All episodes

Eddie Mize, CSO at Pinnacle Group

Apple Podcasts Spotify SoundCloud

In this episode:

Eddie Mize, CSO at Pinnacle Group, Faces of DefCon Artist, and a much more, is our feature interview this week. News from: Lime, Boom Technologies, Amazon, Innovation Pavilion, LogRhythm, Ping Identity, Coalfire and a lot more!

LogRhythm makes a big splash

Those green scooters all around downtown Denver aren't just trash, they're HIPSTER trash. Boom Technologies can you get you there faster. Smart pavement is real, and it's spectacular. HQ2 is still a possibility. Accusations fly around the Innovation Pavilion. Colorado has it's very own security law. LogRhythm gets bought by Thoma Bravo, and the fun only starts for them. Finally, Ping and Coalfire team up for IAM. 

Check out the Defcon documentary here: https://www.youtube.com/watch?v=3ctQOmjQyYg

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12667 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 70 for the week of June 4th, uh, and I have a special guest here today with me, Brad. And why don't you go ahead and introduce yourself?

Hey everybody, this is Brad Bussey. What do you do, Brad? So I am the Principal Security Strategist for Trace3. Yeah, awesome. Well, we're glad to have you help do our co-hosting today, and we'll get to talk about some fun stories and interesting stuff going on here in the Colorado area.

Before we dive into stories, a couple of housekeeping items. Number one, we have a Slack channel. Brad, I know you're active on the Slack channel. We've got a good group of folks out there, 450+ people. If you want to come out and get to know other security professionals here in Colorado, please come join us.

The link to join is in the show notes, and it's also on the front page, colorado-security.com. Additionally, we have a Patreon. A big thank you to those who are supporting the show through the Patreon. That's how we pay for our hosting fees and all of the cool stuff we get to do, and free stickers and shirts and all that. We would appreciate any additional support.

Everything we get goes directly to the, the show and to the community. Nothing goes back into anyone's pocket. With that, why don't we go ahead and jump into some stories? Number 1, have you noticed some random green and black things laying around in the streets in Denver lately. Yeah, I've heard a little bit about those bikes.

Yeah, so there's bikes and scooters that are now littering the streets, uh, the, the dockless craze, right? Where, you know, there's— they don't have a place to, to mount them, so people just leave them wherever they're done using them. And I heard a little bit about people collecting the bikes, taking them back, charging them. Yeah. And then somebody picks them up, or they return them back to a central hub.

Basically, this is the gig the gig economy, right? Right. And the gig here is you charge these things in your house. And I think they say it costs about $0.20 to charge it. They'll pay you about $5 for each one you do.

So you got to figure out the economics of that, right? Isn't there a little bit of mixed opinion from Denver as far as what they think about those bikes on the streets? Yeah. So the first story we grabbed on this was that, you know, there's the law is you can get a DUI on an electric scooter. Interesting.

Okay. But then the newer story which came out after that was that Denver is actually planning to— well, has already notified both of these companies, which is Lime and Bird, to let them know that if they don't get their scooters off the public areas, so off of sidewalks and places that are, you know, in the way of— imagine like a wheelchair trying to get through, right? They don't have those things moved, they're gonna get confiscated basically, right? So it's gonna be interesting to see. This may be a very short-lived experiment here right now.

Didn't you say something about San Francisco having a similar infrastructure, but seems to be doing okay there, right? Well, I actually think San Francisco is having a lot of the exact same problems where they are just kind of like trash thrown in the middle of things, you know, unsafely left everywhere. And they're trying to deal with that. They have not taken the same hard stance that Denver has about kicking them out. But it's the same problems, maybe a little more regulation.

Yeah. All right. Moving along. There is a Denver-based company called Boom Technologies that is working on creating a faster than sound airline that's going to go basically from the United States to China. That's the number one market.

Wow. So that's like Concorde 2.0. That's exactly right. The company is— they're a couple of years away from doing it, but they have over $85 million in funding. So they're not a joke.

They have a 2-seat demonstration model that's going to be ready to go next year. So obviously, they're a ways away from the real deal. Right. But it's going to go as fast as Mach 2.2, which is about 1,451 miles an hour, and it'll get us from Shanghai to Los Angeles, which is normally a 12-hour flight, somewhere in the 5-hour range. That's amazing.

Pretty cool, right? Having sat on a plane for 12+ hours, I would definitely pay for that. So if you're interested in working on a very, very fast flight, you know, Boom Technologies here in town might be your place, right? And I don't know, you probably don't get free flights to China, but maybe— what do I know? Someday.

So what's this I keep hearing about, this new smart pavement technology? Yeah, so I saw that story that US 285 is gonna, is gonna be paved at least in some sections with this smart pavement. And basically it, it's a, some kind of registration to say what trajectory and speed tires are going on, and they have the ability to take that data and turn it into, well, it was going too fast in this trajectory, that means the car went off the road. And they're gonna— they say they can do this for somewhere in the 1.5 times the speed, or the cost, I mean, of normal asphalt. And as a result, they can see in those areas that are high risk if a car goes off the road.

That's, that's interesting. I always think of it as pavement that could help charge vehicles as well, but this sounds more like just reporting back. Yeah, this one, this particular one is just for those really high-risk areas where a lot of cars go off. And the story they tell in the article is about a woman whose car went off the road and she was left there for like, I think it was 72 hours. It was a really long time.

I remember that. Um, before someone found her. And, um, and she, she ended up surviving, but very well could have not survived, you know, based on that, uh, you know, no one knowing that she went off the road. I think she was covered in snow, the vehicle, so they couldn't tell anybody was even in it. Scary stuff for sure.

Yeah. Um, next we have a story that's of reevaluating all the cities that are in the top 20 for Amazon's HQ2 and kind of looking where everyone falls out. They're rated here on, um, looking at the, the qualifications again, um, medium home price, the 5-year home price appreciation, price-to-income ratio, average school score, crime rate to national average, effective property tax rate, and environmental hazard risk rate. So So lots of factors for this. We're like a solid 6.

Number 6. Number 6. I mean, it's not terrible, right? It's not bad. Number 1 is Raleigh, North Carolina.

Atlanta, Pittsburgh, Nashville, and then our dreaded nemesis Austin comes in number 5 directly ahead of us. Yeah. Good food, but they, they can't compete when it comes to technology. Well, the weather is, the weather is the rough part for Austin from my perspective. It's great in every other way.

It's just way too hot. Right. Uh, so yeah, looking, looking at the next story here, the founder of the tech company Innovation Pavilion was recently accused and stepped down because of sexual harassment claims, um, there. So this is an interesting story. Innovation Pavilion is one that we've got to know a little bit over the years as a place where like we've had ISSA and other security meetings at them.

Uh, and you know, this, this MeToo movement has struck pretty close to home here. All right, so next story looks like the Colorado governor has signed a law requiring more protection of consumer data. Yeah, so this is a pretty big, you know, change here for Colorado law and protection here for us. We had, was it 4 different elements that are worth talking about? Number 1, we have a 30-day notification window where we have to notify not only the impacted consumers but the Attorney General of Colorado, that is if there's more than 500 Colorado residents who are impacted by it.

Second element, it requires that both companies and government agencies develop practices ensuring that unneeded records are destroyed. So basically we don't keep all of that consumer data forever, get rid of it when you don't need it anymore. And then finally, we have to implement and maintain adequate security measures against data breaches. So that's pretty easy, right? Right, yeah, no, no problem there.

And don't we have to do all this in, in 30 days? Uh, was it August 1st? I think it's August 1st that it goes into effect. So yeah, not, I mean, not too long, right? 60 days from, from a couple days ago.

And then how long do they have to report, or how long do we have to report a breach? Isn't it somewhere along the lines of 30 days? Yeah, 30 days. Yeah. Yep.

30 days if it's over 500 people. And, um, you know, it's, it's one of the strictest in, in the country. It's, it's tied for the strictest in the country. However, I don't feel like there's a lot of bite here for any of it. You know, you have the policies saying how you're gonna get rid of data.

Well, okay, what does that mean exactly, right? If I have a policy that says I will get rid of data after I don't need it, is that adequate or do you need more? Right. And then of course there's back to this, you know, adequate safeguards against a breach. That's pretty tough to define as well.

Right, absolutely. Yeah, so we have a link to a story about it. We also have a link to the bill itself if you wanna read it and get yourself more educated. It's great reading. So let's talk a little bit about LogRhythm.

Yeah, big change over there. This is exciting. Yeah, so, so LogRhythm was acquired by, uh, Thoma Bravo. Thoma Bravo, one of the biggest private equity firms, especially in the software space. They've had quite a few security companies that they've invested in.

They had a majority and probably, you know, just about 100% stake. They just bought 100% stake or so in LogRhythm just, uh, earlier this week. And they, they took SailPoint public in their IPO, right? And that went pretty— into last year they took SailPoint public. Uh, that was their first IPO.

Generally they've, they've sold most of their companies either to other strategics, so, you know, they might sell like SecureWorks to Dell or, or something like that, or they would take it, sell it to another bigger private equity. But this, they have obviously now shown that they can do IPOs, and this is pretty good stuff. Um, so congratulations for sure to the, the team over there. It looks like From the press releases, Andy Groldyk, who's the CEO, and then the 2 founders are both— they both still have a stake in the company, so they're still invested and gonna, you know, stick with them and hopefully drive to either an IPO or a bigger exit later. Great.

It's pretty good stuff. Final story here that we have this week is a press release that Ping and Coalfire released. Coalfire has brought in Ping to do their IAM work for them, and they just have a case study of interesting how, how they've used Ping to move more towards a zero-trust type of an environment. Pretty good stuff. All right, moving into the Slack Message of the Week.

Uh, once again, thanks to Andre Gaeta, who is our sponsor for the Slack Message of the Week. Uh, we, we do appreciate it, Andre. And this week we're going to give the message to Richard Johnson. Richard brought up the, uh, the Ticketfly breach. I don't know if you had a chance to see that.

Ticketfly is one of those big ticket websites, and they had their site defaced for a short amount of time. If you went out there, it was an anonymous type looking picture, and their whole member database was dumped. So, um, I don't know if you're signed up for Have I Been Pwned, you probably received an email about that recently because it was a— it was some very large number of people involved with that. Be interesting going back and seeing what, what was the vulnerability. How did it happen?

Was it something as simple as a patch not being applied? Default credentials is my guess. Default credentials, all right. I haven't heard yet, but if I was playing the bets, that's what I'd put my money on. So Richard, we'll send you a note and you can pick something from the Colorado Equal Security Store.

We appreciate your support. So why don't we go ahead and jump over to jobs now, starting with my favorite jobs to talk about, the Ping Identity security jobs. We have a senior security analyst that we're looking to hire at Ping. For someone who's got, you know, deep technical knowledge in the Linux networking and security operations areas. It'd be awesome if you're also good at AWS.

Reach out to me if you have any questions about the job. We are looking for someone more senior to help with leadership on that team. Additionally, we are hiring a site reliability engineer who's focused on security operations. So this is someone who's, you know, day in, day out in infrastructure as a service, AWS or, or similar would be great, who wants to be a big part of our, you know, security initiatives going forward there. And from the outside looking in, I can tell you Ping has a great culture and it's an amazing place to work.

Obviously I don't work there, but I know a lot of people that do and they're, they're super happy. Definitely a great company. Cool, thanks, Brad.

And then next we've got a— let's see, this looks like Cronk Sports and Entertainment, a Information Security Director. Yeah, so, so that's Cronky is the, uh, organization that owns like the, the Avalanche and the Denver Nuggets and, um, that, you know, big investors. I think they also own the Los Angeles Rams, but a big company for, for sports here in town. But they do a lot of other stuff as well, network television and all that. And Brian Becker, who we've, who we've talked to on the show a couple times, uh, he is the VP of Security over there and he's looking for a director to help work underneath him.

Great. This one I can say a little easier. Direct Defense is looking for a security analyst team lead. Yeah, so if you want to lead a team there, that sounds pretty good. Optiv is looking to hire a senior advisor on SecOps.

And then Software Engineering Institute, Carnegie Mellon, they're looking for a security engineer. Yeah, it's here in Denver, and I had no idea that they had a presence here. I did not know. I mean, they're, they're the ones who came up with like the Capability Maturity Model, and they do all kinds of great research. Um, so obviously a great place to work if you want to be, you know, talking theoretical security type stuff.

Uh, PwC is hiring a cybersecurity cloud director. I don't know what that means. They do cybersecurity cloud direction, which is good. Could have some Azure and/or AWS and/or Google in the mix. Yeah, any of those things.

And we have Staples, an Archer System Administrator. Yeah, if you want to do GRC tools, that could be fun. SecureSet is hiring a Cybersecurity Lead Instructor. If you want to teach everyone how to do security your way, this is the place to go. And please do.

I think we all need the help. Yeah. And then we have Transamerica, a Senior Paralegal Privacy. Yeah, so a little bit different, somewhat focused on privacy, and certainly the intertwining between security and privacy is just getting closer and closer. Let's go ahead and move over to events.

Uh, as a reminder, we do have an event calendar. Uh, you can take a look there at, uh, what's coming up in the next few weeks or months. We're out scheduled pretty much out to the end of the year at this point, uh, for a lot of different groups. Uh, but we do have a few things here in the next week. So starting on the 5th, uh, the NCC, the National Cybersecurity Center, is doing a Cyber Careers: What Parents, Teachers, and Counselors Should Know.

