Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 68 for the week of May 21st. Alex, how are you this morning?
I'm doing all right, Robb. How are you? I'm doing fantastic. We're ready to kick off yet another fantastic week of security here in Colorado. I'm looking forward to it.
Every week is fantastic. Last Friday, Alex, you and I were scouting out potential keynote comics for RMISC next year. We were. Good times. Had a good time.
We had a guy with a very significant beard as one of our comics. Yes. A very skinny man and a woman named Taylor as potential options. Yeah, they were all fairly funny. They were all fairly funny.
Why don't we go ahead and dive into our stuff? To start off, I do want to remind you we have a Slack channel. This is a Slack channel that's not specific to the podcast. It's meant for all of Colorado security to get together, get to know each other, and, and have a way to ask questions of one another. Yeah.
So come hang out with 400 of your closest security buddies and have some good chats there. You get a link to get into the Slack channel from either the front of our website or the show notes. Also, please review us on iTunes if you subscribe through there. We would love to have a good rating on that. And we also have a mailing list.
If you go to the website, you can sign up there and get the show notes and things like that mailed to you directly. And if you love what we do and you want to help us keep doing it, we have a Patreon set up where you can give some money to help support the cost for the podcast and stuff like getting the stickers out to the community and the things we'd like to keep doing. So go out to the website and click on the Patreon and take a look at the options out there. And along the Patreon lines, I want to give a shout out to Chris Merritt, who was— I on one of our interviews last week. He signed up to be a supporter this week.
He actually signed up as a $25 a month sponsor, which is pretty incredible. Thank you, Chris. Thanks, Chris. Appreciate it. So let's go ahead and jump into the news.
Yeah. So Denver is— so the headline, Denver is still one of America's fittest cities. But I'll say I'm pretty disappointed. We went from being number 3 all the way down to number 7. Yeah.
And I think a couple years back, we might have even been number 1. So lay off the donuts, people. Exactly. The rest of the top list: Arlington, Virginia is number 1, Minneapolis is number 2, Madison— excuse me, Washington, D.C. is number 3, Madison, Wisconsin 4, Portland is 5— that's Portland, Oregon— and Seattle is 6. Well, we're still doing okay, I guess.
So the least healthy city in America: Oklahoma City. Nice. They do love their barbecue, and that doesn't surprise me. I will say we don't see Austin on the list with us for most healthy cities, so they might be beating us at a lot of tech stuff, but not at this. Well, at least that makes me feel good, Robb.
Yeah. There were 2 other Colorado cities that made the list. Aurora was ranked at number 22 and Colorado Springs is number 24. Good stuff. Next, there was a survey that was done that looked to quantify the business impacts if Colorado was the number one state for education.
So basically, next time someone says to you, we can't afford to fund our education and become a world-class education place, you can show to them this survey that shows, well, actually, we'd make a lot of money if we did. Yeah, there was a, a big positive upswing in, you know, overall GDP and other numbers, lots more jobs. By us having a better education system. So kind of an interesting survey. Yeah, interesting.
So we have some news that it looks like Slack has been considering whether to come to Colorado for an HQ2. We're offering them— was it like $10 million in tax incentives to open an office here? It's, it's not quite an Amazon HQ2. It's only looking at, you know, a little under 600 jobs, not, not 50,000 or whatever Amazon would bring, but still pretty cool. So they have confirmed, Slack has confirmed that they will be opening an office in Denver this year, but they have not confirmed whether it's gonna be their second headquarters or it's just another satellite office.
So here's hoping Slack comes to town, and we're also hopeful that we can convince them to throw in a free Slack license for Colorado Equal Security so we can have the good stuff where we don't run out of message queue. Exactly. There was also a story this week um, on Built in Colorado, a number of different companies that are looking for senior developers. So we put this story in here because one of the companies on that list is, uh, Red Canary, who, you know, we've had Brian Bear on the, on the podcast before and we've talked about them. Um, also Casey, Casey Smith.
Yeah, um, great local Colorado company. Uh, excited to see those guys make that list. And of course, if you're a developer or an SRE looking to work with a security company and lots and lots of data They'd be a good place to talk for sure. All right, let's jump over to the security stories side of things. Number one, the really the report we've been waiting for, you know, pins and needles.
I know I've been waiting for it. Quite a while is finally the Cybersecurity 500 is released. And guys, there is a new number one. Da da da da. After what was after you know a bunch, thirteen in a row or whatever.
Root nine B is no longer number one, and in fact, you have to scroll quite a ways down the list to find root nine B. They're now number 148. Alex, how would we explain this drastic change? You know, it's hard to say, Robb. I'm thinking maybe they got confused because, you know, Route 9B was, you know, spun off from Route 9B Holdings and, you know, there was some kerfuffle around that.
So maybe they just got confused about who Route 9B was. So we are not making fun of Route 9B. We are making fun of the Cybersecurity 500, which I— all I can guess is you know, how much money you pay them is how high on the list you show up. And Route 9B probably stopped writing a check. And, and as a result, they got dropped 147 points for no apparent reason.
There were a number of other Colorado security companies that were on the list. Optiv, Webroot, Level 3, Respawn Software. Level 3 doesn't exist anymore, but I'm glad to see that they made the— Yeah, same difference. We all know that it really is Level 3. They just call it CenturyLink.
Yeah, so there are a bunch of— but the companies, like you said, Respond Software, Route 9B still on the list, LogRhythm, Ping Identity, Red Canary, and InteliSecure on the list. I don't know what this list is for other than, you know, marketing materials for number one. Right. It's, would you like to find out the names of 500 security companies? Check out this list.
Moving along, we do have a new survey that was released by Optiv. They call it their Cyber Intelligence Report. And they say that it reveals the state of the cybersecurity landscape. Yeah, there are some findings that they pulled out here. Maybe the most interesting finding on the list is there is— they call it the rise of Netherlands and Lebanon.
Apparently, these guys have stepped up their game into the state actor world. Yeah, I think some of the other findings were maybe not as revolutionary.
You know, cybersocial is the next wave for nation states. I think we've seen that with Facebook and, you know, election hacking and other things like that. Critical infrastructure has been breached. We might be aware of that already. Healthcare IoT is vulnerable.
I think I might have heard that one. Phishing remains the delivery vehicle of choice. I think we all know that. Yeah. So these are just the highlights.
I'm sure that there are other highlights if you read the entire report. So you may want to check that out. Next, there was another Optiv blog that was entitled Dear Directors, It's Time to Do the Right Thing and Elevate IAM. So I'm sure this one goes straight to your heart, Robb. Well, and their point is basically make sure IAM has a good leader in your organization and start looking into zero trust networking as the way to solve that problem.
And both of those are good, reasonable points. So hopefully— I would agree with that. If you can get this into the hand of your board of directors and they're willing to read it, I think it'd be good. Next, CyberGRX had a blog this week about 6 security controls that you need for GDPR. On the same theme as the last one, the number 1 control they mention is identity and access management, followed by DLP, encryption, and pseudo— not pseudonymization.
Thank you. I appreciate your help on that word. Yeah, so all good stuff. They also talk about incident response. Policy management, and not surprisingly, third-party risk management, since CyberGRX is a company that does third-party risk management for people.
Yep. Uh, next blog post, we have one from Ping that's in, uh, it's actually part of their, uh, Privacy Awareness Week in Australia. They give some tips to help support your privacy. I'll go through the list pretty quickly. Don't reuse passwords.
Create a secure password. Use 2-factor authentication. I think I would have put that as the number one on the list if it were me. Um, stop and think before you share. Stay safe on social.
Not sure what that one means, but we're not going to read it. Uh, be skeptical and don't reveal passwords on the phone. And by that they mean don't get on the phone with customer support and give them your password. Yeah, good stuff. Um, and then the final blog we had this week was from Coalfire.
Um, it was a Cyber Engineering Primer, Tools of Compliance Auditing. So this is actually an interesting blog post. Um, they talk about some potential tools that you could, uh, you could use to do configuration management and auditing. So essentially making sure that the configurations of the machines and systems that you have do not drift, that they stay the same. Yeah, they do a good job.
They talk about some, some commercial ones, Nessus, Qualys, uh, Nexpose. But then they talk about some that are not— that don't cost money too. They talk about Puppet and Chef. Um, there's some other stuff here, also some PowerShell stuff down at the end. So yeah, um, actually a fairly interesting blog post, some good suggestions in there.
So if you're looking to do configuration management auditing, check it out. So not a lot of news this week, but we do as always get to do a Slack message of the week. Uh, first of all, thanks to Andre Gaeta who sponsors this out of his own pocket. We appreciate that very much, Andre. This week's Slack Message of the Week goes to Rick Hill.
Rick notified the Slack channel that he saw Slack coming to town, and that started an interesting conversation about having Slack, maybe their HQ too, here in Denver. Robb, that is so meta, a Slack Message of the Week about Slack. I know, I think it's basically a giveaway, right? And if someone could have a, you know, go one level up, right, have a message next week about this week's Message of the Week, I can't see how that wouldn't work. I think that, I think we've given away our secrets.
So, so congrats to Rick. You know, let us know what item from the Colorado Equal Security store you would like, and Andre will get that ordered up for you. Awesome. So let's go ahead and move over to events. Um, first, we do have our event calendar that is on the website colorado-security.com.
So go check that out if you want to see the latest events. And the first one that we have for this week, uh, May 22nd, uh, GDPR in effect, Trimble, a test case. Yeah, so GDPR does go into effect this Friday. If you guys are just learning about it, don't worry about it. GDP what?
You'll be fine, don't worry about it. On the 22nd this week, we also have a meeting at SecureSet, which is their career conversations with Kalia Garrido from Skylarq Digital. And in case you didn't have enough to do on the 22nd, ISSA Colorado Springs is doing a Women in Security event on the 22nd. On the 23rd, we have the GDPR and data privacy in the US. Interesting.
On the 24th, SecureSet is doing one of their capture the flags. And that takes us through the next couple of weeks. We actually— there's actually amazingly nothing on the calendar the week after. Well, next week, I guess, the week of May 28th. So if you're looking to play in something, that's a good week to do it.
Or if you're looking to take a vacation, that'd be a good week to not miss anything. Finally. Yeah. Moving over to jobs. Number 1 job on the list, number 1 on the list, number 1 in my heart is at Ping Identity.
We are hiring a senior security analyst, looking for someone who really understands how technology works and wants to help us optimize and perfect our infrastructure security. Also at Ping, we are hiring a site reliability engineer who focuses on security operations. You have to know how cloud IaaS and platform as a service works But we'd love to have you come work at Ping and work on our security projects in the cloud. Next, AMR is looking for a CISO/VP of IT. So AMR is American Medical Response.
So there you probably think of them as ambulances. Yep. Very good. Charles Schwab is hiring a technical director, cyber threat risk management. That's a big title there.
It is a big title. Fidelity Investments is looking for an IT audit director for enterprise cloud computing. I figured if we were going to put Schwab on the list, we couldn't not put Fidelity on the list. Yes, it only seems fair. You know, Fidelity, you know, I know we all know Schwab has a really big office down in Lone Tree on Lincoln Boulevard.
They have massive big offices now down there now. But Fidelity actually has a pretty good-sized presence in the Greenwood Village area, right, right next to, to the— oh my goodness, the concert hall. Fiddler's Green. Right next to Fiddler's Green. Yeah.
They have several, several floors of that big office building that's attached to Fiddler's Green. Nice. Next, Denver Health is looking for a Security Analyst III. Western Union is hiring an Information Security Manager Compliance. CenturyLink is looking for a Senior Information Security Engineer for Firewall.
NREL, that's the National Renewable Energy Lab, is hiring an Energy Security and Resilience Analyst. That sounds pretty cool. It does sound pretty cool. I don't know what they're doing, but that sounds cool. I don't know what kind of skills you have to have, but I assume that they're skills I don't have.
And then Spectrum is looking for a Principal Security Engineer 1. And Spectrum is basically Charter Communications brand name now, right? Correct. Yeah. And Spectrum is another one that just put up— they put up 2 buildings in the last— yeah, they've got a lot of presence now.
Yeah, right, right on both sides of 25 out of Arapahoe. Anyway, that takes, that takes us to the end for jobs and really takes us to the end for the newscast. We're gonna throw it over to our feature interview, which is with Rich Schliep. Rich is the CISO for the Colorado Secretary of State. You know what that means he does, Alex?
He keeps the state's secretary secure. That's exactly what he does. He also keeps our voting infrastructure, our election security safe. And of course, any business that, that wants to do business in Colorado has to register with the Secretary of State. So all of, all of those local companies we just talked about, they care a lot about what he keeps secure.
Awesome. All right, that's it for this week. Thanks, Robb. All right, talk to you later. This is David McGuire, Director of IT Security at QEP Resources.
This is Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.
All right, this is Robb Reck. I am sitting today with Rich Sleipe. Rich is the CISO for the Secretary of State of Colorado. Rich, before we dive into talking about election security and what it's like to work for the Secretary of State, I want to know about this new hobby that you're getting involved with. It sounds like you're starting to get into biking.
So talk to me, and how do you go from not biking at all to spending, you know, a month's salary on mountain bikes? Well, you have a friend that moves from Silicon Valley who tricks you into thinking this is just a minor hobby. And before you know it, he's got you and your son up in the mountains on his mountain bikes. Yeah, that are incredible because they have shocks on the front and the back and it's really smooth and you can drop your seat and all these new technologies you've never seen. Yeah.
And then he says, well, you know, you're really liking this, you should do this with us a little more often. Yeah. And before you know it, he specs out your bikes and you don't know what you're buying and you have 2 brand new mountain bikes that you're, you're going to be out on every weekend. Then he lets you know that he's into, you know, competitive racing and wants to start, you know, going different places. And you're like, whoa, wait, whoa.
So that's a whole different bike, right? Yeah. So the mountain bike is, uh, is what one costs, and then the racing bikes, those things can be— No, he tried that. No, he's talking about competitive mountain bike. Oh, I didn't even know that there was racing mountain bike.
I thought it was just— All right. He tried to get me a road— to buy a road bike after that. Yeah. And I was like, no, that's enough. Hey, There's got to be a limit somewhere, huh?
So have you been enjoying the new hobby though? Yeah, yeah, it's been great. I love getting outdoors. I'm from the mountains originally, so being able to go around and visit places and be outside is a great thing. Well, it seems like a good place to start.
When you say you're from the mountains originally, what's that mean? So I grew up in Grand Lake, Colorado. I grew up, you know, up there we had 4 days of school and then we got to ski for free on a day. Oh wow. So I got to be a really good skier.
I went to Winter Park and Silver— or Sol Vista, Silver Creek at the time. Sol Vista is the one. Yep, Granby Ranch now. I know. Oh, they renamed it, huh?
Constantly, it seems like. Yeah. So my, my family and I go to Snow Mountain Ranch, the YMCA camp, right up there every year. We make it up there, so I know where Sol Vista is and everything. That's a beautiful area.
So you grew up in Grand Lake itself, is that right? Population what? How many people lived there at the time? 360. 65, I think.
So one person per day. So everyone could have their own day every year. That's pretty good. That's a small population. Yeah, I graduated obviously the Central High School in Granby.
Yeah, I graduated with about 70 to 80 people. So there's— they're pulling in a lot of folks from Winter Park and Fraser. Okay. Yeah. Okay.
I thought you were gonna say I graduated first and last in my class. That's what I thought you were gonna tell me right there. All right. So how did you go from growing up in Grand Lake to getting down here, down the mountain? Uh, so I went to college at Colorado State University.
Okay, uh, go Rams! Yeah, I love that place. Uh, it was a great place. That's where I met my wife, actually, our freshman year at the ice cream social. Oh, nice!
We were married— she the first girl you met then after graduating? Yeah, yeah, yeah, exactly. Yep. And, uh, we've been married, uh, for 23 years this summer now. Congratulations.
But we, yeah, we met at the ice cream social in the dorms, in the engineering dorms. Yeah. And then, uh, Uh, what was your, uh, what'd you study at CSU? You know, I started as civil engineering, um, and then I moved into, uh, construction management. Okay.
I grew up building log homes, so I grew up like hand peeling logs and doing the Lincoln Log thing, literally, and chiseling them out with a hand chisel or electric chisel, but still by hand. That seems like a really inefficient way to build a house, but very unique, and people with, uh, money like that unique look. So how do you, how do you weatherproof a log home? So the ones that we did, we did it the, the old-fashioned way. We actually did chinking in between the logs.
What's that? So it's a basically acrylic type of what used to be cement, but now it's more of acrylic based. You put it so it can expand and contract easier. So you put like an insulation called backer rod in there to in between the logs to kind of stuff them. So you're stacking the logs together and there's like parts that you can see through, right?
Yeah. But some parts are probably hard or there's no gap at all, I'm guessing. Right, right. So how do you get anything between the logs then? So we actually had a machine that basically squeezed it out like toothpaste.
Okay. Basically this chinking material. Yeah. And you would smooth it out in between the logs and it would form a solid barrier between the gaps in the logs with a foam insulation behind it. So it sounds a little bit like caulking when I, when I caulk around my tile.
To hide my mistakes. This is, this is the, the log cabin version of that. Exactly. Yeah. And does you— does building a log cabin cost way more, a little bit more, the same versus, versus using framing?
I, I would say it's probably 30% higher is my guess. I don't know, it's been a while since I've done it. But so how— so you— how many log cabins did you build? Oh, Well, I did it every summer. Yeah.
And then I did it for a little while after that.
Me personally, probably 15 to 20. So it's a pretty big endeavor to build one. Yeah. So you haven't built one for yourself yet? No, I've thought about that a lot.
Yeah, I've thought about doing that. I mean, that would be pretty awesome to live in a house that you built with your own hands. And yeah, just like Abe Lincoln did. Yeah, maybe a little bit better weatherproofing. Yeah, it was funny.
My stepdad, uh, always wanted to make it sure we could build the log homes indoors, and he finally did that. So he built a huge indoor facility to where they— that with a crane on the ceiling so you could build them indoors. Yeah, he did that for a few years, but, but now he's, uh, retiring. Okay, he's pretty much hanging it up now. Well, that, that is really interesting, the log cabin stuff.
Let's— but let's go a little bit further forward. Uh, you went to CSU, Civil engineering, construction, and then what? So after I got out, I went to work for a company called RK Mechanical. Great company. Uh, I went there, I worked there for about 3 years, and they were good guys.
They, they gave me the opportunity when I realized that I wanted to move out of construction management and into computers to actually be their IT guy. And from that point, I got, you know, the famous MCSE, and I learned— 2000, '98, which MCSE did you get? Try to place you. NT. NT?
NT4? Yeah, NT4. Okay. And then upgraded from there, but learned Citrix really good and came to the state as a Citrix administrator. So you went over to— you said you came to the state, you mean Secretary of State's office?
Yeah. And you've been there for a long time, right? Yeah, 17 and a half years. 17 and a half years, you came in over as a Citrix admin. Yeah.
And what's it been like? You know, obviously you've had the opportunity to do different stuff there. Well, maybe before we do that, give me— I was surprised when you said this, this, the organization wasn't as big as I was thinking. How big is the Secretary of State's office? You know, we only have about 125 people plus some contractors, so it's fairly small, but we're really an IT shop.
Yeah. When you look at our business, we're definitely in the business of information systems. We're a big filing cabinet. We deal with data and elections. Everything is centered around that.
We have a fairly large development staff, probably around 30, and then we have another 15 to 20 administrators in those type of roles. Your area is, I assume, the IT administrator area where you were just talking about, right? Yeah. When you came in 17+ years ago, how has it changed since then? Has it grown, or are we about the same size as we were back then?
Drastically changed. We used to have people come in our office. A lot of stuff wasn't online. Yeah, we've moved almost everything online, you know, registering your business, registering to vote. You can do almost anything with our office online now instead of having to come down in person.
So we're definitely focused on that web presence and making it easy for our constituents to, to do business with us. Um, years ago, I was— when I was first hired, I had 4 servers. And I was— servers— we were a Unix shop. I was told the Windows side would never grow any bigger. Now we have a lot more Windows servers than we have Unix or Linux at this point.
Sorry, that's new too. We used to be a Solaris shop and now we're Red Hat.
You guys have gone through a digital transformation, right? You've made your customer experience, which is of course all of us citizens, a lot easier. I know I've used you guys for the for, you know, a business registration before, and every year I get a little reminder. So I appreciate, appreciate making it easy, and I don't have to drive down and, and go see you in your office in person. Yeah, that's a good thing.
I guess you used to mail letters for that stuff too when you started? Yeah. Yeah. Okay. So, you know, when you were hired, you were really on the IT side.
So how is that migrated? Talk to me about, you know, in your time with the Secretary of State, how has that changed? So I started out as a course, a Windows administrator, and then I switched over to the Unix side and became a manager of Windows and still a Unix administrator, managed our web platform based on Java at the time, and then quickly moved into network after that, and then eventually became the security guy. So I kind of did every role there before moving into network security, which has been a huge advantage because I'm familiar with all the systems that are there and how they operate. I've really enjoyed it.
They've given me a lot of opportunities. So when did you, when did you make the move to take on the security responsibilities? What year was that?
About 10 years ago. 2008-ish? Yeah, I started moving into that role. So back then, you know, Mark Weatherford was the first state Chief Information Security Officer. Harley Arneson was to some degree before him.
But officially, I'm On paper, it was Mark Weatherford. Yep. And so Mark really encouraged people to start going into cybersecurity, and then Mike Weber was really the one that sat down, who's now at Coalfire. I was going to say from Coalfire, yeah. And encouraged a whole bunch of us to get our CISSPs.
What was Mike's role? Did he work for the state somewhere? Yeah, yeah, and he actually served as the interim Chief Information Security Officer for a period of time. Was he after Mark then? Yeah.
Okay. We need to get this on the website somewhere, the chronology here. Yeah. So he, so, you know, you were working with those guys and they kind of inspired you to move after this, is that what happened? Absolutely.
I mean, they set the state up, Mark and Mike, and then of course Travis Schack eventually as well, with a lot of success. I mean, they laid a strong foundation. Mark having the state policies, setting up a strong security presence for Colorado and laying those foundations that we've been able to build upon. Yeah, so when you moved over to— were you the first security person for the Secretary of State to do this? Yeah.
And what do you know, what kind of inspired them to say, hey, we need someone to really be paying attention to this and not just have it be, you know, an and also for everyone's job? Really, it was the whole state of Colorado government realized that we needed CISOs, or we needed ISOs at that time, in all the departments. Yeah, to really pay attention to security. I mean, it was a big deal in Colorado, and really thank Mark Weatherford for that. I mean, he kept pointing back to that and showing us what the needs were and laid the foundation for it.
It was— so what do you— what was it, do you think, that— was there a precipitating event that something bad happened that made him say, hey, it's time to get serious here, or was it just an evolution? I think it was more of an evolution at that time. Okay, the It's hard to remember if there was something bad, because there's been so many bad things that have happened over the past— we've been very, very busy as a nation improving our cybersecurity, obviously. Yeah. Okay, so, you know, that's 2008, you really started to focus on security, and I know you still have your hands in some of the IT work as well.
What has it looked like, you know, to go from a world where all of our ballots were cast either via physical mail or, you know, really kind of low-tech voting systems, which I assume was the case when you started there in 2001. I shouldn't assume, but that's what I would assume. Yeah. And then how does it look to go from that to really, you know, quite connected devices and seeing just a ton fewer in-person votes and having those more connected systems? What's that— how's that changed?
So as far as the voting systems, It's a little harder for me to outline that because I wasn't involved in that in the very beginning. I've gotten much more involved in the voting side in the past 4 years as far as, you know, the voting machines themselves. Prior to that, you know, we had the centralized voter registration database. We had HAVA that came along that was passed after the issues in Florida. You had what, sorry?
The Help America Vote Act. Help America Vote, what's that? So that basically said states have to have a centralized voter registration database instead of each county managing their own data. And that happened after the issues that occurred in Florida. So you're talking about the recount Miami-Dade County Bush-Gore, Bush-Gore, right?
I believe so. I think it was Bush-Gore, 2000. So how has that, HAVA, how has HAVA impacted you guys? So we have a— we've really led the way in a lot of ways in Colorado. We have a centralized voter registration base that's of course protected by 2 authentication.
We were one of the first states to do that. Yeah, we've obviously put a lot of security controls and thought around protecting that citizen data and continue to do so. So do you have to give access to, to this central database to all of the counties? Yeah. So you have to manage, you know, how many counties do we have in Colorado?
64. So 64, you have to manage 64 counties trying to get access back into, into the central database that that you guys have ultimate control over. And one of the unique things about Colorado is we have same-day voter registration. So it has to be real-time and up-to-date. And so do they register like at the polling place?
I don't believe they can register at the polling place, but they can go register to vote. I'm not sure about that, they might be able to. It seems like that would add a degree of difficulty, right, if you have to make it bidirectional, they can edit and read, and all that. Interesting. So, you know, obviously, and I do want to talk a little bit about election security and learn more about that, but before we go down that rabbit hole from which we may never return, what are some other elements of security for the Secretary of State that I, that I probably didn't think of?
So we have business registration, business licensing, we have charities, charitable, we have those different pieces in our office that obviously are important. Yeah, we actually just a few weeks ago on the show covered a story that in 2017 we saw another like 100,000+ new businesses start in Colorado, and it took us to like 600,000 new businesses. I assume those numbers are all coming from you. Is that right? Yeah.
Yeah. And what kind of services do you guys offer for those businesses? What's, what's the value? Why sign up with the Secretary of State? Well, of course you have to be registered as a business in Colorado to do business.
Sure. So beyond that, we are working with like Colorado Business Express and stuff like that to provide a central spot in the state. I know SIPA is working on that so that you can go to one spot and get all your resources as a new small business. Yeah. The other thing we've actually been talking about is trying to figure out how we can provide some security resources to those businesses at some point.
We haven't done that yet, but thanks to Colorado Equals Security, I've actually been talking to some of the other CISOs about the possibility of meeting and seeing what we could do. If you think about if a small business in Colorado gets ransomware, that could put them out of business. So we want to at least point them in the right direction so they have resources to look at. Yeah, it's so frequent that we talk about fundamentals about what everyone should be doing and, you know, hey, you should have 2-factor, you should be upgrading and patching your systems. And I think we're imagining some office with 50 people in it.
Whereas the vast majority of our companies are like a 2-person flower shop or that little consulting company that just don't know anything about security. If we could provide resources for those companies that make it easy, how do we do that? I don't know if we have an answer for it, but it certainly is a question worth trying to solve. Do you need help from anyone in the community? Do we have people listening who want to help?
Yeah, we are going to ask for that help. We aren't quite ready yet because I'll Obviously we're getting ready for a huge election cycle. Yeah, but we have been discussing it internally and we're gonna set up some invites that'll go out to your group to see if you can come in and talk to us and help. So what's this, what's this election that's coming up? I haven't heard about this.
You want to share? Obviously, obvious to me at least, one of the interesting things in 2018 is that we now have open primaries. Has the open— and what that means is, is that anyone can vote in either the Republican or the Democrat primary regardless of how you're registered, but you can't vote in both, right? How has that impacted your office? So we've had— we've obviously registered domains and had advertising going out to try and let the constituents know what they should do because it's gonna be confusing to some people.
Yeah. And so we've spent a considerable amount of time figuring out how we can reach those individuals through UChoose, basically campaign So that they know that they have to choose and they can't vote both. Yeah. So what happens if you vote both? We'd have to talk to our elections director about that.
I'm more the cyber guy, but I think that it comes down to whichever one is received first. But I'm not 100% sure about that. But I won't quote you on that. Don't quote me on that. That's an elections thing.
Yeah. Interesting to know. So obviously the services you offer around businesses, it sounds That sounds very interesting. What are the security ramifications of that? Obviously, you have to protect the website, but anything else you want to share on that?
So there's other important pieces with the business, just like your personal information. You need to protect it. And so we've done different steps to allow businesses to actually put a password on their account. For instance, if you were going to do business identity theft, the first thought would be to change information on the Secretary of State's website for a business and claim that you were the person that owned that business. So are you guys looking for that kind of fraudulent behavior as well?
Yeah, and we do work with law enforcement, of course, when we see those kind of issues and a lot of times give information on that. It seems like it would be a really nice thing to find as soon as possible, right? Yes, yes. And probably very difficult to find. Yeah.
So, you know, I'd love to jump over and talk about the election security stuff a little bit. Obviously, the 2016 presidential election became, you know, one of the major headlines was, you know, foreign influence, foreign interference with the primaries, with the election itself, with, you know, trying to just sway voters or maybe just So regardless of whether there's any actual hacking of an election, I think that it just all of a sudden became really top of mind. And since you have 17-plus years experience there, I'd just ask you to kind of talk about, you know, what did things look like in 2015, 2014 compared to how they look now? You know, do you have a before and an after you can share? So Colorado's really made a continual effort to have excellent cybersecurity.
Obviously, we laid that groundwork. Things have been changing a lot. We've prepared a lot more to answer media questions. Yeah, we've obviously continued to increase security around our voter registration database and monitoring and our databases.
Things have really ramped up. I've had a busy few years. We've, we've really ramped up our incident response plans and just our overall monitoring of our systems to look for those type of activities. So do you— obviously there's, there's the active part where you're trying to fix it, but then I, I assume you're— you've got to just be hearing a lot of noise around it as well, right? And do you get pretty well insulated from that, or are you, you know, are you in the firing line hearing from federal officials, city officials, municipal officials?
You know, every, every county wants to talk about it. Is it Is this, is this how it is? What do you think? So we actually enjoy talking about it. Okay.
We encourage it because we want people to know what really is going on. We want them to know the accurate news or the accurate bits of information. The, uh, we've established some really strong relationships in Colorado. Um, as you've read probably recently, the Colorado National Guard has helped us the past few years during the election, and we've actually worked on them with as an exercise part of the Regis tabletop exercises we worked on in the past to get them involved more on an exercise level so they can help us monitor. And it's all because of the relationships we built with them out of the Regis University.
Yeah, along with that, we have a very strong relationship with our counties. We just recently ran a huge tabletop exercise which was also in the paper of Cyberstorm 6, which was put on Homeland Security so we could walk through all the cybersecurity issues and possibilities and continue to improve our incident response. So back me up. You said the Department of Homeland Security put on an exercise. You said Cyberstorm 6.
Cyberstorm 6, which sounds like the exact kind of name that you expect the government to come up with, right? So Cyberstorm 6 was what? So basically it was a tabletop exercise where we had county players Okay, was it, was it like the whole US, all the states involved? People opted in? Was it one state at a time?
So they select different states to participate. Okay, several states participated this last go-around. Yeah, I'd say there's about 5 states, I believe. Okay, Colorado obviously being one of them. Now there's 5 participating states, and there was about another 6 or 7 that were watchers just to learn from the exercise.
And basically it's like any other tabletop. We work with them to plan it and we were— us and one other state chose to do elections. The other pieces— Oh, so it wasn't necessarily an election exercise, this is just some kind of cyber exercise and you guys picked what the topic was? Yeah, and we tried to coordinate it with the other states to some degree, but because we chose elections, we were a little bit separate. Okay, so what was the scenario?
Well, we walked through a lot of different scenarios. We walked through what could happen to the voter registration database, we walked through what could happen under a physical attack. We walk through what would happen if you walked into your polling place and saw a rubber duck sitting on the side of your computer. How would you respond? If I walked into the polling place and I saw a rubber duck next to my computer?
Yeah, or yep, exactly. Why would that be a problem? This doesn't sound that bad. So no, rubber duck device from Hak5. So the Hak5 USB device that actually takes control of your computer, we actually put that in the simulation.
Gotcha. To train counties and other staff on what to look for. Why it is dangerous to have a USB device plugged into your computer if you haven't locked it. Yeah, or even if you have locked it, with a lot of the new stuff, we got this pre-boot compromises that have become pretty well known. So kind of setting the table, is this a— everyone's dialed in from a war room somewhere from the different states and there's like a an incident runner who's playing dungeon master telling you this is what happens next?
Or— so in this particular case, it's not quite like that. It is to some degree. I mean, they had, they had the kind of a war room back in DC. Yeah, but as far as our involvement, because everyone has their day-to-day jobs, yeah, it was more like you would say you would come back, check the scenario, check the inject that happened, and then state how you would respond. Yeah, in email.
Back to the, to the people running the, the game. Yeah. Or the exercise. In this case, Trace Ridpath with the state of Colorado and myself were the ones that came up with the scenarios. So for the most part, the counties, my staff, National Guard, the Colorado Information Analysis Center were all the players, and Trace and I were running the game.
Yeah. And do you think— did you come out of there with some, some new learnings? What do you get out of it? Fantastic. Every time that you run these exercises, you have a tremendous amount of lessons learned.
Yeah, we really want to work with the counties to build better templates and give them better support, and definitely saw where players could have taken different actions. And we're now— we're just, just finished, so we're doing our lessons learned meeting meetings over the next few weeks.
And so backing up a little bit further, In February, there was a story in the Denver Post about a report that looked through the election security from all 50 states. I think the group is the Center for American Progress. Denver Post calls it a liberal-leaning think tank. But they, you know, like I said, they rated all 50 states and they actually gave Colorado, they were tied for the best grade, right? And they gave them kind of your school ABCDE.
E, I assume F grades. You guys got a B, which was tied with— well, tied with 10 other states for that, for as good as it gave. And instead, you know, Colorado gets kudos for, for being the first state in the nation to carry out risk-limiting audits. So I'd love you to talk to me a little bit about this, the study. You know, number one, who is this group, and, and do you even know it?
Is this something you did interactively with them, and You know, did you learn something from that process as well? So I don't know too much about the, the group itself. We've had a number of ratings come back in saying Colorado is a leader in election security because we've done smart things. We've got a verified paper trail that the voter can see that's full page and legible. We've got risk-limiting audits which statistically guarantee that a voting machine hasn't been hacked.
What is that? What is a risk-limiting audit? So basically the mathematicians one of which being Ron Rivest from RSA. He's famous. Yeah, yeah, he's kind of well known.
He's the R in RSA, everybody. Yeah, worked on it, worked on a program that allows you to statistically say, okay, if a race is this close and this many people voted, how many ballots do I need to audit to guarantee that we don't have an issue? Okay. And show statistically that they're good, because you can, you can say you're gonna audit anything, right? Yeah.
I could walk in with 100,000 votes and pick up 2 of them and say, yeah, I audited. Right. But is that any good statistically? No. But you don't have to pick up all 100,000 either, right?
Right. Somewhere between 2 and 100,000 is a sweet spot. Yeah. And Ron gave you an algorithm to figure that out? Yeah, exactly.
Okay. And so you guys are able to figure out how big audits to do, and then you pull those off. Yeah. And what, what level of confidence— I don't know if you're okay with me asking this question. If not, let me know.
What level of confidence would you say you have that no one has been able to use technological means to sway an election in Colorado? Very confident. We haven't seen any evidence of that. It would be very difficult. We have a very distributed election process, right?
Yeah. First of all, your voting machines clearly aren't connected to the internet. Second, you have people monitoring those, and it's not like you have one county or one group that you have to go hack or one system. Yeah, you, you have 64 independent counties running elections that have been set up very intelligently with, you know, bipartisan rules and multiple people watching it, including watchers at these polling places. Yeah, to make sure that things are going smoothly.
So you're, you're pretty confident— it sounds like you're pretty confident that that we haven't. I think from what I was hearing that your confidence is not so much that they couldn't, but that if they did, we'd be able to have seen it. Is that true? Correct. I think that's the way security is today, where I can't stop the bad guys from ever being able to do something, but I can sure as heck make sure that if they do it, I'm going to find out about it.
Exactly. Well, very cool. I'd love to hear some more about the, the things that have gone on since 2016? As you know, have you, as a result of, of this just increased scrutiny, have you put additional stuff in place? And obviously stuff you're allowed to talk about, but is there anything else you could talk about there?
You know, it really comes down to the fundamentals. So there isn't any specific silver bullet in security. You know, the state of Colorado focuses on the critical controls. We focus on Going through those pieces, making sure we know what's out there. Hardware, software inventory, 2-factor authentication, complex passwords, making sure that we're using SSL VPNs with 2-factor authentication.
Your fundamentals is what it comes down to in security. I think the more layered defenses that we have, the better we are. Obviously, we're continuing to improve. Some of the stuff that we're looking at in the future that I think everyone's looking at is automation. We want to do a lot more with automation in those pieces.
Looking at the Python playbooks, I just ran— had our entire security team learn more in-depth Python by taking a great SANS course. Oh nice. I don't know if you've heard about that, but it's a really good SANS course that basically takes you from ground zero, and instead of just teaching you Python, they actually have exercises and you try and hack through different levels. To get all the way to the end. There's a, you know, it keeps growing every time.
Yeah, I think there's about 120 levels right now. Oh man, pretty cool. So another story from the Denver Post, also from February, and we covered this on the show a few months ago, you probably remember, was from the Mueller report that said that Russians had visited a bunch of different states, and one of the states that they visited in 2014, kind of in prep for the election, was Colorado. They came through here. Did you guys hear anything about this?
And, you know, interesting, not interesting? What do you think? I didn't find it too interesting. I mean, our office did release a response basically saying they didn't see any business registrations or any activity in Colorado from those people. Okay, well, so you did have a response.
I wish I had known at the time. I would have covered it. Send me a note next time. All right. So yeah, apparently they viewed or they went to 13 purple states, or sorry, maybe it was 13 people.
They went to a bunch of purple states, so the ones that could go Republican or Democrat in a presidential election, to do some research and kind of get ready for the election. Obviously, there's just a lot of interesting stuff going on there. So, you know, kind of looking at the future, where do you see security for the Department of State for Colorado going, you know, in 2018, 2019, and beyond? Beyond? I think we're going to continue to go where most of the security industry is going.
We're going to see more automation, partially just because we need— there's not enough staff, there's not enough skilled people out there. We're going to continue to try and find more talent so that we do have those people on staff, continue to train them. As far as overall security, that is a good question. As far as what's going to happen politically, I mean, imagine that the politics and the pieces that Washington starts putting down as far as requirements and changes in those requirements is gonna drastically affect us. Yeah, it is interesting.
You guys are obviously funded based on who's in power, and you're gonna be given requirements based on who's in power. Has— I don't know if I wanna ask you a political question. Maybe you don't wanna hear this one. Has having Hickenlooper, who's obviously had some significant focus on security, Having invested in the Cybersecurity Center down in the Springs. It's been one of his planks in his platform.
Has having him as the governor had any impact on your organization? Do you know? The only thing that I've recognized there especially is his support for Debbi Blyth and her team. OIT and their support of us has been fantastic. Debbie continues to invite us and include us in everything that she does, and she's just a great leader.
I mean, she's a mentor and someone that I'll always look up to. Yeah. Well, we've had Debbie on the show before. We love Debbie and certainly support everything she's doing there. Well, I do want to give you a chance to put in a pitch.
Are you looking to hire anyone anytime soon? Anything you want to put out there on that? We will have a job posting coming up on the security front starting in July. So I'm working on that now. We'll have another security position.
What kind of skills are you looking for? Python, automation, cybersecurity, the fundamentals, Linux, Windows. Entry-level, mid-level, senior level? I would say it'll be entry-level. Good, perfect.
And those are— there's a lot of folks coming out of school right now, so if you're looking to get into security, couldn't agree more with Rich. You know, go learn Python, go learn how to do scripting and automation. The better you are at that, the more employable you are these days. Yeah. Okay, anything else we say here before we call it a wrap?
No, I'm glad to be in the state. I think we've continued to be leaders in this area. You know, one of the things to note is Colorado has actually been leading in a lot of different areas as well with like the MS-ISAC and the Elections ISAC that's been started up. Yeah. Through the MS-ISAC or the Center for Internet Security.
We were one of the pilot states to do that and that's been a huge benefit to be able to work with them and have a newsletter and different templates and stuff that they're working on to improve election security and have that fast communication and strong capabilities for all the states. Awesome. Well, Rich, I want to say thank you for helping keep our elections safe and help us, you know, going forward to make sure we choose the people we chose instead of, instead of who someone else says we should be choosing. And, you know, if you ever need anything from us, reach out. Appreciate it.
All right, that's it, and we'll talk to you guys next week for Colorado Equal Security.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.