Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 65 for the week of April 30th. Alex, it's, uh, basically it's May, right?
We'll call it May. It is basically May. It's hard to believe that April has vanished already. We're a week away from kicking off RMISC, and of course we're just a few weeks away from GDPR going live and changing all of our lives forever. Yeah, and we have one story a little bit later about that, but yes, there are lots of people getting very worked up about GDPR finally coming into effect.
Well, I'm really worked up about the Colorado security scene. Let's talk about that.
Start off, let's say thanks to our Patreon donors. We really do appreciate those who've donated to help support the show. We would love it if we could get some more supporters who would help us pay for hosting fees and the website and all the stuff that we got to do as a part of the show. We did have someone this week mention on the Slack channel that since we are over our limit of free messages, that they get some nagging know, messages from that. And we decided that, yeah, we're happy to pay for the paid version of Slack if people are willing to donate through Patreon.
It is only like, you know, $4,000 a month or something like that. I think it was about $3,000 a month. So if you guys would— if we get 30 of you to sign up for $100 a month, that's easy, right? Right. No big deal.
But thanks to all those in the Slack channel. It's been great. Great conversations going on there. Review us on iTunes and Google Play. Also sign up on the website for our mailing list.
Yeah, we haven't talked about the website in a while, colorado-security.com. Just as a reminder, we do have this site. It's, it's not only a place to find the, the show notes, but we also have quite a few other resources on there. We do talk about the event calendar quite a bit, and that is the place where you should go look to see if you want to go to a security event in the Colorado region. Look on there and you'll be able to find something just about every day of the week.
And of course, if you're looking to schedule a security event, that's a good place for you to go and make sure you're not conflicting with something else you want to do. Exactly. And then we also have another section, which is the Colorado Companies page. And we have a nice write-up about all of the Colorado vendors here in town. I think that we'll say, though, that all is in quotes there.
Yeah, that's fair. We probably have 20 or so on the list, but we keep finding more and more companies, and we can't add them as quickly as we find them. Yeah, and if you are a Colorado security company and you're not on the list, let us know. I'll put you on my backlog to add you to the list. I would say that we are only looking for those vendors.
We're not doing consulting companies as there's just too many little, you know, onesie-twosie consulting companies to get them all on the list. Exactly. All right, let's jump into the news. The first story today is about net neutrality. Recently, net neutrality officially, you know, expired based on the FCC rulings that they had.
And this story is about a bill that was in the Colorado legislature that would have essentially said, we're gonna do net neutrality anyway, but they decided not to do it. Yeah, they were gonna tie giving some state money to broadband providers to them supporting net neutrality. This was killed in the legislature for Colorado. So this is not gonna be a thing that we're going forward with here in Colorado either. Yeah, I think on the positive though, there are some states that are putting in measures like that that are gonna, you know, support net neutrality in those states.
And the hope is that if they're supported in those states, then it'll essentially have to roll out and be supported everywhere. Yeah, good stuff. Next on the list is Colorado's— actually Denver's population continues to climb the charts. There are 28 metro areas in the US that are growing by at least 1%, and we are among those. And ours is actually up at 1.77% for the last year, which is faster than some of the other big ones— Atlanta, Phoenix, and Seattle.
Not as fast as some of those big Texas ones. It looks like Dallas, Houston are growing really quickly. I am shocked, shocked, I say, that there are more people moving to Denver. Yeah, I thought the interesting thing in there was we're about 2.8 million in the metro area right now. And this was looking out to 2040.
Right. And there were somewhere over projected somewhere over 4 million by 2040. So we've got plenty more people coming into the area still. Yep. And that's assuming, you know, continuing the same growth rate.
Yes, exactly. Also, we have an article this week about Colorado new business filings. So we hit a record in 2018. We had a total of 120,870 new business filings reported over a 12-month period. This brings us to a little under 700,000 businesses in Colorado, which is the most ever reported.
So number one, that's a lot of businesses. You know, you're talking— that's a lot. You're talking 2/3 of a million. And it's also, to me, it's amazing that basically, you know, 20% new growth of businesses over the last year. That's just a huge number of new businesses to add to the existing pile.
And there's also another couple interesting facts from this article. Our unemployment rate has stayed unchanged at about 3%, um, which is, which is really, really good, significantly below the national average, which was already good at 4.1%. So, you know, a 3% unemployment rate, it means it's, it's really hard to, to find folks right now. I am shocked, shocked I say that it is hard to hire people. Um, yeah, next, uh, System76.
Oh, go ahead, Robb. It's, it's not just It's not just people who want to come to Colorado, it's manufacturing jobs. Yes, it is. Colorado company called System76. They are a computer maker.
So they make desktops, laptops, servers that run Linux. So they actually make the hardware. And they previously had these made in China. Again, not a surprise there, but they have moved those operations back to the US and to Denver. Pretty cool.
I didn't know we had any manufacturing coming to, to Colorado. So it's kind of neat to know that that's happening. Yeah, it was interesting looking at the article. Um, you know, you might think with some of the news going on that it was, you know, related to trade or, you know, make America great again or, you know, other things like that. But it was really that, um, they needed, you know, closer control on, uh, their supply process to be able to, to be a little more nimble, uh, higher quality control.
So they, they thought that bringing it back here, yeah, um, would do that. And, uh, because of that, the, the pricing, uh, seemed to be negligible. So good for them. Awesome. So, Alex, we're recording in the morning right now, and you've got a cup of coffee right in front of you right there.
I do. Do you know where those beans come from? They came from, you know, this machine that someone pushed on the lever and coffee came out. Well, if you were to buy coffee from Bext360, they would not only tell you where those beans come from, they would use the newest and coolest technology to do so— blockchain. What?
That's pretty amazing. So this is a Denver startup that has designed technology that's used with some Ugandan coffee farms to track the coffee from the farmer all the way to where it's sold at one of their, uh, Koda Coffee locations around Denver. Yeah, so, um, interesting application here, right? I guess, um, you know, you've got this unchangeable ledger so you can track where this stuff moves. Um, as I was telling you earlier, It's great that you can, you know, track these things and that people can't change the ledger, but I don't really see how that translates to the physical part of it.
I don't know how someone couldn't switch where the coffee beans are, or maybe I'm missing something in this whole supply chain process. But, you know, it's great that you can track the process. I'm still not really sold that this is anything amazing. Yeah. Unchangeable.
And hopefully you don't make a mistake when you put it in. Right, right, exactly. The good news here is that the blockchain technology is not adding anything to the price there. I don't actually know. I'm not really a coffee guy, but their 12-ounce bag of coffee, of blockchain beans, costs about $14.25.
And they say that's the same as their other coffees. You know, I think just for that, I'm going to have to go to Akkoda Coffee and buy a bag of blockchain beans just to say that I can have some. How much does a 12-ounce bag of coffee usually cost? I have no idea. All right.
So yeah, we're not in the know on this. We definitely are not. All right, uh, next, uh, Optiv had a post this week talking about the CISO periodic table. Yeah, so, you know, mostly I think these things are a little bit gimmicky. Um, this was definitely an opportunity for them to sell.
So if you print it out and put it on the wall, that's, that's a use for it. If you use it on their website, you can drill in and see how they, how they'll sell you services around each of those things, which, you know, of course that's what they do, so that's great. I think it was actually pretty decent for the most part. There was one part that I sent you a note about that I didn't like, which is that they had one element for compliance and then they had a separate element for GDPR, because GDPR is a buzzword right now, I guess. How is that not just the same as other compliance?
Exactly. But I do like it in one sense, and it reminds me a little bit of some of those CISO mind maps or other things like that that you see floating around, essentially just capturing— I don't want to say all, but a lot of the different topics that you need to think about as a security leader. Yeah. What I did like about it is it helps you think of things comprehensively and in a different way than you would with ISO or the NIST Cybersecurity Framework. So they have their categories of business fundamentals.
How do you support digital transformation, governance, risk management? You know, IT fundamentals, asset management, change management, patch management, configuration management, identity management, security program fundamentals where they're going through network security, vulnerability management. Anyway, there's all these different categories on here that are pretty interesting, and I think maybe useful for you to look through and say, hey, I don't really understand that, right? And, and you could read a little bit more, or, you know, oh, in my program I wasn't thinking about this particular thing, so I need to think about that. So Kind of interesting.
And who doesn't like having a periodic table on their wall? I was, I was a chemistry major, so, you know, works for me. So, so everyone but you is the answer to that, by the way. Exactly. So next, we had a blog post from a company called Kaseya.
They are actually not a Colorado company, but the blog post is about them partnering with Webroot to add Webroot's protection to their, their systems management platform. So sounds like they provide remote admin kind of services, you know, managed service kind of IT support. And then now you can use the Webroot antivirus product and other Webroot products within that platform. And as much as we do love the Webroot folks, you might want to use this article that was written by the other half of it, by the Kaseya folks, as an example of how not to write a press release about a new partnership. 'Cause I couldn't understand what the partnership actually was.
And we spent quite a bit of time trying to get through the marketing buzzwords to figure out what's the meat of this thing. On the other hand, if you needed to find something to play buzzword bingo with, this would be a great article. It's a good example for those stories about how not to do this. Moving ahead, we have a blog post here by LogRhythm talking about UEBA, User Entity Behavioral Analysis. And really what they're doing here is just showing how could you use this to help detect if there's a breach in your environment?
What are the security use cases for UEBA? Of course, LogRhythm has added UEBA to their SIEM product, and this is a good way to kind of show, show off how to use that product. Yeah, it's a really interesting product. I like it a lot, and I think that that sort of technology coming into any kind of SIEM product is really going to enhance the value of those products. So Swimlane is the local security orchestration and automation company.
Up in, uh, was it Louisville, right? Um, yeah, they've come up with version 3 of their, of their ver— of technology, and they have some pretty cool upgrades as a part of this. Yeah, it looks like, uh, they are being a little bit more social, I guess I would call it, here. Um, they have what they call some hubs, um, that, you know, they're, uh, helping with, uh, you know, open exchange of information, um, threat intelligence data, you know, and the way that I'll call them playbooks. I don't know if Swimlane calls them playbooks, you know, the way that you do these things in the, in the system.
Yeah, they have not only the, the ability for you to create playbooks internal to your own company that you can mix and match, you know, as you're building out programs, but then they have this hub that things get checked back into and you can start to use other people's stuff. It's a pretty good idea. You know, of course there's some risk. What are you going to share and what does it reveal about your environment? I don't know how, how they do it anonymizing that.
I assume that's something they've, they've taken a lot of look into though. So Pretty cool stuff. Yeah. I, I mean, and I think that's, you know, really sort of the value of some of these platforms, right? It's, they have a base where you can start automating and, um, and orchestrating the way that you do your security operations, but it really helps if you don't have to build out all of the pieces to do that yourself.
So having this, uh, open exchange seems like a great idea. Yeah. Uh, next, uh, Webroot had another blog post. This one was actually by them. Yeah.
Not, not by Kaseya. Um, talking about the STEM pipeline and what you can do. So this was actually by Dave DeFore, uh, who we've had on the show here before. And he— it was, uh, to go along with the Take Your Kids to Work Day, which was on Thursday of this last week. And, and he went and listed 6 things that you can do to help with the STEM pipeline right now.
So I'm actually going to go through these here. I think they're good points. And, and I think all of us, all of you listening, should be thinking about how can we encourage more participation in our careers So number one, let's realize that not everyone is going to want to be an engineer, and that's okay. You know, we need marketing folk, communicators. Of course, in the security world, we need GRC folks, we need project managers, we need security awareness type folks.
So it— we can start to show these other opportunities other than just the hard technology, you know, as potential career paths. Number 2, you're not pushing for a PhD. There are many paths that don't have to start with a 4-year degree. But we, we just want to get folks involved with those skills, and it makes a lot of sense to start encouraging folks to, to play with the technology, not necessarily just encourage them to go off to school. Uh, and number 3, he suggests taking your kids or your neighbor's kids to work.
You know, even if you don't work in tech, just showing what you do every day, uh, get them involved with IT, gives them a chance to really humanize what it means to be in technology. Uh, and of course, number 4, he talks about Legos. Legos are a great toy that can be used, especially since we got the whole Mindstorms. Yeah, that stuff is great. Yeah, they even have ones now that you can, you know, you can use computer programming to essentially program what the Legos are going to do.
Yeah, so like the Mindstorms is the robot you create, and there's all these national competitions and stuff. So that's a great tool to get in without kids knowing that they're even doing programming, right? Number 5, Snap Circuits. This is another toy that he recommends. I don't know this one.
Number 6, programming can be fun for all ages. Young kids can learn to program with tools like Scratch, Blocky, and Alice. So some fun resources you could use to get kids programming. Yeah, I will say there's a great book out there on using Python and Minecraft. So if your kids are into Minecraft, you know, you can help them to automate some of the things in Minecraft and play around with it using Python and some other things like that to, you know, introduce them to programming while they're playing a game that they like.
Yeah, very cool. All right, and then last we have a blog post from Conversant talking about GDPR compliance and some unintentional risks that could come up. So basically they're talking here about the possibility that you might need to get rid of some employee personal data or be prevented from doing certain things that could hamper, you know, internal investigations in your organization because of GDPR. Yeah, the whole right to be forgotten, right? I can tell you I want you to, to wipe everything you know about me.
Well, that probably includes, you know, everything from my employee file at some point. And, uh, and it, and exactly what does that mean if I did something illicit while I was there? Right. Yeah. I mean, it's a question of whether, you know, when you know something might be going on and things like that too.
Right. You know, there are obviously things that can supersede GDPR. If you're on, you know, a legal hold, you're not going to delete the data because you have other obligations to keep it. But yeah, but it's definitely an interesting topic. And of course, They got a buzzword that's really relevant in the world right now, and of course they're going to use it.
But it's an interesting topic. Yep. All right, let's move over to the Slack Message of the Week. Aaron Lafferty, congratulations, you are our Slack Message of the Week winner. Aaron shared with us a survey that he's in the process of doing, and we wanted to share with all of you guys.
So it is a 2-question survey. You read a short paragraph that gives you a scenario, and it asks you a question about it and then a follow-up question. Really easy. It shouldn't take more than 30 seconds to do this. I am— I took the survey yesterday, and I'm super interested in hearing the results.
So Aaron has committed that he'll get back to the community and share what he learns from this. So I wanna encourage all you guys to go take the 30 seconds, click the link, it'll be in the show notes. And, and let, let us, you know, let's get that information because it's all about data breach and who's responsible for stuff. But if you were in the Slack channel, you'd know this already. You should be there right now.
Next, we'll move over to our upcoming events. And as we talked about earlier, there is an event calendar on the website, so go check that out. First on the list, CTA is having their Insight Series, Turn Big Data into Big Business, on May 3rd. And that's it for next week. The week after that, we have a couple things going on.
On the 9th, Wednesday the 9th, we have the CTAs 101 event. You shouldn't go to that though, because that's right in the middle of Rocky Mountain Information Security Conference, so you're going to be hanging out with us there. Yeah, um, that of course is the 8th through the 10th. Uh, first day is pre-conference tracks. We've got a number of those, either half day or full day.
Um, in the evening we are having our community night. So this is a couple of different things. There's a job fair, so really excited about that. We've got a number of companies that are coming in. They're going to be talking about open jobs that they have.
So if you're looking for a job You should come hang out and talk to some of those companies. And then we're also having a bunch of different security organizations come in and talk about themselves, give some content. So we've got InfraGard, Cloud Security Alliance, OWASP, ISSA, and ISACA. So even if you're a member of one of those organizations, maybe you want to learn about the other ones, or you want to hear about what your organization is talking about. And then the, uh, the main conference days are the 9th and the 10th.
A lot of great content there, uh, really excited about it. We're getting really close to being ready with everything, doing all the last-minute preparations. Should be great. And then coming right after RMISC on the 11th and 12th is Denver BSides. This is the, the, the other conference here in town.
It's going to be taking place at the SecureSet Academy on Blake Street. This is a really fun event. Highly recommend. They have signed out of all of their— or they have sold out of all of their, their donor stuff at the lower levels. But you can still pay whatever you want to get a ticket.
And they actually have free registration if you just show up day of. But apparently if you do that, they give you a hard time. That's what I hear. Well, you know, you probably deserve it if you're just showing up that same day, but that doesn't— shouldn't stop you from going anyway. So this is— I mean, really, we're talking about the big week in Colorado security here for the year.
So we're looking forward to spending a whole week with you guys, you know, Tuesday through Saturday. Hopefully you guys can make it to as much of this as you can. Yeah, I mean, that really is great. The 8th through the 12th for these 2 events. Lots of great security content all packed in there.
All right, let's go ahead and jump over to jobs. The first job on the list— this is a surprise— is Ping Identity hiring a senior security analyst. So this is a role on my infrastructure security team looking for someone with some seniority to help us really, you know, mature our internal security operations processes. Looking for someone who's got really strong security and Linux experience, and AWS is a big plus. Alex, I don't see Pulte on the list here.
Yeah, you know, we haven't finished hiring for our internship, but we have lots of great candidates, so I went ahead and took it off the list. If you are a great candidate, you can still apply. We're still in the process of picking folks. Um, but you're going to be in the mix with a, with a lot of great people. So, uh, next, uh, Arrow is looking for a principal security architect in applications.
VMware is hiring 3 different positions that can be here in Colorado, not necessarily have to be, but they're hiring a senior analyst on information security risk management, a senior cloud security architect, and an information security engineer. Overwatch ID, they're a local startup here in the IAM space. Um, they're hiring a few jobs as well. These are not security jobs, but it's for a security company. So they're looking for a senior software engineer, an AngularJS developer, and a DevOps software engineer.
Uh, Recurly is hiring a director of information security. Do you know Recurly? I don't. Um, but they are a, a local company here. Very cool.
Uh, Carbon Black is looking for a senior threat researcher. Carbon Black has been building out a lot of folks up in the Boulder area, so they got lots of open jobs up there. Coalfire is hiring an associate consultant penetration tester. Yeah, so if you want to pen test, that looks like a good one. KPMG is hiring a manager of cybersecurity services for IAM, and Great West Life is hiring a threat and vulnerability management intern.
So another— if you didn't get into the Pulte opportunity, this is probably your next best bet. Exactly. There are lots of great people over at Great West. I'm sure you'd have a great time over there too. Wow, that was pretty good.
All right, well, let's go ahead and throw it over to our feature interview. This week we are talking to Douglas Brush. Douglas is the, uh, the host of one of Colorado's other security podcasts, um, and he's also a director for Kivu Consulting. We've talked about them on the show a few times. Yeah, so we, um, we originally talked to him probably almost a year ago.
Yeah. And so Robb and I were both on his podcast and now, you know, we're flipping that around and having him on ours. So sounds good. All right. Well, that's it for this week.
We'll talk to you next week. And as we're, you know, in the middle of RMISC, it should be fun. Thanks, Robb. All right. See ya.
