mean, I think also, you know, ISSA in Denver has matured to the point where, you know, if someone has a good idea, you know, they can come to you guys with that and, you know, you can help nurture that idea and kind of get it going. The greatest example I think of that is the Women in Security Special Interest Group. So I know Sarah Avery, for a long time, had had this idea that she wanted to start a Women in Security group but just hadn't figured out the best way to do it or the right way to get the momentum going. And, you know, sort of teamed up with ISSA and started the Women in Security Special Interest Group, and it's just— it's been incredible.
Oh, absolutely. And another area that we really are encouraging people to volunteer. We have a lot of experts out there that truly are experts in particular areas, and we want that knowledge to be transferred to other members. So we do put training classes on throughout the year. So if someone's out there and they say, hey, I really would like to help educate in these particular areas, then please contact us and let's have that discussion.
And we'll put something together, work with you, and help you get your idea developed, and we'll get everything scheduled and make that possible. But some of the best training classes I've been to is not someone who does training commercially. It is that individual that's been in the trenches, they've done it, they've got the solutions. Now here's what I've learned and let me show you. And I think those type of trainings go over really, really well.
Yeah, and you guys have had some great trainings in the past, and I love that full-day training avenue is out there too. I did one a couple years ago on NIST Cybersecurity Framework for the chapter. We've had Jim Manico, who's an internationally known application security trainer, come in and do one on application security. There have been all kinds of folks that have come in to do that stuff. So it's really, again, a great benefit.
Well, I went to your Cybersecurity Framework presentation that you did, or that educational session, and at the time I wasn't using CSF. And 9 months later, I've got to do CSF. What I'm going to do, I'm going to call Alex. Alex, you remember those spreadsheets that you had? I don't think I've got copies, but would you mind if I, you know, borrow those from you?
And you're like, yeah, if you can use those, if that can— and just having that as a start made the job so much easier. And, you know, when you start out with that, then the end product is so much better. And that benefits everyone, right? We, we cut down on the level of activity that those that might want to hurt us can do. So yeah, and I think, you know, one of the other lesser-known things that the chapter does is the mentoring program too?
So mentoring program is very good. Elizabeth Bublitz is running that program now, and she's doing an excellent job. So if you think you're looking for a mentor, or if you want to be a mentee, then contact us. We'll get you in contact. But it's a great program, whether you're on the technical side or if you're aspiring to be the next CISO.
We can get you paired up with someone and give you an opportunity to develop those relationships. And that's also occurred for the Women in Security group as well. They've really been pairing people very well and getting some good mentor-mentee relationships. And that's a program we expect to continue well into the future. That's awesome.
And I know I've been participating in that, have some great people that I've been mentoring as part of the ISSA mentor program, so that's been a lot of fun.
One of the other things that I think maybe we glossed over a little bit is about how ISSA works in general. ISSA is a membership organization, so I wonder if maybe you talk a little bit about that, how if people want to join, they can join, and essentially what the benefits are. That you want to be an ISSA member? Right. So ISSA is an international organization, and all the memberships are handled through the international website.
If so, if someone wanted to join, they would go to the international website, and they would register, pay the fee of $95 to international, and then through the registration process, you get to choose what chapter that you want to be associated with. The great thing is you can be associated with multiple chapters. So recently we've helped start a chapter up in northern Colorado in Fort Collins, and so I'm a member of that charter organization. So it's a good opportunity to be involved in multiple organizations, but we encourage people, sign up, be part of Denver, and that's just an another $25. So for $120, they get to come to all the chapter meetings.
We provide lunch or dinner at those. They get to come to all the special interest group meetings. We try to put on 2 to 4 trainings a year. We do our best to make those free as well, and we provide breakfast and lunch. And so most things we try to put on at zero or very little cost.
And so you're going to get your money back really, really quick. And then also, great things like the Rocky Mountain Information Security Conference, that fee structure is so that you join as an ISSA member, you get your money back very quickly because you're reduced fees going to the Rocky Mountain Information Security Conference. And so to me, it's high, high value. I don't know how you would put a percent rate of return on that, but it's higher than any rate of return I've ever calculated, you know, being in the business world. Well, I mean, yes, I think it is a great value.
You get so much out of it. But, you know, even at the starting point, even if you got less value out of it, it still is— it's such a low price point compared to a lot of the other organizations that are out there. Easy entry and a great value. So I think that's really Right, and I had someone contact me this past month. They were a little confused with ISC², and they were like, well, I don't have a certification.
And I explained to them, we're not a certification organization. We're here to help educate people, to help people network. And so it was a good conversation I had with them, but they were under the impression somehow that there was a certification required, and no. We're all security professionals trying to be the best we can be within our profession. Yep.
So I think that the Fort Collins chapter, that's a great story and something maybe we can dive into a little bit more.
I wonder if you'd talk a little bit about that chapter, you know, why it got formed and, you know, what's going on up there. Well, Laura Francis is the president of the chapter, and this has been almost a year ago now that they wanted to form a chapter. And really the difficulty is if you live in the north part of Colorado, you're not— it's not very convenient to drive down to Boulder or to downtown or the DTC to try and get to an event. And there's a lot of technology up in the Fort Collins area. And there's a lot of room for growth there.
So they have started their chapter and they've got all certified. It is a formal chapter now and they're having their monthly meetings. And I'm not sure of the actual membership, but I know it's just grown very, very rapidly. And they made it the Northern Colorado chapter. And the idea is also it's so close to Wyoming that people can come down from Wyoming if they want to be part of ISSA.
So we really salute that group for what they've done and how they've got that started, and it's, it's growing and there's a lot of interest. Yeah, and, and that's awesome. I know, you know, for a long time, um, for the Denver chapter, we had our one meeting that was in the Tech Center, and, you know, we felt like we were definitely excluding the people that were, you know, in Boulder And, you know, sometimes it was, you know, even excluding the people that were in downtown Denver just because it's hard to get to a meeting, which, you know, eventually led us to creating those other monthly chapter meetings as part of the Denver chapter. But yeah, I mean, to your point, even getting all the way up to Boulder, that, that still is a good ways for someone from Fort Collins to come down, say, for a lunch meeting or something like that. So I'm, I'm glad we were able to do that, get that, that extra chapter.
And I think it just shows how vibrant this security community is in the Front Range where we've got the biggest chapter in the world in Denver. We've got— it's either the 2nd or 3rd biggest chapter in Colorado Springs. 2nd largest in Colorado Springs. And then we still have enough room that we can start a 3rd chapter up in Fort Collins. Absolutely.
And anyone out there listening to the podcast, you're over a wide area. And if you come to the Rocky Mountain Information Security Conference, and you want more information about those, we'll have a booth there, and all of the ISSA chapters here in the Colorado area will be represented. So if you're interested in it, let's say you're interested in the Fort— the Northern Colorado, we'll give you information about that. We'll tell you who to contact. I'll drop an email and introduce you.
I'll do whatever you need me to do to help you get associated with the chapter that you'd want to be associated with. I think the, you know, the next frontier now is Western Slope, right? We're gonna get a Grand Junction chapter started. Yeah, I think we're— I think we're gonna have the special interest group that is associated with snowboarding and skiing.
Get a Vail chapter. Yeah, get a Vail chapter. I might sign up for that one real quick-like. That sounds good. So I think we've covered a lot of topics.
We We're getting close to the end of time here. I don't know if there's anything else that you wanted to talk about, James. We talked about volunteering, and I just would like to encourage everyone out there, if you don't think you have time to volunteer formally, then you can always make a difference. And that could be simply helping someone that's new in their career, give them an encouraging word, help explain something to them. Those small steps can really assist the overall good of the information security community.
And I would highly encourage anyone that wants to develop, who wants to make this greater Denver security community great, is really get in there and and volunteer. Find out where your niche is and how you can make it better and go out there and make it happen. So I have enjoyed it and I've learned so much and I've got to meet so many people. It's just totally amazing. Yeah, that's great.
And then I think we've mentioned it a couple times here, but the Rocky Mountain Information Security Conference, co-organized between the Denver ISSA chapter, the Denver ISACA chapter, coming up again May 8th through 10th. I think we're gonna have some great content this year. You know, I'm helping organize, you're helping organize.
The attendee registration is open at this point. By the time people are listening to this, the call for papers is gonna be closed, so people have missed out on that. And, you know, if you are a vendor, and you want to sponsor the conference, we will be taking sponsorships all the way up until the day of the conference. So if you're listening to this and it's before May 8th, then you could still come and sponsor too. But again, the Rocky Mountain Information Security Conference has continued to grow.
We're again doing a 3-day conference this year, 1 day of full pre-conference training and then 2 days of the normal conference tracks. I think that we're going have some great pre-conference sessions. We're going to have a cloud security pre-conference, a DevOps and security. Some folks from Red Canary are going to talk about the Atomic Red Team testing framework that they came up with. We've got someone coming in talking about information security for auditors, how to audit information security.
Lots of great stuff. We've got our keynotes. That have been confirmed at this point, and we're going to be announcing all of the people that are going to be speaking in the normal speaking lineup soon. I think it's going to be great. Well, I've had the opportunity over the past 2 years to travel around, and what's nice is when people don't know that I'm associated with ISSA and they're talking and they talk about the Rocky Mountain Information Security Conference, a lot of positive comments, and I go, oh yeah, I'm associated associate it with, you know.
And it's really good because it's great value, great speakers. And you're heading up the, the conference this year, and everything I see, it's going to surpass last year. And last year was great, so I'm looking forward to it. And I think it's, it's going to be a good time. Awesome.
I'm looking forward to it too. Not only to looking forward to having it happen, but looking forward to, you know, be done with planning. That's always the flip side of it. Sure, sure. And most people may not realize that planning starts in June, right?
The conference is in May, planning starts in June. So it's a year-round thing and a large commitment, but really good for the community. And I think it helps put Colorado on the map for information security. Yep, it's a great conference, and I do hear those comments as well from lots of people about how much people enjoy it, what a good reputation it has. That's good.
Well, I think we're just about out of time, James. Any closing comments? Again, I just want to congratulate you and Robb on what you've done with Colorado Equal Security. Yeah, I know this was a surprise to you. And just so everybody knows, there were 2 awards given.
They're duplicates so that Robb and Alex didn't have to share one. They could each have their own. But when you go and look how much work and how much dedication it takes to put this on each and every week and to keep your website up to date— your website is always up to date, and how you guys do it, I don't know. It's amazing. So again, congratulations and very much appreciated.
Thanks, Jay. Mostly Robb's just a machine, you know, he just hammers through that stuff. Stuff. So, uh, but anyway, thank you. Uh, it's been great talking to you.
Uh, thanks for, for taking the time. Um, again, thank you for all the time that you put into ISSA. Uh, it's a great ISSA chapter here in Denver, and it's only getting better. Awesome. Well, thank you so much, and I've really enjoyed having the time to speak with you.
Awesome. This has been Colorado Equals Security, and we will talk to you next time.
Learn more about the Colorado security scene at colorado-security.org. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.