Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 72, the week of June 18th, and this is Colorado Equals Security. Yes, it is.
Alex, how are you doing? I'm doing well. How are you, Robb? Doing fantastic. Looking forward to yet another wonderful episode discussing some of the most important news that's happening here in the Colorado tech scene.
Only the most important news. Only. We actually hacked those other 2 things that were not most important, right? Yes. Got to call somewhere.
You know, there's a couple things that didn't make the list, including yet another list that showed Denver as being one of the best cities to live in in the country. You know, if there is one thing that is consistent in the news, it's everyone talking about how great Colorado is. That's absolutely true. Before we dive into that wonderful news, we have a couple of reminders for our listeners. Number one, did you know we have a Slack channel?
You know what? I did. It's a wonderful place where you can get to talk to your peers in the Colorado community. We have 480 or so people involved in the Slack channel, including Alex. So that's a good reason to come.
And just recently we added a new channel in the Slack community for those folks that are participating in the Boulder CitySec. Yeah. So if you're a Boulder CitySec person, come on the Slack channel, check it out. You'll know when to go. Absolutely.
If Boulder and security is your thing, like it is Benjamin Edelen's thing, then it's a perfect channel for you. Exactly. We also have a mailing list. You can get signed up if you want to get the show notes delivered into your inbox every week. Go out to colorado-security.com and get signed up.
And if you like the show and you're willing to support us, we do have a Patreon page. You can become a patron of ours. If you commit to at least $10 a month, then you will get a wonderful Colorado Equal Security t-shirt. And we'll also give you a nice shout out on the show. We don't have any new patrons this week, so we don't get to do a shout out this week.
Oh, next week, hopefully one of you can reverse that, you know, one-week trend. Exactly. All right. Let's go ahead and jump into the news. Number one, there is a survey showing the top US and worldwide airports, and good old DIA, or Denver as it's now known, made the list.
I have to say, this is one list where Austin doesn't beat us. Thank God. And so this, this rating was done based on 3 categories: on-time performance, quality of service, and passenger sentiment. I think it's pretty clear how you measure on-time service and passenger sentiment. I don't know how you measure quality of service.
I'm sure that there is someone out there that has a formula to do it. So we were number 3 in the US behind Seattle at number 1 and San Francisco at number 2. Alex, you and I have both been through San Francisco quite a few times, right? Did it seem like the best airport in the country to you? It did not.
Yeah, I'm not sure what makes it so great. Of the Bay Area airports, it is not even my favorite. Which is your favorite? San Jose, I think, is probably the best airport, but I think Oakland is probably the easiest in and out. Hmm.
So if you want to look worldwide, the number one best airport in all the world is the Hamad International Airport in Qatar. That doesn't surprise me. I would have guessed like Dubai or something if I had, if I had had to just pick one, because I think they basically like serve everything for free and first class everywhere you go. Right. And I don't know if we actually said it.
So we were third, but we were also 51st overall in the world. We're 51. We're 51. Yeah, yeah, yeah. Uh, it's, you know, it's a pretty decent ranking.
Yeah, absolutely. Uh, there was also an article this week called, uh, Is Denver a New Kind of Tech Town? Positively. Period. So, so really this article is the one that you want to send to your out-of-state friend who you're trying to convince to come move to Denver.
It's just a really great summary of what makes this a great place to be a technologist. There's some interesting stats. I know one I pulled out of this was that in 2017 there were 39,000 jobs added at a growth which is about a little bit over a percent more than the national average of job growth. Yeah, I thought, you know, one of the big takeaways that I had from the article was essentially the same sentiment that we have about the security community, and, you know, which I guess goes to the larger technology community about how supportive it is, about how welcoming it is. You know, if you're willing to contribute, if you're willing to be nice, people will accept you and help you and be available for you.
Yeah. And there's also this other quote that you had pulled out that Denver Startup Week is one of the biggest— it's actually the biggest free entrepreneurial event in the country with over 20,000 attendees and 367 sessions. So it's a big deal. That is a big deal. Pretty cool.
All right, moving along. We— so we have some news this week, an acquisition. Uh, Boulder-based VictorOps sold to Splunk for $120 million. Yeah, pretty cool. So VictorOps was not a security company per se.
They were more, you know, a performance monitoring sort of company, but they got snatched up into the Splunk ecosystem. Splunk seems to be buying a whole bunch of other companies to, to really go beyond the the, you know, sort of the big, uh, big data log management space and really become more of a platform. You know, it looks like VictorOps, you know, they, they basically do alerting about operational incidents. Uh, that's probably something that could be pretty easily transitioned into security, and I bet Splunk will look to do that there as well. Yeah, if you've got the alerting platform, you can use it for, you know, many other things.
It's just that they used it for operational. Yeah. So Alex, here's a question for you. What do Sam Masiello, John Everson, and Matt Shufeld have in common?
They all live in Colorado. That's one. That's one thing, yes. Something a little more relevant to the news. They're all CISOs.
They are all— they were all finalists for the CISO of the Year Award in 2017. And you know what that means? What does it mean? That we are now open for nominations for this year's CISO of the Year. So if you have a favorite CISO or a most handsome CISO, whatever it is that you think is the criteria that should be used for the CISO of the Year, go ahead and go out there and nominate someone.
It is important that we represent. Last year we did a great job with nominations and we were actually the, the, the most active category. I'd love to see that happen again. And let's just show the CTA and the APEX Awards that the Colorado security community really cares and is engaged with this stuff. If nothing else, you can just use it to kiss up to your boss.
There you go. Yeah, if your, if your boss is a CISO, that's a good way to do it. Uh, next, uh, Optiv named some new executives, a new COO and a new CFO. Uh, Chad Holmes, uh, was the Chief Services and Operations Officer, and Nate Brady is now the Chief Financial Officer. Both of them have a pretty good history.
Both of them worked for Ernst Young, or EY, as I think it's officially called now, in the past. Chad directly came over there from Ernst Young, but before that he was at FireEye, Mandiant, McAfee, Check Point, and Intel. And Brady, the new CFO, was actually the chief accounting officer for Optiv directly before his current job. Yeah, so congratulations to those folks. I feel like we had another recent announcement about leadership appointments at Optiv.
They seem to be adding a lot more executives. And this is not an Optiv-specific comment, but it's fun— it's funny to me that we see all these press releases when they hire executives. I I've never seen a press release to see a non-CEO stepping down, right? Or being asked to leave, right? Yeah, it seems like there should be some kind of news, the revolving door should have 2 sides for all these companies.
They don't. Oh well. But that's not an Opta thing, that's a general industry everywhere you look thing. Next piece of news, Coalfire has a story this week. It's actually just kind of an interesting blog post around how they found a CVE, basically an out-of-band Um, I don't know what XXE stands for.
Do you? Cross— I don't know. I don't know. I don't even know. XXE and a web control.
Basically, it's a neat blog post that talks through how this gentleman did a, uh, a bug bounty and found a really cool, uh, vulnerability. Yeah, I think that the, the takeaway is, is more that, um, the process is interesting that they go through as opposed to the specific vulnerability that they found. And those sorts of details. But there's lots of good links in the article as well if you are someone that's interested in doing a bug bounty. Yeah, so this is, uh, thanks to the author Darryl Damstead.
Uh, he, he wrote this. My recommendation is for those of you listening who are interested in getting into penetration testing or getting into bug bounties, take a look at this. There's some really good tips on how to get started, how to approach the problem, and he does give some resources for other people who have even more resources, right? Yeah, LogRhythm had a blog post this week as well talking about the VPNFilter malware. This was— there's a big announcement over the past couple weeks letting people know from the FBI that you should reboot your router to help fix the problems that could be coming from VPNFilter.
So I don't know that there was anything amazing in this, but it is a really good summary of, uh, of all of the, the different things surrounding VPNFilter. So it's a good place to get all of the information, um, all the way down to the different IOCs. So there's a lot of information packed in that blog post. Um, so it was actually really good. Yeah.
And they do have the Cisco Talos recommendations and they're the ones who did the most research on this. Um, basically, you know, if you think you may be impacted, you should reset your device to factory settings and reboot it. And of course, patch and update your routers with the latest firmware. And it's not the, um, the biggest part of the article, but it does mention the fact that if you're a LogRhythm customer, then you already have rules in place to detect this stuff. All right, so good on them.
Uh, we also have a blog post in here from Red Canary, which is introducing the next chapter of the Atomic Red Team Tests. So they— this is kind of their community involvement, community engagement activities. It's not directly revenue generating from them, but helping other security blue teams get better at what they do. And they have some really nice updates here. Yeah.
So a couple of things that they announced. One, they have a new Slack workspace. So if you want to talk about the Atomic Red Team, you can go into that Slack workspace, converse with the folks that made it and that sort of thing. They've now made it structured and machine readable at its core. The documentation also includes the context around the ATT&CK framework, the MITRE ATT&CK framework, which is one of the things that they base this on.
Um, they have some new APIs that you can use for help, helping to automate the tests. Um, and then they also have a new GitHub page to track all that stuff. So it's, it's cool to see all this maturation that's happening here. I, I do wonder where is it all going and, you know, what is, what is next for the red team, the Atomic Red Team stuff. But it's really cool and I appreciate those guys doing it.
And then we have a couple last stories here and both of them are on along the same lines. Um, first, Regis University adds a cybersecurity undergraduate degree. So for a long time, Regis has had a graduate degree, a master's degree in cybersecurity, and they've been doing a lot of good stuff down there. But now they've added an undergraduate degree. Yeah, so they, they're gonna offer that here in Colorado.
In addition to that, there is another school in Colorado, the Colorado Christian University, that's offering a master's in cybersecurity. And they have a few different emphases there as well. So if you— if your parents want you to go to school but doesn't want you to leave Colorado, or maybe they want you to go to a Christian university and get these degrees, you can do both. You can get the Christian education at Regis. They're a Catholic school.
And then go to get your Christian master's, and it's all set right here for you. Exactly. I will note also, in the Regis program, they do note that as part of this, they're developing and sharing 8 cyber degree classes with high school and community colleges as well. That's awesome. To help boost interest in the field and bring people into cybersecurity.
So that's pretty cool. Very cool stuff. It is neat to see these, these programs getting built. And obviously, this is just going to get bigger as we go, right? Exactly.
Moving along, that is the end of news. We now want to talk about our Slack message of the week. And this is a big shout out to Jeff Ellis. Jeff pointed out to us that there is a Google Cloud Platform training coming up next week here in Denver. So those who aren't AWS people, if you want to learn your Google Cloud, this is your chance to do it.
Even if you are an AWS person and want to learn more about the competition, you know, why it is you might want to be in Google Cloud instead of AWS. It's a free training. I don't know about capacity, but, you know, it's open to anybody. So I assume you should all just show up. Just, yeah, just go.
Just go. Don't register. Just go. But anyway, big thanks to Jeff for doing that. And of course, big thanks to Andre Gaeta.
Andre is the sponsor for the Slack message of the week. Jeff, as the winner, will get his choice of Colorado Equal Security swag from the Colorado Equal Security store. It's all very stylish. All right, why don't we talk about jobs? Hey, why don't we?
So number one job, Ping Identity is hiring. We are hiring a site reliability engineer focused on security operations. So if you want to help keep our, our SaaS product up, located here in Denver, and you want to work on security projects to do it, that's your opportunity. Sweet. Educause is looking for a director of cybersecurity program.
I noticed in the job post they said that they've had their cybersecurity program for 20 years, so it's an established program that you can jump into. That's, that's a long time. Yes, it is. KPMG is hiring a manager of IT security risk assessment. Carbon Black is looking for a threat researcher in reverse engineering.
Pretty cool. Tri-State Generation and Transmission Association. This is what Reed Fudge is, the CISO over there. They are hiring a network security specialist. Staples is looking for a Microsoft Cloud Security Consultant.
Isn't that interesting? Yeah. Staples is hiring a Microsoft Cloud Security Consultant. My guess is it would be an internal consultant, but you never know. My guess would be too, right, that it's to help different business units do that.
I don't think I've ever heard of a company like that having a technology-specific consultant like that. It's just, it's an interesting model. It is. Yeah. All right.
Guild Education is hiring a security engineer. Aetna is looking for an information security specialist for third-party risk assessment. And finally, Colorado's only exclusively SOAR-focused security orchestration automation and response company Swimlane is looking to hire an enterprise sales engineer focused on security operations. And I was careful to say exclusively or solely focused on SOAR because LogRhythm is also playing in the orchestration automation space here. Yeah, so Swimlane this week posted, um, that job and some others on our Slack channel, so there are other jobs available from Swimlane as well.
I think most of them are more either development or sales or other things like that. This was the biggest straight security job that they had. I think if you were to go to swimlane.com and hit enter, you would find those job postings. I bet you would. Yeah.
Hey, do you know we also have a section on our website that's all about events that are coming up? You know, I've heard that there is a calendar that tracks all of them. Yeah. So you could actually like look at it in calendar format. I think you could print it off and you could keep it above your desk as long as you went and printed it off every day or two.
You'd have a really up-to-date calendar of events. I think you, you definitely would. Uh, first, um, ISSA Colorado Springs is having their June meetings on June 19th and 20th. Similarly, the Cloud Security Alliance is having their June chapter meeting on the 19th. On the 20th, ISSA Denver is having a June happy hour, and I believe that's at CyberGRX.
That is at CyberGRX, yeah. And if you haven't had enough drinking after that, you can go over to the DENSEC Meetup, which is at the Rheinhaus, also on the 20th. So downtown, you walk from CyberGRX, walk right over to Rheinhaus, and happy hour to happy hour, and you can look at security people and drink all evening. Uh, on the 21st, uh, AI for GDPR Compliance in Conversation with Darktrace. This is the GDPR meetup group.
Yep. ISSA Colorado Springs has their mini seminar on the 23rd. That's on Saturday morning. On the 26th, uh, the National Cybersecurity Center is doing Beyond Bitcoin: Cryptocurrency and Blockchain for Beginners. This is a good chance for you to learn a little bit about this technology that we are so passionate about.
We didn't have a blockchain article on the show this week. Well, we had to mention it at least a little bit, so that was our mention. Well, we got there. Okay. SecureSet has a Career Conversations with Hillary Constable, all about how to make your resume shine, and that's happening on June 26th.
Nice. On the 27th, ISSA Denver is doing their June special interest group for healthcare. We're almost done. 2 more. Uh, on the 29th, SecureSet has an expert series with Brian Becker.
Brian is the VP of security over at Cronky Sports and Entertainment. And I believe that was actually the 28th, but on the 29th, SecureSet is doing a capture the flag. They are. And, and of course their capture the flags are great. You can come early, come at 5 o'clock if you've never done one of these before, and they'll, they'll show you how to do it.
So when the whole thing kicks off at 6 o'clock, you're able to participate and not feel all left out. Sweet. We made it. We did. Yeah, there is a pretty good gap after that, but no one wants to have an event the week of the 4th of July.
So we're gonna have it. We're gonna have a little bit of a gap going forward there. All right, so that is it for the news this week. We do, of course, have a wonderful feature guest this week. I sat down with Benjamin Edelen, who is the CISO over at the City of Boulder.
Yeah, pretty cool. What did you guys talk about? We talked all about how he got to be the CISO for one of Colorado's hippiest cities. I don't think he said that, but I might have said that. And really what he's focusing on right now.
Nice. Good stuff. Interested to hear it. There's a lot of interesting stuff talking about the government sharing programs. You know, there are quite a few initiatives for government to share threat intelligence data.
And he has a lot of services that he gets to use as a result of that, that those of us in the commercial sector don't get. Well, don't give away the whole interview. Let's get to it. All right. Well, everyone have a good week and we'll talk to you in a week.
Thanks, Robb. Hi, this is Chris Martinez. CISO at DigitalGlobe. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
All right, this is Robb Reck with Colorado Equals Security, and I am today sitting with Benjamin Edelen, who is the CISO for the City of Boulder. Benjamin, I understand during most of your day you're working hard at securing the municipality up there. But when you have your free time, you like to get out on the trails. What is— what's your favorite hike, favorite trail in the Boulder area? By far my favorite trail in the Boulder area is the Sanitas Mountain Trail.
So up behind Boulder there is a Sanitas facility, which I believe used to be a mental institution. That's why it's called Sanitas. And behind it is a whole network of trails, and there's a valley trail and a mountain trail. The mountain trail is about maybe 45 minutes up and 45 minutes back, which is a perfect workout for me. And I'll typically throw a backpack on.
Sometimes I'll throw like a weight plate in the backpack just to get some extra fitness. And it's pretty rocky and yeah, goes straight up the mountain. It's a pretty fun trail. Is it, is it usually pretty crowded, pretty, pretty empty? What do you think?
Well, it depends when you go. On the weekends it is pretty rough. There's a lot of college students and things like that. Yeah. If you can go during the day, during the week, it's almost never a lot of people.
But because it's Boulder, you always have these weird experiences where professional athletes will be on the trail. So there'll be like someone with a baby on their back and like sandals, and they'll just cruise by you at some insane speed. And you know, just when you think that you're, you're getting fit, you can experience what it's like to have real Olympians and things like that on the trail with you. That's kind of the Boulder experience when you're on the trails, but I wouldn't say that it's crowded by any stretch of the imagination except, you know, on the weekends when all the college kids are up there. Yeah, so I want to hear about security and what you do for Boulder, but I want to take our time getting there, right?
So start off, you told me that you're originally from Montana, so talk to me about where in Montana, where did you grow up and what was it like? I grew up in Helena, which is the capital city I grew up with a father who is a pretty amazing outdoorsman, fly fisherman, kind of like if you've ever seen the film A River Runs Through It. A River Runs Through It. Brad Pitt or Robert Redford? Well, a little of both.
Yeah, Livingston, Montana, where that was filmed, is right next to where I went to college in Bozeman, Montana, and that whole area has a tremendous amount of fly fishing opportunities for people who are interested in that. And my father moved up there, I think, in part for that kind of experience, and he's very, very good at it. So we did a lot of floating, a lot of camping, a lot of hiking when I was growing up. And then I moved about an hour and 15 minutes down the road to Bozeman to go to college. So I got a computer science degree from Montana State University.
Yeah. So what, what got you interested in going into computer science in the first place? I assume you didn't grow up as a little kid playing with it, or did you? I sort of did. My parents were public school teachers, and they had a computer in our home very, very early, at least by Montana standards.
So we had an Apple IIe and then an Apple IIGS, and I was always engaged with those devices. I was figuring out how to duplicate floppies, how to get games, how to mail order fun things. Pretty quickly I was into programming. I was into BASIC. Yeah, and I took, I think, 3 years of computer science.
Somehow Helena High had an amazing program for me. They had a discrete math program that was sort of a sidetrack from like a calculus-based high school program taught by a wonderful woman who, who passed away almost immediately after I got done with high school. And that program prepared me incredibly well for discrete math at Montana State for computational theory. And then I was already programming. I was making games.
I was riffing off of Julia sets. I was doing all kinds of fun computer science. So did you ever buy a magazine and copy the code out of the magazine to write it? To write a program? That was one of the original ways to get games, right?
You could get games and then you felt a real sense of accomplishment when When you bothered to do it and you knew that you did it character for character because it wasn't going to work if you screwed anything up. It sure as heck didn't work with that one character mistake, right? You spend— yeah, I did that quite a bit back there in the '80s. Yeah, and I was never any good at development. So I— even now they talk about get computer science into schools and that means programming, but I was always really interested in building systems that were pretty reliable.
So I liked Linux. The Linux and system administration course at Montana State totally changed my life. And I went back to my dorm room and I uninstalled XP or whatever I had, and I put Red Hat 3.1 or something on my computer and immediately messed it up, lost my hard drive, lost all my stuff, figured out where I went wrong, you know, and I had been— I was a Linux user ever after. Essentially. So being a computer science major who was not good at development, that must have been kind of rough.
Well, that's an exaggeration. I mean, I, I definitely could do my homework and things like that. I wasn't really passionate about user interfaces, about a lot of the details that went into those things. But I wrote an operating system, you know, I, I wrote a compiler. I did all of the jobs that were required of me in the computer science program, but I wasn't I was worried that that was what I was gonna be stuck doing in my career because it just didn't feel like what I wanted to do with my time.
And, and I was really excited to find out that there were network planners and system administrators out there that I could work with. Yeah, and get my hands into something a little bit different than development. So what did you do when you graduated? Well, my wife is a medical technologist, so she works in a hospital medical laboratory. And she went to a really nice medical technology school here in Denver at Presbyterian/St.
Luke's. Okay. So she was down here finishing up her school at the same time that I was graduating. She wasn't my wife at the time, but we were together. And when it came time to figure out where to move, we thought that Denver was a really nice opportunity.
It's kind of like Montana with jobs down here. There's more people, but there's a lot of opportunities. Montana with jobs and people. A little bit like Montana. And traffic.
You don't have traffic in Montana, I'm guessing? Well, you know, everyone drives because everything is so far away in Montana, so there can be some traffic up there. But yeah, there's a lot more traffic down here than there is in Montana, obviously. But it was a great opportunity. We could still be in the mountains, we could still see the mountains, we could live in this sort of country-western lifestyle that we kind of enjoy, and yet, you know, you could actually establish a career down here that was really gonna work.
So did you move here without a job then? I did move here without a job, and in fact, I was one of the very last people— I graduated in 2002, right when everything was falling apart. So the whole time I was going to school, I was— it was strongly reinforced about how easy I would— it would be to get a job. I was just gonna stroll right in. They were paying people a ton of money.
The whole time I was going to college, there was this story about how well things were going, and it completely fell apart right as I graduated. I was one of the very last people that Microsoft flew out. I had this beautiful resume, and they had seen my resume, they liked it. It was— it wasn't even good. It was just nicely written.
Yeah, they flew me out there, and I was like, I'm just pulling the tail end of this thing. It's— I'm gonna make it work. Yeah, it didn't work. And when I got here, I was working for basically small companies. Not bad companies at all, but really underfunded organizations doing backroom system administration.
And that stuff was wonderful. I was working for companies where the server room was everybody's old desktops, and then we'd reinstall them with a fresh OS and get them set up as a server. And I learned to solve a ton of problems for no money. Maybe even making money, you know, hosting other people's things on computers that they were just gonna throw away anyway. And I spent time soldering together power supplies and doing whatever it took to keep the lights on in these sort of facilities.
And again, with the Linux background, that prepared me really well when there was a government opportunity. So that's how I got the job at the City of Boulder. I was doing martial arts with someone who, who had an opportunity for a Linux administrator at the city, and And I managed to get myself slotted into that job with those skills. Is it because you were the better martial artist or because you let him or her beat you? It was a combination.
Combination of them. Yeah, I try to— I tried to hit all the boxes. Tried to win and lose. I never intimidated anyone into hiring me. That's not an effective practice, as far as I know.
Yeah, I, I was really excited because the shops that I was working in didn't have a Linux working group, and so I was using Linux to solve individual problems. But it was really great for me as a kind of a new system administrator to be able to walk in with a ton of Linux skills and really help an organization out. Yeah, so when did you start working for Boulder? What year was that? 2006 I started working for Boulder.
So you had a few years where you were kicking around between a few different other companies, it sounds like? Yeah, exactly. Okay, and then you went over there in 2006 as a Linux administrator. Yep. What is it— you know, hardly anyone listening, maybe no one listening, has ever worked for Boulder in IT.
What does the IT organization there for the city look like? It's changed a lot over the years, but right now the IT department at the City of Boulder has 40-odd employees split, I think, relatively evenly between an infrastructure and applications side of the house. And then I am the only security-titled employee there. So I put everybody to work. They're doing double duty to try to secure the environment as well as to do their— Back up to 2006 though, I assume there's got to be a lot less IT resources back then, right?
Or overall IT department? There were. It was a more constrained time, but we had essentially a pair of Linux administrators and a pair of Windows administrators. Maybe we had 3 Windows administrators at the time. Yeah, and so we split vacations and everybody was on call half the time, and the Linux environment provided mostly core services, things like DNS and a lot of network scanning services and a lot of things like that.
And the other thing was we've always had directors there who were really serious about security, especially with outward-facing websites. So we were using the LAMP stack to present our websites, and we felt like we could secure that better than an IIS-based platform at the time. So that was something that I've always done at the city, was to secure those main websites. And we definitely had some interesting incidents. We had a Kosovarian web page one morning.
We had some interesting stuff. What's a Kosovarian web page? The web page had been defaced with with from a— by a group from Kosovo. This was a long time ago. What did they do?
What did they say? They just defaced it. They— you can't really— they couldn't take over the server, but they were able to upload something that replaced a, like, part of an iframe. And so not much of anything. It had just a little, like, we were here kind of comment in there.
Yeah, everybody was very upset about that. They carved their initials in your website. Exactly. Got it. Exactly.
Um, so How long were you— you came in in 2006 as the Linux admin. Walk me forward from there. How long were you doing that job? I was actually— I did that job for 10 years. And at some point, I was also doing network planning.
I was doing, you know, in-building cabling and helping out with the network infrastructure. And those were the 2 main tasks that I had always done there, and I was baking security into those. Those things sort of as rapidly as I could. And this IT department has a security team. We have a lot of security tasks that it can be hard to figure out who the right person to assign those tasks to.
So for example, PCI compliance auditing, those kinds of things. And so a few years back, I wound up asking to do the PCI compliance auditing because I thought it would be interesting. It was actually pretty horrifying. But I learned a ton about security leadership from that, and that kind of drove me into a CISSP and security leadership role when the organization decided that was something important. So you mentioned before we started recording, before we get into your security role, before we started recording, you talked about during the floods when you got a phone call from someone who needed some help with their website.
Can you kind of back up and You know, talk— go back to the Boulder floods and what happened. So that was actually a really big moment for me because I was always concerned. I mentioned that I wasn't necessarily a great programmer. I also was always concerned that I wouldn't really be able to use my skills to help people. I was always good at hardening technology and business processes, but I really wanted to help people out.
So during the floods, Boulder was hit really hard by the floods. 2014, right? 2013 floods. 2013, excuse me. So I was the Linux administrator, and on our LAMP stack set of sites was the Boulder Office of Emergency Management's website.
And that website is really important to our community. It's where they post routes that people can get home safely, or fire status updates, flood status updates, those sorts of things. So I assume mostly that website does absolutely nothing and just sits there dormant? And then, and then you need it and it's incredibly important. Exactly right.
Exactly. And it's not hosted by us anymore. Those guys are pros. But at the time we were hosting it. And so when another organization near us who runs their own office of emergency management— different city— basically, yeah, when another city had a problem with their site, they started calling around to figure out who was running the Boulder OEM site to see if they could get some help with it.
So I wound up on the phone with these folks, and they let me know that they had a hosted solution. The hosted solution had shut them down because of the traffic volume. People were loading it by the probably hundreds of thousands. Because most of the time they had very low traffic. Exactly.
All of a sudden, the host— their hosting provider was getting overwhelmed and hadn't allocated resources for this peak demand, it sounds like. Yeah. Exactly. So they were wondering if there was some way that we could host the site for them on a temporary basis because our site was staying up. And when I got into the backend, it was a Webmin backend, they had locked it down such that we couldn't get their web content back out of it.
And so we actually went to Metasploit and found like a Webmin exploit. And, you know, it was with their permission. We had their passwords and everything, and we, we managed to get into their, their interface and pull their web content, their MySQL databases out and host those. And that was a marathon effort that started about 8 PM with the rain coming down on my house, you know, just hammering away, hoping the power stayed on while I worked through that process for these guys. And we did get their site up, rebranded, and going again so people could get home safely.
So did they have an out-of-date, unpatched version of Webmin? Is that— was that why you were able to do this? I never really looked back at like, was it up to date or not? It was, it was just an emergency operation to take, to pull their content. I'm just gonna assume that they weren't patched, and so that the moral here is don't patch your systems, everybody, so, so you have a good DR strategy.
I can't countenance that advice, but I do— it was really neat to run websites that people counted on to get home safely, and I think that the time is coming when computer scientists are going to have more opportunity to protect human safety. The people who are counting on our solutions and things like that will be counting on them with their lives instead of just with their money. And, you know, we have every once in a while some talking head will, will talk about like a cyber 9/11 or something like that. I think those times are probably coming with vehicles having so much technology in them and things like that. I think our safety will be at risk, and I really like the idea of You know, it's amazing to protect businesses and to protect finance, but it's a really neat feeling to protect people's safety with your skills.
So let's fast forward a little bit. In 2016, I think you said it was 2016 where you turned into a full-time security guy? Yeah. What was the impetus for Boulder to say, hey, it's time for us to appoint a CISO and really dedicate a resource? Resource to do this?
You know what's interesting? I wasn't behind that decision. I wasn't for it or against it. In fact, I had always assumed that we had fallen below some kind of threshold where a dedicated security professional was possible. But my director at the time, Don Ingle, he decided that he thought it was time for our organization to have a dedicated security professional.
And of course, we kept saying on things like PCI audits and things like that, you know, what is— do you have someone who is dedicated to these things? And we did. I was dedicated. I was a dedicated resource for those kinds of roles. And so he brought that to the city council, and they decided that it was worth funding a dedicated security professional.
And then that job was opened up. Like I said, I wasn't actually involved in the creation of that job, but I had put a ton of resources into moving from being a technology professional to being in a security leadership role. So it was very fortuitous for me, and I was able to apply, and it was, it was a nationwide search, and I still was able to capture that role. Congratulations. Yeah, I appreciate it.
That's great. And that was 2 years ago, so I'm still a relatively fresh CISO. CISOs get created somehow, and I'm going through that process. But there's always a fake it till you make it process that we all go through. And people want more confidence in their CISO than that, but there's always some element.
Well, don't worry, no one knows that we're faking it. We'll keep that secret. So, and I think another thing that would be interesting for the folks listening to understand is what is, what is the breadth of services that Boulder offers? You know, obviously we know that the city, there's some kind of tax revenue, you know, you have You mentioned, you know, the, the emergency management stuff. There's probably law enforcement.
Talk me through like what all you guys are responsible for. Yeah, the, the city is really different than a business. We have— it changes from time to time, but we have around 18 departments, and those 18 departments are in— are all in completely different industries. We have people running rec centers, point of sale. We have people who are maintaining trails up in the mountains, park rangers, law enforcement, fire.
We have folks running— creating fresh water for us to drink. We have folks processing wastewater that we— that we're done with, and, and everything in between. Everything that you imagine that a city does, there's a department for that. There are people who are just setting up traffic signals. There are people who are just making sure that the roads don't have potholes in them, just scraping snow, out mowing.
Because all devices are now network-attached smart devices, those groups are all deploying technology at a very rapid pace. There is a real need for the folks who are deploying that technology to become experts at the kinds of things they're doing and in general. And that's why the job is so amazing. Doing security for the whole city means supporting a tremendous amount of different kinds of businesses, and each of those industries, each of those businesses has its own industry. Some of them even have their own ISAC, you know, and there's so much coordination around that.
And then obviously supporting IT is well. IT is a big operation. We support a tremendous amount of different projects at any given time. So you just, you know, you listed off whatever that was, 6 or 8 different departments or agencies that you work with. A group like the police department, law enforcement, I would assume that they have their own IT and probably security staff, or do they leverage the City of Boulder's IT and you, or how does that work?
It's both. So IT is in some ways distributed and in some ways centralized. The network is very centralized, for example. And a lot of purpose-built applications are run by staff within departments. And police is a great example.
Our police department has a records department, and every police and sheriff's department has a records department, and those people are real experts at managing police records. And there are rules that come down from the FBI on how criminal justice data has to be managed, for example. And so they— there's a lot of responsibility there for those folks. So IT is a shared task with law enforcement. And law enforcement uses our network, for example, very differently than other groups.
They may be doing investigative work using our network. They may be, they may be responding to things that have been, that our network has been used to do by, you know, I have to back off of this one, but, you know, I'll just say this and then I'll, we can talk about it later, but, you know, we might get a request from the Secret Service because someone at the public library has threatened the president or something like that. There's all kinds of different ways that the network is being used. The fire department is using it in a completely different way to do their dispatch, and the water folks are using it to control dam valves. Everybody's using it.
I guess what I wonder, though, is how much of all these different agencies' cybersecurity practices do they handle versus how much you handle? Is it a consortium? Consultative approach, or how do you, how do you look at them? I assume like the people who are maintaining your trails probably don't have a security staff, right? And it's, it's you or nothing, or versus whereas the police might actually have some kind of dedicated resources there.
So that kind of resource allocation is evolving, but here is my vision for that. I— it's very much a consultant-oriented approach. I produce a lot of materials. And I set some standards through policy that set a level of expectation for people who are administering technology and who are data owners, it sets a level of responsibility that roughly correlates with like the old 5 critical security controls. You know, keep inventories, figure out what kind of baseline configurations you are expected to have, modify those defaults, apply those baseline configurations to everything in the inventory.
Nuts and bolts security stuff. And I make videos, go around and talk to people, do trainings, send out emails with all kinds of different information, with the idea being to uplift the folks who have those responsibilities and then be able to trust them to manage their technology. So yes, it's very decentralized from that standpoint because every business unit at the City of Boulder is deploying technology very, very quickly. So there is no pipeline for central management of those technologies. That would significantly stall the kind of innovation that people are trying to do with their spaces.
And then I provide a ton of consulting work around— if you have questions, if you're— if you have concerns, if I have questions or concerns, I'll come and find you. I offer a really nice investigative service. If we need to respond to an incident, I need those incidents to be reported and tracked. And so we work through incident handling processes, and I will always produce high-quality materials that will continue to elevate people's understanding. But for example, you mentioned the, you know, maybe the trail crews.
The truth is that we're putting in technology even on the trails to support people, and I don't like the idea that I'm working with 1,400 people who are either already breached or about to be breached in this modern world that we live in. I don't want to leave anybody behind. I don't want to assume that some workgroups need cybersecurity knowledge and some don't. I want to bring everyone inside the security cordon. I never want to pull the cordon in so tight that I leave people outside.
I need them to trust me, to see me as a resource that can provide them not just consulting, but the ability to recover with grace from a serious cybersecurity issue, to set things up correctly. And I also need them to be able to have one set of behaviors that they can take home and use to protect their families too, because even if the trail crew is not deploying technology on the trail, they're coming home to a networked thermostat and networked light bulbs. And then if they're compromised and their 401 is depopulated, those folks are not going to be able to come to work and do the kind of job that they could do if their lives weren't falling apart. So I'm trying to protect people at home and at work with a single set of behaviors. I mean, I'm really passionate about the idea that we need to, we need to bring everybody into the security space.
People already know, they can tell you what, how many ounces of liquids are they allowed to bring on the plane when they go fly, but they couldn't tell you how to put Quad9 onto their home router, and protect their families with the basic nuts and bolts security tools that are free and available for everybody. I'm really committed to finding a way to transmit that information to all of my people so that their home lives are secure, and then they can take those exact same behaviors and just use them at work. Yeah, that's great. That's kind of my thing that I bring to the table with this conversation. You are a resource to a fairly large organization with a lot of different missions, and you're a one-man show.
What kind of resources do you have, you know, provided either from the state or federal or other cities or however else you go get other resources? What are the resources do you have to, to really be your source of help? I started developing resources long ago, so I became an InfraGard member a long time ago, and I still really like InfraGard. I think it's really cool. And through InfraGard, I met some FBI folks, some local FBI folks, and I've been engaged with them ever since.
I met Harley Reinertsen, who is kind of Oz, great and terrible. He sits behind a lot of successful cybersecurity in this region and creates a lot of opportunities for people, puts a lot of different people in touch with resources that they need to succeed. Through those associations, I wound up working with the MS-ISAC, and I believe if there's one thing that I recommend, if there are cybersecurity professionals out there who have not found an ISAC that's right for their organization and joined it, they— you're doing yourself a tremendous disservice from an intelligence standpoint because those ISACs are unbelievable resources, and most ISACs are severely underutilized. They often have a lot of resources that people don't claim, don't use. My experience is the Some of the ISACs are quite good.
Some of the ISACs are not so much. Yeah, and that may be true. I have not participated in more than a handful of the ISACs that exist, but my challenge would be then to join those ISACs and to make whatever difference that people wanna see in them come into reality, because the ISACs are also run by us on some level. Yeah, for sure. Maybe not the MS-ISAC, that's run on our behalf by the feds, but If you're in the water industry or the finance industry, those ISACs are fundamentally run by the industry.
There's real value in injecting yourself and starting to give presentations at their conferences and join their committees and make those changes that you want to see in your ISAC. I maybe am a frequent flyer with the ISAC. I try to use a lot of their services. I think if you join something like an ISAC, getting their service catalog and laminating that baby and having it in your office, and then just start using their services. Start asking for services that you want to exist that don't, and they'll take that feedback.
The feds— I've worked with the Department of Homeland Security on a variety of different things, and they provide some really nice stuff to state and local governments. I, I'm a big fan of finding those external resources and then sharing resources between organizations, so joining meeting other CISOs, meeting other security professionals, meeting other IT professionals in your industry. So I meet up and work with a lot of people in the local government space and share resources. I try to share the policies that I've written, the incident handling guides that I've made, and try to create whatever results I can, you know, in a regional capacity rather than just for my own organization. Yeah, what kind of, you know, meetings of other municipal CISOs or government CISOs in the area.
Do you have any groups locally that you get involved with, with other folks like yourself? There's 2 groups. One of them is CGATE, the Colorado Government Association of IT, and CGATE is kind of the IT association for all the local governments in this area. CGATE meets quarterly, and I try to present at the main 2 CGATE meetings every year and just hold the space open for a big security conversation that's ongoing within that, within that group. And there's tons of people who participate at the same level as me in that conversation.
And then there is an organization called the Colorado Threat Information Sharing Group. And as far as I know, that is a government-only, like a local government and a state government-only organization that shares real-time threat intelligence. And that organization is really in its infancy, but a lot of really interesting work is being done there, a lot of pioneering work is being done there. And I, I've been a member of that group almost since the beginning, but I just wanted to mention the, the person who created that group, Jill Fraser, is a really amazing person. I always feel like Jill is succeeding in all the ways that I'm failing as the CISO.
So she, I think, really drove that group into existence based on a need that we had in this region. And I don't believe that other states have threat intelligence sharing systems like that that are coming into existence yet. So I think she's really led the way in that. And Jill, she is the CISO for Jefferson County, right? That's correct, yeah.
And I think Debbie Blythe's office has really helped in the creation of that as well. Debbie's kind of a hero of mine. Yeah, Debbie's awesome. We had her on the show about a year ago. Hope all's going well, Debbie.
Well, very cool. What is the biggest challenge from a security perspective that that you see looking ahead of you in 2018, 2019? I will reiterate what I said before. I think the biggest challenge that we face in the industry is that we don't find out about things because we don't treat people very well. I think that the security industry— again, every year some security talking head declares this the year of the insider threat.
We package up security as something that people should already know, but we didn't teach them. And then when they make mistakes, they are ashamed of those mistakes and they don't get reported. And when they do get reported, the people who have reported them are willing to look bad. They're willing to call up the service desk and say, I made a mistake. And then they're often not treated particularly well, even though they're really living the values of our organization.
Organizations when they're willing to report a mistake or willing to volunteer something like that. I think the biggest challenge is to find a way to support people. I like supporting technology. I like buying tools and implementing tools that create a broad change in the security landscape of our organizations, but what I'm really interested in is how do we make people's lives better? How do we teach them to protect themselves at home?
How do we give them an experience where they can recover gracefully so that they will come back again and again and again and partner with us as security professionals so that they will be maybe even excited to call us or see us as a trusted and valued resource rather than as like the Politburo of our organizations. I'm really passionate about how do we bring that into existence because I really think right now the landscape is oriented around deploying cybersecurity tools that take away the human element and sort of create a programmatic sense of security, and we pull that cordon inside and leave every— all the humans on the outside of it. I think, you know, this is driven primarily based on some perverse incentives we have in the industry, namely that, you know, we have these very well-compensated salespeople for security tool vendors, right, who will call you and talk about how this tool is going to solve your problem. And, you know, they sell you the tool, they go home and buy their new car, and you're left with yet another tool in your tool belt, right? And there's nobody who's incentivized to have an email right above that saying, don't buy a tool, go focus on helping your people be more effective, right?
That's the discipline it takes from leaders like yourself to really educate and enhance the non-tool side of things. Even the tool— even the non-tools, the training, you know, automate your relationships with your end users. Well, what value are you presenting in an automated relationship? Oh, you could check the box off. You don't even have to write the articles.
You don't even have to write the training. We'll write it for you. We'll deploy it out. You don't lift a finger. There's no communication, collaboration, in that.
And so there is no relationship that gets built by just copying and pasting newsletters out to your staff. I think people need to get in the car. I think they need to start, you know, make videos, go do road shows within their organizations, and start to build a presence and almost act like a security champion for your space and build yourself into a trusted resource. Not sort of distant, and I hope he stays distant because you're only in trouble when he shows up kind of presence within your organization. I think it's really important, and I think people will start being more interested.
They'll gamify their interactions with you. For example, I had one of our training professionals made a really great quiz, a phishing quiz, and I had all kinds of people. 70-year-olds at our employee health fair taking selfies of themselves with their scores on this quiz because— and self-identifying as being good at this because they were trained and they knew how to identify phishing. It's not perfect, but the idea is that people are excited to participate in it when they feel like they have a relationship and there's some human component to it instead of dreading the security training that's coming up or trying to hit next through the training and then guess the quiz answers and get by it so they can go on with their day. I'm going to ask you a related but different question.
What is the biggest threat or threat actor— probably threat's a better word— to Boulder from a security perspective? That's an interesting question. I'm a risk manager, so I like to think about what is gonna cost a lot of money and what's likely to happen. So my perception is, and again, I'm a defensive security professional, so my perception is that we will continue to see monetizable attacks, and we will see monetizable attacks that take on a more social domain. So we'll see people trying to spoof GDPR compliance professionals and extort money from organizations that way.
We'll continue to see the tried and true tricks where people get— find out about a big construction contract and try to change the payment information for that construction contract to their own, you know, Hong Kong address. We'll continue to see people attempting to use phishing. I think phishing is still the sort of delivery point of choice for a lot of these things to try to get people to take actions that are not in the best interest of their organizations. But we're going to see more ugly ugliness. We're going to see some types of attack that will drive us apart as human beings.
We're going to see cryptoware that will allow you to decrypt your files if you are willing to infect 2 or 3 other organizations, for example. We'll see those kinds of attacks will will make it hard to report, make it hard to be truthful about how you operated, and place you into a space where you might have to pay forever if you've made a big enough mistake, and they can blackmail you, those kinds of things. That's, that's what I'm really concerned about, is the proliferation of these tools, and they're getting so much better at finding ways to get their hooks in and monetize the attacks. Yeah, that's interesting. It's an industry.
You know, we're not competing against like soccer hooligans. We're competing against a business that makes money by exploiting our infrastructure, and that business is well-funded, probably better funded than we are. It may be money. It may— there's other interests out there as well, right? There are political interests.
I pretend that I don't know anything about that. It's none of your business. It's always a guess in my experience, and I choose not to to guess that I understand the political landscape. But of course, they're, you know, all— with Stuxnet, for example, we've seen how infrastructure can be damaged and damaged in very subtle ways. And so I wouldn't be surprised if in the future drill bits all over the world start wearing out 15% faster than they should and seeing significant subtle economic damage coming from things that will never be attributable, maybe never even be discovered.
Just slowdowns of network infrastructure, just hardware damage, vehicle damage. I think those kinds of things will proliferate because the attacks that are big and loud and where they leave the tools behind, you know, that's a one and done and it just doesn't, it seems to have created some political turmoil in the short term, but I think what's really gonna do damage in the long term is potentially a cyber warfare type scenario. Yeah, and that can be seen positively. You know, cyber warfare is a— is the first ever theater of war where we didn't have to send our children. So as much as people fear cyber war, it's— it is a theater of war where— and I've said already in this interview that, that attacks will begin to take lives, and I really believe that.
So I think there'll be a life safety component to cyber attacks. But at least for now, it is a— it is a place where governments can duke it out And there's a lot of economic damage, but there isn't a lot of human carnage yet. And I think that's probably superior as a vehicle for warfare, if you got to do warfare, to some of the other options, if you have to do it, right? So I just thinking, you know, one of the reasons it matters to me what the motivation of the attackers is, is it, it tells you what they might attack, right? And, and the things that we might think we would be safe from from an economic target going after.
If you have a different motivation, you know, the folks from Kosovo who are just carving their initials in your website, that's a different motivation. What are the different motivations? They kind of play to what kind of controls I need to think about. I think at this point you could say that there's so many different motivations that we're not going to finish this. I can't even guess.
And you can download, you know, the Verizon report and see what kind of attackers there are, and you can get a sense of what kind of attacks you'll experience. Certainly, if you're managing critical infrastructure, you have to assume that that critical infrastructure might be a target, right? And I believe that essentially, especially internal, or I should say central US cities, are soft. We've never experienced warfare. We've never prepared for warfare.
And so if what we're going to experience experience is any kind of warfare, there's probably an uplift that needs to happen for us to be able to protect our infrastructure from a state actor, for example. We probably are going to have to do a lot of preparation work in order to be safe, because when was the last war that threatened an internal US city? It just doesn't really— it's not something that's at the top of people's minds. But if you're a cybersecurity professional, you probably have to think about these things ahead of time. You got to build the ark before the flood.
So Well, let me ask you, I'm going to change topics. We're getting short on time. Let me ask you, what would your guidance be for those listening who are trying to get into security right now? They've had a different career or they're coming right out of school and they're really interested in becoming the next CISO for Boulder. What do they need to do to start their route, job one, year one?
There are 2 things that I think— first, I'd like to draw a distinction between like a technical security track and a leadership security track. So if you were interested in penetration testing and those kinds of things, Mr. Robot, I am not a subject matter expert at that stuff. And I, I— there are a lot of conferences, there are a lot of classes. SANS offers amazing classes.
That track doesn't necessarily lead to security leadership in my experience. You've talked a little bit about this before, and I like the idea that great security leadership doesn't always come from a security background. I think it's really important to acknowledge that. So first and foremost, if you want to be a CISO, and I'm far from an expert 'cause I only did this once, but if you wanna become a CISO, you need to develop a leadership philosophy. And I remember when I was preparing to interview at the city, listening to, it was one of the podcasts that I think it was Security for Business Leaders.
That's a really good podcast. There's 2 podcasts that I listen to all the way through, the EC Council's podcast and the Security for Business Leaders podcast. One of the gentlemen on that podcast was the CISO of the state of Michigan at the time, or maybe the former CISO, and I looked really hard to try to find his name so I could attribute this to him, but he straight up— they said, what's your approach to leadership? And he said, well, I have a service-based leadership philosophy. I work for the people in my organization, all of them, like the help desk staff.
I work for them. I work for all the people in my space to create these kind of results. And that, I remember that resonating strongly with me. And I think you don't have to have a service-based leadership philosophy, but you have to have a leadership philosophy. If you do not know and believe in some component of your own leadership skills, You cannot create results at the level of a group.
So that's very important if you want to become a cybersecurity leader, and cybersecurity is in need of leadership just as much as it's in need of technical skills. And second of all, I mentioned podcasts. There's a lot of educational material out there. The podcasts are unbelievable, especially for job interviews. They're going to ask you to answer questions like a CISO.
You can listen to hundreds of hours of some of the best CISOs in the world answering questions that are remarkably similar to job interview questions. By tracking down the podcasts that work for you and listening to that. So obviously Colorado Equal Security is extraordinary. We have our own local podcast where you guys talk about upcoming jobs, where you interview the kinds of people that you want to be like if you want to become a cybersecurity professional. I'm also a big believer in training.
I really liked the CISSP. I think some people deride the CISSP on some level. I'm not the biggest fan of the change to their domains. I liked their original 10 domains. Now they're down to 8, and leadership isn't one of them for some reason.
So whatever. I love the CISSP, and when I took it, I wasn't— I didn't know that I was going to become a cybersecurity professional. And I realized while I was studying for the test that the point of the test is to see if you're like me. I was the right guy for whatever the CISSP is supposed to turn you into, and it totally changed me. From being a technology-focused professional to being a people-focused professional.
The CISSP is people, process, and then technology. That really worked for me. It may not be right for a lot of other people. The GSLC is SANS' version of the CISSP. That's a really cool certification too.
Those kinds of certifications will transform you from, if you want to be transformed, and if you let them do their work on you, from someone who is interested in working with technology to someone who really wants to work with people. So all that is great, but if you just graduated from college, you can't get your CISSP, you're not gonna get the interview to use those good questions, and no one wants to hear your philosophy, right? So how do they get from they just graduated to getting that opportunity?
I had a rough road after I graduated from college, but the industry needs people who will, without being told, without having to be rode, who will just bake security into the things that they create. So when you wind up with a job, you're going to be asked to set something up, to do something in a certain way, and if you take the extra time to bake security into it, you're building a— I understand where if you're talking about security professionals, you've just graduated from Regis, you have a degree, and you're doing penetration testing, that's different. I'm coming from the standpoint of myself. I was a system administrator and a network planner, and so baking security into the things that you do turns you into a security professional. If you're already a security professional and you want to make the jump, then you have to ask yourself, what am I doing for people to solve the problems that people have?
In every situation, and if there are extra things you can do, like taking your documentation and making it something people can use. For example, if your organization has security policies that are being circulated that are a scanned image, people can't search through them, but that's the signed version, go get the original Word document, snip the signature out, and refactor it, and take it to your system administrator and start circulating a searchable version of your policies. You know, make a difference at whatever level you're at within your organization for people, not for technology, not for business processes, but so that people can use the tools so that the people around you are better. I think we've all experienced as technology professionals that weird aura that you get where things just work when you're around and they don't work when you're not around. You have to develop the aura where things are more secure when you're around.
You have to do the security version of that, and that involves a really continuous effort to make the space around you a little safer wherever you go. Safer for human beings, not safer for— of course you also have to make it safer for technology. You have to protect systems. You can't leave the firewall wide open, and— but boy, everybody's really confident about their cyber skills. But yeah, but the having the ability to talk to people Another great opportunity is to just start speaking publicly.
I really believe that people don't understand the cybersecurity leadership roles are public speaking roles often. If you don't have any public speaking skills, if you are not able to address a group, if you are not able to create documentation that can be read by people, if you're not willing to be filmed, you'll have a ton of trouble getting your message out to people. If you have something worth saying, you'll, you'll need to develop the skills to share that message as widely as possible, as clearly as possible. Think about developing technical writing skills. Think about developing speaking skills.
When you end up at a conference, sign up for a speaking role and just do it. Just try it out. Don't sit in the back. Sit in the front.
Take advantage of the opportunities that you have to address people and to build those kind of skills. Those skills are extremely marketable. They will build your career all by themselves, no matter what industry you're in. But no supervisor will be like— maybe I'm wrong, but in my industry, no supervisor will come to you and be like, I need you to present at the next conference, unless you're running the conference. Yeah, you have to say, hey, I volunteer.
Oh, I just thought I'd sit down for 20 minutes and write an abstract and send it into the conference for something that I'm kind of scared to talk about, but I have a neat idea about. You gotta opt in, get it out there. And then you will transform. A few of those will totally transform someone who is entry-level within their field into someone who can, who can make a much bigger difference. That's awesome.
Well, I think that's the end of my questions for you. Is there anything you want to leave the community with? Any final parting words?
No. All right, awesome. Well, thank you so much, Benjamin, for your time. This has been fantastic. We'll look forward to catching up with you and, and hearing how things evolve over the next year or so.
Yeah, thank you very much. All right, have a good one. All right. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.