Hello, this is Ian Buxton, Senior Director of Information Risk and Security at Vail Resorts. This is Colorado Equals Security. For Colorado security professionals, by Colorado security professionals. All right, this is Robb Reck, and I am sitting here today with Douglas Brush. Douglas, you are the director of cybersecurity consulting for Keyvu, and maybe more relevant to the folks here in town, you're also the host of another podcast here in town, the podcast Cybersecurity Interviews.
So before we dive into any of that, I want to ask you, what are you most interested in outside of security? Uh, definitely, uh, I would have to say cooking and craft cocktails. Cooking and craft cocktails. So talk to me, what's your, what's your best dish? Oh, best dish.
Uh, so the one I became, um, there's 2 that I'd probably do on the regular basis that are more the holiday entertaining types would be osso buco, and I also like to do braised Berkshire pork chops that just have a nice kind of almost— they basically taste like steak and bacon had a baby. And then you have to like eat, you know, about a pound of that. And it's just very decadent. Steak and bacon had a baby. That sounds, that sounds pretty stinking good.
It is pretty good. It is. You can't go wrong. So talk to me about ossobuco. I don't even know what this is.
It sounds like Italian. So yeah, it's, it's basically, it's braised lamb. So it's this— or I'm sorry, veal. And it's this very delicate cut of veal shank. That's then just cooked and slow cooked for, for hours, low temperatures with some rich flavors.
And it just gets this very nice kind of own gravy in itself and get to eat the bone marrow out of it when it's done. So how often do you, do you go cook like a full meal like this? At least once or twice a week. Wow. Yeah, I, you know, I still equate it a lot to, to cooking, to hacking in a weird way, because, you know, cooking and drink making there's this reverse engineering that goes into it.
Usually if I go out and I have a good dish, I got to figure out how to make it. And so I spend a lot of time trying to figure out how somebody else made something that I can recreate. Interesting. I'm thinking about the correlations there between, between learning how, you know, how a system works and what the components are you need to know and how to make a good dish. Craft cocktails— what's your best cocktail?
Well, I go to— so my 2 stock ones would definitely be Negronis and and Manhattans, but I do variations on those with it either depending, uh, mezcal. And I infuse some mezcal with hibiscus sometimes and do like a, a hibiscus-infused mezcal Negroni. And Manhattans, I've— I used to live in New York City, so I did a Brooklyn. So it was kind of a modification of a Manhattan. I just got to come up with the Denver.
I haven't figured out what that's going to be. What's the Denver going to be? I like it. Um, so next time we do a Colorado Photo equals security happy hour. Do we have, do we have a new bartender?
Oh, are you on the record? I'm on the record. I'll do it. I heard this. I, it was funny when we did our office opening, uh, for Kivu a couple— God, it was right over the holidays.
I designed at, uh, Tupelo and Honey over on, uh, right over by Wawada. We did, we did craft cocktails and I worked with the bartender to come up with about 4 or 5 branded cocktails for the event. Yeah, that's great. Very fun. Well, why don't we talk a little bit about what we're here to talk about, security here in Colorado.
And back me up, where are you from? You're not from Colorado, are you? No, we're coming up on about a year. I moved to Colorado from Brooklyn, New York, and Manhattan, where I had my offices, about a year ago. Okay, so where are you from originally?
From New York, born and raised. In Brooklyn itself? Actually New York City, and then up and down the Hudson River Valley. So I moved out to Poughkeepsie, I was up in IBM country for most of my teen years and then moved down to Manhattan in New York City, in Brooklyn. And after I had a kid and a dog, we, my wife and I, decided it was time to move to Brooklyn like everybody who does that does.
And we moved there for a couple years before coming out to Colorado. And so what brought you out here? Definitely lifestyle and also the business environment. You know, we, I've been for decades building businesses and doing entrepreneurship around technology and security in New York City. At a certain point, it almost becomes almost like a little bit of a Stockholm syndrome.
You start believing that your captives of New York are normal, and that's the normal way to do it. But after a while, you start realizing it's not a viable place to try to raise a family or a business. So I started looking at other areas around the country that had a better footprint for being able to grow and grow consultant practice, particularly around cybersecurity, that also had talent and space and just better, basically better P&Ls because it was just so expensive to grow practices in a major market.
I would love to know, how did you get into security? Presumably you went to high school at some point. When did you get involved in security? Yeah, it was early on. I've always been kind of interested in technology.
I got started with computers when I was about 6 years old before it was like kind of a thing to have kids involved in technology. I was involved with early stages of online services in the '80s and kind of with Prodigy and the different dial-ups and really was kind of embedded in technology early on, and I kind of became the go-to family person to fix computers for family and friends. And after high school, wanted to get into technology as a profession, but at the time, and particularly in the early to mid-'90s, so much was focused on computer science degrees, on mainframes, large computing stacks. And particularly when I was— like I said, I grew up in Poughkeepsie, that was IBM. That's all IBM thought of was mainframes.
And at the point I said, well, look, there's this growing market of end-user computers, small business computers that are where the technology, particularly around networking and software, was becoming— collaborative software was becoming more available. There should be a greater focus on that, but none of the schools or programs really had the ability to offer me that. So I went out on my own, started a consulting practice in the mid-'90s doing your typical kind of break-fix and office support for computers, but it was really embedded at that time a lot with the security culture. I started reading the old Phrack and 2600 magazines, got really involved with monitoring the hacking community forums and things like that. Even though I was doing mostly pure IT consulting, cybersecurity was also something that I was closely following.
I did that for about 10 years before really in the mid-2000s or early 2000s, around 2006 or '07, really decided to focus exclusively on cybersecurity and get really back to kind of my hacker roots. 2006, 2007, you said? Yeah. So you were doing your own consulting for almost a decade then? Yeah.
And what was the impetus to make a change? So around that time, I was doing a lot of work with Merrill Lynch that was quickly disappearing as the markets changed from 2007, 2008. And then around, you know, mid-2008, somebody had contacted me that was doing a lot of audiovisual forensics, which I didn't even know was a thing. And I used to support all his computers and networks for his company, and he'd gone out on his own to start working with— originally with the FBI and folks down in Quantico— went out on his own to do audiovisual forensics and said, hey, listen, I got this new case where I have a computer that's involved in a a big litigation. It's recorded video.
We have concerns that the video timestamps might be off. Would you be interested in looking at the computer and doing a forensic examination? I said, sure, why not? Because I didn't really understand what I was getting into. I was like, yeah, it sounds like a great idea.
And so I did this whole analysis on the computer, was able to find out that the BIOS on the computer was definitely skewed, and the timestamps on the video that about 16 other experts were using their timeline to establish the events that happened on this one particular incident were all off. And so it was really kind of cool moment for me to say, hey, look, I just really be able to dig in, pick through things, do partial portions of litigation, which a lot of people don't like dealing with lawyers. I love the kind of Type A personalities go with them. Got deposed on the matter, issued expert witness report, and really kind of got that taste of doing the litigation consulting, but also the computer forensics and security and said, this is, this is 100% what I want to do, and just doubled down and started my own company doing computer forensics and cybersecurity in New York City. So how did you start your own company?
What's that mean? It means just basically really hanging a shingle and really saying, look, you know, I'm gonna register the domain, set up a website, you know, incorporate a company, start getting staff, building all the vendor contacts. You start hiring people? Yeah, I'd started a partner at the time. We We tried to get some subcontractors going.
I then partnered with another firm that was doing a lot of traditional investigations, some more of the PI-type work, and we partnered a lot because he was doing so much of the background stuff and different things that involved the human element. I said, well, look, there's a huge component that deals with the computers. We did a lot of investigations around counterfeiting, fraud, employee theft, and we teamed up and really was the launchpad for the business. That's pretty neat. So talk to me about the process of starting up your own company.
You said 2007? Is that when that was? Yeah, it was in 2007. Yeah. So it's a different market than it is now, right?
So talk to me about what was it like to set up your own company then? It was definitely different because, you know, it's funny now having gone through— the best kind of barometer that I've had for it lately has been like the show, you know, Mr. Robot, where There was so much of the cybersecurity stuff that we did even 10 years ago that just wasn't part of the cultural zeitgeist. Nobody understood that cybersecurity was this weird thing, but now it's become this pop culture thing. Certainly with all the data breaches, there's more of a consumer and cultural understanding of what that means.
Back then when I said I did computer forensics or investigations, it just washed over people. I just reverted back to, I do something in IT, because that was the only thing they can connect with. Now I think there's a greater understanding of what that means in security because everybody's been exposed to or affected by it on a personal level. It's been interesting, hasn't it? Over the years, my answer to, what do you do, has changed quite a bit.
It used to be, I'm an IT guy, and now, maybe a few years ago, I could start saying, I'm a security guy, or, I stop the hackers, or something like that. Now you can get into pretty nuanced conversations even with Even with the guy who hangs drywall or the woman who works at a flower shop or whatever, they've all seen it on the news now and they understand more than just you work with computers. You're there to start hardening systems. It's pretty fun to see that change. Yeah, it was funny.
Even the local dry cleaner up in Boulder, he had started a web app or a mobile app and had asked for some information. I kind of looked at it and said, hey, this is and secure, I talked to him offline and said, look, you've got to be careful about the way you're taking in some consumer data. He said, wow, I hadn't thought about it. It at least connected with him on a— I think because there was a business risk level that he understood that, hey, if I do something wrong here, I can lose business. Right.
It's funny. If you talk to the guy who owns the dry cleaning shop, he gets it. If you talk to the person who works for him there, the person who works hourly, say, hey, you got a problem with your mobile app. It just couldn't possibly care less, right? You have to connect as something that actually has a meaning.
So talk me through, you know, you started your own security practice in 2007 timeframe. What's next? How'd that go? It went, yeah, it went well and got involved in some bigger cases with bigger clients, and it just kind of morphed from one thing to another where I was supporting a lot of these larger litigations and doing computer forensics and investigations around different things that were events that were happening as part of these litigations, but I started to find there was more and more— basically, when I saw the bad things happen, when the crap hit the fan, I started saying, well, look, I'm seeing the same things over and over again, and would make recommendations to clients about here's how you can actually improve things, and more clients got more, I guess, interested, I would say, in saying how they can prevent those things from happening again. Usually when they've had the big spend and there's lawyers involved and data breach kind of incidents, they just don't want to have to live that again.
It's kind of a good moment when you kind of get their ear to say, okay, how can you improve your security? We started putting more of the lessons learned from when bad things happened, how to be more preventative, and started doing more of that type of consulting as well. Then went into work for a company called Duff Phelps that was a large multinational advisory company, brought my practice that I had started in New York City to them, and we started doing a lot— still a lot of the litigation support, but then definitely a lot of the information protection work. Yeah, yeah, I really started out with security assessments, web application testing for a lot of clients that initially I did their incident response work for that said, hey, can you help me improve our security? Sure.
So work me forward, you know, you didn't do that forever. I know you've changed at some point, so talk me forward from there. Yeah, so then I worked at Duff Phelps for a number of years, helped build their New York City practice. At that time, they were kind of at an inflection point of growing the cybersecurity practice inside the firm, and so I kind of spearheaded some of the growth of the computer forensics and incident response team, built 3 computer forensics labs in different cities, consolidated a lot of the technology workflows and processes.
My kind of job in life at that point was split between doing the hands-on work, a lot of business development, and then IT. Somehow I had about 150% of my time allocated to things between the 3 spots, but just got it done. I really kind of felt that I wanted to continue to expand beyond just the reactive work and do more of the information protection work and went to another company called Kraft Kennedy where I built their what we called, like, kind of went in fresh. It was a managed service provider company that didn't have an information security group and built their information security group called the Information Security and Governance Group. So we did everything that was kind of end-to-end.
So information protection, so pen testing, web application testing, end-user training, CISO services, to governance services around different data compliance, you know, records management and compliance laws like HIPAA. Well, at that point it wasn't before GDPR, but when there was Privacy Shield and different types of European data rules to the traditional incident response and forensics.
Maybe talk to me through those first couple jobs. Give me some stories of a fun engagement. What was a fun engagement that you had during that time? They're always interesting. There's been a lot of— it's more of the lessons learned, particularly there were some larger engagements that we did where organizations went in and tried to do the cheaper route or maybe not the thorough route of their investigations.
Particularly when it involves litigation and there's judges and lawyers involved, that is a contentious situation. You often see that it's spearheaded by folks with inside a legal department at a company that tells the IT department, hey, go find this data, find out what happened. IT goes and launches their investigation, comes back with some findings, and then that makes its way back to the courts where lawyers on either on the other side or on the client side will say, well, this wasn't enough, and they go back for the second rounds and third rounds. And often we find that at that point we get called in because there's been all these efforts that go into it, and at some point a judge or somebody in the legal community tends to get kind of pissed off because they say, look, this hasn't been done right, hasn't followed the legal ramifications of what needs to happen. Chain of custody.
Chain of custody, just general, just defensive, defensible forensic data gathering and searching that meets federal rules, state rules, evidentiary rules. And the problem is you see a lot of these organizations that, again, inside legal counsel will guide IT, but kind of half-assed. And the problem is they don't really see the whole thing that really needs to go in there. They're not— neither of them are experts on it, right? They aren't.
And that's the problem, is they kind of go in and say, well, we don't want to spend money on lawyers or outside vendors. And I get it, like, it can be an expensive thing if you're not insured for it and you're self-insuring or paying out of pocket. It can get costly. But the downside is it's usually about 6 or 7 times more expensive. So we go into this whole engagement where the judge in this one particular matter is It says, look, you have to search the entire environment.
So it went from a very narrow subset of maybe a couple gigs of data that they wanted the entire environment searched to see what data had propagated throughout the environment. So it ended up with 1,300 devices, 5 cities, and about 6 months' worth of work that went to millions of dollars that had they not had the, I guess, a better methodology for their governance and the way that they handled legal situations, it could have been tens of thousands of dollars. Actually, when I was talking to the IT manager at that time, I had a security— I said, why didn't you have some kind of DLP solution or some type of anything that could have globally looked at your environment? He said, well, I wanted to have that and I put it in the budget, but then it got taken out because the CEO wanted everybody to have new iPads. It was kind of like, hey, it's their fault, they could have had this.
And I said, well, you know, there was a communication problem there. You didn't really sell it right internally. And I always thought about that. It's always stuck with me of seeing it from the outside of when you are in security, a lot of times you have to sell no matter what. You have to sell internally, sell to your client.
It's, it's no matter what, it's a loss leader in a certain way. It's like, how do you, how do you just, you know, get this going with security when people just attribute it to as just a loss bucket of money. Yeah, it's interesting, isn't it, like how commonly we blame our business for not being willing to invest where that's basically why they hired us, right, to convince them to invest. And it's a level— there's a shared— I don't want to put it all on the security leader either. There's a shared responsibility there between coming in a language that they understand And then the business has to be willing to, you know, make appropriate risk decisions.
I'd say, you know, the vast majority of the time, a business leader, assuming that the business is, you know, has means to make decisions, that they're not, you know, destitute— but if a business has the money to invest and you show them a business case that says, hey, this is, this is the place to put money to get the best ROI, they're gonna do it. The vast majority of the time, they're gonna do it. It's just we don't do a very good job of usually usually showing why it makes sense to invest in security. Yeah. So what about a spectacular, you know, head desk facepalm moment where you, you've seen some, a customer or because someone you've worked with just do something terrible in one of your engagements?
Oh God, I mean, that was another one where I think we had pitched them on the same thing, like some, some kind of information protection service. So look, let's light touch security assessment, figure out where the holes are. I think they declined us, and then they said, we're never going to spend that money. Then one day we get a call. They said, look, we think we have an incident.
We have some unauthorized logins.
We go and we look through the logs, and then we see not only is there unauthorized logins, there's somebody launched a ransomware attack. We started stepping back and looking, saying, okay, well, Did somebody click on something? What year is this, by the way? This is about 18 months ago. Okay, about 2 years ago.
So, and this is one of the first ones that we saw that came through a crypto attack that came through RDP. Realized they had an open RDP port on their firewall, went right through to some authentication server that had no lockout policy and just grabbed your password. Yeah, they brute-forced, got in, and, you know, we saw that there was now at least one or two unauthorized logins in this crypto attack. And it was one of those where I said, just, God, you know, had they just spent a little bit of money up front to, to just do the minimal amount of protection— I mean, that's one of the things I would flag in any kind of security assessment, say, look, you know, paired open, uh, you know, 3389 RDP port with bad password policy, like, you got to shut that down right away. That's a no-brainer.
And, you know, now they're at $100,000 us and security services because somebody had gone through the entire network and then we had to see what was touched. And there were just— it just became a really one of those where, like, you know, and then things is crazy how much they fought us even after that to say, well, you know, they were looking for somebody else to blame but themselves. And it was one of those— I was like, you know what, do you really— nobody to blame but yourself instead us. You know, we, we told you what you could have done. It's the, you know, ounce of prevention worth a pound of cure situation.
Right? Where if we could just, if we could just do that, that high-risk stuff earlier. That's interesting. So walk me forward some more from where we stopped the story. You know, you came to Kivu at some point.
Was that while you were out in New York? Yeah, so it was in New York, and you know, like any good risk manager, I, I took out a map of the United States and I started saying, okay, well, I live in the New York City area. We've been hit with at least back-to-back hurricanes. I flooded out during Hurricane Sandy from Manhattan. That was actually what forced us to move to Brooklyn.
So we leave during that. The year prior to even us getting moved out of— from Hurricane Sandy, we had another hurricane. My wife has done a number of startups herself, and she was in Brooklyn doing it, and she's had problems with flooding and stuff in Brooklyn. And we just had— we had issues where somebody actually drove into our apartment, which is random, because of course all this stuff happens when I'm out of town as when somebody drives into apartment, we have floods in the apartment or some kind of thing. I assume you're not, you're not ground level, your apartment, right?
We're 4 floors up. But yeah, no, we just had one like thing and tragedy after another. We're like, this is insane. And trying to like take our daughter to school and commute to Manhattan, I'm like, all right, done. This is just too nutty.
So we looked at different places in the US and where to live, and it was funny, Denver and Boulder area kept coming up as highest quality of life, you know, great, uh, economics, you know, the incomes are good here and just the schools are great and everything was just, you know, it was just, uh, you know, unicorns. So we're like, okay, this is great, let's, let's check it out. So about— it was about a year ago and 2 weeks, we came out, we visited Denver and Boulder, fell in love with it, said, you know, we're gonna do it, let's move. So we go back, I tell the job we're gonna move, uh, we started— we told our landlord who gave us an out And we decided to move out to, uh, to Boulder. And we moved out in March, and at that time I decided, okay, well, you know, I really want to build a practice out here.
You know, so you were quitting your job in New York? It was, it was kind of on a contentious thing. I mean, it was one of those interesting things where, you know, we weren't seeing eye to eye on a lot of things, um, and we decided that— I think it was around April that we parted ways, and I started pitching Kivo at that time. I'm saying, you know, around May I was like, here's what's happening in Denver. I don't know if you know this.
And they're like, well, you know, we're based out of San Francisco and New York, major markets. I said, okay, that's great, but I don't, I don't think you appreciate what Denver has to offer, you know, particularly around the security community. It started saying, you know, look, we have some of the largest security chapters with things like ISACA, um, ISACA, ISACA, and all these different groups that are here and the different Really the community things, like I started talking to folks at SecureSet about the training and say, look, there's just, there's an energy here and there's this feed. We should really build our back office here, put our SOC here, put our forensic lab, centralize things out of here. And I started doing the cost analysis even before I was hired with them.
So look, here's how much it would cost for us to do this. How much are you paying to do this in San Francisco and DC? And they're like, oh yeah, this is a no-brainer. Yeah, I said, can you really do this? I was like, yeah, give me, you know, write me the check.
I will, I will, you know, upon this rock I will build my forensic lab. And I just said, you know, this is, this is where we can do it. And, you know, we— I started with them in August, started building momentum with some of the clients that they had already nationally, and but then started reaching out to the local community and building kind of my network out here and getting more involved with the security community in, uh, in Denver. Yeah. And said, you know, we really got to build, you know, push to build this office.
And so we signed an office space lease about a month ago. We move in next month. We're gonna build— basically, I also, because I feel like I don't have enough time on my hands, I also took over some of the roles of like CTO, CISO, CIO, because, you know, I figured why not? Let's rebuild all the IT infrastructure and pull out everything that we had in different cities and centralize it here in Denver, make a big cloud push to push things towards Azure and different types of cloud services to minimize our production footprint, but build our SOC and forensic lab here in Denver in a space up in River District North.
That's awesome. That's a lot of good stuff. What kind of— I assume you're hiring. I know you're hiring. We've talked about it in the past.
What kind of roles are you hiring for here? It's a little bit of everything. We're definitely looking for more people that can do forensic analysis. That's becomes a big thing. Forensics and incident response, because we do so much of that work.
We have some homegrown tools we developed ourselves that we need more analysts in, but also on the information protection side. This company was— we're only about 30 or so people. We want to grow about another 10 people, so a good 30% headcount in the next 12 to 18 months, but we're definitely looking for a lot of people that have experience in doing pen testing, security assessments. The company, as I said, It grew doing incident response and forensics. It was 90% of the business 2 years ago, but we're now probably doing about 30% security assessments.
I would say this year we'll probably be closer to about 40% of the business will be security assessments. More people that can do the offensive work is always— You're looking to hire people who have done it before, or are you looking to train people? Both. Either way. I find it's hard.
What's interesting, what I like about some of the things that we mentioned, Securesat, who's obviously a local group. I teach with them too, and it's great. What I like about them is you're getting people that are getting second or third careers that have good business acumen, enough technical skills where you can kind of teach them what they need, but they also have— a lot of people are either in their late 20s, early 30s, or older, but at least they've had some business experience where they've dealt with customers, they've worked with other people. The challenge that I've had is a lot of the people that we either make lateral hires that have been in the the business for a number of years and are just so either jaded or set in their own ways, they're difficult to do a lateral hire and integrate into our processes. Or we get people that are so young and new that are coming out of graduate degree programs, which are good, but then they still need a lot of hand-holding both on the business side and on the technical side.
So if I could find that balance of people that have had some experience but are willing to learn— like, the best people I could say that I can find are people that have learned how to learn. Where they can quickly figure out, okay, here's how I have to absorb this material. Sure, that's reasonable.
Let's take a pivot here and talk about the other thing you do. You mentioned you're the host for the Cybersecurity Interviews podcast. Where did that come about? I think it was about 2 years ago. I started reading a lot of the business productivity books, and there was one book by Tim Ferriss called The 4-Hour Workweek, week.
And he said, you know, you kind of got to find this passion project. And I forgot what he actually called it in the book, but almost this thing that you want to do that's kind of an aside to what you're doing. And I said, you know, I've always wanted to do a podcast. I always felt like it was conversations that I had with people in, you know, at cybersecurity conferences or at bars with people after work, or just networking in general at different events, that kind of— it's like if there was— that was only recorded. That's that casual conversation about how people got started, where they came from, would be a kind of cool story.
I said, okay, I want to make that into a podcast. How could I talk to different people that are leaders with inside the industry, people that I've learned from, looked up to, or just been— had some kind of touch point that I've said kind of put themselves out there and figured out how did they get to where they are? Because as I coach and mentor people now that I've been doing this long enough, people say, you know, how do I get involved? How— what do I do? And I was like, there's almost like there's no clear path.
You have to just jump in, and everybody's kind of had their different route and relied on different parts of their life to build their experience. So I love hearing these stories because it one validates a lot of what I know, where I, you know, again, I didn't go to college for a lot of this or any of this, you know, I just kind of started my own. And to hear that, you know, a lot of people have had those similar moments where they've had to teach themselves, and there's a lot of commonalities with inside the industry where There's things that I see that are like those emperor has no clothes moments. I'm like, if that would only change, and hearing more people say the same thing becomes kind of a self-validation too. A lot of it is building on me wanting to hear more about what I think I know is right, but getting some validation, but also sharing.
I'm a big proponent that people need to work more with inside the cybersecurity community to talk to each other and share stories because that's all how we learn. So I'm just looking through some of the folks you've talked to so far. You've had a good group of people you've chatted with on the show. Would you be willing to share a favorite moment or two from the interviews you've done? Well, obviously the one with Rob Recanale was the best one ever.
Clearly, clearly was the best interview. Yeah, yeah. But the way, you know, is it— I would say it was more like there's been more of this commonality. So James Carder, who's, you know, CISO of Alogrhythm up here, I did an episode with him, and then I did Kristin Goodinson from Google. It's like where I see these themes when I do them back to back often, and whether there's some bias where I'm pushing them or not, I don't know, but the last 2 episodes we talked a lot about automation.
It's like where you see there's this theme where, God, we need more automation, less analyst work doing data extraction, more people looking at the things that matter, and see those types of trends. I would say for the first 10 or 15 episodes, there was a big trend on the fact that people in the cybersecurity community don't communicate well enough, both verbal and written. There's just these things that keep coming out over and over again from doing these episodes. I'm like, those are the common problems that we need to try to solve. You did get to talk to Troy Hunt, it looks like.
I did. Troy is one of the luminaries in the industry. How was that? It was great because he's just got such an outgoing personality, very easy to talk to, very bright. It's one of those where it was kind of selfish too because I had to know, why would you make a site like Have I Been Pwned?
That had to take an enormous amount of resources, investment, but to hear him talk about it and say, well, no, this is something that I wanted to do as a passion project, and I like helping people. I like to hear him talk about how he spun it into a marketing thing and helped develop his career. It was really cool to hear his story about how he got to where he was on it. You talked to Theresa Payton. She was, if I remember correctly, she was the CISO for the White House?
For the White House, yeah. Any special learnings you got from that conversation? Yeah, it was interesting. Again, on the communications, we talked a lot about how to be a CISO and how to talk about risk in business. And how to position things not to be— cybersecurity issues too often fall heavily on IT, and how to bring it out of the IT conversation and talk about it on the business level about risk.
I guess the last one I'd say is Gary McGraw. He's another huge name in security. Any specific learnings from that one? Yeah, we talked about specifically going back to the earlier conversation, craft cocktails. He's got some good ones.
He's got Deliverall. What's funny is I Immediately, I think I was sitting in the room at ShmooCon a year ago watching him give the keynote address, and I started tweeting him. I'm like, can you be on the show? Like, he just had that personality. He's got such a history, and he was just— he's just one of those, you know, kind of godfathers in the industry.
I had to talk to him. He certainly is. Yeah, it's certainly a cool opportunity to get to meet with him. Yeah, and I'm sure I'm gonna give out a secret that probably both of us have, which is, you know, one of the cool things about having a podcast is when you ask someone to talk to you, they usually say yes, even if they usually wouldn't say yes otherwise, right? I know for me, that's a big part of doing this is I just get to meet cool, you know, new people and have a lot of fun.
It's insane. I've learned so much from it. There was definitely a part of it that I said, I definitely want to learn more. Like, there was just these things that I wanted to hear, question people about that I knew had I walked up to them in the street like a crazy person, they would get away from me. Yeah.
But hey, I'm gonna put a mic in front of you. They're like, oh yeah, I'll sit down for you an hour and tell you anything. Yeah. Otherwise you couldn't have got an hour of their time if you paid it. But no, so you got a podcast and they're willing to listen.
It's a good thing. So the next topic I want to ask you about is really what it's been like in Colorado so far. You know, obviously we are a fully Colorado-focused podcast here. What's the industry been like for you in the last year or so? It's amazing.
It's got this weird energy. I would say weird, that's amazing mischaracterization because it sounds almost negative, but this is exciting energy. It's very different than what I think I felt in New York and with my counterparts even in the Bay Area, where people were definitely a little bit ground down, jaded, bitter. Here there's an excitement and energy that I— it's invigorated me. Any idea what the difference is?
I think there's a lot less pressure. I mean, there's definitely the cost of living, the cost of perform. You know, it's— I felt it was funny, and this is a weird kind of example. So friends of ours own a distillery up in Brooklyn— I'm sorry, in Boulder. And I was thinking about, you know, they own this vodka and gin distillery.
They'd almost do it as a part-time thing. A couple other friends have invested in it. Their overhead's reasonable. They can do this as a kind of a passion project. When I talked to distillers that were in Brooklyn, you know, they basically— I was, and I have been part of nonprofits and different types of groups in New York City where I said, hey, look, would you like to, you know, have your alcohol as part of a sponsor for this event we're doing?
Like, honestly, we can't afford it. We— no batch that we make can go to waste. We're on such thin margins. Yeah. And when I talk to the people out here in Denver and Boulder, they're like, no, we can experiment.
Like, that pressure's off. They can actually try to think and try different things where there's not that fear of failure is gonna completely completely wipe you out. Yeah. And I felt that that was so much of the difference of what you see, particularly in the startup community around here. And it's just where people are willing to take risks because they don't feel like, God, if I don't, you know, do this, I have no room to pivot, I'm just gonna die.
Yeah, that's, that's interesting. I know you've been pretty active on our Slack channel. That's been a pretty cool thing. Have you met anyone cool through there? Any good relationships?
Yeah, you know, starting to develop. Yeah, there's just different people, even people that I've gotten to know. Um, it was funny, just even though I work with SecureSet a good amount, you know, just talking to people that are on the Slack channel that are potential hires. Yeah, um, got to ping James Carder, uh, you know, to get him on the podcast over some people that he had that were available from interns. I think you stole from me, unfortunately.
Uh, but you know, it's just getting to talk to these these different people in the community. I actually had somebody that came over from Mandiant FireEye. He just moved here 2 weeks ago. I was like, first thing you do is we've got to go get a beer. Second, you've got to join the Slack channel.
You've got to get to know the community because it's a very welcoming community. It's been a really neat thing getting to formalize what does the Colorado security community look like and getting some more form around that. I guess I give you the opportunity. Is there anything you wanted to share with the community before we, uh, before we call it? Yeah, you know, I would say just keep contributing.
I mean, there's, there's obviously a lot of events that are coming up like RMISC, BSides, and they're, you know, the one thing that I've always said that when people say, you know, how do you, how do you get more involved? You do it. You just get more involved. You know, you volunteer, you go to the conferences, you meet people. Um, you know, most of the people that I've met here, again, have been almost everybody has been completely welcoming.
You can go up, talk to them, ask them about different things about the security community, what's going on, and everybody's very welcoming here. That's the big thing I would say is just get out there, get involved. I'd add one little point to that. I'm a huge, huge fan of getting involved and volunteering. It's not always as easy to volunteer as you'd like.
You want to get involved with something like Denver BSides, there's no full-time people who are running this thing. You have to be a little bit persistent. To be able to get looped in. One note is probably not enough to really get in the door, but it's worth it. That's how you meet all these great people and get involved with the relationships.
BSides, RMISC, OWASP, Cloud Security Alliance, InfraGard. I could keep going. There are so many good groups in town that could use your help. Anyone listening who wants to get involved, I highly recommend you listen Listen to Douglas and do it. Well, cool.
Thank you very much for your time. Looking forward to seeing what happens, and we'll put a couple links in the show notes to your your podcast and to your into Kivu's website for jobs, and we'll look forward to talking to you soon. All right, Robb. Thank you. See you later.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming upcoming security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.