And then 6/7, 6/8, we've got the ISSA Colorado Springs Annual Cybersecurity and Technology Day, and that's at Fort Carson. Yeah, so we're, we're definitely hitting our, uh, our southern friends here this week. Uh, on the 8th, on Friday here, we have the Women in Technology Conference that's put together by the CTA. And then we have ISSA Denver, the June meetings on 6, 12, 6, 13. If you aren't currently a member of ISSA, I urge you to, to sign up.

There's a lot of value there. I'm actually a member, and it's something that I get a lot of, a lot of value from. A lot of free events that you get to go to as a part of being a member. Membership's pretty cheap. I think it's $120 a year, and you basically get everything for free throughout the year.

Yeah, and it pays for itself, especially if you go to Rocky Mountain InfoSec. Yeah, you get discount on the ticket. Yeah, it's It pays for itself many times over if you go to that conference. Yeah. All right, moving along.

SecureSet has a Hacking 101 focused on PowerShell on the 14th. And then we've got ISC² Secure Summit Denver on 6/15. And that is a full-day conference and a good chance to get to do some networking here in town. Well, that takes us to the end of the news. We have our feature guest coming up.

I sat down with Eddie Mize. Eddie is well known as not only a security leader for Pinnacle Group, but probably better known for his contributions to the community, like his art with the faces of DEF CON. He does a lot of pyrotechnics. He's a rocker. We had a good time getting to meet him and tell some fun stories.

So stick around and listen to that. And with that, Brad, thanks for co-hosting with me this week. Robb, thanks for having me. This was great. All right, well, we'll look forward to talking to you soon.

This is Clay Parker, Director of Security Operations at Trimble Navigation. Welcome to Colorado Equals Security. For Colorado security professionals by Colorado security professionals. All right, this is Robb Reck with Colorado Equal Security, and I am sitting in the Ping office enjoying a Mike's Hard Lemonade with my friend Eddie Mize. Eddie, thank you for supplying the lemonades.

Oh, thanks for having me, Robb. Appreciate it. So the first question I want to understand, how did you end up on a stage opening for 2 bands in Chandler, Arizona, in 2003. Start there. Okay, so I used to play in several bands around Colorado, mostly played drums but have played bass and some other things too and sang.

And I happened to be playing with the Charlotte Jackson Band back then. She's kind of locally famous, has sung the national anthem at several Broncos games and Rockies games and things like that. And so she— we played a lot of kind of classic rock type stuff. Back in those days and was playing percussion and drums with her and singing and also harmonica and a little bit of bass sometimes. And ended up we got invited to come out and open for Grand Funk Railroad on one night and open up for the band America on the next night.

And that was pretty cool in front of about 12,000 people. That's pretty awesome. Yeah, it was pretty nice. And got to go open For Grand Funk, they were just incredible people backstage. We got to hang out with them a little bit and talk to them, and they were super cool.

And then our time came, and so we're putting our stuff up on the stage, and there's some guys there kind of helping out, and the local technicians. And this guy's helping me carry stuff up on the stage, and I thought he's like a local technician. Hey, thanks, man, really appreciate it. Turns out he's the bass player for Grand Funk. He was just— that's how he was just helping.

That's how cool they were. And then I felt terrible, like No, dude, you can't do that. That's awesome. But he did. It was a lot of fun.

So, so were you guys doing covers or original music? Uh, both. Yeah, we had a lot of covers that really played to Sharla's voice. She had an incredible voice, and so she did a lot of things that really fit that well. And then we did some other things too, like did some Lenny Kravitz and some things like that.

What was your favorite cover that you guys played? Probably Lenny Kravitz. Which song? Fly Away. Yeah.

And I sang on that one, so that was a lot of fun too. Oh, that's even more fun then, right? Yeah. Got to go do that. Good times.

And so did you tour for a while, or was it just this one show you guys did? No, we played locally quite a bit for a few years in there. But you didn't go around the country? No, we pretty much tried to stay in here and stay locally. And so we would play kind of all the local venues, you know, Bluebird and Herman's Hideaway and Little Bear and places like that.

So are you still doing it or you're done? No, I just haven't had time. I mean, after that I played with a couple other bands over the years. Played with Flywheel, a band called Flywheel, and a band called Critical Bill, and we played a lot of gigs. And then I'm no great percussionist or drummer, but I'm pretty steady, so I got a lot of work.

So my band that I was in would always loan me out if somebody's got some big gigs. You know, hey, we're doing the Gates Foundation Center down here on Saturday night, can you come sit in percussion? Our percussionist is out, or whatever. I'd go sit in with them. So very cool.

It was a lot of fun. So as interesting as that is, we're not talking about music today. I am interested in learning a little bit about, you know, you, you're a big part of the security community here in Denver, and I want to get some history on that, right? So, so back me up, you know, to the day before you got involved with security. You know, how old is Eddie, and what are you up to then?

You sure you want to go? I want to go that far. Yeah, I think we get like our stone tablets out of the archive and These are Palm Pilots. Yeah, I think it was, um, I was trying to remember, probably, I mean, I got involved with computers probably around '79, '80. Yeah.

And some friends of mine and I, you know, there wasn't computers in schools or anything like that, and some friends of mine, we had a couple of TRS-80 Model 1s and 3s at school that— not from the school, but one of our math professors had got these on some kind of used thing and brought them in and said, hey, we should have this computer club. There was no curriculum. And so we started doing this computer club and messing with those, and from those we kind of had an electrical engineer buddy. His dad was— I think he was at Lockheed or somewhere, and so he got us started on kind of building these Zilog Z80 machines for ourselves and putting those together, kind of like the little Timex and Clear 1000s back in the day and working with those and then got the ability to do some dial-up with some UARTs and acoustic couplers and started sequentially dialing numbers and writing code for that and doing all kinds of fun stuff. So you started sequentially dialing phone numbers for the purpose of?

Just seeing what was out there, honestly, really. Seeing if any modems answered is all we're looking for? Yeah, it was kind of a new thing. I mean, the WarGames movie hadn't even come out yet and so we just thought it was cool. We didn't even know it was called war dialing.

We just, hey, this is cool, you can do this. And my buddy came up with the idea, so we started doing it. And then some people came and said knock it off. Yeah, basically.

Yeah. Or said, you know, don't do anything bad. We weren't doing anything nefarious, but we might have gotten into some systems and stuff. So you're still talking early '80s at that point then? Yeah, real early '80s.

Under the age of 18. Right. I'm sure statute of limitations is long in the past. Long in the past, yeah. It wasn't even illegal back then.

You could sequentially dial all day long as long— and the CFAA wasn't around. Really, it was kind of cautionary, not so much that we were doing anything wrong. Right. What next? You hacked around a little bit, it sounds like, explored what computers you could get access to.

Where'd you go from there? So then really got just into the IT side of things for quite a while. Worked for Heatcraft, which was Lennox Heating and Air Conditioning. So where'd you grow up, by the way? Where were you doing all this?

So some of that was in Texas and some of it was in Tennessee. I was born in Tennessee. And then when I worked for Heatcraft, that was actually in Tennessee. So they're the circuit board division of Lennox Heating and Air. And so I started Actually was just kind of pushing a cart around doing a day job kind of thing.

And thought like after a day of that in this factory, this is terrible stuff. And this guy comes running up to me in a suit and says, hey, everybody says you know about computers. Yeah. And he was like, hey, we just lost all our data in the offices. Can you come help us?

Went up, helped him out. The plant manager came up and said, you're not doing that anymore. You're doing computers. Put me in this room. Did all the computers, learned robotics, started doing all their robots.

Manufacturing robots, got into all their Q&A stuff for their circuit boards and learned all kinds of electronics and circuitry. I didn't really have much training in that before that, but got to work with just incredible people that were really sharp. It kind of progressed from there, and then a company hired me away to Texas to come build out all the network stuff for Compaq Computers when they were just spinning up in Tomball. So moved out there and did that, and then from there it just grew and grew and grew. And ended up at Luanne and Associates in the early '90s and was with them all during the '90s.

Was that still in Texas? No, Luanne here in Denver. Okay. Yeah, Paul Lloyd Luanne. I know Luanne had a presence here.

Are they— that's headquarters. Okay. So is that what brought you to Colorado? Uh, no, I ended up doing a great big job in Tennessee and finishing it up, and then the next contract was going to have me flying all over the country, and I said, you know, I've always been in the mountains. So I said I really would just prefer to pack up and go to Colorado.

So I packed everything up, came out to Colorado Springs, and the next day Lawan and Associates hired me, just kind of off the street. So you just chose to come and you ran into that job with them? Yeah. You said that was early '90s? Yeah.

So you've been here for 20, 25 years? Yeah, a little more than that. Yeah. And then I did take a year and lived in Alaska. So I went to work for Mike Rage, They recruited me out of Lawan for a long time and finally took the job.

Went up there and did basically a year-long job for them building out a bunch of stuff out of Anchorage and Fairbanks and then came back. What's— you said MicroAge? MicroAge. MicroAge, what's that? They were a big systems integrator back in the '90s.

They were the largest kind of networking and systems integrator in Alaska at the time. So they took you up there in the '90s is what we're talking about? Yeah, at the very end of the '90s, like '99. How was Alaska? I loved it.

Yeah, my wife at the time did not. She wanted to come back to the lower 48. Yeah, so that was fun. And then even before that though, I had started doing a lot of security work for our customers through LeJuan and did some for DOD and some other places all around Colorado, firewall stuff and kind of those things in the mid-'90s, and some pharmaceutical organizations and so forth. Won't name too many names.

Security is still kind of a Wild West in a lot of ways, but in the '90s it was— Total Wild West. Totally. Can you tell me a story or two? What did you see in the '90s that we wouldn't believe at this point? Yeah, there was a few.

Did a bunch of work for a belt and hose manufacturer. Here in town. And the owner called me in one day. I'd done work for them for a few years at this point and called me in and they had a Chinese site that was the name of their company, their domain with a CN appended to it, and they were selling knockoff products and just asked if I could help them to remove that because there's no trademark or copyright enforced over there. And so did some things to helped that go away.

We might call this offensive security. Yeah, we'd call it hackback now. The fun thing about it was then years and years later, Jamie Heery and I from Cisco— he's their only DSE for security worldwide. He's a pretty big name and wrote the— What's a DSE? Distinguished Security Engineer, Systems Engineer, something like that.

Then he actually wrote the ICE and the NAC book for Cisco Press and some other things. He and I had started Colorado Healthcare Information Security Users Group, which Drew Labow is part of, and Kristen Garrison and some other people, and got that all kind of fired up in the mid-2000s. We were doing that, and so we had this speaker come from— who I won't say the name, but he used to work for State Department and some other things, and he worked for Schwarzkopf and some other people doing some digital stuff. When he came, he gave this great talk and we were all excited. When he got done, we were going to go up to meet him, but he just got swarmed by everybody there.

So we kind of hung back, and after he had talked to some people and stuff, he goes, I know who you are. I'm like, I never met you before. He goes, yeah, I was— because he had worked with the NSA, obviously, and some other people back in those days with the Gates thing, or the— now it's to, but everybody knows. But he had been involved in that and he said, here's what you did. Like they had watched.

So he knew all about it. Like he knew exactly what I did. And he goes, we couldn't do anything about it, but we weren't going to stop you. So they watched everything you did and cheered on from the sidelines, huh? Well, probably officially didn't cheer, but it was allowed to happen.

That's interesting. Interesting.

It sounds like in the '90s is kind of when you were transitioning from being hardcore IT to getting more officially on the security side. Is that right? Yeah, mid-'90s. Yes, sir.

I know you've changed gigs a couple of times. After you came back from Alaska, what came up next? I came back and worked, consulted with a company called Timberland that I actually had started back in the '90s as a side company and sold it to a couple guys and came back in and worked through that organization for them and worked for a couple other big customers that I'd worked with previously and also did some work with Lawan a little bit when I came back, but independent at that point. So 1099 to them for all that, and then that continued on through into early 2008, and then Exempla Healthcare came after me pretty hard and wanted to hire me over to be their CISO. So we kind of negotiated for a few months, and then early 2008, I took that job.

Were you the first CISO for Exempla? Yeah, actually, that's a great question. It's pretty funny. So a guy named Michael Hossmann was their first security person. They didn't call him CISO then.

They called it security manager or something. Michael Ostmann, a lot of weird coincidences there. Now we're great friends, but back in those days I didn't know him. He had been there before I came and then left, and they'd been a while without a security person before they got me over there to build the team. And he's the person who created the HackRF One and the Ubertooth devices, so he's really instrumental in the radio world, SDR world, and has been really involved in the security community, very high profile since then.

It turned out we actually lived 3 or 4 doors down from each other in the mountains all that time and didn't know it.

Fast forward all these years, now we know each other. That's awesome. It sounds like that job at Exempla was kind of your first real internal security gig. Is that right? Right.

That was the first time I'd come out of the consulting world and gone inside for that. And stayed at Exempla until we merged with Sisters of Charity Living Worth Health. That's not easy to say. Yeah, SCL Health now. Back in those days it was the full— you didn't say the whole thing.

Yeah, and then became the CISO for both organizations. So we ended up with, you know, 11 hospitals and several clinics and so on. Yeah, and you, you were there, you said 2008 to when? When did you leave? Uh, I was there through 2012.

Yeah, so about 4 years. Yeah, decent run. And yeah. What drew you out? Why'd you leave there?

There were some changes internally. At that point in time, there were some challenges around making any headway on the security program. Then what'd you choose to go do? What was the next step? I went back out and started consulting again.

On your own or? I actually worked again with LeJuan as 1099 and at the same time with the Pinnacle Group 1099, so split my time between those two. And then the Pinnacle Group for the next several months kind of kept hinting at, really would like you to kind of come on and build that program and run that. And so pretty soon they made it too attractive and I couldn't say no anymore and I took that. You should have said no for another couple months until the offer keeps getting better, right?

Well, yeah, I did. That's what I did, he says. So you've been there for 5 years? Almost, yeah. It's been, I think, about 4 years officially once I took the full-time role, and then another close to a year on a consulting basis before that.

And what's it been like building that practice? And I guess let's assume nobody listening knows what Pinnacle Group is. What do you guys do, and what were you doing before you got there, or what were they doing before you got there? Yeah, absolutely. And that's kind of a fun story too, kind of all those small world things happen.

So the Pinnacle Group has been around for over 30 years, single owner, and they were a value-added reseller. They did box sales, software licensing for many, many, many years. And then several years ago, I don't remember when this was, but they got very aggressive and came after a lot of the people that were leaving Lawan and Associates that I'd worked with for many years before that. Ultimately, they ended up hiring away some salespeople or people that were already leaving, and they hired them. So they ended up with some of those people, and then they hired away some service folks that I knew really well that were wonderful people and built a service department.

They'd never had that before. So they started offering more like traditional services, so storage, compute, architecture, DBAs, everything except security, and hired away some of these really good friends of mine that I'd worked with for all those years at LeJuan. And so that was one of the things that made it really attractive when I went out on my own, is for them to come talk to me about, hey, why don't you come contract with us, and then eventually why don't you come be here and build this program out? Yeah, because I already knew a lot of them. And so that was really nice, kind of to reconnect with those people and get to work with them again and, and in that new environment.

Yeah. So you came in there, sounds like 2013-ish, came in came in there. Yes, that's right. What did it look like to build that program? Were you the first one doing security services?

Yeah, absolutely. So you're hunting and killing and delivery and all that. So how did you go about building a security practice? Well, right away, I realized that they were going to need a lot of the resources with specialties and SME-type stuff and way beyond my abilities in very specific areas. So I started getting together a pretty good stable of 1099 contractor type people that we could partner with and bring them aboard to do very special things.

Like what? What are the special things? All the traditional services, so red team and pen test type services for those kinds of assessments, risk assessments, so non-adversarial type things, virtual CISO type work, investigations and private investigator type licensing, DFIR. Digital forensics and incident response type people that were specific on that. Then I've really had the privilege over that time to not only— I knew most of these people already, but to get to work with them, bring them on board, and then go be part of those teams and get to engage with them and those clients.

That was really cool. How big is the Pinnacle Group as a starting point? There's about 50 people that are permanent and then probably another 100 people that are part of that partner stable that we work with. Out of that 150, how many of them are security? About 100.

Wow.

It went from being 0% of the company to being 2/3 of the company in the last 5 years? Including the partners, yeah. Wow, holy smokes. I was very privileged in the fact that I'd been such an integral part of DEF CON and a lot of the other security conferences over the years that I already knew a lot of those people, so it was pretty easy to persuade them to, hey, why don't you come work with us? Yeah, we have these opportunities and just got to work with some amazing people.

Yeah, well, that's a good segue. Yeah, I know you have a lot of industry, you know, community involvement with Back Me Up. And how did that get started? Were you, you know, in the '90s or before the '90s? How did you get the broader industry connections that you have?

Yeah, so I'm just trying to even remember when this happened, but it was in the 2000s, I think early 2000s. So I knew Russ Rogers really, really well. He's the guy that's been running DEF CON for the last many, many, many years. Not the last 2, but before that he ran it as sort of the chief operating officer. So he and Jeff that started Black Hat— Jeff Moss is the— Yeah.

He and Jeff had kind of built it up, and Jeff had kind of stepped away from DEF CON some and had Russ run a lot of that. And so Russ was running that, and he He just kind of kept coming after me, hey, man, you got to come to DEF CON and hang out. Just come be a goon, which is their terminology for staff, and we'll put you into somewhere and come and do that. He kept that up for a long time, and finally— I always had stuff that conflicted. There was always something going on and I couldn't make it.

Finally, one year I went, and they put me— I think I was information booth or something, like a staffer for them. Information booth. And so already it was great because I walked in and already knew a ton of people because I had already been involved with a lot of people in the community. And so that was kind of neat. It wasn't this raw startup from scratch kind of thing.

And the second day, I think it was Joe Grand back in those days was making all the badges for DEF CON, and he came over and he said, hey, can you draw my badge? So I drew his badge, and Russ— I think maybe Russ was first. Can you come draw my badge? Drew on his badge. Joe Granz, Pyro came over, Luke McCombie, and said, can you draw my badge?

And then it just grew and grew, and Jeff came over, and it just, it blossomed this big thing. And Russ said, we gotta quit doing this for free because if you're gonna draw on people's badges, why don't you tell them it's like $5 for EFF, Electronic Frontier Foundation, make some money? And so we did, and that went huge. And so the next year I came back, and Russ said, you're not You're not gonna do InfoBooth anymore, we're giving you a booth. So they put a booth together and I started doing this kind of art for charity thing and benefited like Electronic Frontier Foundation, Hackers for Charity, a lot of these kind of organizations.

So I want to step back. Those who don't know, I know you are an artist. How did you become an artist? Where did this interest— you know, we talked about your computers at a young age. Did you have a similar interest in drawing growing up?

I doodled. But didn't have any training or any concept of that as even really a serious hobby. Just kind of, I was that kid in class, you know, I'd doodle on all my notebooks and do Van Halen logos or whatever. Me too, it didn't turn into anything for me. So, but nothing really became of it, and then in 2000, about 2002, I went through some pretty tough life changes and so forth.

And kind of to deal with that, I just started painting and drawing on my own and kind of grew. And so I ended up with a house full of art. I never showed people. It was just there. But I knew Russ really well.

We'd been in a couple of bands together and we'd worked together since 2000, actually '99 I think. And so he came over and he said, hey, you got to put that up on a website. And I'm like, no, it's It's not really for public consumption. He kept at me and so he said, all right. So I let him put it up on a website and then pretty quickly I got contacted by this guy and he said, hey, I've got this band in LA and we play all over and could we use your art for our shows?

And I'm thinking, yeah, like garage band, you know. Yeah. Probably have 50 people at their show. Yeah. And it turns out they were a pretty big name, especially in Europe.

They were kind of this thrash metal stuff, which is not my style. So he would send me pictures of these Jumbotrons with my art up on it at their shows and tons of people in Europe. That was pretty cool. Is this David Hasselhoff we're talking about? I know he's big in Europe.

I don't think he was in a thrash metal band, but who knows? What do I know? I like that visual though now that I think about it. A whole Rob Halford thing going on. But then I guess they were in contact with— this is another small world story— they were in contact with this record label out of San Francisco and they were called Old School Metal Records.

And so this guy calls me one day and he says, hey, I'm the CEO of Old School Metal Records and I'm about to sign Anger Is Art, this thrash metal band, and they use your stuff all the time. Could you do their album cover? Yeah, sure. Whatever. So I did an album cover, and then he calls me back and he said, would you be staff artist for Old School Metal Records and do various— you know, I'm like, yeah, if I can do it in my spare time.

Pretty busy. And he's like, yeah, okay. So I did, and I ended up doing a bunch of album covers for different thrash metal bands, music I didn't care that much for. I'm kind of an old, old school classic rock guy. And, um, and then one day he sent me some pictures of this— some photographs of this guy on stage playing guitar.

And he said, can you draw this guy? So I drew the guy and sent it back to him and he said, the guy wants to talk to you. And I ended up in this conversation. Well, it turns out it was Dan Spitz, the lead guitarist from Anthrax. And I didn't know Anthrax from Adam.

But Dan was a really nice guy so I ended up talking to him and then started doing art for him like on the side. So I did a ton of projects with him over the years. And that kind of got me involved with Peter Balz from the rock group Accept, so kind of these '80s hair metal bands and thrash bands and stuff. And ended up talking to a whole bunch of different bands and working in that kind of community. And that was cool, but this guy Swissman that was the CEO for Old School Metal Records— so now flash forward many more years and career is going along great on my normal day job.

Jamie Heery and I were talking one day and he said, you and I are going to go speak at Cisco Live. So we went and did a Red Team/Blue Team talk at Cisco Live. He said, this guy wants to meet you. This guy comes over, this great big blonde-haired giant guy, and he's like, hey, Eddie, and he gives me a big hug. He said, I'm Swiss Man.

I go, what? He goes, yeah, I run this division of Cisco. I go, you're the CEO of Old School Metal Records? He's like, yeah. And so another weird— That's so random.

Yeah, small world coincidence. And so became really good friends with him in a whole different way. So that was cool. So what I know your art best for is the Faces of DEF CON. Can you talk about that at all?

How'd that come about? And maybe for those who don't know, what is it? Sure, absolutely.

So yeah, the Faces of DEF CON thing started I kind of like the badges that I was talking about at DEF CON. Um, I ended up, uh, I think I drew a picture of Russ first. Again, Russ is always the subject matter on those. And then Pyro came up and said, hey, can you, can you do one of those little portraits of me? And so I was doing them with food, right?

So it was like Sharpie and lime juice and soy sauce and wine and tea and coffee and all this stuff. So what were you making them on, just a piece of paper sitting? Yeah, sometimes canvas, Sometimes paper, just, it wasn't— I didn't intend for them to be archival. They weren't supposed to be hanging on a wall somewhere, right? It's like, I'm not going to use acid-free paper and then put all these acidic and caustic things on it.

It's like, what's the point, right? And, and so it was kind of a goof to start with. Ah, cool, Russ, it looks like Russ. And Russ went crazy, and then Pyro, and then Jeff. Did one of Jeff, um, and then I don't even remember where it progressed, but More and more people started coming up, hey, will you draw me?

Will you draw me? Okay, cool. And what were you doing with them? You were just giving them to the person or were they going— what was happening with them? Nobody even really cared.

All they wanted was the digital version. So they just took a picture of it? Yeah, like I would scan them in and then they could have the digital. And my intent was just, if you want the original, I'll give you the original. It's gonna go in the trash eventually.

And so it just got nuts. Like, so those people all started using them for their avatars for Twitter, Facebook, LinkedIn. Yeah, what year was it that this started? Oh my gosh, that's a great question.

I don't even remember. I want to say maybe 2013, '14. Okay, so 5 years ago. Yeah, not too long ago. And then it got really crazy.

Like, so anywhere I went to any of the cons, especially especially DEF CON, I would get swarmed and now what all people wanted was, hey, will you draw the Faces of DEF CON thing for me? And so that was kind of fun for a while, but then some people would get pissed like, I'm better known than that guy, why would you draw me, you drew him. I can't get to everybody, I'll do as many as I can. And I could do them pretty quick and knock them out, but it was like, and then it about that time, then I think that DEF CON, DEF CON 21, I would say they filmed the DEF CON 20 documentary, and Jason Scott that produced that put a pretty big segment of me and my art in there. And then right after that, people all kind of start talking about those Faces of DEF CON.

So it wasn't even about the art anymore, it was FOD stuff. And so the next year Russ and Jeff kind of tricked me. So they— at the closing ceremonies, you know, you got like whatever, 8,000 people out there and everybody watching it on their closed-circuit TV stuff. And Russ got up and he said, hey, where's Eddie? And I was kind of over on the side getting this— we were doing this charity thing and, you know, what's going on?

He calls me up there and he and Jeff were up there and they had taken this big poster of all the ones I had done so far. I think back in those, maybe it was like 150, and they got everybody to sign them. Oh, that's awesome. And then they presented it to me in front of the closing ceremony. It was kind of embarrassing, but it was, it was cool.

Very nice thing of them to do. And so that was neat. And then after that, it just, it became less fun. So you said 150. How many would you say you've done at this point?

Uh, over 500. Yeah, man. Is a lot of them. That's a lot of people. Yeah, and even now, and I haven't done any, I do just a couple a year now, but when I go to anything, DerbyCon, ShmooCon, GRRCon, Circle City, any B-Sides, whatever, everybody always kind of mobs, hey, how do I get one of those things?

Yeah, really not doing those much anymore. So do you know all of the 500 people, 500+ people, or was it some of them who you just met and just did it? I knew them all except the dead ones, people that passed away, and I did several of them that were memorials because people had requested it that were really involved in the security community and all that kind of stuff. That's kind of sad. Yeah, but it made their families, it really made an impact on them.

And then one other thing came out of that is there's this guy that was a senior editor for Rolling Stone magazine, and he knew some security community people, DEF CON people. He got a hold of me and he said, I'm not part of that, but I just want to pay you. Will you draw my face? I want to use it for my stuff. Yeah, okay.

So he paid me and I drew his face. And another small world story. So I grew up like in the '70s when it first came out, '76, '77. We played Dungeons Dragons. Nobody knew what that was, right?

We were the geek kids, but Original edition? Yeah, we were like, yeah, we had the original green basic manual and stuff. And so I was always a Gary Gygax, Gygax, however you wanna pronounce his name, I was a fanatical fan because of all that. Like, and you know, here's my high school days and we were playing that all the time and stuff. And it was at that point you'd talk to people about it, they didn't know what you're talking about.

That was pretty new. And so I never got to meet him. I went to a couple of conventions and things but never got to meet him. So, all right, so flash forward all these years. A couple years ago, a buddy of mine that had helped work my booth at DEF CON sends me this text.

He said, hey, Gary Gygax's biography is out. Like, oh cool, I got to get it. He goes, you're on the front cover, front page. And I go, what? He goes, your name is— I go, what are you talking about?

And he sends me this text and it's that picture that I drew of that guy from Rolling Stone. Some random guy. That guy wrote the biography of Gary Gygax. Okay. The guy that was the senior editor of Rolling Stone.

And so they had a picture that I drew of him as his about the author thing and credited me in there. And I was like, okay, that's a tiny little thing but it's my little small world fun story. Yeah, that's pretty awesome. That's a bucket list. Yeah.

I wonder if you could use that as a way to get to meet Gary. Is he still alive? I don't even know. No, he passed away a few years ago. All right, well, that's cool.

Uh, so we talked a little bit off when we weren't recording about, uh, the 303 group in town, and I know you, you're, you're involved with those guys. We've had a few 303-type folks on here. We had— what is this 303 here? We had, we had Banshee, and we've had Jericho, and Chris Nickerson, and we've had, uh, Chris Roberts talk. And I'd love to know, how do you get plugged in with that group?

And just kind of talk to me about what that is, because I feel like there's a good chunk of folks in town who really don't even know what that is, right? So just as a starting point, what is the 303 Group? Well, officially it doesn't exist. Okay, the first rule of 303 is I don't really know those people you're talking about. Sorry guys.

Um, no, but, um, we'd like to say that we're a drinking group with a hacking problem. Okay, so yeah, that's fair. Yeah, no, it's, um, when I got involved Again, Russ seems like the source of all evil with all my involvement with these things, but Russ and Pyro, I knew them before I knew the rest of the guys. And so even before I went to DEF CON, Russ and Pyro kind of got me to start coming out. And back in those days, we had a single place that we would meet on Friday nights, and it was pretty consistent and a good group of those people would show up, and started going and hanging out with them.

And it was great. I mean, it was— everybody'd have some drinks and some food, and you'd sit around and talk about hacking and security and all kinds of fun, interesting things. And started doing that really regularly and got involved with them. And then over time, as you probably know, at DEF CON, the 303 group sort of, it's a joke, we've kind of taken over, right? So I think at one point a couple years ago, 303 ran like 40-50% of DEF CON, people that were involved with 303.

I know the 303 party is everyone's favorite part of the event, right? Yeah, everybody kind of comes to that, so that's fun. Yeah, so that's so many stories with that group, but just a lot of fantastic people and people have been super supportive, not only career-wise but on all these other things we're talking about with art and everything else too. And then I actually got into pyrotechnics and explosives through 303 also and through DEF CON. I ended up— Joe Grand had a good friend, Dr. Zoz Brooks, that he did some TV shows for Discovery Channel with, and they had one called Prototype This and and stuff.

So he introduced me to Zoz at DEF CON one year, and Zoz and I started talking and became friends. And then he said— and he's just this brilliant guy, he's got PhDs from MIT and all this other stuff he's involved in— and he said, hey, I'm gonna come out to Denver. He's from Adelaide, Australia, and he lives in Cambridge and does a bunch of work for MIT and stuff. He said, I'm gonna come out to Denver and meet a friend of mine, hang out with a friend of mine. He goes, I want you to meet this guy.

All right, so he came out and we went to Pints and had some scotch and we're hanging out with this guy and turns out this guy's name was Mark Williams and he ran Night Music Professional Pyrotechnics. So he said, hey, you, you like to blow stuff up? Of course I like to blow stuff up, who doesn't? Would you like to do it legally? Yes, that would be far preferable than anything that may or may not have occurred occurred in my life previously.

And so went to some training and some hazmat stuff with him and some background checks and got my license for explosives manufacturer and employee possessor and all the fun stuff from the DOJ. So at that— at this point, if I wanted to have someone blow some stuff up, you'd be the guy to call? Well, I mean, I could tell you what to do, but we'd have to go through some— Professionally, do you do this professionally though? Yeah, yeah, there you go. Yeah.

You're the guy to call. Yeah, I would— I get you for sure in touch with our team and see what you needed to do. So that's pretty fun. So have you got to do any, any big shows around town? Any examples you can give?

You've probably seen them. Well, give me— what's an example or two? Um, the Highlands Ranch and the Parker and the Douglas County, uh, Fourth of July shows every year. Okay. The School of Mines E-Day show every year.

What's E-Day? E-Days is their big homecoming alumni thing at School of Mines. It's a big deal. The CSU homecoming every year, that big show, we do that every year. The Monarch New Year's Eve show at Monarch Ski Area up on the slopes, we do that every year.

And we've done a couple downtown, and let's see what else. Regis, the big Regis show every year, a few like that. So when I, so when I was sitting in Red Rocks on the 4th of July watching Blues Traveler and then watching all the fireworks shows, some significant percentage of those shows are you guys. 3 of them are us. Okay, the 3, the 3 to the right.

To the right, yes, that's right. Anything down south and, and out east is us. All right, all right, I like it. Uh, any, any fun stories you can share about that where something hasn't gone according to plan? I don't want to get you in any trouble here.

No, no, I can, I can tell you one that nothing, nothing too terrible happen. We were actually licensed for manufacturing development too, so we were up in northern Colorado and it was Luke— Pyro is involved with us too, and Russ wasn't at that one, he was involved some, but Luke was there and Zoz and a few other people, and my boss Mark came out and he's got this big star mortar charge We didn't know it was a star, it was just a mortar charge. What's a star mean? A star mortar charge kind of blows the little glowing stars, you know, every direction, 800 feet in every direction. And so he said, hey, this— the label's not on this, it's older, I don't know what it is, and you want to blow it up?

Of course, I'm always a volunteer for that stuff. And so he put a kind of old-school traditional fuse. We normally would do that electronically. Put an old-school traditional fuse in it, and we have a test pit out there where we do development and stuff, and some bunkers. And Luke was in a bunker a long ways away, and he's doing what we call diapering flash.

So he's mixing some flash powder, so pretty high-explosive stuff, and he's making some, some different things that they're doing development on. And they had left the side door open to this while he's in there because it's middle summer, it's hot, so he's in there. And I went out into the test pit and lit this thing and threw it, ran off and hid behind this other bunker thing. And it was a star mortar, which means those stars went in every direction. Yeah, a long ways.

Yeah. And so here's Luke, he tells the story, he's in there working on this flash and he's seeing glowing stars fly by that open door at 100 miles an hour. Well, he's in a table full of highly explosive flash. So that's a scary— and we caught a couple of pastures on fire and had to go put them out and stuff like that. So for those people listening who may try and do neighborhood fireworks— no, do not.

Any advice for them? Yeah, don't. Come see our shows. Don't do that. Yeah, come talk to me.

We'll get you— I'll get you close up to see some really, really really cool stuff and it's much safer. All right, fair enough. We have over 30 years in our company with no significant injuries.

So you've got a lot of stuff. I hear music, I hear art, I hear fireworks. Occasionally you have time for some security stuff. Yeah, these days it's more security than that, but definitely a storied past. And then I was on Discovery Channel because I climbed all the 14,000-foot peaks back when that wasn't a thing.

You got all the 14ers? Yeah, a long time ago. There's a lot, like 50-something? 54 or 56, depending on who you talk to. Yeah.

Did you do 54 or 56? I'm talking to you. I've done 56, but I count them as 54. There's 2 that, that are part of other mountains to me. Okay.

So back when— in this, we're talking about '90s— like, I was doing all this stuff, and it wasn't like you'd go to the top of a 14er on a nice Saturday in midsummer Yeah, and not see anybody. Well, now it's, you know, there's a line, there's 1,000 people, right? But back in those days it was not that way. And in the books back in those days, you had one book basically, this Bornman-Lampert Guide, and you went and bought that sacred book and it had your maps. We didn't have GPS, so you're following your maps and figuring stuff out, and it listed 54.

Yeah. And then there was a couple others that now are considered possible 14ers, but they're really just a sub-peak of one. Right, just go across a— yeah, a ridge. Yeah, yeah. Well, very cool.

I mean, it sounds like there's so many interesting things going on, the community you're involved with. What's kept you in Colorado for the last 20-ish years? Started out as mountains. Yeah. And then really became people.

Yeah. The mountains are why I came back out here and what I wanted to do. And then got involved with a lot of great people at Lawan and then kind of maintained those relationships and then got involved with people like Russ and Pyro and other people and then the 303 folks and just, just wonderful group of people. I think that the people here are just unsurpassed and I travel all the time, but I love it. I love the community.

Yeah, it's been, it's an amazing place where I feel like there is level of openness and willingness to share that I've never seen anywhere else. It is. It's great. Yeah. So a couple of pieces of advice.

What advice would you give to someone who's looking to break into the security field? I mean, there's all kinds of things that you can talk about with education and certifications and things like that, but reality is to really get into that, you need those things, but the reality is go get involved. Involved. Go to the DerbyCons, the GRRCons, DEF CON, BSides, there's BSides Denver, go to RMISC, go start to integrate with the community and meet people. Once that happens, everything else will become more clear.

You'll realize educationally the direction you need to go. You'll realize certifications that don't mean anything or the ones that do and something that can really help you and so forth. Any particular part of security that you would advise folks to look into? There's pen testing and there's blue teaming, there's GRC, there's audit, there's all kinds of things. Where would you suggest we most need folks and people should focus their efforts?

Well, what we're seeing the most right now is really SecOps and DFIR, so digital forensics and incident response. There's a huge vacuum right You cannot get enough people for that. There's so many incidents. Might be because there's not enough people doing security operations. Yeah, that's exactly right.

That's a good point. If you did better SecOps, you wouldn't need so much deeper, right? That's a good point. An ounce of prevention is worth a pound of cure. Absolutely.

Something like that. But yeah, I mean, you know this probably better than anyone else. There's a vacuum in that area too. It's hard to get really good security people. And people think in terms of If I'm going to do security operations, I'm going to go study security exclusively.

They get so niched in that and they don't have that wide background of architecture and servers and networking and all these other things. To really be able to do security, if you're going to secure it, you need to understand it. I talked about that the other day. Starting at that foundational level, I think, is really valuable. I'd echo what you said for anyone listening.

If you want to get into security, don't go get into security. Go learn whatever technology it is that you want to secure. Become an expert at that thing, and then security is just one aspect of it. You can become a full-time security person doing that, but go learn the technology first because that's what makes you marketable, and that's what makes you the best in the world at anything. The other advice I wanted to get from you, what advice do you have for people like me, CISOs who are running security programs?

In the Colorado area as a group, what are we not doing enough of or doing too much of, or how should we adjust our perspective? Well, I would say that there's that group and then there's you. You're a little bit different person there, but so I'm going to address that group because you do a lot of these things already. But I think that you have to, you know, it's been said a million times, you have to think adversarially to be able to be effective in defense. I think that people think that that means, oh, I do my twice-annual pen test, I'm good.

My pen testers work. No, there's a lot more to it than that. It's really a holistic approach and really thinking in terms of security and what I call the 4 legs of the stool. You've seen it a million times when we're doing testing, we'll see somebody who's digitally fantastic. They've just done a great job from a digital perspective, but their physical security is atrocious.

Their social education, things for social engineering, is atrocious. Their governance is virtually nonexistent, or it's a book somewhere that no one ever looks at and they don't follow it. It's really those 4 legs of the stool. It's digital, physical, social, and governance or administrative. I think that if you fall down on any one of those legs, the stool falls over.

You can have big, beefy, log-shaped legs on digital and physical and social and nothing on governance, you're going to fall over. Same thing with any of those. I think to your earlier point, thinking about adversarial, it depends on what threats you're worried about. If the threat you're worried about is a nation-state attacker, you're going to need to focus a lot on your detective controls because you're not going to stop them. But maybe you can know about it immediately, and maybe you can get really good at response.

Maybe if all you're worried about is being hacked from online, your physical is not as important. But if you're talking about a nation-state who can come after you, well, then physical is an awfully important part of it. It's an interesting consideration. Think about who's coming after you in addition. Those 4 lenses, the physical, digital, social, and governance, I don't think I've ever heard it put quite that way.

Interesting. The other thing I always start with, I know that you do too, we've talked about a little bit, but it's understanding the target, understanding the value. What does your organization need to protect? What's the crown jewels? Then think about how that's going to get attacked.

Is it likely to be a digital-only attack? Is my organization's crown jewels important enough that somebody's going to dedicate the effort and time to come after them in whatever means necessary. If somebody has something I really, really want and I'm a bad guy, maybe I don't stop with digital. Maybe I'm willing to do some physical. Maybe I'm willing to do some social engineering for physical access or some phishing campaigns or whatever that looks like.

Those kinds of things, people don't think about the ends. Think about where you're trying to get to. That's the crown jewels. I want to protect those. Now, what's going to happen to get to those?

The better you define your crown jewels, the more specific and frankly cheaper your security can be because you can just layer those controls around the stuff that really matters. Maybe the rest you're not worried too much about. You're really focusing on that sensitive customer data or that financial data or the healthcare data depending on what your organization is. Better user experience, better security all wrapped up together. Well, Eddie, this has been great.

Anything else you want to say to the community before we call it a wrap? No, I really appreciate I appreciate you having me on. It's great to— I love this community, so it's great to have an ability to talk to them and address them. Awesome. Well, if people want to follow you on Twitter, what's your handle?

I actually don't participate in social media except for LinkedIn. Well, my bad. Not a problem, but I can be found on LinkedIn. I'm just LinkedIn Eddie Mize, E-D-D-I-E-M-I-Z-E. I'm at the Pinnacle Group, so emize@thepinnaclegroup.com.

Cool. Those are good ways to reach me. All right, Eddie, thanks for your time. Thanks a lot. All right, see ya.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time. Remember, Colorado equals security.

Back to all episodes