All episodes

Mark Weatherford, Chief Cybersecurity Strategist at vArmour & Former CISO of Colorado

Apple Podcasts Spotify SoundCloud

In this episode:

Mark Weatherford, first CISO of Colorado, and current Chief Cybersecurity Strategist for vArmour is our feature interview this week. News from: Shark Tank, CNBC, Denver International Airport, CTA, Coalfire, zvelo, Webroot and a lot more!

Swim With Sharks In Denver

What could be better than the Sharks coming to town? How about 25 awesome ice cream parlors? Denver is moving up the list of best states for business, and DEN (hard not to say DIA) is getting a massive overhaul. CTA gets a new CEO. Coalfire has TWO blogs so good I couldn't help but include them both this week. And blogs from zvelo and Webroot.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11817 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 75, July 19th, I believe. And I have a special guest.

I've upgraded my co-host this week, Debbi Blyth, the CISO for the state of Colorado. Debbie, it's good to see you again. Good to see you again. Thank you for having me. Absolutely.

It's been about a year, I think, since we had you as a feature guest on the show. And this time you've upgraded or downgraded to co-host status. Awesome. Yeah, I was excited. So really, before we jump into all the news, I'd love to hear what's been going on with you over the last year.

What have you done? Oh my goodness. Well, you know, running the security program at the state of Colorado is been a ton of fun. It's like a half-time job, right? Yeah, just part-time.

What do you do the rest of your time? Well, you heard about the CDOT incident, right? I did. Yeah. So I— that— I was very busy with CDOT for about a month.

Yeah. Threw me completely a month off all my timelines. That was a couple of ransomware infestations back to back, right? Yes, it was. Yeah.

And what I've learned about that is that if you don't pay the ransom within 7 days, sometimes they might hit you again. So that's exactly what happened. Yeah. But we had— someday I'd love to come and talk to you about that. Because we had a lot of phenomenal assistance both at a local level and at a federal level.

We had the Colorado National Guard helping, we had the FBI helping, we had FEMA, we had Homeland Security. So I'd love to come and talk to you about that. That was a great project. Yeah, we should do that. Let's try and get that here in the next couple months to talk about on the show.

That'd be fun. Yeah. Cool. What are you, what are you gonna try and finish up this year, 2018, as Hickenlooper's term ends? Any big priorities for the rest of this year?

Yeah, so one of the things that we're trying to do, and this is across Hickenlooper's cabinet, is really putting good documentation in place for any administration change that might happen. So kind of documenting the program and making it, you know, a visual picture of what it is that we've done over the past 4 years and how everything we've done has kind of snapped together to create a methodology to follow, a framework. But we're also implementing privileged access controls. Continuing with our identity and access management strategy. So there's just a lot of efforts underway that we are continuing.

We're also going to start doing security assessments for each agency. We're kicking it off with CDOT. So I'm looking forward to that because it's going to be sort of a deeper look at each agency than we've done before. Yeah, well, that's pretty neat. I know, I'm excited.

And obviously, when, you know, we have a new— we're definitely having a new governor come in in 2019. And depending on how it all shakes out, if it's a Republican, probably a lot of changes, I'd assume, across everything. If it's Democrat, maybe not so much. Hard to know. Hard to say.

Yeah. Well, we'll keep, we'll keep in touch and we'll hear from you early 2019 whether you're, whether you're still there with the state or if you're somewhere other awesome place, then we'll learn about that too. Sounds great. I look forward to it. Well, let's, let me start off by going through a little bit of housekeeping stuff.

Reminder for everyone, we have a Slack channel and I know Debbie, you're on there. This is a place where we have local security folks get together and just share what's going on with them. Some, some great conversations this week. I actually just posted in the Slack channel looking for a recommendation on, on siding for my house, some siding repairs, because I don't know 500 people in Denver where I can easily ask for help anywhere else. That's the random channel.

That's not the security channel. We also have a mailing list, which is what every week we send out the show notes. So if you want to get the show notes delivered into your mailbox, sign up there, go out to the website. Colorado-security.com to sign up. Uh, we'd love it if you'd rate us and review us on iTunes, and of course you can subscribe there.

And then finally, we do have a Patreon, um, a Patreon campaign where you can support the show, uh, help us make sure we pay for our funding, get to do cool stuff like buy new t-shirts. And of course, actually this week we have a brand new, uh, $10 Patreon. So at the $10 level, they not only get a Colorado Equal Security shirt, but But they also get a shout out on the show. So big thanks to Chris. I think it's Galano.

Chris, we appreciate your sponsorship and look forward to getting to know you here as we go. So with that, why don't we go ahead and jump into the news? So number one on this week's news is that Debbie, did you know that the Sharks, the Shark Tank show is coming to Denver and looking for folks who want to get on the show? That's pretty exciting. They were here last year, and I know I did see a Colorado person on the show.

Sounds like it's July 21st, Saturday, and you get an opportunity for a 1-minute pitch. Yeah, 1 minute to try and convince them. I'd love to try and summarize a good idea into 1 minute. It's probably just the exercise of getting it that short is probably a big part of the success, right? I know it.

Yeah, pretty cool stuff. So another thing this week, the 25 Best Ice Cream Shops in Denver was a great article that came out, and I loved it because it was really all pictures. Yeah, I so we love. I have two little kids. We love ice cream and ice cream shops, and I haven't been to.

I haven't been to probably twenty or maybe eighteen of these. So pretty cool stuff, and I never even heard a couple of them. The number one is called Sweet Cow on Thirty Second Avenue. I had not heard of that. Never heard of Sweet Cow.

Number two is the Inventing Room. We we have been to the Inventing Room. This is the place where they use what is it? The super cold. Oh yeah, nitrogen.

Yeah. Something like that. Yeah, I think it's nitrogen. Really, really cold to do. Like, you know, they nitrogen-infuse like popcorn and ice cream and stuff to really get the dry ice look and everything.

So that one's over there. It's kind of similar area. Number 3, Inside Scoop. Never heard of them. Sweet Cooey I've been to.

That's number 4. And number 5 is Little Man. I expected that one to be a little bit higher. I was really surprised that Bonnie Bray was all the way down at number 13. That's, you know, kind of a landmark ice cream shop and Not as high as I would have expected on the list.

Yeah, well, a lot of good places to try. Debbie, do you have a favorite ice cream place? Well, I do actually. So number 10 on the list is Frozen Matters, and Frozen Matters is about a block and a half from where I work. Yeah.

Um, but what's really cool about Frozen Matters— I've actually never had the ice cream— um, they have a little speakeasy in the back. So this is— it's a bar slash ice cream place? Yeah. So what you have to do, you, you go in. The speakeasy is not open till 5 PM, and you have to know the secret way to get in there.

And if you don't know how to do it, just ask the the lady behind the ice cream counter. She'll tell you. So it's not too hard to find out. It's kind of a fun little place back there. But you're not going to give away the secret on the show today.

Well, I could. How many listeners do we have? Well, we should have about 500 over the next couple of weeks. Oh my gosh. Well, I'd hate to not be able to get a seat in there.

Yeah. So let's keep it to yourself. Okay. I'll keep it to myself. Yeah.

All right. Next news story this week. Colorado has moved up on CNBC's Top States for Business list. As of this year, we are number 5, previously number 6. Yeah, I saw that.

And in fact, we've been in the top 5 with the exception of last year for the past 4 years. So that's pretty good, but not surprising. One of the things that's keeping us from going much higher at this time is the fact that it's expensive to live here in Colorado. Cost of living, we got it. We only got a D+, but we got A's, A+'s, A-'s across workforce, economy, technology innovation, and access to capital.

So pretty good. Number 1 state is Texas. Number 2, Washington. Utah and Virginia. Yep.

Yep. So something I wanted to ask you about is Denver International Airport. They're doing some remodeling and you kind of had an experience with that, didn't you? Yeah. So we were putting the show notes together and I like sending over the articles to Debbie to take a look at.

And I had the DIA story on there, but I hadn't actually read through it yet. And I did this on a flight back to Denver. I got off the plane and I'm like, oh, I'm going to get my lunch. On the other side of the, of the train, you know, when you get to the main terminal. And I got off the train and all of the main terminal restaurants were closed.

They're all closed. And of course, I read the article and I see that was phase 1 of a multi-phase approach to a big renovation for DIA. Yeah, big renovation. They said they're going to improve the way that the traffic flows through the airport, which I'm really hopeful that that will also mean improving the way the traffic flows through the security lines. Yeah, well, so that's actually the primary change, I think.

So they have 4 different phases. Phase 1 just got kicked off. Basically, they're moving all of the ticketing booths for all the airlines. They're moving those into a different space. So at the end of this, they're going to move security, which is now on level 5, up to level 6 to be on the same level with the ticketing booths.

And they'll both be on the north side. It won't be a north and south and there won't be that A concourse security one. So you'll get your tickets at your ticketing booth. You know, you drop off your bags, you'll walk to the north side, you go through 2 different security lines, one on the left, one on the right. And they say that they're using a whole— they're going to be implementing a whole bunch of new techniques that are in play in other airports that will speed up dramatically.

The way the article put it was that, you know, the current security system is kind of a draconian 9/11, you know, quick reaction versus the new technologies which can really enhance speed through security. Awesome. But it is a long tail on this. It looks like, you know, we're not going to expect to see it done through the end of 2021. Which is what, like 3 and a half years from now?

Yeah. But the security starts to happen in early 2020. So we got a little ways to go. Yeah. Oh, and I will say one more thing.

The Level 5 where they're moving security off of is going to become— it's going to be inside of security. It's not going to be accessible if you haven't gone through security yet. And it's going to have restaurants and shops and it's just going to be a big kind of plaza area there. All right. All right.

Next piece of news, the CTA has named Franny Matthews as their new CEO. So we had talked to Andrea Young, who was the previous CEO, and she has moved over back into a private sector role, and Franny has taken her place. I don't know Franny yet. Have you met her? I don't either, I have not.

But it's interesting, I read the article about it, and it sounds like she's been with IBM in the sales organization for the past like 18 years. And she described it as a bit of a left turn, but she's actually been on the board of CTA. So I'm sure she knows the lay of the land. I'm sure she'll be great. Well, that should be pretty fun.

It's nice to see new blood. And of course, congratulations to Andrea for her new role. It looks like she's the COO over at NuCloud, which is a local tech company. Yeah. Yeah.

Next on the list, there was a ColdFire blog about the extended privacy protections that has been granted to California residents. So the California Consumer Protection Act. Yeah, I mean, this basically looks like California's answer to GDPR, right? Giving a whole bunch of requirements. I personally, as I do business with California residents, this is going to impact my company and something I'm really looking at pretty closely.

If you, if you just went through GDPR compliance work, it's very similar. A lot of the same concepts. The work you did doing workflows of where all your consumer data is, it's all going to be what exactly what you need. The right to erase your— the right to, you know, to have an asset inventory of all of your data. About them.

Those are all the same types of things. Yeah, the one thing that I noticed, if you don't do a lot of business in California, so if you just have records of just maybe a handful of California residents, it may not apply to you. If you're a smaller company, you also won't have to worry about it. So, they did a pretty good job of spelling out who it does and who it does not apply to. Something else you might be interested in is Colorado has updated its protection for consumer data privacy law as well.

Yeah. And we are now one of the fastest states in the nation as far as notification for data breach. 30 days. We have to do it in 30 days. So, um, don't blame me, I didn't have any input into that whatsoever.

So, so we had Cole Wist, who's the state representative who co-authored that bill, on the show a couple weeks ago. And number one, I thought it was a really good interview, but he also talked quite a bit about how they came up with that number. Initially it had been I think he said that the initial draft was you had to get to the Attorney General within 15 days, and you had to notify the individuals within 60 days. It might have been 15 and 45. But then they said, well, having 2 different dates was not what they wanted, and it ended up going kind of an in-the-middle date for both.

Anyway, it is what it is at this point. But it's interesting to see the regulatory changes we see coming in. I guess that's not regulatory. That's just a law, right? Statutory change.

Yeah, that's the right word. Well, and it's a faster notification even than HIPAA, and in the state of Colorado takes precedence over HIPAA. There you go. So there you go. Um, so we have a second blog post from Coalfire this week.

I think this is the first time I've ever put 2 blog posts from one company, but I thought that they were both so interesting and, and really relevant to a lot of us. So this one was about the transition to the new SOC criteria, the new SOC 2 criteria. If you guys have been doing, you know, if you remember like a decade ago or whatever it was, 6 years ago, we were doing SAS 70s. We moved into SSA 16s. We're now doing SSA 18s.

And the new SOC 2 criteria also is moving away from their old control framework into a COSO control framework. I'm not going to go through all the details of this, but if you have any interest in either reviewing SOC 2 audits or in having one done for your organization, I think this is a really good document to read through. Yeah, and the one thing that I did notice that seems brand new, there's a couple new things that you need to report, or a couple things you need to report with more depth, let's say. But now you need to disclose system incidents. So they give some good guidance around when you may have incidents that fall into what they're expecting disclosure there.

I think they have more third-party due diligence required, right, for your, your third parties. They had a bunch of stuff. I think that's one of the ones I remember. We've actually transitioned to it at Ping, so I've had to look through it. That was one of the big changes for us, remapping our controls over to the new framework.

Yeah. Yeah. Well, good. So the next article I think you put in there to test my technical acumen, Securely Logging and Tracing HTTP Requests in Go. So if you're using Go and if you're doing debugging, one of the issues that you might run into if you're trying to debug the HTTP or HTTP request, you might, you know, if you're debugging, you're going to send information to your log and it could include information such as authentication credentials or the security token, which you don't want in your log.

So this article goes through and actually explains sort of the methodology of why the individual chose to do it the way he did and then gives you the actual code of what he did. Yeah. Debbie, you killed it. You just killed it. That's awesome.

Really what we try and do is make sure we have a few articles that are going to help teach our more technical folks something new and give them— give back to the community a little bit. Uh, it's awesome that Zvelo created this and kind of like you said is giving this resource out to folks to use. So recommend for those who, who might be interested, take a look at it. Uh, final article here is Webroot has a, uh, has a blog post about 3 cyber threats IT providers should protect against. Uh, anything pop out to you in this especially interesting, Debbie?

Well, it wasn't anything new. So anybody listening, they're not going to get anything necessarily new out of this article. But I did feel like it speaks not just to IT providers, but to all of us. And it's always interesting to see what kind of threats are on the rise because then it helps us to tailor our security strategy to make sure that we are, you know, responding to those. Yeah, I think, you know, for one reason that they wrote it the way they do is they try and sell Webroot as an OEM into MSPs.

You know, MSPs are a big part of their customer base. So they're, they're always looking for that, you know, Google optimization. Um, as a provider of, uh, SaaS services, uh, I think we do have to hold ourselves to a little higher standard. We have to make sure we're not just as good, but, you know, better than our customers. So I appreciate that perspective.

Uh, and it's just interesting to know where they're, where they're coming from on that. Sure. Absolutely.

I think the last one is the CISO of the Year nominations. I don't know. That's right. Yeah. So we have, uh, CTA does their annual APEX Awards and last year we had the CISO of the Year added and of course this year the nominations are open right now.

That's right. In fact, they close on Monday, August 6th. So a couple more weeks. Yeah, you have a couple more weeks to think about who you might want to nominate or go talk to your communications or whoever folks in your company and get them to write you up for a nomination. Yeah, we want to make sure we have a really strong group of folks so that the judging committee can find someone good because there's not that many good people.

You got to get as many in there as you can, right? Very true. All right, that's it for news this week. Let's go ahead and move over to the Slack message of the week. This is where we have a sponsor, Andre Gaeta.

Andre is a local security guy who just wants to help the show be successful, and he will give the winner of the Slack message of the week one free item from the Colorado Equal Security swag store. And this week's winner is Gene McGowan. Generally, we look for something that either sparks some interesting conversation or is a really great insight, but Gene kind of made me laugh this week. He had a Doctor Who quote, which, you know, life is way too serious, and I appreciated his Doctor Who quote. So Gene, you're the guy.

We'll reach out to you and give you the details on how to get your swag. And once again, thanks to Andre Gaeta. Moving on over to events, as a reminder, we do have an event calendar on our website, and it is packed out well into October, November right now. There's a lot of good stuff coming up. So if you're looking for, what am I going to do next week?

Hey, I got some free time. Family's out of town, there's a lot of stuff that you can get involved with. Yeah, so the first one, CSA, is meeting on July 17th, so that's this week. Yeah, it should be a good program. It's on threat hunting with ELK Stack.

Oh, I love that. I know, I got to get my team over there. Yeah, ISSA Colorado Springs has their July meetings on the 17th in the evening. They have their dinner meeting, and then on the 18th at lunch they've got the lunch meeting. That's great.

DENSEC is meeting on July 18th, and that is the kind of laid-back hang out at a, at a local bar. I don't think they've said what bar it is yet. Lately it's been Reinhaus. I don't know if they'll be back there. That's a good place to hang out though.

Same night, OWASP Denver has their monthly meeting. So if you're looking for something more formal and more educational, maybe you go to OWASP. If you just want to hang out with some security folks, maybe take a look at DENSEC. Sounds good. SecureSet is having their career conversations with Allison Lawrence Daly on the 19th.

Also on the 19th, ISC² is having the Data Protection Industry Practices to Identify and Protect Sensitive Information. That's— I think they're both at SecureSet, so I'm not sure how they're doing this because both— I think both of those events are happening in the same place the same night. They got plenty of space. They'll figure it out. Yeah, they have a new nice big location.

Yeah, I'm sure they'll work it out. ISSA in Colorado Springs is having a mini seminar on the 21st. Yeah, these are kind of interesting events. They have 4 hours set aside where it's basically meant this is a place you can go get some CPEs and learn 8 AM to 12 PM once a month on Saturdays. And it'll be different topics, but usually pretty technical and really kind of a concentrated learning experience.

That's awesome. The week of the 23rd, the National Cybersecurity Center is doing their Air Force Academy Cyber Camp. This is for kids. It's a week-long camp to learn about cybersecurity. I wish my kids were old enough.

I think it's junior high is the, is the youngest age for it, but looks really cool. It does. Unfortunately, they are full and on a waiting list, but if you go to their website, they tell you who to call to get on the waiting list. So I'm sure you can get on the waiting list. Make a long, long waiting list for it.

Yeah. There's a GDPR meetup at hosting.com, GDPR and Compliance as a Service, on the 24th. Awesome. On the 26th, SecureSet has their expert series with Douglas Brush. We've had Douglas on the show before.

He's one of the leaders over at Kibu Consulting and a really cool guy. Yeah, he's actually talking about dealing with ransomware and the attackers behind it. So I think it's going to be a good program and I'm going to try to get over there for that. Awesome. Yeah.

ISSA Colorado Springs is having CISSP exam prep 105 on the 28th. So this is, this is your chance if you've been thinking about getting your CISSP. A really affordable way for you to get trained up is going to this training. I think if you're an ISSA member, it's, it's like a couple hundred bucks. And if you, if you're not a member, you have to join to do it, but really affordable.

That's week 1. Recommend you guys get signed up. Sign up early. I'm sure it'll have a good chance of filling up. All right, why don't we go ahead and jump over to jobs now?

We have a couple of jobs that I'll take first. Those are 2 different jobs here at Ping Identity. We're hiring a director of IT. This is someone who's going to be over all of our desktop computing, our networking, telecommunications. One of the, you know, really the leader, strategic leader for our IT at Ping.

And similarly, we have another role there. This one is in our SaaS platform. Our Site Reliability Engineering team is hiring a couple of people who are doing security operations work. So those folks who are going to be kind of the hands-on implementers, the engineers for our security solutions within our SaaS platform. So if you're interested in either of those, take a look at the website and apply, or send out a note out to me and I can help you get connected.

Sounds good. Denver Health has a Security Analyst 3, so this person will be responsible for incident response, for change evaluation, and for security monitoring. Yeah, LogRhythm is hiring a Manager of Security Operations. There's a couple pieces of news here. This is hot off the presses, this just happened.

It's because Greg Foss, who was doing this role, just got promoted into another role within LogRhythm doing more research. So it's kind of a backfill for what he was doing working for James harder in security. Congratulations to Greg, and of course, this is a great opportunity if you want to help run security operations for one of the best security companies here in Denver. It's awesome. The National Cybersecurity Center is hiring a Chief Operating Officer.

That's a pretty big deal. It is a big deal. So they got some new funding this year, and this is really an opportunity to have a good impact with the National Cybersecurity Center. Awesome. Pearson is hiring a Lead Enterprise Security Architect focused on identity.

Pearson, the education company, and I believe that this is probably in the Denver Tech Center area. And Arapahoe Community College is looking for cybersecurity facility— or faculty, sorry. This looks like it's a full-time, 9-month faculty in the computer science department. Pretty fun. You want to go teach some, some of our next generation of security folks?

I like it. And it's cool to see, you know, the local community college getting this too. You know, it's been such a narrow set of schools that had it previously. We're seeing a lot more programs. We saw Colorado Christian started their program recently.

We had, uh, was there was another one in town that just started one? I know Regis has expanded theirs, but a lot of good stuff going on from an educational perspective. Yeah. NREL, the National Renewable Energy Laboratory up north in Boulder, is hiring a cybersecurity research engineer. And NBCUniversal is looking for a cybersecurity architect.

And then finally, Direct Defense is hiring a security analyst team lead. So, uh, opportunity for you to run the security analyst team there. Yeah, it sounds like a fun role because it's customer-facing too. Yeah, I get— you get the combination customer-facing and the technical work. And if you like those 2 things, pretty good.

Well, that takes us to the end of jobs, which is the end of the newscast. We, we are— do have a pretty great feature interview this Mark Weatherford, who I believe is maybe like 3 CISOs, 4 CISOs before you at the state, is going to be our featured guest this week. He was the first CISO of the state. He actually wrote the statute that tells me what it is that I'm supposed to do. So, and I met Mark at, I don't know, some dinner sometime.

And yeah, I just really think he's a great guy and it's going to be a fantastic interview. So Mark was the CISO for the state of Colorado, then he moved to California and he was a CISO there. I think he moved back to DC and was was working out there for quite a while. But he's back in Colorado now, somewhere down the Springs or Monument area, somewhere down there. So he and Alex got together and did an interview a little bit ago.

And I'm glad to get to share that with you guys. Well, Debbie, thank you so much for being the guest host this week and really making Alex look bad by how good a job you did. Well, thank you for having me. I've enjoyed being here. Well, we'll catch up with you in a couple months and get you on the show as a guest again.

Sounds great. All right, thanks Debbie. All right, thank you. This is Lucia Turpin, CISO at Polycom. This is Colorado Equal Security, for Colorado security professionals by Colorado security professionals.

This is Alex Wood with Colorado Equal Security, and I am here today with a very special guest, Mark Weatherford. How's it going, Mark? Good, Alex, how are you? I'm doing well. First, thanks for agreeing to take a couple minutes to talk to us today.

Secondly, you recently became a Patreon supporter of ours, so thank you for that support. Really appreciate the support of the podcast. I think some people probably know your name, but for those that don't, why don't you tell them a little bit about who you are and what it is you're doing today? Yeah, well, so what I'm doing today is I'm working for a security startup company out in Silicon Valley, V Armor. We do cloud and data center security.

And, you know, I've been in the security business literally my whole life. I got out of the Navy in 2001 after having been part of the information security growth during the '80s and the '90s, moved back here to Colorado, and Governor Owens at the time asked me to come and be the first CISO for the state of Colorado. And, and, you know, when I, when I— there was literally, there was nothing in place when I got here. Yeah. And I stepped into this huge office in the Capitol building with a desk and a chair in it, and that was literally all.

That was all the security. That was it. That was it. You know, there were little pockets in some of the agencies around the state, but there was no overall overarching security program for the state. So, you know, that was an incredibly fun time to be in security.

The governor— we didn't have a budget at the time. I mean, I didn't have— the governor had a little pot of money from, from somewhere. He said, okay, I think it was like $2 million, $2.4 million or something. He said, go build this program. And so we did.

We hired a few people. I brought in Coalfire at the time, a fine Colorado company, to come in and help us develop the state security policy. I worked with Senator Ron May and a couple of legislators. We created the nation's first state-level cybersecurity security legislation. So, so, you know, that's kind of my, my link to the, to Colorado.

Yeah. And it was my first CISO job. I left here, Governor Schwarzenegger hired me in California to, to go out and basically do what I did here. So I think it was, it was validation that we did a good job in Colorado. Yeah.

But at the same time, California is a different animal than Colorado. Geez, I'm sure. We had like, I think we had at the time, we had 24 state agencies here. In California, I had over 160 agencies, boards, commissions, departments, etc. But every one of them had a security program.

Incredibly challenging. So you said when you came back to Colorado to do this job, were you from Colorado originally, or did you have ties here from when you were in the Navy? No, none. So I was— I built a security opera— when I got out of the Navy, I went to work for Raytheon and moved to San Diego, and I built a big security operations center there for the Navy, actually. Okay.

And I, out of the blue one day, my boss said, hey, I need somebody to go to Colorado and work on this Missile Defense Agency program out at Schriever Air Force Base. And, and, you know, like, I'm willing to do it, right? So I moved from San Diego to— that's how I ended up in Colorado. That was in like 2003, I think. So that's how I got here.

Awesome. Awesome. So you mentioned that you were in the Navy. I believe you did cryptology or something similar to that in the Navy. What was that like?

And what— how did that change from, from when you went in to when you got out? I imagine there's a lot of technological change during that time. Yeah. So, you know, as a cryptologist, you work basically in the signals intelligence business. So we're looking at taking intelligence out of the air.

And, and so over the years that grew to networks, you know, I mean, we didn't have hardline networks, right, back when I first came in the Navy. And then I went to grad school in the early '90s and I wrote my thesis in 1994, wrote my thesis on information security, which at the time I guarantee there were maybe— I felt like maybe there were like 100 people in the entire world that were doing this. So there weren't a lot of resources, there weren't a lot of people to talk to. The internet was— had— remember, the internet, just the World Wide Web, was invented in 2000 or in 1993, right? So I mean, there was just nothing there, but it was just such a fun, incredible time.

So So from the evolution between then and then, I would say the '90s were, you know, the nirvana of security. We were inventing stuff, we were inventing new tools.

I was— my last job in the Navy, I was in Norfolk, Virginia at the Fleet Information Warfare Center, and I literally got a call one day from a guy at the Navy Surface Warfare Center. He said, I've developed this tool. It's called Shadow. Shadow? Shadow, I think.

It's a— it's an aggregation tool, a data aggregation tool. I'm like, that sounds interesting. I have so much freaking data, I don't know what to do with it all. So I just started sending him this, all of the data that we were collecting for the Navy, and he was like, this is the So he was able to tune the product and really make it a good product. And we had installed it around all over the Navy after that.

That's awesome. So you get out, you go to Raytheon, you eventually end up here, and then you end up at the state.

What was the process you went about, you know, essentially starting from scratch? Was it relationship building? Was it assessment? How did you try and wrap your arms around everything that that you needed to do. It's coming into essentially a very big enterprise, right, and starting from scratch.

Yeah, well, so here in Colorado, I mean, there were probably a dozen or so people that were doing security within their agencies. Some were doing it well, some were doing it not so well. But I pulled everybody together and I said, hey, I'm the new guy. I don't I jokingly tell people all the time, if they would have given me a civics exam before bringing me into state government, I would have failed because I didn't know how government worked. But anyway, so I brought all these people together and I said, we need an enterprise security program for the state.

And when I say enterprise, I mean overarching over all of the the elected officials, or the executive branch agencies. But we also brought in the Secretary of State and the Treasury, because they wanted to be part, and we needed them to be part of the organization. So, we basically wrote the Colorado security program. And it was, at the time, I thought, you know, it was my magnum us. I mean, it was like, this is really good.

We have kind of— we've touched all of the equities for all of the different agencies. We've tried to. But it was a very high-level program. It said, okay, these are the things that you must do or you must at least think about.

So over the course— and then when Governor Owens left office, Governor Ritter came in and and he kept me on, which, you know, is something else I didn't understand really from a, from a government perspective. Typically when an administration changes, they— everybody leaves, right? Especially when it's a change of the party. So Governor Owens was a Republican, Governor Ritter was a Democrat. So I was one, I think, of 2 or 3 people that Governor Ritter came kept on.

And he brought— you may remember, he brought in Mike Lokaitis as the CIO, and Mike was a fan of mine, and he, and he really wanted me to stay and help him build the, the, um, the IT program for the state. So, um, so anyway, it was starting from scratch, from nothing, to, to where we left it. And, you know, and the piece of legislation was really important. I think at the time I didn't even realize how important the legislation was, but it codified Colorado as kind of— I won't say a visionary, but we were certainly leading the pack of a very few number of states that were saying we're going to take security seriously in the state. Yes, let's talk about that a little bit more.

What was this legislation about? What was that? What were the tenets of it? Well, there were 2 important things for me in there. One was it codified the role of the CISO.

And it said, okay, the state will have a CISO, and here's the responsibilities, and it laid them out, you know, here's what the CISO is responsible for. And my introduction to the, to the sausage-making of legislation, you know, they wanted to make me responsible for everything. And, and, and I said, I'm happy to be responsible for it if you give me the authority to to, you know, to address the issues. Well, as you know, the probably one of the biggest challenges, and I had this in California in spades, is state agencies don't want to lose their control. They don't want to lose their authorities.

So we had to water that down just a little bit, the responsibility, and I never had direct responsibility responsibility over the CISOs in the agencies. It was kind of dotted line to them. They still worked for the secretary of that agency, but I could kind of help them and help them move their chess pieces around. So that was the first thing, was the role and responsibilities of the CISO. The second thing was establishing a budget, because if you don't have money, you can't do anything.

So, we actually carved out and created a budget for cybersecurity, information security at the time. That was another interesting thing, and a lot of my friends even today hate me for this, but when we created the office, we were called the Office of Information Security, and I literally could not get the time of day from anybody. One day it just struck me and I said— I think I had been talking, maybe it was with Senator May or one of the other legislators, and I was talking about cybersecurity. Whenever I said cyber, all of a sudden people's eyes lit up. So I am like, I changed unilaterally, I didn't even ask anybody, I changed the name of the office to the Office of Cybersecurity.

And all of a sudden I had credibility. Yeah, I'm like, you know, so it was a lesson to me, you know, that— and even though today, you know, I think cyber is way, way, way overused. Um, I'm not a big fan of the term myself. I know. But, um, but, you know, most people do know what it means, right?

If, you know, inside our industry, if you said information security, people would know you're talking about— if you go outside of, of someone that's in the industry, you say that, they're like, oh, so like, uh, exactly, you deal with paper records and stuff like that. Exactly right. So I mean, I get it even though I hate the word itself. Yeah. So yeah, it is what it is, right?

So you were in Colorado, you left, you went to California. What'd you do after that? So I had planned to come back to Colorado. I mean, I didn't really know what I was gonna do, but I, you know, we still had a house here. Yeah, I kept my house when we left.

And Mike Asante was the Chief Security Officer for the North American Electric Reliability Corporation, NERC. You know, they oversee all of the electricity industry in the United States, in North America I should say, because Canada as well as the US. So Mike called me one day toward— it was like, I think it was probably June. The elections in California were in November. Schwarzenegger was out of office.

In November. I knew that I was planning to come back here. Mike called me in June or so, and he goes, hey, I'm leaving NERC. I think you should apply for the job. You're the right guy to come in and help the electricity industry.

I'm like, Mike, but I don't want to move to D.C. He's like, oh, don't look at that. Look at the job. Anyway, he put my name in. The CEO flew out to Sacramento and met me and interviewed me and offered me the job.

Wow. So I moved to DC, worked at NERC, and it was literally— it is the best job I ever had. It was the most fun working with people who truly care about security and reliability and safety in the electricity industry. There's about 3,000 utilities in North America. And I had influence over them.

I mean, you know, one, I was, I was responsible for developing the critical infrastructure protection standards for the industry, but I was also responsible for enforcing those standards, which is a little bit of a dichotomy there. I mean, but we were able to firewall it off fairly well. So anyway, I was at NERC and then Out of the blue, I get a call one day and somebody says, hey, hold for a call from the White House. I'm like, yeah, right, who's screwing with me? And certainly this guy comes on, he says, hey, your name has been recommended to us as a potential candidate, you know, to go to DHS and run the security program there.

And, and, and I did. I said, you know, Who is this? He said, no, no, no, really, this is a serious call, serious question. He explained what they wanted to do, and I'm like, well, I would love to come and do that, but I'm not sure I want to go back into the government. I'm really enjoying private sector life.

Anyway, long story short, they convinced me to come in, and so I took the Deputy Undersecretary Secretary job at DHS for cybersecurity. And now my mind was really blown. I bet. And I bet for the first 6 months, every day or every week at least, somebody would come in and say, hey, do you know you're responsible for this over here too? And I'm like, holy crap, I didn't know.

I didn't ask enough questions in this interview process. But anyway, It was a phenomenal, phenomenal time. We were doing— my role there was, so not only did I work with all federal civilian federal agencies, civilian being everything except DOD and the intelligence community. All the agencies have their own CISOs, and I worked with a lot of them and a lot of the CIOs. Worked with the legislature the Senate and the House on a number of pieces of legislation.

But the real fun part of that job was there were 18 defined critical infrastructures. There's now 16. At the time, there were 18.

Working with the private sector in these critical infrastructures in the private sector was the most fascinating and rewarding thing I've ever done in my life because I worked with a lot of companies that really hadn't addressed security at all in their sector broadly. So being able to go in and work with the information sharing and analysis centers and the individual companies in those sectors was really rewarding. You know, you could go in and, you know, in our business Usually when the security guy shows up, it's never a good thing. They really embraced what we were doing at DHS and trying to help the private sector. That's awesome.

So you left there about 2013-ish? 2013, went to the Chertoff Group. Right about, well, just about when the executive orders for NIST Cybersecurity Framework came out. I wrote the first draft of that. That's awesome.

We started working on that in August and the president signed it in February. That is great. Yeah. And there have been a lot of things that have happened since then. Oh my gosh.

What are your feelings on how DHS and the role that the federal government has taken around cybersecurity since you've been gone? How do you think that that's been progressing? Yeah, I mean, so, well, I think it's progressing nicely. Nicely, and it's never fast enough, you know, and that's the challenge.

It takes a long time, you know. I mean, you look at that, it took 8 months for us to write, 6 months for us to write that executive order and get it signed. And I can tell you, that executive order did not have everything in it that I wanted in it. I can imagine. And in fact, I will say, you know, I was critical of the the executive order when it first came out because I thought, you know, no one's going to pay attention to this.

But I'll admit I was wrong. I mean, that executive order has really kind of coalesced a lot, and it's really brought the private sector in. It provided a framework the private sector could say, okay, we get this. This is easy to follow, relatively easy to follow, and the government endorses it. So, you know, there's— there— could it have been better?

Yeah, it could be a lot better, but I think it was a good first step. But the problem is, is now we're looking 2013, 2018, 5 years has gone by.

Slow, small. You got to keep the pressure on. Little things, but nothing huge, right? The White House has not kept the pressure on agencies the way they should. I think Yeah, we can always do better, right?

Yeah, can always do better. So, so from there you left and you went over to the dark side. You went over to the vendor side, consulting and all that stuff. What made you take that move? Well, so coming up, you know, the elections were in 2012.

Yeah. And, and as an appointee, if the president didn't get reelected, I was out. In August of that year, I started looking around, and I realized, man, there's a lot of really cool jobs out here. I mean, some seriously good, fulfilling jobs, where you could really make a difference. Michael Chertoff, who, you know, he was the 2nd Secretary of Homeland Security.

I never worked for him. I worked for Janet Napolitano. Yeah, but he had gotten out and he had started this consulting company and totally 100% focused on security. And so he wanted to build a cyber practice. So he asked me to come in and help them to do that.

So You know, of all the different things that I'd looked at, all the different jobs that I'd looked at, this one— I'd never been a consultant, and I honestly, I didn't know if it was going to be a good job or a bad job. It looked fun. It looked like I was going to get to work with a lot of people, and it did. And that was the beautiful thing about that. I mean, we work, you know, the Chertop Group is kind of a pretty premier boutique-ish consulting company and kind of gets to pick and choose a lot of their customers.

And we worked with a lot of Fortune 100s, Fortune 500s, and it was really fun to me to be able to work with them. I will say though, and you know, your audience will not be one bit surprised by that, Fortune 10 companies, Fortune 100 companies, they are every bit as challenged as as what I call the unfortunate 5,000. I think even more challenged in some ways, right? You may not have paid attention to cybersecurity before if you're a smaller company, but once you do, you're probably pretty nimble and can make some changes that are going to help you out a lot. If you're a gigantic Fortune double-digit, single-digit company, you're going to have a whole lot of process, a whole lot of things that are legacy, a whole lot of things that it's going to be hard for you to make a lot of headway on.

That is so astute. In fact, Coalfire just put a paper out, a report out on this last week or 2 weeks ago that kind of validated a lot of what you just said. Over a period of, I think, 6 or 8 months, they'd done 300 pen tests, and they looked at these 300 pen tests and And the results came out, the kind of the medium-sized companies actually had the best security programs because they're the ones, they had a codified program which meant they had a budget and they had responsibilities, but they weren't encumbered by the bureaucracy that a large company is and they had more support than a small company did. So there's a sweet spot in there, and the medium-sized companies really do, at least in my experience, they have better security because they're more focused on it and less challenges that big companies do. I have worked in large companies.

I have worked in small companies, and it is always a challenge just getting things done in big companies. It's not Not whether there's a desire or not, not whether there's support, just actually getting the work done is always hard. Yeah, well, and I won't name it, but you know, there's a big bank that a couple of years, like 2, 3 years ago, said they're spending $500 million a year. I talked to people within that bank and they're like, it's a disaster. We, you know, we, we have a lot of money, but we can't actually spend it efficiently because of the bureaucracy.

Of the organization. Yeah, it's rough. So now you are working for a startup. I also know that you are an advisor to also a number of other startups. How's that been?

How's that process been? Well, I guess I would say anybody that's working in a startup will recognize this. You have your worst days and your best days, sometimes on the same day. Being in a startup is not for the faint of heart. I mean, it really is.

I mean, it's a challenge, you know. Every day, especially when you're a new company, you spend most of your time, you know, trying to get people to recognize you. You have part of the company is developing the product, the other part of the company is trying to market and sell the product. And you never end up where you started. And so, I mean, over a period of time, not just the technology evolves, but the market evolves.

And not just your technology, but the broader technology market. So it's been, you know, for an old guy like me that's been doing this for a long time, Working in a startup has been the most invigorating thing I've ever done. And, you know, I'm kind of the evangelist for the company. My job is really to leverage my relationships, get out and do a lot of speaking, which has given me, quite frankly, given me really a lot of insight into what other companies are doing, what other technologies are doing in this space. As you said, I'm advising a number of companies, and I've tried to keep the overlap between the companies fairly distinct, which means I'm looking at a lot of different technologies.

Everything from supply chain risk management to identity management to control system visibility to physical security, literally across the map. And it's been amazing to me because I may be talking to a customer for one company and I realize, holy cow, they could use this other company's technology today. So I'm able to leverage those relationships, I think, in a really interesting way. The other interesting thing that I've done is being in Silicon Valley, you read about this a lot, Silicon Valley is a really weird place. It's, I mean, there's a bubble around Silicon Valley that people that have been there for a long time, it's almost like being in DC.

DC thinks that this little, you know, this ring around DC is this own world. It's the same way in Silicon Valley. They don't realize, most of them don't realize that there's a whole big world out there that doesn't revolve around developing new technology. People actually have to use this technology.

I think that's part of the value I bring. Certainly having been a CISO and a CSO 3 times, having to deploy stuff, actually have to make stuff work is a big value that I bring to the companies that I work with. Is that the biggest challenge that you see for startups? You know, it's one thing having a great idea, it's another thing to make that idea work for the people that need to use it. Yeah.

Do you see that's one of the biggest problems that startups are having? Yeah, you know, so working with really smart people is its own reward in many respects. But working with a small company of say 10 or 15 people that are really focused on a particular piece of technology and having a guy like me, and I tell them when I come in, I say, if you don't want my honest opinion, you don't want me advising you because if I say that's a great idea that no one is ever going to use, I think a lot of tech companies, they need that kind of honest feedback because too many companies, I think, spend too much time and money getting to a place before they say, holy crap, this is something that no one's going to buy. Great idea. At the same time too, though, and I will say that sometimes people are just ahead of their time.

You know, they, they have an idea or have developed something that the market is just not ready for yet. Um, yeah, I, I definitely see that, uh, fairly often, that, yeah, either it's people aren't ready for that idea yet, or the company thinks that the idea is fully baked and it's only, you know, it's only part of the way there. Yeah. Or, yeah, and, and the Go back to what I said a second ago, you know, where you start is not where you end. I see a lot of tech startups, in fact almost everyone, I may not even be able to think of an exception where what they started, the idea or the tech that they started with didn't evolve into something else.

Sometimes wildly different something else. You may have thought you were starting an identity management company and the next thing you know you're developing a SaaS solution for identity, which is completely different than— Along with seeing all the startups, you mentioned that you get to talk to a lot of different organizations and what they're doing. Are there any commonalities that you see for challenges that organizations are having, either particular areas that they're struggling with security, whether it's program-related or technology-related? Are there any sort of big trends like that that you see? Well, I think the biggest technology trend today is the cloud.

And there's— I still talk— there's one guy that is developing a piece of hardware, and I keep telling him, dude, This solution is dead on arrival. Great idea, you need to make software out of it. Marc Andreessen said back in 2013, software is eating the world, and it couldn't be more true.

Today, this is the most unbelievable thing to me, and Silicon Valley gets this really well right now. You don't have to own anything anymore. You can buy anything. You can go— or rent. Or rent.

Nobody's building server closets anymore. I mean, you may have a couple of servers on-site that you need for some testing or for something, but for the most part, you can go to Amazon or Oracle or Microsoft Azure or Salesforce or or ServiceNow or Cherwell. You can go to any of these companies and buy everything you need to run a company. So I don't know if that answers your question, but I think there's a recognition that, a growing recognition that technology is evolving and the cloud is the future. You know what I mean?

It is. The cloud is the future. Do you see people, security people specifically, finally embracing that? So when, you know, when cloud first came around, everybody's like, no, no, no way, we're not doing that, I don't have any control over that, that gives me the heebie-jeebies, I, you know, I can't give up the control that I have now to let people go to the cloud or anything like that. Do you see that, the tide finally changing in that area?

And I'm gonna give you I'll give you 2 answers and they're probably conflicting answers. The answer, first answer is yes, tremendous growth to the cloud. And I'll give you an analogy. 2009, my first big meeting in the state of California, I'd gathered all the CISOs and security directors together and I gave this, I thought it was a rah-rah talk, hey, we're going to work together, but I can remember saying And by the way, we need to be thinking about the cloud. We don't really know what it is, but there's something there.

And I can remember when I got done, it was like 3 or 4 people just like, they almost ran up to the front, to the stage, and I thought they were going to attack me. And they basically said, over my dead body will I ever move my agency's data to the cloud. And I said, be careful. I don't know, but I just think there's something here. So back to the second part of this.

There's a tremendous recognition today in 2018 that the cloud can probably do security better than most people.

The second part of that and I see it in my company, V Armor, right now, there's, there's a bit of a trend to say, okay, we've moved this to the cloud, maybe we shouldn't have moved everything to the cloud. So people are pulling back a little bit and, and bringing stuff, some things back on-prem because there was a, you know, The conversation about moving to the cloud 4 years ago was all the flexibility that would get you. Well, I realized you can still get locked in when you move to the cloud. I think the other thing is when it first came around, a lot of it was, oh, it'll be cheaper to be in the cloud, and the other was it'll be flexible. I think some people are realizing, one, Well, maybe for certain things I don't need to be flexible.

It's going to be what it is. It's not going to change. My usage is not going to go up and down. I'm not going to get— and then the second part, I'm not going to get any cost savings by putting it in the cloud because I can't spin it up and spin it down. I don't need to move it to this region or that region or have it available all over the world.

It's something that's really simple and it doesn't really need to be there. Is that kind of the reasons you're seeing for people? Yeah. I will say honestly, Honestly, when you think about virtualization in general, VMware started way back in 1998 with the first virtualization technology. Now everything is virtualized.

There's still a few physical— actually, there's still a lot of on-prem physical stuff that is going to be around forever. But it's really easy to take virtualized environments and build— I mean, you're essentially building your own on-prem cloud service. That's why I say a lot of people are coming back and saying, okay, exactly to your point, some stuff works really great in the cloud, but some stuff, maybe I don't need that flexibility, or maybe I need the flexibility that I decide, not what the cloud decides for me. Yeah, I'm seeing that a lot too, and I was someone early on that thought, all right, this makes me really nervous, I don't want to do any of this. And then slowly I got to see that, you know, the power that it could have.

And I think to your point earlier, most of the time these cloud services are going to do security a whole lot better than I can do. Oh my gosh, they've got so much more money, they've got so much more data, they've got all the resources they could possibly want to get this, to make sure that this stuff is secure. And I have choice, at least initially I have choice, right? You mentioned the lock-in piece, which, you know, you could get locked in, but there, you know, if I can say, hey, there's 3 vendors that can provide this service for me, you know, which one has the best security? All right, well, let's use them.

That gives me a lot more power too. Well, and to your point, you know, if Google has a bad day, that's a bad day for thousands or millions of customers. If you have a bad day, that's a bad day for you. So Google is highly incentivized to build a product that's bulletproof. I mean, they have— I read this a couple months ago— they have over 800 security engineers at Google.

That's crazy. Nobody can compete with that kind. I remember saying this back when I was in California and talking to CISOs. It's not that you don't know what to do. It's not that you don't want to do a good job.

You just don't have the same kinds of resources to compete with the cloud service providers. Yeah, and the speed with which they can come out with new services too. We have some Microsoft services and I feel like every other day there's something new that just pops up that, you know, that's breaking news. Security is only going to get better in the cloud. I mean, again, they're highly incentivized to provide security that's bulletproof.

We look at things like, the analogy, I don't know if it's an analogy, we have always used segmentation. We've always had segmentation at our disposal as security professionals as one of those tools in our toolbox that everybody should be using, by the way. Everybody should be using network segmentation. But with virtualization, now we have this whole idea of micro-segmentation where we can segment individual workloads and then we can deploy policy across an entire enterprise to individual workloads. That is powerful security right there.

I mean, if I can secure an individual workload on a hypervisor and in the segmented, micro-segmented away from all the other workloads on that hypervisor, that is powerful security. Yeah, definitely something that we couldn't get before. So we're getting close to running out of time. There's never enough. There's never enough time, Mark.

Never enough time. Anything else that, that you wanted to touch on that we didn't talk about already? I mean, the one thing I would say is, you know, Colorado has an unbelievable tech community. I don't think— and I tell people this all the time— that, you know, People look at Silicon Valley as the center of the universe, and it really is not. And, you know, one of the things that, that many of us are trying to do, saying something that, you know, that you and Robb are doing with this podcast, is trying to expand the, the visibility of the tech community in Colorado.

You know, Governor Hickenlooper set up the National Cybersecurity Center last year.

They are— it's an amazing organization that's going to really, I think, bring some visibility into this, of security specifically, not just tech, but security specifically to Colorado. And, you know, there's a great group of people running the National Cybersecurity Center, and the governor is supporting it, the legislature is supporting it with funding, working closely with the University of Colorado Colorado Springs. And so I, you know, I really would like to see— and I said that when I tried to do something when I was the CISO here to work with the Office of Economic Development to actually put some funding together to start attracting I think we're at that point now where we can do that. One, it is so expensive to live in Silicon Valley. Even though they're still able to attract a lot of talent, Colorado is— I mean, Colorado is a place where people actually want to live here.

So why not bring the jobs here? And the cost of living here is you know, a lot better here than, than in Silicon Valley and a lot better than in DC. You know, the DC metro area, Virginia, Northern Virginia, and Maryland and DC is really becoming a tech hub in itself, mostly to support the government, but there's a lot of really innovation happening. But it's very expensive to live there. I think, you know, Colorado— one of the, one of the, the biggest benefits to me personally, to Mark Weatherford personally, when I moved back to Colorado from DC was I am halfway in the, in the, in the, uh, in the United States now.

I can fly to DC in 3 hours or I can fly to San Francisco in 2 hours. So now I don't have to spend a day flying back and forth coast to coast. Yeah. Um, so Colorado is, you know, it— I tell people this is a place actually people want to live if we can build the right environment, we can start attracting more tech into the state. Awesome.

Hear, hear. I'm all for it. Well, thanks a bunch, Mark. Appreciate your time. This has been Colorado Equals Security, and we will talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes