All episodes

Karen Worstell, Founder of W Risk Group

Apple Podcasts Spotify SoundCloud

In this episode:

Karen Worstell, former CISO for Microsoft, Russell Investments, AT&T, and now Managing Principal and Founder at W Risk Group, is our feature interview this week. News from: Bird, Lime, Sphero, Amazon, National Cybersecurity Center, Google, Ping Identity, SecureSet, Intelisecure and a lot more!

I hope I look this good when I turn 242 years old

Happy birthday America! I hope you like fireworks. Denver makes a scooter program. Tariffs might hit Colorado. Will HQ2 come to Denver? We are the Silicon Valley for Blockchain. Google has news. Ping makes a big acquisition. So does SecureSet. It's not to late to vote for the CISO of the year!

Visit Karen's website at: karenworstell.com

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13391 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 74 for the week of July 9th. Alex, do you feel rested having taken a whole week off of this job?

You know, it's amazing how rested I feel. So rested that I'm ready to go on vacation. And you're— so you're ready to go leave us again, that's what you're saying? So you're kind of an every other week type of a guy? Yeah, you know, that's how I like to roll.

Yeah, well, this is, uh, this is gonna be a good episode. We have some fun news to go through. Before we do, we have a little bit of housekeeping. We have a Slack channel we'd love to get you guys engaged with. It's a place where you get to meet different folks from the security community and have some great conversations.

We also have a mailing list, so if you'd like to receive the show notes every week, go ahead and sign up for that. Uh, we recommend that you rate us on your favorite podcast app and please subscribe so you get these automatically downloaded to your phone each week. And finally, we also have a Patreon going, so if you'd like to support the show, we would love you for you to become a patron. Thanks, uh, to Mark Weatherford who signed up at the $10 level. So, uh, Mark gets a shout out on the show and a t-shirt.

So thank you, Mark, appreciate that. And we would love it if you guys would Come support us as well and get some free swag. It's not free, I guess. Get some swag and help us keep the show going. Exactly.

With that, let's jump into some stories. First story, it's kind of to bring to closure this cliffhanger we've left over the last month or two, right? First, we had scooters laying all around downtown Denver. Yep. And then people riding them everywhere.

It was havoc. It was mayhem. And then all of a sudden, cats and dogs living together. Yeah. You said we're out of here.

We got rid of the scooters. They said, if you don't take them out, we're going to take them out for you. But now You know, it's— if we're back where the city has said you can have scooters as long as you follow our rules, and their rules are basically, eh, do whatever you want. You should do these things, you know, put them here, put them there, you know, don't park them in the middle of the sidewalk. The city has asked them to have the scooters available at bus stops, light rail stations, and low-income neighborhoods.

That sounds like a good idea, but there's no requirement. It's just an ask. They've also asked that you don't block you know, right-of-way and places, you know, basically they want to make it so you can get on and off of public transportation and not be impeded. But it's a pretty lightweight set of rules if you ask me. Yeah.

And for those of you that weren't around downtown during scooterpocalypse, um, you know, these are dockless scooters. So it's not like the old, uh, bikes where you had to pull them out of a dock and things like that. It was, you basically just got on the scooter, um, used an app and you were off. Yeah. So pretty cool stuff.

I think it costs $1 to unlock it and it's, like 50 cents a mile or something like that. I don't remember anyway. And if you're looking to make some money, you can make money by going around and picking these up and charging them. And I think it's like $5 per thing you charge. It seems pretty reasonable to go pick them up.

Yeah. So it's not too bad if you're looking for a little extra cash. Exactly. Next, speaking of cash, Denver leads the US in small business job growth in June 2018 and was number 3 for wage growth. That was a smooth segue.

Yeah, thank you, thank you. So number 1, we're number 1, guys. We are number 1 for job growth. Number 1 for wage growth was Phoenix with a 5% wage growth, which is pretty amazing. So the wages in Phoenix are rising?

Like a phoenix. Well, hey, let's move on. So Denver, there is a Denver tech firm that's concerned about the tariffs. You may have heard a little bit about a trade war and some tariffs being applied. To other countries goods sold in the US and there being some retaliatory tariffs put on US goods.

Well, Sphero, which is the local company that makes those little BB-8 robots, they're worried about these tariffs impacting them. Yeah, so I think at this point they're not taking any action, but I'm sure like a lot of other companies, they are ready to make some changes if tariffs go into effect. And basically, basically the story's summary is, hey, if if tariffs get applied to their stuff, they're going to have to move manufacturing overseas as well. That's kind of what the summary of it was, I think. Next, in the ongoing saga of the Amazon HQ2, there was a survey done by GeekWire, and Denver ranked number 4 in terms of where people want to go for the HQ2.

So this was GeekWire readers. They surveyed them and The those readers said, "Hey, you know we would rather go to Raleigh, Raleigh, Raleigh, Atlanta or Austin before we go to dinner." Our old nemesis Austin, number three on the list. Yeah, I think it's not surprising. I had heard that the D.C. area and Atlanta were the highest on the list in terms of what Amazon was thinking. Of course, that's rumor again.

So not surprising that Atlanta was on there. We will have to see where it actually ends up. And it sounds like maybe we're going to hear something relatively soon. There's some rumors out there that this might not be too far off in the future. Of course, we will be late breaking the Sunday following this news coming out.

We'll cover it for you. And that Monday morning on your drive to work, you can listen to where Amazon is going to be. Exactly. Next, we had some real big news. That, uh, Colorado is going to be the Silicon Valley for blockchain technology, says leader of National Cybersecurity Center Vance Brown.

Yeah, so you guys have probably heard us talk about Vance Brown and the things that they are doing at the National Cybersecurity Center around blockchain. It still is not exactly clear to me why the National Cybersecurity Center is so concerned with blockchain. I do know that you need to have security if you are going to be doing blockchain applications, but You need to have security with lots of other things too. So I'm going to buy a parrot. I'm going to teach it only to say blockchain, and I'm going to leave it here in this room.

Polly, want a blockchain? Blockchain. Also last week, Governor Hickenlooper appointed 12 people to the Council for the Advancement of Blockchain Technology. So we have a council. And how many years experience do they each have in blockchain?

If it's not 10 years, they can't be on the council. Well, however much experience that they have, um, it is, uh, it is non-repudiated. So it's guaranteed their experience is exactly what it is. However, somebody also inserted GoatSea into the middle of the blockchain. So as, as you look up these facts, you also have to see that.

Good stuff, Robb. Good stuff. Next, Google announced $2.8 million in grants for office space in the— and also for Boulder tech education. So we had talked a little bit about some of this stuff previously. You know, Google opened a big campus up in Boulder, but they announced in addition to what previously, which was donating some money to some of the school districts up there, they're also donating some office space for the National Center for Women in Information Technology, which is pretty cool.

Um, and they're also giving a $1.5 million grant to CU's, uh, PHET Interactive Simulations Project, which is providing interactive math and science simulations. Sounds pretty cool. Yeah, well, very, very cool that Google is coming to town and they're bringing some, some, uh, charitable contributions with them. Exactly. Let's talk about, uh, Ping Identity and what they've done in the last week or so.

Who? So Ping Identity, which is the number one cybersecurity firm in all of the world, just announced that they acquired ElasticBeam, which is an API security firm. This has been really fun. It's been kind of brewing a big part of my job for the last couple months as I am the CISO over at Ping. ElasticBeam basically protects APIs and looks at all the traffic going to them looking for anomalous and malicious behavior.

And it's gonna be rolled into the Ping product line and using kind of the intelligence you get from that to enrich the other stuff that do as well. Nice, that sounds pretty cool. It is very cool. So that's, that's a big announcement. Another local company, SecurSet, made another announcement of their own.

So SecurSet Academy, um, you know, they have what, 3 different campuses? Denver, Colorado Springs, and somewhere in Florida, remind me. Um, Tampa. Tampa. In Tampa where they have their, their campuses, they just acquired a company called Hacked, or Hacked.

It's Hacked with a capital E. We're going to call it Hacked for the sake of, uh, making this awkward. They acquired Hacked, uh, in DC, and it's going to be their 4th campus. The founder of that organization, John Ferris, is going to stay on as the campus director, and really just an opportunity for them to have a good presence in, you know, obviously one of the most cybersecurity-aware regions of the country. Yeah, so congratulations to SecureSet on their continued expansion. And finally, we had a blog post this week from InteliSecure entitled The Economics of Data and Information.

I really think that this blog post was not aimed at, at us. I think maybe aimed at some folks that are not nearly as cybersecurity literate, I will say. So the, the blog post is talking about data and information, the difference between the two, and then the fact that It is important that we should protect it. And it is important. And I say the way when I read this, it looks to me like the kind of thing you put out there so that folks who are looking into, you know, what is, how do I do data security, will find this and kind of get educated.

So if you know anyone who might be interested in getting into data protection, data security, this would be a good primer, primer, whatever you want to call it, primer for that. Yeah. I guess we do have one more newsy type thing. As a reminder, the CISO of the Year Award is— the nominations, excuse me, are open right now. So this is the time for you to go get your favorite CISO, the most handsome CISO, most beautiful CISO, excuse me.

Of course, that could be a man or a woman. Either of those words can apply to any of them. And go ahead and apply out to that. And we're looking forward to the APEX Awards in November, October, November, having a good showing of lots of security leaders out there. Vote early, vote often.

You got it. So that takes us to our Slack message of the week. And this week, we would like to congratulate Rishi Singh, who brought to light the fact that Office 365 had an undocumented API for forensic log searches. Yeah, so this is actually the Slack message of the 2 weeks since we took a week off. And this was— it's funny, this news, when, when he announced it, it was brand new.

Wow, look at— there's this awesome API to get our forensic data out of Office 365. And then the news as of what, Friday or Thursday of this week, was actually Microsoft has now turned off that API and it's no longer available. So yeah, so sorry, so sorry. Yeah, it was a good discussion around it. It sounded like some people were enjoying it, investigating it.

Yeah, but for whatever reason, Microsoft decided that they were not going to leave it out there now that people knew about it. Rishi's done a good job also with a lot of conversation in the last couple weeks about privacy regulations. You know, as a Colorado-focused show, we haven't talked about California's new privacy regulation that just passed, but we have a lot of good conversation in there and appreciate Rishi's feedback on that. So once again, congratulations to Rishi. He's going to get to pick something out of the Colorado Equal Security store.

And a huge thank you to Andre Gaeta, who is the sponsor of the Slack Message of the Week. We appreciate Andre continuing this and, you know, helping us engage the community in these conversations. So let's move on to events. We do have an event calendar, so check that out for the latest events. And if you are someone planning an event, please check the calendar first so that you don't schedule over someone else.

You remember a couple of weeks ago when there was basically nothing happening the week of the 4th? This is the opposite of that. Yes. Everyone's decided, okay, we had our time off. Let's get back to work.

So there's an event every day. The ISSA Denver has their July meetings happening the 10th and the 11th. Downtown, it's Boulder, the Tuesday the 10th in the afternoon, Denver Tuesday evening, and then DTC Wednesday lunch. On the 11th also, CTA is doing their CTA 101. So if you want to learn about CTA, go check that out.

On the 13th, SecureSet is doing a capture the flag event. On the 17th, CSA is doing their July meeting. On the 17th and 18th, ISSA Colorado Springs is doing their meetings. They have their dinner on the 17th and their lunch on the 18th. Also on the 18th, DENSEC is doing their monthly meetup.

On the 17th, SecureSet is doing one of their career conversations with Allison Lawrence Daly. Uh, also on the 19th, ISC2 is doing a meeting about data protection industry practices to identify and protect sensitive information. Sounds like they should hook up with InteliSecure for that. Maybe they should. On the 21st, ISSA Colorado Springs is doing one of their Saturday mini seminars.

And then finally on the 23rd, the National Cybersecurity Center is doing the AFA, uh, I assume that's Air Force Academy Cyber Camp. Yeah, it's a week— it's actually a week-long camp. It starts the 23rd, but it goes that whole week. So if you have any kids that want to get involved, that's your opportunity. With that, why don't we jump over to jobs?

We have some awesome jobs here from Ping Identity. There is a Director of IT position if you know someone who wants to help run all of networking, telecommunications, DevSecOps support, system administration for a quickly growing tech company here in town. This is a great opportunity for them. Similarly, at Ping, we have a site reliability engineer focused on security operations. So if you're a cloud guru who wants to help forward the security program, this is your opportunity.

Kaiser Permanente is looking for an executive director of cyber risk defense and also deputy CISO. So this— yeah, go ahead. So this is a very high-level position there. Running, among other things, their security operations and taking the place of Christine Vanderpool. Christine, our friend who has, who has left us in Colorado.

She's moved to Florida. Yes. Good luck, Christine, in Florida. And she's going to enjoy the beach. Good.

Good for her. PDC Energy is hiring a director of information security. Jacobs Entertainment, which is a casino company, is hiring a corporate IT security manager. I assume this comes with free poker chips. Uh, yes, that must have been in the job description.

Yeah. Uh, GBProtect is hiring a senior information security analyst. The Department of Homeland Security is hiring an IT specialist for InfoSec. Centura Health is hiring a security analyst. Comcast is hiring a security engineer for incident response.

Gaming Labs is hiring a security specialist, entry level. Yeah, and there are actually a couple positions for Gaming Labs. There's an entry-level security specialist and a sort of regular security specialist. Actually looked like some interesting work going on there. What do they do there?

Kind of, is it gaming like video games or? So some of it was like gambling. Okay. And there was another vertical that they had, healthcare maybe also. Very cool.

Yeah, definitely check that one out. CU Boulder is looking for an incident response analyst. And it looks like Overwatch ID is still looking to hire some Java software engineers. And a C++ software engineer. Awesome.

All right, well, that's the end of the news here. The next, obviously, we're going to go over our feature interview. We have Karen Worstell. Karen has an awesome background previous to her current role. She has been the CISO for— man, I'm going to get this wrong.

I don't have the notes in front of me, but definitely she was the CISO for Microsoft. She was the CISO for one section of Bank of America. She She several other really large organizations, and she now lives here in Denver. And she shared some of her experience of leading very large organizations and and really what she's doing now. Awesome.

Well, good stuff. Look forward to it. All right, Alex. We'll see you in a couple weeks, and we'll have a guest host in here with me next week. Sounds good.

All right. Talk to you later. Thanks, Robb.

This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado. Security, for Colorado security professionals by Colorado security professionals.

All right, this is Robb Reck, and today I'm with Karen Worstell. Did I say that right, Karen? Yeah, yeah, awesome. So Karen, you have had an awesome career, and I am looking forward to understanding how you developed into such a well-known security leader. Before I do that, I want to understand a little bit about a recent trip you had through a kind of a hellscape of volcanic materials in New Mexico.

Talk to me about this trip you just got back from.

I really have to focus hard on trying to keep some balance in life, and on quite a spur of the moment, we decided to take a road trip out to Fence Lake, New Mexico, because my great-grandfather is buried out there. Oh, wow. And at least that's what we believed, right? We weren't really sure, so we decided we just took off and put the dog in the back of the SUV and drove out to— took 4 days to do a big loop. Yeah.

And saw amazing Colorado. Yeah. So beautiful. And, um, and yeah, drove from Santa Fe to Albuquerque and then took off across the volcanic landscape of northern New Mexico. I had no idea it was such a volcanic state.

Have you been to the Badlands in South Dakota? Well, I've flown over them in a small plane, but I've never like driven through. That's like the— that's what— the way when you described it earlier kind of made me think of that area where it just— everything's crusty and you can't imagine any life being able to survive there. Yeah, yeah. There's an incredible— it was called the Malpais Conservation District, and I really— I just really recommend it if anybody— I mean, I'm kind of a I'm kind of hooked on disasters.

Kind of comes with the territory, I guess. But, you know, like, like planning ahead for things and volcanoes and tornadoes and all that kind of jazz. So I'm fascinated by, you know, major seismic events. Yeah. And, uh, and I— the, the volcanic fields that are down there remind me of Big Island Hawaii.

Yeah, that's what it looks like. Well, what's going on now in Hawaii right now, right, with this, right? I, I saw a, a news story that said don't roast marshmallows over the lava. Apparently that's a— no, that's a common thing right now, I guess. I like— that was a public service announcement that said actually don't, really don't do that.

And I was like, no kidding, really? But now you got me wondering why not, because if people are doing it, it must, it must not be moving that fast. They, they feel safe doing it. Some of it doesn't move very fast. In fact, a few years ago we went to visit the Volcano State Park— the state park anyway— on the Big Island when we went down there, and we found ourselves out in the middle of a lava field that was active.

Yeah. And there were park rangers around that was— they were allowing that, but literally we were walking across that black crust and then you would see a glow like through a crack down below you. And I'm like, are you sure this is really, really a good idea? It's very hot. I mean, like what, 2,000 degrees or something?

Well, as soon as you fall through, they won't let anybody else in there. No, a French guy, a French guy did fall. He fell in, right? So the day before. Oh, and they let you right back in anyway?

So we're like in there anyway. Oh my goodness. So I don't know, maybe, maybe you shouldn't go if the French guy falls in. Pretty hot. Yeah, it doesn't sound like the best.

The worst part was when it started raining and the steam rose up, and then it was really tough. That's why I ended up— like, literally, I made the decision not to wear contacts or eyeglasses anymore because I couldn't— like, virtually couldn't see anything with the steam all around us. Yeah. Well, let's, let's get a little bit into your biography. Start me off.

Where were you born? Where did you grow up? I grew up in Tacoma, Washington. Okay. Yep, just about 45 miles south of Seattle.

Yeah, and it looks like just from doing a cursory look at your LinkedIn, your first studying wasn't necessarily starting on computer security. So how did you get— what did you do right after school?

What did I do right after college? After high school. After high school. After high school, I went straight to the University of Washington.

I majored— I kind of planned on a double major in performance, in music, and in chemistry.

The music was for me, the chemistry was for my father.

And about— you know, I like to tell this story because partway through my undergraduate, I mean, I worked extremely hard. I'm kind of— I'm a 95% creative brain person. Not the analytical side. Yeah, so much. And, uh, for me to start college, I, I started thinking I was going to be doing music and I'd get that science piece done.

And man, it was tough for me. I worked, I worked so much harder than it seemed like to me than my friends. Yeah, to get the same kind of grades. And so I went back to my dad and I said, hey, I could be Phi Beta Kappa if I did humanities and social sciences, I could really, you know, pull off an amazing grade point. And he goes, who would pay for school?

Just like that. And I was like, oh, I see. So I stayed, and I ended up getting— I ended up dropping my music, actually, because I couldn't keep up with both. Yeah. And I finished a degree in biology and a degree degree in chemistry.

Your dad's quote is absolutely hilarious. Who would pay for school? I gotta remember that in 10 years when one of my kids tries to do that to me. It was hard at the time. I kind of resented it, but looking back on it, it was one of the best things ever because I literally had to train a very creative mind to think logically, linearly, you know, and to do that kind of work.

And it's turned out to be a great asset for me, I think, later in my professional career, because I, I'm, I'm killer at problem solving. And I think that's partly because the training on the analytical side combined with the creative thinking has really helped. Yeah. So you graduated with— I think you said biology and chemistry? And what did you do after graduation?

I worked as a research assistant in doing research on blood proteins for hemophilia. I can't, I can't ask very many intelligent questions about that. So, um, the, the basically what that involved, um, at the, uh, just a kind of a spoiler alert, this might be a little bit hard for some people to hear, but I would go down to the slaughterhouse on Monday Yeah, and I had to collect 40 liters of blood for our— for us to run our, you know, labs. So when you say collect, you don't mean grab a bucket that's already waiting for you, is that— is that right? How do you collect, uh, 40 liters?

Put on a lot of rain gear. Okay. And you wait for them. So this, this, Karen, this is the story we should have led with. It's way more interesting than New Mexico.

Karen, tell me about the day that you were covered in blood having to run from authorities. Now, maybe you didn't have to run from the authorities in this case, though. Well, we had— I always worried a little bit because that little UW truck, the little pickup truck that we drove down to the slaughterhouse in Kent Valley, was pretty small. And we had 5 40-liter containers of blood in the back. Oof.

That's a lot. Yeah. Yeah. Yeah. You don't want one of those to tip over on the freeway.

So was the— why in the world would you stop doing this career? This sounds like just a lot of fun. It was. It was amazing, actually. It was the group that I was with, the lab that I was with there, was making huge strides in finding treatments for children who had hemophilia of certain types.

Really important work. And we were getting to do pro— so we were doing protein sequencing with state-of-the-art protein sequencing in the University of Washington Medical School at that time. Um, and then I had found out I was going to have my daughter, and I tried going back to work when there wasn't, you know, there wasn't any Family Medical Leave Act, right? And or EEO or that kind of jazz. And so Um, I tried going back to work when she was 6 weeks old, and it was so tough.

And I worked with a ton of toxic stuff, plus working with blood. Now people know a lot more about the kinds of things that are contagious and communicable. Then we worried about hepatitis because we did work with human blood sometimes. But, uh, yeah, it was— I got kind of freaked out about all of that. Communicable stuff, and some of it I had caught, so, from, you know, the bovine blood.

Yeah, yeah. So it was, um, I, I had to take a break. I couldn't go back. I couldn't keep up with the work routine. I, you know, I had my hats off to anybody who goes back with an infant, but 6 weeks was kind of early.

Yeah. And, uh, so I ended up taking about 5 years off. And by the time I was looking— I realized I really needed to go back and get another job, really needed it. They had moved on from sequencing proteins to sequencing DNA. I mean, I was so obsolete in 5 years.

And I found myself a mom of 2 toddlers, and I had about $13,000 in my pocket to last for 2 weeks, and I needed to figure out what I was going to do with my life. And I— my brother came over to my house, and he brought a TRS-80 computer with a serial number of 6, which we still have. And he laid it out across the table in the kitchen. I mean, it took up the whole table. And he said, Sister, you need to learn to code.

And I started— I was terrified of it. I was pretty sure if I put my fingers on the keyboard and did something wrong, it would smoke. But I started working on that and found out I was really good at coding. And when PLU opened up a computer science department and they— PLU is Pacific Lutheran University in Tacoma. When they advertised for a computer science department and they wanted students, I said Whoa, I'll try, you know.

Yeah, I mean, why not? And I got in. Yeah, 2 years later I had my master's degree in computer science. That's amazing. And you did this with 2 toddlers, and yes, and that's pretty rough.

Yeah, well, I mean, I have— I— yeah, I mean, it's a good thing and a bad thing to be able to motor through like whatever you you've got to tough your way through. Yeah. And then worry about the house burning down later. But yeah, it's, uh, yeah, it was, it was kind of— I don't recommend it, but it's what needed to be done at the time. And yeah.

So you graduated, um, with a master's in computer science. Yep. You have an undergrad and a couple different science degrees, biology and chemistry. What did you do with those degrees? What was your first job out of, out of, uh, your master's?

I got hired by the Boeing company to work on their black projects doing security for— What's a black project? The, you know, the secret school, Secret Service. Yeah, I got you. Secret, top secret stuff. Yeah.

Yeah. So they needed people. So tell us all about that. No, they were, you know, they were things that go boom and things that fly high and do secret stuff. And yeah, yeah, actually one of them was the, um, now it's the F-22.

Another one was the beach. What were you doing on those projects? I was a security administrator. So it's kind of like the very early precursor to what a chief information security officer does now. You run around trying to get everybody to do the right thing.

Right. You kind of take the requirements and figure out how to make the people do the requirements, basically. Right. And the requirements are very prescriptive in that environment. Right.

And everything was done by air gap. But now we're talking like late '80s, early '90s. So pre-internet. So the requirements, I mean, you tell me. My guess would be that there's not a lot defined yet, is there?

It had to do a lot with, uh, uh, the way that information was contained. So whether it was— I mean, we had to do the physical security as well as the digital. Yeah. Uh, but also making sure like that stuff didn't— data leakage was an issue. Isolation of environments, basically isolation of environments, but making sure the data leakage— because we still had, you know, insider threat, basically talking about.

Yeah, 5.5-inch floppy disks. 5.5-inch— well, no, 10-megabyte Bernoulli drives. What was the— what was it? Weren't they the 8-inch floppy disks? I, I never actually— really, those were for like the Wang word processor.

I never, I never saw one, but I've heard them. I've heard of those. Yeah. Um, so you, when you're looking in, in the the late '80s, early '90s, I assume that there was these requirements that you're probably having to figure out a lot of this on the fly. Well, yeah.

And some of it had— like the government, it would come in and say, you've got to do these things. I'll give you an example. One of them was that we had to review all the log files every night. Every day, every 24 hours, the log files had to be reviewed in order to look for suspicious behavior. Year.

And so I diligently took that requirement into the guys who ran our cyber machines. What's a cyber machine? Cyber was— I'm trying to think of what the equivalent of that might be. But it was a scientific processing machine, sort of probably like a DEC. And it had a 60— what is it, 60-megabyte drive? Something like that.

It was like huge then. But I came into the guys and I told them, I said, you're gonna have— it was classified environment— you're gonna have to print out these logs and review them every night. I mean, that's the rule. And they're like, you can't mean that. And I said, no, I mean that.

So the next morning when I came into my office is the printout of the log that's about 4 feet high, right, sitting all— every page stamped classified. Yeah, every single page. So I had to do, you know, I learned my lesson. I learned. But, you know, that's still something that people deal with in some environments even now.

We still print out all our logs. Yeah, you're supposed to do the log review. Isn't that the requirement still? It is still PCI. You have to do, you have to review the logs.

And it's, I'll never forget, I always come back to that cyber example going, yeah, let us show you how that looks. So 9 years, I can only imagine that you know, it looked like 1987 to '96, things changed a lot during those 9 years. You know, to your point, at the beginning there is no internet. At the end, you know, it's the dot-com boom. Yeah.

Can you get any stories about that you can share? Well, yeah, part of— so I got moved from the government classified arena up to start something brand new, because there was no commercial computer security program. And they had me move into the research and technology organization, and I became the co-chair at NIST as Boeing's contribution to the security architecture group for OSI, for the Open Systems Interconnect. Because we, at the time, XOpen, NIST, we were all working on what was distributed computing going to look like. So back in my lab, where we were doing the security work, research work, we were running DCE, we were running CORBA, we were running the very early precursors of NT.

Whatever we could, whatever— we were running a ring network. So whatever the early precursors were for networking, we were running all of them, and we were trying to develop the security models for those, which was amazingly, amazingly fun. Yeah. And, um, I, I went to— I was on a few ANSI groups, subgroups, ANSI being this American National Standards Institute. Yeah.

And I remember there was a meeting one time with just 3 of us there, and we were trying to figure out how to systems that didn't have trust, you know, talk to each other so they could exchange information. And I remember we were sitting around the table going, how are we gonna make this work? And it's like, oh wait, there's this way to do a 3-way handshake. And it's like a— some guy named Diffie and some guy named Hellman put it together, right? And it's called Kerberos.

Let's look at that. You know, I mean, literally we were putting that together. We were writing the security for email. Yeah. And on the fly.

Yeah, making it up. But, but the models became kind of, uh, they were the precursors because at some point it stopped being a collaborative, uh, organic standards process. And some really large companies came in and said, you know, there was an X Open meeting and at the plenary, the company, well-known company from Redmond, came in and said, you know, we're not gonna play this game. You guys can keep doing your de jure standards all you want. We're going to make the de facto standard happen.

And it was born, um, and we went from there. Yeah, the world, the world pivoted at that moment, unknown to a lot of us. So, um, we, so we were working on that, and then, um, so it was all this emerging, you know, emerging technology that we were trying to figure out as it came out. One of my coworkers, Dan Schnakenberg, he— I think it was like '92, we came out with— and Microsoft came out with a new version of Excel. I think it was '92 or '93.

And it had something in it, and Dan came— it had a new piece of code in it, and Dan came into my office and he goes, have you seen this? And I was like, what? He goes, watch this. And so he opens up Excel and there's a macro, right? There's executable code inside Excel.

And we're flipping out. Like, we run the whole company financials on Excel. If this was corrupted, I mean, it executes on open. What does that mean? Like, we're having this, you know, what I call a paper bag moment.

And we went into management and we said, you have to see this. Like, this just happened. We want to make sure you're aware of this because it could have some big implications. And they listened, and then they, they said, you people need to get a life. They say that to us still, don't they, Karen?

Yeah, I'm used to it after all this time, right? That was the first time. That was the first time. Yeah. Yeah.

Awesome. Cool. You got to have such a good experience in pivotal years of the development of the internet and standards. So you were at Boeing through about '96. What did you do next after that?

I had a very brief interlude at Union Carbide. Found out, you know, sometimes we make great choices and sometimes we don't, but that was a great career move for me. And then from there I went to Stanford Research Institute International in Menlo Park. Yeah. And I was hired in to be the research director for something called the for the International Information Integrity Institute.

I think it's still around somewhere. Um, it was bought, I think, by PwC or KPMG several years ago to be their security, their premier security program. We had the top 75 cybersecurity executives in the world who met 3 times a year at locations all over the world and for 4 days to talk about emerging trends, and I was their research director. Wow, so pretty awesome exposure. Unbelievable.

And I got to hear— but I got to hear what they were doing, and I got to hear what their issues were. So they were all freaking out about macros in Excel. Well, it was— by then we had the internet. The internet was like— the power of the internet was really really being understood. And everybody was talking about things like EDI, how to do electronic data interchange, how to do commerce, what to do with the environment that we assumed was always going to be in a secure bubble, and now it's connected to everything.

How do we control the connections to the internet? I mean, people were doing— people were constantly doing lines. They were calling the phone company, and you could get the phone company to install a line anywhere so that— in a commercial enterprise— so that people could have internet capability in their office. Yeah, controlling stuff like that. I mean, it was still the thing that we have to deal with now to some extent as we look at emerging technology and all the new things that are coming out, right?

Like self-driving cars and all the embedded embedded security-related stuff in IoT, everything. As we're trying to keep up with all that, it was the same kind of feeling. Like, what?

Oh, we need to do something about that. So you had the 75 top security leaders in the world, and you were all getting together with the Illuminati 3 times a year. And they're Gettys making the decisions that would rule us all. Any especially interesting anecdotes or stories you can tell out of that? We had one of our clients was Royal Dutch Shell out of the Netherlands.

And if you remember the Bosnian crisis, the Kosovo crisis. If you could summarize for those younger than me listening. So we had a war in the Balkan states and And it was the beginning of cyber— it was kind of the beginning of cyber warfare. And I don't remember any cyber element to this at all, so this is new to me. Yeah, they were launching, um, they were launching attacks against Royal Dutch Shell, and they were, you know, so people were like wondering, am I going to be a target?

So major, major companies who had a presence, were perceived to have a presence in the region, yeah, were starting to see the impact to their internal systems. And so they commissioned us to write a research report, and we called it hacktivism. Did you guys coin the phrase? We coined the phrase hacktivism. Well done, it's a good one.

And asked, is your company a target? And we tried to characterize for people, this is stuff you should be concerned about, and this is stuff you should not be concerned about. I mean, this is— we called website defacement basically was cow tipping. Yeah. And, um, one of the things that happened along that same timeline was the World Trade Organization riots in Seattle happened, and a number of groups were planning their, um, their criminal activity using the internet.

When we were doing our research, we found them and we were like monitoring them And they were monitoring us monitoring them, and we were monitoring them monitoring us monitoring them. We were watching the graphs and everything go back and forth. And we ended up incorporating some of that into the report, and then we gave a private report to all of our members. Well, later on, you know, later on it became evident that we knew something about the attacks before they really happened, and they turned out to be fairly serious. And the physical damage, the in downtown Seattle.

And so we got called on the carpet, like, when did you know and who did you tell? Yeah, all that kind of stuff. So was there— I assume— were there lessons that came out of that that you've taken with you? Did you guys do the right thing? Have you changed the way you would do it if you had to do it again?

I think ethics are always a huge huge piece of what we do. And at the time, my mentor was Don Parker at SRI, and he, he actually had some very, very good rules in place that's, that's said, you know, we could not engage in any way, for example, in social engineering. There was— we were not allowed to do anything that would be deceptive to another party. In order to gain a result. Yeah.

And, uh, you know, some other guidelines like that. So I think it helped keep us, um, from being tempted to go over, uh, over the boundaries. And there were no real boundaries, like there were no rules and there were no— at the time I don't think we had ISC² yet. I don't think we had, you know, these groups that were starting to create codes of practice. Yeah.

The, the, the I4 group was the one that started what eventually became ISO 27000, but that was called originally the Code of Practice. And, and so this was all a really— it was all frontier. Yeah, that's great. Yeah, it was fun. So you were, you were there for just a year or two, SRI?

I was at SRI. Well, SRI— so what happened at SRI was we, we had the I4, and we had the I4 until 2009. 2001. Okay. When we sold, when we sold it.

But it went through it, it went through an iteration when SRI created a startup company and they spun us out and they named us Atomic Tangerine. Okay. And what was that about? Um, it was during the days of, uh, well, some of these companies are still around, but like Razorfish, companies that were doing venture consulting. We started off actually not as a cybersecurity company, but as a venture consulting company.

So, um, SRI being kind of the heartbeat of the think tank in Silicon Valley, people would come to us with new ventures and we would, you know, we would advise them, consult with them, help them, you know, craft them into something that could be really successful. Now it looks like I see on the timeline '99 to 2001, you're doing that. '99 sounds like a great time to be doing that. 2001 sounds like a terrible time to be doing that. Well, 2000, yeah, and the bubble started really disintegrating, you know, in about 2000.

Yeah, exactly. And at that time, one of our investors was— they were Greek shipping tycoons, and we were on their yacht in the Greek islands. And I would never forget, our CFO is looking at his newspaper going, uh, we have to get back. It was just not a good time. Wow.

But, um, did the dot-com burst kind of also burst the Atomic Tangerine, or is that— you know, I see you, you looks like you stopped working there in 2001. Is that related? We sold it. Um, yeah, I actually got made the CEO of the company. Yeah.

Um, in order to get sold as a security pure play. Yeah. And that's— and so that's what I did for— who'd you end up selling to? Redleaf Ventures was the name of the company in Pittsburgh. Okay.

And then next stop, a big bank, huh? Well, yeah, I took— um, there was a little bit of a, a little bit of a family crisis in the middle. Okay. I stopped, uh, The— let's see, I sold the paper— I, I signed the papers to sell Atomic Tangerine on November 5th, and at the time my father was at home with us and he was on hospice. Yeah.

So he passed away 5 days later. And so we took some time, like, I was like, I don't know what I'm gonna do next. I did not make a place for myself in the new company. Yeah. On purpose.

Um, because of the things that were happening in my life. And so everybody that worked for me got a job. Yeah. And I saw— and I didn't. I didn't.

And because I didn't want one. And, um, and so then I was like, oh, what am I going to do now? And so I— on January 2nd, I sent out letters to all my contacts and I said, hey, I would love— I have my mom living with now. Circumstances have really changed. I would love it if I could work with some of you on a consulting basis.

And I got a reply back from Bank of America the next day, and I was hired by that afternoon. So you were part— I was doing a consult— employee. Oh, as an employee? Yeah. So you want to do consulting, but they— none of that?

She goes, actually, would you work for me? And I'm like, yeah, uh, are you serious? I said, I can't. You're in Charlotte, I'm in Puget Sound, I can't travel. Literally, I can't travel.

I've got full-time responsibility for my mother who had Alzheimer's at the time. So it looks like you started there as basically heading their security and business continuity for their investment banking. Is that right? I did. Yeah.

Global commercial investment bank, asset management, and treasury. Yeah. So I mean, that's a pretty big job to do remotely, you know, when you're looking for a little contract gig. I know. Yeah.

No, it was a great— it was amazing for me. Yeah. So what level of maturity did someone like Bank of America have back in the 2002 time frame? It was quite a while back. Very— they had a very well-established program.

Very, very, um, yeah, very— no, very mature. Um, business continuity for, for Bank of America— they were the ones who recovered Wall Street. If it was Bank of America, you know, Bony failed in the Bank of New York failed, and the— and they— so they couldn't clear any transactions from the trading floor anywhere. And Bank of America failed over to— failed over instantly to their trading floor in San Francisco, and they were able to handle the capacity of all of the trading operations. And, and, and, and so their, their, their team was— it was an honor and a privilege for me to be their leader.

I learned so much from the team that I had working for me there. And we had— so we did cybersecurity and business continuity for them. And yeah. So you— I mean, it looks like you don't ever work for little tiny companies. You were there for a year or so, and then you went to this little wireless company, AT&T, right?

Yeah. Yeah, well, I can't— I mean, the good news is in my career I, I always got recruited to the next thing. And Bank of America, what has gone through a, uh, they, they were consolidating. So if you were a certain band level, uh, in the organization, they wanted you in Charlotte. That wasn't going to be a possibility for me.

So, um, so I left Bank of America, but I went straight to AT&T Wireless. And you were the CISO there, it looks like. Yep, and VP of IT Risk Management. Yeah. Now I see, was it Cingular or AT&T?

I see both names on here because I know they bought them at some point. Right.

AT&T Wireless was— it's a very interesting story happened at AT&T Wireless, but they They were bought by Cingular about a year after I— well, a little more than a year after I got there. Okay, so you started off with AT&T and then you went and it became Cingular, right? And then somewhere along the road, didn't it become AT&T again? Yeah, it— yeah, somewhere after you left, I'm guessing. Yeah, yeah, AT&T— the big AT&T bought Cingular.

Yeah, Cingular was actually a joint venture between Southwest Bell and BellSouth. Okay. And then they sold it off to AT&T. Yeah, part of that was AT&T's intention to keep its brand, the blue Death Star brand. Yeah, yeah, that brand is valuable.

Sure it is. So that was, that was all part of that movement. If you notice, Cingular quit having the little, little spinny thing logo and went to the blue star, the blue Death Star. So you, you stayed up in the the Washington Puget Sound area throughout all this, right? You didn't relocate for any of these?

I relocated for Union Carbide and went to Houston. Okay. Houston for 4 years, and then I joined SRI. SRI had an office in Houston. Okay.

But then I— that's a terrible place to relocate to. You know, I've learned my lesson because I said at one point the one place I will never live is Houston. Sure enough, it's the only other place I ever lived. That's a pretty— that's a pretty Pretty good motto to have, I think. So then there's another big company up in the Seattle area, right, that you ended up finding your way over to.

Can you tell a story about getting over to Microsoft? Sure. After the Singular merger, our acquisition wanted us to relocate to— actually, I was supposed to start work in Bothell on Monday, fly to Atlanta for work Tuesday through Thursday and then fly back home. And I was like, I actually have another elder at home. So I had to make a choice to stay.

Yeah. That was— so, and so at the same time, I think in all that uncertainty about whether we were going to— during the acquisition, you never know know sometimes if you're actually going to go with a new company or you're not. And in that period of time, Microsoft recruited me to come on board. So you were the CISO for Microsoft? I was.

Yeah. And now, you weren't the first CISO for Microsoft, were you? I assumed that there was— No, there were several others, I think, before that. Yeah. And I was the last.

I was the last until Brett Arsenault. Yeah. And Brett has that title now. So 2005, 2006 timeframe. This is a little bit after they kind of famously took up the security cause, right?

Was that 2002, 2003 that they— Yeah, it was early. Yeah, around 2000 when Howard Schmidt was there. He was really the instigator of that. So I'd love to hear, were you doing product side stuff or all corporate security? My job was sort of thirds.

I was IT. I was responsible for all of the security of Microsoft's internal systems, and I was responsible for dogfooding their new releases of Windows. Sure. Um, and giving them feedback, product feedback. Okay.

And then, uh, another third of my job was to interface with all the, all the customers and talk to them about security and, and do the, you know, executive roundtables and that kind Yeah. So what was it like to work for Microsoft? They were, at that time, still the biggest folks out there in that 2005 timeframe. They were. And I was really— I have to say, I had a lot of friends who questioned me going there.

Feelings about Microsoft were mixed, right? Yeah, sure. Evil empire is sometimes thrown around. Evil empire was, yeah. And I really believed, based on what I could see that Microsoft had the potential for, that they honestly could have solved the security problem.

They really— I mean, end to end. Back then they had— they owned the whole experience. Yeah, they owned the network, they owned the endpoint, they owned the server. Yeah, they had— they had the browser, they had MSN, they had the internet property. Yeah, I mean, they had so much potential, yeah, to, to make something unbelievably good, and I was excited about that, really excited about that.

Um, 6 months into my job, my first and only meeting with— well, I had a meeting with Ray Ozzy when he wanted to bring in a, um, a peer-to-peer sharing product from his company. He was— he— that was acquired by Microsoft, and they wanted to integrate that with Office. Okay. Created a— blasted a gigantic security hole through, through everything. We had to go tell him that that wasn't going to be acceptable.

That wasn't a real easy meeting. And then, and then I had a meeting with Bill Gates, and it was my only one while I was there, which Craig Mundie and Bill Gates— was he still CEO at the time? Yeah. Okay. And he's sitting where you're sitting across the table from me.

I'm sitting here. Craig Mundie's right there. The head of product division for Windows Security is over here right next to us. And then behind me is every single product manager for the company because what I am there to tell him is, you made a promise to the world on the stage at RSA that you were going to provide single sign-on across Microsoft's platforms. And we're here to tell you that you're going to fail.

Wow. And the reason you're going to fail is the following things are not in place, and in order to turn the ship around, the following things have to change.

6 months into my job, that was— how did that meeting go? How did he take it? Well, I think I had an out-of-body experience in the time. I mean, I was like, I— it was very hard for me to have that I'm not proud of saying that, but you know, people have some of those moments that are so difficult. Yeah.

And I was a little bit terrified, to be honest. Yeah. I had a terrible case of stage fright. Even with all my performance background, it wasn't helping. Did he take it well?

Is he— I mean, I've obviously never sat at a table with Bill Gates, believe it or not. I really have a great deal of respect for him. Yeah. Way of expressing his disappointment is a little hard to hear. And I won't quote it because it's not repeatable, but it was to the room.

Like, what the heck is going on with all of you? And yeah, so— Did delivering that message impart the change that that you were hoping it would? I assume that it's not just about getting bad news, it's about fixing those problems, right? Right. I— their culture— I found the culture for me to be challenging at the time.

I think they've done a lot to change it since then. I want to, I want to believe that. Yeah. Um, I think that, um, I think that there was not the single— unless it was Bill— there wasn't a single person who was going to pull and, and make Office toe the line with Windows, right? There was two— they had a culture.

My experience with it was a culture of what I would call creative destruction. And it's not the best when you have to pull everybody together to get them all rowing in the— you know, I always use the metaphor. My people know that I use this metaphor about when you're in the boat, everybody's oars have to pull in the same direction or you don't go anywhere. And we couldn't make that happen. And it really wasn't up to me to make that happen.

But, um, yeah, there wasn't anybody that that was up to to make that happen. Well, that's part of the problem then, right? Right. Yeah. Yeah.

So you were there for a little over a year. Maybe talk about what was the, the impetus for moving on from there. Well, I think I had come from AT&T Wireless, where we had completed just the opposite. We had completed something that everybody thought was impossible in about 10 months' time. What was the impossible thing?

To make a long story short, when I came on board, there was an implementation of Siebel for their CRM system that they were trying to put in place. It failed dramatically. There was no CRM system during the entire Christmas sales season. And so we had this huge audit finding because the company lost $300 million in one calendar quarter. That's a lot of money.

A lot of money. And so they came back and said, look, you know, first of all, you're going to get sold now. That's new. And you have to demonstrate your compliance with Sarbanes-Oxley. Oxley, and you have 10 months to get it done.

Okay. My boss turned to me and he goes, I'm so glad you've got this. Can you take care of that for me? And we came back and we said, you know, look, now that we— now that we know how to spell SOX, now that we kind of have our arms around the principle of what it means, because nobody's done this before, it's a first-year accelerated filer, um, and that we found the terms and conditions of the sale of the company, $46 billion cash deal on the table, was that if we didn't— if we had any deficiencies in IT, the deal was off. So it was in the terms and conditions.

Yeah. And, um, I came back to him and I said, we have 10 months. Like, we don't have the time to try this once and see if it works and then do do it again. We have to do it exactly right the very first time. And he said, how are you going to do that?

And I said, I don't know yet. You're just gonna have to trust me. Yeah. And we did it. Well, that's awesome.

And, and the reason we did it though is because we were so clear. I mean, the— so the— what I learned about culture and what I learned about how to get a team to get something really difficult done um, like that, even though— I mean, it was monumental. And to, um, and then go to the— and go to an environment that was so hard to get something done. Yeah, that was— and for me, I guess, for me coming from where I've come from in the security field, that was like such a tragically missed opportunity. It was really hard for me to not take that, you know, to heart.

And, um, and so yeah, at one point I had an advisor mentor who just kind of looked at me and said, I want to know by next week when you're going to resign. Hmm. Because it was just, it was just, you couldn't accomplish what you wanted to accomplish. No. Yeah, yeah.

And it was, it was really tough lesson for me, and I think The reason I share this with people is because I think we all hit that moment where we feel like, oh my gosh, this is like the biggest public visible failure I've ever had. Like, I don't want to have a failure. What happens if I fail? Yeah. And I felt like that's what that was for me, because for me that was the pinnacle of my career.

That was where I was going to spend the next 10 years. Yeah. And, um, and I remember walking into my mentor's office and going Man, you know, this sucks. Like, I failed and it's visible. Like, there's no way this— it's in the papers.

There's like no way that this is not visible. And she goes, yeah, you're still standing. How about that? It taught me a really good lesson. Yeah.

And, uh, you know, it's, it's— I think we all have those to one degree or another in our career. And I think the main thing is to— there's a, there's a saying that really love is that the whole world is a very narrow bridge, and the most important thing is to not ever be afraid.

And so it took all the fear out of what I was going to— whatever I was going to do next. So what did you do next? April 2006, you're no longer the CISO for Microsoft. I partnered up with a friend of mine who is was an attorney who was passionate about data security, and we wrote a book on how to evaluate the e-discovery capabilities of law firms.

That's a turn, right? We sold it to every law library in the country, and then that was it. That's all the copies you can sell, yes. Unless you go make edition number 2, right? Second edition is— yeah, right.

And, uh, and then I, I did— I started doing consulting. And just on your own? Pretty much on my own. Yeah. And it worked out fine.

I still had, you know, over a period of time I had had family members who came into our home or that we were responsible for in some way. So that was still going on in my life, and, uh, it just worked out. It was a really nice blend. And I did that, I did that, I did ISO 27000 work. That was my— oh, you help people implement?

Yeah. And, um, and, uh, because I, and I'm a huge believer in that. Like, I, I just think it's the greatest thing. Well, it got born in the I4. That was the standard that actually we watched go all the way through, right?

So, um, Uh, um, at some point, oh, I got recruited again and I went back to work for Russell Investments as their CISO. Another, another big company that everyone's heard of. Russell 500, all that. Was that, was that in Chicago? Isn't that where they are?

No, Seattle. They're in Seattle. Moved them. Yeah, they moved them, uh, to, uh, to Seattle from Tacoma. They were— their headquarters was in Tacoma.

They know that. Yeah. Okay. Yeah, yeah, they were a major, a major player in Tacoma, obviously, and then they moved them up to Seattle. I think most importantly, I see that you served on the board for ISSA Puget Sound.

I did, for quite a while. Yeah, was that fun? Yeah, was it— is it a lively chapter up there? Yeah, the Puget Sound chapter, yeah, um, is an amazing chapter. Is it?

Yeah, it's a, it's a, it's a lively chapter. It has people from all over. There's You know, the number of universities up there with cybersecurity programs, University of Washington. So we had a lot of new people coming in. We had, of course, the Microsoft contingent.

And then the difficulty with it, I think that's really challenging for them, is that the Puget Sound chapter is divided by a lake. And it's really hard to get around. Traffic up there is absolutely abysmal. So you've got everybody on the east side of the lake, everybody in downtown Seattle. We did a demographic study one time of the chapter.

People were all the way up to the Canadian border, all the way down to Portland. We were, you know, we were the main chapter for— and all the way out to, all the way out to the ocean, yeah, to Forks, yeah, you know, and then to the Cascade Mountains. That was the coverage for that chapter. It's a big chapter. Most of it was virtual.

Sure. Have you gotten involved with the best ISSA chapter here in Denver? Okay, good. Denver has, uh, has become a pretty good one. Did you guys look at in Puget Sound ever doing multiple meetings so you could be in, you know, the west and on the east side?

Yeah, splitting it up. Yeah, we tried, we, we tried, uh, no, we didn't do the multiple meeting thing. We did— we tried to do, um, different kinds of meetings. To, to let people in, right? Make it, make it more accessible.

But with so many people not even within driving distance, right? Just hard to do it. Yeah. Yeah. So that's a great segue to say, how in the heck did we get lucky enough to have you come here to Colorado?

Well, thank you very much for that. We're excited to be here. Um, we, we have family here. Yeah. And And we love Denver.

Yeah, love Denver. And you just moved here about a year ago, is that right? Yeah, 2017 timeframe. Yep. And what are you doing?

Are you working still, or what are you up to? We re— we kind of rebranded and relaunched the consulting company, so we're doing work for some large companies. Sure. Doing some consulting. They're still doing ISO-type consulting or different stuff now?

We won't call it that, but yeah, our tagline is to help companies demonstrate due diligence to a defensible standard of care. It comes from having been associated with my lawyer friend. But the idea that— and we learned this on AT&T, we demonstrated that this worked, which is if you do it right, it doesn't necessarily cost— it might cost a little bit more upfront, it's going to take huge amounts of cost out of IT in the long run. That's really what we want to help bring to companies. What's the right kind of companies that should reach out to you?

People who need what?

If they're mid-market, we really enjoy working with mid-market companies who are still trying to figure out how to get started and where they should prioritize. Okay, yeah, awesome. So, and if they're in Denver especially, we really like that. Keep you here local. Yeah, we would really prefer not to be keeping— we go out to the Bay Area quite a bit.

Sure. Yeah, there's a couple of questions I like to ask folks. I'm going to give you a little different, a little different spin on them. You know, I love to get advice for those who are looking to get into security. Sure.

You know, your perspective going back to really before security was a discipline. It's certainly a very immature discipline now, but it's pretty well-defined at this point.

You have this perspective to say things have changed quite a bit. Today, if someone's looking to get into security in 2018, what do they need to get good at first? What should the path look like? Well, it really helps to have, obviously, an understanding of computers. I mean, it's kind of tough to do it without some kind of background there.

But I like— I guess I prefer it when I hire people, and I've always had really great retention rates, I look for people who are crazy excited about learning something new.

If someone comes in— I mean, there's certain skills, there's certain things that I would really want to hire like an engineer for, right? You just need that. But if somebody wants to get started on it and they're, and they're like, they come in and they say, I'll do, I'll do whatever it takes to learn this, just give me something to do so I can get started, I can show them a path at how to do their career from there. Yeah, but they got to have the attitude that says, I'm willing to try new things and I'm willing to do something that might not be very interesting to with. Yeah.

So that's kind of the most— that's the thing I look for the most. And I think we need that now because there's just not enough people for all the openings that are out there. We've got to find a new way. You know, the idea that, well, you have to have 7 years of experience before we can hire you isn't going to work. So that's good advice for hiring managers, but what about that person who's just trying to get that first job?

Yeah, I will go— there's— get some technical background, right? Start with the computers, the networking. You have to have the basic understanding of this medium that we use for communicating and that people use for— Yeah, because you have to secure something. What are you securing? Securing a computer, securing a cloud, an application, a network, whatever it is, we need to know the underlying technology to secure it, right?

Yeah. It's so a basic understanding of that, and then find out if there's something that you, that you love and something that other people need. Yeah, then go there, right? Yeah, it's a good— the Venn diagram showing, you know, what you're passionate about, what people need. Yeah, yeah, yeah.

It doesn't help much if they don't intersect. Yeah, you know, that's— yeah, that's for sure. Yeah. So you obviously— the other question I like to ask is, you your advice for security leaders. You have obviously just this awesome breadth of large enterprise experience that very few people in the world have.

I don't know. It wouldn't surprise me if there's less than 10 people who have led security programs for as many large organizations as you have. What would you say, coming out of that, maybe something that's surprising that I don't expect you know, as a security leader, what have you learned? What would you do differently or not do because of what you've learned? I would learn to let go of the fear of failure.

I wish I had done that sooner. Is failure defined by a data breach? Is failure defined by— well, what is failure in this case? Well, that's a very interesting question.

Can I segue for just a quick second? Of course. I have a license plate on my car that I've had there for a long time. I put it on there when I was at Microsoft, and it commemorates my old boss at Microsoft. It says, no hacker.

Not because I'm against hackers, but because my performance standard, my measurement for the year was no hacks, no leaks. So I came in the next day and said, that's okay. We're all done now. We don't have to worry about that anymore. But, but I would take that personally, right?

If somebody said, here's the, here's the parameters, here's what your goal and your standard is, I would say, all right, I take that up. You know, that's— I'm not gonna fail. I'm gonna make that zero deficiency audit. Yeah, right. And, and I would take— and I, and I think almost worked it sometimes too hard to to, to try to— to strive for perfection there.

Yeah, I would, I would say, well, maybe it was, maybe some people would look at it that way. I would say that was the, that was the goal, and I'm gonna deliver that. Yeah, I'll do whatever it takes to deliver that. But it's, it's one thing to say I'm gonna— I'll do whatever it takes to deliver that. It's another thing to say I'm tying that to my personal, you know, sense of my own self.

Source of value and like your identity being tied up in that. Yeah, I think I needed to learn to decouple that sooner. And, and I, and I think there's probably a lot more people that are real— maybe they're a lot more healthy about it than me. I'm being very transparent about it. But, um, and I— because I don't think I lacked the confidence, you know.

That's the other thing I would say is like, man, confidence is so important, especially for women, to like, uh, I, I want to tell women especially, but everybody in this field, it's like when you go into the room and somebody says we've got a problem to solve, it's like, give me the ball, I'll take it. Like at AT&T Wireless, one of the things we had to solve was identity management. It was unbelievably complicated. We had 36 different identity management systems and 4 systems of record. Yeah, you could have just used Ping Identity to solve that.

And then I— had you been around, I would have, you know. But so we had to come up with a solution for that, right? But in order for that to happen, one person had to own it. And in some ways, in our role, sometimes it means caring enough about getting the job done to not care if you get fired. Hmm.

Like, be willing to stand up and say, I'm gonna take that ball, I'm gonna deliver it. Yeah. But in the meantime, I know full well I have just stretched my neck out on the chopping block, right? And, and it could go off at any moment, right? So that's— but that's okay with me.

Do the right thing because it's the right thing. Thing. Do the right thing because it's the right thing. Yeah, I love it. Yeah, that's great.

Wow, we have an hour fly by. I mean, we could keep going for, for a long time. I want to give you the chance. Is there anything you wanted to talk about that I didn't ask you about? Um, I, I— we did a project, we've done a project, this is based on my experience both as, um, in, in the work that I've done on people side, which is a fair amount of work that I've done there.

I had 2,000 hours of clinical supervised training, um, and my technical background and experience as a leader in this industry, because I'm really disturbed by the drop-off. I don't know if you know this, but women have dropped off from computing occupations by some dramatic amount, right, since the year I got my degree, it's dropped from 35% to 23% of the workforce. It's like 11% of security practitioners is women, right? And so, and so that might— the career for me was the best combination possible of creative and technical. And I— and if somebody wants that, I want them to have that.

So we created a program to train, train people in skills, not the technical skills, because women have got extremely good technical chops already. But this is— and eventually this is for everybody— but it's those skills that we don't get taught that help people motor through the— that experience of having to stick your neck out on the block, you know, and say, give me the ball, and know that you've got the confidence to do it. That's what we teach people. That's awesome. So how do you teach this?

We have an intensive. We've got— we have a 2-day intent. What we did was we created a bunch of online modules, but we teach this in a 2-day intensive, and then we have group coaching calls, live coaching calls once a week. Yeah, we have a private Facebook group, and then we have these online modules that people can have access to anytime they want to, to refresh their skill set. Where should people go to look this up?

It's on our website, is the easiest place, karenwarstel.com. Okay, I'll put it in the show notes too. Yeah, I can send you the link. Awesome. There's a training site too that they can go look at and try to kick the tires on the class.

Well, Karen, this has been a real pleasure getting to hear how you've gone through a really impressive impressive career, and we're so glad that you're here in Colorado with us. Hopefully we can get you up talking in front of the ISSA or ISACA or OWASP or one of those other groups and get to know the community even better. Oh, thanks. Thanks. We're really so delighted to be here, and we just love the security community here.

Awesome. Well, thanks again. Thank you.

Learn more about the Colorado security scene at colorado-security.org. Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes