Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 69 for the week of May 20— what are we, 28th? Memorial Day.
It's Memorial Day, Andre. I have a special guest host today, Andre Gaeta. Andre, thank you for joining us today. We're going to have a good time and enjoy the long weekend. Yeah, absolutely.
Thanks for having me, Robb. All right. Well, let's start off by talking a little bit about what we've got in the area and the resources for folks. We have a Slack channel where people can go get to know other folks in the community. We've got 450-something folks involved in the Slack channel, get to know local other security members and security leaders in the area.
We also ask you guys to get signed up for our mailing list so each week you can get the show notes delivered into your inbox.
Go to the website colorado-security.com to sign up for that. And lastly, we have a Patreon campaign. This is an opportunity for you to help support the show. It gives you the opportunity to donate on a monthly basis any amount that's appropriate for you. We do appreciate the Patreons we have out there.
Andre, I know you are one of those Patreons. We appreciate that very much. Yeah, my pleasure. And we use that money, those resources to help pay for things like hosting for the website, any hardware we need, the shirts that we give away and the stickers and all that, the stuff that we get to let people know about what's going on in the community. Yeah, running a podcast isn't inexpensive, so.
Yeah, it's been pretty good and obviously we've had the chance to do some fun stuff. All right, so let's start off by talking a little bit about, it's actually a federal decision and what might the implications of that be. There was a federal decision that made it sound like states are going to have the opportunity to decide if they want to do sports betting. Yeah, so it's, it's one of those things, right, where, you know, you have an industry that exists today similar to marijuana, right, and the legalization. We didn't create it in Colorado, it existed, and we simply rediverted that revenue stream from cartels into legalized, uh, governed, regulated businesses.
Now here's another industry in gaming that is a multi- billion industry, much of it going offshore, that you can now redirect this online gaming, sports gaming specifically, into taxable revenue for the state. Yeah, it's gonna be interesting to see, number one, does Colorado follow suit? There's, there's a link in the show notes to a Denver Post article that talks about how we may go this way as early as 2019. So number one, it's gonna be interesting to know, will Colorado go that way? And if we do, how does it change things?
Well, I mean, I think you're going to see job creation. You're going to see existing companies that support states like Nevada moving into Colorado to help with that from a compliance and regulation perspective, things like GOIP and Ideology to address fraud. So it's going to be interesting for the economy. I wonder how my, my bookie Boris is going to feel about that when there's legitimate people coming in place. I'm just kidding.
I don't have a bookie. I do know a guy named Boris, though.
So in other news, Chipotle is moving its headquarters out of Denver. This is interesting because we're seeing many companies moving their headquarters to Denver and they're moving out. Yeah, so a couple things to say about that. Number one, they hired a new CEO who's— who was headquartered down in Southern California. I hate to see Chipotle leave.
However, if they're gonna leave, we might as well say some fun things about it. So Number one, quesadilla later, Chipotle. Number two, this is nacho headquarters anymore. Need you to move along. They are, they are guac-ing away from Colorado.
They're guac-ing out on us. It's very sad. Yeah. And, you know, unfortunately, you know, there's going to be enchilada folks out of work as a result of this. It is very unfortunate.
The good news is Colorado does have the jobs to help those folks get back on their feet pretty quickly. Yeah, which is a great segue into the next topic, which is Colorado's dropping unemployment rate plunges into uncharted waters. Yeah, I think for the state, we're at like 2.3%. Kind of some interesting comments. There is this balance, and you and I were laughing about this a little bit earlier.
Like, you know, it's awesome to have so few people unemployed. You know, pretty much we're at full unemployment— full employment, excuse me. Unfortunately, now we start to see the opposite effect, right, where the lack of available work is now impeding the ability for job growth in the area. Yeah, this just feels like one of those situations where you can't win, right? You're, you're damned if you do and you're damned if you don't, right?
It's like, hey, we want to lower unemployment, we lower unemployment. Now there's other negative implications as a result of that, but it's a great place to be for job seekers, right? If you want to get a job, there's lots of opportunities out there for you. Yeah, and we were talking about like recent graduates. As long as someone graduates from school and they're willing to go take an entry-level job There is a job for you out there.
And if you don't know where it is, you know, I'll help you find it. There's plenty of opportunities out there right now, especially in security. Yeah, no shortage. All right, so Colorado has joined the national Operation Crypto Sweep to suss out fraudulent cryptocurrency offerings. Basically, there's a federal initiative to go after companies that are doing either ICOs or other cryptocurrency, that's ICOs, or initial cryptocurrency offerings, right?
The people who are going— they're going after those folks to find people who are doing it fraudulently or not in alignment with SEC requirements. Yeah. I mean, this is just a case where, you know, it's FOMO, right? Fear of missing out. So someone's going to call you up and say, hey, get in on this amazing ICO.
And people are not necessarily fully educated on what is real and what isn't real. That's a risk. So the Colorado authorities have gone after 2 different offerings who did not— they did advertising to Colorado residents, but they didn't disclose the risks of investment. And a couple of interesting stats from this article. There have been at least 310 ICOs in 2018 already.
We're only in May, right? Yep. And I assume that number, you know, is probably just a few months into the year. And those 310 ICOs have raised a total of about $7.5 billion. Yeah, and we, we chatted a little bit about this before, uh, we hit the show.
Um, cryptocurrency as a protocol to build applications on top of is pretty amazing. Things like Ethereum, that's pretty cool. Um, when you start thinking about it as a currency, there's no real intrinsic value to cryptocurrencies. So when you talk about the amount of money that's being raised against it, it's, it's kind of mind-boggling. Yeah.
There is definitely the fear of missing out and what's coming, 'cause no one wants to miss out on the next Bitcoin, right? If you could have bought a Bitcoin for, I don't know, 100 Bitcoin for a dollar back at the beginning, and now they're, you know, $20,000, $10,000 per Bitcoin. It'll be interesting to see how this evolves and goes forward. It's certainly not gonna go anywhere, but we gotta figure out where the value is and how do we leverage it as a society. Agreed.
Do you want to— Yeah. Next up is Alexa. What are you doing in my house? So Lennar Homes is building Amazon's digital assistant into all of its new homes, including a subdivision in Aurora. Lennar is one of the biggest 2 or 3 builders in the country.
And basically they've gone full, you know, all the way in on Alexa, on having Amazon devices everywhere. And I mentioned we didn't put it in the show notes, but this, this same week that we see this story, we see a couple of other massive vulnerabilities built into Alexa where there's the skills or the apps for Alexa that have the ability to eavesdrop indefinitely. And there's other ones that have misheard conversations and ended up sending conversations out to contacts on the list because Alexa is not perfect yet. Alexa is still learning. Far from perfect.
And I think as long as people have the opportunity to be educated, opt out of Alexa, it's a good thing. If it's just being built in and they don't have full education and awareness of, you know, they're every word in their home being recorded. It's a privacy issue. It is a privacy issue. I know we have one and we, you know, have the mute button pressed on it most of the time.
Right. I have the ability to unmute it and, and have it be listening. But, and as long as I feel, I feel relatively comfortable that we're low risk, as long as the mute button works, we'll keep, we'll keep an eye on that. All right. Denver has placed high, actually number 12 on the best cities for young entrepreneurs to look at.
What's interesting about this is it's actually a global list. Looking all around the world, where are the best places for young entrepreneurs to live? Yeah, but we have a thriving economy here. You know, folks are moving here, as we're seeing, in droves. It's a great place to start a business.
There's lots of high-tech, great educational systems with DU and CU and CSU. So, I mean, it's great to be on that list and be number 12. Yeah. So number 12, of course, our dreaded nemesis Austin is number 10, just a couple ahead of us on the list. But if you look one ahead of us, We have that other marijuana capital of the world.
Amsterdam is number 11. So, you know, us and Amsterdam are pulling in the middle of the list, basically. Are you tying those 2 things together? I might be. Number 1 on the list is San Francisco, then New York.
And then I actually don't know this, this, this city, excuse me, Kuala Lumpur from Malaysia. That was number 3. Miami, Los Angeles, Seattle, Beijing. London, Portland, Oregon, and then of course Austin round out the top 10. So interesting list, kind of fun.
They, they say they were ranked on employment, tourism, housing, transportation, internet speed, recreation, education, and gender equality. That's awesome. All right, um, the great segue into Colorado smart lock company LockState, um, lands a Series A funding for expansion. Yeah, they raised $5.7 million. They are one of those smart lock companies that give us the ability to unlock our homes from a phone.
Interesting technology. You and I were talking before the show, you know, there is a little bit of a difference in starting a new company that's not fully software and not fully manufacturing, and how do you get good at both with a small amount of seed investments? Good for them. They've got that. Almost $6 million that should really accelerate their growth there.
Yeah, I look forward to seeing what they do here. Interestingly enough, not only are they in Colorado, they're actually in South Denver on Santa Fe. So you could drive by and stop and say, hey, we heard about you on the media. You guys are awesome. And, you know, blow their minds.
That'd be kind of fun. This ties back to, right, every company is a software company. Yeah, absolutely. So next we have a blog from Red Canary. It's a security operations lessons, what my team learned for building and maturing a security operations center.
So if you are in a company where you run security operations and you want to try and get a jump start on, on what other companies have learned, this looks like a good blog for you. Yeah, absolutely. Go out there and read it. Those guys really know what they're doing.
Uh, next up is Secure64, What Every Company Should Know and Do About Data Exfiltration. So Secure64, they are a secure DNS organization. Basically what they're— this article is telling you is, uh, use their product to take a look at bad stuff that might be happening through DNS. That said, if you're not looking at your DNS traffic, you're missing a really valuable way that you can get insights into malicious behavior. There are just certain things out there that good guys don't usually look up via DNS, and using that as one of your many signals is pretty valuable.
So it's a good idea. Yeah, I mean, it's like email. Everyone's got email, and email needs to be secured, and everyone's got DNS, and you should be looking at that as a part of your security program. Yeah. So did you know that Palo Alto Networks has been working to create a platform that leverages their appliances inside an enterprise, and then you can apply other applications on top of that platform that aren't Palo Alto associated at all?
They're basically trying to become the marketplace or the iTunes for corporate security. Yeah, they're building an ecosystem, right? It's the Salesforce model. Splunk's in that model today, and they want to have partners of theirs build applications on top of their platform that provides high-fidelity data and telemetry, right, into the Pan suite of products. Right.
So I think Salesforce is an awesome example of exactly that same methodology, right, where, you know, you put the data there and then everything else just comes to the data and it embeds Salesforce more and more. So this is not a Pan story, this is actually a Swimlane story. Swimlane has become one of those partners and It is now integrated into Palo Alto's ecosystem and their application framework. And basically you can do your security automation triggered off of the data that comes through Palo Alto and using the Palo Alto levers within the organization to turn things off, to make block, to make IPS rule changes, all that kind of stuff. They have the ability to do that right there within the Palo Alto application framework.
Yeah, I think it's great. And it's a testament to, right, more organizations are becoming platforms, right, for security. We're moving away from point solutions and we need integrated end-to-end solutions. Yeah. So good stuff.
Final story here, we have Webroot has reached their 17th consecutive quarter of double-digit growth. I mean, that's pretty good, right? Go Webroot. You know, we were laughing a moment ago. They took the AOL approach.
I remember walking through Best Buy and as I was exiting, there was a disc right there for Spy Sweeper. Yeah. Right? And this is, you know, maybe a decade ago, but you're talking— More than that, probably. 20 years ago, I bet.
All right. All right. Well, but It's interesting, right? Because you think of like 17 consecutive quarters. Yeah, that's pretty consistent.
That's like Joe DiMaggio numbers, man. Good for Webroot. Congratulations, guys. Well done. So we now have our Slack message of the week.
And I don't have to say thank you to Andre Gaeta. I can just let you do the whole section. Go ahead and take over here. Yeah, so for the Slack message of the week, congratulations to Chris Merritt. Although I I don't know if Chris should really get the prize, or should it be Ryan, Johnny, and what was it, Taylor?
Hold on, we got it here.
Cooper, Ryan, and Johnny. Their top secret plans, their IP has now been disclosed on the Slack channel. We should read the plan. Yeah, so this is a business plan that was created by what I assume is Chris's kids or kids and friends. And what What is the business plan?
Number 1, step 1, win the lottery. Step 2, buy Nintendo Switches if we win. Step 3 is buy computer, buy personal computers if there's money left. 4, construct our glider business. I like how they, they started off by buying what they wanted, then they're gonna worry about using it for funding the business after that.
Absolutely. Step 5 is of course a playdate with each other. Absolutely. And then how much prize money is left over after that. Step 6 is, of course, seeing how much money the lottery winning actually was.
They do have a pricing sheet. I appreciate that. But before they get into the pricing sheet, the next step for the business is hiring salespeople. Hiring salespeople. Yeah, that's fantastic.
Way to go, guys. They do have a sheet full of logos. They've gone far enough to have logos created. Appreciate that. And then They're, they're basically ready to go.
They have a, the plan around. So, so for those who have Series A dollars who are looking to invest in startups here in Colorado, reach out to Cooper, Ryan, and Johnny. They've got a lockdown business plan. And, and I'm pretty sure that they won't use too much of your Series A's money for, for this plan. I, I think you could probably get through this with $600, $700 and, and they'd be ready to go with the glider business.
All right, congratulations to Chris. Of course, you are the winner for this week's competition. We'll send you a note and you can pick something from the Colorado Equal Security store as a thank you. All right, moving along to jobs. We have a few jobs to go through this week, starting off with my very personal favorite.
At Ping Identity, we are looking to hire a senior security analyst. This is someone who understands technology, understands Linux and networking and security operations, hopefully has a little bit of knowledge of AWS as well. We'd love to have you as a part of the team here at Ping. We also have another Ping identity position which is a Site Reliability Engineer focused on security operations. This is someone who helps manage and keep our production environment up but does the security projects in that production environment.
Yeah, Arrow Electronics is on the list. Uh, they're looking for an identity and access management manager, uh, reporting into Rishi. Webroot is hiring a threat research analyst. You just heard that Webroot has 17 quarters in a row of double-digit growth, so you want to go somewhere that you're probably going to have your job for a while. Yep.
And Red Canary is looking for a cert team. Raytheon is hiring a cyber automation engineer. I don't know exactly what a cyber automation engineer does. I assume that they automate cybers. But it doesn't say that specifically in the job description.
And it's one of those government contractors, so it should be fun. Yeah. MITRE is looking for a cybersecurity engineer. Western Union is hiring an IT manager focused on internal audit. And Coalfire, which is up north where, where I'm located as opposed to you down here south, Robb, Coalfire is hiring a consultant penetration tester.
And finally, Alchemy Security is hiring a DevOps engineer. So not security focused, but working for a security company. Finally, let's go ahead and move over to events. As a reminder, we do have an event calendar. If you wonder what's happening in the next couple of weeks, this is the place to go.
Andre, we actually, I think we have a first here on the show. I believe that this is the first time that we have no events happening in the next week. There's nothing here until June 5th. Enjoy the break, guys. Yeah, apparently, you know, Memorial Day, people, people don't want to go back from Memorial Day and go do security things.
Yeah. And kids are out of school now. There you go. That's true. So starting on the 5th of June, NCC, the National Cybersecurity Center down in the Springs, has their Cyber Careers: What Parents, Teachers, and Counselors Should Know.
And the ISSA COS Annual Cybersecurity Technology Day at Fort Carson. That is COS Colorado Springs. ISSA down, down south is doing their event at Fort Carson. And that's on the 7th and 8th both. On the 8th, there is the big Women in Technology Conference.
This is put on by the Colorado Technology Association. This is an opportunity for women who are not only in security but all of technology to get together and, and hopefully, you know, build some great relationships.
I think that takes us to the end of the events, doesn't it? All right, well, that is it for the show. We're gonna throw it over to our feature interview, which is a little different this week. We were reached out to by a lawyer with Ballard Spahr, which is an international legal firm that has a good-sized presence here in Denver. David Stauss from Ballard Spahr reached out to Alex and I and wanted to interview us for their blog.
We said, okay, we'll do it, but only if you let us bring a mic and record the thing. And that's what you're going to get. You're going to get to hear us being interviewed by those guys, by David, talking about all kinds of different stuff. What's the legal landscape look like? How does security work with legal?
What does GDPR mean to our organizations and maybe to your organization as well? Hopefully you'll enjoy it. It should be fun. Yeah, and a quick thank you to all the servicemen and women out there on this Memorial Day weekend. We appreciate what you do on a daily basis, and for everyone else, be safe out there.
Yeah, thanks a lot. And Andre, thank you for making the time to get down here and do the show with us. Alex is, of course, traveling for the long weekend. We'll look forward to having him back here in a week or two. Thanks for having me.
Have a good one. This is Michael Stephan, Privacy Security Officer for Connect for Health Colorado. Welcome to Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.
All right, this is Robb Reck, and I am here today with 2 other folks. This is the first one who you know real well, Alex. Alex, how you doing? Good, how are you, Robb? Doing fantastic.
We are here today joined with a special guest, David Stauss from Ballard Spar. David, thank you so much for reaching out to us. Well, thanks for having me. Absolutely. So David had reached out to say he wanted to talk to us, kind of a joint thing where they have a blog.
And if you guys haven't subscribed to their blog yet, where do they go to get access to it? It would be cyberadvisorblog.com. cyberadvisorblog.com. So he reached out to us to get on their blog, and we figured this would be a great chance for us to do kind of a joint blog podcast mashup crossover, however you look at it. You know, bringing a mega event.
It's a mega event. I think that's fair to say. So David, what do we want to talk about today? Yeah, great. So, well, hey guys, thanks for having me.
I really appreciate you taking the time to talk with us and to be part of our blog as well, where we've just started about 3 or 4 months ago, started blogging on a legal basis. So I love the idea of having a couple of guys who are doing so much in this area of information security really providing us with their insight to my legal readers. I have a couple important questions. Number one, Ballard Spahr, you're a law firm, is that right? We are a law firm.
Some would believe we are a law firm. And does that mean you're a lawyer? I am a lawyer. I warned you before I came here today that I am in fact a lawyer. And I, and I said, I said, you know, I asked you guys if you, if you would like a list of questions we could talk about.
And I said, I have to think about everything I ask for at least hours, 3 or 4 hours before I ever sit down to ask questions. But that's in my nature. So yeah, for those unfamiliar with Ballard Spahr, we're, um, uh, 15 offices nationwide. We got an office here in Denver, and we also have an office in Boulder, Colorado. We've got about 650 lawyers, and we got a pretty active and really good group of privacy and data security attorneys that are working on all these types of issues you guys are, but I think just from a different perspective.
Obviously, you're coming at it from an information security perspective and we come from a legal perspective. I think there's kind of a sweet spot in the middle that maybe we can talk about today. And I know most of this is going to be about Robb and I talking, but we'll let you pump yourself up a little bit more here. I know you not too long ago released a book. On Colorado security and privacy law?
That's right. So we've been really focusing on trying to find, you know, a niche in the market, I think. And so we focus a lot on Colorado privacy and data security law, and myself and another member of my team, Greg Sebchak, wrote a book on that. We published it in October, and of course, just a few months later, they proposed legislation that would substantially change all of the data security law in the state of Colorado, so we will be under pressure to be publishing edition number 2 fairly soon if the law passes. But yeah, no, I appreciate the plug.
So is this a textbook, or who is this intended for? So it's intended for— it is a textbook, so it's online, it's available at the firm's webpage. If you just Google Colorado cybersecurity, it tends to be the first thing that pops pops up, and it's intended for— we have CISOs who use it on a regular basis, compliance people who use it on a regular basis, and lawyers who use it on a regular basis. I think on the legal aspect, there's a lot of people trying to get involved and get up to speed on cybersecurity. From a law perspective, there is so much.
I know there's so much information from the information security perspective. There is so much from a legal perspective. Before we started recording, we were talking about GDPR, right? We have in the firm, we have people who just specialize on GDPR and nothing else. But then you've got foreign laws of Canada, you know, India I think is working on one right now.
All these foreign countries are working on things and you need to be up to speed on that. And then you've got in the United States right now, I've got this working theory that while people have been so focused on GDPR, the law of the United States has changed dramatically. And right now you've got all 50 states with data breach notification laws, you've got 18 states that have information security laws that say you have to do things like maintain reasonable security measures. You've got states like Maryland and Oregon that have specific requirements for what you need to do from information security. You've got state privacy laws, we talk a lot about that in Colorado.
So it's I guess to the point, we tried to capture that from a Colorado perspective and put together a resource that people would find useful and readable. That's the big thing with lawyers is trying to make it readable at the end of the day. I thought it was a legal requirement that it can't ever be understood by common folk. Yeah, no, well, you have to have tons of disclaimers, that's for sure. This is not, you know, this may appear to be a legal text, but it really is not a legal text.
Please don't rely on anything we say here. I can't get you— this does not establish an attorney-client relationship, the fact that you've looked at the book. But yeah, there's all that type of stuff that we have to put in there because of the lawyers like myself. But yeah, it's like I said, we've been really busy with a lot of different aspects right now, not the least of which is GDPR. And I, you know, before I get too far down the line on talking about what we're doing, I love it if for my readers' purposes, if we could just talk a little about your guys' background.
Maybe Robb, start with you. You are the Chief Information Security Officer for Ping Identity. Do I have that right? Yeah, Ping. We are a software company here in Denver, about 630 employees around the world, about half of those in Denver at the headquarters.
Previous to Ping, I worked in financial services at a few different companies. Doing online banking, doing mortgage work, doing actual— a bank itself. So I've had a good run of regulatory requirements. And of course now you talked about GDPR, that's real top of mind for us as an international company with a significant amount of work going on in Europe. In addition to doing that as my full-time gig, I've also been really involved with ISSA here in Denver, which is the Information Systems Security Association.
Denver has the biggest chapter in the world. You should put that in the blog. I think that's now in the podcast. We've had good growth there. I think there are— gosh, is it 800 people?
Just over 800. We just passed over 800 people. In the local Denver chapter? In the Denver chapter, yeah. It's pretty good folks.
We're catching up to you, ISACA. We got our eye on you there. Anyway, it's been really fun to get involved there. And Alex, why don't you tell us a little bit about your background? Sure.
So, Alex Wood, I'm the Chief Information Security Officer for Pulte Financial Services. So that is made up of Pulte Mortgage, PGP Title, and the Pulte Insurance Agency. So people might recognize the name Pulte, more known for Pulte Homes. We're the 3rd largest home builder in the country. And so Pulte Financial Services provides those financial services for folks that are buying Pulte Homes.
And so I've been doing information security for almost 20 years now. So I started my career at IBM, did a lot of managed security services work there. We had a security operations center that I helped stand up, helped develop some of the services that they had there. Spent some time after that at AT&T working in their cloud services group. Among other things.
Then left there to go to— from a several hundred thousand person company to an oil and gas company here, QEP Resources, which is just up the street from where we are now, to start their information security program. Company of 600, so it was a little bit of a change there. Left there, spent some time at Kaiser Permanente doing technology risk management for them, and then a few years back moved over to Pulte to run their information security program. One thing I want to talk to you guys about and make sure we get to is the reason why it makes sense to have both of you in the room with me at one time, and that's what you are doing with Colorado Equals Security. I'm not sure who would want to take the lead, but I think it's great what you're doing, and I think our readers would be interested in it.
For sure. Along with Robb, I've spent a lot of time with ISSA. Robb and I were on the board of the Denver chapter together for several years and formulated the idea that Colorado is this amazing ecosystem for information security. We were involved with ISSA, but there's also a bunch of other organizations that are doing information security. ISSA, ISACA, Cloud Security Alliance, OWASP.
There's also a bunch of startup companies in the area, you know, Ping being one of those, LogRhythm. I think you're allowed to say you're not a startup anymore. 600 employees. We did start here, to be fair, but there's lots of little ones and there's big ones. We've got Ironcore Labs, which is just a tiny little company, and, you know, Swimlane and ProtectWise, all these companies in town.
Vector 8, which I think is, you know, like 2 and a half people. Yeah, we're gonna get them on the show real soon. Real, real startup there. And so we thought, you know, there are all these great things going on, but, you know, we really need to promote all of that stuff. So we wanted to, instead of creating one more, you know, event or one more, you know, thing that's going on, we wanted to sort of be an umbrella.
So Colorado Security was born to try and aggregate and and promote all the stuff around information security that's going on in Colorado. Part of that is a podcast, and so we're recording this right now, and we're going to simulcast this with your blog. We also have a website at colorado-security.com where we have an event calendar, we have a listing of companies, we have security organization listings, all this kind of stuff, news. Good stuff we do there. So I'm going to try and stump you, David.
How many security professionals would you guess that there are here in Colorado? Well, you said before there's 800 in the organization alone, right? So I don't know, 2,000? So according to CTA, Colorado Technology Association, there is about 18,000 security professionals here in Colorado. That's a massive number, right?
That's incredible. And as Alex and I were— he started listing off groups. As you know, when I first got involved, I didn't even know where to start, right? What do you Google to go find other professionals doing security? So I happened to come across ISACA and ISSA, which are probably— they're definitely the 2 biggest, and I got involved with them.
But then as we were doing it, we're finding all these other groups, and there's this one over here and this one over here, and we realized there's just no place where you can go see what are all the options. So to Alex's point, that we became the place where you can find out what are all the options. And so how long have you been running Colorado Security? So a little bit over a year. Our first podcast, which I think you can call our launching, was February 2017.
And you're doing weekly podcasts? We haven't missed a week yet. Yep. And you interview every week, you do an interview of someone within the marketplace, is that right? Yeah.
So we— the podcast format is the first 15 to 20 minutes is local news. We'll go through, you know, what's the big news in the Colorado tech scene over the last week. We'll go through kind of blog posts and press releases from the local companies, talk about job openings that look interesting to us, and we'll talk about the security events that are happening over the next 2 weeks. That's the first 15 to 20 minutes, and then we, we have the feature interview, and that's usually either sitting down with the founder from one of these local tech companies from a CISO from one of the local companies here in town, or just somebody else interesting in the community. So just, you know, we've talked with the heads of the different nonprofits in the area.
We've talked with Dave Navetta, who's a security lawyer in town. Sure. Really try and find folks who we think people will be interested in getting to know. Maybe even a lawyer from Ballard Spahr. Yeah, who knows?
Could happen. Could happen. If I play my cards right, I may make it onto your podcast. Yeah. So, you know, the name of it is Colorado Equals Security.
Any reason why the substance of what you're doing would not be interesting to someone not in Colorado? You know, I think that the things that we touch on are Colorado-based, but they are still issues and news items that I think are of interest to anyone. Interviews, it happens to be Colorado-focused people, but you know, the, the companies that are here, they sell their products everywhere. I think that, you know, just about anybody would still be interested in the content that we provide, except maybe the events. The event section is pretty specific to here.
You know, we, we really wanted to be as narrow as you can, and one thing you learn if you ever get in the entrepreneurial area is the more narrowly you focus, the more successful successful you can be taking over a space. We will never be the biggest podcast in the world, but we can be the biggest Colorado-focused podcast, right? We'd be the only Colorado-focused security podcast. So that's, that's really been our goal, is to really to, to drive the community enrichment here, really try and make— and the name, the purpose is in the name, right? We're trying to make Colorado synonymous with security.
Where do you want to go to get the best people? They're in Colorado. Where's the, where's the best security community? Well, it's in Colorado. It's in Denver.
You want to start a security startup? You do it in Colorado. Yep. How's the podcast been received so far? Terribly.
Everyone hates it. Is that about right? Yeah, pretty much. No, I think things have been going really well. We've gotten great feedback from people.
The, the listenership has continued to slowly grow. We actually had a One piece of feedback from a listener that I find— it made me feel really good. He was up in Fort Collins, and he was not even in security, just in sort of general IT work, and started listening to the podcast on his drive from Fort Collins down to Denver for his job. It really sort of inspired him, and he sort of refocused what his efforts were at work and was doing more on security. Security, and really, really invigorated him because he was just sort of run down and not inspired in his job.
So it's, you know, good feedback like that is what helps me keep going and doing this stuff. And so how can people sign up for your podcast? Yeah, so if you go to the website colorado-security.com, you can find links there, or if you search for Colorado Equals Security on iTunes or Google Play, you'll definitely find it there as well. So let's change topics just a little bit, and I want to ask you about your, your roles. And as you know, my readership on the blog is legal-based, and so I want to kind of poke around and get your guys' thoughts right now on the relevant legal topics.
You mentioned, Robb, GDPR. How much of your time right now is spent thinking about GDPR? Well, right now it's not too bad. But for the last year and a half, it's been one of the overarching projects for us to get in front of.
As a provider of SaaS services, we had 3 different ways we had to think about GDPR. We had to think of it from the perspective of our SaaS product, so any data that we have in the cloud for our customers' consumers. So we're B2B, we only sell to businesses, but they have lots of consumers. Consumers who might be there, and we need to help our customers comply with GDPR because no one's going to want to buy a solution that puts them immediately out of compliance with the biggest privacy regulation ever. So we had to make sure our SaaS products were compliant.
Second aspect is we had to look at our marketing practices. So our marketing team, which for most companies, marketing is not a core IT competency where you're especially good at all this stuff, it really caused us to mature, you know, make sure we had data flows in place for every place where you ingest data. Where is the data being stored? What's the process for doing opt-in, opt-out? Really getting good at understanding the privacy and consent aspects for our marketing practices.
And then the third aspect, which is honestly the easiest one, is getting our arms around privacy from an employee perspective. You know, as a, you know, 600-and-something-person company, we have, you know, call it 70 employees who are EU citizens. Well, we have to treat their data in the way that's compliant with GDPR as well. So our HR systems, all those things have to be compliant. And I kind of walked through them in the priority order that we looked at them and where we were spending our time as well.
And how much time do you think you had to devote to getting GDPR compliant over the last year or so? Well, it went in waves. I'd say a year and a half ago is when we created— and let's call it December of 2016— is where we created a matrix of product requirements that we would have to implement in order to make our products compliant with GDPR. And we delivered those to— so all of December and maybe a couple weeks of January, my GRC team was focused on creating that matrix of requirements. We delivered that to our product team in January of 2017, and then they— and then we were able to hand that off and really take a backseat on that and let them work on building the requirements into the products.
And then mid-2017 is where we really ramped up the other 2 aspects of the project, the marketing and the internal projects. And that's also when we went out and contracted with an external DPO, Data Protection Officer, which is a requirement of GDPR. We did not want to have an internal person for a variety of reasons, but we chose not to have an internal person be a DPO. We engaged with an external DPO who was able to give us some help with some templates and, you know, really give a little bit of guidance. Let me ask you about that.
Yeah, did you feel like there was enough guidance out of the Article 29 Working Party to direct your efforts? No, it's really difficult to just use their working papers, especially the different countries have different interpretations. The regulation itself is just not nearly detailed enough. It's principle-based, right? And some of the principles sound really simple— privacy by design, the right to be forgotten, or right to erasure.
These things sound simple, but when you start getting into the nitty-gritty of them, When you start actually trying to implement is where you realize that it's just not clear enough to make it easy. And so do you think this will be sort of a rolling compliance issue for you? You know, the May compliance deadline will happen and you'll adjust as time goes on? Yeah, so we believe that we have implemented controls that meet all of the requirements. However, as we start to see case law develop, developed around this, I suspect our interpretation, everyone's interpretation of these things is going to change.
And as that happens, we'll probably start to make changes in how we do things. We're ready to be flexible, but we think at this point, you know, from a risk-based perspective, you know, we've really kind of figured out how do you meet the spirit of the law and as close as we can understand it as it is today. Have you sought any certifications like ISOs? 27001 or anything along those lines to try to drive compliance? Yeah, so we are ISO 27001 certified as of March 30th this year.
Okay, congratulations. Thank you. That was also a big priority for us over the last year or two. Did you do that as part of GDPR? Yeah, separately.
It's unrelated to GDPR. It's really just to be able to provide assurance to our customers that, you know, we're operating in an environment that they'd be comfortable with. GDPR kind of drives us in a different direction, which is really more about the consent and privacy and data handling versus internal security practices.
One thing I've heard on my end from clients is a lot about the 72 hours that you're given to provide notification of a breach. How's Ping approached that? That's dependent on whether you're the control controller or the processor. Data controller being the person who is ultimately responsible for that 72-hour timeframe. The processor is the one who's kind of a supplier to the controller.
We're both, right? In the event of one of our employees or the marketing data, we are the controller. In the event of our SaaS product, we're the processor. So for a processor, you have to let your customer know immediately. What does immediately mean?
That's not defined, but that 72 hours is applied directly to our customers from the time that we let them know to when they have to disclose. Interesting. Alex, has GDPR been at all relevant to your business? You know, I've been— I guess I'll say lucky. You know, we are a completely US-based company.
We only build houses in the US, and we only market to US consumers. So it has been a much smaller burden for me than it has been for someone like Robb, who not only markets to folks in the EU but has EU employees and other things like that. So not a whole lot for me. So what would you— what are the legal issues that are on your table right now? Well, I mean, there is some around GDPR just because someone from the EU could theoretically apply for a mortgage with us, right?
So there's been some discussion on, you know, how does that apply to us? You know, what does jurisdiction look like? You know, other things like that around deciding how much risk we have around GDPR, even though our operations are all focused on the US. So that's been one thing.
More general legal issues, we have a whole lot of consumer data that we try to keep safe. So there are all the different US privacy laws that we have to deal with. And that's always a big deal for us. We're also— Let me ask you on that. Sorry to cut you off.
Equifax, the amount of state and even a little bit of federal action on privacy-type issues, breach response issues, the SEC, cybersecurity disclosures, I mean, all these little bits and pieces that have come out, how much does that impact your daily lives or your weekly lives in your positions as CISOs? You know, I'm pretty lucky in that we, in the mortgage industry, there's lots of regulation, Our legal and compliance department is pretty good in keeping up with that stuff. That doesn't directly affect information security, but because of that, they have staff that is dedicated to following those compliance issues as new laws come out. It's like I have a little bit of extra staff to help me through that stuff. It's been really beneficial to have those folks help.
Let me know when something new is coming out and that sort of thing. Do you have a normal interaction that you have with your compliance people that helps drive compliance to these new requirements? Yeah, for sure. I report up through IT to the CIO, but I have a dotted line to our Chief Legal Officer. I spend a lot of time with him, and I have a great relationship with him and his his whole group, which includes compliance.
Robb, is U.S. law relevant to Ping right now? I mean, obviously it's relevant, but is it a hot ticket item right now for banks? I don't think so. We are really not regulated by much of what you just said. We're not public companies, so the SEC is not a factor.
Certainly, we're well aware of breach requirements, and we have outside counsel and internal counsel that help us with that if we ever need it. We are driven much more by what our customers' requirements are, so by trickle-down economics, we get the same requirements that are imposed upon our customers. We do sell to large enterprises, so GLBA, HIPAA, Sarbanes-Oxley, and anything that— FISMA— anything that our customers are required to do we start to see, and as a result, we've built a program that can map across all those different requirement sets. So I'm able to talk to them, although we are not directly regulated under any of those. Okay, and so, you know, Colorado obviously is a big focus for you guys.
The Colorado legislature has legislation now they've been considering that would change the breach notification law and also enact some requirements on maintaining, implementing and maintaining reasonable security measures. Has that been relevant at all to your businesses? Is that something you're tracking? You know, it's been on my radar. Being a financial services company, we are also subject to the New York Department of Financial Services cybersecurity legislation that came last year, I guess it was.
Sure. Which is, I think, even more stringent than what Colorado is proposing. So, from my perspective, we're already there. We're making sure that there's not anything new that's going to take us by surprise. Let me ask you about the New York Division of Financial Services cybersecurity rules.
That was something that you had to go through the compliance period last year? Yes. How much of a lift was that for you? Our program has always been designed not based on compliance. It's based on risk and then providing what it is that we need to do to secure our information.
Because of that, our bar is usually much higher than the compliance regulations, so we actually didn't have to do a whole lot to be able to comply with New York DFS. You probably had to send a letter. You did, right? Because it's a requirement from you. Yes, so our compliance department drafted a letter.
I got to sign it. Nice.
That was exciting. That one, basically they require you have functional risk management, you have vendor risk management. Two-factor, is that something that's required? Yeah, two-factor, and parts are being phased in too. There's some encryption requirements.
Audit logs. Audit logs, business continuity disaster recovery stuff. It is all straightforward to security program implementation. I just, I think that many companies still drive themselves by compliance, so whatever the lowest bar they can meet, that's what they're trying to meet, and we've never driven our program that way. David, what do you— now you talk about the Colorado legislation.
I think Alex and I would both be interested in your take on this proposed requirement that the state look at implementing blockchain to help with their security programs. Is this Are you familiar with this nuance I'm talking about? Yeah, the blockchain legislation. Yeah. Is that going to happen?
If so, whose idea is this? Blockchain is everything right now, right? Is the blockchain lobby that powerful? Yeah, I think the legal community is still— let's look at it generally, right? Blockchain has come out as being a new technology.
Obviously, you guys know far more about blockchain than lawyers like myself would know. The legal community, and this is the more general topic I would say, is the legal community often struggles because we're not equipped to understand the technological background of a lot of things that go on, right? So for instance, you're talking about the New York Division of Financial Services regulations, right? Very prescriptive. They say things like you got to have audit logs, you have to have an incident response plan, you have to, you know, very specific requirements, right?
As opposed to states that have tried to address this issue by saying you just need to implement and maintain reasonable security procedures, sort of like a negligence standard, like we'll figure it out later, you know, juries will figure it out later. And I think the struggle there is, do you really want lawyers trying to say what it is that you guys need to do when we, you know, a lot of us just don't know what it is that we're talking about, frankly. I mean, I spend a lot of time in this area, so I like to think I know enough to be dangerous, but it's a big struggle. And I think the blockchain, to get it back there, is there's this new technology, it's unregulated, you see lots of issues you know, like its application with Bitcoin. And there's a struggle right now by trying to regulate that type of, um, uh, I mean, what's the general name for it?
It'd be, uh, you know, the ledger. Yeah. So, you know, and you see like the SEC trying to get involved, you see states like Delaware trying to get involved and try to regulate these things. And then you see the Colorado application, which is, well, hey, you know, maybe we and look at this from a state-based level and see how we can clean up inefficiencies, right? And so we can apply blockchain in a way that would eliminate the need for X or eliminate the need for Y.
They don't have it figured out yet. There's no doubt that they don't have it figured out yet. But I think you're gonna see this more and more. States kind of, you know, seeing if they can try to do something with this new technology to try to address inefficiencies or be at the cutting edge. And I think it's important for Colorado, you know, just for the same reasons what you guys are doing with Colorado Equals Security, I think it's important for Colorado to try to be on the cutting edge.
And maybe it works, maybe it doesn't work, but by addressing this through the legislative process, I think they're hoping that they will catch on to something that'll really put them on the cutting edge. What's your perspective? I'd be interested in I'm trying to resist my cynicism that says this is the same as saying, here, I made a fancy new kind of wrench and I want you to— I'm gonna pass a law saying that my mechanics have to figure out if they can use the new kind of wrench somewhere. Like, that doesn't make any sense, right? If there's a spot for it, then naturally without a law saying that I have to do this, I'm gonna find it.
But that said, I think you're making a good point that this gives us, an incentive and a drive in an area that might not be otherwise innovative, right? It's possible that, you know, the teams that are doing this just don't have the resources and the cycles to go investigate new technologies, and we're putting a clear mandate to say, let's go figure out if there's a way to get better at it. I guess I get that perspective. Well, and there's also a history of this in Colorado, right? So I can't remember if it was 2 years ago that they passed legislation that set up the National Cybersecurity Center down in Colorado Springs.
They established it, they funded it, and they said, well, listen, we're going to try to make a run at being a cybersecurity center, and we're going to invest all this money into it. We're going to try to really make something that's unique to Colorado. I think you've got a history of the Colorado legislature and the governor trying to tackle these issues with Uh, you know, fully realizing that, that there's going to be, there's going to be speed bumps along the way. Degrees of success, is that, is that what you're saying? I, I think if, if we use that as a baseline to say, is this, is this a good approach?
Well, did the NCC succeed? Well, we didn't set any goals for it, so we can't say it succeeded or didn't succeed. I think what most of us would say 2 years into this not very successful. It hasn't accomplished a lot of goals yet. However, there's something going on, right?
It's generated a lot of buzz. Is that— it's probably a net positive. It might not have been the best way to set— to sink X millions of dollars though, right? That's the question. Yeah, I mean, I think on the, the other side of it, if we— this cryptocurrency law passed, or blockchain law passes, and then, you know, 3 years from now that technology doesn't exist exist anymore.
Well, now you've got a law that says you need to consider this thing and it doesn't even exist. No one's using it. It's like, well, okay, now we're going to be spending more cycles than we need to investigating something continually that doesn't make any sense anymore. Yeah, that's funny. You know how easy it is to get rid of old laws, right?
Right, exactly. I feel like once you make something a law, it's very hard to get rid of it. Look at Tabor. We've got horrible tax issues because of stuff that's been in there for a long time. Lots of other examples as well.
But I feel like that's probably not the best place to put that. You're saying that once you legalize marijuana, there's no way to walk that back? That's probably true. Well, maybe less on that one. This is Colorado after all.
Federal troops descending on Colorado one of these days to— stamp it out. Who knows? We'll see. Yeah, so I, you know, it's an interesting topic you raise, and it must be, from your perspective, it must be a lot different than from my perspective as a lawyer. I look at it and say, okay, you know, legislature's trying something, but from your perspective, it must— it's got a whole different take.
It really does. It's like passing a law that says you have to use, you know, figure out a way to use MySQL in the Colorado IT department. Like, why? Like, why are you telling me I have to look into this one particular technology? Technology when there's a million other ones that I could be using and it's not like this thing does something that nothing else can do.
It just seems strange. It seems ham-fisted to me. Let me ask you about something else that you're involved in, which is the Rocky Mountain Information Security Conference.
Why don't you tell me a little bit about it, Alex? Rocky Mountain Information Security Conference is the largest information Information Security Conference in the region. It's been put on for— is this 12? I think this is number 13. 12 or 13 years jointly by the Denver ISSA and ISACA chapters.
They get together every year, figure out what they want the conference to look like. We have it here in May. It's 3 days this year, so we've got 1 day of pre-conference sort of full or half-day trainings, and then 2 days of sort of a more traditional kind of conference format. We've got a keynote in the morning, we've got blocks of hour-long speakers during the day, and then keynotes in the evening also.
I've been involved in Rocky Mountain Information Security Conference since 2010, I think, and it's been awesome. It's been growing every year. We're going to be— we're I'll say well over 1,000 attendees this year. So I think it's really a great experience, the place to be if you are a security person in Colorado. So Alex is the co-chair of the conference.
ISSA and ISACA both name a chair, so he's the ISSA chair for the conference. I'm the head of programs for it. Now we're recording just before the conference. We're going to release this on the podcast right after, But we've got a lot of cool stuff going on. To Alex's point, just phenomenal growth over the years.
It's been a lot of fun. Tell me, you guys are in conjunction going to do a panel on CISO leadership. Is that right? Tell me a little bit about that. One of the sessions that we're having, CISO panel, I'm going to be moderating.
Robb is one of our panelists. We also have Sam Masiello from Gates Corporation, Gail Curry from Oracle, Rich Schliep from the State of Colorado— sorry, Secretary of State— and Joe McComb from Janus Henderson. We are recording before the panel, but I can guarantee you I'm going to get in a fight with Joe McComb during the panel. So you guys can go look and see how it went. I'm sure it'll be a friendly fight.
No fisticuffs. Looking forward to it.
From my perspective, legal-based readers, what is your sweet spot for the type of people who should be looking to attend this event? Well, there's all kinds of different tracks. Probably the track that would be most relevant to the followers of your blog is our governance, risk, and compliance, or I don't remember what we call it, audit and compliance track. We really get into a series of stuff that isn't as technical in nature. I know that the technical stuff can be little bit intimidating, but we have stuff talking about GDPR, you know, separating fact from fiction, a couple different GDPR tracks.
We have one talking about auditing for SecDevOps as people move to the cloud. We talk about COSO, ISO, and SOC 2 and kind of how those different frameworks overlap with each other, maturing third-party risk management.
Really, I know I can keep going, but there's a lot of different tracks that are not as technical in nature that would probably be really relevant to these folks, including some lessons learned from incidents. If you want to talk about, hey, what did somebody else go through when they had a security incident, it would be a good place to learn there. Also, the elephant in the room is, David, you are speaking at Rocky Mountain Information Security Conference. I am, and I'm guaranteed 2 people being at my event right now. That's right.
Is that true? Yeah, so I don't know if you want to talk about what it is that you're going to be talking about. Yeah, sure. We talked a lot about GDPR and we were talking some about the United States law and the basic theory of the panel is so much time and effort has been devoted over the last year or so to GDPR compliance, but in the wake of Equifax, that US law has changed substantially and is consistently changing and it's actually a full more difficult compliance or regulatory structure than you have with GDPR. Because rather than having one regulation that governs what you need to do, you have 50 different state laws or states' worth of laws, and you have federal requirements as well.
And you have so much proposed legislation on a regular basis that trying to keep track of all of this and trying to make sure you're complying with all these different changing laws is difficult. And so what we're going to do is we're going to talk about how these laws are evolving and the trends that we see in the last couple years. So for example, the state breach notification laws, they are traditionally— have only covered Social Security numbers, credit card information, driver's license numbers. Well, that's being expanded as more and more states in a post-Equifax and even just before Equifax world have looked at this, they've vastly expanded it. So they've expanded it to biometric information, they've expanded it to student identification numbers, things of the like.
So we're gonna talk about those trends, we're gonna talk about the trend of states like Colorado has proposed legislation right now that would really shorten the timeframe for an incident response, that they've gone from these ambiguous, as soon as possible, standards to these set standards of 45 days or 30 days, or even North Carolina has proposed 15 days. So we'll talk about those trends. We'll talk about the information security laws as well. There will be more and more states are jumping into this, and they're saying— we talked about this before— that you've got to maintain reasonable security procedures. Well, what is that?
How does the law look at that, and how can you match up what you guys do and make sure that you're able to articulate to your legal officers who probably look for guidance to you guys, the CISO positions, the information security positions, of, well, am I compliant? The legal officer is going to see a law and say, hey, Colorado requires me to implement and maintain reasonable security procedures, and they're going to say to you guys, well, are we there? What's the toolbox that you can use views and standards that you're aware of from a legal basis that can help answer that question in a way that you feel confident that if there was ever a lawsuit or breach that you would be compliant. And that's a difficult area, as we talked about before. It's the law— lawyers are struggling, in my opinion, with trying to keep up with the technology and keep up with the data breach risk.
And so it's a reactive situation right now where laws are getting amended and implemented and the like, and it's making it difficult, I would imagine, for the technical people to actually drive compliance or drive the ability to assure their executive boards that, hey, we're fine. So we're going to try to plug that hole. We're going to try to talk a lot about that in a way that's meaningful for information security people and try to get ourselves out of our lawyer hat and try to really talk about about that aspect. And obviously your, your listeners will, will be getting this, um, afterwards, so I hope if it sounds interesting, uh, too bad. Yeah, too bad.
I think we may, we may try to recreate it as a, as a webinar later, uh, for the firm because I think it is a, is a relevant and interesting topic. I appreciate you, you asking about it. Yeah, one other interesting thing that I want to talk about with regards to, uh, the conference this year is the, the first night of the conference we're doing something different than we have in the past. Usually we try and bring in, you know, a big-name speaker, you know, somebody like, you know, a Kevin Mitnick or a John McAfee or, you know, something like that, try and draw people down for, for something like that. And this year we're doing it a little bit differently.
We're trying to sort of organically get people down there for the opening night. So we're doing 2 things. One is we're doing a job fair, you know, the Hiring people in the information security industry, it's very hard right now, so there's lots of companies looking for people. There's lots of people coming into the security industry who are looking for jobs. And then the second piece is that we are doing some sort of— I'll call it community night with organizations.
So some of those organizations we talked about earlier— ISSA, ISACA, OWASP, Cloud Security Alliance— they're gonna have representation there. Everybody's gonna have some space where they can do presentations, talk about their organizations, give some content. So if people are already members of those organizations, they're welcome to come. If they want to learn about those organizations, they're welcome to come down to the convention center and hear more about that. So we're really trying to make it more community-based, more, you know, organic, to try and get people down there for that opening night of the conference.
So if this is appealing to the readers of the Bowers Barnes blog, where should they go for more information? Yeah, so the conference website is rmisc.org. It is going to be held May 8th through 10th at the Colorado Convention Center. That opening night, it is open, so you don't have to be registered for the conference to come to the job fair or the community night. So even if you're not planning to attend the full conference, You know, you're welcome to come down and hang out during that time.
And it's all down at the Colorado Convention Center? It is. I believe that we're going 4:00 or 4:30 to 7:00 that night for that opening piece. So people are welcome to come down. We'd love to see lots of people there.
And if you come and you like it and you think it's interesting, well, you know, register and come to the next 2 full days of the conference. Sounds great. Well, thanks so much, guys. Yeah. It's been fun.
Any final— what's your prediction for US privacy law over the next, call it, 18 months? Where do you see it going? I think we will consider to see on a federal level little. Yeah. You know, we've seen some issues get addressed this year, the CLOUD Act, right, which was before the Supreme Court, so they decided let's just enact some legislation.
But, you know, I mean, after Equifax, there was nothing but nonstop congressional hearings and zero legislation that came out of it. There was a couple bills proposed. Lots of draft legislation. Lots of draft legislation. But no one actually did anything with it.
Lots of sound bites. Lots of, you know, I'm gonna go out for reelection next year, so I'd better— Have my name on something. Have my name on something, right? So you saw a couple of those statutes.
There was one serious attempt at national data breach legislation, but that got a lot of pushback from state attorneys general because it would be a preemption issue. They didn't want the federal government coming in and doing that. So I think on a federal level, you'll see— I don't foresee even post-Facebook, right? I mean, there was the hearing with Mark Zuckerberg. There hasn't been a big push for privacy-based legislation.
It's just not something that on a federal level happens to be a big-ticket item. But on the state level, I think that's really where it's happening right now. You have the New York Division of Financial Services, their cybersecurity rules. I think you'll have more and more states in the next legislative session look at the privacy issue seriously. And so for the most part, state legislatures run their calendar January to May or June, right?
That's the legislative session on the state-based level. That's in Colorado as well. So I don't think that this year you saw the big push, but I think next year you're gonna see the big privacy push. I mean, this year was a big breach response push, a lot of states amending their laws for breach response issues and information security issues. Next year I foresee, if I had to fortune tell on this issue, I'd say next year there will be the privacy push.
You will see a lot more GDPR-like issues, the right to be forgotten, right? At the state level. At a state-based level. Which is a nightmare to try and deal with if you're a national company.
Global even more so, right? But it sure would be nice if we could get our federal government to federate some of these things and simplify our lives. But probably not going to happen with the current administration's anti-regulation stance here, I'm guessing. I think that's right. And it's just not been a big-ticket item for a number of years.
I mean, it's just not— I mean, you sort of see this cycle where large-scale data breach or large-scale privacy security incident and then outrage on a federal level, complete inaction, And then repeat, right? And that's what you see. And the real, I think the real engine driving right now, like I said, is state-based. And I should say, it's not only state legislative action, but it's the regulatory action as well. The New York Division of Financial Services, that's a regulatory agency.
The Colorado Division of Securities last year, Gerald Rome, instituted regulations applicable to insurance brokers and broker— or I'm sorry, investment advisors and broker-dealers, cybersecurity rules that are specific to those industries. You're going to see more and more of that. There's been a push from the legal perspective that law firms need to get more compliant. There were some draft rules from the Association of Corporate Counsel that were trying to push that type of issue, so that self-regulatory model will probably gain team as well.
Awesome. All right, well, thanks so much for your time, David. Anything else before we call it a wrap? No, well, thanks so much for your time. I really appreciate it and looking forward to seeing you guys just continue doing great things with Colorado Equal Security.
Thanks, David. Thanks, David. Well, that's it for this week. We'll see you next week on Colorado Equal Security.
Learn more about the Colorado security scene at colorado-security.org. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.