All episodes

Cole Wist, Colorado State Representative

Apple Podcasts Spotify SoundCloud

In this episode:

Cole Wist, Colorado Representative for District 37, is our feature interview this week. News from: The Colorado Sun, Denver Post, Viaggi, University of Colorado, EKS&H, Plante Moran, Ping Identity, Webroot, ProtectWise, SecureSet, Security Pursuit and a lot more!

Blockchain is the new newspaper?

Can you believe it? Alex tracked down Cole Wist, the Colorado Representative who co-authored Colorado's new cybersecurity bill. Also, the Sun rises in Colorado, "Everywhere WiFi" in Denver, CU is going to find cyberbullies. EKS&H is merging with Plante Moran. Ping Identity is a Leader again. And news from Webroot, Protectwise, SecureSet and Security Pursuit. 

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11029 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Rob Rack and Alex Wood.

Was that a familiar tune for you, Alex? Do you know what that was? You know, I— it was, it was a bit familiar to me. I spent some time playing arcade games as a kid, so I'm pretty sure that was the theme song to Mike Tyson Punch-Out!! Mike Tyson's Punch-Out!!

So this is because we are now celebrating the 20th anniversary of Mike Tyson biting off Evander Holyfield's ear in, uh, it was 1997, 1998. Yeah, so obviously good stuff, good stuff. Yeah, we're reliving a little bit of my childhood right there with a Mike Tyson Punch-Out!! theme. Glass Joe.

Glass Glass Joe, got to love Glass Bull. And yeah, what was the King Hippo? King Hippo. Yes. Good stuff.

Beat the crap out of King Hippo. Yeah. Well, so, hey, this is the Colorado Equal Security Podcast. This is episode 73 for the week of June 25th. And we are— we're excited because it's almost the 4th of July.

It is. We're coming up on it real quick here. We've got some great news this week. But before we talk about that, we are going to talk about some announcements. We have a Slack channel in case you hadn't heard.

480 people. Alive and well. It— there's a lot, a lot of great conversation that goes on in there. Um, I read every single message, so, you know, it's good stuff. Even the DMs between people?

Yeah, all of them. I mean, no, I don't do that, Robb. What are you talking about? All the public messages, of course. Uh, we do have a mailing list, so if you want to get the show notes delivered into your inbox each week, go out to colorado-security.com and go to the bottom of the page and sign up to receive those.

We also have a newsletter. If you go to the website, colorado-security.com, you can sign up there and we will send you the show notes. And, you know, maybe sometime in the future we'll send you something else. But for right now, you'll just get the show notes every week. And then we do have a Patreon page.

This is where you can support the show, help pay for our overhead. We promise that any money we receive goes back directly into the show and can buy the brand new stickers and magnets and those things that we've purchased. Yeah. Robb, as you know, I am rocking the magnet on the side of my car. So if you see a Toyota Prius driving around town with a little Colorado Equal Security magnet on the side, that's Alex.

That's me. Give me a honk. And we do have a big shout out and a thank you to go to a new Patreon supporter, Stanton Meyer, who's the CISO over at CoBank, is a brand new supporter. And of course, Stanton, we do appreciate your support very much. Yeah, thanks.

And at the $10 level, you get a shout out on the show. So that's taken care of. You also get a t-shirt. So we'll get Stanton one of those t-shirts. Yeah, sounds good.

Let's go ahead and jump into the news. So some interesting news coming this week. As a starting point, Alex, there has been a lot of controversy lately. The Denver Post's owner was Alden Capital, is really kind of killing the newspaper. Yeah, slowly they've been letting people go or people have been quitting.

A lot of controversy around the actual newsroom there that they're not really committed to having enough people to have an active newsroom. I think it was they had 200 reporters in the newsroom, and they're now down to 65 or something like that. So they've cut 2/3 of the news staff over the last couple of years. And really interesting, in April they actually published a special section of the newspaper on a Sunday that was all about ripping Alden Capital. And specifically, here's a quote: Denver deserves a newspaper owner who supports the newsroom.

If Alden isn't willing to do good journalism here, it should sell the Post to To owners who will. That was written by employees who worked for Alden Capital. Ouch. So I think we buried the lead a little bit. The story that we're actually talking about here is about the Denver Sun, or the Colorado Sun, excuse me, which is a new, essentially startup newspaper that is being staffed by some former Denver Post reporters.

So it's a news website. There's not going to be any paper. And it is, is going to be launched— basically, they launched a Kickstarter where they were trying to to raise $75,000 to get this website off the ground. And they've already raised over $100,000. So it should be starting here very soon.

It is subscription-based. It's not going to be a free website. But it'll have a lot of the, of the reporters that came over from Denver Post, including Tamara Chuang, who is the tech reporter who we've worked with the most. Yeah, really like Tamara. She's done great stuff.

So glad to see that she landed someplace because we, I think last week or the week before talked about the fact that she had left the Post. Yeah. So there's also some more intrigue behind the scenes here that the The Colorado Sun is going to be running on Civil, which is a, a blockchain-based technology that's, that's being, uh, kind of bankrolled by the one of the founders of Ethereum. And it's going to be the, the way, the way that they make decisions about what press is appropriate to be shared and, you know, what's good journalism is going to be based on people who have purchased Civil— what do they call them— a CVL, a CVL token. A form of cryptocurrency so the owners of that token can say, yes, this is good journalism or no, it isn't.

Yeah. And I think it is a little more complex than that. I think that, you know, they do have a sort of, I guess I'll call it a constitution. You know, this is, this is what we aim to do and this is what we consider good news. And if you have one of those tokens, you can essentially decide whether it, it is meeting those requirements or not.

Yeah, that sounds exactly right. Really interesting. Obviously, this is still a little in the future, but They've, you know, they come up with a lot of technology behind it. They've got the money to do this. They have a really impressive staff of reporters to go kick off this new venture.

So it looks like it's going to happen. We're going to get to see the Colorado Sun rise here. I look forward to the sun rising. So next, we have an article about 5 ways Denver, downtown Denver, is working to stay competitive. Actually, a really interesting article about changes that have happened in the commercial landscape in downtown Denver over the past, I think it's 5 or 6 years.

So So if you're only going to click on one link in our show notes, if you're going to look at one article this week, I highly recommend that this is it. There's so much interesting stuff in here. We're going to try and summarize some of that stuff, but there's more in here, way more in here that we can go through. Yeah. And so one little nugget over the last 13 years, the amount of hotel rooms in downtown Denver has doubled from 5,100 to 10,300.

And that is only going to go up from here. Similarly, over the last 5 years, there's been 83 new projects with over $5 billion in investments downtown. And the projects have brought in over 100,000 new residential units, over 100,000 new units downtown Denver, over 4 million square feet of office space, and 3,200 new hotel rooms. Crazy. And from 2013 until now, only 54% of the current tenants downtown were already there.

So basically, half of the business tenants in downtown Denver are new in the past 5 years. The article also calls out a couple of familiar names. They say that WeWork is having a big impact on the real estate market, and Optiv and Apple are called out as a couple of the new biggest office builders or, or tenants downtown as well. That's really cool. I don't think I realized that Apple had space downtown.

Yeah, I don't— I didn't either. So anyway, like I said, take a look at that article. I think it's worth taking a look at. Next story, Viaggi expands their Everywhere Wi-Fi to Denver and other cities. So this is an interesting one.

Viaggi is basically going to offer you a data plan with massively fast connectivity speed, right? It was like 800 gigabit, megabit. What was it? I think it was 800 megabit. I think they were guaranteeing 800 megabit and they were saying over a gig speeds Wi-Fi.

And they're going to be in, I think it's like 25 different cities around the US. And you can get your plan to have this data anywhere you go, basically. Yeah. So it's essentially trying to do you know, like kind of like blanket Wi-Fi over the, over the city, um, using millimeter wave technology. Yeah.

Uh, basically it sort of reminds me of, like you said, it's sort of a cell phone plan, but it's over Wi-Fi. So, uh, you know, theoretically you, any device that supports Wi-Fi, you could have anywhere and, and have it connected. So my first thought is it makes a lot of sense for businesses that don't want to pay for, you know, having office connectivity for an individual. But the way they bundle this is actually, you know, not really business friendly. They, Their plans, they bundle in addition to the Wi-Fi, they give you other services.

So their basic, their most inexpensive plan is called their Everywhere plan. It's $80 a month and it includes a subscription to Spotify Music and to Hulu Limited. Well, you know, I know that need those things at work, Robb. Yeah, well, of course you do. Yeah.

Right. And they have 2 more expensive plans there. What do they call them? Their Everywhere Plus and their Everywhere Plus Plus. Somebody needs a bonus for their naming.

And with those, you get additional packages with Spotify Premium, Hulu Live, Amazon Prime, Netflix, and MoviePass, among other stuff as well. Wow, MoviePass, get to go see movies for free. Yeah, it's pretty cool. Uh, so yeah, uh, could be interesting. Um, essentially, uh, another competitor to the, the, uh, the wireless space.

Uh, so next, um, researchers at CU launched a cyberbullying detector program for social media. So this is research, and, and they basically showed and documented a program that would parse through posts on Instagram specifically and show what looked like cyberbullying tendencies, and they would alert administrators about those posts. Yeah, it's, it's interesting on the surface of it. Um, I, I think we all know that cyberbullying can be a problem, and if you could have some way to alert school officials to let them know that potentially this was happening, um, it would be something that would be worthwhile. I can see some technical problems.

The fact of understanding, you know, whose Instagram links to a person that actually goes to a particular school. Yeah. If they're cyberbullying outside of school, do we really want to have the school deal with that, or is that a parental problem? I don't know. There's— it's interesting, but I think it's sort of at the research stage still at this point.

And how many Alex Woods are they gonna be out there, right? Many. Yeah. So they do say that they have plans to move over to Facebook and Snapchat as well. This only works for public Instagram accounts.

Of course, if it's, if it's private it, they can't see the data. But in addition to having this administrator version, there's also a parental version of this. So instead of getting a couple of accounts or all of the kids' accounts, you get just your student— or excuse me, your child's accounts, and you can get access only to the alerts rather than having to look at all of their posts. It'll just bundle up for you what looks suspicious and send you the context around that. Yeah, and that is a pretty cool idea.

All right, next, EKS&H, which is a local Denver accounting firm, is merging with Plant Moran out of, uh, was it Milwaukee? Yeah, Milwaukee. Yep, you got it. So, uh, EKS&H is Denver's largest accounting firm. Uh, they do SOC 2 reports and financial accounting here, and Plant Moran is one of the largest in the Midwest.

Yeah, and I think they said they'll have, uh, 3,000, um, employees, or maybe 3,000 accountants once they, they combine the 2 companies. Yeah, 3,000 employees in 27 offices around the world. Uh, it looks like Plant Moran is the 15th largest accounting firm in the, in the nation. Uh, EK&S&H is, uh, 50— or excuse me, 41st. When you combine them together, they're going to be the 11th largest.

Good stuff. Um, they do note in here that, um, current customers of EK&S&H, uh, will not have their fees raised. So if you want to become an EK&S&H customer, now is the time to do it so that you get the current fees, not the, uh, I'm sure inflated fees in the future. They say that the headquarters won't be moving. Although they didn't say that forever, and that— but they do say that the name is gonna change to Plant Moran.

It's not gonna be EKS&H in Denver anymore. Yeah, I think they said it was a year or 6 months or something like that. They're brands— 2 brands for a while, and then they'll merge them together. Alex, what's the next really exciting piece of news? I don't know if it's super exciting, Robb.

It's, it's okay. Ping Identity was named a leader in Gartner's 2018 Magic Quadrant. And that's fantastic for access management. That's fantastic. Were they, were they number one, Robb?

Absolutely. Number one in your hearts. I love it. So, you know, this is Gartner's annual report that shows what's the state of things and, and gives you a nice update of what the other IAM companies have done in the last year. Ping remains up there in the upper right corner, and it's nice to see the local companies doing well.

And, you know, if you go to the link here, there is a way to get the report if you want to see it, as long as you're willing to hand over your contact information to Ping and get spammed. And I personally guarantee you, all you have to do is say unsubscribe and that's it. You don't have to— you don't get anything after that. Perfect. In this new GDPR world, we're all on top of these things.

Next, Webroot had an interesting article this week about parsing the distinction between AI and machine learning. And this is Dave DeFore who wrote this, and we've had Dave on the show before. I really like what he— how he did this. I'm not sure I agree with every word of what he says, but the general thrust is great. AI, as he defines it, is Basically something that can emulate a human or an animal, you know, some kind of sentient being's level of intelligence.

You're trying to take the place of a human in most cases. Whereas machine learning is— he calls it the nerdy cousin of AI. These models are designed, data collected, really just apply rules to data to come out with outputs, right? Versus having like the whole, the bigger picture of AI. It's Pretending to be a human versus looking for patterns.

It's kind of the way I think about it. Yeah, that seems reasonable. Uh, next article we have, uh, is actually written by James Condon. James is the head of the threat research group over at ProtectWise in town, and I really like this article. Another article that I highly recommend taking a look at if you're a hiring manager or a security leader.

It's the top 4 ways to find the next generation of cybersecurity talent. Yeah, so there were 4 items. Uh, first, recruit entry-level candidates, um, which I think both Robb and I agree with. Uh, once they're on board, have a plan for developing your new talent. Um, again, great idea.

You can't just have, uh, new folks in the door and not do anything to develop them. Uh, build an environment that attracts and keeps employees happy. I think everybody wants that. And mentor and retain those young employees. So there, there is a lot more detail in the article worth taking a look, but, uh, just highly recommend this is a great way for you to build security programs, number one, affordably, but also, you know, sustainably, right?

If we're just stealing security folks from each other across town, we're not really making anything better in the long run. Exactly. Uh, the next article was, uh, similar but actually from a different point of view. So, uh, that article was about the sort of the hiring manager's point of view, and this is essentially about the job seeker's point of view. So SecureSet had an article about how to stand apart in your InfoSec job search.

And they're really talking here about things that you could do when you're looking for a job to make yourself more marketable for different types of jobs. Yeah, they break it into 3 categories. They talk about security product companies. So if you want to get a job at a company like Webroot, LogRhythm, Ping Identity, Swimlane, what kind of skills are those companies looking for, which are quite different than the other categories? So they spend a few paragraphs talking about what you should do to get ready to go into one of those companies.

Then they talk about going into a security services company, you know, your Red Canary, your InteliSecure, Carbon Black examples that they, they talk about. You know, here they're looking for folks around operations and just different skill sets and how do you get ready for that. And then the final category is how do you get a job in an enterprise, right, doing security work for an enterprise that does something else but you're just securing internally. Yeah, all great points. And, you know, you get with those 2 articles, you get both sides of of the equation there.

Yeah, final story here, uh, is Security Pursuit. They have 5 online business banking best practices. So if you're thinking about how do you want to keep your company's money secure, here's 5 really good tips you can go through. So I'll go through them pretty quickly here. Dedicate a system to banking access.

Don't use the same system that you're using to do your fantasy football and, and, you know, down, you know, go to Instagram to do your banking on. I think it's a great tip. Access online banking through preset bookmarks. Interesting. Alex and I kind of debated this one a little bit ahead of time.

I guess really the idea is to make sure that people are not clicking links and they're not getting phished by— to go to the wrong site. They're always going to the same bookmark to go to, you know, wells Fargo dot com and avoid having that, you know, that URL that looks the same that you might click on. The third is keep systems updated and clean. Ensure patches are up to date. Obviously, kind of just general security hygiene.

Number 4, don't, don't open unexpected or suspicious email attachments. Another one that's just good security hygiene. And finally, require multiple sign-offs. So make sure you have more than one person required to do financial transactions. Yeah, having that dual authority is, is really, really important.

So, Alex, what are they missing? Yeah, so the one thing that I thought that should have been on there too, um, not to diminish the list, but was, uh, 2-factor authentication. You know, anywhere where you can have 2-factor authentication, it's going to make it that much more secure. So great list. I think, you know, make it— put a 6th thing on there, 2-factor auth.

Get kind of gets rid of that password reuse threat that is so common in the organization. And I can't remember if you said it at the beginning, but this was by Security Pursuit, Steve Fox over there. Yeah. And I think this is the first article, maybe the second article we've had from them. Yeah, we've talked with Mitch Tenenbaum, but I don't think we've talked at all with, with Security Pursuit on here.

So good stuff. Uh, finally, last thing to talk about is that the CISO of the Year voting is up right now. So CTA added this award last year. Matt Shufeldt was the 2017 CISO of the Year. We do not know who the 2018 CISO of the Year is going to be.

It's not too late to nominate your favorite one. Exactly. Go check that out. Nominate your friends, your boss. Your favorite podcast host.

Hey, you know, whatever. Whatever it might be. So, all right. That's it for the news. So, let's move over to the Slack message of the week.

Slack message of the week. Slack message of the week. So, congratulations to Dale Drew. Dale, who just joined Zayo as the CISO over there. Gave us a really interesting post that started one of my favorite conversations of the week in Slack, where he was asking about what open source security tools people like to use.

And it spurred, you know, spun out a 100 message back and forth with a lot of really good conversation around open source security tools. And if you were on Slack, you would have all that information about all of the cool open source security tools. So, so number one, thanks, or excuse me, congratulations to Dale. Number 2, Thanks a lot to Andre Gaeta, who is our sponsor for the Slack message of the week. Andre has been sponsoring this out of pocket because he wants to support the podcast.

We appreciate that very much. Drew will get to pick— Dale Drew will get to pick his favorite Colorado Equal Security merchandise and have that sent directly to his door. Awesome. So let's go jump over to jobs. First on the list, not surprisingly, there's a couple Ping Identity jobs.

Yeah, absolutely. We have Ping is looking to hire a site reliability engineer focused on security operations. If you want to help Ping manage our IDaaS, our identity as a service platform, and also help us move our security program forward, this job is for you. And there's a new one this week. We're looking to hire an IT director.

So you'd be in charge of our IT, our networking, telecommunications, procurements, and some other functions within Ping. It's a really good opportunity. And if you are interested or you know someone who'd be a good fit, send me a note. And I would be happy to, uh, to help get them with the hiring manager. Awesome.

Uh, next on the list, um, CPI Card Group is looking for an IT director for info/cybersecurity. So I looked into this one. It looks like it really is just a security-focused position. It's just, it says IT director because I think it reports up to IT, but it is just a security-focused position, 100%. Western Union has a couple of jobs.

They're hiring a senior dev SecOps engineer And they're hiring an information security manager for compliance. Charles Schwab is looking for a technical director for cyber threat risk management. That's a pretty good one. PDC Energy is hiring a senior information security engineer. VMware is looking for a DevOps/automation security engineer.

Twitter is hiring a security engineer. Google is looking for a security and compliance cloud consultant. So VMware, Twitter, and Google are all hiring security engineers here in Denver. Yes, they are. Amazing.

That is super, super cool. Yeah, we're getting some pretty awesome, uh, big tech companies hiring here in town. Uh, speaking of awesome companies to work for, Denver Health is hiring an IS Security Analyst 3. So if you're like an IS Security Analyst 2.5, 2.6, can you round up to a 3 or Well, you know, does that work? You know, I think at some point, you know, you might be a 2 and then you increase your skills, but, you know, your job title is still the same.

So at some point you got to move up to a 3. Yeah, I, I just, I wonder when the rounding happens. And yeah, it's a good question. Is it truncated? Is it?

Yeah. So if you know, you know, I think the rule of math is once you get over 2.5, you got to round up. I like it. I like it. Uh, and then finally, Internet2 is looking for a cyber infrastructure security engineer.

What is Internet 2, Alex? Um, you know, I, I believe it is the, the next generation internet. So it's like the, uh, the information super duper highway? Yes, exactly. It's the, uh, it's the Internet++.

So all of these jobs are in the show notes, so take a look if you, if you're interested in applying, and you can click directly into to apply to them. Uh, next, let's go ahead and go over to our events. As a reminder, if you go to colorado-security.com and click on our security events button, you can see a calendar of events with stuff coming all the way through the end of the year. First, uh, the NCC down in Colorado Springs is doing a Beyond Bitcoin cryptocurrency and blockchain for beginners on June 26th. SecureSet is doing one of their career conversations.

This one's all about how to make your resume shine. Uh, does that involve some sort of polish, or— I don't see how else you could do it. Uh, ISSA Denver is doing their June healthcare special interest group on the 27th. So I went to the airport a while back with some really scuffed shoes, and, and I, and I actually went to the shoeshine people there, and the guy, the guy says to me, hey, if you're not happy with this, come back later and I'll fix it for you. And I'm like, oh, that's really nice.

And then I got out, I'm like, what are the odds of me ever seeing this guy at the airport again? And I've never seen him at the airport again. So I think he got played. Yeah. So where are we right now?

Are we on Brian Becker? Is that where we are? Yes. So SecureSet has an expert series meeting with Brian Becker on June 28th. Brian is the VP of security over at Cronky Sports and Entertainment.

He's probably still hiring a director of security over there too. He probably is. On the 29th, SecureSet is doing a capture the flag. And finally, if you're interested in knowing more about this blockchain thing and you didn't make it to Colorado Springs, OWASP Boulder has you covered on the 5th of July, right after you just got done with your burgers and beers on the 4th. Go learn about digital identity and blockchain with Zach Wolf.

Zach is one of the most knowledgeable blockchain experts here in Colorado, and he'll get you learned up. Yeah. And, you know, I believe that OWASP Boulder does their meetings in the evening. So even if you're super hungover from 4th of July, you can just sleep all day and then go. You can make it over.

Good stuff. Well, that's the end of the news here. We all— we have left ahead of us is an unbelievably great interview that you got for us. So was it like 3 weeks ago we said that Colorado has passed a new cybersecurity bill? Is that right?

So tell me what you did. Yeah. So I thought, whoa, it would be really cool to talk to somebody that was involved in creating that bill. So I reached out to some contacts and ended up talking to Cole Wist, who is a state representative. For, I believe, District 37, which is sort of Greenwood Village, Centennial.

And Cole was, was one of the primary folks that was involved in creating that, the cybersecurity bill for Colorado. So we had a chat last week and it was extremely interesting talking about the bill, talking about, you know, his experiences in the legislature and lots of other good stuff like that. Yeah. So, I mean, heartbreaking, you know, really relevant news. I love it.

Yeah, this is exactly— you're almost like a journalist over there. Don't say that. Uh, well, we will do want to let you know we're not going to be doing a show next week. Alex and I are taking off a week to celebrate our our nation's birthday and and do whatever nation birthday things might one might do. America.

We'll see you guys in in Q3, and hopefully you guys have a good end of your June. Thanks, Robb. See you in a couple weeks. Hello, this is Rock Lambros, Information Security Manager at Mark West Energy Partners. This is Colorado Equal Security.

For Colorado security professionals, by Colorado security professionals.

This is Colorado Equals Security, and I am here with State Representative Cole Wist. Cole, how are you doing today? I'm great, Alex. How are you? Awesome.

Really appreciate you taking a couple minutes today to come talk with us. So for folks that don't know, you think, well, why am I interviewing a state representative? Colorado recently passed some sweeping cybersecurity regulations, which we will talk about, but before we do that, Cole, I'd love to learn more about you. So first, let's talk about your background. Where are you from?

First of all, Alex, I appreciate the opportunity to visit with you. I'm a small-town boy from western Colorado. I grew up in a very small town called Paonia, which is right over Clorid Pass from Glenwood Springs and Carbondale. And I— so basically Aspen, right? You basically grew up in Aspen?

Pretty far from Aspen. There were 5 coal mines when I was there growing up. My dad was the superintendent of one of the mines, and that was my summer job in college. And so I haven't, you know, gone too far from that. I actually worked for a lot of mining companies as an attorney.

I went to the University of Denver undergraduate. And then I went to the East Coast for law school. I guess I really wanted to experience what humidity was like, so I moved to Washington, D.C., and I went to Georgetown Law School and then practiced law for a couple of years in Utah and enjoyed some great Utah skiing and then moved back to Colorado in about 1991 where I practiced law here in Denver ever since then. Nice. So how long have you been a representative then?

So I've been a representative since January of 2016, so I just completed my third session, so I guess about a term and a half. Nice. And what made you decide that you wanted to run for the legislature? Some people might say it's temporary insanity, but, you know, I guess from the time I was young, I was pretty engaged politically. My grandmother was very involved in politics, and I sort of grew up working on campaigns, being involved in policy.

And I guess there's sort of the politics side of this job, which I love, which is meeting people and learning about issues. But then there's the policy side, which really does drive me, and that's about problem solving. And it really kind of relates to my career as a lawyer. You know, lawyers sometimes get a bad rap because people think that they're just paid to fight. But at the end of the day, what lawyers do is help people solve problems.

And sometimes that means as an attorney we do go litigate and fight with other folks in court, but most importantly my job in private practice has been helping people find common ground to solve problems. And that's really what I see my job in as a legislator. So work on a variety of issues. This year I sponsored 29 bills. I got 23 to the governor's desk with 22 signed and only 1 vetoed.

Toe. So pretty proud of that. That's really good. So the— do you think that it helps you being a lawyer and then being a legislator? Well, I think it helps in a couple of respects.

I think when you are passing legislation, you have to look at a problem from a variety of angles, the same as when you're representing a client. And as I've told my clients, I want to understand all the arguments on the other side, but before I'm able to kind of advocate for their position and represent their position. I sort of take the same approach when I'm passing or introducing legislation. We go through a stakeholder process where we'll bring in folks that might be affected by a piece of legislation or might have an interest in it, and that was no different here in the bill we're going to talk about today, House Bill 1128. This was an initiative that we worked on with the Attorney General's Office, so before a bill ever drops in the legislature, we're reaching out to folks that might be interested in it, might be affected by it, and most importantly, we're reaching out to folks like you who are experts in a subject matter to say, what do you think?

We have this idea, here's the direction we think we'd like to go as policymakers, how do you think we could make this bill better? And through that conversation, we'll sometimes do complete rewrites as we did with House Bill 1128. So it really is a problem-solving process, and sometimes you get to the time when you're, when you're going to introduce the bill and decide, well, maybe our idea wasn't as good as we thought it was, or you'll move into, you'll move in a completely different direction. So what's the thing that you were most surprised about after becoming a legislator? You know, I think the— what I'm most surprised about is, you know, how nonpartisan the place is.

And I think most people think about politics and they think about Washington and they think about how broken it is and how we can't get things accomplished. And fortunately for us in Colorado, we only have 120 days to get our work done. So the The one thing that we absolutely have to do is pass the budget. But because our time period is so short, we're either going to get along, try to work together, which doesn't mean we don't have disagreements because we do. But I think the legislature really is a place where people are looking for common ground, looking for partners, and trying to solve problems.

So I think that's been the biggest surprise for me. Nice. That's really good to hear. I think you don't hear as much about that as you do about larger political problems at the national level. Right.

So this bill is all about cybersecurity. What was it that made you think, okay, we really need to have a cybersecurity bill this session? Well, I mean, sometimes legislators have personal stories that relate to a subject matter, and I have one of those. I myself was a victim of identity theft. This was about 3 or 4 years ago, and we learned that we were victims of identity theft in a letter from the Internal Revenue Service.

It was, Dear Mr. Wist, we think someone's using your Social Security number and your wife's Social Security number. We have these 2 tax returns that we don't think are yours. Are they So fortunately, we caught it before someone was able to actually steal our identity and take money, but to this day, we still have to have special numbers to file our tax returns with the IRS. So my big takeaway from that experience was, first of all, we're all at risk, and if your information is stolen through a database breach, you're much more at risk for identity theft to happen to you. Now, I'm not so naive to think that we can stop hackers from stealing information, but what we can do is try to stay a little bit ahead of them and help all Colorado consumers try to be in a position to protect themselves.

So it was really that personal story that attracted me to this issue.

Pragmatic person in terms of government not having the solutions to all problems, and I don't necessarily think that government programs solve all problems. And so really what this bill is designed to do is to give custodians of sensitive personal information the freedom to design policies that work for them and also to, you know, find ways to give us a real reasonable time period to give consumers notice. And we arrived at 30 days as the magic time period, and I can give you some background behind that. But that does put Colorado at the more aggressive end in terms of what other states have looked at for this notice period. But the bill sort of addresses what I thought, based on my takeaway, were the 3 key things.

First of all, how long does a company need your information? Number 2, what kinds policies should companies have to maintain that information? And number 3, how quickly should they give affected consumers notice if there's been a breach? And those are the 3 main components of the bill. Yeah, yeah, those are great pieces for sure.

So you mentioned the process before, generally about how you go about creating a bill, you know, getting information first, talking to people. What was the process that you guys followed for this one in particular? Well, we, as I said at the start, we worked real closely with the Attorney General's Office at the outset, and where there are instances of consumer fraud, the Attorney General's Office is tasked with investigating, partnering with district attorney's offices. So we, we really looked at it as a law enforcement component. What can we do to empower law enforcement to catch the bad guys, and what can we do to protect consumers, and what can we do to help those companies that are maintaining this information to be effective.

So we first started talking about the notice period, and we want— the original draft of the bill had a 7-day notice to the Attorney General's office and 45-day notice to affected consumers. There was some concern about this two-track process, and so we said, well, let's let's agree on a notice period for both the Attorney General's Office and consumers, and we arrived at 30 days. You know, then we also looked at what existing laws are out there. Some, for example, if you're a company that has to be in compliance with HIPAA, your current obligation is a 60-day notice, and you have extensive requirements on you as a custodian of that kind of type of sensitive information in terms of how you keep it. So we were trying to eliminate redundancy in terms of what companies are currently having to comply with in terms of federal requirements.

And we— the last thing I want to do is create something that's going to be expensive for business, something that's not going to have a meaningful impact, and something that's not going to accomplish the objective. So we introduced the original draft. We got a lot of feedback on that. We then did what's called essentially a strike below, where we kind of rewrite the bill. And sometimes after you introduce it, you're going to get some more feedback based on the stakeholders providing input to you.

And most of what the final bill that you see in front of you was what was introduced to the State Affairs Committee. When we had our first committee hearing. Really proud of the fact that this bill got through the entire legislative process with not one no vote, and that's pretty rare. That is, that's pretty cool. I think it does go to show how important people feel cybersecurity is these days.

Right. Do you guys get involved at all with any of our senators and congressmen, US senators and congressmen for things like that? Because I know that, you know, some of our folks are very involved in like the National Cybersecurity Caucus as part of the US House of Representatives, things like that. Is that an area that you guys get input from as well? Not specifically for this bill, but I can tell you that I've had conversations with our own congressmen Mike Coffman about that and Senator Gardner.

Governor Hickenlooper has been a big leader in terms of cybersecurity effort and started the Cybersecurity Center here in Colorado. So I'm very proud of the fact that our state has been, it's been playing a significant leadership role on this issue, and I hope we'll stay there. I think one of the important messages that we were also trying to and with this bill is we don't want to just be like every other state. We want to be cutting edge. We want to be aggressive in terms of how we're taking care of these really important issues.

And, you know, these are threats, and these are things that consumers are concerned about. Yeah, and, you know, you mentioned the 30-day notification before. Some of the other provisions are Having a reasonable cybersecurity program in place. You mentioned that essentially the document management, the data management component, only taking data for as long as you need to have it. One of the other things that I think is important that you guys put in here is third-party oversight, right?

Because there are so many times now where, you know, I as a company, somebody that has your data, have to have these third parties. To make sure that we can get our work done. And so making sure that we are properly giving oversight to those organizations that also have to have that data in order to get whatever our job is done is really important.

On the, the 30 days itself, you mentioned that you had 2 tracks before and you came to an agreement on 30 days in the middle. Was there a lot of argument over that? Was that— how did that go back and forth to settle on 30 days? Well, I mean, most folks always want a longer period of time to comply with something. And, you know, HIPAA-regulated entities currently have 60 days under federal law.

But if you look closely at what the federal requirement says, it specifically provides that if a state wants to do something that's more restrictive, they're not preempted from doing that. We wanted to arrive at a time period which was reasonable. The important factor for me was under our current law, there was no time period, right? So there was no requirement at all, which is not to say that companies weren't incentivized to provide consumers notice if their information was compromised, but there was no uniform standard. And we had this conversation about there being a reasonable amount of time.

First of all, we wanted to make sure that there was some incentive to provide prompt notice, but also we wanted that notice period to run from the date that the breach was discovered. Because, you know, as you know, Alex, anytime we're writing new laws, we're creating potential points for litigation down the road, and the last thing we wanted to was create a circumstance where it was a gotcha for companies who had this data that was compromised. If we had it— the time period run from the date of the breach, but there wasn't a discovery of the breach for, say, 15, 20 days, there might have not been a sufficient period of time to give an adequate notice. And I think that's another part of the 30-day period, is not only do Do you want there to be a notification, but also some specificity that's provided to consumers in terms of what types of information might have been compromised and what consumers do to protect themselves? So, you know, when we were thinking about a reasonable amount of time, this is about the time period this spring when Facebook was going through its major public data breach.

Yeah, I don't know the right word either. Public flogging, I guess, is what to say, about their own security issues. And Mark Zuckerberg testified before Congress about the time that House Bill 1128 was in front of our House for our first legislative hearing. And Mark Zuckerberg testified that he thought 72 hours was a reasonable amount of time time for notification. So when we arrived on 30 days as the compromise, it seemed like a pretty reasonable period of time.

And sometimes, you know, when I talk to folks about this bill, they'll say, 30 days? Wow, that seems like kind of a long period of time. But as you and I both know, 30 days is a very, very tight timeframe to provide this notification. Yeah, you know, I've been in many instances where, you know, I've been working somewhere and we have a suspected breach, for example, right? And so you need time to be able to determine, okay, we know something happened, we're not sure exactly what happened, let's figure out who, if anyone, was affected, and then who was affected.

And if you make the notice period too short, you're gonna get a lot of, you know, I'll call false notices, right? Hey, we know something happened, we're not sure what yet, but we have to notify you, so we're notifying you. You, and then maybe we'll come back later once we can figure out exactly what happened, and we'll give you a better notice. And then, you know, that just leads to confusion and more problems. So I personally think 30 days is pretty reasonable.

And we also had the 500 or more affected consumers as a threshold, because if you had a, let's say, a small breach or something that didn't affect a lot of folks, we didn't want to have this this legislation apply to those. We wanted to give custodians flexibility to address those minor circumstances in the most efficient way possible. So anytime you put essentially the full weight of this process into place, we want to make sure that these are major events. Now, I mean, going forward, we may learn as this bill is implemented in the effective date September 1st that 500 is the wrong number, or 30 days is the wrong notice period. And so I think it's important for folks to understand that we think we have it right with the specifics of this bill, but I think we're gonna, we're gonna learn some things when it starts to roll out, and we may need to make some tweaks to it going forward, and I'm completely open to doing that.

That's awesome. So I wanted to get your opinion. So you, for the security program piece, you know, policies and procedures, stuff that folks have to have in place. The language that's specified in there is reasonable. And I'm sure, you know, being a lawyer, you know, reasonable is a term I think that gets used fairly often.

What was— why did you guys decide to go that route as opposed to giving specific provisions that people might need to follow in order to comply? I'll give you an example. The New York Department of Financial Services put out a cybersecurity— their own regulation a couple years back, and it said, hey, you've got to do this laundry list of things essentially to be in compliance. Now, it's slightly different in that it's only for financial services companies, but it said, hey, you have to have encryption, you have to have 2-factor authentication, you have to have all these sort of specific things that essentially they took the reasonable out and said, this is what reasonable is. I'm just curious from your perspective what the reasoning was to go a little bit more broad and let people define it themselves as opposed to giving specific tasks that they needed to do.

Well, I'm gonna answer that in a roundabout way, and that relates to sort of what I do in private practice. As I told you, I grew up in a mining town, and I now represent mining companies and oil and gas companies in workplace safety and health matters. And there are certain regulations that my clients have to comply with that are clear on their face and that have very specific requirements in terms of what you need to do to be in compliance. Then I think there's the more sort of hands-off approach, which is we're going to give you the broad parameters in terms of what we expect of you, and that the mechanics of how you achieve compliance are really within the discretion of the employer. And I think that this is a circumstance where you have a broad array of companies that are going to be regulated by these specific requirements.

The more specificity we put in the statute in terms of what we expect of you, it may be perfect for Company A that operates in this sector versus Company B that operates in a completely different sector. Both of those 2 companies are similar in the sense that they have confidential proprietary information that's very sensitive, but in terms of the nature of their business and and the way they keep it or how that might impact consumers if there is a breach could be 2 completely different things. So by trying to be too prescriptive in terms of what we expect in the statute, we may actually do more harm than good. So I think the objective here was to provide at least the expectation in a clear way of what we expect custodians to do, but leave a lot of those mechanics and the specifics of compliance up to the companies. And honestly, I think that's the right way to go.

The way that I design a security program is always based on risk, and the risk to every company is different. And if you told me I had to do, you know, X, Y, and Z, well, that might not address the risks that I have, and I can totally comply with the regulation but still not end up any more secure, right? So I really think that that is a much better way to go. I know that some people probably have issue with it because there are, there are some organizations out there that, that may have different views of what reasonable is, and in the short term it could cause problems for consumers because you know, until you go through the legal process, right, and it's determined, is this reasonable or not, you could potentially have consumers that are harmed in the interim, right? The last thing I want to do is create work for lawyers, but I mean, let's be, you know, candid about this.

These types of data breaches do cause harm when someone's identity is stolen, and, you know, there's bound to be litigation on these types of issues. What we've done with the statute is to create an expectation or a definition of what reasonable care is. And if someone— if a custodian, for example, misses the notice period, that could be considered to be negligence in the sense that they're missing the prescribed period, you know, that's in the statute. But in terms of the individual steps that a custodian would take to get into compliance, or in terms of the notification, or the specifics of their policy in terms of how they would maintain the data, I think that there's complete discretion given there. Or even on the piece relating to, you know, destroying the documents or the information when it's no longer needed, that's also within the discretion of the custodian.

So, you know, again, as I said a few minutes ago, we're going to learn after September 1st the way this is working, and there's, you know, there are bound to be breaches, there are bound to be instances where the notifications are triggered here, and we're going to learn a lot in those instances. And I hope what folks will do is communicate back to us, let us know how that's working, communicate with the Attorney General's Office, because if the statute isn't quite right, we need to make it right, because these are critical issues for us to get. One thing that I thought was particularly interesting is that, if I'm not mistaken, government entities are also covered as part of the obligations in this bill. So I wonder if you want to comment on, well, first why that was put in there, and any other comments around that. The original draft of House Bill 1128 did not have government entities in it.

Entities in it. And I was reading through the draft and it just struck me that we shouldn't be passing a law that affects private sector entities if the government's not willing to comply with the same obligations. And let me tell you, you know, why I had that reaction to that. We had a major breach in a juror database that was in the State Department of Law. If you think about all the information that the government has in terms of Social Security numbers and birth dates and all the sensitive information that we want to maintain security of, we are just as much at risk for a breach of a government database as we are a private sector database.

And as a matter of principle, I don't think that we should be passing laws to impose requirements on the private sector that the government isn't willing to comply with itself. So that was a really important piece to me, and obviously we got some pushback. I can imagine. And, you know, some of the smaller counties are concerned about the financial constraints or the financial imposition that that might be on them. And so I think what we've communicated back is we understand that some of you are in a better position today than others in terms of your ability to be in compliance, but I think we have set a reasonable standard that everyone needs to hit.

And I just think if we are going to set that standard for the private sector, the government needs to be there right with them. Yeah, I have had my personal information breached by several government entities. There you go. There you go. So I was glad to see that that was in there.

I've also talked to folks before in education, for example, and, you know, they have regulate— FERPA regulations that say how you're supposed to protect student data, but there's, there's essentially no teeth in it, right? If something happens, I don't think you have to really report it. You don't have to really— there's no process like this. It was sort of missing that teeth on the back end. So I'm glad that that was part of it as well.

Was there anything that you were really hoping was going to make it into this bill that did not make it into the bill? Honestly, no. I mean, I think we, as I told you, we did the major rewrite of the bill before the first legislative hearing and really tried to respond to all of the concerns that heard.

So, I mean, candidly, I feel really good about where the bill is today, or the, you know, the law. I guess we can call it that now since it was signed by the governor. But I'll be really anxious to see how it works. And I hope that we will give the Attorney General's Office and District Attorney's Office a meaningful period of time to go out and actually catch these folks. You know, consumers are anxious about this.

It's one of the things that I hear a lot about when I'm out walking in my district. Folks are concerned about identity theft and they're concerned about how much at risk they are. But what are the options for us? I mean, we all are— this is the way we're conducting business, we're engaging in transactions daily, by the hour, and all of our information is out there. We recognize that this is a part of the way we conduct business in the modern era.

So we can either retreat from that or continue to advance and try to make improvements and protect consumers. So, you know, I hope this bill is a big step in the right direction. I think it is. I would agree, for sure. So you mentioned that, I think you said you introduced 29 bills this session and got 22 of them into law?

22 signed, 1 veto. My first veto in 3 years. Oh wow, so that's a pretty good record. Well, the governor vetoed more bills this year than any other bill. I guess it's his last year, so maybe he wanted to— He's on his way out, he doesn't have to, you know, protect himself anymore.

Right, right. So what were some other big issues that you passed bills in this year? I passed a major bill relating to Medicaid fraud, so making it sort of tightening the restriction on Medicaid fraud. There was a bill on— I'm real active on issues relating to the Department of Corrections, and we had a policy where they were allowing prisoners to be transferred transferred out of state. For example, James Holmes, who committed the Aurora theater shooting, right, was transferred out of state without victims knowing where he was transferred to.

And introduced a bill to make those prisoner transfers completely transparent so that victims are notified, you know, prior or once a relocation is made, that victims are notified. I'm on the Judiciary Committee, so I'm involved in a lot of criminal justice reform issues and, and some budget reform issues. You know, we have a $29 billion budget in this state, and I know folks are tired of sitting in traffic jams and tired of hitting potholes. So hopefully we'll start to really focus on ways to make our budget process work better. And also, you know, I think that our educational system can always We can always create more of a funding base for education.

I did sponsor a bill this year to get more marijuana tax revenue for capital construction for schools. I think when a lot of people voted for Amendment 43, I think they thought that we were really going to be devoting more tax resources for education. And so I've called that bill sort of my effort to true up the intent of Amendment 43 to get more marijuana tax dollars for schools. Nice. So you said you're, you're a term and a half in, so you're not up for reelection then this year?

I am up for reelection this year. So I came in middle of the 2015-2016 session. My predecessor took a vacant Senate seat when a state senator retired, and then I was elected to fill a vacancy in January 2016. So I was elected on a Saturday and sworn in on a Tuesday, and the session started on Wednesday. So when I showed up at the Capitol to start my first session in January 2016, I walk in and they're like, Representative Wist, what are your bills?

I'm like, I have no idea. Where's the bathroom? Right. Where's my phone? Or what's my phone number?

Yeah. So I kind of had to dive right into it, but it's been an incredible experience and And, you know, it's really an honor representing the citizens of my district, and it's a tremendous honor to be able to do the work. And it's something I assume that you're still enjoying and you want to continue to keep doing? I'm running for reelection this year. I hope to be able to, you know, continue to serve.

And, you know, this is a great part of the state. My family, we've lived here for over 20 years now. My kids have gone to public school in this district, and I'm happy that one of my daughters has returned. She's now a reporter at Channel 7. So, you know, it's, it's, it's been a great way to give back to our community, and a community that's been very, very good to my family.

Yeah. So since being a representative is not your only job, how much time does it take? You said how many days were in the session? 120 days in the session? 120 days.

That's It's in the Constitution, and it's good that it's in the Constitution. That means there's only so much damage we can do to the state, because at midnight on the 120th day, all of the representatives and senators turn into— I guess you could say they turn into pumpkins and they go back and they're regular citizens. And it's one of the great things about our— we call it a citizen legislature. We're not professional politicians. We do serve in this capacity for 120 days, but once the session is over, our ability to pass laws expires, and we don't have that authority again until we reconvene in January.

So unless the governor calls us back, we all go back to our regular jobs. I go back to my law firm. I, in fact, I went back to work the very next day. During session, I'm kinda limited. I work weird hours.

I'll my clients will get emails from me between like 5 and 7 in the morning or late at night, but I'm pretty much focused during the session on being a full-time legislator, and then I go back to my law practice when it's over. You know, we have farmers, we have teachers, we have folks that come to the legislature from all walks of life, and that's truly what makes it, I think, a unique institution in the sense that It's not unlike Washington where people go there and they're there for 20, 30, 40 years and they become professional politicians. This isn't our first job. And because of term limits, most of us will serve 4, 6, you know, 8 years is the maximum amount of time that we can serve as state representatives and then we go back. And I think that's a good thing because we continue to bring new folks into the process, get new ideas, and bring a fresh perspective.

To the people's work. Awesome. Well, I think that's all that I wanted to talk about. Is there anything else that you wanted to touch on before we get out of here? Well, I think what folks should understand is that, you know, I hope that they'll see this bill for what it is, and that is this was a bipartisan, broad effort to try to bring some security to consumer data and to also help companies that have this data in their files to be effective on behalf of consumers.

Because as we all know, we can't eliminate the risk, but we can try to manage the risk in an effective way. And if folks have ideas about ways that we can improve the law or make it better once this goes into effect September 1st, They're welcome to email me, call me, text me, whatever works for them, because I'm anxious to hear how it's working. And we can put some stuff in the show notes, but what would be the best way for them to get ahold of you? You can email me at cole.wiss.house@state.co.us, which is a long email address. And my cell number, which is pretty much public out there, it's 303-882-8822.

And they can call me, text me, always welcome to hear. You're a brave man putting your cell phone out there. But, well, anyway, Cole, thank you very much. I appreciate the time. This has been Colorado Equal Security, and we will talk to you next time.

Thanks, Alex. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes