All episodes

Sam Masiello, CISO at Gates Corp

Apple Podcasts Spotify SoundCloud

In this episode:

Sam Masiello, CISO at Gates Corporation is our feature interview this week. News from: Archery Games Denver, Colorado Space and Air Port, Ting, Xero, ProtectWise, Optiv, Red Canary, Ping Identity and a lot more!

Rocket Man in Colorado

What would really make Colorado perfect? Archery Games and, yeah... a spaceport. Let's do it. Centennial gets gig fiber (but not Robb's house).  The atomic clock counts down. Xero grows its Denver presence even more. ProtectWise is AWS competent. Blogs from Optiv, Red Canary and Ping. 

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12145 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 81 for the week of August 27th. Alex, how are you doing?

I am wonderful. How are you, Robb? I can't, I can't complain at all. We are coming to the end of the summer though. It's the weather's cooling off and Kids are back in school.

Yeah, but you know what? It's supposed to be hot again next week. I thought we were going to be in fall already, and now I'm going to be all hot and sweaty. And yeah, we've had some up and down on it, right? But snow could be, could be coming soon.

I did see on the news that there is some snow on the mountains out near Aspen. Hey, Alex, we have some really exciting news stories to talk through this week. We do. I'm super excited. But let's start with some housekeeping.

Let me start off with letting you know that we have a Slack channel. And do you, do you know what Slack is? It's a little bit like an IRC channel except more GUI-based. Yes, it is exactly like IRC except not IRC. And if you want to get an invitation, you can go out to colorado-security.com and click on the Slack channel button.

That'll give you the link to join. Also on colorado-security.com is a link to join our mailing list. If you would like our show notes emailed to you every week, uh, then you go ahead and sign up there and we will get those out to you. And if you listen to this show every week by like manually clicking on it and downloading it, you're not, you're not really doing that, taking the best advantage of the technology that exists. That's true.

You can subscribe to the show. It will be automatically delivered to your favorite podcast client. And of course, if you, uh, if you like it, we'd love it if you'd review us and say nice things about us. And maybe that'll get other folks to come listen to us. Also, if you like us a whole lot, you could sign up to be part of our Patreon campaign.

That is a campaign that we're using to help raise some money to cover the costs for the show. You can sign up there at certain levels. We will give you things like shoutouts on the show and t-shirts. This week we don't have anybody to shout out. So if you go and sign up, then we'll be able to do that for you next week.

All right, let's go ahead and jump into the stories. Number 1, there is a new archery games activity. I'm going to call it an archery games center in Arvada. So is this like shooting apples off of people's heads? Robb is It's, it's actually more like playing dodgeball but with a bow and arrow.

So, so, wow. Do you know anybody that's done this? So, you know, I do these team building events when my team comes into town and we were searching the area to find an activity to do this week and we just did archery, archery tag, archery games on Friday and it was a blast. We had a really good time up in Arvada and I recommend folks take a look at the link in the show notes if you're interested in going and, and go sign up. Good clean fun.

No injuries. Good clean fun. They just opened this week. Nice, nice folks doing the business there and recommend folks do that for team building events or just with your friends. Awesome.

Next, there is some big news this week. There is a spaceport that got a license in Colorado. So what was formerly known as Jeffco Airport and then known as Front Range Airport is now going to be known as the Colorado Spaceport. Colorado Space and Airport, I believe, is the official name of it. Sorry.

So does this mean that I'm going to be able to go there and watch the big takeoffs like you can do at Cape Canaveral? I think what it means is as soon as they got the license, you could immediately go there to get to space. That sounds pretty good. No, actually, it is not the big rockets like you would think of at Cape Canaveral. It is some of the other— I'll call them smaller— the horizontal— it's horizontal takeoffs.

And those— that's the kind of plan that's scheduled for like Richard Branson's Virgin Orbit and Paul Allen's Stratolaunch venture. And the first missions are scheduled for about 5 years from now. So get your tickets now. Put me on the list. Let's do it.

All right. Next, this one hits close to home for me. Ting is a kind of standalone broadband fiber company that's coming to Colorado, and they've started rolling out fiber throughout Centennial, Colorado, which is where I live. Wow. So Robb, do you have gigabit fiber in your home now?

Not yet. I was one of the very first people to sign up and say, get— bring it to me. But they're doing neighborhood by neighborhood lighting everything up. It's going to take years before they get here. And it looked like Centennial gave them a little bit of money to help roll this out within the community.

Um, it seems like for gigabit speed it was about $90 a month, so it seems reasonable if you live in Centennial. Maybe you'll get lucky and get that in your neighborhood. Yeah. Now it may very well be that you're already in space by the time They light up your neighborhood. But I think it's probably still worth doing.

Do they have fiber to the space? Is that a thing? I haven't heard yet. We'll find out maybe soon. Next, there's sort of a sad story that time may be running out on the atomic clock that is in Boulder and then the radio station that broadcasts that atomic clock signal out of Fort Collins.

Yeah. So if you have one of those clocks that automatically synchronizes time, kind of magically seeming, that's actually at risk right now due to some NIST— it was NIST, right? Some NIST budget cuts in 2019. It looks like they may not have the money to keep all of these different stations open, including the one here in town. Yeah, it looked like the Trump administration asked NIST to cut their budget about 36%.

And one of the things that they wanted to cut was this radio station. And it kind of makes me sad looking at the article. The 100th anniversary of that radio station would be in 2019. Yeah. Well, now, all that said, as much as this sounds a little disappointing, there are other solutions now that you can use for this GPS and other technologies that can be used.

But if you have a clock that only works on this radio frequency, you're probably out of luck. It's a scam. They're just trying to get you to buy new clocks. It's like when they, when they went to digital television, right, from analog, and all of a sudden everyone's got to go buy— sorry, you either got to buy a box or you got to buy a brand new TV. Yeah, it's a rough— you're screwed.

All right, let's move along. Uh, Xero, the, uh, the online, uh, kind of, kind of Quicken competitor, the, the bookkeeping, uh, solution that's really been hiring heavily in Denver, is increasing their Denver, uh, workforce once again. They're gonna have about 300 folks in Denver, and they're moving their headquarters up to downtown from the DTC where they've been. Yeah, so they had been Uh, well, I think they were originally based, um, overseas and then they moved here. Um, and now they're moving from the tech center downtown down to, I think, 16th and Platt.

Uh, so cool building down there. So their head— their primary headquarters is in New Zealand. They had their US headquarters in San Francisco. They moved that to Denver last year and we talked about it on the show and now they're moving from the DTC up to downtown Denver to be, to be where all the cool kids are. And they have about 140 people in the Denver office now, going to, as Robb said, 300.

So that's a pretty big increase. It's over 100% increase. Wow, that is insane. Uh, next, uh, ProtectWise, they announced this week that they achieved AWS Security Competency. Does this mean that they were incompetent previously?

So, um, AWS might want to change the name of that award. Um, I guess there's probably like extra competency or supreme competency or, you know, uh, anyway, the, uh, yeah, it does make you think like they were incompetent before and now they're competent. But we know the folks over at ProtectWise. I'm sure they were not incompetent previously. They are very technically astute folks.

It's just kind of a funny name for that designation. Basically, this is just a certification for ProtectWise with AWS saying that they are good with doing security on AWS. Yeah, and of course this is a really important thing for ProtectWise as they've, you know, kind of come into the traffic monitoring world right as the on-prem world is moving into the cloud. So they're making this transition along with it, and it's going to be an important part of their future. So I'm really glad to see the investment they're making there and the success they're having.

Next, we have a blog post from Red Canary about what makes— the question is, what makes an effective security architecture? And here's a hint, the answer is not We need more products. What? We don't need more products? I always like more products.

Gotta, you know, keep my hair all slicked back with all those different products. The vendors just love you. Um, basically the blog is talking about 5 different areas of the sort of security architecture blueprint that they have: security awareness and policy enforcement, vulnerability and log management, privileged account management, content filtering and perimeter prevention, as well as endpoint threat detection response. And I'd say, you know, for 2 or 3 of those, you don't actually need a technology at all, right? It's just good practices, good enforcement across your organization.

Understand where you do need good technologies and go from there. Next, Optiv and Momentum Cyber issued a white paper on 5 trends and technologies that will help relieve the cybersecurity skills shortage. So do you know who Momentum Cyber is? I actually do not. So they are an advisory firm that gives guidance to security companies.

So obviously, you know, working with Optiv who sells products for most of the security companies. They have a good view of the industry. And the 5 things that they came up with to help us with the gigantic skills shortage that we have are machine learning, platform consolidation, security integration, automation and orchestration, and continuous security validation. Yeah, the, the platform consolidation and security integration are awfully similar to me. Um, I think basically it's just trying to move away from point point solutions for these things, right?

I would say even the automation and orchestration kind of falls in the same bucket there. So, um, I think that it's, it's pretty decent. Yeah. All right, let's go ahead and, uh, move along here. Next, I think we have a series of articles from Ping this week.

Um, I'll, I'll group a few of them together and I'll let you take the token binding one. Um, so we have, uh, a press release here about Ping publishing some findings from their CISO Advisory Group. One of the neatest things I've got to do as the CISO over at Ping is reach out to our customers and start Ping's CISO Advisory Council where we get together. And earlier this year we met off in San Diego and really started working through some tough industry questions. What are the things that we need to do to get better and what are the trends that are coming down the pike?

So some of the stuff is going to go into the Ping roadmap for our products, but 2 of the things ended up turning into white papers that we're sharing here. First, what are 7 identity trends that you should be monitoring now? And this is where identity is going to be going and how IAM professionals and security professionals can be prepared for it. And the second one is 8 things that every C-level exec should know about identity. So the intention is here, you know, we have the one with the one for identity folks really helping them prepare for the future, and the other is for folks to take back to their office to say, hey guys, this is how we need to rethink how we're using identity.

And it's, it's for those folks who are outside of the security and identity worlds. Both worth taking a look at. Free white papers. You don't even have to give your information to download the white paper. Just click the link and you can get it and see if it's good.

Wait, what? I can get something for free without having a salesperson come and attack me, Robb? There will be no sales attached. Awesome. Yeah, you got it.

I love it. Uh, so there's another blog post by Ping talking about token binding. So I thought this one was actually pretty interesting. So, you know, there is this concept of tokens, whether it's, you know, OpenID or OAuth or other things like that. You know, the tokens are what essentially grant you access.

Bearer tokens. Bearer tokens. Yeah. But the problem is that those can be stolen. So if someone steals your token, then they can essentially impersonate you, get access to things that you have access to using these tokens.

The IETF just came out with a standard called token binding, which is sort of a novel way to get around this problem. Basically, the, the token is then bound to a specific TLS connection, and then that way someone can't steal the token because it is based on that particular TLS session. So seems pretty cool. The blog also talks about how it is just a standard now, and that for it to be useful, people actually have to implement this into browsers and other things. So Cool idea.

Hopefully it'll get implemented sometime soon. Yeah, they've, they've had— it's interestingly enough, they had Chrome as the ones leading the way for implementing it, and the Chrome team just decided that they're not gonna move forward with it right now. Microsoft is saying yes, and Firefox are both saying yes. So it'll be interesting to see if they can get the momentum to get this over the line and become a much more widely adopted thing. It would help all of our security on the web, and it's invisible.

It just works. It's a pretty good thing. Yeah, exactly. All right, so that is it for the news. Um, now it is time to jump over to the Slack message of the week.

Slack message of the week. We would like to thank Andre Gaeta, uh, who is our continual sponsor for the Slack message of the week. Very, very generous in helping sponsor this. Um, the Slack message for the week this week was a post by Eugene. Um, I don't actually know Eugene's last name, He posted a blog post by Jonathan Zadarsky on dealing with depression in technology.

It was a good blog post, and, you know, depression is a very serious matter, and it affects lots of people, not just in technology, but I think maybe more in technology because you're often isolated, right? And I think especially in security, you know, we, we spend so much of our time looking at the bad part of things, looking at problems, staring at the problems that don't get fixed. It's easy to, to, you know, get frustrated and that can turn into something more serious, I think, if you dwell on it too long. So it's an interesting thing worth reading. So thanks to Eugene for posting that.

We'll get Eugene hooked up with Andre to get his free Colorado Equals Security swag for his Slack message of the week. All right. Moving over to events, we mentioned the colorado-security.com website. Go ahead and head over there and go over to our calendar of events to see what's coming. We want to go a month out in the future on the 18th of September, there is the Ballard Spar Colorado Cybersecurity Symposium.

We hope you guys can join us there. We will be one of the sponsors and be a part of that show, and we'd love to see you there in person. Yeah, we should have more details on content and other things like that soon, but it would be great to have you all there. This is a morning event, 8 to noon kind of deal over at the Ballard Spar offices. So the first thing on the event calendar for this week is the Denver Splunk Meetup on the 27th.

On the 28th, the GDPR meetup is happening, and the focus here is single select search, the missing link to GDPR individual rights compliance. On the 31st, SecureSet is hosting one of their capture the flag events. SecureSet is also doing their Hacking 101 event on the 6th of September. There's a couple— a little bit of a gap there due to Labor Day. A new event that we have on here, Colorado Springs and the Chamber of Commerce down there are doing a first Friday cybersecurity event.

And this is a social and mixer, and they're doing that down there on the 7th of September. And that's in the morning as well. And from what I, what I remember, I think it's the morning. What I, what I heard from Sean Murray, who's the guy who's putting it together, is that it's, it's had a really good attendance in the past. I think it was about 50 or 70 folks, something like that.

And so you get to meet a lot of folks. Immediate correction, it is 4 to 6 PM, not in the morning. 4 to 6 in the morning. It's not as fun to have a mixer in the morning because, you know, then you're drunk all day.

And then last event here for this, this podcast is the CSA is doing a CCSK training on the 7th and 8th. And that is a 4-char— it's gonna cost money to do that training. Yes. As part of that, you do get a token to take the CCSK test. But yeah, it is a non-trivial cost.

All right, jumping over to jobs. Number one is a brand new job with Ping Identity. It's not even posted on the website as we record. Hopefully it'll be breaking news. Hopefully it'll be up on the site here in the next couple of days, but it is for a cloud security architect helping us with securing our, our IDaaS environments in both a SaaS and PaaS environment.

And if you have any interest, you can reach out to me directly and we'll talk about it. Cherwell, which is an ITSM software kind of like ServiceNow, is looking for a director of information security. NREL is hiring a junior information security officer, which is interesting since we, we know they just hired their CISO over there. So I'm guessing that she's looking for some help. Zoom is hiring a senior information security engineer.

Uh, we have Noodles and Company hiring an IT security and compliance manager. I'm guessing since, uh, in that industry, this is probably the person leading their program, might be the one in charge. Carbon Black is looking for a SOC manager up in Boulder. Ball Aerospace is hiring a software security engineer. It looks like Ball Aerospace is hiring for a lot of positions in security.

Several, it looks like, in security, but also just a lot in general. We have— we know Dan Collander, who's the— who's a CISO over there. And I've been twisting his arm to get on the show for, for a year. And he said yes just recently, but he's not on the show yet. Well, maybe he can talk about all the jobs he has.

Come on, Dan. Let's do it. Get with it. State of Colorado is looking for an IT security risk and compliance analyst. We have had Debbi Blyth on the show.

We have the CISO there. Yep. Janus Henderson is hiring a security analyst. Once again, CISO has been on the show. That's Joe McComb.

And RubinBrown is looking for a winter 2019 intern in their business advisory services. And business advisory services does include their cybersecurity services. So if you just finished your summer internship and you just didn't get enough, this is your opportunity. Let's go straight into the winter. All right.

Well, that is the end of our news this week, Alex. We do have a feature interview, which is our take 2 with Sam Masiello. Sam, last time we talked to him was the CISO at TeleTech, and he's now been the CISO over at Gates Corp for about a year. Awesome. I look forward to the interview.

All right. We'll talk to you soon. Thanks, Robb. Hi, this is Rich Schliep, the CISO for the Colorado Department of State. This is Colorado Eco Security for Colorado security professionals by Colorado security professionals.

All right, welcome to Colorado Equal Security. This is Robb Reck, and I am back for, for number 2, part 2, with Sam Masiello. Sam, first question is, how did you get these wonderful new digs that we're in right now? Well, you know, I certainly had nothing to do with that. It's a beautiful new office though.

So for those of us, those who don't know, we moved our office from where we were at about 15th and Wawata, so just south of Coors Field, about 5 blocks away to the new, I'll call it the new Optiv building. That's what most people call it because it has the big Optiv name on top. Although I guess if you ask the Optiv people, they'll say it's Optiv Tower, but during all the conversations that we had before the move, they were calling it Gates Tower, so I don't really know whose tower it is. Optiv's name is on top, so that's how most people recognize it. We have signage on our floors as well.

We're on the base stone at the bottom of the building where it says Gates Corporation, so I don't know. 6 of one, half dozen of the other, I guess. Well, I just, I just go where they tell me to show up every day. It is pretty cool to have a security company's name across the top of the newest skyscraper here in Denver. For sure.

That's pretty neat. So, so last time we talked, you were the CISO for TeleTech, and about a year ago, a little bit less than a year ago, you made the move over to Gates Corp. And I am looking forward to, you know, spending most of our time today talking about that. But I do think it's kind of fun, you know, I just spent a few minutes looking at like who the other tenants are in this building. And, you know, it's pretty big news to get a brand new skyscraper built in town. You guys take— I think you said 7 floors?

6 floors. 6 floors here in the building. And Optiv has a couple. Chipotle was supposed to have 5 or so. And, you know, those jerks have bailed on us and they're not sticking around in Denver.

So they're looking for new tenants for those floors. But a smattering of law firms and financial advisory folks who are filling up the rest of the building here. And you guys are just at 15th and Lawrence, or is that Arapahoe? Arapahoe. Arapahoe.

15th and Arapahoe. Yeah. So nice, nice location. Just a couple blocks from, from the Ping Building. Yeah.

And not far from where we were before. We only moved a few blocks down. So for folks who were already commuting to downtown, you know, the commute, it's about the same. For those of us who were— who take the light rail in, so it was super convenient in the old building because we were literally one block from Union Station. Yeah, now we're about 4 or 5 blocks away, but that's still really convenient.

So, you know, as a starting point, I think it'd be nice to talk to folks about what Gates is, who Gates is. For those of us who have been in Denver for a couple of decades, you know, Gates might be the one, the name that was on those factories over on 25 on the west side of the freeway for quite a while. It's not Gates buildings anymore. For those who are newer, maybe they don't know Gates at all. So high level, who is Gates and What do you guys do?

Yeah, so Gates has been around for 107 years, so we've been around for not too much less time than Colorado has been a state. It's been a staple company in Denver for quite a long time. We do primarily manufacturing, so belts and hoses. We have 2 primary business areas. I'll call it power transmission, which is mostly our belts business, and we have fluid power, which is mostly our hose and hydraulic business.

And Gates is in probably every product or many products that you own or use today, whether it be your car, whether it be your lawnmower, whether it be your household mixer that you have in your kitchen. There's Gates products, whether it's Gates belts or hoses, in pretty much everything, whether it's made by Gates specifically or it's OEM through another manufacturer, but it's actually a Gates product. Gates is pretty much everywhere. We keep the world moving, let's say, in a lot of different ways. But yeah, it's a company that's been around for a long time.

For the— you mentioned earlier the place that was over on I-25 and Broadway. In fact, when most people find out I work for Gates, it takes them a second to think about like what Gates is. They're like, oh, that's nice. And they realize, oh wait, that's the place that was over at I-25 and Broadway. Are you guys still over there?

And people don't realize that we actually got rid of that building a long time ago, but people used to go to that building, or that's how people remember Gates because I remember that building was there for so long. In fact, there's probably a good number of people who used to buy tires from that old building as well, because that's, that's how a lot of people get introduced to Gates from the consumer space, is that people would actually go to that building and buy tires. Where, you know, we're primarily a B2B company where we work with large automobile manufacturers, large auto part resellers, things like that. But people used to go to that building to buy tires. For their cars.

And so I've actually had some people ask me, hey, can I still go buy tires over at that building? Like, well, you couldn't, not for a long time. But, but that's how people remember the company. And they— and I hear stories all the time from people who have had family members and relatives and friends and such who have worked at Gates at some time in the past, just because it's been around for so long and it's been such a major employer here in Denver that, you know, people just— they recognize the name very easily. And if you go to Bandimere Speedway, there's a huge Gates banner there too.

So, you know, and I know I remember the building when I first got to Denver. I do believe the building was still being used when I got there, and then somewhere along the way it was not being used, and it kind of became like a pretty rundown looking building. And then now all of a sudden it's beautiful offices, right? So this revitalization of Denver has been pretty fun to see. So you made the move over here from Teletech, which is another one of the large employers in Denver, right?

And I'd love to hear from your perspective Why would you want to make that change from CISO to one big Denver company to another? I'll talk more about the Gates side of things, because from Gates' perspective, they've been around for a long time, as I mentioned, and they never had a full-time security leader before. There's a gentleman who was here before who was in charge of the network team, was trying to bolt security onto his role, but never really had a full-fledged, and he'll admit this too, so I'm not saying anything— Never had the mandate. Yeah, and he'd admit this as well. It's something that he's he stated to me is that he never really had the structure or the resources to start building a full-fledged program out.

When I found out this position was open, applied for it, and me and the CIO hit it off right away. We talked about philosophies, his own philosophy relative to building a security program or what he thinks it should look like from a high-level structure perspective. I gave him what my philosophy is, and he just said, yeah, that's exactly in alignment with what I think as well. So I gave him some more detail as to kind of how I'd still go about building the program and hit it off with him really well, hit it off with his team really well. I'll say it's been a great move overall.

The environment here is very supportive. I'll say that when I came here, there were people trying to incorporate security into what they were doing in different ways, but didn't necessarily know, like, is it best practice? Is that the right thing to do? Am I even doing something that's actually going to make us more secure? And so from that standpoint, it was good to be able to come in and at least come into an environment where the desire to do things the right way was very strong, not only within the people that were here, but also from a leadership and an executive perspective as well.

There's also a large drive from their standpoint because quite frankly, it's widely believed, and I agree with this as well, that manufacturing/critical infrastructure is something that we're gonna see more attacks in. Gates has a very strong interest in making sure that we're doing the right thing relative to securing the data that we're entrusted with, right? Because we don't have a lot of credit card data. We're not an e-commerce company. We do have a lot of intellectual property.

We have a lot of data that describes how we build our products, how the compounds are put together, how the hoses and the belts are assembled, and just all the pieces and parts that go into that. We also have plans from our partners. As to how they want us to build our belts and hoses that end up going into their products as well. So again, we don't have high-value data relative to things that the consumers would necessarily care about, but certainly for us and our partners who are very large organizations in their own right, we have to make sure we're protecting that information. And plus we're a multinational company, we're in many different countries across the globe, and so we have to be aware of things like GDPR and other rules and regulations that are coming out relative to privacy.

California recently signed a new law. Colorado recently signed a new law. And so we have to make sure we're staying up on all that stuff because at the end of the day, we're protecting not only our own employee data, but also again all that intellectual property. So let's back up to when you first got here, right? Yeah.

I think— am I correct in remembering when you got here there was no one in security at all, right? You were employee one? There was one other person. One other, okay. So My predecessor actually had 3 people on his team.

Okay, himself, another gentleman who ended up going to Optiv from here. Yeah, and then the person who was still here when I got here. Yep. So she's been great, actually. She, she's been with Gates/Tomkins, which is a parent company of Gates, before Blackstone came in.

So between those 2 companies, she's been with Gates for about 18 years. I'll say Gates even though she was with Tomkins and Gates for But she's been around a long time. Yeah, so she's been a great resource to me because she helped, you know, help me understand not only how the company works, but she knows where all the bodies are buried. She knows all the skeletons in the closet, right? So she knows all and has a lot of history as to why we've done certain things or not done certain things in the past, why things are built certain ways, why they're not built certain ways.

So it was me and her for the first 7 months that I was here. Okay, and then in April we hired another gentleman who's worked with me a couple times in the past as well. And last month we hired the person who's going to be leading our security operations center that we're starting to build out as well. So he's going to be based out of India. He's here for July and August to meet some people here, understand process and procedure of Gates, do a lot of knowledge transfer, start documenting some runbooks, things of that nature, so that at the end of this month, at the end of August, he's going to head back to India and he's going to start basically in run state for our security operations center.

We're also looking to hire out there somebody else around that time, so he'll have somebody to be able to mentor, hand off some of the runbook documentation to, and start building out the team and functionality there. So going back to day one when you started at Gates, you had some kind of HR orientation, you figured out where the bathrooms was. How did you go from brand new guy working on the team to starting to really get a plan in place? What did day 1 look like? Month 1?

I'll say first 30 days. To me, and I kind of laid this out to the CIO during the interview process, I said, look, to me, first thing you have to do is start establishing relationships in the company. There are certain relationships you need to make sure you have, that you solidify, that you have in pretty good working order. You have a good rapport with folks. Folks in the IT infrastructure team, the network team, any sort of application development teams that you have.

Legal will certainly be a strong partner as well, because you're going to work with them on contracts and employee investigations and whatever else you need to work with them on. I'm working with them now on some tool deployments, so they have a new compliance tool that they want to work with, and so I've been working with them on that as well. So to me, the first thing is to start establishing those relationships and make sure you know who they are, they know who you are, how you can help each other, how you can be of service to them. It's important to establish those relationships early, because if you don't establish them early and you don't have that strong rapport with those teams, Ultimately, you need them to execute, right? You need them to help you execute, and you need to make sure that they're doing things in a way that, as we were talking about earlier, there was a strong interest in understanding how to do things the right way, they just didn't know how to do it.

And so you need to have that strong partnership there so they understand what your expectations are and they understand when they need to come to you, what sort of questions they need to ask you to make sure that, because you can't, especially when you have a small team, you can't see everything all the time and you can't be in everything in all places at all times. Establishing those relationships and having them understand what the base rules are, what the baseline is as to when they need to be making sure that they're including you in those conversations, then they'll do it organically as opposed to you having to overhear things and stick your fingers in things as opposed to them coming to you organically. So that's a big part of it. Second from there is what do you need to do? Once you have the relationships built, what do you need to do within the organization?

Because every organization is different. As you walk in, as I said, Gates never had a full-time security leader before, so there's a lot of things we're building from the ground up, a lot of foundational things we're putting in place, a lot of process, a lot of procedure, a lot of standards development, a lot of policies that didn't exist before. Every company's different, right? You may walk into a company who's had somebody for a year or 2 who may have some of that stuff in place, or you may walk into a very greenfield environment where none of that's there. From a Gates perspective, Well, really anybody perspective, but what I typically do when I come into an organization is we do a full risk assessment of all the various security domains, right?

Whether it's policy, governance, encryption, endpoint protection, network protection, compliance, the list of like 30, 35 different domains that I generally like to look at. What do you use for your framework for the risk assessment? Mostly the CSF. So just to identify what are the domains we have to care about, ISO as well. The NIST Cybersecurity Framework for those?

Yes, sorry. Unfamiliar? Yes, I probably should have extrapolated that. But we also try to align it towards ISO as well, right? Because ISO certainly has policies and controls that you need to have in place to build a good program.

But when I look at the various security domains, I try to break it down into 2 functional parts, right? So you have, as I said, encryption, endpoint protection, all that stuff. And you look at it from 2 different dimensions. You look at it from one, what's the risk exposure to the company if that if that domain were to somehow get exploited. And you're gonna find that in most organizations there's not gonna be a whole lot of difference between what the risk exposure is, but it depends on the company, right?

E-commerce versus manufacturing, you'll find some variances here and there, but for the most part there's not gonna be a whole lot of variance between is this a high risk, is this a high risk exposure to the company versus low risk exposure to the company. Where things become really variant is in the maturity of those particular areas. So, do you have virtually no awareness of the fact that you should be encrypting sensitive data? Do you have no awareness of the fact that you should have antivirus on your endpoints versus do you have a fully fledged program where you have a next-gen endpoint protection tool on every single endpoint and server that's being fully monitored by a SOC, all the alerting mechanisms in place, right? So, as you look at the spectrum between, let's call it 1 through 5, where 1 is least mature and 5 is most mature, You can look at that sort of assessment and be able to organically be able to develop your roadmap relatively quickly.

You have your high-risk exposure areas, your lowest maturity areas, and say, all right, those are the things we need to work on first, because if they end up getting exploited, they could end up causing the most damage to the company. Then over time, you start building out your capabilities with your people. You start addressing those various areas of weakness, so you start building up maturity in. You start augmenting some tools on top of that, so you can start building upon the capabilities of your people. And building automation on top of that as well, so you can get more mature in those areas.

And then as you, say, move something from a 1 to a 2, or maybe from a 1 to a 2 or 3, you still have your other high-risk exposure areas that may have other low areas of maturity. And so you can just build your roadmap fairly organically by just constantly reassessing where you are relative to that risk assessment. So I think I heard you say you're looking at each kind of area of security through 2 lenses. One is, what's the impact if something bad happens here? The second one is, how mature is our controls in that area right now?

Exactly right. Okay, that's fairly technical in nature, I think, right? You can spend a lot of time on writing policies and putting governance in place, and you talk about the relationships, but you can also formalize relationships and getting IR testing These things that are important part of a security program structure versus actually kind of a technical, go do these things. How do you balance between those 2 areas? How did you determine which one you're going to focus on first, or how do you interweave them?

How do you think about that? Yeah, so I mean, from my standpoint, lay out the plan, work with your executive management. So I work with the CIO, I work with our CFO as well, who our CIO reports to. And kind of laid out the plan of this is how we're going to go about and attack these things. And it needs to be a collaborative discussion as well.

So these are the things that you're proposing that we move forward with, but from a business standpoint, are those things that the business cares about? So there needs to be another part of that discussion as well, is what's important to the business to make sure you're protecting versus what, based off of your risk assessment, do you feel is important to protect? So you have to end up having to put those 2 pieces together to really figure out what is your roadmap going to look like. Because to your point, you can't just focus on the technical details, even though they're looking to you to identify what are those technical details we need to work out. But if you're not necessarily focusing on the areas that's important to the business, then you're not focusing on the right things either.

So you may still need to make sure you're focusing on those areas of low maturity, but at the same time, you need to also make sure from a business standpoint you're focusing on the things that are important to them. Because if something happens to something that's important to the business and you weren't you didn't have your eye on that ball, then that's a pretty difficult one-way conversation.

It makes perfect sense that you come up with a roadmap and then you share that with the key stakeholders. I get that. What about feathering in, though, those things that are— I was thinking only a security leader really understands the importance of incident response. Training or having an IR team and having an IR plan that's been gone through. I think generally speaking, a business leader is going to say, go invest in making me more protected, not so much in getting really good at detection and response and recovery.

How do you balance that and coach your leadership through that process to think about where that should fit? Well, especially that's a great example because these days it's not a question of if you're going to get breached, but when you're going to get breached. So, it's not necessarily a difficult conversation relative to, at least from my perspective, being able to help make sure that the organization is prepared for when that happens. You need to have BCDR plans in place so you can prepare for when system outages occur. You need to have your RTOs and RPOs in place so you know how to recover from those things when they happen.

Well, there's a lot of analogies to be drawn between that and security incident response as well. Because when a security incident happens, you need to make sure people understand how they need to respond. Because if they don't necessarily know what the plan is or what the organizational process is to respond and when those people need to get involved, then what you end up happening is you have people running around like chickens with their heads cut off, everyone trying to do something that is potentially useful, right? They're just trying to help solve the problem, right? Nobody's trying to be destructive.

They're trying to help solve the problem and help try to figure out what's going on and what's wrong. But if people don't necessarily know their role and understand when they need to be getting involved and when they need to be getting engaged and how they need to be getting engaged and who's supposed to engage them, then your plan kind of falls apart relatively quickly, right? You end up having— I had a situation before at another company where there was a proposed, alleged— what's the word I'm looking for? There was a possibility that something may have been breached. And nothing was confirmed at that point.

Research had just barely even started into what the incident was, and somebody else who had heard of the investigation that was going on decided to go tell a data protection authority that there had been a compromise, even though there was no evidence of the fact that actually took place. And so then we had DPAs crawling up our backsides asking for information. And data protection authority is one of the governmental folks in Europe who is responsible for implementing GDPR and other privacy requirements over there, right? Yep, yep, and this was well before GDPR, but still, we had them crawling up our backside on a regular basis asking for information, asking for evidence, asking for all sorts of stuff that we just didn't have yet because there was nothing confirmed that anything actually happened. And we brought a forensics firm in and had them do an investigation, and they could never find anything that actually happened.

So, I mean, it ended up being much to do about nothing. But anyway, kind of circling back, right?

By being able to— what's the word I'm looking for— describe, or yeah, describe, I guess, what the purpose is behind some of these things that you're doing outside of the technical realm, it helps build the business cases to why you need to be doing it, right? Because nobody questions the need to be able to make sure that we have backups of data and of sites when something may go awry or something may go down. Same thing from my perspective is in place from an incident response perspective, where if you don't necessarily know how you're going to respond to a security incident, then how are people going to know what to do? How are people going to know what to do when a system goes down? How are people going to know what to do when you have an incident occur?

I'd love to get as much detail as you're willing to share about what that initial plan turned into, maybe for 2018 objectives and goals for you and your team. What's the punch list of work to get through in your first real full year? I assume you spent most of 2017 kind of figuring out what the plan was going to be and kind of getting to the work in 2018. How much are you willing to share about what you're actually focusing on this year? Yeah, so I'll speak fairly high level about it.

As I mentioned earlier, we're really building a lot of capabilities here in the beginning, so a lot of foundational stuff around just basic capabilities and monitoring. There really wasn't much visibility into what was happening into the network. Wasn't a lot of controls in place as to how we were segregating systems and data and information. Wasn't a lot of visibility into where people were going on the network, where people were logging in from. We've got a lot of those holes fixed at this point.

We put a fair amount of investment into having tools in place that allow us to start getting more of that visibility. Every day we're working with the infrastructure teams to be plugging more and more of our systems into those tools so we can start doing some more data correlation. That's part of the reason why we started building out the SOC now as well, 8 months in, 10 months in, as opposed to earlier, because we didn't really have the maturity yet from a tools perspective to be able to have something to give to them so they can actually have something to monitor. Looking at some of the tools we had in place, rationalizing a lot of the tools we had in place. When I came in, there were a few things that we had purchased prior to my arrival that, quite frankly, the business wasn't ready for, we weren't getting any value out of.

And so a lot of it was rationalizing what we had versus what we needed and not paying for the things anymore that we didn't need. So we actually were able to use some of the money that we got back from those things we weren't paying for anymore to start funding some other things. Because when I started, around the end of September was pretty much around the end of the budget cycle. So there was, you know, my budget was fairly well locked in at that point. So we had that.

And you're so new, you don't really know what you need to spend anyway, right? That's right. That's right.

From that standpoint though, there was still limited flexibility as to what we could actually accomplish this year. So we had to end up using some of the money we got back to fund some of our other initiatives for this year. Also, in addition to getting rid of the things that we don't need anymore that we purchased previously, it's also looking at what we had to make sure that we had licensed appropriately for the tools we wanted to keep. So for the things that we had in place already, do we have a big enough sim, for example? Well, if not, then let's go purchase a larger infrastructure for our sim.

Do we have enough AV licenses for some of the products that we have? Do we have more? So making sure we're properly licensed for the tools we want to keep. There was a— I'll use another example. So like NextGen AV, for example.

We have, being a manufacturing company, we have some fairly old legacy infrastructure that's around. And so we purchased one of the NextGen AV products to help protect us on those systems. Because there were systems that couldn't be patched anymore by Microsoft. So original use case for that AV product was specifically against those systems. But as we have started to deplete those number of systems in the environment and upgrade them into either virtual environments with new operating systems or upgrade the operating systems that's sitting on those machines, what we've done is repurposed that AV product to instead of just solving that one use case for those end-of-life operating systems, Now we're deploying it out to the rest of the server environment as well and not having to pay any more for it because we already had the licenses before.

Now we're just better using licenses that we had. So anyway, go back to your question. A lot of this year has been around visibility, rationalization of tools, operationalizing the tools that we have that we're keeping, and starting to build some more capabilities around them so that we can, for example, utilize the SOC to be able to start getting us some better intelligence and more data around what's happening in the environment. That, you know, figuring out what the environment looked like and putting together a plan was chapter 1, and then chapter 2 is 2018, what you're doing with getting the visibility and maturing some processes. That's chapter 2.

So what's chapter 3 gonna look like? 2019, what do you see as your next hill to climb? Yeah, so I think chapter 3 is going to be a bit of a continuation of chapter 2. There's still a lot of things we're trying to build out here that, you know, quite frankly, we just a small team, there's only so much you can accomplish. You know, we're growing relatively quickly.

As I mentioned, we had 2 at the start of the year. Maybe I shouldn't say relatively quickly. We had 2 at the start of the year. By the end of the year, we'll probably have 5 or 6. So I mean, that's, you know, from a percentage standpoint, that's, that's pretty significant, and it's getting us some additional capabilities.

But, you know, since we're starting from more or less zero, there's still a lot of things we have to get done in 2019 that are just continuation of 2018. But as I start looking at that, right, it's how do we start improving upon what we built upon in 2018. So in addition to more capabilities, things around, say, mobile mobility management— I'm sorry, enterprise mobility management, right? So taking a look at the data that people have on their phones. Here we have a mixture of corporate devices as well as personal devices.

So how do we gain some more management around the data, the Gates data that's going on those devices? And how do we ensure that, let's say, if somebody leaves the company or loses a phone, how do we ensure that the data that belongs to Gates is no longer on that device? So not just preventing authentication so that you can't download any more information, but how do you tie that data to a profile such that when you leave the company or lose your phone, that I can just wipe that data completely and it's no longer there. So things like that, things we're thinking about for next year, but really it's going to be a lot of continuation of what we're building this year and starting to get more visibility and tack more tools into the tools we already have and start building some automation on top of it as well, so that as we continue building out the SOC, we have the ability to give them additional capabilities through automation and have them be able to respond more to alerts and be able to triage alerts that happen, as opposed to trying to build a lot of those rules from the ground up. Yeah.

So when you, you talk about automation, is automation one of the things you're looking to hire for, you know, scripting skills, or is that something that you guys are all learning as you go? How do you think of automation? I wouldn't say at this point we're looking to hire for people that have automation skills. Now that said, you know, if people have scripting abilities, that certainly will help make your job easier. Yeah, but I'm certainly not making it a qualification as what we're looking for at this point.

Yeah, but as we continue to grow out the team and as we continue to want to grow out additional capabilities on top of the tools that we have, at this point the primary goal is just to start operationalizing what we have, and then from there we can start building on additional capabilities around scripting and automation that that we didn't have before. So I'd imagine as we continue to grow out the team, having that sort of skill set will be something that we'll desire more, but it's not necessarily something I require of the people that are coming on the team today. So when you look at folks you want to hire over the next, you know, 6 to 18 months, you know, as you fill out this team, what are the core skill sets or personality attributes or whatever it is you're going to be looking for in those next team Yeah. So I think as we start to build out capabilities, so I generally break down security into 4 fundamental buckets: security operations, GRC, which is governance, risk, and compliance, threat and vulnerability management, and security awareness and education. Now, you can combine some of those legs together, right?

You can put training and awareness under security operations. You can mix and match them. But as I think about kind of the 4 legs of the stool, that's generally how I try to build things out. Now, that said, typically when you're first starting to build out your team, you're focusing mostly on security operations, how to keep the lights on every day, how to start integrating more into the business, working with the infrastructure teams, that sort of thing. And then as you continue to grow out capabilities and start building into things like, let's make sure that we are actually patching our systems, well, that's how you start building out your threat and vulnerability management program.

It'd be nice ideally if you had a leader over each one of those functions, you can kind of have those functions run independently. But what ends up happening, especially with smaller teams, is that you end up kind of doing them all in kind of a mishmash, just in various pieces and parts of your day. So as I think about next year, one of the things that I want to start building out is more of a GRC program. So as we start thinking more about ensuring compliance with GDPR, right, which we're working on, and other areas that we're potentially going to get into from a business standpoint that I can't share at the moment, there's going to be a greater need for having someone who's more at the head of our compliance program, someone who's focusing more on making sure that we are compliant with the controls, making sure that we have the documentation we need to have, making sure we have the segmentation we need to have. It's just not going to be possible, I don't think, with just the people that we have doing mostly SecOps work to try to absorb all of that as well, to have somebody who's actually focused on ensuring from an InfoSec perspective that we're following all the right controls from that standpoint.

As part of that also, doing more risk assessments internally. So as we start getting more visibility into our network and systems, how are we doing relative to improving the environment? Or as we start bringing on new systems, how are we ensuring that those systems are up to our standard from a security standpoint? Right now we're doing that mostly as part of SecOps, but I'd like to have a function that focuses more on new vendor acquisition, new tool acquisition, Third-party cyber risk management, right? So how do we start folding more of a vendor assessment capability into a formal GRC function as opposed to just kind of being part of what we do today?

So I feel like today, you know, we're trying to— we're performing all the actions of that 4-legged stool as part of one SecOps group, which allows us to do a little bit of a lot of things. But as we start growing out the maturity of the program and we need to start doing more things in a more dedicated fashion and be able to move the ball a little bit faster in certain areas. As I think about the next step, GRC is the next thing I want to start building out, and then threat and vulnerability management as well. So I don't necessarily look at a full red team/blue team, but at least starting to get more visibility into the vulnerabilities that exist on the network so we can make sure that as we're identifying those, we have a process in place with our infrastructure teams and our network teams and operations teams to ensure that those systems are getting patched on a regular basis. So making patching more part of the culture and operational tasks of what the infrastructure teams are doing, as opposed to it being more of a break-fix type methodology where we scan and they fix.

It should be they patch, we scan to validate that they're actually performing the operational tasks they're supposed to be doing, where today it's kind of the other way around.

Talk about candidates who would be applying with you. What skills— you talked about GRC, and I get it, but, you know, someone's listening now, they're like, hey, I want to be, I want to be part of the Gates team, and maybe they don't have experience on any of those areas yet. What, what would you like them to go out and learn so when they come talk to you, they're an interesting candidate? Mm-hmm. So quite honestly, I generally try to think outside the box a little bit when it comes to hiring.

When it comes to certain skill sets, obviously, from my perspective, security is more a mindset than anything else. Not to say that experience isn't important. I'm certainly not trying to put it that way, but some of the most successful people that I've hired in security operations roles, so I'll get back to your question in a second, but some of the people that I've been most successful that I've hired in security operations type roles or in SOC type roles have been people that never even came from a security or technical background. One of the most successful people that I had in a previous role was a waitress at Perkins for 9 years before I ended up bringing her onto my team, just because she had the right— she had the mindset, she had the desire to learn, and she became a great security analyst. But as you start moving into— that's great for entry-level type functions, right?

But as you start getting into more advanced functions of security— How do you identify that candidate during an interview? What do you mean? Well, I mean the Perkins waitress. Yeah. You know, how can you tell that that particular candidate has the right mindset, you know, has the, has the right stuff?

Yeah. Without having any experience in the background, that that's the one. Yeah, it was a, it was a bit of a leap of faith, leap of faith to some degree, but at the same time you try to dig into their analytical skills. Whereas for what I was hiring for, that particular position was more of a security operations center type role. There's gonna be a lot of data analytics, a lot of It was at an anti-spam company, and so there's a lot of finding a needle in the haystack, right?

Identifying patterns in emails that were being reported to us by our customers, and so how do you identify the things that are unique to those particular types of messages that you wouldn't find necessarily in something legitimate? So it was, like I said, it was more of a mindset thing than anything else, more of a data analytic skill, more of a how do I How do I learn, I guess, how do I learn good behavior from bad behavior and how do I identify the bad behavior in potentially a very difficult dataset?

Again, that was a leap of faith in some ways, but as you kind of meet somebody and you kind of suss some of their skills out through an interview, you get an idea as to whether or not you think that they have that skill set or not. And of course you can give them some samples and say, you know what, What about this doesn't look right to you? But for somebody who's been a waitress for 9 years, they're not going to know necessarily how to analyze email headers and things like that. But nevertheless, from my standpoint, a lot of the things that I'm looking for now for people who don't necessarily have a lot of experience, it's that desire to learn. Because security to me in a lot of ways comes down to common sense.

There's a lot of things you can learn, but there's a lot of things that just come down to common sense. And if you understand or can learn some of the technical aspects of it, And I think you can be successful. It's just a matter of how you go about that learning, how you go about that learning process, and how you go about obtaining new knowledge and also having the desire to learn more, right? Not just the skills of what you learn on the job every day, but what else are you doing outside of the job to keep sharpening the saw, if you will? Are you involved in the local security groups?

Are you going to OWASP meetings? Are you going to ISSA? Not that I necessarily require that for somebody, but at the same time it shows the desire to learn and become better as opposed to just thinking you're going to go out getting all your training on the job. Yeah, I think that going above and beyond in your personal life is such a critical indicator, right? If this person— is the person going to be passionate about the work?

Are they getting involved with an open source community and like helping some of these projects? OWASP has a lot of projects you can get involved with, right? That kind of work, it can be that what shows that you're, you're the passionate one and you want to learn and and move into new things. I think that's great. What does the future look like for Sam Masiello here at Gates?

Looking a couple years into the future, we're running short on time here, so I'd love to hear you summarize for me where you think this is going. As I said earlier, it's a great environment here. A lot of support from executive leadership, a lot of support from my peers on a regular basis. We're building some really good stuff here. I laid out what I thought was a pretty aggressive plan when I got here, and we're ahead of schedule on the plan.

So I mean, from that standpoint, it's a testament to not only the work that the team is doing, but also the support that we're getting from the organization as well. So I mean, from that standpoint, I really don't feel like I could have landed in a better situation than I have. And I'm not just saying that because we're sitting in our office right now, and who knows who else can hear. It really doesn't matter how good you are as a security leader if the organization's not supportive, you're not going to get anywhere. That's right.

That's exactly right. I've run into that situation in the past.

It goes part and parcel with the organization too. Do they have an appetite to ensure that they are building a good security posture within their organization such that when and if they have a breach of some kind, ultimately you get remembered for how you respond to those situations and how those situations turn out, not so much anymore the fact that you had one, because there's almost an expectation now that you're going to have one at some point. Get popped. That's right. But how do you handle that when it happens?

And what is the support you're gonna get from the organization? And what are the things that you're doing to ensure that you're ready when that happens? But anyway, kind of going down to the next couple years, I mean, I, I hope, knock on wood, that I have a fairly long, successful career here. I mean, at this point, I feel no reason why I'd want to really go anywhere else. I mean, it's a, it's a great company, great organization, great support.

The company went public again back in January after being private for a few years, so that's been a nice lift for the company as well. It certainly creates some energy around here relative to the success of the organization. There's a lot of vested interest that folks have in making sure the company is successful.

We have a lot that we're doing with our various regions as well. One of the things that was also interesting when I got here was— I apologize if I'm going to make us run over on time here. But one of the other standards that we needed to make sure we set when it came into the organization was our various regions were kind of self-managed for a long time. And as I came in and as the new infrastructure leader came in as well, he started just before I did, one of the things that was clear to us was that if we're going to make this environment easier for his team to manage and for my team to manage, we're going to have to start establishing some standards relative to technology and security posture and policies and things like that. Things like that.

And so having partners like that is what makes getting up in the morning to come to this place pretty easy. Awesome. That's great. Well, with that, Sam, awesome to get to reconnect with you and share how things are going. I think since the last time we talked, you were one of the finalists for the 2017 CISO of the Year.

I was, yes. So congratulations. I haven't had a chance to say it to you on the podcast, but congratulations for that. That was well deserved. That was for your work at TeleTech, and maybe you'll Maybe you'll get up there again for for Gatesworth.

I hope so. Awesome. All right, well, hopefully we'll talk to you again soon, and we appreciate reconnecting. Thank you very much. See you soon.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info. At colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes